Commit Graph
55 Commits
Author SHA1 Message Date
baojun-zhang 94ff079f51 feat(storage): add pagination capability for ls/tree. support http-api/cli/python-sdk/go-sdk/typescript-sdk/mcp && CLI/MCP support ls sort capability (#4698)
* feat(storage): add pagination capability for ls/tree. support http-api/cli/python-sdk/go-sdk/typescript-sdk/mcp &&  CLI/MCP support ls sort capability

* feat(storage): add pagination capability for ls/tree.

* feat(storage): add go/typescript sdk pagination capability for ls/tree.
2026-09-07 11:50:15 +08:00
Jiahui ZhouandTRAE CLI 4f9840eca7 feat(tags): support tagged write and filesystem filtering (#4457)
Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-09-01 16:22:35 +08:00
hylinandhylin 507a4f5252 fix(sdk): preserve unavailable error details (#4534)
Co-authored-by: hylin <linhongyu510@users.noreply.github.com>
2026-08-31 20:20:17 +08:00
50228a2e70 feat: support vector record IDs across filesystem APIs (#4442)
* feat: support vector record IDs across filesystem APIs

- centralize deterministic vector record ID generation and migration handling
- allow stat and read to resolve file IDs with actionable missing-index diagnostics
- add selectable filesystem fields and script-friendly ls, tree, and glob output
- preserve complete IDs in simple output and honor tree --simple without fields
- restrict Python SDK ID passthrough to supported read-only endpoints
- preserve explicit empty glob extra_fields for metadata responses
- retain the dedicated Codex OAuth doctor diagnostic path
- document the public API behavior and add CLI, SDK, storage, and server regressions

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* fix(cli): preserve full record IDs in field tables

Render filesystem record IDs without abbreviation in both table and simple field modes so the values can be passed directly to stat and read. Add a regression test for normal table rendering.

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: Maojia Sheng <shengmaojia@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-31 14:32:40 +08:00
Qin Haojie e357af6ac7 feat(acl): 增加资源 ACL、用户组授权与向量权限过滤 (#3213)
* feat(acl): add resource access control

Persist direct and inherited ACL fields in context records so filesystem operations and vector retrieval enforce the same permissions.

* docs(acl): align behavior documentation

* feat(acl): 支持用户组授权

* refactor(acl): 收敛权限更新并补齐异步身份

确保 ACL 更新结果与锁内状态一致,移动失败可恢复向量 URI,并让后台解析沿用发起请求的用户组身份。精简重复实现和低价值测试。

* refactor(acl): 仅在共享资源区启用授权

个人资源保持 owner 私有,分享通过移动到共享区完成;跨区移动按目标 scope 继承或清空 ACL,并将向量权限过滤限制在共享区。

* chore(acl): 移除无关解析器清理

恢复 telemetry 空上下文和 import 的基线写法,仅保留 ACL 用户组身份传递。

* fix(acl): 收紧权限读取与过滤分页

ACL 元数据读取失败时终止权限判断,并确保 grep 的 node_limit 作用于权限过滤后的可见结果。

* refactor(acl): 收敛测试与检索取数逻辑

删除重复、时序绑定和实现细节测试,并撤销非必要的 grep 循环扩容。保留用例只覆盖独立的安全、一致性和兼容性故障。

* refactor(acl): 统一资源操作鉴权

将 write、delete 和 reindex 收敛到 read/write/manage 能力检查,并修复 add target 权限校验未等待的问题。

* refactor(acl): 枚举化权限能力

用 AclAction 和 AclLevel 约束内部权限分支,拒绝裸字符串 action,并保持 API 与存储字符串格式兼容。

* fix(acl): route reindex through unified authorization

* refactor(uri): remove redundant user content root helper

* fix(acl): align resource browsing and ingestion permissions

* test(acl): consolidate ACL contract coverage

* feat(acl): grant creators manager access

* fix(acl): scope creator grants to controlled trees

* fix(acl): isolate add-resource parent refresh authorization

* feat(acl): enforce snapshot permissions

* fix(acl): preserve content write permission errors

* feat(acl): add opt-in protection for new shared content

* feat(cli): configure automatic ACL protection

* refactor(acl): simplify authorization flow

* fix(acl): allow write permission for file move and delete

* refactor(acl): simplify group and permission semantics

* fix(acl): allow write access for snapshot file deletion

* fix(acl): preserve user-scoped reindex access

* refactor(acl): compact indexed principal grants

Store one highest-permission token per principal so in-memory authorization and vector filtering share the same ACL representation.

* fix(acl): preserve background task identity

* fix(acl): bypass acl for watch refresh
2026-08-28 17:22:55 +08:00
dingbenandTRAE CLI 953d0bb9f1 feat(admin): support wildcard matching in list-accounts and list-users (#4409)
* feat(admin): support wildcard matching in list-accounts and list-users

Add fnmatch-based wildcard filtering to the admin list-accounts operation,
matching the existing semantics of list-users (case-sensitive, substring
via *x*). Both operations now accept an optional name filter and limit.

- server: get_accounts(name_filter, limit) using fnmatch; list_accounts
  router exposes `name` and `limit` query params
- ov_cli: add --name/--limit flags to list-accounts
- SDKs (python/go/typescript): thread filter params through admin clients
- docs: document the new filtering params for the admin API

Also fix two pre-existing, unrelated test failures (test-only):
- test_legacy_cleanup_removes_only_legacy_namespaces: update to the
  per-agent-id cleanup contract introduced in 0102a48c
- test_remove_user: raise _wait_for_task budget to accommodate the
  ~2s AGFS recursive cleanup during user deletion

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor(admin): drop limit param from list-accounts, keep name filter

The account list is consumed by callers that fetch the full set and scan
it (vikingbot root-key namespace-policy lookup, config-wizard account
menu, migration registry checks). Defaulting the HTTP route to limit=100
would silently truncate those consumers once an install has >100
accounts. The original requirement was only wildcard name matching, so
remove the limit param from the account path across route, CLI, SDKs and
manager, keeping only the fnmatch `name` filter. list-users is unchanged
(its limit predates this work and its consumers pass explicit large caps).

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(admin): add opt-in limit/page pagination to list-accounts and list-users

Both endpoints now return results in lexicographic order of ID and accept
optional limit/page query params. Pagination is opt-in: omitting limit
returns the full set, so internal full-set consumers stay unaffected.

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-28 11:26:23 +08:00
zgy 80f4ba1412 fix(sdk): align compat client with SDK behavior (#4316)
* fix(sdk): normalize compat message parts

* fix(sdk): inherit normalized add_message in compat client

* fix(sdk): reuse base HTTP initialization in compat client
2026-08-25 21:08:54 +08:00
Jiahui ZhouandTRAE CLI 5a154317cd feat(retrieval): inline matched content on demand (#4261)
Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-24 20:40:44 +08:00
9eac8a6d3d feat(sdk): sync go/ts/python SDKs with server find/search, recall, an… (#3737)
* feat(sdk): sync go/ts/python SDKs with server find/search, recall, and admin changes

Server-side changes recently landed that the language SDKs had drifted from:

- find/search results now return `tags` and no longer return
  `category`/`match_reason`/`relations`/`overview` (#3730). Go's strict
  struct was the only one broken; update MatchedContext accordingly.
- new admin endpoints for agent-evolution and per-account settings (#3695).
- public `search/recall` endpoint was missing from all SDKs.

Changes:
- python: add `level`/`since`/`until`/`time_field` to find/search; add an
  `extra` escape hatch to find/search/add_resource/write/batch_write so new
  server fields can be passed without an SDK bump (only forwarded when set,
  preserving `level=0`); add `recall` and the four admin methods.
- go: fix MatchedContext (add Tags, drop removed fields), add Recall and the
  four admin methods.
- typescript: type MatchedContext/FindResult, add RecallOptions, add `recall`
  and the four admin methods.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): unify options APIs and sync latest server interfaces

- migrate complex Python SDK calls to typed options dictionaries
- add dedicated context search and consistent extra-field handling
- align Go and TypeScript options with omission-aware serialization
- support session config, event tags, Agent Evolution date filters,
  OpenViking Assets, batch write, downloads, and create_parent
- refresh SDK tests and examples across all three languages

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): address options API review findings

- fix Go session extra merging and Python message precedence
- adapt LangChain calls to the Python options API
- migrate repository examples, tests, and documentation

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): complete options migration and message parity

- migrate remaining Python SDK benchmarks to options dictionaries
- normalize empty parts consistently for single and batch messages
- add regression guards for repository SDK call sites

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): align reindex options after main rebase

- preserve reindex tags in Python typed options
- add reindex extra support for Go and TypeScript
- reject official fields passed through extra across SDKs

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): support legacy keyword options

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

docs(sdk): use explicit Python SDK arguments

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): support set tags extra options

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): expose Go add resource options

Expose AddType and ProcessingMode through Go AddResourceOptions and serialize them to the resources API. Add a regression test covering the resulting request payload.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(sdk): flatten core Python client options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

docs(sdk): align Python examples with flattened options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): preserve core API compatibility

Co-authored-by: TRAE CLI <traecli@bytedance.com>

refactor(python-sdk): move resource hints to options

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): align resource option callers

Co-authored-by: TRAE CLI <traecli@bytedance.com>

test(sdk): cover recursive reindex forwarding

Co-authored-by: TRAE CLI <traecli@bytedance.com>

fix(sdk): preserve Go options compatibility

Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(python-sdk): expose message peer id

Co-authored-by: TRAE CLI <traecli@bytedance.com>

test(python-sdk): consolidate options coverage

Co-authored-by: TRAE CLI <traecli@bytedance.com>

feat(python-sdk): add parts and flatten image search

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* docs(sdk): align Python call examples

Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
2026-08-24 14:09:11 +08:00
t0saki a83b81715b feat(uri)!: remove uid-less current-user shorthand in favor of viking://~ (#4196)
* feat(uri)!: reject uid-less current-user shorthand in favor of viking://~

viking://user/<segment> (memories/resources/skills/peers/privacy/sessions
without a user id) was ambiguous with a user literally named after the
segment, and a user actually named e.g. "memories" was unreachable for
USER/ADMIN callers. Now that the viking://~ home alias (#4167) covers the
same need unambiguously, the shorthand fails closed at the request
boundary instead of expanding:

- resolve_current_user_uri raises NamespaceShapeError with a corrective
  hint naming both viking://~/<rest> and the explicit-uid form. Silently
  parsing the reserved segment as a peer user id would misdirect reads
  and writes, so rejection is the only safe removal.
- Bare viking://user falls through to the canonical parser and keeps
  container semantics (a user key listing it sees only its own space).
- The self-id escape stays: a caller whose user_id equals a reserved
  name keeps viking://user/<own-id> as their canonical root. ROOT-role
  literal parsing and the legacy viking://session alias are unchanged.
- AddTargetsConfig normalizes stored legacy config spellings
  (viking://user/resources|skills) to the viking://~ form at validation
  so existing ov.conf/user_config deployments keep working; the accepted
  per-user spelling is now viking://~/resources and viking://~/skills.
- usage_reporter keeps canonicalizing the historical shorthand found in
  old transcripts and additionally recognizes viking://~/memories/.

BREAKING CHANGE: requests using the uid-less viking://user/<segment>
spelling now fail with 400; use viking://~/<segment> or an explicit
viking://user/{user_id}/<segment> URI.

* refactor(clients): migrate first-party emitters to the viking://~ home alias

Every in-repo client that emitted the removed uid-less current-user
shorthand now sends viking://~/... instead: vikingbot fallbacks and
default sentinels, the LangChain store/tools defaults, the shared
recall-core.mjs (all synced plugin copies), the codex/claude-code/
openclaw/openwebui/dsh/zcode/pi plugin emitters, quick-app examples,
Go SDK example, tau2 benchmark targets, and the eval golden dataset.

Compat kept where legacy strings live in stored user configs: bot and
ov_dream sentinels accept both spellings while emitting only ~, and
recall-core still rewrites legacy viking://user/<reserved> config values
client-side. langchain_openviking._uri now classifies viking://~ with
the explicit-user shape so canonicalized server responses keep matching
a ~ root. Plugin READMEs note the server requirement for the alias.

* docs: replace current-user shorthand guidance with the viking://~ home alias

Rewrite every EN/ZH doc and model-facing prompt that advertised the
uid-less viking://user/<segment> spelling: URI concept catalogue,
context-types/storage/extraction/retrieval/session/privacy concepts,
configuration guide (with the legacy add_targets auto-normalization
note), resources/skills/sessions/retrieval/admin API references, FAQ,
capability reference, and the openviking-memory / ov-experience-memory /
openclaw / ov-resources skills. The stale MCP viking://user/<path>
dialect passage in the MCP guide is replaced by ~ guidance, and bare
viking://user is documented as the container of user spaces.

* test(api): migrate live API session-used tests off the removed shorthand

tests/api_test/sessions sent uid-less viking://user/skills/... URIs to
record_used, which the request boundary now rejects with 400 (caught by
the API & CLI Integration Tests CI job; these tests need a live server
and are not part of the local suites). The api_test client authenticates
as an admin-role user key, so the viking://~ home alias expands for it.
tests/api_test/common/test_edge_cases.py is left as is: it asserts a 400
for a non-resource add target, which still holds.
2026-08-21 19:00:19 +08:00
MaojiaShengandTRAE CLI a7c77e6cf7 feat: add freshness-aware parent aggregation (#4180)
* feat: add freshness-aware parent aggregation

Defer wide-directory abstract/overview regeneration until the configured freshness threshold is reached while continuing changed-file semantic and vector processing.

Persist freshness metadata atomically, make parent bubbling L0-aware, preserve separate semantic/vector statuses, and keep explicit waits synchronous.

Rebuild every sampled summary on threshold refresh and always retry directory vectorization so stale sidecars or transient vector failures cannot be silently accepted.

Add focused coverage for freshness policy, pending-state consumption, sampled-summary refresh, vector retries, and parent bubbling.

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive, and applied to memory

* feat: ov reindex support --recursive, and applied to memory

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-21 16:30:44 +08:00
Jiajie - He/him/his 1efb0dce59 feat(compile): improve source materialization and long-running agent loops (#4059)
* feat(compile): compact agent context in-loop and remind iteration budget

* feat(compile): materialize sources for local exec and track reads

* feat(compile): survey-then-targeted read workflow and relaxed submission

* feat(compile): accept file sources, enable exec by default, update docs and tests

* fix(bot): harden compile source handling and compaction (#4099)

* feat(compile): add skill examples and update render

* feat(compile): add checkout workflow and task cancellation

* feat(cli): support compile task status and cancellation

* feat(examples): add compile knowledge graph tools

* docs(compile): document checkout and cancellation APIs

* docs(compile): add context compilation guides and skill examples
2026-08-20 20:17:55 +08:00
zgyandqin-ctx dc39985ad1 refactor: remove resource relation edges (#3956)
* refactor: remove resource relation edges

* fix: remove stale relation references

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-19 17:54:29 +08:00
9a5b47a2ce fix(sdk): expose tree level limit (#4110)
* fix(sdk): expose tree level limit

Why:
- Align all HTTP SDKs with the documented filesystem tree contract and make the bundled Python example valid.
- Let callers control traversal depth without bypassing the SDK clients.

What:
- Expose language-idiomatic tree depth options in Python, TypeScript, and Go.
- Forward level_limit while preserving the default depth of 3 and an explicit depth of 0.
- Add request-contract tests for Python async/sync clients, TypeScript, and Go.

Risk:
- Adding a field to exported Go TreeOptions can affect external unkeyed composite literals; keyed literals, nil options, and zero-value options remain compatible.
- Server behavior is unchanged.

Tests:
- Python: 111 passed, 1 known baseline test deselected; focused tree tests, Ruff check, and Ruff format check passed.
- TypeScript: npm test -- --run; npm run typecheck; npm run build; npm run test:node-types; npm pack --dry-run.
- Go: go vet ./...; go test ./... -count=1; go test -race ./... -count=1.

Live Docs:
- Not applicable; the existing English and Chinese filesystem API references already define level_limit.

* test(sdk): fold tree level limit cases into existing fs option tests

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-08-19 12:17:21 +08:00
DuTaoandqin-ctx e3c8e56fea feat(vikingbot): support OpenViking remote skills (#4095)
* Vikingbot use  SKILLS

* gitignore

* 远程调用

* chore: remove unrelated generated changes

* fix: address remote skill review regressions

* test: prune remote skill tests

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 21:14:31 +08:00
Jiahui ZhouandTRAE CLI 482434ef6e feat(reindex): support tag updates (#3964)
* feat(reindex): support tag updates

Add replace and append tag modes to reindex vector rebuilds, preserve omission-aware behavior, and propagate options through background tasks and namespace rebuilds. Align Python, TypeScript, Go, and CLI interfaces with tests and documentation.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): lock file targets exactly

Use an exact path lock for existing file targets while retaining tree locks for directories and prune-orphans scopes. Add a regression test for single-file reindex.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): handle prune file targets

Use exact locks for existing file targets in prune-orphans mode while retaining tree scope for missing targets. Document the existing Go ReindexOptions wait semantics and add lock regression coverage.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
2026-08-13 13:41:12 +08:00
Jiajie - He/him/his 3577f77423 fix(compile): salvage partial output on timeout and iteration limits (#3948)
* fix(service): break startup circular imports with lazy exports

* fix(fs): avoid root semantic refresh when removing resource scope

* fix(compile): preserve existing wiki links

* fix(sdk): extend HTTP timeout for blocking batch writes

* fix(compile): salvage workspace output on runtime timeout

* feat(compile): support runtime timeout and salvage partial output

* fix: expand compile task and output limits

* revert file

* fix(compile): harden salvage and deadline handling

* update

* fix(compile): address salvage review feedback

* fix(compile): normalize escaped salvage links
2026-08-12 18:51:35 +08:00
Qin Haojie 7abd6ab249 refactor(client): remove Python embedded mode (#3712)
* refactor(client): remove Python embedded mode

Consolidate Python consumers on the HTTP SDK while keeping shared server and storage capabilities unchanged.

* refactor(client): remove obsolete embedded leftovers
2026-08-10 18:00:00 +08:00
7f6085a2f9 feat(memory): support event tag filtering (#3850)
* feat(memory): support event tag filtering

Add session-level default event tags, commit-time overrides, durable queue propagation, and first-write vector index tagging. Include config update APIs and coverage for serialization, concurrency, extraction, and HTTP behavior.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(memory): expose event tags in SDKs and CLI

Add session default tag configuration, config updates, and commit-time event tag overrides across embedded Python, standalone Python, TypeScript, Go, and the Rust CLI. Preserve explicit empty-tag semantics and document each public interface.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(sdk): align legacy session tag APIs

Forward commit-time event tags through the legacy Python HTTP shims and align BaseClient session signatures without adding a new abstract-method requirement for existing subclasses.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(session): allow updating auto-commit policy

Extend PATCH session config to atomically update event tags and auto-commit settings. Merge policy objects by field, use explicit null to disable automatic commits, preserve omitted fields, and expose the contract across SDKs and CLI.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(session): align session config interfaces

Replace the generic session create config JSON flag with explicit event-tag and auto-commit options. Preserve omitted, object, and null auto-commit semantics across HTTP, embedded clients, SDKs, and CLI, reject ambiguous null policy fields, and handle nullable event configuration consistently.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* test(session): trim redundant event tag tests

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-10 11:58:02 +08:00
444cc87bf8 feat: OIDC and LDAP as new auth mode for OpenViking (#3708)
* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner

- Remove heima from partner list in README (en/zh/ja)
- Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME,
  OPENVIKING_PASSWORD) from LDAP auth docs
- Remove temporary switch bash snippets from auth docs
- Fix ldap_password description
- Add web-studio unsupported-auth-mode banner for oidc/ldap servers

* fix: address OIDC/LDAP review comments on auth plugin design

Key changes driven by PR review:

- **Role mapping**: OIDC and LDAP external identities always resolve to
  USER role. Removed map_role() calls and group_membership-based role
  mapping. Admin access is gated by the root API key mechanism only.

- **LDAP credential extraction**: Removed query-parameter-based username/
  password extraction (security concern — passwords in URLs can leak via
  shell history, proxy logs, and monitoring). Clients must use Basic Auth
  header or form data.

- **OIDC identifier sanitization**: Auth0 and other providers may include
  characters like "|" in the `sub` claim. These are now replaced with "_"
  to produce valid OpenViking user identifiers.

- **Dead code removal**: Removed _extract_groups, memberof_attribute,
  require_root_api_key_for_admin, _initialize_api_key_manager, and
  get_request_context_checks from both plugins since they are no longer
  needed.

- **Docs**: Removed query-parameter curl example, memberof_attribute and
  require_root_api_key_for_admin config references.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix(auth): bind lazy OIDC imports at module scope

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-06 12:36:37 +08:00
Jiahui Zhou 6f43a4040c feat: support processing mode for content write (#3615) 2026-08-05 21:42:33 +08:00
Jiahui Zhou d2056e971d Feat/session auto commit v2 (#3736) 2026-08-05 16:18:49 +08:00
2cc96e393e feat(retrieval): assemble auto-recall context server-side via /search mode="context" (#3534)
* feat(retrieval): assemble auto-recall context server-side via /search mode="context"

Auto-recall assembly lived in every harness plugin: each one searched per
memory type, read hits back one by one, and stitched a context block with its
own budget and degradation rules. The implementations drifted, and the shared
weaknesses showed up in production injections — roughly half of the entries
degraded to a bare URI plus a score, character budgets distorted up to 6x on
CJK text, and adjacent turns re-injected the same memories.

This moves assembly into the server as one round trip. /find stays an unchanged
stateless primitive. /search gains mode="context" (mode="list" is the default
and byte-identical to before), and /recall becomes a thin preset over the same
kernel with its v1 field names folded onto the new contract.

New assembly kernel under openviking/retrieve/context_assembler/:

- Token budgeting with a CJK-aware estimate replaces the character budget.
- detail="auto" fills breadth-first then deepens: every candidate gets a
  readable floor, then overview, then full for high-scoring entries. An
  oversized tier falls back to the previous one instead of being truncated,
  bounded by max_tokens / candidates * 2 per entry.
- Overview extraction dispatches by source: memory files use their leading
  Summary section, code files reuse code_outline signatures, long documents use
  a heading tree plus first paragraph.
- Directory hits start at overview and read their .overview.md sidecar, since
  directories carry no stored abstract; their full tier stays capped at
  overview. v1 injected the sidecar as if it were a whole file.
- Quotas generalize beyond memory types to resources and skills, with purpose
  presets supplying ratios when quotas are absent.
- dedup_turns keeps a per-session ledger at {session_uri}/.recall_log.json so
  every harness inherits cross-turn dedup; exclude_uris remains as the
  stateless fallback.
- Rendering flattens to one <memory uri=... type=... score=... detail=...>
  element per entry. Every tier carries its URI, so the model can always drill
  down through the MCP read tool.
- Query expansion and digest rewriting are opt-in and fail closed: both have
  timeout fuses, and a failed rewrite still returns the unrewritten block.
  Retrieval failures are counted into stats rather than silently yielding an
  empty block.

Plugins now send one context request, falling back to /recall and then to raw
find on older deployments, and cache that outcome so only the first turn pays
for the probe. The tri-state recallRewrite knob chooses between local host-CLI
compression and the server digest, and client-side settings move to a plugin
section in ovcli.conf.

* refactor(retrieval): give context tiers a per-category default

The tier ladder assumed `abstract` is a cheap summary. For memory files it
is not: the memory writer stores the whole stripped body in that scalar
because it doubles as the embedding text, so `abstract` costs the same as
`full` and the ladder runs `uri < overview < abstract = full`. Two of the
model's properties fell out of that: exempting `abstract` from the per-entry
cap let a single entry eat several times the budget, and `detail` — which
only ever set a ceiling — collapsed to two distinguishable behaviours across
its four values, since `auto` already allowed `full` for memory.

Tiers now come from a per-category constant table that treats the storage
shape as a given: `events` starts at overview (the one memory type whose
`# Summary` extraction is a real compression) and may deepen to full on
leftover budget; every other category is served at `abstract`, which for
memory already is the complete file at zero read cost and for resources and
skills is the generated 256-char summary. The table carries the note to move
`events` back to `abstract` once the writer stores a separate summary scalar.

Falling out of that: prefetch now reads only the candidates whose planned
tier needs a body rather than every candidate, `detail` becomes a real pin
(start and ceiling) and additionally accepts a per-category map, and
`full_score_threshold` is gone — leftover budget is spent in score order
instead of behind an absolute threshold the observed score band cannot
support. `auto` is still accepted on the wire as a synonym for "unset".

Assembly fixes found alongside:

- Removing the abstract cap exemption would turn an oversized abstract into
  a bare URI, so it now falls back to overview first — for memory that is a
  cheaper substitute, not a step up.
- Rewrite timeouts were reported as failures on Python 3.10, where
  `asyncio.TimeoutError` is a separate class from the builtin.
- `stats.rewrite_usage` read `token_tracker` off `VLMConfig`, which has no
  such attribute; usage was structurally always null. It now reads the model
  instance's tracker and reports only when the call count moved by exactly
  one, since that tracker is shared.
- A single malformed ledger record made every deduped recall in that session
  fail, and the file was never rewritten, so it could not heal. Records are
  now coerced on read and dropped on the next write, along with records left
  ahead of the clock by an archive rotation.
- Entries served as a bare URI no longer enter the dedup cooldown: they lost
  to budget pressure, not to the reader having already seen them.
- The render envelope only neutralised a literal `</memory>`, so a body could
  forge a sibling entry with its own uri, type and score.
- Flat-mode gathering re-derived the category from the URI, reading
  `viking://resources/backup/memories/events/log.md` as an event.
- Cooled and excluded URIs are compensated with extra rows, so a fully cooled
  bucket falls through to the next-best hits instead of coming back empty.
- `/recall` quotas overlay the v1 bucket defaults again; `{"events": 5}` had
  started dropping the other three buckets.
- The MCP `recall` signature sent its own defaults as if the caller had, which
  resolved a different profile than `POST /recall`; an unknown `detail` value
  raised `KeyError` through the whole call instead of degrading.

* feat(codex): inject profile context on session start

Reuse the shared profile builder for startup, clear, and resume hooks while preserving archive injection and orphan-session status output.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(retrieval): raise rewrite timeout default to 30s

* docs(agents): document low-latency recall settings

* fix(codex): prefer luna as recall compressor fallback

* refactor(plugins): unify recall compression setting

* feat(plugins): enable recall compression by default

* docs(agents): use absolute links in image docs

* fix(retrieval): address context assembly review feedback

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* test: trim redundant context assembly coverage

* fix(retrieval): address second-round context assembly review

- Drop the backticked `/search` from the deprecated-recall row in both API
  overviews. The reference checker scans the whole row after the method cell
  for backticked paths, so it read the description as a route named
  `POST /search` and Build Docs failed on an unknown, undocumented route.
- Accept ovcli.conf's full field set in both Python readers. The file's schema
  belongs to the Rust CLI, which writes `root_api_key`, `output`,
  `echo_command`, `show_progress` and `verbose` and ignores unknown keys; the
  two Python readers had drifted into stricter subsets, so the shipped example
  already failed to load in both. Adding the new `plugin` section to a working
  ovcli.conf would have broken `ov doctor` and every SDK client the same way.
- Return 400 from `mode="context"` for a request `mode="list"` also rejects.
  Retrieval validates query and image_url before searching, and the gather
  fuse swallowed that rejection along with genuine scope failures, so a body
  of `{"mode":"context"}` came back 200 with an empty block instead of the
  documented parameter error. Runtime failures still degrade into
  `stats.retrieval_errors`.
- Let a context request that asks for a server-side digest outlast the
  server's rewrite fuse. The plugin's ordinary 15s request timeout is shorter
  than the 30s fuse, so a rewrite that finished inside its own budget was
  aborted client-side, discarding the whole response — including the
  uncompressed block the server returns when a rewrite fails — and falling
  back to `/recall`. The deadline is only extended when the body actually
  requests a rewrite, and `OPENVIKING_RECALL_CONTEXT_TIMEOUT_MS` /
  `plugin.recallContextTimeoutMs` pins it.

* chore(plugins): sync shared modules into the zcode snapshot

* fix(retrieval): align context quotas and plugin defaults

Restore cross-domain coding recall, reuse authoritative actor resource
scopes, and make bucket quotas the sole width control in purpose mode.
Keep plugin defaults server-owned while preserving explicit legacy limit
settings through quota conversion.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(retrieval): preserve recall compatibility

Restore the deprecated recall threshold default, distinguish successful empty rewrites from compressor failures, and document legacy quota floors across coding-agent plugins.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-05 12:31:21 +08:00
Kchen 8d1d52fe5d 资源导入:支持解析后不拆分文档 (#3645) 2026-08-05 11:34:10 +08:00
Hao Zhe c1d38eb47f feat(langchain): support request-scoped actor peers (#3626) 2026-08-01 22:55:33 +08:00
Qin Haojie fd42b1ad92 feat(tasks): support task cancellation (#3577)
* feat(tasks): support task cancellation

* refactor(tasks): scope cancellation to current user

* feat(cli): support task cancellation

* refactor(tasks): make cancellation queue-aware

* refactor(tasks): simplify cancellation bookkeeping

* test: remove task cancellation coverage

* refactor(tasks): trim cancellation coordination

* fix(tasks): contain cancellation to owned work

* feat(tasks): persist resource source metadata

* fix(tasks): handle cancelled work consistently

* refactor(tasks): make completion queue-aware

* fix(tasks): persist terminal state before queue ack

* test(tasks): remove added lifecycle tests

* docs(tasks): document task cancellation
2026-07-30 20:34:27 +08:00
zihengli e9c4cc97c3 refactor: extract Connector delegation and expose declarative add_type (#3591)
* refactor: delegate add_resource imports to external Connector

* refactor: delegate add_resource imports to external Connector

* refactor: extract Connector delegation and expose declarative add_type

* fix: merge main to refactor/connector_delegator

* fix: merge main to refactor/connector_delegator
2026-07-29 18:09:25 +08:00
Jiahui Zhou 34b5a88971 Feat/add resource tags (#3560)
* feat: allow tags during resource import

* feat: support uploaded resource watches with tags

* feat: add resource tag flags to CLI

* fix: reject uploaded resource watches with tags

* docs: untrack add resource tags design draft

* fix: write add_resource tags during ingest

* docs: move add_resource tags docs into resources api

* fix: tighten add_resource tag ingestion semantics

* fix: address add_resource tag review feedback

* fix: merge resource tags at vector upsert

* refactor: carry add_resource tags with ingest options
2026-07-29 15:43:06 +08:00
fujiajie666 c91b0d36f2 feat: implement Skill-driven knowledge compilation for ov compile (#3567)
* feat(compile): implement skill-driven ov compile

Require a Skill and run compile tasks through VikingBot AgentLoop with structured wiki bundle rendering and durable task state.

Add OpenViking batch-write and bot proxy APIs, Python SDK and Rust CLI support, shared link and memory helpers, tests, and a One-Page demo.

* fix(compile): refine defaults, links, and failure handling

* fix(compile): normalize skill tools and degrade gracefully

* feat(compile): support skill-defined artifact outputs

* feat(compile): improve artifact reliability and wiki navigation

* feat(compile): support generating and updating skill packages

* fix(compile): validate OKF frontmatter and catalog page types

* feat(compile): rank target catalog and validate updates lazily

* feat(compile): tag generated wiki files for search

* fix(compile): preserve generated skill artifacts in submissions

* fix(compile): enforce fixed toolset and workspace artifact submissions

* fix(skills): preserve nested metadata in skill frontmatter

* fix(compile): normalize wiki paths and citation line breaks

* docs(examples): remove outdated compile demos

* docs(api): document compile and batch-write endpoints

* fix(content): allow arbitrary resource files in batch writes

* fix(compile): harden task lifecycle, auth, and execution

* fix(compile): disable direct exec by default

* fix(compile): allow file-only tasks when exec is disabled

* fix(compile): prevent task lock leaks
2026-07-28 20:33:25 +08:00
Jiahui Zhou 5d1ba45be4 Feat/add resource processing mode (#3566)
* feat: add resource processing mode

* fix: keep semantic artifacts in vectors-only add resource

* test: support processing mode in api test client

* docs: document add resource processing mode

* fix: align processing mode after resource ingestion refactor

* feat: expose processing mode in TypeScript SDK

* fix: preserve add resource compatibility
2026-07-28 20:09:06 +08:00
Hao Zheandzhiheng.liu 797406c381 fix(sdk): consolidate model, client, and evaluation correctness (#3550)
* fix(models): route multimodal inputs to DashScope embed_content

Sweep findings: A-09. Preserve image parts through the shared embedding entrypoints.

(cherry picked from commit 50b20d7ca9)

* fix(models): constrain DashScope multimodal routing

Sweep findings: A-09. Preserve text mode and require a single fused vector for multipart input.

(cherry picked from commit 77784429d4)

* fix(models): respect DashScope Qwen fusion parameters

Sweep finding A-09

(cherry picked from commit aafc702b20)

* fix(review): preserve tongyi multipart compatibility

Addresses blocking review finding on #3400.

(cherry picked from commit 96844047c5)

* fix(eval): flush queued records on stop and adapt RAG pipeline to FindResult

Sweep findings: B-05, B-12. Drain recorder queues through the sentinel and consume current retrieval result objects.

(cherry picked from commit fecdbeb6d4)

* fix(sdk/python): support sync client inside a running event loop

Sweep findings: F-09. Run sync wrappers on one persistent worker loop with result and exception propagation.

(cherry picked from commit ba0faadc87)

* fix(sdk/python): preserve cancellation and fork safety

Sweep finding: F-09. Preserve original cancellation errors and reset worker synchronization after fork.

(cherry picked from commit a19e3c95e9)

* feat(sdk/go): add tags filter and relations API for parity

Sweep findings: F-11, F-12. Expose existing server capabilities consistently to Go callers.

(cherry picked from commit 8af0c2cb36)

* fix(sdk/python): runnable quickstarts, correct migrate payload, explicit timeout precedence

Sweep findings: F-01, F-02, F-14. Initialize documented clients and preserve Python SDK request/config semantics.

(cherry picked from commit d9a64f5665)

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-28 18:11:30 +08:00
agent 8391d3a758 feat: add global Agent Evolution switch and HTTP usage sink (#3223)
* feat: add per-user agent evolution settings

* simplify Agent Evolution user settings

* fix: preserve agent evolution client compatibility

* feat(snapshot): add path diff API

* feat(snapshot): expose path diff in clients and CLI

* fix(agent-evolution): gate case memory production

* fix(agent-evolution): preserve configuration compatibility

* feat(usage): add built-in HTTP sink

* fix(agent-evolution): address PR review findings

* fix(usage): isolate HTTP outbox by destination

* docs(usage): define CountRecord HTTP mapping

* docs(usage): plan CountRecord HTTP implementation

* feat(usage): emit CountRecord over HTTP

* docs(agent-evolution): design global switch

* docs(agent-evolution): plan global switch migration

* feat(agent-evolution): make production switch global

* fix(agent-evolution): preserve embedded defaults

* test(agent-evolution): cover failed archive policy replay

* docs(agent-evolution): clarify embedded compatibility

* docs(agent-evolution): expose global switch in example config

* refactor(agent-evolution): align global setting terminology

* fix(agent-evolution): preserve session skill extraction

* fix(usage-reporter): capitalize count record keys
2026-07-27 20:09:38 +08:00
DuTao 0ab85f450a feat(session): add turn-aware retention and reliable archive recovery (#3380)
* 优化OpenViking的 session compact逻辑,active message 改为turn,压缩 assistant,保留完整user。
详见RFC:https://github.com/volcengine/OpenViking/discussions/3330

* Vikingbot 使用 ov turn session

* fix pr comment

* 更新文档

* fix pr issue
2026-07-24 14:26:46 +08:00
agent 27debfe7a8 feat(snapshot): add path diff API, SDK, and CLI (#3451)
* feat(snapshot): add path diff API

* feat(snapshot): expose path diff in clients and CLI

* fix(snapshot): pin path diff to resolved commits

* fix(snapshot): bound path diff resource usage

* fix(snapshot): bound diff blob reads

* fix(snapshot): harden path diff API

* fix(snapshot): bound path diff resource usage

* fix(build): sync native binding dependencies
2026-07-23 17:45:36 +08:00
Monday 49ca3cdfe8 feat(python-sdk): support event hooks and lifecycle reset (#3392)
* feat(python-sdk): support event hooks and lifecycle reset

* fix(python-sdk): limit client hooks change to event hooks

* docs(python-sdk): initialize clients in readme examples
2026-07-23 14:16:43 +08:00
ef4d97ebe3 feat(snapshot): support path-filtered commit history (#3271)
* feat(snapshot): support path-filtered commit history

* refactor(snapshot): reuse SDK git log implementation

* fix(snapshot): harden path-filtered log resource limits

* chore: remove stale SDK lock entry

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-07-16 19:53:40 +08:00
Jiahui Zhou 1c46d44fbc Fix/reindex preserve owners (#3096)
* fix: preserve reindex content owners

feat: allow trusted admin role assertion

feat: prune orphan vectors during reindex

fix: harden reindex memory body reads

feat: expose reindex prune options in clients

fix(cli): prefer workspace sdk for compat clients

fix: harden reindex prune orphans

* test: align reindex expectations after rebase
2026-07-14 20:38:30 +08:00
Zayn Jarvis cc0281ac70 fix(studio): sort limited listings by mtime (#3212)
* fix(studio): sort limited listings by mtime

* fix(client): forward ls ordering options
2026-07-13 16:17:02 +08:00
yufeng 5bfa9b617e fix: align TypeScript SDK with server contracts (#3159)
* fix: align TypeScript SDK with server contracts

* fix: harden TypeScript SDK contracts

* fix: handle Node image references safely

* fix: make OVPack downloads atomic
2026-07-11 22:24:16 +08:00
DuTao cbfb387dc7 feat(bot): add unified VikingBot gateway routing and OpenViking auth (#3119)
* bot opt config\api check

* 优化vikingbot的启动链路

* 美化颜色

* docs: add VikingBot gateway routing diagram

* fix(bot): harden gateway auth and proxy routing
2026-07-10 17:45:41 +08:00
Qin Haojie 3003ed61d7 feat(retrieval): support image search (#3093)
Add multimodal image vectorization and image query support across the server, SDKs, and CLI.
2026-07-09 16:42:53 +08:00
baojun-zhang 882d0c16e3 Grep mem optimize (#3043)
* feat(rgafs): add rg command into dockerfile

* feat(glob): cap grep api default node_limit at 256

* feat(python-sdk): expose default node_limit forgrep, update docs
2026-07-07 11:00:11 +08:00
baojun-zhang 6a33ebb7ca Optimize glob walkdir (#3013)
* feat(storage): optimize glob func

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* fix(localfs): offload blocking fs operations to spawn_blocking

* feat(glob): cap glob api default node_limit at 256

* feat(sdk): add node_limit options for glob in python and go SDKs
2026-07-06 21:39:16 +08:00
17631bd353 feat: support ignoring certain files in the multi-version management function, similar to the git ignore feature (#2930)
* docs: add ovgitignore design spec

Co-Authored-By: Claude <noreply@anthropic.com>

* docs: add ovgitignore implementation plan

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): add ovgitignore matcher

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): apply ovgitignore during commits

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(pyagfs): expose ovgitignore commit results

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(vikingfs): manage account ovgitignore

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(git): document ovgitignore semantics

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(git): enable ovgitignore restore assertion and document python api

Co-Authored-By: Claude <noreply@anthropic.com>

* fix: fix gitignore

* fix: fix gitignore

* feat: 新增 git ignore 相关的接口

* fix: 修复 cli 命令渲染

* doc: 删除执行计划文档

* doc: 删除执行计划文档

* feat: 在 http client 中新增 git ignore 相关接口

* fix: 修改文档中关于 .ovgitignore 被版本化的内容

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 11:45:38 +08:00
Qin Haojie 8186cfbdeb feat(auth): support seeded API key generation (#2932)
* feat(auth): support seeded API key generation

Allow admin key issuance flows to accept an optional seed so clients can derive predictable user API keys when needed, while preserving random generation by default.

* fix(go-sdk): preserve explicit empty seed payloads

Use pointer seed options so callers can distinguish omitted seeds from explicit empty seeds, matching the Admin API behavior.
2026-07-02 10:47:18 +08:00
Qin Haojie 6223537a00 feat(fs): 新增 attrs 元信息接口 (#2906)
* feat(fs): add attrs metadata endpoint

* feat(fs): move set tags under attrs API
2026-07-01 11:57:04 +08:00
Qin Haojie d7b96d7715 feat(server): add user add target defaults (#2888)
* feat: add user add target defaults

Allow deployments and per-user settings to provide default add targets while keeping explicit request targets authoritative.

* test: remove low-value CLI config parsing test

* refactor: unify user config option naming
2026-06-29 20:32:00 +08:00
Qin Haojie f9c1a60658 fix: narrow legacy agent id compatibility (#2839)
Treat agent_id as an actor peer alias in new clients while keeping X-OpenViking-Agent handling only on server ingress for old clients.
2026-06-26 14:37:57 +08:00
t0saki 3d456ff442 fix(sdk): omit null/empty request fields so older instances accept them (#2834)
The Python SDK's find/search/add_resource unconditionally attach optional
fields to their request bodies — `args` as an empty `{}` and
`tags`/`score_threshold`/`filter`/`context_type`/`session_id` as `null` — even
when the caller never set them. OpenViking kernels use
`model_config = ConfigDict(extra="forbid")` on these routes, so any instance
that predates a field rejects the whole request with
`body.<field>: Extra inputs are not permitted`. This breaks the SDK (and every
SDK consumer, e.g. vikingbot via `ov.AsyncHTTPClient`) against older instances:
`add_resource` fails on `body.args` against a pre-#2549 instance, and `find`
fails on `body.tags` against a strict pre-#2706 instance.

This is the SDK-side counterpart of #2799, which fixed the same anti-pattern in
the Rust CLI but left the Python SDK untouched.

- Add `_compact_request_body()` and apply it in find/search/add_resource: drop
  null-valued keys and an empty `args` object before sending. Scoped to these
  read/create routes only, where a missing optional field and an explicit null
  are equivalent — not applied globally, since null may mean "clear" on a future
  update/PATCH route. Mirrors the CLI's `compact_request_body`.

Tests: unit tests for `_compact_request_body` and for find/search/add_resource
omitting unset optional fields while keeping explicitly-provided ones.
2026-06-25 21:26:31 +08:00
Qin Haojie cf70a95443 fix(cli): remove unrelated HTTP compat shim (#2826)
Keep the grep/BM25 PR scoped by dropping legacy HTTP compatibility behavior and unrelated SDK config typo guidance.
2026-06-25 17:26:36 +08:00