Commit Graph
30 Commits
Author SHA1 Message Date
Monday 49ca3cdfe8 feat(python-sdk): support event hooks and lifecycle reset (#3392)
* feat(python-sdk): support event hooks and lifecycle reset

* fix(python-sdk): limit client hooks change to event hooks

* docs(python-sdk): initialize clients in readme examples
2026-07-23 14:16:43 +08:00
Yu Zhang 93162b2fd3 fix(sdk-typescript): distinguish cancellation from timeout (#3369) 2026-07-22 19:21:32 +08:00
ef4d97ebe3 feat(snapshot): support path-filtered commit history (#3271)
* feat(snapshot): support path-filtered commit history

* refactor(snapshot): reuse SDK git log implementation

* fix(snapshot): harden path-filtered log resource limits

* chore: remove stale SDK lock entry

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-07-16 19:53:40 +08:00
Jiahui Zhou 1c46d44fbc Fix/reindex preserve owners (#3096)
* fix: preserve reindex content owners

feat: allow trusted admin role assertion

feat: prune orphan vectors during reindex

fix: harden reindex memory body reads

feat: expose reindex prune options in clients

fix(cli): prefer workspace sdk for compat clients

fix: harden reindex prune orphans

* test: align reindex expectations after rebase
2026-07-14 20:38:30 +08:00
Zayn Jarvis cc0281ac70 fix(studio): sort limited listings by mtime (#3212)
* fix(studio): sort limited listings by mtime

* fix(client): forward ls ordering options
2026-07-13 16:17:02 +08:00
yufeng 5bfa9b617e fix: align TypeScript SDK with server contracts (#3159)
* fix: align TypeScript SDK with server contracts

* fix: harden TypeScript SDK contracts

* fix: handle Node image references safely

* fix: make OVPack downloads atomic
2026-07-11 22:24:16 +08:00
yufeng 0536e6897b feat: add JavaScript and TypeScript SDK (#3147)
* feat: add JavaScript and TypeScript SDK

* fix: align TypeScript SDK contracts
2026-07-11 16:06:42 +08:00
DuTao cbfb387dc7 feat(bot): add unified VikingBot gateway routing and OpenViking auth (#3119)
* bot opt config\api check

* 优化vikingbot的启动链路

* 美化颜色

* docs: add VikingBot gateway routing diagram

* fix(bot): harden gateway auth and proxy routing
2026-07-10 17:45:41 +08:00
Qin Haojie 3003ed61d7 feat(retrieval): support image search (#3093)
Add multimodal image vectorization and image query support across the server, SDKs, and CLI.
2026-07-09 16:42:53 +08:00
baojun-zhang 882d0c16e3 Grep mem optimize (#3043)
* feat(rgafs): add rg command into dockerfile

* feat(glob): cap grep api default node_limit at 256

* feat(python-sdk): expose default node_limit forgrep, update docs
2026-07-07 11:00:11 +08:00
baojun-zhang 6a33ebb7ca Optimize glob walkdir (#3013)
* feat(storage): optimize glob func

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* fix(localfs): offload blocking fs operations to spawn_blocking

* feat(glob): cap glob api default node_limit at 256

* feat(sdk): add node_limit options for glob in python and go SDKs
2026-07-06 21:39:16 +08:00
Evo adb57bdcf3 fix(sdk/go): stop sending empty args on AddResource (#2878)
AddResource unconditionally attached args: {} to every request body. Against
instances that predate #2549 (which added the args field to the resources
route under model_config=ConfigDict(extra="forbid")), the empty args object
is rejected with "body.args: Extra inputs are not permitted", so add-resource
fails entirely on older / hosted endpoints.

Only attach args when arguments were actually provided (len(opts.Args) > 0),
mirroring the Python SDK _compact_request_body (#2834) and the Rust CLI
compact_request_body (#2799). Other fields, including directly_upload_media,
are unchanged. Scope is args-only, matching #2834.

Tests cover the three arg states: omitted when unset, omitted when explicitly
empty (server defaults args to {} on this create route, so absent and
present-but-empty are equivalent), and forwarded when populated.
2026-07-02 21:40:10 +08:00
17631bd353 feat: support ignoring certain files in the multi-version management function, similar to the git ignore feature (#2930)
* docs: add ovgitignore design spec

Co-Authored-By: Claude <noreply@anthropic.com>

* docs: add ovgitignore implementation plan

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): add ovgitignore matcher

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(git): apply ovgitignore during commits

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(pyagfs): expose ovgitignore commit results

Co-Authored-By: Claude <noreply@anthropic.com>

* feat(vikingfs): manage account ovgitignore

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(git): document ovgitignore semantics

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(git): enable ovgitignore restore assertion and document python api

Co-Authored-By: Claude <noreply@anthropic.com>

* fix: fix gitignore

* fix: fix gitignore

* feat: 新增 git ignore 相关的接口

* fix: 修复 cli 命令渲染

* doc: 删除执行计划文档

* doc: 删除执行计划文档

* feat: 在 http client 中新增 git ignore 相关接口

* fix: 修改文档中关于 .ovgitignore 被版本化的内容

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-07-02 11:45:38 +08:00
Qin Haojie 8186cfbdeb feat(auth): support seeded API key generation (#2932)
* feat(auth): support seeded API key generation

Allow admin key issuance flows to accept an optional seed so clients can derive predictable user API keys when needed, while preserving random generation by default.

* fix(go-sdk): preserve explicit empty seed payloads

Use pointer seed options so callers can distinguish omitted seeds from explicit empty seeds, matching the Admin API behavior.
2026-07-02 10:47:18 +08:00
Evo 846a620e0e feat(sdk/go): expose grep level_limit to control traversal depth (#2915)
* feat(sdk/go): add LevelLimit to GrepOptions

The server validates+consumes level_limit (default 10) and the Python client
exposes it, but the Go SDK could not send it, so Go callers were silently
pinned to the default traversal depth. Add LevelLimit *int, forwarded only when
set (mirrors NodeLimit).

* feat(sdk/go): forward grep level_limit when set

* test(sdk/go): cover grep level_limit forwarding and nil-omit
2026-07-01 15:51:49 +08:00
Qin Haojie 6223537a00 feat(fs): 新增 attrs 元信息接口 (#2906)
* feat(fs): add attrs metadata endpoint

* feat(fs): move set tags under attrs API
2026-07-01 11:57:04 +08:00
Evo 11b2b63e0b feat(sdk/go): expose target_uri skill scoping (parity with #2813) (#2897)
#2813 promoted account-shared skills (viking://agent/skills) to a
first-class, scoped capability and shipped a target_uri param across the
Python SDK (all 7 skill methods), the Rust CLI, and the server skills
router. The Go SDK skill methods were the only client left without it, so
Go adopters cannot scope skill operations to user-vs-agent roots and must
drop to Python/CLI.

Add an optional TargetURI field to the six skill option structs plus a new
DeleteSkillOptions, and thread target_uri through every skill method
matching the Python SDK + server placement exactly:
- query param: ListSkills, GetSkill, DeleteSkill
- JSON body:   AddSkill, FindSkills, ValidateSkill, UpdateSkill
target_uri is sent only when set (nil omits it), mirroring the Python
"if target_uri is not None" semantics and the server default-root fallback.
Like the Python SDK, skills send target_uri as-is (no client-side
normalization; only find/search normalize).

DeleteSkill previously took no options; it now takes a variadic
opts ...*DeleteSkillOptions so existing DeleteSkill(ctx, name) callers keep
compiling. The change is source-compatible across the module.

Adds TestSkillRequestsScopeTargetURI (asserts query-vs-body placement for
all 7 methods) and TestSkillRequestsOmitTargetURIWhenUnset (asserts omit
for all 7). go test ./... and go vet ./... pass.
2026-06-30 19:34:57 +08:00
Qin Haojie d7b96d7715 feat(server): add user add target defaults (#2888)
* feat: add user add target defaults

Allow deployments and per-user settings to provide default add targets while keeping explicit request targets authoritative.

* test: remove low-value CLI config parsing test

* refactor: unify user config option naming
2026-06-29 20:32:00 +08:00
Qin Haojie f9c1a60658 fix: narrow legacy agent id compatibility (#2839)
Treat agent_id as an actor peer alias in new clients while keeping X-OpenViking-Agent handling only on server ingress for old clients.
2026-06-26 14:37:57 +08:00
t0saki 3d456ff442 fix(sdk): omit null/empty request fields so older instances accept them (#2834)
The Python SDK's find/search/add_resource unconditionally attach optional
fields to their request bodies — `args` as an empty `{}` and
`tags`/`score_threshold`/`filter`/`context_type`/`session_id` as `null` — even
when the caller never set them. OpenViking kernels use
`model_config = ConfigDict(extra="forbid")` on these routes, so any instance
that predates a field rejects the whole request with
`body.<field>: Extra inputs are not permitted`. This breaks the SDK (and every
SDK consumer, e.g. vikingbot via `ov.AsyncHTTPClient`) against older instances:
`add_resource` fails on `body.args` against a pre-#2549 instance, and `find`
fails on `body.tags` against a strict pre-#2706 instance.

This is the SDK-side counterpart of #2799, which fixed the same anti-pattern in
the Rust CLI but left the Python SDK untouched.

- Add `_compact_request_body()` and apply it in find/search/add_resource: drop
  null-valued keys and an empty `args` object before sending. Scoped to these
  read/create routes only, where a missing optional field and an explicit null
  are equivalent — not applied globally, since null may mean "clear" on a future
  update/PATCH route. Mirrors the CLI's `compact_request_body`.

Tests: unit tests for `_compact_request_body` and for find/search/add_resource
omitting unset optional fields while keeping explicitly-provided ones.
2026-06-25 21:26:31 +08:00
Qin Haojie cf70a95443 fix(cli): remove unrelated HTTP compat shim (#2826)
Keep the grep/BM25 PR scoped by dropping legacy HTTP compatibility behavior and unrelated SDK config typo guidance.
2026-06-25 17:26:36 +08:00
0102a48c2a fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills (#2813)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

* fix(cli): remove unexisted transaction observer

* docs: update skills definition

* docs: update skills definition

* docs: update skills definition

* docs: update skills definition

* fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills

* docs(skills): use -p instead of --parent in agent skills examples

Align the `ov skills add` examples in the context-types and viking-uri
docs with the short flag `-p` introduced for `ov skills list/find/show`,
so all four user-facing examples consistently demonstrate the short form
when targeting `viking://agent/skills`.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): error check for api key

* fix(tests): unit test wait until resource not busy

* fix(tests): unit test wait until resource not busy

* fix(sdk): args form in skills find

* fix(skills): pass target uri in request body

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-06-25 14:36:06 +08:00
Haoyu Zhangandzhanghaoyu.la aa53e7aede feat: 实现 commit、restore、show 文件系统多版本管理功能 (#2756)
* feat: 实现 commit、restore、show 文件系统多版本管理功能

fix: 修复commit时删除文件

fix: commit 的 fast path 1 添加 Racy-clean 机制

fix: 将 sdk 中的 git 命令改为 snapshot 命令,同步修改单测

fix: 多版本管理的文件存储目录改为 .ovgit

feat: snapshot cli 渲染

fix: 修复 restore 时将删除的文件回滚时,目录不存在的问题

feat: restore 命令的 project_dir 参数改为可选,不传时默认全目录回滚

feat: 更新文档

fix: 删除暂未使用的配置参数

feat: 新增示例脚本

fix: 修复示例代码

fix: 修复 restore 返回的 task id 任务完成状态

feat: 在 restore 修改文件系统时加锁

fix: fix openviking_sdk

* feat: 将git多版本管理功能改为默认打开,并复用agfs的配置参数作为默认值

* fix: restore 命令改为先完成 ref 一致性协议再写回 VFS;object store 并发改为使用唯一 temp path

* fix: 在 git 配置检验层去除未实现的cas_mode = "redis_lock"模式

* fix: 在 Rust GitService 边界统一校验 account

* fix: 当前commit不支持通过 path 传入目录,增加报错信息

* fix: 将git文件默认存储路径统一为 .ovgit

* fix: restore 时写入 VFS 失败时返回详细的报错,并继续触发 reindex

* fix: 校验 commit、restore、show 的路径

* feat: 实现 commit 时指定目录

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
2026-06-25 11:28:04 +08:00
87329714dd feat(grep): integrate VikingDB bm25 keyword search for grep engine (#2144)
* feat(grep): integrate VikingDB bm25 keyword search for grep engine

* fix(grep): address CI review feedback: max-size eviction to _count_cache, use Literal, Split regex alternation into individual keywords for bm25 (max 10)

* fix(schema): use dynamic __version__ for schema_version and handle dev suffixes in version comparison

* fix(schema): upsert data to vikingdb lack of content

* chore: add benchmark for retrieval

* fix(grep): vikingdb return 200 and no results means no matching content, not necessary to fallback to local fs

* fix(benchmark): sub uri args; add report

* refactor: code format by ruff

* optimize: move grep config (engine and switch_to_remote_threshold) to ov.conf

* optimize: auto adapt remote_return_limit by agg API; rm unnecessary params in keywords search

* fix: adjust benchmark scripts

* fix(grep): store full content for BM25; use PathScope depth; reduce redundant API calls

* refactor: new benchmark

* fix: step1 add resource by real code data

* feat(benchmark): split grep benchmark into effectiveness/performance suites with async reindex

* optimize (benchmark): adjust keywords and ground truth for testing

* fix: truncate 64KB for content field

* optimize: effectiveness add resource plainly

* optimize: change param use of SearchByKeywords from "keywords" to "query"

* optimize(benchmark): refactor effectiveness scripts

* optimize: ensure raw data for content field

* optimize: fulltext analyzer's stop-words only use symbols

* fix: adapt to new ov cli for benchmark

* optimize: reuse file content to avoid re-read AGFS file

* optimize: tune grep vikingdb defaults and refresh bm25 benchmark scripts

* optimize: benchmark client timeout

* update README

* fix: rm unused param

* fix: default values in docs

* optimize: increase truncate byte size to 1MB for content field for VikingDB

* fix(logger): harden queued stream logging (#2786)

* fix(logger): replace StreamHandler with QueueHandler+QueueListener to prevent thread deadlock

When log.output='stdout' (default) and the server is managed by systemd,
concurrent log writes can deadlock because logging.StreamHandler holds a
thread lock across stream.flush() which blocks on systemd-piped file I/O.

During session.commit() phase 2, multiple async coroutines (memory
extraction, summarization) concurrently call logger.info()/warning()
with large payloads. The first thread's flush() blocks on the pipe,
while all subsequent threads block on handler.acquire() forever.
This permanently silences the server log and prevents _write_done_file()
from executing, leaving phase 2 hanging without .done.

Fix: use QueueHandler + QueueListener from stdlib logging.handlers
(Python 3.2+). QueueHandler.emit() does queue.put(record) with no lock
or I/O, returning immediately. QueueListener has a dedicated single
thread as the sole consumer touching the real StreamHandler, making
lock contention impossible.

Changes in _create_log_handler(): stdout/stderr branches now create
a shared QueueListener with unbounded queue, returning QueueHandler
instances to callers. _build_standard_handler() delegates formatter
and filter setup to the real handler in the listener thread.

Closes: #2752

* fix(logger): harden queued stream logging

---------

Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>

---------

Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>
2026-06-24 18:46:02 +08:00
Evo 241c7fb0ce feat(sdk/go): expose set_tags on the filesystem client (#2782)
set_tags shipped stack-wide in #2706 (server, Python SDK, Rust CLI,
openviking_cli) but the Go SDK was the only client surface left without it.
Add Client.SetTags mirroring the Write convention so Go users can write
retrieval tags (replace/append, recursive over directories) without dropping
to Python or the CLI.
2026-06-23 17:58:38 +08:00
Jiahui Zhou 5a433e5a75 docs: add release guide and align SDK tag format (#2765)
* docs: add release guide and align SDK tag format

* fix: restrict main package release tag discovery

* fix: constrain CLI version tag discovery
2026-06-22 17:15:31 +08:00
Evo 4a746d557e feat(sdk/go): expose agent_id/agent_uri peer selector on Find and Search (#2758)
Server FindRequest/SearchRequest accept and use agent_id/agent_uri to
scope retrieval to a peer (_ctx_with_legacy_actor_peer), but the Go SDK
could only set a client-global X-OpenViking-Actor-Peer header and had no
per-call selector. Add AgentID/AgentURI to FindOptions/SearchOptions
(appended for unkeyed-literal compat, mirroring #2703) and forward them
via setString (omit-empty) in Find and Search; add request-body tests.
2026-06-22 15:24:22 +08:00
Jiahui Zhou 02f06488f3 feat: extract standalone python http sdk (#2736)
* feat: extract standalone python http sdk

* fix(python-sdk): restore ovcli.conf compatibility

fix(python-sdk): restore compatibility and lazy-load sdk

fix(python-sdk): restore legacy http client compatibility

docs(python-sdk): add chinese readme
2026-06-22 14:03:05 +08:00
Evo 6234d7a8d5 fix(sdk/go): expose search filters (#2703) 2026-06-18 20:06:19 +08:00
Qin Haojie a59fd048f1 feat(sdk): 支持 Go HTTP SDK (#2680)
* feat(sdk): add Go HTTP client

* docs(api): align Go SDK examples with API reference
2026-06-17 16:11:10 +08:00