Commit graph

109 commits

Author SHA1 Message Date
Ayaan Zaidi
1fa3cf278e
fix(bedrock): memory indexing fails under instance metadata throttling (#161164)
* fix(bedrock): avoid IMDS throttling during memory indexing

* fix(bedrock): preserve SDK context in shared credential chain

* test(bedrock): align credential fixtures with SDK send overloads

* fix(bedrock): coalesce refreshes without retaining rotated roles
2026-09-29 20:39:49 +08:00
NianJiu
bb39458580
fix(memory): avoid unnecessary reindexing for patterned extra paths (#158998)
* fix(memory): avoid unnecessary reindexing for patterned extra paths

* test(memory): preserve native glob semantics in scan regressions

---------

Co-authored-by: NianJiuZst <180004567+NianJiuZst@users.noreply.github.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-27 15:13:10 +05:30
Vincent Koc
4c9869c6fd
docs: fix 12 concrete defects from the ux audit remainder (#144128)
Missing prerequisites for two test lanes, a copy-paste slip in an SDK
sample, three undeclared identifiers in a quick start, a colon promising
keys named two paragraphs later, duplicated Related lists, two unlinked
pages that exist, an unbracketed placeholder, and a bare doctor invocation.

The thirteenth fix, an ffmpeg prerequisite on docs/tools/tts/quickstart.md,
is held back: every PR touching that page is refused by the secret scanner
before review.
2026-09-25 17:28:14 +08:00
Dallin Romney
fc0360dab2
fix(memory): honor bootstrap budget during promotion (#142545) 2026-09-13 18:42:01 -07:00
Ayaan Zaidi
ab0ea18607
fix(models): require explicit GitHub Copilot activation (#144749)
Require explicit Copilot configuration, a saved profile, or COPILOT_GITHUB_TOKEN within the existing agent scope. Generic GitHub credentials continue to serve other tools and remain covered by secret audit and cleanup.

Retire the discovery opt-out through the shared Doctor migration and add one-time upgrade guidance. Update provider documentation and generated configuration inventories.

Validated with focused plugin and secret tests, real Gateway starts across all 16 sanitized configs, and independent CLI checks for activation, Doctor notices, secret detection, and matching-value cleanup.

Related: #144726

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-11 13:51:44 +05:30
Vincent Koc
0d66d24fb1
docs: fix verified accuracy findings in channels, cli, nodes, and reference (#143950)
* docs: fix verified accuracy findings in channels, cli, nodes, and reference

Close the open `accuracy` ledger rows for docs/channels/, docs/cli/,
docs/nodes/ and docs/reference/ that survived verification against source.

Each edit is backed by code or by a dated commit/release:

- Name the release for previously unscoped time-relative claims
  (Slack `progress` default 2026.8.1, Telegram preview default 2026.8.1,
  Discord DAVE receive recovery 2026.2.24, gateway ownership contract
  2026.8.1, cron `--deliver`/`cron.failureDestination`/file store,
  nodes `nodes.run` removal 2026.3.31, media `{{Attachment*}}` rename,
  presence clear action, memory-config embedding identity, schema-19
  `consumed_event_id`, `[view ...]` -> `[embed ...]`).
- Delete time-relative wording where no release record exists and state
  present behaviour instead (mattermost, msteams, groups, audio, camera,
  computer-use, secretref store scope, full-release-validation alias).
- Correct concrete defects: matrix `threadReplies` default, audio
  `gpt-transcribe` -> `gpt-4o-transcribe`, camera `--duration-ms`
  (no such flag), signal quickstart probe command, googlechat macOS
  bind-address check, discord `bash` fences holding slash commands,
  usage-window provider lists, RELEASING script naming, zalo disclaimer
  placement, talk.md placeholders, images.md duplicated vision rule.

`pnpm check:docs` passes. `docs-link-audit --anchors` reports the same 3
pre-existing `#windows-app-node` errors as the merge base.

* docs(nodes): restore the approved media-template deprecation window

ClawSweeper is right: `src/plugins/compat/media-legacy-projection.ts` marks
`{{MediaPath}}`, `{{MediaUrl}}`, `{{MediaType}}` and `{{MediaDir}}` deprecated
with `removeAfter: "2026-10-01"`, gated on a clean published-plugin artifact
sweep. "No removal is scheduled" was wrong.

Both pages now keep the deprecated status, state the approved date and its
gate, and link the record's own docs target
(/plugins/sdk-migration/compatibility-policy#media-legacy-projection).
2026-09-10 18:58:15 +08:00
Vincent Koc
d627732f6b
fix(docs): restore anchor ids dropped by heading renames (#143586)
Renaming a heading changes its minted id, and docs/AGENTS.md requires the
old named anchor to survive the reorganization. Fourteen ids were dropped
without a stub, so published links -- bookmarks, search results, and URLs
written in source -- landed on a page that scrolled nowhere. Nothing
caught it: docs-link-audit only walks the docs tree, so a URL living in
source or in a bookmark is invisible to it, and an id that simply stops
being minted breaks no in-repo link once the in-repo links are repointed.

Three of these are the pages PR #143497 worked around by repointing the
source instead: /tools/slash-commands#config, /cli#status, and
/concepts/models#selection-source-and-fallback-behavior. The rest come
from a sweep of every docs id dropped since May that something in the
repo had once linked to.

Each stub is authored beside the heading that now owns the content, and
each page's id set was enumerated with the repo's own parseDocsDocument
before and after: a strict superset every time, no collisions, no
duplicate authored/canonical id.
2026-09-10 11:23:48 +09:00
Peter Steinberger
a4440c941d
fix(update): avoid false Memory Core migration refusals (#143138) 2026-09-09 07:17:32 -07:00
Vincent Koc
82d4e9a423
docs(automation): split the hooks page by reader job (#143041)
The page was 46,017 characters in one flat run: a quick-start tutorial, a
how-to for writing a hook, three reference blocks (HOOK.md fields, the
bundled hooks, the event catalog and context payloads), and a
troubleshooting section. It is now an index with five children, one per
reader job.

Children:

- /automation/hooks/writing-hooks - hook directory layout, the handler
  contract, reply delivery, the HOOK.md metadata fields
- /automation/hooks/configuration - the master switch and selection
  rules, per-hook entries, discovery precedence, hook packs
- /automation/hooks/bundled-hooks - the five shipped hooks and the
  behavior and options of each
- /automation/hooks/event-types - every event key with its trigger and
  wait behavior, plus the context each producer supplies
- /automation/hooks/troubleshooting - hook not discovered, not eligible,
  not executing

The index keeps the overview, "Choose the right surface", the quick start
with its eligibility and scope subsections, plugin hooks, best practices,
the CLI pointer, and Related.

Anchor strategy: per-anchor redirects are impossible because
redirectSource() rejects any source containing [?#]. All 38 pre-split IDs
computed with parseDocsDocument stay alive on the parent index: 11 remain
natively published (hooks, choose-the-right-surface, quick-start,
plugin-hooks, best-practices, cli-reference, related, and both the encoded
and cleaned forms of the two comma headings) and 27 became authored
<a id="..." /> stubs in a "Where each section moved" list, each linking to
the page that now holds the content. Three punctuated headings emit both an
encoded and a cleaned ID; every form is covered. No ID the index still
publishes itself is stubbed, so there is no duplicate authored/canonical ID
collision. A script asserted each pre-split ID resolves end to end: 38/38
pass, all 26 index-to-child fragment targets resolve, and the 6 pages
report 0 collisions.

Losslessness: the five children and the index blocks reassemble in original
order to a body that is byte-identical to the pre-split body,
sha256 4e46aef7b20e0bc73d3ad71b108e6d6e12e8d4c2a662e96d0bf2509578372ce8.
All 14 code fences are identical one-for-one on both info string and body
sha256. Words 5,316 -> 5,695 and table rows 69 -> 75; the deltas are the
five child frontmatters and ledes, the index's 5-row topic table, and the
27-entry moved list. Largest page is now 12,525 characters.

Prose was not rewritten. Six same-page fragment links inside the moved
content now point at the child holding their target, and seven inbound deep
links from other docs pages were retargeted at the children. Retargeting
the event-context link inside the "Every event has these fields" table
widened one column, so format-docs re-padded that table; the cell contents
are unchanged.

Closes audit finding: r3-0012
2026-09-09 19:53:43 +09:00
Peter Steinberger
c21fa54066
docs(install): add Node.js and Bun compatibility reference pages (#142156)
The Node requirement has changed nine times in 2026 and the reasons (the
SQLite WAL-reset corruption floor and the separate node:sqlite TEXT NUL
decoder bug) were buried in install prose; the Bun page's Caveats section
had become the de facto Bun contract while sitting under Containers.

- Add docs/install/node-compatibility.md: supported lines, why the floors
  exist, platform consequences, what each installer provisions, the guard
  diagnostic, and a sourced history of the requirement across releases.
- Add docs/install/bun-compatibility.md: Bun requirements, per-platform
  SQLite builds, macOS library selection and OPENCLAW_SQLITE_LIBRARY with
  the preload migration, the memory scan fallback, known limitations, and
  release history.
- Keep docs/install/node.md and docs/install/bun.md as install how-tos;
  move the contract paragraphs to the new pages and link them.
- Add a Runtimes nav group (Node, Node compatibility, Bun, Bun
  compatibility) and move Bun out of Containers; no URLs change.
- Point the environment reference, memory config, and install overview at
  the new pages; add zh-CN glossary entries; add a docs guide bullet to
  refresh the tables when the runtime floors in code change.
2026-09-08 05:53:53 -07:00
Peter Steinberger
757e482ab6
feat(sqlite): select an extension-capable SQLite library for Bun on macOS (#141854)
* feat(sqlite): select an extension-capable SQLite library for Bun on macOS

Bun on macOS dlopens Apple's SQLite, which omits extension loading, so
sqlite-vec never loaded and memory search fell back to the batched scan.
Bun's only hook is bun:sqlite Database.setCustomSQLite: one-shot, before
the first open, and fatal to every later open on a bad path.

- Add src/infra/bun-sqlite-library.ts: validate each candidate through
  bun:ffi (WAL-reset-safe version, extension loading present) before
  committing; resolve explicit path > OPENCLAW_SQLITE_LIBRARY >
  Homebrew/MacPorts discovery; memoize process-wide. No-op on Node and
  on Linux/Windows Bun, whose static SQLite already loads extensions.
- Select before the first open in the runtime guard probe and in
  requireNodeSqlite; an unusable override becomes a clean runtime-guard
  diagnostic with exit 1 instead of a stack trace.
- Forward the selected library to the memory KNN child through its typed
  stdin input and select there before opening; the child env stays
  stripped. The #141104 scan fallback remains the no-library path.
- Report the selection at Gateway startup and in doctor.
- Retire the undocumented legacy OPENCLAW_CLAUDE_CLI_LOG_OUTPUT alias so
  the OPENCLAW_* name budget stays at 493.
- Docs: Bun install caveats, environment reference, memory config.

* test(sqlite): retain the KNN stdin spy for payload assertions

* docs(bun): explain migration from custom SQLite preloads
2026-09-07 22:53:04 -07:00
ruel225
0bca64f26a
fix(memory): report skipped symlink roots in status (#140381)
Report configured symlink roots through the scanner's existing skip decision and the existing source-status issues. Keep traversal, indexing, and stored data unchanged while recommending canonical absolute paths.

Consolidates the diagnostic contributions from @ruel225 in #140381 and @gaoanze888 in #140281.

Validation: real baseline and candidate memory CLI checks; owner regression tests fail on baseline and pass after repair; scanner siblings pass; hosted CI passes. Independent behavior acceptance and exact-head review are retained with the PR evidence.

Fixes #140214.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-07 09:13:00 +05:30
Peter Steinberger
3cf73bc17c
fix(memory): preserve indentation in cited search snippets (#140471)
Citation decoration stripped the first line's leading whitespace after retrieval. Preserve that prefix while retaining trailing cleanup and source-footer behavior at the presentation owner.

Cover the real SQLite manager-to-tool path with spaces, tabs, citation-mode controls, unchanged source bytes, and both public result forms. Clarify the documented citation formatting contract.
2026-09-06 15:06:53 -07:00
Peter Steinberger
bf090f0f79
fix(memory): short queries miss note content with trigram indexing (#139777) 2026-09-05 23:53:48 -07:00
Peter Steinberger
29691db02b
fix(memory): explain unsafe legacy host-event path recovery (#139195)
Give doctor one actionable rejection diagnostic with the legacy event path, filesystem error, and supported shared-note indexing alternative. Preserve the existing migration and symlink policy. Reconstructed hangs did not reproduce on 2026.9.1 or main. Refs #139166.
2026-09-05 10:15:28 -07:00
Peter Steinberger
f4647c4d1a
fix(memory): make watcher pressure guidance actionable (#137181)
Replace the rejected memory.search.sync.watch recommendation with effective extra-path/root reduction, host-limit review, and an affected-agent reindex command for the Gateway environment. Reuse the existing CLI formatter to preserve profile/container routing. Watcher behavior, thresholds, timers, schemas and defaults stay unchanged.

Cover native-directory and Chokidar-path warnings, named profiles, exact-once timing and cleanup. Canonicalize the touched test fixture instead of exceeding its line limit.

Proof: real isolated baseline warning and rejected-key CLI validation; 90 watcher/filesystem/registry tests, 343 config/profile siblings, scoped checks and fresh independent review. Candidate recovery proof remains a pre-land gate.

Fixes #137156.
2026-09-03 05:18:36 -07:00
Peter Steinberger
2fffd4e8ba
feat(sessions): enable cross-agent session access by default (#136755)
* feat(sessions): enable cross-agent session access by default

`tools.sessions.visibility` now defaults to `all` and
`tools.agentToAgent.enabled` to `true`; both widen access.
Narrow access via `tools.sessions.visibility` (agent|tree|self),
`tools.agentToAgent.allow`, or `enabled: false`.

Document that an omitted/empty allow list permits every agent pair.
Denial copy for narrowed visibility no longer instructs enabling the
already-on policy. Regenerate prompt-snapshot fixtures for the visibility
hedge. Maintainer-directed.

* feat(security): audit default cross-agent session access

Add `security.trust_model.cross_agent_session_access_default`: `info`
for plain multi-agent defaults, `warn` with sandbox/tool-restriction/
multi-user ingress signals. No new config keys.

* test(gateway): drain detached a2a flow between agentId send rows

The announce/ping-pong flow outlives the sessions_send tool request; the second agentId row picked up the first row's follow-up agent call for agent:orion:main, so each row now waits for gateway active work to drain before releasing its test state.

* test(security): mock the cross-agent access collector in the non-deep facade

The readonly-setup-fallback test mocks audit.nondeep.runtime with an explicit factory; it now exports collectCrossAgentSessionAccessFindings so the registered collector resolves under the mock (CI run 33699015755, checks-node-compact-large-21).

* fix(security): scope the cross-agent audit to unsandboxed sessions

The audit finding now names which agents can reach other agents
(unsandboxed sessions, or any session when
agents.defaults.sandbox.sessionToolsVisibility is "all"), emits nothing
when every agent is fully sandboxed under the default clamp, and says
sandboxed transcripts stay readable by unsandboxed callers.

Docs qualify the agent-to-agent reference with the requester-owned
native/ACP child exception and correct the security overview's sandbox
wording. Addresses both ClawSweeper rank-up moves on #136755.

* docs(security): qualify the fully sandboxed audit exemption

State in the CLI reference and high-level security audit summary that
fully sandboxed rosters under the default spawn-tree clamp produce no
cross-agent access finding. Disabling that clamp removes the exemption.

Addresses the mechanical ClawSweeper rank-up on #136755 at 3208e19534e.

* fix(security): report per-agent session tool reach in the cross-agent audit

The finding now lists which agents can reach other agents (unclamped sessions that still have a session tool allowed) with their calling context and allowed tools, lists non-reaching agents with the reason, and emits nothing when nobody reaches; help text no longer claims enabled=false isolates agents because requester-owned native/ACP child sessions stay reachable under tree or all visibility; gateway final-effect proof that a disabled policy or restrictive allow list never dispatches to the target. Addresses the ClawSweeper re-review on #136755.

* test(gateway): drain detached a2a flow in an afterEach hook

The in-row drain shared the row's 10s budget and could time out under load, leaking the next row's mock calls; the hook has its own bounded timeout.

* docs: stop describing disabled agent-to-agent access as isolation

enabled: false blocks ordinary cross-agent access, but requester-owned native subagent and ACP child sessions stay reachable under tree or all visibility; every introduced claim now says so and points strict separation to tools.sessions.visibility or separate gateways. Addresses the ClawSweeper P2 on #136755.

* test(qa-lab): prove default cross-agent send and policy denials end to end

Three mock-openai flow scenarios run a two-agent QA Gateway: default config dispatches sessions_send to agent:orion:main (accepted, target run observed, target main session created); enabled=false and a restrictive allow list return forbidden before any target work. Addresses the ClawSweeper P1 merge risk on #136755.

* fix(config): stop listing tree visibility as strict separation

Strict separation is agent or self; tree still admits requester-owned native subagent and ACP child sessions across agents. Addresses a ClawSweeper rank-up move on #136755.
2026-09-02 22:39:03 -07:00
0xParzival
e44c4b8a3e
fix(memory): resolve profile auth for compatible embeddings (#134744)
* fix(memory): resolve profile auth for compatible embeddings

* test(memory): close profile fixture SQLite handles

* fix(memory): preserve credential ownership in embedding auth

Resolve saved profile bindings through the canonical terminal auth capability while preserving literal, blank, explicit-header and destination behavior. Retain general model-auth precedence and shared guard policy; exercise real HTTP, SQLite and public CLI indexing/search. Reuse the canonical doctor CI fixture and repair executable-preflight test isolation.

Co-authored-by: 0x-Parzival <0x-Parzival@users.noreply.github.com>

* fix(memory): preserve auth policy for configured embeddings

Carry the selected provider API into the canonical auth-mode check, so direct OpenAI routes reject saved token profiles before embedding HTTP. Check auth migration readiness before classifying provider-entry credentials, including warm snapshots after a legacy credentials file is restored. Keep explicit remote credentials, literal keys, and canonical SQLite profile ownership intact.

Regression coverage exercises provider/API/credential-mode combinations and cold-empty, warm-empty, and populated canonical stores with real embedding HTTP and SQLite.

Co-authored-by: 0xParzival <145645180+0x-Parzival@users.noreply.github.com>

* test(pr): reuse landed cross-checkout fixture

Adopt the exact cross-checkout fixture already landed in main by #134740, resolving the overlapping cleanup while preserving the isolated executable command stubs. The embedding and auth implementation is unchanged.

Co-authored-by: 0xParzival <145645180+0x-Parzival@users.noreply.github.com>

---------

Co-authored-by: 0x-Parzival <0x-Parzival@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: 0xParzival <145645180+0x-Parzival@users.noreply.github.com>
2026-09-01 05:20:13 -07:00
Peter Steinberger
5a6098b7ca
feat(sessions): default session tools to agent visibility (#133469)
* feat(sessions): default session tools to agent visibility

* test(sessions): align prompt fixtures and recover UI headroom

* fix(sessions): align search guidance with visible scope
2026-08-30 13:24:54 -07:00
Peter Steinberger
ba1be2f427
fix(memory): honor configured primary search result limits (#133254) 2026-08-30 03:35:29 -07:00
Peter Steinberger
61a47996d5
fix(memory): forgotten content survives retries and consolidation (#131179)
* fix(memory): preserve provenance until derived content is purged

* refactor(memory): simplify provenance key collections
2026-08-27 15:44:53 -07:00
Peter Steinberger
5153f25495
fix(memory): prevent forgotten session content from returning (#130451) 2026-08-26 16:26:00 -07:00
Peter Steinberger
8e39f58365
docs(memory): add memory provenance and deletion concepts page (#130278)
* docs(memory): add memory provenance and deletion concepts page

New concepts/memory-provenance page tells the operator policy story end to end: recorded session lineage through consolidation, the admission policy and its pipeline-only boundary, memory forget guarantees (whole-entry purge, derived-artifact sweep, forgotten tombstones) and reported boundaries (transcripts, curated writes, paraphrased prose), plus the person/source purge workflow. Cross-linked from memory architecture, dreaming, builtin, overview, CLI, and config reference; registered in docs navigation.

* docs(i18n): add glossary terms for the memory provenance page

* docs(memory): distinguish curated entries from missing lineage in the provenance page
2026-08-26 11:36:39 -07:00
Peter Steinberger
9d9dc31275
feat(memory): session provenance, admission policy, and openclaw memory forget (#130151)
* feat(state): add memory entry origins and session tombstone tables with session-aware write provenance

Additive same-version per-agent tables (memory_entry_origins, memory_session_tombstones) declared canonically with lazy idempotent ensure; read-only agent DB access exposed through the SDK; memory-write observers and the session-memory hook record the authoring session; archived narrative transcripts classified by authoritative run identity.

* feat(memory): admission policy, entry provenance, and openclaw memory forget

memoryPolicy.excludeSessions keeps configured sources out of the dreaming pipeline with recorded exclusions; promotion writes are marker-addressable and carry per-session origins through consolidation; memory forget purges whole entries and every derived artifact (corpus lines, diary quotes, index/FTS/vec/cache, short-term state, backups), reports curated agent writes from transcripts, and tombstones purged sessions so ingestion, backfill, and transcript indexing never re-admit them.

* docs(memory): document admission policy, memory forget, and provenance boundaries

* fix(memory): open the vec probe through openNodeSqliteDatabase

Kysely guardrail forbids direct node:sqlite constructors in production; the in-memory extension probe now uses the canonical opener.

* fix(memory): resolve archived and explicit sessions in memory forget

Explicit --session selectors union live session windows, transcript archives, and exact unresolved ids so an operator-named session always purges and tombstones instead of silently no-oping after lifecycle archival; reports carry per-session resolution sources. ClawSweeper P1 on #130151.

* fix(memory): reconcile consolidation origins for every workspace agent

Shared workspaces record entry origins per source agent; consolidation now re-keys and prunes origins in each participating agent's database (membership from the authoritative dreaming workspace mapping), so a non-owner agent's later memory forget still finds the live consolidated entry. ClawSweeper re-review P1 on #130151.
2026-08-26 10:57:04 -07:00
Peter Steinberger
49d916e8e9
fix(memory): preserve session recall when upgrading from QMD (#130016)
* fix(memory): preserve QMD session search across builtin migration

* fix(memory): migrate agent defaults to canonical memory owner
2026-08-26 03:18:42 -07:00
Peter Steinberger
a556d5379b
fix(google): honor supported Gemini embedding dimensions (#129038) 2026-08-24 23:39:35 -07:00
Peter Steinberger
e30279f89f
fix(google): support stable Gemini Embedding 2 request contracts (#128716)
* fix(memory): support stable Gemini Embedding 2

* fix(memory): validate async Gemini batch dimensions

* docs(memory): explain stable Gemini index rebuild

* docs(memory): cover explicit-dimension rebuilds

* fix(google): honor stable Gemini embedding task contracts

Co-authored-by: Franck MEYER <meyerfranckpro@gmail.com>

---------

Co-authored-by: Codex OpenClaw Migration <noreply@local>
Co-authored-by: Franck MEYER <meyerfranckpro@gmail.com>
2026-08-24 05:38:54 -07:00
Peter Steinberger
8083d4dd3f
fix(memory): enforce canonical SecretRef resolution (#127699)
* fix(memory): enforce canonical SecretRef resolution

Make Gateway runtime snapshots the exclusive owner of memory SecretRef materialization. Bind embedding credentials and headers to provider-owned destinations, and fence per-agent stale reuse by the provider destination/auth contract.

Release note: Memory search resolves secret references through configured provider policy and keeps embedding credentials scoped to their intended destination.

* fix(lmstudio): preserve resolved memory headers

memory remote headers are already materialized by the Gateway snapshot and now bypass SecretRef re-resolution; provider-owned headers retain canonical resolution; final loopback request proof covers literal preservation and precedence.

* fix(memory): bind stale credentials to auth owners

Resolve memory adapter credential owners from snapshot manifest metadata, conservatively fail cold when metadata is absent, and prove Gemini/Google destination changes plus zero-egress unresolved refs.

* fix(memory): scope compatible embedding credentials

Apply destination ownership to the core compatible adapter while preserving destination-owned credentials and intentionally unauthenticated endpoints. Distinguish loopback principals, consolidate duplicate security tests, and verify the final credential boundary through a live isolated Gateway request.

* test(memory): align destination auth precedence

* fix(memory): bind credentials to query identity

Include URL query parameters in embedding destination ownership so provider credentials and headers never cross tenant boundaries.

* fix(memory): preserve query-bound embedding destinations
2026-08-23 20:36:55 -07:00
Peter Steinberger
7349177ce3
feat: main-session agent-wide visibility + session.groupScope routing (#124965)
* feat: add main session group routing

* docs: explain main session routing scopes

* fix: align memory session visibility

* test(qa): cover main-scoped group bindings

* fix(sessions): preserve binding-scoped outbound routes

* fix(routing): preserve explicit outbound owners

* fix(sessions): recognize global main visibility

* chore(ci): prune assertion safety baseline
2026-08-16 19:57:18 -07:00
Peter Steinberger
d23246770a
fix(memory): report indexed SQLite sessions (#124834)
* fix(memory): report indexed SQLite sessions

* refactor(memory): remove unused state path export
2026-08-16 14:38:15 -07:00
Peter Steinberger
1348387076
refactor(plugins): replace node-llama-cpp with managed llama-server (#123105)
Move llama.cpp chat and local embeddings onto a verified externally managed llama-server runtime. Remove the in-process native runtime, forked embedding workers, and node-llama-cpp dependency while preserving guided setup, local GGUF models, tool-capable agent runs, diagnostics, and operator docs.
2026-08-13 16:58:20 -07:00
Peter Steinberger
e45a9460ce
docs: repair spellcheck and anchor drift (#122960)
* docs: repair spellcheck and anchor drift

* docs: satisfy markdown anchor lint
2026-08-12 20:50:56 -07:00
Peter Steinberger
914f73ac99
docs: replace retired config keys with canonical schema keys (#121330) 2026-08-09 20:30:43 -07:00
Peter Steinberger
c37b53868d
feat(memory): enable MMR diversity by default (#121224)
Apply deterministic relevance-biased diversity ordering to builtin hybrid recall and preserve distinct non-tokenized snippets.
2026-08-09 13:30:18 -07:00
Peter Steinberger
8dbd30ba74
feat(memory): per-entry glob patterns for extraPaths (#121209)
* feat(memory): support globbed extra paths

Allow root-relative glob patterns on existing memory.search.extraPaths entries across discovery, watching, reindex identity, and QMD migration.

* fix(memory): drop stale lease type import

* fix(memory): enforce extra path glob scope
2026-08-09 13:05:24 -07:00
Peter Steinberger
8b0735e89f
refactor(memory)!: remove the QMD backend; builtin is the only memory engine (#120936)
* refactor(memory): remove qmd backend

Make builtin the sole memory-core engine, rename the retained session helper barrel, retire QMD config with doctor migrations, and remove QMD runtime/UI/policy surfaces.

* docs(memory): remove qmd backend guidance

Delete the QMD concept page, rewrite memory documentation for builtin retrieval, and remove QMD from navigation and taxonomy source.

* refactor(memory): remove qmd-only leftovers

* refactor(memory): finish qmd integration cleanup

* build(deps): align root string-width types

* build(deps): model root string-width tooling

* refactor(memory): align qmd removal ui and docs

* fix(memory): preserve qmd external paths in doctor

* test(memory): remove obsolete backend probe case

* test(plugin-sdk): refresh private type baseline
2026-08-09 03:05:47 -07:00
Peter Steinberger
cef675233b
docs(memory): explain overlapping hook and transcript indexing (#118299) 2026-08-02 17:06:32 -07:00
Peter Steinberger
28630a9a65
feat(memory): provenance-gated memory with dreaming on by default (#114819)
* feat(memory): add provenance and recall metadata to the memory index

* feat(memory): provenance-gated promotion and capture hygiene

* feat(dreaming): LLM consolidation with deterministic gates, on by default

* feat(active-memory): deterministic recall lane with escalation default

* feat(memory): user model file and standing intents

* docs(memory): document the memory architecture

* fix(memory): live-QA fixes — metadata writers, provenance classes, intent scope, claim accumulation
2026-07-28 06:04:25 -04:00
Peter Steinberger
1e20cc814e
docs: retire config keys that strict validation rejects (#113956)
* docs: correct retired cron/audit config keys, cron failure-alert default, memory recall default, and tool-search telemetry claims

- configuration-reference: cron block documented cron.webhook and cron.failureDestination, both retired by the config-surface reduction tranches (58452de711, edecdbd05e); the cron schema is strict so a copied snippet is rejected. Document only the live keys and note the doctor --fix migrations.
- configuration-reference: root-level audit block is retired; canonical path is logging.audit (src/config/zod-schema.root-shape.ts).
- configuration-reference: cron.failureAlert.after default is 2, not 3 (src/cron/service/failure-alerts.ts).
- memory-config: rememberAcrossConversations defaults on for personal installs (packages/memory-host-sdk/src/host/config-utils.ts), matching the canonical table earlier in the page.
- tool-search: telemetry records catalogSize, per-source counts, and search/describe/call counts, and only on tool_search_code results. No byte accounting exists in the runtime.

* docs: retire remaining references to removed cron, audit, and logging config keys

Sweep follow-up to the previous commit, covering the same bug class in the pages that still contradicted it.

- cron-jobs/cli-cron: global cron.failureDestination is retired; the destination fields now live on cron.failureAlert (src/config/zod-schema.root-shape.ts, merged by legacy-config-migrations.runtime.retired.ts:379). Per-job delivery.failureDestination bullets left intact.
- gateway/audit, cli/audit, gateway/protocol: root-level audit.* is retired; canonical path is logging.audit.*.
- logging: logging.redactSensitive is retired (dead-config-keys.test.ts:198; removed by legacy-config-migrations.runtime.tier-eval.ts:12). resolveConfigRedaction hardcodes DEFAULT_REDACT_MODE = tools, so redaction is unconditional. Also documented that redactPatterns replaces the defaults on the log path (redact.ts:419) while tool payloads always merge them.
- logging: consoleStyle accepts only pretty|json (zod-schema.root-shape.ts:106); compact remains the automatic non-TTY rendering style (logging/console.ts:40) but is no longer settable, and doctor maps a stored one to pretty.
- security: security --fix no longer touches redaction and the logging.redact_off audit check is retired (src/security/audit-loopback-logging.test.ts asserts it never fires).

* chore(docs): regenerate docs map after retired-key cleanup
2026-07-25 18:24:02 -07:00
Peter Steinberger
edecdbd05e
refactor(config): config-surface reduction tranche 3 — product consolidations (review request) (#111527)
* refactor(config): consolidate media model lists

* refactor(config): unify memory configuration

* refactor(config): consolidate TTS ownership

* refactor(config): move typing policy to agents

* refactor(config): retire product-level config surfaces

* refactor(config): share scoped tool policy type

* chore(config): refresh generated baselines

* fix(config): honor agent typing overrides

* fix(config): migrate sibling config consumers

* refactor(infra): keep base64url decoder private

* fix(config): strip invalid legacy TTS values

* chore(config): refresh rebased baseline hash

* fix(doctor): route legacy messages.tts.realtime voice to talk during tts move

* refactor(config): polish final layout names

* refactor(config): freeze retired tuning defaults

* feat(config): add fast mode default symmetry

* refactor(config): key agent entries by id

* docs(config): update final layout reference

* test(config): cover final layout migrations

* chore(config): refresh final layout baselines

* fix(config): align final layout runtime readers

* fix(config): align remaining readers

* fix(config): stabilize final layout migrations

* fix(config): finalize config projection proof

* fix(config): address final layout review

* docs(release): preserve historical config names

* fix(config): complete keyed agent migration

* fix(config): close final migration gaps

* fix(config): finish full-branch review

* fix(config): complete runtime secret detection

* fix(config): close final review findings

* fix(config): finish canonical docs and heartbeat migration

* fix(config): integrate latest main after rebase

* refactor(env): isolate test-only controls

* refactor(env): isolate build and development controls

* refactor(env): collapse process identity indirection

* refactor(env): remove duplicate config and temp aliases

* docs(env): define the operator-facing allowlist

* ci(env): ratchet production variable count

* fix(env): remove stale provider helper import

* fix(env): make ratchet sorting explicit

* test(env): keep test seam in dead-code audit

* test(env): cover ratchet growth and boundary; document surface budgets

* docs(config): document tier-eval consolidations

* docs(config): clarify speech preference ownership

* test(memory): align retired tuning fixtures

* refactor(memory): freeze engine heuristics

* refactor(config): apply tier-eval tranche

* refactor(tts): move persona shaping to providers

* refactor(compaction): move prompt policy to providers

* test(config): align hookified prompt fixtures

* chore(deadcode): classify test-only exports

* chore(github): remove unused spawn helper

* chore(deadcode): classify queue diagnostics

* chore(deadcode): remove unused lane snapshot export

* chore(plugin-sdk): ratchet consolidated surface

* fix(config): integrate latest main after rebase
2026-07-21 20:28:43 -07:00
Peter Steinberger
783a5d21cf
refactor(config): purge numeric tuning knobs behind built-in defaults (#111382) 2026-07-19 07:35:45 -07:00
Peter Steinberger
a5ec26fa3c
fix: prevent LINE channel reloads from hanging on stalled deliveries (#110971)
* fix(channels): bound ingress shutdown and document retention

* docs(channels): note ingress shutdown behavior

* chore: keep release notes in pull request

* docs: refresh documentation map

* fix(line): preserve deferred claims during shutdown

* fix(line): handle late abandonment failures
2026-07-18 23:25:33 +01:00
Peter Steinberger
01a9e1d398
feat(memory): default cross-conversation recall for personal installs (#110597)
* feat(memory): default private recall for personal installs

* fix(memory): repair remember-across CI checks
2026-07-18 12:16:49 +01:00
Dave Morin
4b3ee5e7eb
feat: let agents remember across private conversations (#100140)
* feat(memory): remember across private conversations

Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>

* chore(docs): regenerate config baseline

* fix(memory): restore recall configuration wiring

* fix(memory): scope recall transcript indexing

* test(memory): repair conversation recall fixtures

* test(memory): split session visibility coverage

* style(memory): format type imports

---------

Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 08:21:43 +01:00
Ben Badejo
2725742cad
fix(memory): respect QMD timeout for memory_search (#95757)
* fix(memory): scope qmd search deadline

Preserve the phase-scoped QMD timeout semantics on current main.

Co-authored-by: Peter Steinberger <58493+steipete@users.noreply.github.com>

* docs: refresh generated docs map

* test(memory): reconcile manager mock with current main

* test(memory): isolate deadline mock import

* style(memory): format search test mocks

* test(memory): decouple mock from deadline symbol

* chore(memory): refresh reviewed pull request head

---------

Co-authored-by: Benjamin Badejo <ben@benbadejo.com>
Co-authored-by: Peter Steinberger <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Peter Steinberger <peter@steipete.me>
2026-07-13 00:05:13 -07:00
Vincent Koc
3f55aa837d docs(memory): explain llama.cpp runtime diagnostics 2026-07-11 16:40:14 +08:00
Peter Steinberger
f7d7148cf0
docs: rewrite published docs grounded in current source (#100142)
Source-grounded rewrite of 529 published docs pages with per-unit information-loss verification: 1,713 factual corrections cited to src/**, generated surfaces regenerated, frontmatter titles preserved for i18n, release notes pages untouched. All docs gates green.

Closes #100141
2026-07-05 00:32:47 -04:00
JC
78029e43d2
fix(doctor): warn and document QMD session recall gates (#80947)
* Warn on QMD session recall export mismatch

* Clarify session transcript recall gates
2026-06-28 13:55:27 -07:00
Vincent Koc
f324f7e281 refactor(memory): use the per-agent sqlite database 2026-06-19 01:20:06 +08:00
Vincent Koc
17be26bc4f
fix(gateway): arm qmd startup maintenance
Fix Gateway QMD startup so interval and embedding maintenance are armed when configured, even when the immediate on-boot update is disabled.
2026-06-11 01:13:41 +09:00