Merge commit 'refs/phase3/pre-ajax/publication-tip' into integration/pre-ajax-release

# Conflicts:
#	routes/chat_routes.py
#	routes/session_routes.py
#	src/agent_loop.py
#	src/agent_tools/filesystem_tools.py
#	src/teacher_escalation.py
#	src/tool_capabilities.py
#	src/tool_execution.py
#	tests/test_mcp_add_server_args_validation.py
#	tests/test_token_cache_atomic_swap.py
This commit is contained in:
Alexandre Teixeira
2026-10-05 15:59:59 +01:00
1395 changed files with 360455 additions and 105938 deletions
+83 -3
View File
@@ -101,9 +101,19 @@ jobs:
done
python-tests:
name: Python tests (pytest)
runs-on: ubuntu-latest
name: Python tests (pytest ${{ matrix.shard }})
# Keep the namespace/AppArmor setup tied to the audited Ubuntu release.
runs-on: ubuntu-24.04
# Make Python test validation authoritative for the configured scope.
strategy:
# Report every failing section in one run instead of cancelling the rest
# the moment one shard goes red.
fail-fast: false
matrix:
# Shards partition the suite by test file, so the four together run
# every test exactly once. tests/_shards.py owns the partition and
# tests/test_shards.py pins this list to its DEFAULT_SHARD_COUNT.
shard: ["1/4", "2/4", "3/4", "4/4"]
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
@@ -140,7 +150,77 @@ jobs:
cache: pip
- run: pip install -r requirements.txt
if: steps.docs-check.outputs.docs_only != 'true'
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
if: steps.docs-check.outputs.docs_only != 'true'
with:
node-version: "20"
cache: npm
- run: npm ci
if: steps.docs-check.outputs.docs_only != 'true'
- run: npx playwright install --with-deps chromium
if: steps.docs-check.outputs.docs_only != 'true'
- run: mkdir -p data # sqlite DB lives at ./data/app.db
if: steps.docs-check.outputs.docs_only != 'true'
- run: python -m pytest -q
- name: Install FFmpeg for media integration tests
if: steps.docs-check.outputs.docs_only != 'true'
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends ffmpeg
command -v ffmpeg
ffmpeg -version | head -n 1
- name: Establish functional bubblewrap containment
if: steps.docs-check.outputs.docs_only != 'true'
shell: bash
run: |
set -euo pipefail
sudo apt-get update
sudo apt-get install -y --no-install-recommends bubblewrap
bwrap --version
sysctl kernel.unprivileged_userns_clone user.max_user_namespaces \
kernel.apparmor_restrict_unprivileged_userns
if [ "$(sysctl -n kernel.unprivileged_userns_clone)" != 1 ] || \
[ "$(sysctl -n user.max_user_namespaces)" -eq 0 ]; then
echo '::error::The pytest runner must allow unprivileged user namespaces; kernel namespace support is disabled.'
exit 1
fi
# Match containment._bwrap_available(): PID and mount namespaces,
# including fresh proc/dev mounts, as the unprivileged runner user.
bwrap_probe() {
timeout 3s bwrap --die-with-parent --unshare-pid --ro-bind / / \
--proc /proc --dev /dev /bin/true
}
if ! bwrap_probe && [ "$(sysctl -n kernel.apparmor_restrict_unprivileged_userns)" = 1 ]; then
# Ubuntu 24.04 restricts userns for unconfined applications. Allow
# only the distro bwrap entry point on this ephemeral pytest VM;
# retain the global restriction and all unrelated AppArmor policy.
sudo tee /etc/apparmor.d/odysseus-ci-bwrap > /dev/null <<'PROFILE'
abi <abi/4.0>,
include <tunables/global>
profile odysseus-ci-bwrap /usr/bin/bwrap flags=(unconfined) {
userns,
}
PROFILE
sudo apparmor_parser -r /etc/apparmor.d/odysseus-ci-bwrap
fi
if ! bwrap_probe; then
echo '::error::Functional bubblewrap PID/mount namespaces are required for pytest; containment setup failed.'
exit 1
fi
# Also gate on the runtime probe so a future requirements change
# cannot silently leave this job without real containment coverage.
python - <<'PY'
from src import containment
if not containment._bwrap_available():
raise SystemExit("::error::Runtime bubblewrap functionality probe failed; pytest must not start.")
print("Runtime bubblewrap PID/mount namespace probe passed.")
PY
- name: pytest (shard ${{ matrix.shard }})
if: steps.docs-check.outputs.docs_only != 'true'
env:
PYTEST_SHARD: ${{ matrix.shard }}
run: python -m pytest -q -rs --shard "$PYTEST_SHARD"
+10
View File
@@ -62,6 +62,8 @@ jobs:
- name: Set up Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
with:
driver: docker
# Build without pushing so a broken Dockerfile is caught here, and the
# exact image we ship is what gets scanned.
@@ -73,6 +75,9 @@ jobs:
load: true
tags: odysseus:ci
- name: Free build cache before vulnerability database download
run: docker builder prune --all --force
- name: Scan image with Trivy
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
@@ -103,6 +108,8 @@ jobs:
- name: Set up Buildx
uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0
with:
driver: docker
- name: Build image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
@@ -112,6 +119,9 @@ jobs:
load: true
tags: odysseus:ci
- name: Free build cache before vulnerability database download
run: docker builder prune --all --force
- name: Scan image with Trivy
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
with:
+4 -1
View File
@@ -30,7 +30,10 @@ jobs:
dependency-review:
name: dependency-review (PR gate)
# Only meaningful on a pull request -- it needs a base..head diff to review.
if: github.event_name == 'pull_request'
# dependency-review-action requires GitHub dependency-review support.
# Keep the blocking gate on the canonical repository; forks and maintainer
# preview mirrors still run the advisory pip-audit job below.
if: github.event_name == 'pull_request' && github.repository == 'odysseus-dev/odysseus'
runs-on: ubuntu-latest
permissions:
contents: read