Commit Graph

143 Commits

Author SHA1 Message Date
程序员阿江-Relakkes 8ddf67390d fix(agent-teams): enforce task dependencies in approved teams (#1459)
An approved team handed every member its instructions at the same moment,
so members whose tasks depended on unfinished work started anyway: the
second and third layers of a plan ran before the first, a member could mark
a blocked task in progress, and results only ever went to the lead. The
official CLI states dependencies in tool prompts and nothing more, so the
plan the user approved was not what ran.

- A member whose tasks all wait on other tasks gets its instructions only
  once one of them is ready. What the lead or a teammate sends it before
  that waits in its inbox and arrives with the instructions; only the user
  writing to it, or a shutdown request, reaches it earlier. This survives a
  Stop and a server restart.
- TaskUpdate refuses a teammate that starts or completes a task while a
  task it is blocked by is unfinished. The lead is not held to it.
- Each member is told who waits on its tasks and to send them its result
  before completing, so a dependent member starts with that result in
  hand. A member that starts without one is told whose is missing.
- A member that exits after approving a shutdown request is no longer
  recorded as failed, and the lead gets no failure notice for it. The
  shutdown-approval schema keeps leaving out the desktop backend on
  purpose, now documented and tested.
- TeamPlan tells the lead that a dependent member's prompt is delivered
  when its dependencies are done.
2026-10-06 01:51:35 +08:00
程序员阿江-Relakkes 8a94f09663 docs(readme): make Chinese the default README and keep only the film (#1436)
- README.md is now Chinese; the English README moves to README.en.md.
- Drop the eight-screenshot grid and the Agent Teams loop; the film cover
  remains the single visual. Remove the now-unused thumbnails.
- Point PR triage, change policy, and the docs check at the new file names.
2026-10-04 03:12:59 +08:00
程序员阿江-Relakkes 795ff9d4df feat(desktop): add safe data directory migration (#1433) 2026-10-04 00:39:20 +08:00
程序员阿江-Relakkes 66f9938f36 fix(sessions): stop full transcript parses on every session lookup (#1430)
Every session route resolves its transcript first, and that lookup parsed
the whole file to rank candidates even when only one file matched. The
desktop pages a long session's history request by request, so reopening
it cost one full parse per page and grew quadratically with file size.

Skip the content check when a single file matches, and stop a multi-file
check at the first conversation record. Ranking and API responses are
unchanged.
2026-10-03 21:58:11 +08:00
程序员阿江-Relakkes fd42b0ca05 fix(agent-teams): keep long-running teams recoverable (#1426)
Long Agent Teams runs lost members for good: a truncated provider stream
ended a member's turn with nobody to wake it, the desktop Stop button and
every lead restart killed all members and marked the plan interrupted,
mail sent to a stopped member landed in an inbox nothing read, and a lead
kept inside one long turn never saw member reports. Aligned with the
official CLI 2.1.284 and verified with DeepSeek Flash through a
fault-injecting proxy.

Stream recovery
- Re-send a stream that breaks before any tool ran (proxy truncation,
  transport errors), with the existing retry budget and backoff; the
  desktop drops the discarded attempt's tool cards and todo update.

Desktop team runtime (teamPlanRuntime)
- The server supervises members: a stopped member restarts from its own
  transcript when messaged; transient failures continue automatically
  (15s/45s/2m/5m/10m) and only exhausted retries reach the lead; ready
  dependent tasks wake their owner; a crash-loop guard ignores user stops.
- Stop pauses the team instead of ending it; the lead's next user message
  is followed by a notice listing the stopped members and their open
  tasks. Lead restarts (model/permission switch, crash) keep members;
  server restarts re-own the team. Teams end on /clear or session delete.
- Approving a plan no longer races a concurrent plan read into
  "Launch ownership was lost".

Mailbox and messaging
- Atomic inbox writes, identity-based read marking, read history files,
  idle notifications with result/failureReason, and write failures
  reported instead of "Message sent". External builds keep the official
  between-turn delivery to the lead.
- SendMessage resumes non-running in-process teammates from their
  transcript, notes restarting desktop members, queues mail for members
  of a plan awaiting approval, and rejects unknown names.

CLI in-process teammates
- Compaction uses the teammate's own controller and real history and no
  longer kills it on error; failed turns are classified and continued;
  the turn-end mailbox drains as one batch; one durable transcript per
  teammate.

Lead behaviour
- An unmet /goal ends the lead turn while members work, so member reports
  arrive; WaitSessions on own team members returns immediately.

Desktop UI
- Member states for stopped, auto-retrying and failed, with reason,
  countdown and recovery hint in all five locales.

Tests and tooling
- Regression tests for every behaviour above; module mocks in four test
  files are restored after use so the single-process coverage run is not
  polluted; the desktop smoke asserts the new Stop semantics.
2026-10-03 17:07:30 +08:00
程序员阿江(Relakkes) 4097fc6506 feat(market): curated skills catalog with categories and redesigned detail
Open the skills market on a bundled catalog of 398 curated ClawHub and
SkillHub skills in 13 categories instead of querying both registries live.
Live search stays available as an explicit "search all markets" scope
whose results are marked as not curated.

- Server: catalog scope (default) with category filter, filtering before
  pagination and batched install state; catalog metadata overlaid on live
  detail; per-scanner ClawHub reports, changelog and page URL; manual
  catalog refresh script.
- Pin ClawHub reads and installs to the card's owner so a same-slug copy
  by another author is never shown or installed in its place.
- Desktop: category chips, curated cards with tags, locale-aware summaries,
  detail page with stats, security report, changelog, capability panel and
  triggers; install confirmation requires acknowledgement for unaudited or
  flagged skills.
- Docs: rewrite the skills market section and refresh screenshots.
2026-10-02 02:25:26 +08:00
程序员阿江(Relakkes) e81890cf89 chore: integrate main updates into workspace document preview 2026-09-30 02:37:25 +08:00
程序员阿江(Relakkes) 6bab6fbe97 feat(desktop): preview documents in the workspace and images in chat
Documents the agent writes open in the workspace panel instead of another
application, and local images the agent mentions show up in the conversation.

Workspace preview
- PDF (pdf.js with its own layout and text layer), Word (docx-preview inside a
  scripts-disabled sandboxed iframe) and Excel (SheetJS; .xlsx, .xlsm, .xls) open
  in the side panel with zoom and fit, per-file scroll/zoom/sheet memory, and a
  refresh when the agent rewrites the file. The engines load lazily.
- Bytes come from a new GET /api/sessions/:id/workspace/raw route, with an
  extension allowlist, size caps, the workspace boundary and canonical-path
  checks. The file endpoint returns metadata and a version for documents. The
  client fetches with the bearer credential, so it works in Electron, LAN H5 and
  remote access alike.
- Chat links, output cards and the change card open pdf/docx/xlsx in the
  workspace; documents outside the workdir still go to the system application.
- Image viewer with fit, zoom and pan, and "open in system app".

Chat images
- Markdown images outside the workdir, at ~/, C:\ and file:// paths render, open
  in the viewer, and offer "open original" (pictures only).
- Images returned by tools such as Read appear as thumbnails under the call.

Hardening found in review
- previewFsUrl escapes each path segment; a double-escaped %2e%2e used to leave
  /preview-fs/<session>/.
- The CORS, API timing and remote-access header decorators set headers in place.
  Rebuilding the response buffered whole files in memory and dropped
  Content-Length.
- The engine owns the pdf.js worker, so closing one document no longer fails the
  next open.
- Office archives are inflated in steps to check their real sizes, not the sizes
  they declare.
- A viewer that fails to load stays in its panel instead of taking the window down.

Adds pdfjs-dist, docx-preview, xlsx (SheetJS 0.20.3 tarball) and fflate as
renderer dev dependencies; Vite bundles them.

Refs #1397
2026-09-30 01:53:47 +08:00
程序员阿江(Relakkes) c5347830f4 Merge branch 'worktree-20260929-feature-tab-notify-support' 2026-09-29 17:13:18 +08:00
程序员阿江(Relakkes) 591e84acd6 feat(desktop): highlight sessions waiting for attention 2026-09-29 17:06:59 +08:00
程序员阿江(Relakkes) 58662a0c4e test(coverage): exclude desktop test helpers from changed lines 2026-09-29 16:48:42 +08:00
程序员阿江(Relakkes) 417ca5f283 fix(agent-teams): dismiss approved configuration and preserve runtime controls 2026-09-27 23:47:38 +08:00
程序员阿江(Relakkes) 2cac7c471b feat(agent-teams): add human review and per-member runtime selection 2026-09-25 17:47:39 +08:00
程序员阿江(Relakkes) 7c7ce7d6b9 feat(desktop): add independent session collaboration 2026-09-21 01:16:27 +08:00
程序员阿江(Relakkes) 27f660fe5c fix(perf): bound large session history and tracing resource usage
Page transcript and trace reads, bound UI caches and retained task records,
and replace full-file background polling with incremental projections.
Preserve recovery and ownership semantics across pages and cancel stale work.
2026-09-19 20:29:20 +08:00
程序员阿江(Relakkes) fe10efb65f feat(desktop): add the OpenCode Go subscription provider
OpenCode Go binds the wire format to the URL path and translates nothing
between formats, so one provider record serves /chat/completions, /messages
and /responses depending on the model, each accepting a different credential
header. A record carries only one apiFormat, so presets can now declare
ordered per-model prefix rules (modelApiFormats) and the proxy resolves the
effective format from the request body. Only the exceptions are listed;
anything unmatched keeps the provider's format, which is the endpoint with the
broadest compatibility. A preset with rules is authoritative for apiFormat,
because a value written by a cc-switch import or the edit form would otherwise
silently disable every rule and point the CLI straight at the upstream.

The gateway also rejects any request without a stable per-conversation
x-opencode-session, so presets can declare upstreamHeaders with $SESSION_ID
and $VERSION placeholders. The id is the one the CLI already sends; it is
redacted in traces the same way the credential is, since it also names the
local transcript files.

Title generation builds its own upstream request and bypassed all of the
above, which left AI titles failing for every provider that needs local
request handling; it now goes through the same proxy the CLI uses.

Verified against the live gateway: glm/kimi reach /chat/completions,
minimax/qwen/union-alpha reach /messages, grok/gpt reach /responses, each
with the credential that endpoint accepts.
2026-09-17 22:00:02 +08:00
程序员阿江(Relakkes) f2bfaab50f docs(readme): make English the default README
README.md carried the Chinese version while README.en.md held the English one,
so the GitHub landing page opened in Chinese. Swap them: README.md is now
English and the Chinese version lives in README.zh-CN.md, with both language
switchers pointing at the new paths.
2026-09-17 16:51:56 +08:00
程序员阿江(Relakkes) f7fcbc2d8a merge: integrate local main with skills and connectors 2026-09-14 10:14:37 +08:00
程序员阿江(Relakkes) c4a4178f18 feat(desktop): unify skills and connectors with managed installation and mentions 2026-09-14 10:14:15 +08:00
程序员阿江(Relakkes) 9fce822df3 feat: add secure ngrok remote access with device pairing 2026-09-13 23:28:30 +08:00
程序员阿江(Relakkes) 0bcbfe6921 fix(computer-use): enforce cursor regression and package gates
Route native-only changes through macOS checks and verify relocated cursor resources in final packages. Reject resources that escape the app and exercise visible click feedback against a disposable native receiver.

Connect the regressions to required checks and capture shell fixture output through temporary files.
2026-09-11 15:53:22 +08:00
程序员阿江(Relakkes) 17f194df40 fix(proxy): preserve protocol completion and output budget contracts 2026-09-11 14:22:50 +08:00
程序员阿江(Relakkes) 74f87a27e4 revert(session): remove protocol-based session restrictions
Revert efe5cae19 so existing sessions remain usable and models can be
switched without protocol admission checks. Retain the additive index
schema for already-upgraded caches and rebuild their summaries.
2026-09-10 14:00:50 +08:00
程序员阿江(Relakkes) 56c6a9aa8e feat(computer-use): align native app automation with Codex
Add a persistent isolated JavaScript worker for native app actions and batch
known operations without a model round trip between each input. Preserve
per-cell context, native errors, screenshot coordinates, and image types.

Align macOS gesture, key, inventory, capture, scroll, and clipboard behavior;
include a signed native receiver fixture and compiled sidecar regression tests.
Keep the Windows pixel route and fix cancellation with session-owned mouse
cleanup, lock revalidation, and portable signing-fixture tests.
2026-09-10 03:34:39 +08:00
程序员阿江(Relakkes) efe5cae19e fix(session): lock model switching to the session API protocol 2026-09-09 23:05:33 +08:00
程序员阿江(Relakkes) cfc15ecbf6 Merge remote-tracking branch 'origin/main' into fix/pr-1301-maintainer 2026-09-07 23:39:51 +08:00
程序员阿江(Relakkes) 5f7c719c96 fix(ci): preserve coverage logs across reporter cleanup 2026-09-07 23:30:57 +08:00
程序员阿江(Relakkes) 4eb7ca42ac fix(ci): install native sidecar workspace dependencies 2026-09-07 23:27:37 +08:00
程序员阿江(Relakkes) bd5689dfad fix(ci): run macOS Swift checks on a required macOS lane 2026-09-07 23:23:32 +08:00
程序员阿江(Relakkes) c6146501cc fix(ci): capture coverage reports through regular file descriptors 2026-09-07 23:20:34 +08:00
程序员阿江(Relakkes) 8a4be0dee7 fix(ci): make runtime validation portable to Linux 2026-09-07 21:56:11 +08:00
程序员阿江(Relakkes) 9e4f83bbe3 test: stabilize PR validation and install server adapter dependencies 2026-09-07 21:41:31 +08:00
程序员阿江(Relakkes) b1b5a6d678 docs: switch community to WeCom and make Chinese README default
- Add 新功能支持 issue template, refine bug/question templates with a
  pointer to the user group
- Replace the Feishu user group QR with the WeChat Work group QR in both
  READMEs, include contact info for enterprise/Agent customization
- Make the Chinese README the default README.md, keep the English one as
  README.en.md, update language badges on both
- Update PR change policy, pr-triage docs set and site docs check for the
  renamed README files

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-06 15:57:41 +08:00
程序员阿江(Relakkes) 633320e9f2 fix(release): allow explicitly skipping Windows signing 2026-09-06 11:46:22 +08:00
程序员阿江(Relakkes) 783eed6be6 fix(release): reuse the prepared macOS signing keychain 2026-09-06 04:17:06 +08:00
程序员阿江(Relakkes) 8d8169ea70 fix(models): add GLM 5.3 reasoning capabilities (#1283) 2026-09-01 21:56:49 +08:00
程序员阿江(Relakkes) 0fd6904a95 merge: integrate Computer Use into local main 2026-09-01 20:14:24 +08:00
程序员阿江(Relakkes) 8a37865536 fix(computer-use): harden native macOS automation runtime 2026-09-01 20:06:25 +08:00
程序员阿江(Relakkes) 7858c46bd2 fix(models): preserve GPT relay reasoning effort (#1238) 2026-08-26 19:17:24 +08:00
Relakkes Yang a8cb0c509d test(policy): budget the full dead-import sweep 2026-08-23 19:55:11 +08:00
Relakkes Yang 5fafabfca1 fix(release): isolate draft validation from published assets 2026-08-23 19:36:21 +08:00
Relakkes Yang 417cfdfd69 fix(release): preserve Windows updater config before signing 2026-08-23 19:17:29 +08:00
Relakkes Yang c7a90f2cd1 fix(release): separate SignPath test and release policies 2026-08-23 18:55:10 +08:00
程序员阿江(Relakkes) dd4edc0efe merge: bring main into the computer-use worktree
main is 87 commits ahead and carries a large amount of fixed behaviour this
branch should not be re-deciding. The rule applied throughout: this worktree
owns Computer Use, main owns everything else.

Only 12 files were touched on both sides, and Git merged all of them without
reporting a conflict — but two of those silent merges were wrong, and neither
was visible until the checks ran.

`desktop/src/api/client.ts` ended up with two `apiGetBlob` implementations.
Both sides had independently hit the same problem (an `<img src>` pointed at an
API endpoint is a cross-origin subresource, so it carries no Authorization
header and the server's fetch-metadata policy refuses it) and both had written
the same fix. Git saw two additions in different places and kept both, which
does not even compile. main's version survives: it builds its headers through
the shared `buildHeaders()` rather than assembling them inline, so it inherits
whatever main adds there later.

`src/server/api/computer-use.ts` still imported `runtime/mac_helper.py` and
`runtime/requirements.txt` as compile-time text, both deleted on this branch.
Nothing at runtime referenced them, which is why the deletion looked clean; the
bundler resolves those imports when the server module is loaded, so the failure
surfaced only when the tests actually imported it. That path is now Windows-only
in the same sense the rest of the Python bridge is, and it also ships
`win_cursor_badge.py`, which the badge needs because it runs as its own process.

`computer-use-requirements.test.ts` drops its darwin half for the same reason —
the pins it guards still matter, but only one requirements file is left.

Verified: server 3869 tests / 331 files, desktop 4612 tests / 319 files
(lint + tsc + build), Swift 272 XCTest + 14 Swift Testing, Python 25.

Claude-Session: https://claude.ai/code/session_015j1yxxaoonyAS2iZ7qGnTS
2026-08-23 18:39:47 +08:00
Relakkes Yang af4454f38a feat(release): sign Windows artifacts with SignPath 2026-08-23 18:14:52 +08:00
程序员阿江(Relakkes) 27c31bdc15 fix(models): preserve GPT relay reasoning effort (#1238) 2026-08-23 17:21:53 +08:00
Relakkes Yang fef789f5a8 fix(quality-gate): stabilize Windows validation 2026-08-22 16:06:17 +08:00
程序员阿江(Relakkes) a0afcc7efa feat(desktop): add custom project display names 2026-08-11 02:38:55 +08:00
程序员阿江(Relakkes) ffa2b59105 docs(agents): reserve agent-browser for its committed lanes
The instruction files told every coding agent to reach for agent-browser
whenever a change needed browser-level evidence: copilot-instructions
listed "E2E or agent-browser smoke" as the remedy for cross-boundary
flows, and both contributing guides repeated it. That wording outlived
the tool. With the agent-browser skill uninstalled, agents still parsed
those lines as a recommendation and went looking for the binary instead
of using the browser skill that is actually installed.

Deleting the references would have made the docs wrong. agent-browser is
still a real dependency: check:desktop-ui-smoke spawns it on Linux CI,
and seven maintainer-run e2e scripts under desktop/scripts drive it
directly. It cannot be swapped for ego-browser either — ego lite is a
macOS-only GUI app with no headless mode and a one-time interactive
onboarding, so it cannot run on ubuntu-latest at all.

So the lanes keep the binary and the prose loses the recommendation.
agent-browser is now described as an implementation detail of those two
call sites, and ad-hoc browser work — manual verification, screenshots,
exploratory UI checks — is pointed at the ego-browser skill.

The quality contract asserted the old string, so it would have failed
closed on the reworded line. It now pins the replacement plus the new
routing rule; flipping either sentence turns the test red.
2026-08-09 19:03:50 +08:00
程序员阿江(Relakkes) 4314345b6c fix(quality-gate): drive the ProseMirror composer in the desktop smoke
The smoke waited on `textarea`, but the composer became a ProseMirror
contenteditable (MentionComposer) some time ago, so the selector could
never match. The lane hung for its full 30s timeout and failed on every
run — the screenshot it captured on the way out showed the app rendered
and idle, which is what makes this easy to misread as a UI break.

Target `[data-composer-editor]`, the attribute the editor puts on its
editable node and the same hook composerTestUtils already drives.
2026-08-09 02:47:12 +08:00