Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
2010 commits
Select commit Hold shift + click to select a range
286f266
feat(design-studio): save/open/rename/delete designs (persistence) (#…
jaylfc Jul 4, 2026
a80b5dc
feat(office): wire Write Assist + Calc "Ask your data" to the taOS ag…
jaylfc Jul 4, 2026
972a67d
test(settings): lock in dock/wallpaper partial-save isolation (#1603,…
jaylfc Jul 4, 2026
7ce31f6
release: 1.0.0-beta.27 (Office AI + Database, Web Studio, Music DAW, …
jaylfc Jul 4, 2026
d99a603
Merge pull request #1644 from jaylfc/dev
jaylfc Jul 4, 2026
fff1fd0
feat(app-studio): real build to package to analyze to install to sand…
jaylfc Jul 4, 2026
64f2842
feat(licensing): weight-license metadata + non-commercial accept gate…
jaylfc Jul 4, 2026
c6d2830
fix(video-studio): async generation job (enqueue + poll) instead of b…
jaylfc Jul 4, 2026
0ac11c1
release: 1.0.0-beta.28 (App Studio real pipeline, weight-license acce…
jaylfc Jul 4, 2026
6bb1460
Merge pull request #1649 from jaylfc/dev
jaylfc Jul 4, 2026
200c0a0
feat(music-studio): render/bounce a song to a downloadable WAV (Tone.…
jaylfc Jul 5, 2026
1156161
feat(game-studio): add 4 playable game templates (runner, snake, tapp…
jaylfc Jul 5, 2026
717411e
feat(coding-studio): real sandboxed live preview of workspace files (…
jaylfc Jul 5, 2026
e2390b7
release: 1.0.0-beta.29 (Coding Studio live preview, Music WAV bounce,…
jaylfc Jul 5, 2026
5d384b2
Merge pull request #1656 from jaylfc/dev
jaylfc Jul 5, 2026
84018a2
feat(governance): per-agent LLM budget hard-stops (#160 Slice 2) (#1657)
jaylfc Jul 5, 2026
e8d7ed4
chore(deps): bump the spa-deps group across 1 directory with 22 updat…
dependabot[bot] Jul 5, 2026
7d34a78
fix(models): rkllama downloads report real progress + show installed …
jaylfc Jul 5, 2026
dfdb0e3
release: 1.0.0-beta.30 (rkllama download progress fix, agent budget h…
jaylfc Jul 5, 2026
af5c178
Merge pull request #1660 from jaylfc/dev
jaylfc Jul 5, 2026
3cd257b
feat(governance): agent org model - roles/titles/reporting lines + ga…
jaylfc Jul 5, 2026
cca9392
chore(deps): bump the python-deps group across 1 directory with 4 upd…
dependabot[bot] Jul 5, 2026
c23651f
feat(agents): opt-in heartbeat loop - wake idle running agents with t…
jaylfc Jul 6, 2026
7522dee
Merge remote-tracking branch 'origin/master' into dev
jaylfc Jul 6, 2026
f1280f0
fix(models): parse rkllama plain-text pull progress so RK3588 downloa…
jaylfc Jul 6, 2026
1122320
release: 1.0.0-beta.31 (agent org model + delegation, heartbeat loop,…
jaylfc Jul 6, 2026
7695783
Merge pull request #1665 from jaylfc/dev
jaylfc Jul 6, 2026
66d97e8
ci: stabilize the desktop vitest gate (OOM/flake hardening) (#1666)
jaylfc Jul 6, 2026
2d5fcb8
fix(governance): dedupe decision-answer routing + honest delegation m…
jaylfc Jul 6, 2026
9571076
fix(governance): fold Kilo review on #1667 (no grant leak + honest ex…
jaylfc Jul 6, 2026
5dea7c7
Merge pull request #1667 from jaylfc/fix/174-decision-routing-dedup
jaylfc Jul 6, 2026
f229551
fix(weather): allow open-meteo origins in CSP connect-src (#1668)
jaylfc Jul 6, 2026
dc28af7
fix(desktop): user's wallpaper pick wins over theme default on login …
jaylfc Jul 6, 2026
24b5ea3
Merge pull request #1669 from jaylfc/fix/1668-weather-csp-open-meteo
jaylfc Jul 6, 2026
2d5a8c2
Merge pull request #1670 from jaylfc/fix/1603-user-wallpaper-wins-ove…
jaylfc Jul 6, 2026
6ae2890
feat(devices): DeviceStore with per-device scoped tokens (Apple clien…
jaylfc Jul 6, 2026
03f8ee6
feat(devices): register/list/revoke/update-token routes, per-user sco…
jaylfc Jul 6, 2026
85980f6
feat(devices): require_device scoped-token auth dependency (Apple cli…
jaylfc Jul 6, 2026
ed5e831
feat(push): APNs sender abstraction with null default + ES256 JWT (Ap…
jaylfc Jul 6, 2026
1328bf4
fix(devices): fold Kilo review on #1671 (input caps, device cap, APNs…
jaylfc Jul 6, 2026
fa4713e
Merge pull request #1671 from jaylfc/feat/apple-client-slice1
jaylfc Jul 6, 2026
d936325
release: 1.0.0-beta.32 (Weather search fix, wallpaper-persistence fix…
jaylfc Jul 6, 2026
86d0012
feat(cluster): expose real-time free/used VRAM in /api/cluster/workers
Jul 6, 2026
2d3eebb
Merge pull request #1672 from jaylfc/release/1.0.0-beta.32
jaylfc Jul 6, 2026
0c380a5
Merge pull request #1674 from jaylfc/dev
jaylfc Jul 6, 2026
99cd636
docs(design): RFC for A2A GPU-lease claim/release on taOS controller …
Jul 6, 2026
1b8ed67
feat(cluster): GPU lease claim/release API on taOS controller (#893)
Jul 6, 2026
40f6527
fix(deps): override lodash-es/uuid/nanoid to clear Dependabot alerts …
jaylfc Jul 6, 2026
3eb7e92
feat(settings): hide system-settings panels from non-admin users (#163)
jaylfc Jul 6, 2026
a8338d8
Merge pull request #1676 from jaylfc/fix/173-npm-dependabot-overrides
jaylfc Jul 6, 2026
fa9d1dc
fix(doc-gate): exempt test files from structural rules (#171)
jaylfc Jul 6, 2026
708d42f
Merge pull request #1677 from jaylfc/fix/163-hide-admin-settings
jaylfc Jul 6, 2026
9f86e3f
fix(scheduler): execute due scheduled tasks incl. auto-backup, allow-…
jaylfc Jul 6, 2026
3a6bfcf
chore(scripts): safe prune policy for stale agent worktrees (#172)
jaylfc Jul 6, 2026
4d9a147
Merge pull request #1678 from jaylfc/fix/165-backup-scheduler-executor
jaylfc Jul 6, 2026
df2c86e
Merge remote-tracking branch 'origin/dev' into feat/1675-gpu-lease-fi…
jaylfc Jul 6, 2026
e292600
fix(cluster): atomic lease claim + VRAM-unknown handling + review fix…
jaylfc Jul 6, 2026
8eeb04d
Merge pull request #1679 from jaylfc/chore/172-prune-agent-worktrees
jaylfc Jul 6, 2026
60727be
fix(rkllama): surface the pull error on install failure instead of ge…
jaylfc Jul 6, 2026
a622ece
fix(rkllama): land models in the unified taOS tree so the Models UI s…
jaylfc Jul 6, 2026
6f21c9c
Merge pull request #1680 from jaylfc/feat/1675-gpu-lease-finish
jaylfc Jul 6, 2026
e7e7173
refactor(rkllama): fold Kilo review on the pull-error parser (#1548)
jaylfc Jul 6, 2026
a27d2e7
fix(rkllama): fold Kilo review on the unified-model-store slice (#1548)
jaylfc Jul 6, 2026
a945153
Merge pull request #1682 from jaylfc/feat/unified-model-store-rkllama
jaylfc Jul 6, 2026
9b2d1c3
Merge pull request #1681 from jaylfc/fix/1548-surface-rkllama-pull-error
jaylfc Jul 6, 2026
0ae6690
release: 1.0.0-beta.33 (rkllama unified model store + #1548 fix, GPU-…
jaylfc Jul 6, 2026
2523191
Merge pull request #1685 from jaylfc/release/1.0.0-beta.33
jaylfc Jul 6, 2026
13c07f6
Merge pull request #1687 from jaylfc/dev
jaylfc Jul 6, 2026
bcc5d42
fix(cluster): await cancelled monitor task in ClusterManager.stop()
hognek Jul 6, 2026
f8b3f6e
fix(cluster): await cancelled monitor task in ClusterManager.stop()
hognek Jul 6, 2026
9b1a5ee
feat(containers): add NativeBackend for bare-metal worker deployment
hognek Jul 6, 2026
71a1563
fix(agents): discard stale per-agent key on re-scope failure, fall ba…
hognek Jul 6, 2026
f504560
fix(agents): persist the stale-key discard (fold Kilo review on #1686)
jaylfc Jul 6, 2026
202a132
fix: surface divergence message when branch diverged from tracked remote
hognek Jul 6, 2026
00d2d2b
fix(messages): add hover copy button + explicit select-text to agent …
hognek Jul 6, 2026
bdc8e05
feat(desktop): surface update availability in top-bar badge
hognek Jul 6, 2026
83fbc4b
fix(agents): find opencode installed under any user's home (#1616)
jaylfc Jul 6, 2026
8ee1dde
fix(agents): only probe trusted opencode locations (security review o…
jaylfc Jul 6, 2026
9a3b6d1
style: drop em dashes from #1616 comments
jaylfc Jul 6, 2026
7540ac3
fix(config): heal stale rkllama provider port :8080 -> :7833 on load …
jaylfc Jul 6, 2026
0c8f5b9
fix(models): scan wherever the rkllama service actually writes, for e…
jaylfc Jul 7, 2026
596e64b
feat(chat): per-agent framework slash commands via @agent / prefix in…
hognek Jul 6, 2026
2894c07
Merge pull request #1692 from jaylfc/fix/1686-persist-key-discard
jaylfc Jul 7, 2026
6107837
fix(agents): guard opencode candidate stat against PermissionError (C…
jaylfc Jul 7, 2026
2188409
Merge pull request #1702 from jaylfc/fix/1697-rkllama-provider-port
jaylfc Jul 7, 2026
2fbdedd
fix(models): robust rkllama --models parse, fold Kilo review (#1548)
jaylfc Jul 7, 2026
516a6d9
fix(models): use rkllama.service explicit unit in systemctl fallback …
jaylfc Jul 7, 2026
a7f26f8
fix(agents): log when TAOS_OPENCODE_BIN is set but not executable (fo…
jaylfc Jul 7, 2026
2ec7410
Merge pull request #1701 from jaylfc/fix/1616-opencode-discovery
jaylfc Jul 7, 2026
5f07895
Merge pull request #1704 from jaylfc/fix/1548-scan-rkllama-service-dir
jaylfc Jul 7, 2026
07b8e9c
release: 1.0.0-beta.34 (rkllama model discovery + provider port heal …
jaylfc Jul 7, 2026
b02837e
Merge pull request #1708 from jaylfc/release/1.0.0-beta.34
jaylfc Jul 7, 2026
d33b35b
Merge pull request #1695 from hognek/fix/841-update-check-diverged
jaylfc Jul 7, 2026
02e296a
Merge pull request #1688 from hognek/feat/gpu-lease-coordination
jaylfc Jul 7, 2026
19be613
fix(cluster): authenticate GPU lease endpoints + validate inputs + wi…
jaylfc Jul 7, 2026
ca384fc
fix(governance): delegation + org-model hardening (#1661/#1662 retro,…
jaylfc Jul 7, 2026
a097e9e
fix(messages): cleanup copy-button unmount timers, gate to agent-only…
hognek Jul 7, 2026
8b9a6a2
fix(governance): create _reporting_lock at construction, not in init()
jaylfc Jul 7, 2026
ad85358
fix(desktop): guard currentVersion against dev pattern; drop dead dec…
hognek Jul 7, 2026
6857d46
fix(containers): NativeBackend security + supervision + bug fixes
hognek Jul 7, 2026
fc94095
Merge pull request #1711 from jaylfc/fix/gpu-lease-auth-hardening
jaylfc Jul 7, 2026
1212915
Merge pull request #1712 from jaylfc/fix/delegation-org-hardening
jaylfc Jul 7, 2026
7d0c17d
fix: retro hygiene - heartbeat wake stagger + APNs client close + cry…
jaylfc Jul 7, 2026
98b8935
fix(containers): reject newlines in env values + guard post-kill wait
hognek Jul 7, 2026
32460d1
fix: fold Kilo review WARNINGs on retro-hygiene PR
jaylfc Jul 7, 2026
0f3e2ae
Merge pull request #1714 from jaylfc/fix/retro-hygiene-heartbeat-apns
jaylfc Jul 7, 2026
9eebf02
Merge pull request #1713 from hognek/fix/1691-native-backend-security
jaylfc Jul 7, 2026
12bc2d6
fix(config): rename rkllama backend local-npu to local-rkllama so ins…
jaylfc Jul 7, 2026
b322584
fix(rkllama): bump pinned rkllama ref to main HEAD for the /api/chat …
jaylfc Jul 7, 2026
19d2f74
Merge pull request #1715 from jaylfc/fix/rkllama-backend-name-registr…
jaylfc Jul 7, 2026
a6a2239
Merge pull request #1716 from jaylfc/fix/bump-rkllama-pin-chat-fix
jaylfc Jul 7, 2026
466bae9
Merge pull request #1698 from hognek/fix/issue-835-copyable-agent-text
jaylfc Jul 7, 2026
a54f72d
Merge pull request #1700 from hognek/feat/update-badge
jaylfc Jul 7, 2026
b0d882e
release: 1.0.0-beta.35 (rkllama agent chat fix #1710, copy/select mes…
jaylfc Jul 7, 2026
ba28696
Merge pull request #1717 from jaylfc/release/1.0.0-beta.35
jaylfc Jul 7, 2026
8cc63be
fix(chat): resolve TS2448 TDZ, update generic slash-command test, fix…
hognek Jul 7, 2026
8abeaf2
chore(license): dual-license taOS as AGPL-3.0-or-later + commercial
jaylfc Jul 7, 2026
76c0c2a
Merge pull request #1721 from jaylfc/chore/relicense-agpl-dual
jaylfc Jul 7, 2026
cc2199d
feat(taosnet): license-eligibility classifier for redistribution
jaylfc Jul 7, 2026
ef0e90e
fix(searxng): enable JSON output format via settings.yml bind mount, …
hognek Jul 7, 2026
e0d6d7a
Merge pull request #1720 from hognek/fix/1703-ci-failures
jaylfc Jul 7, 2026
0cff19c
Merge pull request #1723 from jaylfc/feat/taosnet-license-classifier
jaylfc Jul 7, 2026
a6e2984
feat(taosnet): client passkey + web-seed + torrent_url wiring, DHT off
jaylfc Jul 7, 2026
45bd627
docs(taosnet): reconcile model-torrent-mesh design with the shipped c…
jaylfc Jul 7, 2026
041e666
Merge pull request #1728 from jaylfc/feat/taosnet-client-passkey
jaylfc Jul 7, 2026
159a098
Merge pull request #1729 from jaylfc/docs/taosnet-current-state
jaylfc Jul 7, 2026
5ab57de
fix(searxng): harden config_files path validation, persist secret_key…
hognek Jul 7, 2026
4308daf
Merge pull request #1724 from hognek/feat/searxng-settings-yml
jaylfc Jul 8, 2026
05f9558
fix(install-rknpu): pin rkllama --preload restore + context-overflow …
jaylfc Jul 8, 2026
94b17e2
fix(docker-installer): 0600 perms + validity guard on the persisted a…
jaylfc Jul 8, 2026
1d07247
release: 1.0.0-beta.36 (#1735)
jaylfc Jul 8, 2026
2472464
fix(install-rknpu): pin rkllama with structured context-overflow erro…
jaylfc Jul 8, 2026
11aa00b
feat(taosnet): headless passkey fetch for background model downloads …
jaylfc Jul 8, 2026
32c5858
feat(cli): taos recover-password for offline local account recovery (…
jaylfc Jul 8, 2026
0630382
fix(agents): guard against non-chat + small-context models for agents…
jaylfc Jul 8, 2026
098d644
release: 1.0.0-beta.37 (#1746)
jaylfc Jul 8, 2026
91697cd
feat(activity): recover/restart the local AI stack (#1743) (#1749)
jaylfc Jul 8, 2026
33a6dbb
feat(agent-window): scrollbars and stall detection (#1741, #1742) (#1…
jaylfc Jul 8, 2026
9e0495b
fix(agent-window,activity): fold Kilo review findings from #1748/#174…
jaylfc Jul 8, 2026
be5c928
fix(agents): make the mobile Agents view readable (archived rows + he…
jaylfc Jul 8, 2026
d85c4bc
fix(mobile): reflow broken app layouts on phones (mobile pass, batch …
jaylfc Jul 8, 2026
dda9cce
release: 1.0.0-beta.38 (agent-window resilience + mobile-friendliness…
jaylfc Jul 8, 2026
4b39d45
fix(rknpu): a live rkllama port is not 'installed' unless it is a man…
jaylfc Jul 9, 2026
d8342c3
docs(design): cluster-aware backend service management spec (#1757)
jaylfc Jul 9, 2026
d8c555a
feat(catalog): managed-backend-service manifest contract + CI lint (P…
jaylfc Jul 9, 2026
8e901b4
feat(cluster): node-local backend service manager core (Phase 1.2) (#…
jaylfc Jul 9, 2026
8bb607b
refactor(system): derive #1743 restart targets from managed-backend c…
jaylfc Jul 9, 2026
71939f1
feat(models): atomic VRAM check-and-reserve before model load (TOCTOU…
hognek Jul 9, 2026
6b485fb
feat(cluster): advertise available models from Skald sidecar manifest…
hognek Jul 9, 2026
9ac0ff7
fix(install-rknpu): pin rkllama to the 1.3.0 ref + guard the fork pat…
jaylfc Jul 9, 2026
58cd159
fix(worker,models): audit hotfixes - manifest crash, VRAM fail-open, …
jaylfc Jul 9, 2026
f221bff
feat(a2a): authenticated bus send proxy (agents post as themselves, n…
jaylfc Jul 10, 2026
bd86020
test(designstudio): add coverage for the untested Design Studio app (…
jaylfc Jul 10, 2026
55b6ef3
feat(taosgo): persist per-host mesh service credentials at cluster-jo…
jaylfc Jul 10, 2026
7c6f3ba
fix(catalog): fix 6 broken install-script references in agent manifes…
hognek Jul 10, 2026
02ef089
feat(taosgo): headless Headscale mesh-join via system tailscale (Slic…
jaylfc Jul 10, 2026
307c6b8
feat(gamestudio): AI texture/sprite generation via ComfyUI backend (S…
jaylfc Jul 10, 2026
da9a896
feat(agents): least-privilege project_tasks registry scope for kanban…
jaylfc Jul 10, 2026
b8acce7
release: 1.0.0-beta.39 (Game Studio textures, taOSgo mesh-join, proje…
jaylfc Jul 10, 2026
75a2527
fix(agents): model-aware history token budget for agent chat (#1740) …
jaylfc Jul 10, 2026
a48a64f
feat(notifications): OS-level PWA web-push (VAPID) for taOS notificat…
jaylfc Jul 10, 2026
ebf0f51
feat(consent): project picker for project_tasks approval (#1777)
jaylfc Jul 10, 2026
5004a82
release: 1.0.0-beta.40 (consent project picker, PWA web-push, model-a…
jaylfc Jul 10, 2026
c106105
fix(projects): show consent-flow external agents in the External sect…
jaylfc Jul 11, 2026
f9d1d00
test(secrets): add coverage for the Secrets app (#1785)
jaylfc Jul 11, 2026
7a2f70a
test(notes): add vitest coverage for NotesApp/TodoApp mounted behavio…
jaylfc Jul 11, 2026
421b34c
test(chess): add vitest coverage for ChessApp (#1788)
jaylfc Jul 11, 2026
a2f099c
test(imageviewer): add vitest coverage for ImageViewerApp (#1789)
jaylfc Jul 11, 2026
2e0189e
fix(desktop): Registry poll no longer resets scroll (#1761) (#1786)
jaylfc Jul 11, 2026
5ece4cd
chore(deps): bump the python-deps group with 3 updates (#1790)
dependabot[bot] Jul 12, 2026
04cdd09
chore(deps): bump the spa-deps group in /desktop with 16 updates (#1791)
dependabot[bot] Jul 12, 2026
9de6f46
docs(design): account model, free username plus paid chosen subdomain…
jaylfc Jul 12, 2026
617ad59
docs(design): Hailo-10H LLM backend, zero-touch install parity with R…
jaylfc Jul 12, 2026
1869e4e
docs(design): hub.taos.my local-first P2P social network foundation (…
jaylfc Jul 12, 2026
36d3fde
feat(hailo): reserve port 7836 and map hailo-ollama llm-chat capabili…
jaylfc Jul 12, 2026
db6f573
feat(account): controller proxy actions for subdomain check/claim/rel…
jaylfc Jul 12, 2026
5c4afbb
docs(design): Projects app nested elements, one project with typed el…
jaylfc Jul 12, 2026
9d006f4
fix(models): VRAM reservation TTL sweep + #1766 acceptance coverage (…
jaylfc Jul 12, 2026
14270d9
feat(account): frontend types + Account panel split for username/subd…
jaylfc Jul 12, 2026
a266077
feat(hailo): slice 2 hailo-ollama installer (#1771) (#1803)
jaylfc Jul 12, 2026
a28a83b
feat(hailo): slice 3 hailo-ollama managed service manifest (#1804)
jaylfc Jul 13, 2026
1eea646
feat(account): onboarding free username claim step (slice 5) (#1805)
jaylfc Jul 13, 2026
cdc0ecf
feat(hub): identity keypair keystore + directory registration proxy (…
jaylfc Jul 13, 2026
b827b90
feat(hailo): slice 4 install-time gates for Hailo-10H (per design doc…
jaylfc Jul 13, 2026
dccbb7e
feat(hailo): slice 5 runtime detection + provider adapter for Hailo-1…
jaylfc Jul 13, 2026
a33276b
feat(hub): profile object + local hub store (slice 2) (#1809)
jaylfc Jul 13, 2026
35b754d
feat(hub): follow / friend / circle model + request brokering (slice …
jaylfc Jul 13, 2026
c7825d8
feat(projects): nested element store, CRUD routes, and task element t…
jaylfc Jul 13, 2026
a04f9a7
feat(projects): kanban element filter bar (slice 2) (#1812)
jaylfc Jul 13, 2026
81f8d92
feat(hub): post objects, chain logic, image ingest, composer + own-ti…
jaylfc Jul 13, 2026
3a23637
fix: map violet and red note colors to valid tldraw palette names (#1…
jaylfc Jul 13, 2026
e01015a
docs(readme): External Coding Agents section (bring your own AI team)…
jaylfc Jul 13, 2026
c5190e9
fix(hub): serialize chain appends so racing posts are not orphaned (#…
jaylfc Jul 13, 2026
30b4188
fix(canvas): map text elements to visible taos-text shapes (#1819)
jaylfc Jul 13, 2026
a16da5f
feat(projects): element overview grid, creation flow, and drill-in na…
jaylfc Jul 13, 2026
152e4e4
Add confirm guard before video delete (#1821)
jaylfc Jul 14, 2026
70956ab
Projects elements slice 4: element-scoped canvas + files (#1822)
jaylfc Jul 14, 2026
d5ff3c1
feat(agents): add canvas_read and canvas_write scopes
jaylfc Jul 14, 2026
9874328
fix(agents): drop unused SCOPE_LABELS map in ConsentActions
jaylfc Jul 14, 2026
5c3d5e2
feat(agents): canvas routes join the agent-token allowlist (#1800 sli…
jaylfc Jul 14, 2026
45eb164
Merge branch 'feat/lead-identity-mw-allowlist' into feat/lead-identit…
jaylfc Jul 14, 2026
f5f0253
feat(agents): consent approval sets registry handle from sanitized id…
jaylfc Jul 14, 2026
297fd18
fix(agents): reject blank project_id for project-scoped grants
jaylfc Jul 14, 2026
e97bdc1
feat(canvas): agent scope + permission gating and honest attribution
jaylfc Jul 14, 2026
be2ed6e
fix(agents): escape the dot in the canvas snapshot allowlist regexes
jaylfc Jul 14, 2026
bffab44
fix(canvas): fold adversarial review findings 1, 2, 4 into route gating
jaylfc Jul 14, 2026
e02e87f
feat(projects): members canvas checkboxes + exclusive Lead (#1800 sli…
jaylfc Jul 14, 2026
1c05d54
feat(canvas): payload cap + agent write rate limit (#1800 slice 5)
jaylfc Jul 14, 2026
98a31bd
feat(canvas): gate stream + snapshot + keepalive recheck (#1800 slice 4)
jaylfc Jul 14, 2026
de21830
fix(agents): close consent handle-set TOCTOU and active-without-handl…
jaylfc Jul 14, 2026
4f5ee42
Docs-Reviewed: restore slice-3 enforcement tests dropped during slice…
jaylfc Jul 14, 2026
81a84c4
test(agents): update ConsentActions test to the new project-picker label
jaylfc Jul 14, 2026
b07bf9d
feat(council): role registry + member store slice per taos-council.md…
jaylfc Jul 15, 2026
02247e3
feat(projects): deep-link target registry (#1802 slice 2) (#1831)
jaylfc Jul 15, 2026
47c3358
feat(projects): markdown doc reader (#1802 slice 1) (#1832)
jaylfc Jul 15, 2026
29c1e6c
Merge remote-tracking branch 'origin/feat/lead-identity-scope-vocab' …
jaylfc Jul 15, 2026
d70128e
Merge remote-tracking branch 'origin/feat/lead-identity-mw-allowlist'…
jaylfc Jul 15, 2026
91ee945
Merge remote-tracking branch 'origin/feat/lead-identity-route-gating'…
jaylfc Jul 15, 2026
d4ff06e
Merge remote-tracking branch 'origin/feat/lead-identity-stream-gating…
jaylfc Jul 15, 2026
3cb2155
Merge remote-tracking branch 'origin/feat/lead-identity-limits' into …
jaylfc Jul 15, 2026
a1aef1c
Merge remote-tracking branch 'origin/feat/lead-identity-members-ui' i…
jaylfc Jul 15, 2026
aa44876
Merge remote-tracking branch 'origin/feat/lead-identity-consent-handl…
jaylfc Jul 15, 2026
6dd90e9
fix(agents): create active-handle index after status migration
jaylfc Jul 15, 2026
01bb110
feat(catalog): Gemma 4 E4B/E2B uncensored GGUF models (#1836) (#1837)
jaylfc Jul 15, 2026
063004f
Merge pull request #1838 from jaylfc/epic-integrate
jaylfc Jul 15, 2026
5d5dec3
fix(installer): normalise tree ownership before re-run update (#1839)
jaylfc Jul 16, 2026
76f744d
fix(agents): self-heal duplicate active handles so the unique index c…
jaylfc Jul 16, 2026
ce6a104
fix(installer): do not abort the installer if the re-run chown partia…
jaylfc Jul 16, 2026
0b2a563
fix(projects): stop cleared Lead re-promotion + approve canvas scope …
jaylfc Jul 16, 2026
edafd5c
fix(hailo): correct re-install idempotency check + narrow the orphan …
jaylfc Jul 16, 2026
c892227
fix(canvas): bound snapshot render dimensions + offload render + clam…
jaylfc Jul 16, 2026
02c767f
fix(security): account proxy stops forwarding local session cookie + …
jaylfc Jul 16, 2026
e54d25c
fix(hailo): install from hailo_model_zoo_genai via cmake, not a nonex…
jaylfc Jul 16, 2026
f688239
fix(projects): create element_id indexes after migration, not in SCHE…
jaylfc Jul 16, 2026
6d9d9f5
feat(a2a): authenticated SSE stream proxy + since cursor (#1780 S3) (…
jaylfc Jul 16, 2026
b010318
docs(design): external-agent project invite (link + PIN) (#1780)
jaylfc Jul 16, 2026
f145ccd
docs(gate): document agent-JWT API surface + gate auth_middleware dri…
jaylfc Jul 16, 2026
a60ba3a
feat(invite): project_invites store + mint/list/revoke routes (#1780 …
jaylfc Jul 16, 2026
4713468
feat(invite): ProjectMembers invite-external-agent UI (#1780 S4) (#1857)
jaylfc Jul 16, 2026
2d72bfb
fix(cluster): release GPU leases on worker unregister (taOS #1705) (#…
hognek Jul 16, 2026
6353277
feat(invite): redeem + bundle + onboarding kit (#1780 S2) (#1858)
jaylfc Jul 16, 2026
35ddc1e
feat(scheduler): land GPU arbiter on one VRAM authority + eviction/he…
jaylfc Jul 16, 2026
a13ec68
feat(agents): multi-project agent identities (per-project grants, gra…
jaylfc Jul 17, 2026
ecf3c0c
feat(agents): invite + assign external agents to projects from the Ag…
jaylfc Jul 17, 2026
fbda1fa
chore(ci): static guard against the SCHEMA-index-before-migration boo…
jaylfc Jul 17, 2026
7161b48
docs(design): GPU work queue spec (#1864) (#1869)
jaylfc Jul 17, 2026
7f49bee
docs: add taos-development-skill (SKILL.md + soul.md) to .claude/skil…
hognek Jul 17, 2026
96a33cb
fix(cluster): restore local-worker guard + correct worker-update rest…
jaylfc Jul 17, 2026
cbd5f2a
fix(cluster): heartbeat-driven registration refresh for host_lan_ip/u…
hognek Jul 17, 2026
e383891
fix: address Kilo Code Review findings
hognek Jul 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
324 changes: 324 additions & 0 deletions .claude/skills/taos-development-skill/SKILL.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,324 @@
---
name: taos-development-skill
description: TinyAgentOS (taOS) architecture map, contribution workflow, testing guide, common fix patterns, and coding conventions. Load when contributing to taOS - PRs, bug fixes, features, catalog additions.
---

# taos-development-skill

Procedures and architecture for contributing to
[TinyAgentOS](https://github.com/jaylfc/taOS). The non-negotiable rules live in
`soul.md`; this skill is the *how*.

> uses approximate counts (~N) as rough orientation only - actual numbers rot fast in a
> living repo. Trust the tree, not tallies.

## Repository layout

```
<clone>/
tinyagentos/ ← server package
app.py ← FastAPI app factory: lifespan, route registration
config.py ← Platform config, hardware detection
routes/ ← one APIRouter module per feature area (~86 modules)
templates/ ← minimal: agent_debugger.html only (frontend is React SPA)
channel_hub/ ← framework-agnostic messaging: connectors + MessageRouter
adapters/ ← thin per-framework agent adapters (~25 lines each)
cluster/ ← distributed compute: worker registry, task routing, GPU lease
worker/ ← cross-platform worker apps (system tray, Android, iOS)
stores/ ← data layer: aiosqlite (SQLite), one store per concern
chat/ projects/ mcp/ ← chat, project board/canvas/A2A, MCP proxy+permissions
installers/ containers/ ← model/app installers; Docker + LXC backends
migrations/ ← DB migrations
desktop/ ← React + TypeScript SPA (Vite)
app-catalog/ ← YAML app manifests + catalog.yaml (~108 apps)
tests/ ← pytest suite (~3,590 tests)
docs/ ← documentation; agent manual compiled from docs/agent-manual/
```

## Key architectural patterns

- **Routes** - each `routes/*.py` is an `APIRouter` registered in `app.py`'s `create_app()`.
`async def` handlers, `await` all I/O, Pydantic request/response models. Routes access stores
via `request.app.state` (dependency injection set up in the app lifespan) - they do **not**
import stores directly. **No cross-importing between route modules.**
- **Stores** - SQLite via `aiosqlite`, each with `init()`/`close()`, attached to
`request.app.state` in the lifespan (`app.state.metrics`, `app.state.secrets`, …).
- **Config** - `AppConfig` dataclass in `config.py`; YAML serialisation; async-locked saves via
`save_config_locked()`; typed backends (`rkllama`, `ollama`, `openai`, `anthropic`, …).
- **Templates** - **Pico CSS utility classes only** (no other CSS framework). htmx (`hx-get`,
`hx-target`, `hx-swap`) for dynamic partials. Semantic HTML; ARIA labels on interactive elements
without visible text. Templates are minimal - the frontend is a React SPA.
- **Frontend** - React + TypeScript SPA in `desktop/`. Built with Vite: `npm run build` outputs
to `static/desktop/` (gitignored). For development: `npm run dev` serves with hot reload on
port 5173. One concern per component; API calls in dedicated hooks or service files.
- **Cluster** - worker registration, routing to remote nodes, model archive/promotion on capable
hardware, GPU lease claim/release, hardware-tier compatibility.

## Git workflow

### Before starting

1. **Sync from upstream:**
```bash
git fetch origin dev
git checkout dev
git rebase origin/dev
```
Never branch from a stale `dev`.

2. **Create an isolated worktree** (recommended for concurrent work):
```bash
git worktree add /path/to/worktree dev
cd /path/to/worktree
```
When done: `git worktree remove /path/to/worktree` (or `--force` if needed).

3. **Create a branch:** `feat/<slug>` or `fix/<slug>` matching the task.

### After completing the work

4. **Commit before anything else.** Code → test → `git add` → `git commit` (conventional message) →
push to fork.

5. **Open a draft PR, then mark ready immediately:**
```bash
gh pr create --repo jaylfc/taOS --head <user>:<branch> --base dev --draft \
--title "feat(scope): description" --body "Fixes #<issue>. Tests: N/N pass."
gh pr ready <PR#>
```
Do NOT wait for CI - fork PRs are gated behind maintainer workflow approval.
Mark ready once the CODE is done and local tests pass.

6. **Never commit directly to `dev` or `master`.** All work happens on branches.
Main only receives merges via upstream PR approval.

### Branch naming

`feat/<slug>` or `fix/<slug>`. Keep it short and descriptive.

### Commit messages

Conventional commits only:

| Prefix | Use for |
|--------|---------|
| `feat:` | new feature |
| `fix:` | bug fix |
| `docs:` | documentation only |
| `refactor:` | code change with no behaviour change |
| `test:` | adding or updating tests |
| `chore:` | tooling, deps, CI |

No AI tool attribution in commit messages.

## Testing

Run **targeted tests first**, then the fast parallel gate. **Never run the un-parallelised full
suite (`pytest tests/ -v`) locally** - it is massive and will take far too long. CI owns the
full 3.12–3.13 matrix (3.11 on nightly cron only).

```bash
# 1. Targeted - the changed module + related tests, always first:
uv run pytest tests/test_<changed_module>.py tests/<related>/ -v

# 2. Canonical local gate - parallel, run before marking ready:
uv run pytest tests/ --ignore=tests/e2e -n auto
```

### Test conventions

- `conftest.py`: `tmp_data_dir` fixture creates temp config + SQLite
- `app` fixture: `create_app(data_dir=tmp_data_dir)`
- `client` fixture: `AsyncClient(transport=ASGITransport(app=app))` - async HTTP test client
- Module mirroring: `tests/test_agents.py` tests `routes/agents.py`
- SPA stubs: conftest creates stub `index.html`/`sw.js` so tests don't need `npm run build`
- E2E (Playwright) tests excluded from CI and local gate

### CI matrix

- Python 3.12 + 3.13 on every PR/push; 3.11 on nightly cron only
- GitHub Actions: `.github/workflows/ci.yml` in upstream repo
- Uses `uv sync --frozen` and `pytest -n auto`

## CLA - HUMAN signs

taOS requires a Contributor License Agreement for first-time contributors. The CLA bot
flags the PR with a `cla: fail` check.

**The agent does NOT sign the CLA.** Posting the acceptance text accepts a legal agreement - that is the human account-holder's action, not the agent's.

### Procedure when `cla: fail` appears:

1. Verify the commit author email matches a GitHub-verified email.
If the email was wrong, amend the commit with the correct email, force-push.
2. Surface the bot's comment + link to the human. Do NOT post the acceptance text yourself.
Do NOT post `recheck`.

The bot accepts a PR comment in this format (for the human to post):
```
I have read the CLA Document and I hereby sign the CLA
```

## PR / CI flow (fork specifics)

1. After creating the draft PR, check both `gh pr checks <PR#>` **and**
`gh run list --repo jaylfc/taOS --branch <branch>` - the matrix run may not show in
`pr checks` while it awaits approval.
2. **If the CI run shows `action_required`**: the first-time-contributor workflow-approval policy
is blocking it. Surface this to the human - do not re-poll, re-push, or re-create the PR.
Lightweight checks (CLA, Gitar, CodeRabbit) run independently and don't need approval.
3. Once code is done and local tests pass, `gh pr ready`. Address review feedback with additional
commits on the same branch. The maintainer merges upstream.

## Post-Push Bot Review Cycle

After pushing a PR and marking it ready, automated bots (Kilo, CodeRabbit) run reviews.
Address their findings **before** surfacing the PR for human maintainer review - this
eliminates the wasteful push→block→manual-check→unblock→re-dispatch cycle.

### Procedure

1. **Push PR and mark ready.** Wait ~10 minutes for bot reviews to complete.
2. **Pull bot comments:**
```bash
gh pr view <PR#> --repo jaylfc/taOS --json comments --jq \
'.comments[] | select(.author.login == "kilo-code-bot" or .author.login == "coderabbitai[bot]")'
```
3. **If issues found:** fix all findings in a single commit, re-run local tests, push,
then go back to step 1 (max 2 cycles).
4. **Only block for maintainer review when bots are clean** - 0 CRITICAL, 0 WARNING.
If a SUGGESTION-only finding is genuinely not applicable, note the rationale in a
PR comment before blocking.

### Severity tiers

| Tier | Action |
|------|--------|
| CRITICAL | Must fix before blocking for review |
| WARNING | Must fix before blocking for review |
| SUGGESTION | Fix or explain why not applicable |

### Time estimates

| Phase | Duration |
|-------|----------|
| First bot pass (Kilo + CodeRabbit) | ~10 min |
| Fix cycle (if needed) | ~5–10 min |
| Second bot pass (if re-pushed) | ~10 min |
| **Worst case (2 cycles)** | **~30 min** |

## Common fix patterns

- **New route:** `routes/<feature>.py` with `router = APIRouter()` → register in `create_app()` →
tests in `tests/test_<feature>.py` using the `client` fixture.
- **New store:** class with `init()`/`close()` (aiosqlite) → attach in the lifespan → mock in
conftest if needed.
- **Config field:** add to config dataclass → update defaults + `to_dict()`/`from_dict()` →
`test_config.py`.
- **Catalog entry:** `manifest.yaml` under `app-catalog/<category>/<id>/` → add to `catalog.yaml` →
`pytest tests/test_catalog_sync.py`.
- **Debugging a test:** confirm it uses the async `client` fixture and that `tmp_data_dir` setup is
complete; check the store's `init()`; isolate with `pytest <path>::<test> -v`.

## Documentation gate

A gate blocks PRs that add or remove certain feature code without a matching doc update
(configured in `docs/doc-gate.toml`):

| Change | Requires editing |
|--------|-----------------|
| Desktop app under `desktop/src/apps/` added/removed | `README.md` |
| Route module under `tinyagentos/routes/` added/removed | `docs/agent-coordination.md` |
| Installer under `tinyagentos/installers/` or `scripts/install*` added/removed | `README.md` |
| Manifest under `app-catalog/` added/removed | `README.md` |

If your PR trips a rule and there is genuinely nothing to document, add a trailer:
```
Docs-Reviewed: no user-facing change, internal refactor only
```

Run `scripts/install-git-hooks.sh` to enable local hooks (`.githooks/pre-commit` and
`.githooks/commit-msg`) so the gate runs before you push.

## Upstream conventions (from CONTRIBUTING.md)

- **Target branch is `dev`, not `master`.** `master` is the stable live-install track.
- Branch naming: `feat/<slug>` or `fix/<slug>`
- Conventional commits (see table above)
- No AI tool attribution in commits
- Python 3.11+ floor (pyproject.toml: `>=3.11,<3.14`). `match`/`case` and `X | None` union syntax
are available. Most modules use `from __future__ import annotations`.
- Code style: match surrounding code, one concern per module
- Use `uv` for dependency management and test running: `uv sync --extra dev`, `uv run pytest`

## Desktop SPA build + test

```bash
cd desktop
npm install # Node.js 22+
npm run build # tsc -b && vite build → outputs to static/desktop/
npm run test # vitest (unit/component tests)
npm run test:e2e # Playwright browser tests (needs running server)
```

## Adding an app to the catalog

1. Create directory: `app-catalog/<category>/<id>/`
2. Write `manifest.yaml` (use `app-catalog/agents/langroid/manifest.yaml` as template)
3. Add entry to `app-catalog/catalog.yaml`
4. Run `uv run pytest tests/test_catalog_sync.py -v`
5. Open a PR

All fields in `manifest.yaml` except `config_schema` are required. The `hardware_tiers` block
controls which hardware profiles see the app as recommended.

## Pitfalls

- **Full test suite is too large to run locally without `-n auto`.** Use the canonical
gate: `uv run pytest tests/ --ignore=tests/e2e -n auto`. CI handles the full matrix.
- **CI may show `action_required` on every PR from a fork.** GitHub requires maintainer approval
for workflow runs from first-time contributor forks. This can re-trigger on each new PR even after
previous PRs were approved - it's per-workflow-run, not per-contributor. Surface to the human;
do NOT poll or re-push.
- **No lint/format tooling is configured.** There is no `.pre-commit-config.yaml`, no
`.ruff.toml`, and no `[tool.ruff]`, `[tool.black]`, or `[tool.mypy]` section in
`pyproject.toml`. Match the surrounding code style manually.
- **Secrets:** No dedicated secrets store in the current tree. The `stores/` directory pattern
handles data access; secrets management may live in the MCP permissions model or be handled
at the OS/deployment layer. When unsure, treat secrets as escalate-to-human.
- **CONTRIBUTING.md** says Python 3.10+, but `pyproject.toml` requires `>=3.11,<3.14`.
Python 3.11 is the effective floor.
- **Routes do not import stores directly.** They access them via `request.app.state`.
This is a common mistake - check existing routes for the pattern.
- **`static/desktop/` is gitignored.** The SPA build output is a generated artifact.
The conftest in `tests/` stubs the SPA build output so backend tests don't need `npm run build`.

## Issue triage

### Finding actionable issues
1. Filter GitHub issues by `good first issue` or `help wanted` labels
2. Check issue age - fresh issues (< 2 weeks) have highest chance of being unclaimed
3. Read the issue body carefully - look for clear reproduction steps
4. Check if anyone is already assigned

### Difficulty estimation
- **Catalog app addition** (~30 min): New manifest.yaml + catalog.yaml entry
- **Bug fix** (1–3 hours): Reproduce → find root cause → fix + regression test
- **Feature** (3+ hours): Design → implement → tests → documentation

### Before starting work
1. Sync from upstream: `git fetch origin dev`
2. Verify the issue is still open and unassigned
3. Comment on the issue: "Working on this - will open a draft PR"

## First-run setup

```bash
git clone https://github.com/jaylfc/taOS.git
cd tinyagentos
uv sync --extra dev
cd desktop && npm install && npm run build && cd ..
uv run pytest tests/ --ignore=tests/e2e -n auto
```

Python 3.11+ and Node.js 22+ are required.
Loading
Loading