Compare commits
14 Commits
ci/build-d
...
fix/elevat
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a482845031 | ||
|
|
7481086d74 | ||
|
|
a1ed671636 | ||
|
|
8c47d226ad | ||
|
|
e1942603e9 | ||
|
|
926c2647b8 | ||
|
|
c427f4a2fc | ||
|
|
f99f9a6b64 | ||
|
|
39d8c441eb | ||
|
|
40ef3b5d30 | ||
|
|
390b730b37 | ||
|
|
71457fa100 | ||
|
|
da7a45b3a5 | ||
|
|
15a9c21203 |
143
.github/workflows/docker-release.yml
vendored
Normal file
143
.github/workflows/docker-release.yml
vendored
Normal file
@@ -0,0 +1,143 @@
|
||||
name: Docker Release
|
||||
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- main
|
||||
tags:
|
||||
- "v*"
|
||||
|
||||
env:
|
||||
REGISTRY: ghcr.io
|
||||
IMAGE_NAME: ${{ github.repository }}
|
||||
|
||||
jobs:
|
||||
# Build amd64 image
|
||||
build-amd64:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
packages: write
|
||||
contents: read
|
||||
outputs:
|
||||
image-digest: ${{ steps.build.outputs.digest }}
|
||||
image-metadata: ${{ steps.meta.outputs.json }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ${{ env.REGISTRY }}
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Extract metadata
|
||||
id: meta
|
||||
uses: docker/metadata-action@v5
|
||||
with:
|
||||
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
|
||||
tags: |
|
||||
type=ref,event=branch
|
||||
type=semver,pattern={{version}}
|
||||
type=semver,pattern={{version}},suffix=-amd64
|
||||
type=semver,pattern={{version}},suffix=-arm64
|
||||
type=ref,event=branch,suffix=-amd64
|
||||
type=ref,event=branch,suffix=-arm64
|
||||
|
||||
- name: Build and push amd64 image
|
||||
id: build
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
platforms: linux/amd64
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
cache-from: type=gha
|
||||
cache-to: type=gha,mode=max
|
||||
provenance: false
|
||||
push: true
|
||||
|
||||
# Build arm64 image
|
||||
build-arm64:
|
||||
runs-on: ubuntu-24.04-arm
|
||||
permissions:
|
||||
packages: write
|
||||
contents: read
|
||||
outputs:
|
||||
image-digest: ${{ steps.build.outputs.digest }}
|
||||
image-metadata: ${{ steps.meta.outputs.json }}
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ${{ env.REGISTRY }}
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Extract metadata
|
||||
id: meta
|
||||
uses: docker/metadata-action@v5
|
||||
with:
|
||||
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
|
||||
tags: |
|
||||
type=ref,event=branch
|
||||
type=semver,pattern={{version}}
|
||||
type=semver,pattern={{version}},suffix=-amd64
|
||||
type=semver,pattern={{version}},suffix=-arm64
|
||||
type=ref,event=branch,suffix=-amd64
|
||||
type=ref,event=branch,suffix=-arm64
|
||||
|
||||
- name: Build and push arm64 image
|
||||
id: build
|
||||
uses: docker/build-push-action@v6
|
||||
with:
|
||||
context: .
|
||||
platforms: linux/arm64
|
||||
labels: ${{ steps.meta.outputs.labels }}
|
||||
tags: ${{ steps.meta.outputs.tags }}
|
||||
cache-from: type=gha
|
||||
cache-to: type=gha,mode=max
|
||||
provenance: false
|
||||
push: true
|
||||
|
||||
# Create multi-platform manifest
|
||||
create-manifest:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
packages: write
|
||||
contents: read
|
||||
needs: [build-amd64, build-arm64]
|
||||
steps:
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
registry: ${{ env.REGISTRY }}
|
||||
username: ${{ github.repository_owner }}
|
||||
password: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Extract metadata for manifest
|
||||
id: meta
|
||||
uses: docker/metadata-action@v5
|
||||
with:
|
||||
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
|
||||
tags: |
|
||||
type=ref,event=branch
|
||||
type=semver,pattern={{version}}
|
||||
|
||||
- name: Create and push manifest
|
||||
run: |
|
||||
docker buildx imagetools create $(jq -cr '.tags | map("-t " + .) | join(" ")' <<< "$DOCKER_METADATA_OUTPUT_JSON") \
|
||||
${{ needs.build-amd64.outputs.image-digest }} \
|
||||
${{ needs.build-arm64.outputs.image-digest }}
|
||||
env:
|
||||
DOCKER_METADATA_OUTPUT_JSON: ${{ steps.meta.outputs.json }}
|
||||
@@ -12,6 +12,8 @@ Docs: https://docs.clawd.bot
|
||||
### Fixes
|
||||
- Web UI: hide internal `message_id` hints in chat bubbles.
|
||||
- Heartbeat: normalize target identifiers for consistent routing.
|
||||
- Exec: keep approvals for elevated ask unless full mode. (#1616) Thanks @ivancasco.
|
||||
- Gateway: reduce log noise for late invokes + remote node probes; debounce skills refresh. (#1607) Thanks @petter-b.
|
||||
|
||||
## 2026.1.23-1
|
||||
|
||||
|
||||
111
docs/help/faq.md
111
docs/help/faq.md
@@ -9,6 +9,7 @@ Quick answers plus deeper troubleshooting for real-world setups (local dev, VPS,
|
||||
|
||||
- [What is Clawdbot?](#what-is-clawdbot)
|
||||
- [What is Clawdbot, in one paragraph?](#what-is-clawdbot-in-one-paragraph)
|
||||
- [What’s the value proposition?](#whats-the-value-proposition)
|
||||
- [Quick start and first-run setup](#quick-start-and-first-run-setup)
|
||||
- [What’s the recommended way to install and set up Clawdbot?](#whats-the-recommended-way-to-install-and-set-up-clawdbot)
|
||||
- [How do I open the dashboard after onboarding?](#how-do-i-open-the-dashboard-after-onboarding)
|
||||
@@ -20,8 +21,11 @@ Quick answers plus deeper troubleshooting for real-world setups (local dev, VPS,
|
||||
- [I can't access docs.clawd.bot (SSL error). What now?](#i-cant-access-docsclawdbot-ssl-error-what-now)
|
||||
- [How do I install the beta version, and what’s the difference between beta and dev?](#how-do-i-install-the-beta-version-and-whats-the-difference-between-beta-and-dev)
|
||||
- [The docs didn’t answer my question — how do I get a better answer?](#the-docs-didnt-answer-my-question--how-do-i-get-a-better-answer)
|
||||
- [How do I install Clawdbot on Linux?](#how-do-i-install-clawdbot-on-linux)
|
||||
- [How do I install Clawdbot on a VPS?](#how-do-i-install-clawdbot-on-a-vps)
|
||||
- [Can I ask Clawd to update itself?](#can-i-ask-clawd-to-update-itself)
|
||||
- [What does the onboarding wizard actually do?](#what-does-the-onboarding-wizard-actually-do)
|
||||
- [Do I need a Claude or OpenAI subscription to run this?](#do-i-need-a-claude-or-openai-subscription-to-run-this)
|
||||
- [How does Anthropic "setup-token" auth work?](#how-does-anthropic-setup-token-auth-work)
|
||||
- [Where do I find an Anthropic setup-token?](#where-do-i-find-an-anthropic-setup-token)
|
||||
- [Do you support Claude subscription auth (Claude Code OAuth)?](#do-you-support-claude-subscription-auth-claude-code-oauth)
|
||||
@@ -32,6 +36,7 @@ Quick answers plus deeper troubleshooting for real-world setups (local dev, VPS,
|
||||
- [Is a local model OK for casual chats?](#is-a-local-model-ok-for-casual-chats)
|
||||
- [How do I keep hosted model traffic in a specific region?](#how-do-i-keep-hosted-model-traffic-in-a-specific-region)
|
||||
- [Do I have to buy a Mac Mini to install this?](#do-i-have-to-buy-a-mac-mini-to-install-this)
|
||||
- [Do I need a Mac mini for iMessage support?](#do-i-need-a-mac-mini-for-imessage-support)
|
||||
- [Can I use Bun?](#can-i-use-bun)
|
||||
- [Telegram: what goes in `allowFrom`?](#telegram-what-goes-in-allowfrom)
|
||||
- [Can multiple people use one WhatsApp number with different Clawdbots?](#can-multiple-people-use-one-whatsapp-number-with-different-clawdbots)
|
||||
@@ -56,6 +61,7 @@ Quick answers plus deeper troubleshooting for real-world setups (local dev, VPS,
|
||||
- [Where things live on disk](#where-things-live-on-disk)
|
||||
- [Where does Clawdbot store its data?](#where-does-clawdbot-store-its-data)
|
||||
- [Where should AGENTS.md / SOUL.md / USER.md / MEMORY.md live?](#where-should-agentsmd--soulmd--usermd--memorymd-live)
|
||||
- [What’s the recommended backup strategy?](#whats-the-recommended-backup-strategy)
|
||||
- [How do I completely uninstall Clawdbot?](#how-do-i-completely-uninstall-clawdbot)
|
||||
- [Can agents work outside the workspace?](#can-agents-work-outside-the-workspace)
|
||||
- [I’m in remote mode — where is the session store?](#im-in-remote-mode-where-is-the-session-store)
|
||||
@@ -96,6 +102,7 @@ Quick answers plus deeper troubleshooting for real-world setups (local dev, VPS,
|
||||
- [Models: defaults, selection, aliases, switching](#models-defaults-selection-aliases-switching)
|
||||
- [What is the “default model”?](#what-is-the-default-model)
|
||||
- [What model do you recommend?](#what-model-do-you-recommend)
|
||||
- [What do Clawd, Flawd, and Krill use for models?](#what-do-clawd-flawd-and-krill-use-for-models)
|
||||
- [How do I switch models on the fly (without restarting)?](#how-do-i-switch-models-on-the-fly-without-restarting)
|
||||
- [Why do I see “Model … is not allowed” and then no reply?](#why-do-i-see-model-is-not-allowed-and-then-no-reply)
|
||||
- [Why do I see “Unknown model: minimax/MiniMax-M2.1”?](#why-do-i-see-unknown-model-minimaxminimax-m21)
|
||||
@@ -196,6 +203,28 @@ Quick answers plus deeper troubleshooting for real-world setups (local dev, VPS,
|
||||
|
||||
Clawdbot is a personal AI assistant you run on your own devices. It replies on the messaging surfaces you already use (WhatsApp, Telegram, Slack, Mattermost (plugin), Discord, Signal, iMessage, WebChat) and can also do voice + a live Canvas on supported platforms. The **Gateway** is the always-on control plane; the assistant is the product.
|
||||
|
||||
### What’s the value proposition?
|
||||
|
||||
Clawdbot is not “just a Claude wrapper.” It’s a **local-first control plane** that lets you run a
|
||||
capable assistant on **your own hardware**, reachable from the chat apps you already use, with
|
||||
stateful sessions, memory, and tools — without handing control of your workflows to a hosted
|
||||
SaaS.
|
||||
|
||||
Highlights:
|
||||
- **Your devices, your data:** run the Gateway wherever you want (Mac, Linux, VPS) and keep the
|
||||
workspace + session history local.
|
||||
- **Real channels, not a web sandbox:** WhatsApp/Telegram/Slack/Discord/Signal/iMessage/etc,
|
||||
plus mobile voice and Canvas on supported platforms.
|
||||
- **Model-agnostic:** use Anthropic, OpenAI, MiniMax, OpenRouter, etc., with per‑agent routing
|
||||
and failover.
|
||||
- **Local-only option:** run local models so **all data can stay on your device** if you want.
|
||||
- **Multi-agent routing:** separate agents per channel, account, or task, each with its own
|
||||
workspace and defaults.
|
||||
- **Open source and hackable:** inspect, extend, and self-host without vendor lock‑in.
|
||||
|
||||
Docs: [Gateway](/gateway), [Channels](/channels), [Multi‑agent](/concepts/multi-agent),
|
||||
[Memory](/concepts/memory).
|
||||
|
||||
## Quick start and first-run setup
|
||||
|
||||
### What’s the recommended way to install and set up Clawdbot?
|
||||
@@ -254,7 +283,9 @@ not a hard minimum.
|
||||
|
||||
### Can I migrate my setup to a new machine (Mac mini) without redoing onboarding?
|
||||
|
||||
Yes. Copy the **state directory** and **workspace**, then run Doctor once:
|
||||
Yes. Copy the **state directory** and **workspace**, then run Doctor once. This
|
||||
keeps your bot “exactly the same” (memory, session history, auth, and channel
|
||||
state) as long as you copy **both** locations:
|
||||
|
||||
1) Install Clawdbot on the new machine.
|
||||
2) Copy `$CLAWDBOT_STATE_DIR` (default: `~/.clawdbot`) from the old machine.
|
||||
@@ -264,6 +295,10 @@ Yes. Copy the **state directory** and **workspace**, then run Doctor once:
|
||||
That preserves config, auth profiles, WhatsApp creds, sessions, and memory. If you’re in
|
||||
remote mode, remember the gateway host owns the session store and workspace.
|
||||
|
||||
**Important:** if you only commit/push your workspace to GitHub, you’re backing
|
||||
up **memory + bootstrap files**, but **not** session history or auth. Those live
|
||||
under `~/.clawdbot/` (for example `~/.clawdbot/agents/<agentId>/sessions/`).
|
||||
|
||||
Related: [Where things live on disk](/help/faq#where-does-clawdbot-store-its-data),
|
||||
[Agent workspace](/concepts/agent-workspace), [Doctor](/gateway/doctor),
|
||||
[Remote mode](/gateway/remote).
|
||||
@@ -282,6 +317,7 @@ section is the latest shipped version. Entries are grouped by **Highlights**, **
|
||||
Some Comcast/Xfinity connections incorrectly block `docs.clawd.bot` via Xfinity
|
||||
Advanced Security. Disable it or allowlist `docs.clawd.bot`, then retry. More
|
||||
detail: [Troubleshooting](/help/troubleshooting#docsclawdbot-shows-an-ssl-error-comcastxfinity).
|
||||
Please help us unblock it by reporting here: https://spa.xfinity.com/check_url_status.
|
||||
|
||||
If you still can't reach the site, the docs are mirrored on GitHub:
|
||||
https://github.com/clawdbot/clawdbot/tree/main/docs
|
||||
@@ -317,6 +353,14 @@ curl -fsSL https://clawd.bot/install.sh | bash -s -- --install-method git
|
||||
|
||||
More detail: [Install](/install) and [Installer flags](/install/installer).
|
||||
|
||||
### How do I install Clawdbot on Linux?
|
||||
|
||||
Short answer: follow the Linux guide, then run the onboarding wizard.
|
||||
|
||||
- Linux quick path + service install: [Linux](/platforms/linux).
|
||||
- Full walkthrough: [Getting Started](/start/getting-started).
|
||||
- Installer + updates: [Install & updates](/install/updating).
|
||||
|
||||
### How do I install Clawdbot on a VPS?
|
||||
|
||||
Any Linux VPS works. Install on the server, then use SSH/Tailscale to reach the Gateway.
|
||||
@@ -324,6 +368,31 @@ Any Linux VPS works. Install on the server, then use SSH/Tailscale to reach the
|
||||
Guides: [exe.dev](/platforms/exe-dev), [Hetzner](/platforms/hetzner), [Fly.io](/platforms/fly).
|
||||
Remote access: [Gateway remote](/gateway/remote).
|
||||
|
||||
### Can I ask Clawd to update itself?
|
||||
|
||||
Short answer: **possible, not recommended**. The update flow can restart the
|
||||
Gateway (which drops the active session), may need a clean git checkout, and
|
||||
can prompt for confirmation. Safer: run updates from a shell as the operator.
|
||||
|
||||
Use the CLI:
|
||||
|
||||
```bash
|
||||
clawdbot update
|
||||
clawdbot update status
|
||||
clawdbot update --channel stable|beta|dev
|
||||
clawdbot update --tag <dist-tag|version>
|
||||
clawdbot update --no-restart
|
||||
```
|
||||
|
||||
If you must automate from an agent:
|
||||
|
||||
```bash
|
||||
clawdbot update --yes --no-restart
|
||||
clawdbot gateway restart
|
||||
```
|
||||
|
||||
Docs: [Update](/cli/update), [Updating](/install/updating).
|
||||
|
||||
### What does the onboarding wizard actually do?
|
||||
|
||||
`clawdbot onboard` is the recommended setup path. In **local mode** it walks you through:
|
||||
@@ -337,6 +406,15 @@ Remote access: [Gateway remote](/gateway/remote).
|
||||
|
||||
It also warns if your configured model is unknown or missing auth.
|
||||
|
||||
### Do I need a Claude or OpenAI subscription to run this?
|
||||
|
||||
No. You can run Clawdbot with **API keys** (Anthropic/OpenAI/others) or with
|
||||
**local‑only models** so your data stays on your device. Subscriptions (Claude
|
||||
Pro/Max or OpenAI Codex) are optional ways to authenticate those providers.
|
||||
|
||||
Docs: [Anthropic](/providers/anthropic), [OpenAI](/providers/openai),
|
||||
[Local models](/gateway/local-models), [Models](/concepts/models).
|
||||
|
||||
### How does Anthropic "setup-token" auth work?
|
||||
|
||||
`claude setup-token` generates a **token string** via the Claude Code CLI (it is not available in the web console). You can run it on **any machine**. If Claude Code CLI credentials are present on the gateway host, Clawdbot can reuse them; otherwise choose **Anthropic token (paste setup-token)** and paste the string. The token is stored as an auth profile for the **anthropic** provider and used like an API key or OAuth profile. More detail: [OAuth](/concepts/oauth).
|
||||
@@ -406,6 +484,20 @@ If you want other macOS‑only tools, run the Gateway on a Mac or pair a macOS n
|
||||
|
||||
Docs: [iMessage](/channels/imessage), [Nodes](/nodes), [Mac remote mode](/platforms/mac/remote).
|
||||
|
||||
### Do I need a Mac mini for iMessage support?
|
||||
|
||||
You need **some macOS device** signed into Messages. It does **not** have to be a Mac mini —
|
||||
any Mac works. Clawdbot’s iMessage integrations run on macOS (BlueBubbles or `imsg`), while
|
||||
the Gateway can run elsewhere.
|
||||
|
||||
Common setups:
|
||||
- Run the Gateway on Linux/VPS, and point `channels.imessage.cliPath` at an SSH wrapper that
|
||||
runs `imsg` on the Mac.
|
||||
- Run everything on the Mac if you want the simplest single‑machine setup.
|
||||
|
||||
Docs: [iMessage](/channels/imessage), [BlueBubbles](/channels/bluebubbles),
|
||||
[Mac remote mode](/platforms/mac/remote).
|
||||
|
||||
### Can I use Bun?
|
||||
|
||||
Bun is **not recommended**. We see runtime bugs, especially with WhatsApp and Telegram.
|
||||
@@ -706,6 +798,18 @@ workspace, not your local laptop).
|
||||
|
||||
See [Agent workspace](/concepts/agent-workspace) and [Memory](/concepts/memory).
|
||||
|
||||
### What’s the recommended backup strategy?
|
||||
|
||||
Put your **agent workspace** in a **private** git repo and back it up somewhere
|
||||
private (for example GitHub private). This captures memory + AGENTS/SOUL/USER
|
||||
files, and lets you restore the assistant’s “mind” later.
|
||||
|
||||
Do **not** commit anything under `~/.clawdbot` (credentials, sessions, tokens).
|
||||
If you need a full restore, back up both the workspace and the state directory
|
||||
separately (see the migration question above).
|
||||
|
||||
Docs: [Agent workspace](/concepts/agent-workspace).
|
||||
|
||||
### How do I completely uninstall Clawdbot?
|
||||
|
||||
See the dedicated guide: [Uninstall](/install/uninstall).
|
||||
@@ -1220,6 +1324,11 @@ injection and unsafe behavior. See [Security](/gateway/security).
|
||||
|
||||
More context: [Models](/concepts/models).
|
||||
|
||||
### What do Clawd, Flawd, and Krill use for models?
|
||||
|
||||
- **Clawd + Flawd:** Anthropic Opus (`anthropic/claude-opus-4-5`) — see [Anthropic](/providers/anthropic).
|
||||
- **Krill:** MiniMax M2.1 (`minimax/MiniMax-M2.1`) — see [MiniMax](/providers/minimax).
|
||||
|
||||
### How do I switch models on the fly (without restarting)?
|
||||
|
||||
Use the `/model` command as a standalone message:
|
||||
|
||||
@@ -6,9 +6,10 @@ read_when:
|
||||
# Elevated Mode (/elevated directives)
|
||||
|
||||
## What it does
|
||||
- `/elevated on` is a **shortcut** for `exec.host=gateway` + `exec.security=full` (approvals still apply).
|
||||
- `/elevated on` runs on the gateway host and keeps exec approvals (same as `/elevated ask`).
|
||||
- `/elevated full` runs on the gateway host **and** auto-approves exec (skips exec approvals).
|
||||
- `/elevated ask` runs on the gateway host but keeps exec approvals (same as `/elevated on`).
|
||||
- `on`/`ask` do **not** force `exec.security=full`; configured security/ask policy still applies.
|
||||
- Only changes behavior when the agent is **sandboxed** (otherwise exec already runs on the host).
|
||||
- Directive forms: `/elevated on|off|ask|full`, `/elev on|off|ask|full`.
|
||||
- Only `on|off|ask|full` are accepted; anything else returns a hint and does not change state.
|
||||
@@ -18,8 +19,8 @@ read_when:
|
||||
- **Per-session state**: `/elevated on|off|ask|full` sets the elevated level for the current session key.
|
||||
- **Inline directive**: `/elevated on|ask|full` inside a message applies to that message only.
|
||||
- **Groups**: In group chats, elevated directives are only honored when the agent is mentioned. Command-only messages that bypass mention requirements are treated as mentioned.
|
||||
- **Host execution**: elevated forces `exec` onto the gateway host with full security.
|
||||
- **Approvals**: `full` skips exec approvals; `on`/`ask` still honor them.
|
||||
- **Host execution**: elevated forces `exec` onto the gateway host; `full` also sets `security=full`.
|
||||
- **Approvals**: `full` skips exec approvals; `on`/`ask` honor them when allowlist/ask rules require.
|
||||
- **Unsandboxed agents**: no-op for location; only affects gating, logging, and status.
|
||||
- **Tool policy still applies**: if `exec` is denied by tool policy, elevated cannot be used.
|
||||
|
||||
|
||||
@@ -24,7 +24,7 @@ Background sessions are scoped per agent; `process` only sees sessions from the
|
||||
- `security` (`deny | allowlist | full`): enforcement mode for `gateway`/`node`
|
||||
- `ask` (`off | on-miss | always`): approval prompts for `gateway`/`node`
|
||||
- `node` (string): node id/name for `host=node`
|
||||
- `elevated` (bool): alias for `host=gateway` + `security=full` when sandboxed and allowed
|
||||
- `elevated` (bool): request elevated mode (gateway host); `security=full` is only forced when elevated resolves to `full`
|
||||
|
||||
Notes:
|
||||
- `host` defaults to `sandbox`.
|
||||
|
||||
@@ -150,4 +150,35 @@ describe("exec approvals", () => {
|
||||
expect(result.details.status).toBe("completed");
|
||||
expect(calls).not.toContain("exec.approval.request");
|
||||
});
|
||||
|
||||
it("requires approval for elevated ask when allowlist misses", async () => {
|
||||
const { callGatewayTool } = await import("./tools/gateway.js");
|
||||
const calls: string[] = [];
|
||||
let resolveApproval: (() => void) | undefined;
|
||||
const approvalSeen = new Promise<void>((resolve) => {
|
||||
resolveApproval = resolve;
|
||||
});
|
||||
|
||||
vi.mocked(callGatewayTool).mockImplementation(async (method) => {
|
||||
calls.push(method);
|
||||
if (method === "exec.approval.request") {
|
||||
resolveApproval?.();
|
||||
return { decision: "deny" };
|
||||
}
|
||||
return { ok: true };
|
||||
});
|
||||
|
||||
const { createExecTool } = await import("./bash-tools.exec.js");
|
||||
const tool = createExecTool({
|
||||
ask: "on-miss",
|
||||
security: "allowlist",
|
||||
approvalRunningNoticeMs: 0,
|
||||
elevated: { enabled: true, allowed: true, defaultLevel: "ask" },
|
||||
});
|
||||
|
||||
const result = await tool.execute("call4", { command: "echo ok", elevated: true });
|
||||
expect(result.details.status).toBe("approval-pending");
|
||||
await approvalSeen;
|
||||
expect(calls).toContain("exec.approval.request");
|
||||
});
|
||||
});
|
||||
|
||||
@@ -791,7 +791,7 @@ export function createExecTool(
|
||||
const configuredSecurity = defaults?.security ?? (host === "sandbox" ? "deny" : "allowlist");
|
||||
const requestedSecurity = normalizeExecSecurity(params.security);
|
||||
let security = minSecurity(configuredSecurity, requestedSecurity ?? configuredSecurity);
|
||||
if (elevatedRequested) {
|
||||
if (elevatedRequested && elevatedMode === "full") {
|
||||
security = "full";
|
||||
}
|
||||
const configuredAsk = defaults?.ask ?? "on-miss";
|
||||
|
||||
@@ -460,6 +460,22 @@ File contents here`,
|
||||
expect(result).toBe("The actual answer.");
|
||||
});
|
||||
|
||||
it("strips final tags while keeping content", () => {
|
||||
const msg: AssistantMessage = {
|
||||
role: "assistant",
|
||||
content: [
|
||||
{
|
||||
type: "text",
|
||||
text: "<final>\nAnswer\n</final>",
|
||||
},
|
||||
],
|
||||
timestamp: Date.now(),
|
||||
};
|
||||
|
||||
const result = extractAssistantText(msg);
|
||||
expect(result).toBe("Answer");
|
||||
});
|
||||
|
||||
it("strips thought tags", () => {
|
||||
const msg: AssistantMessage = {
|
||||
role: "assistant",
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
import type { AssistantMessage } from "@mariozechner/pi-ai";
|
||||
import { stripReasoningTagsFromText } from "../shared/text/reasoning-tags.js";
|
||||
import { sanitizeUserFacingText } from "./pi-embedded-helpers.js";
|
||||
import { formatToolDetail, resolveToolDisplay } from "./tool-display.js";
|
||||
|
||||
@@ -166,36 +167,7 @@ export function stripDowngradedToolCallText(text: string): string {
|
||||
* that slip through other filtering mechanisms.
|
||||
*/
|
||||
export function stripThinkingTagsFromText(text: string): string {
|
||||
if (!text) return text;
|
||||
// Quick check to avoid regex overhead when no tags present.
|
||||
if (!/(?:think(?:ing)?|thought|antthinking)/i.test(text)) return text;
|
||||
|
||||
const tagRe = /<\s*(\/?)\s*(?:think(?:ing)?|thought|antthinking)\b[^>]*>/gi;
|
||||
let result = "";
|
||||
let lastIndex = 0;
|
||||
let inThinking = false;
|
||||
|
||||
for (const match of text.matchAll(tagRe)) {
|
||||
const idx = match.index ?? 0;
|
||||
const isClose = match[1] === "/";
|
||||
|
||||
if (!inThinking && !isClose) {
|
||||
// Opening tag - save text before it.
|
||||
result += text.slice(lastIndex, idx);
|
||||
inThinking = true;
|
||||
} else if (inThinking && isClose) {
|
||||
// Closing tag - skip content inside.
|
||||
inThinking = false;
|
||||
}
|
||||
lastIndex = idx + match[0].length;
|
||||
}
|
||||
|
||||
// Append remaining text if we're not inside thinking.
|
||||
if (!inThinking) {
|
||||
result += text.slice(lastIndex);
|
||||
}
|
||||
|
||||
return result.trim();
|
||||
return stripReasoningTagsFromText(text, { mode: "strict", trim: "both" });
|
||||
}
|
||||
|
||||
export function extractAssistantText(msg: AssistantMessage): string {
|
||||
|
||||
@@ -468,7 +468,10 @@ export const nodeHandlers: GatewayRequestHandlers = {
|
||||
error: p.error ?? null,
|
||||
});
|
||||
if (!ok) {
|
||||
respond(false, undefined, errorShape(ErrorCodes.INVALID_REQUEST, "unknown invoke id"));
|
||||
// Late-arriving results (after invoke timeout) are expected and harmless.
|
||||
// Return success instead of error to reduce log noise; client can discard.
|
||||
context.logGateway.debug(`late invoke result ignored: id=${p.id} node=${p.nodeId}`);
|
||||
respond(true, { ok: true, ignored: true }, undefined);
|
||||
return;
|
||||
}
|
||||
respond(true, { ok: true }, undefined);
|
||||
|
||||
@@ -344,9 +344,19 @@ export async function startGatewayServer(
|
||||
|
||||
setSkillsRemoteRegistry(nodeRegistry);
|
||||
void primeRemoteSkillsCache();
|
||||
registerSkillsChangeListener(() => {
|
||||
const latest = loadConfig();
|
||||
void refreshRemoteBinsForConnectedNodes(latest);
|
||||
// Debounce skills-triggered node probes to avoid feedback loops and rapid-fire invokes.
|
||||
// Skills changes can happen in bursts (e.g., file watcher events), and each probe
|
||||
// takes time to complete. A 30-second delay ensures we batch changes together.
|
||||
let skillsRefreshTimer: ReturnType<typeof setTimeout> | null = null;
|
||||
const skillsRefreshDelayMs = 30_000;
|
||||
const skillsChangeUnsub = registerSkillsChangeListener((event) => {
|
||||
if (event.reason === "remote-node") return;
|
||||
if (skillsRefreshTimer) clearTimeout(skillsRefreshTimer);
|
||||
skillsRefreshTimer = setTimeout(() => {
|
||||
skillsRefreshTimer = null;
|
||||
const latest = loadConfig();
|
||||
void refreshRemoteBinsForConnectedNodes(latest);
|
||||
}, skillsRefreshDelayMs);
|
||||
});
|
||||
|
||||
const { tickInterval, healthInterval, dedupeCleanup } = startGatewayMaintenanceTimers({
|
||||
@@ -544,6 +554,11 @@ export async function startGatewayServer(
|
||||
if (diagnosticsEnabled) {
|
||||
stopDiagnosticHeartbeat();
|
||||
}
|
||||
if (skillsRefreshTimer) {
|
||||
clearTimeout(skillsRefreshTimer);
|
||||
skillsRefreshTimer = null;
|
||||
}
|
||||
skillsChangeUnsub();
|
||||
await close(opts);
|
||||
},
|
||||
};
|
||||
|
||||
125
src/gateway/server.nodes.late-invoke.test.ts
Normal file
125
src/gateway/server.nodes.late-invoke.test.ts
Normal file
@@ -0,0 +1,125 @@
|
||||
import { afterAll, beforeAll, describe, expect, test, vi } from "vitest";
|
||||
import { WebSocket } from "ws";
|
||||
|
||||
import { GATEWAY_CLIENT_MODES, GATEWAY_CLIENT_NAMES } from "../utils/message-channel.js";
|
||||
import { loadOrCreateDeviceIdentity } from "../infra/device-identity.js";
|
||||
|
||||
vi.mock("../infra/update-runner.js", () => ({
|
||||
runGatewayUpdate: vi.fn(async () => ({
|
||||
status: "ok",
|
||||
mode: "git",
|
||||
root: "/repo",
|
||||
steps: [],
|
||||
durationMs: 12,
|
||||
})),
|
||||
}));
|
||||
|
||||
import {
|
||||
connectOk,
|
||||
installGatewayTestHooks,
|
||||
rpcReq,
|
||||
startServerWithClient,
|
||||
} from "./test-helpers.js";
|
||||
|
||||
installGatewayTestHooks({ scope: "suite" });
|
||||
|
||||
let server: Awaited<ReturnType<typeof startServerWithClient>>["server"];
|
||||
let ws: WebSocket;
|
||||
let port: number;
|
||||
|
||||
beforeAll(async () => {
|
||||
const started = await startServerWithClient();
|
||||
server = started.server;
|
||||
ws = started.ws;
|
||||
port = started.port;
|
||||
await connectOk(ws);
|
||||
});
|
||||
|
||||
afterAll(async () => {
|
||||
ws.close();
|
||||
await server.close();
|
||||
});
|
||||
|
||||
describe("late-arriving invoke results", () => {
|
||||
test("returns success for unknown invoke id (late arrival after timeout)", async () => {
|
||||
// Create a node client WebSocket
|
||||
const nodeWs = new WebSocket(`ws://127.0.0.1:${port}`);
|
||||
await new Promise<void>((resolve) => nodeWs.once("open", resolve));
|
||||
|
||||
try {
|
||||
// Connect as a node with device identity
|
||||
const identity = loadOrCreateDeviceIdentity();
|
||||
const nodeId = identity.deviceId;
|
||||
|
||||
await connectOk(nodeWs, {
|
||||
role: "node",
|
||||
client: {
|
||||
id: GATEWAY_CLIENT_NAMES.NODE_HOST,
|
||||
version: "1.0.0",
|
||||
platform: "ios",
|
||||
mode: GATEWAY_CLIENT_MODES.NODE,
|
||||
},
|
||||
commands: ["canvas.snapshot"],
|
||||
});
|
||||
|
||||
// Send an invoke result with an unknown ID (simulating late arrival after timeout)
|
||||
const result = await rpcReq<{ ok?: boolean; ignored?: boolean }>(
|
||||
nodeWs,
|
||||
"node.invoke.result",
|
||||
{
|
||||
id: "unknown-invoke-id-12345",
|
||||
nodeId,
|
||||
ok: true,
|
||||
payloadJSON: JSON.stringify({ result: "late" }),
|
||||
},
|
||||
);
|
||||
|
||||
// Late-arriving results return success instead of error to reduce log noise
|
||||
expect(result.ok).toBe(true);
|
||||
expect(result.payload?.ok).toBe(true);
|
||||
expect(result.payload?.ignored).toBe(true);
|
||||
} finally {
|
||||
nodeWs.close();
|
||||
}
|
||||
});
|
||||
|
||||
test("returns success for unknown invoke id with error payload", async () => {
|
||||
// Verifies late results are accepted regardless of their ok/error status
|
||||
const nodeWs = new WebSocket(`ws://127.0.0.1:${port}`);
|
||||
await new Promise<void>((resolve) => nodeWs.once("open", resolve));
|
||||
|
||||
try {
|
||||
await connectOk(nodeWs, {
|
||||
role: "node",
|
||||
client: {
|
||||
id: GATEWAY_CLIENT_NAMES.NODE_HOST,
|
||||
version: "1.0.0",
|
||||
platform: "darwin",
|
||||
mode: GATEWAY_CLIENT_MODES.NODE,
|
||||
},
|
||||
commands: [],
|
||||
});
|
||||
|
||||
const identity = loadOrCreateDeviceIdentity();
|
||||
const nodeId = identity.deviceId;
|
||||
|
||||
// Late invoke result with error payload - should still return success
|
||||
const result = await rpcReq<{ ok?: boolean; ignored?: boolean }>(
|
||||
nodeWs,
|
||||
"node.invoke.result",
|
||||
{
|
||||
id: "another-unknown-invoke-id",
|
||||
nodeId,
|
||||
ok: false,
|
||||
error: { code: "FAILED", message: "test error" },
|
||||
},
|
||||
);
|
||||
|
||||
expect(result.ok).toBe(true);
|
||||
expect(result.payload?.ok).toBe(true);
|
||||
expect(result.payload?.ignored).toBe(true);
|
||||
} finally {
|
||||
nodeWs.close();
|
||||
}
|
||||
});
|
||||
});
|
||||
@@ -55,10 +55,10 @@ function extractErrorMessage(err: unknown): string | undefined {
|
||||
function logRemoteBinProbeFailure(nodeId: string, err: unknown) {
|
||||
const message = extractErrorMessage(err);
|
||||
const label = describeNode(nodeId);
|
||||
if (message?.includes("node not connected")) {
|
||||
log.info(
|
||||
`remote bin probe skipped: node not connected (${label}); check nodes list/status for ${label}`,
|
||||
);
|
||||
// Node unavailable errors (not connected or disconnected mid-operation) are expected
|
||||
// when nodes have transient connections - log at info level instead of warn
|
||||
if (message?.includes("node not connected") || message?.includes("node disconnected")) {
|
||||
log.info(`remote bin probe skipped: node unavailable (${label})`);
|
||||
return;
|
||||
}
|
||||
if (message?.includes("invoke timed out") || message?.includes("timeout")) {
|
||||
@@ -213,6 +213,15 @@ function parseBinProbePayload(payloadJSON: string | null | undefined, payload?:
|
||||
return [];
|
||||
}
|
||||
|
||||
function areBinSetsEqual(a: Set<string> | undefined, b: Set<string>): boolean {
|
||||
if (!a) return false;
|
||||
if (a.size !== b.size) return false;
|
||||
for (const bin of b) {
|
||||
if (!a.has(bin)) return false;
|
||||
}
|
||||
return true;
|
||||
}
|
||||
|
||||
export async function refreshRemoteNodeBins(params: {
|
||||
nodeId: string;
|
||||
platform?: string;
|
||||
@@ -261,7 +270,11 @@ export async function refreshRemoteNodeBins(params: {
|
||||
return;
|
||||
}
|
||||
const bins = parseBinProbePayload(res.payloadJSON, res.payload);
|
||||
const existingBins = remoteNodes.get(params.nodeId)?.bins;
|
||||
const nextBins = new Set(bins);
|
||||
const hasChanged = !areBinSetsEqual(existingBins, nextBins);
|
||||
recordRemoteNodeBins(params.nodeId, bins);
|
||||
if (!hasChanged) return;
|
||||
await updatePairedNodeMetadata(params.nodeId, { bins });
|
||||
bumpSkillsSnapshotVersion({ reason: "remote-node" });
|
||||
} catch (err) {
|
||||
|
||||
@@ -67,9 +67,10 @@ export function normalizeAgentId(value: string | undefined | null): string {
|
||||
export function sanitizeAgentId(value: string | undefined | null): string {
|
||||
const trimmed = (value ?? "").trim();
|
||||
if (!trimmed) return DEFAULT_AGENT_ID;
|
||||
if (/^[a-z0-9][a-z0-9_-]{0,63}$/i.test(trimmed)) return trimmed;
|
||||
if (/^[a-z0-9][a-z0-9_-]{0,63}$/i.test(trimmed)) return trimmed.toLowerCase();
|
||||
return (
|
||||
trimmed
|
||||
.toLowerCase()
|
||||
.replace(/[^a-z0-9_-]+/gi, "-")
|
||||
.replace(/^-+/, "")
|
||||
.replace(/-+$/, "")
|
||||
|
||||
61
src/shared/text/reasoning-tags.ts
Normal file
61
src/shared/text/reasoning-tags.ts
Normal file
@@ -0,0 +1,61 @@
|
||||
export type ReasoningTagMode = "strict" | "preserve";
|
||||
export type ReasoningTagTrim = "none" | "start" | "both";
|
||||
|
||||
const QUICK_TAG_RE = /<\s*\/?\s*(?:think(?:ing)?|thought|antthinking|final)\b/i;
|
||||
const FINAL_TAG_RE = /<\s*\/?\s*final\b[^>]*>/gi;
|
||||
const THINKING_TAG_RE = /<\s*(\/?)\s*(?:think(?:ing)?|thought|antthinking)\b[^>]*>/gi;
|
||||
|
||||
function applyTrim(value: string, mode: ReasoningTagTrim): string {
|
||||
if (mode === "none") return value;
|
||||
if (mode === "start") return value.trimStart();
|
||||
return value.trim();
|
||||
}
|
||||
|
||||
export function stripReasoningTagsFromText(
|
||||
text: string,
|
||||
options?: {
|
||||
mode?: ReasoningTagMode;
|
||||
trim?: ReasoningTagTrim;
|
||||
},
|
||||
): string {
|
||||
if (!text) return text;
|
||||
if (!QUICK_TAG_RE.test(text)) return text;
|
||||
|
||||
const mode = options?.mode ?? "strict";
|
||||
const trimMode = options?.trim ?? "both";
|
||||
|
||||
let cleaned = text;
|
||||
if (FINAL_TAG_RE.test(cleaned)) {
|
||||
FINAL_TAG_RE.lastIndex = 0;
|
||||
cleaned = cleaned.replace(FINAL_TAG_RE, "");
|
||||
} else {
|
||||
FINAL_TAG_RE.lastIndex = 0;
|
||||
}
|
||||
|
||||
THINKING_TAG_RE.lastIndex = 0;
|
||||
let result = "";
|
||||
let lastIndex = 0;
|
||||
let inThinking = false;
|
||||
|
||||
for (const match of cleaned.matchAll(THINKING_TAG_RE)) {
|
||||
const idx = match.index ?? 0;
|
||||
const isClose = match[1] === "/";
|
||||
|
||||
if (!inThinking) {
|
||||
result += cleaned.slice(lastIndex, idx);
|
||||
if (!isClose) {
|
||||
inThinking = true;
|
||||
}
|
||||
} else if (isClose) {
|
||||
inThinking = false;
|
||||
}
|
||||
|
||||
lastIndex = idx + match[0].length;
|
||||
}
|
||||
|
||||
if (!inThinking || mode === "preserve") {
|
||||
result += cleaned.slice(lastIndex);
|
||||
}
|
||||
|
||||
return applyTrim(result, trimMode);
|
||||
}
|
||||
@@ -21,5 +21,22 @@ describe("stripThinkingTags", () => {
|
||||
it("returns original text when no tags exist", () => {
|
||||
expect(stripThinkingTags("Hello")).toBe("Hello");
|
||||
});
|
||||
|
||||
it("strips <final>…</final> segments", () => {
|
||||
const input = "<final>\n\nHello there\n\n</final>";
|
||||
expect(stripThinkingTags(input)).toBe("Hello there\n\n");
|
||||
});
|
||||
|
||||
it("strips mixed <think> and <final> tags", () => {
|
||||
const input = "<think>reasoning</think>\n\n<final>Hello</final>";
|
||||
expect(stripThinkingTags(input)).toBe("Hello");
|
||||
});
|
||||
|
||||
it("handles incomplete <final tag gracefully", () => {
|
||||
// When streaming splits mid-tag, we may see "<final" without closing ">"
|
||||
// This should not crash and should handle gracefully
|
||||
expect(stripThinkingTags("<final\nHello")).toBe("<final\nHello");
|
||||
expect(stripThinkingTags("Hello</final>")).toBe("Hello");
|
||||
});
|
||||
});
|
||||
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
import { stripReasoningTagsFromText } from "../../../src/shared/text/reasoning-tags.js";
|
||||
|
||||
export function formatMs(ms?: number | null): string {
|
||||
if (!ms && ms !== 0) return "n/a";
|
||||
return new Date(ms).toLocaleString();
|
||||
@@ -67,38 +69,6 @@ export function parseList(input: string): string[] {
|
||||
.filter((v) => v.length > 0);
|
||||
}
|
||||
|
||||
const THINKING_TAG_RE = /<\s*\/?\s*think(?:ing)?\s*>/gi;
|
||||
const THINKING_OPEN_RE = /<\s*think(?:ing)?\s*>/i;
|
||||
const THINKING_CLOSE_RE = /<\s*\/\s*think(?:ing)?\s*>/i;
|
||||
|
||||
export function stripThinkingTags(value: string): string {
|
||||
if (!value) return value;
|
||||
const hasOpen = THINKING_OPEN_RE.test(value);
|
||||
const hasClose = THINKING_CLOSE_RE.test(value);
|
||||
if (!hasOpen && !hasClose) return value;
|
||||
// If we don't have a balanced pair, avoid dropping trailing content.
|
||||
if (hasOpen !== hasClose) {
|
||||
if (!hasOpen) return value.replace(THINKING_CLOSE_RE, "").trimStart();
|
||||
return value.replace(THINKING_OPEN_RE, "").trimStart();
|
||||
}
|
||||
|
||||
if (!THINKING_TAG_RE.test(value)) return value;
|
||||
THINKING_TAG_RE.lastIndex = 0;
|
||||
|
||||
let result = "";
|
||||
let lastIndex = 0;
|
||||
let inThinking = false;
|
||||
for (const match of value.matchAll(THINKING_TAG_RE)) {
|
||||
const idx = match.index ?? 0;
|
||||
if (!inThinking) {
|
||||
result += value.slice(lastIndex, idx);
|
||||
}
|
||||
const tag = match[0].toLowerCase();
|
||||
inThinking = !tag.includes("/");
|
||||
lastIndex = idx + match[0].length;
|
||||
}
|
||||
if (!inThinking) {
|
||||
result += value.slice(lastIndex);
|
||||
}
|
||||
return result.trimStart();
|
||||
return stripReasoningTagsFromText(value, { mode: "preserve", trim: "start" });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user