Commit Graph

1648 Commits

Author SHA1 Message Date
can1357 bc39ffa265 feat: introduced omptype validation package and migrated workspace dependencies
- Introduce `@oh-my-pi/omptype` as a new ArkType-compatible schema validation package featuring a lazy JIT runtime, JSON Schema emission, and compatibility adapters.
- Replace `arktype` across workspace packages and test utilities with `@oh-my-pi/omptype`.
- Add benchmark suites, tests, and documentation for the new validation engine and adapters.
- Update workspace build, test runner, and release configurations to include the new package.
2026-08-03 21:56:48 +02:00
can1357 6a44844c57 Merge PR #7377: fix(hub): wake owners when supervised processes exit (@paralin) 2026-08-03 15:12:03 +02:00
can1357 1b5148ed84 Merge PR #7368: fix(browser): guard cmux guest rejections (@roboomp) 2026-08-03 14:46:24 +02:00
Christian Stewart 302148523f fix(hub): wake owners when supervised processes exit
Publish terminal daemon completions to the session that started the
process so idle agents can resume without polling hub status.

Persist every unacknowledged generation with a stable completion ID and
immutable snapshot. Replay the collection after reconnect or broker
recovery, and clear each event only after the owning client acknowledges
it.

Signed-off-by: Christian Stewart <christian@aperture.us>
2026-08-03 01:31:39 -07:00
roboomp 8f7c7f7415 fix(coding-agent): honor vision role thinking effort in inspect_image
inspect_image resolved @vision with resolveModelFromString, which dropped the
:high thinking selector, and passed no reasoning to the oneshot. The
google-gemini-cli mapper then emitted thinkingBudget: 0, which thinking-only
Gemini models reject with HTTP 400. Resolve the role's explicit thinking
selector, clamp it to the model's supported efforts, and forward it as the
oneshot reasoning.

Fixes #7448
2026-08-03 05:16:14 +02:00
can1357 aa014717dc refactor(coding-agent): restored static computer worker start hook
- The pi-utils/mime subpath fix made the computer worker graph lazy-safe,
  so the dynamic-import dispatch added for laziness is no longer needed;
  cli.ts and the bundled-host fixture statically import
  startComputerWorker() per the no-inline-import rule.
- worker-entry keeps the selector-guarded direct-source auto-start; the
  worker-selector test now pins the exported hook contract. Verified
  --no-addons CLI startup stays addon-free and the bundled/compiled
  worker-host tests pass.
2026-08-03 00:19:58 +02:00
can1357 0156ddcbe1 fix(coding-agent): kept computer worker graph off CLI startup
- The PR #7205 merge left cli.ts statically importing startComputerWorker,
  dragging the computer worker graph (and pi_natives via the pi-utils
  barrel) into normal CLI startup; --version died under --no-addons and
  dotenv loaded before profile bootstrap. worker-entry is now a
  self-starting side-effect module dispatched via dynamic import like
  every other worker selector, and utils/clipboard.ts imports the mime
  constant from its submodule instead of the barrel.
- Repointed the clipboard test spy at @oh-my-pi/pi-natives/clipboard —
  spying the barrel never intercepted the subpath the code imports, so
  the real native bridge ran (X11 timeouts on headless CI).
- Refreshed the pinned HTML export template digest and the scout gate
  phrase the system-prompt rewrite changed.
2026-08-03 00:02:29 +02:00
can1357 f7480294b4 fix(agent): track rewritten xdev approval tiers 2026-08-02 20:57:06 +02:00
can1357 721c12382c Merge PR #7314: fix(agent): skip prewalk switch on read-only xd:// device calls (@roboomp) 2026-08-02 20:57:06 +02:00
can1357 3de8c3a476 Merge PR #7344: fix(agent): stop leaking scout into prompts when it is disabled (@szavadsky)
# Conflicts:
#	packages/coding-agent/src/prompts/system/system-prompt.md
2026-08-02 20:52:56 +02:00
can1357 ef852af986 feat(computer): implemented modular desktop backend and script workflows
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
2026-08-02 19:46:25 +02:00
can1357 92b50faacc feat(coding-agent/lsp): implemented lsp multiplexer server and shared daemon lifecycle
- Added an LSP multiplexer server, protocol definitions, and daemon lifecycle management to route traffic across sessions.
- Introduced `lsp.shared` settings configuration and SDK session creation support for shared language servers.
- Migrated shared daemon ensure helpers into a central launch module with updated import references.
- Added comprehensive unit tests and fake LSP server fixtures covering muxing, sharing, caching, and restarts.
2026-08-02 18:15:22 +02:00
can1357 4a946e2cfc fix(coding-agent/tools): serialized tab grouping operations in the relay bridge
- Serialized group and ungroup operations to prevent duplicate tab group creation races.
- Queued and serially drained tab grouping requests in the relay bridge to prevent overlapping RPCs.
- Mirrored tab group titles to session storage and healed duplicate groups during background service worker recovery.
- Renamed run-cancellation utility to run-scope and updated corresponding module and test references.
2026-08-02 18:07:07 +02:00
can1357 7c3b24ddf2 feat: implemented cross-platform window discovery and targeting capabilities
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
2026-08-02 17:35:29 +02:00
roboomp c802475aa0 fix(browser): scoped cmux attribution to guest stacks
Dropped the single-active-run fallback that claimed unrelated stackless rejections in the shared main-process realm, matching the eval inline-mode invariant. Only guest-file stack frames attribute a rejection now; stackless reasons keep the fatal path. Restored the probe to an Error rejection carrying a guest stack.

Fixes #7365
2026-08-02 09:37:17 +00:00
roboomp 6113fe9727 fix(browser): handled stackless cmux rejections
Attributed unmatched rejection reasons when exactly one cmux guest run is active, covering primitive and library-created failures without guessing between concurrent runs. Updated the process probe to reject with a primitive value.

Fixes #7365
2026-08-02 09:31:21 +00:00
roboomp 8d4521db78 fix(browser): guarded cmux guest rejections
Captured browser-run-attributable promise rejections before the global fatal handler and surfaced active failures as tool errors. Retained finished run filenames so late rejections remain isolated without consuming unrelated process failures.

Fixes #7365
2026-08-02 09:20:54 +00:00
Slava Zavadsky 3e0763eee7 fix(agent): keep search-tool scout gating live; gate workflowz line 5
Address review feedback on #7344:
- grep/glob/ast_grep descriptions now render via a getter instead of a
  construction-time field, so a live task.disabledAgents change (e.g. via
  /agents) is picked up on the next prompt rebuild instead of leaving
  stale 'Task + scout' guidance cached.
- The workflowz notice now also gates the 'Scout inline FIRST' verb on
  line 5, matching the already-gated line 14.
2026-08-02 00:02:06 -04:00
Slava Zavadsky 9885ee34fc fix(agent): stop leaking scout into prompts when it is disabled
Hard-coded 'scout' references reached the model even when the scout
agent was disabled via task.disabledAgents or absent from the session
spawn list. Gate every such reference on scout actually being spawnable:
the task tool description, the delegation gates, the plan-mode and
workflowz notices, the glob/grep/ast-grep guidance, and the task
specialization advisory. Prompt shape is otherwise unchanged; only
erroneous references to the unavailable subagent are dropped.

Closes #7313
2026-08-01 23:50:33 -04:00
can1357 92c79d80c7 feat: introduced OMP Browser Relay extension with CDP RPC execution
- Implement the OMP Browser Relay extension with WebSocket communication and CDP RPC execution.
- Add browser relay server, daemon management, and bridge multiplexing in the coding agent.
- Introduce CLI commands and settings schema options for configuring and installing the relay.
- Add utility functions and test suites supporting environment parsing and relay lifecycle handling.
2026-08-02 05:33:07 +02:00
roboomp 0e923547aa fix(agent): skip prewalk switch on read-only xd:// device calls
xd:// devices dispatch through the write tool, so a read-only call such
as an lsp navigation matched PREWALK_ACTION_TOOLS and armed the one-way
model hand-off while still reasoning about code shape.

dispatchXdevTool now records the wrapped tool's approval tier on the
XdevDispatch, and the prewalk coordinator only treats a device write as
an implementation action at write/exec tier. Direct edit/write are
unchanged.

Fixes #7312
2026-08-01 19:41:10 +00:00
can1357 386385f18b fix(coding-agent): skipped xd:// mounting when write tool is not granted
- Prevent xdev state allocation and tool mounting in sessions lacking a write tool.
- Expose discoverable tools top-level instead of auto-granting write transports.
2026-08-01 20:39:08 +02:00
can1357 1088ee2127 Merge PR #7203: fix(tui): render mid-turn steering skips as info, not errors (@roboomp) 2026-08-01 20:14:40 +02:00
can1357 2b8546faa0 Merge remote-tracking branch 'origin/farm/8f2adac9/bash-auto-background-clearable-timer' 2026-08-01 08:33:11 +02:00
can1357 ad78b6a84e feat(coding-agent/tools): implemented shared browser daemon management
- Added `ensureSharedBrowser` and shared browser acquisition to manage project-shared broker-owned Chromium instances.
- Implemented concurrent duplicate daemon start prevention and single-flight `pendingOpens` deduplication.
- Updated browser handle disposal to disconnect from shared daemons rather than closing them.
- Updated browser documentation and launch specifications to support shared and local headless runs.
2026-08-01 08:30:05 +02:00
roboomp fe4e553be3 fix(coding-agent): clear bash auto-background threshold timer
waitForManagedBashJob raced job completion against a bare
Bun.sleep(thresholdMs), which cannot be cancelled. When completion,
abort, or steering won the race, the losing Bun.sleep timer stayed
scheduled and ref'd, keeping Bun's event loop alive until the threshold
expired — delaying SDK/headless shutdown and accumulating timers under
fast command rates.

Replace the Bun.sleep with a Promise.withResolvers settled by a
cancellable setTimeout, and route every outcome (including the former
no-signal early return) through one try/finally that clears the timer
and removes the abort/steer listeners.

Add a child-process regression test that runs the real auto-background
path for a fast command against a 30s threshold and asserts the process
exits promptly instead of being held for the full threshold.

Fixes #7235
2026-08-01 05:14:43 +00:00
roboomp ebd84d4f85 fix(tui): render mid-turn steering skips as info, not errors
A tool call aborted mid-batch to service queued steering/peer input emits a synthetic placeholder result with isError:true so the model retries it. The TUI keyed all error styling (red ✘, red frame/text) off that flag, so a normal steering skip rendered identically to a real tool failure.

Mark the skip placeholder with the existing SyntheticToolResultDetails discriminator (source: "interrupt_skipped", executed:false) and render benign skips through the neutral generic card (info glyph, dim text, neutral background), bypassing any bespoke error frame. Genuine failures keep their error styling.

Fixes #7199
2026-07-31 21:06:07 +00:00
can1357 a6c6257574 chore: applied formatter and deduplicated observer stubs in task fixtures 2026-07-31 19:51:52 +02:00
can1357 63d6bd3064 Merge PR #7060: fix(browser): own headless Chromium profile dir to survive Windows EBUSY cleanup (@roboomp) 2026-07-31 19:42:43 +02:00
can1357 f46af54f9c fix(browser): preserve screenshot correctness when attached 2026-07-31 19:42:42 +02:00
can1357 ce1ec2103f Merge PR #7006: fix(tools): stop browser automation from stealing focus in an attached browser (@terrxo)
# Conflicts:
#	packages/coding-agent/src/tools/browser/tab-supervisor.ts
2026-07-31 19:42:12 +02:00
can1357 9c1facec10 test(browser): cover attached tab navigation 2026-07-31 19:41:44 +02:00
can1357 6da7648262 Merge PR #7005: fix(tools): navigate to the requested url when opening an attached browser tab (@terrxo) 2026-07-31 19:41:44 +02:00
can1357 8f6305f772 fix(tools): preserve read continuation notice when spilling 2026-07-31 19:14:47 +02:00
can1357 ce6c57acb0 Merge PR #7117: fix(coding-agent): spill oversized read results to artifacts (@wolfiesch) 2026-07-31 19:14:46 +02:00
can1357 80a46c2d4c fix(coding-agent): avoid splitting parameter expansions 2026-07-31 19:07:18 +02:00
Vincent Huang 296ece7ea5 fix(coding-agent): handle input fd redirects in interceptor 2026-08-01 00:34:19 +12:00
Vincent Huang 270590c225 fix(coding-agent): avoid splitting Bash redirection operators 2026-07-31 23:51:18 +12:00
Vincent Huang edb0deebb4 fix(coding-agent): inspect compound Bash commands in interceptor rules
Match interceptor regexes against conservative, raw shell command segments
in addition to the complete command, so anchored rules can detect commands
after &&, ||, ;, |, &, and newlines without treating quoted or escaped text
as commands.

Add extractFlatShellCommandSegments() to preserve source text for
user-configured regexes, unlike the token-based approval matcher.
Add skipShellWord() and environment-assignment stripping so rules can match
commands prefixed with NAME=value assignments. Preserve the original command
in interception errors after extracting a leading cd command.
2026-07-31 23:26:43 +12:00
Wolfgang Schoenberger 5f9558d17a fix(tools): keep truncation metadata when spilling read output
The artifact spill wrapper dropped the read truncation metadata, so a
spilled oversized read lost its next-offset pagination hint, and an
artifact:// read of an already-spilled result was spilled a second time.
Preserve the existing truncation metadata and skip re-spilling artifact
reads.
2026-07-30 16:25:48 -07:00
Wolfgang Schoenberger 9a6a1b40be fix(coding-agent): spill oversized read results to artifacts 2026-07-30 15:04:52 -07:00
Kyle McCleary 4337797565 Merge remote-tracking branch 'origin/main' into feat/security-native
# Conflicts:
#	packages/coding-agent/src/tools/index.ts
2026-07-29 23:26:22 -07:00
Kyle McCleary 0b968bbb49 feat(security): integrate Codex Security cloud scans 2026-07-29 23:24:26 -07:00
can1357 e05f229f43 refactor: standardized editing syntax by removing copy and delete operations
- Removed copy and delete operations across tokenizer, parser, grammar, and clipboard logic.
- Standardized line-editing operations and block resolvers to use cut exclusively.
- Updated documentation, prompts, and test suites to reflect the removal of copy and delete syntax.
2026-07-30 07:42:48 +02:00
roboomp d0649f9917 fix(browser): reused shared temp removal retries
Route Chromium profile cleanup through pi-utils removeWithRetries while preserving browser-specific warn-and-leave behavior.

Fixes #7058
2026-07-30 05:22:14 +00:00
can1357 9aada058ee feat(hashline): implemented clipboard operations in hashline engine
- Implemented clipboard register management, parsing, and execution rules for CUT, COPY, and PASTE operations in the hashline engine.
- Added session-persistent clipboard state and integration across agent session execution, diff previews, and streaming tools.
- Added comprehensive validation, error messages, recovery handling, and test coverage for clipboard and block operations.
2026-07-30 07:21:43 +02:00
roboomp 7ab3d2ecb6 fix(browser): cleaned headless profile after failed launch
Remove the OMP-owned Chromium user-data directory when executable resolution or puppeteer launch fails before a browser handle exists.

Fixes #7058
2026-07-30 05:19:18 +00:00
roboomp afd6f8eed4 fix(browser): own headless chromium profile dir to survive windows ebusy cleanup
launchHeadlessBrowser let puppeteer-core create and delete a temporary
Chrome profile via an unretried rm() from an eager process-exit hook. On
Windows, when an orphaned browser tree still held the profile lock, that
rm threw EBUSY and rejected the eager promise with no handler attached,
crashing OMP with an unhandled rejection during cleanup.

OMP now passes an explicit --user-data-dir, which makes puppeteer treat
the profile as non-temporary (ChromeLauncher.cleanUserDataDir becomes a
no-op), and removes the directory itself on dispose with lock-tolerant
retry, warning and leaving it in place if it stays busy rather than
crashing.

Fixes #7058
2026-07-30 05:09:26 +00:00
Kyle McCleary dba303e2e0 Merge remote-tracking branch 'origin/main' into feat/security-native 2026-07-29 20:31:08 -07:00
Kyle McCleary d90e54fb09 fix(coding-agent): harden native security workflow 2026-07-29 20:05:57 -07:00