Commit Graph
224 Commits
Author SHA1 Message Date
604275f272 feat(resources): support TOS auth args for HTTP imports (#4248)
* feat(resources): support source headers for HTTP imports

Allow HTTP(S) resource imports to pass request headers for authenticated object storage sources. Fetch authenticated sources into a request-scoped snapshot and keep credentials out of parser inputs and queued jobs.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* fix(resources): reserve source headers from args

Treat source_headers as a top-level add_resource field so it is rejected from args and filtered consistently from queued processor inputs.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat(resources): accept TOS auth through args

Replace generic source header passthrough with explicit tos_signature and tos_access args for HTTP TOS object imports. Keep credentials request-scoped and out of parser and queue payloads.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor(resources): name transient TOS args

Centralize TOS credentials that are accepted from args but excluded from durable resource jobs.

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-24 19:09:09 +08:00
MaojiaShengandTRAE CLI a7c77e6cf7 feat: add freshness-aware parent aggregation (#4180)
* feat: add freshness-aware parent aggregation

Defer wide-directory abstract/overview regeneration until the configured freshness threshold is reached while continuing changed-file semantic and vector processing.

Persist freshness metadata atomically, make parent bubbling L0-aware, preserve separate semantic/vector statuses, and keep explicit waits synchronous.

Rebuild every sampled summary on threshold refresh and always retry directory vectorization so stale sidecars or transient vector failures cannot be silently accepted.

Add focused coverage for freshness policy, pending-state consumption, sampled-summary refresh, vector retries, and parent bubbling.

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive

* feat: ov reindex support --recursive, and applied to memory

* feat: ov reindex support --recursive, and applied to memory

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
2026-08-21 16:30:44 +08:00
zihengli 00bc96258b feat: new tos connector args (#4129)
* feat: new tos connector args

* fix: skill ut

* fix: param check

* fix: param check

* fix: param check

* fix: clarify connector watch eventual consistency

* fix: allow plaintext connector watches and tighten TOS URI validation
2026-08-21 11:00:45 +08:00
agent 056f875e90 feat: restore user-scoped memory extraction policies (#4126)
* feat: add user-scoped memory extraction policies

* refactor: minimize user memory policy session changes

* fix: resolve user memory policy consistently

* refactor: resolve user memory policy once per commit

* refactor: simplify memory policy provider typing

* fix: apply server default user memory policy

* fix: allow resetting user memory policy
2026-08-20 20:28:33 +08:00
Jiajie - He/him/his 1efb0dce59 feat(compile): improve source materialization and long-running agent loops (#4059)
* feat(compile): compact agent context in-loop and remind iteration budget

* feat(compile): materialize sources for local exec and track reads

* feat(compile): survey-then-targeted read workflow and relaxed submission

* feat(compile): accept file sources, enable exec by default, update docs and tests

* fix(bot): harden compile source handling and compaction (#4099)

* feat(compile): add skill examples and update render

* feat(compile): add checkout workflow and task cancellation

* feat(cli): support compile task status and cancellation

* feat(examples): add compile knowledge graph tools

* docs(compile): document checkout and cancellation APIs

* docs(compile): add context compilation guides and skill examples
2026-08-20 20:17:55 +08:00
chuanbao666 421c73be9d fix(storage): 修复 ov add-resource在向量库返回4xx是吞异常问题 (#4160) 2026-08-20 17:42:28 +08:00
Qin Haojie 81eba498b4 fix(uri): server 入口校验并补全 URI,内部只用规范 URI (#4048)
* fix(uri): 明确规范 URI 与用户归属

- 在 API、MCP 等外部入口解析当前用户简写并校验 URI
- 让 Service、VikingFS、索引和 Reindex 只接收规范 URI
- 在 OVPack 中显式保存用户归属,避免 Admin 身份改变路径含义
- 移除 SDK 对非 URI 路径的隐式补全

* fix(sdk): preserve URI normalization before API calls

* fix(content): normalize write URI before routing

* fix(content): keep write policy scoped to content rules

* refactor(content): remove target wrapper validation

* refactor(uri): simplify scope validation
2026-08-19 19:02:39 +08:00
zgyandqin-ctx dc39985ad1 refactor: remove resource relation edges (#3956)
* refactor: remove resource relation edges

* fix: remove stale relation references

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-19 17:54:29 +08:00
agent afa5aae9a6 Revert "feat: add user-scoped memory extraction policies (#3906)" (#4122)
This reverts commit 6fc4d8fa57.
2026-08-19 15:34:05 +08:00
agent 6fc4d8fa57 feat: add user-scoped memory extraction policies (#3906)
* feat: add user-scoped memory extraction policies

* chore: leave deprecated v2 compressor unchanged

* feat: allow agent memory types for peer policies

* revert: disallow agent memory types for peer policies

* feat: complete user memory policy APIs and commit overrides

* refactor: simplify user memory policy settings

* refactor(admin): remove unused batch user settings API

* refactor(session): keep memory policy out of commit API

* refactor(memory): centralize peer memory type resolution

* fix(admin): restore user registration flow

* fix(session): preserve memory policy compatibility

* fix(session): preserve disabled legacy policy output

* revert(session): remove queue memory policy dual write
2026-08-19 15:32:37 +08:00
Qin Haojie 67603473a5 perf(resource): speed up wait=false add-resource (#4100)
* perf(resource): make wait=false ingestion durable

Move source preparation and parser work behind the durable AddResource task
boundary, while keeping task-owned credentials private and short-lived.

* fix(feishu): preflight add-resource roots

* test(fs): align tree rel_path fakes with binding
2026-08-18 23:22:13 +08:00
MaojiaShengandqin-ctx 24cc8c6ee9 feat: refine OKF sidecar metadata handling and write protection (#4092)
* feat: implement l0-l1-okf-sidecars

* feat: implement l0-l1-okf-sidecars

* feat: implement l0-l1-okf-sidecars

* feat: implement l0-l1-okf-sidecars, fix review comments

* feat: implement l0-l1-okf-sidecars, fix review comments

* feat: implement l0-l1-okf-sidecars, fix review comments

* feat: implement l0-l1-okf-sidecars, fix review comments

* test: prune semantic sidecar coverage

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 23:21:06 +08:00
zgy 868a9600d0 fix(mcp): return read errors from underlying fs (#4093) 2026-08-18 17:58:04 +08:00
22f0003320 Perf/reindex vector enqueue concurrency (#4071)
* perf: parallelize reindex vector enqueue

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: TRAE CLI <noreply@bytedance.com>

* perf: parallelize add resource vector enqueue

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* fix: cancel vector enqueue siblings on failure

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor: clarify file vectorization concurrency config

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* test: consolidate vectorization concurrency coverage

---------

Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 16:58:19 +08:00
zgy f6ba06bbf8 fix(mcp): guide directory read failures to list (#4056) 2026-08-18 12:27:00 +08:00
d08d9b99e6 Feat/shared temp upload decouple (#4054)
* refactor(server): decouple shared temp uploads

Remove shared-upload consumption locks and state transitions so uploads remain reusable within their account for 24 hours. Store them under the fixed internal viking://upload root, clean expired account-local directories on new shared uploads, and simplify metadata and deletion cleanup.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(server): configure shared temp upload ttl

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): share temp upload ttl

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): rename temp upload ttl

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): flatten shared temp uploads

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): simplify shared upload metadata name

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* refactor(server): remove legacy shared upload formats

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(server): allow disabling temp upload cleanup

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>

* refactor(server): timestamp shared temp upload directories

Store shared uploads under timestamp-prefixed directories and use directory names for TTL cleanup instead of storage modification times.\n\nCo-authored-by: TRAE CLI <noreply@bytedance.com>

Co-authored-by: TRAE CLI <traecli@bytedance.com>

* test(server): prune shared upload tests

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: TRAE CLI <traecli@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-18 12:13:04 +08:00
Zonas ZhouandClaude 6e77291265 feat(pdf): refactor MinerU parsing to the official file_parse API (#3953)
* feat(pdf): refactor MinerU parsing to the official file_parse API

* feat(pdf): remove mineru_api_key from configuration and examples

* feat(pdf): preflight MinerU /health during service initialization

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
2026-08-17 13:48:49 +08:00
bot-of-qin-ctxandbot-of-qin-ctx 5de59a1141 fix(tasks): keep parent semantic refresh asynchronous (#4041)
Co-authored-by: bot-of-qin-ctx <222410531+qin-ptr@users.noreply.github.com>
2026-08-17 00:39:18 +08:00
Qin Haojie 46f0d60c60 fix(pack): restore account backups without deleting target-only data (#4003) 2026-08-14 16:26:32 +08:00
Jiahui Zhou 62fbf68e84 Discard invalid write-time search tags (#4000) 2026-08-14 14:25:01 +08:00
chenjwandqin-ctx ed1bd4b897 refactor(memory): 统一 V3 提取并提升会话提交与评测稳定性 (#3346)
* fix(memory): disable unsupported tool and skill extraction

* refactor(memory): retire SessionCompressorV2

* docs: design service import cycle fix

* fix(import): break QueueFS service import cycle

* update

* docs: design memory overview lock coverage fix

* fix(memory): cover overview files in update leases

* docs: design session commit default concurrency 50

* perf(queue): raise session commit concurrency to 50

* docs: revise session commit concurrency design

* docs: plan session commit default 8

* perf(queue): default session commit concurrency to 8

* fix(bot): disable cron during eval chat

* docs: design memory link lock stabilization

* docs: plan memory link lock stabilization

* fix(memory): stabilize link update lock coverage

* docs: cover remapped post-group link locks

* docs: design plain-content patch validation

* docs: design first failing patch diagnostics

* fix: report actual failing patch block

* fix(memory): remap replacement links before locking

* fix(bot): include trusted identity in health probe

* test: consolidate memory contract coverage

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-13 21:48:49 +08:00
Qin Haojie 9d5646169b fix(observer): keep empty retrievals diagnostic-only (#3985)
Remove the cumulative retrieval error state and preserve zero-result metrics
without using retrieval yield to determine component health.
2026-08-13 21:46:31 +08:00
Qin Haojie ec18c1dcd8 fix(observer): treat empty retrievals as healthy (#3975)
Record actual search execution errors at the service boundary and use those
errors, rather than empty-result rates, to determine retrieval health.
2026-08-13 21:19:36 +08:00
Jiahui ZhouandTRAE CLI 482434ef6e feat(reindex): support tag updates (#3964)
* feat(reindex): support tag updates

Add replace and append tag modes to reindex vector rebuilds, preserve omission-aware behavior, and propagate options through background tasks and namespace rebuilds. Align Python, TypeScript, Go, and CLI interfaces with tests and documentation.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): lock file targets exactly

Use an exact path lock for existing file targets while retaining tree locks for directories and prune-orphans scopes. Add a regression test for single-file reindex.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(reindex): handle prune file targets

Use exact locks for existing file targets in prune-orphans mode while retaining tree scope for missing targets. Document the existing Go ReindexOptions wait semantics and add lock regression coverage.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
2026-08-13 13:41:12 +08:00
Jiajie - He/him/his 3577f77423 fix(compile): salvage partial output on timeout and iteration limits (#3948)
* fix(service): break startup circular imports with lazy exports

* fix(fs): avoid root semantic refresh when removing resource scope

* fix(compile): preserve existing wiki links

* fix(sdk): extend HTTP timeout for blocking batch writes

* fix(compile): salvage workspace output on runtime timeout

* feat(compile): support runtime timeout and salvage partial output

* fix: expand compile task and output limits

* revert file

* fix(compile): harden salvage and deadline handling

* update

* fix(compile): address salvage review feedback

* fix(compile): normalize escaped salvage links
2026-08-12 18:51:35 +08:00
Qin Haojie c96fbcb85f fix(session): 避免后序归档阻塞队列 Worker (#3944)
* fix(session): 避免归档任务阻塞队列 Worker

后序归档不再占用 Worker 等待前序任务,并根据 QueueFS work 识别和跳过无法恢复的孤儿归档。

* fix(session): 仅调度队首归档任务

同一 Session 只将最早的未完成归档放入 QueueFS,后续归档在前序结束后再依次入队,并兼容升级前已入队任务。

* fix(session): 降低队首归档调度的存储读取

用 QueueFS 运行时索引判断 Session 是否已有归档任务,正常完成后直接调度相邻 Archive,避免每次 Commit 和任务结束都扫描完整历史目录。

* fix(session): 恢复每个归档任务独立入队
2026-08-12 17:35:46 +08:00
zihengli cd55ec89a6 feat(assets): support fixed Git commits, explicit targets, and private repository auth (#3703)
* feat/openviking_assets_support_git_commit_id

* feat/openviking_assets_support_to

* feat/private_git_support_watch

* fix: doc_and_ut

* fix: doc_and_ut

* fix: adapt git token url
2026-08-11 14:07:21 +08:00
Qin Haojie 31e01c58a2 feat(admin): 清理已删除用户数据 (#3924)
* feat(admin): 清理已删除用户数据

删除用户时立即撤销身份,并通过持久队列完成用户数据清理。

* fix(admin): 删除用户时清理任务记录

* fix(admin): 避免过早判定用户任务取消失败
2026-08-11 11:18:40 +08:00
Qin Haojieandsponge225 b877ababa5 perf(queue): 流式调度语义向量化任务 (#3636)
* perf(queue): stream semantic vectorization tasks

* fix(queue): isolate semantic work context

* feat(config): make parse concurrency configurable

* test(queue): update semantic vectorization fakes

* fix(queue): correct semantic vectorization conflict resolution

---------

Co-authored-by: sponge225 <1670519171@qq.com>
2026-08-10 21:24:11 +08:00
Qin Haojie 7abd6ab249 refactor(client): remove Python embedded mode (#3712)
* refactor(client): remove Python embedded mode

Consolidate Python consumers on the HTTP SDK while keeping shared server and storage capabilities unchanged.

* refactor(client): remove obsolete embedded leftovers
2026-08-10 18:00:00 +08:00
agent a779c62a0f feat(agent-evolution): add trajectory date filters (#3915)
* feat(agent-evolution): add trajectory date filters

* refactor(agent-evolution): simplify date validation
2026-08-10 17:53:41 +08:00
Qin Haojie 41f638fbe4 fix(observer): ignore historical lock diagnostics in health (#3920) 2026-08-10 17:49:35 +08:00
zgyandqin-ctx 75a1447dc2 perf(queuefs): defer embedding content materialization (#3871)
* Avoid queueing full content for local vector backends

* perf(queue): defer full content materialization

* perf(queuefs): keep deferred content payload empty

* perf(queuefs): separate embedding input from full-text content

---------

Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-10 17:06:11 +08:00
8acaf7f872 fix(watch): 避免资源移动期间持有全局锁 (#3833)
* fix(watch): avoid global lock during resource moves

Allow unrelated watch operations to continue while viking_fs.mv is running, while serializing overlapping resource paths with a move fence. Preserve transaction integrity across persistence failures, rollback, and caller cancellation.

* feat(resource): add URI mutation coordinator

* refactor(watch): separate target rewrites from resource moves

* refactor(fs): own resource move watch transaction

* feat(watch): coordinate refreshes with URI mutations

* refactor(core): share URI mutation coordinator

* test(watch): focus URI move coverage

* test(watch): reuse existing URI move coverage

---------

Co-authored-by: chenpengfei <chenpengfei@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-10 16:39:37 +08:00
Yu ZhangandClaude Sonnet 4.6 6617a92cdd fix(task-tracker): delete expired persisted tasks (#3913)
Keep expired terminal tasks cached when persistent deletion fails so cleanup can retry without resurrecting stale records after restart.

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-08-10 16:30:56 +08:00
7f6085a2f9 feat(memory): support event tag filtering (#3850)
* feat(memory): support event tag filtering

Add session-level default event tags, commit-time overrides, durable queue propagation, and first-write vector index tagging. Include config update APIs and coverage for serialization, concurrency, extraction, and HTTP behavior.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(memory): expose event tags in SDKs and CLI

Add session default tag configuration, config updates, and commit-time event tag overrides across embedded Python, standalone Python, TypeScript, Go, and the Rust CLI. Preserve explicit empty-tag semantics and document each public interface.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(sdk): align legacy session tag APIs

Forward commit-time event tags through the legacy Python HTTP shims and align BaseClient session signatures without adding a new abstract-method requirement for existing subclasses.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* feat(session): allow updating auto-commit policy

Extend PATCH session config to atomically update event tags and auto-commit settings. Merge policy objects by field, use explicit null to disable automatic commits, preserve omitted fields, and expose the contract across SDKs and CLI.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* fix(session): align session config interfaces

Replace the generic session create config JSON flag with explicit event-tag and auto-commit options. Preserve omitted, object, and null auto-commit semantics across HTTP, embedded clients, SDKs, and CLI, reject ambiguous null policy fields, and handle nullable event configuration consistently.

Co-authored-by: TRAE CLI <noreply@bytedance.com>

* test(session): trim redundant event tag tests

---------

Co-authored-by: TRAE CLI <noreply@bytedance.com>
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
2026-08-10 11:58:02 +08:00
lazyayuan cbc3907791 fix(retrieve): store L1 overview in abstract scalar so Rerank sees L1 text (#3714) 2026-08-08 01:40:32 +08:00
Kchenandchenpengfei 7038ba0694 优化 TaskTracker 并发,消除全局异步锁阻塞 (#3829)
* perf(task): 移除 TaskTracker 全局异步锁

按 task_id 和业务键细化并发控制,限制持久化 I/O 并保持跨事件循环及取消语义一致。

补充 TaskTracker 并发、缓存合并、取消和 AGFS 集成回归测试。

* 修订开源协议

---------

Co-authored-by: chenpengfei <chenpengfei@bytedance.com>
2026-08-06 18:43:09 +08:00
Jiahui Zhou 6f43a4040c feat: support processing mode for content write (#3615) 2026-08-05 21:42:33 +08:00
Jiahui Zhou d2056e971d Feat/session auto commit v2 (#3736) 2026-08-05 16:18:49 +08:00
agent 73a70195b1 feat(agent-evolution): aggregate outcomes and refine experience snapshots (#3742)
* feat(agent-evolution): aggregate trajectory outcomes by experience

* fix(agent-evolution): snapshot only visible experience changes

* docs(api): document agent evolution queries
2026-08-05 14:52:01 +08:00
Kchen 8d1d52fe5d 资源导入:支持解析后不拆分文档 (#3645) 2026-08-05 11:34:10 +08:00
agent 2ced3f1539 feat(agent-evolution): track experience trajectory lineage (#3727)
* feat(agent-evolution): track experience trajectory lineage

* fix(agent-evolution): return matched trajectory records

* fix(agent-evolution): stabilize lineage pagination
2026-08-04 16:15:06 +08:00
Kchenandchenpengfei c7ee8e753a feat(queue): make ExternalParse worker concurrency configurable (#3710)
* feat(config): make external parse concurrency configurable

* refactor(config): move external parse concurrency to queue workers

---------

Co-authored-by: chenpengfei <chenpengfei@bytedance.com>
2026-08-04 12:10:01 +08:00
agent 1494dc3052 feat(agent-evolution): improve provenance, history, and account settings (#3695)
* feat(agent-evolution): record trajectory mapping in snapshot commits

* feat(agent-evolution): apply global switch immediately

* fix(snapshot): hide memory fields in visible history

* fix(agent-evolution): preserve batch snapshot provenance

* feat(agent-evolution): scope runtime settings by account

* fix(agent-evolution): serialize experience snapshot finalization
2026-08-03 20:52:46 +08:00
dingben b65f118521 feat(config): add enable_watch_scheduler toggle for read-only replicas (#3704)
* feat(config): add enable_watch_scheduler toggle for read-only replicas

Add a top-level `enable_watch_scheduler` config flag (default true) and gate
`WatchScheduler.start()` on it in service initialization.

Read-only replicas that share a writer's data must not run the periodic
watch/refresh background loop: it would execute writes against shared storage
(vectordb / backups) and race the writer when persisting watch task state,
which has no cross-process lock. The scheduler instance is still created and
wired for on-demand read paths; only its background loop is skipped.

Defaults to true, so existing single-instance deployments are unaffected.

* fix

* fix
2026-08-03 20:29:00 +08:00
Hao Zheandzhiheng.liu af914ca27b fix(core): harden privacy and background failure handling (#3548)
* fix(server): stop exporting raw query strings and buffering zip responses in observability

Sweep findings: B-03, B-13. Prevent query secrets from reaching traces and keep ZIP responses streaming.

(cherry picked from commit d8ac3dc33b)

* fix(session): tolerate missing/corrupt archive in Phase-2 replay

(NotFoundError / _ArchiveMessagesCorruptError) on a missing or corrupt
archive messages.jsonl instead of returning []. That PR added skip-on-
missing tolerance to the read path (_get_uncovered_archive_messages) and to
resume_queued_commit, but not to the Phase-2 commit replay path
(_prepare_phase2_archive_messages), which calls _read_archive_messages
unguarded while rolling earlier failed archives into the current commit.

Consequence: a terminally-failed earlier archive whose messages.jsonl is
missing/corrupt (legacy "no messages" terminal data, or produced by #3417's
own archive_read terminal path) makes every subsequent commit's Phase-2
extraction raise -> caught by _run_memory_extraction's except -> the current
archive is terminal-failed too. Because the poisoned archive is only removed
from replay once "covered" (which requires a later archive to complete), and
no later archive can ever complete, the session's memory extraction is
permanently poisoned. Raw messages are safe, but extraction is stuck.

Fix: wrap the replay-loop _read_archive_messages call in the same tolerance
_get_uncovered_archive_messages already uses -- skip + warn on not-found
(_is_storage_not_found) and on _ArchiveMessagesCorruptError, re-raise real
storage failures. The skipped archive stays in covered_failed so the current
archive's .done marks it covered, clearing the poison permanently.

Adds a regression test asserting the replay skips a failed archive with a
missing messages.jsonl (and marks it covered) instead of raising, and that a
real storage failure still propagates.

Follow-up to #3417.

(cherry picked from commit 5b8ec9e68a)

* fix(client): align client surfaces without leaking memory metadata

Reconstructs the client-parity work from upstream PR #3439 on current main and strips reserved memory metadata before line slicing in both embedded and HTTP reads.

Based-on: 48b411d58c

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>

* fix(index): propagate semantic vectorization failures safely

Reconstructs upstream PR #3437 on current main, carries enqueue failures through SemanticDagExecutor, and drains the attempt's embedding tracker before retry-visible failure propagation.

Based-on: 02387deb09

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>

* fix(core): close privacy and embedding failure gaps

* fix(memory): strip repeated metadata trailers

* fix(core): close public memory visibility gaps

* ci: skip embedding-dependent resource test without secrets

---------

Co-authored-by: zhiheng.liu <zhiheng.liu@bytedance.com>
2026-08-03 16:07:35 +08:00
Qin Haojie d30f49be6f fix(resource): preserve synchronous ingestion errors (#3698) 2026-08-03 15:43:52 +08:00
Qin Haojie 9295a3b955 fix(session): remove actor scope from session lifecycle (#3661)
Keep sessions user-scoped and remove legacy agent fallback that could leak an actor view into commit memory writes.
2026-07-31 19:52:19 +08:00
Qin Haojie fd42b1ad92 feat(tasks): support task cancellation (#3577)
* feat(tasks): support task cancellation

* refactor(tasks): scope cancellation to current user

* feat(cli): support task cancellation

* refactor(tasks): make cancellation queue-aware

* refactor(tasks): simplify cancellation bookkeeping

* test: remove task cancellation coverage

* refactor(tasks): trim cancellation coordination

* fix(tasks): contain cancellation to owned work

* feat(tasks): persist resource source metadata

* fix(tasks): handle cancelled work consistently

* refactor(tasks): make completion queue-aware

* fix(tasks): persist terminal state before queue ack

* test(tasks): remove added lifecycle tests

* docs(tasks): document task cancellation
2026-07-30 20:34:27 +08:00