Commit Graph
4449 Commits
Author SHA1 Message Date
oldschoolaandcan1357 fd8593b190 test(coding-agent): pass autoApprove context to direct bash call in sdk-move-cwd
sdk-move-cwd.test.ts also calls bashTool.execute directly without context,
hitting the same approval gate as the eval cleanup tests. Same fix.
2026-05-26 20:53:34 +02:00
oldschoolaandcan1357 fc31e71e21 test(coding-agent): pass autoApprove context to direct eval tool calls
The approval gate added in 0efa60b7d requires either a UI runner or an
autoApprove context flag. The python-cleanup tests call EvalTool.execute
directly, bypassing the agent loop that normally supplies context.

Pass { autoApprove: true } as AgentToolContext at three direct call sites.
This matches the in-loop behaviour for tests that opt into approval-free
execution and unblocks CI for #1378.
2026-05-26 20:53:34 +02:00
oldschoolaandcan1357 4d26453a0b feat(coding-agent): restore per-tool approval policies with safer defaults
Re-introduces the per-tool approval system from luzidd's commit 39124f3 (which
is no longer reachable from main) and improves it before re-landing.

What's restored:
- ApprovalPolicy (allow/deny/prompt) plus DEFAULT_APPROVAL_POLICIES.
- ACTION_EXCEPTIONS registry (LSP read-only, bash critical patterns).
- getApprovalPolicy() six-level resolution order.
- ExtensionToolWrapper.execute() gate before extension handlers.
- --auto-approve / --yolo CLI flag and tools.approval.<tool> user config.
- docs/approval-mode.md user guide.

What's improved over the original:
- Replaced unchecked 'as any' casts with typed unknown narrowing helpers.
- Validate userConfig values: invalid strings, numbers, etc. fall through to
  the built-in default instead of being silently honoured (typo no longer
  locks a tool out or grants implicit approval).
- Expanded CRITICAL_BASH_PATTERNS: chmod -R /, chown -R /, bash <(curl ...),
  writes to /etc/passwd|shadow|sudoers, shutdown/reboot/halt/init 0,
  kill -9 1, nc -e / nc -c reverse shells. Pattern shapes require a
  command-position boundary so 'npm run reboot-tests' and 'echo "shutdown the
  queue"' don't false-positive.
- Added DEBUG_READONLY_ACTIONS exception so DAP inspection actions (threads,
  stack_trace, variables, scopes, read_memory, …) auto-allow while
  execution-side actions (launch, attach, continue, evaluate, write_memory,
  set_breakpoint, …) still prompt.
- formatApprovalPrompt: labels mcp__<server>__<tool> calls as MCP server
  tools, surfaces ssh host + command, recognises the modern § hashline header
  for edit, and truncates >240-char fields so a heredoc-sized body cannot
  blow out the confirmation dialog.
- Test suite grown from 40 to 57 cases — new coverage for invalid user
  config, the extended critical-bash patterns, benign-keyword negatives,
  debug exceptions, MCP/ssh prompt formatting, and command truncation.

Verification:
- bun test packages/coding-agent/test/tools/approval.test.ts -> 57 pass
- bun x biome check . -> clean
- bun run check:ts across all 9 workspaces -> clean
2026-05-26 20:53:33 +02:00
can1357 7f08b51f28 test(tests): updated test setup to use shared E2E helpers and reset settings
- Updated the auth-gateway OpenAI responses caching test to use shared E2E helper utilities and the common gateway URL constant.
- Initialized and reset in-memory settings in the nested live rendering test fixture to isolate test state between runs.
2026-05-26 20:51:03 +02:00
can1357 3078d31a4c chore: reformat 2026-05-26 20:44:09 +02:00
Can BölükandGitHub 8448a67602 Merge pull request #1374 from superhedge22/fix-review-enter-submit
Fix /review custom instructions submission
2026-05-26 21:40:15 +03:00
can1357 1d8ee5a891 refactor(yield): migrated to scheduler.wait with abort support and gate
- Replaced Bun.sleep with scheduler.wait for Node-compatible cancellable sleeps.
- Added module-level timestamp gate to skip yields within 50ms of the last one.
- Threaded AbortSignal through ExponentialYield.sleep to cancel losing timers in race.
- Added tests covering gate behaviour and stray-timer cancellation.
2026-05-26 20:37:39 +02:00
Can BölükandGitHub 1595c4c766 Merge pull request #1396 from hezhiyang2000/fix/bash-busy-wait-yield
fix: prevent busy-wait in agent loop and bash executor
2026-05-26 21:34:37 +03:00
can1357 bc9833d422 feat(mcp): added validation and warning for invalid OMP_MCP_TIMEOUT_MS
- Rejected negative values in addition to non-numeric ones, falling back to per-server config or default 30s.
- Emitted a logger warning when an invalid env value is ignored.
- Added tests covering negative and non-numeric rejection cases.
2026-05-26 20:30:02 +02:00
Can BölükandGitHub a2f4c70299 Merge pull request #1415 from omsrisrieternalradhakrsna/mcp-timeout-env-override
Allow disabling MCP client timeouts
2026-05-26 21:29:19 +03:00
Can BölükandGitHub 70480e9875 Merge branch 'main' into fix/coding-agent-misc 2026-05-26 21:27:39 +03:00
Can BölükandGitHub e1b52714be Merge pull request #1398 from justadudewithtime/feat/resolved-model-badge
feat(coding-agent): surface resolved subagent model badge in task widget
2026-05-26 21:25:57 +03:00
Can BölükandGitHub 6ef05f42a7 Merge pull request #1389 from oldschoola/fix/lsp-edits-and-identifiers
fix(coding-agent/lsp): accept $-prefixed identifiers; apply documentChanges in declared order
2026-05-26 21:25:35 +03:00
can1357 7f27627a90 feat(mcp/oauth): added RFC 8414 path-ful issuer form to OAuth discovery
- Extended `buildWellKnownUrls` and `#resolveRegistrationEndpoint` to try `/.well-known//` as a third candidate after origin-root and path-prefixed forms.
- Fixed single-segment path handling so `/my-service` is treated as the gateway prefix rather than dropped.
- Fixed missing `await` on `#tryWellKnownForRegistration` that caused path-prefixed fallback to return an unresolved Promise.
- Added tests for single-segment prefix discovery and RFC 8414 path-ful issuer fallback.
2026-05-26 20:22:25 +02:00
can1357 ab74ef3cac fix(edit): rendered inline op payloads in streaming edit preview
- Adjusted hashline natural-order preview handling so op-insert and op-replace tokens now emit inline body content as payload when available.
- Added an inline-body presence check so those op tokens are skipped only if path or payload is missing for that line.
2026-05-26 20:22:25 +02:00
can1357 c31daf0805 feat(coding-agent): expanded find tool to return matching directories with slash markers
- Dropped the `fileType: natives.FileType.File` restriction so glob searches can return directories as well as files.
- Updated the find tool prompt to document directory results and trailing-slash output.
- Added tests verifying directory matches are included and emitted with a trailing `/`.
2026-05-26 20:22:25 +02:00
can1357 8a32eceb53 fix(utils): clamped usage durations to suppress stale negative reset countdowns
- Clamped `formatDuration` to return `0ms` for non-positive, NaN, or infinite inputs.
- Updated usage report rendering to suppress reset countdowns when `resetsAt` is absent or no longer in the future.
- Added unit tests for `formatDuration` covering clamped values and standard duration formatting.
2026-05-26 20:22:25 +02:00
Can BölükandGitHub 69798a4f3b Merge pull request #1325 from oldschoola/fix/heredoc-deadlock-windows-macos
fix(pi-shell): unblock bash heredocs >4 KiB on Windows and >64 KiB on macOS
2026-05-26 21:22:07 +03:00
Can BölükandGitHub 0e1807a49c Merge pull request #1407 from faizhasim/oauth-path-prefix-fix
feat(coding-agent): support OAuth discovery for path-prefixed auth servers behind gateways
2026-05-26 21:20:29 +03:00
oldschoolaandcan1357 b48cf6d255 fix(pi-shell): preserve heredocs on no-thread targets 2026-05-26 20:12:39 +02:00
oldschoolaandcan1357 ae927b6f81 fix(pi-shell): unblock bash heredocs >4 KiB on Windows and >64 KiB on macOS
brush_core::interp::setup_open_file_with_contents wrote the entire heredoc/here-string body into an anonymous pipe synchronously before handing the reader to the downstream command. Bodies that exceed the OS pipe buffer (~4 KiB on Windows, 16-64 KiB on macOS) deadlocked the writer forever, and the bash tool tripped its 305 s hard timeout without ever launching the consumer. The Linux fast path still uses F_SETPIPE_SZ to grow the pipe inline; every other platform (and Linux bodies that overflow pipe-max-size) now decouples the write onto a fire-and-forget thread that terminates on drain or BrokenPipe.

Adds a 256 KiB regression test that exercises the worst-case shape (: builtin, which never drains stdin), guarded by tokio::time::timeout(10s) so a regression fails CI fast instead of hanging.
2026-05-26 20:12:39 +02:00
can1357 07d13ba15e refactor(auth-broker): migrated OAuth flow from pi-ai CLI to AuthStorage
- Migrated OAuth provider authentication from standalone `pi-ai` CLI to in-process `AuthStorage.login()` flow in coding-agent.
- Made provider argument optional for `login` and `logout` commands with interactive provider picker when omitted.
- Added `list` command to enumerate registered OAuth providers with optional `--json` output format.
- Removed `pi-ai` CLI binary and `bin` entry from @oh-my-pi/ai package; library API remains unchanged.
- Updated documentation and examples to reflect new `omp auth-broker` command interface and in-process OAuth flow.
2026-05-26 19:56:43 +02:00
can1357 664a47dba9 Merge remote-tracking branch 'origin/farm/2867ed83/google-vertex-model-list' 2026-05-26 19:51:58 +02:00
can1357 181304c724 fix(coding-agent/session): reduced default grep match column limit
- Reduced DEFAULT_MAX_COLUMN from 1024 to 512 in streaming-output handling, lowering the default max characters retained per grep match line.
2026-05-26 19:51:53 +02:00
roboomp 016adfbee9 fix(model-registry): gated bundled vertex drop on fresh authoritative cache
Threaded cache freshness/authoritativeness through #loadCachedStandardProviderModels so dropProviderModels only fires when the cached Vertex project-catalog row is both fresh and authoritative. A stale or non-authoritative snapshot (e.g. after ADC discovery failure rewrote the row with authoritative=0) now keeps the bundled Gemini fallback in place, which would otherwise be the last working catalog in API-key-only environments.

Refs #1412
2026-05-26 17:00:48 +00:00
can1357 6899e0aaed chore: bump version to 15.4.3 2026-05-26 18:55:58 +02:00
can1357 15820c1a2f Merge remote-tracking branch 'origin/farm/2867ed83/google-vertex-model-list' 2026-05-26 18:54:43 +02:00
can1357 eb97859995 fix(coding-agent): improved run lookup and made test temp directories unique
- Updated `TempDirGuard` creation in grep tests to include PID and an atomic sequence, preventing temp path collisions.
- Removed the `branch` filter from GitHub action run queries so results are matched by `head_sha` only.
- Adjusted run-watch calls to the simplified `fetchRunsForCommit` interface without the branch argument.
2026-05-26 18:54:22 +02:00
SUPREME e415adecd5 Allow disabling MCP client timeouts 2026-05-26 22:05:41 +05:30
roboomp 8fc200f6e8 fix(providers): discovered vertex project models
Added Google Vertex OpenAI-compatible model discovery with ADC auth and treated authoritative Vertex project catalogs as replacements for bundled Gemini fallbacks in the model registry.

Fixes #1412
2026-05-26 16:34:53 +00:00
can1357 38b7966894 chore: bump version to 15.4.2 2026-05-26 17:51:35 +02:00
can1357 633cb1e98a Merge remote-tracking branch 'origin/farm/be687d0f/fix-planmode-subagent-missing-yield' 2026-05-26 17:48:28 +02:00
Brit 884980bafa feat(settings): highlighted changed settings 2026-05-26 17:40:19 +02:00
roboomp 5955eb13f7 style: bun run fix 2026-05-26 15:14:48 +00:00
roboomp 7487eb330b fix(task): activate yield tool when subagent has explicit tool list
Plan-mode subagents (and any subagent with an explicit `agent.tools` array)
were given the `yield` tool in the registry but not in
`agent.state.tools`. The session prompts and idle reminders still
demanded a `yield` call to terminate, so the model would reason
"there doesn't seem to be a yield tool available" and the turn went
nowhere.

`createTools` correctly appends `yield` to the registry when
`requireYieldTool: true`, but `createAgentSession` then derived the
active tool list from `options.toolNames` directly, dropping `yield`
again. Mirror the invariant already enforced in
`parseAgentFields` (discovery/helpers.ts): when `requireYieldTool` is
set and the caller passes an explicit list, append `yield` to it
before normalization.

Fixes #1408
2026-05-26 15:14:27 +00:00
can1357 774d32cc3f chore: bump version to 15.4.1 2026-05-26 16:53:12 +02:00
Mohd Faiz Hasim 96d4a4ce3b Merge branch 'main' of github.com:can1357/oh-my-pi into oauth-path-prefix-fix 2026-05-26 22:53:11 +08:00
Mohd Faiz Hasim 5be0f01a91 feat(coding-agent): support OAuth discovery for path-prefixed auth servers behind gateways
- Extract resource_metadata URL from WWW-Authenticate and follow RFC 9728 chain
- Add buildWellKnownUrls with path-prefixed well-known fallback for gateways
- Fix resolveRegistrationEndpoint to try path-prefixed well-known (was missing await)
- Support relative Mcp-Auth-Server URL resolution against server URL
- Pass resourceMetadataUrl through all discoverOAuthEndpoints call sites
- Add comprehensive tests for path-prefixed, resource_metadata, and relative URL flows
2026-05-26 22:50:32 +08:00
can1357 796c437dc1 feat: overhauled stream timeout and eval session management
- Replaced external watchdog timers with per-request SDK timeouts for first-event budget across OpenAI, Anthropic, and Azure providers.
- Keyed Python shared kernels by (sessionId, cwd) to prevent cross-directory state bleed.
- Deduplicated concurrent cold-start session acquisition for JS and Python executors.
- Moved `isOpenAIResponsesProgressEvent` to shared module and scoped display output routing per run for interleaved async cells.
2026-05-26 16:49:11 +02:00
can1357 8da054f4cc Merge remote-tracking branch 'origin/farm/6a360fa4/fix-local-pdf-reading' 2026-05-26 15:29:04 +02:00
can1357 5d7a452f11 test(coding-agent/eval): updated eval tests to inject runtime hooks explicitly
- Refactored console-table tests to build explicit RuntimeHooks and pass them to JsRuntime.run.
- Refactored image coercion tests to pass explicit RuntimeHooks into JsRuntime.displayValue instead of constructor hooks.
2026-05-26 15:28:10 +02:00
can1357 67b6685935 feat: added irc.timeoutMs configuration option to settings schema
- Added irc.timeoutMs configuration option to settings schema with 120-second default and preset timeout values.
2026-05-26 15:27:16 +02:00
can1357 a450bbf9a6 fix: corrected runtime execution context variable from session.cwd to msg.session.cwd
- Corrected runtime execution context variable from session.cwd to msg.session.cwd to use correct execution context.
2026-05-26 15:27:16 +02:00
can1357 076ca4e71d test(hashline/payload-syntax): migrated to inline payload syntax
- Updated hashline parser tests to use inline payload syntax (e.g., `tagvpayload` instead of `tagv\npl(payload)`).
- Removed deprecated test cases for bare-blank-line and explicit-blank-payload syntax.
2026-05-26 15:27:06 +02:00
can1357 40f675dad8 feat(hashline/payload-syntax): enforced inline-first payload semantics for hashline
- Enforced strict inline-first hashline payload semantics, removing fallback to empty payload array and requiring explicit inline notation.
- Updated patch syntax documentation to require inline payload notation (e.g., `LINEv[payload]`) instead of separate-line payloads.
- Simplified nullish coalescing in executor by replacing ternary checks for undefined `inlineBody` with `??` operator.
- Consolidated payload rules, brace-handling guidance, and examples across tool documentation and prompt templates.
2026-05-26 15:27:05 +02:00
can1357 5364a9bfd0 refactor(tool-discovery): simplified tool discovery API by removing MCP-specific shims
- Removed deprecated MCP-specific type aliases and functions from tool-discovery module, consolidating to unified generic tool discovery API.
- Migrated session and SDK code to use generic filterBySource() and collectDiscoverableTools() instead of MCP-specific variants.
- Removed deprecated interface members including hasQueuedMessages(), FocusPane, AcpBuiltinCommandRuntime, and legacy settings methods.
- Updated test suites to use renamed generic discovery methods and removed back-compat test coverage for legacy MCP shapes.
2026-05-26 15:27:05 +02:00
can1357 9a2cc3bda0 feat(eval/py): added runtime environment and working directory support to Python kernel execution
- Added `cwd` and `env` optional parameters to kernel execution API for runtime working directory and environment variable control.
- Implemented runtime environment setup in Python runner with `_apply_request_runtime()` to apply cwd and env from request before code execution.
- Enhanced SIGINT handler management with `active_executions` counter and `_begin_exec_sigint()` / `_end_exec_sigint()` functions to prevent state mutation during concurrent execution.
- Changed `SearchRenderArgs.paths` parameter type from `string[]` to `string | string[]` to accept single string paths.
- Added comprehensive test coverage for kernel cwd updates, timeout interruption safety, and SystemExit handling in shared executor sessions.
2026-05-26 15:26:29 +02:00
can1357 bb4c9cae1e feat(coding-agent): added configurable IRC timeout with AbortSignal cancellation
- Added configurable IRC message timeout setting with 120-second default to prevent indefinite hangs.
- Implemented timeout enforcement for IRC send operations using AbortSignal-based cancellation.
- Modified Python tool bridge to route concurrent evaluations using per-run identifiers alongside session IDs.
- Enhanced test coverage for IRC timeout behavior, tool validation, and ephemeral cache key separation.
2026-05-26 14:56:49 +02:00
can1357 0bf1684b97 docs(tools): updated search tool docs to reflect string or array paths support
- Updated type signature to show `paths` accepts `string | string[]` instead of only arrays.
- Clarified that single string paths are wrapped into a one-element list before resolution.
- Improved prompt instructions to explicitly show both string and array usage patterns.
2026-05-26 14:45:15 +02:00
can1357 8a5b3e9552 feat(eval): added shared executor inheritance for subagents with concurrent async cells
- Removed per-session run queues from JS and Python backends, allowing async cells on the same session id to interleave.
- Introduced `getEvalSessionId` on ToolSession so subagents spawned via `task` inherit the parent's executor id and share JS VM and Python kernel state.
- Switched JS runtime state from module-level fields to AsyncLocalStorage so concurrent runs route output and tool calls to their own context.
- Changed Python runner to an asyncio event loop with per-request tasks and ContextVar-based run id tracking for concurrent execution.
- Added mtime-based module cache eviction to preserve singleton state across re-imports of unchanged local files.
2026-05-26 14:37:56 +02:00