Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
124 commits
Select commit Hold shift + click to select a range
7e81746
MUL-7019 fix(wecom): show the agent the message a sender quoted (#7980)
ii-jj Sep 17, 2026
4d4cae7
MUL-7312 LARI-10: Desktop PATH fix + CodeBuddy Claude-parity stream-j…
SeaSand1024 Sep 17, 2026
985986e
MUL-7458 Fix incorrectly folded Copilot CLI replies (#8507)
multica-eve Sep 17, 2026
2e728fc
MUL-7358 fix(agent): require OpenCode >= 1.1.54 so pre-fix builds can…
Bohan-J Sep 17, 2026
29987fd
MUL-7461 test(execenv): clear MULTICA_TASK_CONFIG_ROOT so the suite i…
Bohan-J Sep 17, 2026
b425073
MUL-7409 fix(runtime): stop steering stale-instance cleanup at the sh…
Bohan-J Sep 17, 2026
f9f5e3b
MUL-6734 fix(daemon): resolve Windows set-path overrides via LookPath…
leilei3167 Sep 17, 2026
edcd38f
MUL-7450 fix(settings): report revoked IM channels as disconnected (#…
Bohan-J Sep 17, 2026
9e7e529
fix(editor): release keys from empty mention picker (#8517)
multica-eve Sep 17, 2026
39ad969
MUL-7456 fix(editor): open the mention picker at any token boundary, …
HenrySu-sudo Sep 18, 2026
7112606
test(cli): drain captured stdout while the command runs (#8531)
adaiguoguo Sep 18, 2026
afedc6f
fix(cursor): preserve resumed sessions on connect timeouts (#8527)
mameikagou Sep 18, 2026
ff2933d
MUL-7471 fix(daemon): durably replay terminal reports (#8533)
multica-eve Sep 18, 2026
8006317
MUL-7449: fix: distinguish cancelled child work from done in stage pr…
poijygfdyy Sep 18, 2026
ee2793f
MUL-7372 fix(dingtalk): preserve quoted answer context and first-chun…
yyclaw Sep 18, 2026
7f8e498
MUL-7467 fix(agent): fail silent Pi provider errors (#8535)
multica-eve Sep 18, 2026
78922f7
MUL-7447: fix(comments): explain @all member-only behavior (#8489)
GaoSSR Sep 18, 2026
5336391
MUL-7299: feat(issues): filter issues by the parent project's status …
tempo22 Sep 18, 2026
a6d2a5c
fix(chat): match default list width to inbox (#8537)
forrestchang Sep 18, 2026
78a5f69
MUL-6813: fix: surface private runtime owner mismatch as explicit fai…
makesomethingshit Sep 18, 2026
043821a
MUL-7465 fix(chat): stream Codex deltas end to end (#8536)
multica-eve Sep 18, 2026
bf7e6e5
MUL-5241 fix(agent): bound the hermes shutdown so an escaped pipe hol…
Bohan-J Sep 18, 2026
83c04ce
test(codex): pin first-delta visibility contract (MUL-7465) (#8539)
multica-eve Sep 18, 2026
a647204
MUL-7300 fix(issues): preserve Quick Create original input (#8519)
multica-eve Sep 18, 2026
594ff89
fix(autopilots): make an existing schedule editable again (MUL-7478) …
Bohan-J Sep 18, 2026
d7009df
Revert "MUL-7300 fix(issues): preserve Quick Create original input (#…
Bohan-J Sep 18, 2026
c3920bc
MUL-7481: chore(cli): fold comment update guidance into --help and dr…
Bohan-J Sep 18, 2026
2df765a
docs(changelog): add v0.5.0 release entry (2026-09-18) (MUL-7481) (#8…
multica-eve Sep 18, 2026
d62048f
test(handler): use database clock for timestamp fallback bounds (#8570)
yyclaw Sep 19, 2026
67cec3f
fix(transcript): pair parallel tool results by call identity (#8567)
importcpp Sep 19, 2026
8c4f432
MUL-7485: fix(issues): make the cancelled-work warning specific and m…
adaiguoguo Sep 19, 2026
51e4aef
fix(wecom): send a long answer in pieces instead of losing it (#8344)
seacen Sep 20, 2026
2aa20b0
ZIC-245: fix custom Oh-My-Pi runtime profile identity and discovery (…
vicksiyi Sep 20, 2026
ea04668
fix(runtimes): drop the redundant runtime_type backfill from migratio…
Bohan-J Sep 20, 2026
130bd59
docs(cli): drop the profile migration advice from the OMP section (#8…
Bohan-J Sep 20, 2026
55bc4df
MUL-7518: fix(editor): keep an image's known kind when opening its pr…
Bohan-J Sep 20, 2026
3fbffd5
MUL-7521: fix(i18n): correct inbox agent activity notification hints …
yyclaw Sep 20, 2026
8feab0a
perf(web): reduce route barrel imports for #8387 (#8575)
vicksiyi Sep 20, 2026
a51fd83
MUL-7517: clarify squad leader identity framing (#8597)
multica-eve Sep 20, 2026
6b69b37
Revert "MUL-7517: clarify squad leader identity framing (#8597)" (#8600)
multica-eve Sep 20, 2026
9018df3
feat(projects): set a repository's checkout ref from the UI (MUL-7504…
Bohan-J Sep 20, 2026
80aa31c
MUL-7520 fix(agent): support OpenCode 2.x runtimes (#8596)
Bohan-J Sep 20, 2026
1df4e0a
MUL-7477 fix(telegram): one reply per turn across replicas, restarts …
Bohan-J Sep 20, 2026
6f52e83
fix(projects): drop the rename pencil from local directory resources …
Bohan-J Sep 20, 2026
8ce795b
MUL-7480: Steer active agent turns from comments (#8605)
multica-eve Sep 20, 2026
c375f83
MUL-7418: add issue event and time wakeups (#8467)
forrestchang Sep 20, 2026
36eed42
MUL-7533: fix(selfhost): pass MULTICA_TELEGRAM_SECRET_KEY through to …
luyuehm Sep 21, 2026
5357895
fix(selfhost): pass MULTICA_DINGTALK_SECRET_KEY through and guard int…
Bohan-J Sep 21, 2026
b866dac
fix: preserve active task intent in steer frames (#8621)
multica-eve Sep 21, 2026
f8c90a3
MUL-7546 fix(issues): preserve identifier lookups across remounts (#8…
ldnvnbl Sep 21, 2026
b02beb4
MUL-7528 feat(issues): copy link to a single comment (#8607)
gogodjzhu Sep 21, 2026
41db428
MUL-7324 feat(wecom): answer in the message the question opened (#8355)
seacen Sep 21, 2026
2561b49
MUL-7324 refactor(wecom): trim the stream bubble test suite and its t…
Bohan-J Sep 21, 2026
6dbcc25
MUL-7547 fix(ci): prune the Go build cache to the run's entries and d…
Bohan-J Sep 21, 2026
3de6275
MUL-7480: Link delivered steers to final replies (#8623)
multica-eve Sep 21, 2026
da5843f
fix(runtimes): stack usage KPI cards on mobile widths (#7857)
kakiuwang-ui Sep 21, 2026
2bd4f17
MUL-7058 feat(cli): support self-hosted Gitea release sources (#8027)
2233admin Sep 21, 2026
2eef976
fix(issues): keep a run's comments in the order they were posted (MUL…
Bohan-J Sep 21, 2026
1519006
test(perf): answer the issue wakeups request in the typing scenario (…
Bohan-J Sep 21, 2026
40a48c3
docs(skills): add --compact to squads reference comment reads (MUL-58…
Bohan-J Sep 21, 2026
2b62b2b
fix(cli): compare workdir paths in one namespace (MUL-4252, MUL-7193)…
GODVvVZzz Sep 21, 2026
70f900c
fix: deflake wakeup and squad briefing tests, bound wakeup receipt ex…
Bohan-J Sep 21, 2026
624648c
fix(daemon): offer a Git Bash variant of the Windows reply cookbook (…
Bohan-J Sep 21, 2026
d993257
Revert "fix: preserve active task intent in steer frames (#8621)" (#8…
ldnvnbl Sep 21, 2026
16cc03c
Revert "fix: preserve active task intent in steer frames (#8621)" (#8…
ldnvnbl Sep 21, 2026
7d7e3e5
Revert "Revert "fix: preserve active task intent in steer frames (#86…
ldnvnbl Sep 21, 2026
bd70632
fix(wakeup): end closed-issue wakeups in the application, not a trigg…
Bohan-J Sep 21, 2026
8c9f865
MUL-7480: Revert comment steering feature (#8648)
multica-eve Sep 21, 2026
d4267bf
docs(changelog): add v0.5.1 release entry (2026-09-21) (MUL-7557) (#8…
multica-eve Sep 21, 2026
f41fae6
fix(cursor): own Windows background shells by launch Job membership (…
Bohan-J Sep 21, 2026
da139a7
fix(wecom): name the two exits that leave a reply unaccounted for (MU…
seacen Sep 22, 2026
5140b99
MUL-7577: remove no-start guidance from runtime and platform skill (#…
multica-eve Sep 22, 2026
8bafd36
fix(ui): reduce text shimmer repainting (MUL-7466) (#8653)
multica-eve Sep 22, 2026
430a6a2
fix(ui): run the border beam on the compositor (MUL-7466) (#8681)
Bohan-J Sep 22, 2026
af62622
MUL-7288: fix(server): wake guest squad leaders on worker replies (#8…
bojackli Sep 22, 2026
f95c3b6
fix(desktop): preserve startup toolbar clearance (#8686)
multica-eve Sep 22, 2026
8f1ad46
MUL-7556: index GitHub PR address lookups (#8636)
multica-eve Sep 22, 2026
7a3f29b
fix(installer): preserve Windows PowerShell 5.1 disk parsing (#8663)
vicksiyi Sep 22, 2026
d2423aa
MUL-7590: fix(execenv): support OpenClaw agents.entries per-agent wor…
basuotian Sep 22, 2026
2b60f3b
MUL-7594: fix(server): record creation activity for autopilot issues …
importcpp Sep 22, 2026
024e365
fix(mobile): avoid duplicate WebSocket recovery and reject invalid fr…
importcpp Sep 22, 2026
90e0bdf
MUL-7586 Atomically create issues with custom properties (#8689)
multica-eve Sep 22, 2026
5277031
MUL-7614: fix(views): stop the run-confirm dialog scrolling sideways …
foXaCe Sep 23, 2026
d31fcbc
MUL-7585 feat(telegram): inline recent group context on @mentions (#8…
pseudoyu Sep 23, 2026
1879bc3
MUL-7351: fix(daemon): fence and retry task start acknowledgements (L…
hutiefang76 Sep 23, 2026
6278fdb
feat(web): offer the Windows CLI installer alongside curl (MUL-7602)
basuotian Sep 23, 2026
5403083
MUL-7607 fix(auth): restore invitation-based signup (#8706)
franciscocpg Sep 23, 2026
81f0fb4
test(execenv): stop the test repo template racing git auto maintenanc…
Bohan-J Sep 23, 2026
42727f6
MUL-7611: fix(comments): read only thread routing owners (#8712)
yyclaw Sep 23, 2026
b7cdd76
MUL-7349: feat(server): add the duplicate-mark column and keep it cor…
Bohan-J Sep 23, 2026
be085b1
fix(chat): avoid loading transcripts during cancellation (#8708)
yyclaw Sep 23, 2026
96db419
feat: mark an issue as a duplicate from the status picker (MUL-7349) …
Bohan-J Sep 23, 2026
6ee01c3
fix(cli): reference issue create attachments in the description (#8736)
Bohan-J Sep 23, 2026
9b8da37
MUL-7450 fix(lark): surface the event-delivery check a silent Bot nee…
Bohan-J Sep 23, 2026
a211188
fix(issues): polish the mark-as-duplicate affordance (MUL-7349) (#8738)
Bohan-J Sep 23, 2026
93ae552
feat: add messages to active Claude Code and Codex runs (MUL-7565) (#…
multica-eve Sep 23, 2026
75b5b94
fix(issues): show wakeup fire times in the viewer's timezone (MUL-762…
Bohan-J Sep 23, 2026
8355c7a
fix(cli): name the TLS handshake timeout and stop masking it on login…
Bohan-J Sep 23, 2026
1539c54
feat(issues): make duplicate marks traceable and one click from the o…
Bohan-J Sep 23, 2026
7be1753
MUL-7613: fix(agent): refresh live model catalogs (#8722)
HuangYincan Sep 23, 2026
56bc002
fix(issues): hide unsupported steer action (MUL-7629) (#8745)
multica-eve Sep 23, 2026
d028d7b
refactor(issues): remove dead steer copy (MUL-7629) (#8747)
multica-eve Sep 23, 2026
3ec96f6
fix(issues): preserve active run order before later comments (MUL-763…
forrestchang Sep 23, 2026
92d29fe
docs(changelog): add v0.5.2 release entry (2026-09-23) (MUL-7630) (#8…
multica-eve Sep 23, 2026
4469bac
fix(issues): duplicate mark follow-ups from #8741 review (MUL-7349) (…
Bohan-J Sep 23, 2026
d45aba1
fix(tasks): settle supplements in application transactions (MUL-7630)…
multica-eve Sep 23, 2026
920c3ea
feat(docs): add French documentation aligned with UI terminology (MUL…
Bohan-J Sep 23, 2026
18d9c41
fix(issues): order thread replies by send time, not by trigger (MUL-7…
Bohan-J Sep 23, 2026
0516dd5
MUL-7625: feat(antigravity): stream live tool execution events (#8734)
mameikagou Sep 23, 2026
9df0cae
MUL-7429: complete issues when every linked PR merges (#8758)
forrestchang Sep 23, 2026
1d94166
MUL-7642: full-window attachment viewer that pages through every file…
forrestchang Sep 23, 2026
62efe26
MUL-7620 feat(telegram): send and receive photos, videos and files (#…
pseudoyu Sep 24, 2026
4f315a2
fix(dingtalk): avoid unnecessary issue link escapes (#8768)
yyclaw Sep 24, 2026
4f5fbc9
fix(vcs): explain untrusted TLS certificates and trust private CAs vi…
Bohan-J Sep 24, 2026
d5a25d7
MUL-7608 feat(mobile): add Simplified Chinese localization (#8702)
bingfree88 Sep 24, 2026
1a09c65
feat(llm): support MULTICA_LLM_DISABLE_THINKING env (MUL-7162) (#8657)
gogodjzhu Sep 24, 2026
554937f
docs(telegram): update French pages for photo, video and file support…
pseudoyu Sep 24, 2026
54520de
MUL-7646: fix(claude): report per-run usage for resumed sessions (#8792)
multica-eve Sep 24, 2026
9c69661
feat(web): licensing FAQ, privacy policy, About team section, source-…
Bohan-J Sep 24, 2026
0da0b46
MUL-7672: only a closing keyword completes an issue on PR merge (#8794)
Bohan-J Sep 24, 2026
df2e86c
fix(daemon): retry Windows task root record rename (#8786)
bojackli Sep 24, 2026
e909e9c
MUL-7587 fix(daemon): show on-behalf-of identity in agent context (#8…
RoastDuck0927 Sep 24, 2026
86ac488
chore: merge latest upstream Multica while preserving fork handoffs
harley Sep 24, 2026
1a7a7c1
ci: build immutable CoderPush production images
harley Sep 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
35 changes: 32 additions & 3 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -167,6 +167,20 @@ MULTICA_LLM_DEFAULT_MODEL=
# other 4xx. This budget does not cover a stream that breaks mid-response,
# and it is unrelated to task-level retries.
MULTICA_LLM_MAX_RETRIES=
# - Ask an OpenAI-compatible gateway to turn the model's reasoning
# ("thinking") off by adding chat_template_kwargs: {"enable_thinking":
# false} to every request body this layer sends. Some gateways and
# GLM/Qwen-style model routes honor the field; there it removes the
# thinking pass that would otherwise dominate the latency budget of the
# assist calls above. Standard OpenAI endpoints reject unknown body
# fields, so only enable this when the upstream accepts it. GPT-5.6-family
# models already get reasoning_effort=none on the follow-up questions
# request. Chat auto-titling sends no reasoning field; this switch affects
# it only when the configured upstream accepts chat_template_kwargs.
# Accepted values are true/false and 1/0
# (case-insensitive); anything else fails the boot. The startup log
# ("llm retry policy") reports the effective state.
MULTICA_LLM_DISABLE_THINKING=
MULTICA_DAEMON_CONFIG=
MULTICA_WORKSPACE_ID=
MULTICA_DAEMON_ID=
Expand Down Expand Up @@ -623,6 +637,19 @@ MULTICA_LARK_WS_PROXY_URL=
# Generate one with: openssl rand -base64 32
MULTICA_DINGTALK_SECRET_KEY=

# Slack bot integration (Settings → Integrations → Slack)
# Off until MULTICA_SLACK_SECRET_KEY is set — a base64-encoded 32-byte key
# that encrypts each installation's bot and app tokens at rest. Leave empty
# to disable. Generate one with: openssl rand -base64 32
MULTICA_SLACK_SECRET_KEY=

# Telegram bot integration (Settings → Integrations → Telegram)
# Off until MULTICA_TELEGRAM_SECRET_KEY is set — a base64-encoded 32-byte key
# that encrypts each Bot's token at rest. Leave empty to disable. Keep it
# stable: losing or rotating it makes stored Bot tokens unreadable.
# Generate one with: openssl rand -base64 32
MULTICA_TELEGRAM_SECRET_KEY=

# Frontend
# Leave empty — auto-derived from page origin in browser, set by Makefile for local dev.
# NEXT_PUBLIC_API_URL also feeds the Next.js SSR proxy when explicitly set.
Expand All @@ -640,16 +667,18 @@ NEXT_PUBLIC_WS_URL=
# REMOTE_API_URL=https://multica-api.copilothub.ai

# ==================== Self-hosting: Control Signups (fixes #930) ====================
# Set to "false" to completely disable new user signups (recommended for private instances)
# Set to "false" to restrict new accounts to allowlisted or invited users.
# A pending, unexpired workspace invitation also permits emails outside either
# allowlist when ALLOW_SIGNUP=true. Revocation does not remove existing accounts.
ALLOW_SIGNUP=true
# The web UI reads ALLOW_SIGNUP from /api/config at runtime, so toggling this
# only requires restarting the backend / compose stack — not rebuilding web.
# It is not hot-reloaded.

# Optional: Only allow emails from these domains (comma-separated)
# Optional: Allow emails from these domains without an invitation (comma-separated)
ALLOWED_EMAIL_DOMAINS=

# Optional: Only allow these exact email addresses (comma-separated)
# Optional: Allow these exact email addresses without an invitation (comma-separated)
ALLOWED_EMAILS=

# Set to "true" to disable workspace creation for every caller on this
Expand Down
1 change: 1 addition & 0 deletions .github/ci-paths.json
Original file line number Diff line number Diff line change
Expand Up @@ -102,6 +102,7 @@
"Makefile",
"server/internal/handler/reserved_slugs.json",
"packages/core/paths/reserved-slugs.ts",
"server/cmd/server/router.go",
".github/workflows/ci.yml",
".github/ci-paths.json",
"scripts/ci-scope.mjs",
Expand Down
75 changes: 73 additions & 2 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -282,6 +282,14 @@ jobs:
# release, an entry built on the old one must not be restored. setup-go
# keys on ImageOS for the same reason (actions/setup-go#368).
#
# A rolling entry only grows on its own: each save is the restored entry
# plus this commit's objects, and Go trims only what has sat unused for
# five days, so the entry carried every recent main commit's race objects.
# It reached 3.5 GB in ten days, and restoring and saving it cost more than
# the compile it saved (MUL-7547). Before saving, the job therefore drops
# every entry this run did not use, leaving the next run the objects of the
# tree it is most likely to build.
#
# This job is the only writer of either entry. backend-agent-tests restores
# both, but it downloads just pkg/agent's slice of the module graph and
# finishes first, so letting it save would repeat the first-writer-wins
Expand Down Expand Up @@ -365,6 +373,14 @@ jobs:
key: ${{ steps.gocache.outputs.prefix }}${{ github.sha }}
restore-keys: ${{ steps.gocache.outputs.prefix }}

# Go refreshes a cache entry's mtime when it uses it, but only once that
# mtime is an hour old. So after the run, an entry no newer than an hour
# before the first compile is one this run did not use. The prune step
# before the save compares against this marker.
- name: Mark Go build cache epoch
id: goepoch
run: touch -d '-1 hour' "$RUNNER_TEMP/go-build-epoch"

- name: Build
run: cd server && go build -race ./...

Expand All @@ -387,6 +403,17 @@ jobs:
# pkg/agent runs on its own runner: backend-agent-tests below.
run: bash scripts/test-go.sh --race --only regular

# Go's own trim (cmd/go/internal/cache) with this run as the window
# instead of five days: only `-a`/`-d` entries, and an executable entry
# is a directory, so it goes whole. See the job comment.
- name: Prune Go build cache to this run's entries
if: ${{ !cancelled() && github.event_name == 'push' && steps.goepoch.outcome == 'success' }}
run: |
du -sh ~/.cache/go-build
find ~/.cache/go-build -mindepth 2 -maxdepth 2 \( -name '*-a' -o -name '*-d' \) \
! -newer "$RUNNER_TEMP/go-build-epoch" -exec rm -rf {} +
du -sh ~/.cache/go-build

# Publishes from main only; see the job comment. `!cancelled()` so a red
# main still refreshes the objects for the next run, and the key step's
# outcome so a run that never reached Go does not save an empty entry
Expand Down Expand Up @@ -609,6 +636,45 @@ jobs:
# silently as "ok".
run: go test ./internal/daemon/execenv -v -run '^TestWindowsOpenclawShim' -count=1 -timeout=5m

- name: Test Windows workdir containment guard in the CLI
if: ${{ needs.changes.outputs.backend == 'true' }}
working-directory: server
# The CLI's --content-file / --attachment guard decides whether a path is
# inside the task workdir by canonicalizing both sides. Two of the things
# that decision rests on are Windows-only and covered nowhere else: a
# candidate on another volume, where filepath.Rel returns an error rather
# than a "..", so the guard has to read that as "outside" instead of
# surfacing `Rel: can't make Z:\... relative to C:\...` as a resolve
# failure; and a directory junction — the containment-relevant link shape
# that needs no elevation, so the one real hosts have — which resolves to
# itself rather than to its target under this module's go directive. The
# junction test pins that gap deliberately, records the observations it
# rests on, and fails with instructions if the platform ever starts
# resolving them.
# cmd/multica has no Windows job otherwise, so these windows-tagged
# tests run nowhere else. It matters twice over on a non-admin host,
# where the package's cross-platform cases skip for want of the symlink
# privilege; the ubuntu backend job covers those shapes instead.
# -v so a silent skip (or a -run pattern that stops matching) is visible
# in the log instead of passing as "ok".
run: go test ./cmd/multica -v -run '^TestFileWithinWorkingDirWindows' -count=1 -timeout=5m

- name: Test Windows link-target classification in internal/util
if: ${{ needs.changes.outputs.backend == 'true' }}
working-directory: server
# The guard's Windows correctness rests on internal/util's link-target
# grammar (classifyTarget), whose branch ordering is load-bearing:
# VolumeName is non-empty for drive-absolute paths too, so asking it
# before IsAbs misreads a junction's absolute target as drive-relative
# and resolves it against the working directory — exactly how a
# junction escape read as inside the workdir for one CI run. The
# fixture-free table pins every branch without needing a filesystem,
# but windows-tagged util tests run nowhere else. Scoped to the table
# by name; the package's symlinked-workdir cases belong to the ubuntu
# backend job, which runs the whole package.
# -v so a silent skip or a pattern that stops matching is visible.
run: go test ./internal/util -v -run '^TestClassifyTarget' -count=1 -timeout=5m

- name: Test Windows isolated repo checkout is committable
working-directory: server
# #6449: on Windows the daemon now hands Codex tasks a checkout whose
Expand Down Expand Up @@ -670,7 +736,7 @@ jobs:
# explicitly configured path reach the release executable. The same job
# covers the npm shape, where the entry point is a `.cmd` shim that only
# the command interpreter can run.
run: go test ./internal/daemon -v -run '^(TestCanonicalExecutablePath|TestTrimExtendedLengthPrefix|TestResolveAgentExecutablePathKeeps|TestResolveAgentEntry(FollowsRetargetedInstallerJunction|CanonicalizesRediscoveredJunction|ForLaunchKeepsCmdShimLaunchable|ForLaunchRejectsUnverifiedInitialJunctionTarget|ForLaunchRejectsRediscoveredJunctionWhenFinalPathResolutionFails|DoesNotSharePreRetargetSingleflightResult|ForLaunchFailsWhenJunctionKeepsRetargeting)|TestHandleTaskReportsWindowsCodexProcessStartFailure)' -count=1 -timeout=5m
run: go test ./internal/daemon -v -run '^(TestCanonicalExecutablePath|TestTrimExtendedLengthPrefix|TestResolveAgentExecutablePathKeeps|TestResolveAgentExecutablePath_ProfileOverride|TestResolveAgentEntry(FollowsRetargetedInstallerJunction|CanonicalizesRediscoveredJunction|ForLaunchKeepsCmdShimLaunchable|ForLaunchRejectsUnverifiedInitialJunctionTarget|ForLaunchRejectsRediscoveredJunctionWhenFinalPathResolutionFails|DoesNotSharePreRetargetSingleflightResult|ForLaunchFailsWhenJunctionKeepsRetargeting)|TestHandleTaskReportsWindowsCodexProcessStartFailure)' -count=1 -timeout=5m

- name: Build Windows CLI helper entrypoint
working-directory: server
Expand Down Expand Up @@ -777,7 +843,12 @@ jobs:
if: runner.os != 'Windows'
run: bash scripts/install.test.sh

- name: Test PowerShell installer
- name: Test installer with Windows PowerShell 5.1
if: runner.os == 'Windows'
shell: powershell
run: ./scripts/install.ps1.test.ps1

- name: Test installer with PowerShell 7
if: runner.os == 'Windows'
shell: pwsh
run: ./scripts/install.ps1.test.ps1
Expand Down
52 changes: 52 additions & 0 deletions .github/workflows/coderpush-images.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
name: CoderPush main images

# Build immutable artifacts from main. Publishing images does not deploy them.
on:
workflow_dispatch:

permissions:
contents: read

concurrency:
group: coderpush-images-${{ github.sha }}
cancel-in-progress: false

jobs:
build:
if: github.repository == 'CoderPush/multica' && github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
strategy:
fail-fast: false
matrix:
include:
- image: multica-backend
dockerfile: Dockerfile
- image: multica-web
dockerfile: Dockerfile.web
steps:
- uses: actions/checkout@v4
- uses: docker/setup-buildx-action@v3
- uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- uses: docker/build-push-action@v6
with:
context: .
file: ${{ matrix.dockerfile }}
platforms: linux/amd64
push: true
tags: ghcr.io/coderpush/${{ matrix.image }}:sha-${{ github.sha }}
labels: |
org.opencontainers.image.source=https://github.com/CoderPush/multica
org.opencontainers.image.revision=${{ github.sha }}
build-args: |
VERSION=main-${{ github.sha }}
COMMIT=${{ github.sha }}
NEXT_PUBLIC_APP_VERSION=main-${{ github.sha }}
cache-from: type=gha,scope=${{ matrix.image }}
cache-to: type=gha,mode=max,scope=${{ matrix.image }}
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -79,3 +79,5 @@ data/
__pycache__/
*.pyc
perf-report/
# The production example is a tracked template; `.env*` above would hide it.
!apps/mobile/.env.production.example
26 changes: 25 additions & 1 deletion CLI_AND_DAEMON.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,23 @@ For install script or manual installs, use:
multica update
```

`multica update` auto-detects your installation method and upgrades accordingly.
`multica update` uses GitHub Releases by default. Self-hosted installations can
point the CLI at a GitHub Releases-compatible metadata mirror and an artifact
mirror without changing the command. To let a daemon poll that source, also
enable self-update explicitly because self-hosted auto-update is disabled by
default:

```bash
export MULTICA_RELEASE_API_BASE_URL=https://updates.example/api
export MULTICA_RELEASE_DOWNLOAD_BASE_URL=https://updates.example/releases/download
export MULTICA_DAEMON_AUTO_UPDATE=true
multica update
```

The metadata mirror must serve `/repos/multica-ai/multica/releases/latest` and
`/repos/multica-ai/multica/releases/tags/<tag>`. The artifact mirror must serve
`/<tag>/<asset-name>` and preserve the published `checksums.txt` contents.
When these variables are unset, the GitHub defaults remain unchanged.

## Quick Start

Expand Down Expand Up @@ -1101,3 +1117,11 @@ On the API, both endpoints accept `?include=content` and `?include=metadata`.
A request that sends neither still gets `content`, on both endpoints, so a
server upgrade never changes what an un-upgraded client receives — it is the
CLI that asks for the smaller shape.

### Custom runtime compatibility targets

Create custom Oh-My-Pi profiles with `multica runtime profile create --runtime-type omp --command-name omp --display-name "Custom Oh-My-Pi"`.
The immutable `runtime_type` selects model discovery, skills paths, and launch behavior;
the server derives `protocol_family` (`pi` for `omp`). Custom command/path overrides and
fixed arguments still apply, and the runtime retains its custom-profile provenance.
Existing profiles and the legacy `--protocol-family` flag retain their original target.
7 changes: 6 additions & 1 deletion LICENSE
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,11 @@ together and what must be delivered when you redistribute.

Part I — Additional Conditions

In this Multica License, "the producer" means Index Labs (Hong Kong)
Limited, the company that develops and distributes Multica. Commercial
licenses and branding waivers may be requested at
https://www.multica.ai/contact-sales.

1. Multica may be utilized commercially, including as a backend service for
other applications or as a task management platform for enterprises,
subject to the following conditions:
Expand Down Expand Up @@ -112,7 +117,7 @@ together and what must be delivered when you redistribute.
deliver this complete file. Delivering Part II alone does not
satisfy the Multica License or section 4(a) of Part II.

© 2025-2026 Multica, Inc.
© 2025-2026 Index Labs (Hong Kong) Limited

------------------------------------------------------------------------

Expand Down
6 changes: 3 additions & 3 deletions NOTICE
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
Multica
Copyright 2025-2026 Multica, Inc.
Copyright 2025-2026 Index Labs (Hong Kong) Limited

This product includes software developed at Multica, Inc.
(https://github.com/multica-ai/multica).
This product includes software developed at Index Labs (Hong Kong) Limited
for Multica (https://github.com/multica-ai/multica).

Multica is distributed under the Multica License, which incorporates the
complete text of the Apache License, Version 2.0 together with additional
Expand Down
2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@

**Agents that show up on the board.**

Multica is an open-source workspace where you assign work to AI coding agents the way you'd
Multica is a source-available workspace where you assign work to AI coding agents the way you'd
assign it to a teammate — they pick up the issue, report progress, raise blockers, and hand it
back for review. Self-hostable, works with 26 agent CLIs, no lock-in.

Expand Down
4 changes: 2 additions & 2 deletions README.zh.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@

**智能体,也在看板上。**

Multica 是一个开源的团队工作区。你像给同事派活一样,把任务交给 AI 编码智能体——它自己接手、边做边
Multica 是一个源码公开的团队工作区。你像给同事派活一样,把任务交给 AI 编码智能体——它自己接手、边做边
汇报、卡住了主动说,做完交回来给你审。可自部署,支持 26 种智能体 CLI,不绑定任何厂商。

[![CI](https://github.com/multica-ai/multica/actions/workflows/ci.yml/badge.svg)](https://github.com/multica-ai/multica/actions/workflows/ci.yml)
Expand Down Expand Up @@ -245,7 +245,7 @@ iOS 客户端在 [`apps/mobile/`](apps/mobile/),怎么编译装到自己 iPhon

---

## 开源协议
## 许可协议

[Multica License](LICENSE) —— Apache License 2.0 全文并入,外加针对托管服务、商业嵌入和品牌标识的
附加条件。自部署、改代码、在它之上做东西都可以;准确条款以 [LICENSE](LICENSE) 为准,署名信息见
Expand Down
2 changes: 2 additions & 0 deletions SELF_HOSTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -263,6 +263,8 @@ When developing from a checkout, use the local chart path instead:
helm install multica deploy/helm/multica -n multica
```

If the backend has to reach services whose certificates come from an internal CA, such as a self-hosted Gitea, set `backend.extraCACerts.configMap`. See [Advanced Configuration → Private CA Certificates](SELF_HOSTING_ADVANCED.md#private-ca-certificates-optional).

Watch the pods come up:

```bash
Expand Down
Loading
Loading