* docs: fix stale commands, paths, and provider claims
Sweep findings: D-03, D-04, D-05, D-06, D-07, D-08, D-09. Align setup and API examples with current configuration and CLI behavior.
(cherry picked from commit 2b21ee513b)
* fix(review): correct crypto output flag
Addresses blocking review finding on #3401.
(cherry picked from commit 85bb502709)
* docs(ov): finish stale CLI path cleanup
Complete the #3401 salvage by updating the API-writing templates and the remaining encryption guide examples to the Rust CLI surface.
* fix(ov): make local content operations race-safe
Salvage the safe-I/O portions of OpenViking#3414: reject unsupported local watch requests before upload, atomically create download targets, and write snapshot output before reporting JSON success. Add focused regression coverage.
* fix(ov): validate timeout and node-limit inputs
Salvage and complete OpenViking#3414 by validating every timeout and node-limit surface consistently while preserving config commands as a repair path for invalid persisted values.
* fix(ov): allow explicit help before language setup
Salvage OpenViking#3416 with a narrower contract: only clap-recognized -h/--help requests bypass first-run language selection. Bare command groups, legacy -help, and option values keep the existing gate.
* docs(ov): align session and snapshot command examples
Salvage OpenViking#3419 by correcting positional session and snapshot examples, documenting the canonical observer filesystem command, and keeping fs as a compatible alias.
* fix(ov): honor configured output defaults safely
Salvage and complete OpenViking#3424 with CLI-over-config precedence, runtime validation for normal commands, and a table fallback that leaves config repair commands usable. Also clarify the Python-client versus Rust-CLI upload-mode controls.
* fix(ov): preserve zero node-limit semantics
* ci: skip embedding-dependent resource test without secrets
* fix(cli): validate compile timeout consistently
---------
Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
- add storage.agfs.pathlock.lock_timeout_secs
- use pathlock default timeout instead of hardcoded zero in wrapper
- map legacy storage.transaction.lock_timeout when new config is unset
- remote redolog by using persistent `session_commit` queue.
* docs: fix broken links and anchors across READMEs and guides
Sweep findings: D-10, D-11, D-12, D-13, D-14, D-15. Restore valid documentation targets and stable cross-page anchors.
(cherry picked from commit e3504d633d)
* docs: correct contributor and release references
Reconstruct the factual parts of draft #3397 against current upstream: use the supported setup wizard, align the repository tree and workflow names with tracked files, document current release paths, and repair the bug-bounty link. Excludes install-policy and subjective content rewrites.
Based-on: b332e19e40
Based-on: c89afb17f2
Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
* build: propagate recipe failures and align CMake minimum
Keep build failures visible, use isolated temporary extraction paths, and enforce the native build's CMake 3.15 floor across all contributor guides. CMake version parsing accepts prerelease and vendor suffixes.
Based-on: 8943a12285
Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
* fix(scripts): surface backfill enumeration failures
Preserve the safety fix from draft #3415 while retaining legacy no-op arguments for existing operational scripts. Deprecated arguments now remain parse-compatible, advertise their status in help, and emit explicit warnings when used.
Based-on: 5516d96048
Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
---------
Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
* chore: clear unused files
* fix(tests): fix unit test
* refactor(auth): introduce plugin-based authentication architecture
Replace the monolithic `openviking/server/auth.py` with an extensible
plugin-based auth system. This refactor extracts the three built-in modes
(`dev`, `api_key`, `trusted`) into separate `AuthPlugin` implementations,
adds a registry for third-party plugins, and preserves all existing behavior
while enabling custom authentication backends (e.g. LDAP, OIDC, mTLS).
Key changes:
- **New public API**: `AuthPlugin` (ABC) and `register_auth_plugin` decorator.
- **New registry**: `AuthPluginRegistry` supports runtime registration.
- **Built-in plugins**: `DevAuthPlugin`, `ApiKeyAuthPlugin`, `TrustedAuthPlugin`.
- **Config change**: `auth_mode` widened from `Literal` to `str` for custom modes.
- **Validation delegated**: `validate_server_config()` now delegates to the active
plugin's `validate_config()`, preserving existing validation semantics.
- **Router compatibility**: All existing `require_*` decorators and `resolve_identity`
/ `get_request_context` dependencies remain unchanged. Routers import the same
symbols from `openviking.server.auth`.
- **Tests**: `conftest.py` manually wires the DevAuthPlugin in ASGI tests (lifespan
not triggered). `test_auth.py` expanded with plugin registration and validation tests.
- **Docs**: `04-authentication.md` (en/zh) updated with plugin registration examples.
Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>
* fix(tests): fix trusted mode test
* fix(tests): fix unit test
* fix(cli): remove unexisted transaction observer
* docs: update skills definition
* docs: update skills definition
* docs: update skills definition
* docs: update skills definition
* fix(skills): now we allow viking://agent/skills again, and optimize CLI for skills
* docs(skills): use -p instead of --parent in agent skills examples
Align the `ov skills add` examples in the context-types and viking-uri
docs with the short flag `-p` introduced for `ov skills list/find/show`,
so all four user-facing examples consistently demonstrate the short form
when targeting `viking://agent/skills`.
Co-Authored-By: claude-sonnet-4-6 <noreply@anthropic.com>
* fix(tests): error check for api key
* fix(tests): unit test wait until resource not busy
* fix(tests): unit test wait until resource not busy
* fix(sdk): args form in skills find
* fix(skills): pass target uri in request body
---------
Co-authored-by: claude-sonnet-4-6 <noreply@anthropic.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
* docs(retrieval): note intent-analysis model is configurable via query_planner (#2224)
* docs(retrieval): note intent-analysis model is configurable via query_planner (#2224)
* docs(api): document observer.filesystem from #2045
* docs(api): document observer.filesystem from #2045
* docs(metrics): list filesystem component from #2045
* docs(metrics): list filesystem component from #2045
* feat(ovpack): add v2 manifest and conflict policy
Add a portable OVPack manifest for scalar metadata and make imports validate scope, derived files, and conflicts before writing.
* fix(ovpack): remove import vectorize option
Make OVPack imports always rebuild vectors in the target environment, keep legacy packages compatible, and reject unsupported manifest versions before writing.
* fix(ovpack): remove force import alias
Use on_conflict as the single OVPack import conflict policy and reject removed force inputs.
* fix(ovpack): regenerate runtime vector metadata
Keep type portable but stop exporting or applying created_at, updated_at, and active_count from OVPack manifests.
* fix(ovpack): validate manifest contents
* fix(ovpack): require manifests for imports
* fix(ovpack): close manifest validation gaps
* fix(ovpack): defer parent creation until validation passes
* fix(ovpack): remove export size guard
* fix(ovpack): support session and scope-root restores
* docs(ovpack): document full backup migration
* feat(ovpack): add backup restore workflow
* fix(ovpack): validate import scope compatibility
* feat: 提交1:路径变量系统
feat: Add path variable system with calendar variables
- Implement {calendar:today}, {calendar:ym}, etc.
- Integrate with all URI-handling API endpoints
- Add comprehensive unit tests
- Update documentation
提交2:Rust CLI重构
feat: Rust CLI refactor with progress bar support
- Split HttpClient into BaseClient and FileUploader
- Add dynamic timeout configuration
- Add progress bar for compression/upload
- Configure via --progress flag or config file
* feat: 提交1:路径变量系统
feat: Add path variable system with calendar variables
- Implement {calendar:today}, {calendar:ym}, etc.
- Integrate with all URI-handling API endpoints
- Add comprehensive unit tests
- Update documentation
提交2:Rust CLI重构
feat: Rust CLI refactor with progress bar support
- Split HttpClient into BaseClient and FileUploader
- Add dynamic timeout configuration
- Add progress bar for compression/upload
- Configure via --progress flag or config file
* feat: support --parent, and change default root path for image
* feat: support --parent, and change default root path for image
* docs: fix docs
* fix: review comments
---------
Co-authored-by: openviking <openviking@example.com>
## feat(cc-memory-plugin): implement persistent sessions, native MCP, and async write path
This update transitions the Claude Code memory plugin from a one-shot capture model to a persistent, per-session integration with OpenViking. It introduces native MCP support directly from the FastAPI server, significantly expands the tool surface, and optimizes performance via detached async write hooks.
### Core Engineering & Capabilities
* **Persistent Sessions:** Reworked lifecycle hooks (SessionStart, PreCompact, SessionEnd) to maintain stable session IDs across the entire Claude Code conversation.
* **Native MCP Endpoint:** Replaced the Node.js MCP subprocess with a native `/mcp` endpoint on the OpenViking server.
* Expands to 9 specialized tools: `search`, `read`, `list`, `store`, `add_resource`, `forget`, `grep`, `glob`, and `health`.
* Propagates identity headers (`X-OpenViking-Account`, `X-OpenViking-User`) through the MCP transport.
* **Async Write Path:** Introduced a detached worker pattern for `auto-capture`, `session-end`, and `subagent-stop` hooks. Claude Code no longer blocks on network round-trips to the OpenViking server.
* **Multi-Source Recall:** Enhanced `auto-recall` to search across memories, resources, and skills with URI-deduplication and score-based filtering.
### Configuration & Integration
* **Unified Auth:** Standardized on `Authorization: Bearer` tokens.
* **Config Resolution:** Established a clear priority chain: **Env Vars → ovcli.conf → ov.conf → Defaults**.
* Added comprehensive environment variable coverage for all tuning fields (e.g., `OPENVIKING_SCORE_THRESHOLD`, `OPENVIKING_COMMIT_TOKEN_THRESHOLD`).
* **One-Line Installer:** Added an interactive bash installer (`install.sh`) that handles dependencies, `ovcli.conf` setup, and marketplace registration, with support for both self-hosted and Volcengine Cloud options.
### Bug Fixes & Refinement
* **Self-Injection Prevention:** Implemented block-stripping logic in `auto-capture` to prevent the plugin from re-storing its own injected context blocks into the memory pool.
* **Session Bypass:** Fixed a bug where `session-start` and `subagent-start` ignored bypass patterns.
* **Subagent Isolation:** Implemented `SubagentStart/Stop` hooks with isolated session IDs and specialized agent headers for memory segregation.
* **Docs & Maintenance:** Bumped version to `0.2.2`; added comprehensive agent integration guides; fixed Vue interpolation and markdown fence issues in documentation.
* docs: fix code-doc inconsistencies in English documentation
- Fix default server host: docs claimed 0.0.0.0 but code defaults to 127.0.0.1
- Fix GLOBAL_SEARCH_TOPK: docs said 3 but code uses 10
- Fix VLM model name: docs had doubao-seed-2-0-code-preview-260215, code uses doubao-seed-2-0-pro-260215
- Fix metrics file reference: pointed to nonexistent .vscode/.workdir/metric/METRIC_res.md
- Fix build prerequisite: Go replaced by Rust/Cargo (no .go files remain in repo)
- Fix embedding provider list: README listed 7 providers, code supports 13
- Fix CLI command inconsistency: two ov commands in sessions doc should be openviking
- Add missing session archive endpoint to API overview table
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* docs: revert ov→openviking CLI rename in sessions doc
Both `ov` and `openviking` are registered entry points for the same
Rust CLI binary (pyproject.toml). The short `ov` alias is intentional
and valid — reverting the previous rename.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* docs: sync same fixes to Chinese docs, README_CN, and README_JA
Apply the same consistency fixes from the English docs to:
- docs/zh/ (Chinese documentation)
- README_CN.md (Chinese README)
- README_JA.md (Japanese README)
Changes mirror the English fixes: server host default, GLOBAL_SEARCH_TOPK,
VLM model name, build prerequisites (Go→Rust), embedding provider list,
metrics file reference, and missing session archive endpoint.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>