Skip to content
65 changes: 64 additions & 1 deletion content/changelog/config_v1.3.17.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ version: '1.3.17'

- Expanded highly experimental stateful Code session controls
- `endpoints.agents.repositoryInstructions.timeoutMs` bounds attached-workspace instruction discovery and defaults to `2000` ms
- `statefulCodeSessions.userConfig.bash.maxQueueWaitMs` bounds attached Bash capacity retries and defaults to `300000` ms
- `statefulCodeSessions.environments[].configSchema.limits.maxQueueWaitMs` bounds attached Bash capacity retries and defaults to `300000` ms
- Setting `maxQueueWaitMs` to `0` disables client retries after initial admission without cancelling admitted or running work

- Added Agent error and background-result limits
Expand Down Expand Up @@ -69,4 +69,67 @@ version: '1.3.17'
- Set the value to an empty string only when all LibreChat credentials are injected through other supported environment settings
- Bundled Meilisearch still requires its separately configured master-key Secret

- Added optional saved-chat workspace transitions after rc4
- `endpoints.agents.statefulCodeSessions.conversationMoves.enabled` opts in to moving a conversation's sealed workspace and recovering a missing workspace
- `conversationMoves.allowAttachDetach` separately opts in to attaching or leaving a workspace; omission keeps the move-only policy
- Upgrade every API replica and enable `CODE_ENVIRONMENT_DECISION_VERSION=1` before activating the transitions

- Added optional attached-workspace request budgets
- `statefulCodeSessions.environments[].configSchema.limits.maxRequestTimeoutMs` caps total HTTP time for one call at up to `610000` ms
- The existing 30-second admission budget per attempt remains when this is unset, and `maxQueueWaitMs` remains an independent retry horizon
- Do not enable longer admission until the Code API honors per-request queue allowances and the shortest live ingress timeout has been measured
- `configSchema.limits.minCommandAdmissionMs` reserves `10000` ms by default before command execution (valid `1000`–`300000` ms); the total request budget must exceed this reserve plus 10000 ms of settlement/delivery grace
- Configured and advertised Bash command limits fit within the remaining HTTP budget; a 90000 ms request with an 80000 ms command ceiling and default reserve advertises at most a 70000 ms command

- Added opt-in linked-worktree scheduling for attached Code environments
- `statefulCodeSessions.environments[].configSchema.workspaces.linkedWorktrees` defaults to off; enable only after upgrading LibreChat, deploying Code API linked-worktree support, and starting compatible workers with `--linked-worktree-lanes`
- File tools with a worktree path and Bash commands with a worktree `cwd` use that worker lane; commands that `cd` internally stay in the checkout lane

- Added idle Agent recovery and graceful-shutdown controls
- `endpoints.agents.eventDriven.idlePolling.deliveryMaxIntervalMs` defaults to `15000` ms
- `queuedTurnMaxIntervalMs` and `maintenanceMaxIntervalMs` default to `120000` ms; `completionWaitMaxIntervalMs` defaults to `60000` ms
- Local readiness events can expedite delivery without waiting for an idle MongoDB recovery scan
- `endpoints.agents.backgroundTasks.shutdownInterruptGraceMs` defaults to `5000` ms (valid `0` through `60000`) before unfinished tools are recorded as interrupted during graceful shutdown

- Added `interface.agentSelectorLimit` to cap the unsearched Agent selector at `10` entries by default (valid `1` through `100`); searching still reaches all Agents

- Updated configuration validation and reload behavior
- Malformed explicitly configured `CREDS_KEY` or `CREDS_IV` values now fail startup; migrate data encrypted with an invalid-length key deliberately rather than rotating it blindly
- `rateLimits.conversationsImport`, `rateLimits.tts`, `rateLimits.stt`, and skill/Agent upload limits from `librechat.yaml` now apply to their route limiters without matching environment variables
- Invalid role, group, or user config override writes now return `400` without saving; previously stored overrides that would invalidate the merged config are dropped with a warning
- Reload failures keep the last good validated configuration active; startup validation still fails closed

- Hardened MCP OAuth HTTP requests
- Server-side OAuth discovery, registration, token, and revocation calls reject redirects; configure the final URL when an identity provider redirects
- Private IP literals are refused unless permitted by the existing admin-trusted host or exact address-and-port policy

- Added capability-negotiated workspace edit matching
- `statefulCodeSessions.environments[].configSchema.edits.tolerantMatching` allows whitespace-tolerant fallback by default when the worker advertises `tolerant_match`; set it to `false` to require exact matches
- Attached `edit_file` and protected edit previews only send new matching fields after negotiation; `replace_all` also requires the worker to advertise that feature
- Requires compatible Code API and worker builds implementing [Code Interpreter #271](https://github.com/LibreChat-AI/code-interpreter/pull/271); older deployments keep their current request format and matching behavior
- Edit conflicts use bounded, host-rendered facts rather than untrusted worker text; a rejected batch writes nothing

- Added GPT point-release family fallback and GPT-6.1 Sol
- A GPT point release without its own entry inherits the recognized family's context/output limits, pricing, and reasoning settings; explicit per-release entries win
- GPT-6.1 Sol joins the OpenAI and Agents catalogs, not Assistants; its limits and prices currently inherit GPT-6 Sol rather than new provider-published figures
- Native OpenAI Responses routing can inherit the family policy; Azure deployment routing and custom-endpoint opt-in behavior stay unchanged

- Hardened web-search credential pairing
- User-provided Firecrawl or SearXNG URLs cannot be combined with the server's API key, even when the destination passes SSRF checks
- Firecrawl ignores the optional user URL and uses its default endpoint; SearXNG cannot initialize with that mixed-ownership pair because its URL is required
- User-owned pairs, administrator-owned pairs, and keyless SearXNG remain supported; set both URL and key at the same ownership level

- Added tenant-scoped YAML custom endpoints
- `endpoints.custom[].tenantId` optionally restricts an endpoint and its associated model specs to the authoritative request tenant; omission preserves deployment-wide availability
- Tenant IDs accept 1–128 letters, digits, hyphens, underscores, or periods; whitespace and the reserved `__SYSTEM__` sentinel are invalid
- Missing tenant context does not receive scoped endpoints; cache, override, runtime augmentation, and fallback paths keep the same boundary
- Filtering the last model spec restores normal model controls while preserving explicit interface settings
- Upgrade every API replica before configuring scoped endpoints; older replicas do not enforce the new YAML field

- Bound per-user MCP API keys to their destinations
- UI-created/shared servers require each user to enter a key again when the URL path/query, proxy, transport, auth format/header, or configured OAuth client/destination changes
- Equivalent and cosmetic updates preserve existing keys; legacy keys remain usable at their unchanged boundary without a bulk migration
- Shared servers resolve only their currently declared credential variables, so old generated names cannot bypass re-entry
- Upgrade every API replica, including configuration writers, before relying on the new binding

- Updated the config version to `1.3.17`
Loading
Loading