Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 1 addition & 2 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,9 @@ __pycache__/
venv/
env/
backend/.venv/
backend/package/.venv/

# 忽略 node_modules 文件夹(前端项目)
web/node_modules/
frontend/node_modules/

# 忽略 Docker 运行时数据卷
docker/volumes/
Expand Down
5 changes: 3 additions & 2 deletions .env.template
Original file line number Diff line number Diff line change
Expand Up @@ -45,8 +45,6 @@ NEO4J_PASSWORD=
# # endregion neo4j

# # Services
# YUXI_SUPER_ADMIN_NAME=
# YUXI_SUPER_ADMIN_PASSWORD=
# # ARQ worker 单任务最长执行时间(秒),默认 3600,长耗时任务需调大
# YUXI_JOB_TIMEOUT_SECONDS=3600
# WORKER_HEALTH_INTERVAL_SECONDS=5 # 必须大于 0 且不超过 10;过长会破坏 worker 故障探测
Expand Down Expand Up @@ -130,6 +128,9 @@ SANDBOX_PROVISIONER_TOKEN=
# USER_DATA_PVC=yuxi-user-data # UserWorkspace(含 projects),存储类必须支持 RWX
# SKILLS_PVC=yuxi-skills # 用户授权 Skill 只读投影

# Milvus 知识库与图向量使用同一数据库,API / worker 重建后生效
MILVUS_DB=yuxi

# Milvus 容器 CPU 上界(重建容器后生效;让镜像内置 maxprocs 按 cgroup quota 收敛 GOMAXPROCS)
# 内存随知识库数据量线性增长,故意不设上限:硬上界只会在数据合法增长时
# 把容器推入 OOM→重启→重加载→再 OOM 的循环,监控告警比 kill 更合适
Expand Down
2 changes: 1 addition & 1 deletion .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@ updates:
open-pull-requests-limit: 0

- package-ecosystem: npm
directory: /web
directory: /frontend
schedule:
interval: weekly
open-pull-requests-limit: 0
Expand Down
16 changes: 7 additions & 9 deletions .github/workflows/dependency-audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,13 +6,12 @@ on:
- ".github/workflows/dependency-audit.yml"
- "Makefile"
- "backend/pyproject.toml"
- "backend/package/pyproject.toml"
- "backend/uv.lock"
- "packages/yuxi-cli/pyproject.toml"
- "packages/yuxi-cli/uv.lock"
- "web/package.json"
- "web/pnpm-lock.yaml"
- "web/pnpm-workspace.yaml"
- "frontend/package.json"
- "frontend/pnpm-lock.yaml"
- "frontend/pnpm-workspace.yaml"
- "docs/package.json"
- "docs/pnpm-lock.yaml"
- "docs/pnpm-workspace.yaml"
Expand All @@ -24,13 +23,12 @@ on:
- ".github/workflows/dependency-audit.yml"
- "Makefile"
- "backend/pyproject.toml"
- "backend/package/pyproject.toml"
- "backend/uv.lock"
- "packages/yuxi-cli/pyproject.toml"
- "packages/yuxi-cli/uv.lock"
- "web/package.json"
- "web/pnpm-lock.yaml"
- "web/pnpm-workspace.yaml"
- "frontend/package.json"
- "frontend/pnpm-lock.yaml"
- "frontend/pnpm-workspace.yaml"
- "docs/package.json"
- "docs/pnpm-lock.yaml"
- "docs/pnpm-workspace.yaml"
Expand Down Expand Up @@ -85,7 +83,7 @@ jobs:
strategy:
fail-fast: false
matrix:
project: [web, docs]
project: [frontend, docs]
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
Expand Down
18 changes: 9 additions & 9 deletions .github/workflows/web.yml → .github/workflows/frontend.yml
Original file line number Diff line number Diff line change
@@ -1,28 +1,28 @@
name: Web Quality
name: Frontend Quality

on:
pull_request:
paths:
- 'web/**'
- '.github/workflows/web.yml'
- 'frontend/**'
- '.github/workflows/frontend.yml'
push:
tags: ['v[0-9]*']
branches: [main]
paths:
- 'web/**'
- '.github/workflows/web.yml'
- 'frontend/**'
- '.github/workflows/frontend.yml'

permissions:
contents: read

jobs:
web:
frontend:
name: Lint, unit and production build
runs-on: ubuntu-latest
timeout-minutes: 15
defaults:
run:
working-directory: web
working-directory: frontend
steps:
- uses: actions/checkout@v7
- uses: pnpm/action-setup@v6
Expand All @@ -32,7 +32,7 @@ jobs:
with:
node-version: 22
cache: pnpm
cache-dependency-path: web/pnpm-lock.yaml
cache-dependency-path: frontend/pnpm-lock.yaml
- run: pnpm install --frozen-lockfile
- name: Run read-only web gates
- name: Run read-only frontend gates
run: pnpm run lint:check && pnpm run test:unit && pnpm run build
6 changes: 3 additions & 3 deletions .github/workflows/ruff.yml
Original file line number Diff line number Diff line change
Expand Up @@ -63,6 +63,6 @@ jobs:

- name: Check lint, formatting and imports
run: |
ruff check package
ruff format package --check
ruff check --select I package
ruff check yuxi
ruff format yuxi --check
ruff check --select I yuxi
96 changes: 62 additions & 34 deletions .github/workflows/system-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,9 @@ on:
pull_request:
paths:
- '.env.template'
- 'backend/package/yuxi/**'
- 'backend/yuxi/**'
- 'backend/pyproject.toml'
- 'backend/uv.lock'
- 'backend/server/**'
- 'backend/test/integration/**'
- 'backend/test/e2e/**'
- 'backend/test/support/**'
Expand All @@ -16,17 +15,15 @@ on:
- 'docker-compose.prod.yml'
- 'scripts/ci_prepare_system_tests_env.sh'
- 'scripts/ci_build_topology_images.sh'
- 'scripts/migrate-storage.sh'
- '.github/workflows/system-tests.yml'
push:
tags: ['v[0-9]*']
branches: [main]
paths:
- '.env.template'
- 'backend/package/yuxi/**'
- 'backend/yuxi/**'
- 'backend/pyproject.toml'
- 'backend/uv.lock'
- 'backend/server/**'
- 'backend/test/integration/**'
- 'backend/test/e2e/**'
- 'backend/test/support/**'
Expand All @@ -35,7 +32,6 @@ on:
- 'docker-compose.prod.yml'
- 'scripts/ci_prepare_system_tests_env.sh'
- 'scripts/ci_build_topology_images.sh'
- 'scripts/migrate-storage.sh'
- '.github/workflows/system-tests.yml'
workflow_dispatch:

Expand Down Expand Up @@ -120,7 +116,7 @@ jobs:
- name: Verify Durable Task worker path
run: |
docker compose stop api worker
docker compose run --rm storage-migrator
docker compose run --rm schema-init
docker compose run --rm --no-deps api \
uv run --no-sync --no-dev pytest test/integration/services/test_durable_task_repository.py -q
docker compose run --rm --no-deps \
Expand Down Expand Up @@ -167,10 +163,10 @@ jobs:
run: docker compose down -v

system-tests:
name: PostgreSQL, readiness and deterministic Agent path
name: PostgreSQL, readiness and Agent lifecycle
runs-on: ubuntu-latest
# 新 runner 首次构建 sandbox-provisioner 会下载 Debian 与 Python 依赖,启动预算需覆盖冷缓存构建。
timeout-minutes: 60
timeout-minutes: 90
steps:
- uses: actions/checkout@v7
- name: Set up Docker Buildx
Expand Down Expand Up @@ -206,7 +202,17 @@ jobs:
sandbox_runtime_image=$(docker compose config --format json | python3 -c 'import json, sys; print(json.load(sys.stdin)["services"]["sandbox-provisioner"]["environment"]["SANDBOX_IMAGE"])')
docker pull "$sandbox_runtime_image"
- name: Start focused runtime topology
run: docker compose up -d postgres redis minio sandbox-provisioner api worker
run: docker compose up -d postgres redis minio milvus graph sandbox-provisioner api worker
- name: Wait for Milvus retrieval readiness
run: |
for attempt in $(seq 1 60); do
if docker compose exec -T milvus curl -fsS http://localhost:9091/healthz >/dev/null; then
exit 0
fi
sleep 2
done
docker compose logs etcd minio milvus --tail 200
exit 1
- name: Wait for truthful readiness
run: |
for attempt in $(seq 1 90); do
Expand Down Expand Up @@ -234,7 +240,7 @@ jobs:
done
exit 1
- name: Verify worker shipping health
run: docker compose exec -T worker uv run --no-sync --no-dev arq --check server.worker_main.WorkerSettings
run: docker compose exec -T worker uv run --no-sync --no-dev arq --check yuxi.workers.main.WorkerSettings
- name: Verify local job filtering preserves ARQ dispatch and retry
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/services/test_arq_worker_dispatch.py -q
- name: Verify worker can write personal Skill UserWorkspace
Expand Down Expand Up @@ -286,44 +292,66 @@ jobs:
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/api/test_system_router_api.py::test_health_endpoint_is_public test/integration/api/test_system_router_api.py::test_readiness_endpoint_proves_core_runtime_dependencies test/integration/api/test_system_router_api.py::test_discovery_and_openapi_declare_full_knowledge_capabilities -q
- name: Verify MCP management connection contract
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/api/test_mcp_router.py -q
- name: Verify versioned Schema migration contract
- name: Verify current Schema initialization contract
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/services/test_schema_migration_version.py -q
- name: Verify Milvus 3 text retrieval through worker
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_milvus_text_retrieval_e2e.py -q --durations=10
- name: Verify knowledge statistics projection
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/services/test_knowledge_stats_refresh.py -q
- name: Verify queue transaction and recovery
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/services/test_agent_request_queue_concurrency.py -q
- name: Verify AgentRun lease ownership
- name: Verify Input FIFO transaction and recovery
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/services/test_agent_input_concurrency.py -q
- name: Verify Run lease ownership
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/services/test_agent_run_lease.py -q
- name: Verify Run result causality
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/api/test_agent_run_result_causality.py -q
- name: Verify Turn result causality
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/api/test_turn_result_causality.py -q
- name: Verify lifecycle HTTP and PostgreSQL boundaries
timeout-minutes: 8
run: |
docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api \
uv run --no-sync --no-dev pytest \
test/integration/api/test_public_agent_auth.py \
test/integration/api/test_public_agents_key_boundary.py \
test/integration/api/test_public_thread_alias.py \
test/integration/services/test_agent_input_schema.py \
test/integration/services/test_project_thread_archive.py \
test/integration/services/test_run_stream_redis.py -q
- name: Verify Knowledge Key HTTP boundary without optional knowledge runtime
run: |
docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api \
uv run --no-sync --no-dev pytest \
test/integration/api/test_public_knowledge_key_boundary.py::test_knowledge_key_is_limited_to_public_knowledge_api \
test/integration/api/test_public_knowledge_key_boundary.py::test_agents_key_cannot_access_public_knowledge_api \
test/integration/api/test_public_knowledge_key_boundary.py::test_public_knowledge_does_not_expose_management_routes \
test/integration/api/test_public_knowledge_tools.py::test_knowledge_key_tool_route_boundary_without_kb -q
- name: Verify Subagent state recovery and visibility
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/api/test_subagent_state_recovery.py -q
- name: Verify Message audit HTTP contract
timeout-minutes: 3
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/api/test_chat_router.py::test_thread_message_audits_return_persisted_facts_without_leaking_into_history -q --setup-show -o faulthandler_timeout=60
- name: Verify visible tools for ordinary users
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/api/test_chat_router.py::test_standard_user_restores_visible_function_items_without_internal_audit -q
- name: Verify independent delegated Turn cancellation
run: docker compose exec -T api uv run --no-sync --no-dev pytest test/integration/services/test_delegated_turn_cancellation.py -q
- name: Verify attachment HTTP and object contract
timeout-minutes: 3
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/api/test_chat_router.py::test_thread_artifact_uses_image_signature_for_content_type -q
- name: Verify deterministic E2E stage assignment
run: |
if docker compose exec -T api uv run --no-sync --no-dev pytest test/e2e/test_deterministic_agent_path_e2e.py --collect-only -q -m 'e2e and not (e2e_smoke or e2e_lifecycle or e2e_boundaries)'; then
echo "Unassigned deterministic E2E test detected" >&2
exit 1
else
test "$?" -eq 5
fi
- name: Verify deterministic Agent Run, scheduling and tool result
timeout-minutes: 10
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_deterministic_agent_path_e2e.py -q -m e2e_smoke --durations=10
- name: Verify deterministic Agent failure, resume and cancellation
- name: Verify Input, Turn and Run lifecycle through worker
timeout-minutes: 20
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_agent_lifecycle_e2e.py -q --durations=10
- name: Verify scheduled, model and tool lifecycle paths
timeout-minutes: 12
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_deterministic_agent_path_e2e.py -q -m e2e_lifecycle --durations=10
- name: Verify deterministic SubAgent and Workdir paths
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_agent_lifecycle_extended_e2e.py -q --durations=10
- name: Verify SubAgent and Workdir boundaries
timeout-minutes: 12
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_deterministic_agent_path_e2e.py -q -m e2e_boundaries --durations=10
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_agent_lifecycle_subagent_boundaries_e2e.py -q --durations=10
- name: Verify Agents Key end-user execution scope
timeout-minutes: 6
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_agent_lifecycle_key_scope_e2e.py -q --durations=10
- name: Verify OpenAI events default input and recovery
run: docker compose exec -T -e E2E_USERNAME -e E2E_PASSWORD api uv run --no-sync --no-dev pytest test/e2e/test_openai_events_e2e.py -q --durations=10
- name: Verify identity transaction and replayable secret publication
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/services/test_identity_admin_service.py test/integration/services/test_api_key_schema_migration.py test/integration/services/test_api_key_user_lifecycle.py test/integration/api/test_apikey_router.py -q
- name: Verify destructive storage migration and Skill authorization
run: docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest test/integration/services/test_identity_admin_service.py test/integration/services/test_api_key_user_lifecycle.py test/integration/api/test_apikey_router.py -q
- name: Verify Workdir and Skill authorization
run: |
docker compose exec -T -e TEST_USERNAME="$E2E_USERNAME" -e TEST_PASSWORD="$E2E_PASSWORD" api uv run --no-sync --no-dev pytest \
test/integration/services/test_workdir_user_workspace.py \
Expand Down
2 changes: 0 additions & 2 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,6 @@ on:
- 'scripts/init.sh'
- 'scripts/init.ps1'
- 'scripts/test_init_security.ps1'
- 'scripts/migrate-storage.sh'
- '.github/workflows/test.yml'
push:
tags: ['v[0-9]*']
Expand All @@ -31,7 +30,6 @@ on:
- 'scripts/init.sh'
- 'scripts/init.ps1'
- 'scripts/test_init_security.ps1'
- 'scripts/migrate-storage.sh'
- '.github/workflows/test.yml'

permissions:
Expand Down
18 changes: 1 addition & 17 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -47,13 +47,9 @@ cache
### IDE
.vscode
.idea
.vibe
.qoder
.claude
.cursor
.trae
.codex
.sisyphus
.pytest_cache

*.secret*
Expand All @@ -67,19 +63,7 @@ cache
*.local/*

*.pdf
src/data
*/package-lock.json
web/package-lock.json
saves
saves_dev
notebooks
graphrag
frontend/package-lock.json
docker/volumes
docs/vibe
.cursorrules

/models

.taskr/
.workbuddy/
web/src/utils/__tests__/
Loading
Loading