load.go

   1package config
   2
   3import (
   4	"cmp"
   5	"context"
   6	"encoding/json"
   7	"fmt"
   8	"log/slog"
   9	"maps"
  10	"os"
  11	"os/exec"
  12	"path/filepath"
  13	"regexp"
  14	"runtime"
  15	"slices"
  16	"strconv"
  17	"strings"
  18	"testing"
  19
  20	"charm.land/catwalk/pkg/catwalk"
  21	"git.secluded.site/crush/internal/agent/hyper"
  22	"git.secluded.site/crush/internal/csync"
  23	"git.secluded.site/crush/internal/env"
  24	"git.secluded.site/crush/internal/filepathext"
  25	"git.secluded.site/crush/internal/fsext"
  26	"git.secluded.site/crush/internal/home"
  27	powernapConfig "github.com/charmbracelet/x/powernap/pkg/config"
  28	"github.com/qjebbs/go-jsons"
  29)
  30
  31const defaultCatwalkURL = "https://catwalk.charm.land"
  32
  33// Load loads the configuration from the default paths and returns a
  34// ConfigStore that owns both the pure-data Config and all runtime state.
  35func Load(workingDir, dataDir string, debug bool) (*ConfigStore, error) {
  36	configPaths := lookupConfigs(workingDir)
  37
  38	cfg, loadedPaths, err := loadFromConfigPaths(configPaths)
  39	if err != nil {
  40		return nil, fmt.Errorf("failed to load config from paths %v: %w", configPaths, err)
  41	}
  42
  43	cfg.setDefaults(workingDir, dataDir)
  44
  45	store := &ConfigStore{
  46		config:         cfg,
  47		workingDir:     workingDir,
  48		globalDataPath: GlobalConfigData(),
  49		workspacePath:  filepath.Join(cfg.Options.DataDirectory, fmt.Sprintf("%s.json", appName)),
  50		loadedPaths:    loadedPaths,
  51	}
  52
  53	if debug {
  54		cfg.Options.Debug = true
  55	}
  56
  57	// Load workspace config last so it has highest priority.
  58	if wsData, err := os.ReadFile(store.workspacePath); err == nil && len(wsData) > 0 {
  59		if !json.Valid(wsData) {
  60			return nil, fmt.Errorf("invalid JSON in config file %s", store.workspacePath)
  61		}
  62		merged, mergeErr := loadFromBytes(append([][]byte{mustMarshalConfig(cfg)}, wsData))
  63		if mergeErr == nil {
  64			// Preserve defaults that setDefaults already applied.
  65			dataDir := cfg.Options.DataDirectory
  66			*cfg = *merged
  67			cfg.setDefaults(workingDir, dataDir)
  68			store.config = cfg
  69			store.loadedPaths = append(store.loadedPaths, store.workspacePath)
  70		}
  71	}
  72
  73	// Validate hooks after all config merging is complete so workspace
  74	// hooks also get their matcher regexes compiled.
  75	if err := cfg.ValidateHooks(); err != nil {
  76		return nil, fmt.Errorf("invalid hook configuration: %w", err)
  77	}
  78
  79	if !isInsideWorktree() {
  80		const depth = 2
  81		const items = 100
  82		slog.Warn("No git repository detected in working directory, will limit file walk operations", "depth", depth, "items", items)
  83		assignIfNil(&cfg.Tools.Ls.MaxDepth, depth)
  84		assignIfNil(&cfg.Tools.Ls.MaxItems, items)
  85		assignIfNil(&cfg.Options.TUI.Completions.MaxDepth, depth)
  86		assignIfNil(&cfg.Options.TUI.Completions.MaxItems, items)
  87	}
  88
  89	if isAppleTerminal() {
  90		slog.Warn("Detected Apple Terminal, enabling transparent mode")
  91		assignIfNil(&cfg.Options.TUI.Transparent, true)
  92	}
  93
  94	// Load known providers, this loads the config from catwalk
  95	providers, err := Providers(cfg)
  96	if err != nil {
  97		return nil, err
  98	}
  99	store.knownProviders = providers
 100
 101	env := env.New()
 102	// Configure providers
 103	valueResolver := NewShellVariableResolver(env)
 104	store.resolver = valueResolver
 105
 106	// Disable auto-reload during initial load to prevent nested calls from
 107	// config-modifying operations inside configureProviders.
 108	store.autoReloadDisabled = true
 109	defer func() { store.autoReloadDisabled = false }()
 110
 111	if err := cfg.configureProviders(store, env, valueResolver, store.knownProviders); err != nil {
 112		return nil, fmt.Errorf("failed to configure providers: %w", err)
 113	}
 114
 115	if !cfg.IsConfigured() {
 116		slog.Warn("No providers configured")
 117		return store, nil
 118	}
 119
 120	if err := configureSelectedModels(store, store.knownProviders, true); err != nil {
 121		return nil, fmt.Errorf("failed to configure selected models: %w", err)
 122	}
 123	store.SetupAgents()
 124
 125	// Capture initial staleness snapshot
 126	store.captureStalenessSnapshot(loadedPaths)
 127
 128	return store, nil
 129}
 130
 131// mustMarshalConfig marshals the config to JSON bytes, returning empty JSON on
 132// error.
 133func mustMarshalConfig(cfg *Config) []byte {
 134	data, err := json.Marshal(cfg)
 135	if err != nil {
 136		return []byte("{}")
 137	}
 138	return data
 139}
 140
 141func PushPopCrushEnv() func() {
 142	var found []string
 143	for _, ev := range os.Environ() {
 144		if strings.HasPrefix(ev, "CRUSH_") {
 145			pair := strings.SplitN(ev, "=", 2)
 146			if len(pair) != 2 {
 147				continue
 148			}
 149			found = append(found, strings.TrimPrefix(pair[0], "CRUSH_"))
 150		}
 151	}
 152	backups := make(map[string]string)
 153	for _, ev := range found {
 154		backups[ev] = os.Getenv(ev)
 155	}
 156
 157	for _, ev := range found {
 158		os.Setenv(ev, os.Getenv("CRUSH_"+ev))
 159	}
 160
 161	restore := func() {
 162		for k, v := range backups {
 163			os.Setenv(k, v)
 164		}
 165	}
 166	return restore
 167}
 168
 169func (c *Config) configureProviders(store *ConfigStore, env env.Env, resolver VariableResolver, knownProviders []catwalk.Provider) error {
 170	knownProviderNames := make(map[string]bool)
 171	restore := PushPopCrushEnv()
 172	defer restore()
 173
 174	// When disable_default_providers is enabled, skip all default/embedded
 175	// providers entirely. Users must fully specify any providers they want.
 176	// We skip to the custom provider validation loop which handles all
 177	// user-configured providers uniformly.
 178	if c.Options.DisableDefaultProviders {
 179		knownProviders = nil
 180	}
 181
 182	for _, p := range knownProviders {
 183		knownProviderNames[string(p.ID)] = true
 184		config, configExists := c.Providers.Get(string(p.ID))
 185		// if the user configured a known provider we need to allow it to override a couple of parameters
 186		if configExists {
 187			if config.BaseURL != "" {
 188				p.APIEndpoint = config.BaseURL
 189			}
 190			if config.APIKey != "" {
 191				p.APIKey = config.APIKey
 192			}
 193			if len(config.Models) > 0 {
 194				models := []catwalk.Model{}
 195				seen := make(map[string]bool)
 196
 197				for _, model := range config.Models {
 198					if seen[model.ID] {
 199						continue
 200					}
 201					seen[model.ID] = true
 202					if model.Name == "" {
 203						model.Name = model.ID
 204					}
 205					models = append(models, model)
 206				}
 207				for _, model := range p.Models {
 208					if seen[model.ID] {
 209						continue
 210					}
 211					seen[model.ID] = true
 212					if model.Name == "" {
 213						model.Name = model.ID
 214					}
 215					models = append(models, model)
 216				}
 217
 218				p.Models = models
 219			}
 220		}
 221
 222		headers := map[string]string{}
 223		if len(p.DefaultHeaders) > 0 {
 224			maps.Copy(headers, p.DefaultHeaders)
 225		}
 226		if len(config.ExtraHeaders) > 0 {
 227			maps.Copy(headers, config.ExtraHeaders)
 228		}
 229		// Provider headers use the same error contract as MCP headers:
 230		// a failing $(...) aborts the provider load with a clear
 231		// message, and a header that resolves to the empty string
 232		// (unset bare $VAR under lenient nounset, $(echo), or literal
 233		// "") is dropped from the outgoing request.
 234		for k, v := range headers {
 235			resolved, err := resolver.ResolveValue(v)
 236			if err != nil {
 237				return fmt.Errorf("resolving provider %s header %q: %w", p.ID, k, err)
 238			}
 239			if resolved == "" {
 240				delete(headers, k)
 241				continue
 242			}
 243			headers[k] = resolved
 244		}
 245		prepared := ProviderConfig{
 246			ID:                 string(p.ID),
 247			Name:               p.Name,
 248			BaseURL:            p.APIEndpoint,
 249			APIKey:             p.APIKey,
 250			APIKeyTemplate:     p.APIKey, // Store original template for re-resolution
 251			OAuthToken:         config.OAuthToken,
 252			Type:               p.Type,
 253			Disable:            config.Disable,
 254			SystemPromptPrefix: config.SystemPromptPrefix,
 255			ExtraHeaders:       headers,
 256			ExtraBody:          config.ExtraBody,
 257			ExtraParams:        make(map[string]string),
 258			Models:             p.Models,
 259		}
 260
 261		switch {
 262		case p.ID == catwalk.InferenceProviderAnthropic && config.OAuthToken != nil:
 263			// Claude Code subscription is not supported anymore. Remove to show onboarding.
 264			if !store.reloadInProgress {
 265				store.RemoveConfigField(ScopeGlobal, "providers.anthropic")
 266			}
 267			c.Providers.Del(string(p.ID))
 268			continue
 269		case p.ID == catwalk.InferenceProviderCopilot && config.OAuthToken != nil:
 270			prepared.SetupGitHubCopilot()
 271		}
 272
 273		switch p.ID {
 274		// Handle specific providers that require additional configuration
 275		case catwalk.InferenceProviderVertexAI:
 276			var (
 277				project  = env.Get("VERTEXAI_PROJECT")
 278				location = env.Get("VERTEXAI_LOCATION")
 279			)
 280			if project == "" || location == "" {
 281				if configExists {
 282					slog.Warn("Skipping Vertex AI provider due to missing credentials")
 283					c.Providers.Del(string(p.ID))
 284				}
 285				continue
 286			}
 287			prepared.ExtraParams["project"] = project
 288			prepared.ExtraParams["location"] = location
 289		case catwalk.InferenceProviderAzure:
 290			endpoint, err := resolver.ResolveValue(p.APIEndpoint)
 291			if err != nil || endpoint == "" {
 292				if configExists {
 293					slog.Warn("Skipping Azure provider due to missing API endpoint", "provider", p.ID, "error", err)
 294					c.Providers.Del(string(p.ID))
 295				}
 296				continue
 297			}
 298			prepared.BaseURL = endpoint
 299			prepared.ExtraParams["apiVersion"] = env.Get("AZURE_OPENAI_API_VERSION")
 300		case catwalk.InferenceProviderBedrock:
 301			if p.APIKey == "" && !hasAWSCredentials(env) {
 302				if configExists {
 303					slog.Warn("Skipping Bedrock provider due to missing AWS credentials")
 304					c.Providers.Del(string(p.ID))
 305				}
 306				continue
 307			}
 308		case catwalk.InferenceProvider("hyper"):
 309			if apiKey := env.Get("HYPER_API_KEY"); apiKey != "" {
 310				prepared.APIKey = apiKey
 311				prepared.APIKeyTemplate = apiKey
 312			} else {
 313				v, err := resolver.ResolveValue(p.APIKey)
 314				if v == "" || err != nil {
 315					if configExists {
 316						slog.Warn("Skipping Hyper provider due to missing API key", "provider", p.ID)
 317						c.Providers.Del(string(p.ID))
 318					}
 319					continue
 320				}
 321			}
 322		default:
 323			// if the provider api or endpoint are missing we skip them
 324			v, err := resolver.ResolveValue(p.APIKey)
 325			if v == "" || err != nil {
 326				if configExists {
 327					slog.Warn("Skipping provider due to missing API key", "provider", p.ID)
 328					c.Providers.Del(string(p.ID))
 329				}
 330				continue
 331			}
 332		}
 333		c.Providers.Set(string(p.ID), prepared)
 334	}
 335
 336	// validate the custom providers
 337	for id, providerConfig := range c.Providers.Seq2() {
 338		if knownProviderNames[id] {
 339			continue
 340		}
 341
 342		// Make sure the provider ID is set
 343		providerConfig.ID = id
 344		providerConfig.Name = cmp.Or(providerConfig.Name, id) // Use ID as name if not set
 345		// default to OpenAI if not set
 346		providerConfig.Type = cmp.Or(providerConfig.Type, catwalk.TypeOpenAICompat)
 347		if !slices.Contains(catwalk.KnownProviderTypes(), providerConfig.Type) && providerConfig.Type != hyper.Name {
 348			slog.Warn("Skipping custom provider due to unsupported provider type", "provider", id)
 349			c.Providers.Del(id)
 350			continue
 351		}
 352
 353		if providerConfig.Disable {
 354			slog.Debug("Skipping custom provider due to disable flag", "provider", id)
 355			c.Providers.Del(id)
 356			continue
 357		}
 358		if providerConfig.APIKey == "" {
 359			slog.Warn("Provider is missing API key, this might be OK for local providers", "provider", id)
 360		}
 361		if providerConfig.BaseURL == "" {
 362			slog.Warn("Skipping custom provider due to missing API endpoint", "provider", id)
 363			c.Providers.Del(id)
 364			continue
 365		}
 366		if len(providerConfig.Models) == 0 {
 367			slog.Warn("Skipping custom provider because the provider has no models", "provider", id)
 368			c.Providers.Del(id)
 369			continue
 370		}
 371		apiKey, err := resolver.ResolveValue(providerConfig.APIKey)
 372		if apiKey == "" || err != nil {
 373			slog.Warn("Provider is missing API key, this might be OK for local providers", "provider", id)
 374		}
 375		baseURL, err := resolver.ResolveValue(providerConfig.BaseURL)
 376		if baseURL == "" || err != nil {
 377			slog.Warn("Skipping custom provider due to missing API endpoint", "provider", id, "error", err)
 378			c.Providers.Del(id)
 379			continue
 380		}
 381
 382		// Custom-provider headers share the MCP error contract; see
 383		// the known-provider loop above.
 384		for k, v := range providerConfig.ExtraHeaders {
 385			resolved, err := resolver.ResolveValue(v)
 386			if err != nil {
 387				return fmt.Errorf("resolving provider %s header %q: %w", id, k, err)
 388			}
 389			if resolved == "" {
 390				delete(providerConfig.ExtraHeaders, k)
 391				continue
 392			}
 393			providerConfig.ExtraHeaders[k] = resolved
 394		}
 395
 396		c.Providers.Set(id, providerConfig)
 397	}
 398
 399	if c.Providers.Len() == 0 && c.Options.DisableDefaultProviders {
 400		return fmt.Errorf("default providers are disabled and there are no custom providers are configured")
 401	}
 402
 403	return nil
 404}
 405
 406func (c *Config) setDefaults(workingDir, dataDir string) {
 407	if c.Options == nil {
 408		c.Options = &Options{}
 409	}
 410	if c.Options.TUI == nil {
 411		c.Options.TUI = &TUIOptions{}
 412	}
 413	if len(c.Options.GlobalContextPaths) == 0 {
 414		crushConfigDir := filepath.Dir(GlobalConfig())
 415		c.Options.GlobalContextPaths = []string{
 416			filepath.Join(crushConfigDir, "CRUSH.md"),
 417			filepath.Join(crushConfigDir, "AGENTS.md"),
 418			filepath.Join(filepath.Dir(crushConfigDir), "AGENTS.md"),
 419		}
 420	}
 421	slices.Sort(c.Options.GlobalContextPaths)
 422	c.Options.GlobalContextPaths = slices.Compact(c.Options.GlobalContextPaths)
 423
 424	if dataDir != "" {
 425		c.Options.DataDirectory = dataDir
 426	} else if c.Options.DataDirectory == "" {
 427		if path, ok := fsext.LookupClosestBounded(workingDir, projectBoundary(workingDir), defaultDataDirectory); ok {
 428			c.Options.DataDirectory = path
 429		} else {
 430			c.Options.DataDirectory = filepath.Join(workingDir, defaultDataDirectory)
 431		}
 432	}
 433	c.Options.DataDirectory = filepath.Clean(filepathext.SmartJoin(workingDir, c.Options.DataDirectory))
 434	if c.Providers == nil {
 435		c.Providers = csync.NewMap[string, ProviderConfig]()
 436	}
 437	if c.Models == nil {
 438		c.Models = make(map[SelectedModelType]SelectedModel)
 439	}
 440	if c.RecentModels == nil {
 441		c.RecentModels = make(map[SelectedModelType][]SelectedModel)
 442	}
 443	if c.MCP == nil {
 444		c.MCP = make(map[string]MCPConfig)
 445	}
 446	if c.LSP == nil {
 447		c.LSP = make(map[string]LSPConfig)
 448	}
 449
 450	// Apply defaults to LSP configurations
 451	c.applyLSPDefaults()
 452
 453	// Add the default context paths if they are not already present
 454	c.Options.ContextPaths = append(defaultContextPaths, c.Options.ContextPaths...)
 455
 456	slices.Sort(c.Options.ContextPaths)
 457	c.Options.ContextPaths = slices.Compact(c.Options.ContextPaths)
 458
 459	// Add the default skills directories if not already present.
 460	for _, dir := range GlobalSkillsDirs() {
 461		if !slices.Contains(c.Options.SkillsPaths, dir) {
 462			c.Options.SkillsPaths = append(c.Options.SkillsPaths, dir)
 463		}
 464	}
 465
 466	// Project specific skills dirs.
 467	c.Options.SkillsPaths = append(c.Options.SkillsPaths, ProjectSkillsDir(workingDir)...)
 468
 469	if str, ok := os.LookupEnv("CRUSH_DISABLE_PROVIDER_AUTO_UPDATE"); ok {
 470		c.Options.DisableProviderAutoUpdate, _ = strconv.ParseBool(str)
 471	}
 472
 473	if str, ok := os.LookupEnv("CRUSH_DISABLE_DEFAULT_PROVIDERS"); ok {
 474		c.Options.DisableDefaultProviders, _ = strconv.ParseBool(str)
 475	}
 476
 477	if c.Options.Attribution == nil {
 478		c.Options.Attribution = &Attribution{
 479			TrailerStyle:  TrailerStyleAssistedBy,
 480			GeneratedWith: true,
 481		}
 482	} else if c.Options.Attribution.TrailerStyle == "" {
 483		// Migrate deprecated co_authored_by or apply default
 484		if c.Options.Attribution.CoAuthoredBy != nil {
 485			if *c.Options.Attribution.CoAuthoredBy {
 486				c.Options.Attribution.TrailerStyle = TrailerStyleCoAuthoredBy
 487			} else {
 488				c.Options.Attribution.TrailerStyle = TrailerStyleNone
 489			}
 490		} else {
 491			c.Options.Attribution.TrailerStyle = TrailerStyleAssistedBy
 492		}
 493	}
 494	c.Options.InitializeAs = cmp.Or(c.Options.InitializeAs, defaultInitializeAs)
 495}
 496
 497// applyLSPDefaults applies default values from powernap to LSP configurations
 498func (c *Config) applyLSPDefaults() {
 499	// Get powernap's default configuration
 500	configManager := powernapConfig.NewManager()
 501	configManager.LoadDefaults()
 502
 503	// Apply defaults to each LSP configuration
 504	for name, cfg := range c.LSP {
 505		// Try to get defaults from powernap based on name or command name.
 506		base, ok := configManager.GetServer(name)
 507		if !ok {
 508			base, ok = configManager.GetServer(cfg.Command)
 509			if !ok {
 510				continue
 511			}
 512		}
 513		if cfg.Options == nil {
 514			cfg.Options = base.Settings
 515		}
 516		if cfg.InitOptions == nil {
 517			cfg.InitOptions = base.InitOptions
 518		}
 519		if len(cfg.FileTypes) == 0 {
 520			cfg.FileTypes = base.FileTypes
 521		}
 522		if len(cfg.RootMarkers) == 0 {
 523			cfg.RootMarkers = base.RootMarkers
 524		}
 525		cfg.Command = cmp.Or(cfg.Command, base.Command)
 526		if len(cfg.Args) == 0 {
 527			cfg.Args = base.Args
 528		}
 529		if len(cfg.Env) == 0 {
 530			cfg.Env = base.Environment
 531		}
 532		// Update the config in the map
 533		c.LSP[name] = cfg
 534	}
 535}
 536
 537func (c *Config) defaultModelSelection(knownProviders []catwalk.Provider) (largeModel SelectedModel, smallModel SelectedModel, err error) {
 538	if len(knownProviders) == 0 && c.Providers.Len() == 0 {
 539		err = fmt.Errorf("no providers configured, please configure at least one provider")
 540		return largeModel, smallModel, err
 541	}
 542
 543	// Use the first provider enabled based on the known providers order
 544	// if no provider found that is known use the first provider configured
 545	for _, p := range knownProviders {
 546		providerConfig, ok := c.Providers.Get(string(p.ID))
 547		if !ok || providerConfig.Disable {
 548			continue
 549		}
 550		defaultLargeModel := c.GetModel(string(p.ID), p.DefaultLargeModelID)
 551		if defaultLargeModel == nil {
 552			err = fmt.Errorf("default large model %s not found for provider %s", p.DefaultLargeModelID, p.ID)
 553			return largeModel, smallModel, err
 554		}
 555		largeModel = SelectedModel{
 556			Provider:        string(p.ID),
 557			Model:           defaultLargeModel.ID,
 558			MaxTokens:       defaultLargeModel.DefaultMaxTokens,
 559			ReasoningEffort: defaultLargeModel.DefaultReasoningEffort,
 560		}
 561
 562		defaultSmallModel := c.GetModel(string(p.ID), p.DefaultSmallModelID)
 563		if defaultSmallModel == nil {
 564			err = fmt.Errorf("default small model %s not found for provider %s", p.DefaultSmallModelID, p.ID)
 565			return largeModel, smallModel, err
 566		}
 567		smallModel = SelectedModel{
 568			Provider:        string(p.ID),
 569			Model:           defaultSmallModel.ID,
 570			MaxTokens:       defaultSmallModel.DefaultMaxTokens,
 571			ReasoningEffort: defaultSmallModel.DefaultReasoningEffort,
 572		}
 573		return largeModel, smallModel, err
 574	}
 575
 576	enabledProviders := c.EnabledProviders()
 577	slices.SortFunc(enabledProviders, func(a, b ProviderConfig) int {
 578		return strings.Compare(a.ID, b.ID)
 579	})
 580
 581	if len(enabledProviders) == 0 {
 582		err = fmt.Errorf("no providers configured, please configure at least one provider")
 583		return largeModel, smallModel, err
 584	}
 585
 586	providerConfig := enabledProviders[0]
 587	if len(providerConfig.Models) == 0 {
 588		err = fmt.Errorf("provider %s has no models configured", providerConfig.ID)
 589		return largeModel, smallModel, err
 590	}
 591	defaultLargeModel := c.GetModel(providerConfig.ID, providerConfig.Models[0].ID)
 592	largeModel = SelectedModel{
 593		Provider:  providerConfig.ID,
 594		Model:     defaultLargeModel.ID,
 595		MaxTokens: defaultLargeModel.DefaultMaxTokens,
 596	}
 597	defaultSmallModel := c.GetModel(providerConfig.ID, providerConfig.Models[0].ID)
 598	smallModel = SelectedModel{
 599		Provider:  providerConfig.ID,
 600		Model:     defaultSmallModel.ID,
 601		MaxTokens: defaultSmallModel.DefaultMaxTokens,
 602	}
 603	return largeModel, smallModel, err
 604}
 605
 606func configureSelectedModels(store *ConfigStore, knownProviders []catwalk.Provider, persist bool) error {
 607	c := store.config
 608	defaultLarge, defaultSmall, err := c.defaultModelSelection(knownProviders)
 609	if err != nil {
 610		return fmt.Errorf("failed to select default models: %w", err)
 611	}
 612	large, small := defaultLarge, defaultSmall
 613
 614	largeModelSelected, largeModelConfigured := c.Models[SelectedModelTypeLarge]
 615	if largeModelConfigured {
 616		if largeModelSelected.Model != "" {
 617			large.Model = largeModelSelected.Model
 618		}
 619		if largeModelSelected.Provider != "" {
 620			large.Provider = largeModelSelected.Provider
 621		}
 622		model := c.GetModel(large.Provider, large.Model)
 623		if model == nil {
 624			large = defaultLarge
 625			if persist {
 626				if err := store.UpdatePreferredModel(ScopeGlobal, SelectedModelTypeLarge, large); err != nil {
 627					return fmt.Errorf("failed to update preferred large model: %w", err)
 628				}
 629			}
 630		} else {
 631			if largeModelSelected.MaxTokens > 0 {
 632				large.MaxTokens = largeModelSelected.MaxTokens
 633			} else {
 634				large.MaxTokens = model.DefaultMaxTokens
 635			}
 636			if largeModelSelected.ReasoningEffort != "" {
 637				large.ReasoningEffort = largeModelSelected.ReasoningEffort
 638			}
 639			large.Think = largeModelSelected.Think
 640			if largeModelSelected.Temperature != nil {
 641				large.Temperature = largeModelSelected.Temperature
 642			}
 643			if largeModelSelected.TopP != nil {
 644				large.TopP = largeModelSelected.TopP
 645			}
 646			if largeModelSelected.TopK != nil {
 647				large.TopK = largeModelSelected.TopK
 648			}
 649			if largeModelSelected.FrequencyPenalty != nil {
 650				large.FrequencyPenalty = largeModelSelected.FrequencyPenalty
 651			}
 652			if largeModelSelected.PresencePenalty != nil {
 653				large.PresencePenalty = largeModelSelected.PresencePenalty
 654			}
 655		}
 656	}
 657	smallModelSelected, smallModelConfigured := c.Models[SelectedModelTypeSmall]
 658	if smallModelConfigured {
 659		if smallModelSelected.Model != "" {
 660			small.Model = smallModelSelected.Model
 661		}
 662		if smallModelSelected.Provider != "" {
 663			small.Provider = smallModelSelected.Provider
 664		}
 665
 666		model := c.GetModel(small.Provider, small.Model)
 667		if model == nil {
 668			small = defaultSmall
 669			if persist {
 670				if err := store.UpdatePreferredModel(ScopeGlobal, SelectedModelTypeSmall, small); err != nil {
 671					return fmt.Errorf("failed to update preferred small model: %w", err)
 672				}
 673			}
 674		} else {
 675			if smallModelSelected.MaxTokens > 0 {
 676				small.MaxTokens = smallModelSelected.MaxTokens
 677			} else {
 678				small.MaxTokens = model.DefaultMaxTokens
 679			}
 680			if smallModelSelected.ReasoningEffort != "" {
 681				small.ReasoningEffort = smallModelSelected.ReasoningEffort
 682			}
 683			if smallModelSelected.Temperature != nil {
 684				small.Temperature = smallModelSelected.Temperature
 685			}
 686			if smallModelSelected.TopP != nil {
 687				small.TopP = smallModelSelected.TopP
 688			}
 689			if smallModelSelected.TopK != nil {
 690				small.TopK = smallModelSelected.TopK
 691			}
 692			if smallModelSelected.FrequencyPenalty != nil {
 693				small.FrequencyPenalty = smallModelSelected.FrequencyPenalty
 694			}
 695			if smallModelSelected.PresencePenalty != nil {
 696				small.PresencePenalty = smallModelSelected.PresencePenalty
 697			}
 698			small.Think = smallModelSelected.Think
 699		}
 700	}
 701
 702	// When small isn't explicitly configured and the provider isn't a
 703	// known built-in, use the large model as the small model. This
 704	// prevents two different models from being requested concurrently
 705	// for local/openai-compat providers.
 706	if !smallModelConfigured {
 707		isKnownProvider := false
 708		for _, kp := range knownProviders {
 709			if string(kp.ID) == small.Provider {
 710				isKnownProvider = true
 711				break
 712			}
 713		}
 714		if !isKnownProvider {
 715			slog.Warn("Using large model as small model for unknown provider", "provider", large.Provider, "model", large.Model)
 716			small = large
 717		}
 718	}
 719
 720	c.Models[SelectedModelTypeLarge] = large
 721	c.Models[SelectedModelTypeSmall] = small
 722	return nil
 723}
 724
 725// lookupConfigs searches config files starting at cwd and walking up
 726// through the current project. The upward walk stops at the git
 727// working tree root when one can be detected, otherwise at cwd itself,
 728// so an unrelated crush.json placed above the project is never picked
 729// up. Global user-level config locations are always included
 730// regardless of the boundary.
 731func lookupConfigs(cwd string) []string {
 732	// prepend default config paths
 733	configPaths := []string{
 734		GlobalConfig(),
 735		GlobalConfigData(),
 736	}
 737
 738	configNames := []string{appName + ".json", "." + appName + ".json"}
 739
 740	foundConfigs, err := fsext.LookupBounded(cwd, projectBoundary(cwd), configNames...)
 741	if err != nil {
 742		// returns at least default configs
 743		return configPaths
 744	}
 745
 746	// reverse order so last config has more priority
 747	slices.Reverse(foundConfigs)
 748
 749	return append(configPaths, foundConfigs...)
 750}
 751
 752func loadFromConfigPaths(configPaths []string) (*Config, []string, error) {
 753	var configs [][]byte
 754	var loaded []string
 755
 756	for _, path := range configPaths {
 757		data, err := os.ReadFile(path)
 758		if err != nil {
 759			if os.IsNotExist(err) {
 760				continue
 761			}
 762			return nil, nil, fmt.Errorf("failed to open config file %s: %w", path, err)
 763		}
 764		if len(data) == 0 {
 765			continue
 766		}
 767		if !json.Valid(data) {
 768			return nil, nil, fmt.Errorf("invalid JSON in config file %s", path)
 769		}
 770		configs = append(configs, data)
 771		loaded = append(loaded, path)
 772	}
 773
 774	cfg, err := loadFromBytes(configs)
 775	if err != nil {
 776		return nil, nil, err
 777	}
 778	return cfg, loaded, nil
 779}
 780
 781func loadFromBytes(configs [][]byte) (*Config, error) {
 782	if len(configs) == 0 {
 783		return &Config{}, nil
 784	}
 785
 786	data, err := jsons.Merge(configs)
 787	if err != nil {
 788		return nil, err
 789	}
 790	var config Config
 791	if err := json.Unmarshal(data, &config); err != nil {
 792		return nil, err
 793	}
 794	return &config, nil
 795}
 796
 797func hasAWSCredentials(env env.Env) bool {
 798	if env.Get("AWS_BEARER_TOKEN_BEDROCK") != "" {
 799		return true
 800	}
 801
 802	if env.Get("AWS_ACCESS_KEY_ID") != "" && env.Get("AWS_SECRET_ACCESS_KEY") != "" {
 803		return true
 804	}
 805
 806	if env.Get("AWS_PROFILE") != "" || env.Get("AWS_DEFAULT_PROFILE") != "" {
 807		return true
 808	}
 809
 810	if env.Get("AWS_REGION") != "" || env.Get("AWS_DEFAULT_REGION") != "" {
 811		return true
 812	}
 813
 814	if env.Get("AWS_CONTAINER_CREDENTIALS_RELATIVE_URI") != "" ||
 815		env.Get("AWS_CONTAINER_CREDENTIALS_FULL_URI") != "" {
 816		return true
 817	}
 818
 819	if _, err := os.Stat(filepath.Join(home.Dir(), ".aws/credentials")); err == nil && !testing.Testing() {
 820		return true
 821	}
 822
 823	return false
 824}
 825
 826// GlobalConfig returns the global configuration file path for the application.
 827func GlobalConfig() string {
 828	if crushGlobal := os.Getenv("CRUSH_GLOBAL_CONFIG"); crushGlobal != "" {
 829		return filepath.Join(crushGlobal, fmt.Sprintf("%s.json", appName))
 830	}
 831	return filepath.Join(home.Config(), appName, fmt.Sprintf("%s.json", appName))
 832}
 833
 834// GlobalCacheDir returns the path to the global cache directory for the
 835// application.
 836func GlobalCacheDir() string {
 837	if crushCache := os.Getenv("CRUSH_CACHE_DIR"); crushCache != "" {
 838		return crushCache
 839	}
 840	if xdgCacheHome := os.Getenv("XDG_CACHE_HOME"); xdgCacheHome != "" {
 841		return filepath.Join(xdgCacheHome, appName)
 842	}
 843	if runtime.GOOS == "windows" {
 844		localAppData := cmp.Or(
 845			os.Getenv("LOCALAPPDATA"),
 846			filepath.Join(os.Getenv("USERPROFILE"), "AppData", "Local"),
 847		)
 848		return filepath.Join(localAppData, appName, "cache")
 849	}
 850	return filepath.Join(home.Dir(), ".cache", appName)
 851}
 852
 853// ProjectConfigs returns list of current project configs paths.
 854func ProjectConfigs(cwd string) []string {
 855	return lookupConfigs(cwd)
 856}
 857
 858// GlobalConfigData returns the path to the main data directory for the application.
 859// this config is used when the app overrides configurations instead of updating the global config.
 860func GlobalConfigData() string {
 861	if crushData := os.Getenv("CRUSH_GLOBAL_DATA"); crushData != "" {
 862		return filepath.Join(crushData, fmt.Sprintf("%s.json", appName))
 863	}
 864	if xdgDataHome := os.Getenv("XDG_DATA_HOME"); xdgDataHome != "" {
 865		return filepath.Join(xdgDataHome, appName, fmt.Sprintf("%s.json", appName))
 866	}
 867
 868	// return the path to the main data directory
 869	// for windows, it should be in `%LOCALAPPDATA%/crush/`
 870	// for linux and macOS, it should be in `$HOME/.local/share/crush/`
 871	if runtime.GOOS == "windows" {
 872		localAppData := cmp.Or(
 873			os.Getenv("LOCALAPPDATA"),
 874			filepath.Join(os.Getenv("USERPROFILE"), "AppData", "Local"),
 875		)
 876		return filepath.Join(localAppData, appName, fmt.Sprintf("%s.json", appName))
 877	}
 878
 879	return filepath.Join(home.Dir(), ".local", "share", appName, fmt.Sprintf("%s.json", appName))
 880}
 881
 882// GlobalWorkspaceDir returns the path to the global server workspace
 883// directory. This directory acts as a meta-workspace for the server
 884// process, giving it a real workingDir so that config loading, scoped
 885// writes, and provider resolution behave identically to project
 886// workspaces.
 887func GlobalWorkspaceDir() string {
 888	return filepath.Dir(GlobalConfigData())
 889}
 890
 891func assignIfNil[T any](ptr **T, val T) {
 892	if *ptr == nil {
 893		*ptr = &val
 894	}
 895}
 896
 897func isInsideWorktree() bool {
 898	bts, err := exec.CommandContext(
 899		context.Background(),
 900		"git", "rev-parse",
 901		"--is-inside-work-tree",
 902	).CombinedOutput()
 903	return err == nil && strings.TrimSpace(string(bts)) == "true"
 904}
 905
 906// worktreeRoot returns the absolute path of the git working tree root for
 907// dir, or the empty string if dir is not inside a working tree (bare
 908// repositories, missing git binary, plain directories, or any other
 909// failure mode). Linked worktrees and submodules each report their own
 910// top-level, which is what callers want when bounding lookups.
 911func worktreeRoot(dir string) string {
 912	cmd := exec.CommandContext(
 913		context.Background(),
 914		"git", "rev-parse", "--show-toplevel",
 915	)
 916	cmd.Dir = dir
 917	out, err := cmd.Output()
 918	if err != nil {
 919		return ""
 920	}
 921	root := strings.TrimSpace(string(out))
 922	if root == "" {
 923		return ""
 924	}
 925	abs, err := filepath.Abs(root)
 926	if err != nil {
 927		return ""
 928	}
 929	return abs
 930}
 931
 932// projectBoundary returns the directory at which an upward configuration
 933// search rooted at dir should stop. It is the git working tree root when
 934// one can be detected, otherwise dir itself. Returning dir as a
 935// fallback keeps Crush from silently adopting state files placed above
 936// the current project.
 937func projectBoundary(dir string) string {
 938	if root := worktreeRoot(dir); root != "" {
 939		return root
 940	}
 941	abs, err := filepath.Abs(dir)
 942	if err != nil {
 943		return dir
 944	}
 945	return abs
 946}
 947
 948// GlobalSkillsDirs returns the default directories for Agent Skills.
 949// Skills in these directories are auto-discovered and their files can be read
 950// without permission prompts.
 951func GlobalSkillsDirs() []string {
 952	if crushSkills := os.Getenv("CRUSH_SKILLS_DIR"); crushSkills != "" {
 953		return []string{crushSkills}
 954	}
 955
 956	paths := []string{
 957		filepath.Join(home.Config(), appName, "skills"),
 958		filepath.Join(home.Config(), "agents", "skills"),
 959		// Per the Agent Skills spec, scan ~/.agents/skills
 960		filepath.Join(home.Dir(), ".agents", "skills"),
 961		filepath.Join(home.Dir(), ".claude", "skills"),
 962	}
 963
 964	// On Windows, also load from app data on top of `$HOME/.config/crush`.
 965	// This is here mostly for backwards compatibility.
 966	if runtime.GOOS == "windows" {
 967		appData := cmp.Or(
 968			os.Getenv("LOCALAPPDATA"),
 969			filepath.Join(os.Getenv("USERPROFILE"), "AppData", "Local"),
 970		)
 971		paths = append(
 972			paths,
 973			filepath.Join(appData, appName, "skills"),
 974			filepath.Join(appData, "agents", "skills"),
 975		)
 976	}
 977
 978	return paths
 979}
 980
 981// ProjectSkillsDir returns the default project directories for which Crush
 982// will look for skills.
 983func ProjectSkillsDir(workingDir string) []string {
 984	return []string{
 985		filepath.Join(workingDir, ".agents/skills"),
 986		filepath.Join(workingDir, ".crush/skills"),
 987		filepath.Join(workingDir, ".claude/skills"),
 988		filepath.Join(workingDir, ".cursor/skills"),
 989	}
 990}
 991
 992func isAppleTerminal() bool { return os.Getenv("TERM_PROGRAM") == "Apple_Terminal" }
 993
 994// normalizeHookEvent maps user-provided event names to their canonical
 995// form. Matching is case-insensitive and accepts snake_case variants
 996// (e.g. "pre_tool_use" → "PreToolUse").
 997func normalizeHookEvent(name string) string {
 998	switch strings.ToLower(strings.ReplaceAll(name, "_", "")) {
 999	case "pretooluse":
1000		return "PreToolUse"
1001	default:
1002		return name
1003	}
1004}
1005
1006// ValidateHooks normalizes event names and checks that every configured
1007// hook has a command and a syntactically valid matcher regex. Matcher
1008// compilation used for matching is owned by hooks.Runner; this function
1009// only validates up front so the user sees config errors at load time
1010// rather than on the first tool call.
1011func (c *Config) ValidateHooks() error {
1012	// Normalize event name keys.
1013	for event, eventHooks := range c.Hooks {
1014		canonical := normalizeHookEvent(event)
1015		if canonical != event {
1016			c.Hooks[canonical] = append(c.Hooks[canonical], eventHooks...)
1017			delete(c.Hooks, event)
1018		}
1019	}
1020
1021	for event, eventHooks := range c.Hooks {
1022		for i, h := range eventHooks {
1023			if h.Command == "" {
1024				return fmt.Errorf("hook %s[%d]: command is required", event, i)
1025			}
1026			if h.Matcher == "" {
1027				continue
1028			}
1029			if _, err := regexp.Compile(h.Matcher); err != nil {
1030				return fmt.Errorf("hook %s[%d]: invalid matcher regex %q: %w", event, i, h.Matcher, err)
1031			}
1032		}
1033	}
1034	return nil
1035}