Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
69 commits
Select commit Hold shift + click to select a range
fbbd3ea
feat(tui): add plan mode command and fix plan file editing
euxaristia Jul 10, 2026
79be86d
feat(tui): add missing internal/planmode package
euxaristia Jul 11, 2026
b8389ef
fix(tui): address review findings on plan mode
euxaristia Jul 11, 2026
e5a1064
fix(tui): address review findings on plan mode editor and safety
euxaristia Jul 13, 2026
2437a38
fix(tui): address plan-mode review findings on toggle, session scopin…
euxaristia Jul 13, 2026
1f0039e
fix(tui): guard exitPlanMode against clobbering non-plan permission m…
euxaristia Jul 13, 2026
c81979f
fix(tui): reload plan file into memory on editor exit, preserving sta…
euxaristia Jul 14, 2026
eaadd73
fix(tui): correct /plan command palette description
euxaristia Jul 14, 2026
c812e56
fix(tui,agent): address plan-mode review findings on gating, reload, …
euxaristia Jul 14, 2026
fd9c451
fix(tui,planmode): close editor symlink race, propagate edits to cont…
euxaristia Jul 14, 2026
b0554cf
fix(planmode,tui): harden editor staging and record cleared plans
euxaristia Jul 15, 2026
f7ed6ab
fix(planmode,tui,tools): physical staging containment, cancel-safe pl…
euxaristia Jul 15, 2026
98cff66
fix(planmode): resolve not-yet-existing paths through their deepest e…
euxaristia Jul 15, 2026
baf795a
fix(tui): confirm plan reload in transcript after editor exit
euxaristia Jul 16, 2026
c8d4633
fix(tui,planmode,tools): close plan-mode gating and durability gaps
euxaristia Jul 18, 2026
82acf66
fix(agent): suppress executable hooks while plan/spec-draft mode is a…
euxaristia Jul 18, 2026
353352e
fix(tui): layer plan-mode prompt instead of replacing it
euxaristia Jul 19, 2026
1c39e44
fix(agent): keep trust-gated hooks in spec-draft; harden plan allowlist
euxaristia Jul 19, 2026
8de3b79
fix(planmode,tui): keep durable plans outside the workspace
euxaristia Jul 20, 2026
154839a
fix(planmode): make Windows honor config-root test isolation and stag…
euxaristia Jul 20, 2026
27a17e8
fix(planmode): make plan storage paths collision-resistant
euxaristia Jul 22, 2026
402959e
fix(tui): preserve active plan file content when entering plan mode
euxaristia Jul 23, 2026
81a7d42
fix(tui): address review findings on plan storage workspace path, pla…
euxaristia Jul 23, 2026
cc406b5
fix(tui): reset plan mode on spec session switch and preserve beforeT…
euxaristia Jul 31, 2026
1e33578
fix(agent): update tests off tools.CoreTools/NewWriteFileTool removed…
euxaristia Jul 31, 2026
43a2f91
fix(tui): address plan mode review (btw switch, testing dep, dead field)
euxaristia Aug 1, 2026
f090e5a
fix(tui): polish plan-mode btw/spec edge cases from review
euxaristia Aug 7, 2026
5b8acb1
fix(planmode,tui): address CodeRabbit findings on plan storage and re…
euxaristia Aug 7, 2026
a44848b
fix(planmode,tui,agent): close remaining CodeRabbit findings on plan …
euxaristia Aug 7, 2026
0a34231
fix(planmode): bind ReadPlan containment at open via os.Root
euxaristia Aug 7, 2026
02e6d5e
fix(planmode): refuse final plan symlink without following it
euxaristia Aug 7, 2026
cb03b27
fix(planmode,tui): close open CodeRabbit findings on plan mode
euxaristia Aug 7, 2026
b56a03e
fix(planmode,tui): close remaining CodeRabbit findings on plan mode
euxaristia Aug 7, 2026
005e536
fix(planmode,tui): address CodeRabbit review findings and CI assertio…
euxaristia Aug 8, 2026
3436868
fix(planmode): harden plan writes and editor roundtrip
euxaristia Aug 10, 2026
e4455d7
fix(tui): reconcile plan mode with main command semantics
euxaristia Aug 11, 2026
99f467a
fix(tui): close remaining plan-mode review findings
euxaristia Aug 11, 2026
fc41ec1
Clarify the plan mode entry command
euxaristia Aug 11, 2026
9e3ffbf
fix(planmode,tui): close CodeRabbit findings on plan storage and edit…
euxaristia Aug 12, 2026
911829a
fix(planmode,tui,agent): close remaining CodeRabbit findings on plan …
euxaristia Aug 13, 2026
27e75e3
fix(planmode): recognize a Linux/Darwin ENOTDIR as an intermediate sy…
euxaristia Aug 13, 2026
9649322
test(tui): pin that /plan on creates its session before naming the pl…
euxaristia Aug 13, 2026
a87331a
fix(tui): record a plan-file edit only when the plan actually changed
euxaristia Aug 13, 2026
2bddc16
fix(planmode): refuse a symlink or reparse point at the plan storage …
euxaristia Aug 13, 2026
a3cb30c
fix(planmode): Address CodeRabbit review feedback on plan mode and te…
euxaristia Aug 16, 2026
2a79702
fix(planmode,tui): Address review comments on plan reload and staging…
euxaristia Aug 16, 2026
be1027d
Sync peer identity when /plan enters and exits plan mode.
euxaristia Aug 16, 2026
2de484e
Add a Windows junction test for WritePlan storage-root refusal.
euxaristia Aug 16, 2026
6af27b9
Pause armed loops and goals while plan mode is active.
euxaristia Aug 18, 2026
0448196
fix(planmode): address CodeRabbit review feedback on PR #854
euxaristia Aug 20, 2026
5c9987d
fix(planmode): sync dirfd on rename and update test assertion message
euxaristia Aug 22, 2026
b4e6306
test(planmode): Pin redirected Windows plan reads.
euxaristia Aug 24, 2026
2490825
fix(tui): Restore session state after plan-mode switches.
euxaristia Aug 24, 2026
71448a0
fix(planmode): resolve Windows junctions when judging staging contain…
euxaristia Aug 24, 2026
72f532a
fix(tui): hold queued prompts while plan mode is active
euxaristia Aug 31, 2026
3d79c4e
Address review feedback on plan persistence, isolation, and staging l…
euxaristia Sep 1, 2026
098318c
Fix Unix build imports for plan staging and stale sweep
euxaristia Sep 1, 2026
174e3da
Tighten Unix staging directory descriptor permissions
euxaristia Sep 1, 2026
e84d73b
Address review feedback on plan canonicalization, Windows staging rep…
euxaristia Sep 4, 2026
3a91782
Address review feedback on atomic plan commit locking, continuation u…
euxaristia Sep 4, 2026
31ac425
Assert exact continuation content and test permission mode preservation.
euxaristia Sep 4, 2026
0edfab3
Preserve plan edits across competing writers and clarify session life…
euxaristia Sep 6, 2026
1bcd24c
Use a real alternate Unix temporary root in plan storage tests.
euxaristia Sep 6, 2026
0fdb65c
Cancel plan publication promptly while its writer lock is held.
euxaristia Sep 7, 2026
eefea76
Keep accepted plans consistent on save failure and preserve editor ba…
euxaristia Sep 7, 2026
18af56e
Report the failed plan operation and clarify literal continuation syn…
euxaristia Sep 7, 2026
6973f43
fix(planmode): clarify empty-vs-absent snapshot semantics and fix TMP…
euxaristia Sep 9, 2026
4f1d362
fix(tui): resolve rebase conflict in agentResponseMsg
euxaristia Sep 18, 2026
1135edd
fix: address CodeRabbit minor findings on plan-mode PR
cairn-intern Sep 24, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -225,6 +225,24 @@ Common slash commands:
| `/add-dir` | allow an extra write directory for this session |
| `/theme`, `/doctor`, `/config` | adjust appearance and inspect setup |

`/plan on` enables read-only planning for the current session; switching sessions
exits Plan mode, and returning from `/btw` restores the parent's mode. Plan updates
are accepted only after saving succeeds. A failed save reports an error and keeps
the accepted plan available to the panel, status display, and later reloads.

`/plan open` edits a protected copy through `$VISUAL` or `$EDITOR`. Newly saved
plans include a `<!-- zero-plan-format: 2 -->` marker: keep it when editing so
backslashes remain literal. To quote a literal `Notes:` line or a line beginning
with a pipe and a space, insert `|` followed by one space after its indentation:

```text
| Notes: this is literal content
| | this line starts with a literal pipe and space
```

Existing plans remain readable and are converted with a concurrency check before
opening the editor.

### Headless `exec`

```bash
Expand Down
17 changes: 9 additions & 8 deletions internal/agent/loop.go
Original file line number Diff line number Diff line change
Expand Up @@ -1537,6 +1537,7 @@ func executeToolCall(ctx context.Context, registry *tools.Registry, call ToolCal
// the Run turn loop performs the actual provider switch. Empty for every
// ordinary tool result.
RequestedModel: result.Meta["escalate_to_model"],
PlanSnapshot: result.PlanSnapshot,
}, nil
}

Expand Down Expand Up @@ -1873,15 +1874,15 @@ func toolResultFromPrePermissionReject(call ToolCall, result tools.Result) ToolR
}
}

// hooksSuppressed reports whether advisory (non-veto) hooks must not run for
// this run's permission mode. Plan mode promises a read-only turn, but
// sessionStart/sessionEnd/afterTool hooks execute configured host commands
// outside the advertised-tool and sandbox gates, so dispatching them would let
// merely starting a plan session or finishing a read mutate the workspace.
// hooksSuppressed reports whether lifecycle and afterTool hooks must not run
// for this run's permission mode. Plan mode promises a read-only turn, but
// sessionStart, sessionEnd, and afterTool hooks execute configured host
// commands outside the advertised-tool and sandbox gates, so dispatching them
// would let merely starting or finishing a plan session mutate the workspace
// or spawn processes.
//
// beforeTool is intentionally NOT suppressed: a non-zero exit is a deny gate,
// and skipping it fails open (operators who block secret-file reads via
// beforeTool would lose that protection under /plan on). See dispatchBeforeTool.
// beforeTool is intentionally not gated here: fail-closed policy vetoes must
// still apply to read-only plan-mode calls (see dispatchBeforeTool).
//
// Spec-draft keeps the existing trust-gated hook model: project hooks still
// fire when the workspace (or its worktree trust root) is trusted. That is
Expand Down
Loading
Loading