Commit graph

1999 commits

Author SHA1 Message Date
Vincent Koc
dff789c0a6
test(e2e): retire obsolete plugin staging smoke (#147555) 2026-09-14 12:30:54 +08:00
Peter Steinberger
f8b194a5be
fix: restore plugin networking under Bun (#147421)
* fix(plugins): normalize network runtimes

* build(plugins): align network runtime dependencies

* test(runtime): stabilize network compatibility checks

* fix(codex): route managed transports through runtime owners
2026-09-13 19:25:19 -07:00
Mohammed Alkindi
659faca280
fix: doctor stays silent when Windows state dir is under OneDrive (#123720)
* fix(doctor): warn when Windows state dir resolves under a OneDrive sync root

Doctor warns when the state directory is cloud-synced on macOS (iCloud
Drive, CloudStorage) and on risky Linux mounts, but stayed silent for
the equivalent Windows case, where OneDrive sync locks, delayed writes,
and Files On-Demand dehydration can make session, credential, and
SQLite state flaky.

Detect OneDrive roots from the OneDrive/OneDriveConsumer/
OneDriveCommercial environment variables the sync client maintains --
canonical roots rather than path-shape heuristics, so ordinary local
folders never match. Comparison is case-folded (Windows filesystems
are case-insensitive) and runs on the realpath-resolved target so
junction prefixes cannot misclassify a local dir.

Closes #98470

* fix(doctor): use Windows shell syntax in the OneDrive recovery hint

The OneDrive warning is only ever shown on Windows, but its recovery
line copied the macOS branch's POSIX form:

    OPENCLAW_STATE_DIR=%USERPROFILE%\.openclaw openclaw doctor

Neither Windows shell accepts inline assignment as a prefix. Verified on
Windows 11: cmd.exe answers "'OPENCLAW_STATE_DIR' is not recognized as an
internal or external command" and PowerShell answers "The term
'OPENCLAW_STATE_DIR=...' is not recognized". Every operator who followed
the hint hit an error instead of a fix.

Emit one line per supported shell instead, both confirmed to set the
variable for the command that follows:

    PowerShell: $env:OPENCLAW_STATE_DIR="$env:USERPROFILE\.openclaw"; openclaw doctor
    cmd.exe:    set "OPENCLAW_STATE_DIR=%USERPROFILE%\.openclaw" && openclaw doctor

The text moves into formatWindowsCloudSyncedStateDirWarning, mirroring
formatLinuxSdBackedStateDirWarning, so the rendered string is assertable
without stubbing platform and filesystem. The guard test greps for the
POSIX prefix shape and fails against the old line.

* fix(doctor): follow a OneDrive junction when the state dir leaf is absent

The detector called realpath on the state dir itself and fell back to the
lexical path when that failed. A state dir that does not exist yet - a
fresh install - cannot be resolved, so a not-yet-created leaf beneath a
OneDrive-named junction that actually points at local storage fell back
to its OneDrive-prefixed lexical path and produced a false warning.

Resolve through the nearest existing ancestor and re-append the missing
segments, which is what the two Linux detectors in this file already do
via resolvePathThroughExistingAncestor. The junction is then followed
even when the leaf is absent.

Adds two tests: the false-warning case, and a guard that a missing leaf
whose ancestor really does resolve inside OneDrive still warns.

* fix(doctor): describe gateway-wide relocation instead of one-shot state-dir hints

* test(doctor): preserve open database families in Windows proof

* test(doctor): identify native state snapshot mismatches

* test(doctor): preserve SQLite data without freezing reader metadata

* fix(doctor): honor selected Windows OneDrive environment

---------

Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>
2026-09-14 01:12:51 +08:00
Peter Steinberger
290613f538
fix(update): derive update budgets from measured state instead of fixed literals (#145219)
Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.

Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.

The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.

The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.

Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.

Refs #144758 #144901 #144890 #143292 #146637 #145252. Preserves the activation boundary from #147019.
2026-09-13 09:41:59 -07:00
Peter Steinberger
a1748139ee
improve: reduce worktree filesystem stalls and archive syncs (#146906)
* perf: consolidate filesystem copy and archive operations

* fix: reconcile fs-safe 0.10 integration checks

* refactor: keep native filesystem execution inside infra
2026-09-13 04:07:17 -07:00
Peter Steinberger
825a904df3
feat(worktrees): share source storage with ReFS clones (#146403)
* feat(worktrees): share source storage with ReFS clones

* fix: correct native output types and TLS sidecar registration

* test(worktrees): handle Windows environment key casing

* test(ui): await catalog refresh publication
2026-09-12 16:33:50 -07:00
Hannes Rudolph
38d95fbbb4
fix(docs): restore publishing without changing existing anchors (#146415) 2026-09-12 14:55:17 -07:00
Peter Steinberger
d13f07b1c2
chore(deps): advance cooled dependencies and major upgrades (#146258)
* chore(deps): advance cooled dependencies and major upgrades

* test(logging): migrate failed-sink regression to tslog 5

* test: retain dependency upgrade coverage within lint limits

* fix(deps): preserve compiler launches, Matrix sync and chat metadata

Keep copied script harnesses independent of declaration modules and preserve
Windows executable prefixes after admission. Audit the Matrix sync guard for
42.3, align CI toolchain/cache pins, and refresh session facts after accepted
model-catalog invalidation without relying on picker timing.

* fix(ui): preserve scoped session reconciliation after catalog refresh
2026-09-12 13:28:12 -07:00
Peter Steinberger
ffa6f5f305
improve: speed up loading long session histories (#146286)
* perf(sessions): reduce history loading work

* fix(tooling): register and trace session history benchmark
2026-09-12 12:02:02 -07:00
Peter Steinberger
e14b3ddac2
improve(memory): keep large-note searches responsive (#146168)
* fix: bound concurrent compute work and pending worker inputs

* fix: supply the host response budget in worker checkpoint tests

* fix: preserve prepared catalog ownership under admission pressure

* improve(memory): keep large-note searches responsive

* fix(memory): preserve worker errors and package boundaries

* docs: separate worker entrypoint guidance

* chore: align metadata extraction with main

* chore: align worker registration for main refresh

* fix(memory): unify metadata reads and worker registration

* fix(memory): preserve overload during index bootstrap and repair
2026-09-12 11:59:24 -07:00
Peter Steinberger
89e54b9d25
fix(agents): release completed liveness join contexts (#146034)
* fix(agents): release completed liveness join contexts

* fix(scripts): avoid returning from liveness proof executor

* fix(scripts): register the liveness retention proof command

* chore: register liveness proof executable
2026-09-12 08:41:12 -07:00
Hannes Rudolph
2227743f74
refactor: split release changelogs and synchronize docs mirrors (#145464)
* refactor: split release changelogs and synchronize docs mirrors

* fix: complete split changelog instructions and validation wiring

* fix: complete release changelog mirror integration

Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver.

* test: align docs agent Git ownership fixtures

Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 21:19:18 -07:00
Peter Steinberger
6f1185305d
chore(deps): advance cooled TypeBox, AWS and Copilot SDKs (#145381)
* chore(deps): advance cooled TypeBox, AWS and Copilot SDKs

Update six direct package targets after the frozen 2026-09-04T22:10:05Z seven-day cutoff. All 15 new resolved artifacts match registry integrity and publication-age requirements.

Keep TypeBox pins and plugin examples aligned, and describe Copilot SDK native runtime packaging accurately. Regenerate the Workboard asset references with the updated graph.

Validation: independent P0-P2 review clean; live S3-compatible signed upload/readback/delete passed. Remaining full checks and Copilot live proof run in an isolated Testbox after local dependency-store loss.

* test(copilot): handle the SDK session detach handshake

Keep the held cleanup boundary and all cancellation and host-lifetime assertions while answering session.detach with success. The previous fake session.destroy handler left the real SDK test waiting until its deadline.

* fix(ui): clean up environment picker validation gates
2026-09-11 20:15:55 -07:00
Peter Steinberger
f89fa78584
feat(radius): connect models with browser sign-in and native streaming (#145377)
* refactor(channels): simplify progress rendering ownership

Keep visibility in the compositor and remove redundant mode flags from internal layout helpers. Separate Slack attention-title formatting from native approval task identity construction, avoiding discarded hashes and task objects in Block Kit rendering.

Preserve public SDK and output contracts. Remove one duplicate test left after native start/update builder unification. Related: #145345, #140037.

* fix(ui): let the popover own initial picker focus

WebAwesome already focuses the autofocus input before the opening animation. Remove the duplicate after-show focus that stole focus from a newly opened cloud configuration card. Replace the handler-only unit expectation with a deterministic browser regression that controls the actual animation and preserves initial focus, cloud focus, and machine selection.

* feat(radius): add native model provider and browser sign-in

Support Radius organization API keys and device OAuth, discover account-visible models and tiered prices, and stream native Pi messages through the provider plugin contract. Add setup docs and meaningful auth, catalog, and tool-stream coverage. Regenerate the standard plugin config inventory for the new provider.

* refactor(radius): satisfy provider validation guards

Require captured OAuth and model requests in strict test types. Project optional stream fields directly while preserving validation of supplied values. Focused tests and independent review pass.

* fix(radius): accept live fractional OAuth polling intervals

Radius device authorization advertises interval=0.1 seconds. Accept finite positive fractional intervals and round milliseconds upward; retain expiry and timer bounds. The regression failed against the original parser and all 20 OAuth tests now pass. Live pairing reaches browser authorization.

* fix(radius): publish native model routes and resolve cold starts

Declare pi-messages in the shared API data contract and emit it from authenticated Radius catalogs before registry validation. Resolve cold-start models through the existing provider hook using the same account catalog and pinned auth profile. Remove late normalization hooks and cover real registry deserialization, schema admission, and account-scoped resolution. Live authorization and catalog discovery pass; inference reaches Radius and reports the account billing gate.

* build(radius): integrate plugin publication and documentation metadata

Document the plugin package, exclude its external dist tree from the core npm package, and update extension label routing and the exact release inventory. Regenerate the plugin inventory/reference pages and brand glossary entries. Publication/build-selection and labeler coverage tests pass.
2026-09-11 19:29:25 -07:00
Peter Steinberger
aa0ad4c780
feat(sessions): automatically archive older transcripts (#145172)
* feat(sessions): automatically archive inactive transcripts

Add opt-in worker maintenance, live storage settings, and exact restoration from compressed JSONL archives. Advance the agent schema to 20 and embed verified cold payloads in supported backups.

* fix(sessions): preserve cold history across reads and lifecycle actions

Restore archived history before channel context, latest-text reads, reset and fork operations. Preserve legacy schema migration preflight and steering transcript order; regenerate native protocol bindings and repair the Windows cleanup fault fixture.

* fix(ci): regenerate plugin assets and rebalance cold storage tests

* fix: harden updater validation and account selection
2026-09-11 16:50:58 -07:00
Peter Steinberger
cd6fe8252e
chore(deps): refresh seven-day-cooled npm dependencies (#145124)
* chore(deps): refresh seven-day-cooled npm dependencies

Update 64 direct dependency targets and six pinned transitive targets using
registry publications on or before 2026-09-04T16:49:00Z. Verify publication
timestamps and registry integrity for all 164 newly resolved versions.

Deduplicate compatible resolutions so CodeMirror shares one state instance.
Retire expired cooldown exclusions and Mailparser's redundant security
scopes, retaining Mailauth's fixes at its new parent version. Synchronize
Claude ACP fallback assertions, plugin examples, and generated Workboard
asset metadata. Preserve patched packages and intentional migration holds.

Build, repository-wide formatting, 627 SDK/schema tests, 3613 plugin tests,
142 native/terminal/ACP tests, and independent P0-P2 review passed. Final
changed checks, browser editor proof, and exact-head CI are tracked in the PR.

Closes #145096

* test(tui): complete updated overlay handle fixtures

* fix(diffs): retain read-only types with updated renderer

* fix(validation): retain compact TypeBox rejection diagnostics

Normalize complete boolean child groups immediately before their matching
additional-property aggregate at the shared JSON-schema owner. Preserve
unrelated failures, literal-path collisions, typed/nested property errors,
truncated lists, and original error object identity. Both normalized-error
producers use the helper; validation decisions remain unchanged.

Use one oversized property in the Codex truncation regression so the test
continues exercising its original bound under TypeBox's new error layout.
Keep all rejection and non-execution assertions. Remove one unnecessary
validation-error cast and shrink its assertion ratchet accordingly.

The original Gateway assertions, 342 owner and sibling tests, native type
checks, targeted lint, and independent P0-P2 review pass. A real collision
regression failed the initial implementation and passes with ordered groups.
2026-09-11 14:29:57 -07:00
Peter Steinberger
212f04188a
fix(update): preserve compatible state when switching to npm stable (#144155)
* fix(update): initialize fresh profiles with the selected runtime

Let the staged target initialize compatible state before admitting update history, while retaining executor ownership and existing-state downgrade protection. Preserve read-only previews, owned service selectors, legacy schema metadata, and interruption guards. Reject changed stored channels before adopting their config snapshots.

Refs #144132. Verified ten npm stable targets on isolated Testboxes, existing-state refusals, real systemd startup, and focused red-to-green regressions.

* fix(update): preserve admission and finalization contracts

Reject contradictory native service selectors before fresh state or package
metadata selection, and unwind already-published fresh refusals through the
canonical CLI exit boundary after ownership settles.

Use the synchronous Kysely boundary for interruption metadata inspection.
Align existing-profile and continuation fixtures with their real database,
package version, Gateway version, and control-store ownership. Preserve
legacy fallback, rollback, service lifecycle, and no-op assertions. Document
that fresh previews do not create history.

Related to #144132.

* fix(update): close fresh-admission and control-store races

Publish the existing shared update-control database only after its private
schema and permissions are complete, preserving original authority and
single-link recovery checks. Select fresh initialization from actual state
and keep inherited diagnostic IDs consistent across executor and history.

Preserve current-main update ownership and completion behavior. Repair the
skill-environment detector with source dataflow and scoped validated rule
regeneration, and align regression fixtures with the current runtime and
package integrity contract.

* fix(update): preserve sealed managed handoff startup

Prepare the control database through its existing owner before staging the
standalone helper, then bind the helper to the captured existing identity.
Revalidate before spawn and keep publication dependency resolution lazy so
sealed runtime loading never depends on installation packages or native code.

Register the static OpenGrep fixtures as external Knip inputs. Keep the
Gateway test's synthetic parent alive until its native stop boundary,
preserving notice ordering and production authority checks.

* fix(update): publish control databases with Windows durability

* fix(update): retain executor ownership during service recovery

* fix(update): initialize control storage without optional native bindings

* test(update): align platform and merge workflow fixtures

* test(update): verify settled children and isolate deletion timing
2026-09-11 13:56:09 -07:00
Peter Steinberger
05a2844d39
refactor: keep plugin work and cleanup owned during retirement (#144252)
* refactor(plugins): retain code and cleanup through retirement

* fix(plugins): release cached publications when their owners retire

Release idle prepared publications at registry and metadata-cache retirement while retaining admitted borrowers and surviving Gateways. Resolve late local imports from captured packages and align lifecycle fixtures with their owning contracts.

* fix: preserve plugin loader startup ownership

* fix: retain explicit SDK preference for Bun plugins

* fix(plugins): preserve rebased startup and build contracts

Prepare runtime SDK output for both startup corpora, preserve exact released update-bridge provenance, and share hosted runtime prerequisites within the existing serial budget. Remove the redundant packing pass and isolate the timing fixture from unrelated suite growth.

* style: simplify foundation CI fixtures

* fix(plugins): preserve SDK readiness and startup cleanup

Recognize authorized built relative SDK imports before asynchronous linking so published CJS plugins can synchronously load the same host SDK graph. Bind dashboard preparation to Gateway drain and declare the package-runtime test build prerequisite.

Validation: scoped P2 review clean; 51 loader tests and 602 package/planner tests; published 2026.9.3 upgrade-survivor replay passed; configured TypeScript upgrade, fresh TypeScript startup, and CLI-managed JS/CJS upgrade each passed two RPCs, health, exactly-once service cleanup, and natural exit with unchanged shutdown grace. Runtime/UI/metadata rebuilt; full hosted CI still required.

* test(pr): model GitHub commit authors in merge fixtures

Current main verifies human contributor credit through per-commit GitHub metadata. Return the synthetic repository commit author and unlinked account status, and include the requested PR author type, so the real merge workflow can exercise that contract.

Validation: both original merge-ref failures reproduced before the fixture repair and passed afterward; all 16 selected tooling checks passed; focused P2 review is clean. No production code changes.
2026-09-11 13:42:35 -07:00
Peter Steinberger
3acd5c945a
fix(update): let large candidate snapshots finish (#144901)
Updates with large SQLite state no longer fail at the hidden five-minute candidate snapshot clamp. The openclaw update snapshot owner budgets copying and verification by database size and observed progress, while preserving the configured runtime validation budget.

Select system temporary or state-local storage with capacity for a private snapshot, retain nested SQLite diagnostics, and report failed Gateway restarts accurately. Keep the conservative capacity estimate: copying fails before live mutation when storage is insufficient.

Fixes #144858. Thanks @Baumus for reporting the timeout defect.

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-11 11:49:45 -07:00
Peter Steinberger
505c7c7917
fix: preserve executable files in pnpm package archives (#145042) 2026-09-11 09:01:36 -07:00
RoboClaw
c677baebc9
chore(release): close out 2026.9.4 on main (#144708)
Forward-port the shipped updater, Doctor, schema, and skill snapshot fixes.
Align package metadata and the exact tagged release notes without changing
mobile release versions or any published artifact.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-09-11 18:46:37 +08:00
Alix-007
1b2b06ed2f
fix(memory-wiki): ignore directories during Obsidian CLI discovery (#144681)
## What Problem This Solves

Fixes an issue where `openclaw wiki obsidian status` reports Obsidian as available when PATH contains a searchable directory named `obsidian`. That directory can also hide a valid executable later on PATH.

## Why This Change Was Made

Keep the existing access check and require the resolved target to be a regular file. This rejects directories and directory symlinks while preserving executable-file symlinks and discovery order. Register the new filesystem tests in the existing Windows CI inventory so PATHEXT behavior runs there.

## User Impact

Memory Wiki finds a later executable when an earlier PATH entry contains a same-named directory. Availability probing still does not execute Obsidian.

## Evidence

- Real CLI baseline on main `1685e53b06`: directory-only, directory-shadow, directory-symlink-only, and directory-symlink-shadow cases returned the wrong availability or command.
- Native Linux candidate `3c7e9d6df1f1` (pinned main plus this repair): all 10 public CLI cases passed, including file symlinks, PATH order, non-executable files, dangling links, empty PATH, and permission errors. No marker executable ran.
- Fresh independent public CLI acceptance: all 16 cases passed, including relative and absolute file symlinks, reversed PATH order, and explicit `EACCES` controls.
- Regression tests on the original owner: 3 expected failures, 5 passes, 1 Windows-only skip. Repaired owner and publication source: 10 passes, 1 Windows-only skip. Focused Gateway/status coverage: 8 passes; 51 unrelated cases filtered out.
- Native formatting, focused lint, and the normal pre-commit hook passed. Source review confirmed preserved timeout/error handling and no new config, schema, dependency, or persistence policy.
- The Windows-only PATHEXT test is registered in `test:windows:ci:1`; final hosted checks remain required before landing.

The public runtime build and publication head are recorded separately. The affected discovery, CLI, Gateway, status, config, and process owners match; the additional publication commit only registers the Windows test.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-11 11:25:17 +05:30
Erick Kinnee
99a3f5152a
fix(plugin-sdk): expose focused async embedding batch contract (#129625) 2026-09-10 17:06:43 -07:00
Peter Steinberger
05963f8b5e
fix(runtime): re-exec under an available supported Node before refusing (#143464)
* fix(runtime): reuse an available compatible Node at startup

Share startup recovery between the launcher and legacy CLI runtime admission
so older updaters can run target Doctor through dist/index.js under an
already installed compatible Node. Preserve process-contract exclusions,
arguments, environment, standard streams, and exit status.

Refs #140465

* test(runtime): include recovery proof in E2E routing

* fix(runtime): secure Node discovery and decode service scripts

Reject relative candidates and cwd-resolved runtimes before probing, except
for explicit absolute PATH directories. Parse generated Windows command
quoting and recorded code pages without loading application dependencies.

Skip CP850 and CP949 with a diagnostic instead of guessing executable paths.
Use real task-writer fixtures for encoding, quoting, and fallback coverage.

Refs #140465

* fix(runtime): reject cwd-local manager symlinks

* test(runtime): keep recovery home outside launcher cwd

* fix(runtime): isolate recovery from dotenv environment

* fix(runtime): canonicalize discovery paths before use

* fix(runtime): preserve private Node recovery from home

* refactor(runtime): trim Node recovery comments and aliases

Behavior-neutral cleanup of the recovery launcher module: fold the serviceHome and managerHome aliases into homeDir and shorten five comment blocks to the invariant they protect.
2026-09-10 01:35:39 -07:00
sloptop
43e9b70c47
fix(infra): report actual workspace write failures (#116378)
Report permission, read-only filesystem, and disk-space failures through the shared bounded-write facade while retaining structured error codes and original causes. Keep the dependency's original root handle and route the public SDK helper through the same diagnostic behavior.

Closes #115920.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-10 12:23:40 +05:30
Ayaan Zaidi
41aec3ca92
feat(deepgram): support Flux voice-note transcription (#141836)
Closes #129452.
Replaces #129442 and preserves Safzan Pirani's original Flux contribution.

## Problem and fix

Selecting `flux-general-en` or `flux-general-multi` sends voice-note audio to Deepgram's prerecorded HTTP `/v1/listen` endpoint, which rejects Flux. This change routes those models through the streaming `/v2/listen` protocol. Operators use their existing media model settings; Nova remains the default. Flux requires `ffmpeg`.

The Deepgram plugin owns bounded audio conversion, frame pacing, protocol parsing, and transcript assembly. The shared WebSocket connector applies resolved authentication, private-network policy, proxy routing, and TLS settings. One connection deadline covers DNS preparation, proxy CONNECT, and the opening handshake; Flux keeps its original transcription-attempt deadline after preparation. Cancellation and socket closure release pending connections.

Proxy connections use the existing shared Node agent backed by `@openclaw/proxyline@0.3.12`. [Proxyline #34](https://github.com/openclaw/proxyline/pull/34), now merged, adds prepared proxy DNS/TLS connection options while preserving its existing pending-socket ownership. OpenClaw passes these through `createNodeProxyAgent(...)`; it does not retain a separate proxy-agent implementation or add `https-proxy-agent` as a direct dependency. Proxy TLS and target TLS remain separate.

Configured proxies retain resolved target-address checks before connection. Applicable managed and ambient HTTP(S) proxies retain their existing DNS delegation. `NO_PROXY` bypasses and `ALL_PROXY` alone do not disable address checks. HTTP and WebSocket paths share the managed-proxy predicate.

The query builder combines saved language and explicit query inputs before applying [Deepgram's model contract](https://developers.deepgram.com/reference/speech-to-text/listen-flux). Only `flux-general-multi` receives `language_hint`; explicit query values keep their precedence. The English-only model ignores both language inputs without requiring changes to saved settings.

The documentation follows main's split-page structure: request policy is documented on [Custom providers](https://docs.openclaw.ai/gateway/config-tools/custom-providers), and connection ownership on [Provider voice capabilities](https://docs.openclaw.ai/plugins/sdk-provider-plugins/voice-and-audio). The Deepgram manifest keeps main's categories and the Flux description. No configuration keys or storage changes are added.

## Canonical transport evidence

These results cover the retained compiled candidate with the canonical Proxyline implementation. They are not claims about a newly installed or rebuilt merge head.

- Independent public CLI acceptance saved and read back all four combinations of the two Flux models with either top-level `language: "en"` or `providerOptions.deepgram.language_hint: "en"`. Each ran `openclaw infer audio transcribe --file sample.wav --json` without model or language overrides, returned the expected “Life moves pretty fast” transcript, and exited 0. The original model configuration was restored and verified.
- A saved Nova configuration and a post-fault Flux control returned the expected transcript and exited 0.
- A configured proxy with private-network access explicitly denied produced a visible target-address rejection and exit 1, with no CONNECT admissions, no target connections or bytes, and no remaining proxy connections.
- A stalled CONNECT produced a visible transcription timeout and exit 1 without forced termination. Both admitted connections closed before the CLI exited; zero connections remained. This records two attempts, not a one-second deadline for the whole CLI invocation.
- A successful real-provider transcription through an HTTPS proxy recorded certificate verification enabled, the explicit server name, an authorized client certificate, CONNECT to the intended provider, 570,755 bytes forwarded upstream and 47,863 downstream, and complete peer cleanup. Verification mode was observed from the operator configuration; this public acceptance did not independently inject an invalid server certificate.
- Focused canonical tests passed: 136 WebSocket/HTTP address-policy tests, 3 shared Node-agent tests, and 37 Deepgram tests. Proxyline's 11 connection-control tests passed, including prepared lookup/TLS settings and Node certificate-verification defaults. The retained runtime build, formatting, lint, and documentation checks also passed.
- Proxyline's upstream review and Linux/macOS/Windows, package, and CodeQL checks passed before merge. Its published `0.3.12` package has been inspected: `src` and `dist` are byte-identical to the tested package. Registry metadata identifies release commit `46a8aa2e3c4b8fbed5fc3ccc16a4631cb7ca3d24` and includes package provenance.

## Regression evidence retained

- On baseline `8954f104fb`, the compiled public command failed with HTTP 400 `V2_MODEL_ON_V1_LISTEN_ENDPOINT` and exit 1. The repaired command returned the expected real transcript.
- Five deadline/cancellation cases failed before repair and passed afterward, including socket termination during pending proxy CONNECT. Both English-only language-input cases also failed before their query repair and passed afterward.
- Before the address-policy repair, the forbidden-target fixture received one connection and 1,600 TLS handshake bytes. After repair, it received zero connections and zero bytes. The canonical acceptance above repeats the repaired denial through the public CLI.
- Earlier broad media validation passed 354 tests across 26 files. Earlier SDK surface and import-cycle checks passed. A missing-file public CLI control produced a visible error and exit 1. These are historical coverage, not fresh merge-head results.
- An explicit `undefined` query value exposed by test-type CI was corrected by omitting absent fixture keys. The 11 Flux tests passed afterward; that correction did not change production code or live-proof inputs.

## Review and merge status

The latest ClawSweeper review of `550a7f60d612b1f19efcaec9b94112cf76338931` found no actionable code defect and requested dependency authorization, conflict resolution, and branch readiness. Its suggested direct `https-proxy-agent` addition is superseded by the canonical Proxyline repair above. The existing Proxyline dependency is updated to the published `0.3.12` release; any repository-enforced dependency approval must cover the eventual head.

The maintainer approved an exact-version release-age exception for `@openclaw/proxyline@0.3.12` through **2026-09-15 10:08 UTC**. This exception does not relax the policy for other packages or versions.

The integration preserves main's documentation moves and both manifest fields, and regenerates the config-help digest from the combined inputs. Main leaves the Flux runtime, WebSocket connection owner, and proxy helpers unchanged. Its shared HTTP capture changes require current HTTP integration evidence, including the saved Nova control.

The integrated tree passes a frozen install from the published registry, formatting, targeted lint, generated config and plugin inventory updates, and a fresh compiled CLI build. Fresh tests passed: 138 WebSocket/HTTP address-policy cases, 18 Deepgram cases, and 13 HTTP capture-release/shared-agent cases. A real saved `nova-3` CLI transcription returned the expected sample text with exit 0. The initial direct test configuration excluded the capture-release file; the canonical test router then ran all 13 cases successfully.

Relative to pinned main `412755bd5c`: production TypeScript +559 net, plugin manifest +13, tests/support +714. The growth implements the missing Flux streaming protocol, bounded conversion/transcription, and generic guarded WebSocket transport. Proxyline itself removes 15 net production lines by unifying the proxy dialers. Final exact-head review and CI remain required.

## Separate follow-ups

- The existing HTTP dispatcher maps explicit provider proxy TLS settings to the target TLS hop. The documented settings describe the proxy hop; this WebSocket implementation applies them there. The HTTP mismatch predates this change and needs its own reproduction and repair.
- The CLI's existing `--model` argument does not override an explicit media-model list. Acceptance selects Nova through saved configuration; override semantics remain a separate follow-up.
- Historical [CI run 34193953000](https://github.com/openclaw/openclaw/actions/runs/34193953000) passed test types, browser-extension end-to-end checks, and the other selected children, except [Control UI shard 3](https://github.com/openclaw/openclaw/actions/runs/34193953000/job/101957740234). Its image-handoff failure also reproduced on the exact main parent `64656c24fa` with the same 67 selected files; the standalone case passed. The mocked image scenario does not invoke Deepgram. This is historical evidence of an unrelated failure, not a result or blanket CI exception for the new head. Nine missing-video-encoder errors in that probe were excluded from the recurrence evidence. The earlier [selected-tab browser failure](https://github.com/openclaw/openclaw/actions/runs/34192553828/job/101953552659) remains a separate browser-lifecycle follow-up with its cause unproven.

AI-assisted repair.

Co-authored-by: Safzan Pirani <5602916+safzanpirani@users.noreply.github.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-10 09:45:11 +05:30
Peter Steinberger
411ea27d9a
feat(workers): reuse completed project setup across cloud sessions (#143227)
* feat(workers): reuse completed project setup across cloud sessions

Prepare project setup and runtime at stable workspace and HOME paths before capture. Bind completed environments to one session, preserve edits on restart, and refresh compatible commits while retaining unrelated caches. Apply the approved complete schema 17 contract; keep ready-pool allocation and repository-only admission separate.

Preserve landed upload cancellation, checkpoint outcomes, manifest gzip, and canonical Windows Git configuration. Recover capture requirements after completed setup is replayed following a crash, using existing allocation state. An interrupted warm reuse before enrollment may conservatively capture once more.

Final integration passed 305 focused tests, the full changed gate, and scoped P2 review, with earlier broader and cross-process proof retained. Fresh installed-package and native AWS session qualification are pending; no cloud latency claim yet.

* fix(workers): retain explicit dedicated host classification

Preserve a provider's explicit sharedHost=false result through lease normalization so prepared workspaces can register on dedicated nodes. Keep shared and unspecified hosts rejected by the existing admission guard.

Cover the actual service creation and parser boundaries, document the provider contract, and align existing dispatch, schema migration, Doctor, and native reader fixtures with the prepared-workspace change. Upgrade-survivor checks retain the exact candidate schema from its admitted tarball instead of assuming the published package's older schema.

* test(ui): wait for image custody before advancing handoff

The absence of an error-only send status does not show that custody was established. Wait for the canonical metadata request while the send acknowledgment is held, preserving the original image handle, pixel checks, and frame continuity assertions.

* fix(workers): preserve setup output during initial prepared sync
2026-09-09 17:13:44 -07:00
Peter Steinberger
bf6f74b280
fix(runtime): gate node:sqlite on a NUL round-trip capability probe (#143312)
* fix(runtime): gate node:sqlite on a NUL round-trip capability probe

Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465 #140672.

* fix(runtime): expose capability diagnostics through doctor

Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.

* fix(update): preserve target Node version requirements

* fix(install): remove unused Node major probe state
2026-09-09 13:32:29 -07:00
Jason O'Neal
cec6d16175
feat: offer Node.js updates when the CLI runtime is incompatible (#142742)
* feat: offer Node.js updates when the CLI runtime is incompatible

* fix: include Node runtime recovery in duplicate scans

---------

Co-authored-by: Morrow <morrow@bluedot.it.com>
2026-09-09 10:56:55 -07:00
Peter Steinberger
62ce554723
feat(tui): answer agent questions in gateway and local modes (#143273)
* feat(tui): answer agent questions in gateway and local modes

Render session-owned questions with choices, Other, multi-select, a stepper,
Skip, expiry, and /question. Restore pending prompts after reconnect and
session changes, and keep masked input outside the composer and history.

Serve local questions through QuestionManager and claim eligible replies
before queue policy so answers cannot wait behind their blocked run.
Keep local secret-store requests blocked with explicit setup guidance.
Recover uncertain resolutions without replaying input and surface saved
secret refresh failures without exposing submitted values.

Validation: 1,893 focused and sibling tests; 102 PTY tests; isolated Gateway
and local scripted-model round trips; full build; check:changed; docs checks;
independent P0-P2 review. The broader docs anchor audit reports three existing
broken links in untouched generated maturity pages.

* fix(ci): register the TUI question proof command
2026-09-09 10:53:00 -07:00
LightningWare LLC
faaf4b0fbd
fix(anthropic): preserve cache reuse across transient runtime context (#140621)
Anthropic tool loops could repeatedly write growing conversation history to the
prompt cache because a moving runtime-context carrier owned the checkpoint.
Use the existing replay lifecycle contract to exclude transient carriers from
both request builders while preserving retained anchors. Also omit empty beta
headers that caused direct API requests with thinking disabled to fail.

Add deterministic regression coverage and a packaged Docker test that verifies
real cache reads and incremental writes across two tool continuations and a new
user turn in both builders. Require that lane in stable/full release validation,
with explicit API-key preflight, no request retries, and a declared runtime entry
for dependency analysis.

Validation includes focused package/model/session and workflow tests, build and
package integrity checks, static checks, independent review, mock Docker, and
eight successful live Anthropic Docker requests. Hosted CI run 34379052492 passed
on the final PR head at attempt 2, after one unchanged browser-animation rerun.

Closes #140607

Thanks to @LightningWareLLC for reporting the regression and contributing the
lifecycle-aware cache repair.

Co-authored-by: LightningWareLLC <271410939+LightningWareLLC@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-09 10:35:56 -07:00
Peter Steinberger
05bf4e050b
fix(update): keep old updaters able to restart the Gateway (#142195)
* fix(update): preserve old updater imports across package swaps

* chore(build): keep compatibility inventory types private

* test(build): preserve generated compatibility artifacts in fixtures

* test(build): include recorded bridges in source runner fixtures

* test(build): consolidate compatibility coverage under postbuild

* fix(update): cover the supported updater compatibility window

* fix(update): resolve compatibility exports with ESM semantics
2026-09-08 10:43:46 -07:00
Peter Steinberger
58fcf69cad
chore(release): close out 2026.9.3 on main (#142240)
Align root, native source, plugin and companion version metadata with the published stable release. Preserve newer main code and translations, regenerate the channel catalog, and copy the exact tagged release-note section without adding another release train. Native appcast and locale refreshes remain with their independent owners.
2026-09-08 09:39:38 -07:00
Peter Steinberger
299ea7c393
fix(scripts): run macOS tooling under /bin/bash and make the framework-merge fixture self-contained (#141884)
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures

Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.

Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.

* fix(scripts): keep guarded portable scripts bash 3.2 compatible

* fix(scripts): keep macOS Bash CI coverage green

Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.

Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.

* docs(install): use system Bash in install and recovery commands

Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.

Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.

* fix(scripts): preserve streamed installs and CI packing

Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.

Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.

Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
2026-09-08 01:21:30 -07:00
Dallin Romney
0d25c9b48f
refactor(npm): use pnpm override parser (#141862) 2026-09-07 22:13:16 -07:00
Peter Steinberger
62395281ff
fix(tooling): prevent accidental shared dependency installs (#141719)
* fix(tooling): prevent accidental shared dependency installs

Stop creating implicit checkout-root dependency links during tool bootstrap.
Refuse default pnpm reconciliation through borrowed roots before linking,
while preserving explicit hydrated aliases, existing read-only borrows,
and configured-to-local toolchain fallback.

Include the early guard in package files and document its checkout-root
scope, lifecycle bypasses, and concurrent-path limits.

Validation: 127 focused Linux tests, seven real pnpm install cases,
packaged-root command proof, full checks plus final scoped loader checks,
and independent P0-P2 review.

* fix(tooling): audit install hook and align bootstrap coverage

Include the dependency ownership guard in the exact install lifecycle
contract and dependency fingerprint inputs so CI admits the hook and
invalidates cached dependencies when its implementation changes.

Update the existing wrapper expectation for the intentionally removed
implicit primary-checkout borrowing path while retaining hydration proof.

Validation: reproduced both failures, 517 workflow guards (2 existing
skips), 98 bootstrap/ownership tests, full scoped Linux checks, and
independent P0-P2 review.

* test(tooling): align isolated harness and routing contracts

Provision the copied Docker harness's TypeScript package explicitly and
update the preflight diagnostic and dedicated shim test routing expectations.

Validate compact tooling runner capacity from each resulting group's compiler
membership, preserving all file-policy and negative mutation checks without
freezing incidental compiler co-tenants onto a larger runner.

Validation: all 604 affected Linux tests, complete scoped checks, original
failure reproductions, planner inventory attribution and independent P0-P2
review. No production dependency or capacity policy changed in this follow-up.

* test(tooling): keep bootstrap cases in the runtime owner suite

Preserve all eight bootstrap cases and fixture logic in the existing local
runtime suite, with scoped environment cleanup and precise test routing.
The standalone filename fragmented the integrated GitHub compact plan into
81 jobs; the actual consolidated merge fits all three plans within80.

Keep the cap, estimates, compiler capacity, assertions and test coverage.
Validation: identical moved AST/token bodies, 571 local tests, 624 integrated
Linux tests and full scoped checks, exact merged planner proof, and clean
independent P0-P2 review.
2026-09-07 20:09:36 -07:00
Peter Steinberger
fb57c742b4
improve(tests): reject failed native CLI fixture runs (#141423)
* test(node-host): assert native CLI fixture completion

Use the current Node runtime for synthetic CLI scripts and require native
auth fixtures to complete successfully, not merely print expected output.
Preserve descriptor, environment, Git-instruction and cancellation checks;
strengthen the existing stdin result assertion without duplicating it.
Register the suite in the existing Windows CI inventory and routing case.

A real-child mutation emitting expected output before exit17 passes the
old assertions and fails the strengthened case. The fault is removed;
64 focused cases, changed checks and isolated P0 review pass.
No production change or measured startup-speed claim.

Related: #132180 (node-session split series), original group L.

* test(node-host): respect native fixture platform contracts

Give Windows approval tests a real native executable fixture while keeping
POSIX on its installed Node runtime and valid script path. Do not change
PATHEXT, production approval policy, or native library lookup settings.

Observe the actual supervised timeout result through the existing seam.
Preserve its native exit code, applying124 only when absent, and retain
strict timeout classification, diagnostics, failure and error assertions.
This matches the existing stable-release contract rather than changing
production normalization to satisfy a POSIX-only expectation.

64 local cases and required checks pass on the corrected tree; isolated
P0 review is clean. Updated Windows CI remains required.
Related: #141423 (native CLI fixture reliability), #132180 (split series).
2026-09-07 13:28:38 -07:00
Peter Steinberger
fea46682a9
feat(macos): open links as native Mac tabs in the Browser panel (#140988)
* feat(macos): host native browser tabs in the Control UI Browser panel

* fix(browser): generate native Inspect script from UI source

* fix(ui): satisfy native browser panel lint contracts

* fix(macos): drain Mach-O classification output during packaging

Avoid SIGPIPE from grep exiting early under pipefail, which could skip a universal framework and drop its secondary architecture. The existing packaging suite passes all 85 tests.

* chore(ui): verify native browser localization baseline

Run the keyless baseline and deterministic verification. The 79-entry raw-copy baseline is unchanged; locale metadata and translation memory remain untouched.

* refactor(macos): consolidate reading tabs in the Browser panel

Remove the split sidebar and its width persistence. Route legacy inline links to the default browser, reuse current URLs and retained redirect aliases through returned native tab IDs, and preserve popup, focus, cookie-store, and window lifecycle ownership.

* docs(macos): describe native Browser panel tabs

* Revert "fix(macos): drain Mach-O classification output during packaging"

This reverts commit 259c9a508b280ca1c05ee02def96ae92df7e9100.

* docs: keep the 2026.9.2 release notes unchanged

* fix(macos): resolve native Browser panel review findings

Require pointer-activated main-frame navigation before handing a native
non-displayable HTTP(S) response to the default browser. Record activation
per tab and consume it at response time through a pure response policy.

Discard native captures and stale inspection replies when the captured URL
changes. Let explicit tab selection supersede pending open activation,
including replies that reuse an existing tab. Update the Browser docs.

Regression proof: six new UI cases failed before the fixes, then passed;
the extracted original Swift response policy failed three disallowed cases.
Focused UI tests, pure Swift contracts, app/test builds, and Swift checks pass.

The branch-wide changed gate is blocked by the existing hoisted dependency
layout: UI @noble/hashes resolves into extensions/reef/node_modules, violating
the core tsgo graph boundary. The workspace requires an isolated linker.

* fix(ui): clear the Browser panel address after the last Mac tab closes

* fix(ui): keep the Browser panel working on insecure origins without crypto.randomUUID

* fix(ui): keep a superseded new-tab request from clearing the selected address

* fix(macos): keep pending opens and blank new tabs distinct in the Browser panel

* test(ui): stub getRandomValues deterministically for the insecure-origin panel case

* test(ui): follow the Browser panel native link contract

* refactor(ui): break the Browser panel controller import cycle

* test(macos): wait for the dashboard document before posting the legacy inline link

* test(macos): drop the page-driven legacy inline link smoke test

The dashboard document never finishes loading on the hosted macOS runner, so the test could not post its message; the inline-to-external mapping it covered is a one-line switch in receiveLinkMessage.

* fix(ui): keep native Browser tabs off the live screencast

Carry the live stream into the extracted remote snapshot and viewport owners,
behind the native-tab capture guard. Preserve frame ownership, screenshot
fallback, resize restarts, and teardown on selection and suspension.

Prove native-to-remote-to-native selection, stream closure, late-frame rejection,
and native snapshots without Gateway browser availability. Document the stream
and legacy inline link fallback. Preserve main's draining Mach-O checks after
replaying the historical packaging fix and revert.

Validation: 250 UI tests, six E2E scenarios, native builds and eight Swift contract
tests, architecture and generated-script checks, i18n, and all changed checks.

* ci: guard the browser inspect script check for frozen targets

* perf(ui): keep the native browser bridge off the startup path

* fix(ui): open links in the default browser while Settings hides the Browser panel

* fix(ui): reclaim native browser tabs on explicit reselection

* fix(ui): honor Settings fallback in native link menus

* test(ci): include browser inspect in hosted guard fixtures

* perf(ui): defer native link menus until host initialization

Load the native menu before installing link handlers, with startup-owned cancellation and disposal. Regular browser startup no longer loads native-only menu dependencies; merged startup JS falls from 351292 to 343270 gzip bytes against the same main revision.

* fix(ui): keep native link routing synchronous and load its menu on demand

Restore bootstrap handler installation before startup so gateway admission starts synchronously. Defer the native menu until an external-link context event, share its pending import, and cancel superseded or disposed requests. Cover deferred loading, overlapping right-clicks, and abort/dispose; the admission E2E regressions now pass.

* test(ui): use the native bridge boundary for palette occlusion

Replace the file-wide native host module mock with a scoped WebKit bridge fixture. In the shared non-isolated lane, earlier imports could retain real host detection while the observer saw the mock. Preserve the open, close, and disconnect assertions; the original ordered twelve-file shard now passes all 1055 tests.

* test(ui): seed collapsed navigation before recovery reloads

Set the one-shot navigation intent at document initialization. Mutating the live URL immediately before Retry races router canonicalization during the document probe, causing the recovered fixture to show the expanded sidebar. Preserve floating-inbox recovery assertions; all three requested E2E files pass.

* test(ui): keep deferred menu fixture compatible with the test target

* test(ui): call native link routing synchronously in remaining fixtures
2026-09-07 13:12:46 -07:00
NianJiu
439a4310ef
fix(memory): avoid repeated vector search startup delays (#140730)
Route isolated vector-search children through one private host entrypoint for the existing SQLite, sqlite-vec and text helpers.

Preserve the contributor repair, query results, cancellation, admission and index-publication behavior. Matched native-child measurements improve by 86.3%; real Gateway calls and independent behavior validation confirm the improvement with unchanged results.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-07 23:40:22 +05:30
Peter Steinberger
ce0e84d073
fix(runtime): require Node builds with lossless SQLite reads (#140672)
* fix(runtime): require Node builds with lossless SQLite reads

* fix(runtime): preserve upgrades and guard sealed workers

Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.

* test(runtime): use typed process exports in worker fixture

* test(runtime): align installer fixtures without growing test shards

* test(runtime): align release and guest runtime fixtures

* fix(test): canonicalize Windows temp roots for Node 24

Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.

* test(ci): run Windows temp-root regressions in the native lane
2026-09-07 10:31:31 -07:00
Peter Steinberger
fac726e07a
build(release): publish npm package-lock mirrors as dependency evidence (#140622)
* build(release): publish npm package-lock mirrors as dependency evidence

Release-note context: Existing dependency release archives now carry
pnpm-verified npm package-lock mirrors for openclaw and every publishable
workspace with runtime dependencies. Downstream packagers can select exact
package versions and verify their release commit, including lockless acpx
packages. Generated locks stay outside npm tarballs.

Keep the canonical generator policy: sibling workspace packages publish in
the same release and cannot be resolved from the registry at preflight.
Every entry reports sorted omittedWorkspaceDependencies; nonempty arrays
mark partial locks that consumers must reject instead of installing. Add
the partial-entry total, show omissions in Markdown and release guidance,
and reject omission claims contradicted by resolved lock entries.

Reuse source-root-aware lock workers and extend evidence summaries and
consumer tests without changing tarball contents or bundling policy.
Current-source and v2026.9.1 proofs each contain 46 entries and two partial
locks; all seven lockless plugins have empty omission lists.

Refs #134190

* docs(release): note override normalization for consumers of npm package-lock evidence

A bare npm ci against an evidence lock fails its lock-sync check because the lock carries pnpm-workspace.yaml scoped overrides (codex-acp -> @openai/codex 0.152.1 vs ^0.148.0). Consumers must carry the same overrides or pin nested specs to locked versions, as nix-openclaw does. Verified by replaying the v2026.9.1 @openclaw/acpx lock: raw npm ci fails EUSAGE, normalized lock installs online and offline.

Refs #134190
2026-09-07 10:25:33 -07:00
Peter Steinberger
870195ad8f
fix(deps): adopt fs-safe 0.8.5 (#141165)
* fix(deps): adopt fs-safe 0.8.5

* test(fs): align fault injection with fs-safe metadata

* test: align workspace and backup fixtures with fs-safe metadata

* test(memory): align extra-path errors with fs-safe metadata
2026-09-07 07:06:02 -07:00
Peter Steinberger
92d8b78609
fix(worktrees): prevent shared Git ref cleanup collisions (#141095)
* fix(worktrees): prevent shared Git ref cleanup collisions

Coordinate managed-worktree and worker-result ref mutations through one
canonical common-directory queue, including configured-pruning fetches.
Capture the environment before discovery and retain foreground maintenance
inside the existing owned execution path.

Reject interrupted required output and base selection, including buffered
I/O errors with a zero physical exit code. Preserve checkpoint acceptance,
retention, external Git errors, and the existing local-HEAD fallback.

Closes #131970. Git ownership replacement for #132180; other slices remain
separate and the original PR stays open until they are accounted for.

* test(worktrees): compare live Git worktree identities across platforms

Resolve the fixture's existing paths before comparing them, preserving the
exact lock-reason assertion without requiring Git to use Node's Windows
separator spelling. Run the fixture on every platform.

Native Windows CI exposed the old assertion when the Git suite joined its
explicit target list. Production listing remains unchanged so missing and
prunable worktrees can still be represented.

Follow-up for #141095 and #131970.
2026-09-07 06:26:56 -07:00
Peter Steinberger
40b6339641
refactor: share one-shot tickets and WebSocket helpers across desktop, node, and browser streams (#141185)
Five copies of the same in-memory one-shot ticket (48-hex token, 60 s TTL,
unref'd expiry timer, single-use consume) and seven copies of "write a raw
HTTP status and destroy the socket" had accumulated across the desktop
observer bridge, the node desktop/portal stream broker, sandbox noVNC auth,
the browser extension relay, the browser screencast, voice-call realtime
upgrades, and core upgrade routing. The browser screencast also hand-rolled
the ping/pong keepalive that core already owned.

One shared store now owns ticket generation, shape checks, timers, and
expiry callbacks; one helper writes upgrade rejections (flushing before
destroy) for every status the callers use; the keepalive helper takes a
structural socket so plugins need no `ws` types. Bundled plugins reach all
three through the private-local `openclaw/plugin-sdk/websocket-runtime`
subpath, which keeps the public SDK surface budget unchanged.

Migrated sites: src/gateway/desktop/observe-bridge.ts,
src/gateway/desktop/node-stream-broker.ts, src/agents/sandbox/novnc-auth.ts,
src/gateway/server/plugins-http.ts, src/gateway/server-http-upgrades.ts,
src/gateway/server/http-work-admission.ts,
extensions/browser/src/browser/screencast/{tokens,upgrade}.ts,
extensions/browser/src/browser/extension-relay/{relay-server,gateway-relay-route}.ts,
extensions/voice-call/src/webhook/realtime-handler.ts.

Deliberately unchanged: the artifact-transfer capability tokens (revocable
serving authority, 43-char base64url contract), the Mattermost client
keepalive (own ping/pong deadlines and reconnect coupling), and the diffs
plugin's persistent hashed artifact tokens. The voice-call 401 rejection now
also sends `Connection: close`; relay upgrade sockets gain an error guard so
a client reset during rejection cannot surface as an unhandled error.

Preserve requester revocation with shared-store revokeSignal and listener cleanup.
2026-09-07 05:10:50 -07:00
Peter Steinberger
bff6c68fb0
fix(update): bound finalization and diagnose stalled phases (#140648)
* fix(update): bound finalization and diagnose stalled phases

Record phase progress as it happens, retain OCM-compatible terminal timings,
and stop owned subprocess trees before a timed-out finalizer permits rollback.
Bound shared CLI disposers and report resources that outlive terminal output.
Force-kill the managed Codex version probe at its existing deadline.

The missing deadline, child-custody, and diagnostic recovery paths require
production growth; remove duplicated phase bookkeeping and the version probe's
callback wrapper. Keep issue #139485 open for the affected macOS reproduction.
Reported by @hannesrudolph.

* test(update): complete stalled cleanup fixture

* fix(update): keep completion refresh interruptible

* test(update): use supported subprocess IPC option

* fix(update): preserve triage after bounded preflight

* fix(update): preserve recovery and optional completion outcomes

* fix(update): retain process ownership through finalizer exit

* test(update): keep process and budget checks type-safe

* test(update): exercise Windows orphan cleanup ownership

Detach the fixture grandchild from the launcher-owned libuv Job so only the finalizer Job can terminate it after the launcher exits. Keep borrowed and Gateway negative controls.

* style(tests): use pinned planner formatting

* fix(process): preserve live child custody after probe failure

* fix(update): preserve borrowed CLI process lifetime

* test(update): avoid returning the borrowed caller timer
2026-09-06 23:25:20 -07:00
Peter Steinberger
d3101b5229
feat: add Team Reports plugin for GitHub and Discord activity reports (#139850)
* feat(team-reports): scaffold bundled team activity reports plugin contract

* feat(team-reports): add bundled plugin icon

* feat(team-reports): add team activity reports plugin core

* feat(team-reports): add GitHub and Discord activity sources

Collect activity through cancellable HTTPS clients with pagination, rate-limit
handling, isolated warnings, deterministic ordering, merger attribution,
coauthor parsing, and Discord thread rollup.

Validate 23 source tests, both plugin import guards, production and test
TypeScript checks, and a clean independent review. Preserve the frozen
contract and collection scope.

Full changed checks remain blocked by 11 unused frozen domain exports awaiting
the report core consumers. Scoped lint artifact preparation also rejects the
parent-checkout punycode dependency; an isolated dependency install is needed.
No guard or shared contract was changed to hide these blockers.

* fix(team-reports): resolve lint and dead exports

Bound GitHub issue and review comment titles to a normalized first line
of at most 140 Unicode code points, preserving full bodies for attribution,
duplicate collapsing, and ignore patterns.

Remove unused exports, keep scheduling and summary proof at their runtime
boundaries, and repair plugin lint and strict typecheck findings without
changing contract fields, schemas, dependencies, or baselines.

Validation: 129 plugin tests and 1131 plugin contract tests pass. The full
typecheck and all dead-export scans pass. Repository lint is blocked by
parent-checkout declaration resolution; the build remains deferred under
the requested environment-failure stop condition.

* fix(team-reports): discover GitHub issues by event date, not last update

* fix(team-reports): satisfy type-aware lint rules

* fix(team-reports): reject aborted runs with a typed error message

* fix(team-reports): register plugin secrets, labeler rule, and test fixtures for CI gates

* fix(team-reports): correct fixture import path after rename

* refactor(team-reports): drop test-only seams and simplify helpers

* refactor(team-reports): share source HTTP helpers between clients

* refactor(team-reports): name the source abort labels

* build(team-reports): publish as an official external package

* test(release): count team-reports in the publisher inventory

Marking @openclaw/team-reports publishable adds one npm and one ClawHub package, so the pinned inventory becomes 94 npm and 90 ClawHub.

* refactor(team-reports): share constants and response parsing, consolidate test fixtures

Export DAY_MS and periodSchema from periods.ts and MAX_REPORT_BYTES from limits.ts instead of per-file copies; share the zod response parser between the GitHub and Discord clients; drop the Discord message wrapper in favor of sorting on channel and message IDs; remove the test-only random and nowMs parameters (tests spy on Date.now); share report fixtures across suites. Net -35 lines, all 137 tests and assertions retained.

* fix(team-reports): qualify GitHub issue searches by type for fine-grained tokens

* fix(team-reports): accept advisory credit shapes, skip unreadable advisories, and honor manual day runs

* fix(team-reports): size the summary output budget by roster and surface model fallbacks

* fix(team-reports): accept null advisory credit logins and retry model summaries after a fallback

One of 1780 advisories on a large repository carries credits: [{login: null}], which the credit schema rejected and marked the day stale. With summaries enabled, a stored fallback for unchanged evidence is now retried instead of reused, so a transient model failure does not persist until the evidence changes; disabled runs never carry a model-failure warning forward.

* fix(team-reports): require operator.read on the report route, scan comment-only and advisory-only repositories, and count only closed-window runs for catch-up

* fix(team-reports): extend comment discovery to the current time

The updated: discovery searches used the report window's end, so an issue or pull request edited again after the day closed no longer matched updated:<day> and a comment-only repository was skipped during the 00:05 closed-day run or a historical regeneration. Discovery now bounds updated_at by the current time and the comment endpoints still filter events to the report window.

* fix(team-reports): collect archived private Discord threads
2026-09-06 23:15:10 -07:00
Peter Steinberger
0f087c9625
chore(deps): refresh four seven-day-cooled packages (#140732)
* chore(deps): refresh four seven-day-cooled packages

Update nostr-tools, ignore, tsx and web-tree-sitter across seven manifest
bindings. Preserve the pinned Bash grammar and all existing dependency
policy, overrides, patches and compatibility holds.

The ignore update improves Git-compatible bracket/POSIX matching while
retaining fail-closed matcher composition. Nostr signing/relay entrypoints
remain unchanged; parser ABI, cancellation/reset and explicit deletion
retain their current contracts. Tooling cache policy is unchanged.

Frozen cutoff: 2026-08-31T02:32:01Z. Registry integrity and the complete
lock graph are verified. Focused loopback/owner and independent parser
proof plus managed review are recorded with final validation in the PR.

Closes #140691

* test(ui): keep cache probe independent of filesystem calls

The tsx update replaces synchronous directory indexing with bounded reads.
Require the positive control to observe cache access, rather than a
particular syscall. Keep all no-cache, sentinel, validator and exit-status
assertions unchanged.

The original suite reproduced the Linux/Windows CI assertion failure.
The repaired suite passed all 28 tests on an unchanged retry; the first
repaired run's timeout and cleanup errors remain recorded in PR evidence.
Scoped checks and independent review passed.
2026-09-06 21:45:52 -07:00
Peter Steinberger
eaa614a843
fix(plugins): retain install files when ownership expires (#138870)
* fix(plugins): retain install recovery after ownership loss

Adopt fs-safe 0.8.3 mutation guards and exact publication receipts. Share immediate and retained rollback, preserve Windows copy fallback, and refuse stale owners or substituted backup identities. Keep published recovery state explicit when cleanup cannot finish.\n\nFixes #138815.

* test(archive): verify security outcomes across parser backends

Assert the documented entry-path code rather than backend-specific TAR
wording. Change outside-file sentinels after packing and verify extraction
leaves them untouched, creates no destination entries, and installs no hooks.
2026-09-06 20:30:26 -07:00
Peter Steinberger
d1175e88b4
fix(windows): avoid compiler-triggered gateway startup failures (#140593)
* fix(windows): avoid runtime compilation during gateway startup

Create private SQLite staging directories through the existing Koffi runtime
and Windows security APIs, preserving atomic protected ACLs and exclusive
creation. Remove compiler subprocesses and their obsolete diagnostics.

Use a held .NET process handle for update restart ownership and run the
standalone PowerShell companion without Add-Type or Invoke-Expression.
Require an explicit completion marker because PowerShell can report success
for malformed or incomplete stdin without executing the helper.

Reported by @LegendaryAdventures. Related: #139468.

* fix(windows): preserve detached restart execution and native proof
2026-09-06 19:45:36 -07:00
Peter Steinberger
270762e51d
fix: use the bundle-compatible Proxyline runtime under Bun (#140411)
* fix: use the installed Proxyline peer under Bun

* fix: retain Proxyline peer loading in worker bundles

* test: disable package auto-install in relocated Bun workers
2026-09-06 14:22:07 -07:00