Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
75 changes: 74 additions & 1 deletion content/changelog/config_v1.3.17.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ version: '1.3.17'

- Expanded highly experimental stateful Code session controls
- `endpoints.agents.repositoryInstructions.timeoutMs` bounds attached-workspace instruction discovery and defaults to `2000` ms
- `statefulCodeSessions.userConfig.bash.maxQueueWaitMs` bounds attached Bash capacity retries and defaults to `300000` ms
- `statefulCodeSessions.environments[].configSchema.limits.maxQueueWaitMs` bounds attached Bash capacity retries and defaults to `300000` ms
- Setting `maxQueueWaitMs` to `0` disables client retries after initial admission without cancelling admitted or running work

- Added Agent error and background-result limits
Expand Down Expand Up @@ -69,4 +69,77 @@ version: '1.3.17'
- Set the value to an empty string only when all LibreChat credentials are injected through other supported environment settings
- Bundled Meilisearch still requires its separately configured master-key Secret

- Added optional saved-chat workspace transitions after rc4
- `endpoints.agents.statefulCodeSessions.conversationMoves.enabled` opts in to moving a conversation's sealed workspace and recovering a missing workspace
- `conversationMoves.allowAttachDetach` separately opts in to attaching or leaving a workspace; omission keeps the move-only policy
- Upgrade every API replica and enable `CODE_ENVIRONMENT_DECISION_VERSION=1` before activating the transitions

- Added optional attached-workspace request budgets
- `statefulCodeSessions.environments[].configSchema.limits.maxRequestTimeoutMs` caps total HTTP time for one call at up to `610000` ms
- The existing 30-second admission budget per attempt remains when this is unset, and `maxQueueWaitMs` remains an independent retry horizon
- Do not enable longer admission until the Code API honors per-request queue allowances and the shortest live ingress timeout has been measured
- `configSchema.limits.minCommandAdmissionMs` reserves `10000` ms by default before command execution (valid `1000`–`300000` ms); the total request budget must exceed this reserve plus 10000 ms of settlement/delivery grace
- Configured and advertised Bash command limits fit within the remaining HTTP budget; a 90000 ms request with an 80000 ms command ceiling and default reserve advertises at most a 70000 ms command

- Added opt-in linked-worktree scheduling for attached Code environments
- `statefulCodeSessions.environments[].configSchema.workspaces.linkedWorktrees` defaults to off; enable only after upgrading LibreChat, deploying Code API linked-worktree support, and starting compatible workers with `--linked-worktree-lanes`
- File tools with a worktree path and Bash commands with a worktree `cwd` use that worker lane; commands that `cd` internally stay in the checkout lane

- Added idle Agent recovery and graceful-shutdown controls
- `endpoints.agents.eventDriven.idlePolling.deliveryMaxIntervalMs` defaults to `15000` ms
- `queuedTurnMaxIntervalMs` and `maintenanceMaxIntervalMs` default to `120000` ms; `completionWaitMaxIntervalMs` defaults to `60000` ms
- Local readiness events can expedite delivery without waiting for an idle MongoDB recovery scan
- `endpoints.agents.backgroundTasks.shutdownInterruptGraceMs` defaults to `5000` ms (valid `0` through `60000`) before unfinished tools are recorded as interrupted during graceful shutdown

- Added `interface.agentSelectorLimit` to cap the unsearched Agent selector at `10` entries by default (valid `1` through `100`); searching still reaches all Agents

- Updated configuration validation and reload behavior
- Malformed explicitly configured `CREDS_KEY` or `CREDS_IV` values now fail startup; migrate data encrypted with an invalid-length key deliberately rather than rotating it blindly
- `rateLimits.conversationsImport`, `rateLimits.tts`, `rateLimits.stt`, and skill/Agent upload limits from `librechat.yaml` now apply to their route limiters without matching environment variables
- Invalid role, group, or user config override writes now return `400` without saving; previously stored overrides that would invalidate the merged config are dropped with a warning
- Reload failures keep the last good validated configuration active; startup validation still fails closed

- Hardened MCP OAuth HTTP requests
- Server-side OAuth discovery, registration, token, and revocation calls reject redirects; configure the final URL when an identity provider redirects
- Private IP literals are refused unless permitted by the existing admin-trusted host or exact address-and-port policy

- Added capability-negotiated workspace edit matching
- `statefulCodeSessions.environments[].configSchema.edits.tolerantMatching` allows whitespace-tolerant fallback by default when the worker advertises `tolerant_match`; set it to `false` to require exact matches
- Attached `edit_file` and protected edit previews only send new matching fields after negotiation; `replace_all` also requires the worker to advertise that feature
- Requires compatible Code API and worker builds implementing [Code Interpreter #271](https://github.com/LibreChat-AI/code-interpreter/pull/271); older deployments keep their current request format and matching behavior
- Edit conflicts use bounded, host-rendered facts rather than untrusted worker text; a rejected batch writes nothing

- Added GPT point-release family fallback and GPT-6.1 Sol
- A GPT point release without its own entry inherits the recognized family's context/output limits, pricing, and reasoning settings; explicit per-release entries win
- GPT-6.1 Sol joins the OpenAI and Agents catalogs, not Assistants; its limits and prices currently inherit GPT-6 Sol rather than new provider-published figures
- Native OpenAI Responses routing can inherit the family policy; Azure deployment routing and custom-endpoint opt-in behavior stay unchanged

- Hardened web-search credential pairing
- User-provided Firecrawl or SearXNG URLs cannot be combined with the server's API key, even when the destination passes SSRF checks
- Firecrawl ignores the optional user URL and uses its default endpoint; SearXNG cannot initialize with that mixed-ownership pair because its URL is required
- User-owned pairs, administrator-owned pairs, and keyless SearXNG remain supported; set both URL and key at the same ownership level

- Added tenant-scoped YAML custom endpoints
- `endpoints.custom[].tenantId` optionally restricts an endpoint and its associated model specs to the authoritative request tenant; omission preserves deployment-wide availability
- Tenant IDs accept 1–128 letters, digits, hyphens, underscores, or periods; whitespace and the reserved `__SYSTEM__` sentinel are invalid
- Missing tenant context does not receive scoped endpoints; cache, override, runtime augmentation, and fallback paths keep the same boundary
- Filtering the last model spec restores normal model controls while preserving explicit interface settings
- Upgrade every API replica before configuring scoped endpoints; older replicas do not enforce the new YAML field

- Bound per-user MCP API keys to their destinations
- UI-created/shared servers require each user to enter a key again when the URL path/query, proxy, transport, auth format/header, or configured OAuth client/destination changes
- Equivalent and cosmetic updates preserve existing keys; legacy keys remain usable at their unchanged boundary without a bulk migration
- Shared servers resolve only their currently declared credential variables, so old generated names cannot bypass re-entry
- Upgrade every API replica, including configuration writers, before relying on the new binding

- Tightened native edit approval and import behavior
- Empty or malformed `edit_file.edits` batches now fail closed instead of falling back to top-level replacements
- Native edit arguments, including valid stringified JSON and hook rewrites, are normalized before approval so the preview matches execution
- Imports and other bulk conversation writes cannot copy a Code approval mode; new records use the recipient's preference/default and updates preserve the locally stored choice
- Existing saved modes are not retroactively changed; ordinary user-selected saves remain supported

- Updated the stable release deployment snapshot
- The application version is `v0.8.8` and the Helm chart source is `2.0.15` with `appVersion: v0.8.8`; the RAG chart and configuration schema version are unchanged
- When the chart's `librechat.configEnv` would otherwise be null, set it to `{}` to avoid the known template-rendering failure; credentials still belong in the named Secret

- Updated the config version to `1.3.17`
Loading
Loading