A Bun Gateway could not control its managed desktop without a separate
Node.js install: the computer host resolved a real Node from the desktop
PATH (#147275, then #151933 skipped Bun's node shim). Under Node that
owner already returned process.execPath; under Bun it demanded a second
runtime even though the helper and the CUA provider run on Bun.
Spawn the helper with process.execPath and resolveRuntimeWorkerArgv, the
contract other runtime workers use. Node keeps the same executable.
The runtime test now asserts the helper runs on the host's executable;
it fails under Bun with the previous code, which launched a PATH node.
The Linux live proof gains --runtime to start the built Gateway on
another executable with no node on PATH and to record every owned
process's executable. Docs drop the Node requirement and note that
Bun 1.4.2 lets launched desktop apps inherit the helper's streams until
Bun marks inherited descriptors close-on-exec like Node (openclaw/bun#12).
Consolidate repeated tooling flows while preserving command contracts. Fix swallowed HTML translation errors and browser-realm error handling in the Google Live smoke. Owner tests and CLI parity passed on Testbox; final broad gate replay follows a fixture lint correction.
Open About beside Connection and Gateways without requiring a Gateway connection. Replace the obsolete menu-bar description with the current homepage tagline, retain build metadata and resource links, and add Copy Build Info.
* feat: change the voice during a Talk call
* refactor(talk): group runtime modules and deduplicate shared operations
* fix(discord): support changing voices during active calls
Bind the Talk voice tool to an authorized Discord room run and reconnect its
speaker providers without changing saved defaults. Preserve final transcripts,
unheard exact speech, accepted agent work, and supported provider ownership.
Report unsupported in-call changes before reconnecting.
Repair browser and relay cancellation, stale callbacks, replay, and teardown
races exposed by review. Validate with voice and playback regressions, browser
E2E, scoped lint and types, package builds, and independent review.
* fix(ci): document native voice event coverage
* fix(talk): preserve history across voice changes
* refactor(talk): keep relay capacity limits private
* fix(talk): complete asynchronous stop handling
* fix(talk): complete browser cleanup promise ownership
* fix(ci): close voice selection validation gaps
Keep Discord configuration inputs acyclic, preserve exact gateway method-order coverage for the new voice RPCs, and repair existing process-readiness and wrapper-dependency fixtures without weakening their guards.
* feat(talk): support in-call voice changes on iOS and Android
Negotiate voice selection and consume the Gateway handoff event through the
native call owners. Preserve the conversation, accepted agent work, and the
original Gateway connection while awaiting source closure and replacement
media readiness. Fence Stop, account changes, and push-to-talk recorder races.
Keep successful selections through same-Gateway iOS reconnects without saving
voice defaults. Replace mobile protocol exclusions with handlers, document the
supported transports, and localize failure guidance.
* fix(ci): leave generated native locales to the refresh workflow
* fix: negotiate mobile in-call voice selection support
* feat(openai): support public GPT-Live-1 voice sessions
Adapt public Live sessions, startup events, delegation, audio, captions, and
Platform authentication through the existing OpenAI voice plugin. Keep the
Codex subscription transport separate.
Persist public WebRTC transcripts through the Gateway and drain provider
finalization before releasing voice session owners across relay, Discord,
Voice Call, and MeetingBot. Preserve synchronous bridge disposal.
Validate targeted protocol and lifecycle regressions, authenticated synthetic
voice and WebRTC flows, and the iOS Simulator app build.
Closes#145071
* fix(voice): preserve cleanup and package boundaries
Keep the OpenAI capability catalog cold, remove the delegation type cycle, and expose portable Google mock declarations. Route failed call startup through the existing binding cleanup owner and stop failed local audio processes while provider finalization drains.
* fix(ui): preserve public Live caption fragments
Carry explicit verbatim semantics through the browser transcript pipeline so split words, repeated fragments, whitespace, and overlapping speakers bypass legacy ASR heuristics. Keep Gateway-only persistence and avoid synthetic final or item events.
* test(openai): expose portable delegation mock types
Use public logger and gateway callback contracts in test helpers so declaration-enabled plugin package compilation does not reference private Vitest types. Verified declaration compilation for all six affected plugins and test callers.
* fix(openai): wait for delayed GPT-Live delegation transcripts
Retain metadata-only public delegation notices while user captions are empty, resume through the existing admission owners when text arrives, and claim notice IDs before callbacks to prevent duplicate work. Bound pending notices and missing-input waits; revoke them during close, cancellation, and transcript drain. Preserve subscription prompt fallback behavior.
Validation: 103 focused tests pass; new regressions failed against the original behavior. Independent P0-P2 autoreview is scoped-clean. Combined type/lint gates are owned by the landing checkout because declaration boundaries reject this worker worktree borrowed compiler install.
* feat(openai): select GPT-Live Talk defaults by account
Resolve unpinned Talk models with the selected agent account and session requirements. Platform credentials select public GPT-Live; ChatGPT-only accounts select the subscription voice model. Preserve explicit model pins, manual responses, video, Azure, and direct tool bridge defaults. Keep catalog discovery aligned with session creation without rewriting saved config.
Validation: 177 focused tests pass; scope and account regressions fail on the prior owners. Authenticated microphone-to-delegation-to-spoken-answer proof passes with 211200 audio bytes and awaited completed shutdown. Core and plugin production/test typechecks pass; independent review through P2 is scoped-clean. Full changed-file guards continue in the landing workflow.
* test(openai): isolate Talk account default coverage
Keep the routing suite below its existing line limit by reusing its fixtures in a focused defaults suite with injected host auth. Use explicit blocks in the live audio fixture. Production behavior is unchanged.
Validation: all 61 routing/default tests, extension test typecheck and typed lint pass; independent P0-P2 review is scoped-clean.
* refactor(openai): split realtime delegation dispatch and tests
Keep direct bridge admission and dispatch in a focused local owner, reuse the existing bridge fixture across a dedicated delayed-delegation suite, and apply the required block style. Preserve lifecycle checks, callback binding, transcript publication and subscription behavior without relaxing file budgets.
Validation: 103 focused tests pass across five files; independent P0-P2 autoreview is scoped-clean. The landing lane owns canonical typed validation of the combined candidate with physical dependencies.
* test(openai): expose portable bridge mock callback types
Use public Mock annotations tied to the realtime callback and logger contracts so exported bridge fixtures emit declarations without Vitest private Procedure types.
Validation: actual OpenAI declaration emission and extension-test typecheck pass after reproducing TS2883 before the fix; 40 helper-consumer tests pass; independent P0-P2 autoreview scoped-clean.
* fix(openai): preserve camera-capable Talk defaults
* fix(talk): align browser capabilities with launch models
Resolve optional provider and model overrides through the existing Talk catalog before browser camera negotiation. Preserve other provider rows and explicit model choices, while unpinned OpenAI Talk follows the requested GPT Live account defaults.
* fix(ui): avoid shadowing Talk provider selections
* feat(tui): answer agent questions in gateway and local modes
Render session-owned questions with choices, Other, multi-select, a stepper,
Skip, expiry, and /question. Restore pending prompts after reconnect and
session changes, and keep masked input outside the composer and history.
Serve local questions through QuestionManager and claim eligible replies
before queue policy so answers cannot wait behind their blocked run.
Keep local secret-store requests blocked with explicit setup guidance.
Recover uncertain resolutions without replaying input and surface saved
secret refresh failures without exposing submitted values.
Validation: 1,893 focused and sibling tests; 102 PTY tests; isolated Gateway
and local scripted-model round trips; full build; check:changed; docs checks;
independent P0-P2 review. The broader docs anchor audit reports three existing
broken links in untouched generated maturity pages.
* fix(ci): register the TUI question proof command
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures
Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.
Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.
* fix(scripts): keep guarded portable scripts bash 3.2 compatible
* fix(scripts): keep macOS Bash CI coverage green
Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.
Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.
* docs(install): use system Bash in install and recovery commands
Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.
Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.
* fix(scripts): preserve streamed installs and CI packing
Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.
Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.
Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
Use fresh proof-only token auth for both macOS and Linux rig configs and force loopback token auth at Gateway launch. Keep read-only CLI calls usable without creating or copying device identities, preserve node pairing and signing guards, and isolate ambient Gateway credentials and targets. Cover generated configs and command precedence, and document secret-safe proof cleanup.
* chore(deps): update cooled Oxfmt and isolate declaration fixtures
Select Oxfmt 0.65.0 and its 19 native bindings at the seven-day cutoff, preserving all other dependency pins and security policy. Apply its canonical formatter output and split over-limit UI presentation owners without adding lint or assertion exemptions.
Expose only the real packages needed by declaration fixtures instead of the entire repository dependency namespace. Preserve compiler mutation, cache, publication and cleanup guards and existing deadlines. Retain the fallback boundary assertion that the final reply outcome is failed.
Local proof: 100 declaration and sibling tests; 48 Chromium form-boundary tests; focused UI type/lint/ownership checks; inspected synthetic before/after UI parity; full formatter check; clean bounded Codex review. Current-main integration and exact-head CI follow before landing.
* test(ci): cover unified declarations on Windows
Exercise both declaration fixture modes in the existing second Windows lane. Preserve its serial execution, worker count, and deadlines. Inventory and workflow guards pass; native execution is required in PR CI.
* fix(build): keep native Node steps shell-free on Windows
Preserve literal Node arguments, including encoded import URLs, when the build orchestrator delegates to managed execution. Share native invocation construction across ordinary steps and no-pnpm fallbacks, while retaining pnpm shim handling and all shell-safety and process-cleanup guards.
Four boundary regressions fail before and pass after the repair. Final local launcher and combined declaration runs pass 204 and 21 tests respectively. The original native Windows failure and unrelated local readiness diagnostic are retained in PR evidence.
* style: apply Oxfmt to integrated main changes
Apply only verified canonical formatter output to five newly integrated files. The reviewed Windows launcher repair remains byte-identical. Whole formatting, UI types/build, and the complete line-limit ratchet pass.
* test(ui): consolidate unresolved session workspace cases
* style: format refreshed main presentation changes
Canonical Oxfmt output only. Preserved reviewed Windows and fixture bytes; verified frozen install, all-tree formatting, 382 changed core/UI/package lint targets, 59 session-menu tests, UI types and the canonical UI build.
* style: format current main approval and profile code
* fix(gateway): distinguish policy denials from pending approval
Correct session-host picker guidance after hot-reloaded node command denials. Evaluate Gateway policy independently from pairing approval while keeping commands and capabilities bounded by actual admission. Preserve live connections across deny and reallow. Follow-up to the hot-reload integration in https://github.com/openclaw/openclaw/pull/137160. Verified with registry-backed regressions, 127 owner and sibling tests, 14 UI tests, and a real Gateway/browser deny-reallow flow.
* style: format the updated dashboard gallery
* test(telegram): synchronize abort with real probe backoff
* style: format the current Devices action menu
* fix(ui): keep sidebar invitation layout stable
Keep deployment policy and browser dismissal authoritative while deferring the invitation until active sidebar interaction ends. Remove its independent idle-loaded component, preserve internal focus handoffs and organizer drag ownership, and keep artwork loading geometry-neutral.
Protect the original layout race and delayed policy, pointer, keyboard, drag, touch-input, disablement, and dismissal paths. Full owner proof passed 35 browser and 344 unit cases; four negative controls failed as intended. Final lint, styles, invitation cases and existing build budgets pass. Document the first-appearance behavior.
Independent scoped P0 review found no actionable issue. Follow-up for https://github.com/openclaw/openclaw/pull/137004.
* style: format integrated connected-account views
Canonical Oxfmt output for current main account controls. Executable AST and literal values remain unchanged; profile/account unit tests, browser flows, real-Gateway policy flow, and scoped checks pass. Independent P0 review found no actionable issue. The separately reported startup-JS budget excess remains a pre-land blocker.
* perf(ui): defer connected-account English copy
Load the 50 unchanged account-specific strings with their existing UI consumers rather than every initial page. Preserve shared navigation copy, the complete ordered catalog, and English fallback while registering the fragment in host generation and source hashing.
The explicit startup gate changes from 350191 B failing to 349242 B passing: 949 B removed with no budget, baseline, boot-manifest, or translation-memory changes. The canonical catalog is byte-identical; 150 unit tests, 16 browser cases, classified checks, and independent scoped P0 review pass. Follow-up for https://github.com/openclaw/openclaw/pull/137004.
* test(ui): scope reconnect headings to the page
Assert the selected agent heading inside the New Session surface, not the first heading anywhere in the document. The sidebar invitation is a separate valid heading. Preserve reconnect ordering, draft and request assertions, and all existing timeouts.
Both original assertions reproduce the CI mismatch locally; the complete 15-case file and classified checks pass with the scoped selectors. Independent P0 review is clean. Production code is unchanged.
* fix(test): keep source compiler cache in owned test namespaces
Preserve the tooling shared-cache opt-out while allowing source subprocesses to reuse transforms under the Vitest-owned temporary root. Keep worker IPC safeguards and Doctor deadlines unchanged. Real cache regression fails before the fix; Doctor and tooling boundary suites pass.
* fix(plugin-sdk): keep cold facade loading on canonical boundaries
Load Slack QA operations asynchronously without changing their Promise contracts. Restore prepared workspace aliases for cold activation and resolve bundled tracking metadata without eagerly loading activation policy. Preserve actual activation checks and registry fallback. Use the canonical record guard and shrink the old assertion baseline. Cold-source regression fails with the old alias override; unchanged Slack QA and sibling suites pass.
* test(gateway): keep cancellation fixtures live through cold setup
Give intended running descendants real run-context ownership before awaited setup. The unchanged real sweeper must not classify the fixture as an orphan. The deterministic pre-fix sweep reproduces the missed drain; the corrected fixture passes the same probe, all six cases and 33 admission siblings. No production or deadline changes.
* fix(plugin-sdk): activate browser cleanup asynchronously
Use the existing async activated-facade loader in already-async browser cleanup and remove the duplicate synchronous activation check. This avoids blocking cold source-hosted session resets while preserving activation rechecks, optional cleanup warnings and the public Promise contract. Both unchanged Gateway regressions pass; production shrinks by ten lines. Browser bridge throwing-loader migration is a separate follow-up.
* fix(update): preserve configuration and verify upgrade recovery
Prefer npm before ClawHub only among declared plugin identities, preserving explicit source/version intent, artifact integrity and capability consent. Keep the exact installed beta cohort and require typed target absence before fallback.
Preserve authored environment references through both Doctor writers, resolve snapshot destinations at operation time, and keep migration-only metadata out of redacted snapshots. Avoid loading channel runtimes for unused pairing account facts while retaining captured migration-owner attribution.
Record activation safety at package/Git mutation boundaries. Keep installed-CLI recovery, verify runtime/native-service identity, fence Windows autostart, preserve child status, and avoid duplicating consumed notifications or rejecting completed install switches. Surface update-specific disconnect diagnostics without changing explicit-restart guidance in Model Setup.
Retain the upgrade-survivor first-hop, approval and installed-version oracles. Repair CI's type-only Doctor cycle and stale source-policy, final-Doctor and Teams whitespace expectations without weakening timeouts, gates or the main-owned Markdown fix.
PR: https://github.com/openclaw/openclaw/pull/134490
* test(msteams): align the corrected main whitespace fixture
* perf(ui): remove unreachable update translations
Remove superseded version-only verification copy and the unused idle label from the eager catalog. Keep identity-aware verification and all recovery guidance unchanged, align translation fixtures, and restore the existing merged startup budget without increasing its baseline or limits.
* fix(update): retain consent failures and isolate validation homes
Carry unresolved non-retained plugin capability refusals from missing-install
repair through post-core convergence as typed outcomes, preserving the existing
update failure and restart boundary. Keep usable retained artifacts and
transient fetch failures on their existing notice/warning paths.
Give test invocations a native process HOME before config imports and worker
creation. Preserve bounded live/profile context, report selection, installed
tool caches, and process-group/pipe-owned namespace cleanup or truthful
retention. Keep unknown or mixed explicit real-home selections closed.
Resolve the repo-owned staging helper from its owning cwd and await complete
PID readiness before cancelling native report fixtures.
Align the survivor recovery oracle with typed consent errors that intentionally
have no Doctor reason. Preserve strict plugin/code/version/core-step checks and
historical warning-only reports; successful-update admission still rejects
refusals. Keep the local TestHomeMode alias private and satisfy helper lint.
PR: https://github.com/openclaw/openclaw/pull/134490
* fix(plugins): preserve declared catalog identity during upgrade integration
Carry the prepared, provenance-validated ClawHub package instead of discarding
it into a boolean. Suppress the declared installed counterpart without deriving
an npm identity from overlaid display metadata or hiding an npm namesake.
Keep lazy prepared catalog facts and first-normalized-record icon behavior.
Retain explicit ClawHub-only actions and npm-first dual-source actions, and
cover the selected source's pinned inspection metadata with existing tables.
The incoming duplicate-row cases fail before the provenance fact is retained.
PR: https://github.com/openclaw/openclaw/pull/134490
* fix(ci): include home isolation in PR anchor closure
Register the three runtime dependencies in the canonical extraction and trust inventory. Extracted planners and publishers now load the real home policy, context, and selection modules without stubs or weaker assertions. The existing extracted-anchor regression fails before this change and the full wrapper suite passes afterward.
* fix(update): hand failed upgrades to local coding agents
Route interactive update failures through triage after updater ownership is
released. Preserve the captured installation, invocation directory, bounded
diagnostics and original update result while the installed coding agent
repairs and verifies the machine using its existing permissions.
Keep background and JSON guidance consistent, preserve config references,
and fix resolved consent failures and selected catalog source provenance.
Validation: complete combined P2 review, 639 focused tests, 71 UI unit
tests, and four Chromium scenarios passed. Full changed-code checks passed
all typegraphs but stopped on one no-map-spread lint error in a test fixture.
Local integration checkpoint: fix that fixture and combine the current main
triage owner before final review, package proof, publication, or landing.
* fix(update): preserve configuration and verify upgrade recovery
Prefer npm before ClawHub only among declared plugin identities, preserving explicit source/version intent, artifact integrity and capability consent. Keep the exact installed beta cohort and require typed target absence before fallback.
Preserve authored environment references through both Doctor writers, resolve snapshot destinations at operation time, and keep migration-only metadata out of redacted snapshots. Avoid loading channel runtimes for unused pairing account facts while retaining captured migration-owner attribution.
Record activation safety at package/Git mutation boundaries. Keep installed-CLI recovery, verify runtime/native-service identity, fence Windows autostart, preserve child status, and avoid duplicating consumed notifications or rejecting completed install switches. Surface update-specific disconnect diagnostics without changing explicit-restart guidance in Model Setup.
Retain the upgrade-survivor first-hop, approval and installed-version oracles. Repair CI's type-only Doctor cycle and stale source-policy, final-Doctor and Teams whitespace expectations without weakening timeouts, gates or the main-owned Markdown fix.
PR: https://github.com/openclaw/openclaw/pull/134490
* test(msteams): align the corrected main whitespace fixture
* perf(ui): remove unreachable update translations
Remove superseded version-only verification copy and the unused idle label from the eager catalog. Keep identity-aware verification and all recovery guidance unchanged, align translation fixtures, and restore the existing merged startup budget without increasing its baseline or limits.
* fix(update): retain consent failures and isolate validation homes
Carry unresolved non-retained plugin capability refusals from missing-install
repair through post-core convergence as typed outcomes, preserving the existing
update failure and restart boundary. Keep usable retained artifacts and
transient fetch failures on their existing notice/warning paths.
Give test invocations a native process HOME before config imports and worker
creation. Preserve bounded live/profile context, report selection, installed
tool caches, and process-group/pipe-owned namespace cleanup or truthful
retention. Keep unknown or mixed explicit real-home selections closed.
Resolve the repo-owned staging helper from its owning cwd and await complete
PID readiness before cancelling native report fixtures.
Align the survivor recovery oracle with typed consent errors that intentionally
have no Doctor reason. Preserve strict plugin/code/version/core-step checks and
historical warning-only reports; successful-update admission still rejects
refusals. Keep the local TestHomeMode alias private and satisfy helper lint.
PR: https://github.com/openclaw/openclaw/pull/134490
* fix(plugins): preserve declared catalog identity during upgrade integration
Carry the prepared, provenance-validated ClawHub package instead of discarding
it into a boolean. Suppress the declared installed counterpart without deriving
an npm identity from overlaid display metadata or hiding an npm namesake.
Keep lazy prepared catalog facts and first-normalized-record icon behavior.
Retain explicit ClawHub-only actions and npm-first dual-source actions, and
cover the selected source's pinned inspection metadata with existing tables.
The incoming duplicate-row cases fail before the provenance fact is retained.
PR: https://github.com/openclaw/openclaw/pull/134490
* fix(ci): include home isolation in PR anchor closure
Register the three runtime dependencies in the canonical extraction and trust inventory. Extracted planners and publishers now load the real home policy, context, and selection modules without stubs or weaker assertions. The existing extracted-anchor regression fails before this change and the full wrapper suite passes afterward.
* fix(test): preserve source home when loading profiles
Read the explicitly selected profile with a non-login Bash command so
system and user login startup cannot replace the source HOME first.
Keep positional profile quoting, child-only HOME/USERPROFILE, existing
profile opt-in and test/native-home isolation unchanged.
The existing six profile-home matrix cases failed on Linux CI run
33536959196, job 99953769387. New exact-head Linux CI remains required;
this local repair does not refresh or admit the prior native proof.
PR: https://github.com/openclaw/openclaw/pull/134490
* fix(update): complete failure triage integration
Keep landed failure diagnosis after recovery and cleanup decisions without
letting diagnostic exports authorize activation or overwrite updater exits.
Preserve exact unsafe handoff and nested foreground results, consumed
notifications, successful install-root switches, typed consent failures and
update-specific disconnected guidance alongside main's triage takeover.
Contain diagnostic read failures inside the diagnostic owner so a completed
recovery still releases its lease and sensitive files. Retain phase-labelled
updater, recovery and diagnostic exits plus helper terminal completion.
Remove the trivial aggregate-error wrapper while preserving both failures,
and consolidate launchd/notification coverage into canonical test support.
Focused CLI, Doctor, handoff, UI and profile-home proof passed under external
synthetic homes. Complete integrated P0 review is scoped-clean; exact-head
Linux CI and native/package qualification remain with the parent workflow.
The unchanged main models-cli auth-login test-type error remains a follow-up.
PR: https://github.com/openclaw/openclaw/pull/134490
* test(update): split Doctor and service recovery fixtures
Move the existing Windows Doctor recovery matrix and shared fixtures into
focused files, and keep managed terminal-outcome tests in their existing
result helper. Preserve all case bodies, assertions, and hook cleanup.
Keep Windows restore failure in a local variable and narrow the triage
prompt-write fixture path before string matching. Scoped type-aware lint,
all affected existing suites, and independent follow-up review pass.
The full repository gate and final packaged Crabbox recovery and upgrade
proof remain required before landing.
* fix(update): retain plugin attempt spec on consent failure
* test(update): preserve runtime exports in option mocks
---------
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
* fix(computer-use): unblock the macOS live-rig proof flow
The rig ran its operator CLI and its proof runner from one state dir, so both
shared one device identity. A paired operator device is pinned to the scopes of
its first connect, and `nodes list` connects first for `node.pair.list`
(operator.pairing); the proof runner then needs operator.write, which is a scope
upgrade the gateway never approves silently and which no rig client can approve
for itself. The proof runner is a GATEWAY_CLIENT/BACKEND client, so on a
loopback auth-none gateway it is admitted unpaired with the scopes it asks for:
giving the CLI its own `cli-state` identity is enough, and `agent-state` now
never accumulates a pairing row.
`nodes list` also read `node.list` through the plain CLI client while
`nodes status`/`describe` used the diagnostics ladder. On any gateway where the
CLI must pair, the unfiltered list silently dropped connected/commands/
computerUse and `--connected` failed outright, so the documented rig gate could
not confirm the node. Both call sites now use `callNodeDiagnosticsGatewayCli`.
Docs drop the `devices approve <requestId>` instruction, which was circular:
that invocation is its own new device identity.
* test(cli): share the runtime-log formatter across nodes CLI e2e files
The extracted diagnostics-auth file stringified captured log arguments directly, which the type-aware core lint stripe rejects (no-base-to-string). Move the existing formatter into the shared node test helpers instead of duplicating it.
* fix(cua-computer): prove Linux X11 live vertical
* test(computer-use): authenticate isolated Linux rig
* fix(gateway): refresh computer use after node approval
* refactor(cua-computer): resolve the plugin manifest by static import
* fix(gateway): break plugin runtime import cycle
* fix(computer-use): bind live rig to committed helpers
Stream bounded browser camera frames directly to Gemini Live and keep camera media off the Gateway. Add lifecycle, function-calling, fake-camera E2E, and live-smoke coverage.
Co-authored-by: shushushu <1064076525@qq.com>
* feat(tooling): enforce noUncheckedIndexedAccess in the scripts lane
Burns down all 153 scripts-lane errors (bench aggregation, release
checks, i18n inventories, argv indexing) and flips the flag in
tsconfig.scripts.json. Direct-Node-executed release harness scripts use
local narrowing instead of workspace imports, which do not resolve
under plain node execution. Benchmark measured loops untouched.
* fix(scripts): import expect helpers via relative package sources
tsconfig path aliases resolve from cwd under tsx, so release wrapper
scripts running against old release target cwds could not resolve
@openclaw/normalization-core (not a linked root dependency). Relative
package-source imports match the established pattern on the adjacent
lines and are cwd-independent; old-target planning verified directly.
* feat(tooling): add tsgo typecheck lane for scripts/**
* fix(scripts): burn down scripts type debt surfaced by the new lane
Typing-only except bugs the lane surfaced: gh-read timeout race,
Discord Headers spread dropping entries, undefined allowedHeadBranches
match, plugin-boundary matchAll crash. Deletes retired config keys from
fixtures/benches (prompt snapshots regenerated, config dump only) and
the orphaned non-runnable sync-moonshot-docs script. Adds full-surface
.d.mts declarations for existing .mjs boundaries.