Peter Steinberger
9f13f9b140
feat(openai): make million-token context an explicit opt-in ( #112916 )
...
* feat(openai): add safe long-context opt-in
* fix(ci): keep long-context checks within gates
* fix(ci): keep Codex usage helpers internal
2026-07-23 05:34:54 -04:00
Peter Steinberger
a229456f48
feat(agents): relay Claude native tool requests as Gateway approvals ( #112918 )
...
* feat(agents): relay Claude native tool requests as Gateway approvals
* fix(agents): keep approval relay types local and refresh docs map
2026-07-23 03:21:08 -04:00
Peter Steinberger
099d6351b3
refactor(sessions): canonical lineage model — creation provenance, fork ancestry, generation chain, typed row contract ( #111861 )
...
* fix(sessions): preserve spawn/fork lineage across implicit daily/idle rollover
* refactor(sessions): canonical creation model with forkSource ancestry and generation chain
* feat(sessions): stamp creation provenance across all creation paths and emit created events
* refactor(gateway): lock lineage patching, split control from navigation, add typed session-row contract
* docs(gateway): document creation provenance stamping and lineage patch tightening
* fix(sessions): keep provenance proof-only on wire fallbacks and strip node-local lineage from cron continuations
* fix(gateway): never journal a created event for session adoption
* fix(gateway): keep post-create work on adoption while gating the created event
* fix(sessions): restore trusted ensure-main provenance and stamp navigation parent at spawn
* fix(sessions): allow parentSessionKey through the direct child spawn patch
* fix(ci): break type cycles, satisfy export scan, regenerate Swift protocol models
* refactor(sessions): replace createdBy with createdActor
* fix(protocol): export session row type
* fix(sessions): preserve proven creation provenance
* fix(sessions): close lineage creation gaps
* test(sessions): align atomic spawn lineage coverage
* test(sessions): widen transcript search reconcile wait
* fix(sessions): stamp reset-created rows
* test(sessions): keep reset provenance coverage focused
* fix(sessions): journal chat-created rows
* test(ci): anchor release skill reads to repo
* test(ci): avoid cached module paths
2026-07-22 22:54:31 -04:00
Jason (Json)
7eec1345f9
fix(gateway): preserve Control UI access across device-auth upgrades ( #112558 )
...
* fix(gateway): preserve device auth upgrade recovery
* fix(gateway): satisfy device auth upgrade gates
* fix(doctor): clean disabled device auth bypass
* fix(gateway): recheck migration operator boundary
* fix(gateway): keep migration guard internal
* fix(gateway): preserve insecure migration access
* fix(gateway): reject stale migration handshakes
* fix(gateway): revoke legacy migration sessions
* fix(gateway): bound device-less migration authority
* fix(gateway): require explicit migration pairing
* fix(gateway): revoke alternate migration sessions
* fix(gateway): close migration admission races
* style(gateway): format migration pairing import
* fix(security): audit pending device-auth migration
* fix(gateway): reconcile migration on startup
* fix(gateway): cap device auth migration scopes
* fix(gateway): retain migration socket restrictions
* perf(ui): trim migration startup bundle
* perf(ui): lazy-load device auth migration
* fix(gateway): bind migration completion to approved key
* fix(gateway): preserve migration authorization bounds
* fix(gateway): grant migrated device pairing capability
* fix(ui): preserve device migration bundle budget
* fix(ui): stabilize migration startup budget
* chore(ui): retain startup budget headroom
* fix(ui): split migration overlay helpers
2026-07-22 18:44:48 -06:00
Peter Steinberger
f5562748de
fix(logging): give non-default profiles their own gateway log file ( #112777 )
...
* fix(logging): give non-default profiles their own gateway log file
* chore: defer profile log release note
2026-07-22 19:08:41 -04:00
Peter Steinberger
4e9ae9fbff
feat(cron): system-owned heartbeat monitor jobs replace the dedicated interval scheduler ( #112585 )
...
* feat(cron): system-owned heartbeat monitor jobs replace the interval scheduler
- new internal cron payload kind {kind:"heartbeat"}: execution pokes
requestHeartbeat({source:"interval"}); reported in the protocol job
schema, not accepted from client create/patch
- gateway converges one declaration-keyed monitor job per heartbeat-enabled
agent (schedule every+deterministic phase anchor) at startup and on
config reload; removes monitors for unconfigured agents
- heartbeat runner loses its interval setTimeout machinery; nextDueMs
stays as the cooldown gate, event wakes unchanged
* test(cron): heartbeat monitor regressions; docs for cron-owned cadence
- converge/prune/failure-containment tests for heartbeat monitor jobs
- heartbeat payload run fires an interval wake, no system event
- scheduler tests converted from timer self-fire to wake-queue pokes;
timer-mechanics-only tests deleted with the timer
- persisted-shape accepts the heartbeat payload kind
- docs: heartbeat cadence ownership + system payload kind
* fix(cron): heartbeat monitor review round 1
- targeted cron-monitor interval ticks use the full per-agent path so
due-commitment sessions still deliver
- cron-disabled gateways keep a local fallback interval timer (shipped
cron.enabled=false contract; removed when heartbeat config folds into
cron in #110950 )
- heartbeat job reconciliations serialize with latest-wins epochs and a
bounded 30s retry after a failed convergence pass
* fix(cron): chain clamped fallback heartbeat timers past the setTimeout cap
* fix(cron): heartbeat monitor review round 3
- targeted monitor redirect skips wakes carrying heartbeat overrides and
surfaces the per-agent terminal skip reason instead of not-due
- cron-disabled fallback timer re-arms with a 1s floor after each firing
so a dropped wake cannot end the chain
- heartbeat payloads are system-owned at the service boundary: add requires
the gateway opt-in, patches to the kind are rejected
* fix(cron): heartbeat monitor review round 4 — full ownership enforcement
- prune only jobs proven to be monitors (prefix AND heartbeat payload)
- existing monitors reject every update patch; declarative upserts on the
monitor key require the gateway opt-in even with a different payload
* fix(cron): complete heartbeat monitor ownership boundary
- converge scopes declarative matching to real monitors so a colliding
user job with the same key is never adopted or overwritten
- monitor removal requires the gateway systemOwned opt-in; ad-hoc
API/CLI deletion is rejected, reconciliation cleanup still prunes
* docs(cron): record intentional enrollment-snapshot semantics for monitor ticks
* fix(cron): repair heartbeat monitor CI gates
2026-07-22 14:03:29 -07:00
Peter Steinberger
88875ab7d9
refactor(channels): remove retired ack cleanup branches ( #112635 )
2026-07-22 03:54:28 -07:00
Peter Steinberger
62a6dfb082
fix(macos): direct Gateway TLS pins protect operator traffic ( #112353 )
...
* fix(macos): enforce direct Gateway TLS pins
* fix(macos): preserve existing TLS pin owner keys
* fix(macos): reuse localized TLS error labels
* test(macos): avoid nested Swift Testing require
* test(macos): isolate TLS Keychain tests
* test(macos): isolate TLS integration Keychain
* chore(i18n): update native source inventory
2026-07-22 03:38:10 -07:00
Peter Steinberger
5808b72ed6
refactor(models): own compat in provider catalogs ( #112542 )
2026-07-22 02:14:29 -07:00
Peter Steinberger
3c4a1ec905
refactor(agents): move CLI backend adapters from config DSL to registerCliBackend plugins (review request) ( #112539 )
...
* refactor(agents): move CLI backend adapters into plugins
* test(agents): register CLI backend fixtures through plugins
2026-07-22 00:25:29 -07:00
Peter Steinberger
e01f3e18a7
feat(config): tier settings as common and advanced ( #112538 )
2026-07-21 23:17:47 -07:00
Jason (Json)
1a42e005fb
fix(anthropic): forward selected profiles to Claude CLI ( #112458 )
...
* fix(anthropic): forward Claude CLI auth profiles
* fix(system-agent): inject CLI auth route stores
* fix(claude-cli): pass profile credentials by descriptor
* fix(anthropic): repair selected profile CI coverage
* fix(anthropic): preserve profile owner validation
* test(system-agent): preserve selected profile fixtures
* test(system-agent): narrow selected profile fixture
* test(system-agent): resolve profile store merge
* fix(anthropic): forward profiles to node Claude runs
* fix(system-agent): reconcile profile route projection
* test(system-agent): thread profile store through projection
* fix(anthropic): make selected profile authoritative
* fix(system-agent): type auth setup failures
* fix(system-agent): type setup auth failures
* style: format Claude profile maintenance
* fix(anthropic): keep gateway credentials off nodes
* fix(anthropic): clear ambient auth for selected profiles
* fix(anthropic): secure paired-node Claude auth
* fix(node-host): type Claude fd spawn streams
* style(node-host): satisfy Claude spawn lint
* fix(process): capture exit before secret delivery
* fix(anthropic): preserve node-native Claude auth
2026-07-21 23:27:37 -06:00
Peter Steinberger
edecdbd05e
refactor(config): config-surface reduction tranche 3 — product consolidations (review request) ( #111527 )
...
* refactor(config): consolidate media model lists
* refactor(config): unify memory configuration
* refactor(config): consolidate TTS ownership
* refactor(config): move typing policy to agents
* refactor(config): retire product-level config surfaces
* refactor(config): share scoped tool policy type
* chore(config): refresh generated baselines
* fix(config): honor agent typing overrides
* fix(config): migrate sibling config consumers
* refactor(infra): keep base64url decoder private
* fix(config): strip invalid legacy TTS values
* chore(config): refresh rebased baseline hash
* fix(doctor): route legacy messages.tts.realtime voice to talk during tts move
* refactor(config): polish final layout names
* refactor(config): freeze retired tuning defaults
* feat(config): add fast mode default symmetry
* refactor(config): key agent entries by id
* docs(config): update final layout reference
* test(config): cover final layout migrations
* chore(config): refresh final layout baselines
* fix(config): align final layout runtime readers
* fix(config): align remaining readers
* fix(config): stabilize final layout migrations
* fix(config): finalize config projection proof
* fix(config): address final layout review
* docs(release): preserve historical config names
* fix(config): complete keyed agent migration
* fix(config): close final migration gaps
* fix(config): finish full-branch review
* fix(config): complete runtime secret detection
* fix(config): close final review findings
* fix(config): finish canonical docs and heartbeat migration
* fix(config): integrate latest main after rebase
* refactor(env): isolate test-only controls
* refactor(env): isolate build and development controls
* refactor(env): collapse process identity indirection
* refactor(env): remove duplicate config and temp aliases
* docs(env): define the operator-facing allowlist
* ci(env): ratchet production variable count
* fix(env): remove stale provider helper import
* fix(env): make ratchet sorting explicit
* test(env): keep test seam in dead-code audit
* test(env): cover ratchet growth and boundary; document surface budgets
* docs(config): document tier-eval consolidations
* docs(config): clarify speech preference ownership
* test(memory): align retired tuning fixtures
* refactor(memory): freeze engine heuristics
* refactor(config): apply tier-eval tranche
* refactor(tts): move persona shaping to providers
* refactor(compaction): move prompt policy to providers
* test(config): align hookified prompt fixtures
* chore(deadcode): classify test-only exports
* chore(github): remove unused spawn helper
* chore(deadcode): classify queue diagnostics
* chore(deadcode): remove unused lane snapshot export
* chore(plugin-sdk): ratchet consolidated surface
* fix(config): integrate latest main after rebase
2026-07-21 20:28:43 -07:00
Jason (Json)
24c20eec76
fix(agents): enforce Claude CLI cron tool policies ( #112457 )
...
* fix(agents): enforce Claude CLI tool policies
* fix(agents): bound CLI runtime tool grants
* fix(agents): isolate restricted Claude runs
2026-07-21 19:38:21 -06:00
Peter Steinberger
c84921634d
fix(macos): require explicit consent for privacy-sensitive access ( #112321 )
...
* fix(macos): avoid passive Automation prompts
* fix(macos): keep Voice Wake recognition on device
* fix(macos): require consent for activity presence
* chore(apps): refresh native i18n inventory
* fix(macos): preserve presence clears across gateway versions
* fix(macos): prioritize activity privacy opt-out
* chore(apps): refresh native i18n inventory
* fix(macos): scrub legacy presence activity
* fix(macos): migrate permission status caller
* fix(macos): preserve unknown permission state
* fix(macos): refresh privacy change artifacts
* refactor(macos): remove stale presence helper
* fix(deps): patch URI and Jaeger advisories
* test(gateway): adopt pairing-bound node sessions
2026-07-21 15:28:13 -07:00
Harjoth Khara
13348cad1a
fix(doctor): migrate MCP flags in included config ( #103970 )
...
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-21 10:06:19 -07:00
Peter Steinberger
64607ba63d
feat: show cloud workspace conflicts in the Control UI ( #111329 )
...
* feat(ui): surface cloud workspace conflicts with staged-ref guidance
* fix(ui): satisfy workspace conflict CI checks
* fix(ui): reject terminal controls in conflict paths
* chore: keep release notes out of the PR
* fix(ui): satisfy conflict path lint
* fix(ui): retain cloud conflicts after reclaim
* fix(ui): keep child conflict badges visible
* test(ui): cover cloud conflict recovery in browser
* fix(ci): rotate poisoned dependency snapshot
* fix(ui): keep nested cloud conflicts discoverable
* docs(changelog): note cloud conflict UI
* fix(ui): restore conflict UI budget headroom
2026-07-20 19:27:19 -07:00
Peter Steinberger
49ff6a4497
fix(protocol): classify system agents in rosters ( #111920 )
...
* fix(protocol): classify system agents in rosters
* fix(ci): align agent kind client gates
* fix(ci): keep roster filtering in startup bundle
* chore(ui): remove superseded roster module
* style(android): satisfy agent kind test formatting
* style(linux): format merged agent capability assertion
* fix(config): reject reserved system agent ids
* chore(i18n): refresh native source inventory
* style(android): format agent kind surfaces
* fix(gateway): preserve configured agent ownership
2026-07-20 16:57:04 -07:00
Peter Steinberger
473f2aca33
fix(gateway): honor session title model routing ( #111757 )
...
Route automatic dashboard titles through the effective session model and auth profile while preserving explicit cross-provider utility ownership and the existing generic title fallback.
2026-07-20 02:19:57 -07:00
Peter Steinberger
9056c43368
docs(gateway): add client-building and embedding guides ( #111726 )
...
* docs(gateway): add client-building and embedding guides
* docs(gateway): harden package rollout guidance
2026-07-20 02:12:52 -07:00
Peter Steinberger
fd081d6521
fix(ui): keep Codex commentary visible after runs ( #111648 )
...
* fix(ui): keep Codex commentary visible
* fix(codex): preserve commentary transcript ordering
* fix(ui): preserve commentary retention opt-out
2026-07-20 02:10:56 -07:00
Peter Steinberger
200653bd60
fix(gateway): generate dashboard titles despite sender metadata ( #111613 )
...
* fix(gateway): keep sender identity out of session titles
* docs(changelog): note dashboard session title fix
* test(gateway): type dashboard sender fixture
* docs: keep session title release note in PR
2026-07-19 20:26:28 -07:00
Peter Steinberger
31e52dc5c5
feat(gateway): allow explicit operator.admin in device auto-approval with critical audit finding ( #111509 )
2026-07-19 12:05:04 -07:00
Peter Steinberger
c7e7ac2728
refactor: remove expired plugin compatibility surfaces ( #111451 )
...
* docs(secrets): remove retired web credential paths
* refactor(web): remove retired provider compatibility paths
* refactor(providers): delete retired compatibility routes
* refactor(secrets): remove retired credential aliases
* refactor(plugin-sdk): delete retired compatibility surfaces
* docs(plugin-sdk): remove retired migration guidance
* chore(plugin-sdk): refresh rebased surface budgets
* chore(plugin-sdk): refresh API removal baseline
* refactor(compat): migrate retired internal callers
* chore(plugin-sdk): refresh current-main baselines
* test(config): migrate plugin-owned secret assertions
* test(gateway): narrow plugin secret refs
* fix(plugin-sdk): preserve private boundary type identity
* chore(compat): remove stale sweep references
* chore(lint): lower max-lines budget
* refactor(secrets): remove unused web helper
* build(plugin-sdk): drop removed compat entries
* chore(plugin-sdk): refresh rebased API baseline
* chore(plugin-sdk): use Linux API baseline hash
* fix(plugin-sdk): preserve private bundled build entries
* fix(plugin-sdk): package private runtime facades
* fix(plugins): preserve external credential contracts
2026-07-19 11:04:48 -07:00
Peter Steinberger
783a5d21cf
refactor(config): purge numeric tuning knobs behind built-in defaults ( #111382 )
2026-07-19 07:35:45 -07:00
Peter Steinberger
ccea4ea440
fix(models): support nested policy wildcards ( #111350 )
2026-07-19 06:47:42 -07:00
Peter Steinberger
0f95e66b7f
feat(talk): add durable client voice sessions ( #111216 )
...
Live-append voice transcripts into the agent session and persist a per-agent SQLite call record across relay and client transcript paths.
Add run-scoped spoken confirmation for high-impact actions, mutation digests, bootstrap-context injection, talk.client.transcript and talk.client.close protocol methods, and Control UI adoption. This adds zero new configuration.
Co-authored-by: Clifton King <clifton@users.noreply.github.com >
2026-07-19 01:06:49 -07:00
Peter Steinberger
58452de711
refactor(config): config-surface reduction tranche 1 — retire dead keys, dedupe channel schemas, add growth ratchet ( #111142 )
...
* refactor(config): retire dead and aliased config keys via doctor migrations
* refactor(config): dedupe bundled channel config schemas into shared builders
* feat(config): add config-surface count ratchet to doc-baseline check
* test(config): drop stale fixtures for retired config keys
* fix(doctor): migrate only positive finite MCP timeout aliases
* fix(migrate-hermes): emit canonical MCP timeouts only
* fix(config): satisfy lint and contract gates
2026-07-19 00:52:37 -07:00
Peter Steinberger
30e2129ace
docs(gateway): document x-openclaw-scopes cap on trusted-proxy device auto-approval ( #111228 )
2026-07-18 22:35:32 -07:00
FMLS
4074e0cae1
fix(browser): close tracked tabs after gateway restart ( #110797 )
...
* fix(browser): preserve tab cleanup across restarts
* fix(browser): disambiguate restart tab aliases
* fix(browser): keep untrack selection type private
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-18 22:24:20 -07:00
Peter Steinberger
e23dde3de5
feat: disable automatic session resets by default ( #111140 )
...
* feat(config): disable automatic session resets by default
* fix(sessions): honor pending reset tombstones
* test(sessions): align reset coverage with disabled default
* fix(sessions): preserve explicit reset override fallback
* fix(sessions): inherit active mode in partial type resets
2026-07-18 21:50:48 -07:00
Peter Steinberger
5e51c4bbcc
feat(gateway): auto-approve trusted-proxy browser device pairing ( #111189 )
...
* feat(gateway): auto-approve trusted-proxy browser device pairing
Adds gateway.auth.trustedProxy.deviceAutoApprove so team gateways behind an
identity-aware proxy (Cloudflare Access, oauth2-proxy, Pomerium) can skip the
manual `openclaw devices approve` step for new Control UI/WebChat devices.
Auto-approval fires only for a new (unpaired) operator browser device on a
connection that already passed trusted-proxy auth with a resolved allowUsers
user. Scope upgrades on existing devices and node pairing stay manual. Granted
scopes are capped to the configured set intersected with the connection's
x-openclaw-scopes proxy cap, operator.admin is rejected at config validation,
and the pairing-store approval rechecks new-device status under the store lock
so a repair/upgrade or concurrent approval can never be silently widened. Each
auto-approval emits an audit log line with the proxy user and granted scopes,
and `openclaw security audit` warns when the mode is enabled.
* docs: regenerate docs map for trusted-proxy auto-approval section
2026-07-18 21:23:55 -07:00
Peter Steinberger
d96a87e8e9
docs: document session automation contracts ( #111095 )
2026-07-18 18:10:14 -07:00
Peter Steinberger
62c5a8b888
fix(gateway): make scope errors machine-readable across clients ( #111013 )
...
* fix(gateway): consume structured scope errors
* docs(gateway): clarify tools error boundary
* refactor(gateway): unify node admin policy
2026-07-18 17:53:45 -07:00
Peter Steinberger
fdf44edf4d
docs: document channel ingress guarantees ( #111069 )
2026-07-18 17:26:41 -07:00
Kris Wu
e5b2ca3c6b
feat(config): add compaction.thinkingLevel to override thinking level during compaction ( #98074 )
...
* feat(config): add compaction.thinkingLevel to override thinking during compaction
* fix: make compaction.thinkingLevel override inherited session thinking
* fix: warn on compaction.thinkingLevel ignored by Codex native runtime
* feat(config): add compaction thinking override
Co-authored-by: wu.duozhen@xydigit.com <wu.duozhen@xydigit.com >
* test(agents): remove duplicate compaction harness
Co-authored-by: wu.duozhen@xydigit.com <wu.duozhen@xydigit.com >
* test(plugin-sdk): account for thinking level export
Co-authored-by: wu.duozhen@xydigit.com <wu.duozhen@xydigit.com >
* chore: keep release note in PR metadata
* chore: reconcile plugin SDK surface budgets
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-18 17:18:28 -07:00
Peter Steinberger
4b7d6fa3bf
docs: align interactive client behavior ( #111047 )
2026-07-18 17:00:14 -07:00
Peter Steinberger
9275837f41
docs: explain managed Gateway heap sizing ( #111027 )
2026-07-19 00:36:03 +01:00
Peter Steinberger
5590d7c280
docs: align SecretRef degradation semantics ( #111021 )
2026-07-19 00:18:01 +01:00
Peter Steinberger
a5ec26fa3c
fix: prevent LINE channel reloads from hanging on stalled deliveries ( #110971 )
...
* fix(channels): bound ingress shutdown and document retention
* docs(channels): note ingress shutdown behavior
* chore: keep release notes in pull request
* docs: refresh documentation map
* fix(line): preserve deferred claims during shutdown
* fix(line): handle late abandonment failures
2026-07-18 23:25:33 +01:00
Peter Steinberger
4d683904df
fix(agents): restore ask_user roundtrip in Gateway chats ( #110961 )
...
* fix(agents): restore ask_user channel roundtrip
* test(qa): derive ask_user proof from answers
* test(qa): isolate mock reply directives
* test(qa): wait for complete ask_user reply
* fix(agents): fail closed on stale ask_user prompts
* chore: remove release-owned changelog entry
* fix(agents): satisfy ask_user CI contracts
2026-07-18 22:55:46 +01:00
Peter Steinberger
7a551bff0c
fix(vault): aggregate provider outage diagnostics ( #110908 )
...
* fix(vault): aggregate provider outage diagnostics
* fix(vault): classify revoked token outages
* fix(vault): preserve scoped ACL failures
* fix(vault): keep token probes advisory
* test(vault): satisfy gateway proof gates
* fix(secrets): attribute web provider outages
* test(secrets): prove web outage fan-out in owner suite
* fix(vault): scope malformed responses per secret
* test(secrets): harden exec fanout fixtures
2026-07-18 22:44:06 +01:00
Peter Steinberger
5fe8d6a852
fix(gateway): clients can identify authorization failures ( #110925 )
...
* fix(gateway): structure authorization errors
* test(gateway): align authorization contracts
* fix(gateway): regenerate protocol bindings
* fix(gateway): preserve optional scope errors
* fix(gateway): report complete pairing scopes
* style(gateway): format protocol exports
2026-07-18 22:02:28 +01:00
Peter Steinberger
09a64f7ab0
feat(models): make per-agent allowlists explicit ( #110888 )
2026-07-18 21:42:05 +01:00
Peter Steinberger
1d492f5c53
fix(gateway): honor scopes for WebChat session mutations ( #110931 )
...
* fix(gateway): authorize webchat session mutations by scope
* chore: keep gateway release note in PR body
2026-07-18 20:48:39 +01:00
Omar Shahine
bbad877aed
fix: deliver Codex-generated images on message-tool routes ( #110893 )
...
* fix: deliver Codex-generated images on message-tool routes
* test(codex): cover native image delivery path
Document trusted harness artifact provenance and cover the runner-to-dispatch bridge.\n\nRelease note: Codex-generated images now reach message-tool-only routes while normal source suppression remains intact.\n\nCo-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com >
---------
Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-18 20:45:57 +01:00
Peter Steinberger
8a5c8690e1
fix(secrets): keep unaffected owners live during reload failures ( #110779 )
...
* fix(secrets): isolate reload failures per owner
* refactor(secrets): split runtime activation helpers
* fix(secrets): export web warning type
* fix(secrets): reject unsafe degraded config writes
* fix(secrets): derive reload defaults type
* fix(secrets): defer reload state publication
* fix(secrets): preserve partial refresh state
* fix(secrets): retry superseded reload preflight
* fix(secrets): bind stale credentials to owner contracts
* fix(secrets): scope degraded credential contracts
* fix(secrets): restore source ownership guards
* fix(secrets): recover provider-only degradation
* fix(secrets): enforce degraded reload contracts
* fix(secrets): preserve scoped reload state
* fix(secrets): reconcile deferred descendant state
* fix(secrets): commit reload state atomically
* fix(secrets): preserve source transaction lineage
* test(secrets): use non-secret lineage marker
* chore(plugin-sdk): refresh API baseline
* fix(secrets): canonicalize web owner contracts
* fix(plugin-sdk): preserve legacy secret owner contracts
* fix(secrets): satisfy startup activation types
* test(secrets): align reload fixtures with owner contracts
* refactor(secrets): move source recovery scope helper
* fix(secrets): preserve owner contracts on web failures
* fix(secrets): bind legacy web resolution contract
* fix(secrets): retry stale auth publication
2026-07-18 18:29:24 +01:00
Peter Steinberger
98410d986e
refactor(state): move device identity into canonical SQLite state ( #110392 )
...
* refactor: store device identities in SQLite
* style: satisfy Swift identity lint limits
* test: harden device identity migration fixtures
* fix: harden SQLite device identity recovery
* chore: remove stale identity helper
* refactor: isolate device identity repair
* chore: remove stale migration import
* test: validate migrated identity key types
* fix: harden device identity repair
* style: format device identity assertion
* fix: derive repaired identity key from PEM
* style: remove redundant PEM conversions
* fix: align native identity store with schema v4
* fix(state): satisfy SQLite identity CI gates
* fix(state): coordinate native identity migration
* test(doctor): include native identity claim path
* fix(infra): preserve coordinator release error
* fix(state): clear identity validation gates
* refactor(apple): remove identity test-only APIs
* refactor(apple): remove dead identity error type
* test(apple): use canonical identity test seam
* test(macos): isolate gateway readiness identity
2026-07-18 17:43:56 +01:00
Peter Steinberger
3b2797f09b
improve(ui): settings cleanup batch — universal config.changed emitter, synced chat prefs, dedupe and copy fixes ( #110581 )
...
* fix(gateway): emit config.changed from the reload committer for every accepted write
Agent config_set, CLI, and doctor writes reach the gateway through the file
watcher's reload path, which never broadcast config.changed - only direct RPC
writes did. Move the broadcast to a single onConfigCandidateCommitted hook in
the reload committer so all writers notify connected UIs, including
runtime-skipped commits (writer-intent echo suppression, reload mode off),
and delete the duplicate RPC-side broadcasts.
* feat(ui): sync chat follow-up and commentary prefs across devices
Add chatPersistCommentary and chatFollowUpMode to the ui.prefs sync surface
(schema, types, docs) with clearable null removal for the follow-up override.
Rewrite server-prefs around a descriptor table so a synced pref is one entry
instead of five hand-written code sites. Caption synced rows/sections
(chat prefs, theme, language) and refresh the stale Settings subtitle.
* refactor(ui): dedupe settings constants, drop dead composer branch, refresh copy and docs
Derive the Security tool-profile options from PROFILE_OPTIONS and General's
thinking levels from BASE_THINKING_LEVELS instead of parallel literals.
Remove the unused composer mode:"model" branch, the orphaned
.config-view-toggle CSS family, and stale quick-settings wording. Add static
settings-search entries for the Sessions and Managed Worktrees pages plus a
provenance-row test, and update docs/cli/openclaw.md to describe the current
system-agent config-write policy (denylist roots, route-backing plugin guard,
per-agent routing escalations).
* chore: refresh plugin SDK API baseline after rebase onto current main
2026-07-18 12:10:20 +01:00
Peter Steinberger
347ee45895
fix(secrets): surface degradation in logs and doctor ( #109792 )
...
* fix(secrets): surface degraded owners safely
* fix(secrets): preserve degradation ownership across reloads
* fix(secrets): require cold ownership for source recovery
* refactor(secrets): keep assignment provenance internal
* test(secrets): use provider error contract
* fix(secrets): attribute provider failures to active co-owners
* test(secrets): clarify provider failure fixture
* fix(secrets): redact doctor degradation reasons
* test(secrets): align reload harness with runtime state
* test(secrets): cover atomic source publication
* fix(secrets): preserve web owner degradation context
* fix(secrets): retain active web degradation co-owners
* fix(secrets): keep web provider error internal
* refactor(secrets): unify reload degradation state
* refactor(config): remove obsolete source snapshot setter
2026-07-18 11:46:53 +01:00