Commit Graph

5981 Commits

Author SHA1 Message Date
YeonGyu-Kim 39fb0143da Merge pull request #3986 from code-yeongyu/fix/continuation-message-dispatch
fix(continuation): mark resumed prompts synthetic
2026-05-13 13:46:23 +09:00
YeonGyu-Kim 36f51ddb16 fix(continuation): mark fallback resumes synthetic 2026-05-13 13:36:25 +09:00
YeonGyu-Kim 1189b96d42 fix(continuation): mark atlas resumes synthetic 2026-05-13 13:25:01 +09:00
YeonGyu-Kim e49ba94728 chore(deps): refresh platform lock entries 2026-05-13 13:15:14 +09:00
YeonGyu-Kim 38b1433ff5 fix(continuation): mark resumes synthetic 2026-05-13 13:09:26 +09:00
YeonGyu-Kim 3f92264311 fix(interactive-bash): prohibit tmux kill-server 2026-05-13 13:07:13 +09:00
YeonGyu-Kim 286f5ccfdf when publish always discord 2026-05-13 11:44:47 +09:00
github-actions[bot] 9edaa6e90b release: v4.1.0 2026-05-13 02:32:42 +00:00
YeonGyu-Kim 21460713e3 .opencode to .agents 2026-05-13 11:08:08 +09:00
YeonGyu-Kim a0b46309b4 remove hyperplan for .opencode (not as a feature) 2026-05-13 10:59:15 +09:00
YeonGyu-Kim 75825eb9a6 fix(todo-description-override): add OpenCode schema contract for string priorities 2026-05-12 18:18:52 +09:00
YeonGyu-Kim c740ed8aca fix(delegate-task): route sync prompts by directory 2026-05-12 18:14:17 +09:00
YeonGyu-Kim 6035a551ad fix(background-agent): route session prompts by directory 2026-05-12 18:13:39 +09:00
YeonGyu-Kim 7d09d2c83c Merge pull request #3967 from code-yeongyu/refactor/typescript-no-excuse-slops
Remove unsafe TypeScript test assertions
2026-05-12 17:27:38 +09:00
YeonGyu-Kim 730d72c9af test: require explicit unsafe test value type
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 16:30:00 +09:00
YeonGyu-Kim d5fbada13d test: make unsafe test coercion explicit
Move test coercion out of a hidden global and require each test to import the helper so review tools and runtime scripts can see the unsafe boundary.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:51:31 +09:00
YeonGyu-Kim ce5da13fc5 test: add bun types to test setup
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:48:46 +09:00
YeonGyu-Kim 2fc1786077 test(hashline): remove unsafe test assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:48:46 +09:00
YeonGyu-Kim fb135d047c test(tools): remove unsafe test assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:48:46 +09:00
YeonGyu-Kim 8b093a1115 test(shared): remove unsafe test assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:41:17 +09:00
YeonGyu-Kim f05aeaa63a test(plugin): remove unsafe test assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:41:17 +09:00
YeonGyu-Kim 0787867384 test(ralph-loop): remove unsafe fixture assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:41:17 +09:00
YeonGyu-Kim 23211159c9 test(hooks): remove unsafe test assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:41:17 +09:00
YeonGyu-Kim 11b3638493 test(features): remove unsafe test assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:41:17 +09:00
YeonGyu-Kim 7365163885 test(cli): remove unsafe test assertions
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:41:17 +09:00
YeonGyu-Kim 9c6090a208 test: add typed test coercion helper
Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-12 15:41:17 +09:00
YeonGyu-Kim 4150092e9a test: run suite through isolated mock runner 2026-05-12 15:30:45 +09:00
YeonGyu-Kim cde14b5e37 fix(call-omo-agent): restrict callable agents 2026-05-12 15:28:57 +09:00
YeonGyu-Kim 9ffef79dbb fix(ralph-loop): ignore synthetic idle replays 2026-05-12 15:28:46 +09:00
YeonGyu-Kim 07797e1975 fix(background-agent): preserve direct all-complete replies 2026-05-12 15:28:35 +09:00
github-actions[bot] 2d20037d35 @jas32096 has signed the CLA in code-yeongyu/oh-my-openagent#3966 2026-05-12 04:48:25 +00:00
YeonGyu-Kim d82f6a6024 fix(background-agent): refresh stale todo state 2026-05-12 13:28:40 +09:00
YeonGyu-Kim ec3a7bb1ea Merge pull request #3965 from code-yeongyu/fix/ralph-loop-prompt-result
fix(ralph-loop): return prompt dispatch failures
2026-05-12 13:24:33 +09:00
YeonGyu-Kim 2c0f8e4645 fix(ralph-loop): return prompt dispatch failures 2026-05-12 13:14:07 +09:00
YeonGyu-Kim 2d656bd6bf Merge pull request #3964 from code-yeongyu/fix/electron-bun-runtime-shims
fix(electron): eliminate raw Bun.* runtime calls so plugin loads on OpenCode Desktop
2026-05-12 13:00:49 +09:00
YeonGyu-Kim 8e07ef642e fix(mcp-oauth): use fixed localhost base for callback URL parsing
Cubic AI reviewer flagged the use of the untrusted Host header as the
URL base in startCallbackServer. The server only binds to 127.0.0.1,
so hardcoding "http://127.0.0.1" as the URL base is robust against
malformed or manipulated Host values and matches upstream behavior
prior to the node:http refactor.
2026-05-12 12:54:24 +09:00
YeonGyu-Kim 100819f0bc ci: build plugin before running tests
The dist-bundle regression tests in
src/shared/dist-bundle-bun-globals.test.ts are guarded by
`test.skipIf(!existsSync("dist/index.js"))` and dist/ is
gitignored, so they silently skipped in CI which ran tests before
the build step. Adding the build step earlier ensures the
regression guard runs and a future raw `Bun.*` leak in the bundle
fails CI.
2026-05-12 12:46:50 +09:00
YeonGyu-Kim db3256baf6 test: harden dist-bundle regression guard + Node smoke test
Existing test only checked `globalThis.Bun` top-level destructures
and `__require` calls. Add two new test cases:

1. Raw Bun runtime API scanner: scans dist/index.js for any
   `Bun.<anyMethod>(` or `Bun.<anyMethod>.` call outside shim-safe
   patterns (runtime.Bun, globalThis.Bun, typeof Bun, and the
   "Bun is not defined" error-message string). Uses a negative
   lookbehind so shim indirection (`runtime.Bun.foo`) passes.

2. Node smoke test: imports dist/index.js under
   `node --input-type=module` and asserts stderr contains no
   `ReferenceError` and no `Bun is not defined`. The existing
   case 3 only checked exit code, which masked lazy-evaluation
   crashes that fire after import. Reading exports forces lazy
   module-level evaluation paths to run.
2026-05-12 12:46:50 +09:00
YeonGyu-Kim 11529394aa refactor(cli): use Response(stream).text() instead of Bun.readableStreamToText
bun-install.ts streamToText() was reachable from the plugin bundle via
the cli/config-manager barrel re-export. Replace with the WHATWG
standard `new Response(stream).text()` pattern which works
identically in Bun and Node and avoids the last raw Bun.* runtime
call in dist/index.js.
2026-05-12 12:46:50 +09:00
YeonGyu-Kim 22c7e4eb8e refactor(mcp-oauth): replace Bun.serve with node:http in callback-server
The OAuth callback server was using Bun.serve, which would crash if
mcp-oauth code paths ever entered the plugin bundle. Switch to
node:http.createServer with the same WHATWG behavior:

- Binds to 127.0.0.1, preserves 200/400/404 status codes
- Translates fetch(Request)→Response to (req, res) callback style
- Clears OAuth timeout on success/error/missing-param paths
- Replaces server.stop(true) with server.close() for shutdown

Functional behavior and response bodies unchanged.
2026-05-12 12:46:50 +09:00
YeonGyu-Kim 2386cbd9b9 refactor(port-utils): drop Bun.serve in favor of node:net probe
isPortAvailable() previously bound a one-shot Bun.serve and stopped it.
That call was reachable from the plugin bundle through
src/shared/index.ts barrel re-export and crashed on Electron.

Switch to node:net.createServer().listen(port, host), which Bun fully
implements as well. Adds a 2s safety timeout and removes both
"error" and "listening" handlers on resolution to prevent listener
leaks. Behavior is bit-equivalent: returns true iff a server can bind
to (host, port) right now.

Test file is fully rewritten away from stale Bun.serve mocking. New
tests exercise: free-port detection via port 0, EADDRINUSE handling
via a real net.createServer blocker, findAvailablePort range
exhaustion, getAvailableServerPort auto-selection, 127.0.0.1 default
hostname binding, and probe-server resource cleanup.
2026-05-12 12:46:50 +09:00
YeonGyu-Kim 0aafe20a85 refactor: route raw Bun.file/write/hash/which/spawn through runtime shims
Eliminates 19 unguarded `Bun.*` runtime call sites in the plugin bundle
that crashed with `ReferenceError: Bun is not defined` under Electron.

Per-tool-call hot paths (executed on every Read/Edit):
- src/tools/hashline-edit/hash-computation.ts: Bun.hash.xxHash32 → bunHashXxh32
- src/tools/hashline-edit/hashline-edit-executor.ts: 8 sites via bunFile/bunWrite
- src/hooks/hashline-read-enhancer/hook.ts: Bun.file → bunFile
- src/hooks/hashline-edit-diff-enhancer/hook.ts: 2 sites via bunFile

Plugin-load paths:
- src/hooks/claude-code-hooks/config.ts and config-loader.ts: Bun.file → bunFile
- src/features/claude-code-mcp-loader/loader.ts: Bun.file → bunFile
- src/features/claude-code-plugin-loader/mcp-server-loader.ts: Bun.file → bunFile
- src/features/team-mode/deps.ts: Bun.spawn → spawn shim
- src/hooks/session-notification-utils.ts: Bun.which → bunWhich, also drops
  the bare `declare const Bun` ambient declaration
- src/shared/binary-downloader.ts: Bun.write → bunWrite

Pure mechanical API swaps. No control-flow or signature changes.
2026-05-12 12:46:50 +09:00
YeonGyu-Kim 4394f34225 feat(shim): add bun-file/hash/which shims with Node fallbacks
The plugin builds with `bun build --target bun` and runs under OpenCode
CLI (Bun SEA) but also under OpenCode Desktop (Electron / Node V8) where
`globalThis.Bun` does not exist. Mirror the existing `bun-spawn-shim.ts`
pattern for three more Bun runtime APIs:

- bun-file-shim: bunFile()/bunWrite() backed by node:fs/promises with
  ArrayBuffer slicing to avoid Node Buffer pool exposure
- bun-hash-shim: pure-JS XXH32, bit-exact with Bun.hash.xxHash32 verified
  by 1200-pair fuzz comparison so existing hashline LINE#ID tags remain
  stable across runtimes
- bun-which-shim: synchronous PATH walker with Windows .exe/.cmd/.bat/.com
  extensions plus isUnsafeCommandName guard that rejects path separators,
  parent traversal, drive letters and null bytes before any probe

Each shim uses the canonical `runtime.Bun !== undefined` detection and
delegates to native Bun under IS_BUN, otherwise uses Node primitives.
Each ships with a co-located test that exercises both branches via the
`node:vm.runInNewContext` pattern from bun-hash-shim.test.ts.
2026-05-12 12:46:50 +09:00
YeonGyu-Kim 4da48555ee fix(plugin): normalize event session ids
Handle OpenCode session events that carry the session ID under properties.info.id or properties.info.sessionID so background tasks and continuation hooks do not miss idle/error/delete events.

Add regression coverage for nested session.idle events completing background tasks and waking continuation hooks.
2026-05-12 12:32:26 +09:00
YeonGyu-Kim 4aa2a01e47 Merge pull request #3961 from code-yeongyu/fix/ultrawork-oracle-continuation
fix(ralph-loop): reject promptAsync error responses
2026-05-12 12:12:17 +09:00
YeonGyu-Kim 0de6bd7253 fix(ralph-loop): reject promptAsync error responses 2026-05-12 12:06:49 +09:00
acamq 67f90a819e Merge pull request #3956 from code-yeongyu/fix/web-audit-dependencies
fix(web): patch audit dependency advisories
2026-05-11 16:42:36 -06:00
acamq 33f62c4d36 fix(web): patch audit dependency advisories 2026-05-11 16:37:47 -06:00
acamq 6a9cad1bf7 Merge pull request #3955 from acamq/fix/supply-chain-audit-deps
fix(deps): patch vulnerable MCP transitives
2026-05-11 16:23:46 -06:00
acamq 6b93fbfd65 ci: enforce frozen bun installs 2026-05-11 16:18:19 -06:00