pewdiepie-archdaemon
4faf683912
Treat explicitly supplied proofreading text as data not tool authority
2026-09-17 20:40:00 +00:00
pewdiepie-archdaemon
20361b3de8
Control sampling and canonical prompt in search diagnostics
2026-09-17 20:37:32 +00:00
pewdiepie-archdaemon
39a6a49664
Stop appending unverified search citations to synthesized answers
2026-09-17 20:32:46 +00:00
pewdiepie-archdaemon
87b6a37885
Record search quality failures and separate mechanics from review
2026-09-17 20:26:53 +00:00
pewdiepie-archdaemon
cfb9315e0a
Preserve news query intent and extract nonduplicated semantic page content
2026-09-17 20:24:00 +00:00
pewdiepie-archdaemon
3edf7acd21
Allow evidence verification after successful search and fetch
2026-09-17 20:20:40 +00:00
pewdiepie-archdaemon
7257319004
Preserve every fetched search source within observation budget
2026-09-17 20:17:03 +00:00
pewdiepie-archdaemon
a48ab46f7d
Enforce search source restrictions and expand live prompt coverage
2026-09-17 20:14:32 +00:00
pewdiepie-archdaemon
7fa6c93fb3
separate search freshness from news category selection
2026-09-17 20:08:58 +00:00
pewdiepie-archdaemon
566202dcad
require domain evidence for official source shortcut
2026-09-17 20:07:51 +00:00
pewdiepie-archdaemon
6fb1ce7238
withhold tools for standalone social turns
2026-09-17 20:05:30 +00:00
pewdiepie-archdaemon
dc4a38f3bc
preserve manual formats and require discovery for evidence requests
2026-09-17 20:04:51 +00:00
pewdiepie-archdaemon
2d938b1650
recognize casual news requests and prevent premature source-only completion
2026-09-17 20:03:32 +00:00
pewdiepie-archdaemon
da215cf242
audit search variety with model provenance and per-turn latency
2026-09-17 20:01:38 +00:00
pewdiepie-archdaemon
a7576f721c
verify embedded articles skip redundant retrieval rounds
2026-09-17 19:58:06 +00:00
pewdiepie-archdaemon
02200b2874
reuse embedded search articles and reject browser error pages
2026-09-17 19:57:20 +00:00
pewdiepie-archdaemon
f27070c469
buffer rejected search drafts and cap interactive rounds
2026-09-17 19:53:40 +00:00
pewdiepie-archdaemon
ff4d01a55e
ground fresh searches and verify official documents
2026-09-17 19:49:28 +00:00
pewdiepie-archdaemon
994413c435
compose explicit search and fetch workflows
2026-09-17 19:43:20 +00:00
pewdiepie-archdaemon
8c7ea10520
ground current lookups and recover failed fetches
2026-09-17 19:42:38 +00:00
pewdiepie-archdaemon
dfd4d5a80e
preserve evidence after bounded web search
2026-09-17 19:35:54 +00:00
pewdiepie-archdaemon
f2fb42c7d1
synthesize after bounded search suppression
2026-09-17 19:27:16 +00:00
pewdiepie-archdaemon
295578514e
route current events through bounded news search
2026-09-17 19:26:04 +00:00
pewdiepie-archdaemon
e9a117df0d
bound optional search fallback latency
2026-09-17 19:22:51 +00:00
pewdiepie-archdaemon
6b135eab73
finish resource lookups from verified search metadata
2026-09-17 19:18:05 +00:00
pewdiepie-archdaemon
e49264ae47
preserve product identity in manual search
2026-09-17 19:15:39 +00:00
pewdiepie-archdaemon
e48ea98d2f
broaden empty searches through resilient providers
2026-09-17 19:12:28 +00:00
pewdiepie-archdaemon
e22cf4b500
bound search attempts by research depth
2026-09-17 19:07:22 +00:00
pewdiepie-archdaemon
483fdc7054
require linked broad research synthesis
2026-09-17 19:04:08 +00:00
pewdiepie-archdaemon
e3107a645d
enforce distinct research refinement
2026-09-17 19:02:11 +00:00
pewdiepie-archdaemon
6121442658
unify broad web briefing semantics
2026-09-17 18:58:31 +00:00
pewdiepie-archdaemon
be48da1146
recognize natural broad current queries
2026-09-17 18:55:19 +00:00
pewdiepie-archdaemon
cdc0734347
require breadth for broad current research
2026-09-17 18:51:56 +00:00
pewdiepie-archdaemon
69a1b97c96
recover rendered pages from fetch boilerplate
2026-09-17 18:49:59 +00:00
pewdiepie-archdaemon
4d7c9d44d1
keep compact agent core tools available
2026-09-17 18:47:04 +00:00
pewdiepie-archdaemon
25ff725c1d
repair broad web research recovery
2026-09-17 18:36:12 +00:00
pewdiepie-archdaemon
0aa470b095
recover synthesis after unavailable web search
2026-09-17 13:34:36 +00:00
pewdiepie-archdaemon
337a47d27d
skip redundant synthesis after email actions
2026-09-17 13:21:11 +00:00
pewdiepie-archdaemon
10d637f8b9
ground research synthesis in retrieved source urls
2026-09-17 10:50:20 +00:00
pewdiepie-archdaemon
8ae0c31666
bound web research to retrieval and synthesis
2026-09-17 10:41:14 +00:00
pewdiepie-archdaemon
218d762427
Consolidate Odysseus agent harness and tool contracts
2026-09-17 10:07:40 +00:00
pewdiepie-archdaemon
84aa9a91de
Squash Odysseus development history
2026-09-11 06:04:19 +00:00
RaresKeY
c9dd68d890
refactor(docs): separate Pages site source ( #6176 )
...
CI / Focused test guidance (report-only) (push) Has been cancelled
CI / Python syntax (compileall) (push) Has been cancelled
CI / JS syntax (node --check) (push) Has been cancelled
CI / Python tests (pytest) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (javascript-typescript) (push) Has been cancelled
CodeQL / Analyze (python) (push) Has been cancelled
ci / docker publish / build (amd64) (push) Has been cancelled
ci / docker publish / build (arm64) (push) Has been cancelled
ci / docker publish / merge manifest + tag (push) Has been cancelled
* refactor(docs): separate Pages site source
* fix(docs): preserve published guide pages
* fix(ci): run asset ownership tests for site changes
* fix(docs): track future website media
* fix(ci): let Pages deployments finish
* build(deps): update Pages checkout action
* fix(ci): follow moved setup guide
* fix(docs): repair published setup guide
* fix(docs): retarget preview encoder
2026-08-27 10:20:36 +02:00
RaresKeY
7026cf40b5
docs: bootstrap specs ground truth ( #5794 )
...
CI / Focused test guidance (report-only) (push) Has been cancelled
CI / Python syntax (compileall) (push) Has been cancelled
CI / JS syntax (node --check) (push) Has been cancelled
CI / Python tests (pytest) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (javascript-typescript) (push) Has been cancelled
CodeQL / Analyze (python) (push) Has been cancelled
ci / docker publish / build (amd64) (push) Has been cancelled
ci / docker publish / build (arm64) (push) Has been cancelled
ci / docker publish / merge manifest + tag (push) Has been cancelled
* docs(specs): restore bootstrap after dev rewrite
* docs(specs): remove runtime inventory snapshot
* docs(specs): reconcile current dev truth
* docs(specs): document scheduled task actions as an owner-attribution source
Owner Attribution covered cookie, bearer-token and internal-loopback
requests. Scheduled task actions are a fourth source and behave
differently: _execute_action passes owner=task.owner off the stored
ScheduledTask row, so no request and no resolved principal are in
flight, and route-level require_user() never runs.
Webhook triggers are the sharp case. They are unauthenticated by
design with the token as the only credential and execute under the
stored task.owner.
Paths cite routes/task/task_routes.py, the canonical location after
the task subpackage move (#6081 ); routes/task_routes.py on current dev
is the backward-compat shim.
* docs(specs): add chained tasks to the trigger list, refresh dev stamp
Review feedback from RaresKeY on the previous commit.
"Every trigger path" was too broad: success-chained tasks are another
path into _execute_action. Added them with their own citation, and
noted that chaining additionally requires the target task to share
task.owner and rejects cycles, which is stricter than the trigger-side
checks. Softened the lead-in to "these trigger paths".
Line 56 still pointed at routes/task_routes.py for webhook credential
validation. That path is the backward-compat shim on current dev after
the task subpackage move (#6081 ); repointed to the canonical
routes/task/task_routes.py.
Stamp moved to dev@2a6b09b. Inspection backing that bump was scoped:
every file path cited in this spec was mechanically checked to resolve
on 2a6b09b , and every file:line in the Owner Attribution additions was
read against it. Behavioral claims elsewhere in the file were not
re-audited.
* docs(specs): correct SECURE_COOKIES description to match current behavior
Third of the stale details RaresKeY enumerated. The cookie section
described SECURE_COOKIES as purely opt-in, which stopped being true.
_secure_cookie() (routes/auth_routes.py:89) treats an explicit true or
false as authoritative and derives the Secure attribute from the
request otherwise, including when the variable is unset and when
docker-compose injects it present-but-empty. Either the connection
scheme or the first X-Forwarded-Proto hop being https is enough.
* docs(specs): refresh current dev truth
---------
Co-authored-by: StressTestor <212606152+StressTestor@users.noreply.github.com>
2026-08-25 14:18:44 +02:00
dependabot[bot]
bc7514fa3e
build(deps): bump the actions group with 11 updates ( #6141 )
...
Bumps the actions group with 11 updates:
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout ) | `7.0.0` | `7.0.1` |
| [actions/setup-python](https://github.com/actions/setup-python ) | `6.2.0` | `7.0.0` |
| [actions/setup-node](https://github.com/actions/setup-node ) | `6.4.0` | `7.0.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action ) | `4.36.2` | `4.37.7` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action ) | `4.36.2` | `4.37.7` |
| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action ) | `3.3.0` | `3.4.0` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) | `4.1.0` | `4.3.0` |
| [docker/build-push-action](https://github.com/docker/build-push-action ) | `7.2.0` | `7.3.0` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) | `4.36.2` | `4.37.7` |
| [docker/login-action](https://github.com/docker/login-action ) | `4.2.0` | `4.6.0` |
| [docker/metadata-action](https://github.com/docker/metadata-action ) | `6.1.0` | `6.2.0` |
Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](9c091bb21b...3d3c42e5aa )
Updates `actions/setup-python` from 6.2.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](a309ff8b42...5fda3b95a4 )
Updates `actions/setup-node` from 6.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](48b55a011b...8207627860 )
Updates `github/codeql-action/init` from 4.36.2 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...ff2f1c621b )
Updates `github/codeql-action/analyze` from 4.36.2 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...ff2f1c621b )
Updates `hadolint/hadolint-action` from 3.3.0 to 3.4.0
- [Release notes](https://github.com/hadolint/hadolint-action/releases )
- [Commits](2332a7b74a...2a66e89f53 )
Updates `docker/setup-buildx-action` from 4.1.0 to 4.3.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](d7f5e7f509...37fe631027 )
Updates `docker/build-push-action` from 7.2.0 to 7.3.0
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](f9f3042f7e...53b7df96c9 )
Updates `github/codeql-action/upload-sarif` from 4.36.2 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](8aad20d150...ff2f1c621b )
Updates `docker/login-action` from 4.2.0 to 4.6.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](650006c6eb...dbcb813823 )
Updates `docker/metadata-action` from 6.1.0 to 6.2.0
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](80c7e94dd9...dc80280410 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
- dependency-name: actions/setup-python
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/setup-node
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: hadolint/hadolint-action
dependency-version: 3.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/setup-buildx-action
dependency-version: 4.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/build-push-action
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/login-action
dependency-version: 4.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/metadata-action
dependency-version: 6.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 14:06:31 +02:00
dependabot[bot]
e5ab632270
build(deps-dev): bump @antithesishq/bombadil ( #6026 )
...
Bumps the npm group with 1 update in the / directory: [@antithesishq/bombadil](https://github.com/antithesishq/bombadil ).
Updates `@antithesishq/bombadil` from 0.6.1 to 0.7.0
- [Release notes](https://github.com/antithesishq/bombadil/releases )
- [Changelog](https://github.com/antithesishq/bombadil/blob/main/CHANGELOG.md )
- [Commits](https://github.com/antithesishq/bombadil/compare/v0.6.1...v0.7.0 )
---
updated-dependencies:
- dependency-name: "@antithesishq/bombadil"
dependency-version: 0.7.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 14:03:11 +02:00
RaresKeY
e71f8ceb65
chore(release): align dev version with 1.0.3 ( #6168 )
...
CI / Focused test guidance (report-only) (push) Waiting to run
CI / Python syntax (compileall) (push) Waiting to run
CI / JS syntax (node --check) (push) Waiting to run
CI / Python tests (pytest) (push) Waiting to run
CodeQL / Analyze (actions) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
ci / docker publish / build (amd64) (push) Waiting to run
ci / docker publish / build (arm64) (push) Waiting to run
ci / docker publish / merge manifest + tag (push) Blocked by required conditions
Keep dev version metadata aligned with the current hotfix release while the rolling branch continues toward 1.1.0.
Evidence: the canonical APP_VERSION imports as 1.0.3 and the diff check is clean. This commit changes version metadata only; it does not tag or publish a release.
2026-08-25 10:26:18 +01:00
nopoz
d0d8edf5d8
Merge commit from fork
...
CI / Focused test guidance (report-only) (push) Waiting to run
CI / Python syntax (compileall) (push) Waiting to run
CI / JS syntax (node --check) (push) Waiting to run
CI / Python tests (pytest) (push) Waiting to run
CodeQL / Analyze (actions) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
ci / docker publish / build (amd64) (push) Waiting to run
ci / docker publish / build (arm64) (push) Waiting to run
ci / docker publish / merge manifest + tag (push) Blocked by required conditions
scripts/mlx_image_server.py resolved the model per request
(`req.model or _args.model`) on both /v1/images/generations and
/v1/images/edits, so the caller chose which model was served.
`_is_hidream()` is a substring test and `_snapshot_path()` accepts either a
local directory or a Hugging Face repo id, so a caller-supplied string
selected the HiDream branch and then supplied the directory it runs
`scripts/hidream_o1/generate_hidream_o1_mlx.py` from, under sys.executable.
The server has no auth, and the Cookbook binds it to 0.0.0.0 whenever it is
serving to a remote host, so one POST executed attacker code on the serving
host.
Both paths now use `_args.model`. The request field is still accepted for
OpenAI wire compatibility and ignored, matching scripts/diffusion_server.py,
and Odysseus already sends the served model's own id, so this is a no-op for
legitimate callers. /v1/images/harmonize already pinned.
Regression tests cover both endpoints, the local-directory and
Hugging-Face-repo halves, and that a server actually launched with a HiDream
model still serves it. Three of the four fail on the unfixed code.
2026-08-24 17:38:40 +02:00
Joeseph Grey
b4d12932a9
fix(agent): drop the empty assistant turn from an approved-action replay ( #6124 )
...
CI / Focused test guidance (report-only) (push) Has been cancelled
CI / Python syntax (compileall) (push) Has been cancelled
CI / JS syntax (node --check) (push) Has been cancelled
CI / Python tests (pytest) (push) Has been cancelled
CodeQL / Analyze (actions) (push) Has been cancelled
CodeQL / Analyze (javascript-typescript) (push) Has been cancelled
CodeQL / Analyze (python) (push) Has been cancelled
ci / docker publish / build (amd64) (push) Has been cancelled
ci / docker publish / build (arm64) (push) Has been cancelled
ci / docker publish / merge manifest + tag (push) Has been cancelled
The approved-action replay appends the sealed tool result with no assistant
prose for that round, which produced an assistant message with content "".
Anthropic's Messages API rejects a non-final assistant message with empty
content, so a resumed turn after a tool approval failed before the model saw
the result. A turn carrying neither prose nor reasoning has nothing to say to
any provider, so it is no longer appended. A round with prose, and a
reasoning-only round that DeepSeek thinking mode needs, both still append.
2026-08-20 13:06:22 +02:00
Nikhil Chaudhary
85297cee44
fix(core): clean up orphaned temp files on atomic write failure ( #6068 )
...
CI / Focused test guidance (report-only) (push) Waiting to run
CI / Python syntax (compileall) (push) Waiting to run
CI / JS syntax (node --check) (push) Waiting to run
CI / Python tests (pytest) (push) Waiting to run
CodeQL / Analyze (actions) (push) Waiting to run
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
ci / docker publish / build (amd64) (push) Waiting to run
ci / docker publish / build (arm64) (push) Waiting to run
ci / docker publish / merge manifest + tag (push) Blocked by required conditions
* fix(core): clean up orphaned temp files on atomic write failure
* fixed reviewer suggestion
* removed whitespace
2026-08-19 17:38:24 +02:00