Replace the review walkthrough with the supplied Apple review notes and update documentation, Fastlane, and PDF tooling to use the new Markdown filename.
* feat(release): add the resumable release:stable orchestrator
pnpm release:stable <version> drives one regular stable release as a
resumable state machine (cut, validate, publish, sync-beta, flip-github,
macos, closeout) over the existing helpers, with two operator prompts,
--from/--status/--dry-run, capability probes for the concurrent publish
parent, approval receipt, and closeout changes, and Next: commands on
every refusal. RELEASING.md leads with it and keeps the manual fallback.
* fix(release): bind release:stable child gates to the tooling tag and lock the state directory
Sweep and approve only bot-dispatched children whose head_branch is this
release's protected tooling tag, selected by exact workflow path (the core
OpenClaw NPM Release child was missed by the name regex), and refuse a
second release:stable process on the same state directory.
* fix(release): stop release:stable from mutating child runs and bind dispatch reconciliation to the operator
The API cannot prove which publish parent dispatched a child, so the
orchestrator no longer approves or cancels children: it approves only the
recorded parent's npm-release gate and prints the exact child-approval and
stale-child sweep commands until the approval receipt and self-sweeping
parent are present at the tooling SHA. Runs dispatched on main are
reconciled by workflow path, ref, the operator's login, and a bounded
window, refusing on ambiguity; stale-lock takeover retries the exclusive
create.
* chore(deps): refresh dependencies with a seven-day cutoff
* fix(deps): preserve Teams and jsdom integration contracts
Use the Teams SDK public token and processing APIs while keeping SSO sender
checks ahead of native token operations. Remove obsolete ambient declarations
and route workarounds, and cover the SDK routing with real processing tests.
Adapt the test environment to jsdom private-field bindings, preserve file bytes
and registry cleanup, and preload it through native Node and Bun workers.
* fix(test): preserve jsdom window and fixture contracts
* fix(ci): keep typecheck cache reuse within matching inputs
* fix(update): finish Windows updates after state migration
* test(update): release Windows fixture coordinators before cleanup
* test(update): avoid shadowing migration database in cleanup assertion
* test(ci): allow small Windows fixture timing overage
Share build-scoped compile-cache ownership between the launcher and runtime. Reuse inherited namespaces, avoid redundant respawns, and retire superseded builds with best-effort seven-day and 512 MiB maintenance.
Testbox: 304 focused tests passed with one Bun-only skip; pinned changed-file checks passed. Thirty child launches used 41,544 bytes instead of 1,185,000 bytes, and same-build launch time fell from 2.46 s to 1.22 s. Persistent external-plugin source capture reuse remains outside this scoped change.
* feat(update): let the candidate decide update admission
Stage package targets once, run the candidate's read-only admission against
an explicit live installation, and reuse the stage after admission. Keep
managed-service ownership and every update mutation with the installed
supervisor. Fall back to installed checks for unsupported or failed handoffs.
The new cross-process protocol between an installed updater and a staged
candidate needs one private context-path handoff variable, mirroring existing
post-core context variables. Approve only OPENCLAW_UPDATE_ADMISSION_CONTEXT
for the exact 491-to-492 ratchet transition; no other new names. The CLI option
is the only operator override, and lease/grant authority is unchanged.
* test(update): prove candidate admission in first-hop updates
Cover candidate ownership, markerless fallback, and missing custom plugin
paths with configuration-byte preservation after update and Doctor. Exercise
the packaged admission entry with a pending lifecycle marker and unchanged
profile artifacts. Keep the historical refusal as a separate control.
* docs(update): describe candidate-owned admission
Explain the installed/candidate ownership split, internal context protocol,
CLI-only admission override, fallback behavior, and additive run metadata.
Older installed updaters retain their own pre-staging refusals.
* fix(update): preserve admission startup and stage ownership
Keep persisted admission schemas independent of transport and supervisor
state, and put shared CLI catalog types in a passive leaf to avoid eager
import cycles. Register the internal command's fixed JSON output and the
standalone packaged-entry probe, and regenerate the Swift run projection.
Close fresh-profile stages only in the scope that created them. Preserve
candidate-default cleanup coverage while identifying tests that exercise
the installed admission contract explicitly.
Validated with focused CI failure replays, import-cycle and protocol checks,
compatibility inventory, and full changed checks on a byte-verified isolated
checkout. The original CI failures and source-scoped remote proof remain
recorded in the PR.
* test(update): compare runtime previews with installed admission
Dry runs use installed preflights. Make the real-update comparison in the
runtime-preview fixture select that same owner, preserving its pre-staging
refusal and selected-runner assertions. Default candidate ordering retains
its dedicated CLI coverage.
* test(update): assemble the credential fixture URL at runtime
The admission context test proved artifact credentials never reach the private context by using a literal user:password URL. Build that URL with the URL API instead so no credential-shaped literal exists in source, which is what the ClawSweeper input-safety scan rejected.
* fix(update): keep Node runtime recovery with the installed updater
* fix(update): accept candidate Node engine facts in the update-run schema
* test(update): split the admission test support module
* test(update): return an explicit value from the admission npm fixture
The split fixture callback mixed a bare return with value returns, which oxlint's consistent-return rejects in CI.
* refactor(update): pass the admission context by argument
Use update admit --context with an absolute private-file path, reject malformed invocations before startup, and retain protocol 1 and existing exit codes. Remove the context environment name and preserve the unchanged environment budget.
* refactor: remove TypeScript 6 from plugin runtime and tooling
Keep source plugin loading on Jiti and native module transforms, move development analysis and declaration builds to TypeScript 7, and preserve captured loader and input ownership contracts. Scaffolds compile to the same entry path without shipping a compiler in production.
* refactor: use native checker for restart preflight detection
* fix: keep test-directory docs out of native helper scans
* fix: preserve native compiler tooling across CI runtimes
Keep compiler-backed tests on the supported Node transport, preserve declared Windows aliases and partial-source analysis, and bind relocated SDK reports to their installed compiler. Retain strict package input admission and the existing fixture assertions.
* test: compare messaging guard diagnostics without sorting
* fix: bound native tooling memory and preserve bootstrap loading
* fix: bound native declaration builds with tsdown scheduling
* fix: retire compiler-only helpers from installed packages
* test: migrate routing import scan to native parser
* test(ui): wait for recovered model catalog receipt
Closes#156898
## What Problem This Solves
Large SQLite sessions can repeatedly exhaust the usage-refresh worker's 512 MiB heap, leaving usage totals missing or stale after an otherwise successful `sessions.usage` response.
## User Impact
Large sessions can finish refreshing without increasing the worker limit. Doctor reports bounded, per-session refresh failures and successful refreshes clear their warnings. No configuration, rollup format, database schema, or migration changes are required. Thanks @Conan-Scott for the detailed report and allocation control.
## Why This Change Was Made
The reader eagerly decoded the entire requested range before aggregation's 128-record batches. It now reads at most 1,024 rows and 8 MiB of decoded JSON per page, with one lookahead event (an individual oversized identity event is still accepted). A first pass retains compact navigation facts; selected bodies then feed the existing aggregation in ancestry order. Append validation, reset/leaf fallback, checkpoint checks, and conditional publication remain in place. Navigation metadata still scales with event count; payload bodies do not. The existing incognito host-frame reader is unchanged.
Refresh failures use the existing asynchronous core plugin-state storage, capped at 256 session facts, without storing raw error or transcript content. The cache owner clears each fact after successful publication; Doctor displays unresolved failures.
## Evidence
All heavy validation ran on Blacksmith Testbox (`blacksmith-testbox`, profile `openclaw-check`). Primary measurements and typechecks: lease `tbx_01m38g2xckkz1apk1smezhftg1`, Node 24.19.0, [run](https://github.com/openclaw/openclaw/actions/runs/35942606687). Final lint, guards, paging tests, and benchmark replay: lease `tbx_01m38k1hj8p9r5ay910z20s2sv`, [run](https://github.com/openclaw/openclaw/actions/runs/35946363096). Both leases stopped after validation.
The opt-in `node --import tsx scripts/bench-usage-refresh-memory.ts` fixture uses 24,000 events, 6,000 identity rows and 18,000 production zstd rows: 1,186,945,771 decoded bytes (1.105 GiB), with each event below 4 MiB. Both runs use the real refresh worker and its production 512 MiB limit; the baseline substitutes the original reader/scanner from `57f912b5f7` before executing the same harness with `--expect-oom`.
| Measurement | Original reader | Bounded reader |
| --- | --- | --- |
| Outcome | `ERR_WORKER_OUT_OF_MEMORY` | Complete, exact reference rollup |
| Sampled peak worker heap | 489.8 MiB | 228.9 MiB (53.3% lower) |
| Refresh duration | Failed after 2.39 s | Completed in 4.64 s |
The final-source replay completed in 4.40 s at 234.4 MiB sampled peak, again with exact rollup equality and below the asserted 384 MiB bound.
Heap sampling uses `Worker.getHeapStatistics()` every 10 ms; these are observed peaks, not complete allocation profiles. Failure time is not a throughput comparison. The complete rollup matched the bounded JSONL worker reference, independently checked for 24,000 records, 240,000 tokens, and 24,000 synthetic cost units. Rollup SHA-256: `f0f184c9b958a74211b6d66678bb1808497d07a96b6b8a84cfb1caabfdc9a856`.
- `node scripts/run-vitest.mjs src/infra/session-cost-usage-worker-refresh.test.ts src/infra/session-cost-usage-cache.worker.test.ts src/commands/doctor-usage-cost-cache.test.ts src/infra/session-cost-usage-worker-io.test.ts --maxWorkers=1`: 27 tests passed, 65.98 s total including cold worker compilation. New paging file: 5 tests / 7 ms. Changed worker file: 8 tests / 14.93 s; new failure→Doctor→recovery test: 1.76 s.
- `node scripts/check-changed.mjs`: all selected checks completed successfully across the initial run and resumed native-plan commands. Core types and all 25 test-typecheck shards passed; script/root-test types, lint, formatting, storage/import-cycle/security guards also passed. The initial run caught optional `Worker.resourceLimits` typing; lint caught parameter reassignment and benchmark brace/untyped-throw issues. All were corrected and their failed checks replayed successfully.
- Final `node scripts/run-vitest.mjs src/infra/session-cost-usage-worker-refresh.test.ts --maxWorkers=1`: 5 passed / 7 ms test time, 22.28 s wrapper wall including cold worker compilation.
- Final `node --import tsx scripts/bench-usage-refresh-memory.ts`: passed, same rollup hash as the paired measurement.
- Independent Codex review: no actionable P0–P2 findings.
Initial proof attempts exposed two fixture/setup issues, both corrected before collecting the measurements: missing Testbox checkout dependencies and a synthetic session row that bypassed canonical admission. The final fixture creates the session through its owner. Two later native checksum sync attempts timed out before validation; publishing the reviewed branch and warming a fresh lease recovered native targeted sync. No production data or Gateway deployment was used; this proves the synthetic allocation defect and rollup equality, not attribution of all reported Gateway RSS growth.
* fix: migrate workspace setup archives on Windows
* test(gateway): disable unrelated utility inference in fixtures
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* refactor: retire pre-June import and verification compatibility
Remove pre-June task, flow, and plugin-state sidecar imports, obsolete
runtime chunks, package/installer validation exceptions, the old MCP
attachment fallback, and the April self-upgrade lane with its orphan helpers.
Leave retired data files untouched and document migration through 2026.6.1.
Preserve June-and-later contracts and September delivery recovery receipts.
Refs #156190
* docs: route legacy upgrades through 2026.9.5
* test: await Telegram fixture lifecycle events
Replace the setup stopwatch with the actual stop event or terminal run outcome. Keep cancellation assertions and outer execution bounds, and prove early terminal outcomes fail promptly.
* fix(update): verify every managed Gateway restart attempt
Remove the generated shell and PowerShell restart helpers in favor of the
target installation's Gateway CLI. Verify attempted restarts even when the
target version is unknown, while retaining structured native refusal,
readiness-pending, and unhealthy-start outcomes.
Related: #150153
* fix(update): recognize empty managed service overrides
* fix(daemon): preserve retained PATH precedence during regeneration
Keep the existing safety admission and preservation audit unchanged, then reorder admitted PATH locations around the retained definition. Move PATH policy to its existing daemon owner and exercise normalization, repeated entries, and installer regeneration through planner/audit tests. Code success with reconciliation pending remains intentional.
Pin the published acpx patch and advance the independently published plugin to 2026.9.7 while preserving its host API floor. Keep the exact release-age exception bounded to the verified publication timestamp.
Queued shared GitHub publication retains its original requester and access grant across deferral and restart. Accepted results remain recoverable after access ends.
* feat: add selectable Code Mode executors
Default enabled Code Mode to trusted Node execution and move QuickJS into a bundled executor plugin. Preserve typed discovery, JavaScript-only execution, tool authorization, continuation ownership, and explicit legacy QuickJS selections. Add a web settings selector and document both security boundaries.
* refactor: finish Code Mode executor source cutover
Remove the retired core worker copies and regenerate config documentation for the requested QuickJS plugin. The 21 added plugin paths are standard plugin management fields; core and channel counts stay unchanged.
* refactor: narrow the Code Mode plugin contract
Keep only the executor and guest protocol exports consumed by the QuickJS plugin, budget that generic contract, and load the public plugin artifact through the existing runtime test boundary.
* refactor: align Code Mode workers with current runtime boundaries
Use the worker-side task server, keep asynchronous cleanup ownership explicit, and model the real Promise contracts in lifecycle fixtures. Regenerate the requested plugin config surface and budget the exact 35 public executor exports.
* refactor: keep executor implementation types private
* chore: regenerate code mode config baseline
* fix: satisfy Code Mode executor integration contracts
* test: cover QuickJS plugin metadata and exact settings titles
* test: retain QuickJS integration in the agent runtime suite
* test: keep Code Mode validation within lint and type-shard contracts
* chore(deps): refresh dependencies with seven-day cutoff
Advance eligible runtime, native, release, and development dependencies published by 2026-09-14T07:00:00Z. Preserve compatibility holds and existing reviewed newer pins. Synchronize release integrity checks and scoped overrides; remove the superseded mailparser override.
Preserve Clack cancellation inference with its precise sentinel type and isolate the Vertex proxy fixture from ambient credentials. Timestamp and checksum audits, targeted consumers, native builds/tests, and independent review validate the refresh; required hosted CI remains the landing gate.
* fix(deps): preserve Clack cancellation types in exported prompts
Give styled configure prompts the exact upstream return types so plugin SDK declaration emission can name the new cancellation sentinel. Runtime behavior and generic option values are unchanged.
* fix(deps): preserve release tooling and Android test contracts
Regenerate Ruby lock metadata with pinned Bundler 2.6.9, grant Robolectric 4.17 its documented module access only in Android test JVMs, and keep the precise cancellation type without growing an over-cap source file.
Both previously failing Ruby lock guards, the line-cap and core type checks, all three configured Android test-task JVM arguments, and the actual Robolectric interceptor before/after probe pass. Independent review found no actionable P0/P1 issues.
* fix(deps): close Rustls advisory and align mock session clocks
Rustls 0.23.45 has now completed the seven-day cooldown; update only the shared crate pin and lock to the existing security-fixed desktop version.
Advance accepted mock Gateway writes on the synthetic fixture timeline and correlate permission tests with the actual mutation and refresh. This repairs a reproduced CI fixture race without changing production behavior or weakening assertions.
Validation: 36 Rust gateway-client tests including four TLS handshakes, 50 fixture tests, nine browser cases, scoped changed checks, and independent P0/P1 review passed.
* test(ui): keep external session updates on the committed timeline
* test: stabilize approval and desktop CI fixtures
* build(workboard): refresh assets after dependency rebase
Adopt the released dependency across all direct consumers while retaining
ACPX's transitive 0.12 dependency. Reuse pooled hashing and positional reads
for workspace manifests without adding captured-content allocations or
changing descriptor, mutation, budget, and cancellation fences.
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Retain child close and pending tree-signal completion through shutdown and replacement. Preserve phase budgets and exclusive test-port claims, retire Windows PID authority at exit, and keep bind-probe errors in cleanup failures. Exercise the settlement and recovery boundaries in Windows CI.
* fix: allow Windows gateway startup with nested tilde paths
Isolate config validation from authored and resolved source snapshots before
runtime path normalization. Share startup input comparisons while retaining
include revision, environment drift, and approved repair protections.
Preserve validation-created agent projections and report the category of a
real startup input change without printing config values.
Fixes#154227. Thanks @easyteacher for the byte-level reproduction.
* fix(config): validate before isolating plugin config
* test(config): cover nested paths in Windows startup checks
* fix(config): compare snapshot resolution provenance
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* perf(state): move transcript reads off the Gateway thread
Reuse the existing history worker for durable transcript search and cursor deltas. Keep current sharing checks and display projection on the Gateway, and document the remaining database worker migration with a reproducible inventory.
Testbox proof: 5,000 rows and 50 viewers reduced caller-thread CPU by 96.7% for search and 7.3% for cursor history. Golden responses, 211 focused tests, build, type/lint/storage gates, inventory verification, and docs links passed.
* perf(state): isolate transcript search worker contracts
Move search request/result types into an import-free contract so worker protocol types do not depend on the query implementation. Register and document the inventory generator package commands.
Fix the architecture and unused-file CI failures. Exact failed guards, export scanning, core types, real-worker golden tests, formatting, and inventory regeneration passed on Testbox.
* fix(typesafe): distribute as an official external plugin
Exclude TypeSafe runtime from the core package and enroll @openclaw/typesafe in npm and ClawHub publication. Preserve the plugin ID, protected credentials, and decision-model configuration. Require the post-2026.9.5 decision API and document the pending supporting release.
* fix(typesafe): register the official external install catalog
Keep official package discovery and trust aligned with the TypeSafe distribution cutover. Existing catalog completeness and ClawHub-counterpart checks pass.
* feat(typesafe): support local System One decision models
Add an explicit loopback endpoint for Kev, without forwarding hosted credentials or changing managed proxy authority. Preserve strict answer validation while adapting local instructions, Score legends, and timing metadata. Keep the declared local model out of hosted inference. Document endpoint scope and runtime ownership.
* fix(typesafe): validate local payload types and document Kev
Preserve discriminated question types without assertions and regenerate config documentation for the requested baseUrl field. Add the pinned Kev setup and API-test commands exercised in live inference. Core and channel config budgets remain unchanged; the plugin budget grows by one intentional field.
* docs(agents): allow exact synthetic scanner fixture qualification
* fix(cua): update driver for reliable Linux key taps
* test(cua): bind the SDK refusal predicate callback
* test(ui): avoid token scanning in heap retention fixture
Keep all 64 exact previews, 32 MiB of source payloads, and the existing memory bound and deadlines. Use punctuation for the discarded tail so the test measures retention without spending most of its time scanning an irrelevant long token.
Resolve ACP model references against the connected harness catalog before useful turns, preserving exact model IDs, accepted settings, and conversation history.
Refs #124843.
Reviewed-by: @shakkernerd
Co-authored-by: Shakker <165377636+shakkernerd@users.noreply.github.com>
Prepare canonical assistant and tool-result payloads once per append and retain their serialized bytes across mutation-conflict retries. Keep authoritative parent, sequence, idempotency, generation, and writer checks inside the transaction.
A 200 KiB SessionManager append benchmark reduces median write hold from 7.821 ms to 1.864 ms. Preserve code-mode source decisions, media normalization, public persistence interfaces, and exactly-once behavior. No schema or configuration changes.
Refresh 13 direct dependency packages and 15 resolved versions published by September 13, 2026 at 14:50 UTC.
Preserve compatibility-constrained versions, patches, overrides and the existing strict cooldown. Retain YAML 2.9.0 for the verified release producer and frozen security-review runtime. Regenerate Workboard's content-addressed browser asset pointers.
Validated by exact-head CI run 35520400755 and security/merge-gate reconciliation 35521175227, plus local consumer, release-producer, publication-admission and unchanged UI-budget checks.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>