Commit Graph
4 Commits
Author SHA1 Message Date
Haoyu Zhangandzhanghaoyu.la aa53e7aede feat: 实现 commit、restore、show 文件系统多版本管理功能 (#2756)
* feat: 实现 commit、restore、show 文件系统多版本管理功能

fix: 修复commit时删除文件

fix: commit 的 fast path 1 添加 Racy-clean 机制

fix: 将 sdk 中的 git 命令改为 snapshot 命令,同步修改单测

fix: 多版本管理的文件存储目录改为 .ovgit

feat: snapshot cli 渲染

fix: 修复 restore 时将删除的文件回滚时,目录不存在的问题

feat: restore 命令的 project_dir 参数改为可选,不传时默认全目录回滚

feat: 更新文档

fix: 删除暂未使用的配置参数

feat: 新增示例脚本

fix: 修复示例代码

fix: 修复 restore 返回的 task id 任务完成状态

feat: 在 restore 修改文件系统时加锁

fix: fix openviking_sdk

* feat: 将git多版本管理功能改为默认打开,并复用agfs的配置参数作为默认值

* fix: restore 命令改为先完成 ref 一致性协议再写回 VFS;object store 并发改为使用唯一 temp path

* fix: 在 git 配置检验层去除未实现的cas_mode = "redis_lock"模式

* fix: 在 Rust GitService 边界统一校验 account

* fix: 当前commit不支持通过 path 传入目录,增加报错信息

* fix: 将git文件默认存储路径统一为 .ovgit

* fix: restore 时写入 VFS 失败时返回详细的报错,并继续触发 reindex

* fix: 校验 commit、restore、show 的路径

* feat: 实现 commit 时指定目录

---------

Co-authored-by: zhanghaoyu.la <zhanghaoyu.la@bytedance.com>
2026-06-25 11:28:04 +08:00
t0saki 41a33ec16a feat(mcp): progressive single-entrypoint upload for local files (#1847)
* feat(mcp): progressive single-entrypoint upload for local files

Extends `add_resource` MCP tool to handle local-file paths via a server-orchestrated
two-step flow, eliminating the need for `ov` CLI in sandboxed agent environments
(Claude web, Manus) where local FS is unavailable and CLI install is blocked.

Behavior:
- Remote URL  → unchanged.
- Local path  → server mints a 6-char base62 token, returns prose Step 1 / Step 2
                instructions pointing at /api/v1/resources/temp_upload_signed.
                Agent uploads, then re-calls add_resource(temp_file_id=...).
- temp_file_id → resolved against per-tenant subdir, ingested via existing pipeline.

Token: in-memory dict, 10-min TTL, dict.pop doubles as replay protection.
Per-tenant temp-dir isolation ({root}/{aid}/{uid}/{tfid}); legacy CLI uploads
keep flat layout via dual-lookup in resolve_uploaded_temp_file_id.

Public base URL resolves env > config > listen-host fallback (12-factor: runtime
env trumps image-baked config; production deployments behind MCP proxy + nginx
must set OPENVIKING_PUBLIC_BASE_URL since the agent-facing URL is not derivable
from the server's request scope).

* feat(mcp): infer public base URL from request headers + emit fallback hint

Adds a third fallback layer between explicit operator config and listen-host
fallback: capture X-Forwarded-Host / X-Forwarded-Proto / Host headers in the
MCP identity middleware and use them when neither OPENVIKING_PUBLIC_BASE_URL
nor ServerConfig.public_base_url is set.

Resolution order is now: env > config > X-Forwarded-* > Host > listen-host.
The first two are explicit; the rest are inferred. When an inferred source is
used, the add_resource prose response appends a troubleshooting hint asking
the user to set OPENVIKING_PUBLIC_BASE_URL on the server if upload fails —
because inferred URLs can be wrong if the reverse-proxy chain doesn't forward
X-Forwarded headers, or if the server listens on 0.0.0.0.

Documents the variable in docker-compose.yml (commented-out env block) and
in the MCP integration guides (zh + en) — covers when it's required and the
full resolution chain.

* fix(mcp): address Copilot review on PR #1847

- Relax temp_file_id regex from `[a-zA-Z0-9]+` extension to any non-separator
  chars, and dedupe to a single TEMP_FILE_ID_RE in local_input_guard. The old
  pattern rejected `Path("report.my-file").suffix == ".my-file"` and similar
  legitimate filenames, breaking the progressive upload flow.
- Hoist `_resolve_temp_or_path` import to module level in mcp_endpoint
  (verified no circular import).
- Add `_is_safe_namespace_component` defense-in-depth at the signed-upload
  route so a future code path that mints tokens from less-trusted input
  still cannot escape the per-tenant directory.
- Broaden partial-file cleanup to any exception via try/finally + flag,
  not just HTTPException — prevents OSError/IO failures from leaving
  half-written files behind.
- Scope `_cleanup_temp_files` to the tenant subdir at the signed-upload
  route to bound the rglob scan; the legacy `/temp_upload` route still
  cleans the root level.
- Add round-trip test for unusual filename extensions (.my-file, .bak~, .中文).

* docs(mcp): reflect server-minted temp_file_id in progressive-upload flow

Post-rebase onto TempUploadStore, the agent no longer learns the temp_file_id
from the MCP prose — the server mints it at upload time and returns it in the
JSON response body. Update both en + zh docs accordingly. Also note that the
signed endpoint shares the same persistence layer as /temp_upload, so
local/shared modes (and multi-worker via shared) apply uniformly.

* fix(mcp): address Copilot review on rebased PR #1847

- Drop `upload_signed_max_bytes` config field. The signed endpoint now relies on
  TempUploadStore's streaming `temp_upload.shared_max_size_bytes` check (single
  source of truth, fires even when Content-Length is missing/chunked). Map
  oversize from InvalidArgumentError back to 413.
- Normalize `X-Forwarded-Host` / `X-Forwarded-Proto` to the first comma-separated
  value in `_resolve_public_base_url`, matching the OAuth issuer resolver. Fixes
  malformed upload URLs under multi-hop proxy chains.
- Complete the `public_base_url` field comment to reflect all five fallback layers
  in the resolver, not just env > field > listen.
- Add `watch_interval` / `to` parameters to the MCP tool tables in both en + zh
  integration guides — they were merged in from main's Watch Management API
  during the rebase but the table wasn't updated.
2026-05-19 12:32:45 +08:00
MaojiaShengandopenviking ce998873f9 lisence: change the main lisence to AGPL-3.0 (#1085)
* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

* lisence: change the main lisence from Apache-2.0 to AGPL-v3

---------

Co-authored-by: openviking <openviking@example.com>
2026-03-30 14:37:42 +08:00
qin-ctx 3165ffa0da feat: add HTTP Server and Python HTTP Client (T2 & T4) (#109)
* feat: add Server/Client architecture with HTTP API and restructure documentation

  - Implement FastAPI-based HTTP server (openviking/server/) with REST API
  - Add client abstraction layer (LocalClient, HTTPClient, BaseClient)
  - Add CLI entry point (python -m openviking serve)
  - Fix bugs: session.session_id, link/unlink param names, hmac.compare_digest
  - Restructure docs: remove numbered prefixes, add guides/, rewrite API reference
    with both Python SDK and HTTP API (curl) examples (en/zh)
  - Add quickstart-server, deployment, authentication, monitoring guides
  - Update examples and design docs to reflect implementation

* 提供单测 和 文档

* Merge branch 'main' into feature/server_client

* feat: add server/client examples and server tests

* fix: cross-references

* fix : tests
2026-02-09 21:12:15 +08:00