Compare commits

...
Author SHA1 Message Date
Elliot Slusky b70be55681 fix(openhands): handle none content in token estimates (#612)
Closes #607. Assistant tool-call turns can carry content=None, which crashed token estimation (len(m.content)) and think-tag stripping. Normalize with 'content or ""', route native OpenHands truncation through the shared estimate_prompt_tokens, and add tests for the estimator, the truncation helper, and an end-to-end tool-call run with None content.
2026-06-29 16:51:52 -07:00
Elliot Slusky a0187e40e6 Fix desktop startup fallback to installed Ollama models (#611)
Addresses #605. Prefer an already-installed Ollama model before attempting a startup download (matching the requested tag, else a preferred non-embedding installed model); fall back through installed -> FALLBACK_MODEL -> error, reusing installed models at each failure point; persist the resolved model only for first-run/default so an explicit user choice is never overwritten. Refactors the model logic into testable helpers with unit coverage.
2026-06-29 16:51:49 -07:00
Jon Saad-FalconandClaude Opus 4.8 d32f20f9b3 fix(desktop): align @tauri-apps npm packages with the 2.11 Rust crate (#613)
Desktop release builds failed on all platforms with 'Found version mismatched Tauri packages' because @tauri-apps/api and @tauri-apps/cli were pinned at 2.10.1 while the tauri Rust crate resolved to 2.11.3. Bump both npm packages to the 2.11 line (api 2.11.1, cli 2.11.4) so they share the crate's major.minor. Plugins were already aligned.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-29 16:51:46 -07:00
github-actions[bot] 0b552cbcb5 chore: update clone traffic data [skip ci] 2026-06-29 07:46:59 +00:00
github-actions[bot] 19fd3c8d2b chore: update clone traffic data [skip ci] 2026-06-28 07:24:04 +00:00
Jon Saad-FalconandClaude Opus 4.8 1fa80d8ecd fix(docs): wire the savings leaderboard's Supabase anon key into the docs build (#596)
The docs-site leaderboard (docs/javascripts/leaderboard.js) reads the public
Supabase anon key from window.OPENJARVIS_SUPABASE_ANON_KEY, but nothing set it,
so the published leaderboard always rendered "Leaderboard not configured yet".

Add a generated config file (leaderboard-config.js) loaded before
leaderboard.js that supplies the global, and inject its value at docs-build
time from the existing VITE_SUPABASE_ANON_KEY repo secret. The committed
default is empty, so local `mkdocs build` and fork PRs (no secret) degrade
gracefully. The anon key is public by design (Supabase RLS protects the data).

- docs/javascripts/leaderboard-config.js: empty-default global declaration.
- mkdocs.yml: load leaderboard-config.js before leaderboard.js.
- docs.yml: write the config from the secret (read via env, JSON-encoded into a
  JS string literal to avoid injection) before `mkdocs build`.
- tests/deployment/test_docs_leaderboard.py: guard the wiring + load order.

Verified with a local `mkdocs build`: the generated config ships in site/ and
loads before leaderboard.js.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-27 15:49:18 -07:00
github-actions[bot] b3f90691bf chore: update clone traffic data [skip ci] 2026-06-27 07:07:41 +00:00
github-actions[bot] 4ebf0839e7 chore: update clone traffic data [skip ci] 2026-06-26 07:21:03 +00:00
github-actions[bot] b1e93d4ed0 chore: update clone traffic data [skip ci] 2026-06-25 07:14:52 +00:00
Elliot SluskyandClaude Opus 4.8 eb2b612c7c fix(memory): address service follow-ups (#591)
Closes #582. Route fact-store construction through a new FactStoreRegistry (local backend registered by default); align the default facts path with get_config_dir(); wire completed chat exchanges (streamed and non-streamed) through the EventBus so the memory service captures them consistently; reload the local fact store from disk before operations so external clears don't resurrect stale facts; make the affected config/persona/memory/CLI/route tests hermetic; and refresh uv.lock with the current resolver (locks pytest-xdist + transitive deps, drops py3.14 artifacts since the project constrains Python <3.14).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 19:58:49 -07:00
Elliot SluskyandClaude Opus 4.8 560ec860df fix(docker): build native Rust extension into images (#590)
Build and install the mandatory openjarvis_rust wheel in the CPU, NVIDIA, ROCm, and sandbox Docker images. Rust 1.88 (matching the workspace MSRV / rust-toolchain.toml) and maturin are installed only in the builder stage, the module's import is verified during the build, and maturin is removed before the runtime artifacts are copied so build tooling never ships. The frontend leaderboard anon key is an optional empty-by-default build arg (post-#589), so default images cleanly disable the leaderboard. Adds static deployment coverage for the native build path. Closes #584.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 15:27:17 -07:00
Jon Saad-FalconandClaude Opus 4.8 e7c46c1985 fix(frontend): make Supabase anon key optional to unblock PyPI publishing (#589)
PyPI publishing had been broken since v1.0.3.dev851: #587 made VITE_SUPABASE_ANON_KEY a hard build-time requirement, but no such secret exists, so the frontend build aborted every publish run before the PyPI upload. Decouple package buildability from the leaderboard credential: a missing anon key now disables the savings leaderboard at runtime instead of failing the build, and auto-enables when the secret is provided. Verified: npm run build with the key unset succeeds; tsc + vitest pass.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-24 13:15:06 -07:00
github-actions[bot] 00d1e39b6d chore: update clone traffic data [skip ci] 2026-06-24 07:14:44 +00:00
Elliot SluskyandClaude Opus 4.8 843375d6ef Fix Supabase frontend build env for release builds (#588)
Follow-up to #587. Pass VITE_SUPABASE_ANON_KEY into the frontend builds of both release paths: the PyPI publish workflow (wheel-bundled frontend) and the desktop tauri-action build (npm run build:tauri -> vite build). Kept strict: a missing/empty secret fails the release by design rather than shipping a placeholder key. Requires the VITE_SUPABASE_ANON_KEY repo secret to be set for releases to succeed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 16:32:13 -07:00
Elliot SluskyandClaude Opus 4.8 8d33cb58fa Fix secure cloud key storage and Supabase key config (#587)
Route desktop cloud-key saves/status through the OS credential store (keyring with per-platform native backends: apple-native / windows-native / sync-secret-service), migrate the legacy plaintext ~/.openjarvis/cloud-keys.env into it, remove browser localStorage persistence of provider keys, and push key updates to the running server via /v1/cloud/reload (legacy env-file fallback retained). Remove hardcoded Supabase anon JWTs from frontend/docs source and make VITE_SUPABASE_ANON_KEY a required build var. Adds libdbus-1-dev to the Linux desktop build and a CI build var. Closes #220.

NOTE (post-merge follow-ups, not covered by CI): add the VITE_SUPABASE_ANON_KEY repo secret with the rotated key (release/docs builds otherwise use a placeholder), rotate the previously-committed Supabase anon key, and run a desktop save->restart->read smoke test to confirm keychain persistence.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 16:11:32 -07:00
github-actions[bot] e4c4bcbae3 chore: update clone traffic data [skip ci] 2026-06-23 07:18:13 +00:00
Jon Saad-Falcon 993c24c8b9 test(server): make TestTraceRecording hermetic (env-independent) (#583)
TestTraceRecording relied on the ambient ~/.openjarvis/config.toml leaving traces.enabled at its default, so it failed on any machine with traces disabled locally (passing in CI only because the runner has no config file). Pass an explicit traces-enabled config with a tmp db_path so the tests are environment-independent and parallel-safe under pytest -n auto. Relates to #582.
2026-06-22 19:12:10 -07:00
Elliot Slusky 5bc8d3a2f6 Harden Docker and systemd deployment configs (#581)
Pin all base images and ollama to fixed versions + @sha256 digests (no floating :latest), run Docker images as an unprivileged openjarvis user (uid 10001), replace the curl|bash NodeSource install with a digest-pinned multi-stage copy, install from the committed uv.lock via uv export --frozen --no-dev (hash-verified, --no-deps), and add systemd sandboxing (NoNewPrivileges, ProtectSystem=strict, PrivateTmp, kernel/SUID protections). Closes #228, #563, #564, #565, #566, #567.
2026-06-22 19:12:07 -07:00
53 changed files with 3229 additions and 3353 deletions
+1 -1
View File
@@ -1,7 +1,7 @@
{
"schemaVersion": 1,
"label": "Git Clones",
"message": "128,077",
"message": "137,874",
"color": "green",
"namedLogo": "git"
}
+10 -3
View File
@@ -1,6 +1,6 @@
{
"total_clones": 128077,
"last_updated": "2026-06-22T08:05:29Z",
"total_clones": 137874,
"last_updated": "2026-06-29T07:46:59Z",
"daily": {
"2026-03-27": 2189,
"2026-03-28": 1874,
@@ -88,6 +88,13 @@
"2026-06-18": 1408,
"2026-06-19": 1350,
"2026-06-20": 1437,
"2026-06-21": 1426
"2026-06-21": 1426,
"2026-06-22": 1350,
"2026-06-23": 1468,
"2026-06-24": 1635,
"2026-06-25": 1640,
"2026-06-26": 1338,
"2026-06-27": 1338,
"2026-06-28": 1028
}
}
+8 -2
View File
@@ -40,7 +40,8 @@ jobs:
libappindicator3-dev \
librsvg2-dev \
patchelf \
libxdo-dev
libxdo-dev \
libdbus-1-dev
- name: Setup Node.js
uses: actions/setup-node@v6
@@ -130,7 +131,8 @@ jobs:
libappindicator3-dev \
librsvg2-dev \
patchelf \
libxdo-dev
libxdo-dev \
libdbus-1-dev
- name: Install Rust stable
uses: dtolnay/rust-toolchain@stable
@@ -252,6 +254,10 @@ jobs:
TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
TAURI_SIGNING_PRIVATE_KEY_PASSWORD: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY_PASSWORD }}
TAURI_CONFIG: '{"version":"${{ steps.release-info.outputs.tauri_version }}","bundle":{"externalBin":["binaries/ollama"]}}'
# tauri-action runs beforeBuildCommand (npm run build:tauri -> vite
# build), which requires this at build time (#587). Strict for
# releases: a missing/empty secret fails the build by design.
VITE_SUPABASE_ANON_KEY: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
with:
projectPath: frontend
tauriScript: npx tauri
+20
View File
@@ -41,6 +41,26 @@ jobs:
- name: Install dependencies
run: uv sync --extra docs
# Inject the public Supabase anon key so the savings leaderboard works on
# the published docs site. Missing/empty (e.g. fork PRs) leaves the
# leaderboard gracefully disabled. The key is read from env (not inlined)
# and JSON-encoded into a JS string literal to avoid any injection.
- name: Inject leaderboard Supabase anon key
env:
OPENJARVIS_LEADERBOARD_ANON: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
run: |
python3 - <<'PY'
import json, os, pathlib
key = os.environ.get("OPENJARVIS_LEADERBOARD_ANON", "")
pathlib.Path("docs/javascripts/leaderboard-config.js").write_text(
"// Generated at docs-build time from the VITE_SUPABASE_ANON_KEY secret.\n"
"window.OPENJARVIS_SUPABASE_ANON_KEY = " + json.dumps(key) + ";\n",
encoding="utf-8",
)
print("leaderboard anon key:", "set" if key else "empty (leaderboard disabled)")
PY
- name: Build documentation
run: uv run mkdocs build
+5
View File
@@ -35,3 +35,8 @@ jobs:
- run: npm ci
- run: npx tsc --noEmit
- run: npm run build
env:
# Optional: when the secret is unset the build still succeeds and the
# leaderboard is disabled (see src/lib/supabase.ts). No placeholder,
# so a keyless CI build doesn't bake in a bogus anon key.
VITE_SUPABASE_ANON_KEY: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
+2
View File
@@ -55,6 +55,8 @@ jobs:
cache-dependency-path: frontend/package-lock.json
- name: Build frontend and bundle into package
env:
VITE_SUPABASE_ANON_KEY: ${{ secrets.VITE_SUPABASE_ANON_KEY }}
run: |
set -euo pipefail
cd frontend
+56 -7
View File
@@ -1,34 +1,83 @@
# Base images are pinned to an immutable digest (in addition to a human-readable
# tag) so every build resolves the exact same layers — reproducible builds and
# safe rollbacks (#563).
# Stage 1: Build frontend SPA
FROM node:22-slim AS frontend
FROM node:22.23.0-slim@sha256:d9f850096136edbc402debdd8729579a288aac64574ada0ff4db26b6ae58b0b2 AS frontend
# Public Supabase anon key for the savings leaderboard; empty by default so
# the image's leaderboard stays disabled (#589). Pass --build-arg to enable.
ARG OPENJARVIS_LEADERBOARD_PUBLIC_ANON=
WORKDIR /frontend
COPY frontend/package.json frontend/package-lock.json* ./
RUN npm ci --ignore-scripts 2>/dev/null || npm install
COPY frontend/ .
RUN npm run build
RUN VITE_SUPABASE_ANON_KEY="${OPENJARVIS_LEADERBOARD_PUBLIC_ANON}" npm run build
# Stage 2: Build Python package
FROM python:3.12-slim-bookworm AS builder
FROM python:3.12.13-slim-bookworm@sha256:76d4b7b6305788c6b4c6a19d6a22a3921bf802e9af4d5e1e5bd771208dba74bf AS builder
RUN apt-get update && \
apt-get install -y --no-install-recommends build-essential ca-certificates curl && \
rm -rf /var/lib/apt/lists/*
ENV PATH="/root/.cargo/bin:${PATH}"
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | \
sh -s -- -y --profile minimal --default-toolchain none && \
rustup toolchain install 1.88 --profile minimal && \
rustup default 1.88
WORKDIR /app
COPY pyproject.toml README.md ./
# Install dependencies from the committed lockfile (#567). `uv export --frozen`
# reads uv.lock as-is (no re-resolution) and emits a fully pinned, hash-verified
# requirements set; `--no-deps` then installs exactly that set. This is a
# separate layer from the source copy so dependency installs stay cached when
# only application code changes.
COPY pyproject.toml uv.lock README.md ./
RUN pip install --no-cache-dir uv && \
uv export --frozen --no-dev --extra server --no-emit-project > requirements.txt && \
uv pip install --system --no-deps -r requirements.txt && \
uv pip install --system --no-deps "maturin>=1.12.6,<2"
# Copy the source and the non-src force-include paths (see pyproject
# [tool.hatch.build.targets.wheel.force-include]) before building the project.
COPY src/ src/
COPY rust/ rust/
COPY scripts/install scripts/install
COPY deploy/windows deploy/windows
# Copy built frontend into the server static directory
COPY --from=frontend /src/openjarvis/server/static src/openjarvis/server/static/
RUN pip install --no-cache-dir uv && \
uv pip install --system ".[server]"
# Install the project itself without re-resolving dependencies.
RUN uv pip install --system --no-deps . && \
maturin build --release \
--manifest-path rust/crates/openjarvis-python/Cargo.toml \
--interpreter python3 \
--out /tmp/openjarvis-rust-wheel && \
uv pip install --system --no-deps /tmp/openjarvis-rust-wheel/*.whl && \
python3 -c "import openjarvis_rust; print('openjarvis_rust ok')" && \
python3 -m pip uninstall -y maturin && \
rm -rf /tmp/openjarvis-rust-wheel rust
# Stage 3: Runtime
FROM python:3.12-slim-bookworm
FROM python:3.12.13-slim-bookworm@sha256:76d4b7b6305788c6b4c6a19d6a22a3921bf802e9af4d5e1e5bd771208dba74bf
COPY --from=builder /usr/local /usr/local
COPY --from=builder /app /app
WORKDIR /app
# Run as an unprivileged user — the server needs no root privileges, so dropping
# them limits the blast radius of a compromise (#565). The app writes only to
# $HOME (config/cache/state), which is owned by this user.
RUN groupadd --system --gid 10001 openjarvis && \
useradd --system --uid 10001 --gid openjarvis \
--create-home --home-dir /home/openjarvis openjarvis
ENV HOME=/home/openjarvis
USER openjarvis
EXPOSE 8000
ENTRYPOINT ["jarvis"]
+53 -8
View File
@@ -1,32 +1,69 @@
# Base images are pinned to an immutable digest (in addition to a human-readable
# tag) so every build resolves the exact same layers — reproducible builds and
# safe rollbacks (#563).
# Stage 1: Build frontend SPA
FROM node:22-slim AS frontend
FROM node:22.23.0-slim@sha256:d9f850096136edbc402debdd8729579a288aac64574ada0ff4db26b6ae58b0b2 AS frontend
# Public Supabase anon key for the savings leaderboard; empty by default so
# the image's leaderboard stays disabled (#589). Pass --build-arg to enable.
ARG OPENJARVIS_LEADERBOARD_PUBLIC_ANON=
WORKDIR /frontend
COPY frontend/package.json frontend/package-lock.json* ./
RUN npm ci --ignore-scripts 2>/dev/null || npm install
COPY frontend/ .
RUN npm run build
RUN VITE_SUPABASE_ANON_KEY="${OPENJARVIS_LEADERBOARD_PUBLIC_ANON}" npm run build
# Stage 2: Build Python package (NVIDIA CUDA 12.4)
FROM nvidia/cuda:12.4.0-runtime-ubuntu22.04 AS builder
FROM nvidia/cuda:12.4.0-runtime-ubuntu22.04@sha256:af8bd179ed3bf69d4b63b19a763662a6141f0f62ef099283f68d0b14b4bab0e3 AS builder
RUN apt-get update && \
apt-get install -y --no-install-recommends python3 python3-pip python3-venv && \
apt-get install -y --no-install-recommends \
build-essential \
ca-certificates \
curl \
python3 \
python3-dev \
python3-pip \
python3-venv && \
rm -rf /var/lib/apt/lists/*
ENV PATH="/root/.cargo/bin:${PATH}"
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | \
sh -s -- -y --profile minimal --default-toolchain none && \
rustup toolchain install 1.88 --profile minimal && \
rustup default 1.88
WORKDIR /app
COPY pyproject.toml README.md ./
# Install dependencies from the committed lockfile (#567). See deploy/docker/Dockerfile
# for the rationale behind the frozen export + --no-deps install.
COPY pyproject.toml uv.lock README.md ./
RUN pip install --no-cache-dir uv && \
uv export --frozen --no-dev --extra server --no-emit-project > requirements.txt && \
uv pip install --system --no-deps -r requirements.txt && \
uv pip install --system --no-deps "maturin>=1.12.6,<2"
COPY src/ src/
COPY rust/ rust/
COPY scripts/install scripts/install
COPY deploy/windows deploy/windows
COPY --from=frontend /src/openjarvis/server/static src/openjarvis/server/static/
RUN pip install --no-cache-dir uv && \
uv pip install --system ".[server]"
RUN uv pip install --system --no-deps . && \
maturin build --release \
--manifest-path rust/crates/openjarvis-python/Cargo.toml \
--interpreter python3 \
--out /tmp/openjarvis-rust-wheel && \
uv pip install --system --no-deps /tmp/openjarvis-rust-wheel/*.whl && \
python3 -c "import openjarvis_rust; print('openjarvis_rust ok')" && \
python3 -m pip uninstall -y maturin && \
rm -rf /tmp/openjarvis-rust-wheel rust
# Stage 3: Runtime
FROM nvidia/cuda:12.4.0-runtime-ubuntu22.04
FROM nvidia/cuda:12.4.0-runtime-ubuntu22.04@sha256:af8bd179ed3bf69d4b63b19a763662a6141f0f62ef099283f68d0b14b4bab0e3
RUN apt-get update && \
apt-get install -y --no-install-recommends python3 python3-pip && \
@@ -36,6 +73,14 @@ COPY --from=builder /usr/local /usr/local
COPY --from=builder /app /app
WORKDIR /app
# Run as an unprivileged user (#565). NVIDIA device nodes (/dev/nvidia*) are
# world-accessible, so GPU workloads do not require root.
RUN groupadd --system --gid 10001 openjarvis && \
useradd --system --uid 10001 --gid openjarvis \
--create-home --home-dir /home/openjarvis openjarvis
ENV HOME=/home/openjarvis
USER openjarvis
EXPOSE 8000
ENTRYPOINT ["jarvis"]
+57 -8
View File
@@ -1,32 +1,69 @@
# Base images are pinned to an immutable digest (in addition to a human-readable
# tag) so every build resolves the exact same layers — reproducible builds and
# safe rollbacks (#563).
# Stage 1: Build frontend SPA
FROM node:22-slim AS frontend
FROM node:22.23.0-slim@sha256:d9f850096136edbc402debdd8729579a288aac64574ada0ff4db26b6ae58b0b2 AS frontend
# Public Supabase anon key for the savings leaderboard; empty by default so
# the image's leaderboard stays disabled (#589). Pass --build-arg to enable.
ARG OPENJARVIS_LEADERBOARD_PUBLIC_ANON=
WORKDIR /frontend
COPY frontend/package.json frontend/package-lock.json* ./
RUN npm ci --ignore-scripts 2>/dev/null || npm install
COPY frontend/ .
RUN npm run build
RUN VITE_SUPABASE_ANON_KEY="${OPENJARVIS_LEADERBOARD_PUBLIC_ANON}" npm run build
# Stage 2: Build Python package (AMD ROCm 7.2)
FROM rocm/dev-ubuntu-22.04:7.2 AS builder
FROM rocm/dev-ubuntu-22.04:7.2@sha256:05af5f04a06b04676d4c7438997d0deadaeb7478961ad621376e199bf3aeb644 AS builder
RUN apt-get update && \
apt-get install -y --no-install-recommends python3 python3-pip python3-venv && \
apt-get install -y --no-install-recommends \
build-essential \
ca-certificates \
curl \
python3 \
python3-dev \
python3-pip \
python3-venv && \
rm -rf /var/lib/apt/lists/*
ENV PATH="/root/.cargo/bin:${PATH}"
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | \
sh -s -- -y --profile minimal --default-toolchain none && \
rustup toolchain install 1.88 --profile minimal && \
rustup default 1.88
WORKDIR /app
COPY pyproject.toml README.md ./
# Install dependencies from the committed lockfile (#567). See deploy/docker/Dockerfile
# for the rationale behind the frozen export + --no-deps install.
COPY pyproject.toml uv.lock README.md ./
RUN pip install --no-cache-dir uv && \
uv export --frozen --no-dev --extra server --no-emit-project > requirements.txt && \
uv pip install --system --no-deps -r requirements.txt && \
uv pip install --system --no-deps "maturin>=1.12.6,<2"
COPY src/ src/
COPY rust/ rust/
COPY scripts/install scripts/install
COPY deploy/windows deploy/windows
COPY --from=frontend /src/openjarvis/server/static src/openjarvis/server/static/
RUN pip install --no-cache-dir uv && \
uv pip install --system ".[server]"
RUN uv pip install --system --no-deps . && \
maturin build --release \
--manifest-path rust/crates/openjarvis-python/Cargo.toml \
--interpreter python3 \
--out /tmp/openjarvis-rust-wheel && \
uv pip install --system --no-deps /tmp/openjarvis-rust-wheel/*.whl && \
python3 -c "import openjarvis_rust; print('openjarvis_rust ok')" && \
python3 -m pip uninstall -y maturin && \
rm -rf /tmp/openjarvis-rust-wheel rust
# Stage 3: Runtime
FROM rocm/dev-ubuntu-22.04:7.2
FROM rocm/dev-ubuntu-22.04:7.2@sha256:05af5f04a06b04676d4c7438997d0deadaeb7478961ad621376e199bf3aeb644
RUN apt-get update && \
apt-get install -y --no-install-recommends python3 python3-pip && \
@@ -36,6 +73,18 @@ COPY --from=builder /usr/local /usr/local
COPY --from=builder /app /app
WORKDIR /app
# Run as an unprivileged user (#565). ROCm GPU access is gated by the `video` and
# `render` groups (see group_add in docker-compose.gpu.rocm.yml), so the user is
# added to both; root is not required.
RUN groupadd --system --gid 10001 openjarvis && \
useradd --system --uid 10001 --gid openjarvis \
--create-home --home-dir /home/openjarvis openjarvis && \
(getent group video >/dev/null || groupadd --system video) && \
(getent group render >/dev/null || groupadd --system render) && \
usermod -aG video,render openjarvis
ENV HOME=/home/openjarvis
USER openjarvis
EXPOSE 8000
ENTRYPOINT ["jarvis"]
+61 -7
View File
@@ -1,15 +1,69 @@
FROM python:3.12-slim
# Base images are pinned to an immutable digest (in addition to a human-readable
# tag) so every build resolves the exact same layers (#563).
# Install Node.js 22
RUN apt-get update && apt-get install -y --no-install-recommends \
curl ca-certificates && \
curl -fsSL https://deb.nodesource.com/setup_22.x | bash - && \
apt-get install -y nodejs && \
# Node.js is sourced from the official, digest-pinned image rather than piping a
# remote setup script into bash (`curl ... | bash -`), which performed no
# checksum or signature verification of the downloaded installer (#566). The
# image digest is the integrity check, and the copy is architecture-agnostic.
FROM node:22.23.0-slim@sha256:d9f850096136edbc402debdd8729579a288aac64574ada0ff4db26b6ae58b0b2 AS node
FROM python:3.12.13-slim-bookworm@sha256:76d4b7b6305788c6b4c6a19d6a22a3921bf802e9af4d5e1e5bd771208dba74bf AS builder
RUN apt-get update && \
apt-get install -y --no-install-recommends build-essential ca-certificates curl && \
rm -rf /var/lib/apt/lists/*
ENV PATH="/root/.cargo/bin:${PATH}"
RUN curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | \
sh -s -- -y --profile minimal --default-toolchain none && \
rustup toolchain install 1.88 --profile minimal && \
rustup default 1.88
WORKDIR /app
# Install dependencies from the committed lockfile (#567): `uv export --frozen`
# reads uv.lock as-is and emits a pinned, hash-verified set installed with
# --no-deps (no re-resolution). Copied first so this layer caches independently
# of application source.
COPY pyproject.toml uv.lock README.md ./
RUN pip install --no-cache-dir uv && \
uv export --frozen --no-dev --extra server --no-emit-project > requirements.txt && \
uv pip install --system --no-deps -r requirements.txt && \
uv pip install --system --no-deps "maturin>=1.12.6,<2"
COPY . .
RUN pip install --no-cache-dir ".[server]"
# Install the project itself without re-resolving dependencies.
RUN uv pip install --system --no-deps . && \
maturin build --release \
--manifest-path rust/crates/openjarvis-python/Cargo.toml \
--interpreter python3 \
--out /tmp/openjarvis-rust-wheel && \
uv pip install --system --no-deps /tmp/openjarvis-rust-wheel/*.whl && \
python3 -c "import openjarvis_rust; print('openjarvis_rust ok')" && \
python3 -m pip uninstall -y maturin && \
rm -rf /tmp/openjarvis-rust-wheel rust/target
FROM python:3.12.13-slim-bookworm@sha256:76d4b7b6305788c6b4c6a19d6a22a3921bf802e9af4d5e1e5bd771208dba74bf
# libstdc++6 + ca-certificates are the only runtime requirements of the Node
# binary copied below (the python slim image already provides libc/libgcc).
RUN apt-get update && \
apt-get install -y --no-install-recommends ca-certificates libstdc++6 && \
rm -rf /var/lib/apt/lists/*
COPY --from=builder /usr/local /usr/local
COPY --from=builder /app /app
# Transplant the Node.js runtime from the official image. Both images are Debian
# bookworm, so the glibc/libstdc++ ABI matches.
COPY --from=node /usr/local/bin/node /usr/local/bin/node
COPY --from=node /usr/local/lib/node_modules /usr/local/lib/node_modules
RUN ln -sf /usr/local/lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm && \
ln -sf /usr/local/lib/node_modules/npm/bin/npx-cli.js /usr/local/bin/npx
WORKDIR /app
LABEL openjarvis-sandbox=true
+3 -1
View File
@@ -18,7 +18,9 @@ services:
capabilities: [gpu]
ollama:
image: ollama/ollama:latest
# Pinned to a fixed version + digest for reproducible deployments (#563);
# must match the tag in docker-compose.yml.
image: ollama/ollama:0.30.10@sha256:bfc9c6d53cc6989aa5131a6fde6b162b2802d4d337657f3253b5f69579bddeee
environment:
- NVIDIA_VISIBLE_DEVICES=all
- NVIDIA_DRIVER_CAPABILITIES=compute,utility
+3 -1
View File
@@ -18,7 +18,9 @@ services:
restart: unless-stopped
ollama:
image: ollama/ollama:latest
# Pinned to a fixed version + digest for reproducible deployments and
# predictable rollbacks (#563). Bump deliberately, not implicitly via :latest.
image: ollama/ollama:0.30.10@sha256:bfc9c6d53cc6989aa5131a6fde6b162b2802d4d337657f3253b5f69579bddeee
ports:
- "11434:11434"
volumes:
+20
View File
@@ -14,7 +14,27 @@ Environment=HOME=/opt/openjarvis
# OPENJARVIS_API_KEY=<key> (generate one: `jarvis auth generate-key`)
# It is not prefixed with "-", so the unit fails to start if the file is
# missing — preventing an accidentally unauthenticated public server.
# Keep secrets here (mode 0600, owned by root) rather than inline Environment=
# lines, which leak into `systemctl show` and the journal.
EnvironmentFile=/etc/openjarvis/env
# --- Sandboxing / hardening (#564) ---
# Conservative set: tightens the unit without blocking the server's normal I/O
# or local GPU inference. ProtectSystem=strict makes the whole filesystem
# read-only except ReadWritePaths, so $HOME (config/cache/state under
# /opt/openjarvis) stays writable.
NoNewPrivileges=true
ProtectSystem=strict
ReadWritePaths=/opt/openjarvis
ProtectHome=true
PrivateTmp=true
ProtectControlGroups=true
ProtectKernelLogs=true
ProtectKernelModules=true
ProtectKernelTunables=true
RestrictRealtime=true
RestrictSUIDSGID=true
LockPersonality=true
[Install]
WantedBy=multi-user.target
+12
View File
@@ -0,0 +1,12 @@
// Public Supabase config for the savings leaderboard.
//
// This file is loaded *before* leaderboard.js and supplies the anon key it
// reads from `window.OPENJARVIS_SUPABASE_ANON_KEY`. The key is injected at
// docs-build time from the VITE_SUPABASE_ANON_KEY repo secret (see
// .github/workflows/docs.yml). It is intentionally empty here so that local
// `mkdocs build` and fork pull requests — which have no secret — render the
// graceful "Leaderboard not configured yet" message instead of failing.
//
// The anon key is public by design: Supabase Row-Level Security protects the
// data, so shipping it in the public docs bundle is expected.
window.OPENJARVIS_SUPABASE_ANON_KEY = "";
+3 -3
View File
@@ -1,9 +1,9 @@
(function () {
"use strict";
var SUPABASE_URL = "https://mtbtgpwzrbostweaanpr.supabase.co";
var SUPABASE_ANON_KEY =
"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6Im10YnRncHd6cmJvc3R3ZWFhbnByIiwicm9sZSI6ImFub24iLCJpYXQiOjE3NzMxODk0OTQsImV4cCI6MjA4ODc2NTQ5NH0._xMlqCfljtXpwPj54H-ghxfLFO-jiq4W2WhpU8vVL1c";
var SUPABASE_URL =
window.OPENJARVIS_SUPABASE_URL || "https://mtbtgpwzrbostweaanpr.supabase.co";
var SUPABASE_ANON_KEY = window.OPENJARVIS_SUPABASE_ANON_KEY || "";
var PAGE_SIZE = 50;
var allRows = [];
+67 -52
View File
@@ -11,7 +11,7 @@
"@base-ui/react": "^1.3.0",
"@fontsource-variable/geist": "^5.2.8",
"@tailwindcss/vite": "^4.2.1",
"@tauri-apps/api": "^2",
"@tauri-apps/api": "^2.11.1",
"@tauri-apps/plugin-autostart": "^2",
"@tauri-apps/plugin-dialog": "^2.7.0",
"@tauri-apps/plugin-global-shortcut": "^2",
@@ -42,7 +42,7 @@
"zustand": "^5.0.11"
},
"devDependencies": {
"@tauri-apps/cli": "^2",
"@tauri-apps/cli": "^2.11.4",
"@types/react": "^19.0.0",
"@types/react-dom": "^19.0.0",
"@vitejs/plugin-react": "^4.3.4",
@@ -3720,9 +3720,9 @@
}
},
"node_modules/@tauri-apps/api": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/api/-/api-2.10.1.tgz",
"integrity": "sha512-hKL/jWf293UDSUN09rR69hrToyIXBb8CjGaWC7gfinvnQrBVvnLr08FeFi38gxtugAVyVcTa5/FD/Xnkb1siBw==",
"version": "2.11.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/api/-/api-2.11.1.tgz",
"integrity": "sha512-M2FPuYND2m+wh5hfW9ZpSdxMPdEJovPBWwoHJmwUpysTYNHaOkVFN419m/K0LIgjb/7KU2vBgsUepJWugQCvAA==",
"license": "Apache-2.0 OR MIT",
"funding": {
"type": "opencollective",
@@ -3730,9 +3730,9 @@
}
},
"node_modules/@tauri-apps/cli": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli/-/cli-2.10.1.tgz",
"integrity": "sha512-jQNGF/5quwORdZSSLtTluyKQ+o6SMa/AUICfhf4egCGFdMHqWssApVgYSbg+jmrZoc8e1DscNvjTnXtlHLS11g==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli/-/cli-2.11.4.tgz",
"integrity": "sha512-R8xGtMpwyetawSqm9kYOuMmEqkhUbvcUy8n0aNXIxollKBLESUu5f4Fx+64hgASYm1H+jSWq6jCW6zqTnH6hqQ==",
"dev": true,
"license": "Apache-2.0 OR MIT",
"bin": {
@@ -3746,23 +3746,23 @@
"url": "https://opencollective.com/tauri"
},
"optionalDependencies": {
"@tauri-apps/cli-darwin-arm64": "2.10.1",
"@tauri-apps/cli-darwin-x64": "2.10.1",
"@tauri-apps/cli-linux-arm-gnueabihf": "2.10.1",
"@tauri-apps/cli-linux-arm64-gnu": "2.10.1",
"@tauri-apps/cli-linux-arm64-musl": "2.10.1",
"@tauri-apps/cli-linux-riscv64-gnu": "2.10.1",
"@tauri-apps/cli-linux-x64-gnu": "2.10.1",
"@tauri-apps/cli-linux-x64-musl": "2.10.1",
"@tauri-apps/cli-win32-arm64-msvc": "2.10.1",
"@tauri-apps/cli-win32-ia32-msvc": "2.10.1",
"@tauri-apps/cli-win32-x64-msvc": "2.10.1"
"@tauri-apps/cli-darwin-arm64": "2.11.4",
"@tauri-apps/cli-darwin-x64": "2.11.4",
"@tauri-apps/cli-linux-arm-gnueabihf": "2.11.4",
"@tauri-apps/cli-linux-arm64-gnu": "2.11.4",
"@tauri-apps/cli-linux-arm64-musl": "2.11.4",
"@tauri-apps/cli-linux-riscv64-gnu": "2.11.4",
"@tauri-apps/cli-linux-x64-gnu": "2.11.4",
"@tauri-apps/cli-linux-x64-musl": "2.11.4",
"@tauri-apps/cli-win32-arm64-msvc": "2.11.4",
"@tauri-apps/cli-win32-ia32-msvc": "2.11.4",
"@tauri-apps/cli-win32-x64-msvc": "2.11.4"
}
},
"node_modules/@tauri-apps/cli-darwin-arm64": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-darwin-arm64/-/cli-darwin-arm64-2.10.1.tgz",
"integrity": "sha512-Z2OjCXiZ+fbYZy7PmP3WRnOpM9+Fy+oonKDEmUE6MwN4IGaYqgceTjwHucc/kEEYZos5GICve35f7ZiizgqEnQ==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-darwin-arm64/-/cli-darwin-arm64-2.11.4.tgz",
"integrity": "sha512-1ryOF3ZhpZ/nemHV5zVwBQBz9jDGKmKPvWPADOhc83ig0P4bMc2iER4NbC6r9sjeIZ6RVQ4g3RZIYvezhcl4TQ==",
"cpu": [
"arm64"
],
@@ -3777,9 +3777,9 @@
}
},
"node_modules/@tauri-apps/cli-darwin-x64": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-darwin-x64/-/cli-darwin-x64-2.10.1.tgz",
"integrity": "sha512-V/irQVvjPMGOTQqNj55PnQPVuH4VJP8vZCN7ajnj+ZS8Kom1tEM2hR3qbbIRoS3dBKs5mbG8yg1WC+97dq17Pw==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-darwin-x64/-/cli-darwin-x64-2.11.4.tgz",
"integrity": "sha512-uFsGQAAfuyz1k/yGLmkWfkBlgKAqZfxqlHmLWx81QU27RJWfmbNHCIq8T8w1e+VClleIuZUjpHWfoE4E3DLo3A==",
"cpu": [
"x64"
],
@@ -3794,9 +3794,9 @@
}
},
"node_modules/@tauri-apps/cli-linux-arm-gnueabihf": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-arm-gnueabihf/-/cli-linux-arm-gnueabihf-2.10.1.tgz",
"integrity": "sha512-Hyzwsb4VnCWKGfTw+wSt15Z2pLw2f0JdFBfq2vHBOBhvg7oi6uhKiF87hmbXOBXUZaGkyRDkCHsdzJcIfoJC2w==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-arm-gnueabihf/-/cli-linux-arm-gnueabihf-2.11.4.tgz",
"integrity": "sha512-IaHZn5CdBL21oUmjiVOS1ctw6Ip1O0pjp70FwOWmYz1myWe0SY96ZIj2FYf7pT0m8bI2h/hrs5ZbEXXh44/MkQ==",
"cpu": [
"arm"
],
@@ -3811,13 +3811,16 @@
}
},
"node_modules/@tauri-apps/cli-linux-arm64-gnu": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-arm64-gnu/-/cli-linux-arm64-gnu-2.10.1.tgz",
"integrity": "sha512-OyOYs2t5GkBIvyWjA1+h4CZxTcdz1OZPCWAPz5DYEfB0cnWHERTnQ/SLayQzncrT0kwRoSfSz9KxenkyJoTelA==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-arm64-gnu/-/cli-linux-arm64-gnu-2.11.4.tgz",
"integrity": "sha512-N41/ukTRVe6XSuUTESuFdGeOW2i7k62tK+6gHK5Kd5/q5RPvvi19GaWAVPPb9u95HSGmTChSolBfzynUsssFaA==",
"cpu": [
"arm64"
],
"dev": true,
"libc": [
"glibc"
],
"license": "Apache-2.0 OR MIT",
"optional": true,
"os": [
@@ -3828,13 +3831,16 @@
}
},
"node_modules/@tauri-apps/cli-linux-arm64-musl": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-arm64-musl/-/cli-linux-arm64-musl-2.10.1.tgz",
"integrity": "sha512-MIj78PDDGjkg3NqGptDOGgfXks7SYJwhiMh8SBoZS+vfdz7yP5jN18bNaLnDhsVIPARcAhE1TlsZe/8Yxo2zqg==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-arm64-musl/-/cli-linux-arm64-musl-2.11.4.tgz",
"integrity": "sha512-v277UnT/fB64xAfSroL5N3Km3tLmvATWqJJw/wRI+g6o+HkeD0slyE7gOhNs1MbjE41R7bQOTxMVoL3aomUJmw==",
"cpu": [
"arm64"
],
"dev": true,
"libc": [
"musl"
],
"license": "Apache-2.0 OR MIT",
"optional": true,
"os": [
@@ -3845,13 +3851,16 @@
}
},
"node_modules/@tauri-apps/cli-linux-riscv64-gnu": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-riscv64-gnu/-/cli-linux-riscv64-gnu-2.10.1.tgz",
"integrity": "sha512-X0lvOVUg8PCVaoEtEAnpxmnkwlE1gcMDTqfhbefICKDnOTJ5Est3qL0SrWxizDackIOKBcvtpejrSiVpuJI1kw==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-riscv64-gnu/-/cli-linux-riscv64-gnu-2.11.4.tgz",
"integrity": "sha512-qqgNkQ2u1yZHxjhxsZaxUtRDW8dIqIYm33rx/mzwQv0SfY9x1B+iraj8vWeFiXjjSVVhEMepXSOts1TqPzvXNQ==",
"cpu": [
"riscv64"
],
"dev": true,
"libc": [
"glibc"
],
"license": "Apache-2.0 OR MIT",
"optional": true,
"os": [
@@ -3862,13 +3871,16 @@
}
},
"node_modules/@tauri-apps/cli-linux-x64-gnu": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-x64-gnu/-/cli-linux-x64-gnu-2.10.1.tgz",
"integrity": "sha512-2/12bEzsJS9fAKybxgicCDFxYD1WEI9kO+tlDwX5znWG2GwMBaiWcmhGlZ8fi+DMe9CXlcVarMTYc0L3REIRxw==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-x64-gnu/-/cli-linux-x64-gnu-2.11.4.tgz",
"integrity": "sha512-2VRNWl84FOH0m2giiDkO2h0QXlcMJeX+zJDpI5kDIQAx6s+geF3v48F4DXfJez4GS/FdoDGnPnw1C2iYGbQ7bQ==",
"cpu": [
"x64"
],
"dev": true,
"libc": [
"glibc"
],
"license": "Apache-2.0 OR MIT",
"optional": true,
"os": [
@@ -3879,13 +3891,16 @@
}
},
"node_modules/@tauri-apps/cli-linux-x64-musl": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-x64-musl/-/cli-linux-x64-musl-2.10.1.tgz",
"integrity": "sha512-Y8J0ZzswPz50UcGOFuXGEMrxbjwKSPgXftx5qnkuMs2rmwQB5ssvLb6tn54wDSYxe7S6vlLob9vt0VKuNOaCIQ==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-linux-x64-musl/-/cli-linux-x64-musl-2.11.4.tgz",
"integrity": "sha512-o9GyhYor/nc7xarmwDE3ka2szuW3uuZzXjHWh64Q8YX5AtSgxdQkFWzrY4O8KiGtVNvFBI14H3Q49Qj5TOIP/A==",
"cpu": [
"x64"
],
"dev": true,
"libc": [
"musl"
],
"license": "Apache-2.0 OR MIT",
"optional": true,
"os": [
@@ -3896,9 +3911,9 @@
}
},
"node_modules/@tauri-apps/cli-win32-arm64-msvc": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-win32-arm64-msvc/-/cli-win32-arm64-msvc-2.10.1.tgz",
"integrity": "sha512-iSt5B86jHYAPJa/IlYw++SXtFPGnWtFJriHn7X0NFBVunF6zu9+/zOn8OgqIWSl8RgzhLGXQEEtGBdR4wzpVgg==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-win32-arm64-msvc/-/cli-win32-arm64-msvc-2.11.4.tgz",
"integrity": "sha512-ld5Ehb598m0VkYyylRPNeCFsBe/km0jxis6KgMpl3IGY6I/i1RwQXO05I1AsXUXO2WC6AvB/Lw4qTf/asiuEiQ==",
"cpu": [
"arm64"
],
@@ -3913,9 +3928,9 @@
}
},
"node_modules/@tauri-apps/cli-win32-ia32-msvc": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-win32-ia32-msvc/-/cli-win32-ia32-msvc-2.10.1.tgz",
"integrity": "sha512-gXyxgEzsFegmnWywYU5pEBURkcFN/Oo45EAwvZrHMh+zUSEAvO5E8TXsgPADYm31d1u7OQU3O3HsYfVBf2moHw==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-win32-ia32-msvc/-/cli-win32-ia32-msvc-2.11.4.tgz",
"integrity": "sha512-12Hxi0XX/H5VFxO/bGgHkFWhml9VMgEOu9CidjeCeTNQ1l6fpUlbiGgSP7CLI3PFtW9/FfbeHieZ+kyWK5H7CA==",
"cpu": [
"ia32"
],
@@ -3930,9 +3945,9 @@
}
},
"node_modules/@tauri-apps/cli-win32-x64-msvc": {
"version": "2.10.1",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-win32-x64-msvc/-/cli-win32-x64-msvc-2.10.1.tgz",
"integrity": "sha512-6Cn7YpPFwzChy0ERz6djKEmUehWrYlM+xTaNzGPgZocw3BD7OfwfWHKVWxXzdjEW2KfKkHddfdxK1XXTYqBRLg==",
"version": "2.11.4",
"resolved": "https://registry.npmjs.org/@tauri-apps/cli-win32-x64-msvc/-/cli-win32-x64-msvc-2.11.4.tgz",
"integrity": "sha512-+vDiqBIU5dMISg/wNvX3sF+ZHfgJGJ5T0AcO+EHNXV9GGAG+P5fzodlDXD3QdKCRgZxMoCm5PPvj3BqLNjBthw==",
"cpu": [
"x64"
],
+2 -2
View File
@@ -18,7 +18,7 @@
"@base-ui/react": "^1.3.0",
"@fontsource-variable/geist": "^5.2.8",
"@tailwindcss/vite": "^4.2.1",
"@tauri-apps/api": "^2",
"@tauri-apps/api": "^2.11.1",
"@tauri-apps/plugin-autostart": "^2",
"@tauri-apps/plugin-dialog": "^2.7.0",
"@tauri-apps/plugin-global-shortcut": "^2",
@@ -49,7 +49,7 @@
"zustand": "^5.0.11"
},
"devDependencies": {
"@tauri-apps/cli": "^2",
"@tauri-apps/cli": "^2.11.4",
"@types/react": "^19.0.0",
"@types/react-dom": "^19.0.0",
"@vitejs/plugin-react": "^4.3.4",
+1108 -1007
View File
File diff suppressed because it is too large Load Diff
+13
View File
@@ -24,9 +24,22 @@ serde_json = "1"
reqwest = { version = "0.12", features = ["json", "multipart"] }
tokio = { version = "1", features = ["full"] }
# Cloud API keys are stored in the OS credential store via `keyring`. keyring v3
# enables NO backend by default — without an explicit per-platform feature it
# silently falls back to a non-persistent in-memory mock, so keys would not
# survive an app restart. Each desktop target opts into its native store.
[target.'cfg(target_os = "macos")'.dependencies]
objc = "0.2"
dispatch = "0.2"
keyring = { version = "3", features = ["apple-native"] }
[target.'cfg(target_os = "windows")'.dependencies]
keyring = { version = "3", features = ["windows-native"] }
[target.'cfg(target_os = "linux")'.dependencies]
# Blocking Secret Service backend (no internal async runtime, so it is safe to
# call from the tokio-driven Tauri commands). Needs libdbus-1-dev at build time.
keyring = { version = "3", features = ["sync-secret-service", "crypto-rust"] }
[features]
default = ["custom-protocol"]
+373 -88
View File
@@ -9,7 +9,7 @@ use tokio::sync::Mutex;
const OLLAMA_PORT: u16 = 11434;
const JARVIS_PORT: u16 = 8000;
/// Small, fast model pulled at startup so the app opens quickly.
/// Small, fast model used when startup needs a default Ollama tag.
const STARTUP_MODEL: &str = "qwen3.5:4b";
/// Tiny fallback model if even the startup model can't be pulled.
@@ -104,7 +104,7 @@ fn default_local_model(ram_gb: f64) -> &'static str {
struct BootPlan {
/// Whether to start and wait for the bundled Ollama.
launch_ollama: bool,
/// The single Ollama model to pull (None for custom endpoints).
/// The preferred Ollama model (None for custom endpoints).
model_to_pull: Option<String>,
/// Optional `(engine_key, bare_host)` override for a custom endpoint,
/// e.g. `("lmstudio", "http://localhost:1234")`. Written into
@@ -608,6 +608,69 @@ async fn wait_for_jarvis_health(
}
async fn ollama_has_model(model: &str) -> bool {
let models = ollama_model_names().await;
matching_installed_model(&models, model).is_some()
}
fn parse_ollama_model_names(body: &serde_json::Value) -> Vec<String> {
body.get("models")
.and_then(|m| m.as_array())
.map(|models| {
models
.iter()
.filter_map(|m| {
m.get("name")
.or_else(|| m.get("model"))
.and_then(|n| n.as_str())
})
.filter(|name| !name.trim().is_empty())
.map(|name| name.to_string())
.collect()
})
.unwrap_or_default()
}
fn model_names_match(installed: &str, requested: &str) -> bool {
installed == requested
|| installed.strip_suffix(":latest") == Some(requested)
|| requested.strip_suffix(":latest") == Some(installed)
}
fn matching_installed_model(models: &[String], requested: &str) -> Option<String> {
models
.iter()
.find(|model| model_names_match(model, requested))
.cloned()
}
fn model_name_looks_embedding_only(model: &str) -> bool {
let name = model.to_ascii_lowercase();
["embed", "embedding", "rerank", "minilm", "bge-", "bge_", "e5-", "e5_"]
.iter()
.any(|marker| name.contains(marker))
}
fn preferred_installed_model(models: &[String]) -> Option<String> {
models
.iter()
.find(|model| !model.trim().is_empty() && !model_name_looks_embedding_only(model))
.or_else(|| models.iter().find(|model| !model.trim().is_empty()))
.cloned()
}
fn startup_installed_model(requested_model: &str, installed_models: &[String]) -> Option<String> {
matching_installed_model(installed_models, requested_model)
.or_else(|| preferred_installed_model(installed_models))
}
fn should_persist_resolved_model(cfg: &InferenceConfig) -> bool {
cfg.model
.as_deref()
.map(|model| model.trim().is_empty())
.unwrap_or(true)
}
async fn ollama_model_names() -> Vec<String> {
let url = format!("http://127.0.0.1:{}/api/tags", OLLAMA_PORT);
let client = reqwest::Client::builder()
.timeout(Duration::from_secs(5))
@@ -615,21 +678,10 @@ async fn ollama_has_model(model: &str) -> bool {
.unwrap();
if let Ok(resp) = client.get(&url).send().await {
if let Ok(body) = resp.json::<serde_json::Value>().await {
if let Some(models) = body.get("models").and_then(|m| m.as_array()) {
return models.iter().any(|m| {
m.get("name")
.and_then(|n| n.as_str())
.map(|n| {
n == model
|| n.strip_suffix(":latest") == Some(model)
|| model.strip_suffix(":latest") == Some(n)
})
.unwrap_or(false)
});
}
return parse_ollama_model_names(&body);
}
}
false
Vec::new()
}
async fn pull_model(model: &str) -> Result<(), String> {
@@ -751,7 +803,7 @@ async fn boot_backend(backend: SharedBackend, status: SharedStatus) {
.into();
}
// For the Ollama path, the model pull may fall back to FALLBACK_MODEL; we
// For the Ollama path, model resolution may fall back to FALLBACK_MODEL; we
// record what is actually available here so the serve command below uses
// it instead of the originally-planned tag. None on the custom path.
let mut serve_model_override: Option<String> = None;
@@ -798,8 +850,8 @@ async fn boot_backend(backend: SharedBackend, status: SharedStatus) {
s.detail = "Inference engine ready.".into();
}
// Phase 2: Pull the single default model (see default_local_model /
// boot_plan). We deliberately do NOT pull any others.
// Phase 2: Resolve one model to serve. Prefer an installed model on
// first run so startup does not depend on a download succeeding.
let model = plan
.model_to_pull
.clone()
@@ -810,41 +862,63 @@ async fn boot_backend(backend: SharedBackend, status: SharedStatus) {
s.detail = format!("Checking for {}...", model);
}
if !ollama_has_model(&model).await {
let installed_models = ollama_model_names().await;
let resolved_model = if let Some(installed) = startup_installed_model(&model, &installed_models) {
installed
} else {
{
let mut s = status.lock().await;
s.detail = format!("Downloading {}... (this may take a minute)", model);
}
if let Err(e) = pull_model(&model).await {
// If the chosen model fails, try the tiny fallback
eprintln!("Warning: failed to pull {}: {}", model, e);
if !ollama_has_model(FALLBACK_MODEL).await {
{
let mut s = status.lock().await;
s.detail = format!("Downloading {}...", FALLBACK_MODEL);
}
if let Err(e2) = pull_model(FALLBACK_MODEL).await {
let mut s = status.lock().await;
s.error = Some(format!("Failed to download model: {}", e2));
return;
match pull_model(&model).await {
Ok(()) => model.clone(),
Err(e) => {
eprintln!("Warning: failed to pull {}: {}", model, e);
// If a local model appeared while pulling, use it instead of
// making startup depend on another network pull.
if let Some(installed) = preferred_installed_model(&ollama_model_names().await) {
installed
} else if ollama_has_model(FALLBACK_MODEL).await {
FALLBACK_MODEL.to_string()
} else {
{
let mut s = status.lock().await;
s.detail = format!("Downloading {}...", FALLBACK_MODEL);
}
if let Err(e2) = pull_model(FALLBACK_MODEL).await {
if let Some(installed) =
preferred_installed_model(&ollama_model_names().await)
{
installed
} else {
let mut s = status.lock().await;
s.error = Some(format!("Failed to download model: {}", e2));
return;
}
} else {
FALLBACK_MODEL.to_string()
}
}
}
}
};
if resolved_model != model {
let mut s = status.lock().await;
s.detail = format!("Using installed model {}.", resolved_model);
}
// The pull may have fallen back to FALLBACK_MODEL; serve and persist
// whatever is actually available now, not the originally-planned tag.
let resolved_model = if ollama_has_model(&model).await {
model
} else {
FALLBACK_MODEL.to_string()
};
serve_model_override = Some(resolved_model.clone());
// Persist the resolved model so Settings shows it and future boots reuse it.
let mut persisted = cfg.clone();
persisted.model = Some(resolved_model);
let _ = write_inference_config(&persisted);
// Persist only first-run/default resolution. If the user explicitly
// configured a model, do not overwrite that choice with a temporary
// fallback selected just to keep startup nonfatal.
if should_persist_resolved_model(&cfg) {
let mut persisted = cfg.clone();
persisted.model = Some(resolved_model);
let _ = write_inference_config(&persisted);
}
{
let mut s = status.lock().await;
@@ -1204,7 +1278,7 @@ async fn boot_backend(backend: SharedBackend, status: SharedStatus) {
// additions aren't accidentally stripped.
prepare_subprocess_for_appimage(&mut cmd);
// Inject cloud API keys from ~/.openjarvis/cloud-keys.env
// Inject cloud API keys from secure desktop storage.
for (key, value) in read_cloud_keys() {
cmd.env(&key, &value);
}
@@ -1720,17 +1794,111 @@ async fn submit_savings(
// Cloud API key management
// ---------------------------------------------------------------------------
/// Path to the cloud keys file (~/.openjarvis/cloud-keys.env).
fn cloud_keys_path() -> std::path::PathBuf {
const SECURE_KEY_SERVICE: &str = "OpenJarvis Cloud Keys";
const MANAGED_CLOUD_KEY_NAMES: &[&str] = &[
"OPENAI_API_KEY",
"ANTHROPIC_API_KEY",
"GEMINI_API_KEY",
"GOOGLE_API_KEY",
"OPENROUTER_API_KEY",
"MINIMAX_API_KEY",
"TAVILY_API_KEY",
];
/// Legacy path used by older desktop builds. New saves never write here.
fn legacy_cloud_keys_path() -> std::path::PathBuf {
let home = home_dir();
std::path::PathBuf::from(home)
.join(".openjarvis")
.join("cloud-keys.env")
}
/// Read cloud keys from disk and return as key=value pairs.
fn read_cloud_keys() -> Vec<(String, String)> {
let path = cloud_keys_path();
fn validate_cloud_key_name(key_name: &str) -> Result<(), String> {
let valid = !key_name.is_empty()
&& key_name.len() <= 128
&& key_name.ends_with("_API_KEY")
&& key_name
.chars()
.all(|ch| ch.is_ascii_uppercase() || ch.is_ascii_digit() || ch == '_');
if valid {
Ok(())
} else {
Err(format!("Invalid API key name: {}", key_name))
}
}
fn engine_api_key_name(engine: &str) -> String {
let normalized: String = engine
.chars()
.map(|ch| {
if ch.is_ascii_alphanumeric() {
ch.to_ascii_uppercase()
} else {
'_'
}
})
.collect();
let trimmed = normalized.trim_matches('_');
let engine_name = if trimmed.is_empty() {
CUSTOM_FALLBACK_ENGINE.to_ascii_uppercase()
} else {
trimmed.to_string()
};
format!("{}_API_KEY", engine_name)
}
fn managed_cloud_key_names() -> Vec<String> {
let mut names: Vec<String> = MANAGED_CLOUD_KEY_NAMES
.iter()
.map(|name| (*name).to_string())
.collect();
let cfg = read_inference_config();
if matches!(&cfg.kind, SourceKind::Custom) {
let engine = cfg.engine.unwrap_or_else(|| CUSTOM_FALLBACK_ENGINE.to_string());
let key_name = engine_api_key_name(&engine);
if validate_cloud_key_name(&key_name).is_ok() {
names.push(key_name);
}
}
names.sort();
names.dedup();
names
}
fn secure_store_get(key_name: &str) -> Result<Option<String>, String> {
validate_cloud_key_name(key_name)?;
let entry = keyring::Entry::new(SECURE_KEY_SERVICE, key_name)
.map_err(|err| format!("Failed to open secure key storage for {}: {}", key_name, err))?;
match entry.get_password() {
Ok(value) => Ok(Some(value)),
Err(keyring::Error::NoEntry) => Ok(None),
Err(err) => Err(format!("Failed to read {} from secure key storage: {}", key_name, err)),
}
}
fn secure_store_set(key_name: &str, key_value: &str) -> Result<(), String> {
validate_cloud_key_name(key_name)?;
let entry = keyring::Entry::new(SECURE_KEY_SERVICE, key_name)
.map_err(|err| format!("Failed to open secure key storage for {}: {}", key_name, err))?;
if key_value.is_empty() {
return match entry.delete_credential() {
Ok(()) => Ok(()),
Err(keyring::Error::NoEntry) => Ok(()),
Err(err) => Err(format!(
"Failed to remove {} from secure key storage: {}",
key_name, err
)),
};
}
entry
.set_password(key_value)
.map_err(|err| format!("Failed to save {} in secure key storage: {}", key_name, err))
}
fn read_legacy_cloud_keys() -> Vec<(String, String)> {
let path = legacy_cloud_keys_path();
let mut keys = Vec::new();
if let Ok(contents) = std::fs::read_to_string(&path) {
for line in contents.lines() {
@@ -1746,47 +1914,68 @@ fn read_cloud_keys() -> Vec<(String, String)> {
keys
}
/// Save a single cloud API key to the keys file.
#[tauri::command]
async fn save_cloud_key(key_name: String, key_value: String) -> Result<(), String> {
let path = cloud_keys_path();
// Ensure directory exists
if let Some(parent) = path.parent() {
let _ = std::fs::create_dir_all(parent);
fn migrate_legacy_cloud_keys() {
let path = legacy_cloud_keys_path();
if !path.exists() {
return;
}
// Read existing keys, update/add the one being saved
let mut keys: Vec<(String, String)> = read_cloud_keys()
let legacy_keys = read_legacy_cloud_keys();
if legacy_keys.is_empty() {
let _ = std::fs::remove_file(&path);
return;
}
let mut migrated_all = true;
for (key, value) in legacy_keys {
if value.is_empty() {
continue;
}
if secure_store_set(&key, &value).is_err() {
migrated_all = false;
}
}
if migrated_all {
let _ = std::fs::remove_file(path);
}
}
/// Read cloud keys from secure desktop storage and return key=value pairs.
fn read_cloud_keys() -> Vec<(String, String)> {
migrate_legacy_cloud_keys();
managed_cloud_key_names()
.into_iter()
.filter(|(k, _)| k != &key_name)
.collect();
if !key_value.is_empty() {
keys.push((key_name, key_value));
}
.filter_map(|key| match secure_store_get(&key) {
Ok(Some(value)) if !value.is_empty() => Some((key, value)),
_ => None,
})
.collect()
}
// Write back
let content: String = keys
.iter()
.map(|(k, v)| format!("{}={}", k, v))
.collect::<Vec<_>>()
.join("\n");
std::fs::write(&path, content + "\n").map_err(|e| format!("Failed to save key: {}", e))?;
// Set permissions to owner-only (chmod 600)
#[cfg(unix)]
{
use std::os::unix::fs::PermissionsExt;
let _ = std::fs::set_permissions(&path, std::fs::Permissions::from_mode(0o600));
}
// Tell the running server to hot-reload its cloud engine so the user
// doesn't need to restart the app after entering an API key.
async fn reload_cloud_keys(keys: Vec<(String, String)>) {
let reload_url = format!("http://127.0.0.1:{}/v1/cloud/reload", JARVIS_PORT);
let key_map: serde_json::Map<String, serde_json::Value> = keys
.into_iter()
.map(|(key, value)| (key, serde_json::Value::String(value)))
.collect();
let _ = reqwest::Client::new()
.post(&reload_url)
.json(&serde_json::json!({ "keys": key_map }))
.timeout(std::time::Duration::from_secs(10))
.send()
.await;
}
/// Save a single cloud API key to secure desktop storage.
#[tauri::command]
async fn save_cloud_key(key_name: String, key_value: String) -> Result<(), String> {
let key_value = key_value.trim().to_string();
secure_store_set(&key_name, &key_value)?;
// Tell the running server to hot-reload its cloud engine so the user
// doesn't need to restart the app after entering an API key.
reload_cloud_keys(vec![(key_name, key_value)]).await;
Ok(())
}
@@ -1794,10 +1983,13 @@ async fn save_cloud_key(key_name: String, key_value: String) -> Result<(), Strin
/// Get which cloud providers have keys configured (without exposing values).
#[tauri::command]
async fn get_cloud_key_status() -> Result<serde_json::Value, String> {
let keys = read_cloud_keys();
let status: Vec<serde_json::Value> = keys
.iter()
.map(|(k, v)| serde_json::json!({ "key": k, "set": !v.is_empty() }))
migrate_legacy_cloud_keys();
let status: Vec<serde_json::Value> = managed_cloud_key_names()
.into_iter()
.map(|key| {
let set = matches!(secure_store_get(&key), Ok(Some(value)) if !value.is_empty());
serde_json::json!({ "key": key, "set": set })
})
.collect();
Ok(serde_json::json!(status))
}
@@ -1809,8 +2001,8 @@ async fn get_inference_source() -> Result<InferenceConfig, String> {
}
/// Persist the chosen inference source. `host` is normalized to a bare base
/// URL. For custom endpoints, an optional API key is stored in cloud-keys.env
/// under `<ENGINE>_API_KEY`. Applies on next app launch.
/// URL. For custom endpoints, an optional API key is stored in secure desktop
/// storage under `<ENGINE>_API_KEY`. Applies on next app launch.
#[tauri::command]
async fn set_inference_source(
kind: String,
@@ -1842,7 +2034,7 @@ async fn set_inference_source(
.engine
.clone()
.unwrap_or_else(|| CUSTOM_FALLBACK_ENGINE.to_string());
let key_name = format!("{}_API_KEY", engine.to_ascii_uppercase());
let key_name = engine_api_key_name(&engine);
// Save the key before persisting the config: if the key can't be
// written, surface it and DON'T record a custom source whose
// credential is missing (which would fail confusingly at runtime).
@@ -2529,8 +2721,10 @@ pub fn run() {
mod tests {
use super::{
boot_plan, default_local_model, format_uv_sync_failure, format_uv_sync_spawn_error,
normalize_host, parse_inference_config, upsert_engine_host, uv_sync_stderr_tail,
InferenceConfig, SourceKind,
matching_installed_model, model_names_match, normalize_host, parse_inference_config,
parse_ollama_model_names, preferred_installed_model, should_persist_resolved_model,
startup_installed_model,
upsert_engine_host, uv_sync_stderr_tail, InferenceConfig, SourceKind,
};
use std::path::Path;
@@ -2612,6 +2806,97 @@ mod tests {
assert_eq!(default_local_model(1.0), super::FALLBACK_MODEL);
}
#[test]
fn parse_ollama_model_names_reads_nonempty_names() {
let body = serde_json::json!({
"models": [
{"name": "llama3.2:latest"},
{"name": ""},
{"name": "qwen3.5:4b"},
{"model": "mistral:latest"}
]
});
assert_eq!(
parse_ollama_model_names(&body),
vec![
"llama3.2:latest".to_string(),
"qwen3.5:4b".to_string(),
"mistral:latest".to_string()
]
);
}
#[test]
fn model_names_match_treats_latest_as_optional() {
assert!(model_names_match("llama3.2:latest", "llama3.2"));
assert!(model_names_match("llama3.2", "llama3.2:latest"));
assert!(model_names_match("qwen3.5:4b", "qwen3.5:4b"));
assert!(!model_names_match("llama3.2:latest", "qwen3.5:4b"));
}
#[test]
fn installed_model_helpers_pick_matching_or_first_model() {
let models = vec!["llama3.2:latest".to_string(), "qwen3.5:4b".to_string()];
assert_eq!(
matching_installed_model(&models, "llama3.2"),
Some("llama3.2:latest".to_string())
);
assert_eq!(
preferred_installed_model(&models),
Some("llama3.2:latest".to_string())
);
}
#[test]
fn preferred_installed_model_skips_embedding_names_when_chat_model_exists() {
let models = vec![
"nomic-embed-text:latest".to_string(),
"llama3.2:latest".to_string(),
];
assert_eq!(
preferred_installed_model(&models),
Some("llama3.2:latest".to_string())
);
}
#[test]
fn startup_installed_model_uses_existing_model_for_defaults() {
let models = vec!["llama3.2:latest".to_string()];
assert_eq!(
startup_installed_model("qwen3.5:4b", &models),
Some("llama3.2:latest".to_string())
);
}
#[test]
fn startup_installed_model_uses_existing_model_when_configured_model_missing() {
let models = vec!["llama3.2:latest".to_string()];
assert_eq!(
startup_installed_model("qwen3.5:4b", &models),
Some("llama3.2:latest".to_string())
);
}
#[test]
fn resolved_model_is_only_persisted_when_no_model_was_configured() {
let default_cfg = InferenceConfig { kind: SourceKind::Ollama, ..Default::default() };
assert!(should_persist_resolved_model(&default_cfg));
let empty_cfg = InferenceConfig {
kind: SourceKind::Ollama,
model: Some(" ".into()),
..Default::default()
};
assert!(should_persist_resolved_model(&empty_cfg));
let user_cfg = InferenceConfig {
kind: SourceKind::Ollama,
model: Some("qwen3.5:9b".into()),
..Default::default()
};
assert!(!should_persist_resolved_model(&user_cfg));
}
#[test]
fn parse_defaults_to_ollama_when_file_missing_or_garbage() {
assert!(matches!(parse_inference_config("").kind, SourceKind::Ollama));
+74 -48
View File
@@ -1,7 +1,15 @@
import { useState, useRef, useEffect } from 'react';
import { useState, useRef, useEffect, useCallback } from 'react';
import { Search, Cpu, X, Download, Loader2, Trash2, Check, Cloud, Key, Eye, EyeOff } from 'lucide-react';
import { useAppStore } from '../lib/store';
import { pullModel, deleteModel, fetchModels, preloadModel, isTauri } from '../lib/api';
import {
pullModel,
deleteModel,
fetchModels,
preloadModel,
isTauri,
getCloudKeyStatus,
saveCloudKey,
} from '../lib/api';
/** Popular models that users can download from the catalogue. */
const CATALOGUE_MODELS = [
@@ -23,7 +31,6 @@ const CATALOGUE_MODELS = [
interface CloudProvider {
name: string;
envKey: string;
storageKey: string;
models: Array<{ id: string; desc: string }>;
}
@@ -31,7 +38,6 @@ const CLOUD_PROVIDERS: CloudProvider[] = [
{
name: 'OpenAI',
envKey: 'OPENAI_API_KEY',
storageKey: 'openjarvis-openai-key',
models: [
{ id: 'gpt-4o', desc: 'GPT-4o — fast, multimodal' },
{ id: 'gpt-4o-mini', desc: 'GPT-4o Mini — cheap, fast' },
@@ -41,7 +47,6 @@ const CLOUD_PROVIDERS: CloudProvider[] = [
{
name: 'Anthropic',
envKey: 'ANTHROPIC_API_KEY',
storageKey: 'openjarvis-anthropic-key',
models: [
{ id: 'claude-sonnet-4-6', desc: 'Claude Sonnet 4.6 — balanced' },
{ id: 'claude-opus-4-6', desc: 'Claude Opus 4.6 — most capable' },
@@ -51,7 +56,6 @@ const CLOUD_PROVIDERS: CloudProvider[] = [
{
name: 'Google',
envKey: 'GEMINI_API_KEY',
storageKey: 'openjarvis-gemini-key',
models: [
{ id: 'gemini-2.5-pro', desc: 'Gemini 2.5 Pro — flagship' },
{ id: 'gemini-2.5-flash', desc: 'Gemini 2.5 Flash — fast' },
@@ -61,7 +65,6 @@ const CLOUD_PROVIDERS: CloudProvider[] = [
{
name: 'OpenRouter',
envKey: 'OPENROUTER_API_KEY',
storageKey: 'openjarvis-openrouter-key',
models: [
{ id: 'openrouter/auto', desc: 'Auto — best model for the task' },
{ id: 'openrouter/anthropic/claude-sonnet-4', desc: 'Claude Sonnet 4 via OpenRouter' },
@@ -70,16 +73,6 @@ const CLOUD_PROVIDERS: CloudProvider[] = [
},
];
function getStoredKey(storageKey: string): string {
try { return localStorage.getItem(storageKey) || ''; } catch { return ''; }
}
function setStoredKey(storageKey: string, value: string): void {
try {
if (value) localStorage.setItem(storageKey, value);
else localStorage.removeItem(storageKey);
} catch {}
}
type Tab = 'installed' | 'catalogue' | 'cloud';
export function CommandPalette() {
@@ -92,11 +85,10 @@ export function CommandPalette() {
const [deleting, setDeleting] = useState<string | null>(null);
const [customModel, setCustomModel] = useState('');
const [showKeys, setShowKeys] = useState<Record<string, boolean>>({});
const [apiKeys, setApiKeys] = useState<Record<string, string>>(() => {
const keys: Record<string, string> = {};
for (const p of CLOUD_PROVIDERS) keys[p.storageKey] = getStoredKey(p.storageKey);
return keys;
});
const [apiKeys, setApiKeys] = useState<Record<string, string>>({});
const [cloudKeyStatus, setCloudKeyStatus] = useState<Record<string, boolean>>({});
const [cloudKeyError, setCloudKeyError] = useState<string | null>(null);
const [savingKey, setSavingKey] = useState<string | null>(null);
const inputRef = useRef<HTMLInputElement>(null);
const models = useAppStore((s) => s.models);
@@ -106,6 +98,20 @@ export function CommandPalette() {
const setCommandPaletteOpen = useAppStore((s) => s.setCommandPaletteOpen);
const installedIds = new Set(models.map((m) => m.id));
const desktopKeyStorage = isTauri();
const refreshCloudKeyStatus = useCallback(async () => {
if (!desktopKeyStorage) {
setCloudKeyStatus({});
return;
}
try {
setCloudKeyStatus(await getCloudKeyStatus());
setCloudKeyError(null);
} catch (e: any) {
setCloudKeyError(e?.message || 'Failed to read cloud key status');
}
}, [desktopKeyStorage]);
const filtered = tab === 'installed'
? (query
@@ -122,6 +128,10 @@ export function CommandPalette() {
inputRef.current?.focus();
}, []);
useEffect(() => {
void refreshCloudKeyStatus();
}, [refreshCloudKeyStatus]);
useEffect(() => {
setSelectedIdx(0);
}, [query, tab]);
@@ -210,24 +220,29 @@ export function CommandPalette() {
};
const handleSaveKey = async (provider: CloudProvider, value: string) => {
setStoredKey(provider.storageKey, value);
setApiKeys((prev) => ({ ...prev, [provider.storageKey]: value }));
const keyValue = value.trim();
setSavingKey(provider.envKey);
setCloudKeyError(null);
// Also save to Tauri backend so the server process picks up the key
if (isTauri()) {
try {
const { invoke } = await import('@tauri-apps/api/core');
await invoke('save_cloud_key', { keyName: provider.envKey, keyValue: value });
} catch {}
try {
await saveCloudKey(provider.envKey, keyValue);
setApiKeys((prev) => ({ ...prev, [provider.envKey]: '' }));
await refreshCloudKeyStatus();
useAppStore.getState().addLogEntry({
timestamp: Date.now(), level: 'info', category: 'model',
message: `${provider.name} API key ${keyValue ? 'saved' : 'removed'}. Refreshing model list...`,
});
await refreshModels();
} catch (e: any) {
setCloudKeyError(e?.message || `Failed to save ${provider.name} API key`);
} finally {
setSavingKey(null);
}
};
useAppStore.getState().addLogEntry({
timestamp: Date.now(), level: 'info', category: 'model',
message: `${provider.name} API key ${value ? 'saved' : 'removed'}. Refreshing model list…`,
});
// Refresh the model list so cloud models appear immediately.
await refreshModels();
const handleKeyBlur = (provider: CloudProvider) => {
const draft = apiKeys[provider.envKey] || '';
if (draft.trim()) void handleSaveKey(provider, draft);
};
const handleKeyDown = (e: React.KeyboardEvent) => {
@@ -323,6 +338,11 @@ export function CommandPalette() {
<Check size={12} /> Downloaded {pullSuccess} successfully
</div>
)}
{tab === 'cloud' && cloudKeyError && (
<div className="px-4 py-2 text-xs" style={{ color: 'var(--color-error)', background: 'rgba(220,38,38,0.05)' }}>
{cloudKeyError}
</div>
)}
{/* Results */}
<div className="max-h-[400px] overflow-y-auto py-2">
@@ -431,13 +451,17 @@ export function CommandPalette() {
/* ── Cloud Models tab ── */
<div className="px-4 py-2">
<div className="text-[11px] mb-3" style={{ color: 'var(--color-text-tertiary)' }}>
Add your API keys to use cloud models. Keys are stored locally on your device only.
{desktopKeyStorage
? 'Add your API keys to use cloud models. Keys are stored in secure desktop storage.'
: 'Configure cloud provider keys in the server environment to use cloud models.'}
</div>
{CLOUD_PROVIDERS.map((provider) => {
const key = apiKeys[provider.storageKey] || '';
const hasKey = !!key;
const isVisible = showKeys[provider.storageKey];
const key = apiKeys[provider.envKey] || '';
const hasSavedKey = !!cloudKeyStatus[provider.envKey];
const hasKey = hasSavedKey || !!key.trim();
const isVisible = showKeys[provider.envKey];
const isSaving = savingKey === provider.envKey;
return (
<div key={provider.name} className="mb-4">
@@ -458,26 +482,28 @@ export function CommandPalette() {
<input
type={isVisible ? 'text' : 'password'}
value={key}
onChange={(e) => setApiKeys((prev) => ({ ...prev, [provider.storageKey]: e.target.value }))}
onBlur={() => handleSaveKey(provider, apiKeys[provider.storageKey] || '')}
placeholder={`${provider.envKey}`}
onChange={(e) => setApiKeys((prev) => ({ ...prev, [provider.envKey]: e.target.value }))}
onBlur={() => handleKeyBlur(provider)}
placeholder={hasSavedKey ? 'Saved in secure storage' : provider.envKey}
disabled={!desktopKeyStorage || isSaving}
className="flex-1 text-xs px-2 py-1.5 bg-transparent outline-none font-mono"
style={{ color: 'var(--color-text)' }}
/>
<button
onClick={() => setShowKeys((prev) => ({ ...prev, [provider.storageKey]: !prev[provider.storageKey] }))}
onClick={() => setShowKeys((prev) => ({ ...prev, [provider.envKey]: !prev[provider.envKey] }))}
className="px-2 cursor-pointer" style={{ color: 'var(--color-text-tertiary)' }}
>
{isVisible ? <EyeOff size={12} /> : <Eye size={12} />}
</button>
</div>
{hasKey && (
{hasSavedKey && (
<button
onClick={() => handleSaveKey(provider, '')}
disabled={isSaving}
className="px-2 py-1 rounded-lg text-[10px] cursor-pointer"
style={{ color: 'var(--color-error)', border: '1px solid var(--color-error)' }}
style={{ color: 'var(--color-error)', border: '1px solid var(--color-error)', opacity: isSaving ? 0.5 : 1 }}
>
Remove
{isSaving ? 'Saving' : 'Remove'}
</button>
)}
</div>
@@ -1,6 +1,7 @@
import { useState, useEffect, useCallback } from 'react';
import type React from 'react';
import { invoke } from '@tauri-apps/api/core';
import { LEADERBOARD_ENABLED, SUPABASE_ANON_KEY, SUPABASE_URL } from '../../lib/supabase';
// ---------------------------------------------------------------------------
// Types
@@ -279,9 +280,6 @@ function getOrCreateAnonId(): string {
return id;
}
const SUPABASE_URL = 'https://mtbtgpwzrbostweaanpr.supabase.co';
const SUPABASE_KEY = 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6Im10YnRncHd6cmJvc3R3ZWFhbnByIiwicm9sZSI6ImFub24iLCJpYXQiOjE3NzMxODk0OTQsImV4cCI6MjA4ODc2NTQ5NH0._xMlqCfljtXpwPj54H-ghxfLFO-jiq4W2WhpU8vVL1c';
const REFRESH_INTERVAL_MS = 5000;
export function SavingsDashboard({ apiUrl }: { apiUrl: string }) {
@@ -318,15 +316,16 @@ export function SavingsDashboard({ apiUrl }: { apiUrl: string }) {
return () => clearInterval(timer);
}, [fetchData]);
// Share savings to Supabase when opted in and data changes
// Share savings to Supabase when opted in and data changes. Skipped entirely
// when no anon key was built in (leaderboard disabled).
useEffect(() => {
if (!optInEnabled || !displayName || !data) return;
if (!LEADERBOARD_ENABLED || !optInEnabled || !displayName || !data) return;
const dollarSavings = data.per_provider.reduce((s, p) => s + p.total_cost, 0);
const energySaved = data.per_provider.reduce((s, p) => s + (p.energy_wh || 0), 0);
const flopsSaved = data.per_provider.reduce((s, p) => s + (p.flops || 0), 0);
invoke('submit_savings', {
supabaseUrl: SUPABASE_URL,
supabaseKey: SUPABASE_KEY,
supabaseKey: SUPABASE_ANON_KEY,
payload: {
anon_id: anonId,
display_name: displayName,
+4 -1
View File
@@ -1,4 +1,4 @@
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
// Regression for #266: the frontend must send the local API key as a Bearer
// token on /v1 + /api requests, or `jarvis serve` with a key configured 401s
@@ -26,11 +26,14 @@ class MemoryStorage {
}
beforeEach(() => {
vi.resetModules();
vi.stubEnv('VITE_SUPABASE_ANON_KEY', 'test-anon-key');
(globalThis as unknown as { localStorage: MemoryStorage }).localStorage =
new MemoryStorage();
});
afterEach(() => {
vi.unstubAllEnvs();
(globalThis as unknown as { localStorage?: MemoryStorage }).localStorage =
undefined;
});
+27 -4
View File
@@ -1,12 +1,10 @@
import type { ModelInfo, SavingsData, ServerInfo } from '../types';
import { SUPABASE_ANON_KEY, SUPABASE_URL } from './supabase';
// ---------------------------------------------------------------------------
// Supabase config — safe to embed (RLS protects writes)
// Supabase config
// ---------------------------------------------------------------------------
const SUPABASE_URL = import.meta.env.VITE_SUPABASE_URL || 'https://mtbtgpwzrbostweaanpr.supabase.co';
const SUPABASE_ANON_KEY = import.meta.env.VITE_SUPABASE_ANON_KEY || 'eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJzdXBhYmFzZSIsInJlZiI6Im10YnRncHd6cmJvc3R3ZWFhbnByIiwicm9sZSI6ImFub24iLCJpYXQiOjE3NzMxODk0OTQsImV4cCI6MjA4ODc2NTQ5NH0._xMlqCfljtXpwPj54H-ghxfLFO-jiq4W2WhpU8vVL1c';
declare global {
interface Window {
__TAURI_INTERNALS__?: unknown;
@@ -15,6 +13,31 @@ declare global {
export const isTauri = () => typeof window !== 'undefined' && !!window.__TAURI_INTERNALS__;
export type CloudKeyStatus = Record<string, boolean>;
export async function getCloudKeyStatus(): Promise<CloudKeyStatus> {
if (!isTauri()) return {};
try {
const { invoke } = await import('@tauri-apps/api/core');
const rows = await invoke<Array<{ key: string; set: boolean }>>('get_cloud_key_status');
return Object.fromEntries(rows.map((row) => [row.key, row.set]));
} catch (e: any) {
throw new Error(e?.message ?? e ?? 'Failed to read cloud key status');
}
}
export async function saveCloudKey(keyName: string, keyValue: string): Promise<void> {
if (!isTauri()) {
throw new Error('Cloud API keys can be saved in the desktop app only.');
}
try {
const { invoke } = await import('@tauri-apps/api/core');
await invoke('save_cloud_key', { keyName, keyValue });
} catch (e: any) {
throw new Error(e?.message ?? e ?? 'Failed to save cloud key');
}
}
// Cached API base URL fetched from the Tauri backend at startup.
// This avoids hardcoding the port — the Rust backend is the single
// source of truth for JARVIS_PORT.
+11
View File
@@ -0,0 +1,11 @@
export const SUPABASE_URL =
import.meta.env.VITE_SUPABASE_URL || 'https://mtbtgpwzrbostweaanpr.supabase.co';
// The Supabase anon key is optional at build time. When it is unset the public
// savings leaderboard is disabled rather than failing the build — this keeps
// the `openjarvis` package and desktop app buildable without coupling
// publishability to a leaderboard credential. Set VITE_SUPABASE_ANON_KEY at
// build time (from a repo secret) to enable the leaderboard.
export const SUPABASE_ANON_KEY = import.meta.env.VITE_SUPABASE_ANON_KEY ?? '';
export const LEADERBOARD_ENABLED = SUPABASE_ANON_KEY.length > 0;
+115 -24
View File
@@ -19,9 +19,21 @@ import {
RefreshCw,
} from 'lucide-react';
import { useAppStore, type ThemeMode } from '../lib/store';
import { checkHealth, fetchSpeechHealth, getMemoryStats, getInferenceSource, setInferenceSource, type InferenceSource } from '../lib/api';
import {
checkHealth,
fetchSpeechHealth,
getMemoryStats,
getInferenceSource,
setInferenceSource,
getCloudKeyStatus,
saveCloudKey,
isTauri,
type InferenceSource,
} from '../lib/api';
import { isAutoUpdateDisabled, setAutoUpdateDisabled } from '../components/Desktop/UpdateChecker';
const CLOUD_KEY_STATUS_CHANGED = 'openjarvis-cloud-key-status-changed';
function OllamaModelList() {
const [models, setModels] = useState<Array<{ name: string; size: number }>>([]);
useEffect(() => {
@@ -44,32 +56,111 @@ function OllamaModelList() {
);
}
function ApiKeyInput({ storageKey, placeholder }: { storageKey: string; placeholder: string }) {
const [value, setValue] = useState(() => {
try { return localStorage.getItem(storageKey) || ''; } catch { return ''; }
});
function ApiKeyInput({ keyName, placeholder }: { keyName: string; placeholder: string }) {
const [value, setValue] = useState('');
const [saved, setSaved] = useState(false);
const save = (v: string) => {
setValue(v);
try { if (v) localStorage.setItem(storageKey, v); else localStorage.removeItem(storageKey); } catch {}
setSaved(true);
setTimeout(() => setSaved(false), 2000);
const [hasKey, setHasKey] = useState(false);
const [error, setError] = useState('');
const desktopKeyStorage = isTauri();
const refresh = useCallback(async () => {
if (!desktopKeyStorage) {
setHasKey(false);
return;
}
try {
const status = await getCloudKeyStatus();
setHasKey(!!status[keyName]);
} catch {
setHasKey(false);
}
}, [desktopKeyStorage, keyName]);
useEffect(() => {
void refresh();
window.addEventListener(CLOUD_KEY_STATUS_CHANGED, refresh);
return () => window.removeEventListener(CLOUD_KEY_STATUS_CHANGED, refresh);
}, [refresh]);
const save = async (v: string) => {
const next = v.trim();
if (!next) return;
setError('');
try {
await saveCloudKey(keyName, next);
setValue('');
setHasKey(true);
setSaved(true);
window.dispatchEvent(new Event(CLOUD_KEY_STATUS_CHANGED));
setTimeout(() => setSaved(false), 2000);
} catch (e: any) {
setError(e?.message || 'Failed to save API key');
}
};
const remove = async () => {
setError('');
try {
await saveCloudKey(keyName, '');
setValue('');
setHasKey(false);
setSaved(true);
window.dispatchEvent(new Event(CLOUD_KEY_STATUS_CHANGED));
setTimeout(() => setSaved(false), 2000);
} catch (e: any) {
setError(e?.message || 'Failed to remove API key');
}
};
return (
<div className="flex items-center gap-2">
<input type="password" value={value} onChange={e => save(e.target.value)} placeholder={placeholder}
<input
type="password"
value={value}
onChange={e => setValue(e.target.value)}
onBlur={() => { if (value.trim()) void save(value); }}
placeholder={hasKey ? 'Saved in secure storage' : placeholder}
disabled={!desktopKeyStorage}
className="w-48 px-2 py-1 rounded text-xs"
style={{ background: 'var(--color-bg)', border: '1px solid var(--color-border)', color: 'var(--color-text)' }} />
{hasKey && (
<button
onClick={() => void remove()}
className="px-2 py-1 rounded text-[10px] cursor-pointer"
style={{ color: 'var(--color-error)', border: '1px solid var(--color-error)' }}
>
Remove
</button>
)}
{saved && <span className="text-[10px]" style={{ color: 'var(--color-success)' }}>Saved</span>}
{error && <span className="text-[10px]" style={{ color: 'var(--color-error)' }}>{error}</span>}
</div>
);
}
function CloudProviderStatus({ label, storageKey }: { label: string; storageKey: string }) {
function CloudProviderStatus({ label, keyName }: { label: string; keyName: string }) {
const [hasKey, setHasKey] = useState(false);
const desktopKeyStorage = isTauri();
const refresh = useCallback(async () => {
if (!desktopKeyStorage) {
setHasKey(false);
return;
}
try {
const status = await getCloudKeyStatus();
setHasKey(!!status[keyName]);
} catch {
setHasKey(false);
}
}, [desktopKeyStorage, keyName]);
useEffect(() => {
try { setHasKey(!!localStorage.getItem(storageKey)); } catch { setHasKey(false); }
}, [storageKey]);
void refresh();
window.addEventListener(CLOUD_KEY_STATUS_CHANGED, refresh);
return () => window.removeEventListener(CLOUD_KEY_STATUS_CHANGED, refresh);
}, [refresh]);
return (
<span className="flex items-center gap-1 text-xs" style={{ color: 'var(--color-text-secondary)' }}>
<span style={{
@@ -424,10 +515,10 @@ export function SettingsPage() {
</div>
<SettingRow label="Cloud providers" description="Green dot means API key is configured">
<div className="flex flex-wrap gap-3">
<CloudProviderStatus label="OpenAI" storageKey="openjarvis-openai-key" />
<CloudProviderStatus label="Anthropic" storageKey="openjarvis-anthropic-key" />
<CloudProviderStatus label="Google" storageKey="openjarvis-gemini-key" />
<CloudProviderStatus label="OpenRouter" storageKey="openjarvis-openrouter-key" />
<CloudProviderStatus label="OpenAI" keyName="OPENAI_API_KEY" />
<CloudProviderStatus label="Anthropic" keyName="ANTHROPIC_API_KEY" />
<CloudProviderStatus label="Google" keyName="GEMINI_API_KEY" />
<CloudProviderStatus label="OpenRouter" keyName="OPENROUTER_API_KEY" />
</div>
</SettingRow>
</Section>
@@ -435,23 +526,23 @@ export function SettingsPage() {
{/* API Keys */}
<Section title="API Keys">
<SettingRow label="OpenAI" description="GPT-4, GPT-3.5, etc.">
<ApiKeyInput storageKey="openjarvis-openai-key" placeholder="sk-..." />
<ApiKeyInput keyName="OPENAI_API_KEY" placeholder="sk-..." />
</SettingRow>
<SettingRow label="Anthropic" description="Claude models">
<ApiKeyInput storageKey="openjarvis-anthropic-key" placeholder="sk-ant-..." />
<ApiKeyInput keyName="ANTHROPIC_API_KEY" placeholder="sk-ant-..." />
</SettingRow>
<SettingRow label="Google" description="Gemini models">
<ApiKeyInput storageKey="openjarvis-gemini-key" placeholder="AI..." />
<ApiKeyInput keyName="GEMINI_API_KEY" placeholder="AI..." />
</SettingRow>
<SettingRow label="OpenRouter" description="Multi-provider routing">
<ApiKeyInput storageKey="openjarvis-openrouter-key" placeholder="sk-or-..." />
<ApiKeyInput keyName="OPENROUTER_API_KEY" placeholder="sk-or-..." />
</SettingRow>
</Section>
{/* Tools */}
<Section title="Tools">
<SettingRow label="Web Search" description="SerpAPI or Tavily key for web search tool">
<ApiKeyInput storageKey="openjarvis-search-key" placeholder="API key..." />
<SettingRow label="Web Search" description="Tavily key for web search tool">
<ApiKeyInput keyName="TAVILY_API_KEY" placeholder="tvly-..." />
</SettingRow>
</Section>
+3 -1
View File
@@ -1,7 +1,9 @@
/// <reference types="vite/client" />
interface ImportMetaEnv {
readonly VITE_API_URL: string;
readonly VITE_API_URL?: string;
readonly VITE_SUPABASE_URL?: string;
readonly VITE_SUPABASE_ANON_KEY?: string;
}
interface ImportMeta {
+3
View File
@@ -4,6 +4,9 @@ import react from '@vitejs/plugin-react';
import tailwindcss from '@tailwindcss/vite';
import { VitePWA } from 'vite-plugin-pwa';
// VITE_SUPABASE_ANON_KEY is intentionally NOT required here: a missing key
// disables the savings leaderboard at runtime (see src/lib/supabase.ts) rather
// than failing the build, so the package/app stays publishable without it.
export default defineConfig({
resolve: {
alias: {
+1
View File
@@ -127,6 +127,7 @@ markdown_extensions:
- pymdownx.tilde
extra_javascript:
- javascripts/leaderboard-config.js
- javascripts/leaderboard.js
- https://cdn.jsdelivr.net/npm/@docsearch/js@3
- javascripts/docsearch-init.js
+5 -5
View File
@@ -19,6 +19,7 @@ from openjarvis.agents.prompt_loader import (
from openjarvis.core.events import EventBus
from openjarvis.core.registry import AgentRegistry
from openjarvis.core.types import Message, Role, ToolCall, ToolResult
from openjarvis.engine._base import estimate_prompt_tokens
from openjarvis.engine._stubs import InferenceEngine
from openjarvis.tools._stubs import BaseTool, build_tool_descriptions
@@ -116,8 +117,7 @@ class NativeOpenHandsAgent(ToolUsingAgent):
max_prompt_tokens: int = 3000,
) -> list[Message]:
"""Truncate messages if estimated token count exceeds limit."""
total_chars = sum(len(m.content) for m in messages)
estimated_tokens = total_chars // 4
estimated_tokens = estimate_prompt_tokens(messages)
if estimated_tokens <= max_prompt_tokens:
return messages
# Find the last user message and truncate its content
@@ -125,7 +125,7 @@ class NativeOpenHandsAgent(ToolUsingAgent):
if messages[i].role == Role.USER:
excess_tokens = estimated_tokens - max_prompt_tokens
excess_chars = excess_tokens * 4
original = messages[i].content
original = messages[i].content or ""
if len(original) > excess_chars + 200:
truncated = original[: len(original) - excess_chars]
messages[i] = Message(
@@ -258,7 +258,7 @@ class NativeOpenHandsAgent(ToolUsingAgent):
# still emitted before re-raising.
self._emit_turn_end(turns=1, error=True)
raise
content = self._strip_think_tags(result.get("content", ""))
content = self._strip_think_tags(result.get("content") or "")
usage = result.get("usage", {})
self._emit_turn_end(turns=1)
return AgentResult(
@@ -315,7 +315,7 @@ class NativeOpenHandsAgent(ToolUsingAgent):
for k in total_usage:
total_usage[k] += usage.get(k, 0)
content = result.get("content", "")
content = result.get("content") or ""
# Strip think tags so they don't interfere with parsing
content = self._strip_think_tags(content)
last_content = content
+11 -6
View File
@@ -11,7 +11,9 @@ from rich.markdown import Markdown
from openjarvis.cli._tool_names import resolve_tool_names
from openjarvis.core.config import load_config
from openjarvis.core.events import EventBus
from openjarvis.core.types import Message, Role
from openjarvis.memory import publish_completed_exchange
def _read_input(prompt: str = "You> ") -> Optional[str]:
@@ -57,6 +59,7 @@ def chat(
console = Console(stderr=True)
config = load_config()
bus = EventBus(record_history=False)
import dataclasses as _dc
@@ -97,12 +100,11 @@ def chat(
if agent_key and agent_key != "none":
try:
import openjarvis.agents # noqa: F401 — trigger registration
from openjarvis.core.events import EventBus
from openjarvis.core.registry import AgentRegistry
if AgentRegistry.contains(agent_key):
agent_cls = AgentRegistry.get(agent_key)
kwargs: dict = {"bus": EventBus()}
kwargs: dict = {"bus": bus}
if getattr(agent_cls, "accepts_tools", False):
tool_names_list = resolve_tool_names(
@@ -184,7 +186,7 @@ def chat(
try:
from openjarvis.memory import build_memory_service
memory_service = build_memory_service(config, engine, model)
memory_service = build_memory_service(config, engine, model, event_bus=bus)
if memory_service is not None:
memory_service.start()
console.print("[dim] Memory: active[/dim]")
@@ -280,9 +282,12 @@ def chat(
console.print(Markdown(content))
console.print()
# Hand the exchange to the memory service (non-blocking).
if memory_service is not None:
memory_service.submit(user_input, content)
publish_completed_exchange(
bus,
user_input,
content,
source="cli.chat",
)
except KeyboardInterrupt:
console.print("\n[dim]Generation interrupted.[/dim]")
except Exception as exc:
+6 -1
View File
@@ -498,7 +498,12 @@ def serve(
try:
from openjarvis.memory import build_memory_service
memory_service = build_memory_service(config, engine, model_name)
memory_service = build_memory_service(
config,
engine,
model_name,
event_bus=bus,
)
if memory_service is not None:
memory_service.start()
console.print(" Memory svc: [cyan]active[/cyan]")
+3 -1
View File
@@ -932,7 +932,9 @@ class StorageConfig:
backend: str = "local" # fact-store backend ("local" = on-disk JSONL)
extraction_model: str = "" # model for fact extraction ("" = active model)
max_facts: int = 1000 # cap on stored facts (oldest evicted past the cap)
facts_path: str = str(DEFAULT_CONFIG_DIR / "memory_facts.jsonl")
facts_path: str = field(
default_factory=lambda: str(get_config_dir() / "memory_facts.jsonl")
)
# Backward-compatibility alias
+1
View File
@@ -27,6 +27,7 @@ class EventType(str, Enum):
TOOL_CALL_END = "tool_call_end"
MEMORY_STORE = "memory_store"
MEMORY_RETRIEVE = "memory_retrieve"
CHAT_EXCHANGE_COMPLETED = "chat_exchange_completed"
AGENT_TURN_START = "agent_turn_start"
AGENT_TURN_END = "agent_turn_end"
TELEMETRY_RECORD = "telemetry_record"
+6
View File
@@ -11,6 +11,7 @@ from typing import TYPE_CHECKING, Any, Callable, Dict, Generic, Tuple, Type, Typ
if TYPE_CHECKING:
from openjarvis.agents._stubs import BaseAgent
from openjarvis.engine._stubs import InferenceEngine
from openjarvis.memory.store import FactStore
from openjarvis.tools.storage._stubs import MemoryBackend
T = TypeVar("T")
@@ -109,6 +110,10 @@ class MemoryRegistry(RegistryBase[Type["MemoryBackend"]]):
"""Registry for memory / retrieval backends."""
class FactStoreRegistry(RegistryBase[Type["FactStore"]]):
"""Registry for automatic-memory fact store backends."""
class AgentRegistry(RegistryBase[Type["BaseAgent"]]):
"""Registry for agent implementations."""
@@ -170,6 +175,7 @@ __all__ = [
"CompressionRegistry",
"ConnectorRegistry",
"EngineRegistry",
"FactStoreRegistry",
"LearningRegistry",
"MemoryRegistry",
"MinerRegistry",
+1 -1
View File
@@ -55,7 +55,7 @@ def estimate_prompt_tokens(messages: Sequence[Message]) -> int:
Uses ~4 characters per token (standard BPE average for English) plus
a small per-message overhead for role markers and separators.
"""
total_chars = sum(len(m.content) for m in messages)
total_chars = sum(len(m.content or "") for m in messages)
# ~4 tokens overhead per message for role markers / separators
overhead = len(messages) * 4
return max(1, total_chars // 4 + overhead)
+6 -1
View File
@@ -9,7 +9,11 @@ and configured via the ``[memory]`` section of ``config.toml``.
from __future__ import annotations
from openjarvis.memory.extractor import FactExtractor
from openjarvis.memory.service import MemoryService, build_memory_service
from openjarvis.memory.service import (
MemoryService,
build_memory_service,
publish_completed_exchange,
)
from openjarvis.memory.store import (
Fact,
FactStore,
@@ -25,4 +29,5 @@ __all__ = [
"MemoryService",
"build_memory_service",
"create_fact_store",
"publish_completed_exchange",
]
+60 -3
View File
@@ -20,6 +20,7 @@ import queue
import threading
from typing import Any, List, Optional
from openjarvis.core.events import Event, EventBus, EventType
from openjarvis.memory.extractor import FactExtractor
from openjarvis.memory.store import Fact, FactStore, create_fact_store
@@ -37,10 +38,13 @@ class MemoryService:
store: FactStore,
extractor: FactExtractor,
*,
event_bus: EventBus | None = None,
max_queue: int = 256,
) -> None:
self._store = store
self._extractor = extractor
self._event_bus = event_bus
self._subscribed = False
self._queue: "queue.Queue[Any]" = queue.Queue(maxsize=max(1, max_queue))
self._thread: Optional[threading.Thread] = None
self._running = threading.Event()
@@ -52,6 +56,7 @@ class MemoryService:
if self._running.is_set():
return
self._running.set()
self._subscribe_events()
self._thread = threading.Thread(
target=self._loop,
name="memory-service",
@@ -73,6 +78,7 @@ class MemoryService:
if thread is not None:
thread.join(timeout=timeout)
self._thread = None
self._unsubscribe_events()
logger.debug("Memory service stopped")
@property
@@ -99,6 +105,34 @@ class MemoryService:
logger.debug("Memory service queue full; dropping exchange")
return False
def _subscribe_events(self) -> None:
"""Subscribe to lifecycle events that feed automatic memory."""
if self._event_bus is None or self._subscribed:
return
self._event_bus.subscribe(
EventType.CHAT_EXCHANGE_COMPLETED,
self._on_completed_exchange,
)
self._subscribed = True
def _unsubscribe_events(self) -> None:
"""Unsubscribe from lifecycle events (idempotent)."""
if self._event_bus is None or not self._subscribed:
return
self._event_bus.unsubscribe(
EventType.CHAT_EXCHANGE_COMPLETED,
self._on_completed_exchange,
)
self._subscribed = False
def _on_completed_exchange(self, event: Event) -> None:
"""Queue a completed chat exchange published on the event bus."""
data = event.data or {}
self.submit(
str(data.get("user_text", "") or ""),
str(data.get("assistant_text", "") or ""),
)
# -- worker -------------------------------------------------------------
def _loop(self) -> None:
@@ -145,6 +179,8 @@ def build_memory_service(
config: Any,
engine: Any,
default_model: str = "",
*,
event_bus: EventBus | None = None,
) -> Optional[MemoryService]:
"""Build a :class:`MemoryService` from config, or ``None`` if disabled.
@@ -170,11 +206,32 @@ def build_memory_service(
store = create_fact_store(
getattr(mem, "backend", "local"),
path=getattr(mem, "facts_path", "~/.openjarvis/memory_facts.jsonl"),
path=getattr(mem, "facts_path", None),
max_facts=getattr(mem, "max_facts", 1000),
)
extractor = FactExtractor(engine, model)
return MemoryService(store, extractor)
return MemoryService(store, extractor, event_bus=event_bus)
__all__ = ["MemoryService", "build_memory_service"]
def publish_completed_exchange(
bus: EventBus | None,
user_text: str,
assistant_text: str = "",
*,
source: str = "",
) -> bool:
"""Publish a completed chat exchange for lifecycle subscribers."""
if bus is None or not user_text or not user_text.strip():
return False
bus.publish(
EventType.CHAT_EXCHANGE_COMPLETED,
{
"user_text": user_text,
"assistant_text": assistant_text or "",
"source": source,
},
)
return True
__all__ = ["MemoryService", "build_memory_service", "publish_completed_exchange"]
+37 -8
View File
@@ -18,6 +18,14 @@ from dataclasses import asdict, dataclass
from pathlib import Path
from typing import Iterable, List
from openjarvis.core.paths import get_config_dir
from openjarvis.core.registry import FactStoreRegistry
def _default_fact_path() -> Path:
"""Return the env-aware default JSONL path for automatic memory facts."""
return get_config_dir() / "memory_facts.jsonl"
@dataclass(slots=True)
class Fact:
@@ -56,6 +64,7 @@ class FactStore(ABC):
"""Return the number of stored facts."""
@FactStoreRegistry.register("local")
class LocalFactStore(FactStore):
"""Append-only JSONL fact store on the local filesystem.
@@ -67,11 +76,13 @@ class LocalFactStore(FactStore):
def __init__(
self,
path: str | Path = "~/.openjarvis/memory_facts.jsonl",
path: str | Path | None = None,
*,
max_facts: int = 1000,
) -> None:
self._path = Path(path).expanduser()
self._path = (
Path(path).expanduser() if path is not None else _default_fact_path()
)
self._max_facts = max(0, int(max_facts))
self._lock = threading.Lock()
self._facts: List[Fact] = self._load()
@@ -116,6 +127,10 @@ class LocalFactStore(FactStore):
tmp.write_text(payload, encoding="utf-8")
os.replace(tmp, self._path)
def _sync_from_disk_locked(self) -> None:
"""Refresh in-memory facts from disk while holding ``self._lock``."""
self._facts = self._load()
# -- FactStore API ------------------------------------------------------
def add(self, text: str, source: str = "") -> bool:
@@ -123,6 +138,7 @@ class LocalFactStore(FactStore):
if not text:
return False
with self._lock:
self._sync_from_disk_locked()
lowered = text.lower()
if any(f.text.lower() == lowered for f in self._facts):
return False # dedupe
@@ -135,10 +151,12 @@ class LocalFactStore(FactStore):
def list(self) -> List[Fact]:
with self._lock:
self._sync_from_disk_locked()
return list(self._facts)
def clear(self) -> int:
with self._lock:
self._sync_from_disk_locked()
removed = len(self._facts)
self._facts = []
if self._path.exists():
@@ -150,6 +168,7 @@ class LocalFactStore(FactStore):
def count(self) -> int:
with self._lock:
self._sync_from_disk_locked()
return len(self._facts)
@property
@@ -158,22 +177,32 @@ class LocalFactStore(FactStore):
return self._path
def _ensure_fact_store_backends_registered() -> None:
"""Restore built-in fact-store registrations if a test cleared registries."""
if not FactStoreRegistry.contains("local"):
FactStoreRegistry.register_value("local", LocalFactStore)
def create_fact_store(
backend: str = "local",
*,
path: str | Path = "~/.openjarvis/memory_facts.jsonl",
path: str | Path | None = None,
max_facts: int = 1000,
) -> FactStore:
"""Construct a fact store for the configured *backend*.
Only the ``"local"`` (on-disk JSONL) backend is supported today; the
factory exists so additional backends can be added without changing the
service or CLI wiring.
registry-backed constructor exists so additional backends can be added
without changing the service or CLI wiring.
"""
_ensure_fact_store_backends_registered()
key = (backend or "local").strip().lower()
if key == "local":
return LocalFactStore(path, max_facts=max_facts)
raise ValueError(f"Unknown memory backend '{backend}'. Supported backends: local")
if not FactStoreRegistry.contains(key):
supported = ", ".join(FactStoreRegistry.keys())
raise ValueError(
f"Unknown memory backend '{backend}'. Supported backends: {supported}"
)
return FactStoreRegistry.create(key, path, max_facts=max_facts)
__all__ = ["Fact", "FactStore", "LocalFactStore", "create_fact_store"]
+4 -4
View File
@@ -1,8 +1,8 @@
"""Direct cloud API router — bypasses the engine system entirely.
Reads API keys from ~/.openjarvis/cloud-keys.env at request time so
it works even when the server was started without cloud keys in its
environment. Uses httpx directly so no cloud SDK packages are required.
Reads API keys from the process environment, with a legacy
~/.openjarvis/cloud-keys.env fallback for non-desktop/manual setups. Uses
httpx directly so no cloud SDK packages are required.
"""
from __future__ import annotations
@@ -38,7 +38,7 @@ _LOCAL_HF_ORGS = (
def _load_keys() -> dict[str, str]:
"""Read cloud-keys.env from disk every call so live updates are picked up."""
"""Read available cloud keys every call so live updates are picked up."""
keys: dict[str, str] = {}
# File first, then fall back to process environment
if _CLOUD_ENV_FILE.exists():
+115 -17
View File
@@ -195,7 +195,13 @@ async def chat_completions(request_body: ChatCompletionRequest, request: Request
# from the engine for true real-time output.
if request_body.tools:
return await _handle_stream_tools(
engine, model, request_body, complexity_info, app_config=config
engine,
model,
request_body,
complexity_info,
app_config=config,
bus=getattr(request.app.state, "bus", None),
memory_service=getattr(request.app.state, "memory_service", None),
)
return await _handle_stream(
engine,
@@ -204,6 +210,8 @@ async def chat_completions(request_body: ChatCompletionRequest, request: Request
complexity_info,
trace_store=getattr(request.app.state, "trace_store", None),
app_config=config,
bus=getattr(request.app.state, "bus", None),
memory_service=getattr(request.app.state, "memory_service", None),
)
# Non-streaming: use agent if available, otherwise direct engine call.
@@ -247,20 +255,44 @@ async def chat_completions(request_body: ChatCompletionRequest, request: Request
getattr(request.app.state, "memory_service", None),
query_text_for_complexity,
response,
bus=getattr(request.app.state, "bus", None),
source="server.chat",
)
return response
def _remember_exchange(memory_service, user_text: str, response) -> None:
"""Submit a completed exchange to the memory service (non-blocking)."""
if memory_service is None or not user_text:
def _response_content(response) -> str:
"""Extract assistant text from an OpenAI-compatible response object."""
content = ""
choices = getattr(response, "choices", None)
if choices:
content = getattr(choices[0].message, "content", "") or ""
return content
def _record_completed_exchange(
memory_service,
user_text: str,
assistant_text: str,
*,
bus=None,
source: str = "server.chat",
) -> None:
"""Publish or submit a completed exchange without blocking a reply."""
if not user_text:
return
try:
content = ""
choices = getattr(response, "choices", None)
if choices:
content = getattr(choices[0].message, "content", "") or ""
memory_service.submit(user_text, content)
if bus is not None:
from openjarvis.memory import publish_completed_exchange
publish_completed_exchange(
bus,
user_text,
assistant_text,
source=source,
)
elif memory_service is not None:
memory_service.submit(user_text, assistant_text)
except Exception: # noqa: BLE001 — memory is best-effort, never fail a reply
logging.getLogger("openjarvis.server").debug(
"Memory submit failed",
@@ -268,6 +300,24 @@ def _remember_exchange(memory_service, user_text: str, response) -> None:
)
def _remember_exchange(
memory_service,
user_text: str,
response,
*,
bus=None,
source: str = "server.chat",
) -> None:
"""Record a completed non-streaming exchange."""
_record_completed_exchange(
memory_service,
user_text,
_response_content(response),
bus=bus,
source=source,
)
def _handle_direct(
engine,
model: str,
@@ -457,6 +507,8 @@ async def _handle_stream_tools(
complexity_info=None,
*,
app_config=None,
bus=None,
memory_service=None,
):
"""Stream a raw OpenAI-compat function-calling response via SSE.
@@ -477,8 +529,14 @@ async def _handle_stream_tools(
messages = _ensure_identity_prompt(messages, app_config)
chunk_id = f"chatcmpl-{uuid.uuid4().hex[:12]}"
use_cloud = is_cloud_model(model)
query_text = ""
for _m in reversed(req.messages):
if _m.role == "user" and _m.content:
query_text = _m.content
break
async def generate():
full_content = ""
# Send the role chunk first (OpenAI convention).
first_chunk = ChatCompletionChunk(
id=chunk_id,
@@ -497,6 +555,7 @@ async def _handle_stream_tools(
tools=req.tools,
):
if sc.content:
full_content += sc.content
content_chunk = ChatCompletionChunk(
id=chunk_id,
model=model,
@@ -553,6 +612,14 @@ async def _handle_stream_tools(
if complexity_info is not None:
finish_dict["complexity"] = complexity_info.model_dump()
yield f"data: {_json.dumps(finish_dict)}\n\n"
if full_content:
_record_completed_exchange(
memory_service,
query_text,
full_content,
bus=bus,
source="server.chat.stream",
)
yield "data: [DONE]\n\n"
return StreamingResponse(
@@ -570,6 +637,8 @@ async def _handle_stream(
*,
trace_store=None,
app_config=None,
bus=None,
memory_service=None,
):
"""Stream response using SSE format.
@@ -710,6 +779,15 @@ async def _handle_stream(
ended_at=time.time(),
)
if full_content:
_record_completed_exchange(
memory_service,
query_text,
full_content,
bus=bus,
source="server.chat.stream",
)
# Send finish chunk with usage data if available
import json as _json
@@ -848,14 +926,34 @@ async def reload_cloud_engine(request: Request):
"""
import os
# Re-read ~/.openjarvis/cloud-keys.env and update the running process env.
keys_path = get_config_dir() / "cloud-keys.env"
if keys_path.exists():
for raw_line in keys_path.read_text().splitlines():
line = raw_line.strip()
if line and not line.startswith("#") and "=" in line:
k, v = line.split("=", 1)
os.environ[k.strip()] = v.strip()
submitted_keys: dict[str, str] | None = None
try:
body = await request.json()
raw_keys = body.get("keys") if isinstance(body, dict) else None
if isinstance(raw_keys, dict):
submitted_keys = {
str(k): str(v)
for k, v in raw_keys.items()
if str(k).endswith("_API_KEY")
}
except Exception:
submitted_keys = None
if submitted_keys is not None:
for key, value in submitted_keys.items():
if value:
os.environ[key] = value
else:
os.environ.pop(key, None)
else:
# Compatibility fallback for non-desktop/manual configurations.
keys_path = get_config_dir() / "cloud-keys.env"
if keys_path.exists():
for raw_line in keys_path.read_text().splitlines():
line = raw_line.strip()
if line and not line.startswith("#") and "=" in line:
k, v = line.split("=", 1)
os.environ[k.strip()] = v.strip()
# Try to build a fresh CloudEngine.
try:
+46 -1
View File
@@ -8,7 +8,7 @@ from openjarvis.agents._stubs import AgentContext
from openjarvis.agents.native_openhands import NativeOpenHandsAgent
from openjarvis.core.events import EventBus, EventType
from openjarvis.core.registry import AgentRegistry
from openjarvis.core.types import Conversation, Message, Role, ToolResult
from openjarvis.core.types import Conversation, Message, Role, ToolCall, ToolResult
from openjarvis.tools._stubs import BaseTool, ToolSpec
# ---------------------------------------------------------------------------
@@ -118,6 +118,51 @@ class TestNativeOpenHandsRegistration:
class TestNativeOpenHandsAgent:
def test_truncate_handles_none_content_tool_call_turn(self):
"""Tool-call assistant turns may carry content=None."""
engine = MagicMock()
engine.engine_id = "mock"
agent = NativeOpenHandsAgent(engine, "test-model")
messages = [
Message(role=Role.USER, content="hi"),
Message(
role=Role.ASSISTANT,
content=None, # type: ignore[arg-type]
tool_calls=[ToolCall(id="call_1", name="calculator", arguments="{}")],
),
]
assert agent._truncate_if_needed(messages) == messages
def test_native_tool_call_with_none_content_does_not_crash(self):
"""Native tool-call responses may omit assistant text content."""
engine = MagicMock()
engine.engine_id = "mock"
engine.generate.side_effect = [
_engine_response(
None,
tool_calls=[
{
"id": "call_1",
"name": "calculator",
"arguments": '{"expression": "2+2"}',
}
],
),
_engine_response("The result is 4."),
]
agent = NativeOpenHandsAgent(
engine,
"test-model",
tools=[_CalculatorStub()],
)
result = agent.run("What is 2+2?")
assert result.content == "The result is 4."
assert result.turns == 2
assert [tr.content for tr in result.tool_results] == ["4"]
def test_simple_response(self):
"""No code -> direct answer."""
engine = MagicMock()
+29 -7
View File
@@ -15,6 +15,7 @@ from openjarvis.agents._stubs import (
)
from openjarvis.cli.chat_cmd import _read_input, chat
from openjarvis.core.config import JarvisConfig
from openjarvis.core.events import Event, EventBus, EventType
from openjarvis.core.registry import AgentRegistry, ToolRegistry
from openjarvis.core.types import ToolCall, ToolResult
from openjarvis.tools._stubs import BaseTool, ToolSpec
@@ -121,25 +122,45 @@ class TestChatAgents:
assert "failed" not in result.output.lower()
def test_memory_service_started_fed_and_stopped(self) -> None:
"""The REPL starts the memory service, submits each turn, and stops it."""
"""The REPL starts memory, publishes each turn, and stops it."""
class _SpyMemoryService:
def __init__(self) -> None:
def __init__(self, bus: EventBus) -> None:
self.bus = bus
self.started = False
self.stopped = False
self.submissions: list[tuple[str, str]] = []
def start(self) -> None:
self.started = True
self.bus.subscribe(
EventType.CHAT_EXCHANGE_COMPLETED,
self._on_completed_exchange,
)
def submit(self, user_text: str, assistant_text: str = "") -> bool:
self.submissions.append((user_text, assistant_text))
return True
def _on_completed_exchange(self, event: Event) -> None:
self.submissions.append(
(
event.data["user_text"],
event.data.get("assistant_text", ""),
)
)
def stop(self, timeout: float = 2.0) -> None:
self.stopped = True
self.bus.unsubscribe(
EventType.CHAT_EXCHANGE_COMPLETED,
self._on_completed_exchange,
)
spy: _SpyMemoryService | None = None
def _build_memory_service(*args, event_bus: EventBus | None = None, **kwargs):
nonlocal spy
assert event_bus is not None
spy = _SpyMemoryService(event_bus)
return spy
spy = _SpyMemoryService()
engine = MagicMock()
engine.engine_id = "mock"
engine.generate.return_value = {"content": "engine fallback"}
@@ -154,7 +175,7 @@ class TestChatAgents:
patch("openjarvis.intelligence.register_builtin_models"),
patch(
"openjarvis.memory.build_memory_service",
return_value=spy,
side_effect=_build_memory_service,
),
):
result = CliRunner().invoke(
@@ -164,6 +185,7 @@ class TestChatAgents:
)
assert result.exit_code == 0
assert spy is not None
assert spy.started is True
assert spy.stopped is True
assert spy.submissions == [("hello", "simple ok")]
+2
View File
@@ -18,6 +18,7 @@ from openjarvis.core.registry import (
CompressionRegistry,
ConnectorRegistry,
EngineRegistry,
FactStoreRegistry,
MemoryRegistry,
MinerRegistry,
ModelRegistry,
@@ -35,6 +36,7 @@ def _clean_registries() -> None:
ModelRegistry.clear()
EngineRegistry.clear()
MemoryRegistry.clear()
FactStoreRegistry.clear()
MinerRegistry.clear()
AgentRegistry.clear()
ToolRegistry.clear()
+3 -2
View File
@@ -48,6 +48,7 @@ class TestConfigPhase5:
with pytest.raises(KeyError):
ModelRegistry.get("iso-test")
def test_load_config_default(self):
cfg = load_config()
def test_load_config_default(self, tmp_path, monkeypatch):
monkeypatch.setenv("OPENJARVIS_HOME", str(tmp_path / "home"))
cfg = load_config(tmp_path / "missing-config.toml")
assert isinstance(cfg, JarvisConfig)
+209 -4
View File
@@ -1,7 +1,14 @@
"""Tests for Docker and deployment files."""
"""Tests for Docker and deployment files.
These are static file-content checks (no Docker daemon required) so they run in
the default CI lane. They guard the deployment hardening from #228 and its
sub-issues (#563 image pinning, #564 systemd hardening, #565 non-root, #566
secure Node install, #567 frozen lockfile installs).
"""
from __future__ import annotations
import re
from pathlib import Path
try:
@@ -11,6 +18,35 @@ except ModuleNotFoundError: # pragma: no cover - Python < 3.11
ROOT = Path(__file__).resolve().parent.parent.parent
DOCKER_DIR = ROOT / "deploy" / "docker"
SYSTEMD_DIR = ROOT / "deploy" / "systemd"
def _dockerfiles() -> list[Path]:
return sorted(DOCKER_DIR.glob("Dockerfile*"))
def _compose_files() -> list[Path]:
return sorted(DOCKER_DIR.glob("docker-compose*.yml"))
def _from_lines(content: str) -> list[str]:
return [
ln.strip()
for ln in content.splitlines()
if ln.strip().upper().startswith("FROM ")
]
def _image_lines(content: str) -> list[str]:
"""`image: ...` lines from a compose file, ignoring comments."""
out = []
for ln in content.splitlines():
stripped = ln.strip()
if stripped.startswith("#"):
continue
if stripped.startswith("image:"):
out.append(stripped)
return out
class TestDockerFiles:
@@ -37,10 +73,12 @@ class TestDockerFiles:
]
non_src_includes = [s for s in force_include if not s.startswith("src/")]
install_marker = 'uv pip install --system ".[server]"'
# The project itself is built by the final `--no-deps .` install (#567);
# the force-includes must be present before that step.
install_marker = "uv pip install --system --no-deps ."
wheel_dockerfiles = [
p
for p in sorted(DOCKER_DIR.glob("Dockerfile*"))
for p in _dockerfiles()
if install_marker in p.read_text() and "COPY src/ src/" in p.read_text()
]
# Sanity: we actually found the wheel-building Dockerfiles to guard.
@@ -85,5 +123,172 @@ class TestDockerFiles:
assert "jarvis:" in content
assert "ollama:" in content
def test_dockerfiles_build_native_rust_extension(self):
build_dockerfiles = [
"Dockerfile",
"Dockerfile.gpu",
"Dockerfile.gpu.rocm",
"Dockerfile.sandbox",
]
required_markers = [
"rustup toolchain install 1.88",
"maturin build --release",
"rust/crates/openjarvis-python/Cargo.toml",
"/tmp/openjarvis-rust-wheel/*.whl",
"import openjarvis_rust",
]
for name in build_dockerfiles:
content = (DOCKER_DIR / name).read_text()
for marker in required_markers:
assert marker in content, (
f"{name}: missing native build marker {marker!r}"
)
for name in ["Dockerfile", "Dockerfile.gpu", "Dockerfile.gpu.rocm"]:
content = (DOCKER_DIR / name).read_text()
assert "COPY rust/ rust/" in content, f"{name}: rust workspace not copied"
assert content.index("COPY rust/ rust/") < content.index(
"maturin build --release"
), f"{name}: rust workspace copied after native build"
def test_systemd_service_exists(self):
assert (ROOT / "deploy" / "systemd" / "openjarvis.service").is_file()
assert (SYSTEMD_DIR / "openjarvis.service").is_file()
class TestImagePinning:
"""#563 — base images and ollama pinned to fixed versions + digests."""
def test_no_floating_latest_tag_in_image_directives(self):
# `:latest` only acceptable inside comments (rationale text).
for path in _dockerfiles() + _compose_files():
for ln in path.read_text().splitlines():
code = ln.split("#", 1)[0]
assert ":latest" not in code, f"{path.name}: floating :latest in {ln!r}"
def test_every_from_pins_a_digest(self):
for path in _dockerfiles():
froms = _from_lines(path.read_text())
assert froms, f"{path.name}: no FROM lines found"
for ln in froms:
assert "@sha256:" in ln, (
f"{path.name}: FROM is not digest-pinned: {ln!r}"
)
def test_ollama_image_pinned_with_version_and_digest(self):
for path in _compose_files():
for ln in _image_lines(path.read_text()):
if "ollama/ollama" in ln:
assert "@sha256:" in ln, f"{path.name}: ollama not digest-pinned"
# A concrete version tag (digits) must accompany the digest.
assert re.search(r"ollama/ollama:\d", ln), (
f"{path.name}: ollama missing a version tag"
)
class TestNonRootUser:
"""#565 — GPU images (and the base image) drop root."""
NON_ROOT = ["Dockerfile", "Dockerfile.gpu", "Dockerfile.gpu.rocm"]
def test_creates_and_switches_to_non_root_user(self):
for name in self.NON_ROOT:
content = (DOCKER_DIR / name).read_text()
assert "useradd" in content, f"{name}: no useradd"
# A USER directive switching away from root must exist and not be root.
user_lines = [
ln.strip()
for ln in content.splitlines()
if ln.strip().upper().startswith("USER ")
]
assert user_lines, f"{name}: no USER directive"
assert all("root" not in ln for ln in user_lines), (
f"{name}: USER directive still root"
)
def test_user_directive_is_last_stage(self):
# USER must appear after the final FROM so the runtime stage is non-root.
for name in self.NON_ROOT:
content = (DOCKER_DIR / name).read_text()
last_from = content.rfind("\nFROM ")
user_idx = content.rfind("\nUSER ")
assert user_idx > last_from, f"{name}: USER not in final runtime stage"
class TestSandboxNodeSecurity:
"""#566 — Node installed without an unverified curl|bash pipe."""
def test_no_curl_pipe_bash(self):
content = (DOCKER_DIR / "Dockerfile.sandbox").read_text()
for ln in content.splitlines():
code = ln.split("#", 1)[0] # ignore the explanatory comment
assert "| bash" not in code and "|bash" not in code, (
f"unverified pipe-to-bash install remains: {ln!r}"
)
assert "nodesource.com" not in code, "still using NodeSource setup script"
def test_node_sourced_from_pinned_official_image(self):
content = (DOCKER_DIR / "Dockerfile.sandbox").read_text()
assert "COPY --from=node" in content, "Node not copied from pinned image stage"
froms = _from_lines(content)
assert any("node:" in ln and "@sha256:" in ln for ln in froms), (
"no digest-pinned node base stage"
)
class TestFrozenInstall:
"""#567 — Docker builds install from the committed, frozen uv.lock."""
BUILD_DOCKERFILES = [
"Dockerfile",
"Dockerfile.gpu",
"Dockerfile.gpu.rocm",
"Dockerfile.sandbox",
]
def test_copies_lockfile(self):
for name in self.BUILD_DOCKERFILES:
content = (DOCKER_DIR / name).read_text()
assert "uv.lock" in content, f"{name}: uv.lock not referenced"
def test_uses_frozen_export(self):
for name in self.BUILD_DOCKERFILES:
content = (DOCKER_DIR / name).read_text()
assert "uv export --frozen" in content, f"{name}: no frozen export"
assert "--no-deps" in content, (
f"{name}: deps re-resolved (missing --no-deps)"
)
def test_no_unpinned_pyproject_resolution(self):
# The old `uv pip install --system ".[server]"` re-resolved deps on every
# build; it must not come back.
for name in self.BUILD_DOCKERFILES:
content = (DOCKER_DIR / name).read_text()
assert '".[server]"' not in content, (
f"{name}: still re-resolves from pyproject"
)
class TestSystemdHardening:
"""#564 — systemd unit ships secrets via EnvironmentFile and is sandboxed."""
def _service(self) -> str:
return (SYSTEMD_DIR / "openjarvis.service").read_text()
def test_environment_file_for_secrets(self):
assert "EnvironmentFile=" in self._service()
def test_core_hardening_directives_present(self):
content = self._service()
for directive in (
"NoNewPrivileges=true",
"ProtectSystem=strict",
"PrivateTmp=true",
):
assert directive in content, f"missing hardening directive: {directive}"
def test_writable_state_path_declared(self):
# ProtectSystem=strict makes the FS read-only; the working/home dir must
# be re-granted write access or the server cannot persist config/state.
content = self._service()
assert "ReadWritePaths=" in content
+45
View File
@@ -0,0 +1,45 @@
"""Static guards for the docs-site savings-leaderboard Supabase wiring.
`docs/javascripts/leaderboard.js` reads the public Supabase anon key from
`window.OPENJARVIS_SUPABASE_ANON_KEY`. That global is set by a generated
config file (`leaderboard-config.js`) which must load *before* leaderboard.js,
and whose value is injected at docs-build time from the VITE_SUPABASE_ANON_KEY
secret (see `.github/workflows/docs.yml`). These are text-only checks no
mkdocs build required so they run in the default CI lane.
"""
from __future__ import annotations
from pathlib import Path
ROOT = Path(__file__).resolve().parent.parent.parent
MKDOCS = ROOT / "mkdocs.yml"
DOCS_WORKFLOW = ROOT / ".github" / "workflows" / "docs.yml"
CONFIG_JS = ROOT / "docs" / "javascripts" / "leaderboard-config.js"
LEADERBOARD_JS = ROOT / "docs" / "javascripts" / "leaderboard.js"
_ANON_GLOBAL = "window.OPENJARVIS_SUPABASE_ANON_KEY"
def test_config_js_declares_anon_key_global():
assert CONFIG_JS.is_file(), "leaderboard-config.js is missing"
assert _ANON_GLOBAL in CONFIG_JS.read_text()
def test_leaderboard_reads_the_anon_key_global():
# leaderboard.js must consume the global the config file sets.
assert _ANON_GLOBAL in LEADERBOARD_JS.read_text()
def test_config_is_loaded_before_leaderboard_in_mkdocs():
content = MKDOCS.read_text()
cfg = content.index("javascripts/leaderboard-config.js")
lb = content.index("javascripts/leaderboard.js")
assert cfg < lb, "leaderboard-config.js must be listed before leaderboard.js"
def test_docs_workflow_injects_the_anon_key():
content = DOCS_WORKFLOW.read_text()
assert "VITE_SUPABASE_ANON_KEY" in content, "workflow doesn't read the secret"
assert "leaderboard-config.js" in content, "workflow doesn't write the config file"
assert _ANON_GLOBAL in content, "workflow doesn't set the anon-key global"
+17
View File
@@ -0,0 +1,17 @@
from __future__ import annotations
from openjarvis.core.types import Message, Role, ToolCall
from openjarvis.engine._base import estimate_prompt_tokens
def test_estimate_prompt_tokens_handles_none_content_tool_call_turn() -> None:
messages = [
Message(role=Role.USER, content="hi"),
Message(
role=Role.ASSISTANT,
content=None, # type: ignore[arg-type]
tool_calls=[ToolCall(id="call_1", name="lookup", arguments="{}")],
),
]
assert estimate_prompt_tokens(messages) == 8
+35
View File
@@ -6,6 +6,7 @@ import json
import pytest
from openjarvis.core.registry import FactStoreRegistry
from openjarvis.memory.store import LocalFactStore, create_fact_store
@@ -74,6 +75,20 @@ def test_clear(tmp_path):
assert LocalFactStore(path).count() == 0
def test_external_clear_does_not_resurrect_stale_facts(tmp_path):
"""A running store instance must not re-flush facts cleared elsewhere."""
path = tmp_path / "facts.jsonl"
running = LocalFactStore(path)
cli = LocalFactStore(path)
running.add("old fact")
assert cli.clear() == 1
running.add("new fact")
assert [f.text for f in LocalFactStore(path).list()] == ["new fact"]
def test_load_skips_malformed_lines(tmp_path):
path = tmp_path / "facts.jsonl"
path.write_text(
@@ -107,6 +122,26 @@ def test_create_fact_store_local(tmp_path):
assert isinstance(store, LocalFactStore)
def test_create_fact_store_uses_fact_store_registry(tmp_path):
class CustomFactStore(LocalFactStore):
pass
FactStoreRegistry.register_value("custom", CustomFactStore)
store = create_fact_store("custom", path=tmp_path / "f.jsonl", max_facts=5)
assert isinstance(store, CustomFactStore)
def test_create_fact_store_default_path_uses_openjarvis_home(tmp_path, monkeypatch):
monkeypatch.setenv("OPENJARVIS_HOME", str(tmp_path))
store = create_fact_store("local")
assert isinstance(store, LocalFactStore)
assert store.path == tmp_path / "memory_facts.jsonl"
def test_create_fact_store_unknown_backend(tmp_path):
with pytest.raises(ValueError):
create_fact_store("cloud", path=tmp_path / "f.jsonl")
+38 -1
View File
@@ -7,7 +7,12 @@ import time
from types import SimpleNamespace
from openjarvis.core.config import StorageConfig
from openjarvis.memory.service import MemoryService, build_memory_service
from openjarvis.core.events import EventBus
from openjarvis.memory.service import (
MemoryService,
build_memory_service,
publish_completed_exchange,
)
from openjarvis.memory.store import LocalFactStore
@@ -67,6 +72,38 @@ def test_submit_extracts_and_stores(tmp_path):
svc.stop()
def test_completed_exchange_event_extracts_and_stores(tmp_path):
bus = EventBus(record_history=True)
extractor = FakeExtractor(["User likes jazz"])
store = LocalFactStore(tmp_path / "facts.jsonl")
svc = MemoryService(store, extractor, event_bus=bus)
svc.start()
try:
assert publish_completed_exchange(
bus,
"I like jazz",
"Noted.",
source="test",
)
assert _wait_until(lambda: svc.fact_count() == 1)
assert extractor.calls == [("I like jazz", "Noted.")]
finally:
svc.stop()
def test_completed_exchange_event_unsubscribes_on_stop(tmp_path):
bus = EventBus(record_history=True)
extractor = FakeExtractor(["User likes jazz"])
store = LocalFactStore(tmp_path / "facts.jsonl")
svc = MemoryService(store, extractor, event_bus=bus)
svc.start()
svc.stop()
publish_completed_exchange(bus, "I like jazz", "Noted.", source="test")
assert extractor.calls == []
def test_submit_when_not_running_is_dropped(tmp_path):
extractor = FakeExtractor(["x"])
svc = _service(tmp_path, extractor)
+3 -2
View File
@@ -33,7 +33,7 @@ def test_path_traversal_rejected(bad):
SystemPromptBuilder._resolve_persona(MemoryFilesConfig(persona_name=bad))
def test_none_persona_build_does_not_raise():
def test_none_persona_build_does_not_raise(tmp_path, monkeypatch):
"""Regression (#497): `--persona none` resolves to empty file paths; building
the prompt must not raise IsADirectoryError when those empty paths are read
(Path("") is "." reading a directory raised before the empty-path guard).
@@ -42,7 +42,8 @@ def test_none_persona_build_does_not_raise():
from openjarvis.core.config import load_config
cfg = load_config()
monkeypatch.setenv("OPENJARVIS_HOME", str(tmp_path / "home"))
cfg = load_config(tmp_path / "missing-config.toml")
mf = dataclasses.replace(cfg.memory_files, persona_name="none")
builder = SystemPromptBuilder(
agent_template=cfg.agent.default_system_prompt or "",
+152 -23
View File
@@ -10,6 +10,7 @@ import pytest
fastapi = pytest.importorskip("fastapi")
from fastapi.testclient import TestClient # noqa: E402
from openjarvis.core.events import EventBus, EventType # noqa: E402
from openjarvis.server.app import create_app # noqa: E402
# ---------------------------------------------------------------------------
@@ -54,10 +55,19 @@ def _make_agent(content="Hello from agent"):
return agent
def _test_config():
from openjarvis.core.config import JarvisConfig
cfg = JarvisConfig()
cfg.analytics.enabled = False
cfg.traces.enabled = False
return cfg
@pytest.fixture
def client():
engine = _make_engine()
app = create_app(engine, "test-model")
app = create_app(engine, "test-model", config=_test_config())
return TestClient(app)
@@ -65,7 +75,7 @@ def client():
def client_with_agent():
engine = _make_engine()
agent = _make_agent()
app = create_app(engine, "test-model", agent=agent)
app = create_app(engine, "test-model", agent=agent, config=_test_config())
return TestClient(app)
@@ -92,7 +102,12 @@ class TestMemoryServiceWiring:
def test_non_streaming_completion_feeds_memory(self):
engine = _make_engine(content="remembered reply")
spy = _SpyMemoryService()
app = create_app(engine, "test-model", memory_service=spy)
app = create_app(
engine,
"test-model",
memory_service=spy,
config=_test_config(),
)
client = TestClient(app)
resp = client.post(
@@ -109,7 +124,13 @@ class TestMemoryServiceWiring:
engine = _make_engine()
agent = _make_agent(content="agent reply")
spy = _SpyMemoryService()
app = create_app(engine, "test-model", agent=agent, memory_service=spy)
app = create_app(
engine,
"test-model",
agent=agent,
memory_service=spy,
config=_test_config(),
)
client = TestClient(app)
resp = client.post(
@@ -122,9 +143,83 @@ class TestMemoryServiceWiring:
assert resp.status_code == 200
assert spy.submissions == [("remember this", "agent reply")]
def test_non_streaming_completion_publishes_completed_exchange(self):
bus = EventBus(record_history=True)
engine = _make_engine(content="event reply")
app = create_app(engine, "test-model", bus=bus, config=_test_config())
client = TestClient(app)
resp = client.post(
"/v1/chat/completions",
json={
"model": "test-model",
"messages": [{"role": "user", "content": "publish this"}],
},
)
assert resp.status_code == 200
events = [
e for e in bus.history if e.event_type == EventType.CHAT_EXCHANGE_COMPLETED
]
assert len(events) == 1
assert events[0].data["user_text"] == "publish this"
assert events[0].data["assistant_text"] == "event reply"
def test_streaming_completion_feeds_memory_without_bus(self):
engine = _make_engine()
spy = _SpyMemoryService()
app = create_app(
engine,
"test-model",
memory_service=spy,
config=_test_config(),
)
client = TestClient(app)
resp = client.post(
"/v1/chat/completions",
json={
"model": "test-model",
"messages": [{"role": "user", "content": "stream remember"}],
"stream": True,
},
)
assert resp.status_code == 200
assert "data:" in resp.text
assert spy.submissions == [("stream remember", "Hello world")]
def test_streaming_completion_publishes_completed_exchange(self):
bus = EventBus(record_history=True)
engine = _make_engine()
app = create_app(engine, "test-model", bus=bus, config=_test_config())
client = TestClient(app)
resp = client.post(
"/v1/chat/completions",
json={
"model": "test-model",
"messages": [{"role": "user", "content": "stream event"}],
"stream": True,
},
)
assert resp.status_code == 200
assert "data:" in resp.text
events = [
e for e in bus.history if e.event_type == EventType.CHAT_EXCHANGE_COMPLETED
]
assert len(events) == 1
assert events[0].data["user_text"] == "stream event"
assert events[0].data["assistant_text"] == "Hello world"
def test_no_memory_service_is_noop(self):
engine = _make_engine()
app = create_app(engine, "test-model") # memory_service defaults to None
app = create_app(
engine,
"test-model",
config=_test_config(),
) # memory_service defaults to None
client = TestClient(app)
resp = client.post(
"/v1/chat/completions",
@@ -207,7 +302,7 @@ class TestChatCompletions:
"model": "test-model",
"finish_reason": "tool_calls",
}
app = create_app(engine, "test-model")
app = create_app(engine, "test-model", config=_test_config())
client = TestClient(app)
resp = client.post(
"/v1/chat/completions",
@@ -255,7 +350,7 @@ class TestChatCompletions:
"finish_reason": "tool_calls",
}
agent = _make_agent(content="GENERIC AGENT FILLER")
app = create_app(engine, "test-model", agent=agent)
app = create_app(engine, "test-model", agent=agent, config=_test_config())
client = TestClient(app)
resp = client.post(
@@ -342,7 +437,7 @@ class TestChatCompletions:
lambda data: received_records.append(data),
)
app = create_app(wrapped, "test-model")
app = create_app(wrapped, "test-model", config=_test_config())
app.state.bus = bus
client = TestClient(app)
@@ -483,7 +578,13 @@ class TestChatCompletions:
# bus present + agent registered == the exact live condition under
# which the pre-fix code routed to the (broken) agent stream bridge.
agent = _make_agent(content="GENERIC AGENT FILLER")
app = create_app(engine, "test-model", agent=agent, bus=EventBus())
app = create_app(
engine,
"test-model",
agent=agent,
bus=EventBus(),
config=_test_config(),
)
client = TestClient(app)
resp = client.post(
@@ -592,6 +693,15 @@ def _make_capturing_engine(captured: list):
return engine
def _identity_config():
from openjarvis.core.config import JarvisConfig
cfg = JarvisConfig()
cfg.agent.default_system_prompt = "You are OpenJarvis."
cfg.analytics.enabled = False
return cfg
class TestIdentityPromptInjection:
"""Regression for #540.
@@ -607,7 +717,7 @@ class TestIdentityPromptInjection:
def test_stream_injects_identity_when_absent(self):
captured: list = []
engine = _make_capturing_engine(captured)
client = TestClient(create_app(engine, "test-model"))
client = TestClient(create_app(engine, "test-model", config=_identity_config()))
resp = client.post(
"/v1/chat/completions",
@@ -628,7 +738,7 @@ class TestIdentityPromptInjection:
def test_stream_no_double_injection_when_client_supplies_system(self):
captured: list = []
engine = _make_capturing_engine(captured)
client = TestClient(create_app(engine, "test-model"))
client = TestClient(create_app(engine, "test-model", config=_identity_config()))
resp = client.post(
"/v1/chat/completions",
@@ -652,7 +762,7 @@ class TestIdentityPromptInjection:
captured: list = []
engine = _make_capturing_engine(captured)
# No agent -> non-stream request goes through _handle_direct.
client = TestClient(create_app(engine, "test-model"))
client = TestClient(create_app(engine, "test-model", config=_identity_config()))
resp = client.post(
"/v1/chat/completions",
@@ -670,7 +780,7 @@ class TestIdentityPromptInjection:
def test_direct_no_double_injection_when_client_supplies_system(self):
captured: list = []
engine = _make_capturing_engine(captured)
client = TestClient(create_app(engine, "test-model"))
client = TestClient(create_app(engine, "test-model", config=_identity_config()))
resp = client.post(
"/v1/chat/completions",
@@ -691,7 +801,7 @@ class TestIdentityPromptInjection:
def test_stream_tools_injects_identity_when_absent(self):
captured: list = []
engine = _make_capturing_engine(captured)
client = TestClient(create_app(engine, "test-model"))
client = TestClient(create_app(engine, "test-model", config=_identity_config()))
resp = client.post(
"/v1/chat/completions",
@@ -733,7 +843,7 @@ class TestModelsEndpoint:
def test_multiple_models(self):
engine = _make_engine(models=["model-a", "model-b", "model-c"])
app = create_app(engine, "model-a")
app = create_app(engine, "model-a", config=_test_config())
client = TestClient(app)
resp = client.get("/v1/models")
data = resp.json()
@@ -754,7 +864,7 @@ class TestHealthEndpoint:
def test_unhealthy(self):
engine = _make_engine()
engine.health.return_value = False
app = create_app(engine, "test-model")
app = create_app(engine, "test-model", config=_test_config())
client = TestClient(app)
resp = client.get("/health")
assert resp.status_code == 503
@@ -768,19 +878,19 @@ class TestHealthEndpoint:
class TestCreateApp:
def test_app_state(self):
engine = _make_engine()
app = create_app(engine, "test-model")
app = create_app(engine, "test-model", config=_test_config())
assert app.state.engine is engine
assert app.state.model == "test-model"
def test_app_with_agent(self):
engine = _make_engine()
agent = _make_agent()
app = create_app(engine, "test-model", agent=agent)
app = create_app(engine, "test-model", agent=agent, config=_test_config())
assert app.state.agent is agent
def test_app_without_agent(self):
engine = _make_engine()
app = create_app(engine, "test-model")
app = create_app(engine, "test-model", config=_test_config())
assert app.state.agent is None
@@ -790,8 +900,26 @@ class TestCreateApp:
# ---------------------------------------------------------------------------
def _traces_enabled_config(tmp_path):
"""A config with traces explicitly enabled, isolated to *tmp_path*.
``create_app`` only builds a trace store when ``config.traces.enabled`` is
true (server/app.py). Relying on the ambient ``load_config()`` made these
tests fail on any machine whose ``~/.openjarvis/config.toml`` disables
traces; pinning an explicit config + tmp db keeps them hermetic and
parallel-safe under ``pytest -n auto``.
"""
from openjarvis.core.config import JarvisConfig
cfg = JarvisConfig()
cfg.traces.enabled = True
cfg.traces.db_path = str(tmp_path / "traces.db")
cfg.analytics.enabled = False
return cfg
class TestTraceRecording:
def test_agent_completion_creates_trace(self):
def test_agent_completion_creates_trace(self, tmp_path):
"""A non-streaming agent completion records exactly one trace.
The collector is the single writer: it saves directly and also
@@ -810,9 +938,10 @@ class TestTraceRecording:
"test-model",
agent=agent,
bus=EventBus(record_history=False),
config=_traces_enabled_config(tmp_path),
)
store = app.state.trace_store
assert store is not None, "traces enabled by default → store should exist"
assert store is not None, "traces explicitly enabled → store should exist"
assert store.count() == 0
client = TestClient(app)
@@ -831,10 +960,10 @@ class TestTraceRecording:
assert trace.query == "What is 2+2?"
assert trace.result == "traced reply"
def test_streaming_completion_creates_trace(self):
def test_streaming_completion_creates_trace(self, tmp_path):
"""A streamed completion (no agent) records the assembled response."""
engine = _make_engine()
app = create_app(engine, "test-model")
app = create_app(engine, "test-model", config=_traces_enabled_config(tmp_path))
store = app.state.trace_store
assert store is not None
assert store.count() == 0
Generated
+275 -1992
View File
File diff suppressed because it is too large Load Diff