Peter Steinberger
4b7d6fa3bf
docs: align interactive client behavior ( #111047 )
2026-07-18 17:00:14 -07:00
Peter Steinberger
ec998a0f3f
feat(canvas): export widgets as PNG — copy or download from the card menu ( #110992 )
...
* feat(canvas): export widgets as PNG — copy to clipboard or download from the card menu
* fix(ui): widget-export lint, knip, and lines-budget cleanup
2026-07-19 00:39:59 +01:00
Peter Steinberger
5590d7c280
docs: align SecretRef degradation semantics ( #111021 )
2026-07-19 00:18:01 +01:00
Peter Steinberger
242093fb00
fix(ui): dark theme AA contrast for coral fills — deepen primary/destructive, add widget accent-fill token ( #110957 )
2026-07-18 21:56:24 +01:00
Peter Steinberger
81362bf643
feat(apps,ui): question surface parity and composer takeover ( #110681 )
...
* feat(apple): question parity — persistent summaries, skip, reconnect fallback, macOS keyboard
* feat(android): question parity — persistent summaries, skip, reconnect fallback
* feat(ui): question panel replaces composer while expanded
* fix(apps): regenerate question parity contracts
* fix(apps): preserve question reconciliation state
* fix(apps): keep question terminal state monotonic
* test(android): satisfy question test formatting
* fix(security): restore skill audit file reads
* fix(apps): harden question parity edge cases
* fix(apps): preserve expired question summaries
* fix(apps): keep question recovery retries current
* fix(apps): retry stale question recovery snapshots
* fix(android): reset stale question retry budgets
* docs(tools): clarify question composer takeover
* fix(apps): satisfy question recovery release gates
* fix(apps): preserve unknown question outcomes
* fix(apps): harden question action state
* fix(apps): keep unavailable questions terminal
* fix(apps): finalize local question outcomes
* fix(apps): preserve question card API
* fix(apps): reconcile external question answers
* fix(apps): reset question backoff budget
* chore(apps): refresh native i18n inventory
* fix(android): distinguish question skip progress
* fix(android): reconcile locally expired questions
* fix(apps): keep question recovery state fresh
* docs: note question surface parity
* fix(ui): reconcile IME draft before question takeover
* docs: leave question parity notes to release workflow
2026-07-18 21:42:15 +01:00
Peter Steinberger
09a64f7ab0
feat(models): make per-agent allowlists explicit ( #110888 )
2026-07-18 21:42:05 +01:00
Peter Steinberger
1cacb12c4d
feat(canvas): give show_widget a design system — theme tokens, base styles, live host theme bridge ( #110832 )
2026-07-18 21:05:16 +01:00
Peter Steinberger
9710a1339e
refactor(canvas): promote inline-widget hosting and show_widget to core ( #110475 )
...
* refactor(canvas): promote inline widgets to core
* docs(agents): note discord show_widget ownership at core registration
* ci: retrigger after GitHub scheduling outage
* fix(canvas): satisfy dead-code and test type checks
2026-07-18 14:40:45 +01:00
cxbAsDev
05fb8e6e61
fix(cli): bound --message-file reads for agent command ( #101442 )
...
* fix(cli): bound --message-file reads for agent command
* fix(cli): preserve symlinked --message-file paths with bounded reads
* fix(cli): preserve FIFO message files with bounded reads, document 4 MiB cap
* fix(cli): accept FIFO --message-file targets via bounded descriptor read
* test(cli): drop duplicate FIFO message-file read test
* docs(cli): note 4 MiB --message-file cap in agent help text
* style(commands): format agent-via-gateway test
* fix(cli): preserve procfs message-file reads
Co-authored-by: 陈宪彪0668000387 <chen.xianbiao@xydigit.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
Co-authored-by: Peter Steinberger <peter@steipete.me >
2026-07-18 12:29:33 +01:00
Peter Steinberger
9d97e10efe
refactor: move non-session runtime journals to SQLite ( #109427 )
...
* refactor: migrate runtime JSONL state to SQLite
* chore: refresh SQLite migration validation
* fix: preserve safe audit migration order
* fix: sanitize retired audit archives safely
* fix: satisfy SQLite storage architecture gates
* fix: serialize plugin doctor state migrations
* fix: bound memory event SQLite projections
* fix: rotate memory event projections safely
* fix: preserve imported event retention age
* fix: harden memory event export projection
* fix: canonicalize memory event migrations
* fix: harden legacy journal migrations
* fix: report unsafe legacy journal paths
* fix: preserve journal ownership during migration
* fix: keep legacy file imports doctor-only
* fix: align SQLite audit CI coverage
* refactor: keep state helpers module-private
* fix: harden legacy state migration recovery
* fix: reconcile SQLite state audit migration
* test: use neutral audit redaction fixtures
* fix: close SQLite migration recovery gaps
* refactor: split audit migration recovery helpers
* test: prove completed audit pads stay out of backups
* fix: preserve audit record ordinals across blank lines
* fix: align SQLite audit CI contracts
* build: package SQLite audit E2E entries
* fix: preserve audit ordinals in backup snapshots
2026-07-18 11:42:14 +01:00
Peter Steinberger
09963412d1
fix(exec): track background commands as tasks ( #110468 )
2026-07-18 08:51:23 +01:00
Peter Steinberger
d7de67ae02
feat: ask_user follow-ups — harness convergence, channel finalization + reactions, native cards, docked web panel ( #110372 )
...
* feat(ask-user): follow-up harness slice
* feat(ask-user): follow-up channels slice
* feat(ask-user): follow-up native slice
* feat(ui): dock question panel above composer with stepper and compact stream summaries
* docs: refresh follow-up integration maps
* test(ui): align terminal summary proof
* fix(infra): echo declared option answers in terminal status when free-text is allowed
* fix(infra): keep reaction answering when display labels are formatter-adjusted
* fix(agents): settle plain-text claims only after question registration commits
* fix(agents,apps): commit-ordered claim persistence, claim-aware prompt delivery, non-blocking question refresh
* fix(harness,infra): reaction-appropriate question copy, caller presentations honored
* fix(native,infra,agents): local-expiry eviction, value-addressed reactions, reserve-before-request
* fix(infra,android): dual-mode question resolver for compact callbacks; reset terminal retention on replayed pending
* fix(harness,discord): claim-aware prompt delivery in run helper; escape finalization labels
* fix(macos): merge transient-content visibility with question cards after main sync
* fix: repair ask user follow-up CI
* test: update limited bootstrap scope expectation
* fix: retain shared question card API
* chore: refresh native i18n inventory
2026-07-18 03:32:39 -04:00
Peter Steinberger
746d257f05
feat: contract sessions-family tool outputs ( #110424 )
...
* feat(agents): contract sessions-family tool outputs
* refactor(agents): remove unused fast-mode exports
2026-07-18 06:43:12 +01:00
Peter Steinberger
b9c5c7c9fc
feat(agents): contract filesystem tools for code mode ( #110395 )
2026-07-18 06:26:04 +01:00
Peter Steinberger
1c225c855d
fix: CLI timeout warnings explain stopped work ( #110369 )
...
* fix: clarify CLI timeout failures
* docs: update timeout docs map
2026-07-18 06:18:11 +01:00
Vito Cappello
cd1ab40632
fix: gateway boots when a configured plugin payload is broken ( #110239 )
...
* fix: quarantine broken plugins during gateway startup
* fix(plugins): preserve degraded boot on package read errors
* fix(gateway): emit quarantine diagnostic once
* fix(gateway): refresh plugin quarantine every boot
* fix(gateway): harden plugin payload quarantine
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com >
* fix(ci): satisfy plugin quarantine checks
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com >
---------
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-18 03:50:50 +01:00
Peter Steinberger
19296b003b
improve(agents): normalized web_search output contract with boundary-owned wrapping ( #110308 )
...
* feat: normalize web search output contract
* refactor(agents): promote web_search contract from a dedicated output module
* fix(agents): wrap unwrapped web_search text and pass unknown provider payloads through as raw
* fix(agents): gate web_search results branch on conforming rows and cover metadata fields
* fix(agents): gate every provider text path at the web_search boundary
* test(agents): align web_search fixtures with boundary-owned wrapping
* fix(agents): make the web_search boundary own the untrusted-content envelope
* fix(agents): report declared web_search errors first and align the documented contract
* fix(agents): bind envelope stripping to real markers and densify result rows
* fix(agents): emit canonical urls and a closed error code from web_search
* fix(agents): keep structured provider error diagnostics in the wrapped message
* fix(agents): satisfy production export and lint gates for the web_search contract
2026-07-18 03:39:29 +01:00
Peter Steinberger
53b53f1977
improve(agents): exact web_fetch output contract with cleaned result shape ( #110223 )
...
* feat: add web fetch output contract
* fix(agents): keep web_fetch contract schema module-local
* docs: refresh docs map for the web_fetch result section
2026-07-18 03:28:29 +01:00
Peter Steinberger
d371ea1f01
perf(agents): wave-1 tool output contracts for code mode ( #110215 )
...
* feat(agents): keep output contracts complete across opaque schema leaves
* test(agents): add code mode schema-hint hot-path micro-benchmark
* test(agents): count raw-first inspection execs per tool in live bench
* feat(agents): expand compact output contract hints
* feat(agents): declare wave one tool output contracts
* docs(tools): list built-in output contracts
* fix(agents): bound union scans before literal-union analysis
* fix(agents): keep wave-1 contract schemas module-local and type-exact
2026-07-18 01:02:18 +01:00
Peter Steinberger
ec8f6e5e03
feat(browser): add secure per-tab copilot panel ( #109817 )
...
* feat(browser): add copilot security contracts
* fix(gateway): expose verified client identity to handlers
* feat(browser): add secure per-tab copilot panel
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* refactor(browser): separate copilot gateway hint custody
* fix(browser): preserve legacy pairing parse shape
* fix(browser): harden copilot lifecycle custody
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* fix(browser): enforce copilot lifecycle boundaries
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* style(browser): format copilot sources
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* fix(browser): preserve copilot consent revocation
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* refactor(browser): split copilot custody owners
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* test(browser): normalize websocket array buffers
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* chore(protocol): regenerate Swift gateway models
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* refactor(browser): model copilot runtime entrypoints
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* fix(browser): honor extension build boundaries
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* test(gateway): assert targeted chat delivery
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* test(gateway): cover targeted delivery calls
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* fix(browser): declare copilot build dependencies
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* fix(ci): clear browser copilot gate failures
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* test(ci): cover copilot lint exclusion
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* fix(browser): gate copilot on relay custody
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
* test(browser): bound copilot relay frames
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
---------
Co-authored-by: Cameron Beeley <cameron.beeley@gmail.com >
2026-07-18 01:00:23 +01:00
Peter Steinberger
da44d52ac6
feat: ask_user — structured questions from the agent with web card, channel buttons, and text answers ( #109922 )
...
* feat(gateway): add transient question runtime (question.* methods + broadcasts)
* feat(agents): add blocking ask_user question tool with chat prompt delivery and text-reply claim
* feat(ui): interactive in-thread question cards for ask_user
* feat(channels): native tap-to-answer buttons for ask_user on Telegram, Discord, and Slack
* feat(ui): unify codex and gateway question cards with interactive gateway answering
* refactor(agents): collapse ask_user pending state to one registry; docs for ask_user
* fix(agents): include ask_user in normal gateway runs; add question-flow control-ui e2e
* test(ui): avoid credential-shaped fixture in question card test
* refactor(ui): reorder stream-group context keys
* fix(gateway,ui): validate question answers at resolve; reject secret/duplicate-label questions; UI retry and reconnect hardening
* fix(gateway,agents): canonicalize accepted option answers; bound ask_user option labels to 64 chars
* chore(ci): prune unused question exports, allowlist mobile question events, fix discord lint
* chore(ci): regenerate protocol/i18n/docs/tool-display artifacts for question surface
* fix(protocol): flatten QuestionRecord for native codegen; drop TS-only alias from schema registry
* chore(android): regenerate ask-user localization resources
* docs: regenerate docs map after rebase
* fix(ci): avoid stale read-only dependency disks
* test: remove stale reef lint suppression ratchet
* fix(ci): keep source locale drift advisory in release gates
* fix(ci): scope locale advisory handling to parity check
2026-07-17 22:24:17 +01:00
Peter Steinberger
3d1e8f9475
perf(agents): compose conversation tools in code mode ( #110098 )
2026-07-17 20:54:32 +01:00
Peter Steinberger
b319493a52
improve: let Code Mode use declared tool result shapes ( #109813 )
...
* feat(agents): add Code Mode output contracts
* perf(agents): defer untrusted tool schemas
* chore(plugin-sdk): refresh API baseline
* fix(agents): preserve deferred schema markers
* fix(agents): preserve policy-blocked tool results
* fix(agents): preserve nullable output contracts
* fix(agents): reject policy blocks from success contracts
* fix(agents): preserve output contracts through normalization
* test(agents): type normalized tool fixtures
* fix(agents): validate catalog results before projection
* fix(agents): keep result snapshots internal
* fix(agents): fail closed on unrenderable unions
* fix(agents): preserve empty result markers
* test(agents): keep result fixture discriminator literal
* test(agents): use native own-property check
2026-07-17 14:46:37 +01:00
snowzlmbot
17c2ce05d8
fix(secrets): keep startup alive when TTS SecretRefs are missing ( #101265 )
...
* fix(secrets): degrade missing TTS SecretRefs at startup
* test(secrets): keep non-activating startup strict
* test(secrets): mark denied key fixture synthetic
* test(secrets): use synthetic TTS key fixture
* test(secrets): use neutral TTS key placeholder
* test(secrets): isolate TTS key placeholder
* test(secrets): shorten TTS ref fixture name
* test(secrets): normalize synthetic credential fixtures
* test(secrets): isolate optional redaction coverage
* fix(secrets): preserve degraded TTS ref ownership
* refactor(secrets): keep optional resolver internal
* test(secrets): cover default provider alias misses
* test(secrets): pin explicit provider ownership
* style(secrets): format optional assignment imports
* refactor(secrets): keep optional metadata private
* style(secrets): restore collector file header
* fix(secrets): isolate unavailable SecretRef owners
Co-authored-by: snowzlmbot <293528334+snowzlmbot@users.noreply.github.com >
* test(secrets): complete provider fixtures
* style(status): avoid degraded path shadowing
* style(secrets): satisfy runtime lint
* refactor(secrets): keep error codes internal
* fix(secrets): keep unowned assignments fail closed
* fix(secrets): preserve provider resolution batching
* fix(secrets): normalize stalled resolution errors
* fix(secrets): reject provider limit violations
---------
Co-authored-by: snowzlmbot <293528334+snowzlmbot@users.noreply.github.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 21:07:01 -07:00
Peter Steinberger
57cc2ca308
improve: reduce compact tool orchestration turns ( #109596 )
...
* perf(agents): streamline compact tool orchestration
* fix(agents): preserve compact schema narrowing
* refactor(agents): focus legacy tool-search guidance
* fix(agents): defer MCP compact schema hints
* chore: drop release-owned changelog edit
2026-07-16 20:53:42 -07:00
Peter Steinberger
28a3540f32
feat: add native inline widget support ( #109212 )
...
* feat: add native inline widget support
* refactor: simplify plugin surface refresh
* fix: preserve plugin surface refresh API
* fix: reload widgets after WebKit termination
* fix: harden native widget refresh
* fix: bound native widget recovery
* docs: defer native widget release note
* chore: refresh native i18n inventory
* fix: harden native widget delivery
* refactor: simplify native widget API surface
* fix: serialize native widget capability refresh
* fix: harden native widget recovery
* fix: recover native widget capabilities
* style: format widget refresh role selection
* fix: correct widget refresh formatting
* fix: harden cross-platform widget recovery
* fix: bind widget trust and recovery to routes
* chore: refresh native i18n inventory
* chore: regenerate Android gateway protocol
* test: remove unused release workflow read
2026-07-16 19:24:41 -07:00
Peter Steinberger
349f78776d
fix(models): refresh bundled provider catalogs ( #109410 )
...
* fix(models): refresh bundled provider catalogs
* docs(models): refresh generated docs map
* fix(xiaomi): keep provider helper private
* chore(release): defer catalog release note
2026-07-16 16:47:25 -07:00
Peter Steinberger
334c182c27
refactor(diffs): move ephemeral artifacts to SQLite ( #109328 )
...
* refactor(diffs): move ephemeral artifacts to SQLite
* fix(plugin-state): satisfy SDK validation gates
* test(diffs): satisfy lint contracts
* fix(plugin-state): count expired blobs toward quotas
* fix(plugin-state): harden blob storage boundaries
* fix(plugins): replace stale install provenance
2026-07-16 16:47:19 -07:00
Peter Steinberger
2409df768c
fix(kimi): honor K3 thinking off ( #109335 )
...
* fix(kimi): honor K3 thinking off
* chore: defer Kimi release note
* test(kimi): narrow live reasoning blocks
2026-07-16 13:50:15 -07:00
NianJiu
42ff5ec754
feat(kimi): add Kimi K3 support ( #109202 )
...
* feat(moonshot): add Kimi K3 support
* feat(kimi): add K3 subscription models
---------
Co-authored-by: NianJiuZst <180004567+NianJiuZst@users.noreply.github.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 11:41:12 -07:00
Peter Steinberger
20d748a4f0
feat(agents): agent-owned gateway terminals with operator co-attach
2026-07-16 09:12:50 -07:00
Peter Steinberger
8fe4eeea9e
fix(exec): stop isolated state dirs from moving live approvals ( #108742 )
...
* fix(exec): isolate approval state directories
* chore: drop release-owned changelog entry
* chore: refresh native i18n inventory
* fix(ci): pin XcodeGen for Periphery scans
2026-07-16 08:57:32 -07:00
Peter Steinberger
16d1f487fe
feat(widgets): unify show_widget across surfaces ( #108983 )
...
* feat(widgets): unify show_widget across surfaces
* docs(canvas): keep lazy show_widget descriptor in sync with the loaded tool
2026-07-16 05:24:11 -07:00
Shubhankar Tripathy
67fdd2596f
docs(lobster): enumerate injected workflow env vars and clarify step-output access ( #108622 )
...
* docs(lobster): enumerate injected workflow env vars and clarify step-output access (#82281 )
* docs(lobster): refresh workflow environment docs map
Clarify how shells handle nonexistent step-output variables and regenerate the generated docs map for the new section.
Co-authored-by: Shubhankar Tripathy <reach2shubhankar@gmail.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 05:05:21 -07:00
Peter Steinberger
2d9584ccda
feat(canvas): interactive widgets can send follow-up prompts in web chat ( #108889 )
...
* feat(canvas): let widget buttons send prompts into web chat
Inline show_widget documents get a sendPrompt(text) bridge: a private
MessageChannel offered to the Control UI before widget code runs. The chat
adopts only the first offer per frame, requires transient user activation,
a visible focused frame, plain text (no slash commands), and rate limits
10 prompts/minute per widget. Accepted prompts run the normal user send
path of the owning chat pane.
* fix(canvas): appease lint/knip/docs gates for widget prompts
Split widget prompt tests into their own file, drive validation and rate
limits through the real port path instead of exported internals, use
addEventListener on the adopted port, and regenerate docs_map.
* fix(canvas): install widget listeners per window for non-isolated tests
Module-boolean listener flags broke in shared vitest workers where each test
file gets a fresh jsdom window; key installation by window instead and give
port flushing more headroom.
2026-07-16 04:52:26 -07:00
Shubhankar Tripathy
6390edec25
fix(memory-lancedb): prevent cross-agent memory leakage ( #103799 )
...
* fix(memory-lancedb): gate auto-recall and auto-capture on per-agent memorySearch.enabled (#103590 )
The before_prompt_build auto-recall hook only checked the plugin-level
autoRecall flag, so agents configured with memorySearch.enabled: false
still received <relevant-memories> injected from the shared LanceDB store
- leaking one agent's private memories into another agent's prompts. Gate
both recall injection and agent_end auto-capture on the current agent's
memorySearch.enabled (per-agent entry wins over agents.defaults; unset
means enabled), mirroring core resolveMemorySearchConfig semantics.
* fix(memory-lancedb): normalize agent ids before the memorySearch gate
Review follow-up on #103799 : a configured id like 'XiaoHuo' or one with
surrounding whitespace missed the exact-match per-agent override and
inherited the enabled default, leaving the disclosure path active.
Normalize both the hook agent id and configured entry ids with the SDK
normalizeAgentId before comparing.
* fix(memory-lancedb): resolve the per-agent memorySearch gate via resolveAgentConfig
* fix(memory): isolate LanceDB rows by agent
Co-authored-by: Shubhankar Tripathy <reach2shubhankar@gmail.com >
* fix(memory): isolate LanceDB rows by agent
Co-authored-by: Shubhankar Tripathy <reach2shubhankar@gmail.com >
* refactor(memory): keep LanceDB store types private
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 03:33:08 -07:00
Peter Steinberger
2488d794ca
feat(ui): expand child sessions in sidebar ( #108838 )
...
* feat(ui): expand child sessions in sidebar
* test(ui): type child session list options
* refactor(ui): split child session data helpers
* fix(ui): preserve session link semantics
* fix(ui): retry incomplete child session loads
* chore: keep release changelog owner-only
2026-07-16 03:26:49 -07:00
Peter Steinberger
a97bdfb687
feat(agents): narrow gateway tool to read-only config
...
Phase 3 of #107237 . Removes config.apply/config.patch/restart from the
regular-agent gateway tool (mirroring Phase 2's update.run removal); only
config.get and config.schema.lookup reads remain. Persistent config changes
and restarts now go exclusively through the human-approved openclaw
delegation path — closing the last unmediated agent config-write surface.
gateway stays owner-only/control-plane gated (config reads expose secrets and
host topology). Legacy setups can re-enable writes via the existing per-agent
tool allowlist; no new config key. Net -2271 LOC.
Refs #107237
2026-07-15 01:56:31 -07:00
Peter Steinberger
a6a0716486
feat(setup): rename Crestodian to OpenClaw system agent
...
User-facing name is now OpenClaw (the system speaks); internal code name is
system-agent. Gateway methods crestodian.* -> openclaw.chat/openclaw.setup.*,
agent tool -> openclaw, reserved agent ids openclaw + retired crestodian.
openclaw setup routes: onboarding flags -> onboard, -m/--yes -> system agent,
bare configured interactive -> OpenClaw chat, unconfigured -> onboarding.
Hidden crestodian CLI and /crestodian TUI aliases kept; docs moved to
docs/cli/openclaw.md with redirect stub. macOS/Android strings in lockstep.
Refs #107237
2026-07-14 11:03:02 -07:00
Shakker
3976ec47d3
fix: default skill workshop approvals to auto ( #107690 )
...
Skill Workshop lifecycle actions now run without an additional Gateway approval by default, while explicit `approvalPolicy: "pending"` keeps the operator approval gate.
Prepared head SHA: 06e907797e
Co-authored-by: Shakker <165377636+shakkernerd@users.noreply.github.com >
Reviewed-by: @shakkernerd
2026-07-14 18:31:51 +01:00
Jesse Merhi
00364ee777
improve: warn before non-ClawHub plugin installs ( #102197 )
...
Merged via squash.
Prepared head SHA: e08d9e737d
Co-authored-by: jesse-merhi <79823012+jesse-merhi@users.noreply.github.com >
Co-authored-by: jesse-merhi <79823012+jesse-merhi@users.noreply.github.com >
Reviewed-by: @jesse-merhi
2026-07-15 03:25:36 +10:00
VACInc
6f0326af36
fix: prevent session exports from writing outside workspace ( #104708 )
...
* fix: prevent session exports outside workspace
* fix: support aliased workspace export paths
---------
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-14 09:20:43 -07:00
Peter Steinberger
cf8b57e7d0
feat(skills): scan session history for workshop ideas ( #106766 )
...
* feat: scan past sessions for skill proposals
* feat(ui): add progressive skill history scans
* fix(ui): keep skill history scans synchronized
* refactor: split skill history scan ownership
* style: fix mock helper formatting
* style: format skill history scan
* build: refresh skill history schema baselines
* build: refresh plugin SDK baseline after rebase
* perf(ui): keep startup request budget bounded
* fix(skills): satisfy history scan integration gates
* fix(ui): bound control ui startup chunks
* build: refresh plugin SDK API baseline
* build(ui): refresh self-learning translation memory
* refactor(ui): split skill workshop state
* fix(ci): refresh skill workshop gates
* fix(ci): satisfy skill history lint
* build: refresh plugin SDK baseline after main rebase
2026-07-13 16:15:50 -07:00
Peter Steinberger
2198591d0f
fix(ui): self-learning works after concurrent config changes ( #106764 )
...
* fix(ui): retry stale self-learning config updates
* chore: keep release notes out of the PR
2026-07-13 14:27:29 -07:00
Vitor Cepeda Lopes
93b3f4c45b
feat(xai): add native streaming TTS ( #103993 )
...
* feat(xai): add streaming TTS via wss://api.x.ai/v1/tts
Expose streamSynthesize on the bundled xAI speech provider so Talk and
Discord streaming playback can use xAI alongside batch REST synthesis.
Adds ws runtime dependency, byte-cap enforcement, and provider tests.
* fix(xai): harden streaming TTS per review feedback
Restrict streaming WS to api.x.ai, decode WebSocket payloads explicitly,
refresh idle timeout on audio.delta, add lifecycle/security tests, and
document the official xAI streaming contract plus non-realtime-voice scope.
* fix(xai): bound streaming TTS text deltas
* fix(xai): require secure native TTS streaming endpoint
* docs(tts): remove duplicate output formats section
* fix(xai): preserve surrogate pairs in tts frames
* fix(xai): bound streaming TTS websocket payloads
* fix(xai): align TTS websocket decoding with ws types
* fix(xai): pin native streaming TTS endpoint
* test(xai): cover native streaming TTS live path
* fix(xai): preserve streaming codec compatibility
* style(xai): format streaming endpoint guard
* docs(tts): describe xAI streaming output policy [skip ci]
* fix(xai): own voice-note TTS format policy [skip ci]
* docs(tts): keep provider summary concise [skip ci]
* test(xai): use explicit placeholder credentials [skip ci]
* test(xai): keep fixtures scanner-safe [skip ci]
---------
Co-authored-by: TheAngryPit <16145902+TheAngryPit@users.noreply.github.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-13 06:08:28 -07:00
Peter Steinberger
d3f6d63fec
feat(ui): surface self-learning toggle in the Skill Workshop tab ( #106093 )
...
Surfaces skills.workshop.autonomous.enabled in the Control UI Workshop tab:
a Self-learning header toggle plus an enable pitch card on the empty
proposal board. Reads the include-resolved config snapshot, patches the
canonical key over the existing runtimeConfig RFC 7396 merge-patch seam,
and surfaces patch failures in the workshop error banner. Copy states the
token cost and that drafts arrive as pending proposals (no unconditional
review guarantee, which would be false under approvalPolicy "auto").
Splits workshop empty states, header controls, and the self-learning
module out of the oversized page/view files. Locale bundles synced
(fallbacks=0 across 20 locales).
Closes #106054
2026-07-13 00:54:14 -07:00
Peter Steinberger
32c84b0f41
feat(skills): capture reusable techniques from successful work ( #105674 )
...
* feat(skills): capture reusable experience safely
* feat(skills): review completed work for reusable learning
* docs(skills): explain self-learning
* docs: clarify self-learning runtime scope
* fix(skills): harden autonomous workshop reviews
* test(skills): align review prompt fixture
2026-07-13 00:22:06 -07:00
Vincent Koc
f33ab243cf
fix(sqlite): reject runtimes vulnerable to WAL corruption ( #106065 )
...
* fix(sqlite): require WAL-reset-safe Node runtime
* docs(sqlite): document safe Node runtime floor
* fix(sqlite): defer runtime library validation until use
* fix(ci): align startup memory with Node 24.15
2026-07-13 13:59:00 +08:00
Developers Digest
8809848b19
feat(firecrawl): add keyless Firecrawl Search (Free) provider + richer firecrawl_search options ( #97078 )
...
* feat(firecrawl): add keyless Firecrawl Search (Free) provider + richer firecrawl_search options
Add an opt-in, keyless 'firecrawl-free' web_search provider (Firecrawl
Search (Free)) mirroring the Parallel plugin's parallel-free pattern:
requiresCredential false, no autoDetectOrder, never auto-selected. The
free path is credential-isolated — it never resolves or sends any
Firecrawl API key (no Authorization header), so opting out of credentials
cannot leak a configured/paid key — and its results and cache key carry a
distinct 'firecrawl-free' provider identity. The keyed 'firecrawl'
provider and core search auto-select behavior are unchanged, honoring the
maintainers' opt-in policy for keyless search.
Registered in index.ts, the web-search-provider barrel, the
web-search-contract-api metadata artifact (the onboarding/setup source),
manifest contracts, the official external plugin catalog snapshot, and
the doctor/contract registries.
Also extend the firecrawl_search tool to /v2/search parity:
includeDomains/excludeDomains (mutually exclusive), tbs, location,
country, and raise the result cap to 100.
* docs: regenerate docs_map for firecrawl heading rename
---------
Co-authored-by: developersdigest <jonathan@sideguide.dev >
2026-07-12 21:04:43 -07:00
Peter Steinberger
18eb472f82
fix(gradium): restrict TTS credential egress ( #105169 )
...
* fix(gradium): restrict TTS base URL before sending API keys
* fix(gradium): pin credential egress hostname
* docs(changelog): note Gradium credential guard
* docs(changelog): note Gradium credential guard
---------
Co-authored-by: 张贵萍0668001030 <zhang.guiping@xydigit.com >
2026-07-12 09:43:22 +01:00