mount acp in the goosed server to migrate using acp protocols iteratively - #9097
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c573e696a2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| }; | ||
|
|
||
| const buildAcpWebSocketUrl = (baseUrl: string, token: string): string => { | ||
| const url = new URL('/acp', baseUrl); |
There was a problem hiding this comment.
Preserve backend base path when building ACP URL
Constructing the ACP endpoint with new URL('/acp', baseUrl) drops any path prefix in baseUrl, so an external backend configured at a subpath (for example https://host/goosed) will produce wss://host/acp instead of wss://host/goosed/acp. REST calls still use the configured base URL, so ACP becomes unreachable specifically for reverse-proxy/path-prefixed deployments.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 83e0a125da
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| <meta charset="UTF-8" /> | ||
| <meta | ||
| http-equiv="Content-Security-Policy" | ||
| content="default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self' http://127.0.0.1:* https: ws://127.0.0.1:* wss://127.0.0.1:*; object-src 'none'; font-src 'self' data: https:; media-src 'self' mediastream:; form-action 'none'; base-uri 'self'; manifest-src 'self'; worker-src 'self'; frame-src 'self' https: http:;" |
There was a problem hiding this comment.
Allow external ACP WebSocket origins in static CSP
The new ACP path opens a WebSocket to whatever backend get-acp-url returns, but this meta CSP only permits ws:///wss:// on 127.0.0.1. When users configure an external backend (for example https://secure.company.net:12604), the renderer’s ACP connection is blocked by this document policy, so _goose/config/extensions always fails and falls back to REST. Even though buildCSP() now adds external WS origins, browser CSP enforcement treats header and meta policies cumulatively, so the restrictive meta policy still blocks external ACP sockets.
Useful? React with 👍 / 👎.
* main: (102 commits) Dynamically refresh skill instructions each turn (#9217) Build non-vulkan linux variants using ubuntu 22.04 (#9211) fix(ui): show tool name in approval prompt (#9216) feat: add Atomic Chat as declarative OpenAI-compatible provider (#9210) chore: bump package.json versions from 0.19.1 to 0.20.0 (#9218) feat: support GOOSE_OAUTH_CALLBACK_PORT for stable OAuth redirect_uri (#9209) [RFC] feat(oauth): proactive token refresh to avoid re-auth on every session (#8386) fix: resolve Azure CLI on Windows by using az.cmd (#9215) fix: handle non-interactive terminal in goose configure on Windows (#9214) Better parsing of pasted html as markdown so agents understand (#9190) fix: persist accumulated cost in session DB to survive reload (#9191) fix(publish-npm): build binary from current SHA + add compat check (#9212) feat(desktop): add goose://new-session deep link to open fresh chat (#9196) Add PR previews using cloudflare pages (#9208) fix: prevent tool-use marker leakage in toolshim output (#8310) Prompt injection mitigation: update pattern-based detection (#9198) remove goose2 related skills (#9189) Switch GH pages deploy to actions/artifact workflow (#9025) fix(summon): re-apply canonical limits when delegate overrides model (#9183) Split code signing from build (#8587) ...
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3dca9a76f5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| <meta charset="UTF-8" /> | ||
| <meta | ||
| http-equiv="Content-Security-Policy" | ||
| content="default-src 'self'; style-src 'self' 'unsafe-inline'; script-src 'self' 'unsafe-inline'; img-src 'self' data: https:; connect-src 'self' http://127.0.0.1:* https: wss: ws://127.0.0.1:* wss://127.0.0.1:*; object-src 'none'; font-src 'self' data: https:; media-src 'self' mediastream:; form-action 'none'; base-uri 'self'; manifest-src 'self'; worker-src 'self'; frame-src 'self' https: http:;" |
There was a problem hiding this comment.
Permit ws:// external ACP origins in static CSP
When externalGoosed.url uses http://, get-acp-url builds a ws://.../acp?token=... endpoint, but the static meta CSP only allows ws://127.0.0.1:* (plus wss:) and does not allow arbitrary ws:// origins. Because the document still has this meta policy, ACP WebSocket connections to non-local HTTP backends are blocked in the renderer, so the new ACP extension-read path cannot work for that supported configuration and always falls back to REST.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a1db34f75b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| setExtensionWarnings(extensionResponse.warnings || []); | ||
| return extensionResponse.extensions; | ||
| }, [extensionsList]); | ||
| const { extensions, warnings } = await getConfiguredExtensions(); |
There was a problem hiding this comment.
Restore REST fallback for extension reads
refreshExtensions() now hard-depends on ACP (getConfiguredExtensions) and no longer falls back to the existing REST getExtensions path, so any ACP setup failure (for example an external backend that hasn’t mounted /acp yet, a blocked WebSocket policy, or transient ACP init errors) makes extension loading and getExtensions(true) fail. This also breaks post-mutation refreshes (addExtension/removeExtension) by throwing after a successful REST write, leaving the UI in an inconsistent state where the change succeeded server-side but the list does not refresh.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Intentionally removed — REST extension endpoints are being migrated out as part of the ACP rollout, so a fallback would be short-lived complexity in the direction we're moving away from.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 73c1ef7ee1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| let acp_router = create_acp_router(acp_server).layer(middleware::from_fn_with_state( | ||
| secret_key.clone(), | ||
| check_acp_token, | ||
| )); |
There was a problem hiding this comment.
Exempt ACP CORS preflight from token middleware
check_acp_token is applied as an outer layer on the ACP router, so unauthenticated OPTIONS /acp preflight requests are rejected with 401 before the inner CORS layer can answer them. Any browser client using ACP over HTTP (POST/DELETE with application/json) will fail CORS negotiation even with a valid token on the real request, because preflight requests do not carry that token. Please either skip auth for OPTIONS in check_acp_token or place CORS outside auth for the ACP branch.
Useful? React with 👍 / 👎.
jamadeo
left a comment
There was a problem hiding this comment.
Looks good to me. Are you thinking that we start with ACP+ methods that aren't session based before moving on to the session itself? I think after this merges, moving the core session over might be a good next step.
I was planning to use get session list initially for proving whether this approach is good. However there was pr (session instead of thread to fix the backwards compatibility) pending to merge and it was hard to prove before that pr merging into main. So i choose get extensions randomly instead. Now we are happy to use this mount approach., totally agree to start with session (core feature) for migration! |
…r's global config (#3) * remove goose2 related skills (aaif-goose#9189) * Prompt injection mitigation: update pattern-based detection (aaif-goose#9198) * fix: prevent tool-use marker leakage in toolshim output (aaif-goose#8310) Signed-off-by: Eugenio La Cava <eugeniolcv@gmail.com> Signed-off-by: Michael Neale <michael.neale@gmail.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Michael Neale <michael.neale@gmail.com> * Add PR previews using cloudflare pages (aaif-goose#9208) * feat(desktop): add goose://new-session deep link to open fresh chat (aaif-goose#9196) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(publish-npm): build binary from current SHA + add compat check (aaif-goose#9212) Signed-off-by: Alex Hancock <alexhancock@block.xyz> * fix: persist accumulated cost in session DB to survive reload (aaif-goose#9191) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Better parsing of pasted html as markdown so agents understand (aaif-goose#9190) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: handle non-interactive terminal in goose configure on Windows (aaif-goose#9214) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: resolve Azure CLI on Windows by using az.cmd (aaif-goose#9215) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * [RFC] feat(oauth): proactive token refresh to avoid re-auth on every session (aaif-goose#8386) Signed-off-by: Vincenzo Palazzo <vincenzopalazzodev@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: support GOOSE_OAUTH_CALLBACK_PORT for stable OAuth redirect_uri (aaif-goose#9209) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore: bump package.json versions from 0.19.1 to 0.20.0 (aaif-goose#9218) Signed-off-by: Alex Hancock <alexhancock@block.xyz> * feat: add Atomic Chat as declarative OpenAI-compatible provider (aaif-goose#9210) Co-authored-by: Yana Lyalyuk <yanalyalyuk@MacBook-Pro-Yana.local> Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): show tool name in approval prompt (aaif-goose#9216) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Build non-vulkan linux variants using ubuntu 22.04 (aaif-goose#9211) * Dynamically refresh skill instructions each turn (aaif-goose#9217) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Preserve thinking content for providers that require it (aaif-goose#8857) Signed-off-by: jh-block <jhugo@block.xyz> * improvement(tui): make spacing/layout nicer (aaif-goose#9243) * fix: zero out cost for local providers (ollama, local) (aaif-goose#9222) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(recipe): use mkdir -p for self-test workspace initialization (aaif-goose#9247) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: widen MOIM allowlist to suppress expected fix_conversation warnings (aaif-goose#9226) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: replace Venice custom provider with declarative config (aaif-goose#9234) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: add blog post for hooks feature (aaif-goose#9227) * fix(autovisualiser): use appInfo instead of clientInfo in MCP Apps init handshake (aaif-goose#9249) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore(deps): bump cliclack from 0.3.8 to 0.5.4 (aaif-goose#8966) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump tokio-tungstenite from 0.28.0 to 0.29.0 (aaif-goose#9271) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump tokio-cron-scheduler from 0.14.0 to 0.15.1 (aaif-goose#9267) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the cargo-minor-and-patch group with 6 updates (aaif-goose#9266) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump azure/trusted-signing-action from 1.0.0 to 2.0.0 (aaif-goose#9265) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/checkout from 4 to 6 (aaif-goose#9264) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/attest-build-provenance from 3.0.0 to 4.1.0 (aaif-goose#9263) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 (aaif-goose#9262) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * docs: document summon extension requirement for delegate and load tools (aaif-goose#9231) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: opt-in to vercel ai gateway leaderboard (aaif-goose#9259) * Remove Filesystem MCP extension from catalog (aaif-goose#9225) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * mount acp in the goosed server to migrate using acp protocols iteratively (aaif-goose#9097) * fix: zero out cost for local providers (ollama, local) (aaif-goose#9219) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: hooks guide (aaif-goose#9288) * feat(chatgpt_codex): add gpt-5.5 to known models (aaif-goose#9292) Signed-off-by: Michael Neale <michael.neale@gmail.com> * fix(cli): enable VT processing on Windows Console Host (aaif-goose#9248) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: improve Telegram gateway error reporting and connection reliability (aaif-goose#9223) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(desktop): eliminate cross-window deep link contamination (aaif-goose#9273) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Lifei Zhou <lifei@squareup.com> * feat(acp): pass session cwd param to acp providers (aaif-goose#9229) Signed-off-by: Matt Toohey <contact@matttoohey.com> Signed-off-by: Kalvin Chau <kalvin@block.xyz> * fix: reduce excessive MISSING_TRANSLATION warnings for fallback locales (aaif-goose#9294) * Flush OTLP traces reliably on exit with configurable timeout (aaif-goose#9228) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: activate custom provider after adding via configure (aaif-goose#9213) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(extension_manager): set TCP_USER_TIMEOUT on streamable HTTP clients (aaif-goose#9207) Signed-off-by: Hugues Clouâtre <hugues@linux.com> * fix: use current_exe() instead of PATH lookup when spawning goose (aaif-goose#9236) Signed-off-by: Matt Toohey <contact@matttoohey.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Add documentation for new provider SaladCloud AI Gateway (aaif-goose#9253) * fix(ui): align sidebar hamburger in macOS fullscreen (aaif-goose#9257) Signed-off-by: Cole McIntosh <colemcintosh6@gmail.com> * fix(desktop): ScheduleModal error message styling (aaif-goose#9278) Signed-off-by: SteveO <steve.officer@gmail.com> * fix(config): check file fallback when keyring has no entry (aaif-goose#9279) Signed-off-by: sheikhlimon <sheikhlimon404@gmail.com> * docs: add guide for connecting goose Desktop to a remote goosed server (aaif-goose#9275) Signed-off-by: James Crosswell <james.crosswell@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(otel): emit trace_output as span attribute instead of event (aaif-goose#9255) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat(tui): diff viewer (aaif-goose#9260) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat(cli): add `goose review` local code review command (aaif-goose#9114) Signed-off-by: Joah Gerstenberg <joahg@squareup.com> Signed-off-by: Joah Gerstenberg <joah@squareup.com> Co-authored-by: Joah Gerstenberg <joahg@squareup.com> Co-authored-by: Amp <amp@ampcode.com> * Structured per-provider config block, non-destructive provider switching (aaif-goose#8977) Signed-off-by: Douwe Osinga <douwe@squareup.com> Signed-off-by: Aaron Yourk <ayourk@gmail.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: reorganize (aaif-goose#9310) * feat(acp): paginate session list (aaif-goose#9199) Signed-off-by: Kalvin Chau <kalvin@block.xyz> * Add Linux musl CLI builds (aaif-goose#9240) Signed-off-by: jh-block <jhugo@block.xyz> * Remove vendored Windows binaries (aaif-goose#9318) Signed-off-by: jh-block <jhugo@block.xyz> * fix: stop killing goosed when a window closes (aaif-goose#9302) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Remove popular chat topics from new chat screen (aaif-goose#9307) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * flag for login shell PATH (aaif-goose#9313) * fix(cli): use plain '> ' prompt instead of goose emoji (aaif-goose#9305) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Add support for optional api_key configuration for declarative openai-engine providers (aaif-goose#9202) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat(hooks): PreToolUse denial (aaif-goose#9304) Signed-off-by: Alex Hancock <alexhancock@block.xyz> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: open-plugins generalization + skills (aaif-goose#9112) Co-authored-by: Jack Amadeo <jackamadeo@block.xyz> * Feat/summon subagent instructions (aaif-goose#9325) Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: add /goal command for agent self-evaluation before finishing (aaif-goose#9069) Signed-off-by: Michael Neale <michael.neale@gmail.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> * feat: slash commands (built-in, skill, recipe) in acp server (aaif-goose#9238) * chore: update canonical model registry (aaif-goose#9331) Signed-off-by: Bradley Axen <baxen@squareup.com> * Add Linux desktop Vulkan packages (aaif-goose#9323) Signed-off-by: jh-block <jhugo@block.xyz> * Add unified thinking effort control across all providers (aaif-goose#9242) Signed-off-by: jh-block <jhugo@block.xyz> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * Surface resolved Databricks model metadata (aaif-goose#9206) Signed-off-by: jh-block <jhugo@block.xyz> * fix(databricks): ensure parallel tool image responses don't interleave tool results (aaif-goose#9241) Signed-off-by: Steve Marshall <steve.marshall@fasthosts.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Include request URL in provider error messages (aaif-goose#9232) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore(release): bump version to 1.35.0 (minor) (aaif-goose#9150) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * feat: add Harbor eval runner (aaif-goose#9138) * [Prompt injection mitigation] Update pattern-based detection to reduce FPs (aaif-goose#9350) * chore(deps): bump openssl from 0.10.79 to 0.10.80 (aaif-goose#9334) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump idna from 3.10 to 3.15 in /scripts/provider-error-proxy (aaif-goose#9328) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump brace-expansion from 5.0.5 to 5.0.6 in /evals/open-model-gym/suite (aaif-goose#9311) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump fast-uri from 3.1.0 to 3.1.2 in /evals/open-model-gym/mcp-harness (aaif-goose#9117) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump fast-uri from 3.1.0 to 3.1.2 in /documentation (aaif-goose#9115) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump peter-evans/create-pull-request from 8.1.0 to 8.1.1 (aaif-goose#9106) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump ip-address and express-rate-limit in /evals/open-model-gym/mcp-harness (aaif-goose#9065) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump nanoid from 0.4.0 to 0.5.0 (aaif-goose#8965) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump mockall from 0.13.1 to 0.14.0 (aaif-goose#8962) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(goose): honor GOOSE_FAST_MODEL env var in ModelConfig::with_fast (aaif-goose#9296) Signed-off-by: Vladislav Dobromyslov <vladik.dobrik@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Preserve selected branch across project chats (aaif-goose#9010) Signed-off-by: morgmart <98432065+morgmart@users.noreply.github.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(anthropic): send empty object instead of null for tool_use input (aaif-goose#9355) Signed-off-by: fresh3nough <anonwurcod@proton.me> * fix(gateway): respect GOOSE_MAX_TURNS in gateway sessions (aaif-goose#9354) Signed-off-by: fresh3nough <anonwurcod@proton.me> * Add feature codemode to tests (aaif-goose#9344) * fix(desktop): remove unused fetch-metadata IPC handler (SSRF) (aaif-goose#9340) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: include full recipe parameter details in load/discovery output (aaif-goose#9233) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Add Repology badge to README (aaif-goose#9245) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: mention configurable timeout env vars in Ollama stream stall error (aaif-goose#9246) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * Add Scaleway provider (aaif-goose#9254) Co-authored-by: Quentin Champenois <qchampenois@scaleway.com> * Add goose://resume session deep link (aaif-goose#9343) * chore(deps): bump webpack-dev-server from 5.2.2 to 5.2.4 in /documentation (aaif-goose#9316) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix: preserve thinking content for provider context (aaif-goose#9314) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * feat(providers): add NEAR AI Cloud provider (aaif-goose#9352) Signed-off-by: Pierre LE GUEN <26087574+PierreLeGuen@users.noreply.github.com> * Revert "Split code signing from build (aaif-goose#8587)" (aaif-goose#9361) * fix(litellm): use context limit from /model/info for custom models (aaif-goose#9303) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * cleanup: remove current goose2 code (aaif-goose#9368) * feat(cli): make MAX_CODE_BLOCK_LINES configurable via env vars (aaif-goose#9301) Signed-off-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: tui command on goose-cli (aaif-goose#9385) * protocol cleanup (aaif-goose#9147) * chore(deps): bump actions-rust-lang/setup-rust-toolchain from 1.16.0 to 1.16.1 (aaif-goose#9370) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/setup-python from 5 to 6 (aaif-goose#9371) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump EmbarkStudios/cargo-deny-action from 2.0.17 to 2.0.19 (aaif-goose#9372) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump step-security/harden-runner from 2.19.1 to 2.19.4 (aaif-goose#9373) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump docker/build-push-action from 6.18.0 to 7.2.0 (aaif-goose#9374) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump qs and express in /documentation (aaif-goose#9375) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the cargo-minor-and-patch group with 12 updates (aaif-goose#9376) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump clap_mangen from 0.2.33 to 0.3.0 (aaif-goose#9377) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump sigstore-verify from 0.6.6 to 0.8.0 (aaif-goose#9378) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump shlex from 1.3.0 to 2.0.1 (aaif-goose#9379) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump lru from 0.16.3 to 0.18.0 (aaif-goose#9382) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump strum from 0.27.2 to 0.28.0 (aaif-goose#9384) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump ctor from 0.2.9 to 1.0.6 (aaif-goose#9380) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * chore(deps): bump agent-client-protocol from 0.11.1 to 0.12.1 (aaif-goose#9381) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * chore(deps): bump image from 0.24.9 to 0.25.10 (aaif-goose#9383) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(agents): serialize per-session agent creation to stop duplicate MCP init (aaif-goose#9357) Signed-off-by: fresh3nough <anonwurcod@proton.me> * Fix desktop chat search session limiting (aaif-goose#9366) Signed-off-by: Angie Jones <jones.angie@gmail.com> * Build summon instructions per turn (aaif-goose#9329) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: stats update (aaif-goose#9410) * Simplify UI customization (aaif-goose#9353) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore(deps): bump qs from 6.14.2 to 6.15.2 in /evals/open-model-gym/mcp-harness (aaif-goose#9395) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Add Turkish desktop locale (aaif-goose#9392) Signed-off-by: dejavu <dejavu@Mac.home> Co-authored-by: dejavu <dejavu@Mac.home> * Improve dependency hygiene (aaif-goose#9360) Signed-off-by: jh-block <jhugo@block.xyz> * fix(desktop): stop the main window growing taller on every launch (aaif-goose#9409) Signed-off-by: Asish Kumar <officialasishkumar@gmail.com> * Russian language support (aaif-goose#9406) Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * chore(release): bump version to 1.36.0 (minor) (aaif-goose#9417) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * add databricks ai gateway provider (aaif-goose#9274) Signed-off-by: Bradley Axen <baxen@squareup.com> * Prefer goose aliases for Databricks v2 inventory (aaif-goose#9430) Signed-off-by: Bradley Axen <baxen@squareup.com> * fix(ci): build linux x86_64 standard inside manylinux_2_28 for glibc 2.28+ compat (aaif-goose#9415) Signed-off-by: Andrew Mello <andrew@88plug.com> Co-authored-by: Alex Hancock <alex@alexhancock.com> Co-authored-by: jh-block <255854896+jh-block@users.noreply.github.com> * feat: add /model slash command to CLI for session model switching (aaif-goose#8747) Signed-off-by: Bradley Axen <baxen@squareup.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * local inference: stricter GGUF requirements, auto detection of tool calling support, fixed thinking output parsing (aaif-goose#9442) Signed-off-by: jh-block <jhugo@block.xyz> * fix: tolerate missing responses output (aaif-goose#9449) Signed-off-by: Angie Jones <jones.angie@gmail.com> * fix(ui): preserve pending env vars in Add Extension form (aaif-goose#9285) Signed-off-by: UGBOMEH OGOCHUKWU WILLIAMS <williamsugbomeh@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: make tool output size limit configurable via GOOSE_MAX_TOOL_RESPONSE_SIZE (aaif-goose#9256) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: make azure api-version query param optional (aaif-goose#9221) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(desktop): start new chat in current window from recipe param modal (aaif-goose#9422) Signed-off-by: Michael Neale <micn@block.xyz> * fix(desktop): refresh provider list in Switch Models picker (aaif-goose#9408) Signed-off-by: Asish Kumar <officialasishkumar@gmail.com> * feat(providers): add Alibaba (Qwen via DashScope) declarative provider (aaif-goose#9443) Signed-off-by: Jeremy Dawes <jeremy@jezweb.net> * feat(providers): add Perplexity as a declarative OpenAI-compatible provider (aaif-goose#9324) * chore(deps): bump sha2 from 0.10.9 to 0.11.0 (aaif-goose#8963) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * refactor: convert desktop v1 and goose-server extensions to ACP+ (aaif-goose#9448) * doc: Add Scaleway provider (aaif-goose#9423) Co-authored-by: Quentin Champenois <qchampenois@scaleway.com> * CLI to list skills with token counts (aaif-goose#9326) * feat: add `tui` feature flag to gate the tui command (aaif-goose#9428) Signed-off-by: Rodolfo Olivieri <rolivier@redhat.com> * Add Scholar Sidekick MCP extension (aaif-goose#9433) * Add ACP session system prompt setter (aaif-goose#9478) Signed-off-by: Bradley Axen <baxen@squareup.com> * fix(acp): forward ACP server context window size to clients (aaif-goose#9455) Signed-off-by: Matt Toohey <contact@matttoohey.com> * Expose raw provider supported models over ACP (aaif-goose#9475) Signed-off-by: Bradley Axen <baxen@squareup.com> Signed-off-by: Matt Toohey <contact@matttoohey.com> Co-authored-by: Matt Toohey <contact@matttoohey.com> * fix-A: per-run member credential on update_provider + fail-closed restore Per the streams plan-note (2026-08-12): one shared goosed container, per-run member credentials, never persisted, fail-closed on restore. - POST /agent/update_provider accepts optional api_key (per-run member credential). When present the provider is built from that key via new providers::create_with_explicit_key: anthropic (from_key mirrors from_env minus the secret lookup), openrouter (same mirror), openai (from_env endpoint resolution + auth swap via ApiClient::with_auth). Any other provider with api_key set is a hard 400 - never a silent from_env fallback. - Sessions running on an explicit key are marked with a new external_credential boolean in the session store (schema v14; only the marker is persisted, never the key). The marker is written BEFORE the provider swap so a crash in between fails closed. - Restore fails closed for marked sessions: Agent::restore_provider_from_session refuses to rebuild from env/config keys, and AgentManager::create_agent_locked skips the process-wide default-provider fallback. The provider stays unset until the caller (the bridge) re-supplies the key on its existing per-run update_provider call - recoverable by design. - Tests: request deserialization with/without api_key; anthropic and openrouter from_key carry the supplied key (auth inspected); unsupported provider rejected; external_credential round-trips through the session store; fail-closed restore constructs no env-based provider. Note: ui/desktop/openapi.json intentionally not regenerated (server- side fork; the new field is optional and additive). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix-A: per-run OpenAI-compatible host (api_host) for member Venice keys Additive follow-up to the per-run-credential patch. Lets a member's own key run in the shared goosed container against an OpenAI-compatible endpoint (e.g. Venice) that isn't the box's default OpenAI host. - OpenAiProvider::from_key_with_host(model, key, host): builds the ApiClient directly against the supplied host (parsed the same way as OPENAI_BASE_URL, so `/v1` vs versionless base_path is honored) with the member's bearer token. Reads NOTHING from process-global config - not OPENAI_BASE_URL/OPENAI_HOST/OPENAI_BASE_PATH, org/project, or custom headers - so the box's own OpenAI settings can't shadow a member's endpoint. Rejects empty key/host. - UpdateProviderRequest gains api_host: Option<String> (serde default, backward compatible). create_with_explicit_key grows an api_host param: openai + Some(host) -> from_key_with_host; openai + None keeps from_key. Never persisted; still marked external_credential (fail closed on restore) like every explicit-key path. - Tests: request deserialization with api_host; from_key_with_host targets the supplied host (host/base_path/auth asserted) and rejects empty host; create_with_explicit_key routes openai+api_host. No anthropic-oauth, no chatgpt_codex, no credential_kind - the OAuth impersonation paths were declined and are not built here. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix-A: per-session member OAuth for anthropic (claude-code) + codex Extend the per-run member-credential path (previously API-key only) to OAuth-native credentials for both anthropic (Claude subscription) and openai-codex (ChatGPT subscription), so goosed can run on a member's own OAuth token per session rather than a global disk token or the box key. Wire contract (UpdateProviderRequest, /agent/update_provider): - auth_token: Option<String> (#[serde(default)]) — member OAuth token - credential_kind: Option<String> (#[serde(default)]) — "oauth" | "api-key" Handler: external_credential = api_key.is_some() || auth_token.is_some(). credential_kind is authoritative; when absent, presence of auth_token/api_key selects the mode (so pre-OAuth api-key-only bodies still work: deploy-safe). Routing (providers::create_with_oauth_token, sibling of create_with_explicit_key): - provider "anthropic"/"claude-code" + oauth -> ClaudeCodeProvider, which injects CLAUDE_CODE_OAUTH_TOKEN into each fresh `claude` subprocess env (per-subprocess isolation; the real binary owns the OAuth/beta handshake). - provider "openai-codex"/"codex"/"chatgpt_codex"/"openai" + oauth -> ChatGptCodexProvider carrying a per-session TokenData instead of the global on-disk TokenCache; account id derived from the token's own JWT claims. Unsupported providers are a hard error, never an env-credential fallback. Secrets are #[serde(skip)] and redacted from Debug (manual impls). Tokens are never persisted. openapi.json regenerated (also closes the fix-A api_key/api_host carried gap). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(session): thread the session's member into stdio extension env (GOOSE_SESSION_MEMBER) Fabrica T-BYOM (2026-08-19): a goosed session started FOR A MEMBER now tells its stdio extensions which member they serve, so member-aware extensions (streamgen / websearch) can route their LLM calls through the Fabrica bridge on the member's OWN credential instead of the container's box-wide key. - StartAgentRequest.session_member: additive, serde(default) — the bridge's server-driven lane sends it in the body; deploy-order-safe for old callers. - start_agent prefers the edge-authed X-Member HEADER over the body field: on the SPA lane Caddy's forward_auth stamps X-Member from the verified session (a browser can forge the body but never that header). - SessionMemberState (extension_data key fabrica_session_member.v0): the shape-guarded ([a-z0-9_-]{1,40}) persisted form on the session — no session schema change, rides the existing versioned-key ExtensionData map. - ExtensionConfig::Stdio spawn injects GOOSE_SESSION_MEMBER beside the existing AGENT_SESSION_ID when the session carries a member; absent → memberless env, extensions keep the box-key path byte-identically. - ui/desktop/openapi.json regenerated (also picks up PR #1's additive auth_token/credential_kind on UpdateProviderRequest — the carried regen follow-up). The desktop TS client regen (npx @hey-api/openapi-ts) is deliberately skipped — Fabrica drives goosed over HTTP, no desktop app. cargo check green; cargo test -p goose --lib: 1434 passed / 91 failed — IDENTICAL 91 failures at the untouched pin 729254b (pre-existing local sqlx feature quirk); the 4 new SessionMemberState tests all pass. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(update_provider): per-run credential must not require the provider's global config resolve_provider_model_info() gates on check_provider_configured (the GLOBAL env/config credential) and instantiates the provider from env to fetch model info. It ran BEFORE the per-run credential branch, so a member key for a provider this goosed has no global key for (openrouter / venice / openai on a box carrying only ANTHROPIC_API_KEY) failed with 400 "Provider 'openrouter' is not configured" — even though create_with_explicit_key supports it. With an external credential the model-info lookup is now advisory (reasoning set when it resolves, left unset otherwise); the env-credential path is unchanged. Found on the fab_os_local twin running the BYOM GOOSE_SESSION_MEMBER cell (member on an OpenRouter key). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Signed-off-by: Eugenio La Cava <eugeniolcv@gmail.com> Signed-off-by: Michael Neale <michael.neale@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Signed-off-by: Alex Hancock <alexhancock@block.xyz> Signed-off-by: Vincenzo Palazzo <vincenzopalazzodev@gmail.com> Signed-off-by: jh-block <jhugo@block.xyz> Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Matt Toohey <contact@matttoohey.com> Signed-off-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: Hugues Clouâtre <hugues@linux.com> Signed-off-by: Cole McIntosh <colemcintosh6@gmail.com> Signed-off-by: SteveO <steve.officer@gmail.com> Signed-off-by: sheikhlimon <sheikhlimon404@gmail.com> Signed-off-by: James Crosswell <james.crosswell@gmail.com> Signed-off-by: Joah Gerstenberg <joahg@squareup.com> Signed-off-by: Joah Gerstenberg <joah@squareup.com> Signed-off-by: Aaron Yourk <ayourk@gmail.com> Signed-off-by: Bradley Axen <baxen@squareup.com> Signed-off-by: Steve Marshall <steve.marshall@fasthosts.com> Signed-off-by: Vladislav Dobromyslov <vladik.dobrik@gmail.com> Signed-off-by: morgmart <98432065+morgmart@users.noreply.github.com> Signed-off-by: fresh3nough <anonwurcod@proton.me> Signed-off-by: Pierre LE GUEN <26087574+PierreLeGuen@users.noreply.github.com> Signed-off-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Signed-off-by: Angie Jones <jones.angie@gmail.com> Signed-off-by: dejavu <dejavu@Mac.home> Signed-off-by: Asish Kumar <officialasishkumar@gmail.com> Signed-off-by: Andrew Mello <andrew@88plug.com> Signed-off-by: UGBOMEH OGOCHUKWU WILLIAMS <williamsugbomeh@gmail.com> Signed-off-by: Michael Neale <micn@block.xyz> Signed-off-by: Jeremy Dawes <jeremy@jezweb.net> Signed-off-by: Rodolfo Olivieri <rolivier@redhat.com> Co-authored-by: Jack Amadeo <jackamadeo@block.xyz> Co-authored-by: dorien-koelemeijer <62866702+dorien-koelemeijer@users.noreply.github.com> Co-authored-by: Eugenio <292452+eugenio@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Michael Neale <michael.neale@gmail.com> Co-authored-by: Douwe Osinga <douwe@block.xyz> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Alex Hancock <alexhancock@block.xyz> Co-authored-by: Vincenzo Palazzo <vincenzopalazzodev@gmail.com> Co-authored-by: yanalialiuk <ylialuke@gmail.com> Co-authored-by: Yana Lyalyuk <yanalyalyuk@MacBook-Pro-Yana.local> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: jh-block <jhugo@block.xyz> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Lifei Zhou <lifei@squareup.com> Co-authored-by: Angie Jones <jones.angie@gmail.com> Co-authored-by: Kalvin C <kalvinnchau@users.noreply.github.com> Co-authored-by: Hugues Clouâtre <15008125+clouatre@users.noreply.github.com> Co-authored-by: Matt Toohey <contact@matttoohey.com> Co-authored-by: Maksim <82521640+mgorkii-nlplogix@users.noreply.github.com> Co-authored-by: Cole McIntosh <82463175+colesmcintosh@users.noreply.github.com> Co-authored-by: Steve Officer <steve.officer+github@googlemail.com> Co-authored-by: Sheikh Limon <sheikhlimon404@gmail.com> Co-authored-by: James Crosswell <jamescrosswell@users.noreply.github.com> Co-authored-by: Joah Gerstenberg <joah@squareup.com> Co-authored-by: Joah Gerstenberg <joahg@squareup.com> Co-authored-by: Amp <amp@ampcode.com> Co-authored-by: ayourk <ayourk@users.noreply.github.com> Co-authored-by: Monroe Williams <monroe@pobox.com> Co-authored-by: Bradley Axen <baxen@squareup.com> Co-authored-by: Steve Marshall <steve.marshall@fasthosts.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> Co-authored-by: Lucas Kim <45152028+Raptors65@users.noreply.github.com> Co-authored-by: Vladislav <51202067+vampik33@users.noreply.github.com> Co-authored-by: morgmart <98432065+morgmart@users.noreply.github.com> Co-authored-by: fre$h <anonwurcod@proton.me> Co-authored-by: Rodolfo Olivieri <rodolfo.olivieri3@gmail.com> Co-authored-by: Quentin Champenois <26109239+Quentinchampenois@users.noreply.github.com> Co-authored-by: Quentin Champenois <qchampenois@scaleway.com> Co-authored-by: Tonchain <luckyimpetus@gmail.com> Co-authored-by: asim48-ctrl <asim48@gmail.com> Co-authored-by: Pierre LE GUEN <26087574+PierreLeGuen@users.noreply.github.com> Co-authored-by: spendletonliveaction <105226994+spendletonliveaction@users.noreply.github.com> Co-authored-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Co-authored-by: seneroner77-cmd <seneroner77@gmail.com> Co-authored-by: dejavu <dejavu@Mac.home> Co-authored-by: Asish Kumar <87874775+officialasishkumar@users.noreply.github.com> Co-authored-by: Dmitry Beskov <43372966+besdar@users.noreply.github.com> Co-authored-by: 88plug <19512127+88plug@users.noreply.github.com> Co-authored-by: Alex Hancock <alex@alexhancock.com> Co-authored-by: jh-block <255854896+jh-block@users.noreply.github.com> Co-authored-by: UGBOMEH OGOCHUKWU WILLIAMS <williamsugbomeh@gmail.com> Co-authored-by: Jeremy Dawes <jeremy@jezweb.net> Co-authored-by: James Liounis <james.liounis@perplexity.ai> Co-authored-by: Rodolfo Olivieri <rolivier@redhat.com> Co-authored-by: Mark Lavercombe <mlava@users.noreply.github.com> Co-authored-by: philoengineer <philoengineer@users.noreply.github.com>
Summary
This PR starts a spike on the desktop migration (this could be the reference app) from
goosedREST APIs to ACP .Instead of bundling both
goosedand thegoosebinary during migration, this adds/acpto the existinggoosedserver. Desktop can continue launching onlygoosed, while individual features move from REST to ACP one at a time.In the PR using acp to get extension list to prove this approach works.
Planned Migration Approach
During migration:
goosedas it does today.goosedserves both existing REST routes and the new/acproute./acpdirectly from the renderer over WebSocket.After migration:
goosed.goose serveACP server directly.Why this approach
This avoids increasing the desktop bundle size by shipping both
goosedandgooseduring migration, while still letting us validate ACP feature-by-feature.It also gives us a practical way to discover ACP gaps: migrate one feature, identify missing protocol/custom-method support, add it on the ACP side, then remove the old REST dependency.