Commit graph

827 commits

Author SHA1 Message Date
Ahmed Allam
463b149bdb fix(budget): parked agents count as active; park never overwrites a stop
active_agents_except (finish_scan, wait_for_message) treats budget_paused as
active, so a root cannot finish the scan over a parked child. park_for_budget
only transitions a running agent, and the wake back to running happens under
the coordinator lock.
2026-09-30 03:13:40 +03:00
Ahmed Allam
d355838ea0 feat(budget): budget_policy=pause parks every agent at the limit until the operator resumes
Adds budget_policy: stop | pause to run_strix_scan / ReportUsageHooks /
AgentCoordinator, independent of interactive mode. Under pause the agents
get no budget warnings and no sub-agent reserve; each agent parks before
its next LLM call once spent >= limit or the scan is paused, sessions and
sandbox stay alive, and coordinator.resume_budget(max_budget_usd=...)
replaces the limit and wakes every parked agent without adding anything
to any session. coordinator.pause_budget() parks a running scan the same
way. In-flight calls are never cancelled, so spent may end above the
limit. Parked agents count as active for stop_agent.
2026-09-30 03:13:40 +03:00
ian-at-strix
0ff9f8c324
feat(tui): animate the wait_for_agents indicator (#1383) 2026-09-29 14:39:07 -07:00
ian-at-strix
954bc0d527
perf(prompt): load requested skills after a cache point (#1382)
Siblings differ only in the skills they were spawned with, but those came
first in <specialized_knowledge>, so their prompts diverged at 39%. Shared
skills and the catalog now come first, and the requested skills follow a
cache point, so siblings share 93%.

The extra system message takes a fourth Claude breakpoint, so the Bedrock
tool_config one goes: the first system breakpoint already covers the tools.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 00:35:22 +03:00
ian-at-strix
e66c56c473
perf(llm): give Claude a cache point before the per-run scope (#1376)
* perf(llm): give Claude a cache point before the per-run scope

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* refactor(llm): split the system prompt at a generic <cache_point> marker

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 00:35:22 +03:00
ian-at-strix
50425c2c99
perf(prompt): put per-run scope at the end of the system prompt (#1375)
* perf(prompt): put per-run scope at the end of the system prompt

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* test(prompt): assert scope renders once, after the shared prefix

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-30 00:35:21 +03:00
alex s
6ae036e6c1
docs(skills): refresh framework behavior and security testing guidance (#1372) 2026-09-29 10:11:02 -07:00
ian-at-strix
0c702723aa
fix(tui): suspend on ctrl+z (#1371)
Bubble Tea's raw mode clears ISIG, so ctrl+z reached the TUI as a key and
was ignored instead of stopping the job. Return tea.Suspend for it on every
screen, and re-enable mouse tracking on resume, since Bubble Tea's restore
brings back the alt screen but not the mouse mode.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 22:44:25 -04:00
Yash Aslekar
d6dd9dec26
fix(dev): make check-all non-mutating (#1360) 2026-09-27 17:47:20 -07:00
devin-ai-integration[bot]
ae38fe70cd
Fill in blank tool-call ids so strict providers accept the history (#1355) 2026-09-23 18:34:22 -07:00
alex s
4c1be22150
Let agents delete a vulnerability report they filed (#1354) 2026-09-23 17:25:23 -07:00
devin-ai-integration[bot]
56f7d45388
feat(llm): structured per-attempt provider request log with provider request ids (#1353) 2026-09-22 20:49:41 -07:00
yoni-at-strix
e158eab3f8
feat(mcp): initialize connections lazily (#1347)
* feat(mcp): initialize connections lazily

* fix(mcp): replace terminally dead sessions

* fix(mcp): improve targeted tool discovery

* fix(mcp): limit active tool fallback
2026-09-22 14:02:02 -04:00
Ahmed Allam
56e9ae982c runtime: read_only local sources become :ro bind mounts
A local_code target can mark its tree read_only; collect_local_sources
forwards the flag and build_bind_mounts mounts the tree read-only instead
of relying on host mode bits, skipping the per-metadata remounts since the
whole tree is already immutable. Used for pulled container image layouts.
2026-09-20 06:10:13 +03:00
Ahmed Allam
355a8bb437 fix(reporting): move the git blame hint to the end of the tool description 2026-09-18 21:39:35 +03:00
Ahmed Allam
77a0cf839b fix(reporting): make the git blame hint a casual inline note 2026-09-18 21:39:35 +03:00
Ahmed Allam
cafa4b19fd fix(reporting): keep git blame guidance to the technical_analysis field 2026-09-18 21:39:35 +03:00
alex s
976835194d
Prompt agents to include local Git blame in technical details (#1329)
* Enrich issue technical details with local Git blame

* Bound report history enrichment and require unambiguous repository identity

* test(history): drive attribution through the CLI scan setup and isolate git config

* Simplify Git blame attribution to existing reporting instructions

* Make local blame guidance reliable in live reporting
2026-09-18 13:05:53 -04:00
Ahmed Allam
4c1f00d1ee fix(runtime): tear the sandbox down when staging is cancelled
CancelledError is not an Exception, so a run cancelled during the extra-file
upload or unpack left a created-but-uncached sandbox running.
2026-09-17 21:53:35 +03:00
Ahmed Allam
46d7bdb290 fix(runtime): place extra files as agent-writable sandbox files on every backend
Extra files (knowledge trees, workspace files) reached the docker sandbox as
per-file read-only bind mounts whose parent directories docker created as
root, so the sandbox user could neither edit them nor create siblings. They
now travel as one tar archive uploaded after bring-up and unpacked as the
sandbox user, on every backend.
2026-09-17 21:53:35 +03:00
alex s
910c1ea4bb
fix(build): keep the TUI sidecar hook importable on hatchling 1.32.1 (#1325)
hatchling 1.32.1 made BuildHookInterface a two-parameter generic, so
subscripting it with one argument raises TypeError when the hook module
is imported and every from-source build fails. Subclass the unsubscripted
interface, which works on both the old and new generic signatures.
2026-09-16 14:25:38 -04:00
alex s
65d495bb7f
feat(config): STRIX_API_TYPE forces responses vs chat completions (#1324)
* Add api_type field to LlmSettings

Added 'api_type' field to LlmSettings for API path selection.

* Refactor API type handling in models.py

* Implement test for LlmSettings API type

Add test for API type override settings in LlmSettings.

* fix(tests): lint api_type test, cover the api_base override route, document STRIX_API_TYPE

* fix(models): keep LiteLLM chat-completions tool schema when STRIX_API_TYPE=responses

---------

Co-authored-by: RAJVARDHAN <95933896+vardhans07@users.noreply.github.com>
2026-09-16 11:13:30 -04:00
Ahmed Allam
2dadbb748a chore(deps): require litellm>=1.101.0 for gpt-6-astra max_completion_tokens mapping 2026-09-16 01:07:48 +03:00
Ahmed Allam
84f4108195 fix(web_search): send only the agent's query to Exa search
Exa /search is a neural search endpoint, not a chat model, so prepending
the Perplexity system prompt made Exa match the prompt's own vocabulary
(Kali, OWASP, apt, NIST) instead of the query. The system prompt stays
on the Perplexity path where it is a chat system message; the Exa
summary instruction is unchanged.
2026-09-13 19:40:50 +03:00
Elisabeth Rulke
0c4364a6a7 docs: add Vercel AI Gateway provider guide
Add Vercel AI Gateway as an LLM provider option, mirroring the existing
provider pages. New guide, an overview card, and a nav entry after
OpenRouter. Docs only.
2026-09-12 19:37:41 +03:00
Ahmed Allam
95e085eb6c feat(prompts): require http_exchange_ids for proxy-validated findings
Agents mostly left http_exchange_ids empty because the only nudge was the
parameter docstring. The REPORTING rules now state that a finding validated
through the proxy is not fully filed until the ids of its proving exchanges
(exploit plus baseline) are attached, copied from list_requests/view_request,
omitted only for findings with no captured HTTP at all, and attached after
the fact with update_vulnerability_report when needed. The Caido section
tells agents to note the ids as they test.
2026-09-10 03:50:17 +03:00
alex s
22959a7ba6
feat(reporting): link HTTP exchange evidence (#1281)
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-09-09 07:50:23 -07:00
devin-ai-integration[bot]
52b1923347
fix(models): frontier model check matches the model name only, never the provider route (#1280)
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-09-06 11:09:24 -07:00
Ahmed Allam
ff5c8cc8e4 chore: release v1.6.2 2026-09-05 04:22:29 +03:00
Ahmed Allam
afce7d95e8 fix(telemetry): classify setup-mode TUI preflight and preparation failures 2026-09-05 04:08:09 +03:00
Ahmed Allam
2e1db25786 feat(telemetry): classify error beacons by phase and exception class
error events now carry phase (startup/preflight/sandbox_init/agent_setup/
agent_loop) and the exception class name (plus its cause), never the message
or trace. Startup and preflight failures that exit(1) before the scan starts
are beaconed with a stable error_type instead of vanishing. scan_ended
distinguishes budget_exceeded, rate_limited, and headless agent_stopped
from user_exit.
2026-09-05 04:08:09 +03:00
devin-ai-integration[bot]
f4b0416b71
docs: update README and CLI links (#1272)
Co-authored-by: Ahmed Allam <ahmed39652003@gmail.com>
2026-09-04 17:56:08 -07:00
Ahmed Allam
c2c84f1131 chore(telemetry): drop unnecessary lock around loaded-skills set 2026-09-05 03:26:12 +03:00
Ahmed Allam
bb7e82b6ea chore(telemetry): drop per-load skill_loaded beacons, send anonymous events
Report the distinct set of skills used once on scan_ended instead of one
skill_loaded event per skill per prompt render. Mark PostHog events with
$process_person_profile=false (distinct_id is a throwaway session id, so
person profiles were never useful) and tag them with $lib/$lib_version.
2026-09-05 03:26:12 +03:00
Ahmed Allam
9cc9de8cdc fix(warmup): drop docker from WARMUP_MODULES
The Docker checks import the Docker SDK on the main thread before the
warm-up join, so warming it saves nothing and leaves one module shared
between the two threads during the startup window.
2026-09-05 02:45:34 +03:00
Ahmed Allam
a3bf864e1e test(warmup): assert wait_for_import_warmup blocks until the thread finishes 2026-09-05 02:45:34 +03:00
Ahmed Allam
e60fd83931 refactor(warmup): drop the orphan purge and join the warm-up once before the engine imports 2026-09-05 02:45:34 +03:00
Ahmed Allam
7f46dd17d3 fix(cli): wait for the import warm-up before importing the agents SDK on the main thread
The warm-up thread imports strix.core.runner while warm_up_llm and
preflight_model_connection import agents.models.interface. Both walk the
agents SDK graph from different entry points, CPython fails one side to
break the import-lock cycle, and the orphan purge then removes agents.*
from sys.modules while the main thread is still importing it, crashing
strix -n with KeyError: 'agents.models'.
2026-09-05 02:45:34 +03:00
devin-ai-integration[bot]
afa7c4a77f
feat(web_search): add Exa as a web search provider alongside Perplexity (#1270) 2026-09-04 10:34:28 -07:00
oyasumi
f6d9790ecb fix(viewer): show stopped run status 2026-09-04 01:10:10 +03:00
alex s
5d015df6b1
fix(cloud): print top-up instructions on 402 and guide oversize or archive --source (#1242)
- Every payment-required error now ends with a "Next step" line: the
  platform hint when one is sent, else the topup command and the billing
  URL for the configured platform. JSON output gets the same text as
  next_step. The platform hint is no longer repeated inside the error.
- An archive file passed to --source is rejected with guidance to pass
  the directory instead, which packs and excludes deps/build output.
- An oversize archive names its largest files and points to --exclude
  and --dry-run --show-files.
- uploads request help points to scans start --source for local code.
2026-09-02 15:26:37 -04:00
Ahmed Allam
1edafd3e80 fix(agents): stop parents waiting on finished non-interactive children
A non-interactive agent's loop returns after its terminal state, yet
send_message_to_agent kept reporting messages to it as delivered and the
parent then waited out wait_for_agents on a reply that could never come.

- AgentRuntime.resumable records whether the loop parks for wake-ups after a
  terminal state; run_agent_loop / _start_child_runner set it from interactive.
- AgentCoordinator.send returns False (nothing queued) for a terminal agent
  that is not resumable; send_message_to_agent surfaces target_status and
  delivery_status=not_delivered with a pointer to list_reports / get_report.
- wait_for_agents returns wait_outcome=no_active_agents at once when no other
  agent is running or waiting in a non-interactive run.
- agent_finish reads the reports the finishing agent filed from the report
  state and puts their ids in the completion report, the parent message
  (filed_report_ids) and its own return payload, so parents no longer have to
  infer what was filed from prose.
2026-09-02 22:11:12 +03:00
Ahmed Allam
f1e24fe3f2 chore: release v1.6.1 2026-09-02 19:05:46 +03:00
Ahmed Allam
e644f4a02c docs(readme): shorten the coding-agent skills paragraph 2026-09-02 18:46:33 +03:00
Ahmed Allam
1ebe1007e8 docs: keep the existing recommended model rows in the README 2026-09-02 18:35:45 +03:00
Ahmed Allam
53d2e5cfeb docs: note viewer steering, history, and report prerequisites 2026-09-02 18:35:45 +03:00
Ahmed Allam
7708f717d5 docs: trim crammed README sections and add cloud CLI and viewer docs pages 2026-09-02 18:35:45 +03:00
devin-ai-integration[bot]
a8642de76c
docs(readme): trim the strix cloud section to the essentials (#1237) 2026-09-02 07:19:56 -07:00
Ahmed Allam
75b89018d3 docs: use openrouter/z-ai/glm-5.3 as the default model in setup examples 2026-09-02 16:52:53 +03:00
Ahmed Allam
129f938094 fix(models): keep aggregator routes out of RECOMMENDED_MODEL_NAMES, family matching already accepts them 2026-09-02 16:52:53 +03:00