Bind prepared selections to current library and profile authority across admission waits, including rollback and unknown native commit outcomes. Preserve private revision disclosure and worker error identity. Native import and mutations remain for the follow-up; retain the shipped synchronous SDK readers.
* feat(update): adopt immutable installations and prepare sealed generations without activating them
* fix(update): repair immutable preparation dependency boundaries
Register the packaged immutable launcher as a Knip executable entry and retain
the immutable SQLite read worker closure in the PR wrapper inventory.
Extract startup installation facts and package activation runtime types at their
leaf contracts. Migrate all consumers and remove the broad reverse dependencies
that made both static import cycles lane-caused. Keep lazy initialization and
cancellation with the Gateway lifecycle owner.
* fix(update): use typed immutable record size predicates
Express the existing 64-KiB JSON byte bounds through Kysely expression builders.
Preserve BLOB casts, bound values, and null filtering at the immutable record owner.
The real SQLite store tests, full architecture command, staged changed-file gate,
and independent review pass. The schema and durability contract are unchanged.
* fix(state): stop polling pinned SQLite handles
Publish idleness from the common borrower release owner, including maintenance
ownership transferred to an independent reader. Remove the read-only adapter's
separate scheduling policy and consolidate asynchronous completion/cancellation.
Keep authority checks after WAL shutdown and preserve failed cleanup for retry.
Idle expiry now waits for pinned readers instead of rearming. The existing
30-minute window, transaction retries, explicit disposal and durable state stay
unchanged. Regression coverage proves zero timers after close, late release,
transferred maintenance ownership, and ownership lost during awaited cleanup.
The original timer and incomplete release handoff each fail their regression;
the final candidate passes the real SQLite, borrower, cleanup, status and CLI/UI
proof on Blacksmith Testbox. Native staged checks run on the isolated Linux rig.
Related: #163799
* test(e2e): preserve relabeled candidate content inventory
Use the existing fixture version-stamping owner when the published-driver
candidate is older than the driver. Refresh the authored build-info hash while
preserving opaque build identity and detection of unrelated package corruption.
Remove the duplicate stamping loop and unpersisted relabeledFrom expectation;
the relabel receipt already records the original and target versions.
The original published-driver cell installed the candidate but correctly
rejected its stale content inventory. Focused fixture tests and native changed
checks pass on Blacksmith Testbox; independent review found no actionable issues.
Related: #163799
* test(browser): preserve the MCP module between pooled test files
Read the harness's registered Chrome MCP mock through a normal dynamic import.
Vitest importMock also populates the real module ID with empty-body metadata;
pooled cleanup can preserve that body and leave a later real import without its
exports. No extra mock loader or cache policy is needed for this assertion.
The ordered server.agent-contract-core -> server-context.list-profiles replay
reproduces all three CI failures before this change and passes all 59 tests
afterward. The full four-group CI bundle passes 1,937 tests with 66 skipped on
Blacksmith Testbox. Existing assertions, production code and scheduling remain
unchanged.
Related: #163799
* wip(secrets): settings metadata worker cutover (parked: #150992 security overlap in configureGatewayForSetup; store-bound question callbacks need async authority)
* refactor(secrets): finish worker metadata cutover
Move ordinary settings metadata reads and set/delete/rollback through the shared-state workers. Await acknowledged persistence before settings and credential-question success, retain private question settlement across reset, and preserve exact-writer compensation and released synchronous SDK methods.
* test(secrets): await fixture writes and preserve worker routing order
Await protected credential seeding before Gateway startup closes parent-side database admissions. Keep the Gateway worker inventory sorted for canonical CI and CLI selection.
The original routing failures reproduced in five runs per file and passed five times per file on the merge base. The corrected tooling tests pass all 533 cases; changed-file checks and P2 review are clean.
Publish committed name metadata through both cron mutation owners and refresh
Gateway display projections at asynchronous boundaries. Retain physical
generation fences and reject unprepared or invalidated lookups instead of
reading SQLite on the caller thread. Preserve rename/delete labels, including
hidden SSE prefix refreshes and malformed peer metadata.
Builds on #160448. No schema, retention, durability, configuration, or update
contract changes. Native name reads retain the Doctor transaction-hook contract.
* refactor(sessions): move conversation delivery ledger to workers
Preserve delivery FIFO, idempotency, correlation, and live admission across worker waits. Keep reply commits consumed if waiter authority expires before the optional audit artifact. No schema or stored-state format changes.
* refactor(sessions): type delivery query results
* test(sessions): retain delivery worker fixture ownership
* test(sessions): bind recovery fixtures to queue state
* refactor(sessions): move cold selection and protection to workers
Keep live work admissions and cooldowns on the host while selecting and rechecking stored protection in the archive worker. Retain logical admission scopes and lexical artifact paths, and use the existing execution owner for ordinary cold maintenance opening. No schema, retention, configuration, or update behavior changes.
* fix(sessions): retain freelist pragma guard annotation
* refactor(state): register worker operations once per domain
Infer shared-state worker command contracts from lazy per-domain handler tables. Migrate Web Push, APNs, worktree registry operations, and fleet registry while preserving the existing broker and transaction owners.
* refactor(sessions): run health store summaries in history worker
* refactor(state): register worker operations once per domain
Infer shared-state worker command contracts from lazy per-domain handler tables. Migrate Web Push, APNs, worktree registry operations, and fleet registry while preserving the existing broker and transaction owners.
* refactor(memory): move retained index reads into workers
* test(memory): align fixtures with worker read ownership
Repair the ten fixture failures exposed by retained worker reads. Install the embedding generation and token budget, retain a file-backed startup owner, and preserve the explicit scheduler-yield proof through source-wide snapshots.
Follow-up to #161053 (shared-session emoji reactions).
Reaction writes now run through the SQLite worker admission the sibling
session stores use (runOpenClawAgentWorkerWrite); the native path stays
only for process-held incognito databases the worker cannot reopen by
path, and the handler revalidates live authority around the awaited
write.
The plugin action dispatch path awaits onPlatformSendDispatch right
before the synchronous handoff fence, exactly like the send path, so the
reaction mirror re-reads the conversation binding at the final handoff
and refuses a message whose conversation was rebound while the action
runner prepared delivery.
Channels with one bot reaction per message (Telegram bots, WhatsApp)
declare the new optional ChannelPlugin.capabilities.reactionSlots =
"single"; when a person removes one emoji while others remain, the
mirror re-sets the newest surviving emoji instead of clearing the slot.
Multi-slot channels are unchanged.
Also trims redundant scaffolding in the reaction handler, kernel, UI
component and worker.
Proof: 119 focused tests across store, handler, dispatch and UI; mocked
Gateway reactions e2e; typecheck lanes; database-worker inventory check;
live two-person Gateway proof with the qa-channel mirror reporting
delivered through the final-dispatch hook.
* refactor(cron): await standalone quarantine registration
* docs(db): refresh quarantine worker inventory
* test(cron): colocate legacy crontab warning coverage
Move the existing warning cases to their owning suite while preserving their assertions. This leaves room for the quarantine SQL regression under the Doctor fixture line-count ratchet and avoids unnecessary SQLite fixture setup.
* docs(sqlite): refresh worker inventory after main merge
Regenerate the existing inventory from the merged source. Keep the quarantine classification and PR production delta unchanged.
People who can send to or suggest in a session can put emoji reactions on
any saved prompt or reply in the Control UI. Everyone reading the session
sees the chips update live, the agent sees each reaction as a System line
on its next turn (never woken for it), and reactions on prompts that came
from a channel are mirrored back to that channel as the bot's reaction.
Operators whose role only permits viewing see the chips without controls.
Storage is a same-version `session_reactions` companion table in the
per-agent database, installed on open like the session-sharing tables and
inert for older builds; reactions never touch transcript bytes. Two Gateway
methods (`session.reactions.set`/`list`) and one session event carry the
state, the hello frame projects the operator's session cap so the UI applies
the server's rule, and reaction reads run in the admitted history worker. Channel
mirroring keeps one bot reaction per emoji, dispatches in commit order, and
rechecks reactor authority and the source conversation before channel I/O.
The picker is a tapback-style pill below the message with six quick emoji,
pressed state for your own, keyboard navigation, and a custom entry that
applies a complete emoji the moment it lands (IME-safe, single emoji only).
Chips animate on change and list reactors with "You" first.
Live proof on a real Gateway with two identities and a QA channel; storage,
Gateway, UI, e2e and authority tests; published-2026.9.6 upgrade check.
* fix: PR mentions appear as unrelated session banners
Keep PR banners tied to the working branch instead of assistant reply links. Remove the transcript discovery cache and its unused version reader while retaining publication results and branch lifecycle checks.
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
* fix: PR mentions appear as unrelated session banners
Worked on by:
- @vyctorbrzezowski
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
OpenClaw-Publication: 263f80c6-d9ef-47f7-8a40-5251b869f0dd
---------
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Remove Tasks and TaskFlow runtime, APIs, CLI, SDK surfaces and panels after the Cron, session, native execution and media completion ownership cutovers. Preserve stored rows and import provable legacy native assignments through Doctor; ambiguous ownership stays untouched with a warning.
Follows #158221, #158217, #158225, #158222, #158702 and #158776. Related: #156532. Task-specific public APIs retire immediately; retained responsibilities use their existing owners.
Maintainer-authorized administrative landing after full CI run 36312986498 attempt 2 passed on 274595e2, with subsequent actual conflicts reviewed and focused checks passing. Current PR CI preflight hits the 64 KiB changed-path metadata limit before tests (run 36335042695); its duplicate security-review status mirrors that planning failure. Review and scoped proof are recorded in the PR. Published 9.4 native import is proven; remaining native completion and 9.4 rollback witnesses are explicitly unproven.
Use transactions on the actual SQLite state and device databases for ordinary writes. Remove redundant coordination databases, transport, and exclusion layers while preserving bounded process ownership for startup, schema work, and offline maintenance.
Tie test and QA scratch retirement to settled workers and native resources, preserve active plugin captures, and join SDK declaration compiler processes before synchronous semantic rendering.
Validation: main-tier CI on 5e731c1f64 had 144 successful jobs and one Windows ACP initialization timeout. Qualified unchanged replay 36314027585 passed all 896 tests with the original 48-file order, six projects, toolchain, and deadlines. The original timeout remains unexplained and recorded in the PR. Reviewed main-conflict integration through 39caa592ef passes focused SQLite, Doctor, image, and Cron proof plus affected typechecks and lint. No accepted actionable independent-review findings remain.
Squash landing of #157413 under explicit maintainer authority to resolve logical main drift and admin-merge using the completed CI evidence. No PR-specific schema or public configuration migration.
## What Problem This Solves
The shared channel ingress queue still performs operational reads and writes synchronously on the Gateway thread, despite exposing an asynchronous API.
## User Impact
Inbound persistence and replay use the existing shared-state SQLite broker. Admission returns only after commit; claim fencing, per-account ordering, dedupe, retention, and accepted-write settlement remain intact. Operational listings observe earlier committed writes and still create a missing database for ordinary read-write queues. Explicit read-only inspection remains noncreating.
Update behavior: no schema, stored-byte, config, port, webhook path, signature, dedupe-window, or retention change; no migration or operator action. The maintainer approved the worker-access change and the broker-ordered listing adjustment. Legacy pre-May-31 Telegram spool import and Telegram startup profiling remain documented follow-ups, as directed.
## Why This Change Was Made
All twelve mutations and the operational listings cut over together to preserve one FIFO owner. Diagnostic failed-health, pressure, and account discovery already use read-only workers. Channel parsing and lane policy stay on the host; the worker verifies the prepared ordered snapshot before applying a claim or recovery decision. Custom claim clocks are sampled at transaction admission. Accepted commits settle even if caller authority later revokes.
The drain consumes one coherent pending/claimed snapshot. `listUnsettled` is optional for existing external queue implementations through the next SDK major. `purge` accepts an optional cancellation signal, and Telegram passes its existing signal. Runtime construction binds live plugin authority to every operation, replacing the purge-only wrapper. The existing table and database version are unchanged.
Deletes the main-thread queue SQL path and superseded runtime wrapper. The final write cutover is intentionally larger than the fixture slices because mixing native and broker mutations would break admission ordering. Earlier slices removed Telegram directory helpers and consolidated shared fixture scaffolding.
Production +964/-942/net +22; tests and test support +837/-315/net +522; docs +41/-18/net +23; tooling +3/-0/net +3. The runtime growth preserves authority and settlement across a worker boundary. All earlier slices plus this candidate total production net +446; test fixture consolidation reduced the original +517 growth to +386 before the final routing/regression coverage.
## Evidence
Provider: blacksmith-testbox. Lease `tbx_01m3f53n667mcj031n55vm5tj8` ([run](https://github.com/openclaw/openclaw/actions/runs/36251856365)), frozen install, `pnpm tsgo:core` (41.13s), `pnpm tsgo:extensions:test` (78.55s), and inventory generation/check passed. Nine focused owner files passed 144 tests. Single-worker wall cost per file: queue 33.02s; claim ownership 9.28s; readonly access 8.07s; pruning 7.20s; drain lanes 8.50s; monitor 9.44s; plugin-state runtime 14.12s; registry runtime-config 11.08s; Telegram monitor 15.15s. The two changed tooling files passed 381 tests in a combined 192.99s single-worker wall.
The additional 72-file per-config run used `pnpm test <explicit routed ingress paths> --maxWorkers=1`: 128 core tests and 855 extension tests passed, with two fixture failures over 518.11s. LINE and MS Teams waited for a `listPending` spy that the coherent snapshot intentionally replaces. Both fixtures now capture the real monitor and await its pump, preserving the eight-delivery cap and queued-row assertions.
Lease `tbx_01m3faw6necd61h11wcf6se4hs` ([run](https://github.com/openclaw/openclaw/actions/runs/36257798905)) proved the corrections: `pnpm test extensions/line/src/webhook-spool.test.ts --maxWorkers=1` passed 14 tests in 31.09s; `pnpm test extensions/msteams/src/msteams-ingress.test.ts --maxWorkers=1` passed 15 in 18.32s. Extension types (79.74s), runtime import cycles (9.38s; zero), Madge cycles (26.36s; zero), SDK exports (0.22s), and docs sanity (54.79s) passed. The existing pruning case with padded protected IDs passed (five tests, 8.46s). Negative controls failed for the intended reasons: removing normalization deleted a protected row; raising either channel's cap to nine caused nine deliveries where eight were required. The production controls were restored and checked.
Worker routing is covered by actual queue operations with calling-thread SQLite primitives refusing execution. Regression probes also cover missing database creation, committed-then-list inside an older ambient snapshot, live authority after awaited policy, custom-clock transaction grants, post-grant settlement, and coherent lane inspection. No weaker guards or assertions were substituted.
Deslop is clean. Codex P0–P2 review is clean after supplying the full unchanged worker kernel: two earlier allegations were disproven by existing normalization and corrupt-row filtering, with direct tests. The final review used a byte-verified capture of the full 35-file diff and the broker/kernel context. Rebase onto `4ab72dd0d2` was patch-identical. The maintainer authorized GitHub exact-head auto-merge; required CI remains the gate.
Fresh proof on published source head `b828403ef8f309ffda1e4859f6eca3268fdc66cb` (same lease): queue/claim/readonly regression suites passed 47 tests in 38.51s; regenerated inventory and its check passed (545 source files, 2543 primitive calls). `pnpm plugin-sdk:api:diff --base 4ab72dd0d2 --head b828403ef8f309ffda1e4859f6eca3268fdc66cb` passed in 242.79s; exports passed in 0.17s. The SDK acknowledgement digest is `e2cba13f`. No entrypoints were added or removed; the additive queue contract is intentional and documented. Final head `0b24c42b9242b07e1a7c60147b4cba5f46d5bd91` only refreshes two generated source-line references.
Merged-main signed-SMS SIGKILL/replay proof is the remaining post-merge task and will be recorded in this PR.
## Stack
Landed: #157687 → #158203 → #158233 → #158288 → #158412 → #158477 → #158628 → #158637 → #158860 → #158887 → #158896 → #158928 → #158933 → #158980 → #158987 → #159006 → #159008. This is the final atomic broker cutover and inventory slice. Signed-SMS crash/replay proof follows on merged main.
* refactor: remove TypeScript 6 from plugin runtime and tooling
Keep source plugin loading on Jiti and native module transforms, move development analysis and declaration builds to TypeScript 7, and preserve captured loader and input ownership contracts. Scaffolds compile to the same entry path without shipping a compiler in production.
* refactor: use native checker for restart preflight detection
* fix: keep test-directory docs out of native helper scans
* fix: preserve native compiler tooling across CI runtimes
Keep compiler-backed tests on the supported Node transport, preserve declared Windows aliases and partial-source analysis, and bind relocated SDK reports to their installed compiler. Retain strict package input admission and the existing fixture assertions.
* test: compare messaging guard diagnostics without sorting
* fix: bound native tooling memory and preserve bootstrap loading
* fix: bound native declaration builds with tsdown scheduling
* fix: retire compiler-only helpers from installed packages
* test: migrate routing import scan to native parser
* test(ui): wait for recovered model catalog receipt
* perf(state): move transcript reads off the Gateway thread
Reuse the existing history worker for durable transcript search and cursor deltas. Keep current sharing checks and display projection on the Gateway, and document the remaining database worker migration with a reproducible inventory.
Testbox proof: 5,000 rows and 50 viewers reduced caller-thread CPU by 96.7% for search and 7.3% for cursor history. Golden responses, 211 focused tests, build, type/lint/storage gates, inventory verification, and docs links passed.
* perf(state): isolate transcript search worker contracts
Move search request/result types into an import-free contract so worker protocol types do not depend on the query implementation. Register and document the inventory generator package commands.
Fix the architecture and unused-file CI failures. Exact failed guards, export scanning, core types, real-worker golden tests, formatting, and inventory regeneration passed on Testbox.