Peter Steinberger
126b549a26
feat: run and reclaim cloud worker sessions from Control UI ( #108398 )
...
* feat(gateway): finish cloud worker session reclaim
* chore(gateway): refresh cloud worker artifacts
* fix(gateway): preserve recovery environment narrowing
* test(gateway): complete worker tunnel mock
* fix(gateway): harden cloud worker recovery
* fix(gateway): serialize forced worker teardown
* fix(gateway): handle replaced workspace directories
* fix(gateway): preserve forced destroy receiver
* test(ui): cover cloud worker reclaim flow
* fix(gateway): close final worker recovery races
* fix(ci): align cloud worker generated surfaces
* test(gateway): satisfy worker queue lint
* fix(gateway): recheck remote workspace after lease fence
* chore: move cloud worker release note to PR
2026-07-15 11:24:04 -07:00
Peter Steinberger
bbb62d8510
chore(plugins): window unused and bundled-only public plugin-sdk subpaths ( #108415 )
...
* chore(plugins): window unused and bundled-only public plugin-sdk subpaths
* fix(plugins): keep literal compat codes in windowed subpath seeds
2026-07-15 11:21:59 -07:00
Peter Steinberger
2d7be9e84f
fix(docs-i18n): protect split product links
2026-07-15 13:50:06 -04:00
Peter Steinberger
f810fb35d5
refactor(reef): centralize peer trust in SQLite ( #108375 )
...
* feat(plugin-sdk): support removing pairing requests
* refactor(reef): centralize peer trust in SQLite
* chore: defer Reef release note
* fix(reef): share runtime state across module instances
* refactor(reef): narrow trust store boundary
* test(reef): pass config to account description
2026-07-15 10:21:54 -07:00
Peter Steinberger
f3adeb2ac6
fix(discord): move command deploy cache to sqlite ( #108381 )
2026-07-15 10:03:09 -07:00
Peter Steinberger
9497450511
refactor: eliminate dead-export baseline ( #108376 )
...
Burn the grandfathered unused-export baseline to zero and enforce a hard-zero Knip gate.
2026-07-15 17:05:07 +01:00
Peter Steinberger
f41c143345
refactor(state): move skill upload staging to SQLite ( #108346 )
...
* refactor(state): move skill upload staging to sqlite
* test(skills): make archive mode assertion portable
* fix(skills): fence upload finalization by lease owner
* fix(skills): handle nullable lease expiry
* fix(skills): bound upload install leases
2026-07-15 08:40:46 -07:00
jincheng-xydt
b2e42e3645
fix(update): preserve pnpm and Bun global installs ( #107802 )
...
* fix(update): preserve pnpm and bun global installs
* fix(update): anchor pnpm updates to invoking install
* fix(update): recover skipped pnpm lifecycle
* fix(update): fail closed on ambiguous pnpm ownership
* fix(update): tolerate pnpm probe warnings
* fix(update): bind pnpm installs to project owners
* fix(update): isolate pnpm mutations from caller pins
* docs(changelog): credit pnpm 11 report
Co-authored-by: jincheng-xydt <xu.jincheng@xydigit.com >
* chore(changelog): defer release note ownership
* fix(update): make package-root fallback explicit
* test(update): split pnpm scenario coverage
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-15 08:03:35 -07:00
Shakker
8d5592548b
docs: explain ClickClack post-add verification ( #108332 )
2026-07-15 15:20:33 +01:00
Peter Steinberger
4e78d91c0f
refactor(sessions): split session accessor by ownership ( #108247 )
2026-07-15 06:47:29 -07:00
Peter Steinberger
e38cd62e0d
refactor(state): move managed image records to SQLite ( #108290 )
...
* refactor(state): move managed image records to sqlite
* refactor(state): narrow managed image store exports
* fix(state): preserve managed image media roots
* test(state): track managed image temp directories
2026-07-15 06:14:10 -07:00
marchpure
69ef3ca980
fix(codex): make loop relay optional ( #97224 )
...
Move the Codex-specific PreToolUse loop relay switch into the Codex
plugin, preserve policy relays, and cover both normal and side turns.
Co-authored-by: Peter Steinberger <steipete@gmail.com >
Co-authored-by: marchpure <marchpure@users.noreply.github.com >
2026-07-15 05:29:20 -07:00
Shakker
611e7ddfe3
docs: sync ClickClack secret credential registry ( #108271 )
2026-07-15 13:05:10 +01:00
Shakker
f281b74e49
docs: refresh ClickClack docs map ( #108271 )
2026-07-15 13:05:10 +01:00
Shakker
fa6776b9b2
docs: clarify ClickClack token sources
2026-07-15 13:05:10 +01:00
Shakker
7af8f7dc22
docs: document ClickClack guided setup
2026-07-15 13:05:10 +01:00
Peter Steinberger
44a0c093cf
fix(docs): expose generated taxonomy links
2026-07-15 07:28:58 -04:00
Ayaan Zaidi
8160bbdf2e
fix(telegram): deliver rich-message authoring contract to every runtime via inbound formatting hints
2026-07-15 16:42:27 +05:30
Peter Steinberger
ddc9ec3f36
feat(discord): opt-in Discord Activities widget support ( #107442 )
...
Adds a Discord Activities integration so an agent can show a self-contained
HTML widget to Discord users, opened as a sandboxed Activity inside the client.
Off by default: routes, the discord_widget tool, and the launch handler register
only when channels.discord.activities is configured. OAuth identifies the user
and gates on the account allowlist; widget lookup is capability- or
instance-validated; token exchange is rate-limited; widget HTML runs in a
no-network sandboxed iframe.
2026-07-15 04:07:46 -07:00
morluto
1a34950d9c
fix(commitments): keep heartbeats responsive with large queues ( #105780 )
...
* fix(commitments): migrate store to sqlite
Replace steady-state JSON persistence with typed shared-state rows and a doctor-only verified import for shipped legacy data.
Co-authored-by: morluto <76467478+morluto@users.noreply.github.com >
* fix(commitments): satisfy migration gates
* fix(commitments): type sqlite counts defensively
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-15 03:58:03 -07:00
Peter Steinberger
84c7941f1e
refactor: simplify recent async ownership fixes ( #108164 )
...
* fix(device-pair): preserve concurrent notify state
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* refactor(ui): simplify logbook refresh ownership
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(qa-lab): bound multipass retry window
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* chore: keep release notes in PR body
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(ui): keep logbook controller state private
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(ui): retire logbook client epochs
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(ui): retire inactive logbook ownership
Co-authored-by: Alix-007 <li.long15@xydigit.com >
* fix(device-pair): require atomic notify state
Co-authored-by: Alix-007 <li.long15@xydigit.com >
---------
Co-authored-by: Alix-007 <li.long15@xydigit.com >
2026-07-15 03:32:15 -07:00
Peter Steinberger
61bd901da9
docs(plugin-sdk): refresh generated API hashes ( #108221 )
2026-07-15 02:54:55 -07:00
Peter Steinberger
13c7cf45c8
docs(onepassword): document error codes, audit errorCode, and authorization handoff
2026-07-15 02:11:49 -07:00
Peter Steinberger
a97bdfb687
feat(agents): narrow gateway tool to read-only config
...
Phase 3 of #107237 . Removes config.apply/config.patch/restart from the
regular-agent gateway tool (mirroring Phase 2's update.run removal); only
config.get and config.schema.lookup reads remain. Persistent config changes
and restarts now go exclusively through the human-approved openclaw
delegation path — closing the last unmediated agent config-write surface.
gateway stays owner-only/control-plane gated (config reads expose secrets and
host topology). Legacy setups can re-enable writes via the existing per-agent
tool allowlist; no new config key. Net -2271 LOC.
Refs #107237
2026-07-15 01:56:31 -07:00
Peter Steinberger
75db23f3fc
fix: prevent stale rescue approvals from executing ( #108147 )
...
* fix(system-agent): persist rescue approvals in sqlite
Co-authored-by: Yung-Chen Tang <46495124+yungchentang@users.noreply.github.com >
* fix(system-agent): narrow rescue expiry clock
* test(system-agent): isolate rescue docker inference
* test(system-agent): align rescue docker doctor contract
* test(system-agent): accept canonical model shape
* fix(system-agent): refuse remote doctor repairs
* fix(infra): break rescue migration import cycle
* test(system-agent): lock rescue publish ordering
* test(system-agent): align rescue harness assertions
---------
Co-authored-by: Yung-Chen Tang <46495124+yungchentang@users.noreply.github.com >
2026-07-15 01:53:00 -07:00
Peter Steinberger
6eda184f27
refactor: simplify native session executable resolution ( #108169 )
2026-07-15 01:49:45 -07:00
Dallin Romney
6c4e76ea8b
ci(qa): reuse Matrix live workflow for releases ( #103604 )
...
* ci(qa): reuse Matrix live workflow for releases
* docs(testing): restore Tailscale isolation flag
* fix(ci): make Matrix artifact names ref-safe
* test(ci): type Matrix workflow profiles
* style(testing): format Tailscale isolation guidance
2026-07-15 01:48:59 -07:00
Peter Steinberger
bef86c8b88
fix(macos): skip post-update window for app-only updates ( #108146 )
...
* fix(macos): skip app-only update dialog
* fix(macos): preserve incomplete gateway recovery
* chore: leave release changelog ownership intact
2026-07-15 01:38:49 -07:00
Hannes Rudolph
63aafd003d
docs: explain snapshots and rollback ( #108159 )
2026-07-15 02:29:29 -06:00
Peter Steinberger
b65a2d836a
feat(linux): discover gateways via Bonjour and open their dashboard ( #108115 )
...
New discovery.rs browses _openclaw-gw._tcp with a lifetime mdns-sd
browser, keeps a fullname-keyed snapshot (resolved updates replace,
goodbye/TTL removes), and mirrors the native clients' TXT contract and
direct-selection gate (resolved SRV endpoint routing; tailnetDns is a
hint only). The bootstrap page lists discovered gateways and connecting
navigates the dashboard WebView to the resolved endpoint, validated
against the live snapshot; remote selection cancels the local watchdog
so an in-flight local bootstrap cannot steal the WebView back.
2026-07-15 01:22:36 -07:00
Dallin Romney
ad34552473
refactor(qa): migrate Matrix scenarios into QA Lab ( #103589 )
...
* refactor(qa): migrate Matrix scenarios into QA Lab
* fix(qa): build Matrix boundary declarations
* fix(qa): preserve Matrix preview boundaries
* fix(qa): preserve Matrix hot reload semantics
* fix(qa): harden Matrix destructive scenario failures
* fix(qa): harden Matrix scenario isolation
* fix(qa): close Matrix negative scenario blind spots
* fix(qa): isolate Matrix substrate state
* fix(qa): harden Matrix transport substrate
* fix(qa): preserve Matrix profile and event parity
* fix(qa): preserve explicit scenario models
* fix(qa): align Matrix scenario coverage taxonomy
* fix(qa): format Matrix allowlist cleanup
* fix(qa): satisfy migrated Matrix CI contracts
* fix(qa): reconcile Matrix migration with current main
* fix(qa): break scenario flow import cycle
* fix(qa): reconcile Matrix max-lines ownership
* fix(qa): address Matrix review boundaries
* fix(qa): remove stale Matrix lint suppression
* fix(qa): adopt split Matrix E2EE flows
* fix(qa): export Matrix scenario record guard
* fix(qa): align Matrix migration with privatized helpers
* refactor(qa): finish Matrix QA Lab ownership
* fix(qa): preserve Matrix suite defaults
* fix(qa): reconcile Matrix cleanup with current main
* test(qa): follow canonical Matrix profile size
* fix(qa): guard stale Matrix QA package output
* docs(qa): redirect retired Matrix QA pages
* refactor(qa): finish Matrix runner rename
* test(qa): assert Matrix defaults through profile resolver
* docs: refresh QA cleanup map
* fix(qa): privatize Matrix storage discovery
2026-07-15 01:22:20 -07:00
Peter Steinberger
0be803ebc0
fix: npm 12 global updates no longer stop at the candidate guard ( #108100 )
...
* fix(update): approve candidate lifecycle on npm 12
* test(update): align npm lifecycle argv expectations
2026-07-15 01:10:32 -07:00
Peter Steinberger
f3e6042119
fix(ui): preserve explicit steer queue mode ( #108121 )
2026-07-15 01:09:55 -07:00
Peter Steinberger
2afa9de438
fix(codex): structured abort detection, tool-schema repair, native-result middleware relay ( #108105 )
...
* fix(codex): use structured turn status for aborts, repair tool schemas, relay native results to middleware
- turn aborts are detected from the correlated turn/completed status instead
of byte-matching private codex-rs prose; the <turn_aborted> marker remains a
non-terminal user-interrupt hint (tags only, wording-independent) because the
app-server collapses all abort reasons into "interrupted" (#99268 )
- dynamic-tool schemas are repaired before projection via the shared OpenAI
normalizer: annotation nulls stripped, type:null inferred from object/array
shape hints; unrepairable null constraints stay quarantined instead of
widening the schema (#106277 , #97913 )
- Codex-native tool results now flow through agentToolResultMiddleware at the
post_tool_use relay boundary (observe-only: the Codex PostToolUse contract
cannot replace a native tool response) (#95597 )
* test(codex): regenerate prompt snapshots for normalized dynamic-tool schemas
The shared OpenAI strict-compat normalization now runs on Codex dynamic tools,
so empty object schemas gain additionalProperties:false and required:[] in the
snapshot payloads, matching what the OpenAI provider family sends.
2026-07-15 00:51:24 -07:00
Peter Steinberger
fe469082b7
chore(plugins): backfill compat windows for deprecated plugin-sdk subpaths ( #108035 )
2026-07-15 00:49:02 -07:00
Yuval Dinodia
7974def3fd
fix(codex): restore shell for restricted turns ( #92294 )
...
* fix(codex): keep OpenClaw exec when native surface has no environment (#92238 )
* chore: keep release note in PR
* fix(codex): keep shell tool type internal
Co-authored-by: yetval <yetvald@gmail.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-15 00:37:04 -07:00
Peter Steinberger
53cc2977ac
chore(plugin-sdk): align baseline after auth refactor
2026-07-15 08:30:41 +01:00
Peter Steinberger
15cc637004
chore(plugin-sdk): refresh API baseline
2026-07-15 08:30:41 +01:00
Peter Steinberger
6beb726be7
fix(docs): preserve inline code literals
2026-07-15 03:10:11 -04:00
Peter Steinberger
0754d23615
fix: group native sessions by host ( #108062 )
...
* fix(control-ui): group native sessions by host
* test: satisfy native session checks
* chore: remove release-owned changelog entry
2026-07-14 23:51:00 -07:00
Peter Steinberger
92fc907ffb
fix: preserve TUI restore state without JSON races ( #108058 )
...
* refactor(tui): move last session state to sqlite
* chore: keep release notes in PR body
* test: update doctor migration fixture
* chore: satisfy dead code export gate
2026-07-14 23:46:22 -07:00
clawsweeper[bot]
5afb1fb381
feat(ui): add follow-up behavior setting for active runs (steer by default) ( #108032 )
...
* feat(ui): add follow-up behavior setting (queue vs steer) for active runs
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
* default follow-up behavior to steer
Follow-ups sent while a run is active now steer into the running turn by
default; queue mode becomes the persisted opt-out. Offline/disconnected
sends still always queue.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
* feat(ui): steer active follow-ups by default
---------
Co-authored-by: openclaw-clawsweeper[bot] <openclaw-clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-14 23:28:27 -07:00
Peter Steinberger
23c0a7b612
fix: preserve working installs on unsupported Node ( #106994 )
...
* fix(update): preserve installs on unsupported Node
* fix(update): verify skipped install scripts
* refactor(update): share global install preflight
* fix(update): validate Bun-installed Node runtime
* fix(update): classify install preflight failures
* refactor(update): normalize install failure reasons
* style(update): format updater policy test
* fix(update): preserve pnpm script policy safety
* fix(update): classify hosted git sources
* chore: leave release notes to release flow
* fix(release): defer package inventory helper loading
* style(release): keep inventory loader LOC-neutral
* fix(update): validate staged package lifecycle
* fix(update): match packed lifecycle contract
* fix(update): harden Bun package activation
* test(update): model packed Bun lifecycle
* style(update): avoid lifecycle name shadowing
* fix(update): remove unsafe Bun staging experiment
* fix(update): satisfy updater type checks
* fix(update): preserve packed npm package name
* fix(update): preserve checkout failure status
* fix(update): disable scripts while packing candidates
* fix(update): preflight source package engines safely
* fix(update): preserve legacy npm downgrades
* fix(update): pin npm packing to selected Node
* fix(update): stage npm activation before replacing live package
* fix(update): guard non-npm source activation
* refactor(update): isolate npm staging helpers
* fix(update): harden staged package lifecycle
* test(update): satisfy merged type gates
* fix(update): privatize runtime npm helper
* fix(ci): satisfy merged lint and type gates
* docs(changelog): defer updater note to release
* fix(update): guard package activation runtime
* fix(update): preserve installs on unsupported Node
* test(update): reject prerelease Node runtimes
* test(update): use shared temp cleanup
* fix(update): fail closed when install scripts are skipped
* fix(update): pack install guard in docker artifacts
* fix(ci): keep install guard export tooling-local
2026-07-14 23:19:48 -07:00
Peter Steinberger
3d4ba02574
feat(active-memory): add recall-specific fast mode ( #108043 )
...
* feat(active-memory): add fast mode override
* fix(agents): preserve fast auto cutoff
* fix(active-memory): inherit parent fast mode
* docs: refresh generated docs map
2026-07-14 23:09:04 -07:00
Dallin Romney
fc56b55403
docs: refresh generated docs map ( #108052 )
2026-07-14 23:05:07 -07:00
Peter Steinberger
b9a837ec8d
refactor(agents): split agent session responsibilities ( #107948 )
2026-07-14 22:25:08 -07:00
Peter Steinberger
e9fc23ad1f
refactor(plugin-sdk): remove private testing barrel ahead of window ( #108020 )
2026-07-14 22:13:37 -07:00
Peter Steinberger
290836cafd
refactor(config): split config I/O responsibilities ( #107983 )
...
* refactor(config): split config I/O
* fix(config): align split modules with guardrails
* fix(config): remove dead write metadata helper
* style(config): format write safety imports
* fix(config): preserve comment-loss warning on split writes
2026-07-14 22:11:22 -07:00
clawsweeper[bot]
3a208a5068
fix(discord): prevent presence wake floods after reconnects ( #107969 )
...
* feat(discord): throttle online-presence events after gateway reconnects
After a Discord gateway (re)connect the presence replay burst emitted one
system event per member, waking the agent each time. Add a per-account
emission gate: a post-reconnect suppression window (default 5 min), a
sliding-window burst limit (default 8/60s, logged once per episode), and
a configurable per-user greeting cooldown (default 8h). New guild
presenceEvents knobs: cooldownSeconds, reconnectSuppressSeconds,
burstLimit, burstWindowSeconds.
* fix(discord): preserve presence throttle retries
* fix(discord): preserve presence throttle retries
* fix(discord): scope presence throttle per guild
Co-authored-by: openclaw-clawsweeper[bot] <openclaw-clawsweeper[bot]@users.noreply.github.com>
* fix(discord): keep presence gate internals private
Co-authored-by: openclaw-clawsweeper[bot] <openclaw-clawsweeper[bot]@users.noreply.github.com>
---------
Co-authored-by: openclaw-clawsweeper[bot] <openclaw-clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com >
Co-authored-by: Peter Steinberger <peter@steipete.me >
2026-07-14 22:02:53 -07:00
Monkey-wusky
4a9a556a3a
fix(config): reject zero-value resetArchiveRetention to prevent silent data loss ( #104516 )
...
* fix(config): reject zero-value resetArchiveRetention to prevent silent data loss
* fix: add braces to guard clauses for curly lint rule
* fix: normalize numeric values and cover pruneAfter fallback in migration
* fix: reject zero-value pruneAfter at schema level to close fallback gap
* fix: independently check and repair both retention fields in migration
* fix: split doctor diagnostics into field-specific rules and messages
* fix: remove unused local in migration test helper
* fix: repair 5 lint errors (curly braces, zero-fraction, narrow value)
* fix(doctor): rewrite zero resetArchiveRetention to false instead of deleting it
Deleting a zero resetArchiveRetention caused the runtime to fall back to
pruneAfter (default 30d), which contradicted the doctor output that
claimed archives would be kept indefinitely. Only an explicit false
value produces indefinite retention per the documented schema.
- P1: Rewrite zero resetArchiveRetention to false in the doctor
migration apply callback, matching the promised indefinite-retention
behavior.
- P3: Update the pruneAfter rule warning to describe eligible
stale/non-preserved session entries instead of "all sessions".
* fix(config): repair zero retention safely
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
Co-authored-by: Peter Steinberger <peter@steipete.me >
2026-07-14 21:47:40 -07:00