Commit graph

99086 commits

Author SHA1 Message Date
Vincent Koc
322e358bb0
docs(browser): audit engine licenses and non-AGPL alternatives (#154382)
* docs(browser): audit engine licenses and non-AGPL alternatives

Preserve the reviewed browser-stack change while incorporating the landed prerequisites.

Original revision: 8f41f08a1e92c079ad19ab9f3b849be26cf1559b

* test(gateway): complete prepared placement read fixture

Supply the required empty policyConfig in the placement lifecycle read fixture. This repairs the inherited check-test-types-core-4 failure while keeping the production browser-stack changes unchanged.
2026-09-24 00:01:33 +08:00
Peter Steinberger
19a898ce91
style(sessions): brace the final currentness guard (#156519) 2026-09-23 09:01:04 -07:00
Peter Steinberger
0901260323 test(gateway): complete placement read policy fixture
Supply the policyConfig required by SessionRowReadView after scoped session authorization was introduced. This restores the gateway-root type check without weakening the production contract or changing lifecycle assertions.
2026-09-23 08:52:04 -07:00
Peter Steinberger
b28166ffb9
fix(ui): reduce redundant work while typing and streaming (#156355)
* perf(ui): avoid redundant chat renders and geometry work

* test(ui): install transcript DOM fixtures for identity rendering

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-23 08:40:32 -07:00
RoboClaw
5b29899f06
feat(ui): copy user messages as markdown (#156563)
Add the shared Copy as Markdown control to user messages in Control UI chat, preserving complete message text and the existing copied/error feedback.

Verified the production UI bundle on the exact PR head in Chromium: six native clipboard comparisons passed across desktop and mobile, including long grouped user messages, multiline Markdown, Unicode, and assistant-message copying. Exact-head required CI is green; ClawSweeper has no actionable findings.

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
2026-09-23 08:32:15 -07:00
Peter Steinberger
3720703c4e
docs(release): re-cut only on request; cherry-pick main fixes for blockers only (#156577)
Encode the release owner's directive: a cut candidate keeps its base unless
Peter explicitly asks for a re-cut in that release. Cherry-pick merged main
commits onto the release branch only for confirmed release blockers, each
named in the handoff record.
2026-09-23 08:27:56 -07:00
Peter Steinberger
aa29e14365
test(gateway): assert reclamation runs off the Gateway thread (#156591) 2026-09-23 15:24:47 +00:00
Peter Steinberger
4e9e68140a
fix(zalouser): avoid Gateway stalls during credential persistence (#156003)
* fix(zalouser): avoid Gateway stalls during credential persistence

Move QR credential saves and logout revocation onto the shared SQLite worker,
await their durable completion, and keep restoration behind pending revocation
on its originally selected state directory. Preserve the credential format,
revocation markers, refresh CAS, and named older-host capability fallback.

Carry a live hosted-wizard assertion through setup and into the final write
grant so a detached QR login cannot persist after its owner is retired.

Validation: 172 focused tests across worker storage, registered setup, synthetic
SDK transport, and core wizard lifecycle; complete independent P2 review clean.
Repository gates: 34 passed, 3 unchanged core gates reused. The inherited unused
TSGO_CORE_TEST_MAX_ROOTS export is the sole remaining gate failure on this base;
canonical fix 1619aff478 supplies its repair.

Regression controls prove the former host-SQL logout path, a missing final
wizard-lifetime guard, and state-root drift across a pending logout. No live
provider account, operator Gateway restart, schema change, or protocol bump.

* test(gateway): await recap publication before projection assertion

Wait for the existing owner's next publication after releasing the model result,
assert its captured state without filtering successful outcomes, and check one
direct describe response. Preserve the durable watermark and model-call assertions.
No production logic or test deadline changes.

Validation: 22 cases on the exact tested CI merge with Node 24.21; real writer
queue probe preserves the old updating recap until write settlement, then exposes
the published current recap. Owning type graph, typed lint, formatting, and P2
review pass. The initial CI log redacts the returned summary, so the change does
not claim that its historical failure was proved timing-only.

* test(discord): scope policy reload fixture activation

Limit the synthetic policy fixture to its Discord plugin so real reloads do
not cold-load unrelated runtime plugins. Require the reload to report
applied while preserving the active-turn, held lookup and revocation flow.

Exact CI merge-source proof passed locally in 15.3s. Root fixture types,
typed lint, formatting and independent review passed. No production code
or test timeout changed.
2026-09-23 08:23:57 -07:00
Peter Steinberger
470c69ced0
test(ui): keep reconnect session fixtures consistent
The reconnect cases supplied new titles only in a deferred sessions.list
reply while the mock Gateway retained old canonical rows. A later
sessions.describe response could correctly outrank that older list request
and leave the sidebar showing the old title.

Update the canonical fixture rows before reconnecting, defer the exact
global preview request, and release its normal response. Preserve every
assertion and reconnect/poll budget.

Validation: two-CPU Testbox pressure with one busy process; controlled
before failure 1/1 and after failure 0/1; natural baseline 0/3 and candidate
0/20 failures (220 assertions). All three original 78-file shard replays
passed 303/303, including 33/33 target cases. A fresh-main integration
also passed all 11 cases. P2 review, formatting, diff checks, typed lint,
rejecting canary, coercion and dead-export checks passed. The full UI type
graph retains two independently reproduced baseline Promise.withResolvers
errors in chat-person-reference and chat-scroll tests.

The existing browser reconnect, observer and row-retention coverage costs
44.133 seconds for all 11 cases with one worker.
Sighting: CI run 35673180468, job 106574292641.
Native Testbox proof: run 35869189032; integration: run 35877301218.
2026-09-23 08:23:12 -07:00
RoboClaw
359a8a35b5
fix: show unread marker when a visible session completes (#155690)
* fix(sessions): show unread marker after completion

Co-authored-by: hxy91819 <8814856+hxy91819@users.noreply.github.com>

* fix: show unread marker when a visible session completes

Worked on by:
- @hxy91819

Co-authored-by: hxy91819 <8814856+hxy91819@users.noreply.github.com>
OpenClaw-Publication: e5256717-72f2-4407-a461-f446a7d19ff2

---------

Co-authored-by: hxy91819 <8814856+hxy91819@users.noreply.github.com>
2026-09-23 08:21:44 -07:00
Peter Steinberger
46b698a66d perf(ui): defer Profile identity editor copy
Load Profile-only identity copy through the existing lazy Profile registrar.
Keep shared sidebar and Settings search labels eager, preserve their single
text owner, and compose the complete English catalog in its original order.

Repair the current-main startup asset budget without changing its baseline
or limit: clean main measured 371450 bytes against 371332; the full candidate
build measured 370947 bytes. Visible text and permissions are unchanged.

Validation: exact ordered catalog digest unchanged; keyless i18n verification;
61 existing Profile/access/identity/search tests (5.337s wrapper); UI types;
scoped formatting and lint; full build (250.487s); enforced final asset budget;
fresh independent review with no actionable findings.
2026-09-23 08:20:32 -07:00
Peter Steinberger
b02f2c22d4
fix(ci): give hosted Control UI checks the 35-minute budget on full-release dispatches (#156570) 2026-09-23 08:19:49 -07:00
Peter Steinberger
11867abe45
fix(gateway): session lists stall after identity-scope changes (#156339)
* fix(gateway): retain session facts across identity-scope reloads

* test(gateway): preserve operator scope types in reload fixtures
2026-09-23 08:17:25 -07:00
Peter Steinberger
f6a3ed707c
perf(gateway): select prepared session rows once per read (#156221) 2026-09-23 08:14:46 -07:00
Vincent Koc
645f1bc4ef
feat(browser): add portable Lightpanda deployment and benchmarks (#154360)
* feat(browser): add opt-in Lightpanda semantic profiles

* fix(browser): reject direct selectors for Lightpanda profiles

* feat(browser): add portable Lightpanda deployment and benchmarks

* docs(browser): translate lightweight browser page title

* fix(browser): verify stale targets with a valid navigation control
2026-09-23 15:14:16 +00:00
Vincent Koc
a479b6c4b4
fix(ci): avoid caller PIDs in Doctor identity fixture (#156564) 2026-09-23 23:13:20 +08:00
RoboClaw
b1ec560836
refactor: centralize session-group defaults replacement (#154017)
Centralize authoritative group-default snapshot replacement in the existing helper. Remove the caller’s duplicate projection and retain one frozen-input regression covering omission, explicit false, metadata retention and nonmutation.

No group-ownership, schema, protocol or appearance change. The cleanup reduces production code by three lines.

Implementation and verification: https://team.openclaw.ai/chat/roboclaw/839d1724
Original discussion: https://team.openclaw.ai/chat/roboclaw/dashboard/28feaf46-a23c-468e-bfad-ab44a1d5ac7b

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: shakkernerd <165377636+shakkernerd@users.noreply.github.com>
2026-09-23 15:11:59 +00:00
Peter Steinberger
a1107a5217
fix(update): update system-scope services and hand the restart to the operator (#156584)
Share writable-root admission between Gateway and CLI updates, preserve exact
operator guidance, and join the system-service updater before Gateway exit.
Keep the restart warning visible when later Doctor warnings fill the report.

Fixes #156409. Thanks @ion-developing for the report.
2026-09-23 15:08:36 +00:00
Peter Steinberger
a93058cf4c
fix(plugins): keep the release-only runtime-llm ownership and isolated-reasoning tests green (#156565)
Operator authority currency no longer folds the caller's own abort signal into
assertCurrent, so a caller-aborted direct completion settles through the
provider result again instead of rejecting after the stream ended (regressed
in #156346). The isolated reasoning validation fixture uses max, which stays
unsupported for the host-resolved model now that Ultra is a harness mode on
every runtime (#155393).

Co-authored-by: Peter Steinberger <studpete@gmail.com>
2026-09-23 08:08:11 -07:00
Peter Steinberger
20445202d3
fix(sessions): back off automatic maintenance replans (#156583)
Coalesce invalidated automatic maintenance behind the per-store write-quiet
timer and pause after three consecutive rejections. Preserve pending keys
and commit authority. In warn mode, capture the age fact without creating
a reclamation operation.

Refs #153257. Thanks to @abuegab1-spec for tracing the generation-change
loop and suggesting the explicit warn-mode guard.

Validated with failing baseline regressions, 86 owner/sibling tests,
isolated Gateway write-load and persisted-state proof, and Codex review.
2026-09-23 15:07:29 +00:00
Peter Steinberger
60d25b947d
ci: shorten and split real-Gateway UI validation (#156270)
* ci: shorten real-Gateway UI validation

Use runtime-only preparation while build-artifacts retains SDK declaration checks. Preserve four exhaustive Gateway tours in full manual and release validation with their faster owner-boundary siblings in ordinary CI.

* test(ci): align real-Gateway preparation guards

Keep the paired runtime and UI build contract, assert the existing runtime-only mode, and document SDK validation ownership in the artifact job.

* ci: split real-Gateway UI validation into two jobs

* fix(ci): declare the shared real-Gateway parallel inventory

* test(ci): require manifest strings before decoding

* ci: balance standalone UI proofs across Gateway shards

* ci: defer desktop transport tour to release validation

* perf(test): reuse prebuilt Control UI assets

* test(ui): align Gateway fixtures with catalog and build contracts
2026-09-23 08:04:22 -07:00
holny
19aac94e9e
fix: rewinding a conversation changes its cached prompt prefix (#155749)
Closes #155685

## What Problem This Solves

Fixes: rewinding and resending otherwise identical conversation content changes the cached Runtime prompt because rewind rotates the transcript UUID.

## User Impact

Rewinds no longer introduce this avoidable prompt-prefix change. The stable session key remains available, and transcript IDs still rotate to fence stale writers. No configuration, storage, or permission changes are required.

## Why This Change Was Made

The existing Runtime renderer omits the volatile transcript identifier while retaining isolated-cron key normalization. Runtime metadata inputs and session identity management remain unchanged.

## Evidence

Rechecked on built base `6f90a9a332` and candidate `522b01b387c82254e364c68bac2091cb24a432a3`. Used a normal isolated Gateway, its registered `chat.send` and `sessions.rewind` methods, and the registered Anthropic Messages HTTP/SSE transport against a synthetic loopback provider. Sessions and history were created through ordinary chat sends, not by seeding the store.

| Observation | Before | After |
| --- | --- | --- |
| Stable session key | Preserved | Preserved |
| Persisted transcript UUID rotates on rewind | Yes | Yes |
| Replayed provider history and tools | Identical | Identical |
| System prompt difference | Only the Runtime UUID | None |
| Complete captured resend request bodies | Different | Byte-identical, 14,791 bytes |

An ordinary subsequent turn also completed and retained the successor identity. The public history DTO's transcript-position source metadata changed with the required identity rotation; that is distinct from the byte-identical provider-facing history.

- The value-based rewind regression failed before the fix while the existing isolated-cron control passed. Both passed afterward.
- Earlier focused verification passed: four files, 218 tests, covering the renderer, prompt parameters, CLI consumer, and cache-prefix shaping. The selected run took 59.35 seconds in the wrapper, including cold worker preparation; the rewind and cron value cases took 6 ms and 1 ms.
- Earlier verification also passed both affected test-type projects, production types, scoped lint/format, and structural ratchets. Fresh hosted CI covers the current merged head.

This verifies emitted request bytes and cache-checkpoint placement, not live provider cache hits, token savings, or billing. Provider responses and usage were synthetic; no paid provider calls were made.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-23 20:30:12 +05:30
Peter Steinberger
46e894f891
refactor(plugins): deslop codex and agent-harness plugins (#156297)
* refactor(codex): deslop codex

* refactor(plugins): deslop agent-harness provider plugins
2026-09-23 07:58:14 -07:00
Shakker
2a88df00f6
fix: enable Guest session creation and controls (#155565)
Enable Guest session creation and permitted controls for owned conversations. Keep delayed settings and Stop actions bound to their original session and run.
2026-09-23 15:54:40 +01:00
Vincent Koc
b7eb012f64
feat(browser): add opt-in Lightpanda semantic profiles (#154359)
* feat(browser): add opt-in Lightpanda semantic profiles

* fix(browser): reject direct selectors for Lightpanda profiles
2026-09-23 22:50:37 +08:00
Peter Steinberger
0bd1624a88
perf(state): avoid main-thread subagent completion lock waits
Move subagent completion, recovery, and delivery task writes to the existing SQLite worker and publication owner. Preserve FIFO settlement, exact run/generation ownership, live authority, retries, and shipped synchronous SDK callbacks. Add caller attribution to slow coordinator-wait diagnostics.

A synthetic 600 ms holder reduced maximum main-thread coordinator wait from 603.439 ms to zero native attempts and maximum synchronous call duration from 617.422 ms to 0.684 ms. Blacksmith Testbox proof covers contention, durable outcomes, queued revocation, close settlement, cancellation, and affected Gateway flows.

The caller audit documents remaining synchronous runtime owners; this change does not eliminate every main-thread state write. No schema or configuration changes and no live deployment.
2026-09-23 14:44:29 +00:00
Peter Steinberger
de0d340597
fix(plugins): verify ClawHub archive files by extracted names (#156322)
## What Problem This Solves

Legacy ClawHub ZIP archives can be rejected when the separate preflight parser and the extractor interpret their filenames differently.

## User Impact

ClawHub verifies the extractor's canonical filenames and SHA-256 hashes before installation. A native-backed CP437 archive that previously failed now installs when its files match the advertised metadata. Harmless backslash aliases may normalize to those exact paths, and root-only records that produce no output are ignored. Unsafe paths, collisions, missing or changed files, extra files, named unsupported records, and archive limits remain enforced.

## Why This Change Was Made

The released extractor's existing entry callback supplies the complete canonical inventory, including named records that extraction cannot materialize. Verification hashes the observed regular files in the fresh, unstripped extraction workspace and retains unsupported records without a digest so they cannot disappear from integrity checks.

This removes the second ZIP read/parser and the later directory walk, reducing production code by 48 lines without adding a library API or changing configuration or stored formats. Server-provided paths and generated `_meta.json` validation remain strict. The install documentation records the canonical-name behavior.

## Evidence

- The real native-backed installer CP437 case failed before this change and passes afterward. Synthetic archive proof also covers canonical aliases, inert root records, named unsupported entries, complete inventory/hash matching, unsafe paths, archive limits, cleanup, and installation authority.
- Focused proof passed 146 tests in 33.20 seconds wall time. The changed ClawHub suite measured 107 tests in 23.77 seconds wall time; the final CI repair rerun passed the same 107 tests in 38.04 seconds of wrapper time.
- All 14 affected checks passed in 181.69 seconds. The assertion-safety baseline shrinks exactly from 7 to 5; no boundary waiver or policy exception was added.
- CI identified a facade export retained only by a negative test spy after its production caller was deleted. Both are now removed; the real installer assertions for single extraction, lost authority, absent persistent installation, and cleanup remain. The exact full production and all-export dependency scans now pass, along with affected type, format, and lint checks.
- Fresh independent scoped reviews found no actionable findings. Lead review checked the released extractor's planning/publication guarantee and the final implementation.
- Proof uses synthetic archives and the actual installer on macOS. No live ClawHub service or Windows execution is claimed.
2026-09-23 07:42:46 -07:00
Peter Steinberger
c225612220
test(gateway): join session announcements before reading history
The F112 sibling shard timed out its final five-second chat.history check
after sessions_send had already returned its reply. The tool also starts a
detached announcement whose fixture writes to that same transcript; the
reply does not settle those writes. Diagnostic timing showed the history
request starting 1.4 seconds before the announcement finished.

Retain the real announcement mock's completion and join it before reading
history. Preserve the real Gateway RPC, five-second deadline, transcript
and provenance assertions, and reply-before-agent.wait ordering. No retry,
poll, or production change is needed.

The full file passes 15 tests on the two-CPU pressure Testbox. A one-worker
pnpm test run measured 125.23 seconds including cold setup and transforms.
2026-09-23 07:41:48 -07:00
Peter Steinberger
5ea791a841
test(gateway): prepare compaction before arming observers
The original F112 job replay failed the first manual compaction RPC under
two-CPU pressure. Its lazy handler loaded after the RPC and operation-event
observers started their deadlines. The RPC timed out, leaving both event
promises unobserved until their own deadlines rejected.

Prepare the narrow compaction handler in fixture setup under real timers,
then immediately join the real RPC and both preinstalled event observers.
Keep the existing deadlines and all response, event, and SQLite assertions.
This removes cold test-module preparation from the observation interval and
handles sibling promise failures without adding retries or timer overrides.

The complete compaction file passes 22 tests on the pressure Testbox;
pnpm test with one worker measured 148.35 seconds including cold transforms.
2026-09-23 07:41:48 -07:00
Peter Steinberger
77b3233487
fix(test): settle chat fixtures before releasing session stores
Main run 35819027407 (7f0ea8e54), job 107047075859, returned
UNAVAILABLE from a revoked history worker read in chat.history.
The suite Gateway projection outlives each session fixture, so request
and session admission drains do not settle its pending membership reads.
Unregistering and closing the old store can revoke a read later observed
by the next request.

Opt the chat fixture into projection settlement before unregistration
and after topology publication, before closing the store. Keep other
shared-helper consumers on their existing cleanup path: some deliberately
close databases or seed raw rows before cleanup. A held real-worker-read
regression fails with the original helper's exact revocation error.

Join admitted turns and the actual media-discard promise before asserting
cleanup after an ACK. Preserve abort waiter ordering with a scoped timer
clock, retaining the two-second deadline and all terminal/replay assertions.
Real timers are restored before replay and failure cleanup.

The earlier universal drain was reverted after sessions.create and
permission-root failed in run 35849145166, jobs 107142832758 and
107142832752. This repair enumerates direct and transitive helper consumers
for the required broad Testbox proof instead of relying on changed files.
2026-09-23 07:41:48 -07:00
Vincent Koc
d9bf2a328e
improve(i18n): reuse source hashes in bulk catalog verification (#152657)
* improve(i18n): reduce locale catalog hashing overhead

* improve(i18n): reuse source hashes in bulk catalog verification

* Merge branch 'main' into improve/i18n-prepared-catalog-source

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-23 07:40:00 -07:00
Vincent Koc
a87f01c46c
feat(models): publish v2 catalog beside unchanged v1 (#156530)
* feat(models): publish v2 catalog beside unchanged v1

* test(models): satisfy catalog publisher fixture lint
2026-09-23 14:37:23 +00:00
Peter Steinberger
6619a0e5eb
fix(memory): reject reads outside a replaced authorized directory (#156222)
Related: #154370

## What Problem This Solves

Fixes memory reads returning contents outside an authorized directory when that directory is replaced between path admission and the actual read.

## User Impact

Memory reads and transient retries stay bound to the admitted filesystem root. Existing contained workspace aliases, strict extra-directory rules, hardlinks, literal filenames, Markdown/glob restrictions, file-size behavior, and missing-file versus I/O-error results remain supported.

## Why This Change Was Made

The memory reader now retains the existing fs-safe Root through the content read and retry, replacing separate path checks followed by an unrelated absolute-path read. This removes duplicate containment helpers without changing configuration, stored formats, or public memory APIs. The existing `memory_get` and remote-worker routes continue to call the same reader.

## Evidence

- Two real directory-substitution cases returned outside contents on the original implementation and now refuse the substituted data. Existing compatibility controls also passed on the original source.
- Final focused proof passed 40 cases in 73.022 seconds. The changed reader suite passed all 15 cases with `node scripts/run-vitest.mjs packages/memory-host-sdk/src/host/read-file.test.ts --maxWorkers=1 --reporter=verbose` in 59.985 seconds wall time. Cold preparation differs between runs; no speed comparison is claimed.
- Coverage includes contained workspace aliases, rejected extra-root aliases, hardlinks, literal `~`, Markdown/glob admission, transient `EAGAIN` retries, propagated `EIO`, and missing/error distinctions.
- All selected check components passed across the initial runs and targeted lint corrections, including core and all 25 test type graphs, dead exports, formatting, and the remaining guards. The final ten-command recovery run passed in 583.501 seconds; the original failing check command is not represented as a pass.
- Earlier review findings about retry and I/O propagation were fixed. The final review's Markdown-widening claim was rejected after source inspection: `matchesDirectory` still requires `.md`, its directory branch requires that predicate, and the retained `note.txt` rejection case passes. Raw review findings were preserved; there are no accepted actionable findings. The final lint edit only omitted an identical default `void` type argument.
- Proof used synthetic local files on macOS. No Windows or live-Gateway execution is claimed.
2026-09-23 07:36:09 -07:00
Peter Steinberger
f2d7a0d210
fix(agents): republish model owners after a superseded auth refresh (#156561)
Reuse the auth publication queue and shared typed lifecycle predicate for one fresh-generation retry. Preserve pending gates and record a terminal retry failure so readers settle with a diagnostic reason.

Refs #156178. Thanks @Captain69G for the detailed report.
2026-09-23 14:31:34 +00:00
Vincent Koc
d8bf4703c6
feat(ui): explain connection access in Profile (#156304)
* feat(ui): show connection permissions in profile

* fix(ui): defer profile connection access copy

* improve(ui): explain Profile access in plain language

* test(ui): preserve personal editor through access reconnect

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-23 22:31:06 +08:00
Peter Steinberger
ecf2fc7c17
feat(ci): add bounded retries for declared flaky release jobs (#156463)
* feat(frv): retry declared flaky jobs once per child

Freeze exact flaky-job declarations into the execution plan and admit one
automatic retry wave from child attempt one to two. Retain intent and
rejection witnesses across parent recovery without replaying requests.

Coordinate manual retries with automatic owners, preserve confirmed
no-effect outcomes through later operator attempts, and finish batch
provenance admission before issuing sibling mutations. Refuse unsupported
frozen tooling before creating refs or dispatching validation.

* fix(frv): bind immutable retry cache and workflow fixtures

Limit retry-intent cache saves to parent attempt one after the intent
witness succeeds. Qualify only that exact proof-cache path, key, workflow,
and job under cache isolation.

Refresh frozen dispatch fixture defaults and bind the expanded collector
dependencies and artifact downloads to their owning jobs.

* docs(frv): clarify when retry rejection evidence exists
2026-09-23 07:29:37 -07:00
Vincent Koc
318fc3c41f
fix: align Inbox notification ages and controls (#156560) 2026-09-23 14:26:40 +00:00
openclaw-mantis[bot]
3b77f9653c
chore(ui): refresh control ui locales (#156559)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-23 14:26:21 +00:00
Peter Steinberger
6e424042ad
fix(tests): await SDK retention maintenance (#155659) 2026-09-23 07:25:52 -07:00
Jason (Json)
a5fe21a5e7
fix(worktrees): recover interrupted clean removals (#156529)
* fix(worktrees): recover interrupted clean removals

* refactor(worktrees): name retained Git configuration reader precisely

* test(worktrees): settle recovery fixture state before cleanup
2026-09-23 08:22:35 -06:00
Vincent Koc
6b3eb02c54
feat(catalog): define the model-first v2 feed contract (#156518)
* feat(catalog): define the model-first v2 feed contract

* docs(catalog): explain v2 validation assertions

* fix(models): preserve v2 provider identities during sanitization
2026-09-23 14:19:06 +00:00
Vincent Koc
ab5b994413
improve(i18n): reduce locale catalog hashing overhead (#152355)
* improve(i18n): reduce locale catalog hashing overhead

* Merge branch 'main' into investigate/p13-sha256-helper-20260919

* Merge branch 'main' into investigate/p13-sha256-helper-20260919

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-23 22:15:34 +08:00
Peter Steinberger
917029cc35
refactor: reuse CLI process exit fixtures (#156550) 2026-09-23 07:15:19 -07:00
Peter Steinberger
c755700867
refactor(sessions): share canonical row selection (#156495) 2026-09-23 07:13:47 -07:00
Peter Steinberger
9db35b7514
fix(agentsapi): package the bundled plugin icon, activity mark, and agent-runtimes category (#156549) 2026-09-23 14:08:59 +00:00
Peter Steinberger
9c85b63490
fix(workers): keep running turns on their original session store (#156452)
* fix(workers): keep running turns on their original session store

* fix(workers): stop new transcript submissions after cancellation

* test(workers): assert cancellation stops new transcript writes
2026-09-23 07:08:24 -07:00
Shakker
282fc78eaf
feat: support scoped session reading and organization (#155184)
Allow scoped users to read visible conversations and organize their own existing sessions while preserving separate execution permissions.
2026-09-23 14:56:25 +01:00
Peter Steinberger
482a4b2c49
perf(workers): accelerate warm cloud startup (#156380)
* perf(workers): reduce warm cloud startup work

* fix(workers): preserve snapshot recovery and refresh rules

* fix(workers): avoid lifecycle self-contention during admission

* fix(state): retain warm authority reads for Incognito lifetimes
2026-09-23 06:52:10 -07:00
Peter Steinberger
73788ab0d3
fix(ci): never fail a release image build on the build-limit warning relay (#156444) 2026-09-23 06:50:07 -07:00
Peter Steinberger
668eef7522
perf(secrets): reuse upstream TLS trust and connections (#156357)
Parse the immutable proxy CA bundle once and give each process grant an origin-pooled HTTPS agent. Revoke active and idle connections with their grant.

A 1,000-request local TLS rig reduced SecureContext creation and handshakes from 1,000 to 1, and main-thread CPU from 5.048 to 0.383 ms/request with identical forwarded payloads. All 99 focused proxy tests pass on Blacksmith Testbox.
2026-09-23 06:48:56 -07:00