160 lines
10 KiB
Markdown
160 lines
10 KiB
Markdown
# Changelog
|
||
|
||
All notable changes to LazyBoy are documented here.
|
||
|
||
## [Unreleased]
|
||
|
||
Long computer-use runs no longer die when the prompt creeps a few dozen tokens
|
||
over the model's context window. Stale browser snapshots are stubbed, oversized
|
||
tool dumps are capped, and an `exceed_context_size` response compact-retries
|
||
the same turn instead of failing the job.
|
||
|
||
Each model provider keeps its own API key, model, and endpoint in the
|
||
database. Switching xAI → OpenCode Go no longer wipes the xAI key, and the
|
||
settings field shows dots instead of the secret.
|
||
|
||
Sign in with your own account. The shared install token is gone, and so are the
|
||
model keys in the environment.
|
||
|
||
- **Register and log in** with a username and password in the app. Passwords are
|
||
stored as PBKDF2-HMAC-SHA256 (120,000 rounds, per-password salt) and sessions
|
||
live in the database as token digests in an `HttpOnly`, `SameSite=Strict`
|
||
cookie. Repeated failures cool a username down for five minutes.
|
||
- **One workspace per account.** Agents, chats, runs, schedules, credential
|
||
vaults, and model keys belong to the account that created them; a second
|
||
account on the same install sees none of it. Work created before this release
|
||
is adopted by the first account that registers.
|
||
- **Model keys come from Settings → Models only.** `LAZYBOY_APP_TOKEN`,
|
||
`XAI_API_KEY`, `OPENCODE_GO_API_KEY`, and `OPENAI_API_KEY` are no longer read.
|
||
A workspace without a key does not quietly run on someone else's: the run
|
||
fails immediately and points at the setting to fix.
|
||
- **`LAZYBOY_ALLOWED_HOSTS`** lists the domain names an install may be addressed
|
||
by (DNS rebinding guard). IPs and `localhost` keep working with no config.
|
||
- Removed: the token login screen, `LAZYBOY_APP_TOKEN`, and the rule that a
|
||
non-loopback bind required a 32-character token. `SANDBOX_SUPERVISOR_TOKEN`
|
||
and `LAZYBOY_VAULT_KEY` are still required in `.env`.
|
||
- **Context window fitting.** Long computer-use runs stub stale browser
|
||
snapshots, cap tool dumps, and compact-retry on `exceed_context_size`
|
||
instead of failing the job 42 tokens over a 128k window. Tune with
|
||
`LAZYBOY_MODEL_CONTEXT_CHARS`.
|
||
- **Model keys stay put.** Each provider keeps its own key, model, and base
|
||
URL. Switching provider no longer clears the previous key; the form shows
|
||
dots and never echoes the token.
|
||
|
||
### 繁體中文
|
||
|
||
長時間操作電腦時,舊的網頁快照不再把模型上下文塞爆:較舊的觀察會收成摘要,工具輸出有上限,模型回 `exceed_context_size` 時會壓縮後重試同一輪,而不是整份任務失敗。
|
||
|
||
每個供應商的 API 金鑰、模型與端點會各自記住。從 xAI 換到 OpenCode Go 不會清掉另一家的金鑰;設定畫面只顯示圓點,真正的 token 留在資料庫。
|
||
|
||
改成自己的帳號登入:共享的安裝 token 拿掉了,環境變數裡的模型金鑰也拿掉了。
|
||
|
||
- **在 App 裡註冊與登入**:密碼以 PBKDF2-HMAC-SHA256(120,000 輪、每組密碼各自的
|
||
salt)存放,session 在資料庫只存雜湊,cookie 是 `HttpOnly` + `SameSite=Strict`。
|
||
同一帳號連續失敗會冷卻五分鐘。
|
||
- **一個帳號一個工作區**:Agent、對話、執行紀錄、排程、憑證庫與模型金鑰都只屬於
|
||
建立它的帳號,同一套安裝的第二個帳號看不到任何資料;舊資料由第一個註冊的帳號接手。
|
||
- **模型金鑰只吃「設定 → 模型」**:不再讀 `LAZYBOY_APP_TOKEN`、`XAI_API_KEY`、
|
||
`OPENCODE_GO_API_KEY`、`OPENAI_API_KEY`。沒設金鑰的工作區不會偷偷用別人的金鑰,
|
||
任務會立刻失敗並指出該去哪裡補。
|
||
- **`LAZYBOY_ALLOWED_HOSTS`**:要改用網域名稱連進來時列在這裡(DNS rebinding 防護);
|
||
用 IP 或 `localhost` 不用設定。
|
||
- 移除:token 登入畫面、`LAZYBOY_APP_TOKEN`,以及「綁非 loopback 需 32 字元 token」
|
||
的規則。`.env` 仍需要 `SANDBOX_SUPERVISOR_TOKEN` 與 `LAZYBOY_VAULT_KEY`。
|
||
- **模型上下文配額。** 長時間操作電腦時,較舊的網頁快照會收成摘要、工具輸出有上限,
|
||
模型回 `exceed_context_size` 時會壓縮後重試同一輪,而不是只超出幾十個 token 就
|
||
整份任務失敗。可用 `LAZYBOY_MODEL_CONTEXT_CHARS` 調整。
|
||
- **模型金鑰會記住。** 每個供應商的金鑰、模型與端點各自存在資料庫。從 xAI 換到
|
||
OpenCode Go 不會清掉 xAI 的金鑰;畫面上只顯示圓點,真正的 token 不會再出現。
|
||
|
||
## [v0.1.0-alpha] - 2026-09-09
|
||
|
||
First public alpha. Self-hosted AI agent workspace: each agent gets an isolated Linux desktop, you watch it live, and you can take over at any time.
|
||
|
||
This is a source release. There is no pre-built binary; `make up` builds the API, supervisor, and desktop images from this tree.
|
||
|
||
### Highlights
|
||
|
||
- **A real computer per agent** — Debian + XFCE + Chromium in Docker. Browser, terminal, files, and GUI, with a live noVNC view.
|
||
- **Cua desktop driver** — clicks, typing, windows, clipboard, and the visible terminal go through Cua (`cua-driver-rs` v0.23.2). The old AT-SPI / CDP path is gone.
|
||
- **Chat that carries work** — text, images, and file attachments; the agent opens them on its own desktop. Inbox copies expire on their own.
|
||
- **Take over, then hand back** — sign in, pass a check, or nudge the same desktop by hand. Saved logins live in an encrypted vault and never pass through the model.
|
||
- **Several agents and groups** — shared Team computers or private desktops. `@name` wakes one agent; otherwise a short router picks who should answer.
|
||
- **Teach by demo, then schedule** — turn a walkthrough into a skill; cron runs it again.
|
||
- **Your models and tools** — xAI, OpenCode Go, OpenAI-compatible endpoints, MCP, and file skills.
|
||
- **Voice calls** — talk to the agent after you enable a voice provider.
|
||
- **Desktop and phone UI** — English and Traditional Chinese. On a phone: collapsible chat, keyboard, trackpad, right-click, drag, and scroll.
|
||
- **Runs that finish the job** — no hard turn quota on real work. The agent has to verify against the current screen before it stops; looping is paused for you instead of being cut off. Hover the thinking avatar for the live trace; a failed run can be retried.
|
||
- **Memory and hygiene** — optional long-term memory (pgvector), room-scoped recall, and retention jobs for traces, recordings, and checkpoints.
|
||
|
||
### Install
|
||
|
||
You need Docker and Compose, Git, Make, Python 3, and an API key for a supported model.
|
||
|
||
```bash
|
||
git clone https://github.com/igs170911/LazyBoy.git
|
||
cd LazyBoy
|
||
git checkout v0.1.0-alpha
|
||
make env
|
||
```
|
||
|
||
Edit `.env` and set one of `XAI_API_KEY`, `OPENCODE_GO_API_KEY`, or `OPENAI_API_KEY`. Then:
|
||
|
||
```bash
|
||
make up
|
||
make health
|
||
```
|
||
|
||
Open [http://127.0.0.1:3101](http://127.0.0.1:3101) and sign in with `LAZYBOY_APP_TOKEN`. The first run builds images from source and takes a while.
|
||
|
||
### Alpha caveats
|
||
|
||
- Early software. Expect rough edges in the desktop driver, group routing, and long-running tasks.
|
||
- The API binds `127.0.0.1` by default. For a phone on your network set `LAZYBOY_BIND_IP=0.0.0.0` (token must be at least 32 characters). Put it behind HTTPS before you expose it.
|
||
- Do not publish supervisor port `7091` or mount the host Docker socket into an agent computer.
|
||
- You bring the model API key. Screenshots and page contents can still reach the model; keep passwords in the vault, not in the prompt.
|
||
|
||
See [Operations](./docs/operations.md) for resource limits, environment variables, and the security model.
|
||
|
||
### 繁體中文
|
||
|
||
第一個公開 alpha。自架 AI Agent 工作空間:每個 Agent 有自己的隔離 Linux 桌面,你可以即時觀看,也可以隨時接手。
|
||
|
||
這是原始碼發行版,沒有預先編好的執行檔;`make up` 會從此樹狀目錄建出 API、supervisor 與桌面映像。
|
||
|
||
**重點**
|
||
|
||
- **每個 Agent 一台電腦** — Docker 裡的 Debian + XFCE + Chromium。瀏覽器、終端、檔案與圖形介面,畫面用 noVNC 即時看。
|
||
- **Cua 桌面驅動** — 點擊、打字、視窗、剪貼簿與可見終端都走 Cua(`cua-driver-rs` v0.23.2)。舊的 AT-SPI / CDP 路徑已移除。
|
||
- **對話裡就能交工作** — 文字、圖片、檔案附件;Agent 在自己的桌面開啟。收件匣複本會到期清除。
|
||
- **隨時接管再交回** — 同一桌面登入、過驗證或手動調整。帳密放加密保險庫,不會經過模型。
|
||
- **多 Agent 與群組** — Team 共用電腦或 Private 獨立桌面。`@名字` 只叫醒一個人;沒點名時由短路由決定誰回。
|
||
- **示範教學與排程** — 把操作示範收成技能,再用 cron 重複執行。
|
||
- **自選模型與工具** — xAI、OpenCode Go、OpenAI 相容端點、MCP、檔案技能。
|
||
- **語音通話** — 設定語音服務後可以直接通話。
|
||
- **桌面與手機介面** — 英文與繁體中文。手機可收合聊天側欄,遠端桌面有鍵盤、觸控板、右鍵、拖曳與捲動。
|
||
- **任務以做完為準** — 正式工作不再用固定輪數腰斬。Agent 要對著當下畫面自我驗證才准停;鬼打牆會暫停等你,而不是直接切斷。滑過思考頭像可看即時紀錄,失敗的 run 可以重試。
|
||
- **記憶與清理** — 可選的長期記憶(pgvector)、依房間範圍回想,以及紀錄、錄影、checkpoint 的保留週期。
|
||
|
||
**安裝**
|
||
|
||
需要 Docker 與 Compose、Git、Make、Python 3,以及一組支援的模型 API 金鑰。
|
||
|
||
```bash
|
||
git clone https://github.com/igs170911/LazyBoy.git
|
||
cd LazyBoy
|
||
git checkout v0.1.0-alpha
|
||
make env
|
||
```
|
||
|
||
編輯 `.env`,設定 `XAI_API_KEY`、`OPENCODE_GO_API_KEY` 或 `OPENAI_API_KEY` 其中之一,然後 `make up` 與 `make health`。打開 [http://127.0.0.1:3101](http://127.0.0.1:3101),用 `LAZYBOY_APP_TOKEN` 登入。第一次會從原始碼建映像,需要一段時間。
|
||
|
||
**Alpha 注意事項**
|
||
|
||
- 早期軟體。桌面驅動、群組路由、長任務都還可能不穩。
|
||
- API 預設只綁 `127.0.0.1`。要給區網手機用請設 `LAZYBOY_BIND_IP=0.0.0.0`(token 至少 32 字)。對外之前請放在 HTTPS 後面。
|
||
- 不要把 supervisor `:7091` 對外,也不要把主機 Docker socket 掛進 Agent 電腦。
|
||
- 模型金鑰自己準備。截圖與頁面內容仍可能進模型;密碼放保險庫,不要寫在提示詞裡。
|
||
|
||
資源上限、環境變數與安全模型見 [部署指南](./docs/operations.md)。
|