Commit graph

232 commits

Author SHA1 Message Date
Peter Steinberger
91b8f103cb
refactor: retire the TaskFlow Webhooks plugin (#158225)
* refactor: retire the TaskFlow Webhooks plugin

* fix(doctor): preserve restrictive plugin allowlist retirement

* test(update): prove sole plugin policy survives retirement

* chore(webhooks): remove retired plugin label mapping

* test(plugins): consolidate retired plugin warning cases

* fix(doctor): preserve permitted plugins during retirement

* test(update): verify preserved plugin policy and evidence

* fix(testing): retain upgrade policy publisher dependencies

* test(update): isolate inherited channel discovery state

* ci: refresh Webhooks checks after main QA reference repair
2026-09-25 20:29:15 -07:00
Peter Steinberger
54a986072f
docs(plugins): remove obsolete Gateway restart guidance (#146516)
* docs(plugins): remove obsolete Gateway restart guidance

* docs(plugins): simplify apply hints and update Session Share guidance
2026-09-12 16:48:13 -07:00
Vincent Koc
2393e17f27
docs: fix one-way and absolute links across cli, tools, gateway, and channels (#143157)
* docs: fix one-way and absolute links across cli, tools, gateway, and channels

Closes the open `link`-kind audit findings filed against docs/cli/,
docs/tools/, docs/gateway/ and docs/channels/.

- Convert 21 absolute `https://docs.openclaw.ai/...` links to root-relative
  paths on protocol, clients, external-apps, embedding, protocol/transport,
  and zaloclawbot so local previews and versioned builds resolve them.
- Add the missing reverse link for one-way Related entries, using the house
  bullet or `<Card>` shape each page already uses.
- Link terms that were named but not linked: SecretRef and
  `gateway.trustedProxies` on sms, the meeting providers on transcripts,
  `openclaw models`/`openclaw agent` on infer, Talk on tts, `/tools/invoke`
  on the gateway index.
- Give distinct link text to the two "macOS platform notes" links on
  gateway/troubleshooting.
- Point the IRC workspace `.env` link at the section anchor rather than the
  Security index.
- Add Related sections to pages that had none (sms, transcripts, promos,
  progress-card, onboard, access-groups, concepts/memory, operator-scopes).
- Add the 28 zh-CN glossary sources the new list-item link labels require,
  each inserted beside a related existing term.

No anchor targets change. `pnpm check:docs` is green.

* docs: link devices and doctor inline on pairing, and trusted proxy auth from the security index

Completes two findings that were only half-applied: r3-1324 asked for the
sibling commands to be linked inline on /cli/pairing, and r3-1579 lists the
security index among the four pages that should link back to
/gateway/trusted-proxy-auth.

* docs: match each Related list's existing separator style

The added bullets used an em dash in lists whose existing entries separate
the label and gloss with a hyphen. Normalized 11 files so each list stays
internally consistent.

* docs: correct four inaccurate Related-link descriptions from review

ClawSweeper found that several glosses I wrote misdescribed their targets.
Verified each against the destination page and corrected:

- ask_user is for non-secret questions; its own reference says never to answer
  it with a credential, so the secrets-page gloss now points credential entry
  at the masked secrets tool (P1).
- OpenClaw sandbox policy does not wrap ACP harness execution
  (tools/acp-agents/delivery.md), so the ACP backlink now names the separate
  boundary instead of implying coverage (P2).
- Code Mode is a QuickJS-WASI JavaScript/TypeScript orchestration surface, not
  something built on the xAI code_execution tool documented on that page (P2).
- openclaw qr emits a mobile-node bootstrap payload, not a channel DM pairing
  code, on both the pairing and devices pages (P2).

Audited the other 100 descriptions for the same class of error and fixed six
more: OpenShell is a managed sandbox backend rather than a surface the sandbox
bounds (3 pages); a Cloud Workers gloss claimed sandbox settings apply when its
managed workspace is explicitly not an OS sandbox; openclaw promos lists and
claims promotional offers; the 1Password gloss overstated the plugin relation;
and the progress-card bullets no longer assert undocumented dashboard rendering.

* docs: correct three more link descriptions and audit every remaining gloss

Addresses the second review round, and then re-checks the whole set rather
than only the three reported.

Reported:
- openclaw attach launches Claude Code with a scoped Gateway MCP grant
  (cli/attach.md:2); it does not attach a terminal to a running session.
  Fixed on cli/mcp.md and cli/tui.md.
- Bare openclaw setup opens an interactive system-agent chat and falls
  through to guided onboarding on a fresh system (cli/setup.md:12), so
  calling it 'the non-interactive setup command' was wrong.
- Access groups have no pairing prerequisite: a group 'grants nothing by
  itself' and only matters where an allowlist references it. Dropped the
  invented sequencing claim.

Found by auditing the remaining descriptions against each target's own
summary:
- openclaw worker is explicitly 'not a general-purpose command for manual
  worker registration' (cli/worker.md:13); reworded on cloud-workers and
  protocol/handshake.
- /reference/rpc documents RPC adapters for external CLIs, not worker RPC
  method shapes; repointed to /gateway/protocol/rpc-methods.
- stable-https-url gives a tailnet-only URL via Tailscale Serve, which the
  iOS and Android glosses omitted.
- Tightened health, logs, sandbox, resume, infer, dashboard, diffs,
  prometheus, music-generation, subagents, pairing, audit, tools-invoke,
  configuration-reference, and the three goal glosses to match their pages
  instead of asserting relationships no page documents.

One glossary source added for the new label.

* docs: attribute goal reads and updates to the dedicated goal tools

The session-tool page documents session discovery, messaging, lifecycle, and
orchestration tools; goal operations use get_goal, create_goal, and
update_goal instead (docs/tools/goal.md:132-149). I corrected the other three
goal glosses last round and missed this one.

---------

Co-authored-by: Vincent Koc <vincent@openclaw.org>
2026-09-10 07:40:16 +09:00
Vincent Koc
c83277b970
docs: correct verified accuracy defects in CLI, tools, and automation pages (#143179)
* docs: correct verified accuracy defects in CLI, tools, and automation pages

Resolve the open `accuracy` audit findings for docs/cli/, docs/tools/ and
docs/automation/. Every claim was checked against the implementation before
the prose was touched; findings the source contradicted are left unchanged and
rebutted in the PR body.

Factual corrections (docs disagreed with code):

- onboard: Z.AI defaults are glm-5.3 (coding) and glm-5.2 (general), not
  glm-5.2/glm-5.1 (extensions/zai/model-definitions.ts, openclaw.plugin.json).
- sessions: the cleanup --json example printed a sessions.json store path, but
  both JSON exits map storePath through resolveSqliteTargetFromSessionStorePath
  (src/commands/sessions-cleanup.ts, src/config/sessions/cleanup-result.ts).
- diffs: `plugins install diffs` resolved to an unrelated npm package; the
  plugin is external, not bundled (extensions/diffs/package.json).
- ollama-search: a bare "OLLAMA_API_KEY" string is a literal key, not env
  indirection (src/config/types.secrets.ts).
- minimax-search: the region list contradicted its own opening condition and
  merged two tiers (extensions/minimax/src/minimax-web-search-provider.runtime.ts).
- imap: addressTokens is a per-account key (extensions/imap/src/config.ts).
- thinking: GLM-5.3 is a second Z.AI exception (extensions/zai/provider-policy-api.ts).
- video-generation: buffer-backed videoToVideo also covers fal reference-to-video
  (src/video-generation/live-test-helpers.ts).
- slash-commands: the missing third source is skill commands
  (src/auto-reply/commands-registry-list.ts).
- cron: `cron` is the registered command and `automations` its alias
  (src/cli/cron-cli/register.ts).
- setup: add the real --classic and --agent-name flags to the Options table
  (src/cli/program/register.setup.ts).
- path: file-slot wildcard rejection exits 2 (extensions/oc-path/src/cli.ts).

Version scope added only where a release could be cited: 2026.8.1 (heartbeat
task migration, inferred commitments, artifact-area staging), 2026.4.29 (owner
bootstrap), 2026.4.26 (Hunter Alpha), 2026.3.31 (nodes.run). Elsewhere the
time-relative wording is replaced with the verified current behaviour rather
than a guessed version.

* docs(swarm): keep the limits-and-roadmap anchor after the heading rename

docs/AGENTS.md requires existing published heading ids to stay stable. The
rename from 'Limits and roadmap' to 'Limits' changed the generated fragment,
so add an explicit <a id="limits-and-roadmap" /> stub above the heading.
parseDocsDocument now reports both ids with no collisions.
2026-09-09 23:57:06 +09:00
Vincent Koc
588436b7ea
docs: close reciprocal-link gaps in concepts, nodes, and platforms (#143022)
* docs: close reciprocal-link gaps in concepts, nodes, and platforms

Link-only fixes from the docs link audit. Every change adds or retargets a
link; no surrounding prose was rewritten.

- Replace the redirect-only /plugins target with the real /tools/plugin page
  in the memory-architecture config table.
- Add missing back-links so pages listed under Related link back: model
  providers, context engines, agent runtimes, session tools, streaming,
  node troubleshooting, computer use, and the nodes hub.
- Give Related sections to three pages that had none: session search,
  the personal agent benchmark pack, and EasyRunner.
- Link the macOS Skills detail page from the macOS hub task table.
- Link each workspace template from its entry in the workspace file map.

The memory-architecture table is re-aligned by scripts/format-docs.mts
because one cell changed width; no cell content changed but that one link.

* docs: point the workspace tools template at the live AGENTS.md section

TOOLS.md is a retirement notice, not a template; the local tool
conventions template is the `## Tools` section of the AGENTS.md
template. Addresses the ClawSweeper P3 finding.

---------

Co-authored-by: Vincent Koc <vincent@openclaw.org>
2026-09-09 19:10:07 +09:00
Vincent Koc
e8ffd3cf09
docs: replace private paths and document the ClawHub docs source (#140227)
Docs governance and publish-hygiene pass over docs/AGENTS.md and the
pages its rules cover.

- Replace every `~/Projects` operator path in docs/ with a neutral
  placeholder. 38 occurrences across 13 pages, including the private
  repo path `~/Projects/manager/skills`. `docs/AGENTS.md` forbids local
  paths, and its own Internal Docs bullet named one.
- Record the placeholder convention in the Published Link Rules bullet
  that bans local paths.
- Document the ClawHub docs source in Source Ownership: this repo holds
  no `/clawhub/**` page sources even though `docs/docs.json` lists them,
  so a local preview and `pnpm docs:check-links` report those routes as
  missing until `OPENCLAW_DOCS_SYNC_CLAWHUB_REPO` points at a ClawHub
  checkout.
- Drop the Strict-STE hard violation rate on `docs/AGENTS.md` from 18
  hard (3.4 per 100 words) to 0 by splitting semicolon sentences and
  sentences over 20 words, and by naming the actor in passive
  sentences. No rule changes meaning.
- Convert the Maturity Scorecard paragraph to a bulleted list, matching
  every other section.
- `docs/prose.md`: name v2026.8.1 as the release that removed OpenProse,
  and explain the `--agent codex` flag and the third-party skills CLI.
- Link `/prose` from `tools/skills` and `tools/slash-commands`.
- `docs/docs_map.md`: correct the summary to describe the stub, and drop
  the H1 that repeated the frontmatter title.

Closes audit findings: r3-0734, r3-0736, r3-0907, r3-0910, r3-2277,
r3-2278, r3-2285, r3-2286, r3-2287, r3-2288, r4-clawhub-0001

Partially addresses r3-0906 (private path removed; publish-tree
exclusion left as a follow-up). Not addressed: r3-0909 (generator
change).
2026-09-06 23:48:33 +08:00
Peter Steinberger
bd8b3c806d
fix(plugins): trace trust refusals and repair legacy provenance (#138746)
* fix(plugins): trace trust refusals and repair legacy provenance

* fix: keep trust diagnostics within their owner boundaries

Keep remote Gateway failures independent of local service inspection and contain best-effort diagnostic errors. Remove ambient registry-path inference from the trust formatter so unavailable provenance remains unknown. Cover ordered recovery, remote tunnels, and portable diagnostic paths.

* fix(daemon): distinguish unavailable service facts from absence

Decode LaunchAgent definitions with the native parser and preserve recorded command and environment bytes. Strict service inspection now rejects unknown definitions and requires native absence evidence before reporting no installed service; non-strict environment-path recovery remains available.

* test(daemon): decode generated LaunchAgents on all CI hosts

Use the existing native decoder fixture seam for the real install-plan regeneration test, preserving its environment and SecretRef assertions. Group strict multiline parsing under one condition to satisfy lint without changing reader behavior.

* fix(daemon): reject unresolved Windows service assignments

Require literal, case-insensitive Windows environment facts for strict service inspection, preserving whitespace and escaped percent values. Keep unresolved expansion and unsupported shell syntax unknown without exposing raw service failures. Preserve lenient recovery and adapt real LaunchAgent update fixtures to the native decoder boundary on Linux.

* docs(gateway): document native service definition recovery
2026-09-04 20:28:14 -07:00
weiqinl
1af9bacfa0
fix(config): align plugin reload guidance (#136740)
Closes #136710

## Problem

`config.schema.lookup` reported `reloadKind: "hot"` for `plugins.entries.*.enabled`, but its schema help said a restart was required. Several plugin docs repeated the stale restart guidance.

## Product path

```bash
openclaw gateway call config.schema.lookup \
  --params '{"path":"plugins.entries.<plugin>.enabled"}' \
  --json
```

## Root cause

Plugin enablement moved to the in-process plugin reload path, but the older help and lifecycle docs did not move with it. The generic plugin reload rule is hot. An active plugin can still declare a restart-triggering prefix, and `gateway.reload.mode: "off"` still disables config reload.

## Fix

- Describe the default hybrid reload mode and plugin-specific restart exception in schema help.
- Align the generic plugin lifecycle docs with the existing runtime behavior.
- Move the regression from a copy-quality test into the real Gateway WebSocket lookup boundary.
- Keep reload planning, configuration defaults, schemas, and protocol behavior unchanged.

## Compatibility

This is a wording and regression-test repair. It does not change configuration, defaults, reload planning, stored data, or the Gateway protocol.

## Proof

- Current-main red: [Blacksmith run 33714053532](https://github.com/openclaw/openclaw/actions/runs/33714053532) returned `reloadKind: "hot"` beside help containing `(restart required)` for two wildcard plugin paths.
- Regression red: [Blacksmith run 33714561306](https://github.com/openclaw/openclaw/actions/runs/33714561306) failed the new WebSocket lookup test on the stale help.
- Exact-tree green: formatter, `pnpm docs:list --headings`, the WebSocket regression, 24 help-quality tests, and three plugin reload sibling tests passed in [Blacksmith run 33715965706](https://github.com/openclaw/openclaw/actions/runs/33715965706).
- Live green: [Blacksmith run 33716204027](https://github.com/openclaw/openclaw/actions/runs/33716204027) returned matching `hot` metadata and hybrid-mode help for the reported path and a second wildcard path.
- Exact-head Autoreview passed with no P0 findings.

## Credit

This repair preserves @LiuwqGit's original commit and intent.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-03 10:34:18 +05:30
Peter Steinberger
7eebd6d4a6
docs(hooks): clarify setup and execution contracts (#130734) 2026-08-26 23:12:06 -07:00
Jesse Merhi
47442197a1
feat(ui): review install policy warnings (#120900)
* feat(ui): review install policy warnings

* fix(ui): keep install feedback on runtime plugin
2026-08-15 13:07:02 +10:00
Jesse Merhi
bf40269cb7
feat(security): require acknowledgement for policy warnings (#116489) 2026-08-15 03:58:45 +10:00
Peter Steinberger
e45a9460ce
docs: repair spellcheck and anchor drift (#122960)
* docs: repair spellcheck and anchor drift

* docs: satisfy markdown anchor lint
2026-08-12 20:50:56 -07:00
Jesse Merhi
d90e47783d
fix(plugins): remove local dependency denylist (#101813) 2026-08-11 12:21:29 +10:00
Peter Steinberger
b99c507ce6
docs(plugins): include Agent Plugins in the plugins page read-when hints (#120323) 2026-08-07 12:35:03 -07:00
Peter Steinberger
f4387b7a5e
feat(plugins): support the Agent Plugins bundle format (#120115)
* feat(plugins): support the Agent Plugins bundle format

* docs(plugins): document the Agent Plugins bundle format

* test(agents): preserve agent bundle runtime discovery

* fix(plugins): isolate Agent Plugins data-dir failures and align MCP support reporting

* docs(plugins): list Agent Plugins in the canonical plugin-format guides

* fix(plugins): gate Agent Plugins detection on schema, pure inspection, root-relative cwd

* fix(plugins): record Agent Plugins data-dir ownership explicitly

* docs(plugins): cover Agent Plugins in the CLI install detection guide

* fix(plugins): carry Agent Plugins data-dir and transport contracts through external MCP projections
2026-08-07 02:55:08 -07:00
Brandon
bfc99c97c5
docs(plugins): clarify hook runtime activation (#77629)
* docs(plugins): clarify hook runtime activation

* docs(plugins): correct hook startup activation guidance

* docs(plugins): clarify hook runtime activation

* docs(plugins): clarify hook runtime startup

Co-authored-by: Brandon Zarnitz <bzarnitz13@gmail.com>

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-07-30 01:02:31 +08:00
Vito Cappello
cd1ab40632
fix: gateway boots when a configured plugin payload is broken (#110239)
* fix: quarantine broken plugins during gateway startup

* fix(plugins): preserve degraded boot on package read errors

* fix(gateway): emit quarantine diagnostic once

* fix(gateway): refresh plugin quarantine every boot

* fix(gateway): harden plugin payload quarantine

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>

* fix(ci): satisfy plugin quarantine checks

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>

---------

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 03:50:50 +01:00
Jesse Merhi
00364ee777
improve: warn before non-ClawHub plugin installs (#102197)
Merged via squash.

Prepared head SHA: e08d9e737d03f7bde665caa34ecf1c841aea97ba
Co-authored-by: jesse-merhi <79823012+jesse-merhi@users.noreply.github.com>
Co-authored-by: jesse-merhi <79823012+jesse-merhi@users.noreply.github.com>
Reviewed-by: @jesse-merhi
2026-07-15 03:25:36 +10:00
Peter Steinberger
f7d7148cf0
docs: rewrite published docs grounded in current source (#100142)
Source-grounded rewrite of 529 published docs pages with per-unit information-loss verification: 1,713 factual corrections cited to src/**, generated surfaces regenerated, frontmatter titles preserved for i18n, release notes pages untouched. All docs gates green.

Closes #100141
2026-07-05 00:32:47 -04:00
Joe Pahuchi
b27ac78d4d
fix(plugins): make empty-allowlist actionable for new users (#78105)
* fix(plugins): make empty-allowlist warning actionable for first-time users

* fix(plugins): make empty-allowlist warnings actionable

* fix(plugins): make empty-allowlist warnings actionable

* fix(plugins): make empty-allowlist actionable for new users

---------

Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com>
2026-06-23 04:41:40 +00:00
Sally O'Malley
e6ffcf7362
docs: clarify before_install hook scope (#92766)
Signed-off-by: sallyom <somalley@redhat.com>
2026-06-13 16:54:04 -04:00
Josh Avant
154f439c81
Add operator install policy and remove dangerous-code install scanners (#89516)
* feat: add operator install policy

* test: cover plain-file plugin install code

* fix: preserve locationless install policy findings

* refactor: remove install-time plugin scanner

* test: remove stale plugin install helper

* fix: preserve before-install builtin scan type

* fix: preserve plugin dependency denylist

---------

Co-authored-by: Mainframe <mainframe@MainfraacStudio.localdomain>
2026-06-03 14:17:29 -07:00
Peter Steinberger
4c33aaa86c
refactor: unify OpenAI provider identity (#88451)
* refactor: unify OpenAI provider identity

* refactor: move legacy oauth sidecar doctor helpers

* test: align OpenAI fixtures after rebase

* test: clean OpenAI provider unification

* fix: finish OpenAI provider cleanup

* fix: finish OpenAI cleanup follow-through

* fix: finish OpenAI CI cleanup
2026-05-31 00:29:44 +01:00
Peter Steinberger
d92b3b5cc2
refactor: unify OpenAI provider identity
Refactor OpenAI provider identity so OpenAI remains the canonical provider for API-key and OAuth-backed flows while legacy openai-codex state is doctor/migration-only.

Keeps OpenAI Codex Responses as an API/transport class rather than a provider identity, moves auth aliases through providerAuthAliases, updates doctor repair sequencing for old auth/profile state, and refreshes tests/docs around the canonical OpenAI behavior.
2026-05-30 11:48:41 +02:00
Peter Steinberger
4491232874
fix: resolve compatible npm plugin versions
* fix: resolve compatible npm plugin versions

* fix: satisfy plugin install lint

* fix: refresh plugin install tests on latest main
2026-05-28 23:20:32 +01:00
fuller-stack-dev
40fa750b4f
docs: explain bundled plugin npm override 2026-05-26 23:51:53 +01:00
Peter Steinberger
99a1107b61
docs: absorb hook and subagent guidance PRs 2026-05-23 09:47:37 +01:00
Peter Steinberger
15b0d43412
docs: clarify plugin gateway auto-restart 2026-05-16 17:11:53 +01:00
Kevin Lin
6a23e26a27
docs: consolidate plugin install docs (#81167)
* docs: consolidate plugin install docs

* docs: align plugin getting started page

* snap

* docs: add reusable audit viewer tooling

* docs: add audit viewer doc mode

* docs: add audit viewer diff mode

* docs: strengthen plugin docs audit coverage

* docs: preserve plugin scan order reference

* docs: resolve plugin audit coverage gaps

* docs: strengthen audit line mappings

* docs: narrow plugin docs refactor scope

* docs: preserve plugin audit facts

* docs: keep audit skill local

* docs: remove audit skill from pr

* fix: satisfy plugin scan lint

* docs: address plugin docs review
2026-05-13 13:17:39 -07:00
Peter Steinberger
694ca50e97
Revert "refactor: move runtime state to SQLite"
This reverts commit f91de52f0d.
2026-05-13 13:33:38 +01:00
Peter Steinberger
f91de52f0d
refactor: move runtime state to SQLite
* refactor: remove stale file-backed shims

* fix: harden sqlite state ci boundaries

* refactor: store matrix idb snapshots in sqlite

* fix: satisfy rebased CI guardrails

* refactor: store current conversation bindings in sqlite table

* refactor: store tui last sessions in sqlite table

* refactor: reset sqlite schema history

* refactor: drop unshipped sqlite table migration

* refactor: remove plugin index file rollback

* refactor: drop unshipped sqlite sidecar migrations

* refactor: remove runtime commitments kv migration

* refactor: preserve kysely sync result types

* refactor: drop unshipped sqlite schema migration table

* test: keep session usage coverage sqlite-backed

* refactor: keep sqlite migration doctor-only

* refactor: isolate device legacy imports

* refactor: isolate push voicewake legacy imports

* refactor: isolate remaining runtime legacy imports

* refactor: tighten sqlite migration guardrails

* test: cover sqlite persisted enum parsing

* refactor: isolate legacy update and tui imports

* refactor: tighten sqlite state ownership

* refactor: move legacy imports behind doctor

* refactor: remove legacy session row lookup

* refactor: canonicalize memory transcript locators

* refactor: drop transcript path scope fallbacks

* refactor: drop runtime legacy session delivery pruning

* refactor: store tts prefs only in sqlite

* refactor: remove cron store path runtime

* refactor: use cron sqlite store keys

* refactor: rename telegram message cache scope

* refactor: read memory dreaming status from sqlite

* refactor: rename cron status store key

* refactor: stop remembering transcript file paths

* test: use sqlite locators in agent fixtures

* refactor: remove file-shaped commitments and cron store surfaces

* refactor: keep compaction transcript handles out of session rows

* refactor: derive transcript handles from session identity

* refactor: derive runtime transcript handles

* refactor: remove gateway session locator reads

* refactor: remove transcript locator from session rows

* refactor: store raw stream diagnostics in sqlite

* refactor: remove file-shaped transcript rotation

* refactor: hide legacy trajectory paths from runtime

* refactor: remove runtime transcript file bridges

* refactor: repair database-first rebase fallout

* refactor: align tests with database-first state

* refactor: remove transcript file handoffs

* refactor: sync post-compaction memory by transcript scope

* refactor: run codex app-server sessions by id

* refactor: bind codex runtime state by session id

* refactor: pass memory transcripts by sqlite scope

* refactor: remove transcript locator cleanup leftovers

* test: remove stale transcript file fixtures

* refactor: remove transcript locator test helper

* test: make cron sqlite keys explicit

* test: remove cron runtime store paths

* test: remove stale session file fixtures

* test: use sqlite cron keys in diagnostics

* refactor: remove runtime delivery queue backfill

* test: drop fake export session file mocks

* refactor: rename acp session read failure flag

* refactor: rename acp row session key

* refactor: remove session store test seams

* refactor: move legacy session parser tests to doctor

* refactor: reindex managed memory in place

* refactor: drop stale session store wording

* refactor: rename session row helpers

* refactor: rename sqlite session entry modules

* refactor: remove transcript locator leftovers

* refactor: trim file-era audit wording

* refactor: clean managed media through sqlite

* fix: prefer explicit agent for exports

* fix: use prepared agent for session resets

* fix: canonicalize legacy codex binding import

* test: rename state cleanup helper

* docs: align backup docs with sqlite state

* refactor: drop legacy Pi usage auth fallback

* refactor: move legacy auth profile imports to doctor

* refactor: keep Pi model discovery auth in memory

* refactor: remove MSTeams legacy learning key fallback

* refactor: store model catalog config in sqlite

* refactor: use sqlite model catalog at runtime

* refactor: remove model json compatibility aliases

* refactor: store auth profiles in sqlite

* refactor: seed copied auth profiles in sqlite

* refactor: make auth profile runtime sqlite-addressed

* refactor: migrate hermes secrets into sqlite auth store

* refactor: move plugin install config migration to doctor

* refactor: rename plugin index audit checks

* test: drop auth file assumptions

* test: remove legacy transcript file assertions

* refactor: drop legacy cli session aliases

* refactor: store skill uploads in sqlite

* refactor: keep subagent attachments in sqlite vfs

* refactor: drop subagent attachment cleanup state

* refactor: move legacy session aliases to doctor

* refactor: require node 24 for sqlite state runtime

* refactor: move provider caches into sqlite state

* fix: harden virtual agent filesystem

* refactor: enforce database-first runtime state

* refactor: rename compaction transcript rotation setting

* test: clean sqlite refactor test types

* refactor: consolidate sqlite runtime state

* refactor: model session conversations in sqlite

* refactor: stop deriving cron delivery from session keys

* refactor: stop classifying sessions from key shape

* refactor: hydrate announce targets from typed delivery

* refactor: route heartbeat delivery from typed sqlite context

* refactor: tighten typed sqlite session routing

* refactor: remove session origin routing shadow

* refactor: drop session origin shadow fixtures

* perf: query sqlite vfs paths by prefix

* refactor: use typed conversation metadata for sessions

* refactor: prefer typed session routing metadata

* refactor: require typed session routing metadata

* refactor: resolve group tool policy from typed sessions

* refactor: delete dead session thread info bridge

* Show Codex subscription reset times in channel errors (#80456)

* feat(plugin-sdk): consolidate session workflow APIs

* fix(agents): allow read-only agent mount reads

* [codex] refresh plugin regression fixtures

* fix(agents): restore compaction gateway logs

* test: tighten gateway startup assertions

* Redact persisted secret-shaped payloads [AI] (#79006)

* test: tighten device pair notify assertions

* test: tighten hermes secret assertions

* test: assert matrix client error shapes

* test: assert config compat warnings

* fix(heartbeat): remap cron-run exec events to session keys (#80214)

* fix(codex): route btw through native side threads

* fix(auth): accept friendly OpenAI order for Codex profiles

* fix(codex): rotate auth profiles inside harness

* fix: keep browser status page probe within timeout

* test: assert agents add outputs

* test: pin cron read status

* fix(agents): avoid Pi resource discovery stalls

Co-authored-by: dataCenter430 <titan032000@gmail.com>

* fix: retire timed-out codex app-server clients

* test: tighten qa lab runtime assertions

* test: check security fix outputs

* test: verify extension runtime messages

* feat(wake): expose typed sessionKey on wake protocol + system event CLI

* fix(gateway): await session_end during shutdown drain and track channel + compaction lifecycle paths (#57790)

* test: guard talk consult call helper

* fix(codex): scale context engine projection (#80761)

* fix(codex): scale context engine projection

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* chore: align Codex projection changelog

* chore: realign Codex projection changelog

* fix: isolate Codex projection patch

---------

Co-authored-by: Eva (agent) <eva+agent-78055@100yen.org>
Co-authored-by: Josh Lehman <josh@martian.engineering>

* refactor: move agent runtime state toward piless

* refactor: remove cron session reaper

* refactor: move session management to sqlite

* refactor: finish database-first state migration

* chore: refresh generated sqlite db types

* refactor: remove stale file-backed shims

* test: harden kysely type coverage

# Conflicts:
#	.agents/skills/kysely-database-access/SKILL.md
#	src/infra/kysely-sync.types.test.ts
#	src/proxy-capture/store.sqlite.test.ts
#	src/state/openclaw-agent-db.test.ts
#	src/state/openclaw-state-db.test.ts

* refactor: remove cron store path runtime

* refactor: keep compaction transcript handles out of session rows

* refactor: derive embedded transcripts from sqlite identity

* refactor: remove embedded transcript locator handoff

* refactor: remove runtime transcript file bridges

* refactor: remove transcript file handoffs

* refactor: remove MSTeams legacy learning key fallback

* refactor: store model catalog config in sqlite

* refactor: use sqlite model catalog at runtime

# Conflicts:
#	docs/cli/secrets.md
#	docs/gateway/authentication.md
#	docs/gateway/secrets.md

* fix: keep oauth sibling sync sqlite-local

# Conflicts:
#	src/commands/onboard-auth.test.ts

* refactor: remove task session store maintenance

# Conflicts:
#	src/commands/tasks.ts

* refactor: keep diagnostics in state sqlite

* refactor: enforce database-first runtime state

* refactor: consolidate sqlite runtime state

* Show Codex subscription reset times in channel errors (#80456)

* fix(codex): refresh subscription limit resets

* fix(codex): format reset times for channels

* Update CHANGELOG with latest changes and fixes

Updated CHANGELOG with recent fixes and improvements.

* fix(codex): keep command load failures on codex surface

* fix(codex): format account rate limits as rows

* fix(codex): summarize account limits as usage status

* fix(codex): simplify account limit status

* test: tighten subagent announce queue assertion

* test: tighten session delete lifecycle assertions

* test: tighten cron ops assertions

* fix: track cron execution milestones

* test: tighten hermes secret assertions

* test: assert matrix sync store payloads

* test: assert config compat warnings

* fix(codex): align btw side thread semantics

* fix(codex): honor codex fallback blocking

* fix(agents): avoid Pi resource discovery stalls

* test: tighten codex event assertions

* test: tighten cron assertions

* Fix Codex app-server OAuth harness auth

* refactor: move agent runtime state toward piless

* refactor: move device and push state to sqlite

* refactor: move runtime json state imports to doctor

* refactor: finish database-first state migration

* chore: refresh generated sqlite db types

* refactor: clarify cron sqlite store keys

* refactor: remove stale file-backed shims

* refactor: bind codex runtime state by session id

* test: expect sqlite trajectory branch export

* refactor: rename session row helpers

* fix: keep legacy device identity import in doctor

* refactor: enforce database-first runtime state

* refactor: consolidate sqlite runtime state

* build: align pi contract wrappers

* chore: repair database-first rebase

* refactor: remove session file test contracts

* test: update gateway session expectations

* refactor: stop routing from session compatibility shadows

* refactor: stop persisting session route shadows

* refactor: use typed delivery context in clients

* refactor: stop echoing session route shadows

* refactor: repair embedded runner rebase imports

# Conflicts:
#	src/agents/pi-embedded-runner/run/attempt.tool-call-argument-repair.ts

* refactor: align pi contract imports

* refactor: satisfy kysely sync helper guard

* refactor: remove file transcript bridge remnants

* refactor: remove session locator compatibility

* refactor: remove session file test contracts

* refactor: keep rebase database-first clean

* refactor: remove session file assumptions from e2e

* docs: clarify database-first goal state

* test: remove legacy store markers from sqlite runtime tests

* refactor: remove legacy store assumptions from runtime seams

* refactor: align sqlite runtime helper seams

* test: update memory recall sqlite audit mock

* refactor: align database-first runtime type seams

* test: clarify doctor cron legacy store names

* fix: preserve sqlite session route projections

* test: fix copilot token cache test syntax

* docs: update database-first proof status

* test: align database-first test fixtures

* docs: update database-first proof status

* refactor: clean extension database-first drift

* test: align agent session route proof

* test: clarify doctor legacy path fixtures

* chore: clean database-first changed checks

* chore: repair database-first rebase markers

* build: allow baileys git subdependency

* chore: repair exp-vfs rebase drift

* chore: finish exp-vfs rebase cleanup

* chore: satisfy rebase lint drift

* chore: fix qqbot rebase type seam

* chore: fix rebase drift leftovers

* fix: keep auth profile oauth secrets out of sqlite

* fix: repair rebase drift tests

* test: stabilize pairing request ordering

* test: use source manifests in plugin contract checks

* fix: restore gateway session metadata after rebase

* fix: repair database-first rebase drift

* fix: clean up database-first rebase fallout

* test: stabilize line quick reply receipt time

* fix: repair extension rebase drift

* test: keep transcript redaction tests sqlite-backed

* fix: carry injected transcript redaction through sqlite

* chore: clean database branch rebase residue

* fix: repair database branch CI drift

* fix: repair database branch CI guard drift

* fix: stabilize oauth tls preflight test

* test: align database branch fast guards

* test: repair build artifact boundary guards

* chore: clean changelog rebase markers

---------

Co-authored-by: pashpashpash <nik@vault77.ai>
Co-authored-by: Eva <eva@100yen.org>
Co-authored-by: stainlu <stainlu@newtype-ai.org>
Co-authored-by: Jason Zhou <jason.zhou.design@gmail.com>
Co-authored-by: Ruben Cuevas <hi@rubencu.com>
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com>
Co-authored-by: Shakker <shakkerdroid@gmail.com>
Co-authored-by: Kaspre <36520309+Kaspre@users.noreply.github.com>
Co-authored-by: dataCenter430 <titan032000@gmail.com>
Co-authored-by: Kaspre <kaspre@gmail.com>
Co-authored-by: pandadev66 <nova.full.stack@outlook.com>
Co-authored-by: Eva <admin@100yen.org>
Co-authored-by: Eva (agent) <eva+agent-78055@100yen.org>
Co-authored-by: Josh Lehman <josh@martian.engineering>
Co-authored-by: jeffjhunter <support@aipersonamethod.com>
2026-05-13 13:15:12 +01:00
Jesse Merhi
6c92324c5f
Revert "Check ClawHub trust before plugin installs (#81307)" (#81363)
This reverts commit 87eb450047.
2026-05-13 19:34:18 +10:00
Jesse Merhi
87eb450047
Check ClawHub trust before plugin installs (#81307)
Merged via squash.

Prepared head SHA: 273fd7c20e
Co-authored-by: jesse-merhi <79823012+jesse-merhi@users.noreply.github.com>
Co-authored-by: jesse-merhi <79823012+jesse-merhi@users.noreply.github.com>
Reviewed-by: @jesse-merhi
2026-05-13 16:31:52 +10:00
Kaspre
5375281974 fix(plugins): load untracked TS source plugins 2026-05-12 07:08:38 +01:00
Kevin Lin
ce0584af89
docs: reorganize Codex harness docs (#80029)
* docs: reorganize codex harness docs

* docs: address codex harness review findings

* docs: move codex references to reference nav

* docs: add codex topic configuration section
2026-05-09 19:02:50 -07:00
pashpashpash
02fe0d8978
Keep OpenAI Codex migrations on automatic runtime routing (#79238)
* fix: keep migrated openai codex routes automatic

* scope runtime policy to providers and models

* fix runtime policy surfaces

* fix ci runtime policy checks

* fix doctor stale session runtime pins
2026-05-08 16:05:35 +09:00
Patrick Erichsen
10f9a758b6
docs: add dedicated ClawHub docs tab (#79159)
* docs: add clawhub docs tab

* fix: satisfy docs sync lint

* docs: prune internal clawhub nav pages

* docs: include ClawHub publishing page in nav

* docs: use clawhub how-it-works route
2026-05-07 18:55:08 -07:00
Vincent Koc
91ed1604b0
docs(imessage): make imsg the supported setup path 2026-05-07 12:53:01 -07:00
Peter Steinberger
330ba1fa31 refactor: move canvas to plugin surfaces 2026-05-07 09:07:18 +01:00
Peter Steinberger
a8801350d8
docs: clarify planned monthly support lines 2026-05-07 01:42:20 +01:00
the sun gif man
d4b4660026
config: stop automatic writes and guard Nix mutators (#78047)
Keep startup-derived plugin enablement, gateway auth tokens, control UI origins, and owner-display secrets runtime-only instead of persisting them into openclaw.json.

Refuse config writers, mutating update/plugin lifecycle commands, and doctor repair/token generation in Nix mode with agent-first nix-openclaw guidance.

Verification:
- pnpm check
- pnpm build
- pnpm test -- src/config/io.write-config.test.ts src/config/mutate.test.ts src/config/io.owner-display-secret.test.ts src/gateway/server-startup-config.recovery.test.ts src/gateway/startup-auth.test.ts src/gateway/startup-control-ui-origins.test.ts src/cli/plugins-cli.install.test.ts src/cli/plugins-cli.policy.test.ts src/cli/plugins-cli.uninstall.test.ts src/cli/plugins-cli.update.test.ts src/cli/update-cli.test.ts src/auto-reply/reply/commands-plugins.install.test.ts src/auto-reply/reply/commands-plugins.test.ts src/commands/onboarding-plugin-install.test.ts src/commands/doctor.runs-legacy-state-migrations-yes-mode-without.e2e.test.ts src/commands/doctor/shared/codex-route-warnings.test.ts src/commands/doctor/repair-sequencing.test.ts src/agents/auth-profile-runtime-contract.test.ts src/auto-reply/reply/agent-runner-execution.test.ts
- GitHub CI green on 05a2c71b90

Co-authored-by: Codex <noreply@openai.com>
2026-05-06 14:43:32 +02:00
Jesse Merhi
1c42c77433
feat: add user input blocking lifecycle gates (#75035)
Summary:
- The PR adds a `before_agent_run` plugin hook with pass/block decisions, redacted blocked-turn persistence, diagnostics/docs/changelog updates, and focused runner, gateway, session, and plugin tests.
- Reproducibility: not applicable. as a feature PR rather than a current-main bug report. Current main lacks ` ... un`, while the PR head adds source coverage and copied live Gateway/WebChat log proof for the new behavior.

Automerge notes:
- PR branch already contained follow-up commit before automerge: fix: trim before agent hook PR scope
- PR branch already contained follow-up commit before automerge: fix: keep before-agent blocks redacted
- PR branch already contained follow-up commit before automerge: fix: keep runtime context out of model prompt
- PR branch already contained follow-up commit before automerge: docs: refresh config baseline after rebase
- PR branch already contained follow-up commit before automerge: fix: align blocked turn clients with redacted content
- PR branch already contained follow-up commit before automerge: fix: remove out-of-scope client block UI changes

Validation:
- ClawSweeper review passed for head 767e46fde8.
- Required merge gates passed before the squash merge.

Prepared head SHA: 767e46fde8
Review: https://github.com/openclaw/openclaw/pull/75035#issuecomment-4351843275

Co-authored-by: Jesse Merhi <jessejmerhi@gmail.com>
Co-authored-by: jesse-merhi <79823012+jesse-merhi@users.noreply.github.com>
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
2026-05-06 11:41:04 +00:00
Vincent Koc
5d557171b3
fix(plugins): apply npm overrides to managed roots (#78386) 2026-05-06 02:47:25 -07:00
Peter Steinberger
2eaf8ad712
feat(plugins): support npm pack installs 2026-05-06 09:16:49 +01:00
Vincent Koc
4ee234f8ee
docs: typography hygiene across 6 pages
Replaced 66 typography characters (curly quotes, apostrophes, em/en
dashes, non-breaking hyphens) with ASCII equivalents per
docs/CLAUDE.md heading and content hygiene rules.

- docs/channels/mattermost.md: 12 chars
- docs/tools/plugin.md: 11 chars
- docs/providers/xai.md: 11 chars
- docs/plugins/building-plugins.md: 11 chars
- docs/concepts/streaming.md: 11 chars
- docs/concepts/model-providers.md: 11 chars
2026-05-05 20:45:39 -07:00
Peter Steinberger
cbc228f0f6
docs: explain blocked plugin ownership repair 2026-05-06 04:43:37 +01:00
hcl
d193d15f17
fix(plugins): explain source-only package diagnostics (#77835) (#77842) 2026-05-05 17:43:13 -07:00
Peter Steinberger
b2096d19ec fix(plugins): default bundled discovery to allowlist 2026-05-04 23:50:03 +01:00
Peter Steinberger
41257a5f6f fix(plugins): rename bundled allowlist discovery policy 2026-05-04 23:50:03 +01:00
Peter Steinberger
3ed569ac3c fix(plugins): respect allowlist for web provider fallback 2026-05-04 23:50:03 +01:00