| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
fix(run): make an explicit ai-jail selection exact with --no-X for unselected rows The checklist and `--jail=LIST` emitted only enabled toggles, so the user's own ai-jail config (e.g. a global `~/.ai-jail` enabling `docker`) could still mount what an unchecked row or an explicit list left out, and the summary line misreported it. - Interactive checklist: `marked_choices` passes every row the user saw, checked as `--X` and unchecked as `--no-X`. - `--jail=LIST` (including `none`): after the named entries, every visible checklist row the list did not name is forced off with `--no-X`. Rows that are not visible (absent credentials, CLI-only toggles) are never forced. - Bare `--jail` is unchanged: smart-default rows only, the rest left to the user's ai-jail config, because no selection was shown. - `JailToggleChoice::implied` marks rows forced off by omission, so the summary names the user's own `no-X` entries and says "everything else in the checklist off" for the rest. - Tests: an adversarial unit test (unchecked docker row and `--jail=none` yield `--no-docker` / `--no-*` for every visible row, with bare `--jail` as the control); parse, checklist, summary and end-to-end expectations updated, the latter platform-aware for the Linux-only rows. - Docs: design §5 semantics, cookbook, support matrix, CHANGELOG. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm | 6 小时前 | |
Merge main into release/2.5 (forward-merge: 2.4.2 + #995 #985 #984 #978 #991) # Conflicts: # CHANGELOG.md # crates/ai-memory-hooks/src/router.rs # docs/security-boundaries.md | 1 天前 | |
feat(core): expose is_dos_device_name for reuse outside PagePath Server profile names become file names, so the CLI needs the same Windows device-name check PagePath components already get. Expose it instead of keeping a second list that can drift. | 18 小时前 | |
fix(security): derive capture-exclusion path flavor from the host (GHSA-vh98) A capture-exclusion candidate or shell argument spelled with a leading `//` (e.g. `//repo/secret/token.txt`) self-classified as a Windows UNC path regardless of the actual host. On a POSIX host `match_paths` then filtered it against zero POSIX `ignore_paths` patterns (a flavor mismatch), so the file was captured instead of dropped — a fail-open in the capture trust boundary. Path flavor for an untrusted candidate is now derived from the host (the cwd): on a POSIX host a leading `//` collapses to a single `/` before classification, so it matches POSIX `ignore_paths` as intended. A genuine Windows/UNC host's UNC candidates are unaffected. Fixed in both front doors — the native hook (`ai-memory-hooks` `capture_policy.rs`) and the generated TypeScript integrations (`ai-memory-cli` `render_shared.rs`, `captureHostWindows` / `windowsHost`) — with a shared regression fixture and an adversarial test per surface (violation + POSIX control + Windows-UNC control). Also documents (docs/users.md) that a trusted-proxy non-root user is `AuthLevel::User` with no DB identity, so `restricted`/grant enforcement does not apply to them — the proxy is the authz boundary — and records that boundary and its pinning test in docs/security-boundaries.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm | 12 小时前 | |
Merge branch 'pr-859' into release/2.5 # Conflicts: # CHANGELOG.md | 7 天前 | |
Merge PR #756: fix(cli): apply message send admission and post-commit observers # Conflicts: # CHANGELOG.md | 7 小时前 | |
fix(read_page): include_related only walks pages the caller may read Under per-project authorization (#708), page_links and the graph drop a link whose far end is in a project the viewer cannot read, but the multi-hop related walk behind memory_read_page's include_related took no viewer. A restricted user therefore got the path, title, workspace and project of pages in projects they hold no grant on, up to three hops out, and the walked pages had their access bumped on the user's behalf. related_walk now takes the viewer and appends the same readable_repository_predicate to both the outgoing and incoming hop queries, so an unreadable page is neither returned nor walked through. memory_read_page passes viewer_from_parts. A None viewer (root, or authorization off) walks exactly as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014aqFKAuGVkuBoewmpA3cx9 | 17 小时前 | |
perf(dev): a self-contained build and a two-tier test loop on every platform The edit-to-result loop was ~380s for the workspace on macOS and needed an environment variable on every command. This makes `cargo t` the whole story on macOS, Linux, and Windows, with numbers measured along the way. Build - `[profile.dev]` keeps only line tables (full debuginfo put ~190 MB of DWARF in each test binary and made the build linker-bound); dependencies build at opt-level 1 with no debuginfo; proc macros and build scripts at opt-level 3, since they are run once per dependent crate. - Test binaries: 78 to 11 in the everyday loop (13 under `--workspace`). Each one is a link and, on macOS (Gatekeeper) and Windows (Defender), a first-run malware scan of the whole file, paid serially by nextest's list phase before the first test starts. Integration tests now live in `tests/suite/` and compile into their crate's own test harness (`mod.rs`, included from `src/lib.rs` under `#[cfg(test)]`, with `extern crate self` so they keep addressing the public API by crate name). Only the CLI keeps a separate `suite` target, because its tests run the built executable. The evals harness leaves `default-members`, so a bare `cargo t` skips its two binaries while `--workspace` (CI, the hook, `cargo tf`) still builds them. A repo-layout test fails on an undeclared suite file, a stray top-level `tests/*.rs`, or a `mod.rs` that `lib.rs` never includes. - `ai-memory-cli` gains a lib target; `main.rs` is a shim. 806 tests that lived in the bin are reachable, and `--lib` runs skip the 127 MB binary. - The web crate's vendored `static/tailwind.css` is the default on every build, so nothing needs `TAILWIND_SKIP=1` any more: every release, Docker, and CI path already used the vendored file, and the download branch only ever ran for developers who forgot the flag (and then rewrote the source tree as a side effect). `TAILWIND_BUILD=1 cargo build -p ai-memory-web` regenerates it explicitly. CI runs that on Linux and fails if the committed file is stale, a check that did not exist before; the committed file reproduces byte for byte today. - `tokenizers` aligned on one version instead of the 0.21 pin plus the 0.22 candle pulled in. Test tiers - `.config/nextest.toml`: the `default` profile skips any test whose module path has a segment starting with `slow` or `stress` (`packaging::slow::*` drives real wrapper scripts and fake container engines at 10-20s each; `stress_*` modules hammer concurrency), reports every failure in one run, and marks anything over 5s in its summary so a new slow test is visible the day it lands. `full` runs everything. `ci` keeps its retries and writes JUnit. - `.cargo/config.toml` holds two aliases and nothing else: `cargo t` (default members) and `cargo tf` (`--workspace -P full`). `cargo t -p <crate>` builds just that crate. Neither passes `--all-targets`: there are no examples or benches, and it only added harnesses for two `test = false` targets. - `scripts/install-git-hooks.sh` installs an opt-in pre-push hook that runs the full tier, touching only its own marked block. Two independent things run the skipped tier: that hook, and CI, which uses `cargo test` and never reads the nextest config. Slow tests fixed rather than tiered - `project_observations` in the consolidator trimmed an over-budget projection one observation at a time, re-rendering the whole text and re-scoring every remaining candidate after each removal. Each score scans the body, so 256 observations of 4k chars cost ~65k body scans per prompt: 14s in production consolidation, exactly as in the unit test. Scores and per-block sizes are now computed once and the prune subtracts; output is unchanged and pinned by the existing tests. 13.9s to 0.18s. - Windows takes ~2s to refuse a loopback connect, so every hook test that posted to a closed port paid 2s per request. `dead_http_endpoint()` in the new `ai-memory-test-support` crate accepts and closes instead, with a fallback to the closed port where binding is denied. devin hook tests: 4.2s to 0.15s each. - The store unit fixture opened a file-backed SQLite with the default rollback journal and synchronous=FULL, so ~120 parallel fixtures fsynced every transaction. journal_mode=MEMORY + synchronous=OFF: 242s to 89s of test time, p90 1.6s to 0.5s. - Windows-only tests resolve `powershell.exe` or `pwsh.exe` once per process and the auto-improve eval fixtures are `.ps1` scripts instead of cmd.exe batch files; a post-bind settle sleep is gone; the two unpinned multi-thread tokio tests pin `worker_threads = 4`. The four copies of the PowerShell resolver and the mcp suite's duplicated `post`/`get` helpers are now one each. Not done, with the numbers in AGENTS.md: nextest vs in-process libtest is a wash per crate and a rout for the workspace (20s vs 309s); the `local-embeddings` default feature costs ~50s of cold build and ~27 MB per binary but under a second per relink, so it stays a product default. Measured: workspace loop ~380s to ~150s on macOS; on a 32-thread Windows box the warm everyday run is 20s of test time across 2919 tests in 11 binaries, and the rebuild after a core edit is 13s of cargo with lld plus the first-run scans. | 26 天前 | |
fix(security): derive capture-exclusion path flavor from the host (GHSA-vh98) A capture-exclusion candidate or shell argument spelled with a leading `//` (e.g. `//repo/secret/token.txt`) self-classified as a Windows UNC path regardless of the actual host. On a POSIX host `match_paths` then filtered it against zero POSIX `ignore_paths` patterns (a flavor mismatch), so the file was captured instead of dropped — a fail-open in the capture trust boundary. Path flavor for an untrusted candidate is now derived from the host (the cwd): on a POSIX host a leading `//` collapses to a single `/` before classification, so it matches POSIX `ignore_paths` as intended. A genuine Windows/UNC host's UNC candidates are unaffected. Fixed in both front doors — the native hook (`ai-memory-hooks` `capture_policy.rs`) and the generated TypeScript integrations (`ai-memory-cli` `render_shared.rs`, `captureHostWindows` / `windowsHost`) — with a shared regression fixture and an adversarial test per surface (violation + POSIX control + Windows-UNC control). Also documents (docs/users.md) that a trusted-proxy non-root user is `AuthLevel::User` with no DB identity, so `restricted`/grant enforcement does not apply to them — the proxy is the authz boundary — and records that boundary and its pinning test in docs/security-boundaries.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm | 12 小时前 | |
Merge fix/wiki-racy-read-enoent: retry a walk that read a vanished file # Conflicts: # CHANGELOG.md | 7 小时前 | |
fix(run): make an explicit ai-jail selection exact with --no-X for unselected rows The checklist and `--jail=LIST` emitted only enabled toggles, so the user's own ai-jail config (e.g. a global `~/.ai-jail` enabling `docker`) could still mount what an unchecked row or an explicit list left out, and the summary line misreported it. - Interactive checklist: `marked_choices` passes every row the user saw, checked as `--X` and unchecked as `--no-X`. - `--jail=LIST` (including `none`): after the named entries, every visible checklist row the list did not name is forced off with `--no-X`. Rows that are not visible (absent credentials, CLI-only toggles) are never forced. - Bare `--jail` is unchanged: smart-default rows only, the rest left to the user's ai-jail config, because no selection was shown. - `JailToggleChoice::implied` marks rows forced off by omission, so the summary names the user's own `no-X` entries and says "everything else in the checklist off" for the rest. - Tests: an adversarial unit test (unchecked docker row and `--jail=none` yield `--no-docker` / `--no-*` for every visible row, with bare `--jail` as the control); parse, checklist, summary and end-to-end expectations updated, the latter platform-aware for the Linux-only rows. - Docs: design §5 semantics, cookbook, support matrix, CHANGELOG. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MDbhmszrjG9s5MrPrTuNtm | 6 小时前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 6 小时前 | ||
| 1 天前 | ||
| 18 小时前 | ||
| 12 小时前 | ||
| 7 天前 | ||
| 7 小时前 | ||
| 17 小时前 | ||
| 26 天前 | ||
| 12 小时前 | ||
| 7 小时前 | ||
| 6 小时前 |