Commit Graph
558 Commits
Author SHA1 Message Date
Zayn JarvisandZayn 22c6b21924 docs: document ov get raw download (#4124)
Co-authored-by: Zayn <zayn@users.noreply.github.com>
2026-08-28 11:47:01 +08:00
Jiahui ZhouandTRAE CLI 805633d5b8 Feat/memory extraction operation metrics (#4410)
* fix(metrics): measure volcengine embedding call latency

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(metrics): classify model call outcomes

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(metrics): expose model call error codes

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(metrics): tag memory extraction by type

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-28 11:44:43 +08:00
dingbenandTRAE CLI 953d0bb9f1 feat(admin): support wildcard matching in list-accounts and list-users (#4409)
* feat(admin): support wildcard matching in list-accounts and list-users

Add fnmatch-based wildcard filtering to the admin list-accounts operation,
matching the existing semantics of list-users (case-sensitive, substring
via *x*). Both operations now accept an optional name filter and limit.

- server: get_accounts(name_filter, limit) using fnmatch; list_accounts
  router exposes `name` and `limit` query params
- ov_cli: add --name/--limit flags to list-accounts
- SDKs (python/go/typescript): thread filter params through admin clients
- docs: document the new filtering params for the admin API

Also fix two pre-existing, unrelated test failures (test-only):
- test_legacy_cleanup_removes_only_legacy_namespaces: update to the
  per-agent-id cleanup contract introduced in 0102a48c
- test_remove_user: raise _wait_for_task budget to accommodate the
  ~2s AGFS recursive cleanup during user deletion

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor(admin): drop limit param from list-accounts, keep name filter

The account list is consumed by callers that fetch the full set and scan
it (vikingbot root-key namespace-policy lookup, config-wizard account
menu, migration registry checks). Defaulting the HTTP route to limit=100
would silently truncate those consumers once an install has >100
accounts. The original requirement was only wildcard name matching, so
remove the limit param from the account path across route, CLI, SDKs and
manager, keeping only the fnmatch `name` filter. list-users is unchanged
(its limit predates this work and its consumers pass explicit large caps).

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(admin): add opt-in limit/page pagination to list-accounts and list-users

Both endpoints now return results in lexicographic order of ID and accept
optional limit/page query params. Pagination is opt-in: omitting limit
returns the full set, so internal full-set consumers stay unaffected.

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-28 11:26:23 +08:00
zihengli b8c89099be Fix/add resource (#4344)
* fix: web url deny error code

* feat: support feishu_app_id in args

* feat: connector task add internal task tag

* fix: remove connector extra meta info

* feat: watch api add source_type

* fix: terminate Git preflight process groups on timeout

* fix: internal task meta
2026-08-27 20:58:29 +08:00
Jiahui Zhou 9952ce1ec6 fix: create missing files on content write (#4360) 2026-08-26 22:18:14 +08:00
zgy 6e0aa34fab docs(resources): clarify add-resource target semantics (#4357) 2026-08-26 20:41:16 +08:00
Zayn Jarvis ea717aa05b fix(uri): resolve home alias for root requests (#4342) 2026-08-26 14:26:35 +08:00
t0sakiand7487 a61c57bf59 fix(codex): preserve transcript cursors across commit and compaction (#4191)
* fix(#4058): [Bug]: Codex memory plugin replays historical turns after resume or transcript compaction

Fixes #4058

Ref: https://github.com/volcengine/OpenViking/issues/4058

* fix(codex): retire committed cursors and keep activity-based concurrency

Preserving the transcript cursor after a commit stops the replay, but it also
means nothing deletes state files any more: clearState() lost its last caller,
so every codex session — including ones that never captured a turn — leaves a
file behind, and listStates() reads all of them on every SessionStart.

The sweep now retires cursor-only states in the same pass: a real cursor is
kept for resume until OPENVIKING_CODEX_COMMITTED_TTL_MS (default 30 days, past
the life of the codex rollout it indexes), and a state that never captured
anything goes on the idle schedule, which is what the old sweep did with it.

Releasing ovSessionId also wrote lastUpdatedAt, making a committed session look
freshly active; saveState() takes touch:false so the field keeps meaning "last
transcript activity" for both the active window and retention.

Requiring a live ovSessionId to count as recently-active made the heuristic
miss sessions PreCompact had just committed, which can still be running: the
count is back on activity alone, and only a state with a live session is
committed.

Also name the shrink predicate: role === "user" covers tool results too
(normalizeCaptureRole maps them onto the user role), so findLastHumanTurnIndex
requires a text part, and the no-human-turn fallback to a full replay is now
visible in the log instead of silent.

---------

Co-authored-by: 7487 <1042653432@qq.com>
2026-08-26 11:44:40 +08:00
zgy 80f4ba1412 fix(sdk): align compat client with SDK behavior (#4316)
* fix(sdk): normalize compat message parts

* fix(sdk): inherit normalized add_message in compat client

* fix(sdk): reuse base HTTP initialization in compat client
2026-08-25 21:08:54 +08:00
yufeng c3f3fb499e fix: normalize agent logos and guide rendering (#4325) 2026-08-25 21:01:43 +08:00
yufeng 156de74caf docs: add DeepSeek Harness, WorkBuddy, and Doubao guides (#4321) 2026-08-25 20:05:52 +08:00
Zayn Jarvis 9b7bb49634 Revert "feat(cli): download directories as zip archives (#4262)" (#4320)
This reverts commit 18d6805b81.
2026-08-25 18:39:59 +08:00
7ee7561121 refactor(parser):Unify Office Document Parsing with AnyDoc and Restore Compatibility Safeguards (#4279)
* docs: add anydoc office converter design

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(parse): add AnydocConfig and anydoc adapter skeleton

Register anydoc parser config with firecrawl-anydoc dependency and a small
attribute adapter for binding name normalization ahead of converter wiring.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(parse): add anydoc conversion core

Serialize anydoc documents to GFM while preserving embedded images through the existing storage media pipeline.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(parse): address Task 2 review findings

Move inline-code backslash escaping out of the f-string expression for
Python 3.10/3.11 compatibility, and stop tracking the SDD task report
in the product tree.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(parse): wire Word and legacy Doc to anydoc

Route Word and real OLE documents through the shared converter while preserving configurable legacy fallbacks and OOXML disguise handling.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(parse): honor anydoc config and safe fallbacks

Wire application parser settings into the default registry and prevent unsupported ODT/RTF files from reaching python-docx.

* feat(parse): wire PowerPoint and EPUB to anydoc

Route supported presentation and EPUB formats through the shared converter while preserving safe format-specific legacy fallbacks.

Co-authored-by: Cursor <cursoragent@cursor.com>

* feat(parse): wire Excel parser to anydoc

Route modern spreadsheet formats through anydoc with safe row truncation while preserving legacy process-pool conversion when anydoc is disabled.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(parse): preserve Excel ingestion options

Forward directory parse settings through the anydoc path and make skipped row truncation observable.

* docs(parse): document anydoc Office support

Reflect the expanded Office and EPUB format coverage while keeping PDF behavior explicitly unchanged.

* fix(parse): address final anydoc review findings

Resolve signatureless CSV conversion and preserve ingestion options across Office parsers while documenting and testing XLSB behavior.

* feat: unify office parsing with anydoc

* refactor: simplify anydoc renderer organization

* fix(parse): align anydoc parser config switch

* fix(anydoc): preserve legacy parser compatibility

* fix(anydoc): restore legacy safeguards

* refactor(anydoc): keep Office parsing on the unified path

* fix(anydoc): preserve config and benchmark compatibility

* fix(markdown): isolate link rewrite state per parse

---------

Co-authored-by: 张剑锋 <zhangjianfeng@ydjdev.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-25 18:28:54 +08:00
Zayn JarvisandClaude Fable 5 18d6805b81 feat(cli): download directories as zip archives (#4262)
* feat(cli): download directories as zip archives

* fix(download): cap directory archives

* fix(download): bound directory archives while they are built

The archive size cap was only enforced by `os.path.getsize()` after the
whole ZIP had been written, and `actual_total` counts file payload bytes
only. A tree made of empty directories or empty files therefore adds
per-entry ZIP headers that no check sees until the temp file is already
complete: with the limit set to 1 KiB, a 20k-entry tree writes 1.9 MB to
disk before being rejected.

Check the live write offset after every member so the temp archive stays
within the limit as it grows.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013CneCiyRjLaeDRYSWKngcJ

* docs(download): make the KG snippet re-runnable and sync the API catalog

The new knowledge-graph snippet extracts with a plain `unzip`, but the
note above it only tells the reader to delete the archive. Re-running it
leaves the previously extracted `./journal-kg/` in place, so `unzip`
stops at an overwrite prompt — and in a non-interactive shell it exits 1
without extracting anything. Use `unzip -o` and say what the note
actually has to cover.

Also update the endpoint catalog in api/01-overview.md, which still
described /content/download as file-bytes only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013CneCiyRjLaeDRYSWKngcJ

* fix(download): build directory archives in memory, not in a temp file

The temp archive is handed to FileResponse with a BackgroundTask that
unlinks it, but starlette runs `background` only after a successful
send. Both Range-header error branches (starlette/responses.py:370,373)
`return await PlainTextResponse(...)` before reaching it, so a malformed
or unsatisfiable Range leaks the archive permanently — 22 such requests
leak 22 files in a local repro, up to 10 MiB each, with nothing to
reclaim them. asyncio.CancelledError misses the `except Exception`
cleanup for the same reason.

Since the archive is capped at 10 MiB anyway, build it in a BytesIO and
return it as a plain Response, exactly like the single-file branch. That
drops the temp file, the cleanup callback, and the tempfile/os/
FileResponse/BackgroundTask imports, and gives both branches the same
`Content-Disposition: attachment; filename*=UTF-8''...` form instead of
two different ones.

Directory downloads no longer honour Range. They never usefully did:
the archive is rebuilt per request and zipfile stamps time.localtime()
into every member, so resuming a range spliced two different archives.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013CneCiyRjLaeDRYSWKngcJ

* fix(download): return 413 for oversized directory archives

RESOURCE_EXHAUSTED maps to 429, which tells clients the request is
rate-limited and worth retrying after a backoff. An archive over the
10 MiB cap fails because of the directory's own size, so every retry
re-walks the tree and re-zips it before failing again.

Add PAYLOAD_TOO_LARGE / 413 and raise it from the archive size check.
The code is plumbed through both status<->code maps (server app and
utils), the client's code->exception table, and the Rust CLI's status
mapping, so an over-cap `ov get` still surfaces a typed error rather
than falling through to INTERNAL.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013CneCiyRjLaeDRYSWKngcJ

* feat(cli): write directory downloads as a named .zip in a target directory

`ov get viking://resources/myfolder ./myfolder` wrote the ZIP bytes to a
path named `myfolder` with no suffix: a regular file wearing a folder's
name, which `cd` rejects and `file` reports as ZIP data. The local path
was always used verbatim, so only the docs' hard-coded `./project.zip`
form produced a sane result.

Treat a target that is an existing directory — or omitted, meaning the
current directory — as the destination *directory*, and name the file
after the resource, appending `.zip` when the response came back as
`application/zip`. An explicit non-directory path is still used
verbatim, so `ov get <uri> ./explicit.zip` is unchanged. Nothing is
extracted; the archive is what lands.

get_bytes_with_type exposes the response Content-Type, which is how the
caller tells a raw file apart from a directory served as a ZIP;
get_bytes keeps its old signature for the TUI and its existing test.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013CneCiyRjLaeDRYSWKngcJ

* fix(download): bound archive entries and preflight targets

* fix(cli): preflight existing symlink targets

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-25 18:16:34 +08:00
Zayn JarvisandClaude Fable 5 0e77cd4eb7 feat(mcp): return media as native content blocks (#4257)
* feat(mcp): return images as native content blocks

* test(mcp): allow configured tool decorators

* feat(mcp): return audio as native content blocks

* feat(mcp): add embedded-resource download mode

* fix(mcp): bound native media reads

* fix(mcp): add actionable media download fallback

* fix(mcp): point directory reads at list, share URI suffix parsing

- directory hint now names the list tool / `ov ls` / `ov tree`
- audio MIME sniffing ignores query/fragment like the extension gate
  does, so `clip.ogg?v=2` no longer fails as an unsupported format
- bound the preflight stat fan-out with the existing read semaphore

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01YXgAtkdLQZhXu4ZbHpaDqR

* fix(mcp): validate video reads before fallback

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-25 14:24:11 +08:00
Zayn Jarvis e319306337 docs: refresh WeChat group QR code (#4304) 2026-08-25 10:52:48 +08:00
Qin Haojie 234a2d9fe7 feat(fs): create default L0 on mkdir (#4277) 2026-08-24 21:28:10 +08:00
Onefly 76c56acf70 docs(embedding): clarify DashScope endpoint configuration (#4154) 2026-08-24 20:46:48 +08:00
Jiahui ZhouandTRAE CLI 5a154317cd feat(retrieval): inline matched content on demand (#4261)
Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-24 20:40:44 +08:00
604275f272 feat(resources): support TOS auth args for HTTP imports (#4248)
* feat(resources): support source headers for HTTP imports

Allow HTTP(S) resource imports to pass request headers for authenticated object storage sources. Fetch authenticated sources into a request-scoped snapshot and keep credentials out of parser inputs and queued jobs.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* fix(resources): reserve source headers from args

Treat source_headers as a top-level add_resource field so it is rejected from args and filtered consistently from queued processor inputs.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(resources): accept TOS auth through args

Replace generic source header passthrough with explicit tos_signature and tos_access args for HTTP TOS object imports. Keep credentials request-scoped and out of parser and queue payloads.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor(resources): name transient TOS args

Centralize TOS credentials that are accepted from args but excluded from durable resource jobs.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-24 19:09:09 +08:00
Yu ZhangandClaude Sonnet 4.6 85228eb38d fix(vlm): pass Codex reasoning effort (#4244)
Allow openai-codex VLM configuration to carry reasoning_effort through credential normalization and into Responses API requests so deployments can tune model effort without out-of-tree patches.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-24 16:27:36 +08:00
DuTao 4369e28dca fix(memory): expose reasons for skipped empty-URI operations (#4168)
* 增加空uri的原因

* fix  pr bug

* 加入Memory diff

* fix(memory): preserve semantics for skipped URI reporting
2026-08-24 16:21:04 +08:00
9eac8a6d3d feat(sdk): sync go/ts/python SDKs with server find/search, recall, an… (#3737)
* feat(sdk): sync go/ts/python SDKs with server find/search, recall, and admin changes

Server-side changes recently landed that the language SDKs had drifted from:

- find/search results now return `tags` and no longer return
  `category`/`match_reason`/`relations`/`overview` (#3730). Go's strict
  struct was the only one broken; update MatchedContext accordingly.
- new admin endpoints for agent-evolution and per-account settings (#3695).
- public `search/recall` endpoint was missing from all SDKs.

Changes:
- python: add `level`/`since`/`until`/`time_field` to find/search; add an
  `extra` escape hatch to find/search/add_resource/write/batch_write so new
  server fields can be passed without an SDK bump (only forwarded when set,
  preserving `level=0`); add `recall` and the four admin methods.
- go: fix MatchedContext (add Tags, drop removed fields), add Recall and the
  four admin methods.
- typescript: type MatchedContext/FindResult, add RecallOptions, add `recall`
  and the four admin methods.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): unify options APIs and sync latest server interfaces

- migrate complex Python SDK calls to typed options dictionaries
- add dedicated context search and consistent extra-field handling
- align Go and TypeScript options with omission-aware serialization
- support session config, event tags, Agent Evolution date filters,
  OpenViking Assets, batch write, downloads, and create_parent
- refresh SDK tests and examples across all three languages

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): address options API review findings

- fix Go session extra merging and Python message precedence
- adapt LangChain calls to the Python options API
- migrate repository examples, tests, and documentation

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): complete options migration and message parity

- migrate remaining Python SDK benchmarks to options dictionaries
- normalize empty parts consistently for single and batch messages
- add regression guards for repository SDK call sites

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): align reindex options after main rebase

- preserve reindex tags in Python typed options
- add reindex extra support for Go and TypeScript
- reject official fields passed through extra across SDKs

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): support legacy keyword options

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

docs(sdk): use explicit Python SDK arguments

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): support set tags extra options

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): expose Go add resource options

Expose AddType and ProcessingMode through Go AddResourceOptions and serialize them to the resources API. Add a regression test covering the resulting request payload.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): flatten core Python client options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

docs(sdk): align Python examples with flattened options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): preserve core API compatibility

Co-authored-by: TRAE CLI <traecli@bytedance.com>

refactor(python-sdk): move resource hints to options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): align resource option callers

Co-authored-by: TRAE CLI <traecli@bytedance.com>

test(sdk): cover recursive reindex forwarding

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): preserve Go options compatibility

Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(python-sdk): expose message peer id

Co-authored-by: TRAE CLI <traecli@bytedance.com>

test(python-sdk): consolidate options coverage

Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(python-sdk): add parts and flatten image search

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* docs(sdk): align Python call examples

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
2026-08-24 14:09:11 +08:00
Qin Haojie ad750121ed fix(api-keys): hide deleting users from list (#4234) 2026-08-24 14:03:50 +08:00
yufeng e7ab26ab24 fix(docs): remove duplicate CLI API key block (#4236) 2026-08-24 12:27:54 +08:00
ManAsWindandlinweiye 2af48624e0 docs: remove duplicate OpenClaw API key copy (#4195)
* docs: add API key blocks to agent guides

* docs: use connect agent template tokens

* docs: remove page wording from agent copy

* docs: sync English agent integration copy

* docs: remove duplicate OpenClaw API key copy

---------

Co-authored-by: linweiye <linweiye.voph@bytedance.com>
2026-08-21 21:03:30 +08:00
t0saki a83b81715b feat(uri)!: remove uid-less current-user shorthand in favor of viking://~ (#4196)
* feat(uri)!: reject uid-less current-user shorthand in favor of viking://~

viking://user/<segment> (memories/resources/skills/peers/privacy/sessions
without a user id) was ambiguous with a user literally named after the
segment, and a user actually named e.g. "memories" was unreachable for
USER/ADMIN callers. Now that the viking://~ home alias (#4167) covers the
same need unambiguously, the shorthand fails closed at the request
boundary instead of expanding:

- resolve_current_user_uri raises NamespaceShapeError with a corrective
  hint naming both viking://~/<rest> and the explicit-uid form. Silently
  parsing the reserved segment as a peer user id would misdirect reads
  and writes, so rejection is the only safe removal.
- Bare viking://user falls through to the canonical parser and keeps
  container semantics (a user key listing it sees only its own space).
- The self-id escape stays: a caller whose user_id equals a reserved
  name keeps viking://user/<own-id> as their canonical root. ROOT-role
  literal parsing and the legacy viking://session alias are unchanged.
- AddTargetsConfig normalizes stored legacy config spellings
  (viking://user/resources|skills) to the viking://~ form at validation
  so existing ov.conf/user_config deployments keep working; the accepted
  per-user spelling is now viking://~/resources and viking://~/skills.
- usage_reporter keeps canonicalizing the historical shorthand found in
  old transcripts and additionally recognizes viking://~/memories/.

BREAKING CHANGE: requests using the uid-less viking://user/<segment>
spelling now fail with 400; use viking://~/<segment> or an explicit
viking://user/{user_id}/<segment> URI.

* refactor(clients): migrate first-party emitters to the viking://~ home alias

Every in-repo client that emitted the removed uid-less current-user
shorthand now sends viking://~/... instead: vikingbot fallbacks and
default sentinels, the LangChain store/tools defaults, the shared
recall-core.mjs (all synced plugin copies), the codex/claude-code/
openclaw/openwebui/dsh/zcode/pi plugin emitters, quick-app examples,
Go SDK example, tau2 benchmark targets, and the eval golden dataset.

Compat kept where legacy strings live in stored user configs: bot and
ov_dream sentinels accept both spellings while emitting only ~, and
recall-core still rewrites legacy viking://user/<reserved> config values
client-side. langchain_openviking._uri now classifies viking://~ with
the explicit-user shape so canonicalized server responses keep matching
a ~ root. Plugin READMEs note the server requirement for the alias.

* docs: replace current-user shorthand guidance with the viking://~ home alias

Rewrite every EN/ZH doc and model-facing prompt that advertised the
uid-less viking://user/<segment> spelling: URI concept catalogue,
context-types/storage/extraction/retrieval/session/privacy concepts,
configuration guide (with the legacy add_targets auto-normalization
note), resources/skills/sessions/retrieval/admin API references, FAQ,
capability reference, and the openviking-memory / ov-experience-memory /
openclaw / ov-resources skills. The stale MCP viking://user/<path>
dialect passage in the MCP guide is replaced by ~ guidance, and bare
viking://user is documented as the container of user spaces.

* test(api): migrate live API session-used tests off the removed shorthand

tests/api_test/sessions sent uid-less viking://user/skills/... URIs to
record_used, which the request boundary now rejects with 400 (caught by
the API & CLI Integration Tests CI job; these tests need a live server
and are not part of the local suites). The api_test client authenticates
as an admin-role user key, so the viking://~ home alias expands for it.
tests/api_test/common/test_edge_cases.py is left as is: it asserts a 400
for a non-resource add target, which still holds.
2026-08-21 19:00:19 +08:00
ManAsWindandlinweiye c92ad738c1 docs: refine Chinese agent integration copy (#4194)
* docs: add API key blocks to agent guides

* docs: use connect agent template tokens

* docs: remove page wording from agent copy

* docs: sync English agent integration copy

---------

Co-authored-by: linweiye <linweiye.voph@bytedance.com>
2026-08-21 17:39:29 +08:00
MaojiaShengandTRAE CLI a7c77e6cf7 feat: add freshness-aware parent aggregation (#4180)
* feat: add freshness-aware parent aggregation

Defer wide-directory abstract/overview regeneration until the configured freshness threshold is reached while continuing changed-file semantic and vector processing.

Persist freshness metadata atomically, make parent bubbling L0-aware, preserve separate semantic/vector statuses, and keep explicit waits synchronous.

Rebuild every sampled summary on threshold refresh and always retry directory vectorization so stale sidecars or transient vector failures cannot be silently accepted.

Add focused coverage for freshness policy, pending-state consumption, sampled-summary refresh, vector retries, and parent bubbling.

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive, and applied to memory

* feat: ov reindex support --recursive, and applied to memory

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-21 16:30:44 +08:00
t0saki ff38bb5dd1 feat(uri): add viking://~ home alias for the caller's user root (#4167)
* feat(uri): add viking://~ home alias for the caller's user root

Accept `viking://~` (and `viking://~/<suffix>`) as a server-side alias
for the authenticated caller's user namespace root. The alias is
expanded at the request boundary by resolve_current_user_uri for
USER/ADMIN identities, so every control plane that already funnels
through validate_request_viking_uri (REST, MCP, and therefore CLI/SDK
clients) gets it with no client changes.

Design points:
- `~` is a reserved token that can never collide with a real user id
  (validate_user_id's charset excludes it), so segment-0 aliasing does
  not weaken canonical-first parsing.
- The canonical parser (resolve_uri) rejects the alias outright,
  mirroring the legacy-session handling: root-role requests, internal
  callers, and storage paths fail closed instead of materializing a
  literal '~' directory.
- The alias is accepted but never advertised: scope error copy
  ("Must be one of: ...") filters it at both the parser and the public
  validator, and VikingURI.build refuses to mint it, so responses and
  persisted data stay canonical.
- MCP search now resolves exclude_uris with the same strictness as the
  REST search router (closes the one entry point that skipped it).

* refactor(mcp): drop tilde mention from tool docstrings

Agents pass viking://~ through verbatim and responses echo the
canonical form, so the alias is self-explanatory on contact; carrying
the sentence in 12 tool descriptions costs every MCP session tokens.
Docs keep the alias documented for humans.
2026-08-20 20:44:40 +08:00
agent 056f875e90 feat: restore user-scoped memory extraction policies (#4126)
* feat: add user-scoped memory extraction policies

* refactor: minimize user memory policy session changes

* fix: resolve user memory policy consistently

* refactor: resolve user memory policy once per commit

* refactor: simplify memory policy provider typing

* fix: apply server default user memory policy

* fix: allow resetting user memory policy
2026-08-20 20:28:33 +08:00
Jiajie - He/him/his 1efb0dce59 feat(compile): improve source materialization and long-running agent loops (#4059)
* feat(compile): compact agent context in-loop and remind iteration budget

* feat(compile): materialize sources for local exec and track reads

* feat(compile): survey-then-targeted read workflow and relaxed submission

* feat(compile): accept file sources, enable exec by default, update docs and tests

* fix(bot): harden compile source handling and compaction (#4099)

* feat(compile): add skill examples and update render

* feat(compile): add checkout workflow and task cancellation

* feat(cli): support compile task status and cancellation

* feat(examples): add compile knowledge graph tools

* docs(compile): document checkout and cancellation APIs

* docs(compile): add context compilation guides and skill examples
2026-08-20 20:17:55 +08:00
t0saki c7044075ef feat(dsh): serve tools over the shared stdio MCP proxy (#4157)
* feat(dsh): serve tools over the shared stdio MCP proxy

Replace the dsh bundle's seven hand-registered `viking_*` tools with the
OpenViking MCP surface, reached through the same stdio proxy every other
memory integration starts, and collapse the four duplicated proxy
entrypoints onto a shared config builder.

The bundle now mounts `@deepseek-ai/dsh-mcp-client` (which ships with dsh
itself) on `servers/mcp-proxy.mjs`. Pointing an MCP SDK client straight at
the server's `/mcp` endpoint does not work: with `stateless_http=True` the
server still answers `GET /mcp` with an idle 200 SSE stream, and once the
SDK client opens that standalone stream it stops resolving POST responses,
so `tools/list` never returns. The stdio proxy owns the transport itself
and is unaffected.

`trimSlash`, `normalizePath`, `uniq`, the watched-credential-path list and
the cfg -> proxyConfig mapping existed in four near-identical copies
(claude-code, codex, opencode, agent-plugins; the last one carried a
"keep in sync with claude-code" comment). They move to
`memory-plugin-shared/lib/mcp-proxy-config.mjs` and all five entrypoints —
including the new dsh one — now shape their config through
`buildMcpProxyConfig`. Behavior is preserved per field, including codex's
explicit `mcpUrl` override, claude-code's `ovcli.conf` credential-source
probe, and opencode's extra watched config file.

The bridge is mounted last in `apply()` so a proxy that fails to start
cannot hold up profile injection, recall, capture, commit, or the URI
guard registrations above it.

* feat(dsh): add to the unified installer and ship the shared skill

The bundle now registers its own isolated `ctx.skills` provider serving the
shared `openviking-memory` skill, so DSH gets the same guidance the Claude
Code, Codex, and Cursor integrations ship. `sync.mjs` distributes the skill
to the bundle, and the provider uses `includeDefaultRoots: false` so it
never shadows DSH's own project/user skill catalog.

`install.sh` grows a `dsh` harness id, auto-detected like the others, plus a
profile prompt that defaults to `web` (`--dsh-profile` / `OPENVIKING_DSH_PROFILE`
answer it up front). The installer always installs the published package:
`dsh plugin` forwards to pnpm, and a linked source tree cannot resolve the
dsh peers the bundle imports because Node resolves them from the checkout's
realpath rather than from the profile.

Documentation is restructured around installing rather than internals. The
integration page now leads with the one-line installer and keeps behavior at
the level the other harness pages use, with configuration in a details block;
design rationale moves to the bundle README, which itself leads with Install
and groups the rationale under "Design notes". Capability-reference claims
that dsh is outside the unified installer are corrected.

* chore(dsh): release 0.2.0

The MCP tool surface, the stdio proxy transport, and the bundled skill all
change what the bundle does for an existing user, so this is a minor bump
rather than a patch. 0.1.0 remains the native-`viking_*` tool surface.

* docs(dsh): note pnpm's 24h minimum release age

pnpm 11 refuses releases younger than minimumReleaseAge (24 hours by
default), and surfaces it as a registry 404, so installing a freshly
published version reads as "the package does not exist".

* fix(dsh): honour dev source mode in the installer

install_dsh ignored SOURCE_MODE and always fetched the published package,
so selecting "current checkout" installed npm's build instead of the
working tree and validation still reported success.

npm is the bundle's only distribution channel, so the github/tos choice
does not apply to it: every mode except dev now installs the published
package, and dev packs the checkout with npm pack first. It has to arrive
as a real package rather than a link, because a linked source tree
resolves its dsh peers from its own realpath and misses the profile's
hoisted node_modules. The install line reports which source was used.

* fix(dsh): make repeated installs actually overwrite

Two ways a re-run silently kept stale code:

pnpm treats an already-satisfied version as a no-op regardless of which
tarball the file: dependency points at, so a dev re-install after editing
the checkout left the previous build in place. Local installs now drop the
package before adding it back; that is confined to local sources, since
doing it for the registry path would leave nothing installed when add
fails.

A bare package name has the same effect in reverse: a profile holding a
dev build satisfies it, so switching back to the published package was a
no-op. The registry path now asks for @latest.

The packed tarball is named after a fingerprint of the checkout's shipped
files, so an unchanged checkout skips the pack and keeps a stable path in
the profile lockfile.
2026-08-20 19:05:18 +08:00
ManAsWindandlinweiye 42d37996cf docs: use connect agent template tokens (#4152)
* docs: add API key blocks to agent guides

* docs: use connect agent template tokens

---------

Co-authored-by: linweiye <linweiye.voph@bytedance.com>
2026-08-20 17:37:42 +08:00
Zayn Jarvis 2c205d8a7a docs: tag GitHub referrals with UTM (#4155)
* docs: tag GitHub referrals with UTM

* docs: tag GitHub referrals with UTM
2026-08-20 16:48:00 +08:00
98a0104aaa Fix/filter invalid attr tags (#4123)
* fix(fs): filter invalid tags from attrs

Hide legacy non key-value search tags from filesystem attributes while preserving valid tags. Add regression coverage for the read boundary.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(session): update auto commit policy defaults

Raise token and message thresholds, clear the retained-message default, and expand the corresponding bounds. Synchronize the session API and configuration documentation.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-19 21:11:18 +08:00
Qin Haojie 592c0fe036 fix(feishu): support legacy doc imports (#4130)
* fix(feishu): support legacy doc imports

Keep legacy Feishu doc resources on the doc API path instead of routing doccn tokens through docx blocks.

* test(feishu): trim legacy doc coverage

Keep legacy doc import coverage focused on public Feishu accessor behavior and remove extra mock-level assertions.
2026-08-19 19:42:52 +08:00
Qin Haojie 81eba498b4 fix(uri): server 入口校验并补全 URI,内部只用规范 URI (#4048)
* fix(uri): 明确规范 URI 与用户归属

- 在 API、MCP 等外部入口解析当前用户简写并校验 URI
- 让 Service、VikingFS、索引和 Reindex 只接收规范 URI
- 在 OVPack 中显式保存用户归属,避免 Admin 身份改变路径含义
- 移除 SDK 对非 URI 路径的隐式补全

* fix(sdk): preserve URI normalization before API calls

* fix(content): normalize write URI before routing

* fix(content): keep write policy scoped to content rules

* refactor(content): remove target wrapper validation

* refactor(uri): simplify scope validation
2026-08-19 19:02:39 +08:00
zgyandqin-ctx dc39985ad1 refactor: remove resource relation edges (#3956)
* refactor: remove resource relation edges

* fix: remove stale relation references

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-19 17:54:29 +08:00
agent afa5aae9a6 Revert "feat: add user-scoped memory extraction policies (#3906)" (#4122)
This reverts commit 6fc4d8fa57.
2026-08-19 15:34:05 +08:00
agent 6fc4d8fa57 feat: add user-scoped memory extraction policies (#3906)
* feat: add user-scoped memory extraction policies

* chore: leave deprecated v2 compressor unchanged

* feat: allow agent memory types for peer policies

* revert: disallow agent memory types for peer policies

* feat: complete user memory policy APIs and commit overrides

* refactor: simplify user memory policy settings

* refactor(admin): remove unused batch user settings API

* refactor(session): keep memory policy out of commit API

* refactor(memory): centralize peer memory type resolution

* fix(admin): restore user registration flow

* fix(session): preserve memory policy compatibility

* fix(session): preserve disabled legacy policy output

* revert(session): remove queue memory policy dual write
2026-08-19 15:32:37 +08:00
Hao Zhe da138de7ce feat(resources): expose context count in upload tasks
Expose upload-attributed context_count in completed add_resource tasks, with idempotent counting and API documentation.
2026-08-19 10:32:57 +08:00
MaojiaShengandqin-ctx 24cc8c6ee9 feat: refine OKF sidecar metadata handling and write protection (#4092)
* feat: implement l0-l1-okf-sidecars

* feat: implement l0-l1-okf-sidecars

* feat: implement l0-l1-okf-sidecars

* feat: implement l0-l1-okf-sidecars, fix review comments

* feat: implement l0-l1-okf-sidecars, fix review comments

* feat: implement l0-l1-okf-sidecars, fix review comments

* feat: implement l0-l1-okf-sidecars, fix review comments

* test: prune semantic sidecar coverage

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 23:21:06 +08:00
t0saki 458e7fae37 docs: add a cross-integration capability reference page (#4076)
* docs: fix integration docs and comments that contradict the code

- codex: credential resolution in the default `auto` mode is env-first — `credentials.mjs`
  only falls back to `ovcli.conf` when no credential env var is set, while the docs and the
  `config.mjs` header comment claimed `ovcli.conf` wins by default. Also document
  `OPENVIKING_CREDENTIAL_SOURCE=cli`, which was undocumented.
- codex: the four hook scripts send the key as `X-API-Key` in addition to
  `Authorization: Bearer`; the README documented Bearer only.
- claude-code: the OV session id is `cc-<cc_session_id>` verbatim (`deriveHarnessSessionId`
  does no hashing), not `cc-<sha256(cc_session_id)>`.
- claude-code: `hooks.json` registers 9 hooks, not 7 — the responsibilities table was
  missing the `PreToolUse` `viking://` guard and the `PostToolUse` skill-experience hook.
- claude-code: archival is triggered client-side (the `Stop` hook commits once
  server-reported pending tokens cross `commitTokenThreshold`, default 20000, plus
  unconditional commits from `PreCompact` / `SessionEnd` / `SubagentStop`). The README
  attributed it to a server-side `auto_commit_threshold`, but
  `memory.session_auto_commit.default_enabled` is false and no plugin sends a policy.
- trae / opencode: the MCP proxy transparently exposes the full server tool set (16 tools);
  the docs listed a 4-item sample or 11-13 tools and omitted `tree` / `write` / `edit`.
- trae-cli: the installer registers the MCP server as `openviking-memory`, but the verify
  step told users to look for `openviking`.
- pi: the manual install block omitted the `pi install <dest>` registration step that the
  one-click installer runs, so a hand-copied extension is never registered.
- install.sh: `--uninstall` handles cursor, trae, trae-cn, trae-cli and zcode; the `--help`
  text still said Cursor/TRAE only.
- mcp_endpoint.py: the module docstring enumerated 13 tools and omitted `recall`,
  `list_watches` and `cancel_watch`; replaced the stale enumeration with a pointer to the
  `@mcp.tool` registrations.

* docs: add a cross-integration capability reference page

The agent-integrations section had per-integration install guides but no place
to compare integrations against each other. This adds one bilingual page that
does that, and wires it into the existing pages in both directions.

- New page `docs/{en,zh}/agent-integrations/16-capability-reference.md`: a
  dimension-first comparison of every OpenViking integration — active tool
  surface, automatic hook surface, install/credential/config layering, recall
  and injection, session and commit lifecycle (including a shutdown-path x
  harness end-state matrix), compaction takeover, write/delete boundaries,
  degradation, and a per-harness profile card for each integration.
- Sidebar: `StructuredSidebarCopy` gains an optional `topItems` field so a
  section can list flat entries next to its overview; agent-integrations uses
  it to place the new page beside the overview. Other sections are unaffected.
- Links both ways: the overview and all 14 per-integration pages link to the
  reference, and the reference links back to each integration page from its
  profile card, from the non-coding integration table, and from the custom
  agent integration paths. Section cross-references (§x.x) are real in-page
  anchor links, generated from the built heading ids.
- trae-cli is documented as TraeCode CLI 2.0 only, installed through a codex
  plugin alias; 1.0 and its standalone plugin are called out as unsupported.
- The MCP tool surface is described as 15 tools throughout, matching the
  removal of the `recall` tool in favour of `search` with `mode="context"`.
  Pages outside this change that still mention an MCP `recall` tool
  (04-codex, 12-cursor, 15-agent-plugins, guides/06-mcp-integration) need a
  follow-up sweep once that removal lands.

* docs: 更新服务端 MCP 工具面描述,简化信息并明确更新方式
2026-08-18 20:38:06 +08:00
Zayn Jarvis c1fc0b730e docs(hermes): recommend memory setup openviking (#4098)
* docs(hermes): recommend memory setup openviking

Point Hermes docs at `hermes memory setup openviking` and describe the
real wizard. Shorten Volcengine console agent guides to TOS + cloud API
key, and mark docs/images as console-only.

* docs(hermes): drop setup filler

Keep the command and the two connection paths. Remove picker
explanations and wizard narration.

* docs: keep images AGENTS.md.local local-only

Ignore AGENTS.md.local like AGENTS.md. Drop the unused
docs/images/README.md.

* docs(console): keep harness setup to command plus API key

Drop installer narration, idempotency notes, and copied site
guides. Console pages only need the TOS command and cloud key.

* docs(console): restore Install / Verify / Troubleshoot

Keep the short cloud setup, put it back under the three section
headings the console pages use.

* docs(console): add Reference links

Point each harness page at docs.openviking.net, the coding-agent
blog where it exists, and the example source.

* docs(console): label Reference as manual settings and blog

Use Docs on Manual Settings for the full site page. Use Blog
about how it works where a how-it-works writeup exists.
2026-08-18 20:19:29 +08:00
22f0003320 Perf/reindex vector enqueue concurrency (#4071)
* perf: parallelize reindex vector enqueue

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: TRAE CLI <noreply@bytedance.com>

* perf: parallelize add resource vector enqueue

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* fix: cancel vector enqueue siblings on failure

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor: clarify file vectorization concurrency config

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* test: consolidate vectorization concurrency coverage

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 16:58:19 +08:00
t0sakiandTRAE CLI add72f9bed feat(plugins): install TraeCode CLI 2.0 via Codex alias (#4079)
* feat(plugins): install TraeCode CLI via Codex alias

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* fix(installer): keep trae-cli as public harness

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-18 16:21:47 +08:00
wutongyuonceandqin-ctx 7e7ad2e1f6 chore: remove dead git tuning knobs and duplicate release/frontend files (#4089)
* chore: remove dead git tuning knobs and duplicate release/frontend files

- GitTuningConfig: drop upload_concurrency, restore_concurrency,
  ref_cas_max_retry, and ref_cas_backoff_ms, which were parsed but never read
  anywhere (verified no source readers). Keep commit_index_enabled and
  blob_exists_precheck_enabled, the two knobs that actually take effect.
- Design doc: mark the removed knobs as roadmap items to be added back when
  the behavior lands, and correct stale 'not implemented' claims
  (validate_account_id is enforced at the Git service entry; blob reads are
  limited via show_with_limit).
- Remove .github/workflows/release-vikingbot-first.yml: a historical one-off
  PyPI release workflow whose bot/ package lacks build metadata.
- web-studio: delete pnpm-lock.yaml and the pnpm-only package.json block;
  the Makefile and CI already use npm + package-lock.json as the single
  install chain. Net -9,695 lines.

* docs: align cleanup notes with current behavior

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 15:38:36 +08:00
t0saki eb5aaf78e9 feat(mcp): consolidate recall into context search (#4075) 2026-08-18 12:45:45 +08:00
d08d9b99e6 Feat/shared temp upload decouple (#4054)
* refactor(server): decouple shared temp uploads

Remove shared-upload consumption locks and state transitions so uploads remain reusable within their account for 24 hours. Store them under the fixed internal viking://upload root, clean expired account-local directories on new shared uploads, and simplify metadata and deletion cleanup.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(server): configure shared temp upload ttl

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): share temp upload ttl

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): rename temp upload ttl

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): flatten shared temp uploads

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): simplify shared upload metadata name

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): remove legacy shared upload formats

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(server): allow disabling temp upload cleanup

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor(server): timestamp shared temp upload directories

Store shared uploads under timestamp-prefixed directories and use directory names for TTL cleanup instead of storage modification times.\n\nCo-authored-by: TRAE CLI <noreply@bytedance.com>

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* test(server): prune shared upload tests

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 12:13:04 +08:00