* fix: keep historical state repairs in Doctor
* fix: narrow added state column names before recording them
* fix: preserve Doctor repair ownership and prove retained history upgrades
* test: match native SQLite locations in ownership race proof
* test: distinguish published updater cron-history repairs
Keep explicitly linked GitHub accounts on one canonical person, preserving the primary public identity, consent, avatar, and mention Inbox across sign-ins. Search full names and verified handles, and render selected mentions as accessible person cards without changing permissions or literal copied text. Preserve Markdown reference links and selected labels.
The nullable primary-account field does not introduce a shared-state schema-version bump. Older single-account writers may discard secondary links or split profiles; backup restoration or explicit relinking is required after such a downgrade. This tradeoff was explicitly accepted and remains documented.
Preserve main’s shared-transcript page cache and committed resident profile-catalog publication while selecting the stable primary public account. Retain the record-coercion import needed by explicit mention rendering after the message-recovery refactor. Retain strict synthetic repository-identity request validation and cross-checkout assertions. Wait for committed startup child-roster work before measuring streamed-render budgets, keeping every budget and assertion intact; main owns the concurrent compact-planner fixture repair. Main now owns the repository-response and focused Codex fixture repairs; no duplicate fixture implementation remains. Earlier startup, Docker, cloud, database-fixture and wizard prerequisites are already on main and are not duplicated here.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Join canonical agent and shared-state SQLite cleanup in Codex fixtures and drain reusable disk-budget workers at file teardown. Concurrent drains share one completion so accepted scans finish and later worker reuse stays intact. Runtime lifecycle cleanup uses the same owner.
Add bounded, redacted native-worker diagnostics for extension-fork teardown stalls while preserving the existing failure deadline and Vitest termination and exit-joining ownership. No dependency patch, retry, schema, or public configuration change.
Exact-head CI run 35289664323 passed with zero pending checks. Native-resource regression, real-process shutdown scenarios, and 20 Linux pressure runs verify cleanup and unchanged failure outcomes. The original intermittent timeout was not reproduced verbatim.
Related: #150819. The voice-call fixture repair remains in #151187.
Fixes#151081. Reported by @ThaMan666.
Recover update repair for stopped externally managed systemd Gateways by preserving the existing external policy in fresh Doctor children and resolving shared systemd templates to the authenticated account instance. Keep the deployment owner responsible for stopping and restarting its service, with lifecycle and database admission still enforced.
Acknowledge untouched package-owner refusals once the installed version satisfies the resolved target. Revalidate the latest ledger record, exclude active updates and retained recovery, and preserve the original refusal detail and finish time. Runs that reached installation or finalization still require normal repair. No configuration, CLI, dependency, or database schema changes.
Parent-owned service parking for full repair of a running managed Gateway remains with #151003. The maintainer accepted this scope separation and deferred ClawSweeper's corresponding P1 and rank-up move to that companion.
Validation: exact-head CI run 35272975075 passed with zero pending checks; the review of record is scoped-clean. Recorded focused suites passed 2,766 tests with 6 skips, along with the runtime build and changed-code checks. Native systemd proof compared published 2026.9.4 failure with successful installed-candidate stopped-service repair. Legacy refusal acknowledgement used an explicitly synthetic record and kept the service PID unchanged.
Interrupted Gateway startup, update inspection, and CLI reads could leave large private SQLite staging copies behind. Reclaim abandoned copies through the existing snapshot lifecycle owner while preserving live readers, recent legacy copies, canonical databases, and backups.
Use SQLite lifetime tokens and parent admission to coordinate nested workers. Commit retirement before closing handles and removing data; retain control files until copied data is removed. Recognize released updater layouts and retain the 24-hour legacy age threshold. Cleanup failures remain warnings.
Run asynchronous reclamation in the existing SQLite worker. Callers can cancel independently without terminating a surviving caller's shared pass. When the last caller leaves, settle the current directory before stopping, and let later allocation recover the remaining backlog. Drain snapshot workers before shutdown cleanup.
Validation: exact-head CI run 35266032454 passed with zero pending checks on ab8037229203cc8a42735263637245f09477f2aa. Recorded focused proof passed 203 SQLite tests with one platform skip and 31 Gateway lifecycle tests. Published OpenClaw 2026.9.4 worker proof preserved fresh interrupted copies, reclaimed 202,375,168 aged bytes, and left source bytes unchanged. Review r4 was scoped-clean at P0/P1; the exact-head ClawSweeper review reported no actionable findings or before-merge moves.
Windows CI covers released-layout removal, independent cancellation, and directory-boundary settlement. Native Windows signal interruption and late-worker races remain a documented coverage gap.
Closes#149978. Related: #150091. Thanks to @vyctorbrzezowski, @Glucksberg, and @stwhwing for the production reproductions.
Run full member rows through the existing session-transcript read worker and recheck session identity and management rights after awaiting. Preserve actor evidence, ordering, missing-store behavior, incognito ownership, and the synchronous compatibility facade. Broader target, catalog, public-share, and projection reads remain with their existing owners.
Startup admission rejected missing or drifted canonical SQLite indexes before the existing writable schema owner could repair them. Let schema-21 agent databases reach that owner before readiness, retain strict checks for required tables, columns, ownership, integrity, and supported versions, and report each repaired or refused database in stable order.
Preserve the existing validated index repair and rollback path. No schema version, persisted table definition, dependency, public configuration, or CLI option changes. This is a bounded current-schema repair; the complete published-image schema-19-to-21 upgrade remains unverified and outside this change.
Evidence: exact-head CI run 35253609128 passed with zero pending checks; the accepted independent review is scoped-clean. Existing proof covers 1,553 state tests, 98 Doctor consumer tests, 1,147 outside consumer tests, changed-file checks, and isolated Gateway readiness with retained session tables and a clean integrity check.
Thanks to @dh-js for reporting the image-upgrade failure in #150797 and @n0sn3b for the multi-agent diagnostic report.
Related: #150797
Prevent credential-shaped values from appearing in public Vitest assertion diagnostics while preserving credential key names and value lengths. This exposure class was observed in CI run 35222673726.
Use one shared reporter factory and redaction policy for configured and CLI-selected reporters, UI/browser configurations, and native report merging. Scrub task errors, expected/actual values, diffs, source excerpts, and encoded GitHub annotations before delegating to the selected reporters. Preserve reporter options, failure exits, and native blob-merge rejection. Test console capture remains outside this boundary.
Application runtime and update behavior are unchanged. No configuration option, dependency, stored setting, schema, or application migration changes. The report owner generates temporary diagnostic configuration, so ClawSweeper's residual data-model compatibility checkbox does not apply.
Validation: 34 policy tests, four real child-run regressions, config/CLI inheritance checks, and four native report-merge cases are reported passing. The r2 review of record is scoped-clean with no accepted/actionable P0/P1 findings. Exact-head CI run 35249843668 is green with zero pending checks; no rerun was requested.
Related: #150898
Native Bash spill tests could exhaust their 20-second child deadline compiling TypeScript before the producer started. Prepare both real Bash tool and executor roots through the existing invocation-owned subprocess compiler, while retaining fresh children, native stream errors, exact Unicode output, private spill permissions, and process-group cleanup. Record the producer receipt on first output without relaxing the child or producer deadlines.
No production runtime behavior changes. Document the prepared fixture path and preserve standalone/watch source resolution.
Validation: exact-head CI run 35243435450 passed for 3026f59db61596091d846535cb93456eeb6a2181; native hosted CI/Testbox gates passed. Recorded author proof includes 286 passing Linux tests, 120 quiet and 120 pressured native cases, and 46 passing macOS tests after rebase. Codex and exact-head ClawSweeper reviews found no actionable defects.
Related: #150935
Skip unrelated pending archive publication for fresh session upserts with
maintenance disabled. Preserve publication for existing entries, resets,
removal retries, maintenance, and Doctor work.
A real archive collision reproduces creation failing after its session row
and transcript committed; verify successful creation and later archive
recovery through the lifecycle entry points.
Related: #130741
* fix(agents): attribute prompt-cache drops to system prompt suffix churn
The prompt-cache observation tracker fingerprinted only the stable system prefix, so a volatile-suffix change that re-caches OpenAI Responses instructions was reported as 'no tracked cache input change'. Digest the suffix separately and report a systemPromptSuffix change. Document the measured OpenAI cache behavior (1024-token breakpoint steps on the ChatGPT-backed route, suffix-change cost, session-sticky routing) instead of an unexplained plateau.
* fix(agents): preserve unexplained cache-drop regression coverage
Keep the runner fixture suffix stable and qualify provider cache observations.
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
---------
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Preserve signed generated-media references when completion and retry prompts pass through legacy reply parsing. Delimit vulnerable punctuation and literal quotes in the shared formatter, and keep explicitly delimited values intact in parse-output.ts through validation and fallback handling.
Retain ordinary unquoted cleanup, file-URL conversion ownership, attachment validation, current prompt modes, and missing-only recovery. Add producer-to-parser regressions and document quoted legacy references.
P0-P2 review is clean. The refresh onto 62507cc516 preserves the complete reviewed patch and all five file hashes. Retained Blacksmith Testbox run 35193105282 at the previous verified head proves 17 intended original-code failures, 557 passing candidate tests, and the complete selected changed gate. Fresh exact-head CI run 35215130600 passes with 140 successful jobs and a green rollup, including 39 current media-path tests and 18 current local-root tests. Those results satisfy ClawSweeper's refreshed-coverage requests; no introduced code or security defect was found. The previous unrelated Doctor fixture CI failure is fixed in the refreshed main by #150655. Final refreshed fingerprints and diff checks pass.
Fix Windows build and test cleanup when descendants outlive their command leader. Retain kernel Job ownership from admission, start owned cleanup on leader exit, preserve bounded terminal output, and release temporary-resource claims only after descendant extinction and output closure are verified. Preserve taskkill diagnostics and report unresolved survivors.
Reuse the native Windows Job bindings and one runtime/compiler entrypoint inventory. Keep CI planning dependency-free and preserve exited Gateway migration guidance. Installed updater behavior and persistent operator state are unchanged; no dependency, schema, configuration, deadline, retry, or baseline changes.
Validation: exact-head CI run 35229160236 is green, including both Windows shards. Recorded current-head Linux proof has 220 passing cases and 5 platform skips, with build and changed checks passing. Native Windows inherited-pipe proof fails before the repair and passes three serial runs afterward, preserving 256 KiB plus terminal output and verifying descendant extinction, closed pipes, and ownership release. Accepted Codex review is scoped-clean at P0/P1.
* perf(sessions): publish keyed row invalidations
Use one shared change registry and defer SQLite notifications until commit. Cover run, lifecycle, activity, metadata, placement, and store changes without adding snapshot owners; retain exact-key cold readers for the next projection step.
* perf(gateway): keep materialized session rows resident
Repeated session reads rebuild unchanged row data. Add a per-store projection that refreshes committed keys and retains prepared facts for list, describe, and event consumers. Retire the optional session prewarm and its unused count reader.
* fix(gateway): serve current session rows from memory
Keep lists, descriptions, and live row events synchronized with owner publications, including sharing and profile changes. Remove result caching, polling fences, and duplicate database-backed row builders.
* fix(gateway): preserve session row updates across cutover
Honor event clearing and exact incognito lookup, and keep Doctor renames and lifecycle events bound to current session identities. Extract owner and test helpers required by the line-cap gate.
* fix(gateway): keep projected session reads available to callers
Bind request contexts to their runtime projection and retain the local
resource host through deferred cleanup. Recheck description authority after
readiness and admit stores before capturing event identity.
Remove duplicate event presentation and migrate consumer fixtures to the
resident owner while preserving visibility and lifecycle checks.
* fix(gateway): preserve session snapshot consumers
Keep authorized incognito snapshots transient, preserve tool capture before reply completion, and bind transcript facts to their physical store. Update resident-reader fixtures for startup, ownership, and presentation timing.
* chore(gateway): keep fallback row helper internal
* test(gateway): compare keyed placement calls correctly
* fix(gateway): reconcile committed session row identities
Prevent worker deletions from reappearing and capture the current session
identity before background row materialization. Read chat thinking facts
from the prepared session-auth catalog and keep fixture stores alive until
detached work settles. Consolidate placement preparation and preserve the
series production-line reduction.
* fix(gateway): preserve admitted physical session paths
Report the admitted SQLite filename while retaining store locators for row selection. Keep test stores alive through their owning work, and measure creation and history state at their actual admission boundaries.
* style(infra): format shared registry invalidation signature
* test(gateway): initialize session fixtures before read admission
Hydrate simulated restart and media-history fixtures before invoking resident session readers. Seed the child database through its existing stopped-process boundary while retaining the read and rendering assertions.
* test(qa): bind media replay to its configured conversation
Open the QA session explicitly and verify its mock model before exercising attachment delivery and replay. Preserve the original model responses, rendering assertions, and timeout bounds.
* fix(gateway): retain profile authority for synthetic session reads
Trusted plugin callers now acquire current exact profile identity, aliases, and roles from the resident profile owner. Share that owner with selected-profile bindings and reuse the prepared describe capability so clean reads stay free of SQLite.
* fix(gateway): consume prepared stored model lineage
Preserve raw parent identity across global display aliases and follow current resident parents when inherited model facts change.
* fix(gateway): finish model source consumer cutover
Use the current prepared model-source reader in the embedded backend and session fixtures after the upstream contract change.
* test: align failure injection with current read owners
Keep profile-resolution failure isolation and failed bounded-read accounting under the current resident-profile and rooted-filesystem APIs.
* fix(gateway): preserve CPU and lifecycle snapshot ownership
Measure resident list work within synchronous CPU boundaries and retain failure isolation. Reject lifecycle enrichment without a captured row so queued events cannot attach successor sessions.
* test(gateway): repair resident projection fixtures
Expose the persisted-model resolvers used by local Gateway admission and include keyed publication dependencies in materialized wrappers. Join admitted recovery continuations before releasing fixture stores so their final writes retain a live target.
* refactor(gateway): retire superseded session list workers
The resident row owner replaces per-request inventory and page reads. Remove the unused worker adapter and its caches while retaining shared exact readers, admission checks, and generic worker support. Preserve authority and admission regressions at the resident boundary.
* test(gateway): align ACP fixtures with readonly metadata owner
Follow the ACP metadata reader to its readonly owner and remove obsolete type imports after the store-type extraction. Retain the existing metadata reuse and lifecycle assertions.
* fix(gateway): isolate projection from startup admission borrows
Keep pending agent stores unavailable to projection refreshes until preparation completes. Run projection work in its owner context and publish topology after successful admission, with fail-first background and capture regressions.
Retain unfinished agent database inspections under the Gateway lifetime so a slow healthy database no longer turns its foreground wait timeout into a fatal startup error. Keep affected agents degraded until inspection and guarded credential, session, and model preparation complete; healthy agents can serve in the meantime. Corruption and pending migrations retain Doctor guidance.
Compose deferred admission with the existing Linux spawn-broker owner. Shutdown cancels and joins retained inspection and preparation before broker cleanup. Preserve caller cancellation, foreground failures before handoff, and inherited auth snapshots within their selected state directory.
Thanks to @desksk for the report and offline integrity timings.
Validation: recorded focused and real SQLite-child/HTTP boundary proof, scoped-clean Codex review, and green exact-head CI. Published-updater and retained Windows-service compatibility remain unverified; the PR records the scoped Rank-up skip.
Closes#150574.
Related: #141918, #142179, #150444, #150564.
* fix: keep conversation list reads from blocking the gateway
Move cold Node session inventory and selected-page reads through the existing SQLite worker broker while preserving current final visibility and membership decisions. Bound idle worker references and reuse metadata without requiring a writable session handle.
* fix: integrate session list workers with current cache ownership
Adopt the shared cache revision API and preserve the required worker module export. Synchronize the single-flight regression through loader-entry signals and settle requests before fixture cleanup.
* test: align session list consumers with worker ownership
Observe the current worker-store API across shared test module resets, await database resource drainage before durable reopen, and run native consumers in forked owners. Keep projection and target-preparation assertions at their actual owners without weakening physical admission or timeouts.
* fix: bound session-list observers through page consumption
* test: isolate model catalog read budget from background work
* perf(sessions): avoid host adapters in metadata workers
Keep grouped entry reads with the existing entry cache and membership queries in the sharing kernel. Use the existing Kysely facade directly for node-only queries so read workers avoid importing writable scope and lifecycle setup. Preserve canonical admission, cache, membership, and final page checks.
* test(voice-call): await routed bridge connections
* perf(build): bundle TypeBox with the shared runtime
* test: preserve native TypeBox imports in legacy finalizer
* perf: overlap independent session inventory reads
Prepare one target plan, preload at most four inventories, and assemble through the same ordered reader as synchronous callers. Join started reads before reporting failures and preserve earlier canonicalization and admission errors. The bounded candidate passes 65 focused cases and selected checks; latency and peak memory still require matched qualification.
* perf: transfer serialized SQLite worker replies
* fix(build): preserve native TypeBox validation registries
Keep the extension loader and external tool-dispatch validator on the same
Format and Settings registries. Remove forced TypeBox bundling and the
legacy-finalizer exception it required; retain the canonical virtual
subpaths used by extensions and sealed builds.
The original compiled dispatcher executed custom-format-invalid arguments.
The repaired built flow rejects format, shape, and exact-optional failures
while preserving valid tool execution. Focused tests, full build, typed lint,
and independent review pass. A controlled local comparison preserves cached
and concurrent list latency, with additional first-use and reopen cost.
* fix: include shared worker bytes in PR wrapper sources
Bound Gateway post-ready memory growth on large fleets by sharing one catalog worker and one transcript-reconciliation worker across configured agents. Preserve task-specific credentials, source generations, guarded transcript writes, exact lease recovery, and complete shutdown drainage. Expose owner-recorded worker-pool diagnostics without new operator settings.
Keep duplicate catalog discovery removed through the credential snapshot handoff and publication joining already integrated on main via #150026, with pool-level request-count integration coverage. Register catalog worker retirement before installing its listener, and reject stale publication before retaining generations or joining auth work.
Related: #149538. Thanks to @609NFT for the fleet measurements and constructor-attributed rerun that identified retained catalog isolates.
Validation: exact-head CI passed for 40cdb969512cdf299e0d11f0a8caba91e6d6f8c5 (https://github.com/openclaw/openclaw/actions/runs/35183530133); the authorized review of record and exact-head ClawSweeper review found no actionable defects. Recorded 200-agent prior-head measurements reduced post-ready RSS growth from 2144.7 to 250.5 MiB while preserving 1600 searchable rows and clean shutdown. Later lifecycle corrections have targeted regression proof. The candidate-specific published-updater transition remains explicitly excepted; final-head RSS and the reporter's 632-agent Linux allocator outcome are outside the measured claim.
Retain conservative maintenance age facts across unrelated commits and metadata writes while explicitly invalidating historical backdates, restores, imports, and repairs. Keep the periodic recheck deadline with the transaction-aware fact so timed and inline maintenance share one expiry owner, including replacement-only flows.
* fix: preserve file operations with fs-safe 0.13.0
* fix: preserve native filesystem consumer behavior
* build: adopt verified fs-safe 0.13.1 artifacts
* test: align release inventory with deferred plugins
* test: make temp permissions and staging swaps deterministic
Exercise the real secure-temp resolver for private-root creation and repair while preserving shared-parent permissions. Keep replaced staging inodes open through publication so Linux cannot immediately reuse their identities; retain the strict rejection and cleanup assertions.
* test: isolate logs in diagnostic environment fixtures
Select an isolated log file while mocking the logical platform and restore the previous override through the logger owner. This keeps cold Windows runs from failing before the second port poll while preserving the existing environment and signal assertions.
* test: assert Fish-quoted completion profile paths
Check the complete guarded Fish source block instead of searching for raw Windows paths. Preserve installation, idempotence, cache, and command-registration assertions, and verify a fixed Windows path against a literal quoted reload command.
Preserve shared beta/latest comparisons in a versioned pooled representation.
Keep full facts, logical digests, historical receipt support and admission limits.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
Use the existing two-agent preflight budget and scoped reclamation workers to overlap first-admission certification. Retain each worker across its agent's batches, join native close before downstream consumers, and drain active tasks before surfacing a refusal. Keep ordinary archive FIFO and runtime worker reuse intact.
Preserve process-local physical proof and per-agent write authority. Keep legacy-main and managed-worktree startup detection-only after #150110, report pending worktree repairs from awaited found counts, and leave repair writes with Doctor.
Related: #149538, #148529, #149323, #150110. Trigger: #149388. Reported by @609NFT.
* perf(sessions): yield detail projections and refresh retention
Reuse the session-list worker and one shared projection budget for sessions.describe. Read the current target, permissions, liveness, placement, and display time after asynchronous work while preserving complete topology and strict database admission.
* perf(sessions): budget registry snapshot preparation
Honor the shared projection budget before accepting cached or worker registry rows. Recheck the budget after coalesced yields while keeping accepted rows, raw-memory winners, and retention classification in one synchronous continuation.
Preserve the shared failed-fill cohort and synchronous callers. Cover registered list/detail scheduling, snapshot freshness, and retirement at the preparation boundary.
* fix(sessions): preserve failed-read cohorts across publications
Keep pending and failed-fill waiter identity when same-owner named updates touch the partial registry cache. Reset, rebinding, full replacement and admission retirement continue to fence readers.
Exercise named updates and deletions during the failed or absent fill budget pause, including later independent retries and publications following explicit invalidation.
* fix: preserve Windows credential reads with fs-safe 0.12.0
* test: preserve compiled fs-safe configuration checks on Windows
* test: drain workspace page routes before closing fixtures
* ci: move heavy main checks to 16-vCPU runners
* perf(cli): avoid eager protocol schemas in cron registration
* test: align prerelease workflow expectation with main CI
* test: resume pending MCP Code Mode fixture calls
* test(agents): cover cloned admitted normalizers
Extend the canonical assembly-array fixture from #149662 with an admitted provider that returns cloned tools. Preserve its metadata, catalog, successful execution, abort-wrapper and post-disposal assertions. The production Array.from owner remains unchanged on main.
* ci: spread Control UI checks across twelve shards
* docs(ci): align runner guidance with current placement
* ci: route trusted hybrid preflight to Blacksmith
* test: align hybrid preflight runner table
* ci: retain real-Gateway failure diagnostics
Keep captured browser JSON and screenshots in an attempt-specific artifact when the real-Gateway CI job fails. Reuse the ordinary Control UI upload policy with seven-day retention and ignore absent captures, while preserving test commands and sanitized proof uploads.
Extend the existing workflow guard and document that diagnostic artifacts are not sanitized public proof. The new guard fails before the fix; all 18 focused alias, workflow, and command cases pass afterward. Workflow lint, selected changed-file checks, and independent review pass.
* fix(ui): preserve agent panel intent while route data loads
A reused Agents page retained its initialized flag after its route data became pending. Roster initialization could then navigate through the default Overview panel, replacing an intended Files route. Require current route data before navigation and panel work, and clear initialization when the pending update applies.
Keep explicit Settings selection revisions authoritative when the loader completes. Four focused regression cases fail before the repair with the reproduced Overview URL; 136 adjacent cases, targeted lint, formatting and independent review pass afterward.
* ci: publish allowlisted UI failure summaries
Keep raw browser reports and screenshots out of automatic CI artifacts. Write an explicit public projection from the existing failure owner and select only its fixed filename in ordinary and real-Gateway jobs. Raw captures remain local, and fixed private filenames keep sensitive labels out of logged paths. Older frozen targets without the summary produce no matching artifact.
Preserve original failures and manual sanitized proof capture. Sensitive-sentinel regressions cover nested state, route parameters, labels, errors, models and content, including evaluation, screenshot and storage failures. All 10 helper cases, six workflow/command cases, workflow validation, plain Node import and selected changed-file checks pass; independent review found no actionable issues.
* fix: align FileTransfer with fs-safe 0.12.0
Upgrade the FileTransfer dependency introduced by #148881 to the same exact version used by core, OpenShell and 1Password. Regenerate the importer with pnpm 12.3.4 and retain all other lock entries.
Strengthen the existing orphan-WAL collision regression with equal-length, different-content bytes so recovery exercises the shared hash path and preserves the existing quarantine. Frozen installation, the 16-case sidecar suite, 18 tool-policy cases and 23 UI/diagnostic cases pass on the integrated source; independent review found no actionable issues.
* test(ui): retain safe Canvas failure diagnostics
* test(gateway): model live child execution in stop proof
* test(ui): inspect HTML sandbox after render readiness
* test(cron): cover event schedules after API state updates
* ci: count hosted rows after hybrid preflight routing
Use the existing asynchronous keyed-store reader for review decisions and
pending lists, and reject results after live channel authority closes.
Preserve synchronous review requests, decisions, and completed-row retention
under their existing uninterrupted authority-check-and-mutation contract.
Keep existing digest identity, stored JSON, capacity, retention, and older-host
read adapters. Reuse canonical database cleanup in shared flow fixtures and
exercise registered review commands, pipeline behavior, and cold worker reads.
* perf(sessions): reuse maintenance age facts between writes
Skip repeated retention candidate scans when neither the cap nor an age
boundary can change an entry. Keep facts with the existing connection
revision owner and invalidate them on rollback or untracked writes.
Schedule idle age maintenance through the existing kick, preserving cap
buffering, forced cleanup, and lifecycle protection.
* fix(sessions): break maintenance revision type cycle
Move the shared connection revision into a leaf contract so entry snapshots
and maintenance age facts no longer create a type-only import cycle.
Preserve complete Anthropic checkpoints, bound branch summary requests,
and keep recovery attached to the active session. Clear inherited runtime
claims when branching or restoring a checkpoint, preserve committed
compactions through later cancellation, and count native completions once.
Remove obsolete test-only compaction exports and copied retry tests.
Exercise real provider compaction, SQLite reopening, and tool-only memory
recall through the supported transport and managed-runner paths.
* test(agents): cover owner-driven subagent read caching
Protect idle reads, keyed updates, full replacement, restore, and cold
writes from repeated scans or incomplete retained-run snapshots.
Replace TTL-only expectations with explicit owner publication.
* perf(agents): keep subagent read snapshots until owner updates
Stop full SQLite reloads after idle 500 ms windows in session lists and
maintenance reads. Patch loaded snapshots by key, replace them on full
writes and restore, and leave partial cold writes for complete hydration.
* fix(agents): publish committed completion changes to registry readers
Advance loaded run snapshots after atomic completion writes so readers
observe delivery changes without polling. Defer registry notifications
until the correlated subagent and task state has been published.
* perf(agents): wake collector waits only on registry publication
Remove the registry TTL polling cadence from agents_wait. Keep mutation
notifications, deadline handling, and abort cleanup so idle waits do not
re-read the registry and completed collectors still wake promptly.
* test(gateway): publish retained child fixtures through the registry owner
Seed outstanding child results through strict registry persistence so
loaded snapshots observe the fixture mutation. Preserve result visibility,
requester isolation, and unchanged delivery-state assertions.
Await worker-backed cold binding restoration at bundled entry points while retaining synchronous public APIs and snapshot writes. Include startup reconciliation in the existing cleanup boundary, and stop acquired binding managers on cancellation before client construction.
* perf(reef): move inbox cursor persistence off main thread
Use worker-backed comparisons for monotonic cursor writes, await persistence before publishing progress, and join admitted writes at shutdown. Preserve atomic older-host updates and synchronous transport callbacks; prevent overlapping direct drains from lowering the published cursor.
* test(reef): drain state resources before fixture deletion
Await canonical shared-state closure before resetting test policy and removing temporary databases. Apply the same ordering to native fixtures because native opens also publish identity bookkeeping. Keep runtime behavior and test assertions unchanged.