Goon
cd7c812b3d
fix(cron): suppress no-reply deliveries by token
2026-06-13 09:01:56 +07:00
Goon
3ec20dfb55
fix(cron): wait for in-flight jobs on shutdown
2026-06-12 22:44:45 +07:00
Goon
25b039dbe9
feat(skills): add bundled goclaw gateway skill
2026-06-12 22:17:41 +07:00
Duy /zuey/ and GitHub
4f87b93dbd
feat: add qwen3.7-plus to Bailian Coding catalog
...
Closes #169
2026-06-12 17:57:48 +07:00
Goon
9cd57a920c
feat: add multi-attachment delivery batching
2026-06-12 17:33:54 +07:00
Goon
7692939d09
Merge remote-tracking branch 'origin/dev' into codex/issue-161-skill-self-evolution
...
# Conflicts:
# cmd/skills_cmd.go
# docs/project-changelog.md
# internal/http/skills.go
# internal/store/sqlitestore/schema.go
2026-06-12 14:57:09 +07:00
Goon
fa79693b5d
Merge remote-tracking branch 'origin/dev' into codex/issue-161-skill-self-evolution
...
# Conflicts:
# docs/project-changelog.md
2026-06-12 14:48:55 +07:00
Goon
f45bfa860c
feat(skills): add skill self-evolution metrics
2026-06-12 14:47:51 +07:00
Goon
569e946e43
fix: resolve issue 159 dev merge conflict
2026-06-12 14:42:48 +07:00
Goon
0bf7f88054
feat(skills): add lifecycle API and CLI
2026-06-12 10:38:53 +07:00
Goon
e2c0398ec9
feat(cli): add trace operator commands
2026-06-12 09:48:01 +07:00
Duy /zuey/ and GitHub
8d664954e6
Merge pull request #156 from digitopvn/codex/issue-137-mid-flight-requests
...
fix(pipeline): preserve mid-flight follow-up requests
2026-06-12 00:36:28 +07:00
Goon
152b2ac0f7
fix(pipeline): preserve mid-flight follow-up requests
2026-06-12 00:28:00 +07:00
Duy /zuey/ and GitHub
167b80e778
feat(traces): add search and advanced filters
...
Closes #152
2026-06-12 00:14:40 +07:00
Duy /zuey/ and GitHub
9203782ae3
fix(tools): fail closed on github cli credentials ( #154 )
2026-06-11 23:57:56 +07:00
Goon
59a1773a18
Merge remote-tracking branch 'origin/dev' into codex/merge-nextlevelbuilder-goclaw
2026-06-09 22:49:30 +07:00
Goon
a63080714a
Merge remote-tracking branch 'upstream/dev' into codex/merge-nextlevelbuilder-goclaw
...
# Conflicts:
# internal/pipeline/think_stage.go
# internal/pipeline/tool_stage.go
# tests/integration/git_adapter_ssh_test.go
2026-06-09 22:38:32 +07:00
Duy /zuey/ and GitHub
fdba1c2138
feat(channels): add sidecar delivery behavior overrides
...
Closes #144 .
- Retire user-facing Tool Status Messages and deterministic tool-status channel text.
- Add sidecar-generated Quick Acknowledgement and Intermediate Replies with provider/model/timeout/token/char caps.
- Resolve delivery behavior as Channel > Agent > Workspace with agent overrides in other_config.delivery_behavior.
- Preserve legacy block_reply defaults for Intermediate Replies.
2026-06-09 22:24:24 +07:00
Duy /zuey/ and GitHub
23b18fa6cd
fix(channels): rely on generated intermediate progress ( #143 )
...
* fix(channels): add reasoning delivery modes
* fix(telegram): show tool status without placeholder
* docs(plans): mark issue 67 behavior plan complete
* feat(config): add behavior setting purpose tooltips
* fix(channels): rely on generated intermediate progress
2026-06-09 09:12:23 +07:00
43837afca3
fix(security): consolidate & enhance batched security fixes ( #1155 , #967 , #972 , #974 , #989 , #973 ) ( #1185 )
...
* fix(sandbox): avoid shell in FsBridge writes
Replace sh -c with interpolated path by shell-free 'tee -- <path>' argv form,
piping content via stdin. Prevents command injection through filenames
containing shell metacharacters inside the sandbox container.
Co-authored-by: evgyur <evgyur@gmail.com >
* fix(security): fail-closed on pairing DB errors across channels
On IsPaired lookup error, deny instead of granting access. Covers the shared
CheckDMPolicy/CheckGroupPolicy helpers (Slack/Discord/Feishu/WhatsApp/Zalo) and
the four inline Telegram pairing checks.
Co-authored-by: Srini <srinis.k@gmail.com >
* fix(security): harden provider URL validation against SSRF
Enforce scheme check for all provider types; restrict local types (ollama,
claude_cli, acp) to an explicit localhost allowlist instead of skipping checks;
resolve remote hostnames and reject any IP in a private/reserved range via the
shared security.IsBlocked CIDR list (covers loopback, link-local, metadata,
multicast, and unspecified 0.0.0.0/::). Closes the wildcard-DNS bypass and the
local-type escape hatch. Operator opt-in via GOCLAW_ALLOW_PRIVATE_PROVIDER_URLS.
Exports security.IsBlocked as the single source of truth for blocked ranges.
Co-authored-by: Linh Vo Van <linh.vo@e-cq.net >
* feat(pipeline): add fail-closed tool call authorization gate
Gate tool execution against the server-side AllowedTools allowlist built from the
RBAC/tenant-aware filtered tool set. Resolve the tool-call prefix before the
allowlist lookup so prefixed agents are not wrongly blocked, re-check deny on lazy
MCP activation, and expand IsDenied to cover aliased tool names.
Co-authored-by: Huy Doan <tui@pm.me >
* fix(security): expand file-serve deny-list defense-in-depth
Add absolute-path deny prefixes (/home, /Users, /srv, /var/lib, /var/www, /opt)
and an explicit fail-closed log when no file-serving boundary is configured.
Co-authored-by: Linh Vo Van <linh.vo@e-cq.net >
* fix(providers): allow claude cli executable paths
Refs: #1185
---------
Co-authored-by: evgyur <evgyur@gmail.com >
Co-authored-by: Srini <srinis.k@gmail.com >
Co-authored-by: Linh Vo Van <linh.vo@e-cq.net >
Co-authored-by: Huy Doan <tui@pm.me >
2026-06-05 00:48:38 +07:00
Duy /zuey/ and GitHub
53ef912441
fix(channels): add reasoning delivery modes ( #135 )
2026-06-03 11:01:14 +07:00
Duy /zuey/ and GitHub
3e7876a4b4
fix(ci): avoid zuey release asset race ( #129 )
2026-05-31 22:37:08 +07:00
Duy /zuey/ and GitHub
64c02ea5a6
ci: speed up zuey beta deploy ( #127 )
...
* ci: speed up zuey beta deploy
* ci: mark issue 88 plan complete
2026-05-31 21:47:28 +07:00
Duy /zuey/ and GitHub
94cbaa9f0f
fix(pipeline): recover truncated codex runs ( #126 )
...
* fix(pipeline): recover empty truncated codex responses
* fix(providers): continue fallback after content policy errors
2026-05-31 21:07:48 +07:00
Goon
02d7b6f3de
fix: stabilize agent git access
2026-05-31 19:42:05 +07:00
Goon
a8afed2a81
fix(channels): announce tools before execution
2026-05-31 19:29:49 +07:00
Goon
1f40047583
fix(channels): gate initial intermediate replies
2026-05-31 18:10:12 +07:00
Duy /zuey/ and GitHub
10e663f21d
Merge pull request #120 from digitopvn/codex/issue-117-agent-scoped-git-credentials-plan
...
feat(cli-credentials): add agent-scoped git credentials
2026-05-31 17:40:50 +07:00
Goon
994acfe3a4
feat(cli-credentials): add agent-scoped git credentials
2026-05-31 16:49:23 +07:00
Goon
32273f04d3
feat(channels): use generated quick ack progress
2026-05-31 16:19:23 +07:00
Goon
d78f97b9d7
feat(channel-memory): merge dev for passive extraction
2026-05-31 14:01:29 +07:00
Duy /zuey/ and GitHub
2cd750ac44
feat(channels): add context capability admin surface
...
Squash merge PR #115 after resolving changelog and SQLite migration-map conflicts with current dev. Renumbered channel-context PostgreSQL migration to 000075 and bumped PG required schema to 75 plus SQLite schema to 44 so it follows the run timeline migration. Local checks passed: go test ./..., go build ./..., go build -tags sqliteonly ./..., go vet ./..., and pnpm -C ui/web build. PR CI run 26705617311 passed release-versioning, go, and web.
2026-05-31 13:50:31 +07:00
Duy /zuey/ and GitHub
2a523e3f97
feat: add group chat context prompt
...
Squash merge PR #114 after resolving changelog and pipeline input conflicts with current dev. Local checks passed: go test ./internal/agent ./cmd ./internal/channels/..., go build ./..., go build -tags sqliteonly ./..., and go vet ./.... PR CI run 26705332779 passed release-versioning, go, and web.
2026-05-31 13:35:04 +07:00
Duy /zuey/ and GitHub
269e2618ae
feat: add archived run timeline
...
Squash merge PR #113 after resolving the project changelog conflict with current dev. Local checks passed: Go store/http/gateway/agent/pipeline tests, SQLite-tagged tests, both Go builds, web Vitest, and web build. PR CI run 26705098712 passed release-versioning, go, and web.
2026-05-31 13:22:07 +07:00
Duy /zuey/ and GitHub
990fabf94b
fix(config): persist shell deny group disables
...
Squash merge PR #112 after resolving the project changelog conflict with current dev. Local checks passed: config gateway tests, provider/http/tools deny-pattern tests, go build ./..., and go build -tags sqliteonly ./.... PR CI run 26704832350 passed release-versioning, go, and web.
2026-05-31 13:08:24 +07:00
Duy /zuey/ and GitHub
9ab3d6dfe5
feat(tools): local-first document extraction for read_document
...
Squash merge PR #111 after resolving docs/changelog conflicts. Local checks covered tools/config and both Go builds; PR CI run 26704622503 passed release-versioning, go, and web.
2026-05-31 12:55:38 +07:00
Duy /zuey/ and GitHub
80893a1e6c
feat(skills): add selected skill downloads
...
Squash merge PR #110 after resolving dev changelog conflict. Local checks covered Go http/store, full web test/build; PR CI run 26704448786 passed release-versioning, go, and web.
2026-05-31 12:44:29 +07:00
Duy /zuey/ and GitHub
1d9436350d
fix(discord): backfill thread history attachments
...
Squash merge PR #106 after resolving dev changelog conflict. PR CI run 26704244687 passed release-versioning, go, and web.
2026-05-31 12:33:15 +07:00
Duy /zuey/ and GitHub
df8a03df48
fix: allow skill_manage companion files
...
Squash merge PR #104 after validation.
2026-05-31 12:24:22 +07:00
Duy /zuey/ and GitHub
484bcc7b71
fix: harden parallel tool scheduling
...
Squash merge PR #103 after validation.
2026-05-31 12:24:00 +07:00
Duy /zuey/ and GitHub
4de94c1d7c
fix(telegram): repair voice transcription routing
...
Squash merge PR #102 after resolving dev changelog conflict. PR CI run 26704061639 passed release-versioning, go, and web.
2026-05-31 12:23:40 +07:00
Duy /zuey/ and GitHub
cf66bda618
fix(rapidapi): add cron credential diagnostics
...
Squash merge PR #101 after resolving dev conflicts and fixing cron GetJob snapshot race. PR CI run 26703877225 passed release-versioning, go, and web.
2026-05-31 12:13:14 +07:00
Duy /zuey/ and GitHub
4ed4eb9509
fix(sandbox): isolate tenant workspace mounts
...
Squash merge PR #100 after resolving changelog conflict with current dev. PR CI run 26703558537 passed release-versioning, go, and web.
2026-05-31 11:55:10 +07:00
Duy /zuey/ and GitHub
f0f39ce31f
feat(channels): add human-like chat behavior
...
Squash merge PR #99 after resolving conflicts with current dev. PR CI run 26703381807 passed release-versioning, go, and web.
2026-05-31 11:44:56 +07:00
Duy /zuey/ and GitHub
361f2abbf5
fix(packages): use writable scratch dir for github updates
...
Squash merge PR #97 after resolving changelog conflict with current dev. PR CI run 26703171763 passed release-versioning, go, and web.
2026-05-31 11:33:12 +07:00
Duy /zuey/ and GitHub
c4e0bd2be5
fix(cli-credentials): stabilize git preset creation
...
Squash merge PR #96 after PR #92 . PR checks were green; dev beta CI will be monitored after merge.
2026-05-31 11:05:47 +07:00
Goon
34bb6121b8
feat(channel-memory): document passive extraction
2026-05-29 20:48:45 +07:00
Goon
697aa266e0
feat(channels): document context admin surface
2026-05-29 19:43:06 +07:00
Duy /zuey/ and GitHub
f771cff77c
fix(channels): coalesce multi-attachment inbounds ( #63 ) ( #90 )
...
Implements 3 coalescing layers to handle rapid multi-attachment inbounds:
- Bus debouncer: delays inbound messages 1s, merges duplicates
- Web chat debouncer: buffers client-side inbound frames for batch RPC
- Telegram album aggregator: collects album members via AfterFunc+Stop timer
Drops media-bypass shortcut (forces 1s media floor). Aggregator enforces:
- AfterFunc+Stop timer discipline with ordered drain on stop
- 2-tuple (album_id, sender) keying for isolation
- Dual DoS caps: max 10 albums per sender, max 100 messages per album
- merged_message_ids dedup seeding across all 3 surfaces
Closes #63
2026-05-28 18:30:34 +07:00
Duy /zuey/ and GitHub
a591473546
feat(secure-cli): CLI credential adapters framework + git adapter ( #82 ) ( #89 )
...
* feat(secure-cli): Phase 1 schema + storage delta (issue #82 )
Adds `adapter_name` column to secure_cli_binaries and `credential_type` + `host_scope` columns to secure_cli_user_credentials. LookupByBinary LEFT JOIN now projects AdapterName, UserCredentialType, and UserHostScope. Extends SecureCLIStore with SetUserCredentialsTyped(ctx, binaryID, userID, env, credType, hostScope); legacy SetUserCredentials delegates to typed variant with nil/nil for backward compat.
PG migration 73 + RequiredSchemaVersion bumped to 73. SQLite incremental migrations (versions 39–41) + SchemaVersion 42. 7 SQLite + 6 PG integration tests covering schema, round-trip, NULL legacy, LookupByBinary projection.
Fixes #82
* feat(secure-cli): Phase 2 CredentialAdapter framework + passthrough (issue #82 )
Adds CredentialAdapter interface + Injection{ArgvPrefix,Env,Cleanup,ScrubValues} struct. Registry resolves by name; falls back to passthrough for empty/unknown. passthroughAdapter is default no-op — all existing presets (gh/aws/gcloud/kubectl/terraform/gws) behave bit-for-bit identically.
Per-request WithScrubBag(ctx) + AddScrubValuesCtx + ScrubCredentialsCtx for multi-tenant secret isolation (replaces package-global slice). Hook in executeCredentialed between env merge and exec: resolve adapter by bin.AdapterName, reject non-passthrough in sandbox, call Prepare, splice ArgvPrefix, merge Env, defer Cleanup, register ScrubValues.
Audit log security.system_env_injection records adapter name + env key names + argv_prefix_len + sha256(host_scope) — NEVER values. CLIPreset.AdapterName field added; empty default for legacy presets.
12 unit tests covering passthrough no-op, registry fallback + nil safety, Injection shape, hashHostScope determinism, sortedKeys, scrub bag per-request isolation + concurrent + short-value guard.
Fixes #82
* feat(secure-cli): Phase 2b extensibility helpers + psql stub adapter (issue #82 )
Proves CredentialAdapter framework generalizes beyond git. Adds materializeEphemeral(ctx, content, prefix) shared helper — 0600 tmpfile + idempotent atomic.Bool cleanup latch; memfd intentionally rejected (resolves "self" against child process).
Adds psqlAdapter consuming framework end-to-end via PGPASSFILE pattern; libpq-spec .pgpass escaping for `:` and `\`. Registers psql preset with AdapterName: "psql" (production UI for typed creds lands in v2).
Interface validation gate passes: Injection shape unchanged, hook is psql-agnostic, no special branch needed.
Tests: ephemeral write/cleanup/concurrent/zero-content; psql routing/content/escaping/error paths/registration.
Fixes #82
* feat(secure-cli): git adapter PAT + SSH implementation (issue #82 )
Phase 3 — PAT path
- gitAdapter PAT branch via GIT_CONFIG_COUNT/KEY_0/VALUE_0 env (git 2.31+)
so the token never lands on argv, .git/config, or remote URL
- Host-scope enforcement with IDN normalization (golang.org/x/net/idna)
and embedded-userinfo rejection in URL parsing
- CVE-2018-17456 mitigation: resolve remote URLs via `git config --get`
not `git remote get-url` to dodge ext::sh protocol handler injection
- Case-insensitive DenyArgs blocking `-c http.`, `-c credential.`,
`-c core.sshcommand`, `config --global/--system`, `credential-helper`,
bare `daemon`
- New WithExecCwd / ExecCwdFromContext context helpers — fixes a latent
design gap where the adapter's pre-flight `git config --get` ran in
goclaw's daemon CWD instead of the agent's repo
- 14 unit tests covering subcommand routing, host normalization,
scp-form parsing, userinfo rejection, CRLF token rejection,
CVE-2018-17456 regression, DenyArgs preset coverage
- 3 integration tests against a local TLS git-http-backend server
proving end-to-end clone + fetch + host-mismatch rejection with
zero token leakage into the cloned .git/config
Phase 4 — SSH path
- gitAdapter ssh_key branch materializes per-call 0600 tmpfile via
the Phase 2b materializeEphemeral helper, injects GIT_SSH_COMMAND
with -o IdentitiesOnly=yes -o BatchMode=yes
-o StrictHostKeyChecking=accept-new, idempotent cleanup
- ValidateSSHKey using golang.org/x/crypto/ssh rejects
passphrase-protected keys via ErrSSHKeyPassphraseUnsupported sentinel
- 8 unit tests covering passphrase rejection, env shape, cleanup
lifecycle, host-mismatch reuse, malformed-blob rejection
- 3 integration tests proving tmpfile 0600 lifecycle, env propagation
to child process, cleanup-on-exec-failure, no-orphan-on-rejection
- 2 new i18n keys (en/vi/zh) for SSH-passphrase and SSH-key-invalid
Verification: go vet clean, go build ./... clean,
go build -tags sqliteonly ./... clean, go test -race
./internal/tools/ pass, go test -tags integration
./tests/integration/ -run TestGitAdapter pass.
Refs #82
* feat(secure-cli): UI presets + typed credential HTTP path + i18n (issue #82 )
Phase 5. Typed PUT envelope with {error:{code,message}, error_key} for
field-level errors. CliCredentialGitFields React component (PAT/SSH picker,
host_scope input, CRLF→LF normalization, masked-edit). 17 i18n keys × 3
locales (backend + frontend). i18n parity test.
* feat(secure-cli): audit log schema + adapter framework docs (issue #82 )
Phase 6. emitSystemEnvInjectionAudit helper centralizes
security.system_env_injection slog with host_scope_hash (SHA-256 8 hex,
plaintext hostname omitted for PII safety). Audit shape pinned by
TestEmitSystemEnvInjectionAudit_*. New docs: git-credential-adapter.md
(user guide), credential-adapter-playbook.md (R1 implementer guide w/
kubectl/docker/npm/aws/psql worked mappings). 09-security.md § 14
trust-boundary diagram + SSH TOFU + SIGKILL caveats. 03-tools-system.md
§ 8a. Changelog entry.
* docs(journal): issue #82 CLI credential adapters shipped
Retrospective covering 6 commits across phases 1-6: framework, git PAT/SSH, psql stub, UI/i18n, audit log schema, docs. Notes memfd-drop rationale, TOFU/SIGKILL caveats, sentinel-length lesson from audit-shape tests.
* fix(secure-cli): honor per-request scrub bag on success+failure paths (#82 )
Sandbox and host exec paths called the non-Ctx ScrubCredentials, so
adapter ScrubValues registered into the per-request bag during Prepare
(e.g. GitLab glpat-, Bitbucket app-passwords, Azure DevOps PATs, Gitea
tokens, SSH key tmpfile paths) were ignored on stdout/stderr returned
to the agent. Only the package-global regex pass ran — covering ghp_
but nothing else.
Switch all four exec/sandbox call sites to ScrubCredentialsCtx so the
bag is consulted. Also scrub the slog adapter_cleanup_failed line —
os.Remove errors embed the full tmpfile path.
Add 5 regression tests that pin success path, failure path, negative
control (proves the bag is what catches the sentinel), classic-PAT
sanity, and timeout path no-leak.
Locks AC6 against non-GitHub PAT providers.
* fix(secure-cli): address review-pr #89 findings
- ui/web: SSH key Textarea was 'text-xs' on all viewports, triggering
iOS Safari auto-zoom on focus. Switch to 'text-base md:text-xs' so
mobile renders 16px (no zoom) while desktop keeps compact mono font.
- psql adapter: add on-disk pgpass tmpfile path to ScrubValues. psql
echoes 'could not open password file "<path>"' on IO errors, so
the path needs scrubbing alongside the password. Mirrors the git SSH
adapter pattern. Update test assertion accordingly.
- psql adapter: replace literal 'nil' context with 'context.TODO()'
to silence staticcheck SA1012.
2026-05-28 18:17:49 +07:00