Commit Graph
193 Commits
Author SHA1 Message Date
Qin Haojie fd098cfd65 fix(cli): preserve structured API errors (#3379)
* fix(error): preserve structured errors in cli

* fix(cli): preserve status for non-json errors
2026-07-22 18:06:48 +08:00
Jiahui Zhou 5390bd5e54 fix: require all retrieval tags in search (#3097) 2026-07-21 11:54:01 +08:00
Qin Haojie 370fe45f6f fix(auth): serialize API key registry writes (#3377)
Prevent concurrent account and user registry updates from racing in AGFS.
2026-07-20 17:51:07 +08:00
huangruitengandhuangruiteng f0d241e4a0 fix(bot): enable logs for config-started gateway (#3319)
Co-authored-by: huangruiteng <huangruiteng@bytedance.com>
2026-07-17 10:56:16 +08:00
ef4d97ebe3 feat(snapshot): support path-filtered commit history (#3271)
* feat(snapshot): support path-filtered commit history

* refactor(snapshot): reuse SDK git log implementation

* fix(snapshot): harden path-filtered log resource limits

* chore: remove stale SDK lock entry

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-07-16 19:53:40 +08:00
t0saki db6c91fa89 fix(mcp): advertise plain-typed tool schemas for strict function-calling APIs (#3288)
FastMCP derives tool input schemas from Python type hints, so Optional/
Union parameters become anyOf nodes with no top-level type, and nested
models become $ref/$defs. Valid JSON Schema, but clients that forward
these schemas verbatim to strict function-calling APIs break: Gemini's
OpenAPI 3.0 subset rejects the whole request (400: schema didn't specify
the schema type field), and n8n's JSON-schema-to-Zod conversion can
silently fall back and drop tool arguments entirely.

Rewrite the advertised schemas after registration: drop null branches,
collapse unions to their most general branch, inline $refs, and ensure
every node carries an explicit type. Runtime argument validation still
uses the original function signatures, so union parameters keep
accepting every branch (e.g. read still takes a bare URI string even
though the schema advertises an array).

Also type recall's other_peer_penalty honestly as
Optional[Union[float, Dict[str, float]]] instead of Optional[Any],
which produced an empty {} schema node.
2026-07-16 12:24:21 +08:00
Qin Haojie d47f2106ee refactor: remove unused and deprecated APIs (#3272)
Delete dead compatibility paths and test-only helpers so unsupported APIs do not remain as accidental contracts.
2026-07-16 10:49:56 +08:00
Qin Haojie ca70bc0649 refactor(embedding): remove unused batch APIs (#3260) 2026-07-15 16:44:57 +08:00
zihengli 540139091f feat(connector): delegate add_resource imports to external Connector (#3084)
* feat(connector): delegate add_resource imports to external Connector

Opt-in integration that routes add_resource data fetching and parsing
to external Connector service; the Connector stages source data and
calls back into OV through the standard add_resource pipeline.

- add ConnectorClient wrapping the control plane's inner doc/add and
  task/info endpoints
- add [connector] config section: enable, connector/tracker endpoint
  URLs, timeout_seconds, poll_interval_ms, allowed_add_types
- route add_resource via Connector when enabled and args.add_type is
  in allowed_add_types; otherwise fall back to the standard pipeline
  with an info log
- track imports as connector_import TaskRecords and poll Connector
  task status in the background until terminal state or timeout

* fix(connector): delegate add_resource imports to external Connector
2026-07-15 16:34:23 +08:00
huangruitengandhuangruiteng abc325826b fix(auth): allow root key on trusted admin targets (#3249)
Co-authored-by: huangruiteng <huangruiteng@bytedance.com>
2026-07-15 11:04:22 +08:00
Jiahui Zhou 1c46d44fbc Fix/reindex preserve owners (#3096)
* fix: preserve reindex content owners

feat: allow trusted admin role assertion

feat: prune orphan vectors during reindex

fix: harden reindex memory body reads

feat: expose reindex prune options in clients

fix(cli): prefer workspace sdk for compat clients

fix: harden reindex prune orphans

* test: align reindex expectations after rebase
2026-07-14 20:38:30 +08:00
huangruitengandhuangruiteng d0305c2f06 fix(mcp): expose context_type filter (#3181)
* fix(mcp): expose retrieval filters

* fix(mcp): limit retrieval scope to context type

---------

Co-authored-by: huangruiteng <huangruiteng@bytedance.com>
2026-07-14 11:17:23 +08:00
huangruitengandhuangruiteng b40b518c45 fix(reindex): honor configured VLM concurrency (#3220)
Co-authored-by: huangruiteng <huangruiteng@bytedance.com>
2026-07-13 17:59:48 +08:00
Zayn Jarvis cc0281ac70 fix(studio): sort limited listings by mtime (#3212)
* fix(studio): sort limited listings by mtime

* fix(client): forward ls ordering options
2026-07-13 16:17:02 +08:00
huangruitengandhuangruiteng 9bbb65ea62 fix: allow owners to reindex user scope (#3204)
Co-authored-by: huangruiteng <huangruiteng@bytedance.com>
2026-07-13 14:35:30 +08:00
t0saki c99e65472b fix(server): default OAuth client scope for scope-less DCR (ChatGPT invalid_scope) (#3210)
#2921 persisted the DCR scope when the registrar sends one and started
advertising scopes_supported=["mcp"] in the PRM document. ChatGPT's DCR
omits the scope field, so its client registers scope-less, then requests
the advertised scope=mcp at /authorize and gets bounced back with
error=invalid_scope before any consent page renders.

- app.py: pass default_scopes=["mcp"] to ClientRegistrationOptions so
  scope-less registrations get the default grant; valid_scopes stays
  unset so clients that register their own scope strings are not
  rejected at DCR time
- provider.py: single-source the scope as MCP_SCOPE; get_client() falls
  back to it for NULL-scope rows, repairing already-registered clients
  without migration or re-registration
- router.py: reuse MCP_SCOPE in the PRM scopes_supported
- tests: provider fallback unit tests + end-to-end scope-less DCR and
  legacy NULL-scope client authorize regressions
2026-07-13 12:49:19 +08:00
huangruitengandhuangruiteng d4c5f23253 fix(content-write): anchor user resources at direct parent (#3176)
Co-authored-by: huangruiteng <huangruiteng@bytedance.com>
2026-07-13 10:09:21 +08:00
Kchenandchenpengfei 20f0603060 修复 ov write 抢锁失败返回 409 / return 409 on write lock contention (#3157)
中文:抢写锁失败时改抛 ResourceBusyError,复用现有 CONFLICT 到 HTTP 409 的错误映射。

English: align ov write lock contention with existing conflict handling used by other resource operations.

Co-authored-by: chenpengfei <chenpengfei@bytedance.com>
2026-07-11 17:11:13 +08:00
t0saki 2a81edc707 Add workspace peer mode for memory plugins (#3099) 2026-07-09 17:53:36 +08:00
Qin Haojie f0cfd09803 fix(reindex): stop chunking memory vectors (#3077) 2026-07-08 14:48:56 +08:00
Qin Haojie 16a0bff812 fix(pack): allow users to import and export permitted URIs (#3078)
Allow USER callers through pack import/export routes while leaving URI ACL enforcement to VikingFS.
2026-07-08 14:45:30 +08:00
t0saki f905562534 feat(plugins): stdio MCP proxy, remote marketplace install, and type-quota recall for memory plugins (#3039)
* feat: add memory plugin mcp harness

* refactor: vendor shared memory plugin modules

* feat: add type quota recall api

* feat: commit codex memory by token threshold

* feat: capture codex tool calls as parts

* feat: add claude skill experience recall

* chore: fix lint in type quota recall server files

* feat: remote marketplace install with unified openviking naming

- Fix root .claude-plugin/marketplace.json git-subdir discriminator key
  ("type" -> "source"); claude plugin validate now passes.
- Unified installer gains --source remote|archive|dev: remote registers a
  synthesized git-subdir marketplace for Claude Code and a git marketplace
  for Codex (no repo clone); archive consumes the slim TOS marketplace zip;
  dev registers the checkout's examples/ directory for both harnesses.
- One marketplace name (openviking) across all modes and harnesses, so the
  plugin id is always openviking-memory@openviking; installer migrates old
  openviking-plugins-local registrations and config.toml sections.
- Restore legacy Claude Code (<2.0) support: claude mcp add (stdio proxy)
  plus node-based hooks merge into ~/.claude/settings.json.
- Restore optional statusline registration (fetches sources on opt-in).
- Checkbox TUI harness selection via /dev/tty with non-tty fallback.
- Add examples/.agents/plugins/marketplace.json so Codex directory installs
  drop the synthetic symlink marketplace.
- Add shared setup wizard (scripts/setup.mjs) for pure-marketplace installs.
- release-tos.yml: upload memory-plugin-shared/install.sh and build/upload
  the memory-plugin-marketplace zip; tos-install.sh prefers it and pins all
  fetches to TOS via OPENVIKING_SHARED_INSTALL_URL.
- CI: bash -n on installer scripts; marketplace contract tests updated.

* fix(installer): register Claude remote marketplace as a directory

File-type marketplaces (bare marketplace.json path) make Claude Code derive
a wrong installLocation and 'marketplace update' fails with EISDIR. Write
the synthesized manifest to <dir>/.claude-plugin/marketplace.json and add
the directory instead; compare registered sources by exact match so the
old file registration migrates cleanly.

* feat(statusline): show model name and native-style context percentage

A custom statusLine replaces Claude Code's native line including its context
indicator, so reproduce it from the statusline stdin payload: 'Fable 5 ·
ctx 42%' right after the health segment, with native color thresholds
(<70% dim, 70-89% yellow, >=90% red). Falls back from used_percentage to
remaining_percentage to token counts, and stays visible in bypass mode
since it describes the CC conversation, not OV. Opt out with
OPENVIKING_STATUSLINE_CTX=off. Line cap raised 80 -> 100 visible chars.

* fix(installer): keep checkout progress off stdout in plugin_dir_on_disk

Callers capture the function's stdout, so ensure_checkout's info lines were
concatenated into the statusline command registered in settings.json.

* fix(installer): re-register codex git marketplace instead of upgrading

Codex doesn't expose which --ref a git marketplace was added with, and
'marketplace upgrade' refreshes the old ref — so a URL match must not skip
re-registration or a ref override installs the wrong snapshot. Also remove
the stale pre-unification plugin cache directory during migration.

* fix(installer): include .agents in codex sparse checkout

A plugin-dir-only sparse checkout omits the repo-root marketplace manifest
and fails with 'marketplace root does not contain a supported manifest'.
Adding --sparse .agents keeps the snapshot slim (~7.5M vs full repo).

* feat(installer): bilingual prompts, dist channel selection, and TOS git marketplace for codex

- Interactive language selection (English/中文, --lang, auto-detected from
  locale); every user-facing prompt is bilingual.
- Download-source selection (--dist github|tos, prompted interactively):
  github keeps the remote marketplaces; tos serves GitHub-blocked regions.
- Credentials step now always shows the current ovcli.conf values (masked
  key) and offers keep-or-reconfigure instead of silently reusing them.
- Codex on TOS installs from a TOS-hosted git repo over dumb HTTP and keeps
  remote updates (codex plugin marketplace upgrade); falls back to the
  archive directory if the repo is unavailable. release-tos.yml builds and
  uploads the single-commit bare repo (repack + update-server-info).
- Claude Code on TOS warns that directory marketplaces cannot auto-update.
- tos-install.sh bootstraps shrink to TOS_BASE + --dist tos.
- Docs (READMEs, agent-integrations pages, image cards, en+zh) now all use
  the single shared installer and drop the deleted wrapper instructions.

* feat(installer): unify all choice prompts on an arrow-key TUI menu

Language, download source, connection mode, keep-or-reconfigure
credentials, statusline enable/replace, and legacy-mode confirmation all
render as the same single-select menu (arrow keys / digit shortcuts /
enter, radio-style highlight) instead of mixed numbered and y/N prompts.
Falls back to numbered input when /dev/tty can't be drawn on and to the
default choice when non-interactive. Free-text fields (URL, API key) stay
line inputs; the harness picker keeps its checkbox multi-select.

* fix(installer): stop piping plugin lists into grep -q under pipefail

grep -q exits on first match and SIGPIPEs the producer, so with pipefail
the 'codex plugin list | grep -q' check read as a miss every time (codex's
list is long; claude's short list masked the bug). Capture the output and
substring-match in bash instead — validation no longer false-warns.

Also: drop the stdio-proxy line from the Done summary; always offer the
install-source menu unless --dist/--source was given (with a checkout the
menu gains a dev option and defaults to it); surface the Claude-on-TOS
no-auto-update warning at source resolution instead of after install.

* fix: unignore examples/memory-plugin-shared/lib and commit the shared modules

The Python build-artifact 'lib/' gitignore rule silently swallowed the
shared plugin module source, so CI checkouts had only the vendored copies
and sync.test.mjs failed with ENOENT on the source directory.

* fix(recall): budget summary/uri fallbacks and sanitize non-finite scores

max_chars is the recall API's contract, but only full fragments counted
toward it — VikingBot's client-side heuristic, faithfully ported, lets
summary and uri fallbacks render far past the budget (repro: max_chars=100
rendered 548 chars). Every fragment now counts; oversized summaries degrade
to uri fragments and entries that can't even fit a uri line are dropped
(reported via stats.dropped). VikingBot itself is intentionally unchanged.

Also run _sanitize_floats over the /recall response like the neighboring
/find and /search routes, so inf/nan scores return 0.0 instead of a 500.
2026-07-07 12:33:59 +08:00
baojun-zhang 6a33ebb7ca Optimize glob walkdir (#3013)
* feat(storage): optimize glob func

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* feat(rgafs): implement paged glob traversal without full tree materialization

* fix(localfs): offload blocking fs operations to spawn_blocking

* feat(glob): cap glob api default node_limit at 256

* feat(sdk): add node_limit options for glob in python and go SDKs
2026-07-06 21:39:16 +08:00
zgy a50e9fd677 feat: add recursive web crawler based on Scrapy (#2836)
* Refactor recursive web import into HTTP accessor

Move ordinary web page import routing into HTTPAccessor and materialize crawled pages as a temporary directory via WebImporter.

Relocate Scrapy/Playwright crawling under parse.accessors.web_crawler, keep trafilatura extraction inside HTMLParser, and avoid repeated ResourceService.add_resource calls.

Add recursive crawl controls, safe request validation, page/download classification, and focused unit coverage.

* Document recursive web crawler options

* fix(web-crawler): stop SSRF sub-resource block from failing whole render

The playwright fallback validated every sub-resource request against the
SSRF guard and raised on the first disallowed host, failing the entire
page render. volcengine docs load a probe resource on an internal host,
so rendering always failed and the crawler stored the static anti-bot
"Please wait..." challenge page as content.

Now a blocked sub-resource is only aborted; the main document and final
URL still gate the result. Also wait past JS interstitials, retry reads
through in-flight navigation, and reject shell/challenge pages instead of
storing them.

* fix(web-crawler): surface renderer error hint on entry-page failure

When Playwright is unavailable, the renderer returns an actionable install
hint via RenderResult.error, but the spider silently kept the static shell
and WebImporter raised only the generic "Failed to fetch entry page". The
hint never reached the user.

Now the spider records rendered.error on the failed page, and WebImporter
appends the entry page's failure reason to the raised message so the CLI
shows the Playwright install instructions.

* fix(web-crawler): surface render hints and enforce crawl limits

* fix(web-crawler): avoid rendering SSR app pages

* perf(web-crawler): bound render concurrency and cap networkidle wait

Playwright renders were dispatched from parse callbacks without any
concurrency limit, so a page with many child links could spawn dozens of
Chromium pages at once (observed peak 28 for a 20-page crawl), risking OOM
on large sites and starting ~2.3x more renders than needed before
max_pages stopped the crawl. Gate renders with a semaphore sized to
config.concurrency and re-check the success limit after acquiring a slot
so queued callbacks skip rendering once the crawl is already done.

Also cap the networkidle wait at 8s: pages with continuous background
activity (e.g. GraphiQL) never go idle and previously blocked until the
full render timeout, turning a ~3s page into ~38s. Content is ready after
domcontentloaded and _wait_past_challenge covers late-arriving text.

Bump default concurrency 5 -> 10.

* fix(web-crawler): route .html/.htm URLs through recursive WebImporter

An explicit .html/.htm URL is detected as DOWNLOAD_HTML via the extension
map, so access() previously only routed URLType.WEBPAGE to WebImporter and
these URLs fell through to single-file download, silently ignoring
depth/max_pages. Route DOWNLOAD_HTML through WebImporter too, treating a
single-page import as the depth=0 case.

* fix(web-crawler): improve HTML extraction and rendering heuristics

- Drop trafilatura favor_precision=True: it stripped the full body of
  link-dense pages, keeping only headers.
- Only render __NEXT_DATA__ pages with Playwright when their static body
  is too thin; SSR/SSG Next.js pages already ship full text.
- Disable Scrapy telnet console to avoid opening port 6023.

* fix(web-crawler): keep code-hosting single-file URLs off recursive crawler

GitHub/GitLab blob and GitHub raw URLs resolve to a single file, not a
site. Route them through the single-file download path instead of the
recursive WebImporter, which otherwise crawls the hosting UI shell.

* docs(resources): add recursive web crawler usage examples

Add depth/max_pages crawl examples to the HTTP, Python SDK, and CLI
blocks in both the zh and en resource API docs, plus path-prefix
filtering and skip_download_links variants.
2026-07-03 19:25:10 +08:00
0279102b21 Fix/restore health identity (#2978)
* fix(server): restore identity resolution in /health endpoint

The /health endpoint was refactored in #2503 which removed the identity
resolution logic. This caused the frontend dashboard to show 'Usage/Audit
未初始化' because the role field was missing from the response.

Restored the identity resolution so that /health returns account_id,
user_id, and role when an API key is provided.

Co-Authored-By: Claude <noreply@anthropic.com>

* test(server): update health endpoint tests for identity resolution

- Test that /health returns identity info when API key is provided
- Test that /health omits identity info when no API key is provided

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: wugj <wugj@g-bits.com>
Co-authored-by: Claude <noreply@anthropic.com>
2026-07-03 14:50:38 +08:00
chenjwandClaude fd73dcf23a Feat/自进化(经验记忆)框架重构 (#2503)
* Add trajectory experience learning redesign doc

* auto-commit before eval 20260607_043406

* auto-commit before eval 20260607_044129

* auto-commit before eval 20260607_123706

* auto-commit before eval 20260607_125514

* auto-commit before eval 20260607_133737

* auto-commit before eval 20260607_144649

* auto-commit before eval 20260607_154631

* Refine streaming memory train merge pipeline

* Refine session train policy optimization architecture

* Add VikingMem ARA paper analysis

* Force merge for mixed extraction memory patches

* auto-commit before eval 20260608_134426

* auto-commit before eval 20260608_142108

* auto-commit before eval 20260608_153909

* auto-commit before eval 20260608_154845

* auto-commit before eval 20260608_170143

* update

* auto-commit before eval 20260611_150946

* auto-commit before eval 20260611_153933

* auto-commit before eval 20260611_154251

* Fix tau2 reward wrapper call

* auto-commit before eval 20260611_193803

* auto-commit before eval 20260611_194939

* update

* auto-commit before eval 20260612_111029

* auto-commit before eval 20260612_112104

* auto-commit before eval 20260612_122603

* auto-commit before eval 20260612_123359

* auto-commit before eval 20260612_124303

* auto-commit before eval 20260612_130257

* Fallback peer routing to first conversation peer

* Route self memory through self peer sentinel

* Keep self sentinel out of peer memory paths

* auto-commit before eval 20260612_154051

* auto-commit before eval 20260612_154850

* auto-commit before eval 20260612_161633

* auto-commit before eval 20260612_184022

* auto-commit before eval 20260612_201845

* auto-commit before eval 20260612_202637

* auto-commit before eval 20260612_204040

* auto-commit before eval 20260612_224621

* Fix locomo progress column initialization

* Add memory field versioning

* auto-commit before eval 20260612_232318

* Simplify locomo progress display

* Remove locomo progress elapsed time

* Batch streaming memory merges by group

* Derive patch merge language from patches

* Detect patch merge language from updated files

* auto-commit before eval 20260613_004339

* auto-commit before eval 20260613_005835

* Persist memory update trace id

* auto-commit before eval 20260613_012722

* auto-commit before eval 20260613_013923

* auto-commit before eval 20260613_014708

* Enforce peer scope after memory merge

* auto-commit before eval 20260613_033402

* auto-commit before eval 20260613_151931

* auto-commit before eval 20260613_164217

* chore: raise vikingbot eval parallelism

* chore: tune vikingbot parallelism to 150

* auto-commit before eval 20260613_185807

* chore: restore vikingbot parallelism default

* feat(locomo): add import progress reporting

* chore(memory): restore profile and preference templates

* Fix tau2 reward JSON serialization

* Refactor tau2 batch memory training

* Stream batch train JSONL events

* Add fast path for batch training case specs

* Optimize streaming train gradient chunking

* Optimize patch merge prompt context

* fix tau2 memory training vectorization

* fix(memory): revert profile preference granularity rules

* bd init: initialize beads issue tracking

* update

* Log memory template fallback failures

* Record all rollout artifacts

* Fix OpenViking peer search forwarding

* Stop tracking Beads local state

* auto-commit before eval 20260616_002037

* Deprecate memory version selector

* Retry transient LoCoMo import HTTP failures

* Add memory schema stage and peer routing

* Organize LoCoMo benchmark outputs

* Restore VikingBot user memory auto recall

* Show elapsed time on LoCoMo progress bars

* Quiet transient import retries

* Shorten LoCoMo progress bars

* Route non-peer memories to self scope

* auto-commit before eval 20260616_124513

* Suppress memory read not found logs

* Limit LoCoMo import memory types

* Rename peer routing schema flag

* Rename peer schema flag to enable_peer

* Rename schema peer flag to peer_enabled

* auto-commit before eval 20260616_135946

* auto-commit before eval 20260616_140641

* auto-commit before eval 20260616_141753

* Show cached baseline eval at start of training

* Preserve remote policy contents

* Show failed work in progress bars

* Hide zero failed progress counts

* Disable tau2 service progress by default

* Reuse policy lock for policy deletes

* feat: add session skill extraction to Memory V3 streaming trainer

- Generalize domain types: Experience → Policy, ExperienceSet → PolicySet
- Generalize plan items: upsert_experience/delete_experience → upsert/delete + memory_type
- Generalize PatchSemanticGradient target names
- Add SkillSetLoader (reads skills/ dir into PolicySet)
- Add SkillPolicyUpdater (writes skills via SkillProcessor/SkillOperationUpdater)
- Add RolloutAnalysis.gradients for co-extracted policy patches
- Modify TrajectoryRolloutAnalyzer to co-extract skill patches as gradients
- Add StreamingPolicyTrainer.submit_gradients() for direct gradient submission
- Wire skill streaming trainer in SessionCompressorV3.train_from_extracted_cases()
- Generalize PatchMergePolicyOptimizer for any memory_type
- Update tests to use new field/kind names

Co-authored-by: Claude <noreply@anthropic.com>

* Persist experience reminders in tau2 rollouts

* Enable tau2 epoch test eval by default

* Persist train rollout artifacts incrementally

* Ensure tau2 vikingbot user simulator deps

* Auto repair tau2 vikingbot simulator deps

* Avoid blocking tau2 vikingbot service loop

* Avoid tau2 gym reset when loading cases

* Clean tau2 rollout commit messages

* Clean tau2 tool trajectory serialization

* Retry vikingbot VLM rate limits

* Refine tau2 training case selection

* Promote vikingbot hook execution log level

* Improve VLM rate limit retry detection

* Update trajectory analysis prompt format

* Limit tau2 service logs to warnings

* Run tau2 vikingbot rollouts on service loop

* Lower vikingbot experience recall threshold

* Offload tau2 vikingbot blocking setup

* Retry tau2 LiteLLM rate limits

* Pin trajectory and experience outputs to Chinese

* Retry tau2 rate limits indefinitely

* Highlight tau2 training accuracy summaries

* Hide redundant avg reward console metrics

* Tighten memory extraction templates

* Reduce tau2 memory template noise

Evaluation: benchmark/tau2/train/run_batch_train_eval.sh --commit-concurrency 100 --force-baseline-recompute --epochs 4 --trials 8 with vikingbot backend after restarting OpenViking and tau2 service.

Result: epoch 1 test accuracy improved to 58.75% ± 4.84pp (94/160), compared with prior epoch 1 test reference 46.88% (75/160). Baseline in this run was 51.25%; epoch 0 test was 45.62%.

* Constrain tau2 memory extraction sources

Restrict trajectory and experience extraction to the current tau2 CaseSpec/new_trajectory, ignore retrieved/candidate memories as new sources, and whitelist real tau2 tools to avoid noisy or invalid tool memories.

Evaluation:
- Command: benchmark/tau2/train/run_batch_train_eval.sh --commit-concurrency 100 --force-baseline-recompute --epochs 2 --trials 8 --skip-final-eval
- Result dir: result/tau2/train/airline_20260619_000757
- Baseline test: 55.00% (88/160)
- Epoch0 train: 66.67% (20/30)
- Epoch0 test: 56.25% (90/160)
- Epoch1 train: 60.00% (18/30)
- Epoch1 test: 60.00% ± 3.54pp (96/160), better than previous best 58.75%.

* Preserve tau2 train non-run results

* Improve memory extraction guardrails

Run: result/tau2/train/run_airline_20260619_044051

tau2 airline epoch1 test/final: 62.50% (100/160), baseline cache hit 55.00% (88/160), delta +7.50pp; exceeds previous best 60.00% by +2.50pp.

* Support train split eval in tau2 batch runs

* Add slot support to tau2 vikingbot launcher

* Copy OpenViking configs for tau2 slots

* Tune tau2 case1 memory extraction

Run: result/tau2/train_1/run_airline_20260619_201546

Metric: train case1, slot1, 2 epochs, final train eval 3/8 = 37.50%, delta +37.50pp.

* Advise tau2 train case1 best result

Best run: result/tau2/train_1/run_airline_20260619_201546, final 3/8 = 37.50%.

* Tune tau2 memory gate extraction

* Advise tau2 train case1 50pct result

* Guard failed write experience branches

* Advise tau2 train case1 100pct result

* Guard tau2 oracle training memories

* Recall trajectory diagnostics for tau2 rollouts

* Recall tau2 case specs for training rollouts

* Guard evaluated tau2 final states

* Inject compact tau2 oracle checklists

* Stabilize tau2 slot train multi-case runs

* Guard tau2 case10 oracle terminal state

* Use supported tau2 training memory types

* Match tau2 oracle writes by expected subset

* Autofill tau2 case10 oracle writes before done

* Enable tau2 case10 guard for train split

* Record slot1 S008 case10 guard best advice

* Generalize tau2 S008 oracle terminal guard

* Record slot1 S008 general guard best advice

* Remove tau2 benchmark oracle guard

* Prevent training ground truth memory recall

* Refine tau2 training memory extraction

* Fix epoch train rollout artifact stage

* Refine memory training rollout pipeline

* update

* auto-commit before eval 20260623_120317

* fix sdk read_raw for memory metadata

* use visible case links for experience recall

* auto-commit before eval 20260623_225354

* tau2/train: cap run_batch_train_eval rollout concurrency at 100

* update

* update

* update

* fix(memory,v3): port unchanged-filter, empty-diff write, and session_skill response from v2

- Port _same_memory_file filter to compressor_v3._build_memory_diff so
  no-op merges/patches don't inflate memory_diff.json update counts
- Write memory_diff.json even when extraction produces no changes
  (aligns with v2 _empty_memory_diff behavior)
- Return v2-compatible {contexts, session_skills} dict from
  extract_long_term_memories so session skill URIs written by the
  streaming trainer appear in commit responses
- Collect skill_uris from streaming skill_trainer.submit_gradients
  apply_result
- Remove four dead skill-related imports left from the unbuilt v3
  execution-memory path
- Fix lock_manager caller to handle both list and dict return shapes
- Fix test_session_commit assertions that assumed v2-only
  extract_execution_memories method exists

* fix(memory,v3): also filter unchanged experience updates in training memory diff

* train: finish rollout and memory refactor

* memory: refine runtime-visible extraction prompts

* train: constrain communication memory extraction

* auto-commit before eval 20260629_235623

* memory: address training review fixes

* update

* update

* message: reuse part deserializer

* train: snapshot memory prompt yaml

* prompts: restore memory yaml templates from main

* memory: scope streaming update results

* update

* update

* session: train canonical merged cases

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-07-03 11:27:17 +08:00
xierfloatandwugj a6e72f929e fix(server): persist OAuth DCR client scope to fix invalid_scope for MCP clients (#2921)
OAuth Dynamic Client Registration silently dropped the client `scope`, so any
spec-compliant MCP client that requests a scope (e.g. scope=mcp) failed
/authorize with invalid_scope. The MCP SDK's client.validate_scope() requires
requested scopes to be a subset of the registered client.scope, which was always
None because register_client() never stored it.

- storage.py: add `scope` column to oauth_clients (+ idempotent migration) and
  persist it in register_client()
- provider.py: pass client_info.scope on registration; return scope from
  get_client() so validate_scope() sees the registered scope
- router.py: advertise scopes_supported=["mcp"] in the RFC 9728 PRM document
- tests: assert scope round-trips through register/get

Co-authored-by: wugj <wugj@g-bits.com>
2026-07-02 16:44:19 +08:00
Qin Haojie 8186cfbdeb feat(auth): support seeded API key generation (#2932)
* feat(auth): support seeded API key generation

Allow admin key issuance flows to accept an optional seed so clients can derive predictable user API keys when needed, while preserving random generation by default.

* fix(go-sdk): preserve explicit empty seed payloads

Use pointer seed options so callers can distinguish omitted seeds from explicit empty seeds, matching the Admin API behavior.
2026-07-02 10:47:18 +08:00
t0saki 78321080d5 feat(mcp): auto-ingest local-file uploads via signed temp_upload token (#2925)
Collapse the MCP add_resource local-file flow to a single step: the agent
POSTs the file to a token-authorized temp_upload URL and the server finishes
ingestion in the same request, so no second add_resource(temp_file_id) call
is needed.

- Merge the signed upload into POST /api/v1/resources/temp_upload via a
  two-layer auth dependency (API key first, else a one-time ?token=), and
  remove the dedicated temp_upload_signed route. The API-key path is
  unchanged (still returns temp_file_id) for the CLI and import_ovpack.
- Bind to/reason/actor_peer_id into the upload token so auto-ingest keeps
  the caller's target, reason, and peer scope; on the token path identity
  and actor peer come only from the token, never from upload request
  headers.
- Extract ingest_temp_upload() helper and surface add_resource business
  errors instead of reporting a false success (mark_failed on error, and
  route the result through response_from_result / the MCP error string).
- Update en/zh docs for the single-step flow.
2026-07-01 20:36:15 +08:00
Qin Haojie 6223537a00 feat(fs): 新增 attrs 元信息接口 (#2906)
* feat(fs): add attrs metadata endpoint

* feat(fs): move set tags under attrs API
2026-07-01 11:57:04 +08:00
baojun-zhang 843a4a3a39 feat(encrypt): Protect encrypted writes with temp-file publish and dual-path locking (#2894)
* feat(encrypt): Protect encrypted writes with temp-file publish and dual-path locking

* fix(storage): reuse outer lock handles, keep encrypted temp files out of user space, preserve encrypted-only path locking, and add cross-layer temp-path tests

* fix(storage): reuse rollback lock handles and gate encrypted wrapper creation on replace publish support

* fix(storage): reuse rollback lock handles, align encrypted temp lock paths, and use localfs replace publish semantics
2026-07-01 11:27:26 +08:00
Qin Haojie d7b96d7715 feat(server): add user add target defaults (#2888)
* feat: add user add target defaults

Allow deployments and per-user settings to provide default add targets while keeping explicit request targets authoritative.

* test: remove low-value CLI config parsing test

* refactor: unify user config option naming
2026-06-29 20:32:00 +08:00
3afe85fbd0 perf(content-write): anchor semantic refresh at the file's direct parent / 写入语义刷新锚点改为文件直接父目录 (#2864)
[EN]
#2863 made content-write refresh recursive but kept the anchor collapsed to the
resource project root. As a result, writing a single deeply-nested file makes the DAG
recursively walk the ENTIRE project subtree; and because vectorize tasks are
batch-dispatched only at the end of a DAG run, the changed file's L2 vector is not
enqueued for embedding until that whole subtree walk plus the full bottom-up overview
chain (leaf -> ... -> project root) completes.

This change anchors the refresh at the written file's DIRECT PARENT directory instead.
The changed file is then a direct child of the DAG run root, so its own L2 vector and the
parent's L0/L1 are produced from a single-directory run; ancestor summaries still refresh
via the existing parent bubble. The final set of refreshed directories and re-embedded
vectors is unchanged, but the changed file's vector latency drops from a
whole-project-subtree run to a single-directory run.

Details:
- New `anchor_to_parent` flag on `_resolve_root_uri`, used only by the two write paths
  (`write` / `_create_and_write`). `set_tags` keeps the project-root collapse that the
  derived `.abstract.md` sidecar mapping relies on.
- Removes the `recursive=True` introduced by #2863, which is no longer needed once the
  refresh is anchored at the correct (direct-parent) directory.

[中文]
#2863 把 content-write 的刷新改成了递归,但锚点仍然塌缩到资源项目根。于是写一个深层嵌套
文件会让 DAG 递归遍历整棵项目子树;又因为向量化任务是在一趟 DAG run 结束时才批量派发的,
被改文件的 L2 向量要等到整棵子树遍历 + 自底向上的 overview 链(叶子 -> … -> 项目根)全部
跑完之后,才会入嵌入队列。

本改动把刷新锚点改为被写文件的【直接父目录】。这样被改文件就是 DAG run 根目录的直接子文件,
它自己的 L2 向量和父目录的 L0/L1 只需一趟单目录 run 即可生成;祖先目录摘要仍然走现有的父
目录冒泡刷新。最终被刷新的目录集合、被重嵌的向量集合都不变,但被改文件向量的延迟从"整棵
项目子树 run"降到了"单目录 run"。

细节:
- 在 `_resolve_root_uri` 上新增 `anchor_to_parent` 开关,仅两个写路径(`write` /
  `_create_and_write`)启用;`set_tags` 保留塌缩到项目根的语义(派生 `.abstract.md` 边车
  映射依赖它)。
- 移除 #2863 引入的 `recursive=True`——锚点定位正确后不再需要它。

Co-authored-by: chenpengfei <chenpengfei@bytedance.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 11:10:57 +08:00
Jiahui Zhou b2c9768e55 fix: refresh content writes recursively (#2863) 2026-06-26 19:53:12 +08:00
Qin Haojie f9c1a60658 fix: narrow legacy agent id compatibility (#2839)
Treat agent_id as an actor peer alias in new clients while keeping X-OpenViking-Agent handling only on server ingress for old clients.
2026-06-26 14:37:57 +08:00
Haoyu Zhangandzhanghaoyu.la aa53e7aede feat: 实现 commit、restore、show 文件系统多版本管理功能 (#2756)
* feat: 实现 commit、restore、show 文件系统多版本管理功能

fix: 修复commit时删除文件

fix: commit 的 fast path 1 添加 Racy-clean 机制

fix: 将 sdk 中的 git 命令改为 snapshot 命令,同步修改单测

fix: 多版本管理的文件存储目录改为 .ovgit

feat: snapshot cli 渲染

fix: 修复 restore 时将删除的文件回滚时,目录不存在的问题

feat: restore 命令的 project_dir 参数改为可选,不传时默认全目录回滚

feat: 更新文档

fix: 删除暂未使用的配置参数

feat: 新增示例脚本

fix: 修复示例代码

fix: 修复 restore 返回的 task id 任务完成状态

feat: 在 restore 修改文件系统时加锁

fix: fix openviking_sdk

* feat: 将git多版本管理功能改为默认打开,并复用agfs的配置参数作为默认值

* fix: restore 命令改为先完成 ref 一致性协议再写回 VFS;object store 并发改为使用唯一 temp path

* fix: 在 git 配置检验层去除未实现的cas_mode = "redis_lock"模式

* fix: 在 Rust GitService 边界统一校验 account

* fix: 当前commit不支持通过 path 传入目录,增加报错信息

* fix: 将git文件默认存储路径统一为 .ovgit

* fix: restore 时写入 VFS 失败时返回详细的报错,并继续触发 reindex

* fix: 校验 commit、restore、show 的路径

* feat: 实现 commit 时指定目录

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
2026-06-25 11:28:04 +08:00
87329714dd feat(grep): integrate VikingDB bm25 keyword search for grep engine (#2144)
* feat(grep): integrate VikingDB bm25 keyword search for grep engine

* fix(grep): address CI review feedback: max-size eviction to _count_cache, use Literal, Split regex alternation into individual keywords for bm25 (max 10)

* fix(schema): use dynamic __version__ for schema_version and handle dev suffixes in version comparison

* fix(schema): upsert data to vikingdb lack of content

* chore: add benchmark for retrieval

* fix(grep): vikingdb return 200 and no results means no matching content, not necessary to fallback to local fs

* fix(benchmark): sub uri args; add report

* refactor: code format by ruff

* optimize: move grep config (engine and switch_to_remote_threshold) to ov.conf

* optimize: auto adapt remote_return_limit by agg API; rm unnecessary params in keywords search

* fix: adjust benchmark scripts

* fix(grep): store full content for BM25; use PathScope depth; reduce redundant API calls

* refactor: new benchmark

* fix: step1 add resource by real code data

* feat(benchmark): split grep benchmark into effectiveness/performance suites with async reindex

* optimize (benchmark): adjust keywords and ground truth for testing

* fix: truncate 64KB for content field

* optimize: effectiveness add resource plainly

* optimize: change param use of SearchByKeywords from "keywords" to "query"

* optimize(benchmark): refactor effectiveness scripts

* optimize: ensure raw data for content field

* optimize: fulltext analyzer's stop-words only use symbols

* fix: adapt to new ov cli for benchmark

* optimize: reuse file content to avoid re-read AGFS file

* optimize: tune grep vikingdb defaults and refresh bm25 benchmark scripts

* optimize: benchmark client timeout

* update README

* fix: rm unused param

* fix: default values in docs

* optimize: increase truncate byte size to 1MB for content field for VikingDB

* fix(logger): harden queued stream logging (#2786)

* fix(logger): replace StreamHandler with QueueHandler+QueueListener to prevent thread deadlock

When log.output='stdout' (default) and the server is managed by systemd,
concurrent log writes can deadlock because logging.StreamHandler holds a
thread lock across stream.flush() which blocks on systemd-piped file I/O.

During session.commit() phase 2, multiple async coroutines (memory
extraction, summarization) concurrently call logger.info()/warning()
with large payloads. The first thread's flush() blocks on the pipe,
while all subsequent threads block on handler.acquire() forever.
This permanently silences the server log and prevents _write_done_file()
from executing, leaving phase 2 hanging without .done.

Fix: use QueueHandler + QueueListener from stdlib logging.handlers
(Python 3.2+). QueueHandler.emit() does queue.put(record) with no lock
or I/O, returning immediately. QueueListener has a dedicated single
thread as the sole consumer touching the real StreamHandler, making
lock contention impossible.

Changes in _create_log_handler(): stdout/stderr branches now create
a shared QueueListener with unbounded queue, returning QueueHandler
instances to callers. _build_standard_handler() delegates formatter
and filter setup to the real handler in the listener thread.

Closes: #2752

* fix(logger): harden queued stream logging

---------

Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>

---------

Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>
2026-06-24 18:46:02 +08:00
Qin Haojie 5f8547a48a feat(session): expose memory diff uri (#2789) 2026-06-23 20:34:40 +08:00
Denys Kashkovskyiandqin-ctx 681bd1ee5f fix(queuefs): skip semantic generation for non-directory memory URIs (#2734) (#2735)
* fix(queuefs): skip semantic generation for non-directory memory URIs

A memory file reindexed with mode=semantic_and_vectors enqueues a
context_type="memory" semantic message whose URI is a file. on_dequeue
routes it to _process_memory_directory, which ls()'d the file, raised, and
the outer handler re-enqueued it as a transient error — forever, starving
the semantic queue. The entry is AGFS-persisted, so it survives a restart
and blocks `reindex --wait` and memory writes that wait on the queue.

_process_memory_directory now stat()s the URI first: a confirmed
non-directory (or missing) URI is marked done and skipped instead of
listed, so the message acks and the queue drains. When stat is unavailable
it falls through to the existing ls() path, leaving current behavior
unchanged.

Fixes #2734

* fix(queuefs): preserve retries for stat failures

* fix(reindex): skip memory semantics for file targets

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-06-23 18:09:39 +08:00
LinQiang391andLinQiang391 7fa34c9520 fix(session): make failed archives skippable and tune OpenClaw auto-commit (#2775)
Treat failed session archives as terminal skipped state so later commits can continue, and replace OpenClaw's fixed auto-commit token threshold with a context-window ratio while tolerating the deprecated config key.

Co-authored-by: LinQiang391 <linqiang391@users.noreply.github.com>
2026-06-23 12:00:29 +08:00
DuTao 027e21bb7e feat(bot): Simplify the bot auth check, support ov's trusted auth_mode. (#2769)
* 增加bot的配置校验。优化bot的逻辑

* 去除 mode的逻辑依赖

* 调整dev的提示文案

* fix:
1. trusted localhost允许 without root key;
2. 调整文档废弃root_api_key;

* 现在 proxy 生成 openviking_connection 时会带上当前 OpenViking server 的 server_url,VikingBot 收到 request-scoped connection 后会优先使用这个 URL,不会再 fallback 到静态 bot.ov_server.server_url 去请求另一台 server。

* fix ipv6

* fix trusted模式chat指令使用root_api_key
2026-06-23 11:59:35 +08:00
Zayn Jarvis 79f7bdd184 fix(auth): align role serialization with string roles (#2728) 2026-06-19 13:30:28 +08:00
MaojiaShengandclaude-sonnet-4-6 ab656e240d refactor(auth): introduce plugin-based authentication architecture (#2709)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
2026-06-18 20:05:17 +08:00
Jiahui Zhou 21c58bd8f6 Set tags (#2706)
* feat(vectordb): add partial update api

fix(vectordb): support partial updates across adapters

fix(vectordb): return structured update results

test(vectordb): cover update result behavior

* feat(vectordb): support partial upsert semantics

* feat(content): support explicit search tags

* refactor unify search tag update api

* refactor(content): drop unrelated peer_id from semantic refresh

* fix(content): normalize set-tags targets and cli output
2026-06-18 17:48:49 +08:00
AutoCoder ecced9930a feat(code-tools): add code navigation endpoints (#2671)
Add HTTP APIs for code outline, search, and expansion backed by the existing AST tooling.

Expose the same capabilities through the opencode plugin and cover the new routes, parser behavior, and plugin wiring with tests.
2026-06-17 16:12:19 +08:00
fujiajie666 2583da8459 Feature/wiki link (#2558)
* memory-resource记忆链接

* ov write, rm 更新 .overview

* 更新docs

* bug fix

* 更好的利用时间,摘要信息进行memory提取

* 合并

* 通过session.commit封装 --reason

* 回滚vlm代码

* 回滚rust代码

* bug fix

* 兼容peers, user 作用域

* bug fix

* bug fix

* bug fix

* bug fix

* format ruff fix

* --reason 使用同一个session_id,ruff修正

* --reason 使用同一个session_id,ruff修正,peer memory

* ruff修正
2026-06-16 23:07:30 +08:00
Zayn Jarvis 56c903afc6 fix(cli): normalize skill zip paths (#2615)
* fix(cli): normalize skill zip paths

* refactor: share relative path sanitization

* refactor: centralize safe viking uri joins

* test: cover posix skill upload paths
2026-06-15 19:14:16 +08:00
agent a4aefac1f7 feat(session): Support image message extraction (#2578)
* Support image message extraction

* fix: fix image url

* fix: bug

* fix: image parts readme
2026-06-15 18:03:27 +08:00
Qin Haojie 43a93d7ad9 feat(resource): 支持飞书用户 token 导入 (#2549)
* feat(resource): 支持飞书用户 token 导入

* feat(resource): 支持飞书用户 token watch

* fix(feishu): allow one-time user token imports

* test(feishu): trim redundant token coverage
2026-06-15 16:34:27 +08:00
Qin Haojie 058cd1f5ea feat(migration): add legacy user-peer migration (#2610)
* feat(migration): add legacy user-peer migration

* test(migration): trim redundant migration tests
2026-06-15 13:21:33 +08:00