Commit Graph
60 Commits
Author SHA1 Message Date
Buddhika GodakandaandClaude d9fbb0790b Recover truncated tool calls, and never pass a leaked one off as an answer
Small local models drift off the tool-call format, especially with a large
tool schema in play. Two failures followed from that, both of which ended
the turn looking like the model had simply stopped mid-sentence.

Salvage handled well-formed Qwen/Hermes XML but gave up entirely on a call
cut off partway through. It now takes the function name plus every
parameter that actually closed. A trailing unterminated `<parameter=…>` is
dropped rather than guessed, so a half-written path or file body can never
reach a tool; if that leaves a required argument missing, the call fails
validation and the model gets a corrective tool error, which is the agent
loop working.

Worse, a call that never parsed at all was reported as `status: completed`
— indistinguishable from the model deciding it was done, leaving the user
with narration trailing off into stray closing tags. It now ends on the
error path, so the GUI offers Retry. That is the right affordance here: the
drift is probabilistic, not deterministic, so the same model usually
succeeds on a second attempt.

Detection ignores fenced and inline code, so a model *explaining* tool-call
syntax is still a real answer, and requires that tools were offered at all.

Reported against qwen3.5-9b on LM Studio, 2026-07-26.

Co-Authored-By: Claude <noreply@anthropic.com>
2026-07-27 05:50:54 +05:30
Rohit Prasad db93d75bf6 Merge pull request #101 from andrewyng/meta-muse-spark
Add Meta Model API provider with Muse Spark 1.1
2026-07-25 01:27:39 -07:00
Rohit C Prasad fc6ce501dd Add Meta Model API provider with Muse Spark 1.1 2026-07-25 01:21:07 -07:00
Rohit Prasad f467c4ca73 Merge pull request #115 from andrewyng/rpSlackApprovalOwners
Harden Slack approval handling
2026-07-25 00:38:50 -07:00
Rohit P 7656952692 security: harden Slack approval handling 2026-07-24 22:33:13 -07:00
Rohit Prasad 56b3c62864 Merge pull request #107 from andrewyng/rpSecurityHardeningFollowup
Security Hardening
2026-07-24 22:05:43 -07:00
Rohit P ac83bc0490 security: complete local access protections 2026-07-24 18:44:39 -07:00
Rohit P 3f5ac872ca security: refine workspace trust controls 2026-07-24 18:44:39 -07:00
Rohit P 8ee0a0d082 security: strengthen session handling 2026-07-24 18:44:39 -07:00
Rohit P 9cc2761998 security: tighten permission handling 2026-07-24 18:44:39 -07:00
Rohit Prasad 54b4bfd82d Merge pull request #103 from andrewyng/fix-ci-ollama-probe
Pin the Ollama probe in the curated-models test
2026-07-24 17:37:29 -07:00
Rohit Prasad dd33f2cab0 Merge pull request #49 from fahadsiddiqui/harden/boundary-oauth-shell-ws
fix: harden local trust boundaries (shell allowlist, MCP OAuth loopback, WS ingestion)
2026-07-24 15:43:59 -07:00
Rohit C Prasad 2325728f3f Pin the Ollama probe in the curated-models test
The picker gates ollama:* on a live local probe, so this passed only where Ollama runs and failed in CI.
The probe's own behaviour stays covered by test_ollama_models_gated_on_liveness.
2026-07-24 12:48:38 -07:00
Fahad Siddiqui 657cf03460 fix: harden local trust boundaries (shell allowlist, MCP OAuth loopback, WS ingestion)
Boundary-hardening pass addressing three audit findings on the local sidecar.

Shell command allowlist (andrewyng/openworker#28):
- Replace prefix-string matching in PermissionEngine._command_allowed with
  argv-aware matching: reject any command containing shell operators
  (; & | > < ` $( ( and newlines) before consulting the allowlist, then require
  the allowlisted entry's tokens to be an exact argv prefix. This closes the
  auto-run bypass where an allowlisted "git status" also auto-ran
  "git status && rm -rf ~", pipes, redirection, and command substitution.
- Drop language interpreters / package managers (python, python3, node, npm,
  npx) from DEFAULT_ALLOWED_COMMANDS — allowlisting an interpreter allowlists
  arbitrary code (python3 -c "..."), defeating approval gating. Read-only
  inspection commands and pytest remain.

MCP OAuth loopback (andrewyng/openworker#29):
- Verify the OAuth state at the loopback boundary. The MCP SDK already validates
  state (compare_digest), so this is not a CSRF fix but defense-in-depth: capture
  the state from the authorize URL and have deliver_callback ignore a callback
  whose state does not match WITHOUT consuming the pending future, so a stray or
  forged local hit can no longer abort a user's in-progress sign-in. Falls back to
  prior accept-any behavior when no state was captured.

WebSocket ingestion caps (andrewyng/openworker#38):
- Bound a single user_message frame in the session WS loop: max text length,
  max attachment count, and max total attachment bytes. Oversized frames get a
  visible error frame and are dropped instead of being buffered into a turn; the
  socket stays alive. Guards the unauthenticated loopback socket against cheap
  memory spikes.

Tests:
- Allowlist: reject operator chaining (8 variants), argv-boundary matching, and
  interpreters-not-auto-allowed-by-default.
- OAuth: state extraction, and mismatched/missing state ignored without consuming
  the flow while the matching state still resolves it.
- WS: oversized text and too-many-attachments rejected with an error frame, and a
  normal message still works afterwards.

Full suite: 865 passed (1 pre-existing unrelated failure in
test_provider_router::test_manager_curated_models, present on origin/main).
2026-07-24 01:41:05 +05:00
Yashas 4766e59c47 Keep ripgrep searches out of generated directories (#10)
* Skip generated directories in ripgrep searches

* Apply ripgrep exclusions after user globs
2026-07-23 12:29:19 -07:00
Rohit P 4ffc73f1e8 README: Minor updates. 2026-07-23 11:26:19 -07:00
Rohit C Prasad f7c70a2478 README: add how-it-works diagram from the website 2026-07-23 09:29:00 -07:00
Rohit C Prasad 062b1b12b3 Update README 2026-07-23 09:23:56 -07:00
Rohit C Prasad 0e48499075 README: link the website 2026-07-23 09:14:26 -07:00
Rohit C Prasad 9fc4bc43e6 Rewrite README: download links, capabilities, architecture, run-from-source 2026-07-23 09:01:29 -07:00
Rohit C Prasad da1d25373c Prepare app release 0.1.6: version bump v0.1.6 2026-07-23 08:49:30 -07:00
Rohit C Prasad 27d72e5c5e Add Kimi K2.7 Code via Together to the model matrix 2026-07-23 08:41:21 -07:00
Rohit C Prasad eae5fbd8d0 Fix Anthropic extended thinking for current model families
Adaptive thinking for 4.6+/newest models, budgets kept for older ones.
Safety-refusal fallback to Opus for the newest tier; add Inkling via Together.
2026-07-23 08:25:47 -07:00
Rohit C Prasad ba99978e03 Enable Claude extended thinking by default, drop the settings field
Fixed 8192 budget; the provider profile key stays a hidden override (0 = off).
Per-turn composer control is future work.
2026-07-23 07:57:04 -07:00
Rohit C Prasad 2968254713 Keep the BETA chip on the wordmark line
Smaller raised chip, nowrap on the wordmark — no second line under the traffic lights.
2026-07-23 07:50:27 -07:00
Rohit C Prasad a9458524e8 Blur-save non-secret provider fields on configured providers
The Test button was the form's only save path — extras like the thinking budget
silently never persisted. Blur saves with a Saved flash; empty clears.
2026-07-23 07:43:24 -07:00
Rohit C Prasad 3d00187310 Add BETA tag: sidebar wordmark, boot splash, onboarding, README
Quiet gray chip, presentation-only — never in bundle or artifact names (updater safety).
2026-07-23 07:43:24 -07:00
Rohit C Prasad f2b8fde428 Keep Retry offered across model switches
Switch notices no longer consume the retry guard or hide the button.
Error, switch model, Retry is the intended recovery path; retry runs on the new model.
2026-07-23 07:43:24 -07:00
Rohit C Prasad d10990bdf7 Coerce union-typed JSON Schema for Gemini tool declarations
Vendor MCP schemas with type: [a, b] failed SDK validation and killed every Gemini turn.
Null unions become nullable; multi-type unions become anyOf.
2026-07-23 07:43:24 -07:00
Rohit C Prasad 52038c2136 Fix boot splash mark and stuck model picker on cold start
Splash shows the real 6-point OpenWorker star, not the 4-point sparkle glyph.
Settings reload after the health check lands, so the picker can't stay on Loading models.
2026-07-23 07:43:24 -07:00
Rohit C Prasad 2a2fffd280 Pause Google one-click connect pending CASA verification
Gmail/Calendar/Drive show a disabled Coming-soon button; the server refuses the flow too.
Manual token connect and already-connected accounts are untouched.
2026-07-23 07:43:24 -07:00
Rohit C Prasad 71b0df8ea2 Rename bot references from ocw to OpenWorker
Correlation token now emits [ow:id]; legacy [ocw:id] replies still parse.
Invite hints and docstrings say @OpenWorker.
2026-07-23 07:43:24 -07:00
Rohit C Prasad 1032e3a664 Persist Always-allow grants with the session
Grants were in-memory only — every restart re-asked for approved tools/commands.
Saved on the session record, re-applied on engine rebuild.
2026-07-23 07:43:24 -07:00
Rohit C Prasad 5a61873ae0 Trim release UI: simpler Settings, mode menu, session subtitle
Mode menu offers Discuss/Ask for approval/Full access only.
Topbar subtitle is model-only and inert (persona page hidden this release).
2026-07-23 07:43:24 -07:00
Rohit C Prasad 55ff8b76e9 Anthropic extended thinking, opt-in via provider thinking_budget field
Thinking/redacted blocks replay verbatim in tool loops via the _anthropic sidecar.
Streaming thinking_delta/signature_delta surface as reasoning; sampling knobs dropped.
Live-verified tool loop + streaming on claude-haiku-4-5.
2026-07-22 16:38:25 -07:00
Rohit C Prasad 0e8b85e6f3 Show reasoning traces: live Thinking block + persisted disclosure
New reasoning_delta event; traces persist as a display sidecar stripped from provider feeds.
Sources: compat vendors' reasoning_content and Gemini thought summaries (include_thoughts).
Live-verified on GLM via Together and Gemini 3; Gemini tool loops stay healthy.
2026-07-22 16:15:11 -07:00
Rohit C Prasad f1eb652d61 Allow mid-session model switching with a persisted transcript marker
Picker stays live for the session; switches persist a model_switch notice (§17 revised).
Rebinds refused mid-turn; images become placeholders for non-vision targets at send time.
2026-07-22 15:43:54 -07:00
Rohit C Prasad a63710ecfe Add Gemini 3 models with thought-signature support
Signatures ride the assistant message as a _gemini sidecar and are reattached in tool loops.
Thought-flagged parts are filtered from answer text; foreign sidecars stripped on the OpenAI wire.
Live-verified both Gemini 3 models end-to-end; without the echo they 400 on every tool loop.
2026-07-22 14:05:23 -07:00
Rohit C Prasad 878b858ece Persist error/interrupt markers in history; add Retry on failed turns
Engine appends a display-only notice message on error/interrupted; providers never see it.
New retry frame re-runs a failed turn with no new user message, guarded on the error tail.
GUI renders persisted notices on reload and a Retry button on the trailing error.
2026-07-22 13:45:43 -07:00
Rohit C Prasad d8903bc927 Keep interrupted partial streams in the transcript
GUI flushes the streaming buffer into a durable item on interrupted/error.
Engine persists partial text on the provider-error path like the stop path.
e2e red-green verified; full suites pass.
2026-07-22 10:40:01 -07:00
Rohit C Prasad f32f75feb2 Prepare app release 0.1.5: version bump v0.1.5 2026-07-21 23:16:54 -07:00
Rohit C Prasad 87efcec09d updater: passive install mode on Windows
Progress bar only — no NSIS dialogs during auto-update (takes effect updating FROM 0.1.5).
2026-07-21 23:16:40 -07:00
Rohit C Prasad 628b6a82d3 gui: gate the macOS overlay layout to macOS
Shell injects the OS; Windows/Linux keep the native title bar with no traffic-light insets.
Thin scrollbars on Windows/Linux so panels stop losing width to classic scrollbars.
2026-07-21 23:16:40 -07:00
Rohit C Prasad f6ad97274d engine: Stop works in every state, not just between iterations
Stream drops between chunks (+ the pre-first-token wait); pending approvals/questions/plans resolve as interrupted.
Running shell commands die via an executor interrupt hook; skipped tool calls still get results (no orphans).
Also fixes delete_session calling a nonexistent engine.interrupt().
2026-07-21 23:16:40 -07:00
Rohit C Prasad 0bc149fae4 gui: boot splash says Starting OpenWorker 2026-07-21 22:02:20 -07:00
Rohit C Prasad 5e3c3c9810 settings: gate ollama models on a live local Ollama
Keyless is not configured — ollama:* picker entries render only while /api/tags answers (30s cached probe).
Stops phantom local models on machines without Ollama.
2026-07-21 22:02:20 -07:00
Rohit C Prasad 4241f4ac64 updater: point the GitHub fallback endpoint at this repo
The branded redirect stays primary; the baked fallback still named the old monorepo.
v0.1.4
2026-07-21 17:20:08 -07:00
Andrew Ng 99a0956556 README
Added introductory information about OpenWorker, its functionalities, and usage.
2026-07-21 16:36:49 -07:00
Rohit C Prasad 946b21d838 Prepare app release 0.1.4: version bump 2026-07-21 16:05:26 -07:00
Rohit C Prasad 009d46600e composer: drop the hardcoded model fallback
Until /v1/settings supplies the list the picker is a disabled "Loading models…" chip.
The baked-in list had gone stale and offered phantom ids during the boot race.
2026-07-21 16:05:15 -07:00