* refactor(config): remove retired agents.list and default markers from the authored config type
The authored OpenClawConfig type still declared AgentsConfig.list and
AgentConfig.default after #162612 made config validation reject both, so
`satisfies OpenClawConfig` kept admitting fixtures and writers that Gateway
startup then refused (#163766, #163623). Production code also read the
untyped runtime agents.list projection, which structuredClone drops, so
config-mutation drafts and canonical configs silently saw an empty roster.
The authored type now rejects both shapes. Doctor and pre-admission
migration inputs use the Doctor-owned OpenClawConfigWithLegacyRoster type
(src/config/legacy.roster.ts), which stays structurally assignable to
OpenClawConfig, so legacy fixtures need no casts. Runtime readers use the
roster owners (listAgentEntries, resolveAgentEntry, resolveAgentConfig).
Raw default-marker compatibility for raw SDK inputs is unchanged.
The non-enumerable runtime agents.list projection is kept, untyped, for
plugins built against SDK releases through 2026.9.x and registered as the
deprecated compatibility record agent-list-runtime-projection (removal after
2027-01-02), documented in docs/plugins/sdk-migration/how-to-migrate.md.
Fixes found by the cutover:
- Feishu dynamic agents: lock-time duplicate and maxAgents checks saw an
empty cloned roster and wrote an agents.list that validation rejects.
- TUI abort, sessions_send, harness compaction preflight, and run-session
lookup resolved a default agent even when an explicit owner was known;
models.list now uses the ambient owner like models.ts.
- ACP session-metadata migration ignored plugin-declared owners; Talk lost
configured wake names; per-agent model normalization and model-auth policy
cleanup skipped canonical agents.entries.
About 1,075 test fixtures now author canonical agents.entries with the
explicit per-surface owners Doctor materializes; Doctor/migration tests keep
legacy input typed as OpenClawConfigWithLegacyRoster.
* refactor: convert roster fixtures added on main to keyed agents.entries
Keep runtime fixtures canonical and preserve explicit per-call ownership. Pin the Doctor schema rehearsal session-store owner without restoring an implicit default. Remove file-transfer reload selectors for rejected list and default fields; canonical workspace paths continue to cover roster changes.
* test(zalouser): keep raw legacy-list coverage in Doctor state migration test
The legacy-list case had been converted to keyed entries, duplicating the keyed-roster case. Doctor state migrations receive raw pre-migration config, so restore the raw agents.list input under a plugin-local raw roster type.
* fix(memory-host-sdk): preserve raw default-marker workspace inheritance
Use the shared raw legacy default-marker reader before first-agent workspace inheritance. Preserve explicit ownership resolution and restore the marked secondary-agent regression with the legacy input type.
* refactor: split oversized files below their line-cap baselines
Extract Mistral cache-cost normalization, sessions-send input readers, and Feishu roster collection. Move session-repair and QMD migration coverage into protected sibling suites and consolidate existing test fixtures without dropping assertions.
* fix(ci): clear lint, Docker e2e boundary, and ratchet failures for the roster cutover
Keep the npm Telegram live runner on a local historical-config type instead of importing src, fix oxlint diagnostics in converted tests, move the agents.list runtime projection compat record into its own module, split branch-grown files back under their line-cap allowances, and shrink the assertion-safety baseline for casts this branch removed.
* test: canonicalize fixtures added during main merge
* test(memory-core): type split QMD Doctor fixture as raw legacy config
The QMD cases moved into doctor-contract-api.qmd.test.ts lost the raw pre-Doctor config type, so check-test-types rejected their agents.list fixture. Share RawLegacyDoctorConfig from the test support module and use it in both files.
* fix(doctor): name canonical agent workspace paths in removed-workspaces warning
The warning reads agents through listAgentEntries, so it now labels configured workspaces as agents.entries.<id>.workspace instead of the retired agents.list path.
* test: type preserved canary inputs as legacy rosters
* refactor(gateway): move transcript replay ledger off thread
Route ledger begin, terminal completion, and exact discard through the existing shared-state broker and placement mutation owner. Preserve live grants, native receipt settlement, ordered replay, and fresh-claim rollback cleanup. Await pending and terminal persistence around the existing transcript application.
Also repair the inherited async session-manager fixture in worker claim recovery. Validation covers 100 focused tests, zero caller-thread ledger SQL, Gateway runtime build, type/lint guards, zero cycles, and P2 review. The inherited env-name budget remains unchanged.
* test(worker): retain harness storage identity across worker startup
Capture the Gateway transcript storage environment before the in-process worker changes process.env. Keep the production RPC deadline so cold worker admission does not inject extra timeout faults into exact replay-count tests. Production code, test deadlines, and assertions are unchanged.
Share repeated tooling parsing, projections, and fixture transforms while preserving command and generated-output contracts. Repair the OpenGrep help range so bootstrap code no longer replaces documented usage.
* fix(workers): keep running turns on their original session store
* fix(workers): stop new transcript submissions after cancellation
* test(workers): assert cancellation stops new transcript writes