Commit graph

32 commits

Author SHA1 Message Date
Josh Avant
163cd10bfa
feat(tools): explain terminal access restrictions (#157014)
* feat(tools): explain terminal access restrictions

* test(agents): support source-aware roster fixtures

* fix(cli): inspect remote agents and retain approval summaries
2026-09-24 02:53:23 -05:00
Vincent Koc
e6031c1f43
docs: fix 16 secops-owned audit findings across gateway, cli, and security pages (#144030)
Co-authored-by: Vincent Koc <vincent@openclaw.org>
2026-09-10 20:28:21 +08:00
Vincent Koc
f575b7f4ef
docs(cli,tools): fix information-architecture findings in CLI and tools pages (#143775)
Structure-only changes: no prose is added or reworded beyond the new
heading titles themselves. Every published anchor id is preserved.

- cli/doctor/checks.md: split the 42-bullet `## Notes` list into nine
  H3 groups so individual checks are addressable.
- cli/doctor/sqlite-maintenance.md: sentence-case the one Title Case H3
  (slug unchanged).
- cli/mcp/registry.md: move `Saved MCP server definitions` directly after
  the intro that introduces its command list; `Codex tool approvals` now
  follows it.
- cli/plugins/install.md: promote the nine collapsed accordions to H3
  sections (they carry scope gates, `--force`/`--pin` semantics and
  install-policy rules), lift the source/locator prose above them, and
  head the trailing local-path run.
- cli/plugins.md: add the body H1 used by the other CLI command pages.
- cli/update/how-updates-run.md: add per-topic H4s inside
  `Restart handoff`, promote `Plugin sync details` out of
  `Git checkout flow`, and head the package-manager install text that was
  sitting inside the Git checkout section.
- cli/onboard.md: give the flag list its own `## Flags` heading and demote
  `Additional non-interactive flags` under `Non-interactive setup`.
- cli/approvals.md: move the `openclaw exec-policy` section after
  `Common options` so the page opens on the command it is titled for.
- cli/infer.md: move the "turn infer into a skill" how-to off the top of
  the reference page.
- cli/index.md: file `devices` with pairing/channels to match the sidebar,
  and name the `automations` alias on the cron row.
- tools/tts/field-reference.md: drop the stray H3 nested inside the Inworld
  accordion (its id is kept as an authored anchor) and lift the SecretRef
  paragraph out from between two accordions.
- docs.json: drop the duplicate `tools/tts` nav entry, put browser
  agent-tools before troubleshooting and existing-session beside profiles,
  file `cli/wiki` with memory/models and `cli/openclaw` with onboard/setup.
2026-09-10 15:41:30 +09:00
Vincent Koc
e8ffd3cf09
docs: replace private paths and document the ClawHub docs source (#140227)
Docs governance and publish-hygiene pass over docs/AGENTS.md and the
pages its rules cover.

- Replace every `~/Projects` operator path in docs/ with a neutral
  placeholder. 38 occurrences across 13 pages, including the private
  repo path `~/Projects/manager/skills`. `docs/AGENTS.md` forbids local
  paths, and its own Internal Docs bullet named one.
- Record the placeholder convention in the Published Link Rules bullet
  that bans local paths.
- Document the ClawHub docs source in Source Ownership: this repo holds
  no `/clawhub/**` page sources even though `docs/docs.json` lists them,
  so a local preview and `pnpm docs:check-links` report those routes as
  missing until `OPENCLAW_DOCS_SYNC_CLAWHUB_REPO` points at a ClawHub
  checkout.
- Drop the Strict-STE hard violation rate on `docs/AGENTS.md` from 18
  hard (3.4 per 100 words) to 0 by splitting semicolon sentences and
  sentences over 20 words, and by naming the actor in passive
  sentences. No rule changes meaning.
- Convert the Maturity Scorecard paragraph to a bulleted list, matching
  every other section.
- `docs/prose.md`: name v2026.8.1 as the release that removed OpenProse,
  and explain the `--agent codex` flag and the third-party skills CLI.
- Link `/prose` from `tools/skills` and `tools/slash-commands`.
- `docs/docs_map.md`: correct the summary to describe the stub, and drop
  the H1 that repeated the frontmatter title.

Closes audit findings: r3-0734, r3-0736, r3-0907, r3-0910, r3-2277,
r3-2278, r3-2285, r3-2286, r3-2287, r3-2288, r4-clawhub-0001

Partially addresses r3-0906 (private path removed; publish-tree
exclusion left as a follow-up). Not addressed: r3-0909 (generator
change).
2026-09-06 23:48:33 +08:00
Peter Steinberger
ec930a14cd
fix(cli): emit snapshots for approval allowlist JSON no-ops (#136574) 2026-09-02 13:53:57 -07:00
Peter Steinberger
de12e0a06c
feat(approvals): standing-grant ledger, revocation, and configurable terms (#131602)
* feat(approvals): standing-grant ledger, revocation, and configurable terms

Completes the operator half of cron standing grants (#129526):

- Grants are listable and revocable. New gateway methods
  exec.approval.grants.list/revoke (operator.approvals scope), CLI
  'openclaw approvals grants list|revoke', and a Standing grants section
  on the Control UI approvals page with per-row revoke. Revocation is
  idempotent, records the acting client, and takes effect at the next
  occurrence's spawn boundary.
- Grant terms are frozen at mint and configurable. Default stays
  until-revoked (matching what shipped Always allow has always meant);
  tools.exec.grantExpiryDays sets a day-bounded default for future
  grants (enterprise fleet policy), and resolve surfaces may override
  per grant via grantExpiresInDays / --expires-in-days. Existing grants
  keep their minted terms; config changes are never retroactive.
- expires_at_ms goes nullable (NULL = until revoked). The mandatory-
  expiry shape never reached a release tag, so the lazy ensure rebuilds
  it in place; grants are re-derivable authority, so the fail-closed
  cost is one re-prompt.
- Approval cards say what Always allow does. Automation approvals carry
  a standing-grant ApprovalScope (new union member) built server-side
  from the cron run registry (now carrying the job display name); the
  Control UI inbox card and modal render it via i18n, e.g. 'Always
  allow runs this exact command for "grant-demo" without asking, for
  10 days (revocable)'.
- Aux method registries stay in lockstep: new parity test fails when a
  GATEWAY_AUX_METHODS entry lacks a lazy handler (this gap produced
  live unknown-method errors during bring-up).

Live-proven on a hermetic gateway: until-revoked grant ran 62 promptless
occurrences; UI and CLI revocation each returned the prompt on the next
occurrence; config default stamped exactly 10.0 days via a UI resolve;
--expires-in-days 99 override stamped 99.0 days; ledger and card
screenshots captured from the running Control UI.

* chore(ui): annotate the scope narrowing assertion for the safety ratchet

* test(gateway): move aux-method parity check to its own suite

* fix(ci): boundary-parse UI approval scope; register grants schemas for native codegen

- The Swift/Kotlin generators discover named schemas through the
  protocol schema fragments; the standing-grant scope member and the
  grants list/revoke shapes were missing there, which made the Swift
  generator silently drop the ApprovalScope union and broke ios-build.
  Registered, regenerated, union and new struct emitted again.
- The chained-assertion lane rejects 'as unknown as' in the UI scope
  parser; replaced with a real per-kind boundary parser, which is what
  the rule asks for.
- The sqlite-allow-raw marker must share the line of a mid-statement
  prepare() call for the Kysely guardrail; split the pragma read so the
  SAFETY comment and the allow marker each sit on their own guarded
  line.

* chore(ui): record startup-budget growth for the approvals scope line

The standing-grant scope renderer and grants-ledger strings ride the
boot path (~700 B gzip). Recorded via the check's --update-baseline flow
with the reason inline; well under the committed 350 KiB hard cap.

* fix(gateway): restore the channel-restart helper export dropped on main

#118157 made startGatewayChannelFromActiveRegistry module-local while
its colocated test still imports it, breaking check-test-types and the
compact shard on every merge ref. Smallest correct main heal per the
broken-CI doctrine; the test passes again.

* fix(gateway): drive channel-restart reload coverage through its exported owner

Replaces the prior export restore: #118157 made the restart helper
module-local (the dead-export scan is right that tests are not
production consumers), but left its colocated test importing it, so
main failed check-test-types either way. The test now exercises the
same preserveManualStop semantics through rollbackStoppedGatewayChannels,
the exported reload owner, and the helper stays private.

* test(ui): answer the grants ledger request in approvals-page history tests

The approvals page now loads the standing-grant ledger next to history;
a method-aware stub answers it out of band so the ordered history mocks
keep their call counts. Adds coverage for the ledger render and the
revoke round-trip.

* chore(ui): record CI-observed startup-JS baseline for the grants surface

The e2e-real-gateway lane builds the same tree ~600 B larger than checks-ui
and local builds, past the 64 B variance allowance; record the CI-observed
value so the enforcement limit stops straddling cross-lane build variance.

* fix(cli): escape standing-grant ledger fields visibly; register grants methods in inventory tests

The grant ledger's revokedBy (client display name), automation label, and
agent-authored command now go through escapeApprovalTextForTerminal like the
pending-approvals table, so hostile control characters render as visible
\u{...} escapes instead of being silently stripped by the table renderer.
Regression test fails pre-fix. Also lists exec.approval.grants.list/revoke
in the 2026.8 release-train roster, classifies the approvals grants command
group for JSON output, and fixes the stubGrants mock typing.
2026-08-28 02:56:20 -07:00
Josh Avant
1c37c8cdc7
fix(exec): scope reusable approvals to their working directory (#129636)
* fix(exec): bind durable approvals to working directory

* chore(apps): refresh native string inventory

* test(node-host): preserve prepared working directory

* fix(exec): use shared path safety facade

* fix(exec): revalidate approved directory identity
2026-08-25 18:24:14 -07:00
Peter Steinberger
4c7a8d412b
feat(cli): support --json across reporting commands (#117928)
* feat(cli): support --json across reporting commands

* test(cli): satisfy json command checks

* test(cli): type json exception map
2026-08-02 02:56:08 -07:00
Peter Steinberger
9eae43bd37
refactor(infra): move exec approvals into the shared SQLite state DB (#114063)
* refactor(infra): move exec approvals into the shared SQLite state DB

Delete the file-runtime exec-approvals store (exec-approvals.json + .lock
sidecar machinery) on both runtimes and make the reserved
exec_approvals_config singleton row canonical. Doctor owns the one-time
import with claim/verify/receipt discipline; runtime fails closed with a
doctor instruction while un-migrated legacy state exists. The wire CAS
contract, socket semantics, and gateway auth-token derivations are
unchanged. Kills the #113929 lock-contention bug class structurally and
nets around -2.9k lines.

* fix(infra): green CI gates and retire file-era exec approvals tests

Break the migration-type import cycle with a leaf contract, regenerate the
plugin-SDK API and native i18n baselines for the intentional surface change,
drop unused exports, and replace the macOS file-era approvals test suite with
SQLite-backed behavior coverage per the obsolete-internals test policy.

* chore: green max-lines ratchet, native i18n baseline, and unused-export scan
2026-07-26 06:39:23 -04:00
Peter Steinberger
edecdbd05e
refactor(config): config-surface reduction tranche 3 — product consolidations (review request) (#111527)
* refactor(config): consolidate media model lists

* refactor(config): unify memory configuration

* refactor(config): consolidate TTS ownership

* refactor(config): move typing policy to agents

* refactor(config): retire product-level config surfaces

* refactor(config): share scoped tool policy type

* chore(config): refresh generated baselines

* fix(config): honor agent typing overrides

* fix(config): migrate sibling config consumers

* refactor(infra): keep base64url decoder private

* fix(config): strip invalid legacy TTS values

* chore(config): refresh rebased baseline hash

* fix(doctor): route legacy messages.tts.realtime voice to talk during tts move

* refactor(config): polish final layout names

* refactor(config): freeze retired tuning defaults

* feat(config): add fast mode default symmetry

* refactor(config): key agent entries by id

* docs(config): update final layout reference

* test(config): cover final layout migrations

* chore(config): refresh final layout baselines

* fix(config): align final layout runtime readers

* fix(config): align remaining readers

* fix(config): stabilize final layout migrations

* fix(config): finalize config projection proof

* fix(config): address final layout review

* docs(release): preserve historical config names

* fix(config): complete keyed agent migration

* fix(config): close final migration gaps

* fix(config): finish full-branch review

* fix(config): complete runtime secret detection

* fix(config): close final review findings

* fix(config): finish canonical docs and heartbeat migration

* fix(config): integrate latest main after rebase

* refactor(env): isolate test-only controls

* refactor(env): isolate build and development controls

* refactor(env): collapse process identity indirection

* refactor(env): remove duplicate config and temp aliases

* docs(env): define the operator-facing allowlist

* ci(env): ratchet production variable count

* fix(env): remove stale provider helper import

* fix(env): make ratchet sorting explicit

* test(env): keep test seam in dead-code audit

* test(env): cover ratchet growth and boundary; document surface budgets

* docs(config): document tier-eval consolidations

* docs(config): clarify speech preference ownership

* test(memory): align retired tuning fixtures

* refactor(memory): freeze engine heuristics

* refactor(config): apply tier-eval tranche

* refactor(tts): move persona shaping to providers

* refactor(compaction): move prompt policy to providers

* test(config): align hookified prompt fixtures

* chore(deadcode): classify test-only exports

* chore(github): remove unused spawn helper

* chore(deadcode): classify queue diagnostics

* chore(deadcode): remove unused lane snapshot export

* chore(plugin-sdk): ratchet consolidated surface

* fix(config): integrate latest main after rebase
2026-07-21 20:28:43 -07:00
Peter Steinberger
a2ccbdfa96
feat(cli): list and resolve pending approvals headlessly (#111060)
* feat(cli): manage pending approvals

* fix(cli): show terminal-safe approval ids raw, reserve id64 tokens for hostile ids

* fix(cli): preserve opaque approval ids verbatim

* fix(cli): tokenize leading-hyphen approval ids for pasteability

* fix(cli): lossless utf16 id64 tokens for opaque approval ids

* fix(cli): resolve approval ids verbatim, no input trim

* fix(cli): scope-only approval auth, reviewer-safe system-agent summaries, skip ill-formed ids

* fix(cli): validate pending approval ids

* fix(cli): align approvals catalog and docs map
2026-07-18 23:23:49 -07:00
NIO
98fb858769
docs(cli): clarify that exec-policy show and approvals get exclude per-session /exec overrides (#94999)
* docs(cli): clarify exec-policy show and approvals get exclude per-session /exec overrides

* refactor(cli): centralize session exec override note

* test(cli): cover node exec override note

* test(cli): use complete node policy fixture

---------

Co-authored-by: NIO <nocodet@mail.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-11 02:58:37 -07:00
Peter Steinberger
d92d5774f5
fix(node): report Mac exec policy defaults (#103945) 2026-07-10 22:07:44 +01:00
Peter Steinberger
a7faec8ca1
fix(gateway): support native Windows exec approvals (#101669)
* fix(gateway): support native Windows exec approvals

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>

* chore: defer changelog entry to release

* test: use tracked approvals temp directories

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-07-07 14:50:59 +01:00
Peter Steinberger
f7d7148cf0
docs: rewrite published docs grounded in current source (#100142)
Source-grounded rewrite of 529 published docs pages with per-unit information-loss verification: 1,713 factual corrections cited to src/**, generated surfaces regenerated, frontmatter titles preserved for i18n, release notes pages untouched. All docs gates green.

Closes #100141
2026-07-05 00:32:47 -04:00
Vincent Koc
adad27d744
fix(exec): honor state dir approvals (#92056) 2026-06-11 09:30:56 +09:00
Devin Robison
49737a50af
Fail closed on exec approval timeout (#89938)
* Fail closed on exec approval timeout

* Align exec approval fallback default docs
2026-06-10 10:32:54 -06:00
Peter Steinberger
694ca50e97
Revert "refactor: move runtime state to SQLite"
This reverts commit f91de52f0d.
2026-05-13 13:33:38 +01:00
Peter Steinberger
f91de52f0d
refactor: move runtime state to SQLite
* refactor: remove stale file-backed shims

* fix: harden sqlite state ci boundaries

* refactor: store matrix idb snapshots in sqlite

* fix: satisfy rebased CI guardrails

* refactor: store current conversation bindings in sqlite table

* refactor: store tui last sessions in sqlite table

* refactor: reset sqlite schema history

* refactor: drop unshipped sqlite table migration

* refactor: remove plugin index file rollback

* refactor: drop unshipped sqlite sidecar migrations

* refactor: remove runtime commitments kv migration

* refactor: preserve kysely sync result types

* refactor: drop unshipped sqlite schema migration table

* test: keep session usage coverage sqlite-backed

* refactor: keep sqlite migration doctor-only

* refactor: isolate device legacy imports

* refactor: isolate push voicewake legacy imports

* refactor: isolate remaining runtime legacy imports

* refactor: tighten sqlite migration guardrails

* test: cover sqlite persisted enum parsing

* refactor: isolate legacy update and tui imports

* refactor: tighten sqlite state ownership

* refactor: move legacy imports behind doctor

* refactor: remove legacy session row lookup

* refactor: canonicalize memory transcript locators

* refactor: drop transcript path scope fallbacks

* refactor: drop runtime legacy session delivery pruning

* refactor: store tts prefs only in sqlite

* refactor: remove cron store path runtime

* refactor: use cron sqlite store keys

* refactor: rename telegram message cache scope

* refactor: read memory dreaming status from sqlite

* refactor: rename cron status store key

* refactor: stop remembering transcript file paths

* test: use sqlite locators in agent fixtures

* refactor: remove file-shaped commitments and cron store surfaces

* refactor: keep compaction transcript handles out of session rows

* refactor: derive transcript handles from session identity

* refactor: derive runtime transcript handles

* refactor: remove gateway session locator reads

* refactor: remove transcript locator from session rows

* refactor: store raw stream diagnostics in sqlite

* refactor: remove file-shaped transcript rotation

* refactor: hide legacy trajectory paths from runtime

* refactor: remove runtime transcript file bridges

* refactor: repair database-first rebase fallout

* refactor: align tests with database-first state

* refactor: remove transcript file handoffs

* refactor: sync post-compaction memory by transcript scope

* refactor: run codex app-server sessions by id

* refactor: bind codex runtime state by session id

* refactor: pass memory transcripts by sqlite scope

* refactor: remove transcript locator cleanup leftovers

* test: remove stale transcript file fixtures

* refactor: remove transcript locator test helper

* test: make cron sqlite keys explicit

* test: remove cron runtime store paths

* test: remove stale session file fixtures

* test: use sqlite cron keys in diagnostics

* refactor: remove runtime delivery queue backfill

* test: drop fake export session file mocks

* refactor: rename acp session read failure flag

* refactor: rename acp row session key

* refactor: remove session store test seams

* refactor: move legacy session parser tests to doctor

* refactor: reindex managed memory in place

* refactor: drop stale session store wording

* refactor: rename session row helpers

* refactor: rename sqlite session entry modules

* refactor: remove transcript locator leftovers

* refactor: trim file-era audit wording

* refactor: clean managed media through sqlite

* fix: prefer explicit agent for exports

* fix: use prepared agent for session resets

* fix: canonicalize legacy codex binding import

* test: rename state cleanup helper

* docs: align backup docs with sqlite state

* refactor: drop legacy Pi usage auth fallback

* refactor: move legacy auth profile imports to doctor

* refactor: keep Pi model discovery auth in memory

* refactor: remove MSTeams legacy learning key fallback

* refactor: store model catalog config in sqlite

* refactor: use sqlite model catalog at runtime

* refactor: remove model json compatibility aliases

* refactor: store auth profiles in sqlite

* refactor: seed copied auth profiles in sqlite

* refactor: make auth profile runtime sqlite-addressed

* refactor: migrate hermes secrets into sqlite auth store

* refactor: move plugin install config migration to doctor

* refactor: rename plugin index audit checks

* test: drop auth file assumptions

* test: remove legacy transcript file assertions

* refactor: drop legacy cli session aliases

* refactor: store skill uploads in sqlite

* refactor: keep subagent attachments in sqlite vfs

* refactor: drop subagent attachment cleanup state

* refactor: move legacy session aliases to doctor

* refactor: require node 24 for sqlite state runtime

* refactor: move provider caches into sqlite state

* fix: harden virtual agent filesystem

* refactor: enforce database-first runtime state

* refactor: rename compaction transcript rotation setting

* test: clean sqlite refactor test types

* refactor: consolidate sqlite runtime state

* refactor: model session conversations in sqlite

* refactor: stop deriving cron delivery from session keys

* refactor: stop classifying sessions from key shape

* refactor: hydrate announce targets from typed delivery

* refactor: route heartbeat delivery from typed sqlite context

* refactor: tighten typed sqlite session routing

* refactor: remove session origin routing shadow

* refactor: drop session origin shadow fixtures

* perf: query sqlite vfs paths by prefix

* refactor: use typed conversation metadata for sessions

* refactor: prefer typed session routing metadata

* refactor: require typed session routing metadata

* refactor: resolve group tool policy from typed sessions

* refactor: delete dead session thread info bridge

* Show Codex subscription reset times in channel errors (#80456)

* feat(plugin-sdk): consolidate session workflow APIs

* fix(agents): allow read-only agent mount reads

* [codex] refresh plugin regression fixtures

* fix(agents): restore compaction gateway logs

* test: tighten gateway startup assertions

* Redact persisted secret-shaped payloads [AI] (#79006)

* test: tighten device pair notify assertions

* test: tighten hermes secret assertions

* test: assert matrix client error shapes

* test: assert config compat warnings

* fix(heartbeat): remap cron-run exec events to session keys (#80214)

* fix(codex): route btw through native side threads

* fix(auth): accept friendly OpenAI order for Codex profiles

* fix(codex): rotate auth profiles inside harness

* fix: keep browser status page probe within timeout

* test: assert agents add outputs

* test: pin cron read status

* fix(agents): avoid Pi resource discovery stalls

Co-authored-by: dataCenter430 <titan032000@gmail.com>

* fix: retire timed-out codex app-server clients

* test: tighten qa lab runtime assertions

* test: check security fix outputs

* test: verify extension runtime messages

* feat(wake): expose typed sessionKey on wake protocol + system event CLI

* fix(gateway): await session_end during shutdown drain and track channel + compaction lifecycle paths (#57790)

* test: guard talk consult call helper

* fix(codex): scale context engine projection (#80761)

* fix(codex): scale context engine projection

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* chore: align Codex projection changelog

* chore: realign Codex projection changelog

* fix: isolate Codex projection patch

---------

Co-authored-by: Eva (agent) <eva+agent-78055@100yen.org>
Co-authored-by: Josh Lehman <josh@martian.engineering>

* refactor: move agent runtime state toward piless

* refactor: remove cron session reaper

* refactor: move session management to sqlite

* refactor: finish database-first state migration

* chore: refresh generated sqlite db types

* refactor: remove stale file-backed shims

* test: harden kysely type coverage

# Conflicts:
#	.agents/skills/kysely-database-access/SKILL.md
#	src/infra/kysely-sync.types.test.ts
#	src/proxy-capture/store.sqlite.test.ts
#	src/state/openclaw-agent-db.test.ts
#	src/state/openclaw-state-db.test.ts

* refactor: remove cron store path runtime

* refactor: keep compaction transcript handles out of session rows

* refactor: derive embedded transcripts from sqlite identity

* refactor: remove embedded transcript locator handoff

* refactor: remove runtime transcript file bridges

* refactor: remove transcript file handoffs

* refactor: remove MSTeams legacy learning key fallback

* refactor: store model catalog config in sqlite

* refactor: use sqlite model catalog at runtime

# Conflicts:
#	docs/cli/secrets.md
#	docs/gateway/authentication.md
#	docs/gateway/secrets.md

* fix: keep oauth sibling sync sqlite-local

# Conflicts:
#	src/commands/onboard-auth.test.ts

* refactor: remove task session store maintenance

# Conflicts:
#	src/commands/tasks.ts

* refactor: keep diagnostics in state sqlite

* refactor: enforce database-first runtime state

* refactor: consolidate sqlite runtime state

* Show Codex subscription reset times in channel errors (#80456)

* fix(codex): refresh subscription limit resets

* fix(codex): format reset times for channels

* Update CHANGELOG with latest changes and fixes

Updated CHANGELOG with recent fixes and improvements.

* fix(codex): keep command load failures on codex surface

* fix(codex): format account rate limits as rows

* fix(codex): summarize account limits as usage status

* fix(codex): simplify account limit status

* test: tighten subagent announce queue assertion

* test: tighten session delete lifecycle assertions

* test: tighten cron ops assertions

* fix: track cron execution milestones

* test: tighten hermes secret assertions

* test: assert matrix sync store payloads

* test: assert config compat warnings

* fix(codex): align btw side thread semantics

* fix(codex): honor codex fallback blocking

* fix(agents): avoid Pi resource discovery stalls

* test: tighten codex event assertions

* test: tighten cron assertions

* Fix Codex app-server OAuth harness auth

* refactor: move agent runtime state toward piless

* refactor: move device and push state to sqlite

* refactor: move runtime json state imports to doctor

* refactor: finish database-first state migration

* chore: refresh generated sqlite db types

* refactor: clarify cron sqlite store keys

* refactor: remove stale file-backed shims

* refactor: bind codex runtime state by session id

* test: expect sqlite trajectory branch export

* refactor: rename session row helpers

* fix: keep legacy device identity import in doctor

* refactor: enforce database-first runtime state

* refactor: consolidate sqlite runtime state

* build: align pi contract wrappers

* chore: repair database-first rebase

* refactor: remove session file test contracts

* test: update gateway session expectations

* refactor: stop routing from session compatibility shadows

* refactor: stop persisting session route shadows

* refactor: use typed delivery context in clients

* refactor: stop echoing session route shadows

* refactor: repair embedded runner rebase imports

# Conflicts:
#	src/agents/pi-embedded-runner/run/attempt.tool-call-argument-repair.ts

* refactor: align pi contract imports

* refactor: satisfy kysely sync helper guard

* refactor: remove file transcript bridge remnants

* refactor: remove session locator compatibility

* refactor: remove session file test contracts

* refactor: keep rebase database-first clean

* refactor: remove session file assumptions from e2e

* docs: clarify database-first goal state

* test: remove legacy store markers from sqlite runtime tests

* refactor: remove legacy store assumptions from runtime seams

* refactor: align sqlite runtime helper seams

* test: update memory recall sqlite audit mock

* refactor: align database-first runtime type seams

* test: clarify doctor cron legacy store names

* fix: preserve sqlite session route projections

* test: fix copilot token cache test syntax

* docs: update database-first proof status

* test: align database-first test fixtures

* docs: update database-first proof status

* refactor: clean extension database-first drift

* test: align agent session route proof

* test: clarify doctor legacy path fixtures

* chore: clean database-first changed checks

* chore: repair database-first rebase markers

* build: allow baileys git subdependency

* chore: repair exp-vfs rebase drift

* chore: finish exp-vfs rebase cleanup

* chore: satisfy rebase lint drift

* chore: fix qqbot rebase type seam

* chore: fix rebase drift leftovers

* fix: keep auth profile oauth secrets out of sqlite

* fix: repair rebase drift tests

* test: stabilize pairing request ordering

* test: use source manifests in plugin contract checks

* fix: restore gateway session metadata after rebase

* fix: repair database-first rebase drift

* fix: clean up database-first rebase fallout

* test: stabilize line quick reply receipt time

* fix: repair extension rebase drift

* test: keep transcript redaction tests sqlite-backed

* fix: carry injected transcript redaction through sqlite

* chore: clean database branch rebase residue

* fix: repair database branch CI drift

* fix: repair database branch CI guard drift

* fix: stabilize oauth tls preflight test

* test: align database branch fast guards

* test: repair build artifact boundary guards

* chore: clean changelog rebase markers

---------

Co-authored-by: pashpashpash <nik@vault77.ai>
Co-authored-by: Eva <eva@100yen.org>
Co-authored-by: stainlu <stainlu@newtype-ai.org>
Co-authored-by: Jason Zhou <jason.zhou.design@gmail.com>
Co-authored-by: Ruben Cuevas <hi@rubencu.com>
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com>
Co-authored-by: Shakker <shakkerdroid@gmail.com>
Co-authored-by: Kaspre <36520309+Kaspre@users.noreply.github.com>
Co-authored-by: dataCenter430 <titan032000@gmail.com>
Co-authored-by: Kaspre <kaspre@gmail.com>
Co-authored-by: pandadev66 <nova.full.stack@outlook.com>
Co-authored-by: Eva <admin@100yen.org>
Co-authored-by: Eva (agent) <eva+agent-78055@100yen.org>
Co-authored-by: Josh Lehman <josh@martian.engineering>
Co-authored-by: jeffjhunter <support@aipersonamethod.com>
2026-05-13 13:15:12 +01:00
Vincent Koc
8d1f98ef08
docs(gateway,platforms,cli): add Related sections to entry and reference pages 2026-04-23 20:08:26 -07:00
Vincent Koc
2777b089b5
docs: normalize frontmatter titles to sentence case 2026-04-23 13:15:17 -07:00
Tak Hoffman
4bf94aa0d6
feat: add local exec-policy CLI (#64050)
* feat: add local exec-policy CLI

* fix: harden exec-policy CLI output

* fix: harden exec approvals writes

* fix: tighten local exec-policy sync

* docs: document exec-policy CLI

* fix: harden exec-policy rollback and approvals path checks

* fix: reject exec-policy sync when host remains node

* fix: validate approvals path before mkdir

* fix: guard exec-policy rollback against newer approvals writes

* fix: restore exec approvals via hardened rollback path

* fix: guard exec-policy config writes with base hash

* docs: add exec-policy changelog entry

* fix: clarify exec-policy show for node host

* fix: strip stale exec-policy decisions
2026-04-10 01:16:03 -05:00
Peter Steinberger
1d1c52e6e6
docs: refresh mcp approvals and hooks refs 2026-04-04 08:46:37 +01:00
Peter Steinberger
45c8207ef2 fix(exec): clarify auto routing semantics (#58897) (thanks @vincentkoc) 2026-04-03 02:37:12 +09:00
Peter Steinberger
c678ae7e7a
feat(exec): default host exec to yolo 2026-04-02 14:52:51 +01:00
Gustavo Madeira Santana
ba735d0158
Exec approvals: unify effective policy reporting and actions (#59283)
Merged via squash.

Prepared head SHA: d579b97a93
Co-authored-by: gumadeiras <5599352+gumadeiras@users.noreply.github.com>
Co-authored-by: gumadeiras <5599352+gumadeiras@users.noreply.github.com>
Reviewed-by: @gumadeiras
2026-04-01 22:02:39 -04:00
Seb Slight
abcaa8c7a9
Docs: add nav titles across docs (#5689) 2026-01-31 15:04:03 -06:00
cpojer
8cab78abbc
chore: Run pnpm format:fix. 2026-01-31 21:13:13 +09:00
Peter Steinberger
9a7160786a refactor: rename to openclaw 2026-01-30 03:16:21 +01:00
Peter Steinberger
6d16a658e5 refactor: rename clawdbot to moltbot with legacy compat 2026-01-27 12:21:02 +00:00
Peter Steinberger
40646c73af feat: improve exec approvals defaults and wildcard 2026-01-21 09:55:10 +00:00
Peter Steinberger
3686bde783 feat: add exec approvals tooling and service status 2026-01-18 15:23:41 +00:00