Commit Graph
27 Commits
Author SHA1 Message Date
Qin Haojie 9295a3b955 fix(session): remove actor scope from session lifecycle (#3661)
Keep sessions user-scoped and remove legacy agent fallback that could leak an actor view into commit memory writes.
2026-07-31 19:52:19 +08:00
baojun-zhang 2f9451231e refactor(pathlock):using rust implement instead python (#3602)
* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):optimize unit test code

* refactor(pathlock):optimize encryption create func

* refactor(pathlock):avoid releasing handoffed pathlock on enqueue errors

* fix(pathlock): use owned lease capability and handle S3 create-new 409 as conflict

* fix(ragfs): keep original FsContext for multi-write metadata

* fix(pathlock): resolve lease coverage and CAS handling issues

- detect S3 conditional conflicts from structured service errors
- pass transaction leases when deleting skill roots
- let temp cleanup acquire locks for temp paths
- disambiguate cache and pathlock providers in cache tests
- update temp cleanup lease assertions

* fix(ragfs): bypass pathlock for multi-write metadata

* fix(ragfs): revert pathlock fail-fast design

* fix(ragfs):fix(ragfs): use non-blocking fcntl locks for localfs CAS

* fix(ragfs): serialize heartbeat lease refresh with release and report real conflict kind

* fix(ragfs): preserve conflict kind snapshot and drop unused test scaffolding

* fix(ragfs): preserve conflict kind snapshot and drop unused test scaffolding
2026-07-29 19:45:34 +08:00
baojun-zhang 1841dfed81 Revert "refactor(pathlock):using rust implement instead python (#3557)" (#3597)
This reverts commit 6b538db569.
2026-07-29 11:31:41 +08:00
baojun-zhang 6b538db569 refactor(pathlock):using rust implement instead python (#3557)
* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):optimize unit test code

* refactor(pathlock):optimize encryption create func

* refactor(pathlock):avoid releasing handoffed pathlock on enqueue errors

* fix(pathlock): use owned lease capability and handle S3 create-new 409 as conflict

* fix(ragfs): keep original FsContext for multi-write metadata

* fix(pathlock): resolve lease coverage and CAS handling issues

- detect S3 conditional conflicts from structured service errors
- pass transaction leases when deleting skill roots
- let temp cleanup acquire locks for temp paths
- disambiguate cache and pathlock providers in cache tests
- update temp cleanup lease assertions

* fix(ragfs): bypass pathlock for multi-write metadata

* fix(ragfs): revert pathlock fail-fast design
2026-07-29 11:08:42 +08:00
DuTao 0ab85f450a feat(session): add turn-aware retention and reliable archive recovery (#3380)
* 优化OpenViking的 session compact逻辑,active message 改为turn,压缩 assistant,保留完整user。
详见RFC:https://github.com/volcengine/OpenViking/discussions/3330

* Vikingbot 使用 ov turn session

* fix pr comment

* 更新文档

* fix pr issue
2026-07-24 14:26:46 +08:00
Qin Haojie ca70bc0649 refactor(embedding): remove unused batch APIs (#3260) 2026-07-15 16:44:57 +08:00
87329714dd feat(grep): integrate VikingDB bm25 keyword search for grep engine (#2144)
* feat(grep): integrate VikingDB bm25 keyword search for grep engine

* fix(grep): address CI review feedback: max-size eviction to _count_cache, use Literal, Split regex alternation into individual keywords for bm25 (max 10)

* fix(schema): use dynamic __version__ for schema_version and handle dev suffixes in version comparison

* fix(schema): upsert data to vikingdb lack of content

* chore: add benchmark for retrieval

* fix(grep): vikingdb return 200 and no results means no matching content, not necessary to fallback to local fs

* fix(benchmark): sub uri args; add report

* refactor: code format by ruff

* optimize: move grep config (engine and switch_to_remote_threshold) to ov.conf

* optimize: auto adapt remote_return_limit by agg API; rm unnecessary params in keywords search

* fix: adjust benchmark scripts

* fix(grep): store full content for BM25; use PathScope depth; reduce redundant API calls

* refactor: new benchmark

* fix: step1 add resource by real code data

* feat(benchmark): split grep benchmark into effectiveness/performance suites with async reindex

* optimize (benchmark): adjust keywords and ground truth for testing

* fix: truncate 64KB for content field

* optimize: effectiveness add resource plainly

* optimize: change param use of SearchByKeywords from "keywords" to "query"

* optimize(benchmark): refactor effectiveness scripts

* optimize: ensure raw data for content field

* optimize: fulltext analyzer's stop-words only use symbols

* fix: adapt to new ov cli for benchmark

* optimize: reuse file content to avoid re-read AGFS file

* optimize: tune grep vikingdb defaults and refresh bm25 benchmark scripts

* optimize: benchmark client timeout

* update README

* fix: rm unused param

* fix: default values in docs

* optimize: increase truncate byte size to 1MB for content field for VikingDB

* fix(logger): harden queued stream logging (#2786)

* fix(logger): replace StreamHandler with QueueHandler+QueueListener to prevent thread deadlock

When log.output='stdout' (default) and the server is managed by systemd,
concurrent log writes can deadlock because logging.StreamHandler holds a
thread lock across stream.flush() which blocks on systemd-piped file I/O.

During session.commit() phase 2, multiple async coroutines (memory
extraction, summarization) concurrently call logger.info()/warning()
with large payloads. The first thread's flush() blocks on the pipe,
while all subsequent threads block on handler.acquire() forever.
This permanently silences the server log and prevents _write_done_file()
from executing, leaving phase 2 hanging without .done.

Fix: use QueueHandler + QueueListener from stdlib logging.handlers
(Python 3.2+). QueueHandler.emit() does queue.put(record) with no lock
or I/O, returning immediately. QueueListener has a dedicated single
thread as the sole consumer touching the real StreamHandler, making
lock contention impossible.

Changes in _create_log_handler(): stdout/stderr branches now create
a shared QueueListener with unbounded queue, returning QueueHandler
instances to callers. _build_standard_handler() delegates formatter
and filter setup to the real handler in the listener thread.

Closes: #2752

* fix(logger): harden queued stream logging

---------

Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>

---------

Co-authored-by: Qin Haojie <qinhaojie.exe@bytedance.com>
Co-authored-by: njuboy11 <njuboy11@users.noreply.github.com>
2026-06-24 18:46:02 +08:00
MaojiaShengandclaude-sonnet-4-6 ab656e240d refactor(auth): introduce plugin-based authentication architecture (#2709)
* chore: clear unused files

* fix(tests): fix unit test

* refactor(auth): introduce plugin-based authentication architecture

Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).

Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
  plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
  / `get_request_context` dependencies remain unchanged. Routers import the same
  symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
  not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.

Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>

* fix(tests): fix trusted mode test

* fix(tests): fix unit test

---------

Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
2026-06-18 20:05:17 +08:00
fujiajie666 2583da8459 Feature/wiki link (#2558)
* memory-resource记忆链接

* ov write, rm 更新 .overview

* 更新docs

* bug fix

* 更好的利用时间,摘要信息进行memory提取

* 合并

* 通过session.commit封装 --reason

* 回滚vlm代码

* 回滚rust代码

* bug fix

* 兼容peers, user 作用域

* bug fix

* bug fix

* bug fix

* bug fix

* format ruff fix

* --reason 使用同一个session_id,ruff修正

* --reason 使用同一个session_id,ruff修正,peer memory

* ruff修正
2026-06-16 23:07:30 +08:00
Qin Haojie ff258768c2 feat(memory): 引入 User/Peer 记忆隔离模型 (#2236)
* feat(memory): introduce user and peer memory isolation

Unify agent-scoped memory behavior into user-owned memory spaces, add peer_id compatibility for session and retrieval paths, and wire memory_policy through session commit flows.

* feat(memory): align session identity around peer IDs

* feat(search): pass peer id through retrieval

* refactor(memory): remove agent identity from integrations

* fix(memory): isolate peer identity from self extraction

* fix(tau2): provision benchmark user configs

* fix(auth): allow admin keys to access data APIs

* fix(openclaw): enable peer memory policy for peer roles

* fix(openclaw): resolve sender for peer recall

* refactor(session): simplify memory extraction routing

* refactor(ov-cli): reduce formatting-only diff

* refactor(message): remove unused message helpers

* refactor(retrieval): simplify peer target resolution

* refactor(namespace): remove deprecated agent namespace policy

* fix(agent): propagate peer id through integrations

* fix(auth): align integration clients with api-key mode
2026-06-05 10:55:48 +08:00
Qin Haojie e648b2679c feat(ovpack): add v2 manifest and backup restore (#1927)
* feat(ovpack): add v2 manifest and conflict policy

Add a portable OVPack manifest for scalar metadata and make imports validate scope, derived files, and conflicts before writing.

* fix(ovpack): remove import vectorize option

Make OVPack imports always rebuild vectors in the target environment, keep legacy packages compatible, and reject unsupported manifest versions before writing.

* fix(ovpack): remove force import alias

Use on_conflict as the single OVPack import conflict policy and reject removed force inputs.

* fix(ovpack): regenerate runtime vector metadata

Keep type portable but stop exporting or applying created_at, updated_at, and active_count from OVPack manifests.

* fix(ovpack): validate manifest contents

* fix(ovpack): require manifests for imports

* fix(ovpack): close manifest validation gaps

* fix(ovpack): defer parent creation until validation passes

* fix(ovpack): remove export size guard

* fix(ovpack): support session and scope-root restores

* docs(ovpack): document full backup migration

* feat(ovpack): add backup restore workflow

* fix(ovpack): validate import scope compatibility
2026-05-11 11:09:35 +08:00
DuTao bb515b1007 feat(openviking): Add User-Level Skill Privacy Configuration Capability (#1745)
* 增加用户隐私信息,skill 提取

* 增加用户隐私信息,skill 提取

* 字段提取

* privacy 配置cli 指令

* doc

* doc
2026-04-28 18:32:16 +08:00
Jiahui Zhou fea7c01ed5 Revert "feat(retrieve): use tags metadata for cross-subtree retrieval (#1162)" (#1200)
This reverts commit e72b614b3d.
2026-04-03 14:37:47 +08:00
13ernkastel e72b614b3d feat(retrieve): use tags metadata for cross-subtree retrieval (#1162)
* feat: use tags to expand cross-subtree retrieval

* fix: harden sync retrieval argument forwarding

* fix: resolve PR lint failures

* feat(tags): namespace stored and queried resource tags

* fix(tags): enforce canonical tag namespaces

* style: sort resource service imports
2026-04-03 13:24:38 +08:00
Qin HaojieandClaude Opus 4.6 cad9ec1408 refactor(model): unify config-driven retry across VLM and embedding (#926)
* refactor(model): unify config-driven retry across VLM and embedding

Move retry behavior into shared model-call utilities and config defaults so VLM and embedding providers handle transient failures consistently.

Co-Authored-By: Claude Opus 4.6

* fix

* docs(config): document model retry settings
2026-03-31 16:17:28 +08:00
MaojiaShengandopenviking ce998873f9 lisence: change the main lisence to AGPL-3.0 (#1085)
* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

---------

Co-authored-by: openviking <openviking@example.com>
2026-03-30 14:37:42 +08:00
Qin Haojie b560372697 fix(http): replace temp paths with upload ids (#1012)
* fix(http): replace temp paths with upload ids

Stop exposing server filesystem paths through temp uploads and require
HTTP callers to use temp_file_id across server, clients, tests, and docs.

* fix(cli): upload local ovpacks in http mode

Make the Rust HTTP client import local ovpack files through temp uploads
and cover the flow with an end-to-end SDK regression test.

* fix(api): align integration client with temp upload contract

* fix(client): fail fast for invalid ovpack imports
2026-03-27 14:49:49 +08:00
Qin HaojieandClaude Opus 4.6 1823a7c4f7 feat(storage): add path locking and selective crash recovery for write operations (#431)
* feat(storage): add transaction support with journal, undo, and crash recovery

Implement a full transaction system for VikingFS storage operations including
write-ahead journal, path locking, undo/rollback, context manager API, and
crash recovery. Includes comprehensive tests and documentation.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* test(transaction): add e2e rollback tests for mv and multi-step operations

Add end-to-end tests covering rollback scenarios that were missing:
- mv rollback: file moved back to original location on failure
- mv commit: file persists at new location
- Multi-step rollback: mkdir + write + mkdir all reversed in order
- Partial step rollback: only completed entries are reversed
- Nested directory rollback: child removed before parent
- Best-effort rollback: single step failure does not block others

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(storage): add transaction support with path locking and journal

Implement transaction system for VikingFS with ACID-like guarantees:
- TransactionManager with configurable lock timeout and journal-based recovery
- PathLock supporting point, subtree, and mv lock modes
- Refactor VikingFS mv to use cp+rm to prevent lock files from being carried
- Fix stale lock detection returning false for missing lock files
- Update ragas eval to use LangchainLLMWrapper

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: tests

* fix(transaction): fix rollback and race condition bugs

- Reconstruct RequestContext from undo params for vectordb_delete/update_uri
  rollback (previously skipped silently due to missing ctx)
- Serialize ctx fields into undo params in rm/mv operations
- Fix Phase 1 undo path to target archive dir instead of session root
- Remove Phase 2 fs_write_new undo (overwrites are idempotent, checkpoint
  handles recovery)
- Add ancestor SUBTREE recheck after lock creation in acquire_subtree
- Move _collect_uris inside TransactionContext in rm/mv to close race window
- Log journal persistence failures instead of silently swallowing

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor(transaction): make TransactionManager required and rewrite tests with real backends

Remove all optional/fallback code paths where tx_manager could be None. get_transaction_manager()
now raises RuntimeError if not initialized. Fix undo rollback to reconstruct ctx for vectordb_upsert
and use correct agent_id default. Replace mock-based transaction tests with integration tests using
real AGFS and VectorDB backends.

* refactor(transaction): make rollback fully async and unify session commit path

- Convert execute_rollback/rollback_entry to async, removing sync run_async wrappers
- Unify Session.commit() to delegate to commit_async(), removing duplicate phase methods
- Fix SUBTREE lock to conflict with ancestor SUBTREE locks (was previously missing)
- Fix mv lock mode: directory moves now use SUBTREE on both source and destination
- Replace deprecated asyncio.get_event_loop() with get_running_loop()
- Remove max_parallel_locks config option
- Update docs (en/zh) and tests to match new async rollback signatures

* fix: tests

* refactor(transaction): simplify session commit and add redo-based crash recovery

Session commit no longer wraps archive phase in a transaction. Phase 2 uses
redo semantics so crashed memory-extraction can be replayed from archive.
PathLock stale-lock cleanup no longer redundantly re-checks timeout.
Semantic processor vectorization runs concurrently via asyncio.gather.

* fix: transaction

* fix: UserIdentifier

* refactor(transaction): replace undo-based transaction manager with lightweight lock + redo-log

Remove the heavyweight TransactionManager/Journal/UndoEntry system (~4000 lines) and
replace it with a simpler architecture: LockManager for path locking, LockContext as
the async context manager, LockHandle/LockOwner protocol, and a RedoLog for crash
recovery of session_memory operations. VikingFS rm/mv now use inline error handling
instead of rollback semantics. Updated docs, observers, and tests accordingly.

Co-Authored-By: Claude Opus 4.6

* fix(transaction): remove checkpoint dead code, fix TOCTOU race, clarify mv lock param

- Remove unused _write_checkpoint/_write_checkpoint_async/_read_checkpoint
  from Session (superseded by redo-log)
- Re-resolve URI inside lock in resource_processor Phase 3.5 to prevent
  concurrent add_resource calls from resolving to the same final_uri
- Rename acquire_mv dst_path to dst_parent_path with docstring to clarify
  that callers pass the destination parent directory

* fix: path

* fix: resource lock

* fix: test

* docs: update

* fix: tests

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-18 14:50:19 +08:00
zhoujiahui b280b56b30 feat(trace): add request-level trace metrics and API support (#640)
refactor: replace operation trace with telemetry

fix telemetry demo skill ingestion

simplify telemetry summary metric keys

rename remaining trace telemetry artifacts

feat: support configurable telemetry payloads

docs: rewrite operation telemetry design in chinese

fix: reject telemetry for async session commit

refactor: isolate telemetry orchestration

refactor: remove telemetry from find payloads

refactor: remove telemetry event payloads

fix(trace): keep only telemetry-related changes

fix(trace): remove top-level usage from telemetry responses

feat(console): default telemetry on proxied operations
2026-03-15 22:44:15 +08:00
Qin HaojieandClaude Opus 4.6 4d7d222658 fix(test): 修复测试稳定性问题,清理废弃代码 (#353)
* fix(test): 修复测试稳定性问题,清理废弃代码

- 重构 is_closing 为基类正式 property,移除 getattr 防御性调用
- 测试用例使用唯一 account ID 避免跨测试数据冲突
- 服务器测试使用独立临时目录避免并发竞争
- 修复 ResourceWarning 测试因历史警告导致的误报
- 修复 CLI grep 命令参数顺序
- 更新路径遍历测试断言为 ValueError
- 移除已废弃的 CompressManager 测试
- 改进 AGFS_LIB_PATH 环境变量路径发现逻辑
- 新增 ragas/datasets/pandas 测试依赖
- 改进 CLI 服务器启动失败时的错误输出

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* revert: 回退 binding_client.py 的改动,由其他人负责修改

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-28 17:04:44 +08:00
Qin HaojieandClaude Opus 4.6 8274cc31ef fix: 修复单测以适配 vectordb 接口重构,统一测试数据路径 (#333)
- 修复 filesystem stat 错误匹配,增加 "not found" 判断
- 为 AddResourceRequest 添加 model_validator 校验 path 参数
- 处理 queue manager 未初始化时 ObserverService 的异常
- 简化 vectordb record ID 生成逻辑,移除 owner_space
- 捕获 HTTP client close 时的 RuntimeError
- 统一测试数据路径至 test_data/ 目录
- 更新测试用例使用 get_context_by_uri() 等新接口
- 移除测试 mock 对 VikingDBInterface 的依赖

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 19:40:12 +08:00
kkkwjxandqin-ctx 37b5d0d359 Multi tenant (#283)
* test: add multi-tenant isolation unit coverage

* feat: implement phase2 multi-tenant context isolation

* feat: multi tenant

* fix: resolve multi-tenant merge conflicts

* feat: multi tenant

* fix: enforce tenant isolation for session get

* tos config

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-02-25 18:25:36 +08:00
Qin Haojie b92f2c0fc7 feat: 多租户 Phase 1 - API 层多租户能力 (#260)
* doc: update design

* feat: multi_tenant

* feat: multi_tenant

* feat: multi tenant

* feat: multi tenant

* fix: tests

* fix: rust cli
2026-02-24 13:40:44 +08:00
MaojiaSheng db7319f4a2 refactor: to accelerate cli launch speed, refactor openviking_cli dir (#150)
* fix: remove await asyncio and call agfs directly

* feat: mv cli out of openviking

* refactor: mv cli out of openviking

* refactor: mv cli out of openviking
2026-02-12 22:12:50 +08:00
qin-ctx 002e14087f refactor(client): 拆分 HTTP 客户端,分离嵌入模式与 HTTP 模式 (#141)
* refactor(client): 拆分 HTTP 客户端,分离嵌入模式与 HTTP 模式

- 将 HTTPClient 重命名为 AsyncHTTPClient,新增 SyncHTTPClient 同步封装
- AsyncOpenViking/SyncOpenViking 仅保留嵌入模式,HTTP 模式使用独立的 AsyncHTTPClient/SyncHTTPClient
- HTTP 客户端支持从 ovcli.conf 自动加载 url/api_key
- 移除客户端构造函数中的 user 参数,统一使用默认用户
- 简化 CLIContext,直接使用 SyncHTTPClient
- 简化 VikingFS._uri_to_path 实现
- 更新文档、示例和测试适配新 API

* fix queue
2026-02-12 12:25:54 +08:00
qin-ctx 6d55bf4aa1 feat: 新增 Bash CLI 基础框架与完整命令实现 (T3 + T5) (#132)
* feat: 新增 Typer CLI 并统一配置加载机制

引入基于 Typer 的完整 CLI 模块 (openviking/cli),支持 resources、
sessions、search、filesystem、content、relations、pack、debug、
observer、system 等子命令。

新增统一配置加载器 (config_loader),采用三级解析链(显式路径 →
环境变量 → ~/.openviking/),同时服务于 server (ov.conf) 和
CLI (ovcli.conf)。

精简 AsyncOpenViking / SyncOpenViking 客户端,移除 service 模式
(vectordb_url / agfs_url) 和环境变量回退逻辑,仅保留 embedded
和 HTTP 两种模式。

同步更新中英文文档、示例和测试。

* fix: remove user  when create session

* fix: tests

* fix: tests
2026-02-11 15:53:10 +08:00
qin-ctx 3165ffa0da feat: add HTTP Server and Python HTTP Client (T2 & T4) (#109)
* feat: add Server/Client architecture with HTTP API and restructure documentation

  - Implement FastAPI-based HTTP server (openviking/server/) with REST API
  - Add client abstraction layer (LocalClient, HTTPClient, BaseClient)
  - Add CLI entry point (python -m openviking serve)
  - Fix bugs: session.session_id, link/unlink param names, hmac.compare_digest
  - Restructure docs: remove numbered prefixes, add guides/, rewrite API reference
    with both Python SDK and HTTP API (curl) examples (en/zh)
  - Add quickstart-server, deployment, authentication, monitoring guides
  - Update examples and design docs to reflect implementation

* 提供单测 和 文档

* Merge branch 'main' into feature/server_client

* feat: add server/client examples and server tests

* fix: cross-references

* fix : tests
2026-02-09 21:12:15 +08:00