Commit graph

6128 commits

Author SHA1 Message Date
openclaw-mantis[bot]
6f90a9a332
chore(i18n): refresh native locales (#156534)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-23 13:44:38 +00:00
Peter Steinberger
31dd34ff19
fix(macos): report named-profile startup failures without a listener (#156441)
A named profile's readiness failure required port-ownership proof, which always fails without a listener PID, so the real startup error was replaced by a phantom port conflict. Check ownership only when something is listening; ready results keep strict ownership proof.

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-23 06:41:18 -07:00
Shakker
d17bc2129b
fix: respect role model restrictions in model pickers (#154839)
Project permitted model catalogs and defaults through the shared role-policy owner. Retire stale choices on policy changes while preserving session history and saved model preferences.
2026-09-23 14:04:13 +01:00
RoboClaw
bdd47f252a
feat: edit personal instructions on multi-user gateways (#155256)
Enable authenticated users to edit their personal instructions from Profile or chat on multi-user Gateways. Keep single-user Gateways on the workspace-root USER.md.

Preserve requester-bound authority, safe local writes, conflict checks, reconnect drafts, normal Profile spacing, and the startup performance budget.

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
2026-09-23 05:55:12 -07:00
Peter Steinberger
9ed5a04a65
ci: warn on size and performance limits in GitHub Actions
Source and performance budgets shared fatal exits with correctness checks,
so ordinary growth could block otherwise valid changes. Centralize limit
severity and GitHub annotations/summaries, keep local checks strict, and
carry warnings across native lint, container, and BuildKit boundaries.

Keep semantic lint, types, API inventories, source ownership, invalid
measurements, process failures, and runner admission guards blocking.

Validation: P2 review clean; three Linux owner-configuration replays and
20 standalone policy runs passed; typechecks, targeted type-aware lint,
Knip export scans, workflow checks, formatting, and diff checks passed.
The changed gate found a test environment typing error, corrected and
verified by the root-test typecheck. One unrelated preparation process
cleanup failure did not reproduce in its diagnostic replay; no fix claimed.
2026-09-23 02:35:32 -07:00
Peter Steinberger
2559458e2b
test: consolidate serialized model rollback coverage (#156169)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-22 21:57:58 -07:00
Peter Steinberger
ce783beb23
fix(android): shorten native CI test tails without dropping coverage (#156084)
* ci(android): retain Gradle caches and parallelize phone test classes

* test(android): advance reconnect retry timers with a virtual clock

* ci(android): balance app lint across existing native jobs

* ci(android): run all four native rows without a second wave

* ci(android): preserve hosted fallback resource limits
2026-09-22 21:38:11 -07:00
Peter Steinberger
35fd3b1617
test(macos): keep the rendered Quick Chat suite stable on hosted runners (#156134)
## Summary

`QuickChatCatalogPresentationTests` › "rendered Quick Chat preserves catalog disclosure and shortcut behavior in order" fails intermittently in the hosted `macos-swift (tests)` job (Full Release Validation runs 35761278329 and 35802234377 for 2026.9.6; passes locally). The uploaded `macos-native-test-logs` artifacts show two failure shapes, both environmental:

1. `QuickChatPresentationTests.swift:304` `Expectation failed: condition()` with the diagnostic `Quick Chat presented: visible=true, active=true, key=true, editorReady=true`. The only wait that can fail with that state is `waitUntil { !application.isActive }` after `application.deactivate()`: the hosted runner never hands activation to another app, so the *precondition* for "presents without foreground ownership" is unattainable there, while the behavior itself (panel visible, editor focused, reopen, disable) is proven.
2. On frozen release targets (`HISTORICAL_TARGET=true`) the rendered suite still runs in the parallel default lane. Parallel suites open key windows, Quick Chat dismisses on focus loss by design, and the test then reports `windowVisible=false windowKey=false` plus a reset `model.speed` (the 5-issue attempt). Current targets already isolate the suite into the `default-rendered` lane; frozen targets did not.

## Changes

- `apps/macos/Tests/OpenClawIPCTests/QuickChatPresentationTests.swift`: the activation hand-off before firing the shortcut is a bounded, non-asserting `poll` that prints whether the host yielded activation; every behavioral assertion after it is unchanged. `waitUntil` now delegates to `poll`.
- `.github/workflows/ci.yml`: run the isolated `default-rendered` lane for frozen targets too whenever the suite exists in the checked-out tree; older tags without the suite keep the single default lane.

## Proof

- Local `swift test --disable-sandbox --filter QuickChatCatalogPresentationTests` (apps/macos): 5/5 passes.
- One extra run with another application in the foreground (app deliberately not active) passes.
- `swiftformat --lint` clean on the changed file.
2026-09-23 04:04:39 +00:00
openclaw-mantis[bot]
5a911db502
chore(i18n): refresh native locales (#156006)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-22 23:29:41 +00:00
Jacqueline Henriksen
f9e969c081
feat(decisions): add explicit evaluation and Labs opt-in foundation (#155134)
Add provider-neutral explicit Decision evaluation through the existing runtime, declared provider capabilities, and a default-off Labs consent foundation. Keep explicit evaluation independent of Labs and retire the unreleased TypeSafe-specific tool. No automatic consumer or public selection/local-availability inspection API is added.

Verified the registered core tool with real ONNX CPU inference, host-bound rejection before dispatch, and agent disablement. Preserve the contributor implementation and the reviewed Labs UI/config behavior.

Related: #155115, #155314, #155317

Co-authored-by: Jacqueline Henriksen <jjjhenriksen@gmail.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
2026-09-22 15:55:02 -07:00
openclaw-mantis[bot]
1a266f2b2e
chore(i18n): refresh native locales (#155864)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-22 17:30:13 +00:00
RoboClaw
8363348fa1
improve(android): keep tool activity in one compact disclosure (#155765)
Keep Android live and completed tools in one compact disclosure while preserving command output, live diffs, failure status, and completed-work grouping. Carry run ownership through optimistic prompts and acknowledgement rekeys, and synchronize the voice-note fixture with its actual history owner.

Closes #155466

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-22 09:49:14 -07:00
openclaw-mantis[bot]
9c1b487ade
chore(i18n): refresh native locales (#155571)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-22 15:36:13 +00:00
RoboClaw
fbc540f147
improve(android): keep chat photos outside text bubbles (#155338)
Reapply the reviewed source-only gallery delta onto the landed camera change. Preserve both the camera source-specific decoding policy and the compact gallery layout argument. Keep bounded four-image navigation, original assistant ordering, native regression coverage and existing viewer/auth owners. Generated locale output remains owned by the refresh workflow.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-22 07:47:57 -07:00
RoboClaw
6005e26243
fix(android): isolate camera captures and preview staged photos (#153033)
* fix(android): isolate camera captures and preview staged photos

Serialize camera captures at their process-wide owner, revalidate access
after asynchronous work, and release request-owned CameraX resources.

Preview admitted composer images through the bounded local-image path
without relaxing incoming inline limits or replacing the image viewer.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>

* test(android): cover camera cancellation and recovery

Exercise the public camera handlers across contention, lifecycle stop, cancellation and subsequent capture admission. Assert request-owned CameraX bindings and temporary files are released. Production behavior is unchanged.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>

* fix(android): size forked Robolectric test workers explicitly

Give Android application test workers a bounded 1 GiB heap rather than inheriting Gradle’s implicit 512 MiB default. The Gradle daemon heap is separate. Full-suite heap analysis reproduced the playout allocation failure and traced dominant retained memory to framework SDK resources and instrumentation. Preserve test order, assertions, PCM fixture, SDKs and application runtime limits.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>

---------

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
2026-09-22 06:30:17 -07:00
RoboClaw
bb2d479926
feat(browser): unify local Chrome setup across desktop and terminal (#152057)
* feat(browser): unify local Chrome setup across desktop and terminal

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* feat(browser): unify local Chrome setup across desktop and terminal

OpenClaw-Publication: d19e865e-b5a0-4c70-8876-c1662f6e7ef2

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* chore(linux): format Chrome setup fixture

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* feat(browser): keep desktop Chrome setup local and preserve pairing

Delegate Windows registration to the shared native management owner, preserve
released native bridge compatibility and saved launcher profiles, and integrate
serialized desktop setup through isolated local runtimes.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): repair native setup CI contracts

Keep Windows installer dependencies acyclic, validate Unicode within the
package library target, and remove unused private exports. Require all
eight packaged native-host proof cases and update lazy CLI inventory.
Apply native Swift formatter diagnostics without changing behavior.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(cli): account for plugin-owned browser extension catalog

Keep the core-only registration invariant aligned with the Browser plugin
owner already exercised by its lazy registration tests.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(macos): retain released Chrome bridge request expectation

Align the native bridge test with the shipped contract1 request retained
by the canonical setup owner, and reject extra legacy payload fields.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(tui): give command handler harness a unique export

Rename the shared TUI test helper and both consumers to avoid the
Gateway placement harness export collision. No alias or guard waiver.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* chore(sdk): allow canonical browser config path resolver

Apply the approved single public-export and callable allowance for
resolveConfigPath. Preserve canonical pre-config path ownership and
all other SDK surface checks.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): preserve desktop setup selection and supported actions

Keep native automatic setup selector-free and resolve saved local browser
selection through the canonical setup owner before installation. Respect
Mac action advertisements and the released legacy install projection in
the Apps card, and document the public config-path resolver contract.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(auth): retry model selection after concurrent credential refresh

Adopt upstream PR #152426, commit 32298b10f6, without changing its five source files.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test: preserve native setup selection and await dashboard document

Match the selector-free native CLI arguments exactly and preserve a saved work-profile result. Wait through the existing document-readiness owner only at the quota test browser-proof boundary, after auth assertions.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): avoid preloading already imported modules

Remove exact direct static JavaScript imports from lazy preload tables using the emitted build graph. Preserve HTML, lazy-only JavaScript, CSS, and locale hints. Source-exact CI merge reproduction drops startup gzip from 363283 to 362968 bytes without changing budgets. Add a real emitted-bundle regression.

Apply rustfmt layout to the native Chrome selector-free expected arguments.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: preserve Chrome profiles and attachment follow-up branch binding

Let the TUI canonical setup controller retain its saved browser profile and project only a bounded returned name. Align both native first-run fixture expectations with selector-free setup.

Join pending chat history before the composer task handoff can expose an admitted attachment to restored-outbox delivery. Preserve idempotency, attachment custody, restored delivery semantics, and all existing assertions and timeouts. Add a deterministic regression reproduced on the exact failed CI merge and its main parent.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(state): adopt canonical worker-custody fixture repair

Adopt src/plugin-state/plugin-state-worker.test.ts byte-for-byte from upstream bfec65a2a0 (#152456).

The former fixture held its late competing owner until after awaiting off-thread acquisition. Preserve that overlap, assert continued host authority checks and noncompletion, release custody, then assert the original result and persisted state. No production locking, guard, deadline or outcome assertion is relaxed.

Both prior failures reproduced on the exact CI main parent with independently installed frozen dependencies and Node 24.19.0. All 12 repaired file tests, selected state-logging types, scoped typed lint and fresh P0-P2 review passed.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): retain saved Windows setup profiles

Recover configured extension profiles through bounded serial read-only C# inspection. Select only independently validated current matching descriptors, confirm the selected generation before effects, and leave the single mutation under the existing C# owner. Preserve POSIX behavior, existing manual relay verification and explicit same-profile repair.

Missing descriptors, runtime/origin drift and unknown or changing observations fail closed without automatic mutation. Keep raw management facts private and populate the existing browserProfile field only from validated binding metadata. No ABI, schema, SDK, configuration flag or registry/activation owner change.

29 actual CLI/controller/Windows-adapter boundary cases plus sibling coverage: 94 tests pass. Canonical changed checks, full production build and fresh independent P0-P2 review passed. Actual C# native proof remains separately coordinated.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): preserve saved profiles after POSIX bundle relocation

Separate validated native registration ownership from supported origin-migration readiness. Recover the profile only after full private manifest and exact launcher validation; preserve the existing one-slot migration rule and all unsupported-origin, ACL and foreign-host refusals. Fail closed before selector-free installation when the saved selection cannot be proved.

Extract the unchanged shared origin helpers into a cohesive sibling to satisfy the existing line-cap guard without waivers. Windows admission, ABI and selector behavior remain unchanged.

Actual Linux/Darwin CLI-to-filesystem relocation regressions: 18 failures on original production, all 22 cases repaired. Preserve the private relay key and inode, config, Chrome preferences, work relay19444 and explicit-profile intent. 137 focused tests, eight real POSIX native-host E2E cases, canonical changed checks, full production build and fresh P0-P2 review passed.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): retain input handoff through the shared outbox owner

Remove the superseded pending-history no-yield workaround after main introduced foreground submission custody in the shared outbox owner. Restore chat-submit-guard.ts exactly to pinned main cc7 rather than retaining competing timing policies. Keep passive drains fenced while the input task yields.

Preserve the retained history regression with explicit MessageChannel admission, no passive send before resume, and the same terminal leaf, idempotency key, attachment bytes and exactly-once assertions after completion. Original composed source fails all five focused cases; the repair passes 67 handoff/attachment cases and 20 real Chromium cases in the canonical secretless network-none runner. Canonical checks, UI build/performance and fresh P0-P2 review pass. No assertion, timeout, origin or proxy-policy weakening.

Browser POSIX/Windows repairs remain byte-identical to accepted255f. The failed e40e CI receipts remain preserved; fresh exact-head CI and parent handoff are still required.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(tasks): preserve reads across native event finalization

Hand joined event publication to its exact native successor after the native
flow and observer publication frame completes. Keep worker settlement and
cleanup, reversible claim transfer, current-authority and ABA checks, and
post-commit delivery in their existing owners without replaying writes.

Cover pre-result and readback finalization, native and reentrant successor
chains, rollback, failed publication, delivery, and terminal activity cleanup.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(ui): retain rail baseline geometry on readiness failure

Keep the exact existing readiness predicate, fixtures, case inventory, assertion and timeout. When the predicate is false, retain synthetic marker identity and numeric geometry so hosted CI can distinguish scroll, visibility and viewport failures.

This is diagnostic evidence, not a repair or waiver of the unresolved rail failure. Local rootless browser infrastructure is unavailable; the existing hosted CI lane will verify the reviewed task-publication repair and collect meaningful rail evidence. Canonical changed checks and P0-P2 diagnostic review pass.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* docs(linux): describe saved-profile Chrome setup selection

Match the selector-free adapter argument vector and its regression test. Address the fresh P3 review finding without changing runtime behavior. Markdown syntax and diff checks pass; the generic formatter excludes this subtree.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(transcripts): join configured startup before cleanup faults

Observe and await the real startTranscripts promise through a narrow call-through spy while retaining the configured service entry point and real SQLite/provider work. Bind the await to the existing test lifetime instead of charging startup to the subsequent short active-map poll.

Gate provider return after persisted utterance to prove readiness does not settle early; retain both missing/unreadable row injections and all cleanup, private-source, lifecycle-token and summary assertions. Cover real startup rejection explicitly. No production change, timeout increase, retries or broad module/storage mocks.

The deterministic ordering boundary fails with the old fire-and-forget readiness and passes with the real promise join. Final 39 tests across 3 files, canonical changed checks and full-owner P0-P2 review pass. This does not recover whether the historical CI startup was late or rejected.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): preserve automatic desktop status inspection

Restore read-only Device-page inspection for current and released Mac bridges while keeping installation and verification explicit. Preserve the native filesystem prerequisite proof, split installer repair tests within the existing line cap, and remove the superseded constant export.

* fix(browser): preserve registered setup configuration

Require canonical setup to match an owned launcher's effective state and
config selection before installation or relay access. Preserve equivalent
implicit/explicit default selections and the saved launch context. Recheck
automatic profile selection before effects and the current manifest before
publication through the existing registration owner. Keep manual install
and relocation repair contracts unchanged.

Cover mismatched configs, legacy selectors, equivalent defaults, selection
drift, and actual bootstrap after refused setup. Restore the missing Command
import in the existing Unix-only companion CLI test.

Focused tests, types, lint, fresh review, clean package build and sealed Mac
ARM64 runtime proof pass. The separate historical clock-jump CI failure has
bounded replay evidence and remains documented without a speculative fix.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* fix(browser): keep setup registration types acyclic

Move the private registration status contract beside its context policy and
point both consumers at that owner. Remove the publication-module back-edge
without keeping an unused compatibility export.

The full architecture gate, extension production/test types, typed lint and
fresh independent review pass. Node's transformed JavaScript is byte-identical
for all three affected modules, so the existing runtime proof remains valid.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* test(linux): handle Chrome setup in desktop sharing fixture

Recognize the exact automatic Chrome setup invocation and require its native
no-respawn flag. Keep unknown-command rejection, selected-auth validation,
process-group ownership and joined teardown assertions unchanged.

The original fixture reproduces the CI rejection against the real Linux app.
The repaired fixture passes all nine checks against that same binary, with
five Chrome setup calls and five node starts and joined stops. Fresh review
is clean; production app behavior is unchanged.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

---------

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-22 06:28:29 -07:00
Peter Steinberger
b03f0366f6
fix(i18n): refresh locales to unblock release validation
Refresh native translations from verified Native App Locale Refresh run 35713695170 and regenerate Android and Apple resources against current source. Regenerate Control UI translation memory and fallback metadata for the new Code Mode hints.

Strict native and Control UI checks pass with zero Control UI fallbacks. Keep source and release parity gates unchanged.
2026-09-22 05:47:56 -07:00
Peter Steinberger
6ba6f0c7a7
fix(tests): observe cron refresh readiness (#155645)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-22 04:15:54 -07:00
RoboClaw
65821c2c48
fix(ios): assistant files are not downloadable in chat (#155195)
* fix(ios): make assistant file attachments downloadable

Decode managed document envelopes, reuse scoped artifact downloads, and hand files to the native system exporter with owned temporary copies.

Co-authored-by: Takhoffman <781889+Takhoffman@users.noreply.github.com>

* test(ios): prove managed file downloads through native sharing

Register baseline-compatible decode and real-app loopback Gateway tests in the existing iOS lifecycle lane. Retain exact-baseline behavioral failures, candidate assertions, simulator screenshots, xcresults, and full logs without changing production renderers or transport owners.

Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>

* test(ios): fix attachment proof CI contracts

Keep fixture imports before executable declarations and require the registered attachment proof plus all native evidence paths in the workflow contract test. Both CI failures reproduced locally and now pass without weakening existing assertions.

Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>

* test(ios): keep document UI proof in full validation

Honor measured native test budgets: keep the 95-second pairing/share UI flow in the existing full-manual tests phase, while adding decoder, loader, and typography regressions to the existing mandatory PR smoke invocation. Preserve all voice/lifecycle/watch checks and retained evidence; contract tests verify both tiers.

Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>

* test(ios): align executed smoke suite contract

Require all seven executed smoke selectors: preserve the original voice cleanup suites and add the approved decoder, document loader, and typography regressions. Keep the single invocation and normal Debug simulator signing assertions.

Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>

---------

Co-authored-by: Takhoffman <781889+Takhoffman@users.noreply.github.com>
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
2026-09-22 03:01:38 -07:00
Vincent Koc
de0c72fea4
fix(ci): isolate macOS launch-agent fixture homes (#155551)
* test(macos): isolate launch agent homes without changing HOME

* test(macos): pin environment key type in isolation fixture
2026-09-22 16:09:52 +08:00
Shakker
65e49fa200
fix: bind queued GitHub publication to its requester (#154477)
Queued shared GitHub publication retains its original requester and access grant across deferral and restart. Accepted results remain recoverable after access ends.
2026-09-22 06:20:21 +01:00
Peter Steinberger
c69b8b9868
fix: recognize verified team admins as channel owners (#153508)
* fix: recognize verified team admins as channel owners

Resolve channel owner authority from SQLite profile identity links and current login grants, with immediate revocation across deferred work. Keep Gateway and bundled plugins on one native SDK graph and replace the related process-global authority registries with instance-owned capabilities.

* fix: preserve channel owner authority through deferred work

Authorize Discord commands before ACP preparation and retain the original live owner through backend effects and updater handoffs. Normalize direct notice recipients through channel contracts. Complete native test-loader and instance-runtime fixture coverage, including final-effect and revocation regressions.

* fix(plugins): retain host SDK access in captured workers

Link captured plugins to the selected host package for worker isolates, preserving native SDK identity through retained generations and recovery. Align CI fixtures with instance-owned runtimes and join owned asynchronous work in teardown and Telegram buffering tests.

Validation: native worker regression fails before the fix and passes across native/legacy and source/dist hosts; 325 core tests, the full 3121-test Slack suite, targeted channel tests, protocol generation, Android lint, changed checks, and independent review pass.

* fix(runtime): keep snapshot cleanup inside owned directories

Treat captured SDK host-package links as removable leaves, preserving ownership records until snapshot data is gone. Preserve sanitized readiness subprocess failures and exercise Doctor through its complete isolated runtime on clean installations.

* fix(plugins): keep lazy runtime ownership metadata local

Preserve deferred Gateway facets with instance-owned proxy metadata and retain redacted readiness failure diagnostics on the current subprocess result owner.

* fix(auth): retain live owner authority through command effects

Carry the admitted administrator assertion through command dispatch, ACP controls and metadata commits, config and allowlist writes, plugin consent and installation, MCP mutation, and restart preparation. Preserve accepted-operation settlement and condition restart acknowledgement cleanup on its owned revision. Prove allowed administrators, forbidden senders, revocation and reassignment through real handler and persistence boundaries.

* refactor(restart): require owned revisions for sentinel cleanup

Remove the unused unconditional clear facade and storage branch. Keep revision-floor migration, durable failure reporting, and updater consumption proof on the canonical conditional-clear operation.

* test(auth): align owner regressions with fixture lint contracts

* refactor(auth): simplify channel owner and runtime authority

Resolve linked channel administration from the current Team role policy, retaining identity-grant fallback only for roleless installations. Consolidate Gateway generation state into its lifecycle owner, simplify Discord native routing and remove redundant loader and ingress state. Preserve current-authority checks before writes and required cleanup after accepted operations.

* test(auth): compare public generation state values

* refactor(auth): keep authority fixtures and handoff types with their owners

Extract coherent fixture builders and internal updater types to keep large files from growing. Correct the task-identifier test import to its codec owner and remove the unused internal route-policy export. Preserve all runtime behavior, assertions, deadlines and revision-owned sentinel cleanup.

* fix(channels): preserve native conversation scope in ingress authority

* fix(imessage): bind ingress after reply ID mapping

* fix(test): preserve scoped filesystem and channel admission contracts

* test(fleet): share stopped container state fixture

* test(fleet): type stop mock against the container contract

* fix(auth): retain current owner authority through deferred effects

* refactor(auth): keep authority fixtures and helpers with their owners

* fix(ci): remove duplicate database worker test entry

Retain the existing worker.runtime test entry so compact CI planning includes every storage-state test once. The duplicate introduced in d2c8c34af2 made preflight reject all split timing generations for this owner.

Reproduced the exact preflight error before the repair. Hybrid, GitHub, and Blacksmith planning now preserve all 660 unique storage-state files. The 217 planner/config tests, selected changed-file checks, formatting, and diff checks pass.

* refactor(auth): prepare profile authority in SQLite workers

Move channel identity and affected profile writes onto the existing worker owners, with current authority at commit and explicit rollback recovery. Bind native Telegram commands to verified ingress and retain shared-owner administration.

* fix(auth): preserve owner checks and released ingress callers

Forward Telegram authority through configured backend preparation and retain released ingress helper provenance through the existing plugin instance owner. Keep identity result types in the leaf contract and repair worker-aware test routing and fixtures without weakening policy assertions.

* fix: correct ingress names and database test ownership

Keep supported SDK ingress adapters while distinguishing internal policy operations. Assign broker-dependent HTTP suites only to the Gateway fork owner, preserve sorted test discovery, reuse chat registration fixtures, and declare the dynamically loaded Telegram test entry.

* test(cli): use prepared runtime for MCP probe exit

Exercise the real CLI entrypoint instead of compiling source-backed SQLite workers inside the command deadline. Keep the 30-second deadline and the exit, JSON, and named diagnostic checks.

* test(codex): check native worker termination at teardown

Observe native Worker thread IDs after fixture cleanup instead of equating
thread exit with asynchronous resource-destroy notification. Keep the
allocation assertion and existing cleanup; do not wait for idle retirement.

The three-case file passes in 48.495s. Omitting only its harness disk-worker
drain fails immediately on a live thread in 30.715s. A Node 24.19 control
observes threadId -1 while the async destroy notification is still pending.
Managed review is clean through P2. The earlier CI worker identity remains
unproven; this is a test-contract repair, not a production leak claim.

* test: settle identity fixtures and route database cleanup

Wait for actual GitHub metadata entry and settle both identity requests on failure. Run the session-store consumer in the existing database fork owner so native retirement can use the host broker.

* test: settle admin fixtures at their owning boundaries

Await canonical asynchronous MCP OAuth reads and the existing Gateway attachment completion. Keep avatar work independently gated and preserve all permission assertions. Move ingress and callback fixture helpers into the existing support owner to keep the health suite within its line-growth limit.

* test(worker): share the compiled SDK graph in crash fixtures
2026-09-21 19:56:45 -07:00
Peter Steinberger
48f664ca00
fix: review provider precautions before continuing chat (#155214)
* fix: review provider precautions before continuing chat

* fix: preserve provider review integration contracts

* fix: carry provider review authority into runtime attempts

* fix(android): match Robolectric discovery callback overrides
2026-09-22 01:05:14 +00:00
Peter Steinberger
d0f40a8de2
chore(deps): refresh dependencies with seven-day cutoff (#154652)
* chore(deps): refresh dependencies with seven-day cutoff

Advance eligible runtime, native, release, and development dependencies published by 2026-09-14T07:00:00Z. Preserve compatibility holds and existing reviewed newer pins. Synchronize release integrity checks and scoped overrides; remove the superseded mailparser override.

Preserve Clack cancellation inference with its precise sentinel type and isolate the Vertex proxy fixture from ambient credentials. Timestamp and checksum audits, targeted consumers, native builds/tests, and independent review validate the refresh; required hosted CI remains the landing gate.

* fix(deps): preserve Clack cancellation types in exported prompts

Give styled configure prompts the exact upstream return types so plugin SDK declaration emission can name the new cancellation sentinel. Runtime behavior and generic option values are unchanged.

* fix(deps): preserve release tooling and Android test contracts

Regenerate Ruby lock metadata with pinned Bundler 2.6.9, grant Robolectric 4.17 its documented module access only in Android test JVMs, and keep the precise cancellation type without growing an over-cap source file.

Both previously failing Ruby lock guards, the line-cap and core type checks, all three configured Android test-task JVM arguments, and the actual Robolectric interceptor before/after probe pass. Independent review found no actionable P0/P1 issues.

* fix(deps): close Rustls advisory and align mock session clocks

Rustls 0.23.45 has now completed the seven-day cooldown; update only the shared crate pin and lock to the existing security-fixed desktop version.

Advance accepted mock Gateway writes on the synthetic fixture timeline and correlate permission tests with the actual mutation and refresh. This repairs a reproduced CI fixture race without changing production behavior or weakening assertions.

Validation: 36 Rust gateway-client tests including four TLS handshakes, 50 fixture tests, nine browser cases, scoped changed checks, and independent P0/P1 review passed.

* test(ui): keep external session updates on the committed timeline

* test: stabilize approval and desktop CI fixtures

* build(workboard): refresh assets after dependency rebase
2026-09-21 16:55:54 -07:00
RoboClaw
489d5d1d6b
fix(android): keep gateway discovery current after service changes (#155038)
Keep Android Gateway discovery tied to live registrations by serializing service-info callbacks and atomically publishing local and wide-area changes. Preserve legacy resolution ownership, TLS pins, pairing and permission rules.

Validated with callback ordering/replacement regressions, discovery siblings, native lint and exact-head CI. No physical-device, live-mDNS or simultaneous live wide-area overlap acceptance is claimed.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-21 16:11:59 -07:00
RoboClaw
f1f0bb1e4a
fix(android): restore video playback after switching media (#155037)
Settle the released current media player's loading, playing and position state together so a video becomes retryable after playback handoff. Ignore stale releases and retain voice-blocking and transport authorization.

Validated with real-player Robolectric handoff/retry/disposal regressions, Gateway media siblings, native lint and exact-head CI. No physical-device or live-Gateway playback acceptance is claimed.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-21 16:09:00 -07:00
RoboClaw
e7f94eb363
fix(android): unblock gateway switching after interrupted voice notes (#155036)
Retire voice-note media acquisition from the recorder lifecycle owner so backgrounding or leaving Chat no longer leaves Gateway switching blocked. Preserve independent pending imports, sends and attachment authorization.

Validated with recorder, composer and sidebar regressions, native lint and exact-head CI. Native before/after proof is documented in the PR; no physical-device recording or live pairing acceptance is claimed.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-21 16:06:59 -07:00
RoboClaw
d00afc6ae1
fix(android): stop runs in explicitly owned sessions (#155035)
Fix Android Stop for explicitly owned sessions and keep every abort in a captured batch bound to its original Gateway, agent and session. Surface rejected or uncertain aborts only in that conversation and preserve coroutine cancellation.

Validated with abort/stream regressions, native inventory checks, native lint and exact-head CI. Native before/after proof is documented in the PR; no physical-device or live-Gateway acceptance is claimed.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-21 16:04:09 -07:00
Peter Steinberger
ff90bc7fb2
feat(crabbox): run native CUA in macOS and Windows cloud desktops (#152060)
Add native computer use and Browser/Terminal launchers for prepared macOS and Windows cloud workers through Crabbox's existing authenticated transport, placement, and teardown.

Launch the separately signed Mac Cloud Worker app through LaunchServices and let it own Node/CUA, desktop permissions, and the renewable idle assertion. Bind Windows enrollment and replay to the worker's interactive account and session. Preserve uncertain launch evidence for reprovisioning, and require confirmed lease teardown before downgrading readers of newer desktop metadata.

Preserve chat end-follow during coalesced composer and goal resizing by carrying the actual scroll correction through the existing resize event and offset owner. Retain the canonical rail, progress, and approval lifecycle implementations.

Validation: exact-head CI passed 165 jobs with seven skips; 142 focused approval cases passed locally. Historical native platform proof and the remaining current-driver, lock/account-loss, enrollment, and downgrade qualification limits are recorded in #152060 under the requested best-effort testing scope.

Refs #152060.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-21 15:31:06 -07:00
Peter Steinberger
97dd4d233b
feat(gateway): download inline artifacts over HTTPS (#154673)
* feat(gateway): download inline artifacts over HTTPS

* fix(ui): renew binary artifact downloads on click

* refactor(gateway): keep artifact read validation with session resolution

* fix(ui): reject proxy app pages during artifact downloads
2026-09-21 14:52:14 -07:00
Patrick Erichsen
87a4643452
feat(plugins): show installation progress and lifecycle feedback (#150235)
Punchcard-Session: coral-lantern-meadow-m8
2026-09-21 21:45:39 +00:00
Patrick Erichsen
97043faf6f
fix(plugins): simplify installation and grouped settings (#150234)
* feat: add contextual plugin help to Ask OpenClaw

Punchcard-Session: crisp-summit-lantern-qk

* fix(ui): redact URL credentials from plugin Ask drafts

Reuse the canonical URL policy in the bounded help-value scan, including
serialized map keys. Keep the editable config value intact and prove
rejected Save → Ask → Send on desktop and phone.

Punchcard-Session: crisp-summit-lantern-qk

* test: reuse the complete Custodian context fixture

Punchcard-Session: crisp-summit-lantern-qk

* refactor(ui): narrow plugin help selection input

Accept only the loaded selection facts consumed by the help controller, removing its type dependency on the complete page renderer model.

Punchcard-Session: crisp-summit-lantern-qk

* perf(ui): keep plugin help preparation off startup

Separate synchronous dock state and session ownership from lazy question preparation and session persistence helpers. Register plugin-only English copy with its lazy consumers while preserving source catalog order.

Punchcard-Session: crisp-summit-lantern-qk

* style: normalize contextual help rebase spacing

Punchcard-Session: crisp-summit-lantern-qk

* perf(ui): keep attachment media preparation off startup

Punchcard-Session: crisp-summit-lantern-qk

* test(qwen): fix the clock for default timeout assertions

Punchcard-Session: crisp-summit-lantern-qk

* test(ui): wait for side-chat opening focus

Punchcard-Session: crisp-summit-lantern-qk

* chore(pr): deduplicate wrapper dependency inventory

Punchcard-Session: crisp-summit-lantern-qk

* test(qwen): drop superseded default-clock workaround

* feat: group bundled plugin settings by authored manifest metadata

Punchcard-Session: crisp-summit-lantern-qk

* fix(plugins): simplify settings and catalog interactions

Remove redundant install review UI, organize settings using authored groups,
show truthful defaults, and repair catalog layout and loading states.

Punchcard-Session: crisp-summit-lantern-qk

* test(config): move tier schema checks to their owner suite

Punchcard-Session: crisp-summit-lantern-qk

* test(ui): align settings and draft recovery contracts

Wait for the settings search control and verify editable drafts cannot send before inference recovery.

Punchcard-Session: crisp-summit-lantern-qk

* fix(ui): honor modal cursor and sample header geometry atomically

Use the shared cursor token for the document Close action. Read the moving header title and tabs in one browser evaluation so the strict alignment assertion compares the same animation frame.

Punchcard-Session: crisp-summit-lantern-qk

* test(ui): observe settings assets without route interception

Punchcard-Session: crisp-summit-lantern-qk

* test(plugins): isolate bundled-only catalog curation fixtures

Punchcard-Session: crisp-summit-lantern-qk

* docs(plugins): explain explicit stored-key reveal

Punchcard-Session: crisp-summit-lantern-qk

* test(ui): await prior plugin settings inspections

Punchcard-Session: crisp-summit-lantern-qk

* chore(config): refresh the merged documentation baseline

Punchcard-Session: crisp-summit-lantern-qk

* fix(ui): expose roster pagination refresh state

Punchcard-Session: crisp-summit-lantern-qk

* fix(gateway): retain live authority through plugin lifecycle effects

Keep active request authority available to device, profile, origin, and
shared-auth revocation after ordinary transport disconnects. Revalidate
plugin lifecycle authority before tentative acceptance writes and runtime
application, while preserving lease-owned compensation.

Journal marker undo state before removal so a post-removal revocation
cannot leave a restored plugin index without its original retention marker.

Punchcard-Session: crisp-summit-lantern-qk

* test(ui): honor retained session windows in mutation fixture

Punchcard-Session: crisp-summit-lantern-qk

* test(plugins): exercise archive limits with real ZIP entries

Punchcard-Session: coral-lantern-meadow-m8

* test(plugins): declare complete installed catalog fixtures

Punchcard-Session: coral-lantern-meadow-m8

* fix(gateway): retain required new-agent welcome on rejoin

Punchcard-Session: coral-lantern-meadow-m8

* fix(ui): preserve composer contrast across theme integration

Punchcard-Session: coral-lantern-meadow-m8

* fix(test): exclude checkout scratch from compiler inputs

Concurrent hook fixtures can disappear after namespace enumeration. Keep root scratch outside compiler cache preparation while retaining nested workspace and installed metadata invalidation.

Punchcard-Session: coral-lantern-meadow-m8

* fix(test): await native turn admission before interrupting

Punchcard-Session: coral-lantern-meadow-m8

* test(gateway): use client registry in approval fixture

Punchcard-Session: coral-lantern-meadow-m8
2026-09-21 14:02:06 -07:00
Peter Steinberger
6869ace3d3
chore: move Apple CI to Xcode 27 (#154332)
* ci: validate Apple builds and tests with Xcode 27

* fix(ci): include Swift selection in trusted platform checkouts

* fix(ci): retain Periphery index layout and report Swift crashes

* fix(test): adapt native validation to Xcode 27 runtime and indexing

* test: run Quick Chat presentation flows with Swift Testing

* docs: clarify Xcode analyzer compatibility requirements

* test: diagnose early AppKit test process exit

* test: give rendered Mac tests an AppKit event loop

* test: await AppKit event processing before rendered tests

* test: wait for the rendered Quick Chat model picker

* fix(ci): isolate Apple test logs and await fixture readiness

* test: retain all default-profile capture evidence

* fix(ci): repair Apple qualification diagnostics and fixtures

* test: surface Quick Chat sends rejected before transport entry

* test: capture suspended Quick Chat tasks during CI stalls

* test: read attributed accessibility titles without abandoning Swift tasks

* test: normalize accessibility titles across native fixtures

* test: find named-profile model controls by accessible name

* fix: retain lost Windows PID authority through shutdown retries

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-21 13:57:07 -07:00
Peter Steinberger
c077d5f5f3
feat(themes): support plugin hats and critter artwork (#154935)
Let plugin themes declare bounded, self-contained SVG assets for avatar hats
and composer visitors. Capture artwork with each plugin generation, expose
content-hashed authenticated resource URLs, and rasterize images lazily in
the Control UI. Personal imports remain limited to built-in artwork IDs.

Package declared assets through the shared filesystem boundary while keeping
manifest declarations usable by native build and updater tooling. Preserve
existing pointer interactions, loaded-photo hats, palette notifications,
and transcript invalidation. Document validation and reload behavior.

Validation: focused protocol, manifest, Gateway, UI, packaging, native updater,
and extracted PR tooling tests; core/UI/scripts and affected test typechecks;
protocol generators, style lint, dead-code checks, assertion and line-cap
ratchets, formatting, docs links, and scoped-clean P1 review. Inspected
synthetic before/after captures are attached to the PR. Startup budget files
remain unchanged at 370300 B baseline and 370876 B enforcement.
2026-09-21 10:30:47 -07:00
Vincent Koc
b61609f316
fix(android): exclude unused Picnic resources from app packages (#154782) 2026-09-21 20:20:35 +08:00
Peter Steinberger
9e61c5e3a1
feat(ui): let themes drop the mascot, set status words, add critters and avatar hats (#154518)
* feat(ui): let themes drop the mascot, set status words, add critters and avatar hats

Portable theme definitions (built-in, plugin, personal) gain four optional
presentation fields. `mascot: "none"` swaps the lobster mark, favicon, login
gate, system avatar, About hero, and the working-row claw for a neutral prompt
mark drawn in the theme's primary color, and keeps the resident lobster and
lobster strangers off the composer ledge while ordinary visitors keep coming
under the unchanged Lobster visits toggle. `workingPhrases` replaces the
crustacean long-wait words with theme-authored text (up to 24, empty = silent).
`critters` adds catalog visitors (a penguin in a red fedora, and the fedora on
its own) to the ledge traffic at 2 % per critter per load without changing the
regulars' odds. `avatarHat` puts a fedora on an agent avatar about one page
load in six, seeded per agent and load.

The Gateway validates the fields in normalizeThemeDefinition and the TypeBox
schema, projects them onto plugin and personal descriptors, and the theme tool
imports them unchanged. The Control UI resolves branding through the theme
context, stamps data-theme-mascot and data-theme-avatar-hat on the root, and
rebuilds the favicon from computed colors when the mascot changes.

Startup JS grows by 2,467 B gzip (0.67 %); the baseline moves with it.

* fix(ui): complete portable theme branding and CI contracts

* fix(ui): satisfy core lint and the Linux startup budget

* fix(ui): give the startup JS baseline its allowance headroom
2026-09-21 04:08:22 -07:00
Peter Steinberger
f7dae76bee
feat(search): configure providers and verify search in Settings (#154135)
* feat(search): configure providers and verify search in Settings

* refactor(search): keep settings projections lint clean

* fix(search): bind provider tests to applied settings

* fix(search): preserve protocol order and complete CI coverage

* perf(search): defer model URL validation until needed

* fix(search): recheck authority before provider requests

* fix(search): include authority helper in wrapper closure

* test(qa): retain redacted cron run failure diagnostics

Keep the existing timeout and success predicate while preserving the complete redacted cron response in assertion output and retained proof. The original CI timeout remains unproven after bounded replay; this change improves diagnosis without claiming a causal flake repair.

* fix(search): project status from published auth state

Keep Search settings credential availability and native routing on lifecycle-published auth snapshots. Missing publication remains unavailable instead of reopening persisted auth on the Gateway request thread. Regression cases fail on the previous cold-state fallback; 71 focused and sibling cases, typechecks, lint, and independent review pass.
2026-09-21 03:51:42 -07:00
Peter Steinberger
6c9900b470
fix(macos): sign in again from an open dashboard (#154639)
* fix(macos): restore sign-in from open dashboards

* test(macos): capture native sign-in recovery proof
2026-09-21 03:41:35 -07:00
Peter Steinberger
ed7dd25135
fix(macos): stabilize readiness and installer regression tests (#154269)
* fix(macos): stabilize readiness and installer regression tests

* test(macos): distinguish health and retry timer admissions
2026-09-20 22:56:02 -07:00
Peter Steinberger
54abbae585
fix: refresh stale Gateway shutdown budgets during updates and Doctor (#153636)
* fix: refresh stale Gateway stop policies before maintenance

Main recognized historical systemd timeouts, but maintenance could stop the
resident before repair, and Doctor and already-current or no-restart updates
could preserve stale computed policy. A published 2026.9.5 resident also retains
its startup shutdown budget after the unit changes.

Refresh owned policy through the existing definition-mutation and backup owners,
confirm daemon reload, preserve operator drop-ins, and retain restore/reload/input
retirement ordering. Share maintenance between update and Doctor, and warn when
a non-stopping refresh still has a short effective manager timeout.

Publish process-owned shutdown budgets and lifecycle write-custody facts. Reuse
the suspension owner and existing update deadline: stop when idle, warn and stop
at the deadline for ordinary work or unknown custody, and refuse only current
reported write custody with its exact owner phase. Reread native policy when the
new Gateway accepts shutdown without resetting its elapsed budget or watchdog.

Thanks @ezimerman for the installed-unit and shutdown evidence.
Fixes #153153. Refs #150898, #152879, #153017.

* fix: preserve the resident shutdown budget in Gateway status

The kernel request-context adapter copied host lifecycle control methods but
dropped the recorded shutdown-budget getter. Real Linux package proof observed
a 325-second startup budget while status omitted it, forcing maintenance onto
the legacy unknown-budget path.

Forward the live getter through the existing adapter without changing request
authority or adding another budget owner. Add a real-kernel registered-status
regression for short and adequate budgets; the corrected test fails on the
original adapter and passes with the forwarding line.

Refs #153153.

* test: control the Gateway shutdown clock consistently

Restore the explicit node:perf_hooks performance import for the run-loop regressions that retain their own fake-clock assertions. They must control the same monotonic clock as the production shutdown-budget owner. Keep the deadline assertions, timers, and production behavior unchanged.

* fix: preserve Doctor legacy reads during Gateway preflight

The stale-Gateway probe opened the canonical owner-lease database without
Doctor's existing legacy-catalog admission. With a built install and a busy
Gateway port, that read created WAL/SHM files and rejected a supported repair
before maintenance could stop the Gateway.

Carry the existing read admission through restart inspection to the lease owner.
Keep ordinary restart validation unchanged and preserve canonical artifacts.
Use synthetic port, build, and reachability facts in the regression fixture while
retaining real lease reads and byte-preservation assertions.

Refs #153153.

* refactor: keep Gateway maintenance owners within line limits

The L903 stop-policy repair exceeded the existing line-growth gate after
composition with current restart and service identity handling. Move request
upgrade policy into its existing request owner and service revalidation into
one sibling implementation without changing their behavior.

Preserve original request admission time and Doctor's statically primed
maintenance facade across package replacement. The bounded drain, recorded
custody-only refusal, warning policy, and native backup/reload ordering remain
unchanged. No options, schema changes, suppressions, or baseline growth.

Validation: 398 focused tests, core typecheck, line-growth ratchet, and fresh
Codex P1 review passed. Full changed checks continue on the frozen source.

* test: retain backup custody coverage through the archive walker

The rebase incorporated the maintained archive walker, but the L903 custody
regression still referenced the retired tar-create mock. Use the existing
walker mock bound to the real backup command without changing assertions or
production code.

Validation: 132 backup, migration, cron, coordinator, and suspension tests
passed. Fresh Codex P1 review is clean. Full changed checks continue.

* fix: preserve maintenance lifecycle and wrapper contracts

Doctor fixtures advertised a running native service without the matching
resident identity, effective policy, or lifecycle readiness response. Supply
those facts through the same RPC and native-query boundaries used by the real
maintenance owner, including fresh readiness without a resident budget.

Keep exact suspension assertions current with the additive custody category.
Install the model-acquisition fixture's manager after normal PATH setup so
startup and shutdown observe the same policy under the original deadlines.
Include the custody owner in the canonical PR-wrapper source inventory.

Move the unchanged Doctor inspection assertion and shared fixtures into their
existing policy/support owners to preserve the line-growth ratchet. Do not
change the bounded-deferral, warning, or reported-write-custody refusal policy.

* fix: preserve Stop ownership through shutdown budget refresh

An asynchronous systemd budget read could resume after Stop captured a
foreground updater and re-arm the hard-exit worker. Keep watchdog admission
with the run loop's current successor owner, and represent an absent cleanup
deadline with no process-cleanup budget.

Preserve foreground no-op service ownership and the full native allowance
after verified parking. Keep one fake clock for boundary tests, prepare
fixture operations before held scripts, and join cancelled fixture work
before the next case. Move unchanged budget cases into their support owner.

Retain the ruling that unknown custody cannot block an update and only
reported write custody may refuse maintenance. Preserve all existing test
assertions and limits. The full Linux changed gate, 790 focused Linux tests,
and a fresh P1 review passed; local host limitations are recorded in the PR.

* refactor(doctor): extract update-run admission from doctor-maintenance

* fix: preserve native policy and write custody during maintenance

* fix: keep shutdown integration within source and type gates

* fix(test): own survivor model endpoint before baseline setup

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-21 12:31:05 +08:00
RoboClaw
b86dc71207
refactor: remove compaction checkpoints (#154131)
* refactor: remove compaction checkpoints

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: d8185b46-c34b-46cb-a7bc-f4992867d3c9

* refactor: remove compaction checkpoints

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 80da0151-c7d1-4d40-80a6-e4a560bedf53

* refactor: remove compaction checkpoints

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: a7caf11d-e661-4a0f-8363-644cc007693a

* refactor: remove compaction checkpoints

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: e1a860df-02a1-4a99-a3f1-e9889eea119e

* test: repair checkpoint retirement CI fixtures

Route deferred QA tools through their declared dispatcher, preserve exact successful chronology receipts, and await rendered native accessibility values without weakening assertions.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(codex): stabilize bounded rollout fixture

Reuse steipete's reviewed startup-scan synchronization repair from #154260 (89f04eec2cb1e9e30f859f4a2f37a28f018d6715). Preserve preview, workspace, native-call-count and byte-limit assertions. Focused 12-case file passes on the composed candidate.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-20 19:47:11 -07:00
Peter Steinberger
37bbf5a1b6
fix: reduce serialized Swift test execution (#154190)
* fix: reduce serialized Swift test execution

* test: synchronize Swift fixture readiness and completion
2026-09-20 18:54:05 -07:00
Peter Steinberger
647e62369f
fix: keep Tauri new-session shortcut in the foreground (#154118)
Stop registering Cmd/Ctrl+Shift+O system-wide so other foreground apps receive their own New Session shortcut. Preserve Quick Chat global activation and its reservation against hijacking the foreground chord.
2026-09-20 17:25:58 -07:00
Peter Steinberger
68def4154c
fix: avoid claiming macOS has no login keychain (#154151)
Scope saved-Gateway keychain lookup failures to the app launch environment. Suggest reopening from Finder, retain configuration guidance for a persistently missing keychain, and document credential-free macOS fixtures.
2026-09-20 17:14:14 -07:00
Peter Steinberger
3ec1caf958
fix: reduce Swift test execution overhead (#154100) 2026-09-20 16:00:10 -07:00
RoboClaw
ddb31b38a8
feat(ui): refresh work progress without adding a chat message (#154044)
* feat(ui): refresh work progress without adding a chat message

Worked on by:
- @steipete
- @shakkernerd

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: shakkernerd <165377636+shakkernerd@users.noreply.github.com>
OpenClaw-Publication: d2d91917-0d1c-4b51-b6d6-08b345a1ee4b

* fix(ui): recover progress refresh retries without duplicate work

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: shakkernerd <165377636+shakkernerd@users.noreply.github.com>

* fix(protocol): align generated refresh method order

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: shakkernerd <165377636+shakkernerd@users.noreply.github.com>

* fix(ui): allow retry after queued progress refresh settles

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: shakkernerd <165377636+shakkernerd@users.noreply.github.com>

---------

Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: shakkernerd <165377636+shakkernerd@users.noreply.github.com>
2026-09-20 15:54:53 -07:00
openclaw-mantis[bot]
1e6d645b75
chore(i18n): refresh native locales (#153967)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-20 22:31:36 +00:00
Colin Johnson
6e5a6c6c5a
fix(ios): prevent chat freezing when sending a photo (#154082)
* fix(ios): prevent chat freezing when sending a photo

* test(ios): wait for composer recovery after send
2026-09-20 18:29:43 -04:00
Dallin Romney
af00d16e35
fix(macos): shrink universal app downloads by pruning the node worker (#150773)
* fix(macos): prune bundled node worker runtime

* fix(macos): retain lazy worker capabilities

* fix(macos): retain internal package dependencies

* test(macos): prove app-gated computer commands

* refactor(macos): reuse runtime entrypoint owner

* fix(macos): register worker build entry

* test(macos): stage worker pruner fixture

* fix(macos): retain sqlite worker runtime

* fix(macos): validate pruned elevation worker

* fix(macos): retain descriptor-launched workers

* fix(macos): finalize private node worker exits

Use the shared CLI finalizer so completed workers and startup failures exit even when plugin-owned handles remain. Cover normal shutdown, signal exit status, and startup failure through the private entry.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-20 14:41:35 -07:00
Peter Steinberger
691da4f147
fix(ui): enable desktop access from Systems (#154008)
* fix(ui): enable desktop access from Systems

Detect compatible host desktops before opt-in, preserve existing configuration, and enable access through the shared configuration and restart owner. Normalize Mac platform labels and explain macOS Remote Management access failures.

* test(ui): initialize Systems fixtures before navigation
2026-09-20 14:27:19 -07:00