load.go

   1package config
   2
   3import (
   4	"cmp"
   5	"context"
   6	"encoding/json"
   7	"fmt"
   8	"log/slog"
   9	"maps"
  10	"os"
  11	"os/exec"
  12	"path/filepath"
  13	"regexp"
  14	"runtime"
  15	"slices"
  16	"strconv"
  17	"strings"
  18	"testing"
  19
  20	"charm.land/catwalk/pkg/catwalk"
  21	"github.com/charmbracelet/crush/internal/agent/hyper"
  22	"github.com/charmbracelet/crush/internal/csync"
  23	"github.com/charmbracelet/crush/internal/env"
  24	"github.com/charmbracelet/crush/internal/filepathext"
  25	"github.com/charmbracelet/crush/internal/fsext"
  26	"github.com/charmbracelet/crush/internal/home"
  27	powernapConfig "github.com/charmbracelet/x/powernap/pkg/config"
  28	"github.com/qjebbs/go-jsons"
  29)
  30
  31const defaultCatwalkURL = "https://catwalk.charm.land"
  32
  33// Load loads the configuration from the default paths and returns a
  34// ConfigStore that owns both the pure-data Config and all runtime state.
  35func Load(workingDir, dataDir string, debug bool) (*ConfigStore, error) {
  36	configPaths := lookupConfigs(workingDir)
  37
  38	cfg, loadedPaths, err := loadFromConfigPaths(configPaths)
  39	if err != nil {
  40		return nil, fmt.Errorf("failed to load config from paths %v: %w", configPaths, err)
  41	}
  42
  43	cfg.setDefaults(workingDir, dataDir)
  44
  45	store := &ConfigStore{
  46		config:         cfg,
  47		workingDir:     workingDir,
  48		globalDataPath: GlobalConfigData(),
  49		workspacePath:  filepath.Join(cfg.Options.DataDirectory, fmt.Sprintf("%s.json", appName)),
  50		loadedPaths:    loadedPaths,
  51	}
  52
  53	if debug {
  54		cfg.Options.Debug = true
  55	}
  56
  57	// Load workspace config last so it has highest priority.
  58	if wsData, err := os.ReadFile(store.workspacePath); err == nil && len(wsData) > 0 {
  59		if !json.Valid(wsData) {
  60			return nil, fmt.Errorf("invalid JSON in config file %s", store.workspacePath)
  61		}
  62		merged, mergeErr := loadFromBytes(append([][]byte{mustMarshalConfig(cfg)}, wsData))
  63		if mergeErr == nil {
  64			// Preserve defaults that setDefaults already applied.
  65			dataDir := cfg.Options.DataDirectory
  66			*cfg = *merged
  67			cfg.setDefaults(workingDir, dataDir)
  68			store.config = cfg
  69			store.loadedPaths = append(store.loadedPaths, store.workspacePath)
  70		}
  71	}
  72
  73	// Validate hooks after all config merging is complete so workspace
  74	// hooks also get their matcher regexes compiled.
  75	if err := cfg.ValidateHooks(); err != nil {
  76		return nil, fmt.Errorf("invalid hook configuration: %w", err)
  77	}
  78
  79	if !isInsideWorktree() {
  80		const depth = 2
  81		const items = 100
  82		slog.Warn("No git repository detected in working directory, will limit file walk operations", "depth", depth, "items", items)
  83		assignIfNil(&cfg.Tools.Ls.MaxDepth, depth)
  84		assignIfNil(&cfg.Tools.Ls.MaxItems, items)
  85		assignIfNil(&cfg.Options.TUI.Completions.MaxDepth, depth)
  86		assignIfNil(&cfg.Options.TUI.Completions.MaxItems, items)
  87	}
  88
  89	if isAppleTerminal() {
  90		slog.Warn("Detected Apple Terminal, enabling transparent mode")
  91		assignIfNil(&cfg.Options.TUI.Transparent, true)
  92	}
  93
  94	// Load known providers, this loads the config from catwalk
  95	providers, err := Providers(cfg)
  96	if err != nil {
  97		return nil, err
  98	}
  99	store.knownProviders = providers
 100
 101	env := env.New()
 102	// Configure providers
 103	valueResolver := NewShellVariableResolver(env)
 104	store.resolver = valueResolver
 105
 106	// Disable auto-reload during initial load to prevent nested calls from
 107	// config-modifying operations inside configureProviders.
 108	store.autoReloadDisabled = true
 109	defer func() { store.autoReloadDisabled = false }()
 110
 111	if err := cfg.configureProviders(store, env, valueResolver, store.knownProviders); err != nil {
 112		return nil, fmt.Errorf("failed to configure providers: %w", err)
 113	}
 114
 115	if !cfg.IsConfigured() {
 116		slog.Warn("No providers configured")
 117		return store, nil
 118	}
 119
 120	if err := configureSelectedModels(store, store.knownProviders, true); err != nil {
 121		return nil, fmt.Errorf("failed to configure selected models: %w", err)
 122	}
 123	store.SetupAgents()
 124
 125	// Capture initial staleness snapshot
 126	store.captureStalenessSnapshot(loadedPaths)
 127
 128	return store, nil
 129}
 130
 131// mustMarshalConfig marshals the config to JSON bytes, returning empty JSON on
 132// error.
 133func mustMarshalConfig(cfg *Config) []byte {
 134	data, err := json.Marshal(cfg)
 135	if err != nil {
 136		return []byte("{}")
 137	}
 138	return data
 139}
 140
 141func PushPopCrushEnv() func() {
 142	var found []string
 143	for _, ev := range os.Environ() {
 144		if strings.HasPrefix(ev, "CRUSH_") {
 145			pair := strings.SplitN(ev, "=", 2)
 146			if len(pair) != 2 {
 147				continue
 148			}
 149			found = append(found, strings.TrimPrefix(pair[0], "CRUSH_"))
 150		}
 151	}
 152	backups := make(map[string]string)
 153	for _, ev := range found {
 154		backups[ev] = os.Getenv(ev)
 155	}
 156
 157	for _, ev := range found {
 158		os.Setenv(ev, os.Getenv("CRUSH_"+ev))
 159	}
 160
 161	restore := func() {
 162		for k, v := range backups {
 163			os.Setenv(k, v)
 164		}
 165	}
 166	return restore
 167}
 168
 169func (c *Config) configureProviders(store *ConfigStore, env env.Env, resolver VariableResolver, knownProviders []catwalk.Provider) error {
 170	knownProviderNames := make(map[string]bool)
 171	restore := PushPopCrushEnv()
 172	defer restore()
 173
 174	// When disable_default_providers is enabled, skip all default/embedded
 175	// providers entirely. Users must fully specify any providers they want.
 176	// We skip to the custom provider validation loop which handles all
 177	// user-configured providers uniformly.
 178	if c.Options.DisableDefaultProviders {
 179		knownProviders = nil
 180	}
 181
 182	for _, p := range knownProviders {
 183		knownProviderNames[string(p.ID)] = true
 184		config, configExists := c.Providers.Get(string(p.ID))
 185		// if the user configured a known provider we need to allow it to override a couple of parameters
 186		if configExists {
 187			if config.BaseURL != "" {
 188				p.APIEndpoint = config.BaseURL
 189			}
 190			if config.APIKey != "" {
 191				p.APIKey = config.APIKey
 192			}
 193			if len(config.Models) > 0 {
 194				models := []catwalk.Model{}
 195				seen := make(map[string]bool)
 196
 197				for _, model := range config.Models {
 198					if seen[model.ID] {
 199						continue
 200					}
 201					seen[model.ID] = true
 202					if model.Name == "" {
 203						model.Name = model.ID
 204					}
 205					models = append(models, model)
 206				}
 207				for _, model := range p.Models {
 208					if seen[model.ID] {
 209						continue
 210					}
 211					seen[model.ID] = true
 212					if model.Name == "" {
 213						model.Name = model.ID
 214					}
 215					models = append(models, model)
 216				}
 217
 218				p.Models = models
 219			}
 220		}
 221
 222		headers := map[string]string{}
 223		if len(p.DefaultHeaders) > 0 {
 224			maps.Copy(headers, p.DefaultHeaders)
 225		}
 226		if len(config.ExtraHeaders) > 0 {
 227			maps.Copy(headers, config.ExtraHeaders)
 228		}
 229		// Provider headers use the same error contract as MCP headers:
 230		// a failing $(...) aborts the provider load with a clear
 231		// message, and a header that resolves to the empty string
 232		// (unset bare $VAR under lenient nounset, $(echo), or literal
 233		// "") is dropped from the outgoing request.
 234		for k, v := range headers {
 235			resolved, err := resolver.ResolveValue(v)
 236			if err != nil {
 237				return fmt.Errorf("resolving provider %s header %q: %w", p.ID, k, err)
 238			}
 239			if resolved == "" {
 240				delete(headers, k)
 241				continue
 242			}
 243			headers[k] = resolved
 244		}
 245		prepared := ProviderConfig{
 246			ID:                 string(p.ID),
 247			Name:               p.Name,
 248			BaseURL:            p.APIEndpoint,
 249			APIKey:             p.APIKey,
 250			APIKeyTemplate:     p.APIKey, // Store original template for re-resolution
 251			OAuthToken:         config.OAuthToken,
 252			Type:               p.Type,
 253			Disable:            config.Disable,
 254			SystemPromptPrefix: config.SystemPromptPrefix,
 255			ExtraHeaders:       headers,
 256			ExtraBody:          config.ExtraBody,
 257			ExtraParams:        make(map[string]string),
 258			Models:             p.Models,
 259		}
 260
 261		switch {
 262		case p.ID == catwalk.InferenceProviderAnthropic && config.OAuthToken != nil:
 263			// Claude Code subscription is not supported anymore. Remove to show onboarding.
 264			if !store.reloadInProgress {
 265				store.RemoveConfigField(ScopeGlobal, "providers.anthropic")
 266			}
 267			c.Providers.Del(string(p.ID))
 268			continue
 269		case p.ID == catwalk.InferenceProviderCopilot && config.OAuthToken != nil:
 270			prepared.SetupGitHubCopilot()
 271		}
 272
 273		switch p.ID {
 274		// Handle specific providers that require additional configuration
 275		case catwalk.InferenceProviderVertexAI:
 276			var (
 277				project  = env.Get("VERTEXAI_PROJECT")
 278				location = env.Get("VERTEXAI_LOCATION")
 279			)
 280			if project == "" || location == "" {
 281				if configExists {
 282					slog.Warn("Skipping Vertex AI provider due to missing credentials")
 283					c.Providers.Del(string(p.ID))
 284				}
 285				continue
 286			}
 287			prepared.ExtraParams["project"] = project
 288			prepared.ExtraParams["location"] = location
 289		case catwalk.InferenceProviderAzure:
 290			endpoint, err := resolver.ResolveValue(p.APIEndpoint)
 291			if err != nil || endpoint == "" {
 292				if configExists {
 293					slog.Warn("Skipping Azure provider due to missing API endpoint", "provider", p.ID, "error", err)
 294					c.Providers.Del(string(p.ID))
 295				}
 296				continue
 297			}
 298			prepared.BaseURL = endpoint
 299			prepared.ExtraParams["apiVersion"] = env.Get("AZURE_OPENAI_API_VERSION")
 300		case catwalk.InferenceProviderBedrock:
 301			if !hasAWSCredentials(env) {
 302				if configExists {
 303					slog.Warn("Skipping Bedrock provider due to missing AWS credentials")
 304					c.Providers.Del(string(p.ID))
 305				}
 306				continue
 307			}
 308			prepared.ExtraParams["region"] = env.Get("AWS_REGION")
 309			if prepared.ExtraParams["region"] == "" {
 310				prepared.ExtraParams["region"] = env.Get("AWS_DEFAULT_REGION")
 311			}
 312			for _, model := range p.Models {
 313				if !strings.HasPrefix(model.ID, "anthropic.") {
 314					return fmt.Errorf("bedrock provider only supports anthropic models for now, found: %s", model.ID)
 315				}
 316			}
 317		case catwalk.InferenceProvider("hyper"):
 318			if apiKey := env.Get("HYPER_API_KEY"); apiKey != "" {
 319				prepared.APIKey = apiKey
 320				prepared.APIKeyTemplate = apiKey
 321			} else {
 322				v, err := resolver.ResolveValue(p.APIKey)
 323				if v == "" || err != nil {
 324					if configExists {
 325						slog.Warn("Skipping Hyper provider due to missing API key", "provider", p.ID)
 326						c.Providers.Del(string(p.ID))
 327					}
 328					continue
 329				}
 330			}
 331		default:
 332			// if the provider api or endpoint are missing we skip them
 333			v, err := resolver.ResolveValue(p.APIKey)
 334			if v == "" || err != nil {
 335				if configExists {
 336					slog.Warn("Skipping provider due to missing API key", "provider", p.ID)
 337					c.Providers.Del(string(p.ID))
 338				}
 339				continue
 340			}
 341		}
 342		c.Providers.Set(string(p.ID), prepared)
 343	}
 344
 345	// validate the custom providers
 346	for id, providerConfig := range c.Providers.Seq2() {
 347		if knownProviderNames[id] {
 348			continue
 349		}
 350
 351		// Make sure the provider ID is set
 352		providerConfig.ID = id
 353		providerConfig.Name = cmp.Or(providerConfig.Name, id) // Use ID as name if not set
 354		// default to OpenAI if not set
 355		providerConfig.Type = cmp.Or(providerConfig.Type, catwalk.TypeOpenAICompat)
 356		if !slices.Contains(catwalk.KnownProviderTypes(), providerConfig.Type) && providerConfig.Type != hyper.Name {
 357			slog.Warn("Skipping custom provider due to unsupported provider type", "provider", id)
 358			c.Providers.Del(id)
 359			continue
 360		}
 361
 362		if providerConfig.Disable {
 363			slog.Debug("Skipping custom provider due to disable flag", "provider", id)
 364			c.Providers.Del(id)
 365			continue
 366		}
 367		if providerConfig.APIKey == "" {
 368			slog.Warn("Provider is missing API key, this might be OK for local providers", "provider", id)
 369		}
 370		if providerConfig.BaseURL == "" {
 371			slog.Warn("Skipping custom provider due to missing API endpoint", "provider", id)
 372			c.Providers.Del(id)
 373			continue
 374		}
 375		if len(providerConfig.Models) == 0 {
 376			slog.Warn("Skipping custom provider because the provider has no models", "provider", id)
 377			c.Providers.Del(id)
 378			continue
 379		}
 380		apiKey, err := resolver.ResolveValue(providerConfig.APIKey)
 381		if apiKey == "" || err != nil {
 382			slog.Warn("Provider is missing API key, this might be OK for local providers", "provider", id)
 383		}
 384		baseURL, err := resolver.ResolveValue(providerConfig.BaseURL)
 385		if baseURL == "" || err != nil {
 386			slog.Warn("Skipping custom provider due to missing API endpoint", "provider", id, "error", err)
 387			c.Providers.Del(id)
 388			continue
 389		}
 390
 391		// Custom-provider headers share the MCP error contract; see
 392		// the known-provider loop above.
 393		for k, v := range providerConfig.ExtraHeaders {
 394			resolved, err := resolver.ResolveValue(v)
 395			if err != nil {
 396				return fmt.Errorf("resolving provider %s header %q: %w", id, k, err)
 397			}
 398			if resolved == "" {
 399				delete(providerConfig.ExtraHeaders, k)
 400				continue
 401			}
 402			providerConfig.ExtraHeaders[k] = resolved
 403		}
 404
 405		c.Providers.Set(id, providerConfig)
 406	}
 407
 408	if c.Providers.Len() == 0 && c.Options.DisableDefaultProviders {
 409		return fmt.Errorf("default providers are disabled and there are no custom providers are configured")
 410	}
 411
 412	return nil
 413}
 414
 415func (c *Config) setDefaults(workingDir, dataDir string) {
 416	if c.Options == nil {
 417		c.Options = &Options{}
 418	}
 419	if c.Options.TUI == nil {
 420		c.Options.TUI = &TUIOptions{}
 421	}
 422	if dataDir != "" {
 423		c.Options.DataDirectory = dataDir
 424	} else if c.Options.DataDirectory == "" {
 425		if path, ok := fsext.LookupClosestBounded(workingDir, projectBoundary(workingDir), defaultDataDirectory); ok {
 426			c.Options.DataDirectory = path
 427		} else {
 428			c.Options.DataDirectory = filepath.Join(workingDir, defaultDataDirectory)
 429		}
 430	}
 431	c.Options.DataDirectory = filepath.Clean(filepathext.SmartJoin(workingDir, c.Options.DataDirectory))
 432	if c.Providers == nil {
 433		c.Providers = csync.NewMap[string, ProviderConfig]()
 434	}
 435	if c.Models == nil {
 436		c.Models = make(map[SelectedModelType]SelectedModel)
 437	}
 438	if c.RecentModels == nil {
 439		c.RecentModels = make(map[SelectedModelType][]SelectedModel)
 440	}
 441	if c.MCP == nil {
 442		c.MCP = make(map[string]MCPConfig)
 443	}
 444	if c.LSP == nil {
 445		c.LSP = make(map[string]LSPConfig)
 446	}
 447
 448	// Apply defaults to LSP configurations
 449	c.applyLSPDefaults()
 450
 451	// Add the default context paths if they are not already present
 452	c.Options.ContextPaths = append(defaultContextPaths, c.Options.ContextPaths...)
 453	slices.Sort(c.Options.ContextPaths)
 454	c.Options.ContextPaths = slices.Compact(c.Options.ContextPaths)
 455
 456	// Add the default skills directories if not already present.
 457	for _, dir := range GlobalSkillsDirs() {
 458		if !slices.Contains(c.Options.SkillsPaths, dir) {
 459			c.Options.SkillsPaths = append(c.Options.SkillsPaths, dir)
 460		}
 461	}
 462
 463	// Project specific skills dirs.
 464	c.Options.SkillsPaths = append(c.Options.SkillsPaths, ProjectSkillsDir(workingDir)...)
 465
 466	if str, ok := os.LookupEnv("CRUSH_DISABLE_PROVIDER_AUTO_UPDATE"); ok {
 467		c.Options.DisableProviderAutoUpdate, _ = strconv.ParseBool(str)
 468	}
 469
 470	if str, ok := os.LookupEnv("CRUSH_DISABLE_DEFAULT_PROVIDERS"); ok {
 471		c.Options.DisableDefaultProviders, _ = strconv.ParseBool(str)
 472	}
 473
 474	if c.Options.Attribution == nil {
 475		c.Options.Attribution = &Attribution{
 476			TrailerStyle:  TrailerStyleAssistedBy,
 477			GeneratedWith: true,
 478		}
 479	} else if c.Options.Attribution.TrailerStyle == "" {
 480		// Migrate deprecated co_authored_by or apply default
 481		if c.Options.Attribution.CoAuthoredBy != nil {
 482			if *c.Options.Attribution.CoAuthoredBy {
 483				c.Options.Attribution.TrailerStyle = TrailerStyleCoAuthoredBy
 484			} else {
 485				c.Options.Attribution.TrailerStyle = TrailerStyleNone
 486			}
 487		} else {
 488			c.Options.Attribution.TrailerStyle = TrailerStyleAssistedBy
 489		}
 490	}
 491	c.Options.InitializeAs = cmp.Or(c.Options.InitializeAs, defaultInitializeAs)
 492}
 493
 494// applyLSPDefaults applies default values from powernap to LSP configurations
 495func (c *Config) applyLSPDefaults() {
 496	// Get powernap's default configuration
 497	configManager := powernapConfig.NewManager()
 498	configManager.LoadDefaults()
 499
 500	// Apply defaults to each LSP configuration
 501	for name, cfg := range c.LSP {
 502		// Try to get defaults from powernap based on name or command name.
 503		base, ok := configManager.GetServer(name)
 504		if !ok {
 505			base, ok = configManager.GetServer(cfg.Command)
 506			if !ok {
 507				continue
 508			}
 509		}
 510		if cfg.Options == nil {
 511			cfg.Options = base.Settings
 512		}
 513		if cfg.InitOptions == nil {
 514			cfg.InitOptions = base.InitOptions
 515		}
 516		if len(cfg.FileTypes) == 0 {
 517			cfg.FileTypes = base.FileTypes
 518		}
 519		if len(cfg.RootMarkers) == 0 {
 520			cfg.RootMarkers = base.RootMarkers
 521		}
 522		cfg.Command = cmp.Or(cfg.Command, base.Command)
 523		if len(cfg.Args) == 0 {
 524			cfg.Args = base.Args
 525		}
 526		if len(cfg.Env) == 0 {
 527			cfg.Env = base.Environment
 528		}
 529		// Update the config in the map
 530		c.LSP[name] = cfg
 531	}
 532}
 533
 534func (c *Config) defaultModelSelection(knownProviders []catwalk.Provider) (largeModel SelectedModel, smallModel SelectedModel, err error) {
 535	if len(knownProviders) == 0 && c.Providers.Len() == 0 {
 536		err = fmt.Errorf("no providers configured, please configure at least one provider")
 537		return largeModel, smallModel, err
 538	}
 539
 540	// Use the first provider enabled based on the known providers order
 541	// if no provider found that is known use the first provider configured
 542	for _, p := range knownProviders {
 543		providerConfig, ok := c.Providers.Get(string(p.ID))
 544		if !ok || providerConfig.Disable {
 545			continue
 546		}
 547		defaultLargeModel := c.GetModel(string(p.ID), p.DefaultLargeModelID)
 548		if defaultLargeModel == nil {
 549			err = fmt.Errorf("default large model %s not found for provider %s", p.DefaultLargeModelID, p.ID)
 550			return largeModel, smallModel, err
 551		}
 552		largeModel = SelectedModel{
 553			Provider:        string(p.ID),
 554			Model:           defaultLargeModel.ID,
 555			MaxTokens:       defaultLargeModel.DefaultMaxTokens,
 556			ReasoningEffort: defaultLargeModel.DefaultReasoningEffort,
 557		}
 558
 559		defaultSmallModel := c.GetModel(string(p.ID), p.DefaultSmallModelID)
 560		if defaultSmallModel == nil {
 561			err = fmt.Errorf("default small model %s not found for provider %s", p.DefaultSmallModelID, p.ID)
 562			return largeModel, smallModel, err
 563		}
 564		smallModel = SelectedModel{
 565			Provider:        string(p.ID),
 566			Model:           defaultSmallModel.ID,
 567			MaxTokens:       defaultSmallModel.DefaultMaxTokens,
 568			ReasoningEffort: defaultSmallModel.DefaultReasoningEffort,
 569		}
 570		return largeModel, smallModel, err
 571	}
 572
 573	enabledProviders := c.EnabledProviders()
 574	slices.SortFunc(enabledProviders, func(a, b ProviderConfig) int {
 575		return strings.Compare(a.ID, b.ID)
 576	})
 577
 578	if len(enabledProviders) == 0 {
 579		err = fmt.Errorf("no providers configured, please configure at least one provider")
 580		return largeModel, smallModel, err
 581	}
 582
 583	providerConfig := enabledProviders[0]
 584	if len(providerConfig.Models) == 0 {
 585		err = fmt.Errorf("provider %s has no models configured", providerConfig.ID)
 586		return largeModel, smallModel, err
 587	}
 588	defaultLargeModel := c.GetModel(providerConfig.ID, providerConfig.Models[0].ID)
 589	largeModel = SelectedModel{
 590		Provider:  providerConfig.ID,
 591		Model:     defaultLargeModel.ID,
 592		MaxTokens: defaultLargeModel.DefaultMaxTokens,
 593	}
 594	defaultSmallModel := c.GetModel(providerConfig.ID, providerConfig.Models[0].ID)
 595	smallModel = SelectedModel{
 596		Provider:  providerConfig.ID,
 597		Model:     defaultSmallModel.ID,
 598		MaxTokens: defaultSmallModel.DefaultMaxTokens,
 599	}
 600	return largeModel, smallModel, err
 601}
 602
 603func configureSelectedModels(store *ConfigStore, knownProviders []catwalk.Provider, persist bool) error {
 604	c := store.config
 605	defaultLarge, defaultSmall, err := c.defaultModelSelection(knownProviders)
 606	if err != nil {
 607		return fmt.Errorf("failed to select default models: %w", err)
 608	}
 609	large, small := defaultLarge, defaultSmall
 610
 611	largeModelSelected, largeModelConfigured := c.Models[SelectedModelTypeLarge]
 612	if largeModelConfigured {
 613		if largeModelSelected.Model != "" {
 614			large.Model = largeModelSelected.Model
 615		}
 616		if largeModelSelected.Provider != "" {
 617			large.Provider = largeModelSelected.Provider
 618		}
 619		model := c.GetModel(large.Provider, large.Model)
 620		if model == nil {
 621			large = defaultLarge
 622			if persist {
 623				if err := store.UpdatePreferredModel(ScopeGlobal, SelectedModelTypeLarge, large); err != nil {
 624					return fmt.Errorf("failed to update preferred large model: %w", err)
 625				}
 626			}
 627		} else {
 628			if largeModelSelected.MaxTokens > 0 {
 629				large.MaxTokens = largeModelSelected.MaxTokens
 630			} else {
 631				large.MaxTokens = model.DefaultMaxTokens
 632			}
 633			if largeModelSelected.ReasoningEffort != "" {
 634				large.ReasoningEffort = largeModelSelected.ReasoningEffort
 635			}
 636			large.Think = largeModelSelected.Think
 637			if largeModelSelected.Temperature != nil {
 638				large.Temperature = largeModelSelected.Temperature
 639			}
 640			if largeModelSelected.TopP != nil {
 641				large.TopP = largeModelSelected.TopP
 642			}
 643			if largeModelSelected.TopK != nil {
 644				large.TopK = largeModelSelected.TopK
 645			}
 646			if largeModelSelected.FrequencyPenalty != nil {
 647				large.FrequencyPenalty = largeModelSelected.FrequencyPenalty
 648			}
 649			if largeModelSelected.PresencePenalty != nil {
 650				large.PresencePenalty = largeModelSelected.PresencePenalty
 651			}
 652		}
 653	}
 654	smallModelSelected, smallModelConfigured := c.Models[SelectedModelTypeSmall]
 655	if smallModelConfigured {
 656		if smallModelSelected.Model != "" {
 657			small.Model = smallModelSelected.Model
 658		}
 659		if smallModelSelected.Provider != "" {
 660			small.Provider = smallModelSelected.Provider
 661		}
 662
 663		model := c.GetModel(small.Provider, small.Model)
 664		if model == nil {
 665			small = defaultSmall
 666			if persist {
 667				if err := store.UpdatePreferredModel(ScopeGlobal, SelectedModelTypeSmall, small); err != nil {
 668					return fmt.Errorf("failed to update preferred small model: %w", err)
 669				}
 670			}
 671		} else {
 672			if smallModelSelected.MaxTokens > 0 {
 673				small.MaxTokens = smallModelSelected.MaxTokens
 674			} else {
 675				small.MaxTokens = model.DefaultMaxTokens
 676			}
 677			if smallModelSelected.ReasoningEffort != "" {
 678				small.ReasoningEffort = smallModelSelected.ReasoningEffort
 679			}
 680			if smallModelSelected.Temperature != nil {
 681				small.Temperature = smallModelSelected.Temperature
 682			}
 683			if smallModelSelected.TopP != nil {
 684				small.TopP = smallModelSelected.TopP
 685			}
 686			if smallModelSelected.TopK != nil {
 687				small.TopK = smallModelSelected.TopK
 688			}
 689			if smallModelSelected.FrequencyPenalty != nil {
 690				small.FrequencyPenalty = smallModelSelected.FrequencyPenalty
 691			}
 692			if smallModelSelected.PresencePenalty != nil {
 693				small.PresencePenalty = smallModelSelected.PresencePenalty
 694			}
 695			small.Think = smallModelSelected.Think
 696		}
 697	}
 698
 699	// When small isn't explicitly configured and the provider isn't a
 700	// known built-in, use the large model as the small model. This
 701	// prevents two different models from being requested concurrently
 702	// for local/openai-compat providers.
 703	if !smallModelConfigured {
 704		isKnownProvider := false
 705		for _, kp := range knownProviders {
 706			if string(kp.ID) == small.Provider {
 707				isKnownProvider = true
 708				break
 709			}
 710		}
 711		if !isKnownProvider {
 712			slog.Warn("Using large model as small model for unknown provider", "provider", large.Provider, "model", large.Model)
 713			small = large
 714		}
 715	}
 716
 717	c.Models[SelectedModelTypeLarge] = large
 718	c.Models[SelectedModelTypeSmall] = small
 719	return nil
 720}
 721
 722// lookupConfigs searches config files starting at cwd and walking up
 723// through the current project. The upward walk stops at the git
 724// working tree root when one can be detected, otherwise at cwd itself,
 725// so an unrelated crush.json placed above the project is never picked
 726// up. Global user-level config locations are always included
 727// regardless of the boundary.
 728func lookupConfigs(cwd string) []string {
 729	// prepend default config paths
 730	configPaths := []string{
 731		GlobalConfig(),
 732		GlobalConfigData(),
 733	}
 734
 735	configNames := []string{appName + ".json", "." + appName + ".json"}
 736
 737	foundConfigs, err := fsext.LookupBounded(cwd, projectBoundary(cwd), configNames...)
 738	if err != nil {
 739		// returns at least default configs
 740		return configPaths
 741	}
 742
 743	// reverse order so last config has more priority
 744	slices.Reverse(foundConfigs)
 745
 746	return append(configPaths, foundConfigs...)
 747}
 748
 749func loadFromConfigPaths(configPaths []string) (*Config, []string, error) {
 750	var configs [][]byte
 751	var loaded []string
 752
 753	for _, path := range configPaths {
 754		data, err := os.ReadFile(path)
 755		if err != nil {
 756			if os.IsNotExist(err) {
 757				continue
 758			}
 759			return nil, nil, fmt.Errorf("failed to open config file %s: %w", path, err)
 760		}
 761		if len(data) == 0 {
 762			continue
 763		}
 764		if !json.Valid(data) {
 765			return nil, nil, fmt.Errorf("invalid JSON in config file %s", path)
 766		}
 767		configs = append(configs, data)
 768		loaded = append(loaded, path)
 769	}
 770
 771	cfg, err := loadFromBytes(configs)
 772	if err != nil {
 773		return nil, nil, err
 774	}
 775	return cfg, loaded, nil
 776}
 777
 778func loadFromBytes(configs [][]byte) (*Config, error) {
 779	if len(configs) == 0 {
 780		return &Config{}, nil
 781	}
 782
 783	data, err := jsons.Merge(configs)
 784	if err != nil {
 785		return nil, err
 786	}
 787	var config Config
 788	if err := json.Unmarshal(data, &config); err != nil {
 789		return nil, err
 790	}
 791	return &config, nil
 792}
 793
 794func hasAWSCredentials(env env.Env) bool {
 795	if env.Get("AWS_BEARER_TOKEN_BEDROCK") != "" {
 796		return true
 797	}
 798
 799	if env.Get("AWS_ACCESS_KEY_ID") != "" && env.Get("AWS_SECRET_ACCESS_KEY") != "" {
 800		return true
 801	}
 802
 803	if env.Get("AWS_PROFILE") != "" || env.Get("AWS_DEFAULT_PROFILE") != "" {
 804		return true
 805	}
 806
 807	if env.Get("AWS_REGION") != "" || env.Get("AWS_DEFAULT_REGION") != "" {
 808		return true
 809	}
 810
 811	if env.Get("AWS_CONTAINER_CREDENTIALS_RELATIVE_URI") != "" ||
 812		env.Get("AWS_CONTAINER_CREDENTIALS_FULL_URI") != "" {
 813		return true
 814	}
 815
 816	if _, err := os.Stat(filepath.Join(home.Dir(), ".aws/credentials")); err == nil && !testing.Testing() {
 817		return true
 818	}
 819
 820	return false
 821}
 822
 823// GlobalConfig returns the global configuration file path for the application.
 824func GlobalConfig() string {
 825	if crushGlobal := os.Getenv("CRUSH_GLOBAL_CONFIG"); crushGlobal != "" {
 826		return filepath.Join(crushGlobal, fmt.Sprintf("%s.json", appName))
 827	}
 828	return filepath.Join(home.Config(), appName, fmt.Sprintf("%s.json", appName))
 829}
 830
 831// GlobalCacheDir returns the path to the global cache directory for the
 832// application.
 833func GlobalCacheDir() string {
 834	if crushCache := os.Getenv("CRUSH_CACHE_DIR"); crushCache != "" {
 835		return crushCache
 836	}
 837	if xdgCacheHome := os.Getenv("XDG_CACHE_HOME"); xdgCacheHome != "" {
 838		return filepath.Join(xdgCacheHome, appName)
 839	}
 840	if runtime.GOOS == "windows" {
 841		localAppData := cmp.Or(
 842			os.Getenv("LOCALAPPDATA"),
 843			filepath.Join(os.Getenv("USERPROFILE"), "AppData", "Local"),
 844		)
 845		return filepath.Join(localAppData, appName, "cache")
 846	}
 847	return filepath.Join(home.Dir(), ".cache", appName)
 848}
 849
 850// ProjectConfigs returns list of current project configs paths.
 851func ProjectConfigs(cwd string) []string {
 852	return lookupConfigs(cwd)
 853}
 854
 855// GlobalConfigData returns the path to the main data directory for the application.
 856// this config is used when the app overrides configurations instead of updating the global config.
 857func GlobalConfigData() string {
 858	if crushData := os.Getenv("CRUSH_GLOBAL_DATA"); crushData != "" {
 859		return filepath.Join(crushData, fmt.Sprintf("%s.json", appName))
 860	}
 861	if xdgDataHome := os.Getenv("XDG_DATA_HOME"); xdgDataHome != "" {
 862		return filepath.Join(xdgDataHome, appName, fmt.Sprintf("%s.json", appName))
 863	}
 864
 865	// return the path to the main data directory
 866	// for windows, it should be in `%LOCALAPPDATA%/crush/`
 867	// for linux and macOS, it should be in `$HOME/.local/share/crush/`
 868	if runtime.GOOS == "windows" {
 869		localAppData := cmp.Or(
 870			os.Getenv("LOCALAPPDATA"),
 871			filepath.Join(os.Getenv("USERPROFILE"), "AppData", "Local"),
 872		)
 873		return filepath.Join(localAppData, appName, fmt.Sprintf("%s.json", appName))
 874	}
 875
 876	return filepath.Join(home.Dir(), ".local", "share", appName, fmt.Sprintf("%s.json", appName))
 877}
 878
 879// GlobalWorkspaceDir returns the path to the global server workspace
 880// directory. This directory acts as a meta-workspace for the server
 881// process, giving it a real workingDir so that config loading, scoped
 882// writes, and provider resolution behave identically to project
 883// workspaces.
 884func GlobalWorkspaceDir() string {
 885	return filepath.Dir(GlobalConfigData())
 886}
 887
 888func assignIfNil[T any](ptr **T, val T) {
 889	if *ptr == nil {
 890		*ptr = &val
 891	}
 892}
 893
 894func isInsideWorktree() bool {
 895	bts, err := exec.CommandContext(
 896		context.Background(),
 897		"git", "rev-parse",
 898		"--is-inside-work-tree",
 899	).CombinedOutput()
 900	return err == nil && strings.TrimSpace(string(bts)) == "true"
 901}
 902
 903// worktreeRoot returns the absolute path of the git working tree root for
 904// dir, or the empty string if dir is not inside a working tree (bare
 905// repositories, missing git binary, plain directories, or any other
 906// failure mode). Linked worktrees and submodules each report their own
 907// top-level, which is what callers want when bounding lookups.
 908func worktreeRoot(dir string) string {
 909	cmd := exec.CommandContext(
 910		context.Background(),
 911		"git", "rev-parse", "--show-toplevel",
 912	)
 913	cmd.Dir = dir
 914	out, err := cmd.Output()
 915	if err != nil {
 916		return ""
 917	}
 918	root := strings.TrimSpace(string(out))
 919	if root == "" {
 920		return ""
 921	}
 922	abs, err := filepath.Abs(root)
 923	if err != nil {
 924		return ""
 925	}
 926	return abs
 927}
 928
 929// projectBoundary returns the directory at which an upward configuration
 930// search rooted at dir should stop. It is the git working tree root when
 931// one can be detected, otherwise dir itself. Returning dir as a
 932// fallback keeps Crush from silently adopting state files placed above
 933// the current project.
 934func projectBoundary(dir string) string {
 935	if root := worktreeRoot(dir); root != "" {
 936		return root
 937	}
 938	abs, err := filepath.Abs(dir)
 939	if err != nil {
 940		return dir
 941	}
 942	return abs
 943}
 944
 945// GlobalSkillsDirs returns the default directories for Agent Skills.
 946// Skills in these directories are auto-discovered and their files can be read
 947// without permission prompts.
 948func GlobalSkillsDirs() []string {
 949	if crushSkills := os.Getenv("CRUSH_SKILLS_DIR"); crushSkills != "" {
 950		return []string{crushSkills}
 951	}
 952
 953	paths := []string{
 954		filepath.Join(home.Config(), appName, "skills"),
 955		filepath.Join(home.Config(), "agents", "skills"),
 956		// Per the Agent Skills spec, scan ~/.agents/skills
 957		filepath.Join(home.Dir(), ".agents", "skills"),
 958		filepath.Join(home.Dir(), ".claude", "skills"),
 959	}
 960
 961	// On Windows, also load from app data on top of `$HOME/.config/crush`.
 962	// This is here mostly for backwards compatibility.
 963	if runtime.GOOS == "windows" {
 964		appData := cmp.Or(
 965			os.Getenv("LOCALAPPDATA"),
 966			filepath.Join(os.Getenv("USERPROFILE"), "AppData", "Local"),
 967		)
 968		paths = append(
 969			paths,
 970			filepath.Join(appData, appName, "skills"),
 971			filepath.Join(appData, "agents", "skills"),
 972		)
 973	}
 974
 975	return paths
 976}
 977
 978// ProjectSkillsDir returns the default project directories for which Crush
 979// will look for skills.
 980func ProjectSkillsDir(workingDir string) []string {
 981	return []string{
 982		filepath.Join(workingDir, ".agents/skills"),
 983		filepath.Join(workingDir, ".crush/skills"),
 984		filepath.Join(workingDir, ".claude/skills"),
 985		filepath.Join(workingDir, ".cursor/skills"),
 986	}
 987}
 988
 989func isAppleTerminal() bool { return os.Getenv("TERM_PROGRAM") == "Apple_Terminal" }
 990
 991// normalizeHookEvent maps user-provided event names to their canonical
 992// form. Matching is case-insensitive and accepts snake_case variants
 993// (e.g. "pre_tool_use" → "PreToolUse").
 994func normalizeHookEvent(name string) string {
 995	switch strings.ToLower(strings.ReplaceAll(name, "_", "")) {
 996	case "pretooluse":
 997		return "PreToolUse"
 998	default:
 999		return name
1000	}
1001}
1002
1003// ValidateHooks normalizes event names and checks that every configured
1004// hook has a command and a syntactically valid matcher regex. Matcher
1005// compilation used for matching is owned by hooks.Runner; this function
1006// only validates up front so the user sees config errors at load time
1007// rather than on the first tool call.
1008func (c *Config) ValidateHooks() error {
1009	// Normalize event name keys.
1010	for event, eventHooks := range c.Hooks {
1011		canonical := normalizeHookEvent(event)
1012		if canonical != event {
1013			c.Hooks[canonical] = append(c.Hooks[canonical], eventHooks...)
1014			delete(c.Hooks, event)
1015		}
1016	}
1017
1018	for event, eventHooks := range c.Hooks {
1019		for i, h := range eventHooks {
1020			if h.Command == "" {
1021				return fmt.Errorf("hook %s[%d]: command is required", event, i)
1022			}
1023			if h.Matcher == "" {
1024				continue
1025			}
1026			if _, err := regexp.Compile(h.Matcher); err != nil {
1027				return fmt.Errorf("hook %s[%d]: invalid matcher regex %q: %w", event, i, h.Matcher, err)
1028			}
1029		}
1030	}
1031	return nil
1032}