5174 Commits
Author SHA1 Message Date
github-actions[bot] 7de51a87a1 chore: update beta formula for v1.0.63-beta.3 [skip ci] 2026-09-23 10:09:22 +00:00
赤川 d181098455 Merge pull request #1447 from DingTalk-Real-AI/codex/changelog-v1.0.63-beta.3
chore(release): seal v1.0.63-beta.3 changelog
v1.0.63-beta.3
2026-09-23 17:54:45 +08:00
chichuan 59afd32657 chore(release): seal v1.0.63-beta.3 changelog 2026-09-23 17:51:14 +08:00
赤川 e7ff2f8ecc Merge pull request #1446 from typefield/fix/1441-darwin-amd64-sg-read-only
fix(release): pin Darwin deployment target and gate assets on dyld acceptance
2026-09-23 17:43:32 +08:00
玉澜 f37bb1cee6 fix(release): validate every universal slice in the Darwin SG_READ_ONLY gate
Review on #1446 flagged that the publication gate parsed only the first
__DATA_CONST flags word of an otool -l capture, so a universal library
with a healthy first slice and a broken later slice would still ship.
Replace the inline one-shot awk with scripts/release/extract-data-const-
flags.awk, a state machine that emits one flags word per __DATA_CONST
segment in every slice (segname is only honored directly after cmdsize,
so section entries can never contribute), and fail closed if any entry
lacks SG_READ_ONLY.

Add a regression test driven by real otool captures: broken/healthy
v1.0.62 thin binaries, the vendored universal runtime dylib, and a
universal sample whose last slice is broken — the exact case the old
parser wrongly passed. Also remove MACOSX_DEPLOYMENT_TARGET from the
--exec ambient pass-through so the container always receives the single
unconditional 11.0 pin from compiler_env.
2026-09-23 16:49:05 +08:00
玉澜 16f3bee4e8 fix(release): pin Darwin deployment target and gate assets on dyld acceptance
The v1.0.62 darwin/amd64 asset was rejected by dyld before main() with
'__DATA_CONST segment missing SG_READ_ONLY flag' (#1441). The osxcross
x86_64 wrapper in the pinned cross image defaults the deployment target
to macOS 10.13, where ld64-711 emits __DATA_CONST without SG_READ_ONLY;
the arm64 toolchain floor is 11.0 and is unaffected. CGO=0 builds used
Go's internal linker and were also unaffected.

Pin MACOSX_DEPLOYMENT_TARGET=11.0 for the CGO release builds, matching
the arm64 floor and the vendored SafeChat library, and add a release
gate that statically checks SG_READ_ONLY on the binary and its runtime
library and launches every Darwin asset the macOS runner can execute
(amd64 via Rosetta) before publication.

Verified against the pinned cross image: the real dws darwin/amd64
binary builds with __DATA_CONST flags 0x10 (was 0x0), CGO_ENABLED=1 and
the SafeChat backend linked.
2026-09-23 12:30:13 +08:00
github-actions[bot] d2b1ff3583 chore: update beta formula for v1.0.63-beta.2 [skip ci] 2026-09-22 16:08:51 +00:00
赤川 c220234c7b Merge pull request #1439 from DingTalk-Real-AI/codex/changelog-v1.0.63-beta.2
docs: seal changelog for v1.0.63-beta.2
v1.0.63-beta.2
2026-09-22 23:25:35 +08:00
chichuan 9f4be1f6ac docs: seal changelog for v1.0.63-beta.2 2026-09-22 23:22:55 +08:00
98ef6f9c65 fix(dingtalk-tag): 统一参数并完善草稿校验与本地员工发布 (#1434)
* fix(dingtalk-tag): rename type/visibility flags and drop allow-join-group

- create/list/save-draft: CLI flag --main-program-type -> --type; MCP field unchanged (digitalTagEmployeeProfile.type for create/save-draft, top-level type for list)
- set-visibility: CLI flag --staff-ids -> --user-ids; still sends staffIds to MCP set_visibility
- publish: remove --allow-join-group flag (no such field)
- sync contract test, defaults/boundaries tests, skill docs (multi+mono) and changelog

* docs: add current test evidence for PR #1434

* fix(dingtalk-tag): reject skill update --file combined with --enabled locally

Server update_skill forbids fileUrl together with enabled/attributes and returns a bare INVALID_PARAM. Add a local mutual-exclusion guard in capability skill update so the combination fails fast with a clear message before any upload/remote call; clarify help/usage and capability.md (multi+mono) that --file and --enabled are mutually exclusive. Add coverage test.

* fix(dingtalk-tag): initialize local publish prompt and validate draft fields

* docs: refresh digital employee draft and publish test evidence

* docs(dingtalk-tag): clarify run trace null output means no trace available

run trace 输出 null(无 data)不是错误,而是该来源暂无可用 trace(未就绪/来源不匹配/无对应执行)。服务端 success(null) 与 CLI 保留合法 null 均为既有契约,故仅在 help/Long 与 run.md(multi+mono) 补充说明,不改输出契约。

* fix(dingtalk-tag): preserve silent legacy flags and document visibility

* test(dingtalk-tag): cover publish failure with an existing prompt

* docs: refresh silent compatibility and coverage test evidence

* fix(dingtalk-tag): support optional prompt during employee creation

---------

Co-authored-by: siyideng <dsy274007@alibaba-inc.com>
Co-authored-by: dingpan <dingpan.dp@alibaba-inc.com>
2026-09-22 23:13:45 +08:00
github-actions[bot] 0ac76534ff chore: update beta formula for v1.0.63-beta.1 [skip ci] 2026-09-22 03:41:19 +00:00
赤川 765ca39275 docs: seal changelog for v1.0.63-beta.1 (#1433) v1.0.63-beta.1 2026-09-22 11:04:15 +08:00
42d8178a5a feat(dingtalk-tag): 数字员工管理、身份登录与本地 Agent 接入 (#1391)
* feat(dev): add DEAP agent commands

* feat(dev): add DEAP profile flags

* feat(deap-agent): 观测命令对齐 HSF 接口收敛

- 删 run-executions、resolve-run-id 两个命令(HSF 接口已移除对应方法)
- run-status 改双定位:--run-id 或 --source-id+--source-type 二选一,全场域通用;
  移除旧的 assistantId+taskId 单聊口径
- 新增 send-message:以数字员工身份发消息返回 runId,写操作需 --yes 确认
- source-type 加白名单 enum(im_message/trigger_rule/scenario_instance)
- 同步契约测试与叶子清单

* refactor(deap-agent): source-type 白名单收敛为 im_message + trigger_rule

chat-2 删除 scenario_instance 来源类型后同步;并注明 im_message 的 sourceId 是
钉钉开放态 openMessageId,单聊/群@/群感知三条链路含义一致。

* fix(deap-agent): 按规范解析内建 MCP 端点

* fix: align deap agent cli with mcp tools

* refactor(deap-agent): 删除 send-message;run-status/trace 只按来源定位

- 删除 send-message 命令(HSF 侧 sendMessage 已移除)
- run-status / trace 去掉 --run-id 与 --trace-id,统一 --source-id + --source-type
  且与 --assistant-id 一并必填:调用方拿不到 runId,留个填不了的 flag 只诱导瞎传
- 保留辰驷 c158ea17 对生命周期命令的 MCP 文案对齐

* refactor(deap): 提到顶级 dws deap 前缀,分管理态/观测态两子组

DEAP 是独立平台,与开放平台应用(agentId/clientId/机器人配置)无包含关系,
此前挂在 dws dev deap-agent 下会让两个产品的路由与文案互相干扰。

命令树:
- dws deap manage   create/detail/list/save-draft/publish/delete(含不可逆写)
- dws deap observe  run-status/trace(全部只读)

契约:ProductID dev→deap,canonicalPath 与 CLIPath 全量更新;MCP tool 名不变,
MCP 侧配置无需调整。

Skill 文档:新增 references/deap/(index + manage + observe),并在 misc 路由表、
说明与 frontmatter 注册。observe.md 写清 openTaskId→openMessageId 两跳取法——
dws chat message send 只返回 openTaskId,直接拿它查必然 NOT_FOUND,而报错
看不出是 ID 类型错了。

* refactor(deap): dev.go / devapp_test.go 回退至主干,不在其领域留痕

dev 是开放平台应用的命令树,属另一领域。DEAP 迁到顶级 dws deap 后,
dev 侧无需任何改动——之前加的挂载已删,剩下的注释与文案提示也一并回退,
两个文件现与 origin/main 逐字一致。

DEAP 不再挂 dev 的事实由 deap_agent_test.go 的 TestDeapIsNotMountedUnderDev
单独钉住(断言写在本领域测试文件里,不侵入 dev 的测试)。

* docs(deap): 去掉与 dev 的对比性提示

那些"两者是不同产品/别搞混/曾挂在 dev 下"的措辞源于早先把 DEAP 挂在 dev 下的
误解。dev 与 DEAP 本无关联,写对比反而凭空建立联想并暗示一段已不存在的历史。

清理:deap-index.md 的混淆警示、misc SKILL.md 的路由提示、deapHandler 与
deapProductID 的注释、TestDeapIsNotMountedUnderDev(该测试同时耦合 devHandler)。

保留 AvoidWhen 里的产品边界声明:create 在两侧同名,属真实可能的误选,
与"别搞混"的元叙述不同。

* feat(deap): select detail configuration type

* ci(actions): 简化构建并发布 Release

* feat: add Skill and MCP commands to deap agent

* fix(deap): compose Skill upload and creation

* fix(deap): route MCP query to published tool

* fix(deap): route skill query to registered tool

* feat(deap): support combined response modes

* feat(deap): use scoped credential for skill upload

* fix(deap): call published skill upload credential tool

* fix(deap): follow renamed upload credential tool

* docs(deap): explain temporary dws token workflow

* docs(deap): remove deprecated dws token workflow

* feat(dingtalk-tag): rename deap command and add auth token

* docs(dingtalk-tag): clarify dws auth credential response

* refactor(dingtalk-tag): group capabilities and unify agent IDs

* feat(dingtalk-tag): support main program type

* docs(dingtalk-tag): document local agent program type

* feat(skill): align dingtalk-tag guidance

* feat(dingtalk-tag): connect digital employees to local DSH

* fix(dingtalk-tag): constrain main program types

* feat(dingtalk-tag): filter employee list by program type

* fix(dingtalk-tag): resolve managed token identity

* fix(dingtalk-tag): bind managed identities to published profile

* fix(dingtalk-tag): resolve async reply receipts

* docs(dingtalk-tag): clarify default program type guidance

* feat(dingtalk-tag): add profile-only connect mode [skip ci]

* fix(dingtalk-tag): resolve operator in employee token scope

* feat(dingtalk-tag): add isolated local Agent adapters

* fix(dingtalk-tag): close registration races and verify worker lifecycle

* fix(dingtalk-tag): validate saved employee self identity

* feat(dingtalk-tag): unify adapter lifecycle and DSH release control

* fix(dingtalk-tag): fence lost hosts and recover DSH registration

* feat(dingtalk-tag): rename managed login command

* feat(dingtalk-tag): complete managed employee login

* fix(auth): complete external code login and address review findings

Based on build.17.1. Expose auth exchange with client-id selection, verified identity persistence, transactional direct credentials, scoped configuration and accurate provenance. Redact code arguments in performance reports. Include regression tests and bounded real-service verification notes.

* fix(auth): isolate exchange invocations and preserve credential pairing

* fix(auth): close early-exit and config-snapshot isolation gaps

* fix(dingtalk-tag): tolerate temporarily unavailable send receipts

* feat(dingtalk-tag): integrate server device binding lifecycle

* fix(dingtalk-tag): fence uncertain binding writes and preserve retry receipts

* test(dingtalk-tag): update binding command and interface contracts

* fix: refresh local agent binding token and classify rejections

* chore: repair digital employee release fragment metadata

* fix: align local agent MCP tool names

* fix(release): upload only distributable archives and checksums

* docs(release): require change notes and include installation guidance

* fix: align local agent MCP binding contract (#13)

Validated against the pre-production bind -> rebind -> unbind lifecycle on PR head 49e20e79cdbf9b07efbc581aefe90cb839957dff.

* fix(dingtalk-tag): mark digital employee event source

* feat(dingtalk-tag): remove connect profile-only mode

* feat(dingtalk-tag): 移除 connect bind 和 rebind 子命令

* fix(dingtalk-tag): flatten MCP config and require employee scope

* fix(connect): 修正未知命令纠错和发布详情错误提示

* docs(dingtalk-tag): align MCP draft auto-mount guidance

* docs(dingtalk-tag): correct MCP auto-mount release note

* feat(dingtalk-tag): add digital employee management and local agent integration

* fix(dingtalk-tag): align dry-run contracts and cross-platform CI

* fix(event): 修正数字员工传输就绪与系统帧处理

* docs: 补充数字员工真实收发与恢复验收证据

* test(dingtalk-tag): cover platform identity and failure boundaries

* test(dingtalk-tag): exercise worker startup and upload failure paths

* fix(dingtalk-tag): handle Windows shutdown and corrupt state paths

* test(dingtalk-tag): cover login delivery and unbind recovery boundaries

* docs: 明确原消息故障未解决并补充来源对照

* fix: adapt upstream named registration and test employee failure boundaries

* fix: complete employee lifecycle cancellation and failure coverage

* test: wait for consumer startup before cancellation

* docs: align shared skill descriptions with upstream routing

* fix: allow atomic employee state replacement during Windows reads

* fix: retry bounded Windows snapshot rename contention

* test: exercise employee daemon lifecycle on Windows

* feat(dingtalk-tag): align user-facing manage contract

* fix(dingtalk-tag): unify supervisor user id field

* fix: 数字员工事件消费沿用默认来源

* fix(dingtalk-tag): unify avatar URL handling

* fix(dingtalk-tag): map agent type to MCP contract

* fix(dingtalk-tag): validate response mode by agent type

* feat(dingtalk-tag): add manage set-visibility command and align merged tests

- Add `dws dingtalk-tag manage set-visibility` leaf binding the set_visibility
  MCP tool (agent-uuid/visibility required; staff-ids/dept-ids as full-replace
  string slices), with full contract (Identity/Interface/Safety/Selection).
- Align merge-carried PR-only tests with the feature branch's authoritative
  contract:
  - drop deapAgentProfileJSON assertions (profile-json flag removed by feature)
  - remove retired employee-no size-validation case
  - update published-detail missing-identity error assertion to the generalized
    message that no longer leaks field names
  - provide required --response-mode in RemovesRetiredFlags create case (open_code
    default now mandates it) and reflect it in expected MCP args

* fix: address PR #1391 CI lint and auto-CR P1/P2 findings

- CI Lint (make format-check): gofmt-realign the create-args map literal in
  deap_agent_test.go so the format gate passes and the full test matrix runs.
- [P1] external_exchange.go: reuse the ClientSecret of the finally selected
  clientID by scanning all candidates. The reuse loop was gated on
  clientID == configured.id, but configured is only the first valid candidate,
  so explicitly selecting a later app/env candidate via --client-id dropped its
  unmanaged secret and fell through to an empty-secret managed exchange,
  breaking that app's normal OAuth authorization-code login. Managed-ness is now
  decided per candidate. Adds env/app later-candidate regression tests.
- [P2] apiclient: reject CR/LF in the streaming UploadMultipart field keys,
  file field name and file name before creating the pipe/goroutine, matching the
  existing non-streaming newMultipartBody guard, so user-controlled names cannot
  inject extra MIME headers/fields. Adds streaming-entry injection tests.

* test(app): align deap-agent schema contract with simplified dingtalk-tag contract

The feature branch simplified the digital-employee create/save-draft/list
contract in source but internal/app/schema_deap_agent_contract_test.go still
asserted the pre-simplification shape, so the final-schema gate failed once CI
Lint stopped fail-fast-skipping the matrix. Verified the same failures exist on
the pristine feature branch (pre-existing test debt, not a merge artifact).

- create_digital_employee: 11 -> 7 params (drop dept-name/icon/profile-json/
  employee-no/position-name/supervisor-uid; add avatar-url/supervisor-user-id;
  main-program-type property digitalTagEmployeeProfile.mainProgramType -> type).
- update_digital_employee_draft: 15 -> 11 params (same removals/additions).
- list_digital_employees: main-program-type property mainProgramType -> type.
- MCP auto-mount help/schema: expected phrases 自动追加/selectedSkills ->
  自动挂载/回读确认 to match the current create_mcp guidance.
- Add set_visibility to the final-schema contract (new manage leaf: write/high/
  user_required; agent-uuid/visibility required, staff-ids/dept-ids arrays).

* fix(dingtalk-tag): make create example pass agent dry-run gate

The create_digital_employee example was rewritten to showcase --avatar-url but
dropped --response-mode and pointed avatar-url at a local ./avatar.png. Under
DWS_AGENT_EXAMPLES_DRY_RUN the example must survive the command's own
validation: open_code (default) now requires a --response-mode, and a local
avatar path must be a readable image file, which the dry-run harness does not
materialize. Restore --response-mode mention_only and use a public HTTPS avatar
URL so the example dry-runs through the standard request preview without a
local file read.

* test(helpers): reach 100% changed-code coverage for deap avatar/skill-upload; preserve credential error cause

The changed-code coverage gate (target 100%) failed at 97.74% because the
platform harness only runs TestCrossPlatformCoverage*/TestAllShortcuts tests,
and the digital-employee avatar-upload feature shipped without such tests.

- Rename the four TestDevDeapAgent* avatar/local-agent tests to the
  TestCrossPlatformCoverage* convention so the platform coverage harness runs
  them (avatar uncovered statements 59 -> 32).
- Add deap_agent_avatar_coverage_test.go covering the remaining branches:
  avatar URL validation (http-no-host/unsafe-path/bad-ext/unreadable/dir/
  oversize/valid), stage-error formatting + Unwrap, created-UUID envelope
  traversal, profile preparation, invalid main-program-type, save-draft
  response-mode/avatar validation, create/save avatar call branches (dry-run,
  transport error, parse error, upload error), and the OpenAPI avatar uploader
  delegate.
- Improve the skill-upload credential error: stop collapsing every cause into a
  bare "OpenAPI 认证失败". Preserve the underlying stage cause and server
  code/trace for the MCP credential call (no secret exists yet on failure),
  while still redacting the injected resolver error so credential material can
  never leak. Covered by a new temporaryCredential MCP-branch test.

Local platform coverage gate now reports 100.0000% (2971 changed statements).

* test(helpers): make avatar unsafe-path case cross-platform for Windows coverage

The avatar URL-input branch test used "/abs/path.png" to trigger SafeInputPath's
absolute-path rejection, but filepath.IsAbs("/abs/path.png") is false on Windows,
so it fell through to the unreadable-file branch and failed Coverage (Windows)
with '本地文件不可读' instead of '路径不安全'. Use a NUL control character
("invalid\x00.png"), which rejectControlChars rejects on every platform (same
convention as the existing upload-boundaries test), keeping the unsafe-path
branch covered cross-platform.

* fix(dingtalk-tag): gate employee enqueue on capacity before writing ledger

Previously enqueue wrote the audit entry and dedup task file before checking
the 128-conversation and 32-per-queue capacity limits. A transient capacity
rejection therefore left an 'accepted' task file behind, so Event Bus
redelivery of the same event was short-circuited as already handled and the
message was permanently swallowed (recovery only rewrites accepted->needs_review,
never reprocessing).

Move both capacity checks ahead of audit/writeEmployeeJSON. enqueue holds r.mu
and is the sole producer, so a queue with room can never fill before the send,
letting the record persist only once acceptance is guaranteed; the send is now
unconditional and non-blocking.

Add regression coverage asserting that queue_capacity and conversation_capacity
rejections leave no dedup record and that redelivering the same event after the
backpressure clears is accepted and persisted.

* docs(dingtalk-tag): describe set-visibility scope as ALL/PARTIAL

Align the set-visibility command help, flag usage, MCP description, example and
parameter docs with the server contract that now accepts ALL and PARTIAL
(SELECTED kept only as a legacy alias). PARTIAL is stated explicitly to mean
'visible to the specified members/departments', and the example uses the full
--visibility PARTIAL value instead of the truncated PART.

* feat(dingtalk-tag): unify capability lifecycle

* 补齐数字员工能力跨平台覆盖测试

* docs: add reproducible test evidence for PR #1391

* fix(dingtalk-tag): upload the validated skill file handle

* docs: refresh PR 1391 test evidence and CR resolutions

* ci: give Windows native coverage enough time to finish

* fix(dingtalk-tag): align profile contracts and require explicit type

* fix(test): satisfy required employee type fixture

---------

Co-authored-by: chensi.wx <chensi.wx@alibaba-inc.com>
Co-authored-by: siyideng <dsy274007@alibaba-inc.com>
Co-authored-by: chichuan <haofeng.hf@alibaba-inc.com>
Co-authored-by: 赤川 <30925823+haofeng0705@users.noreply.github.com>
Co-authored-by: 丞天 <yuanchenyu.ycy@alibaba-inc.com>
Co-authored-by: dingpan <dingpan.dp@alibaba-inc.com>
2026-09-22 10:46:27 +08:00
赤川 002121d7bd fix(test): accept CRLF in OA TableField docs (#1432) 2026-09-21 21:54:04 +08:00
dingtalk-dws-reviewer-router[bot] 7cc805fa9d Merge pull request #1430
Merged by the dedicated Reviewer Router GitHub App for PR #1430.
2026-09-21 13:33:38 +00:00
赤川 0562fb360e Merge branch 'main' into pre_login_legacy_auth-token 2026-09-21 20:54:47 +08:00
dingtalk-dws-reviewer-router[bot] ebd98c4f2a Merge pull request #1018
Merged by the dedicated Reviewer Router GitHub App for PR #1018.
2026-09-21 12:04:13 +00:00
john a98a6439c7 Merge branch 'main' into feat/wait-framework 2026-09-21 19:40:38 +08:00
muling.cs a5c7be3d8a Merge branch 'main' into pre_login_legacy_auth-token 2026-09-21 18:09:55 +08:00
muling.cs 73c063a53e fix(auth): defer legacy ciphertext-mismatch repair until fresh login
Allow OAuth, device, auth-code, PAT, and --token reauthorization to start
when the legacy auth-token ciphertext has a confirmed DEK mismatch or a
missing DEK. The old ciphertext is preserved until fresh credentials are
available, then only the slots targeted by that login's persistence plan
are replaced. Transient and unclassified Keychain failures still fail
closed.
2026-09-21 18:09:33 +08:00
dingtalk-dws-reviewer-router[bot] bdbaca603c Merge pull request #1419
Merged by the dedicated Reviewer Router GitHub App for PR #1419.
2026-09-21 07:36:36 +00:00
hlzjsong 36219d2a99 Merge branch 'main' into dek_missing_relogin_only 2026-09-21 14:56:45 +08:00
muling.cs 56a6fc02ae fix(auth): render DEK-missing retry guidance through i18n
auth login --intl pins the display locale to English for the whole login
flow, but the retry guidance added for the v1 multi-profile DEK migration
was hard-coded Chinese, breaking the default English output contract.

Resolve the copy through i18n.T and add the en/zh catalog entries. The
guidance tests now cover both locales, including an end-to-end --intl
assertion, and locale-relative assertions keep the suite stable under
CI locales.
2026-09-21 14:19:41 +08:00
dingtalk-dws-reviewer-router[bot] 09e285608f Merge pull request #1426
Merged by the dedicated Reviewer Router GitHub App for PR #1426.
2026-09-21 03:15:32 +00:00
昕卉 8c4d3658a7 fix(contact): declare --id required and return validation error for blank dingtalkId 2026-09-21 10:52:16 +08:00
昕卉 24cd00c8f8 docs(contact): clarify get-by-dingtalk-id only returns userId 2026-09-21 10:52:16 +08:00
昕卉 0cafe76ea2 feat(contact): add get-by-dingtalk-id command to retrieve userId by dingtalkId
- Add dws contact user get-by-dingtalk-id --id <dingtalkId>
- Alias search-dingtalk for LLM-friendly invocation
- Map to MCP tool get_user_id_by_dingtalk_id (HSF direct)
- Add unit tests for argument mapping and blank ID rejection
- Add changelog fragment
2026-09-21 10:52:16 +08:00
dingtalk-dws-reviewer-router[bot] e81001f665 Merge pull request #1361
Merged by the dedicated Reviewer Router GitHub App for PR #1361.
2026-09-21 02:51:32 +00:00
muling.cs cbed4cbadc test(auth): keep retry-guidance constructor covered on all platforms
The app-package test that calls NewLoginRetryGuidanceErrorForTest lands in
the c-a-l partition, which the CI coverage shards do not run, so the Linux
full-suite coverage gate reported the changed statement uncovered. Add an
in-package cross-platform test that exercises the constructor in the
auth-package shard and mark the single-statement helper noinline so the
compiler cannot fold it into the caller on any platform.
2026-09-21 10:02:38 +08:00
muling.cs ac83155894 test(auth): cover DEK-missing retry branch and nil unwrap on all platforms
The changed-code coverage gate failed on both macOS and Windows: the
new Unwrap nil-receiver guard was never exercised, and the v1-to-v2
migration retry branch in saveTokenDataLocked was only covered by the
darwin/linux file-DEK test, leaving Windows at 88.2%. Add a stubbed
keychain test that mirrors the file-DEK scenario without platform
backend dependencies and an explicit nil-receiver unwrap test.
2026-09-21 00:02:02 +08:00
muling.cs 143e373b59 Merge remote-tracking branch 'origin/dek_missing_relogin_only' into dek_missing_relogin_only 2026-09-20 21:39:48 +08:00
muling.cs aa4cecc106 test(auth,keychain): harden DEK-classification and retry-guidance coverage
Add unit coverage proving LoginRetryGuidance rejects unrelated errors and
finds the retry condition through nested wraps while preserving the
original cause; assert the retried login persists a readable token; and
pin that a genuinely missing file DEK stays classified as missing rather
than ciphertext mismatch on Linux.
2026-09-20 21:32:40 +08:00
muling.cs 2cbdc1f0ac Merge branch 'main' into dek_missing_relogin_only 2026-09-20 21:31:33 +08:00
muling.cs 465bf73696 feat(auth): guide explicit-profile relogin after v1-to-v2 migration with a lost DEK
When a fresh login for an explicit --profile target runs the v1 registry
migration, the migration itself must skip DEK-missing slots, so the
first write of the organization slot can still fail with a missing DEK
after the migration raised profiles.json to v2. That failure is
recoverable by repeating the same login command, so surface a
profile-stable retry guidance instead of the raw technical error, keep
the technical cause only in the wrapped error chain and diagnostic logs,
and classify old file-DEK ciphertext read failures on Linux as
ciphertext mismatch so the repair path matches darwin.
2026-09-20 21:31:26 +08:00
muling.cs 822f83773e fix(keychain): classify file-DEK decrypt failures as ciphertext mismatch on Linux
Linux platformGet and platformValidateAuthTokenEntries returned raw
decrypt errors for ciphertext written under a previous DEK, so
IsCiphertextKeyMismatch never matched and the login repair path could
not clear the stale slot after a DEK rotation. Reuse the shared
fileDEKCiphertextMismatchError helper on both darwin and linux so the
classification is identical across file-DEK backends.
2026-09-20 21:31:13 +08:00
赤川 6a553c531b Merge branch 'main' into codex/fix-oa-tablefield-format-1347 2026-09-20 20:51:51 +08:00
0cc3170b5f feat(oa): supoort goout and overtime suite (#1381)
* feat: add attendance approval MCP shortcuts

* feat(oa): add goout and overtime

* docs(skill): align attendance-suite docs after multi oa.md navigation split

- Retarget multi suite workflow references from ../oa.md to ../oa-create.md
  (forecast/select/confirm/create sections, interaction principles, submitUrl
  guidance): the navigation-variant oa.md no longer carries those sections.
  Restore the interaction-principles section in oa-create.md so the
  zero-parenthesis summary and open-info collection constraints survive on
  the multi variant.
- Extend the attendance-suite intro and the forecast-invalidation note in
  oa-create.md to all four suites (leave/supply/goout/overtime).
- Mark forecast-process as required when a template has a mandatory
  self-select approver node (leave/supply), matching goout/overtime.
- Drop the per-suite detail read-back verification rules (overtime, goout,
  form-components) in favor of the generic create-and-post-write-verification
  contract in oa-create.md.

* docs(skill): condense OA interaction-principles block in mono/multi skills

* feat(skills): promote selection-clarification rule to general principle #5 in 交互优化原则

- Add rule 5 选择澄清优先(交互形态硬约束) covering all discrete-option
  clarifications (template, type/shift, time range, per-day duration, reason)
- Overtime step 6 now references principle #5 instead of inline duplicate
- Sync 多日确认 wording to point to 上条 consistently
- mono/multi byte-identical; check-mono-multi-skill-content.sh exit=0

* fix(attendance): reject non-positive proposed overtime durations before server call

The calculate-approve-duration validation only checked that the proposed
total duration strings were parseable floats, so negative values, zero,
NaN, and Inf passed through; detail-list entries only checked that a
duration field existed, so null, objects, negatives, and non-numeric
strings were forwarded verbatim. The server trusts per-day proposals
without arbitration, so those inputs would become wrong overtime
durations in the approval assembly.

Require finite positive numbers for the total duration flags and every
detail-list entry, reject hour/day fields that do not match the
requested duration mode (and both together), and align the flag and
constraint declarations with the tightened runtime checks. Adds 16
rejection subtests covering zero/negative/NaN/Inf/null/object/non-numeric
and mode mismatches, all asserting zero downstream calls.

* fix(attendance): reject invalid detail-list workDate millisecond timestamps

The numeric workDate branch only checked wd <= 0, so fractional
timestamps (1.5), second-granularity values (10 digits), and oversized
finite values beyond int64 range passed validation and were forwarded
verbatim. The contract declares 13-digit millisecond timestamps and
string inputs normalize through UnixMilli(), so those malformed numbers
would be misinterpreted or fail only downstream.

Require numeric workDate entries to be finite integers within the
13-digit millisecond range, align the constraint declaration, and add
rejection subtests for fractional/second-granularity/tiny/oversized
values, all asserting zero downstream calls.

* docs(skill): require mapped duration extValue assembly in OA suite docs

- batch-overtime duration extendValue: forbid passing the
  calculate-approve-duration response through as-is; it must contain
  non-empty unit (mapped from response durationUnit), durationInHour,
  durationInDay and compressedValue, otherwise the server rejects with
  invalid-params error (verified via server-side trace + source)
- goout workflow step 7: replace residual "response as-is" wording
  with the mapping-table contract
- mono oa.md: fold four suite workflows into a pointer table

* docs(skill): drop evidence-annotation wording from OA suite docs

- strip "生产实证" / dated "实证" provenance annotations from goout and
  overtime suite assembly rules (oa-form-components, oa-goout,
  attendance); factual conclusions remain unchanged

* fix(attendance): publish custom constraint evidence in delivered flag help

The delivery schema contract test requires every custom constraint's
decision facts to survive in the delivered parameter descriptions, and
the shortcut count baselines to track the three new attendance tools.

Split the multi-flag custom constraints into semantic per-flag groups
(matching upstream shortcut convention), embed the constraint evidence
into each flag description, and bump the public/published/delivered
count constants (473/530/473 -> 476/533/476).

* test(attendance): cover approval shortcut validation and execution branches

The coverage gate reported 59.2% on changed code: the detail-list
rejection fixtures passed bare objects, so the JSON-array precheck
rejected them and the per-item workDate/duration validation branches
were never reached (the assertions only require an error, which the
precheck satisfied).

Wrap those fixtures as arrays so they exercise the per-item checks,
add rejection cases for the remaining validation branches (biz-type
and duration-mode ranges, malformed start/end, half-day dependency,
principal-user duplicates, modified-date format, detail-list shape and
workDate forms, companion approve-type/ranges, complex overtime
work-date), add valid-payload Validate cases (the execute helper never
calls Validate, so its success returns were dead in tests), and add
Execute-path cases for optional payload passthrough, malformed
start/end/work-date, non-object detail items, companion result shape
and transport failures.

Changed-code coverage for the new attendance shortcuts is now 100%.

* fix(attendance): align detail-list help with the two-stage overtime workflow

The flag help claimed --detail-list was mandatory for cross-day
windows, but the overtime workflow's first stage must omit it so the
server returns the per-day skeleton used to disambiguate the window;
only the second stage (after the user confirms per-day durations)
carries it. Mirror the corrected wording in the attendance skill help
block.

---------

Co-authored-by: PPSTAR <pengruotong.prt@alibaba-inc.com>
Co-authored-by: gongyuan.cl <gongyuan.cl@alibaba-inc.com>
2026-09-20 20:29:24 +08:00
dingtalk-dws-reviewer-router[bot] 15afd99eab Merge pull request #1423
Merged by the dedicated Reviewer Router GitHub App for PR #1423.
2026-09-20 12:04:26 +00:00
johnandClaude Opus 4.7 1dc6343d11 test(corecmd): ensure proper newline in wait_phase_test.go
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
2026-09-20 19:49:55 +08:00
john c717376610 chore: restore test file newline 2026-09-20 19:41:13 +08:00
john a023522299 test(corecmd): cover implicit wait timeout fallback 2026-09-20 19:38:25 +08:00
hlzjsong 5821b61d87 Merge branch 'main' into dek_missing_relogin_only 2026-09-20 19:16:41 +08:00
muling.cs f1d8ac13f2 test(auth): cover v1 migration hard-fail on non-DEK org slot errors
The platform coverage gate enforces 100% changed-code coverage for
TestCrossPlatformCoverage* tests on every runner. The DEK-missing skip
introduced in ensureProfilesMigrationLocked left the remaining hard-fail
branch (org slot read error that is neither NotFound nor DEK-missing)
uncovered, failing the macOS and Windows coverage gates.
2026-09-20 19:08:32 +08:00
john f91955759b fix(corecmd): validate wait timeout before invocation 2026-09-20 18:52:52 +08:00
南润 0817e6fee0 test(aisearch): cover evidence enrichment branches 2026-09-20 18:20:43 +08:00
南润 94cdc58737 fix(aisearch): restore IM route policy marker 2026-09-20 17:43:22 +08:00
南润 9e32f5be02 fix(aisearch): keep skill within context budget 2026-09-20 17:35:16 +08:00
南润 95c410a0b3 feat(aisearch): enrich search evidence and resolved details 2026-09-20 17:12:44 +08:00
dingtalk-dws-reviewer-router[bot] fa5b06aea7 Merge pull request #1410
Merged by the dedicated Reviewer Router GitHub App for PR #1410.
2026-09-20 08:11:47 +00:00
muling.cs 746c8b4ab4 fix(auth): let v1 migration skip missing-DEK org slots
A valid v1 multi-profile registry with a lost shared DEK still stranded
fresh login: after the target-only repair, saveTokenDataLocked runs the
v1 registry migration, which hard-failed when reading a non-target
organization slot (load from keychain: dek missing).

Treat IsDEKMissing like a permanently unreadable slot during migration:
skip the organization (and the legacy global mirror consult) without
blocking reauthorization. The unreadable ciphertext stays intact and is
replaced only by that organization's next fresh login.

Adds a darwin regression test reproducing the v1 dual-profile DEK-loss
scenario: fresh login for one profile persists, non-target org and
identity ciphertext remain byte-identical.
2026-09-20 16:09:26 +08:00