Peter Steinberger
57e2f220de
fix(ci): restore packaged OpenWebUI and update validation ( #113614 )
...
Co-authored-by: Peter Steinberger <steipete@golden-gate.local >
2026-07-25 04:14:41 -07:00
joshavant
f153858045
fix(onepassword): make SecretRef setup production-safe
2026-07-25 06:03:30 -05:00
Vincent Koc
2b19ae1f00
fix(snapshot): recover complete pending sqlite snapshots ( #113607 )
2026-07-25 18:50:50 +08:00
Peter Steinberger
55d66fbf98
chore(scripts): remove resolved investigation tools and orphans ( #113532 )
...
* chore(scripts): remove orphaned wrappers
* chore(scripts): remove resolved investigation tools
* refactor(code-mode): remove orphaned plugin namespaces
* test(code-mode): remove stale namespace import
2026-07-25 02:47:40 -07:00
Vitor Cepeda Lopes
2296e898e1
fix(release): stop Windows package descendants after timeout ( #111956 )
...
* fix(release): terminate Windows package command trees
* fix(release): type package runner test output
* fix(release): scope package runner normalization to Windows
* test(release): run package timeout proof on Windows CI
---------
Co-authored-by: TheAngryPit <16145902+TheAngryPit@users.noreply.github.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-25 02:20:27 -07:00
Vincent Koc
3af03aee6c
refactor(approvals): share native target resolvers ( #113568 )
2026-07-25 16:23:14 +08:00
Peter Steinberger
a5d758e74b
refactor(plugin-sdk): share channel DM policy setup ( #113537 )
2026-07-25 01:00:53 -07:00
Vincent Koc
7a5c47db8e
test(sqlite): prove repository interruption recovery ( #113555 )
2026-07-25 15:37:16 +08:00
Vincent Koc
6734b132f1
test(sqlite): prove restore interruption recovery ( #113531 )
2026-07-25 15:16:51 +08:00
Peter Steinberger
dcaf78735a
docs(readme): fix stale claims, restructure, and repair the contributor avatar wall ( #113547 )
...
* fix(clawtributors): emit fixed 48px avatar tiles in README wall
* docs(readme): fix stale claims and restructure; apply fixed-size contributor tiles
2026-07-25 00:15:58 -07:00
Vincent Koc
bdd5653c3e
test(sqlite): prove killed vacuum recovery ( #113518 )
2026-07-25 13:56:41 +08:00
Peter Steinberger
82d1a03f25
refactor(agents): move implicit-main fallback into load-time roster injection ( #112678 )
...
* refactor(agents): require explicit roster defaults
* feat(onboard): create named first roster agent
* refactor(agents): remove runtime main fallbacks
* style(agents): apply roster refactor formatting
* refactor(agents): finish roster-only runtime sweep
* fix(doctor): migrate legacy main session sqlite
* fix(doctor): harden roster session migrations
* fix(onboard): commit first agent atomically
* fix(config): support empty-roster analysis
* fix(agents): preserve legacy main state during creation
* fix(setup): materialize baseline agent roster
* fix(agents): harden legacy default transfer recovery
* fix(agents): simplify roster-only legacy compatibility
* fix(agents): preserve staged first-agent entries
* fix(config): migrate persisted implicit-main rosters
* fix(config): preserve staged empty rosters
* fix(agents): finalize roster-only upgrade paths
* fix(sessions): close legacy main migration outcomes
* fix(config): migrate legacy roster markers at load
* fix(sessions): preserve roster upgrade history
* refactor(sessions): restore lean legacy main compatibility
* fix(setup): prepare first-agent credentials before publish
* fix(config): stabilize roster snapshot migration
* refactor(sessions): shrink legacy main compatibility
* fix(agents): restore roster compatibility fidelity
* fix(sessions): preserve divergent legacy history
* refactor(agents): narrow roster-only scope
* fix(config): isolate roster migration
* test(agents): align roster-only fixtures
* fix(agents): keep main agent undeletable
* fix(agents): harden roster migration invariants
* fix(agents): close setup and audit scope gaps
* fix(cron): scope session reaper throttles by agent
* fix(agents): preserve scoped owner precedence
* fix(config): preserve authored config ownership
* fix(setup): keep default workspace and roster in sync
* fix(setup): preserve default entry workspace on bare runs
* fix(agents): adapt roster rebase to keyed entries
* fix(agents): honor both roster representations
* fix(agents): route roster reads through shared helpers
* fix(config): preserve canonical roster writes
* fix(cron): resolve dynamic default for session reaper
* fix(agents): close dynamic default migration gaps
* fix(agents): align scoped session ownership
* fix(sessions): preserve legacy main directory casing
* fix(agents): align cron and legacy auth ownership
* fix(setup): provision the committed default workspace
* fix(cron): align scoped ownership and reaping
* fix(cron): treat blank agent ids as absent
* fix(cron): retain configured session-store owners
* fix(agents): repair roster-aware CI boundaries
* fix(cron): preserve scoped ownership resolution
* fix(agents): preserve rosterless maintenance paths
* fix(agents): propagate roster ownership through runtime boundaries
* fix(agents): preserve roster ownership across runtime paths
* fix(agents): harden roster diagnostics and legacy routing
* fix(agents): remove redundant diagnostic import
* test(agents): type CLI policy fixture explicitly
* fix(config): preserve canonical roster mutation identity
* fix(doctor): read canonical agent rosters consistently
* fix(config): resolve compound roster unsets safely
* fix(config): finalize main-session reconciliation
* fix(doctor): read canonical session state safely
* fix(sessions): preserve current visibility alias
* fix(config): track roster include provenance
* test(config): type roster provenance cases
* fix(config): refine roster include ownership
* fix(agents): preserve staged roster invariants
* test(config): align fixtures with explicit roster ownership
* test(node-host): preserve optional plan typing
* fix(config): preserve authored roster projections
* test(config): keep raw roster fixtures explicit
* test(config): normalize rosters at runtime fixtures
* fix(config): protect authored roster ownership
* fix(agents): require explicit session ownership
* fix(agents): enforce scoped roster ownership
* fix(sessions): merge fixed-store agent partitions
* fix(agents): harden roster ownership boundaries
* fix(config): reject ambiguous roster projections
* fix(sessions): preserve persisted store ownership
* fix(sessions): keep collision diagnostics additive
* fix(security): scan malformed roster workspaces
* test(config): align snapshot fixtures after rebase
* test(agents): use explicit roster fixtures
* fix(config): harden roster diagnostic boundaries
* fix(sessions): isolate fixed-store agent databases
* test(agents): type malformed default markers
* refactor(sessions): extract store collision resolution
* test(system-agent): split oversized setup coverage
* style(system-agent): format split setup suite
* fix(sessions): preserve promoted store ownership
* fix(sessions): derive scoped owner before target
* fix(sessions): preserve explicit sqlite ownership
* fix(agents): restore roster compatibility across CI
* fix(agents): enforce roster-owned runtime boundaries
* fix(agents): satisfy default lookup lint
* test(sessions): split known-owner coverage
* fix(state): satisfy path identity lint
* fix(agents): preserve malformed roster safety boundaries
* fix(agents): restore roster compatibility at runtime boundaries
* fix(config): satisfy roster boundary type checks
* fix(agents): preserve roster ownership across runtime probes
Setup inference probes now execute as the configured roster owner. Malformed agent-prefixed session rows are intentionally omitted by the fail-closed visibility contract rather than normalized by tests.
* fix(agents): satisfy session list owner lint
* fix(agents): preserve roster-owned runtime boundaries
Restore shared logical rows for exact SQLite session locators while keeping their physical database owner separate. The ownership regression test now constructs an explicit sole-owner database directly instead of relying on first-touch capture, matching the intentional shared-store contract.
* fix(sessions): preserve multiply owned exact stores
* fix(sessions): restore runtime owner boundaries
Keep incognito sentinels agent-owned, fold default-agent approvals into the global snapshot, and preserve the configless legacy-main CLI policy fallback. Also repair the existing CLI watchdog test lifecycle so the compact shard observes its timeout without an unawaited assertion or async timer stall; product behavior is unchanged by that test-only fix.
* test(ci): align owner-scoped fixtures
These assertions are unchanged. The fixtures now declare the intended non-default runner, expose the session-key constant imported by production status code, and select the main approvals bucket explicitly on Windows.
* fix(agents): close final roster ownership gaps
2026-07-24 22:38:09 -07:00
Vincent Koc
5f63f744ea
test(sqlite): prove publication interruption recovery ( #113512 )
2026-07-25 13:09:32 +08:00
Vincent Koc
92f01470d4
test(sqlite): crash writers during reliability proof ( #113498 )
2026-07-25 12:44:29 +08:00
joshavant
09c26e24eb
fix(installer): harden managed script downloads
2026-07-24 17:22:07 -05:00
Sebastien Tardif
99f78133b3
fix(install): validate downloaded scripts before execution
...
Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca >
2026-07-24 17:22:07 -05:00
Peter Steinberger
1e93465a2a
refactor(sqlite): enforce one database connection boundary ( #113418 )
...
* refactor(sqlite): centralize database opens
* test(sqlite): mock connection owner boundary
2026-07-24 15:15:17 -07:00
Peter Steinberger
5bea268128
feat(anthropic): complete Claude Opus 5 rollout ( #113392 )
...
* feat(models): add Claude Opus 5 support
* test(models): align Opus 5 setup fixtures
* test(models): update ambient Opus 5 detection
* fix(models): reconcile Opus 5 support with main
2026-07-24 14:55:36 -07:00
Peter Steinberger
14df16007f
fix(ci): log every pr-ci-sweeper classification and scan by creation time ( #113397 )
2026-07-24 13:33:16 -07:00
Jason (Json)
ee606def49
fix(codex): stop Computer Use readiness stalls across fallbacks ( #113393 )
...
* fix(codex): bound computer use readiness preflight
* chore(codex): keep service status internal
2026-07-24 14:27:53 -06:00
Peter Steinberger
1e9d918037
feat(sdk): always persist media facts and ship facts-first replacements for legacy Media* surfaces ( #113355 )
...
* feat(sdk): always persist media facts and ship facts-first replacements for legacy Media* surfaces
PR 1 of the media legacy retirement program (audit-frozen, 4 PRs).
- Every media-bearing user turn now persists normalized __openclaw.media
facts unconditionally while continuing to emit the legacy top-level
Media* projection byte-identically (dual-write bridge; the conditional
shouldPersistStructuredMediaEntries gate now always includes media).
- New replacement APIs, shipped before any removal: typed hook media
facts (media[], originalMedia[], mediaStagingPending) on message
events; {{AttachmentPath}}/{{AttachmentUrl}}/{{AttachmentContentType}}/
{{AttachmentDir}}/{{AttachmentIndex}} template variables; focused
openclaw/plugin-sdk/media-local-roots subpath split out of the
deprecated agent-media-payload facade.
- Every legacy surface carries @deprecated naming its replacement, under
one named compatibility record media-legacy-projection with the
operator-approved removeAfter 2026-10-01 (two release trains; deletion
additionally gates on a clean published-plugin artifact sweep).
- Generic transcript append invariant documented; SDK migration, hooks,
and configuration docs updated to the facts-first path.
Writer golden matrix proves legacy bytes and model prompt bytes are
unchanged while nested facts become unconditional. 2,189 broad media
tests green; SDK api-baseline regenerated on fresh-env Testbox.
* feat(sdk): register media-local-roots subpath exports and deprecation metadata
Completes PR 1: package export map for openclaw/plugin-sdk/media-local-roots
plus the deprecated-subpath inventory and doc metadata entries for the
media-legacy-projection record.
* chore(sdk): track media-local-roots entrypoint and deprecated-export budgets
* fix(sdk): keep deprecated MSTeams buildMediaPayload re-export through the compat window
Deleting shipped runtime-api re-exports belongs to retirement PR 4 after
the media-legacy-projection window; PR 1 only deprecates. Also formats
the migration-guide schedule table.
* docs: regenerate docs map for media migration additions
2026-07-24 10:42:17 -07:00
Vincent Koc
1e15b18bcb
fix(sqlite): support deep Windows state paths ( #113336 )
...
* fix(sqlite): normalize core database locations
* fix(sqlite): preserve Windows immutable read paths
* test(windows): exercise deep SQLite state paths
* test(windows): isolate Unix supervisor fixtures
* test(infra): keep handoff fixture within lint budget
* fix(sqlite): own read-only paths at node boundary
* chore(release): leave changelog to release flow
* fix(sqlite): classify resolved Windows UNC paths
2026-07-24 23:55:12 +08:00
Peter Steinberger
4e9cba2aba
fix(release): scope dependency conflicts to bundled plugins ( #113350 )
2026-07-24 08:08:55 -07:00
Peter Steinberger
7dfb660d1f
fix(release): keep msteams packaging and Docker reruns reliable ( #113332 )
...
* fix(release): forward-port beta packaging repairs
* fix(ci): acknowledge sweeper token grant
2026-07-24 07:05:41 -07:00
Vincent Koc
48d65f94a1
fix(test): release SQLite fixtures before Windows cleanup ( #113316 )
...
* fix(test): close SQLite fixtures before Windows cleanup
* test(windows): extend fixture cleanup retries
* fix(test): avoid registry reads during fixture cleanup
2026-07-24 20:04:57 +08:00
Peter Steinberger
4302896638
fix(i18n): unwrap invented inline code
2026-07-24 07:48:30 -04:00
Vincent Koc
a18e8fbe0c
refactor(tooling): centralize positive env integers ( #113277 )
2026-07-24 16:23:35 +08:00
Peter Steinberger
73bba03e4c
refactor: canonicalize session delivery state ( #113225 )
...
* refactor: canonicalize session delivery state
* test: canonicalize reply persistence fixtures
* test: canonicalize talk delivery fixtures
* test: canonicalize voice session routes
* test: canonicalize attachment delivery fixtures
* test: migrate gateway delivery fixtures
* fix: skip invalid session delivery rows
* test: align delivery SDK surface gates
* fix: preserve legacy delivery precedence
* test: canonicalize heartbeat delivery fixtures
* fix: preserve delivery route prompt identity
* test: canonicalize session delivery fixtures
* fix: preserve recoverable legacy delivery routes
* fix: canonicalize remaining session state
* fix: preserve canonical session classification
* style: format delivery state changes
* test: refresh plugin SDK delivery baseline
* test: avoid mutating session fixture input
* style: simplify delivery identity check
* style: simplify delivery origin spread
* fix: preserve fresh delivery route metadata
* test: assert canonical surface route switch
* fix: canonicalize doctor file-store imports
* fix: preserve transitional delivery migration state
* fix: satisfy canonical delivery CI gates
* ci: scope GitHub App token permissions
* test: infer canonical delivery projections
* test: canonicalize ACP requester delivery fixtures
* test: canonicalize harness rollback fixture
* style: apply pinned formatter
2026-07-24 01:01:19 -07:00
Peter Steinberger
f3c4b120e2
fix(tooling): prevent silent test filters and local dependency reconciliation ( #113236 )
...
* fix(tooling): harden changed checks and test filters
* test(tooling): align temp report with helper lanes
2026-07-24 00:55:52 -07:00
Jason (Json)
aee46707ba
feat(plugins): support manifest-declared MCP Apps in native plugins ( #113224 )
...
* feat(plugins): load native manifest MCP servers
* fix(gateway): advertise proxied plugin surface ports
* fix(codex): retain MCP App transcript previews
* fix(codex): render native MCP apps inline
* fix(mcp-apps): resolve harness-native views by session
* fix(codex): normalize null MCP result metadata
* fix(ui): give inline MCP apps full message width
* test(codex): use generic native MCP App fixtures
* chore(plugin-sdk): refresh harness runtime baseline
* refactor(codex): isolate native MCP App contracts
* fix(codex): satisfy native app CI contracts
* fix(ci): scope automation app tokens
* chore(ci): defer token scopes to current main
2026-07-24 01:43:48 -06:00
Vincent Koc
342816a58d
fix(i18n): publish Android flavor locale artifacts
2026-07-24 15:26:58 +08:00
Vincent Koc
4990ac3aa9
fix(i18n): cover Android flavor surfaces
2026-07-24 15:26:58 +08:00
joshavant
bd559a98ed
fix(cron): migrate scheduled authority provenance
2026-07-24 01:24:03 -05:00
Peter Steinberger
80449f9a8f
refactor(scripts): retire the STALE-CANCELLED watcher verdict ( #113242 )
...
Run-identity supersession (#113230 ) resolves the scenario this heuristic
softened: superseded runs and rerun-attempt leftovers are filtered before
classification, so aggregate-FAILURE-with-green-duplicates now classifies
as GREEN or PENDING on evidence. The only remaining reachable case —
identity-less app check runs posting duplicate same-name results — is
genuinely ambiguous and now honestly exits FAILING (15) instead of the
special verify-manually exit 17.
2026-07-23 23:11:41 -07:00
Vincent Koc
5ff16901ef
refactor(browser): reuse shared error coercion ( #113229 )
2026-07-24 13:58:29 +08:00
Peter Steinberger
169dad6224
fix: watch-pr-ci exits with false FAILURE when draft-to-ready cancels superseded runs ( #113230 )
...
* fix(scripts): ignore superseded workflow runs in watch-pr-ci rollup classification
Draft->ready re-triggers leave cancelled superseded runs on the head SHA
forever, and GitHub's aggregate rollup state counts them, so the watcher
emitted terminal FAILURE while the replacement run was still in progress
and could never reach GREEN (observed on PR #113150 , head bd1b9a0e ).
- fetch run identity per check and resolve same-name checks to the newest
run/check id (GitHub latest-name-wins); drop cancelled checks from
replaced runs; keep older runs' unique jobs visible
- paginate statusCheckRollup contexts (bounded, 10 pages) so >100-context
rollups are not truncation-blind; changed or lost snapshots throw into
the bounded retry
- classify GREEN when aggregate FAILURE is explained solely by superseded
contexts with full visibility; truncation still fails conservatively
* ci: scope GitHub App token permissions in stale, labeler, auto-response, and pr-ci-sweeper
Fixes red main: #112963 bumped zizmor v1.22.0 -> v1.28.0, whose github-app
audit flags create-github-app-token mints without permission-* inputs (14
high findings, Workflow Sanity red on main since 3b7b2a2a1f ). Most
workflows already migrated to scoped tokens; these four were stragglers.
Scopes follow each consumer's actual API surface: stale needs issues/PR
write plus actions read for its state-cache check; labeler needs label
CRUD (issues write), PR write, members read for maintainer gates, and
contents read where actions/labeler reads its config; auto-response needs
issues/PR write plus members read; pr-ci-sweeper needs actions write to
re-fire runs, checks read, and PR write. Verified locally with the exact
CI invocation (zizmor 1.28.0, repo config, regular persona, medium
severity/confidence): no findings, ignore/suppress counts match CI.
2026-07-23 22:46:04 -07:00
Peter Steinberger
3b7b2a2a1f
chore: update dependencies and migrate major contracts ( #112963 )
...
* build(deps): complete latest dependency migrations
* fix(deps): satisfy updated dependency types
* fix(deps): hold incompatible build tooling
* fix(deps): preserve portable tooling contracts
* build(deps): allow reviewed fresh transitive releases
* fix(deps): repair major upgrade validation
* build(deps): regenerate current dependency graph
* fix(logging): keep tslog adapter type private
* fix(agents): narrow grep subprocess handle
* fix(codex): prefer pinned managed binary
* fix(codex): fence managed native provenance
* build(deps): align codex ACP with managed harness
* fix(slack): use socket-mode Undici runtime
* fix(slack): detect cross-runtime responses
* fix(slack): bridge package-owned fetch types
* fix(deps): retain tslog v4 JSON contract
* build(plugin-sdk): refresh logging API manifest
2026-07-23 21:21:01 -07:00
Peter Steinberger
61f036f748
refactor(agents): close embedded attempt terminal outcomes ( #113201 )
...
* refactor(agents): close embedded attempt outcomes
* test(agents): align trajectory terminal fixture
* refactor(codex): share attempt failure type
* fix(codex): retain projector result contract
* test(agents): keep terminal projections test-only
* chore(plugin-sdk): refresh attempt terminal baseline
2026-07-23 19:56:03 -07:00
Peter Steinberger
90aee82793
feat(sessions): suggestion queue + typing indicator ( #113173 )
...
* feat(protocol): add session collaboration contracts
* feat(gateway): add session suggestion queue and typing
* feat(ui): add session suggestion controls
* fix(collaboration): restrict suggestion resolution
* fix(collaboration): dedupe suggestion dispatch modes
* fix(collaboration): preserve resolver identity
* fix(collaboration): reconcile suggestion state
* fix(collaboration): filter identityless suggestion events
* fix(ui): expose full suggestion text
* fix(collaboration): durably claim suggestion dispatch
* fix(collaboration): harden suggestion events and typing
* fix(collaboration): reconcile suggestion races
* fix(ui): reconcile suggestion capabilities
* fix(collaboration): close suggestion privacy races
* test(ui): satisfy suggestion lifecycle lint
* fix(collaboration): fence resolved suggestion events
* test(collaboration): type deferred audit result
* fix(collaboration): fence delayed typing events
* fix(ui): coalesce suggestion refreshes
* fix(ui): preserve resolved self suggestions
* fix(collaboration): enforce draft suggestion visibility
* fix(collaboration): fence post-dispatch finalization
* fix(ui): retain suggestions across visibility changes
* fix(collaboration): fence suggestion context and archives
* fix(collaboration): fence suggestion resolve lifecycle
* fix(collaboration): map suggestion replacement races
* refactor(gateway): extract session typing state
* fix(collaboration): integrate suggestion storage with session nodes
* refactor(gateway): extract session sharing snapshot cache
* fix(collaboration): satisfy protocol and deadcode gates
* fix(ci): register iOS release script entrypoints
* fix(collaboration): fence typing by session instance
* fix(collaboration): enforce incognito suggestion privacy
* docs(ui): clarify solo suggestion dormancy
* test(gateway): preserve incognito literal type
* test(gateway): split session typing coverage
* test(gateway): register collaboration method expectations
2026-07-23 18:59:58 -07:00
joshavant
17eea1c0ab
fix(channels): preserve visible partial delivery
2026-07-23 20:34:39 -05:00
Peter Steinberger
0d406a84db
fix(docs-i18n): accept hyphenated numeric compounds
2026-07-23 20:14:49 -04:00
joshavant
090bdab5b8
fix(ci): register iOS release script entries
2026-07-23 19:08:40 -05:00
joshavant
ba09e05e97
refactor(ios): append unpadded App Store revisions
2026-07-23 18:42:16 -05:00
joshavant
b7d77b0f21
feat(ios): deterministically plan App Store releases
2026-07-23 18:18:32 -05:00
Peter Steinberger
083276eada
fix(docs-i18n): mask composite numeric literals
2026-07-23 18:45:00 -04:00
Peter Steinberger
fc92b9fd91
feat(ui): merge creator avatar into sidebar leading slot, move creator filter into Threads menu ( #113150 )
...
* feat(ui): merge creator avatar into sidebar leading slot and move creator filter into Threads menu
The per-row creator chip previously rendered next to the leading state
indicator, so rows with a known creator started their titles at a
different x-offset than rows without one. The avatar now occupies the
single fixed leading slot: unread renders as a corner badge on it,
running as a spinner ring, and open/merged PR state as a colored corner
badge, while attention and pinned icons keep the slot. Child rows keep
their status badges and no longer render owner chips.
The standalone 'Filter by creator' select above the session list is
gone; the Threads funnel menu gains a People radio section with owner
chips, and the funnel trigger shows an accent dot while a creator
filter is active. The empty Threads header stays visible when ownership
chrome is active so the filter can always be cleared. Mock dev fixtures
gain two creator identities so the ownership chrome is demonstrable.
* test(ui): guard parent row spread in child-avatar ownership case
2026-07-23 15:26:56 -07:00
joshavant
30395ba31b
feat(ios): support App Store release revisions
2026-07-23 16:24:15 -05:00
Peter Steinberger
4ab29c941d
fix(docs-i18n): escape translated list ordinals
2026-07-23 15:46:21 -04:00
Peter Steinberger
73d279c232
fix(plugins): preserve shipped SDK and lifecycle state ( #113101 )
...
* fix(plugins): restore shipped channel compatibility
* docs(plugins): record shipped channel compatibility
* test(plugin-sdk): budget shipped channel compatibility
* docs(plugin-sdk): track shipped channel compat window
* test(plugins): align shipped compat guardrails
2026-07-23 12:30:54 -07:00
Peter Steinberger
7d4a16c0a5
chore(docs-i18n): log opt-in rejected body
2026-07-23 14:42:36 -04:00