mirror of
https://github.com/volcengine/OpenViking.git
synced 2026-09-29 04:02:57 +08:00
python-sdk@0.1.10
195
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
9c31b11076 |
fix(codex-doctor): accept [features] hooks = true in modern Codex (#4634) (#4635)
* fix(codex-doctor): accept [features] hooks = true and retain legacy plugin_hooks compatibility * fix(codex-doctor): probe live CLI features for default-enabled hooks and normalize symlink run * fix(codex-doctor): prioritize modern hooks over legacy flags |
||
|
|
0c5147cae2 | ci: surface API and CLI test failures directly (#4663) | ||
|
|
30c5092672 |
fix(openclaw): strip dev dependencies from release artifacts (#4699)
OpenClaw installs extracted plugin artifacts as project roots, so npm still resolves devDependencies under --omit=dev. Build first, then strip the field from both npm and ClawHub packages to avoid Arborist peer-resolution crashes. |
||
|
|
37ef554bb2 |
refactor(plugins): converge the harness forks back onto the shared library (#4594)
* refactor(plugins): ship each harness only the shared modules it imports `sync.mjs` grouped its lists by how they had grown rather than by what each target imports, so three modules travelled to plugins that never load them: `setup-wizard.mjs` reached dsh and zcode, neither of which ships a setup entry point, and `async-writer.mjs` reached opencode, which its host imports in-process and so has no hook subprocess to detach a write from. Split the groups by capability — the hook set, the wizard, the stdio proxy pair, the batch sender, the async write path — and give pi its own list, so a target's entry says which capabilities it has. `sync.test.mjs` kept its own copy of those lists, and the copy had drifted: it was missing `plugin-config`, `retryable`, `recall-compress-core` and `mcp-proxy-config`, so a stale vendored copy of any of them would have passed CI. Import the lists from `sync.mjs` instead, guarding the sync behind an entrypoint check, and add the check the duplicate could never make: every module in `lib/` is claimed by some target, and no target holds a banner-carrying file the sync no longer ships. * refactor(zcode): capture and shape the proxy config through the shared modules zcode sent every turn it parsed straight to the server: no length cap, no acknowledgement filter, no slash-command or injected-status guard — the four things `shouldCaptureText` does for every other harness. It re-derived the proxy config object by hand too, which is how it came to watch a narrower set of credential files than `buildMcpProxyConfig` watches. Route both through the shared modules. The dedup key stays keyed on the raw turn, so raising the cap later never resends a turn the server already holds in truncated form. * refactor(pi): log through the shared JSON Lines logger pi carried two copies of a hand-written `debugLog` — one in `index.ts`, one in `sync.ts` — that appended `<ISO timestamp> <message>` lines, read `OV_DEBUG_LOG` directly, and could only be turned on through the environment. Both are the shared `debug-log.mjs` with the structure taken out: no stage field, no JSON payload, no config knob, and a spelling of the variable no other harness uses. Use `createLogger` in both places, add a `debugLogPath` config key so the log can be turned on the way every other pi setting is, and read `OPENVIKING_DEBUG_LOG` with `OV_DEBUG_LOG` kept as a deprecated alias so existing setups keep logging. * fix(dsh): honor syncTurns on every write path, not just capture `syncTurns: false` gated `capture()` alone, so a read-only session still committed on `turn/end`, still committed again on dispose, and still replayed whatever an earlier session had queued. The toggle promised no writes and made three. Gate the commit paths and the replay on it too, and document it — the README and the integration page never mentioned the key at all. A backlog queued while capture was on stays on the queue for a session that still writes. * chore(plugins): bump the zcode and dsh plugin versions Both changed behavior in this branch — zcode now filters and truncates what it captures and watches the full credential set, dsh now writes nothing when `syncTurns` is off — and installed copies are keyed by version. * fix(plugins): make the installer and the plugin test matrix work in a git worktree `resolve_self_checkout` looked for `.git` as a directory. A linked worktree keeps it as a file pointing at the real gitdir, so `CHECKOUT_DIR` stayed empty there: `--source dev` resolved the marketplace to `/examples` and failed outright, and every other path fell through to `remote`, which clones from GitHub. On this machine that turned six of the thirteen installer tests red and made `release-marketplace.test.mjs` hang for twenty minutes on the network — long enough that the CPU starvation failed an unrelated recall timing assertion too. Test for existence instead of for a directory. Three test files were never run by CI, so nothing noticed that one of them had gone stale: the pi wiring assertion still required `new RecallManager(...)` to end at the session-id getter, which stopped being true when the recall ledger was added a fourth argument. Assert only the getter, and register all three files in `pr.yml` — the matrix now covers every `*.test.mjs` under `examples/`. |
||
|
|
1d89f8d465 |
feat(plugins): derive the workspace peer from git, and let a repository carry its own config (#4595)
* fix(plugins): stop dropping ovcli.conf's plugin section, and unrot the sync test
`ov config add|edit`, the config wizard and `ov config switch` all rebuild
ovcli.conf from the `Config` struct, which has no `plugin` field and no
catch-all — so every write silently deleted the whole `plugin` section the
memory plugins own. `write_config_file` now carries over the top-level keys
`Config` does not model, `save_edited_config` reads them from the old name on a
rename, and `activate_config` keeps the active file's. Modeled keys are
deliberately not carried over: one that is `None` was cleared on purpose.
`KNOWN_CONFIG_KEYS` decides what counts as modeled, guarded by a test that
fails when a struct field is added without listing it.
sync.test.mjs kept its own copies of the target lists and they had drifted —
dsh, opencode and agent-plugins were each missing modules the sync ships, so a
stale vendored file passed CI. It now imports the lists from sync.mjs (whose
`main()` moved behind an entrypoint guard) and additionally fails on a module
no target claims or a banner-carrying orphan no target lists.
Also in this hygiene pass:
- postRecall dropped `peer_scope` on any 400/422, silently widening recall from
the caller's own peer to the whole user root. It now retries only on an
unknown-field rejection, remembers the downgrade so every turn stops paying
for a rejected request, and both doctors warn while that memo is live.
- The session peer pins (Claude Code's `ws-peer-*.json`, Codex's
`workspacePeerId`) carry a version, so a pin written under one derivation
rule cannot outlive it. Derivation is unchanged, so today they re-derive to
the same value.
- recall-session-wiring.test.mjs was never registered in CI and had rotted
against a fourth RecallManager argument; assertion fixed and registered.
* feat(plugins): layered workspace configuration
A workspace can now carry `<root>/.openviking/config.json`, which a team
commits, and `config.local.json`, which stays private; a per-machine registry
under `~/.openviking/workspaces/` sits above both so the user keeps the last
word over any repository they clone. All three share one schema and one merge,
and they slot in exactly where ovcli.conf's `plugin` section already does, so
`OPENVIKING_*` still wins over everything.
Three modules, synced to all seven plugin targets:
- workspace-identity.mjs finds the workspace root and reads git's own idea of
what the repository is called, using only filesystem reads. No `git`
subprocess: hooks are fresh Node processes on prompt-level paths with budgets
as tight as Codex's 3s SessionEnd, and this keeps working where git is absent
from PATH or would refuse the repo over dubious ownership. Worktrees converge
through `commondir`; submodules stay separate; `$HOME` and `/` are never
workspace roots.
- workspace-config.mjs discovers, parses, filters and merges the layers, and
records per-key provenance — which layer won and what it covered up.
- workspace-registry.mjs keeps one file per workspace rather than one listing
them all, so concurrent hooks cannot lose each other's writes, and treats a
path whose git identity has changed as a miss rather than inheriting the
previous repository's peer.
These files are trusted without a prompt, because a hook is non-interactive and
any approval gate degrades into "run one command per workspace first". What is
refused instead is structural and costs nobody anything: connection and
credential keys are stripped loudly, `${VAR}` is never expanded, and
`cli_config_profile` — which decides which credentials reach which server — is
registry-only and name-only. What a committed file switches off is announced in
doctor rather than blocked.
An adversarial review pass over these three modules found 18 defects, all fixed
here and each now covered by a test. The one that mattered: `JSON.parse` keeps
`__proto__` as an own property, so a 128-byte committed file could write
straight into `Object.prototype`, and since `process.env` reads through the
prototype chain and the environment outranks ovcli.conf, that set
`OPENVIKING_URL` and `OPENVIKING_API_KEY` for the whole process — silently
shipping the user's real API key to an attacker's host. Prototype keys are now
dropped with a warning in both the strip and the merge. The rest: unbounded
recursion (a 4KB file could take out every sibling layer), the identity cache
storing a remote's embedded token at 0644, worktrees under a directory named
`modules` misread as submodules, the registry's negative-evidence check being
inert in its only caller, `Number(null)` pinning cost knobs to a bound, and
provenance lying when two layers disagree about a key's type.
`.gitignore` no longer ignores all of `.openviking/`, which would have stopped
a team's config.json from ever being committed; doctor warns when a workspace
still does. The schema maps `capture.commit_token_threshold`, matching the knob
the loaders actually read — the RFC's example named a turn-based one that does
not exist.
* feat(plugins): derive the workspace peer from git, configurably
The peer a workspace writes its memories under was the working directory with
every non-alphanumeric byte turned into a dash. That made the identity an
accident of where the repository happened to sit: a clone on another machine, a
rename, a worktree, or simply `cd examples/` each minted a separate, empty
namespace, and there is no server-side rename or merge to recover from it.
The default is now git's own idea of the repository. `peer.source` decides the
rule and reads from every layer — `OPENVIKING_PEER_SOURCE`, ovcli.conf's
`plugin.peerSource`, or `peer.source` in a workspace file:
- `git` (new default) ≡ `["{git_remote}", "{git_root}", "{cwd}"]` — the
normalized origin, else the repository root, else the working directory. No
preset adds a prefix; a path-derived id already starts with `-` on POSIX, so
it cannot collide with a remote-derived one.
- `cwd` — the old rule, byte for byte.
- `none` — send no peer. `OPENVIKING_WORKSPACE_PEER=0` still means this.
- Any template, or a list tried in order, over `{git_remote}` `{git_root}`
`{cwd}` `{dir}`. Substitution is all-or-nothing: an empty variable falls
through to the next template rather than leaving a half-formed shared id.
So `/Users/x/Dev/OpenViking/examples/codex-memory-plugin` with origin
`git@github.com:volcengine/OpenViking.git` is `github.com-volcengine-openviking`
from any subdirectory, worktree, machine or clone. Every clone of one repository
shares one peer; a fork has a different origin and stays separate, and
`gh pr checkout` of someone else's PR does not change origin, so reviewing does
not move a session's memory.
Nobody has to migrate. The pre-git id is always recomputable locally, so
`resolveEffectivePeerId` returns it alongside the effective one and recall still
reaches it: under the default `peer_scope: "all"` the server's cross-peer sweep
already covers it for free, and under `"actor"` — where that sweep is off by
definition — the plugin asks that peer separately, as itself, which is cheaper
and reaches more than a bare cross-peer read would. There is no deadline on
this. Wired through all five recall paths; doctor names the previous peer and
says which of the two is carrying it.
`source` keeps its three values because five call sites compare it against the
literal `"workspace"` to decide whether a session pin may be reused; the new
`origin` field names the template that actually produced the id, and doctor
prints it. Both session pins bump their version, so a pin frozen under the old
rule cannot outlive it.
* docs: the workspace peer comes from git, and a workspace can carry config
Every page that described the peer as the working directory with its
non-alphanumerics dashed now describes `peer.source` and the git default, with
the presets, the template variables, the clone-vs-fork identity semantics, and
why no migration is required. The capability reference gains the three new
shared modules; the client configuration page gains a Workspace Configuration
section covering the two workspace files, the per-machine registry, the
precedence table, the v1 schema and what a workspace file may not set; the
Claude Code and Codex integration pages, which never mentioned peer derivation
at all, each gain a short section. All zh mirrors follow.
`examples/schemas/workspace-config-v1.json` is the schema the `$schema` key in
a workspace file points at, and `examples/workspace-config.example.json` is a
file to copy. `ovcli.conf.example` shows `plugin.peerSource`.
Two facts worth stating plainly, both verified against the loaders rather than
assumed: `OPENVIKING_PEER_SOURCE` and the workspace-file layer are read only by
the Claude Code and Codex plugins today, so the other harnesses run on the
default and their pages document the config key rather than an env var that
would be inert; and pi and dsh compute their legacy id from the process cwd,
so their pages promise dual-read only under the default `peer_scope: "all"`.
* fix(mcp): stop the proxies from guessing a peer out of their launch directory
Three MCP proxies keyed the actor peer off `process.cwd()`, which for a
long-lived server started from a static MCP config is the directory the harness
happened to launch from — often the plugin's own. The Codex proxy already
refused this and had a test forbidding it; the rule now holds for all of them
through the same `resolveMcpActorPeerId`.
The plan called for the parent process to inject `OPENVIKING_PEER_ID` at launch
instead, following dsh's `mcp.mjs:27`. That only works for dsh: Claude Code and
agent-plugins are launched from a static `.mcp.json`/`mcp.json` with no
environment block, and OpenCode's `createOpenVikingMcpConfig` builds a command
and args with nowhere to put one. So the fix is to stop guessing rather than to
guess better — a proxy sends no actor peer, which is broad recall, the default.
`resolveMcpActorPeerId` now warns and widens where it used to throw. Refusing to
start took away every memory tool because a scope preference could not be
honoured, which costs the user far more than the wider search does; the warning
says which two settings would scope it.
* test(pi): follow the git-derived peer default rather than pinning the cwd id
* fix(plugins): warn on the camelCase spelling of a connection key too
The projection into harness knobs is an allowlist, so `apiKey` in a workspace
file could never take effect — but it vanished without a word, which reads as
acceptance. It is refused by name now, like its snake_case twin.
* feat(cli): ov workspace show, and ov peer link|migrate|forget-previous
`ov workspace show` answers "which layer actually set this" the way
`git config --show-origin --show-scope` does: the workspace root and how it was
found, the git remote, every template variable, the effective peer and the
template that produced it, each config layer with whether it applied, and per
key the effective value plus everything it shadowed.
That question matters here because three languages read this configuration and
each could drift. So the Rust reader is not a paraphrase of the JS one — the two
were run side by side over the identity helpers, the merge with full provenance
trees, the file-read rules and the registry's raw bytes, and made byte-identical.
That comparison paid for itself: it caught `serde_json::Map::remove` being a
swap remove under `preserve_order`, which reshuffled a registry file the JS half
reads on every rewrite.
It also caught the divergence that would have made the command a liar. ovcli.conf's
`plugin` section speaks the flat knob names a harness loader reads (`peerSource`,
`recallLimit`); a workspace file spells the same settings nested (`peer.source`,
`recall.max_items`). Both are one chain in `loadPluginSettings`, and the port had
merged the flat file into the nested tree, so `plugin.peerSource: "cwd"` in
ovcli.conf left `ov workspace show` reporting the git-derived peer while every
plugin sent the cwd-derived one.
`ov peer link <id>` pins a peer for this workspace in the registry — the way out
of a fork that should share the upstream's memory, or a legacy id worth keeping.
`ov peer migrate` moves a peer's memories and resources with the fs mv API,
reporting the plan by default and requiring `--apply`; the server has no merge
semantics, so a collision is refused with the colliding path rather than
overwritten, and a listing that fills its limit aborts rather than planning from
a truncated view that could hide one. `ov peer forget-previous` clears the
recorded ids.
`workspace show`, `peer link` and `peer forget-previous` are local and do not
require ovcli.conf; `peer migrate` talks to the server and does. Both config
gates and the hand-rendered help are registered, with a test pinning the gates
against each other.
A test now reads FORBIDDEN_KEYS, REGISTRY_ONLY_KEYS and FREE_FORM_SECTIONS out
of the JS module and compares them to the Rust constants, because those lists
are what someone fixing a bug in one language edits — and they had already
drifted once while this was being written.
* build(cli): record the sha2 dependency edge in Cargo.lock
Already vendored for other workspace members; ov_cli now uses it for the
registry slot hash.
* test(plugins): the fixtures the plan named that were still missing
A moved or renamed repository keeping its identity is the change's whole point
and had no test; a shallow clone was worth pinning because it is exactly what
the rejected root-commit scheme could not answer; and the registry's
read-modify-write window between two hooks of one session is now written down as
a test rather than only as a comment.
* fix: the defects a plan review turned up
An independent review against the plan this branch was built from found ten
real defects. Each was reproduced before being fixed and is now covered by a
test.
The four that broke a promise the feature makes:
- The workspace config layer was resolved from the hook process's own working
directory, not from the `cwd` on its stdin payload — which is the
authoritative one. A hook started in one repository while the session sits in
another applied the wrong `.openviking/config.json`: its peer, its bypass
patterns, its `capture.enabled`. `loadConfig` now takes the directory, and
every hook that receives one re-resolves with it. Late re-resolution is safe
precisely because connection and credential keys are structurally forbidden
in a workspace file, so `baseUrl` and `apiKey` cannot move under an already
built client — the gates that a workspace can switch off moved below the
parse so they are decided on the right config too.
- Codex threw away a workspace file's `peer.id`: it returned the credential
chain's peer verbatim, so `{"peer": {"id": "team-a"}}` did nothing. Claude
Code had always honoured it.
- Claude Code's session pin returned only the id and source, dropping
`legacyPeerId` — so from the second hook of a session onward, dual-read
stopped asking the peer that holds everything written before the derivation
changed. Silently, and exactly where it mattered.
- `ov peer migrate` read the source peer with the actor-peer header set, which
the server refuses for another peer's path, and treated every `stat` error as
"does not exist". The common case — an `actor_peer_id` in ovcli.conf — got a
cheerful "Nothing to migrate" instead of a 403. It now uses a client with no
actor peer and tells a real error apart from an empty source.
The rest:
- A directory outside any repository is a workspace again. It had no root at
all, so a `.openviking/config.json` there was ignored entirely. `$HOME` and
`/` are still never roots, now judged on the starting directory rather than
on where the upward walk stops, and `git_root` stays empty outside a
repository so the `git` preset still falls through to `{cwd}`.
- The registry slot is keyed on identity, not path. Two linked worktrees of one
repository are one workspace — one peer, so one set of settings and one
`ov peer link` — and keying on the checkout path split them in two. This also
makes crossing two repositories physically impossible rather than merely
detected. (Their `config.json` files still follow each checkout; those are
files on a branch.)
- git folds section and key names to lower case, so `[Remote "origin"]` with
`URL = …` is a remote `git config` reads and we did not. A quoted subsection
stays case-sensitive.
- `min_client_version` warns instead of being silently kept as data, and still
never blocks.
- `cli_config_profile` was validated and then never used. It now selects
`~/.openviking/ovcli.conf.<name>` before credentials resolve — registry-only,
name-only, and a hard error when the profile is missing, because quietly
authenticating somewhere the user did not choose is the failure the key
exists to prevent.
- `ov workspace show` is exempt from the language gate. It is a diagnostic and
has to work on a machine where no language was ever chosen; `peer link`,
`migrate` and `forget-previous` mutate state and still gate.
- `ov peer link` records the peer it replaced, so a later `migrate` with no
`--from` finds it instead of falling back to a recomputed cwd id.
Two more the plan asked for that were missing: doctor now checks the knobs
*inside* ovcli.conf's `plugin` section — it was on the allowlist, so until now
`peerSorce` sat there doing nothing with no complaint — and suggests the key
you probably meant. A test derives the known-knob set from what the two loaders
actually read, so the list cannot rot into one that rejects a real knob; it
caught a missing entry the moment it was written.
The RFC is archived at docs/design/, with the three claims implementation
disproved corrected in place: the knob is `commit_token_threshold`, `__self`
and `ext-` are not reserved server-side, and a worktree converges its identity
rather than its config file.
* revert(cli): withdraw ov workspace and ov peer from this branch
The command surface these two files added was larger than the feature they
served: 4792 lines of Rust for `ov workspace show` and
`ov peer link|migrate|forget-previous`, against a change whose whole point is
what the hooks send. None of it had reached a user-facing document — only the
RFC named it — so it goes back out whole and the branch becomes a plugin
change plus one CLI bug fix.
Restored from the branch's merge-base rather than from origin/main, since main
has moved on since the branch was cut and those commits are not this branch's
to carry. `sha2` was pulled in only by `workspace.rs`, so its dependency edge
leaves with it.
What stays is `config.rs` and `config_wizard/store.rs`: `ov config add|edit`
dropped the whole `plugin` section because the wizard round-tripped the file
through a typed struct, and that fix has nothing to do with the withdrawn
commands.
The registry under `~/.openviking/workspaces/` stays too, as a layer the
plugins read. Nothing writes it for now; `ov-memory-doctor` prints the path it
expects, and the file is small enough to create by hand. A writer can come back
on its own merits.
* fix(plugins): derive a peer only inside a git repository
Codex desktop opens a directory per task — `~/Documents/Codex/<date>/<slug>/` —
and none of them is a repository. The `git` preset ended its fallback chain at
`{cwd}`, so every one-off task minted its own empty peer, and each new one
started with no memory. Nine such directories here, nine peers.
There is nothing app-specific to read: the state file that lists those threads
is Electron-private, a megabyte wide, desktop-only, and would have to be parsed
inside SessionEnd's 3-second budget. The signal that generalizes is structural
— the directory is not a repository, and nothing in it says it is a project.
So the default chain is now `["{git_remote}", "{git_root}"]` and stops there. A
directory that is neither a repository nor marked gets no peer at all, and what
is remembered in it goes to the user-level space, which is where it went before
peers existed. Deriving an identity from a bare path is what `peer.source:
"cwd"` is for, and it is a word away.
Naming such a directory is the other half. `findWorkspaceRoot` now also stops
at a directory holding `.openviking/config.json` or `config.local.json`, so a
marker file works from any depth below it, the way a repository does — and when
that marker sits inside a repository the git variables still resolve to the
enclosing repository, so marking a subdirectory of a monorepo does not split
the default peer. `{git_root}` is the repository's root, `{dir}` the workspace
root's name whichever made it one.
Nothing moves. When no template resolves, the pre-git id is still computed and
returned as `legacyPeerId`, so `peer_scope: "actor"` keeps asking for it and
`"all"` keeps sweeping it.
Two doctor bugs fell out of the same walk: `checkWorkspace` read `git.kind`
unconditionally and threw wherever there was no repository, and the peer block
warned "set peer.source to git" at a directory where `git` is exactly what is
already set and correctly resolves to nothing. It now says why no peer is sent,
and prints the file to create.
* docs(plugins): say how to give a directory its own peer, to users and to agents
The behavior change is only useful if the reader can act on it, and two kinds
of reader have to: the person whose scratch folder stopped having a memory, and
the coding agent they ask about it.
`docs/{en,zh}/configuration/02-client.md` is the one place that spells the rule
out, and everything else links to it. It gains "Give a Directory Its Own Peer",
which opens with the file to create and then the ladder above and below it;
"By Situation", eight rows from fork to throwaway folder; and "Recall
Isolation", which separates where memories are written from what is read back,
names the server's per-category penalties, and states the cost of sending no
peer outside a repository — a user-level memory is read at full weight in every
project afterwards.
The eight integration pages, both capability references, six plugin READMEs,
the changelog and the schema stop promising a fallback to the working
directory. Checking those claims against the loaders turned up one that was
never true: opencode, dsh and pi do not read workspace files at all, so a
`peer.id` written for them does nothing. Said plainly rather than left to be
discovered.
For agents, `openviking-memory/SKILL.md` gains ten lines on where memories are
filed — it is the skill that fires when someone asks why a folder has no
project memory, and it had nothing to say — and both `ov-memory-doctor`
references gain a table from what the user says to the exact key to write.
`ov-memory-doctor` prints the same snippet, so an agent that runs it needs no
further reading.
One snippet has to be identical in twenty places for any of this to hold, so
`WORKSPACE_PEER_HINT` is a constant the report builds its line from, and
`peer-guidance.test.mjs` asserts it appears verbatim wherever it is promised,
that no page still spells the retired chain or names a command this branch
withdrew, and that every variable the canonical page documents is one the code
substitutes. It asserts no prose: rewording a page must not turn it red.
* fix(plugins): reject an unrecognized peer.source instead of using it as an id
`peer.source` accepts a preset name, a template, or a list of templates, and
anything that is not a preset was treated as a template. A template with no
`{...}` in it renders to itself, so a typo became the peer: `"Git"` wrote every
memory under a peer literally named `Git`, and `"gti"` under `gti`. Silently —
the wrong namespace is indistinguishable from an empty one until someone
notices their project has no memory.
A bare string that is neither a preset nor contains `{` now warns and falls
back to the `git` default. A list is still taken at face value: writing one is
explicit enough that a typo inside it is a different kind of mistake.
The warning travels through an optional `onWarn` callback falling back to
stderr, matching `resolveMcpActorPeerId` in `mcp-proxy-config.mjs` — there is no
warnings array in reach, because `resolveEffectivePeerId` is called from the
hook runtime and from four harness config loaders, none of which thread one.
* docs(plugins): say what each harness can actually do with a peer
The peer documentation promised the same thing everywhere, but only the Claude
Code and Codex plugins read workspace configuration files. `loadPluginSettings`
is called from exactly two loaders; the other harnesses build their config from
their own file plus the environment. So a reader following the docs under pi,
dsh, opencode or cursor would create `.openviking/config.json` and watch it do
nothing.
The skill is the sharpest case: `openviking-memory/SKILL.md` is synced to
cursor and dsh as well, and it told an agent to write that file. An agent would
have done it, reported success, and changed nothing. It now names the two
harnesses that read it and points everyone else at `OPENVIKING_PEER_ID`.
The integration pages had started teaching the recipe and then retracting it in
the same sentence, which is worse than not mentioning it; they now carry the
one instruction that works there, and link to the canonical section for the
rest. The capability reference gains the same qualification, next to the
paragraph that already says only two harnesses read those layers.
Two smaller corrections. The doctor references had the same question answered
twice, once in the peer table and once in the troubleshooting table 140 lines
below; the troubleshooting row survives, since it carries a diagnostic column.
The RFC still archived implementation notes for the CLI this branch withdrew,
which would read as a description of commands that exist.
`peer-guidance.test.mjs` guards this alignment, and had two flaws of its own: it
swept the changelogs, which are generated from GitHub Releases and would go red
on a release note nobody wrote by hand, and it sliced a page between two
headings with `indexOf` without checking either was found — renaming the closing
heading would have silently scanned to end of file.
Also here, because it is the same kind of mismatch: the zcode MCP proxy sent an
actor peer under broad recall, where the other proxies leave the header unset.
It now routes through `resolveMcpActorPeerId` like they do. The dsh proxy
deliberately does not — its parent process resolves the peer per session and
injects it into the child environment, so it is not guessing at a launch
directory, and that reason is now recorded next to the line.
* fix(plugins): ship and install only the shared modules a plugin imports
Three new modules were fanned out to all seven plugin directories in one hunk,
and only two plugins call them. That left dead weight in five directories, and
it broke three installs.
The install is the part that mattered. `install.sh` copies a hand-written list
of shared files into `~/.openviking/agent-integrations/memory-plugin-shared/lib`,
where cursor, TRAE and TRAE CLI import from. The list names `workspace-peer.mjs`
but not `workspace-identity.mjs`, which `workspace-peer.mjs` imports — nor
`workspace-config.mjs`, which identity had come to import for three filename
constants. Copying exactly that list and importing the hook runtime fails with
ERR_MODULE_NOT_FOUND, so every hook of those three harnesses would have died on
startup. Nothing tested the list.
`CONFIG_DIR_NAME`, `TEAM_FILE` and `LOCAL_FILE` now live in
`workspace-identity.mjs`, which is where the walk that recognises a marked
directory needs them; `workspace-config.mjs` imports and re-exports them, so no
call site moves. Identity has no library-internal dependency left, which is what
makes the installed set closed at fifteen files instead of pulling the whole
configuration layer along behind it. `install-lib-closure.test.mjs` derives both
sides — the list parsed out of the shell script, and the transitive imports of
the three entrypoints — and fails in either direction, so neither a new
dependency nor a stale entry can go unnoticed again.
With identity standing alone, the fan-out can follow what is actually imported.
`sync.mjs` moves from arrays chained by spread — where the harness that does not
need a file is often the one the array is named after — to explicit per-target
lists. `plugin-config.mjs`, `workspace-config.mjs` and `workspace-registry.mjs`
leave dsh, pi, opencode and zcode, none of which import them; all four workspace
modules leave agent-plugins, whose only importer was deleted a half hour after
they arrived and whose peer is environment-only by design. That is about 4500
lines of vendored code that said something the code did not do.
The registry loses its write path in the same spirit. `writeEntry`,
`rememberPreviousPeer` and `listEntries` had no caller outside their own tests:
the CLI that would have written them was withdrawn from this branch. `readEntry`
and `entryPath` stay, because a hand-created entry is still read and the doctor
still prints where to put one. `cli_config_profile` goes with them — the whole
mechanism, down to the documentation that described it, since nothing ever
resolved a profile through it.
This is not a new policy. `HARNESS_KEYS` already carried the rule in a comment,
added the day after the same speculative fan-out happened in August: add a key
as its loader starts calling `loadPluginSettings`, not before, so the section
never promises a knob that silently does nothing.
* fix(dsh): thread peerSource into the per-session peer
The integration page documents `peerSource` in dsh's Cordis patch, but `stateFor` never passed it to `resolveEffectivePeerId`, so the key resolved to nothing and every dsh session ran on the default derivation. Pass it, and keep the pre-git id alongside so dual-read reaches memories written before the default changed.
* docs(plugins): correct the shared-layer counts after the distribution changed
The capability reference still described the pre-branch distribution: 18 library modules against 23, per-target counts from before each target stopped receiving the workspace configuration layer, and `workspace-config` / `workspace-registry` listed as reaching every JS harness when only claude-code and codex load them. It also still said `cli_config_profile` was registry-only, and that the registry is written for you.
* docs(rfc): lead with a TL;DR of the workspace config and peer source proposal
* feat(plugins): let peer.source name the harness with {harness}
The peer templates could describe where a checkout sits but never which
agent was running in it, so one repository could not keep a separate
memory per agent even when its user wanted that. The harness name was
already in every config, only baked into the User-Agent string.
No preset uses the new variable: sharing one project memory across
agents is the more useful default, so splitting stays opt-in via a
template such as "{git_remote}-{harness}". It is composed at render
time rather than in the workspace identity, whose result is cached
under a cwd-only key that two harnesses in one directory would share.
* docs(rfc): record git_branch and peer.command as directions, not deliverables
* chore(plugins): resync the openclaw vendored recall-core after the rebase
* test(opencode): follow resolveEffectivePeerId's widened return shape
Also mark the openclaw shared copies generated, the way every other sync
target already is.
|
||
|
|
f6d9dec6b6 |
feat: 增加事务化文件系统复制能力 (#4185)
* refactor: share vector URI rewrite rules * feat: add strict vector transfer transactions * feat: add transactional VikingFS copy * feat: coordinate filesystem copy service * feat: expose filesystem copy API * feat: add ov cp command * test: cover filesystem copy end to end * test: compose CLI collection hooks * fix: support vector copy on volcengine backend * fix: harden copy transaction boundaries * fix: retain copied entry in parent semantics * fix: scan local vectors with supported sort key * fix: refresh move target parent semantics * fix: report missing copy target directory * feat: rebuild transfer parent semantics from target summaries * fix: refresh both parents after move * docs: document filesystem copy API * fix: adapt copy flow to canonical URI boundary * fix: adapt transfer semantics after upstream rebase * fix: harden copy and move transaction boundaries * fix: preserve transfer metadata and direct ACLs * ci: exercise copy with available capabilities * fix: restore move vectors after ACL refresh failure --------- Co-authored-by: chenpengfei <chenpengfei@bytedance.com> |
||
|
|
2bb07a4d54 | fix(ci): wait for ClawHub prepublication checks (#4510) | ||
|
|
7200cdb176 |
feat(codex): commit on SessionEnd hook, keep SessionStart sweep as fallback (#4429)
* feat(codex): commit on SessionEnd hook, keep SessionStart sweep as fallback Codex ships a SessionEnd hook since rust-v0.145.0. The plugin now commits the OpenViking session from that hook (marker + detached worker within the 1s/3s budget, catching up turns the last Stop never sent) and reduces the SessionStart active-window heuristic to an ended/idle sweep. Adds a per-session lock so the Stop worker, PreCompact, SessionEnd worker and sweep no longer clobber each other's state writes, stops an unreadable transcript from resetting the capture cursor, and merges the three copies of the HTTP/transcript helpers into scripts/ov-session.mjs. * fix(codex): guard SessionEnd partial catch-up, make the sweep catch up, token the end marker, own the lock Review follow-up for #4429: SessionEnd no longer commits after an incomplete catch-up (tail turns were archived away); capture hooks record transcriptPath so the SessionStart sweep catches up before committing; the .ended marker's timestamp acts as a token that the SessionEnd worker and the sweep re-verify under the lock, and Stop/PreCompact/resume only clear markers older than their own start; withSessionLock stamps an owner file and takes over stale locks by atomic rename with an inode check so a taker never moves a lock a racer just created. Plugin 0.8.1. * fix(codex): catch up ended sessions with no live id, guard unreadable transcripts, make the end marker and the lock takeover race-free Four defects found reviewing the SessionEnd commit path: - The SessionStart sweep cleared the `.ended` marker of a state with no live ovSessionId before taking the lock, so a session PreCompact had released and that then produced more turns lost its tail when its SessionEnd worker died. A marker now always enters the lock, and only a catch-up that finds nothing new may clear it. - catchUpTurns reported an unreadable transcript as an empty one, so all three callers committed and archived a session whose tail they never saw. It now reports `unreadable` and they keep the session live for a later retry. - clearEnded read the marker's timestamp and then removed the path, deleting a marker a concurrent SessionEnd had just written. The timestamp moved into the filename, so a conditional removal targets an immutable path. - session-state.test.mjs was missing from the CI test list. Also replaces the lock's stale takeover: renaming the directory aside left the lock path momentarily absent, which let another racer's mkdir succeed next to the taker. Takers now race for the `owner` file inside the directory instead. * fix(codex): make the end marker's generation unique within a millisecond Date.now() alone is not a generation: two SessionEnd hooks in the same millisecond produced the same marker path, so the first one's conditional removal took the second one's marker with it. The marker is now created exclusively and its timestamp bumped until that succeeds; bumping rather than randomizing keeps the names ordered, which is what the `before` cutoff compares. The race test drops its artificial 2 ms gap and runs 500 iterations. |
||
|
|
26314efb7a |
ci: build the release docker image once (#4469)
* ci: build the release docker image once, not twice release.yml carries a full copy of the docker build/manifest jobs from build-docker-image.yml. Both fire on the same release: the tag push triggers build-docker-image.yml while the release event triggers release.yml's copy, so every release builds the same image 4 times (2 arch x 2 workflows, ~16 min each) and both pipelines race to write the same v0.4.x and latest tags. Drop the copy. build-docker-image.yml has to exist anyway (main images, manual dispatch) and emits the identical tag set for a tag ref. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01247pby58vheLBLmHPV3WKQ * ci: assert the release's docker image actually landed The tag push and the release event fire in the same second, so the image is still ~16 min from existing when release.yml starts. Poll the tag's build-docker-image run, fail on a missing or failed run, then inspect both registries for the version tag. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01247pby58vheLBLmHPV3WKQ * ci: assert latest points at the released tag too The version tag existing was never the failure mode; latest silently staying on the previous release was. Compare digests instead of just checking the version tag is present. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01247pby58vheLBLmHPV3WKQ --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com> |
||
|
|
871f6dfa19 | Revert "ci: persist BuildKit mount caches across runs (#4421)" (#4467) | ||
|
|
013b4a042e |
ci: persist BuildKit mount caches across runs (#4421)
* ci: persist BuildKit mount caches across runs Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci: key mount caches on native-build inputs, drop npm/uv from cache-map Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
206054cf15 |
feat(memory-plugin): add ov-memory-doctor skill and diagnostics script for Claude Code and Codex (#4389)
* feat(memory-plugin): add ov-memory-doctor skill and diagnostics script for Claude Code and Codex * docs(memory-plugin): link docs and mark the Volcengine-hosted service in the doctor skill * feat(memory-plugin): add a Server health section to the doctor for local deployments When the resolved url is loopback the doctor now inspects the server side: ov.conf startup blockers (plugin-only keys the server rejects, dev mode on a non-loopback bind, empty root_api_key, port mismatch, relative workspace, unexpanded $VAR secrets, provider credential rules), the server process and port owner (pid file, lsof/ss, docker container and its /app/.openviking mount), the vector index's recorded embedding vs the configured one, the server log when log.output is a file, and GET /ready. Remote servers get the /ready probe only. The docker pending_initialization stub is recognised in the Connection section. Skills, references and READMEs describe the new section; provider-level validation stays with openviking-server doctor. * refactor(memory-plugin): trim the doctor's Server health section to the port, plugin-only ov.conf keys and /ready The section replicated the server's own config validation (top-level and server.* key allowlists, provider credential rules, vlm, workers) and inspected the pid file, docker mounts, systemd, the vector collection metadata and the server log. All of that is what openviking-server reports itself at startup or what `openviking-server doctor` covers, and the allowlists would drift with every new config field. Keep what the server cannot tell the client: whether anything listens on the port, the plugin-only ov.conf keys the server refuses to start on, and GET /ready. doctor-core.mjs is now synced only to the plugins that ship a doctor script; the opencode and zcode copies were never imported. |
||
|
|
3b1db2082f | fix(memory-plugin): setup wizard first-run path, proxy hint, config source reporting (#4387) | ||
|
|
54171182da | fix(ci): avoid generated branches for plugin releases (#4242) | ||
|
|
c7044075ef |
feat(dsh): serve tools over the shared stdio MCP proxy (#4157)
* feat(dsh): serve tools over the shared stdio MCP proxy Replace the dsh bundle's seven hand-registered `viking_*` tools with the OpenViking MCP surface, reached through the same stdio proxy every other memory integration starts, and collapse the four duplicated proxy entrypoints onto a shared config builder. The bundle now mounts `@deepseek-ai/dsh-mcp-client` (which ships with dsh itself) on `servers/mcp-proxy.mjs`. Pointing an MCP SDK client straight at the server's `/mcp` endpoint does not work: with `stateless_http=True` the server still answers `GET /mcp` with an idle 200 SSE stream, and once the SDK client opens that standalone stream it stops resolving POST responses, so `tools/list` never returns. The stdio proxy owns the transport itself and is unaffected. `trimSlash`, `normalizePath`, `uniq`, the watched-credential-path list and the cfg -> proxyConfig mapping existed in four near-identical copies (claude-code, codex, opencode, agent-plugins; the last one carried a "keep in sync with claude-code" comment). They move to `memory-plugin-shared/lib/mcp-proxy-config.mjs` and all five entrypoints — including the new dsh one — now shape their config through `buildMcpProxyConfig`. Behavior is preserved per field, including codex's explicit `mcpUrl` override, claude-code's `ovcli.conf` credential-source probe, and opencode's extra watched config file. The bridge is mounted last in `apply()` so a proxy that fails to start cannot hold up profile injection, recall, capture, commit, or the URI guard registrations above it. * feat(dsh): add to the unified installer and ship the shared skill The bundle now registers its own isolated `ctx.skills` provider serving the shared `openviking-memory` skill, so DSH gets the same guidance the Claude Code, Codex, and Cursor integrations ship. `sync.mjs` distributes the skill to the bundle, and the provider uses `includeDefaultRoots: false` so it never shadows DSH's own project/user skill catalog. `install.sh` grows a `dsh` harness id, auto-detected like the others, plus a profile prompt that defaults to `web` (`--dsh-profile` / `OPENVIKING_DSH_PROFILE` answer it up front). The installer always installs the published package: `dsh plugin` forwards to pnpm, and a linked source tree cannot resolve the dsh peers the bundle imports because Node resolves them from the checkout's realpath rather than from the profile. Documentation is restructured around installing rather than internals. The integration page now leads with the one-line installer and keeps behavior at the level the other harness pages use, with configuration in a details block; design rationale moves to the bundle README, which itself leads with Install and groups the rationale under "Design notes". Capability-reference claims that dsh is outside the unified installer are corrected. * chore(dsh): release 0.2.0 The MCP tool surface, the stdio proxy transport, and the bundled skill all change what the bundle does for an existing user, so this is a minor bump rather than a patch. 0.1.0 remains the native-`viking_*` tool surface. * docs(dsh): note pnpm's 24h minimum release age pnpm 11 refuses releases younger than minimumReleaseAge (24 hours by default), and surfaces it as a registry 404, so installing a freshly published version reads as "the package does not exist". * fix(dsh): honour dev source mode in the installer install_dsh ignored SOURCE_MODE and always fetched the published package, so selecting "current checkout" installed npm's build instead of the working tree and validation still reported success. npm is the bundle's only distribution channel, so the github/tos choice does not apply to it: every mode except dev now installs the published package, and dev packs the checkout with npm pack first. It has to arrive as a real package rather than a link, because a linked source tree resolves its dsh peers from its own realpath and misses the profile's hoisted node_modules. The install line reports which source was used. * fix(dsh): make repeated installs actually overwrite Two ways a re-run silently kept stale code: pnpm treats an already-satisfied version as a no-op regardless of which tarball the file: dependency points at, so a dev re-install after editing the checkout left the previous build in place. Local installs now drop the package before adding it back; that is confined to local sources, since doing it for the registry path would leave nothing installed when add fails. A bare package name has the same effect in reverse: a profile holding a dev build satisfies it, so switching back to the published package was a no-op. The registry path now asks for @latest. The packed tarball is named after a fingerprint of the checkout's shipped files, so an unchanged checkout skips the pack and keeps a stable path in the profile lockfile. |
||
|
|
dc39985ad1 |
refactor: remove resource relation edges (#3956)
* refactor: remove resource relation edges * fix: remove stale relation references --------- Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com> |
||
|
|
7e7ad2e1f6 |
chore: remove dead git tuning knobs and duplicate release/frontend files (#4089)
* chore: remove dead git tuning knobs and duplicate release/frontend files - GitTuningConfig: drop upload_concurrency, restore_concurrency, ref_cas_max_retry, and ref_cas_backoff_ms, which were parsed but never read anywhere (verified no source readers). Keep commit_index_enabled and blob_exists_precheck_enabled, the two knobs that actually take effect. - Design doc: mark the removed knobs as roadmap items to be added back when the behavior lands, and correct stale 'not implemented' claims (validate_account_id is enforced at the Git service entry; blob reads are limited via show_with_limit). - Remove .github/workflows/release-vikingbot-first.yml: a historical one-off PyPI release workflow whose bot/ package lacks build metadata. - web-studio: delete pnpm-lock.yaml and the pnpm-only package.json block; the Makefile and CI already use npm + package-lock.json as the single install chain. Net -9,695 lines. * docs: align cleanup notes with current behavior --------- Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com> |
||
|
|
4bf438a655 |
fix(vectordb): encode string IDs before hashing (#3995)
* fix(vectordb): encode string IDs before hashing * ci(cuvs-tests): run test_str_to_uint64.py in the CPU-only regression job |
||
|
|
ff415b905d |
feat(plugins): package the openviking-memory skill into coding agent plugins (#3974)
Ship the generic openviking-memory SKILL.md from examples/skills as the canonical source and vendor it into the codex, claude-code, and cursor memory plugins through the existing shared-file sync script. - examples/skills/openviking-memory/SKILL.md is the single source of truth - sync.mjs copies skills verbatim (no GENERATED banner: it would sit ahead of the YAML frontmatter and break every skill loader) - sync.test.mjs asserts the vendored copies stay byte-identical - the marketplace staging script now requires the two newly vendored copies Split out of #3866: this carries only the generic skill packaging. The Experience / agent-evolution half of that PR (ov-experience-memory skill, server MCP experience tools, usage attribution) is deliberately excluded. |
||
|
|
b7aa01d227 |
feat(plugins): add OpenViking memory integration for TRAE CLI (#4026)
* feat: add OpenViking memory integration for TRAE CLI Add TRAE CLI lifecycle hooks and MCP proxy support, wire the integration into the shared installer, and cover idempotent install and uninstall behavior. Co-authored-by: TRAE CLI <noreply@bytedance.com> * fix(trae-cli): cover archive installs and hook payload aliases * fix: keep TRAE CLI installation explicit Leave TRAE Desktop detection unchanged and avoid auto-selecting TRAE CLI. TRAE CLI remains available through an explicit harness selection or --harness trae-cli. Co-authored-by: TRAE CLI <noreply@bytedance.com> * fix(trae-cli): auto-select installed CLI commands Detect traecli and traex only when they are available in PATH, then mark and select the TRAE CLI harness automatically. --------- Co-authored-by: “bianhaonan” <“bianhaonan@bytedance.com”> Co-authored-by: TRAE CLI <noreply@bytedance.com> |
||
|
|
d7ab37c76e |
feat(plugins): add OpenViking memory for DSH (#3993)
* feat(plugins): add OpenViking memory for DSH * feat(dsh-plugin): graft review items — source whitelist, dsh constructors, live recall gate Applies the #task-65 review verdict's graft list from #3991 onto the #3993 base: - capture whitelist: drop every plugin-sourced user message (any plugin, not just this one) so injected context never mirrors into memory as human input; recall queries keep their existing scope - pre-step: register with prepend so this listener sees the final claimed batch, and short-circuit on signal.aborted around each await - adopt dsh constructors behind exact-pinned peers (devDependencies mirror the pins): tools flow through @deepseek-ai/dsh-tools defineTool (declarative parameters, output schema/render, presentCall per tool), plugin messages through @deepseek-ai/dsh-llm createUserMessage; a registration-shape test makes a future rc pin bump fail CI instead of a user install when the ToolDefinition contract moves - live-recall.test.mjs: opt-in (OPENVIKING_E2E=1) real-backend gate — store a sentinel via session commit, wait for extraction, assert recall returns it; passed against a live OpenViking server in 124s (note: commit with the default keep_recent_count=10 extracts nothing from short sessions — the test pins keepRecentCount 0) - README: why injection is pre-step user messages, not the system prompt (complete:true personas silently drop prompt assembly), plus peer-pin rationale and a Testing section Tests: 15 pass + 1 env-gated (node --test), requires npm ci for the pinned dsh devDependencies — CI step lands separately (workflow scope). * ci(pr): install DSH plugin deps before running memory plugin tests * fix(dsh-plugin): finalize neutral plugin integration Remove product-specific identifiers from the DSH plugin surface and harden its lifecycle, HTTP contracts, archive tooling, and ordered offline delivery. Co-authored-by: TRAE CLI <noreply@bytedance.com> --------- Co-authored-by: Zayn Jarvis <zaynjarvis@gmail.com> Co-authored-by: TRAE CLI <noreply@bytedance.com> |
||
|
|
8abd61fcb6 |
feat(plugins): add Agent Plugins 1.0 portable package (#3998)
* feat(plugins): add Agent Plugins 1.0 portable package Add agent-plugins/, an Agent Plugins 1.0 conformant package (https://agent-plugins.org/specification) that any conforming client can load: plugin.json manifest, an openviking-memory skill teaching the hook-less recall + persist loop, and an mcp.json stdio entry running a stdio -> streamable-HTTP proxy that resolves credentials from OPENVIKING_* env -> ~/.openviking/ovcli.conf -> ~/.openviking/ov.conf, same as the ov CLI. servers/shared/* are generated copies of memory-plugin-shared/lib, wired into sync.mjs / sync.test.mjs TARGETS so they cannot drift silently. config.mjs / debug-log.mjs / mcp-proxy.mjs are adapted from claude-code-memory-plugin with the hook-tuning knobs dropped. plugin.test.mjs validates spec conformance (schema URLs and matching spec versions, name rules, closed manifest root, semver, skill frontmatter, referenced files staying inside the plugin root, node --check on all .mjs) and runs in CI via pr.yml. The skill treats tree/write/edit as optional, since they only exist on servers that carry #3936. Docs: docs/{en,zh}/agent-integrations/15-agent-plugins.md, registered in the VitePress sidebar and the integration overview tables, plus a link from the three root READMEs. The docs recommend the per-client plugin whenever the harness has hooks, with the shared installer one-liner. Based on #3994 by @ZaynJarvis. Co-Authored-By: Zayn Jarvis <zaynjarvis@gmail.com> * docs(agent-plugins): pluralize README title --------- Co-authored-by: Zayn Jarvis <zaynjarvis@gmail.com> |
||
|
|
33043cb1b8 |
feat(plugins): expose session commit trace IDs (#3977)
Preserve result.trace_id across plugin HTTP wrappers, include it in commit success and failure logs, and surface it in user-visible commit confirmations where supported. |
||
|
|
2d5aa9cd3d |
fix(plugins): ship Experience skill in plugin packages (#3946)
* fix(plugins): ship experience memory skill * fix(openclaw): drop unpublished selector aliases |
||
|
|
7e26fab61c |
fix(memory-plugins): report tool output verbatim, let the server externalize (#3933)
Coding-agent plugins capped a tool part's `tool_output` at 2000 chars before
POSTing it to `/api/v1/sessions/{id}/messages`. That cap sits below the server's
own externalization threshold (`tool_output_externalization.threshold_chars`,
default 20000), so output in the 2k-20k band was destroyed for no reason and
anything larger never reached `ToolResultStore` - leaving `tool_output_ref`
permanently empty and the `/tool-results` read-back path unusable.
Raise the `captureToolMaxChars` default to 1000000 (a guard against pathological
payloads, not a truncation policy) and lift the opencode/pi clamps that would
otherwise pin it back to 20000. claude-code had no knob at all - two hardcoded
`TOOL_OUTPUT_PART_MAX_CHARS = 2000` constants - so it gains the same config
entry and both capture scripts now read it.
Also stop pi from sending tool output twice: for a tool-only payload the
rawText-derived text part re-rendered the same output the tool part carries.
|
||
|
|
9d5cbae70e | fix(examples): align quick start with server mode (#3923) | ||
|
|
eda69f997f |
feat(ci): auto-publish openclaw plugin on merge to main (#3836)
Add push trigger (paths: examples/openclaw-plugin/**) to the release workflow, keep publish jobs enabled on push, serialize runs with a concurrency group, and retry the ClawHub verify step which races the registry's read-after-write / rate-limit window. Co-authored-by: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
0ab48f96fc |
fix(session): recover partial capture sessions (#3820)
Treat messages.jsonl as the materialization boundary for session-aware recall, repair partial session roots during the existing authoritative append path, and preserve Claude capture cursors when writes never reach the server. Also replay explicitly retryable storage conflicts across memory plugins. Co-authored-by: TRAE CLI <noreply@bytedance.com> |
||
|
|
2cc96e393e |
feat(retrieval): assemble auto-recall context server-side via /search mode="context" (#3534)
* feat(retrieval): assemble auto-recall context server-side via /search mode="context"
Auto-recall assembly lived in every harness plugin: each one searched per
memory type, read hits back one by one, and stitched a context block with its
own budget and degradation rules. The implementations drifted, and the shared
weaknesses showed up in production injections — roughly half of the entries
degraded to a bare URI plus a score, character budgets distorted up to 6x on
CJK text, and adjacent turns re-injected the same memories.
This moves assembly into the server as one round trip. /find stays an unchanged
stateless primitive. /search gains mode="context" (mode="list" is the default
and byte-identical to before), and /recall becomes a thin preset over the same
kernel with its v1 field names folded onto the new contract.
New assembly kernel under openviking/retrieve/context_assembler/:
- Token budgeting with a CJK-aware estimate replaces the character budget.
- detail="auto" fills breadth-first then deepens: every candidate gets a
readable floor, then overview, then full for high-scoring entries. An
oversized tier falls back to the previous one instead of being truncated,
bounded by max_tokens / candidates * 2 per entry.
- Overview extraction dispatches by source: memory files use their leading
Summary section, code files reuse code_outline signatures, long documents use
a heading tree plus first paragraph.
- Directory hits start at overview and read their .overview.md sidecar, since
directories carry no stored abstract; their full tier stays capped at
overview. v1 injected the sidecar as if it were a whole file.
- Quotas generalize beyond memory types to resources and skills, with purpose
presets supplying ratios when quotas are absent.
- dedup_turns keeps a per-session ledger at {session_uri}/.recall_log.json so
every harness inherits cross-turn dedup; exclude_uris remains as the
stateless fallback.
- Rendering flattens to one <memory uri=... type=... score=... detail=...>
element per entry. Every tier carries its URI, so the model can always drill
down through the MCP read tool.
- Query expansion and digest rewriting are opt-in and fail closed: both have
timeout fuses, and a failed rewrite still returns the unrewritten block.
Retrieval failures are counted into stats rather than silently yielding an
empty block.
Plugins now send one context request, falling back to /recall and then to raw
find on older deployments, and cache that outcome so only the first turn pays
for the probe. The tri-state recallRewrite knob chooses between local host-CLI
compression and the server digest, and client-side settings move to a plugin
section in ovcli.conf.
* refactor(retrieval): give context tiers a per-category default
The tier ladder assumed `abstract` is a cheap summary. For memory files it
is not: the memory writer stores the whole stripped body in that scalar
because it doubles as the embedding text, so `abstract` costs the same as
`full` and the ladder runs `uri < overview < abstract = full`. Two of the
model's properties fell out of that: exempting `abstract` from the per-entry
cap let a single entry eat several times the budget, and `detail` — which
only ever set a ceiling — collapsed to two distinguishable behaviours across
its four values, since `auto` already allowed `full` for memory.
Tiers now come from a per-category constant table that treats the storage
shape as a given: `events` starts at overview (the one memory type whose
`# Summary` extraction is a real compression) and may deepen to full on
leftover budget; every other category is served at `abstract`, which for
memory already is the complete file at zero read cost and for resources and
skills is the generated 256-char summary. The table carries the note to move
`events` back to `abstract` once the writer stores a separate summary scalar.
Falling out of that: prefetch now reads only the candidates whose planned
tier needs a body rather than every candidate, `detail` becomes a real pin
(start and ceiling) and additionally accepts a per-category map, and
`full_score_threshold` is gone — leftover budget is spent in score order
instead of behind an absolute threshold the observed score band cannot
support. `auto` is still accepted on the wire as a synonym for "unset".
Assembly fixes found alongside:
- Removing the abstract cap exemption would turn an oversized abstract into
a bare URI, so it now falls back to overview first — for memory that is a
cheaper substitute, not a step up.
- Rewrite timeouts were reported as failures on Python 3.10, where
`asyncio.TimeoutError` is a separate class from the builtin.
- `stats.rewrite_usage` read `token_tracker` off `VLMConfig`, which has no
such attribute; usage was structurally always null. It now reads the model
instance's tracker and reports only when the call count moved by exactly
one, since that tracker is shared.
- A single malformed ledger record made every deduped recall in that session
fail, and the file was never rewritten, so it could not heal. Records are
now coerced on read and dropped on the next write, along with records left
ahead of the clock by an archive rotation.
- Entries served as a bare URI no longer enter the dedup cooldown: they lost
to budget pressure, not to the reader having already seen them.
- The render envelope only neutralised a literal `</memory>`, so a body could
forge a sibling entry with its own uri, type and score.
- Flat-mode gathering re-derived the category from the URI, reading
`viking://resources/backup/memories/events/log.md` as an event.
- Cooled and excluded URIs are compensated with extra rows, so a fully cooled
bucket falls through to the next-best hits instead of coming back empty.
- `/recall` quotas overlay the v1 bucket defaults again; `{"events": 5}` had
started dropping the other three buckets.
- The MCP `recall` signature sent its own defaults as if the caller had, which
resolved a different profile than `POST /recall`; an unknown `detail` value
raised `KeyError` through the whole call instead of degrading.
* feat(codex): inject profile context on session start
Reuse the shared profile builder for startup, clear, and resume hooks while preserving archive injection and orphan-session status output.
Co-authored-by: TRAE CLI <noreply@bytedance.com>
* fix(retrieval): raise rewrite timeout default to 30s
* docs(agents): document low-latency recall settings
* fix(codex): prefer luna as recall compressor fallback
* refactor(plugins): unify recall compression setting
* feat(plugins): enable recall compression by default
* docs(agents): use absolute links in image docs
* fix(retrieval): address context assembly review feedback
Co-authored-by: TRAE CLI <noreply@bytedance.com>
* test: trim redundant context assembly coverage
* fix(retrieval): address second-round context assembly review
- Drop the backticked `/search` from the deprecated-recall row in both API
overviews. The reference checker scans the whole row after the method cell
for backticked paths, so it read the description as a route named
`POST /search` and Build Docs failed on an unknown, undocumented route.
- Accept ovcli.conf's full field set in both Python readers. The file's schema
belongs to the Rust CLI, which writes `root_api_key`, `output`,
`echo_command`, `show_progress` and `verbose` and ignores unknown keys; the
two Python readers had drifted into stricter subsets, so the shipped example
already failed to load in both. Adding the new `plugin` section to a working
ovcli.conf would have broken `ov doctor` and every SDK client the same way.
- Return 400 from `mode="context"` for a request `mode="list"` also rejects.
Retrieval validates query and image_url before searching, and the gather
fuse swallowed that rejection along with genuine scope failures, so a body
of `{"mode":"context"}` came back 200 with an empty block instead of the
documented parameter error. Runtime failures still degrade into
`stats.retrieval_errors`.
- Let a context request that asks for a server-side digest outlast the
server's rewrite fuse. The plugin's ordinary 15s request timeout is shorter
than the 30s fuse, so a rewrite that finished inside its own budget was
aborted client-side, discarding the whole response — including the
uncompressed block the server returns when a rewrite fails — and falling
back to `/recall`. The deadline is only extended when the body actually
requests a rewrite, and `OPENVIKING_RECALL_CONTEXT_TIMEOUT_MS` /
`plugin.recallContextTimeoutMs` pins it.
* chore(plugins): sync shared modules into the zcode snapshot
* fix(retrieval): align context quotas and plugin defaults
Restore cross-domain coding recall, reuse authoritative actor resource
scopes, and make bucket quotas the sole width control in purpose mode.
Keep plugin defaults server-owned while preserving explicit legacy limit
settings through quota conversion.
Co-authored-by: TRAE CLI <noreply@bytedance.com>
* fix(retrieval): preserve recall compatibility
Restore the deprecated recall threshold default, distinguish successful empty rewrites from compressor failures, and document legacy quota floors across coding-agent plugins.
Co-authored-by: TRAE CLI <noreply@bytedance.com>
---------
Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
|
||
|
|
f08293411d |
fix(zcode): make memory capture reliable (#3728)
Use ZCode rollout logs as the authoritative incremental source, advance capture state only for the acknowledged prefix, and persist host turn identity with the OpenViking turn_id contract. Detach Stop writes, package ZCode in the TOS marketplace artifact, add end-to-end regressions, and move the integration docs under community plugins. Co-authored-by: TRAE CLI <noreply@bytedance.com> |
||
|
|
b2e1972610 |
refactor(langchain): extract standalone integration package (#3685)
* refactor(langchain): extract standalone integration package * fix(langchain): preserve optional legacy imports * fix(langchain): guard legacy submodule imports |
||
|
|
de9c3cec15 |
fix(storage): preserve deletion and session durability (#3553)
* fix(ragfs): preserve cache visibility on partial S3 deletes Surface exact and per-object S3 deletion failures, while always invalidating the affected directory and stat cache scope after a recursive delete attempt. Source-PR: #3407 Original-Commit: |
||
|
|
6f10e26361 |
perf(plugins): batch add-message writes and shared async detach across memory plugins (#3261)
* Batch add-message writes across memory plugins * fix(plugins): stop batch enqueue at first failure and bump plugin versions Keep pending-queue entries a contiguous prefix when a mid-stream enqueue fails: consumers mark the first sent+queued payloads as captured, so a queued entry after a gap could silently drop the gapped message. Bump claude-code 0.4.3, codex 0.7.3, opencode 0.2.3, cursor/trae 0.1.2 so existing installs pick up the batch write path. |
||
|
|
6de1cd2c6e |
test(oc2ov): fail fast on empty OpenClaw output (#3250)
Co-authored-by: huangruiteng <huangruiteng@bytedance.com> |
||
|
|
161fbab22c | docs: disclose agent provenance in contribution templates (#3216) | ||
|
|
91a8f03084 |
docs: add tabbed API examples (#3185)
* docs: add tabbed API examples * docs: move llms actions to page header * docs: make content layout responsive * docs: split guide navigation sections * docs: regroup agent and migration guides * docs: add wide-screen page gutters * fix: address API docs review findings * fix: address API docs review findings * fix: harden API example tabs * fix: harden tabbed API documentation * fix(docs): hide unavailable llms actions * fix(docs): group API examples into tabs * fix(docs): preserve localized response tabs |
||
|
|
5bfa9b617e |
fix: align TypeScript SDK with server contracts (#3159)
* fix: align TypeScript SDK with server contracts * fix: harden TypeScript SDK contracts * fix: handle Node image references safely * fix: make OVPack downloads atomic |
||
|
|
e123bbc0ec | ci: restore token-based ClawHub release workflow (#3160) | ||
|
|
0536e6897b |
feat: add JavaScript and TypeScript SDK (#3147)
* feat: add JavaScript and TypeScript SDK * fix: align TypeScript SDK contracts |
||
|
|
9cf42405a8 | fix(installer): avoid silent exit after harness selection (#3128) | ||
|
|
7e6a0515f9 |
perf(cuvs): optimize filters, rebuilds, concurrency, and memory (#3092)
* perf(cuvs): fast-path cached native filter routes * perf(cuvs): parallelize auto filter preflight * perf(cuvs): add search route telemetry * test(cuvs): use a valid telemetry vector dimension * perf(cuvs): reuse native filter preflight results * perf(cuvs): allow concurrent snapshot searches * perf(cuvs): coalesce optional background rebuilds * perf(cuvs): coordinate per-GPU build admission * perf(cuvs): add opt-in float16 search * build(cuvs): support vector benchmark harnesses * perf(cuvs): bound concurrent GPU searches * perf(cuvs): avoid partial background rebuilds * fix(cuvs): address rebuild and telemetry review feedback * fix(cuvs): defer rebuild until index initialization --------- Co-authored-by: Yuanqing Zhao <2604121+yuanqingz@users.noreply.github.com> |
||
|
|
d14dd69665 |
feat: add Cursor and TRAE memory integrations (#3109)
* feat: add Cursor and TRAE memory integrations * fix: install Cursor plugin from shared command * refactor: share Cursor and TRAE integration runtime * fix: migrate legacy OpenViking MCP entry * docs: simplify Cursor and TRAE setup guides * fix: harden Cursor and TRAE memory integrations * refactor: standardize Cursor and TRAE integrations * refactor: clarify Cursor and TRAE hook entrypoints * fix: address Cursor and TRAE integration review |
||
|
|
c43e22d705 |
ci(release): add controlplane MCP PyPI release workflow (#3117)
Manual-dispatch workflow that builds mcp-server-openviking-controlplane (MCP server + ov-cp CLI) from an explicit ref of an external source repo (default volcengine/mcp-server, subdirectory server/mcp_server_openviking_controlplane) and publishes it to TestPyPI/PyPI via the existing trusted-publishing environments. Requires a one-time pending-publisher registration on (Test)PyPI binding the project name to this repo + workflow file + environment. |
||
|
|
2a81edc707 | Add workspace peer mode for memory plugins (#3099) | ||
|
|
85b9878be3 |
feat(pi): add OpenViking context takeover (#3081)
Co-authored-by: ZaynJarvis <31875147+ZaynJarvis@users.noreply.github.com> |
||
|
|
b511d91ee5 |
feat(plugins): retrofit OpenCode and pi memory integrations (hybrid MCP, shared lib, 4-harness installer) (#3079)
* feat(plugins): align opencode and pi memory integrations * fix(installer): tolerate missing optional harness CLIs * fix(installer): install opencode file wrapper * fix(opencode): import path for logger initialization * fix(installer): register pi extension after copy * feat(plugins): use MCP for opencode integration * docs: move OpenCode and pi integrations to dedicated pages Promote the OpenCode plugin and pi extension out of the community-plugins page into their own numbered agent-integrations pages (10-opencode, 11-pi, en + zh), update the overview routing table, and refresh the OpenCode image cards to the hybrid MCP architecture (unified installer, openviking_* MCP tools, ovcli.conf credentials). * docs: bare TOS installer commands and reference more examples Drop --harness from TOS-mirror install commands (image cards use the bare installer URL, matching the claude-code/codex cards); add Open WebUI tool server and an examples/ pointer to the community-plugins page (en + zh). * docs: bare TOS installer commands across agent-integration pages TOS-mirror install commands carry no flags anywhere; the installer wizard asks for source, harnesses, language, and credentials. |
||
|
|
a39b60dcae | fix: isolate component release workflows (#2975) | ||
|
|
4d92cd875e |
ci: add cuVS post-merge regression guards (#3065)
Co-authored-by: Yuanqing Zhao <2604121+yuanqingz@users.noreply.github.com> |
||
|
|
f905562534 |
feat(plugins): stdio MCP proxy, remote marketplace install, and type-quota recall for memory plugins (#3039)
* feat: add memory plugin mcp harness
* refactor: vendor shared memory plugin modules
* feat: add type quota recall api
* feat: commit codex memory by token threshold
* feat: capture codex tool calls as parts
* feat: add claude skill experience recall
* chore: fix lint in type quota recall server files
* feat: remote marketplace install with unified openviking naming
- Fix root .claude-plugin/marketplace.json git-subdir discriminator key
("type" -> "source"); claude plugin validate now passes.
- Unified installer gains --source remote|archive|dev: remote registers a
synthesized git-subdir marketplace for Claude Code and a git marketplace
for Codex (no repo clone); archive consumes the slim TOS marketplace zip;
dev registers the checkout's examples/ directory for both harnesses.
- One marketplace name (openviking) across all modes and harnesses, so the
plugin id is always openviking-memory@openviking; installer migrates old
openviking-plugins-local registrations and config.toml sections.
- Restore legacy Claude Code (<2.0) support: claude mcp add (stdio proxy)
plus node-based hooks merge into ~/.claude/settings.json.
- Restore optional statusline registration (fetches sources on opt-in).
- Checkbox TUI harness selection via /dev/tty with non-tty fallback.
- Add examples/.agents/plugins/marketplace.json so Codex directory installs
drop the synthetic symlink marketplace.
- Add shared setup wizard (scripts/setup.mjs) for pure-marketplace installs.
- release-tos.yml: upload memory-plugin-shared/install.sh and build/upload
the memory-plugin-marketplace zip; tos-install.sh prefers it and pins all
fetches to TOS via OPENVIKING_SHARED_INSTALL_URL.
- CI: bash -n on installer scripts; marketplace contract tests updated.
* fix(installer): register Claude remote marketplace as a directory
File-type marketplaces (bare marketplace.json path) make Claude Code derive
a wrong installLocation and 'marketplace update' fails with EISDIR. Write
the synthesized manifest to <dir>/.claude-plugin/marketplace.json and add
the directory instead; compare registered sources by exact match so the
old file registration migrates cleanly.
* feat(statusline): show model name and native-style context percentage
A custom statusLine replaces Claude Code's native line including its context
indicator, so reproduce it from the statusline stdin payload: 'Fable 5 ·
ctx 42%' right after the health segment, with native color thresholds
(<70% dim, 70-89% yellow, >=90% red). Falls back from used_percentage to
remaining_percentage to token counts, and stays visible in bypass mode
since it describes the CC conversation, not OV. Opt out with
OPENVIKING_STATUSLINE_CTX=off. Line cap raised 80 -> 100 visible chars.
* fix(installer): keep checkout progress off stdout in plugin_dir_on_disk
Callers capture the function's stdout, so ensure_checkout's info lines were
concatenated into the statusline command registered in settings.json.
* fix(installer): re-register codex git marketplace instead of upgrading
Codex doesn't expose which --ref a git marketplace was added with, and
'marketplace upgrade' refreshes the old ref — so a URL match must not skip
re-registration or a ref override installs the wrong snapshot. Also remove
the stale pre-unification plugin cache directory during migration.
* fix(installer): include .agents in codex sparse checkout
A plugin-dir-only sparse checkout omits the repo-root marketplace manifest
and fails with 'marketplace root does not contain a supported manifest'.
Adding --sparse .agents keeps the snapshot slim (~7.5M vs full repo).
* feat(installer): bilingual prompts, dist channel selection, and TOS git marketplace for codex
- Interactive language selection (English/中文, --lang, auto-detected from
locale); every user-facing prompt is bilingual.
- Download-source selection (--dist github|tos, prompted interactively):
github keeps the remote marketplaces; tos serves GitHub-blocked regions.
- Credentials step now always shows the current ovcli.conf values (masked
key) and offers keep-or-reconfigure instead of silently reusing them.
- Codex on TOS installs from a TOS-hosted git repo over dumb HTTP and keeps
remote updates (codex plugin marketplace upgrade); falls back to the
archive directory if the repo is unavailable. release-tos.yml builds and
uploads the single-commit bare repo (repack + update-server-info).
- Claude Code on TOS warns that directory marketplaces cannot auto-update.
- tos-install.sh bootstraps shrink to TOS_BASE + --dist tos.
- Docs (READMEs, agent-integrations pages, image cards, en+zh) now all use
the single shared installer and drop the deleted wrapper instructions.
* feat(installer): unify all choice prompts on an arrow-key TUI menu
Language, download source, connection mode, keep-or-reconfigure
credentials, statusline enable/replace, and legacy-mode confirmation all
render as the same single-select menu (arrow keys / digit shortcuts /
enter, radio-style highlight) instead of mixed numbered and y/N prompts.
Falls back to numbered input when /dev/tty can't be drawn on and to the
default choice when non-interactive. Free-text fields (URL, API key) stay
line inputs; the harness picker keeps its checkbox multi-select.
* fix(installer): stop piping plugin lists into grep -q under pipefail
grep -q exits on first match and SIGPIPEs the producer, so with pipefail
the 'codex plugin list | grep -q' check read as a miss every time (codex's
list is long; claude's short list masked the bug). Capture the output and
substring-match in bash instead — validation no longer false-warns.
Also: drop the stdio-proxy line from the Done summary; always offer the
install-source menu unless --dist/--source was given (with a checkout the
menu gains a dev option and defaults to it); surface the Claude-on-TOS
no-auto-update warning at source resolution instead of after install.
* fix: unignore examples/memory-plugin-shared/lib and commit the shared modules
The Python build-artifact 'lib/' gitignore rule silently swallowed the
shared plugin module source, so CI checkouts had only the vendored copies
and sync.test.mjs failed with ENOENT on the source directory.
* fix(recall): budget summary/uri fallbacks and sanitize non-finite scores
max_chars is the recall API's contract, but only full fragments counted
toward it — VikingBot's client-side heuristic, faithfully ported, lets
summary and uri fallbacks render far past the budget (repro: max_chars=100
rendered 548 chars). Every fragment now counts; oversized summaries degrade
to uri fragments and entries that can't even fit a uri line are dropped
(reported via stats.dropped). VikingBot itself is intentionally unchanged.
Also run _sanitize_floats over the /recall response like the neighboring
/find and /search routes, so inf/nan scores return 0.0 instead of a 500.
|
||
|
|
1352096b0c | feat(docs): add page-view + referrer + search tracking via Viewer-Counter (#2982) |