A named profile's readiness failure required port-ownership proof, which always fails without a listener PID, so the real startup error was replaced by a phantom port conflict. Check ownership only when something is listening; ready results keep strict ownership proof.
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Project permitted model catalogs and defaults through the shared role-policy owner. Retire stale choices on policy changes while preserving session history and saved model preferences.
Enable authenticated users to edit their personal instructions from Profile or chat on multi-user Gateways. Keep single-user Gateways on the workspace-root USER.md.
Preserve requester-bound authority, safe local writes, conflict checks, reconnect drafts, normal Profile spacing, and the startup performance budget.
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Source and performance budgets shared fatal exits with correctness checks,
so ordinary growth could block otherwise valid changes. Centralize limit
severity and GitHub annotations/summaries, keep local checks strict, and
carry warnings across native lint, container, and BuildKit boundaries.
Keep semantic lint, types, API inventories, source ownership, invalid
measurements, process failures, and runner admission guards blocking.
Validation: P2 review clean; three Linux owner-configuration replays and
20 standalone policy runs passed; typechecks, targeted type-aware lint,
Knip export scans, workflow checks, formatting, and diff checks passed.
The changed gate found a test environment typing error, corrected and
verified by the root-test typecheck. One unrelated preparation process
cleanup failure did not reproduce in its diagnostic replay; no fix claimed.
* ci(android): retain Gradle caches and parallelize phone test classes
* test(android): advance reconnect retry timers with a virtual clock
* ci(android): balance app lint across existing native jobs
* ci(android): run all four native rows without a second wave
* ci(android): preserve hosted fallback resource limits
## Summary
`QuickChatCatalogPresentationTests` › "rendered Quick Chat preserves catalog disclosure and shortcut behavior in order" fails intermittently in the hosted `macos-swift (tests)` job (Full Release Validation runs 35761278329 and 35802234377 for 2026.9.6; passes locally). The uploaded `macos-native-test-logs` artifacts show two failure shapes, both environmental:
1. `QuickChatPresentationTests.swift:304` `Expectation failed: condition()` with the diagnostic `Quick Chat presented: visible=true, active=true, key=true, editorReady=true`. The only wait that can fail with that state is `waitUntil { !application.isActive }` after `application.deactivate()`: the hosted runner never hands activation to another app, so the *precondition* for "presents without foreground ownership" is unattainable there, while the behavior itself (panel visible, editor focused, reopen, disable) is proven.
2. On frozen release targets (`HISTORICAL_TARGET=true`) the rendered suite still runs in the parallel default lane. Parallel suites open key windows, Quick Chat dismisses on focus loss by design, and the test then reports `windowVisible=false windowKey=false` plus a reset `model.speed` (the 5-issue attempt). Current targets already isolate the suite into the `default-rendered` lane; frozen targets did not.
## Changes
- `apps/macos/Tests/OpenClawIPCTests/QuickChatPresentationTests.swift`: the activation hand-off before firing the shortcut is a bounded, non-asserting `poll` that prints whether the host yielded activation; every behavioral assertion after it is unchanged. `waitUntil` now delegates to `poll`.
- `.github/workflows/ci.yml`: run the isolated `default-rendered` lane for frozen targets too whenever the suite exists in the checked-out tree; older tags without the suite keep the single default lane.
## Proof
- Local `swift test --disable-sandbox --filter QuickChatCatalogPresentationTests` (apps/macos): 5/5 passes.
- One extra run with another application in the foreground (app deliberately not active) passes.
- `swiftformat --lint` clean on the changed file.
Add provider-neutral explicit Decision evaluation through the existing runtime, declared provider capabilities, and a default-off Labs consent foundation. Keep explicit evaluation independent of Labs and retire the unreleased TypeSafe-specific tool. No automatic consumer or public selection/local-availability inspection API is added.
Verified the registered core tool with real ONNX CPU inference, host-bound rejection before dispatch, and agent disablement. Preserve the contributor implementation and the reviewed Labs UI/config behavior.
Related: #155115, #155314, #155317
Co-authored-by: Jacqueline Henriksen <jjjhenriksen@gmail.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
Keep Android live and completed tools in one compact disclosure while preserving command output, live diffs, failure status, and completed-work grouping. Carry run ownership through optimistic prompts and acknowledgement rekeys, and synchronize the voice-note fixture with its actual history owner.
Closes#155466
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Reapply the reviewed source-only gallery delta onto the landed camera change. Preserve both the camera source-specific decoding policy and the compact gallery layout argument. Keep bounded four-image navigation, original assistant ordering, native regression coverage and existing viewer/auth owners. Generated locale output remains owned by the refresh workflow.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
* fix(android): isolate camera captures and preview staged photos
Serialize camera captures at their process-wide owner, revalidate access
after asynchronous work, and release request-owned CameraX resources.
Preview admitted composer images through the bounded local-image path
without relaxing incoming inline limits or replacing the image viewer.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* test(android): cover camera cancellation and recovery
Exercise the public camera handlers across contention, lifecycle stop, cancellation and subsequent capture admission. Assert request-owned CameraX bindings and temporary files are released. Production behavior is unchanged.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
* fix(android): size forked Robolectric test workers explicitly
Give Android application test workers a bounded 1 GiB heap rather than inheriting Gradle’s implicit 512 MiB default. The Gradle daemon heap is separate. Full-suite heap analysis reproduced the playout allocation failure and traced dominant retained memory to framework SDK resources and instrumentation. Preserve test order, assertions, PCM fixture, SDKs and application runtime limits.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
---------
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* feat(browser): unify local Chrome setup across desktop and terminal
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* feat(browser): unify local Chrome setup across desktop and terminal
OpenClaw-Publication: d19e865e-b5a0-4c70-8876-c1662f6e7ef2
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* chore(linux): format Chrome setup fixture
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* feat(browser): keep desktop Chrome setup local and preserve pairing
Delegate Windows registration to the shared native management owner, preserve
released native bridge compatibility and saved launcher profiles, and integrate
serialized desktop setup through isolated local runtimes.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): repair native setup CI contracts
Keep Windows installer dependencies acyclic, validate Unicode within the
package library target, and remove unused private exports. Require all
eight packaged native-host proof cases and update lazy CLI inventory.
Apply native Swift formatter diagnostics without changing behavior.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(cli): account for plugin-owned browser extension catalog
Keep the core-only registration invariant aligned with the Browser plugin
owner already exercised by its lazy registration tests.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(macos): retain released Chrome bridge request expectation
Align the native bridge test with the shipped contract1 request retained
by the canonical setup owner, and reject extra legacy payload fields.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(tui): give command handler harness a unique export
Rename the shared TUI test helper and both consumers to avoid the
Gateway placement harness export collision. No alias or guard waiver.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* chore(sdk): allow canonical browser config path resolver
Apply the approved single public-export and callable allowance for
resolveConfigPath. Preserve canonical pre-config path ownership and
all other SDK surface checks.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): preserve desktop setup selection and supported actions
Keep native automatic setup selector-free and resolve saved local browser
selection through the canonical setup owner before installation. Respect
Mac action advertisements and the released legacy install projection in
the Apps card, and document the public config-path resolver contract.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(auth): retry model selection after concurrent credential refresh
Adopt upstream PR #152426, commit 32298b10f6, without changing its five source files.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test: preserve native setup selection and await dashboard document
Match the selector-free native CLI arguments exactly and preserve a saved work-profile result. Wait through the existing document-readiness owner only at the quota test browser-proof boundary, after auth assertions.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): avoid preloading already imported modules
Remove exact direct static JavaScript imports from lazy preload tables using the emitted build graph. Preserve HTML, lazy-only JavaScript, CSS, and locale hints. Source-exact CI merge reproduction drops startup gzip from 363283 to 362968 bytes without changing budgets. Add a real emitted-bundle regression.
Apply rustfmt layout to the native Chrome selector-free expected arguments.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: preserve Chrome profiles and attachment follow-up branch binding
Let the TUI canonical setup controller retain its saved browser profile and project only a bounded returned name. Align both native first-run fixture expectations with selector-free setup.
Join pending chat history before the composer task handoff can expose an admitted attachment to restored-outbox delivery. Preserve idempotency, attachment custody, restored delivery semantics, and all existing assertions and timeouts. Add a deterministic regression reproduced on the exact failed CI merge and its main parent.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(state): adopt canonical worker-custody fixture repair
Adopt src/plugin-state/plugin-state-worker.test.ts byte-for-byte from upstream bfec65a2a0 (#152456).
The former fixture held its late competing owner until after awaiting off-thread acquisition. Preserve that overlap, assert continued host authority checks and noncompletion, release custody, then assert the original result and persisted state. No production locking, guard, deadline or outcome assertion is relaxed.
Both prior failures reproduced on the exact CI main parent with independently installed frozen dependencies and Node 24.19.0. All 12 repaired file tests, selected state-logging types, scoped typed lint and fresh P0-P2 review passed.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): retain saved Windows setup profiles
Recover configured extension profiles through bounded serial read-only C# inspection. Select only independently validated current matching descriptors, confirm the selected generation before effects, and leave the single mutation under the existing C# owner. Preserve POSIX behavior, existing manual relay verification and explicit same-profile repair.
Missing descriptors, runtime/origin drift and unknown or changing observations fail closed without automatic mutation. Keep raw management facts private and populate the existing browserProfile field only from validated binding metadata. No ABI, schema, SDK, configuration flag or registry/activation owner change.
29 actual CLI/controller/Windows-adapter boundary cases plus sibling coverage: 94 tests pass. Canonical changed checks, full production build and fresh independent P0-P2 review passed. Actual C# native proof remains separately coordinated.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): preserve saved profiles after POSIX bundle relocation
Separate validated native registration ownership from supported origin-migration readiness. Recover the profile only after full private manifest and exact launcher validation; preserve the existing one-slot migration rule and all unsupported-origin, ACL and foreign-host refusals. Fail closed before selector-free installation when the saved selection cannot be proved.
Extract the unchanged shared origin helpers into a cohesive sibling to satisfy the existing line-cap guard without waivers. Windows admission, ABI and selector behavior remain unchanged.
Actual Linux/Darwin CLI-to-filesystem relocation regressions: 18 failures on original production, all 22 cases repaired. Preserve the private relay key and inode, config, Chrome preferences, work relay19444 and explicit-profile intent. 137 focused tests, eight real POSIX native-host E2E cases, canonical changed checks, full production build and fresh P0-P2 review passed.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): retain input handoff through the shared outbox owner
Remove the superseded pending-history no-yield workaround after main introduced foreground submission custody in the shared outbox owner. Restore chat-submit-guard.ts exactly to pinned main cc7 rather than retaining competing timing policies. Keep passive drains fenced while the input task yields.
Preserve the retained history regression with explicit MessageChannel admission, no passive send before resume, and the same terminal leaf, idempotency key, attachment bytes and exactly-once assertions after completion. Original composed source fails all five focused cases; the repair passes 67 handoff/attachment cases and 20 real Chromium cases in the canonical secretless network-none runner. Canonical checks, UI build/performance and fresh P0-P2 review pass. No assertion, timeout, origin or proxy-policy weakening.
Browser POSIX/Windows repairs remain byte-identical to accepted255f. The failed e40e CI receipts remain preserved; fresh exact-head CI and parent handoff are still required.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(tasks): preserve reads across native event finalization
Hand joined event publication to its exact native successor after the native
flow and observer publication frame completes. Keep worker settlement and
cleanup, reversible claim transfer, current-authority and ABA checks, and
post-commit delivery in their existing owners without replaying writes.
Cover pre-result and readback finalization, native and reentrant successor
chains, rollback, failed publication, delivery, and terminal activity cleanup.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(ui): retain rail baseline geometry on readiness failure
Keep the exact existing readiness predicate, fixtures, case inventory, assertion and timeout. When the predicate is false, retain synthetic marker identity and numeric geometry so hosted CI can distinguish scroll, visibility and viewport failures.
This is diagnostic evidence, not a repair or waiver of the unresolved rail failure. Local rootless browser infrastructure is unavailable; the existing hosted CI lane will verify the reviewed task-publication repair and collect meaningful rail evidence. Canonical changed checks and P0-P2 diagnostic review pass.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* docs(linux): describe saved-profile Chrome setup selection
Match the selector-free adapter argument vector and its regression test. Address the fresh P3 review finding without changing runtime behavior. Markdown syntax and diff checks pass; the generic formatter excludes this subtree.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(transcripts): join configured startup before cleanup faults
Observe and await the real startTranscripts promise through a narrow call-through spy while retaining the configured service entry point and real SQLite/provider work. Bind the await to the existing test lifetime instead of charging startup to the subsequent short active-map poll.
Gate provider return after persisted utterance to prove readiness does not settle early; retain both missing/unreadable row injections and all cleanup, private-source, lifecycle-token and summary assertions. Cover real startup rejection explicitly. No production change, timeout increase, retries or broad module/storage mocks.
The deterministic ordering boundary fails with the old fire-and-forget readiness and passes with the real promise join. Final 39 tests across 3 files, canonical changed checks and full-owner P0-P2 review pass. This does not recover whether the historical CI startup was late or rejected.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): preserve automatic desktop status inspection
Restore read-only Device-page inspection for current and released Mac bridges while keeping installation and verification explicit. Preserve the native filesystem prerequisite proof, split installer repair tests within the existing line cap, and remove the superseded constant export.
* fix(browser): preserve registered setup configuration
Require canonical setup to match an owned launcher's effective state and
config selection before installation or relay access. Preserve equivalent
implicit/explicit default selections and the saved launch context. Recheck
automatic profile selection before effects and the current manifest before
publication through the existing registration owner. Keep manual install
and relocation repair contracts unchanged.
Cover mismatched configs, legacy selectors, equivalent defaults, selection
drift, and actual bootstrap after refused setup. Restore the missing Command
import in the existing Unix-only companion CLI test.
Focused tests, types, lint, fresh review, clean package build and sealed Mac
ARM64 runtime proof pass. The separate historical clock-jump CI failure has
bounded replay evidence and remains documented without a speculative fix.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* fix(browser): keep setup registration types acyclic
Move the private registration status contract beside its context policy and
point both consumers at that owner. Remove the publication-module back-edge
without keeping an unused compatibility export.
The full architecture gate, extension production/test types, typed lint and
fresh independent review pass. Node's transformed JavaScript is byte-identical
for all three affected modules, so the existing runtime proof remains valid.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* test(linux): handle Chrome setup in desktop sharing fixture
Recognize the exact automatic Chrome setup invocation and require its native
no-respawn flag. Keep unknown-command rejection, selected-auth validation,
process-group ownership and joined teardown assertions unchanged.
The original fixture reproduces the CI rejection against the real Linux app.
The repaired fixture passes all nine checks against that same binary, with
five Chrome setup calls and five node starts and joined stops. Fresh review
is clean; production app behavior is unchanged.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
---------
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Refresh native translations from verified Native App Locale Refresh run 35713695170 and regenerate Android and Apple resources against current source. Regenerate Control UI translation memory and fallback metadata for the new Code Mode hints.
Strict native and Control UI checks pass with zero Control UI fallbacks. Keep source and release parity gates unchanged.
* fix(ios): make assistant file attachments downloadable
Decode managed document envelopes, reuse scoped artifact downloads, and hand files to the native system exporter with owned temporary copies.
Co-authored-by: Takhoffman <781889+Takhoffman@users.noreply.github.com>
* test(ios): prove managed file downloads through native sharing
Register baseline-compatible decode and real-app loopback Gateway tests in the existing iOS lifecycle lane. Retain exact-baseline behavioral failures, candidate assertions, simulator screenshots, xcresults, and full logs without changing production renderers or transport owners.
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
* test(ios): fix attachment proof CI contracts
Keep fixture imports before executable declarations and require the registered attachment proof plus all native evidence paths in the workflow contract test. Both CI failures reproduced locally and now pass without weakening existing assertions.
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
* test(ios): keep document UI proof in full validation
Honor measured native test budgets: keep the 95-second pairing/share UI flow in the existing full-manual tests phase, while adding decoder, loader, and typography regressions to the existing mandatory PR smoke invocation. Preserve all voice/lifecycle/watch checks and retained evidence; contract tests verify both tiers.
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
* test(ios): align executed smoke suite contract
Require all seven executed smoke selectors: preserve the original voice cleanup suites and add the approved decoder, document loader, and typography regressions. Keep the single invocation and normal Debug simulator signing assertions.
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
---------
Co-authored-by: Takhoffman <781889+Takhoffman@users.noreply.github.com>
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
Queued shared GitHub publication retains its original requester and access grant across deferral and restart. Accepted results remain recoverable after access ends.
* fix: recognize verified team admins as channel owners
Resolve channel owner authority from SQLite profile identity links and current login grants, with immediate revocation across deferred work. Keep Gateway and bundled plugins on one native SDK graph and replace the related process-global authority registries with instance-owned capabilities.
* fix: preserve channel owner authority through deferred work
Authorize Discord commands before ACP preparation and retain the original live owner through backend effects and updater handoffs. Normalize direct notice recipients through channel contracts. Complete native test-loader and instance-runtime fixture coverage, including final-effect and revocation regressions.
* fix(plugins): retain host SDK access in captured workers
Link captured plugins to the selected host package for worker isolates, preserving native SDK identity through retained generations and recovery. Align CI fixtures with instance-owned runtimes and join owned asynchronous work in teardown and Telegram buffering tests.
Validation: native worker regression fails before the fix and passes across native/legacy and source/dist hosts; 325 core tests, the full 3121-test Slack suite, targeted channel tests, protocol generation, Android lint, changed checks, and independent review pass.
* fix(runtime): keep snapshot cleanup inside owned directories
Treat captured SDK host-package links as removable leaves, preserving ownership records until snapshot data is gone. Preserve sanitized readiness subprocess failures and exercise Doctor through its complete isolated runtime on clean installations.
* fix(plugins): keep lazy runtime ownership metadata local
Preserve deferred Gateway facets with instance-owned proxy metadata and retain redacted readiness failure diagnostics on the current subprocess result owner.
* fix(auth): retain live owner authority through command effects
Carry the admitted administrator assertion through command dispatch, ACP controls and metadata commits, config and allowlist writes, plugin consent and installation, MCP mutation, and restart preparation. Preserve accepted-operation settlement and condition restart acknowledgement cleanup on its owned revision. Prove allowed administrators, forbidden senders, revocation and reassignment through real handler and persistence boundaries.
* refactor(restart): require owned revisions for sentinel cleanup
Remove the unused unconditional clear facade and storage branch. Keep revision-floor migration, durable failure reporting, and updater consumption proof on the canonical conditional-clear operation.
* test(auth): align owner regressions with fixture lint contracts
* refactor(auth): simplify channel owner and runtime authority
Resolve linked channel administration from the current Team role policy, retaining identity-grant fallback only for roleless installations. Consolidate Gateway generation state into its lifecycle owner, simplify Discord native routing and remove redundant loader and ingress state. Preserve current-authority checks before writes and required cleanup after accepted operations.
* test(auth): compare public generation state values
* refactor(auth): keep authority fixtures and handoff types with their owners
Extract coherent fixture builders and internal updater types to keep large files from growing. Correct the task-identifier test import to its codec owner and remove the unused internal route-policy export. Preserve all runtime behavior, assertions, deadlines and revision-owned sentinel cleanup.
* fix(channels): preserve native conversation scope in ingress authority
* fix(imessage): bind ingress after reply ID mapping
* fix(test): preserve scoped filesystem and channel admission contracts
* test(fleet): share stopped container state fixture
* test(fleet): type stop mock against the container contract
* fix(auth): retain current owner authority through deferred effects
* refactor(auth): keep authority fixtures and helpers with their owners
* fix(ci): remove duplicate database worker test entry
Retain the existing worker.runtime test entry so compact CI planning includes every storage-state test once. The duplicate introduced in d2c8c34af2 made preflight reject all split timing generations for this owner.
Reproduced the exact preflight error before the repair. Hybrid, GitHub, and Blacksmith planning now preserve all 660 unique storage-state files. The 217 planner/config tests, selected changed-file checks, formatting, and diff checks pass.
* refactor(auth): prepare profile authority in SQLite workers
Move channel identity and affected profile writes onto the existing worker owners, with current authority at commit and explicit rollback recovery. Bind native Telegram commands to verified ingress and retain shared-owner administration.
* fix(auth): preserve owner checks and released ingress callers
Forward Telegram authority through configured backend preparation and retain released ingress helper provenance through the existing plugin instance owner. Keep identity result types in the leaf contract and repair worker-aware test routing and fixtures without weakening policy assertions.
* fix: correct ingress names and database test ownership
Keep supported SDK ingress adapters while distinguishing internal policy operations. Assign broker-dependent HTTP suites only to the Gateway fork owner, preserve sorted test discovery, reuse chat registration fixtures, and declare the dynamically loaded Telegram test entry.
* test(cli): use prepared runtime for MCP probe exit
Exercise the real CLI entrypoint instead of compiling source-backed SQLite workers inside the command deadline. Keep the 30-second deadline and the exit, JSON, and named diagnostic checks.
* test(codex): check native worker termination at teardown
Observe native Worker thread IDs after fixture cleanup instead of equating
thread exit with asynchronous resource-destroy notification. Keep the
allocation assertion and existing cleanup; do not wait for idle retirement.
The three-case file passes in 48.495s. Omitting only its harness disk-worker
drain fails immediately on a live thread in 30.715s. A Node 24.19 control
observes threadId -1 while the async destroy notification is still pending.
Managed review is clean through P2. The earlier CI worker identity remains
unproven; this is a test-contract repair, not a production leak claim.
* test: settle identity fixtures and route database cleanup
Wait for actual GitHub metadata entry and settle both identity requests on failure. Run the session-store consumer in the existing database fork owner so native retirement can use the host broker.
* test: settle admin fixtures at their owning boundaries
Await canonical asynchronous MCP OAuth reads and the existing Gateway attachment completion. Keep avatar work independently gated and preserve all permission assertions. Move ingress and callback fixture helpers into the existing support owner to keep the health suite within its line-growth limit.
* test(worker): share the compiled SDK graph in crash fixtures
* chore(deps): refresh dependencies with seven-day cutoff
Advance eligible runtime, native, release, and development dependencies published by 2026-09-14T07:00:00Z. Preserve compatibility holds and existing reviewed newer pins. Synchronize release integrity checks and scoped overrides; remove the superseded mailparser override.
Preserve Clack cancellation inference with its precise sentinel type and isolate the Vertex proxy fixture from ambient credentials. Timestamp and checksum audits, targeted consumers, native builds/tests, and independent review validate the refresh; required hosted CI remains the landing gate.
* fix(deps): preserve Clack cancellation types in exported prompts
Give styled configure prompts the exact upstream return types so plugin SDK declaration emission can name the new cancellation sentinel. Runtime behavior and generic option values are unchanged.
* fix(deps): preserve release tooling and Android test contracts
Regenerate Ruby lock metadata with pinned Bundler 2.6.9, grant Robolectric 4.17 its documented module access only in Android test JVMs, and keep the precise cancellation type without growing an over-cap source file.
Both previously failing Ruby lock guards, the line-cap and core type checks, all three configured Android test-task JVM arguments, and the actual Robolectric interceptor before/after probe pass. Independent review found no actionable P0/P1 issues.
* fix(deps): close Rustls advisory and align mock session clocks
Rustls 0.23.45 has now completed the seven-day cooldown; update only the shared crate pin and lock to the existing security-fixed desktop version.
Advance accepted mock Gateway writes on the synthetic fixture timeline and correlate permission tests with the actual mutation and refresh. This repairs a reproduced CI fixture race without changing production behavior or weakening assertions.
Validation: 36 Rust gateway-client tests including four TLS handshakes, 50 fixture tests, nine browser cases, scoped changed checks, and independent P0/P1 review passed.
* test(ui): keep external session updates on the committed timeline
* test: stabilize approval and desktop CI fixtures
* build(workboard): refresh assets after dependency rebase
Keep Android Gateway discovery tied to live registrations by serializing service-info callbacks and atomically publishing local and wide-area changes. Preserve legacy resolution ownership, TLS pins, pairing and permission rules.
Validated with callback ordering/replacement regressions, discovery siblings, native lint and exact-head CI. No physical-device, live-mDNS or simultaneous live wide-area overlap acceptance is claimed.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Settle the released current media player's loading, playing and position state together so a video becomes retryable after playback handoff. Ignore stale releases and retain voice-blocking and transport authorization.
Validated with real-player Robolectric handoff/retry/disposal regressions, Gateway media siblings, native lint and exact-head CI. No physical-device or live-Gateway playback acceptance is claimed.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Retire voice-note media acquisition from the recorder lifecycle owner so backgrounding or leaving Chat no longer leaves Gateway switching blocked. Preserve independent pending imports, sends and attachment authorization.
Validated with recorder, composer and sidebar regressions, native lint and exact-head CI. Native before/after proof is documented in the PR; no physical-device recording or live pairing acceptance is claimed.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Fix Android Stop for explicitly owned sessions and keep every abort in a captured batch bound to its original Gateway, agent and session. Surface rejected or uncertain aborts only in that conversation and preserve coroutine cancellation.
Validated with abort/stream regressions, native inventory checks, native lint and exact-head CI. Native before/after proof is documented in the PR; no physical-device or live-Gateway acceptance is claimed.
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Add native computer use and Browser/Terminal launchers for prepared macOS and Windows cloud workers through Crabbox's existing authenticated transport, placement, and teardown.
Launch the separately signed Mac Cloud Worker app through LaunchServices and let it own Node/CUA, desktop permissions, and the renewable idle assertion. Bind Windows enrollment and replay to the worker's interactive account and session. Preserve uncertain launch evidence for reprovisioning, and require confirmed lease teardown before downgrading readers of newer desktop metadata.
Preserve chat end-follow during coalesced composer and goal resizing by carrying the actual scroll correction through the existing resize event and offset owner. Retain the canonical rail, progress, and approval lifecycle implementations.
Validation: exact-head CI passed 165 jobs with seven skips; 142 focused approval cases passed locally. Historical native platform proof and the remaining current-driver, lock/account-loss, enrollment, and downgrade qualification limits are recorded in #152060 under the requested best-effort testing scope.
Refs #152060.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* feat: add contextual plugin help to Ask OpenClaw
Punchcard-Session: crisp-summit-lantern-qk
* fix(ui): redact URL credentials from plugin Ask drafts
Reuse the canonical URL policy in the bounded help-value scan, including
serialized map keys. Keep the editable config value intact and prove
rejected Save → Ask → Send on desktop and phone.
Punchcard-Session: crisp-summit-lantern-qk
* test: reuse the complete Custodian context fixture
Punchcard-Session: crisp-summit-lantern-qk
* refactor(ui): narrow plugin help selection input
Accept only the loaded selection facts consumed by the help controller, removing its type dependency on the complete page renderer model.
Punchcard-Session: crisp-summit-lantern-qk
* perf(ui): keep plugin help preparation off startup
Separate synchronous dock state and session ownership from lazy question preparation and session persistence helpers. Register plugin-only English copy with its lazy consumers while preserving source catalog order.
Punchcard-Session: crisp-summit-lantern-qk
* style: normalize contextual help rebase spacing
Punchcard-Session: crisp-summit-lantern-qk
* perf(ui): keep attachment media preparation off startup
Punchcard-Session: crisp-summit-lantern-qk
* test(qwen): fix the clock for default timeout assertions
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): wait for side-chat opening focus
Punchcard-Session: crisp-summit-lantern-qk
* chore(pr): deduplicate wrapper dependency inventory
Punchcard-Session: crisp-summit-lantern-qk
* test(qwen): drop superseded default-clock workaround
* feat: group bundled plugin settings by authored manifest metadata
Punchcard-Session: crisp-summit-lantern-qk
* fix(plugins): simplify settings and catalog interactions
Remove redundant install review UI, organize settings using authored groups,
show truthful defaults, and repair catalog layout and loading states.
Punchcard-Session: crisp-summit-lantern-qk
* test(config): move tier schema checks to their owner suite
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): align settings and draft recovery contracts
Wait for the settings search control and verify editable drafts cannot send before inference recovery.
Punchcard-Session: crisp-summit-lantern-qk
* fix(ui): honor modal cursor and sample header geometry atomically
Use the shared cursor token for the document Close action. Read the moving header title and tabs in one browser evaluation so the strict alignment assertion compares the same animation frame.
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): observe settings assets without route interception
Punchcard-Session: crisp-summit-lantern-qk
* test(plugins): isolate bundled-only catalog curation fixtures
Punchcard-Session: crisp-summit-lantern-qk
* docs(plugins): explain explicit stored-key reveal
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): await prior plugin settings inspections
Punchcard-Session: crisp-summit-lantern-qk
* chore(config): refresh the merged documentation baseline
Punchcard-Session: crisp-summit-lantern-qk
* fix(ui): expose roster pagination refresh state
Punchcard-Session: crisp-summit-lantern-qk
* fix(gateway): retain live authority through plugin lifecycle effects
Keep active request authority available to device, profile, origin, and
shared-auth revocation after ordinary transport disconnects. Revalidate
plugin lifecycle authority before tentative acceptance writes and runtime
application, while preserving lease-owned compensation.
Journal marker undo state before removal so a post-removal revocation
cannot leave a restored plugin index without its original retention marker.
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): honor retained session windows in mutation fixture
Punchcard-Session: crisp-summit-lantern-qk
* test(plugins): exercise archive limits with real ZIP entries
Punchcard-Session: coral-lantern-meadow-m8
* test(plugins): declare complete installed catalog fixtures
Punchcard-Session: coral-lantern-meadow-m8
* fix(gateway): retain required new-agent welcome on rejoin
Punchcard-Session: coral-lantern-meadow-m8
* fix(ui): preserve composer contrast across theme integration
Punchcard-Session: coral-lantern-meadow-m8
* fix(test): exclude checkout scratch from compiler inputs
Concurrent hook fixtures can disappear after namespace enumeration. Keep root scratch outside compiler cache preparation while retaining nested workspace and installed metadata invalidation.
Punchcard-Session: coral-lantern-meadow-m8
* fix(test): await native turn admission before interrupting
Punchcard-Session: coral-lantern-meadow-m8
* test(gateway): use client registry in approval fixture
Punchcard-Session: coral-lantern-meadow-m8
* ci: validate Apple builds and tests with Xcode 27
* fix(ci): include Swift selection in trusted platform checkouts
* fix(ci): retain Periphery index layout and report Swift crashes
* fix(test): adapt native validation to Xcode 27 runtime and indexing
* test: run Quick Chat presentation flows with Swift Testing
* docs: clarify Xcode analyzer compatibility requirements
* test: diagnose early AppKit test process exit
* test: give rendered Mac tests an AppKit event loop
* test: await AppKit event processing before rendered tests
* test: wait for the rendered Quick Chat model picker
* fix(ci): isolate Apple test logs and await fixture readiness
* test: retain all default-profile capture evidence
* fix(ci): repair Apple qualification diagnostics and fixtures
* test: surface Quick Chat sends rejected before transport entry
* test: capture suspended Quick Chat tasks during CI stalls
* test: read attributed accessibility titles without abandoning Swift tasks
* test: normalize accessibility titles across native fixtures
* test: find named-profile model controls by accessible name
* fix: retain lost Windows PID authority through shutdown retries
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Let plugin themes declare bounded, self-contained SVG assets for avatar hats
and composer visitors. Capture artwork with each plugin generation, expose
content-hashed authenticated resource URLs, and rasterize images lazily in
the Control UI. Personal imports remain limited to built-in artwork IDs.
Package declared assets through the shared filesystem boundary while keeping
manifest declarations usable by native build and updater tooling. Preserve
existing pointer interactions, loaded-photo hats, palette notifications,
and transcript invalidation. Document validation and reload behavior.
Validation: focused protocol, manifest, Gateway, UI, packaging, native updater,
and extracted PR tooling tests; core/UI/scripts and affected test typechecks;
protocol generators, style lint, dead-code checks, assertion and line-cap
ratchets, formatting, docs links, and scoped-clean P1 review. Inspected
synthetic before/after captures are attached to the PR. Startup budget files
remain unchanged at 370300 B baseline and 370876 B enforcement.
* feat(ui): let themes drop the mascot, set status words, add critters and avatar hats
Portable theme definitions (built-in, plugin, personal) gain four optional
presentation fields. `mascot: "none"` swaps the lobster mark, favicon, login
gate, system avatar, About hero, and the working-row claw for a neutral prompt
mark drawn in the theme's primary color, and keeps the resident lobster and
lobster strangers off the composer ledge while ordinary visitors keep coming
under the unchanged Lobster visits toggle. `workingPhrases` replaces the
crustacean long-wait words with theme-authored text (up to 24, empty = silent).
`critters` adds catalog visitors (a penguin in a red fedora, and the fedora on
its own) to the ledge traffic at 2 % per critter per load without changing the
regulars' odds. `avatarHat` puts a fedora on an agent avatar about one page
load in six, seeded per agent and load.
The Gateway validates the fields in normalizeThemeDefinition and the TypeBox
schema, projects them onto plugin and personal descriptors, and the theme tool
imports them unchanged. The Control UI resolves branding through the theme
context, stamps data-theme-mascot and data-theme-avatar-hat on the root, and
rebuilds the favicon from computed colors when the mascot changes.
Startup JS grows by 2,467 B gzip (0.67 %); the baseline moves with it.
* fix(ui): complete portable theme branding and CI contracts
* fix(ui): satisfy core lint and the Linux startup budget
* fix(ui): give the startup JS baseline its allowance headroom
* feat(search): configure providers and verify search in Settings
* refactor(search): keep settings projections lint clean
* fix(search): bind provider tests to applied settings
* fix(search): preserve protocol order and complete CI coverage
* perf(search): defer model URL validation until needed
* fix(search): recheck authority before provider requests
* fix(search): include authority helper in wrapper closure
* test(qa): retain redacted cron run failure diagnostics
Keep the existing timeout and success predicate while preserving the complete redacted cron response in assertion output and retained proof. The original CI timeout remains unproven after bounded replay; this change improves diagnosis without claiming a causal flake repair.
* fix(search): project status from published auth state
Keep Search settings credential availability and native routing on lifecycle-published auth snapshots. Missing publication remains unavailable instead of reopening persisted auth on the Gateway request thread. Regression cases fail on the previous cold-state fallback; 71 focused and sibling cases, typechecks, lint, and independent review pass.
* fix: refresh stale Gateway stop policies before maintenance
Main recognized historical systemd timeouts, but maintenance could stop the
resident before repair, and Doctor and already-current or no-restart updates
could preserve stale computed policy. A published 2026.9.5 resident also retains
its startup shutdown budget after the unit changes.
Refresh owned policy through the existing definition-mutation and backup owners,
confirm daemon reload, preserve operator drop-ins, and retain restore/reload/input
retirement ordering. Share maintenance between update and Doctor, and warn when
a non-stopping refresh still has a short effective manager timeout.
Publish process-owned shutdown budgets and lifecycle write-custody facts. Reuse
the suspension owner and existing update deadline: stop when idle, warn and stop
at the deadline for ordinary work or unknown custody, and refuse only current
reported write custody with its exact owner phase. Reread native policy when the
new Gateway accepts shutdown without resetting its elapsed budget or watchdog.
Thanks @ezimerman for the installed-unit and shutdown evidence.
Fixes#153153. Refs #150898, #152879, #153017.
* fix: preserve the resident shutdown budget in Gateway status
The kernel request-context adapter copied host lifecycle control methods but
dropped the recorded shutdown-budget getter. Real Linux package proof observed
a 325-second startup budget while status omitted it, forcing maintenance onto
the legacy unknown-budget path.
Forward the live getter through the existing adapter without changing request
authority or adding another budget owner. Add a real-kernel registered-status
regression for short and adequate budgets; the corrected test fails on the
original adapter and passes with the forwarding line.
Refs #153153.
* test: control the Gateway shutdown clock consistently
Restore the explicit node:perf_hooks performance import for the run-loop regressions that retain their own fake-clock assertions. They must control the same monotonic clock as the production shutdown-budget owner. Keep the deadline assertions, timers, and production behavior unchanged.
* fix: preserve Doctor legacy reads during Gateway preflight
The stale-Gateway probe opened the canonical owner-lease database without
Doctor's existing legacy-catalog admission. With a built install and a busy
Gateway port, that read created WAL/SHM files and rejected a supported repair
before maintenance could stop the Gateway.
Carry the existing read admission through restart inspection to the lease owner.
Keep ordinary restart validation unchanged and preserve canonical artifacts.
Use synthetic port, build, and reachability facts in the regression fixture while
retaining real lease reads and byte-preservation assertions.
Refs #153153.
* refactor: keep Gateway maintenance owners within line limits
The L903 stop-policy repair exceeded the existing line-growth gate after
composition with current restart and service identity handling. Move request
upgrade policy into its existing request owner and service revalidation into
one sibling implementation without changing their behavior.
Preserve original request admission time and Doctor's statically primed
maintenance facade across package replacement. The bounded drain, recorded
custody-only refusal, warning policy, and native backup/reload ordering remain
unchanged. No options, schema changes, suppressions, or baseline growth.
Validation: 398 focused tests, core typecheck, line-growth ratchet, and fresh
Codex P1 review passed. Full changed checks continue on the frozen source.
* test: retain backup custody coverage through the archive walker
The rebase incorporated the maintained archive walker, but the L903 custody
regression still referenced the retired tar-create mock. Use the existing
walker mock bound to the real backup command without changing assertions or
production code.
Validation: 132 backup, migration, cron, coordinator, and suspension tests
passed. Fresh Codex P1 review is clean. Full changed checks continue.
* fix: preserve maintenance lifecycle and wrapper contracts
Doctor fixtures advertised a running native service without the matching
resident identity, effective policy, or lifecycle readiness response. Supply
those facts through the same RPC and native-query boundaries used by the real
maintenance owner, including fresh readiness without a resident budget.
Keep exact suspension assertions current with the additive custody category.
Install the model-acquisition fixture's manager after normal PATH setup so
startup and shutdown observe the same policy under the original deadlines.
Include the custody owner in the canonical PR-wrapper source inventory.
Move the unchanged Doctor inspection assertion and shared fixtures into their
existing policy/support owners to preserve the line-growth ratchet. Do not
change the bounded-deferral, warning, or reported-write-custody refusal policy.
* fix: preserve Stop ownership through shutdown budget refresh
An asynchronous systemd budget read could resume after Stop captured a
foreground updater and re-arm the hard-exit worker. Keep watchdog admission
with the run loop's current successor owner, and represent an absent cleanup
deadline with no process-cleanup budget.
Preserve foreground no-op service ownership and the full native allowance
after verified parking. Keep one fake clock for boundary tests, prepare
fixture operations before held scripts, and join cancelled fixture work
before the next case. Move unchanged budget cases into their support owner.
Retain the ruling that unknown custody cannot block an update and only
reported write custody may refuse maintenance. Preserve all existing test
assertions and limits. The full Linux changed gate, 790 focused Linux tests,
and a fresh P1 review passed; local host limitations are recorded in the PR.
* refactor(doctor): extract update-run admission from doctor-maintenance
* fix: preserve native policy and write custody during maintenance
* fix: keep shutdown integration within source and type gates
* fix(test): own survivor model endpoint before baseline setup
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
Stop registering Cmd/Ctrl+Shift+O system-wide so other foreground apps receive their own New Session shortcut. Preserve Quick Chat global activation and its reservation against hijacking the foreground chord.
Scope saved-Gateway keychain lookup failures to the app launch environment. Suggest reopening from Finder, retain configuration guidance for a persistently missing keychain, and document credential-free macOS fixtures.
* fix(ui): enable desktop access from Systems
Detect compatible host desktops before opt-in, preserve existing configuration, and enable access through the shared configuration and restart owner. Normalize Mac platform labels and explain macOS Remote Management access failures.
* test(ui): initialize Systems fixtures before navigation