Patch notes: Live's feature loader runs on the network's web runtime
Imported. Imported from Commit messages from the OpenVibers repositories on GitHub; originally by OpenVibers.
What shipped on OpenVibe from 2026-09-27 to 2026-09-28: 80 changes to OpenVibe.Live, OpenVibe.AI, OpenVibe.Network, OpenVibe.Games, OpenVibe.Media, OpenVibe.Community and 7 more. Every line below is a commit message from the OpenVibers repositories, linked to the change itself.
Highlights
- OpenVibe.Live: Live's feature loader runs on the network's web runtime (roadmap WS-P task 6; openvibe-shared 1.22.0 -> 1.23.0). public/js/ov-loader.js was extracted into openvibe-shared/web-runtime.js and is now a 50-line wrapper: it reads the #ov-assets… (
d4c15e1) - OpenVibe.Network: Account export and deletion (roadmap WS-B task 7, ADR-033; openvibe-contracts 0.70.0 -> 0.71.0). server/identity/account-data.js. (
e2787eb) - OpenVibe.Live: Live calls no model provider itself and keeps no shared provider key (roadmap WS-O task 2, shims C-20 and C-21). Production has run AI_SERVICE=remote since 2026-09-23 and the local provider path has had no calls since; streamers' own keys… (
04cd59f)
OpenVibe.Live
- N-1 fixtures re-recorded from 2e6f546, the release now in production (npm run n-1:record). (
8525ff1) - Live's feature loader runs on the network's web runtime (roadmap WS-P task 6; openvibe-shared 1.22.0 -> 1.23.0). public/js/ov-loader.js was extracted into openvibe-shared/web-runtime.js and is now a 50-line wrapper: it reads the #ov-assets… (
d4c15e1) - deploy/scripts/deploy.sh hands over to ovhost deploy live (OpenVibe.Host strategy release-layout; roadmap WS-N task 11). The old script is kept, unchanged, as deploy/scripts/deploy-legacy.sh. The wrapper maps --wait-idle, --restart… (
f0edbc0) - N-1 fixtures re-recorded from f0edbc0, the release now in production (npm run n-1:record; the first Live release deployed by ovhost's release-layout strategy). (
e663abb) - Live follows account merges (roadmap WS-B task 5, ADR-029; openvibe-contracts 0.68.0 -> 0.70.0). network.subject.merged arrives at POST /internal/network-events (the --network subscription now asks for it) and server/auth/subject-merge.js… (
4b7fa3f) - Live declares its release components, so a stylesheet-only release is swapped into open tabs in place (D46 scenario 1; Host docs/release-acceptance.md gate 1e, which was open). server/web/release-components.js has three components. styles… (
efab014) - N-1 fixtures re-recorded from efab014, the release now in production (npm run n-1:record). (
29d6808) - openvibe-shared 1.23.0 -> 1.23.1: release-watch drops an in-place region fetched for the previous account when openvibe-auth-changed fires and fetches it again with the new session (D46 scenario 9, which Live's in-place account switch… (
0481e9c) - N-1 fixtures re-recorded from 0481e9c, the release now in production (npm run n-1:record). (
cd89ba3) - Live takes part in account export and deletion (roadmap WS-B task 7, ADR-033; openvibe-contracts 0.70.0 -> 0.71.0). network.account.export_requested and network.account.deleted arrive at POST /internal/network-events (the --network… (
585428d) - Account deletion erases a staged chat table on whichever side writes it now (ADR-033, C-04): Live while chat-tables.authority() is live, and its capture relays the delete to Chat's copy; Chat once Chat writes the table (OpenVibe.Chat… (
06cf38b) - N-1 fixtures re-recorded from 06cf38b, the release now in production (npm run n-1:record). (
cc50c46) - A streamer's own provider key lives in OpenVibe.AI, not in Live's database (roadmap WS-O task 2; AI fca04c7, 0b9f7aa; Network d37ee87 grants live ai.credential.manage). (
4d758fa) - Live calls no model provider itself and keeps no shared provider key (roadmap WS-O task 2, shims C-20 and C-21). Production has run AI_SERVICE=remote since 2026-09-23 and the local provider path has had no calls since; streamers' own keys… (
04cd59f) - A streamer's AI-viewer daily budget is a cap in OpenVibe.AI (roadmap WS-O task 2; AI 960f14a ai.quota.attribution.manage, Network 728266b). server/ai/viewer-quota.js: on the site's AI with a budget, PUT… (
1954db2) - N-1 fixtures re-recorded from 1954db2, the release now in production (npm run n-1:record). (
c887515) - The moment picker sends OpenVibe.AI its facts, not a rendered prompt (roadmap WS-O task 2; AI 2574aad live.moments.pick template). _findBestMoment runs live.moments.pick with the title, the paste or clip flavor, the timeline, transcript… (
ec7e4b8) - N-1 fixtures re-recorded from ec7e4b8, the release now in production (npm run n-1:record). (
4b9e036) - The Arena judges send OpenVibe.AI what Live heard, not a prompt (roadmap WS-O task 2; AI f1564ac live.arena.judge_beef and judge_mic templates). judgeBeef sends the target's names and transcribed forms, whether and how the name was… (
9f32f86) - The home slogans, the daily secret and the Star of OpenVibe send OpenVibe.AI data, not prompts (roadmap WS-O task 2; AI templates live.hero.slogans, live.easter_egg, live.home.star). The slogan job sends the chat vibe, per-user notes… (
5bec390) - Chat analysis, person overviews, session titles and VOD ranking send OpenVibe.AI data, not prompts (roadmap WS-O task 2; AI 6b14064). The global chat picture and every chatter's profile (signed-in, bridged, anonymous) send the prior notes… (
fb2d768)
OpenVibe.AI
ai.openvibe.network · repository
- media.analyze, local-first media analysis (roadmap WS-O task 5). A new step kind, media_analysis (server/workflows/media-analysis.js), behind the workflow media.analyze (server/workflows/media.js, namespace media; Live may run it through… (
67fb2a4) - media.analyze on real streams (WS-O task 5, after the first production runs). Three fixes, from a 3-minute stretch of a JapaneseOldGuy VOD with speech 94% of the time but no highlights. Silence is -50 dB, real silence: a quiet stream talks… (
2d9a16f) - media.analyze: a highlight's speech is measured in time (at least half the window inside transcript segments), not in space-separated words, so Japanese speech counts (production: JapaneseOldGuy's VOD had loud and scene-change highlights… (
e587ce1) - A local model for media.analyze (WS-O task 5): deploy/systemd/openvibe-llm.service runs llama.cpp's llama-server on 127.0.0.1:8090 (OpenAI API, no key), held back for live streams (2 threads, CPUQuota 150%, nice 19, MemoryMax 3G).… (
566822e) - media.analyze transcribes long recordings in windows (WS-O task 5). The whisper provider caps a call at its own 10-minute timeout, so a whole hour-long VOD would have come back without a transcript. Speech-to-text now runs in windows… (
6f61c11) - A person's own provider key lives in OpenVibe.AI (roadmap WS-O task 2; openvibe-contracts 0.49.0 -> 0.73.0). (
fca04c7) - A credential's models or budget change without the key; a new provider or base URL needs it again (openvibe-contracts 0.73.0 -> 0.74.0, ai.credential-put@1 api_key optional after the first put). A key never follows a new endpoint on its… (
0b9f7aa) - Per-streamer AI budgets are AI quotas (roadmap WS-O task 2; openvibe-contracts 0.74.0 -> 0.75.0 ai.quota.attribution.manage). server/api/attribution-quotas.js: a service sets (PUT /api/v1/attribution-quotas/:attribution, hour or day, cost… (
960f14a) - media.analyze reads a recording where it lies instead of downloading it (roadmap WS-O tasks 2 and 5: the ranged fetch Live's adoption waited for). (
a5512c3) - .env.example documents AI_MEDIA_STREAM (media.analyze streams through the loopback reader by default; 0 downloads first). (
60eca1e) - live.moments.pick is a versioned template, not a prompt Live renders (roadmap WS-O task 2). The prompt from Live's ai-moments-job.js is the template live.moments.pick, with JSON output t, title and desc. The prepare hook formats the… (
2574aad) - The Arena judges are versioned templates, not prompts Live renders (roadmap WS-O task 2). live.arena.judge_beef and live.arena.judge_mic carry Live's system prompts and JSON schemas (arena/listener.js) and take what Live heard: the… (
f1564ac) - The home slogans, the daily secret and the Star of OpenVibe are versioned templates (roadmap WS-O task 2). live.hero.slogans, live.easter_egg and live.home.star move from passthrough to structured workflows (version 2 of each key), with… (
7c01c65) - Chat analysis, person overviews, session titles and VOD ranking are versioned templates (roadmap WS-O task 2). Live's prompts from chat-ai.js, chat-ai-routes.js and ai-moments-job.js become five structured workflows. live.chat.global takes… (
6b14064)
OpenVibe.Network
- deploy/scripts/deploy.sh hands over to ovhost deploy network --install-units (OpenVibe.Host strategy git-checkout; roadmap WS-N task 11). The old script is kept, unchanged, as deploy/scripts/deploy-legacy.sh. ovhost does what it did… (
d69ec60) - Live may run media.analyze on OpenVibe.AI (roadmap WS-O task 5): its ai.run.create and ai.run.read grants for openvibe.ai carry the namespaces live.*, network.site_copy and media.analyze (AI 67fb2a4, local-first VOD and clip analysis).… (
d072928) - Live's AI grants move to the new default at boot (follows d072928): CHANGED_DEFAULT_NAMESPACES moves Live's ai.run.create and ai.run.read rows for openvibe.ai from [live., network.site_copy] to [live., network.site_copy, media.analyze]… (
9b3835d) - Account merge (roadmap WS-B task 5, ADR-029; openvibe-contracts 0.68.0 -> 0.70.0). server/identity/account-merge.js folds a second account into the one a person keeps. The person: the account they keep opens a 10-minute intent (POST… (
899ca7a) - A merged account has no tokens of its own (ADR-029, found in the first production merge). Revocation has second precision, so the folded-in account's fresh sign-in token, minted in the same second as the merge, still answered /me for up to… (
25226d2) - Account export and deletion (roadmap WS-B task 7, ADR-033; openvibe-contracts 0.70.0 -> 0.71.0). server/identity/account-data.js. (
e2787eb) - Mod principals (roadmap WS-M task 3, ADR-013; openvibe-contracts 0.71.0 -> 0.72.0). server/identity/mod-principals.js: a mod install is the principal mod:<mod_id>, whose grants are the approved subset of what its manifest requests. (
c3a6441) - The probe principal may manage Games mods (games.mod.manage on openvibe.games) for the production mod lifecycle proof (roadmap WS-M task 6; Games apps/server/scripts/modLifecycleProof.ts installs, grants, uses and revokes a proof mod… (
2e9b5d5) - Live may store a streamer's own provider key in OpenVibe.AI (ai.credential.manage on openvibe.ai; roadmap WS-O task 2, AI fca04c7; openvibe-contracts 0.72.0 -> 0.73.0), so Live stops keeping third-party keys in its database.… (
d37ee87) - Live may cap a streamer's AI-viewer spend as an AI quota on their attribution (ai.quota.attribution.manage on openvibe.ai; roadmap WS-O task 2, AI 960f14a; openvibe-contracts 0.73.0 -> 0.75.0). test/principals.test.js follows Live's AI… (
728266b) - The admin AI panel follows Live's move to OpenVibe.AI (roadmap WS-O task 2, Live 04cd59f): the provider, key, base URL, model and price settings are gone from its list and its help text, and the status line shows which service runs AI… (
6a686fe)
OpenVibe.Games
- deploy/scripts/deploy.sh: deploys run through ovhost deploy games (OpenVibe.Host strategy pnpm-build; roadmap WS-N task 11). ovhost does the production procedure (pull, pnpm install --frozen-lockfile, pnpm build, restart openvibe-games)… (
e2d9a5d) - The game pages run their own pinned OpenVibe Frame (roadmap WS-P task 4, D42: the Games client). The server gains openvibe-shared 1.23.0 and serves its browser files at /shared (apps/server/src/net/sharedAssets.ts: only the files… (
8200c2c) - Games follows account merges (roadmap WS-B task 5, ADR-029). The platform events subscription now also asks for network.subject.merged; a delivery from Network with a valid payload calls store.identity.mergeSubject(from, into, merge_id)… (
9058cdd) - Games takes part in account export and deletion (roadmap WS-B task 7, ADR-033; apps/server openvibe-contracts 0.53.0 -> 0.71.0). POST /internal/events takes network.account.export_requested and network.account.deleted (the boot… (
fcb62c5) - Mod grants live in OpenVibe.Network (roadmap WS-M task 3, ADR-013; Network c3a6441, Contracts 0.72.0 mods.grant.manage). With a platform client, the mods API asks Network first and applies only what it answered… (
86fe34d) - apps/server/scripts/modLifecycleProof.ts: one production mod lifecycle (roadmap WS-M task 6, ADR-013). With the operator's probe principal (games.mod.manage on openvibe.games), a fresh proof mod (one inert prop far from spawn, published by… (
b724b5a) - Mod budgets are enforced on the offending mod only (roadmap WS-M task 4), and mod security tests (task 5). The runtime already timed each reconcile against the manifest's cpuMs. (
b5feaf8) - A late network.mod.grants_changed no longer undoes a newer grant (found by the production lifecycle proof: the register event, revision 1 with nothing approved, arrived after the API had applied revision 2's grant, so the prop flapped off… (
1529a52)
OpenVibe.Media
- N-1 fixtures re-recorded from 1157a54, the release now in production (npm run n-1:record). (
743c86f) - The media index loads its theme loader from Media's own /shared (roadmap WS-P task 4, D42): the last shared script a public page still took from openvibe.network (Media already served /shared; browse.js now uses openvibe-shared/serve.url… (
124ad1a) - Media follows account merges (roadmap WS-B task 5, ADR-029). network.subject.merged arrives at POST /internal/events (the same signed, loopback-only endpoint as the revocations; ensureSubscription now keeps one subscription per topic) and… (
be0facd) - N-1 fixtures re-recorded from the release now in production (npm run n-1:record). (
33ce8c9) - Media takes part in account export and deletion (roadmap WS-B task 7, ADR-033; openvibe-contracts 0.54.0 -> 0.71.0). POST /internal/events takes network.account.export_requested and network.account.deleted (the boot subscriptions now… (
a207b1d) - N-1 fixtures re-recorded from a207b1d, the release now in production (npm run n-1:record). (
793fafe) - Per-actor rate limits at Media's capability boundaries (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/actor-limits.js makes one limiter that counts each caller: the Network token's principal (svc:community, app:app_… of a… (
1125a3c)
OpenVibe.Community
openvibe.community · repository
- N-1 fixtures re-recorded from 69f5feb, the release now in production (npm run n-1:record). (
49565ac) - Community follows account merges (roadmap WS-B task 5, ADR-029). network.subject.merged joins the pulse consumer's topics (subscribed at boot) and server/identity/subject-merge.js applies it through the consumer's inbox, once per event, in… (
794e7e2) - N-1 fixtures re-recorded from the release now in production (npm run n-1:record). (
fe23860) - Community takes part in account export and deletion (roadmap WS-B task 7, ADR-033; openvibe-contracts 0.49.0 -> 0.71.0). The pulse consumer takes network.account.export_requested and network.account.deleted (subscribed at boot).… (
82e2bb9) - N-1 fixtures re-recorded from 82e2bb9, the release now in production (npm run n-1:record). (
7d35b5d) - Per-actor rate limits at Community's API routers (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/actor-limits.js makes one limiter per app, used by the paste, comment, forum (spaces, posts, groups), Pulse and relay APIs once… (
52d923a)
OpenVibe.Chat
- N-1 fixtures re-recorded from d4704b2, the release now in production (npm run n-1:record). (
4c563fc) - N-1 fixtures re-recorded with Live's widget at f0edbc0, the Live release now in production (N1_LIVE_REF=f0edbc0 npm run n-1:record). (
b3252cb) - Chat follows account merges (roadmap WS-B task 5, ADR-029). network.subject.merged joins the consumer's topics (a sixth subscription at boot) and server/chat/subject-merge.js applies it inside the inbox, once per event, in one transaction.… (
88202c1) - N-1 fixtures re-recorded from the Chat release now in production, with Live's widget at efab014 (npm run n-1:record). (
561cec9) - Chat takes part in account export and deletion (roadmap WS-B task 7, ADR-033; openvibe-contracts 0.57.0 -> 0.71.0). POST /internal/events takes network.account.export_requested and network.account.deleted (subscribed at boot).… (
a2d100d)
OpenVibe.Tools
- Dev tools run on the network's web runtime; the webhook viewer shows a sender's method and headers as text (roadmap WS-P task 6, the second site; openvibe-shared 1.22.0 -> 1.23.0 in every app). dev.html loads /shared/web-runtime.js (the… (
68f1330) - deploy/scripts/deploy.sh hands over to ovhost deploy tools (OpenVibe.Host strategy multi-app; roadmap WS-N task 11). The old script is kept, unchanged, as deploy/scripts/deploy-legacy.sh. ovhost does what it did (untracked lockfiles the… (
5768232) - Tools pages run their own pinned shared files (roadmap WS-P task 4, D42: the Tools satellites' static pages). apps/_shared/release.js mounts /shared (openvibe-shared/serve, content-addressed, only the browser files) in every app with the… (
390d3df)
OpenVibe.Events
events.openvibe.network · repository
- Per-actor rate limits at Events' capability routes (roadmap WS-R task 4): openvibe-sdk v0.12.0 is now a dependency, and server/actor-limits.js makes one limiter per app that counts each verified principal (svc:live, app:app_…) after its… (
7530c2f)
OpenRe.Stream
- deploy/scripts/deploy.sh hands over to ovhost deploy openre (OpenVibe.Host strategy release-layout; roadmap WS-N task 11). The old script is kept, unchanged, as deploy/scripts/deploy-legacy.sh. deploy (release + api in one), release… (
fadd8a3)
OpenVibe.Search
search.openvibe.network · repository
- Per-actor rate limits at Search's API routes (roadmap WS-R task 4): openvibe-sdk v0.12.0 is now a dependency, and server/actor-limits.js makes one limiter per app. Owner routes count the service principal (svc:wiki); query and saved-search… (
8ed7667)
OpenVibe.Tips
- Per-actor rate limits on Tips' /api/v1 (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/api/actor-limits.js makes one limiter per app, counted once api/auth.js resolved the caller and before any work (the idempotency store… (
1e6bfbb)
OpenVibe.VIP
- Per-actor rate limits on VIP's /api/v1 (roadmap WS-R task 4, openvibe-sdk v0.12.0 limits). server/api/actor-limits.js makes one limiter per app, counted once api/auth.js resolved the caller and before any work, Billing included: a service… (
0fbcbb5)
Patch notes are put together automatically when enough changes have shipped, or when a large feature lands. See every site's own updates page for the live list.
Comments
Comments could not be loaded from OpenVibe.Community right now. Reload later.