Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
1d45f5b
🏡 feat: Remember Agent Workspace Defaults (#15843)
danny-avila Sep 12, 2026
7b71c3f
🥅 fix: Keep Tool Error Prefix Parsing In Bounds (#15857)
danny-avila Sep 12, 2026
fe351ee
🧨 fix: Defuse Skill and Artifact Parsing Backtracking (#15856)
danny-avila Sep 12, 2026
f3e2bf2
🧲 fix: Match Directory Users to Existing Principals (#15855)
danny-avila Sep 12, 2026
e7dea56
🧵 fix: Preserve Per-Message Inspection Budgets Through Provider Prepa…
danny-avila Sep 12, 2026
bd08a36
🔣 fix: Encode Images From Storage Keys (#15851)
Ricky-Hao Sep 12, 2026
5a2c4a0
🔐 fix: Stop an MCP Credential Refresh From Fencing Its Own Connection…
danny-avila Sep 12, 2026
5b4ec6b
🔎 feat: Filter and Sort the Sidebar Chats List (#15842)
berry-13 Sep 12, 2026
246e7e5
💠 fix: Paint Native Tool Verification Badges (#15862)
berry-13 Sep 12, 2026
fb13224
🧪 test: Restore Two Rotted Integration Suites and Run Every One in CI…
danny-avila Sep 12, 2026
ddd2dd8
🪢 fix: Recover a Failed MCP Server Once When Reinspections Overlap (#…
danny-avila Sep 12, 2026
037b033
📇 fix: Stop an MCP Credential Refresh From Fencing Its Own Catalog Re…
danny-avila Sep 12, 2026
f25242d
🦘 feat: Share Run-Scoped Files With Subagents (#15848)
usnavy13 Sep 13, 2026
7a83b8f
📟 feat: Record Safe Upstream Model Failures (#15800)
dustinhealy Sep 13, 2026
19eb249
🔠 feat: Render Safe Upstream Model Errors (#15837)
dustinhealy Sep 13, 2026
1163045
🖋️ feat: Seal Code Environment Choices Per Conversation (#15868)
danny-avila Sep 13, 2026
2e1ccbb
🪂 fix: Release Stalled MCP Catalog Recovery Without Dropping Refreshe…
danny-avila Sep 13, 2026
74fa60c
🔎 fix: Enforce WEB_SEARCH Role Permission on Agents (#15875)
danny-avila Sep 13, 2026
f43301f
🔭 feat: Conversation Trace Viewer (#15869)
danny-avila Sep 13, 2026
17c7b30
💤 fix: Preserve Dormant Workspace Bindings (#15877)
danny-avila Sep 13, 2026
3f2e477
🛬 fix: Land MCP OAuth Callbacks on Waiting Connections (#15876)
danny-avila Sep 13, 2026
e18606e
🚀 v0.8.8-rc3 (#15859)
danny-avila Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
4 changes: 4 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -729,6 +729,10 @@ TTS_API_KEY=
#==================================================#

# LIBRECHAT_CODE_API_KEY=

# Advertise the immutable per-conversation code-environment decision protocol.
# Enable only after every LibreChat API replica runs a version that supports protocol v1.
# CODE_ENVIRONMENT_DECISION_VERSION=1
# LIBRECHAT_CODE_BASEURL=
# Current self-hosted Code Interpreter deployments use per-user LibreChat JWTs outside local mode.
# Configure the matching public verifier on Code Interpreter; see:
Expand Down
23 changes: 13 additions & 10 deletions .github/workflows/agents-integration-tests.yml
Original file line number Diff line number Diff line change
@@ -1,19 +1,22 @@
name: Agents Integration Tests

# Runs the packages/api `src/agents/**` integration specs (e.g. the durable HITL
# checkpointer and cross-replica subagent delivery against real MongoDB and Redis). These
# are `*.integration.spec.ts`, which `test:ci` deliberately excludes — without this
# job they run nowhere and their regressions guard nothing.
name: Integration Tests

# Runs every packages/api `*.integration.spec.ts` / `*.integration.test.ts` suite (e.g. the
# durable HITL checkpointer and cross-replica subagent delivery against real MongoDB and
# Redis, the admin config secret registry against a real Config collection, MCP flows
# against in-process servers). `test:ci` deliberately excludes them, and the Redis-backed
# `*.cache_integration` / `*.stream_integration` suites run in cache-integration-tests.yml —
# without this job they run nowhere and their regressions guard nothing. Selection is by
# suffix, not folder, so a suite added anywhere under src is picked up.
on:
pull_request:
branches:
- main
- dev
- dev-staging
- release/*
# The suite builds and consumes data-provider and data-schemas and imports
# The suites build and consume data-provider and data-schemas and import
# across packages/api (the build-cache keys below hash all three src trees),
# so it must re-run on any of them — not just src/agents.
# so they must re-run on any of them.
paths:
- 'packages/api/src/**'
- 'packages/api/package.json'
Expand Down Expand Up @@ -106,9 +109,9 @@ jobs:
if: steps.cache-api.outputs.cache-hit != 'true'
run: npm run build:api

- name: Run agents integration tests
- name: Run integration tests
working-directory: packages/api
env:
NODE_ENV: test
REDIS_URI: redis://127.0.0.1:6379
run: npm run test:agents-integration
run: npm run test:integration
1 change: 1 addition & 0 deletions CONTEXT.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
- **Scheduled run admission**: The claimed-occurrence phase that rehydrates the owner, validates current schedule policy and agent reachability, resolves files and MCP readiness, and only then competes for durable generation capacity. It owns cancellation and lease revalidation until a generation slot is reserved; a slow or failed readiness check never occupies generation capacity.

- **Attached code environment**: A principal- or deployment-authorized stateful workspace owned by an outbound `librechat-code` worker on a user-chosen machine or VM. LibreChat selects it and enforces approval policy, Code API authenticates and dispatches to it, and the worker's local sandbox and capability flags remain the final execution ceiling. The environment interface is runtime-neutral: native SRT, WSL2, Docker/NsJail, and future adapters expose the same workspace operations without leaking host paths or runtime configuration into agent tools.
- **Conversation code-environment decision**: The immutable choice established by a conversation's first accepted submission between validated attached workspaces and continuing without an attached environment. Agent defaults and recent workspace preferences may suggest a draft choice, but only the persisted conversation decision authorizes attached workspace tool registration; later turns, retries, resumes, and alternate ingresses cannot upgrade or replace it.
- **Agent run envelope**: the versioned, JSON-safe request contract created after ingress authentication and protocol validation but before agent, provider, tool, or MCP initialization. It carries only the validated protocol payload and the minimum trusted principal identifiers. The execution host rehydrates all runtime state from those identifiers.
- **Agent execution context**: runtime-only, transport-free state rehydrated beside an Agent run envelope. It contains the authenticated user, application configuration, normalized request metadata, and resolved conversation facts needed by initialization, but never Express request/response objects or serialized credentials.
- **Agent execution host**: the protocol-neutral module that owns run admission, disconnect cancellation, provider-start fencing, and terminal settlement. Protocol implementations execute behind its callback interface; HTTP adapters retain validation and final stream rendering.
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# v0.8.8-rc2
# v0.8.8-rc3

# Base node image
FROM node:24.16.0-alpine AS node
Expand Down
2 changes: 1 addition & 1 deletion Dockerfile.multi
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Dockerfile.multi
# v0.8.8-rc2
# v0.8.8-rc3

# Set configurable max-old-space-size with default
ARG NODE_MAX_OLD_SPACE_SIZE=6144
Expand Down
47 changes: 23 additions & 24 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,30 +51,21 @@
</a>
</p>

## 🚀 What's New in v0.8.8-rc2

- **Agent run control:** Interrupt an Agent before visible answer text, steer runs with files and quoted excerpts, durably queue follow-ups, and recover saved partial work with **Keep going** or **Answer now**.
- **Agent activity:** Optional generated labels group reasoning and tool work, fold completed groups into live phase cards, keep generated files visible, summarize multi-step phases, and show the current reasoning direction.
- **Human-in-the-loop Agents:** Stream up to four related questions, pause for input or tool approval, and resume durably.
- **Unified Agent Builder:** Configure Skills, MCP, Code Interpreter, orchestration, Programmatic Tool Calling, model-spec controls, and per-tool background and intent settings in one Tools marketplace; Skills can be enabled for standalone runtime authoring without exposing the existing catalog.
- **Durable Agent automation:** Authenticated Agent Events support bound child actors, expected-action receipts, per-actor mailboxes, event batching, durable human pauses, and automatic detached Actions across built-in stream stores.
- **Deeper Subagent history:** Browse branch-aware child turns with bounded reasoning and stable live event views, load earlier activity, inspect event details, continue completed child chats, and automatically wake saved parent Agents when detached work settles.
- **Background tools:** Eligible Code Interpreter, MCP, Plugin, and Action tools can run while an Agent keeps working, with automatic delivery for supported completions and polling controls when needed.
- **Code Interpreter workflows:** Sandbox images return as viewable artifacts; highly experimental stateful sessions add scoped managed, attached, or personal environments, per-message file downloads, and guarded file-write and command permissions.
- **Agent extensibility:** Experimental Agent Plugins bundle deployment Skills, MCP servers, and opt-in command hooks; saved Agent teams run as isolated Subagent graphs.
- **Scheduled Chats (experimental):** Run saved Agents with presets or custom cron, selectable time zones, multi-day weekly cadence, and optional Chat Project destinations.
- **Memory and context:** Agents can use optionally isolated memory, preserve adaptive context fading across turns, and show categorized current-window usage, tokens, and optional cost.
- **Editable long pastes:** Long pasted text becomes an editable attachment that can be moved back into the composer; attachment-only turns and reliable Upload as Text downloads are also supported.
- **Projects, settings, and navigation:** Search conversation titles and message contents, manage project chats, use searchable settings and shortcuts, pin chats, choose clock/week conventions, and navigate faster on mobile.
- **Sharing and artifacts:** Stable shared links support personal copies; fullscreen previews, Mermaid export, PowerPoint templates, shell scripts, and original Office downloads expand file workflows.
- **Web search:** Keenable adds keyless search and page fetch, while SearXNG and Tavily gain richer controls and all web-tool egress uses stronger SSRF protection.
- **Security and authentication:** Default HTTP security headers, opt-in nonce CSP, authenticated local images, per-user Code Interpreter JWTs, stable SAML identity binding, live-session OpenID token refresh, and retired JWT-secret rejection harden deployments.
- **Models and reasoning:** Added GPT-5.6 with Responses reasoning controls, Claude Fable 5.1, Opus 5, and Sonnet 5, plus Gemini 3.8/3.7/3.6 Flash and Gemini 3.5 Flash-Lite.
- **Langfuse observability:** Configure encrypted in-app connections, tenant fanout, authenticated gateways, export-decision telemetry, and authorized session links in chats and shared views.
- **Administration:** Source-aware content filters can audit or block model-bound data, while tenant Insights, delegated configuration, encrypted secrets, and expiring violation scores improve operations.
- **Streaming and reliability:** Adaptive smoothing, Redis delta batching and failover recovery, automatic generation protocol v2, live MCP catalog refresh, Agent circuit breakers, and DocumentDB support improve long runs and scaled deployments.

Read the [full v0.8.8-rc2 changelog](https://www.librechat.ai/changelog/v0.8.8-rc2).
## 🚀 What's New in v0.8.8-rc3

- **Agent Management API (beta):** Create, discover, update, and delete Agents; manage Agent files and Skills; and authenticate machine clients through deployment-bound OIDC identities while preserving existing role and Agent access controls.
- **Attached workspaces (highly experimental):** Select or save a per-Agent default workspace for each managed or personal code worker, then let Agents inspect trees, read and search files, author changes, and run Bash with bounded timeouts. Personal workers support bounded self-service enrollment, readiness status, and per-Agent Git identity.
- **Background tool controls:** Optionally cancel ordinary background tools, including attached Bash, while keeping detached Subagent execution independent.
- **Code approval controls:** Choose **Ask**, **Allow**, or **Deny** for file writes and command execution where administrators permit it, including a **Full access** mode for trusted attached environments. File Search and Run Code also honor role grants.
- **Manual context compaction:** Start a summarize-only turn before the context window fills while preserving recent conversation content according to the deployment's summarization policy.
- **Context Usage:** Inspect dialogue, retained tool traffic, Agent instructions, cache, cost, and runway pressure without double-counting category subsets.
- **Unified attachments:** Upload once and let LibreChat route content to the model or extracted text, then provision File Search and Code tools only when needed.
- **Models:** Added GPT-6 Astra for the OpenAI and Agents endpoints, with Responses API routing and tool-call support.
- **Agent and chat UI:** Unified tool activity, reasoning, search, and Agent workflows; added one draggable Pinned section for chats and favorites, morphing state icons, high-contrast themes, rich-text message copying, clearer sidebar titles, and refined live phase layouts.
- **Observability:** Export correlated application logs through OpenTelemetry, configure allowlisted Langfuse trace identity and metadata, tag browser diagnostics with client build IDs, and scope Insights to authorized Agents.
- **Reliability and security:** Strengthened Agent continuation and checkpoint recovery, Redis liveness detection, DocumentDB coordination, OpenID and MCP OAuth sessions, shared-link throttling, tenant isolation, attachment bounds, and upload error handling.

Read the [full v0.8.8-rc3 changelog](https://www.librechat.ai/changelog/v0.8.8-rc3).

# ✨ Features

Expand Down Expand Up @@ -102,6 +93,8 @@ Read the [full v0.8.8-rc2 changelog](https://www.librechat.ai/changelog/v0.8.8-r
- [Skills](https://www.librechat.ai/docs/features/skills): Create reusable `SKILL.md` instruction bundles for manual, automatic, or always-on agent workflows
- [Agent Plugins](https://www.librechat.ai/docs/features/agent_plugins): Experimentally bundle deployment Skills and MCP servers into startup-loaded packages
- [Subagents](https://www.librechat.ai/docs/features/subagents): Delegate focused work to isolated child agent runs with their own context windows
- Agent Management API: Automate Agent, file, and Skill management with deployment-bound OIDC clients
- Attached Code Workspaces: Let Agents inspect, search, edit, and run commands in managed or personal workspaces (highly experimental)
- Compatible with Custom Endpoints, OpenAI, Azure, Anthropic, AWS Bedrock, Google, Vertex AI, Responses API, and more
- [Model Context Protocol (MCP) Support](https://modelcontextprotocol.io/clients#librechat) for Tools

Expand All @@ -126,10 +119,12 @@ Read the [full v0.8.8-rc2 changelog](https://www.librechat.ai/changelog/v0.8.8-r
- Edit, Resubmit, and Continue Messages with Conversation branching
- Create and share prompts with specific users and groups
- [Fork Messages & Conversations](https://www.librechat.ai/docs/features/fork) for Advanced Context control
- Compact long conversations on demand while preserving recent context

- 💬 **Multimodal & File Interactions**:
- Upload and analyze images with Claude 3, GPT-4.5, GPT-4o, o1, Llama-Vision, and Gemini 📸
- Chat with Files using Custom Endpoints, OpenAI, Azure, Anthropic, AWS Bedrock, & Google 🗃️
- Copy messages as formatted rich text for documents, email, and collaboration apps

- 🌎 **Multilingual UI**:
- English, 中文 (简体), 中文 (繁體), العربية, Deutsch, Español, Français, Italiano
Expand All @@ -142,6 +137,10 @@ Read the [full v0.8.8-rc2 changelog](https://www.librechat.ai/changelog/v0.8.8-r

- 🎨 **Customizable Interface**:
- Customizable Dropdown & Interface that adapts to both power users and newcomers
- Light, dark, system, and high-contrast appearance modes

- 📈 **Observability**:
- Export traces and logs with OpenTelemetry and connect Langfuse for Agent and model insights

- 🌊 **[Resumable Streams](https://www.librechat.ai/docs/features/resumable_streams)**:
- Never lose a response: AI responses automatically reconnect and resume if your connection drops
Expand Down
1 change: 1 addition & 0 deletions api/config/index.js
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,7 @@ function getActionFlowStateManager(flowsCache) {
if (!actionFlowManager) {
actionFlowManager = new FlowStateManager(flowsCache, {
ttl: Time.ONE_MINUTE * 3,
redisScriptExecutor: evalKeyvRedisScript,
});
}
return actionFlowManager;
Expand Down
3 changes: 2 additions & 1 deletion api/db/indexSync.js
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ const mongoose = require('mongoose');
const { MeiliSearch } = require('meilisearch');
const { logger } = require('@librechat/data-schemas');
const { CacheKeys } = require('librechat-data-provider');
const { isEnabled, FlowStateManager } = require('@librechat/api');
const { isEnabled, FlowStateManager, evalKeyvRedisScript } = require('@librechat/api');
const { getLogStores } = require('~/cache');
const { batchResetMeiliFlags } = require('./utils');

Expand Down Expand Up @@ -372,6 +372,7 @@ async function indexSync() {

const flowManager = new FlowStateManager(flowsCache, {
ttl: 60000 * 10, // 10 minutes TTL for sync operations
redisScriptExecutor: evalKeyvRedisScript,
});

// Use a unique flow ID for the sync operation
Expand Down
4 changes: 2 additions & 2 deletions api/package.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"name": "@librechat/backend",
"version": "v0.8.8-rc2",
"version": "v0.8.8-rc3",
"description": "",
"scripts": {
"start": "echo 'please run this from the root directory'",
Expand Down Expand Up @@ -46,7 +46,7 @@
"@azure/storage-blob": "^12.30.0",
"@google/genai": "^2.8.0",
"@keyv/redis": "5.1.6",
"@librechat/agents": "^3.8.5",
"@librechat/agents": "^3.8.6",
"@librechat/api": "*",
"@librechat/data-schemas": "*",
"@microsoft/microsoft-graph-client": "^3.0.7",
Expand Down
5 changes: 2 additions & 3 deletions api/server/controllers/agents/__tests__/callbacks.spec.js
Original file line number Diff line number Diff line change
Expand Up @@ -22,9 +22,8 @@ jest.mock('@librechat/api', () => ({
}
: null,
),
isCodeSessionToolName: jest.fn((name) =>
['execute_code', 'bash_tool', 'read_file'].includes(name),
),
isCodeArtifactToolOutput: jest.requireActual('@librechat/api').isCodeArtifactToolOutput,
isCodeSessionToolName: jest.requireActual('@librechat/api').isCodeSessionToolName,
}));

jest.mock('@librechat/data-schemas', () => ({
Expand Down
Loading
Loading