Read immutable pin descriptions and eligible manifests through the canonical
shared-state reader, retaining admission, snapshot scope, exact artifact bytes,
and first-resource error order. Capture pin and catalog facts before awaits so
caller mutation cannot mix revisions or change the selected filesystem host.
Await the existing per-root node fixture cleanup before deleting test state.
No schema, retention, durability, permission, or dependency change is introduced.
Run exact managed-attachment lookup and full visible-history JSON validation in the existing session-history worker. Preserve cold restoration ownership, read fences, archive fallback, SyntaxError, and process-held incognito reads.
The paired 5,000-message benchmark reduced caller-thread CPU from 7.5992 ms to 0.4082 ms per lookup, with wall time moving from 7.49 ms to 7.85 ms. Add native-worker regression and parity proof without a new cache or lifecycle owner.
Testbox tbx_01m313hc0abgpmy9fkam2yzzaa: full type graphs, changed checks, focused tests, build, and benchmark passed. Existing cold/history sibling tests also passed. Independent review found no actionable findings.
Read existing profiles and initialized approvals without writer admission.
Batch exec authorization commits through the shared-state worker while
retaining policy, deletion-fence, and lifecycle checks through settlement.
Contended-writer proof reduces mean main-thread delay from 330-331 ms to
0.37-0.63 ms. Validated on Blacksmith Testbox with focused regressions,
typechecks, lint, storage guards, and independent review.
* perf(state): move transcript reads off the Gateway thread
Reuse the existing history worker for durable transcript search and cursor deltas. Keep current sharing checks and display projection on the Gateway, and document the remaining database worker migration with a reproducible inventory.
Testbox proof: 5,000 rows and 50 viewers reduced caller-thread CPU by 96.7% for search and 7.3% for cursor history. Golden responses, 211 focused tests, build, type/lint/storage gates, inventory verification, and docs links passed.
* perf(state): isolate transcript search worker contracts
Move search request/result types into an import-free contract so worker protocol types do not depend on the query implementation. Register and document the inventory generator package commands.
Fix the architecture and unused-file CI failures. Exact failed guards, export scanning, core types, real-worker golden tests, formatting, and inventory regeneration passed on Testbox.
* feat(process): support awaited stdout consumers
* refactor(node-host): move launch and turn journals to the state worker
Preserve journal transactions and live-owner checks while retaining result persistence and native settlement. Carry the existing shared admission component from #148623; process consumption remains in the #149442 parent.
* fix(node-host): preserve receipt reads after supervisor shutdown
* test(node-host): await worker inventory reconciliation
* test(node-host): route prepared journal fixture through broker owner
* test(node-host): route background worker cleanup through SQLite broker
* refactor(node-host): clarify async pause and output loop contracts
Transfer revocable host integrity proof after ordinary handle close through the existing native admission port. Keep receiver identity validation and durable verification gates intact. A synthetic 1 GiB database opens in 12 ms median versus 96 ms; Testbox regression, sibling tests, changed checks, and independent review pass.
Direct Anthropic OAuth requests could fail with claude_code_version_too_old because they advertised Claude Code 2.1.75. Maintain a 2.1.278 client-version floor and prefer a newer installed stable CLI through the Anthropic plugin's shared, bounded probe. Both transports use one selected version for request headers and billing metadata; failed or slow probes fall back to the floor.
Preserve API-key and other provider routes without configuration, credential, dependency, or state migrations. Cover request identity and probe lifecycle, and repair the cold metadata fixture and OS-watch race encountered during validation. Focused tests and exact-head CI passed; candidate live OAuth acceptance remains unverified.
Thanks to @Cyb3rb1ade, @raghidtawil-lab, and @davidcittadini for the reports and controlled comparisons. The single-snapshot and header/billing boundary-test approach builds on @KrasimirKralev's prior work.
Fixes#94716. Related: #154016. Supersedes the approach in #150790 with credit; that PR remains open for maintainer follow-up. The separate model-allowlist issue #144903 is outside this repair.
Co-authored-by: Krasimir Kralev <263465593+KrasimirKralev@users.noreply.github.com>
* fix(gateway): retain lifecycle notice queue context
* test(outbound): include private context in caller expectations
* fix(gateway): keep restart cleanup in its original state root
Carry startup's captured environment through the sentinel read and every
revision-checked cleanup path. A preparation hook changing the ambient root
must not delete an unrelated equal-revision sentinel in another database.
Preserve the canonical transaction and revision guards. Real startup and
SQLite regressions cover original consumption, unrelated-root preservation,
and a newer marker in the original root; terminal delivery is mocked.
* refactor(outbound): bind captured recovery context once
* test: join Doctor database cleanup before snapshots
* fix(gateway): reconcile terminal restart sentinel snapshots
* test(gateway): retain captured context in update permission assertions
Read /tasks and /status task snapshots through the canonical accepted-write
fence and prepared read owner, preserving session visibility and strict
agent-local counts without synchronous SQLite refresh.
Keep the original race guards after a scoped worker-row fixture witness,
and repair status fixtures to exercise successful replies. Include the
canonical prepared-runtime fixture correction from 2e73d8e93e.
* perf(fleet): run registry operations in SQLite workers
* fix(state): preserve readonly admission error context
* test(gateway): retain catalog root failure diagnostics
* fix: preserve uncertain lease outcomes before caller recovery
* fix(state): reject retired read scopes and retain wrapper imports
Reject new admissions to closing or closed selected read scopes while keeping already-admitted readers owned through cleanup. Preserve typed invalidation at plugin discovery boundaries.
Include the retained-read eager dependencies in the canonical PR wrapper inventory.
* test(state): require rejection of retired read scopes
Update the three existing disposable-scope variants to expect the canonical
admission error while preserving active and unrelated source assertions.
* refactor: move plugin blob storage into workers
Move all eight asynchronous BlobStore methods onto the existing shared-state
mutation and retained read owners. Preserve quotas, transactional accounting,
read-source selection, and typed error and cleanup behavior.
* fix(state): keep ordinary reads in the SQLite worker
Use the existing independent readonly worker for ordinary fixed reads while
retaining cached writer custody. Validate captured file identity around opens
and acceptance, and bind previously missing paths when their first file appears.
Keep selected snapshots and native preparation scopes with their existing owners.
* fix: catalog refresh fails when previous discovery finishes
Retain selected plugin registries through awaited preparation and hand construction claims to the completed generation. Preserve stale-publication cleanup and borrowed Gateway-root ownership. Related: #151588, #148290.
* fix(test): retain Telegram suite output on subprocess errors
* test: align Blob worker CI inventories
Include Diffs in the expected database-worker planner group while retaining exact coverage and duplicate checks.
Carry the packaging fixture dependency from canonical main commit 5741b3cbe8 (PR #151967), whose one-line patch matches the original 8b58def37fbf0e5750492a9fc9de87478e54e3d2.
No production or build inputs change; compiled runtime and active-writer evidence retain their original commit bindings.
* fix(state): clarify blob preparation callback contracts
* test(plugins): load Diffs lifecycle fixture through public facade
* refactor: move outbound claim and renewal SQLite to worker
* test: route outbound queue consumers through database workers
* test: expect worker routing for durable Discord delivery
* test(ci): retain one owner for Twitch delivery coverage
* test(outbound): clean up ACK fixtures with their owner
* test: join Doctor database cleanup before snapshots
* test(claws): adopt canonical Doctor reader cleanup
Carry the exact Doctor fixture from 8416d71015 (#146361). Preserve ordered async drain, native reset, and temporary-directory cleanup while closing both metadata readers in finally. Supersedes the local helper-based fixture repair without changing Claims production.
* refactor(outbound): centralize delivery queue worker dispatch
Route the existing eight queue operations through one typed domain adapter while retaining each executor and transaction owner. Remove the obsolete lease-only selector and preserve current-main worker operations and canonical fixtures. Reuse the exact duplicate test-route deletion from 57a0a198ebdec2530afd17b656183f060fb4c4b3.
* test(outbound): control recovery snapshot timing
Capture the queue row and await real worker renewal before fixing the host recovery clock. Model an expired detached scan without shortening the authoritative lease or sleeping. Fix the clock before startup captures its recovery deadline. Preserve exact owner, renewed expiry, and retry assertions; both modes reject a stale-snapshot guard mutation. Production remains unchanged.
* refactor(code-mode): execute JavaScript with typed API discovery
Keep schema-derived tool declarations available to agents while removing TypeScript compilation, optional preflight, and language selection from Code Mode. Retire the saved languages setting through shared Doctor/startup migration, preserving activation and limits. Existing TypeScript cells must be rewritten as JavaScript.
Related: #153889
* fix(code-mode): complete JavaScript cutover checks
* docs(config): regenerate JavaScript-only Code Mode baseline
* test(code-mode): match public names in live validation errors
* test(code-mode): avoid shadowing the selected call
* test(code-mode): allow fixture rereads in live evidence
* fix: avoid transient CLI snapshot failures during database writes
Back off between synchronous snapshot attempts using the existing bounded retry policy. Preserve source-byte checks, cleanup, permanent errors, and the ten-attempt cap without replaying Gateway requests.
* test: make snapshot quiescence timing deterministic
Measure the bounded admission policy with virtual time instead of including worker startup and private-copy I/O in a one-second assertion. Preserve independent copy and cleanup coverage.
* perf: move asynchronous update history reads to shared worker
* fix: isolate update history worker query dependencies
* test: separate update history read coverage
* fix(tasks): keep identifier repair out of Gateway restore
Doctor and legacy imports normalize historical identifiers atomically while preserving physical subagent identities and existing completion bindings. Keep indexed batched runtime queries and canonicalize identifiers at explicit producer boundaries. Direct binary/container upgrades require Doctor before Gateway startup; no schema version or index changes.
* perf(ui): defer usage-only English until its page loads
* fix(tasks): retain restore invalidation after transaction rollback
* fix(update): preserve migration advice environment during triage
* perf(transcripts): move caption appends to shared worker
Preserve captured write admission and drain accepted speech before final notes
or failed-start restoration. Keep the existing summary and SQLite kernels.
Carry the already-landed test import correction from #153480 so the current
source passes its test typecheck.
* refactor(transcripts): prepare worker schemas in the read owner
Preserve the same database, path, environment, read-only flag, and schema
error boundary while keeping shared command dispatch within its line cap.
* fix(transcripts): remove startup registry dependency cycle
Pass the state directory consumed by retry retention and revocation directly.
This removes the unnecessary capture-context type edge while preserving the
same state and session identity checks.
* fix(transcripts): fence speech before startup failure drainage
* test(sessions): await native fixture retirement before reads
Reuse connections in the existing agent, shared-state, read-worker, and
coordinator owners, and align reclamation worker retirement with the same
idle window. Preserve explicit lifecycle invalidation with acknowledged
worker cleanup, borrow pins, and retries for retained failed cleanup.
Keep protected snapshots and native-exit settlement contracts intact.
Document focused native-open measurements and lifecycle proof in the PR.
* refactor(sessions): register first-use categories off thread
Move registration into the existing shared-state worker while preserving existing-category admission avoidance, atomic append ordering, durable session success, and catalog-only patch invalidation. Both post-commit callers await registration before notification. Refs #144592 and #150565.
* refactor(state): keep session delivery dispatch with its contract
Reuse the canonical 13-command selector without changing tag order or the delivery executor. This keeps the current-main dispatcher within its existing line cap when category registration and the GitHub pending read are combined. Refs #150565.
Preserve exact-agent grants, legacy migration errors, normalization, and
fail-closed policy results while moving the row query to the existing
shared-state read owner. Synchronous authorization and policy mutations
retain their existing owners.
Refs #151092.
Route the four asynchronous sandbox registry readers through the shared-state
read owner while preserving snapshot custody and missing-state noncreation.
Share queries and row decoders with native writers and currentness checks,
retaining browser workspace ownership and generation retirement behavior.
Charge sandbox selectors through the existing pooled reader admission.
Registry writes, reservation callbacks, and Doctor imports remain synchronous.
Related: #144592
Carry the host's revocable integrity proof through native execution admission
and the prepared lease into the existing database-open gate. Discard remembered
proof before Doctor maintenance can run raw mutations.
Avoid repeated integrity and foreign-key scans for a verified live host file
without changing schema, configuration, or cross-process verification policy.
* fix: preserve restart ownership and chat position during startup
Keep foreground and update-owned restarts within their existing capped cleanup deadline instead of assuming an enclosing service will replace them. Anchor the chat position rail after its first visible-message measurement. Stabilize Doctor and memory SQLite fixtures and assert the actual Codex process-notification ordering contract.
* test: exercise doctor state isolation on Windows
* fix(ci): wait for exiting Darwin process groups
* fix(tasks): keep superseded progress from failing readers
* fix(tasks): preserve publication ownership through supersession
* test: acknowledge delivery fixtures with their claim owner
* test(qa): join parent acknowledgement before terminal assertions
* test(tasks): arm scan barrier after starting mutation
* test: retire task event owners at fixture boundaries
* test: share port claims and await hover recovery
* fix(github): keep publication options responsive with many pending requests
Stream and validate pending repository receipts on the existing shared-state worker, retaining the latest compact result. Revalidate current session and personal GitHub identity after the awaited read while preserving the non-repository fallback and canonical confirmation checks.
* test(codex): isolate turn-event fixture clocks
Use controlled clocks and an accepted-turn barrier for plan restoration and interrupted-completion fixtures. Keep the execution budget and assertions unchanged, and move the cases into a dedicated suite with the same database-worker routing.
* test: preserve acknowledgement worker owner checks
Carry only the delivery acknowledgement fixture correction from 883b2a9441 (#153296). Preserve explicit null and undefined owner checks, use the acquired claim for cleanup, and keep omitted-owner acknowledgement idempotent after settlement.
Keep verification records in the quarantine store and let the existing
lease owner consume clean proof and certify the last checkpointed close.
Share gate eligibility with readiness, queue quick verification after
listening, and invalidate proof across crashes, aliases, and maintenance.
The warmed 899.5 MB fixture gate falls from 1094 ms to 17.8 ms (98.4%).
Full checks remain for updates, migrations, unclean or replaced files,
Doctor, shared state, snapshot fallback, and daily verification.
Normalize legacy task identifiers before registry hydration and keep records, writes, receipts, and status projections canonical. Use the existing indexes for populated mutation selectors while preserving legacy subagent binding ownership and rollback recovery. Follow-up to #153394.
* fix(reply): preserve code and attachments in streamed replies
* fix: retain prepared reply metadata through delivery
Preserve attachment associations through media normalization and shared prepared delivery. Remove static import cycles and keep Gateway and Telegram fixtures aligned with the shared operation contract.
* test: fix streamed reply integration guards and recovery coverage
Prune the removed max-lines suppression and reuse the shared first-text extractor at Gateway test call sites. Extend registered Telegram recovery coverage to preserve an attachment alias associated with the second media item while deduplicating its singular URL.
Validated owner guards, formatting, targeted lint, extension test types, 245 Gateway/shared cases and 11 Telegram recovery cases. Fresh independent review is clean through P2.
* test: reuse Gateway message inspection without line growth
Use the existing message-unwrapping helper at shared text-extractor call sites and remove two redundant missing-message throws. The retained empty-string assertions still reject absent messages.
Verified the exact CI merge composition against main parent 7f731617 with the maintained line-cap guard, scoped lint, formatting, all 223 Gateway cases, and fresh independent review through P2.
* test: repair streaming media coverage and CI checks
* fix(telegram): keep recovered finals from resending block media
* test(telegram): exercise prepared replies through native transport
* fix(reply): clear stale metadata after media staging failures
Always replace attachment metadata with the surviving aligned entries. A failed
first file must not lend its name or MIME type to a later URL that has no
metadata. Clear the metadata when no media survives.
Add a regression using the existing normalizer fixture; it fails before this
change on the stale filename.
* test(telegram): use shared SDK fixtures in recovery suites
Keep recovery suites on existing unpublished test facades and reuse public
runtime entrypoints where available. Preserve all delivery assertions and
fixture behavior while removing direct core imports from plugin tests.
Name the existing mock type through Vitest's public Mock contract so test
fixture declarations remain portable without changing runtime behavior.
* fix(tasks): respect live publication invalidation
Recheck recovery-witness invalidation before notifications and after
observer callbacks. Intervening committed writes remain authoritative even
when task records return to equal values, without dropping valid receipt
readiness or weakening publication assertions.
* fix(tests): import prepared replacement from lifecycle
* fix: preserve Node debugger attachment on SIGUSR1
Use SIGUSR2 for Gateway restarts and reserve SIGUSR1 for Node's inspector.
Update internal callers, diagnostics, QA harnesses, and operator docs.
Route current unmanaged Gateways through owner-targeted restart RPC while
retaining SIGUSR1 only for verified legacy Gateway locks during upgrades.
Refuse self-signaling embedded Unix hosts without a restart handler.
Manual restart scripts must switch to SIGUSR2; prefer openclaw gateway restart.
* test: follow prepared runtime replacement owner
Run bootstrap and Doctor workspace reads through the existing reader owner while preserving snapshot and typed-alias semantics. Retain native cleanup failure facts when composing with the read pool, and charge the captured workspace selector by UTF-8 bytes.
* fix(onboarding): avoid blocking recommendation storage
Keep recommendation reads on the independent read-only worker and route all five mutations through the existing shared-state actor. Preserve workspace identity, no-create reads, transaction and CAS behavior, and await persistence in registered CLI actions and both wizard completion paths.
* refactor(onboarding): keep state decoding and dispatch with owners