Commit Graph
206 Commits
Author SHA1 Message Date
Zayn Jarvis 997e750ccc fix(ov): redact gateway secrets in config show and create root key with 0600 (#3411)
* fix(ov): redact gateway secrets in config show and create root key with 0600

Sweep findings: E-02, E-03. Prevent credential disclosure in output and at key creation.

* test(ov): drop trivial init-key permission test

The 0600 fix is a one-line OpenOptions::mode; a dedicated tokio+tempfile
test module for a single mode assertion is not worth its weight. The
redaction test in store.rs (a real multi-case security behavior) stays.
2026-07-23 10:47:28 +08:00
Qin Haojie fd098cfd65 fix(cli): preserve structured API errors (#3379)
* fix(error): preserve structured errors in cli

* fix(cli): preserve status for non-json errors
2026-07-22 18:06:48 +08:00
Jiahui Zhou 4295dfdef0 docs(cli): update ov cli readme (#3388) 2026-07-22 00:01:59 +10:00
Jiahui Zhou 5390bd5e54 fix: require all retrieval tags in search (#3097) 2026-07-21 11:54:01 +08:00
ef4d97ebe3 feat(snapshot): support path-filtered commit history (#3271)
* feat(snapshot): support path-filtered commit history

* refactor(snapshot): reuse SDK git log implementation

* fix(snapshot): harden path-filtered log resource limits

* chore: remove stale SDK lock entry

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-07-16 19:53:40 +08:00
Qin Haojie d47f2106ee refactor: remove unused and deprecated APIs (#3272)
Delete dead compatibility paths and test-only helpers so unsupported APIs do not remain as accidental contracts.
2026-07-16 10:49:56 +08:00
Jiahui Zhou 1c46d44fbc Fix/reindex preserve owners (#3096)
* fix: preserve reindex content owners

feat: allow trusted admin role assertion

feat: prune orphan vectors during reindex

fix: harden reindex memory body reads

feat: expose reindex prune options in clients

fix(cli): prefer workspace sdk for compat clients

fix: harden reindex prune orphans

* test: align reindex expectations after rebase
2026-07-14 20:38:30 +08:00
DuTao cbfb387dc7 feat(bot): add unified VikingBot gateway routing and OpenViking auth (#3119)
* bot opt config\api check

* 优化vikingbot的启动链路

* 美化颜色

* docs: add VikingBot gateway routing diagram

* fix(bot): harden gateway auth and proxy routing
2026-07-10 17:45:41 +08:00
zgy 6ab724bc67 fix(cli): avoid misreporting upstream model auth errors (#3116) 2026-07-10 16:05:37 +08:00
Qin Haojie 3003ed61d7 feat(retrieval): support image search (#3093)
Add multimodal image vectorization and image query support across the server, SDKs, and CLI.
2026-07-09 16:42:53 +08:00
zgy 07113f81e0 fix(cli): don't misreport remote fetch auth failures as API key errors (#3074)
When the server crawls a URL that returns 401/403, it wraps the failure
in a 5xx envelope. The CLI matched on auth-flavored message text alone
and rendered "OpenViking rejected the API key", wrongly pointing users
at their local config.

Gate the API-key error report on status: 5xx responses are never treated
as a client auth failure even when the message mentions authentication or
forbidden. Also split the 401 vs 403 fetch messages so 403 reads as an
access-denied / anti-bot block rather than a credential problem.
2026-07-08 14:50:59 +08:00
Qin Haojie 44180e39ff fix(cli): preserve mixed warning output fields (#3062)
Keep warning arrays from taking over table rendering when an API result also contains scalar fields like status, root_uri, and task_id.
2026-07-07 17:09:27 +08:00
baojun-zhang 6a33ebb7ca Optimize glob walkdir (#3013)
* feat(storage): optimize glob func

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* fix(localfs): offload blocking fs operations to spawn_blocking

* feat(glob): cap glob api default node_limit at 256

* feat(sdk): add node_limit options for glob in python and go SDKs
2026-07-06 21:39:16 +08:00
Qin Haojie 4b9d17db2f fix(ragfs): sort directory listings dirs first (#2993) 2026-07-03 20:00:35 +08:00
MaojiaSheng 3c419ed09a chore: replace doubao 2.0 pro with doubao 2.0 lite as recomended VLM model (#2984) 2026-07-03 16:09:20 +08:00
Haoyu Zhangandzhanghaoyu 8fb94e9f4d fix: 修复git路径问题 (#2963)
Co-authored-by: zhanghaoyu <zhanghaoyu.la@bytedance.com>
2026-07-02 19:15:58 +08:00
tuofangandfang dd5b1d7a7f Skip caching control plugins during mount (#2948)
Co-authored-by: fang <fang@fangMacBook-Air.local>
2026-07-02 16:33:38 +08:00
17631bd353 feat: support ignoring certain files in the multi-version management function, similar to the git ignore feature (#2930)
* docs: add ovgitignore design spec

Co-Authored-By: Claude <noreply@anthropic.com>

* docs: add ovgitignore implementation plan

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): add ovgitignore matcher

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): apply ovgitignore during commits

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(pyagfs): expose ovgitignore commit results

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(vikingfs): manage account ovgitignore

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(git): document ovgitignore semantics

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(git): enable ovgitignore restore assertion and document python api

Co-Authored-By: Claude <noreply@anthropic.com>

* fix: fix gitignore

* fix: fix gitignore

* feat: 新增 git ignore 相关的接口

* fix: 修复 cli 命令渲染

* doc: 删除执行计划文档

* doc: 删除执行计划文档

* feat: 在 http client 中新增 git ignore 相关接口

* fix: 修改文档中关于 .ovgitignore 被版本化的内容

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 11:45:38 +08:00
baojun-zhang c699144012 feat(encrypt):reduce encrypted temp-write metadata overhead by caching temp-root readiness and turning the temp-file path into TTL fast path + NotFound fallback + AlreadyExists cleanup . (#2933) 2026-07-02 10:57:47 +08:00
Qin Haojie 8186cfbdeb feat(auth): support seeded API key generation (#2932)
* feat(auth): support seeded API key generation

Allow admin key issuance flows to accept an optional seed so clients can derive predictable user API keys when needed, while preserving random generation by default.

* fix(go-sdk): preserve explicit empty seed payloads

Use pointer seed options so callers can distinguish omitted seeds from explicit empty seeds, matching the Admin API behavior.
2026-07-02 10:47:18 +08:00
Qin Haojie 6223537a00 feat(fs): 新增 attrs 元信息接口 (#2906)
* feat(fs): add attrs metadata endpoint

* feat(fs): move set tags under attrs API
2026-07-01 11:57:04 +08:00
baojun-zhang 843a4a3a39 feat(encrypt): Protect encrypted writes with temp-file publish and dual-path locking (#2894)
* feat(encrypt): Protect encrypted writes with temp-file publish and dual-path locking

* fix(storage): reuse outer lock handles, keep encrypted temp files out of user space, preserve encrypted-only path locking, and add cross-layer temp-path tests

* fix(storage): reuse rollback lock handles and gate encrypted wrapper creation on replace publish support

* fix(storage): reuse rollback lock handles, align encrypted temp lock paths, and use localfs replace publish semantics
2026-07-01 11:27:26 +08:00
Qin Haojie d7b96d7715 feat(server): add user add target defaults (#2888)
* feat: add user add target defaults

Allow deployments and per-user settings to provide default add targets while keeping explicit request targets authoritative.

* test: remove low-value CLI config parsing test

* refactor: unify user config option naming
2026-06-29 20:32:00 +08:00
t0saki 2846bb6e76 feat(resources): ingest whole sites via sitemap / RSS / Atom (#2858)!
Add WebFeedAccessor (priority 60) that turns a single sitemap /
sitemapindex / RSS / Atom URL into ONE resource tree: it mirrors every
listed page into a temp directory and reuses the existing DirectoryParser
pipeline (the same "fetch-many -> dir -> tree" contract as GitAccessor).
A watch on the feed URL keeps the whole site refreshed (new pages added,
removed pages dropped on each rebuild).

- New openviking/parse/accessors/web_feed_accessor.py: WebFeedAccessor +
  sitemap/feed extractors (nested sitemapindex recursion with depth cap,
  RSS 2.0 / Atom via feedparser), bounded concurrent polite mirroring,
  robots.txt, same-host / include / exclude / max_pages limits.
- args={"site": true} forces whole-site ingestion from a bare domain or
  page by auto-discovering the sitemap/RSS (robots.txt, HTML
  <link rel=alternate>, conventional paths); {"site": false} opts a
  feed-looking URL back out to HTTPAccessor.
- Thread accessor-selection kwargs through can_handle; the registry
  tolerates accessors whose can_handle lacks **kwargs (back-compatible).
- Single-page adds get a non-blocking "this site exposes a sitemap/RSS"
  suggestion appended to the MCP add_resource response, gated to the
  site root only; never auto-crawls.
- New WebFeedConfig (parsers.webfeed): max_pages, concurrency, politeness
  delay, same_host_only, respect_robots, max_depth, suggest_feed.
- Dependencies: feedparser (robust RSS/Atom), defusedxml (XXE-safe XML).
- Docs: zh/en resources API, MCP/CLI/SDK help, ov.conf.example.
- Tests: 52 unit tests (fake httpx, no network).
2026-06-26 21:13:03 +08:00
Zayn Jarvis fb39c57442 document reindex modes (#2845) 2026-06-26 16:35:11 +08:00
Qin Haojie f9c1a60658 fix: narrow legacy agent id compatibility (#2839)
Treat agent_id as an actor peer alias in new clients while keeping X-OpenViking-Agent handling only on server ingress for old clients.
2026-06-26 14:37:57 +08:00
0102a48c2a fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills (#2813)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

* fix(cli): remove unexisted transaction observer

* docs: update skills definition

* docs: update skills definition

* docs: update skills definition

* docs: update skills definition

* fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills

* docs(skills): use -p instead of --parent in agent skills examples

Align the `ov skills add` examples in the context-types and viking-uri
docs with the short flag `-p` introduced for `ov skills list/find/show`,
so all four user-facing examples consistently demonstrate the short form
when targeting `viking://agent/skills`.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): error check for api key

* fix(tests): unit test wait until resource not busy

* fix(tests): unit test wait until resource not busy

* fix(sdk): args form in skills find

* fix(skills): pass target uri in request body

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-06-25 14:36:06 +08:00
Haoyu Zhangandzhanghaoyu.la aa53e7aede feat: 实现 commit、restore、show 文件系统多版本管理功能 (#2756)
* feat: 实现 commit、restore、show 文件系统多版本管理功能

fix: 修复commit时删除文件

fix: commit 的 fast path 1 添加 Racy-clean 机制

fix: 将 sdk 中的 git 命令改为 snapshot 命令,同步修改单测

fix: 多版本管理的文件存储目录改为 .ovgit

feat: snapshot cli 渲染

fix: 修复 restore 时将删除的文件回滚时,目录不存在的问题

feat: restore 命令的 project_dir 参数改为可选,不传时默认全目录回滚

feat: 更新文档

fix: 删除暂未使用的配置参数

feat: 新增示例脚本

fix: 修复示例代码

fix: 修复 restore 返回的 task id 任务完成状态

feat: 在 restore 修改文件系统时加锁

fix: fix openviking_sdk

* feat: 将git多版本管理功能改为默认打开,并复用agfs的配置参数作为默认值

* fix: restore 命令改为先完成 ref 一致性协议再写回 VFS;object store 并发改为使用唯一 temp path

* fix: 在 git 配置检验层去除未实现的cas_mode = "redis_lock"模式

* fix: 在 Rust GitService 边界统一校验 account

* fix: 当前commit不支持通过 path 传入目录,增加报错信息

* fix: 将git文件默认存储路径统一为 .ovgit

* fix: restore 时写入 VFS 失败时返回详细的报错,并继续触发 reindex

* fix: 校验 commit、restore、show 的路径

* feat: 实现 commit 时指定目录

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
2026-06-25 11:28:04 +08:00
Zayn Jarvis c0fa12f9ef docs: clarify local cli binary smoke (#2792) 2026-06-24 14:02:13 +08:00
t0saki 2af4d748d8 fix(cli): omit null/empty request fields so older instances accept them (#2799)
The CLI unconditionally attaches optional fields to the find/search/add_resource
request bodies — `args` as an empty `{}` and `tags`/`context_type` as `null` —
even when the user never set them. OpenViking kernels use
`model_config = ConfigDict(extra="forbid")` on these routes, so any instance that
predates a field rejects the whole request with
`body.<field>: Extra inputs are not permitted`. This breaks whenever the CLI is
newer than the target instance (and, symmetrically, when a field is later
renamed/removed): e.g. `ov add-resource` fails on `body.args` against a pre-#2549
instance, and `ov find` fails on `body.tags` against a strict pre-#2706 instance.

- Add `compact_request_body()` and apply it in find/search/add_resource: drop
  null-valued keys and an empty `args` object before sending. Scoped to these
  read/create routes only, where a missing optional field and an explicit null
  are equivalent — not applied globally, since null may mean "clear" on a future
  update/PATCH route. This mirrors the existing `create_parent` backward-compat
  convention.
- When a field is explicitly set but unsupported, translate the raw pydantic
  `Extra inputs are not permitted` error into a version-mismatch hint and suggest
  `ov health`, instead of surfacing the opaque API error.

Tests: unit tests for `compact_request_body` and `extra_forbidden_field`.
2026-06-24 12:54:10 +08:00
Xiaobin Huang 6d6660b162 chore(cli): show detailed validation error messages, extract zh-CN to store (#2762)
validation_error_copy() took _error: &Error but completely ignored
it, always returning the same generic message regardless of the actual
failure. Users saw 'Validation failed. Check the server URL and API
key if required.' for every kind of error — network unreachable,
unhealthy server, rejected API key, or HTTP errors.

Now inspects the error to provide actionable messages:
- Network errors → 'Cannot reach the server. Check the URL.'
- Unhealthy server → 'Server reported unhealthy status.'
- Auth rejected (401/403) → 'API key was rejected.'
- HTTP errors → 'Server returned HTTP {status}.'
- Config errors → passes through the original message
- Other → original generic fallback

Both English (validation_error_copy) and Chinese
(validation_error_copy_zh) paths updated.
2026-06-24 11:15:04 +08:00
MaojiaShengandclaude-sonnet-4-6 1cc72d1dc8 fix(cli): remove unexisted transaction observer (#2764)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

* fix(cli): remove unexisted transaction observer

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
2026-06-23 15:23:14 +08:00
Zayn Jarvis f869731485 Support gzip responses in Rust CLI (#2783) 2026-06-23 12:12:47 +08:00
DuTao 027e21bb7e feat(bot): Simplify the bot auth check, support ov's trusted auth_mode. (#2769)
* 增加bot的配置校验。优化bot的逻辑

* 去除 mode的逻辑依赖

* 调整dev的提示文案

* fix:
1. trusted localhost允许 without root key;
2. 调整文档废弃root_api_key;

* 现在 proxy 生成 openviking_connection 时会带上当前 OpenViking server 的 server_url,VikingBot 收到 request-scoped connection 后会优先使用这个 URL,不会再 fallback 到静态 bot.ov_server.server_url 去请求另一台 server。

* fix ipv6

* fix trusted模式chat指令使用root_api_key
2026-06-23 11:59:35 +08:00
Ben Sharir 42891b9a07 queuefs: enable SQLite auto-vacuum for new queue databases (#2754)
Fixes unbounded queue.db growth for newly created QueueFS SQLite
databases by enabling SQLite auto_vacuum=FULL at DB initialization.

- Detect brand-new databases (no tables in sqlite_master)
- Set PRAGMA auto_vacuum=FULL and run VACUUM before schema creation
- Preserve existing deployed databases unchanged (no risky rewrites)
- Add regression tests for both new-db and legacy-db behavior

Fixes #2707
2026-06-22 15:23:15 +08:00
Xiaobin Huang 44b3895e8b fix(cli): filter non-Press key events to prevent double-registration (#2737)
* fix(cli): filter non-Press key events to prevent double-registration in interactive prompts

On Windows with ENABLE_VIRTUAL_TERMINAL_INPUT enabled (crossterm 0.28.1),
the console can generate both Press and Release key events for a single
physical key press. The TUI runner (tui/mod.rs) already filters for
KeyEventKind::Press, but the config wizard, config switch selector,
and skill multi-select did not, causing double-processing of every
key press.

Add key.kind == KeyEventKind::Press guard to all three interactive
event-reading loops:
- config_wizard/wizard.rs: prompt_select and prompt_text
- handlers.rs: config switch prompt_select
- commands/skills.rs: skill multi-select prompt

Also add explicit Event::Key(_) => {} arms to discard non-Press
key events cleanly.

* perf(cli): render only on state change, not on every event loop iteration

Previously ui.render() was called at the top of every event loop
iteration, causing a full clear-and-redraw for every ignored event
(Release, Resize, and other non-Press events). On Windows with
ENABLE_VIRTUAL_TERMINAL_INPUT enabled, crossterm can emit multiple
events per physical key press, leading to excessive flickering.

Restructure all three interactive event loops to:
- Render once initially before the loop
- Re-render only when selection/state actually changes (Up/Down/Space)
- Re-render on terminal resize
- Skip render entirely for Release, unhandled Press, and other events
2026-06-20 12:57:32 +08:00
Zayn Jarvis 0418a4537c fix config wizard user management flow (#2721) 2026-06-19 13:33:22 +08:00
baojun-zhang 8a2d7813fd fix(ragfs): fix root directory acquire encryption account_id exception, make _system fixed (#2717) 2026-06-18 21:12:09 +08:00
baojun-zhang cea96fb8cc feat(ragfs): add plaintext fallback for encrypted-read migration path (#2712) 2026-06-18 18:25:47 +08:00
Jiahui Zhou 21c58bd8f6 Set tags (#2706)
* feat(vectordb): add partial update api

fix(vectordb): support partial updates across adapters

fix(vectordb): return structured update results

test(vectordb): cover update result behavior

* feat(vectordb): support partial upsert semantics

* feat(content): support explicit search tags

* refactor unify search tag update api

* refactor(content): drop unrelated peer_id from semantic refresh

* fix(content): normalize set-tags targets and cli output
2026-06-18 17:48:49 +08:00
Qin Haojie 94c32da7a2 fix(ragfs): ignore path locks during shape probe (#2695)
* fix(ragfs): ignore path locks during shape probe

* fix(ragfs): log encrypted read failures
2026-06-17 22:29:01 +08:00
baojun-zhang b586a0c638 feat(ragfs): optimize S3 head-object error message return and parallelize legacy shape probe (#2692) 2026-06-17 21:00:53 +08:00
baojun-zhang 6d4633009d fix(ragfs): skip zero-byte files during legacy shape probe (#2691) 2026-06-17 19:45:31 +08:00
tuofangandfang 2d56bd71f4 feat(ragfs): add CachedFileSystem and Redis/Mooncake/Yuanrong cache providers (#2520)
* add CachedFileSystem + CacheProvider trait and Mooncake/Yuanrong Provide

add CachedFileSystem + CacheProvider trait and Mooncake/Yuanrong Provide

* Handle poisoned known_keys mutexes in cache providers

* Add configurable cache support to ragfs python

* Add Redis cache provider support

* Prune native cache providers from default build

* Add RAGFS cache guides in Chinese and English

* delete .cargo/config.toml

* Fix stale cache invalidation across shared wrappers

* Document Yuanrong native concurrency limits

* add CachedFileSystem + CacheProvider trait and Mooncake/Yuanrong Provide

add CachedFileSystem + CacheProvider trait and Mooncake/Yuanrong Provide

* Handle poisoned known_keys mutexes in cache providers

* Add configurable cache support to ragfs python

* Add Redis cache provider support

* Prune native cache providers from default build

* Add RAGFS cache guides in Chinese and English

* delete .cargo/config.toml

* Fix stale cache invalidation across shared wrappers

* Document Yuanrong native concurrency limits

* Limit directory cache entries and add regression test

* docs: add TOS s3fs backend test design

* Add runtime cache config override

* add build guides for mooncake and yuanrong

* fix _FakeConfig test with cache

* fix(ragfs): cache encrypted data below the encryption layer

- pass runtime cache config to the Rust binding
- cache ciphertext instead of decrypted content
- disable cache for encrypted multi-write mounts
- update tests and provider build documentation

* fix(ragfs): invalidate cache after same-mount raw copy

Ensure copy_within_mount invalidates the cached destination file and
parent directory after the raw backend fast path writes data directly.
This prevents stale reads and stale directory metadata when cache is
enabled and Python cp() uses the same-mount copy optimization.

Add a regression test covering overwrite copy followed by read/list.

* fix(ragfs): preserve multi-write discovery through cache layer

Allow MountableFS::as_multiwrite() to unwrap CachedFileSystem when
discovering the underlying MultiWriteWrappedFS. This preserves
multi-write admin paths and same-mount copy behavior for cache-enabled,
unencrypted multi-write mounts.

Add a regression test covering sync status, sync retry, same-mount copy,
and unmount behavior for cached unencrypted multi-write mounts.

* feat(ragfs): add cache-aware tree traversal mode

- add configurable tree traversal mode to cache policy
- keep default tree behavior delegated to backend
- allow cached traversal to reuse read_dir directory cache
- bypass cached traversal for multi-write backends
- add regression coverage for tree cache behavior and fallbacks

* docs: design cache-aware grep traversal

* feat(ragfs): add cache-aware grep traversal

Introduce a shared cache traversal mode for recursive APIs and use it to
optionally run grep through CachedFileSystem.

- add CacheTraversalMode with backend and cached_traversal modes
- keep CacheTreeMode as a compatibility alias
- route tree and grep through cached traversal only when explicitly enabled
- reuse cached read_dir entries and full-file reads during grep traversal
- keep multi-write traversal on the backend path
- expose storage.agfs.cache.traversal_mode in Python config
- raise max cached directory entries threshold to 4096
- add regression tests for grep cache traversal and traversal config

* Optimize cached grep generation validation

* Parallelize cached grep file scanning

---------

Co-authored-by: fang <fang@fangMacBook-Air.local>
2026-06-17 16:01:52 +08:00
Qin Haojie ff73e68644 fix(ragfs): ignore legacy task records during shape probe (#2675) 2026-06-17 11:55:35 +08:00
fujiajie666 2583da8459 Feature/wiki link (#2558)
* memory-resource记忆链接

* ov write, rm 更新 .overview

* 更新docs

* bug fix

* 更好的利用时间,摘要信息进行memory提取

* 合并

* 通过session.commit封装 --reason

* 回滚vlm代码

* 回滚rust代码

* bug fix

* 兼容peers, user 作用域

* bug fix

* bug fix

* bug fix

* bug fix

* format ruff fix

* --reason 使用同一个session_id,ruff修正

* --reason 使用同一个session_id,ruff修正,peer memory

* ruff修正
2026-06-16 23:07:30 +08:00
Hao Zhe fbea47eef9 feat(cli): improve config TUI (#2663)
* feat(cli): improve config TUI

Add a Switch Config entry to the interactive ov config menu and route it through the existing config switch flow.

Make the config status header responsive with full and compact modes, keeping the original wordmark/boat art only when the terminal has enough room.

Fix wrapped-row clearing for config, switch, skill removal, help, and error surfaces so terminal resizes do not leave stale borders or duplicated content.

* fix(cli): address config TUI review feedback
2026-06-16 19:43:39 +08:00
baojun-zhang eff7e67037 feat(storage): support content-type auto-detecting in S3 case (#2668)
* feat(storage): support content-type auto-detecting in S3 case

* feat(storage): update code doc
2026-06-16 18:24:17 +08:00
baojun-zhang ccc059bdf8 fix(storage): fix empty chunk overwrite during multiwrite copy (#2652) 2026-06-16 14:14:27 +08:00
Zayn Jarvis 56c903afc6 fix(cli): normalize skill zip paths (#2615)
* fix(cli): normalize skill zip paths

* refactor: share relative path sanitization

* refactor: centralize safe viking uri joins

* test: cover posix skill upload paths
2026-06-15 19:14:16 +08:00