Anthropic tool loops could repeatedly write growing conversation history to the
prompt cache because a moving runtime-context carrier owned the checkpoint.
Use the existing replay lifecycle contract to exclude transient carriers from
both request builders while preserving retained anchors. Also omit empty beta
headers that caused direct API requests with thinking disabled to fail.
Add deterministic regression coverage and a packaged Docker test that verifies
real cache reads and incremental writes across two tool continuations and a new
user turn in both builders. Require that lane in stable/full release validation,
with explicit API-key preflight, no request retries, and a declared runtime entry
for dependency analysis.
Validation includes focused package/model/session and workflow tests, build and
package integrity checks, static checks, independent review, mock Docker, and
eight successful live Anthropic Docker requests. Hosted CI run 34379052492 passed
on the final PR head at attempt 2, after one unchanged browser-animation rerun.
Closes#140607
Thanks to @LightningWareLLC for reporting the regression and contributing the
lifecycle-aware cache repair.
Co-authored-by: LightningWareLLC <271410939+LightningWareLLC@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Fixes#140918
## What Problem This Solves
Configured Responses proxies did not receive the requested session-affinity header through OpenClaw's managed transport. Azure-compatible routes also lost the session and cache-retention values before client construction.
## Why This Change Was Made
The existing shared header policy now honors explicit affinity settings and cache-disabled omission. The executor prepares HTTP headers once for OpenAI, Azure, and continuation identity, removing the separate factory forwarding obligation. WebSocket requests retain their distinct turn headers and use the same policy.
## User Impact
Opted-in compatible proxies receive stable session-derived affinity across turns, while separate ordinary sessions remain distinct. Disabling cache retention suppresses generated affinity. Explicit caller headers retain case-insensitive precedence. The managed native default, unconfigured-proxy omission, standalone Responses default, and existing length clamp are preserved.
## Evidence
- Real Gateway `chat.send`, `agent.wait`, and history readback produced successful streamed replies on pinned main through both OpenAI-compatible and Azure-compatible loopback endpoints, while the requested affinity header was absent.
- The signed candidate passed the same successful Gateway flow. Fresh independent acceptance exercised 22 further successful turns across both SDK routes: same-session stability, separate sessions, cache-disabled omission, mixed-case caller overrides, no-option omission, and explicit opt-out. Every reply was visible and present in history.
- Two direct/prepared Azure regression cases failed against the incoming production code for the missing header. The repaired candidate passed 108 focused checks, covering public and managed API policy names, caller precedence, native WebSocket/continuation behavior, parsing/retry controls, and both Azure/Foundry SDK client branches. Formatting and the normal commit hook passed.
- [Exact-head CI](https://github.com/openclaw/openclaw/actions/runs/34340825407) supplies the full required checks and type-aware lint. The native scoped type-aware lint attempt hit its 4 GiB limit and remains failed evidence; its limit was not raised. The hosted type/lint checks passed. The sole failed child is an unrelated frozen-source fixture assertion in `live-docker-stage.test.ts`; independent source review establishes that its isolated Bash/Node read path cannot call the changed transport code. No matching main failure was found, so this classification relies on the inspected execution boundary rather than a claimed main reproduction.
The loopback tests use the actual OpenAI and AzureOpenAI SDK clients with synthetic provider responses. They prove header delivery and successful replies, not production cache performance or cached-token gains. Native-provider WebSocket/continuation, long-value clamping, and Foundry-service behavior have source/component coverage; no live production-service proof is claimed. Raw requests, credentials, session identities, and infrastructure details remain private.
Thanks @louisfy for the original repair and managed-alias correction. Contributor ancestry and earlier review history are preserved.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(ai): repair malformed streamed tool-call JSON instead of failing the turn
Fine-grained tool streaming skips server-side JSON validation, so a
finished tool_use block can arrive with raw control characters or
invalid escapes inside string values. The terminal parse currently
rejects the whole turn with "Provider completed tool call with
malformed JSON arguments".
Apply the existing repairJson string-literal repair (escape raw control
characters, double invalid escapes) before rejecting. Truncated or
non-object buffers still fail closed so a cut-off write never executes
with partial arguments. Attach privacy-safe diagnostics (argument
length, short hash, repair attempted) as the error cause without
echoing tool arguments.
Related: #135111
* fix(ai): scope terminal tool-call repair to Anthropic and preserve valid escapes
Address review on #141323:
- Gate string-literal repair behind an explicit option and enable it only
from the Anthropic Messages stream reducer, the transport whose provider
documents unvalidated tool input. OpenAI Chat Completions, Responses, and
Mistral terminals keep their strict contract.
- Add a preserveValidControlEscapes mode to repairJson so terminal repair
never rewrites a legitimate \n after a Windows-path-looking prefix while
repairing a sibling field.
- Mirror the bounded diagnostics onto errorCode/errorBody so
projectProviderError carries them onto the terminal assistant message;
assert them at the transport boundary.
- Add a loopback HTTP integration test that drives the real transport
client (no fetch mock) through repair and fail-closed paths.
- Stop exporting the diagnostics type flagged by knip.
Related: #135111
* test(ai): pin fail-closed rejection of truncated free-text tool arguments
Add the truncated exec examples from the #135111 discussion as explicit
regression cases so terminal repair can never shorten a cut-off command
into an executable one, and assert the command text never surfaces in
the error, cause, or errorBody.
Related: #135111
Related: #136257, #141852
## What Problem This Solves
Fixes an issue where users could enable a Fast choice that has no effect for a selected OpenAI, xAI, or MiniMax request. Models without a Fast alias and OpenAI requests controlled by an explicit service tier still fell back to provider-wide support.
## Why This Change Was Made
Provider metadata shares the existing alias and service-tier rules with request construction. The existing selected-model capability field carries the result to controls. Explicit-tier precedence, unknown native capability, and saved-preference clearing stay intact.
The rules use existing lightweight internal entries. MiniMax pricing and its proposed M3 paid lane remain separate work in #107378.
## User Impact
Known no-op Fast choices are disabled, while supported requests keep their current mapping. Typed `/fast` commands continue to set or clear preferences. The capability describes local request mapping; it makes no speed, pricing, entitlement, or native-runtime claim.
## Evidence
The real compiled Gateway and its authenticated client produced these results:
| Selected non-native request | Baseline capability | Candidate capability |
| --- | --- | --- |
| xAI `grok-4.3` | absent | false |
| xAI `grok-3` | absent | true |
| MiniMax `MiniMax-M2.5` | absent | false |
| MiniMax `MiniMax-M2.7` | absent | true |
| OpenAI Responses with explicit `flex` | absent | false |
| OpenAI Responses without an explicit tier | absent | true |
- All six rows remain available under the selected OpenClaw runtime. Public output excludes credentials, endpoints and private parameter records.
- Fresh independent acceptance passed all six metadata clauses after its own nonce command. Both Gateway runs stopped; the independent service recorded no remaining processes and enforced memory, CPU and swap limits.
- 43 focused checks pass: provider rules, selected-model/agent parameters, dynamic aliases, composed OpenAI/ChatGPT tier precedence, and the corrected auth-refresh expectation. Formatting and lint pass; the changed assertion and normal hooks were verified on Testbox.
- Baseline source is `127e3ffa30`, exercised through source-equivalent build `1b284af37e091fab9fc58297e4478a0f701ed6fd`. Candidate proof uses actual CI build `d85807c2b634c885fd1d5caa2d17c99cf5601d9f` from run [34291602461](https://github.com/openclaw/openclaw/actions/runs/34291602461). The later commit changes only the expected metadata in one test, so production proof remains valid at its original build identity.
- The earlier CI run caught that expected-row mismatch and two channel test timeouts before their injected reply callbacks. Full history is retained; those timeouts are not claimed fixed. Current results are in [PR checks](https://github.com/openclaw/openclaw/pull/142682/checks).
- Generic control, unknown-case and preference-clearing proof from #141852 is retained for unchanged consumers. Fresh acceptance covers the new public metadata; it does not claim browser clicks or vendor inference.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Align root, native source, plugin and companion version metadata with the published stable release. Preserve newer main code and translations, regenerate the channel catalog, and copy the exact tagged release-note section without adding another release train. Native appcast and locale refreshes remain with their independent owners.
Fixes#141374. Related #119712 remains separate.
OpenAI-compatible Chat Completions proxies can report `usage.cache_creation_input_tokens` at the top level. OpenClaw previously counted those reported cache writes as uncached input, which also used the wrong catalog price.
The shared usage owner now accepts that reported field after both existing nested write aliases. Nested values, including zero, keep precedence. Direct and managed streams use the same owner. The change adds two production lines and real HTTP regression coverage.
Application validation uses the documented `openclaw agent exec --config ... --state-dir ... --json` command with a configured custom Chat Completions provider and distinct synthetic prices. It resolves that provider, sends a real loopback `POST /v1/chat/completions` SSE request, and returns the final answer, usage and `costUsd`. Pinned main `0604bbce80` and candidate `275d8c64e38ce01a0a5ec1bd1272eadbb5872600` ran on the same isolated Linux/Node 24.19.0 machine with OpenAI SDK 7.8.0.
| Reported prompt 1500, read 1200, write 300, output 200 | Main | Candidate |
| --- | ---: | ---: |
| Uncached input | 300 | 0 |
| Cache write | 0 | 300 |
| Total tokens | 1700 | 1700 |
| Catalog cost at distinct synthetic prices | 0.001 | 0.001075 |
The final CLI output reports cache write 300, read 1200, output 200, total 1700, and `costUsd: 0.001075`. Its existing aggregate format omits zero-valued input; the underlying provider message records input zero. Both CLI commands returned their unique fixture answer and exited successfully after one configured provider request.
Independent application acceptance adds 26 CLI runs covering both nested aliases and zeros, billed zero and positive totals, absent writes, varied counts/prices, and malformed-counter diagnostics. Read-only checks of the application-produced session databases confirm the matching assistant messages, explicit input zero, write 300, correct costs, and per-call billed origins. All CLI children, servers and connections closed. The 140 package HTTP observations and 124 independent package requests remain complementary boundary coverage.
The contributed regression tests fail in four intended write-bucket cases on main; all 63 focused candidate tests pass. Formatting, focused lint and the max-lines/environment ratchets passed. Exact-head hosted CI is green in [run 34146536650](https://github.com/openclaw/openclaw/actions/runs/34146536650).
The package HTTP tests complement the configured CLI proof; direct package calls alone do not establish application routing. This is synthetic local-provider proof, not live vendor billing or a Gateway/UI session. Malformed-counter diagnostics distinguish the package's trusted-counter behavior from application normalization; this patch changes neither numeric-validation nor pricing policy. Bare invalid JSON retains the SDK error path. No top-level cache-read support, inferred counters, new configuration, or persistence change is included.
AI-assisted verification. Contributor implementation and credit are preserved.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Preserve a typed unfinished-tool-call diagnosis in live replies and chat history, including partial text, phased output and ordinary display caps. Keep execution admission, retry policy, refusal precedence and private-error redaction unchanged.
Related: #138874
Worked on by:
- @Takhoffman
Co-authored-by: Takhoffman <781889+Takhoffman@users.noreply.github.com>
Reuse the classified text, thinking, and tool-call collections and avoid joining text when replay needs content parts. Preserve Unicode sanitation, reasoning signatures, tool order, and the existing wire representation.
* refactor(crypto): share SHA-256 identifier helpers
Preserve raw digest slicing and logging label normalization in a Node-only normalization-core subpath. Keep browser exports and public logging contracts unchanged.
Proof: 453 old/new comparisons and browser-root compilation passed; independent review clean. Consumer and package gates continue in the PR.
* fix(build): resolve shared crypto source during type checks
NodeNext requires the exact TypeScript source mapping before package artifacts exist. A resolver probe fails without this mapping and resolves the canonical owner with it; independent review is clean.
* refactor: speed up cold Google policy checks
Share the existing Gemini classifiers through a lightweight AI entry so policy checks avoid streaming imports. Preserve historical SDK names and thinking/replay behavior; retain the existing policy cases with an import-boundary regression guard.
* fix: resolve Google classifiers in source-only plugin loads
Register the new AI internal entry in the native source alias table. Extend the existing host-parent resolution boundary test and verify PDF and provider context behavior without generated root or AI build outputs.
* fix(agents): preserve Responses cache prefixes across user turns
Keep runtime-context carriers append-only for the OpenAI Responses family so
previous tool rounds remain a stable request prefix. Treat carriers as part of
their user turn during compaction, reusing the structured marker used for LLM
conversion. Preserve transient behavior for other APIs.
* test(agents): keep provider replay proof outside core source
Place the provider-to-runner contract test with the existing plugin integration
suites so the core source boundary remains intact. Keep the same real policy,
submission path, successful tool round, and four API cases.
* test(agents): group native provider conversation contracts
Keep the reasoning and runtime-context cases in the existing tooling suite so
the compact hosted plan stays within its 80-job budget. Preserve all cases and
scope each provider's cleanup to its own suite; do not change runner limits.
Preserve text, thinking, and signatures supplied in Anthropic block-start events through the canonical stream reducer. Reuse the completed-signature path so streamed signatures replace initial seeds. SDK-oracle regressions and local HTTP proof cover seeded, seed-only, and empty-start sequences.
* fix(openai-completions): apply Anthropic cache markers on the managed transport
* fix(openai-completions): preserve string content and explicit long cache TTL
Avoid constructing replay keys when a managed call cannot record or use one, and reuse the record already prepared for the request. Preserve signature ownership, earlier-turn replay staging, argument identity, and the separate signed-parts behavior.
Use one bounded OpenAI downgrade diagnostic owner, remove the Responses-specific logger/cache and policy callback, and pass prepared projection facts directly into serialization. Preserve request policy and wire bytes. Related: #140692; follow-up to #140592.
Carry the original API through provider-stream dispatch and enforce store:false after payload hooks for native ChatGPT Codex Responses. Preserve non-Codex policy and supported request controls.
Verified final HTTPS payloads through prepared completion dispatch with synthetic provider responses. Independent behavioral acceptance covers direct, canonical, wrapped, malformed and sibling routes. All 38 focused tests pass; the regression cases fail on the original production code.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* refactor(ai): share Responses function-tool assembly
Absorb managed Responses projection and serialization into the existing converter while retaining caller-owned strict policy and diagnostics. Preserve wire order, omission, tool choice, and stream lifecycle. Add real SDK loopback coverage for both entrypoints. Related: #140590.
* fix(ai): preserve the Responses function-tool result type
Narrow the shared converter to the function tools it actually emits, retaining compatible strict-field omission. Shrink the assertion baseline after deleting the duplicate converter. This resolves the initial CI type failure and the final review index-only finding; the reviewed working tree already contained this correction.
* fix(agents): abort silent model streams while the consumer is parked
The LLM idle watchdog armed its gap timer only while the consumer sat
inside next() and cleared it as soon as an event was delivered, so a
provider that went silent while the consumer was parked between next()
calls was never aborted. Keep the watchdog armed from the first next()
until the producer settles or the iterator closes, re-armed by delivered
events, provider activity, and tool heartbeats. Report ChatGPT WebSocket
stream progress on the caller's signal so that activity reaches the
watchdog like the SSE path.
* test(agents): move parked-consumer watchdog tests to their own file
llm-idle-timeout.test.ts sits at the max-lines lint limit; keep the new
coverage in a sibling file.
* fix(agents): observe producer completion without consuming repaired results
Keep native EventStream completion independent of consumer result decorators, and retain historical pending-read guards for structural streams. Cover producer completion between malformed argument fragments and parked structural consumers.
Worked on by:
- @VACInc
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
---------
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Bound discarded-text allocations in prompt-cache keys, compaction instructions,
widget titles, typing previews, reply identifiers and Slack fallback chunks.
Reuse one pure code-point prefix helper across eight consumers while preserving
existing limits and output bytes. Keep newer streaming and one-pass owners intact.
Ordinary Unicode parity and isolated consumer measurements support the change.
The separate compaction seconds/RSS pair showed peak RSS increased by 244KiB;
no whole-process memory reduction is claimed. Preserve contributor ancestry
and carry the canonical CI repairs without expanding the performance scope.
Co-authored-by: xuyuanhao <aa9736195201@gmail.com>
Co-authored-by: 許元豪 <146086744+edenfunf@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* fix: send x-opencode-session header on OpenCode endpoints
OpenCode Go/Zen (opencode.ai) enforces an x-opencode-session header from 2026-09-06 and uses it for prompt-cache routing. Add an "opencode" session-affinity mode detected by baseUrl host (covers zen/go/v1 and zen/v1, OpenAI-completions and Anthropic transports). For opencode hosts the header is sent whenever a stable session id is available, without requiring the sendSessionAffinityHeaders opt-in; the flag-gated generic modes are unchanged.
Fixes#137165
* fix: emit x-opencode-session regardless of cache retention on OpenCode endpoints
Review follow-up: extract isOpencodeEndpoint (trailing-dot safe, parse guarded) shared by both transports; the compliance header now survives cacheRetention none; add Anthropic zen/go and OpenAI zen/v1 regression coverage.
* fix(opencode): identify conversations across all model transports
* fix(opencode): cover managed transports and preserve configured identity
* fix(google): merge model and stream headers case-insensitively
* test(opencode): use transport-specific model fixtures
---------
Co-authored-by: Ghilteras <Ghilteras@users.noreply.github.com>
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(agent): recover settled turns after websocket failures
Classify transport-level WebSocket failures at the provider boundary and carry completed-assistant failures through the canonical terminal outcome policy. Permanent close codes and timeout observations remain fail-closed.
Worked on by:
- @VACInc
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix: recover final answers after WebSocket disconnects
Worked on by:
- @VACInc
OpenClaw-Publication: dfe624ba-e8f9-4b4b-b100-7d095034170a
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(agent): finalize assistant-reported transport failures
Use the validated settled-turn recovery context as the provider-warning gate regardless of whether the provider failure was thrown or returned as an assistant error.
Worked on by:
- @VACInc
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* Publish openclaw/openclaw-openclaw-vacinc-issue-138959
Worked on by:
- @VACInc
OpenClaw-Publication: 7444a256-821a-41c7-9444-ebdc6714d3e2
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* test(agent): prove WebSocket finalization without replay
Exercise the real failed assistant through the shared attempt projector, terminal preparation, and tool-free finalization after HTTP and WebSocket failures. Preserve the completed tool and transcript exactly once.
Worked on by:
- @VACInc
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(agent): honor permanent WebSocket close disposition
Give the structured permanent-close marker precedence over retry-looking text in the existing terminal-error guard. Preserve refusal and no-replay behavior for ordinary retries and settled-turn finalization.
Worked on by:
- @VACInc
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* test(agent): adapt settled-turn fixture to current result API
Keep the same transport-failure assistant, transcript and settled-tool evidence while following the three-argument execution, settled and prompt contract introduced on main.
Worked on by:
- @VACInc
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
---------
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(gateway): honor UTC ordering in HTTP date validators
Use one strict singleton-date admission path for static and immutable byte
responses. Keep leap-second validators earlier than the following second,
while preserving the Retry-After ceiling and existing ETag/range policies.
Closes#140153.
* test(gateway): include distinct headers in static request fixtures
* fix(gateway): reduce cold model-runtime request stalls
Bind provider/auth/config operations at the native plugin loader boundary
instead of importing broad host execution graphs during registration.
Keep descriptor construction light and defer execution-only Codex/OpenAI
work to its canonical owners without changing synchronous auth, process,
logging, or lifecycle semantics.
Preserve full runtime readiness, authored cache/override identity, mutable
runtime method views, and invocation-bound latest session lineage. Remove
obsolete wrappers and the unused eager conversation startup path.
The isolated source reproduction reduced prepared refresh from roughly
291 seconds to 17 seconds on the same historical Linux proof setup. The
latest integrated ARM64 profile still measures 19 seconds; this does not
claim that all cold source-registration blocking is eliminated. Compiled
Gateway/browser catalog proof returned in 568 ms.
Protected Gateway/browser tests use fresh secretless VM/containers only.
No timeout/assertion, configuration, schema, dependency, or SDK budget
expansion. New private host seams require coordinated host/plugin release,
not independent publication with an older compatibility floor.
Refs #139867
* fix(plugins): finish native runtime import boundaries
Keep unused native policy facets lazy, use canonical type and profile-ID leaves, and reuse SDK lazy-method forwarding. Remove obsolete provider wrappers and repair lifecycle/catalog fixtures without weakening assertions or deadlines.
Validated with the original 273-file CLI selection (6841 passed, 85 skipped), the complete changed gate in a fresh secretless container, the final build, and isolated review. Context: #139911 and #139867.
* test(doctor): supply native auth in memory startup fixture
Register the real OpenAI plugin with the host model-auth contract while preserving all semantic-data, migration, SecretRef, and degraded-owner assertions. Both cases and the original 259-case CI shard pass in a fresh secretless container; typed lint and isolated review pass. No production changes.
* refactor(ai): share Anthropic protocol projection and stream reduction
Use one owner for Messages transcript projection, tool and generation parameters, and streamed event reduction. Retain standalone and managed transport policies, exact event contracts, seeded tool inputs, refusal handling, compaction, cancellation, and usage.
* test(ai): preserve seeded Anthropic tool inputs across transports
* refactor(ai): share Google protocol projection and stream reduction
Use one prepared-transcript projector and one stream reducer for direct Google SDK and managed transports. Preserve signed-part boundaries, event timing, usage and error contracts, native-video admission, route normalization, and plugin-owned authentication.
* refactor(ai): keep Google projection types internal
* fix: keep rate-limit retries transient in chat
* fix(agents): retain tool and media facts across retries
Persist failed-attempt facts before dependent results while deferring partial text and terminal diagnostics. Keep display overrides and code-source ownership consistent without duplicating tool facts or billing.
* fix: preserve retry recovery ordering after rebase
Reuse run-aware Gateway history recovery and consolidate its repeated-attempt coverage. Preserve oversized provider retry floors through error projection, keep non-rate retry status visible, and require newer run-event order before resuming terminal error projections.
* refactor(client): keep run event normalization in its owner
Re-export the existing Gateway run-event normalizer and types through the public session projection module. Remove the redundant forwarding wrapper and fix test lint after the history recovery consolidation.
* chore(deps): refresh seven-day-cooled dependencies
* fix: resolve dependency refresh CI blockers
Recheck caller cancellation after the OpenAI SSE iterator ends and before
Chat Completions can promote provisional tool calls. OpenAI 7.8 may end
an aborted iterator normally; preserve the shared transport's abort contract.
Wait for the fake WebSocket receive callback before emitting replies in
three Watch journal fixtures, retaining their existing timeout and assertions.
Point the QA release-policy catalog at the repository-owned plugin guide
after main removed its duplicate ClawHub publishing page.
The existing OpenAI regression fails before the owner fix and passes after,
with 243 owner/sibling tests and both transports exercised over real loopback
HTTP. The 58-test QA catalog suite, changed gates, AI package build, and
independent scoped P0 review pass. Fresh exact-head hosted CI, including
iOS lifecycle and production advisory checks, remains required before merge.
* test(mattermost): control loopback timeout deadlines
* test(ai): cover cancellation at normal stream completion
Prove the shared Chat Completions parser rejects an abort immediately before normal iterator return and never finalizes the provisional tool call. The regression fails with only the post-loop guard removed; 312 owner and sibling tests and the changed-file gate pass with the guard intact.
* fix(ui): preserve focused popovers during sidebar updates
Keep community invitation geometry deferred while a DOM-owned popover item has keyboard focus, even when Chromium reports no sidebar focus-within. Exercise background presence updates after real menu focus.
Distinguish independent Swarm child hydration from canonical roster refreshes in the held unread acknowledgement test. Preserve immediate badge clearing and prove an extra canonical refresh still fails the assertion.
Validation: 12 Control UI E2E cases and 431 related UI tests pass; the focused invitation case fails on the previous production condition. Independent Codex P0 review is scoped-clean.
* chore(deps): upgrade CUA and preserve published docs anchors
Upgrade CUA 0.22.0 to 0.22.2 with its coordinated accepted native
artifact records, and slugify 2.2.0 to 2.2.1 under the frozen seven-day
cutoff. Preserve Mint's published heading and component anchors before
counter allocation.
Synchronize the docs publisher's independent slugify manifest and npm
lock atomically with its parser; reject unrelated dependency drift after
rebasing the publish commit. Preserve every existing product security
exception, patch, toolchain document, and public configuration contract.
209 selected owner tests, source/publisher anchor corpus comparisons,
full changed checks and build, the exact dependency age/integrity audit,
and independent managed P0 review passed. Native CUA execution and
fresh exact-head CI remain required before landing PR #138199.
* chore(deps): refresh newly cooled September 5 dependencies
Advance the frozen seven-day selection to 2026-08-29T18:40:39Z. Update AWS, ACP, TUI, Discord types, Matrix WASM and duration formatting; align standalone broker Node types. Preserve main security exceptions and hold incompatible direct Zod upgrades.
* fix: align dependency refresh CI fixtures
Model the atomic publisher manifest/lock handoff in the process-fault fixture and execute its real validator before push. Preserve strict command matching, drain ordering and terminal rejection semantics. Inline the single-use reasoning-effort resolver to keep the shared stream below its existing line limit without changing cancellation or reasoning behavior.
* test(ui): await settled skill-menu geometry
Wait for the existing semantic and animation readiness boundary before comparing list and action widths. Preserve exact width tolerance, viewport bounds and read-only pin assertions; do not fast-forward animation or alter production styling.
* test(ui): bind live browser disclosures to their owners
Adapt the run/tool identity repair from 90c51add82 while preserving the existing 15-second overall observation budget. Remove live page-wide positional disclosure polling; keep history and inert-route assertions, and capture optional synthetic proof.