Commit Graph

16632 Commits

Author SHA1 Message Date
Peter Steinberger e04ea7916c feat(twitch): preserve accepted chat through local crashes (#110852)
* feat(twitch): add durable ingress queue

* fix(twitch): satisfy ingress type boundaries
2026-07-18 18:50:56 +01:00
Peter Steinberger 736dddb96a fix(feishu): preserve inbound messages across restarts (#110864)
* fix(feishu): adopt durable inbound ingress

* fix(feishu): preserve failed broadcast ingress

* fix(feishu): commit broadcast lanes at adoption

* test(feishu): fix lifecycle fixture typing
2026-07-18 18:49:38 +01:00
Dallin Romney 917bec3987 fix(qa): stabilize Matrix maturity scenarios (#110398) 2026-07-18 10:46:44 -07:00
Wynne668 1dedaea994 fix(nextcloud-talk): release failed room info response bodies (#110441)
* fix(nextcloud-talk): release failed room info response bodies

* test(nextcloud-talk): satisfy room info lint

* fix(nextcloud-talk): settle guarded response bodies

Co-authored-by: ZengWen-DT <ceng.wen@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 18:45:45 +01:00
Peter Steinberger c2431dfcd2 test(memory): isolate qmd shard fixtures (#110863) 2026-07-18 18:40:02 +01:00
Peter Steinberger 8d89ddd8c2 feat(qqbot): preserve inbound messages through gateway restarts (#110844)
* feat(qqbot): add durable ingress drain

* docs(qqbot): document command replay window

* fix(qqbot): harden ingress settlement cleanup

* fix(qqbot): serialize ingress timeout settlement

* fix(qqbot): satisfy ingress CI guards

* fix(qqbot): satisfy ingress type gates
2026-07-18 18:35:28 +01:00
Peter Steinberger 8a5c8690e1 fix(secrets): keep unaffected owners live during reload failures (#110779)
* fix(secrets): isolate reload failures per owner

* refactor(secrets): split runtime activation helpers

* fix(secrets): export web warning type

* fix(secrets): reject unsafe degraded config writes

* fix(secrets): derive reload defaults type

* fix(secrets): defer reload state publication

* fix(secrets): preserve partial refresh state

* fix(secrets): retry superseded reload preflight

* fix(secrets): bind stale credentials to owner contracts

* fix(secrets): scope degraded credential contracts

* fix(secrets): restore source ownership guards

* fix(secrets): recover provider-only degradation

* fix(secrets): enforce degraded reload contracts

* fix(secrets): preserve scoped reload state

* fix(secrets): reconcile deferred descendant state

* fix(secrets): commit reload state atomically

* fix(secrets): preserve source transaction lineage

* test(secrets): use non-secret lineage marker

* chore(plugin-sdk): refresh API baseline

* fix(secrets): canonicalize web owner contracts

* fix(plugin-sdk): preserve legacy secret owner contracts

* fix(secrets): satisfy startup activation types

* test(secrets): align reload fixtures with owner contracts

* refactor(secrets): move source recovery scope helper

* fix(secrets): preserve owner contracts on web failures

* fix(secrets): bind legacy web resolution contract

* fix(secrets): retry stale auth publication
2026-07-18 18:29:24 +01:00
Peter Steinberger a89086282a fix(googlechat): preserve webhook messages across restarts (#110833)
* feat(googlechat): add durable ingress drain

* fix(googlechat): retain webhook dedupe horizon

* fix(googlechat): break ingress type cycle
2026-07-18 18:26:28 +01:00
Marcus Castro f705f69fc2 fix(whatsapp): preserve live connections across reloads (#110762) 2026-07-18 14:18:11 -03:00
Wynne668 c1eba30949 fix(qa): discard ignored guarded response bodies (#110443)
* fix(qa-lab): release failed suite gateway response bodies

* fix(qa): discard ignored guarded response bodies

Co-authored-by: ZengWen-DT <ceng.wen@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 18:08:16 +01:00
Peter Steinberger 50fdbc5c3f test(feishu): fix delivery trace dispatcher fixture (#110838) 2026-07-18 18:07:41 +01:00
Peter Steinberger 7a35e243c4 refactor(channels): adopt durable Nextcloud Talk and Nostr ingress (#110653)
Accepted Nextcloud Talk webhook and Nostr relay messages now use the shared durable channel-ingress queue. Claims stay owned until reply-lane terminal completion; bounded append and delivery retries fail closed into dead-letter handling; restart recovery owns redelivery; and Nostr cursors advance only after relay EOSE and durable progress.

Related: #109657
2026-07-18 17:30:37 +01:00
Peter Steinberger 4fbdb6d011 test(qa): align coverage inventory contracts (#110799) 2026-07-18 17:22:50 +01:00
Peter Steinberger 3fd3ad8301 fix(ci): restore plugin prerelease validation (#110787)
* test: align plugin prerelease assertions

* test: remove stale vitest import
2026-07-18 17:00:15 +01:00
Peter Steinberger d7b0bacf10 fix(teams-meetings): join and transcribe live meetings reliably (#110615)
* fix(teams-meetings): validate live web flows

* chore(plugin-sdk): update meeting runtime baseline

* test(teams-meetings): align live validation fixtures

* fix(teams-meetings): harden live browser validation

* fix(teams-meetings): preserve live transition lifecycles

* fix(meeting-bot): pass wait budget during recovery

* test(teams-meetings): satisfy extension lint

* fix(teams-meetings): preserve browser session ownership

* fix(teams-meetings): retire audio bridges after leave

* fix(teams-meetings): harden leave and audio ownership

* fix(teams-meetings): preserve leave transition ownership

* fix(teams-meetings): serialize leave cleanup safely

* fix(teams-meetings): guard live transition cleanup

* fix(teams-meetings): preserve adapter boundaries

* fix(teams-meetings): await caption readiness

* fix(teams-meetings): surface caption blockers

* fix(teams-meetings): retry transient media playback

* chore(teams-meetings): defer release notes

* refactor(meeting-bot): isolate navigation error helper

* test(teams-meetings): keep page control helper private

* fix(meeting-bot): bound caption lifecycle cleanup

* chore(plugin-sdk): refresh API baseline

* test(teams-meetings): split caption ownership coverage

* fix(teams-meetings): retry pending audio routing

* fix(teams-meetings): retain leave transition ownership

* fix(teams-meetings): refresh transcript target

* fix(teams-meetings): bound audio routing retries

* fix(teams-meetings): retry pending remote audio

* fix(teams-meetings): harden media source ownership
2026-07-18 15:57:22 +01:00
VectorPeak 4dff4c4996 fix(signal): preserve base URL path prefixes (#110495)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 15:22:31 +01:00
Peter Steinberger 3f976a949a test(signal): isolate tool-result harness lifecycle (#110720) 2026-07-18 15:06:19 +01:00
Peter Steinberger 9710a1339e refactor(canvas): promote inline-widget hosting and show_widget to core (#110475)
* refactor(canvas): promote inline widgets to core

* docs(agents): note discord show_widget ownership at core registration

* ci: retrigger after GitHub scheduling outage

* fix(canvas): satisfy dead-code and test type checks
2026-07-18 14:40:45 +01:00
Peter Steinberger 40793e6f8b fix: bound pasted input and provider response bodies (#110627)
* refactor(runtime): centralize bounded I/O handling

* fix(runtime): finalize bounded I/O contracts

* chore(security): drop stale audit import

* docs(changelog): credit bounded I/O fixes

Co-authored-by: Pick-cat <huang.ting3@xydigit.com>

* fix(agents): keep provider HTTP options private

* fix(ai): traverse OpenAI schema maps by value

* fix(runtime): preserve absolute download deadlines

* ci(ui): stabilize compressed CSS budget

* fix(ai): traverse legacy schema applicators

---------

Co-authored-by: Pick-cat <huang.ting3@xydigit.com>
2026-07-18 13:54:56 +01:00
cxbAsDev af2662f25a fix(reef): add timeout and bounded JSON reads to relay transport (#108333)
* fix(reef): bound relay request duration

Co-authored-by: 陈宪彪0668000387 <chen.xianbiao@xydigit.com>

* test(reef): satisfy timeout fixture lint

Co-authored-by: 陈宪彪0668000387 <chen.xianbiao@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Peter Steinberger <peter@steipete.me>
2026-07-18 13:28:32 +01:00
Peter Steinberger 684ae080d4 fix(signal): preserve durable ingress retry ownership (#110629)
* test(signal): await durable ingress adoption

* fix(signal): keep session conflict retries claim-aware

* test(signal): normalize captured monitor errors

* test(signal): exercise core ingress lifecycle seam
2026-07-18 12:35:27 +01:00
Peter Steinberger 01a9e1d398 feat(memory): default cross-conversation recall for personal installs (#110597)
* feat(memory): default private recall for personal installs

* fix(memory): repair remember-across CI checks
2026-07-18 12:16:49 +01:00
Peter Steinberger 0ac69b9fe8 fix(zalo): prevent webhook message loss after acknowledgment (#110630)
* fix(zalo): adopt durable ingress drain with ack gated on raw-envelope append

OA webhooks acked before detached processing behind a 5-minute in-memory
guard, and Zalo does not retry (silent loss). Raw webhook JSON now appends
durably (event_id = Bot API message.message_id, lane per chat.id) before the
200; failed appends answer 400/500 so nothing acks unpersisted. Dispatch runs
through the core drain with serialized admissions across append backoff,
deferred claims held through shutdown until adoption, retry/dead-letter
classification, and 30d/20k tombstones replacing the deleted 5min/5k guard
after its parity test. Webhook and polling transports stay mutually
exclusive; no twin scenario exists across the four received-event types.

Autoreview scanner false-positive on deleted-line token field references; full
manual review performed (ack ordering, dual-transport exclusivity, eleven-test
matrix). Part of the #109657 fleet program (wave 3).

* refactor(zalo): keep webhook runtime exports private

* test(zalo): use managed temp directories
2026-07-18 12:09:22 +01:00
Peter Steinberger 9d97e10efe refactor: move non-session runtime journals to SQLite (#109427)
* refactor: migrate runtime JSONL state to SQLite

* chore: refresh SQLite migration validation

* fix: preserve safe audit migration order

* fix: sanitize retired audit archives safely

* fix: satisfy SQLite storage architecture gates

* fix: serialize plugin doctor state migrations

* fix: bound memory event SQLite projections

* fix: rotate memory event projections safely

* fix: preserve imported event retention age

* fix: harden memory event export projection

* fix: canonicalize memory event migrations

* fix: harden legacy journal migrations

* fix: report unsafe legacy journal paths

* fix: preserve journal ownership during migration

* fix: keep legacy file imports doctor-only

* fix: align SQLite audit CI coverage

* refactor: keep state helpers module-private

* fix: harden legacy state migration recovery

* fix: reconcile SQLite state audit migration

* test: use neutral audit redaction fixtures

* fix: close SQLite migration recovery gaps

* refactor: split audit migration recovery helpers

* test: prove completed audit pads stay out of backups

* fix: preserve audit record ordinals across blank lines

* fix: align SQLite audit CI contracts

* build: package SQLite audit E2E entries

* fix: preserve audit ordinals in backup snapshots
2026-07-18 11:42:14 +01:00
mushuiyu886 42e6972d35 fix(opencode): Zen GPT-5.6 models are missing from discovery (#110405)
* fix(opencode): add Zen GPT-5.6 models

* test(opencode): narrow GPT-5.6 policy fixture

* fix(opencode): align GPT-5.6 thinking levels

Co-authored-by: 杨浩宇0668001029 <yang.haoyu@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 11:14:05 +01:00
Peter Steinberger e7fe47d63f fix(browser): allow one retry after transient failures (#110607)
* fix(browser): soften transient retry guidance

* style(browser): format retry hint test

* chore: keep release note in PR body
2026-07-18 10:58:22 +01:00
Peter Steinberger a068d38b66 refactor(plugins)!: remove experimental workspaces plugin (#110416)
* refactor(plugins)!: remove experimental workspaces plugin

* fix(doctor): remove retired workspaces plugin state

* refactor(doctor): settle retired-workspaces cleanup before legacy-state detect

* chore(i18n): leave workflow-owned locale artifacts to the locale refresh

* ci: retrigger after GitHub scheduling outage
2026-07-18 10:56:37 +01:00
Peter Steinberger f14947d256 fix(codex): persist automatic compaction history (#110587)
* fix(codex): persist automatic compaction counts

* test(codex): stress compaction and restart recovery

* test(codex): bind compaction waves to fresh counts

* chore: keep Codex release note in PR
2026-07-18 10:37:25 +01:00
xingzhou 91ded68990 fix(vault): SecretRef resolution no longer hangs on stalled response bodies (#108970)
* fix(vault): keep request deadline through response body

* test(vault): use generic stalled-body fixture

* test(vault): mark fixture token synthetic

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 09:46:50 +01:00
Alix-007 bc77ef3398 fix(browser): time out relay WebSocket opening (#109114)
* fix(browser): time out relay WebSocket opening

* test(browser): resolve worker import at runtime

* test(browser): refresh relay worker mocks

Co-authored-by: Alix-007 <li.long15@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Peter Steinberger <peter@steipete.me>
2026-07-18 09:36:46 +01:00
Alix-007 cc7bd4d95a fix(qa-lab): bound Node binary lookup (#109428) 2026-07-18 09:35:16 +01:00
Alix-007 78b4a4afed fix(qa-lab): bound WhatsApp auth archive extraction (#109501) 2026-07-18 09:33:38 +01:00
Chris Eckert 42be965eac improve(mattermost): restart only the changed account on config reload (#99312)
* improve(gateway): restart only the changed account on channel config reload

When a config change is scoped entirely to one channel account
(channels.{kind}.accounts.{accountId}[.*]), restart just that account
instead of the whole channel. Wholesale channel restarts disconnect every
account on the channel; on gateways running many accounts, each
account-scoped config write (adding an account, changing one account's
settings) briefly dropped every other account's connection.

The reload plan gains a restartChannelAccounts bucket populated only when
all of a channel's changed paths are account-scoped; any channel-global
path falls back to the existing wholesale restart, and a channel scheduled
for wholesale restart drops its per-account entries so each (channel,
account) pair restarts at most once. The executor runs per-account
restarts through the existing stopChannel/startChannel accountId parameter.

* fix(gateway): preserve account reload admission

* fix(gateway): scope surgical reloads to isolated plugins

* test(gateway): avoid preactivating reload snapshot

* docs(channels): define account reload isolation contract

* fix(gateway): preflight scoped account reloads

* fix(gateway): re-drain live scoped reload targets

* docs: refresh generated docs map

* fix(mattermost): align scoped reload with durable ingress

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 09:33:06 +01:00
Peter Lee 9a7d615dfc fix(agents): use fetchWithSsrFGuard in minimax-vlm.ts instead of raw fetch (#106163)
* fix(agents): use fetchWithSsrFGuard in minimax-vlm.ts instead of raw fetch

Replace raw fetch() with fetchWithSsrFGuard + withTrustedEnvProxyGuardedFetchMode
in minimaxUnderstandImage, aligning with all other agent network transport
paths (provider-transport-fetch, mcp-http-fetch, web-guarded-fetch, tools-manager).

This adds SSRF protection, redirect safety, debug capture, and proper
dispatcher lifecycle management. The ensureGlobalUndiciEnvProxyDispatcher
call is removed since guarded fetch handles proxy routing in trusted env-proxy
mode.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(agents): preserve configured MiniMax origins in guarded-fetch migration

* fix(agents): resolve lint and type-suppression regressions in MiniMax VLM guarded-fetch tests

Replace as-any casts in vi.mock vi.importActual calls with generic type
parameters, and replace the opts:any parameter in the fetch-guard bridge
with an inline type. Add SSRF policy assertions covering default hosts,
custom public hosts, and explicitly-authorized loopback origins.

* fix(minimax-vlm): thread allowPrivateNetwork into guarded-fetch policy

Honor the explicit provider request private-network opt-out in the MiniMax
VLM guarded-fetch path. When an operator sets
models.providers.<id>.request.allowPrivateNetwork: false, skip the origin
exception for non-default hosts so the explicit denial is authoritative.

Also fix an invalid Vitest fn generic (two-parameter form -> function
signature) that caused check-test-types to fail.

* fix(agents): use canonical provider SSRF policy for MiniMax VLM

* fix(media): harden MiniMax VLM transport

Co-authored-by: Peter Lee <li.xialong@xydigit.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Peter Steinberger <peter@steipete.me>
2026-07-18 09:29:24 +01:00
xingzhou 34440523cd fix(voice-call): ngrok tunnels no longer survive cleanup (#110122)
* fix(voice-call): ngrok tunnels no longer survive cleanup

* fix(voice-call): document bounded ngrok shutdown

* fix(voice-call): reap ngrok after startup timeout

* fix(voice-call): type ngrok process with ignored stdin

* fix(voice-call): compose ngrok timeout lifecycle
2026-07-18 09:09:29 +01:00
Peter Steinberger fcdf3954d7 fix(meetings): wait for audio bridge cleanup (#110548)
* fix(meetings): wait for audio bridge cleanup

Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com>

* test(meetings): skip POSIX signal proof on Windows

---------

Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com>
2026-07-18 09:00:19 +01:00
Peter Steinberger 307353dd1c fix(qa): complete gateway-less transport cleanup 2026-07-18 08:56:13 +01:00
Peter Steinberger 18a49b3a78 refactor(discord): authorize widgets by channel audience (#110522)
* refactor(discord): authorize widgets by channel audience

* docs: refresh Discord Activity map
2026-07-18 08:42:40 +01:00
Peter Steinberger d7de67ae02 feat: ask_user follow-ups — harness convergence, channel finalization + reactions, native cards, docked web panel (#110372)
* feat(ask-user): follow-up harness slice

* feat(ask-user): follow-up channels slice

* feat(ask-user): follow-up native slice

* feat(ui): dock question panel above composer with stepper and compact stream summaries

* docs: refresh follow-up integration maps

* test(ui): align terminal summary proof

* fix(infra): echo declared option answers in terminal status when free-text is allowed

* fix(infra): keep reaction answering when display labels are formatter-adjusted

* fix(agents): settle plain-text claims only after question registration commits

* fix(agents,apps): commit-ordered claim persistence, claim-aware prompt delivery, non-blocking question refresh

* fix(harness,infra): reaction-appropriate question copy, caller presentations honored

* fix(native,infra,agents): local-expiry eviction, value-addressed reactions, reserve-before-request

* fix(infra,android): dual-mode question resolver for compact callbacks; reset terminal retention on replayed pending

* fix(harness,discord): claim-aware prompt delivery in run helper; escape finalization labels

* fix(macos): merge transient-content visibility with question cards after main sync

* fix: repair ask user follow-up CI

* test: update limited bootstrap scope expectation

* fix: retain shared question card API

* chore: refresh native i18n inventory
2026-07-18 03:32:39 -04:00
Peter Steinberger 1ebfa066a5 fix(synology-chat): bound outgoing response deadlines (#110520)
Co-authored-by: Pick-cat <huang.ting3@xydigit.com>
2026-07-18 08:32:25 +01:00
Peter Steinberger a676afd54d fix(qa): release transport leases after gateway stop 2026-07-18 08:23:34 +01:00
Dave Morin 4b3ee5e7eb feat: let agents remember across private conversations (#100140)
* feat(memory): remember across private conversations

Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>

* chore(docs): regenerate config baseline

* fix(memory): restore recall configuration wiring

* fix(memory): scope recall transcript indexing

* test(memory): repair conversation recall fixtures

* test(memory): split session visibility coverage

* style(memory): format type imports

---------

Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 08:21:43 +01:00
mushuiyu886 bfc94ad3c5 fix(nostr): accept uppercase Bech32 keys in setup and DM targeting (#109878)
* fix(nostr): accept uppercase NSEC and NPUB inputs

* test(nostr): satisfy target resolver type check
2026-07-18 08:13:11 +01:00
Peter Steinberger 1f160696dc fix(vydra): preserve errors for broken response bodies (#110478)
Co-authored-by: Pick-cat <huang.ting3@xydigit.com>
2026-07-18 07:59:17 +01:00
mushuiyu886 ac75f0c17a fix(nostr): relay connection failures no longer report successful publishes (#110007)
* fix(nostr): fail over relay connection errors

* fix(nostr): preserve pool publish semantics
2026-07-18 07:53:55 +01:00
Peter Steinberger b116ae5a43 fix: stop mock Control UI QA from hanging in live suites (#110481)
* fix(qa): keep transcript boundary scenario mock-only

* fix(qa): filter scenario-pinned provider lanes

* test(qa): narrow transcript scenario execution type
2026-07-18 07:51:58 +01:00
pick-cat f7cc0ef838 fix(synology-chat): bound user_list fetches with a wall-clock deadline (#109111)
* fix(synology-chat): bound user_list fetches with a wall-clock deadline

* refactor(synology-chat): keep deadline internal

* style(synology-chat): format deadline proof

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 07:51:12 +01:00
Chris Eckert 1d5bf19df4 improve(diagnostics): surface run startup phases as session-correlated events (#107984)
* improve(diagnostics): surface run startup phases as session-correlated events

The embedded runner reports ordered startup milestones (workspace, auth,
context_engine, ..., model_call_started) through the private
onExecutionPhase callback, so they reach typing indicators and cron
watchdogs but never the diagnostic bus. External status surfaces that
already consume run.attempt / run.progress / model.call.* cannot see
where a turn is during startup — exactly the window that matters when a
run hangs before its first model call.

Wrap params.onExecutionPhase once at the runner entry so every phase
transition also emits a session-correlated run.execution_phase event
(runId, sessionId, sessionKey, closed EmbeddedAgentExecutionPhase +
provider/model/tool context). The event rides the async diagnostic lane
like the other high-frequency lifecycle events, so ordering against
model.call.* is preserved and no subscriber work runs on the hot path.
The wrapper tracks session rotation via onSessionIdChanged so
post-compaction phases carry the current session id. Stability records
project the milestone into their dedicated phase/provider/model fields.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(diagnostics): preserve trusted phase observability

* chore(plugin-sdk): refresh diagnostic API baseline

* fix(diagnostics): publish execution phases to plugins

* refactor(logging): keep public diagnostic recorder path

* fix(plugin-sdk): keep deprecated budget exact

* fix(plugin-sdk): refresh diagnostic surface budget

* fix(diagnostics): preserve execution phase coverage

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 07:46:26 +01:00
mushuiyu886 a5cef86b5c fix(nostr): reject non-object profile imports (#110330) 2026-07-18 07:45:10 +01:00
mushuiyu886 f76f06b1ae fix(nostr): return relay event ids in send receipts (#110006) 2026-07-18 07:21:56 +01:00