Commit Graph

1083 Commits

Author SHA1 Message Date
can1357 bef97a69bb Merge PR #6529: fix(coding-agent): guard retain renderer streaming args (@roboomp) 2026-07-25 00:59:14 +02:00
can1357 8851e93d21 Merge PR #6551: fix(coding-agent): use session settings in file guards (@roboomp) 2026-07-25 00:59:14 +02:00
roboomp 144043ad48 fix(coding-agent): used session settings in file guards
Passed session-scoped settings through Edit and Write generated-file checks and fell back to schema defaults when no global singleton exists.

Guarded inline image sizing against an uninitialized global settings proxy and added isolated-session regression coverage.

Fixes #6549
2026-07-24 22:42:38 +00:00
can1357 f23bc266a8 feat(natives): enabled per-language rewrite rules for mixed-language paths
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
2026-07-24 21:52:29 +02:00
roboomp d7c7ca033d fix(coding-agent): guarded retain renderer streaming args
- Treated transient non-array retain items as absent during TUI streaming.
- Added regression coverage for malformed partial renderer arguments.
- Documented the fix in the coding-agent changelog.

Fixes #6528
2026-07-24 15:52:01 +00:00
can1357 c55b28a26d chore(coding-agent): format eval display helpers 2026-07-24 16:49:31 +02:00
can1357 ff49b986d5 feat(coding-agent/tools): introduced language-specific code formatters for display rendering
- Added language-specific code formatters for JavaScript, Julia, Python, and Ruby to improve display rendering.
- Integrated display formatting into browser run and eval render tools while preserving verbatim execution.
- Added comprehensive test suites verifying formatting stability, lexical safety, and streaming behavior.
2026-07-24 16:26:03 +02:00
can1357 5acdefc7b3 feat(coding-agent/web): introduced structured web-search query parsing module
- Implemented a structured web-search query parsing module supporting directives, tokenization, date parsing, and syntax serialization.
- Updated search providers to map query directives and date bounds to native provider parameters and filters.
- Added lenient result constraint post-filtering and configuration settings for enhanced engine routing.
- Added comprehensive unit and integration tests covering query parsing, constraint filtering, and provider-specific request mapping.
2026-07-24 16:05:14 +02:00
can1357 d4792ed38b fix(tools): leniently inferred missing todo op from unambiguous payloads
- Kept op required in the todo schema; lenientArgValidation now routes raw args to execute(), where resolveTodoParams re-validates and repairs an omitted op (list -> init, phase+items -> append, bare items on empty list -> init).
- Ambiguous op-less calls surface the schema error as a retryable tool error instead of a hard validation failure.
2026-07-24 12:03:06 +02:00
usr-bin-roygbiv 68ac163e2c fix(computer): harden native desktop execution 2026-07-24 01:40:05 +00:00
can1357 681d7daf65 feat(computer): unified native addon, /computer toggle, function tool
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
  a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
  XTest input with keysym mapping) compiled into the core addon on every
  published target; Linux arm64 and musl are now supported and headless
  hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
  lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
  build dependencies, and the now-unreferenced vendored libspa crate;
  reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
  XTest layouts reject negative origins and coordinates beyond 0..=32767,
  batch coordinates stay bound to the frame last returned to JS with
  intermediate screenshots deferred, coordinate input requires a
  previously returned frame, and failed chord releases still release
  every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
  no input is emitted after expiry and wait-heavy batches are rejected
  upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
  scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
  a regular function tool with a typed GA action schema across OpenAI,
  Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
  session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
2026-07-24 01:40:05 +00:00
usr-bin-roygbiv 57f8acdd18 fix(native): harden desktop input and compatibility 2026-07-24 01:40:05 +00:00
usr-bin-roygbiv b9504f65e7 feat: add native Codex computer use 2026-07-24 01:40:04 +00:00
can1357 e23359fd1a fix(prompts): restored JS spread operator mangled into Unicode ellipsis by reformat
- 24e2a52615 turned ...f into …f inside the workflow-notice parallel example, making the copyable snippet a syntax error.
2026-07-23 23:15:31 +02:00
can1357 2ecba08e2a Merge PR #6407: fix(browser): bound open timeout and lease browser across tab acquisition (@roboomp) 2026-07-23 22:15:24 +02:00
can1357 bbf0402990 fix(coding-agent): surface JSON-RPC error code so -32601 method-not-found is recognized regardless of message text
Codex P2 on #6403: sendRequest rejected with only the server's error
message; a server answering rust-analyzer/reloadWorkspace with code
-32601 but nonstandard text (e.g. "Unknown request") would fail
isMethodNotFoundError and turn lsp reload into a hard error instead of
falling back to the generic reload. Include the code in the rejection
message so the existing -32601 substring check matches. Adds a
regression test with a -32601/"Unknown request" response.
2026-07-23 22:15:23 +02:00
can1357 221c93c88b Merge PR #6403: fix(coding-agent): propagate cancellation from lsp reload instead of false restart (@roboomp) 2026-07-23 22:15:23 +02:00
can1357 418076e44a fix: treat escaped quotes inside double-quoted backticks as inner quoting
Bash treats \" inside a backtick substitution nested in double quotes as
a quote delimiter for the inner command; the generic backslash-skip made
isInsideShellQuote report such quoted literals as unquoted, wrongly
expanding internal URLs inside them (Codex P2 review finding).
2026-07-23 22:15:23 +02:00
can1357 5ac3094d88 Merge PR #6418: fix(tool): expand internal urls inside backtick substitutions (@roboomp) 2026-07-23 22:15:23 +02:00
can1357 c991270145 Merge PR #6404: fix(coding-agent): make PDF image cache content-aware (@roboomp) 2026-07-23 22:15:22 +02:00
roboomp 70e92d32a6 fix(tool): expand internal urls inside backtick substitutions
isInsideShellQuote opened an expansion context for $() command
substitution but never tracked legacy backtick substitution, so an
unquoted skill:// (or other supported scheme) nested directly inside a
backtick pair within double quotes kept the outer quote active and was
left literal. Treat an unescaped backtick as an expansion-context
boundary on the same substitution stack, restoring the outer quote when
the pair closes, matching $() behavior including nesting in either
order. Single-quoted and escaped-backtick text stay literal.

Fixes #5645
2026-07-23 19:20:08 +00:00
roboomp d4b1fd5107 fix(browser): bound open timeout and lease browser across tab acquisition
The browser tool's open action only passed the requested timeout to acquireTab; acquireBrowser ran under the caller signal alone, so CDP discovery/connect could run through its own fixed 5s/30s waits past the requested deadline. A freshly-created browser also sat in the registry at refCount 0 during worker/surface acquisition: the worker-abort branch released it only on tempHold (never on the fresh refCount-0 case), orphaning the handle, and two different-name opens sharing one refCount-0 browser let a single failure dispose it out from under the survivor.

Compose one open deadline from the caller signal and params.timeout and thread it through both acquireBrowser and acquireTab; caller cancellation stays ToolAbortError, the requested timeout becomes a timeout ToolError. Hold one explicit registry lease across tab acquisition, released exactly once on the mutually-exclusive success/rollback paths, and make the worker-abort browser release mirror the error paths' refCount-0 check.

Fixes #6365
2026-07-23 19:02:38 +00:00
roboomp 7877df00e4 fix(coding-agent): made pdf image cache content-aware
- Snapshotted source bytes before deriving path-and-content cache generations.
- Coalesced cold extraction with independent caller cancellation and atomic publication.
- Covered replacement, mutation, concurrency, cleanup, isolation, and component limits.

Fixes #6368
2026-07-23 18:58:58 +00:00
roboomp eeb3fa6ace fix(coding-agent): propagated cancellation from lsp reload instead of false restart
reloadServer caught every error from both fallback mechanisms in bare
catch blocks, so a caller cancel or tool timeout was swallowed and fell
through to `proc.kill(); return "Restarted"` -- reporting a successful
restart while killing the server with no replacement.

- Propagate ToolAbortError/timeout from both the rust-analyzer request
  and the didChangeConfiguration notification fallback.
- Gate the fallback on genuine method-not-found via isMethodNotFoundError
  instead of any error.
- Replace the blind proc.kill with shutdownClientInstance: remove the
  client from the registry by identity and await confirmed process exit,
  surfacing a truthful teardown error when the process outlives the kill.

Fixes #6369
2026-07-23 18:58:15 +00:00
can1357 5b3275c7ae feat(coding-agent): introduced ordered provider priority lists for search and images
- Replaced single-provider preferences with ordered priority lists for web search and image generation.
- Added a `MultiSelectSubmenu` component supporting toggle and reordering interactions in settings.
- Implemented migration logic to convert legacy single-provider preferences into ordered priority lists.
- Updated setup wizard scenes, image generation fallback logic, and search provider chains to use priority lists.
2026-07-23 20:44:50 +02:00
can1357 344714aea7 Merge PR #4890: feat(coding-agent): use Grok 4.5 for xAI web search (@metaphorics)
# Conflicts:
#	packages/coding-agent/src/web/search/providers/xai.ts
2026-07-23 20:16:05 +02:00
can1357 154d4ace9f Merge PR #4448: feat(todo): add blocked status with block/unblock ops (@mattwilkinsonn)
# Conflicts:
#	packages/coding-agent/src/modes/interactive-mode.ts
#	packages/coding-agent/src/prompts/tools/todo.md
2026-07-23 17:32:43 +02:00
can1357 9d5f158e23 fix(coding-agent): preserved default markdown rendering for internal-URL reads
Gated the read.renderMarkdown opt-in at read time (details tagging) instead
of inside the renderer. The renderer gate silently flipped every
protocol-supplied text/markdown read (skill://, pr://, issue://, history://,
rule://, omp://, agent://, vault://, local://, memory://, ssh://) from the
formatted markdown cell to the raw code cell when the setting was off, which
regressed default TUI behavior. Local file tagging now happens only when the
setting is enabled, so the default render path is byte-identical to the
pre-setting behavior while opt-in previews still work end-to-end.

Also inlined the tautological isMarkdownContentPath wrapper, pinned the
widened prose-summary bypass (.mdx stays verbatim when prose summaries are
off) with a test, and documented it under Changed in the changelog.
2026-07-23 17:30:33 +02:00
can1357 42a3da21de Merge PR #4001: feat(coding-agent): opt-in Markdown read previews (@oldschoola) 2026-07-23 17:30:33 +02:00
can1357 09d02c641f fix(coding-agent): closed bash approval rule bypasses
Tested the shell-control guard against the raw command: whitespace
normalization collapsed newlines/CR before the guard ran, so
'git status\nrm file.txt' rode a 'git *' allow rule while bash executed
both lines. Honored tool-owned allow/prompt policies in yolo mode so
per-command prompt rules were no longer silently discarded under the
default approvalMode. Added precision regression tests through the real
matcher (separators, subshells, redirects, env prefixes, path/quoting
variants) that fail on the unfixed head.
2026-07-23 17:30:32 +02:00
can1357 794515fd1a Merge PR #6363: feat(coding-agent): support per-command bash approval rules (@WahidinAji) 2026-07-23 17:30:32 +02:00
can1357 0f54c0df70 fix(tools): autoqa consent handling from default off to opt-in 2026-07-23 13:24:45 +02:00
Cakrawala 6d7457663f feat(coding-agent): support per-command bash approval rules 2026-07-23 17:11:41 +07:00
can1357 536d37ac07 Merge PR #5137: perf(coding-agent): avoid cold LSP startup on format-only writes (@wolfiesch) 2026-07-23 11:37:13 +02:00
CoderTCY d115ac66c1 Fix by review 2026-07-23 10:23:06 +08:00
CoderTCY 1071984385 Fixes 2026-07-23 09:54:35 +08:00
CoderTCY 3ada287cb0 feat(firecrawl): support keyless mode when no API key is configured
When FIRECRAWL_API_KEY is not set, fall back to Firecrawl keyless mode
(omit Authorization header). Auto-chain still requires a credential via
isAvailable; explicit webSearch: firecrawl works keyless via
isExplicitlyAvailable returning true.

Closes https://github.com/can1357/oh-my-pi/issues/4332
2026-07-23 09:54:35 +08:00
can1357 52ad6516ef feat(diff): implemented native UTF-16 diff processing and removed jsdiff
- Implemented native UTF-16 text processing in Rust diff module with support for unpaired surrogates.
- Removed `similar` crate from Rust workspace and `diff` npm package from coding-agent, hashline, and natives.
- Removed jsdiff fallback wrappers and `isWellFormed()` guards from TypeScript diff implementations.
- Added comprehensive test suite for native diff functions covering random inputs and edge cases including surrogates and emoji.
- Renamed model `codex-auto-review` to `gpt-5.3-codex-spark` with updated pricing and context window.
2026-07-23 01:35:31 +02:00
can1357 fc6256372d test: fix local-midnight logger flake and stale kimi k3 thinking format pin
- logger-multiprocess asserted the UTC day (toISOString) while DailyRotateFile names files with the LOCAL date, failing nightly between 00:00 and 02:00 local (UTC+2); the per-pid rotation-file invariant now matches any dated name.
- kimi-code k3 bundled compat moved to thinkingFormat 'kimi' with the catalog regen; the K3 named-tool-choice downgrade gate keys on provider/id/baseUrl, so only the stale precondition needed updating.
2026-07-23 00:13:14 +02:00
can1357 9a0a154e53 Merge PR #6279: perf(coding-agent): compute edit and word diffs natively (@wolfiesch) 2026-07-22 21:13:23 +02:00
can1357 13e7f29bc4 Merge PR #6296: fix(tools): cap per-tool default timeout with tools.maxTimeout (@roboomp) 2026-07-22 21:13:20 +02:00
roboomp b2ac625377 fix(coding-agent/launch): kept pre-ready exits as not-ready in wait
A for:"ready" wait woke on any terminal state, but reported timedOut:false even
when readiness was never observed — the only success signal on the wait result —
so callers could chain work against a dead process. Split the wake predicate
from the ready-observed check: the wait still wakes on a terminal exit, but
timedOut now reflects whether readiness was actually observed (readyAt, live
ready, or a running daemon with no ready spec).

Fixes #6303
2026-07-22 16:49:34 +00:00
roboomp 3c1fbdd3f3 fix(coding-agent/launch): surfaced pre-ready exits in TUI
The model-facing start content reported when a process exited before readiness,
but launchRenderResult rebuilt the interactive result solely from structured
details and dropped that explanation. Mirror the terminal-without-readyAt
condition in the TUI start renderer and add a renderer contract test.

Fixes #6303
2026-07-22 16:43:35 +00:00
roboomp 4a000330c6 fix(coding-agent/launch): cleared stale readiness on restart entry
readyAt/readyMatch belong to the exited generation but were only reset by
#launch, which runs after the restart backoff delay. During the "restarting"
window the sticky-marker predicate from the prior commit therefore reported a
dead service as ready, letting start and for:"ready" waits race it. Clear both
markers when #settle enters "restarting"; #launch re-sets them once the new
child is up. Adds a regression test that observes the backoff window.

Fixes #6303
2026-07-22 16:36:24 +00:00
roboomp 87552aae30 fix(coding-agent/launch): woke ready waits on sticky marker not live state
hub start and for:"ready" waits polled the live daemon state, so a process
that flipped starting→ready→exited within one 50ms poll interval was only
ever observed as "exited" and the wait blocked for the full readiness
timeout — despite #markReady durably recording readyAt. A pre-ready exit
had the same failure since terminal states only woke the wait during broker
shutdown.

Wake both waits on readyAt !== undefined || terminalState(state); readyTimedOut
= !ready then falls out. The start renderer reports "Process exited before
readiness was observed." for a pre-ready exit. Adds two regression tests that
hang to their caps on the old code.

Fixes #6303
2026-07-22 16:29:38 +00:00
roboomp 1b6588e520 fix(tools): cap per-tool default timeout with tools.maxTimeout
clampTimeout resolved the per-tool default (bash 300s) whenever the agent
omitted `timeout` and only enforced the tool's own min/max, so the
tools.maxTimeout global ceiling — applied solely in sdk.ts on explicitly
numeric args — was bypassed on the common default-fallback path.

Thread maxTimeout into clampTimeout so the resolved effective timeout,
including the default path, is capped before the per-tool floor/ceiling
apply. Explicit values below the cap still win; maxTimeout <= 0 stays
no-cap. Applied at every call site (bash, eval, browser, debug, lsp,
fetch, and the session-level bash executor), and the bash clamp notice
now names the global ceiling when it is the binding limit.

Fixes #6294
2026-07-22 15:18:27 +00:00
Wolfgang Schoenberger ee6717872c test(natives): cover ill-formed UTF-16 rejection and jsdiff fallback 2026-07-22 04:32:46 -07:00
Wolfgang Schoenberger d866532bd1 perf(coding-agent): reduce format-on-write latency 2026-07-21 13:53:52 -07:00
can1357 a87d7d35cd Merge PR #4961: fix(agent): stop malformed subagent yield loops (@roboomp)
# Conflicts:
#	packages/coding-agent/src/prompts/system/workflow-notice.md
#	packages/coding-agent/src/task/executor.ts
#	packages/coding-agent/src/tools/yield.ts
2026-07-20 22:51:53 +02:00
can1357 8f2cd23e39 Revert "Merge PR #5812: fix(read): honor exact line selector bounds (@roboomp)"
This reverts commit 58c71d5b50, reversing
changes made to 7c7227bc8e.
2026-07-18 22:04:43 +02:00