Commit Graph
1948 Commits
Author SHA1 Message Date
roboomp 3106a15f7d fix(mcp): raced oauth login against cancellation
Esc and wizard abort signals now race the MCP OAuth login promise directly, so cancellation wins even before OAuthCallbackFlow reaches its callback wait and registers an abort listener. OAuthCallbackFlow also checks pre-aborted signals before opening/waiting on the callback server and its wait path handles already-aborted signals.

Threaded the abort signal into MCP OAuth fetches so dynamic client registration, metadata discovery, authorization probes, and token exchange unblock promptly when the user cancels.

Added a regression test where MCPOAuthFlow.login never observes ctrl.signal, matching the pre-wait race called out in review.

Fixes #3888
2026-06-30 10:21:26 +00:00
roboomp a6b2bac882 fix(mcp): made Esc cancel /mcp reauth and /mcp add OAuth flow
#handleOAuthFlow now installs an editor.onEscape hook that aborts its
AbortController, and accepts an external abortSignal so the add-wizard
can thread its own controller through (the wizard owns focus and absorbs
Esc itself). Cancellation surfaces as MCPOAuthCancelledError, which the
reauth and add catches translate into a neutral status line instead of
the generic OAuth failure banner. Disambiguated from the existing 5-min
timeout via a userCancelled flag so timeouts still read as errors.

The wizard intercepts Esc/Ctrl+C while #oauthAbort is set so its own
"Press Esc to cancel" advertisement now matches the behaviour, and
renames its error heading + tip when the failure is a user cancel. Also
fixed the misleading "(Press Ctrl+C to cancel)" message in the chat
transcript onAuth block to say "Press Esc" — Ctrl+C is bound to the
editor clear action, not interrupt.

Fixes #3888
2026-06-30 10:07:05 +00:00
roboomp 88be72e4d4 fix(coding-agent): seed tool-args reveal with the partial JSON already in hand
ToolArgsRevealController.setTarget initialized new entries with revealed=0, so the first message_update returned { __partialJson: "" } even when the provider had already parsed a complete chunk. For renderers without exposeRawPartialJson (e.g. write), the throttled re-parse + cached displayArgs short-circuited every subsequent setTarget, leaving the preview body blank until tool_execution_end.

Seed revealed with the full incoming partialJson length on entry creation (clamped to a surrogate-safe boundary). The first frame now carries the parsed path/content immediately; subsequent message_updates extend target and the reveal ticks pace only the newly arrived bytes — no field is ever truncated because the seeded prefix is the longest the entry has seen so far.

Fixes #3881
2026-06-30 08:04:49 +00:00
roboomp 64734021a7 fix(tui): deliver buffered double-Esc as two events and re-arm loader after task completion
StdinBuffer held a bare `\x1b\x1b` chunk (or emitted it as one when followed by
a non-CSI byte). `parseKey("\x1b\x1b")` returns undefined, so CustomEditor
fell through to the base editor and never fired the configured `onEscape` —
the double-escape gesture and the second-press single-Esc handler both went
dead whenever the terminal batched the two presses into one stdin read.

Split a bare `\x1b\x1b` into two ESC events at the buffer layer, mirroring
the existing split for ESC + SGR mouse report. Meta-CSI/SS3 chords
(`\x1b\x1b[A`, `\x1b\x1bO…`) still emit as one combined sequence.

EventController.tool_execution_update re-armed the working loader when a
transient overlay (auto-compaction / auto-retry / handoff) had torn it down
mid-tool; tool_execution_end did not. A subagent (`task`) call only fires
_end, so a task result landing after such an overlay left the UI looking
idle even though the session was still streaming. Mirror the reconciler
call in #handleToolExecutionEnd.

Fixes #3857
2026-06-30 03:41:24 +00:00
can1357 ce20cfb68e merge #3829: align /extensions MCP status with /mcp list and persist re-enable 2026-06-30 03:01:01 +02:00
can1357 e8090bb48a feat: introduced binary file detection to prevent encoding corruption
- Introduced `isProbablyBinary` utility to sniff file headers for NUL bytes or invalid UTF-8 sequences.
- Updated `ReadTool` to use the binary sniffer, preventing mojibake corruption in output when reading non-text files.
- Refined `file-mentions` auto-reads to skip binary files and mark them as `binary` in the message transcript.
- Added comprehensive unit tests for binary detection logic, covering NUL bytes, truncated multibyte characters, and path-based file sniffing.
2026-06-30 02:59:41 +02:00
roboomp e34f2a81e9 fix(tui): force-enabled MCP from tool-owned sources via enabledServers
Codex review on #3829: when an MCP server lives in a non-writable
source config such as opencode.json with enabled:false, the dashboard
re-enable had nowhere to write to — the writable mcp.json fallback
did not own the server, so setMcpServerEnabled fell through to the
denylist and the source's enabled:false kept the row disabled.

Added a parallel allowlist to the user-level mcp.json that overrides
a non-writable source's enabled:false flag without ever mutating the
foreign config:

- types + schema: new enabledServers array (mirrors disabledServers).
- config-writer: readEnabledServers + setServerForceEnabled helpers,
  and setMcpServerEnabled now writes to enabledServers on enable
  when no writable mcp.json owns the server, clears it whenever a
  writable source becomes the source of truth, and always clears the
  override on disable so a force-enabled server can be turned off.
- mcp/config (runtime loader) and state-manager (dashboard read):
  honor enabledServers as an override on enabled:false, while still
  letting disabledServers win.
- Added a regression test that walks the full lifecycle for an
  opencode.json server: enabled:false is surfaced as disabled, the
  dashboard re-enable force-enables via enabledServers without
  touching opencode.json, then disable clears the override and
  populates disabledServers.

Fixes #3827
2026-06-29 20:39:50 +00:00
roboomp 16ef3c54f4 fix(tui): re-enabled MCP alternate config sources
Codex review on #3829: the dashboard re-enable path still missed MCP
servers loaded from supported non-primary native config files such as
.omp/.mcp.json or user .mcp.json. Those rows carry enabled:false from
their source file, so falling back to the user disabledServers denylist
could not make the row active again.

- setMcpServerEnabled now accepts the loaded row's sourcePath and checks
  it before the primary project/user mcp.json paths.
- extension-dashboard passes the source path for writable MCP providers
  (native and mcp-json), avoiding accidental edits to third-party tool
  configs while still updating .omp/.mcp.json and standalone MCP JSON
  sources.
- Added a regression test for a server loaded from .omp/.mcp.json with
  enabled:false; re-enable flips that file to enabled:true and does not
  write the denylist.

Fixes #3827
2026-06-29 20:26:16 +00:00
roboomp 812b246e7e fix(tui): dashboard re-enable flips enabled:false in mcp.json
Codex review on #3829: when an MCP server's mcp.json entry carries
enabled:false, the dashboard toggle previously only removed the name
from the user-level disabledServers denylist. state-manager's new
`server.enabled === false` check (state-manager.ts:156) then still
marked the row disabled, leaving such servers impossible to re-enable
from /extensions.

Extracted setMcpServerEnabled() into mcp/config-writer.ts mirroring
/mcp enable | /mcp disable semantics:

- Server defined in project mcp.json -> update enabled on that entry.
- Else server defined in user mcp.json -> update enabled on that entry.
- Else (discovered third-party server) -> use the user-level disabledServers denylist.
- On re-enable, always clear any stale denylist entry.

extension-dashboard.ts routes mcp:* toggles through this helper. Added
four new regression tests covering: enabled:false re-enable, mixed
flag+denylist re-enable, disable on a config-resident server writing
enabled:false (not denylist), and discovered-server denylist round-trip.

Fixes #3827
2026-06-29 20:13:15 +00:00
roboomp 6256f97eaf fix(tui): aligned /extensions MCP status with /mcp list
Two read paths previously diverged on whether an MCP server was active or
disabled. /mcp list (slash-commands/helpers/mcp.ts:388) treats a server
as disabled when config.enabled === false OR the name is in the
user-level disabledServers denylist; the runtime MCP loader does the
same in mcp/config.ts:115. The /extensions dashboard only consulted
the dashboard-private settings.disabledExtensions array, so a server
disabled via /mcp disable or enabled:false kept showing as active.

Toggling MCP servers from the dashboard had the mirror problem: it only
wrote to settings.disabledExtensions, so /mcp list never noticed.

- state-manager: read user-level disabledServers from mcp.json once and
  consider enabled:false / denylist membership when deriving each MCP
  extension's state, matching /mcp list semantics.
- extension-dashboard: route mcp:* toggles through setServerDisabled
  against the canonical mcp.json denylist, and clean any legacy
  settings.disabledExtensions entry on re-enable so it doesn't keep the
  server marked disabled.
- Added a regression test exercising both read signals and the
  setServerDisabled round-trip the dashboard's MCP toggle now uses.

Fixes #3827
2026-06-29 20:05:04 +00:00
can1357 68285aa9d5 fix(coding-agent): throttled tui tool argument parsing and updates
- Optimized TUI tool argument previews by throttling JSON re-parsing to prevent frame starvation during high-frequency streaming.
- Suppressed redundant component updates for unchanged parsed fields while maintaining raw preview integrity for bash and patch renderers.
- Added adaptive parsing logic to `ToolArgsRevealController` that distinguishes between renderers requiring continuous raw JSON streams and those consuming parsed arguments.
- Updated `EventController` to dynamically determine exposure requirements based on tool type and wire-format metadata.
2026-06-29 07:11:18 +02:00
can1357 4db3d68bdb feat(coding-agent): implemented git worktree detection and rendering
- Added `git.repo.linkedWorktreeSync` to identify and resolve git worktree metadata without spawning subprocesses.
- Updated `StatusLineComponent` to detect linked worktrees and resolve project/worktree context names.
- Modified path segment rendering to collapse nested git worktree paths and display the worktree name when it diverges from the active branch.
- Introduced `icon.worktree` symbol across themes to visually distinguish git worktree paths.
2026-06-28 22:50:30 +02:00
can1357 6e3d401239 Merge remote-tracking branch 'origin/farm/04d319fb/ctrl-q-follow-up-queue-sends-the-literal' 2026-06-28 21:51:22 +02:00
can1357 6dab2b3196 Merge PR #3604: fix stale todo HUD rows (@jeffscottward) 2026-06-28 18:55:26 +02:00
can1357 0ffe6c8e1f Merge PR #3675: keep moved sessions resumable (@riverpilot)
# Conflicts:
#	packages/coding-agent/src/modes/controllers/command-controller.ts
2026-06-28 18:46:19 +02:00
roboomp 404a43e02b fix(coding-agent): expand paste markers in Ctrl+Q follow-ups
InputController.handleFollowUp read raw editor text via getText(),
bypassing the paste-store expansion the Enter path applies through
Editor.getExpandedText(). A large paste collapsed into a [Paste #N, +X
lines] marker was therefore sent verbatim to the model when queued with
Ctrl+Q / Ctrl+Enter, silently dropping the pasted content.

Switch the follow-up path to getExpandedText() so queued submissions
match the Enter path. Image markers are untouched; pendingImages
forwarding is unchanged.

Updated existing input-controller stubs (skill-queue, followup-image,
keybindings) to implement getExpandedText, matching the production
CustomEditor surface.

Fixes #3737
2026-06-28 16:42:39 +00:00
Jeff Scott Ward 917d2834a3 fix: address todo reminder review feedback 2026-06-28 12:03:06 -04:00
Jeff Scott Ward 9a9dc88f43 fix: address todo HUD review feedback 2026-06-28 11:16:30 -04:00
can1357 8185fdbfa9 feat(coding-agent): queued tool argument updates to prevent edit loss
- Implemented a queueing mechanism in `ToolExecutionComponent` to prevent starvation of edit previews during high-frequency argument updates.
- Replaced eager cancellation of in-flight diff computations with a drain loop that ensures every update is processed once the current compute settles.
- Added `partialJsonOf` helper to safely narrow streamed JSON buffers from tool arguments.
- Added regression test to verify that slow diff computations are not aborted by incoming stream chunks and instead queue a subsequent re-run.
2026-06-28 17:11:43 +02:00
Jeff Scott Ward 54f83e794e fix: preserve subagent hint API 2026-06-28 11:09:17 -04:00
Jeff Scott Ward dd917046d8 fix: anchor todo reminder HUD 2026-06-28 11:09:16 -04:00
can1357 fbad280b57 feat: implemented multi-advisor concurrent runtime with tui management
- Introduced comprehensive support for multiple concurrent, independently-configured advisors via `WATCHDOG.yml` files.
- Implemented a full-screen TUI overlay for managing advisor rosters, models, tools, and instructions.
- Added session-wide advisor initialization, telemetry aggregation, and named transcript isolation.
- Enhanced advisor security and observability with secret redaction in tool results and secure XML attribute encoding.
2026-06-28 12:55:09 +02:00
can1357 51a2a0342f test(coding-agent): implemented guest reconciliation and expanded testing for collaboration
- Introduced guest snapshot reconciliation to maintain host state consistency during session switching.
- Improved yield tool reliability by implementing incremental schema validation and strict parameter enforcement.
- Fixed a calculation edge case in the status line to prevent negative time values during activity tracking.
- Expanded the test suite with new validation for session interruption, collab state synchronization, and process error handling.
2026-06-28 09:52:44 +02:00
can1357 267926c8f7 feat(agent): enabled image attachments and draft restoration for skill commands
- Updated invokeSkillCommand to accept image and link attachments.
- Added draft restoration logic to preserve input state if command dispatch fails.
- Modified invocation path to pass image data to invokeSkillCommandFromText for processing.
- Refactored command dispatch flow to handle errors by restoring the user's composer draft.
2026-06-28 09:52:44 +02:00
roboomp f82086f805 refactor(coding-agent): moved Alt+M context gate into setModel
Replaced the controller-side switchActiveModel flag with a currentContextTokens hint on AgentSession.setModel, so the over-context decision is computed against the refreshed candidate metadata. setModel returns whether the live switch happened, and the Alt+M default-role path uses that to gate the live side effects.
2026-06-28 07:13:03 +00:00
roboomp 3765d80cbc fix(coding-agent): fixed alt-m default over context
Decoupled default-role persistence from live model switching when the selected model is below the current session context window.

Updated the model selector regression coverage so the Alt+M Default action remains selectable and advances to thinking selection.

Fixes #3708
2026-06-28 07:04:31 +00:00
can1357 96a1aed196 feat(coding-agent/modes): replaced static idle recap with LLM-generated summary
- Replace the static "Goal/Next" status line with an ephemeral LLM-generated summary triggered after idle periods.
- Hook the recap into the agent's side-channel pipeline, using live goal and task state as context anchors for meaningful recaps.
- Implement abort logic so that active user interactions immediately cancel pending recaps and discard late-arriving responses.
2026-06-28 08:15:24 +02:00
can1357 1852329c8c feat(coding-agent): added compact status line thinking level setting
- Added `statusLine.compactThinkingLevel` setting to render the thinking level as a leading icon.
- Replaced the verbose ` · <level>` suffix with a single glyph when compact mode is enabled.
- Updated the status line controller and component to resolve and propagate the new configuration.
2026-06-28 08:04:55 +02:00
can1357 2592b9dfe3 merge #3684: track active processing time for time_spent segment
# Conflicts:
#	packages/coding-agent/src/modes/controllers/event-controller.ts
2026-06-28 07:52:36 +02:00
can1357 5cdbf67cf3 fix focused stream preservation on rebuild 2026-06-28 07:49:55 +02:00
can1357 a3f4abd777 merge #3658: preserve in-flight assistant turn across /shake rebuilds 2026-06-28 07:49:49 +02:00
can1357 00f6468e9b merge #3672: allow thinking toggle after streamed reasoning 2026-06-28 07:49:41 +02:00
can1357 443195a81f merge #3700: preserve queued skill invocations during compaction
# Conflicts:
#	packages/coding-agent/src/session/messages.ts
#	packages/coding-agent/test/session-messages.test.ts
2026-06-28 07:49:33 +02:00
can1357 d18e2c2f4d feat(agent): introduced idle progress recaps and optional session titles
- Added idle recap functionality to EventController to display goals and next actions when the agent is inactive.
- Updated session parsing in gc-cli and memories to correctly support optional title entries in session files.
2026-06-28 07:27:01 +02:00
roboomp 796bf51f46 fix(coding-agent): preserved queued skill images
Kept image content attached to compaction-queued skill prompts when they are rebuilt as custom messages.
2026-06-28 04:46:26 +00:00
roboomp 9cfbece323 fix(coding-agent): queued retry-drained skill prompts
Kept compaction-queued skill prompts in the agent queue during retry drains instead of allowing them to start a fresh turn after compaction unwinds.
2026-06-28 04:34:48 +00:00
roboomp 80e772ba4d fix(coding-agent): preserved queued skill invocations
Rebuilt compaction-queued /skill: commands as user-attributed skill prompts when the queue drains.

Fixes #3697
2026-06-28 04:21:07 +00:00
roboomp 3c97ad1e15 fix(tui): reset time_spent meter on AgentSession.switchSession file swap
Address PR review: switchSession (/resume, /move, ACP fork/load,
RPC switch_session, extension switchSession) mutates the loaded
session file in place under the same AgentSession ref, so a WeakMap
keyed only on the AgentSession ref carried the previous
conversation's meter into the resumed one — the footer kept showing
the previous total after resuming a different idle session.

Snapshot the loaded sessionFile path in the per-session meter and
detect a real-to-real transition inside #meter(): on a swap, drop
the old meter and start a fresh one. The undefined → real first-save
transition only refreshes the snapshot (same conversation, same
identity, accumulated time preserved). #closeStaleActiveWindow now
routes through #meter() so the file-change check applies there too.

Adds two regression tests covering the real-to-real swap and the
first-save no-reset.
2026-06-27 21:12:10 +00:00
roboomp 8c6b2db1f7 fix(tui): track time_spent meters per session
Address PR review: SessionFocusController synthesizes agent_start on
mid-turn attach but does not pair it with a synthetic agent_end on
unfocus. With a single shared StatusLineComponent meter, returning to
the main session while a subagent was still streaming left
#activeStartedAt open, so the main status line kept ticking through
idle time after the subagent finished.

Replace the single #activeMs / #activeStartedAt fields with a WeakMap
keyed on AgentSession. markActivityStart / markActivityEnd /
getActiveMs / resetActiveTime all operate on the currently-attached
session's meter, so detaching from a subagent never bleeds its open
window into main. setSession closes a stale window (in-flight + new
session not streaming) on re-focus so a subagent that finished while
we were detached does not credit the detached gap.

Adds two regression tests covering both cases.
2026-06-27 21:01:14 +00:00
roboomp 68db2ce649 fix(tui): track active processing time for time_spent status segment
The time_spent segment rendered Date.now() - sessionStartTime, so an
idle session displayed hours of "time spent" while the agent did
nothing — the only inputs were wall-clock and the unmoving session
start.

Replace sessionStartTime with activeMs in SegmentContext and accumulate
inside StatusLineComponent across agent_start -> agent_end windows.
markActivityStart/markActivityEnd are idempotent (reentrant agent_start
events and superseded agent_end events never double-count); the segment
ticks live during an open window and freezes when the agent yields.
The session-boundary hook drops the now-meaningless wall-clock argument
and is renamed setSessionStartTime -> resetActiveTime; it zeroes the
accumulator and drops any in-flight window so /clear / fresh-session /
joined-collab paths start the meter at zero.

Fixes #3681
2026-06-27 20:50:19 +00:00
Alexander Kirilin f209087cfd fix(omp): keep moved sessions resumable 2026-06-27 15:57:09 -04:00
roboomp 9302e17545 fix(tui): updated streaming thinking visibility
Propagated the first observed reasoning-content unlock to the active streaming assistant component before the reveal controller re-renders it. Added a regression that starts a hidden thinking-off stream and verifies the first reasoning delta becomes visible.
2026-06-27 17:30:02 +00:00
roboomp 4d0ef260b6 fix(tui): allowed thinking toggle after streamed reasoning
Tracked received thinking content per interactive session so OpenAI-compatible providers that omit reasoning metadata can still reveal streamed reasoning blocks. Added a Ctrl+T regression covering the unlocked visibility path.

Fixes #3669
2026-06-27 17:18:04 +00:00
roboomp 85e2f904d7 fix(tui): preserve in-flight assistant turn across /shake rebuilds
`handleShakeCommand` calls `rebuildChatFromMessages()`, which clears
`chatContainer` and replays only committed `state.messages`. The agent's
in-flight `streamMessage` and its still-pending tool calls live OUTSIDE
`state.messages` until `message_end`, so the live `streamingComponent`
and `pendingTools` entries were detached while their references stayed
live — every subsequent `message_update`/`message_end` event then
updated orphaned components that never re-rendered, and the in-flight
LLM output disappeared from the chat. Other mid-stream rebuild paths
(setting toggles such as `display.cacheMissMarker` and
`tui.renderMermaid`) had the same flaw.

Snapshot the live `streamingComponent` and `pendingTools` (in their
original chat-container order) before clear, re-append after the
historical replay, and restore the `pendingTools` map so the next
streamed tool-call delta routes back into the preserved component
instead of stacking a duplicate ToolExecutionComponent below it. Idle
rebuilds are unchanged.

Fixes #3656
2026-06-27 13:19:50 +00:00
can1357 0bb0547f17 fix(ui): reordered project path display for homedir priority
- Prioritized homedir projects over /work in status line path display.
2026-06-27 12:26:11 +02:00
can1357 357c29224d feat: implemented symbol-based streaming state for isolated metadata
- Migrated internal streaming state from string-based properties to symbol-keyed properties for improved data isolation and safety.
- Replaced the deprecated `stripVariant` utility with centralized `clearStreamingPartialJson` and symbol-specific helper methods across all provider implementations.
- Implemented `stripStreamingBlockSymbols` and updated deep equality checks to ensure metadata does not interfere with content comparisons.
- Standardized streaming metadata access through a new `block-symbols` utility module.
2026-06-27 12:07:08 +02:00
can1357 c3f7e849e5 refactor: centralized AI error handling into a dedicated module
- Migrated 288 lines of scattered error classification logic from `utils/error-id.ts` into a cohesive `packages/ai/src/error/` module with 13 specialized submodules covering flags, classes, OAuth, providers, rate-limiting, and finalization.
- Replaced 100+ generic `Error` throws across 60+ provider and registry files with semantic `AIError.*` classes (e.g., `AIError.MissingApiKeyError`, `AIError.OAuthError`, `AIError.ProviderResponseError`), improving error diagnostics and retry logic.
- Consolidated error utility imports from `pi-utils` and scattered classification functions into a single `AIError` namespace, reducing coupling and simplifying error handling across all packages.
2026-06-27 10:44:13 +02:00
can1357 b96c341532 refactor(coding-agent/modes): removed unused subagent hub hint integration
- Removed dead code responsible for setting the subagent hub hint in the interactive mode initialization.
2026-06-27 08:24:16 +02:00
can1357 98b7db0c84 feat(coding-agent): simplified subagent status line display
- Removed "running" status and hub hint details from the subagent badge text.
- Updated relevant status line tests to expect the simplified badge format.
2026-06-27 08:18:58 +02:00
roboomp 9d5b1f245d fix(acp): resolved generated image blob refs
Resolved live ACP generate_image payloads through the blob store before emitting image content while keeping rawOutput compact.

Added regression coverage for content[] image blocks and details.images entries without duplicating blob refs as fallback text.

Fixes #3623
2026-06-27 03:46:05 +00:00