Pin Linux CI to the checksum-verified 1e6f Bun fork prerelease and qualify complete Quicksilver worker, broker event-order, and broker group-custody coverage. Preserve V8/registerHooks exclusions, Windows skips, and the shutdown workaround required by stock Bun.
Proof: every existing Bun selection compared against 86bd without new failures or skips; final admitted CI groups passed on 1e6f; the candidate passed all ten Node-hidden smoke steps with an empty blocker list. Focused Node/Bun checks, changed-file checks, and both P2 reviews passed. Three unchanged provider-message assertions failed equally in the frozen baseline comparison, and the old smoke's Chrome startup failure is recorded in the PR evidence.
Exclude dotted .test-utils.ts and .test-utils.tsx paths through the existing build-input owner. Preserve runtime support inputs and extend the existing build-stamp regression.
The controlled prepared test-utility-edit workflow at db793644 improved from 67.205s to 27.870s mean wall time. Current-source correctness and changed-file gates remain pending in the draft PR.
The Telegram userbot skill's node:test (*.test.mjs) and Python (*.test.py)
files are not Vitest-routable, so aggressive PR selection drops them as
direct targets. Their only CI owner is the Vitest wrapper
test/scripts/telegram-e2e-userbot-skill.test.ts, which the policy watch
selected for 20 named non-test scripts only. Test-only skill PRs (e.g.
#162968) and later scripts (reply-policy-*, telegram-runtime) planned
nothing in either selection mode.
Watch the skill's whole scripts/ directory, the agents/openai.yaml the
wrapper parses, and the fixture it loads by URL. The wrapper stays in the
release-only core-tooling family; it now also runs on PRs that touch the
skill, the only PRs that can break these self-contained scripts.
Complete the fs-safe watcher migration for catalog and usage-template caches, with non-persistent subscriptions so one-shot commands exit naturally. Preserve atomic-save and missing-root recovery behavior.
Re-read selected sources after undetailed invalidations and restart the dev child only when content changes. Keep unchanged Skills coverage available, and honor CHOKIDAR_INTERVAL for forced polling and automatic fallback. Remove redundant native transports and transport-specific fixtures.
Completes #159226 and supersedes #158182. Dependency pins remain owned by main.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
The generated native inventory stored one line per string with every
extraction site inline, sorted alphabetically. Two PRs reusing a string
("Retry") both rewrote its line, and a feature's new strings ("Group by",
"Group chat") landed in the same insertion gap, so parallel native PRs
conflicted in apps/.i18n/native-source.json and needed a rebase plus a
full CI rerun.
Inventory v3 writes one line per extraction site, clustered by source
file, with clusters ordered by a hash of the path so new sibling files do
not share a gap. Each row's position depends only on its own content, so
independent edits merge cleanly (including GitHub's server-side merge)
and the merged text equals a fresh baseline. The new
scripts/native-i18n-inventory.ts owns serialization and parsing; the
generator, Android/Gradle and Apple readers migrate to it together and
receive the same entries in the same order as before.
* feat(llm-core): add Claude in-history system message capability
* improve(agents): pin the stable prompt prefix and append section updates on capable Claude routes
* improve(agents): send turn-scoped runtime context as system messages on capable Claude routes
* fix(plugins): exclude rolled-back registrations from execution scopes
* test(agents): give the live prefix-update case a fifteen-minute budget
Two real plugin-runtime builds on a loaded host exceed the six-minute case timeout; the probes themselves are unchanged.
* fix(agents): preserve dispatch freshness and provider review authority
* fix: keep subagent registration responsive during database contention
* test: isolate npm config in installer version fixtures
* fix(agents): fence registration rollback after supersession
* test(agents): inject registration faults through async writer
* test(agents): adapt spawn lifecycle to async persistence
* fix: separate session metadata maintenance from archive admission
* test: use archive finalization for idle collection fixture
* test: pass maintenance cases the Vitest test context
* test: join native cleanup and forward registry persistence in fixtures
* test: isolate registration rollback cancellation from source revocation
* fix: cancel accepted subagents through the lifecycle owner
* fix(state): preserve registry snapshots on validated reopens
* fix(state): explicitly type worker transcript assertions
* test(gateway): retain directive fixture state through cleanup
* test: assert preserved predecessor metadata independently
* test: use the typed session owner in registration recovery proof
* test: join skill library database cleanup before removing state
* test(sessions): bind archive maintenance to fixture state
* test(gateway): follow catalog completion in privacy fixtures
* test(media): use valid PNG in Windows file URL fixture
* test(acp): align fixture state and cleanup ownership
* test: retain restart fixture state through cleanup
* test: retire SQLite owner generations across test files
* test: synchronize completion and maintenance worker fixtures
* refactor: dispatch archive pruning through its worker owner
* test: align reclamation and cleanup fixtures with their owners
* fix: preserve selected subagent ownership observations
* test: preserve registry acknowledgments in fixtures
* fix(ci): settle memory capacity before runtime placement
* test(subagents): forward requester handoff acknowledgements
* fix(sessions): preserve cleanup environment across SDK calls
* test(subagents): bind registration fixtures to their requested owner
* fix(ci): remove duplicate database worker test entry
Keep one PDF resource-test registration in the existing fork-owned inventory.
The repeated entry prevented compact timing generation before CI tests began.
Preserve the complete unique test set and the duplicate guard.
* test(sessions): fix cold maintenance fixture context and cleanup
* test(subagents): forward acknowledged IDs in requester retirement
Preserve the persistence callback receipt through the watched-session test
adapter and trigger requester retirement only for acknowledged run IDs.
* fix(state): retain explicit transcript assertion bindings
Restore the typed local assertion targets required by the production compiler.
Keep the creation-path simplification and current worker dispatch unchanged.
* test(sessions): verify archival in cold maintenance proof
Assert the existing durable-conversation archive contract and retained session
data while preserving the cold worker, FIFO, host-access and settlement guards.
* test(sessions): run SDK cleanup proof with live database owner
* test(sessions): await native writer before cleanup race mutation
* test: preserve registry acknowledgement ordering in fixtures
* test: run session fork coverage with the host SQLite broker
* fix(state): retire failed shared workers before lease cleanup
Keep cleanup bound to the original database identity and live owner while joining canonical actor retirement. Preserve active-callback refusal and existing-only admission.
Make lifecycle fixtures observe real completion and retain the original assertions and deadlines. Align shutdown proof with the shared maintenance writer and await UI readiness within its existing polling budget.
* test: bind generated SQLite fixtures to physical identities
Pass observed identities into cleanup admission while retaining the real host-broker refusal. Use a physical fixture identity for schema-scope proof instead of mocking away identity checks. Preserve the full cross-file cleanup and retained-lease assertions.
* test(subagents): respect retirement acknowledgement before registration
Observe the successor joining the actual pending write, then hold only the older cleanup continuation after persistence and publication settle. Preserve successor data, current authority, publication revision and hook fencing when that continuation resumes. Join both operations on cancellation without changing deadlines.
* test: run catalog boundary coverage with the host SQLite broker
Classify the existing embedded-attempt catalog suite with the canonical forked-process owner. Keep broker admission guards and all test assertions unchanged.
* test: preserve active runs and order watcher replacement fixtures
* test: align worker inventory with upstream classifications
* fix: retain failed-spawn cleanup and completion authority
* fix: align subagent cleanup checks with worker ownership
Return the existing false completion policy for retired stores before checking
live delivery authority. Eligible delivery still requires current authority at
the outbound boundary.
Route preparation-fixture cleanup through the captured Gateway owner and join
accepted handlers before tearing down parent state. Align session-group fixture
helpers with the catalog's state directory and classify published inbound
maintenance under the existing host broker test project.
Verified 60 focused behavior cases, 481 project-ownership checks, three owning
type graphs, 13 static checks, and two scoped independent reviews. The prior
parent-fork teardown failure did not reproduce in one bounded diagnostic replay;
its cause remains unresolved. All temporary diagnostics were removed.
The wrapper now reaches supported-session-store, channel-route, delivery-context.shared, and the message-channel helpers at runtime; the closure tests reported them missing on main.
* feat(plugin-sdk): await session persistence and deprecate sync writes
* test(sessions): fix awaited persistence fixture types
* fix(sessions): preserve binding and delivery publication
* test(sessions): isolate compaction retarget authority
Model the retarget as an independent operation so the fixture reaches post-commit publication validation. Keep the committed receipt, accounting, and replacement-transcript assertions intact.
* fix(ci): remove duplicate database-worker test routing
Main already routes attempt-phase-lifecycle.test.ts through the database-worker owner. Remove the duplicate introduced by the SDK branch. Exact-head preflight and the native local manifest both reproduced the failure; the corrected manifest passes with 69 selected Node rows. Unique test coverage and the duplicate guard stay intact. Formatting and P2 review pass.
* fix(sessions): keep maintenance projections with the host owner
Return committed projection-rebuild facts from maintenance workers and schedule them through the existing host owner. Preserve custody, rollback, and synchronous compatibility. Update async fixtures and host-broker test routing, restore the native wrapper import inventory, and route memory visibility declarations through their existing producer.
Focused Linux proof passed342 tests across17 suites; old-code controls fail at pending projections. SDK declarations retain legacy signatures with four additive exports. Types, lint, T1, Madge, focused routing checks, and P2 review pass.
* test(cli): await blocked-run hook entry without polling
Await the existing hook-entry gate instead of racing awaited transcript persistence against vi.waitFor's one-second default. Preserve the early-settlement failure and the assertion that agent_end must finish before the CLI run settles.
The two focused cases pass in 155.98s including preparation; their test bodies take 3.656s and 1.804s. Fresh P2 review is clean.
* test(cli): use the deferred helper default type
* test(gateway): keep worktree fixture on the shared state root
Use the nested fixture only for workspace and device files. Activating its environment switches process state roots underneath the shared Gateway, whose projection retains its startup environment. Preserve the registry witness guard and every cwd, transcript, initial-run, and follow-up assertion.
CI observed AgentDatabaseRegistryChangedError during creation. The exact callback interleaving was not captured, and unmodified main passed the whole file in 172.229s; that is non-reproduction, not inherited-failure qualification. The corrected fixture passes all 10 cases in original order in 164.077s. Semantic lint, formatting, and fresh P2 review pass.
* refactor(sessions): separate hydration types and CLI hook fixtures
Keep transcript hydration results beside their request contracts and retain aggregate exports. Move the CLI hook fixture owner into test support without changing coverage. This removes both line-cap increases after main integration; 112 composition tests and all 52 reliability tests pass.
Remove cron JSON jobs/state and JSONL history imports whose last stable writer predates July 2026. Keep supported quarantine and SQLite migrations with Doctor, and refuse retired live inputs before update activation while preserving the published Gateway and operator data.
Final-head Testbox validation and both published 2026.9.7 update cells pass. The PR records source-qualified CI failures inherited from main and their landed fixes.
* fix(agents): describe unrecorded tool results as unknown outcomes
Use shared unknown-outcome guidance while preserving the Responses-family aborted convention. Retain synthetic provenance in model context so late real results can replace repair placeholders without changing existing detection or stored transcript rows.
* improve(agents): assert provider request history stays append-only
Track converted message prefixes and record declared compaction, pruning, runtime-context, and image rewrites. Notify every cache-affinity baseline for the same session identity. Memoize message/content and schema fingerprints, with strict assertions enabled only by an opt-in environment flag.
* fix(agents): pin the shared tool-result text for the request wrapper
Include packages/llm-core/src/types.ts in the PR wrapper's extracted source inventory. Main commit 93625aa3d1 pulled tool-result-pairing.ts into that graph, so its existing shared tool-result text import must be included for standalone wrapper execution.
* feat(state): add inactive incognito report and outbox adapters
Bind transcript reports and closed-turn outbox commands to the retained incognito actor connection and shared FIFO publication owner. Keep production routing host-owned until P7 and preserve durable outbox semantics.
* fix(tooling): retain incognito transcript wrapper dependency
Remove redundant Wear page and polling state, retired iOS row fields and branches, and a shared session preference forwarder. Simplify valid-string decoding and keep localization guards and source inventory aligned with their surviving owners.
Production reduction: 41 net Swift/Kotlin lines. Fresh full review is clean through P2. Remote proof passed 76 Wear tests, 62 localization tests, native localization verification, Kotlin and Android lint, and both cycle checks; hosted native CI gates landing.
* feat: use MCP plugin apps across conversations and workspace files
Extend the opt-in MCP Apps host with discovery and entrypoints, settings, rich forms, scoped file editing, multimodal context, deep links, and native Codex session preparation. Preserve existing requester, approval, runtime, and file authority owners.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: keep app context compact and review large tool payloads
Reuse the canonical bounded plugin approval preview without rejecting otherwise valid large App arguments. Keep the same one-shot approval and live-authority gates. Bound context-strip icons and scrolling so attachments leave the composer usable.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: reveal pending input above fullscreen MCP apps
Keep App fullscreen rendering in the existing browser top layer and return to inline for same-conversation questions or approvals without replacing the iframe. Consolidate host-context, resource, and input notifications under the existing bridge lifetime.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test: preserve full attempt inputs in native assignment fixtures
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: release session access when MCP app launch preparation fails
Preserve the upstream optional ifMatch contract and document unconditional-save semantics explicitly.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): defer question controls and preserve canonical keyboard values
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(mcp): preserve app authority through startup and user turns
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(codex): share native app startup across concurrent discoveries
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* docs(mcp): explain native app prompting and request limits
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* feat: use MCP plugin apps across conversations and workspace files
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: f2f8d735-c1ac-4a0d-84f3-1576113c1baf
* fix(mcp): keep form contracts and test helpers with their owners
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* feat: use MCP plugin apps across conversations and workspace files
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 2513c3ef-4af8-4722-b802-ffa426df486a
* fix(codex): revalidate MCP App authority before native retries
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(ui): provide chat identity fixture context dependencies
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* feat: use MCP plugin apps across conversations and workspace files
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 85c132dc-d926-46ca-b57e-2d9e01f15487
* fix: integrate MCP app owners with current main
* fix(gateway): accept option labels from installed clients for rich forms
* chore(format): anchor the native apps formatter ignore
* perf(ui): load the MCP app link parser on demand
Keep startup click interception parser-free and capture the normalized href before lazy navigation. Preserve ordinary, modified and download links; drop malformed plugin links and cancel pending navigation on disposal. Router/parser proof: 17 tests passed in 4.50s wall. Startup gzip: 374086 -> 373613 B; 159 B still above the unchanged 373454 B limit.
* perf(ui): register MCP app English with lazy consumers
Move the MCP App catalog out of startup English and register it synchronously at every consumer. Keep the shared namespace anchor and host catalog composition so all text and source order remain byte-identical. i18n verification passes without baseline changes. Startup gzip: 373613 -> 373103 B, 351 B below the unchanged 373454 B limit.
* fix(ui): intercept only well-formed MCP app links
Require the plugin/app/tool shape before cancelling browser navigation so ordinary ChatGPT plugin pages keep their default behavior. Preserve lazy strict parsing and accepted native and web app links.
* fix(gateway): watch MCP app files directly so loaded macOS hosts still notify
Watch the bound file to avoid FSEvents directory event drops under load. Re-arm on atomic replacement, retry ENOENT once on the next immediate turn, and retain subscription authority and cleanup. Cover replacement followed by a plain write through the registered resource routes.
* fix(gateway): use the errno guard when rearming MCP app watches
Use the shared filesystem error guard instead of an unchecked type assertion. Keep the single immediate ENOENT retry and all subscription behavior unchanged.
* fix(codex): read the canonical MCP transport field
Main migrates MCP transport aliases before runtime (#162256) and retired the SDK re-export of the alias resolver, so the native app catalog reads the canonical server.transport field the same way the agentsapi plugin does.
* fix(gateway): keep MCP app file subscriptions alive across rename gaps
Keep resource subscriptions alive while editors move the old file aside before installing its replacement. Poll missing paths at 250 ms, return to the inode watcher when the file reappears, and release polling on subscription close. Recheck after polling registration to cover replacement before its first stat; share the rearm guard so late callbacks cannot leak watchers.
* test(codex): type the rooted thread policy support from attempt fixtures
The rooted policy support that main added types its lifecycle input from the raw thread signature, while this branch's binding fixtures carry full attempt params. Derive it from the shared attempt-thread fixture type, as the sibling policy-refresh support already does.
* test(ui): exercise the MCP app link probe through the click boundary
The eager link probe was exported only for its unit test, which the production dead-export scan rejects. Keep it module-private and assert the same accepted and rejected links through real click interception.
* style(lint): clear MCP app lint errors
CI run 36988865432 jobs check-lint-core-1 and check-lint-core-2 rejected shadowed stat callback variables, a returning Promise executor, and reassigned projection parameters. Rename the inner variables and use local projection bindings and an executor block without changing behavior.
* test(agents): align bundle MCP fixture ownership
CI run 36988865432 job checks-node-changed-compact-large-14 failed seven merge cases because the fixture omitted the loader-required pluginIdsByServer map. Type the fixture against the producer contract and verify ownership survives only for unshadowed enabled bundle servers, preserving the migrated transport behavior.
* fix(auto-reply): register turns before MCP context leasing
CI run 36988865432 job checks-node-changed-compact-large-33-2 exposed an asynchronous MCP lease before synchronous run registration. Prepare App context after ownership registration and image admission, revalidate requester authority around the lease, and retain commit and rollback settlement with the execution outcome owner.
* test(gateway): admit MCP shutdown requests through current policy
CI run 36988865432 job checks-node-changed-compact-large-9 timed out because the fixture ignored an admission rejection before its upstream call. Publish matching Gateway and runtime config, create the session through its RPC owner, and observe early request settlement while preserving all shutdown ordering and cleanup assertions.
* refactor(apple): drop the label-only question toggle
Periphery flagged toggleOption(questionID🏷️) as dead: production selects by canonical value since the rich-form change, and only tests still called the label overload. Tests now toggle by value; the ambiguous-label case becomes an unknown-value no-op.
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Complete the volume-specific fixture contract after the generic per-agent cutover in #163360. Seed modelProvider and check that durable field after migration, preserving the existing session, transcript, archive, and model assertions.
Exercise the actual phase-produced stores through the canonical session reader in the existing baseline-order fixture. The unchanged volume writer fails the retired-provider guard while the base control passes; all four affected cells pass after the repair. Scoped lint, root types, syntax, Docker boundaries, line-cap checks, and independent P2 review pass.
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* fix: preserve large CUA responses under Bun
Use runtime stdio streams for anchor output backpressure, then publish
socket EOF through Bun's built-in POSIX shutdown binding after flush.
This preserves process cleanup authority and works before the fork's
duplicated-descriptor fix as well as on the current fork.
Keep stdin and signal handling unchanged, and fund the output adapter
with behavior-preserving type and envelope simplification (net zero LOC).
The existing CUA consumer passes 13/13 on Node 24, old Bun b368, and the
current fork on AWS Linux; old Bun previously failed two large-output
cases. All three pass real retirement and stdin readiness tests. Both
output descriptors preserve 11 MiB and publish EOF while the owner stays
alive, including stock musl Bun and macOS. Scoped P2 review, changed-file
checks, and import-cycle checks pass.
* fix(build): recognize Bun FFI in sealed worker artifacts
The CUA output fix uses Bun's runtime-provided FFI module behind a Bun-only
guard. Admit that exact builtin in the worker closure check while retaining
the Node CLI eager-import policy and rejecting native npm dependencies.
The added fixture fails before this correction and passes afterward on
Node and Bun. A real qaRuntime build passes its artifact guard, and the
sealed anchor runs without project dependencies on Node, old Bun, and the
current fork with full output and EOF before process-owner retirement.
Scoped P2 review and changed-script checks pass. Production LOC stays flat.
scripts/pr merge-recover --cancel-auto aborted with 'prior_names[@]: unbound variable' when the retained outcome held no prior merge captures: the wrapper re-execs /bin/bash 3.2 on macOS, where set -u rejects an empty array expansion, so the cancellation returned before retiring the auto-merge request. Use the ${arr[@]+"${arr[@]}"} idiom for the prior and supplied capture arrays. test/scripts/pr-merge-outcome.test.ts: 76 passed.
* refactor(models): prepare persisted catalogs off the Gateway thread
* fix(tooling): retain catalog worker imports in PR wrapper
Include the catalog read operation and its runtime import closure in trusted wrapper extraction. The existing wrapper closure checks reproduce the missing modules and pass with the repaired inventory.
Bind the synthetic native persona fixture qualification to its packed SHA-256, package, source path, rule, and count while preserving frozen release policies. Keep every source file scanned and reject modified fixture bytes or identities.
Co-authored-by: Peter Steinberger <steipete@gmail.com>
The first-hop release lane exited silently before Docker when npm 12 returned
name-keyed pack JSON. Move filename extraction into the existing fixture
helper and use the canonical npm JSON normalizer. Keep the single-result and
nonempty filename checks, with a useful error for malformed output, and
leave recorded package integrity and identity admission unchanged.
Real pinned npm 12.1.0 packing a synthetic package reproduced the original
silent exit; the repaired helper resolves that output to the actual tarball.
The existing shell boundary regression now covers both array and keyed JSON
in its recorded source sweep and fails before the repair. Five negative CLI
cases retain malformed-output rejection. Full fixture suite: 34 passed,
43.00s wrapper wall; the new rejection cases total 0.80s.
Changed checks, Node/Bash syntax checks, and independent review passed.
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Deferred Bun plugin SDK imports could fall through to a linked built host after their captured generation survived cache replacement. Reuse the existing scoped resolver under the retained cache so the generation keeps its selected SDK host and admission boundary.
Correct the serialization, cancellation and source-prescan fixtures without weakening their contracts. Update the published-upgrade survivor to the supported per-agent source layout and current model metadata, preserving migration and source-custody assertions.
Proof: 105 plugin/boundary cases and 202 upgrade-harness cases on each runtime; full build and changed checks; clean P2 review; exact-head CI; published 2026.9.7 updater through full state/plugin/Gateway survivor with all 11,350 immutable entries matching the candidate. The unchanged Bun CallSite column runtime gap remains documented.
The SQLite worker ratchet inventories working-tree source with rg. Include its fixture in the existing prerequisite mapping so clean runners install ripgrep before testing an unchanged baseline. Cover exact targets, exact and glob includes, and grouped tooling selection in the existing manifest regression.
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Retire the public plugin-sdk/command-auth, plugin-sdk/discord, and plugin-sdk/telegram-account subpaths early, with the Plugin SDK owner's approval (2026-10-02). No bundled runtime imports them. No official external plugin at latest or extended-stable imports them either, and the only older @openclaw/discord releases that did (2026.3.7-3.13, 2026.5.2) already import subpaths main removed earlier.
Remove the modules, package exports, entrypoint inventory, compat registrations, and obsolete tests. Move the three surviving contract tests to their focused SDK subpaths. Drop 15 internal exports orphaned by the retirement and the dead isCommandMessage and resolveDualTextControlCommandGate wrappers. Shrink the SDK surface budgets by exactly 3 entrypoints, 128 exports, 79 callable exports, and 128 deprecated exports.
Breaking change for third-party plugins that import these paths: use channel-ingress-runtime, command-auth-native, command-status, or models-provider-runtime, as described in docs/plugins/sdk-migration/import-paths.md and the removal timeline.
Landed over inherited main reds only (Codex model/list sequence tests from #163320, the memory-host-sdk boundary test fixed by 2516be90f1).
* fix(agents): preserve completed turn delivery during follow-up
Keep completed subagent results and their parent-delivery custody across ordinary next-turn admission. Fence predecessor session effects while preserving exact execution guards, independent receipts, and fresh successor authority. Paused continuation and steer retain replacement semantics.
Regression proof uses registered agent admission with paused transcript and delivery boundaries, distinct turn outputs, durable receipts, restored pending delivery, and replay deduplication. Focused announce, reactivation, registry, type, lint, and formatting checks passed; independent review found no actionable P0-P2 findings.
* test(agents): align follow-up delivery CI coverage
Update sibling expectations for retained completed runs, keep requester completion task-scoped, and wait for the real Gateway dispatch signal in the admission regression. Migrate the benchmark to the cleanup ownership callback.
* test(agents): prove independent completion delivery authority
Exercise real child Gateway admission and requester input writes with independently revoked predecessor and successor sources. Assert persisted receipts, transcript attribution, exact source identity, and replay deduplication. All three cases reject a borrowed-authority negative control.
* test(core): split oversized subprocess consumer suites
Separate CLI lifecycle, Gateway startup, command dispatch, and bare-root
flows; media reads and storage; catalog metadata and hosted persistence.
Prepare workers during collection only for the six observed consumers.
Keep all 221 cases, assertions, and fixture initialization order; the
exit-only and catalog metadata files remain declaration-free.
Prune the two split baselines and one already-stale baseline entry.
Validation: 221 passing cases; six collection loads and two none results.
Changed-file formatting/lint, affected tsgo graphs, both line-cap ratchets,
and diff checks pass. The global changed-path typecheck remains blocked
by the inherited agents-other root budget (724/720); affected graphs pass.
The review's baseline concern was rejected against the native stale-entry
check and direct lint of the unchanged target file.
* fix(test): collect extension subprocess dependencies
Move Anthropic's real process helper acquisition to collection while
retaining vi.importActual and its mock reset behavior. Move DeepInfra
and xAI's one-time subject imports and mock setup to collection, keeping
their real HTTP transport and negative SSRF assertions intact.
Validation: all 20 cases pass and first declaration loads are collection;
all case names/counts are unchanged. Formatting and extension test types
pass. The normal extension lint lane was blocked while preparing Plugin
SDK declarations by its existing 300000 ms timeout; no timeout or guard
was changed. The final candidate received the scoped P2 review recorded
with the preceding core split commit.
* test(plugin-sdk): preload compiled subprocesses for extension tests
Move worker preparation into collection through a repo-local, non-production
SDK subpath. Let Codex app-server setup preload declarations while keeping
worker-cpu imports after file mocks; preserve per-test imports and assertions.
Register private source and declaration aliases without adding package exports
or production artifacts. Remove unused CLI fixture exports and reuse the alias
normalization owner so the existing dead-export and line-cap gates pass.
* fix(test): preload compiled subprocesses for newly screened suites
* fix(test): preload remaining screened subprocess declarations
Move compiled subprocess preparation out of test and hook deadlines in six confirmed declaration consumers. Preserve lazy imports, mock ordering, and assertions; keep the shared meeting plugin helper unchanged so platform-scoped loading retains its existing order.
* style(test): keep Parallel suite separator
* fix(ci): keep protected selection for split CLI and catalog suites
The owner splits moved protected run-main and official-catalog cases into
four new suites. Add them to PR_PROTECTED_RUNTIME_TEST_FILES so global inputs
such as pnpm-lock.yaml still select them, and assert that in the existing
global-input planner test.
* docs(agents): trim root AGENTS.md under the 20K bootstrap limit
OpenClaw injects a workspace's AGENTS.md into agent context capped at 20,000
chars; above that it keeps a 9K head, a policy digest, and a 3K tail. Sessions
whose workspace is an openclaw checkout or managed worktree therefore saw most
of "One owner", "Runtime and code safeguards", and "Product and validation"
only as fragments. Root AGENTS.md was 27,913 chars; it is now 18,900.
Every rule is kept, either condensed in place or moved verbatim to its owner
with a pointer:
- red main, CI spend, pre-existing reds -> openclaw-pr-maintainer landing.md
- screenshot completion gate -> openclaw-pr-maintainer media.md
- test failure policy -> openclaw-testing SKILL.md
- cyber-classifier interruption procedure -> security-triage SKILL.md
Schema-check placement, test budgets, and main-drift rules already live in
docs/reference/database-schemas.md, docs/help/testing/writing-tests.md, and
landing.md, so root keeps one-line pointers. The Team update rule is owned by
the update-team-server skill.
* docs(agents): restore trimmed rules and move remaining detail to owners
Autoreview flagged clauses the first trim condensed away. Restore them in root (complete-module reads, maintainer approval for untrusted execution, contributor credit, release lock mirrors, Night Watch, audit approval scope, updater rollback, and others) and move the capability ladder, execution gotchas, CODEOWNERS governance, and the full cleanup rule verbatim to the SDK guide, scripts guide, and maintainer skill.
* docs(agents): keep isolation, migration-path, fixture, and rerun conditions
Correct Node-only assumptions in Doctor, update, storage, and process fixtures while preserving their behavior checks.
Use shared Node executable/version facts for service and runner fixtures, preserve the real host identity for schema/state workers, and make diagnostic, filesystem, preload, parsing, and crash fixtures explicit about the runtime facts they exercise.
Validation covers every repaired owner and affected sibling on Node 24 and verified Bun b368, plus Linux directory and zombie cases. Exact-head CI and P2 review passed. Four unchanged files have source-backed Bun runtime stop reports; local timeout evidence remains recorded alongside separate Darwin controls.
Doctor left its child writers (spawn-broker process groups) without durable custody, so an update that found an unsettled writer could neither prove settlement nor safely start the migrated candidate, and an operator could be left with a down Gateway. The update command owner now reserves custody before spawning, binds native process identity before admitting input, retains its inventory through Doctor death, and admits migrated-candidate Gateway recovery only after proven writer settlement; unverified writers keep the data-at-risk refusal with PID guidance. Recovery snapshot capture drains SQLite writers first so a refused candidate start still rolls back. The immutable 2026.9.5 parent limitation is documented.
Closes#162055
* fix: release deleted agents' model and auth resources
* fix: await only existing deleted-agent builds
* fix: close deleted agents' native memory managers
* fix(agents): close deleted database readers across worker isolates
* fix(agents): revive deleted stores by their captured owner
* refactor(state): remove superseded reader-close entry points
* fix(agents): preserve commit outcomes and close readers before trash
* fix(tooling): include agent readers in native wrapper inventory
* fix(agents): adapt deleted-reader cleanup to native worker owners
* fix(agents): preserve deletion fences across worker generations
* fix(agents): release deletion guards and repair CI proof
Release worker heartbeat references when a deletion lease closes. Keep the
journal authority SELECT in its worker-only module and route the catalog
reader fixture through the existing database-worker lane.
Close the survivor fixture's seed writer before recovery, establish archive
LRU order, and restore the shared logger mock's trace contract. Add effect
boundary coverage for revoked deletion authority and move bounded transport,
channel logging, and fixture code to their existing modules.
Preserves the agent deletion and recreation repair for #159007.
Co-authored-by: Chris Eckert <christopher.k.eckert@gmail.com>
* test(ci): retain native command and auth retirement diagnostics
Wait for a native command receipt before checking its result so a terminal
failure exposes its reason immediately. Include isolated Gateway logs in the
removed-profile assertion, with a debug-only publication retirement summary
that identifies cache, owner, pending-build, and Gateway-loan state.
This diagnoses UI and auth failures from CI run 36965599681 without relaxing
assertions, extending timeouts, or changing retirement/recovery authority.
Co-authored-by: Chris Eckert <christopher.k.eckert@gmail.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Chris Eckert <christopher.k.eckert@gmail.com>
An MCP SDK-only update invalidated Apple Mermaid assets because the key
hashed the entire root manifest and lockfile. Fingerprint the renderer's
workspace and resolved dependency closure, retaining optional/peer
metadata, package integrity, sources, patches and build configuration.
Keep key calculation install-free and preserve output verification and
cold rebuilds.
The exact main/PR input pair now shares a key. Frozen Vite 8.3.1 proof:
0.919s cold to 0.082s verified reuse, with identical bundle bytes.
Final cache and macOS fixture tests, root type lanes, boundary lint,
check-changed, architecture and P2 review passed. The cache file measured
8.15s pnpm wall; final native macOS wrapper proof passed all 168 cases.
Whole tooling: 25,950 passed, 501 existing skips, 26 inherited failures in
untouched updater and suppression-inventory fixtures. Two updater cases
reproduced in isolation; both additional suppression entries are already
present at the source base. No assertion, skip, or baseline was weakened.