Set main to the shipped stable version 2026.9.1 (root, apps, plugins, and
version-owned generated metadata via `pnpm release:prepare`), make the
`## 2026.9.1` changelog section identical to the tagged release branch, and
carry the native locale refresh that the release preflight requires.
Release: https://github.com/openclaw/openclaw/releases/tag/v2026.9.1
npm: openclaw@2026.9.1 (latest, beta); 89 @openclaw/* plugins at 2026.9.1.
* chore(deps): refresh cooled packages and trusted Codex
Refresh 17 direct targets and owner-constrained transitive families using the
fixed 2026-08-25T02:09:07Z cutoff. Preserve the seven-day policy, trusted Codex
family and exact grammY exceptions. Pair native digests, runtime constants,
current-version documentation, UI boot manifest and Vercel lock fingerprint.
Apply only the approved TypeBox/Codex override bumps and remove the obsolete
Mailparser HTML-converter override now owned directly by Mailparser 3.9.16.
Consumer validation exposed an empty-reply outcome bug: final payload filtering
could report failure without notifying dispatch, hiding the diagnostic from
Gateway clients. Record failed outcomes at both existing payload failure
producers. Preserve deliberate silence, continuations and committed delivery.
Regression coverage checks directive-only output, real Gateway/TUI errors and
successful subsequent turns. Align the reset assertion with its existing
clear-context boundary; no reset behavior or schema changes.
Clarify release-only changelog edits in contributor guidance. No changelog,
OpenClaw release version, new configuration, or protocol version changes.
Proof: full builds, 993 dependency-owner tests, 111 reply/Gateway tests, 28
original-order PTY cases, full static/package checks and 29 repair checks;
exact-tag Codex protocol gate; real native SDK/Codex/CUA probes and inspected
synthetic Control UI before/after screenshots/video. The loaded-host PTY retry,
three preexisting exploratory library defects and partial advisory coverage
remain documented, not presented as a clean upstream security sweep.
* fix(codex): align catalog and fixture runtime versions
* test: expose Windows gateway cleanup failures
Preserve original cron assertion errors and report bounded taskkill/process/pipe diagnostics without changing shutdown policy or deadlines. Correct the Codex model/list cache-side-effect wording. The original Windows failure still requires diagnosis from native CI evidence.
* test: align native validation and late-filter proof
Keep Windows projects serial within each machine while retaining both matrix jobs and all assertions. Use valid Responses events and a late-filtered heartbeat marker to protect the terminal-failure callback after upstream streaming changes. Assert the exact error and successful next turn, not erasure of earlier PTY stream history.
* test(ci): align Windows guard with serial projects
* chore(deps): regenerate boot groups after integration
* test: remove empty package manifest suites
Delete eight plugin-only registrations that declare no assertions. The existing manifest helper registers only dependency-ownership and host-floor checks, so these rows fail Vitest collection while protecting no contract. Preserve all 501 manifest/dependency assertions; the original scoped command now passes. Independent Codex review found no actionable P0 issues.
* fix(talk): retain playback ownership until the player drains
Integrate the focused playback-owner repair from
59c2767beed12c101dc52225dc20d1e5692af3e6 in #136049 to unblock the native
CI failure in dependency refresh #135177. Remove estimated-duration
completion; only the generation-checked PCM player result completes normal
output. Explicit cancellation, clear, replacement and teardown retain their
existing ownership.
Keep the turn, playback marks and microphone echo suppression while queued
audio remains pending. The deterministic regression uses the existing
microphone timestamp seam; the original stale-player failure case is
unchanged. Document actual-drain behavior for Apple clients.
Also retain the canonical boot-generator refresh after the required conflict
rebase: main's gateway-suspend schema and download helper join the captured
shared boot group. No manual budget change or new dependency selection.
Local focused Swift proof passed 35 tests in four suites with synthetic
transport/capture/player boundaries. Full candidate isolated P0 review is
scoped-clean. Hosted toolchain parity and remaining landing gates remain
required; no merge-recovery or publication bypass.
* feat(buzz): preserve root identity across named account setup
Keep named credentials, rooms, lifecycle, and setup writes account-owned; preserve static root-layout policy through Doctor without importing disabled plugin runtimes. Fixes#130062.
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(buzz): resolve setup credentials without disabling accounts
Preserve authored secret references and reject unavailable credentials without saving account changes. Require an authorized room selection to finish setup.
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(channels): distinguish preserved roots from empty promotion
Keep ordinary env-only account promotion seeding accounts.default while an
explicit preserve-root owner keeps its root intact, including empty roots.
Use one canonical promotion result and remove the unused keys-only wrapper.
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(outbound): resolve local account defaults before formatting
Carry one locally resolved account through prefixing, target resolution and
delivery. Preserve explicit, host and binding precedence, and keep omitted
account input absent when delegating to a remote Gateway.
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(buzz): report the selected account's missing room path
Use the canonical account configuration path in startup recovery guidance.
Cover missing, empty and disabled room lists for implicit root, named and
explicit-default identities before opening a relay or recovery store.
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(buzz): settle account work before scoped reloads
Keep sibling identities connected during named-account edits. Fence profile
publication after cancellation and join pending profile work after relay close
so replacement account lifetimes cannot overlap stale profile effects.
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(gateway): reconcile channel lifetimes after secret resolution
Route no-op secret publication through the existing reload transaction and
merge resolved channel effects with its authored restart scope. Leave cold
accounts stopped without masking lifecycle failures or undoing manual stops.
Preserve shared-auth generation ownership across provider-only changes.
Discovered while verifying Buzz multiaccount setup and isolated recovery.
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(buzz): align setup reload policy and account guidance
Declare isolated named-account reloads on the standalone setup descriptor.
Cover both public descriptors and document nested room and auth-tag paths,
including the implicit-root-only environment fallback.
Co-authored-by: yu-xin-c <2182712990@qq.com>
---------
Co-authored-by: yu-xin-c <2182712990@qq.com>
* fix(channels): validate headless channel setup
* docs(channels): document headless provisioning
* fix(channels): repair setup metadata typing
* chore(channels): regenerate official channel catalog for env metadata
* fix(slack): keep mode-conditional env contract plugin-owned
Static --use-env declaration keeps only the unconditional SLACK_BOT_TOKEN;
socket-vs-HTTP conditional requirements (app token, signing secret) stay in
Slack's own setup validation so HTTP mode no longer demands an irrelevant
SLACK_APP_TOKEN.
* chore(sdk): regenerate api baselines and catalog after rebase
* fix(slack): align manifest env declaration with runtime contract
* chore(sdk): regenerate api baselines after rebase
* chore(sdk): regenerate api baselines after rebase
* chore(sdk): regenerate api baselines after rebase