Project permitted model catalogs and defaults through the shared role-policy owner. Retire stale choices on policy changes while preserving session history and saved model preferences.
Enable authenticated users to edit their personal instructions from Profile or chat on multi-user Gateways. Keep single-user Gateways on the workspace-root USER.md.
Preserve requester-bound authority, safe local writes, conflict checks, reconnect drafts, normal Profile spacing, and the startup performance budget.
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Add provider-neutral explicit Decision evaluation through the existing runtime, declared provider capabilities, and a default-off Labs consent foundation. Keep explicit evaluation independent of Labs and retire the unreleased TypeSafe-specific tool. No automatic consumer or public selection/local-availability inspection API is added.
Verified the registered core tool with real ONNX CPU inference, host-bound rejection before dispatch, and agent disablement. Preserve the contributor implementation and the reviewed Labs UI/config behavior.
Related: #155115, #155314, #155317
Co-authored-by: Jacqueline Henriksen <jjjhenriksen@gmail.com>
Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
* fix(update): explain foreign destination refusals
Preserve bounded ownership facts and sanitized installation paths through
update history and public reports. Keep destination protection and canonical
path admission, and retain prefix-mismatch recovery in status and Doctor.
Refs #154466. Thanks @imHw, @agent-axos, and @smaill02 for the reports.
* ci(ui): cover destination diagnostics in startup budget
The shared destination report adds 375 gzip bytes to startup, taking the CI merge from 370570 to 370945 bytes. Raise the paired baseline and cap by only 69 bytes, retaining the existing 512-byte growth and 64-byte variance allowances.
* ci(ui): refresh startup budget after rebase
Measure main 05804bcf and the rebased head with the same UI toolchain: 370367 B to 370756 B (+389 B). Set the paired baseline and cap to the fresh measured head while preserving existing allowances. Main passes its own budget.
* fix: recognize verified team admins as channel owners
Resolve channel owner authority from SQLite profile identity links and current login grants, with immediate revocation across deferred work. Keep Gateway and bundled plugins on one native SDK graph and replace the related process-global authority registries with instance-owned capabilities.
* fix: preserve channel owner authority through deferred work
Authorize Discord commands before ACP preparation and retain the original live owner through backend effects and updater handoffs. Normalize direct notice recipients through channel contracts. Complete native test-loader and instance-runtime fixture coverage, including final-effect and revocation regressions.
* fix(plugins): retain host SDK access in captured workers
Link captured plugins to the selected host package for worker isolates, preserving native SDK identity through retained generations and recovery. Align CI fixtures with instance-owned runtimes and join owned asynchronous work in teardown and Telegram buffering tests.
Validation: native worker regression fails before the fix and passes across native/legacy and source/dist hosts; 325 core tests, the full 3121-test Slack suite, targeted channel tests, protocol generation, Android lint, changed checks, and independent review pass.
* fix(runtime): keep snapshot cleanup inside owned directories
Treat captured SDK host-package links as removable leaves, preserving ownership records until snapshot data is gone. Preserve sanitized readiness subprocess failures and exercise Doctor through its complete isolated runtime on clean installations.
* fix(plugins): keep lazy runtime ownership metadata local
Preserve deferred Gateway facets with instance-owned proxy metadata and retain redacted readiness failure diagnostics on the current subprocess result owner.
* fix(auth): retain live owner authority through command effects
Carry the admitted administrator assertion through command dispatch, ACP controls and metadata commits, config and allowlist writes, plugin consent and installation, MCP mutation, and restart preparation. Preserve accepted-operation settlement and condition restart acknowledgement cleanup on its owned revision. Prove allowed administrators, forbidden senders, revocation and reassignment through real handler and persistence boundaries.
* refactor(restart): require owned revisions for sentinel cleanup
Remove the unused unconditional clear facade and storage branch. Keep revision-floor migration, durable failure reporting, and updater consumption proof on the canonical conditional-clear operation.
* test(auth): align owner regressions with fixture lint contracts
* refactor(auth): simplify channel owner and runtime authority
Resolve linked channel administration from the current Team role policy, retaining identity-grant fallback only for roleless installations. Consolidate Gateway generation state into its lifecycle owner, simplify Discord native routing and remove redundant loader and ingress state. Preserve current-authority checks before writes and required cleanup after accepted operations.
* test(auth): compare public generation state values
* refactor(auth): keep authority fixtures and handoff types with their owners
Extract coherent fixture builders and internal updater types to keep large files from growing. Correct the task-identifier test import to its codec owner and remove the unused internal route-policy export. Preserve all runtime behavior, assertions, deadlines and revision-owned sentinel cleanup.
* fix(channels): preserve native conversation scope in ingress authority
* fix(imessage): bind ingress after reply ID mapping
* fix(test): preserve scoped filesystem and channel admission contracts
* test(fleet): share stopped container state fixture
* test(fleet): type stop mock against the container contract
* fix(auth): retain current owner authority through deferred effects
* refactor(auth): keep authority fixtures and helpers with their owners
* fix(ci): remove duplicate database worker test entry
Retain the existing worker.runtime test entry so compact CI planning includes every storage-state test once. The duplicate introduced in d2c8c34af2 made preflight reject all split timing generations for this owner.
Reproduced the exact preflight error before the repair. Hybrid, GitHub, and Blacksmith planning now preserve all 660 unique storage-state files. The 217 planner/config tests, selected changed-file checks, formatting, and diff checks pass.
* refactor(auth): prepare profile authority in SQLite workers
Move channel identity and affected profile writes onto the existing worker owners, with current authority at commit and explicit rollback recovery. Bind native Telegram commands to verified ingress and retain shared-owner administration.
* fix(auth): preserve owner checks and released ingress callers
Forward Telegram authority through configured backend preparation and retain released ingress helper provenance through the existing plugin instance owner. Keep identity result types in the leaf contract and repair worker-aware test routing and fixtures without weakening policy assertions.
* fix: correct ingress names and database test ownership
Keep supported SDK ingress adapters while distinguishing internal policy operations. Assign broker-dependent HTTP suites only to the Gateway fork owner, preserve sorted test discovery, reuse chat registration fixtures, and declare the dynamically loaded Telegram test entry.
* test(cli): use prepared runtime for MCP probe exit
Exercise the real CLI entrypoint instead of compiling source-backed SQLite workers inside the command deadline. Keep the 30-second deadline and the exit, JSON, and named diagnostic checks.
* test(codex): check native worker termination at teardown
Observe native Worker thread IDs after fixture cleanup instead of equating
thread exit with asynchronous resource-destroy notification. Keep the
allocation assertion and existing cleanup; do not wait for idle retirement.
The three-case file passes in 48.495s. Omitting only its harness disk-worker
drain fails immediately on a live thread in 30.715s. A Node 24.19 control
observes threadId -1 while the async destroy notification is still pending.
Managed review is clean through P2. The earlier CI worker identity remains
unproven; this is a test-contract repair, not a production leak claim.
* test: settle identity fixtures and route database cleanup
Wait for actual GitHub metadata entry and settle both identity requests on failure. Run the session-store consumer in the existing database fork owner so native retirement can use the host broker.
* test: settle admin fixtures at their owning boundaries
Await canonical asynchronous MCP OAuth reads and the existing Gateway attachment completion. Keep avatar work independently gated and preserve all permission assertions. Move ingress and callback fixture helpers into the existing support owner to keep the health suite within its line-growth limit.
* test(worker): share the compiled SDK graph in crash fixtures
Load plugin skill previews without waiting for every supporting file.
Read the validated inventory and SKILL.md first, fetch supporting bodies only
when selected, and preserve bounded path/link/size/hash checks for installed
and catalog plugins. Scope caches to the open preview and connection, retain
retry/skeleton states, and preserve foreground reading position when a late
sibling response completes.
Measured live Composio initial-read median: 9.456s to 1.931s (7 to 2 requests).
Verified lazy reads, errors/races, rendered scroll regression, and review fixes.
Co-authored-by: Patrick-Erichsen <20157849+Patrick-Erichsen@users.noreply.github.com>
* fix(protocol): expose canonical suspension result validation
Let external lifecycle controllers validate prepare and status responses through the public protocol package instead of duplicating response-field allowlists. Preserve optional write-custody evidence and unfamiliar owner phases without changing schemas or lifecycle authority.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(cli): prepare device auth before connection timeouts
The actor-open preflight did not load its deferred command runtime, so cold token reads could consume the later Gateway RPC deadline. Dispatch an explicit preparation command through the existing worker owner without reading or caching token facts. Preserve read-only admission, mutation authority, and the original CLI timeout budgets.
Repairs the cold-auth CI failure exposed while qualifying #155258.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* feat: add contextual plugin help to Ask OpenClaw
Punchcard-Session: crisp-summit-lantern-qk
* fix(ui): redact URL credentials from plugin Ask drafts
Reuse the canonical URL policy in the bounded help-value scan, including
serialized map keys. Keep the editable config value intact and prove
rejected Save → Ask → Send on desktop and phone.
Punchcard-Session: crisp-summit-lantern-qk
* test: reuse the complete Custodian context fixture
Punchcard-Session: crisp-summit-lantern-qk
* refactor(ui): narrow plugin help selection input
Accept only the loaded selection facts consumed by the help controller, removing its type dependency on the complete page renderer model.
Punchcard-Session: crisp-summit-lantern-qk
* perf(ui): keep plugin help preparation off startup
Separate synchronous dock state and session ownership from lazy question preparation and session persistence helpers. Register plugin-only English copy with its lazy consumers while preserving source catalog order.
Punchcard-Session: crisp-summit-lantern-qk
* style: normalize contextual help rebase spacing
Punchcard-Session: crisp-summit-lantern-qk
* perf(ui): keep attachment media preparation off startup
Punchcard-Session: crisp-summit-lantern-qk
* test(qwen): fix the clock for default timeout assertions
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): wait for side-chat opening focus
Punchcard-Session: crisp-summit-lantern-qk
* chore(pr): deduplicate wrapper dependency inventory
Punchcard-Session: crisp-summit-lantern-qk
* test(qwen): drop superseded default-clock workaround
* feat: group bundled plugin settings by authored manifest metadata
Punchcard-Session: crisp-summit-lantern-qk
* fix(plugins): simplify settings and catalog interactions
Remove redundant install review UI, organize settings using authored groups,
show truthful defaults, and repair catalog layout and loading states.
Punchcard-Session: crisp-summit-lantern-qk
* test(config): move tier schema checks to their owner suite
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): align settings and draft recovery contracts
Wait for the settings search control and verify editable drafts cannot send before inference recovery.
Punchcard-Session: crisp-summit-lantern-qk
* fix(ui): honor modal cursor and sample header geometry atomically
Use the shared cursor token for the document Close action. Read the moving header title and tabs in one browser evaluation so the strict alignment assertion compares the same animation frame.
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): observe settings assets without route interception
Punchcard-Session: crisp-summit-lantern-qk
* test(plugins): isolate bundled-only catalog curation fixtures
Punchcard-Session: crisp-summit-lantern-qk
* docs(plugins): explain explicit stored-key reveal
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): await prior plugin settings inspections
Punchcard-Session: crisp-summit-lantern-qk
* chore(config): refresh the merged documentation baseline
Punchcard-Session: crisp-summit-lantern-qk
* fix(ui): expose roster pagination refresh state
Punchcard-Session: crisp-summit-lantern-qk
* fix(gateway): retain live authority through plugin lifecycle effects
Keep active request authority available to device, profile, origin, and
shared-auth revocation after ordinary transport disconnects. Revalidate
plugin lifecycle authority before tentative acceptance writes and runtime
application, while preserving lease-owned compensation.
Journal marker undo state before removal so a post-removal revocation
cannot leave a restored plugin index without its original retention marker.
Punchcard-Session: crisp-summit-lantern-qk
* test(ui): honor retained session windows in mutation fixture
Punchcard-Session: crisp-summit-lantern-qk
* test(plugins): exercise archive limits with real ZIP entries
Punchcard-Session: coral-lantern-meadow-m8
* test(plugins): declare complete installed catalog fixtures
Punchcard-Session: coral-lantern-meadow-m8
* fix(gateway): retain required new-agent welcome on rejoin
Punchcard-Session: coral-lantern-meadow-m8
* fix(ui): preserve composer contrast across theme integration
Punchcard-Session: coral-lantern-meadow-m8
* fix(test): exclude checkout scratch from compiler inputs
Concurrent hook fixtures can disappear after namespace enumeration. Keep root scratch outside compiler cache preparation while retaining nested workspace and installed metadata invalidation.
Punchcard-Session: coral-lantern-meadow-m8
* fix(test): await native turn admission before interrupting
Punchcard-Session: coral-lantern-meadow-m8
* test(gateway): use client registry in approval fixture
Punchcard-Session: coral-lantern-meadow-m8
Let plugin themes declare bounded, self-contained SVG assets for avatar hats
and composer visitors. Capture artwork with each plugin generation, expose
content-hashed authenticated resource URLs, and rasterize images lazily in
the Control UI. Personal imports remain limited to built-in artwork IDs.
Package declared assets through the shared filesystem boundary while keeping
manifest declarations usable by native build and updater tooling. Preserve
existing pointer interactions, loaded-photo hats, palette notifications,
and transcript invalidation. Document validation and reload behavior.
Validation: focused protocol, manifest, Gateway, UI, packaging, native updater,
and extracted PR tooling tests; core/UI/scripts and affected test typechecks;
protocol generators, style lint, dead-code checks, assertion and line-cap
ratchets, formatting, docs links, and scoped-clean P1 review. Inspected
synthetic before/after captures are attached to the PR. Startup budget files
remain unchanged at 370300 B baseline and 370876 B enforcement.
Let built-in, plugin, and personal themes select five avatar hats. Preserve the lobster artwork colors and tune each new overlay to the existing tilted avatar band. Extend normalization, import-schema, and rendered-avatar coverage and document every hat ID.
Rebase onto the merged portable-theme change, retaining its explicit-field theme map and loaded-photo avatar coverage. Swift and Kotlin generation are already current. Startup JS measures 370,196 B locally; the approved 370,300 B baseline retains the 512 B growth and 64 B build-variance allowances, giving a 370,876 B enforcement limit, 700 B (0.19%) above current main.
Validation: 302 focused protocol, tool, UI, and performance tests; protocol generation chain; core/UI typechecks; UI style lint; changed-file oxlint and oxfmt; docs MDX checks; line-cap ratchet; production UI build and performance gate; inspected synthetic before/after avatar captures; scoped local review clean at P1.
* feat(ui): let themes drop the mascot, set status words, add critters and avatar hats
Portable theme definitions (built-in, plugin, personal) gain four optional
presentation fields. `mascot: "none"` swaps the lobster mark, favicon, login
gate, system avatar, About hero, and the working-row claw for a neutral prompt
mark drawn in the theme's primary color, and keeps the resident lobster and
lobster strangers off the composer ledge while ordinary visitors keep coming
under the unchanged Lobster visits toggle. `workingPhrases` replaces the
crustacean long-wait words with theme-authored text (up to 24, empty = silent).
`critters` adds catalog visitors (a penguin in a red fedora, and the fedora on
its own) to the ledge traffic at 2 % per critter per load without changing the
regulars' odds. `avatarHat` puts a fedora on an agent avatar about one page
load in six, seeded per agent and load.
The Gateway validates the fields in normalizeThemeDefinition and the TypeBox
schema, projects them onto plugin and personal descriptors, and the theme tool
imports them unchanged. The Control UI resolves branding through the theme
context, stamps data-theme-mascot and data-theme-avatar-hat on the root, and
rebuilds the favicon from computed colors when the mascot changes.
Startup JS grows by 2,467 B gzip (0.67 %); the baseline moves with it.
* fix(ui): complete portable theme branding and CI contracts
* fix(ui): satisfy core lint and the Linux startup budget
* fix(ui): give the startup JS baseline its allowance headroom
* feat(search): configure providers and verify search in Settings
* refactor(search): keep settings projections lint clean
* fix(search): bind provider tests to applied settings
* fix(search): preserve protocol order and complete CI coverage
* perf(search): defer model URL validation until needed
* fix(search): recheck authority before provider requests
* fix(search): include authority helper in wrapper closure
* test(qa): retain redacted cron run failure diagnostics
Keep the existing timeout and success predicate while preserving the complete redacted cron response in assertion output and retained proof. The original CI timeout remains unproven after bounded replay; this change improves diagnosis without claiming a causal flake repair.
* fix(search): project status from published auth state
Keep Search settings credential availability and native routing on lifecycle-published auth snapshots. Missing publication remains unavailable instead of reopening persisted auth on the Gateway request thread. Regression cases fail on the previous cold-state fallback; 71 focused and sibling cases, typechecks, lint, and independent review pass.
* fix: refresh stale Gateway stop policies before maintenance
Main recognized historical systemd timeouts, but maintenance could stop the
resident before repair, and Doctor and already-current or no-restart updates
could preserve stale computed policy. A published 2026.9.5 resident also retains
its startup shutdown budget after the unit changes.
Refresh owned policy through the existing definition-mutation and backup owners,
confirm daemon reload, preserve operator drop-ins, and retain restore/reload/input
retirement ordering. Share maintenance between update and Doctor, and warn when
a non-stopping refresh still has a short effective manager timeout.
Publish process-owned shutdown budgets and lifecycle write-custody facts. Reuse
the suspension owner and existing update deadline: stop when idle, warn and stop
at the deadline for ordinary work or unknown custody, and refuse only current
reported write custody with its exact owner phase. Reread native policy when the
new Gateway accepts shutdown without resetting its elapsed budget or watchdog.
Thanks @ezimerman for the installed-unit and shutdown evidence.
Fixes#153153. Refs #150898, #152879, #153017.
* fix: preserve the resident shutdown budget in Gateway status
The kernel request-context adapter copied host lifecycle control methods but
dropped the recorded shutdown-budget getter. Real Linux package proof observed
a 325-second startup budget while status omitted it, forcing maintenance onto
the legacy unknown-budget path.
Forward the live getter through the existing adapter without changing request
authority or adding another budget owner. Add a real-kernel registered-status
regression for short and adequate budgets; the corrected test fails on the
original adapter and passes with the forwarding line.
Refs #153153.
* test: control the Gateway shutdown clock consistently
Restore the explicit node:perf_hooks performance import for the run-loop regressions that retain their own fake-clock assertions. They must control the same monotonic clock as the production shutdown-budget owner. Keep the deadline assertions, timers, and production behavior unchanged.
* fix: preserve Doctor legacy reads during Gateway preflight
The stale-Gateway probe opened the canonical owner-lease database without
Doctor's existing legacy-catalog admission. With a built install and a busy
Gateway port, that read created WAL/SHM files and rejected a supported repair
before maintenance could stop the Gateway.
Carry the existing read admission through restart inspection to the lease owner.
Keep ordinary restart validation unchanged and preserve canonical artifacts.
Use synthetic port, build, and reachability facts in the regression fixture while
retaining real lease reads and byte-preservation assertions.
Refs #153153.
* refactor: keep Gateway maintenance owners within line limits
The L903 stop-policy repair exceeded the existing line-growth gate after
composition with current restart and service identity handling. Move request
upgrade policy into its existing request owner and service revalidation into
one sibling implementation without changing their behavior.
Preserve original request admission time and Doctor's statically primed
maintenance facade across package replacement. The bounded drain, recorded
custody-only refusal, warning policy, and native backup/reload ordering remain
unchanged. No options, schema changes, suppressions, or baseline growth.
Validation: 398 focused tests, core typecheck, line-growth ratchet, and fresh
Codex P1 review passed. Full changed checks continue on the frozen source.
* test: retain backup custody coverage through the archive walker
The rebase incorporated the maintained archive walker, but the L903 custody
regression still referenced the retired tar-create mock. Use the existing
walker mock bound to the real backup command without changing assertions or
production code.
Validation: 132 backup, migration, cron, coordinator, and suspension tests
passed. Fresh Codex P1 review is clean. Full changed checks continue.
* fix: preserve maintenance lifecycle and wrapper contracts
Doctor fixtures advertised a running native service without the matching
resident identity, effective policy, or lifecycle readiness response. Supply
those facts through the same RPC and native-query boundaries used by the real
maintenance owner, including fresh readiness without a resident budget.
Keep exact suspension assertions current with the additive custody category.
Install the model-acquisition fixture's manager after normal PATH setup so
startup and shutdown observe the same policy under the original deadlines.
Include the custody owner in the canonical PR-wrapper source inventory.
Move the unchanged Doctor inspection assertion and shared fixtures into their
existing policy/support owners to preserve the line-growth ratchet. Do not
change the bounded-deferral, warning, or reported-write-custody refusal policy.
* fix: preserve Stop ownership through shutdown budget refresh
An asynchronous systemd budget read could resume after Stop captured a
foreground updater and re-arm the hard-exit worker. Keep watchdog admission
with the run loop's current successor owner, and represent an absent cleanup
deadline with no process-cleanup budget.
Preserve foreground no-op service ownership and the full native allowance
after verified parking. Keep one fake clock for boundary tests, prepare
fixture operations before held scripts, and join cancelled fixture work
before the next case. Move unchanged budget cases into their support owner.
Retain the ruling that unknown custody cannot block an update and only
reported write custody may refuse maintenance. Preserve all existing test
assertions and limits. The full Linux changed gate, 790 focused Linux tests,
and a fresh P1 review passed; local host limitations are recorded in the PR.
* refactor(doctor): extract update-run admission from doctor-maintenance
* fix: preserve native policy and write custody during maintenance
* fix: keep shutdown integration within source and type gates
* fix(test): own survivor model endpoint before baseline setup
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
Reduce shared-state worker memory by keeping pure payload helpers and audit/approval validators in their narrow existing owners. Preserve validator identity, payload behavior, schema, authority, persistence and public contracts.
Current-main integration preserves the reviewed 18-file repair. Exact-head CI passed, including the canonical artifact build, typechecks, lint, worker import-boundary regression, speech-only/queued-speech delivery, outbound payload cases and all 352 Gateway handler cases. Fresh independent review reports no code or security findings; its timing-documentation follow-up is addressed.
Retained RSS measurements demonstrate the memory improvement. Separate CPU and status-latency repair/qualification remain open; this merge does not qualify or publish a release.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
* fix(ui): enable desktop access from Systems
Detect compatible host desktops before opt-in, preserve existing configuration, and enable access through the shared configuration and restart owner. Normalize Mac platform labels and explain macOS Remote Management access failures.
* test(ui): initialize Systems fixtures before navigation
* fix(update): hand foreground replacement to the CLI owner
Keep the Gateway available through validation, close its installed module
graph before publication, and let a fresh successor verify completion.
Route RPC updates through the existing detached updater and retire the
duplicate synchronous finalizer and unconsumed private activation receiver.
Require current foreground ownership throughout admission, preserve legacy
native handoffs, and resolve session aliases at the RPC boundary. Preserve
actual same-revision outcomes, join cancellation, and retain backups while
replacement verification is pending.
* fix(update): refresh verified Git target admission
* fix(update): preserve promoted Git runtime freshness
Preserve candidate runtime timestamps during Git activation so copy traversal
cannot invert the build and runtime postbuild stamps. Ordinary CLI commands
keep the validated runtime identity, while genuinely newer builds still trigger
postbuild.
Cover real Git inventory and filesystem promotion with fresh and stale runtime
stamps, plus the ordinary --version launcher path. Validate 218 owner and sibling
tests, the standalone two-case regression, changed-code gates, and P2 review.
* fix(protocol): accept existing update acknowledgment fields
Declare the acknowledgment fields already emitted by update.run, regenerate the Swift model, and validate captured handler replies against the canonical result schema. Clarify that acknowledgment is distinct from durable completion.
* fix(update): refuse foreground updates without respawn
Reject OPENCLAW_NO_RESPAWN foreground requests before handoff with actionable recovery guidance, and recheck the policy after acknowledgement and before parking. Preserve rejected foreground parking decisions in the existing helper activation fence, including refusals arriving after the notice timeout; managed-service notices retain best-effort behavior.
* fix(update): retain foreground stop before closure
* test(update): consolidate refusal and lifecycle fixtures
* refactor: remove canary launch argument mutation
* fix: hosted Stop bypasses foreground updater settlement
## What Problem This Solves
Connects supported installed OpenCode, Qwen Code, Pi, and Kilo Code agents to Models settings, setup, the shared model picker, and chat. Each CLI owns its sign-in; this does not discover every arbitrary ACP-compatible executable.
## User Impact
- Enabling an installed agent finishes at the configuration acknowledgement, without waiting for model discovery.
- Native model choices survive reload. Disabling an agent stops new discovery and turns without interrupting admitted work or deleting history.
- When optional chat restrictions cannot be enforced, an administrator can explicitly choose **Continue for this chat** to use the native app's permissions. Required sandboxing and other mandatory boundaries remain enforced; agent and global defaults do not change.
- Continue retries the original refused message and attachments once. A newer draft is preserved rather than sent under an earlier confirmation. Native assistant output streams before the final response.
- Explicit permission and sandbox preferences survive same-chat resets and expiry. Native consent remains incarnation-bound and is retired on reset, fork, runtime change, or stronger settings.
- Empty native discovery does not remove unrelated API models or trigger false model-fact changes, including repeated empty reads.
## Why This Change Was Made
OpenClaw owns model selection, consent, transcripts, session lifecycle, and run authority. ACPX owns transport, model inspection, session-scoped client permissions, and final prompt admission. This consumes upstream ACPX [#622](https://github.com/openclaw/acpx/pull/622), [#623](https://github.com/openclaw/acpx/pull/623), and [#624](https://github.com/openclaw/acpx/pull/624), rather than maintaining private enforcement wrappers in OpenClaw.
Both dependencies now use published **acpx 0.17.1**. The temporary Git-source pin and source-build approval are removed. Exact, dated dependency cooldown exclusions remain; installer integrity checks and script-disabled managed installation are unchanged.
The final reconciliation keeps catalog requests with the existing catalog schema owner, removes an unused type facade, and preserves native observation identity at the merge producer. Native policy calculation lives in the existing execution-policy module instead of importing the full agent runner during preflight. Runtime availability, implicit fallback, and explicit native pins stay with the execution selector; chat preflight checks only the known host-only runtime's permission restrictions. Tests exercise real catalog invalidation rather than retired UI wording or private metadata.
## Evidence
- **Published-driver upgrade:** the actual npm `openclaw@2026.9.4` updater installed the standard candidate package. Staging, migration rehearsal/continuation, canary, swap, and Doctor succeeded. The existing session retained its ID, model, runtime, workspace, label, and permissions. Restart was explicit after `update --no-restart`; automatic OS-service restart is not claimed.
- **Managed plugin and native continuity:** the unchanged candidate plugin archive installed through the repository's canonical local prepublish npm registry fixture with normal official-package provenance. Its ACPX dependency matched public npm 0.17.1, and its SDK resolved the installed candidate core—not the source checkout. A native conversation continued across a real Gateway process restart. Reset cleared consent; a stale lifecycle grant was rejected without peer effects; fresh explicit consent restored execution. The peer was a deterministic ACP subprocess, not paid-provider inference. The candidate OpenClaw plugin itself is not publicly released.
- **Telegram Test Server:** six real-user sends and two callback selections produced native-runtime confirmation edits. Four persisted snapshots verified native provider/model/runtime selection, `/reset` retention, restart retention, and unchanged agent defaults. Zero inference requests. The unchanged QA runner used Bun after a host Node/Undici error; the product Gateway used Node and the built candidate. Leases, credentials, processes, and listeners were cleaned up.
- **Real provider:** OpenCode through ACPX 0.17.1 returned the requested exact smoke response using `opencode/big-pickle`, an isolated HOME, and no API-key environment variables.
- **Real UI/Gateway:** a synthetic ACP subprocess refused the first message under Read Only, automatically retried it after confirmation, and streamed assistant chunks while its final response was still held. The recording contains one session creation and one automatic `chat.send`. [Inspected before/after screenshots](https://github.com/openclaw/openclaw/pull/150224#issuecomment-5748103787) are embedded in the PR discussion and originating chat; [earlier consent/retry captures](https://github.com/openclaw/openclaw/pull/150224#issuecomment-5743925304) remain available.
- **Regression proof:** repeated empty native discovery failed before the producer fix: captured API rows disappeared, and configured API rows emitted false invalidations. Both cases pass after repair. A successful empty provider refresh still removes its own obsolete rows; native cancellation, final-prompt authority, and API/native route separation remain covered.
- **Lightweight preflight:** the existing lazy-handler regression reproduced a speech-runtime import during basic `chat.send` validation. Moving the shared policy implementation fixed it without changing policy decisions: all nine moved function bodies and denial-prompt initializers have identical tokens. The registered consent-refusal test, 25 native-process cases, 18 model-ownership cases, 168 harness-selection cases, and seven relocated pure policy cases passed. The seven policy cases were moved, not added; the oversized selection module no longer needs its old size exception.
- **Single availability owner:** hosted creation/recovery regressions exposed a duplicate availability check in chat preflight. Removing it restores inherited and recovered native selections without inventing fixture runtimes or changing stored pins. Four title/initial-send selection paths, tombstone recovery, and refusal before message persistence passed unchanged. Temporary core-runtime fixture pins were removed; execution still rejects unavailable explicit native ownership rather than silently switching to an API provider.
- **Focused checks:** more than 700 cases passed across the repair rounds, including registered native-process execution, Gateway creation/recovery/admission/compaction/queued Stop, protocol exports, plugin boundaries, catalog ownership, Telegram callbacks, and 12 browser scenarios. The policy-cutover tree passed a full build and core production/UI/core-test typechecks; the subsequent availability-owner correction passed focused execution, production types, and lint. Protocol generation/Swift/Kotlin checks, assertion safety, and runtime import-cycle checks passed. Startup JS measured 364,119 bytes gzip against the 364,774-byte limit. The complete protocol schema's serialized bytes stayed identical through its module relocation. Size exceptions were pruned, not relaxed.
Upgrade, Telegram, and UI recordings bind the compiled `99ecb40e5d` artifact. Later ACP changes affect empty catalog observations, schema placement, metadata-only policy loading, and test fixtures. Consent decisions and denial prompts are unchanged; native execution and pre-admission refusal were rechecked after the policy move. The final main merge also carries upstream update-service planning changes; retained upgrade proof still exercises the unchanged published 2026.9.4 driver with explicit no-restart, not a new automatic-service-restart claim. Historical observations are not relabeled as reruns of a later commit. Final exact-head review and hosted checks remain separate gates.
### Disclosed limits
- Direct local `npm-pack` installation imported successfully but correctly lacked official-plugin storage trust for native execution. The normal npm installation through the canonical prepublish registry fixture closed that execution gap without trust overrides.
- An optional custom `--bundle-plugin acpx` distribution failed Darwin staging in `fsevents@2.3.3` (`binding.gyp` missing). No flags or packaging code were weakened; the standard candidate installation remained intact. That custom-distribution route is not claimed green.
- Matching-backup restoration and a post-upgrade external MCP tool call were not exercised.
## Compatibility and intended permission contract
The maintainer-requested behavior is explicit administrator-only, per-chat delegation to the native app when optional restrictions cannot be enforced—not silent global relaxation or a second OpenClaw enforcement system. Mandatory boundaries, live run authority, and consent retirement remain required. The accompanying SDK additions use the existing harness, transcript, and turn-stream owners; existing silent transcript-write defaults remain unchanged.
The candidate plugin declares `compat.pluginApi: >=2026.9.5`; supported installation uses that SDK floor rather than relying on the older general install hint. The package proof upgraded the host before installing the candidate plugin.
Existing API-key setup and explicit ACP commands remain available. No database schema migration is introduced. No package release, operator Gateway redeployment, or OpenClaw merge is included in this preparation.
## Contributor context
Sandbox recovery and upstream-first integration requested by @obviyus. [Discussion, implementation and verification](https://team.openclaw.ai/chat/roboclaw/dashboard/c522995c-e4fe-471a-848e-0d8fc44edd5c).
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(ui): reduce background traffic when opening chats
Use the compact automation inventory for sidebar Inbox alerts while retaining agent, update, running, and automatic-disable facts. Share pagination and snapshot recovery with the full editor inventory.
A registered browser regression preserves the same three alerts and two pages while reducing synthetic inventory responses from 403,177 to 17,794 bytes. Focused Gateway, UI, and browser proof plus selected checks pass.
* test(ui): align automation fixtures with compact inventory
Preserve full editor responses and ordered pagination cases while returning compact rows to Inbox and palette readers. Match the Gateway compact contract and drain the existing SQLite fixture lifecycle before deleting its directory.
* fix(automations): accept compact inventory attention facts
Reuse canonical field schemas for compact Gateway rows while retaining older protocol-v4 compact and full-list responses. Exercise actual projected rows through output validation and the Code Mode catalog.
* test: repair compact fixtures and rebalance Gateway typechecks
Preserve the nonempty automation fixture and concrete pacing discriminants. Move worker-environment tests between existing compiler graphs to restore the unchanged root limit, retaining every test, stripe, and concurrency setting.
* test(ui): persist mock config snapshots before reload
* test(ui): let plugin settings writes own mock config state
* fix(ui): leave space inside disclosure focus rings
* test(ui): match involving-me refreshes by query
* test(ui): consolidate config snapshot regression with main
* test(ui): retain snapshot hash coverage after consolidation
* test(ui): drive sidebar pagination refresh with fake time
* fix: restore Mac presence context and Canvas media playback
* refactor(gateway): separate the node session type contract
* test(codex): cover active presence in prompt fixtures
* test: include active computer in Codex context ordering
* test: supply snapshot auth-profile store
* test: align presence search and CLI prompt expectations
* fix(ui): keep attached context out of message text
Preserve bounded send-time reference snapshots separately from authored text through queued sends, retries, transcript display, and edit actions. Keep raw context inspectable behind a disclosure without changing its authority.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): complete context attachment CI coverage
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(state): align custody proof with worker acquisition
Apply the already-landed test correction from bfec65a2a0. Release the late competing host owner before awaiting the worker, while preserving authority checks, operation outcomes, and persisted-state assertions. Reproduces and repairs both failures in CI job 105859785996 without production changes or longer timeouts.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(ui): keep simulated history fling events contiguous
Drive the final contact movement, release, and initial inertia in one browser task so RPC latency cannot split the intended continuous gesture. Preserve total movement, stationary-touch coverage, omitted scrollend, and every-frame anchoring assertions.
* test(ui): avoid shadowing the momentum fixture parameter
* test: fix native shutdown and session fixture races
Keep Sparkplug compilation synchronous in test Node processes and propagate the shared argv policy to Vitest fork workers. This avoids a proven compiler/GC deadlock during process.exit without changing production shutdown, assertions, or deadlines. Join background session disk measurements before closing and handing off SQLite fixtures.
* test: fix compiler policy assertion and rebalance UI typechecks
Retain the independent Sparkplug shutdown policy when opting into Maglev. Split chat test roots into an appended shard without changing coverage or root limits.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Selecting a different Control UI theme applies its default interface/chat fonts and complete light/dark palette through the existing preference writer. Same-theme selections, passive updates and subsequent customization remain intact.
Preserve the documented downgrade requirement: remove or replace a configured ui.prefs.accent="theme" before downgrading to a hex-only Gateway. The maintainer accepted this tradeoff.
Verified with focused unit and browser coverage, independent review, and green exact-head CI.
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Keep generic text and workspace limits unchanged while allowing up to 2 MiB of UTF-8 HTML through the existing isolated preview path.
Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
* fix(plugins): preserve authored config through runtime load plans
* feat(judgments): add typed provider runtime and plugin SDK
* feat(plugins): add per-agent decision models
Add an opt-in decisionModel role for typed choices, scores, and boolean
probabilities, with global defaults and per-agent inheritance or disablement.
Keep provider lifecycle and prepared credentials host-owned, and expose
manifest-only decision choices separately from conversational model catalogs.
Adapt the provider foundation from #152237 to the decisions contract. Existing
configurations keep decision calls disabled until a model is selected.
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
* fix(plugins): complete decision inspection and preserve authored config
Expose optional decision-provider health through the Gateway wire schema
and generated native DTOs. Preserve the landed SecretRef prerequisite’s
identity behavior for unchanged activation plans. Move model mocks into
one private sibling factory without expanding the public helper surface.
Validation: 51 handler/protocol tests, 18 post-extraction tests, 52 runtime
and integration tests, generated protocol checks, and clean P0-P2 review.
The SDK surface-budget increase remains pending maintainer approval.
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
* perf(plugins): reduce decision overhead and unnecessary reloads
Keep one full provider input snapshot and an independent question rubric. Recognize decision-only catalog providers with the existing normalization policy, and reload plugins only for decision-model changes while preserving roster actions. Apply the approved SDK surface increment and behavior-neutral cleanup.
Validation: 58 runtime/config/loader tests, 610 Gateway regression/sibling tests plus 15 final catalog cases, full core typechecks, scoped lint and clean managed review. A 143155-attempt synthetic stress run settles all 18104 provider calls at max concurrency four.
* fix(plugins): preserve reload boundaries and decision test contracts
Materialize only present decision-selector leaves so Telegram account creation/removal retains its parent lifecycle action. Select UI controls by model role, preserve independent chat and decision catalogs in tests, remove an unused probe, and rebalance existing typecheck shards without raising their limits.
Validation: 588 reload tests, 58 shard/loader tests, 38 UI catalog tests, 9 browser tests, affected typechecks, unused-file scans, and clean managed review.
* test(ui): address model pickers by role in gateway flows
Disambiguate Primary from the new Decision picker in the real-Gateway catalog test, alias browser test, and Agents view assertions. Preserve draft and publication checks. Unit/browser/typecheck proof and managed review pass; real-Gateway execution follows on the integrated build.
* test(plugins): isolate runtime metadata and preserve shard headroom
Move the existing lazy-runtime metadata contract intact into its own focused module. Group CLI program tests with commands so newer main tests keep every typecheck shard within existing limits. No production changes or limit increases.
Validation: 57 tests, four typecheck graphs, canonical line guards against the CI main snapshot, targeted lint and clean managed review.
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
Preserve the reached update operation, recorded target and installation facts,
bounded redacted exception causes, and measured rollback outcomes in unexpected
failure reports. Capture and project these facts through the existing update
ledger, failure-fact, and public-identifier owners while preserving report consent,
preview custody, and recovery authority.
Optional diagnostic writes cannot replace the original failure or interrupt
recovery. Rollback summaries are recorded after complete service-definition
restoration. Existing JSON records gain optional nullable fields; SQLite remains
at v17 with no migration or new configuration.
Validated with focused regression suites, published 2026.9.4 updater and older-reader
compatibility proof, scoped-clean independent review, and exact-head CI (156 jobs,
zero failing required checks).
Related: #152193
Thanks to @bobbygaerd for the report.
* feat(usage): restore history and add creator breakdowns
Show the last 30 calendar days with complete server-side aggregates and creator filtering before row limits. Fix chart segment styling, remove redundant cost loading, and recover gracefully from incomplete usage and transient busy responses.
* test(usage): migrate browser proof to consolidated reports
Keep calendar, recovery, selected-control and provider convergence coverage aligned with server-owned daily costs and the bounded 5/10/20-second retry schedule.
* test(usage): complete single-report reconnect coverage
* fix(usage): align creator totals and ranges with selected days
Scope creator amounts and JSON exports to selected daily buckets. Carry the chart’s displayed calendar order into mouse and keyboard range selection, including empty days and filtered partial reports.
* fix(usage): preserve complete creator totals for day selections
Aggregate daily amounts and date-set session counts before the row limit. Keep off-page creators and distinct multi-day counts in the breakdown, headline, and JSON export while preserving explicit client row filters.
* style(usage): make cohort sorting and fixtures explicit
* fix(usage): hydrate context after creator filtering
Preserve saved context details for creator-filtered rows beyond the unfiltered page. Keep heavy reads bounded to emitted rows and retain fresh identity and visibility checks. Extend the owner integration matrix with red/green creator-filtered context and bounded-read coverage.
* test(cron): await cleanup and control manual timer ticks
Await the existing Gateway deletion operation instead of polling an arbitrary deadline. Keep the manually driven reaper suite from starting real two-second background ticks while archive workers settle. Preserve the existing session, owner and cleanup assertions; production scheduling is unchanged.
* fix(auth): await refresh settlement before retrying stale reads
Observe the existing OAuth producer after reader cleanup and before the single retry. Scope observation to current credential ownership and the canonical refresh generation, including inherited, fenced and portable peers; retire replaced claims without releasing remaining cleanup.
Reproduce pending/final publication races and ownership changes with controlled real-manager tests. Validate 75 focused cases, affected types and lint, and all three rebuilt Gateway quota-recovery scenarios. Independent review has no actionable P0-P2 findings.
* fix(usage): integrate worker discovery and selected exports
Keep inventory on the existing Usage worker without materializing archive payloads. Preserve async collection access and native cleanup for actual readers, and align export availability with loaded selected rows while retaining complete creator and daily JSON totals.
Validated 106 worker cases, 16 actual Usage RPC and worker entry cases, 57 UI cases, 22 cron cleanup cases, affected types and lint, and the runtime build. Fresh independent review has no actionable P0-P2 findings.
* fix(nodes): prevent orphaned work after cancellation and crashes
Keep hosted-worker capacity occupied until the process owner confirms descendant cleanup. Preserve completed turn results, peer isolation, and recoverable cleanup ownership when a replacement node host shuts down.
Allow the exact cancelled worker to settle its finishing acknowledgment without recreating publication or execution authority. Carry private lineage descriptors through the existing worker-start channel and package the sealed relay and anchor with the worker bundle.
* fix(nodes): preserve compatible starts across fleet upgrades
Keep released workers on their supported type-only startup and detached process-group owner. Select stronger relay ownership from the worker build capability.
Negotiate captured exec-policy support separately at node inventory so unsupported hosts show the existing update-required outcome before OpenClaw worker dispatch. Preserve remote-exec eligibility, current-authority checks, and cleanup operations.
Validated with released-worker startup and termination proof, registered inventory and dispatch regressions, focused sibling tests, changed checks, and independent review.
* test(nodes): keep current-worker fixtures eligible
Declare captured exec-policy support on the five current-node fixtures that exercise prepared dispatch, replay, authority revocation, and admission. Forward execution mode through the prepared fixture currentness callback independently of slot consumption.
Preserve assertions and deliberate legacy and remote-exec fixtures. All16 reproduced failures are fixed;243 tests across16 files and selected checks pass. Production, build, and dependency inputs are unchanged from97fe.
* ci: refresh node lifecycle merge validation
* fix(node-host): preserve cleanup evidence during worker recovery
Restore released process-group recovery after the leader exits. Record the selected transport before admission and retain exact-anchor root/lineage completion in a journal-owned companion table before releasing capacity after restart.
Use existing-file completion transactions so late cleanup cannot recreate removed state. Preserve public receipts, schema version and terminal retention; drain active modern workers before rollback to an older writer.
* fix(node-host): keep schema DDL annotation beside its call
Preserve the existing canonical first-use schema exception at the leading callsite recognized by the SQL guard. No SQL, guard rule or runtime behavior changes.
* fix(node-host): load journal writer before source helper cleanup
* test(macos): gate readiness recovery after owner failure
Hold the failed startup owner beyond an explicit waiter budget, then require a fresh health request and cleared failure state. Preserve the owner deadline and join cancellation cleanup. Production inputs are unchanged by this commit; disposable native proof runs on a separate task branch.
* fix(nodes): keep free capacity available during recovery
Bound observation of an unfinished cleanup anchor without releasing its reservation or escalating against it. Reconcile retained physical owners through status even when their requested turn has completed, preserving the turn outcome and requiring both lineage completion and tree extinction before freeing capacity.
* fix(nodes): recover capacity after bounded restart observation
Retain exact cleanup observation in the node supervisor after startup returns, publish freed capacity automatically after verified cleanup, and stop and join observation on shutdown. Share cancellation intent and preserve completed turn results.
* feat: let agents apply plugin and personal themes
Add declarative plugin theme metadata, descriptive theme list/get/set/import operations, and shared profile appearance writes. Plugin additions and palette updates follow hot reload without a Gateway restart. Preserve legacy local imports, bound profile authority, and atomic concurrent preference updates.
Refs #152449.
* fix: complete theme integration and defer catalog loading
* refactor: share theme mode validation and trim startup work
* chore: shrink theme assertion allowances
* test: await the initial Android gateway handoff
* fix(gateway): settle chat waits after user cancellation
* fix(gateway): preserve upstream cancellation settlement
* test(memory): preserve real worker deadline clocks
* test(daemon): preserve distinct replacement fixture identity
* test(transcripts): await completed automatic capture startup
Observe the real startup promise before exercising next-day account ownership, and always stop the service during cleanup. This removes the provider-entry timing race while preserving the ownership assertions.
Validate the repository before accepting worktree setup, preserve the suggested prompt while the operator selects a usable source, and consume stale pending intent when an existing session successfully binds its corrected worktree. Preserve session identities and transcript history during recovery.
* fix(meetings): load full transcripts and generate missing summaries
Automatically load all transcript pages, retain earlier speech, and generate missing notes through the shared summary owner with current request authority. Filter exact transcription artifacts at generation and capture while preserving meaningful speech, explicit prompts, and existing archive rows.
* fix(meetings): pause hidden readers and sync protocol models
* test(memory): drain transcript workers before fixture cleanup
Keep public GitHub issues, pull requests, commits, comments, images, and diffs readable beside chat in a resizable, tabbed reader. Preserve external navigation for modified clicks and explicit links.
Move GitHub transport and document mapping into the bundled plugin, and expose the passive reader through the shared plugin contract. Preserve operator plugin controls, managed-preview credential authority, anonymous detail reads, and existing host read-library behavior.
Bind responses to their requested resource, retain rapid reader opens in FIFO order, and cancel stale batches on close or session replacement. Add regression coverage and synchronize heartbeat and attachment tests with their actual completion boundaries.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(auth): retry model selection after concurrent credential refresh
* test(auth): verify fresh selection after stale reads
* feat(ui): show host and thread CPU in the compact status tile
Closes#152264
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: include CPU telemetry in native PR wrapper archives
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(gateway): keep retained assets available when cleanup races
Claim each evicted generation in a fresh private staging container so concurrent publishers cannot recursively delete the same tree. Record completed, already-pruned, and deferred cleanup outcomes without rejecting verified publication. Preserve cancellation and exact publication winner checks.
Adopt the existing maintainer repair from #152322 to resolve the recurring Windows pruning failure encountered by the compact CPU feature.
(cherry picked from commit b00bc04ce2)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* feat: show mentioned sessions in Involving me
Persist personal mention involvement separately from authorship. Add reversible per-person hide/show controls and resurface only for a fresh explicit mention.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: complete personal involvement integration and durability proof
Preserve session preparation identity, share personal menu requests with the Sessions page, retain canonical protocol and browser test owners, and prove preferences survive cold database reopen.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test: remove unused cold-reopen assignment
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test: repair SQLite worker checks after main integration
Remove duplicate promisify declarations introduced by main's Doctor merge and assert the idle-worker shutdown timer only during shutdown, not unrelated reclamation. All 81 affected tests pass and independent review is scoped-clean.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test: use the canonical persisted pin field in reopen proof
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): hide personal involvement actions on single-identity gateways
Gate rendering and action eligibility on the Gateway's multiple-identity capability across shared session menus. Refresh the gate on policy and context changes; cover both personal choices, compact menus, and the real browser flow.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* chore(workboard): refresh generated assets after session involvement integration
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(ui): await layout readiness in cron keyboard coverage
Wait for font metrics and the ResizeObserver-owned scroll clearance before keyboard focus. Preserve the strict overlap, reachability, keyboard and no-RPC assertions; no retries or timeout changes.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* chore(protocol): regenerate personal involvement method catalog
Retain main's independent environment-session methods and the personal involvement method in the canonical generated catalog.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: show pasted text as compact chat chips
* fix(ui): show pasted text excerpts above chat bubbles
* fix: synchronize upload provenance checks and assets
* test(ui): split outbox migration coverage
* chore(workboard): refresh assets after main rebase
* test(ui): distinguish loading status from copy feedback
* test(ui): include file origin in outbox capacity proof
* test(ui): await the complete disclosure line measurement
## What Problem This Solves
Repeated process polls crowded out useful progress. This larger change replaces separate channel and client decisions with shared activity preparation.
## Why This Change Was Made
This presentation state has one writer. Channels, web, terminal and native clients consume prepared facts; raw tool output remains available under details.
## User Impact
Routine polls stay quiet. Failures and approvals remain visible. Unmatched historical calls show an unknown outcome, not a permanent spinner.
## Evidence
- Real Telegram: repeated rows before; nine quiet polls, commentary, correct final result and draft cleanup after.
- Deliberate exit 2 remains visible without changing raw execution fields.
- Package build, focused channel/history/web/terminal tests and core/UI types pass.
- The same unchanged plugin compiles and runs against the released and candidate packages.
- Browser red/green: expanded item-only failures, blocked calls and unknown outcomes keep their prepared status live and after reload; 420 focused UI tests pass. Raw results remain unchanged.
- Reconnect testing includes main's fix in #151567 for the observed route loop.
- The maintainer explicitly waived native before/after screenshots and manual native UI verification for this PR. Hosted native tests remain required; device UI behavior is not claimed.
| Before | After |
| --- | --- |
|  |  |

Web expanded tool details (actual browser, cropped):
| Before: false completion | After: preserved outcome |
| --- | --- |
|  |  |
## Compatibility
Optional chat/task history activity; no protocol-version, user-config, store or migration change. Released plugin callbacks remain functional. Updated bundled adapters opt into prepared items. The shared SDK exports and two updated Slack progress snapshots are approved.
## Consumers
Channels, web, terminal and native adapters share the prepared facts.
## Invalidation
Existing run ownership, final-delivery fences and history refresh rules remain.
## Tests
Failure, approval, privacy, history, plugin-upgrade and authority regressions remain. File-size repairs move existing tests without removing their assertions.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>