You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
New tools — four more built-in tools round out the surface so AI
agents can stay inside acp-bridge instead of falling back to
their own knowledge:
edit — surgical string replacement. Replace exactly one
occurrence of old_text with new_text in an existing file.
Refuses to act if old_text is missing or appears more than once,
so the model has to re-read the file rather than guess.
write_file — create or overwrite a file with new content.
Sibling to edit for whole-file rewrites; rejects .. escapes.
web_fetch — fetch a URL over HTTP/HTTPS and return the body
as text. HTML is reduced to readable text (scripts/styles
stripped, tags removed, whitespace collapsed). 5 MB body cap,
30 s timeout. Off by default: requires LLM_WEB_ALLOWLIST to be set to a
comma-separated list of host suffixes (e.g. LLM_WEB_ALLOWLIST=docs.rs,crates.io). Empty allowlist blocks
every request. This is an opt-in safety boundary so a
misconfigured sandbox cannot exfiltrate to internal
infrastructure.
git_status, git_diff, git_log, git_commit —
read-only and write git operations, all run inside the session
working directory. git_diff accepts an optional path and a staged: true flag (--cached). git_log accepts max_count
(clamped to 1–200, default 20) and an optional path filter. git_commit stages the listed paths (or git add -u when paths is omitted) and commits with the supplied message.
acp-bridge now publishes four plan notification helpers — acp::PlanEntry, acp::notify_plan, acp::notify_session_info, acp::notify_usage, acp::AvailableCommand, acp::notify_available_commands. Engine hooks fire available_commands_update and session_info_update immediately
after session/new, and usage_update + session_info_update
after session/prompt returns.
LlmConfig.context_size — model context window in tokens,
surfaced as usage_update.size. Override via LLM_MODEL_CONTEXT
env var or [llm].model_context config field (default 32768).
PromptResult::usage carries an estimated used token count
(chars / 4 across the session history) so the usage_update has
a number to ship. Local backends rarely stream stable per-turn
token counts; this is intentionally approximate.
acp::kind_for_tool now classifies edit, write_file, web_fetch, and the four git_* tools so Clients render the
right icon and affordance.
Classified backend errors — LlmErrorKind (Unreachable, RateLimited, ServerBusy, Auth, BadRequest, NotFound, Timeout, ParseError, Unknown) and LlmError::is_retryable(). chat and stream_chat now return Result<_, LlmError> instead
of plain strings. Failed turns emit a structured error.data.category + error.data.retryable in the JSON-RPC
response so Clients can branch on it (e.g. "auto-retry on backend_unreachable, show 'check your model name' on not_found").
Changed
Wire order on session/prompt and session/new — the
post-event notifications (available_commands_update, session_info_update, usage_update) are emitted before the
JSON-RPC response, not after. Clients that buffer the entire
notification stream per turn (most ACP Clients) see the
notifications bound to the right sessionId; Clients that read
strictly one-line-at-a-time still get the response on the line
after the notifications.
PromptResult gains error_class: Option<LlmErrorKind> and error_retryable: bool so the engine's failure classification
reaches the JSON-RPC response without string-matching.
Tests
14 new unit tests (src/tools.rs): write / edit (unique match,
missing, ambiguous, empty), web_fetch allowlist enforcement, HTML
reduction, git status.
3 new unit tests (src/llm.rs): LlmErrorKind::as_str stability,
retryable classification, status-code → kind mapping.
All existing test suites still pass; 159 tests total.