Commit graph

2529 commits

Author SHA1 Message Date
dependabot[bot]
e4e92001d6
chore(deps): bump the actions group across 1 directory with 7 updates
Bumps the actions group with 7 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.7` | `4.38.2` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action) | `4.37.7` | `4.38.2` |
| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action) | `3.4.0` | `3.5.0` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action) | `4.3.0` | `4.4.1` |
| [docker/build-push-action](https://github.com/docker/build-push-action) | `7.3.0` | `7.4.0` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `4.37.7` | `4.38.2` |
| [actions/deploy-pages](https://github.com/actions/deploy-pages) | `5.0.0` | `5.0.1` |



Updates `github/codeql-action/init` from 4.37.7 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](ff2f1c621b...2892aa5e19)

Updates `github/codeql-action/analyze` from 4.37.7 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](ff2f1c621b...2892aa5e19)

Updates `hadolint/hadolint-action` from 3.4.0 to 3.5.0
- [Release notes](https://github.com/hadolint/hadolint-action/releases)
- [Commits](2a66e89f53...06be81baf8)

Updates `docker/setup-buildx-action` from 4.3.0 to 4.4.1
- [Release notes](https://github.com/docker/setup-buildx-action/releases)
- [Commits](37fe631027...f87e5991a6)

Updates `docker/build-push-action` from 7.3.0 to 7.4.0
- [Release notes](https://github.com/docker/build-push-action/releases)
- [Commits](53b7df96c9...c3c9e263c2)

Updates `github/codeql-action/upload-sarif` from 4.37.7 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](ff2f1c621b...2892aa5e19)

Updates `actions/deploy-pages` from 5.0.0 to 5.0.1
- [Release notes](https://github.com/actions/deploy-pages/releases)
- [Commits](cd2ce8fcbc...368f825286)

---
updated-dependencies:
- dependency-name: actions/deploy-pages
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: actions
- dependency-name: docker/build-push-action
  dependency-version: 7.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: docker/setup-buildx-action
  dependency-version: 4.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: github/codeql-action/init
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: github/codeql-action/upload-sarif
  dependency-version: 4.38.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
- dependency-name: hadolint/hadolint-action
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-10-06 18:21:22 +00:00
Léo
2cd02da7fc
Merge pull request #6503 from odysseus-dev/release/pre-ajax-freeze2
chore(release): publish qualified pre-Ajax migration
2026-10-06 20:14:01 +02:00
Léo
ee13ed1eee fix(security): keep the post-external-context approval gate on by default
Request authority admits whole tool families from the user's request, so a
request to read email also admits send_email, delete_email and bulk_email,
and agent processes inherit the host network. With the gate defaulting to
off, an instruction injected through an email or a fetched page reaches those
tools with no other check; dev refuses them today.

Default the gate on, keep ODYSSEUS_TOOL_APPROVAL_GATE=0 as the opt-out, and
pin the production default with a test that imports the module in a fresh
interpreter. Four routing tests written for the opt-out posture now set it
explicitly.
2026-10-06 19:49:15 +02:00
Alexandre Teixeira
8f0a28c05e docs(config): refresh generated environment reference 2026-10-06 18:46:02 +01:00
Alexandre Teixeira
dfd1f7e7cb fix(network): honor loopback policy for ipv6 localhost 2026-10-06 18:31:22 +01:00
Alexandre Teixeira
9aa58b218a fix(tasks): recover registered endpoint runtime credentials 2026-10-06 18:31:16 +01:00
Alexandre Teixeira
622738bda7 fix(endpoints): accept registered canonical chat urls 2026-10-06 18:31:13 +01:00
Alexandre Teixeira
82cfd7d69a fix(security): enforce delegated authority in local web fetches 2026-10-06 18:31:08 +01:00
Alexandre Teixeira
c7961d178f fix(security): confine workspace existence checks 2026-10-06 15:18:34 +01:00
Alexandre Teixeira
ee48c9c51e fix(security): eliminate induced regex denial-of-service paths 2026-10-06 13:36:01 +01:00
Alexandre Teixeira
2e4ad7c383 docs(config): refresh generated environment reference 2026-10-06 03:40:32 +01:00
Alexandre Teixeira
3d91ad82cb fix(security): harden Python service boundaries 2026-10-06 03:16:54 +01:00
Alexandre Teixeira
da3800b662 fix(security): eliminate parser denial-of-service paths 2026-10-06 03:16:53 +01:00
Alexandre Teixeira
ab6f52d30c fix(security): harden host bridge request boundaries 2026-10-06 03:16:53 +01:00
Alexandre Teixeira
f2b72e8a9a test(security): strengthen browser boundary regressions 2026-10-06 03:16:53 +01:00
Alexandre Teixeira
61b63c9ce3 fix(security): isolate session cost ledger keys
Use Map-backed cost ledgers so externally derived session and run identifiers never cross ordinary object prototype semantics. Preserve the existing JSON storage format and extend browser and isolated ledger regressions for replay, overflow, legacy data, and reserved keys.
2026-10-06 00:25:24 +01:00
Alexandre Teixeira
232249eb09 fix(security): harden browser security boundaries
Reject unsafe metric ledger keys, keep email HTML inspection inert, and construct gallery thumbnails structurally. Add adversarial browser regressions for the remaining CodeQL security boundaries.
2026-10-05 23:48:14 +01:00
Alexandre Teixeira
0d97651686 fix(security): avoid SVG title DOM reparsing
Extract strict text-only SVG titles without reparsing model output as DOM, preserving sandboxed SVG rendering and safe accessibility labels.
2026-10-05 22:33:25 +01:00
Alexandre Teixeira
9ee614e2ac fix(security): enforce registered endpoint authority
Require caller-supplied model endpoints to resolve through enabled owner-visible registrations, harden session path encoding, and remove the SVG title HTML parsing sink.
2026-10-05 22:24:15 +01:00
Alexandre Teixeira
481726acf2 fix(security): address CodeQL findings in migration candidate 2026-10-05 20:48:12 +01:00
Alexandre Teixeira
851d3dcea2 test(ci): stabilize public CI shard validation 2026-10-05 19:21:50 +01:00
Alexandre Teixeira
2cc4b8a4b1 Merge commit 'refs/phase3/pre-ajax/publication-tip' into integration/pre-ajax-release
# Conflicts:
#	routes/chat_routes.py
#	routes/session_routes.py
#	src/agent_loop.py
#	src/agent_tools/filesystem_tools.py
#	src/teacher_escalation.py
#	src/tool_capabilities.py
#	src/tool_execution.py
#	tests/test_mcp_add_server_args_validation.py
#	tests/test_token_cache_atomic_swap.py
2026-10-05 15:59:59 +01:00
Alexandre Teixeira
dab660543b chore(publication): close pre-integration release blockers 2026-10-05 01:37:49 +01:00
Alexandre Teixeira
3d3aee2093 Merge pull request #64 from pewdiepie-archdaemon/integration/wave6-on-wave4
test(wave6): isolate test runtime for opt-in xdist and preserve explicit no-web intent
2026-10-03 05:00:57 +01:00
Alexandre Teixeira
0ab6fc102c docs(env): refresh generated configuration reference
Regenerate website/configuration-reference.md with
scripts/generate_env_reference.py. The negative-web correction in
96e82562 inserted five lines in src/agent_loop.py ahead of the
ODYSSEUS_MAX_VISUAL_EVIDENCE_IMAGES and _FRAMES reads, so their recorded
locations move from 15329/15361 to 15334/15366. No variable, default or
description changed.
2026-10-03 04:47:25 +01:00
Alexandre Teixeira
80adeda937 fix(agent): honor explicit no-web requests 2026-10-03 04:02:59 +01:00
Alexandre Teixeira
18996588ff docs(tests): record Wave 6 parallel test measurements
Document opt-in local workers and the per-process runtime ownership model.
Record the two parallel-only failures found and fixed in test
infrastructure. Record the measured results on the final code: serial
oracle 496.3s, -n 2 267.6s (1.85x), and two green -n 4 runs at 155.6s mean
(3.19x), all with identical skip and xfail sets and no leaked processes,
listeners, state, or runtime roots. Recommend -n 4 locally and explain
why -n auto was not run. The full serial run remains the release oracle.
2026-10-03 03:46:53 +01:00
Alexandre Teixeira
77b61c222e test: serve browser assets without head-of-line blocking
The shared static server handled one connection at a time. Chromium can
open a speculative connection and never send a request, so every queued
request waited behind it. Under parallel load a computed-style capture's
navigation stalled for 30s and failed. Under CPU saturation, 4 of 12
captures stalled for about 29s each.

Serve each connection on a daemon thread. The existing serve-this-worktree
test now holds a silent connection open while it fetches, and times out
against the serial server. The configuration reference's recorded source
lines are unchanged.
2026-10-03 03:46:52 +01:00
Alexandre Teixeira
256beebb3d test: keep pytest basetemp within the AF_UNIX path limit
Moving TMPDIR into the private runtime root left pytest's default
<TMPDIR>/pytest-of-<user>/pytest-<n> beneath it. With xdist's popen-gw<n>
the real-tmux witness bound a 110-byte socket path, over Linux's 107-byte
sun_path limit, so it failed under every worker count while passing
serially.

The controller now roots basetemp at the private root's pytest directory;
xdist hands workers popen-gw<n> beneath it. An explicit --basetemp wins.
A tmux-independent witness binds a socket at the same path budget.
2026-10-03 03:46:52 +01:00
Alexandre Teixeira
e1bc13b634 test: retain ownership of sockets and subprocess groups 2026-10-03 03:46:52 +01:00
Alexandre Teixeira
6eb0bbfe70 test: isolate pytest runtime defaults across workers and runs 2026-10-03 03:46:52 +01:00
Alexandre Teixeira
a52c657150 test(web): repair negative security witnesses 2026-10-03 03:46:52 +01:00
Alexandre Teixeira
decfab12f9 fix(tests): preserve bootstrap reference locations 2026-10-03 03:46:52 +01:00
Alexandre Teixeira
9fd6919ee9 fix(tests): isolate database and module state 2026-10-03 03:46:52 +01:00
Alexandre Teixeira
3468ad36d7 Merge pull request #62 from pewdiepie-archdaemon/feature/effects-provenance-wave4
feat(runtime): add durable effect provenance and truthful completion
2026-10-03 03:10:58 +01:00
Alexandre Teixeira
7563d859bc fix(effects): close independent review correctness gaps 2026-10-03 02:55:31 +01:00
Alexandre Teixeira
da4bf3531f Merge frozen lab b1666951 (Wave 3) into Wave 4 effects provenance
Integrates the merged and frozen Wave 3 lab commit
b1666951faf8285054e1ca90f11533b0fb53fb57 with a normal merge, preserving
every Wave 4 commit unchanged.

Conflict: src/agent_runtime/resources.py. Wave 3's _control_plane_snapshot()
/ _control_plane_path(path, *, snapshot=None) split is kept. The snapshot adds
the effect-store directories to its prefix set after the recursive job-dir
inventory and no longer references path (the auto-merged prefix check would
have raised NameError there). _control_plane_path calls _aliases_effect_store
after its os.stat, only for multiply linked files, so single-link files never
list the store.

Semantic reconciliation (no textual conflict): bg_monitor keeps launch
settlement right after the first successful validate_job and before the
authority check, with Wave 3's post-drain revalidation intact. The
deleted-session branch, terminal before linkage validation, now settles a
validated launch too: that job is later pruned and its publication retired,
which would otherwise leave its effect RUNNING. Regression tests cover the
snapshot form of the effect-store check and both deleted-session linkage
outcomes.
2026-10-03 01:13:36 +01:00
Alexandre Teixeira
3e43809ed6 docs(effects): record corrective pass and Wave 3 rebase checklist 2026-10-03 01:00:18 +01:00
Alexandre Teixeira
4d07e2da2d test(effects): close Wave 4 adversarial regressions
Real-seam coverage for each corrective fix, each checked by mutation:
requested edit/patch states (CRLF-exact, unrelated change contradicts,
partial read and underivable targets stay unverified, superseded effects are
history); directory and launch-index fsync order observed via real fsync
targets; dispatch refused when the directory fsync fails; independent
objects, threads and processes never reuse positions; settle-once and
recovery against another writer; torn-tail repair; unbound tools cannot
manufacture RUNNING/cleanup/facts or settle launches; external effects never
complete as satisfied, are always disclosed, and passing tests stay test
facts; verifier staleness and RUNNING launches without obligations;
known-scope child effects leave unrelated parent evidence fresh; browser page
refusal survives a matching approval and child authority with no claim, no
execution id and no producer call; effect-store hardlinks are caught without
scanning the store.

Replaces the uncommitted tests that asserted a CONTENT_CHANGED predicate and
blocking on any RUNNING effect.
2026-10-03 00:58:32 +01:00
Alexandre Teixeira
7267341d49 fix(effects): protect provenance control state efficiently
A hardlink into the effect store was protected only by the log's own nlink
refusal, which an agent could undo by removing the alias after writing
through it. Adding the store to the recursive control-plane inventory would
make every path check cost grow with accumulated runs. _aliases_effect_store
instead uses the store's invariants: logs and launch indexes refuse
st_nlink != 1 and the store is flat, so only a multiply linked regular file
on the store's device is compared by inode against one non-recursive listing.
Single-link files cost nothing and the store is never rglob-inventoried. The
helper takes a stat result so it plugs into Wave 3's scan-local snapshot after
the rebase.
2026-10-03 00:58:32 +01:00
Alexandre Teixeira
b23c6d40b3 fix(effects): require evidence for external completion claims
Effect obligations were consulted only for declared artifacts, and reported
external success could be presented as done. Now, regardless of declared
artifacts:

- the latest effect on any changed file contradicted by a fresh readback
  fails the run (a superseded earlier effect is history, not a contradiction);
- a passing verifier followed by an effect that may have changed state
  without settled evidence is stale (BLOCKED);
- executed external effects that are not VERIFIED cap the decision at
  UNVERIFIED, and the answer always carries server-authored facts for them
  ("reported success; any external change it made was not independently
  verified", "reported failure", "unknown outcome").

The disclosure is structural and does not depend on recognizing the model's
wording. When it is the only change, the model's answer events are released
unchanged and the disclosure follows as one delta (and in round_texts).
Prose filtering is also tightened (remote verbs are mutation claims, an
unnamed "I updated it" cannot borrow the single required artifact, bare
"Done." is a terminal claim beside unverified external effects). A passing
verifier still supports test claims; it never speaks for the external effect.

Replaces the uncommitted attempt that blocked every run with any RUNNING
effect: a background launch with no declared obligations completes
UNVERIFIED.
2026-10-03 00:58:32 +01:00
Alexandre Teixeira
682b44a3ec fix(effects): preserve producer trust boundaries
Result-dictionary keys could set lifecycle state for any producer: a dynamic
or registry tool returning bg_job_id/detached became RUNNING, teardown became
verified cleanup, and timed_out/failure_kind/mutation_attempted/containment
were copied from untrusted results. Facts are now scoped to the producer the
dispatcher actually bound. An unbound tool contributes its exit status alone.
RUNNING requires a bound process producer (and an exact launch reservation
for bg_job_id), cleanup is attested only by a bound process producer, and job
observations and launch settlement only by a bound manage_bg_jobs operation
on exactly one Wave 3-validated job. External/remote-acknowledged facts come
from the captured ExternalResource, not from the result.
2026-10-03 00:58:32 +01:00
Alexandre Teixeira
04da2f04e8 fix(effects): make journal sequencing crash and concurrency safe
Sequence positions were allocated from each EffectLog object's in-memory
counter, so two objects, threads or processes could reuse a position or
settle one effect twice; replay then failed closed for the whole log. Every
append now takes an exclusive flock, merges the durable records other writers
appended (truncating a torn tail a crashed writer left), allocates from that
merged tail, rejects records the merged history makes invalid (a second
settlement, recovery of a claim another writer settled or marked running),
then appends, fsyncs and releases. history() merges others' records under a
shared lock. An incremental consistency index keeps appends O(1).

The first append of each log object fsyncs the log's directory, and every
directory created for it is fsynced in its parent, all under the lock before
the claim returns. A failed write or directory fsync truncates the record
back, so dispatch is refused and nothing unacknowledged is later merged. The
launch index writes and fsyncs a temp file, replaces it, then fsyncs the
directory. flock and directory fsync are POSIX-only and not claimed
elsewhere.
2026-10-03 00:58:32 +01:00
Alexandre Teixeira
f79c2aba7e fix(effects): make postconditions prove intended mutations
edit_file and apply_patch update claims asserted only existence (or, in the
uncommitted corrective attempt, any content change), so an unrelated write
could verify them. Each filesystem postcondition is now the exact content the
producer's own transformation writes from the identity-checked pre-state:
edit_file through the extracted pure _edit_file_text (no newline
translation), apply_patch updates through _apply_patch_hunks on the
universal-newline pre-state. An oversized, replaced or undecodable pre-state,
a non-matching hunk, or an underivable write_file body leaves the whole claim
without postconditions (UNVERIFIED) instead of letting derivable targets
verify the operation or falling back to existence.
2026-10-03 00:58:11 +01:00
Alexandre Teixeira
071e4ec957 Merge pull request #60 from pewdiepie-archdaemon/feature/runtime-resource-authority
feat(runtime): bind runtime resources to authority
2026-10-03 00:32:35 +01:00
Alexandre Teixeira
6cd6ee43c3 docs(runtime): record Wave 3 closure evidence and contracts 2026-10-03 00:20:15 +01:00
Alexandre Teixeira
55d5b1d10a test(runtime): use live local control transport credentials 2026-10-03 00:10:24 +01:00
Alexandre Teixeira
721b5ca831 fix(runtime): retain malformed launch publications safely 2026-10-02 23:57:57 +01:00
Alexandre Teixeira
3d7d32dbe2 fix(runtime): preserve in-flight foreground attachment state 2026-10-02 23:48:41 +01:00
Alexandre Teixeira
3db903c336 fix(runtime): retain publications when recovery state is unreadable 2026-10-02 23:39:13 +01:00