Commit Graph

19174 Commits

Author SHA1 Message Date
Peter Steinberger 8ed072ee16 fix: bound GPT-Live buffers and preserve workspace lock ownership (#120911)
* perf(openai): bound realtime audio buffering without repeated copies

* fix(openai): publish media timer before first tick

* fix(gateway): preserve workspace receiver lock ownership

* perf(openai): transfer pending audio ownership

* test(gateway): remove duplicate receiver wait
2026-08-09 09:01:54 -07:00
Peter Steinberger 92bacda206 refactor(telegram): reuse outbound topic preparation (#121095)
Follows #120916 by removing duplicate outbound preparation and transport harness code while preserving channel Direct Messages, forum, and bot-private routing.
2026-08-09 08:57:37 -07:00
Peter Steinberger 75a454469d fix(browser): coalesce volatile tab cleanup (#114507) 2026-08-09 08:50:33 -07:00
Peter Steinberger 081a565cba perf(doctor): restore telegram doctor repairs dropped on source-run hosts (#120954)
* perf(doctor): keep telegram doctor enumeration off the runtime graph

Telegram's built doctor artifact reached execa through dist chunking, so a
source-run host (pnpm dev, tsx CLI, vitest) could not require it and silently
dropped all 9 telegram legacy config rules plus its state migration. The
artifact also pulled telegram's runtime stores, making it a 674-chunk outlier
that dominated doctor enumeration.

Root cause: `src/token.ts` took the broad `plugin-sdk/provider-auth` barrel for
`resolveDefaultSecretProviderAlias`, dragging the auth-profile store, provider
runtime, and plugin install graph (execa, kysely, commander) into the closure.
The alias now has a narrow `plugin-sdk/secret-provider-alias` leaf, and
provider-auth re-exports it so its runtime surface is unchanged.

Thread-binding, sent-message, and sticker-cache row shapes, keys, and legacy
sidecar readers move to `*.legacy-state.ts` leaves. The doctor closure keeps
the rows and drops the ACP, session-binding, send, logger, and plugin-runtime
graphs the stores also load.

The postbuild control-plane verifier only required each artifact in a plain
Node child, the one host where these graphs resolve fine, so it proved nothing
about the invariant that broke. It now also walks each built doctor artifact's
static import closure and fails when it reaches the process-spawn graph, which
is the dist-level analogue of the source closure guard.

Guard rules added for provider-auth, acp-runtime, and conversation-runtime; the
telegram boundary test became a real closure assertion instead of a string grep.

* fix(doctor): drop dead export surface from the telegram legacy-state split

Knip and oxlint caught leftovers from the split: the leaves exported helpers
only they use, the store modules re-exported constants nobody imports from them
anymore, and thread-bindings kept a `testing` barrel whose last production
caller was the migration path that now reads the leaf directly. Tests import the
constants from the leaf that owns them, and the reset helper directly.

The closure gate's failure message still interpolated a `host` field left over
from a probe-host approach that was reverted before commit; the existing verifier
test caught it. The gate now has its own coverage: a transitive chunk edge to a
forbidden dependency is reported, while dynamic imports and non-doctor contract
surfaces are not.

* fix(doctor): adopt the upstream telegram thread-binding store split

`main` landed an equivalent thread-binding leaf as `thread-bindings-store.ts`
while this branch was open, so the branch-local `thread-bindings.legacy-state.ts`
is dropped rather than kept as a second path for the same rows.

`state-migrations.ts` now reaches token.js through the lazy import `main` added,
so `token.ts` is no longer in the doctor closure at all. The narrow
`secret-provider-alias` leaf still matters: telegram's contract-api closure
reaches `provider-auth` through `token.ts` on current `main`, which is the same
execa/kysely/commander graph, so the barrel is repaired at its source instead of
being deferred a second time.

* fix(scripts): type the built doctor closure gate for the TypeScript migration

The gate was authored against the `.mjs` script and landed in the `.mts` file
`main` migrated to, so its parameters were implicitly `any` and `check:test-types`
failed. Adds the explicit signatures plus the violation type.

Regenerates the plugin-sdk API baseline: `provider-auth` re-exports the default
secret-provider alias from the new leaf, so its module hash moves while its
runtime export surface stays identical.
2026-08-09 08:50:03 -07:00
Peter Steinberger 0303af17f3 test: remove low-value implementation assertions (#121085)
* test: remove low-value implementation assertions

* test: refresh native i18n inventory
2026-08-09 08:48:48 -07:00
Vincent Koc 7ea5f8fec6 fix(qa): enforce fresh Matrix state restarts (#121060)
Capture the fallback freshness boundary only after the pre-restart status read completes, immediately before the destructive restart begins.

Co-authored-by: Dallin Romney <6581799+RomneyDa@users.noreply.github.com>

Punchcard-Session: amber-workshop-workshop-36
2026-08-09 23:39:31 +08:00
Peter Steinberger d60a5f7dd4 refactor(plugins): consolidate delivery fixtures (#114464) 2026-08-09 08:30:53 -07:00
Peter Steinberger 843c145b7d fix(codex): preserve provider usage breakdown (#117013) 2026-08-09 08:30:07 -07:00
Vincent Koc 46e6f93a86 fix(qa): reset Matrix scenario config state (#120017)
* fix(qa): reset Matrix scenario config state

Punchcard-Session: amber-workshop-workshop-36

* fix(qa): preserve Matrix tombstone array intent

Punchcard-Session: amber-workshop-workshop-36

* fix(qa): restore Matrix audio scope default

Punchcard-Session: amber-workshop-workshop-36

* fix(qa): type Matrix account reset state

Punchcard-Session: amber-workshop-workshop-36
2026-08-09 23:24:03 +08:00
Peter Steinberger 9a96375e60 feat(gateway): session-catalog terminal start plans behind cliAgents gate (#121020)
* feat(gateway): add session-catalog terminal start plans

* refactor(gateway): split catalog terminal start handler

* fix(gateway): enforce catalog terminal start eligibility

* test(gateway): split session catalog snapshot coverage
2026-08-09 08:13:39 -07:00
Peter Steinberger 75e2595123 fix(slack): preserve system event occurrences and retries (#116384) 2026-08-09 08:12:02 -07:00
Peter Steinberger 9f30191ead refactor(plugins): consolidate message policy fixtures (#114428) 2026-08-09 08:09:33 -07:00
Peter Steinberger ef0c9834be fix(matrix): report block typing refresh failures (#117059) 2026-08-09 07:49:22 -07:00
Pavan Kumar Gondhi e688ed6b88 fix(qqbot): confine staged voice filenames (#120188) 2026-08-09 20:18:31 +05:30
Peter Steinberger fc9905edb2 refactor(providers): consolidate streaming fixtures (#114475) 2026-08-09 07:37:52 -07:00
Masato Hoshino 3ee6c6a3e1 fix(zalo): treat a non-positive mediaMaxMb as unset, not a 0-byte cap (#120988)
`channels.zalo.mediaMaxMb: 0` (or a negative value) passes config validation
and then makes every inbound image download and every hosted outbound media
send fail, with no error naming the setting.

The monitor resolved the cap with `??`, which only replaces `null`/`undefined`,
so `0` and negatives survived into `mediaMaxMb * 1024 * 1024` and reached the
media core as a byte budget no payload can satisfy. Nothing upstream normalizes
the value: the channel schema declares `mediaMaxMb` with no range, and
`mergeAccountConfig` is a plain spread that keeps `0`.

Everywhere else a non-positive `mediaMaxMb` means unset, never reject-all: the
canonical schema is `z.number().positive()`, most bundled channels publish
`exclusiveMinimum: 0`, and the core resolvers fall back to their default. Guard
the resolver so a non-positive value falls back to `DEFAULT_MEDIA_MAX_MB`, which
is what unset already means for Zalo.

Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
2026-08-09 09:36:23 -05:00
Peter Steinberger c70aee247e refactor(scripts): migrate JavaScript tools to TypeScript (#121005)
* refactor(scripts): migrate JavaScript tools to TypeScript

* fix(ci): keep changed-scope preflight zero-install

* fix(ci): preserve zero-install script owners

* fix(ci): complete script migration follow-through

* fix(release): keep stable closeout zero-install

* fix(scripts): preserve standalone execution boundaries

* fix(scripts): repair standalone loader boundaries

* fix(scripts): normalize gateway observation ids

* fix(scripts): keep Docker packager standalone

* test(scripts): preserve rebase cleanup helpers

* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00
Peter Steinberger 00194139ba refactor(providers): consolidate contract fixtures (#114424) 2026-08-09 07:07:47 -07:00
Peter Steinberger 2e6c2bba19 fix(feishu): restore forwarded interactive card content (#115136) 2026-08-09 07:07:03 -07:00
Ayaan Zaidi 409fb7abca fix(telegram): enforce direct-message tool policies
Enforce configured Telegram direct-message tool policies across queued runs and native harnesses. Unsupported restricted harnesses now refuse visibly; turns without explicit policy keep existing tool access.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-08-09 19:32:30 +05:30
Ayaan Zaidi 6a586cd0ea fix(telegram): keep tool progress transient without drafts
Keep quiet Telegram tool progress on the transient draft lane when it exists. Preserve durable delivery for media, execution approvals, and ask-user prompts across direct and queued turns.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-08-09 19:18:02 +05:30
Peter Steinberger 8616c0c374 refactor: finish shared test helper migrations (#120996)
* test: finish shared helper migrations

* test: fix helper migration CI

* style: fix test import ordering

* test(acpx): restore deferred void types

* test: fix helper migrations after rebase
2026-08-09 06:00:06 -07:00
Peter Steinberger 6794fc0fc8 refactor(plugins): consolidate messaging fixtures (#114423) 2026-08-09 05:48:15 -07:00
Peter Steinberger c48339527a fix(imessage): deliver service-qualified media to existing chats [AI-assisted] (#115006)
* fix(imessage): resolve service-qualified media chats

* test(imessage): keep custody coverage on auto handles
2026-08-09 05:42:18 -07:00
Peter Steinberger ab62621223 fix(discord): clean voice temp files on send failures (#120904) 2026-08-09 05:21:20 -07:00
Peter Steinberger 7dcb4fb760 feat(talk): broker realtime sideband control (#121054)
* feat(talk): broker OpenAI realtime sideband

* test(openai): prove audio-only sideband offer

* fix(talk): harden realtime sideband control

* fix(talk): restore sideband session update fence

* fix(talk): recognize GA function output events

* refactor(talk): unify realtime broker session leases

* fix(talk): use PCM audio for WebRTC sideband

* chore(plugin-sdk): refresh API baseline
2026-08-09 05:14:20 -07:00
Peter Steinberger 2a57e1a1af fix(github-copilot): preserve cumulative poll backoff (#103434) 2026-08-09 04:50:18 -07:00
Peter Steinberger 71a33f07a9 fix(imessage): make SSH-backed sends and actions reliable (#121038)
* fix(imessage): harden remote Mac transport

Route SSH-backed iMessage actions through JSON-RPC, preserve remote database paths, and stage outbound files on the Messages Mac with bounded cleanup. Keep local action semantics intact while failing closed on ambiguous wrappers and surfacing the remaining imsg v0.13.4 limits.

* fix(imessage): remove test-only exports
2026-08-09 04:48:38 -07:00
Peter Steinberger 11e897a630 fix(discord): preserve attachment content types (#114460)
Co-authored-by: Zhe Liu <15888718+zheliu2@users.noreply.github.com>
2026-08-09 04:44:38 -07:00
Peter Steinberger b869d5e73f fix(workers): skip shared-host quiescence sweeps (#120969)
* fix(workers): skip shared-host quiescence sweeps

Refs #120952.

* test(workers): update shared-host fixtures

Refs #120952.

* fix(workers): reconcile shared-host lease metadata

* fix(workers): fence unknown lease isolation

* chore(plugin-sdk): refresh API baseline

* fix(workers): fence tunnel isolation updates

* docs(workers): clarify shared-host final fences

* ci: invalidate Vitest cache for state schemas

* refactor(workers): import stableWorkerPathComponent from its defining module

workspace-sync.ts crossed the 700-line lint budget by one; drop its
re-export and point consumers at workspace-sync-helpers directly.
2026-08-09 04:34:39 -07:00
Peter Steinberger d1b4ed872c fix(slack): preserve inbound attachment metadata (#114502) 2026-08-09 04:09:18 -07:00
Peter Steinberger c7cf69a110 fix(opencode): refresh hosted model catalogs (#121030)
* fix(opencode): refresh hosted model catalogs

Align Zen and Go availability, pricing, limits, transports, lifecycle metadata, and model-specific reasoning controls with current provider contracts.

Co-authored-by: samson1357924 <samson1357924@gmail.com>

Co-authored-by: xialonglee <li.xialong@xydigit.com>

* fix(opencode): align catalog metadata with runtime contracts

---------

Co-authored-by: xialonglee <li.xialong@xydigit.com>
2026-08-09 04:05:47 -07:00
Peter Steinberger d280ec1e70 fix(qqbot): handle malformed gateway hello bodies (#121031)
Normalize hostile QQ gateway HELLO bodies before reading heartbeat_interval, use a timer-safe fallback, and keep diagnostics non-throwing.

Co-authored-by: 万拥 0668000723 <wan.yong@xydigit.com>
2026-08-09 03:55:37 -07:00
Peter Steinberger 4e9e7359f6 refactor(acpx): reuse operation session snapshot (#120924) 2026-08-09 03:52:44 -07:00
Peter Steinberger 8362f74c99 feat(browser): add all-tabs extension access (#120995)
* feat(browser): add all-tabs extension access

* fix(browser): preserve cancel revocation during startup

* test(browser): align all-tabs Chromium fixtures
2026-08-09 03:15:54 -07:00
Peter Steinberger a9d3980ed1 refactor(acpx): complete lease ownership and remove legacy reaper heuristics (#121016)
* refactor(acpx): harden pending process leases

* fix(acpx): bound retained probe leases
2026-08-09 03:15:39 -07:00
Peter Steinberger c092900e3c fix(plugins): keep OpenCode Go bundled (#120985)
* fix(plugins): keep OpenCode Go bundled

* fix(plugins): mark OpenCode Go dist bundled

* fix(docs): show OpenCode Go as bundled

* fix(release): defer bundled plugin publication
2026-08-09 03:09:47 -07:00
Peter Steinberger 8b0735e89f refactor(memory)!: remove the QMD backend; builtin is the only memory engine (#120936)
* refactor(memory): remove qmd backend

Make builtin the sole memory-core engine, rename the retained session helper barrel, retire QMD config with doctor migrations, and remove QMD runtime/UI/policy surfaces.

* docs(memory): remove qmd backend guidance

Delete the QMD concept page, rewrite memory documentation for builtin retrieval, and remove QMD from navigation and taxonomy source.

* refactor(memory): remove qmd-only leftovers

* refactor(memory): finish qmd integration cleanup

* build(deps): align root string-width types

* build(deps): model root string-width tooling

* refactor(memory): align qmd removal ui and docs

* fix(memory): preserve qmd external paths in doctor

* test(memory): remove obsolete backend probe case

* test(plugin-sdk): refresh private type baseline
2026-08-09 03:05:47 -07:00
Peter Steinberger e40e352fe7 refactor(session-url): centralize normalization and contract tests (#120945)
* refactor(session-url): centralize contract normalization

* fix(ui): resolve normalization agent-id alias

* test(session-url): make grammar tables type-safe
2026-08-09 02:56:07 -07:00
Peter Steinberger 0df1a89e3a fix(telegram): preserve visible draft recovery (#120626)
* fix(telegram): preserve visible draft recovery

* fix(telegram): await visible draft send

* test(telegram): use const in draft recovery test

* test(telegram): add live partial failure proof

* test(telegram): register live recovery coverage

* ci(qa): support mock Telegram proof scenarios

* test(telegram): isolate live recovery fallback

* test(telegram): assert live recovery behavior

* fix(agents): join partial reply delivery

* test(telegram): keep settlement proof at core boundary
2026-08-09 02:54:38 -07:00
Peter Steinberger d0e812e18f refactor(chutes): remove accidental core OAuth shim (#120993)
* refactor(chutes): remove accidental core OAuth shim

* chore(plugin-sdk): refresh API baseline

* chore(plugin-sdk): refresh API baseline

* chore(plugin-sdk): refresh API baseline

* chore(plugin-sdk): refresh API baseline

* chore(plugin-sdk): refresh API baseline
2026-08-09 02:27:27 -07:00
Peter Steinberger 7d4066639e feat(meetings): enable Linux Chrome talk-back (#118451)
* feat(meetings): add Linux audio routing

* chore(plugin-sdk): refresh meeting audio API baseline
2026-08-09 02:13:17 -07:00
Peter Steinberger c708b41af4 fix(beam): open uploads at canonical catalog URLs (#120927)
* fix(beam): emit canonical catalog URLs

* fix(beam): type readonly runtime config

* fix(gateway): keep minimal metadata startup lazy

* chore(plugin-sdk): refresh API baseline
2026-08-09 02:09:01 -07:00
Peter Steinberger cc4cc83e36 refactor(acpx): remove dead config keys (#120937) 2026-08-09 00:50:12 -07:00
Peter Steinberger e839d4b6de fix(mcp): preserve client and requester lifecycle ownership (#120894)
* fix(codex): preserve MCP discovery client ownership

* fix(codex): close MCP client lifecycle gaps

* test(gateway): isolate profile avatar state

* test(gateway): use immutable cleanup ordering
2026-08-09 00:47:32 -07:00
Peter Steinberger 499d81cdbd perf(plugins): make every plugin closure statically kysely-free and guard it transitively (#120876)
* perf(plugins): close the last kysely closure chains and guard reachability transitively

Follow-up to #120698/#120811/#120882: the closure guard's enumerated barrel
bans cannot catch new heavy edges, and two closures still statically reached
kysely on main.

- guard: add a transitive kysely-reachability test that walks static value
  imports from every doctor-contract and legacy-setup closure through plugin,
  plugin-sdk, and relative core graphs, failing with the full import chain;
  type-only and lazy dynamic imports stay allowed
- llm-task/model refs: manifest-model-id-normalization reads snapshots
  through a registration-slot runtime bridge (snapshot modules register at
  eval; require fallback covers cold processes) and
  current-plugin-metadata-state moves its process-scoped facts onto a
  globalThis singleton so dual module instances share published state
- telegram: split thread-bindings-store.ts (pure record shapes + legacy-file
  readers) out of the acp-runtime-heavy manager, delete the consumer-less
  testing export, move the pure bot-user-id token parse to
  token-fingerprint.ts, and lazy-import token.js in the async update-offset
  detector

llm-task enumeration drops to ~0.8s/157 modules cold; every closure is now
statically kysely-free and stays that way by construction.

* fix(telegram): repoint the native-command menu state at the token-fingerprint parser
2026-08-09 00:39:45 -07:00
Dallin Romney 4847655826 fix(cua-computer): ignore retired driver path (#120502) 2026-08-09 15:34:30 +08:00
Ayaan Zaidi a3d2ac7dc8 fix(telegram): inherit root group policy across accounts
Use channels.telegram.groups as the shared default when an account omits groups. Explicit account maps, including {}, remain full replacements. This keeps chat admission and sender restrictions on one policy path and fixes silent multi-account authorization failures.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-08-09 12:08:53 +05:30
Peter Steinberger 54ae94530c refactor(approvals): simplify resolver plumbing (#120923) 2026-08-08 23:09:24 -07:00
Peter Steinberger d7133e7df6 fix(telegram): preserve direct messages topic routing (#120916)
Replies, previews, and media in channel Direct Messages topics now remain in their originating topic. Bot-private and forum topic routing remains unchanged.
2026-08-08 22:53:35 -07:00