Repository navigation
Conversation
NTaylorMullen
approved these changes
Apr 17, 2025
yaleh
pushed a commit
to yaleh/gemini-cli
that referenced
this pull request
Jun 29, 2025
Remove internal docs and mention of Gerrit from README
yewenchen
pushed a commit
to yewenchen/gemini-cli
that referenced
this pull request
Jul 8, 2025
This was referenced Jul 22, 2025
bishal-codepros
pushed a commit
to bishal-codepros/gemini-cli
that referenced
this pull request
Jul 22, 2025
…esWithGlob function - Remove redundant abort check before glob operation (no async operations between checks) - Keep abort check at function start and after async glob operation where signal can actually change - Improves performance by eliminating unnecessary CPU cycles
cocosheng-g
added a commit
to cocosheng-g/gemini-cli
that referenced
this pull request
Oct 24, 2025
# This is the 1st commit message: feat: Create BYOID auth client when detecting BYOID credentials This change introduces a BYOID auth client that is created when BYOID credentials are detected. It also refactors the code assist server and setup to use the new AuthClient type. # This is the commit message google-gemini#2: resolve comments # This is the commit message google-gemini#3: load credentials only once and lazy load the client # This is the commit message google-gemini#4: use original method names # This is the commit message google-gemini#5: use original method names for getOauthClient # This is the commit message google-gemini#6: remove redundant test mock
aka76bm
referenced
this pull request
in aka76bm/gemini-cli
Oct 31, 2025
…m_and_yarn-2e94d63b2a chore(deps): bump tar from 7.5.1 to 7.5.2 in the npm_and_yarn group across 1 directory
aka76bm
referenced
this pull request
in aka76bm/gemini-cli
Oct 31, 2025
chore(deps): bump tar from 7.5.1 to 7.5.2 in the npm_and_yarn group across 1 directory #3
Adib234
pushed a commit
that referenced
this pull request
Nov 11, 2025
Grinsven
added a commit
to Grinsven/gemini-cli-1
that referenced
this pull request
Nov 23, 2025
anowardear062-svg
approved these changes
Jan 14, 2026
18 tasks
4 of 18 tasks
4 of 18 tasks
5 tasks
Closed
SeunghyunLee1982
referenced
this pull request
in SeunghyunLee1982/gemini-cli
May 16, 2026
Extend `kind: anthropic` agents from v0 single-shot to a turn-capped tool-use loop. Optional `tools` whitelist + `max_turns` cap (default 5, max 50) opt the sub-agent in to calling a subset of Gemini's tools via the standard scheduler. Empty/omitted `tools` keeps the v0 single-shot path verbatim (see commit 2522024) so all existing markdown agent files keep working bit-identically. Design source of truth: design-loop/design-v2.md, APPROVED by both validators in design-loop/review-opus-v2.md and review-gemini-v2.md. Key architectural decisions (per design §): - **Isolation.** Mirrors `local-executor.ts:164-205`: derived MessageBus (`parentBus.derive(definition.name)`), per-invocation ToolRegistry, whitelisted-and-cloned tools only. Skips `Kind.Agent` to prevent nested sub-agents. TUI activity attributes to the right subagent via the cloned tools' messageBus. - **Schema pass-through.** Reads `parametersJsonSchema` (raw JSON Schema 2020-12, what every core/MCP tool actually populates) over OpenAPI- flavored `parameters`. Strip `propertyOrdering` (Gemini-only). Coerce non-object root to permissive `{ type: 'object', properties: {} }`. - **Schedule via the standard scheduler.** `scheduleAgentTools` with block.id as callId, per-turn prompt_id `${promptId}#anthropic-${turn}`, `parentCallId` from `getToolCallContext()`. Soft-rejection (Cancel outcome) feeds an is_error tool_result and the loop continues; hard abort throws and the outer catch returns CANCELLED. - **Back-propagation.** Single user message per turn with N tool_result blocks, each keyed by the matching tool_use_id and ordered to match the assistant's tool_use order — NOT the scheduler return order. Verified by a parallel-tool-use test that returns out of order on purpose. - **Truncation cap = 48 KB chars** (`ANTHROPIC_TOOL_RESULT_MAX_CHARS`). Soft hint encourages refining the next call. - **Verbose partToString** for tool_result content so a `read_file` on a PNG yields `[Image: image/png, 12 KB]` instead of an empty string. - **System prompt is append-only**: tool-availability line + soft-reject suffix. Never replaces the user's body. - **Loader change.** Drops `tools` / `max_turns` from `guessIntendedKind` because both anthropic and local schemas accept them — keeping them would mis-attribute anthropic-shaped frontmatter as local on validation failure. Anthropic agents must now declare `kind: anthropic` explicitly. Files (line counts as of commit): - `packages/core/src/agents/anthropic-invocation.ts` (+~430 net): adds `executeWithTools`, helper `toArgsRecord`, `finalAssistantText`. v0 `executeSingleShot` preserved verbatim. - `packages/core/src/agents/anthropic-tools.ts` (+179, new): schema conversion, response-parts string rendering, truncation. - `packages/core/src/agents/anthropic-tools.test.ts` (+223, new): 17 tests covering schema identity, propertyOrdering strip, non-object coercion, truncation, image-part verbose rendering. - `packages/core/src/agents/anthropic-invocation.test.ts` (+961, new): 15 tests — single-shot back-compat, isolated registry, parentCallId via getToolCallContext, parallel tool_use ordering, soft reject, hard abort, max_tokens stop, empty content, max_turns drain, oversize truncation, image placeholder, schema pass-through, unauthorized tool synth. - `packages/core/src/agents/types.ts` (+29): adds `tools`, `max_turns` to `AnthropicAgentDefinition`, plus `ANTHROPIC_TOOL_RESULT_MAX_CHARS = 49152` and `DEFAULT_ANTHROPIC_MAX_TURNS = 5`. - `packages/core/src/agents/agentLoader.ts` (+18 net): schema fields with `isValidToolName` (no wildcards) refinement; drop `tools` / `max_turns` from heuristic; thread fields through. - `packages/core/src/agents/agentLoader.test.ts` (+167): seven new anthropic-loader tests; updates one existing test that relied on the removed `tools`-as-local-signal behavior. - `packages/cli/src/ui/components/views/AgentsStatus.tsx` (+4): renders an "Anthropic Agents" bucket (fixes a pre-existing v0 display bug where `kind: anthropic` agents were silently filtered out). - `CLAUDE.md` (+~30): documents new fields and starter whitelist. Validation gates (all pass on this commit): - `npm run typecheck`: pass (all 4 workspaces). - `node scripts/lint.js --eslint`: pass (0 errors, 0 warnings). - `node scripts/lint.js --prettier`: pass. - `npx vitest run packages/core/src/agents/`: 36 files, 731 tests, 0 fail. - `npm run build --workspace=packages/core`: pass. - `npm run build --workspace=packages/cli`: pass. (`npx vitest run packages/core/src/utils/` has 3 pre-existing failing files unrelated to this change — see the `src/config/constants.js` import-path issue on `getFolderStructure.test.ts` and friends. Confirmed they fail identically on the pre-change tree.) Non-blocking observations from Opus's round-2 review: 1. The 48 KB truncation cap relies on Claude honoring the "[Refine your call]" hint to avoid re-read loops on the same file. There is no hard back-pressure — implementing it would require per-call dedup tracking. Worth a follow-up if field tests show repeated re-reads; not addressed here. 2. Risk #3 (parentCallId from getToolCallContext() returning undefined) is asserted in `round-trips a tool_use turn` — `opts.parentCallId` is explicitly expected to be `undefined` when no enclosing tool context. The scheduler accepts that today (same as local agents). 3. Implementer judgment: removed the `// eslint-disable-next-line @typescript-eslint/no-extraneous-class` directive on `FakeAnthropic` in tests because it has a real constructor and the rule never fires. Things I would push back on as reviewer: - The `responsePartsToToolResultContent` helper reads `fr.parts` via an `as unknown as { parts?: unknown }` cast because `FunctionResponse` doesn't officially expose that field. Slightly ugly but the field is real and used by multimodal-capable Gemini models — passing the same Part array through `convertToFunctionResponse` produces it. - `executeToolUses` builds `results` as a sparse `Array<... | undefined>` then filters at the end. Simpler and type-correct than mutating a dense array with assertions; the filter is the only safety net ensuring callers see a fully-populated `Anthropic.ToolResultBlockParam[]`. Co-Authored-By: Claude Opus 4.7 <[email protected]>
SeunghyunLee1982
referenced
this pull request
in SeunghyunLee1982/gemini-cli
May 17, 2026
Adds a persistent agent swarm primitive behind the `experimental.swarm` settings flag. The main Gemini agent can now spawn long-lived Claude sub-agent instances, send them multiple messages across orchestrator turns (retaining `messages` state), and release them — going beyond the existing one-shot `kind: anthropic` AgentTool delegation. Scope (v1.0): - Sync only. `message` blocks until the session's turn completes. - In-memory `SwarmManager` singleton; sessions die with the process. - Single discriminated `swarm` tool with `action: spawn | message | release | list`. Zod-backed discriminated union. - Read-only tool whitelist by default (`read_file`, `grep_search`, `glob`, `list_directory`, `read_many_files`); per-spawn `tools` override allowed. - Session abort bound to `Config.getAppAbortSignal()` (SIGINT / process exit), NOT the orchestrator turn signal — ending an orchestrator turn does not kill the swarm. - 30-minute idle TTL with background sweep; sessions wedged in `running` past `2 * TTL` are aborted, marked `error`, and kept in `list()` for user debugging. - Feature-flagged off by default. The Anthropic message loop body from `AnthropicAgentInvocation` was extracted into `anthropic-loop.ts` so both the v1 single-shot path and the new long-lived `SwarmSession` share the same tool-use machinery. Design + reviews: - Multi-turn design discussion: `design-loop/swarm-design.md` (Claude + Gemini, Turns 0-4 + Final Synthesis with the locked v1.0 acceptance E2E). - Phase 1 reviews: `design-loop/phase1-review-opus.md`, `design-loop/phase1-review-gemini.md`. - Phase 2 reviews: `design-loop/phase2-review-opus.md`, `design-loop/phase2-review-gemini.md`. Phase 2 review items addressed in this commit: - Gemini #1: TTL sweep no longer deletes stuck-RUNNING sessions — they're aborted + marked ERROR + kept in `list()`. - Opus #1/#3: per-session app-abort listeners now have a disposer that fires from `SwarmSession.release()` and from the TTL-stuck path; no more unbounded listener accumulation across spawn/release cycles. - Opus #2: `appAbortDisposers` (Config) and `appAbortDisposer` (SwarmManager) are nulled out after firing for clarity. - Opus #4: `lastActiveAt` is stamped on RUNNING entry so a legitimate 35-minute turn is not misjudged "stuck" by the 2 * TTL sweep. Acceptance gate: - The locked stateful-continuity E2E is in `packages/core/src/agents/swarm/swarm-continuity.test.ts`. It intercepts the Anthropic SDK at the module boundary and asserts that the THIRD `messages.create` call (Agent A's second turn) sees the prior user+assistant turns in its `messages` array. If session statelessness regresses (e.g. someone resets `messages = []`), the test fails. Validation gates passed: - `npm run typecheck` (all workspaces) - `node scripts/lint.js --eslint` - `node scripts/lint.js --prettier` - `npm run build --workspace=packages/core` - `npm run build --workspace=packages/cli` - `npx vitest run packages/core/src/agents/` (753 passed) - `npx vitest run packages/core/src/agents/swarm/` (18 passed) Deferred to v1.1+ (per the synthesis): - `async: true` spawn + `poll` / `await` actions. - Shared workspace dir at `~/.gemini/swarm/<session_id>/work/`. - Budget guardrails (`max_spend_usd`, `max_total_tokens`). - Cross-process persistence. - Haiku worker reintegration (user policy default stands). Co-Authored-By: Claude Opus 4.7 <[email protected]>
SeunghyunLee1982
referenced
this pull request
in SeunghyunLee1982/gemini-cli
May 19, 2026
…overy
Closes the gap between v1.0's "process pool of single-shot workers" and the
intended "stateful collaborator team with smart orchestrator" model. R3-locked
design after a three-round multi-model debate (see design-loop/), then
implemented and put through an Opus + Gemini reviewer loop before commit.
Area 1 — `role` / `charter`. Optional short labels (≤80 / ≤200 chars) on
`spawn` that flow through the Zod schema, JSON tool schema, session params,
`list()`, and the new `swarm_status` snapshot. They also get woven into the
session's composed system prompt so the sub-agent knows what hat it's wearing
without the orchestrator having to repeat itself in every message.
Area 2 — `message_turn_cap_reached` status. Hitting `max_turns` no longer
appends a `[Note: hit max_turns=N.]` suffix and silently returns; it's now a
first-class outcome. `runAnthropicMessageLoop` returns
`{ text, capReached: boolean }`. `SwarmResult.message` splits into:
- `status: 'ok' | 'message_turn_cap_reached'` — message outcome
- `session_status: SwarmSessionStatus` — session lifecycle (idle/running/
released/error)
Cap-reached is a normal IDLE return; the session lives. The single-shot
anthropic-invocation path is bit-compatible (silently drops `capReached`).
Area 3 — Plan-mode tool filter. `SWARM_BLOCKED_TOOL_NAMES` (containing
`ENTER_PLAN_MODE_TOOL_NAME` / `EXIT_PLAN_MODE_TOOL_NAME` imported directly
from `tool-names`) is applied in the per-tool clone loop, so both inherit-all
and explicit `tools: [...]` paths drop mode-control tools. Closes the
host-CLI-state-escalation hole the user surfaced in the Phase 4 live test
where a sub-agent inherited `exit_plan_mode` and burned its turn budget
trying to escape Plan Mode.
Area 4 — `swarm_status` companion tool. New `swarm-status-tool.ts`
(`Kind.Other`, no args, no confirm) that calls
`SwarmManager.getSwarmStatusSnapshot()`. The snapshot exposes every live
session's `role` / `charter` / `status` / `turn_count` /
`seconds_since_active`, the shared `workspace_dir`, and a newest-first
`recent_events[]` ring (50 entries, fed by `publishActivity`). Sub-agents
are deliberately handed this read-only window — the verb surface
(`swarm spawn/message/release`) stays orchestrator-only behind `Kind.Agent`.
Area 5 — auto system-prompt block + default tool. `SWARM_PROTOCOL_BLOCK` is
woven into `composedSystemPrompt` between the tool advertisement and the
soft-reject suffix; it tells the sub-agent it's in a swarm, to call
`swarm_status()` for peer context, and to append a `[<agent_id> @ <ts>]`
line to `<workspace_dir>/state.md` after substantive work. `swarm_status` is
appended to `DEFAULT_SWARM_TOOLS` and auto-injected on the inherit-all path
(explicit lists are respected).
Area 6 — SKILL.md adds four sections covering self-discovery via
`swarm_status`, the `state.md` convention, "release on role-exhaustion, not
task-completion", and cap-handling. CLAUDE.md's Swarm section is updated for
the v1.0.x shape.
Tests (6 mandated, all present and exercising the real surface, not theater):
- Plan-mode filter regression with explicit list
- role/charter round-trip through list() + swarm_status snapshot
- cap-reached returns IDLE session_status, turnCount still increments
- `getSwarmStatusSnapshot` agents[] + recent_events ordering
- composed system prompt contains protocol block + role + charter
- anthropic-loop `{ capReached: true }` shape on max_turns
Post-review tweaks (Opus #2/#3 follow-ups, addressed before commit):
- SWARM_BLOCKED_TOOL_NAMES now references the tool-name constants directly
(no drift if those tools are ever renamed)
- SWARM_STATUS_TOOL_NAME hoisted to types.ts as single SoT; swarm-manager
and swarm-status-tool both import from there (cycle-free)
Out of scope (deferred per user):
- agent-memory MCP integration (v1.2+; RAG-style retrieval + write-back)
- Persistent .events.jsonl on disk (v1.1+; current ring is in-memory only,
consistent with "sessions die with parent CLI" policy)
- `callerAgentId` resolution from MessageBus name (v1.1; today every
sub-agent sees `self_agent_id: undefined`, which is benign)
Rejected design directions (recorded in design-loop/swarm-model-r*.md):
- `SwarmArchetype` registry + `catalog()` action (Gemini R1 → moved off in R2)
- `since_last_turn` / `context_update` orchestrator-push fields (user
redirection in R3: "공유 메모리 + self-discovery 방향으로")
- `suggest_release` hint from sub-agent (user: "안 넣으면 문제 되는 명확한
시나리오 안 보이면 빼자")
Validation:
npm run typecheck — pass
node scripts/lint.js --eslint — pass
node scripts/lint.js --prettier — pass for staged files
npm run build --workspace=packages/core — pass
npm run build --workspace=packages/cli — pass
npx vitest run packages/core/src/agents/ — 766 passed / 1 skipped
npx vitest run packages/core/src/scheduler — 146 passed
npx vitest run packages/core/src/policy — 326 passed (2 pre-existing
topic-policy failures unrelated to this commit; verified clean on
f114440 before this work)
Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
SeunghyunLee1982
referenced
this pull request
in SeunghyunLee1982/gemini-cli
May 19, 2026
Closes a real UX gap surfaced in the user's live testing: the orchestrator (Gemini model) doesn't naturally reach for the `swarm` tool, even when registered, even with explicit prompt steering. It falls back to `run_shell_command` and tries `gemini swarm ...` recursively. The fork ships substantial swarm + policy machinery already (Phases 4–6), but the model-side disposition layer was missing. R1/R2 multi-model design debate (Opus + Gemini in parallel, two rounds) settled the design at `design-loop/swarm-orchestrator- disposition.md`. After implementation, a six-reviewer pass (three angles — TS/clean-code, intent, tests/abstractions — each with one Opus + one Gemini reviewer) ran in parallel; all six returned SHIP or SHIP-WITH-FOLLOW-UP. Cheap follow-ups are addressed in this commit; the rest are noted in the design doc and the agent-memory entry for v2 pickup. Four layers, all gated on `Config.isSwarmEnabled()` so upstream non-swarm users see zero behavior change: 1) Tool description rewrite (~+150 tokens). `SWARM_TOOL_DESCRIPTION` and `SWARM_STATUS_TOOL_DESCRIPTION` now carry explicit "when to use" + the anti-pattern "DO NOT shell out to `gemini` — there is no `gemini swarm` verb." Drift-guard tests pin the anti-pattern phrasing so accidental rewording regresses behavior loudly. 2) Orchestrator system-prompt disposition block + single inline worked example (~+300 tokens, conditional). New `SwarmDispositionOptions` + `renderSwarmDisposition` in `prompts/snippets.ts`. Inserted between `renderSubAgents` and `renderAgentSkills` in `getCoreSystemPrompt`. `promptProvider.ts` gates on `(SWARM_TOOL_NAME ∨ SWARM_STATUS_TOOL_NAME) ∈ registered tools` AND `isSwarmEnabled()`. The block names the tool, flags the no-CLI-verb anti-pattern, references `swarm_status`, and embeds one `<example>` showing a `swarm spawn` call. The example is inline rather than separate so in-context proximity isn't diluted by intervening prompt sections. 3) `swarm-collaboration` skill auto-inline (~+1.6k tokens, only when swarm enabled). `promptProvider.ts` filters the skill out of the regular `<available_skills>` manifest and inlines its SKILL.md body via new `renderSwarmInline`. Removes the activate-skill indirection so the protocol (state.md convention, release rules, paste-verbatim discipline) lands in the orchestrator's context without an extra round-trip. Hardcoded for the single fork-builtin inline candidate; an `inline: boolean` metadata flag was explicitly rejected in R2 (YAGNI; the LOCKED v2 north star reserves the capability/ template data-model surface). 4) Runtime guard — tier-1 default-deny `PolicyRule`. Registered from `config.ts` inside the existing `isSwarmEnabled()` tool- registration block. Pattern matches the JSON-stringified args form (`stableStringify(toolCall.args)`), NOT raw shell text — that ground-truth correction was caught in R2 when both models independently traced `PolicyEngine.matchRule` and found the raw-shell prototype from R1 would silently never match. The correct shape is `/"command":"(gemini|gemini-fork)(\s|"|\\)/`; the policy engine's existing sub-command splitter (`policy-engine.ts:469-475`) handles `bash -c "gemini foo"` and `cd /tmp && gemini ...` via recursive `check()`. The deny message carries the redirect text. `tier-4` user policies can still override. Review-cycle fixes folded in before commit: - Legacy snippets gap (Opus angle 1 #1): `snippets.legacy.ts` now imports the Phase 8 option types and renderers from `snippets.ts` and wires them into legacy `getCoreSystemPrompt`, so Gemini 2.x orchestrators with swarm enabled get the disposition block too. The disposition fix matters more for older models with stronger shell-first priors, not less. - Misleading test narration (Opus angles 2 + 3, cross-flagged): `policy-engine.test.ts` comment for the `bash -c "gemini help"` case had the wrong mechanism. The DENY actually fires via the sub-command splitter recursing into the inner `gemini help`, not the JSON-escape `(\\)` alternative at the top level. Corrected. - `swarm_status`-only branch test gap (Opus angle 3): added a case proving the disposition AND auto-inline both fire when only `SWARM_STATUS_TOOL_NAME` is registered (sub-agents themselves get `swarm_status` without `swarm` per the recursion-guard filter in `swarm-manager.ts`). - Empty-body edge case (Gemini angle 3): `renderSwarmInline` now returns `''` for whitespace-only bodies so a future skill loader returning an empty string doesn't render a dangling `# Skill — <name> (auto-loaded)` header with no content. Test added. Non-blocking review findings deferred to follow-ups (recorded in the design doc / agent-memory entry): - `SWARM_TOOL_NAME` SoT split (Opus angle 1 #3, Gemini angle 1): `SWARM_STATUS_TOOL_NAME` lives in lightweight `agents/swarm/ types.ts`, while `SWARM_TOOL_NAME` is still in heavy `swarm-tool.ts`. Consolidating both into the central `tools/tool-names.ts` is a separate cleanup. - Phase 8 prompt fields bypass `withSection` (Opus angle 1 #2): the operator `GEMINI_PROMPT_<KEY>=0` mute knob doesn't apply to the new sections. Routing through `withSection` is a separate consistency fix. - Layer 4 brittleness on `stableStringify` (Gemini angle 2): the argsPattern coupling to the policy engine's stringify format is a structural smell. A dedicated structured-arg matcher in the policy engine is a v2-level improvement. Tests landed (11 new): - `policy-engine.test.ts`: JSON-shape pattern denies `gemini …`, `gemini-fork …`, and `bash -c "gemini help"` (via recursive splitter); passes through `ls -la` and `echo gemini`. - `swarm-tool.test.ts`: anti-pattern drift guards on both tool descriptions. - `promptProvider.test.ts`: disposition block on/off; auto- inline pulled out/in manifest; only-`swarm_status` branch fires both layers; `renderSwarmInline` empty-body returns ''. - `config.test.ts`: tier-1 deny rule registered iff swarm enabled; carries the expected `source`, `toolName`, `decision`, `argsPattern` shape, and `denyMessage`. Gates: npm run typecheck — pass node scripts/lint.js --eslint — pass node scripts/lint.js --prettier — pass for staged files; design-loop docs auto-formatted by pre-commit hook npm run build --workspace=packages/core — pass npm run build --workspace=packages/cli — pass npx vitest run packages/core/src/policy/ — 330/332 (the 2 pre-existing topic-policy.test.ts failures, unrelated, verified on parent commit f190547) npx vitest run packages/core/src/agents/swarm/ — 36/36 npx vitest run packages/core/src/prompts/ — 65/65 Files committed include the LOCKED design doc (`design-loop/swarm-orchestrator-disposition.md`) and the `.gitignore` exception that tracks it (alongside `swarm-north-star.md`). Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
Closed
joneba-google
referenced
this pull request
in joneba-google/gemini-cli-clone
Jul 8, 2026
merge main into branch refactor/server-ts
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 18, 2026
Resolves all 7 review comments from gemini-code-assist[bot]: google-gemini#1 [CRITICAL] write-todos.ts - Replaced clear+recreate with reconciliation strategy that matches existing tasks by title, preserving IDs, types, parent-child relationships, and dependencies. Only status is updated for matched tasks. New items are created, absent items removed. Epics and parent tasks created by dedicated tracker tools are never deleted. google-gemini#2 [SECURITY-HIGH] trackerService.ts - Added path traversal guard: deleteTask() now validates ID matches /^[0-9a-f]{6}$/i before any filesystem operation. google-gemini#3 [HIGH] trackerService.ts - Moved child-task deletion guard from tool layer into TrackerService.deleteTask() so all callers (tools, SDK, tests) get the same referential integrity protection. google-gemini#4 [HIGH] trackerService.ts - Cascade dependency cleanup now sets updatedAt on affected tasks so disk metadata stays consistent. google-gemini#5 [HIGH] trackerService.ts - createTask() now retries up to 10 times if the generated 6-char hex ID collides with an existing task. google-gemini#6 [HIGH] trackerService.ts - deleteTask() now clears parentId on any task that referenced the deleted task as parent, preventing orphaned invisible tasks in the UI. google-gemini#7 [HIGH] trackerTools.ts - TrackerDeleteTaskInvocation.execute() now trims and validates the ID parameter with the same regex before calling the service, catching bad input at the tool boundary. Tests: 49 passed (added 4 new: path traversal guard, child-task block at service layer, updatedAt cascade, ID reconciliation preservation).
Closed
5 tasks done
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 18, 2026
Addresses all 11 review comments from gemini-code-assist[bot]: Security (CRITICAL + HIGH): - Add validateToolParamValues to ASTSearchTool with path validation using resolveDefensiveToolPath + resolveToRealPath + validatePathAccess, preventing path traversal attacks (comments google-gemini#1, google-gemini#2, google-gemini#8, google-gemini#9) Parsing correctness (HIGH): - findClosingBrace: track parenthesis depth to ignore braces inside inline object types in function params (comment google-gemini#3) - findClosingBrace: return lines.length-1 instead of startLine+50 when brace matching fails, for honest boundary reporting (comment google-gemini#7) - extractSymbols: track block comment state (/* ... */) to skip commented-out code declarations (comment google-gemini#4) - findIndentEnd: track Python triple-quoted strings to avoid early termination on docstrings with low indentation (comment google-gemini#5) - extractSymbols: fix enum body skipping, enums now advance the line pointer past their body like classes/functions (comment google-gemini#10) Documentation: - collectSourceFiles: document .gitignore/.geminiignore limitation and plan for FileDiscoveryService integration (comment google-gemini#6) - findClosingBrace: document escaped-quote limitation in the string-literal stripping regex (comment google-gemini#11)
4 of 6 tasks
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 18, 2026
Fixes 5 comments from third review round: CRITICAL/HIGH (google-gemini#1,google-gemini#2): Map scope path traversal - file_path for "map" scope now goes through resolveDefensiveToolPath + validatePathAccess before reaching getCodebaseMap. handleMapScope accepts safePath param. HIGH (google-gemini#3): Block comment stripping rewritten from state-tracking to character-level replacement. New stripBlockComments() replaces comment content with spaces, preserving line numbers. Handles mid-line comments and multi-line blocks correctly. HIGH (google-gemini#4): validateToolParamValues now trims symbol_name and file_path at the top before any checks, preventing whitespace-only values. HIGH (google-gemini#5): handleSymbolScope accepts trimmed symbolName as a parameter instead of reading raw this.params.symbol_name, so LLM-injected whitespace does not cause lookup mismatches.
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 18, 2026
google-gemini#1 [SECURITY-CRITICAL] tool-names.ts - Removed write_todos->tracker_list_tasks alias. write_todos is a state-modifying tool; aliasing it to a read-only tool would let read-only auto-approve policies bypass write protection. google-gemini#2 [HIGH] trackerService.ts - Moved fs.unlink() AFTER reference cleanup in deleteTask(). If a crash occurs mid-operation, the DB stays consistent: orphaned dep/parent references would permanently break validateCanClose and validateNoCircularDependencies on the affected tasks. google-gemini#3 [HIGH] tool-names.test.ts - Removed test for the deleted alias. 48 tests passing. Session 1+2 CLI E2E verified.
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 18, 2026
HIGH (google-gemini#1): String literal regex in findClosingBrace now handles escaped quotes via negated character class with backslash alternation: /(TICK)(?:[^(TICK)\\]|\\.)*TICK/g pattern for all three quote types. Resolves the documented limitation for strings like "a \" {". HIGH (google-gemini#2): Triple-quote tracking in findIndentEnd rewritten to track the specific opener (""" vs TICK TICK TICK). A block started with """ can only be closed by """, preventing cross-type toggle bugs. HIGH (google-gemini#3): Directory walk depth limit raised from 6 to 15. Supports deep monorepo structures like packages/core/src/tools/definitions/ model-family-sets/ (depth 7) without silently omitting files.
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 18, 2026
CRITICAL (google-gemini#1): getFileOutline now validates resolved path is a subpath of targetDir before any fs access. Traversal returns null. CRITICAL (google-gemini#2): getCodebaseMap validates searchDir stays within targetDir. Traversal returns an error string instead of walking arbitrary dirs. HIGH (google-gemini#3,google-gemini#4): stripBlockComments now accepts language parameter. Uses # for Python line comments, // for others. String literal contents are blanked (replaced with spaces) while preserving delimiters, preventing false keyword matches inside strings and incorrect brace counting from template literal contents.
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 18, 2026
Review fixes: - HIGH (google-gemini#1): Python member regex removed leading \s+ since trimmed lines have no leading whitespace. Methods now extracted correctly. - HIGH (google-gemini#2): getCodebaseMap uses resolvedTargetDir for path.relative instead of raw this.targetDir, preventing incorrect relative paths. - HIGH (google-gemini#3): Python test expanded to assert class method children (Handler.run as method child). Bugs found via thorough manual testing: - extractSymbols indent check now uses original lines[i] instead of cleaned[i]. Block comment blanking inflates indentation of the cleaned line (e.g. "/* comment */ export class A" becomes 19 spaces of indent), causing false top-level rejection.
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 19, 2026
Resolves all 7 review comments from gemini-code-assist[bot]: google-gemini#1 [CRITICAL] write-todos.ts - Replaced clear+recreate with reconciliation strategy that matches existing tasks by title, preserving IDs, types, parent-child relationships, and dependencies. Only status is updated for matched tasks. New items are created, absent items removed. Epics and parent tasks created by dedicated tracker tools are never deleted. google-gemini#2 [SECURITY-HIGH] trackerService.ts - Added path traversal guard: deleteTask() now validates ID matches /^[0-9a-f]{6}$/i before any filesystem operation. google-gemini#3 [HIGH] trackerService.ts - Moved child-task deletion guard from tool layer into TrackerService.deleteTask() so all callers (tools, SDK, tests) get the same referential integrity protection. google-gemini#4 [HIGH] trackerService.ts - Cascade dependency cleanup now sets updatedAt on affected tasks so disk metadata stays consistent. google-gemini#5 [HIGH] trackerService.ts - createTask() now retries up to 10 times if the generated 6-char hex ID collides with an existing task. google-gemini#6 [HIGH] trackerService.ts - deleteTask() now clears parentId on any task that referenced the deleted task as parent, preventing orphaned invisible tasks in the UI. google-gemini#7 [HIGH] trackerTools.ts - TrackerDeleteTaskInvocation.execute() now trims and validates the ID parameter with the same regex before calling the service, catching bad input at the tool boundary. Tests: 49 passed (added 4 new: path traversal guard, child-task block at service layer, updatedAt cascade, ID reconciliation preservation).
dylanyunlon
added a commit
to dylanyunlon/gemini-cli
that referenced
this pull request
Sep 19, 2026
google-gemini#1 [SECURITY-CRITICAL] tool-names.ts - Removed write_todos->tracker_list_tasks alias. write_todos is a state-modifying tool; aliasing it to a read-only tool would let read-only auto-approve policies bypass write protection. google-gemini#2 [HIGH] trackerService.ts - Moved fs.unlink() AFTER reference cleanup in deleteTask(). If a crash occurs mid-operation, the DB stays consistent: orphaned dep/parent references would permanently break validateCanClose and validateNoCircularDependencies on the affected tasks. google-gemini#3 [HIGH] tool-names.test.ts - Removed test for the deleted alias. 48 tests passing. Session 1+2 CLI E2E verified.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.