Two nav repairs (an orphaned reference page with a real inbound link, and
two start/ pages sitting under Help > Community), Related lists and index
cards that omitted whole top-level areas, and a plain-English pass over the
pages carrying rate findings.
Hard STE violations across the 46 measured pages: 649 -> 334 at the 25-word
cap, 767 -> 388 at 20. Every page named by a rate row is now under 1.5 at
both caps except reference/templates/AGENTS.md, refuted separately.
Co-authored-by: Vincent Koc <vincent@openclaw.org>
* docs: fix accuracy findings in concepts, start, install, and help
Corrects statements in the onboarding docs that disagree with the code, and
scopes version-locked claims to the release that changed them.
Each change is backed by a source reference; findings that turned out to be
wrong about the code are listed in the PR body rather than "fixed".
* docs(retry): separate Discord Gateway reconnects from request retry defaults
The "Applies to" column listed gateway reconnects alongside Discord sends.
The WebSocket reconnect loop does not use that envelope: gateway.ts allows
50 attempts and backs off from 2000 ms with no jitter, while retry.ts governs
per-request retries only.
Addresses the ClawSweeper P2 finding.
* fix(auth): reconcile Gateway secret guidance and macOS password prompts
* test(config): align Gateway secret help selectors
* chore(macos): move the remote password prompt change to its own PR
* feat(onboarding): quick-start lane opens the web dashboard from one prompt
Fresh unconfigured installs (including npx openclaw@latest) now offer a
single lane select after the security note: Quick start detects existing
AI access (Claude Code / Codex CLI logins, API keys), verifies it with a
live completion, persists the config, and opens the Control UI from a
foreground Gateway - no service install, Ctrl+C stops it and the config
stays. Custom setup preserves the full guided wizard unchanged; when
detection finds nothing usable, quick start falls back into manual
provider setup and the normal flow.
Setup apply gains an installDaemon passthrough so the wizard can skip
service installation (and Linux linger enablement) when the caller hosts
the Gateway in the foreground.
* refactor(onboarding): keep wizard i18n schema as a plain tree alias
The stringly-typed t() resolver with English fallback never needed the
partial required-key intersection; locale parity for the quickstart keys
is covered by the locale files themselves.
* fix(onboarding): compress quick-start security note and honor foreground skip wording
Show a one-line security pointer before the lane choice and keep the full note and confirmation in custom setup. Correct fallback wording to explain that quick-start defaults remain during manual provider setup.
Report foreground startup for any non-external daemon skip when service installation is disabled. Add a brief agent bootstrap safety beat pointing to the security guide and audit command.
* fix(onboarding): preserve quick-start ownership and auth
Keep externally supervised Gateway lifecycles out of the foreground quick-start host. Deliver the existing one-time Control UI bootstrap on headless and browser-launch-failure paths, and keep SSH login coordinates explicit.
(cherry picked from commit 5780873915c27f11b92cbf662101cec57271484e)
* fix(onboarding): keep guarded discovery consent out of quick start
Preserve ask-first discovery consent from an interrupted setup by excluding a saved guarded access mode from the quick-start offer. Keep the guarded access prompt as the default and require look-around consent before scanning.
Regression proof: the incomplete-config test fails before the guard and passes after it, with no lane prompt, no automatic scan, and no full-access persistence.
* test(onboarding): skip through the always-offered manual picker in the guarded-consent regression
Main's #134907 makes the manual stage always offer Custom Provider, so the
declined-discovery path now reaches the grouped picker; answer skip to keep
the test scoped to consent preservation.
---------
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
* fix(desktop): preserve verified onboarding handoffs
Keep browser pairing grants separate from native transport credentials, preserve fresh-setup intent across activation and restart, and show owned activation progress and errors even for undiscovered models and scrolled forms. Align native recovery/cancellation feedback and onboarding documentation. Refs #131706.
* fix(ui): bind cancellation cleanup to its original setup attempt
* fix(ui): retire expired setup outcomes before presentation
* fix(desktop): retire rejected setup attempts
Record definitive setup non-admission at the Gateway boundary so browser and native onboarding release only their own rejected attempts. Retain uncertainty for requests that may have dispatched, and preserve terminal cleanup after presentation retirement.
Keep the macOS packaging ownership assertions valid when private scratch storage lives on an external volume. Linux busy/retry and real Ollama handoff, native transport/onboarding suites, browser flows, and isolated review are verified; final signed Mac live proof remains a pre-merge gate.
* test(macos): validate parsed DMG mount paths
* fix(onboard): honor explicit auth when keeping the current model
Co-authored-by: Jony <13896935+zyz619963502zyz@users.noreply.github.com>
* test(onboard): preserve existing config across wizard snapshots
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Jony <13896935+zyz619963502zyz@users.noreply.github.com>
Align copyable onboarding commands with the mandatory risk acknowledgement and an explicit health disposition for config-only automation.\n\nRefs #121951.
* feat(channels): add channel-owned setup contracts
* test(channels): align legacy setup fixtures
* chore(channels): regenerate config and SDK baselines after rebase
* fix(update): run fresh doctor after current-process core changes
* fix(channels): align add pre-scan with execution precedence
* style(cli): format channels-cli test additions
* fix(channels): restore option-before-positional channel resolution via metadata arity scan
* fix(channels): keep help flags out of metadata arity escalation
* test(update): mock fresh post-update doctor in current-process suites
* style: format review fixes and correct entrypoint mock type
* fix(channels): register only modern contract options for dual-publishing plugins
* test(update): align downgrade suites with fresh-doctor child invocation
* docs(channels): record empty-contract and input-forwarding invariants
* fix(line): keep the shipped --token switch as a channel access token alias
* fix(signal): stop treating exact cross-family loopback endpoints as bind-aligned
* chore(config): regenerate docs config baselines after second rebase
* style: format rebased channels add tests
* fix(channels): enforce field-key and flag-name agreement in setup contracts
* fix(signal): detect container endpoints for bare --http-url setup
* fix(signal): ignore unconfigured accounts in transport collision checks
* fix(channels): validate negated setup flags in contract and normalizer
* fix(signal): preserve existing transport kind when setup detection is unreachable
* style(signal): use direct boolean check in collision guard
* style(signal): type test config literals
* docs(update): record two-read design of fresh-doctor validation gate
* fix(channels): satisfy post-rebase architecture gates
* docs: refresh channel setup map
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* feat(onboarding): recommend plugins and skills from installed apps
Scan installed macOS apps during classic onboarding (TCC-free), gather
candidates from official catalogs + ClawHub search, let the configured
model pick genuine matches, and offer an opt-in multiselect install step.
Adds a device.apps node-host command (default-off sharing, Android-parity
envelope) so remote gateways can request a paired Mac's inventory, and a
wizard.appRecommendations kill switch. Custom setup-inference completions
no longer inherit the 32-token verification-probe output cap.
* feat(onboarding): recommend apps in guided flow
* fix(onboarding): harden app recommendations against ClawHub self-promotion
Third-party ClawHub skills are never pre-selected regardless of model tier
(publisher-controlled listing text reaches the matcher prompt and could
promote itself); their labels now say they install third-party code.
Installed-app scans follow symlinked .app bundles. Matcher output stays
bounded by the resolved model's own maxTokens budget (documented invariant).
* fix(onboarding): key official catalog candidates by resolved plugin id
Real catalog entries are package manifests without a top-level id; keying the
candidate map and channel/provider classification by entry.id collapsed the
whole official catalog into one undefined-keyed entry, so no official plugin
or channel was ever recommended. Regression test runs against the bundled
catalogs.
* fix(onboarding): satisfy lint, types, deadcode, and migration gates
Split the guided-onboarding test into a self-contained custodian suite to stay
under max-lines. Narrow app-recommendation exports (drop dead node-payload
normalizer, unexport internal types/helpers, route candidate tests through the
public API), replace map-spread with a helper, unexport device.apps result
types, add installedAppsSharing to node-host migration expectations, cast the
wizard multiselect mock, and regenerate the docs map.
* test(onboarding): register new live test in the shard classifier
* refactor(sessions): migrate runtime storage to sqlite
* test(sessions): fix sqlite CI regressions
* test(sessions): align remaining sqlite fixtures
* fix(codex): require sqlite trajectory recorder
* test(sessions): align orphan recovery sqlite fixture
* test(sessions): align sqlite rebase fixtures
* fix(sessions): finish current-main integration of the sqlite flip
Resolve the whole-store SDK removal across its owner boundary: drop the
loadSessionStore re-export and the registry whole-store wrappers, wire
hasTrackedActiveSessionRun into gateway chat, complete the
preserveLockedHarnessIds cleanup contract, flip the codex thread-history
import to storePath targets, and port remaining main-side tests from
file-store helpers to session accessor reads.
* chore: drop committed pebbles log, revert plugin-inspector bump, refresh generated docs
Remove the 1.8k-line .pebbles/events.jsonl work log from the branch, restore
the plugin-inspector advisory lane to main's pinned 0.3.10 so the supply-chain
bump gets its own review, and regenerate docs_map, the plugin SDK API baseline,
and the export-surface ratchet for the merged tree.
* feat(sessions): keep archived transcripts by default with zstd cold storage
Codex-style retention: deleting or resetting a session archives its
transcript as a zstd-compressed JSONL artifact (plain when the runtime
lacks node:zlib zstd) and keeps it until the disk budget evicts oldest
first. resetArchiveRetention now governs both deleted and reset archives
and defaults to keep; maxDiskBytes defaults to 2gb so retention stays
bounded, with archives evicted before live sessions. The cron reaper
follows the same knob instead of deleting archives on its own timer.
* fix(state): converge agent DB migration lineages and bound database growth
Merge coherence: run both structure-gated legacy memory-schema repairs
(flip-lineage drop, main-lineage identity rebuild) before the flip
migration so pre-flip v1/v2 and pre-merge flip v1/v4 databases all
converge, and hoist foreign_keys=OFF outside the schema transaction
where the pragma was silently ignored and the v1 sessions rebuild
cascade-deleted session_entries.
Growth guards: fresh agent DBs enable auto_vacuum=INCREMENTAL, WAL
maintenance releases freed pages in bounded passes (never a blocking
full VACUUM), and doctor reports state/agent DB bloat from freelist
stats.
* fix(codex): resolve the store path for thread-history import via the SDK
The supervision catalog passed the legacy sessionFile locator to the
storePath-targeted transcript mirror; resolve the agent store path with
the session-store SDK helper instead of a runtime-object seam so test
fakes and headless callers need no extra surface. Drop the obsolete
missing-session-id preprocessing case: sessions rows are NOT NULL on
session_id and upsert repairs id-less patches at write time.
* fix(sessions): fail safe on malformed disk-budget config and doctor stat errors
A malformed explicit maxDiskBytes disables the budget instead of
falling back to the destructive 2gb default the user never chose, and
the doctor bloat check skips databases whose paths stat-fail instead of
aborting doctor.
* fix(sessions): complete sqlite conflict translations
* test(sqlite): align hardening checks with maintenance
* test(sessions): inspect compressed transcript archives
* fix(tests): await session seeds and drop unused helpers flagged by CI lint
The five unawaited writeSessionStoreSeed calls raced their SQLite seeds
against the assertions, failing compact shards; the bloat probe drops a
useless initializer and the merged tests drop now-unused helpers.
* test(sessions): type legacy proof events directly
* test(sessions): align hardening contracts
* perf(sessions): read usage transcript sizes from SQL aggregates
Usage/cost scans walked every session and materialized every transcript
event just to re-stringify it for a byte estimate — the #86718 stall
class reborn on the DB. readTranscriptStatsSync sums stored JSON bytes
in SQLite without loading a single row.
* fix(sessions): re-root foreign-root transcript paths onto the current sessions dir
Restored backups, moved OPENCLAW_STATE_DIR, and rehearsal copies carry
absolute sessionFile paths from the old root; the containment fallback
kept those foreign paths, so migration read (and would archive) files in
the original root and reported local copies missing. Re-root the
canonical agents/<id>/sessions suffix onto the current dir when the file
exists there; genuine cross-root layouts still fall through unchanged.
* test(agents): seed harness admission through sqlite
* fix(sqlite): close agent db on pragma setup failure
* fix(doctor): compact and retrofit incremental auto-vacuum after session import
The migration is the sanctioned offline window: post-import compact
reclaims import churn and applies auto_vacuum=INCREMENTAL to databases
created before the fresh-DB pragma existed, so runtime maintenance can
release pages in bounded passes on every install.
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Fixes rough edges in the standalone install flow (install.sh -> openclaw onboard), found and verified by running the flow in a clean container and on a clean macOS Tahoe VM:
- Provider auth setup failures (e.g. the preselected "Anthropic Claude CLI" option on a host without a Claude CLI login) no longer kill the whole wizard. The interactive wizard notes the error and returns to the provider picker; explicit --auth-choice automation still fails fast.
- Onboarding config now persists before the channel/search/skills steps, so a crash or cancel during channel pairing no longer loses auth + gateway decisions.
- With model auth skipped, finalize no longer auto-sends the "Wake up, my friend!" message (which always failed with a provider auth error). The hatch seed is gated on usable model credentials and a "Model auth missing" note explains the next step.
- Search provider picker no longer labels non-key credentials (e.g. SearXNG base URL) as "API key required".
- install.sh no longer warns "PATH missing npm global bin dir" with manual fix steps after it already persisted the export line; it reports the PATH was updated and how to reload the current shell.
- Removed the dead interactive hooks onboarding step (setupInternalHooks); quickstart enables default hooks silently.
Verified live per fix in a clean Debian/Node 24 container and on a clean macOS 26.5 Parallels VM (wizard re-prompt, SearXNG label), plus wizard/onboard test suites and tsgo:core.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Fix live model inference edge cases across provider streaming, model switching, outbound delivery, and gateway tool resolution.
Includes live/provider issue fixes and leaves #89100 explicitly partial for the remaining FM-2 group routing case.