Commit Graph

416 Commits

Author SHA1 Message Date
Teknium
56f8655bc6 chore: map simonvanlaak contributor email 2026-08-13 11:12:19 -07:00
Teknium
35720fbc44 chore: map contributor email 2026-08-13 11:12:05 -07:00
Teknium
0818086c50 fix(kanban): backfill legacy gateway notify subs to notify+wake on first migration
Before delivery_mode existed the notifier woke unconditionally when the task
carried a session_id — pre-existing gateway subscriptions had de facto active
wake. The column's 'notify' default alone would silently disable that on
upgrade. Backfill gateway rows to notify+wake on first-add only (tui stays
notify); explicit user downgrades are never overwritten by re-migration.
Sabotage-verified regression tests included.
2026-08-13 10:47:40 -07:00
kshitij
4498daf00f chore: map contributor email hustwkr@users.noreply.github.com
Bare noreply form (no +<id> prefix) needs an explicit mapping file
for check-attribution CI.
2026-08-13 22:44:23 +05:30
uperLu
4901564694 chore: map contributor email 2026-08-13 22:07:32 +05:30
Teknium
f84ecd3607 chore: map zhjay@stu.xjtu.edu.cn -> ZHJay for contributor attribution
(cherry picked from commit 06899b54437f7bb36b126d96a1e740afeb34d855)
2026-08-12 22:38:17 -07:00
Teknium
7d0b5a332c chore: AUTHOR_MAP for zhouou6@users.noreply.github.com → shali10 2026-08-12 19:43:41 -07:00
Teknium
ea6f4e33c3 chore(contributors): map ernst-bablick email for PR #69609 salvage 2026-08-12 19:43:29 -07:00
Hermes Agent
12a7a46578 chore: map hermes-agent@nousresearch.com contributor email 2026-08-12 19:43:22 -07:00
Teknium
c89ca9c4bf chore(attribution): map dnethusahan.h05@gmail.com -> deaneeth (PR #64317 salvage) 2026-08-12 18:38:25 -07:00
Teknium
e3215cfbdc chore: map hfsearcy@gmail.com -> hsearcy for contributor attribution 2026-08-12 17:07:51 -07:00
Teknium
d48c5f29ee Merge pull request #84878 from NousResearch/salv/62319
fix(desktop): allow remote gateway token storage on keyring-less Linux (salvage #62319)
2026-08-12 16:50:44 -07:00
Teknium
9994bc9ec9 fix(gateway): enforce post-auth normalized reaction observer
Builds on Paolo Antinori's #68431 salvage for #64176. Move plugin dispatch behind the profile-scoped runner authorization boundary, fail closed on malformed reaction identities, preserve observer registration across Telegram app rebuilds, and document the deliberately observer-only contract.

Co-authored-by: Paolo Antinori <pantinor@redhat.com>
2026-08-12 16:42:28 -07:00
Teknium
33840149d0 chore: map voice contributor attribution 2026-08-12 16:42:07 -07:00
Teknium
98c3edbd8b chore: map github.commits@widow.cc -> Zeus-Deus for contributor attribution 2026-08-12 16:40:20 -07:00
Teknium
d409f67485 feat(platforms): add typed plugin send paths
Route plugin target parsing, validation, and host-driven delivery through PlatformEntry across CLI and cron while preserving the host-only send_message policy.
2026-08-12 16:27:19 -07:00
Teknium
7a5062fbcd feat(plugins): add runtime-backed plugin Doctor
Validate plugin manifests, imports, hook signatures, and runtime registrations through the real plugin loader in an isolated temporary home.
2026-08-12 16:27:07 -07:00
Teknium
5265409012 docs(plugins): document config and state ownership 2026-08-12 16:26:43 -07:00
Teknium
f6aaff4646 chore(contributors): map Magnus Hedemark 2026-08-12 16:25:20 -07:00
kshitij
1d3d021282 chore: map 1759158233@qq.com -> wanquanY for contributor attribution 2026-08-13 01:34:00 +05:30
rob-maron
7113a69248 fix(models_dev): map meta-ai provider to models.dev 'meta' id (salvage #81418) (#84679)
* fix(models_dev): map meta-ai provider to models.dev 'meta' id

Muse Spark models (muse-spark-1.1/1.2/-contributor) are served via the Meta
Model API and reverse-map from api.meta.ai to the Hermes provider id 'meta-ai'.
models.dev keys the same models under the provider id 'meta'.

lookup_models_dev_context() / _get_provider_models() resolve the models.dev id
strictly via PROVIDER_TO_MODELS_DEV.get(provider) (no raw-id fallback, unlike
get_model_info()), so an unmapped 'meta-ai' missed entirely and context fell
back to the generic 256K default instead of the true ~1M window. Add the
meta-ai->meta mapping (plus a defensive meta->meta) so context and pricing
resolve from models.dev: 1.1=1,000,000; 1.2 & -contributor=1,048,576.

* add contributor email

---------

Co-authored-by: Beto de Paola <betodepaola@meta.com>
2026-08-12 14:42:00 -04:00
kshitij
a5170af4a8 chore: map hermes-agent@nous.local commit identity to @C-EXCITE-STUDIO
Salvaged PR #83678's commit is authored under a generic local agent
identity with no linked GitHub account; map it to the PR opener for
release attribution (same pattern as hermes-agent@users.noreply.local).
2026-08-12 13:58:26 +05:30
elisam0
17688f994e feat: add Nemotron Lightning to reasoning timeout (#83982) 2026-08-12 08:21:09 +00:00
kshitij
a2fbe745b4 chore: map contributor email cmoiccool 2026-08-12 13:20:38 +05:30
kshitij
936dd7346f chore: add landaun to contributor email map for #83906 salvage 2026-08-11 20:37:06 +05:30
Teknium
2cdb30a474 chore: contributor email mapping for salvaged commit 2026-08-10 19:16:59 -07:00
Teknium
0d21eb82b5 chore: contributor email mapping for salvaged commit 2026-08-10 18:04:59 -07:00
Michael Gannotti
373631bea1 fix(dashboard): raise fd soft limit + replace iterdir with scandir to stop fd leak (#81547)
Two-part fix for the dashboard fd exhaustion reported in #81547:

1. Raise RLIMIT_NOFILE soft limit on startup (before uvicorn binds).
   macOS defaults to 256 for LaunchAgent processes — too tight for the
   dashboard which opens 3 fds (db+wal+shm) per SessionDB per request
   across all profiles. After days of polling the soft limit exhausts
   and every os.listdir/open raises OSError [Errno 24]. The helper raises
   to the hard limit (or minimum 4096), matching the reporter's ulimit
   workaround. No-op on Windows (no resource module).

2. Replace bare Path.iterdir() with context-managed os.scandir() in four
   dashboard hot paths: _fallback_profile_dicts, file manager list,
   checkpoint listing, and plugin discovery. iterdir() returns a
   generator that holds an open directory fd until fully consumed; if
   an exception interrupts iteration the fd leaks. os.scandir() is an
   explicit context manager that guarantees close on exit, following
   the same idiom already used in /api/fs/list.

Tests: 6 passed, 3 skipped (resource-module tests skip on Windows).
2026-08-10 18:04:59 -07:00
Teknium
1485a4ac2b chore: contributor email mappings for salvaged commits 2026-08-10 17:02:56 -07:00
kshitij
b50e27e6d7 Merge pull request #83301 from kshitijk4poor/chore/author-map-angriff36
chore: add Angriff36 to AUTHOR_MAP for PR #29543 salvage
2026-08-11 02:24:30 +05:30
Jakub Wolniewicz
4317c92751 chore(contributors): map Nikita Barkov 2026-08-10 12:43:46 -07:00
Teknium
39a234b133 fix(browser): gate browser_exec on terminal surface; pin schema helpers digest
Follow-ups on the salvaged Browser Use CLI integration (PR #66476):

- browser_exec runs model-written Python on the host. Strip it at
  tool-definition time for sessions whose resolved toolsets exclude
  'terminal' so terminal-less surfaces (locked-down messaging configs)
  don't silently regain host code execution through the browser toolset.
  Session-level gate in model_tools, not a check_fn (check_fn results are
  TTL-cached process-wide across sessions).
- Replace the live 'browser-use skill' schema fetch with a pinned helpers
  digest: no third-party version-drifting text in the prompt, byte-stable
  schema across machines. A/B benchmarked (108 runs, opus-4.8 + kimi-k3,
  6 multi-step web tasks x 3 arms x 3 reps): pinned digest matches the
  full skill dump 36/36 vs 36/36 at ~equal tokens; both cut total task
  tokens ~60% vs the legacy browser_* toolset.
- Docs note for the terminal gate; contributor mapping for salvage.
2026-08-10 10:45:44 -07:00
kshitij
8c13c99189 chore: add Angriff36 to AUTHOR_MAP for PR #29543 salvage 2026-08-10 21:21:41 +05:30
teknium1
0514d67fa6 chore: map contributor email for salvaged commit 2026-08-10 00:23:41 -07:00
StanleyStetson
4d79bd3d02 fix(gateway): reject boolean ordinals and bare confirm_truncate on prompt.submit
Two hardening guards extracted from #82766 by @StanleyStetson:

- bool is an int subclass, so a JSON `true` in truncate_before_user_ordinal
  coerced via int() to ordinal 1 and aimed a CONFIRMED rewind at the second
  user turn — the same silent-loss class as #82756. Reject with 4004.
- confirm_truncate with no truncation target is leaked client rewind state
  on an ordinary submit; fail fast with 4004 instead of silently ignoring
  the flag, so the corrupted client state is surfaced.

Part of the composite fix for #82756.
2026-08-10 11:01:15 +05:30
joaomarcos
abd85a94bc fix(gateway): keep the personality pivot out of the truncate ordinal space (#82756)
`truncate_before_user_ordinal` is an index into the list of *real* user
turns. The gateway builds that list with `role == "user" and not
display_kind`, and `test_prompt_submit_truncate_ordinal_skips_display_kind_rows`
already pins why: "Without the filter, a trailing marker shifts the ordinal
so the wrong message is targeted for truncation."

`_apply_personality_to_session` broke that invariant at the producer. Its
pivot marker rides as `role=user` — deliberately, so strict
OpenAI-compatible providers accept it mid-conversation (the same reason
`_append_model_switch_marker` does) — but unlike the model-switch marker it
carried no `display_kind`. The gateway therefore counted it as a real user
turn while no client ever renders it as one.

After a personality change the two sides address different lists: every
later rewind/edit/regenerate resolves one slot too early, and
`replace_messages()` hard-DELETEs the extra span. That is the reported
signature — an in-range, valid ordinal, `confirm_truncate: true`, and a cut
that moved backwards with no user rewind action.

Tag the pivot like the model-switch marker, and teach the desktop to
project the kind as a timeline row so a persisted marker is never rendered
— or counted — as a user turn on the client side either. Both ends must
exclude it; excluding it on only one end just inverts the drift.

The regression test drives the real injection point rather than a
hand-written marker dict. Without the fix it fails with "the pivot shifted
the ordinal: the cut landed at 3 instead of 5", losing a turn the user
never asked to drop.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-10 11:01:15 +05:30
kshitij
c91024e6c7 chore: AUTHOR_MAP for aameobius@gmail.com → francialisomlimoeiro
PR #82682 salvage contributor attribution.
2026-08-10 10:58:05 +05:30
Teknium
497c90f317 chore: map contributor email for hillimited 2026-08-09 15:02:27 -07:00
Teknium
7830d9e102 chore: map TomAce7 contributor email for attribution audit 2026-08-09 15:02:00 -07:00
kshitij
f284693496 chore: AUTHOR_MAP for afgl_mk93@icloud.com (PR #81851) 2026-08-09 22:29:39 +05:30
kshitij
9c9be875ff chore: add contributor mapping for adam@exo.ai (PR #82070) 2026-08-09 16:13:52 +05:30
brooklyn!
774e9d4d59 Merge pull request #82390 from NousResearch/bb/draft-status
fix(desktop,title): name and mark an unsent session, and the titler behind it
2026-08-09 04:42:30 -05:00
Brooklyn Nicholson
b824f7537f chore(contributors): map yy28's email for the cherry-picked title fix 2026-08-09 04:33:58 -05:00
kshitij
51c07bd8f8 chore: AUTHOR_MAP for drissman@gmail.com (PR #82061) 2026-08-09 14:13:02 +05:30
Sohom Sahaun
21bc9ba341 fix(model-switch): split YYYYMMDD date stamps from version tuple in _model_sort_key
_model_sort_key treated YYYYMMDD snapshot stamps (e.g.
claude-opus-4-20250514) as version components, so 20250514 > 8
and resolve_alias("opus", "anthropic") returned the wrong model.

Fix: split components ≥ 19_000_101 (smallest plausible date stamp)
out of the version tuple, keeping them as a trailing tiebreaker so
bare IDs sort before their dated snapshots and newer snapshots
before older ones.  Shorter numeric components (mistral-large-2411,
gpt-4-0613) keep their current behavior.  No models.dev dependency
in the sort path.
2026-08-08 18:35:31 -07:00
Teknium
93be7f0117 test(file-ops): end-to-end regression suite for the UTF-8-flagged-as-binary class
Real-backend coverage for the dupe-swarm cluster: truncated-CJK and
Cyrillic sample cuts, utf-8-sig BOM, genuine binaries (PNG/ELF magic,
NUL-in-text), empty files, UTF-16 both endians (read-only pin), plus the
sibling sites — read_file_raw (patch/V4A, #80221), patch_replace, and
content search (#80308).

Closes #76886 #77047 #77842 #80221 #80251 #80308 #80922
2026-08-08 12:34:06 -07:00
Teknium
ad82fc9bdc chore: contributor email mappings for salvaged Windows-encoding PRs 2026-08-08 12:33:19 -07:00
Teknium
9e6cfcda5a fix: finish the missing-encoding sweep — BOM-tolerant reads for user-edited stores
Complements the cherry-picked contributor fixes and closes out the
remaining sites of the 'missing explicit encoding' bug class, which is
now permanently gated by ruff PLW1514 (enabled repo-wide in
pyproject.toml and enforced by the blocking `ruff check .` step in
.github/workflows/lint.yml):

- tools/memory_tool.py: read MEMORY.md/USER.md via utf-8-sig so a
  Notepad BOM never glues U+FEFF onto the first entry (issue #10878,
  PR #10888 by @easyvibecoding — strict-decode contract of
  _read_raw_checked preserved rather than errors="replace", so
  undecodable files still refuse read-modify-write instead of being
  lossily rewritten). Regression tests included.
- tools/skills_tool.py: SKILL.md and skill file reads pinned to
  utf-8-sig + errors="replace" — deterministic across platforms instead
  of the locale fallback proposed in PR #51701 (superseded: falling back
  to cp1252/GBK makes the same skill render differently per host); .env
  reader aligned with the canonical utf-8-sig dialect in hermes_cli/config.py.
- agent/shell_hooks.py, hermes_cli/main.py, gateway/slash_commands.py:
  explicit utf-8 on the remaining fdopen/open text-mode sites flagged by
  the AlexFucuson9 sweep series (#56033 #56940 #65565 #66782 #66791).

Co-authored-by: easyvibecoding <easyvibecoding@users.noreply.github.com>
Co-authored-by: AlexFucuson9 <AlexFucuson9@users.noreply.github.com>
Co-authored-by: flyingdoubleg <wangzhe00zju@gmail.com>
Co-authored-by: LeonSGP43 <cine.dreamer.one@gmail.com>
2026-08-08 12:32:23 -07:00
Teknium
566b5b16a9 fix(agent,gateway): class-level lone-surrogate chokepoints (#80366 #55143 #55309 #50959 #19819)
Own the surrogate-crash class at three chokepoints instead of leaf sites:

- finalize_turn scrubs final_response once where model text leaves the
  conversation loop — covers oneshot stdout (#80366), NIM/any-provider
  responses (#19819), and every delivery consumer of the turn result.
- _sanitize_gateway_final_response scrubs at the gateway chat-surface
  boundary — Telegram utf16_len (#55309) and Signal formatting (#55143)
  can no longer see a lone surrogate; raw-text surfaces keep passthrough.
- run_conversation walks the fully-built api_kwargs with
  _sanitize_structure_surrogates so tool descriptions (session_search,
  #50959) and every other request-body leaf are JSON-encodable before
  any provider sees them.

Regression tests pin all three chokepoints plus helper semantics.
Cherry-picked alongside #79240 (TheophilusChinomona) and #80374
(rainbowgore) whose commits precede this one with authorship preserved.
2026-08-08 12:31:19 -07:00
Teknium
d871cda170 chore: contributor email mapping for salvaged commits 2026-08-08 12:30:19 -07:00