chichuan
ea9b14239c
fix: scope pre-commit checks to staged changes
2026-09-07 18:18:01 +08:00
github-actions[bot]
36680f062a
chore: update beta formula for v1.0.62-beta.5 [skip ci]
2026-09-07 05:25:08 +00:00
赤川
7349dc4079
Merge pull request #1307 from DingTalk-Real-AI/codex/changelog-v1.0.62-beta.5
...
docs(release): seal v1.0.62-beta.5
v1.0.62-beta.5
2026-09-07 13:14:18 +08:00
chichuan
fcf8d35b8d
docs(release): seal v1.0.62-beta.5
2026-09-07 13:12:58 +08:00
dingtalk-dws-reviewer-router[bot]
81edc40c86
Merge pull request #1303
...
Merged by the dedicated Reviewer Router GitHub App for PR #1303 .
2026-09-07 04:21:16 +00:00
克谨
381f3fbf0c
Merge remote-tracking branch 'origin/main' into codex/fix-oa-empty-page-pagination
2026-09-07 11:54:04 +08:00
dingtalk-dws-reviewer-router[bot]
608464299f
Merge pull request #1293
...
Merged by the dedicated Reviewer Router GitHub App for PR #1293 .
2026-09-07 03:51:42 +00:00
克谨
bb0d3e1944
fix(oa): accept omitted hasMore on empty terminal pages
2026-09-07 11:40:48 +08:00
龙允
545dfc2406
Merge branch 'main' into codex/schema-compat-required-one-of
2026-09-07 11:28:08 +08:00
dingtalk-dws-reviewer-router[bot]
8e10cc6a88
Merge pull request #1212
...
Merged by the dedicated Reviewer Router GitHub App for PR #1212 .
2026-09-06 21:47:50 +00:00
nitonitori
eecb7a2b50
fix(doc): 含 mention 的 verify 步骤不再报 success
...
评审指出只给 verify 步骤加 scope="partial" 不足:仅按 steps[].status 推进、
尚不认识 scope 字段的既有消费者,仍会把无法核验 @人 目标的回读当作完整
成功。现把该步骤状态由 success 降为 partial,旧消费者的 status=="success"
判断因此不再命中。docEnvelope 的 ok/status/complete 是固定值,不由步骤推导,
所以操作本身仍报 success。
同时补上评审要求的输出断言:新增 runDocCoverageEnvelope 捕获命令实际发布的
JSON 信封,对 +create、+update append|overwrite、+checkpoint-update 四种真实
调用逐一断言操作仍 success,但 data.verified=false、verificationScope=partial、
verify 步骤非 success 且为 partial、warnings 非空。原先那条断言只判了不报错。
2026-09-07 05:28:37 +08:00
nitonitori
3d4aa5ba45
docs(skills): 还原被冻结的 doc-create-workflow.md
...
该文件是 intent_routes.json 里 sha256 固定的 protected reference,上一个
提交改了它导致 Policy 的 protected doc Reference check 失败。
改动本身也是多余的:被改的那句「verified=false 才进入恢复流程」位于
「JSONML 起稿 → 写入(--doc-format jsonml)→ 验收」之下,而 mention 改写
不作用于 JSONML,该路径不会出现 mention 作用域的 verified=false。同文件
markdown 路径的「内置回读验收」不以 verified 为判据,缺失补救的触发条件
是 commit_unknown / 超时 / 内容缺失,也不受影响。
markdown 侧的例外说明保留在未冻结的 doc-create.md 与两份 doc-update.md。
2026-09-07 04:51:32 +08:00
nitonitori
7decf15ba9
docs(skills): mention 的 verified=false 不再触发恢复流程
...
含 @人 的写入现在返回 verified=false,而 doc-create 的结果处理与
doc-create-workflow 的验收步骤都把 verified=false 当作进入恢复流程的
信号,会让 Agent 把一次成功的创建误判成需要重读重写。补上例外说明,
并在 doc-update 的 @人 条目里明确不要为此追加读写。
2026-09-07 04:39:03 +08:00
nitonitori
955e92530f
fix(doc): 含 mention 的写入不再宣称已验证
...
自动 CR 连续四轮判定不通过,明确指出顶层仍返回 verified=true 与成功步骤,
调用方可能把目标错误的写入当作已完整验证;并给出可接受的补救之一是
「把写入结果置为未验证」。
因此含 mention 的写入改为 data.verified=false,而操作本身保持 status=success、
ok=true:内容确实写入了,只是其中一项属性无法由回读证明。同时新增
unverifiableLocally=["mention_targets"],表明该缺口不是「还没查」而是「回读查不
出来」——重读文档不会得到新信息,避免调用方为不可能完成的校验白跑往返。
不含 mention 的写入输出完全不变(verified 仍为 true,作用域键与 warning 不出现)。
取舍说明:此前一版用 verificationScope=partial 保留 verified=true,试图既消除
过度声明又不触发重试;门禁不接受该折中,故按其列举的补救落地。
验证:Go 单测断言同步为 verified=false 并新增 unverifiableLocally 断言,变更行
覆盖率 100%,internal/shortcut/... 与 internal/helpers/... 全绿;线上实测含
mention 时 status=success 而 verified=false,不含 mention 时输出不变;
dws-agent-eval 13 条真实调接口用例 13 passed(断言已同步)。
2026-09-07 04:16:39 +08:00
nitonitori
7ef8f38768
fix(doc): mention 配对增加双射一致性校验
...
评审连续三轮卡在「目标互换仍返回 verified=true」。逐目标核验需要
openDingTalkId → staffId 的反查,而该反查在 CLI 面上不存在(openDingTalkId 仅作
输出字段;contact 查询入口是姓名/手机/部门/角色),dws api 又要求自有应用凭证且
把 raw OpenAPI 塞进文档校验路径违背现有架构——故无法在本 PR 内实现。
但按位置配对之外还有两条纯本地可判的约束此前没做,现补上:
- 同一个 openDingTalkId 必须解析到同一个 profile 目标
- 两个不同的 openDingTalkId 不得解析到同一个 profile 目标
这能捕捉服务端把身份搞混(同 id 前后不一致、不同 id 撞到同一人)的情形,把不可
判范围收窄到「两个不同 id 的目标互换」这一项——作者侧从不携带解析后的 staffId,
(A→X,B→Y) 与 (A→Y,B→X) 在本地信息量下不可区分,属信息不足而非实现薄弱。
验证:新增 4 行表驱动用例覆盖两条约束的正反面,另测 destination 提取的边界;
变更行覆盖率 100%;internal/shortcut/... 与 internal/helpers/... 全绿。
2026-09-07 04:07:41 +08:00
nitonitori
02c821578e
test(doc): 补齐 append 后缀比较三层的覆盖
...
CI 的 Enforce coverage gate 以 COVERAGE_TARGET=100 要求变更行全覆盖,本地复现
发现 markdownSemanticallyEndsWith 有两个新增分支未被触达:service 指纹后缀命中
的那条,以及 mention token 路径的入口守卫。
补一条用例分别喂三种输入形态:
- 仅空白折叠的布局差异(渲染 HTML 后缀不同、service 指纹相同)→ 仍应判为后缀
- 空回读 + 含 mention 的预期 → token 数不足,判否
- 超长回读 → 指纹不可用,判否
这三层各需要不同输入,否则其中一层会静默失去覆盖。
2026-09-07 03:45:37 +08:00
nitonitori
1ef072831d
Merge remote-tracking branch 'upstream/main' into feat/doc-markdown-mention
2026-09-07 03:22:50 +08:00
nitonitori
d4ce4cdfc1
fix(doc): +checkpoint-update 补齐 mention 作用域披露
...
真实场景验证(独立上下文 Agent 跑用户级请求)暴露上一版的接线不完整:带正文的
写后回读有三条路径,但作用域标注与 warning 只挂了两条。+checkpoint-update 只从
compactDocVerification 拿到嵌套的 verification.mentionTargetsVerified=false,
缺少同级 verificationScope / unverified,也没有 warning——同一限制在不同路径上
披露不一致,等于把最显眼的信号漏在了其中一条路径上。
补上该路径的 annotateMentionVerificationScope 与 withMentionTargetWarning。
同时修一处文档误导:doc-update.md 的"仅 markdown 正文生效:append / overwrite"
容易被读成 create 不生效(实测 create 初始正文同样会被改写,doc-create.md 才是
对的)。改为"本命令的 append / overwrite(doc create 初始正文同样生效)"。该误读
在真实场景验证中确实让 Agent 多绕了一步。
验证:internal/shortcut/doc 全包绿;线上实测 +checkpoint-update 含 mention 时
verificationScope=partial、unverified=[mention_targets]、verify 步骤 scope=partial、
nested mentionTargetsVerified=false、1 条 warning 均可读到,不含 mention 时全部不出现。
2026-09-07 03:22:30 +08:00
nitonitori
eaf295249c
fix(doc): mention warning 只透出两条事实
...
原文案夹带了"重新读取文档同样无法核验此项,无需为此追加验证往返"的推断与建议,
超出了结果应该陈述的范围。改为只讲两件事:
@人链接指向的具体人员需用户自行核对;
正文其余部分(含该链接的位置与显示文本)均已通过回读校验。
作用域字段不变(verificationScope=partial、unverified=[mention_targets]、
verify 步骤 scope=partial)。Go 单测与 eval 断言同步改为逐条校验这两句事实,
不再依赖已删除的措辞。
验证:internal/shortcut/... 与 internal/helpers/... 全绿;线上实测文案与字段
均如预期;eval 13 条真实调接口用例 13 passed。
2026-09-07 02:33:30 +08:00
nitonitori
dbc4f56042
fix(doc): 含 mention 的写入以"部分验证"声明作用域
...
上一版只在嵌套字段与 warning 里披露限制,顶层仍是裸的 verified=true、verify
步骤仍标 success,调用方可能把目标错误的写入当作完全验证并继续后续流程。
改为在与 verified 同级处自带限定:
data.verificationScope = "partial"
data.unverified = ["mention_targets"]
steps[verify].scope = "partial"
保留 verification.mentionTargetsVerified=false 与说明性 warning。
刻意不把 verified 改成 "partial" 字符串:类型由 bool 变 string 会让 JS 侧
truthy 判断误判为已验证,比现状更糟,也会打破既有消费方(含本仓 eval 断言)。
加字段是加法、不破坏既有读法。
warning 补上"重新读取文档同样无法核验此项,无需为此追加验证往返":该缺口不是
"还没验"而是"本地无从验",说清楚才不会让调用方为一个不可能完成的校验白跑往返。
不含 mention 的写入输出完全不变(作用域键、步骤 scope、warning 均不出现)。
验证:internal/shortcut/... 与 internal/helpers/... 全绿;线上实测含 mention 的
+update overwrite 三层信息均可读到(verificationScope=partial、
unverified=[mention_targets]、verify 步骤 scope=partial、mentionTargetsVerified=false、
1 条 warning),不含 mention 时全部不出现;eval 13 条真实调接口用例 13 passed
(已补齐对同级作用域标记与 warning 措辞的断言)。
2026-09-07 02:18:22 +08:00
nitonitori
6a034a3bcf
fix(doc): 含 mention 的写入不再隐含声明 @人 目标身份已验证
...
评审第二轮指出:按位置配对只检查"预期是 mention 协议、实际是 profile 链接",
并不核对两者是否同一用户,因此目标错了也报 verified=true。
取证后确认,问题范围比评审描述的更广,也因此改法不同:单个 mention 指向错误
的人、不同标签的两个 mention 目标互换,同样都判定通过。也就是说本地不可消歧
的集合不是"同标签多 mention"这个子集,而是全部 mention 写入——openDingTalkId
与改写后的 staffId 不同值且无本地映射。若只对同标签情形失败关闭,等于用"标签
是否重复"当"是否可消歧"的代理,拦不住真正的目标问题还会拒绝合法写入(同名同姓
在通讯录里常见);若一致地对全部 mention 失败关闭,则回退上一轮修的缺陷。
因此按"不过度声明"处理:比对逻辑不变(位置、显示文本、顺序与所有非 mention
链接照旧严格校验),但含 mention 的结果新增
verification.mentionTargetsVerified=false 与一条说明性 warning,verified 不再
被读成"@ 到的人也已核对"。不含 mention 的写入输出完全不变。
真正逐目标核验仍需服务端回吐改写映射,属跨仓库变更,另立任务。
同时把上一轮那条把互换固定为 want=true 的用例改写:保留比对层接受(目标本就
不参与比对),但注释与命名改为说明"目标不被比对",并新增 envelope 层用例断言
未校验标记与 warning 的存在、以及不含 mention 时两者都不出现。
验证:internal/shortcut/... 与 internal/helpers/... 全绿;线上实测含 mention
的 +update overwrite 返回 verified=true 且 mentionTargetsVerified=false 带 1 条
warning,不含 mention 时两者均不出现;eval 13 条真实调接口用例 13 passed(其中
shortcut overwrite 用例已补上对该标记与 warning 的断言)。
2026-09-07 01:24:46 +08:00
nitonitori
0a8f7c3ca5
fix(doc): mention 写后回读改为按位置配对,不再放宽其他个人资料链接
...
评审指出上一版把"链接形态"当成了"配对关系":只要预期正文任意位置含 mention
协议,指纹就会把两侧所有 dingtalk://…/page/profile 链接折叠成同一个令牌,
于是作者自己写的普通个人资料链接也失去校验——它若在回读侧指向了另一个人
(显示文本相同),仍会误报 verified=true。已本地复现确认。
改为按位置配对:指纹不再做任何归一、保留原始 destination,并额外输出 token
序列;比较时逐位判定,只有"预期侧该位置是 mention 私有协议、实际侧是 profile
链接"这一种差异被容忍,其余 token 必须严格相同。append 路径同规则做尾部比较。
据此删除 markdownMentionCanonicalFingerprint 与 canonicalizeMentionLinks
参数——那个抽象在生成指纹时就丢掉了配对所需的信息。
已知限制(本次接受,未处理):同显示文本的多个 mention 若目标互换,两侧 token
序列逐位完全一致,本地不可判别。openDingTalkId 与改写后的 staffId 不同值且无
本地映射,要判定必须由服务端回吐改写结果。已在代码注释与用例中标注,若将来该
行为变化,对应用例会失败并强制复核。
验证:新增 12 行表驱动用例,覆盖评审要求的"mention 与普通 profile 链接并存"
(并存正确→过、普通链接漂移→拒),以及补标题 / append 前置内容在含 mention
时的容忍不被本次改动破坏。改动前后跑同一张 13 场景基线矩阵,仅
"普通链接漂移"一格由 true 翻转为 false,其余全部不变。
internal/shortcut/... 与 internal/helpers/... 全绿;eval 13 条真实调接口用例
13 passed;线上补测"mention + 普通链接并存"返回 verified=true,私有协议未落库、
普通链接原样保留、mention 已改写。
2026-09-07 00:39:16 +08:00
dingtalk-dws-reviewer-router[bot]
6f71222b9b
Merge pull request #1287
...
Merged by the dedicated Reviewer Router GitHub App for PR #1287 .
2026-09-06 04:56:25 +00:00
赤川
2370a832f0
Merge branch 'main' into codex/fix-4629-safechat-read-backend-gate
2026-09-06 12:39:21 +08:00
dingtalk-dws-reviewer-router[bot]
d39d75909a
Merge pull request #1284
...
Merged by the dedicated Reviewer Router GitHub App for PR #1284 .
2026-09-05 02:52:08 +00:00
赤川
7b908f7166
Merge branch 'main' into codex/aitable-view-filter-or
2026-09-05 10:37:22 +08:00
赤川
3222e52a73
Merge pull request #1295 from DingTalk-Real-AI/codex/fix-router-blocked-automerge
...
fix(ci): 恢复 blocked PR 的 App 自动合并
2026-09-05 10:37:00 +08:00
chichuan
9879bf4cf6
fix(ci): 恢复 blocked PR 的 App 自动合并
2026-09-04 22:21:32 +08:00
xlb1130
67342f2ae0
Merge branch 'main' into codex/fix-4629-safechat-read-backend-gate
2026-09-04 18:41:33 +08:00
hyz
16d12efb82
Merge branch 'main' into codex/aitable-view-filter-or
2026-09-04 17:09:23 +08:00
赤川
51926f0bfe
Merge pull request #1264 from notable-open/feat/aitable-app-mode
...
feat(aitable): 支持AI表格应用模式相关的dws指令
2026-09-04 17:04:22 +08:00
赤川
4cdf26a314
Merge pull request #1169 from nitonitori/feat/block-delete-batch
...
feat(doc): 支持文档块批量删除,--block-id 支持逗号分隔
2026-09-04 17:03:48 +08:00
CHHH
cd7a3aca7c
Merge branch 'main' into feat/block-delete-batch
2026-09-04 15:27:25 +08:00
克谨
8f28a3dc89
Merge remote-tracking branch 'origin/main' into codex/aitable-view-filter-or
2026-09-04 14:59:03 +08:00
xlb1130
f7762946e1
Merge branch 'main' into codex/fix-4629-safechat-read-backend-gate
2026-09-04 14:41:45 +08:00
龙允
f7d2d8d8b6
fix(policy): accept required-parameter to one-of compatibility
...
Allow a newly introduced require_one_of group only when a historical unconditional required parameter without a default already guarantees a supplied member. Preserve rejection of unrelated incompatible changes.
Add regression coverage for compatible alternatives, conditional and defaulted inputs, independent groups, parameter removal, and type drift. Keep product declarations and runtime behavior unchanged.
2026-09-04 14:25:54 +08:00
notable-open
5129f2d2b3
Merge branch 'main' into feat/aitable-app-mode
2026-09-04 14:23:28 +08:00
赤川
343b3e649c
Merge pull request #1291 from DingTalk-Real-AI/qoder/ci-fail-fast-and-admitted-merge-retry
...
ci: fail-fast PR cancellation and admitted-merge discovery retry
2026-09-04 13:54:00 +08:00
chichuan
efb333078e
Merge remote-tracking branch 'origin/main' into qoder/ci-fail-fast-and-admitted-merge-retry
2026-09-04 12:45:05 +08:00
chichuan
233b170a9d
fix(release): keep npm retirement notices out of the pack integrity run
...
The npm registry started answering legacy audit calls with a deprecation
notice ("This endpoint is being retired. Use the bulk advisory endpoint
instead"). On hosted runners the notice rode along the pinned-npm pack
invocation on stderr and the call latency behind it stretched the pack to
312s, failing TestReleaseNpmPackingIgnoresLifecycleScripts — which
asserted on CombinedOutput even though the script's real contract (the
one release.yml consumes via command substitution) is integrity-only
stdout. Disable audit/fund banners for the deterministic pack and assert
stdout separately from stderr diagnostics.
2026-09-04 12:36:02 +08:00
chichuan
77bc5e145c
fix(ci): bind fail-fast cancellation to the repository explicitly
...
The tripwire jobs deliberately skip checkout to stay lightweight, but
without a git working directory gh cannot infer the base repo: the first
production firing (run 33835779761) logged "failed to determine base
repo" and the cancel request never reached the API, so doomed siblings
ran to completion. Pass -R "$GITHUB_REPOSITORY" and pin the bound
command in the tripwire contract test. Detection timing was confirmed
correct in the same run: the tripwire started 8 seconds after the
triggering failure.
2026-09-04 12:35:59 +08:00
xlb1130
3ea5cb3298
Merge branch 'main' into codex/fix-4629-safechat-read-backend-gate
2026-09-04 12:24:40 +08:00
克谨
e9d860816e
Merge remote-tracking branch 'origin/main' into codex/aitable-view-filter-or
2026-09-04 12:16:47 +08:00
github-actions[bot]
5243e5ca19
chore: update beta formula for v1.0.62-beta.4 [skip ci]
2026-09-04 04:12:16 +00:00
chichuan
d0d9617bbd
ci: cancel doomed pull-request jobs on first substantive failure
...
A failing pull-request admission run keeps every already-launched sibling
job running to completion: production data showed 14% of job-minutes went
to cancelled runs and failed runs burned 100+ doomed job-minutes after the
first red check, because GitHub has no cross-job fail-fast and matrices
deliberately keep fail-fast disabled so every broken shard reports.
Each substantive job now has a dedicated fail-fast-* tripwire that cancels
the whole run through gh run cancel the moment that job fails. One tripwire
per job is required because a job-level needs evaluates only after every
watched job completes. Tripwires depend on lint directly and fire only for
pull-request events after a successful lint classification: protected-main
pushes run to completion as the coverage-cache producer and keep the full
failure picture for triage. A cancelled admission run still fails the nine
required ruleset contexts, so the mechanism can never authorize a merge.
TestCIFailFastTripwiresWatchEverySubstantiveJob derives the watched set
from the live job graph: a new substantive job without a tripwire, or a
tripwire orphaned by a removed or exempted job, fails the contract tests.
2026-09-04 12:02:19 +08:00
chichuan
1b38caa7ff
fix(ci): retry admitted-merge PR discovery past association-index lag
...
Protected-main pushes fire within seconds of the merge, before GitHub's
commit-to-PR association index necessarily lists the fresh merge commit.
Both production attempts since the reuse mechanism landed fell back to the
complete main suite with "expected one associated merged PR, found 0" even
though the PR records already bound the exact merge identity.
Discovery now re-polls on a bounded budget (twelve attempts five seconds
apart by default, tunable through DWS_ADMITTED_MERGE_RETRY_*) and also
consults the most recently updated closed main PRs under the identical
exact filter, since the merge transaction records merge_commit_sha on the
PR before the push event fires. Only zero-match discovery retries;
ambiguous results still throw immediately and an exhausted budget keeps
the complete protected-main suite, so fail-closed semantics are unchanged.
2026-09-04 12:01:55 +08:00
赤川
3e90e6547e
Merge pull request #1290 from DingTalk-Real-AI/codex/changelog-v1.0.62-beta.4
...
docs(release): seal v1.0.62-beta.4
v1.0.62-beta.4
2026-09-04 11:57:35 +08:00
克谨
5c0e4892c9
Merge remote-tracking branch 'origin/main' into codex/aitable-view-filter-or
2026-09-04 11:52:34 +08:00
chichuan
3696457e0a
docs(release): seal v1.0.62-beta.4
2026-09-04 11:52:09 +08:00
赤川
f314f19c26
Merge pull request #1289 from DingTalk-Real-AI/codex/docs-1288-release-fragment
...
docs(release): record checksum validation fix
2026-09-04 11:31:32 +08:00