Add batch reads, @file completion, interruptible commands, tool sets

Tools, six built-in to fourteen:
- read_many_files: up to 20 paths read concurrently, each with its own window.
  An unreadable path is reported in its own block instead of throwing.
- multi_edit: several edits to one file, validated in memory first so a late
  failure cannot leave the file half-written.
- list_dir: ignore-aware depth-limited tree.
- git_status/diff/log/show/blame: read-only, spawned with a fixed argv rather
  than a shell string, which is what makes them safe to auto-approve.

toolSets gates them. core is always on; edit-plus and git are optional. A
disabled set reaches neither the wire nor the system prompt, since a prompt
naming an absent tool teaches calls that cannot succeed.

Interface:
- Reasoning streams to a collapsed panel, ctrl-r expands, dropped when the turn
  ends: it is progress, not the answer.
- The tool in flight is named from tool-input-start, before its arguments finish
  streaming, and cleared on its result.
- Prompts typed mid-turn queue and drain in order. esc clears the queue as well
  as aborting.
- @ opens a path picker fed by the ignore-aware walker. Prefix matches rank
  above substring matches, so @src/ means "under src/". The walk runs on the
  first @, not at startup.

ctrl-c kills the command in flight and keeps the turn. The call throws rather
than returning, so the model cannot read a killed command as one that ran and
failed on its own terms. The kill takes the whole process tree: killing cmd /c
alone left the real command holding both pipes open, so the read never returned
and the interrupt did nothing for 19 seconds.

Two pruning fixes:
- A tool result whose tool call was pruned is now dropped with it. Pruning
  counts messages, so the cut landed between an assistant tool-call and the tool
  message answering it, producing 400 "No tool call found for function call
  output with call_id ...". The reverse pairing is left alone: a call awaiting
  its result is what a suspended approval looks like.
- ignore.ts called statFs without importing it, so walk() crashed on the first
  symlink.

482 tests, up from 404. Docs synced across README, ROADMAP, TODO, and all of
docs/: tool sets, the new tools, ctrl-c semantics, the tool-start event, and the
two hand-maintained tool-name lists recorded as a known weakness.
This commit is contained in:
Muhammad Zakir Ramadhan
2026-09-03 01:37:48 +07:00
parent a5ace7a23f
commit 2fa6ee247b
36 changed files with 2541 additions and 215 deletions
+70
View File
@@ -7,6 +7,8 @@ import { createHost } from '../src/plugins';
import { guardPlugin, timePlugin } from '../src/plugins-builtin';
import { Session } from '../src/session';
import { loadSkills } from '../src/skills';
import { MUTATING_TOOLS, TOOL_SETS, TOOL_SET_NAMES, isToolSetName, toolSetOf } from '../src/tools';
import { GIT_TOOL_NAMES } from '../src/tools-git';
const usage = {
inputTokens: { total: 5, noCache: 5, cacheRead: 0, cacheWrite: 0 },
@@ -226,3 +228,71 @@ test('afterTurn fires once the turn ends', async () => {
for await (const _ of session.send('hi')) void _;
expect(fired).toBe(1);
});
test('the git tools are offered by default and never prompt', async () => {
const { seen, model } = recorder();
const session = new Session({ model, askApproval: async () => 'deny' });
for await (const _ of session.send('what changed')) void _;
const offered = (seen[0]?.tools ?? []).map((t) => t.name);
for (const name of GIT_TOOL_NAMES) expect(offered).toContain(name);
for (const name of GIT_TOOL_NAMES) expect(MUTATING_TOOLS as readonly string[]).not.toContain(name);
});
test('a disabled tool set reaches neither the wire nor the prompt', async () => {
const { seen, model } = recorder();
const session = new Session({ model, askApproval: async () => 'deny', toolSets: [] });
for await (const _ of session.send('hi')) void _;
const offered = (seen[0]?.tools ?? []).map((t) => t.name);
expect(offered).toContain('read_file');
expect(offered).toContain('bash');
expect(offered).not.toContain('git_status');
expect(offered).not.toContain('multi_edit');
expect(offered).not.toContain('list_dir');
const system = JSON.stringify(seen[0]?.prompt.find((m) => m.role === 'system'));
expect(system).not.toContain('git_status');
expect(system).not.toContain('multi_edit');
});
test('an enabled set is offered while the others stay withheld', async () => {
const { seen, model } = recorder();
const session = new Session({ model, askApproval: async () => 'deny', toolSets: ['git'] });
for await (const _ of session.send('hi')) void _;
const offered = (seen[0]?.tools ?? []).map((t) => t.name);
expect(offered).toContain('git_diff');
expect(offered).not.toContain('multi_edit');
});
test('core is never withheld, whatever the config says', async () => {
const { seen, model } = recorder();
const session = new Session({ model, askApproval: async () => 'deny', toolSets: ['git'] });
for await (const _ of session.send('hi')) void _;
const offered = (seen[0]?.tools ?? []).map((t) => t.name);
for (const name of TOOL_SETS.core) expect(offered).toContain(name);
});
test('session tools survive tool-set gating, since they are not part of that budget', async () => {
const { seen, model } = recorder();
const session = new Session({ model, askApproval: async () => 'deny', toolSets: [], memory: new Memory('/repo-test') });
for await (const _ of session.send('hi')) void _;
const offered = (seen[0]?.tools ?? []).map((t) => t.name);
expect(offered).toContain('todo_write');
expect(offered).toContain('remember');
});
test('toolSetOf names the set a tool came from, and nothing for a session tool', () => {
expect(toolSetOf('read_file')).toBe('core');
expect(toolSetOf('multi_edit')).toBe('edit-plus');
expect(toolSetOf('git_log')).toBe('git');
expect(toolSetOf('todo_write')).toBeUndefined();
});
test('isToolSetName accepts the real sets only, so a typo in config is ignored', () => {
for (const name of TOOL_SET_NAMES) expect(isToolSetName(name)).toBe(true);
expect(isToolSetName('gti')).toBe(false);
});