Commit Graph

2332 Commits

Author SHA1 Message Date
doryani-agent 2a980fbcbd fix(update): let systemd clients outwait legitimate unit transactions
Salvage the unit-budget implementation from #104745, replacing its test
matrix with two invariant tests and covering the sibling graceful start.
Keep unprivileged property reads, finite fallbacks, real manager errors,
and post-restart health verification.

Native disposable user unit: old client timed out after 15.03 seconds;
new client completed the same 16-second stop transaction in 16.13 seconds.
The unit stayed active with a new PID; missing-unit errors stayed errors.

Co-authored-by: Teknium <127238744+teknium1@users.noreply.github.com>
2026-09-07 08:20:09 -07:00
Teknium bbbcde8173 fix(process): stop late forks escaping deadline tree cleanup 2026-09-07 08:19:32 -07:00
Teknium e1a161538a fix(cron): make failed runs diagnosable without verbose delivery errors
Persist a redacted chained traceback in the private run output and expose
redacted last_error in tool and slash listings, including historical errors.
Keep the run_job concise error return unchanged for delivery classification.

Slim redo of liuhao1024's earliest #104545; adds forced redaction and keeps
formatting in a topical sibling. Local SDK/socket A/B verifies diagnosis
visibility plus healthy-script, clearing, and private-file controls.
Canonical tests queued under the campaign lock at commit time.

Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>
2026-09-07 08:18:56 -07:00
Teknium e3710c1593 fix(cron): preserve continuity across silent audit ticks
Slim redo of #104546 and #104551: scan newest-first, match suppression only before payload separators, and keep error context. Covers wake gates and empty outputs without reading every historical file twice.

Co-authored-by: PRATHAMESH75 <prathamesh290504@gmail.com>

Co-authored-by: Konstantin Khlopkov <konstantin.khlopkov93@gmail.com>
2026-09-07 08:18:20 -07:00
Teknium 549e6aab38 fix(bot-mode): preserve refusal reasons across local delivery
Emit the one-shot reason marker outside the CLI facade; parse whole codes before falling back to legacy prose. Explicit coordination and unknown codes cannot be labeled target_busy.

Fixes #104784
Co-authored-by: William Echo <2054936695@qq.com>
2026-09-07 08:15:32 -07:00
Teknium ab98a92a45 fix(notifications): report applied skill batch operations
Use successful applied result records rather than requested operations, and keep staged writes silent. Include legacy delete/write messages.

Fixes #104506
Co-authored-by: Konstantin Khlopkov <konstantin.khlopkov93@gmail.com>
2026-09-07 08:14:14 -07:00
Teknium 7876d183c9 fix(approval): recover legacy list values without character grants
Recover legacy stringified lists with a warning. Reject malformed shapes and nonstring members without admitting approvals or rewriting user config on read.

Fixes #104779
Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>
2026-09-07 08:13:38 -07:00
Teknium 04767e7aaa fix(display): distinguish estimated context from provider usage 2026-09-07 08:13:01 -07:00
Teknium 1eb1b795b5 test(gemini): verify alias routing and compatible endpoint controls 2026-09-07 08:10:36 -07:00
Teknium a9ef4a7625 fix(codex): keep transport echoes out of durable user history
Port the exact submitted-wire-text ownership boundary from #93546 onto
current topical runtime code. Do not add the candidate's mocked-result
fallback or storage-level content deduplication. Preserve later distinct
and identical user events, separate identical accepted turns, and keyless
inputs. Add two regression invariants and offline subprocess-wire A/B.

Local wire A/B: 4/8 control matrix passing on base, 8/8 after.
Broader tests queued behind campaign lock; not ready for merge.

Refs #104653
Original diagnosis: @gitszabolcs (#38254)
Original implementation: #43127, submitted by @vashkartik
Focused salvage and wire-text correction: @fancyboi999 (#93546)
Current-main carry-forward considered: #104698

Co-authored-by: Xinmin Zeng <135568692+fancyboi999@users.noreply.github.com>
Co-authored-by: VECTOR <vector.hq@outlook.com>
2026-09-07 08:09:57 -07:00
Teknium 5904c7a395 fix(threats): keep unrelated role prose in context files
Salvage the bounded target-slot design from #104617, using mandatory
word separators to avoid ambiguous repeated matches. Preserve long
payload detection and execution-verb boundaries. Replace the three
candidate tests with two context-loader invariants and document the
heuristic's limits.

Fixes #104609
Co-authored-by: Konstantin Khlopkov <konstantin.khlopkov93@gmail.com>
2026-09-07 08:09:20 -07:00
Teknium bbbccd3935 fix: failed probe credentials cannot fall through to configured auth 2026-09-07 08:08:04 -07:00
Teknium 7d44fe9c74 fix: capability probes send minted credentials instead of callable representations
Extend #104477 to the native thinking, vision, metadata, and local header paths identified by #87641. Materialize only at probe boundaries; leave the chat callable and cache ownership untouched. Local-wire A/B: thinking and vision show requests change from 403 to 200, while static credentials and callable chat retain success. Target suites queued.

Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>
2026-09-07 08:08:04 -07:00
Teknium bdf45abd7c fix: prefer owned Anthropic grants and bind auxiliary refresh to request credentials
Port owned-before-borrowed resolution from #104624, crediting the root cause in #104622. Include the synchronous and asynchronous auxiliary fallback recovery sites: forward the failed request key so an unrelated borrowed login never owns that refresh. Local-wire probes preserve the borrowed file and exchange only the owned grant. Broader validation remains queued; do not treat this commit as ready.

Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>

Co-authored-by: d-bow-dev <24577047+dwb1991@users.noreply.github.com>
2026-09-07 08:07:26 -07:00
Teknium 134b173efa fix: reject independent Nous account refresh without clearing cooldown 2026-09-07 08:06:48 -07:00
Teknium f087cb8055 test: exercise credential controls through PTY and local OAuth wire 2026-09-07 08:06:48 -07:00
Brian Le 32a59f3bf7 feat: refresh one pooled OAuth grant from the CLI 2026-09-07 08:06:48 -07:00
Brian Le 1a4bb74a40 feat: choose pooled credential priority from the CLI 2026-09-07 08:06:48 -07:00
Brian Le 53221df05f feat: reset one pooled credential without clearing sibling cooldowns 2026-09-07 08:06:48 -07:00
Konstantin Khlopkov af212103b0 feat(cli): show entry id and priority in hermes auth list (#104636) 2026-09-07 08:06:11 -07:00
Teknium 7d50f99fbb fix(gateway): honor privacy policy in busy message origins
Reuse the effective gateway config and shared session platform policy before hashing model-facing metadata. Preserve original routing state and cover enabled/disabled redaction across all busy injection routes.
2026-09-07 07:12:06 -07:00
Teknium 9d576c45e9 docs: describe gateway injection origin context 2026-09-07 07:12:06 -07:00
Teknium 478d772f2c fix(desktop): resolve artifact downloads in their originating session 2026-09-07 07:11:36 -07:00
Teknium b578261584 fix: keep Kanban worker scope out of descendant processes
Carry the existing write fence across Hermes-owned spawn boundaries without
dropping board routing or changing credential policy. Grant dispatcher and
managed tool runtimes explicit task scope; align CLI task mutations with tools.

Verify real shell/CLI descendants, dispatcher startup, and supervised stdio
transport against isolated SQLite boards. This is cooperative runtime scoping,
not OS confinement.

Refs #103974, #104058, #104904
2026-09-07 07:10:28 -07:00
Teknium 258fa9741c fix: retain Kanban decomposition identity and inherit parent tenants 2026-09-07 07:09:59 -07:00
Teknium 9745a7f0f1 fix(terminal): show sudo password prompts for paths and env prefixes 2026-09-07 07:09:30 -07:00
Teknium 2efb8bde58 docs: clarify fallback credential and cooldown behavior 2026-09-07 07:08:25 -07:00
Teknium f845f02df0 docs: clarify fallback credential and cooldown behavior 2026-09-07 07:06:58 -07:00
Teknium 10b0722ce5 docs: explain fenced hosted-room authority recovery
Document actual groups.promote/groups.demote parameters and required
old-writer fencing before confirmation. Demotion is a controlled rejoin
step, not an atomic promote-then-demote handover or log reconciliation.
Clarify replica coverage, confirmation meaning, and lineage readback.

Corrected redo of #104342; its nonexistent groups.peer methods and unsafe
handover ordering are not carried forward.

Fixes #104309
Refs #104904
Co-authored-by: Rohith Pariki <rohithpariki@gmail.com>
2026-09-07 07:04:23 -07:00
Teknium d70fb4e6bd fix(desktop): keep directive hover timers on owned boundaries 2026-09-07 06:58:20 -07:00
Konstantin Khlopkov 45c7388213 fix(desktop): give the composer action pill a transit-safe hide delay 2026-09-07 06:58:20 -07:00
Teknium f17f18cd11 fix(desktop): release Windows app locks at staged promotion
Salvage #101887 after native Actions 34097643131 reproduced WinError 32 using a ready Electron app with its cwd inside the live release. Reuse the existing install-scoped process cleanup before promotion and wait after forced termination, preserving rollback.

Co-authored-by: fangliquan <fangliquan@qq.com>
2026-09-07 06:55:13 -07:00
Jerry Gooch 26ed08c23e fix(desktop): isolate hidden composer selection 2026-09-07 06:46:56 -07:00
Teknium c89f3b8800 fix(delegation): one completion per call by default; queued units no longer stalled; tell the model results land between turns
Three orchestrator failures traced through the Sep 7 gpt-6-astra campaign sessions:

1. delegation.independent_completions (new, default false). #104299 made every
   ungrouped task its own completion message, so a 15-task call woke the
   orchestrator up to 15 times; one chain received 132 notices and answered
   130 of them with "already incorporated". A multi-task call now returns as
   ONE consolidated message unless the flag is on; `group` is inert until then.

2. Queued units were killed before they started. Units of one call share a
   pool slot but the executor was still sized by slots, so with 15 units live
   a new unit queued behind a full pool; the stale monitor's clock ran from
   dispatch, interrupted it at 450 s, and the child exited `interrupted 0.02s`
   when its thread finally came up (13 such lanes in one session). The
   executor now grows to the number of live units and the stall clock arms
   when the runner actually starts.

3. The tool text said "do not wait or poll — just continue" without saying
   that completions are delivered only BETWEEN turns. A model that never ends
   its turn (one 203-minute turn, 717 API calls) never received 40 finished
   results. Tool description, dispatch note and completion header now say to
   finish independent work, give a one-line status, and end the turn.
2026-09-07 06:46:54 -07:00
Teknium 0b3391322c fix: keep desktop provider setup within its selected profile
Remount scope-owned credential state on Applies-to changes and bind onboarding requests to their initiating route. Cancel polling and invalidate late results when setup closes or reopens, without undoing writes already sent.

Co-authored-by: By JTT <29462570+jordan-thirkle@users.noreply.github.com>
2026-09-07 06:44:04 -07:00
Teknium 026e3e84ea fix: reject unavailable desktop profile and session targets 2026-09-07 06:26:22 -07:00
Teknium 12891ea3bd fix(desktop): scope tool changes and commit rebuild ownership together 2026-09-07 06:26:22 -07:00
Teknium 27f32bd50b test: exercise output-cap removal across native and child surfaces 2026-09-07 06:15:43 -07:00
Teknium fd3565deec fix: remove dedicated user-facing output cap controls 2026-09-07 06:15:43 -07:00
Teknium 9a78d5ac2b test(desktop): document and probe reading-position restoration 2026-09-07 06:14:35 -07:00
Teknium 4dcdb5e896 fix(cli): allow pinned installs to disable passive update checks
Adapt the config-only portion of #104347; omit its environment flag and unrelated docs. Explicit update commands remain independent.

Co-authored-by: Rohith Pariki <rohithpariki@gmail.com>
2026-09-07 06:13:16 -07:00
Teknium 5f02693fe0 fix(desktop): reconnect only the active gateway route 2026-09-07 06:12:00 -07:00
Teknium d79575cb89 fix(slack): preserve explicit suspension after timer removal 2026-09-07 06:10:54 -07:00
Teknium 34e512ae58 fix(sessions): remove remaining timer migration and guidance 2026-09-07 06:10:54 -07:00
Teknium 1481a0de96 docs(gateway): describe persistent sessions without reset timers 2026-09-07 06:10:54 -07:00
Teknium 7798241eab fix: retain pending fleet restarts until supervisors recover
Discover systemd targets before stopping old processes, restart even when
there are no gateway PIDs, and require successful scope listings plus active
verification. Pending launchd recovery also retains failures for inaccessible
listings and installed jobs without supervision. Keep existing PID cleanup
intact but before recovery so it cannot kill freshly verified workers.

Slim redo informed by #104274, #104283, and #104285.

Co-authored-by: fangliquanflq <fangliquan@qq.com>
Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>
2026-09-07 06:10:49 -07:00
Teknium f914c9b070 fix(mcp): enforce profile ownership throughout OAuth sessions 2026-09-07 06:10:28 -07:00
Teknium 11ca36edce docs: clarify fallback credential and cooldown behavior 2026-09-07 06:07:16 -07:00
Teknium 57c60f2e0c fix: explain the launchctl registration restriction without inventing KeepAlive 2026-09-07 06:05:51 -07:00
Teknium 33c78d189e docs: describe browser session continuation preflight 2026-09-07 06:00:05 -07:00