Commit graph

2037 commits

Author SHA1 Message Date
Peter Steinberger
2ce0573b02
fix(gateway): preserve active work during recovered Node restarts (#153435)
* fix(gateway): preserve work during recovered Node restarts

Let Unix Node recovery wrappers respect the existing Gateway stop budget.
Share startup-safe command classification and deadline facts, and resolve
managed restart intent against the live serving owner in its write
transaction with current update authority.

Preserve the existing public PID intent API, record format, and Windows
behavior. Keep cold lifecycle test preparation outside timed hooks.

Inspired by @ly85206559's wrapper-grace approach in #147054; this repair
is independently authored from main. Related: #146956. Windows cooperative
shutdown remains a follow-up.

* refactor(gateway): stabilize restart callback and test setup

Declare receiver-independent restart intent callbacks as arrows and retain typed signal spy handles for lint-safe assertions. Move cold lifecycle imports into test collection so worker preparation cannot consume timed setup hooks.
2026-09-19 22:41:17 -07:00
Omar Shahine
88c56ec432
feat(plugins): add experimental FaceTime realtime voice bridge (#119291)
* feat(plugins): add experimental FaceTime realtime voice bridge

Co-authored-by: Peter Steinberger <steipete@gmail.com>

Co-authored-by: Dallin Romney <dallinromney@gmail.com>

* test(facetime): align portable release gates

* ci: refresh FaceTime PR checks

* fix(facetime): retain startup suppression through hangup

Begin carrier closure before startup teardown and keep native suppression pending until carrier absence is confirmed.

* fix(facetime): retain cancellation until carrier safety is confirmed

* fix(facetime): separate carrier closure from startup teardown

* test(pr): model authoritative repository identity in sibling fixtures

* fix(facetime): retain suppression without carrier proof

Do not treat the capture watchdog shutdown as evidence that the native carrier terminated. Keep the call unresolved and process suppression retained until exact termination or stable absence is observed.\n\nCo-authored-by: Codex <noreply@openai.com>

* fix(facetime): retain disconnected carrier proof

* fix(facetime): stabilize live audio startup and routing

* fix(facetime): refresh merged lockfile

* refactor(facetime): separate helper result projection

* fix(facetime): align published package metadata

* fix(facetime): satisfy preflight lint checks

* fix(facetime): preserve consult and carrier ownership

* test(facetime): declare regression fixture types

* test(release): align merged publisher inventory

* fix(facetime): retain runtime across safe uninstall

* fix(facetime): restore responsive call opening

* refactor(facetime): keep greeting policy localized

* fix(facetime): accept trusted stock Xcode

* fix(facetime): use compiler link drivers

* fix(facetime): repair portable lifecycle checks

* fix(facetime): normalize installed driver permissions

* fix(facetime): preserve consults during caller speech

* fix(facetime): make answered-call greeting reliable

* fix(facetime): honor explicit agent session owner

* fix(facetime): finish voice consults promptly

* fix(facetime): preserve repeated voice consults

* fix(facetime): settle consult delivery before reporting success

* fix(facetime): retain suppression until carrier closure is proven

* docs(facetime): refresh merged plugin reference count

* fix(facetime): preserve installed driver when backup fails

* test(facetime): prove rejected calls cannot start media

* fix(facetime): verify unknown SIP status before setup advice

* test(facetime): prove caller rejection at authenticated media boundary

---------

Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-09-19 20:36:04 -07:00
Josh Lehman
cde6bbdcfe
feat(plugins): add decision models with per-agent selection (#152237)
* fix(plugins): preserve authored config through runtime load plans

* feat(judgments): add typed provider runtime and plugin SDK

* feat(plugins): add per-agent decision models

Add an opt-in decisionModel role for typed choices, scores, and boolean
probabilities, with global defaults and per-agent inheritance or disablement.
Keep provider lifecycle and prepared credentials host-owned, and expose
manifest-only decision choices separately from conversational model catalogs.

Adapt the provider foundation from #152237 to the decisions contract. Existing
configurations keep decision calls disabled until a model is selected.

Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>

* fix(plugins): complete decision inspection and preserve authored config

Expose optional decision-provider health through the Gateway wire schema
and generated native DTOs. Preserve the landed SecretRef prerequisite’s
identity behavior for unchanged activation plans. Move model mocks into
one private sibling factory without expanding the public helper surface.

Validation: 51 handler/protocol tests, 18 post-extraction tests, 52 runtime
and integration tests, generated protocol checks, and clean P0-P2 review.
The SDK surface-budget increase remains pending maintainer approval.

Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>

* perf(plugins): reduce decision overhead and unnecessary reloads

Keep one full provider input snapshot and an independent question rubric. Recognize decision-only catalog providers with the existing normalization policy, and reload plugins only for decision-model changes while preserving roster actions. Apply the approved SDK surface increment and behavior-neutral cleanup.

Validation: 58 runtime/config/loader tests, 610 Gateway regression/sibling tests plus 15 final catalog cases, full core typechecks, scoped lint and clean managed review. A 143155-attempt synthetic stress run settles all 18104 provider calls at max concurrency four.

* fix(plugins): preserve reload boundaries and decision test contracts

Materialize only present decision-selector leaves so Telegram account creation/removal retains its parent lifecycle action. Select UI controls by model role, preserve independent chat and decision catalogs in tests, remove an unused probe, and rebalance existing typecheck shards without raising their limits.

Validation: 588 reload tests, 58 shard/loader tests, 38 UI catalog tests, 9 browser tests, affected typechecks, unused-file scans, and clean managed review.

* test(ui): address model pickers by role in gateway flows

Disambiguate Primary from the new Decision picker in the real-Gateway catalog test, alias browser test, and Agents view assertions. Preserve draft and publication checks. Unit/browser/typecheck proof and managed review pass; real-Gateway execution follows on the integrated build.

* test(plugins): isolate runtime metadata and preserve shard headroom

Move the existing lazy-runtime metadata contract intact into its own focused module. Group CLI program tests with commands so newer main tests keep every typecheck shard within existing limits. No production changes or limit increases.

Validation: 57 tests, four typecheck graphs, canonical line guards against the CI main snapshot, targeted lint and clean managed review.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
2026-09-19 14:37:53 -07:00
Peter Steinberger
a8c423006e
refactor: adopt fs-safe 0.16 and remove duplicate filesystem logic (#152972)
* refactor: reuse fs-safe 0.16 filesystem helpers

Upgrade core and plugin dependencies to the published release. Delegate missing-suffix probing and positional snapshot copying while retaining database identity policy, cache, durability, and cleanup ownership. Remove 333 production lines and document bounded alias diagnostics.

* fix: retain exact directory identities for fs-safe 0.16

Preserve bigint directory identity in updater handoffs, backup publication, and snapshot staging. Keep initial receipts through durability checks, retain published update-state compatibility, and share snapshot directory policy. Cover real publication phases and large filesystem IDs while documenting the released dependency declaration gap.

* test: record approved fs-safe receipt type exceptions

* test: rebalance Gateway type-check groups
2026-09-19 13:50:32 -07:00
Peter Steinberger
58067a8214
fix(skills): stop repeated scans after watched folders are removed (#152903) 2026-09-19 08:34:16 -07:00
Vincent Koc
1232d3f13e
fix(update): converge post-core work in the candidate runtime (#144317)
* refactor(test): centralize worker declaration metadata

Replay the reviewed first tooling layer on the current frozen main base. Keep package activation declarations reserved for the later owning layers; preserve the inherited main build graph and test coverage.

* fix(update): bind recovery admission to existing authority

Replay the reviewed authority layer on current main, preserving the diagnostics import owner. Retain Json (fuller-stack-dev) rollback-journal and Bun regression coverage; restore NORMAL reader policy after rollback-mode admission so retained Bun statements do not hold locks after settlement. Later FD3 custody remains in its owning layer.

* fix(config): retain authority across config persistence

Replay the accepted config authority layer without behavioral changes. Preserve producer-owned write guards through backup, snapshot, persistence, reread, and error settlement.

* fix(plugins): fence convergence with lifecycle authority

Replay the accepted plugin authority layer without behavioral changes. Keep install-record, peer-link, retention, doctor repair, and cohort operations under their existing canonical lease owners.

* fix(update): preserve authority through post-core convergence

Replay the accepted five-file post-core convergence layer without new behavior. Keep config and plugin operations within the existing admitted owner scope.

* fix(plugins): preserve first authority refusal during repair

Keep authority failures outside filesystem warning conversion, retain the first callback refusal through normalized installer outcomes, and join admitted peer repairs before rejection. Preserve the synchronous peer guard and lease-bound index CAS finalizer.

Adapt the Doctor and convergence ownership pattern from Jason Sy in #144130. Focused red/green: 23 failures became 32 passes; full peer and retention controls pass 37 cases. Native review raised an overlapping async callback scenario; source review rejects it because the current per-invocation Doctor path is serial. Root final-effect and installed integration gates remain open.

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>

* fix(config): refuse guarded include writes before effects

Reject include-owned mutations carrying inherited authority, explicit assertCurrent, or beforeCommit before Root preparation and backup effects. Remove the unreachable guarded include publisher and retain ordinary include publication and custom-root IO ownership.

Three missing-refusal regressions reproduced before the repair. All 107 cases in mutate, io.write-lock and io.write-reread pass, including ordinary include exclusion and compensation controls. Native P1 review is scoped-clean. The fs-safe final-effect contract and installed candidate integration remain separate draft gates.

* fix(config): retain update authority through runtime activation

* fix(plugins): repair leased authority CI coverage

Remove the unused unleased record writer and seed test fixtures through the canonical store producer. Keep compiled Doctor fixture module identity and direct leased-writer assertions.

Bind registry authority callbacks and correct the focused fixture typing and lint errors without weakening refusal checks. Independent source review and native P0/P1 review passed; runtime and hosted CI qualification remain pending.

* test(plugins): omit redundant deferred type arguments

Use the existing void generic default for the three deferred test controls. The correction emits byte-identical JavaScript and preserves all assertions.

This trivial test-only delta was independently verified after the full L4 P0/P1 review. The earlier focused 295-test and selected typecheck passes remain source-bound; the failed lint surface and unrun export scans still require qualification.

* test(plugins): cover synchronous host-link admission turns

Retain the three filesystem API-entry scheduling controls contributed by Jason Sy (@fuller-stack-dev) in https://github.com/openclaw/openclaw/pull/144316#issuecomment-5632474077.

Cover missing node_modules, stale symlink, and package-copy replacement while preserving the existing synchronous authority contract and test seed helper. These controls observe API-entry timing, not native filesystem-effect atomicity or an observed regression on this source.

Independent exact-block review and fresh full L4 native P0/P1 review passed. Targeted execution of these added cases remains pending.

* fix(update): omit absent config write authority options

Preserve the normal config writer options when no updater authority is supplied. Keep guarded writes unchanged and avoid undefined caller callbacks shadowing prepared options.

* fix(update): bind migrated finalization to candidate runtime

Move the existing worker-local finalization context into the convergence layer without serializing it or changing authority. Preserve the original finalization fence through the shared candidate phase.

Add the actual worker caller-binding regression and candidate lease and executor controls. The unchanged worker regression failed on the parent source; final-head runtime and native qualification remain pending.

* refactor(update): share restart sentinel notification options

* fix(plugins): retain updater authority through package settlement

* test(plugins): verify publication across updater revocation

* fix(test): satisfy updater authority lint rules

* fix(update): preserve first authority refusal through Doctor finalization

* test(update): qualify guarded convergence across current CI lanes

* fix(update): retain live authority in fresh Doctor children

* test(update): preserve Doctor authority in CLI fixtures

* test(update): share legacy Doctor command matching

* fix(config): retain root publication identity for compensation

* test: stabilize backup identity and trace watcher failures

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 06:17:34 -06:00
Peter Steinberger
dcb4847e48
feat(release): check publication gates before dispatch (#152470)
* feat(release): check publication gates before dispatch

* fix(release): accept empty draft bodies in publish preflight

* fix(release): wire publish preflight command and shared gate proof

* fix(release): discover draft state and await committed archive proof

* fix(ci): preserve release metadata types and catalog test lifetime

* fix(release): reuse resume authority and settle UI test phases

* style(release): satisfy typed metadata and UI fixture lint
2026-09-19 01:41:43 -07:00
Peter Steinberger
a94a7b2768
chore(release): close out 2026.9.5 on main (#151823)
* chore(release): close out 2026.9.5 on main

* chore(release): align GitHub plugin with 2026.9.5 closeout
2026-09-19 01:37:16 -07:00
Peter Steinberger
cb496f6448
perf(logging): skip impossible AWS secret redaction scans (#152484) 2026-09-19 00:41:13 -07:00
Peter Steinberger
0b55540c63
perf(state): cache resolved agent database paths (#152525)
Reuse final paths for a bounded set of agent IDs and resolved state roots while retaining live environment and legacy-directory resolution. Include output-parity tests and a reproducible benchmark showing 80-82% lower hot-path cost.
2026-09-18 23:54:06 -07:00
RoboClaw
a46de01a4a
feat: read GitHub issues, pull requests, and commits beside chat (#148464)
Keep public GitHub issues, pull requests, commits, comments, images, and diffs readable beside chat in a resizable, tabbed reader. Preserve external navigation for modified clicks and explicit links.

Move GitHub transport and document mapping into the bundled plugin, and expose the passive reader through the shared plugin contract. Preserve operator plugin controls, managed-preview credential authority, anonymous detail reads, and existing host read-library behavior.

Bind responses to their requested resource, retain rapid reader opens in FIFO order, and cancel stale batches on close or session replacement. Add regression coverage and synchronize heartbeat and attachment tests with their actual completion boundaries.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-18 23:54:04 -07:00
Peter Steinberger
0cbbec0272
fix: restore fs-safe native support after update fallback (#152349)
* fix: restore fs-safe native support after optional-free updates

* fix(docker): include fs-safe repair in dependency inputs
2026-09-18 20:33:14 -07:00
RoboClaw
864dc28939
chore(deps): refresh dependencies with seven-day release cutoff (#152220)
* chore(deps): refresh dependencies with seven-day release cutoff

Update 20 compatible package versions published by September 11, 2026 at 17:55 UTC; preserve patches, overrides, and incompatible pins.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* chore(deps): refresh dependencies with seven-day release cutoff

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 56ff74cb-22b8-4962-ab53-39496522a822

* fix(deps): preserve docs publishing and align ACP version checks

Retain slugify 2.2.1 and transliterate 1.6.0 so the independent publisher graph and existing documentation anchors remain compatible. Align exact Claude ACP assertions and skill documentation with the updated 0.76.0 manifest pin.

Validation: docs-sync CLI failed before the hold and passed afterward; 11 publisher tests, 26 Markdown/anchor tests, and 326 ACPX tests passed. No production logic, timing budgets, or assertions weakened.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-18 19:59:52 -07:00
Jason (Json)
9904ad65e0
fix(update): avoid rehearsal failures while databases are active (#149449)
* fix(update): snapshot rehearsal SQLite through online backup

Use the existing async backup path only for disposable rehearsal copies.
Preserve synchronous inspection, bounded worker output, and parent-owned
scratch when worker or monitor termination is uncertain.

Cover concurrent WAL writers, snapshot integrity, cancellation, deadlines,
low-space refusal, and stdout/stderr overflow through the worker boundary.

* test(update): align rehearsal mocks with bounded snapshot runner

Align the canary snapshot mock with the bounded UTF-8 runner. Delegate real progress probes and non-canary children; exclude snapshot-worker results from progress-byte parsing. Preserve timing, cancellation, byte-limit and capacity assertions.

Include the reviewed managed-parent lifecycle assertion grouping that resolves the shared max-lines prerequisite.

These test corrections address failures in the preceding hosted run. Source review and focused static checks passed; behavioral and type qualification must come from the corrected exact-head hosted run. First-hop and native LAND gates remain open.

* test(update): make rehearsal worker fixtures portable

* test(update): scope rehearsal fixtures to worker entrypoint

* test(update): compare equivalent Windows scratch paths

* test(update): stabilize Windows rehearsal qualification

Use append-only committed progress records to avoid the observed Windows rename race while preserving concurrent WAL acquisition assertions.

Include the exact test-only CI prerequisites from #152099 (d339607c) and three duplicate declaration removals from #152028 (3fceb860).

Co-authored-by: Peter Steinberger <steipete@gmail.com>

---------

Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-18 19:57:35 -06:00
Kimi Yu
ce616b6417
feat: read agent documents from a host-owned workspace (#150584) 2026-09-18 15:46:13 -07:00
Peter Steinberger
ab46acdcd2
refactor: reuse fs-safe and fix Windows asset retention (#151932)
* refactor: reuse fs-safe transfers and directory walks

Replace caller-owned copy, hashing, and traversal loops with the pinned fs-safe operations. Preserve source verification, publication, and cancellation ownership. Refs #151928.

* test: register plugin-owned fs-safe inventory helpers

* fix: reuse verified Windows asset publication winners
2026-09-18 11:04:15 -07:00
Peter Steinberger
16341cdf46
fix(process): confirm Windows stdio cleanup after parent exit (#151443)
Windows owned stdio children now use the existing retained Job owner to confirm descendant cleanup after the parent exits, preserving interactive input and worker IPC.

Keep native support optional: unavailable or failed Job setup falls back to ordinary command startup and reports typed uncertainty. Tree-required cleanup retains state locks and temporary artifacts until extinction is certified; transport-only cleanup remains independent. Claude prompt and skill artifacts are retained with a warning when cleanup is uncertain.

Related: #151325, #150427, #150244.

Validation: exact-head CI run 35354835669 is green, including both Windows node-test jobs; 243 focused tests passed locally on macOS with six native Windows skips. The P1 review is scoped-clean, and all 13 reviewed commits are preserved by a semantic-equivalent rebase. Hosted Windows proof and the capability matrix satisfy the maintainer's compatibility-proof ruling.
2026-09-18 08:32:42 -07:00
Peter Steinberger
3c4c111b0f
feat: automatically update idle headless nodes (#151545)
* feat(node): update headless runtimes automatically when idle

Stage private packaged node runtimes and activate only after all owned work
and cleanup settle. Preserve pairing and launch options, keep automatic
activations at least 12 hours apart, and leave shared-state migration and
Gateway installation ownership with the normal updater.

Document defaults, opt-outs, runtime version discovery, and recovery.
Support recoverable Windows selector replacement across service restarts.

Refs #151462

* fix(node): complete auto-update integration and settings defaults

Capture the launcher in compiled test runtimes and trusted wrapper inventories, register the package update proof, and use the canonical Kysely read path. Preserve the inherited enabled state in the config UI and align caller tests with the node shutdown lifecycle.

* fix(node): preserve retained plugin work during automatic updates

Require an explicit idle result from plugin commands, preserve older-plugin work, and connect bundled lifetime owners to automatic node updates. Join canceled inference and failed terminal cleanup before command settlement; keep historical state repair with Doctor. Document compatibility and extend installed-package proof for retained legacy plugin work.

* test(browser): align idle-work fixtures with runtime exports

* test(browser): extract proxy request fixtures

* test(node): retain idle assertions across native cleanup
2026-09-18 06:20:27 -07:00
Vincent Koc
73775cb8a2
fix(gateway): reduce worker overhead with large session stores (#149700)
* fix(gateway): avoid full-store hydration for worker session lookup

Punchcard-Session: brisk-summit-brook-mr

* improve(bench): measure worker transcript commit scaling

Punchcard-Session: brisk-summit-brook-mr

* fix(gateway): avoid unrelated prompt reads in worker target lookup

Use current-main list discovery and register the real worker commit benchmark through the supported source runner.

Punchcard-Session: clear-workshop-brook-w2

* test(gateway): verify worker lookups skip unrelated prompts

Punchcard-Session: clear-workshop-brook-w2

* fix(bench): use retained session key reader for fixture counts

Keep the seeded session-count assertion outside measured commit work after the runtime count API retirement.

Punchcard-Session: ember-river-harbor-t4

* fix(ci): settle streaming fixtures and update native test expectations

Punchcard-Session: ember-river-harbor-t4

* fix(test): keep child pagination and dashboard state coherent

Punchcard-Session: ember-river-harbor-t4

* test(ui): split session fixtures and child-query cases

Punchcard-Session: ember-river-harbor-t4

* test(ui): reuse serialized record predicate

Punchcard-Session: ember-river-harbor-t4

* test(ui): report stalled inactive-agent outbox stage

Punchcard-Session: ember-river-harbor-t4
2026-09-18 16:38:53 +08:00
Peter Steinberger
497d4ff3d2
fix(state): reclaim interrupted SQLite staging copies (#150816)
Interrupted Gateway startup, update inspection, and CLI reads could leave large private SQLite staging copies behind. Reclaim abandoned copies through the existing snapshot lifecycle owner while preserving live readers, recent legacy copies, canonical databases, and backups.

Use SQLite lifetime tokens and parent admission to coordinate nested workers. Commit retirement before closing handles and removing data; retain control files until copied data is removed. Recognize released updater layouts and retain the 24-hour legacy age threshold. Cleanup failures remain warnings.

Run asynchronous reclamation in the existing SQLite worker. Callers can cancel independently without terminating a surviving caller's shared pass. When the last caller leaves, settle the current directory before stopping, and let later allocation recover the remaining backlog. Drain snapshot workers before shutdown cleanup.

Validation: exact-head CI run 35266032454 passed with zero pending checks on ab8037229203cc8a42735263637245f09477f2aa. Recorded focused proof passed 203 SQLite tests with one platform skip and 31 Gateway lifecycle tests. Published OpenClaw 2026.9.4 worker proof preserved fresh interrupted copies, reclaimed 202,375,168 aged bytes, and left source bytes unchanged. Review r4 was scoped-clean at P0/P1; the exact-head ClawSweeper review reported no actionable findings or before-merge moves.

Windows CI covers released-layout removal, independent cancellation, and directory-boundary settlement. Native Windows signal interruption and late-worker races remain a documented coverage gap.

Closes #149978. Related: #150091. Thanks to @vyctorbrzezowski, @Glucksberg, and @stwhwing for the production reproductions.
2026-09-17 13:19:48 -07:00
Peter Steinberger
146c4147a8
fix: Windows cleanup leaves descendants running after leader exit (#150244)
Fix Windows build and test cleanup when descendants outlive their command leader. Retain kernel Job ownership from admission, start owned cleanup on leader exit, preserve bounded terminal output, and release temporary-resource claims only after descendant extinction and output closure are verified. Preserve taskkill diagnostics and report unresolved survivors.

Reuse the native Windows Job bindings and one runtime/compiler entrypoint inventory. Keep CI planning dependency-free and preserve exited Gateway migration guidance. Installed updater behavior and persistent operator state are unchanged; no dependency, schema, configuration, deadline, retry, or baseline changes.

Validation: exact-head CI run 35229160236 is green, including both Windows shards. Recorded current-head Linux proof has 220 passing cases and 5 platform skips, with build and changed checks passing. Native Windows inherited-pipe proof fails before the repair and passes three serial runs afterward, preserving 256 KiB plus terminal output and verifying descendant extinction, closed pipes, and ownership release. Accepted Codex review is scoped-clean at P0/P1.
2026-09-17 07:40:19 -07:00
Peter Steinberger
6fa64d9f71
fix(memory): reduce CPU work during index sync (#150602) 2026-09-17 01:33:59 -07:00
Ayaan Zaidi
3b45d6ac5d
refactor(acpx): adopt published runtime lifecycle (#150150)
Delegate ACP process pooling and execution to the published runtime while preserving existing session controls.

## What Problem This Solves
The installed-agent picker needs a shared ACP lifecycle. This refactor removes duplicate runtime ownership and preserves existing ACP operations, cancellation, and process cleanup.

## Why This Change Was Made
Adopt published ACPX 0.16.0 for pooling and execution. OpenClaw supplies session-scoped tool context, records leases at spawn boundaries, and owns service shutdown. Each state has one writer. Production code decreases by 251 lines.

## User Impact
Concurrent diagnostic probes serialize through cleanup. Reconnect receives the current logical session's tool context. Shutdown closes initialized runtime resources.

## Evidence
Runtime artifact: `86bd6996abe0`; upgrade proof: `5f3c842e8275`; current source: `5aaed2debb44`. Runtime, proxy, and service source are unchanged. Existing package and upgrade observations retain the artifact identities below.

- Registered Gateway proof admits two `/acp doctor` requests from distinct sessions owned by the existing `main` agent before either probe starts. Probe processes run serially and return healthy diagnostics. Active ACP work completes.
- `/acp cancel` reaches an active peer, and the persistent session remains usable. Signaling only the Gateway during another active turn triggers graceful drain. After the work completes, the Gateway exits with code 0 and all owned peer processes are gone before harness cleanup. Shutdown proof covers cooperative graceful drain.
- Installed plugin files and the ACPX 0.16.0 dependency are verified against the exact candidate artifact.
- On `5aaed2debb44`, `pnpm test:extension acpx` passes 292 cases. The upgrade assertions, plugin registry, and migration-order suites pass 165 cases. Earlier runtime/reconnect/process-owner proof passes 106 cases.
- `upgrade-survivor-assertions.test.ts`: 112 passed; selected upgrade/registry runner guards: 48 passed. Dropped ACP metadata and changed model controls fail.
- Preflight, changed lint, format, max-lines, deadcode, assertion safety, shell controls, and `pnpm build` pass.
- The unchanged packed SDK consumer compiles against published 2026.9.4 and the candidate using TypeScript 6.0.3: `tsc -p tsconfig.json --pretty false`, with `strict=true` and `skipLibCheck=false`.
- Frozen released and candidate ACPX plugins pass installation and Gateway runtime smoke on the packed candidate core.
- Native macOS `bash scripts/e2e/lib/upgrade-survivor/run.sh`, baseline `openclaw@2026.9.4`, scenario `acpx-openclaw-tools-bridge`, manual restart mode: the published updater finishes, saved ACP metadata survives before standalone Doctor, and Gateway probes pass with a canonical `/private/tmp` test root.
- After that update, authenticated admin `chat.send` runs `/acp spawn main --thread off --mode persistent`; the subsequent ACP prompt returns the synthetic peer's persisted history. This proves a configured-main operation, not native-provider resume or MCP tool execution.

Packed SHA-256:
- Core: `ff96f1c3b7f3b49e7a880d4a0e0f6cc989277f171115ca08a25a606b3db61a09`
- ACPX: `e968973b8a747a551c37fc612869fc4f8b4bf668d0dd49f1bea024d0bb938728`

## Compatibility
Recorded artifact compatibility observations:
- Actual 2026.4.25 stops at its dangerous-code install gate; actual 2026.9.4 rejects `agent-runtimes`. That category comes from #142760 and is unchanged here.
- A `/tmp` alias fixture fails retained-import receipt lookup: the unchanged migration owner writes and reads different `/tmp` and `/private/tmp` keys. Failed automatic and manual-repair results are retained.
- An arbitrary unconfigured ACP target can spawn but fails reply dispatch. The configured-main operation above passes.
- External-package built-in MCP bridge resolution emits a missing source entry. The published ACPX 2026.9.4 resolver reproduces this; no bridge-path fix is included.
- The retained full release-check run was red for generated locale drift and the literal `setupSurface` top-file scan. Actual strict compilation above passes through the re-exported declarations.

## Consumers
Runtime facade, lazy proxy, service, and synthetic ACP peer move together. The public ACP runtime interface is unchanged.

## Invalidation
Spawn callbacks record leases. Service shutdown settles initialized runtime resources.

## Tests
Reconnect checks inspect actual session-load tool context. Upgrade proof preserves saved ACP identity and model options. Counts above overlap.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-17 14:00:59 +05:30
Dallin Romney
59f709f8f1
refactor(qa): capture artifacts from running transports (#149928)
* refactor(qa): capture artifacts through transports

* build(qa): adopt Crabline 0.1.26 evidence API

* chore(qa): shrink assertion safety baseline

* refactor(qa): remove obsolete artifact selection alias

* build(qa): update Crabline to 0.1.27
2026-09-17 00:00:08 -07:00
Peter Steinberger
6dbf1873f9
fix: preserve file operations with fs-safe 0.13.1 (#150263)
* fix: preserve file operations with fs-safe 0.13.0

* fix: preserve native filesystem consumer behavior

* build: adopt verified fs-safe 0.13.1 artifacts

* test: align release inventory with deferred plugins

* test: make temp permissions and staging swaps deterministic

Exercise the real secure-temp resolver for private-root creation and repair while preserving shared-parent permissions. Keep replaced staging inodes open through publication so Linux cannot immediately reuse their identities; retain the strict rejection and cleanup assertions.

* test: isolate logs in diagnostic environment fixtures

Select an isolated log file while mocking the logical platform and restore the previous override through the logger owner. This keeps cold Windows runs from failing before the second port poll while preserving the existing environment and signal assertions.

* test: assert Fish-quoted completion profile paths

Check the complete guarded Fish source block instead of searching for raw Windows paths. Preserve installation, idempotence, cache, and command-registration assertions, and verify a fixed Windows path against a literal quoted reload command.
2026-09-16 17:21:11 -07:00
Peter Steinberger
f78f51359d
chore(deps): refresh dependencies with seven-day cutoff (#149908)
* chore(deps): refresh dependencies with seven-day cutoff

Advance eligible application, native, release, and development dependencies
published by 2026-09-09T06:51:52Z. Audit new registry resolutions and native
artifact hashes, preserving existing security pins and compatibility holds.

Adapt MCP Apps 2 tool discovery and host context, retain Clack cancellation
handling, and align the updater fixture with its runtime assembly owner.
Synchronize native artifact checks, operational docs, and tooling pins.

Validation includes frozen installation, full build, CLI rebuild, typechecks,
lint, 96 npm package locks, dependency audits, focused runtime and native
proofs, and independent review. Exact-head hosted CI is required before land.

* fix(deps): preserve scroll ownership and synchronize toolchain contracts

* fix(cli): preserve generic wizard option values after Clack update

* docs(lobster): clarify credentials for embedded remote calls

* test(cli): use Clack cancellation sentinel in prompt fixtures

* fix(ios): avoid opening audio input during relay cancellation

* test: reuse dependency update fixtures within line limits

* fix(crabbox): retain the previous trusted pnpm pin

* test(gateway): synchronize task access churn with page selection

* test(macos): isolate the challenge timeout transport fixture

* fix(macos): preserve hidden windows through deminiaturization

* fix(macos): exclude hidden dashboards from window selection
2026-09-16 09:06:40 -07:00
Peter Steinberger
c1f00edb04
fix(ci): reject line-cap growth on pull requests (#149622)
* fix(ci): ratchet line caps without blocking main

Independently green PRs can combine to exceed max-lines and block main.
Use explicit hosted warnings and an oxlint-backed changed-file growth check.
Keep canonical caps, suppression inventory, and strict local/landing lint.

* fix(ci): preserve warning counts and isolated lint runners

Count native colored diagnostics and load cumulative config only when
warning mode is requested. Restore strict-runner fixture isolation and
accurate hosted warning totals.

* fix(ci): align line-cap ratchet with global warnings

Main now warns for all max-lines scopes, making hosted-only demotion redundant. Keep the PR growth ratchet and document the shared warning policy and shrink-only maintenance.
2026-09-16 04:25:37 -07:00
Peter Steinberger
c7ea115c3e
fix: preserve Windows credential reads with fs-safe 0.12.0 (#149124)
* fix: preserve Windows credential reads with fs-safe 0.12.0

* test: preserve compiled fs-safe configuration checks on Windows

* test: drain workspace page routes before closing fixtures

* ci: move heavy main checks to 16-vCPU runners

* perf(cli): avoid eager protocol schemas in cron registration

* test: align prerelease workflow expectation with main CI

* test: resume pending MCP Code Mode fixture calls

* test(agents): cover cloned admitted normalizers

Extend the canonical assembly-array fixture from #149662 with an admitted provider that returns cloned tools. Preserve its metadata, catalog, successful execution, abort-wrapper and post-disposal assertions. The production Array.from owner remains unchanged on main.

* ci: spread Control UI checks across twelve shards

* docs(ci): align runner guidance with current placement

* ci: route trusted hybrid preflight to Blacksmith

* test: align hybrid preflight runner table

* ci: retain real-Gateway failure diagnostics

Keep captured browser JSON and screenshots in an attempt-specific artifact when the real-Gateway CI job fails. Reuse the ordinary Control UI upload policy with seven-day retention and ignore absent captures, while preserving test commands and sanitized proof uploads.

Extend the existing workflow guard and document that diagnostic artifacts are not sanitized public proof. The new guard fails before the fix; all 18 focused alias, workflow, and command cases pass afterward. Workflow lint, selected changed-file checks, and independent review pass.

* fix(ui): preserve agent panel intent while route data loads

A reused Agents page retained its initialized flag after its route data became pending. Roster initialization could then navigate through the default Overview panel, replacing an intended Files route. Require current route data before navigation and panel work, and clear initialization when the pending update applies.

Keep explicit Settings selection revisions authoritative when the loader completes. Four focused regression cases fail before the repair with the reproduced Overview URL; 136 adjacent cases, targeted lint, formatting and independent review pass afterward.

* ci: publish allowlisted UI failure summaries

Keep raw browser reports and screenshots out of automatic CI artifacts. Write an explicit public projection from the existing failure owner and select only its fixed filename in ordinary and real-Gateway jobs. Raw captures remain local, and fixed private filenames keep sensitive labels out of logged paths. Older frozen targets without the summary produce no matching artifact.

Preserve original failures and manual sanitized proof capture. Sensitive-sentinel regressions cover nested state, route parameters, labels, errors, models and content, including evaluation, screenshot and storage failures. All 10 helper cases, six workflow/command cases, workflow validation, plain Node import and selected changed-file checks pass; independent review found no actionable issues.

* fix: align FileTransfer with fs-safe 0.12.0

Upgrade the FileTransfer dependency introduced by #148881 to the same exact version used by core, OpenShell and 1Password. Regenerate the importer with pnpm 12.3.4 and retain all other lock entries.

Strengthen the existing orphan-WAL collision regression with equal-length, different-content bytes so recovery exercises the shared hash path and preserves the existing quarantine. Frozen installation, the 16-case sidecar suite, 18 tool-policy cases and 23 UI/diagnostic cases pass on the integrated source; independent review found no actionable issues.

* test(ui): retain safe Canvas failure diagnostics

* test(gateway): model live child execution in stop proof

* test(ui): inspect HTML sandbox after render readiness

* test(cron): cover event schedules after API state updates

* ci: count hosted rows after hybrid preflight routing
2026-09-16 04:10:09 -07:00
Vincent Koc
d0f4dc76b1
fix(scripts): preserve Bun in the kitchen-sink RPC walk (#149474) 2026-09-16 16:04:15 +08:00
Vincent Koc
351ff29013
refactor: preserve caller signal ownership in FreeBSD discovery (#149706)
* refactor: share FreeBSD service discovery without signal ownership

* test: avoid returning timer from FreeBSD fixture executor
2026-09-16 15:56:25 +08:00
Vincent Koc
0ab1513aae
fix(sandbox): keep file tools aligned with overlapping mounts (#148893)
* fix(sandbox): align file tools with effective container mounts

* fix(sandbox): preserve selected paths through file tool execution

* fix(sandbox): normalize file reference prefixes once

* fix(sandbox): normalize legacy file identities

* test(sandbox): preserve path helpers in guard mocks

* test(sandbox): include protected skills in mount fixture

* test(sandbox): model mounted config runtime metadata

* refactor(sandbox): keep mount selection helpers internal

* test(sandbox): preserve fixture behavior under lint rules

* fix(sandbox): resolve canonical reads and covered mounts

* test(sandbox): preserve mount identity tuple types

* fix(sandbox): use backend mappings for file tool admission

* fix(sandbox): preserve normalized paths through guard fallback

* fix(sandbox): preserve native file identity across path mappings

* test(agents): align image auth fixture with runtime reads

* test(agents): split workspace filesystem coverage

* docs(sandbox): reference typed filesystem bridge contract
2026-09-16 15:54:51 +08:00
Vincent Koc
09dfdecc54
feat(freebsd): inspect native rc.d service discovery (#148875)
* feat(freebsd): inspect native rc.d service discovery

* test(freebsd): expose native inspector fixture failures

* test(freebsd): initialize native chroot library paths

* ci(freebsd): retain native proof after successful build

* ci(freebsd): remove completed temporary native proof

* fix(freebsd): bound inspector capture lifetime

* test(freebsd): retire temporary inspector proof
2026-09-16 12:43:54 +08:00
Peter Steinberger
bc28af41e1
perf(sessions): validate canonical changes off the Gateway thread (#149388)
Track canonical validation with the physical database verification owner and
certify schema-21 pending rows in bounded retained-worker batches. Keep native
reader admission keyed to its exact handle, main-key policy, and physical
receipt while selected session reads and synchronous commit guards stay current.

Preserve warm transcript-root policy reuse and validation-before-key-refusal
ordering. Keep legacy Workshop catalog repair owned by Doctor, and retain the
published-updater schema migration and backup rollback proof.

Accepted design: #149323.
2026-09-15 21:29:28 -07:00
Dallin Romney
013f409f7a
test(qa): run Discord through Crabline (#116446)
* test(qa): run Discord through Crabline

* test(qa): exercise full Discord scenarios through Crabline

* test(qa): consume Crabline 0.1.24

* test(qa): satisfy Discord transport boundaries

* fix(qa): confine Discord Crabline transport

* refactor(qa): share channel driver option
2026-09-15 03:06:06 -07:00
PollyBot13
8cdb0d6df0
improve: reduce whole-file write receipt latency (#148132)
* improve: reduce write receipt latency by reusing bounded diffs

* chore: expose write diff benchmark as a package script
2026-09-14 22:10:55 -06:00
Peter Steinberger
243f71c53b
fix(gateway): restore Windows scheduled-task inspection (#148671)
* test(gateway): exercise scheduled-task probes on Windows

* fix(gateway): restore scheduled-task inspection on Windows

Allow the task probe to inherit or create a console and emit HRESULTs through the PowerShell pipeline. Preserve probe diagnostics in Doctor and update refusals without granting maintenance authority when inspection is unavailable.

Reported by @westaicommerce (#148601).
2026-09-14 19:00:34 -07:00
Dallin Romney
e0f7f70808
fix(deps): remove vulnerable markdown-it smartquotes parser (#148375) 2026-09-14 13:04:26 -07:00
Peter Steinberger
a393db42e7
chore(deps): upgrade fs-safe to 0.11.0 (#148087)
* chore(deps): upgrade fs-safe to 0.11.0

* docs(secrets): explain hardlinked credential recovery

Document private single-link credential replacement at the configured path. Extend the existing resolver regression to verify rejection, recovery, and preservation of the old hardlink inode and bytes.
2026-09-14 10:46:38 -07:00
Vincent Koc
dff789c0a6
test(e2e): retire obsolete plugin staging smoke (#147555) 2026-09-14 12:30:54 +08:00
Peter Steinberger
f8b194a5be
fix: restore plugin networking under Bun (#147421)
* fix(plugins): normalize network runtimes

* build(plugins): align network runtime dependencies

* test(runtime): stabilize network compatibility checks

* fix(codex): route managed transports through runtime owners
2026-09-13 19:25:19 -07:00
Mohammed Alkindi
659faca280
fix: doctor stays silent when Windows state dir is under OneDrive (#123720)
* fix(doctor): warn when Windows state dir resolves under a OneDrive sync root

Doctor warns when the state directory is cloud-synced on macOS (iCloud
Drive, CloudStorage) and on risky Linux mounts, but stayed silent for
the equivalent Windows case, where OneDrive sync locks, delayed writes,
and Files On-Demand dehydration can make session, credential, and
SQLite state flaky.

Detect OneDrive roots from the OneDrive/OneDriveConsumer/
OneDriveCommercial environment variables the sync client maintains --
canonical roots rather than path-shape heuristics, so ordinary local
folders never match. Comparison is case-folded (Windows filesystems
are case-insensitive) and runs on the realpath-resolved target so
junction prefixes cannot misclassify a local dir.

Closes #98470

* fix(doctor): use Windows shell syntax in the OneDrive recovery hint

The OneDrive warning is only ever shown on Windows, but its recovery
line copied the macOS branch's POSIX form:

    OPENCLAW_STATE_DIR=%USERPROFILE%\.openclaw openclaw doctor

Neither Windows shell accepts inline assignment as a prefix. Verified on
Windows 11: cmd.exe answers "'OPENCLAW_STATE_DIR' is not recognized as an
internal or external command" and PowerShell answers "The term
'OPENCLAW_STATE_DIR=...' is not recognized". Every operator who followed
the hint hit an error instead of a fix.

Emit one line per supported shell instead, both confirmed to set the
variable for the command that follows:

    PowerShell: $env:OPENCLAW_STATE_DIR="$env:USERPROFILE\.openclaw"; openclaw doctor
    cmd.exe:    set "OPENCLAW_STATE_DIR=%USERPROFILE%\.openclaw" && openclaw doctor

The text moves into formatWindowsCloudSyncedStateDirWarning, mirroring
formatLinuxSdBackedStateDirWarning, so the rendered string is assertable
without stubbing platform and filesystem. The guard test greps for the
POSIX prefix shape and fails against the old line.

* fix(doctor): follow a OneDrive junction when the state dir leaf is absent

The detector called realpath on the state dir itself and fell back to the
lexical path when that failed. A state dir that does not exist yet - a
fresh install - cannot be resolved, so a not-yet-created leaf beneath a
OneDrive-named junction that actually points at local storage fell back
to its OneDrive-prefixed lexical path and produced a false warning.

Resolve through the nearest existing ancestor and re-append the missing
segments, which is what the two Linux detectors in this file already do
via resolvePathThroughExistingAncestor. The junction is then followed
even when the leaf is absent.

Adds two tests: the false-warning case, and a guard that a missing leaf
whose ancestor really does resolve inside OneDrive still warns.

* fix(doctor): describe gateway-wide relocation instead of one-shot state-dir hints

* test(doctor): preserve open database families in Windows proof

* test(doctor): identify native state snapshot mismatches

* test(doctor): preserve SQLite data without freezing reader metadata

* fix(doctor): honor selected Windows OneDrive environment

---------

Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>
2026-09-14 01:12:51 +08:00
Peter Steinberger
290613f538
fix(update): derive update budgets from measured state instead of fixed literals (#145219)
Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.

Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.

The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.

The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.

Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.

Refs #144758 #144901 #144890 #143292 #146637 #145252. Preserves the activation boundary from #147019.
2026-09-13 09:41:59 -07:00
Peter Steinberger
a1748139ee
improve: reduce worktree filesystem stalls and archive syncs (#146906)
* perf: consolidate filesystem copy and archive operations

* fix: reconcile fs-safe 0.10 integration checks

* refactor: keep native filesystem execution inside infra
2026-09-13 04:07:17 -07:00
Peter Steinberger
825a904df3
feat(worktrees): share source storage with ReFS clones (#146403)
* feat(worktrees): share source storage with ReFS clones

* fix: correct native output types and TLS sidecar registration

* test(worktrees): handle Windows environment key casing

* test(ui): await catalog refresh publication
2026-09-12 16:33:50 -07:00
Hannes Rudolph
38d95fbbb4
fix(docs): restore publishing without changing existing anchors (#146415) 2026-09-12 14:55:17 -07:00
Peter Steinberger
d13f07b1c2
chore(deps): advance cooled dependencies and major upgrades (#146258)
* chore(deps): advance cooled dependencies and major upgrades

* test(logging): migrate failed-sink regression to tslog 5

* test: retain dependency upgrade coverage within lint limits

* fix(deps): preserve compiler launches, Matrix sync and chat metadata

Keep copied script harnesses independent of declaration modules and preserve
Windows executable prefixes after admission. Audit the Matrix sync guard for
42.3, align CI toolchain/cache pins, and refresh session facts after accepted
model-catalog invalidation without relying on picker timing.

* fix(ui): preserve scoped session reconciliation after catalog refresh
2026-09-12 13:28:12 -07:00
Peter Steinberger
ffa6f5f305
improve: speed up loading long session histories (#146286)
* perf(sessions): reduce history loading work

* fix(tooling): register and trace session history benchmark
2026-09-12 12:02:02 -07:00
Peter Steinberger
e14b3ddac2
improve(memory): keep large-note searches responsive (#146168)
* fix: bound concurrent compute work and pending worker inputs

* fix: supply the host response budget in worker checkpoint tests

* fix: preserve prepared catalog ownership under admission pressure

* improve(memory): keep large-note searches responsive

* fix(memory): preserve worker errors and package boundaries

* docs: separate worker entrypoint guidance

* chore: align metadata extraction with main

* chore: align worker registration for main refresh

* fix(memory): unify metadata reads and worker registration

* fix(memory): preserve overload during index bootstrap and repair
2026-09-12 11:59:24 -07:00
Peter Steinberger
89e54b9d25
fix(agents): release completed liveness join contexts (#146034)
* fix(agents): release completed liveness join contexts

* fix(scripts): avoid returning from liveness proof executor

* fix(scripts): register the liveness retention proof command

* chore: register liveness proof executable
2026-09-12 08:41:12 -07:00
Hannes Rudolph
2227743f74
refactor: split release changelogs and synchronize docs mirrors (#145464)
* refactor: split release changelogs and synchronize docs mirrors

* fix: complete split changelog instructions and validation wiring

* fix: complete release changelog mirror integration

Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver.

* test: align docs agent Git ownership fixtures

Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 21:19:18 -07:00