本文件记录 DeerFlow 的所有重要变更。
格式参考 Keep a Changelog, 版本号遵循 语义化版本规范。
English | 中文
本节累积面向 2.1.0 里程碑(里程碑 2)的工作。
-
网关: 现在会无条件签发请求 trace id,且每个 Gateway HTTP 响应都会携带
X-Trace-Idheader。此前二者均受logging.enhance.enabled控制;该配置现在 仅控制日志输出——即日志记录是否包含trace_id字段及其格式。此 header 无法关闭;使用默认enabled: false的安装在升级后也会开始收到它。定时任务、 MCP 任务通知 run、IM 渠道消息以及内嵌DeerFlowClient都会为每个工作单元绑定 一个 id,因此此前没有 trace id 的 run 记录、checkpoint 元数据和 Langfuse trace 现在也会包含它。run 请求的metadata或config.context中提供的deerflow_trace_id现在会被忽略并覆盖,以确保响应 header、日志和持久化 run 保持一致;如需跨服务固定关联 id,请发送X-Trace-Id请求 header。logging仍需重启后生效。未新增或移除任何配置键。([#5119]) -
技能: 沙箱现在将
/mnt/skills保留给“仅启用项”的托管投影视图。DEER_FLOW_HOST_SKILLS_PATH与SKILLS_HOST_PATH不再使用;Docker/AIO 和 hostPath 部署会从DEER_FLOW_HOST_BASE_DIR推导投影路径。指向/mnt/skills或其子路径的 E2B operator 挂载会被跳过并告警,避免遮蔽托管投影;请将额外内容 挂载到其他容器路径。用户投影会从磁盘重读全局启用状态,使切换在下一次获取沙箱时 跨 Gateway worker 生效。既有 E2B 沙箱在重建前仍保留创建时快照;PVC 模式暂不提供 已禁用技能的文件系统隔离。([#4178]) -
沙箱: E2B 现在将
sandbox.replicas作为进程级容量上限来强制执行。默认的wait策略会等待acquire_timeout,随后令当前智能体回合失败。DeerFlow 不会自 动重试该回合。可使用burst配合burst_limit允许有限地超出额度多开 VM。reject策略可在返回容量错误前先回收一个预热 VM。(#4391) -
技能: 包含
SKILL.md的目录现在是一个运行时包边界。该包内嵌套的SKILL.md文件被视为支撑数据,不再注册为独立技能;若自定义目录结构较为特殊,需将可独立加 载的技能移到不带自身SKILL.md的命名空间目录下。(#4098) -
记忆: 记忆系统现已可插拔(
memory.manager_class选择后端;默认deermem自包含)。DeerMem 私有配置从memory:顶层移入memory.backend_config,/memory/config响应(以及client.get_memory_config())的结构也发生了变化。(#4122) -
记忆:
/memory/config与client.get_memory_config()不再返回扁平的 DeerMem 字段(storage_path、max_facts、debounce_seconds、token_counting、guaranteed_*、staleness_*等)。改为返回{enabled, mode, injection_enabled, manager_class, backend_config},其中backend_config是一个由当前后端自行解释的不透明 dict 。记忆数据响应(/memory、/memory/status的 data)未变。读取旧扁平字段的 外部 API / SDK 客户端需改为读取backend_config。(#4122) -
记忆: 自定义
memory.storage_class发生迁移:旧的默认路径deerflow.agents.memory.storage.FileMemoryStorage已不存在(现为deerflow.agents.memory.backends.deermem.deermem.core.storage.FileMemoryStorage)。自定义MemoryStorage子类的__init__必须接受config(此前为无参)。 损坏或过期的storage_class会记录错误并回退到FileMemoryStorage(不会崩溃 )——请更新路径与签名以恢复使用。(#4122) -
记忆:
storage_path的语义由“文件路径”改为“根目录”。抽象化之前,绝对storage_path是共享的记忆文件(不按用户隔离),相对值则是 data base_dir 下的全局文件。现在storage_path(无论绝对或相对)都是根目录;按用户的记忆存放在{storage_path}/users/{uid}/memory.json。若升级后仍保留旧的默认storage_path: memory.json(一个相对文件名),会导致 按用户的记忆孤立,或在保存时触发NotADirectoryError。因此旧版迁移会带告警 丢弃以.json结尾的文件式storage_path值,且当storage_path解析到一 个已存在的文件时工厂会抛出异常。如需自定义根目录,请将memory.backend_config.storage_path设置为一个目录。(#4122) -
记忆: 当
memory.mode: tool搭配一个未实现search()的后端时,现在会在 Gateway 启动时由MemoryManager的不变量校验快速失败并抛出ValueError,而不 是启动成功后在每次memory_search调用时静默返回空结果。两个内置后端都实现了search()(DeerMem 会检索,noop返回[]),因此仅影响未覆盖search()就 接入的自定义后端。这是有意为之——静默返回空比启动期报错更糟。修复方式:切换到mode: middleware,或覆盖search()(并设置supports_search=True)。(#4324) -
配置:
database.checkpoint_delta_snapshot_frequency已迁移为database.checkpoint_delta.snapshot_frequency,默认值从1000改为10。 旧顶层字段仍会在告警后映射到新字段,显式的新字段优先。依赖旧默认值的 delta 模式部署现在会将快照频率提高 100 倍;如需保留原节奏,请显式设置为1000。([#4516]) -
Docker: 两份 compose 文件发布的入口端口现在默认只绑定回环地址 (
127.0.0.1)。依赖旧0.0.0.0绑定的部署必须设置BIND_HOST才能向其他网卡 暴露服务。([#4618])
- 认证: 新增用于程序化 API 访问的个人访问令牌(PAT):
POST/GET/DELETE /api/v1/auth/pats用于管理令牌(仅展示一次,以 SHA-256 摘要存储);默认拒绝的路由策略只允许会话/run 生命周期路由,并进一步受令牌的threads/runsscope 限制;任何具有取消能力的请求维度(?action=、multitask_strategy)还额外要求runs:cancel。([#5041]) - 认证: 登录限流参数可配置:
auth.local.max_login_attempts(默认 5,最小 2) 与auth.local.lockout_seconds(默认 300),实时解析,配置重载后下次登录即生效 ,无需重启 Gateway——这对多名用户共享同一出口 IP 的企业代理 / NAT 部署是解锁 通道。默认值不变。([#5110])
-
中间件: 新增
TokenBudgetMiddleware,强制单个 run 的 token 预算,在主智 能体与子智能体之间累加共享。(#3412) -
中间件: 结构化的工具结果元数据与工具进度状态机,让运行时对多步工具流拥有 一等可见性。(#3601)
-
上下文: 每个 run 记录生效的记忆身份,并在摘要过程中持久化持久上下文(系统 消息、记忆与工具状态),以结构化运行时元数据的形式发出,压缩(compaction)不再 丢失这些信息。(#3556、#3887、#3906)
-
运行时: 目标延续(goal continuation)允许 run 跨多个智能体回合朝目标继续 执行,并跟踪、限制
continuation_count。(#3858) -
子智能体: 系统维护的委派账本(delegation ledger)防止对在途任务重复委派, 并设总委派上限以约束单个 run 的扇出。(#3877、#4115)
-
子智能体: 在会话中持久化并展示子智能体的步骤历史。(#3845)
-
工具: 结构化摘要取代预览中原始的超大工具输出。(#3377)
-
文件: 文件工具引入确定性的“写前读”版本门控,避免覆盖并发编辑。(#3912)
-
网关: 感知缓存的成本核算将 token 成本归因到缓存 / 未缓存路径;Redis stream 桥接启用分布式事件流;并向用户暴露手动上下文压缩。(#3920、#3191、#3969)
-
网关: 可通过
stream_bridge.heartbeat_interval_seconds配置 stream bridge 的心跳间隔(默认 15 秒),使位于激进 proxy 空闲超时之后的部署可以统一调节 SSE、/wait和内部订阅者。([#5017]) -
运行时: 双模式 checkpoint 存储(基于 LangGraph
DeltaChannel)将长调研 / 编码 run 的会话存储从 O(N²) 降至近线性。(#4292) -
智能体: 配置声明的主智能体中间件,让部署方无需修改运行时链即可加入自定义
AgentMiddleware类。(#3964) -
智能体: 按智能体的模型与生成设置(
temperature、max_tokens、thinking_enabled、reasoning_effort)可覆盖共享的模型 profile。(#4347) -
运行时: 记录终态的 artifact 投递回执,使预期要
present_files的 run 在 投递失败时不再误报成功。(#4365) -
上传: 通过
list_uploaded_files工具懒加载历史文件,而非注入完整清单。(#4174) -
运行时: Delta 模式 checkpoint 历史缓存(内存/Redis)支持 O(1) 增量合成, 通过
database.checkpoint_cache配置。([#4638]) -
调度器:
scheduler.recursion_limit可设置定时运行的 LangGraph super-step 上限(默认 1000,与 Web UI 一致,并受max_recursion_limit限制)。([#4848]) -
运行时: 每次工具调用都会携带由运行时签发且可防篡改的工具回执;有界回执账本 会注入模型上下文,使智能体能在报告中引用执行证据。默认通过新的
verification配置节启用。([#4659]) -
子智能体: 子智能体委派现在可验证,并按 RFC #4651 分层实现:每份子智能体 报告都必须引用工具回执(例如
[r3 write_file]),并为每个交付物附上可验证 handle;主智能体会将这些引用与子智能体的实际执行记录交叉核对,task委派的acceptance_criteria也会在父侧确定性检查(文件是否存在/非空、记录的测试命令 退出状态),无法判定的项目会报告为 UNVERIFIED,而不是静默通过。([#5076]、 [#5090]、[#5109]) -
澄清: 人工输入卡片支持结构化表单字段,智能体可精确请求所需信息。([#4406])
-
子智能体: 内置子智能体会接收当前日期上下文锚点,使相对日期任务与主智能体 直接处理时表现一致。([#4797])
-
子智能体: 设置页新增部署级子智能体目录;自定义智能体可配置显式 worker allowlist,并在 prompt 与执行阶段同时强制执行。([#4887])
-
子智能体: 并发由统一的进程级容量控制器管理;可选
batch_task工具可把大量 独立项目作为基于 SQL 的持久、可恢复批次执行,支持租约、有限重试、暂停、恢复与 取消,并在聊天中展示进度。([#4998]) -
智能体: 注入 lead / 子智能体 prompt 的当前日期上下文遵循可选的
DEER_FLOW_DATE_TIMEZONE环境变量(IANA 名称,如Asia/Shanghai),非 UTC 部署的用户在午夜前后不再被告知错误的“今天”;未设置时保持服务器本地时区行为。 ([#5154]) -
子智能体: 被委派的子智能体可以发现此前回合上传的文件:父 run 经校验的
uploaded_files边界会注入子智能体的图状态,使list_uploaded_files可参与 正常的工具策略过滤(持久batch_taskworker 保持禁用)。([#5170])
-
记忆: 记忆合并(consolidation)合成碎片化的事实,并通过 LLM 为每条事实分 配的
expected_valid_days/staleFactsToExtend进行过期审查,剪除静默过期的 事实。(#3996、#3860、#4143) -
记忆: 保证注入纠正事实(并优雅降级),使用户的纠正始终能触达模型。(#3592)
-
记忆: 精简可插拔的
MemoryManager接口以方便后端接入——新后端不再需要实现 未被调用的抽象方法,DeerMem 专有的 hook 注入也移出共享工厂。(#4326) -
记忆: 增量式按智能体作用域的 Markdown 事实存储,按智能体隔离事实,且更新 单条事实时无需重写或重建整个集合的索引。(#4279)
-
记忆: 记忆消息处理新增会话水位(watermark)、无意义回合过滤与持久化队列, 使抽取不再每回合都重新喂入完整会话。(#4447)
-
记忆: 内置 FTS5/BM25 检索适配器,无需外部服务即可对已存记忆全文搜索。([#4360])
-
记忆: 新增可插拔后端:通过 HTTP 接入 OpenViking 与 mem0,以及作为用户模型 记忆 provider 的 Honcho。([#4509]、[#4528]、[#4730])
-
记忆: 混合事实淘汰策略综合多种信号,决定容量满时应丢弃哪些事实。([#4789])
-
技能: 原生 SkillScan(阶段一)在加载时静态分析技能包;
describe_skill支 持延迟发现,模型按需获取技能 schema,而非一开始就加载全部技能。(#3033、#3775) -
技能: 按用户的自定义技能隔离,并配合沙箱挂载。(#3889)
-
技能: 选中一个技能后技能列表会重新打开,便于连续附加多个技能。([#4639])
-
技能: 可直接从“技能”设置页安装本地
.skillarchive,并复用现有的按用户 installer 和安全扫描。([#5039]) -
技能: 播客生成的火山引擎音色可按说话人性别覆盖配置,默认值经过修剪、对空值 安全。([#5156])
-
社区工具: 新增网络检索 / 抓取引擎——GroundRoute、Crawl4AI(
web_fetch)与 fastCRW provider——并新增 Browserlessweb_capture截图工具和 Braveimage_search。(#3675、#3821、#3585、#3881、#3866) -
MCP: MCP 工具调用支持按 server 的
tool_call_timeout,并提供路由提示引导 模型选用正确的 server。(#3843、#4004) -
MCP: 新增官方 OpenViking
/mcp示例,通过 DeerFlow 通用 MCP 客户端暴露其 原生工具集。([#4745]) -
社区工具: 将“智能体化浏览器控制”作为会话的一等能力——基于 Playwright 的浏 览器会话由智能体操作,用户可在工作区中观察或接管。(#4187)
-
社区工具: Lark / 飞书 CLI 集成打包了运行时安装、官方
lark-*技能包与交 互式授权流程,使该集成不再依赖手动环境配置。(#3971) -
集成: 可在“设置 > 集成”中按用户切换 Lark/飞书应用凭据;新 App ID/Secret 会在写入前校验,成功切换后撤销旧 OAuth token。([#4703])
-
ACP: 支持 MiniMax Code (
mcode acp) 作为原生外部编码智能体;ACP thought chunk 不再拼接进工具结果。([#4846]) -
模型: 新增 Z.AI GLM-5.3-Flash profile,保持 thinking 始终开启并停止通用 reasoning-effort 转发,因为该模型会拒绝关闭 thinking,且只接受自身定义的 effort 值。([#5074])
-
社区工具: 新增 Serply(支持 news 与 scholar 垂直搜索)和腾讯云 WSA 网络 搜索 provider,并为 DDGS、Brave、Tavily 与 SearXNG 提供统一的原生时间范围过滤 (日/周/月/年)。([#5023]、[#5057]、[#5099])
-
社区工具: 新增 Sofya
web_search与web_fetchprovider——搜索结果直接 携带每个页面的内容,并按结果设上限,使默认搜索保持内联。([#5239]) -
知识库: 新增可选的只读 RAGFlow 检索,通过已配置的 RAGFlow dataset 暴露
knowledge_search(query)智能体工具,并提供 dataset ID allowlist,以及错误路径 中的凭据和 dataset ID 脱敏。([#4955]) -
知识库: 新增可选的只读 LightRAG 检索,作为同一
knowledge组的另一个knowledge_search(query)provider——运营方通过配置哪个条目来选择 RAGFlow 或 LightRAG。它调用 LightRAG 的结构化/query/dataendpoint(不做 LLM 生成),将 排序后的 chunk 格式化为带引用编号的文本,可选的X-API-Key在所有模型可见路径 中脱敏,服务端错误消息会映射为可操作的工具错误。([#5209])
- MCP: 新增持久任务运行时:长时工具任务通过持久 driver 跨 Gateway 重启继续, 进度与完成通知显示在聊天 UI 中。([#4665]、[#4690]、[#4833])
- MCP: 共享 MCP server 可注入按用户区分的凭据;未映射用户默认拒绝,存储的 凭据在 Gateway API 响应中脱敏。([#4868])
- MCP: 新增按 server 的
tool_name_prefix,让已自行命名空间化工具的 server 保留原始工具名;默认行为不变。([#4624]) - MCP: “设置 > 工具”现在可以通过定向 Gateway endpoint 新增、编辑和删除 MCP server;复制粘贴 JSON 的工作流会保留高级字段和已脱敏的 secret placeholder。 ([#5022])
- MCP: 共享 HTTP/SSE server 可通过
headers_from_context将请求作用域的 secret 映射为 header:调用方在config.context.secrets中提供每次请求的值, 配置只存储键名,缺失值默认拒绝。([#5010]) - MCP:
extensions_config.example.json新增可选的parallel-searchserver 条目(https://search.parallel.ai/mcp,HTTP,默认无鉴权),默认禁用;启用后会 暴露parallel-search_web_search与parallel-search_web_fetch,并文档化可选 的 Bearer 认证。([#5028])
-
渠道: 把 IM 的
channel_user_id以DEERFLOW_CHANNEL_USER_ID暴露给沙箱 命令。(#3926) -
渠道: 对同一会话的密集消息进行排队,并在批次间保留话题卡片预览。(#3988)
-
渠道: 入站 webhook 去重迁移到 Postgres,使多个 Gateway Pod 可同时服务同一 IM 渠道而不重复处理事件。([#4210])
-
渠道: 钉钉入站消息支持文件与图片附件。([#4423])
-
渠道: 新增 Buzz (Nostr) 渠道连接器及配套前端体验。([#4649]、[#4727])
-
渠道: IM 命令
/agent list与/agent use <name>允许会话切换到 owner 的 自定义智能体:选择会持久化到会话元数据(重启后恢复)并优先于过期的渠道默认值, IM 创建的会话在 Web UI 打开时路由到同一智能体;同时/agent在斜杠技能解析器 、前端与 TUI 中保留,避免任何技能遮蔽该命令。([#5168])
-
认证: 通用 OIDC / SSO 认证,并支持 Keycloak。(#3506)
-
护栏: 已认证的运行时上下文在
GuardrailRequest中暴露,安全干预以 run 事 件的形式持久化。(#3665、#3837) -
认证: “保持登录”选项,配合统一的会话 cookie 策略(HTTPS 下使用持久化
Securecookie,公网 HTTP 下使用会话 cookie)。(#4255) -
认证: 部署方可关闭本地自注册,将新账号限制为仅通过 SSO / OIDC 开通。(#4311)
-
鉴权: 内置 RBAC 鉴权 provider 与统一工厂,并在装配期(模型可见前移除工具 )与运行期(拒绝被禁用的调用)双重强制执行工具鉴权。(#4260、#4370)
-
鉴权: Gateway 路由权限改由已配置的
AuthorizationProvider推导,不再使用 固定表。([#4439]) -
鉴权: 模型权限会在 Gateway 路由和智能体运行时双重执行,获取沙箱时还会校验
sandbox:execute。([#4540]、[#4911]) -
鉴权:
GET /auth/me现在返回调用方的生效路由权限(RFC #4063 阶段 4),直接 读取认证中间件在每个已认证请求上标记的AuthContext——不产生额外的 provider 评估——使前端能隐藏调用方角色无法执行的操作。([#5228])
-
沙箱: 新增 E2B 与 BoxLite(micro-VM)沙箱 provider;BoxLite 自带预热池。(#3883 、#3940、#3951)
-
provisioner: ClusterIP Service 与按技能作用域的 PVC 挂载,并支持配置沙箱 容器端口。(#4016、#3928)
-
沙箱: 新增云沙箱 provider:Tenki 与 OpenSandbox。([#4382]、[#4877])
-
沙箱: K8s provisioner 模式新增可选的 lark-cli 凭据 broker sidecar,将 Lark 应用密钥与 OAuth token 移出沙箱文件系统;沙箱只看到转发命令的 shim。默认关闭。 ([#4501])
-
沙箱: E2B mount 上传的 wall-clock deadline 可通过
mount_upload_deadline_seconds配置(默认 120 秒)。([#4876]) -
沙箱: E2B 沙箱创建后会携带结构化的
MountUploadResult(truncated、reason、上传统计),并在同进程内的 warm-pool 回收后保留——挂载上传因资源限制 被截断的情况可以在代码中观察,而非只出现在 Gateway 日志。([#4884]) -
沙箱: 本地 Docker AIO 沙箱新增可选的受控出网:
sandbox.network.mode支持isolated(每个沙箱独立内部 bridge,无出站路由)与allowlist(同样的 bridge 加上自行解析目标的域名 allowlist HTTP(S) 策略 sidecar,拒绝 IP 字面量与 ECH); 被拒绝的公网域名可通过人工输入卡片批准(临时授权或本沙箱内永久允许),非交互 run 默认失败,受限模式下沙箱 API 也不再直接发布。要求 Docker Engine 28+;open仍是默认值。([#5152])
- 扩展: 新增 out-of-tree Python 扩展系统,可贡献中间件、任务生命周期与系统模型
observer、Gateway 服务和 HTTP 路由,并用
deerflow extensions管理。([#4636]、 [#4684]、[#4780]) - 扩展: 扩展可观察消息来源、中间件策略、智能体装配指纹、上下文压缩、护栏决策
和工具的 MCP 来源。
deerflow-extension-api升至 0.2.0,0.1 扩展会在启动时被拒绝。 ([#4863])
- 持久化: 可通过
postgres_schema选择自定义 PostgreSQL schema;ORM、LangGraph checkpointer 与 store 表均创建在其中,启动时自动创建。([#3442])
-
前端: 支持重新生成最新回答。(#3637)
-
前端: 引用来源证据面板、智能体 run 的工作区变更评审,以及可视化的
ask_clarification卡片。(#3907、#3945、#3956) -
前端: 语音输入、方向键回溯 prompt 历史、输入框内容润色,以及“(思考了 N 秒)”思考时长标签。(#4036、#3718、#3986、#3627)
-
前端: 用
agents_api特性开关控制智能体 UI 的可见性,并在后端与 UI 中持 久化 AI 回合时长。(#3769、#3663) -
前端: 将斜杠技能(slash-skill)激活渲染为内联标签(chip)。(#3981)
-
前端: 本地化的 AI 辅助声明。(#4374)
-
前端: 支持置顶最近会话。(#4442)
-
前端: 在输入框中校验
/goal目标长度。(#4337) -
前端: 实时显示上下文窗口使用量。([#3183])
-
前端: 可原地编辑并重新运行最近一次用户回合。([#4377])
-
前端: 澄清卡片待处理时仍可输入并发送回复。([#4530])
-
建议: 可通过
suggestions.max_suggestions配置后续建议数量(默认 3)。([#4533]) -
Artifact: 可在 artifact 面板中内联编辑文本 artifact。([#4596])
-
Artifact: Markdown artifact 可在新窗口 reader 中以渲染形式打开(并提供 “查看源文件”和“下载”fallback);一次 run 中展示的所有文件也可根据该 run 的 投递回执打包下载为 zip。([#5056]、[#5117])
-
前端: 自定义智能体聊天支持 Browser Live。([#4719])
-
前端: 新增长会话大纲:超过 5 个用户回合后,紧凑侧边菜单会列出会话中的问题, 支持跳转并跟踪当前章节。([#5025])
-
前端: 定时任务可复制为可编辑草稿,保留配置但不带 run 历史。([#5064])
-
会话: 分支会话自动使用
Title (2)、Title (3)等编号区分标题,最近会话 列表以树形连接线展示父子关系。([#4983]) -
前端: 支持归档与恢复会话:侧边栏 Archive 操作配 Undo toast、搜索栏上方的 “最近会话 / 已归档”标签页,以及按会话的恢复控件;SQL 与 Memory 存储在分页前 应用归档过滤,同时保留消息、文件、链接、置顶状态与当前 URL。([#5236])
-
项目: 项目工作区组织会话(Projects MVP 阶段一):侧边栏 Projects 区块支持 平铺 / 分组列表模式,项目详情页带分页的会话列表,项目内新建聊天会预创建线程并 归属该项目,run 永远不会落到所选项目之外;分支继承项目归属、支持在项目间移动 ,并提供项目的创建 / 重命名 / 归档 / 恢复 / 删除。([#5265])
-
Artifact: 已完成的 CSV/TSV artifact 以有界表格预览(最多 200 行 × 50 列, 每页 50 行,吸顶表头,可选首行表头),解析在后台线程进行、复用现有 1 MiB range 加载器——字面字符串、前导零与多行带引号单元格都得以保留,长单元格可在可复制的 对话框中打开,源码视图一键切换。([#5284])
-
可观测性: trace-id 关联与增强日志,以及通过 Monocle 实现的智能体可观测性 。(#3902、#4024)
-
工具: 类 Hermes 的终端工作台(
deerflowCLI,基于DeerFlowClient),以 及脱敏的社区支持包(support-bundle)生成器。(#3760、#3886) -
安装向导: 安装向导现在会询问 OpenAI 兼容的 gateway 模型是否支持 thinking ,并新增火山引擎 Coding Plan 快速安装路径。(#3428、#4141)
-
TUI:
clear命令。(#4306) -
TUI: 支持透明终端背景。([#4631])
-
网关: 新增
GET /health/ready就绪探针,执行有界的数据库SELECT 1, 数据库不可达时返回 503(memory 后端返回 200not_configured);/health仍为 纯存活探针,生产 compose 的健康检查也改用就绪探针。([#5166]) -
可观测性: 延迟工具晋升(routing-hint 自动晋升与显式
tool_search)会以 隐私最小化的middleware:tool_promotionrun 事件持久化(工具名、来源、数量、 智能体归因;不含查询、schema 或结果),且仅在技能策略过滤之后观测,被拒绝的 schema 不会被报告为生效晋升。([#5183])
-
前端性能: 保持公共根页面和本地化文档静态化;懒加载关闭的工作区面板及编辑器/ 高亮依赖;增量推导流式消息状态;限制流式 Markdown 工作量;虚拟化超长消息与聊天 列表;暂停屏幕外装饰效果,并对代表性路由设置 JS/CSS 预算。
-
浏览器: 协商二进制 Browser Live JPEG 帧,兼容旧 JSON/base64 协议;每次刷新 只呈现最新帧,并撤销已替换的 object URL。
-
Artifact: 普通文本 artifact 支持 HTTP byte-range 流式读取;Web UI 初始预览 限制为 1 MiB,用户显式请求后才加载完整文件。
-
沙箱: Helm chart 现在默认将每个沙箱的 Service 设为
ClusterIP而非NodePort,因此代码执行沙箱只能通过集群内 Service DNS(http://sandbox-<id>-svc.<ns>.svc.cluster.local)访问,不再绑定到每个节点(包括 GKE / EKS / AKS 上外部可达的)网卡。升级时现 有 chart 安装会从 NodePort 切到 ClusterIP。如需保留原有可达性(外部探测命中 30xxx 端口,或 gateway 不在 K8s 的 Docker-Compose / 混合部署路径),请设置provisioner.sandboxServiceType: NodePort(必要时配合provisioner.nodeHost)。provisioner 本身不变(自 #4016 起已按模式感知)。(#4190) -
技能: 处于激活态的限制型技能若要委派给子智能体,必须在
allowed-tools中 显式声明task。只读发现基础设施(tool_search与describe_skill)仍可用, 但无法为被禁用的业务工具授予 schema 可见性或执行权限。(#4098) -
记忆: 抽象化之前位于顶层的
memory.*DeerMem 字段(storage_path、max_facts、debounce_seconds、model_name、token_counting、staleness_*、consolidation_*等)在加载时会带告警自动迁移到backend_config,因此升级不会静默地把自定 义配置回退为默认值(model_name->backend_config.model.model)。将它们移到config.yaml的memory.backend_config下即可消除告警。(#4122) -
记忆: 新增
memory.mode(middleware|tool);tool模式会注册供模 型直接调用的记忆工具(memory_search/add/update/delete),取代被动的逐 回合摘要。manager_class解析改为快速失败(未知后端时抛出ValueError,而非 静默回退)。(#4023) -
中间件: 声明式分层中间件构建器;
ThreadData现在先于Uploads运行。(#3809) -
沙箱: 宿主机到虚拟机的输出脱敏正则现在统一归属,消除重复的模式编译。(#4108)
-
文档:
AGENTS.md成为智能体指引的权威来源,CLAUDE.md通过@AGENTS.md导入;模块指南同步刷新。(#3770) -
记忆: OpenViking 后端改用官方适配器;旧 trusted-mode 的
auth_mode/account字段会被拒绝,改用绑定凭据的 USER API key。([#4707]) -
网关: 在 run-event journal 出现之前创建的会话,会在首次新 run 前把 checkpoint 历史回填为 seed event,使旧会话升级后仍可见且顺序正确。([#4590])
-
智能体: 子智能体委派改按净收益路由;除非并行延迟、专长能力或上下文隔离明确 有益,否则主智能体默认直接执行。([#4384])
- 运行时: 会话元数据现在仅在 run 通过启动屏障后才切换为
running,待取消的 run 不再短暂呈现running状态;worker 启动期间客户端可能观察到先前的会话状态 。(#4450) - 运行时: 通过原子化、感知租约的接管(takeover)claim 重新检查孤儿候选 run ,使扫描后的成功心跳仍保持 run 活跃,且仅有一个 reconciler 上报恢复。(#4424 、#4434)
- 技能:
allowed-tools只作用于斜杠激活或实际加载的主智能体技能,避免被动 启用的技能与评测 fixture 从每个 run 中移除 MCP、网络、文件与委派工具。(#4095 、#4098、#4192) - 模型: 在所有
BaseChatOpenAI子类(VllmChatModel、MindIEChatModel、PatchedChatMiMo、PatchedChatStepFun、PatchedChatMiniMax)上生效api_base,而不只是ChatOpenAI/PatchedChatOpenAI。此前这五个子类会静默丢弃配置的 endpoint,随后以一个含义 不明的unexpected keyword argument 'api_base'让每次请求都失败;它们也未被纳 入未知配置 key 的告警。两者现在都基于issubclass(BaseChatOpenAI)判断。(#4146) - 智能体: 在 LLM 请求前合并
SystemMessage;保证工具运行后仍有可见响应;避 免在流结束前发起默认的 LLM 标题调用;为省略号预留空间以使本地标题遵守max_chars;并将工具输出尾部前移,使回退截断遵守max_chars。(#3711、#4033、#3885 、#4052、#4017) - 智能体: 动态上下文的日期扫描跳过无日期的提醒;从不含
config.yaml的智能 体目录加载SOUL.md;update_agent的旧版智能体守卫要求存在config.yaml; 并拒绝空的SOUL.md更新。(#3685、#4136、#4166、#4219) - 中间件: 为循环检测的工具频次计数器加窗口,避免长 run 误触;阻止标题中间件
流式输出 token;修复“同内容列表耗尽时位置回退误取无关 todo”的问题;在
_apply、before_agent、_clear_run_state与_drain_pending_warnings之间持有 token 预算锁;丢弃孤立的ToolMessage以免严格型 provider 返回 400;净化非法 tool-call 参数;并在 dangling 修复中从空的 tool-call 名称与畸形 tool-call id 恢复。(#4072 、#3566、#3709、#3714、#4080、#4193、#4008、#4246) - 子智能体: 继承
LoopDetectionMiddleware与摘要中间件,使工具循环能被打断 、步骤能被捕获;将回合预算上限以MAX_TURNS_REACHED暴露并附带部分结果;在累 加式stop_reason+token_budget上统一护栏上限;压缩前注入持久上下文;保留 父 checkpoint 命名空间;在 general-purpose 系统 prompt 中禁用task工具;flush 失败时重新缓冲子智能体事件以避免丢失步骤;并修复子智能体run_id为None时 丢失loop_capped停止原因的问题。(#3931、#4009、#3949、#3980、#4040 、#4215、#4161、#4082、#4059) - 记忆: 加固对 null / 空值边界情况的处理——跳过仅含空白的事实;在更新、检索
与剩余三处原始读取中规整 null 的
confidence/source.confidence;将显式null的backend_config值视为缺省;修复事实无 id 或事实列表为空时的KeyError/UnboundLocalError;停止防抖更新队列的忙等(busy-spin);并在优雅关闭时刷写记 忆队列以防丢失。(#3719、#4074、#4076、#4034、#4217、#3993、#3992 、#4073、#4181) - 运行: 关闭 run 原子性中的多 worker 归属缺口;在租约续期于截止期前无法确认
时令本地执行快速失败,并在 peer 接管后对迟到的完成写入加围栏;多 worker 下将 cancel
降级为租约接管;让
create_thread在插入竞态时仍幂等;从运行时上下文读取stop_reason;并将 run 时长持久化到 checkpoint 以供历史读取。(#4003、#4064、#4414、#3800 、#4188、#4118、#4431) - 运行时: 序列化 SQLite event-store 写入,避免按会话的序列号冲突;在 journal
中跳过隐藏的人类消息;并去掉
_merge_stream_text中静默丢弃 delta 的行为。(#4077 、#3698、#4085) - 网关: 按真实
event_type关联会话消息反馈;把 artifact 服务、gateway 上 传与 Discord 渠道中的阻塞文件 IO 移出事件循环;限制上传文件的上下文清单;并实 时追踪畸形的 Redis 重连 id。(#3651、#3551、#3935、#3927、#3917、#4012) - 上传: 在写入前先占位转换后的 Markdown 配套文件名,使同词干(stem)的两个
可转换上传(或一个可转换上传加一个同词干
.md上传)不再在同一请求内静默互相 覆盖。uploads.auto_convert_documents开启时,配套.md会得到唯一名称(如a_1.md);POST /threads/{id}/uploads与DeerFlowClient.upload_files都会在markdown_file中返回实际文件名。(#4288) - 配置: 将为 null 的对象型配置节规整为默认值;在 store 与 sync checkpointer
中遵循统一数据库配置;并让旧版 DB 回填在已存在的表上补建缺失的
Index对象。(#3573 、#3904、#3994、#4090) - 模型: 将
stream_chunk_timeout默认值应用到所有BaseChatOpenAI子类; 并为ChatOpenAI把api_base规范化为base_url,遇到未知配置 key 时给出告 警。(#4102、#3790) - MCP: 按 server 隔离工具发现失败;同步 session-pool 单例的生命周期;按配置 内容 + 路径(而非仅更新的 mtime)失效工具缓存;在加载时校验 MCP 工具名,使延迟 prompt 保持惰性;并按来源 server 路由工具,而非按名称前缀。(#3772、#3797、 #4124、#4154、#3812)
- 技能: 斜杠技能每个 run 仅激活一次,而非每次模型调用都激活;补齐技能安装安
全扫描的覆盖缺口;在评审 CI 中识别被完全删除的技能包,并在 SkillScan 中把剩余
的
requests/httpx方法识别为网络出口;在无参 skills prompt 段落复用已解 析的 app 配置;并支持不重启 Gateway 即可重新加载已挂载技能。(#4103、#3924 、#4169、#4130、#4160、#4264) - 沙箱: 为反向路径翻译与输出脱敏正则加上段边界;在
read_file/str_replace中处理单边行范围与空文件;对齐 AIO bash 工作目录;在 Windows 的反向 resolve 包 含性检查中使用os.sep;在 bash 命令中规范化 Windows 反斜杠路径;阻止glob/grep/ls暴露被禁用技能的文件;并在沙箱审计中允许合法的 heredoc 命令。(#4035 、#4053、#4078、#4079、#4051、#4058、#3869、#4096、#3786) - 沙箱: 同步沙箱 provider 单例的生命周期(含并发回归测试),并让 provisioner 中的 k8s 调用不阻塞事件循环。(#3730、#3941)
- 沙箱: 将沙箱 artifact 挂载与渠道用户对齐;修复非 root / NFS 主机上的本地
开发(
make dev);停止时回收 macOS 上的 nginx 进程;并修复 Docker 中生产环境 Postgres 的 UV-extras 检测。(#3729、#3590、#3828、#3897) - 渠道: 在解析渠道 provider 配置前先校验 provider;对 GitHub webhook 重投递
去重,并丢弃冗余的 GitHub review-comment webhook 扇出;把斜杠技能白名单检查限
定在 run 的 owner 作用域;将飞书文件消息批量到一个会话,并以 bot @mention 前缀
分发飞书群命令;在
/connect绑定码前接受前导 @mention,且不把裸connect当 作绑定命令;阻止飞书创建会话话题并限流卡片更新;让 UI 运行时渠道配置优先于config.yaml;修复bot_login/mention_login仅含空白时require_mention的门控;防护 企业微信中为 null 的引用字段;并将入站去重按聊天作用域的工作区建立 key,使 Telegram 、飞书、微信与钉钉在默认(未绑定)配置下不再因重投递重复执行智能体,遇到瞬时失 败时释放去重 key 以便重投递仍可恢复。(#4100、#4104、#4131、#4129、#3753 、#4229、#4222、#4251、#3810、#3674、#4055、#4069、#4287) - 前端: 摘要过程中保留消息与持久上下文;流式期间保留 artifact 并稳定 artifact
路径;解析相对 artifact 图片路径;在 header 下拉中保留已展示的 artifact;保持
孤立的工具消息可见;工具步骤期间展示助手文本;客户端导航时重置新会话;防止并发
提交导致流被取消;修复过期 run 的重连与取消处理;修复聊天公式渲染、单波浪线 markdown
、双重 reasoning 渲染、UTF-16 markdown 二进制分类与 Streamdown 中的
<memory>标签;让最近会话行整体可点击;上传前校验附件上限并修复消息复制中上传文件元数据 ;修复移动端工作区与可访问性阻塞、卡片工具消息 bug 以及侧边聊天工具栏 / 面板按 钮行为;拦截未解析的建议模板占位符;刷新通知权限;仅对已完成回合显示分支操作; 在自定义智能体聊天中启用重新生成;并为被中断的首回合 run 生成兜底标题。(#3826 、#3791、#4094、#4038、#3854、#3880、#4114、#3673、#3878、#3908 、#3557、#4245、#3870、#3966、#4209、#3733、#3900、#3944、#3740 、#3976、#3959、#3961、#3764、#3768、#4147、#3967、#3874、#3644) - TUI:
/quit退出前先中断活动 run。(#4235) - harness: 当大纲标题数恰好等于
MAX_OUTLINE_ENTRIES时不再误判为被截断。(#3856) - 追踪: 把 Langfuse trace 元数据附加到目标评估器。(#4202)
- 上下文: 修复 context-compress 的 bug。(#4065)
- ThreadData: 修复
runtime.context为None时的AttributeError。(#3989) - goal: 修复 stand-down 期间
continuation_count被重复递增的问题。(#4199) - 熔断器: 修复半开探测不可重试后熔断器卡死的问题。(#3991)
- GitHub:
allow_authors登录名改为大小写不敏感匹配。(#4218) - 社区工具:
image_search现在返回全分辨率图片 URL。(#3990) - 技能: 把技能历史接口中的阻塞文件 IO 移出事件循环。(#3563)
- 技能: SkillScan 不再把惰性求值的 PEP 695 类型别名误判为网络出口。(#4315)
- 追踪: 从运行时上下文解析 Langfuse trace 的用户。(#3794)
- 护栏: 将内部 owner 归因透传到护栏上下文。(#3839)
- 子智能体: 子智能体上限与
MIN_SUBAGENT_LIMIT保持一致地限幅。(#4081) - 子智能体: 加载按用户作用域的技能。(#4356)
- MCP: 按 server 的 OAuth 预热改为失败即软降级,并持久化轮换后的 refresh token 。(#4084)
- MCP: 忽略畸形的类路径文本。(#4456)
- 认证: 邮箱账号改为大小写不敏感解析。(#4101)
- 认证: 从 setup-status 超时中恢复。(#4371)
- 调度器: 修复一个调度竞态,该竞态可能为同一个定时任务启动两个 run。(#4105)
- 渠道: 缓冲并在 busy run 期间排空被排队的 GitHub 评论。(#4133)
- 渠道: 在转换为 mrkdwn 前先转义 Slack 保留字符。(#4197)
- 渠道: 飞书卡片 / reaction SDK 调用上检查
response.success()。(#4234) - 渠道: 丢弃不携带会话身份的入站钉钉消息。(#4316)
- 渠道: 支持接收入站 Telegram 附件。(#4392)
- 记忆: 合并后的事实从其来源继承
expected_valid_days。(#4225) - 配置:
_memory_config与 AppConfig 自动重载保持同步。(#4208) - Postgres: 用
pool_recycle与command_timeout加固异步引擎,消除陈旧连 接导致的 504。(#4230) - harness: 为
invoke_acp_agent增加超时,避免无限挂起。(#4238) - 社区工具: 在
web_fetch(Browserless)中暴露目标页的错误状态。(#4239) - 沙箱: 放宽 BoxLite / AIO 的租户哈希范围,并在回收时校验身份。(#4171)
- 沙箱:
str_replace在任意文件上遇到空old_str时改为无操作。(#4256) - 沙箱: 序列化 E2B 的释放状态转换。(#4355)
- 沙箱: 限制 E2B 输出同步的资源占用。(#4364)
- 沙箱: 在
after_agent中解包被Overwrite包裹的沙箱状态。(#4381) - 沙箱: 本地 AIO 流量绕过代理。(#4444)
- 模型: 暴露因长度截断的模型响应,而非直接丢弃。(#4309)
- 流式: 保持大文件生成过程的响应性。(#4354)
- 流式: 把自定义事件暴露给
astream_events。(#4403) - 流式: 对回放历史中的缺口发出信号。(#4426)
- 摘要: 使用 run 模型进行摘要,摘要 provider 失败时回退。(#4361)
- 运行时: 模型调用后移除临时的图片上下文。(#4267)
- 运行时: 阻止子图流式帧冒充根帧。(#4407)
- 运行时: 拒绝不支持的 run 选项与流模式。(#4430)
- 运行时: 序列化 checkpoint 写入与活动 run、线性化 delta 模式的 checkpoint
恢复,并接受 SDK 默认的
stream_resumable=false,以避免恢复竞态。(#4437、#4460 、#4468) - checkpoint: 解包对空 channel 的
Overwrite首次写入。(#4383) - nginx: 允许超长聊天 prompt 通过
/api/langgraph/,不再直接返回 500。(#4277) - 网关: 当 header 已设置时,优先使用
X-Trace-Id而非metadata.deerflow_trace_id。(#4283) - 网关: 为分支补种 run-events,使继承的历史在分叉后仍然保留。(#4385)
- 网关: 分支历史补种的 run id 按继承的回合作用域划分。(#4459)
- 前端: 加固 artifact 与 markdown 渲染。(#4117)
- 前端: 工作区变更评审中,把“符号链接替换文件”与“删除”区分开。(#4170)
- 前端: 把工作区变更文本缓存生命周期中的阻塞文件 IO 移出事件循环。(#4268)
- 前端: 对 artifact URL 的路径段进行编码。(#4278)
- 前端: 厘清 run 时长的展示。(#4348)
- 前端: 在分支会话中保留重新生成状态。(#4358)
- 前端: reasoning-effort 未设置时默认展示为 Medium。(#4373)
- 前端: 剥离并解析
<current_uploads>上传上下文标签。(#4402) - 前端: 保持前导的孤立工具消息可见。(#4408)
- 前端: 刷新后保持已完成子任务卡片的稳定。(#4432)
- 前端: 通过 inline style 应用消息图片的
maxWidth。(#4446) - 前端: 恢复 artifact 与侧边面板的可调整大小。(#4469)
- 前端: 允许非 localhost 主机访问 dev-server。(#4471)
- 内容安全: 回填空的内容过滤响应,避免污染会话。(#4394)
- 工具: 从
list_uploaded_files的 schema 中排除注入的 runtime。(#4376) - Artifact: 显式加载完整文件时限定在来源会话内,使其他会话中同路径 artifact 仍保持 1 MiB 预览。([#4634])
- 沙箱:
SandboxAuditMiddleware改为按命令替换所处位置判断风险:普通输出捕获 不再误拦,而命令位置、解释器代码参数、eval/source、process substitution 与 here-string 中执行下载内容仍会阻止;heredoc 正文继续按数据处理。([#4611]、[#4623]) - MCP: 设置页的启停只校验目标 server;允许禁用已不合规目标但拒绝重新启用,
支持规范中的
transport别名、展示后端校验详情,并以原子方式更新共享配置。([#4574]、[#4577]) - MCP: 用按 server 的
session_init_timeout(默认 60 秒,null可关闭)限制工具 发现与持久 stdio session 初始化,避免挂起 server 阻塞智能体装配或 Gateway 事件循环。([#4657]) - 运行时:
.tool-results等超大工具输出外置目录不再计入工作区变更和产物检测, 仅外置工具输出的 run 不会再被投递校验误判失败。([#4657]) - 前端: 回合仍在流式输出时隐藏旧的后续建议。([#3396])
- 前端: 修复流式渲染抖动:不重复播放逐字动画、稳定步骤文本和消息顺序,并保持 reasoning 位于答案上方。([#4266]、[#4510]、[#4513]、[#4578])
- 前端: 聊天路由中的 thread id 现在会编码,特殊字符不再破坏导航。([#4302])
- 前端: 从 React children 正确渲染引用链接。([#4486])
- 前端: 本地化会话导出失败消息。([#4493])
- 前端: 拖拽折叠面板时同步侧边面板状态。([#4556])
- 前端: 每个 run 只渲染一张工作区变更卡片。([#4559])
- 前端: 活动 artifact 发生变化时刷新其内容。([#4584])
- 网关: 拒绝 API 请求中的非正读取上限。([#4284])
- 网关: 解析 thread id 时兼容为 null 的
config.configurable。([#4301]) - 网关: 统一各 API 路由的 thread id 校验。([#4589])
- 网关: 合并并发的会话元数据更新,避免相互静默覆盖。([#4489])
- 网关: 向跨域客户端暴露 run 元数据响应 header,使分离部署的前端能及时获知新 run id。([#4535])
- 网关: 从稳定 checkpoint 执行“编辑并重跑”,确保编辑后的 prompt 真正运行, 并在重跑后保留手动标题。([#4534]、[#4539])
- 运行时: 可从任意存活 Gateway worker 取消 run,停止按钮不再依赖请求路由。([#4500])
- 运行时: interrupt 或 rollback admission 中途取消时关闭替代 run,避免留下不可见的活动 run。([#4472])
- 运行时: 重新生成响应时保留当前标题,并支持最近一次尚未写入 checkpoint 的中断响应。([#4480]、[#4524])
- 智能体: 将 404 等
web_fetch错误页识别为错误证据,使重试和停滞保护能够响应。([#4314]) - 智能体: 规范化澄清选项时兼容 XML-to-dict 形态。([#4527])
- 子智能体: 委派执行使用隔离 callback 与惰性技能激活,修复跨事件循环错误及被动
技能移除
write_file等基础工具的问题。([#4497]) - 沙箱: 初始化沙箱时兼容被
Overwrite包裹的状态。([#4429]) - 沙箱: 安全协调 E2B 沙箱:选择首个健康候选、按用户与会话采纳规范实例、延后 处理 peer 的活动副本,并在宽限期后回收孤儿。([#4443])
- 沙箱: 销毁 readiness 失败的沙箱前先取得所有权,避免 peer 采纳后误杀活动回合。([#4505])
- 沙箱:
grep支持搜索单个文件。([#4512]) - 沙箱: 使用 Redis 所有权时在部署范围内强制 E2B 容量上限。([#4575])
- 技能: 斜杠调用可从托管 integrations 根目录激活集成技能。([#4570])
- 技能: 更新技能时把阻塞文件 IO 移出事件循环,并序列化并发写入。([#3565])
- MCP: 忽略过大的类路径文本。([#4582])
- 记忆: 在创建临界区拒绝重复事实,按条目边界截断 mem0 注入上下文,并阻止 “仅检查”等任务级指令进入长期记忆。([#4599]、[#4600]、[#4604])
- 调度器: 启动成功后的记账若失败,仍保留 run slot 与 run id,防止后续重复启动。([#4504])
- 配置: 被删除的 extensions 配置文件按不存在处理,工具与技能配置解析仍可继续。([#4275])
- 配置: 为异步 ORM engine 规范化
postgres://短 scheme。([#4293]) - 控制台: 模型定价混用货币时禁用成本汇总,避免输出无意义总额。([#4564])
- Browserless: 接受
timeout配置键并加固类型转换。([#4519]) - Docker: 仅在浏览器请求升级时发送
Connection: upgrade,修复远程访问 Docker dev stack 时登录页循环刷新。([#4250]) - 运行时: JSONL 批量事件按 run 分组写入,避免跨多个 run 的批次全落入首个文件。([#4938])
- 运行时: 恢复独立 LangGraph Studio 兼容:图入口、文件式 app、系统助手发现与
langgraph dev工作流重新可用。([#4760]、[#4838]) - 网关: 只在
/messages/page中把turn_duration标到 run 的最后一条 AI 消息。([#4755]) - 网关: 跨越 event 分页上限仍保持精确历史归因,旧 AI 消息不再归到后续 run。([#4953])
- 网关: MCP task worker 停止时以 HTTP 503 拒绝取消请求。([#4963])
- 中间件: 修复动态上下文目标、列表字符串净化、重复无效工具占位符,以及摘要误 压缩当前用户请求等四个上下文问题。([#4667]、[#4668]、[#4693]、[#4882])
- 中间件: 恢复向模型说明
write_todos工具的系统 prompt 注入。([#4735]) - 智能体: SQL agent-store 签名改为内容敏感,时间戳复用时注册表也不会继续提供旧路由。([#4709])
- 工具: 使用运行时用户解析待展示文件,避免有效 artifact 被误判在 outputs 外。([#4677])
- 工具: 强引用延迟子智能体清理任务,防止 GC 销毁待执行清理并泄漏记录与锁。([#4928])
- 子智能体: 每个后台执行使用服务端 execution ID,复用 provider tool-call ID 的 并发 run 不再覆盖、轮询或取消彼此状态。([#4758])
- Harness: 把 ACP workspace 创建与 MCP 配置加载移出事件循环。([#4965])
- MCP: 收到 task snapshot 时拒绝非有限
poll_after_seconds。([#4750]) - MCP: OAuth token 交换中以配置的
grant_type为准,extra_token_params不再能 静默切换 flow。([#4860]) - MCP: 从工作区变更排除内部 stdio 临时目录
.mcp/tmp。([#4898]) - MCP: 持久任务提交中途取消时同时取消远端任务。([#4933])
- 沙箱: 接受文档中的 E2B reconciliation 配置字段。([#4772])
- 沙箱: 按文件、挂载及整个上传过程限制 E2B mount 上传的大小、文件数和时间。([#4812]、[#4842])
- 沙箱: 保留 E2B 同步文件名尾部空白并容忍越界远端 mtime。([#4861])
- 沙箱: 配置解析时拒绝 Redis 所有权中的非有限租约时间值。([#4960])
- 沙箱: 结构化技能读取经沙箱 provider 路径映射解析,与
ls/shell 使用同一启用状态投影。([#4792]) - 技能: moderation scanner 支持 Responses API content block,合法技能管理决策不再误判不可解析。([#4936])
- 记忆: Honcho 与 Mem0 在配置解析时拒绝非正或非有限的 timeout/字符上限。([#4783]、[#4823])
- 记忆: 自定义智能体 bootstrap 事实限定到所选智能体 bucket。([#4804])
- Artifact: Windows 支持原子保存;读取响应提供 SHA-256 ETag,使普通 HTTP LAN
等无
crypto.subtle环境也能预览和编辑。([#4629]、[#4865]) - 前端: 长 run 前后保持会话顺序稳定,用户消息不再重复或落到自身步骤之后, mid-run 页面重载后回合步骤也不再出现在触发该 run 的用户消息之前。([#4620]、 [#4660]、[#4834])
- 前端: HTML artifact 注入 base href 时不再把
<header>误判为<head>。([#4625]) - 前端: 落地页案例通过公开只读
/showcase/路由打开。([#4635]) - 前端: 聊天页按置顶状态排序。([#4643])
- 前端: Markdown inline code 中的
<think>保持原样,并恢复纯 reasoning 回合的复制按钮。([#4647]) - 前端: 模型加载失败时显示工作区错误 banner 与重试操作。([#4840]、[#5021])
- 前端: 后续回合流式输出时仍保留已完成助手消息的复制等操作。([#4844])
- 前端: Browser Live 重连成功后保持新连接,不再立即拆除并再次重连。([#4951])
- 前端: 复制 Lark 授权链接时复用 clipboard fallback。([#4767])
- 前端: 统一使用“DeerFlow”大小写并修复落地页 “What's New” 标题。([#4970])
- 渠道: 用固定 worker pool 与有界队列限制入站流量,关闭时等待真实跨线程任务。([#4800]、[#4816])
- 渠道: 飞书、Telegram 与企业微信发送附件时把文件 IO 移到 worker 线程。([#4633])
- 渠道: Telegram connection identity 查询回到 Gateway 事件循环执行。([#4815])
- 飞书: 接收文件保持事件循环非阻塞,避免重名覆盖、越界写入,并让单个附件失败不阻塞其余消息。([#4627]、[#4903])
- 钉钉: 命令分类前剥离前导
@bot,群聊中的/new等命令可被识别。([#4724]) - Discord: 渠道停止后不再启动 typing-indicator 循环。([#4752])
- 企业微信: 序列化 WebSocket 启停并等待 SDK 接收任务真正结束。([#4762])
- Buzz: 用持久 seen-id store 丢弃重连后的重复事件。([#4888])
- Lark: 沙箱内 CLI lock 目录保持可写,含凭据的 config 根目录仍为只读。([#4701])
- 调度器: 手动触发也遵守全局
max_concurrent_runs,达到上限返回 HTTP 409。([#4769]) - 调度器: 读取时转换序列化的任务时间戳。([#4785])
- 调度器: 支持安全的多实例恢复,启动时不会把 peer 的活动 run 当成本地残留;
通过
scheduler.multi_instance显式启用。([#4713]) - 调度器: busy 的定时 occurrence 改为进入持久队列而非跳过,由
scheduler.queue_timeout_seconds限制等待并可跨 Gateway 重启。([#4918]) - CLI: headless
--print、--json与--cli新增--recursion-limit。([#4615]) - 开发: backend
make dev的 Uvicorn watcher 排除运行时状态,智能体写文件不再重启 Gateway。([#4759]) - 开发: 诊断脚本按自身位置解析路径,可从任意工作目录运行根诊断命令。([#4736])
- Docker: 加固本地与容器启动:
make up等待健康检查,允许缺失.env,生产 环境可写 extensions 配置,运行数据不进入构建上下文,日志命令正确解析 checkout, 默认回环 origin 可完成 dev setup hydration。([#4658]、[#4806]、[#4852]、[#4853]、[#4956]、[#4959]) - 网关: 为持久化消息标记服务端权威的 feed 位置,避免历史超过一页且触发上下文 压缩后,较早的用户消息消失或跳到步骤流中间。([#4696])
- Lark: 托管凭据切换时,先清除旧应用的 OAuth 数据再写入替换项,从而保留新
app secret,后续浏览器授权不再解析到空的
client_secret。([#4820]) - 消息: 移除旧版
<uploaded_files>标签处理:后端将 #4174 之前的写法视为 普通内容,仅剥离<current_uploads>;前端继续剥离旧标签,确保历史会话仍能干净 渲染。([#4826]) - 技能: 在写入门控处拒绝空的
SKILL.mddescription,与 loader 的既有要求 保持一致;编辑自定义技能时,空 description 不再先写入一个随后被 loader 拒绝、 从而破坏磁盘技能的文件。([#4867]) - 沙箱: 将
bash、ls、glob、grep、read_file、write_file、str_replace和task面向模型的description参数统一改为可选(默认空), provider 省略该参数时不再在执行前被拒绝。([#4878]) - 沙箱: 限制 Windows 命令执行:host 命令在新进程组中运行,超时后通过
taskkill /T /F终止,避免子进程使调用一直保持打开;输出继续使用现有的 10 MiB 有界捕获。([#4946]) - 沙箱: 将 Windows MSYS 路径转换排除限定到安全的虚拟路径前缀,不再全局 禁用转换,使依赖正常路径转换的 host-native CLI launcher 恢复工作。([#5003])
- 技能: app config 热重载后重新构建按用户的技能存储,避免其继续绑定到旧配置 实例中的路径。([#4972])
- 技能: 解析可移植的
allowed-toolsscalar 时感知括号,使Bash(tvly *)这类条目保持完整;未匹配括号会被拒绝而非静默拆分,参数限定条目保持字面含义, 不会扩大访问范围。([#4984]) - 智能体: 规范化
Command结果中返回的ToolMessage,错误 payload 不再默认 获得成功回执,工具进度追踪也能正确识别。([#4977]) - MCP:
get_session在 eviction 期间被取消时拆除 in-flight session owner, 避免调用方取消后泄漏 owner task 或超时后仍保持挂起。([#5008]) - MCP: 普通 stdio 工具在 transport 断开后可重新连接:仅当失败的 pooled session 仍在注册时将其淘汰,原始错误照常返回且不自动重放,后续重试会启动新的 子进程。([#5018])
- MCP: 持久 MCP 任务轮询发生协议超时时保留 pooled stdio session——408
并非断开——使任务状态得以保留,下一次轮询不再报告
task_not_found。([#5027]) - MCP: 在配置边界拒绝无法作为 HTTP header value 传输的凭据(尾部换行或空白、 非 ASCII),避免 transport 异常回显完整值并将 secret 泄漏到模型上下文、 checkpoint 和 trace。([#5066])
- 子智能体: poller 意外退出时清理后台任务条目,提交失败时移除 PENDING registry 条目,避免失败或崩溃的轮询泄漏条目,或让子智能体在无人管理的情况下继续运行。 ([#5069])
- 子智能体: 在提交失败路径停止僵尸 PENDING registry 条目,并直接根据 waiter 长度计算容量快照中的 queued 数量,避免遍历被其他线程并发修改的 deque。([#5086])
- 渠道: 将
ChannelStore读取与 mutation 同步,get_thread_id()/list_entries()不再触发dictionary changed size during iteration。([#5083]) - Discord: 强引用 ack-reaction task,并在关闭时将其 drain,避免 GC 静默丢弃 reaction 或在重启周期之间固定住 channel。([#5049])
- Buzz: 将 seen-event 持久化移出事件循环,使用合并的原子写入;写入过程中有 新事件时保留 dirty generation,并在关闭时等待最终 flush。([#5103])
- 流式传输: subscriber 使用过期 cursor 重连到空或已 drain 的 stream 时,
MemoryStreamBridge._make_gap不再触发IndexError。([#5047]) - 上传: dedupe 文件名时在 UTF-8 code point 边界截断 stem,使其保持在 255-byte 上限内;两个仅 dedupe suffix 不同的最大长度文件现在都能成功上传,不再导致整个 batch 失败。([#5059])
- 前端: 格式化结构化上传错误详情(FastAPI validation issue、对象、数组),
不再显示
[object Object]。([#5071]) - 前端: 无需重载即可在当前聊天 header、document title、搜索结果和 metadata cache 之间同步重命名后的会话标题。([#5045])
- 前端: 将已选模型名称限制在 selector button 宽度内,过长名称会在 composer 和 sidecar 中显示省略号,而不再溢出。([#5050])
- 前端: 长子任务卡片标题截断为单行并提供 tooltip;当委派模型省略
description而回退到完整 prompt 时,不再撑破聊天布局。([#5136]) - 开发: 所有平台的前端开发服务器默认使用 Webpack
(
DEER_FLOW_DEV_BUNDLER=turbo可重新启用 Turbopack),避免 Turbopack 在 macOS 上泄漏 PostCSS worker、在 Windows 上发生 runtime panic。([#5036]、[#5133]) - 脚本: 使用显式 interpreter(
bash scripts/...)运行仓库 shell script, 避免 zip/tarball 下载、core.fileMode=false或非 POSIX 文件系统导致 executable bit 丢失后,make docker-start等命令以Permission denied失败。([#5031]) - 依赖: 改为依赖重命名后的
tenkipackage,而非已从 PyPI 移除的tenki-sandbox(import 仍为tenki_sandbox),使干净 checkout 能在make dev/uv sync时正常解析依赖。([#5087]) - 记忆: 配置为终止回合的记忆读取现在会抛出与后端无关的
MemoryReadError, 且 prompt 装配阶段不会再吞掉它:严格模式的 OpenViking(read: raise)、Mem0 与 Honcho 读取都会传播;OpenViking 作用域解析失败遵循配置的读取策略;5 秒注入 deadline 同样遵循该策略(fail-open 时无上下文继续,严格模式以超时为原因抛出)。 ([#4726]) - 记忆: 删除或清空自定义智能体时会取消缓冲中的记忆抽取,待处理的防抖定时器 不再复活已删除的按智能体记忆作用域,也不会用过期的待处理更新覆盖新的清空结果。 ([#5123])
- 智能体: 当上传(或其他)上下文包装被注入消息文本时,会话标题改用用户的原始
消息内容生成,标题不再引用服务端注入的
<current_uploads>上下文;仅含附件的 消息保持New Conversation兜底。([#4729]) - 智能体: 分数形式的摘要触发阈值会基于模型声明的
context_window解析(现已 转换为 LangChain profile),无法解析的分数子句降级为永不触发的阈值并给出告警, 而不是让整个智能体构建崩溃;百分比风格与非有限的触发值会在配置加载时被拒绝。 ([#4901]) - 智能体: 仅当搜索模式无法解析主应用配置时,自定义智能体存储才回退到文件存储 ——非法配置与缺失配置路径会直接暴露,而非静默切换存储后端——异步智能体路由中的 store IO 也移出事件循环。([#4952])
- 中间件: 循环检测的硬停止在整个工具调用批次内生效:选中软告警后不再结束检查 ,同一响应中较晚跨过运营方配置硬上限的调用会被拒绝,而不是随早前的告警一起放行 。([#5245])
- 沙箱: 五个远程沙箱 provider(E2B、OpenSandbox、AIO、Tenki、BoxLite)的
list_dir与glob原样返回文件名,不再剥离空白,名称以空格开头或结尾的文件 不会列在不存在的路径下。([#4980]) - 沙箱: 共享同一会话沙箱的并发子智能体在进程级执行租约与任务作用域的 AIO shell 会话下运行:一个兄弟节点完成不再在他方仍在运行时释放共享沙箱,也不会损坏 隐式持久会话;发生损坏后会晋升健康的替换会话,而不是继续使用它。([#5134])
- 沙箱: Bash 工具引导智能体用证据(
uname -s、sw_vers、uname -a)检测 执行环境,而非依赖模型假设;被拒绝的 host 路径会指引它改用纯命令探测或允许的 虚拟路径,而不是重复被拦截的命令。([#5111]) - 沙箱: Docker AIO 兼容 capability allowlist 加入
FOWNER,启动时会chmod /run/user/1000的 AIO 镜像(如 1.11.0)在加固后的默认 capability 下 可以再次启动,no-new-privileges保持开启。([#5163]) - 沙箱: 文件追加不再在预读失败时破坏已有内容:E2B 追加只把“文件不存在”类 错误视为空文件,其他错误直接抛出,不再用追加的尾部覆盖整个文件;AIO 追加改用 服务端原生 append 模式,完全不需要预读。([#5261]、[#5278])
- 技能: 技能 Markdown 显式以 UTF-8 读取,默认代码页非 UTF-8 的 Windows 主机
上,本地化技能不再以
UnicodeDecodeError校验失败。([#4995]) - MCP: 运行时配置变更后 MCP 工具缓存可以重新初始化:此前的模块级
asyncio.Lock绑定到已关闭的事件循环,且初始化标志无同步保护,导致更新后的 每次调用都以Lock is bound to a different event loop失败,或在多个 worker 线程间产生初始化竞态。([#5062]) - MCP: 同步包装的 MCP 工具保持 LangGraph
ToolRuntime注入(无注解的同步 包装器现在对functools.wraps透明),按用户的作用域解析与持久任务提交不再以runtime=None运行——此前这会让完成通知 run 落到默认 lead 智能体而非该会话的 自定义智能体。([#5164]) - 认证: 重复的 OAuth 身份不再误报“Email already registered”——两类完整性
冲突已区分——OAuth 身份的部分索引也声明了
postgresql_where,Postgres 会按 意图构建部分索引而非全量索引。([#5026]) - 前端: 移动端侧边栏触发按钮在普通与自定义智能体欢迎页保持可点击;此前换行的
(较长的本地化)欢迎文案在相同
z-index覆盖层中可能盖住 header 的可点区域。 ([#5149]) - 子智能体:
SubagentResult生命周期时间戳在所有写入点都使用带 UTC 的时区, 遵循仓库统一约定,非 UTC 主机上不再写入本地挂钟时间。([#5153]) - 浏览器: 后台 live-frame 调度任务保持强引用,GC 不再因回收任务而丢失其
finally中的 pending guard 清理,Browser Live 视图不再静默停止刷新。([#5155]) - 运行时: 同一 LangChain run id 的重复
on_llm_end回调只持久化一条llm.ai.response事件(重放的 usage 按生成位置合并,首个回调为准),provider 重发带回 usage 的回调时,追加式消息 API 不再返回重复响应。([#5187]) - 运行时: completion hook 或任务停止扇出内抛出的取消会先让终态收尾完成—— 扩展 observer 得以运行、流的 END 标记得以发布——然后再重新抛出中断;收尾尾部 仍可被中断。([#5191])
- 模型: 被取消的 LLM 调用会释放其持有的熔断器恢复探测(覆盖 provider 执行、
并发准入与退避),取消后同中间件的后续调用不再看到
CircuitBreakerOpen;探测 所有权按每次调用的 token 加围栏,取消较旧的调用不会释放其他调用的探测。([#5197]) - 运行时: 内嵌
DeerFlowClient的图缓存在任何授权模式下都按生效用户建立键, 并在运行时上下文中落实同一用户,顺序复用于不同用户时不再提供用其他用户的 prompt 与工作区状态装配的图。([#5206]) - 运行时: 被取消的工作区变更快照捕获会排空已在运行的扫描并清理该 run 的文本
缓存,不再泄漏
deerflow-workspace-changes-*目录;仅元数据的捕获则立即传播 取消,不再等待扫描完成。([#5232]、[#5234]) - 持久化: Gateway 启动时容忍数据库已被迁移到经明确评审的更新版本
(
0019_thread_incarnations),使部署更新后仍可回滚到本镜像;其他未知版本、 空版本表与多行版本表仍然快速失败。([#5219]) - 社区工具: Tavily Extract 结果缺少
title时回退到结果 URL 或请求 URL 作为 展示标题,不再因KeyError丢弃可用页面内容。([#5280]) - 上传: 上传文档的大纲排除围栏代码块,代码注释与围栏内的粗体示例不再挤占 50 条标题预算中的真实章节。([#5281])
- 子智能体: 压缩之后,委派账本会区分“执行完成”与“任务验收”,并保留已完成 子智能体未满足与未验证验收标准的有界示例,主智能体会修复剩余缺口,而不是把已完成 的结果当作全部完成。([#5287])
- 开发:
_pick_python()通过/usr/bin/env校验解释器候选,与前端实际的 启动方式保持一致;在 Microsoft Store Python 桩能通过 Bash 探测却无法通过env的 Windows 上,make dev不再无法启动前端。([#5181])
- 运行时: 为
MemoryRunStore按thread_id、MemoryRunEventStore事件按run_id建立索引,避免 O(n) 扫描。(#3562、#3686) - 子智能体: 通过 seen-id 集合对流式 AI 消息去重(O(n²) -> O(n))。(#3687)
- 沙箱:
LocalSandbox的路径改写正则与本地路径脱敏模式改为按实例缓存,不再 每次搜索命中都重新编译。(#3648、#3713) - 消息: 按组为工具调用结果建立索引。(#4411)
- 前端: 流式渲染按帧预算合并,而非逐 chunk 渲染。(#4425)
- 前端: 不再在每个流式 chunk 上重新推导消息内容。(#4441)
- 沙箱:
read_file只从沙箱读取请求的行范围,不再先获取整个文件。([#3824]) - 浏览器: Browser Live 进度帧改用 JPEG 编码,减小传输负载。([#4836])
- 中间件: 通过
wrap_model_call注入view_image内容,而非使用进入 checkpoint 的隐藏消息,避免每张已查看图片最多 20 MB 的 base64 数据同时存在于两个 checkpoint 中,也避免中断的 run 遗留该 payload。([#5014]) - 前端: 在流式 chunk 之间缓存已稳定消息的 copy-data 推导结果,不再让每个 chunk 都为每条已稳定消息重新计算 toolbar/copy 文本。([#5095])
- 运行时: 限制终态 run 结束后的 Gateway 内存,阻止 GC 后的低水位随已完成 session 持续上升。([#5112])
- 前端: 聊天流改为请求
messages-tuple+updates+custom,不再请求完整 的values状态快照——重传的历史values消息约占 SSE 负载的 75%——在本地把 reducer 事件折叠进渲染状态,完整快照仅保留用于回放缺口恢复。([#5159])
- 提示词注入: 新增输入净化中间件防御提示词注入,输入护栏中伪造的框架标签会
被拦截,系统上下文以
SystemMessage注入以隔离角色。(#3662、#4155、#3661) - 提示词注入: 对渲染进模型 prompt 的不可信内容进行 HTML 转义——记忆事实与摘
要、
SOUL.md、子智能体描述、技能元数据,以及记忆更新 prompt 中的会话块——并中 和web_capture工具结果中的提示词注入标签。(#4028、#4119、#4137、#4157 、#4162、#4099、#4060、#4097、#4128) - 机密: 从技能环境中清除继承来的密钥环境变量(
MYSQL_PWD、REDISCLI_AUTH、缩写形式的*_PASS与 Postgres 的PGPASSFILE);请求作用域的密钥对斜杠激 活与自主调用的技能都会绑定。(#4018、#4026、#3871、#3938) - web_fetch: 针对自托管 provider 的 SSRF 防护。(#3942)
- 护栏: 空的 allowlist 现在会拒绝所有工具,而非放行(fail open)。(#4067)
- 鉴权: 全局技能管理接口现在要求管理员权限;旧版 skills 挂载按用户可见性门
控;artifact 遵循受信任的
owner-user-idheader;受信任的鉴权主体透传到运行时 。(#3855、#3985、#3982、#4203) - 认证: 在 access-token 生命周期内持久化
csrf_tokencookie。(#3872) - 存储: 不再在 checkpoint 状态中持久化 base64 图片数据。(#4140)
- MCP: 拒绝 run metadata 中的旧版 MCP 凭据。([#4448])
- MCP: 在配置 API 中限制 stdio launcher 参数与环境变量,防止 allowlist 中的
npx/uvx注册被参数或环境变量转化为任意代码执行。([#4617]) - 认证: 加固登录后
next路径校验。([#4587]) - 运行时: 在智能体、上传、ThreadData、记忆与技能中遵循 LangGraph Server 的 已认证用户身份,并拒绝客户端提供的身份字段。([#4538])
- 前端: 分离 origin 部署中,模型、工作区变更和 range artifact 请求会发送 session cookie。([#4827])
- 前端: 恢复自定义 Streamdown rehype 链的净化,artifact Markdown 与记忆设置
摘要不再能渲染
javascript:链接或on*handler 等恶意 HTML。([#4987]) - 技能: 投影技能文件改为复制而非 hardlink,沙箱写入不能再修改规范来源;所有 平台(含 Windows)遇到漂移的投影命名空间都会 fail closed。([#4825]、[#4830])
- 脚本: support bundle 中任意位置的 secret-shaped key(如
db_pass、signing_key)都会脱敏。([#4242]) - 沙箱: MCP 来源的工具结果现在会通过与内置网络工具相同的信任边界进行净化,
恶意或被攻陷的 MCP server 无法再向模型传入伪造的
<system-reminder>或用户输入 边界标签。([#4839]) - 沙箱: 加固本地 Docker sandbox container:sandbox host 非 loopback 时,
发布端口默认绑定 Docker bridge gateway 而非
0.0.0.0(DEER_FLOW_SANDBOX_BIND_HOST=0.0.0.0可恢复广泛绑定);使用 Docker 默认 seccomp profile 替代无条件seccomp=unconfined(DEER_FLOW_SANDBOX_SECCOMP_UNCONFINED=1可重新启用);container 还会丢弃 所有 capability、启用no-new-privileges并使用有界资源。([#4986]) - 鉴权: 在无状态 stream/wait endpoint 上强制 run-create 权限
(
runs:create);创建、更新、恢复和手动触发定时任务 mutation 时,同时要求threads:write与runs:create。([#5030]) - 鉴权: 复用持久化 sandbox 前重新检查授权策略,使被撤销的
sandbox:executegrant 在下一次 sandbox-backed 回合立即生效,而不会随缓存的 sandbox 继续存活。([#5006]) - 技能: 在 sandbox 文件系统层强制 Custom Agent 技能 allowlist:显式
skills策略会生成签名的按用户/会话技能视图,带 shell 或文件工具的 Custom Agent 不再能 读取策略排除的技能。([#5077]) - run: GET stream join 上的取消/回滚 action 现在返回
405 Method Not Allowed——取消后继续 stream 应使用 POST——关闭 safe method 上 被 CSRF middleware 有意豁免的状态变更;不带 action 的 GET join 保持不变。 ([#5092]) - Lark: Windows 上的 Lark CLI 凭据目录强制私有 ACL(仅 Gateway SID 的受保护
DACL、拒绝 reparse point、基于句柄的遍历),把 POSIX
0700/0600的保密性 契约扩展到继承授权、junction 重定向、硬链接别名与 TOCTOU 替换等场景。([#5141]) - 沙箱: 沙箱子进程环境会清除
SSH_AUTH_SOCK——继承宿主机 ssh-agent socket 会让沙箱内代码用智能体持有的所有密钥签名与认证——除非技能通过 required-secrets 显式声明。([#5145])
- 文档: 说明生产 Docker 下
LocalSandboxProvider如何解析sandbox.mounts[].host_path,并给出 Gateway bind-mount 与配置示例。([#3833]) - 文档: 说明 Crawl4AI >= 0.9 需要 bearer token。([#4518])
- 文档: 记录 GitHub 入站去重 TTL 语义及不会被去重的重投递,并收紧测试。([#4274])
- 文档: 更新智能体
AGENTS.md与ARCHITECTURE.md指南。([#4817]) - 文档: 新增 Honcho 记忆后端专门指南,并在 README 加入长期记忆入口。([#4822])
- 文档: 自定义智能体文档与 API 对齐(中英文 agents / threads / lead-agent
页面):必填的 ASCII
name请求字段、小写存储、/api/agents/check的名称可用 性行为,以及不再声称从display_name自动派生 slug。([#4944])
- 测试: 前端单元测试迁移到 rstest,并在 DOM 环境运行 hook 级测试。([#3703]、[#4453])
- 测试: live client 测试要求显式 opt-in。([#4482])
- 测试: LLM 错误测试替身不再复用共享
FakeError。([#4744]) - 测试: 工具输出测试用自构造失败条件替代魔法不可写绝对路径。([#4722])
- 测试: 新增多回合消息流图集成不变量测试。([#3708])
- 测试: 使用 Monocle Test Tools 新增 trace 行为测试,校验路由、工具调用和 token/时长成本。([#4025])
- 测试: 覆盖 MCP 层中被动技能的工具可见性。([#4247])
- 测试: 为感知租约的孤儿恢复增加 SQL 与并发 reconciler 覆盖。([#4427])
- 测试: 恢复 memory updater 回归测试。([#4490])
- 测试: 锁定 Gateway offline banner 的 POST logout 行为。([#4506])
- 测试: 在 SkillScan 测试中记录已知 instance-client 假阴性。([#4644])
- 重构: 抽取并测试前端 placeholder 检测工具。([#3783])
- 重构: 合并 E2B client 生命周期 helper,并在 warm-pool 淘汰时复用 kill helper。([#4262]、[#4298])
- 重构: 命名 E2B capacity ledger 的 meta-field 数量,使 admission offset 明确。([#4764])
- 开发: blocking-IO detector 的调用图追踪 self/cls 属性链和本地别名。([#4200])
- CI: 发布 lark-cli-init 与 lark-broker 镜像。([#4558])
- 开发: host 侧 pnpm 调用统一经带 Corepack fallback 的 runner。([#4405])
- 基准: 新增隔离的 checkpoint channel-mode 基准,对比
full与delta的延迟、存储和回放。([#4395]) - 依赖: 升级
cryptography49.0.0 -> 50.0.0、postcss8.4.31 -> 8.5.25、h24.3.0 -> 4.4.1、两个langgraph-checkpoint-*3.1.0 -> 3.1.1,以及nanoid5.1.6 -> 5.1.16。([#4681]、[#4683]、[#4737]、[#4738]、[#4747]、[#4748]) - 基准: 在
backend/scripts/benchmark/deermem_eviction/下新增可复现的混合 memory eviction 评测,为 #4789 策略提供按构造实现 blind 的确定性 grader。 ([#4810]) - 基准: 在 checkpoint benchmark 中同时测量 Postgres checkpoint/blob/write 的存储增长,并与内存和 SQLite 对照。([#5051])
- 测试: 将
tests/blocking_io/从make test中排除;专用的make test-blocking-iosuite(及其 CI workflow)仍是该目录的 owner。([#5105]) - 重构: 在五个远程 sandbox provider 间共享 sandbox identity 推导和 acquire serialization(RFC #4741),替换五张会随进程生命周期无限增长的 provider 专用 lock table;每个 provider 的 golden vector 保证推导出的 id 逐字节一致。([#5089])
- CI: 后端单元测试 workflow 拆分为四个并行分片——各自独占 runner 与隔离的
Postgres/Redis——使用
pytest-split与提交的时长基线,基线缺失时直接失败;make test仍是完整的离线套件入口。([#5137]) - 开发: Playwright
webServer的 Next.js 改经pnpm exec启动,Windows 的 E2E 运行可解析平台对应的包二进制,不再因无扩展名的 POSIX shim 失败。([#5185]) - 测试: Windows 上跳过 POSIX mode-bit 技能权限断言(
chmod契约在该平台不可 观测),使 Windows 贡献者可以获得绿色的后端套件基线。([#5244])
2.0.0 — 2026-06-15
DeerFlow 2.0 是围绕"超级智能体"框架的彻底重写,核心包含子智能体、持久化记忆、
沙箱执行以及可扩展的技能(Skill)/工具系统。本版本与 1.x 系列没有共享代码,
原有的 Deep Research 框架仍在
main-1.x 分支上维护。
本次发布关闭了 2.0.0 里程碑, 自首个 2.0 里程碑标签以来累计合并 180 个 Pull Request。
- harness: 从
RunStore重新加载历史 run,并持久化"已中断(interrupted)" 状态。run 的取消 / 多任务调度语义现在要求拥有该 run 的 worker 上具备可用的 RunStore;跨 worker 的取消请求将返回409,不再静默"伪成功"。(#2932)
- 智能体: 自定义智能体支持自我更新,并按用户隔离 —— 智能体可在普通对话中
持久化对自身
SOUL.md/config.yaml的修改。(#2713) - 循环检测: 支持配置开关,并可按工具维度覆盖触发频率。(#2586、#2711)
- 循环检测: 警告注入延后执行,避免与工具调用生命周期错位。(#2752)
- 运行: 将
model_name从 gateway 请求一直透传到运行时与持久化层(SQLite 存储)。(#2775) - 子智能体: 通过终态任务事件,把子智能体的 token 用量流式上报到 header。 (#2882)
- 记忆: 新增
memory.token_counting配置,支持在受限网络环境下禁用 tiktoken。(#3465) - 建议: AI 追问(follow-up)建议改为可选。(#3591)
- 模型: 新增 StepFun 推理模型适配器。(#3461)
- 社区工具: 新增 Brave Search 网络检索工具。(#3528)
- 渠道: Discord 增加"仅响应 mention"模式、话题路由(thread routing)以及 正在输入指示。(#2842)
- IM: 新增"用户自有 IM 渠道连接"——用户可以在运营方配置的 bot 之上,绑定 自己的 Slack / Telegram / Discord / 飞书 / 钉钉 / 微信 / 企业微信 账号。 (#3487)
- 模型: 新增 MiMo 推理内容(reasoning content)的补丁支持。(#3298)
- 模型: 新增 MiniMax provider,用于图像 / 视频 / 播客类技能,并新增"音乐 生成"技能。(#3437)
- 社区工具: 新增 SearXNG 与 Browserless 的网络检索 / 抓取工具。(#3451)
- 社区工具: 为
image_search新增 Serper Google 图片 provider。(#3575) - 渠道: Telegram 智能体回复改为就地编辑占位消息的方式流式输出。(#3534)
- 追踪: LangGraph 追踪名设置为
lead_agent(自定义智能体则使用其agent_name),让 Langfuse / LangSmith 中的 trace 更清晰。(#3101) - 前端: 优化 token 用量的展示模式。(#2329)
- 默认值: 默认开启 token 用量统计。(#2841)
- 默认值: 提高默认的上下文摘要触发阈值。(#3174)
- 追踪: 把子智能体的 span 归属到父线程的 Langfuse trace 上。(#3611)
- 技能: 新增
blocking-io-guard技能,用于阻塞 IO 排查与运行时锚点。 (#3503) - 技能: 新增面向维护者的 issue 与 PR 工作流技能。(#3554)
- 技能: 增强维护者编排(orchestrator)的评审工作流。(#3606)
- harness: 把 thread 元数据过滤下推到 SQL,不再在 Python 侧后过滤。 (#2865)
- 运行时: 为 run 增加
thread_id索引,避免RunManager中的 O(n) 扫描。 (#3499) - 运行时: 为
MemoryRunEventStore中的消息建立索引,避免 O(n) 扫描。 (#3531) - 持久化: 按类缓存
Base.to_dict的列反射结果。(#3654) - 沙箱: 加快 glob/grep 遍历中的
should_ignore_name判断。(#3657)
- 上传: 拒绝指向符号链接的上传目标。(#2623)
- 上传: 在 Windows 上支持基于符号链接保护的安全上传。(#2794)
- MCP: 在 MCP 配置接口的响应中对敏感字段进行脱敏。(#2667)
- MCP: 加固 MCP 配置接口对异常输入的处理。(#3425)
- 认证: 拒绝跨站点(cross-site)的认证 POST 请求。(#2740)
- 网关: 限制 skill artifact 预览的解压上限,避免被 zip-bomb 类构造滥用。 (#2963)
- 沙箱: 仅在 aio(DooD)沙箱模式下挂载宿主机的 Docker socket。(#3517)
- 沙箱: 默认不再 bind-mount 宿主机的 CLI 认证目录。(#3521)
- 运行时: rollback 恢复的 checkpoint 现在能够覆盖更新的 checkpoint。 (#2582)
- 运行时: 持久化 run 的消息摘要。(#2850)
- 运行时: 限制
write_file执行失败时上报的观测信息长度,避免失败 trace 撑爆上下文。(#3133) - 运行时: 加锁保护同步单例的初始化与 reset 路径。(#3413)
- 运行时: 为 run events 移除 PostgreSQL 上不必要的聚合
FOR UPDATE。(#2962) - 运行: gateway 重启后从持久化存储中恢复历史 run。(#2989)
- 网关: threads 接口返回 ISO 8601 格式的时间戳。(#2599)
- 网关: 对已经处于 interrupted 状态的 run,cancel 接口幂等返回。 (#3058)
- 网关: 将
stream_existing_run拆分为按 HTTP 方法区分的多个路由,确保 OpenAPIoperationId唯一。(#3228) - 事件: 序列化结构化的 DB event 内容。(#2762)
- 持久化: SQLite 后端的存储统一返回带时区的时间戳。(#3130)
- 持久化: 复用 token 用量按模型分组的 SQL 表达式。(#2910)
- 运行: 忽略已过期的 run reconnect 冲突。(#3284)
- nginx: 把 CORS 策略下放到 gateway 的 allowlist,避免双重应用。 (#2861)
- 持久化: 修复运行时 journal 中 run 生命周期事件的记录。(#3470)
- 网关: 在无状态(stateless)run 接口上强制校验 thread 归属。(#3473)
- 运行时: 通过 SSE values 事件把 interrupt 透传给 LangGraph SDK。(#3605)
- 序列化: 从流式 values 事件中剥离 base64 图片数据。(#3631)
- 历史: 从 REST 接口响应中剥离 base64 图片数据。(#3535)
- 网关: token 用量归因到实际使用的模型。(#3658)
- 子智能体: 让"子智能体超时"成为原子化的终态。(#2583)
- 子智能体: 工具与中间件按 model 覆盖(model override)来构造。(#2641)
- 子智能体: 把
system_prompt与 skills 合并到单条SystemMessage。 (#2701) - 子智能体: 子智能体与父 run 的 checkpointer 隔离。(#3559)
- 智能体:
update_agent与setup_agent一致,遵循runtime.context的user_id。(#2867) - 智能体: 解决
TodoMiddleware中todos通道的类型冲突。(#3200) - 智能体: 把自定义智能体路由中的阻塞文件 IO 移出事件循环。(#3457)
- 智能体: 新智能体的 bootstrap 流程保持在用户作用域内。(#2784)
- 循环检测: 注入 warn 时仍保持 tool-call 配对。(#2725)
- 中间件: 同步原始 tool-call 元数据。(#2757)
- 中间件: dangling 配对中间件正确处理非法 tool call。(#2891)
- 中间件: 防止 todo 完成提醒消息泄漏到 IM 渠道。(#2907)
- 中间件: 调用模型前先把 tool result 的相邻关系规范化。(#2939)
- 智能体:
resolve_agent_dir要求存在config.yaml,从而跳过仅含记忆的 目录。(#3481) - 智能体: 在 context / configurable 间同步
agent_name,并拒绝空的 soul。(#3553) - 中间件: 把
UploadsMiddleware中的上传扫描移出事件循环。(#3311) - 中间件: 把记忆注入移出事件循环,避免 tiktoken 造成阻塞。(#3411)
- 中间件: 针对非挂载型沙箱,把超限的工具输出外置到沙箱中。(#3417)
- 中间件: 在中间件 state 中保留 sandbox reducer。(#3629)
- 子智能体: general-purpose 的
max_turns提升到 150,默认超时提升到 30 分钟。(#3610)
- 记忆: 用常驻事件循环替换短生命周期的
asyncio.run()。(#2627) - 记忆: 队列化的 memory 更新按智能体维度隔离。(#2941)
- 记忆: 解析被外层包裹的 memory 更新 JSON 响应。(#3252)
- 追踪: 把
session_id与user_id透传到 Langfuse trace。(#2944) - 追踪: 修复中文 memory trace 信息显示为 unicode 转义序列的问题。 (#3104)
- MCP: 修复 MCP 配置中列表型变量的环境变量解析。(#2556)
- 模型: Codex 的 token 用量记录到
usage_metadata。(#2585) - 沙箱: 在
RemoteSandboxBackend中补上list_running。(#2716) - 沙箱: Windows / Git Bash 下关闭 MSYS 路径转换。(#2766)
- 沙箱: 沙箱就绪轮询不再阻塞事件循环。(#2822)
- 沙箱:
SandboxAPI 边界统一遵守/mnt/user-data契约。(#2881) - 沙箱: Provisioner 的 PVC 数据按用户隔离。(#2973)
- 沙箱: 合并幂等的沙箱状态更新。(#3518)
- 工具: 引入
Runtime类型别名,消除 Pydantic 序列化告警。(#2774) - 工具: 在重入式
get_available_tools调用之间保留tool_search的提升 状态。(#2885) - harness: 为同步客户端封装仅异步可用的 config 工具。(#2878)
- harness: 同步客户端可用所有原本仅异步的工具(统一封装)。(#2935)
- 工具检索: 通过移除 ContextVar,可靠地隐藏延迟加载的 MCP schema。 (#3342)
- 检索: 修复 DDGS 的维基百科区域处理。(#3423)
- web_fetch: 在受限网络环境下为 Jina reader 支持代理。(#3430)
- 沙箱: 通过
Command持久化懒加载获取到的沙箱状态。(#3464) - 沙箱: 修复 AIO 沙箱缓存被陈旧复用的问题。(#3494)
- 沙箱: 在使用全新 id 重试前先创建 shell session。(#3577)
- 沙箱: 不再把字符串字面量路径片段误判为不安全的绝对路径。(#3623)
- 沙箱:
read_file命中二进制文件时返回可操作的提示信息。(#3624) - MCP: 让 stdio MCP 产出的文件可通过虚拟沙箱路径解析。(#3600)
- MCP: 在设置页的工具列表上展示"需要管理员权限"的状态。(#3533)
- MCP: 新增工具缓存重置接口。(#3602)
- 上传: 修复上传文件大小的接口契约。(#3408)
- 技能: 强制校验
allowed-tools元数据。(#2626) - 技能: 在各聊天渠道下加固
/skill斜杠激活。(#3466) - 技能: 修复自定义 skill 安装时的权限问题。(#3241)
- 渠道: Gateway 的命令请求需要鉴权。(#2742)
- 技能: SKILL.md 出现 YAML 错误时,展示出错行号与引号提示。(#3335)
- 技能: 把技能压缩包的安装移出事件循环。(#3505)
- 渠道: 提取回复时忽略隐藏的控制消息。(#3270)
- 渠道: 渠道重启时重新加载配置。(#3514)
- 渠道: 暴露企业微信(WeCom)WebSocket 连接失败的信息。(#3526)
- 渠道: Discord 上传完成后关闭文件句柄。(#3561)
- 渠道: 用户自有 IM 消息要求绑定身份。(#3578)
- 渠道: IM 文件与辅助命令限定在 owner 作用域内。(#3579)
- 渠道: 以运行时的 provider 状态为权威来源。(#3580)
- 渠道: 加固运行时凭证管理接口。(#3581)
- 渠道: 让渠道连接流程可确定(deterministic)。(#3582)
- 渠道: 集中各渠道共享的重试辅助逻辑。(#3583)
- 渠道: 增加运行态的防护约束(operational guardrails)。(#3584)
- 渠道: 按相等性(equality)退订渠道监听器。(#3608)
- 认证: 用缓存响应替换 setup-status 接口的 429 限流。(#2915)
- 认证: 自动生成的 JWT secret 持久化保存,重启后仍可用。(#2933)
- 认证: 对齐"认证禁用(auth-disabled)"模式与 mock 历史加载行为。 (#3471)
- 前端: 在 prod 模式下恢复
getGatewayConfig的localhost兜底。 (#2718) - 聊天: 修复新会话第一条用户消息被吞掉的问题。(#2731)
- 前端: header 总计 token 数采用后端线程级 token 用量。(#2800)
- 前端: 异步 chat submit 完成后再清空输入框。(#2940)
- 前端: 修复登录页闪烁与 ResizeObserver 死循环。(#2954)
- 前端: 对恢复出的会话消息去重。(#2958)
- 前端: 避免乐观渲染产生重复的用户消息。(#3002)
- 前端: 流式中的 assistant 消息不再展示复制按钮。(#3176)
- 前端: 新建 thread 后立即在侧边栏显示。(#3283)
- 前端: 新建会话的 thread 消息相互隔离。(#3508)
- 前端: 限制深层嵌套列表的缩进,避免渲染崩溃。(#3393、#3570)
- token 用量: token 用量按 message id 去重聚合。(#2770)
- 前端: 剪贴板复制回退到 Streamdown。(#3397)
- 前端: 移除用 Backspace 删除 prompt 附件的快捷键。(#3410)
- 前端: 把记忆设置的工具栏重排为两行。(#3433)
- 建议: 解析追问问题前先剥离内联的
<think>推理内容。(#3435) - 前端: 追问建议被禁用时不再发起请求。(#3599)
- 前端: 工作区会话列表在超过 50 个 thread 后分页加载。(#3485)
- 前端: 避免长串不可断行文本导致用户消息气泡溢出。(#3488)
- 前端: SSR 鉴权探测无法连通 gateway 时仍保持工作区可交互。(#3495)
- 前端: 用户消息按纯文本渲染,并限制引用(blockquote)嵌套层级。 (#3502)
- 前端: 删除后重置当前激活的会话。(#3519)
- 前端: 优化移动端工作区布局。(#3646)
- 前端: 多段(multi-part)AI 消息渲染完整内容。(#3649)
- 打包: 新增
postgresextra 以支持 store / checkpointer,并完善安装 说明。(#2584) - harness: 运行时路径以项目根目录为基准解析。(#2642)
- Docker: 让 nginx 在每次请求时再解析 upstream 名称。(#2717)
- Docker: 把 Gateway 默认改为单 worker,避免多 worker 模式下出现异常。 (#3475)
- 脚本:
make dev重启时保留uvextras。(#2767、#2754) - 脚本: 停止时清理本地 nginx。(#3005)
- 部署: 没有
python3时,secret 生成回退到python/openssl。 (#3074) - 配置: 让 reload boundary 在代码层面可发现。(#3144、#3153)
- replay-e2e: 重放 fixture 按调用方与会话作为 key。(#3453)
- 安装向导: 更新 LLM provider 向导的默认值。(#3421)
- 配置: 把
config.yaml中为 null 的列表字段归一为空列表。(#3434) - 脚本: gateway reload 时排除运行时状态目录。(#3426)
- 脚本: 在 uvicorn 的 reload-exclude 生效前先创建 backend/sandbox 目录。 (#3460)
- 脚本: 修复
make start-daemon之后无法用make stop正确停止 next-server 的问题。(#3498) - Makefile: 修复 per-commit hooks 的安装。(#3569)
- replay-e2e: 重放匹配改为按会话,而非使用当前系统 prompt。(#3436)
- provider(重构): 各 provider 间共享 assistant payload 的回放匹配逻辑。 (#3307)
- lead-agent(重构): 把
build_middlewares改为 public,去掉最后一个跨 模块的私有导入。(#3458) - todo(重构): 移除未使用的完成提醒计数器。(#3530)
- 补充 blocking-IO 检测的使用与维护说明。(#3233)
- 清理文档中残留的"独立 LangGraph 服务器"相关内容。(#3301)
- 在 PR 模板与 CONTRIBUTING 中补充 AI 辅助声明。(#3398)
- 补充自定义 AIO 沙箱镜像的文档。(#3548)
- 开发: 新增 async / thread 边界检测器。(#2936)
- 运行时: 增加 lifecycle 端到端测试覆盖。(#2946)
- Windows: 后端 Makefile 各 target 加入
PYTHONIOENCODING与PYTHONUTF8。(#3069) - blocking-io: 检测器以"显式失败(fail-loud)"方式解析仓库根目录,并提供 共享 CLI 入口。(#3512)
- 运行时: 为
JsonlRunEventStore的异步 IO 增加 Blockbuster 运行时锚点。 (#3313) - CI: 统一 PR / issue 打标签逻辑,修复 reviewing 任务的崩溃与标签抖动。 (#3455)
+[#3183]: https://github.com/bytedance/deer-flow/pull/3183 [#3396]: https://github.com/bytedance/deer-flow/pull/3396 [#3442]: https://github.com/bytedance/deer-flow/pull/3442 [#3565]: https://github.com/bytedance/deer-flow/pull/3565 [#3703]: https://github.com/bytedance/deer-flow/pull/3703 [#3708]: https://github.com/bytedance/deer-flow/pull/3708 [#3783]: https://github.com/bytedance/deer-flow/pull/3783 [#3824]: https://github.com/bytedance/deer-flow/pull/3824 [#3833]: https://github.com/bytedance/deer-flow/pull/3833 [#4025]: https://github.com/bytedance/deer-flow/pull/4025 [#4178]: https://github.com/bytedance/deer-flow/pull/4178 [#4200]: https://github.com/bytedance/deer-flow/pull/4200 [#4210]: https://github.com/bytedance/deer-flow/pull/4210 [#4242]: https://github.com/bytedance/deer-flow/pull/4242 [#4247]: https://github.com/bytedance/deer-flow/pull/4247 [#4250]: https://github.com/bytedance/deer-flow/pull/4250 [#4262]: https://github.com/bytedance/deer-flow/pull/4262 [#4266]: https://github.com/bytedance/deer-flow/pull/4266 [#4274]: https://github.com/bytedance/deer-flow/pull/4274 [#4275]: https://github.com/bytedance/deer-flow/pull/4275 [#4284]: https://github.com/bytedance/deer-flow/pull/4284 [#4293]: https://github.com/bytedance/deer-flow/pull/4293 [#4298]: https://github.com/bytedance/deer-flow/pull/4298 [#4301]: https://github.com/bytedance/deer-flow/pull/4301 [#4302]: https://github.com/bytedance/deer-flow/pull/4302 [#4314]: https://github.com/bytedance/deer-flow/pull/4314 [#4360]: https://github.com/bytedance/deer-flow/pull/4360 [#4377]: https://github.com/bytedance/deer-flow/pull/4377 [#4382]: https://github.com/bytedance/deer-flow/pull/4382 [#4384]: https://github.com/bytedance/deer-flow/pull/4384 [#4395]: https://github.com/bytedance/deer-flow/pull/4395 [#4405]: https://github.com/bytedance/deer-flow/pull/4405 [#4406]: https://github.com/bytedance/deer-flow/pull/4406 [#4423]: https://github.com/bytedance/deer-flow/pull/4423 [#4427]: https://github.com/bytedance/deer-flow/pull/4427 [#4429]: https://github.com/bytedance/deer-flow/pull/4429 [#4439]: https://github.com/bytedance/deer-flow/pull/4439 [#4443]: https://github.com/bytedance/deer-flow/pull/4443 [#4448]: https://github.com/bytedance/deer-flow/pull/4448 [#4453]: https://github.com/bytedance/deer-flow/pull/4453 [#4472]: https://github.com/bytedance/deer-flow/pull/4472 [#4480]: https://github.com/bytedance/deer-flow/pull/4480 [#4482]: https://github.com/bytedance/deer-flow/pull/4482 [#4486]: https://github.com/bytedance/deer-flow/pull/4486 [#4489]: https://github.com/bytedance/deer-flow/pull/4489 [#4490]: https://github.com/bytedance/deer-flow/pull/4490 [#4493]: https://github.com/bytedance/deer-flow/pull/4493 [#4497]: https://github.com/bytedance/deer-flow/pull/4497 [#4500]: https://github.com/bytedance/deer-flow/pull/4500 [#4501]: https://github.com/bytedance/deer-flow/pull/4501 [#4504]: https://github.com/bytedance/deer-flow/pull/4504 [#4505]: https://github.com/bytedance/deer-flow/pull/4505 [#4506]: https://github.com/bytedance/deer-flow/pull/4506 [#4509]: https://github.com/bytedance/deer-flow/pull/4509 [#4510]: https://github.com/bytedance/deer-flow/pull/4510 [#4512]: https://github.com/bytedance/deer-flow/pull/4512 [#4513]: https://github.com/bytedance/deer-flow/pull/4513 [#4516]: https://github.com/bytedance/deer-flow/pull/4516 [#4518]: https://github.com/bytedance/deer-flow/pull/4518 [#4519]: https://github.com/bytedance/deer-flow/pull/4519 [#4524]: https://github.com/bytedance/deer-flow/pull/4524 [#4527]: https://github.com/bytedance/deer-flow/pull/4527 [#4528]: https://github.com/bytedance/deer-flow/pull/4528 [#4530]: https://github.com/bytedance/deer-flow/pull/4530 [#4533]: https://github.com/bytedance/deer-flow/pull/4533 [#4534]: https://github.com/bytedance/deer-flow/pull/4534 [#4535]: https://github.com/bytedance/deer-flow/pull/4535 [#4538]: https://github.com/bytedance/deer-flow/pull/4538 [#4539]: https://github.com/bytedance/deer-flow/pull/4539 [#4540]: https://github.com/bytedance/deer-flow/pull/4540 [#4556]: https://github.com/bytedance/deer-flow/pull/4556 [#4558]: https://github.com/bytedance/deer-flow/pull/4558 [#4559]: https://github.com/bytedance/deer-flow/pull/4559 [#4564]: https://github.com/bytedance/deer-flow/pull/4564 [#4570]: https://github.com/bytedance/deer-flow/pull/4570 [#4574]: https://github.com/bytedance/deer-flow/issues/4574 [#4575]: https://github.com/bytedance/deer-flow/pull/4575 [#4577]: https://github.com/bytedance/deer-flow/pull/4577 [#4578]: https://github.com/bytedance/deer-flow/pull/4578 [#4582]: https://github.com/bytedance/deer-flow/pull/4582 [#4584]: https://github.com/bytedance/deer-flow/pull/4584 [#4587]: https://github.com/bytedance/deer-flow/pull/4587 [#4589]: https://github.com/bytedance/deer-flow/pull/4589 [#4590]: https://github.com/bytedance/deer-flow/pull/4590 [#4596]: https://github.com/bytedance/deer-flow/pull/4596 [#4599]: https://github.com/bytedance/deer-flow/pull/4599 [#4600]: https://github.com/bytedance/deer-flow/pull/4600 [#4604]: https://github.com/bytedance/deer-flow/pull/4604 [#4611]: https://github.com/bytedance/deer-flow/issues/4611 [#4615]: https://github.com/bytedance/deer-flow/pull/4615 [#4617]: https://github.com/bytedance/deer-flow/pull/4617 [#4618]: https://github.com/bytedance/deer-flow/pull/4618 [#4620]: https://github.com/bytedance/deer-flow/pull/4620 [#4623]: https://github.com/bytedance/deer-flow/pull/4623 [#4624]: https://github.com/bytedance/deer-flow/pull/4624 [#4625]: https://github.com/bytedance/deer-flow/pull/4625 [#4627]: https://github.com/bytedance/deer-flow/pull/4627 [#4629]: https://github.com/bytedance/deer-flow/pull/4629 [#4631]: https://github.com/bytedance/deer-flow/pull/4631 [#4633]: https://github.com/bytedance/deer-flow/pull/4633 [#4634]: https://github.com/bytedance/deer-flow/pull/4634 [#4635]: https://github.com/bytedance/deer-flow/pull/4635 [#4636]: https://github.com/bytedance/deer-flow/pull/4636 [#4638]: https://github.com/bytedance/deer-flow/pull/4638 [#4639]: https://github.com/bytedance/deer-flow/pull/4639 [#4643]: https://github.com/bytedance/deer-flow/pull/4643 [#4644]: https://github.com/bytedance/deer-flow/pull/4644 [#4647]: https://github.com/bytedance/deer-flow/pull/4647 [#4649]: https://github.com/bytedance/deer-flow/pull/4649 [#4657]: https://github.com/bytedance/deer-flow/pull/4657 [#4658]: https://github.com/bytedance/deer-flow/pull/4658 [#4659]: https://github.com/bytedance/deer-flow/pull/4659 [#4660]: https://github.com/bytedance/deer-flow/pull/4660 [#4665]: https://github.com/bytedance/deer-flow/pull/4665 [#4667]: https://github.com/bytedance/deer-flow/pull/4667 [#4668]: https://github.com/bytedance/deer-flow/pull/4668 [#4677]: https://github.com/bytedance/deer-flow/pull/4677 [#4681]: https://github.com/bytedance/deer-flow/pull/4681 [#4683]: https://github.com/bytedance/deer-flow/pull/4683 [#4684]: https://github.com/bytedance/deer-flow/pull/4684 [#4690]: https://github.com/bytedance/deer-flow/pull/4690 [#4693]: https://github.com/bytedance/deer-flow/pull/4693 [#4701]: https://github.com/bytedance/deer-flow/pull/4701 [#4703]: https://github.com/bytedance/deer-flow/pull/4703 [#4707]: https://github.com/bytedance/deer-flow/pull/4707 [#4709]: https://github.com/bytedance/deer-flow/pull/4709 [#4713]: https://github.com/bytedance/deer-flow/pull/4713 [#4719]: https://github.com/bytedance/deer-flow/pull/4719 [#4722]: https://github.com/bytedance/deer-flow/pull/4722 [#4724]: https://github.com/bytedance/deer-flow/pull/4724 [#4727]: https://github.com/bytedance/deer-flow/pull/4727 [#4730]: https://github.com/bytedance/deer-flow/pull/4730 [#4735]: https://github.com/bytedance/deer-flow/pull/4735 [#4736]: https://github.com/bytedance/deer-flow/pull/4736 [#4737]: https://github.com/bytedance/deer-flow/pull/4737 [#4738]: https://github.com/bytedance/deer-flow/pull/4738 [#4744]: https://github.com/bytedance/deer-flow/pull/4744 [#4745]: https://github.com/bytedance/deer-flow/pull/4745 [#4747]: https://github.com/bytedance/deer-flow/pull/4747 [#4748]: https://github.com/bytedance/deer-flow/pull/4748 [#4750]: https://github.com/bytedance/deer-flow/pull/4750 [#4752]: https://github.com/bytedance/deer-flow/pull/4752 [#4755]: https://github.com/bytedance/deer-flow/pull/4755 [#4758]: https://github.com/bytedance/deer-flow/pull/4758 [#4759]: https://github.com/bytedance/deer-flow/pull/4759 [#4760]: https://github.com/bytedance/deer-flow/pull/4760 [#4762]: https://github.com/bytedance/deer-flow/pull/4762 [#4764]: https://github.com/bytedance/deer-flow/pull/4764 [#4767]: https://github.com/bytedance/deer-flow/pull/4767 [#4769]: https://github.com/bytedance/deer-flow/pull/4769 [#4772]: https://github.com/bytedance/deer-flow/pull/4772 [#4780]: https://github.com/bytedance/deer-flow/pull/4780 [#4783]: https://github.com/bytedance/deer-flow/pull/4783 [#4785]: https://github.com/bytedance/deer-flow/pull/4785 [#4789]: https://github.com/bytedance/deer-flow/pull/4789 [#4792]: https://github.com/bytedance/deer-flow/pull/4792 [#4797]: https://github.com/bytedance/deer-flow/pull/4797 [#4800]: https://github.com/bytedance/deer-flow/pull/4800 [#4804]: https://github.com/bytedance/deer-flow/pull/4804 [#4806]: https://github.com/bytedance/deer-flow/pull/4806 [#4812]: https://github.com/bytedance/deer-flow/pull/4812 [#4815]: https://github.com/bytedance/deer-flow/pull/4815 [#4816]: https://github.com/bytedance/deer-flow/pull/4816 [#4817]: https://github.com/bytedance/deer-flow/pull/4817 [#4822]: https://github.com/bytedance/deer-flow/pull/4822 [#4823]: https://github.com/bytedance/deer-flow/pull/4823 [#4825]: https://github.com/bytedance/deer-flow/pull/4825 [#4827]: https://github.com/bytedance/deer-flow/pull/4827 [#4830]: https://github.com/bytedance/deer-flow/pull/4830 [#4833]: https://github.com/bytedance/deer-flow/pull/4833 [#4836]: https://github.com/bytedance/deer-flow/pull/4836 [#4838]: https://github.com/bytedance/deer-flow/pull/4838 [#4840]: https://github.com/bytedance/deer-flow/pull/4840 [#4842]: https://github.com/bytedance/deer-flow/pull/4842 [#4844]: https://github.com/bytedance/deer-flow/pull/4844 [#4846]: https://github.com/bytedance/deer-flow/pull/4846 [#4848]: https://github.com/bytedance/deer-flow/pull/4848 [#4852]: https://github.com/bytedance/deer-flow/pull/4852 [#4853]: https://github.com/bytedance/deer-flow/pull/4853 [#4860]: https://github.com/bytedance/deer-flow/pull/4860 [#4861]: https://github.com/bytedance/deer-flow/pull/4861 [#4863]: https://github.com/bytedance/deer-flow/pull/4863 [#4865]: https://github.com/bytedance/deer-flow/pull/4865 [#4868]: https://github.com/bytedance/deer-flow/pull/4868 [#4877]: https://github.com/bytedance/deer-flow/pull/4877 [#4882]: https://github.com/bytedance/deer-flow/pull/4882 [#4887]: https://github.com/bytedance/deer-flow/pull/4887 [#4888]: https://github.com/bytedance/deer-flow/pull/4888 [#4898]: https://github.com/bytedance/deer-flow/pull/4898 [#4903]: https://github.com/bytedance/deer-flow/pull/4903 [#4911]: https://github.com/bytedance/deer-flow/pull/4911 [#4918]: https://github.com/bytedance/deer-flow/pull/4918 [#4928]: https://github.com/bytedance/deer-flow/pull/4928 [#4933]: https://github.com/bytedance/deer-flow/pull/4933 [#4936]: https://github.com/bytedance/deer-flow/pull/4936 [#4938]: https://github.com/bytedance/deer-flow/pull/4938 [#4951]: https://github.com/bytedance/deer-flow/pull/4951 [#4953]: https://github.com/bytedance/deer-flow/pull/4953 [#4956]: https://github.com/bytedance/deer-flow/pull/4956 [#4959]: https://github.com/bytedance/deer-flow/pull/4959 [#4960]: https://github.com/bytedance/deer-flow/pull/4960 [#4963]: https://github.com/bytedance/deer-flow/pull/4963 [#4965]: https://github.com/bytedance/deer-flow/pull/4965 [#4970]: https://github.com/bytedance/deer-flow/pull/4970 [#4983]: https://github.com/bytedance/deer-flow/pull/4983 [#4987]: https://github.com/bytedance/deer-flow/pull/4987 [#4998]: https://github.com/bytedance/deer-flow/pull/4998 [#4696]: https://github.com/bytedance/deer-flow/pull/4696 [#4810]: https://github.com/bytedance/deer-flow/pull/4810 [#4820]: https://github.com/bytedance/deer-flow/pull/4820 [#4826]: https://github.com/bytedance/deer-flow/pull/4826 [#4834]: https://github.com/bytedance/deer-flow/pull/4834 [#4839]: https://github.com/bytedance/deer-flow/pull/4839 [#4867]: https://github.com/bytedance/deer-flow/pull/4867 [#4876]: https://github.com/bytedance/deer-flow/pull/4876 [#4878]: https://github.com/bytedance/deer-flow/pull/4878 [#4946]: https://github.com/bytedance/deer-flow/pull/4946 [#4955]: https://github.com/bytedance/deer-flow/pull/4955 [#4972]: https://github.com/bytedance/deer-flow/pull/4972 [#4977]: https://github.com/bytedance/deer-flow/pull/4977 [#4984]: https://github.com/bytedance/deer-flow/pull/4984 [#4986]: https://github.com/bytedance/deer-flow/pull/4986 [#5003]: https://github.com/bytedance/deer-flow/pull/5003 [#5006]: https://github.com/bytedance/deer-flow/pull/5006 [#5008]: https://github.com/bytedance/deer-flow/pull/5008 [#5010]: https://github.com/bytedance/deer-flow/pull/5010 [#5014]: https://github.com/bytedance/deer-flow/pull/5014 [#5017]: https://github.com/bytedance/deer-flow/pull/5017 [#5018]: https://github.com/bytedance/deer-flow/pull/5018 [#5021]: https://github.com/bytedance/deer-flow/pull/5021 [#5022]: https://github.com/bytedance/deer-flow/pull/5022 [#5023]: https://github.com/bytedance/deer-flow/pull/5023 [#5025]: https://github.com/bytedance/deer-flow/pull/5025 [#5027]: https://github.com/bytedance/deer-flow/pull/5027 [#5030]: https://github.com/bytedance/deer-flow/pull/5030 [#5031]: https://github.com/bytedance/deer-flow/pull/5031 [#5036]: https://github.com/bytedance/deer-flow/pull/5036 [#5039]: https://github.com/bytedance/deer-flow/pull/5039 [#5041]: https://github.com/bytedance/deer-flow/pull/5041 [#5045]: https://github.com/bytedance/deer-flow/pull/5045 [#5047]: https://github.com/bytedance/deer-flow/pull/5047 [#5049]: https://github.com/bytedance/deer-flow/pull/5049 [#5050]: https://github.com/bytedance/deer-flow/pull/5050 [#5051]: https://github.com/bytedance/deer-flow/pull/5051 [#5056]: https://github.com/bytedance/deer-flow/pull/5056 [#5057]: https://github.com/bytedance/deer-flow/pull/5057 [#5059]: https://github.com/bytedance/deer-flow/pull/5059 [#5064]: https://github.com/bytedance/deer-flow/pull/5064 [#5066]: https://github.com/bytedance/deer-flow/pull/5066 [#5069]: https://github.com/bytedance/deer-flow/pull/5069 [#5071]: https://github.com/bytedance/deer-flow/pull/5071 [#5074]: https://github.com/bytedance/deer-flow/pull/5074 [#5076]: https://github.com/bytedance/deer-flow/pull/5076 [#5077]: https://github.com/bytedance/deer-flow/pull/5077 [#5083]: https://github.com/bytedance/deer-flow/pull/5083 [#5086]: https://github.com/bytedance/deer-flow/pull/5086 [#5087]: https://github.com/bytedance/deer-flow/pull/5087 [#5089]: https://github.com/bytedance/deer-flow/pull/5089 [#5090]: https://github.com/bytedance/deer-flow/pull/5090 [#5092]: https://github.com/bytedance/deer-flow/pull/5092 [#5095]: https://github.com/bytedance/deer-flow/pull/5095 [#5099]: https://github.com/bytedance/deer-flow/pull/5099 [#5103]: https://github.com/bytedance/deer-flow/pull/5103 [#5105]: https://github.com/bytedance/deer-flow/pull/5105 [#5109]: https://github.com/bytedance/deer-flow/pull/5109 [#5112]: https://github.com/bytedance/deer-flow/pull/5112 [#5117]: https://github.com/bytedance/deer-flow/pull/5117 [#5119]: https://github.com/bytedance/deer-flow/pull/5119 [#5133]: https://github.com/bytedance/deer-flow/pull/5133 [#5136]: https://github.com/bytedance/deer-flow/pull/5136 [#5239]: https://github.com/bytedance/deer-flow/pull/5239 [#3183]: https://github.com/bytedance/deer-flow/pull/3183 [#4726]: https://github.com/bytedance/deer-flow/pull/4726 [#4729]: https://github.com/bytedance/deer-flow/pull/4729 [#4884]: https://github.com/bytedance/deer-flow/pull/4884 [#4901]: https://github.com/bytedance/deer-flow/pull/4901 [#4944]: https://github.com/bytedance/deer-flow/pull/4944 [#4952]: https://github.com/bytedance/deer-flow/pull/4952 [#4980]: https://github.com/bytedance/deer-flow/pull/4980 [#4995]: https://github.com/bytedance/deer-flow/pull/4995 [#5026]: https://github.com/bytedance/deer-flow/pull/5026 [#5028]: https://github.com/bytedance/deer-flow/pull/5028 [#5062]: https://github.com/bytedance/deer-flow/pull/5062 [#5110]: https://github.com/bytedance/deer-flow/pull/5110 [#5111]: https://github.com/bytedance/deer-flow/pull/5111 [#5123]: https://github.com/bytedance/deer-flow/pull/5123 [#5134]: https://github.com/bytedance/deer-flow/pull/5134 [#5137]: https://github.com/bytedance/deer-flow/pull/5137 [#5141]: https://github.com/bytedance/deer-flow/pull/5141 [#5145]: https://github.com/bytedance/deer-flow/pull/5145 [#5149]: https://github.com/bytedance/deer-flow/pull/5149 [#5152]: https://github.com/bytedance/deer-flow/pull/5152 [#5153]: https://github.com/bytedance/deer-flow/pull/5153 [#5154]: https://github.com/bytedance/deer-flow/pull/5154 [#5155]: https://github.com/bytedance/deer-flow/pull/5155 [#5156]: https://github.com/bytedance/deer-flow/pull/5156 [#5159]: https://github.com/bytedance/deer-flow/pull/5159 [#5163]: https://github.com/bytedance/deer-flow/pull/5163 [#5164]: https://github.com/bytedance/deer-flow/pull/5164 [#5166]: https://github.com/bytedance/deer-flow/pull/5166 [#5168]: https://github.com/bytedance/deer-flow/pull/5168 [#5170]: https://github.com/bytedance/deer-flow/pull/5170 [#5181]: https://github.com/bytedance/deer-flow/pull/5181 [#5183]: https://github.com/bytedance/deer-flow/pull/5183 [#5185]: https://github.com/bytedance/deer-flow/pull/5185 [#5187]: https://github.com/bytedance/deer-flow/pull/5187 [#5191]: https://github.com/bytedance/deer-flow/pull/5191 [#5197]: https://github.com/bytedance/deer-flow/pull/5197 [#5206]: https://github.com/bytedance/deer-flow/pull/5206 [#5209]: https://github.com/bytedance/deer-flow/pull/5209 [#5219]: https://github.com/bytedance/deer-flow/pull/5219 [#5228]: https://github.com/bytedance/deer-flow/pull/5228 [#5232]: https://github.com/bytedance/deer-flow/pull/5232 [#5234]: https://github.com/bytedance/deer-flow/pull/5234 [#5236]: https://github.com/bytedance/deer-flow/pull/5236 [#5244]: https://github.com/bytedance/deer-flow/pull/5244 [#5245]: https://github.com/bytedance/deer-flow/pull/5245 [#5261]: https://github.com/bytedance/deer-flow/pull/5261 [#5265]: https://github.com/bytedance/deer-flow/pull/5265 [#5278]: https://github.com/bytedance/deer-flow/pull/5278 [#5280]: https://github.com/bytedance/deer-flow/pull/5280 [#5281]: https://github.com/bytedance/deer-flow/pull/5281 [#5284]: https://github.com/bytedance/deer-flow/pull/5284 [#5287]: https://github.com/bytedance/deer-flow/pull/5287