mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
2407 commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
5697a7277a
|
fix(agents): use exact model rows for harness support (#147849)
Keep API, endpoint, and request override facts tied to the selected configured model. Reuse the existing configured-row resolver and remove duplicate prefix stripping and normalized-row merging from harness support. Preserve literal legacy selection, legacy-only fallback, and same-spelling duplicate semantics. Registered-harness regressions fail in both conflicting row orders before the fix; 203 focused tests, the changed-file gate, and independent review pass. Related: #130706, #143822. |
||
|
|
d46f9ebf2b
|
fix(memory): explain partial search timeouts and allow 30 seconds (#147702) | ||
|
|
f8b194a5be
|
fix: restore plugin networking under Bun (#147421)
* fix(plugins): normalize network runtimes * build(plugins): align network runtime dependencies * test(runtime): stabilize network compatibility checks * fix(codex): route managed transports through runtime owners |
||
|
|
cc5a7467f9
|
fix(tasks): record execution ownership and settle orphaned records at restore (#147585)
* fix(tasks): settle orphaned execution records at restore Record nullable process ownership for Gateway runs and local native harness processes. Settle confirmed dead owners through the existing restart outcome normalizer before restored tasks can block another drain. Preserve live, foreign-host, unknown, and legacy ownership. Add compatible nullable SQLite columns without changing the schema version. Reported by @gregbond (#143420). * fix(tasks): keep unchanged restores read-only Request write admission only when restored state contains a confirmed orphan, then reread and revalidate ownership before persisting settlement. Preserve existing create/delete admission-failure semantics and cover a concurrent owner rebind. List the three approved nullable ownership columns in the canonical additive schema contract test without relaxing its declaration checks. * fix(tasks): preserve newer flow results during restore Synchronize a restored orphan's mirrored flow only when that task is the latest linked record. Keep newer live and completed successors' status, goal, and terminal timestamps while still settling the orphaned task. Cover both mixed-owner cases through the registry restore boundary. |
||
|
|
3a99779313
|
fix(codex): isolate hook imports and cancel disconnected waits (#147444)
Isolate the native hook relay build graph while preserving readonly state lookup, explicit policy decisions, and the lazy authenticated Gateway fallback. Cancel disconnected request waits through the existing approval authority. Keep duplicate callers independently cancellable, retain unbound durable approval deduplication, and detach exact relay-owned entries before callbacks so old cleanup cannot remove a successor. Observe already-started promises when synchronous cancellation wins. Update managed Codex to the official 0.154.0 release and align its version fixtures and current documentation. This improves lifecycle ownership and reduces the relay import closure; it does not cap hook concurrency, prove faster bursts, or establish resolution of the historical constrained-host timeout. Related: https://github.com/openclaw/openclaw/issues/91009 Thanks to @nvtoroy for the constrained-host captures and guarded opt-out evidence in https://github.com/openclaw/openclaw/pull/121668 and https://github.com/openclaw/openclaw/pull/111205. The opt-out proposal remains distinct and unimplemented by this change. |
||
|
|
cb9c7d992b
|
refactor(plugins): remove unused provider wizard option projection (#146695)
Keep setup choices on the canonical manifest/install-catalog flow and remove
the unused runtime option producer, private shape, and builder. Retain
provider choice resolution, model pickers, model-selected hooks, and public
provider types. Move repository-local test coverage to the surviving owners
and remove only the already-retired test-helper exports and documentation.
Include the canonical constrained-host lint prerequisite from
|
||
|
|
23b0cacfc5
|
fix(ui): hide deleted Beams immediately in the sidebar (#147460) | ||
|
|
dab1f08376
|
feat: give every plugin a compact chat activity icon (#147333)
* feat: give every plugin a compact chat activity icon Separate package-owned activity SVGs from plugin identity artwork. Ship 154 defaults and seven exact tool overrides, preserving Echo and the progress claw. Include authenticated bounded delivery, safe mask rendering, packaging, and authoring guidance. * test: declare Vite types for the activity asset browser test * refactor: keep plugin artwork selection with catalog presentation facts * test: scope activity browser types and simplify fixture copies |
||
|
|
2386efc05c
|
feat(code-mode): infer results from the requested action (#147291)
Some checks failed
Native App Locale Refresh / Refresh native vi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / publish_plugins_npm (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / warm (linux) (push) Waiting to run
Vitest Cache Warm / warm (macos) (push) Waiting to run
Workflow Sanity / no-tabs (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / debian-installer (push) Has been cancelled
Website Installer Sync / linux-build-tools-failure (push) Has been cancelled
Website Installer Sync / linux-non-root (push) Has been cancelled
Website Installer Sync / Fedora installer (non-root) (push) Has been cancelled
Website Installer Sync / Fedora installer (root) (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
* feat(code-mode): infer action-specific tool results * refactor(agents): simplify tool call id normalization |
||
|
|
b45e2464f5
|
feat(workboard): add selection and bulk card actions (#144756)
* feat(workboard): add selection and bulk card actions * test(workboard): cover retry after partial bulk edit failure * build(workboard): refresh bulk action assets * test(workboard): use the gateway request contract in bulk fixtures * test(workboard): reuse the typed request fixture * fix(workboard): guard bulk actions against stale cards * fix(workboard): preserve revisions across linked bulk deletes * fix(workboard): preserve card snapshots when applying delete receipts * build: refresh Workboard browser assets * test(workboard): await concurrent SQLite fixture cleanup |
||
|
|
31c6862ff8
|
refactor(workboard): refine card and board editors (#144754)
* refactor(ui): refine Workboard card and board editors * test(workboard): cover editor retry guidance and appearance resets * fix(workboard): initialize column drafts before tracking edits * refactor(workboard): mount appearance controls with editors * build(workboard): refresh editor assets * refactor(workboard): introduce assignment helpers with editors * refactor(workboard): retire unused editor selection adapters * test(workboard): introduce radio readiness checks with editors * fix(workboard): preserve appearance updates and isolate emoji input * fix(control-ui): preserve emoji composition in editors * build: refresh Workboard browser assets * test(workboard): adapt appearance fixtures to SQLite worker |
||
|
|
c1258c0864
|
refactor(ui): share Workboard selection and appearance controls (#144748)
* refactor(ui): share agent and appearance controls * style(ui): apply the pinned formatter to shared controls * test(ui): keep shared control proof independent of Workboard details * refactor(workboard): defer adapters to their first consumers * fix(ui): hydrate shared avatars and apply appearance colors * fix(control-ui): isolate appearance colors by component * fix(ui): retain shared agent selection styles * test(ui): await appearance glyph import before assertions |
||
|
|
cd1ff2a4d6
|
feat: load CDN libraries and fonts in widgets (#147265)
* feat: load CDN libraries and fonts in widgets Share public static-resource origins across document, sandbox, and channel policies while keeping API access and native Gateway pins separate. Add visualization guidance for inline code explanations and persistent dashboards. * fix: preserve local widget renderers in direct hosting Keep document-approved same-origin renderer scripts available in the intersecting HTTP CSP. Cover stored and newly wrapped registered documents without granting API connections. |
||
|
|
21de1eaf75
|
fix(ui): remove floating customization button (#147245)
Keep plugin view selection and reload on the Plugins page. Render that page in the built-in workspace so operators can recover custom workspaces without a floating control. |
||
|
|
38fb08d04b
|
refactor(workboard): keep SQLite work off the Gateway event loop (#146976)
* refactor(workboard): run SQLite persistence in workers Preserve board-scoped hydration and card-scoped notification reads while moving complete database operations to plugin-owned worker connection leases. Drain admitted work and retain retryable cleanup across service retirement and transport failure. * test(workboard): preserve unclassified plugin routing coverage * test(workboard): await persisted cleanup outcomes |
||
|
|
c456e000de
|
fix(google-meet): honor summary output paths (#147078)
Route artifact and attendance summaries through the existing output writer, preserving summary bytes, file modes, and explicit write failures. Remove the direct-stdout summary paths. |
||
|
|
60643b4d0b
|
fix(channels): keep replies working after hot config reloads (#147001)
Keep inbound channel replies working after hot config reloads when a long-lived plugin monitor retains its startup config. Shared reply dispatch now always selects the Gateway's committed model-runtime publication, preserving exact catalog isolation and publication waits without restarting the monitor. The shipped optional usePublishedModelRuntime SDK argument remains accepted, deprecated, and ignored until the next SDK major. Standalone dispatch and explicit per-turn overrides retain their existing contracts; transport durability remains owned by channel ingress. The low-level regression delivers before reload, fails on the original code after reload with PreparedModelCatalogConfigReplacedError, and passes after the fix. Focused dispatch and sibling tests, standalone runner fixtures, build, and changed-file checks passed. A synthetic Gateway/channel/HTTP-provider harness delivered two replies around reload with the same Gateway process and monitor; real WeChat and Windows coverage remains unproven. Fixes #146854 Related: #145563 Reported by @sunhsiao (#146854). Reproduction discussion and regression shape from @Lidashi1025 and @BronyaZaychik0328 (#145563). |
||
|
|
e05d8b6c90
|
fix: admit borrowed memory writes through the agent database owner (#146760) | ||
|
|
0d1cf24318
|
fix: settle embedded transcript repairs before session cleanup (#146842)
* fix(agents): settle embedded transcript writes before cleanup * test: supply session manager in prompt error fixtures |
||
|
|
b10035faa9
|
fix(backup): archive unmanaged SQLite files as opaque bytes (#146700)
## What Problem This Solves
An unrelated SQLite file with foreign-key violations could prevent every backup from completing.
## Why This Change Was Made
Whether an included file gets the live-database snapshot path is decided by exactly one mechanism at `src/commands/backup-resource-inventory.ts:336`, from the core set plus declared plugin resources. The online root snapshot supplies the registry used for discovery and traversal, so planning no longer needs a quiet write-ahead log.
## User Impact
Undeclared files survive backup unchanged with filename warnings. Foreign SQLite symbolic links that exceed the link-resolution limit (`ELOOP`), including loops, are skipped with a filename warning. Corrupt managed databases and unavailable plugin SQLite capabilities still stop publication.
## Evidence
- Pinned main `
|
||
|
|
877f157740
|
fix(agents): retain session writes through database admission (#146732) | ||
|
|
44ea63fe35
|
refactor(tasks): move managed child linkage to shared worker (#146678) | ||
|
|
2716950abf
|
fix(plugins): reuse registrations with prepared metadata (#146703) | ||
|
|
f5d9acfa70
|
refactor: share Markdown table parsing for Teams (#146464) | ||
|
|
ee679bb785
|
fix(state): share agent write admission with trajectory producers (#146563)
* fix: keep I/O responsive during queued session writes * test(telegram): await debounced dispatch completion * fix(state): share agent write admission with trajectory producers * fix(gateway): join worker event writes before acknowledgment |
||
|
|
e360372317
|
fix: avoid repeated catalog refreshes after slow discovery (#146665) | ||
|
|
f1c1f274ef
|
fix(session-share): hide subagents and tool activity (#146598)
* test(upgrade): assert explicit baseline plugin * fix(session-share): hide subagents and tool activity Publish only user and assistant conversation text from eligible root sessions. Preserve forks, redaction, read-only storage, and pagination; reject cursors from the previous mixed-item projection. Skip unrelated local adoption scans for publication-only catalog queries. |
||
|
|
a84d90b9c2
|
fix(models): reclaim plugin captures after catalog workers stop (#146513)
Give each catalog Worker a parent-owned capture directory. Release execution at confirmed Worker exit and join detached advisory cleanup on pool close. Preserve static Worker options, and fence synchronous cancellation during preparation or construction before releasing ownership. Make full-catalog test assertions follow the existing completed publication after one bounded foreground request, preserving pending and cancellation coverage and all production deadlines. |
||
|
|
1db6e89d4e
|
fix(gateway): release retired catalog waiters (#146498)
* fix(gateway): release retired catalog waiters * refactor(gateway): separate catalog admission from provider results |
||
|
|
404387d910
|
feat(telegram): apply access and reply policy without reconnecting (#146129)
* feat(telegram): apply access and reply policy without reconnecting * test(telegram): align retained-turn fixtures with extension contracts * test(telegram): use typed reload policy keys * fix(telegram): refresh ingress policy before cancellation |
||
|
|
b04aaad592
|
fix(nextcloud-talk): reject excess concurrent webhook reads (#146356)
* fix(nextcloud-talk): reject excess concurrent webhook reads Acquire a listener-owned in-flight limiter slot before the unauthenticated webhook body read, reject overflow with a close-aware HTTP 429, and release the slot after signature verification but before authenticated dispatch. Incomplete requests previously pinned a pre-auth reader for the full timeout without consuming the authentication-failure budget, letting any reachable client hold unbounded numbers of sockets and readers to degrade webhook availability. This follows the owner-level pattern merged for SMS (#136504) and Feishu (#137230). * fix(nextcloud-talk): preserve queued acknowledgements under pipelined overflow Serialize webhook admission per connection through the shared HTTP request lifecycle (runHttpConnectionRequest, re-exported on the plugin SDK guards subpath) so a pipelined request's overflow rejection only starts after every earlier response on the connection finished. Covers the reviewed sequence with real TCP: a saturated keep-alive connection with admission pending past the one-second close timer must still deliver the earlier signed 200 before the close-aware 429. * docs(nextcloud-talk): document overload admission and SDK connection ordering Record the 64-slot admission bound, its close-aware 429 overflow behavior, ordered keep-alive acknowledgements, and the unverified sender-redelivery risk in the channel guide. Document runHttpConnectionRequest's response-completion and closure semantics for plugin-owned webhook listeners on the SDK infrastructure page. * docs(nextcloud-talk): correct overload mitigation guidance The 64-read admission budget is hard-coded and not configurable, so raising reverse-proxy connection limits cannot relieve saturation and can feed more requests into the rejection path. Advise reducing or buffering upstream concurrency instead, and state plainly that the budget is fixed. |
||
|
|
e7b868bbab
|
feat(voice): share GPT Live across meetings and calls (#146546)
* feat(voice): unify Live sessions across calls and meetings Resolve provider capabilities and interruption policy through the shared realtime voice owner. Keep meeting input isolated from virtual-microphone output, reuse native delegation for meetings and Voice Call, and preserve explicit Stop across browser and Apple relay clients.\n\nValidated with real Live API and synthetic Chromium/WebRTC proof, focused regressions, changed-file checks, and independent review. Related to #146289. * test(voice): align capture fixtures and validation gates Model browser audio capture in the shared meeting RPC fixtures so startup failure tests reach the provider and verify capture cleanup. Preserve the same relay startup behavior while simplifying duplicate lifecycle branches. Rebalance the pre-existing 702-root platform test graph by moving security tests beside sandbox/tool tests; keep coverage, graph counts, and limits. * fix(meetings): preserve configured input commands Keep explicitly configured capture/filter/mixer output as provider input on local Chrome and paired nodes, preserving the v2026.9.4 contract. Generated input and output-only overrides continue to use managed browser capture. Retain Live's isolation guard and explain how to remove an input override when selecting Live. Prove the actual PCM paths through both meeting engines and transports, and document the preserved configuration behavior. |
||
|
|
0be813c33d
|
fix(ui): make coding session discovery settings easy to find (#146502)
* fix(ui): surface coding session discovery controls Add a sidebar shortcut and searchable session source settings for installed Claude Code, Codex, OpenCode, and Pi plugins. Reuse the existing Gateway configuration owner, including Pi's ACPX preference, and keep unavailable schemas visible without permitting invalid edits. Preserve existing defaults. * perf(ui): simplify session source menu navigation |
||
|
|
54a986072f
|
docs(plugins): remove obsolete Gateway restart guidance (#146516)
* docs(plugins): remove obsolete Gateway restart guidance * docs(plugins): simplify apply hints and update Session Share guidance |
||
|
|
5b792cf8f3
|
refactor(tasks): move managed flow state changes to SQLite workers (#146495) | ||
|
|
82ab1e1f58
|
fix(qa): isolate gateway child supervisor state (#146397) | ||
|
|
2bfd953001
|
fix: await approval target persistence before completing delivery (#146325)
* fix: await approval target persistence before completing delivery * fix(test): preserve aggregate extension routing |
||
|
|
5278a8f2ed
|
feat: share selected sessions read-only with a paired team Gateway (#136253)
* feat(node-host): advertise an explicit node command allowlist Persist exact node command selection and restrict ancillary publication and hosting. Preserve the unchanged assertion baseline under the work-order stop rule; check:changed requests removing the obsolete runtime.ts count (2 to 0). * feat(plugin-sdk): session transcript catalog reader Expose bounded read-only native display pages and portable attribution through the existing runtime subpath. Keep pagination scoped to the original active transcript branch and allow an explicit bounded native cursor length. * feat(session-share): read-only OpenClaw session catalog across paired gateways Publish explicitly selected native session groups through two paired node commands. Validate the closed wire contract, reject remote profile claims, and keep receiver identity binding opt-in and display-only. * fix(gateway): show published session catalogs to view-scoped roles Let publication consent satisfy catalog read visibility for roles allowed to view others, while owner-only and unprofiled callers stay hidden. Preserve published attribution without accepting a remote local-session adoption claim. Regression tests reproduce four pre-fix failures; final validation stopped at the work-order baseline gate. * docs: session sharing across gateways Document sessions-only node setup, explicit publication groups, receiver attribution, view-scoped catalog access, and read-only limits. Add the bundled plugin inventory and generated reference entry. Live proof runbook remains outside the repository; build and rig execution are blocked by the work-order baseline restriction. * fix(session-share): preserve source storage and paired reconnects Respect configured stores through listing, paging, and revocation. Keep cold listings available and bound raw transcript reads. Prefer the established paired node credential on service restart, suppress unrelated host metrics, and refresh the approved plugin configuration docs. * refactor(gateway): separate authorized catalog reads Keep the catalog dispatcher within its owned scope and preserve post-read role checks and sender projection. Align the rebased tests with their shared setup and imports. |
||
|
|
1c2b861e6e
|
fix(auth): keep plugin auth available during provider discovery (#146336)
* fix(auth): keep synthetic auth discovery with its provider owner Preserve auth-only descriptors and skip catalog-only matches before selecting a provider. Bound lightweight fallback to refs without a declared owner, so unrelated discovery failures cannot hide valid native auth or force unnecessary cold admission. Keep fresh external-auth capture and immutable plugin generation ownership intact. * fix(auth): preserve provider match evaluation order Match the provider reference before inspecting synthetic-auth hooks, preserving lazy descriptor selection while retaining the scoped discovery repair. |
||
|
|
d13f07b1c2
|
chore(deps): advance cooled dependencies and major upgrades (#146258)
* chore(deps): advance cooled dependencies and major upgrades * test(logging): migrate failed-sink regression to tslog 5 * test: retain dependency upgrade coverage within lint limits * fix(deps): preserve compiler launches, Matrix sync and chat metadata Keep copied script harnesses independent of declaration modules and preserve Windows executable prefixes after admission. Audit the Matrix sync guard for 42.3, align CI toolchain/cache pins, and refresh session facts after accepted model-catalog invalidation without relying on picker timing. * fix(ui): preserve scoped session reconciliation after catalog refresh |
||
|
|
a0cd0b8139
|
fix(discord): support continuous GPT Live conversations (#146289)
* fix(discord): support continuous GPT Live conversations Reuse the Gateway-owned GPT Live bridge for Discord voice, preserve speaker-bound agent delegation, and let Live own interruption while microphone input remains admitted during playback. Pace input continuously, play short replies, and preserve queued speech pauses. Document model-specific voice routes and unsupported host turn policies. * fix(discord): preserve live voice admission and defaults Keep unpinned realtime configurations on their provider default, ignore silent RTP for speaker retention, and retain live-policy freshness through roster enrichment and agent dispatch. Cover policy revocation during the real participant lookup path, fresh and existing model defaults, and idle speaker reclamation. * test(discord): isolate delegation admission coverage Keep the unchanged native delegation admission cases in a focused suite so the voice receive tests remain within the repository file-size limit. * test(voice): prove delegated agent authority and cancellation * test(discord): await continuous playback completion |
||
|
|
fdf2853f48
|
fix(codex): restore native discovery and hide empty catalogs (#146305)
* fix(codex): restore native discovery and hide empty catalogs Use the node native Codex home for listing, transcript reads, and terminal resume without requiring the Gateway agent on the node. Keep Gateway ownership for adopted Chats. Use native authentication for catalog connections, preserve primary source fingerprints during recovery, and let native clients start without an OpenClaw agent. Keep managed inference auth requirements and existing node permission boundaries. Hide empty sidebar catalogs while continuing normal discovery refreshes. * test(ui): cover catalog errors beside available sessions * fix(codex): preserve node compatibility and hidden catalog paging |
||
|
|
7b87a492ab
|
refactor: move shared database admission into its worker (#146172) | ||
|
|
e14b3ddac2
|
improve(memory): keep large-note searches responsive (#146168)
* fix: bound concurrent compute work and pending worker inputs * fix: supply the host response budget in worker checkpoint tests * fix: preserve prepared catalog ownership under admission pressure * improve(memory): keep large-note searches responsive * fix(memory): preserve worker errors and package boundaries * docs: separate worker entrypoint guidance * chore: align metadata extraction with main * chore: align worker registration for main refresh * fix(memory): unify metadata reads and worker registration * fix(memory): preserve overload during index bootstrap and repair |
||
|
|
f47a0d4348
|
improve: avoid loading plugin state values for record counts (#146285) | ||
|
|
d72a144e7b
|
improve: keep image and PDF processing responsive (#146094)
* fix: bound concurrent compute work and pending worker inputs * fix: supply the host response budget in worker checkpoint tests * fix: preserve prepared catalog ownership under admission pressure * improve: keep image and PDF processing responsive * fix: register PDF worker declarations in build fixtures * test: rebalance SQLite checks into the state shard * fix: resolve workers in standalone plugin packages * docs: separate worker entrypoint guidance |
||
|
|
63e204c2e5
|
fix: bound concurrent compute work and pending worker inputs (#146067)
* fix: bound concurrent compute work and pending worker inputs * fix: supply the host response budget in worker checkpoint tests * fix: preserve prepared catalog ownership under admission pressure |
||
|
|
d593351b13
|
fix(signal): refuse account deletion that activates a shadowed identity (#145981)
Deleting selected Signal row `collision-key` could report success and activate shadowed `Collision Key` after restart (#145750). The delete owner now rejects that takeover before effects, naming both keys. Unambiguous deletion works; dormant rows stay preserved.
The installed manifest is the single account-key policy declaration. Its snapshot reaches CLI/setup writers and post-write readers. Installation refreshes mutable operation facts while preserving callbacks and admitted Gateway inventory. Disabled owners retain maintenance policy; enabled-owner precedence stays intact. Reserved account IDs are rejected before setup writes.
The decision `whether a logical account survives deletion` is made by exactly one mechanism at `src/channels/plugins/config-helpers.ts:146`, which reruns `resolveChannelAccountKey` on the proposed remaining map.
## Consumers
S1–S36 bind every typed/manual location to its disposition. Coordinates are reviewed head `9a248139` or marked baseline; correction rows supersede relocated entries without erasing history.
The removed prepared API has no references; its `accountKey` duplicated the logical ID. The 74 remaining locations in 20 files have distinct contracts: Discord presence partitioning (`extensions/discord/src/monitor/presence-cache.ts`); Matrix storage identity and fixtures (`extensions/matrix/src/matrix/client/create-client.test.ts`, `extensions/matrix/src/matrix/client/create-client.ts`, `extensions/matrix/src/matrix/client/storage.ts`, `extensions/matrix/src/matrix/client/types.ts`, `extensions/matrix/src/storage-paths.ts`); Signal compatibility cleanup and reply-author partitioning (`extensions/signal/src/config-compat.ts`, `extensions/signal/src/reply-authors.ts`); WhatsApp group paths (`extensions/whatsapp/src/group-config-path.ts`); selected raw keys for field clearing, allowlists, setup, account config, and group policy (`src/channels/plugins/config-helpers.ts`, `src/channels/plugins/helpers.ts`, `src/channels/plugins/setup-helpers.ts`, `src/config/channel-account-config.ts`, `src/config/group-policy.ts`, `src/config/group-policy.test.ts`, `src/plugin-sdk/allowlist-config-edit.ts`); directory-cache invalidation (`src/infra/outbound/target-resolver.ts`); legacy pairing-file migration (`src/infra/state-migrations.channel-pairing.ts`); route indexing (`src/routing/resolve-route.ts`); and audit grouping (`src/security/audit-channel.ts`). None consumes the removed prepared-removal field.
`src/commands/channels/remove.ts:70,73,235` retains `shouldStopRuntime` through `beforeRemoval`, after deletion admission. Count: three declarations/uses.
census: generic accountKey reviewed — 74 callers listed
census: generic shouldStopRuntime reviewed — 3 callers listed
| Symbol | Exact disposition |
| --- | --- |
| S1 `ConfigWriteSnapshot` | Add/remove read receipt; no schema/writer. |
| S2 `PluginCacheScope` | Ancestry retained until scope exit. |
| S3 `ScopedPluginMetadataSnapshot` | Producer metadata/cache plus parent; runtime pinned. |
| S4 `applyChannelAccountRemoval` | Validate callback/no-op before stop/lifecycle. |
| S5 `applyPreparedChannelAccountRemoval` | Removed; callers use applyChannelAccountRemoval. |
| S6 `buildPluginMetadataOwnerMaps` | Enabled owner first, else maintenance owner; no borrowed policy. |
| S7 `clearPluginMetadataLifecycleCaches` | Operation revocation before Gateway guard; process lifetime retained. |
| S8 `createPluginCache` | Existing allocation/cleanup; hosted callbacks live through settlement. |
| S9 `deleteAccountFromConfigSection` | Re-resolve remaining map; propagate refusal. |
| S10 `getCurrentPluginMetadataSnapshot` | Explicit invalidation expires mutable facts; runtime pinned; no fallback. |
| S11 `getScopedPluginCache` | Current-cache projection includes ancestry. |
| S12 `getScopedPluginCaches` | Internal ancestry projection; no new lifetime authority. |
| S13 `invalidatePluginCacheMetadata` | Clear facts; retain modules/instances until cleanup. |
| S14 `prepareChannelAccountConfiguration` | Guard explicit ID; omitted ID reaches plugin defaults. |
| S15 `prepareChannelAccountRemoval` | Removed; applyChannelAccountRemoval owns outcome. |
| S16 `readCommandConfigSnapshot` | Read receipt retained; writer owns callback scope. |
| S17 `registerPluginMetadataProcessMemoLifecycleClear` | Process defaults retained; operation revocation opts in. |
| S18 `requireValidConfigFileSnapshot` | Validation/read/adoption retained; no config key. |
| S19 `requireValidConfigForWrite` | Write receipt retained; policy uses phase scope. |
| S20 `resolveAccountKey` | Existing public selector; optional channel context; explicit policy wins; reject reserved creation. |
| S21 `resolveChannelAccountEntry` | Shared row projection uses selected policy. |
| S22 `resolveChannelAccountKey` | Internal forwarding adapter and delete check; no SDK export. |
| S23 `resolveSignalAccountEntry` | Signal row projection; schema/Doctor/transport retained. |
| S24 `resolveSignalAccountKey` | Signal uses public selector; direct manifest removed. |
| S25 `revokeCurrentPluginMetadataSnapshotScopes` | Single enclosing-cache invalidator; runtime excluded. |
| S26 `runChannelsAddWizardFlow` | Prepared policy through naming/setup/persistence. |
| S27 `runChannelsSetupWizard` | Hosted wizard updates selected stored row. |
| S28 `runCollectedChannelOnboardingPostWriteHooks` | Reread committed config/policy before retained hooks. |
| S29 `runHostedSetup` | One disposable hosted operation through final hook; drops inherited runtime. |
| S30 `runHostedWizard` | Wizard scope through settlement/cancel/postwrite; drops inherited runtime. |
| S31 `runOutsidePluginCache` | Exit clears cache and ancestry. |
| S32 `setupChannels` | Post-install status/config/DM scopes retain callbacks for all callers. |
| S33 `signalAccountKeyPolicy` | Removed; snapshot supplies policy. |
| S34 `withCommandPluginMetadata` | Prepared snapshot/cache carrier returns Promise<Awaited<T>>. |
| S35 `withPluginCache` | Ancestry tracks invalidation, not module retirement. |
| S36 `withPluginMetadataSnapshotScope` | Producer identity detects invalidation; publication preserves facts. |
### Current pinned consumers
All 413 historical typed file rows remain; correction rows below supersede moved references.
| Consumer | Referenced symbols and pinned line numbers; disposition above applies to each |
| --- | --- |
| `extensions/signal/runtime-api.ts` | S9@9 |
| `extensions/signal/src/account-key-repair.ts` | S24@5, 36 |
| `extensions/signal/src/account-selection.ts` | S22@3, 10; S23@13; S24@6, 17 |
| `extensions/signal/src/accounts.ts` | S23@11, 292 |
| `extensions/signal/src/config-compat.ts` | S24@6, 329, 340, 390, 402, 514 |
| `extensions/signal/src/config-schema.ts` | S23@16, 164 |
| `extensions/signal/src/setup-core.ts` | S23@30, 215; S24@30, 365 |
| `extensions/signal/src/setup-transport.ts` | S23@9, 89, 123, 124 |
| `src/agents/agent-bundle-mcp-runtime-config.cache.test.ts` | S7@17, 26; S8@14, 38, 84, 167; S35@15, 39, 84, 103, 159, 167; S36@11, 73, 92 |
| `src/agents/agent-bundle-mcp-runtime-config.test.ts` | S7@3, 32, 58 |
| `src/agents/agent-bundle-mcp-runtime.agent-bundle.test.ts` | S7@10, 25, 156, 217 |
| `src/agents/agent-model-discovery.test.ts` | S7@7, 20 |
| `src/agents/agent-project-settings-snapshot.ts` | S35@12, 87 |
| `src/agents/auth-profile-runtime-contract.test.ts` | S7@15, 95 |
| `src/agents/auth-profiles/order.test.ts` | S7@11, 63 |
| `src/agents/btw.test.ts` | S10@11, 1206 |
| `src/agents/cli-runner/bundle-mcp.test.ts` | S7@11, 147, 190 |
| `src/agents/embedded-agent-runner/compact.delegate-resources.test.ts` | S7@18, 517, 629 |
| `src/agents/embedded-agent-runner/compact.foreground-resources.test.ts` | S7@12, 430 |
| `src/agents/embedded-agent-runner/compact.hooks.harness.ts` | S10@494 |
| `src/agents/embedded-agent-runner/compact.queued-resources.test.ts` | S7@8, 214 |
| `src/agents/embedded-agent-runner/compaction-session-execution.ts` | S10@21, 187 |
| `src/agents/embedded-agent-runner/history.ts` | S21@10, 192 |
| `src/agents/embedded-agent-runner/model.configured-pricing.test.ts` | S36@7, 67 |
| `src/agents/embedded-agent-runner/model.generation-scope.test-support.ts` | S7@7, 161 |
| `src/agents/embedded-agent-runner/model.generation-scope.test.ts` | S7@6, 101 |
| `src/agents/embedded-agent-runner/model.manifest-alias.ts` | S10@7, 304 |
| `src/agents/embedded-agent-runner/model.provider-hooks.ts` | S10@7, 51 |
| `src/agents/embedded-agent-runner/model.static-catalog.provider-alias.test.ts` | S7@18, 94 |
| `src/agents/embedded-agent-runner/model.static-catalog.snapshot-cache.test.ts` | S7@3, 123, 339 |
| `src/agents/embedded-agent-runner/model.static-catalog.test.ts` | S7@58, 131; S8@57, 169; S35@57, 169 |
| `src/agents/embedded-agent-runner/model.static-catalog.ts` | S10@10, 122 |
| `src/agents/embedded-agent-runner/run-orchestrator.cleanup-resources.test.ts` | S7@8, 317 |
| `src/agents/embedded-agent-runner/run/runtime-preparation.thinking.test.ts` | S7@9, 152 |
| `src/agents/exec-auto-reviewer.resources.test.ts` | S7@9, 265 |
| `src/agents/identity.ts` | S21@8, 33, 117 |
| `src/agents/isolated-completion.resources.test.ts` | S7@10, 333 |
| `src/agents/mcp-auth-profile.integration.test-support.ts` | S8@501; S35@501 |
| `src/agents/model-catalog.ts` | S10@11, 191 |
| `src/agents/model-discovery-context.ts` | S10@8, 50 |
| `src/agents/model-fallback-candidates.generation.test.ts` | S8@8, 51; S35@8, 51; S36@6, 251, 264 |
| `src/agents/model-fallback-candidates.ts` | S10@11, 188, 193 |
| `src/agents/model-fast-mode.ts` | S35@3, 21 |
| `src/agents/model-ref-shared.test.ts` | S7@10, 26, 31 |
| `src/agents/model-selection-shared.ts` | S10@17, 115, 192, 1297 |
| `src/agents/model-suppression.test.ts` | S7@21, 33; S8@19, 49, 50; S10@17, 161; S35@19, 59, 60, 61 |
| `src/agents/models-config.providers.normalize-keys.test.ts` | S36@10, 257 |
| `src/agents/models-config.write-serialization.test.ts` | S7@61, 163 |
| `src/agents/openclaw-tools.media-factory-plan.test.ts` | S7@9, 191, 203; S10@5, 374, 376 |
| `src/agents/prepared-model-catalog-worker.metadata.integration.test.ts` | S8@4, 22; S10@53; S35@7, 23, 59 |
| `src/agents/prepared-model-catalog.resources.test.ts` | S7@11, 106, 183 |
| `src/agents/prepared-model-runtime-lease.ts` | S36@3, 169 |
| `src/agents/prepared-model-runtime.inbound-registry.ts` | S10@6, 77 |
| `src/agents/prepared-model-runtime.plugin-context.test.ts` | S7@7, 21 |
| `src/agents/prepared-model-runtime.published-resources.test.ts` | S7@12, 207, 325 |
| `src/agents/prepared-model-runtime.run-resources.test.ts` | S7@14, 215, 251 |
| `src/agents/provider-attribution.test.ts` | S7@174, 217; S8@173, 312; S35@173, 311 |
| `src/agents/provider-auth-aliases.test.ts` | S7@67, 260, 619; S8@66, 505, 506; S35@66, 524, 527 |
| `src/agents/provider-auth-aliases.ts` | S10@10, 59, 65 |
| `src/agents/runtime-plan/auth.test.ts` | S7@43, 62 |
| `src/agents/runtime-plan/prepare-auth.metadata.test.ts` | S36@3, 29, 94, 110 |
| `src/agents/runtime-plugins.context-engine.integration.test.ts` | S8@14, 345, 346; S35@14, 347, 348 |
| `src/agents/runtime-plugins.hooks.integration.test.ts` | S8@14, 47, 48; S35@14, 50, 53 |
| `src/agents/runtime-plugins.ts` | S36@8, 167, 217 |
| `src/agents/sandbox/sanitize-env-vars.ts` | S10@7, 118 |
| `src/agents/simple-completion-runtime.plugin-scope.test.ts` | S7@9, 97 |
| `src/agents/simple-completion-runtime.selected-model.test.ts` | S7@9, 20 |
| `src/agents/simple-completion-runtime.test.ts` | S10@35 |
| `src/agents/subagents/spawn/acp-spawn-parent-stream.ts` | S21@25, 124 |
| `src/agents/tool-policy-declared-context.ts` | S10@6, 130 |
| `src/agents/tools-effective-inventory.cold-provider.test.ts` | S7@26, 120, 134 |
| `src/agents/tools/manifest-capability-availability.ts` | S10@8, 157 |
| `src/agents/tools/media-generate-tool.donor-resources.test.ts` | S7@7, 43 |
| `src/agents/tools/media-generate-tool.resources.test.ts` | S7@16, 289 |
| `src/agents/tools/pdf-tool.helpers.test.ts` | S36@5, 105 |
| `src/agents/tools/video-generate-tool.test.ts` | S7@18, 373; S10@11, 492 |
| `src/agents/utility-model.ts` | S10@5, 50 |
| `src/auto-reply/chunk.ts` | S21@9, 49, 92 |
| `src/auto-reply/command-auth.ts` | S21@16, 454, 475 |
| `src/auto-reply/reply/block-streaming.ts` | S21@6, 60 |
| `src/auto-reply/reply/commands-account-policy.test.ts` | S36@4, 82 |
| `src/auto-reply/reply/get-reply-directive-aliases.test.ts` | S36@12, 162 |
| `src/auto-reply/reply/get-reply-run.prepared-metadata.test.ts` | S10@3, 75, 84, 122 |
| `src/auto-reply/reply/memory-flush.test.ts` | S36@13, 286 |
| `src/auto-reply/reply/model-runtime-normalization.ts` | S10@12, 25 |
| `src/auto-reply/reply/reply-threading.ts` | S21@11, 51 |
| `src/auto-reply/reply/stage-sandbox-media.scp.test.ts` | S7@11, 178 |
| `src/channels/account-config-enabled.ts` | S21@3, 13 |
| `src/channels/bundled-channel-catalog-read.test.ts` | S7@48, 362, 383 |
| `src/channels/draft-streaming-chunking.ts` | S21@4, 33 |
| `src/channels/join-intro/report-channel-room-join.ts` | S21@13, 74 |
| `src/channels/plugins/account-config-mutation.test.ts` | S4@6, 297, 333, 371, 402, 428; S14@7, 28, 100, 148, 180, 202, 241 |
| `src/channels/plugins/account-config-mutation.ts` | S4@200; S14@67; S22@5, 97 |
| `src/channels/plugins/account-key-policy.test.ts` | S36@11, 75 |
| `src/channels/plugins/bundled.shape-guard.test.ts` | S7@8, 223 |
| `src/channels/plugins/catalog.test.ts` | S7@8, 30, 81, 115, 236, 253; S8@7, 76, 107; S35@7, 76, 106 |
| `src/channels/plugins/config-helpers.test.ts` | S9@7, 49 |
| `src/channels/plugins/config-helpers.ts` | S9@115; S20@8, 197; S22@9, 87, 125, 143, 190 |
| `src/channels/plugins/config-write-policy-shared.ts` | S21@6, 71 |
| `src/channels/plugins/helpers.ts` | S22@9, 57, 63 |
| `src/channels/plugins/read-only.legacy-workspace.test.ts` | S7@4, 22 |
| `src/channels/plugins/read-only.test.ts` | S7@18, 847, 884 |
| `src/channels/plugins/setup-contract.test.ts` | S8@3, 27; S35@3, 27 |
| `src/channels/plugins/setup-helpers.ts` | S22@8, 50, 93, 311, 370 |
| `src/cli/capability-cli/model.resources.test.ts` | S7@12, 279 |
| `src/cli/channel-auth.ts` | S19@13, 108 |
| `src/cli/command-config-snapshot.ts` | S16@7 |
| `src/cli/directory-cli.ts` | S19@19, 114 |
| `src/cli/node-worker-bootstrap.test.ts` | S7@30, 51 |
| `src/cli/plugins-cli.policy.test.ts` | S7@8, 66, 93 |
| `src/cli/plugins-feature-artifact.test.ts` | S8@14, 138, 294; S35@14, 138, 294 |
| `src/cli/plugins-feature-artifact.ts` | S8@17, 66; S35@17, 66 |
| `src/cli/plugins-update-command.ts` | S8@48, 544; S35@48, 544 |
| `src/cli/program/config-guard.test.ts` | S8@11, 94, 152; S35@13, 153 |
| `src/cli/run-main.exit.test.ts` | S11@17, 668, 672 |
| `src/cli/run-main.ts` | S8@22, 1017; S35@22, 1017 |
| `src/cli/update-cli/update-command-plugins.degradation.test.ts` | S8@11, 225; S35@11, 225 |
| `src/commands/agents.add.test.ts` | S32@23 |
| `src/commands/agents.commands.add.ts` | S19@51, 123; S32@56, 443 |
| `src/commands/agents.commands.bind.ts` | S19@14, 122 |
| `src/commands/agents.commands.delete.ts` | S19@67, 138 |
| `src/commands/agents.commands.identity.ts` | S19@30, 70 |
| `src/commands/channel-setup/plugin-install.test.ts` | S7@99, 215, 231 |
| `src/commands/channels.add.test.ts` | S8@18, 843; S21@22, 804; S27@43, 490; S32@142; S35@18, 844 |
| `src/commands/channels.remove.test.ts` | S8@10, 613; S9@5, 334, 604; S35@10, 613 |
| `src/commands/channels/add-wizard.ts` | S26@125, 340; S27@317; S32@142; S34@24, 205 |
| `src/commands/channels/add.ts` | S1@29, 145; S14@7, 288; S19@32, 137; S26@156; S28@343; S34@29, 274 |
| `src/commands/channels/capabilities.ts` | S18@32, 287; S19@33, 284 |
| `src/commands/channels/remove.ts` | S4@4, 224; S1@21, 116; S19@25, 102; S34@21, 106 |
| `src/commands/channels/shared.ts` | S19@11, 18 |
| `src/commands/config-validation.test.ts` | S19@4, 63, 86 |
| `src/commands/config-validation.ts` | S1@54; S16@39; S18@27, 119; S19@46; S34@57; S36@63 |
| `src/commands/configure.wizard.default-agent.test.ts` | S32@8 |
| `src/commands/configure.wizard.ts` | S32@55, 707 |
| `src/commands/doctor-config-preflight-plugin-index.ts` | S8@9, 70; S35@9, 71 |
| `src/commands/doctor-config-preflight-plugin-verification.test.ts` | S8@10, 88, 105, 112, 190, 193; S35@10, 88, 105, 112, 190, 193 |
| `src/commands/doctor-config-preflight.plugin-persistence.test.ts` | S8@19, 169, 207, 214, 225, 262, 273, 354, 370, 427, 463, 478, 500, 529, 553, 596; S10@12, 237, 302, 308, 317, 324; S35@22, 169, 207, 214, 226, 262, 273, 354, 370, 427, 463, 479, 500, 529, 553, 596; S36@13, 502 |
| `src/commands/doctor-maintenance.plugin-preflight.test.ts` | S7@11, 20, 120 |
| `src/commands/doctor-plugin-registry-generation-repair.test.ts` | S8@20, 89, 91; S35@20, 89, 91 |
| `src/commands/doctor-post-upgrade.test.ts` | S7@11, 22 |
| `src/commands/doctor/channel-capabilities.packaged.test.ts` | S7@34, 43, 50 |
| `src/commands/doctor/shared/channel-plugin-blockers.test.ts` | S7@7, 59 |
| `src/commands/doctor/shared/legacy-config-account-promotion.test.ts` | S7@6, 19, 98, 162, 254 |
| `src/commands/doctor/shared/legacy-config-binding-repair.ts` | S21@7, 99 |
| `src/commands/doctor/shared/legacy-config-issues.ts` | S36@10, 74 |
| `src/commands/doctor/shared/missing-configured-plugin-install.load-path.test.ts` | S7@12, 22 |
| `src/commands/doctor/shared/plugin-metadata-snapshot-scope.ts` | S8@8, 78, 88, 153; S35@10, 136; S36@4, 138 |
| `src/commands/doctor/shared/post-core-plugin-convergence.source-checkout.test.ts` | S8@20, 246, 257, 329; S35@20, 246, 257, 329 |
| `src/commands/doctor/shared/stale-auth-order.test.ts` | S7@17, 123 |
| `src/commands/doctor/shared/xai-auto-retirement.test.ts` | S7@5, 19, 28 |
| `src/commands/migrate.resources.test.ts` | S7@8, 22 |
| `src/commands/models/auth.registry.test.ts` | S7@5, 24 |
| `src/commands/models/list.manifest-catalog.snapshot.test.ts` | S7@6, 22 |
| `src/commands/models/list.probe.resources.test.ts` | S7@17, 331 |
| `src/commands/models/list.status-command.ts` | S36@75, 350 |
| `src/commands/models/list.status.test.ts` | S7@8, 681, 700, 719; S10@6, 680, 683, 698, 710 |
| `src/commands/models/model-selection.runtime.test.ts` | S7@18, 74 |
| `src/commands/onboard-channels.e2e.test.ts` | S32@98, 604 |
| `src/commands/onboard-channels.ts` | S28@5; S32@6 |
| `src/commands/onboard-quickstart-host.plugin-generation.test.ts` | S7@10, 15, 79; S8@8, 28, 82; S35@8, 28, 82 |
| `src/commands/onboard-quickstart-host.ts` | S8@7, 27; S35@7, 27 |
| `src/commands/onboarding-plugin-install.ts` | S7@66, 131 |
| `src/commands/plugin-control-plane-cold-imports.test.ts` | S7@3, 28 |
| `src/commands/status-all/channels-manifest-discovery.test.ts` | S8@8, 69; S35@8, 69 |
| `src/commands/status.plugin-metadata-snapshot.test.ts` | S7@3, 48, 73 |
| `src/commands/status.scan-overview.ts` | S16@159 |
| `src/config/channel-account-config.ts` | S20@3, 83; S22@4, 76 |
| `src/config/channel-capabilities.ts` | S21@4, 51 |
| `src/config/channel-doctor-helpers.ts` | S22@3, 196 |
| `src/config/context-visibility.ts` | S21@2, 54 |
| `src/config/group-policy.ts` | S21@3, 104; S22@3, 75 |
| `src/config/implicit-mentions.ts` | S21@2, 29 |
| `src/config/io.context.plugin-metadata.test.ts` | S7@8, 133 |
| `src/config/io.plugin-metadata.ts` | S8@8, 88; S35@8, 88 |
| `src/config/io.snapshot.recovery.test.ts` | S7@7, 18 |
| `src/config/io.snapshot.test.ts` | S7@8, 26 |
| `src/config/io.snapshot.ts` | S36@4, 256 |
| `src/config/markdown-tables.ts` | S21@5, 57 |
| `src/config/plugin-auto-enable.apply.ts` | S17@5, 32 |
| `src/config/plugin-auto-enable.channels.test.ts` | S7@6, 167, 264 |
| `src/config/plugin-auto-enable.core.test.ts` | S7@8, 1247, 1342, 1372, 1407, 1441 |
| `src/config/plugin-auto-enable.shared.ts` | S10@10, 658, 669 |
| `src/config/plugin-auto-enable.test-helpers.ts` | S7@5, 16 |
| `src/config/test-helpers.ts` | S7@6, 12 |
| `src/config/validation.channel-metadata.test.ts` | S7@6, 273 |
| `src/config/validation.dm-policy.test.ts` | S7@3, 15 |
| `src/context-engine/registry.copied-view-resources.test.ts` | S7@16, 37 |
| `src/cron/delivery-channel-validation.ts` | S21@9, 99 |
| `src/cron/trigger-script.preparation.test.ts` | S7@21, 105 |
| `src/flows/channel-setup.test.ts` | S8@5, 1629; S32@224, 230, 236, 243, 248, 250, 899, 1298, 1335, 1819; S35@5, 1630 |
| `src/flows/channel-setup.ts` | S28@77, 90; S32@156; S34@27, 106, 289, 439, 449, 582, 986, 1088, 1105; S35@38, 251, 727 |
| `src/gateway/config-reload.test.ts` | S8@55, 6782, 6819; S35@55, 6782, 6819 |
| `src/gateway/config-reload.ts` | S8@44, 376; S35@44, 376 |
| `src/gateway/control-ui-plugin-assets.ts` | S8@15, 163; S35@15, 163 |
| `src/gateway/health/collector.channel-discovery.test.ts` | S7@12, 30 |
| `src/gateway/http-utils.ts` | S10@18, 181 |
| `src/gateway/server-channels.ts` | S21@64, 374, 382 |
| `src/gateway/server-close.metadata.test-support.ts` | S35@7, 107 |
| `src/gateway/server-close.model-cache.test.ts` | S10@13, 297; S36@14, 204 |
| `src/gateway/server-http-plugin-auth.test.ts` | S7@4, 18, 41, 72 |
| `src/gateway/server-http-plugin-auth.ts` | S17@3, 28 |
| `src/gateway/server-methods/migrations.resources.test.ts` | S7@11, 19 |
| `src/gateway/server-methods/wizard.test.ts` | S8@10, 148; S10@7, 164, 173, 192 |
| `src/gateway/server-methods/wizard.ts` | S8@15, 62; S27@57; S30@61, 120, 135; S35@15, 65 |
| `src/gateway/server-plugin-bootstrap.ts` | S35@8, 61 |
| `src/gateway/server-plugin-reload.cache.test-support.ts` | S8@8, 40, 119; S35@10, 41, 63, 120, 185 |
| `src/gateway/server-plugin-reload.installed-package.test.ts` | S7@16, 55 |
| `src/gateway/server-plugin-reload.recovery.test.ts` | S7@8, 118 |
| `src/gateway/server-plugin-reload.ts` | S8@21, 97; S35@21, 270, 286, 297 |
| `src/gateway/server-plugins.lifecycle.test.ts` | S7@11, 313 |
| `src/gateway/server-plugins.ts` | S10@9, 290 |
| `src/gateway/server-startup-lifetime.test.ts` | S8@29, 178, 203; S35@31, 206 |
| `src/gateway/server-startup-minimal-boot.test.ts` | S7@12, 29 |
| `src/gateway/server-startup-plugin-quarantine.test.ts` | S8@26, 407, 438; S35@26, 407, 438 |
| `src/gateway/server-startup-workspace-readiness.test.ts` | S7@14, 55 |
| `src/gateway/server.chat.gateway-server-chat-b.test.ts` | S36@47, 2071 |
| `src/gateway/server.config-patch.test.ts` | S7@13, 160 |
| `src/gateway/server.config-policy-response.test.ts` | S7@7, 44 |
| `src/gateway/server.config-security-policy.test.ts` | S7@5, 44 |
| `src/gateway/server.sessions.create.test.ts` | S10@612; S36@612 |
| `src/gateway/server.shared-auth-rotation.test.ts` | S7@20, 71 |
| `src/gateway/session-utils.test.ts` | S7@29, 328 |
| `src/gateway/sessions-patch.test.ts` | S7@9, 317 |
| `src/image-generation/runtime.resources.test.ts` | S7@14, 153 |
| `src/infra/dotenv-workspace-blocklist.test.ts` | S7@12, 134 |
| `src/infra/event-session-routing.ts` | S21@6, 113 |
| `src/infra/heartbeat-visibility.ts` | S21@4, 54 |
| `src/infra/state-migrations.caller-mode.inventory.test.ts` | S8@16, 100, 112, 118, 156; S35@16, 100, 112, 118, 156; S36@6, 120 |
| `src/infra/update-candidate-bundled-provenance.test.ts` | S8@10, 167, 263, 385; S35@10, 167, 263, 385 |
| `src/media-understanding/defaults.generation.test.ts` | S36@3, 60, 64 |
| `src/media/channel-inbound-roots.installed-plugin.test.ts` | S7@10, 22, 183 |
| `src/media/channel-inbound-roots.lifecycle.test.ts` | S8@5, 22, 23; S35@5, 50 |
| `src/media/configured-max-bytes.ts` | S21@6, 39 |
| `src/media/document-extractors.runtime.test.ts` | S7@8, 121 |
| `src/music-generation/runtime.resources.test.ts` | S7@14, 147 |
| `src/plugin-sdk/account-resolution.ts` | S20@21; S22@22 |
| `src/plugin-sdk/allowlist-config-edit.ts` | S22@8, 197 |
| `src/plugin-sdk/channel-config-helpers.ts` | S9@11, 292, 468 |
| `src/plugin-sdk/channel-entry-contract.lifecycle.test.ts` | S8@6, 37; S35@6, 50, 83 |
| `src/plugin-sdk/channel-plugin-common.ts` | S9@20 |
| `src/plugin-sdk/core.ts` | S9@249 |
| `src/plugin-sdk/facade-loader.test.ts` | S7@9, 505 |
| `src/plugin-sdk/facade-runtime.test.ts` | S7@13, 104, 164, 351, 377 |
| `src/plugins/activation-context.test.ts` | S7@10, 36 |
| `src/plugins/activation-context.ts` | S10@11, 100, 108 |
| `src/plugins/bundled-capability-runtime.test.ts` | S8@14, 130; S35@14, 130 |
| `src/plugins/bundled-dir.test.ts` | S8@10, 383, 416, 428, 448, 497; S35@10, 383, 417, 423, 425, 428, 431, 448, 497 |
| `src/plugins/bundled-discovery-state.ts` | S17@9, 42 |
| `src/plugins/bundled-package-channel-metadata.test.ts` | S7@16, 34, 126 |
| `src/plugins/bundled-plugin-metadata.public-surfaces.test.ts` | S7@11, 16 |
| `src/plugins/bundled-plugin-metadata.test.ts` | S7@29, 39, 826 |
| `src/plugins/capability-artifact.ts` | S8@18, 135; S35@18, 135 |
| `src/plugins/capability-consent.ts` | S17@40, 81 |
| `src/plugins/capability-provider-runtime.test.ts` | S7@164, 398 |
| `src/plugins/capability-provider-runtime.ts` | S10@14, 196 |
| `src/plugins/channel-catalog-registry.workspace.test.ts` | S7@13, 19, 61, 137; S8@12, 109; S35@12, 109 |
| `src/plugins/cli-config-lifetime.test.ts` | S7@24, 143; S10@16, 146, 220 |
| `src/plugins/cli-metadata-lifetime.test.ts` | S7@31, 61, 90; S10@21, 276, 320, 399, 464 |
| `src/plugins/cli-registry-loader.ts` | S8@24, 78; S35@24, 84 |
| `src/plugins/current-plugin-metadata-snapshot.test.ts` | S7@29, 825, 851, 872; S8@26, 840, 841; S10@12, 130, 133, 135, 141, 163, 169, 179, 185, 211, 214, 218, 230, 281, 306, 325, 346, 350, 356, 374, 385, 413, 424, 443, 465, 480, 500, 502, 506, 518, 530, 532, 545, 553, 588, 595, 627, 633, 636, 654, 656, 667, 672, 673, 674, 675, 686, 691, 708, 709, 713, 714, 731, 733, 735, 737, 745, 749, 757, 761, 773, 777, 789, 790, 807, 810, 818, 827, 852, 854, 856, 858, 861, 873, 883, 892, 895, 912, 914, 919, 979; S36@17, 158, 342, 370, 381, 405, 409, 439, 462, 552, 710, 848, 849, 855, 909 |
| `src/plugins/current-plugin-metadata-snapshot.ts` | S10@393, 444; S11@17, 188, 218, 410; S12@14, 198; S13@15, 209; S17@27, 447; S25@197, 447; S31@18, 283; S3@66, 70, 83, 214; S35@19, 163, 263; S36@223 |
| `src/plugins/discovery-checkout.test.ts` | S8@8, 47, 113, 184; S35@8, 47, 113, 184 |
| `src/plugins/discovery.test.ts` | S7@20, 473, 3309; S8@19, 3346, 3370, 3391; S35@19, 3346, 3370, 3391 |
| `src/plugins/doctor-contract-registry.test-fixtures.ts` | S7@3, 7 |
| `src/plugins/doctor-contract-registry.test.ts` | S8@8, 125, 134, 138; S35@8, 132, 134, 136, 138 |
| `src/plugins/host-hook-cleanup.retirement.test.ts` | S8@9, 125 |
| `src/plugins/install-persistence.enablement.test.ts` | S7@19, 69 |
| `src/plugins/install-persistence.test.ts` | S7@23, 49 |
| `src/plugins/install-persistence.ts` | S8@36, 218; S35@36, 218 |
| `src/plugins/install.archive-dependencies.test.ts` | S8@7, 77; S35@7, 77 |
| `src/plugins/installed-plugin-index-facts.test.ts` | S8@8, 49, 103, 115, 145, 152; S35@8, 49, 103, 115, 151, 152, 153, 156 |
| `src/plugins/installed-plugin-index-store-write.ts` | S7@56, 237 |
| `src/plugins/installed-plugin-index-store.test.ts` | S7@40, 48; S10@17, 270, 286 |
| `src/plugins/installed-plugin-index.compat.test.ts` | S7@16, 23 |
| `src/plugins/installed-plugin-index.test.ts` | S8@24, 427, 1079, 1127; S35@24, 427, 1079, 1127 |
| `src/plugins/legacy-session-surfaces.state-migration.test.ts` | S7@11, 20, 171, 267, 345 |
| `src/plugins/loader-load-context.ts` | S10@15, 327, 333 |
| `src/plugins/loader-module-runtime.ts` | S35@5, 144, 160, 228, 241 |
| `src/plugins/loader-runtime-load.ts` | S8@16, 113; S35@16, 147 |
| `src/plugins/loader.capability-factory.test.ts` | S8@28, 183, 184, 479; S35@31, 194, 196, 481 |
| `src/plugins/loader.hooks-and-runtime.test-utils.ts` | S8@31, 236; S35@31, 239 |
| `src/plugins/loader.instance-cleanup.test.ts` | S8@15, 122, 185, 234, 376, 422, 476, 501; S35@15, 130, 135, 137, 186, 379, 426, 482, 504 |
| `src/plugins/loader.lazy-alias.test.ts` | S8@18, 128, 567, 570, 606, 609, 626, 634; S35@18, 128, 567, 570, 608, 610, 611, 615, 618, 623, 626, 646 |
| `src/plugins/loader.runtime-registry.test.ts` | S7@49, 848 |
| `src/plugins/management-catalog.ts` | S11@36, 48; S35@37, 63 |
| `src/plugins/management-service.capability-consent.test.ts` | S7@20, 165 |
| `src/plugins/management-service.inspect.test.ts` | S7@8, 28 |
| `src/plugins/management-service.lifecycle-cache.test.ts` | S7@6, 126, 173, 339, 505; S17@7, 47 |
| `src/plugins/management-service.policy-imports.test.ts` | S7@26, 44 |
| `src/plugins/management-service.registry-refresh.test.ts` | S7@5, 179 |
| `src/plugins/management-service.ts` | S8@65, 184; S35@65, 185 |
| `src/plugins/management-service.workspace-inventory.test.ts` | S7@19, 52 |
| `src/plugins/manifest-backup-resources.test.ts` | S7@8, 58 |
| `src/plugins/manifest-contract-eligibility.test.ts` | S7@41, 56; S17@12 |
| `src/plugins/manifest-metadata-scan.test.ts` | S7@13, 88, 184, 206 |
| `src/plugins/manifest-model-id-normalization.test.ts` | S7@13, 99, 105, 158, 167; S36@9, 123 |
| `src/plugins/manifest-model-suppression.test.ts` | S8@20, 67, 68; S35@20, 82, 83, 90 |
| `src/plugins/manifest-registry-installed.ownership.test.ts` | S7@19, 25, 93 |
| `src/plugins/manifest-registry-installed.test.ts` | S7@15, 21, 318; S8@14, 284; S35@14, 284 |
| `src/plugins/manifest-registry.test.ts` | S8@13, 523; S35@13, 523 |
| `src/plugins/manifest.json5-tolerance.test.ts` | S7@8, 18 |
| `src/plugins/memory-runtime.test.ts` | S8@14, 270, 345 |
| `src/plugins/migration-provider-runtime.test.ts` | S7@13, 183 |
| `src/plugins/plugin-cache-primitives.test.ts` | S7@7, 94, 130 |
| `src/plugins/plugin-cache-primitives.ts` | S17@3, 57 |
| `src/plugins/plugin-cache.test.ts` | S7@24, 31, 50; S8@17, 39, 78, 174, 210, 223; S35@20, 43, 78, 174, 212, 225 |
| `src/plugins/plugin-cache.ts` | S8@165, 185; S11@194, 208; S12@199; S13@146; S2@48, 52, 59; S31@215; S35@211 |
| `src/plugins/plugin-discovery-ordering.test.ts` | S7@8, 70 |
| `src/plugins/plugin-generation-conditions.test.ts` | S8@6, 23; S35@6, 23 |
| `src/plugins/plugin-lifecycle-lease.ts` | S8@12, 126; S35@15, 131 |
| `src/plugins/plugin-metadata-account-key-policies.test.ts` | S7@5, 16; S8@4, 51; S35@4, 51 |
| `src/plugins/plugin-metadata-lifecycle.test.ts` | S7@18, 92, 115, 128, 209; S8@10, 145, 234; S17@19, 25; S35@14, 145, 235 |
| `src/plugins/plugin-metadata-lifecycle.ts` | S7@244; S17@236; S35@19, 143 |
| `src/plugins/plugin-metadata-readers.runtime.ts` | S10@2 |
| `src/plugins/plugin-metadata-snapshot-readers.ts` | S10@15 |
| `src/plugins/plugin-metadata-snapshot-required.ts` | S10@34, 35, 38 |
| `src/plugins/plugin-metadata-snapshot.runtime.ts` | S10@54, 55, 58 |
| `src/plugins/plugin-metadata-snapshot.test.ts` | S7@37, 134; S8@32, 148, 228, 240; S10@18, 241, 246; S35@35, 149, 230, 240; S36@20, 163, 237, 264, 835 |
| `src/plugins/plugin-metadata-snapshot.ts` | S6@195, 283; S8@29, 381; S10@10, 388, 535; S35@32, 381, 481 |
| `src/plugins/plugin-module-generation.bun.test-support.ts` | S8@5, 46; S35@5, 46 |
| `src/plugins/plugin-module-generation.interop.test.ts` | S8@8, 38; S35@8, 38 |
| `src/plugins/plugin-module-generation.sdk.test.ts` | S8@7, 25, 58; S35@9, 25 |
| `src/plugins/plugin-module-generation.test.ts` | S8@8, 26; S35@8, 26 |
| `src/plugins/plugin-module-loader-cache.test.ts` | S8@11, 24, 25, 30, 214, 215; S35@14, 34, 225, 235 |
| `src/plugins/plugin-module-loader-cache.ts` | S35@24, 211, 450, 609 |
| `src/plugins/plugin-native-module-loader.ts` | S35@9, 56, 86, 129 |
| `src/plugins/plugin-registry-contributions.current-snapshot.test.ts` | S7@13, 27, 289 |
| `src/plugins/plugin-registry-inspection.test.ts` | S7@13, 26, 31, 148, 424 |
| `src/plugins/plugin-registry-snapshot.state-migration.test.ts` | S7@25, 41, 46, 133, 255; S8@24, 256; S35@24, 256 |
| `src/plugins/plugin-registry-snapshot.test.ts` | S7@18, 30, 1462 |
| `src/plugins/plugin-registry-snapshot.ts` | S8@49, 574; S10@14, 131; S35@49, 574 |
| `src/plugins/plugin-registry.test.ts` | S7@18, 36, 60, 951 |
| `src/plugins/plugin-sdk-native-resolver.test.ts` | S7@9, 255 |
| `src/plugins/prepared-model-generation.lifecycle.test.ts` | S36@9, 137 |
| `src/plugins/provider-auth-choice.install-discovery.test.ts` | S10@12, 258; S11@17, 202 |
| `src/plugins/provider-auth-choice.ts` | S8@18, 377, 378; S35@18, 394, 451, 516, 536 |
| `src/plugins/provider-auth-choices.test.ts` | S7@57 |
| `src/plugins/provider-discovery.runtime.ts` | S35@9, 263 |
| `src/plugins/provider-external-auth-core.ts` | S10@2, 23 |
| `src/plugins/provider-model-routes.installed.test.ts` | S36@14, 60, 183, 232, 288 |
| `src/plugins/provider-public-artifacts.test.ts` | S7@13, 78, 908; S8@10, 398, 399, 899, 911; S35@10, 400, 411, 430, 438, 904, 910, 911 |
| `src/plugins/provider-runtime.ts` | S10@22, 763 |
| `src/plugins/provider-setup-availability.ts` | S8@7, 36; S35@7, 39, 73 |
| `src/plugins/provider-thinking.ts` | S10@4, 63; S35@5, 27 |
| `src/plugins/providers.runtime-core.ts` | S10@15, 187, 199 |
| `src/plugins/providers.runtime.consult-current-snapshot.test.ts` | S7@12, 95, 102 |
| `src/plugins/providers.ts` | S10@6, 424, 564 |
| `src/plugins/public-surface-generation.test.ts` | S8@18, 87; S35@18, 97 |
| `src/plugins/public-surface-loader.test.ts` | S7@378, 421, 557 |
| `src/plugins/registry-refresh.ts` | S8@8, 34; S35@8, 34 |
| `src/plugins/runtime-context.test.ts` | S8@3, 25, 45; S35@3, 25, 45 |
| `src/plugins/runtime-plugin-boundary.whatsapp.test.ts` | S7@8, 156 |
| `src/plugins/runtime.ts` | S7@28, 690 |
| `src/plugins/runtime/generation-scope.ts` | S36@3, 28 |
| `src/plugins/runtime/load-context.current-snapshot.test.ts` | S7@9, 74; S10@4, 104, 110 |
| `src/plugins/runtime/load-context.test.ts` | S7@72, 100; S8@5, 260, 263; S35@5, 260, 263 |
| `src/plugins/runtime/runtime-llm.prepared-owner.test.ts` | S7@40, 956 |
| `src/plugins/runtime/runtime-web-channel-plugin.test.ts` | S8@15, 102; S35@15, 112 |
| `src/plugins/sdk-alias.test.ts` | S8@13, 1755, 1756; S35@13, 1763, 1767 |
| `src/plugins/sdk-alias.ts` | S35@27, 1400, 1410, 1436 |
| `src/plugins/setup-registry.lifecycle.test.ts` | S7@30, 64, 517, 587; S8@21, 90, 127, 176, 232, 614, 630, 684, 685, 758; S11@23, 321, 343, 984, 986; S35@25, 92, 129, 178, 234, 239, 621, 629, 647, 660, 682, 683, 702, 714, 719, 736, 759, 766, 768, 771, 806; S36@13, 432 |
| `src/plugins/setup-registry.runtime.test.ts` | S7@7, 48; S10@34, 38; S36@3, 92, 123, 151, 167 |
| `src/plugins/setup-registry.test-fixtures.ts` | S7@2, 5 |
| `src/plugins/setup-registry.test.ts` | S7@1301; S8@8, 1223, 1224; S35@8, 1234 |
| `src/plugins/setup-registry.ts` | S35@28, 537 |
| `src/plugins/status-effective-plugin-discovery.test.ts` | S7@8, 97, 104, 114, 130, 133, 141 |
| `src/plugins/status.registry-snapshot.bundles.test.ts` | S7@4, 20 |
| `src/plugins/status.registry-snapshot.dependency-health.test.ts` | S7@6, 18 |
| `src/plugins/status.registry-snapshot.test.ts` | S7@13, 59; S10@8, 551, 603 |
| `src/plugins/status.runtime-inspection.test.ts` | S7@36, 51 |
| `src/plugins/status.test.ts` | S7@6, 354 |
| `src/plugins/status.ts` | S8@31, 395; S35@31, 396 |
| `src/plugins/tools.optional.test.ts` | S7@114, 622; S8@23, 3080, 3767 |
| `src/plugins/update-cohort.integration.test.ts` | S8@8, 100; S35@8, 100 |
| `src/plugins/update-cohort.test.ts` | S8@9, 230; S35@9, 230 |
| `src/plugins/update-cohort.ts` | S8@12, 74, 153; S35@12, 74, 153 |
| `src/plugins/web-provider-resolution-shared.ts` | S10@3, 147 |
| `src/routing/account-lookup.test.ts` | S20@6, 16 |
| `src/routing/account-lookup.ts` | S20@51, 77, 89, 94; S21@54; S22@19, 27, 35, 61 |
| `src/secrets/provider-env-vars.ts` | S10@7, 138, 145, 158 |
| `src/secrets/resolve.ts` | S10@16, 166 |
| `src/security/dangerous-config-flags-current-snapshot.test.ts` | S10@5, 31, 36, 50 |
| `src/security/dangerous-config-flags-current.ts` | S10@4, 21 |
| `src/skills/loading/plugin-skills.test.ts` | S7@17, 197; S8@16, 271; S35@16, 271 |
| `src/skills/loading/plugin-skills.ts` | S17@17, 39; S35@16, 70 |
| `src/skills/loading/skills.test.ts` | S7@10, 183, 346 |
| `src/system-agent/approval-intent.resources.test.ts` | S7@15, 333 |
| `src/system-agent/config-redaction.test.ts` | S36@7, 204 |
| `src/system-agent/config-redaction.ts` | S10@27, 137, 146 |
| `src/system-agent/hosted-setup.runtime.test.ts` | S8@8, 690; S10@5, 707, 728, 776 |
| `src/system-agent/hosted-setup.runtime.ts` | S8@3, 62; S29@49, 99, 138, 160, 202; S32@96; S35@3, 64 |
| `src/system-agent/plugin-artifact.ts` | S8@13, 169; S35@13, 169 |
| `src/system-agent/setup-inference-activate.ts` | S8@31, 453 |
| `src/system-agent/setup-inference-credentials.lifecycle.test.ts` | S7@10, 17 |
| `src/system-agent/setup-inference-credentials.ts` | S8@20, 77; S35@20, 82, 121 |
| `src/system-agent/setup-inference-detect.lifecycle.test.ts` | S7@7, 14 |
| `src/system-agent/setup-inference-turn.test.ts` | S8@8, 66, 84; S10@7, 119, 126, 131, 154; S35@8, 66 |
| `src/system-agent/setup-inference-turn.ts` | S8@26, 402; S35@26, 330 |
| `src/system-agent/setup-inference.provider-install-owner.test.ts` | S10@12, 260 |
| `src/system-agent/system-agent.lifecycle.test.ts` | S8@10, 99; S35@10, 100 |
| `src/system-agent/system-agent.test-helpers.ts` | S36@15, 119 |
| `src/system-agent/system-agent.ts` | S8@159; S35@159 |
| `src/transcripts/status.metadata.test.ts` | S36@5, 96 |
| `src/transcripts/status.test.ts` | S36@9, 194, 256, 318 |
| `src/transcripts/status.ts` | S10@6, 24 |
| `src/tts/tts-request.preparation-resources.test.ts` | S7@15, 136 |
| `src/tts/tts-request.resources.test.ts` | S7@18, 207 |
| `src/tts/tts-streaming.resources.test.ts` | S7@16, 193 |
| `src/tts/tts-summary.selection.test.ts` | S7@13, 25 |
| `src/video-generation/runtime.resources.test.ts` | S7@16, 168 |
| `src/web-fetch/content-extractors.runtime.test.ts` | S7@3, 42 |
| `src/wizard/setup.migration-resources.test.ts` | S7@7, 15 |
| `src/wizard/setup.ts` | S32@597 |
### Predecessor-only retired consumers
Baseline coordinates use the symbol table’s retired/migrated dispositions; current counterparts are above.
| Baseline consumer | Retired symbol and baseline line |
| --- | --- |
| `extensions/signal/src/account-selection.ts` | S33@14; S33@4 |
| `extensions/signal/src/accounts.ts` | S33@11; S33@78 |
| `extensions/signal/src/setup-core.ts` | S33@320; S33@33 |
| `extensions/signal/src/setup-transport.ts` | S33@316; S33@9 |
| `extensions/signal/src/shared.ts` | S33@11; S33@35 |
| `src/channels/plugins/account-config-mutation.test.ts` | S5@286; S5@322; S5@358; S5@388; S5@413; S5@6; S15@275; S15@324; S15@360; S15@390; S15@407; S15@8 |
| `src/channels/plugins/account-config-mutation.ts` | S5@215; S15@196 |
| `src/commands/channels/remove.ts` | S5@223; S5@4; S15@209; S15@6 |
### Additional lexical and manual consumers
Retain means source disposition, not live execution.
| Consumer | Exact disposition |
| --- | --- |
| `apps/ios/Sources/Gateway/GatewaySettingsStore.swift:764`; `apps/ios/Sources/Gateway/KeychainStore.swift:37` | Exclude `deleteAccounts` homonym: Keychain deletion, no channel/native change. |
| `docs/plugins/manifest.md:102,261`; `docs/plugins/manifest/surfaces.md:353–362` | Retain documented manifest policy declaration. Snapshot remains its projection; no new manifest/config key. |
| `docs/plugins/sdk-channel-plugins/setup-and-config.md:91–130` | Changed public selector documentation. Documents optional channel context on resolveAccountKey and its absence from v2026.9.4. No new public name remains. |
| `docs/channels/signal.md:86` | Changed user guidance correctly describes collision refusal and preserved rows. This is CLI documentation, not a protocol field. |
| `extensions/clickclack/src/accounts.ts:86,122` | Retain explicit-normalizer SDK account/token-file reads; no creation mode. |
| `extensions/discord/src/accounts.ts:52`; `extensions/discord/src/token.ts:70` | Retain no-policy SDK account/token reads. |
| `extensions/discord/src/monitor/gateway-registry.ts:16,22,27,32`; `extensions/discord/src/monitor/presence-cache.ts:12,22,43,49` | Exclude local `resolveAccountKey` homonyms: runtime registry/presence partitioning, not the changed shared selector. The latter's generic accountKey uses are already separately listed in the PR. |
| `extensions/feishu/src/channel.ts:1130` | Retain custom no-op/unsupported delete; CLI rejects normalized no-op before effects. No shared-map survival check. |
| `extensions/googlechat/src/accounts.ts:71`; `extensions/imessage/src/accounts.ts:47` | Retain no-policy default/account reads through public wrapper. No creation mode. |
| `extensions/line/src/accounts.ts:88`; `extensions/line/src/group-keys.ts:52` | Retain no-policy account and group reads. |
| `extensions/line/src/config-adapter.test.ts:34` | Retain adapter delete control; shared owner rejects aliases admitted by its selector. |
| `extensions/matrix/src/account-selection.ts:130`; `extensions/matrix/src/matrix/account-config.ts:81` | Retain SDK channel normalizer; Matrix identity/storage unchanged. |
| `extensions/matrix/src/channel.setup.test.ts:277`; `extensions/msteams/src/channel.test.ts:79` | Retain registered configuration/delete controls and protocol. |
| `extensions/signal/openclaw.plugin.json:13` | Retain the sole Signal account-key policy declaration; disabled maintenance and active owner selection consume this via metadata. |
| `extensions/signal/src/account-selection.test.ts:191,198,264`; `extensions/signal/src/core.test.ts:1366` | Signal config.deleteAccount covers collision refusal; root-default/core deletion controls remain. |
| `extensions/slack/src/accounts.ts:93`; `extensions/slack/src/shared.test.ts:77,108` | Retain no-policy read and registered adapter/delete contract tests. |
| `extensions/sms/src/accounts.ts:103`; `extensions/sms/src/channel.test.ts:92` | Retain no-policy account read and registered hybrid deletion control. |
| `extensions/telegram/src/account-config.ts:15`; `extensions/telegram/src/token.ts:125` | Retain explicit-normalizer entry/token reads through SDK barrels; no Signal policy threading. |
| `extensions/twitch/src/config.ts:68,116`; `extensions/twitch/src/token.ts:64` | Retain normalized account/config/token reads; no creation mode. |
| `extensions/whatsapp/src/account-config.ts:13`; `extensions/whatsapp/src/doctor-contract.test.ts:104` | Retain default account wrapper and existing case-insensitive Doctor expectation. No Doctor transform change. |
| `extensions/zalo/src/token.ts:42` | Retain SDK entry read for token selection. |
| `src/channels/plugins/read-only.ts:209,325,383–391` | Lightweight adapter carries selected policy, rebinds input/output config and calls registered deletion. Propagates refusal without inferring success. |
| `src/channels/plugins/types.adapters.ts:92` | Synchronous delete returns config; ambiguity uses existing error path/result shape. |
| `src/commands/agents.providers.test.ts:106,125` | Existing account-read/config-adapter fixture; retained no-policy provider setup contract. |
| `src/commands/channels.plugin-install.test-helpers.ts:70` | Existing custom delete mock is fixture infrastructure, not real installation-policy proof. |
| `src/config/zod-schema.providers-whatsapp.ts:126` | Existing schema validation reads default account through unchanged no-policy wrapper. No schema or migration edit. |
| `src/plugin-sdk/account-core.ts:15`; `src/plugin-sdk/account-resolution-runtime.ts:5`; `src/plugin-sdk/routing.ts:33` | Retain public entry/normalized-entry barrels. They continue reaching the same selector. Shipped declaration compatibility is recorded in the matrix below. |
| `src/plugin-sdk/channel-config-helpers.test.ts:346,388,584,606,644,715,763` | Retain SDK scoped/hybrid deletion and return-contract controls. |
| `src/plugins/contracts/plugin-sdk-runtime-api-guardrails.test.ts:217` | Retain public runtime export fixture for `deleteAccountFromConfigSection`; no removed prepared API. |
| `src/plugins/loader.prefer-over.test.ts:43,139` | Retain preferred-plugin/manifest policy precedence fixture. It remains a useful sibling to maintenance-policy selection. |
| `src/plugins/manifest-registry.ts:460`; `src/plugins/manifest-types.ts:400`; `src/plugins/manifest.ts:259–260`; `src/plugins/plugin-metadata-snapshot.types.ts:32` | Retain declaration parsing/types/projection; no new policy declaration/field. |
| `src/status/status-text.ts:97` | Retain status formatting's normalized-entry read. No creation path or newly composed protocol field. |
| `src/wizard/i18n/locales/en.ts:518`; `src/wizard/i18n/locales/zh-CN.ts:502`; `src/wizard/i18n/locales/zh-TW.ts:502` | Retain localized delete prompts/error handling; no new locale key. |
| `test/buzz-account-config-mutation.test.ts:53` | Retain existing preparation helper case; new command claims use command suites. |
### Returned adapters and their registrations
Returned callbacks consume the shared deletion owner.
| Consumer | Exact disposition |
| --- | --- |
| `extensions/signal/src/shared.ts:32` | Changed registered scoped adapter removes direct policy constant; snapshot-backed shared delete selection/refusal is authoritative. |
| `extensions/whatsapp/src/shared.ts:59` | Retain scoped adapter; named deletion consumes shared owner, root cleanup retains configured field list. |
| `extensions/matrix/src/config-adapter.ts:18` | Retain scoped adapter and Matrix's registered account accessors; delete now consumes shared post-map admission. |
| `extensions/discord/src/shared.ts:86` | Retain scoped adapter and Discord accessors; shared deletion result is consumed without another survival check. |
| `extensions/zalo/src/channel.ts:142` | Retain registered scoped deletion. |
| `extensions/nextcloud-talk/src/channel.adapters.ts:19` | Retain registered scoped deletion. |
| `extensions/irc/src/channel.ts:103` | Retain registered scoped deletion. |
| `extensions/zalouser/src/shared.ts:32` | Retain registered scoped deletion. |
| `extensions/imessage/src/shared.ts:36` | Retain registered scoped deletion. |
| `extensions/googlechat/src/channel-base.ts:48` | Retain registered scoped deletion. |
| `extensions/mattermost/src/channel-config-shared.ts:55` | Retain registered scoped deletion. |
| `extensions/line/src/config-adapter.ts:11` | Retain registered scoped deletion. |
| `extensions/telegram/src/config-adapter.ts:35` | Retain registered scoped deletion. |
| `extensions/slack/src/config-adapter.ts:16` | Retain scoped base spread into Slack configuration; shared named-delete admission, existing channel-specific effects unchanged. |
| `extensions/tlon/src/channel.ts:58` | Retain hybrid adapter: named-account deletion consumes shared owner; configured default credential cleanup remains its existing contract. |
| `extensions/synology-chat/src/channel.ts:112` | Retain hybrid adapter with the same named/default distinction. |
| `extensions/feishu/src/channel.ts:488` | Retain hybrid base plus custom registered wrapper at `:1130`; do not mistake its custom no-op outcome for a shared-selector refusal. |
| `extensions/sms/src/channel.ts:71` | Retain hybrid named-account delete and default credential clearing contract. |
| `src/commands/channels.adds-non-default-telegram-account.test.ts:116` | Retain existing registered command fixture using returned scoped adapter; sibling promotion/naming proof is not new installation-policy evidence. |
| `src/auto-reply/reply/commands-allowlist.test.ts:137` | Retain returned adapter fixture for allowlist command behavior; does not exercise delete. |
| `src/commands/agents.providers.test.ts:125`; `src/plugin-sdk/channel-config-helpers.test.ts:410,435,739` | Retain factory-returned test consumers; SDK public adapter result shape unchanged. |
### Final consumers, hosts, and external declarations
| Consumer | Exact disposition |
| --- | --- |
| `src/commands/channels/status.ts:69`; `src/commands/channels/status-config-format.ts:81` | Final CLI status consumes Gateway or configured-account view. Cold status and selected transport establish the bounded deletion claim. |
| `src/gateway/server-methods/channels.ts:330,392,496` | Status/stop consumers; no delete RPC. CLI admission precedes registered stop. |
| `src/gateway/server-channels.ts:374,382` | Runtime account preparation consumes the selected account entry; cold start is the final state check after persistence. |
| `extensions/signal/src/sse-reconnect.ts:89`; `extensions/signal/src/client.ts:350–366` | Final recording boundary builds `/api/v1/events` and its account query from selected endpoint/phone. Exact/alias/legacy recorder observations discriminate actual transport identity. |
| `src/flows/channel-setup-navigation.ts:13`; `src/wizard/navigation-prompter.ts:304` | Generic awaited result consumers retain their contracts; the phase producer now declares its awaited result. |
| `src/system-agent/chat-wizard-host.ts:355,370,384,398` | Channel, skills, search and Gateway starts share hosted setup and its operation lifetime. Completion semantics stay intact; channel proof plus existing sibling tests bound the claim. |
| `src/system-agent/chat-turn-router.ts:453,456,459,462` | Dispatches to four hosted starts, independently of `wizard.start`; same metadata owner. |
| `src/gateway/server-methods/system-agent.ts:590` | `system-agent.chat` enters the chat router/host path under existing admission; shared hosted runner drops inherited runtime metadata and owns complete setup. |
| `src/system-agent/tui-backend.ts:433,447` | Terminal Gateway/search handoffs consume hosted resource lifetime; source disposition only. |
| `src/commands/agents.commands.add.ts:443`; `src/commands/configure.wizard.ts:707`; `src/wizard/setup.ts:597` | Local CLI callers inherit the operation owner and shared setup phases. |
| `src/commands/onboarding-plugin-install.ts:131`; `src/plugins/installed-plugin-index-store-write.ts:237`; `src/plugins/runtime.ts:690` | Invalidation producers revoke nested operation facts; admitted Gateway inventory stays stable. |
| `src/plugin-sdk/account-resolution.ts:19–23`; `src/routing/account-lookup.ts:19–51,94–119` | Remove candidate-only resolveChannelAccountKey export. Existing resolveAccountKey accepts optional channelId; map, ID, normalizer, policy and allowMissing retain their contracts, including reserved creation rejection. |
| `extensions/signal/package.json:95–102` | Unchanged support floors; published/candidate matrix below excludes candidate Signal on an old SDK. |
| `scripts/release-check.ts:121,753,767`; `scripts/fixtures/packed-plugin-sdk-setup-consumer.ts:1` | Retain the unchanged external setup consumer and compile owner. The shipped/candidate declaration matrix below records exact artifact applicability; SDK channel-context execution is covered separately. |
### Structural and retained-fixture consumers
| Consumer | Exact disposition |
| --- | --- |
| `test/scripts/plugin-sdk-surface-report.test.ts:138,163`; `scripts/plugin-sdk-surface-report.mts:373,509` | Public export/callable counts remain unchanged after removal of the candidate-only export; existing guards are retained. |
| `test/extension-test-boundary.test.ts:242`; `src/plugins/contracts/boundary-invariants.test.ts:331`; `scripts/check-tsgo-core-boundary.mts` | Project/type-graph guards retained. Real Signal agreement moves to root integration ownership through public facade loading. |
| `src/commands/doctor-config-preflight.plugin-persistence.test.ts:195,399`; `src/commands/doctor-plugin-registry-generation-repair.test.ts:94`; `src/gateway/config-reload.test.ts:6823`; `src/commands/onboard-quickstart-host.plugin-generation.test.ts:104` | Rewritten fixtures distinguish nested refresh from independent/admitted frozen consumers; durable-state rejection, Doctor non-restoration, full inventory and lease release remain asserted. |
### Current correction test consumers
These 561c1895 coordinates supersede historical test references above; C10 only shifts callback fixture lines.
| Consumer | Exact disposition |
| --- | --- |
| `src/plugins/test-helpers/install-account-policy.test-support.ts:4,39–59` | New fixture writes real manifest `channelAccountKeyPolicies`, calls `loadPluginMetadataSnapshot` and `clearPluginMetadataLifecycleCaches`. Used by CLI add `:1930`, setup flow `:1582` and hosted setup `:700` below. Installer simulation for registered-entry proof, not a production policy declaration. |
| `test/plugins/signal-account-policy.integration.test.ts:5,14–48` | Relocated Signal/core agreement: `withPluginMetadataSnapshotScope` selects an earlier policy-free owner over the real Signal manifest; loads the public Signal facade. Retires the round-1 core-only Signal import/scope row. |
| `src/channels/plugins/account-config-mutation.test.ts:5–8`; `src/channels/plugins/account-key-policy.test.ts:1–16` | Historical S4/S36 test coordinates are retired: no current removal-helper/real-Signal scope consumers here. Commands replace them in `src/commands/channels.add.test.ts:1417` and `src/commands/channels.remove.test.ts:362,385,417,491,557`; Signal agreement moves to the integration file above. |
| `src/routing/account-lookup.test.ts:3–96`; `src/commands/channels.add.test.ts:1930–2044`; `src/flows/channel-setup.test.ts:1582–1717`; `src/system-agent/hosted-setup.runtime.test.ts:700–851` | Current public-selector/scoped-policy consumers: SDK arguments, installed-policy final row/status and retained postwrite callbacks. Supersede old test positions; no new production owner. |
| `test/setup.signal.ts:7–16` | Parses the real Signal manifest with `loadPluginManifest` before the snapshot fixture; preserves policy and per-test scope/reset. Fixes raw-JSON category typing; no production change. |
### Deleted fixture fields
The filename heuristic finds 16 removed private fixture keys in `src/channels/plugins/account-config-mutation.test.ts` (base `89bf2a4e`), with zero surviving consumers. Shared contracts and same-word homonyms remain; C4 commands preserve the fixture behavior.
Baseline locations: `accountId:207,213,277,282,300,324,409`; `accountIds:330,396`; `action:278,360,390,396,410,421`; `allowTopLevel:352`; `config:254,314,345,384`; `deleteAccount:256,316,347,384`; `gateway/startAccount:272`; `listAccountIds:255,315,346`; `nextCfg:212`; `nextConfig:367`; `prevCfg:211,299`; `resolveAccountId:180`; `sectionKey:351`; `setAccountEnabled:317,348`; `value:366`.
census: generic accountId reviewed — 0 callers listed
census: generic accountIds reviewed — 0 callers listed
census: generic action reviewed — 0 callers listed
census: generic allowTopLevel reviewed — 0 callers listed
census: generic config reviewed — 0 callers listed
census: generic deleteAccount reviewed — 0 callers listed
census: generic gateway reviewed — 0 callers listed
census: generic listAccountIds reviewed — 0 callers listed
census: generic nextCfg reviewed — 0 callers listed
census: generic nextConfig reviewed — 0 callers listed
census: generic prevCfg reviewed — 0 callers listed
census: generic resolveAccountId reviewed — 0 callers listed
census: generic sectionKey reviewed — 0 callers listed
census: generic setAccountEnabled reviewed — 0 callers listed
census: generic startAccount reviewed — 0 callers listed
census: generic value reviewed — 0 callers listed
### Correction coordinates and completed merge census
The a6de2d82 delta had 77 source/17 test references and 11 project-local gaps. Completed query: merge `730d8f0e4b1b35bbccffa60474e9fc7485751b08`, head `561c1895e26f33230ec298ce51e23d1de60061a8`, tree `7d9cd60e3fa5d856ab12343d489965c95dc7eeb1`. Six projects loaded: core, Signal, UI, extension tests, SDK package and root. Across 34 positions: 159 resolved/45 project-local gaps; all 34 resolve in root. Exit 0; no stderr. References: 3,752 raw/1,816 unique across 413 files (532 source, 1,284 test/support). Retained `typed-census-merge-730d8f0e-complete-coverage.json` names all 131 unselected projects. These are limits, not zero consumers or execution/typecheck proof. Native, string, facade and dynamic consumers have manual/lexical dispositions. Queried owners and proof-relevant paths match candidate to merge; no unexpected production consumer. Source coordinates below retain the a6de2d82 delta.
| Symbol | Current source locations |
| --- | --- |
| S20 | `src/routing/account-lookup.ts:43,72,84,89`; `src/config/channel-account-config.ts:3,83`; `src/channels/plugins/config-helpers.ts:8,197`; `src/plugin-sdk/account-resolution.ts:19`; `extensions/signal/src/account-selection.ts:1,7` |
| S22 | `src/routing/account-lookup.ts:19,27,35,56`; `src/config/channel-account-config.ts:4,76`; `src/config/group-policy.ts:3,75`; `src/channels/plugins/config-helpers.ts:9,87,125,143,190`; `src/channels/plugins/helpers.ts:9,57,63`; `src/channels/plugins/setup-helpers.ts:8,50,93,311,370`; `src/channels/plugins/account-config-mutation.ts:5,97`; `src/config/channel-doctor-helpers.ts:3,196`; `src/plugin-sdk/allowlist-config-edit.ts:8,197` |
| S34 | `src/commands/config-validation.ts:57`; `src/flows/channel-setup.ts:27,106,289,439,449,582,986,1088,1105`; `src/commands/channels/add-wizard.ts:24,205`; `src/commands/channels/add.ts:29,274`; `src/commands/channels/remove.ts:21,106` |
| S24 | `extensions/signal/src/account-selection.ts:3,16`; `extensions/signal/src/config-compat.ts:6,329,340,390,402,514`; `extensions/signal/src/setup-core.ts:30,365`; `extensions/signal/src/account-key-repair.ts:5,36` |
| S23 | `extensions/signal/src/account-selection.ts:12`; `extensions/signal/src/accounts.ts:11,292`; `extensions/signal/src/setup-transport.ts:9,89,123,124`; `extensions/signal/src/setup-core.ts:30,215`; `extensions/signal/src/config-schema.ts:16,164` |
## Invalidation
- Delete admission: `src/channels/plugins/config-helpers.ts:143` re-resolves before `applyChannelAccountRemoval` invokes stop/lifecycle; refusal causes no write/success. Existing publication/reload and cold restart consume successful writes.
- Install: `src/plugins/plugin-metadata-lifecycle.ts:244` invokes operation revocation before its active-Gateway guard. `src/plugins/current-plugin-metadata-snapshot.ts:197` visits enclosing caches, excluding admitted runtime caches; `src/plugins/plugin-cache.ts:146` clears facts, retaining modules/instances.
- Custody: `src/flows/channel-setup.ts` loads callbacks into its enclosing operation under the install lease. `src/gateway/server-methods/wizard.ts:61` and `src/system-agent/hosted-setup.runtime.ts:49` own operations through runner/hook settlement.
- Final read: `src/flows/channel-setup.ts:90` rereads committed config and scopes metadata before collected hooks. Ordinary publication does not revoke admitted scopes.
## Contention
No new lock/queue/writer. Stop follows deletion admission; hosted admission/cancellation remain through cleanup. Deferred completion/cancellation pass; no full concurrency-stress claim.
## Tests
Tier L. C10/C12 at 623bd36f: 128 tests/5 files/4 shards pass (35.47 s): selector, CLI add, hosted setup and both Signal suites. Three-file direct Oxlint and native review pass; CI core types/lint pass; root test types require the fixture repair. Retained: 778 tests/14 files/6 shards, 10 SDK surface tests, plugin-import/core graph checks pass; budgets unchanged. Fixture parser: 17 Signal/integration tests pass; root types await CI.
| Correction / current test entry | Retained behavior; PASS |
| --- | --- |
| C2 `src/gateway/server-methods/wizard.test.ts:149`: `wizard.start` setup/channels/cancel | Type-only fixture repair; three callback-lifetime/Gateway-preservation cases unchanged. |
| C3 `test/plugins/signal-account-policy.integration.test.ts:14`: Signal `config.resolveAccount` plus SDK reader | Relocated competing-owner case loads real Signal via public facade; earlier policy-free owner wins. |
| C4 `src/commands/channels.add.test.ts:1417`: `channelsAddCommand` | Replaces helper omission/normalization cases: omitted ID reaches plugin, Work selected, writer uses work, lifecycle/result retain Work. |
| C4 `src/commands/channels.remove.test.ts:362,385,417,491,557`: `channelsRemoveCommand` | Unknown delete/disable have no effects; unauthored listed default disables; normalized delete preserves sibling/lifecycle; fresh no-op and unsupported delete/disable never stop/write/run hooks. |
| C6 `src/commands/channels.add.test.ts:1930`; `src/flows/channel-setup.test.ts:1582`; `src/system-agent/hosted-setup.runtime.test.ts:700` | CLI add, setupChannels, ChatWizardHost.startChannel carry installed manifest through original-row rename, final config/status and retained postwrite callback; CLI/chat preserve executable Gateway inventory. |
| C9 `src/commands/doctor-config-preflight.plugin-persistence.test.ts:138,267` | runDoctorConfigPreflight: five scope/replacement rows plus alpha/beta: nested refresh vs independent reader, full inventory/exact durable leaf and lease release. |
| C9 `src/gateway/config-reload.test.ts:6774`; `src/commands/doctor-plugin-registry-generation-repair.test.ts:76` | startGatewayConfigReloader/applyPluginLifecycleChange and maybeRepairPluginRegistryState: nested/independent durable-input rejection/no acceptance and no restoration. |
| C9 `src/commands/onboard-quickstart-host.plugin-generation.test.ts:19` | runQuickstartForegroundGateway: mutable/pinned first inventories see install; mutable caller refreshes, admitted generation remains old. |
C9's 13 changed-family rows cover all seven former failures; no terminal safeguard deleted. Signal collision test replaces row-preservation-only with refusal/no takeover; removal validates before stop, unsupported deletion never stops, and obsolete prepared-wrapper assertions move to command behavior.
Red evidence is claim-specific. Historical lease-ancestry and wizard lifetime cases fail prior owners. C6 CLI before phase repair reads no selected account immediately after install; candidate reaches correct persistence/hooks. Historical setup/hosted reds show callback-custody/scope failure, not a wrong final row. C2 type repair, C3 relocation, C4 entry replacements and C9 fixture ownership are not each claimed red; unchanged publication-preservation cases pass.
C1 models awaited results; C8 forwards arguments into one policy lookup. The a6de2d82 declaration build predates test-only 561c1895. C12 replaces parameter assignment with an equivalent local; explicit policy still avoids the sole scoped lookup. C10 types two registered callbacks for nullable/omitted IDs through existing normalization, makes work-phone reads explicit and retains all assertions. C11 updates census coordinates. Accepted runtime/old-state proof remains bound to its recorded head; no new execution is implied.
Real CLI and cold Gateway proof at `9a24813986c8fa440e144b35af7ee0d374f11d4d`:
| Operation | Pinned main | Candidate |
| --- | --- | --- |
| Delete colliding Signal account | Exit 0; cold start activates Shadowed identity | Exit 1 names both keys; config unchanged; Selected identity stays running and survives cold restart |
| Delete one stored identity | Positive control | Exit 0; cold start not configured/running; zero recorder requests |
| Delete with disabled Signal plugin | Maintenance control | Exit 1 names both keys; config unchanged |
| Setup `constructor`, `__proto__`, `prototype` | Reserved selector can report a default account | All exit 1; config bytes unchanged |
| Doctor preview and repair | Existing collision preservation contract | Preview leaves account map unchanged; repair preserves colliding/dormant rows and normalizes the unambiguous alias |
| Consumer / support floor | State artifact producer | Operation | Result |
| --- | --- | --- | --- |
| Candidate Signal runtime; existing own-number account-map format | Actual v2026.9.4 source CLI at `
|
||
|
|
a02a33d523
|
fix: support large SQLite worker commands with bounded transport (#146019)
* fix: support large SQLite worker commands with bounded transport * refactor: keep SQLite transfer handles in the leaf contract |
||
|
|
4dd1723ba0
|
fix: Nostr profile actions fail for paired dashboard operators (#145932)
## What Problem This Solves Fixes an issue where paired dashboard operators could not save or import a Nostr profile when their browser held only its device credential. Save & Publish and Import from Relays each returned HTTP 401, then displayed `e?.trim is not a function`. The dashboard handoff in `docs/web/control-ui/connect-and-pair.md`, paired-operator Control UI read authorization, and profile editor in `docs/channels/nostr.md` establish this contract. The defect was reproduced on pinned main ` |