Commit Graph

19718 Commits

Author SHA1 Message Date
Vincent Koc be0ed2fcd3 fix(browser): keep upload cleanup out of startup
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-08-19 10:04:49 -07:00
Eden 14b59a06f5 fix(line): deliver a location LINE cannot render instead of dropping it (#126298)
* fix(line): deliver a location LINE cannot render instead of dropping it

A location whose title or address is blank makes LINE reject the whole
request, so every delivery path filtered it out before sending. The reply
then arrived without the pin, and nothing told the user or the operator that
a part of the message had been removed: the coordinates the sender supplied
were discarded silently.

The location builder now answers with the values the sender wrote — the
non-blank label plus the coordinates — as a text message, so an unrenderable
pin degrades into something the chat can show instead of disappearing. Both
delivery paths inherit that from the single builder, and the three call sites
that used to skip a null result no longer have a branch to take.

Live validation against the Messaging API confirms the shape: the authored
location is rejected with "May not be empty" on messages[0].address, the same
rejection kills an entire batch that also carries valid text, and both
degraded forms validate cleanly.

* fix(line): bound the location fallback to LINE's text limit

Nothing caps the location labels at the schema, so a long title with a blank
address produced one raw text message past LINE's 5,000-character limit — the
provider rejected it and the location was lost exactly as silently as before.

The pin path already caps each label at 100 characters. Name that limit and
apply it in the fallback too, so both forms carry the same bound instead of
one of them re-deriving the provider's rules.

* test(line): merge the duplicate send.js imports
2026-08-20 00:29:51 +08:00
Peter Steinberger ae55a4090c refactor(canvas): make the panel a widget presenter (#126030)
* refactor(canvas): retire legacy host and commands

* refactor(apple): narrow shared Canvas contracts

* refactor(macos): keep Canvas as widget presenter

* refactor(ios): remove Canvas client

* refactor(android): remove Canvas client

* refactor(linux): remove Canvas client

* fix(ci): isolate native locale artifacts

* fix(linux): regenerate companion lockfile

* fix(canvas): refresh native tool display metadata

* test(canvas): align coverage with presenter surface

* test(canvas): remove obsolete asset root seam

* test(canvas): stabilize retirement CI coverage

* refactor(swift): remove orphaned resource wrapper

* test(ios): remove retired canvas layout assertion

* fix(macos): reserve retired canvas command namespace

* refactor(macos): isolate canvas command policy

* fix(canvas): select only eligible macOS panels

* fix(canvas): keep panel selection plugin-owned
2026-08-19 08:21:07 -07:00
Onur Solmaz c2de3206d4 feat(llama-cpp): support external llama-server
* feat(llama-cpp): add external server provider

* feat(llama-cpp): document external server setup

* refactor(llama-cpp): harden external provider boundaries

* fix(llama-cpp): support external structured output

* fix(llama-cpp): isolate replacement endpoint credentials

* test(llama-cpp): register external live shard

* fix(llama-cpp): preserve explicit endpoint authorization

* fix(llama-cpp): clear disabled inline credentials

* fix(llama-cpp): preserve external local service configs

* test(llama-cpp): cover retained external configs

* test(llama-cpp): cover authorization precedence
2026-08-19 17:32:00 +03:00
Peter Steinberger 0f1670d895 test: remove moving-tip redundancies (#126312) 2026-08-19 05:48:14 -07:00
Pavan Kumar Gondhi e2dc4067c7 fix(mattermost): prevent messages from sharing another sender's turn (#124531)
* fix(mattermost): isolate inbound debounce by sender

* fix(mattermost): reject authorless inbound posts

* fix(mattermost): keep system posts out of debounce batches

* test(mattermost): align ingress mock sender type

* fix(mattermost): keep invalid ingress from reconnecting
2026-08-19 18:14:58 +05:30
Peter Steinberger 97557ec3f5 fix(widgets): route show_widget through Discord Activities (#126294)
* refactor(widgets): unify Discord presentation

* fix(discord): keep incomplete Activity routes private

* fix(discord): require usable Activity accounts

* docs(discord): clarify hidden Activity routes
2026-08-19 05:41:37 -07:00
Peter Steinberger aa6949839d test: remove final delta scaffolding (#126310) 2026-08-19 05:16:43 -07:00
Peter Steinberger e7d7075865 test: stabilize extension lifecycle isolation (#126309)
* test(msteams): synchronize SDK stream lifecycle

* test(plugins): preserve error runtime exports in mocks
2026-08-19 04:56:42 -07:00
Peter Steinberger 1fa82e9795 fix: browser screenshots fail on routed Control UI pages (#126290)
* fix(browser): validate proxied file ownership

* fix(ui): separate route and resource base paths

* test(ui): align resource base fixtures

* test(ui): align route-base fixtures with focus routes

* perf(ui): keep profile avatar URLs out of startup
2026-08-19 04:36:07 -07:00
Michael Appel 55f6700fe1 fix(discord): preserve realtime speaker context (#123243) 2026-08-19 04:25:24 -07:00
Peter Steinberger 4af09d4961 feat(ui): unify focused presentation routes (#126143)
* feat(ui): unify focused presentation routes

/focus/<target> replaces unshipped standalone query links across dashboard, terminal, desktop, and native apps.

Gateway-served index assets are anchored so nested documents resolve their bundles from the Control UI base path.

* test(gateway): narrow emitted asset URLs

Fixes check:test-types TS18048/TS2322 by dropping unmatched optional captures before comparing emitted asset URLs.

* test(docs): follow centralized cloud secret guidance

Fixes the stale current-main docs test after #126132 centralized GCP and Hetzner setup in docker-vm-runtime.

* test(ui): retry missing locator reads

The 500ms locator text read can time out while the menu label is still rendering, causing expect.poll to reject instead of using its owning 10s retry window. Treat only Playwright TimeoutError as a missing value so the outer poll retries while page-closure and arbitrary failures still surface.

* test(android): capture TLS probe coroutine

The TLS probe test inferred its coroutine from mutable scope children, racing unrelated child startup and teardown in CI. Capture the exact Job from inside the probe coroutine and join that owner before asserting the stale-attempt guard.

* fix(gateway): preserve plugin focus routes

Keep approval handling ahead of plugin dispatch, but treat focus documents as an unclaimed Control UI fallback after plugin authentication and routing. Exact and prefix plugin routes therefore retain ownership, while unclaimed reads serve the focus document and other methods return 404.

* fix(ui): migrate released terminal links

Preserve stable v2026.7.1 terminal query compatibility by rewriting the root/base ?view=terminal URL once to the canonical /focus/terminal path with history.replace. Keep URL parsing path-only, and leave the removed desktop and dashboard query forms as a hard cut.

* test(codex): assign run-attempt tools shard

Cached filtered configs caused duplicate ownership, and the test lacked a canonical full-suite owner.

* test(ui): keep cloud recovery proof state-owned

The recovery test should assert owner state and reload identity, while dedicated tests own transient alert visibility.

* test(qa): wait for outbound bus state

* fix(qa): reserve gateway ports through staging

* refactor(qa): keep socket creation in gateway owner
2026-08-19 03:41:29 -07:00
Pavan Kumar Gondhi 2020fc2274 fix(nextcloud-talk): prevent shared proxy webhook lockouts (#126251)
* fix(nextcloud-talk): isolate proxy webhook rate limits

* fix(nextcloud-talk): preserve proxy fallback buckets
2026-08-19 15:59:21 +05:30
Peter Steinberger 9f8d53d6fb fix(codex): reap app-server descendant processes (#126285)
* fix(codex): reap app-server descendant processes

Contain the exact live Codex app-server ancestry before transport close so independently grouped MCP descendants cannot survive client retirement or overlap a replacement.\n\nCloses #119760.

* fix(codex): retain proven app-server descendants

* fix(codex): converge app-server quiescence

* fix(codex): bound app-server stop retries

* fix(codex): hold app-server root through eof

* fix(codex): bound app-server quiescence

* fix(codex): release stopped app-server processes

* fix(codex): bound app-server containment work

* fix(codex): bound process inspection asynchronously
2026-08-19 03:08:18 -07:00
Peter Steinberger 67750753a2 fix: capture GitHub identity from authenticated sign-in (#126114)
* fix: capture GitHub identity from authenticated sign-in

Automatically persist verified GitHub identities from Cloudflare Access and Tailscale Serve while keeping public Git co-author credit as a separate opt-in.

* test: stabilize cleanup and activity capture

* fix(security): bind GitHub profiles by account id

* test: scope activity capture to route

* fix(security): gate profile requests on identity sync

* fix(security): close pending profile authorization gaps

* test(ui): stabilize terminal continuation menu

* test: stabilize startup recovery timing

* test: keep one Codex attempt tools owner

* fix(plugins): allow profile-independent gateway reads
2026-08-19 01:35:52 -07:00
Peter Steinberger ee33840164 test(google-meet): route hooks through test API (#126249) 2026-08-19 01:33:09 -07:00
Peter Steinberger fef5fc55f4 fix(codex): prevent node process control from targeting gateway sessions (#126253) 2026-08-19 01:31:52 -07:00
Peter Steinberger 30337c8962 fix(qa-lab): include plural execution channels (#126140)
* fix(qa-lab): include plural execution channels

* chore(qa-lab): register browser error adapter

* fix(qa-lab): keep browser errors within boundaries

* fix(qa-lab): redact browser error credentials

* fix(sessions): drain sqlite writers during test cleanup

* fix(sessions): scope sqlite test handle cleanup

* test(codex): dedupe run attempt tools shard

* test(codex): converge run attempt tools shard
2026-08-19 01:17:22 -07:00
Peter Steinberger 88edcd1654 fix(qa): mark partial suite artifacts as running (#125924)
* fix(qa): mark partial suite artifacts as running

Isolated QA suite progress artifacts now identify themselves as running in JSON and Markdown, so completed-prefix results cannot be mistaken for terminal teardown. Final artifacts keep their existing completed shape, with process regression coverage for clean exit and closed Gateway listeners.

* test(qa): decouple suite runtime from teardown deadline

Allow the real QA scenario to finish under a contended extension shard while keeping the post-summary process exit requirement fixed at 45 seconds.

* test(qa): keep lifecycle proof observable

Emit a bounded progress heartbeat while the real QA child is still producing its terminal summary so the extension shard watchdog does not mistake a long, active process proof for a stalled Vitest run.

* test(qa): isolate lifecycle process environment

Run the real QA child outside Vitest and shared compile-cache markers, and fail fast with bounded process output when it exits before publishing a terminal summary.

* test(qa): run lifecycle proof on repo gateway

Build and launch the real repository Gateway when dist is absent, avoid package-candidate auth bootstrap, and keep the teardown regression bounded and observable in unbuilt extension-test jobs.

* test(qa): terminate Windows lifecycle process trees

* fix(qa): reject running confidence summaries
2026-08-19 01:12:22 -07:00
Peter Steinberger 3378e07d50 refactor(plugin-sdk): promote shared runtime primitives (#126193)
* refactor(plugin-sdk): promote shared runtime primitives

* test(codex): keep one attempt tools owner
2026-08-19 01:10:18 -07:00
Peter Steinberger 629f37e841 fix(codex): preserve transcript mirror identity (#126245)
Keep the writer-owned idempotency key stable across transcript redaction so final Codex snapshots replay against the admitted SQLite row instead of dropping mirrored history.\n\nCloses #126244
2026-08-19 01:07:27 -07:00
Peter Steinberger 554fc80e2f fix: Full access sessions no longer request exec approval (#126210)
* fix: stop Full access sessions from requesting exec approval

* fix: propagate Full access policy to compaction

* fix: source compaction permissions from session state
2026-08-19 01:04:36 -07:00
Peter Steinberger a4b265aa9b test(google-meet): remove testing re-export (#126223) 2026-08-19 00:26:09 -07:00
Peter Steinberger 554dfbe0a2 feat(discord): auto-join occupied voice rooms (#125974)
* feat(discord): auto-join occupied voice rooms

Add opt-in voice.autoJoin[].whenOccupied residency so Discord voice bots join for the first human and leave when the room becomes empty while preserving existing always-on, manual, transcript, and follow-user behavior.\n\nCloses #125973

* test(discord): isolate process runtime mocks

Use stable hoisted runtime-env mocks so isolate=false Discord test ordering cannot turn sleepWithAbort back into an unmocked function.

* fix(discord): defer unknown voice occupancy

Treat memberless voice states as unresolved instead of human so bot-only rooms cannot trigger occupancy-managed auto-join. Add cache-to-listener and manager regressions.\n\nCloses #125973

* test: isolate shared module mocks

Replace ineffective non-isolated module spies with stable hoisted mocks and a child-process SQLite connection-reuse probe so gateway and Discord shards are order-independent.

* test(gateway): inline connection reuse probe

Keep the child-process SQLite ownership probe in its owning Vitest file so Knip sees the full test surface without weakening process isolation or the original order regression.
2026-08-19 00:08:54 -07:00
Peter Steinberger 49d8cfd393 fix(security): prevent blocked SearXNG refs from using ambient URLs (#126214)
* fix(security): honor blocked SearXNG secret refs

* docs(searxng): clarify blocked SecretRef policy

* test(codex): route attempt tools coverage
2026-08-19 00:02:58 -07:00
Peter Steinberger f92e9367e8 fix(build): rebuild incomplete managed-update cache hits (#125954)
* fix(build): invalidate incomplete cache hits

* test(qa): align empty completion lifecycle
2026-08-18 23:25:04 -07:00
Peter Steinberger 3205e9282d fix(codex): keep progress card directly visible (#126189) 2026-08-18 23:20:27 -07:00
Peter Steinberger 2e6457b8e6 fix(codex): restore GPT-5.6 reasoning effort options (#126182)
* fix(codex): preserve model effort capabilities

Keep public model identities separate from app-server execution routing, and retain provider-owned complete effort metadata when account discovery is partial.

Fixes #126005

* refactor(codex): avoid redundant thread rotation

* fix(codex): preserve model fallbacks without leaking wire ids
2026-08-18 22:56:20 -07:00
Peter Steinberger 0d14434d0e feat(secrets): add explicit protected and agent-readable access (#126088)
* feat(secrets): add explicit agent access modes

Distinguish protected write-only secrets from agent-readable Gateway environment values, expose policy-bound Gateway exec aliases to Codex, and activate Node environment proxy support for destination-bound egress.\n\nCloses #125975

* fix(gateway): bind lifecycle dispatch to owning instance

* test(ui): preserve mock gateway recovery state

* fix(codex): avoid unavailable gateway process guidance

* fix(harness): keep run correlation host-owned

* fix(gateway): bind restart delivery to instance

* test(codex): construct tools through test host capability
2026-08-18 22:51:15 -07:00
Peter Steinberger 3550b174e9 fix(crabbox): derive machine classes from catalog (#126184) 2026-08-18 22:35:13 -07:00
Peter Steinberger a6b77ffc07 fix(msteams): preserve replies after durable ingress replay (#126169)
* fix(msteams): preserve replies across ingress replay

Recovered Teams channel and group-chat responses now preserve reply and quote context across durable ingress replay. Discovery metadata also advertises the existing group and reaction capabilities.

* chore(msteams): document replay assertion safety

* test(msteams): normalize replay delivery errors
2026-08-18 22:22:13 -07:00
Peter Steinberger e38a06439e refactor: trim locale and QA fixture debt (#126139)
* refactor: trim locale and QA fixture debt

* fix(qa): preserve shared flow portability

* chore(qa): document shared flow branch

* fix(docs): align plugin SDK subpath catalog

* fix(ci): align shared docs and flow contracts
2026-08-18 22:17:19 -07:00
Peter Steinberger 2456c77459 improve(gateway): avoid repeated logging and delivery scans (#126147)
* perf(gateway): remove repeated logging and delivery scans

Exact session-delivery retries no longer scan the full queue. Logging and diagnostics reuse lifecycle-owned settings and listener interest so uninterested projections are skipped, while outbound WebSocket summaries are built only after recipient admission.

* fix(infra): break diagnostic listener import cycle

Keep event-type validation at the diagnostic dispatcher while the process-wide listener presence counter remains a leaf module.

* test(cli): use logging override owner

Exercise late one-shot JSON diagnostics through the canonical logger override setter so lifecycle-cached console settings are invalidated as they are in production.

* test(auth): use logging override owner

Configure the locked-update warning test through the canonical logger override setter so lifecycle-cached console settings are invalidated before assertion.

* test(gateway): normalize redacted media fixture

Compare durable inbound media facts against the public redaction contract so random identifiers that resemble sensitive text do not make the Gateway suite flaky.
2026-08-18 22:13:22 -07:00
Peter Steinberger baefd067bb fix(deps): keep package runtime dependencies single-owned (#126119)
* fix(deps): consolidate shared runtime helpers

* test(concurrency): support current test lib target

* fix(time): preserve year-scale plugin durations

* fix(agents): preserve empty subagent completions
2026-08-18 22:12:45 -07:00
Peter Steinberger ffdd0641c8 fix(workboard): retry managed worktree cleanup after hook failures (#126162)
* fix(workboard): retry managed worktree cleanup

* fix(workboard): keep workspace mutation type local
2026-08-18 22:05:16 -07:00
Peter Steinberger dcdfd737e5 fix(workboard): recover interrupted worker launches (#126170)
* fix(workboard): recover interrupted worker launches

Persist prepared, accepted, and failed launch phases so Gateway restart reconciliation cannot leave cards permanently running between launch preparation and worker acceptance.

* fix(workboard): require durable terminal evidence

Do not synthesize terminal-session acceptance timing during restart reconciliation; stale same-key terminal rows without updatedAt now fail the prepared launch instead of being adopted.
2026-08-18 22:01:14 -07:00
Peter Steinberger 85cec65a19 fix(signal): preserve partial final delivery after later send failures (#126160)
* fix(signal): preserve partial final delivery

* test(signal): keep ingress boundary on sdk seams

* test(delivery): cover accepted partial target adoption
2026-08-18 21:55:09 -07:00
Peter Steinberger dc37ed8f63 fix(agents): record empty subagent completion delivery (#126179)
* fix(agents): preserve delivery after incomplete completion

* test(qa): distinguish failed delivered completions
2026-08-18 21:46:38 -07:00
Peter Steinberger 5564671c4f fix(gateway): bound audit and Codex backlogs (#126154)
* fix(gateway): bound audit and Codex backlogs

Live Gateway SQLite lock failures and process heap pressure exposed two
independent queue owners. Route best-effort audit persistence through the
canonical shared-state connection with bounded contention retries, and remove
the per-notification Codex yield so the keyed turn queue can drain directly.

Follow-up to #126033 and #126073.

* fix(gateway): annotate raw SQLite cold-open probe

* test(codex): register notification burst shard
2026-08-18 21:44:09 -07:00
Peter Steinberger 4ffa2a4418 fix(gateway): avoid readiness flaps during Reef reconnects (#126151)
* fix(gateway): avoid readiness flaps during Reef reconnects

* docs: preserve plugin SDK private-local contract wording
2026-08-18 21:29:43 -07:00
Peter Steinberger 601f65b2fd fix(clickclack): advertise media delivery capability (#126168) 2026-08-18 21:11:59 -07:00
Peter Steinberger 6c26bc7e2b fix(workboard): preserve concurrent edits during rollback (#126161) 2026-08-18 21:08:49 -07:00
ClawSweeper 7e69b1d5ab fix(ui): make Guardian review activity subtle (#125395)
* fix(ui): make guardian reviews subtle

* fix(ui): correlate Guardian warning cleanup

* fix(ui): retain ambiguous Guardian warnings

* fix(codex): preserve Guardian review state

Keep command-owned review state durable across reconnect and persisted history, with conservative bounded outcomes and producer-owned routine warning correlation. Verify native user-home app-server auth instead of injecting stored profiles.

* refactor(ui): split workspace conflict rendering

---------

Co-authored-by: RoboClaw <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-18 20:28:23 -07:00
Peter Steinberger feda957fc5 fix(gateway): bind channel completion dispatch (#126113)
* fix(gateway): bind channel completion dispatch

* fix(plugin-sdk): scope harness completion dispatch

* test(agents): cover scoped completion dispatch
2026-08-18 19:48:24 -07:00
Peter Steinberger 64776a0489 fix(sessions): preserve committed results across reconnects (#125904)
* fix(sessions): preserve committed operation results

Report post-commit create failures through the existing runError response and retain confirmed same-client Control UI mutations across reconnects while fencing replacement clients.

* test(ui): await new-session ownership state

* test(ui): clarify draft teardown durability

* fix(ui): preserve reconnect refresh failures

* test(ui): poll absent text targets safely

* test(sms): await ingress spool ownership

* test(ui): await cloud startup failure state

* test(ui): await canonical place selection

* test(ui): scope activity feed to route owner

* test(ui): stabilize route-owned activity states
2026-08-18 19:13:58 -07:00
Peter Steinberger c97b8ffdfc refactor: consolidate meeting and media provider families (#126053)
* refactor(plugins): consolidate provider family helpers

* fix(plugin-sdk): keep meeting script helpers private

* fix(plugins): sync meeting boundary paths
2026-08-18 19:11:13 -07:00
Peter Steinberger 886cf1a0bf fix(cua-computer): resolve the ESM-only driver SDK during artifact verification (#126120)
@trycua/cua-driver ships an exports map with only the import condition, so
require-condition resolution throws PATH_NOT_EXPORTED even when the package
is installed. Every real Windows/Linux node host therefore failed driver
artifact verification with COMPUTER_DRIVER_PACKAGE_MISSING despite a correct
install. Fall back to import-condition resolution before concluding the
package is missing; the platform packages keep resolving through require.

Found during a live CUA node bring-up on an Ubuntu guest; the regression
test exercises real installed-package resolution on Linux/Windows CI.
2026-08-18 19:06:52 -07:00
Peter Steinberger cc273e6eea fix(channels): stop idle ingress retention writes (#126073)
* fix(channels): prune ingress retention on admission

* style(channels): keep ingress monitor within limit

* fix(channels): skip pruning ignored ingress
2026-08-18 19:05:30 -07:00
Peter Steinberger 61eb7b932b fix(agents): keep guided auth atomic through creation (#126096)
* fix(agents): make guided auth creation atomic

* fix(auth): keep staged agent workspace explicit

* test(auth): use managed temp directory

* fix(gateway): finish detached lifecycle dispatch migration

* fix(auth): carry staged workspace through providers

* test(auth): align mocks with batch persistence
2026-08-18 18:18:53 -07:00
Samuel Judson 6ccc57b331 fix: add ssrf protection to Beam fetches (#123848)
* Add ssrf protection to Beam fetches.

* Additional robustness following initial comments.

* fix(beam): make redirect failures terminal

* chore(plugin-sdk): refresh surface budget

* docs(beam): define redirect restart behavior

* docs(beam): align redirect config help

* test(beam): cover warning before redirect block

* fix(beam): always report terminal redirect blocks

---------

Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com>
2026-08-18 18:00:58 -07:00