Commit graph

60 commits

Author SHA1 Message Date
Peter Steinberger
520442c337
test(agents): add live Code Mode comparison workloads (#147537)
Extend the existing model matrix with isolated Gateway tasks, fixed-workload build comparisons, and separate task and interview evidence. Preserve failed trials, exact source identities, task effects, logical cell completion, and observed preview coverage.

Validation: 187 focused tests, changed-file and targeted type/lint/docs checks, exact-candidate runtime build, actual OpenAI smoke, read-only replay of 24 original trials plus the final smoke, and fresh P2 review. Original scores and interview qualifications remain preserved.
2026-09-13 16:32:28 -07:00
Peter Steinberger
f9ccd07ded
fix: skip official setup approvals and default to Astra (#145646)
* fix: skip official setup approvals and default to Astra

* test: align default-model expectations across consumers

* test: align attachment catalog with Astra default

* fix: preserve configured Codex catalog model selections
2026-09-12 00:34:25 -07:00
Shakker
53200287f8
fix: preserve child signal termination during CLI respawn (#144838)
Preserve actual Unix child termination signals through startup respawns so supervisors stop interrupted runtimes without entering watcher recovery. Keep explicit numeric exits and Windows termination behavior intact.

Fixes #144200.
2026-09-11 12:05:59 +01:00
Vincent Koc
26b84d3f38
docs(tools): split the browser page by reader job (#142984)
* docs(tools): split the browser page by reader job

docs/tools/browser.md was 55,693 characters across 21 H2 sections mixing
explanation, how-to, reference, and troubleshooting. Move each section into
docs/tools/browser/ and keep /tools/browser as the index.

The split is content-preserving: the nine child pages plus the three blocks
the index still publishes (lede, What you get, Related) reconstruct the
original body byte-for-byte (sha256 a28d5ea4...). Only the four H2 lines that
became child page titles are not reproduced verbatim; each keeps its anchor
on the index.

Every one of the 43 pre-split anchor IDs -- headings, their percent-encoded
and cleaned variants, and the Accordion and Tab titles -- is authored as an
<a id> stub on the index, so existing /tools/browser#... links still resolve.
Per-anchor redirects are not possible: redirectSource() rejects sources
containing [?#].

* docs(tools): retarget cross-references orphaned by the browser split

Eleven link targets, no prose changes. Three were same-page or same-route
anchors inside the moved content: /tools/browser/setup's [Configuration] link
was genuinely broken (its target moved to the configuration page), and the
[Profiles] and [Custom Chrome MCP launch] links resolved only through the
index's anchor stub. The remaining eight are inbound deep links from other
pages, retargeted at the page that now holds the section, matching the
code-mode split precedent.

* docs(i18n): add zh-CN glossary entries for the browser child page titles

check-docs-i18n-glossary requires a source term for every changed doc label.
2026-09-09 18:48:49 +09:00
Peter Lee
f10e8952d4
fix(cli): identify accepted runs after agent transport loss (#111899)
## What Problem This Solves

Fixes an issue where users running `openclaw agent` could not identify an accepted Gateway run from the human diagnostic after the connection closed or the CLI wait timed out. The run ID already appeared in JSON failure output, but the human hint omitted it.

## Why This Change Was Made

The hint reads the existing error-bound Gateway metadata and names the accepted run. Timeout failures also mention `--timeout <seconds>`. Both hints retain the instruction to check Gateway status and the session transcript before retrying.

The original automatic embedded fallback reported in #111407 was already removed from main. This PR completes the remaining diagnostic improvement; it does not introduce a reattachment command or guarantee that the run is still active.

## User Impact

Operators can correlate an ambiguous failure with the accepted run before risking duplicate execution. The original error, nonzero exit, canonical JSON envelope (`ok: false`, `error.type`, `error.message`, optional `runId` and `origin`), retry behavior, and cancellation behavior remain unchanged. Failures without an observed accepted ID keep the generic hint.

Fixes #111407.

## Evidence

Verified candidate `da178e1210818e8a8a1ec64145d871a30a4228f5` against pinned main `fc55b5b936` on one isolated Linux Testbox, using real `pnpm openclaw agent` processes, a real Gateway, an authenticated production WebSocket client, a loopback fault proxy, and a deterministic local provider.

- Before: accepted-run transport close and timeout retain the ID in JSON but omit it from the human hint. After: both human hints include the exact accepted ID; only timeout includes timeout guidance. Both exit unsuccessfully and retain the same sanitized transport error.
- Baseline and candidate controls cover human/JSON output, pre-acceptance failure, missing or unobserved acceptance IDs, cached final errors, transient and exhausted handshakes, normal completion, signals and `chat.abort`, local state-lock refusal, and standalone local execution/signals. Accepted transport-loss cases submit one CLI turn and one provider request. Cached-final proof uses one explicit fixture seed followed by the original CLI request, with one provider request total.
- Focused tests: 126 agent-command cases, 19 shared-failure cases, and the contributed real-Gateway end-to-end test passed. Changed-file formatting/lint and documentation MDX checks passed.
- Exact-head [CI run](https://github.com/openclaw/openclaw/actions/runs/34204549245) is green.

The timeout control uses the documented CLI timeout; its Gateway turn may already have ended. Process-level proof covers observable output and execution; original error-object identity and source-only invariants are covered by the focused tests and code review. No external inference or production channel was used.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-08 22:22:59 +05:30
Vincent Koc
4d7a33874b
docs: correct 8 verified factual errors (#141158)
Each fix replaces a statement that contradicts the CLI implementation,
a TypeScript type, or the tool catalog. No prose or structure changes.

docs/cli/agent.md:11 — said "The explicit `--local` flag is the only
embedded execution path". `agent exec` is also embedded: the same page
at line 21 says it "runs one embedded agent turn without connecting to
a Gateway", and src/commands/agent-exec.ts:210 documents it as "Run one
isolated embedded agent turn and project its stable CLI result."

docs/cli/secrets.md:27 — the recommended operator loop ran `openclaw
secrets configure` with no `--plan-out`, then applied
`/tmp/openclaw-secrets-plan.json` on the next line. A plan file is only
written when the flag is passed: src/cli/secrets-cli.ts:255 guards the
write with `if (opts.planOut) { ... writeFileSync(opts.planOut, ...) }`,
and there is no default plan path. Added the flag to line 27.

docs/gateway/config-tools.md:26,46 — the `coding` profile row and the
`group:media` row listed `image` as a tool id. The catalog registers
`view_image`: src/agents/tool-catalog.ts:427 `id: "view_image"`, and
src/agents/tools/image-tool.ts:807 `name: "view_image"`. No tool with
id `image` exists. The same page already says so at line 149: "The image
inspection tool is `view_image`."

docs/cli/plugins.md:36,40 — the synopsis omitted flags the commands
accept. src/cli/plugins-cli.ts:136 gives `enable` `--accept-capabilities`;
src/cli/plugins-cli.ts:180,186 give `install` `--accept-capabilities` and
`--acknowledge-install-policy-warning`.

docs/cli/devices.md — the command reference had no section for
`openclaw devices join-code`, which src/cli/devices-cli.ts:43-47
registers with the description "Mint a single-use node onboarding URL".
Added a section matching its actual option surface.

docs/cli/index.md:165,200 — the command tree omitted `secrets store`
(registered at src/cli/secrets-store-cli.ts:164 and documented in the
`openclaw secrets` table at docs/cli/secrets.md:18) and `plugins pack`
(registered at src/cli/plugins-cli.ts:277 and listed in the plugins
synopsis at docs/cli/plugins.md:49).

docs/plugins/hooks.md:497 — the `BeforeToolCallResult` type block omitted
`scope`, while docs/plugins/plugin-permission-requests.md:93 tells plugin
authors to "Set `requireApproval.scope`". The real type has it:
src/plugins/hook-before-tool-call-result.ts:21 `scope?: ApprovalScope;`.

docs/diagnostics/flags.md:51 — the multi-flag example enabled
`"gateway.*"`. No diagnostic flag lives in a `gateway.` namespace: the
call sites are `timeline`, `diagnostics.timeline`, `plugin.load-profile`,
`ingress.timing` and `health`, and the page's own Known flags table
(lines 24-34) lists none. Replaced it with `health`, a real flag.

Closes audit findings: r3-0182, r3-0198, r3-0335, r3-0128, r3-0199, r3-0195, r5-0022, r3-0281
2026-09-07 18:54:43 +08:00
RoboClaw
d8af304112
improve(qa): extend Code Mode evaluation scenarios (#140913)
Extend the existing Code Mode evaluation harness with opt-in large-result reduction, independent-read composition and dependent-chain tasks. Preserve default matrix size and distinguish missing telemetry from observed zeros.

Focused tests, negative controls, dry-run evidence, changed checks, independent review and exact-head CI pass. No live model performance result is claimed.

Worked on by:
- @Takhoffman

Co-authored-by: Takhoffman <781889+Takhoffman@users.noreply.github.com>
2026-09-06 23:27:26 -07:00
Peter Steinberger
60adac1aff
fix(agents): fit compacted context and prioritize foreground replies (#139822)
* fix(agents): fit compacted context and prioritize foreground replies

Size automatic client-side compaction against the prepared foreground request,
including its actual queued context. Preserve pending input, complete exchanges,
and transient prompt ownership across compaction and initial steering. When
fixed context consumes the preferred reserve target, allow only a strictly
smaller history replacement instead of rejecting useful progress.

Run optional Gateway maintenance after delivery under fresh session admission;
preempt and drain it before the next foreground turn. Keep required checkpoints,
one-shot CLI boundaries, native compaction ownership, and explicit session fences.

Related: #121617, #53008

* test(agents): align maintenance fixtures with foreground ownership

Exercise required checkpoints through compaction, wait for optional maintenance settlement, and retain cancellation and delivery guards. Give retry-only sessions a valid context window and verify the actual remaining construction deadline. Qualify early-preflight headroom in the docs based on live measurements.

Validation: 51 SDK, construction, and direct-reply tests; 196 command and CLI owner tests; changed-scope test and docs gates; independent P0-P2 review. Production runtime files are unchanged from ae631c61.

* refactor(agents): remove overwritten model-switch result stores

Fallback provider and model are recorded from the completed attempt before the only return. Model-switch retries cannot expose the intermediate catch-block values. Removing those dead stores also keeps the merged module below the existing line limit after main adds error-transcript forwarding.

Validation: 131 model-switch tests, full changed-scope checks, and independent P0-P2 review pass. No inference, maintenance, or model-selection behavior changes.

* fix(agents): preserve pending turns through maintenance

Keep required memory checkpoints on a detached view of the processed conversation,
with private execution identity and the original sandbox, tool restrictions, and
prompt-cache ownership. Preserve admitted input independently of request sizing.

Carry intentional automatic compaction skips through their owner so foreground
preparation can continue, while preserving manual SDK results and failure handling.
Exclude hidden maintenance from displayed activity without changing cancellation
or operational liveness.

Regression coverage includes real SQLite admission, restricted memory writes,
compaction, and exact pending-input delivery. Focused suites, changed checks, and
independent review pass; fresh CLI and Tauri measurements follow on this revision.

* test(gateway): align activity mocks with session presentation

Preserve the raw operational progress mocks while supplying the separate
session-presentation query used by activity projections. Update shared fixture
consumers and reset paths without changing assertions or production behavior.

All six hosted CI failures reproduce before this fixture repair. The seven full
owner and sibling suites (183 tests), scoped changed checks, and independent
review pass afterward. Runtime files remain identical to bbbad8fd live proof.

* fix(agents): keep memory maintenance out of user transcripts

Run required and optional memory inference on private conversation copies.
Preserve source policy, prepared model facts, and cache identity while keeping
canonical compaction and memory outcomes with the original session owner.

Interrupted maintenance no longer becomes queued user context in the next
request. Owner cancellation does not count as a failed memory attempt.

* test(agents): use canonical history in delivery maintenance fixture

* fix(agents): prevent nested maintenance dependency cycles
2026-09-06 11:31:27 -07:00
Peter Steinberger
bcef3b3526
fix(runtime): require cleanup evidence before releasing owned work (#139657)
* fix(runtime): retain cleanup ownership across agent teardown

Keep command results and cancellation separate from cleanup uncertainty.
MCP, LSP, Codex, CLI and Gateway owners retain cleanup evidence before
releasing resources or replacing a prior execution. Keep bounded agent
state when closure cannot be confirmed and fence retained host writes.

Stage 3 consumer extraction from #135868, following the process foundation
in #139517. Remove duplicate cleanup timers, one-use adapters, and the
unused asynchronous finalizer callback while preserving plugin disposal
compatibility.

* test(runtime): simplify cleanup ownership fixtures

* fix(runtime): fence retired handles and check transport exit evidence

* test(runtime): align cleanup proof with suite boundaries
2026-09-05 22:20:12 -07:00
Peter Steinberger
b3dcb2d52b
fix: preserve local-model capabilities and conversation history (#138850)
* fix: retain local-model tools without changing sibling agents

Infer structured Tool Search from the final resolved provider route instead
of writing global lean mode during model setup. Preserve explicit user
choices and migrate only the lean flag owned by the retired setup marker.

Align CLI and native Ollama context caps and scale the built-in compaction
reserve to small context windows. Preserve ordinary forced message delivery
through the shared tool catalog while keeping private replies restricted.

Full build, focused owner tests, config baseline, and independent review
passed. Fresh CLI/native Ollama evaluation is tracked before landing.

Fixes #138753.

* test: cover private delivery and isolate local-model regressions

* fix: clarify deferred tool calls and trim repeated metadata

Keep full structured call details while presenting only exact tool identity
and the unchanged target result to the model. Explain tools-mode wrapping
and compact automation summaries without changing execution permissions.

Validation: 468 focused tests, failing-before compact-output regression,
and independent Codex review. Fresh real-model setup and recall proof follows.

* test: refresh automation prompt snapshots

Regenerate the canonical prompt fixtures for compact list summaries and
full get details. Snapshot drift check and all16 reconstruction tests pass.
Production remains byte-identical to8fa7d1488c3.

* fix: retain exact timing in compact automation lists

Include existing at/every/cron schedules after the normal visibility filter
so disabled jobs and recurring intervals can be understood in one tool call.
Keep event commands, working directories, payloads, and delivery definitions
behind the existing full-job read. Preserve scheduleKind for API compatibility.

The real local-model trial found the job but invented its schedule because
only the kind was exposed. Owner regressions reproduce that missing state.

* test: dispose assistant panel session capabilities

The panel fixture owns its application-level session capability. Removing
DOM alone leaves subscription retries alive and contaminates later fake
clocks. Register disposal at creation without changing runtime behavior or
weakening the Sessions typing timer assertion.

The original 11-file worker order reproduces the failure before cleanup and
passes all 233 tests afterward. Independent review is clean.

* fix: expose readable run times in compact automation results

Add exact ISO next/last run dates using the canonical timestamp formatter.
Keep the shipped millisecond fields for programmatic clients and preserve
null for absent run times. Models can now report dates without calendar
arithmetic on epoch values.

All 253 Gateway tests pass; five old-producer failures establish timestamp
and absence coverage. Independent review is clean.

* fix: preserve current Ollama context caps during doctor

Do not turn catalog windows or provider output budgets into stronger
num_ctx pins when a current contextTokens cap is already present. Avoid
provider-wide synthesis for mixed current/legacy models; migrate uncapped
native siblings individually and preserve existing explicit overrides.

Retain the shipped native legacy budget precedence and the compatibility
adapter's own API-specific behavior. Simplify the private API classifiers
and budget resolver while fixing the migration owner.

Live reproduction: Doctor tried to pin 262144 over the onboarded 32768 cap.
Eight pre-fix regressions fail; all 98 migration tests pass after the fix.
Independent review is clean. Existing oversized pins remain operator-owned.

* fix(ollama): preserve prepared tool text and continuation hints

Keep caller-budgeted explicit tool text intact when adding structured
fallback content. Bound structured data separately so large file pages
and Tool Search results retain their complete instructions.

Live native wire reproduction showed a 15,976-character tool result
truncated to 8,014 characters, deleting its continuation offset.
Regression coverage preserves long text, Unicode and whitespace while
retaining structured-data bounds and redaction.

* fix(agents): share the command budget with post-turn maintenance

Use the foreground run's remaining allowance for memory flushing and
compaction instead of restarting a full timeout for each phase. Cancel
and settle maintenance before returning the completed reply, while
preserving caller cancellation, restart fencing, and accepted compaction
session/count facts.

A live local-model turn completed in 462 seconds, but its CLI waiter
expired at 630 seconds while a separate memory flush was still running.
The existing model and Gateway deadlines remain unchanged.

Regression coverage includes exhausted and unlimited budgets, shared
phase expiry, committed successors, CLI siblings, and caller abort.

* fix(ollama): preserve native chat history on overflow

Default local native requests to truncate:false and shift:false so context
pressure reaches OpenClaw's compaction/recovery path instead of silently
removing conversation history. Preserve explicit model parameters and keep
hosted routes unchanged. Document the verified runtime and partial-output
behavior.

* fix(ollama): preserve hosted defaults through custom proxies

Exclude explicit Ollama Cloud provider routes from local history-preserving
request defaults even when their model and proxy URL lack cloud markers.
Reuse the existing cloud-origin check and cover the real native request.

* test(ollama): expect history preservation in timeout requests

Keep the complete request expectation aligned with the intentional native
truncate:false and shift:false defaults. Preserve the timeout and every
other existing assertion. No production behavior changes.

* fix(agents): use provider compaction effort and one summary format

Native Ollama summaries default to thinking off through prepared provider
metadata; explicit compaction settings and hosted routes retain precedence.
Use one primary summary format across history, prefix, stage and fallback
requests, preserving focus and existing output budgets.

Three live 4B compactions hit the existing 180-second watchdog with low
effort. A controlled thinking-off request completed in 39 seconds but
exposed conflicting formats. Owner regressions cover both failures.
No new operator configuration, schema, or timeout increases.
2026-09-05 05:32:07 -07:00
Peter Steinberger
26f87a3700
fix: allow environment-only agent runs without a native harness (#138449)
* fix: allow environment-only agent runs without a native harness

* chore(ui): reconcile measured main startup baseline

Unmodified main b6a4d0dad4 fails the startup gzip check at 350377 B in Linux CI; a pristine source build measures 350363 B. Record the measured main baseline while retaining the fixed cap and existing growth and variance allowances.
2026-09-04 11:37:51 -07:00
Peter Steinberger
fe784239d8
fix(browser): avoid standalone routing errors and cropped screenshots (#135315)
* fix(browser): avoid standalone routing errors and cropped screenshots

Route implicit standalone browser calls locally while preserving Gateway-owned routing. Capture through the session that owns viewport or device emulation, serialize mutations, and preserve successful viewport changes after later device errors.

* test(browser): complete control-server connection fixture

* fix(protocol): retain named schema types in declarations

* fix(browser): bound interrupted captures and release stale metrics

* fix(browser): distinguish embedded contexts from Gateway owners

Mark local embedded RPC contexts at their owner so standalone browser calls can use local control without Gateway discovery. Preserve caller and ambient Gateway bindings after retirement, and replace mocked ownership checks with real local-admission coverage.
2026-09-01 18:17:47 -07:00
Sebastien Tardif
bfbc3f6144
fix(cli): keep agent exec run errors when cleanup fails (#135273)
* fix(cli): keep agent exec run errors when cleanup fails

After a failed run, attach cleanup as a secondary envelope field
instead of replacing the run error. Successful runs that only fail
cleanup still report the cleanup error.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>

* fix(cli): preserve agent exec failures during cleanup

Keep the primary run envelope and exit code when cleanup also fails.
Report secondary cleanup errors on stderr without extending the JSON result.

Co-authored-by: Sebastien Tardif <sebtardif@ncf.ca>

---------

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Sebastien Tardif <sebtardif@ncf.ca>
2026-09-01 17:00:09 -07:00
MarMar Labs
833a38b925
fix(cli): reject a blank --session-id or --session-key instead of ignoring it (#134797)
* fix(cli): reject a blank --session-id or --session-key instead of ignoring it

`openclaw agent --agent ops --session-id "$SESSION_ID" --message hi` with an
empty SESSION_ID does not fail. It runs the turn in the ops agent's default
session, so a caller that meant to target one session silently writes into
another.

Every downstream layer trims the value and treats blank as absent.
`normalizeSessionKeyOptsForDispatch` computes `hasExplicitSessionTarget` from
`Boolean(opts.sessionId?.trim())`, so a blank id reads as "no explicit target"
and the dispatch falls through to the agent default. `--session-key` takes the
same path, and `src/agents/command/session.ts` normalizes blank to undefined
as well, so nothing further down can tell the two cases apart.

`agentCliCommand` already rejects the sibling case three lines up:

    if (opts.agent !== undefined && !opts.agent.trim()) {
      throw new Error("--agent must not be blank");
    }

This applies that same rule to the other two selector flags. An omitted flag is
still absent and still resolves normally; only a flag that is present and blank
now fails.

* fix(cli): reject explicit blank agent selectors

Validate all documented selectors at the shared CLI command boundary before
session normalization or dispatch. Preserve omitted and valid selectors,
cover local and Gateway paths, and document the explicit-blank contract.

Co-authored-by: MarMar Labs <marmar9615@icloud.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: MarMar Labs <marmar9615@icloud.com>
2026-09-01 03:18:58 -07:00
Peter Steinberger
97998cb25f
fix(usage): correct cached long-context cost estimates (#133349)
* fix(usage): correct cached long-context cost estimates

Keep Venice extended schedules in the owning manifest, select per-call tiers from total prompt input, and preserve explicit pricing and provider-billed totals through run accounting. Fixes #133343.

* test(usage): assert worker monetary result metadata
2026-08-30 13:05:18 -07:00
Peter Steinberger
312f016093
fix(cli): preserve Gateway run IDs in agent JSON failures (#133006)
Keep observed Gateway run provenance in agent --json failures so automation can correlate accepted and cached run errors. Preserve existing error fields, human output, cancellation behavior, and retry policy; local request keys are never reported as Gateway provenance.
2026-08-29 19:52:00 -07:00
Peter Steinberger
3ab27a2900
fix(cli): exit non-zero when an agent turn fails (#125557)
The gateway-routed path already mapped terminal run status to an exit code,
but the local embedded path did not, so a failed turn exited 0 while its own
JSON envelope reported status "error". Route both through the canonical
agent-run terminal outcome, and fail closed on an unrecognized status since
the gateway response carries an open string.
2026-08-17 21:31:25 -07:00
Peter Steinberger
572e9f907a
fix(skills): expand explicit references on agent turns (#124784)
* fix(skills): expand explicit references on agent turns

Route generic Gateway, CLI, webhook, and local agent turns through the same explicit skill-reference renderer as channel auto-replies. Keep original transcript text, preserve unknown slash behavior, and fail visibly for allowlist-hidden skills.

Maintainer review: scoped Option 1 — generic agent turns expand both $skill-name and leading /skill-name args through shared skill rendering; they do not run the channel command dispatcher, and all other slash commands retain their existing behavior.

* fix(skills): bound explicit reference prompts

* fix(skills): prefer allowed reference collisions

* fix(skills): preserve command invocation boundaries

* fix(skills): reject hidden channel slash commands

* perf(skills): skip literal dollar discovery
2026-08-16 16:09:21 -07:00
Peter Steinberger
08507909ed
fix(cli): guard remaining embedded state writers (#121282) 2026-08-09 17:09:35 -07:00
Peter Steinberger
8ede4046e2
fix(cli): guard embedded agent state ownership (#120896) 2026-08-08 23:59:50 -07:00
Peter Steinberger
a4c6efc998
fix(cli): preserve installed plugins in agent exec (#116336)
Some checks are pending
Native App Locale Refresh / Refresh native fr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native hi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native id (push) Blocked by required conditions
Native App Locale Refresh / Refresh native sv (push) Blocked by required conditions
Native App Locale Refresh / Refresh native it (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pt-BR (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ru (push) Blocked by required conditions
Native App Locale Refresh / Refresh native th (push) Blocked by required conditions
Native App Locale Refresh / Refresh native tr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native uk (push) Blocked by required conditions
Native App Locale Refresh / Refresh native vi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / publish_plugins_npm (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Workflow Sanity / no-tabs (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
2026-07-30 03:00:17 -07:00
Peter Steinberger
d6f9affe79
feat(cli): run agent exec against the ambient config, composed in memory (#116038)
* feat(cli): run agent exec against the ambient config, composed in memory

Exec previously ignored the operator's config entirely, so a one-shot turn
could not reach configured providers, credentials, or agentRuntime harness
selection. It now layers config the way other folder-scoped coding CLIs do.

The composed config is published as this process's runtime snapshot rather
than serialized to a temp file and re-read through OPENCLAW_CONFIG_PATH. The
snapshot is the only in-process config cache, so the file only ever fed it --
while writing env-substituted provider keys to disk where the run's own exec
tool could read them.

* fix(cli): resolve exec stored credentials from the configured agent dir

* chore(scripts): allow agent exec the file-scoped config loader at its process boundary

* test(cli): cover the exec credential default and pinned-config flags
2026-07-29 15:38:27 -04:00
Peter Steinberger
3f4d65a672
feat(harness): report copilot code-mode engagement on the attempt result (#115913)
* feat(harness): report copilot code-mode engagement on the attempt result

* test(copilot): prove code-mode engagement through the production tool bridge

* docs: describe the normalized codeModeEngaged value for native harnesses
2026-07-29 14:44:15 -04:00
Vincent Koc
1c36054494
feat(agents): add code mode model acceptance matrix (#115305)
* feat(agents): add code mode model acceptance matrix

* fix(qa): emit canonical Code Mode matrix evidence

* fix(qa): reserve code mode matrix output safely

* fix(qa): require fresh matrix builds

* fix(qa): protect matrix evidence paths
2026-07-29 14:12:20 +08:00
Peter Steinberger
cf4cb0ac85
feat(agents): report per-run stats (code-mode engagement, round trips, cost) in agent JSON envelopes (#114688)
* feat(agents): add per-run stats to embedded agent run meta

Adds codeModeEngaged, assistantTurns, bridgeCalls, and costUsd to
EmbeddedAgentRunMeta.agentMeta and mirrors them on the agent exec --json
envelope. Code-mode engagement is stamped from the tool-surface truth,
round trips accumulate across attempts beside usage, bridge counts come
from the run's tool-search catalog counters, and cost reuses the shared
model pricing helpers (cache tiers included, omitted without cost data).

* fix(agents): accumulate bridge call counts across run attempts

Attempt cleanup clears the per-attempt tool-search catalog, so retries and
fallbacks discarded earlier bridge counts. Fold each attempt's bridgeCalls
into the run accumulator beside assistantTurns and stamp the cumulative
totals into agentMeta, matching the documented per-run contract.
2026-07-27 23:48:01 -04:00
Peter Steinberger
69399b1cc3
feat(cli): add openclaw agent exec headless one-shot runner (#113988)
* feat(cli): add agent exec headless runner

* test(cli): align agent parent startup paths

* fix(cli): scope agent exec environment explicitly
2026-07-25 20:59:20 -07:00
Peter Steinberger
6f43c50f37
fix(cli): preserve failure exit semantics (#112210) 2026-07-21 01:48:25 -07:00
Peter Steinberger
c5254f13ee
refactor(cli)!: remove automatic gateway→embedded fallback from openclaw agent (#112074)
A Gateway timeout or closed connection now fails the command with an
actionable stderr hint instead of silently re-running the whole turn
embedded under a fresh gateway-fallback-* session. The silent fallback
could double-execute side effects (the Gateway may still finish an
accepted turn), returned context-free answers to --session-key callers,
and ran with the CLI host's local config. --local remains the only
embedded execution path.

Also deletes the resultMetaOverrides plumbing (the fallback was its only
writer) and the fallback marker fields added in #111645.
2026-07-20 23:30:37 -07:00
cxbAsDev
05fb8e6e61
fix(cli): bound --message-file reads for agent command (#101442)
* fix(cli): bound --message-file reads for agent command

* fix(cli): preserve symlinked --message-file paths with bounded reads

* fix(cli): preserve FIFO message files with bounded reads, document 4 MiB cap

* fix(cli): accept FIFO --message-file targets via bounded descriptor read

* test(cli): drop duplicate FIFO message-file read test

* docs(cli): note 4 MiB --message-file cap in agent help text

* style(commands): format agent-via-gateway test

* fix(cli): preserve procfs message-file reads

Co-authored-by: 陈宪彪0668000387 <chen.xianbiao@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Peter Steinberger <peter@steipete.me>
2026-07-18 12:29:33 +01:00
Peter Steinberger
1c225c855d
fix: CLI timeout warnings explain stopped work (#110369)
* fix: clarify CLI timeout failures

* docs: update timeout docs map
2026-07-18 06:18:11 +01:00
xingzhou
0a868179e4
fix(session): stop repeated restart recovery after retry budget (#96230)
* fix(session): bound restart recovery across gateway restarts

Co-authored-by: Mason Huang <masonxhuang@proton.me>

* style(session): format restart recovery changes

* fix(session): fence recovery notice state

* test(session): align internal recovery types

* test(session): type recovery completion fixture

* style(session): satisfy recovery lint rules

* test(plugin-sdk): split recovery boundary coverage

* test(plugin-sdk): use tracked recovery temp dirs

* fix(session): preserve stale admission errors

* fix(session): close recovery lifecycle races

* fix(session): rotate rejected recovery dispatch ids

* fix(session): enforce recovery quarantine boundaries

* fix(session): close restart recovery exhaustion gaps

* fix(session): preserve recovery command narrowing

* test(session): type restart recovery fixtures

* fix(session): enforce restart recovery quarantine

* fix(session): close restart recovery races

* fix(session): type recovery lifecycle state

* fix(session): enforce recovery ownership fences

* fix(session): fence recovery lifecycle completion

* fix(session): quarantine cross-process recovery

* fix(session): retire stale recovery ownership

* fix(session): restore rejected recovery admission

* fix(session): preserve restored recovery target

* fix(session): retry pending recovery races

* fix(session): preserve concurrent recovery aborts

* fix(session): quarantine recovery lifecycle state

* fix(session): settle exact recovery delivery fences

* fix(session): keep recovery restoration internal

* fix(session): close recovery admission races

* fix(session): retry durable recovery rollback

* fix(session): guard cached recovery settlement

* fix(session): close recovery ownership gaps

* fix(session): resume after delayed recovery rollback

* fix(session): finalize unrecoverable restart state

* fix(session): retry admitted recovery restoration

* fix(session): preserve recovery cleanup guarantees

* fix(session): restore failed terminal settlement

* chore(plugin-sdk): refresh API baseline

* fix(session): close recovery owner retry races

* test(session): type recovery owner fixture

* refactor(session): remove obsolete owner validator

* fix(session): preserve explicit abort recovery

---------

Co-authored-by: Mason Huang <masonxhuang@proton.me>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-17 15:36:09 +01:00
Peter Steinberger
a2a68d154b
fix(agent): preserve explicit recipient sessions (#101507)
* fix(agent): honor recipient session routing

Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: pingfanfan <pingfan.work@gmail.com>

* fix(agent): preserve canonical recipient routes

* fix(agent): require exact recipient routes

Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>

Co-authored-by: pingfanfan <pingfan.work@gmail.com>

* fix(agent): harden recipient route resolution

* fix(imessage): require canonical recipient handles

* fix(agent): refine provider recipient exactness

* fix(agent): bound direct alias session routing

* fix(signal): preserve direct alias route type

* fix(agent): honor binding-scoped recipient sessions

* fix(routing): honor configured main session aliases

* fix(clickclack): align account-owned session routes

* fix(twitch): preserve canonical recipient sessions

* fix(routing): isolate stable outbound identities

* chore: defer recipient session changelog

* fix(sms): use dedicated channel SDK facade

---------

Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: pingfanfan <pingfan.work@gmail.com>
2026-07-07 10:07:13 +01:00
Peter Steinberger
f7d7148cf0
docs: rewrite published docs grounded in current source (#100142)
Source-grounded rewrite of 529 published docs pages with per-unit information-loss verification: 1,713 factual corrections cited to src/**, generated surfaces regenerated, frontmatter titles preserved for i18n, release notes pages untouched. All docs gates green.

Closes #100141
2026-07-05 00:32:47 -04:00
ooiuuii
a0fedcfb7e
feat(cli): add --message-file to openclaw agent
Merges the Clownfish-repaired contributor branch for #93351. The latest repair preserves inline --message whitespace, adds --message-file coverage for gateway and local embedded runs, and the PR is clean/mergeable on head 4897f2fc20.
2026-06-22 20:13:57 +08:00
Kaspre
01fce88082 fix(agent): abort accepted gateway runs on signal 2026-05-22 09:16:36 +01:00
Kaspre
eb7f3b7b50
fix(agent): support explicit CLI session keys (#85121)
Some checks are pending
CI / check-lint (push) Blocked by required conditions
CI / check-prod-types (push) Blocked by required conditions
CI / check-test-types (push) Blocked by required conditions
CI / check-additional-boundaries-a (push) Blocked by required conditions
CI / check-additional-boundaries-bcd (push) Blocked by required conditions
CI / check-additional-extension-bundled (push) Blocked by required conditions
CI / check-additional-extension-channels (push) Blocked by required conditions
CI / check-additional-extension-package-boundary (push) Blocked by required conditions
CI / check-additional-runtime-topology-architecture (push) Blocked by required conditions
CI / check-docs (push) Blocked by required conditions
CI / skills-python (push) Blocked by required conditions
CI / -4 (push) Blocked by required conditions
CI / -5 (push) Blocked by required conditions
CI / macos-swift (push) Blocked by required conditions
CI / -6 (push) Blocked by required conditions
ClawSweeper Dispatch / dispatch (push) Waiting to run
Docs Sync Publish Repo / sync-publish-repo (push) Waiting to run
Docs / docs (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / publish_plugins_npm (push) Blocked by required conditions
Website Installer Sync / static (push) Waiting to run
Website Installer Sync / linux-docker (push) Waiting to run
Website Installer Sync / macos-installer (push) Waiting to run
Website Installer Sync / windows-installer (push) Waiting to run
Website Installer Sync / sync-website (push) Blocked by required conditions
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / no-tabs (push) Waiting to run
Summary:
- The PR adds `openclaw agent --session-key`, normalizes explicit session keys through Gateway and embedded agent execution, and updates docs, tests, and changelog.
- Reproducibility: yes. Current main's `openclaw agent` registration and gateway CLI option type lack `--sessi ... Gateway agent protocol already accepts `sessionKey`; this is source-reproducible without executing the CLI.

Automerge notes:
- PR branch already contained follow-up commit before automerge: fix(agent): support explicit CLI session keys

Validation:
- ClawSweeper review passed for head 2c76dd339f.
- Required merge gates passed before the squash merge.

Prepared head SHA: 2c76dd339f
Review: https://github.com/openclaw/openclaw/pull/85121#issuecomment-4513508932

Co-authored-by: Kaspre <kaspre@gmail.com>
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: clawsweeper[bot] <274271284+clawsweeper[bot]@users.noreply.github.com>
Approved-by: takhoffman
Co-authored-by: takhoffman <781889+takhoffman@users.noreply.github.com>
2026-05-22 03:08:25 +00:00
Peter Steinberger
694ca50e97
Revert "refactor: move runtime state to SQLite"
This reverts commit f91de52f0d.
2026-05-13 13:33:38 +01:00
Peter Steinberger
f91de52f0d
refactor: move runtime state to SQLite
* refactor: remove stale file-backed shims

* fix: harden sqlite state ci boundaries

* refactor: store matrix idb snapshots in sqlite

* fix: satisfy rebased CI guardrails

* refactor: store current conversation bindings in sqlite table

* refactor: store tui last sessions in sqlite table

* refactor: reset sqlite schema history

* refactor: drop unshipped sqlite table migration

* refactor: remove plugin index file rollback

* refactor: drop unshipped sqlite sidecar migrations

* refactor: remove runtime commitments kv migration

* refactor: preserve kysely sync result types

* refactor: drop unshipped sqlite schema migration table

* test: keep session usage coverage sqlite-backed

* refactor: keep sqlite migration doctor-only

* refactor: isolate device legacy imports

* refactor: isolate push voicewake legacy imports

* refactor: isolate remaining runtime legacy imports

* refactor: tighten sqlite migration guardrails

* test: cover sqlite persisted enum parsing

* refactor: isolate legacy update and tui imports

* refactor: tighten sqlite state ownership

* refactor: move legacy imports behind doctor

* refactor: remove legacy session row lookup

* refactor: canonicalize memory transcript locators

* refactor: drop transcript path scope fallbacks

* refactor: drop runtime legacy session delivery pruning

* refactor: store tts prefs only in sqlite

* refactor: remove cron store path runtime

* refactor: use cron sqlite store keys

* refactor: rename telegram message cache scope

* refactor: read memory dreaming status from sqlite

* refactor: rename cron status store key

* refactor: stop remembering transcript file paths

* test: use sqlite locators in agent fixtures

* refactor: remove file-shaped commitments and cron store surfaces

* refactor: keep compaction transcript handles out of session rows

* refactor: derive transcript handles from session identity

* refactor: derive runtime transcript handles

* refactor: remove gateway session locator reads

* refactor: remove transcript locator from session rows

* refactor: store raw stream diagnostics in sqlite

* refactor: remove file-shaped transcript rotation

* refactor: hide legacy trajectory paths from runtime

* refactor: remove runtime transcript file bridges

* refactor: repair database-first rebase fallout

* refactor: align tests with database-first state

* refactor: remove transcript file handoffs

* refactor: sync post-compaction memory by transcript scope

* refactor: run codex app-server sessions by id

* refactor: bind codex runtime state by session id

* refactor: pass memory transcripts by sqlite scope

* refactor: remove transcript locator cleanup leftovers

* test: remove stale transcript file fixtures

* refactor: remove transcript locator test helper

* test: make cron sqlite keys explicit

* test: remove cron runtime store paths

* test: remove stale session file fixtures

* test: use sqlite cron keys in diagnostics

* refactor: remove runtime delivery queue backfill

* test: drop fake export session file mocks

* refactor: rename acp session read failure flag

* refactor: rename acp row session key

* refactor: remove session store test seams

* refactor: move legacy session parser tests to doctor

* refactor: reindex managed memory in place

* refactor: drop stale session store wording

* refactor: rename session row helpers

* refactor: rename sqlite session entry modules

* refactor: remove transcript locator leftovers

* refactor: trim file-era audit wording

* refactor: clean managed media through sqlite

* fix: prefer explicit agent for exports

* fix: use prepared agent for session resets

* fix: canonicalize legacy codex binding import

* test: rename state cleanup helper

* docs: align backup docs with sqlite state

* refactor: drop legacy Pi usage auth fallback

* refactor: move legacy auth profile imports to doctor

* refactor: keep Pi model discovery auth in memory

* refactor: remove MSTeams legacy learning key fallback

* refactor: store model catalog config in sqlite

* refactor: use sqlite model catalog at runtime

* refactor: remove model json compatibility aliases

* refactor: store auth profiles in sqlite

* refactor: seed copied auth profiles in sqlite

* refactor: make auth profile runtime sqlite-addressed

* refactor: migrate hermes secrets into sqlite auth store

* refactor: move plugin install config migration to doctor

* refactor: rename plugin index audit checks

* test: drop auth file assumptions

* test: remove legacy transcript file assertions

* refactor: drop legacy cli session aliases

* refactor: store skill uploads in sqlite

* refactor: keep subagent attachments in sqlite vfs

* refactor: drop subagent attachment cleanup state

* refactor: move legacy session aliases to doctor

* refactor: require node 24 for sqlite state runtime

* refactor: move provider caches into sqlite state

* fix: harden virtual agent filesystem

* refactor: enforce database-first runtime state

* refactor: rename compaction transcript rotation setting

* test: clean sqlite refactor test types

* refactor: consolidate sqlite runtime state

* refactor: model session conversations in sqlite

* refactor: stop deriving cron delivery from session keys

* refactor: stop classifying sessions from key shape

* refactor: hydrate announce targets from typed delivery

* refactor: route heartbeat delivery from typed sqlite context

* refactor: tighten typed sqlite session routing

* refactor: remove session origin routing shadow

* refactor: drop session origin shadow fixtures

* perf: query sqlite vfs paths by prefix

* refactor: use typed conversation metadata for sessions

* refactor: prefer typed session routing metadata

* refactor: require typed session routing metadata

* refactor: resolve group tool policy from typed sessions

* refactor: delete dead session thread info bridge

* Show Codex subscription reset times in channel errors (#80456)

* feat(plugin-sdk): consolidate session workflow APIs

* fix(agents): allow read-only agent mount reads

* [codex] refresh plugin regression fixtures

* fix(agents): restore compaction gateway logs

* test: tighten gateway startup assertions

* Redact persisted secret-shaped payloads [AI] (#79006)

* test: tighten device pair notify assertions

* test: tighten hermes secret assertions

* test: assert matrix client error shapes

* test: assert config compat warnings

* fix(heartbeat): remap cron-run exec events to session keys (#80214)

* fix(codex): route btw through native side threads

* fix(auth): accept friendly OpenAI order for Codex profiles

* fix(codex): rotate auth profiles inside harness

* fix: keep browser status page probe within timeout

* test: assert agents add outputs

* test: pin cron read status

* fix(agents): avoid Pi resource discovery stalls

Co-authored-by: dataCenter430 <titan032000@gmail.com>

* fix: retire timed-out codex app-server clients

* test: tighten qa lab runtime assertions

* test: check security fix outputs

* test: verify extension runtime messages

* feat(wake): expose typed sessionKey on wake protocol + system event CLI

* fix(gateway): await session_end during shutdown drain and track channel + compaction lifecycle paths (#57790)

* test: guard talk consult call helper

* fix(codex): scale context engine projection (#80761)

* fix(codex): scale context engine projection

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* fix: document Codex context projection scaling

* chore: align Codex projection changelog

* chore: realign Codex projection changelog

* fix: isolate Codex projection patch

---------

Co-authored-by: Eva (agent) <eva+agent-78055@100yen.org>
Co-authored-by: Josh Lehman <josh@martian.engineering>

* refactor: move agent runtime state toward piless

* refactor: remove cron session reaper

* refactor: move session management to sqlite

* refactor: finish database-first state migration

* chore: refresh generated sqlite db types

* refactor: remove stale file-backed shims

* test: harden kysely type coverage

# Conflicts:
#	.agents/skills/kysely-database-access/SKILL.md
#	src/infra/kysely-sync.types.test.ts
#	src/proxy-capture/store.sqlite.test.ts
#	src/state/openclaw-agent-db.test.ts
#	src/state/openclaw-state-db.test.ts

* refactor: remove cron store path runtime

* refactor: keep compaction transcript handles out of session rows

* refactor: derive embedded transcripts from sqlite identity

* refactor: remove embedded transcript locator handoff

* refactor: remove runtime transcript file bridges

* refactor: remove transcript file handoffs

* refactor: remove MSTeams legacy learning key fallback

* refactor: store model catalog config in sqlite

* refactor: use sqlite model catalog at runtime

# Conflicts:
#	docs/cli/secrets.md
#	docs/gateway/authentication.md
#	docs/gateway/secrets.md

* fix: keep oauth sibling sync sqlite-local

# Conflicts:
#	src/commands/onboard-auth.test.ts

* refactor: remove task session store maintenance

# Conflicts:
#	src/commands/tasks.ts

* refactor: keep diagnostics in state sqlite

* refactor: enforce database-first runtime state

* refactor: consolidate sqlite runtime state

* Show Codex subscription reset times in channel errors (#80456)

* fix(codex): refresh subscription limit resets

* fix(codex): format reset times for channels

* Update CHANGELOG with latest changes and fixes

Updated CHANGELOG with recent fixes and improvements.

* fix(codex): keep command load failures on codex surface

* fix(codex): format account rate limits as rows

* fix(codex): summarize account limits as usage status

* fix(codex): simplify account limit status

* test: tighten subagent announce queue assertion

* test: tighten session delete lifecycle assertions

* test: tighten cron ops assertions

* fix: track cron execution milestones

* test: tighten hermes secret assertions

* test: assert matrix sync store payloads

* test: assert config compat warnings

* fix(codex): align btw side thread semantics

* fix(codex): honor codex fallback blocking

* fix(agents): avoid Pi resource discovery stalls

* test: tighten codex event assertions

* test: tighten cron assertions

* Fix Codex app-server OAuth harness auth

* refactor: move agent runtime state toward piless

* refactor: move device and push state to sqlite

* refactor: move runtime json state imports to doctor

* refactor: finish database-first state migration

* chore: refresh generated sqlite db types

* refactor: clarify cron sqlite store keys

* refactor: remove stale file-backed shims

* refactor: bind codex runtime state by session id

* test: expect sqlite trajectory branch export

* refactor: rename session row helpers

* fix: keep legacy device identity import in doctor

* refactor: enforce database-first runtime state

* refactor: consolidate sqlite runtime state

* build: align pi contract wrappers

* chore: repair database-first rebase

* refactor: remove session file test contracts

* test: update gateway session expectations

* refactor: stop routing from session compatibility shadows

* refactor: stop persisting session route shadows

* refactor: use typed delivery context in clients

* refactor: stop echoing session route shadows

* refactor: repair embedded runner rebase imports

# Conflicts:
#	src/agents/pi-embedded-runner/run/attempt.tool-call-argument-repair.ts

* refactor: align pi contract imports

* refactor: satisfy kysely sync helper guard

* refactor: remove file transcript bridge remnants

* refactor: remove session locator compatibility

* refactor: remove session file test contracts

* refactor: keep rebase database-first clean

* refactor: remove session file assumptions from e2e

* docs: clarify database-first goal state

* test: remove legacy store markers from sqlite runtime tests

* refactor: remove legacy store assumptions from runtime seams

* refactor: align sqlite runtime helper seams

* test: update memory recall sqlite audit mock

* refactor: align database-first runtime type seams

* test: clarify doctor cron legacy store names

* fix: preserve sqlite session route projections

* test: fix copilot token cache test syntax

* docs: update database-first proof status

* test: align database-first test fixtures

* docs: update database-first proof status

* refactor: clean extension database-first drift

* test: align agent session route proof

* test: clarify doctor legacy path fixtures

* chore: clean database-first changed checks

* chore: repair database-first rebase markers

* build: allow baileys git subdependency

* chore: repair exp-vfs rebase drift

* chore: finish exp-vfs rebase cleanup

* chore: satisfy rebase lint drift

* chore: fix qqbot rebase type seam

* chore: fix rebase drift leftovers

* fix: keep auth profile oauth secrets out of sqlite

* fix: repair rebase drift tests

* test: stabilize pairing request ordering

* test: use source manifests in plugin contract checks

* fix: restore gateway session metadata after rebase

* fix: repair database-first rebase drift

* fix: clean up database-first rebase fallout

* test: stabilize line quick reply receipt time

* fix: repair extension rebase drift

* test: keep transcript redaction tests sqlite-backed

* fix: carry injected transcript redaction through sqlite

* chore: clean database branch rebase residue

* fix: repair database branch CI drift

* fix: repair database branch CI guard drift

* fix: stabilize oauth tls preflight test

* test: align database branch fast guards

* test: repair build artifact boundary guards

* chore: clean changelog rebase markers

---------

Co-authored-by: pashpashpash <nik@vault77.ai>
Co-authored-by: Eva <eva@100yen.org>
Co-authored-by: stainlu <stainlu@newtype-ai.org>
Co-authored-by: Jason Zhou <jason.zhou.design@gmail.com>
Co-authored-by: Ruben Cuevas <hi@rubencu.com>
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com>
Co-authored-by: Shakker <shakkerdroid@gmail.com>
Co-authored-by: Kaspre <36520309+Kaspre@users.noreply.github.com>
Co-authored-by: dataCenter430 <titan032000@gmail.com>
Co-authored-by: Kaspre <kaspre@gmail.com>
Co-authored-by: pandadev66 <nova.full.stack@outlook.com>
Co-authored-by: Eva <admin@100yen.org>
Co-authored-by: Eva (agent) <eva+agent-78055@100yen.org>
Co-authored-by: Josh Lehman <josh@martian.engineering>
Co-authored-by: jeffjhunter <support@aipersonamethod.com>
2026-05-13 13:15:12 +01:00
Peter Steinberger
f50ece6d62 fix(cli): expose gateway delivery status 2026-05-10 14:09:01 +01:00
Kaspre
7903fe2ab7 docs(cli): clarify delivery error fields 2026-05-10 14:09:01 +01:00
Kaspre
94d923c055 fix(cli): surface durable delivery status 2026-05-10 14:09:01 +01:00
Hemant Sudarshan
fbae2a6441
Fix gateway timeout embedded fallback session lock (#74543)
* Agent: isolate gateway timeout fallback sessions

* fix(cli): isolate gateway timeout fallback sessions

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-04-29 19:38:11 +01:00
Frank Yang
e008830d0e
fix(agents): clean up local Claude stdio runs (#73292)
Clean up local Claude stdio one-shot runs before returning from embedded `openclaw agent --local`, including bundle MCP loopback teardown for local process resources.

Keeps gateway-owned MCP loopback cleanup internal to the Gateway, documents the local-vs-gateway behavior, and aligns the stale OpenAI provider-runtime fixture with the current unsupported Codex mini route.
2026-04-28 07:06:01 +01:00
Alex Knight
b1e530b204
fix(cli): mark embedded agent fallback (#72730)
* fix(cli): mark embedded agent fallback

* refactor(cli): structure embedded fallback metadata

* refactor(cli): move fallback metadata types out of EmbeddedPiRunMeta

---------

Co-authored-by: Alex Knight <15041791+amknight@users.noreply.github.com>
2026-04-27 22:14:11 +10:00
Peter Steinberger
fd9d32f022
fix(agents): retry empty compatible turns 2026-04-27 11:44:55 +01:00
Peter Steinberger
e0bee76fb0
fix: retire one-shot agent MCP runtimes 2026-04-25 08:58:02 +01:00
Peter Steinberger
96515891a2
fix: keep agent json stdout clean 2026-04-25 04:32:18 +01:00
Vincent Koc
8d1f98ef08
docs(gateway,platforms,cli): add Related sections to entry and reference pages 2026-04-23 20:08:26 -07:00
Vincent Koc
2777b089b5
docs: normalize frontmatter titles to sentence case 2026-04-23 13:15:17 -07:00
Peter Steinberger
f1805ab54d
fix: centralize provider thinking profiles 2026-04-21 09:13:35 +01:00