* fix(gateway): preserve work during recovered Node restarts
Let Unix Node recovery wrappers respect the existing Gateway stop budget.
Share startup-safe command classification and deadline facts, and resolve
managed restart intent against the live serving owner in its write
transaction with current update authority.
Preserve the existing public PID intent API, record format, and Windows
behavior. Keep cold lifecycle test preparation outside timed hooks.
Inspired by @ly85206559's wrapper-grace approach in #147054; this repair
is independently authored from main. Related: #146956. Windows cooperative
shutdown remains a follow-up.
* refactor(gateway): stabilize restart callback and test setup
Declare receiver-independent restart intent callbacks as arrows and retain typed signal spy handles for lint-safe assertions. Move cold lifecycle imports into test collection so worker preparation cannot consume timed setup hooks.
* fix(plugins): preserve authored config through runtime load plans
* feat(judgments): add typed provider runtime and plugin SDK
* feat(plugins): add per-agent decision models
Add an opt-in decisionModel role for typed choices, scores, and boolean
probabilities, with global defaults and per-agent inheritance or disablement.
Keep provider lifecycle and prepared credentials host-owned, and expose
manifest-only decision choices separately from conversational model catalogs.
Adapt the provider foundation from #152237 to the decisions contract. Existing
configurations keep decision calls disabled until a model is selected.
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
* fix(plugins): complete decision inspection and preserve authored config
Expose optional decision-provider health through the Gateway wire schema
and generated native DTOs. Preserve the landed SecretRef prerequisite’s
identity behavior for unchanged activation plans. Move model mocks into
one private sibling factory without expanding the public helper surface.
Validation: 51 handler/protocol tests, 18 post-extraction tests, 52 runtime
and integration tests, generated protocol checks, and clean P0-P2 review.
The SDK surface-budget increase remains pending maintainer approval.
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
* perf(plugins): reduce decision overhead and unnecessary reloads
Keep one full provider input snapshot and an independent question rubric. Recognize decision-only catalog providers with the existing normalization policy, and reload plugins only for decision-model changes while preserving roster actions. Apply the approved SDK surface increment and behavior-neutral cleanup.
Validation: 58 runtime/config/loader tests, 610 Gateway regression/sibling tests plus 15 final catalog cases, full core typechecks, scoped lint and clean managed review. A 143155-attempt synthetic stress run settles all 18104 provider calls at max concurrency four.
* fix(plugins): preserve reload boundaries and decision test contracts
Materialize only present decision-selector leaves so Telegram account creation/removal retains its parent lifecycle action. Select UI controls by model role, preserve independent chat and decision catalogs in tests, remove an unused probe, and rebalance existing typecheck shards without raising their limits.
Validation: 588 reload tests, 58 shard/loader tests, 38 UI catalog tests, 9 browser tests, affected typechecks, unused-file scans, and clean managed review.
* test(ui): address model pickers by role in gateway flows
Disambiguate Primary from the new Decision picker in the real-Gateway catalog test, alias browser test, and Agents view assertions. Preserve draft and publication checks. Unit/browser/typecheck proof and managed review pass; real-Gateway execution follows on the integrated build.
* test(plugins): isolate runtime metadata and preserve shard headroom
Move the existing lazy-runtime metadata contract intact into its own focused module. Group CLI program tests with commands so newer main tests keep every typecheck shard within existing limits. No production changes or limit increases.
Validation: 57 tests, four typecheck graphs, canonical line guards against the CI main snapshot, targeted lint and clean managed review.
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
* refactor: reuse fs-safe 0.16 filesystem helpers
Upgrade core and plugin dependencies to the published release. Delegate missing-suffix probing and positional snapshot copying while retaining database identity policy, cache, durability, and cleanup ownership. Remove 333 production lines and document bounded alias diagnostics.
* fix: retain exact directory identities for fs-safe 0.16
Preserve bigint directory identity in updater handoffs, backup publication, and snapshot staging. Keep initial receipts through durability checks, retain published update-state compatibility, and share snapshot directory policy. Cover real publication phases and large filesystem IDs while documenting the released dependency declaration gap.
* test: record approved fs-safe receipt type exceptions
* test: rebalance Gateway type-check groups
* refactor(test): centralize worker declaration metadata
Replay the reviewed first tooling layer on the current frozen main base. Keep package activation declarations reserved for the later owning layers; preserve the inherited main build graph and test coverage.
* fix(update): bind recovery admission to existing authority
Replay the reviewed authority layer on current main, preserving the diagnostics import owner. Retain Json (fuller-stack-dev) rollback-journal and Bun regression coverage; restore NORMAL reader policy after rollback-mode admission so retained Bun statements do not hold locks after settlement. Later FD3 custody remains in its owning layer.
* fix(config): retain authority across config persistence
Replay the accepted config authority layer without behavioral changes. Preserve producer-owned write guards through backup, snapshot, persistence, reread, and error settlement.
* fix(plugins): fence convergence with lifecycle authority
Replay the accepted plugin authority layer without behavioral changes. Keep install-record, peer-link, retention, doctor repair, and cohort operations under their existing canonical lease owners.
* fix(update): preserve authority through post-core convergence
Replay the accepted five-file post-core convergence layer without new behavior. Keep config and plugin operations within the existing admitted owner scope.
* fix(plugins): preserve first authority refusal during repair
Keep authority failures outside filesystem warning conversion, retain the first callback refusal through normalized installer outcomes, and join admitted peer repairs before rejection. Preserve the synchronous peer guard and lease-bound index CAS finalizer.
Adapt the Doctor and convergence ownership pattern from Jason Sy in #144130. Focused red/green: 23 failures became 32 passes; full peer and retention controls pass 37 cases. Native review raised an overlapping async callback scenario; source review rejects it because the current per-invocation Doctor path is serial. Root final-effect and installed integration gates remain open.
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
* fix(config): refuse guarded include writes before effects
Reject include-owned mutations carrying inherited authority, explicit assertCurrent, or beforeCommit before Root preparation and backup effects. Remove the unreachable guarded include publisher and retain ordinary include publication and custom-root IO ownership.
Three missing-refusal regressions reproduced before the repair. All 107 cases in mutate, io.write-lock and io.write-reread pass, including ordinary include exclusion and compensation controls. Native P1 review is scoped-clean. The fs-safe final-effect contract and installed candidate integration remain separate draft gates.
* fix(config): retain update authority through runtime activation
* fix(plugins): repair leased authority CI coverage
Remove the unused unleased record writer and seed test fixtures through the canonical store producer. Keep compiled Doctor fixture module identity and direct leased-writer assertions.
Bind registry authority callbacks and correct the focused fixture typing and lint errors without weakening refusal checks. Independent source review and native P0/P1 review passed; runtime and hosted CI qualification remain pending.
* test(plugins): omit redundant deferred type arguments
Use the existing void generic default for the three deferred test controls. The correction emits byte-identical JavaScript and preserves all assertions.
This trivial test-only delta was independently verified after the full L4 P0/P1 review. The earlier focused 295-test and selected typecheck passes remain source-bound; the failed lint surface and unrun export scans still require qualification.
* test(plugins): cover synchronous host-link admission turns
Retain the three filesystem API-entry scheduling controls contributed by Jason Sy (@fuller-stack-dev) in https://github.com/openclaw/openclaw/pull/144316#issuecomment-5632474077.
Cover missing node_modules, stale symlink, and package-copy replacement while preserving the existing synchronous authority contract and test seed helper. These controls observe API-entry timing, not native filesystem-effect atomicity or an observed regression on this source.
Independent exact-block review and fresh full L4 native P0/P1 review passed. Targeted execution of these added cases remains pending.
* fix(update): omit absent config write authority options
Preserve the normal config writer options when no updater authority is supplied. Keep guarded writes unchanged and avoid undefined caller callbacks shadowing prepared options.
* fix(update): bind migrated finalization to candidate runtime
Move the existing worker-local finalization context into the convergence layer without serializing it or changing authority. Preserve the original finalization fence through the shared candidate phase.
Add the actual worker caller-binding regression and candidate lease and executor controls. The unchanged worker regression failed on the parent source; final-head runtime and native qualification remain pending.
* refactor(update): share restart sentinel notification options
* fix(plugins): retain updater authority through package settlement
* test(plugins): verify publication across updater revocation
* fix(test): satisfy updater authority lint rules
* fix(update): preserve first authority refusal through Doctor finalization
* test(update): qualify guarded convergence across current CI lanes
* fix(update): retain live authority in fresh Doctor children
* test(update): preserve Doctor authority in CLI fixtures
* test(update): share legacy Doctor command matching
* fix(config): retain root publication identity for compensation
* test: stabilize backup identity and trace watcher failures
---------
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Reuse final paths for a bounded set of agent IDs and resolved state roots while retaining live environment and legacy-directory resolution. Include output-parity tests and a reproducible benchmark showing 80-82% lower hot-path cost.
Keep public GitHub issues, pull requests, commits, comments, images, and diffs readable beside chat in a resizable, tabbed reader. Preserve external navigation for modified clicks and explicit links.
Move GitHub transport and document mapping into the bundled plugin, and expose the passive reader through the shared plugin contract. Preserve operator plugin controls, managed-preview credential authority, anonymous detail reads, and existing host read-library behavior.
Bind responses to their requested resource, retain rapid reader opens in FIFO order, and cancel stale batches on close or session replacement. Add regression coverage and synchronize heartbeat and attachment tests with their actual completion boundaries.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* chore(deps): refresh dependencies with seven-day release cutoff
Update 20 compatible package versions published by September 11, 2026 at 17:55 UTC; preserve patches, overrides, and incompatible pins.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* chore(deps): refresh dependencies with seven-day release cutoff
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 56ff74cb-22b8-4962-ab53-39496522a822
* fix(deps): preserve docs publishing and align ACP version checks
Retain slugify 2.2.1 and transliterate 1.6.0 so the independent publisher graph and existing documentation anchors remain compatible. Align exact Claude ACP assertions and skill documentation with the updated 0.76.0 manifest pin.
Validation: docs-sync CLI failed before the hold and passed afterward; 11 publisher tests, 26 Markdown/anchor tests, and 326 ACPX tests passed. No production logic, timing budgets, or assertions weakened.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(update): snapshot rehearsal SQLite through online backup
Use the existing async backup path only for disposable rehearsal copies.
Preserve synchronous inspection, bounded worker output, and parent-owned
scratch when worker or monitor termination is uncertain.
Cover concurrent WAL writers, snapshot integrity, cancellation, deadlines,
low-space refusal, and stdout/stderr overflow through the worker boundary.
* test(update): align rehearsal mocks with bounded snapshot runner
Align the canary snapshot mock with the bounded UTF-8 runner. Delegate real progress probes and non-canary children; exclude snapshot-worker results from progress-byte parsing. Preserve timing, cancellation, byte-limit and capacity assertions.
Include the reviewed managed-parent lifecycle assertion grouping that resolves the shared max-lines prerequisite.
These test corrections address failures in the preceding hosted run. Source review and focused static checks passed; behavioral and type qualification must come from the corrected exact-head hosted run. First-hop and native LAND gates remain open.
* test(update): make rehearsal worker fixtures portable
* test(update): scope rehearsal fixtures to worker entrypoint
* test(update): compare equivalent Windows scratch paths
* test(update): stabilize Windows rehearsal qualification
Use append-only committed progress records to avoid the observed Windows rename race while preserving concurrent WAL acquisition assertions.
Include the exact test-only CI prerequisites from #152099 (d339607c) and three duplicate declaration removals from #152028 (3fceb860).
Co-authored-by: Peter Steinberger <steipete@gmail.com>
---------
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Windows owned stdio children now use the existing retained Job owner to confirm descendant cleanup after the parent exits, preserving interactive input and worker IPC.
Keep native support optional: unavailable or failed Job setup falls back to ordinary command startup and reports typed uncertainty. Tree-required cleanup retains state locks and temporary artifacts until extinction is certified; transport-only cleanup remains independent. Claude prompt and skill artifacts are retained with a warning when cleanup is uncertain.
Related: #151325, #150427, #150244.
Validation: exact-head CI run 35354835669 is green, including both Windows node-test jobs; 243 focused tests passed locally on macOS with six native Windows skips. The P1 review is scoped-clean, and all 13 reviewed commits are preserved by a semantic-equivalent rebase. Hosted Windows proof and the capability matrix satisfy the maintainer's compatibility-proof ruling.
* feat(node): update headless runtimes automatically when idle
Stage private packaged node runtimes and activate only after all owned work
and cleanup settle. Preserve pairing and launch options, keep automatic
activations at least 12 hours apart, and leave shared-state migration and
Gateway installation ownership with the normal updater.
Document defaults, opt-outs, runtime version discovery, and recovery.
Support recoverable Windows selector replacement across service restarts.
Refs #151462
* fix(node): complete auto-update integration and settings defaults
Capture the launcher in compiled test runtimes and trusted wrapper inventories, register the package update proof, and use the canonical Kysely read path. Preserve the inherited enabled state in the config UI and align caller tests with the node shutdown lifecycle.
* fix(node): preserve retained plugin work during automatic updates
Require an explicit idle result from plugin commands, preserve older-plugin work, and connect bundled lifetime owners to automatic node updates. Join canceled inference and failed terminal cleanup before command settlement; keep historical state repair with Doctor. Document compatibility and extend installed-package proof for retained legacy plugin work.
* test(browser): align idle-work fixtures with runtime exports
* test(browser): extract proxy request fixtures
* test(node): retain idle assertions across native cleanup
Interrupted Gateway startup, update inspection, and CLI reads could leave large private SQLite staging copies behind. Reclaim abandoned copies through the existing snapshot lifecycle owner while preserving live readers, recent legacy copies, canonical databases, and backups.
Use SQLite lifetime tokens and parent admission to coordinate nested workers. Commit retirement before closing handles and removing data; retain control files until copied data is removed. Recognize released updater layouts and retain the 24-hour legacy age threshold. Cleanup failures remain warnings.
Run asynchronous reclamation in the existing SQLite worker. Callers can cancel independently without terminating a surviving caller's shared pass. When the last caller leaves, settle the current directory before stopping, and let later allocation recover the remaining backlog. Drain snapshot workers before shutdown cleanup.
Validation: exact-head CI run 35266032454 passed with zero pending checks on ab8037229203cc8a42735263637245f09477f2aa. Recorded focused proof passed 203 SQLite tests with one platform skip and 31 Gateway lifecycle tests. Published OpenClaw 2026.9.4 worker proof preserved fresh interrupted copies, reclaimed 202,375,168 aged bytes, and left source bytes unchanged. Review r4 was scoped-clean at P0/P1; the exact-head ClawSweeper review reported no actionable findings or before-merge moves.
Windows CI covers released-layout removal, independent cancellation, and directory-boundary settlement. Native Windows signal interruption and late-worker races remain a documented coverage gap.
Closes#149978. Related: #150091. Thanks to @vyctorbrzezowski, @Glucksberg, and @stwhwing for the production reproductions.
Fix Windows build and test cleanup when descendants outlive their command leader. Retain kernel Job ownership from admission, start owned cleanup on leader exit, preserve bounded terminal output, and release temporary-resource claims only after descendant extinction and output closure are verified. Preserve taskkill diagnostics and report unresolved survivors.
Reuse the native Windows Job bindings and one runtime/compiler entrypoint inventory. Keep CI planning dependency-free and preserve exited Gateway migration guidance. Installed updater behavior and persistent operator state are unchanged; no dependency, schema, configuration, deadline, retry, or baseline changes.
Validation: exact-head CI run 35229160236 is green, including both Windows shards. Recorded current-head Linux proof has 220 passing cases and 5 platform skips, with build and changed checks passing. Native Windows inherited-pipe proof fails before the repair and passes three serial runs afterward, preserving 256 KiB plus terminal output and verifying descendant extinction, closed pipes, and ownership release. Accepted Codex review is scoped-clean at P0/P1.
Delegate ACP process pooling and execution to the published runtime while preserving existing session controls.
## What Problem This Solves
The installed-agent picker needs a shared ACP lifecycle. This refactor removes duplicate runtime ownership and preserves existing ACP operations, cancellation, and process cleanup.
## Why This Change Was Made
Adopt published ACPX 0.16.0 for pooling and execution. OpenClaw supplies session-scoped tool context, records leases at spawn boundaries, and owns service shutdown. Each state has one writer. Production code decreases by 251 lines.
## User Impact
Concurrent diagnostic probes serialize through cleanup. Reconnect receives the current logical session's tool context. Shutdown closes initialized runtime resources.
## Evidence
Runtime artifact: `86bd6996abe0`; upgrade proof: `5f3c842e8275`; current source: `5aaed2debb44`. Runtime, proxy, and service source are unchanged. Existing package and upgrade observations retain the artifact identities below.
- Registered Gateway proof admits two `/acp doctor` requests from distinct sessions owned by the existing `main` agent before either probe starts. Probe processes run serially and return healthy diagnostics. Active ACP work completes.
- `/acp cancel` reaches an active peer, and the persistent session remains usable. Signaling only the Gateway during another active turn triggers graceful drain. After the work completes, the Gateway exits with code 0 and all owned peer processes are gone before harness cleanup. Shutdown proof covers cooperative graceful drain.
- Installed plugin files and the ACPX 0.16.0 dependency are verified against the exact candidate artifact.
- On `5aaed2debb44`, `pnpm test:extension acpx` passes 292 cases. The upgrade assertions, plugin registry, and migration-order suites pass 165 cases. Earlier runtime/reconnect/process-owner proof passes 106 cases.
- `upgrade-survivor-assertions.test.ts`: 112 passed; selected upgrade/registry runner guards: 48 passed. Dropped ACP metadata and changed model controls fail.
- Preflight, changed lint, format, max-lines, deadcode, assertion safety, shell controls, and `pnpm build` pass.
- The unchanged packed SDK consumer compiles against published 2026.9.4 and the candidate using TypeScript 6.0.3: `tsc -p tsconfig.json --pretty false`, with `strict=true` and `skipLibCheck=false`.
- Frozen released and candidate ACPX plugins pass installation and Gateway runtime smoke on the packed candidate core.
- Native macOS `bash scripts/e2e/lib/upgrade-survivor/run.sh`, baseline `openclaw@2026.9.4`, scenario `acpx-openclaw-tools-bridge`, manual restart mode: the published updater finishes, saved ACP metadata survives before standalone Doctor, and Gateway probes pass with a canonical `/private/tmp` test root.
- After that update, authenticated admin `chat.send` runs `/acp spawn main --thread off --mode persistent`; the subsequent ACP prompt returns the synthetic peer's persisted history. This proves a configured-main operation, not native-provider resume or MCP tool execution.
Packed SHA-256:
- Core: `ff96f1c3b7f3b49e7a880d4a0e0f6cc989277f171115ca08a25a606b3db61a09`
- ACPX: `e968973b8a747a551c37fc612869fc4f8b4bf668d0dd49f1bea024d0bb938728`
## Compatibility
Recorded artifact compatibility observations:
- Actual 2026.4.25 stops at its dangerous-code install gate; actual 2026.9.4 rejects `agent-runtimes`. That category comes from #142760 and is unchanged here.
- A `/tmp` alias fixture fails retained-import receipt lookup: the unchanged migration owner writes and reads different `/tmp` and `/private/tmp` keys. Failed automatic and manual-repair results are retained.
- An arbitrary unconfigured ACP target can spawn but fails reply dispatch. The configured-main operation above passes.
- External-package built-in MCP bridge resolution emits a missing source entry. The published ACPX 2026.9.4 resolver reproduces this; no bridge-path fix is included.
- The retained full release-check run was red for generated locale drift and the literal `setupSurface` top-file scan. Actual strict compilation above passes through the re-exported declarations.
## Consumers
Runtime facade, lazy proxy, service, and synthetic ACP peer move together. The public ACP runtime interface is unchanged.
## Invalidation
Spawn callbacks record leases. Service shutdown settles initialized runtime resources.
## Tests
Reconnect checks inspect actual session-load tool context. Upgrade proof preserves saved ACP identity and model options. Counts above overlap.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix: preserve file operations with fs-safe 0.13.0
* fix: preserve native filesystem consumer behavior
* build: adopt verified fs-safe 0.13.1 artifacts
* test: align release inventory with deferred plugins
* test: make temp permissions and staging swaps deterministic
Exercise the real secure-temp resolver for private-root creation and repair while preserving shared-parent permissions. Keep replaced staging inodes open through publication so Linux cannot immediately reuse their identities; retain the strict rejection and cleanup assertions.
* test: isolate logs in diagnostic environment fixtures
Select an isolated log file while mocking the logical platform and restore the previous override through the logger owner. This keeps cold Windows runs from failing before the second port poll while preserving the existing environment and signal assertions.
* test: assert Fish-quoted completion profile paths
Check the complete guarded Fish source block instead of searching for raw Windows paths. Preserve installation, idempotence, cache, and command-registration assertions, and verify a fixed Windows path against a literal quoted reload command.
* fix(ci): ratchet line caps without blocking main
Independently green PRs can combine to exceed max-lines and block main.
Use explicit hosted warnings and an oxlint-backed changed-file growth check.
Keep canonical caps, suppression inventory, and strict local/landing lint.
* fix(ci): preserve warning counts and isolated lint runners
Count native colored diagnostics and load cumulative config only when
warning mode is requested. Restore strict-runner fixture isolation and
accurate hosted warning totals.
* fix(ci): align line-cap ratchet with global warnings
Main now warns for all max-lines scopes, making hosted-only demotion redundant. Keep the PR growth ratchet and document the shared warning policy and shrink-only maintenance.
* fix: preserve Windows credential reads with fs-safe 0.12.0
* test: preserve compiled fs-safe configuration checks on Windows
* test: drain workspace page routes before closing fixtures
* ci: move heavy main checks to 16-vCPU runners
* perf(cli): avoid eager protocol schemas in cron registration
* test: align prerelease workflow expectation with main CI
* test: resume pending MCP Code Mode fixture calls
* test(agents): cover cloned admitted normalizers
Extend the canonical assembly-array fixture from #149662 with an admitted provider that returns cloned tools. Preserve its metadata, catalog, successful execution, abort-wrapper and post-disposal assertions. The production Array.from owner remains unchanged on main.
* ci: spread Control UI checks across twelve shards
* docs(ci): align runner guidance with current placement
* ci: route trusted hybrid preflight to Blacksmith
* test: align hybrid preflight runner table
* ci: retain real-Gateway failure diagnostics
Keep captured browser JSON and screenshots in an attempt-specific artifact when the real-Gateway CI job fails. Reuse the ordinary Control UI upload policy with seven-day retention and ignore absent captures, while preserving test commands and sanitized proof uploads.
Extend the existing workflow guard and document that diagnostic artifacts are not sanitized public proof. The new guard fails before the fix; all 18 focused alias, workflow, and command cases pass afterward. Workflow lint, selected changed-file checks, and independent review pass.
* fix(ui): preserve agent panel intent while route data loads
A reused Agents page retained its initialized flag after its route data became pending. Roster initialization could then navigate through the default Overview panel, replacing an intended Files route. Require current route data before navigation and panel work, and clear initialization when the pending update applies.
Keep explicit Settings selection revisions authoritative when the loader completes. Four focused regression cases fail before the repair with the reproduced Overview URL; 136 adjacent cases, targeted lint, formatting and independent review pass afterward.
* ci: publish allowlisted UI failure summaries
Keep raw browser reports and screenshots out of automatic CI artifacts. Write an explicit public projection from the existing failure owner and select only its fixed filename in ordinary and real-Gateway jobs. Raw captures remain local, and fixed private filenames keep sensitive labels out of logged paths. Older frozen targets without the summary produce no matching artifact.
Preserve original failures and manual sanitized proof capture. Sensitive-sentinel regressions cover nested state, route parameters, labels, errors, models and content, including evaluation, screenshot and storage failures. All 10 helper cases, six workflow/command cases, workflow validation, plain Node import and selected changed-file checks pass; independent review found no actionable issues.
* fix: align FileTransfer with fs-safe 0.12.0
Upgrade the FileTransfer dependency introduced by #148881 to the same exact version used by core, OpenShell and 1Password. Regenerate the importer with pnpm 12.3.4 and retain all other lock entries.
Strengthen the existing orphan-WAL collision regression with equal-length, different-content bytes so recovery exercises the shared hash path and preserves the existing quarantine. Frozen installation, the 16-case sidecar suite, 18 tool-policy cases and 23 UI/diagnostic cases pass on the integrated source; independent review found no actionable issues.
* test(ui): retain safe Canvas failure diagnostics
* test(gateway): model live child execution in stop proof
* test(ui): inspect HTML sandbox after render readiness
* test(cron): cover event schedules after API state updates
* ci: count hosted rows after hybrid preflight routing
* test(gateway): exercise scheduled-task probes on Windows
* fix(gateway): restore scheduled-task inspection on Windows
Allow the task probe to inherit or create a console and emit HRESULTs through the PowerShell pipeline. Preserve probe diagnostics in Doctor and update refusals without granting maintenance authority when inspection is unavailable.
Reported by @westaicommerce (#148601).
* chore(deps): upgrade fs-safe to 0.11.0
* docs(secrets): explain hardlinked credential recovery
Document private single-link credential replacement at the configured path. Extend the existing resolver regression to verify rejection, recovery, and preservation of the old hardlink inode and bytes.
* fix(doctor): warn when Windows state dir resolves under a OneDrive sync root
Doctor warns when the state directory is cloud-synced on macOS (iCloud
Drive, CloudStorage) and on risky Linux mounts, but stayed silent for
the equivalent Windows case, where OneDrive sync locks, delayed writes,
and Files On-Demand dehydration can make session, credential, and
SQLite state flaky.
Detect OneDrive roots from the OneDrive/OneDriveConsumer/
OneDriveCommercial environment variables the sync client maintains --
canonical roots rather than path-shape heuristics, so ordinary local
folders never match. Comparison is case-folded (Windows filesystems
are case-insensitive) and runs on the realpath-resolved target so
junction prefixes cannot misclassify a local dir.
Closes#98470
* fix(doctor): use Windows shell syntax in the OneDrive recovery hint
The OneDrive warning is only ever shown on Windows, but its recovery
line copied the macOS branch's POSIX form:
OPENCLAW_STATE_DIR=%USERPROFILE%\.openclaw openclaw doctor
Neither Windows shell accepts inline assignment as a prefix. Verified on
Windows 11: cmd.exe answers "'OPENCLAW_STATE_DIR' is not recognized as an
internal or external command" and PowerShell answers "The term
'OPENCLAW_STATE_DIR=...' is not recognized". Every operator who followed
the hint hit an error instead of a fix.
Emit one line per supported shell instead, both confirmed to set the
variable for the command that follows:
PowerShell: $env:OPENCLAW_STATE_DIR="$env:USERPROFILE\.openclaw"; openclaw doctor
cmd.exe: set "OPENCLAW_STATE_DIR=%USERPROFILE%\.openclaw" && openclaw doctor
The text moves into formatWindowsCloudSyncedStateDirWarning, mirroring
formatLinuxSdBackedStateDirWarning, so the rendered string is assertable
without stubbing platform and filesystem. The guard test greps for the
POSIX prefix shape and fails against the old line.
* fix(doctor): follow a OneDrive junction when the state dir leaf is absent
The detector called realpath on the state dir itself and fell back to the
lexical path when that failed. A state dir that does not exist yet - a
fresh install - cannot be resolved, so a not-yet-created leaf beneath a
OneDrive-named junction that actually points at local storage fell back
to its OneDrive-prefixed lexical path and produced a false warning.
Resolve through the nearest existing ancestor and re-append the missing
segments, which is what the two Linux detectors in this file already do
via resolvePathThroughExistingAncestor. The junction is then followed
even when the leaf is absent.
Adds two tests: the false-warning case, and a guard that a missing leaf
whose ancestor really does resolve inside OneDrive still warns.
* fix(doctor): describe gateway-wide relocation instead of one-shot state-dir hints
* test(doctor): preserve open database families in Windows proof
* test(doctor): identify native state snapshot mismatches
* test(doctor): preserve SQLite data without freezing reader metadata
* fix(doctor): honor selected Windows OneDrive environment
---------
Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>
Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.
Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.
The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.
The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.
Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.
Refs #144758#144901#144890#143292#146637#145252. Preserves the activation boundary from #147019.
* chore(deps): advance cooled dependencies and major upgrades
* test(logging): migrate failed-sink regression to tslog 5
* test: retain dependency upgrade coverage within lint limits
* fix(deps): preserve compiler launches, Matrix sync and chat metadata
Keep copied script harnesses independent of declaration modules and preserve
Windows executable prefixes after admission. Audit the Matrix sync guard for
42.3, align CI toolchain/cache pins, and refresh session facts after accepted
model-catalog invalidation without relying on picker timing.
* fix(ui): preserve scoped session reconciliation after catalog refresh