* feat(ui): orbit collaborative session avatars while a run is active
While a sidebar session row has an active run, the two-identity lead avatar
(owner in front, one participant or the +N bubble behind) orbits in a shallow
3D circle: perspective scales the nearer face up and the farther one down, and
the pair swaps depth as it turns. Idle rows stay untransformed, so the pinned
28x20 stack geometry is unchanged. Reduced motion disables the orbit and a
queued run pauses it alongside the ring.
The mock dev scenario gains two running collaborative rows so the state is
reachable in `pnpm dev:ui:mock`.
* feat(ui): trace the run arc around collaborative session avatars
Replace the 3D orbit from the previous commit: the faces of a two-identity
owner stack now stay put, and while the row runs the lead slot draws the union
outline of the two circles instead of a round ring. A faint track shows the
whole outline and a quarter-length accent arc flows along it at the ring's
linear speed, dipping through the cusps between the faces. Single-face rows
keep the existing round ring; queued runs pause the arc and reduced motion
draws the outline solid. `renderSessionGlyph` gains `ring: "circle" | "pair"`
and the leading indicator picks the pair whenever the chip stacks a
participant or +N behind the owner.
Sidebar unit coverage asserts the pair trace on a running stacked row and the
round ring on a running solo row; the e2e idle geometry and queue ring
contracts are unchanged.
* fix(release): bind ClawHub categories to trusted tooling
Project reviewed single-category metadata through the existing isolated package
manifest overlay while retaining the frozen candidate version, runtime files,
package manifest, and generated channel configuration. Pack with trusted release
tooling before the unchanged transaction-sealing and approval boundaries.
Use existing reviewed category assignments; retain the shared runtime vocabulary
for acpx and codex. Do not change published npm artifacts or the final release tag.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
* fix(release): keep category validation native-node safe
Extract the unchanged category contract into a dependency-free module so
pre-build packaging and updater entrypoints do not load compiled imports.
Preserve existing barrel exports and validation behavior.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
* test(transcripts): keep capture lifecycle fixture model-free
Explicitly disable utility routing in the capture replacement fixture so
its real heuristic-summary and lifecycle assertions do not depend on a
provider metadata snapshot retained by an earlier test file. Keep all
assertions, deadlines, and production code unchanged.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Preserve substring admission and AST ownership checks while removing repeated per-file name-array construction and literal scans. The full guard improved 48.85% and 53.63% in a fixed four-call ABBA comparison; all outputs matched. Thirteen baseline and candidate tests, all twenty changed checks, and independent Codex review passed. Retain shared-host, warm-filesystem and inconclusive memory qualifications in the PR.
Admit the exact frozen 2026.9.4 publisher revision to the existing historical runner-header contract. Preserve every source, workflow, successful-step, time-window, shell-body, registry signature, provenance, and qualified Docker constraint.
Extend the existing acceptance/rejection table across both verified revisions. The actual split-publication verifier passes using retained npm and Docker evidence, without changing any published package or final tag.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
* refactor(test): centralize worker declaration metadata
Replay the reviewed first tooling layer on the current frozen main base. Keep package activation declarations reserved for the later owning layers; preserve the inherited main build graph and test coverage.
* test: stabilize auth discovery and onboarding checks
Pair synthetic OAuth refresh with capability discovery. Retain the Android test synchronization landed upstream in commit 1237e647. No production code or timeout changes.
* test: isolate yielded session reset runtime
* test: align isolated Gateway inventory assertions
* fix(ui): let plain tooltips yield pointer actions
* test: preserve loose objects in Git corruption fixtures
* fix: keep tooltips lean and metadata snapshots refreezable
* test(android): pin approval reconciliation handler entry
---------
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
* refactor: remove unused auth warming from model browsing
Model browsing resolves route-aware auth, while failures and refreshes
still maintained a private provider-only cache with no current consumer.
Retire its worker, failure hook, lifecycle wiring, and test-only checker
options; keep canonical availability, native login preparation, external
CLI hydration, auth refresh, reload, and model publication intact.
Move retained preparation and selected-account tests to their actual
owners and preserve disk-reopen billing and healthy-profile fallback proof.
* test: prove provider auth recovery through the built Gateway
Replace the retired rewarm-log assertion with credential replacement and
models.authRefresh, then verify catalog availability and a successful
new-key response in history from the same Gateway process. Preserve the
HTTP429 retry count, HTTP401 persistence, scoped rate-limit state and
large configured-catalog proof. Rename the smoke and migrate both runtime
prerequisite and CI-plan references together.
Validated with 57 focused tests, staged changed checks and P2 review.
Use the shared MarkdownIt parser to resolve fenced and raw literal boundaries before component preprocessing. Preserve containing quote markers during JSX removal so examples stay literal and the docs auditor reports live links at their original source lines.
* fix(pr): recover partially written review transitions
Classify index and working-tree entries independently against the journaled
source and target before replaying an interrupted native restore. Preserve
foreign bytes, ignored overlaps, and hidden index metadata, including
intent-to-add and resolve-undo state. Rebuild the validated source index so
completed index deletions can still remove their remaining source files.
Preserve the reserved .local artifact namespace and existing journal endpoints.
Unknown zero-byte files remain refused rather than inferred as owned writes.
Validation: 66 native owner cases, complete changed checks, and independent
review. Regression cases demonstrate worktree-first and index-first recovery,
plus fail-before/pass-after coverage for intent-to-add and resolve-undo guards.
Related: #143802
* fix(pr): register the journal validator executable entry
* test(pr): preserve Git reader coverage for journal recovery
Exercise the active Node-helper Git reader in the failure fixture and keep operation artifacts in the reserved .local namespace. Record reader starts and delayed exits after stdout closure so successful validation still proves every producer joined before lock release.
Validation: focused reader cases changed from two failures to five passes; full operation-lock suite passed 114 tests with one Linux-only zombie case skipped on macOS. Complete changed checks and focused independent review passed. Production runtime bytes are unchanged.
* fix(pr): preserve leading BOM characters in Git path records
Treat Git output as pathname records rather than a BOM-framed text document. Preserve an initial U+FEFF while keeping fatal UTF-8 decoding, so an untracked lookalike cannot be misclassified as a target path before native replay.
The native regression previously changed HEAD before final refusal; it now preserves the source state. All 67 owner tests, complete changed checks, and focused independent review pass.
* test(ui): mock a subagent task transcript with tool calls
* fix(ui): render task details as a compact activity feed
Show task titles derived from prompts, current progress, finished duration,
tool counts, and compact grouped activity across the full detail panel width.
Keep readers at the bottom for new activity and preserve their position when
loading earlier history.
Reuse the chat tool classification, reconciliation, summaries, and Markdown
owners. Remove the task-only full-chat renderer and transcript controller;
retain the independent full-page subagent avatar policy and inspector fallback.
Correct the mock transcript registry type without amending the fixture commit.
* fix(ui): use tool-kind icons in the task activity feed
* fix(ui): keep complete commands in expanded task feed rows
* fix(ui): keep expanded task feed commands free of template whitespace
* fix(ui): keep pending task feed scroll corrections across renders
* test(ui): align task E2E coverage with the activity feed
* fix(ui): recover capped replies in the task activity feed
Restore automatic full-message recovery for capped assistant replies in task
panels. Reuse the shared eligibility and retry contracts, load through the child
session and task agent, and keep recovery state scoped to the selected task and
connection. Preserve the preview during loading and offer Retry after three
failed attempts.
Cover recovery, stale results, and retry behavior with component tests and a
Tasks-rail mock Gateway E2E. Add a recoverable running-task reply to the dev
fixture and document the sessionless transcript limit.
* fix(ui): recover capped task replies once per message
Share the bounded, run-verified terminal model projection between Gateway
rows, /model and /status without changing stored selection or telemetry.
Render the prepared selected and active model facts, preserving literal
provider-local prefixes and the original entry's context provenance.
Remove duplicate selection and prefix-stripping helpers. Keep unmatched
fallback notices on the legacy usage projection path, and validate active
context budgets against the original session and final model identity.
Refs: #134496, #130706
* fix(ci): prepare selected release native fixtures
Enable and prepare the selected native heartbeat live test through its
existing runtime build owner. Keep Doctor scenario and canonical-path
service shims on the same selected checkout while retaining trusted shared
helpers. Complete the managed test's ephemeral TCP endpoint adapter so
shutdown verification cannot observe an unrelated host Gateway.
Qualification context: https://github.com/openclaw/openclaw/actions/runs/34507645027
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
* test(ci): bind live-shard cancellation to the test child
Use an isolated APNs-only inventory through the existing shard selector so
build preparation cannot masquerade as live-child readiness. Assert the
actual test:live arguments and join owned processes before fixture cleanup.
Preserve the original signal, descendant-death, and timeout assertions.
The original 20-file CI order passes all 332 tests after the correction.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
---------
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Related: #136257
## What Problem This Solves
First-run setup discarded a credential after a failed connection check, which forced another sign-in. Managed local models could also receive a second verification turn with tools enabled.
## Why This Change Was Made
One setup owner now saves the selected credential through the existing auth-profile store, confirms the candidate configuration in memory with one tool-free provider turn, and commits configuration only after success. New submissions receive distinct profile identities. A rejected replacement therefore preserves both the working credential and the rejected credential, and setup cannot fall back to another profile during confirmation. Saved-sign-in retry reuses the saved profile without another login. Gateway activation reports completion only after releasing setup admission, so an immediate follow-up can start.
The cutover removes staged credential stores, promotion/rollback helpers, the detection worker, and the parallel verification path. Existing provider installation, scoped runtime generations, cancellation, relevant config conflict checks, protected credential checks, and error redaction remain with their owners. CLI wizard, Gateway setup, completion, and update-repair callers use the shared confirmation owner. Custom endpoint setup defers its preliminary completion to that owner.
## User Impact
- Failed confirmation preserves the credential and leaves configuration unchanged.
- Rejected replacement credentials cannot overwrite a working sign-in.
- Saved-sign-in retry runs a fresh confirmation without repeating login. A saved replacement remains selectable when it uses the current model.
- Local models receive one tool-free confirmation turn.
- No SQLite table, column, or migration is added.
Discovery retains the previous 30-second asynchronous deadline and returns completed saved/native/manual choices when a provider hook stalls. The worker is removed as part of this extraction. Synchronous plugin imports still share the Gateway event loop; the deadline does not restore worker isolation. Custom endpoint settings remain available for retry while the Gateway runs; after restart, those endpoint settings may need to be supplied again.
## Evidence
Pinned main `0f309a4cf1` reproduced the credential-loss defect through the shipped setup Gateway request with no configured default. Rejection left configuration unchanged but discarded the submitted credential.
Real-provider proof drives the compiled CLI Gateway in scratch state through the public setup requests. It records complete provider requests/responses and config/credential state before the request and after the result. Success, real HTTP 401 rejection, saved-sign-in recovery, and working-credential replacement are covered. Each setup confirmation uses the selected credential with `tools: []`; only success writes the selected configuration. Failed attempts and corrections remain in the private evidence record.
Focused validation includes setup activation, turn ownership, stalled discovery, Gateway/Control UI admission, wizard import and retry, provider adapters, protected routes, plugin persistence/index/registry, and auth planning. The initial cutover passed 816 targeted tests; the correction reruns the affected owners and adds replacement, exclusive-auth, and stalled-discovery cases. Formatting, syntax lint, unused-export scans, the max-lines/environment ratchets, normal commit hooks, and runtime builds passed. Full type checking and CI run on GitHub.
A real Chromium regression and independent browser pass show the saved replacement row on desktop and mobile, verify the saved-profile activation request contains no key or new sign-in, and observe success. This browser lane uses a mocked Gateway; the separate real-provider lane proves credential/configuration behavior.
The complete deletion ledger classifies every deleted or rewritten test file and identifies the current behavior owner. Production TypeScript remains smaller after the cutover.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Classify core runtime files from the complete collected inventory using the existing test-file predicate. Remove the separate src traversal and reuse the prepared diagnostic path while preserving public, private, type-only and test reference rules.
* feat(release): prepare npm and ClawHub for one-button publication
Stage complete plugin inventories in non-publishing owner workflows and
publish the original tarballs through the existing protected npm and
ClawHub publishers from one readiness receipt.
Bind source, tooling, producer attempts, and artifact digests. Require
established ClawHub publishers before readiness, verify every prepared
package before writers, and activate GitHub visibility only after exact
parent and canonical registry readback checks.
Share bounded artifact download recovery and verified archive reuse.
Retain partial dispatch requests, support explicit preparation adoption
and the existing successful-core resume path, and never blindly repeat
an uncertain registry mutation. Document native/platform boundaries and
the existing failed-core-child reconciliation limit.
Refs #136392
* fix(ci): run frozen bundle clients from their shipped layout
Resolve only the selected bundle contract with local committed-object reads and trusted syntax parsing. Preserve each legacy client's manifest, helper, import depth and bytes before Docker staging, and reject unknown or unreadable contracts.
* fix(ci): preserve frozen source read failures
Distinguish committed absence from missing, corrupt, or wrong-kind Git objects before selecting frozen compatibility. Share bounded local-only source reads across the shell and bundle resolver, and preserve errors through conditional callers before gateway Docker work. This is the source-read stage only; aggregate frozen admission remains separate.
* fix(ci): reconcile retained full release dispatches
* fix(ci): retain postpublish diagnostics when verification fails
* fix(ci): isolate frozen consumer contracts
* fix(ci): invoke publication diagnostics through guarded entrypoint
* fix(ci): add inert frozen target admission
* fix(ci): admit frozen source contracts before release work
Bind selected source, trusted tooling, package identity and resolved baseline selections at the four existing workflow prerequisites. Keep acquisition and conditional trusted parser provisioning separate from inert evaluation.
Share the actual consumer selectors, preserve authorized omissions and preparation-only assets, and retain bounded admission diagnostics without treating them as validation or publication authority.
* fix(ci): pin package tooling and align admission fixtures
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Use physical pages and configured redirects consistently for docs link and navigation validation. Remove the legacy frontmatter alias scan, which accepted URLs that the publisher does not emit and reread every Markdown page. Preserve the existing published-route and ClawHub owners.
## Summary
Native Codex sign-in now supplies model availability without copying its credentials into OpenClaw profiles. CLI, chat, status, and Gateway model controls use one prepared owner for per-model runtime eligibility, physical routes, and authentication mode. Selections are revalidated before session persistence.
Native sign-in observations no longer masquerade as host-prepared credentials when the registered runtime evaluates model eligibility. Native credentials remain with Codex. Explicit profiles, account pins, authored routes, isolated agent homes, and remote server accounts retain their existing boundaries. Native local stdio uses the user home only when no prepared OpenClaw credential or explicit home selection owns the route. The separate Gateway authentication projection and ordinary-read Codex credential import are removed.
Explicit import preserves the supported declared `openai:default` profile reference. Apply now rechecks inherited account identity and usability at the destination, so an account inserted under the same profile ID after planning cannot be silently replaced. Matching shared accounts stay inherited. Native authentication enumeration also follows the captured plugin generation, including an explicitly empty generation, instead of unrelated ambient registry state.
Default local discovery asks the existing ordered-profile owner first and carries its selected profile and store into the shared client. Native login is the fallback when that owner selects no profile; an explicitly selected native home retains its authority.
Stdio proxies keep the destination server’s account and model catalog. Local login probing and the native user-home default apply only to owned local stdio runtimes; proxy arguments from configuration and environment use the existing proxy classifier.
Login-status probing also retains the official Node launcher prefix and native configuration arguments while removing the app-server transport suffix. Runtime verification rules are unchanged.
## Compatibility
The approved native-owner cutover requires explicit import or reselection for old CLI-backed pins outside the supported declared default-profile recovery. The credential documentation describes that recovery. Existing explicitly isolated homes and remote connections retain their selection. No configuration key, protocol version, or SQLite schema is added.
Dependency contract personally inspected in Codex at `e5769939113536eb72752660bf7d1903f799d198`: [`codex-rs/app-server-protocol/src/protocol/v2/account.rs:524`](e576993911/codex-rs/app-server-protocol/src/protocol/v2/account.rs (L524)) (`GetAccountParams` and `GetAccountResponse`), [`codex-rs/app-server/src/request_processors/account_processor.rs:826`](e576993911/codex-rs/app-server/src/request_processors/account_processor.rs (L826)) (managed refresh and client-supplied token login), and [`codex-rs/cli/src/login.rs:443`](e576993911/codex-rs/cli/src/login.rs (L443)) (native login status). `account/read` supplies account identity; an unknown remote subscription mode remains unknown. [`codex-rs/cli/src/main.rs:1344`](e576993911/codex-rs/cli/src/main.rs (L1344)) confirms that stdio proxy forwards to the selected Unix socket.
## Validation
- Native Testbox: 300 selected tests passed across import/auth bridge, native login/logout, per-model choices, captured generation ownership, status, Gateway metadata, and CLI cleanup.
- The inherited-account and captured-registry regressions failed before their fixes and pass afterward.
- The registered-harness correction passed 60 focused tests. The proxy correction failed six regression cases before the fix, then passed all 76 focused tests.
- The profile-owned discovery correction passed 18 catalog cases and two selected shared-client cases after two expected regression failures. The launcher correction passed 31 native/transport cases after its expected regression failure.
- A required merge-conflict rebase retained all 17 PR patches. The auth-pin and selected-model setup tests passed all 23 cases on the rebased head; retained runtime captures keep their original tested build identities.
- Formatting and syntax lint passed for each correction. Type checks and full CI run on GitHub.
- Telegram Test Server commands on the compiled candidate: native runtime selection succeeds; status agrees; a missing explicit profile rejects without changing selection; verified native logout plus public catalog refresh rejects the native runtime. No inference requests were made.
- Enabled-discovery proof with the real Codex binary selects the profile-owned catalog while native login is absent or different, and the native catalog for explicit user-home selection. An official Node-launcher control with no host profiles reports native auth and an available native model. Synthetic host-token cases retain vendor auth-rejection diagnostics; this proof establishes catalog ownership, not vendor credential validity.
- Public interactive migration was paused at confirmation while a same-ID inherited account was inserted. A different account reports conflict; a matching usable account is reused; neither writes a child-local shadow. The unrelated shared profile and native source remain intact.
- Public CLI migration preserves the declared `openai:default` reference, configured model, and native source bytes. Repeating import with a separate backup output retains one profile and reports no credential write.
- Synthetic native credentials prove local command and ownership behavior; they do not establish vendor authentication or inference. Full GitHub CI and the exact-head landing review are tracked by the required checks and landing receipt.
Related: #136257. Builds on explicit import from #142933. Discord #143322 is a separate consumer lane.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
## What Problem This Solves
DeepSeek kept only the first object alternative in MCP tool schemas. Valid Notion-style database and data-source parent arguments then failed local validation before reaching the tool.
Merge supported object properties, keep common required keys, and pool compatible discriminator literals. Preserve permissive keys, descriptions, and own prototype-shaped keys. Keep object/null alternatives usable by the local validator, including literal and outer constraints. Shared type-array coercion now preserves genuine null without turning invalid non-null values into null; valid conversions and null-only behavior remain supported.
The flattened schema remains an approximation. Conflicting property shapes retain the first definition, shared annotations retain the first annotation, and the tool owner still enforces original whole-object constraints that the flattened schema cannot express. Primitive and mixed-union selection remains unchanged.
## Evidence
- 86 focused owner and sibling tests pass; selecting the production normalizer runs all 40 provider cases.
- Independent public Gateway validation covers 125 cases with bundled DeepSeek/OpenAI routing, captured model requests and actual MCP receipts. Baseline rejects the valid later parent branches; candidate delivers all three exactly once. Negative cases remain local rejections or explicit tool-owner errors, as applicable.
- Runtime proof uses commit `a243f9793987b9091a356ea984b43107dbdd180c`. The later assertion-baseline count reduction changes no runtime, dependency, test, or fixture input.
- The hosted candidate build and artifact checks passed: https://github.com/openclaw/openclaw/actions/runs/34500899684/job/102951656517. Full PR CI and exact-head review remain separate gates.
The public validation uses synthetic loopback providers and a local MCP server. The contributor's earlier live Notion report recorded successful data-source page creation and archival; that remains attributed contributor evidence. All six contributor commits are preserved.
Fixes#143790.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* refactor(protocol): simplify generated schema registration
* fix(protocol): handle Windows paths in registry type checks
Normalize diagnostic filenames using the same path rule as the compiler host, so expected readonly diagnostics are recognized on Windows. The actual package guard and both optional-mode compiler probes pass; the native Windows execution is separate evidence.
Build the inventory overview and reference pages from the same collected records. Keep the independent manifest coverage scan unchanged.
Validation: manifest reads dropped from 608 to 304 across 152 manifests; all 154 generated files remained byte-identical. Existing six helper cases, all 17 changed checks and independent review passed.
Use the canonical schema-inline plugin in the production handoff build so relocated helpers load without neighboring SQL assets. Cover the registered production graph through real staging and an isolated Node load.
Worked on by: @IWhatsskill
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
* fix(ci): run frozen bundle clients from their shipped layout
Resolve only the selected bundle contract with local committed-object reads and trusted syntax parsing. Preserve each legacy client's manifest, helper, import depth and bytes before Docker staging, and reject unknown or unreadable contracts.
* fix(ci): preserve frozen source read failures
Distinguish committed absence from missing, corrupt, or wrong-kind Git objects before selecting frozen compatibility. Share bounded local-only source reads across the shell and bundle resolver, and preserve errors through conditional callers before gateway Docker work. This is the source-read stage only; aggregate frozen admission remains separate.
* fix(ci): isolate frozen consumer contracts
* fix(ci): add inert frozen target admission
* fix(ci): validate Docker lane alias contracts
* docs: close small audit categories (governance, generated, link)
- ci/scheduled-workflows: date the Dependency Audit triage owner and name the routing team (r5-0143)
- AGENTS.md: link the secret placeholder conventions page from the placeholder rule (r3-2264)
- model-providers/custom-providers: align the moonshot config example with the documented example model (r3-1349)
- secretref-credential-surface: group the 114 supported targets by top-level config key (r3-2248)
- generate-plugin-inventory-doc: describe docs/plugins/reference.md as a pointer, not an index (r3-2078)
- cli/file-transfer: new CLI reference page for openclaw file-transfer (r5-0196)
* docs(cli/file-transfer): qualify the non-interactive migration error
runApprovalMigration returns after printing the no-work message when no legacy
items remain (extensions/file-transfer/src/cli.ts:58-62), before it reads
process.stdin.isTTY. The non-interactive error therefore fires only when
permissions still need review. Addresses the P3 ClawSweeper finding.
---------
Co-authored-by: Vincent Koc <vincent@openclaw.org>
* docs: scope version-locked claims across plugins, platforms, providers, and gateway
Resolves 78 accuracy-audit rows across five directory batches. Most changes
replace time-relative wording ("currently", "not yet", "previously") with
either a release number established by tag containment or a restatement as a
present-tense limit where no release record exists.
Also marks placeholder identifiers in SDK samples that read as exported APIs,
completes one command sample that was a bare object fragment, and dates two
deprecation notes from the compatibility registry.
* docs(automation): cite the beta tag and its stable release for the SQLite cutover
v2026.5.30 was never released as a stable tag; only v2026.5.30-beta.1 and
-beta.2 exist, and the first stable release containing the migration commit
d115fb4cf9 is v2026.6.1.
Uses the form already established at
docs/reference/database-schemas/agent-schema-history.md:13, which names the
beta tag and the stable release separately.
* docs(automation): the SQLite cutover shipped in beta.1, not beta.2
The earlier commit named beta.2 because the local tag set was incomplete
when the containment query ran. With tags fetched, v2026.5.30-beta.1 also
contains d115fb4cf9.
---------
Co-authored-by: Vincent Koc <vincent@openclaw.org>
* feat(control-ui): show cloud session machine specs
Expose optional OS, machine class, vCPU, and memory metadata on correlated
worker placements. Resolve provider defaults through lifecycle-owned catalogs
without changing persisted profile snapshots.
Show known machine facts in sidebar hovercards and placement tooltips. Refresh
session subscribers when discovery completes, and fence catalog warmups
against profile changes.
* test(gateway): account for machine catalog preflight discovery
Model the read-only providers catalog query in Crabbox preflight fixtures. Assert exact command sequences so failed preflight still cannot allocate or clean up a worker.
* refactor(gateway): centralize machine catalog lifecycle
Keep machine metadata subscriptions, cleanup, and warmup warnings with the catalog owner. Delegate its async listing operations directly so the environment service stays within its line limit after concurrent preparation changes.
* fix(ui): files panel squashes session files into nested scroll regions
The Chat Files rail gave every section its own shrinking scroll region, so
long artifact or read lists collapsed to a row or two and the search field
sat below the fold. The rail now scrolls as one list under a fixed toolbar
with the search field and filter chips; groups are native disclosures that
search or a chip forces open, session-kind badges are neutral, and the row
and header-action templates share one renderer.
The Control UI mock's Files fixtures matched an `agent:alpha` key that the
session URL contract rejects, so they never rendered; they now match
`agent:main:main`.
* fix(ui): align files panel cursor and preview tests
* fix(ui): clear files filters when revealing a file
* fix(crabbox): automatically manage current CLI installations
Acquire a checksum-verified supported Crabbox distribution in the plugin's own versioned tools directory when the selected executable is outdated or missing. Preserve operator binaries and recovery copies, share admission with remote proof tooling, and remove obsolete provider/platform version branches.
Keep cancellation, heartbeat teardown, Doctor repair, and warm-image cleanup under their lifecycle owners. Outdated installations now repair automatically before cloud-worker operations.
* fix(crabbox): preserve error causes and align lifecycle fixtures
* fix(crabbox): preserve profile-specific doctor guidance
* test(crabbox): model version checks in gateway lifecycle fixtures