feat: tui command on goose-cli - #9385
Conversation
| Ok(cmd) | ||
| } | ||
| } | ||
| } |
There was a problem hiding this comment.
so this doesn't actually run the current goose binary as the source of ACP, right?
There was a problem hiding this comment.
The TUI does. So we have some psuedo-cycles here... different commands but:
goose tui -> runs TUI -> uses goose acp (or connects to server via HTTP/WS)
| } | ||
| dir = d.parent().map(Path::to_path_buf); | ||
| } | ||
| } |
There was a problem hiding this comment.
what is the use case here? if I am developing the TUI, am I likely to use this path?
There was a problem hiding this comment.
Yeah I thought it could be helpful that when running cargo run --bin goose -- tui it also runs the tui from source
8378a81 to
75dfc73
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 75dfc73d0c
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| if let Some(script) = find_local_script() { | ||
| return TuiSource::LocalScript(script); | ||
| } | ||
| let spec = std::env::var(TUI_NPM_SPEC_ENV).unwrap_or_else(|_| DEFAULT_NPM_SPEC.to_string()); | ||
| TuiSource::Npx(spec) |
There was a problem hiding this comment.
Honor GOOSE_TUI_SCRIPT override before auto-discovery
The new command advertises GOOSE_TUI_SCRIPT as the highest-priority source, but resolve_source never reads that variable and always chooses auto-discovered local script or npx. In environments that rely on pinning a specific built tui.js (e.g., CI, custom packaging, or local debugging), the override currently cannot work and users cannot force the intended script when a local checkout is present.
Useful? React with 👍 / 👎.
…r's global config (#3) * remove goose2 related skills (aaif-goose#9189) * Prompt injection mitigation: update pattern-based detection (aaif-goose#9198) * fix: prevent tool-use marker leakage in toolshim output (aaif-goose#8310) Signed-off-by: Eugenio La Cava <eugeniolcv@gmail.com> Signed-off-by: Michael Neale <michael.neale@gmail.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Michael Neale <michael.neale@gmail.com> * Add PR previews using cloudflare pages (aaif-goose#9208) * feat(desktop): add goose://new-session deep link to open fresh chat (aaif-goose#9196) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(publish-npm): build binary from current SHA + add compat check (aaif-goose#9212) Signed-off-by: Alex Hancock <alexhancock@block.xyz> * fix: persist accumulated cost in session DB to survive reload (aaif-goose#9191) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Better parsing of pasted html as markdown so agents understand (aaif-goose#9190) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: handle non-interactive terminal in goose configure on Windows (aaif-goose#9214) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: resolve Azure CLI on Windows by using az.cmd (aaif-goose#9215) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * [RFC] feat(oauth): proactive token refresh to avoid re-auth on every session (aaif-goose#8386) Signed-off-by: Vincenzo Palazzo <vincenzopalazzodev@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: support GOOSE_OAUTH_CALLBACK_PORT for stable OAuth redirect_uri (aaif-goose#9209) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore: bump package.json versions from 0.19.1 to 0.20.0 (aaif-goose#9218) Signed-off-by: Alex Hancock <alexhancock@block.xyz> * feat: add Atomic Chat as declarative OpenAI-compatible provider (aaif-goose#9210) Co-authored-by: Yana Lyalyuk <yanalyalyuk@MacBook-Pro-Yana.local> Co-authored-by: Cursor <cursoragent@cursor.com> * fix(ui): show tool name in approval prompt (aaif-goose#9216) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Build non-vulkan linux variants using ubuntu 22.04 (aaif-goose#9211) * Dynamically refresh skill instructions each turn (aaif-goose#9217) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Preserve thinking content for providers that require it (aaif-goose#8857) Signed-off-by: jh-block <jhugo@block.xyz> * improvement(tui): make spacing/layout nicer (aaif-goose#9243) * fix: zero out cost for local providers (ollama, local) (aaif-goose#9222) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(recipe): use mkdir -p for self-test workspace initialization (aaif-goose#9247) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: widen MOIM allowlist to suppress expected fix_conversation warnings (aaif-goose#9226) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: replace Venice custom provider with declarative config (aaif-goose#9234) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: add blog post for hooks feature (aaif-goose#9227) * fix(autovisualiser): use appInfo instead of clientInfo in MCP Apps init handshake (aaif-goose#9249) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore(deps): bump cliclack from 0.3.8 to 0.5.4 (aaif-goose#8966) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump tokio-tungstenite from 0.28.0 to 0.29.0 (aaif-goose#9271) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump tokio-cron-scheduler from 0.14.0 to 0.15.1 (aaif-goose#9267) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the cargo-minor-and-patch group with 6 updates (aaif-goose#9266) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump azure/trusted-signing-action from 1.0.0 to 2.0.0 (aaif-goose#9265) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/checkout from 4 to 6 (aaif-goose#9264) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/attest-build-provenance from 3.0.0 to 4.1.0 (aaif-goose#9263) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 (aaif-goose#9262) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * docs: document summon extension requirement for delegate and load tools (aaif-goose#9231) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: opt-in to vercel ai gateway leaderboard (aaif-goose#9259) * Remove Filesystem MCP extension from catalog (aaif-goose#9225) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * mount acp in the goosed server to migrate using acp protocols iteratively (aaif-goose#9097) * fix: zero out cost for local providers (ollama, local) (aaif-goose#9219) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: hooks guide (aaif-goose#9288) * feat(chatgpt_codex): add gpt-5.5 to known models (aaif-goose#9292) Signed-off-by: Michael Neale <michael.neale@gmail.com> * fix(cli): enable VT processing on Windows Console Host (aaif-goose#9248) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: improve Telegram gateway error reporting and connection reliability (aaif-goose#9223) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(desktop): eliminate cross-window deep link contamination (aaif-goose#9273) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Lifei Zhou <lifei@squareup.com> * feat(acp): pass session cwd param to acp providers (aaif-goose#9229) Signed-off-by: Matt Toohey <contact@matttoohey.com> Signed-off-by: Kalvin Chau <kalvin@block.xyz> * fix: reduce excessive MISSING_TRANSLATION warnings for fallback locales (aaif-goose#9294) * Flush OTLP traces reliably on exit with configurable timeout (aaif-goose#9228) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: activate custom provider after adding via configure (aaif-goose#9213) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(extension_manager): set TCP_USER_TIMEOUT on streamable HTTP clients (aaif-goose#9207) Signed-off-by: Hugues Clouâtre <hugues@linux.com> * fix: use current_exe() instead of PATH lookup when spawning goose (aaif-goose#9236) Signed-off-by: Matt Toohey <contact@matttoohey.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Add documentation for new provider SaladCloud AI Gateway (aaif-goose#9253) * fix(ui): align sidebar hamburger in macOS fullscreen (aaif-goose#9257) Signed-off-by: Cole McIntosh <colemcintosh6@gmail.com> * fix(desktop): ScheduleModal error message styling (aaif-goose#9278) Signed-off-by: SteveO <steve.officer@gmail.com> * fix(config): check file fallback when keyring has no entry (aaif-goose#9279) Signed-off-by: sheikhlimon <sheikhlimon404@gmail.com> * docs: add guide for connecting goose Desktop to a remote goosed server (aaif-goose#9275) Signed-off-by: James Crosswell <james.crosswell@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(otel): emit trace_output as span attribute instead of event (aaif-goose#9255) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat(tui): diff viewer (aaif-goose#9260) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat(cli): add `goose review` local code review command (aaif-goose#9114) Signed-off-by: Joah Gerstenberg <joahg@squareup.com> Signed-off-by: Joah Gerstenberg <joah@squareup.com> Co-authored-by: Joah Gerstenberg <joahg@squareup.com> Co-authored-by: Amp <amp@ampcode.com> * Structured per-provider config block, non-destructive provider switching (aaif-goose#8977) Signed-off-by: Douwe Osinga <douwe@squareup.com> Signed-off-by: Aaron Yourk <ayourk@gmail.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: reorganize (aaif-goose#9310) * feat(acp): paginate session list (aaif-goose#9199) Signed-off-by: Kalvin Chau <kalvin@block.xyz> * Add Linux musl CLI builds (aaif-goose#9240) Signed-off-by: jh-block <jhugo@block.xyz> * Remove vendored Windows binaries (aaif-goose#9318) Signed-off-by: jh-block <jhugo@block.xyz> * fix: stop killing goosed when a window closes (aaif-goose#9302) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Remove popular chat topics from new chat screen (aaif-goose#9307) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * flag for login shell PATH (aaif-goose#9313) * fix(cli): use plain '> ' prompt instead of goose emoji (aaif-goose#9305) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Add support for optional api_key configuration for declarative openai-engine providers (aaif-goose#9202) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat(hooks): PreToolUse denial (aaif-goose#9304) Signed-off-by: Alex Hancock <alexhancock@block.xyz> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: open-plugins generalization + skills (aaif-goose#9112) Co-authored-by: Jack Amadeo <jackamadeo@block.xyz> * Feat/summon subagent instructions (aaif-goose#9325) Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: add /goal command for agent self-evaluation before finishing (aaif-goose#9069) Signed-off-by: Michael Neale <michael.neale@gmail.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> * feat: slash commands (built-in, skill, recipe) in acp server (aaif-goose#9238) * chore: update canonical model registry (aaif-goose#9331) Signed-off-by: Bradley Axen <baxen@squareup.com> * Add Linux desktop Vulkan packages (aaif-goose#9323) Signed-off-by: jh-block <jhugo@block.xyz> * Add unified thinking effort control across all providers (aaif-goose#9242) Signed-off-by: jh-block <jhugo@block.xyz> Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> * Surface resolved Databricks model metadata (aaif-goose#9206) Signed-off-by: jh-block <jhugo@block.xyz> * fix(databricks): ensure parallel tool image responses don't interleave tool results (aaif-goose#9241) Signed-off-by: Steve Marshall <steve.marshall@fasthosts.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Include request URL in provider error messages (aaif-goose#9232) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore(release): bump version to 1.35.0 (minor) (aaif-goose#9150) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * feat: add Harbor eval runner (aaif-goose#9138) * [Prompt injection mitigation] Update pattern-based detection to reduce FPs (aaif-goose#9350) * chore(deps): bump openssl from 0.10.79 to 0.10.80 (aaif-goose#9334) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump idna from 3.10 to 3.15 in /scripts/provider-error-proxy (aaif-goose#9328) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump brace-expansion from 5.0.5 to 5.0.6 in /evals/open-model-gym/suite (aaif-goose#9311) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump fast-uri from 3.1.0 to 3.1.2 in /evals/open-model-gym/mcp-harness (aaif-goose#9117) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump fast-uri from 3.1.0 to 3.1.2 in /documentation (aaif-goose#9115) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump peter-evans/create-pull-request from 8.1.0 to 8.1.1 (aaif-goose#9106) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump ip-address and express-rate-limit in /evals/open-model-gym/mcp-harness (aaif-goose#9065) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump nanoid from 0.4.0 to 0.5.0 (aaif-goose#8965) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump mockall from 0.13.1 to 0.14.0 (aaif-goose#8962) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * feat(goose): honor GOOSE_FAST_MODEL env var in ModelConfig::with_fast (aaif-goose#9296) Signed-off-by: Vladislav Dobromyslov <vladik.dobrik@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Preserve selected branch across project chats (aaif-goose#9010) Signed-off-by: morgmart <98432065+morgmart@users.noreply.github.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(anthropic): send empty object instead of null for tool_use input (aaif-goose#9355) Signed-off-by: fresh3nough <anonwurcod@proton.me> * fix(gateway): respect GOOSE_MAX_TURNS in gateway sessions (aaif-goose#9354) Signed-off-by: fresh3nough <anonwurcod@proton.me> * Add feature codemode to tests (aaif-goose#9344) * fix(desktop): remove unused fetch-metadata IPC handler (SSRF) (aaif-goose#9340) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: include full recipe parameter details in load/discovery output (aaif-goose#9233) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * Add Repology badge to README (aaif-goose#9245) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: mention configurable timeout env vars in Ollama stream stall error (aaif-goose#9246) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * Add Scaleway provider (aaif-goose#9254) Co-authored-by: Quentin Champenois <qchampenois@scaleway.com> * Add goose://resume session deep link (aaif-goose#9343) * chore(deps): bump webpack-dev-server from 5.2.2 to 5.2.4 in /documentation (aaif-goose#9316) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix: preserve thinking content for provider context (aaif-goose#9314) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * feat(providers): add NEAR AI Cloud provider (aaif-goose#9352) Signed-off-by: Pierre LE GUEN <26087574+PierreLeGuen@users.noreply.github.com> * Revert "Split code signing from build (aaif-goose#8587)" (aaif-goose#9361) * fix(litellm): use context limit from /model/info for custom models (aaif-goose#9303) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * cleanup: remove current goose2 code (aaif-goose#9368) * feat(cli): make MAX_CODE_BLOCK_LINES configurable via env vars (aaif-goose#9301) Signed-off-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: tui command on goose-cli (aaif-goose#9385) * protocol cleanup (aaif-goose#9147) * chore(deps): bump actions-rust-lang/setup-rust-toolchain from 1.16.0 to 1.16.1 (aaif-goose#9370) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump actions/setup-python from 5 to 6 (aaif-goose#9371) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump EmbarkStudios/cargo-deny-action from 2.0.17 to 2.0.19 (aaif-goose#9372) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump step-security/harden-runner from 2.19.1 to 2.19.4 (aaif-goose#9373) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump docker/build-push-action from 6.18.0 to 7.2.0 (aaif-goose#9374) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump qs and express in /documentation (aaif-goose#9375) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the cargo-minor-and-patch group with 12 updates (aaif-goose#9376) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump clap_mangen from 0.2.33 to 0.3.0 (aaif-goose#9377) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump sigstore-verify from 0.6.6 to 0.8.0 (aaif-goose#9378) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump shlex from 1.3.0 to 2.0.1 (aaif-goose#9379) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump lru from 0.16.3 to 0.18.0 (aaif-goose#9382) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump strum from 0.27.2 to 0.28.0 (aaif-goose#9384) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump ctor from 0.2.9 to 1.0.6 (aaif-goose#9380) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * chore(deps): bump agent-client-protocol from 0.11.1 to 0.12.1 (aaif-goose#9381) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * chore(deps): bump image from 0.24.9 to 0.25.10 (aaif-goose#9383) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix(agents): serialize per-session agent creation to stop duplicate MCP init (aaif-goose#9357) Signed-off-by: fresh3nough <anonwurcod@proton.me> * Fix desktop chat search session limiting (aaif-goose#9366) Signed-off-by: Angie Jones <jones.angie@gmail.com> * Build summon instructions per turn (aaif-goose#9329) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * docs: stats update (aaif-goose#9410) * Simplify UI customization (aaif-goose#9353) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * chore(deps): bump qs from 6.14.2 to 6.15.2 in /evals/open-model-gym/mcp-harness (aaif-goose#9395) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * Add Turkish desktop locale (aaif-goose#9392) Signed-off-by: dejavu <dejavu@Mac.home> Co-authored-by: dejavu <dejavu@Mac.home> * Improve dependency hygiene (aaif-goose#9360) Signed-off-by: jh-block <jhugo@block.xyz> * fix(desktop): stop the main window growing taller on every launch (aaif-goose#9409) Signed-off-by: Asish Kumar <officialasishkumar@gmail.com> * Russian language support (aaif-goose#9406) Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * chore(release): bump version to 1.36.0 (minor) (aaif-goose#9417) Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * add databricks ai gateway provider (aaif-goose#9274) Signed-off-by: Bradley Axen <baxen@squareup.com> * Prefer goose aliases for Databricks v2 inventory (aaif-goose#9430) Signed-off-by: Bradley Axen <baxen@squareup.com> * fix(ci): build linux x86_64 standard inside manylinux_2_28 for glibc 2.28+ compat (aaif-goose#9415) Signed-off-by: Andrew Mello <andrew@88plug.com> Co-authored-by: Alex Hancock <alex@alexhancock.com> Co-authored-by: jh-block <255854896+jh-block@users.noreply.github.com> * feat: add /model slash command to CLI for session model switching (aaif-goose#8747) Signed-off-by: Bradley Axen <baxen@squareup.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * local inference: stricter GGUF requirements, auto detection of tool calling support, fixed thinking output parsing (aaif-goose#9442) Signed-off-by: jh-block <jhugo@block.xyz> * fix: tolerate missing responses output (aaif-goose#9449) Signed-off-by: Angie Jones <jones.angie@gmail.com> * fix(ui): preserve pending env vars in Add Extension form (aaif-goose#9285) Signed-off-by: UGBOMEH OGOCHUKWU WILLIAMS <williamsugbomeh@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * feat: make tool output size limit configurable via GOOSE_MAX_TOOL_RESPONSE_SIZE (aaif-goose#9256) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix: make azure api-version query param optional (aaif-goose#9221) Signed-off-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Douwe Osinga <douwe@squareup.com> * fix(desktop): start new chat in current window from recipe param modal (aaif-goose#9422) Signed-off-by: Michael Neale <micn@block.xyz> * fix(desktop): refresh provider list in Switch Models picker (aaif-goose#9408) Signed-off-by: Asish Kumar <officialasishkumar@gmail.com> * feat(providers): add Alibaba (Qwen via DashScope) declarative provider (aaif-goose#9443) Signed-off-by: Jeremy Dawes <jeremy@jezweb.net> * feat(providers): add Perplexity as a declarative OpenAI-compatible provider (aaif-goose#9324) * chore(deps): bump sha2 from 0.10.9 to 0.11.0 (aaif-goose#8963) Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> * refactor: convert desktop v1 and goose-server extensions to ACP+ (aaif-goose#9448) * doc: Add Scaleway provider (aaif-goose#9423) Co-authored-by: Quentin Champenois <qchampenois@scaleway.com> * CLI to list skills with token counts (aaif-goose#9326) * feat: add `tui` feature flag to gate the tui command (aaif-goose#9428) Signed-off-by: Rodolfo Olivieri <rolivier@redhat.com> * Add Scholar Sidekick MCP extension (aaif-goose#9433) * Add ACP session system prompt setter (aaif-goose#9478) Signed-off-by: Bradley Axen <baxen@squareup.com> * fix(acp): forward ACP server context window size to clients (aaif-goose#9455) Signed-off-by: Matt Toohey <contact@matttoohey.com> * Expose raw provider supported models over ACP (aaif-goose#9475) Signed-off-by: Bradley Axen <baxen@squareup.com> Signed-off-by: Matt Toohey <contact@matttoohey.com> Co-authored-by: Matt Toohey <contact@matttoohey.com> * fix-A: per-run member credential on update_provider + fail-closed restore Per the streams plan-note (2026-08-12): one shared goosed container, per-run member credentials, never persisted, fail-closed on restore. - POST /agent/update_provider accepts optional api_key (per-run member credential). When present the provider is built from that key via new providers::create_with_explicit_key: anthropic (from_key mirrors from_env minus the secret lookup), openrouter (same mirror), openai (from_env endpoint resolution + auth swap via ApiClient::with_auth). Any other provider with api_key set is a hard 400 - never a silent from_env fallback. - Sessions running on an explicit key are marked with a new external_credential boolean in the session store (schema v14; only the marker is persisted, never the key). The marker is written BEFORE the provider swap so a crash in between fails closed. - Restore fails closed for marked sessions: Agent::restore_provider_from_session refuses to rebuild from env/config keys, and AgentManager::create_agent_locked skips the process-wide default-provider fallback. The provider stays unset until the caller (the bridge) re-supplies the key on its existing per-run update_provider call - recoverable by design. - Tests: request deserialization with/without api_key; anthropic and openrouter from_key carry the supplied key (auth inspected); unsupported provider rejected; external_credential round-trips through the session store; fail-closed restore constructs no env-based provider. Note: ui/desktop/openapi.json intentionally not regenerated (server- side fork; the new field is optional and additive). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix-A: per-run OpenAI-compatible host (api_host) for member Venice keys Additive follow-up to the per-run-credential patch. Lets a member's own key run in the shared goosed container against an OpenAI-compatible endpoint (e.g. Venice) that isn't the box's default OpenAI host. - OpenAiProvider::from_key_with_host(model, key, host): builds the ApiClient directly against the supplied host (parsed the same way as OPENAI_BASE_URL, so `/v1` vs versionless base_path is honored) with the member's bearer token. Reads NOTHING from process-global config - not OPENAI_BASE_URL/OPENAI_HOST/OPENAI_BASE_PATH, org/project, or custom headers - so the box's own OpenAI settings can't shadow a member's endpoint. Rejects empty key/host. - UpdateProviderRequest gains api_host: Option<String> (serde default, backward compatible). create_with_explicit_key grows an api_host param: openai + Some(host) -> from_key_with_host; openai + None keeps from_key. Never persisted; still marked external_credential (fail closed on restore) like every explicit-key path. - Tests: request deserialization with api_host; from_key_with_host targets the supplied host (host/base_path/auth asserted) and rejects empty host; create_with_explicit_key routes openai+api_host. No anthropic-oauth, no chatgpt_codex, no credential_kind - the OAuth impersonation paths were declined and are not built here. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix-A: per-session member OAuth for anthropic (claude-code) + codex Extend the per-run member-credential path (previously API-key only) to OAuth-native credentials for both anthropic (Claude subscription) and openai-codex (ChatGPT subscription), so goosed can run on a member's own OAuth token per session rather than a global disk token or the box key. Wire contract (UpdateProviderRequest, /agent/update_provider): - auth_token: Option<String> (#[serde(default)]) — member OAuth token - credential_kind: Option<String> (#[serde(default)]) — "oauth" | "api-key" Handler: external_credential = api_key.is_some() || auth_token.is_some(). credential_kind is authoritative; when absent, presence of auth_token/api_key selects the mode (so pre-OAuth api-key-only bodies still work: deploy-safe). Routing (providers::create_with_oauth_token, sibling of create_with_explicit_key): - provider "anthropic"/"claude-code" + oauth -> ClaudeCodeProvider, which injects CLAUDE_CODE_OAUTH_TOKEN into each fresh `claude` subprocess env (per-subprocess isolation; the real binary owns the OAuth/beta handshake). - provider "openai-codex"/"codex"/"chatgpt_codex"/"openai" + oauth -> ChatGptCodexProvider carrying a per-session TokenData instead of the global on-disk TokenCache; account id derived from the token's own JWT claims. Unsupported providers are a hard error, never an env-credential fallback. Secrets are #[serde(skip)] and redacted from Debug (manual impls). Tokens are never persisted. openapi.json regenerated (also closes the fix-A api_key/api_host carried gap). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(session): thread the session's member into stdio extension env (GOOSE_SESSION_MEMBER) Fabrica T-BYOM (2026-08-19): a goosed session started FOR A MEMBER now tells its stdio extensions which member they serve, so member-aware extensions (streamgen / websearch) can route their LLM calls through the Fabrica bridge on the member's OWN credential instead of the container's box-wide key. - StartAgentRequest.session_member: additive, serde(default) — the bridge's server-driven lane sends it in the body; deploy-order-safe for old callers. - start_agent prefers the edge-authed X-Member HEADER over the body field: on the SPA lane Caddy's forward_auth stamps X-Member from the verified session (a browser can forge the body but never that header). - SessionMemberState (extension_data key fabrica_session_member.v0): the shape-guarded ([a-z0-9_-]{1,40}) persisted form on the session — no session schema change, rides the existing versioned-key ExtensionData map. - ExtensionConfig::Stdio spawn injects GOOSE_SESSION_MEMBER beside the existing AGENT_SESSION_ID when the session carries a member; absent → memberless env, extensions keep the box-key path byte-identically. - ui/desktop/openapi.json regenerated (also picks up PR #1's additive auth_token/credential_kind on UpdateProviderRequest — the carried regen follow-up). The desktop TS client regen (npx @hey-api/openapi-ts) is deliberately skipped — Fabrica drives goosed over HTTP, no desktop app. cargo check green; cargo test -p goose --lib: 1434 passed / 91 failed — IDENTICAL 91 failures at the untouched pin 729254b (pre-existing local sqlx feature quirk); the 4 new SessionMemberState tests all pass. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(update_provider): per-run credential must not require the provider's global config resolve_provider_model_info() gates on check_provider_configured (the GLOBAL env/config credential) and instantiates the provider from env to fetch model info. It ran BEFORE the per-run credential branch, so a member key for a provider this goosed has no global key for (openrouter / venice / openai on a box carrying only ANTHROPIC_API_KEY) failed with 400 "Provider 'openrouter' is not configured" — even though create_with_explicit_key supports it. With an external credential the model-info lookup is now advisory (reasoning set when it resolves, left unset otherwise); the env-credential path is unchanged. Found on the fab_os_local twin running the BYOM GOOSE_SESSION_MEMBER cell (member on an OpenRouter key). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> --------- Signed-off-by: Eugenio La Cava <eugeniolcv@gmail.com> Signed-off-by: Michael Neale <michael.neale@gmail.com> Signed-off-by: Douwe Osinga <douwe@squareup.com> Signed-off-by: Alex Hancock <alexhancock@block.xyz> Signed-off-by: Vincenzo Palazzo <vincenzopalazzodev@gmail.com> Signed-off-by: jh-block <jhugo@block.xyz> Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: Matt Toohey <contact@matttoohey.com> Signed-off-by: Kalvin Chau <kalvin@block.xyz> Signed-off-by: Hugues Clouâtre <hugues@linux.com> Signed-off-by: Cole McIntosh <colemcintosh6@gmail.com> Signed-off-by: SteveO <steve.officer@gmail.com> Signed-off-by: sheikhlimon <sheikhlimon404@gmail.com> Signed-off-by: James Crosswell <james.crosswell@gmail.com> Signed-off-by: Joah Gerstenberg <joahg@squareup.com> Signed-off-by: Joah Gerstenberg <joah@squareup.com> Signed-off-by: Aaron Yourk <ayourk@gmail.com> Signed-off-by: Bradley Axen <baxen@squareup.com> Signed-off-by: Steve Marshall <steve.marshall@fasthosts.com> Signed-off-by: Vladislav Dobromyslov <vladik.dobrik@gmail.com> Signed-off-by: morgmart <98432065+morgmart@users.noreply.github.com> Signed-off-by: fresh3nough <anonwurcod@proton.me> Signed-off-by: Pierre LE GUEN <26087574+PierreLeGuen@users.noreply.github.com> Signed-off-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Signed-off-by: Angie Jones <jones.angie@gmail.com> Signed-off-by: dejavu <dejavu@Mac.home> Signed-off-by: Asish Kumar <officialasishkumar@gmail.com> Signed-off-by: Andrew Mello <andrew@88plug.com> Signed-off-by: UGBOMEH OGOCHUKWU WILLIAMS <williamsugbomeh@gmail.com> Signed-off-by: Michael Neale <micn@block.xyz> Signed-off-by: Jeremy Dawes <jeremy@jezweb.net> Signed-off-by: Rodolfo Olivieri <rolivier@redhat.com> Co-authored-by: Jack Amadeo <jackamadeo@block.xyz> Co-authored-by: dorien-koelemeijer <62866702+dorien-koelemeijer@users.noreply.github.com> Co-authored-by: Eugenio <292452+eugenio@users.noreply.github.com> Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Michael Neale <michael.neale@gmail.com> Co-authored-by: Douwe Osinga <douwe@block.xyz> Co-authored-by: Douwe Osinga <douwe@squareup.com> Co-authored-by: Alex Hancock <alexhancock@block.xyz> Co-authored-by: Vincenzo Palazzo <vincenzopalazzodev@gmail.com> Co-authored-by: yanalialiuk <ylialuke@gmail.com> Co-authored-by: Yana Lyalyuk <yanalyalyuk@MacBook-Pro-Yana.local> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: jh-block <jhugo@block.xyz> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Lifei Zhou <lifei@squareup.com> Co-authored-by: Angie Jones <jones.angie@gmail.com> Co-authored-by: Kalvin C <kalvinnchau@users.noreply.github.com> Co-authored-by: Hugues Clouâtre <15008125+clouatre@users.noreply.github.com> Co-authored-by: Matt Toohey <contact@matttoohey.com> Co-authored-by: Maksim <82521640+mgorkii-nlplogix@users.noreply.github.com> Co-authored-by: Cole McIntosh <82463175+colesmcintosh@users.noreply.github.com> Co-authored-by: Steve Officer <steve.officer+github@googlemail.com> Co-authored-by: Sheikh Limon <sheikhlimon404@gmail.com> Co-authored-by: James Crosswell <jamescrosswell@users.noreply.github.com> Co-authored-by: Joah Gerstenberg <joah@squareup.com> Co-authored-by: Joah Gerstenberg <joahg@squareup.com> Co-authored-by: Amp <amp@ampcode.com> Co-authored-by: ayourk <ayourk@users.noreply.github.com> Co-authored-by: Monroe Williams <monroe@pobox.com> Co-authored-by: Bradley Axen <baxen@squareup.com> Co-authored-by: Steve Marshall <steve.marshall@fasthosts.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Jack Amadeo <jackamadeo@squareup.com> Co-authored-by: Lucas Kim <45152028+Raptors65@users.noreply.github.com> Co-authored-by: Vladislav <51202067+vampik33@users.noreply.github.com> Co-authored-by: morgmart <98432065+morgmart@users.noreply.github.com> Co-authored-by: fre$h <anonwurcod@proton.me> Co-authored-by: Rodolfo Olivieri <rodolfo.olivieri3@gmail.com> Co-authored-by: Quentin Champenois <26109239+Quentinchampenois@users.noreply.github.com> Co-authored-by: Quentin Champenois <qchampenois@scaleway.com> Co-authored-by: Tonchain <luckyimpetus@gmail.com> Co-authored-by: asim48-ctrl <asim48@gmail.com> Co-authored-by: Pierre LE GUEN <26087574+PierreLeGuen@users.noreply.github.com> Co-authored-by: spendletonliveaction <105226994+spendletonliveaction@users.noreply.github.com> Co-authored-by: Stephen Pendleton <spendleton@bluecatnetworks.com> Co-authored-by: seneroner77-cmd <seneroner77@gmail.com> Co-authored-by: dejavu <dejavu@Mac.home> Co-authored-by: Asish Kumar <87874775+officialasishkumar@users.noreply.github.com> Co-authored-by: Dmitry Beskov <43372966+besdar@users.noreply.github.com> Co-authored-by: 88plug <19512127+88plug@users.noreply.github.com> Co-authored-by: Alex Hancock <alex@alexhancock.com> Co-authored-by: jh-block <255854896+jh-block@users.noreply.github.com> Co-authored-by: UGBOMEH OGOCHUKWU WILLIAMS <williamsugbomeh@gmail.com> Co-authored-by: Jeremy Dawes <jeremy@jezweb.net> Co-authored-by: James Liounis <james.liounis@perplexity.ai> Co-authored-by: Rodolfo Olivieri <rolivier@redhat.com> Co-authored-by: Mark Lavercombe <mlava@users.noreply.github.com> Co-authored-by: philoengineer <philoengineer@users.noreply.github.com>
Summary
goose-cli:goose tuiwill now launch https://www.npmjs.com/package/@aaif/gooseTesting
Local usage
Related Issues
#6642
Screenshots/Demos (for UX changes)
cargo run --bin goose -- tui