* fix(memory): retain worker session export retries
Reject after two obsolete redaction snapshots instead of exporting on the
Gateway thread. Record resolved targeted sessions before preparation so a
failed export retains pending work for generic retry. Full rebuilds continue
to preserve the published index.
Verified both regressions against independent controls and all four ordinary
redaction cases against the final code.
* test(memory): isolate queued retry recovery from dirty state
Use the existing maintenance handoff so ordinary dirty-file retries cannot rescue a dropped queued request. Preserve every queue recovery assertion.
* perf(workspace): offload inventory and manifest processing
Keep the Gateway and paired nodes responsive during large workspace transfers with bounded computation workers. Hosts retain session authority, Git processes, file writes, durable acceptance, and cleanup.
Use transferable UTF-8 payloads for supported Unicode inventories, preserve independent errors during cancellation, and compare already-decoded manifests without copying their object graphs between threads.
* test(workspace): finish manifest fixture ownership
* refactor(workspace): distinguish stage input implementation
* test: register workspace benchmark and honor system Bash
* fix(tasks): settle orphaned execution records at restore
Record nullable process ownership for Gateway runs and local native harness
processes. Settle confirmed dead owners through the existing restart outcome
normalizer before restored tasks can block another drain. Preserve live,
foreign-host, unknown, and legacy ownership.
Add compatible nullable SQLite columns without changing the schema version.
Reported by @gregbond (#143420).
* fix(tasks): keep unchanged restores read-only
Request write admission only when restored state contains a confirmed orphan,
then reread and revalidate ownership before persisting settlement. Preserve
existing create/delete admission-failure semantics and cover a concurrent
owner rebind.
List the three approved nullable ownership columns in the canonical additive
schema contract test without relaxing its declaration checks.
* fix(tasks): preserve newer flow results during restore
Synchronize a restored orphan's mirrored flow only when that task is the
latest linked record. Keep newer live and completed successors' status,
goal, and terminal timestamps while still settling the orphaned task.
Cover both mixed-owner cases through the registry restore boundary.
* perf(sessions): offload transcript preparation
Use the shared session-transcript worker with separate context and background queues. Preserve exact-secret redaction and reset recall metadata through preparation and index publication.
* test(sessions): expect preserved transcript fence errors
* fix(memory): preserve indexes when transcript preparation fails
Propagate operational worker errors through existing shadow-rebuild recovery. Advance the private chunking revision so unchanged reset-bearing indexes rebuild through the existing owner without changing transcript hashes or schemas.
* test(ci): include QA profile status routing coverage
* fix: keep status polling off the Gateway main thread
* refactor(tasks): finish status summary cutover
* fix: complete status polling verification
* test: run Gateway status ownership checks on the host
* test: verify status host routing across test aggregates
Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.
Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.
The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.
The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.
Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.
Refs #144758#144901#144890#143292#146637#145252. Preserves the activation boundary from #147019.
* perf(sessions): reduce disk-pressure reclamation overhead
Reuse a sweep-owned reclamation Worker while preserving each victim transaction and live authority. Keep archive-only workers off the lifecycle import graph, join before final physical accounting, and preserve current physical-store ownership and per-request worker diagnostics.
Focused integration tests, compiled dependency-boundary regression, changed checks, normal build, and independent P0 review passed. Earlier matched-workload checkpoints reduced cleanup from 51.446s to 22.436s, but strict timing and SCALE gates remain unpassed; fresh integrated-head stress proof is still required.
* refactor(sessions): keep reclamation contracts acyclic
Move shared plan and result types into the existing lifecycle-types owner so the Worker no longer imports its runtime caller. Preserve exact type shapes and runtime behavior. Both cycle checks, focused tests, bootstrap regression, strict build/declarations, and independent P0 review pass.
* fix(sessions): preserve current admission during sweep worker reuse
Refresh the disk-pressure cleanup optimization in #140897 against current SQLite ownership. Keep per-victim retained claims, authorization and publication ordering while reusing one Worker per sweep. Bind each request to its own async context and preserve the original authority error during cleanup.
Focused owner, archive and combined regression tests, classified checks, full build and independent P0 review passed. Full stress acceptance remains blocked by missing original harness inputs; this commit does not claim landing readiness.
* test(gateway): align reclamation probe with worker bootstrap
Use the current bootstrap database options in the real SQLite validation preload. Both Gateway admission cases failed before this fixture correction and pass afterward, preserving revocation, same-store progress, native checks and lease cleanup assertions.
* fix(sessions): preserve cold mutation lifetimes during sweep reuse
Integrate the disk-pressure performance follow-up #140897 with cold storage from #145172. Share request admission and authorization while keeping cold mutations one-shot through cleanup and native exit, and retaining one validated reclamation Worker per sweep. Keep restore preparation, synchronous commit checks, publication ordering and final physical accounting intact.
Remove inherited dead UI exports and obsolete styles, exercise configuration through its real menu entrypoint, reuse picker test setup, and consolidate duplicate lifecycle notification construction. Preserve the 720-root and file-size limits without suppressions.
Focused cold/reclamation/Gateway tests, reset and UI coverage, classified checks, full build and independent P0 review passed. Full stress acceptance remains pending the separately reviewed replacement rig.
* test(auto-reply): incorporate canonical thinking test split
Apply the unchanged test-only split from upstream 9ab6ba866c (#145632) to repair the preexisting 1006-line CI failure on the retention candidate. No production behavior changes. Focused 83 tests, scoped lint and formatting pass; independent full-candidate P0 review is clean. Stress acceptance remains outstanding.
* refactor(sessions): clarify reclamation cleanup handling
* test: drain retained database workers before fixture cleanup
* test: preserve fixture state through retained worker drainage
* test: adapt archive bootstrap proof to tsdown handle
* test(sessions): drain archive fixture resources before removal
* test(gateway): drain the captured shared-state fixture owner
* fix(gateway): yield to I/O between startup phases
Retain the complete shutdown graph and lifecycle before yielding. Let queued I/O and close requests run before core runtime startup, and reject canceled startup before it can continue.
* perf(sessions): trim archive worker database bootstrap
Archive materialization and publication use fresh read-only connections, so avoid loading the writable database runtime to search an isolate-local cache that cannot contain parent handles. Share missing-table adaptation with cached readers while preserving validation, native close, and one-shot Worker exit ordering.
Verify the emitted archive bootstrap excludes the writable database module even when built with the parent session-store SDK entry. Preserve archive bytes, failure recovery, and borrowed/fresh reader behavior through focused tests.
* perf(sessions): skip artifact preparation without file candidates
Use the existing file inventory to avoid resolving every session path when no eligible transcript artifact can be removed, and avoid prompt projection without prompt blobs. Preserve the existing removal rules and validate with the stale-temp regression and 77 artifact/disk-budget cases.
* perf(state): keep startup agent integrity scans off the main thread
Run the full startup integrity and foreign-key scan against the already-owned
private agent snapshot through the existing integrity child. Retain the snapshot
and parent reader through native child close, then perform the unchanged schema
and migration checks. Preserve fresh admission before the migration lease and
before writes, source artifact neutrality, and original-path diagnostics.
Keep shared-state scans on their existing connection for the narrow legacy
Workshop-index admission. Move the unchanged schema-preflight error class to
its existing messages owner while preserving its public export. Update the
sole direct native integrity fixture for the diagnostic label.
Two real startup regressions fail on the original main-thread scan and pass
afterward, including a real foreign-key violation. 107 focused cases across
six files, selected repository checks, and independent review through P2 pass.
The integrated build and whole-Gateway stress limits remain required; this
commit does not claim a stress or runtime-update acceptance result.
* perf(sessions): reuse scoped archive workers during cleanup
Keep archive execution within cleanup and deletion scopes while closing fresh readers and files for every operation. Preserve per-victim commits and publication, and drain native work on failure or retirement.
Narrow singleton reference hydration through the existing parser without a reference cache. Align cold-handle and fixture cleanup proof with their canonical lifecycle owners.
* refactor(sessions): isolate archive contracts from execution
Move shared archive types into a leaf contract and migrate internal callers to remove the type-only import cycle without changing runtime behavior.
Model cold handles through canonical cache eviction in lifecycle fixtures and await native drainage before fixture cleanup.
* perf(sessions): yield between cleanup phases
Avoid loading the full session store when ordinary cleanup does not use the repair snapshot. Reuse canonical entries already read within the maintenance transaction when writing archive metadata, preserving the original previous entry and all writer guards.
Yield outside transactions before lifecycle application and the following snapshot so cleanup preparation, atomic writes, and queued responses do not combine into one long event-loop pause. Repair options, archive ordering, metadata, and transaction atomicity remain unchanged.
The original large workload recorded a 664.79 ms gap; a separate CPU profile identified the repeated store load and maintenance transaction as dominant costs. The focused 66-test suite, static checks, and independent P0-P2 review pass. Fresh compiled responsiveness and published-updater acceptance remain required for this source.
A passive SQLite checkpoint can return busy=0 while a reader prevents it from copying all WAL frames. Record blocked, complete, and failed outcomes on the existing maintenance handle and expose the recorded observation through status --deep and Doctor.
Warn after two blocked observations or a WAL above max(2 × database bytes, 64 MiB), show frame progress and the last completed checkpoint, and name a graceful Gateway restart and status report as the next steps. Completion clears the warning. Observations are process-local; checkpoint scheduling, schemas, retention, and recovery stay unchanged.
Validated by real-SQLite regression coverage, built-Gateway held-reader/recovery proof, and exact-head CI. This fixes the diagnostic gap; the original incident's long-lived reader remains unidentified.
Fixes#146744
Refs #146719
Reported by @thegizmopro (#146719).
* improve(doctor): avoid full copies for schema-only inspections
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* test(doctor): follow the snapshot owner after rebase
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(doctor): comply with SQLite query guardrails
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(doctor): preserve ownership in fast schema checks
Carry ownership metadata through the coherent child read, retain native source admission through failed close, and cover actual Doctor/restart callers. Keep explicit agent-file preflight with the agent inspector to stay under the source-size gate. Remove the upstream unused secret-ref import that blocked typechecking without changing its public re-export.
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(doctor): reuse canonical read-only SQLite pragmas
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
---------
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
* fix: avoid repeated agent database integrity scans
Reuse the first successful verification across physical reopens and admitted cleanup workers during the Gateway lifetime. Bind remembered health to the agent and physical database identity, share revocation with workers, and keep fresh ownership, schema, migration, repair, and quarantine checks.
Related: #145909, #118885. Maintainer-requested verification policy; no persistent marker or durability change.
* test: preserve cold admission coverage with remembered integrity
Explicitly invalidate verification only where fixtures exercise cold integrity admission, and retain ordinary close and revocation paths. Move the unchanged session-project schema probe to its migration owner, extract native scan instrumentation, and remove callback shadowing.
* test: complete fixtures before reusing database verification
Settle the canonical validity projection for healthy raw fixture rows and invalidate verification only for tests that exercise first-scan admission. Preserve existing history protection, warm-parent, and refusal assertions.
* build: coalesce tiny Control UI boot chunks
Keep undersized measured boot tails with their consumers through automatic chunking. This removes inherited dependency-layout-sensitive startup overhead while preserving the generated boot manifest, route boundaries, maximum chunk sizes, and all compressed-size budgets.
* chore(deps): advance cooled dependencies and major upgrades
* test(logging): migrate failed-sink regression to tslog 5
* test: retain dependency upgrade coverage within lint limits
* fix(deps): preserve compiler launches, Matrix sync and chat metadata
Keep copied script harnesses independent of declaration modules and preserve
Windows executable prefixes after admission. Audit the Matrix sync guard for
42.3, align CI toolchain/cache pins, and refresh session facts after accepted
model-catalog invalidation without relying on picker timing.
* fix(ui): preserve scoped session reconciliation after catalog refresh
* fix(state): migrate attestations without legacy path aliases
Fix updates from schema-1 installs such as 2026.6.35 when workspace_path_aliases was never created. Preserve existing attestation timestamps, bootstrap hashes, and null-path recovery through the accepted schema-13 migration.
* fix(state): finish pre-audit schema repair in doctor
Complete canonical migration for recognized schema-1 stores before Doctor reads agent and workspace state. Preserve the existing global-owner requirement and the refusal to recreate a missing audit ledger in later schemas.
* ci: rebalance Gateway session test roots
Move the complete session test family back to gateway-root after the
server family received its own graph. Current main exceeded the unchanged
700-root guard in gateway-other, which blocked unrelated PR merge checks.
Gateway root moves from 335 to 416 roots and gateway-other from 701 to
620. Preserve all 10,077 roots exactly once, the 720-root hard cap, graph
identities, cache paths, and compiler concurrency.
The original guard reproduces the failure on current main. All 24 owner
tests, both affected compiler graphs, changed checks, and review passed.
Invalidate the written agent price index through the existing models.json owner. Remove unused preparation results and queue wrappers while preserving serialized writes and copied public results. Related: #130706.
Preserve newly acknowledged cron cadence and pacing edits when an older completed run is reconciled after a scheduler-state write failure. Keep completed history without replaying the payload.
Refs #145722.
Cron recovery applies the pending run's own result and watcher-state edit protection when timestamps collide, including after owner edits close its execution receipt.
Refs #145336.
* fix: avoid full agent copies during schema version preflight
Read agent schema metadata through the existing bounded read-only child while retaining source admission and native close ownership. Keep full validation and required private snapshot paths unchanged. Accepted storage scope: #145412.
* fix: preserve source inspection lock tolerance
Keep the existing 30-second source-reader wait, prove an exclusive rollback writer can release after eight seconds without refusing an update, and reuse Kysely and the existing schema-version/transaction owners. No timeout or SQL guard exceptions are added.
* fix: keep schema inspection out of lightweight version imports
Keep the version reader byte-identical to its prior lightweight contract. Header inspection retains Kysely and the deferred transaction owner, with read-only PRAGMAs owned by the existing SQLite configuration boundary. Full neutral Linux package build, native lock tests, and large-store proof pass without changing budgets or allowlists.
* test: preserve ownership admission during header preflight
Cover config-only ownership admission for all six agent roles after integrating the current startup isolation owner. Header-only inspection must not skip copied-owner refusal or alter source bytes.
* fix: share the model context worker entrypoint
Let runtime launch, packaged output, and precompiled test workers consume one declaration. This removes measured cold TypeScript loading from functional worker proof without increasing deadlines or changing the worker's source or installed path.
* fix: retain only the upstream context worker registration
Main independently landed the same worker registry consolidation in #145708. Keep its canonical registration and remove the duplicate introduced by Git integration; all three worker registration/build files now match main exactly.
* feat(agents): add role templates and team onboarding
Add bundled coordinator, researcher, writer, and reviewer workspace programs
with complete identities through agents add --role. Add agents team create
and guided/non-interactive onboard --team using the existing creation owner.
Keep fleet ownership explicit, preserve existing agents and ambient owners,
and target the coordinator explicitly after onboarding. Preflight normalized
ID conflicts and distinguish fresh main placeholders from established agents.
Keep normalized agent-creation JSON machine-readable.
Reuse scalar option validation and test setup helpers without adding config
keys, dependencies, global delegation policy, or store schemas.
* fix(cli): align setup team flags and command JSON classification
* refactor(agents): express role templates as Claw sources
* fix(agents): reject role adoption before publishing workspace files
* feat(custodian): recommend agent roles and teams
Offer catalog-backed Chief of staff, specialist, team, and custom choices
from New agent, and seed approved creations through the CLI lifecycle owners.
Keep coordinator as the role id without adding CLI flags or config keys.
Carry host requester provenance through team creation and report committed
members when later creation or bookkeeping fails. Record those partial
outcomes for operator visibility and post-write verification.
Update role documentation and the mock custodian welcome.
* feat(ui): add roster-first Agents home
Add the /agents roster with activity, main-chat previews, identity cards, and direct chat navigation. Keep agent configuration at /settings/agents and reuse the existing creation flow. Include bounded session refreshes, synthetic fixtures, focused navigation and page tests, and Control UI documentation.
* fix(ui): align agents e2e navigation with roster home
Retarget settings behavior tests to /settings/agents and include Agents in default sidebar ordering expectations. Preserve existing permission, avatar, persistence, and navigation assertions. Reproduced six failures before repair; all 22 affected and sibling browser tests now pass.
* perf(ui): defer agent page copy and route setup
Register Agents home copy with the lazy view while keeping sidebar labels eager and preserving the complete source catalog. Defer agent page render adapters and the settings roster loader through the existing lazy route pattern, keeping loader logic and displayed copy unchanged.
Reduce startup gzip by 274 bytes on the branch and 275 bytes in the local CI merge-tree replay without changing performance budgets.
* feat(ui): link the agent switcher to the Agents home
Add an All agents action above New agent using the existing menu navigation and dismissal flow. Keep the Agents heading unchanged, document the entry point, and cover roster navigation and action ordering.
* fix(ui): restore eager agent settings route loading
* feat(ui): add optional sidebar agent roster
Add a browser-scoped sidebarAgentsMode preference with the existing chip as
its default. The agent menu toggles a compact roster with working activity,
last-active time, existing unread counts, and links to all agents or creation.
Share identity, activity ordering, previews, and bounded session loading with
the Agents home. Keep agent switching and selected-agent session scope on
the existing sidebar path, and defer roster rendering to protect startup.
Document the mode and include focused unit, mocked browser, and fixture proof.
* fix(ui): share roster activity between sidebar and Agents home
* feat(ui): group sidebar sessions by agent in roster mode
Show every selectable agent's pinned and recent sessions under collapsible,
working-first headers, with per-agent new-session and main-chat links.
Share bounded session activity with Agents home, preserve current-session
visibility and row ownership, and retain the context chip and list filters.
Document the 300-row window and browser-local collapse preferences.
Refs #141476.
* refactor(ui): break sidebar session navigation import cycle
* feat(ui): team mode hides Home, adds a "+" agent switcher, and scopes pages to all agents
Make each agent header its canonical main-chat entry, keep collapse separate,
and offer ordered agent selection from the sidebar New session controls.
Default shared page scope to all agents when team mode starts, preserve manual
filters during navigation, and restore the prior scope when it ends.
Show shared avatar/name chips on agent-owned lists. Keep Memory, Model
providers, and Skill Workshop single-agent, with concrete navigation selection.
Reconcile cold saved scopes and apply Memory route ownership before requests.
Document the mode and validate sidebar, scope, list, and browser behavior.
Refs #141476.
* fix(ui): persist the pre-team agent scope per gateway
Remember the pre-team page scope in gateway-scoped browser preferences, including an explicit all-agents selection. Restore it after chat navigation, reloads, and gateway switching, then clear it when team mode ends.
Validate with 424 focused unit/component tests, the sidebar browser scenario, UI typechecking, i18n, lint, and architecture checks. The full changed-file gate reproduces existing TS2352 fixture errors in the Model providers and Usage route tests at the starting commit.
Refs #141476.
* fix(ui): type route tests against the team-mode page contracts
* fix(ui): expose agent ids on identity chips and assert them in e2e
Include stable owner IDs in accessible chip labels and tooltips. Preserve same-session-id ownership proof with two identically named agents, including an empty current session, and identify row owners through the shared chip across list tests.
Validate the real-Gateway Usage scenario, sidebar and Usage tests, i18n, docs, and changed checks. Refs #141476.
* feat(ui): team mode replaces the agent chip with a workspace header
Show the configured Gateway name or OpenClaw with the product mark in team
mode. Keep chat context with the open session, preserve the header controls,
and limit the workspace menu to Show one agent, Agent settings, and Help.
Restore keyboard focus when switching between the workspace and agent chip.
Reuse the existing help submenu and header styles, document the mode, and
verify workspace identity, menu contents, context changes, and chip restoration.
Validation includes 376 unit/component tests, all 31 selected browser tests,
i18n, changed-file checks, architecture, and production build/performance.
Refs #141476.
* feat(ui): agent-first team sidebar rows and indicators
Integrate the reviewed team sidebar layout, trailing activity and attention indicators, nested row geometry, and default face avatars. Preserve shared roster lifecycle and identity updates. Refs #141476.
* fix(ui): keep team activity on stable compact session rows
Keep configured team order and move main conversations into session rows, leaving header summaries only for collapsed groups. Keep titles on one line, child state in the right column, Online collapsed initially, and conversation actions clearly labeled.
Move default face artwork into the lazy roster module and remove the obsolete shared preview path and indicator export. Preserve normal session visibility filters when restoring the canonical global stream. Verify desktop and touch geometry, nested rows, identity precedence, filters, and same-id Usage ownership. Refs #141476.
* improve(ui): keep agent creation in Settings
Remove the New agent shortcut and command handler from sidebar menus, keeping conversation creation and agent switching focused on existing agents. Preserve administrator-gated creation in Settings at zero, one, and multiple agents, and the Agents home action. Update menu coverage and the Settings and team-mode documentation. Refs #141476.
Co-authored-by: hannesrudolph <49103247+hannesrudolph@users.noreply.github.com>
* fix(ui): deduplicate trailing sidebar status indicators
Keep collapsed descendant summaries in the trailing state column and suppress status kinds already represented by the parent, preserving distinct queued work and attention. Fill the global conversation menu avatar with the default face. Cover parent/child status overlap and wait for menu animation before measuring geometry. Refs #141476.
* test(ui): keep roster activity fixture updates immutable
Use Object.assign for row copies inside the activity-order regression to satisfy the repository map-copy lint rule without changing fixture behavior.
* fix(ui): share one default agent avatar across surfaces
Share image, identity emoji, and deterministic SVG face rendering across
Control UI agent cards, menus, chips, chat, owners, and participants.
Keep people avatars on their existing profile and initials path.
Select seven crisp silhouettes and ten hues from the stable agent id,
load the artwork lazily, and retire pending faces when identity emoji
arrive. Preserve authenticated image ownership and error fallback.
Resolve full-message transcript artwork with the same effective agent id
as its replies. Replace the tiny mock images with crisp synthetic artwork.
Refs #141476.
* fix(ui): polish team-mode session rows and group actions
Give each agent group New conversation, Open main chat, All sessions,
and Collapse others actions. Keep the global team filter without the
redundant Sessions heading, See all link, or section-level creation menu.
Reserve aligned child-count, unread, and state slots for team rows and
collapsed groups. Prioritize input and error attention, preserve each
expanded row's own activity, and use plain 12px nested carets. Keep
chip-mode controls and leading activity unchanged.
Document the team actions and indicators. Cover keyboard, touch, shared
agent scope, collapse persistence, fixed geometry, and conflict ownership.
Update the stale shared-avatar assertion to the current textAvatar field.
Refs #141476.
* test(ui): follow the New conversation label in e2e
Update the new-session transition, session ownership, navigation, and
message-action tooltip flows to the reviewed sidebar accessible name.
Retain keyboard coverage of the chip-mode global creation link.
Refs #141476.
* fix(ui): keep team-mode titles and names readable
Move team session filters into the sidebar header toolbar and remove the
empty filter row. Size trailing indicators to present state and let quiet
session titles use the remaining row width. Share the collapsed summary
and header-action area so hover and keyboard focus preserve agent names.
Keep chip mode, agent-owned menus, plain carets, nested guides, and row
heights. Preserve the workspace label beside four equally sized controls.
Update sidebar docs and cover 258px title/name geometry, touch, keyboard,
and filter behavior. Shrink the assertion baseline after removing a cast.
Refs #141476.
* fix(ui): keep the product mark for the system agent avatar
Resolve reserved system identities to the mounted, build-versioned OpenClaw
favicon in the shared avatar renderer, without image or generated-face fallback.
Pass the custodian's canonical agent ID instead of threading a page-owned image.
Keep the chat image contract and accessible name while removing its extra wrapper.
Preserve ordinary agent image, emoji, and generated-face behavior. Cover system
identities, image errors, and mounted assets, and document the product-mark rule.
Refs #141476.
* fix(ui): keep configured image avatars beside chat replies
Restore the chat image classes and accessible name for configured avatars,
including images fetched through the authenticated workspace avatar path.
Reuse the existing image slot with shared emoji and generated-face fallbacks,
and keep reserved system agents on the OpenClaw product mark.
Cover image sources, fallback behavior, saved and streaming replies, and
forwarded messages. Document configured workspace images beside replies.
Refs #141476.
* Revert "improve(ui): keep agent creation in Settings"
This reverts commit 0d7a78db4f4cfab2cbee00515b38c30ab316780b.
* docs(ui): preserve current sidebar menu wording
Keep the New conversation labels and no-filter agent switcher description accurate after restoring the New agent shortcut.
* fix(ui): reconcile sidebar roster integration checks
Align avatar recovery tests introduced by main with the shared generated-face
fallback and nested image markup, preserving authenticated loading, revision
recovery, and stale-error coverage. Restore the Usage loader's narrow Gateway
and agent-selection input contract after its lazy-loader extraction.
Validation: reproduce the four failing avatar assertions before the fix;
52 avatar and Usage route tests pass afterward. Independent review is clean.
* fix(ui): align sidebar fixtures and identity e2e with main
---------
Co-authored-by: hannesrudolph <49103247+hannesrudolph@users.noreply.github.com>
* feat(agents): add role templates and team onboarding
Add bundled coordinator, researcher, writer, and reviewer workspace programs
with complete identities through agents add --role. Add agents team create
and guided/non-interactive onboard --team using the existing creation owner.
Keep fleet ownership explicit, preserve existing agents and ambient owners,
and target the coordinator explicitly after onboarding. Preflight normalized
ID conflicts and distinguish fresh main placeholders from established agents.
Keep normalized agent-creation JSON machine-readable.
Reuse scalar option validation and test setup helpers without adding config
keys, dependencies, global delegation policy, or store schemas.
* fix(cli): align setup team flags and command JSON classification
* refactor(agents): express role templates as Claw sources
* fix(agents): reject role adoption before publishing workspace files