Xubin Ren
731b8fc2ed
fix(models): synchronize canonical runtime selection
2026-08-16 11:50:56 +08:00
Xubin Ren
0a6ee1c539
fix(models): preserve preset rename compatibility
2026-08-16 11:50:56 +08:00
Xubin Ren
c15e6f2a37
fix(models): support atomic preset renames
2026-08-16 11:50:56 +08:00
Xubin Ren
3dc38f6396
refactor(models): unify preset names
2026-08-16 11:50:56 +08:00
Xubin Ren
8dc08853e4
fix(providers): preserve legacy OrcaRouter custom configs
2026-08-16 00:26:51 +08:00
Xubin Ren
656480546b
test(providers): cover OrcaRouter WebUI integration
2026-08-16 00:26:51 +08:00
XiaoHuo888
fd2d419956
feat(providers): add OrcaRouter as a named gateway provider
...
Registers OrcaRouter (https://www.orcarouter.ai ) as a built-in OpenAI-compatible gateway provider mirroring the OpenRouter wiring: registry spec (sk-orca- key prefix, default base URL), ProvidersConfig field, WebUI icon/brand + deferred model list, docs, and tests.
2026-08-16 00:26:51 +08:00
Xubin Ren
5e84055dbb
fix(plugins): verify content at skill read boundary
2026-08-16 00:01:54 +08:00
yu-xin-c
e99b1a11aa
fix(plugins): revalidate cached skill roots
2026-08-16 00:01:54 +08:00
Xubin Ren
2f19068eb0
fix(session): clear file state at deletion boundary
2026-08-15 23:49:20 +08:00
yu-xin-c
42afebb0cb
fix(agent): bound per-session file state
2026-08-15 23:49:20 +08:00
Xubin Ren
ecef2b055d
fix(cron): prevent replay after persistence failure
2026-08-15 23:34:35 +08:00
f10rence
8bdf5ed2b2
fix(cron): keep scheduler alive when job-store persistence fails
...
A single OSError from _save_store() (disk full, permission change, locked
file) escaped _on_timer's try/finally and killed the asyncio timer task,
because _arm_timer() sits outside the block. All scheduled jobs silently
stopped until restart or a manual re-arm via add_job/update_job/remove_job.
Move _arm_timer() into the finally block and guard the whole tick body
(including _load_store, which can persist during agent-binding migrations)
so a transient persistence failure is logged and retried on the next tick
instead of killing the scheduler.
Add test_save_store_failure_does_not_kill_scheduler to cover the failure
path that existing tests (which mock _arm_timer) never exercised.
2026-08-15 23:34:35 +08:00
shen0122
4de728a555
fix(anthropic): treat stream idle timeout as inactivity only, not total time
2026-08-14 23:18:13 +08:00
dajiaohuang
057c5e849b
fix(session): restore state when file-cap archive fails
2026-08-14 11:22:22 +08:00
chengyongru
e226242dfc
fix(session): serialize canonical file access ( #5383 )
2026-08-14 10:32:17 +08:00
Xubin Ren
e3d1819a2b
fix(webui): isolate folder picker environment
2026-08-14 04:03:54 +09:00
Xubin Ren
9703656b25
test(webui): make folder picker tests portable
2026-08-14 04:03:54 +09:00
Xubin Ren
26c9687b80
feat(webui): add native workspace folder picker
2026-08-14 04:03:54 +09:00
Xubin Ren
335808e525
fix(webui): bound restored session previews
2026-08-14 03:46:01 +09:00
Xubin Ren
fd7eb8e046
fix(webui): restore transcript-only session history
2026-08-14 03:46:01 +09:00
Bobby
af582246f1
[Security] exec.allowPatterns shell-chain bypass allows unintended command execution
...
Closes #5306
2026-08-13 11:05:04 +08:00
arcdrake22 and Xubin Ren
0c684c5a99
fix(gemini): preserve imported tool history across model switches
...
Co-authored-by: Xubin Ren <52506698+Re-bin@users.noreply.github.com >
2026-08-13 03:07:37 +09:00
yorkhellen and Xubin Ren
d3382d7e57
fix(exec): guard bare and named-user home paths
...
Co-authored-by: Xubin Ren <52506698+Re-bin@users.noreply.github.com >
2026-08-13 02:50:58 +09:00
Xubin Ren and shixi-li
76f629e925
fix(web): keep credential URLs out of failure logs
...
Co-authored-by: shixi-li <40780706+shixi-li@users.noreply.github.com >
2026-08-13 02:26:22 +09:00
Xubin Ren
5f916bbd3a
fix(web): keep credential redirects away from Jina
2026-08-13 02:26:22 +09:00
shixi-li
31a71d6cd5
fix(web): keep credential-bearing URLs away from the remote Jina reader
2026-08-13 02:26:22 +09:00
chengyongru
edec29e997
feat(providers): support DeepSeek V4 Pro Responses
2026-08-13 01:02:41 +08:00
Xubin Ren and santhreal
01c7323d74
fix(exec): parse shell path boundaries safely
...
Co-authored-by: santhreal <64453045+santhreal@users.noreply.github.com >
2026-08-13 01:53:38 +09:00
Xubin Ren
001a7492c2
fix(exec): guard POSIX double-slash absolute paths
2026-08-13 01:53:38 +09:00
santhreal
6fc0807fbf
fix(tools): handle redirection and grouping delimiters in ExecTool path guard
2026-08-13 01:53:38 +09:00
Xubin Ren and lmzopq
cd7480945b
fix(session): preserve history across storage relocation
...
Co-authored-by: lmzopq <1646888+lmzopq@users.noreply.github.com >
2026-08-13 01:41:10 +09:00
Xubin Ren
d2cbe6536e
fix(session): reject symlinked legacy session migration
2026-08-13 01:41:10 +09:00
李明振
b34f1bd0e8
fix(session): store session history outside the agent workspace
...
Session files lived under <workspace>/sessions/ (since #713 ), which is the
on-disk scope of the agent's filesystem tools. With restrict_to_workspace
enabled, an agent could read_file / list_dir every session transcript —
including other users' or channels' conversations — bypassing the scoped
sessions.py access layer entirely.
Move session storage to ~/.nanobot/sessions/<sha256-of-resolved-workspace>[:16]/,
outside the workspace. Per-workspace isolation (the goal of #713 ) is preserved
via a hash of the resolved workspace path, so different workspaces keep
independent session stores. A one-shot, idempotent migration moves legacy
in-workspace *.jsonl files into the new location at store init.
Scope note: this protects sessions whenever restrict_to_workspace=true. The
default restrict_to_workspace=false leaves read_file unrestricted in general
(not only sessions) and is a separate concern.
Refs #5278
2026-08-13 01:41:10 +09:00
Xubin Ren
edaef4e4f5
fix(cli): isolate management subprocess environments
2026-08-12 21:09:29 +09:00
chengyongru
e455a2b7fa
feat(webui): add MCP management dialog
2026-08-12 18:28:23 +08:00
chengyongru
19997d20bb
refactor: move MCP lifecycle out of AgentLoop ( #5343 )
2026-08-12 17:51:04 +08:00
chengyongru
4b5319b760
feat(webui): add tabbed pane workbench ( #5322 )
2026-08-12 14:45:12 +08:00
chengyongru
1656664a47
test(exec): isolate Windows platform mock
2026-08-12 14:37:27 +08:00
chengyongru
a6193932a0
fix(exec): clean up failed job assignment
2026-08-12 14:37:27 +08:00
chengyongru
bcf5d8a6ed
fix(exec): retain process trees after root exit
2026-08-12 14:37:27 +08:00
yorkhellen and TRAE CLI
d64b84604c
fix(exec): terminate one-shot process trees on cleanup
...
Run one-shot commands in their own process tree and terminate all
descendants after timeout, cancellation, or unexpected failures.
Co-authored-by: TRAE CLI <noreply@bytedance.com >
2026-08-12 14:37:27 +08:00
Xubin Ren
abfcdd481a
fix(cli): validate Windows subprocess environment
2026-08-12 02:57:48 +09:00
LHMQ878
ec3dfb21ba
fix(cli): stop leaking API keys to CLI app subprocesses
...
Installed CLI apps were started with os.environ.copy(), so provider keys
from the parent process were visible to untrusted binaries. Use a minimal
allowlist env matching the shell tool.
Fixes #4783
2026-08-12 02:57:48 +09:00
Xubin Ren
72d3ce6b23
fix(skills): make PNG weather example Windows-safe
2026-08-12 02:48:03 +09:00
Kail Tian
b14ac4c401
fix(skills): make weather workflow Windows-safe
2026-08-12 02:48:03 +09:00
LHMQ878
f5cf4dcd2c
fix(providers): stop writing API keys into process os.environ
...
OpenAICompatProvider already passes api_key into AsyncOpenAI. Mutating
shared os.environ leaked credentials across providers (gateway overwrite
and setdefault first-writer-wins).
Fixes #4784
2026-08-12 02:35:40 +09:00
Wesley Zhang
99e07e138e
fix(tools): reject non-finite number parameters
2026-08-12 02:25:20 +09:00
chengyongru
d45c893f68
fix(webui): surface MCP runtime connection failures ( #5331 )
2026-08-11 23:52:02 +08:00
Xubin Ren
247c474e64
perf(plugins): cache verified skill roots
2026-08-11 20:16:24 +09:00