100 Commits
Author SHA1 Message Date
jubaoliangandCursor a3851ea7e2 fix: check workspace root isdir only after a host-prefix guard
CodeQL flags is_dir on an admin-supplied path unless realpath is contained with startswith first. Keep the denylist, and stat the directory only inside that guard.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 02:02:25 +00:00
jubaoliangandCursor 349aec69ce fix: add trailing newline to PKCE test
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 01:23:17 +00:00
jubaoliangandCursor 6e10ba1673 fix: identify pypi.org by hostname and keep PKCE S256 out of tests
CodeQL treats a "pypi.org" substring as an incomplete URL check, and SHA-256 of the OAuth verifier as password hashing. Label only the parsed hostname, and verify S256 with the RFC 7636 vector.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-27 01:21:00 +00:00
jubaoliangandCursor b03978de36 chore: release 1.0.2b3
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 16:36:31 +00:00
jubaoliangandCursor 09d72e603b feat(dashboard): add remember-me checkbox on the login page
Default stays persistent (localStorage). Unchecking keeps the JWT in
sessionStorage for this tab only; SSO popups post the token back so the
opener can store it correctly.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-26 22:22:16 +08:00
jubaoliangandCursor 4c3bf76479 fix: team chat/IM UX, ACP sandbox, channel thinking, and related polish
Improve team streaming visibility (live speakers, generating footer, IM
dispatch/wrap-up), relax ACP tool enable under sandbox while locking
runners, strip channel think tags per show_thinking, and clarify provider
CLI usage in the assistant skill. Includes self-update/UpdateConfig WIP
from the same working tree.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 23:59:46 +08:00
jubaoliangandCursor 1d2b2558fb feat(chat): team artifacts, fan-in tool trail, and host wrap-up context
Persist member file refs and tool history on team walls, open docks by producer agent, and inject truncated member answers into host follow-up so wrap-up can follow their advice.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-25 14:48:45 +08:00
jubaoliangandCursor 5e34c8a001 fix: connectors empty layout and restore prior control-plane behaviors
Apply the remaining working-tree changes: connectors empty-state layout,
plus the knowledge, HITL, captcha, workspace, user-cache, and SSRF
adjustments with matching tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 22:40:47 +08:00
jubaoliangandCursor 44023b192f docs: point README at TencentCloud octop-harness repos
The harness-* libraries are now published as octop-harness, octop-gateway,
octop-memory, and octop-browser.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-24 18:23:52 +08:00
jubaoliangandCursor cf99ab89df chore: sync uv.lock for 1.0.2b2
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:09:50 +00:00
jubaoliangandCursor f6acc87e62 chore: release 1.0.2b2
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 15:06:20 +00:00
jubaoliangandCursor 6ede49b2f5 fix(experts): drop redundant add buttons from the edit drawer
Managing skills and subagents already covers install and copy, so the extra add actions only duplicated that entry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 23:02:04 +08:00
jubaoliangandCursor 494a921cfc fix(fnos): parse prerelease versions for FPK builds
Digits-only sed left VER as the whole pyproject line for 1.0.2b1, so
native upload and GHCR wait both failed and no .fpk was attached.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 22:48:41 +08:00
jubaoliangandCursor 963cb14007 fix(chat): show the real team name on the welcome heading
Team rooms used a hardcoded "#管理团队" / "#Manage team" string instead of
the agent name already passed into WelcomeScreen.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:34 +08:00
jubaoliangandCursor df7f7d187c feat(connectors): 企查查改为 API Key,并用 internal 模式加载工具
公网 HTTP 无法完成 OAuth 回调;对话若按 gateway 注入会得到空工具表。改为粘贴 Key,harness 走内部 HTTP 聚合五个 MCP。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 17:50:19 +08:00
jubaoliangandCursor 49bceee5d2 fix(desktop): write NSIS version defines via Python, avoid PowerShell $vars
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 02:34:07 +00:00
jubaoliangandCursor 58d960e37a fix(ci,security): retry NSIS install and harden CodeQL hotspots
Retry Chocolatey NSIS with SourceForge fallback; rebuild safe_request URL after validation; use hostname checks in Codex OAuth tests; stop exposing polish exception text.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 02:17:41 +00:00
jubaoliangandCursor f6a20b713f fix: NSIS pep440 VI version, experts empty guide, CodeQL URL hostname checks
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-23 01:09:27 +00:00
jubaoliangandCursor d46ba606d1 chore: release 1.0.2b1
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 15:05:49 +00:00
jubaoliangandCursor c7f828676e feat(dashboard): unify empty guides with Tasks-like plain style
Align skill packages, knowledge bases, browser, and desktop idle tips
with borderless layout and shared mascot sizing; move desktop Check/
Connect into the guide; and use Route for chat model Auto to avoid the
skills Sparkles collision.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 22:31:51 +08:00
jubaoliangandCursor 69f31656c3 feat(chat): add per-thread HITL allow policy
Keep tool-approval bypass on the conversation (allow this tool / allow all)
without changing global security settings. Also let expert create carry
welcome quick prompts, and replace the login forgot-password tip with a
platform-specific CLI dialog.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 17:14:28 +08:00
jubaoliangandCursor f5a6404a83 feat(chat): add + menu to open dock panels while right rail is hidden
When the chat dock is open the floating workspace/browser/terminal
buttons disappear; expose the same actions from a title-bar + menu and
keep the popup mask from closing while that menu is open.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 16:41:03 +08:00
jubaoliangandCursor 7bb2ae2e2d fix(backup): include .octop and runtime dirs in workspace zip export
aglob("**/*") skips hidden paths, so downloads only packed a few root files.
Walk the local tree (and als/aglob fallbacks) so archives include the full workspace.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 13:10:19 +08:00
jubaoliangandCursor c81bd7295f fix(chat): make composer mode and model triggers icon-only
The 32px buttons were clipping selected labels. Match the other toolbar icons, keep the selection in the tooltip, and show provider logos in the model picker.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 11:26:24 +08:00
jubaoliangandCursor 04ac1835b0 fix(experts): keep public portrait when publishing without upload
Snapshot avatars only cover custom uploads; persist bundled/remote icon_url in the manifest so published cards no longer fall back to the default Lucide icon.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-22 10:49:47 +08:00
jubaoliangandCursor f951aadf3b feat(dashboard): put chat workspace in the dock and point help to octop.cloud
Open workspace in the same right/bottom/popup tabs as browser and file
changes, and send Help & Feedback to https://octop.cloud.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 21:15:31 +08:00
jubaoliangandCursor bf1f95e7b8 fix(dashboard): collapse login forgot-password CLI tip
Keep the login form quiet: show a Forgot password? control first, then
expand admin-first help with the host CLI command as secondary detail.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 14:14:31 +08:00
jubaoliangandCursor f843e5f704 feat(experts): compose prompts and skills when creating experts
Allow editing AGENTS.md, picking marketplace or other-expert skills, and
adding subagents in the create/edit drawers. Default is a blank AGENTS.md
template; marketplace or copy failures warn instead of aborting create.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 12:59:17 +08:00
jubaoliang b46bb8a480 fix(db): 写事务改用 BEGIN IMMEDIATE,避免多进程下「先读后写」被中止
Merged from #888.
2026-09-21 03:04:50 +00:00
jubaoliang 9fac342e47 fix(auth): tell locked-out users how to reset a password (#869)
Merged from #880.
2026-09-21 03:03:58 +00:00
jubaoliang fcb49d31fb fix(pwa): stop iOS status bar from frosting page content (#874)
Merged from #878.
2026-09-21 03:03:41 +00:00
jubaoliang 4510f25dc9 fix(knowledge): decode GBK text documents instead of mojibake
Merged from #879.
2026-09-21 03:03:24 +00:00
jubaoliang 32dce2d2b8 fix(dashboard): refresh agent context after saving runtime config
Merged from #882.
2026-09-21 03:03:08 +00:00
jubaoliang 06f632ec59 fix(hitl): stop dashboard ask cards from reappearing (#782)
Merged from #877.
2026-09-21 03:02:52 +00:00
jubaoliang aba6b0bb8f fix(knowledge): 远程 OCR 的「请上传图片」拒绝提示不再作为正文入库
Merged from #867.
2026-09-21 03:02:35 +00:00
jubaoliang c7919ff22e fix(env): 含换行的环境变量值在保存/读取往返中被截断
Merged from #881.
2026-09-21 03:02:17 +00:00
jubaoliang f0917aefb6 fix(cron): cron 触发按配置时区执行,而非宿主系统时区
Merged from #864.
2026-09-21 03:02:00 +00:00
jubaoliangandCursor e446463bb9 fix(chat): omit skills group from shortcut picker
Skills already have a dedicated picker; keep the quick-command popover to slash commands only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-21 07:40:51 +08:00
jubaoliangandCursor ae62ec3088 fix: LAN MCP HTTP、TLS 公网 IP 预检与 Models 侧栏抽屉
允许本机/局域网 MCP 使用 HTTP 并返回结构化错误码;TLS 预检优先走云元数据与国内可达 IP 探测;send_file 工具错误不再误判为模型故障;模型配置弹窗改为右侧抽屉。

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-20 20:00:39 +08:00
jubaoliangandCursor 005d6d195f fix(changelog): remove conflict markers left by #746 squash
Move the iOS safe-area note to Unreleased and restore the 1.0.1 fix list.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-19 13:22:38 +00:00
jubaoliangandCursor ae43484894 fix(dashboard): normalize lockfile to registry.npmjs.org
Tencent mirror resolved URLs plus replace-registry-host=always made CI
fetch registry.npmjs.org/npm/<pkg> and 404 on Release npm ci.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-19 01:31:07 +00:00
jubaoliangandCursor 4fcd40edc0 chore: merge main into release/1.0.1
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-18 16:16:05 +00:00
jubaoliangandCursor 07f4e66483 chore: sync uv.lock version to 1.0.1
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-18 16:14:00 +00:00
jubaoliangandCursor f5264e5a29 chore: release 1.0.1
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-18 16:12:00 +00:00
jubaoliangandCursor 5e7a8ba956 feat: container FS defaults, expert portraits, chat HITL/skills UX
Ship a coordinated polish pass: container-aware workspace roots, SkillHub
UTF-8 repair and expert avatars, safer HITL resume/queue behavior, friendlier
skill slash tokens, and catalog “show more” UX with harness bumps.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-19 00:00:30 +08:00
jubaoliangandCursor d2ee5db833 fix(dashboard): keep open-browser chip from stretching; bump harness-browser
Stop .openBrowserPrompt from filling the message column under the turn
grid, and raise the harness-browser floor to >=0.7.9 for the Windows CDP
profile writability fixes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-18 09:58:06 +08:00
jubaoliangandCursor 7df8fa348d feat(dashboard): tools tabs with ACP, restore ACP nav, tighten card grids
Move ACP into Personalization → Tools as a sub-tab alongside built-in and
plugin tools, while restoring the standalone Control ACP sidebar page so
both surfaces stay available. Also leave scrollbar clearance on card-list
scrollers and tighten horizontal card gaps across dashboard grids.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-18 09:57:52 +08:00
jubaoliangandCursor 16cd11faf4 chore: release 1.0.0
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-14 01:43:23 +00:00
jubaoliangandCursor 12785f7751 fix(backup): list large archives without full tar scan
Peek only the first tar member for manifest flags and run list_backup_files
off the event loop so Backup/Restore stays responsive with multi-GB files.

Closes #674

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-14 09:41:42 +08:00
jubaoliangandCursor b3edf893ab feat(update): default to stable-only checks with optional pre-releases
Keep automatic update reminders on the latest stable release, pin upgrades
to the confirmed version, and require --allow-prerelease for CLI beta installs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-14 09:40:32 +08:00
jubaoliangandCursor 0c7420d93a chore: sync uv.lock for 0.9.35
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-13 17:07:55 +00:00
jubaoliangandCursor 0b439913fc chore: release 0.9.35
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-13 17:05:31 +00:00
jubaoliangandCursor cbcf57de91 chore: release 0.9.34
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 15:31:15 +00:00
jubaoliangandCursor 08814ecffa fix(chat): restore history timestamps and align user bubbles
Refresh dropped message times because live projection never copied
checkpoint_ts. Stamp the current turn, fall back to created_at, keep
the user avatar lined up with the text bubble, and move copy/edit
beside the timestamp. README now matches shipped knowledge, plugin,
and PostgreSQL surfaces.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 22:45:23 +08:00
jubaoliangandCursor b1f267f7c1 feat(chat): hang sender avatars beside a composer-aligned column
Keep message bodies on the 960px input track and place expert/user
avatars in extra side gutters, with one expert avatar per turn.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 20:54:02 +08:00
jubaoliangandCursor 0bdf7f4d14 feat: persist failed chat turns and add expert task examples
Keep partial tokens and stream errors in thread history after a stop or
provider failure, and drive cron empty-state cards from manifest
task_examples. Backup skips stale workspace paths instead of creating them.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-12 19:05:32 +08:00
jubaoliangandCursor fb76f44a47 chore: release 0.9.33
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-11 02:36:35 +00:00
jubaoliangandCursor fcf23bdca4 feat: apply resource policy on user create and require cron job names
Admins can set storage-root and token quota when creating a user, and
cronjob_create now requires a display name with prompt-prefix fallback.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-11 10:26:17 +08:00
jubaoliang 5b6c91302c feat: expert composer defaults (KB + MCP) and per-user policies
Allow experts and skill packages to carry composer defaults so that
installed/created agents start with the author's chosen knowledge bases
and MCP servers. Defaults are persisted as agent profile columns and
validated against the installing user. Adds the per-user policy resource
table (migration 014) and wires the dashboard composer fields plus
locale strings.

- Add knowledge_base_ids and mcp_servers to the agent profile schema
- Validate KB/MCP ids on expert/skill-package install and create paths
- Persist defaults via migrate.py helper and 014_user_policy migration
- Surface composer default fields in the dashboard expert/skill UI
2026-09-11 02:00:01 +08:00
jubaoliangandCursor 17b3b65308 feat(dashboard): open skill/KB editors in a drawer and move list actions into more menus
Create and edit skill packages and knowledge bases from a right drawer. Move edit/delete onto each list card, and let knowledge bases attach into the current chat.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 17:47:18 +08:00
jubaoliang 52bad9c4d0 feat(users): per-user resource policies (workspace root + token quota) and slash parser
Add a `user_policies` table (migration v14) backing per-user `workspace_root_dir`
(restricts local backend roots) and `token_quota` (lifetime token limit). Token
quota is enforced in the agent runtime via TokenQuotaMiddleware. Extract slash
command parsing into infra/gateway/slash/parser.py and expose policies on the
users API. Frontend adds admin policy UI, storage/chat/experts restyle, and a
shared TabLabel / PageLoading component.
2026-09-08 14:21:28 +08:00
jubaoliang 2fd3a5de7a feat: add Didi connector, improve upgrade progress reliability
- Add Didi (滴滴) MCP connector: catalog entry, remote spec builder,
  credential validation, and dashboard logo asset.
- Report upgrade progress while the upgrade task runs (backend polls
  the task with a timeout loop instead of blocking silently) and
  retry the frontend progress poll a few times before surfacing an
  error, instead of failing on the first transient fetch error.
- Desktop launcher: detect when the bundled portable runtime is newer
  than the installed one and replace it in place (extract to a
  side-by-side dir, swap, keep a previous copy for rollback on
  failure) instead of only extracting on first launch.
- Fix wording in sync-main-to-develop.yml (sync direction was
  described backwards: "develop onto main" -> "main into develop").
2026-09-07 09:04:29 +08:00
jubaoliangandCursor 1c23cc86ec chore: release 0.9.32
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-06 03:56:36 +00:00
jubaoliangandCursor 3358d01542 fix(backup): restore old archives after schema changes without 500s
Migrate immediately after overlay and repair folded v13 connectors schema so existing backups stay usable. Refuse newer schema versions with BACKUP_SCHEMA_INCOMPATIBLE. Also drop the knowledge-bases Beta nav badge.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-06 11:43:15 +08:00
jubaoliang d9a0e5fad3 chore: misc unrelated fixes 2026-09-06 10:30:40 +08:00
jubaoliang a90388d573 feat(experts): add catalog display metadata to bundled skills 2026-09-06 10:30:40 +08:00
jubaoliang c62ec8e945 feat(plugins): add per-agent plugin toggle, move plugin config to Personalization 2026-09-06 10:30:40 +08:00
jubaoliang 1a12948c21 feat(storage): add OpenSandbox remote sandbox storage backend 2026-09-06 10:30:40 +08:00
jubaoliang 05b7548284 feat(connectors): support multiple connector instances and shared connectors 2026-09-06 10:30:40 +08:00
jubaoliang 61f4ba6354 feat(settings): move voice and search settings under models page
- Relocate voice and search engine settings from Advanced to Models
  page/permission category (nav, routes, permission gates).
- Add /admin/voice/providers/test-configuration endpoint and
  VoiceManager.test_configuration() to probe unsaved provider values
  before saving.
- Redirect legacy /admin/advanced?tab=voice|search links to the new
  Models page location.
2026-09-05 11:09:07 +08:00
jubaoliang fa2f6a7f56 feat(browser): isolate harness-browser profiles per Octop user
Replace the legacy shared/default Playwright session router with
per-user harness-browser profiles (`user-<id>`) so concurrent users no
longer share one Chrome session, cookie jar, or recording. The backend
now always derives the profile from the authenticated user (or the IM
thread's agent owner) instead of trusting client-supplied profile/session
ids, and a BrowserProfileMiddleware pins tool-selected profiles to the
same boundary. Also dedupes ThreadRegistry's session-refresh logic.
2026-09-05 08:35:26 +08:00
jubaoliang 118bad5c24 feat: optimize AskQuestionCard UI and knowledge parsing 2026-09-04 17:26:06 +08:00
jubaoliang 3d61e9bf85 feat: add agent trajectory recording + make CronJobs name column non-bold 2026-09-04 15:22:29 +08:00
jubaoliangandCursor f5875837a3 style(desktop): apply Ruff formatting to portable launch scripts
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-04 11:13:47 +08:00
jubaoliangandCursor 515f601838 perf(trajectory): bound live stream persistence overhead
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-03 12:59:13 +00:00
jubaoliangandCursor 8401f892da feat(knowledge): expand document formats, add optional OCR, and show upload progress
Parse more text and spreadsheet types, add optional local/remote OCR for images and scanned PDFs, and surface upload progress so indexing no longer appears stuck.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-03 20:03:21 +08:00
jubaoliangandCursor 3695bac224 feat(dashboard): keep token usage stats on one row
Hide overflowing metric cards behind a more menu on desktop so the summary row no longer wraps.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-03 20:02:54 +08:00
jubaoliangandCursor f810664206 feat(chat): show human-readable HITL approval cards
Replace raw JSON tool-approval dumps with localized summaries, an attention icon, and message-consistent spacing.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-03 18:04:25 +08:00
jubaoliangandCursor 064f957782 feat(backup): let users choose archive contents and keep omitted data
Default backups skip chat history so archives stay smaller. Restore only
replaces packed config, workspaces, skill packages, plugins, and knowledge
files, and preserves live chats when they were not included.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-03 17:59:02 +08:00
jubaoliangandCursor f3d301f92c feat(dashboard): replace antd Spin with OctopSpinner globally
Match the boot-splash loading ring on first paint, and hyphenate the octop-assistant skill name.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-03 17:58:41 +08:00
jubaoliangandCursor 31215950f9 fix(mobile): write daemon.json and restart Docker via sudo when not root
Passwordless sudo can install the engine, but /etc/docker/daemon.json and
systemctl restart still need elevation; otherwise the Tencent mirror step
silently skips.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-02 09:33:30 +00:00
jubaoliangandCursor 6f286aad3e Merge pull request #511 from miaowmint/feat/auto-install-docker
feat(mobile): auto-install Docker for Android container backend

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-02 09:24:47 +00:00
jubaoliangandCursor c1b7ba36ea Merge pull request #533 from huangcheng/fix/log-size-rotate-delaycompress
fix(logging): size-cap rotation and logrotate delaycompress

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-02 09:20:39 +00:00
jubaoliangandCursor 9ac0dd962f fix(desktop): keep dock chrome clear of window controls
Reserve a toolbar spacer so right-dock and popup actions no longer sit
under frameless caption buttons, hide the PWA install entry inside the
Wails shell, restyle the splash as a card with a progress bar, and add
Windows settings-window height so DWM does not clip the bottom inset.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-02 17:15:54 +08:00
jubaoliangandCursor cea720fcbb fix(ci): unify desktop and portable release artifact names
GitHub Release assets mixed unversioned Octop-<plat>.zip with Octop-Desktop-*
and PEP wheels. Name public files Octop-<kind>-<os>-<arch>-<version>.<ext>,
gzip the Linux desktop tarball, and keep the zip payload directory plus the
macOS .app Resources name stable so the Wails shell still unpacks them.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-02 11:19:20 +08:00
jubaoliangandCursor 51d5e49247 fix(ci): repair FnOS workflow parse error and stop re-running CI per release
The FnOS FPK workflow kept a stray env block when the rolling-release step was
removed, so GitHub rejected the whole file and Release's dispatch failed with
"'env' is already defined" — silently, because that job is continue-on-error.

CI also ran the full suite three times per release (release PR, main push, sync
PR) on identical trees. Drop the main push build, since PR checks already run on
the merge result, and skip the post-release sync PR, which is auto-merged before
its checks even start.

Release now passes the tag to the sync workflow so the branch is named after the
version instead of the constant "manual", which every release force-pushed over.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-02 10:29:31 +08:00
jubaoliangandCursor 3b725c326d chore: sync uv.lock version to 0.9.31
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-01 13:13:03 +00:00
jubaoliangandCursor c2d35feff2 chore: release 0.9.31
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-01 13:11:20 +00:00
jubaoliangandCursor e81ccc19f8 feat(chat): expand process summary while streaming
Keep thinking/tool process open during live generation so users can follow it, then collapse when the turn finishes. History stays collapsed.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-01 21:08:29 +08:00
jubaoliang 97adaf5941 fix(mobile): use posix_compat.geteuid for cross-platform mypy
os.geteuid() does not exist on Windows, breaking mypy in CI. Reuse the existing octop.infra.utils.posix_compat.geteuid() shim like the rest of the codebase.
2026-09-01 12:08:48 +00:00
jubaoliangandCursor b92d3ed8b2 fix(desktop): restore frameless window drag without blocking title-bar clicks
The dashboard is loaded from a remote origin, so Wails never injects
runtime.js. Arm wails:drag ourselves, put window controls on the right, and
drop InvisibleTitleBarHeight. Expert profile skill/subagent cards now show
the icon beside the title, with status or slug on the same row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 21:34:44 +08:00
jubaoliang e91521a029 fix(ci): rename FnOS fpk to Octop-fnos-{docker,native}-<ver> and drop rolling latest
- scripts/build-fpk.sh: emit Octop-fnos-docker-<ver>.fpk / Octop-fnos-native-<ver>.fpk (variant in the name, not a bare -native suffix).
- fnos-build-fpk.yml: FPK_NAME_PREFIX is now Octop-fnos; stop passing FPK_ITER; the release tag is fnos-<ver> (no -NN iteration, no -vanilla) and the rolling fnos-vanilla-latest release is no longer produced.
- fnos/README.md: document the new versioned artifact names.
2026-08-31 18:33:25 +08:00
jubaoliang d7a09f0c58 fix(desktop): set macOS invisible title bar height for frameless window
Configure MacWindow.InvisibleTitleBarHeight (32px) on the frameless desktop
window so macOS keeps a draggable region beneath the custom title bar.
Only affects the macOS build; other platforms are unchanged.
2026-08-31 17:12:58 +08:00
jubaoliang 3f2aec191a fix: serve 404 for stale hashed assets and harden desktop shell
- api: answer a missing /assets/<hash>.js with 404 instead of the SPA
  shell, so the browser no longer rejects index.html as a module script
  ("not a valid JavaScript MIME type") and hides a stale shell left
  behind by an upgrade.
- dashboard: extend the stale-chunk reload regex to also match MIME
  rejection errors surfaced by WebKit / Chrome / Firefox.
- desktop: split the macOS icon onto an 824/1024 canvas (icons.icns) and
  add applyAppIcon / applyTrayIcon so the Dock glyph is not oversized.
- agents: hand harness an absolute workspace_dir on Windows, where the
  agent-facing /.octop/workspaces/<id> form has no drive letter.
2026-08-31 04:47:45 +00:00
jubaoliangandCursor edca8236e7 fix: silence CodeQL oauth log and HITL selection ReDoS
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 02:40:19 +00:00
jubaoliangandCursor b767016a5b chore: merge main into release/0.9.30
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 02:34:28 +00:00
jubaoliangandCursor 3a3282af22 chore: merge develop into release/0.9.30
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 02:28:37 +00:00
jubaoliangandCursor 5abfafb012 docs: update 0.9.30 changelog for develop follow-ups
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-31 02:08:04 +00:00
jubaoliang c6a49bff26 chore: merge develop into release/0.9.30 2026-08-31 02:07:52 +00:00
jubaoliangandCursor 8e70633771 chore: release 0.9.30
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-30 13:58:15 +00:00