Commit Graph
244 Commits
Author SHA1 Message Date
Qin Haojie 9d5646169b fix(observer): keep empty retrievals diagnostic-only (#3985)
Remove the cumulative retrieval error state and preserve zero-result metrics
without using retrieval yield to determine component health.
2026-08-13 21:46:31 +08:00
Qin Haojie ec18c1dcd8 fix(observer): treat empty retrievals as healthy (#3975)
Record actual search execution errors at the service boundary and use those
errors, rather than empty-result rates, to determine retrieval health.
2026-08-13 21:19:36 +08:00
Jiahui ZhouandTRAE CLI 482434ef6e feat(reindex): support tag updates (#3964)
* feat(reindex): support tag updates

Add replace and append tag modes to reindex vector rebuilds, preserve omission-aware behavior, and propagate options through background tasks and namespace rebuilds. Align Python, TypeScript, Go, and CLI interfaces with tests and documentation.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): lock file targets exactly

Use an exact path lock for existing file targets while retaining tree locks for directories and prune-orphans scopes. Add a regression test for single-file reindex.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): handle prune file targets

Use exact locks for existing file targets in prune-orphans mode while retaining tree scope for missing targets. Document the existing Go ReindexOptions wait semantics and add lock regression coverage.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
2026-08-13 13:41:12 +08:00
Jiajie - He/him/his 3577f77423 fix(compile): salvage partial output on timeout and iteration limits (#3948)
* fix(service): break startup circular imports with lazy exports

* fix(fs): avoid root semantic refresh when removing resource scope

* fix(compile): preserve existing wiki links

* fix(sdk): extend HTTP timeout for blocking batch writes

* fix(compile): salvage workspace output on runtime timeout

* feat(compile): support runtime timeout and salvage partial output

* fix: expand compile task and output limits

* revert file

* fix(compile): harden salvage and deadline handling

* update

* fix(compile): address salvage review feedback

* fix(compile): normalize escaped salvage links
2026-08-12 18:51:35 +08:00
Ziyang Guo efbe012d6b perf(pathlock): back off contended lock retries (#3642)
Replace the fixed 50 ms retry loop with bounded exponential backoff and jitter while preserving the original first-retry latency floor. Clamp each delay to the remaining timeout so retry sleeps do not add avoidable timeout overshoot.

Add deterministic interval and polling-reduction checks plus a four-waiter contention regression. The 10-second worst-case schedule drops retry probes from 200 to 29 while all waiters still acquire after the holder releases.

Tests: cargo test -p ragfs --lib lock:: -- --nocapture
2026-08-12 10:31:41 +08:00
baojun-zhang 8ef840da95 fix(storage): treat localfs read ENOENT as NotFound (#3935)
* fix(pathlock): treat localfs read ENOENT as NotFound

Map ENOENT from localfs read back to NotFound when a file disappears
between metadata() and fs::read().

This avoids misclassifying lock-file delete races as plugin I/O errors
in pathlock token reads, so missing .path.ovlock is handled as an
expected absence instead of a fatal lock I/O failure.

* fix(pathlock): treat localfs read ENOENT as NotFound

Map ENOENT from localfs read back to NotFound when a file disappears
between metadata() and fs::read().
2026-08-11 20:40:39 +08:00
zihengli cd55ec89a6 feat(assets): support fixed Git commits, explicit targets, and private repository auth (#3703)
* feat/openviking_assets_support_git_commit_id

* feat/openviking_assets_support_to

* feat/private_git_support_watch

* fix: doc_and_ut

* fix: doc_and_ut

* fix: adapt git token url
2026-08-11 14:07:21 +08:00
7f6085a2f9 feat(memory): support event tag filtering (#3850)
* feat(memory): support event tag filtering

Add session-level default event tags, commit-time overrides, durable queue propagation, and first-write vector index tagging. Include config update APIs and coverage for serialization, concurrency, extraction, and HTTP behavior.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(memory): expose event tags in SDKs and CLI

Add session default tag configuration, config updates, and commit-time event tag overrides across embedded Python, standalone Python, TypeScript, Go, and the Rust CLI. Preserve explicit empty-tag semantics and document each public interface.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(sdk): align legacy session tag APIs

Forward commit-time event tags through the legacy Python HTTP shims and align BaseClient session signatures without adding a new abstract-method requirement for existing subclasses.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(session): allow updating auto-commit policy

Extend PATCH session config to atomically update event tags and auto-commit settings. Merge policy objects by field, use explicit null to disable automatic commits, preserve omitted fields, and expose the contract across SDKs and CLI.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(session): align session config interfaces

Replace the generic session create config JSON flag with explicit event-tag and auto-commit options. Preserve omitted, object, and null auto-commit semantics across HTTP, embedded clients, SDKs, and CLI, reject ambiguous null policy fields, and handle nullable event configuration consistently.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* test(session): trim redundant event tag tests

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-10 11:58:02 +08:00
baojun-zhang 9791c87554 feat(pathlock): keep lease alive across handoff and rotate adopt capability (#3903)
- keep handed-off leases in the registry with pending_handoff so auto-refresh continues
- include lease_ref in PathLockHandoffRef for same-process adopt fast path
- rotate both lease_ref and ownership_ref on adopt to invalidate stale producer capabilities
- reject stale capability use in release, release_selected and refresh
- validate owner_id, lock_paths and covered_paths before local adopt
- reject replayed fallback adopt when the same owner/path token is already held
- add tests for pending handoff refresh, retryable adopt race, forged coverage and replay rejection
2026-08-10 11:40:56 +08:00
Ray Tien 9806d60443 fix(cli): keep Config test fixtures in sync (#3870) 2026-08-07 20:48:50 +08:00
Onefly 98e6e5d24f fix(cli): correct Rust CLI license metadata (#3729) 2026-08-07 17:15:31 +08:00
baojun-zhang bd5cce09c7 feat(pathlock): adjust pathlock config (#3854) 2026-08-07 13:21:30 +08:00
baojun-zhang 758fc7f0fa feat(queuefs): add bounded redis startup stale-recovery sweeps (#3748)
* feat(queuefs): add bounded redis startup stale-recovery sweeps

* fix(queuefs): decouple redis startup recovery from heartbeat with bounded 0/30/60 sweeps
2026-08-06 13:19:20 +08:00
444cc87bf8 feat: OIDC and LDAP as new auth mode for OpenViking (#3708)
* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix: remove heima partner, clean up auth docs, add web-studio unsupported auth banner

- Remove heima from partner list in README (en/zh/ja)
- Remove unsupported env var references (OPENVIKING_AUTH_MODE, OPENVIKING_USERNAME,
  OPENVIKING_PASSWORD) from LDAP auth docs
- Remove temporary switch bash snippets from auth docs
- Fix ldap_password description
- Add web-studio unsupported-auth-mode banner for oidc/ldap servers

* fix: address OIDC/LDAP review comments on auth plugin design

Key changes driven by PR review:

- **Role mapping**: OIDC and LDAP external identities always resolve to
  USER role. Removed map_role() calls and group_membership-based role
  mapping. Admin access is gated by the root API key mechanism only.

- **LDAP credential extraction**: Removed query-parameter-based username/
  password extraction (security concern — passwords in URLs can leak via
  shell history, proxy logs, and monitoring). Clients must use Basic Auth
  header or form data.

- **OIDC identifier sanitization**: Auth0 and other providers may include
  characters like "|" in the `sub` claim. These are now replaced with "_"
  to produce valid OpenViking user identifiers.

- **Dead code removal**: Removed _extract_groups, memberof_attribute,
  require_root_api_key_for_admin, _initialize_api_key_manager, and
  get_request_context_checks from both plugins since they are no longer
  needed.

- **Docs**: Removed query-parameter curl example, memberof_attribute and
  require_root_api_key_for_admin config references.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat: support oidc and ldap auth

* feat: support oidc and ldap auth

* fix(auth): bind lazy OIDC imports at module scope

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-06 12:36:37 +08:00
Jiahui Zhou 6f43a4040c feat: support processing mode for content write (#3615) 2026-08-05 21:42:33 +08:00
baojun-zhang 8c9c2282a6 feat(queuefs): support redis as queufs backend ,redis mode support singleton 、cluster 、 sentinel (#3741) 2026-08-05 17:19:42 +08:00
Kchen 8d1d52fe5d 资源导入:支持解析后不拆分文档 (#3645) 2026-08-05 11:34:10 +08:00
baojun-zhang df1557901e feat(ragfs): add structured lock tracing logs (#3693)
* feat(ragfs): add structured lock tracing logs

* feat(ragfs): add log async writer

* fix(ragfs): add CRITICAL trans && add rust hook to receive rotate log file
2026-08-03 15:58:55 +08:00
Hao Zheandzhiheng.liu c4d2b27c64 fix(ov): harden CLI configuration and command behavior (#3552)
* docs: fix stale commands, paths, and provider claims

Sweep findings: D-03, D-04, D-05, D-06, D-07, D-08, D-09. Align setup and API examples with current configuration and CLI behavior.

(cherry picked from commit 2b21ee513b)

* fix(review): correct crypto output flag

Addresses blocking review finding on #3401.

(cherry picked from commit 85bb502709)

* docs(ov): finish stale CLI path cleanup

Complete the #3401 salvage by updating the API-writing templates and the remaining encryption guide examples to the Rust CLI surface.

* fix(ov): make local content operations race-safe

Salvage the safe-I/O portions of OpenViking#3414: reject unsupported local watch requests before upload, atomically create download targets, and write snapshot output before reporting JSON success. Add focused regression coverage.

* fix(ov): validate timeout and node-limit inputs

Salvage and complete OpenViking#3414 by validating every timeout and node-limit surface consistently while preserving config commands as a repair path for invalid persisted values.

* fix(ov): allow explicit help before language setup

Salvage OpenViking#3416 with a narrower contract: only clap-recognized -h/--help requests bypass first-run language selection. Bare command groups, legacy -help, and option values keep the existing gate.

* docs(ov): align session and snapshot command examples

Salvage OpenViking#3419 by correcting positional session and snapshot examples, documenting the canonical observer filesystem command, and keeping fs as a compatible alias.

* fix(ov): honor configured output defaults safely

Salvage and complete OpenViking#3424 with CLI-over-config precedence, runtime validation for normal commands, and a table fallback that leaves config repair commands usable. Also clarify the Python-client versus Rust-CLI upload-mode controls.

* fix(ov): preserve zero node-limit semantics

* ci: skip embedding-dependent resource test without secrets

* fix(cli): validate compile timeout consistently

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-31 21:45:53 +08:00
Hao Zheandzhiheng.liu de9c3cec15 fix(storage): preserve deletion and session durability (#3553)
* fix(ragfs): preserve cache visibility on partial S3 deletes

Surface exact and per-object S3 deletion failures, while always invalidating the affected directory and stat cache scope after a recursive delete attempt.

Source-PR: #3407
Original-Commit: 8d6addf28e

* fix(session): preserve legacy policy and peer identity compatibility

Parse string false and other legacy boolean-like memory policy values without silently enabling extraction or breaking persisted configs. Encode mixed-script peers losslessly, while retaining their former lossy IDs as read-only retrieval and extraction aliases.

Source-PR: #3422
Original-Commit: 0dfd5a9ed9

* fix(memory): drain timer flush tasks during shutdown

Retain the shielded timer flush task and await it when close cancels the timer loop, so batch failures are observed and submitters are resolved without unhandled task exceptions.

Source-PR: #3438
Original-Commit: ca1d74e164

* fix(storage): preserve peer isolation and cache correctness

* fix(ingest): reserve encoded peer namespace

* ci: skip embedding-dependent resource test without secrets

* fix(ragfs): invalidate caches after partial remove

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-31 21:45:29 +08:00
baojun-zhang 89c2705192 feat(pathlock): split lock busy from io for retryable stale cleanup (#3659) 2026-07-31 16:08:18 +08:00
Hao Zheandzhiheng.liu 4237c66031 fix(bot): harden scheduling, sessions, sandbox, and packaging (#3549)
* fix(bot): make SRT sandbox constructible and surface startup failures

Sweep findings: C-02, C-04. Read SRT settings from the correct config and never cache failed startups.

(cherry picked from commit 0d3798399a)

* fix(bot): reject unschedulable cron jobs and honest manual runs

Sweep findings: C-07, C-08. Reject impossible schedules and fail no-op manual execution.

(cherry picked from commit 47413fdffe)

* build: ship VikingBot workspace and bridge assets in wheels

Sweep findings: F-07. Copy required bot assets into the package and resolve installed workspace templates correctly.

(cherry picked from commit 85e9ff2d06)

* fix(bot): OpenAPI channel concurrency, session deletion, and context handling

Sweep findings: C-09, C-10, C-11. Reject ambiguous requests and make session deletion durable.

(cherry picked from commit 68fd70c5be)

* docs(bot): correct channel setup config paths and license metadata

Sweep findings: C-13, C-15. Point channel setup at ov.conf and align package metadata with MIT.

(cherry picked from commit b15c241037)

* fix(review): align bot license metadata

Addresses blocking review finding on #3426.

(cherry picked from commit 001e0fa7ed)

* fix(bot): preserve cron scheduler liveness

Record callback-less scheduled runs as job errors so recurring timers persist and rearm, while manual runs still fail without mutating state. Document the OpenAPI context rejection and same-session concurrency contract.

* fix(ragfs): use stable Windows file identity APIs

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-07-31 15:57:43 +08:00
agent bed5a0231a fix(agent evolution): snapshot complete experience directory on session commit (#3646)
* fix(snapshot): preserve untracked files in partial commits

* fix(snapshot): scope reconciliation to experience directory
2026-07-31 14:01:40 +08:00
zihengli 36d419aaa6 fix:openviking assets import external connector switch (#3634)
* fix:openviking assets import external connector switch

* fix(tests): update quick-start fake embedder compatibility

* fix:openviking assets import external connector switch

* fix:openviking assets import external connector switch
2026-07-31 13:55:41 +08:00
baojun-zhang 7c956f23bc feat(config): add compatible default timeout for ragfs pathlock (#3641)
- add storage.agfs.pathlock.lock_timeout_secs
- use pathlock default timeout instead of hardcoded zero in wrapper
- map legacy storage.transaction.lock_timeout when new config is unset
- remote redolog by using  persistent `session_commit` queue.
2026-07-31 11:23:27 +08:00
Qin Haojie fd42b1ad92 feat(tasks): support task cancellation (#3577)
* feat(tasks): support task cancellation

* refactor(tasks): scope cancellation to current user

* feat(cli): support task cancellation

* refactor(tasks): make cancellation queue-aware

* refactor(tasks): simplify cancellation bookkeeping

* test: remove task cancellation coverage

* refactor(tasks): trim cancellation coordination

* fix(tasks): contain cancellation to owned work

* feat(tasks): persist resource source metadata

* fix(tasks): handle cancelled work consistently

* refactor(tasks): make completion queue-aware

* fix(tasks): persist terminal state before queue ack

* test(tasks): remove added lifecycle tests

* docs(tasks): document task cancellation
2026-07-30 20:34:27 +08:00
Kchenandchenpengfei 86771b467e fix(pathlock): tolerate concurrent lock directory creation (#3635)
Co-authored-by: chenpengfei <chenpengfei@bytedance.com>
2026-07-30 20:20:09 +08:00
baojun-zhang f063f3b493 fix(pathlock): remove legacy encrypted lock files on read_token (#3629) 2026-07-30 17:48:52 +08:00
zihengli 47bbf7a66a feat(cli): add Openviking asset manifest mode to add-resource (#3358)
* feat: implement server-resolved OpenViking Assets manifests

Add the openviking-assets/1 declaration flow with server-owned configuration parsing and native Rust CLI execution.

- Resolve one flat Manifest against one Catalog through an authenticated server endpoint with strict schema and Git semantic validation.
- Reject recursive includes and unsafe clone URLs; return a resolved plan without submitting resources or running server-side batches.
- Keep local credential aliases, manifest state, dry-run, failure isolation, and per-asset create/sync orchestration in the CLI.
- Generate normalized stable asset identities on the server and remove the CLI direct SHA-1 dependency.
- Update flat examples and add server resolver/API plus Rust CLI coverage.

* feat: implement server-resolved OpenViking Assets manifests

* feat: implement server-resolved OpenViking Assets manifests

* fix(pathlock): tolerate missing lock token after recursive delete

* feat: implement server-resolved OpenViking Assets manifests

* feat: implement server-resolved OpenViking Assets manifests
2026-07-30 15:29:07 +08:00
baojun-zhang 2f9451231e refactor(pathlock):using rust implement instead python (#3602)
* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):optimize unit test code

* refactor(pathlock):optimize encryption create func

* refactor(pathlock):avoid releasing handoffed pathlock on enqueue errors

* fix(pathlock): use owned lease capability and handle S3 create-new 409 as conflict

* fix(ragfs): keep original FsContext for multi-write metadata

* fix(pathlock): resolve lease coverage and CAS handling issues

- detect S3 conditional conflicts from structured service errors
- pass transaction leases when deleting skill roots
- let temp cleanup acquire locks for temp paths
- disambiguate cache and pathlock providers in cache tests
- update temp cleanup lease assertions

* fix(ragfs): bypass pathlock for multi-write metadata

* fix(ragfs): revert pathlock fail-fast design

* fix(ragfs):fix(ragfs): use non-blocking fcntl locks for localfs CAS

* fix(ragfs): serialize heartbeat lease refresh with release and report real conflict kind

* fix(ragfs): preserve conflict kind snapshot and drop unused test scaffolding

* fix(ragfs): preserve conflict kind snapshot and drop unused test scaffolding
2026-07-29 19:45:34 +08:00
zihengli e9c4cc97c3 refactor: extract Connector delegation and expose declarative add_type (#3591)
* refactor: delegate add_resource imports to external Connector

* refactor: delegate add_resource imports to external Connector

* refactor: extract Connector delegation and expose declarative add_type

* fix: merge main to refactor/connector_delegator

* fix: merge main to refactor/connector_delegator
2026-07-29 18:09:25 +08:00
Jiahui Zhou 34b5a88971 Feat/add resource tags (#3560)
* feat: allow tags during resource import

* feat: support uploaded resource watches with tags

* feat: add resource tag flags to CLI

* fix: reject uploaded resource watches with tags

* docs: untrack add resource tags design draft

* fix: write add_resource tags during ingest

* docs: move add_resource tags docs into resources api

* fix: tighten add_resource tag ingestion semantics

* fix: address add_resource tag review feedback

* fix: merge resource tags at vector upsert

* refactor: carry add_resource tags with ingest options
2026-07-29 15:43:06 +08:00
baojun-zhang 1841dfed81 Revert "refactor(pathlock):using rust implement instead python (#3557)" (#3597)
This reverts commit 6b538db569.
2026-07-29 11:31:41 +08:00
baojun-zhang 6b538db569 refactor(pathlock):using rust implement instead python (#3557)
* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):using rust implement instead python

* refactor(pathlock):optimize unit test code

* refactor(pathlock):optimize encryption create func

* refactor(pathlock):avoid releasing handoffed pathlock on enqueue errors

* fix(pathlock): use owned lease capability and handle S3 create-new 409 as conflict

* fix(ragfs): keep original FsContext for multi-write metadata

* fix(pathlock): resolve lease coverage and CAS handling issues

- detect S3 conditional conflicts from structured service errors
- pass transaction leases when deleting skill roots
- let temp cleanup acquire locks for temp paths
- disambiguate cache and pathlock providers in cache tests
- update temp cleanup lease assertions

* fix(ragfs): bypass pathlock for multi-write metadata

* fix(ragfs): revert pathlock fail-fast design
2026-07-29 11:08:42 +08:00
fujiajie666 c91b0d36f2 feat: implement Skill-driven knowledge compilation for ov compile (#3567)
* feat(compile): implement skill-driven ov compile

Require a Skill and run compile tasks through VikingBot AgentLoop with structured wiki bundle rendering and durable task state.

Add OpenViking batch-write and bot proxy APIs, Python SDK and Rust CLI support, shared link and memory helpers, tests, and a One-Page demo.

* fix(compile): refine defaults, links, and failure handling

* fix(compile): normalize skill tools and degrade gracefully

* feat(compile): support skill-defined artifact outputs

* feat(compile): improve artifact reliability and wiki navigation

* feat(compile): support generating and updating skill packages

* fix(compile): validate OKF frontmatter and catalog page types

* feat(compile): rank target catalog and validate updates lazily

* feat(compile): tag generated wiki files for search

* fix(compile): preserve generated skill artifacts in submissions

* fix(compile): enforce fixed toolset and workspace artifact submissions

* fix(skills): preserve nested metadata in skill frontmatter

* fix(compile): normalize wiki paths and citation line breaks

* docs(examples): remove outdated compile demos

* docs(api): document compile and batch-write endpoints

* fix(content): allow arbitrary resource files in batch writes

* fix(compile): harden task lifecycle, auth, and execution

* fix(compile): disable direct exec by default

* fix(compile): allow file-only tasks when exec is disabled

* fix(compile): prevent task lock leaks
2026-07-28 20:33:25 +08:00
Jiahui Zhou 5d1ba45be4 Feat/add resource processing mode (#3566)
* feat: add resource processing mode

* fix: keep semantic artifacts in vectors-only add resource

* test: support processing mode in api test client

* docs: document add resource processing mode

* fix: align processing mode after resource ingestion refactor

* feat: expose processing mode in TypeScript SDK

* fix: preserve add resource compatibility
2026-07-28 20:09:06 +08:00
Zayn JarvisandClaude Opus 4.8 f316d6ad04 fix(ragfs): enforce mount containment and write-flag semantics in LocalFS (#3402)
* fix(ragfs): enforce mount containment and write-flag semantics in LocalFS

Sweep findings: E-01, E-04. Reject lexical traversal and honor LocalFS write contracts.

* fix(review): reject absolute localfs remainders

Addresses blocking review finding on #3402.

* fix(ragfs): close LocalFS glob mount-escape gap

LocalFS::glob_directory only called validate_virtual_path(path), which
rejects `..` but accepts an absolute remainder. A `//`-double-slash mount
path (e.g. `/local//etc`) survives normalize_path, and find_mount hands the
remainder `//etc` to glob_directory; validate_virtual_path passes it
(components are [RootDir, Normal("etc")], no ParentDir), and glob_via_walk's
resolve_virtual_path strips one slash to `/etc` and joins it over the base —
an absolute join that overrides the base and lists the host directory.

Every other op (read/write/stat/rename/remove/grep) routes through
resolve_path, which adds the is_absolute check. glob now calls the same
resolve_path guard (discarding the returned PathBuf) so it shares the
containment contract. Directory-listing info leak only; content reads were
already covered.

Adds test_localfs_glob_mount_rejects_absolute_remainder mirroring the read
regression test.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RbWx1T81KkNV4nucxWsPXZ

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-25 13:17:22 +08:00
agent 27debfe7a8 feat(snapshot): add path diff API, SDK, and CLI (#3451)
* feat(snapshot): add path diff API

* feat(snapshot): expose path diff in clients and CLI

* fix(snapshot): pin path diff to resolved commits

* fix(snapshot): bound path diff resource usage

* fix(snapshot): bound diff blob reads

* fix(snapshot): harden path diff API

* fix(snapshot): bound path diff resource usage

* fix(build): sync native binding dependencies
2026-07-23 17:45:36 +08:00
Zayn Jarvis 997e750ccc fix(ov): redact gateway secrets in config show and create root key with 0600 (#3411)
* fix(ov): redact gateway secrets in config show and create root key with 0600

Sweep findings: E-02, E-03. Prevent credential disclosure in output and at key creation.

* test(ov): drop trivial init-key permission test

The 0600 fix is a one-line OpenOptions::mode; a dedicated tokio+tempfile
test module for a single mode assertion is not worth its weight. The
redaction test in store.rs (a real multi-case security behavior) stays.
2026-07-23 10:47:28 +08:00
Qin Haojie fd098cfd65 fix(cli): preserve structured API errors (#3379)
* fix(error): preserve structured errors in cli

* fix(cli): preserve status for non-json errors
2026-07-22 18:06:48 +08:00
Jiahui Zhou 4295dfdef0 docs(cli): update ov cli readme (#3388) 2026-07-22 00:01:59 +10:00
Jiahui Zhou 5390bd5e54 fix: require all retrieval tags in search (#3097) 2026-07-21 11:54:01 +08:00
ef4d97ebe3 feat(snapshot): support path-filtered commit history (#3271)
* feat(snapshot): support path-filtered commit history

* refactor(snapshot): reuse SDK git log implementation

* fix(snapshot): harden path-filtered log resource limits

* chore: remove stale SDK lock entry

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-07-16 19:53:40 +08:00
Qin Haojie d47f2106ee refactor: remove unused and deprecated APIs (#3272)
Delete dead compatibility paths and test-only helpers so unsupported APIs do not remain as accidental contracts.
2026-07-16 10:49:56 +08:00
Jiahui Zhou 1c46d44fbc Fix/reindex preserve owners (#3096)
* fix: preserve reindex content owners

feat: allow trusted admin role assertion

feat: prune orphan vectors during reindex

fix: harden reindex memory body reads

feat: expose reindex prune options in clients

fix(cli): prefer workspace sdk for compat clients

fix: harden reindex prune orphans

* test: align reindex expectations after rebase
2026-07-14 20:38:30 +08:00
DuTao cbfb387dc7 feat(bot): add unified VikingBot gateway routing and OpenViking auth (#3119)
* bot opt config\api check

* 优化vikingbot的启动链路

* 美化颜色

* docs: add VikingBot gateway routing diagram

* fix(bot): harden gateway auth and proxy routing
2026-07-10 17:45:41 +08:00
zgy 6ab724bc67 fix(cli): avoid misreporting upstream model auth errors (#3116) 2026-07-10 16:05:37 +08:00
Qin Haojie 3003ed61d7 feat(retrieval): support image search (#3093)
Add multimodal image vectorization and image query support across the server, SDKs, and CLI.
2026-07-09 16:42:53 +08:00
zgy 07113f81e0 fix(cli): don't misreport remote fetch auth failures as API key errors (#3074)
When the server crawls a URL that returns 401/403, it wraps the failure
in a 5xx envelope. The CLI matched on auth-flavored message text alone
and rendered "OpenViking rejected the API key", wrongly pointing users
at their local config.

Gate the API-key error report on status: 5xx responses are never treated
as a client auth failure even when the message mentions authentication or
forbidden. Also split the 401 vs 403 fetch messages so 403 reads as an
access-denied / anti-bot block rather than a credential problem.
2026-07-08 14:50:59 +08:00
Qin Haojie 44180e39ff fix(cli): preserve mixed warning output fields (#3062)
Keep warning arrays from taking over table rendering when an API result also contains scalar fields like status, root_uri, and task_id.
2026-07-07 17:09:27 +08:00