mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
24 commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
dab1f08376
|
feat: give every plugin a compact chat activity icon (#147333)
* feat: give every plugin a compact chat activity icon Separate package-owned activity SVGs from plugin identity artwork. Ship 154 defaults and seven exact tool overrides, preserving Echo and the progress claw. Include authenticated bounded delivery, safe mask rendering, packaging, and authoring guidance. * test: declare Vite types for the activity asset browser test * refactor: keep plugin artwork selection with catalog presentation facts * test: scope activity browser types and simplify fixture copies |
||
|
|
b10035faa9
|
fix(backup): archive unmanaged SQLite files as opaque bytes (#146700)
## What Problem This Solves
An unrelated SQLite file with foreign-key violations could prevent every backup from completing.
## Why This Change Was Made
Whether an included file gets the live-database snapshot path is decided by exactly one mechanism at `src/commands/backup-resource-inventory.ts:336`, from the core set plus declared plugin resources. The online root snapshot supplies the registry used for discovery and traversal, so planning no longer needs a quiet write-ahead log.
## User Impact
Undeclared files survive backup unchanged with filename warnings. Foreign SQLite symbolic links that exceed the link-resolution limit (`ELOOP`), including loops, are skipped with a filename warning. Corrupt managed databases and unavailable plugin SQLite capabilities still stop publication.
## Evidence
- Pinned main `
|
||
|
|
7292689e7f
|
fix(signal): start accounts with spaced keys without Doctor (#145750)
## What Problem This Solves Signal lists `Work Phone` as `work-phone` but misses its authored number/endpoint. Fresh startup reports unconfigured and never contacts that endpoint until Doctor renames the key. Runtime must work without the #138982 cleanup. ## Why This Change Was Made The decision 'which stored key serves Signal account id X' is made by exactly one mechanism at `src/routing/account-lookup.ts:94`. Signal declares its rule once in manifest metadata: exact keys win; normalized aliases use authored settings only with a nonempty own number. The task owner accepted own-number transport/settings, whole-root inheritance for aliases without a number, exact collision winners, and Doctor refusing cleanup that activates ignored settings. Setup preserves restrictions in the canonical default row, even when empty, and restores its number to root. Promotion targets the runtime winner. The second correction removes command singleton/writer raw-key bypasses: selector-owned optional creation; existing selection for delete/clear. Global owner authority stays separate. ## User Impact Own-number aliases start at their authored endpoint without Doctor. Root inheritance, exact winners and other channels' maps remain stable; adding an account preserves the active account's inherited credentials. No config keys, schema or protocol versions change. Public SDK exports remain. Code `8828dc61b2da6d7ed02b8765080ed8f474ae2567`: 76 files (+1,941/-360) against e76. Credit: @marmar9615-cloud for the report; adversarial review found the incomplete repair. ## Evidence Eight runtime scenarios cover both status paths, 35 startup cases and allowed/excluded senders across setup, reload and restart. | Fresh alias, no Doctor | Pinned base ` |
||
|
|
f9ccd07ded
|
fix: skip official setup approvals and default to Astra (#145646)
* fix: skip official setup approvals and default to Astra * test: align default-model expectations across consumers * test: align attachment catalog with Astra default * fix: preserve configured Codex catalog model selections |
||
|
|
fe056539fd
|
fix(plugins): keep rebuilt bundled plugins on git installs instead of npm refreshes with a mismatched SDK (#145356)
Git/dev installations keep the plugin rebuilt from the running source checkout instead of refreshing a same-version npm build with a different Plugin SDK. Doctor records why the registry artifact was not admitted. Manifest-registry selection owns bundle precedence and dormant install detection. Named plugin updates, --all, and stable/beta release-cohort convergence carry that decision through package-mutation preflight while retaining strict checks for active packages. Existing npm records remain available, explicit plugin paths retain priority, and package-host updates retain their registry behavior. Fixes #145266 Thanks @DonnieFi for reporting the artifact skew and providing the reproduction evidence. |
||
|
|
dda6470454
|
feat(desktop): match virtual worker displays to the viewport (#143938)
* feat(desktop): match virtual worker displays to the viewport Keep Fit as the default and gate Match on provider-owned resize permission and authenticated controller ownership. Preserve sizing choices during reconnects and retire resize authority with input control. Pass resolved SSH VNC credentials through optional auth metadata and reconcile lost physical modifier releases after native popups. Add instrumented production Gateway/XFCE resize proof and native selection regressions. * fix(desktop): align renderer exports and suppression inventory * test(desktop): cover real node carrier resize qualification * test(workers): align repository access provider fixture * fix(ci): run real desktop resize proof with an upstream fixture * fix(ci): bind desktop proof to raw merge identity * fix(ci): retain safe desktop proof failure diagnostics * fix(ci): expose safe desktop SSH setup diagnostics * fix(ci): keep desktop proof phase tuple private * fix(ci): retain desktop proof phase after timeout * fix(ci): observe Gateway startup at desktop proof timeout * fix(ci): run desktop proof against built Gateway * fix(ci): assert visible desktop recovery state * fix(ci): remove retired desktop spy allowance * test(ui): model targeted desktop status in sizing fixtures |
||
|
|
8ebd18d84c
|
fix(doctor): preserve consumers of renamed auth profiles (#145136)
Doctor can rename a saved credential while leaving account selections and model references pointing at its deleted ID. This can make a new conversation use another account, send a profile ID as a literal API key, or leave an automation unable to run. A saved session can also restore the deleted credential after a failed model change, and an older stored pin with surrounding spaces can lose its selected account. Ordinary interactive Doctor also imported and archived credentials without completing all their consumers. Both Doctor entry paths now use one auth-completion operation. It completes verified imports through the existing credential, account-link, config, session, and automation owners. Planned collision mappings are kept separate from completed-import and verified recovery facts. No database schema, runtime alias, plugin callback contract, or public config option is added. Current signed PR head: `97b7f558aa772e06825e3aece4abf7ae84ecf19c`. The latest commit removes a redundant empty-session return and its helper; the existing preview and repair paths already produce the same summary. Current merge-tree checks use `0fc267c94c12f7138e674762c0e19f51a0dd963b`, whose second parent is this head. Earlier runtime, released-state, and published-updater captures below retain their original source identities. ## Consumers | Stored representation | Repair owner | Runtime consumer | | --- | --- | --- | | Credential IDs, auth order, last-good and usage keys | Existing auth importer, alias allocator, and receipt owners | Credential selection and rotation | | Personal `model-accounts` links | `state/user-model-accounts.ts` inside the shared receipt transaction | New conversations and normal turns | | Provider `apiKey` profile reference | Explicit Doctor config slot using the reader's secret normalization | Provider authentication | | Media `profile` / `preferredProfile` | Explicit Doctor config slots with exact ID matching | Media and image model selection | | Plugin `authProfileId` / `defaultAuthProfileId` | Bounded plugin/channel config adapter | Registered LLM Task and older installed plugins | | MCP OAuth and legacy model-runtime profile IDs | Existing typed config slots, following reader trimming | MCP authentication and runtime policy | | Configured `@profile` model suffixes, model-map keys, and allow policies | Existing model parser and slot traversal | Agent/default/utility/media models, heartbeat, subagents, compaction, reviewers, hooks, and channel overrides | | Active session `authProfileOverride`, including accepted surrounding spaces | Session owner with explicit profile-only repair admission; lookup follows the reader’s `.trim()` rule | `agents/auth-profiles/session-override.ts` account selection | | Saved session `modelFallback.prevAuthProfileOverride` | Same session owner and verified rename map, independently of the active pin | Agent-selected model change snapshots the pin; failed-turn auto-revert restores it; session account selection consumes it | | Saved automation primary/fallback suffixes | Existing cron changed-row writer after config persistence | Registered automation execution | `doctor/auth-profile-repair.ts` joins the explicit repair sequence and ordinary health contribution. Successful imports report completed IDs; failed owners report blocked IDs. Config credentials and AWS metadata are updated only after import verification and archival. An empty completed map remains visible so the health flow does not repeat an operation already completed by the explicit sequence. The private `emptyRepairSummary` helper and its sole call are removed. Empty session stores use the existing preview or repair summary path; no public interface or persisted shape changes. The removed importer result `configOwnerMigrationApplied` is replaced by `migratedProfileIds` and `blockedProfileIds`. The shared completion operation consumes these facts; source-owner, canonical-key, flat-profile, sequencing, health-flow and fast-path fixtures mirror that return contract. Config and session runners consume the completed map, including an explicitly empty map. Recovery uses current verified archive/credential evidence after the importer has resumed pending receipts. It can recover the recorded target even when the initial plan was empty. A before-state plan is not completion authority. A declined live source cannot borrow permission from an old archive or an unrelated receipt. Session preview remains read-only when given a map. The registered health flow explicitly admits profile-only session updates after auth completion. The session owner repairs both active and rollback pins using the same completed map. It trims only lookup input and leaves unmapped saved strings unchanged. Marker timestamps, source, previous model/provider choices, credential provenance and compaction count, runtime bindings, and protected-harness state remain intact. Full repair retains its existing behavior. The rollback producer is `src/config/sessions/session-model-fallback.ts:54-59`, entered through the registered sessions tool’s model patch at `src/agents/tools/sessions-tool.ts:496-515` and persisted by `src/gateway/sessions-patch.ts:547-550,643-644`. `src/agents/session-model-auto-revert.ts:84-102` restores the previous credential after a definitive failed turn; `src/agents/auth-profiles/session-override.ts:332` trims that restored pin before account selection. `src/config/sessions/types.ts:521-524` and `store-entry-shape.ts:56-80,186` retain both saved forms, and `session-entry-projection.ts:38-45,60-64` carries the rollback marker through projection. Doctor changes these saved references; no later runtime alias table is added. Automation repair reads stored config together with runtime state, changes only matching reference slots, and submits only changed jobs. It retains same-job legacy config such as notify markers and excludes embedded runtime-authority fields from the config overlay. General cron normalization and unrelated repairs retain their own admission. The census also follows the link writer in `src/gateway/model-account-connect.ts` through `src/agents/auth-profiles/session-override.ts` and `src/gateway/session-create-service.ts`; provider lookup in `src/agents/model-auth-provider-config.ts`; media entry/image runtimes; `src/agents/mcp-auth-profile.ts`; the released LLM Task and Reef readers; the model-ref parser and `packages/model-catalog-core/src/configured-model-refs.ts`; and cron model selection, preparation, and dispatch. `ui/src/pages/profile/model-accounts.ts` and `ui/src/pages/new-session/model-control.ts` consume Gateway IDs; generated native protocol models project those IDs. They add no independent durable auth-selection store. UI inventory retains its existing reopen/reconnect lifecycle. Config contracts remain in `src/config/types.auth.ts`, `src/config/types.tools.ts`, `src/config/zod-schema.core.ts`, `src/config/zod-schema.mcp-server.ts`, and `docs/plugins/manifest/surfaces.md`. Browser/tool profiles, human profile IDs, secret references, prompts, and historical replay/binding fingerprints remain distinct contracts. Literal credentials, structured secret references, user text, explicit disconnects, link timestamps, ownership, and collision decisions remain intact. Historical CLI/plugin credential fingerprints keep their existing mismatch and reuse rules. ## Contention Auth aliases and personal links use the existing shared receipt transaction and auth-store locks. The link owner validates participating records before its first write and changes only their stored value. Separate agent databases retain their receipt-based recovery contract. The automation writer rechecks changed-job definitions and existence inside its transaction. It preserves concurrent additions and merges current scheduler state and runtime authority. No prompt or import runs inside that write transaction. The session correction adds no lock or queue. Both slots are changed inside the existing session replacement operation after its current-entry read. Its runtime proof uses an idle saved session and stopped Gateway during Doctor; it does not claim a Doctor-versus-in-flight-turn race. The existing shared-store owner tests passed all three selected cases: scheduler state survives stale CRUD views, stale edits are rejected, and stale deletion is rejected. Three selected authority-preservation tests also passed, covering concurrent runtime/authority state, authority clearing, and older embedded authority. Signed Doctor controls preserved the unrelated dreaming row and all non-reference fields on the affected job. These owner tests and Doctor controls are separate observations, not a claim that the Doctor fixture injected a concurrent authority change. ## Invalidation Credential owners continue to clear auth snapshots after mutation. Personal links read current SQLite state. Config publication stays with the existing config writer, before downstream automation repair. Session updates use the existing session writer and recency rules; the cron writer advances its existing committed revision. The saved rollback pin is derived state that can become authoritative on a later failed turn. Verified credential rename invalidates it together with the active pin. The correction preserves the existing success/rollback marker lifecycle, preview admission, and restart/reload owners. Prior CI merge `532b42292bcf23fbb1b0f01978649df8e92b062b` passed all six flows on copied v2026.9.4 state without reseeding credentials. The actual registry-installed v2026.9.4 updater then installed the validated candidate package; rehearsal, Doctor lint, config validation, plugin resolution, continuation, Gateway canary, and installed Doctor all succeeded. The resulting installed Gateway used the selected credential for a new conversation and the released LLM Task plugin. The update used `--no-restart`, so this proves subsequent installed-Gateway startup, not automatic service restart. Historical Telegram restart/reload evidence retains its original head and covers the unchanged runtime publication owners. ## Tests All three packaged Doctor cases are new relative to the PR base: free destination with padded references, occupied destination, and ordinary interactive Doctor through a real terminal. The suite retains the older installed-plugin fixture and all prior assertions, adds saved automation primary/fallback checks to every case, and checks the second run. The interactive case stores the legacy credential only in JSON, accepts the actual config/import prompts, and does not use `--fix` or `--yes`. Each case now also checks active and rollback pins, rollback-only repair, unmapped padded values, protected harness state, marker preservation, and unchanged second-run snapshots. These assertions pass on the corrected source and combined CI tree. The automation proof invokes registered `cron.run` and correlates `cron.runs` by run ID after the real Doctor command. New-conversation proof uses `sessions.create` and `chat.send`; the registered LLM Task proof uses `/tools/invoke`; utility proof uses `sessions.title.prepare`. Historical proof retains its original source identities: - Main baseline ` |
||
|
|
a48c47a09c
|
docs: align model catalog and provider login guides (#144591)
Related: #136257 ## What Problem This Solves The setup guide still says credentials are saved only after a successful live test, and the Models guide describes API keys as inline configuration. These statements conflict with the landed credential and activation flow. Catalog guidance also mixes user tasks with internal loader details. ## Why This Change Was Made Document the current shared Gateway catalog, explicit refresh, compatible last-good results, session model search, credential-only login, model-access consent, shared API-key management, and saved-credential recovery. Preserve the Models page's first-picker discovery request and distinguish legacy auth refresh from model-list fallback. ## User Impact Users can choose between connecting and activating a model, retry a saved sign-in after failed setup, and understand when credentials were saved but the Gateway has not applied them. Plugin authors can declare the login choices that these surfaces actually support. Runtime behavior is unchanged. ## Evidence Current-main source audit covers all eight changed pages. `pnpm docs:list`, `pnpm check:docs`, and `git diff --check` pass. The optional anchor check reports the same 53 pre-existing failures on the candidate and the untouched baseline; no new anchor failure is introduced. Focused source-mode validation: 73 tests pass across credential editing/removal, refresh and older-Gateway recovery, manifest login choices, setup activation/retry, and session-selection scope. No tests were added or changed. Live CLI checks cover model listing/refresh, provider filtering, API-key save/list/remove, and the hosted catalog's disabled result. Telegram Test Server proof captures the provider buttons for `/login`, the `/models` menu, and OpenRouter's missing-secure-address recovery message. The chat run made zero model requests and cleaned up successfully. Completed browser authorization is source-verified, not claimed as live proof. Co-authored-by: Ayaan Zaidi <hi@obviy.us> |
||
|
|
e52d47f89a
|
feat(auth): sign in to OpenRouter from private chat (#144491)
Related: #136257 ## What Problem This Solves Private-chat `/login openrouter` required a Control UI handoff instead of completing browser sign-in from chat. Browser callback waits could also hide the sign-in URL or keep cancellation behind the pending login. ## Why This Change Was Made OpenRouter now supplies its PKCE authorization URL and key exchange to a core-owned HTTPS callback. Core binds the callback to the managed Tailscale origin, a deadline, cancellation and Gateway restart; it consumes each response once. The callback acknowledges receipt without granting Control UI access or claiming credentials were saved. Setup and login share one auth-context owner, including current caller authority. The wizard chooses hosted completion only when the connected browser origin matches the managed HTTPS origin; localhost and other remote connections retain manual redirect completion. Existing local and remote CLI completion remains available. No new operator setting, database schema or protocol version is introduced. ## User Impact - `/login openrouter`, or OpenRouter in the bare `/login` menu, sends a **Sign in with OpenRouter** URL action before completion. - `/login cancel` cancels that chat's pending login. Other chat sessions retain their own login. - Missing managed HTTPS publication gives Tailscale Serve and CLI guidance. Serve requires the browser to have tailnet access. - Wizard browser waits show the existing sign-in link without an extra Continue action. Credential success follows persistence. ## Evidence - Baseline regressions reproduce the missing direct chat link and missing wizard browser-wait delivery. - Targeted Vitest covers callback state, deadlines, denial, replay, restart, cancellation, owner isolation, persistence ordering, CLI siblings, native Telegram and UI presentation. The command-ticket regression also preserves executable-command ordering. - Real HTTP requests through an isolated Gateway prove callback receipt, actual credential persistence, cancellation and replay rejection. - Live Telegram Test Server proof covers the direct command and an actual OpenRouter menu-button click, URL delivery before completion, chat cancellation and subsequent HTTP 410. No model request was needed. - Actual Models-screen proof uses the running Gateway and a temporary HTTPS proxy: select a provider, observe the waiting link without Continue, accept the callback, observe saved credentials, and reject replay. A localhost session retains the OpenRouter redirect input. - Formatting, syntax lint and runtime build passed. Independent public Gateway acceptance passed, including two-session cancellation, saved credentials after completion, replay rejection, timeout, restart and fresh-client authentication rejection. The approved extraction scope from #136257 leaves real OpenRouter account approval as a manual check. Actual Tailscale route provisioning is also unexercised. Automated evidence uses the existing managed-origin contract, a temporary HTTPS proxy for full UI completion, a synthetic credential provider, and the real OpenRouter plugin for live Telegram delivery. Live owner revocation hot-reloads the channel, invalidates its pending callback before any key exchange, leaves no OpenRouter profile, and rejects a subsequent non-owner login. Co-authored-by: Ayaan Zaidi <hi@obviy.us> |
||
|
|
b34254154b
|
feat(models): separate provider login from model activation (#144329)
## Problem Models sign-in also runs model setup, which can activate a provider's starter model. Bare `/login` starts OpenAI device authentication before the user chooses a provider. ## Solution Add credential-only provider login in Models and one shared provider menu for chat. Plugins declare optional login choices in their manifests. Core resolves provider and method choices and produces existing command buttons or copyable commands. Bare `/login` always asks for a provider, even when only one is available. API-key and local setup methods remain available through explicit provider commands. `/login codex` retains its device-code flow. The credential-only flow uses the shared persistence and auth-refresh owner from merged #144181. It preserves the selected model, restrictions, concurrent settings and existing account pins. Models publishes the saved credential through the current Gateway context. Cancellation locks at the real persistent-effect boundary; confirmed saves remain visible through later errors. Caller authority is checked at credential and session commits, and disconnected clients cannot finish pending login. Qualified choices reject stale or ambiguous plugin owners. Leaving Models closes its wizard input through the existing close operation and waits for admission to settle. This uses optional `closeInput` on `wizard.cancel`; ordinary cancellation still refuses to interrupt a protected save. Separate pending requests keep page disposal independent of an outstanding Cancel response. The final conflict resolution also preserves the shared refresh outcomes from merged #144436: rejected or unreachable refresh reports saved credentials with recovery guidance. One shared error module carries saved-credential and settings-write failure facts, and the provider-neutral runtime owns completion/failure wording for both chat paths. Channels render core-owned command actions. Provider-neutral recovery replaces the old OpenAI-specific recovery path. OpenAI, MiniMax and xAI declare their supported credential-only choices; methods requiring starter discovery retain setup. ## Impact - No new configuration keys or database schema. - Optional metadata preserves setup for plugins that omit it. - Connecting a provider does not activate its default model. - Chat selection rechecks current owner permission and availability. ## Evidence Original baseline: ` |
||
|
|
efefa622e2
|
docs: fix 20 link defects confirmed live in the verified backlog (#144133)
Mis-pointed targets where a correct target exists, first mentions of documented surfaces that were never linked, and pages with no Related section at all. Adds 57 internal links, none broken. These sat in the ledger's verified bucket, which an earlier round did not have in scope when it reported this category closed. Co-authored-by: Vincent Koc <vincent@openclaw.org> |
||
|
|
e98a5c15f3
|
docs: scope version-locked claims across plugins, platforms, providers, and gateway (#144032)
* docs: scope version-locked claims across plugins, platforms, providers, and gateway
Resolves 78 accuracy-audit rows across five directory batches. Most changes
replace time-relative wording ("currently", "not yet", "previously") with
either a release number established by tag containment or a restatement as a
present-tense limit where no release record exists.
Also marks placeholder identifiers in SDK samples that read as exported APIs,
completes one command sample that was a bare object fragment, and dates two
deprecation notes from the compatibility registry.
* docs(automation): cite the beta tag and its stable release for the SQLite cutover
v2026.5.30 was never released as a stable tag; only v2026.5.30-beta.1 and
-beta.2 exist, and the first stable release containing the migration commit
|
||
|
|
c41730baf0
|
docs: scope version-locked claims in tools and plugins pages (#143982)
Close the open accuracy findings for docs/tools/ and docs/plugins/ that were still valid after the recent page splits. - exec-approvals: date the non-directory-bound generated-entry migration to 2026.8.1 (#129636) - exec: date the sessions.patch execSecurity/execAsk retirement to 2026.8.1 (#132740) - sdk-channel-inbound: date the runtime.channel.turn.* alias removal to 2026.5.27, and state the runPreparedReply compatibility record - sdk-channel-plugins: scope the retainNativeCatalog deprecation to 2026.9.2 from its own @deprecated annotation - sdk-runtime/state-and-system: date the plugin-state lease removal to 2026.8.1 (#121140) - sdk-runtime, sdk-runtime/gateway-and-nodes, sdk-runtime/media, sdk-provider-plugins/{media-and-search,runtime-hooks}: mark caller-owned helpers in samples as placeholders, not SDK exports - sdk-overview/tools-and-commands: make the agentPromptGuidance sample a complete registerCommand call - sdk-provider-plugins/runtime-hooks: state that resolveWebSocketSessionPolicy carries no compatibility-registry record - architecture-internals/provider-hooks: give augmentModelCatalog its 2026-10-01 removal gate from src/plugins/compat - architecture-internals/load-pipeline: complete the activation consumer list with the onAgentHarnesses and onConfigPaths consumers - hooks: replace "before the next major release" with the per-surface compatibility-registry contract - manifest/surfaces: drop the undated "open" proposal status - beam: drop "Current" from the automatic-mirror sentence |
||
|
|
3b61516187
|
docs: fix information-architecture findings in plugins and channels docs (#143926)
Some checks are pending
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pt-BR (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ru (push) Blocked by required conditions
Native App Locale Refresh / Refresh native sv (push) Blocked by required conditions
Native App Locale Refresh / Refresh native th (push) Blocked by required conditions
Native App Locale Refresh / Refresh native tr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native uk (push) Blocked by required conditions
Native App Locale Refresh / Refresh native vi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / publish_plugins_npm (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / warm (linux) (push) Waiting to run
Vitest Cache Warm / warm (macos) (push) Waiting to run
Workflow Sanity / no-tabs (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Structural-only pass over the open `ia` audit rows for docs/plugins/ and docs/channels/. No prose was rewritten; the only content additions are headings, one Related section, and one section index. - channels/whatsapp: group 24 flat H2 sections under four parent H2s (Setup, Access control, Messaging and delivery, Reactions and typing) by demoting contiguous siblings to H3. No sections reordered. - channels/clickclack: add a Configuration H2 so the JSON5/config-keys/ hostname references stop nesting under Quick setup, give the stray plugin-allowlist paragraph its own H3, and add a Related section. - channels/groups: drop the two redirect-only H2 stubs and carry their links into Related; both old ids kept as authored anchor stubs. - plugins/bundles: promote "MCP for embedded OpenClaw" to H2 and its children to H3, removing the H5 depth under "Supported now". - plugins/dependency-resolution: add eight H3s inside "Install roots". - plugins/manifest/setup-and-auth: put the `setup` object table before its child `setup.providers` table. - plugins/google-meet: rename the "Notes" H2 to "Audio bridge architecture" (old `#notes` id kept as an anchor stub) and move "Realtime session health" under it, out of Quick start. - plugins/sdk-overview: move the session-discussion paragraph below the registration table it was interrupting. - plugins/sdk-setup: fold "ClawHub publishing" into "Publishing and installing" as an H3 and add a section index after the intro. - plugins/codex-harness-reference: link the five unlinked config-surface table rows to the child pages that document them. - plugins/architecture: sidebar title "Internals" -> "Architecture". - docs.json: order channels/groups before channels/group-messages, and move plugins/install-overrides into the maintainer reference group. Anchor proof: parseDocsDocument id sets before/after over all 11 changed pages -- 0 ids lost, 0 collisions, 16 ids added. |
||
|
|
fec7692fbe
|
fix(update): finish the update with recorded warnings on recoverable hiccups (#143767)
* fix(update): retain recoverable maintenance warnings Let disposable validation cleanup, retired derived-cache cleanup, and Git tracking setup finish with actionable warnings. Preserve migration ownership, canonical update timing, failed imports, cancellation, and Gateway boot gates. Carry approved Doctor warnings through IPC, progress, and update history. Release-note context: updates finish with recorded warnings for recoverable maintenance hiccups; unsafe or unverified updates still fail. * fix(update): preserve Doctor advisory shape and warning records Keep the existing package Doctor advisory kind/message contract. Carry complete bounded warning records on the update step and forward them through progress into the ledger, preserving each reason and repair command without misusing Doctor IPC diagnostic details. Prove the existing package post-core path and multi-warning history/reporting, including normal exit 0 and explicit advisory exit 86. Hard failures retain their original classification. |
||
|
|
d84f5e8cbd
|
docs(plugins): fix accuracy findings across the plugin docs (#143857)
Closes the open `accuracy` audit findings scoped to `docs/plugins/`, each verified against source before editing. Corrections where the docs understated or misstated the code: - Telephony support listed 2 of 9 bundled providers that implement `synthesizeTelephony`. - `allowInvalidConfigRecovery` named 2 of the 5 recovery cases in `isAllowedPluginRecoveryIssue`. - The `activation-command-hint` row omitted the live `manifest-cli-command-owner` reason. - A `js`/`export default` config example was neither a real config surface nor checked by `check-docs-config-examples` (that fence language is skipped); converted to `json5`, now validated. - `npm:@openclaw/google-meet` skips the official-catalog install plan; the package is in the catalog, so the bare spec is correct. Version scope added only where a release or dated compat record exists: `2026.4.22` (guardian env removal), `2026.5.2` (Meet access-type control), `2026.8.1` (Teams/Zoom live validation), `2026.8.2` (Beam named links), `2026.9.2` (legacy doctor selector), and the dated `removeAfter` records in `src/plugins/compat/`. Elsewhere the time-relative wording is dropped and present behaviour stated, rather than a version guessed. `docs/plugins/plugin-inventory.md` is generated: the fix is in `scripts/generate-plugin-inventory-doc.mts`, regenerated, `plugins:inventory:check` rc=0. |
||
|
|
cf41c606df
|
docs: close remaining one-way link findings in cli, plugins, tools, providers (#143855)
* docs: close remaining one-way link findings in cli, plugins, tools, providers Adds the back-links and anchors that PR #143157 did not cover, and gives two "see below" tables real headings to link to. - Related back-links: cli/tui -> resume, cli/doctor -> status, configuration-reference -> configure, voice-call -> voicecall CLI, onepassword -> secrets CLI, acp-agents-setup -> acpx reference, llama-cpp -> llama-cpp reference, cli/policy -> policy reference, ollama -> LM Studio and Memory LanceDB, image/video generation -> OpenRouter, google-meet -> ElevenLabs, media-understanding -> Mistral, tts service links -> Fish Audio, tools/secrets -> ask_user. - manifest/config-and-secrets: H3 headings for the dangerousFlags and secretInputs detail tables; the two "See below" cells now link to them. - sdk-overview/capabilities: new "Worker providers" heading; the manifest worker-provider contract link now lands on it instead of 36 lines above. - providers/openrouter: the model-list Note pointed at /concepts/model-providers, which carries no OpenRouter catalog; it now points at OpenRouter's own catalog and keeps a separate pointer to OpenClaw model selection. - glossary.zh-CN: 7 sources for the new list-item link labels. * docs(google): link the Gemini CLI runtime tab to the CLI backends page r3-2107. `google-gemini-cli` is the CLI backend id the bundled Google plugin registers, so the tab that configures it should point at the page documenting its argv, JSONL dialect, and session behavior. The Related card alone left the tab itself unlinked. --------- Co-authored-by: Vincent Koc <vincent@openclaw.org> |
||
|
|
b98b1589d3
|
fix(configure): stop Moonshot China auth reinstall loops (#143742) | ||
|
|
a4440c941d
|
fix(update): avoid false Memory Core migration refusals (#143138) | ||
|
|
58394c97dc
|
docs(plugins,providers): close open link-audit findings for plugins and providers (#143021)
Fixes the open `link`-kind audit findings filed against `docs/plugins/` and `docs/providers/`: missing reciprocal "Related" links, one link to a page that moved in an earlier split, one card pointing at the wrong route, and one duplicate card title. Link-only: no prose was rewritten. The one prose-adjacent change wraps existing words in a link (`senseaudio.md` "Voice Call", `nodes/computer-use.md` "Codex Computer Use"). `docs/docs.json` and `docs/.i18n/glossary.zh-CN.json` are untouched. Co-authored-by: Vincent Koc <vincent@openclaw.org> |
||
|
|
c61d773282
|
docs(tools): split the code mode page by reader job (#142425)
The page was 79,412 characters with 43 headings in a flat run of 32 H2 sections, mixing a how-to quickstart, explanation, reference for exec, wait, the guest API, error codes, and telemetry, plus a contributor test plan. It is now an index with eight children, one per reader job. Children: - /tools/code-mode/quickstart - enable it, override one model, recover from tool errors, verify the surface, Swarm fan-out - /tools/code-mode/configuration - fields, automatic per-model activation, the preferred-model list, activation precedence - /tools/code-mode/tool-surface - model-visible tools, exec, wait, the hidden catalog, Tool Search interaction, name collisions - /tools/code-mode/guest-api - guest globals, catalog handles, MCP namespaces, virtual API declarations, paginated file data - /tools/code-mode/output - declared output contracts and the output API - /tools/code-mode/internals - runtime status, scope, terms, nested tool execution, snapshot lifecycle, QuickJS-WASI, TypeScript, security - /tools/code-mode/troubleshooting - error codes, telemetry, debugging - /tools/code-mode/maintainers - implementation layout, validation checklist, E2E test plan Anchor strategy: per-anchor routes are impossible because redirectSource() rejects any source containing [?#]. All 44 pre-split IDs computed with parseDocsDocument stay alive on the parent index instead: 4 remain natively published (what-it-does, why-use-it, technical-tour, related) and 40 became authored <a id="..." /> stubs in a "Where each section moved" list, each linking to the page that now holds the content. The one punctuated heading emits both an encoded and a cleaned ID; both are stubbed. No ID the index still publishes itself is stubbed, so there is no duplicate authored/canonical ID collision. A script enumerated the pre-split IDs and asserted each resolves end to end: 44/44 pass, and the 9 pages report 0 collisions. External deep links such as the CHANGELOG and appcast entries to #guest-runtime-api still land correctly. Losslessness: 43 of 43 section bodies are byte-identical at their destination, and all 23 code fences are character-identical on both info string and body. Words 10,630 -> 11,081, links 18 -> 65, table rows 40 -> 52, fences 23 -> 23; every delta is accounted for by the index's two child tables (12 rows, 8 links) and the 39-entry moved list. The empty "## Quickstart" heading became the quickstart page title, and its five H3 children were promoted to H2 with identical heading text, so their IDs are unchanged. Prose was not rewritten. Five orphaned cross-references were repaired: four same-page fragment links that now point at the child holding the target, and the "Technical tour" signpost, which said "The rest of this page covers" and now says "These pages cover". Six inbound deep links from other docs pages were retargeted at the children. Closes audit findings: r3-0783, r3-0784 |
||
|
|
f7d2fa7402
|
fix(models): preserve authored rows during generated catalog refresh (#142302)
Preserve manual root models during generated catalog refresh and require current authentication for deferred generated inventory. Keep root authorship separate from disposable cache membership, reuse the shared owner/endpoint filter, and consolidate generated-marker detection. Compiled CLI regressions and controls, focused source checks, and independent acceptance verify the behavior. Co-authored-by: Ayaan Zaidi <hi@obviy.us> |
||
|
|
f9ea6dbb69
|
feat(models): scope implicit catalogs to configured provider endpoints (#142158)
## What Problem This Solves
A provider configured with a custom endpoint still advertises native models that the endpoint might not support. A retained generated catalog can also restore native rows or the old native URL during catalog preparation.
This implements the approved endpoint inventory outcome from #136257. Explicit model declarations remain authoritative, including models that reuse native or previously generated IDs.
## Why This Change Was Made
One provider-owned eligibility rule now covers manifest planning, implicit discovery, static preparation and resolution, runtime augmentation, generated catalog reads, and recovery. It reuses the existing normalized URL, declared host/suffix, alias, and native model URL semantics.
Providers without native endpoint declarations keep their discovery behavior. Model-level URL overrides alone do not exclude provider inventory. Shared hooks retain eligible sibling identities. Explicit model definitions, credentials, defaults, aliases, headers, costs, and token settings retain their existing owners.
Recovery and registry reads share the generated-provider filter. Request classification and inventory share the endpoint matcher. Static and authored runtime preparation share the inline-model completion owner. No configuration switch, persistence schema, or request authorization policy is added.
## User Impact
For a proxy under an existing provider ID, declare its supported models in `models.providers.<id>.models`. A nonmatching provider-level `baseUrl` excludes implicit rows, including retained generated rows. Native endpoint configurations remain eligible.
Catalog membership does not prove that a credential or model request will succeed.
## Evidence
- Baseline: `openclaw models list --all --provider deepseek --json --refresh` returned the three published native DeepSeek models at both native and synthetic custom endpoints. The retained baseline build was `e3d987e97d1bb260f0e4937b3b75393df9d3fd99`, from raw CI revision `f12624aed3ee3bf2b67b63db0cc8769fc77d7e45`. Affected catalog owners matched pinned main `
|
||
|
|
9da1f244bf
|
docs(plugins): split the manifest reference by domain (#140504)
The plugin manifest reference had grown to 158,349 characters across 38 H2 sections, mixing model, provider, setup, auth, capability, host surface, config, and packaging metadata on one page. Split it into seven child pages under docs/plugins/manifest/, keeping plugins/manifest as a short index that still carries the whole top-level field table. Children: - plugins/manifest/models - modelSupport, modelCatalog, modelIdNormalization, modelPricing, OpenClaw Provider Index - plugins/manifest/providers - generation provider metadata, mediaUnderstandingProviderMetadata, providerEndpoints, providerRequest - plugins/manifest/setup-and-auth - setup.nativeSessionCatalog, providerAuthChoices, setup, uiHints - plugins/manifest/capabilities - contracts, toolMetadata, activation - plugins/manifest/surfaces - plugin icon and doctorContract, transcriptSources, backupResources, mcpServers, controlUi, dashboard, catalog, cliCommands, commandAliases, qaRunners, channelConfigs - plugins/manifest/config-and-secrets - configContracts, secretProviderIntegrations - plugins/manifest/package-json - manifest versus package.json, discovery precedence Anchor strategy: pointer sections plus authored <a id> stubs on the parent, the pattern already used for gateway/configuration-reference, rather than the per-anchor routes used for web/control-ui. docs.json redirects match on pathname only - redirectSource() in scripts/lib/docs-redirects.mjs throws on /[?#]/ - so no redirect can carry a fragment, and a per-anchor route only helps a link written as a route. Other pages deep-link into this reference with #fragments, so the parent keeps every id alive instead: the new "Where each field is documented" section carries one authored stub per moved id, sitting on the list item that links to the child section that now owns it. Anchor and inbound-link table, produced by script rather than counted by hand: - 49 heading ids exposed before the split; 49 still resolve on the parent after it, with 0 id collisions on the parent or any child - 47 route references to /plugins/manifest across 26 files, 8 of them carrying a fragment; all 8 repointed at the owning child - 6 same-page fragment links inside the top-level field table; the 5 whose target moved were repointed at the child, and #capability-catalogs stayed on the parent Losslessness: - 38 H2 blocks in, 38 out, each assigned to exactly one page - 15,481 words of H2 body before; 2,394 kept plus 13,087 moved after - 33 code fences before; 3 kept plus 30 moved after - 237 documented field rows before and after, 0 lost - top-level field table: 51 rows before and after, in the same order - every section body concatenates back to the original text unchanged Nav places plugins/manifest and its child group directly after plugins/sdk-overview instead of last in the group. No generator emits links into this page. The 151 pages produced by scripts/generate-plugin-inventory-doc.mts and scripts/lib/plugin-inventory-doc.mts contain no /plugins/manifest reference, and the six references in the generated docs/maturity/taxonomy.md are all fragment-free. Prose findings against this page are deliberately deferred so a structural split stays reviewable: r3-0498 (526-word worker-provider paragraph), r3-0499 (49-row prose table), r3-0500 (STE violation rate), r3-0503, r3-0504, r3-0505, r3-1409, r3-1892, r3-1893, r3-1894, r3-2017, r3-2022, r5-0109, r5-0110, r5-0111, r5-0113, r5-0114, r5-0115, r5-0116, r5-0117, r5-0118, r5-0119, r5-0120, r5-0121. r3-0502 is only partly addressed here: the explanation sections now have their own pages, but the runtime hook contracts still need to move to the SDK pages. The zh-CN glossary gains seven entries for the new page titles. Those translations are unreviewed. Closes audit findings: r3-0501, r3-1895 |