Peter Steinberger
7a398fe6f8
fix(update): preserve plugin policy on failures ( #108661 )
2026-07-16 00:38:44 -07:00
Peter Steinberger
0f32033d78
fix(ui): add thinking level to new cloud sessions ( #108679 )
2026-07-15 23:54:00 -07:00
Peter Steinberger
d8b723fb00
fix: channel turns recover safely after gateway restart ( #108283 )
...
* fix(gateway): recover channel turns safely after restart
* refactor(gateway): keep recovery identity internal
* refactor(gateway): keep recovery metadata private
* fix(gateway): preserve recovery action authority
* fix(gateway): close recovery lifecycle gaps
* fix(gateway): fail closed on missing delivery receipts
* fix(gateway): fail closed on unmirrorable replies
* fix(gateway): persist terminal delivery intent
* fix(gateway): align recovery lifecycle types
* fix(gateway): require exact terminal thread receipt
* fix(gateway): close recovered terminal tool calls
* test(gateway): type terminal tool correlation
* fix(gateway): satisfy restart recovery CI contracts
* fix(gateway): require terminal tool correlation
* fix(agents): scope recovery receipts to source turns
* fix(gateway): fail closed without restart correlation
* fix(gateway): dedupe terminal source redelivery
* fix(agents): keep recovery tool results causal
* test(auto-reply): clean recovery fixture directories
* fix(gateway): allow live terminal sends without recovery claims
* fix(agents): reconcile delivered sends through restart aborts
* fix(agents): keep recovery continuations in source turns
* fix(agents): keep source-less sends non-terminal
* fix(auto-reply): dedupe active source redelivery
* fix(agents): harden recovery receipt contracts
* fix(agents): admit terminal recovery successors
* docs(recovery): document canonical receipt ownership
* fix(agents): fail closed on stale turn authority
* test(auto-reply): assert rebound session state
* fix(plugins): keep restart recovery hook list internal
2026-07-15 23:01:26 -07:00
Peter Steinberger
da59d6ade9
feat(onboarding): detect local inference providers ( #108605 )
...
* feat(onboarding): detect local inference providers
* fix(onboarding): satisfy inference choice lint
* chore(i18n): refresh onboarding locales
* chore: leave changelog to release automation
* chore(plugin-sdk): refresh API baseline
* fix(onboarding): preserve source config during local activation
2026-07-15 22:46:16 -07:00
keshavbotagent
9f5609382b
fix(telegram): preserve tool progress under preambles ( #108394 )
...
* fix(telegram): keep tool rows below progress preambles
* fix(telegram): preserve text tool progress under preambles
* fix(telegram): preserve memory progress under preambles
---------
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-07-16 10:48:53 +05:30
Peter Steinberger
5bfcd779b1
fix(ui): local sessions show no placement icon ( #108615 )
...
* fix(ui): distinguish cloud worker sessions
* chore: defer session icon release note
* fix(ui): keep placement helper private
2026-07-15 22:05:09 -07:00
Peter Steinberger
3c8269ca52
refactor(codex)!: fold the codex text provider into openai with a doctor migration
...
The live codex text provider was a redundant projection of the openai
catalog (exclusive provider ownership; the openai plugin's ChatGPT OAuth
discovery already serves gpt-5.6-* route-aware). Folding it:
- extensions/codex no longer registers a text provider, catalog entry, or
synthetic text auth; provider.ts/provider-catalog.ts/provider-discovery.ts
and the route-blind model-name heuristics are deleted; the narrow
post-harness reasoning fallback moves to an app-server-owned module
- openai thinking policy keys on explicit selected-route provenance
(api === openai-chatgpt-responses) instead of value-shape inference
- models.list gains an optional additive agentRuntime field (configured
intent); session agentHarnessId remains the execution proof
- doctor --fix migrates the shipped codex/* config shape end to end:
every model slot, provider-config merge with blocker-aware conflict
handling, sessions, cron payloads (two-phase: runtime policy persists
before cron refs rewrite), transcripts; migrated refs carry model-scoped
agentRuntime.id=codex preserving the shipped wizard semantics; auto
runtime policies normalize to codex with sibling fields preserved;
blocked provider conflicts retain the whole legacy namespace fail-closed
with an actionable warning
- the stale openai:default profile cleanup (#91352 ) was deliberately
deferred to a follow-up after review showed it needs per-agent identity
proofs; doctor keeps warning about unusable profiles
Fixes #105561
Fixes #84637
Fixes #90420
2026-07-16 03:06:43 +01:00
Peter Steinberger
9317aadaa2
feat(slack): add opt-in scoped presence events ( #108510 )
...
* feat(slack): add opt-in presence events
* style(slack): satisfy presence lint rules
* chore: keep release changelog centralized
* fix(slack): satisfy presence integration gates
* fix(slack): preserve eligible presence targets
2026-07-15 17:43:26 -07:00
morluto
16801bf4f0
fix(agents): prevent subagent registry resurrection ( #105793 )
...
* fix(agents): retire legacy subagent registry JSON
Co-authored-by: morluto <76467478+morluto@users.noreply.github.com >
* fix(agents): keep migration decision internal
Co-authored-by: morluto <76467478+morluto@users.noreply.github.com >
* style(agents): format migration decision type
Co-authored-by: morluto <76467478+morluto@users.noreply.github.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-15 17:01:42 -07:00
Dallin Romney
2d9b78fff7
refactor(qa): canonicalize live scenario coverage ( #108464 )
2026-07-15 16:50:41 -07:00
Dallin Romney
ca45a784f3
docs: align QA transport and release workflow contracts ( #108463 )
...
* docs: align QA transport workflow contracts
* docs: clarify Mantis env credentials
2026-07-15 14:51:37 -07:00
Peter Steinberger
766742c674
refactor(node-host): move configuration to shared SQLite ( #108457 )
...
* refactor(node-host): move config to shared SQLite
* test(node-host): satisfy migration gates
2026-07-15 14:02:23 -07:00
Peter Steinberger
b624abfc69
fix(discord): stop channel presence greetings for unrelated guild members ( #108448 )
...
* fix(discord): scope presence wakes to channel viewers
* chore: remove release-owned changelog entry
* fix(discord): bound presence permission lookups
* test(discord): bind presence fetch mock
* fix(discord): keep presence lookup overflow retryable
2026-07-15 13:51:48 -07:00
Peter Steinberger
32a84d093f
refactor(agents): split agent command orchestration ( #108424 )
...
* refactor(agents): split agent command orchestration
* test(agents): tighten cleanup ownership proof
* refactor(agents): keep command helper types private
* test(cli): track refactored secret resolution callsite
* fix(agents): preserve post-run session ownership
* fix(agents): preserve media recovery across command split
2026-07-15 13:42:05 -07:00
Dallin Romney
af71400c8e
refactor(qa): route live channel selectors through suite host ( #108429 )
...
* refactor(qa): route live channel selectors through suite host
* fix(qa): repair live selector CI
* fix(qa): remove retired runner exports
* fix(qa): remove obsolete live evidence
2026-07-15 13:35:34 -07:00
Dallin Romney
77d07dc3e9
refactor(qa): migrate Telegram scenarios into QA Lab ( #108430 )
...
* refactor(qa): migrate Telegram scenarios into QA Lab
* refactor(qa): remove retired Telegram runner exports
2026-07-15 12:55:00 -07:00
xydt-tanshanshan
d201acd6e8
refactor(push-web): move web push store to shared SQLite state DB ( #103294 )
...
* refactor(push-web): move state to shared SQLite
Co-authored-by: hailory <hailory@xydigit.com >
* fix(push-web): harden legacy migration retries
* fix(push-web): format migration lock errors
* fix(push-web): gate runtime during legacy migration
* fix(push-web): keep store internals private
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
Co-authored-by: hailory <hailory@xydigit.com >
2026-07-15 12:54:22 -07:00
Peter Steinberger
d37e873420
refactor(plugins): split plugin type contracts ( #108416 )
...
* refactor(plugins): split plugin type contracts
* refactor(plugins): split provider type contracts
* refactor(plugins): extract plugin definition contract
2026-07-15 12:51:39 -07:00
Peter Steinberger
126b549a26
feat: run and reclaim cloud worker sessions from Control UI ( #108398 )
...
* feat(gateway): finish cloud worker session reclaim
* chore(gateway): refresh cloud worker artifacts
* fix(gateway): preserve recovery environment narrowing
* test(gateway): complete worker tunnel mock
* fix(gateway): harden cloud worker recovery
* fix(gateway): serialize forced worker teardown
* fix(gateway): handle replaced workspace directories
* fix(gateway): preserve forced destroy receiver
* test(ui): cover cloud worker reclaim flow
* fix(gateway): close final worker recovery races
* fix(ci): align cloud worker generated surfaces
* test(gateway): satisfy worker queue lint
* fix(gateway): recheck remote workspace after lease fence
* chore: move cloud worker release note to PR
2026-07-15 11:24:04 -07:00
Peter Steinberger
bbb62d8510
chore(plugins): window unused and bundled-only public plugin-sdk subpaths ( #108415 )
...
* chore(plugins): window unused and bundled-only public plugin-sdk subpaths
* fix(plugins): keep literal compat codes in windowed subpath seeds
2026-07-15 11:21:59 -07:00
Peter Steinberger
2d7be9e84f
fix(docs-i18n): protect split product links
2026-07-15 13:50:06 -04:00
Peter Steinberger
f810fb35d5
refactor(reef): centralize peer trust in SQLite ( #108375 )
...
* feat(plugin-sdk): support removing pairing requests
* refactor(reef): centralize peer trust in SQLite
* chore: defer Reef release note
* fix(reef): share runtime state across module instances
* refactor(reef): narrow trust store boundary
* test(reef): pass config to account description
2026-07-15 10:21:54 -07:00
Peter Steinberger
f3adeb2ac6
fix(discord): move command deploy cache to sqlite ( #108381 )
2026-07-15 10:03:09 -07:00
Peter Steinberger
9497450511
refactor: eliminate dead-export baseline ( #108376 )
...
Burn the grandfathered unused-export baseline to zero and enforce a hard-zero Knip gate.
2026-07-15 17:05:07 +01:00
Peter Steinberger
f41c143345
refactor(state): move skill upload staging to SQLite ( #108346 )
...
* refactor(state): move skill upload staging to sqlite
* test(skills): make archive mode assertion portable
* fix(skills): fence upload finalization by lease owner
* fix(skills): handle nullable lease expiry
* fix(skills): bound upload install leases
2026-07-15 08:40:46 -07:00
jincheng-xydt
b2e42e3645
fix(update): preserve pnpm and Bun global installs ( #107802 )
...
* fix(update): preserve pnpm and bun global installs
* fix(update): anchor pnpm updates to invoking install
* fix(update): recover skipped pnpm lifecycle
* fix(update): fail closed on ambiguous pnpm ownership
* fix(update): tolerate pnpm probe warnings
* fix(update): bind pnpm installs to project owners
* fix(update): isolate pnpm mutations from caller pins
* docs(changelog): credit pnpm 11 report
Co-authored-by: jincheng-xydt <xu.jincheng@xydigit.com >
* chore(changelog): defer release note ownership
* fix(update): make package-root fallback explicit
* test(update): split pnpm scenario coverage
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-15 08:03:35 -07:00
Shakker
8d5592548b
docs: explain ClickClack post-add verification ( #108332 )
2026-07-15 15:20:33 +01:00
Peter Steinberger
4e78d91c0f
refactor(sessions): split session accessor by ownership ( #108247 )
2026-07-15 06:47:29 -07:00
Peter Steinberger
e38cd62e0d
refactor(state): move managed image records to SQLite ( #108290 )
...
* refactor(state): move managed image records to sqlite
* refactor(state): narrow managed image store exports
* fix(state): preserve managed image media roots
* test(state): track managed image temp directories
2026-07-15 06:14:10 -07:00
marchpure
69ef3ca980
fix(codex): make loop relay optional ( #97224 )
...
Move the Codex-specific PreToolUse loop relay switch into the Codex
plugin, preserve policy relays, and cover both normal and side turns.
Co-authored-by: Peter Steinberger <steipete@gmail.com >
Co-authored-by: marchpure <marchpure@users.noreply.github.com >
2026-07-15 05:29:20 -07:00
Shakker
611e7ddfe3
docs: sync ClickClack secret credential registry ( #108271 )
2026-07-15 13:05:10 +01:00
Shakker
f281b74e49
docs: refresh ClickClack docs map ( #108271 )
2026-07-15 13:05:10 +01:00
Shakker
fa6776b9b2
docs: clarify ClickClack token sources
2026-07-15 13:05:10 +01:00
Shakker
7af8f7dc22
docs: document ClickClack guided setup
2026-07-15 13:05:10 +01:00
Peter Steinberger
44a0c093cf
fix(docs): expose generated taxonomy links
2026-07-15 07:28:58 -04:00
Ayaan Zaidi
8160bbdf2e
fix(telegram): deliver rich-message authoring contract to every runtime via inbound formatting hints
2026-07-15 16:42:27 +05:30
Peter Steinberger
ddc9ec3f36
feat(discord): opt-in Discord Activities widget support ( #107442 )
...
Adds a Discord Activities integration so an agent can show a self-contained
HTML widget to Discord users, opened as a sandboxed Activity inside the client.
Off by default: routes, the discord_widget tool, and the launch handler register
only when channels.discord.activities is configured. OAuth identifies the user
and gates on the account allowlist; widget lookup is capability- or
instance-validated; token exchange is rate-limited; widget HTML runs in a
no-network sandboxed iframe.
2026-07-15 04:07:46 -07:00
morluto
1a34950d9c
fix(commitments): keep heartbeats responsive with large queues ( #105780 )
...
* fix(commitments): migrate store to sqlite
Replace steady-state JSON persistence with typed shared-state rows and a doctor-only verified import for shipped legacy data.
Co-authored-by: morluto <76467478+morluto@users.noreply.github.com >
* fix(commitments): satisfy migration gates
* fix(commitments): type sqlite counts defensively
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-15 03:58:03 -07:00
Peter Steinberger
84c7941f1e
refactor: simplify recent async ownership fixes ( #108164 )
...
* fix(device-pair): preserve concurrent notify state
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* refactor(ui): simplify logbook refresh ownership
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(qa-lab): bound multipass retry window
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* chore: keep release notes in PR body
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(ui): keep logbook controller state private
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(ui): retire logbook client epochs
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(ui): retire inactive logbook ownership
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(device-pair): require atomic notify state
Co-authored-by: Alix-007 <li.long15@xydigit.com >
---------
Co-authored-by: Alix-007 <li.long15@xydigit.com >
2026-07-15 03:32:15 -07:00
Peter Steinberger
61bd901da9
docs(plugin-sdk): refresh generated API hashes ( #108221 )
2026-07-15 02:54:55 -07:00
Peter Steinberger
13c7cf45c8
docs(onepassword): document error codes, audit errorCode, and authorization handoff
2026-07-15 02:11:49 -07:00
Peter Steinberger
a97bdfb687
feat(agents): narrow gateway tool to read-only config
...
Phase 3 of #107237 . Removes config.apply/config.patch/restart from the
regular-agent gateway tool (mirroring Phase 2's update.run removal); only
config.get and config.schema.lookup reads remain. Persistent config changes
and restarts now go exclusively through the human-approved openclaw
delegation path — closing the last unmediated agent config-write surface.
gateway stays owner-only/control-plane gated (config reads expose secrets and
host topology). Legacy setups can re-enable writes via the existing per-agent
tool allowlist; no new config key. Net -2271 LOC.
Refs #107237
2026-07-15 01:56:31 -07:00
Peter Steinberger
75db23f3fc
fix: prevent stale rescue approvals from executing ( #108147 )
...
* fix(system-agent): persist rescue approvals in sqlite
Co-authored-by: Yung-Chen Tang <46495124+yungchentang@users.noreply.github.com >
* fix(system-agent): narrow rescue expiry clock
* test(system-agent): isolate rescue docker inference
* test(system-agent): align rescue docker doctor contract
* test(system-agent): accept canonical model shape
* fix(system-agent): refuse remote doctor repairs
* fix(infra): break rescue migration import cycle
* test(system-agent): lock rescue publish ordering
* test(system-agent): align rescue harness assertions
---------
Co-authored-by: Yung-Chen Tang <46495124+yungchentang@users.noreply.github.com >
2026-07-15 01:53:00 -07:00
Peter Steinberger
6eda184f27
refactor: simplify native session executable resolution ( #108169 )
2026-07-15 01:49:45 -07:00
Dallin Romney
6c4e76ea8b
ci(qa): reuse Matrix live workflow for releases ( #103604 )
...
* ci(qa): reuse Matrix live workflow for releases
* docs(testing): restore Tailscale isolation flag
* fix(ci): make Matrix artifact names ref-safe
* test(ci): type Matrix workflow profiles
* style(testing): format Tailscale isolation guidance
2026-07-15 01:48:59 -07:00
Peter Steinberger
bef86c8b88
fix(macos): skip post-update window for app-only updates ( #108146 )
...
* fix(macos): skip app-only update dialog
* fix(macos): preserve incomplete gateway recovery
* chore: leave release changelog ownership intact
2026-07-15 01:38:49 -07:00
Hannes Rudolph
63aafd003d
docs: explain snapshots and rollback ( #108159 )
2026-07-15 02:29:29 -06:00
Peter Steinberger
b65a2d836a
feat(linux): discover gateways via Bonjour and open their dashboard ( #108115 )
...
New discovery.rs browses _openclaw-gw._tcp with a lifetime mdns-sd
browser, keeps a fullname-keyed snapshot (resolved updates replace,
goodbye/TTL removes), and mirrors the native clients' TXT contract and
direct-selection gate (resolved SRV endpoint routing; tailnetDns is a
hint only). The bootstrap page lists discovered gateways and connecting
navigates the dashboard WebView to the resolved endpoint, validated
against the live snapshot; remote selection cancels the local watchdog
so an in-flight local bootstrap cannot steal the WebView back.
2026-07-15 01:22:36 -07:00
Dallin Romney
ad34552473
refactor(qa): migrate Matrix scenarios into QA Lab ( #103589 )
...
* refactor(qa): migrate Matrix scenarios into QA Lab
* fix(qa): build Matrix boundary declarations
* fix(qa): preserve Matrix preview boundaries
* fix(qa): preserve Matrix hot reload semantics
* fix(qa): harden Matrix destructive scenario failures
* fix(qa): harden Matrix scenario isolation
* fix(qa): close Matrix negative scenario blind spots
* fix(qa): isolate Matrix substrate state
* fix(qa): harden Matrix transport substrate
* fix(qa): preserve Matrix profile and event parity
* fix(qa): preserve explicit scenario models
* fix(qa): align Matrix scenario coverage taxonomy
* fix(qa): format Matrix allowlist cleanup
* fix(qa): satisfy migrated Matrix CI contracts
* fix(qa): reconcile Matrix migration with current main
* fix(qa): break scenario flow import cycle
* fix(qa): reconcile Matrix max-lines ownership
* fix(qa): address Matrix review boundaries
* fix(qa): remove stale Matrix lint suppression
* fix(qa): adopt split Matrix E2EE flows
* fix(qa): export Matrix scenario record guard
* fix(qa): align Matrix migration with privatized helpers
* refactor(qa): finish Matrix QA Lab ownership
* fix(qa): preserve Matrix suite defaults
* fix(qa): reconcile Matrix cleanup with current main
* test(qa): follow canonical Matrix profile size
* fix(qa): guard stale Matrix QA package output
* docs(qa): redirect retired Matrix QA pages
* refactor(qa): finish Matrix runner rename
* test(qa): assert Matrix defaults through profile resolver
* docs: refresh QA cleanup map
* fix(qa): privatize Matrix storage discovery
2026-07-15 01:22:20 -07:00
Peter Steinberger
0be803ebc0
fix: npm 12 global updates no longer stop at the candidate guard ( #108100 )
...
* fix(update): approve candidate lifecycle on npm 12
* test(update): align npm lifecycle argv expectations
2026-07-15 01:10:32 -07:00