- Check resp.StatusCode range (2xx) before JSON decoding
- Provide clear actionable errors with HTTP status codes for 5xx failures
- Prevent cryptic JSON parse errors from HTML error pages
- Introduced StripMessageDirectives in the agent loop to remove internal
[[name:value]] routing tags from user-facing content while preserving
them in session store for model context
- Narrowed regex from wildcard `(?s)\[\[.*?\]\]` to structured
`\[\[\w+(?::[^\]\n]+)?\]\]` to avoid false positives on legitimate content
- Preserved [[tts...]] tags for TTS AutoTagged pipeline compatibility
- Added 15 unit tests covering strip, preserve, and edge cases
- Fixed step numbering in agent loop (steps 5-9)
* fix(tools): resolve Windows build errors and harden filesystem security
* fix(tools): remove stale Windows skip in hardlink test
Now that checkHardlink uses GetFileInformationByHandle on Windows,
the test should run on all platforms.
---------
Co-authored-by: viettranx <viettranx@gmail.com>
* fix(agent): handle duplicate tool call IDs with occurrence-aware sanitization
* refactor(agent): simplify duplicate tool call ID handling
Replace complex occurrence-aware queue system with simpler approach:
- uniquifyToolCallIDs: append runID+iteration+index to all IDs at
response time, guaranteeing cross-turn uniqueness via UUID
- sanitizeHistory: simple seen-set dedup for legacy sessions with
pre-existing duplicate IDs, no queue/counter logic needed
- Restore full problem description in sanitizeHistory docstring
- Add unit tests for both dedup paths and edge cases
---------
Co-authored-by: viettranx <viettranx@gmail.com>
Improves supportsThoughtSignature with providerType and model normalization.
Strengthens collapseToolCallsWithoutSig with TrimSpace and camelCase support
to handle 'Thinking=OFF' whitespace signatures and proxy key translations.
Simplified approach to fix duplicate tool_call_ids that cause HTTP 400 on OpenAI-compatible APIs (OpenRouter, vLLM, DeepSeek).
- uniquifyToolCallIDs: appends runID+iteration+index to all IDs at response time, guaranteeing cross-turn uniqueness via UUID
- sanitizeHistory: simple seen-set dedup for legacy sessions with pre-existing duplicate IDs
- Anthropic guard: skips ID rewriting when RawAssistantContent is present
- Unit tests for both paths + edge cases
Closes#283
* fix(telegram): isolated transport, sticky fallback, and overall timeouts
* fix(telegram): improve networking isolation for high-concurrency
- Tune MaxIdleConnsPerHost to 64 (default 2 starves concurrent sends)
- Fix data race in enableIPv4Only using sync.Once
- Add force_ipv4 config option for explicit IPv4-only mode
- Narrow auto-detect heuristic to "unreachable" only (avoid false-positive on timeouts)
- Use bot username instead of token prefix in logs
- Extract applyIPv4Dialer helper for reuse between config and runtime paths
---------
Co-authored-by: viettranx <viettranx@gmail.com>
* fix(telegram): thread transport policy into media downloads with SSRF guard
* fix(telegram): trust configured APIServer during media downloads
* fix(telegram): use proper download timeout and clone DefaultTransport
- Clone http.DefaultTransport when proxy is configured to preserve
connection pool, TLS handshake timeout, and keep-alive defaults
- Use dedicated 5-minute context timeout for media downloads instead
of the shared 30s client timeout, preventing large file timeouts
(local Bot API supports up to 200 MB)
---------
Co-authored-by: viettranx <viettranx@gmail.com>
* feat(telegram): implement robust message splitting and dynamic HTML retry logic
* fix(telegram): fix sendHTML error chain regression and add split depth limit
- Re-check err.Error() in thread-not-found handler instead of stale errStr,
restoring the original chained fallback behavior
- Add maxSplitDepth (5) to prevent unbounded recursion when Telegram
repeatedly rejects split chunks
- Rename misleading test case to reflect actual monolithic fallback behavior
---------
Co-authored-by: viettranx <viettranx@gmail.com>