Set main to the shipped stable version 2026.9.1 (root, apps, plugins, and
version-owned generated metadata via `pnpm release:prepare`), make the
`## 2026.9.1` changelog section identical to the tagged release branch, and
carry the native locale refresh that the release preflight requires.
Release: https://github.com/openclaw/openclaw/releases/tag/v2026.9.1
npm: openclaw@2026.9.1 (latest, beta); 89 @openclaw/* plugins at 2026.9.1.
* chore(deps): refresh cooled packages and trusted Codex
Refresh 17 direct targets and owner-constrained transitive families using the
fixed 2026-08-25T02:09:07Z cutoff. Preserve the seven-day policy, trusted Codex
family and exact grammY exceptions. Pair native digests, runtime constants,
current-version documentation, UI boot manifest and Vercel lock fingerprint.
Apply only the approved TypeBox/Codex override bumps and remove the obsolete
Mailparser HTML-converter override now owned directly by Mailparser 3.9.16.
Consumer validation exposed an empty-reply outcome bug: final payload filtering
could report failure without notifying dispatch, hiding the diagnostic from
Gateway clients. Record failed outcomes at both existing payload failure
producers. Preserve deliberate silence, continuations and committed delivery.
Regression coverage checks directive-only output, real Gateway/TUI errors and
successful subsequent turns. Align the reset assertion with its existing
clear-context boundary; no reset behavior or schema changes.
Clarify release-only changelog edits in contributor guidance. No changelog,
OpenClaw release version, new configuration, or protocol version changes.
Proof: full builds, 993 dependency-owner tests, 111 reply/Gateway tests, 28
original-order PTY cases, full static/package checks and 29 repair checks;
exact-tag Codex protocol gate; real native SDK/Codex/CUA probes and inspected
synthetic Control UI before/after screenshots/video. The loaded-host PTY retry,
three preexisting exploratory library defects and partial advisory coverage
remain documented, not presented as a clean upstream security sweep.
* fix(codex): align catalog and fixture runtime versions
* test: expose Windows gateway cleanup failures
Preserve original cron assertion errors and report bounded taskkill/process/pipe diagnostics without changing shutdown policy or deadlines. Correct the Codex model/list cache-side-effect wording. The original Windows failure still requires diagnosis from native CI evidence.
* test: align native validation and late-filter proof
Keep Windows projects serial within each machine while retaining both matrix jobs and all assertions. Use valid Responses events and a late-filtered heartbeat marker to protect the terminal-failure callback after upstream streaming changes. Assert the exact error and successful next turn, not erasure of earlier PTY stream history.
* test(ci): align Windows guard with serial projects
* chore(deps): regenerate boot groups after integration
* test: remove empty package manifest suites
Delete eight plugin-only registrations that declare no assertions. The existing manifest helper registers only dependency-ownership and host-floor checks, so these rows fail Vitest collection while protecting no contract. Preserve all 501 manifest/dependency assertions; the original scoped command now passes. Independent Codex review found no actionable P0 issues.
* fix(talk): retain playback ownership until the player drains
Integrate the focused playback-owner repair from
59c2767beed12c101dc52225dc20d1e5692af3e6 in #136049 to unblock the native
CI failure in dependency refresh #135177. Remove estimated-duration
completion; only the generation-checked PCM player result completes normal
output. Explicit cancellation, clear, replacement and teardown retain their
existing ownership.
Keep the turn, playback marks and microphone echo suppression while queued
audio remains pending. The deterministic regression uses the existing
microphone timestamp seam; the original stale-player failure case is
unchanged. Document actual-drain behavior for Apple clients.
Also retain the canonical boot-generator refresh after the required conflict
rebase: main's gateway-suspend schema and download helper join the captured
shared boot group. No manual budget change or new dependency selection.
Local focused Swift proof passed 35 tests in four suites with synthetic
transport/capture/player boundaries. Full candidate isolated P0 review is
scoped-clean. Hosted toolchain parity and remaining landing gates remain
required; no merge-recovery or publication bypass.
* chore(deps): refresh eligible seven-day npm dependencies
* docs(plugins): align embedded TypeBox dependency pins
* test(deps): align evidence and Escape ownership
* fix(ci): repair native PID imports and cancellation assertions
* test(ui): make effort Escape ownership explicit
* fix(agents): keep error presentation on prepared policy
* fix(agents): preserve loaded provider policy in error presentation
* fix(agents): carry prepared provider owners into lifecycle errors
Preserve endpoint-owned recovery guidance for custom provider routes in terminal events and callbacks. Reuse the prepared model handle and full-signal classifier, with a real Agent/AgentSession boundary regression.
* fix(agents): reconcile explicit diagnostic ownership and structured errors
Keep presentation on explicit prepared owners, preserve full assistant error facts ahead of generic request wrappers, and retain raw-schema diagnostics. Carry prepared owners into terminal observations and prove source/compiled scope boundaries. Complete the shared attempt fixture with the real model-handle getter.
* fix(agents): carry full classified facts into safe failure copy
Share explicit-owner assistant classification between direct formatting and the user-facing wrapper. Preserve structured codes, types and body evidence in safe provider/model/status copy, including message-less failures, while retaining raw-schema diagnostics and ownerless policy boundaries.
* fix(ui): keep Home work context lazy and current
Let the existing deferred assistant panel prepare page work context once,
using the shell's validated route facts. Keep explicit agent ownership
through global/main aliases and refresh the quoted reference when session,
agent or Gateway snapshots change.
Reuse the frozen refinement from PR #134059:
6e2a8f9550e6e6da957b0352fa674024f198118e.
Add source-bound roster-refresh/send proof, extend the existing owner
fixture for snapshot updates and cleanup, and regenerate the boot manifest
for the pinned dependency graph. Startup gzip is 347243 B under the
unchanged 347353 B gate. The UI repair removes two production lines net.
* test(agents): align generation fixtures with prepared metadata
Use the captured main generation-scope contract in lifecycle and
source/compiled provider-owner fixtures. Remove its retired config input
while preserving provider selection and empty-generation fencing.
Integrate captured main 10564e2 with the Home context refinement from
PR #134059 and the assistant dock cleanup from PR #134435. Preserve the
existing contributor credit and canonical catalog owner already on main.
The integrated candidate passes the normal full build, scoped checks,
679 original-order model cases, 400 backend owner cases, both catalog
E2Es, 290 UI cases and 18 browser cases. Final grouped startup gzip is
347299 B under the unchanged 347353 B enforcement limit.
* refactor(ui): keep submission projection in lazy chat owner
Keep the app store responsible for bounded retained bytes and client lifetime.
Move receipt adaptation and display retirement into the existing history
projection owner, shared by both lazy chat consumers. Preserve missing-store
behavior and the retained-prompt, attachment and reconnect contracts.
Continue the retained-submission owner from PR #134059
(0f3e17e56b).
Validation: 808 owner tests, 21 Chromium cases, grouped-bundle Home and
retired-prompt proof, changed checks and fresh full-candidate autoreview.
Startup gzip: 347588 -> 347320 bytes; unchanged limit 347353.
* feat(channels): add channel-owned setup contracts
* test(channels): align legacy setup fixtures
* chore(channels): regenerate config and SDK baselines after rebase
* fix(update): run fresh doctor after current-process core changes
* fix(channels): align add pre-scan with execution precedence
* style(cli): format channels-cli test additions
* fix(channels): restore option-before-positional channel resolution via metadata arity scan
* fix(channels): keep help flags out of metadata arity escalation
* test(update): mock fresh post-update doctor in current-process suites
* style: format review fixes and correct entrypoint mock type
* fix(channels): register only modern contract options for dual-publishing plugins
* test(update): align downgrade suites with fresh-doctor child invocation
* docs(channels): record empty-contract and input-forwarding invariants
* fix(line): keep the shipped --token switch as a channel access token alias
* fix(signal): stop treating exact cross-family loopback endpoints as bind-aligned
* chore(config): regenerate docs config baselines after second rebase
* style: format rebased channels add tests
* fix(channels): enforce field-key and flag-name agreement in setup contracts
* fix(signal): detect container endpoints for bare --http-url setup
* fix(signal): ignore unconfigured accounts in transport collision checks
* fix(channels): validate negated setup flags in contract and normalizer
* fix(signal): preserve existing transport kind when setup detection is unreachable
* style(signal): use direct boolean check in collision guard
* style(signal): type test config literals
* docs(update): record two-read design of fresh-doctor validation gate
* fix(channels): satisfy post-rebase architecture gates
* docs: refresh channel setup map
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* feat(imessage): add native poll action
Wire the imsg CLI 'poll send' bridge command into the iMessage channel
message-tool action surface, mirroring the existing Discord poll action.
Adds the 'poll' action (gate: polls), a sendPoll runtime, selector-gated
capability advertisement (pollPayloadMessage), config type + zod schema,
regenerated channel metadata, docs, and tests.
* feat(imessage): read inbound polls, vote, and suppress vote echo
Builds on the native poll send action:
- Inbound polls now render to the agent as a readable line (question +
numbered options + tallies) instead of the raw 0xFFFD balloon placeholder,
so a received poll no longer reads as an empty message.
- New `poll-vote` action casts a vote via `imsg poll vote`, resolving a
1-based option index / text / UUID to the poll's option identifier.
- message_tool_only echo guard: the model tends to narrate its choice in a
text reply right after voting ("Blue."), which is redundant since the vote
shows on the poll. A new `poll_vote_echo` suppression reason (alongside
inbound_metadata_echo / internal_runtime_context_echo) drops a send/reply
that exactly restates the just-cast vote, using the option label imsg
returns. Extra content passes through untouched.
* fix(imessage): gate poll-vote on imsg poll.vote rpc capability
Released imsg carries the pollPayloadMessage selector (poll create) but
predates the poll.vote CLI/RPC. Gating both poll and poll-vote on that
selector alone would advertise a vote action the released CLI rejects.
Gate poll-vote additionally on the advertised poll.vote rpc method so this
plugin can ship ahead of the imsg release.
* fix(imessage): enforce poll.vote capability at execution, not just discovery
Codex review flagged the discovery gate as bypassable: a caller that already
knows action=poll-vote skips describeMessageTool and reaches handleAction
directly. Add the same imessageRpcSupportsMethod(status, 'poll.vote') check in
the poll-vote execution path (after assertPrivateApiEnabled), so a direct
dispatch on released imsg fails closed with a clear message instead of an
opaque CLI rejection. Adds a negative handleAction test.
* fix(imessage): harden native poll support
* fix(message): validate targets before channel discovery
* fix(message): validate targets before channel discovery
---------
Co-authored-by: Omar Shahine <lobster@users.noreply.github.com>
Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* chore(release): close out 2026.6.10 on main
* chore(release): align native app metadata for 2026.6.10
* chore(release): sync Android 2026.6.10 notes
* docs(changelog): preserve 2026.6.9 history
* docs(changelog): preserve 2026.6.9 history
* refactor: move imessage monitor state to sqlite
* test: use OpenClaw temp root in iMessage state helper
* test: avoid pending promise lint in chat tests
* test: harden gateway ci flakes
* test: align session list merge expectation
Bumps OpenClaw release metadata to 2026.5.31 across package manifests, app version files, plugin metadata, changelog headings, and generated shrinkwraps.
Verification:
- pnpm plugins:sync:check
- pnpm ios:version:check
- pnpm deps:shrinkwrap:check
- git diff --check
- stale 2026.5.30/build-code scan across changed files
- autoreview clean: no accepted/actionable findings
- PR CI green for real gates: Checks, security scans, dependency guard, app lanes, real behavior proof
Known non-code workflow issue:
- label workflow failed because this PR hits GitHub's 100-label issue cap before the size-label step.