* fix(feishu): support legacy doc imports
Keep legacy Feishu doc resources on the doc API path instead of routing doccn tokens through docx blocks.
* test(feishu): trim legacy doc coverage
Keep legacy doc import coverage focused on public Feishu accessor behavior and remove extra mock-level assertions.
viking://user is a protected namespace root in _ensure_supported_delete_namespace,
so viking_fs.rm("viking://user/", recursive=True) was silently rejected with
PermissionDeniedError. The exception was swallowed by try/except, leaving
account metadata deleted from accounts.json but all filesystem data intact.
Use _async_agfs.rm("/local/{account_id}", recursive=True) directly to bypass
the namespace guard. This also now correctly deletes _system/users.json which
was previously missed (not under viking://user/ or viking://resources/).
The public MountableFS constructors do not initialize a pathlock manager, but
multi-write mount and raw copy used expect() on the missing manager, so calling
either fast path on such an instance panicked.
Return Error::Config with a clear message instead; tests that need the success
path already build the manager via with_test_pathlock_manager().
* fix(sdk): expose tree level limit
Why:
- Align all HTTP SDKs with the documented filesystem tree contract and make the bundled Python example valid.
- Let callers control traversal depth without bypassing the SDK clients.
What:
- Expose language-idiomatic tree depth options in Python, TypeScript, and Go.
- Forward level_limit while preserving the default depth of 3 and an explicit depth of 0.
- Add request-contract tests for Python async/sync clients, TypeScript, and Go.
Risk:
- Adding a field to exported Go TreeOptions can affect external unkeyed composite literals; keyed literals, nil options, and zero-value options remain compatible.
- Server behavior is unchanged.
Tests:
- Python: 111 passed, 1 known baseline test deselected; focused tree tests, Ruff check, and Ruff format check passed.
- TypeScript: npm test -- --run; npm run typecheck; npm run build; npm run test:node-types; npm pack --dry-run.
- Go: go vet ./...; go test ./... -count=1; go test -race ./... -count=1.
Live Docs:
- Not applicable; the existing English and Chinese filesystem API references already define level_limit.
* test(sdk): fold tree level limit cases into existing fs option tests
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
Co-authored-by: Claude <noreply@anthropic.com>
- VolcEngine selection now opens an access-tier submenu: Agent Plan
(api/plan/v3), Coding Plan (api/coding/v3), or pay-as-you-go API, with
doubao-seed-2.0-lite / doubao-embedding-vision defaults for the plans
- BytePlus gains the same submenu with ModelArk Coding Plan
(api/coding/v3, dola-seed-2.0-lite / skylark-embedding-vision) and
pay-as-you-go
- Embedding 'Other (manual)' becomes a Custom/manual submenu offering
interactive OpenAI-compatible prompts (URL, key, model, dimension)
alongside the editor hand-off
- Custom VLM/embedding prompts accept !back to return to the provider
menu; plan submenus support back navigation and seed defaults from the
existing config endpoint (unknown volces.com/bytepluses.com endpoints
are offered as a keep-current option)
- Two-step flow seeds the VLM plan menu from the embedding tier choice;
summaries now show the api_base so tiers are distinguishable
- Fix provider re-detection for BytePlus plan endpoints (domain-based,
since VolcEngine and BytePlus share the volcengine provider string)
- Document the plan endpoints in ov.conf.example
* perf(resource): make wait=false ingestion durable
Move source preparation and parser work behind the durable AddResource task
boundary, while keeping task-owned credentials private and short-lived.
* fix(feishu): preflight add-resource roots
* test(fs): align tree rel_path fakes with binding
* docs: fix integration docs and comments that contradict the code
- codex: credential resolution in the default `auto` mode is env-first — `credentials.mjs`
only falls back to `ovcli.conf` when no credential env var is set, while the docs and the
`config.mjs` header comment claimed `ovcli.conf` wins by default. Also document
`OPENVIKING_CREDENTIAL_SOURCE=cli`, which was undocumented.
- codex: the four hook scripts send the key as `X-API-Key` in addition to
`Authorization: Bearer`; the README documented Bearer only.
- claude-code: the OV session id is `cc-<cc_session_id>` verbatim (`deriveHarnessSessionId`
does no hashing), not `cc-<sha256(cc_session_id)>`.
- claude-code: `hooks.json` registers 9 hooks, not 7 — the responsibilities table was
missing the `PreToolUse` `viking://` guard and the `PostToolUse` skill-experience hook.
- claude-code: archival is triggered client-side (the `Stop` hook commits once
server-reported pending tokens cross `commitTokenThreshold`, default 20000, plus
unconditional commits from `PreCompact` / `SessionEnd` / `SubagentStop`). The README
attributed it to a server-side `auto_commit_threshold`, but
`memory.session_auto_commit.default_enabled` is false and no plugin sends a policy.
- trae / opencode: the MCP proxy transparently exposes the full server tool set (16 tools);
the docs listed a 4-item sample or 11-13 tools and omitted `tree` / `write` / `edit`.
- trae-cli: the installer registers the MCP server as `openviking-memory`, but the verify
step told users to look for `openviking`.
- pi: the manual install block omitted the `pi install <dest>` registration step that the
one-click installer runs, so a hand-copied extension is never registered.
- install.sh: `--uninstall` handles cursor, trae, trae-cn, trae-cli and zcode; the `--help`
text still said Cursor/TRAE only.
- mcp_endpoint.py: the module docstring enumerated 13 tools and omitted `recall`,
`list_watches` and `cancel_watch`; replaced the stale enumeration with a pointer to the
`@mcp.tool` registrations.
* docs: add a cross-integration capability reference page
The agent-integrations section had per-integration install guides but no place
to compare integrations against each other. This adds one bilingual page that
does that, and wires it into the existing pages in both directions.
- New page `docs/{en,zh}/agent-integrations/16-capability-reference.md`: a
dimension-first comparison of every OpenViking integration — active tool
surface, automatic hook surface, install/credential/config layering, recall
and injection, session and commit lifecycle (including a shutdown-path x
harness end-state matrix), compaction takeover, write/delete boundaries,
degradation, and a per-harness profile card for each integration.
- Sidebar: `StructuredSidebarCopy` gains an optional `topItems` field so a
section can list flat entries next to its overview; agent-integrations uses
it to place the new page beside the overview. Other sections are unaffected.
- Links both ways: the overview and all 14 per-integration pages link to the
reference, and the reference links back to each integration page from its
profile card, from the non-coding integration table, and from the custom
agent integration paths. Section cross-references (§x.x) are real in-page
anchor links, generated from the built heading ids.
- trae-cli is documented as TraeCode CLI 2.0 only, installed through a codex
plugin alias; 1.0 and its standalone plugin are called out as unsupported.
- The MCP tool surface is described as 15 tools throughout, matching the
removal of the `recall` tool in favour of `search` with `mode="context"`.
Pages outside this change that still mention an MCP `recall` tool
(04-codex, 12-cursor, 15-agent-plugins, guides/06-mcp-integration) need a
follow-up sweep once that removal lands.
* docs: 更新服务端 MCP 工具面描述,简化信息并明确更新方式
* docs(hermes): recommend memory setup openviking
Point Hermes docs at `hermes memory setup openviking` and describe the
real wizard. Shorten Volcengine console agent guides to TOS + cloud API
key, and mark docs/images as console-only.
* docs(hermes): drop setup filler
Keep the command and the two connection paths. Remove picker
explanations and wizard narration.
* docs: keep images AGENTS.md.local local-only
Ignore AGENTS.md.local like AGENTS.md. Drop the unused
docs/images/README.md.
* docs(console): keep harness setup to command plus API key
Drop installer narration, idempotency notes, and copied site
guides. Console pages only need the TOS command and cloud key.
* docs(console): restore Install / Verify / Troubleshoot
Keep the short cloud setup, put it back under the three section
headings the console pages use.
* docs(console): add Reference links
Point each harness page at docs.openviking.net, the coding-agent
blog where it exists, and the example source.
* docs(console): label Reference as manual settings and blog
Use Docs on Manual Settings for the full site page. Use Blog
about how it works where a how-it-works writeup exists.
The official npm bin (ov.mjs) starts with #!/usr/bin/env node. The Python
entry-point fallback skipped every shebang file on PATH, so the Node wrapper
was never exec'd and users got 'ov binary not found'.
Only compare against and skip the current Python entry point itself; other
PATH executables (including the Node shebang wrapper) are exec'd normally, and
exec failures are no longer swallowed.
* chore: remove dead git tuning knobs and duplicate release/frontend files
- GitTuningConfig: drop upload_concurrency, restore_concurrency,
ref_cas_max_retry, and ref_cas_backoff_ms, which were parsed but never read
anywhere (verified no source readers). Keep commit_index_enabled and
blob_exists_precheck_enabled, the two knobs that actually take effect.
- Design doc: mark the removed knobs as roadmap items to be added back when
the behavior lands, and correct stale 'not implemented' claims
(validate_account_id is enforced at the Git service entry; blob reads are
limited via show_with_limit).
- Remove .github/workflows/release-vikingbot-first.yml: a historical one-off
PyPI release workflow whose bot/ package lacks build metadata.
- web-studio: delete pnpm-lock.yaml and the pnpm-only package.json block;
the Makefile and CI already use npm + package-lock.json as the single
install chain. Net -9,695 lines.
* docs: align cleanup notes with current behavior
---------
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
- Root pytest config excludes the self-contained api_test/oc2ov_test E2E
subprojects so the root collection no longer descends into them.
- Gemini E2E module skips via importorskip when google.genai is absent,
instead of failing at import time before the skip check.
- Session lifecycle tests reference the existing partial-based client
fixture instead of the removed AsyncOpenViking API.
- The remote-server ensure_resources_dir fixture is no longer session-wide
autouse; it is injected only into cli_remote-marked tests, and the
cli_remote marker is registered in the root config.
* chore(web-studio): remove dead code (unreachable files and unused exports)
Static sweep of web-studio/src for code no module reaches from the
main.tsx / routeTree.gen.ts entry graph, plus exported symbols nothing
references anywhere (including their own file and tests).
Deleted files:
- src/router.tsx — superseded by the inline createRouter in main.tsx
- src/lib/sessions/generate-title.ts — never called
- src/lib/sessions/types/session.ts — re-export barrel nobody imports
- src/components/ui/{breadcrumb,combobox,context-menu,input-group,progress}.tsx
— shadcn primitives never added to any screen; re-addable via `shadcn add`
Removed unused exports (and the imports/constants they were the last
consumer of):
- lib/admin-options.ts: sortedAccounts
- lib/sessions/types/chat.ts: ChatState
- lib/sessions/types/message.ts: getTextContent, getToolParts, getContextParts
- routes/home/-lib/format.ts: formatDateKey, formatTimestamp
- routes/playground/-lib/types.ts: VikingEntryHandler
- routes/playground/-lib/utils.ts: buildBreadcrumbs
- routes/resources/-hooks/viking-fm.ts: usePrefetchVikingFsList, useVikingFind
- routes/resources/-lib/normalize.ts: sameUri, normalizeUriForDisplay
- routes/resources/-lib/upload.ts: getExtensionFromName
No behaviour change. `vite build` succeeds, `tsc --noEmit` output is
byte-identical to main, and `vitest run` shows the same pre-existing
19 failed files / 56 failed tests as main.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* chore(web-studio): drop the unused pnpm lockfile
Nothing in the repo installs web-studio with pnpm: `make build-studio`
runs `npm ci && npm run build`, and both setup-node steps in
`.github/workflows/_build.yml` cache on `web-studio/package-lock.json`.
No workflow reads `pnpm-lock.yaml`.
The file had also drifted out of sync with package.json — 24 specifiers
missing — so `pnpm install --frozen-lockfile` failed outright, which only
ever hurt someone reaching for pnpm locally.
Also drops the `pnpm.onlyBuiltDependencies` field: pnpm 11 no longer
reads it and warns when it is present.
package-lock.json stays as the single source of truth.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
- Add rehype-raw and rehype-sanitize so raw HTML in Markdown renders while stripping scripts and other dangerous tags
- Give table cells full borders, center content both axes, and pass through colSpan / rowSpan
- Add file-preview-html tests covering raw HTML rendering, table attribute passthrough, and script stripping
* fix(plugin): report server recall top score
Derive the status snapshot's top score from server-assembled context so /ov no longer reports 0.00 for scored recalls.
Co-Authored-By: Claude Sonnet 4.6 noreply@anthropic.com
* test(plugin): remove redundant recall state tests
* fix(plugin): remove misleading recall top score
---------
Co-authored-by: qin-ctx <qinhaojie.exe@bytedance.com>
Ship the generic openviking-memory SKILL.md from examples/skills as the
canonical source and vendor it into the codex, claude-code, and cursor
memory plugins through the existing shared-file sync script.
- examples/skills/openviking-memory/SKILL.md is the single source of truth
- sync.mjs copies skills verbatim (no GENERATED banner: it would sit ahead
of the YAML frontmatter and break every skill loader)
- sync.test.mjs asserts the vendored copies stay byte-identical
- the marketplace staging script now requires the two newly vendored copies
Split out of #3866: this carries only the generic skill packaging. The
Experience / agent-evolution half of that PR (ov-experience-memory skill,
server MCP experience tools, usage attribution) is deliberately excluded.
* feat: add OpenViking memory integration for TRAE CLI
Add TRAE CLI lifecycle hooks and MCP proxy support, wire the integration into the shared installer, and cover idempotent install and uninstall behavior.
Co-authored-by: TRAE CLI <noreply@bytedance.com>
* fix(trae-cli): cover archive installs and hook payload aliases
* fix: keep TRAE CLI installation explicit
Leave TRAE Desktop detection unchanged and avoid auto-selecting TRAE CLI. TRAE CLI remains available through an explicit harness selection or --harness trae-cli.
Co-authored-by: TRAE CLI <noreply@bytedance.com>
* fix(trae-cli): auto-select installed CLI commands
Detect traecli and traex only when they are available in PATH, then mark and select the TRAE CLI harness automatically.
---------
Co-authored-by: “bianhaonan” <“bianhaonan@bytedance.com”>
Co-authored-by: TRAE CLI <noreply@bytedance.com>
* feat(pdf): refactor MinerU parsing to the official file_parse API
* feat(pdf): remove mineru_api_key from configuration and examples
* feat(pdf): preflight MinerU /health during service initialization
Co-Authored-By: Claude <noreply@anthropic.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
* feat(plugins): add OpenViking memory for DSH
* feat(dsh-plugin): graft review items — source whitelist, dsh constructors, live recall gate
Applies the #task-65 review verdict's graft list from #3991 onto the
#3993 base:
- capture whitelist: drop every plugin-sourced user message (any plugin,
not just this one) so injected context never mirrors into memory as
human input; recall queries keep their existing scope
- pre-step: register with prepend so this listener sees the final
claimed batch, and short-circuit on signal.aborted around each await
- adopt dsh constructors behind exact-pinned peers (devDependencies
mirror the pins): tools flow through @deepseek-ai/dsh-tools defineTool
(declarative parameters, output schema/render, presentCall per tool),
plugin messages through @deepseek-ai/dsh-llm createUserMessage; a
registration-shape test makes a future rc pin bump fail CI instead of
a user install when the ToolDefinition contract moves
- live-recall.test.mjs: opt-in (OPENVIKING_E2E=1) real-backend gate —
store a sentinel via session commit, wait for extraction, assert
recall returns it; passed against a live OpenViking server in 124s
(note: commit with the default keep_recent_count=10 extracts nothing
from short sessions — the test pins keepRecentCount 0)
- README: why injection is pre-step user messages, not the system
prompt (complete:true personas silently drop prompt assembly), plus
peer-pin rationale and a Testing section
Tests: 15 pass + 1 env-gated (node --test), requires npm ci for the
pinned dsh devDependencies — CI step lands separately (workflow scope).
* ci(pr): install DSH plugin deps before running memory plugin tests
* fix(dsh-plugin): finalize neutral plugin integration
Remove product-specific identifiers from the DSH plugin surface and harden its lifecycle, HTTP contracts, archive tooling, and ordered offline delivery.
Co-authored-by: TRAE CLI <noreply@bytedance.com>
---------
Co-authored-by: Zayn Jarvis <zaynjarvis@gmail.com>
Co-authored-by: TRAE CLI <noreply@bytedance.com>
* feat(plugins): add Agent Plugins 1.0 portable package
Add agent-plugins/, an Agent Plugins 1.0 conformant package
(https://agent-plugins.org/specification) that any conforming client can
load: plugin.json manifest, an openviking-memory skill teaching the
hook-less recall + persist loop, and an mcp.json stdio entry running a
stdio -> streamable-HTTP proxy that resolves credentials from
OPENVIKING_* env -> ~/.openviking/ovcli.conf -> ~/.openviking/ov.conf,
same as the ov CLI.
servers/shared/* are generated copies of memory-plugin-shared/lib, wired
into sync.mjs / sync.test.mjs TARGETS so they cannot drift silently.
config.mjs / debug-log.mjs / mcp-proxy.mjs are adapted from
claude-code-memory-plugin with the hook-tuning knobs dropped.
plugin.test.mjs validates spec conformance (schema URLs and matching
spec versions, name rules, closed manifest root, semver, skill
frontmatter, referenced files staying inside the plugin root, node
--check on all .mjs) and runs in CI via pr.yml.
The skill treats tree/write/edit as optional, since they only exist on
servers that carry #3936.
Docs: docs/{en,zh}/agent-integrations/15-agent-plugins.md, registered in
the VitePress sidebar and the integration overview tables, plus a link
from the three root READMEs. The docs recommend the per-client plugin
whenever the harness has hooks, with the shared installer one-liner.
Based on #3994 by @ZaynJarvis.
Co-Authored-By: Zayn Jarvis <zaynjarvis@gmail.com>
* docs(agent-plugins): pluralize README title
---------
Co-authored-by: Zayn Jarvis <zaynjarvis@gmail.com>