Commit Graph

307 Commits

Author SHA1 Message Date
Hyu df64f83e12 fix(telemetry): schedule the trace payload send instead of dropping it
close_trace() called the coroutine TelemetryManager.start_send_task without
awaiting or scheduling it, so every payload closed on that path was silently
dropped and the runtime logged "coroutine ... was never awaited". The only
other caller awaits it correctly, so both call styles stay supported: call the
manager, schedule the returned coroutine on the running loop, and close it with
a debug log when no loop is available.

Regression case added in tests/unit_tests/telemetry/test_trace.py: it fails
before this change (payload never delivered) and passes after.
2026-10-01 02:32:28 +08:00
Hyu 0efc1fb1cc feat(telemetry): trace one inbound event end to end
Execution telemetry already reported window counters. This adds one bounded,
content-free chain per inbound platform event, so a single event can be
followed from its source platform through routing and processing to the
platform API calls it caused.

- telemetry/trace.py: ContextVar trace identity with route and run scopes, and
  a 32-stage bound per chain.
- telemetry/execution.py: keeps at most 64 chains for 120s, decides sampling
  from the observed outcome, and sends one payload per chain keyed by
  query_id = trace_id, so Space fetches a chain by primary identity. Window
  counters are unchanged and remain the source of coverage statistics.
- botmgr / pipelinemgr / orchestrator: bind the trace at the ingress boundary,
  scope routing identity per dispatch, and attach the run identity, so nested
  lanes (event -> route -> pipeline/runner -> platform API) reuse one chain. A
  run reached without an ingress (WebUI debug, service API) owns its own chain.
- space.execution_trace selects off | failures | sampled | all (default
  sampled: failures, WebUI debug runs and every N-th success).

Chains carry only code-defined identifiers (adapter and runner types, route
identity as type:uuid, run id); never message content, tool arguments or
platform user identifiers.
2026-10-01 02:12:44 +08:00
RockChinQ d3e4bd55cd fix: document telemetry opt-out and silence delivery failures (#2618)
* fix: document telemetry opt-out and silence delivery failures

* style: format telemetry debug logging
2026-09-30 22:27:05 +08:00
RockChinQ 30585c8657 refactor: remove beta diagnostics collection and reporting (#2616) 2026-09-30 20:24:35 +08:00
Hyu 5a31ac75fc style(tools): format the sandbox interpreter and skill tool changes with ruff 2026-09-30 18:45:00 +08:00
Hyu 4fc700b7e0 fix(tools): hide register_skill when Cloud sandboxes cannot scan host directories
scan_skill_directory is disabled for Cloud-managed sandboxes, but the
register_skill tool was still advertised to the model whenever a backend was
available, so every call failed closed without a usable explanation. Advertise
register_skill only when the runtime may scan sandbox directories, and keep
activate available in both modes.
2026-09-30 18:44:16 +08:00
Hyu ff3f321120 fix(tools): resolve the sandbox interpreter for workspace file scripts
The workspace file tools (read/write/edit/glob/grep) ran a script through
`python`, which a sandbox built from a host rootfs may not provide: those hosts
ship `python3` only, and a read-only /usr prevents creating a `python` shim
inside the jail. Every file tool then failed with `/bin/sh: 1: python: not
found`. Resolve the interpreter with `command -v python3 || command -v python`,
matching the interpreter the Box service already uses for its own scripts.
2026-09-30 18:44:16 +08:00
RockChinQ 1fde3b4283 fix(certification): align certified sharing and unsigned dedicated admission (#2610)
Integrate certification policy, SDK/Core semantics, and documentation on canonical branch. Resolve duplicated documentation and keep invalid Cloud signatures rejected.
2026-09-29 00:56:18 +08:00
RockChinQ 0468c2be15 Merge pull request #2609 from langbot-app/fix/cloud-unsigned-dedicated-20260928
fix(plugin): allow unsigned Cloud plugins as dedicated
2026-09-28 22:40:02 +08:00
Hyu 6ee9c0a9a3 fix(operation-trace): bind the workspace scope on every off-request write
Cloud runtime refuses unscoped database access and workspace_operation_logs is row-level-secured on the bound Workspace. The background writer, the retention pass and the metadata reads all run outside a request lifetime, so each of them failed and the failure was swallowed by the best-effort handler: enabling tracing recorded nothing at all.

The route wrapper also traces after the handler released its scope, so level resolution has to carry the Workspace itself. Without it the level read back as 0 and the request was dropped before it was even queued.

The startup gate now enumerates the Workspaces through this instance's execution bindings, because a cross-Workspace metadata scan cannot see them under RLS, and it runs after the Workspace service exists. The writer starts with a clean context so it cannot inherit the scope of the request that first enqueued a trace, and a dropped write is reported instead of being logged only at debug.
2026-09-28 22:38:35 +08:00
RockChinQ ce118b4f41 fix(plugin): allow unsigned Cloud plugins on dedicated workers 2026-09-28 14:26:10 +00:00
RockChinQ c384e4715a test(plugin): include stateless certificate model in shared fixtures 2026-09-28 09:14:54 +00:00
RockChinQ b51a448b1e feat: stateless certified shared worker
Implements stateless singleton component model for certified shared Workers, integrating with SDK 0.7.0.
2026-09-28 13:25:40 +08:00
TyperBody b0fab2386e Merge remote-tracking branch 'origin/master' into feat/workspace-operation-traceability 2026-09-28 01:56:03 +08:00
TyperBody 9ecb469d13 feat(operation-trace): lead with the change, fix pipeline extension tracing
The panel answered "who, when, what" poorly: the actual before → after diff
was hidden behind a click, the actor was a muted line, and a whole row went to
the route while duration and hash sat in a permanent right column. The data
already arrives with the page, so the panel now reads top-down in the order an
operator actually looks:

* who and when first, then the action and resource, then the diff spelled out
  inline (long values collapse to their size so a pipeline config does not
  render as two near-identical blobs), with route / method / status / duration
  / evidence hash moved into the expanded diagnostics line;
* the whole card is the expand toggle with a rotating chevron, which removes
  the ambiguity of a small text link whose expanded state looked identical;
* records are bucketed into today / yesterday / dated groups so a long history
  reads as a timeline;
* a "changes only" toggle (reusing the level filter) answers "who changed
  something" in one click -- in the live log 489 of 499 rows are pure views,
  so this is the difference between a haystack and the ten rows that matter.

Tracing fixes found while reading the live log:

* PUT /pipelines/<uuid>/extensions was classified as a plugin config change
  because the generic ('/extensions') rule ran first; it now maps to a
  pipeline-specific action;
* that handler recorded no diff at all, so "modified extension config" could
  never say what changed. It now captures the previous bindings and reports the
  before → after.

Cache: the integrity result is now keyed by (Workspace, listing filters) so
each view reuses its own verification, and a delete invalidates all views for
the Workspace. Fourteen tests cover the projection, the verifier, the cache
lifecycle and the failure modes.
2026-09-28 01:03:02 +08:00
TyperBody ed93e7f1ac perf(operation-trace): project hash columns and make the integrity cache safe
The integrity scan selected whole rows, so a cold pass paged in the
changes/detail payloads and the client fingerprint for up to
MAX_INTEGRITY_SCAN_ROWS rows the verifier never reads. Project only the hash
columns, and add a lightweight verifier so the scan no longer builds a full
display dict per row.

Repair the read cache so it is a latency shield, not a correctness shortcut:
a result computed within INTEGRITY_CACHE_TTL_SECONDS is served from the
per-Workspace cache (opening, refreshing and paging all land inside that
window and pay nothing), while a cache miss re-verifies the whole window. An
incremental scan that skips previously verified ids can never see an edit to
an already-cached row -- exactly the tampering this feature exists to expose.
Verified against a live 414-row log: 50 content edits and 7 re-signed links
are all detected, including an edit to a row verified on a previous pass.

Also fix two correctness gaps and one maintenance bug:
- age-based prune deleted rows without invalidating the cached prefix;
- the boundary baseline is now read only when the history exceeds the scan
  window, which a bounded scan makes the rare case;
- the operation-log retention block had drifted outside the per-binding loop
  in the maintenance task, so only the last discovered Workspace was ever
  pruned while the others grew unbounded.

Tests: scan projection, verifier parity, TTL cache reuse, cache-miss
re-verification, edit to an already-verified row, hash mismatch, chain break
and prune invalidation.
2026-09-27 23:43:51 +08:00
huanghuoguoguo 4f95016998 test(api): align CLI diagnostics with integration gates 2026-09-27 17:46:19 +08:00
huanghuoguoguo 07f3283abf feat(api): enable CLI diagnostics on current master 2026-09-27 17:31:06 +08:00
RockChinQ f488087cc4 Merge remote-tracking branch 'origin/master' into feat/certified-cross-tenant-worker-pool 2026-09-25 13:33:22 +00:00
RockChinQ 300f5825bb fix(plugin): fail closed on incomplete certification records 2026-09-25 13:13:35 +00:00
RockChinQ 9f296bd57e feat(plugin): route certified installs to shared workers 2026-09-25 12:48:55 +00:00
TyperBody c76fd2d7c5 fix(migration): treat an unselected runner id as not_legacy
A saved pipeline may carry the post-migration shape
{'ai': {'runner': {'id': ''}, 'runner_config': {}}} while no runner has been
selected yet. The planner matched the empty id against the certified
'plugin:author/name/component' form, failed, and returned a malformed-id
blocker, so the whole 'migrate all' batch stopped with both pipelines reported
as blocked even though there was no legacy section and nothing to convert.

A blank id with no legacy runner section now reports not_legacy: no work is
needed and no target is synthesized. A blank id that still coexists with a
legacy section remains an explicit invalid_runner_id blocker, because that
ambiguous state must be resolved by the operator rather than guessed.
2026-09-25 20:02:17 +08:00
TyperBody afe700f1d8 fix(plugin): keep certified marketplace packages installable on OSS
The certified-archive admission gate treated any declared certificate it could
not resolve as an untrusted archive and rejected the install with
CERTIFIED_PLUGIN_OSS_FORCE_REQUIRED. OSS ships an empty
plugin.certification.trusted_public_keys ring and the marketplace signs every
package with its own issuer key, so all certified marketplace packages (for
example langbot-team/RunnerDemo and langbot-team/LocalAgent) failed at the
'validating plugin package' step before artifact storage.

Admission now distinguishes an unresolvable declaration from a configured trust
decision that fails:

- record certificate_id only when the key_id is actually present in the
  configured ring, so an empty ring yields an unresolvable declaration;
- OSS degrades an unresolvable declaration to the existing oss_dev dedicated
  profile with CERTIFIED_PLUGIN_OSS_UNTRUSTED_DEDICATED instead of blocking;
- a resolvable declaration that still fails keeps requiring the explicit
  administrator force (CERTIFIED_PLUGIN_OSS_FORCE_REQUIRED);
- Cloud stays fail-closed and rejects before storage.

No shared-runtime privilege is granted when the issuer is not trusted, so this
withholds isolation rather than escalating it.
2026-09-25 19:32:54 +08:00
Type_rBody f09c8a8bed Merge pull request #2549 from langbot-app/experiment/in-process-assistant
feat(web): add an in-process workspace assistant
2026-09-25 13:56:30 +08:00
RockChinQ eb9261fae1 fix(migration): pin certified runner packages 2026-09-25 05:42:34 +00:00
TyperBody f316958619 Merge remote-tracking branch 'origin/master' into experiment/in-process-assistant 2026-09-25 12:46:34 +08:00
RockChinQ 9b589a8f08 merge: integrate 4.11 into master 2026-09-24 02:01:00 +08:00
Martin 874eb6600c fix(wecombot): stop empty bubbles and premature stream close on blank final chunks (#2561)
* fix(pipeline): stop emitting empty final assistant messages

An empty final streaming chunk was appended as an empty message chain when no sandbox outbox attachment was present, so platforms received an empty reply. Only append the chain when attachments were actually collected, and gate the "Call ..." tool notice behind output.misc.track-function-calls so it no longer becomes the final chunk of a stream.

* fix(wecombot): do not close stream on a blank final snapshot

A blank final snapshot closed the WeCom stream with an empty bubble and pushed the real answer into a separate reply_text message. Skip blank final snapshots and keep the session open so the following non-blank chunk can finalize it. Covered by new regression tests.
2026-09-23 18:28:11 +08:00
RockChinQ ee90ec61d0 fix(agent): preserve configured prompts in debug runs
[verified] Independently reviewed debug-only Query initialization, explicit-empty prompt semantics, scoped Runner schema/config, trusted execution metadata and MCP projection. Focused RED/GREEN and 249 regression tests pass. No shared orchestration or nondebug behavior changes.
2026-09-21 19:18:30 +00:00
RockChinQ 5d9684731e merge(4.11): integrate master marketplace updates preserving Runner lifecycle 2026-09-21 16:58:35 +00:00
RockChinQ 27871e4363 merge: integrate master certification and document identity fixes into 4.11 2026-09-21 10:55:40 +00:00
RockChinQ 381bb3f852 fix(rag): retain interrupted ingestion state and engine identity 2026-09-21 07:47:31 +00:00
RockChinQ 52f5699533 fix(plugin): honor requested marketplace version (#2555) 2026-09-20 23:59:50 +08:00
RockChinQ 942a302808 fix(plugin): load certification key ring from env (#2554) 2026-09-20 22:22:32 +08:00
RockChinQ 20a04a77bf feat(plugin): enforce certified archive admission (#2553)
* feat(plugin): add certified admission policy

* feat(plugin): enforce certified archive admission

* chore(plugin): pin certified SDK beta

* fix(plugin): consume SDK beta 5

* style(plugin): format certification admission
2026-09-20 18:54:45 +08:00
fdc310 e7ad051cf6 Merge remote-tracking branch 'origin/dev/4.11.x' into dev/4.11.x
# Conflicts:
#	uv.lock
#	web/src/i18n/locales/en-US.ts
#	web/src/i18n/locales/ja-JP.ts
#	web/src/i18n/locales/zh-Hans.ts
#	web/src/i18n/locales/zh-Hant.ts
2026-09-19 11:00:45 +08:00
fdc310 cc8a0ec847 feat: simplify resource setup and detail guides 2026-09-19 02:39:35 +08:00
RockChinQ 79cac0c6a3 fix(reasoning): apply explicit per-call levels without runner config caching 2026-09-19 00:05:49 +08:00
RockChinQ 60606e1997 fix(migration): improve runner migration and plugin installation feedback 2026-09-18 13:10:32 +08:00
RockChinQ e77acfa3ab fix(box): align integration tests with runner-owned bindings 2026-09-18 01:07:43 +08:00
RockChinQ a6ac25cf84 feat(agent): add task-oriented run logs and execution details 2026-09-18 00:59:17 +08:00
RockChinQ b264d46d77 feat: delegate sandbox policy to runners and simplify pipeline migration 2026-09-17 23:05:27 +08:00
RockChinQ 8c119bc4b6 feat: add verified manual pipeline migration for plugin runners 2026-09-16 18:13:11 +00:00
huanghuoguoguo 0be53c6ef4 feat(assistant): improve chat feedback and model selection 2026-09-16 22:37:02 +08:00
huanghuoguoguo 48140fbfd4 fix(assistant): align resource tools with application services 2026-09-16 22:37:02 +08:00
huanghuoguoguo e82d71029e feat(assistant): prototype in-process workspace assistant 2026-09-16 22:37:02 +08:00
RockChinQ 273b1ea3cf Merge master into dev/4.11.x and preserve plugin runner architecture
Reconcile migration branches without rewriting published revisions; retain additive Codex, monitoring, provider and platform fixes. Keep dynamic runner schemas and Host ownership, restore compatibility regressions, and preserve safe model-test error handling.
2026-09-16 08:13:07 +00:00
dadachann 03854b5d33 fix(telemetry): require acknowledged adapter evidence and prepare beta.3 2026-09-15 13:23:12 +00:00
Hyu f7cfb23480 feat: collect beta-only adapter acceptance evidence 2026-09-15 20:40:03 +08:00
BiFangKNT 1143d6a5ae feat(storage): media content-addressable cache and monitoring base64 externalization
- Add MediaCache using xxHash3-128 (with sha256 fallback) content-addressable storage
- Externalize message chain image payloads before recording monitoring and discarded messages
- Strip base64 payloads to null in SQLite monitoring_messages, dropping row size from megabytes to hundreds of bytes
- Add GET /api/v1/files/media/<filename> route with immutable HTTP cache headers to serve cached media
- Integrate age-based retention (default 30 days) and configurable disk quota with MaintenanceService cleanup loop
- Add defensive sanitizer in MonitoringService.record_message against oversized raw base64 payloads
- Add comprehensive unit tests and end-to-end verification covering CAS deduplication, route serving, and LRU pruning
2026-09-15 17:58:23 +08:00