Commit Graph
8327 Commits
Author SHA1 Message Date
Mark IJbema facc157242 Merge remote-tracking branch 'origin/main' into mark/selected-organization-default
# Conflicts:
#	packages/kilo-jetbrains/backend/src/main/kotlin/ai/kilocode/backend/rpc/KiloAppRpcApiImpl.kt
2026-07-07 17:01:13 +02:00
Mark IJbema 7ea26b0ed5 refactor: apply cloud org as login-time default 2026-07-07 16:46:34 +02:00
Marius aa454ebe27 Merge pull request #12008 from Kilo-Org/feat/sandbox-writable-paths-ui-test
feat(sandbox): widen writable-paths settings input and add coverage
2026-07-07 15:55:16 +02:00
Marius a87a4e027d Merge pull request #12004 from Kilo-Org/design-reload-feature
feat: add /reload action to reboot the instance from disk
2026-07-07 14:56:58 +02:00
Christiaan Arnoldus 98583247cb Merge pull request #11969 from Kilo-Org/fix/fable-routed-model
Show actually used models when using fable
2026-07-07 14:50:24 +02:00
Mark IJbema d70977fd92 test: cover Kilo account selection defaults 2026-07-07 14:38:02 +02:00
marius-kilocode e29196c949 feat(sandbox): widen writable-paths settings input and add coverage
Widen the Additional Writable Paths input in the Sandboxing settings tab
so long filesystem paths are readable while typing, reusing the existing
wide-input variant without affecting the network toggle row.

Add tests for the sandbox_writable_paths behavior: real sandbox
enforcement that configured extra paths become writable while unlisted
paths and .git stay denied, and a config-scope test confirming the
setting is honored from global config only and dropped from project
config.
2026-07-07 14:35:34 +02:00
marius-kilocode 4ab34f1f4c test: add /instance/reload scenario to httpapi exercise
The coverage mode requires every documented endpoint to have a
scenario. Without this, test:httpapi fails with a missing scenario
for the new /instance/reload route.
2026-07-07 14:33:06 +02:00
Marius 6cdc26c1f2 Merge pull request #11995 from trim21/feat/sandbox-writable-paths
feat(sandbox): add configurable writable paths option
2026-07-07 14:24:15 +02:00
Mark IJbema 552167fc33 fix: preserve manual Kilo account selection 2026-07-07 14:08:03 +02:00
Mark IJbema b1d004d568 fix: avoid profile sync side effects 2026-07-07 13:54:38 +02:00
Mark IJbema 08f0bf6457 Merge pull request #11886 from Kilo-Org/mark/config-file-substitution-trust
fix(cli): block file/env references in untrusted project config
2026-07-07 13:37:17 +02:00
Christiaan Arnoldus 208ebfc6a7 Merge branch 'main' into fix/fable-routed-model 2026-07-07 13:36:56 +02:00
marius-kilocode 1c31d7ea49 fix: address review feedback on reload handler
- Block reload for retry and offline session states, not just busy
  (hasActiveSession rejects any non-idle state)
- Close TOCTOU race by calling store.reload inline instead of deferring
  to a pre-response handler, so the busy check and reload run in the
  same effect
- Avoid double-firing reloadAfterAuthChange: only call it eagerly for
  worktree sessions where the SSE directory check won't match; for the
  workspace root the existing SSE handler already fires it
- Replace err: any with unknown + narrowing
- Add in-flight guard to the CLI /reload plugin to prevent overlapping
  reloads from rapid double-invocation
- Remove the TaskHeader reload button (redundant with /reload slash
  command, avoids chat visual regression baseline churn)
2026-07-07 13:22:30 +02:00
marius-kilocode cef3dc7ae8 feat: add /reload action to reboot the instance from disk
Reboots the per-directory instance, reloading config, skills, agents,
commands, and MCP prompts changed on disk without restarting the
server. Sessions and history are preserved; only the per-directory
instance caches are torn down and rebuilt.

Server: POST /instance/reload wraps the existing atomic
InstanceStore.reload path (the same one project.git.init uses). The
rebuild completes before the 200 response, so clients can refetch with
no race. Returns 409 ConflictError while a session is actively
running. Emits the existing server.instance.disposed SSE event, which
the TUI and extension already use to auto-refetch.

CLI: /reload palette command calls the endpoint; the TUI already
bootstraps on server.instance.disposed.

Extension: /reload slash command, a reload button in the task header
and settings panel, and a Kilo Code: Reload Config and Skills command
palette entry. The handler clears the command cache and reuses
reloadAfterAuthChange to re-fetch config, providers, agents, skills,
and commands. Reload targets the current session's directory so Agent
Manager worktree sessions reload their own worktree instance rather
than the workspace root.

SDK: regenerate so client.instance.reload is available to external
integrations.
2026-07-07 12:38:12 +02:00
Trim21andkilo-code-bot[bot] af6bbd8c9f Update packages/opencode/src/config/config.ts
Co-authored-by: kilo-code-bot[bot] <240665456+kilo-code-bot[bot]@users.noreply.github.com>
2026-07-07 18:35:01 +08:00
trim21 e463069674 fix(sandbox): expand ~ in writable paths and restrict to global config only
- Expand leading ~ to os.homedir() in execute() before passing paths
  to the sandbox profile, so ~/tmp resolves correctly.
- Strip sandbox_writable_paths from project-scoped config overlays.
  A repo kilo.json must not be able to widen the sandbox beyond the
  user's global config intent.
2026-07-07 18:05:53 +08:00
Mark IJbema 81213b9f25 fix: respect unavailable personal Kilo accounts 2026-07-07 11:46:34 +02:00
Mark IJbema 61b9e0935c fix(cli): honor cloud-selected Kilo organization 2026-07-07 11:30:13 +02:00
Evgeny Shurakov 40790d8139 fix(cli): show remote badge in prompt status (#11976) 2026-07-07 09:32:11 +02:00
trim21 0d27eb17fd feat(sandbox): add configurable writable paths option
Add experimental.sandbox_writable_paths config option that allows users
to specify additional filesystem paths the sandbox permits writes to.
These paths are merged with the default writable paths when the sandbox
is active.

CLI: new config field + policy integration
VS Code: list input UI in the Sandboxing settings tab
2026-07-07 12:42:42 +08:00
Catriel Müller 9ce665d3ee Merge remote-tracking branch 'origin/main' into feat/cli-vim-mode-prompt 2026-07-06 16:03:20 -03:00
Catriel Müller ea0f5a044f Merge pull request #11223 from maphew/fix/cli-cloud-fork-session-import
fix(cli): import cloud sessions before validation
2026-07-06 14:44:53 -03:00
Johnny Eric Amancio b976b5a013 feat(cli): opt-in project memory (#11921)
* feat(memory): opt-in project memory — capture, recall, CLI + TUI integration

Add project memory: the standalone @kilocode/kilo-memory effect layer plus the
opencode CLI/server/TUI integration. Memory is disabled by default, so it is a
no-op until enabled (no behavior change when off).

Capture (turn-close consolidation): per-op parse salvage, secret redaction that
skips the offending op instead of aborting the batch, supersede-only auto-updates
(never model-driven deletes), correction-aware echo handling, non-LLM fallback
digests on interrupted/error turns, a shared interval throttle with idle-flush.

Recall + injection: keyword tokenizer with camelCase/compound splitting, light
stemming, and an English-first stopword filter (Unicode-aware; non-English falls
back to plain token-overlap), a live relevance floor, a budget-reserved startup
index, a session-digest catalog, and per-session prompt-cache pinning of the
injected memory block.

Surfaces: kilo_memory_save / kilo_memory_recall tools, the memory HTTP API
(contract schemas live in the package), and a status-focused TUI sidebar showing
auto-save, loaded context, and active recall, plus the /memory dialog.

* fix(memory): address PR review feedback

- C1: bump @kilocode/kilo-memory in the changeset
- C2: redact secrets before they hit the audit log (skip + salvage paths);
  redact before truncating in salvageTyped so a secret straddling the
  500-char cap can't leak an unmatched fragment; opText -> salvageText
- C3: de-abbreviate savedOperations, "changes" wording, ops.ts -> operations.ts
- C4: log.warn on the remaining silent-catch fallbacks (turn diff, memory
  context injection, tool-visibility check)
- C5: relocate memory storage from ~/.kilo to Global.Path.data, delete the
  now-dead needsDependencyInstall guard, add /memory status (root path) and
  /memory edit ($VISUAL/$EDITOR + auto-rebuild)
- C6: replace the hardcoded English stopword list with corpus-derived
  ubiquitous-term filtering (df across the user's own entries) and the
  English suffix stemmer with suffix-tolerant term matching, so recall
  noise-filtering works in any language
- C8: delete the CORRECTION_INTENT English regex; echo turns now run typed
  capture (digest stays echo-gated), bounded by the interval throttle, with
  the typed prompt as the language-agnostic content filter
- C9: exclude generated paths (dist/build/coverage/*.gen.*/*.map/snapshots)
  from the durable-diff churn fallback so generated churn can't burn a
  consolidation call
- C11: fix duplicated assert in httpapi-memory test; assert the error body
- kilo-code-bot batch: clause-boundary regex fix, byte-safe catalog
  truncation, max-length guards on remember/correct/forget payloads (text,
  query, key, sessionID), trim consistency in reconcile, param-shadowing
  rename, missing doc entry for kilo_memory_recall, dead-code removal,
  dialog UI fixes, memoryEnabledCache eviction bound, dedicated Configure
  schema, recall permission renderer, covered-session pointer cap, redact
  chat transcript before the consolidation model call, split configProtected
  metadata from disableAlways so memory-save prompts don't show config-file
  copy, drop unused MemoryService.layer provide from tool registry
- redact colon-separated low-entropy secrets too (password: hunterx),
  accepting the prose false-positive tradeoff (secret: enabled) in favor of
  not missing a real secret
- rename lastConsolidatedAt -> lastTypedConsolidationAt to make its narrow
  scope (typed-consolidation throttle clock) explicit; regen openapi/SDK
- drop now-dead home/config fields from MemoryPaths.Host after the data-dir
  relocation; add Process.splitCommand for quoted $EDITOR/$VISUAL paths with
  spaces, used by /memory edit and the pre-existing Editor.open utility

* refactor(memory): shared client helpers, capture hardening, /memory UX rework

- extract client-side derivations into kilo-memory so both frontends share
  one implementation: MemoryDecisions.summarize (decision-log summary),
  MemoryAutosaveStatus.summarize (autosave-status semantics), and
  MemoryMarkerMeta (marker wire contract encode/decode)
- match exact-key upserts via the canonical stored id (slugged key,
  normalized section) so a re-emitted spaced/uppercase key updates the
  entry instead of falling to fuzzy dedupe
- salvageTyped throws on valid JSON without an operations array so the
  caller's fallback path records a parse error instead of a silent
  zero-op success
- rename memory tool metadata files -> sources (stripPartMetadata rewrites
  tool-part metadata.files assuming apply_patch records, mangling string[])
- read state instead of status for tool enabled checks; dedupe TUI helpers
  (errorMessage, shared route(), Locale.number, relativeTime)
- /memory UX: bare /memory opens a help modal driven by a structured
  command catalog in kilo-memory; /memory on|off become the canonical
  toggle verbs (enable/disable kept as quiet aliases); /memory status opens
  a clean overview dialog (root path, autosave, startup context, source
  counts, index size) instead of a toast; /memory show is the single full
  audit view (inspect removed)
2026-07-06 17:45:49 +02:00
Christiaan Arnoldus dc99ae8f79 fix(cli): route fable model aliases 2026-07-06 15:55:31 +02:00
Evgeny Shurakov cd49ae633c CLI - Remote model catalog and WebSocket reconnection fixes (#11835)
* feat(cli): remote model catalog and WebSocket reconnection fixes

* fix(cli): preserve provider default semantics under truncation and deflake reconnect test

* fix(cli): omit provider default when per-provider truncation removes preferred model

* refactor(cli): simplify remote model catalog by removing size limits

* refactor(cli): strip remote model catalog to sanitize-and-shape only

* fix(cli): cap remote model catalog at MAX_MODELS

* fix(cli): preserve model metadata and enforce remote catalog limits

* fix(cli): omit currentModel and defaultModel when truncation drops them

* fix(cli): keep stable connection identity across reconnects

* feat(cli): include protocol version in remote session heartbeat
2026-07-06 14:48:30 +02:00
Mark IJbema 8dad071203 fix(cli): surface scope-blocked {file:} even under missing:empty; cover guard
Agent prompts substitute with missing:"empty", which swallowed every file read error — including a deliberate out-of-scope scope block — so an escaping {file:} was silently emptied and never warned, contradicting the agent.ts catch narrative. Tag security blocks as ConfigVariableGuard.BlockedError (out-of-scope, fd swap, /proc) and, in substitute(), always reject those regardless of missing:"empty"; genuine missing/IO errors are still emptied. Now an out-of-scope {file:} in an agent prompt rejects, hits the agent catch, and records a warning. Adds guard/substitute tests for the block-under-missing:empty, missing-is-emptied, and BlockedError classification cases.
2026-07-06 13:37:39 +02:00
Mark IJbema e06feff06c docs(cli): clarify {file:} rejection message is about a missing project scope
The message said file references are 'not allowed in project config', but in-root file references ARE allowed when a fileScope is supplied (the normal project path). This branch only fires when no scope was provided, so reword it to reflect that specific case and update the comment.
2026-07-06 12:02:05 +02:00
Mark IJbema 10e519d830 fix(cli): don't let a project agent substitution error break config loading
ConfigAgent.load() awaited ConfigVariable.substitute without a catch, so a throw (untrusted {env:} or out-of-scope {file:} in a project agent prompt) propagated through Effect.promise and failed the whole config load. Catch it, record a warning, and skip only the offending agent — mirroring the existing frontmatter-parse handling and the project config-file loops. Scope stays JSON-config-loading; the markdown substitution path (KilocodeMarkdown.substitute) remains the separate follow-up in #11889.
2026-07-06 11:58:18 +02:00
Mark IJbema c7f0ccf102 fix(cli): close non-Linux scope-check TOCTOU by verifying fd matches validated path
The read is fd-pinned, but on non-Linux the scope check realpath'd the caller's path independently of the fd, so an attacker could swap the path between open and check to validate an in-root inode while the fd pointed elsewhere. fstat the open fd and compare dev/ino against the resolved path; reject if they differ, so the inode we validate is the inode we read.
2026-07-06 10:40:59 +02:00
Mark IJbema faa2bae104 docs: clarify project {file:} rejects paths that escape the project root
In-root absolute paths are intentionally allowed; only references that leave the root (absolute paths outside it, ../ traversal, symlinks) are rejected. Fix the docs wording and add a regression test for the in-root absolute case.
2026-07-06 10:03:15 +02:00
Mark IJbema 47a40fe7f7 fix(cli): tolerate unsafe project config in settings overlay
KilocodeConfigOverlay.load() propagated InvalidError from untrusted {env:}/out-of-scope {file:} substitutions through Promise.all, breaking the whole /config/overlay instead of skipping the offending file. Skip failed files (log + return {}) so the settings overlay still shows remaining config, matching the main config loader's degrade-gracefully behavior.
2026-07-06 10:02:29 +02:00
Mark IJbema 1d49502b77 fix(cli): read config file references through the pinned fd to close TOCTOU race
On non-Linux, read() validated the target via realpath but re-read by path, letting an attacker swap the file between the check and the read. Read through the already-open FileHandle (file.readFile) on every platform so the validated inode is the one read. Drops the now-unused load callback.
2026-07-06 09:51:26 +02:00
Catriel Müller 10951d68ea Merge remote-tracking branch 'origin/main' into fix/cli-cloud-fork-session-import
# Conflicts:
#	packages/opencode/src/cli/cmd/tui/thread.ts
#	packages/opencode/src/kilocode/cli/cmd/tui/thread.ts
#	packages/opencode/test/kilocode/cli/tui/thread.test.ts
2026-07-03 18:05:01 -03:00
Catriel Müller 2be834fbfc refactor(cli): extract vim prompt logic into kilocode mirror
Move the vim modal editing engine and prompt integration out of shared
upstream files and into src/kilocode/ mirrors per the Fork Isolation Rule:

- src/kilocode/cli/cmd/tui/component/prompt/vim.ts (engine, moved)
- src/kilocode/cli/cmd/tui/component/prompt/index.tsx (new mirror with
  useVim, VimModeIndicator, vimToggleCommand)
- test/kilocode/cli/cmd/tui/prompt/vim.test.ts (moved)

The shared prompt/index.tsx now calls into the mirror behind minimal
kilocode_change markers instead of inlining ~200 lines of vim logic.
2026-07-03 17:54:37 -03:00
Catriel Müller 1fc8f066fd Merge pull request #11506 from mvanhorn/fix/11480-tui-live-spent-cost
fix(cli): show live session spend in TUI sidebar during active turn
2026-07-03 16:57:00 -03:00
kilo-maintainer[bot] 4ed43ab7c5 release: v7.4.1 2026-07-03 17:10:11 +00:00
Marius 771f8c880c Merge pull request #11923 from Kilo-Org/fix/11903-subagent-permission-hang
fix(cli): fail headless subagent permission asks instead of hanging
2026-07-03 18:38:10 +02:00
marius-kilocode b05cbcaca2 fix(cli): reject subagent asks over the wire for daemon and attach runs 2026-07-03 18:04:55 +02:00
marius-kilocode fda4e1756b fix(cli): fail headless subagent permission asks instead of hanging 2026-07-03 17:39:52 +02:00
Marius 51e45d7fb7 Merge pull request #11887 from Kilo-Org/mark/harden-allow-everything-auth
fix(cli): require auth for allow everything endpoint
2026-07-03 16:58:01 +02:00
kilo-maintainer[bot] c78d44a143 release: v7.4.0 2026-07-03 14:40:55 +00:00
Marius fcc1b64330 Merge branch 'main' into mark/harden-allow-everything-auth 2026-07-03 16:12:48 +02:00
marius-kilocode 4a5a6adf83 refactor(cli): move TUI worker auth derivation into kilo mirror module 2026-07-03 15:56:23 +02:00
Marius c993b645bd Merge pull request #11898 from Kilo-Org/alluring-flyingfish
fix(cli): keep sandbox disabled by default
2026-07-03 15:38:07 +02:00
marius-kilocode abe2f8e6e5 Merge origin/main into alluring-flyingfish 2026-07-03 15:17:24 +02:00
Marius c0b128f308 Merge pull request #11913 from Kilo-Org/understood-meerkat
fix(cli): retain shell output for fast-exiting commands
2026-07-03 15:13:08 +02:00
Johnny Eric Amancio c36c293f3c fix(cli): resolve plan_exit to the plan file actually saved (#11896)
plan_exit fell back to Session.plan()'s generated slug path whenever
the model omitted an explicit path, which no longer matched the
agent-chosen filename plan mode now instructs. That mismatch caused
both the wrong filename shown after "Plan is ready" and a silently
missing implement-next-session prompt (issue #11859).

plan_exit and the follow-up flow now verify the plan file exists,
recovering it via a session-timestamp glob or the plan agent's last
markdown write when the exact path is missing, and fail loudly with
actionable guidance when nothing was written.

The failure message also names an explicit path parameter that got
rejected (outside the project, or a directory), instead of silently
substituting a freshly-guessed filename that never matches what the
model actually wrote. This only affects wording of the final error:
Session.plan() and locate()'s recovery tiers still run first, so a
rejected path that's actually the canonical non-git plans dir (which
sits outside the project boundary by design) still recovers via the
timestamp glob rather than failing outright.
2026-07-03 14:54:14 +02:00
Marius 63255595c3 Merge pull request #11912 from Kilo-Org/exuberant-archer
feat(cli): persist /sandbox toggle across new sessions
2026-07-03 14:51:26 +02:00
marius-kilocode 70a002da47 fix(test): make tool/shell.test.ts deterministic (fast commands lost output)
tool/shell.test.ts intermittently failed in CI (e.g. falls back from
terminal-only configured shell [159.79ms]) with result.output being
"(no output)". Reproduced locally at ~13% across two test cases, so
this is a real timing race rather than a one-off flake.

Bun's child_process discards buffered stdout/stderr once the child emits
"close", and our CrossSpawnSpawner attaches stream readers lazily, so
fast-exiting processes lose all output before the reader attaches. The
same path serves the live shell tool, so the test is correctly catching
a product bug.

Tap stdout/stderr into PassThroughs synchronously at spawn time, and
await the reader fiber after the process exits so scope teardown cannot
interrupt it before trailing chunks are drained.
2026-07-03 14:49:58 +02:00