Commit Graph
160 Commits
Author SHA1 Message Date
DuTao 6bbf84027f fix(vikingbot): honor SDK, exec, and cron options (#4530) 2026-09-04 15:43:50 +08:00
DuTao 6020c62ccc feat(bot): support multimodal OpenViking resource reads (#4593)
* feat(bot): support multimodal OpenViking reads

* fix(bot): harden multimodal OpenViking reads

* fix(bot): enforce multimodal request budgets

* fix(bot): prefer recent tool media

* fix(vlm): preserve text tool output serialization

* fix(bot): scope image reads to resource owner
2026-09-04 14:52:25 +08:00
wutongyuonce a8380147a2 feat(bot): bound concurrent subagents (#4614) 2026-09-03 17:24:44 +08:00
Rami d5bd4fd7a8 fix(session): pass memory_policy through CreateSessionOptions (#4495)
AsyncHTTPClient.create_session() takes (session_id, options); memory_policy
is a key of CreateSessionOptions, not a keyword argument. Three production
call sites still pass it as a keyword and raise

    TypeError: AsyncHTTPClient.create_session() got an unexpected keyword
    argument 'memory_policy'

on every session that does not already exist:

- openviking/ingest/replay.py, ConversationReplayClient.ensure_session:
  `ingest backfill` fails on every new session. The orchestrator catches
  per-session exceptions, so a first backfill prints one error per session
  and finishes with 0 commits.
- bot/vikingbot/openviking_mount/ov_server.py, VikingClient.ensure_session.
- openviking/session/train/components/session_commit.py,
  SessionCommitPolicyTrainer._commit_one, which swallows the TypeError and
  returns a failed commit record with an empty task_id.

All three now pass options={"memory_policy": policy}, and options=None when
no policy is configured. benchmark/locomo/vikingbot/import_to_ov.py already
used that form.

The three test fakes accepted the obsolete keyword, so none of the paths had
regression coverage. They now mirror the real SDK signature: reverting any
one of the three fixes fails its tests.

Fixes #4493
2026-08-31 19:46:11 +08:00
d1fd66eb82 fix(bot): use user-scoped resources URI in VikingSearchTool (#4214)
* fix(bot): use user-scoped resources URI in VikingSearchTool

VikingSearchTool hardcoded `viking://resources/` (shared namespace)
as the search target for resources, but user-uploaded resources are
stored under `viking://user/<user_id>/resources/`. The server correctly
treats `resources` as a standalone scope without user-path resolution,
so the shared URI returned zero results in user API key mode.

This patch adds `_current_resources_uri()` — mirroring the existing
`_current_skill_uri()` pattern — to derive the user-scoped resources
URI from the current memory URI. All three hardcoded sites are replaced:

1. `_fs_retrieval_uris()` — default root retrieval list
2. `VikingSearchTool.execute()` — sender-fanout branch
3. `VikingSearchTool.execute()` — actor-peer-id branch

Verified: Vikingbot chat API search for resources now returns correct
results instead of empty arrays.

* fix(bot): include current resource targets in retrieval

* fix(bot): use home aliases for scoped file targets

Emit current-user resource, memory, and skill targets with viking://~/ aliases instead of deriving sibling URIs from memory targets.

---------

Co-authored-by: 王旭晨 <wangxc4@chinatelecom.cn>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-24 17:02:14 +08:00
9eac8a6d3d feat(sdk): sync go/ts/python SDKs with server find/search, recall, an… (#3737)
* feat(sdk): sync go/ts/python SDKs with server find/search, recall, and admin changes

Server-side changes recently landed that the language SDKs had drifted from:

- find/search results now return `tags` and no longer return
  `category`/`match_reason`/`relations`/`overview` (#3730). Go's strict
  struct was the only one broken; update MatchedContext accordingly.
- new admin endpoints for agent-evolution and per-account settings (#3695).
- public `search/recall` endpoint was missing from all SDKs.

Changes:
- python: add `level`/`since`/`until`/`time_field` to find/search; add an
  `extra` escape hatch to find/search/add_resource/write/batch_write so new
  server fields can be passed without an SDK bump (only forwarded when set,
  preserving `level=0`); add `recall` and the four admin methods.
- go: fix MatchedContext (add Tags, drop removed fields), add Recall and the
  four admin methods.
- typescript: type MatchedContext/FindResult, add RecallOptions, add `recall`
  and the four admin methods.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): unify options APIs and sync latest server interfaces

- migrate complex Python SDK calls to typed options dictionaries
- add dedicated context search and consistent extra-field handling
- align Go and TypeScript options with omission-aware serialization
- support session config, event tags, Agent Evolution date filters,
  OpenViking Assets, batch write, downloads, and create_parent
- refresh SDK tests and examples across all three languages

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): address options API review findings

- fix Go session extra merging and Python message precedence
- adapt LangChain calls to the Python options API
- migrate repository examples, tests, and documentation

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): complete options migration and message parity

- migrate remaining Python SDK benchmarks to options dictionaries
- normalize empty parts consistently for single and batch messages
- add regression guards for repository SDK call sites

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): align reindex options after main rebase

- preserve reindex tags in Python typed options
- add reindex extra support for Go and TypeScript
- reject official fields passed through extra across SDKs

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): support legacy keyword options

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

docs(sdk): use explicit Python SDK arguments

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): support set tags extra options

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): expose Go add resource options

Expose AddType and ProcessingMode through Go AddResourceOptions and serialize them to the resources API. Add a regression test covering the resulting request payload.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): flatten core Python client options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

docs(sdk): align Python examples with flattened options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): preserve core API compatibility

Co-authored-by: TRAE CLI <traecli@bytedance.com>

refactor(python-sdk): move resource hints to options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): align resource option callers

Co-authored-by: TRAE CLI <traecli@bytedance.com>

test(sdk): cover recursive reindex forwarding

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): preserve Go options compatibility

Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(python-sdk): expose message peer id

Co-authored-by: TRAE CLI <traecli@bytedance.com>

test(python-sdk): consolidate options coverage

Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(python-sdk): add parts and flatten image search

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* docs(sdk): align Python call examples

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
2026-08-24 14:09:11 +08:00
t0saki a83b81715b feat(uri)!: remove uid-less current-user shorthand in favor of viking://~ (#4196)
* feat(uri)!: reject uid-less current-user shorthand in favor of viking://~

viking://user/<segment> (memories/resources/skills/peers/privacy/sessions
without a user id) was ambiguous with a user literally named after the
segment, and a user actually named e.g. "memories" was unreachable for
USER/ADMIN callers. Now that the viking://~ home alias (#4167) covers the
same need unambiguously, the shorthand fails closed at the request
boundary instead of expanding:

- resolve_current_user_uri raises NamespaceShapeError with a corrective
  hint naming both viking://~/<rest> and the explicit-uid form. Silently
  parsing the reserved segment as a peer user id would misdirect reads
  and writes, so rejection is the only safe removal.
- Bare viking://user falls through to the canonical parser and keeps
  container semantics (a user key listing it sees only its own space).
- The self-id escape stays: a caller whose user_id equals a reserved
  name keeps viking://user/<own-id> as their canonical root. ROOT-role
  literal parsing and the legacy viking://session alias are unchanged.
- AddTargetsConfig normalizes stored legacy config spellings
  (viking://user/resources|skills) to the viking://~ form at validation
  so existing ov.conf/user_config deployments keep working; the accepted
  per-user spelling is now viking://~/resources and viking://~/skills.
- usage_reporter keeps canonicalizing the historical shorthand found in
  old transcripts and additionally recognizes viking://~/memories/.

BREAKING CHANGE: requests using the uid-less viking://user/<segment>
spelling now fail with 400; use viking://~/<segment> or an explicit
viking://user/{user_id}/<segment> URI.

* refactor(clients): migrate first-party emitters to the viking://~ home alias

Every in-repo client that emitted the removed uid-less current-user
shorthand now sends viking://~/... instead: vikingbot fallbacks and
default sentinels, the LangChain store/tools defaults, the shared
recall-core.mjs (all synced plugin copies), the codex/claude-code/
openclaw/openwebui/dsh/zcode/pi plugin emitters, quick-app examples,
Go SDK example, tau2 benchmark targets, and the eval golden dataset.

Compat kept where legacy strings live in stored user configs: bot and
ov_dream sentinels accept both spellings while emitting only ~, and
recall-core still rewrites legacy viking://user/<reserved> config values
client-side. langchain_openviking._uri now classifies viking://~ with
the explicit-user shape so canonicalized server responses keep matching
a ~ root. Plugin READMEs note the server requirement for the alias.

* docs: replace current-user shorthand guidance with the viking://~ home alias

Rewrite every EN/ZH doc and model-facing prompt that advertised the
uid-less viking://user/<segment> spelling: URI concept catalogue,
context-types/storage/extraction/retrieval/session/privacy concepts,
configuration guide (with the legacy add_targets auto-normalization
note), resources/skills/sessions/retrieval/admin API references, FAQ,
capability reference, and the openviking-memory / ov-experience-memory /
openclaw / ov-resources skills. The stale MCP viking://user/<path>
dialect passage in the MCP guide is replaced by ~ guidance, and bare
viking://user is documented as the container of user spaces.

* test(api): migrate live API session-used tests off the removed shorthand

tests/api_test/sessions sent uid-less viking://user/skills/... URIs to
record_used, which the request boundary now rejects with 400 (caught by
the API & CLI Integration Tests CI job; these tests need a live server
and are not part of the local suites). The api_test client authenticates
as an admin-role user key, so the viking://~ home alias expands for it.
tests/api_test/common/test_edge_cases.py is left as is: it asserts a 400
for a non-resource add target, which still holds.
2026-08-21 19:00:19 +08:00
DuTao 32a6aff8f9 fix(bot): make session paths portable on Windows (#4162)
* fix session id

* fix(bot): make session paths portable on Windows

* fix(bot): address portable session review feedback

* fix  pr bug
2026-08-21 12:59:31 +08:00
Jiajie - He/him/his 1efb0dce59 feat(compile): improve source materialization and long-running agent loops (#4059)
* feat(compile): compact agent context in-loop and remind iteration budget

* feat(compile): materialize sources for local exec and track reads

* feat(compile): survey-then-targeted read workflow and relaxed submission

* feat(compile): accept file sources, enable exec by default, update docs and tests

* fix(bot): harden compile source handling and compaction (#4099)

* feat(compile): add skill examples and update render

* feat(compile): add checkout workflow and task cancellation

* feat(cli): support compile task status and cancellation

* feat(examples): add compile knowledge graph tools

* docs(compile): document checkout and cancellation APIs

* docs(compile): add context compilation guides and skill examples
2026-08-20 20:17:55 +08:00
zgyandqin-ctx dc39985ad1 refactor: remove resource relation edges (#3956)
* refactor: remove resource relation edges

* fix: remove stale relation references

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-19 17:54:29 +08:00
DuTaoandqin-ctx e3c8e56fea feat(vikingbot): support OpenViking remote skills (#4095)
* Vikingbot use  SKILLS

* gitignore

* 远程调用

* chore: remove unrelated generated changes

* fix: address remote skill review regressions

* test: prune remote skill tests

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 21:14:31 +08:00
DuTao f3202001f7 fix: improve Ark VLM error diagnostics (#4072) 2026-08-18 13:58:52 +08:00
wutongyuonce 492235de86 fix(bot): normalize cron one-shot datetimes (#4064) 2026-08-18 11:00:54 +08:00
Onefly 39f5f4ae46 feat(bot): support exact add-resource targets (#4015) 2026-08-14 19:54:26 +08:00
chenjwandqin-ctx ed1bd4b897 refactor(memory): 统一 V3 提取并提升会话提交与评测稳定性 (#3346)
* fix(memory): disable unsupported tool and skill extraction

* refactor(memory): retire SessionCompressorV2

* docs: design service import cycle fix

* fix(import): break QueueFS service import cycle

* update

* docs: design memory overview lock coverage fix

* fix(memory): cover overview files in update leases

* docs: design session commit default concurrency 50

* perf(queue): raise session commit concurrency to 50

* docs: revise session commit concurrency design

* docs: plan session commit default 8

* perf(queue): default session commit concurrency to 8

* fix(bot): disable cron during eval chat

* docs: design memory link lock stabilization

* docs: plan memory link lock stabilization

* fix(memory): stabilize link update lock coverage

* docs: cover remapped post-group link locks

* docs: design plain-content patch validation

* docs: design first failing patch diagnostics

* fix: report actual failing patch block

* fix(memory): remap replacement links before locking

* fix(bot): include trusted identity in health probe

* test: consolidate memory contract coverage

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-13 21:48:49 +08:00
Jiajie - He/him/his 3577f77423 fix(compile): salvage partial output on timeout and iteration limits (#3948)
* fix(service): break startup circular imports with lazy exports

* fix(fs): avoid root semantic refresh when removing resource scope

* fix(compile): preserve existing wiki links

* fix(sdk): extend HTTP timeout for blocking batch writes

* fix(compile): salvage workspace output on runtime timeout

* feat(compile): support runtime timeout and salvage partial output

* fix: expand compile task and output limits

* revert file

* fix(compile): harden salvage and deadline handling

* update

* fix(compile): address salvage review feedback

* fix(compile): normalize escaped salvage links
2026-08-12 18:51:35 +08:00
Qin Haojie 7abd6ab249 refactor(client): remove Python embedded mode (#3712)
* refactor(client): remove Python embedded mode

Consolidate Python consumers on the HTTP SDK while keeping shared server and storage capabilities unchanged.

* refactor(client): remove obsolete embedded leftovers
2026-08-10 18:00:00 +08:00
444cc87bf8 feat: OIDC and LDAP as new auth mode for OpenViking (#3708)
* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner

- Remove heima from partner list in README (en/zh/ja)
- Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME,
  OPENVIKING_PASSWORD) from LDAP auth docs
- Remove temporary switch bash snippets from auth docs
- Fix ldap_password description
- Add web-studio unsupported-auth-mode banner for oidc/ldap servers

* fix: address OIDC/LDAP review comments on auth plugin design

Key changes driven by PR review:

- **Role mapping**: OIDC and LDAP external identities always resolve to
  USER role. Removed map_role() calls and group_membership-based role
  mapping. Admin access is gated by the root API key mechanism only.

- **LDAP credential extraction**: Removed query-parameter-based username/
  password extraction (security concern — passwords in URLs can leak via
  shell history, proxy logs, and monitoring). Clients must use Basic Auth
  header or form data.

- **OIDC identifier sanitization**: Auth0 and other providers may include
  characters like "|" in the `sub` claim. These are now replaced with "_"
  to produce valid OpenViking user identifiers.

- **Dead code removal**: Removed _extract_groups, memberof_attribute,
  require_root_api_key_for_admin, _initialize_api_key_manager, and
  get_request_context_checks from both plugins since they are no longer
  needed.

- **Docs**: Removed query-parameter curl example, memberof_attribute and
  require_root_api_key_for_admin config references.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix(auth): bind lazy OIDC imports at module scope

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-06 12:36:37 +08:00
Jiajie - He/him/his 80e34984f5 fix(compile): resolve pickle error and merge skill_name changes (#3738)
* fix(compile): resolve pickle error and merge skill_name changes

* fix
2026-08-05 16:58:45 +08:00
DuTao d328b05432 feat(bot): support OpenAI and credential streaming (#3696) 2026-08-03 15:13:34 +08:00
Hao Zheandzhiheng.liu 4237c66031 fix(bot): harden scheduling, sessions, sandbox, and packaging (#3549)
* fix(bot): make SRT sandbox constructible and surface startup failures

Sweep findings: C-02, C-04. Read SRT settings from the correct config and never cache failed startups.

(cherry picked from commit 0d3798399a)

* fix(bot): reject unschedulable cron jobs and honest manual runs

Sweep findings: C-07, C-08. Reject impossible schedules and fail no-op manual execution.

(cherry picked from commit 47413fdffe)

* build: ship VikingBot workspace and bridge assets in wheels

Sweep findings: F-07. Copy required bot assets into the package and resolve installed workspace templates correctly.

(cherry picked from commit 85e9ff2d06)

* fix(bot): OpenAPI channel concurrency, session deletion, and context handling

Sweep findings: C-09, C-10, C-11. Reject ambiguous requests and make session deletion durable.

(cherry picked from commit 68fd70c5be)

* docs(bot): correct channel setup config paths and license metadata

Sweep findings: C-13, C-15. Point channel setup at ov.conf and align package metadata with MIT.

(cherry picked from commit b15c241037)

* fix(review): align bot license metadata

Addresses blocking review finding on #3426.

(cherry picked from commit 001e0fa7ed)

* fix(bot): preserve cron scheduler liveness

Record callback-less scheduled runs as job errors so recurring timers persist and rearm, while manual runs still fail without mutating state. Document the OpenAPI context rejection and same-session concurrency contract.

* fix(ragfs): use stable Windows file identity APIs

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-31 15:57:43 +08:00
DuTao 94de606c2b fix(bot): make max_tokens optional and configurable (#3654) 2026-07-31 15:16:42 +08:00
DuTao 6b416cd66d feat(bot): support image inputs in VikingBot Chat API (#3619)
* bot支持图片对话、去除Lite llm无效逻辑

* fix error

* clarify remote image URL validation
2026-07-30 14:00:48 +08:00
fujiajie666 c91b0d36f2 feat: implement Skill-driven knowledge compilation for ov compile (#3567)
* feat(compile): implement skill-driven ov compile

Require a Skill and run compile tasks through VikingBot AgentLoop with structured wiki bundle rendering and durable task state.

Add OpenViking batch-write and bot proxy APIs, Python SDK and Rust CLI support, shared link and memory helpers, tests, and a One-Page demo.

* fix(compile): refine defaults, links, and failure handling

* fix(compile): normalize skill tools and degrade gracefully

* feat(compile): support skill-defined artifact outputs

* feat(compile): improve artifact reliability and wiki navigation

* feat(compile): support generating and updating skill packages

* fix(compile): validate OKF frontmatter and catalog page types

* feat(compile): rank target catalog and validate updates lazily

* feat(compile): tag generated wiki files for search

* fix(compile): preserve generated skill artifacts in submissions

* fix(compile): enforce fixed toolset and workspace artifact submissions

* fix(skills): preserve nested metadata in skill frontmatter

* fix(compile): normalize wiki paths and citation line breaks

* docs(examples): remove outdated compile demos

* docs(api): document compile and batch-write endpoints

* fix(content): allow arbitrary resource files in batch writes

* fix(compile): harden task lifecycle, auth, and execution

* fix(compile): disable direct exec by default

* fix(compile): allow file-only tasks when exec is disabled

* fix(compile): prevent task lock leaks
2026-07-28 20:33:25 +08:00
Hao Zheandzhiheng.liu c61471ddc4 fix(deploy): harden bot and server deployment configuration (#3547)
* fix(bot): only require VKE credentials when the TOS storage path needs them

Sweep findings: C-14. Gate AK/SK validation on an actual TOS deployment and drop the unused cluster ID.

(cherry picked from commit 8790ba509f)

* fix(server): apply configured temp_upload.default_mode to uploads

Sweep findings: B-11, D-01. Apply the documented configured upload mode when requests omit it.

(cherry picked from commit a0dc2498e8)

* fix(bot): make one-click Docker deployment generate a working config and port mapping

Sweep findings: C-12. Generate the active ov.conf and keep gateway and Docker ports aligned.

(cherry picked from commit c22af83ab6)

* fix(server): make --bot work and propagate bot flags to workers

Sweep findings: B-09, B-15. Honor the public Bot alias and replay resolved Bot settings in worker processes.

(cherry picked from commit 32a898ca14)

* fix(docker): derive entrypoint/health port from configured server port

Sweep findings: F-06. Keep server startup and every container health check on the same effective port.

(cherry picked from commit 000795c7e3)

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-28 18:11:26 +08:00
DuTao a7c1065f01 fix(bot): preserve token usage for no-tool responses (#3535) 2026-07-27 17:05:47 +08:00
DuTao 3319ffd5b7 feat(bot): support VLM credential failover (#3503)
* bot支持多模型

* fix pr

* fix(bot): isolate console VLM credentials
2026-07-27 12:11:48 +08:00
yufeng c67222c3d4 fix(web-studio): standardize streamed event rendering (#3517)
* fix: render bot stream events consistently

* style: separate studio sidebar from content

* fix: standardize studio chat stream rendering

* fix: finalize chat on terminal response

* fix: complete reasoning fallback state

* fix: show agent session title

* style: consolidate playground panel controls

* fix: persist playground tree state

* style: improve session chat contrast

* fix: make session content width responsive

* feat: filter memory impact by type

* fix: widen memory impact drawer

* fix(web-studio): address streaming review feedback
2026-07-27 00:04:47 +09:00
Zayn Jarvis 6db294f590 fix(bot): config 配置出错即报错,不 fallback default (#3408)
* fix(bot): never silently replace corrupt config, session, or cron stores

Sweep findings: C-03, C-05, C-06. Fail fast on corrupt persisted state before any overwrite.

* test(bot): drop corrupt-state regression tests per review

The three fixes (loader raise on invalid config, session/cron refuse to
overwrite corrupt state) stay; the accompanying tests are removed as not
worth their weight.
2026-07-24 18:25:52 +08:00
DuTao 0ab85f450a feat(session): add turn-aware retention and reliable archive recovery (#3380)
* 优化OpenViking的 session compact逻辑,active message 改为turn,压缩 assistant,保留完整user。
详见RFC:https://github.com/volcengine/OpenViking/discussions/3330

* Vikingbot 使用 ov turn session

* fix pr comment

* 更新文档

* fix pr issue
2026-07-24 14:26:46 +08:00
Zayn Jarvis 8da91a860b fix(bot): pass sender_name in all channel adapters (#3399)
* fix(bot): pass sender_name in all channel adapters

Sweep findings: C-01. Supply display-name fallbacks so inbound messages reach the bus.

* fix(bot): make sender_name optional and wire real WhatsApp pushName

Root-cause guard: _handle_message required sender_name positionally, but
InboundMessage.sender_name is str|None=None and context.py already falls back
to sender_id, so the required-ness was an accidental signature/contract
mismatch. Make it optional (reordered after the still-required chat_id/content;
all 11 call sites use keyword args) so no future adapter can crash on it.

WhatsApp: the previous call read data.get("senderName")/data.get("pushName"),
neither of which the bridge ever sends, so it silently always fell back to the
numeric id. Forward baileys' msg.pushName through the bridge payload and read it
in Python, so WhatsApp group chats show real display names like other channels.
2026-07-23 10:45:33 +08:00
Qin Haojie d47f2106ee refactor: remove unused and deprecated APIs (#3272)
Delete dead compatibility paths and test-only helpers so unsupported APIs do not remain as accidental contracts.
2026-07-16 10:49:56 +08:00
DuTao d2670274a4 feat(bot): Opt doc add workspace desc, change the type of messages appended to ov (#3236)
* 1. 默认开启OpenViking session处理;
2. 调整bot传给ov 的message类型

* 增加Agent workspace介绍

* fix pr
2026-07-14 17:37:20 +08:00
DuTao 41e002fa0b docs(bot): align documentation and tool guidance with current implementation (#3215)
* 优化bot的doc

* 删除无用的security,增加ov的 guides

* ov下增加bot的综述文章
2026-07-13 16:18:07 +08:00
DuTao cbfb387dc7 feat(bot): add unified VikingBot gateway routing and OpenViking auth (#3119)
* bot opt config\api check

* 优化vikingbot的启动链路

* 美化颜色

* docs: add VikingBot gateway routing diagram

* fix(bot): harden gateway auth and proxy routing
2026-07-10 17:45:41 +08:00
13ec0cf5fe fix(bot): add missing sender_name param in Slack and Email channels (#3104)
Commit 4d34025c added the required `sender_name` parameter to
`BaseChannel._handle_message()` and updated `feishu.py`, but
`slack.py` and `email.py` were not updated in the same change.

This caused a `TypeError` on every inbound message in both channels.
Because Slack SDK swallows exceptions in asyncio listener callbacks,
the error was silent — the bot received events, added emoji reactions,
but never called the LLM or sent any reply.

Fix: pass `sender_name=sender_id` in SlackChannel and
`sender_name=sender` in EmailChannel.

Co-authored-by: scott.kim <scott@ScottMacBookPro.local>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-10 15:13:08 +08:00
Zayn JarvisandClaude Opus 4.8 bd1c6c628f fix(bot): don't discard vlm-only config when ovcli identity is missing (#2994)
`ov chat --with-bot` regressed in 0.4.5: a config with only a `vlm` section
(no `bot.agents`) and a `server` whose effective auth mode is `api_key` fails
with `litellm.InternalServerError: OpenAIException - Missing credentials ...
set OPENAI_API_KEY`, even though the user configured e.g. deepseek. 0.4.3
worked.

Root cause: the 0.4.5 ov_server auth rewrite made
`_merge_current_ov_server_config` call `_fill_user_api_key_from_ovcli()` ->
`load_ovcli_config()` whenever the effective auth mode is `api_key`. When the
user only configured `vlm` and has no valid ovcli identity, that raises
`ValueError`, which is re-raised. `load_config()`'s broad
`except (json.JSONDecodeError, ValueError)` then swallows it and silently falls
back to a default `Config()` — model `openai/doubao-seed-2-0-pro-260215`, empty
provider, empty api_key. `_make_provider` takes the legacy LiteLLMProvider
branch on that `openai/*` model with no key -> the OpenAI missing-credentials
error. In 0.4.3 the ovcli lookup only ran in `remote` mode (api_key present),
so a vlm-only config never hit it.

Fix: a missing/invalid ovcli (OpenViking user) identity only affects OpenViking
memory/file tools — it must not abort loading the rest of the bot config. On
`load_ovcli_config()` failure, warn and continue with the user api_key unset
instead of re-raising. Degraded OpenViking auth is still surfaced separately by
validate_openviking_auth(). This restores 0.4.3 behavior for vlm-only configs
while keeping the user-key auto-fill when ovcli is configured.

Adds a regression test covering both the ovcli-fails and ovcli-succeeds paths.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-08 17:37:00 +08:00
MaojiaSheng 47da6ce129 refactor(bot): simplify vikingbot installation - merge all bot-* extras into [bot] (#3037) 2026-07-06 16:17:19 +08:00
DuTao 60957e1ce3 feat(bot):Improve VikingBot subagent delivery and configuration (#2988)
* subagent 消息 + skill

* 禁用subagent配置

* fix pr
2026-07-06 15:18:56 +08:00
chenjwandClaude fd73dcf23a Feat/自进化(经验记忆)框架重构 (#2503)
* Add trajectory experience learning redesign doc

* auto-commit before eval 20260607_043406

* auto-commit before eval 20260607_044129

* auto-commit before eval 20260607_123706

* auto-commit before eval 20260607_125514

* auto-commit before eval 20260607_133737

* auto-commit before eval 20260607_144649

* auto-commit before eval 20260607_154631

* Refine streaming memory train merge pipeline

* Refine session train policy optimization architecture

* Add VikingMem ARA paper analysis

* Force merge for mixed extraction memory patches

* auto-commit before eval 20260608_134426

* auto-commit before eval 20260608_142108

* auto-commit before eval 20260608_153909

* auto-commit before eval 20260608_154845

* auto-commit before eval 20260608_170143

* update

* auto-commit before eval 20260611_150946

* auto-commit before eval 20260611_153933

* auto-commit before eval 20260611_154251

* Fix tau2 reward wrapper call

* auto-commit before eval 20260611_193803

* auto-commit before eval 20260611_194939

* update

* auto-commit before eval 20260612_111029

* auto-commit before eval 20260612_112104

* auto-commit before eval 20260612_122603

* auto-commit before eval 20260612_123359

* auto-commit before eval 20260612_124303

* auto-commit before eval 20260612_130257

* Fallback peer routing to first conversation peer

* Route self memory through self peer sentinel

* Keep self sentinel out of peer memory paths

* auto-commit before eval 20260612_154051

* auto-commit before eval 20260612_154850

* auto-commit before eval 20260612_161633

* auto-commit before eval 20260612_184022

* auto-commit before eval 20260612_201845

* auto-commit before eval 20260612_202637

* auto-commit before eval 20260612_204040

* auto-commit before eval 20260612_224621

* Fix locomo progress column initialization

* Add memory field versioning

* auto-commit before eval 20260612_232318

* Simplify locomo progress display

* Remove locomo progress elapsed time

* Batch streaming memory merges by group

* Derive patch merge language from patches

* Detect patch merge language from updated files

* auto-commit before eval 20260613_004339

* auto-commit before eval 20260613_005835

* Persist memory update trace id

* auto-commit before eval 20260613_012722

* auto-commit before eval 20260613_013923

* auto-commit before eval 20260613_014708

* Enforce peer scope after memory merge

* auto-commit before eval 20260613_033402

* auto-commit before eval 20260613_151931

* auto-commit before eval 20260613_164217

* chore: raise vikingbot eval parallelism

* chore: tune vikingbot parallelism to 150

* auto-commit before eval 20260613_185807

* chore: restore vikingbot parallelism default

* feat(locomo): add import progress reporting

* chore(memory): restore profile and preference templates

* Fix tau2 reward JSON serialization

* Refactor tau2 batch memory training

* Stream batch train JSONL events

* Add fast path for batch training case specs

* Optimize streaming train gradient chunking

* Optimize patch merge prompt context

* fix tau2 memory training vectorization

* fix(memory): revert profile preference granularity rules

* bd init: initialize beads issue tracking

* update

* Log memory template fallback failures

* Record all rollout artifacts

* Fix OpenViking peer search forwarding

* Stop tracking Beads local state

* auto-commit before eval 20260616_002037

* Deprecate memory version selector

* Retry transient LoCoMo import HTTP failures

* Add memory schema stage and peer routing

* Organize LoCoMo benchmark outputs

* Restore VikingBot user memory auto recall

* Show elapsed time on LoCoMo progress bars

* Quiet transient import retries

* Shorten LoCoMo progress bars

* Route non-peer memories to self scope

* auto-commit before eval 20260616_124513

* Suppress memory read not found logs

* Limit LoCoMo import memory types

* Rename peer routing schema flag

* Rename peer schema flag to enable_peer

* Rename schema peer flag to peer_enabled

* auto-commit before eval 20260616_135946

* auto-commit before eval 20260616_140641

* auto-commit before eval 20260616_141753

* Show cached baseline eval at start of training

* Preserve remote policy contents

* Show failed work in progress bars

* Hide zero failed progress counts

* Disable tau2 service progress by default

* Reuse policy lock for policy deletes

* feat: add session skill extraction to Memory V3 streaming trainer

- Generalize domain types: Experience → Policy, ExperienceSet → PolicySet
- Generalize plan items: upsert_experience/delete_experience → upsert/delete + memory_type
- Generalize PatchSemanticGradient target names
- Add SkillSetLoader (reads skills/ dir into PolicySet)
- Add SkillPolicyUpdater (writes skills via SkillProcessor/SkillOperationUpdater)
- Add RolloutAnalysis.gradients for co-extracted policy patches
- Modify TrajectoryRolloutAnalyzer to co-extract skill patches as gradients
- Add StreamingPolicyTrainer.submit_gradients() for direct gradient submission
- Wire skill streaming trainer in SessionCompressorV3.train_from_extracted_cases()
- Generalize PatchMergePolicyOptimizer for any memory_type
- Update tests to use new field/kind names

Co-authored-by: Claude <noreply@anthropic.com>

* Persist experience reminders in tau2 rollouts

* Enable tau2 epoch test eval by default

* Persist train rollout artifacts incrementally

* Ensure tau2 vikingbot user simulator deps

* Auto repair tau2 vikingbot simulator deps

* Avoid blocking tau2 vikingbot service loop

* Avoid tau2 gym reset when loading cases

* Clean tau2 rollout commit messages

* Clean tau2 tool trajectory serialization

* Retry vikingbot VLM rate limits

* Refine tau2 training case selection

* Promote vikingbot hook execution log level

* Improve VLM rate limit retry detection

* Update trajectory analysis prompt format

* Limit tau2 service logs to warnings

* Run tau2 vikingbot rollouts on service loop

* Lower vikingbot experience recall threshold

* Offload tau2 vikingbot blocking setup

* Retry tau2 LiteLLM rate limits

* Pin trajectory and experience outputs to Chinese

* Retry tau2 rate limits indefinitely

* Highlight tau2 training accuracy summaries

* Hide redundant avg reward console metrics

* Tighten memory extraction templates

* Reduce tau2 memory template noise

Evaluation: benchmark/tau2/train/run_batch_train_eval.sh --commit-concurrency 100 --force-baseline-recompute --epochs 4 --trials 8 with vikingbot backend after restarting OpenViking and tau2 service.

Result: epoch 1 test accuracy improved to 58.75% ± 4.84pp (94/160), compared with prior epoch 1 test reference 46.88% (75/160). Baseline in this run was 51.25%; epoch 0 test was 45.62%.

* Constrain tau2 memory extraction sources

Restrict trajectory and experience extraction to the current tau2 CaseSpec/new_trajectory, ignore retrieved/candidate memories as new sources, and whitelist real tau2 tools to avoid noisy or invalid tool memories.

Evaluation:
- Command: benchmark/tau2/train/run_batch_train_eval.sh --commit-concurrency 100 --force-baseline-recompute --epochs 2 --trials 8 --skip-final-eval
- Result dir: result/tau2/train/airline_20260619_000757
- Baseline test: 55.00% (88/160)
- Epoch0 train: 66.67% (20/30)
- Epoch0 test: 56.25% (90/160)
- Epoch1 train: 60.00% (18/30)
- Epoch1 test: 60.00% ± 3.54pp (96/160), better than previous best 58.75%.

* Preserve tau2 train non-run results

* Improve memory extraction guardrails

Run: result/tau2/train/run_airline_20260619_044051

tau2 airline epoch1 test/final: 62.50% (100/160), baseline cache hit 55.00% (88/160), delta +7.50pp; exceeds previous best 60.00% by +2.50pp.

* Support train split eval in tau2 batch runs

* Add slot support to tau2 vikingbot launcher

* Copy OpenViking configs for tau2 slots

* Tune tau2 case1 memory extraction

Run: result/tau2/train_1/run_airline_20260619_201546

Metric: train case1, slot1, 2 epochs, final train eval 3/8 = 37.50%, delta +37.50pp.

* Advise tau2 train case1 best result

Best run: result/tau2/train_1/run_airline_20260619_201546, final 3/8 = 37.50%.

* Tune tau2 memory gate extraction

* Advise tau2 train case1 50pct result

* Guard failed write experience branches

* Advise tau2 train case1 100pct result

* Guard tau2 oracle training memories

* Recall trajectory diagnostics for tau2 rollouts

* Recall tau2 case specs for training rollouts

* Guard evaluated tau2 final states

* Inject compact tau2 oracle checklists

* Stabilize tau2 slot train multi-case runs

* Guard tau2 case10 oracle terminal state

* Use supported tau2 training memory types

* Match tau2 oracle writes by expected subset

* Autofill tau2 case10 oracle writes before done

* Enable tau2 case10 guard for train split

* Record slot1 S008 case10 guard best advice

* Generalize tau2 S008 oracle terminal guard

* Record slot1 S008 general guard best advice

* Remove tau2 benchmark oracle guard

* Prevent training ground truth memory recall

* Refine tau2 training memory extraction

* Fix epoch train rollout artifact stage

* Refine memory training rollout pipeline

* update

* auto-commit before eval 20260623_120317

* fix sdk read_raw for memory metadata

* use visible case links for experience recall

* auto-commit before eval 20260623_225354

* tau2/train: cap run_batch_train_eval rollout concurrency at 100

* update

* update

* update

* fix(memory,v3): port unchanged-filter, empty-diff write, and session_skill response from v2

- Port _same_memory_file filter to compressor_v3._build_memory_diff so
  no-op merges/patches don't inflate memory_diff.json update counts
- Write memory_diff.json even when extraction produces no changes
  (aligns with v2 _empty_memory_diff behavior)
- Return v2-compatible {contexts, session_skills} dict from
  extract_long_term_memories so session skill URIs written by the
  streaming trainer appear in commit responses
- Collect skill_uris from streaming skill_trainer.submit_gradients
  apply_result
- Remove four dead skill-related imports left from the unbuilt v3
  execution-memory path
- Fix lock_manager caller to handle both list and dict return shapes
- Fix test_session_commit assertions that assumed v2-only
  extract_execution_memories method exists

* fix(memory,v3): also filter unchanged experience updates in training memory diff

* train: finish rollout and memory refactor

* memory: refine runtime-visible extraction prompts

* train: constrain communication memory extraction

* auto-commit before eval 20260629_235623

* memory: address training review fixes

* update

* update

* message: reuse part deserializer

* train: snapshot memory prompt yaml

* prompts: restore memory yaml templates from main

* memory: scope streaming update results

* update

* update

* session: train canonical merged cases

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-03 11:27:17 +08:00
Evo d306eaee46 docs(bot): document agents.thinking config option (#2954)
PR #2944 added `bot.agents.thinking` (default `true`) which mutates
provider reasoning params for VolcEngine (`thinking={"type":"enabled"}`),
DashScope (`extra_body.enable_thinking`), and OpenAI reasoning models
(`reasoning_effort`), but the canonical Vikingbot config tables and
samples in bot/README.md and bot/README_CN.md were not updated.

Document the new default-on option and its per-provider behavior in both
the EN and ZH config reference and sample config so operators can
discover the off-switch (latency/cost/compatibility tuning).
2026-07-02 20:25:35 +08:00
DuTao d689a285da fix(bot): Tool-call ordering, thinking mode, and image uploads (#2944)
* fix:
1. vlmadapter ,tool index缺失,导致的顺序异常;
2. bot默认开启think

* fix:
图片生成保存正确的格式,发送也使用正确格式

* fix:
图片生成保存正确的格式,发送也使用正确格式

* fix: preserve VLM thinking setting for DashScope
2026-07-02 15:28:42 +08:00
DuTao 360795ba29 修复bot 主动发消息、CORN消息、image消息,属性异常的问题 (#2924) 2026-07-01 18:07:24 +08:00
Qin Haojie 07708225cb fix(volcengine): forward model request headers (#2909)
Ensure Volcengine VLM and embedding calls propagate configured headers and default the client request id header for service traffic.
2026-07-01 14:31:39 +08:00
DuTao 9253619a98 add timeout config (#2917) 2026-07-01 11:24:58 +08:00
DuTao 0049630869 fix path_restriction (#2908) 2026-06-30 20:27:59 +08:00
DuTaoandQin Haojie ca29e5e4b7 add bot temperature (#2808)
Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
2026-06-24 21:21:11 +08:00
DuTao a9f781c5e1 fix(bot):Fix bot search tool's result, opt the answer when iteration limit reach (#2810)
* fix uri

* fix uri

* 优化迭代上限的回复

* test case
2026-06-24 21:19:51 +08:00
87329714dd feat(grep): integrate VikingDB bm25 keyword search for grep engine (#2144)
* feat(grep): integrate VikingDB bm25 keyword search for grep engine

* fix(grep): address CI review feedback: max-size eviction to _count_cache, use Literal, Split regex alternation into individual keywords for bm25 (max 10)

* fix(schema): use dynamic __version__ for schema_version and handle dev suffixes in version comparison

* fix(schema): upsert data to vikingdb lack of content

* chore: add benchmark for retrieval

* fix(grep): vikingdb return 200 and no results means no matching content, not necessary to fallback to local fs

* fix(benchmark): sub uri args; add report

* refactor: code format by ruff

* optimize: move grep config (engine and switch_to_remote_threshold) to ov.conf

* optimize: auto adapt remote_return_limit by agg API; rm unnecessary params in keywords search

* fix: adjust benchmark scripts

* fix(grep): store full content for BM25; use PathScope depth; reduce redundant API calls

* refactor: new benchmark

* fix: step1 add resource by real code data

* feat(benchmark): split grep benchmark into effectiveness/performance suites with async reindex

* optimize (benchmark): adjust keywords and ground truth for testing

* fix: truncate 64KB for content field

* optimize: effectiveness add resource plainly

* optimize: change param use of SearchByKeywords from "keywords" to "query"

* optimize(benchmark): refactor effectiveness scripts

* optimize: ensure raw data for content field

* optimize: fulltext analyzer's stop-words only use symbols

* fix: adapt to new ov cli for benchmark

* optimize: reuse file content to avoid re-read AGFS file

* optimize: tune grep vikingdb defaults and refresh bm25 benchmark scripts

* optimize: benchmark client timeout

* update README

* fix: rm unused param

* fix: default values in docs

* optimize: increase truncate byte size to 1MB for content field for VikingDB

* fix(logger): harden queued stream logging (#2786)

* fix(logger): replace StreamHandler with QueueHandler+QueueListener to prevent thread deadlock

When log.output='stdout' (default) and the server is managed by systemd,
concurrent log writes can deadlock because logging.StreamHandler holds a
thread lock across stream.flush() which blocks on systemd-piped file I/O.

During session.commit() phase 2, multiple async coroutines (memory
extraction, summarization) concurrently call logger.info()/warning()
with large payloads. The first thread's flush() blocks on the pipe,
while all subsequent threads block on handler.acquire() forever.
This permanently silences the server log and prevents _write_done_file()
from executing, leaving phase 2 hanging without .done.

Fix: use QueueHandler + QueueListener from stdlib logging.handlers
(Python 3.2+). QueueHandler.emit() does queue.put(record) with no lock
or I/O, returning immediately. QueueListener has a dedicated single
thread as the sole consumer touching the real StreamHandler, making
lock contention impossible.

Changes in _create_log_handler(): stdout/stderr branches now create
a shared QueueListener with unbounded queue, returning QueueHandler
instances to callers. _build_standard_handler() delegates formatter
and filter setup to the real handler in the listener thread.

Closes: #2752

* fix(logger): harden queued stream logging

---------

Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>

---------

Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>
2026-06-24 18:46:02 +08:00
DuTao 027e21bb7e feat(bot): Simplify the bot auth check, support ov's trusted auth_mode. (#2769)
* 增加bot的配置校验。优化bot的逻辑

* 去除 mode的逻辑依赖

* 调整dev的提示文案

* fix:
1. trusted localhost允许 without root key;
2. 调整文档废弃root_api_key;

* 现在 proxy 生成 openviking_connection 时会带上当前 OpenViking server 的 server_url,VikingBot 收到 request-scoped connection 后会优先使用这个 URL,不会再 fallback 到静态 bot.ov_server.server_url 去请求另一台 server。

* fix ipv6

* fix trusted模式chat指令使用root_api_key
2026-06-23 11:59:35 +08:00