Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
125 commits
Select commit Hold shift + click to select a range
62b266e
fix(api): check delegated draft permissions before running (#866)
rodboev Sep 17, 2026
0316539
fix(web): shorten exploration URLs (#853)
wesm Sep 18, 2026
d42272c
feat(imap): retrieve, edit, and delete managed drafts (#861)
rodboev Sep 19, 2026
8131389
docs(imap): fix setup links (#874)
rodboev Sep 21, 2026
7837532
fix(carddav): reject unsupported configured providers (#839)
wesm Sep 21, 2026
c6bb331
fix(web): explain query failures and offer recovery (#854)
wesm Sep 21, 2026
70a56c4
fix(ci): install SQLite headers for browser test builds (#873)
salmonumbrella Sep 21, 2026
0748525
feat(eval): measure search quality against relevance ratings (#879)
wesm Sep 22, 2026
61df409
fix(pst): treat empty attachment tables as no attachments (#888)
rodboev Sep 22, 2026
9e84275
fix(pst): skip search folders when walking PST archives (#887)
rodboev Sep 22, 2026
56d3f0b
feat(imap): recover identified draft operations (#880)
rodboev Sep 22, 2026
a36a394
fix(emlx): restore partial-message attachments from Apple Mail's Atta…
fucx Sep 22, 2026
6f1ca13
docs: update documentation for 0.20.0 (#891)
wesm Sep 22, 2026
e328909
docs: use plain language on the website and move Changelog up (#893)
wesm Sep 22, 2026
e27d0a4
fix(docs): repair deployment and publish Markdown pages (#892)
wesm Sep 23, 2026
b5969b2
web: make Directory detail scroll and summarize attributes (#902)
salmonumbrella Sep 23, 2026
06e9f7d
fix(analytics): skip pre-1970 years in annual relationship temperatur…
rodboev Sep 23, 2026
57f16e3
fix(imap): preserve legacy Message-IDs during membership refresh (#913)
eliemada Sep 23, 2026
94981b9
web: improve relationship calendar layout and navigation (#904)
salmonumbrella Sep 23, 2026
5fd9553
web: clarify relationship identities and views (#903)
salmonumbrella Sep 23, 2026
f4fa31e
feat(carddav): support Digest and approved private destinations (#899)
salmonumbrella Sep 23, 2026
c14568c
fix(daemon): let CLI commands skip local daemon auto-start (#909)
rodboev Sep 23, 2026
7abbea1
test(timing): convert remaining owned waits and check polling budgets…
rodboev Sep 23, 2026
61b7fa5
feat(meetings): add context export, source actions, and activity metr…
salmonumbrella Sep 24, 2026
3a456a3
api,web: make source status read-only and bounded (#905)
salmonumbrella Sep 24, 2026
2babf03
fix(mcp): keep initialization independent of archive statistics (#908)
rodboev Sep 24, 2026
9b84739
fix(store): log canceled planner maintenance at debug level (#910)
rodboev Sep 24, 2026
46d918a
fix(slack): allow excluding DMs and group DMs from sync (#911)
rodboev Sep 24, 2026
4e2551e
feat(import): add iMazing CSV archives (#851)
salmonumbrella Sep 24, 2026
d80d904
feat(vector): add a SQLite semantic search accelerator (#871)
salmonumbrella Sep 24, 2026
e62c068
feat(beeper): submit stored audio and transcripts to Docbank (#876)
rodboev Sep 24, 2026
2471da0
fix(mcp): publish saved view canonical_state as a schema object (#935)
rodboev Sep 25, 2026
28174dd
build: skip the golangci-lint install when the pinned version is pres…
rodboev Sep 25, 2026
569d84b
feat(setup): let setup finish without a Google credential (#931)
exactmike Sep 25, 2026
fbdc5d0
test(sync,api): run sync and API tests in parallel (#936)
rodboev Sep 25, 2026
958d527
fix(update): attach a context before restarting the daemon (#941)
fucx Sep 25, 2026
ac15d62
test(vector): allow rounding differences in exact-filter scores (#942)
wesm Sep 25, 2026
a7c7c53
Add Kata-backed person agendas (#889)
salmonumbrella Sep 26, 2026
32cc5ef
feat(microsoft): sign in with a device code via --headless (#937)
exactmike Sep 26, 2026
cbb816e
api,web: explain linked identities with context and provenance (#906)
salmonumbrella Sep 26, 2026
37f1107
feat(gmail): manage reply drafts and send-as aliases (#882)
rodboev Sep 26, 2026
01ea454
feat(eval): compare search rankings with Jev reranking (#930)
rodboev Sep 26, 2026
75e659c
fix(store): stop backups overwriting a new file; adopt kit v0.26.0 fi…
mariusvniekerk Sep 26, 2026
ca0576e
test(timing): clear remaining sleeptest findings (#921) (#927)
rodboev Sep 26, 2026
8b0a966
fix(cache): serve published analytics while refresh runs (#914)
salmonumbrella Sep 27, 2026
d83d20e
fix(emlx): skip re-ingest when attachment restoration changes nothing…
salmonumbrella Sep 27, 2026
c97eb87
fix(sync): keep scheduled sources on cadence under load (#956)
salmonumbrella Sep 27, 2026
cbb15f7
test(cli): refuse real background daemon launches in tests (#954)
rodboev Sep 27, 2026
d7f11b3
ci: fall back to direct module fetch on proxy errors (#967)
rodboev Sep 27, 2026
783c0cf
ci: lint windows-only code on the windows runner (#968)
rodboev Sep 27, 2026
e186afe
fix(store): scope people-fact migration checks to affected tables (#965)
shntnu Sep 27, 2026
1bec68d
fix(search): report concurrent daemon work accurately (#926)
salmonumbrella Sep 27, 2026
9d1db6d
fix(search): show readable chat results in search tables (#933)
salmonumbrella Sep 27, 2026
f7ba448
feat(slack): allow per-run DM selection (#966)
shntnu Sep 27, 2026
e239a2a
ci: split windows cli and store tests across three runners (#976)
rodboev Sep 27, 2026
4ead902
fix(api): return complete JSON for invalid UTF-8 (#923)
salmonumbrella Sep 27, 2026
5987ab6
fix(imap): refetch full header on empty HEADER.FIELDS (#959)
franklintra Sep 27, 2026
c440ee9
perf(search): resolve address filters through participants (#925)
salmonumbrella Sep 27, 2026
9fb7cfb
ci: move workflows to Namespace runners (#974)
wesm Sep 27, 2026
c22fe8d
fix(beeper): stop retrying media the source has deleted (#950)
salmonumbrella Sep 28, 2026
a7e3c12
refactor(cli): isolate configuration per command invocation (#970)
rodboev Sep 28, 2026
c459e43
fix(carddav): Enumerate Google contacts on the initial sync (#963)
aaronwolen Sep 28, 2026
9cd3c4d
feat(imap): add fresh drafts, reply-all and sender selection (#881)
rodboev Sep 28, 2026
53e28e5
fix(import): record chat message size estimates (#934)
salmonumbrella Sep 28, 2026
08d7e58
fix(search): fit tables to terminals and preserve redirected text (#979)
salmonumbrella Sep 28, 2026
df7bd11
fix(cache): pin CSV quoting for analytics cache snapshots (#975)
aaronwolen Sep 28, 2026
b6deabe
fix(cache): repair invalid UTF-8 during analytics export (#924)
salmonumbrella Sep 28, 2026
604483a
feat(people): add provider presets and gate Codex enrollment (#918)
salmonumbrella Sep 28, 2026
b377dbf
fix(gmail): recover from quota throttling in the shared client (#969)
metcalfc Sep 28, 2026
4525622
perf(search): check FTS coverage without reading stored content (#978)
salmonumbrella Sep 28, 2026
20cf096
test(peoplesweep): skip Linux-only Codex proxy tests on macOS (#982)
wesm Sep 28, 2026
7ba0ec4
perf(cache): normalize relationship activity and keep appends increme…
salmonumbrella Sep 28, 2026
579be0d
fix(vcard): derive and refresh full names for nameless contacts (#962)
spf13 Sep 28, 2026
2a160c4
fix(people): reuse enrichment citations across lookups (#983)
wesm Sep 28, 2026
f3add78
feat(beeper): route stored audio from captured sources (#939)
rodboev Sep 28, 2026
b41344a
test(web): wait for the directory drawer before keyboard disclosure (…
rodboev Sep 29, 2026
d2e82f7
fix(cache): keep queries responsive and label imports incremental (#915)
salmonumbrella Sep 29, 2026
2bd6468
fix(store): sample SQLite planner maintenance on close (#986)
wesm Sep 29, 2026
5d1ce39
feat(msmail): sync Microsoft 365 mail through Microsoft Graph (#944)
exactmike Sep 29, 2026
61a8d1f
fix(identity): preserve account opt-out during scheduled sync (#987)
wesm Sep 29, 2026
e54b14f
feat(meetings): add Muesli and link meeting attendees to people (#946)
salmonumbrella Sep 29, 2026
386d024
feat(export): export original emails and threads (#953)
salmonumbrella Sep 29, 2026
289f3e4
fix(people): stop repeating failed enrichment lookups (#988)
wesm Sep 29, 2026
0b48fa8
feat(web): replace the tab bar with a grouped sidebar and global sear…
wesm Sep 29, 2026
f5f59b1
fix(people): seed display names on participant promotion (#998)
salmonumbrella Sep 29, 2026
ef66efc
feat(web): give Everything and Files one toolbar and save views in pl…
wesm Sep 30, 2026
1486c4f
fix(imessage): reject invalid Apple Messages timestamps (#1001)
salmonumbrella Sep 30, 2026
8869c13
fix(imap): recover legacy Message-IDs during baseline sync (#1000)
salmonumbrella Sep 30, 2026
c185b1b
feat(msmail): delete Graph mail at the source (#1012)
exactmike Oct 1, 2026
3008f0c
feat(drafts): allow delegated gmail and imap draft lifecycle (#666) (…
rodboev Oct 1, 2026
bf24339
feat(drafts): keep local chat drafts behind the existing draft comman…
rodboev Oct 1, 2026
6ed03f7
refactor(store): share one draft lifecycle between IMAP and Gmail (#1…
rodboev Oct 1, 2026
428b7c5
fix(documents): expose extraction causes and consent inline attachmen…
salmonumbrella Oct 1, 2026
a3f5f04
feat(web): give the People workspaces one structure (#1019)
wesm Oct 1, 2026
d8afbae
feat(imap): forward archived mail with stored attachments (#666) (#1004)
rodboev Oct 1, 2026
1c5a485
feat(beeper): write native chat drafts through the draft commands (#1…
rodboev Oct 1, 2026
5e8fff6
feat(web): bring the Manage pages into the overhauled UI (#1029)
wesm Oct 1, 2026
913ab25
refactor: use backoff for supported retry policies (#1032)
mariusvniekerk Oct 1, 2026
76f56e8
perf(web): reduce query costs and fix Files and layout regressions (#…
wesm Oct 1, 2026
6ada091
refactor(vector): use Kit for embedding requests and rank fusion (#1034)
mariusvniekerk Oct 2, 2026
0a3a46f
refactor(store): share one attribute store between people and organiz…
rodboev Oct 2, 2026
9f11539
fix(web): draw every pane divider as one 4px kit-ui handle (#1038)
mariusvniekerk Oct 2, 2026
52793f5
feat(carddav): support multiple named connections (#1010)
salmonumbrella Oct 2, 2026
1d543f7
fix(directory): use activity channels in the primary channel filter (…
salmonumbrella Oct 2, 2026
9e1cc2a
docs(oauth): add IMAP.AccessAsUser.All from Microsoft Graph (#1033)
exactmike Oct 2, 2026
a36b89d
fix(pst): preserve message identifiers and reconcile reply threads (#…
salmonumbrella Oct 2, 2026
3e1eab2
perf(vector): remove base64 preprocessing CPU bottleneck (#1047)
salmonumbrella Oct 2, 2026
5e21204
fix(store): prevent NULL timestamps from wedging activity projection …
wesm Oct 2, 2026
b5eeea9
fix(scheduler): bound maintenance and resume projection fairly (#1048)
salmonumbrella Oct 2, 2026
3389746
feat(people): add reviewed identity and contact tools with optional s…
salmonumbrella Oct 2, 2026
8c9cb39
fix(analytics): preserve cache work across concurrent syncs (#1044)
salmonumbrella Oct 2, 2026
598ca5c
fix(people): wrap scoring scans before reporting completion (#1063)
salmonumbrella Oct 2, 2026
b9f7a37
docs: prepare 0.21.0 release guides and screenshots (#1069)
wesm Oct 2, 2026
549ae7e
feat(identity): complete survivor metadata and OAuth evidence (#1056)
salmonumbrella Oct 3, 2026
de834d7
feat(whatsapp): make Apple imports incremental (#1052)
eserie Oct 3, 2026
a9d9a16
feat(plaud): add native meeting sync (#1042)
salmonumbrella Oct 3, 2026
7b0eb1c
fix(store): discover legacy Beeper audio with no attachment state (#1…
rodboev Oct 4, 2026
cba9fbc
fix(mcp): declare query_sql output schema as an object (#1078)
salmonumbrella Oct 4, 2026
ae698a8
feat(calendar): add daemon-controlled event operations (#1041)
salmonumbrella Oct 4, 2026
008a353
fix(deps): update module go.opentelemetry.io/otel/sdk to v1.45.0 [sec…
renovate[bot] Oct 4, 2026
1cc3cb0
feat: configure supervised deployments without startup scripts (#1036)
salmonumbrella Oct 4, 2026
728c73c
feat(slack): support public-only archives and conversation selection …
wesm Oct 5, 2026
e0f930a
refactor(eval): use Docbank's TypeSafe client for the rerank arm (#1005)
rodboev Oct 5, 2026
9c7ad3f
refactor: share retry, credential, owner-match and export helpers (#1…
rodboev Oct 5, 2026
aa41181
refactor(carddav): move the network calls behind a Remote interface (…
exactmike Oct 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 5 additions & 0 deletions .custom-gcl.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
version: v2.13.1
plugins:
- module: "go.kenn.io/kit"
import: "go.kenn.io/kit/lint/gclplugin"
version: "v0.25.1-0.20260918202731-04a175847323"
3 changes: 3 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,6 @@ internal/vcard/registry/data/*.csv -text whitespace=blank-at-eol,blank-at-eof,sp
# line endings on Windows checkouts.
internal/slack/testdata/slackdump/standard/general/attachments/** -text
internal/slack/testdata/slackdump/standard/__uploads/** -text

# Keep the pinned upstream Vec1 source byte-for-byte reproducible.
internal/vector/sqlitevec/vec1/vec1.c -text whitespace=-blank-at-eol,-blank-at-eof
5 changes: 5 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
self-hosted-runner:
labels:
- windows-11-vs2026-arm
- namespace-profile-linux-4cpu
- namespace-profile-linux-8cpu
- namespace-profile-windows-8cpu
- nscloud-ubuntu-24.04-arm64-4x8
- namespace-profile-mac-6cpu
3 changes: 1 addition & 2 deletions .github/workflows/ci-pr.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,7 @@
name: CI

# The PR dispatcher always calls the main-pinned workflow. That workflow
# independently routes same-repository Linux jobs to the managed public fleet
# and fork jobs to GitHub-hosted runners.
# runs PR jobs on Namespace, including fork PRs.
on:
pull_request:

Expand Down
200 changes: 145 additions & 55 deletions .github/workflows/ci.yml

Large diffs are not rendered by default.

40 changes: 40 additions & 0 deletions .github/workflows/codex-isolation.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: Codex isolation

on:
pull_request:
push:
branches: [main]
workflow_dispatch:

permissions:
contents: read

jobs:
pinned-artifact:
# Ubuntu 22.04 permits the unprivileged user namespaces used by Bubblewrap.
runs-on: ubuntu-22.04
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: actions/setup-go@924ae3a1cded613372ab5595356fb5720e22ba16 # v6.5.0
with:
go-version-file: go.mod
cache: 'true'
- name: Install Bubblewrap
run: sudo apt-get update && sudo apt-get install -y bubblewrap
- name: Download pinned Codex artifact
run: |
mkdir -p "$RUNNER_TEMP/codex-artifact"
cd "$RUNNER_TEMP/codex-artifact"
curl -fsSL --retry 3 https://github.com/openai/codex/releases/download/rust-v0.156.0/codex-x86_64-unknown-linux-musl.tar.gz -o codex.tar.gz
echo '3d49d9af25a5168cfc51e50e520ab238b23083c259ae7c14f89b007cb2545c7b codex.tar.gz' | sha256sum -c -
tar -xzf codex.tar.gz
echo '78a11f06e0a2dda42d13fba1d50dc62e8cbdb2d5f69789722f4d4d99b5cdbe30 codex-x86_64-unknown-linux-musl' | sha256sum -c -
echo "MSGVAULT_CODEX_PINNED_EXECUTABLE=$PWD/codex-x86_64-unknown-linux-musl" >> "$GITHUB_ENV"
- name: Exercise launcher and protocol without real credentials
run: |
CGO_ENABLED=0 go build -trimpath -buildvcs=false -o "$RUNNER_TEMP/codex-artifact/msgvault-codex-bridge" ./cmd/msgvault-codex-bridge
chmod 755 "$RUNNER_TEMP/codex-artifact/msgvault-codex-bridge"
bridge_digest=$(sha256sum "$RUNNER_TEMP/codex-artifact/msgvault-codex-bridge" | cut -d' ' -f1)
go test -tags "fts5 sqlite_vec" -c -ldflags="-X go.kenn.io/msgvault/internal/peoplesweep.codexBridgeSHA256=$bridge_digest" -o "$RUNNER_TEMP/codex-artifact/peoplesweep.test" ./internal/peoplesweep
cd internal/peoplesweep
MSGVAULT_CODEX_TEST_DEFAULT_BRIDGE=1 "$RUNNER_TEMP/codex-artifact/peoplesweep.test" -test.timeout=5m -test.run='^TestCodex' -test.count=1
38 changes: 2 additions & 36 deletions .github/workflows/docker-pr.yml
Original file line number Diff line number Diff line change
@@ -1,8 +1,6 @@
name: Docker

# Bootstrap the split between validation and publishing on a GitHub-hosted
# runner. Follow-up PRs can return this dispatcher to docker.yml@main once
# that read-only reusable workflow is present on the default branch.
# Run the main-pinned build and smoke checks on Namespace.
on:
pull_request:
paths:
Expand All @@ -25,36 +23,4 @@ permissions: read-all

jobs:
validate:
runs-on: ubuntu-latest

steps:
- name: Checkout
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

- name: Set up Docker Buildx
uses: docker/setup-buildx-action@bb05f3f5519dd87d3ba754cc423b652a5edd6d2c # v4.2.0

- uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: 1.3.14

- name: Build browser application
run: make web-assets-check

- name: Build amd64 image
uses: docker/build-push-action@53b7df96c91f9c12dcc8a07bcb9ccacbed38856a # v7.3.0
with:
context: .
platforms: linux/amd64
push: false
load: true
tags: msgvault:test
build-args: |
VERSION=test
COMMIT=${{ github.sha }}
BUILD_DATE=test
cache-from: type=gha
cache-to: type=gha,mode=max

- name: Smoke test (amd64)
run: scripts/smoke-container.sh msgvault:test
uses: kenn-io/msgvault/.github/workflows/docker.yml@main
3 changes: 2 additions & 1 deletion .github/workflows/docker.yml
Original file line number Diff line number Diff line change
@@ -1,14 +1,15 @@
name: Docker

on:
workflow_dispatch:
workflow_call:

permissions: read-all

jobs:
# PR validation: build and smoke-test only, no registry access
validate:
runs-on: ${{ github.repository == 'kenn-io/msgvault' && github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository && github.event.pull_request.base.repo.full_name == github.repository && 'kenn-linux-x64-public' || 'ubuntu-latest' }}
runs-on: namespace-profile-linux-4cpu
permissions:
contents: read

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ on:

jobs:
docs:
runs-on: ubuntu-24.04
runs-on: namespace-profile-linux-4cpu
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0

Expand Down
3 changes: 2 additions & 1 deletion .github/workflows/workflow-validation.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
name: Workflow validation

on:
workflow_dispatch:
pull_request:
paths:
- ".github/workflows/**"
Expand All @@ -10,7 +11,7 @@ permissions:

jobs:
actionlint:
runs-on: ubuntu-latest
runs-on: namespace-profile-linux-4cpu
steps:
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
- uses: raven-actions/actionlint@3d39aea434753780c3b3d4a1a31c854b4dbf49d7 # v2.2.0
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# Go binaries
/msgvault
/msgvault-codex-bridge
/msgvault.exe
/mimeshootout

Expand Down
23 changes: 23 additions & 0 deletions .golangci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,7 @@ linters:
- ineffassign
- intrange
- iotamixing
- kennlint
- loggercheck
- makezero
- mirror
Expand Down Expand Up @@ -203,8 +204,30 @@ linters:
# use errors.Is to distinguish, which wrapping would break.
- .Err(

custom:
# Kit's analyzers, built into custom-gcl by `make lint`. Only sleeptest
# runs. The stock sqlclosecheck and rowserrcheck above stay; Kit's
# copies and its other analyzers are off until they get their own pass.
kennlint:
type: module
description: Kit sleeptest, time.Sleep in tests outside synctest.
original-url: go.kenn.io/kit/lint
settings:
disable:
- errtext
- nohttpmux
- rowserrcheck
- sqlcheck
- sqlclosecheck
- testifyhelper

exclusions:
rules:
# Workspace varies in Linux enrollment tests excluded from Windows builds.
- linters: [unparam]
path: internal/peoplesweep/codex_app_server_test\.go
text: "syntheticCodexAuth - workspace"

# Tests legitimately repeat fixture strings
- linters: [goconst]
path: _test\.go
Expand Down
4 changes: 4 additions & 0 deletions .roborev.toml
Original file line number Diff line number Diff line change
Expand Up @@ -54,4 +54,8 @@ repo-ignored local credential files, dotenv files, OAuth client JSON, or
other dotfiles into those artifacts. Do not flag literal example strings in
documentation snippets as leaked secrets unless they are plausible real
credentials.

The Jev adapter passes a plain http.Client to Docbank's TypeSafe client,
which refuses redirects on its own copy. Do not flag redirect handling
in internal/vector/rerank/jev.go.
"""
15 changes: 12 additions & 3 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ RUN cd web && bun run generate && bun run build

# Go build stage.
# Pin by digest for reproducibility; update periodically.
FROM golang:1.27.0-bookworm@sha256:484ef6066fa69acb059fdfeda7ba2b8f7391f2ef6abc6f9b8411e669ebd56466 AS builder
FROM golang:1.27.1-bookworm@sha256:69a7b9788769bec032d238959b61854e9ae87f57be9029ec04e9885fabf99195 AS builder

# Install build dependencies for CGO (SQLite, DuckDB).
# libsqlite3-dev provides sqlite3.h, required to compile the sqlite-vec
Expand All @@ -26,6 +26,9 @@ RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-ins

WORKDIR /src

# Fall back to the module's source repo on any proxy error, not just 404/410.
ENV GOPROXY=https://proxy.golang.org|direct

# Download dependencies first (layer caching)
COPY go.mod go.sum ./
RUN go mod download
Expand All @@ -42,13 +45,17 @@ ARG COMMIT=unknown
ARG BUILD_DATE=unknown

# Note: Module path must match go.mod (go.kenn.io/msgvault)
RUN CGO_ENABLED=1 go build \
RUN CGO_ENABLED=0 go build -trimpath -buildvcs=false \
-o /msgvault-codex-bridge ./cmd/msgvault-codex-bridge \
&& bridge_digest=$(sha256sum /msgvault-codex-bridge | cut -d' ' -f1) \
&& CGO_ENABLED=1 go build \
-tags "fts5 sqlite_vec" \
-trimpath \
-ldflags="-s -w \
-X go.kenn.io/msgvault/cmd/msgvault/cmd.Version=${VERSION} \
-X go.kenn.io/msgvault/cmd/msgvault/cmd.Commit=${COMMIT} \
-X go.kenn.io/msgvault/cmd/msgvault/cmd.BuildDate=${BUILD_DATE}" \
-X go.kenn.io/msgvault/cmd/msgvault/cmd.BuildDate=${BUILD_DATE} \
-X go.kenn.io/msgvault/internal/peoplesweep.codexBridgeSHA256=${bridge_digest}" \
-o /msgvault \
./cmd/msgvault

Expand All @@ -61,6 +68,7 @@ RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-ins
tzdata \
wget \
libstdc++6 \
bubblewrap \
&& rm -rf /var/lib/apt/lists/*

# Create non-root user
Expand All @@ -69,6 +77,7 @@ RUN groupadd --gid 1000 msgvault \

# Copy binary from builder
COPY --from=builder /msgvault /usr/local/bin/msgvault
COPY --from=builder --chown=msgvault:msgvault /msgvault-codex-bridge /usr/local/bin/msgvault-codex-bridge

# Set up data directory with correct ownership
ENV MSGVAULT_HOME=/data
Expand Down
Loading
Loading