Autumn-27
052c35a954
Merge PR #18 : delete traffic targets and LLM task conversations from UI (laohuan12138)
...
- Traffic 页:按 host 多选精确批量删 + 子串删 + 删后 _blobs 内容寻址块 GC 回收;新增 GET /api/traffic/hosts
- LLM 记录页:按 task_id 下拉选择 + 按任务删除
- 修复 host 选择器 Popover 高度渲染;.gitignore 加 /dist/
- 新增 traffic/traffic_test.go(DeleteHost/DeleteHostsExact/Hosts/GC 共 4 个测试)
本地已验证:go build/vet、traffic 测试、前端 tsc/build 均通过;与当前 main 无冲突。
2026-08-11 09:38:12 -04:00
Autumn-27
37bb386f97
build(bench): 新增 tsecbench 测评环境
...
- Dockerfile.bench / docker-compose.bench.yml:tsecbench 测评镜像与编排
- bench/entrypoint.sh、seed.sh:容器入口与任务种子脚本
- bench/prompts/*:测评用 planner/worker/challenge 提示词
- bench/.env.example、kali_tools.txt:配置模板与工具清单(真实 .env 仍被忽略)
2026-08-11 09:20:29 -04:00
Autumn-27
6b1a756a59
chore(deps): 升级 Autumn-27/norma v0.2.7 → v0.2.8
2026-08-11 09:17:14 -04:00
Autumn-27
79493d5a4a
feat(activity): 任务会话历史反向分页 + SSE 可靠性整改
...
后端:
- ActivityPage(会话过滤 main/plan/intent + before 反向分页)、ActivityMaxID
(任务级快照游标)、ListByKindPage(Intent 列表分页,突破固定 300 上限)
- 新增 GET /api/exploration/activity/history(items/snapshot_cursor/
earliest_cursor/has_more);snapshot_cursor 为任务级游标
- streamActivity:一次 2000 → 循环补偿追平;输出标准 SSE id 行;支持
Last-Event-ID;补偿查询错误记录日志并关闭连接
- intents 支持分页形态(?before/?page → {items,has_more}),无参数保持旧裸数组
- 新增 idx_act_worker(exploration_id, worker, id) 支撑 Main/Plan 反向翻页
(schema.sql 幂等,旧库启动自动补建,无迁移)
前端:
- sessions-tab 单一 allActivity → 分会话缓存;首屏只加载 Main 最新页并据其
快照游标建唯一任务级 SSE;Plan/Worker 点击懒加载
- 统一 mergeBySeq 合并去重;未激活会话只维护 lastTs/unread;向上滚动分页
加载旧历史并保持滚动位置;每会话内存上限裁剪
- 按 session_key 写各自缓存 + 每 key 请求令牌防会话切换串数据;SSE 连接状态
可见、加载失败可重试,异常不再静默为"暂无消息"
- api 新增 activityHistory / intentsPage
测试:db/activity_page_test.go 覆盖多 Agent 过滤、反向翻页无重复无遗漏、
快照游标、Intent 超页分页(已对真实 PostgreSQL 通过)
2026-08-11 09:13:12 -04:00
Autumn-27
95aba396c2
feat(activity): 丢弃记录日志合并为单条 error,带 reason/summary/累计数
...
- 把「丢弃该记录」与「FK 诊断」合并成一条 error 级日志(含"丢弃"关键字,
后台只筛 error 也能看到完整信息,不再漏掉 info 级诊断行)
- reason 分类:fk_violation(23503) / unique_violation(23505) / pg_error(code) / write_error
- 带 summary 预览(截断去换行)+ 该任务累计丢弃条数,便于判断丢的是哪条、丢弃规模
- 新增 dropReason/bumpDrop/preview 辅助与 dropCnt 计数
2026-08-11 09:10:35 -04:00
Autumn-27
ea833ad992
feat(activity): 写失败时带 expID,并对外键(23503)现场诊断
...
- AppendActivity 失败日志补上 store.expID,直观看到写的是哪个 exploration
- 丢弃记录时若为外键违反(SQLSTATE 23503),调用新增的 ExplorationDiag 现场查库:
exploration 是否存在 / 引用它的 task 数 / 当前 MAX(exploration.id),
一行日志区分「父行真没了」vs「expID 拿错了」vs「外键未按 RESTRICT 建」
- 系统日志页时间戳补上年月日(原来只有时分秒)
2026-08-11 08:44:55 -04:00
Autumn-27
daee98b33a
build: install telnet in runtime image
2026-08-10 11:21:47 -04:00
Autumn-27
f43f2a7c8f
fix(mock): update DeepSeek base URL
2026-08-10 11:18:00 -04:00
FileShare Developer
c76d0f4c93
feat: delete traffic targets and LLM task conversations from UI
...
Add delete controls to the Traffic and LLM Records pages so users can
purge recorded data without hand-editing the data volume.
Traffic page:
- Host target picker (Popover with checkboxes + select-all toggle)
- Exact-match batch delete for multiple hosts (DELETE /api/traffic/hosts)
- Substring delete for the host-filter input (DELETE /api/traffic?host=)
- Orphaned content-addressed blob garbage collection after deletes
- Distinct-hosts endpoint (GET /api/traffic/hosts) for the picker
LLM Records page:
- Task picker dropdown (distinct task_id + record counts)
- Per-task delete (DELETE /api/llm/records?task=)
Other:
- Add /dist/ to .gitignore (build artifact)
- Extend traffic_test.go with DeleteHost, DeleteHostsExact, Hosts tests
- Fix Popover render bug (replace ScrollArea that broke height calc)
- Remove fade/zoom animation on the host picker Popover
2026-08-10 11:10:58 +08:00
Autumn-27 and Claude Opus 4.8
a121e8967c
fix(scope): add_task_scope 支持 host:port 目标,入库前剥端口
...
ip/root_domain/subdomain 三类范围入库前统一 stripHostPort:
- ip 带端口(如 10.0.188.136:3000)之前直接报"无效 ip/cidr"
- 域名带端口更隐蔽,不报错却存下匹配不到资产的垃圾键
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 09:09:59 -04:00
Autumn-27 and Claude Opus 4.8
e00a4a8e72
refactor(asset): delete_assets_by_host 改为平台工具(默认绑 Auto)
...
之前作为任务域工具挂在 worker/mainagent 列表里;移除绑定后它也从 BuiltinToolSeeds
自动生成的 seed 清单里消失,导致从未写入 tools 表、UI 看不到。改到平台工具层
(platformTools),由 seedOrchestrationTools 每次启动独立 seed 并默认绑内置 Auto agent,
不属于任务 agent。db 层 DeleteByHost 不变。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 04:49:57 -04:00
Autumn-27 and Claude Opus 4.8
e30218f948
feat(asset): 新增按 host 精确删除资产的工具 delete_assets_by_host
...
DeleteByHost(host):DomainKey 归一化后按 domain/root_domain/ip 精确等值删除,
连带该 host 下的 service/endpoint;传根域名会连带其子域名。exploration_anchors
为 ON DELETE CASCADE,删除不被外键阻塞。工具层 delete_assets_by_host 返回按类型
分组的删除计数。硬删除、作用于全局资产库、不可撤销。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 04:18:21 -04:00
Autumn-27 and Claude Opus 4.8
aab6b9c948
fix(ui): 抽屉/对话框内 Select 等弹层不再误关抽屉
...
抽屉内 Radix 弹层(Select 下拉等)portal 到抽屉外,开着弹层时点遮罩,同一次
pointerdown 被 Select 与 Sheet 两个 DismissableLayer 处理:Select 先关闭且是
discrete 事件、React 同步 flush,轮到 Sheet 判断时弹层 data-state 已翻成 closed,
"当下检测弹层是否打开"不可靠,导致抽屉被连带关闭。
改为在 pointerdown 的 capture 阶段(早于 Radix 冒泡监听)先记录"此刻有无弹层开着",
onInteractOutside 据此:开着弹层时点遮罩→只收弹层不关抽屉;无弹层时点遮罩→正常关闭。
下沉到 sheet.tsx/dialog.tsx 基础组件,一次覆盖所有含下拉的抽屉/对话框;移除 agents
页此前重复的 per-callsite 处理。已用无头浏览器验证三种场景(点选项/点遮罩收下拉/
无弹层点遮罩关闭)均正确。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 03:17:49 -04:00
Autumn-27 and Claude Opus 4.8
f86885ec3d
feat(task): 创建任务可选下发种子意图,worker 免等首轮规划直接开跑
...
新增 seed_first_intent(默认开启):创建即把"描述+目标"作为一条意图
写入 frontier,worker 轮询领取立即执行,省掉开跑前的首轮 planner LLM;
跑完由 NotifyDone 正常唤醒 planner 判定/补充。CTF 场景常一 work 解决。
- Engine.Run 首轮 kick 改为"frontier 为空才触发",一处覆盖普通/种子/恢复三种情况
- HTTP createTask 与 spawn_task 工具同步支持;bump 工具 schema 刷新 flag 使旧库生效
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 02:19:40 -04:00
Autumn-27 and Claude Opus 4.8
4cf622593a
feat(trigger): 新增"任务创建"触发机制(on_task_create)
...
自定义 agent 触发条件从 5 种扩展到 6 种,新增任务被创建时触发。
用 tasks.id 单调水位线 + scheduler_state 防重复,重启不补触发;
触发消息完整分行给出任务ID/描述/目标。DB 加列并带 ALTER 迁移。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 02:19:29 -04:00
Autumn-27 and Claude Opus 4.8
5962826f2d
feat(mock): 补全工具执行 / LLM 录制的 mock 数据
...
- data:commandRecords(curl/sqlmap/ffuf/nmap + 超时报错)、llmRecords
(worker/planner,含一条 429 error) + llmRecordDetail(带 req/resp body)
- handler:/commands、/llm/records、/llm/records/{id} 路由
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 01:33:23 -04:00
Autumn-27 and Claude Opus 4.8
de09b1746f
docs(readme): 增加资产覆盖图截图
...
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 01:33:23 -04:00
Autumn-27 and Claude Opus 4.8
4c407dc448
feat(mock): 补全新功能的 mock 数据(覆盖度/覆盖图/关联/工作空间)
...
- data:coverage、coverageGraph(11 节点树)、assetRefsFor、WS_TREE +
workspaceList/Read 示例文件树
- handler:/tasks/{id}/coverage · coverage-graph · asset-refs +
/workspace/list · read 路由(写/建/删走 {ok:true} 兜底)
- api:workspaceUpload/Download 加 MOCK 守卫(裸 fetch 绕过 http 助手,
demo 下改为 no-op/占位下载,不再网络报错)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 01:23:59 -04:00
Autumn-27 and Claude Opus 4.8
75ca97feb1
docs(readme): 新增系统技术架构章节 + Mermaid 架构图
...
- 双图架构(探索图+资产图)+ 锚点连接、总体分层图与组件表
- 引擎意图闭环时序图、worker 过程级信息交换图、planner 多轮共享
todolist 稳定攻击链路图(5 张 Mermaid,GitHub 原生渲染,无 emoji)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 01:23:59 -04:00
Autumn-27 and Claude Opus 4.8
6bffd491ee
feat(workspace): 新增工作空间文件管理器(针对 workDir)
...
后端 server/workspace.go(全部在 requireAuth 之后,路径限定在 workDir):
- list/read/write/mkdir/delete/download/upload 七个端点
- wsResolve 用 Clean("/"+rel)+前缀校验防 .. 遍历;上传经 filepath.Base
再二次校验;读文本 2MB 上限(超限/二进制仅下载);上传 512MB 上限;
下载文件名过滤 + filename* UTF-8 编码
前端:
- 侧边栏「工作空间」入口(/function/workspace)
- api/types:workspaceList/read/write/mkdir/delete + upload(FormData)
+ download(blob 带 token)
- page:面包屑导航 + 目录表格 + 上传/新建文件夹/刷新 + 每行下载/删除
+ 右侧 Sheet 文本编辑器(二进制/超大仅下载)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 01:01:19 -04:00
Autumn-27 and Claude Opus 4.8
5f0fac33aa
feat(agent): 按任务/意图预建 agent 工作目录,worker 免手动建目录
...
- 新增 ensureRunDir(base,taskID,intentID):os.MkdirAll 建
<workDir>/<taskID>[/i<intentID>],返回路径;cmdOutDir 助手
- worker:CWD/ToolOutputDir/提示词指到 <workDir>/<taskID>/i<意图id>/
(引擎预建),删 workerArtifactSubdir,新 workerArtifactSpec 文案
- planner/mainagent:补 WorkingDir=<workDir>/<taskID>/ + ToolOutputDir
(此前根本没设 WorkingDir);artifactSpec 文案改为「本任务工作目录」
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 00:40:31 -04:00
Autumn-27 and Claude Opus 4.8
f7197da988
feat(coverage): graph_overview 注入当前测试范围根资产(scope)
...
coverage 块新增 scope 字段(ListTaskScope 原始行:root_domain/subdomain/
ip/cidr/company,压缩为 {kind,value/company_id,source}),让 planner 看到
本任务圈定的目标本身而非仅覆盖度数字;note 说明其为范围边界、可用
add_task_scope 增补 / list_untested_assets 看未测资产。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 00:28:20 -04:00
Autumn-27 and Claude Opus 4.8
e35c766e6a
feat(coverage): 覆盖图节点用 lucide 图标 + 精简 label + 抽屉展示关联意图/事实
...
- 节点图标 emoji → 平台一致的 lucide 图标(白色 SVG data URI,iconSrc)
- 图内 label:服务显示 端口·标题·状态码(不再完整 URL),端点只显示 path
- 点节点抽屉新增「关联意图/关联事实/关联发现」:按 exploration_anchors
反查本任务锚定该资产的节点
- db AssetRefs(assetID);server GET /api/tasks/{id}/asset-refs?asset_id=X
- types/api taskAssetRefs;抽屉按 node.asset_id 拉取渲染
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-09 00:28:19 -04:00
Autumn-27 and Claude Opus 4.8
9c1591ad8e
fix(worker): search_all_worker_traces 排除调用者自身的意图 trace
...
之前走 ActivityTraceSearch(nil) 会把 worker 自己这条意图的步骤也搜出来
(纯噪声,本就在其上下文里)。新增 ActivityTraceSearchExcluding(node_id<>x),
工具传 t.ownerNode:worker=自身意图→排除自己;planner/mainagent 不受影响。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 13:24:35 -04:00
Autumn-27 and Claude Opus 4.8
db2e1f9a49
refactor(coverage): 资产覆盖图改用 G6 真力导向布局
...
- 渲染引擎 xyflow+d3-force(静态坐标) → @antv/g6 d3-force 布局
+ drag-element-force/drag-canvas/zoom-canvas:拖拽实时重排、缩放平移
- 动态 import @antv/g6(避开 SSR/静态导出),顶层仅 import type
- 折叠/分页、点击抽屉、展示更多逻辑与配色语义原样保留
- 轮询改为按需刷新(避免力导布局被反复打断)
- 依赖:声明 @antv/g6,移除不再用的 d3-force/@types/d3-force
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 13:14:49 -04:00
Autumn-27 and Claude Opus 4.8
04f40daa5c
fix(goals): URL/带子域目标登记为 subdomain,禁止缩成根域
...
修正目标设定 agent 把带子域的 URL 目标(如 https://xxx.example.net/ )
误登记成整个根域 example.net、放大测试范围的问题。goalsScopeTail 明确:
URL/主机名一律取完整主机名 kind=subdomain,禁止归约到 eTLD+1;仅裸根域名
或用户明说「整站/所有子域」才用 root_domain。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 12:59:58 -04:00
Autumn-27 and Claude Opus 4.8
6dce6317e8
feat(worker): 派发意图时按 asset_ids 自动纳入任务测试范围
...
- Execute 里复用已查出的目标资产,逐个 AddAutoScope(与 insertAssets 同一套
保守粒度、source=auto)
- 去重由 upsertTaskScope 的 ON CONFLICT DO NOTHING + uq_task_scope 唯一索引
保证,重跑/重试幂等 no-op
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 12:59:58 -04:00
Autumn-27 and Claude Opus 4.8
f80ed0b7fe
feat(worker): 意图目标资产原始数据注入 + 覆盖度不再喂给 worker
...
- Execute 启动指令后附上意图 asset_ids 对应资产的原始 JSON(GetByIDs),
省去 worker 开场再查一次 list_assets;查不到/为空/无 store 则不加
- 新增 intentAssetIDs 从意图 payload 解析 asset_ids
- renderWorkerGraphOverview 删除 coverage 键:覆盖度是规划者信号,
与 worker「只做领到那条意图」的边界相悖,不再进 worker 提示词
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 12:40:26 -04:00
Autumn-27 and Claude Opus 4.8
e841bc9332
feat(goals): 目标设定 agent 提取并登记测试资产范围
...
- DecomposeGoals 新增 as/taskID 参数,有效时复用 add_task_scope 工具挂入本次调用
- 追加 code-owned tail(仅工具挂上时):从目标/描述提取明确的
root_domain/subdomain/ip/cidr 并登记为 task_scope;只登记明确写出的、
拿不准选更精确的;不处理 company(任务刚建公司通常未入库、名字解析不上,
留给 plan 阶段)
- MaxTurns 4→6;server createGoals 传入 AssetStore + 数字 taskID
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 12:30:51 -04:00
Autumn-27 and Claude Opus 4.8
c396674d2b
feat(coverage): 任务新增「资产覆盖图」力导向图 tab
...
后端(只读,无迁移):
- db BuildCoverageGraph(taskID,expID) 复用 covTargetCTE 拉范围内全部类型资产 +
tested 标记,补连接节点(缺失根域名/公司,灰),按字段派生 child→parent 边
- server GET /api/tasks/{id}/coverage-graph
前端:
- 新 tab coverage-graph-tab:xyflow 渲染 + d3-force 静态力导向布局
- 已测=实色高亮、范围内未测=灰、范围外连接节点=灰虚线;点节点看详情抽屉
- 折叠/分页:同父同类型子节点默认展示 20(已测优先),超出收进折叠节点,
抽屉「展示更多(+20)」把下一批拉进图;布局仅在可见集合变化时重算
- types/api + d3-force 依赖声明 + 注册 tab
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 12:30:41 -04:00
Autumn-27 and Claude Opus 5
4c4f65f40a
refactor(coverage): 覆盖度改按类型统计 + 新增 list_untested_assets 工具
...
- 去掉 backlog(避免把未测清单塞进提示词引导 plan),改由 plan 自行判断。
- Coverage 去 Backlog、加 by_type [{type,total,tested}];TaskCoverage 改 GROUP BY type,
累加得总分母/总已测。
- 新增 db.ListUntestedAssets(范围内未测资产,可按类型过滤 + 分页)与 list_untested_assets
工具(type + page/page_size,默认页大小 10),绑 planner、随 BuiltinToolSeeds 播种。
- graph_overview 的 coverage 现为 {denominator,tested,pct,by_type,note};note 提示按需调
list_untested_assets 自行判断,不再推送 backlog。
- /api/tasks/{id}/coverage 去掉 backlog 参数;前端覆盖度卡改为按类型「已测/总数」徽章。
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-08 11:50:51 -04:00
Autumn-27 and Claude Opus 5
aeadd0d48b
feat(coverage): 资产测试覆盖度(task_scope 范围 + fact 派生已测)
...
按 docs/任务覆盖度设计-最终版.md 实现(轻量版,粗估供 agent 参考):
- 新表 task_scope(覆盖度分母 + per-task 授权边界):CREATE TABLE IF NOT EXISTS 进
schema.sql,随 db.go 每次启动 Exec,旧库自动生效。
- db/task_scope.go:AddAutoScope(insertAssets 按资产类型保守入范围)、AddAgentScope
(add_task_scope 工具:company/root_domain/subdomain/ip/cidr)、ListTaskScope、
TaskCoverage(范围内资产中被 fact 节点锚定过的占比 + backlog 取样)。
- insertAssets 顶层循环按 worker 显式插入的资产类型自动入范围(source=auto);
side-effect 派生的资产不触发(钩子在 handler 顶层、派生在 db 层内部),范围不盲目扩大。
- add_task_scope 工具绑 planner,随 BuiltinToolSeeds 播种(新库/旧库皆 seed)。
- graph_overview 注入 coverage(denominator/tested/backlog_sample + 粗估提示)供 planner 参考。
- HTTP:GET /api/tasks/{id}/coverage、/scope;任务总览页覆盖度卡(含 backlog)。
- 修 toolcatalog_test(record_fact 绑定断言,早前 mainagent 加 recordFact 后未同步)。
验证:go build / vet / agent test / 前端 tsc 均通过。注:DB 层 SQL 尚未经 live Postgres 运行验证。
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-08 09:09:38 -04:00
Autumn-27 and Claude Opus 5
58e057a3f2
chore(planner): 意图 summary 要求写测试目标完整地址
...
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-08 07:54:17 -04:00
Autumn-27 and Claude Opus 5
1025938dd9
fix(asset): insert_assets 由程序权威赋 task_id + service/endpoint 补建 subdomain/root_domain
...
- insert_assets 不再把 task_id 暴露给模型/依赖模型传:schema 去掉 task_id,handler 直接用 SetTaskID 设的 t.taskID,避免模型漏传/错传导致资产未归任务或归错任务。
- UpsertHTTPService/UpsertOtherService/UpsertEndpoint 新增 side effect linkHostAssets:把 host 反向登记为独立 root_domain + subdomain 资产(非 apex、非 IP 才建 subdomain);endpoint 原来无任何 side effect,现补建 root_domain/subdomain/IP。
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-08 07:54:17 -04:00
Autumn-27 and Claude Opus 4.8
e01b659097
feat(assets): 资产页新增「应用」Tab + app 字段可搜
...
- 资产页 TABS 补 app 分类,新增应用列表(应用名/Bundle ID/分类/ICP 备案)+勾选/删除
- DSL 搜索白名单补 bundle_id/category/app_icp(原仅 app_name),前端搜索建议同步
- list/count 本就按 type 通用,app 自动适配;补齐后 app 资产可看/可搜/可删
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 06:19:11 -04:00
Autumn-27 and Claude Opus 4.8
6d8fa5bc48
feat(agent): 触发后处理可配置(运行模式/合并模式/并发上限) + 修复抽屉内下拉误关
...
每个自定义 agent 可配置触发后如何调度运行:
- 运行模式 serial|parallel:串行排队一次一个 / 每次触发各自并发一个会话
- 合并模式 by_task|all|none(仅 serial):同任务合并 / 全部合并成一条 / 不合并
- parallel 带每 agent 最大并发上限(0=不限),超限排队等空位
实现:
- DB: agents 加 trigger_run_mode/trigger_merge_mode/trigger_max_parallel 三列
(schema + 幂等 ALTER 迁移,已发版补旧库);Agent 结构/scan/SetAgentTriggerBehavior
- 调度重构: triggerRun bool → triggerActive 计数 + triggerCfg 缓存;
StartTriggeredRun 走 pumpLocked/runAndPump 统一泵模型,nextTriggerRun 按合并模式
取(新增 mergeAllRuns);并发安全(session 按 conv-id 隔离,已确认)
- config 接口暴露/接收三字段;max_turns 改可选指针,避免触发 tab 部分 patch 清零
- 前端: 触发 tab 顶部加运行/合并模式下拉 + 最大并发输入,改动即存
修复: 抽屉(Sheet)内 Select 下拉 portal 到抽屉外,点选项/点别处被当成点击外部
误关抽屉。SelectContent 改 position=popper,并给 SheetContent 加 onInteractOutside
守卫(按 e.detail.originalEvent.target 判定弹层内点击则不关)。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 04:23:09 -04:00
Autumn-27 and Claude Opus 4.8
f9716269ea
feat(agent): 触发器新增「工具调用」条件 + 定时触发改为复选框展开
...
- 定时触发统一为前置复选框,勾选后展开「每 N 秒」+ 消息(与其它条件一致)
- 新增工具调用触发(P3 第 5 种条件):
- 选中系统工具列表(至少一个),任务执行中这些工具每次调用完成即触发 agent
- 触发消息带上任务 id/描述/目标 + 工具名 + 入参 + 返回内容(各截断 1500 字)
- 只读任务执行的 activity,触发跑的会话写 conversation_activities,天然无自触发循环
- DB: agent_triggers 加 on_tool_call/tool_call_message/tool_names 三列;
已发版,附幂等 ALTER TABLE ADD COLUMN IF NOT EXISTS 供旧库升级补列
- scheduler: 新增 last_toolcall_id 水位线(首启 seed) + fireToolCalls,以 tool_result
为水位、回连 tool_use 取入参,按选中工具集合匹配后触发
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-08 02:59:07 -04:00
Autumn-27 and Claude Opus 5
82bd19a1cd
docs(tools): create_custom_tool 描述前置【重要】提示,引导安装平台外工具后登记
...
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-07 12:21:12 -04:00
Autumn-27 and Claude Opus 5
e86657cfd1
fix(ui): 表单弹窗溢出( #11 ) + LLM 配置弹窗点外部误关闭( #13 )
...
#11 Textarea(field-sizing-content 自动增高)加 max-h-[45vh]+overflow-auto 到顶改内部滚动,DialogContent 加 max-h-[90dvh]+overflow-y-auto 兜底;#13 新建 Profile 弹窗加 onInteractOutside preventDefault,点外部不再关闭。
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-07 12:20:15 -04:00
Autumn-27 and Claude Opus 5
5000aadd8f
fix(chat): 修复会话刷新丢失最终答案( #3 ) + 反向分页/详情懒加载/会话URL持久化
...
- 后端消息列表默认按 id 升序取最旧一页,长会话刷新后最终答案落在页外而丢失
(发新消息推进游标才重现)。改为:
- db.ConvActivityPage:反向分页,取最新/更早一页 + hasMore
- 消息接口按 since(增量)/before(更早页)/最新页 三种模式返回
- 前端聊天页:
- 打开会话仅加载最新一页,滚动到顶部再反向加载更早(保持滚动位置不跳)
- Transcript 的 UserRow/AnswerBlock 改为进入视口才拉 detail,避免打开会话即对
整页每步发详情请求
- 选中会话 id 持久化到 URL(?c=<id>),刷新回到当前会话
- 修复新建会话后被"清理失效 id"effect 误清导致停留在新建页、输入框内容与灰色
发送按钮卡死:移除该 effect + onStarted 乐观插入
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-07 11:45:33 -04:00
Autumn-27 and Claude Opus 5
349b0d104d
feat(agent): 主 agent 默认工具集增加 report_finding/record_fact
...
- MainAgentTools 加入 addFinding/recordFact,主 agent 确证漏洞或事实时可直接登记
- report_finding 描述前置[重要]标注,强化调用约束
- gofmt 对齐 tools_insert 参数缩进与 import 顺序
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com >
2026-08-07 10:04:21 -04:00
Autumn-27 and Claude Opus 4.8
3c8a9f74f8
fix(web): 守卫跳转登录页前清除 cookie,修复 cookie 与 localStorage 不一致导致的无限重定向白屏
...
(main)/layout.tsx 的客户端守卫判定未登录时只跳 /login,未清 cookie;
而 proxy.ts 仅凭 cookie 是否存在放行,二者在 cookie 存在但 localStorage
为空时互相弹跳 → 无限重定向 → 白屏。跳转前调用 auth.clearToken() 同步
清除两处凭证,与退出登录/401 处理的既有约定保持一致。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-07 09:43:30 -04:00
Autumn-27 and Claude Opus 4.8
89e6df837a
Merge: PR5 LLM 录制/工具执行 + session 修复/录制开关/模型列表回退
...
合入 lornlee 的 PR #5(LLM 模型清单、命令执行录制、LLM 请求录制),
并在其基础上修复 session 断链、增加录制开关(默认关)、模型列表第三方回退、
命令页改为工具执行列表。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-07 09:35:06 -04:00
Autumn-27 and Claude Opus 4.8
ad9f14f140
feat: LLM 录制开关、模型列表第三方回退、命令页改为工具执行
...
在 review PR5 基础上的三处改进:
1. LLM 录制开关(默认关,settings.llm_record)
- 录制页数据大小下拉框旁加开关;关闭时 Recorder.Stream 直接透传,
不序列化、不累积、不写库,零开销。切换即时生效,无需重建 agent。
2. 模型列表拉取支持 Anthropic 兼容第三方
- pgListModels 改为按序尝试多个候选端点:anthropic 的 /v1/models 拿不到时,
剥掉 /anthropic 回退到 OpenAI 式 /models(自动切 Bearer 头)。
修复 DeepSeek(anthropic) 加载模型 404。
3. 命令页改为「工具执行」列表
- ListCommands 去掉 tool='Bash' 过滤,覆盖所有 tool_use;返回工具名列,
搜索匹配工具名或参数。前端加「工具」列、标题/侧边栏改为「工具执行」。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-07 09:32:01 -04:00
Autumn-27 and Claude Opus 4.8
10f891a21d
fix(llmrec): 从 ctx 读取 session,修复 task/worker 列为空
...
原实现依赖 SetSession() 写入共享的 sessionID 字段,但该方法从未被调用,
导致 session/task/worker 恒为空、落库为 NULL,前端两列无数据。且共享可变字段
在 planner 与多 worker 并发调用同一 Recorder 时会互相覆盖、串号。
norma 已通过 transcript.WithSessionID 把 session 注入 ctx(格式 exp<N>-<role>),
改为在 Stream 中按 ctx 逐调用读取,天然 per-call、无竞争。删除未使用的
SetSession/getContext 及共享字段。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-08-07 08:52:24 -04:00
Autumn
8d3b0d17e7
Update README.md
2026-08-07 10:20:56 +08:00
Autumn
a642403764
add Cairn
2026-08-07 10:19:50 +08:00
lornlee
5b58330f01
feat: 添加LLM模型清单、命令执行记录录制和LLM请求记录录制功能
2026-07-30 15:18:40 +08:00
Autumn-27 and Claude Opus 4.8
0f94849012
fix(docker): 用 NodeSource 装 Node 20(Playwright 要求 >=20)
...
bookworm 自带的 apt nodejs 是 18.20.4,Playwright 全局安装报
"requires Node.js 20 or higher" 导致镜像构建失败。改为从 NodeSource
装 20.x(自带 npm),移除 apt 的 nodejs/npm。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-28 12:11:04 -04:00
Autumn-27 and Claude Opus 4.8
3f798ec74e
chore(docker): 预装 Playwright MCP/CLI 及 chromium
...
镜像内全局预装 @playwright/mcp、@playwright/cli、playwright,并
`playwright install --with-deps chromium` 预置浏览器及系统依赖,运行时
不再联网下载。browser MCP 启动参数去掉 -y 与 @latest(改用已装好的本地版本)。
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
2026-07-28 11:52:53 -04:00