Commit Graph
84 Commits
Author SHA1 Message Date
Zayn JarvisandClaude Fable 5 03bd469417 fix(openclaw-plugin): drop SecretRef exec resolver from packaged plugin (#3849)
Marketplace install scanners (ArkClaw) block plugins whose shipped code
contains child_process. Keep env/file SecretRef sources; configuring
{source:"exec"} now fails with a clear error pointing at env/file.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-06 18:50:38 +08:00
agent 61c42e3bb0 feat(openclaw): add experience memory tools (#3827) 2026-08-06 15:52:31 +08:00
Ziyang Guo abc387955d feat(openclaw-plugin): SecretRef support for config.apiKey (#3522) (#3618)
Issue #3522 — the OpenClaw plugin's `config.apiKey` only accepted a plain
string, resolved through local `${ENV_VAR}` interpolation. `INSTALL*.md`
documented this as a known limitation: users who store their other OpenClaw
provider credentials (LLM, TTS, MCP servers) through the standard
`{source, id[, provider]}` SecretRef mechanism (env / file mount /
exec-backed vault such as 1Password, Vault, gopass) had to keep the
OpenViking key as cleartext inside `openclaw.json`.

### config.ts — `string | OpenVikingSecretRef` widening

* Add `OpenVikingSecretRef = "env"|"file"|"exec"` discriminated union type,
  matching the shape OpenClaw core uses for its own credential fields
  (`env` + `file` implemented in-plugin, `exec` forwarded to `child_process`
  so providers like `@transmitt0r/openclaw-plugin-onepassword` can manage
  the OpenViking key without SDK coupling).
* Add `resolveSecret()` resolver with explicit, actionable errors:
  - env: unset var = throw, no silent empty fallback
  - file: `~` expanded, UTF-8 read, whitespace trimmed; unreadable file
    rethrows with the OpenViking field name prefixed so config misconfigs
    surface with a clear label and path
  - exec: lazy `require("node:child_process").execFileSync(provider,[id])`,
    stdout trimmed, 15s timeout; errors prefixed with provider + id
  - unknown source / missing id / missing exec provider = explicit throw
* `memoryOpenVikingConfigSchema.parse()` widens `rawApiKey` to
  `string | OpenVikingSecretRef`, then passes it through
  `resolveSecret(rawApiKey, "config.apiKey")` *before* the existing
  `resolveEnvVars` pass. Plain strings transparently fall through
  `resolveSecret` unchanged, so `${ENV_VAR}` interpolation is preserved
  100% backward-compatibly.
* `OPENVIKING_API_KEY` env fallback is unchanged and triggers only when the
  `apiKey` config key is absent — a user who deliberately sets `apiKey: ""`
  still gets "" (explicitly unauthenticated), not the env fallback.
* `uiHints.apiKey.help` documents the SecretRef shape and recommends it.

### openclaw.plugin.json — widening schema + UI hints

* `configSchema.properties.apiKey` becomes `oneOf: [string, env ref, file ref, exec ref]`.
  Each object variant has a `title`, `additionalProperties: false`,
  `required`, and explicit description per field, so OpenClaw's config UI
  can render them individually instead of showing a generic JSON object blob.
* `uiHints.apiKey.help` matches the new config.ts wording.

### INSTALL.md / INSTALL-ZH.md — SecretRef usage tables

Replace the old "plaintext / chmod 0600" caveat bullet with a 3-row table
(env / file / exec) showing example JSON + notes (Kubernetes secretKeyRef
mount for `file`, 1Password `op://` URL convention for `exec`). The
backward-compat string path is retained at the end of the new bullet so
existing deployments that haven't migrated yet still get the old permission
advice — no surprise behaviour for upgrading users.

### tests/ut/config.test.ts — SecretRef regression suite (10 new cases)

Under a new `describe("… SecretRef (#3522)")`:

1. Backward compat: `${OV_KEY}` interpolation still resolves.
2. env source — happy path with a fresh env var.
3. env source — unset var throws, no silent fallback.
4. file source — real `mkdtemp`-created file, trimmed whitespace. Cleanup
   in `afterEach`.
5. file source — missing-path error message contains readable label + path.
6. exec source — `vi.spyOn(child_process.execFileSync)` asserts provider +
   args, stdout trimmed.
7. exec source — missing `provider` field errors.
8. Schema validation — unknown `source` and missing `id` each throw with
   error messages that name the problem.
9. Env fallback boundary — explicit `apiKey: ""` is NOT overridden by
   OPENVIKING_API_KEY, but `apiKey` absent IS (backward-compat behaviour
   contract pinned with a test so future refactors can't regress).

Covers every branch inside `resolveSecret()`, plus the backward-compat
contracts issue #3522 called out.
2026-07-30 16:21:06 +08:00
Hao Zhe 3b2571b36e feat(openclaw): add catalog icon (#3362) 2026-07-20 14:55:30 +08:00
Hao Zhe ebe7fa2a7d fix(plugins): align OpenCode and OpenClaw contracts (#3232) 2026-07-17 17:06:27 +08:00
Qin Haojie b27e326e4d fix(openclaw): restore peer_role routing (#3252)
* fix(openclaw): restore peer_role routing

The plugin refactor stopped applying peer_role to message attribution and data-plane actor headers, causing assistant mode to tag user messages and route every request as the agent. Restore role-aware routing across context and tool flows.

* fix(openclaw): close peer routing isolation gaps

* fix(openclaw): separate message peers from actor scope
2026-07-15 17:39:13 +08:00
huangruitengandhuangruiteng 092ec1db6d fix(openclaw): send peer_id for session messages (#3115)
Co-authored-by: huangruiteng <huangruiteng@bytedance.com>
2026-07-10 15:06:40 +08:00
Evo f8ae35c274 fix(openclaw-plugin): require OpenClaw 2026.5.27 (#3021) 2026-07-07 21:35:04 +08:00
Carateffee 1a11b1ba3d fix(openclaw-plugin): support config headers (#3044) 2026-07-07 13:42:55 +08:00
AutoCoder 2d3fa8b17f Store OpenClaw tool parts as assistant messages (#2934) 2026-07-02 09:07:42 +08:00
87329714dd feat(grep): integrate VikingDB bm25 keyword search for grep engine (#2144)
* feat(grep): integrate VikingDB bm25 keyword search for grep engine

* fix(grep): address CI review feedback: max-size eviction to _count_cache, use Literal, Split regex alternation into individual keywords for bm25 (max 10)

* fix(schema): use dynamic __version__ for schema_version and handle dev suffixes in version comparison

* fix(schema): upsert data to vikingdb lack of content

* chore: add benchmark for retrieval

* fix(grep): vikingdb return 200 and no results means no matching content, not necessary to fallback to local fs

* fix(benchmark): sub uri args; add report

* refactor: code format by ruff

* optimize: move grep config (engine and switch_to_remote_threshold) to ov.conf

* optimize: auto adapt remote_return_limit by agg API; rm unnecessary params in keywords search

* fix: adjust benchmark scripts

* fix(grep): store full content for BM25; use PathScope depth; reduce redundant API calls

* refactor: new benchmark

* fix: step1 add resource by real code data

* feat(benchmark): split grep benchmark into effectiveness/performance suites with async reindex

* optimize (benchmark): adjust keywords and ground truth for testing

* fix: truncate 64KB for content field

* optimize: effectiveness add resource plainly

* optimize: change param use of SearchByKeywords from "keywords" to "query"

* optimize(benchmark): refactor effectiveness scripts

* optimize: ensure raw data for content field

* optimize: fulltext analyzer's stop-words only use symbols

* fix: adapt to new ov cli for benchmark

* optimize: reuse file content to avoid re-read AGFS file

* optimize: tune grep vikingdb defaults and refresh bm25 benchmark scripts

* optimize: benchmark client timeout

* update README

* fix: rm unused param

* fix: default values in docs

* optimize: increase truncate byte size to 1MB for content field for VikingDB

* fix(logger): harden queued stream logging (#2786)

* fix(logger): replace StreamHandler with QueueHandler+QueueListener to prevent thread deadlock

When log.output='stdout' (default) and the server is managed by systemd,
concurrent log writes can deadlock because logging.StreamHandler holds a
thread lock across stream.flush() which blocks on systemd-piped file I/O.

During session.commit() phase 2, multiple async coroutines (memory
extraction, summarization) concurrently call logger.info()/warning()
with large payloads. The first thread's flush() blocks on the pipe,
while all subsequent threads block on handler.acquire() forever.
This permanently silences the server log and prevents _write_done_file()
from executing, leaving phase 2 hanging without .done.

Fix: use QueueHandler + QueueListener from stdlib logging.handlers
(Python 3.2+). QueueHandler.emit() does queue.put(record) with no lock
or I/O, returning immediately. QueueListener has a dedicated single
thread as the sole consumer touching the real StreamHandler, making
lock contention impossible.

Changes in _create_log_handler(): stdout/stderr branches now create
a shared QueueListener with unbounded queue, returning QueueHandler
instances to callers. _build_standard_handler() delegates formatter
and filter setup to the real handler in the listener thread.

Closes: #2752

* fix(logger): harden queued stream logging

---------

Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>

---------

Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>
2026-06-24 18:46:02 +08:00
Evo 81a9dd29ec fix(openclaw): merge runtime query config updates (#2673) 2026-06-24 01:31:03 +08:00
LinQiang391andLinQiang391 7fa34c9520 fix(session): make failed archives skippable and tune OpenClaw auto-commit (#2775)
Treat failed session archives as terminal skipped state so later commits can continue, and replace OpenClaw's fixed auto-commit token threshold with a context-window ratio while tolerating the deprecated config key.

Co-authored-by: LinQiang391 <linqiang391@users.noreply.github.com>
2026-06-23 12:00:29 +08:00
Mingjian Que ac208dd184 test(openclaw): restore tool placeholder capture contract (#2747) 2026-06-20 21:06:54 +08:00
Mingjian Que 4ce2832c7f docs(openclaw): restore explicit memory write guidance (#2746) 2026-06-20 21:05:17 +08:00
Mingjian Que e4c98c6031 fix(openclaw): honor auto-recall timeout config (#2743) 2026-06-20 16:36:12 +08:00
EurakaxunandEurekaxun 5179a79d97 fix(openclaw): preserve heartbeat-looking user messages (#2660)
Co-authored-by: Eurekaxun <eurekaxun@163.com>
2026-06-20 16:04:33 +08:00
LinQiang391andCursor b55d379160 chore(openclaw-plugin): release 2026.6.18 and raise OpenViking floor to 0.4.1 (#2705)
Bump plugin to 2026.6.18 across package.json, package-lock.json and install-manifest. Raise minOpenvikingVersion 0.2.9 to 0.4.1 and add recommended OpenClaw/OpenViking versions. Update the guide version matrix and add a manifest-contract test that locks the compatibility floors/recommended versions and keeps pluginVersion in sync with package.json version.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-18 17:14:49 +08:00
Mingjian Que d9e40b0974 refactor(openclaw): add setup and routing modules (#2654)
* refactor(openclaw): add setup and routing modules

* docs(openclaw): align docs and healthcheck with peer routing

* refactor(openclaw): wire modular runtime into core

* fix(openclaw): package plugin runtime directory
2026-06-17 10:26:23 +08:00
Mingjian Que ccf00aa8a4 feat(openclaw): add TOS release installer flow (#2653) 2026-06-17 01:07:50 +08:00
Mingjian Que 2d130feb62 test(openclaw): cover install contracts and runtime docs (#2647)
* test(openclaw): cover package install contract

* refactor(openclaw): extract query result formatters

* docs(openclaw): document runtime RPC and install contracts

* docs(openclaw): complete websocket rpc API reference
2026-06-16 22:15:01 +08:00
Mingjian Que 740b7fcbe7 feat(openclaw): add runtime query config (#2646) 2026-06-16 20:47:47 +08:00
Mingjian Que 3727d4bb62 feat(openclaw): enhance recall trace HTTP routes (#2645) 2026-06-16 20:07:56 +08:00
Mingjian Que 06c4fc10ef feat(openclaw): add feature gates RPC (#2642) 2026-06-16 19:13:53 +08:00
Qin Haojie 794ee3ee41 fix(openclaw): default peer role to assistant (#2626) 2026-06-15 21:54:55 +08:00
Mingjian Que 66622aa210 test(openclaw): cover default memory auto recall search (#2600) 2026-06-14 10:40:48 +08:00
Qin HaojieandMijamind719 8353976bc8 feat(plugins): use actor peer scope (#2595)
* feat(plugins): use actor peer scope

* docs(openclaw): clarify actor peer recall scope

---------

Co-authored-by: Mijamind719 <mijamind@163.com>
2026-06-14 10:15:27 +08:00
Mingjian Que 47c88843d0 docs(openclaw): refresh OpenViking operator guidance (#2591)
* docs(openclaw): refresh OpenViking operator guidance

* fix(openclaw): include recall trace in install manifest

* docs(openclaw): restore reference docs from 2386

* docs(openclaw): clarify session history archive lookup

* docs(openclaw): align restored docs with current plugin

* docs(openclaw): restore full context database skill

* docs(openclaw): restore install guidance from 2386
2026-06-13 11:39:29 +08:00
Mingjian Que 564c7624b8 feat(openclaw): configure recall target types (#2590)
* feat(openclaw): configure recall target types

* fix(openclaw): align recall session target uri

* fix(openclaw): remove session semantic recall target
2026-06-13 11:22:08 +08:00
Mingjian Que d497b05aee feat(openclaw): wire recall trace runtime (#2589)
* feat(openclaw): wire recall trace runtime

* feat(openclaw): expose recall trace gateway routes

* feat(openclaw): align archive recall trace details

* test(openclaw): cover auto recall trace recording

* fix(openclaw): avoid duplicate memory recall search
2026-06-13 11:05:33 +08:00
Mingjian Que e2ca85d8ec feat(openclaw): add recall trace core (#2587) 2026-06-13 10:28:20 +08:00
Mingjian Que 61203e84b2 feat(openclaw): gate agent-visible tools (#2566) 2026-06-12 14:48:21 +08:00
marchpureandhaoxingjun 2dbee8e33d add OpenViking read tools to OpenClaw plugin (#2551)
* add ov_list tool to openclaw plugin

* declare ov_list in OpenClaw plugin manifest

* add OpenViking read tools to OpenClaw plugin

---------

Co-authored-by: haoxingjun <haoxingjun@bytedance.com>
2026-06-11 23:51:47 +08:00
Qin Haojie e06671b351 feat(session): 将 session 存储到 user 命名空间 (#2556)
* feat(session): store sessions in user namespace

* fix(session): tolerate legacy commit body fields
2026-06-11 14:33:00 +08:00
Mingjian Que ba8c8ec058 fix(openclaw-plugin): stop capturing tool placeholders (#2534) 2026-06-10 16:20:34 +08:00
Qin Haojie a6fc0424bc fix(session): apply memory type policy whitelist (#2530)
* fix(session): apply memory type policy whitelist

Restore top-level memory_types filtering for session memory extraction and validate it against enabled registry schemas. Ensure initialization and peer-aware smoke coverage honor the whitelist.

* fix(session): scope session skills to execution memory policy

* refactor(session): remove per-commit memory policy
2026-06-10 14:54:24 +08:00
Qin Haojie 669f379591 fix(test): anonymize openclaw auto-recall fixture (#2541) 2026-06-10 14:39:57 +08:00
Mingjian Que 74102b78f0 fix(openclaw): use user namespace for experience recall (#2537) 2026-06-10 14:13:53 +08:00
Mingjian Que 5854dbfdc2 Restrict auto recall to transformContext assemble (#2532) 2026-06-10 14:08:10 +08:00
Mingjian Que 790daaf885 feat(openclaw): inject agent experience memories (#2281) 2026-06-10 10:43:41 +08:00
Mingjian Que e5c8208dcb Make OpenClaw auto-recall timeout configurable (#2448) 2026-06-05 14:05:54 +08:00
Qin Haojie ff258768c2 feat(memory): 引入 User/Peer 记忆隔离模型 (#2236)
* feat(memory): introduce user and peer memory isolation

Unify agent-scoped memory behavior into user-owned memory spaces, add peer_id compatibility for session and retrieval paths, and wire memory_policy through session commit flows.

* feat(memory): align session identity around peer IDs

* feat(search): pass peer id through retrieval

* refactor(memory): remove agent identity from integrations

* fix(memory): isolate peer identity from self extraction

* fix(tau2): provision benchmark user configs

* fix(auth): allow admin keys to access data APIs

* fix(openclaw): enable peer memory policy for peer roles

* fix(openclaw): resolve sender for peer recall

* refactor(session): simplify memory extraction routing

* refactor(ov-cli): reduce formatting-only diff

* refactor(message): remove unused message helpers

* refactor(retrieval): simplify peer target resolution

* refactor(namespace): remove deprecated agent namespace policy

* fix(agent): propagate peer id through integrations

* fix(auth): align integration clients with api-key mode
2026-06-05 10:55:48 +08:00
MaojiaSheng 57b2e2a00e fix(openclaw-plugin): authenticate auto-recall health precheck (#2384)
Reuse the OpenViking client for auto-recall prechecks so remote /health probes carry the same auth and tenant headers as normal requests, preventing false recall skips behind authenticated gateways.
2026-06-02 16:07:38 +08:00
Mingjian Que e42dd12741 docs(openclaw): document explicit memory writes (#2323) 2026-06-01 16:58:41 +08:00
EurakaxunandEurekaxun ab855a43b0 fix: add cjk-aware token estimation (#2348)
Co-authored-by: Eurekaxun <eurekaxun@163.com>
2026-06-01 14:12:27 +08:00
AutoCoder 9e99c8f7db Add URI to autorecall memories (#2321) 2026-05-30 16:42:58 +08:00
Mingjian Que edb82d56fd fix(openclaw-plugin): report memory_store zero extraction (#2307) 2026-05-29 19:46:51 +08:00
AutoCoder 1d631cd38d Rename search tool to ov_search to avoid conflict with existing OpenClaw tool name (#2235) 2026-05-26 11:58:15 +08:00
HaotianChen616 f39b030926 feat: externalize oversized session tool results (#2058)
Squashed commits:

- 28e175c8 feat: externalize oversized session tool results
- 73d6461d feat: coalesce OpenClaw tool results by turn
- 3bf4a0c2 fix: apply tool result config and filtered listing
- a5bc0582 [bugfix] extractNewTurnMessages会错误过滤掉没有text block的assistant toolCall,用[toolCall: toolName]占位符确保消息传入
- 1d76827b style: format tool result compression changes
- 495b5623 fix: preserve textless toolUse turns
- 399f2dc3 feat: expose tool result access tools
- 43b48dd7 fix: honor min preview chars for source reads
- 6eaaf54f fix: split aggregated tool result messages
- f8ad98c3 fix: hydrate tool outputs for extraction
- f9031458 fix: improve tool descriptions for tool result access tools
- ae3bcd33 fix: hydrate source-read tool outputs
- 8976f8ce test: add tool result compression bench cases
2026-05-21 14:36:10 +08:00
AutoCoderandCodex 15e5284062 fix(openclaw): read L2 content in memory recall (#2002)
Co-authored-by: Codex <codex@example.com>
2026-05-13 15:06:27 +08:00