3 Commits
Author SHA1 Message Date
lihongyuan99 04ed76445f docs(fnos): name the fpk packages the release actually ships (#1145)
The 两种安装包 table listed octop-<ver>.fpk / octop-native-<ver>.fpk, which
no build stage emits: build-fpk.sh always appends the kind to the prefix,
CI sets FPK_NAME_PREFIX=Octop-fnos, and the v1.0.2b2 release carries
Octop-fnos-docker-1.0.2b2.fpk / Octop-fnos-native-1.0.2b2.fpk. The rest of
the file, including the manual-install step, already used those names.
2026-09-26 23:41:00 +08:00
lihongyuan99andjubaoliang aeb486c722 fix(security): keep IPv6 brackets and path params when rebuilding pinned URLs (#1092)
Co-authored-by: jubaoliang <jubaoliang@tencent.com>
2026-09-24 15:10:19 +08:00
lihongyuan99 dfd7fd0c9f fix(plugins): keep wiki_summary requests under *.wikipedia.org (#1027)
wiki_summary interpolates its `lang` argument straight into the URL host
(`https://{lang}.wikipedia.org/...`), and the tool schema the harness
builds from the signature gives the model an unconstrained `str`. A value
like "evil.com#" makes httpx resolve host=evil.com, and "localhost:8443/"
reaches a loopback port -- the response's `extract` is then echoed back
into the chat, so it is also a read-back channel.

Validate `lang` as a bare subdomain label and return the usual error card
otherwise; real codes (zh, en, zh-classical, simple, nb) are unaffected.
2026-09-24 15:04:12 +08:00