21 Commits
Author SHA1 Message Date
c8217c1acf docs: refresh README roadmap, anchors, and product sync (#1212)
Align EN/CN README with shipped features and current install/channel
docs; fix GitHub heading anchors and drop obsolete extras examples.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 11:19:13 +08:00
2209cdc90f chore(deps): switch runtime packages to octop-* 1.0.0 (#1136)
Replace orcakit-harness-agent / harness-* with octop-harness, octop-gateway, octop-memory, and octop-browser, and align docs, UI copy, and generated paths.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 06:44:24 +08:00
jubaoliangandCursor 494a921cfc fix(fnos): parse prerelease versions for FPK builds
Digits-only sed left VER as the whole pyproject line for 1.0.2b1, so
native upload and GHCR wait both failed and no .fpk was attached.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:41 +08:00
薄生 339c78deff Feature/support discord (#972)
* feat(discord): add channel setup and default all-channel access

* build(deps): require harness-gateway 0.9.9 for Discord
2026-09-22 16:42:51 +08:00
veenyi cf9d700d61 fix(fnos): 安装向导接管管理员密码,根治 Octop123 被弱密码黑名单拒绝导致 FPK 无法启动 (issue #502)
根因:应用密码策略(src/octop/infra/users/password.py)的常见弱密码黑名单包含 octop123,
而 FnOS FPK 把初始密码写死为 Octop123,首次启动 octop init 报 "password is too common"
直接退出("Octop process exited early"),全新安装的 native / docker FPK 均无法启动。

修复内容:
- 安装向导(wizard/install,native + docker)提供两种密码方式:
  ① 自己输入密码:install_init / install_callback 按应用侧策略预校验(≥8 位、
     含字母和数字、不在常见弱密码黑名单),无效密码在安装阶段直接拦截并中文提示;
  ② 自动生成随机密码(推荐):octop_generate_password 生成 16 位强密码。
- 随机/自定义密码双通道送达:
  ① 应用「设置」窗口(wizard/config)顶部直接显示当前账号与密码(安装/改密时
     由回调渲染占位符模板),用户免翻文件;
  ② 数据目录 octop-login.txt 回落备份,永久保留、随改密同步更新。
- 启动器与容器入口三重兜底:.env 无密码时自动生成;init 因密码策略被拒时
  自动改用随机密码重试一次,并回写 .env 保持一致 —— 存量坏 .env(Octop123)
  升级后首次启动即被救活,不再依赖用户手工清理。
- 应用「设置」窗口支持改密:保持不变 / 随机生成 / 自定义(config_init 前置校验),
  本地版走官方 CLI `octop user passwd` 离线改密(停服→改密→启服防写库冲突),
  Docker 版走 `docker exec octop octop user passwd`;凭据三处同步(.env /
  octop-login.txt / 设置窗口显示)。
- 官方 CLI 管理保障:安装回调注册 octop / octop-cli 到 PATH 并做 `octop version`
  冒烟验证(结果写入安装日志)。
- docker/docker-entrypoint.sh:未设置 OCTOP_DEFAULT_PASSWORD 时自动生成随机密码,
  指定密码被策略拒绝时自动回退随机;credential.txt 增加访问地址行。
- compose / .env.example / README / user-guide 移除 Octop123 默认值与宣传文案。

本地验证:19 个 shell 脚本 bash -n 全过;7 个向导 JSON 全部合法;密码生成 300/300
通过字符集/长度/首字母/末位数字断言;octop_validate_password 与官方
validate_password_policy 对拍 19/19 一致、黑名单 14 项逐字一致;渲染链端到端模拟
(生成→校验→回落保存→设置窗口渲染→JSON 复检)通过。
2026-09-12 08:15:24 +08:00
liukewia 6a8914d2ba feat(release): append templated download links to GitHub Release notes (#548)
* feat(release): add download links generation for GitHub releases

- Introduced a new script `release_download_links.py` to generate markdown for download links based on version tags.
- Updated the release workflow to append download links to the release notes if not already present.

* refactor(release): update download section headings and links for consistency

- Changed section titles in the release notes from Chinese to English for clarity.
- Updated download link labels in the `release_download_links.py` script to use English terms.
- Adjusted unit tests to reflect the updated headings in the download section.
2026-09-03 19:38:17 +08:00
liukewia bd92457dd2 chore: make Playwright Chromium opt-in in installers and images (#537)
* refactor: update Dockerfile and installation scripts to make Playwright Chromium optional

- Removed pre-installation of Playwright Chromium in Dockerfile and installation scripts.
- Updated documentation to clarify that Playwright Chromium is not downloaded by default; users can opt-in using the `--extras browser` flag.
- Adjusted README and script comments to reflect changes in installation behavior regarding Chromium.
- Ensured that existing system Chrome/Chromium installations are reused when available.

* refactor(browser): update browser environment interface and add Chrome installation check

- Modified the BrowserEnvStatus interface to include new properties for Playwright and Chrome detection.
- Enhanced the Chat component to check for Chrome installation and prompt users to install if missing.
- Added utility functions to determine if a redirect to the Chrome installation page is necessary.
- Updated localization files to include messages related to Chrome installation prompts in English and Chinese.
- Introduced tests for the new Chrome installation logic to ensure correct behavior.

* fix(browser): update Chrome installation prompt and navigation logic

- Modified the message displayed when Chrome is not installed to provide clearer instructions.
- Replaced the info message with a confirmation modal that prompts users to navigate to the Chrome installation page.
- Updated dependencies in the Chat component to include the new modal functionality and ensure mobile responsiveness.

* fix(localization): update Chrome installation prompts in English and Chinese

- Changed the message for missing browser detection to provide clearer instructions.
- Updated the Chat component to reflect the new localization keys for the Chrome installation prompt.
- Ensured consistency in messaging across different languages for better user experience.

* fix(localization): improve browser installation prompts in English and Chinese

- Updated messages for browser detection and installation to provide clearer instructions for users.
- Ensured consistency in localization across both English and Chinese versions for better user experience.
- Enhanced user guidance for installing a browser to facilitate remote browsing and automated actions.

* fix(localization): update browser status messages in English and Chinese

- Revised messages related to browser readiness and uninstallation for clarity and consistency.
- Enhanced user guidance in both languages to improve the overall experience when managing the built-in browser.
- Ensured that the localization updates reflect the intended functionality and user interactions.

* fix(localization): update shutdown messages in English and Chinese

- Revised shutdown confirmation messages for clarity and consistency across both languages.
- Enhanced user understanding of the browser shutdown process and its implications.
- Ensured localization updates align with the intended user experience when managing the browser.

* chore(dependencies): update harness-browser to version 0.7.8

- Bumped harness-browser dependency from 0.7.7 to 0.7.8 in pyproject.toml and uv.lock.
- Updated associated package metadata to reflect the new version and its dependencies.
2026-09-03 14:47:26 +08:00
jubaoliang e91521a029 fix(ci): rename FnOS fpk to Octop-fnos-{docker,native}-<ver> and drop rolling latest
- scripts/build-fpk.sh: emit Octop-fnos-docker-<ver>.fpk / Octop-fnos-native-<ver>.fpk (variant in the name, not a bare -native suffix).
- fnos-build-fpk.yml: FPK_NAME_PREFIX is now Octop-fnos; stop passing FPK_ITER; the release tag is fnos-<ver> (no -NN iteration, no -vanilla) and the rolling fnos-vanilla-latest release is no longer produced.
- fnos/README.md: document the new versioned artifact names.
2026-08-31 18:33:25 +08:00
jubaoliangandjubaoliang bd1fbdd930 refactor(fnos): split fnos packaging into docker/ and native/ variants (#421)
* fix(tests): align subagent catalog division count with bundled library

The bundled subagent catalog now loads 19 divisions (272 agents), but two
tests still hard-coded an expected count of 16. Update the assertions so the
pre-commit suite is green.

* refactor(fnos): split fnos packaging into docker/ and native/ variants

Restructure the FnOS package layout so the Docker build and the native
installer live under separate directories (fnos/docker and fnos/native)
instead of a single fnos/ tree plus a parallel fnos-native/. Update the
FPK build workflow, build-fpk.sh and fnos/common.sh to source from the
new paths, and refresh fnos/README.md accordingly.

Follow-up to PR #407.

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-08-25 17:24:37 +08:00
veenyiandveenyi d9cb47631d feat(fnos): add FnOS NAS app packaging (Docker + native .fpk) (#407)
* feat(fnos): add FnOS (飞牛 NAS) app packaging for Docker and native installs

Adds the packaging tree to build Octop as a FnOS app center package (.fpk):

- fnos/: Docker-deployable FPK (thin wrapper that runs the Octop image
  via docker-compose on the NAS)
- fnos-native/: native FPK that runs Octop directly on the FnOS host with
  the system Python 3.12 runtime (no Docker required)
- scripts/build-fpk.sh: generic FPK build helper using the official fnpack
  CLI (injects the version from pyproject.toml into the manifest)

Both packages share the same app version as pyproject.toml. Container image
name is referenced as ghcr.io/TencentCloud/octop:latest — maintainers can
republish under their own namespace; the per-repo CI (image build + release
workflow) is intentionally left out of this PR.

* feat(fnos): first-use guide — fixed initial credentials admin/Octop123 with docs

- The previous default password 'octop' does not satisfy the password
  policy (>=8 chars incl. letters and digits) enforced by 'octop init',
  so the bootstrap admin could not be created
- Switch the default to Octop123, identical to the official Docker image
- Manifest install text now prints the initial account/password and tells
  users to change it after first login
- fnos/README.md gains a 'First use' section (credentials table + change
  password guidance) so users never need to dig into data directories

* ci(fnos): add FnOS packaging pipeline as a fork-maintainer template

Provides a complete CI template that builds the Octop Docker image,
the Docker .fpk and the native .fpk, then publishes GitHub releases
(fixed version + rolling latest):

- Trigger: workflow_dispatch only, so it never auto-runs on upstream
- Image namespace referenced as ghcr.io/TencentCloud/octop (placeholder;
  fork maintainers replace with their own)
- Iteration numbering, changelog generation (install-first, no-merges,
  capped at 30 entries) and rolling release management included

* refactor(fnos): dedupe lifecycle scripts into scripts/fnos/common.sh; tighten process kill

Addresses review feedback:

- Extract find_python312 / fix_ownership_and_perms / free_octop_ports into a
  single shared library scripts/fnos/common.sh (injected into both packages'
  cmd/common.sh by build-fpk.sh at package time) instead of duplicating them
  across 7 docker/native lifecycle scripts
- Tighten the leftover-process cleanup: only kill processes under this
  install dir (TRIM_APPDEST), no more broad 'pgrep -f octop' that could kill
  other users' / other installs' processes
- Root README: add an 'FnOS Installation' section pointing to fnos/README.md
  and noting the initial credentials + the #406 dependency for non-root CLI
  installs

* feat(fnos): transparent app icons (512/256/64) — remove white background for dark/light themes

---------

Co-authored-by: veenyi <veenyi@users.noreply.github.com>
2026-08-25 14:29:40 +08:00
HUANG Chengandjubaoliang 98e2ed106f feat(mobile): Remote Phone (adb stream, dashboard, agent tools) (#354)
* feat(mobile): add Remote Android probe, API, stream, and dashboard

Multi-backend mobile support for self-hosted Octop: install-time host
capability probe, gated /api/mobile routes, adb WebSocket stream, and
Control → Remote Android dashboard page for Mac/emulator dev paths.

* feat(mobile): wire harness agent adb tools for Remote Android

Register mobile_screenshot, mobile_tap, mobile_swipe, mobile_launch_app,
mobile_ui_dump, and mobile_handoff_to_user when capabilities.mobile is
enabled, with permission and readiness checks.

* feat(mobile): polish Remote Phone UX and session-bound agent control

Rename the surface to Remote Phone, add quality presets, device info, AI
panel, and chat-dock phone tab; bind agent tools to the active stream
session and cover with unit tests.

* chore(mobile): drop docs/specs/remote-android.md from the PR

* fix(mobile): ruff I001 import formatting in device_info tests

* fix(mobile): resolve adb via PATH and SDK env only

Drop hardcoded per-OS SDK layout guesses; honor PATH, ANDROID_HOME,
and ANDROID_SDK_ROOT (with adb.exe on Windows).

* style(mobile): apply ruff format to mobile modules

CI runs ruff format --check; keep these files format-clean.

---------

Co-authored-by: jubaoliang <jubaoliang@gmail.com>
2026-08-22 16:42:30 +08:00
jubaoliangandjubaoliang 18ab9f6ba9 feat: workspace backend sandboxing, execute-env injection, and ephemeral image refs (#376)
* feat: workspace backend sandboxing, execute-env injection, and ephemeral image refs

Workspace file-I/O hardening across backend and dashboard:
- Host directory sandboxing via root_dir allow-list and denied prefixes
- Execute-environment defaults injected into harness backend specs
- Ephemeral workspace image rematerialization for model calls
- Attachment hint expansion and inbound store improvements
- Portable memory backend and skill workspace catalog updates
- Dashboard UI for agent backend fields and root-dir selection
- Bump harness-agent 0.9.23 / harness-memory 0.9.7; docs + install notes

* feat: add user invitation codes with admin management and redeem flow

- Add user_invites table (migration 009) plus SQLite/Postgres reconcile paths
- Add InviteRepo and InviteService for create/revoke/list/redeem
- Expose public validate/redeem endpoints and admin create/revoke/list routers
- Extract default-agent bootstrap into octop.infra.agents.default_agent
- Add invite error codes and en/zh i18n strings
- Dashboard: invite drawer, login redeem UI, users list, and locales

* fix: add Windows cross-platform guards for pre-existing sandbox/rootfs tests

- Guard POSIX/container-only tests (rootfs-absolute /.octop/... workspace
  paths) with posix_only in test_thread_artifacts.py and test_agent_manager.py
- Normalize the rendered workspace path assertion in test_octop_builtin_skills.py
  (forward slashes on Windows, not str(tmp_path) backslashes)
- Canonicalize ws_dir before the prefix check in attachment hint/path tests
  (tempfile may yield an 8.3 short path on Windows while the resolved
  attachment path uses the long form)

These failures predate the user-invites commit and are unrelated to it; the
product path logic is correct.

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-08-21 22:32:48 +08:00
薄生 02d1638de3 Feature/image polish (#263)
* fix: fix script version issue and change output to english

* fix:cancel delete octop-login.txt logic
2026-08-13 19:43:25 +08:00
jubaoliang c8132dbdfb feat: scoped root_dir bubblewrap jail and workspace path I/O (#167) 2026-08-05 20:04:04 +08:00
jubaoliang 00167f93a0 Merge pull request #116 from bringCool/docs/tencent-cloud-mirror-examples
docs(mirrors): optimize default China mirror examples to Tencent Cloud
2026-08-01 18:07:23 +08:00
jubaoliangandCursor ae02694fed feat(dashboard): tabbed chat dock file tree and account UX polish
Unify file list / file viewer / browser into closable dock tabs with a
PR-style path tree and path dedupe; polish account popover and rail UX;
harden install mirrors and bump harness-agent.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-01 07:31:32 +00:00
leun c8373877f7 docs(mirrors): optimize default China mirror examples to Tencent Cloud
Update the "faster downloads" mirror examples in docker docs and
install scripts to use Tencent Cloud's PyPI/APT/NPM mirrors
(mirrors.cloud.tencent.com), so the documented defaults match what
scripts/install.sh and self_update.py already try first at runtime.

Affected: docker/Dockerfile, docker/docker_build.sh,
docker/README.md, docker/README_CN.md, scripts/README.md,
scripts/install.sh (--help).
2026-07-31 19:58:13 +08:00
0a5f658e27 fix: search probe, table pagination, chat icon, and install hardening (#28)
Add missing POST /api/search/{id}/test so Advanced Search key checks work,
fix Ant Design pageSize changers stuck at 10, clarify the new-chat icon,
slide-renew JWT for active sessions, tighten chat polish prompts, and harden
install.sh for python-dev / Playwright mirrors.

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-20 19:48:47 +08:00
jubaoliangandjubaoliang 6ee2f156f5 feat: remote desktop install and connector probe improvements (#16)
- Refactor RemoteDesktop control page
- Add desktop install hook and setup script tweaks
- Enhance connector probe with better detection
- Sync README and locale strings (zh/en)

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-07-16 21:18:54 +08:00
085506e3f3 Feat/connectors gateway install (#14)
* feat(connectors): add gateway connectors and drop baidu-netdisk/figma

Expand the catalog with QQ Music, Fliggy, Baidu Map, Ctrip Wendao, Meituan Travel, and Yuandian; migrate Tencent News to API key; unify gateway credential probes; remove Baidu Netdisk/Figma OAuth paths.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore(install): ship Playwright by default and harden install scripts

Make browser tooling a core dependency, drop obsolete optional extras, and improve glibc/Playwright system-deps handling across install.sh/ps1/bat.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(desktop): install build deps before Python packages on Linux

Add a build-deps-only path so remote desktop setup can compile extension wheels when system headers are missing.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(dashboard): cache update-status checks in localStorage

Deduplicate concurrent PyPI probes across mounts and persist the last known update status with a short TTL.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(live): add OSS probes, secret helpers, and CI live job

Centralize require_env skipping, document live credentials in .env.example, and wire a secrets-gated live-tests workflow.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore(tests): rename chat WS integration test and drop dead cases

Align the chat transport test name with WebSocket usage and remove a skipped bootstrap harness test.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): unblock typecheck, CodeQL, and drifted live tests

Align mypy with requires-python 3.12 so numpy stubs parse; clarify Fliggy
SHA-256 use for request signing; update live expert/backend assertions
to the lazy Expert catalog and DEFAULT_BACKEND_SPEC with root_dir.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(ci): news Skill-Request-Id, workspace live reads, CodeQL FP

Add Tencent News CLI headers required by error 4010; assert expert
seeds via agent.workspace instead of host-rooted backend paths; ignore
Fliggy signing digests in CodeQL (protocol SHA-256, not password KDF).

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(tests): allow newline-only __init__.py in expert live checks

Office-automation skill packages ship empty package markers; strip()-based
emptiness assertions should not treat those as copy failures.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(tests): compare expert seeds via adownload_bytes

Harness aread_text replaces empty/whitespace file bodies with a system
reminder, which broke live office-automation __init__.py checks.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: jubaoliang <jubaoliang@tencent.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-14 19:25:51 +08:00
jubaoliang 748d998cf2 first commit 2026-07-09 14:32:36 +00:00