Commit graph

2090 commits

Author SHA1 Message Date
joshavant
932abb0a84
docs(ios): adopt Apple-specific App Review notes
Replace the review walkthrough with the supplied Apple review notes and update documentation, Fastlane, and PDF tooling to use the new Markdown filename.
2026-09-25 02:39:56 -05:00
Peter Steinberger
878ee97ecd
feat(release): add the resumable release:stable orchestrator (#157941)
* feat(release): add the resumable release:stable orchestrator

pnpm release:stable <version> drives one regular stable release as a
resumable state machine (cut, validate, publish, sync-beta, flip-github,
macos, closeout) over the existing helpers, with two operator prompts,
--from/--status/--dry-run, capability probes for the concurrent publish
parent, approval receipt, and closeout changes, and Next: commands on
every refusal. RELEASING.md leads with it and keeps the manual fallback.

* fix(release): bind release:stable child gates to the tooling tag and lock the state directory

Sweep and approve only bot-dispatched children whose head_branch is this
release's protected tooling tag, selected by exact workflow path (the core
OpenClaw NPM Release child was missed by the name regex), and refuse a
second release:stable process on the same state directory.

* fix(release): stop release:stable from mutating child runs and bind dispatch reconciliation to the operator

The API cannot prove which publish parent dispatched a child, so the
orchestrator no longer approves or cancels children: it approves only the
recorded parent's npm-release gate and prints the exact child-approval and
stale-child sweep commands until the approval receipt and self-sweeping
parent are present at the tooling SHA. Runs dispatched on main are
reconciled by workflow path, ref, the operator's login, and a bounded
window, refusing on ambiguity; stale-lock takeover retries the exclusive
create.
2026-09-24 23:46:36 -07:00
Peter Steinberger
2abecd703d
chore(deps): refresh dependencies with a seven-day cutoff (#157238)
* chore(deps): refresh dependencies with a seven-day cutoff

* fix(deps): preserve Teams and jsdom integration contracts

Use the Teams SDK public token and processing APIs while keeping SSO sender
checks ahead of native token operations. Remove obsolete ambient declarations
and route workarounds, and cover the SDK routing with real processing tests.

Adapt the test environment to jsdom private-field bindings, preserve file bytes
and registry cleanup, and preload it through native Node and Bun workers.

* fix(test): preserve jsdom window and fixture contracts

* fix(ci): keep typecheck cache reuse within matching inputs
2026-09-25 02:38:45 +00:00
Josh Avant
83d24ab022
fix: preserve channel-owner revocation across recovery (#157709) 2026-09-24 21:21:12 -05:00
Peter Steinberger
9332dfd14b
fix(packaging): avoid heap exhaustion on large bundles (#157471) 2026-09-24 16:21:21 -07:00
Peter Steinberger
2f4fae3c0d
fix(update): finish Windows updates after state migration (#157262)
* fix(update): finish Windows updates after state migration

* test(update): release Windows fixture coordinators before cleanup

* test(update): avoid shadowing migration database in cleanup assertion

* test(ci): allow small Windows fixture timing overage
2026-09-24 20:32:46 +00:00
Hannes Rudolph
2c84cd27f5
refactor(docs): retire Mintlify setup and preview the current site (#157544) 2026-09-24 14:28:39 -06:00
Peter Steinberger
3fadd8c3f7
perf(plugins): reuse and bound CLI compile caches (#157528)
Share build-scoped compile-cache ownership between the launcher and runtime. Reuse inherited namespaces, avoid redundant respawns, and retire superseded builds with best-effort seven-day and 512 MiB maintenance.

Testbox: 304 focused tests passed with one Bun-only skip; pinned changed-file checks passed. Thirty child launches used 41,544 bytes instead of 1,185,000 bytes, and same-build launch time fell from 2.46 s to 1.22 s. Persistent external-plugin source capture reuse remains outside this scoped change.
2026-09-24 20:18:39 +00:00
Vincent Koc
64b7465031
fix(skills): refresh skills after watched directories are replaced (#156324)
Some checks are pending
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pt-BR (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ru (push) Blocked by required conditions
Native App Locale Refresh / Refresh native sv (push) Blocked by required conditions
Native App Locale Refresh / Refresh native th (push) Blocked by required conditions
Native App Locale Refresh / Refresh native tr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native uk (push) Blocked by required conditions
Native App Locale Refresh / Refresh native vi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / no-tabs (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
2026-09-24 23:20:37 +08:00
Peter Steinberger
acffa7681f
feat(update): let the candidate decide update admission (#155632)
* feat(update): let the candidate decide update admission

Stage package targets once, run the candidate's read-only admission against
an explicit live installation, and reuse the stage after admission. Keep
managed-service ownership and every update mutation with the installed
supervisor. Fall back to installed checks for unsupported or failed handoffs.

The new cross-process protocol between an installed updater and a staged
candidate needs one private context-path handoff variable, mirroring existing
post-core context variables. Approve only OPENCLAW_UPDATE_ADMISSION_CONTEXT
for the exact 491-to-492 ratchet transition; no other new names. The CLI option
is the only operator override, and lease/grant authority is unchanged.

* test(update): prove candidate admission in first-hop updates

Cover candidate ownership, markerless fallback, and missing custom plugin
paths with configuration-byte preservation after update and Doctor. Exercise
the packaged admission entry with a pending lifecycle marker and unchanged
profile artifacts. Keep the historical refusal as a separate control.

* docs(update): describe candidate-owned admission

Explain the installed/candidate ownership split, internal context protocol,
CLI-only admission override, fallback behavior, and additive run metadata.
Older installed updaters retain their own pre-staging refusals.

* fix(update): preserve admission startup and stage ownership

Keep persisted admission schemas independent of transport and supervisor
state, and put shared CLI catalog types in a passive leaf to avoid eager
import cycles. Register the internal command's fixed JSON output and the
standalone packaged-entry probe, and regenerate the Swift run projection.

Close fresh-profile stages only in the scope that created them. Preserve
candidate-default cleanup coverage while identifying tests that exercise
the installed admission contract explicitly.

Validated with focused CI failure replays, import-cycle and protocol checks,
compatibility inventory, and full changed checks on a byte-verified isolated
checkout. The original CI failures and source-scoped remote proof remain
recorded in the PR.

* test(update): compare runtime previews with installed admission

Dry runs use installed preflights. Make the real-update comparison in the
runtime-preview fixture select that same owner, preserving its pre-staging
refusal and selected-runner assertions. Default candidate ordering retains
its dedicated CLI coverage.

* test(update): assemble the credential fixture URL at runtime

The admission context test proved artifact credentials never reach the private context by using a literal user:password URL. Build that URL with the URL API instead so no credential-shaped literal exists in source, which is what the ClawSweeper input-safety scan rejected.

* fix(update): keep Node runtime recovery with the installed updater

* fix(update): accept candidate Node engine facts in the update-run schema

* test(update): split the admission test support module

* test(update): return an explicit value from the admission npm fixture

The split fixture callback mixed a bare return with value returns, which oxlint's consistent-return rejects in CI.

* refactor(update): pass the admission context by argument

Use update admit --context with an absolute private-file path, reject malformed invocations before startup, and retain protocol 1 and existing exit codes. Remove the context environment name and preserve the unchanged environment budget.
2026-09-24 05:56:37 -07:00
Peter Steinberger
b4653c7deb
chore(release): close out 2026.9.6 on main (#156869) 2026-09-23 23:02:54 -07:00
Peter Steinberger
c8eab36020
refactor: run plugins and tooling without TypeScript 6 (#156829)
* refactor: remove TypeScript 6 from plugin runtime and tooling

Keep source plugin loading on Jiti and native module transforms, move development analysis and declaration builds to TypeScript 7, and preserve captured loader and input ownership contracts. Scaffolds compile to the same entry path without shipping a compiler in production.

* refactor: use native checker for restart preflight detection

* fix: keep test-directory docs out of native helper scans

* fix: preserve native compiler tooling across CI runtimes

Keep compiler-backed tests on the supported Node transport, preserve declared Windows aliases and partial-source analysis, and bind relocated SDK reports to their installed compiler. Retain strict package input admission and the existing fixture assertions.

* test: compare messaging guard diagnostics without sorting

* fix: bound native tooling memory and preserve bootstrap loading

* fix: bound native declaration builds with tsdown scheduling

* fix: retire compiler-only helpers from installed packages

* test: migrate routing import scan to native parser

* test(ui): wait for recovered model catalog receipt
2026-09-23 22:34:20 -07:00
Peter Steinberger
5b90a73498
fix(usage): prevent refresh OOMs on large SQLite sessions (#156937)
Closes #156898

## What Problem This Solves

Large SQLite sessions can repeatedly exhaust the usage-refresh worker's 512 MiB heap, leaving usage totals missing or stale after an otherwise successful `sessions.usage` response.

## User Impact

Large sessions can finish refreshing without increasing the worker limit. Doctor reports bounded, per-session refresh failures and successful refreshes clear their warnings. No configuration, rollup format, database schema, or migration changes are required. Thanks @Conan-Scott for the detailed report and allocation control.

## Why This Change Was Made

The reader eagerly decoded the entire requested range before aggregation's 128-record batches. It now reads at most 1,024 rows and 8 MiB of decoded JSON per page, with one lookahead event (an individual oversized identity event is still accepted). A first pass retains compact navigation facts; selected bodies then feed the existing aggregation in ancestry order. Append validation, reset/leaf fallback, checkpoint checks, and conditional publication remain in place. Navigation metadata still scales with event count; payload bodies do not. The existing incognito host-frame reader is unchanged.

Refresh failures use the existing asynchronous core plugin-state storage, capped at 256 session facts, without storing raw error or transcript content. The cache owner clears each fact after successful publication; Doctor displays unresolved failures.

## Evidence

All heavy validation ran on Blacksmith Testbox (`blacksmith-testbox`, profile `openclaw-check`). Primary measurements and typechecks: lease `tbx_01m38g2xckkz1apk1smezhftg1`, Node 24.19.0, [run](https://github.com/openclaw/openclaw/actions/runs/35942606687). Final lint, guards, paging tests, and benchmark replay: lease `tbx_01m38k1hj8p9r5ay910z20s2sv`, [run](https://github.com/openclaw/openclaw/actions/runs/35946363096). Both leases stopped after validation.

The opt-in `node --import tsx scripts/bench-usage-refresh-memory.ts` fixture uses 24,000 events, 6,000 identity rows and 18,000 production zstd rows: 1,186,945,771 decoded bytes (1.105 GiB), with each event below 4 MiB. Both runs use the real refresh worker and its production 512 MiB limit; the baseline substitutes the original reader/scanner from `57f912b5f7` before executing the same harness with `--expect-oom`.

| Measurement | Original reader | Bounded reader |
| --- | --- | --- |
| Outcome | `ERR_WORKER_OUT_OF_MEMORY` | Complete, exact reference rollup |
| Sampled peak worker heap | 489.8 MiB | 228.9 MiB (53.3% lower) |
| Refresh duration | Failed after 2.39 s | Completed in 4.64 s |

The final-source replay completed in 4.40 s at 234.4 MiB sampled peak, again with exact rollup equality and below the asserted 384 MiB bound.

Heap sampling uses `Worker.getHeapStatistics()` every 10 ms; these are observed peaks, not complete allocation profiles. Failure time is not a throughput comparison. The complete rollup matched the bounded JSONL worker reference, independently checked for 24,000 records, 240,000 tokens, and 24,000 synthetic cost units. Rollup SHA-256: `f0f184c9b958a74211b6d66678bb1808497d07a96b6b8a84cfb1caabfdc9a856`.

- `node scripts/run-vitest.mjs src/infra/session-cost-usage-worker-refresh.test.ts src/infra/session-cost-usage-cache.worker.test.ts src/commands/doctor-usage-cost-cache.test.ts src/infra/session-cost-usage-worker-io.test.ts --maxWorkers=1`: 27 tests passed, 65.98 s total including cold worker compilation. New paging file: 5 tests / 7 ms. Changed worker file: 8 tests / 14.93 s; new failure→Doctor→recovery test: 1.76 s.
- `node scripts/check-changed.mjs`: all selected checks completed successfully across the initial run and resumed native-plan commands. Core types and all 25 test-typecheck shards passed; script/root-test types, lint, formatting, storage/import-cycle/security guards also passed. The initial run caught optional `Worker.resourceLimits` typing; lint caught parameter reassignment and benchmark brace/untyped-throw issues. All were corrected and their failed checks replayed successfully.
- Final `node scripts/run-vitest.mjs src/infra/session-cost-usage-worker-refresh.test.ts --maxWorkers=1`: 5 passed / 7 ms test time, 22.28 s wrapper wall including cold worker compilation.
- Final `node --import tsx scripts/bench-usage-refresh-memory.ts`: passed, same rollup hash as the paired measurement.
- Independent Codex review: no actionable P0–P2 findings.

Initial proof attempts exposed two fixture/setup issues, both corrected before collecting the measurements: missing Testbox checkout dependencies and a synthetic session row that bypassed canonical admission. The final fixture creates the session through its owner. Two later native checksum sync attempts timed out before validation; publishing the reviewed branch and warming a fresh lease recovered native targeted sync. No production data or Gateway deployment was used; this proves the synthetic allocation defect and rollup equality, not attribution of all reported Gateway RSS growth.
2026-09-24 02:50:28 +00:00
Peter Steinberger
039972e063
fix: migrate workspace setup archives on Windows (#156704)
* fix: migrate workspace setup archives on Windows

* test(gateway): disable unrelated utility inference in fixtures

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-23 17:24:11 -07:00
Peter Steinberger
7dbfab8c2c
chore(deps): refresh dependencies with a seven-day cutoff (#156363)
* chore(deps): refresh dependencies with a seven-day cutoff

* fix(deps): preserve runtime and tooling contracts after upgrades

* fix(deps): align fixture lifetimes and preserve Unicode contracts

* fix(ui): publish goal rejections and align integration fixtures

Publish rejected goal actions through the existing renderer lifecycle. Start the Session Share service in integration fixtures, preserve same-job workflow authority, and distinguish pnpm launcher escalation from detached cleanup ownership.

* test: follow Corepack ownership and await navigation handoff
2026-09-23 17:35:48 +00:00
Peter Steinberger
3bbaf039b5
test(skills): retire expired same-schema downgrade proof (#156575)
* test(skills): retire expired same-schema downgrade proof

* test(gateway): await committed recap publication

* chore: merge main and retain landed recap readiness fix

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-23 10:24:04 -07:00
Jason (Json)
a5fe21a5e7
fix(worktrees): recover interrupted clean removals (#156529)
* fix(worktrees): recover interrupted clean removals

* refactor(worktrees): name retained Git configuration reader precisely

* test(worktrees): settle recovery fixture state before cleanup
2026-09-23 08:22:35 -06:00
Peter Steinberger
3e4ab6bed8
refactor: retire pre-June import and verification compatibility (#156285)
* refactor: retire pre-June import and verification compatibility

Remove pre-June task, flow, and plugin-state sidecar imports, obsolete
runtime chunks, package/installer validation exceptions, the old MCP
attachment fallback, and the April self-upgrade lane with its orphan helpers.

Leave retired data files untouched and document migration through 2026.6.1.
Preserve June-and-later contracts and September delivery recovery receipts.

Refs #156190

* docs: route legacy upgrades through 2026.9.5

* test: await Telegram fixture lifecycle events

Replace the setup stopwatch with the actual stop event or terminal run outcome. Keep cancellation assertions and outer execution bounds, and prove early terminal outcomes fail promptly.
2026-09-23 02:22:22 -07:00
Peter Steinberger
741a1c84cd
feat: use protected model credentials in Crabbox applications (#156207)
* feat: use protected model credentials in Crabbox applications

* refactor: use the shared model egress lazy runtime owner
2026-09-23 07:36:15 +00:00
Peter Steinberger
dc063e7bc0
chore(deps): update fs-safe to 0.18.2 (#156262) 2026-09-23 07:16:19 +00:00
Peter Steinberger
b855e24dac
fix(update): verify every managed Gateway restart attempt (#155355)
* fix(update): verify every managed Gateway restart attempt

Remove the generated shell and PowerShell restart helpers in favor of the
target installation's Gateway CLI. Verify attempted restarts even when the
target version is unknown, while retaining structured native refusal,
readiness-pending, and unhealthy-start outcomes.

Related: #150153

* fix(update): recognize empty managed service overrides

* fix(daemon): preserve retained PATH precedence during regeneration

Keep the existing safety admission and preservation audit unchanged, then reorder admitted PATH locations around the retained definition. Move PATH policy to its existing daemon owner and exercise normalization, repeated entries, and installer regeneration through planner/audit tests. Code success with reconciliation pending remains intentional.
2026-09-22 19:32:37 -07:00
Vincent Koc
59a734b735
feat: export committed plugin inventory for resource coverage (#155775) 2026-09-23 09:14:59 +08:00
Sarah Fortune
488019c3c3
refactor(agents): share external harness session and attempt machinery (#152181)
* refactor: share external harness session coordination

* refactor(agents): keep shared session helpers behind private runtime SDK

* refactor(agents): share native session admission and attempt execution

* refactor(agents): sync private attempt runtime exports

* style(agents): format shared harness extraction

* refactor(agents): simplify shared harness extraction

* style(agents): format simplified harness helpers

* fix(agents): align shared harness checks and fixtures

* style(agents): format receiver-independent initializer

* fix(agents): preserve extension fixture boundaries after extraction

* style(test): format shared initializer fixture setup

* fix(plugin-sdk): sync generated harness runtime export ordering

---------

Co-authored-by: Sarah Fortune <sarah.fortune@gmail.com>
2026-09-22 16:31:59 -07:00
Vincent Koc
efc15b8fd4
fix(acpx): adopt acpx 0.19.1 runtime fixes (#155760)
Pin the published acpx patch and advance the independently published plugin to 2026.9.7 while preserving its host API floor. Keep the exact release-age exception bounded to the verified publication timestamp.
2026-09-23 01:38:42 +08:00
Vincent Koc
439396ff1e
chore(deps): update fs-safe to 0.18.1 (#155771)
* chore(deps): update fs-safe to 0.18.1

* chore(deps): integrate fixed main for fs-safe validation

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-23 00:21:15 +08:00
Vincent Koc
b3f097deb9
fix(acpx): adopt lifecycle repairs without blocking session migration (#155377)
* fix(acpx): adopt process and session lifecycle repairs

* fix(acpx): preserve Doctor migration with canonical record IDs
2026-09-22 15:42:22 +08:00
Shakker
65e49fa200
fix: bind queued GitHub publication to its requester (#154477)
Queued shared GitHub publication retains its original requester and access grant across deferral and restart. Accepted results remain recoverable after access ends.
2026-09-22 06:20:21 +01:00
Peter Steinberger
09e06495a3
feat: run Code Mode on Node or isolated QuickJS (#154522)
* feat: add selectable Code Mode executors

Default enabled Code Mode to trusted Node execution and move QuickJS into a bundled executor plugin. Preserve typed discovery, JavaScript-only execution, tool authorization, continuation ownership, and explicit legacy QuickJS selections. Add a web settings selector and document both security boundaries.

* refactor: finish Code Mode executor source cutover

Remove the retired core worker copies and regenerate config documentation for the requested QuickJS plugin. The 21 added plugin paths are standard plugin management fields; core and channel counts stay unchanged.

* refactor: narrow the Code Mode plugin contract

Keep only the executor and guest protocol exports consumed by the QuickJS plugin, budget that generic contract, and load the public plugin artifact through the existing runtime test boundary.

* refactor: align Code Mode workers with current runtime boundaries

Use the worker-side task server, keep asynchronous cleanup ownership explicit, and model the real Promise contracts in lifecycle fixtures. Regenerate the requested plugin config surface and budget the exact 35 public executor exports.

* refactor: keep executor implementation types private

* chore: regenerate code mode config baseline

* fix: satisfy Code Mode executor integration contracts

* test: cover QuickJS plugin metadata and exact settings titles

* test: retain QuickJS integration in the agent runtime suite

* test: keep Code Mode validation within lint and type-shard contracts
2026-09-21 17:33:04 -07:00
Peter Steinberger
d0f40a8de2
chore(deps): refresh dependencies with seven-day cutoff (#154652)
* chore(deps): refresh dependencies with seven-day cutoff

Advance eligible runtime, native, release, and development dependencies published by 2026-09-14T07:00:00Z. Preserve compatibility holds and existing reviewed newer pins. Synchronize release integrity checks and scoped overrides; remove the superseded mailparser override.

Preserve Clack cancellation inference with its precise sentinel type and isolate the Vertex proxy fixture from ambient credentials. Timestamp and checksum audits, targeted consumers, native builds/tests, and independent review validate the refresh; required hosted CI remains the landing gate.

* fix(deps): preserve Clack cancellation types in exported prompts

Give styled configure prompts the exact upstream return types so plugin SDK declaration emission can name the new cancellation sentinel. Runtime behavior and generic option values are unchanged.

* fix(deps): preserve release tooling and Android test contracts

Regenerate Ruby lock metadata with pinned Bundler 2.6.9, grant Robolectric 4.17 its documented module access only in Android test JVMs, and keep the precise cancellation type without growing an over-cap source file.

Both previously failing Ruby lock guards, the line-cap and core type checks, all three configured Android test-task JVM arguments, and the actual Robolectric interceptor before/after probe pass. Independent review found no actionable P0/P1 issues.

* fix(deps): close Rustls advisory and align mock session clocks

Rustls 0.23.45 has now completed the seven-day cooldown; update only the shared crate pin and lock to the existing security-fixed desktop version.

Advance accepted mock Gateway writes on the synthetic fixture timeline and correlate permission tests with the actual mutation and refresh. This repairs a reproduced CI fixture race without changing production behavior or weakening assertions.

Validation: 36 Rust gateway-client tests including four TLS handshakes, 50 fixture tests, nine browser cases, scoped changed checks, and independent P0/P1 review passed.

* test(ui): keep external session updates on the committed timeline

* test: stabilize approval and desktop CI fixtures

* build(workboard): refresh assets after dependency rebase
2026-09-21 16:55:54 -07:00
Peter Steinberger
c65911334f
refactor: compact agent storage and index full-text maintenance (#153683)
* refactor: compact agent payloads and index full-text maintenance

* perf: reuse transcript metadata plans during agent migration

* fix: preserve storage upgrade fixtures and backup projections

* fix: complete compact-storage validation repairs

* fix: complete compact-storage CI contracts

* test: retain upgrade failure details and stabilize cleanup checks

* test: qualify upgrades with immutable fixture package identities

* fix: qualify storage fixtures and binary types

* docs(memory): correct storage migration schema version
2026-09-21 16:23:13 -07:00
Peter Steinberger
cf92474409
refactor(fs-safe): adopt 0.18 workspace readers (#155108)
Adopt the released dependency across all direct consumers while retaining
ACPX's transitive 0.12 dependency. Reuse pooled hashing and positional reads
for workspace manifests without adding captured-content allocations or
changing descriptor, mutation, budget, and cancellation fences.

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-21 13:12:15 -07:00
Peter Steinberger
3e68350c7c
fix: join local provider child cleanup before releasing ownership
Retain child close and pending tree-signal completion through shutdown and replacement. Preserve phase budgets and exclusive test-port claims, retire Windows PID authority at exit, and keep bind-probe errors in cleanup failures. Exercise the settlement and recovery boundaries in Windows CI.
2026-09-21 12:15:57 -07:00
Vincent Koc
b25f3d8296
fix(sqlite): reclaim scratch files when storage is full (#154937)
* fix(sqlite): reclaim scratch files when storage is full

* fix(maintainers): retain snapshot retirement wrapper source
2026-09-21 17:56:51 +00:00
Vincent Koc
1b6962a92c
fix(packaging): omit unused native Bash parsers from npm installs (#154843)
* fix(packaging): omit native Bash parser from npm installs

* test(build): resolve nested plugin slots in config checks
2026-09-21 22:35:50 +08:00
Peter Steinberger
6c3c9dd594
perf(plugins): reduce callback scope overhead (#154625)
* perf(plugins): reduce callback scope overhead

* perf(plugins): clarify benchmark method interception

* perf(plugins): register the invocation benchmark command

* perf(plugins): keep the measured invocation optimization focused

* perf(plugins): stabilize CI question fixture readiness
2026-09-21 11:40:38 +00:00
Peter Steinberger
82e4576d14
improve(discord): speed up source worker startup on supported hosts (#154615)
* perf(discord): narrow audio worker media imports

* fix(plugins): preserve published host support with narrow worker imports
2026-09-21 11:12:44 +00:00
Peter Steinberger
285411f632
fix: allow Windows gateway startup with nested tilde paths (#154331)
* fix: allow Windows gateway startup with nested tilde paths

Isolate config validation from authored and resolved source snapshots before
runtime path normalization. Share startup input comparisons while retaining
include revision, environment drift, and approved repair protections.

Preserve validation-created agent projections and report the category of a
real startup input change without printing config values.

Fixes #154227. Thanks @easyteacher for the byte-level reproduction.

* fix(config): validate before isolating plugin config

* test(config): cover nested paths in Windows startup checks

* fix(config): compare snapshot resolution provenance

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-21 17:08:48 +08:00
Vincent Koc
8c63ed2d57
fix(ci): verify provider OpenSSH before Testbox setup (#154478) 2026-09-21 14:10:22 +08:00
Peter Steinberger
00caa84ce7
perf(sessions): reconcile transcript FTS by exact row ownership (#153834) 2026-09-21 05:27:45 +00:00
Peter Steinberger
65485f6ade
fix(browser): preserve references across waits and renderer changes (#154215)
* fix(browser): preserve references across waits and renderer changes

Pin and bundle the patched Chrome DevTools MCP 1.8.0 runtime so source and npm installs receive the same identity repair. Verify packaged bytes and exercise real browser waits, cross-origin frames, stale-reference rejection, and recovery.

* fix(browser): declare bundled MCP dependency ownership

* test(browser): remove unused tarball fixture imports

* ci(browser): remove retired MCP download prewarming

* test(browser): pack MCP bundles with portable npm runner
2026-09-20 22:05:49 -07:00
Peter Steinberger
b082302d15
perf(state): move transcript reads off the Gateway thread (#154318)
* perf(state): move transcript reads off the Gateway thread

Reuse the existing history worker for durable transcript search and cursor deltas. Keep current sharing checks and display projection on the Gateway, and document the remaining database worker migration with a reproducible inventory.

Testbox proof: 5,000 rows and 50 viewers reduced caller-thread CPU by 96.7% for search and 7.3% for cursor history. Golden responses, 211 focused tests, build, type/lint/storage gates, inventory verification, and docs links passed.

* perf(state): isolate transcript search worker contracts

Move search request/result types into an import-free contract so worker protocol types do not depend on the query implementation. Register and document the inventory generator package commands.

Fix the architecture and unused-file CI failures. Exact failed guards, export scanning, core types, real-worker golden tests, formatting, and inventory regeneration passed on Testbox.
2026-09-20 21:13:24 -07:00
Peter Steinberger
bdb935f50e
improve(workers): reduce worker startup time and memory (#154293) 2026-09-20 19:45:53 -07:00
Peter Steinberger
5acfb83d9f
feat(typesafe): support local System One decision models (#154059)
* fix(typesafe): distribute as an official external plugin

Exclude TypeSafe runtime from the core package and enroll @openclaw/typesafe in npm and ClawHub publication. Preserve the plugin ID, protected credentials, and decision-model configuration. Require the post-2026.9.5 decision API and document the pending supporting release.

* fix(typesafe): register the official external install catalog

Keep official package discovery and trust aligned with the TypeSafe distribution cutover. Existing catalog completeness and ClawHub-counterpart checks pass.

* feat(typesafe): support local System One decision models

Add an explicit loopback endpoint for Kev, without forwarding hosted credentials or changing managed proxy authority. Preserve strict answer validation while adapting local instructions, Score legends, and timing metadata. Keep the declared local model out of hosted inference. Document endpoint scope and runtime ownership.

* fix(typesafe): validate local payload types and document Kev

Preserve discriminated question types without assertions and regenerate config documentation for the requested baseUrl field. Add the pinned Kev setup and API-test commands exercised in live inference. Core and channel config budgets remain unchanged; the plugin budget grows by one intentional field.

* docs(agents): allow exact synthetic scanner fixture qualification
2026-09-20 19:44:29 -07:00
Peter Steinberger
b73d0e4541
ci: shorten Windows jobs by sharing project setup (#154107)
* ci: avoid repeated Windows test project setup

* test: narrow Windows partition guard inputs
2026-09-20 16:38:30 -07:00
Peter Steinberger
0ef255d27b
fix(cua): update driver to 0.28.2 for reliable Linux key taps (#153830)
* fix(cua): update driver for reliable Linux key taps

* test(cua): bind the SDK refusal predicate callback

* test(ui): avoid token scanning in heap retention fixture

Keep all 64 exact previews, 32 MiB of source payloads, and the existing memory bound and deadlines. Use punctuation for the discarded tail so the test measures retention without spending most of its time scanning an irrelevant long token.
2026-09-20 15:43:56 -07:00
Bobby Bones
cc522878b3
fix: ACP model requests fail for aliases and provider references (#152850)
Resolve ACP model references against the connected harness catalog before useful turns, preserving exact model IDs, accepted settings, and conversation history.

Refs #124843.

Reviewed-by: @shakkernerd
Co-authored-by: Shakker <165377636+shakkernerd@users.noreply.github.com>
2026-09-20 23:09:54 +01:00
Dallin Romney
af00d16e35
fix(macos): shrink universal app downloads by pruning the node worker (#150773)
* fix(macos): prune bundled node worker runtime

* fix(macos): retain lazy worker capabilities

* fix(macos): retain internal package dependencies

* test(macos): prove app-gated computer commands

* refactor(macos): reuse runtime entrypoint owner

* fix(macos): register worker build entry

* test(macos): stage worker pruner fixture

* fix(macos): retain sqlite worker runtime

* fix(macos): validate pruned elevation worker

* fix(macos): retain descriptor-launched workers

* fix(macos): finalize private node worker exits

Use the shared CLI finalizer so completed workers and startup failures exit even when plugin-owned handles remain. Cover normal shutdown, signal exit status, and startup failure through the private entry.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-20 14:41:35 -07:00
Peter Steinberger
5e3b91ce6d
refactor: simplify filesystem operations with fs-safe 0.17 (#153973)
* refactor: simplify filesystem operations with fs-safe 0.17

* test: retire obsolete fs-safe suppression inventory entries

* test: include existing UI fixture in stylelint targets

* test: use codec owner for task identifier fixtures
2026-09-20 14:05:04 -07:00
Peter Steinberger
6e603b9ba7
perf(sessions): prepare transcript payloads before writer locks (#153818)
Prepare canonical assistant and tool-result payloads once per append and retain their serialized bytes across mutation-conflict retries. Keep authoritative parent, sequence, idempotency, generation, and writer checks inside the transaction.

A 200 KiB SessionManager append benchmark reduces median write hold from 7.821 ms to 1.864 ms. Preserve code-mode source decisions, media normalization, public persistence interfaces, and exactly-once behavior. No schema or configuration changes.
2026-09-20 10:02:28 -07:00
RoboClaw
bddcd95b8d
chore(deps): refresh dependencies with a seven-day cutoff (#153781)
Refresh 13 direct dependency packages and 15 resolved versions published by September 13, 2026 at 14:50 UTC.

Preserve compatibility-constrained versions, patches, overrides and the existing strict cooldown. Retain YAML 2.9.0 for the verified release producer and frozen security-review runtime. Regenerate Workboard's content-addressed browser asset pointers.

Validated by exact-head CI run 35520400755 and security/merge-gate reconciliation 35521175227, plus local consumer, release-producer, publication-admission and unchanged UI-budget checks.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-20 09:06:33 -07:00