pewdiepie-archdaemon
edcd94a312
Record verified text routing fixes and remaining quality failures
2026-09-17 20:42:41 +00:00
pewdiepie-archdaemon
08ab1c9507
Keep supplied proofreading text out of document review controls
2026-09-17 20:41:56 +00:00
pewdiepie-archdaemon
4faf683912
Treat explicitly supplied proofreading text as data not tool authority
2026-09-17 20:40:00 +00:00
pewdiepie-archdaemon
20361b3de8
Control sampling and canonical prompt in search diagnostics
2026-09-17 20:37:32 +00:00
pewdiepie-archdaemon
39a6a49664
Stop appending unverified search citations to synthesized answers
2026-09-17 20:32:46 +00:00
pewdiepie-archdaemon
87b6a37885
Record search quality failures and separate mechanics from review
2026-09-17 20:26:53 +00:00
pewdiepie-archdaemon
cfb9315e0a
Preserve news query intent and extract nonduplicated semantic page content
2026-09-17 20:24:00 +00:00
pewdiepie-archdaemon
3edf7acd21
Allow evidence verification after successful search and fetch
2026-09-17 20:20:40 +00:00
pewdiepie-archdaemon
7257319004
Preserve every fetched search source within observation budget
2026-09-17 20:17:03 +00:00
pewdiepie-archdaemon
a48ab46f7d
Enforce search source restrictions and expand live prompt coverage
2026-09-17 20:14:32 +00:00
pewdiepie-archdaemon
7fa6c93fb3
separate search freshness from news category selection
2026-09-17 20:08:58 +00:00
pewdiepie-archdaemon
566202dcad
require domain evidence for official source shortcut
2026-09-17 20:07:51 +00:00
pewdiepie-archdaemon
6fb1ce7238
withhold tools for standalone social turns
2026-09-17 20:05:30 +00:00
pewdiepie-archdaemon
dc4a38f3bc
preserve manual formats and require discovery for evidence requests
2026-09-17 20:04:51 +00:00
pewdiepie-archdaemon
2d938b1650
recognize casual news requests and prevent premature source-only completion
2026-09-17 20:03:32 +00:00
pewdiepie-archdaemon
da215cf242
audit search variety with model provenance and per-turn latency
2026-09-17 20:01:38 +00:00
pewdiepie-archdaemon
a7576f721c
verify embedded articles skip redundant retrieval rounds
2026-09-17 19:58:06 +00:00
pewdiepie-archdaemon
02200b2874
reuse embedded search articles and reject browser error pages
2026-09-17 19:57:20 +00:00
pewdiepie-archdaemon
f27070c469
buffer rejected search drafts and cap interactive rounds
2026-09-17 19:53:40 +00:00
pewdiepie-archdaemon
ff4d01a55e
ground fresh searches and verify official documents
2026-09-17 19:49:28 +00:00
pewdiepie-archdaemon
994413c435
compose explicit search and fetch workflows
2026-09-17 19:43:20 +00:00
pewdiepie-archdaemon
8c7ea10520
ground current lookups and recover failed fetches
2026-09-17 19:42:38 +00:00
pewdiepie-archdaemon
dfd4d5a80e
preserve evidence after bounded web search
2026-09-17 19:35:54 +00:00
pewdiepie-archdaemon
f2fb42c7d1
synthesize after bounded search suppression
2026-09-17 19:27:16 +00:00
pewdiepie-archdaemon
295578514e
route current events through bounded news search
2026-09-17 19:26:04 +00:00
pewdiepie-archdaemon
e9a117df0d
bound optional search fallback latency
2026-09-17 19:22:51 +00:00
pewdiepie-archdaemon
6b135eab73
finish resource lookups from verified search metadata
2026-09-17 19:18:05 +00:00
pewdiepie-archdaemon
e49264ae47
preserve product identity in manual search
2026-09-17 19:15:39 +00:00
pewdiepie-archdaemon
e48ea98d2f
broaden empty searches through resilient providers
2026-09-17 19:12:28 +00:00
pewdiepie-archdaemon
e22cf4b500
bound search attempts by research depth
2026-09-17 19:07:22 +00:00
pewdiepie-archdaemon
483fdc7054
require linked broad research synthesis
2026-09-17 19:04:08 +00:00
pewdiepie-archdaemon
e3107a645d
enforce distinct research refinement
2026-09-17 19:02:11 +00:00
pewdiepie-archdaemon
6121442658
unify broad web briefing semantics
2026-09-17 18:58:31 +00:00
pewdiepie-archdaemon
be48da1146
recognize natural broad current queries
2026-09-17 18:55:19 +00:00
pewdiepie-archdaemon
cdc0734347
require breadth for broad current research
2026-09-17 18:51:56 +00:00
pewdiepie-archdaemon
69a1b97c96
recover rendered pages from fetch boilerplate
2026-09-17 18:49:59 +00:00
pewdiepie-archdaemon
4d7c9d44d1
keep compact agent core tools available
2026-09-17 18:47:04 +00:00
pewdiepie-archdaemon
25ff725c1d
repair broad web research recovery
2026-09-17 18:36:12 +00:00
pewdiepie-archdaemon
0aa470b095
recover synthesis after unavailable web search
2026-09-17 13:34:36 +00:00
pewdiepie-archdaemon
337a47d27d
skip redundant synthesis after email actions
2026-09-17 13:21:11 +00:00
pewdiepie-archdaemon
10d637f8b9
ground research synthesis in retrieved source urls
2026-09-17 10:50:20 +00:00
pewdiepie-archdaemon
8ae0c31666
bound web research to retrieval and synthesis
2026-09-17 10:41:14 +00:00
pewdiepie-archdaemon
218d762427
Consolidate Odysseus agent harness and tool contracts
2026-09-17 10:07:40 +00:00
pewdiepie-archdaemon
84aa9a91de
Squash Odysseus development history
2026-09-11 06:04:19 +00:00
RaresKeY
c9dd68d890
refactor(docs): separate Pages site source ( #6176 )
...
* refactor(docs): separate Pages site source
* fix(docs): preserve published guide pages
* fix(ci): run asset ownership tests for site changes
* fix(docs): track future website media
* fix(ci): let Pages deployments finish
* build(deps): update Pages checkout action
* fix(ci): follow moved setup guide
* fix(docs): repair published setup guide
* fix(docs): retarget preview encoder
2026-08-27 10:20:36 +02:00
RaresKeY and StressTestor
7026cf40b5
docs: bootstrap specs ground truth ( #5794 )
...
* docs(specs): restore bootstrap after dev rewrite
* docs(specs): remove runtime inventory snapshot
* docs(specs): reconcile current dev truth
* docs(specs): document scheduled task actions as an owner-attribution source
Owner Attribution covered cookie, bearer-token and internal-loopback
requests. Scheduled task actions are a fourth source and behave
differently: _execute_action passes owner=task.owner off the stored
ScheduledTask row, so no request and no resolved principal are in
flight, and route-level require_user() never runs.
Webhook triggers are the sharp case. They are unauthenticated by
design with the token as the only credential and execute under the
stored task.owner.
Paths cite routes/task/task_routes.py, the canonical location after
the task subpackage move (#6081 ); routes/task_routes.py on current dev
is the backward-compat shim.
* docs(specs): add chained tasks to the trigger list, refresh dev stamp
Review feedback from RaresKeY on the previous commit.
"Every trigger path" was too broad: success-chained tasks are another
path into _execute_action. Added them with their own citation, and
noted that chaining additionally requires the target task to share
task.owner and rejects cycles, which is stricter than the trigger-side
checks. Softened the lead-in to "these trigger paths".
Line 56 still pointed at routes/task_routes.py for webhook credential
validation. That path is the backward-compat shim on current dev after
the task subpackage move (#6081 ); repointed to the canonical
routes/task/task_routes.py.
Stamp moved to dev@2a6b09b. Inspection backing that bump was scoped:
every file path cited in this spec was mechanically checked to resolve
on 2a6b09b , and every file:line in the Owner Attribution additions was
read against it. Behavioral claims elsewhere in the file were not
re-audited.
* docs(specs): correct SECURE_COOKIES description to match current behavior
Third of the stale details RaresKeY enumerated. The cookie section
described SECURE_COOKIES as purely opt-in, which stopped being true.
_secure_cookie() (routes/auth_routes.py:89) treats an explicit true or
false as authoritative and derives the Secure attribute from the
request otherwise, including when the variable is unset and when
docker-compose injects it present-but-empty. Either the connection
scheme or the first X-Forwarded-Proto hop being https is enough.
* docs(specs): refresh current dev truth
---------
Co-authored-by: StressTestor <212606152+StressTestor@users.noreply.github.com >
2026-08-25 14:18:44 +02:00
dependabot[bot]
bc7514fa3e
build(deps): bump the actions group with 11 updates ( #6141 )
...
Bumps the actions group with 11 updates:
| Package | From | To |
| --- | --- | --- |
| [actions/checkout](https://github.com/actions/checkout ) | `7.0.0` | `7.0.1` |
| [actions/setup-python](https://github.com/actions/setup-python ) | `6.2.0` | `7.0.0` |
| [actions/setup-node](https://github.com/actions/setup-node ) | `6.4.0` | `7.0.0` |
| [github/codeql-action/init](https://github.com/github/codeql-action ) | `4.36.2` | `4.37.7` |
| [github/codeql-action/analyze](https://github.com/github/codeql-action ) | `4.36.2` | `4.37.7` |
| [hadolint/hadolint-action](https://github.com/hadolint/hadolint-action ) | `3.3.0` | `3.4.0` |
| [docker/setup-buildx-action](https://github.com/docker/setup-buildx-action ) | `4.1.0` | `4.3.0` |
| [docker/build-push-action](https://github.com/docker/build-push-action ) | `7.2.0` | `7.3.0` |
| [github/codeql-action/upload-sarif](https://github.com/github/codeql-action ) | `4.36.2` | `4.37.7` |
| [docker/login-action](https://github.com/docker/login-action ) | `4.2.0` | `4.6.0` |
| [docker/metadata-action](https://github.com/docker/metadata-action ) | `6.1.0` | `6.2.0` |
Updates `actions/checkout` from 7.0.0 to 7.0.1
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1 )
Updates `actions/setup-python` from 6.2.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-python/releases )
- [Commits](https://github.com/actions/setup-python/compare/a309ff8b426b58ec0e2a45f0f869d46889d02405...5fda3b95a4ea91299a34e894583c3862153e4b97 )
Updates `actions/setup-node` from 6.4.0 to 7.0.0
- [Release notes](https://github.com/actions/setup-node/releases )
- [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e...820762786026740c76f36085b0efc47a31fe5020 )
Updates `github/codeql-action/init` from 4.36.2 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd )
Updates `github/codeql-action/analyze` from 4.36.2 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd )
Updates `hadolint/hadolint-action` from 3.3.0 to 3.4.0
- [Release notes](https://github.com/hadolint/hadolint-action/releases )
- [Commits](https://github.com/hadolint/hadolint-action/compare/2332a7b74a6de0dda2e2221d575162eba76ba5e5...2a66e89f53d0771bb131a7fa31f3136336094aa6 )
Updates `docker/setup-buildx-action` from 4.1.0 to 4.3.0
- [Release notes](https://github.com/docker/setup-buildx-action/releases )
- [Commits](https://github.com/docker/setup-buildx-action/compare/d7f5e7f509e45cec5c76c4d5afdd7de93d0b3df5...37fe631027851001ddb9b187196cc803df7f5f0e )
Updates `docker/build-push-action` from 7.2.0 to 7.3.0
- [Release notes](https://github.com/docker/build-push-action/releases )
- [Commits](https://github.com/docker/build-push-action/compare/f9f3042f7e2789586610d6e8b85c8f03e5195baf...53b7df96c91f9c12dcc8a07bcb9ccacbed38856a )
Updates `github/codeql-action/upload-sarif` from 4.36.2 to 4.37.7
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd )
Updates `docker/login-action` from 4.2.0 to 4.6.0
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...dbcb813823bdd20940b903addbd779551569679f )
Updates `docker/metadata-action` from 6.1.0 to 6.2.0
- [Release notes](https://github.com/docker/metadata-action/releases )
- [Commits](https://github.com/docker/metadata-action/compare/80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9...dc802804100637a589fabce1cb79ff13a1411302 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: actions
- dependency-name: actions/setup-python
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: actions/setup-node
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: actions
- dependency-name: github/codeql-action/init
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: github/codeql-action/analyze
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: hadolint/hadolint-action
dependency-version: 3.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/setup-buildx-action
dependency-version: 4.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/build-push-action
dependency-version: 7.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: github/codeql-action/upload-sarif
dependency-version: 4.37.7
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/login-action
dependency-version: 4.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
- dependency-name: docker/metadata-action
dependency-version: 6.2.0
dependency-type: direct:production
update-type: version-update:semver-minor
dependency-group: actions
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 14:06:31 +02:00
dependabot[bot]
e5ab632270
build(deps-dev): bump @antithesishq/bombadil ( #6026 )
...
Bumps the npm group with 1 update in the / directory: [@antithesishq/bombadil](https://github.com/antithesishq/bombadil ).
Updates `@antithesishq/bombadil` from 0.6.1 to 0.7.0
- [Release notes](https://github.com/antithesishq/bombadil/releases )
- [Changelog](https://github.com/antithesishq/bombadil/blob/main/CHANGELOG.md )
- [Commits](https://github.com/antithesishq/bombadil/compare/v0.6.1...v0.7.0 )
---
updated-dependencies:
- dependency-name: "@antithesishq/bombadil"
dependency-version: 0.7.0
dependency-type: direct:development
update-type: version-update:semver-minor
dependency-group: npm
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-25 14:03:11 +02:00
RaresKeY
e71f8ceb65
chore(release): align dev version with 1.0.3 ( #6168 )
...
Keep dev version metadata aligned with the current hotfix release while the rolling branch continues toward 1.1.0.
Evidence: the canonical APP_VERSION imports as 1.0.3 and the diff check is clean. This commit changes version metadata only; it does not tag or publish a release.
2026-08-25 10:26:18 +01:00
nopoz
d0d8edf5d8
Merge commit from fork
...
scripts/mlx_image_server.py resolved the model per request
(`req.model or _args.model`) on both /v1/images/generations and
/v1/images/edits, so the caller chose which model was served.
`_is_hidream()` is a substring test and `_snapshot_path()` accepts either a
local directory or a Hugging Face repo id, so a caller-supplied string
selected the HiDream branch and then supplied the directory it runs
`scripts/hidream_o1/generate_hidream_o1_mlx.py` from, under sys.executable.
The server has no auth, and the Cookbook binds it to 0.0.0.0 whenever it is
serving to a remote host, so one POST executed attacker code on the serving
host.
Both paths now use `_args.model`. The request field is still accepted for
OpenAI wire compatibility and ignored, matching scripts/diffusion_server.py,
and Odysseus already sends the served model's own id, so this is a no-op for
legitimate callers. /v1/images/harmonize already pinned.
Regression tests cover both endpoints, the local-directory and
Hugging-Face-repo halves, and that a server actually launched with a HiDream
model still serves it. Three of the four fail on the unfixed code.
2026-08-24 17:38:40 +02:00