Self-hosted AI workspace.
Find a file
Alexandre Teixeira 11ad4e2739 fix(url-safety): resolve NAT64 well-known prefix to IPv4 target
The R09 scholarly hardening routes every hop through check_outbound_url with
block_private=True. On a DNS64/NAT64 network, an IPv4-only host can resolve
through the RFC 6052 Well-Known Prefix. For example, export.arxiv.org resolved
to 64:ff9b::924b:5b2a in the reproduced environment.

CPython classifies that outer IPv6 prefix as reserved, so the URL guard rejected
the request before examining the effective IPv4 destination.

Decode addresses in exactly 64:ff9b::/96 to their embedded IPv4 destination and
evaluate that destination under the strict outbound policy.

The translated target is always checked with private-address blocking enabled.
This prevents the NAT64 prefix from becoming a path to loopback, private,
shared/CGNAT, link-local, multicast, unspecified, or other non-global IPv4
space.

Network-specific translation prefixes are not decoded. In particular,
64:ff9b:1::/48 remains subject to the existing IPv6 policy.

Coverage includes:

- public IPv4 destinations embedded through the RFC 6052 prefix
- loopback, link-local, private, CGNAT, multicast, unspecified, benchmark, and
  TEST-NET rejection
- network-specific NAT64 prefixes remaining undecoded
- deterministic scholarly provider tests without live DNS dependence
- redirect query parameter isolation
- relative redirect resolution
- HTTP error fallback behavior
- editor draft GET and DELETE behavior remaining unaffected

R09, R11, and R01 were independently audited and otherwise left unchanged.
2026-09-23 15:32:04 +01:00
.github ci: install FFmpeg for media integration tests 2026-09-23 01:08:20 +01:00
assets/branding refactor(docs): separate Pages site source (#6176) 2026-08-27 10:20:36 +02:00
companion fix(companion): honor configured pairing address (#6060) 2026-08-15 21:11:10 +02:00
config/searxng Generate SearXNG secret on first boot 2026-06-01 11:03:02 +09:00
core feat(provider): support multiple ChatGPT subscriptions with usage 2026-09-22 13:12:19 +01:00
docker Squash Odysseus development history 2026-09-11 06:04:19 +00:00
docs Verify research-before-streaming at interactive temperature 2026-09-17 22:48:03 +00:00
integrations Add Codex and Claude document draft integration 2026-06-09 14:27:53 +09:00
licenses perf(static): vendor KaTeX and Mermaid, and load them on first use (#5994) 2026-08-16 22:43:12 +01:00
mcp_servers Consolidate Odysseus agent harness and tool contracts 2026-09-17 10:07:40 +00:00
plans Consolidate Odysseus agent harness and tool contracts 2026-09-17 10:07:40 +00:00
resources/skills Squash Odysseus development history 2026-09-11 06:04:19 +00:00
routes fix(review): harden scholarly redirects, editor draft limits, and threat model 2026-09-23 12:53:06 +01:00
scripts fix(ci): make maintainer harness contract self-contained and portable 2026-09-22 11:31:45 +01:00
services fix(review): harden scholarly redirects, editor draft limits, and threat model 2026-09-23 12:53:06 +01:00
specs docs: bootstrap specs ground truth (#5794) 2026-08-25 14:18:44 +02:00
src fix(url-safety): resolve NAT64 well-known prefix to IPv4 target 2026-09-23 15:32:04 +01:00
static fix(ui): restore rich text controls and accessible research map 2026-09-22 23:26:43 +01:00
swift/odysseus-mlx-image-bridge Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
tests fix(url-safety): resolve NAT64 well-known prefix to IPv4 target 2026-09-23 15:32:04 +01:00
website Squash Odysseus development history 2026-09-11 06:04:19 +00:00
.dockerignore refactor(docs): separate Pages site source (#6176) 2026-08-27 10:20:36 +02:00
.env.example Harden maintainer-preview harness and review fixes 2026-09-21 06:54:03 +00:00
.gitattributes perf(static): vendor KaTeX and Mermaid, and load them on first use (#5994) 2026-08-16 22:43:12 +01:00
.gitignore refactor(docs): separate Pages site source (#6176) 2026-08-27 10:20:36 +02:00
ACKNOWLEDGMENTS.md Squash Odysseus development history 2026-09-11 06:04:19 +00:00
app.py Squash Odysseus development history 2026-09-11 06:04:19 +00:00
build-macos-app.sh refactor(docs): separate Pages site source (#6176) 2026-08-27 10:20:36 +02:00
build-windows-portable.ps1 feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
CONTRIBUTING.md chore: update repository URLs after organization transfer (#5622) 2026-07-20 16:43:47 +02:00
docker-compose.gpu-amd.yml Harden maintainer-preview harness and review fixes 2026-09-21 06:54:03 +00:00
docker-compose.gpu-nvidia.yml Harden maintainer-preview harness and review fixes 2026-09-21 06:54:03 +00:00
docker-compose.yml Harden maintainer-preview harness and review fixes 2026-09-21 06:54:03 +00:00
Dockerfile Squash Odysseus development history 2026-09-11 06:04:19 +00:00
HARNESS_VERSION reserve wall time for artifact completion 2026-09-19 12:45:09 +00:00
install-service.sh Odysseus v1.0 2026-05-31 23:58:26 +09:00
launch-windows.ps1 fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032) 2026-08-15 23:09:01 -06:00
launcher.py Squash Odysseus development history 2026-09-11 06:04:19 +00:00
LICENSE chore: backport main-only changes to dev AGPL relicense + Cookbook serve fix (#3704) 2026-06-09 23:20:34 +02:00
odysseus-ui.service fix: systemd service should serve on port 7000 to match Docker/setup/README (#1297) 2026-06-03 02:04:37 +09:00
Odysseus.spec feat(launcher): add portable windows launcher (#976) 2026-06-16 04:58:16 +01:00
package-lock.json Squash Odysseus development history 2026-09-11 06:04:19 +00:00
package.json Squash Odysseus development history 2026-09-11 06:04:19 +00:00
pyproject.toml test: add fast lane and duration visibility (#3659) 2026-06-09 20:11:47 +02:00
README.md Harden maintainer-preview harness and review fixes 2026-09-21 06:54:03 +00:00
requirements-optional.txt Squash Odysseus development history 2026-09-11 06:04:19 +00:00
requirements.txt Harden maintainer-preview harness and review fixes 2026-09-21 06:54:03 +00:00
ROADMAP.md Merge verified Odysseus fixes 2026-07-23 14:49:02 +00:00
SECURITY.md fix(auth): derive the session cookie Secure flag from the request scheme (#6048) 2026-08-16 22:56:36 +01:00
setup.py fix(setup): load .env so a pre-seeded admin password is honored on native installs (#4787) 2026-06-23 20:08:05 +02:00
start-macos.sh fix(mcp): stop assuming http://localhost:7000 for the OAuth callback (#6032) 2026-08-15 23:09:01 -06:00
THREAT_MODEL.md fix(review): harden scholarly redirects, editor draft limits, and threat model 2026-09-23 12:53:06 +01:00
update_windows.bat Windows: add Docker update script 2026-06-02 20:45:32 +09:00

Odysseus

A self-hosted AI workspace for chat, agents, research, documents, email, notes, calendar, and local model workflows.

Quick Start · Setup Guide · Contributing · Roadmap

Packaging status

Odysseus interface


Quick Start

dev is the default branch and gets the newest changes first. Use main if you want the more curated branch.

git clone https://github.com/odysseus-dev/odysseus.git
cd odysseus
cp .env.example .env
docker compose up -d --build

Open http://localhost:7011 when the containers are healthy. The first admin password is printed in docker compose logs odysseus.

Native installs, GPU notes, Windows/macOS instructions, HTTPS, and configuration live in the setup guide.

Features

  • Chat + Agents — local/API models, tools, MCP, files, shell, skills, and memory.
  • Cookbook — hardware-aware model recommendations, downloads, and serving.
  • Deep Research — multi-step web research with source reading and report generation.
  • Compare — blind side-by-side model testing and synthesis.
  • Documents — writing-first editor with AI edits, suggestions, Markdown, HTML, CSV, and syntax highlighting.
  • Email — IMAP/SMTP inbox with triage, tags, summaries, reminders, and reply drafts.
  • Notes, Tasks + Calendar — reminders, todos, scheduled agent tasks, and CalDAV sync.
  • Extras — gallery/image editor, themes, uploads, web search, presets, sessions, and 2FA.

Demo

A full hover-to-play tour lives on the Odysseus landing page. Its source lives under website/.

Contributing

Help is welcome. The best entry points are fresh-install testing, provider setup bugs, mobile/editor polish, docs, and small focused refactors. See CONTRIBUTING.md and ROADMAP.md.

Security

Odysseus is a self-hosted workspace with powerful local tools. Keep auth enabled, keep private data out of Git, and do not expose raw model/service ports publicly.

  • Keep AUTH_ENABLED=true for any network-accessible deployment.
  • Keep LOCALHOST_BYPASS=false outside local development.

Deployment details are in the setup guide.

Star History

Star History Chart

License

AGPL-3.0-or-later -- see LICENSE and ACKNOWLEDGMENTS.md.