Commit graph

9370 commits

Author SHA1 Message Date
Peter Steinberger
c18ef6a423
build(plugins): emit declared private worker entries (#144821) 2026-09-11 03:02:51 -07:00
Vincent Koc
3456f50eb1
fix(ci): keep FRV dispatch inputs out of GitHub CLI arguments (#144815) 2026-09-11 17:44:33 +08:00
Vincent Koc
8ac24c73da
fix(release): reject fresh extended-stable checklist launches (#127215) 2026-09-11 16:59:46 +08:00
Vincent Koc
6aab56d5c2
fix(maturity): bind evidence to semantic taxonomy identity (#143976)
* fix(maturity): bind evidence to semantic taxonomy identity

Punchcard-Session: calm-river-harbor-jg

* test(maturity): brace historical evidence fixture loops

Punchcard-Session: calm-river-harbor-jg

* test(maturity): use QA test surface and explicit type checks

Punchcard-Session: calm-river-harbor-jg
2026-09-11 16:48:45 +08:00
Vincent Koc
57b1433566
fix(ci): allow FRV binary artifact reads (#144760) 2026-09-11 15:47:59 +08:00
Peter Steinberger
d9dd26fb6c
feat(ui): trace the run arc around collaborative session avatars (#144696)
* feat(ui): orbit collaborative session avatars while a run is active

While a sidebar session row has an active run, the two-identity lead avatar
(owner in front, one participant or the +N bubble behind) orbits in a shallow
3D circle: perspective scales the nearer face up and the farther one down, and
the pair swaps depth as it turns. Idle rows stay untransformed, so the pinned
28x20 stack geometry is unchanged. Reduced motion disables the orbit and a
queued run pauses it alongside the ring.

The mock dev scenario gains two running collaborative rows so the state is
reachable in `pnpm dev:ui:mock`.

* feat(ui): trace the run arc around collaborative session avatars

Replace the 3D orbit from the previous commit: the faces of a two-identity
owner stack now stay put, and while the row runs the lead slot draws the union
outline of the two circles instead of a round ring. A faint track shows the
whole outline and a quarter-length accent arc flows along it at the ring's
linear speed, dipping through the cusps between the faces. Single-face rows
keep the existing round ring; queued runs pause the arc and reduced motion
draws the outline solid. `renderSessionGlyph` gains `ring: "circle" | "pair"`
and the leading indicator picks the pair whenever the chip stacks a
participant or +N behind the owner.

Sidebar unit coverage asserts the pair trace on a running stacked row and the
round ring on a running solo row; the e2e idle geometry and queue ring
contracts are unchanged.
2026-09-11 00:27:07 -07:00
RoboClaw
088d0f5b87
fix(release): publish frozen plugins with valid ClawHub categories (#144615)
* fix(release): bind ClawHub categories to trusted tooling

Project reviewed single-category metadata through the existing isolated package
manifest overlay while retaining the frozen candidate version, runtime files,
package manifest, and generated channel configuration. Pack with trusted release
tooling before the unchanged transaction-sealing and approval boundaries.

Use existing reviewed category assignments; retain the shared runtime vocabulary
for acpx and codex. Do not change published npm artifacts or the final release tag.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>

* fix(release): keep category validation native-node safe

Extract the unchanged category contract into a dependency-free module so
pre-build packaging and updater entrypoints do not load compiled imports.
Preserve existing barrel exports and validation behavior.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>

* test(transcripts): keep capture lifecycle fixture model-free

Explicitly disable utility routing in the capture replacement fixture so
its real heuristic-summary and lifecycle assertions do not depend on a
provider metadata snapshot retained by an earlier test file. Keep all
assertions, deadlines, and production code unchanged.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-09-11 00:22:21 -07:00
Peter Steinberger
b7402c5b9e
ci: preserve tooling metadata in precise test plans (#144621) 2026-09-10 21:24:17 -07:00
Peter Steinberger
1f00d8ab16
perf(scripts): prepare coercion name matching once (#144253)
Preserve substring admission and AST ownership checks while removing repeated per-file name-array construction and literal scans. The full guard improved 48.85% and 53.63% in a fixed four-call ABBA comparison; all outputs matched. Thirteen baseline and candidate tests, all twenty changed checks, and independent Codex review passed. Retain shared-host, warm-filesystem and inconclusive memory qualifications in the PR.
2026-09-10 21:04:59 -07:00
RoboClaw
cf865a2289
fix(release): verify 2026.9.4 split publication recovery (#144638)
Admit the exact frozen 2026.9.4 publisher revision to the existing historical runner-header contract. Preserve every source, workflow, successful-step, time-window, shell-body, registry signature, provenance, and qualified Docker constraint.

Extend the existing acceptance/rejection table across both verified revisions. The actual split-publication verifier passes using retained npm and Docker evidence, without changing any published package or final tag.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-09-10 21:04:08 -07:00
Vincent Koc
7905e68405
refactor(test): separate worker declaration metadata from compilation (#144313)
* refactor(test): centralize worker declaration metadata

Replay the reviewed first tooling layer on the current frozen main base. Keep package activation declarations reserved for the later owning layers; preserve the inherited main build graph and test coverage.

* test: stabilize auth discovery and onboarding checks

Pair synthetic OAuth refresh with capability discovery. Retain the Android test synchronization landed upstream in commit 1237e647. No production code or timeout changes.

* test: isolate yielded session reset runtime

* test: align isolated Gateway inventory assertions

* fix(ui): let plain tooltips yield pointer actions

* test: preserve loose objects in Git corruption fixtures

* fix: keep tooltips lean and metadata snapshots refreezable

* test(android): pin approval reconciliation handler entry

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-10 21:48:26 -06:00
Vincent Koc
e62272f04a
refactor(docs-i18n): remove unused test translator (#144580) 2026-09-11 10:55:08 +08:00
Peter Steinberger
c916694931
refactor: remove unused auth warming from model browsing (#144560)
* refactor: remove unused auth warming from model browsing

Model browsing resolves route-aware auth, while failures and refreshes
still maintained a private provider-only cache with no current consumer.
Retire its worker, failure hook, lifecycle wiring, and test-only checker
options; keep canonical availability, native login preparation, external
CLI hydration, auth refresh, reload, and model publication intact.

Move retained preparation and selected-account tests to their actual
owners and preserve disk-reopen billing and healthy-profile fallback proof.

* test: prove provider auth recovery through the built Gateway

Replace the retired rewarm-log assertion with credential replacement and
models.authRefresh, then verify catalog availability and a successful
new-key response in history from the same Gateway process. Preserve the
HTTP429 retry count, HTTP401 persistence, scoped rate-limit state and
large configured-catalog proof. Rename the smoke and migrate both runtime
prerequisite and CI-plan references together.

Validated with 57 focused tests, staged changed checks and P2 review.
2026-09-10 19:22:52 -07:00
Patrick Erichsen
a321595f49
feat: download assets from the Browser sidebar (#144480)
* feat: download assets from the Browser sidebar

* fix(ui): size browser toolbar icons and show inline download progress

* fix(browser): save sidebar assets through the owning browser session

* fix(browser): align download request types and lint contracts

* fix(browser): enforce download policy before redirect traffic

* fix(ui): keep browser download assets off the startup path
2026-09-10 18:24:06 -07:00
Peter Steinberger
8f282c6939
fix(docs): preserve live links between fenced HTML examples (#144537)
Use the shared MarkdownIt parser to resolve fenced and raw literal boundaries before component preprocessing. Preserve containing quote markers during JSX removal so examples stay literal and the docs auditor reports live links at their original source lines.
2026-09-10 18:21:39 -07:00
Erick Kinnee
99a3f5152a
fix(plugin-sdk): expose focused async embedding batch contract (#129625) 2026-09-10 17:06:43 -07:00
Peter Steinberger
7b230efeac
fix(sqlite): speed up read-only snapshot startup (#144448)
* perf(sqlite): bundle read-only snapshot child independently

* test(build): retain standalone worker declaration coverage
2026-09-10 16:20:24 -07:00
Peter Steinberger
4cb202363d
fix(pr): recover partially written review transitions (#144431)
* fix(pr): recover partially written review transitions

Classify index and working-tree entries independently against the journaled
source and target before replaying an interrupted native restore. Preserve
foreign bytes, ignored overlaps, and hidden index metadata, including
intent-to-add and resolve-undo state. Rebuild the validated source index so
completed index deletions can still remove their remaining source files.

Preserve the reserved .local artifact namespace and existing journal endpoints.
Unknown zero-byte files remain refused rather than inferred as owned writes.

Validation: 66 native owner cases, complete changed checks, and independent
review. Regression cases demonstrate worktree-first and index-first recovery,
plus fail-before/pass-after coverage for intent-to-add and resolve-undo guards.

Related: #143802

* fix(pr): register the journal validator executable entry

* test(pr): preserve Git reader coverage for journal recovery

Exercise the active Node-helper Git reader in the failure fixture and keep operation artifacts in the reserved .local namespace. Record reader starts and delayed exits after stdout closure so successful validation still proves every producer joined before lock release.

Validation: focused reader cases changed from two failures to five passes; full operation-lock suite passed 114 tests with one Linux-only zombie case skipped on macOS. Complete changed checks and focused independent review passed. Production runtime bytes are unchanged.

* fix(pr): preserve leading BOM characters in Git path records

Treat Git output as pathname records rather than a BOM-framed text document. Preserve an initial U+FEFF while keeping fatal UTF-8 decoding, so an untracked lookalike cannot be misclassified as a target path before native replay.

The native regression previously changed HEAD before final refusal; it now preserves the source state. All 67 owner tests, complete changed checks, and focused independent review pass.
2026-09-10 15:48:05 -07:00
Peter Steinberger
238f099b0a
fix(ui): task panel squeezes subagent transcripts beside Show earlier (#144413)
* test(ui): mock a subagent task transcript with tool calls

* fix(ui): render task details as a compact activity feed

Show task titles derived from prompts, current progress, finished duration,
tool counts, and compact grouped activity across the full detail panel width.
Keep readers at the bottom for new activity and preserve their position when
loading earlier history.

Reuse the chat tool classification, reconciliation, summaries, and Markdown
owners. Remove the task-only full-chat renderer and transcript controller;
retain the independent full-page subagent avatar policy and inspector fallback.
Correct the mock transcript registry type without amending the fixture commit.

* fix(ui): use tool-kind icons in the task activity feed

* fix(ui): keep complete commands in expanded task feed rows

* fix(ui): keep expanded task feed commands free of template whitespace

* fix(ui): keep pending task feed scroll corrections across renders

* test(ui): align task E2E coverage with the activity feed

* fix(ui): recover capped replies in the task activity feed

Restore automatic full-message recovery for capped assistant replies in task
panels. Reuse the shared eligibility and retry contracts, load through the child
session and task agent, and keep recovery state scoped to the selected task and
connection. Preserve the preview during loading and offer Retry after three
failed attempts.

Cover recovery, stale results, and retry behavior with component tests and a
Tasks-rail mock Gateway E2E. Add a recoverable running-task reply to the dev
fixture and document the sessionless transcript limit.

* fix(ui): recover capped task replies once per message
2026-09-10 15:22:18 -07:00
Vyctor H. Brzezowski
38e0e2e9d4
fix(docs): render parameter labels containing angle brackets (#144390)
* fix(docs): preserve quoted component attribute boundaries

* fix(test): validate docs renderer payload before decoding
2026-09-10 18:51:42 -03:00
Peter Steinberger
8e9e753e7b
perf(ci): reuse verified frozen-source trees (#144421) 2026-09-10 14:41:37 -07:00
Peter Steinberger
dc6018d207
fix(status): project settled fallback models consistently (#134496)
Share the bounded, run-verified terminal model projection between Gateway
rows, /model and /status without changing stored selection or telemetry.
Render the prepared selected and active model facts, preserving literal
provider-local prefixes and the original entry's context provenance.

Remove duplicate selection and prefix-stripping helpers. Keep unmatched
fallback notices on the legacy usage projection path, and validate active
context budgets against the original session and final model identity.

Refs: #134496, #130706
2026-09-10 14:22:03 -07:00
Vyctor H. Brzezowski
0d1dabc08f
fix(docs): restore literal text in expandable titles (#144389)
* fix(docs): restore literals before encoding components

* fix(docs): validate encoded payload before decoding in tests
2026-09-10 18:17:21 -03:00
Vyctor H. Brzezowski
0203193f9d
fix(docs): preserve inline raw tags during preprocessing (#144393) 2026-09-10 17:41:49 -03:00
Dallin Romney
3af7ef33c1
fix(qa): close Crabline after gateway shutdown (#143992) 2026-09-10 13:40:29 -07:00
RoboClaw
7444f28d2d
fix(ci): prepare selected release native fixtures (#144338)
* fix(ci): prepare selected release native fixtures

Enable and prepare the selected native heartbeat live test through its
existing runtime build owner. Keep Doctor scenario and canonical-path
service shims on the same selected checkout while retaining trusted shared
helpers. Complete the managed test's ephemeral TCP endpoint adapter so
shutdown verification cannot observe an unrelated host Gateway.

Qualification context: https://github.com/openclaw/openclaw/actions/runs/34507645027

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>

* test(ci): bind live-shard cancellation to the test child

Use an isolated APNs-only inventory through the existing shard selector so
build preparation cannot masquerade as live-child readiness. Assert the
actual test:live arguments and join owned processes before fixture cleanup.

Preserve the original signal, descendant-death, and timeout assertions.
The original 20-file CI order passes all 332 tests after the correction.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>

---------

Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-09-10 13:26:13 -07:00
Ayaan Zaidi
496433f5ae
fix: retain setup credentials after a failed connection check (#144195)
Related: #136257

## What Problem This Solves

First-run setup discarded a credential after a failed connection check, which forced another sign-in. Managed local models could also receive a second verification turn with tools enabled.

## Why This Change Was Made

One setup owner now saves the selected credential through the existing auth-profile store, confirms the candidate configuration in memory with one tool-free provider turn, and commits configuration only after success. New submissions receive distinct profile identities. A rejected replacement therefore preserves both the working credential and the rejected credential, and setup cannot fall back to another profile during confirmation. Saved-sign-in retry reuses the saved profile without another login. Gateway activation reports completion only after releasing setup admission, so an immediate follow-up can start.

The cutover removes staged credential stores, promotion/rollback helpers, the detection worker, and the parallel verification path. Existing provider installation, scoped runtime generations, cancellation, relevant config conflict checks, protected credential checks, and error redaction remain with their owners. CLI wizard, Gateway setup, completion, and update-repair callers use the shared confirmation owner. Custom endpoint setup defers its preliminary completion to that owner.

## User Impact

- Failed confirmation preserves the credential and leaves configuration unchanged.
- Rejected replacement credentials cannot overwrite a working sign-in.
- Saved-sign-in retry runs a fresh confirmation without repeating login. A saved replacement remains selectable when it uses the current model.
- Local models receive one tool-free confirmation turn.
- No SQLite table, column, or migration is added.

Discovery retains the previous 30-second asynchronous deadline and returns completed saved/native/manual choices when a provider hook stalls. The worker is removed as part of this extraction. Synchronous plugin imports still share the Gateway event loop; the deadline does not restore worker isolation. Custom endpoint settings remain available for retry while the Gateway runs; after restart, those endpoint settings may need to be supplied again.

## Evidence

Pinned main `0f309a4cf1` reproduced the credential-loss defect through the shipped setup Gateway request with no configured default. Rejection left configuration unchanged but discarded the submitted credential.

Real-provider proof drives the compiled CLI Gateway in scratch state through the public setup requests. It records complete provider requests/responses and config/credential state before the request and after the result. Success, real HTTP 401 rejection, saved-sign-in recovery, and working-credential replacement are covered. Each setup confirmation uses the selected credential with `tools: []`; only success writes the selected configuration. Failed attempts and corrections remain in the private evidence record.

Focused validation includes setup activation, turn ownership, stalled discovery, Gateway/Control UI admission, wizard import and retry, provider adapters, protected routes, plugin persistence/index/registry, and auth planning. The initial cutover passed 816 targeted tests; the correction reruns the affected owners and adds replacement, exclusive-auth, and stalled-discovery cases. Formatting, syntax lint, unused-export scans, the max-lines/environment ratchets, normal commit hooks, and runtime builds passed. Full type checking and CI run on GitHub.

A real Chromium regression and independent browser pass show the saved replacement row on desktop and mobile, verify the saved-profile activation request contains no key or new sign-in, and observe success. This browser lane uses a mocked Gateway; the separate real-provider lane proves credential/configuration behavior.

The complete deletion ledger classifies every deleted or rewritten test file and identifies the current behavior owner. Production TypeScript remains smaller after the cutover.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-11 00:52:25 +05:30
Peter Steinberger
decc0d9e05
refactor(scripts): reuse SDK guard source inventory (#144298)
Classify core runtime files from the complete collected inventory using the existing test-file predicate. Remove the separate src traversal and reuse the prepared diagnostic path while preserving public, private, type-only and test reference rules.
2026-09-10 12:12:39 -07:00
Vincent Koc
cc9fe3963c
fix(ci): check frozen contracts before release fanout (#144236)
* feat(release): prepare npm and ClawHub for one-button publication

Stage complete plugin inventories in non-publishing owner workflows and
publish the original tarballs through the existing protected npm and
ClawHub publishers from one readiness receipt.

Bind source, tooling, producer attempts, and artifact digests. Require
established ClawHub publishers before readiness, verify every prepared
package before writers, and activate GitHub visibility only after exact
parent and canonical registry readback checks.

Share bounded artifact download recovery and verified archive reuse.
Retain partial dispatch requests, support explicit preparation adoption
and the existing successful-core resume path, and never blindly repeat
an uncertain registry mutation. Document native/platform boundaries and
the existing failed-core-child reconciliation limit.

Refs #136392

* fix(ci): run frozen bundle clients from their shipped layout

Resolve only the selected bundle contract with local committed-object reads and trusted syntax parsing. Preserve each legacy client's manifest, helper, import depth and bytes before Docker staging, and reject unknown or unreadable contracts.

* fix(ci): preserve frozen source read failures

Distinguish committed absence from missing, corrupt, or wrong-kind Git objects before selecting frozen compatibility. Share bounded local-only source reads across the shell and bundle resolver, and preserve errors through conditional callers before gateway Docker work. This is the source-read stage only; aggregate frozen admission remains separate.

* fix(ci): reconcile retained full release dispatches

* fix(ci): retain postpublish diagnostics when verification fails

* fix(ci): isolate frozen consumer contracts

* fix(ci): invoke publication diagnostics through guarded entrypoint

* fix(ci): add inert frozen target admission

* fix(ci): admit frozen source contracts before release work

Bind selected source, trusted tooling, package identity and resolved baseline selections at the four existing workflow prerequisites. Keep acquisition and conditional trusted parser provisioning separate from inert evaluation.

Share the actual consumer selectors, preserve authorized omissions and preparation-only assets, and retain bounded admission diagnostics without treating them as validation or publication authority.

* fix(ci): pin package tooling and align admission fixtures

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 03:11:58 +08:00
Peter Steinberger
f7c4102de5
fix(docs): reject unpublished permalink routes (#144279)
Use physical pages and configured redirects consistently for docs link and navigation validation. Remove the legacy frontmatter alias scan, which accepted URLs that the publisher does not emit and reread every Markdown page. Preserve the existing published-route and ClawHub owners.
2026-09-10 12:01:23 -07:00
Peter Steinberger
9edbe0b152
perf(build): skip hashes before mandatory cache restores (#144242) 2026-09-10 11:17:09 -07:00
Peter Steinberger
dd394523be
ci: give full CLI tests measured CPU capacity (#144257) 2026-09-10 11:12:06 -07:00
Ayaan Zaidi
d9048fd29e
feat(models): align native sign-in and model runtime choices (#143588)
## Summary

Native Codex sign-in now supplies model availability without copying its credentials into OpenClaw profiles. CLI, chat, status, and Gateway model controls use one prepared owner for per-model runtime eligibility, physical routes, and authentication mode. Selections are revalidated before session persistence.

Native sign-in observations no longer masquerade as host-prepared credentials when the registered runtime evaluates model eligibility. Native credentials remain with Codex. Explicit profiles, account pins, authored routes, isolated agent homes, and remote server accounts retain their existing boundaries. Native local stdio uses the user home only when no prepared OpenClaw credential or explicit home selection owns the route. The separate Gateway authentication projection and ordinary-read Codex credential import are removed.

Explicit import preserves the supported declared `openai:default` profile reference. Apply now rechecks inherited account identity and usability at the destination, so an account inserted under the same profile ID after planning cannot be silently replaced. Matching shared accounts stay inherited. Native authentication enumeration also follows the captured plugin generation, including an explicitly empty generation, instead of unrelated ambient registry state.

Default local discovery asks the existing ordered-profile owner first and carries its selected profile and store into the shared client. Native login is the fallback when that owner selects no profile; an explicitly selected native home retains its authority.

Stdio proxies keep the destination server’s account and model catalog. Local login probing and the native user-home default apply only to owned local stdio runtimes; proxy arguments from configuration and environment use the existing proxy classifier.

Login-status probing also retains the official Node launcher prefix and native configuration arguments while removing the app-server transport suffix. Runtime verification rules are unchanged.

## Compatibility

The approved native-owner cutover requires explicit import or reselection for old CLI-backed pins outside the supported declared default-profile recovery. The credential documentation describes that recovery. Existing explicitly isolated homes and remote connections retain their selection. No configuration key, protocol version, or SQLite schema is added.

Dependency contract personally inspected in Codex at `e5769939113536eb72752660bf7d1903f799d198`: [`codex-rs/app-server-protocol/src/protocol/v2/account.rs:524`](e576993911/codex-rs/app-server-protocol/src/protocol/v2/account.rs (L524)) (`GetAccountParams` and `GetAccountResponse`), [`codex-rs/app-server/src/request_processors/account_processor.rs:826`](e576993911/codex-rs/app-server/src/request_processors/account_processor.rs (L826)) (managed refresh and client-supplied token login), and [`codex-rs/cli/src/login.rs:443`](e576993911/codex-rs/cli/src/login.rs (L443)) (native login status). `account/read` supplies account identity; an unknown remote subscription mode remains unknown. [`codex-rs/cli/src/main.rs:1344`](e576993911/codex-rs/cli/src/main.rs (L1344)) confirms that stdio proxy forwards to the selected Unix socket.

## Validation

- Native Testbox: 300 selected tests passed across import/auth bridge, native login/logout, per-model choices, captured generation ownership, status, Gateway metadata, and CLI cleanup.
- The inherited-account and captured-registry regressions failed before their fixes and pass afterward.
- The registered-harness correction passed 60 focused tests. The proxy correction failed six regression cases before the fix, then passed all 76 focused tests.
- The profile-owned discovery correction passed 18 catalog cases and two selected shared-client cases after two expected regression failures. The launcher correction passed 31 native/transport cases after its expected regression failure.
- A required merge-conflict rebase retained all 17 PR patches. The auth-pin and selected-model setup tests passed all 23 cases on the rebased head; retained runtime captures keep their original tested build identities.
- Formatting and syntax lint passed for each correction. Type checks and full CI run on GitHub.
- Telegram Test Server commands on the compiled candidate: native runtime selection succeeds; status agrees; a missing explicit profile rejects without changing selection; verified native logout plus public catalog refresh rejects the native runtime. No inference requests were made.
- Enabled-discovery proof with the real Codex binary selects the profile-owned catalog while native login is absent or different, and the native catalog for explicit user-home selection. An official Node-launcher control with no host profiles reports native auth and an available native model. Synthetic host-token cases retain vendor auth-rejection diagnostics; this proof establishes catalog ownership, not vendor credential validity.
- Public interactive migration was paused at confirmation while a same-ID inherited account was inserted. A different account reports conflict; a matching usable account is reused; neither writes a child-local shadow. The unrelated shared profile and native source remain intact.
- Public CLI migration preserves the declared `openai:default` reference, configured model, and native source bytes. Repeating import with a separate backup output retains one profile and reports no credential write.
- Synthetic native credentials prove local command and ownership behavior; they do not establish vendor authentication or inference. Full GitHub CI and the exact-head landing review are tracked by the required checks and landing receipt.

Related: #136257. Builds on explicit import from #142933. Discord #143322 is a separate consumer lane.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-10 23:23:36 +05:30
Abi X Renhart
b47f1848ac
fix(deepseek): preserve object-union tool arguments (#143819)
## What Problem This Solves

DeepSeek kept only the first object alternative in MCP tool schemas. Valid Notion-style database and data-source parent arguments then failed local validation before reaching the tool.

Merge supported object properties, keep common required keys, and pool compatible discriminator literals. Preserve permissive keys, descriptions, and own prototype-shaped keys. Keep object/null alternatives usable by the local validator, including literal and outer constraints. Shared type-array coercion now preserves genuine null without turning invalid non-null values into null; valid conversions and null-only behavior remain supported.

The flattened schema remains an approximation. Conflicting property shapes retain the first definition, shared annotations retain the first annotation, and the tool owner still enforces original whole-object constraints that the flattened schema cannot express. Primitive and mixed-union selection remains unchanged.

## Evidence

- 86 focused owner and sibling tests pass; selecting the production normalizer runs all 40 provider cases.
- Independent public Gateway validation covers 125 cases with bundled DeepSeek/OpenAI routing, captured model requests and actual MCP receipts. Baseline rejects the valid later parent branches; candidate delivers all three exactly once. Negative cases remain local rejections or explicit tool-owner errors, as applicable.
- Runtime proof uses commit `a243f9793987b9091a356ea984b43107dbdd180c`. The later assertion-baseline count reduction changes no runtime, dependency, test, or fixture input.
- The hosted candidate build and artifact checks passed: https://github.com/openclaw/openclaw/actions/runs/34500899684/job/102951656517. Full PR CI and exact-head review remain separate gates.

The public validation uses synthetic loopback providers and a local MCP server. The contributor's earlier live Notion report recorded successful data-source page creation and archival; that remains attributed contributor evidence. All six contributor commits are preserved.

Fixes #143790.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-10 23:06:38 +05:30
Vincent Koc
2aad8478b8
fix(tooling): join memory profiler children within cleanup deadlines (#143503)
* fix(tooling): join memory profiler children within cleanup deadlines

* test(tooling): collect conditional cleanup fixtures
2026-09-11 01:29:59 +08:00
Peter Steinberger
bb3b67a5b0
fix(crabbox): reuse managed CLI across QA and remote proof (#144154)
* refactor(crabbox): centralize CLI discovery and setup

Reuse plugin-owned binary admission in QA Lab and workflow setup, carry verified versions through proof tooling, and preserve caller environments. Follow-up to #143768.

* fix(crabbox): preserve QA executable working directory
2026-09-10 09:57:28 -07:00
Vincent Koc
1bbb15a68b
fix(ci): keep Android runner package setup deterministic (#143468)
* fix(ci): isolate Android APT sources

* fix(ci): use varied-color Android conversion smoke input

* fix(ci): keep Android image smoke true-color

* fix(ci): generate two-axis Android image fixture

* fix(ci): fully inspect Android JPEG metadata
2026-09-11 00:04:51 +08:00
Peter Steinberger
0589eaf3a3
refactor(protocol): simplify generated schema registration (#144112)
* refactor(protocol): simplify generated schema registration

* fix(protocol): handle Windows paths in registry type checks

Normalize diagnostic filenames using the same path rule as the compiler host, so expected readonly diagnostics are recognized on Windows. The actual package guard and both optional-mode compiler probes pass; the native Windows execution is separate evidence.
2026-09-10 09:00:15 -07:00
Vincent Koc
67e99bc838
refactor(scripts): share concurrent Knip scan orchestration (#143745) 2026-09-10 23:46:41 +08:00
Vincent Koc
091689b829
fix(ci): reject invalid frozen contracts for Docker aliases (#144129) 2026-09-10 23:39:41 +08:00
Peter Steinberger
044cf2e6e0
refactor(docs): reuse collected plugin inventory records (#144120)
Build the inventory overview and reference pages from the same collected records. Keep the independent manifest coverage scan unchanged.

Validation: manifest reads dropped from 608 to 304 across 152 manifests; all 154 generated files remained byte-identical. Existing six helper cases, all 17 changed checks and independent review passed.
2026-09-10 08:25:25 -07:00
RoboClaw
76db6d1846
fix(update): inline schemas in managed handoff runtime (#144031)
Use the canonical schema-inline plugin in the production handoff build so relocated helpers load without neighboring SQL assets. Cover the registered production graph through real staging and an isolated Node load.

Worked on by: @IWhatsskill

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-10 09:05:05 -06:00
Vincent Koc
3c4981a51e
fix(ci): validate frozen targets without executing candidate code (#144023)
* fix(ci): run frozen bundle clients from their shipped layout

Resolve only the selected bundle contract with local committed-object reads and trusted syntax parsing. Preserve each legacy client's manifest, helper, import depth and bytes before Docker staging, and reject unknown or unreadable contracts.

* fix(ci): preserve frozen source read failures

Distinguish committed absence from missing, corrupt, or wrong-kind Git objects before selecting frozen compatibility. Share bounded local-only source reads across the shell and bundle resolver, and preserve errors through conditional callers before gateway Docker work. This is the source-read stage only; aggregate frozen admission remains separate.

* fix(ci): isolate frozen consumer contracts

* fix(ci): add inert frozen target admission

* fix(ci): validate Docker lane alias contracts
2026-09-10 22:51:05 +08:00
Peter Steinberger
8de89effa7
improve: reduce SQLite snapshot process startup cost (#144022)
* perf(sqlite): trim snapshot child import graph

* test(update): forward snapshot marker in finalization fixture
2026-09-10 07:12:02 -07:00
Vincent Koc
b0286f17be
docs: close the small audit categories (generated, governance, link, split) (#144029)
* docs: close small audit categories (governance, generated, link)

- ci/scheduled-workflows: date the Dependency Audit triage owner and name the routing team (r5-0143)
- AGENTS.md: link the secret placeholder conventions page from the placeholder rule (r3-2264)
- model-providers/custom-providers: align the moonshot config example with the documented example model (r3-1349)
- secretref-credential-surface: group the 114 supported targets by top-level config key (r3-2248)
- generate-plugin-inventory-doc: describe docs/plugins/reference.md as a pointer, not an index (r3-2078)
- cli/file-transfer: new CLI reference page for openclaw file-transfer (r5-0196)

* docs(cli/file-transfer): qualify the non-interactive migration error

runApprovalMigration returns after printing the no-work message when no legacy
items remain (extensions/file-transfer/src/cli.ts:58-62), before it reads
process.stdin.isTTY. The non-interactive error therefore fires only when
permissions still need review. Addresses the P3 ClawSweeper finding.

---------

Co-authored-by: Vincent Koc <vincent@openclaw.org>
2026-09-10 21:52:03 +08:00
Vincent Koc
e98a5c15f3
docs: scope version-locked claims across plugins, platforms, providers, and gateway (#144032)
* docs: scope version-locked claims across plugins, platforms, providers, and gateway

Resolves 78 accuracy-audit rows across five directory batches. Most changes
replace time-relative wording ("currently", "not yet", "previously") with
either a release number established by tag containment or a restatement as a
present-tense limit where no release record exists.

Also marks placeholder identifiers in SDK samples that read as exported APIs,
completes one command sample that was a bare object fragment, and dates two
deprecation notes from the compatibility registry.

* docs(automation): cite the beta tag and its stable release for the SQLite cutover

v2026.5.30 was never released as a stable tag; only v2026.5.30-beta.1 and
-beta.2 exist, and the first stable release containing the migration commit
d115fb4cf9 is v2026.6.1.

Uses the form already established at
docs/reference/database-schemas/agent-schema-history.md:13, which names the
beta tag and the stable release separately.

* docs(automation): the SQLite cutover shipped in beta.1, not beta.2

The earlier commit named beta.2 because the local tag set was incomplete
when the containment query ran. With tags fetched, v2026.5.30-beta.1 also
contains d115fb4cf9.

---------

Co-authored-by: Vincent Koc <vincent@openclaw.org>
2026-09-10 21:33:28 +08:00
Peter Steinberger
e89128c69e
feat(control-ui): show cloud session machine specs (#143864)
* feat(control-ui): show cloud session machine specs

Expose optional OS, machine class, vCPU, and memory metadata on correlated
worker placements. Resolve provider defaults through lifecycle-owned catalogs
without changing persisted profile snapshots.

Show known machine facts in sidebar hovercards and placement tooltips. Refresh
session subscribers when discovery completes, and fence catalog warmups
against profile changes.

* test(gateway): account for machine catalog preflight discovery

Model the read-only providers catalog query in Crabbox preflight fixtures. Assert exact command sequences so failed preflight still cannot allocate or clean up a worker.

* refactor(gateway): centralize machine catalog lifecycle

Keep machine metadata subscriptions, cleanup, and warmup warnings with the catalog owner. Delegate its async listing operations directly so the environment service stays within its line limit after concurrent preparation changes.
2026-09-10 03:47:57 -07:00
Peter Steinberger
cbc245824e
fix(ui): files panel squashes session files into nested scroll regions (#143854)
* fix(ui): files panel squashes session files into nested scroll regions

The Chat Files rail gave every section its own shrinking scroll region, so
long artifact or read lists collapsed to a row or two and the search field
sat below the fold. The rail now scrolls as one list under a fixed toolbar
with the search field and filter chips; groups are native disclosures that
search or a chip forces open, session-kind badges are neutral, and the row
and header-action templates share one renderer.

The Control UI mock's Files fixtures matched an `agent:alpha` key that the
session URL contract rejects, so they never rendered; they now match
`agent:main:main`.

* fix(ui): align files panel cursor and preview tests

* fix(ui): clear files filters when revealing a file
2026-09-10 02:54:21 -07:00
Peter Steinberger
4af8616c62
fix(crabbox): automatically update outdated CLI installations (#143768)
* fix(crabbox): automatically manage current CLI installations

Acquire a checksum-verified supported Crabbox distribution in the plugin's own versioned tools directory when the selected executable is outdated or missing. Preserve operator binaries and recovery copies, share admission with remote proof tooling, and remove obsolete provider/platform version branches.

Keep cancellation, heartbeat teardown, Doctor repair, and warm-image cleanup under their lifecycle owners. Outdated installations now repair automatically before cloud-worker operations.

* fix(crabbox): preserve error causes and align lifecycle fixtures

* fix(crabbox): preserve profile-specific doctor guidance

* test(crabbox): model version checks in gateway lifecycle fixtures
2026-09-10 02:05:55 -07:00
Dallin Romney
e7ec02ac79
fix(release): load frozen Anthropic internals safely (#143810) 2026-09-10 02:02:25 -07:00