Commit Graph

6546 Commits

Author SHA1 Message Date
YeonGyu-Kim 5eabeb80f9 Merge pull request #4082 from PeterPonyu/fix/3685-notepad-no-write-fallback
fix(notepad-guard): refuse Write tool for .sisyphus/notepads files (#3685)
2026-05-21 00:37:27 +09:00
YeonGyu-Kim 85d03298b9 Merge pull request #4098 from sjawhar/feat/look-at-async
fix(look-at): rework session poller to wait for assistant response, not just idle
2026-05-21 00:15:22 +09:00
YeonGyu-Kim aa3187bfbb Merge pull request #4180 from JacobZyy/fix/plugin-hooks-merge 2026-05-21 00:14:58 +09:00
YeonGyu-Kim 343d9ed2fe Merge pull request #4099 from sjawhar/fix/mcp-reload-survival
fix(skill-mcp): allow MCP manager to accept connections after disconnectAll
2026-05-21 00:13:29 +09:00
YeonGyu-Kim 7a5b8d831e Merge pull request #4100 from sjawhar/fix/tmux-isolated-close-no-layout
fix(tmux): skip layout enforcement when closing isolated container pane
2026-05-21 00:11:55 +09:00
YeonGyu-Kim 12ed091e93 Merge pull request #4101 from sjawhar/fix/modalities-object-shape
fix(model-capabilities): handle object-shaped modalities in readModalityKeys
2026-05-21 00:10:29 +09:00
YeonGyu-Kim aa5eeaf892 Merge pull request #4102 from sjawhar/fix/skill-directory-param
fix(skill): pass directory to getAllSkills + fix async test timing
2026-05-21 00:08:40 +09:00
YeonGyu-Kim 3ee0209a41 Merge pull request #4113 from PeterPonyu/fix/3937-runtime-fallback-quota-patterns
fix(runtime-fallback): classify more provider quota error names
2026-05-21 00:07:08 +09:00
YeonGyu-Kim f35bb95634 Merge pull request #4114 from PeterPonyu/fix/3607-detect-shell-windows-msystem
fix(non-interactive-env): use powershell syntax on Windows regardless of SHELL/MSYSTEM (#3607)
2026-05-21 00:04:45 +09:00
YeonGyu-Kim c6d754d389 Merge pull request #4115 from PeterPonyu/fix/3726-glob-grep-broken-symlinks
fix(glob,grep): tolerate broken symlinks and non-fatal I/O warnings (#3726)
2026-05-21 00:03:53 +09:00
YeonGyu-Kim 8276eb6c53 Merge pull request #4121 from mguttmann/fix-4119
fix(delegate-task): default run_in_background and load_skills instead of throwing (fixes #4119)
2026-05-21 00:01:12 +09:00
JacobZyy 33f121b113 fix: add PATH to restricted hook env, protect HOME/CLAUDE_PROJECT_DIR from allowlist override, reset plugin hooks state in tests
- P1: When allowedEnvVars is provided, PATH was missing from the base
  restricted env, causing non-builtin commands to fail at exec time
- P2: Allowlisted HOME/CLAUDE_PROJECT_DIR could overwrite normalized
  values from getHomeDirectory()/cwd with ambient process.env values
- P2: Test suite mutated shared pluginHooksState singleton without
  resetting it in afterEach, causing cross-test state leaks
2026-05-20 22:49:05 +08:00
YeonGyu-Kim 3e9c3f8ada Merge pull request #4146 from LYY/fix/skill-shortname-fallback
fix: support unambiguous short skill names in delegated skill loading
2026-05-20 23:42:44 +09:00
YeonGyu-Kim 2fd627144a Merge remote-tracking branch 'origin/dev' into dev 2026-05-20 23:41:09 +09:00
YeonGyu-Kim 791825fc20 Merge pull request #4153 from MoerAI/fix/fallback-model-string-guard
fix(shared,delegate-task,claude-code-agent-loader): guard model parsers against non-string input (fixes #4145)
2026-05-20 23:40:33 +09:00
YeonGyu-Kim e246965789 Merge pull request #4154 from MoerAI/fix/todo-description-override-fires
fix(plugin): wire tool.definition handler so todo-description-override actually fires (fixes #3705)
2026-05-20 23:38:51 +09:00
YeonGyu-Kim b463acda72 Merge pull request #4171 from MoerAI/fix/multimodal-looker-tool-usage-guidance
fix(agents): declare multimodal-looker tool allowlist in prompt to prevent death loop on small VL models (fixes #4116)
2026-05-20 23:36:10 +09:00
YeonGyu-Kim eea27d6f7e fix(mcp): resolve local mcp runtimes
Resolve built-in local MCP runtime executables before handing command arrays to OpenCode so lsp and ast_grep do not depend on a bare node or bun lookup in the host PATH.

Keep source, dist, bootstrap, workspace-safety, and disabled_mcps behavior covered by focused tests and real OpenCode MCP status QA.

Plan: plans/fix-built-in-mcp-runtime-executables.md
2026-05-20 23:33:32 +09:00
YeonGyu-Kim 37be0d5691 Merge pull request #4174 from MoerAI/fix/cli-setup-alias-for-install
fix(cli): add 'setup' as an alias for the install command (fixes #4112)
2026-05-20 23:31:41 +09:00
JacobZyy 0a20844bd4 fix: address PR #4180 review - security, typing, and test coverage
- Apply mcp_env_allowlist to plugin hooks: intersect HTTP allowedEnvVars
  with MCP allowlist, set command allowedEnvVars to full MCP allowlist
- Scrub process.env in executeHookCommand when allowedEnvVars provided
- Add PluginHooksState class with per-directory Map storage
- Add PluginHooksConfig interface for typed boundary layer
- Pass directory context through hook-config-handler
- Add 16 tests across 4 files (40 assertions) covering allowlist
  filtering, env scrubbing, directory isolation, and edge cases
- Remove unnecessary 'as' type assertions, use discriminated union
  narrowing instead
2026-05-20 22:30:25 +08:00
YeonGyu-Kim fd6a7aed17 Merge pull request #4176 from jangByeongHui/fix/skill-mcp-env-allowlist-bypass-3995
fix(skill-mcp-manager): trust explicit skill MCP env vars (#3995)
2026-05-20 23:09:12 +09:00
YeonGyu-Kim 1e42c61026 fix(todo-continuation): normalize prompt agent
Todo continuation could reinject with a lowercase built-in config key such as hephaestus when no registered alias was available. OpenCode prompt dispatch expects the prompt-facing agent name, so the continuation failed with an agent-not-found error.

Normalize the dispatch fallback through the existing prompt agent display-name resolver and pin the lowercase Hephaestus regression.
2026-05-20 23:07:52 +09:00
YeonGyu-Kim 32f0e1e0af Merge pull request #4186 from lang-911/feat/grok-reasoning-effort
fix(model-heuristics): register Grok family so reasoningEffort survives on @ai-sdk/openai
2026-05-20 22:05:22 +09:00
YeonGyu-Kim 3e2662dc6d chore: update bun.lock 2026-05-20 19:46:11 +09:00
YeonGyu-Kim 5a6955053b Merge pull request #4206 from jeongjin0/fix/session-ready-background-tasks
fix(notification): suppress ready alerts during background tasks
2026-05-20 19:44:46 +09:00
YeonGyu-Kim 69e7ab4723 Merge pull request #4083 from PeterPonyu/fix/3724-slash-command-content-duplicated 2026-05-20 19:07:18 +09:00
YeonGyu-Kim 4611856176 Merge pull request #4172 from MoerAI/fix/team-mode-base-dir-chmod-eperm 2026-05-20 18:59:59 +09:00
github-actions[bot] efe0458cd3 release: v4.2.3 2026-05-20 09:36:37 +00:00
YeonGyu-Kim 4e4bb3613d docs(release): finalize v4.2.3 release notes 2026-05-20 18:25:12 +09:00
YeonGyu-Kim fbcc1435e2 fix(runtime-fallback): recognize completion progress events 2026-05-20 18:19:26 +09:00
YeonGyu-Kim 2f5fc7c4e9 fix(rules-core): block symlinked rule directory escapes 2026-05-20 18:19:17 +09:00
YeonGyu-Kim 330e437f08 docs(agents): regenerate hierarchical AGENTS.md for 2026-05-20
Sync the AGENTS.md hierarchy to current code state:

Drift fixes in 11 existing files
- Root: 2026-05-20 commit 39aadbf9f, ~2167 TS files, 120 barrel index.ts,
  57 src/hooks dirs, 297 (179 non-test) src/shared files, 11 OpenCode hook
  handlers in plugin-interface.ts, packages list adds ast-grep-mcp + rules-core,
  first-prompt-watchdog 206 LOC, parent-wake-notifier 587 LOC
- src/AGENTS.md: file counts, plugin-interface handler count
- src/shared/AGENTS.md: title + counts 278/170 -> 297/179
- src/hooks/AGENTS.md: 57 dirs, note unwired WIP (task-reminder,
  hashline-edit-diff-enhancer)
- src/features/AGENTS.md: module map with NON-TEST counts + sub-AGENTS.md
  column, 7 modules without sub-doc
- src/features/background-agent/AGENTS.md: add 12 newer files (parent-wake-
  notifier 587 LOC, loop-detector, error-classifier, fallback-retry-handler,
  process-cleanup, subagent-spawn-limits, session-status-classifier,
  compaction-aware-message-resolver, etc.)
- src/plugin/AGENTS.md: 11 handlers, add system-transform.ts + command-
  execute-before.ts + build-team-idle-wake-hint-client.ts
- src/config/AGENTS.md: note schema/internal/permission.ts
- src/cli/AGENTS.md: 8 commands including 'version'
- src/plugin-handlers/AGENTS.md, packages/web/AGENTS.md: date bump

New AGENTS.md in 4 directories
- packages/AGENTS.md: index of 15 packages (11 platform binaries + 2 MCP
  packages + rules-core + web), role map, conventions
- docs/AGENTS.md: WHERE TO LOOK table for 19 docs across 6 subdirs
- .opencode/AGENTS.md: 5 skills + 4 slash commands + relationship to .agents/
- .agents/AGENTS.md: superset migration target (9 skills + 4 commands)
2026-05-20 17:18:44 +09:00
YeonGyu-Kim 39aadbf9f0 fix(context-recovery): handle idle sessions 2026-05-20 17:02:18 +09:00
github-actions[bot] caa751aa62 @jeongjin0 has signed the CLA in code-yeongyu/oh-my-openagent#4206 2026-05-20 07:46:36 +00:00
신정진 60a23a557e fix(notification): suppress ready alerts during background tasks
Gate idle ready notifications on the existing background-task continuation marker so cmux does not receive premature ready alerts while delegated work is still active.

Constraint: Reuse marker state from background task lifecycle without adding new notification config

Rejected: Patch cmux directly | notification readiness belongs upstream in OMO

Confidence: high

Scope-risk: narrow
2026-05-20 16:40:45 +09:00
YeonGyu-Kim c197c24047 docs(agents): require merge commits for PRs 2026-05-20 15:30:33 +09:00
YeonGyu-Kim 2339606678 docs(release): expand v4.2.3 CHANGELOG and add OmO logo to README.ru.md
- CHANGELOG: detail BUG-A/B (team-mode delivery), BUG-C/D
  (runtime-fallback event/finish blind spots), BUG-E (parent-wake
  same-source reservation), BUG-F (markerless workspace rules); the
  packages/rules-core and packages/ast-grep-mcp extractions; the
  prompt-async-gate hold default change; the new symlink-escape security
  fix; the rules-core isolation note; and the v4.3.0 deferred items
  (prompt-async-gate.ts split, @ast-grep/napi stale dep cleanup).
- README.ru.md: add the OmO logo block so the Russian README matches
  README.md / README.ja.md / README.ko.md / README.zh-cn.md.
2026-05-20 15:29:16 +09:00
YeonGyu-Kim a0d75d15f6 docs(prompt-gate): document DEFAULT_PROMPT_ASYNC_POST_DISPATCH_HOLD_MS 250 -> 2000
The hold default jumped 8x in v4.2.3 to absorb slower-provider
session.error arrivals before reservation release. Update the RFC code
block, the prose default callout, and the retry-latency note so the
documented default matches src/shared/prompt-async-gate.ts.
2026-05-20 15:29:16 +09:00
YeonGyu-Kim b24dc6eeb8 fix(rules-core): isolate package + block symlink escape from rule sources
- Drop the back-import of src/shared/logger so @oh-my-opencode/rules-core
  stays free of host-adapter dependencies (ROADMAP package layering
  invariant). Expose setSisyphusRuleDeprecationLogger(logger) for hosts to
  inject their own logger; default is a noop.
- Wire the host injection in src/hooks/rules-injector/rule-file-finder.ts
  as a module-level side effect so existing behavior is preserved.
- Add realpath boundary check to findRuleFilesRecursive and
  validFileRealPath. Project rule scanners now refuse entries whose
  realpath escapes the rule-source root, closing the symlink-escape
  vector where a malicious repo could point .github/copilot-instructions.md
  (or any .omo/rules/* entry) at ~/.ssh/id_rsa and have the rule injector
  pull the secret into model context.
2026-05-20 15:29:16 +09:00
YeonGyu-Kim 89f6902617 Merge pull request #4205 from code-yeongyu/fix/comment-checker-apply-patch-payloads
fix(comment-checker): handle apply_patch payloads
2026-05-20 15:28:35 +09:00
YeonGyu-Kim b527725169 Merge pull request #4203 from code-yeongyu/fix/continuation-prompt-dispatch-20260520051014
fix(plugin): dispatch synthetic idle hooks
2026-05-20 15:23:10 +09:00
YeonGyu-Kim 3bd6302021 fix(comment-checker): handle apply_patch payloads
Accept apply_patch edits from nested result/metadata file lists and from raw patchText args when OpenCode does not provide direct metadata.files.

Forward tool args through the after-hook pipeline so comment-checker can inspect raw apply_patch inputs while preserving existing write, edit, and multiedit routing.

Tests: bun test src/hooks/comment-checker/hook.apply-patch.test.ts src/hooks/comment-checker/hook.before-after.test.ts src/plugin/tool-execute-after.test.ts

Tests: bun test src/hooks/comment-checker

Tests: bun run typecheck

Tests: bun run build
2026-05-20 15:21:12 +09:00
YeonGyu-Kim 7d9cc4fb98 Merge pull request #4204 from code-yeongyu/hotfix/og-static-deploy-fix
fix(web): switch OG to static PNG to unblock Cloudflare deploy
2026-05-20 15:19:18 +09:00
YeonGyu-Kim 6fd5e7c9ec fix(web): switch OG image from next/og to static PNG file convention
PR #4202 introduced dynamic OG via app/opengraph-image.tsx + app/twitter-image.tsx
using next/og ImageResponse. Build succeeds, but deploy to Cloudflare Workers
fails:

  ✘ [ERROR] Unable to extract npm package name from
    .open-next/server-functions/default/node_modules/next/dist/compiled/
    @vercel/og/yoga.wasm?module
  [plugin wrangler-module-collector]
  ##[error]The process '/home/runner/.bun/bin/bunx' failed with exit code 1

Root cause: wrangler-module-collector can't resolve @vercel/og's bundled
yoga.wasm import from the OpenNext server-functions output. Known regression
in @opennextjs/cloudflare interop with @vercel/og (related to issue #1163 +
PRs #1169/#1176 in opennextjs/opennextjs-cloudflare, plus newer bundling
discussion in #1221).

Fix: switch to Next.js file convention static OG images. Place
app/opengraph-image.png + app/twitter-image.png (the same 1200x630
PNG that was being rendered dynamically). Next.js auto-emits og:image +
twitter:image metadata pointing at these routes, with correct
og:image:width/height/type tags. No @vercel/og, no WASM, no edge runtime.

The static PNGs were generated from PR #4202's dynamic ImageResponse during
local QA - identical visual output: dark #0a0a0a background, cyan
#00d4ff brand wordmark, headline, install command pill, terminal cursor.

Build verified: /opengraph-image.png and /twitter-image.png now show as
static routes (0 B route handler size). First-load JS unchanged.

Future-revisit: re-enable dynamic OG when @opennextjs/cloudflare ships the
fixes from PRs #1169/#1176/#1221 stable for Next 15.x deploys.
2026-05-20 15:16:02 +09:00
YeonGyu-Kim 5154ab4c6f Merge pull request #4202 from code-yeongyu/feature/web-portfolio-refinement-20260520
feat(web): designer-portfolio refinement + dynamic OG + perf -46%
2026-05-20 15:10:13 +09:00
YeonGyu-Kim e9c44ddb1b fix(web): drop nested <main> on manifesto (WCAG 1.3.1)
LocalizedPageShell at app/_components/localized-page-shell.tsx:34
already renders <main className='flex-1'>{children}</main> as the
page landmark. The manifesto/page.tsx shell was wrapping that with
its own <main>, producing nested main landmarks (axe-core:
landmark-no-duplicate-main + landmark-main-is-top-level).

Switch outer wrapper to <div>; keep styling (bg-background,
text-foreground, min-h-screen, overflow-x-hidden) intact. The
inner <main> from the shell remains the canonical landmark.

Pre-existing on origin/dev (the pre-decomposition manifesto/page.tsx
also had a top-level <main>), surfaced by PR #4202 hands-on QA
via axe-core run on /ko/manifesto.
2026-05-20 15:00:22 +09:00
YeonGyu-Kim f5d5e9801b fix(web): hero Get Started CTA -> /docs#installation (closes #3848)
Get Started button previously linked to /docs (root), landing users on
Overview. Issue #3848 reporter and concurrent PR #3948 asked for a
deeper link straight to Installation.

lib/docs-sections.ts declares 'installation' as a stable section id
rendered via <section id={section.id}> in app/[locale]/docs/page.tsx,
so /docs#installation is a valid deep link.

This also supersedes the in-flight PR #3948 (which targets the
pre-decomposition landing-page.tsx).
2026-05-20 14:40:24 +09:00
YeonGyu-Kim 0ebba9eba1 fix(rules-injector): retry storage writes after cleanup race
The full Bun suite can remove the shared rules-injector storage directory between a parent-directory check and the file write. Save operations now create the directory immediately before writing and retry once if ENOENT still wins the race.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-20 14:35:28 +09:00
YeonGyu-Kim 4a72729acc fix(plugin): run idle hooks for synthetic status idle
OpenCode now treats session.status idle as the durable completion boundary, but the plugin only dispatched the synthetic session.idle through the main hook chain. Idle-only side effects such as tmux forwarding and team member idle continuations were skipped.

Route synthetic idle through the same idle-only hook path used by real session.idle events and pin the behavior with a regression test.

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-05-20 14:35:28 +09:00
YeonGyu-Kim 64997d5e81 test(web): responsive matrix — 6 viewports x 4 locales x 2 pages
e2e/responsive.spec.ts (new):

- 6 viewports: iPhone SE (375x667), iPhone 14 Pro (390x844),
  iPad mini (768x1024), iPad Pro (1024x1366), laptop (1280x800),
  desktop (1920x1080)
- 4 locales: en, ko, ja, zh
- 2 pages: landing /, manifesto /manifesto
- Checks: no horizontal scroll, no overflow-x, primary CTA visible,
  hero headline visible, nav button hit target (44x44 mobile / 32x32
  desktop)

48 tests total. All pass against current build.

/docs has pre-existing horizontal overflow at 1024px viewport
(fixed-width sidebar interacting with code blocks). Intentionally
out of scope for this PR — commented in the spec, tracked as
follow-up.
2026-05-20 14:27:02 +09:00