Commit graph

860 commits

Author SHA1 Message Date
Ahmed Allam
849671f288 fix(tui): drop the Model label from the stats panel 2026-10-04 04:54:29 +03:00
Ahmed Allam
faca0d4d1d fix(tui): pin the Model panel to the sidebar bottom and enlarge the show-sidebar button 2026-10-04 04:54:29 +03:00
Ahmed Allam
1a680f4aa3 fix(tui): keep sidebar panels inside the terminal height 2026-10-04 04:54:29 +03:00
Ahmed Allam
701c22b8a9 fix(tui): collapsible, zoomable sidebar panels and a sidebar toggle
Every sidebar panel gets a header with a click-to-collapse chevron and a
click-to-zoom glyph; a one-row chip on the viewer line hides the whole
sidebar and brings it back from a narrow rail. Tab skips collapsed and
hidden panels, scrollbar hit zones follow the rendered bars, and
fillBackground also repaints after the bare ESC[m reset so no cell shows
the terminal background.
2026-10-04 04:54:29 +03:00
Ahmed Allam
e1d7f5c433 fix(tui): keep blank lines inside fenced code when rendering report markdown 2026-10-04 02:11:45 +03:00
Ahmed Allam
64dae6f484 fix(tui): render report section bodies as markdown 2026-10-04 02:11:45 +03:00
Ahmed Allam
b49ac2fd9e fix(preflight): check extra headers for subscription models and the dedupe key as sent 2026-10-04 01:48:35 +03:00
Ahmed Allam
08df05db61 fix(preflight): skip unused credentials for subscription models, check dedupe credentials too 2026-10-04 01:48:35 +03:00
Ahmed Allam
4ca15a6e60 style: drop docstrings from the header-value check 2026-10-04 01:48:35 +03:00
Ahmed Allam
539960d953 fix(preflight): name a non-ASCII character in the API key instead of raising UnicodeEncodeError
httpx encodes header values as ASCII, so a smart quote, non-breaking
space or byte-order mark pasted into LLM_API_KEY (or LLM_EXTRA_HEADERS)
surfaced as a bare UnicodeEncodeError from inside the client, wrapped in
ModelConnectionError. The preflight now checks these settings first and
fails with the setting name, the code point, its Unicode name and its
position. Nothing is trimmed or rewritten and the key itself is never
printed.
2026-10-04 01:48:35 +03:00
Ahmed Allam
7280c40caa style: drop docstrings from the UTF-8 stream helpers 2026-10-04 01:19:48 +03:00
Ahmed Allam
5c3476795a fix(cli): force UTF-8 stdout/stderr on Windows so Rich output never raises
Windows hands a redirected or legacy console stream the ANSI code page
(cp1252), which cannot encode Rich's panels or the model's text: one
check mark in a finding ended a headless run with UnicodeEncodeError, and
the error handler raised again rendering its own panel. Reconfigure both
streams to UTF-8 at startup on win32, and open the Go TUI's os.devnull
sink as UTF-8 so logging into it stops producing --- Logging error ---
reports under the same code page.
2026-10-04 01:19:48 +03:00
Ahmed Allam
45b775dcd5 fix(cli): apply the --fail-on threshold regardless of run status
A stopped run with no findings already exits 0, so skipping the threshold
only when low findings exist made the gate depend on the wrong thing.
The threshold now always applies; reporting an unfinished run is a separate
exit-code concern.
2026-10-04 00:03:23 +03:00
siundu254
b11228192d Resolve PR Comments 2026-10-04 00:03:23 +03:00
siundu254
3cd6c93fa0 Fail on Severity 2026-10-04 00:03:23 +03:00
Ahmed Allam
65172fecd8 fix(tui): link every wrapped line of the viewer URL to the full URL
The sidebar wraps the viewer URL, and terminals that linkify by text only
pick up the first line, so the click opened the viewer with a truncated
token. Emit each wrapped line as an OSC 8 hyperlink to the whole URL.
2026-10-03 23:24:05 +03:00
Ahmed Allam
0107a15295 test: reject a leading heading in any finish_scan example field 2026-10-03 23:07:56 +03:00
Ahmed Allam
c0258b25fa fix(finish_scan): stop asking for a section heading in every report field
Every renderer of the final report already titles each section, so the
heading the docstring asked for printed twice. Describe the fields as
section bodies and drop the example headings.
2026-10-03 23:07:56 +03:00
Ahmed Allam
99c0711687 fix(config): use the Responses API whenever the model's catalog entry lists /v1/responses 2026-10-02 18:41:53 +03:00
Ahmed Allam
2635fb5307 chore(inputs): drop unused logger 2026-10-02 18:17:27 +03:00
Ahmed Allam
8ab5e39c06 fix(inputs): send reasoning_effort as configured; no route-specific handling 2026-10-02 18:17:27 +03:00
Ahmed Allam
e1ec259ac2 fix(inputs): send reasoning_effort=none explicitly on chat completions; hint at the Responses API when tools+effort are rejected 2026-10-02 18:17:27 +03:00
Ahmed Allam
066bd60a03 fix(runner): pick the SDK route from the resolved model override
configure_sdk_model_defaults only sees STRIX_LLM; a model= override to
run_strix_scan re-applies the route for the model that actually runs.
2026-10-02 18:17:27 +03:00
Ahmed Allam
6ab123484d fix(config): choose Responses vs chat completions from the model, not the base URL
A base URL no longer forces chat completions. resolve_api_type() keeps an
explicit STRIX_API_TYPE, uses Responses without a base URL or for
api.openai.com, uses Responses for models whose LiteLLM catalog entry has
no /v1/chat/completions endpoint, and chat completions for other gateways.

On the chat completions route, reasoning_effort is omitted for models
whose LiteLLM parameter map does not list it there instead of failing the
request with function tools. STRIX_REASONING_EFFORT and STRIX_API_TYPE
are matched case-insensitively.
2026-10-02 18:17:27 +03:00
alex s
007ed1a94e
fix(reporting): restore create_vulnerability_report parameter descrip… (#1391)
* fix(reporting): restore create_vulnerability_report parameter descriptions

A docstring line beginning with a backtick fence example opened a markdown
code block that griffe's Google-style parser never saw closed, so the Args
section was parsed as plain text and the generated tool schema carried no
per-parameter descriptions. Reword the example, move Args after the trailing
notes so nothing after it is dropped from the tool description, and add a
test asserting every scan-agent tool parameter has a description.

* test(reporting): cover respond_to_user and reject null parameter descriptions
2026-09-30 13:26:48 -04:00
Ahmed Allam
ef272b8e0d chore(models): remove the model quality warning and its allowlists 2026-09-30 10:04:28 +03:00
Ian
9b72488c92 docs + unit test fix 2026-09-30 04:46:01 +03:00
Ian
c77bdd2c2a Disable by default 2026-09-30 04:46:01 +03:00
Ian
c814f6bf30 Made session IDs optional 2026-09-30 04:46:01 +03:00
Ian
a1658fe59b Scarf support 2026-09-30 04:46:01 +03:00
Ian
3fbccc6b1d Non-streaming path 2026-09-30 04:46:01 +03:00
Ian
c9aebc6c87 larger default block size 2026-09-30 04:46:01 +03:00
Ian
95fbd8d687 Openrouter sticky sessions for caching, with telemetry 2026-09-30 04:46:01 +03:00
Ahmed Allam
463b149bdb fix(budget): parked agents count as active; park never overwrites a stop
active_agents_except (finish_scan, wait_for_message) treats budget_paused as
active, so a root cannot finish the scan over a parked child. park_for_budget
only transitions a running agent, and the wake back to running happens under
the coordinator lock.
2026-09-30 03:13:40 +03:00
Ahmed Allam
d355838ea0 feat(budget): budget_policy=pause parks every agent at the limit until the operator resumes
Adds budget_policy: stop | pause to run_strix_scan / ReportUsageHooks /
AgentCoordinator, independent of interactive mode. Under pause the agents
get no budget warnings and no sub-agent reserve; each agent parks before
its next LLM call once spent >= limit or the scan is paused, sessions and
sandbox stay alive, and coordinator.resume_budget(max_budget_usd=...)
replaces the limit and wakes every parked agent without adding anything
to any session. coordinator.pause_budget() parks a running scan the same
way. In-flight calls are never cancelled, so spent may end above the
limit. Parked agents count as active for stop_agent.
2026-09-30 03:13:40 +03:00
ian-at-strix
0ff9f8c324
feat(tui): animate the wait_for_agents indicator (#1383) 2026-09-29 14:39:07 -07:00
ian-at-strix
954bc0d527
perf(prompt): load requested skills after a cache point (#1382)
Siblings differ only in the skills they were spawned with, but those came
first in <specialized_knowledge>, so their prompts diverged at 39%. Shared
skills and the catalog now come first, and the requested skills follow a
cache point, so siblings share 93%.

The extra system message takes a fourth Claude breakpoint, so the Bedrock
tool_config one goes: the first system breakpoint already covers the tools.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 00:35:22 +03:00
ian-at-strix
e66c56c473
perf(llm): give Claude a cache point before the per-run scope (#1376)
* perf(llm): give Claude a cache point before the per-run scope

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(llm): split the system prompt at a generic <cache_point> marker

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 00:35:22 +03:00
ian-at-strix
50425c2c99
perf(prompt): put per-run scope at the end of the system prompt (#1375)
* perf(prompt): put per-run scope at the end of the system prompt

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(prompt): assert scope renders once, after the shared prefix

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 00:35:21 +03:00
alex s
6ae036e6c1
docs(skills): refresh framework behavior and security testing guidance (#1372) 2026-09-29 10:11:02 -07:00
ian-at-strix
0c702723aa
fix(tui): suspend on ctrl+z (#1371)
Bubble Tea's raw mode clears ISIG, so ctrl+z reached the TUI as a key and
was ignored instead of stopping the job. Return tea.Suspend for it on every
screen, and re-enable mouse tracking on resume, since Bubble Tea's restore
brings back the alt screen but not the mouse mode.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:44:25 -04:00
Yash Aslekar
d6dd9dec26
fix(dev): make check-all non-mutating (#1360) 2026-09-27 17:47:20 -07:00
devin-ai-integration[bot]
ae38fe70cd
Fill in blank tool-call ids so strict providers accept the history (#1355) 2026-09-23 18:34:22 -07:00
alex s
4c1be22150
Let agents delete a vulnerability report they filed (#1354) 2026-09-23 17:25:23 -07:00
devin-ai-integration[bot]
56f7d45388
feat(llm): structured per-attempt provider request log with provider request ids (#1353) 2026-09-22 20:49:41 -07:00
yoni-at-strix
e158eab3f8
feat(mcp): initialize connections lazily (#1347)
* feat(mcp): initialize connections lazily

* fix(mcp): replace terminally dead sessions

* fix(mcp): improve targeted tool discovery

* fix(mcp): limit active tool fallback
2026-09-22 14:02:02 -04:00
Ahmed Allam
56e9ae982c runtime: read_only local sources become :ro bind mounts
A local_code target can mark its tree read_only; collect_local_sources
forwards the flag and build_bind_mounts mounts the tree read-only instead
of relying on host mode bits, skipping the per-metadata remounts since the
whole tree is already immutable. Used for pulled container image layouts.
2026-09-20 06:10:13 +03:00
Ahmed Allam
355a8bb437 fix(reporting): move the git blame hint to the end of the tool description 2026-09-18 21:39:35 +03:00
Ahmed Allam
77a0cf839b fix(reporting): make the git blame hint a casual inline note 2026-09-18 21:39:35 +03:00
Ahmed Allam
cafa4b19fd fix(reporting): keep git blame guidance to the technical_analysis field 2026-09-18 21:39:35 +03:00