Commit graph

9965 commits

Author SHA1 Message Date
Peter Steinberger
2ce0573b02
fix(gateway): preserve active work during recovered Node restarts (#153435)
* fix(gateway): preserve work during recovered Node restarts

Let Unix Node recovery wrappers respect the existing Gateway stop budget.
Share startup-safe command classification and deadline facts, and resolve
managed restart intent against the live serving owner in its write
transaction with current update authority.

Preserve the existing public PID intent API, record format, and Windows
behavior. Keep cold lifecycle test preparation outside timed hooks.

Inspired by @ly85206559's wrapper-grace approach in #147054; this repair
is independently authored from main. Related: #146956. Windows cooperative
shutdown remains a follow-up.

* refactor(gateway): stabilize restart callback and test setup

Declare receiver-independent restart intent callbacks as arrows and retain typed signal spy handles for lint-safe assertions. Move cold lifecycle imports into test collection so worker preparation cannot consume timed setup hooks.
2026-09-19 22:41:17 -07:00
Peter Steinberger
af83e3e98d
improve: reduce GitHub API work in PR review and CI polling (#153424)
* perf(scripts): avoid eager PR check expansion

* test: align cross-checkout fixture with lean PR metadata
2026-09-19 22:21:31 -07:00
Peter Steinberger
44b0127030
fix(github): distinguish publication locks from unavailable storage (#152437)
Publication and confirmation now distinguish held workspace leases from unavailable storage and caller-canceled acquisition. The shared SQLite lease owner records these outcomes, replacing the publication-specific retry inference while preserving caller authority, native settlement, and retired-owner fencing.

Doctor records pre-grant cancellation as a visible inspection warning without changing its signal budget or mutating source state. No new configuration, CLI options, schemas, dependencies, or wait limits are introduced.

Validation: scoped-clean Codex review; native SQLite/worker, registered publication RPC, Doctor, updater-authority, and wrapper-boundary proof; exact-head CI gate success. The current candidate's published-updater through healthy Gateway restart scenario remains an explicitly accepted, bounded validation gap recorded in the PR body.
2026-09-19 22:14:42 -07:00
Peter Steinberger
e7f5b8f57a
refactor(package): reuse fs-safe staging-debris traversal (#153400) 2026-09-19 21:54:58 -07:00
Bảo Võ
184cdd4eff
test(update): preserve unverified restart outcomes after package swaps (#142102)
* fix(update): keep a managed update from stranding the gateway after the install swap

A managed package update stages the new version, swaps it over the live
install root, and only then restarts and verifies the gateway. That
restart runs inside the updater process, which is still executing the
build that was just replaced. The bundled dist is split into
content-hashed chunks, so any `import()` reached for the first time after
the swap resolves to a chunk name that only the old tree contained:

  Gateway: restart failed: Error: ENOENT: no such file or directory,
  open '.../node_modules/openclaw/dist/shared-DFJEouXv.js'

`maybeRestartService` caught that as a restart failure, which became
`recovery.serviceRestartSafe: false`, which made the update helper exit
with the unsafe code and log "keep the gateway stopped until the
installation is repaired". The installation was fine -- npm install, the
swap, and doctor had all exited 0 -- but the gateway stayed down until
someone restarted it by hand. Observed on a 2026.9.1 -> 2026.9.2 npm
update: a 3h outage from a successful upgrade.

Two changes:

- Warm the restart path's lazy modules in `beforeActivate`, the last
  point where this process can still read its own install tree. The probe
  gained a loader for `gateway/call.js`, which was a bare dynamic import
  and so could not be warmed.

- Recognize a missing module inside our own install root and stop
  treating it as a verdict on the new install. Restarting the service is
  strictly better than parking it: the old process is gone either way,
  and a genuinely broken install still surfaces through the service's own
  supervision. A missing *data* file in the install root is still a real
  failure.

Claude-Session: https://claude.ai/code/session_01WKVaMWLzdHNJCa82nnTfWg

* test(update): use canonical normalization in restart regression

* test(update): register package-swap regression in its CI owner

* test(gateway): join task events before reset fixture cleanup

* test(gateway): join task events before in-test settlement

* test(gateway): prepare auth command runtime before handshake

* fix(ci): bound serial storage-state test stripes

* fix(ci): scope storage file ceiling to hosted jobs

* test(transcripts): wait for routed provider startup

* test: honor delivery and session fixture ownership

* test(transcripts): join configured provider startup

---------

Co-authored-by: baovo15 <duybao.vin@gmail.com>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 22:50:18 -06:00
Kimi Yu
e1976b0bef
feat(skills): use remote workspace skills in agent tasks (#153126) 2026-09-19 21:48:56 -07:00
RoboClaw
5fa791c28c
fix(e2e): recognize compiled baseline plugin activation (#153410)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 21:28:08 -07:00
Marvinthebored
6f2fabae04
fix: explain apply_patch workspace rejections (#136126)
Explain which workspace policy rejected apply_patch in operator logs across OpenClaw, Codex, and worker execution. Preserve containment decisions, outside files, and model-visible errors.

Refs #93140.
Reviewed-by: @shakkernerd
Co-authored-by: Shakker <165377636+shakkernerd@users.noreply.github.com>
2026-09-20 04:53:45 +01:00
Peter Steinberger
1b5c7dd511
fix(macos): honor worker package timeout budgets (#153380) 2026-09-19 20:37:14 -07:00
Omar Shahine
88c56ec432
feat(plugins): add experimental FaceTime realtime voice bridge (#119291)
* feat(plugins): add experimental FaceTime realtime voice bridge

Co-authored-by: Peter Steinberger <steipete@gmail.com>

Co-authored-by: Dallin Romney <dallinromney@gmail.com>

* test(facetime): align portable release gates

* ci: refresh FaceTime PR checks

* fix(facetime): retain startup suppression through hangup

Begin carrier closure before startup teardown and keep native suppression pending until carrier absence is confirmed.

* fix(facetime): retain cancellation until carrier safety is confirmed

* fix(facetime): separate carrier closure from startup teardown

* test(pr): model authoritative repository identity in sibling fixtures

* fix(facetime): retain suppression without carrier proof

Do not treat the capture watchdog shutdown as evidence that the native carrier terminated. Keep the call unresolved and process suppression retained until exact termination or stable absence is observed.\n\nCo-authored-by: Codex <noreply@openai.com>

* fix(facetime): retain disconnected carrier proof

* fix(facetime): stabilize live audio startup and routing

* fix(facetime): refresh merged lockfile

* refactor(facetime): separate helper result projection

* fix(facetime): align published package metadata

* fix(facetime): satisfy preflight lint checks

* fix(facetime): preserve consult and carrier ownership

* test(facetime): declare regression fixture types

* test(release): align merged publisher inventory

* fix(facetime): retain runtime across safe uninstall

* fix(facetime): restore responsive call opening

* refactor(facetime): keep greeting policy localized

* fix(facetime): accept trusted stock Xcode

* fix(facetime): use compiler link drivers

* fix(facetime): repair portable lifecycle checks

* fix(facetime): normalize installed driver permissions

* fix(facetime): preserve consults during caller speech

* fix(facetime): make answered-call greeting reliable

* fix(facetime): honor explicit agent session owner

* fix(facetime): finish voice consults promptly

* fix(facetime): preserve repeated voice consults

* fix(facetime): settle consult delivery before reporting success

* fix(facetime): retain suppression until carrier closure is proven

* docs(facetime): refresh merged plugin reference count

* fix(facetime): preserve installed driver when backup fails

* test(facetime): prove rejected calls cannot start media

* fix(facetime): verify unknown SIP status before setup advice

* test(facetime): prove caller rejection at authenticated media boundary

---------

Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-09-19 20:36:04 -07:00
RoboClaw
eadd90b8fa
test(e2e): overwrite converged baseline companion fixtures (#153382)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 20:34:48 -07:00
RoboClaw
066a93fbda
fix(release): recognize the reviewed 2026.9.6 plugin inventory (#153372)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 19:59:19 -07:00
Peter Steinberger
e6b30393d3
fix: avoid repeated worker startup for Node state reads (#151929)
* perf(fleet): run registry operations in SQLite workers

* fix(state): preserve readonly admission error context

* test(gateway): retain catalog root failure diagnostics

* fix: preserve uncertain lease outcomes before caller recovery

* fix(state): reject retired read scopes and retain wrapper imports

Reject new admissions to closing or closed selected read scopes while keeping already-admitted readers owned through cleanup. Preserve typed invalidation at plugin discovery boundaries.

Include the retained-read eager dependencies in the canonical PR wrapper inventory.

* test(state): require rejection of retired read scopes

Update the three existing disposable-scope variants to expect the canonical
admission error while preserving active and unrelated source assertions.

* fix(state): keep ordinary reads in the SQLite worker

Use the existing independent readonly worker for ordinary fixed reads while
retaining cached writer custody. Validate captured file identity around opens
and acceptance, and bind previously missing paths when their first file appears.

Keep selected snapshots and native preparation scopes with their existing owners.

* fix: catalog refresh fails when previous discovery finishes

Retain selected plugin registries through awaited preparation and hand construction claims to the completed generation. Preserve stale-publication cleanup and borrowed Gateway-root ownership. Related: #151588, #148290.

* fix(test): retain Telegram suite output on subprocess errors

* fix(ci): require full compact proof for worker policy guards (#151427)

Fix compact CI policy guards that confused a two-worker budget with a parallel-to-serial transition. Preserve inherited job ceilings on already-serial recipients and reject redundant group-policy rewrites.

Select the complete compact plan on Blacksmith and hybrid runs when the owning planner-policy test changes; keep GitHub targeting precise. Production admission-before-placement, worker limits, and measurements remain unchanged.

Validation: focused host-profile and policy cases, serial-policy negative controls, and exact-head CI run 35343663468 passed. ClawSweeper and the retained scoped review found no actionable defects. No user-visible runtime change.

* refactor(state): move fixed-read snapshot tokens off the main thread

* perf(gateway): materialize archived session rows on demand (#151574)

* fix: avoid host-speed failures in catalog performance checks (#151732)

Replace the catalog benchmark's host-dependent 20 ms median limit with 20 times an independent in-process CPU reference. Check every composed list for exactly 20 SQLite reads, including three binding-authority reads, and zero plugin-state worker operations, while preserving the existing native-RPC, file-I/O, and session-payload guards.

This is a test reliability repair with no runtime or update behavior change. Production changes: 0 lines; tests and test support: +61/-7 across two files.

Validation: exact-head CI is green; the reviewed proof includes five passing local runs, two-CPU Testbox and hosted calibration, an extra-SELECT negative control, and a uniform CPU slowdown that fails the independent timing guard. Round-2 Codex autoreview and exact-head ClawSweeper review found no actionable defects.

* test(gateway): match catalog read budget to binding owner

* test(codex): synchronize agent-end context scenarios

Own the fixture clock and wait for turn start and ten response progress
events before selecting completion, cancellation, or refusal. Keep the
five-second budget and require the expected terminal outcome.

Restore real timers before cancelling and joining the run so a failed
assertion cannot discard cleanup deadlines.

Validation: 62 agent-end, deadline, and lifecycle tests; extension test
types; scoped lint and format; independent P2 review. A temporary assertion
failure also verified cancellation, unsubscribe, and joined cleanup.

* test(state): intercept asynchronous snapshot preparation in lifecycle controls

* fix(state): bound and reuse fixed-read workers

Reuse healthy Node execution workers while each read retains its source pins
through native cleanup. Preserve Bun per-task retirement and the public pool
contract with an internal owned-task boundary, exact-slot settlement, and
aggregation of independent cleanup failures.

Carry snapshot reader leases and existing-schema context from the token
foundation. Capture and charge both retained path fields before queueing.
Keep best-effort quarantine admission with its existing owner.

Validated with 83 focused tests, the full changed-file gate, a normal build,
independent P0-P2 review, and five ordinary compiled Node/Bun proof runs.

* fix(tooling): complete extracted wrapper dependencies

Include the worker pool completion, core, and owned-task modules in the
existing PR wrapper component inventory so extracted wrappers reach their
normal argument validation with a complete eager import closure.

Carry the exact packaging fixture repair from canonical
5741b3cbe8 (#151967): copy the existing
packed-openclaw-tarballs helper into the no-dependency harness.

* fix(test): preserve complete Git test inventories beyond one MiB

Carry the exact two-file repair from canonical
fd0c00bbe3 (#151991).

Use the bounded 16 MiB Git inventory capture and reject child-process
errors even with status zero. Preserve working-tree/untracked tests and
the existing filesystem fallback, with the canonical boundary controls.

No unrelated main ancestry or runtime source changes are included.

* fix(sqlite): name scoped worker declaration return type
2026-09-19 19:57:39 -07:00
Peter Steinberger
883b2a9441
fix: keep PR identity checks working when GraphQL quota is exhausted (#153296)
* fix(scripts): use REST for writer identity and reviewer claims

Use included-header REST identity reads through the protected selected CLI, preserving the actual mutation writer and quota diagnostics. Verify reviewer assignment through the REST assignees response. Keep GraphQL contracts for queue state, squash previews, required-check app binding, and atomic publication. Refs #153199.

* test: preserve acknowledgement worker owner checks
2026-09-19 19:50:55 -07:00
Dallin Romney
5cab502457
perf(ci): cache plugin boundary source scans (#151426) 2026-09-19 19:35:28 -07:00
Kimi Yu
59916acb71
feat(agents): send input attachments to remote workspaces (#152652) 2026-09-19 19:34:55 -07:00
RoboClaw
750295a859
fix(e2e): isolate worktree upgrade proof from title repair (#153350)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 19:20:46 -07:00
RoboClaw
286487d234
fix(ui): keep attached context out of message text (#152539)
* fix(ui): keep attached context out of message text

Preserve bounded send-time reference snapshots separately from authored text through queued sends, retries, transcript display, and edit actions. Keep raw context inspectable behind a disclosure without changing its authority.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): complete context attachment CI coverage

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(state): align custody proof with worker acquisition

Apply the already-landed test correction from bfec65a2a0. Release the late competing host owner before awaiting the worker, while preserving authority checks, operation outcomes, and persisted-state assertions. Reproduces and repairs both failures in CI job 105859785996 without production changes or longer timeouts.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(ui): keep simulated history fling events contiguous

Drive the final contact movement, release, and initial inertia in one browser task so RPC latency cannot split the intended continuous gesture. Preserve total movement, stationary-touch coverage, omitted scrollend, and every-frame anchoring assertions.

* test(ui): avoid shadowing the momentum fixture parameter

* test: fix native shutdown and session fixture races

Keep Sparkplug compilation synchronous in test Node processes and propagate the shared argv policy to Vitest fork workers. This avoids a proven compiler/GC deadlock during process.exit without changing production shutdown, assertions, or deadlines. Join background session disk measurements before closing and handing off SQLite fixtures.

* test: fix compiler policy assertion and rebalance UI typechecks

Retain the independent Sparkplug shutdown policy when opting into Maglev. Split chat test roots into an appended shard without changing coverage or root limits.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-19 19:19:31 -07:00
Dallin Romney
3444c7d3dc
fix(release): wait longer for npm publication readback (#151421) 2026-09-20 02:04:34 +00:00
Kimi Yu
14cf1689a8
feat(memory): read and update files on remote workspaces (#153124) 2026-09-19 18:53:57 -07:00
David
c6bb12b061
fix(plugins): reject hollow installs and repair missing dependencies (#103398)
* test(plugins): repro hollow npm dependency tree accepted by install

* fix(plugins): reject managed npm installs with missing required dependencies

npm can exit 0 while leaving the installed plugin's declared dependency
tree unmaterialized; the hollow install previously passed lock-metadata
verification and loaded at startup only to die at import time. Verify the
declared required dependencies resolve from the installed package dir and
roll the managed root back when they do not.

* fix(doctor): detect and repair installed plugins with missing required dependencies

Status surfaces already point users at doctor --fix when an installed
plugin's dependency tree is broken, but doctor only recognized entry
diagnostics and stale runtime packages as repairable. Walk record-backed
snapshot plugins with buildPluginDependencyStatus, surface the missing
package names in the health finding, and route the plugin through the
existing repairable-install flows so --fix reinstalls the package.

* test(doctor): cover missing required dependency detection and repair

* style: apply oxfmt to touched plugin install files

* test(plugins): assert hollow install rollback state

* test(doctor): cover dependency repair eligibility

* fix(doctor): scope dependency repair to active installs

* test(doctor): cover fresh dependency repair generation

* fix(doctor): reinstall broken plugin in fresh generation

* test(doctor): use managed root retention fixtures

* test(plugins): cover optional dependency override installs

* fix(plugins): honor optional dependency overrides

* fix(doctor): preserve intentional disabled-plugin skips

* style(doctor): format capability consent forwarding

* test(doctor): preserve repaired plugin record generation

* fix(doctor): carry repaired records into metadata refresh

* test(doctor): include workspace in record refresh proof

* test(doctor): assert rebuilt cleanup metadata index

* test(doctor): reproduce registry record rollback

* fix(doctor): reload install records before registry repair

* test(doctor): isolate registry cache regression

* test(doctor): reproduce disabled dependency repair

* fix(doctor): ignore disabled dependency repairs

* test(doctor): reproduce hollow runtime cohort drift

* test(doctor): review staged cohort repair artifact

* test(doctor): accept cohort repair capabilities

* test(doctor): stage a valid cohort repair artifact

* test(doctor): materialize cohort repair target

* fix(plugins): carry cohort policy through update specs

* fix(plugins): resolve version-bound updates per target

* fix(doctor): keep hollow runtimes on core cohort

* test(doctor): cover current and pinned hollow runtimes

* test(doctor): expose cohort override drift

* fix(doctor): override hollow runtimes with canonical specs

* fix(plugins): pin canonical runtime overrides to cohort

* test(doctor): reject runtime package identity collision

* fix(doctor): bind cohort override to package identity

* test(doctor): reject conflicting runtime package identity

* fix(doctor): bind cohort override to active package

* test(doctor): respect runtime package selector identity

* fix(doctor): respect runtime package selector

* test(doctor): reject stale runtime identity collision

* fix(doctor): bind stale runtime repair to package identity

* refactor(doctor): isolate runtime package staleness

* test(doctor): enforce runtime cohort acceptance

* test(doctor): model runtime cohort payloads

* fix(doctor): define runtime cohort acceptance

* fix(doctor): reject stale runtime repair payloads

* fix(doctor): pass runtime version to cohort check

* style(doctor): avoid repair input shadowing

* test(doctor): require a fresh runtime generation

* refactor(doctor): name fresh generation failures

* fix(doctor): require fresh dependency repair roots

* test(doctor): model fresh repair generations

* test(doctor): materialize repaired generation payload

* test(doctor): materialize official repair payload

* test(doctor): classify against compatibility host

* fix(doctor): share compatibility host version

* test(doctor): isolate compatibility host cases

* chore: tighten env var name budget

* refactor(doctor): narrow runtime payload metadata

* refactor(doctor): keep cohort matcher internal

* test(doctor): expose runtime cohort source drift

* fix(doctor): classify the active runtime payload

* test(doctor): isolate cohort source cases

* test(doctor): align runtime payload fixtures

* test(doctor): expose cohort rejection commit leak

* fix(doctor): reject stale cohorts before npm commit

* test(doctor): allow updater preflight warnings

* test(plugins): cover npm precommit fallback wiring

* test(plugins): expose rejected generation leak

* fix(plugins): remove rejected fresh npm roots

* refactor(plugins): inline npm update attempt

* test(doctor): reject npm artifact identity drift

* fix(plugins): reject npm package identity drift

* fix(plugins): preserve npm resolution diagnostics

* test(plugins): cover npm identity mismatch diagnostics

* fix(plugins): report canonical npm identity mismatch

* fix(doctor): validate runtime package JSON shape

* test(plugins): reject exact npm selector drift

* fix(plugins): reject npm selector metadata drift

* test(plugins): preserve semver-like npm dist-tags

* test(plugins): preserve npm 12 semver-like dist-tags

* fix(plugins): preserve semver-like npm dist-tags

* test(plugins): cover npm array exact selector drift

* fix(plugins): classify npm array selector drift

* test(plugins): lock exact selector metadata parity

* test(doctor): cover beta convergence identity gate

* test(doctor): cover post-install cohort rollback

* fix(doctor): defer runtime commit through record validation

* test(doctor): cover accepted runtime transaction commit

* test(doctor): cover install rollback on index failure

* fix(doctor): settle runtime installs after index write

* test(doctor): cover deferred cleanup failure

* fix(doctor): preserve committed repair on cleanup failure

* test(doctor): fence runtime repair lease ownership

* fix(doctor): fence runtime repair lifecycle writes

* test(doctor): expose updater repair transaction gap

* fix(doctor): defer updater repair transactions

* test(doctor): cover updater rollback ordering

* refactor(doctor): keep lifecycle lease type internal

* refactor(doctor): centralize repair rollback errors

* docs(doctor): tighten lease cleanup invariant

* refactor(doctor): return lease write promise directly

* fix: mark plugin repair rollback paths terminal

* test(plugins): reproduce hollow dependency package detection

* fix(plugins): require dependency package manifests for install health

* test(plugins): model a complete installed snapshot dependency

* test(plugins): reject successful npm installs with missing dependencies

* fix(plugins): reject incomplete managed npm dependencies before publication

* test(doctor): diagnose active npm dependency corruption

* test(doctor): create complete dependency-health fixture roots

* test(doctor): retain bundled ownership in dependency control

* fix(doctor): attribute missing dependencies to active npm roots

* fix(doctor): report missing required plugin dependencies

* test(doctor): cover dependency repair retention ownership and failures

* test(doctor): materialize successful updater replacement fixtures

* fix(doctor): repair incomplete dependencies through retained npm generations

* test(doctor): cover deferred dependency repair and cleanup failures

* fix(doctor): report dependency repairs deferred by package updates

* fix(doctor): retain visible outcomes for deferred dependency repairs

* style(plugins): keep managed npm dependency imports together

* style(plugins): format dependency status regression fixtures

* test(doctor): cover mixed dependency repair marker ownership

* test(plugins): preserve literal npm tags in singleton metadata

* test(plugins): keep malformed metadata fixtures as array values

* fix(plugins): honor literal tags in npm 12 view metadata

* fix(doctor): narrow optional dependency repair install record

* test(plugins): reject dependencies outside managed projects

* test(doctor): distinguish owned dependency hoists from ancestors

* test(plugins): cover bounded and generic dependency lookup

* test(plugins): compare project alias identity instead of spelling

* fix(plugins): bound managed dependency lookup to its owner

* fix(plugins): verify dependencies within the installed npm project

* fix(doctor): check dependencies against the recorded npm project

* refactor(doctor): isolate configured npm dependency health collection

* refactor(doctor): keep candidate discovery within its module budget

* refactor(doctor): settle marker cleanup before returning or throwing

* style(doctor): format the dependency health collector

* fix(plugins): make dependency boundary exit explicit

* test(doctor): cover stale runtime dependency repair collisions

* style(doctor): format dependency collision regressions

* test(plugins): preserve direct host links during managed installs

* test(plugins): inspect the returned update generation for host links

* test(doctor): preserve healthy canonical host dependencies

* test(doctor): initialize the host dependency fixture directory

* fix(plugins): audit canonical hosts in managed dependency checks

* fix(plugins): preserve audited hosts in staged npm installs

* fix(doctor): reuse canonical host dependency audit

* fix(doctor): await audited managed dependency health

* test(plugins): cover audited host and managed dependency boundaries

* test(plugins): inspect hollow dependencies in the npm stage

* fix(plugins): reject hollow installs and repair required dependencies

Share managed dependency admission with eligible same-version Doctor repair.
Preserve deferred transaction ownership, conditional index publication, and
current timeout forwarding through existing updater and lease owners.

Co-authored-by: nxmxbbd <32288+nxmxbbd@users.noreply.github.com>

* test(plugins): preserve hollow-install coverage within CI boundaries

* test(gateway): await private timeout registration settlement

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: nxmxbbd <32288+nxmxbbd@users.noreply.github.com>
2026-09-19 18:51:06 -06:00
Peter Steinberger
d22782a7f0
refactor(state): share the agent database worker lifecycle (#153150)
* refactor(state): share the agent database worker lifecycle

* fix(state): retain canonical worker identity during cleanup
2026-09-19 17:08:16 -07:00
Peter Steinberger
18f1c117e6
fix: resume unfinished tasks after Gateway restarts (#153243)
Recover interrupted parent turns regardless of subagent-result provenance. Settle interrupted children through normal completion and let the parent inspect retained state before continuing or replacing them. Remove automatic child relaunch and retry machinery, preserve existing receipt reconciliation, and fence cleanup against newer owners.
2026-09-19 17:07:32 -07:00
Peter Steinberger
8e7443e653
fix(codex): preserve delivery facts and native approval semantics (#151863)
* fix(codex): preserve delivery facts and native approval semantics

Keep failed sends from suppressing replies or recording false delivery. Share the host delivery facts before presentation middleware, preserve per-artifact media and finalized native text, and honor native approval lifetimes and explicit form answers.

Replace duplicate delivery and quota decisions with their existing owners. Document the seven shared SDK helpers and apply the approved seven-export and seven-callable surface budget increase.

* test(codex): align native fixtures with canonical outcomes

* test(codex): align mirrored transcript assertions

* fix(codex): retain core conversation delivery receipts
2026-09-19 16:45:20 -07:00
Peter Steinberger
0a3302711b
fix(macos): show About in native connection settings (#153184)
Open About beside Connection and Gateways without requiring a Gateway connection. Replace the obsolete menu-bar description with the current homepage tagline, retain build metadata and resource links, and add Copy Build Info.
2026-09-19 23:40:58 +00:00
Jason (Json)
97c7b35933
fix: complete Gateway upgrades after Node prefix changes (#145335)
Complete managed Gateway upgrades after Node prefix changes while preserving the verified service during preparation and recovering only owned failed activations.

Keep requester/executor and original/candidate ownership through native children; retain uncertain cleanup and original failure outcomes. Source and isolated native component checks are documented in the canonical PR. The wider first-hop installer and other platform journeys remain separate program work.

Closes #107930. Canonical PR history retains the original contributor commits; repository-supported squash preserves explicit contributor credit.

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-09-19 16:58:05 -06:00
Ben.Li
216998cac9
fix(install): fall back to portable Node after package manager failure (#134386)
Windows installations can now recover automatically when winget, Chocolatey, or Scoop fails or leaves an unsupported Node.js runtime. Guarded package-manager attempts warn and continue through the remaining methods to the existing elevation-free portable Node installer. Runtime validation still gates OpenClaw installation.

The installer remains the sole owner of runtime provisioning. Updated Windows documentation and regression coverage describe and protect failure fallthrough, successful recovery, and final refusal when no usable runtime can be provisioned.

Validation: all 99 exact-head checks completed without failures, including Windows installer CI and openclaw/ci-gate. The isolated Windows recovery trace exercised real portable download, extraction, PATH recovery, and runtime/SQLite validation after an injected Chocolatey failure. Codex review was scoped-clean; ClawSweeper reported no actionable findings or Rank-up moves.

Related: #133869
2026-09-19 14:51:05 -07:00
Josh Lehman
cde6bbdcfe
feat(plugins): add decision models with per-agent selection (#152237)
* fix(plugins): preserve authored config through runtime load plans

* feat(judgments): add typed provider runtime and plugin SDK

* feat(plugins): add per-agent decision models

Add an opt-in decisionModel role for typed choices, scores, and boolean
probabilities, with global defaults and per-agent inheritance or disablement.
Keep provider lifecycle and prepared credentials host-owned, and expose
manifest-only decision choices separately from conversational model catalogs.

Adapt the provider foundation from #152237 to the decisions contract. Existing
configurations keep decision calls disabled until a model is selected.

Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>

* fix(plugins): complete decision inspection and preserve authored config

Expose optional decision-provider health through the Gateway wire schema
and generated native DTOs. Preserve the landed SecretRef prerequisite’s
identity behavior for unchanged activation plans. Move model mocks into
one private sibling factory without expanding the public helper surface.

Validation: 51 handler/protocol tests, 18 post-extraction tests, 52 runtime
and integration tests, generated protocol checks, and clean P0-P2 review.
The SDK surface-budget increase remains pending maintainer approval.

Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>

* perf(plugins): reduce decision overhead and unnecessary reloads

Keep one full provider input snapshot and an independent question rubric. Recognize decision-only catalog providers with the existing normalization policy, and reload plugins only for decision-model changes while preserving roster actions. Apply the approved SDK surface increment and behavior-neutral cleanup.

Validation: 58 runtime/config/loader tests, 610 Gateway regression/sibling tests plus 15 final catalog cases, full core typechecks, scoped lint and clean managed review. A 143155-attempt synthetic stress run settles all 18104 provider calls at max concurrency four.

* fix(plugins): preserve reload boundaries and decision test contracts

Materialize only present decision-selector leaves so Telegram account creation/removal retains its parent lifecycle action. Select UI controls by model role, preserve independent chat and decision catalogs in tests, remove an unused probe, and rebalance existing typecheck shards without raising their limits.

Validation: 588 reload tests, 58 shard/loader tests, 38 UI catalog tests, 9 browser tests, affected typechecks, unused-file scans, and clean managed review.

* test(ui): address model pickers by role in gateway flows

Disambiguate Primary from the new Decision picker in the real-Gateway catalog test, alias browser test, and Agents view assertions. Preserve draft and publication checks. Unit/browser/typecheck proof and managed review pass; real-Gateway execution follows on the integrated build.

* test(plugins): isolate runtime metadata and preserve shard headroom

Move the existing lazy-runtime metadata contract intact into its own focused module. Group CLI program tests with commands so newer main tests keep every typecheck shard within existing limits. No production changes or limit increases.

Validation: 57 tests, four typecheck graphs, canonical line guards against the CI main snapshot, targeted lint and clean managed review.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
2026-09-19 14:37:53 -07:00
gennadyclaw
6f36619571
fix(imessage): keep queued answers attached to their questions (#150626)
* fix(imessage): keep queued answers attached to their questions

* fix(imessage): keep queued reply targets with correct provenance

* test(agents): isolate CLI image capability discovery

* test: await asynchronous owner completion

* test(cron): await deferred session cleanup

* test: await lifecycle settlement in CI fixtures

* test(codex): compile catalog workers before fixture requests

* test(codex): keep worker declarations out of root builds

* test: use Git transport for wrapper fixture clones

---------

Co-authored-by: gennadyclaw <275141878+gennadyclaw@users.noreply.github.com>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 13:50:15 -06:00
Peter Steinberger
d13df30cf7
fix(scripts): report quota from the failed GitHub response (#152723) 2026-09-19 12:36:57 -07:00
Peter Steinberger
3a722d4c62
fix(ci): keep security review pending while CI runs (#153005)
Distinguish missing or active CI from failed CI. Keep the required combined status pending without failing the waiting review job, and fail visibly on approval, CI, metadata, or evaluation errors. Preserve workflow, head, attempt, and authority checks.
2026-09-19 12:24:53 -07:00
Kimi Yu
b856d4e0f4
feat(workspace): share document policy and unavailable errors with adapters (#152635) 2026-09-19 11:51:53 -07:00
Josh Avant
fda6fb3016
fix(ci): avoid stale Security Review failures after reevaluation (#153089) 2026-09-19 13:31:50 -05:00
Peter Steinberger
62d82f91fe
fix(ci): retain valid installed startup CPU diagnostics (#152888) 2026-09-19 09:50:10 -07:00
Peter Steinberger
f8f1ad8381
fix: settle shared SQLite worker ownership before retirement (#152873)
* fix: settle shared SQLite worker ownership before retirement

* fix: recover shared SQLite workers after completed cleanup
2026-09-19 09:33:10 -07:00
Peter Steinberger
a528e8a7fa
refactor(config): isolate value traversal from config IO (#152490) 2026-09-19 08:34:14 -07:00
RoboClaw
e2bcb1614d
feat(ui): start background sessions from the command palette (#152370)
* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: 14827970-7924-451d-8862-e4823c8d05b3

* fix(ui): complete command palette integration checks

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: 07e9b68b-7855-4ef0-afc6-1c89b594225f

* fix(ui): preserve palette preferences across main integration

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: 3362af9f-c880-4d89-8a06-573005a0fff6

* fix(ui): integrate canonical auth recovery prerequisite

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: 838a5d1a-6420-421b-b69d-1f5822c41608

* refactor(ui): keep modal element lookup private

Preserve the uncached Lit query behavior through a native-private getter so normal minification keeps the focus repair within the unchanged startup budget.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>

* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: d2d0c3a7-7dc0-45b8-8eb6-48b0bcf55e17

* fix(ui): settle palette resize proof within startup budget

Keep ResizeObserver as the input geometry owner and remove the never-shipped window-resize fallback. Wait for a quiet three-frame mutation window after finite observer updates settle instead of assuming two RAF callbacks drained resize delivery. Keep timeout defaults, geometry assertions and performance budgets unchanged.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>

* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: b678acf2-311a-4e4b-a837-84795cde5209

* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: 74931436-9bf0-4269-a1e7-4c2adafebd28

* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: 8172c174-201a-4126-8d06-95bbdd8878d9

* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: 60b33350-94a6-4e48-a116-b8deb745fb32

* fix(ui): use the default route type in shell docks

Remove the redundant RouteId type argument from the newly integrated shell docks consumer. ApplicationContext already defaults to RouteId; preserve the same type and emitted runtime behavior while satisfying the hosted type-aware lint gate.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>

* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: fcaa690c-b240-4847-b767-c2a43664b677

* feat(ui): start background sessions from the command palette

Worked on by:
- @steipete
- @vyctorbrzezowski
- @jalehman

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
OpenClaw-Publication: c484dcd8-8089-44ab-a691-d8804bff5c68

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
2026-09-19 08:21:22 -07:00
PollyBot13
2123133078
fix: preserve exhaustive upgrade release coverage (#145874)
* fix: preserve exhaustive upgrade release coverage

* test: isolate upgrade baseline fixture dependencies

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 09:13:37 -06:00
Peter Steinberger
cf399a2a7a
fix: avoid blocking Gateway requests during skill archive commits (#152816)
* fix: avoid blocking Gateway requests during skill archive commits

* fix: include upload error in native wrapper sources
2026-09-19 07:48:56 -07:00
Peter Steinberger
75a3213b93
fix(ci): reuse REST metadata for rollup attachment (#152893) 2026-09-19 07:40:15 -07:00
RoboClaw
28d8ee4f09
fix: sandboxed sessions cannot edit managed projects (#152641)
* fix: sandboxed sessions cannot edit managed projects

OpenClaw-Publication: 5fe32b07-39e6-4bf4-95cd-08d71841c971
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(sandbox): fence retired workspace effects and preserve cleanup ownership

Keep final filesystem and runtime effects behind captured authority, retain one removal cleanup owner, and complete source/type and synthetic-fixture custody contracts.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(sandbox): preserve guest teardown and selected project directories

Retain marker-bound process cleanup after execution authority retires, revalidate Codex transports at spawn, preserve selected project subdirectories, and repair canonical publication fixture custody without weakening sandbox or receipt guards.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(codex): reject retained input after workspace revocation

Carry captured child authority through pipe, PTY and HTTP input and settle failed readiness handoffs without losing termination custody. Bind publication lifecycle fixtures to the actual canonical session store instead of an obsolete custom path.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(skills): report stalled watcher settlement phases

Record failure-only watcher readiness and pending timer callsites to diagnose the repeated native Windows CI hang. Keep all behavior assertions and timeout values unchanged.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 07:29:22 -07:00
Peter Steinberger
f6d3da2272
ci(test): size Vitest workers from measured CI headroom (#152864)
Use measured CI-only six/eight-worker memory tiers for roomy serial self-hosted jobs. Retain local behavior, actual-host fallback limits, Gateway exclusivity, unproven group caps, and historical timing floors. The twelve predefined Blacksmith probe samples passed; native PR CI remains a separate validation step.
2026-09-19 06:37:55 -07:00
Peter Steinberger
3055a08326
fix: preserve causes in unexpected update failure reports (#152331)
Preserve the reached update operation, recorded target and installation facts,
bounded redacted exception causes, and measured rollback outcomes in unexpected
failure reports. Capture and project these facts through the existing update
ledger, failure-fact, and public-identifier owners while preserving report consent,
preview custody, and recovery authority.

Optional diagnostic writes cannot replace the original failure or interrupt
recovery. Rollback summaries are recorded after complete service-definition
restoration. Existing JSON records gain optional nullable fields; SQLite remains
at v17 with no migration or new configuration.

Validated with focused regression suites, published 2026.9.4 updater and older-reader
compatibility proof, scoped-clean independent review, and exact-head CI (156 jobs,
zero failing required checks).

Related: #152193
Thanks to @bobbygaerd for the report.
2026-09-19 06:37:04 -07:00
Peter Steinberger
88df612b94
feat(usage): restore history and add creator breakdowns (#152528)
* feat(usage): restore history and add creator breakdowns

Show the last 30 calendar days with complete server-side aggregates and creator filtering before row limits. Fix chart segment styling, remove redundant cost loading, and recover gracefully from incomplete usage and transient busy responses.

* test(usage): migrate browser proof to consolidated reports

Keep calendar, recovery, selected-control and provider convergence coverage aligned with server-owned daily costs and the bounded 5/10/20-second retry schedule.

* test(usage): complete single-report reconnect coverage

* fix(usage): align creator totals and ranges with selected days

Scope creator amounts and JSON exports to selected daily buckets. Carry the chart’s displayed calendar order into mouse and keyboard range selection, including empty days and filtered partial reports.

* fix(usage): preserve complete creator totals for day selections

Aggregate daily amounts and date-set session counts before the row limit. Keep off-page creators and distinct multi-day counts in the breakdown, headline, and JSON export while preserving explicit client row filters.

* style(usage): make cohort sorting and fixtures explicit

* fix(usage): hydrate context after creator filtering

Preserve saved context details for creator-filtered rows beyond the unfiltered page. Keep heavy reads bounded to emitted rows and retain fresh identity and visibility checks. Extend the owner integration matrix with red/green creator-filtered context and bounded-read coverage.

* test(cron): await cleanup and control manual timer ticks

Await the existing Gateway deletion operation instead of polling an arbitrary deadline. Keep the manually driven reaper suite from starting real two-second background ticks while archive workers settle. Preserve the existing session, owner and cleanup assertions; production scheduling is unchanged.

* fix(auth): await refresh settlement before retrying stale reads

Observe the existing OAuth producer after reader cleanup and before the single retry. Scope observation to current credential ownership and the canonical refresh generation, including inherited, fenced and portable peers; retire replaced claims without releasing remaining cleanup.

Reproduce pending/final publication races and ownership changes with controlled real-manager tests. Validate 75 focused cases, affected types and lint, and all three rebuilt Gateway quota-recovery scenarios. Independent review has no actionable P0-P2 findings.

* fix(usage): integrate worker discovery and selected exports

Keep inventory on the existing Usage worker without materializing archive payloads. Preserve async collection access and native cleanup for actual readers, and align export availability with loaded selected rows while retaining complete creator and daily JSON totals.

Validated 106 worker cases, 16 actual Usage RPC and worker entry cases, 57 UI cases, 22 cron cleanup cases, affected types and lint, and the runtime build. Fresh independent review has no actionable P0-P2 findings.
2026-09-19 06:33:46 -07:00
Gio Della-Libera
cbf935baba
fix(plugins): archive updates fail on development-only dependencies (#143350)
* fix(plugins): isolate npm manifest resolution

* fix(plugins): preserve hook host dependencies

* test(plugins): align npm isolation coverage with CI limits

* fix(plugins): link optional-only OpenClaw host dependencies

* test(gateway): settle companion databases before fixture cleanup

* test(plugins): cover optional hosts in native import preparation

* test(skills): close status watchers before retiring fixture roots

---------

Co-authored-by: Gio Della-Libera <235387111+giodl73-repo@users.noreply.github.com>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 07:08:53 -06:00
Peter Steinberger
8277325ccf
fix(nodes): prevent orphaned work and incompatible launches (#149158)
* fix(nodes): prevent orphaned work after cancellation and crashes

Keep hosted-worker capacity occupied until the process owner confirms descendant cleanup. Preserve completed turn results, peer isolation, and recoverable cleanup ownership when a replacement node host shuts down.

Allow the exact cancelled worker to settle its finishing acknowledgment without recreating publication or execution authority. Carry private lineage descriptors through the existing worker-start channel and package the sealed relay and anchor with the worker bundle.

* fix(nodes): preserve compatible starts across fleet upgrades

Keep released workers on their supported type-only startup and detached process-group owner. Select stronger relay ownership from the worker build capability.

Negotiate captured exec-policy support separately at node inventory so unsupported hosts show the existing update-required outcome before OpenClaw worker dispatch. Preserve remote-exec eligibility, current-authority checks, and cleanup operations.

Validated with released-worker startup and termination proof, registered inventory and dispatch regressions, focused sibling tests, changed checks, and independent review.

* test(nodes): keep current-worker fixtures eligible

Declare captured exec-policy support on the five current-node fixtures that exercise prepared dispatch, replay, authority revocation, and admission. Forward execution mode through the prepared fixture currentness callback independently of slot consumption.

Preserve assertions and deliberate legacy and remote-exec fixtures. All16 reproduced failures are fixed;243 tests across16 files and selected checks pass. Production, build, and dependency inputs are unchanged from97fe.

* ci: refresh node lifecycle merge validation

* fix(node-host): preserve cleanup evidence during worker recovery

Restore released process-group recovery after the leader exits. Record the selected transport before admission and retain exact-anchor root/lineage completion in a journal-owned companion table before releasing capacity after restart.

Use existing-file completion transactions so late cleanup cannot recreate removed state. Preserve public receipts, schema version and terminal retention; drain active modern workers before rollback to an older writer.

* fix(node-host): keep schema DDL annotation beside its call

Preserve the existing canonical first-use schema exception at the leading callsite recognized by the SQL guard. No SQL, guard rule or runtime behavior changes.

* fix(node-host): load journal writer before source helper cleanup

* test(macos): gate readiness recovery after owner failure

Hold the failed startup owner beyond an explicit waiter budget, then require a fresh health request and cleared failure state. Preserve the owner deadline and join cancellation cleanup. Production inputs are unchanged by this commit; disposable native proof runs on a separate task branch.

* fix(nodes): keep free capacity available during recovery

Bound observation of an unfinished cleanup anchor without releasing its reservation or escalating against it. Reconcile retained physical owners through status even when their requested turn has completed, preserving the turn outcome and requiring both lineage completion and tree extinction before freeing capacity.

* fix(nodes): recover capacity after bounded restart observation

Retain exact cleanup observation in the node supervisor after startup returns, publish freed capacity automatically after verified cleanup, and stop and join observation on shutdown. Share cancellation intent and preserve completed turn results.
2026-09-19 05:34:17 -07:00
Vincent Koc
1232d3f13e
fix(update): converge post-core work in the candidate runtime (#144317)
* refactor(test): centralize worker declaration metadata

Replay the reviewed first tooling layer on the current frozen main base. Keep package activation declarations reserved for the later owning layers; preserve the inherited main build graph and test coverage.

* fix(update): bind recovery admission to existing authority

Replay the reviewed authority layer on current main, preserving the diagnostics import owner. Retain Json (fuller-stack-dev) rollback-journal and Bun regression coverage; restore NORMAL reader policy after rollback-mode admission so retained Bun statements do not hold locks after settlement. Later FD3 custody remains in its owning layer.

* fix(config): retain authority across config persistence

Replay the accepted config authority layer without behavioral changes. Preserve producer-owned write guards through backup, snapshot, persistence, reread, and error settlement.

* fix(plugins): fence convergence with lifecycle authority

Replay the accepted plugin authority layer without behavioral changes. Keep install-record, peer-link, retention, doctor repair, and cohort operations under their existing canonical lease owners.

* fix(update): preserve authority through post-core convergence

Replay the accepted five-file post-core convergence layer without new behavior. Keep config and plugin operations within the existing admitted owner scope.

* fix(plugins): preserve first authority refusal during repair

Keep authority failures outside filesystem warning conversion, retain the first callback refusal through normalized installer outcomes, and join admitted peer repairs before rejection. Preserve the synchronous peer guard and lease-bound index CAS finalizer.

Adapt the Doctor and convergence ownership pattern from Jason Sy in #144130. Focused red/green: 23 failures became 32 passes; full peer and retention controls pass 37 cases. Native review raised an overlapping async callback scenario; source review rejects it because the current per-invocation Doctor path is serial. Root final-effect and installed integration gates remain open.

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>

* fix(config): refuse guarded include writes before effects

Reject include-owned mutations carrying inherited authority, explicit assertCurrent, or beforeCommit before Root preparation and backup effects. Remove the unreachable guarded include publisher and retain ordinary include publication and custom-root IO ownership.

Three missing-refusal regressions reproduced before the repair. All 107 cases in mutate, io.write-lock and io.write-reread pass, including ordinary include exclusion and compensation controls. Native P1 review is scoped-clean. The fs-safe final-effect contract and installed candidate integration remain separate draft gates.

* fix(config): retain update authority through runtime activation

* fix(plugins): repair leased authority CI coverage

Remove the unused unleased record writer and seed test fixtures through the canonical store producer. Keep compiled Doctor fixture module identity and direct leased-writer assertions.

Bind registry authority callbacks and correct the focused fixture typing and lint errors without weakening refusal checks. Independent source review and native P0/P1 review passed; runtime and hosted CI qualification remain pending.

* test(plugins): omit redundant deferred type arguments

Use the existing void generic default for the three deferred test controls. The correction emits byte-identical JavaScript and preserves all assertions.

This trivial test-only delta was independently verified after the full L4 P0/P1 review. The earlier focused 295-test and selected typecheck passes remain source-bound; the failed lint surface and unrun export scans still require qualification.

* test(plugins): cover synchronous host-link admission turns

Retain the three filesystem API-entry scheduling controls contributed by Jason Sy (@fuller-stack-dev) in https://github.com/openclaw/openclaw/pull/144316#issuecomment-5632474077.

Cover missing node_modules, stale symlink, and package-copy replacement while preserving the existing synchronous authority contract and test seed helper. These controls observe API-entry timing, not native filesystem-effect atomicity or an observed regression on this source.

Independent exact-block review and fresh full L4 native P0/P1 review passed. Targeted execution of these added cases remains pending.

* fix(update): omit absent config write authority options

Preserve the normal config writer options when no updater authority is supplied. Keep guarded writes unchanged and avoid undefined caller callbacks shadowing prepared options.

* fix(update): bind migrated finalization to candidate runtime

Move the existing worker-local finalization context into the convergence layer without serializing it or changing authority. Preserve the original finalization fence through the shared candidate phase.

Add the actual worker caller-binding regression and candidate lease and executor controls. The unchanged worker regression failed on the parent source; final-head runtime and native qualification remain pending.

* refactor(update): share restart sentinel notification options

* fix(plugins): retain updater authority through package settlement

* test(plugins): verify publication across updater revocation

* fix(test): satisfy updater authority lint rules

* fix(update): preserve first authority refusal through Doctor finalization

* test(update): qualify guarded convergence across current CI lanes

* fix(update): retain live authority in fresh Doctor children

* test(update): preserve Doctor authority in CLI fixtures

* test(update): share legacy Doctor command matching

* fix(config): retain root publication identity for compensation

* test: stabilize backup identity and trace watcher failures

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 06:17:34 -06:00
Peter Steinberger
68e23ccf84
feat: let agents apply plugin and personal themes (#152460)
* feat: let agents apply plugin and personal themes

Add declarative plugin theme metadata, descriptive theme list/get/set/import operations, and shared profile appearance writes. Plugin additions and palette updates follow hot reload without a Gateway restart. Preserve legacy local imports, bound profile authority, and atomic concurrent preference updates.

Refs #152449.

* fix: complete theme integration and defer catalog loading

* refactor: share theme mode validation and trim startup work

* chore: shrink theme assertion allowances

* test: await the initial Android gateway handoff

* fix(gateway): settle chat waits after user cancellation

* fix(gateway): preserve upstream cancellation settlement

* test(memory): preserve real worker deadline clocks

* test(daemon): preserve distinct replacement fixture identity

* test(transcripts): await completed automatic capture startup

Observe the real startup promise before exercising next-day account ownership, and always stop the service during cleanup. This removes the provider-entry timing race while preserving the ownership assertions.
2026-09-19 04:51:01 -07:00
Peter Steinberger
760f4b5b77
test: diagnose stalled infra test workers (#152381)
Infrastructure tests could pass and then stall during fork termination without identifying the outstanding resource or blocked wait.

Extend the existing diagnostic forks adapter to the infra pool and capture bounded active-resource, thread, child-process, and blocked-wait evidence after ten seconds. A separate Linux observer can collect evidence even when the worker event loop is blocked. Preserve Vitest shutdown ownership, deadlines, isolation, and worker limits, and join diagnostic capture before removing its temporary directory.

This is internal test instrumentation with no user-visible runtime change. The natural intermittent stall was not reproduced, so this change does not claim to resolve its root cause. Related: #151663, #151946.

Validation: normal shutdown and three injected stalled-shutdown scenarios, Linux observer boundary proof, 93/93 routing assertions, and changed-file checks passed. The hosted campaign passed 20 repetitions, 80 plan invocations, and 1,000 fork teardowns. Exact-head CI run 35416912203 passed; the native watcher excluded 12 superseded check contexts. Campaign autoreview was scoped-clean, and the exact-head ClawSweeper review had no actionable findings or Rank-up moves.

Production LOC: 0. Tests: +123/-23. Test support: +272/-5.
2026-09-19 03:53:39 -07:00
Peter Steinberger
a980c88c88
fix: avoid cold Matrix auth checks without persisted state (#152576)
* fix: avoid cold Matrix auth checks without persisted state

* fix: sync Matrix prerequisite in official channel catalog
2026-09-19 03:41:48 -07:00