mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 01:29:56 +00:00
* refactor: split release changelogs and synchronize docs mirrors * fix: complete split changelog instructions and validation wiring * fix: complete release changelog mirror integration Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver. * test: align docs agent Git ownership fixtures Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions. --------- Co-authored-by: Peter Steinberger <steipete@gmail.com>
78 KiB
78 KiB
2026.4.5
Breaking
- Config: remove legacy public config aliases such as
talk.voiceId/talk.apiKey,agents.*.sandbox.perSession,browser.ssrfPolicy.allowPrivateNetwork,hooks.internal.handlers, and channel/group/roomallowtoggles in favor of the canonical public paths andenabled, while keeping load-time compatibility andopenclaw doctor --fixmigration support for existing configs. (#60726) Thanks @vincentkoc.
Changes
- Agents/video generation: add the built-in
video_generatetool so agents can create videos through configured providers and return the generated media directly in the reply. - Agents/music generation: ignore unsupported optional hints such as
durationSecondswith a warning instead of hard-failing requests on providers like Google Lyria. - Providers/Arcee AI: add a bundled Arcee AI provider plugin with
ARCEEAI_API_KEYonboarding, Trinity model catalog (mini, large-preview, large-thinking), OpenAI-compatible API support, and OpenRouter as an alternative auth path. (#62068) Thanks @arthurbr11. - Providers/ComfyUI: add a bundled
comfyworkflow media plugin for local ComfyUI and Comfy Cloud workflows, including sharedimage_generate,video_generate, and workflow-backedmusic_generatesupport, with prompt injection, optional reference-image upload, live tests, and output download. - Tools/music generation: add the built-in
music_generatetool with bundled Google (Lyria) and MiniMax providers plus workflow-backed Comfy support, including async task tracking and follow-up delivery of finished audio. - Providers: add bundled Qwen, Fireworks AI, and StepFun providers, plus MiniMax TTS, Ollama Web Search, and MiniMax Search integrations for chat, speech, and search workflows. (#60032, #55921, #59318, #54648).
- Providers/Amazon Bedrock: add bundled Mantle support plus inference-profile discovery and automatic request-region injection so Bedrock-hosted Claude, GPT-OSS, Qwen, Kimi, GLM, and similar routes work with less manual setup. (#61296, #61299) Thanks @wirjo.
- Control UI/multilingual: add localized control UI support for Simplified Chinese, Traditional Chinese, Brazilian Portuguese, German, Spanish, Japanese, Korean, French, Turkish, Indonesian, Polish, and Ukrainian. Thanks @vincentkoc.
- Plugins: add plugin-config TUI prompts to guided onboarding/setup flows, and add
openclaw plugins install --forceso existing plugin and hook-pack targets can be replaced without using the dangerous-code override flag. (#60590, #60544). - Control UI/skills: add ClawHub search, detail, and install flows directly in the Skills panel. (#60134) Thanks @samzong.
- iOS/exec approvals: add generic APNs approval notifications that open an in-app exec approval modal, fetch command details only after authenticated operator reconnect, and clear stale notification state when the approval resolves. (#60239) Thanks @ngutman.
- Matrix/exec approvals: add Matrix-native exec approval prompts with account-scoped approvers, channel-or-DM delivery, and room-thread aware resolution handling. (#58635) Thanks @gumadeiras.
- Channels/context visibility: add configurable
contextVisibilityper channel (all,allowlist,allowlist_quote) so supplemental quote, thread, and fetched history context can be filtered by sender allowlists instead of always passing through as received. - Providers/request overrides: add shared model and media request transport overrides across OpenAI-, Anthropic-, Google-, and compatible provider paths, including headers, auth, proxy, and TLS controls. (#60200) Thanks @vincentkoc.
- Providers/OpenAI: add forward-compat
openai-codex/gpt-5.4-mini, an opt-in GPT personality, and provider-owned GPT-5 prompt contributions so Codex/GPT runs stay cache-stable and compatible with bundled catalog lag. - Agents/Claude CLI: expose OpenClaw tools to background Claude CLI runs through a loopback MCP bridge and switch bundled runs to stdin +
stream-jsonpartial-message streaming so prompts stop riding argv, long replies show live progress, and final session/usage metadata still land cleanly. (#35676) Thanks @mylukin. - ACPX/runtime: embed the ACP runtime directly in the bundled
acpxplugin, remove the extra external ACP CLI hop, harden live ACP session binding and reuse, and add a genericreply_dispatchhook so bundled plugins like ACPX can own reply interception without hardcoded ACP paths in core auto-reply routing. (#61319). - Agents/progress: add experimental structured plan updates and structured execution item events so compatible UIs can show clearer step-by-step progress during long-running runs.
- Providers/Anthropic: remove the Claude CLI backend and setup-token from new onboarding, keep existing configured legacy profiles runnable, and have
openclaw doctorrepair or remove staleanthropic:claude-clistate during migration. - Tools/video generation: add bundled xAI (
grok-imagine-video), Alibaba Model Studio Wan, and Runway video providers, plus live-test/default model wiring for all three. - Memory/search: add Amazon Bedrock embeddings for Titan, Cohere, Nova, and TwelveLabs models, with AWS credential-chain auto-detection for
provider: "auto"and provider-specific dimension controls. Thanks @wirjo. - Providers/Amazon Bedrock Mantle: generate bearer tokens from the AWS credential chain so Mantle auto-discovery can use IAM auth without manually exporting
AWS_BEARER_TOKEN_BEDROCK. Thanks @wirjo. - Memory/dreaming (experimental): add weighted short-term recall promotion, a
/dreamingcommand, Dreams UI, multilingual conceptual tagging, and doctor/status repair support, while refactoring dreaming from competing modes into three cooperative phases (light, deep, REM) with independent schedules and recovery behavior so durable memory promotion can run in the background with less manual setup. (#60569, #60697) Thanks @vignesh07. - Memory/dreaming: add configurable aging controls (
recencyHalfLifeDays,maxAgeDays) plus optional verbose logging so operators can tune recall decay and inspect promotion decisions more easily. - Memory/dreaming: add REM preview tooling (
openclaw memory rem-harness,promote-explain), surface possible lasting truths during REM staging, and make deep promotion replay-safe so reruns reconcile instead of duplicatingMEMORY.mdentries. - Memory/dreaming: write dreaming trail content to top-level
dreams.mdinstead of daily memory notes, update/dreaminghelp text to point there, and keepdreams.mdavailable for explicit reads without pulling it into default recall. Thanks @davemorin. - Memory/dreaming: add the Dream Diary surface in Dreams, simplify user-facing dreaming config to
enabledplus optionalfrequency, treat phases as implementation detail in docs/UI, and keep the lobster animation visible above diary content. Thanks @vignesh07. - Prompt caching: keep prompt prefixes more reusable across transport fallback, deterministic MCP tool ordering, compaction, embedded image history, normalized system-prompt fingerprints,
openclaw status --verbosecache diagnostics, and the removal of duplicate in-band tool inventories from agent system prompts so follow-up turns hit cache more reliably. (#58036, #58037, #58038, #59054, #60603, #60691) Thanks @bcherny and @vincentkoc. - Agents/cache: diagnostics: add prompt-cache break diagnostics, trace live cache scenarios through embedded runner paths, and show cache reuse explicitly in
openclaw status --verbose. Thanks @vincentkoc. - Agents/cache: stabilize cache-relevant system prompt fingerprints by normalizing equivalent structured prompt whitespace, line endings, hook-added system context, and runtime capability ordering so semantically unchanged prompts reuse KV/cache more reliably. Thanks @vincentkoc.
- Agents/tool prompts: remove the duplicate in-band tool inventory from agent system prompts so tool-calling models rely on the structured tool definitions as the single source of truth, improving prompt stability and reducing stale tool guidance.
- Config/schema: enrich the exported
openclaw config schemaJSON Schema with field titles and descriptions so editors, agents, and other schema consumers receive the same config help metadata. (#60067) Thanks @solavrc. - Matrix/exec approvals: clarify unavailable-approval replies so Matrix no longer claims chat approvals are unsupported when native exec approvals are merely unconfigured. (#61424) Thanks @gumadeiras.
- Providers/OpenAI Codex: add forward-compat
openai-codex/gpt-5.4-minisynthesis across provider runtime, model catalog, and model listing so Codex mini works before bundled Pi catalog updates land. - Providers/OpenAI: add an opt-in GPT personality and move GPT-5 prompt tuning onto provider-owned system-prompt contributions so cache-stable guidance stays above the prompt cache boundary and embedded runner paths reuse the same provider-specific prompt behavior.
- Docs/IRC: replace public IRC hostname examples with
irc.example.comand recommend private servers for bot coordination while listing common public networks for intentional use. - Memory/dreaming: group nearby daily-note lines into short coherent chunks before staging them for dreaming, so one-off context from recent notes reaches REM/deep with better evidence and less line-level noise (#61583). Thanks @mbelinky.
- Memory/dreaming: drop generic date/day headings from daily-note chunk prefixes while keeping meaningful section labels, so staged snippets stay cleaner and more reusable. (#61597) Thanks @mbelinky.
- Plugins/Lobster: run bundled Lobster workflows in process instead of spawning the external CLI, reducing transport overhead and unblocking native runtime integration. (#61523) Thanks @mbelinky.
- Plugins/Lobster: harden managed resume validation so invalid TaskFlow resume calls fail earlier, and memoize embedded runtime loading per runner while keeping failed loads retryable. (#61566) Thanks @mbelinky.
- Agents/bootstrap: add opt-in
agents.defaults.contextInjection: "continuation-skip"so safe continuation turns can skip workspace bootstrap re-injection, while heartbeat runs and post-compaction retries still rebuild context when needed. Fixes #9157. Thanks @cgdusek.
Fixes
- Control UI/chat: show
/ttsand other local audio-only slash replies in webchat by embedding local audio in the assistant message and rendering<audio>controls instead of dropping empty-text finals. Fixes #61564. (#61598) Thanks @neeravmakwana. - Security: preserve restrictive plugin-only tool allowlists, require owner access for
/allowlist addand/allowlist remove, fail closed whenbefore_tool_callhooks crash, block browser SSRF redirect bypasses earlier, and keep non-interactive auth-choice inference scoped to bundled and already-trusted plugins. (#58476, #59836, #59822, #58771, #59120) Thanks @eleqtrizit and @pgondhi987. - Providers/OpenAI: make GPT-5 and Codex runs act sooner with lower-verbosity defaults, visible progress during tool work, and a one-shot retry when a turn only narrates the plan instead of taking action.
- Providers/OpenAI and reply delivery: preserve native
reasoning.effort: "none"and strict schemas where supported, add GPT-5.4 assistantphasemetadata across replay and the Gateway/v1/responseslayer, and keep commentary buffered untilfinal_answerso web chat, session previews, embedded replies, and Telegram partials stop leaking planning text. Fixes #59150, #59643, #61282. - Telegram: fix current-model checks in the model picker, HTML-format non-default
/modelconfirmations, explicit topic replies, persisted reaction ownership across restarts, caption-media placeholder andfile_idpreservation on download failure, and upgraded-install inbound image reads. (#60384, #60042, #59634, #59207, #59948, #59971) Thanks @sfuminya, @GitZhangChi, @dashhuang, @samzong, @v1p0r, and @neeravmakwana. - Telegram: restore DM voice-note preflight transcription so direct-message audio stops arriving as raw
<media:audio>placeholders. (#61008) Thanks @manueltarouca. - Telegram/reasoning: only create a Telegram reasoning preview lane when the session is explicitly
reasoning:stream, so hidden<think>traces from streamed replies stop surfacing as chat previews on normal sessions. Thanks @vincentkoc. - Telegram/native command menu: trim long menu descriptions before dropping commands so sub-100 command sets can still fit Telegram's payload budget and keep more
/entries visible. (#61129) Thanks @neeravmakwana. - Telegram/startup: bound
deleteWebhook,getMe, andsetWebhookstartup requests while keeping the longergetUpdatespoll timeout, so wedged Telegram control-plane calls stop hanging startup indefinitely. (#61601) Thanks @neeravmakwana. - Agents/failover: classify Anthropic "extra usage" exhaustion as billing so same-turn model fallback still triggers when Claude blocks long-context requests on usage limits. (#61608) Thanks @neeravmakwana.
- Discord: keep REST, webhook, and monitor traffic on the configured proxy, preserve component-only media sends, honor
@everyoneand@heremention gates, keep ACK reactions on the active account, and split voice connect/playback timeouts so auto-join is more reliable. (#57465, #60361, #60345) Thanks @geekhuashan. - Discord/reply tags: strip leaked
[[reply_to_current]]control tags from preview text and honor explicit reply-tag threading during final delivery, so Discord replies stay attached to the triggering message instead of printing reply metadata into chat. - Discord/replies: replace the unshipped
replyToOnlyWhenBatchedflag withreplyToMode: "batched"so native reply references only attach on debounced multi-message turns while explicit reply tags still work. - Discord/image generation: include the real generated
MEDIA:paths in tool output, avoid duplicate plain-output media requeueing, and persist volatile workspace-generated media into durable outbound media before final reply delivery so generated image replies stop pointing at missing local files. - Slack: route live DM replies back to the concrete inbound DM channel while keeping persisted routing metadata user-scoped, so normal assistant replies stop disappearing when pairing and system messages still arrive. (#59030) Thanks @afurm.
- WhatsApp: restore
channels.whatsapp.blockStreamingand reset watchdog timeouts after reconnect so quiet chats stop falling into reconnect loops. (#60007, #60069) Thanks @MonkeyLeeT and @mcaxtr. - Android/Talk Mode: cancel in-flight
talk.speakplayback when speech is explicitly stopped, and restore spoken replies on both node-scoped and gateway-backed sessions by keeping reply routing and embedded transport overrides aligned with the current playback path. (#60306, #61164, #61214). - Voice-call/OpenAI: pass full plugin config into realtime transcription provider resolution so streaming calls can discover the bundled OpenAI realtime transcription provider again. Fixes #60936. Thanks @sliekens and @vincentkoc.
- Matrix/exec approvals: anchor seeded approval reactions to the primary Matrix prompt event, resolve them from event metadata instead of prompt text, and clean up chunked approval prompts correctly. (#60931) Thanks @gumadeiras.
- Matrix: recover more reliably when secret storage or recovery keys are missing by recreating secret storage during repair and backup reset, hold crypto snapshot locks during persistence, and surface explicit too-large attachment markers. (#59846, #59851, #60599, #60289) Thanks @al3mart, @emonty, and @efe-arv.
- Matrix/DM sessions: add
channels.matrix.dm.sessionScope, shared-session collision notices, and aligned outbound session reuse so separate Matrix DM rooms can keep distinct context when configured. (#61373) Thanks @gumadeiras. - Matrix: move legacy top-level
avatarUrlinto the default account during multi-account promotion and keep env-backed account setup avatar config persisted. (#61437) Thanks @gumadeiras. - MS Teams: download inline DM images via Graph API and preserve channel reply threading in proactive fallback. (#52212, #55198) Thanks @Ted-developer and @hyojin.
- MS Teams: replace the deprecated Teams SDK HttpPlugin stub with
httpServerAdapterso recurring gateway deprecation warnings stop firing and the Express 5 compatibility workaround stays on the supported SDK path. (#60939) Thanks @coolramukaka-sys. - Control UI/chat: add a per-session thinking-level picker in the chat header and mobile chat settings, and keep the browser bundle on UI-local thinking/session-key helpers so Safari no longer crashes on Node-only imports before rendering chat controls.
- Sandbox/SSH: reject hardlinked files during cross-device rename fallback so EXDEV file copies preserve the same pinned file-boundary checks as direct reads.
- Control UI: keep Stop visible during tool-only execution, preserve pending-send busy state, and clear stale ClawHub search results as soon as the query changes. (#54528, #59800, #60267) Thanks @chziyue and @frankekn.
- Control UI/avatar: honor
ui.assistant.avatarwhen serving/avatar/:agentIdso Appearance UI avatar paths stop falling back to initials placeholders. (#60778) Thanks @hannasdev. - Control UI/cron: highlight the Cron refresh button while refresh is in flight so the page's loading state stays visible even when prior data remains on screen. (#60394) Thanks @coder-zhuzm.
- Control UI/Overview: prevent gateway access token/password visibility toggle buttons from overlapping their inputs at narrow widths. (#56924) Thanks @bbddbb1.
- Auto-reply: unify reply lifecycle ownership across preflight compaction, session rotation, CLI-backed runs, and gateway restart handling so
/stopand same-session overlap checks target the right active turn and restart-interrupted turns return the restart notice instead of being silently dropped. (#61267) Thanks @dutifulbob. - Reply delivery: prevent duplicate block replies on
text_endchannels so providers that emit explicit text-end boundaries no longer double-send the same final message. (#61530). - Gateway/startup: default
gateway.modetolocalwhen unset, detect PID recycling in gateway lock files on Windows and macOS, and show startup progress so healthy restarts stop getting blocked by stale locks. (#54801, #60085, #59843) Thanks @BradGroux and @TonyDerek-dot. - Gateway/macOS: let launchd
KeepAliveown in-process gateway restarts again, adding a short supervised-exit delay so rapid restarts avoid launchd crash-loop unloads whileopenclaw gateway restartstill reports real LaunchAgent errors synchronously. - Gateway/macOS: re-bootstrap the LaunchAgent if
launchctl kickstart -kunloads it during restart so failed restarts do not leave the gateway unmanaged until manual repair. - Gateway/macOS: recover installed-but-unloaded LaunchAgents during
openclaw gateway startandrestart, while still preferring live unmanaged gateways during restart recovery. (#43766) Thanks @HenryC-3. - Gateway/Windows scheduled tasks: preserve Task Scheduler settings on reinstall, fail loudly when
/Rundoes not start, and report fast failed restarts accurately instead of pretending they timed out after 60 seconds. (#59335) Thanks @tmimmanuel. - Windows/restart: fall back to the installed Startup-entry launcher when the scheduled task was never registered, so
/restartcan relaunch the gateway on Windows setups whereschtasksinstall fell back during onboarding. (#58943) Thanks @imechZhangLY. - Windows/restart: clean up stale gateway listeners before Windows self-restart and treat listener and argv probe failures as inconclusive, so scheduled-task relaunch no longer falls into an
EADDRINUSEretry loop. (#60480) Thanks @arifahmedjoy. - Update/npm: prefer the npm binary that owns the installed global OpenClaw prefix so mixed Homebrew-plus-nvm setups update the right install. (#60153) Thanks @jayeshp19.
- Agents/music and video generation: add
tools.media.asyncCompletion.directSendas an opt-in direct-delivery path for finished async media tasks, while keeping the legacy requester-session wake/model-delivery flow as the default. - CLI/skills JSON: route
skills list --json,skills info --json, andskills check --jsonoutput to stdout instead of stderr so machine-readable consumers receive JSON on the expected stream again. (#60914; fixes #57599; landed from contributor PR #57611 by @Aftabbs) Thanks @Aftabbs. - CLI/Commander: preserve Commander-computed exit codes for argument and help-error paths, and cover the user-argv parse mode in the regression tests so invalid CLI invocations no longer report success when exits are intercepted. (#60923) Thanks @Linux2010.
- Cron: replay interrupted recurring jobs on the first gateway restart instead of waiting for a second restart. (#60583) Thanks @joelnishanth.
- Cron: send failure notifications through the job's primary delivery channel using the same session context as successful delivery when no explicit
failureDestinationis configured. (#60622) Thanks @artwalker. - Exec/remote skills: stop advertising
exec host=nodewhen the current exec policy cannot route to a node, and clarify blocked exec-host override errors with both the requested host and allowed config path. - Agents/Claude CLI/security: clear inherited Claude Code config-root and plugin-root env overrides like
CLAUDE_CONFIG_DIRandCLAUDE_CODE_PLUGIN_*, so OpenClaw-launched Claude CLI runs cannot be silently pointed at an alternate Claude config/plugin tree with different hooks, plugins, or auth context. Thanks @vincentkoc. - Agents/Claude CLI/security: clear inherited Claude Code provider-routing and managed-auth env overrides, and mark OpenClaw-launched Claude CLI runs as host-managed, so Claude CLI backdoor sessions cannot be silently redirected to proxy, Bedrock, Vertex, Foundry, or parent-managed token contexts. Thanks @vincentkoc.
- Agents/Claude CLI/security: force host-managed Claude CLI backdoor runs to
--setting-sources user, even under custom backend arg overrides, so repo-local.claudeproject/local settings, hooks, and plugin discovery do not silently execute inside non-interactive OpenClaw sessions. Thanks @vincentkoc. - Agents/Claude CLI: treat malformed bare
--permission-modebackend overrides as missing and fail safe back tobypassPermissions, so customcliBackends.claude-cli.argssecurity config cannot accidentally consume the next flag as a bogus permission mode. Thanks @vincentkoc. - Gateway/device pairing: require non-admin paired-device sessions to manage only their own device for token rotate/revoke and paired-device removal, blocking cross-device token theft inside pairing-scoped sessions. (#50627) Thanks @coygeek.
- Gateway/plugin routes: keep gateway-auth plugin runtime routes on write-only fallback scopes unless a trusted-proxy caller explicitly declares narrower
x-openclaw-scopes, so plugin HTTP handlers no longer mint admin-level runtime scopes on missing or untrusted HTTP scope headers. (#59815) Thanks @pgondhi987. - Build/types: fix the Node
createRequire(...)helper typing so provider-runtime lazy loads compile cleanly again andpnpm buildno longer fails in the Pi embedded provider error-pattern path. - Gateway/security: scope loopback browser-origin auth throttling by normalized origin so one localhost Control UI tab cannot lock out a different localhost browser origin after repeated auth failures. Thanks @vincentkoc.
- Gateway/auth: serialize async shared-secret auth attempts per client so concurrent Tailscale-capable failures cannot overrun the intended auth rate-limit budget. Thanks @Telecaster2147.
- Device pairing/security: keep non-operator device scope checks bound to the requested role prefix so bootstrap verification cannot redeem
operator.*scopes throughnodeauth. (#57258) Thanks @jlapenna. - Device pairing: reject rotating device tokens into roles that were never approved during pairing, and keep reconnect role checks bounded to the paired device's approved role set. (#60462) Thanks @eleqtrizit.
- Gateway/device auth: reuse cached device-token scopes only for cached-token reconnects, while keeping explicit
deviceTokenscope requests and empty-cache fallbacks intact so reconnects preserveoperator.readwithout breaking explicit auth flows. (#46032) Thanks @caicongyang. - Mobile pairing/security: fail closed for internal
/pairsetup-code issuance, cleanup, and approval paths when gateway pairing scopes are missing, and keep approval-time requested-scope enforcement on the internal command path. (#55996) Thanks @coygeek. - Mobile pairing/bootstrap: keep QR bootstrap handoff tokens bounded to the mobile-safe contract so node handoff stays unscoped and operator handoff drops mixed
node.*,operator.admin, andoperator.pairingscopes. Thanks @vincentkoc. - Mobile pairing/Android: tighten secure endpoint handling so Tailscale and public remote setup reject cleartext endpoints, private LAN pairing still works, merged-role approvals mint both node and operator device tokens, and bootstrap tokens survive node auto-pair until operator approval finishes. (#60128, #60208, #60221) Thanks @obviyus.
- Android/canvas security: require exact normalized A2UI URL matches before forwarding canvas bridge actions, rejecting query mismatches and descendant paths while still allowing fragment-only A2UI navigation.
- Synology Chat/security: default low-level HTTPS helper TLS verification to on so helper/API defaults match the shipped safe account default, and only explicit
allowInsecureSsl: trueopts out. Thanks @vincentkoc. - Synology Chat/security: route webhook token comparison through the shared constant-time secret helper for consistency with other bundled plugins. Thanks @vincentkoc.
- Plugins/marketplace: block remote marketplace symlink escapes without breaking ordinary local marketplace install paths. (#60556) Thanks @eleqtrizit.
- Telegram/local Bot API: honor
channels.telegram.apiRootfor buffered media downloads, addchannels.telegram.network.dangerouslyAllowPrivateNetworkfor trusted fake-IP setups, and requirechannels.telegram.trustedLocalFileRootsbefore reading absolute Bot APIfile_pathvalues. (#59544, #60705) Thanks @SARAMALI15792 and @obviyus. - Outbound/sanitizer: strip leaked
<tool_call>,<function_calls>, and model special tokens from shared user-visible assistant text, including truncated tool-call streams, so internal scaffolding no longer bleeds into replies across surfaces. (#60619) Thanks @oliviareid-svg. - Agents/errors: surface an explicit disk-full message when local session or transcript writes fail with
ENOSPC/disk full, so those runs stop degrading into opaqueNO_REPLY-style failures. Thanks @vincentkoc. - Exec approvals: remove heuristic command-obfuscation gating from host exec so gateway and node runs rely on explicit policy, allowlist, and strict inline-eval rules only.
- Agents/tool results: cap live tool-result persistence and overflow-recovery truncation at 40k characters so oversized tool output stays bounded without discarding recent context entirely.
- Discord/video replies: split text-plus-video deliveries into a text reply followed by a media-only send, and let live provider auth checks honor manifest-declared API key env vars like
MODELSTUDIO_API_KEY. - Config/All Settings: keep the raw config view intact when sensitive fields are blank instead of corrupting or dropping the rendered snapshot. (#28214) Thanks @solodmd.
- Plugin SDK/facades: back-fill bundled plugin facade sentinels before plugin-id tracking re-enters config loading, so CLI/provider startup no longer crashes with
shouldNormalizeGoogleProviderConfig is not a functionor other empty-facade reads during bundled plugin re-entry. Thanks @adam91holt. - Plugins/facades: back-fill facade sentinels before tracked-plugin resolution re-enters config loading, so facade exports stay defined during circular provider normalization. (#61180) Thanks @adam91holt.
- QA lab: restore typed mock OpenAI gateway config wiring so QA-lab config helpers compile cleanly again and
pnpm check/pnpm buildstay green. - Discord/image generation: include the real generated
MEDIA:paths in tool output and avoid duplicate plain-output media requeueing so Discord image replies stop pointing at missing local files (#61450). Thanks @gumadeiras. - Slack: route live DM replies back to the concrete inbound DM channel while keeping persisted routing metadata user-scoped, so normal assistant replies stop disappearing when pairing and system messages still arrive. (#59030) Thanks @afurm.
- Discord/reply tags: strip leaked
[[reply_to_current]]control tags from preview text and honor explicit reply-tag threading during final delivery, so Discord replies stay attached to the triggering message instead of printing reply metadata into chat. - Telegram: fix current-model checks in the model picker, HTML-format non-default
/modelconfirmations, explicit topic replies, persisted reaction ownership across restarts, caption-media placeholder andfile_idpreservation on download failure, and upgraded-install inbound image reads. (#60384, #60042, #59634, #59207, #59948, #59971) Thanks @sfuminya, @GitZhangChi, @dashhuang, @samzong, @v1p0r, and @neeravmakwana. - Telegram: restore DM voice-note preflight transcription so direct-message audio stops arriving as raw
<media:audio>placeholders. (#61008) Thanks @manueltarouca. - Telegram/reasoning: only create a Telegram reasoning preview lane when the session is explicitly
reasoning:stream, so hidden<think>traces from streamed replies stop surfacing as chat previews on normal sessions. Thanks @vincentkoc. - Telegram/native command menu: trim long menu descriptions before dropping commands so sub-100 command sets can still fit Telegram's payload budget and keep more
/entries visible. (#61129) Thanks @neeravmakwana. - Feishu/reasoning: only expose streamed reasoning previews when the session is explicitly
reasoning:stream, so hidden reasoning traces do not surface on normal streaming sessions. Thanks @vincentkoc. - Discord: keep REST, webhook, and monitor traffic on the configured proxy, preserve component-only media sends, honor
@everyoneand@heremention gates, keep ACK reactions on the active account, and split voice connect/playback timeouts so auto-join is more reliable. (#57465, #60361, #60345) Thanks @geekhuashan. - WhatsApp: restore
channels.whatsapp.blockStreamingand reset watchdog timeouts after reconnect so quiet chats stop falling into reconnect loops. (#60007, #60069) Thanks @MonkeyLeeT and @mcaxtr. - Browser/security: re-run SSRF safety checks after interaction-driven navigations and before snapshot reads so click, submit, keyboard, and current-page snapshot flows fail closed on disallowed destinations. (#62023) Thanks @eleqtrizit.
- Memory: keep
memory-corebuiltin embedding registration on the already-registered path so selectingmemory-coreno longer recurses through plugin discovery and crashes during startup. (#61402) Thanks @ngutman. - Agents/tool results: keep large
readoutputs visible longer, preserve the latestreadoutput when older tool output can absorb the overflow budget, and fall back to Pi's normal overflow compaction/retry path before replacing a freshreadwith a compacted stub. Thanks @vincentkoc. - Memory/QMD: prefer modern
qmd collection add --glob, accept newer single-line JSON hit metadata while keeping legacy line fields, refresh QMD docs/doctor install guidance and model-override guidance, and keep older QMD releases working. Thanks @vincentkoc. - MS Teams: download inline DM images via Graph API and preserve channel reply threading in proactive fallback. (#52212, #55198) Thanks @Ted-developer and @hyojin.
- MS Teams: replace the deprecated Teams SDK HttpPlugin stub with
httpServerAdapterso recurring gateway deprecation warnings stop firing and the Express 5 compatibility workaround stays on the supported SDK path. (#60939) Thanks @coolramukaka-sys. - Matrix/exec approvals: anchor seeded approval reactions to the primary Matrix prompt event, resolve them from event metadata instead of prompt text, and clean up chunked approval prompts correctly. (#60931) Thanks @gumadeiras.
- Matrix: recover more reliably when secret storage or recovery keys are missing by recreating secret storage during repair and backup reset, hold crypto snapshot locks during persistence, and surface explicit too-large attachment markers. (#59846, #59851, #60599, #60289) Thanks @al3mart, @emonty, and @efe-arv.
- Android/Talk Mode: cancel in-flight
talk.speakplayback when speech is explicitly stopped, so stale replies stop starting after barge-in or manual stop. (#61164) Thanks @obviyus. - Android/Talk Mode: restore spoken assistant replies on node-scoped sessions by keeping reply routing synced to the resolved node session key and pausing mic capture during reply playback. (#60306) Thanks @MKV21.
- Android/Talk Mode: restore voice replies on gateway-backed talk mode sessions by updating embedded runner transport overrides to the current agent transport API. (#61214) Thanks @obviyus.
- Voice-call/OpenAI: pass full plugin config into realtime transcription provider resolution so streaming calls can discover the bundled OpenAI realtime transcription provider again. Fixes #60936. Thanks @sliekens and @vincentkoc.
- Control UI/chat: add a per-session thinking-level picker in the chat header and mobile chat settings, and keep the browser bundle on UI-local thinking/session-key helpers so Safari no longer crashes on Node-only imports before rendering chat controls.
- Control UI: keep Stop visible during tool-only execution, preserve pending-send busy state, and clear stale ClawHub search results as soon as the query changes. (#54528, #59800, #60267) Thanks @chziyue and @frankekn.
- Control UI/avatar: honor
ui.assistant.avatarwhen serving/avatar/:agentIdso Appearance UI avatar paths stop falling back to initials placeholders. (#60778) Thanks @hannasdev. - Control UI/cron: highlight the Cron refresh button while refresh is in flight so the page's loading state stays visible even when prior data remains on screen. (#60394) Thanks @coder-zhuzm.
- Control UI/Overview: prevent gateway access token/password visibility toggle buttons from overlapping their inputs at narrow widths. (#56924) Thanks @bbddbb1.
- CLI/skills JSON: route
skills list --json,skills info --json, andskills check --jsonoutput to stdout instead of stderr so machine-readable consumers receive JSON on the expected stream again. (#60914; fixes #57599; landed from contributor PR #57611 by @Aftabbs) Thanks @Aftabbs. - CLI/Commander: preserve Commander-computed exit codes for argument and help-error paths, and cover the user-argv parse mode in the regression tests so invalid CLI invocations no longer report success when exits are intercepted. (#60923) Thanks @Linux2010.
- Cron: replay interrupted recurring jobs on the first gateway restart instead of waiting for a second restart. (#60583) Thanks @joelnishanth.
- Cron: send failure notifications through the job's primary delivery channel using the same session context as successful delivery when no explicit
failureDestinationis configured. (#60622) Thanks @artwalker. - Live model switching: only treat explicit user-driven model changes as pending live switches, so fallback rotation, heartbeat overrides, and compaction no longer trip
LiveSessionModelSwitchErrorbefore making an API call. (#60266) Thanks @kiranvk-2011. - Exec approvals: reuse durable exact-command
allow-alwaysapprovals in allowlist mode so identical reruns stop prompting, and tighten Windows interpreter/path approval handling so wrapper and malformed-path cases fail closed more consistently. (#59880, #59780, #58040, #59182) Thanks @luoyanglang, @SnowSky1, and @pgondhi987. - Node exec approvals: keep node-host
system.runapprovals bound to the prepared execution plan across async forwarding, so mutable script operands still get approval-time binding and drift revalidation instead of dropping back to unbound execution. - Agents/exec approvals: let
exec-approvals.jsonagent security override stricter gateway tool defaults so approved subagents can usesecurity: “fullâ€without falling back to allowlist enforcement again. (#60310) Thanks @lml2468. - Agents/exec: restore
host=noderouting for node-pinned andhost=autosessions, while still blocking sandboxedautosessions from jumping to gateway. (#60788) Thanks @openperf. - Exec/heartbeat: use the canonical
exec-eventwake reason fornotifyOnExitso background exec completions still trigger follow-up turns whenHEARTBEAT.mdis empty or comments-only. (#41479) Thanks @rstar327. - Heartbeat: skip wake delivery when the target session lane is already busy so the pending event is retried instead of getting drained too early. (#40526) Thanks @lucky7323.
- Group chats/agent prompts: tell models to minimize empty lines and use normal chat-style spacing so group replies avoid document-style blank-line formatting. Thanks @vincentkoc.
- Providers/OpenAI GPT: treat short approval turns like
ok do itandgo aheadas immediate action turns, and trim overly memo-like GPT-5 chat confirmations so OpenAI replies stay shorter and more conversational by default. Thanks @vincentkoc. - Providers/OpenAI Codex: split native
contextWindowfrom runtimecontextTokens, keep the default effective cap at272000, and expose a per-modelcontextTokensoverride onmodels.providers.*.models[]. Thanks @vincentkoc. - Providers/OpenAI-compatible WS: compute fallback token totals from normalized usage when providers omit or zero
total_tokens, so DashScope-compatible sessions stop storing zero totals after alias normalization. (#54940) Thanks @lyfuci. - Agents/OpenAI: mark Claude-compatible file tool schemas as
additionalProperties: falseso direct OpenAI GPT-5 routes stop rejecting thereadtool with invalid strict-schema errors. Thanks @vincentkoc. - Agents/OpenAI: fall back to
strict: falsefor native OpenAI tool calls when a tool schema is not strict-compatible, and normalize empty-object tool schemas to includerequired: [], so direct GPT-5 routes stop failing with invalid strict-schema errors like missingpathinrequired. - Agents/GPT: add explicit work-item lifecycle events for embedded runs, use them to surface real progress more reliably, and stop counting tool-started turns as planning-only retries. Thanks @vincentkoc.
- Plugins/OpenAI: enable
gpt-image-1reference-image edits through/images/editsmultipart uploads, and stop inferring unsupported resolution overrides when no explicitsizeorresolutionis provided. Thanks @vincentkoc. - Agents/replay: remove the malformed assistant-content canonicalization repair from replay history sanitization instead of extending that legacy repair path into replay validation.
- Plugins/OpenAI: tune the OpenAI prompt overlay for live-chat cadence so GPT replies stay shorter, more human, and less wall-of-text by default. Thanks @vincentkoc.
- Providers/compat: stop forcing OpenAI-only defaults on proxy and custom OpenAI-compatible routes, preserve native vendor-specific reasoning/tool/streaming behavior across Anthropic-compatible, Moonshot, Mistral, ModelStudio, OpenRouter, xAI, and Z.ai endpoints, and route GitHub Copilot Claude models through Anthropic Messages instead of OpenAI Responses. Thanks @vincentkoc.
- Providers/GitHub Copilot: send IDE identity headers on runtime model requests and GitHub token exchange so IDE-authenticated Copilot runs stop failing with missing
Editor-Version. (#60641) Thanks @VACInc and @vincentkoc. - Providers/OpenRouter failover: classify
403 “Key limit exceededâ€spending-limit responses as billing so model fallback continues instead of stopping on generic auth. (#59892) Thanks @rockcent. - Providers/Anthropic: keep
claude-cli/*auth on live Claude CLI credentials at runtime, avoid persisting stale bearer-token profiles, and suppress macOS Keychain prompts during non-interactive Claude CLI setup. (#61234) Thanks @darkamenosa. - Providers/Anthropic: when Claude CLI auth becomes the default, write a real
claude-cliauth profile so local and gateway agent runs can use Claude CLI immediately without missing-API-key failures. Thanks @vincentkoc. - Memory/dreaming: make Dreams config reads and writes respect the selected memory slot plugin (including
doctor.memory.statusand Control UI fallback state) instead of always targetingmemory-core. (#62275) Thanks @SnowSky1. - Providers/Anthropic Vertex: honor
cacheRetention: “longâ€with the real 1-hour prompt-cache TTL on Vertex AI endpoints, and defaultanthropic-vertexcache retention like direct Anthropic. (#60888) Thanks @affsantos. - Agents/Anthropic: preserve native
toolu_*replay ids on direct Anthropic and Anthropic Vertex paths so cache-sensitive history stops rewriting known-valid Anthropic tool-use ids. (#52612) Thanks @vincentkoc. - Providers/Google: add model-level
cacheRetentionsupport for direct Gemini system prompts by creating, reusing, and refreshingcachedContentsautomatically on Google AI Studio runs. (#51372) Thanks @rafaelmariano-glitch. - Google Gemini CLI auth: detect bundled npm installs by scanning packaged bundle files for the Gemini OAuth client config, so
npm install -g @google/gemini-clilayouts work again. (#60486) Thanks @wzfmini01. - Google Gemini CLI auth: detect personal OAuth mode from local Gemini settings and skip Code Assist project discovery for those logins, so personal Google accounts stop failing with
loadCodeAssist 400 Bad Request. (#49226) Thanks @bobworrall. - Google Gemini CLI auth: improve OAuth credential discovery across Windows nvm and Homebrew libexec installs, and align Code Assist metadata so Gemini login stops failing on packaged CLI layouts. (#40729) Thanks @hughcube.
- Google Gemini CLI models: add forward-compat support for stable
gemini-2.5-*model ids by letting the bundled CLI provider clone them from Google templates, sogemini-2.5-flash-liteand related configured models stop showing up as missing. (#35274) Thanks @mySebbe. - Google image generation: disable pinned DNS for Gemini image requests and honor explicit
pinDnsoverrides in shared provider HTTP helpers so proxy-backed image generation works again. (#59873) Thanks @luoyanglang. - Providers/Microsoft Foundry: preserve explicit image capability on normalized Foundry deployments, repair stale GPT/o-series text-only model metadata across gateway and runtime paths, and keep unknown fallback models from borrowing unrelated image support. Thanks @vincentkoc.
- Providers/Model Studio: preserve native streaming usage reporting for DashScope-compatible endpoints even when they are configured under a generic provider key, so streamed token totals stop sticking at zero. (#52395) Thanks @IVY-AI-gif.
- Providers/Z.AI: preserve explicitly registered
glm-5-*variants likeglm-5-turboinstead of intercepting them with the generic GLM-5 forward-compat shim. (#48185) Thanks @haoyu-haoyu. - Amazon Bedrock/aws-sdk auth: stop injecting the fake
AWS_PROFILEapiKey marker when no AWS auth env vars exist, so instance-role and other default-chain setups keep working without poisoning provider config. (#61194) Thanks @wirjo. - Agents/Kimi tool-call repair: preserve tool arguments that were already present on streamed tool calls when later malformed deltas fail reevaluation, while still dropping stale repair-only state before
toolcall_end. Thanks @vincentkoc. - Plugins/Kimi Coding: parse tagged tool calls and keep Anthropic-native tool payloads so Kimi coding endpoints execute tools instead of echoing raw markup. (#60051, #60391) Thanks @obviyus and @Eric-Guo.
- Media understanding: auto-register image-capable config providers for vision routing, so custom GLM-style provider ids with image models stop failing with “no media-understanding provider registeredâ€. (#51418) Thanks @xydt-610.
- Plugins/media understanding: enable bundled Groq and Deepgram providers by default so configured transcription models work without extra plugin activation config. (#59982) Thanks @yxjsxy.
- MiniMax/pricing: keep bundled MiniMax highspeed pricing distinct in provider catalogs and preserve the lower M2.5 cache-read pricing when onboarding older MiniMax models. (#54214) Thanks @octo-patch.
- MiniMax: advertise image input on bundled
MiniMax-M2.7andMiniMax-M2.7-highspeedmodel definitions so image-capable flows can route through the M2.7 family correctly. (#54843) Thanks @MerlinMiao88888888. - Models/MiniMax: honor
MINIMAX_API_HOSTfor implicit bundled MiniMax provider catalogs so China-hosted API-key setups pickapi.minimaxi.com/anthropicwithout manual provider config. (#34524) Thanks @caiqinghua. - Usage/MiniMax: invert remaining-style
usage_percentfields when MiniMax reports only remaining percentage data, so usage bars stop showing nearly-full remaining quota as nearly-exhausted usage. (#60254) Thanks @jwchmodx. - Usage/MiniMax: let usage snapshots treat
minimax-portaland MiniMax CN aliases as the same MiniMax quota surface, and prefer stored MiniMax OAuth before falling back to Coding Plan keys. Thanks @vincentkoc. - Usage/MiniMax: prefer the chat-model
model_remainsentry and derive Coding Plan window labels from MiniMax interval timestamps so MiniMax usage snapshots stop picking zero-budget media rows and misreporting 4h windows as5h. (#52349) Thanks @IVY-AI-gif. - Model picker/providers: treat bundled BytePlus and Volcengine plan aliases as their native providers during setup, and expose their bundled standard/coding catalogs before auth so setup can suggest the right models. (#58819) Thanks @Luckymingxuan.
- Tools/web_search (Kimi): when
tools.web.search.kimi.baseUrlis unset, inherit native Moonshot chatbaseUrl(.ai/.cn) so China console keys authenticate on the same host as chat. Fixes #44851. (#56769) Thanks @tonga54. - Agents/Claude CLI: keep non-interactive
--permission-mode bypassPermissionswhen customcliBackends.claude-cli.argsoverride defaults, including fallback resolution before the runtime plugin registry is active, so cron and heartbeat Claude CLI runs do not regress to interactive approval mode. (#61114) Thanks @cathrynlavery and @thewilloftheshadow. - Agents/Claude CLI: persist explicit
openclaw agent --session-idruns under a stable session key so follow-ups can reuse the stored CLI binding and resume the same underlying Claude session. Thanks @vincentkoc. - Agents/Claude CLI: persist routed Claude session bindings, rotate them on
/newand/reset, and keep live Claude CLI model switches moving across the configured Claude family so resumed sessions follow the real active thread and model. Thanks @vincentkoc. - Agents/CLI backends: invalidate stored CLI session reuse when local CLI login state or the selected auth profile credential changes, so relogin and token rotation stop resuming stale sessions. Thanks @vincentkoc.
- Agents/Claude CLI/images: reuse stable hydrated image file paths and preserve shared media extensions like HEIC when passing image refs to local CLI runs, so Claude CLI image prompts stop thrashing KV cache prefixes and oddball image formats do not fall back to
.bin. Thanks @vincentkoc. - Agents/compaction: keep assistant tool calls and displaced tool results in the same compaction chunk so strict summarization providers stop rejecting orphaned tool pairs. (#58849) Thanks @openperf.
- Agents/failover: scope Anthropic
An unknown error occurredfailover matching by provider so generic internal unknown-error text no longer triggers retryable timeout fallback. (#59325) Thanks @aaron-he-zhu. - Agents/subagents: honor allowlist validation, auth-profile handoff, and session override state when a subagent retries after
LiveSessionModelSwitchError. (#58178) Thanks @openperf. - Agents/runtime: make default subagent allowlists, inherited skills/workspaces, and duplicate session-id resolution behave more predictably, and include value-shape hints in missing-parameter tool errors. (#59944, #59992, #59858, #55317) Thanks @hclsys, @gumadeiras, @joelnishanth, and @priyansh19.
- Agents/pairing: merge completion announce delivery context with the requester session fallback so missing
tostill reaches the original channel, and includeoperator.talk.secretsin CLI default operator scopes for node-role device pairing approvals. (#56481) Thanks @maxpetrusenko. - Agents/scheduling: steer background-now work toward automatic completion wake and treat
processpolling as on-demand inspection or intervention instead of default completion handling. (#60877) Thanks @vincentkoc. - Agents/skills: skip
.gitandnode_moduleswhen mirroring skills into sandbox workspaces so read-only sandboxes do not copy repo history or dependency trees. (#61090) Thanks @joelnishanth. - ACP/agents: inherit the target agent workspace for cross-agent ACP spawns and fall back safely when the inherited workspace no longer exists. (#58438) Thanks @zssggle-rgb.
- ACPX/Windows: preserve backslashes and absolute
.exepaths in Claude CLI parsing, and fail fast on wrapper-script targets with guidance to usecmd.exe /c,powershell.exe -File, ornode <script>. (#60689). - Auth/failover: persist selected fallback overrides before retrying, shorten
auth_permanentlockouts, and refresh websocket/shared-auth sessions only when real auth changes occur so retries and secret rotations behave predictably. (#60404, #60323, #60387) Thanks @extrasmall0 and @mappel-nv. - Gateway/channels: pin the initial startup channel registry before later plugin-registry churn so configured channels stay visible and
channels.statusstops falling back to emptychannelOrder/channelspayloads after runtime plugin loads. Thanks @vincentkoc. - Prompt caching: order stable workspace project-context files before
HEARTBEAT.mdand keepHEARTBEAT.mdbelow the system-prompt cache boundary so heartbeat churn does not invalidate the stable project-context prefix. (#58979) Thanks @yozu and @vincentkoc. - Prompt caching: route Codex Responses and Anthropic Vertex through boundary-aware cache shaping, and report the actual outbound system prompt in cache traces so cache reuse and misses line up with what providers really receive. Thanks @vincentkoc.
- Agents/cache: preserve the full 3-turn prompt-cache image window across tool loops, keep colliding bundled MCP tool definitions deterministic, and reapply Anthropic Vertex cache shaping after payload hook replacements so KV/cache reuse stays stable. Thanks @vincentkoc.
- Status/cache: restore
cacheReadandcacheWritein transcript fallback so/statuskeeps showing cache hit percentages when session logs are the only complete usage source. (#59247) Thanks @stuartsy. - Status/usage: let
/statusandsession_statusfall back to transcript token totals when the session meta store stayed at zero, so LM Studio, Ollama, DashScope, and similar OpenAI-compatible providers stop showingContext: 0/.... (#55041) Thanks @jjjojoj. - Mattermost/config schema: accept
groups.*.requireMentionagain so existing Mattermost configs no longer fail strict validation after upgrade. (#58271) Thanks @MoerAI. - Doctor/config: compare normalized
talkconfigs by deep structural equality instead of key-order-sensitive serialization soopenclaw doctor --fixstops repeatedly reporting/applying no-optalk.provider/providersnormalization. (#59911) Thanks @ejames-dev. - Anthropic CLI onboarding: rewrite migrated fallback model refs during non-interactive Claude CLI setup too, so onboarding and scripted setup no longer keep stale
anthropic/*fallbacks after switching the primary model toclaude-cli/*. Thanks @vincentkoc. - Models/Anthropic CLI auth: replace migrated
agents.defaults.modelsallowlists whenopenclaw models auth login --provider anthropic --method cli --set-defaultswitches toclaude-cli/*, so staleanthropic/*entries do not linger beside the migrated Claude CLI defaults. Thanks @vincentkoc. - Doctor/Claude CLI: add dedicated Claude CLI health checks so
openclaw doctorcan spot missing local installs or broken auth before agent runs fail. Thanks @vincentkoc. - Plugins/auth-choice: apply provider-owned auth config patches without recursively preserving replaced default-model maps, so Anthropic Claude CLI and similar migrations can intentionally swap model allowlists during onboarding and setup instead of accumulating stale entries. Thanks @vincentkoc.
- Plugins/onboarding: write dotted plugin uiHint paths like Brave
webSearch.modeas nested plugin config sollm-contextsetup stops failing validation. (#61159) Thanks @obviyus. - Plugins/install: preserve unsafe override flags across linked plugin and hook-pack probes so local
--linkinstalls honor the documented override behavior. (#60624) Thanks @JerrettDavis. - Plugins/cache: inherit the active gateway workspace for provider, web-search, and web-fetch snapshot loads when callers omit
workspaceDir, so compatible plugin registries and snapshot caches stop missing on gateway-owned runtime paths. (#61138) Thanks @jzakirov. - Plugin SDK/context engines: export the missing context-engine result and subagent lifecycle types from
openclaw/plugin-sdkso context engine plugins can typeContextEngineimplementations without local workarounds. (#61251) Thanks @DaevMithran. - Tasks/maintenance: reconcile stale cron and chat-backed CLI task rows against live cron-job and agent-run ownership instead of treating any persisted session key as proof that the task is still running. (#60310) Thanks @lml2468.
- Plugins: suppress trust-warning noise during non-activating snapshot and CLI metadata loads. (#61427) Thanks @gumadeiras.
- Agents/video generation: accept
agents.defaults.videoGenerationModelin strict config validation andopenclaw config set/get, so gateways usingvideo_generateno longer fail to boot after enabling a video model. - Matrix/streaming: add a quiet preview mode for streamed Matrix replies, keep legacy
partialpreview-first behavior, and finalize quiet media captions correctly so previews stop notifying early without dropping final text semantics. (#61450) Thanks @gumadeiras. - Agents/compaction: skip redundant partial summarization when no messages were oversized, so the same transcript is not summarized twice after a full summarization failure. Fixes #61465. (#61603) Thanks @neeravmakwana.
- Gateway/shutdown: bound websocket-server shutdown even when no tracked clients remain, so gateway restarts stop hanging until the watchdog kills the process. (#61565) Thanks @mbelinky.
- Control UI/multilingual: localize the remaining shared channel, instances, nodes, and gateway-confirmation strings so the dashboard stops mixing translated UI with hardcoded English labels. Thanks @vincentkoc.
- Discord/media: raise the default inbound and outbound media cap to
100MBso Discord matches Telegram more closely and larger attachments stop failing on the old low default. - Matrix: keep direct transport requests on the pinned dispatcher by routing them through undici runtime fetch, so Matrix clients resume syncing on newer runtimes without dropping the validated address binding. (#61595) Thanks @gumadeiras.
- Plugins/facades: resolve globally installed bundled-plugin runtime facades from registry roots so bundled channels like LINE still boot when the winning plugin install lives under the global extensions directory with an encoded scoped folder name. (#61297) Thanks @openperf.
- Matrix: avoid failing startup when token auth already knows the user ID but still needs optional device metadata, retry transient auth bootstrap requests, and backfill missing device IDs after startup while keeping unknown-device storage reuse conservative until metadata is repaired. (#61383) Thanks @gumadeiras.
- Agents/exec: stop streaming
tool_execution_updateevents after an exec session backgrounds, preventing delayed background output from hitting a stale listener and crashing the gateway while keeping the output available throughprocess poll/log. (#61627) Thanks @openperf. - Matrix: pass configured
deviceIdthrough health probes and keep probe-only client setup out of durable Matrix storage, so health checks preserve the correct device identity without rewritingstorage-meta.jsonor related probe state on disk. (#61581) Thanks @MoerAI. - Image generation/build: write stable runtime alias files into
dist/and route provider-auth runtime lookups through those aliases so image-generation providers keep resolving auth/runtime modules after rebuilds instead of crashing on missing hashed chunk files (#57816). Thanks @ForestDengHK. - Config/runtime: pin the first successful config load in memory for the running process and refresh that snapshot on successful writes/reloads, so hot paths stop reparsing
openclaw.jsonbetween watcher-driven swaps (#57816). Thanks @ForestDengHK. - Config/legacy cleanup: stop probing obsolete alternate legacy config names and service labels during local config/service detection, while keeping the active
~/.openclaw/openclaw.jsonpath canonical (#57816). Thanks @ForestDengHK. - ACP/sessions_spawn: register ACP child runs for completion tracking and lifecycle cleanup, and make registration-failure cleanup explicitly best-effort so callers do not assume an already-started ACP turn was fully aborted. (#40885) Thanks @xaeon2026 and @vincentkoc.
- ACP/tasks: mark cleanly exited ACP runs as blocked when they end on deterministic write or authorization blockers, and wake the parent session with a follow-up instead of falsely reporting success (#57816). Thanks @ForestDengHK.
- ACPX/runtime: derive the bundled ACPX expected version from the extension package metadata instead of hardcoding a separate literal, so plugin-local ACPX installs stop drifting out of health-check parity after version bumps. (#49089) Thanks @jiejiesks and @vincentkoc.
- Gateway/auth: make local-direct
trusted-proxyfallback require the configured shared token instead of silently authenticating same-host callers, while keeping same-host reverse proxy identity-header flows on the normal trusted-proxy path. Thanks @zhangning-agent and @vincentkoc. - Memory/QMD: send MCP
querycollection filters as the upstreamcollectionsarray instead of the legacy singularcollectionfield, so mcporter-backed QMD 1.1+ searches still scope correctly after the unifiedquerytool migration. (#54728) Thanks @armanddp and @vincentkoc. - Memory/QMD: keep
qmd embedactive insearchmode too, so BM25-first setups still build a complete index for later vector and hybrid retrieval. (#54509) Thanks @hnshah and @vincentkoc. - Memory/QMD: point
QMD_CONFIG_DIRat the nestedxdg-config/qmddirectory so per-agent collection config resolves correctly. (#39078) Thanks @smart-tinker and @vincentkoc. - Memory/QMD: include deduplicated default plus per-agent
memorySearch.extraPathswhen building QMD custom collections, so shared and agent-specific extra roots both get indexed consistently. (#57315) Thanks @Vitalcheffe and @vincentkoc. - Memory/session indexer: include
.jsonl.reset.*and.jsonl.deleted.*transcripts in the memory host session scan while still excluding.jsonl.bak.*compaction backups and lock files, so memory search sees archived session history without duplicating stale snapshots. Thanks @hclsys and @vincentkoc. - Agents/sandbox: honor
tools.sandbox.tools.alsoAllow, let explicit sandbox re-allows remove matching built-in default-deny tools, and keep sandbox explain/error guidance aligned with the effective sandbox tool policy. (#54492) Thanks @ngutman. - LINE/ACP: add current-conversation binding and inbound binding-routing parity so
/acp spawn .. --thread here, configured ACP bindings, and active conversation-bound ACP sessions work on LINE like the other conversation channels (#57816). Thanks @ForestDengHK. - LINE/markdown: preserve underscores inside Latin, Cyrillic, and CJK words when stripping markdown, while still removing standalone
_italic_markers on the shared text-runtime path used by LINE and TTS. (#47465) Thanks @jackjin1997. - TTS/Microsoft: auto-switch the default Edge voice to Chinese for CJK-dominant text without overriding explicitly selected Microsoft voices. (#52355) Thanks @extrasmall0.
- Agents/context pruning: count supplementary-plane CJK characters with the shared code-point-aware estimator so context pruning stops underestimating Japanese and Chinese text that uses Extension B ideographs. (#39985) Thanks @Edward-Qiang-2024.
- Slack/status reactions: add a reaction lifecycle for queued, thinking, tool, done, and error phases in Slack monitors, with safer cleanup so queued ack reactions stay correct across silent runs, pre-reply failures, and delayed transitions. (#56430) Thanks @hsiaoa.
- macOS/local gateway: stop OpenClaw.app from killing healthy local gateway listeners after startup by recognizing the current
openclaw-gatewayprocess title and using the currentopenclaw gatewaylaunch shape (#57816). Thanks @ForestDengHK. - Gateway/OpenAI compatibility: accept flat Responses API function tool definitions on
/v1/responsesand preservestrictwhen normalizing hosted tools into the embedded runner, so spec-compliant clients like Codex no longer fail validation or silently lose strict tool enforcement. Thanks @malaiwah and @vincentkoc. - Memory/QMD: resolve slugified
memory_searchfile hints back to the indexed filesystem path before returning search hits, somemory_getworks again for mixed-case and spaced paths. (#50313) Thanks @erra9x. - OpenAI/Codex fast mode: map
/fastto priority processing on native OpenAI and Codex Responses endpoints instead of rewriting reasoning settings, and document the exact endpoint and override behavior (#57816). Thanks @ForestDengHK. - Memory/QMD: weight CJK-heavy text correctly when estimating chunk sizes, preserve surrogate-pair characters during fine splits, and keep long Latin lines on the old chunk boundaries so memory indexing produces better-sized chunks for CJK notes. (#40271) Thanks @AaronLuo00.
- Security/LINE: make webhook signature validation run the timing-safe compare even when the supplied signature length is wrong, closing a small timing side-channel. (#55663) Thanks @gavyngong.
- LINE/status: stop
openclaw statusfrom warning about missing credentials when sanitized LINE snapshots are already configured, while still surfacing whether the missing field is the token or secret. (#45701) Thanks @tamaosamu. - Gateway/health: carry webhook-vs-polling account mode from channel descriptors into runtime snapshots so passive channels like LINE and BlueBubbles skip false stale-socket health failures. (#47488) Thanks @karesansui-u.
- Agents/MCP: reuse bundled MCP runtimes across turns in the same session, while recreating them when MCP config changes and disposing stale runtimes cleanly on session rollover. (#55090) Thanks @allan0509.
- Memory/QMD: honor
memory.qmd.update.embedIntervaleven when regular QMD update cadence is disabled or slower by arming a dedicated embed-cadence maintenance timer, while avoiding redundant timers when regular updates are already frequent enough. (#37326) Thanks @barronlroth. - Memory/QMD: add
memory.qmd.searchToolas an exact mcporter tool override, so custom QMD MCP tools such ashybrid_searchcan be used without weakening the validatedsearchModeconfig surface. (#27801) Thanks @keramblock. - Memory/QMD: keep reset and deleted session transcripts in QMD session export so daily session resets do not silently drop most historical recall from
memory_search. (#30220) Thanks @pushkarsingh32. - Memory/QMD: rebind collections when QMD reports a changed pattern but omits path metadata, so config pattern changes stop being silently ignored on restart. (#49897) Thanks @Madruru.
- Memory/QMD: warn explicitly when
memory.backend=qmdis configured but theqmdbinary is missing, so doctor and runtime fallback no longer fail as a silent builtin downgrade. (#50439) Thanks @Jimmy-xuzimo and @vincentkoc. - Memory/QMD: pass a direct-session key on
openclaw memory searchso CLI QMD searches no longer get denied assession=<none>under direct-only scope defaults. (#43517) Thanks @waynecc-at and @vincentkoc. - Memory/QMD: keep
memory_searchsession-hit paths roundtrip-safe when exported session markdown lives under the workspaceqmd/directory, somemory_getcan read the exact returned path instead of failing on the genericqmd/sessions/...alias. (#43519) Thanks @holgergruenhagen and @vincentkoc. - Agents/memory flush: keep daily memory flush files append-only during embedded attempts so compaction writes do not overwrite earlier notes. (#53725) Thanks @HPluseven.
- Web UI/markdown: stop bare auto-links from swallowing adjacent CJK text while preserving valid mixed-script path and query characters in rendered links. (#48410) Thanks @jnuyao.
- BlueBubbles/iMessage: coalesce URL-only inbound messages with their link-preview balloon again so sharing a bare link no longer drops the URL from agent context. Thanks @vincentkoc.
- Sandbox/browser: install
fonts-noto-cjkin the sandbox browser image so screenshots render Chinese, Japanese, and Korean text correctly instead of tofu boxes. Fixes #35597. Thanks @carrotRakko and @vincentkoc. - Memory/FTS: add configurable trigram tokenization plus short-CJK substring fallback so memory search can find Chinese, Japanese, and Korean text without breaking mixed long-and-short queries. Thanks @carrotRakko.
- Hooks/config: accept runtime channel plugin ids in
hooks.mappings[].channel(for examplefeishu) instead of rejecting non-core channels during config validation. (#56226) Thanks @AiKrai001. - TUI/chat: keep optimistic outbound user messages visible during active runs by deferring local-run binding until the first gateway chat event reveals the real run id, preventing premature history reloads from wiping pending local sends. (#54722) Thanks @seanturner001.
- TUI/model picker: keep searchable
/modeland/modelsinput mode from hijackingj/kas navigation keys, and harden width bounds underm-filtered model lists so search no longer crashes on long rows. (#30156) Thanks @briannicholls. - Agents/Kimi: preserve already-valid Anthropic-compatible tool call argument objects while still clearing cached repairs when later trailing junk exceeds the repair allowance. (#54491) Thanks @yuanaichi.
- Docker/setup: force BuildKit for local image builds (including sandbox image builds) so
./docker-setup.shno longer fails onRUN --mount=...when hosts default to Docker's legacy builder. (#56681) Thanks @zhanghui-china. - Control UI/agents: auto-load agent workspace files on initial Files panel open, and populate overview model/workspace/fallbacks from effective runtime agent metadata so defaulted models no longer show as
Not set. (#56637) Thanks @dxsx84. - Control UI/slash commands: make
/steerand/redirectwork from the chat command palette with visible pending state for active-run/steer, correct redirected-run tracking, and a single canonical/steerentry in the command menu. (#54625) Thanks @fuller-stack-dev. - Exec/runtime: default implicit exec to
host=auto, resolve that target to sandbox only when a sandbox runtime exists, keep explicithost=sandboxfail-closed without sandbox, and show/execeffective host state in runtime status/docs (#57816). Thanks @ForestDengHK. - Exec: fail closed when the implicit sandbox host has no sandbox runtime, and stop denied async approval followups from reusing prior command output from the same session. (#56800) Thanks @scoootscooob.
- Exec/approvals: infer Discord and Telegram exec approvers from existing owner config when
execApprovals.approversis unset, extend the default approval window to 30 minutes, and clarify approval-unavailable guidance so approvals do not appear to silently disappear (#57816). Thanks @ForestDengHK. - Exec/node: stop gateway-side workdir fallback from rewriting explicit
host=nodecwd values to the gateway filesystem, so remote node exec approval and runs keep using the intended node-local directory. (#50961) Thanks @openperf. - Plugins/ClawHub: sanitize temporary archive filenames for scoped package names and slash-containing skill slugs so
openclaw plugins install @scope/nameno longer fails withENOENTduring archive download. (#56452) Thanks @soimy. - Telegram/polling: keep the watchdog from aborting long-running reply delivery by treating recent non-polling API activity as bounded liveness instead of a hard stall. (#56343) Thanks @openperf.
- Memory/FTS: keep provider-less keyword hits visible at the default memory-search threshold, so FTS-only recall works without requiring
--min-score 0. (#56473) Thanks @opriz. - Memory/LanceDB: resolve runtime dependency manifest lookup from the bundled
extensions/memory-lancedbpath (including flattened dist chunks) so startup no longer fails with a missing@lancedb/lancedbdependency error. (#56623) Thanks @LUKSOAgent. - Tools/web_search: localize the shared search cache to module scope so same-process global symbol lookups can no longer inspect or mutate cached web-search responses. Thanks @vincentkoc.
- Agents/silent turns: fail closed on silent memory-flush runs so narrated
NO_REPLYself-talk cannot stream or finalize into external replies even when block streaming is enabled. (#52593) Thanks @ForestDengHK. - Browser/plugins: auto-enable the bundled browser plugin when browser config or browser tool policy already references it, and show a clearer CLI error when
plugins.allowexcludesbrowser(#57816). Thanks @ForestDengHK. - Matrix/plugin loading: ship and source-load the crypto bootstrap runtime sidecar correctly so current
mainstops warning about failed Matrix bootstrap loads andmatrix/indexplugin-id mismatches on every invocation. (#53298) thanks @keithce. - iOS/Live Activities: mark the
ActivityKitimport inLiveActivityManager.swiftas@preconcurrencyso Xcode 26.4 / Swift 6 builds stop failing on strict concurrency checks. (#57180) Thanks @ngutman. - Plugins/Matrix: mirror the Matrix crypto WASM runtime dependency into the root packaged install and enforce root/plugin dependency parity so bundled Matrix E2EE crypto resolves correctly in shipped builds. (#57163) Thanks @gumadeiras.
- Plugins/CLI: add descriptor-backed lazy plugin CLI registration so Matrix can keep its CLI module lazy-loaded without dropping
openclaw matrix ...from parse-time command registration. (#57165) Thanks @gumadeiras. - Plugins/CLI: collect root-help plugin descriptors through a dedicated non-activating CLI metadata path so enabled plugins keep validated config semantics without triggering runtime-only plugin registration work, while preserving runtime CLI command registration for legacy channel plugins that still wire commands from full registration. (#57294) thanks @gumadeiras.
- Anthropic/OAuth: inject
/fastservice_tierhints for directsk-ant-oat-*requests so OAuth-authenticated Anthropic runs stop missing the same overload-routing signal as API-key traffic. Fixes #55758. Thanks @Cypherm and @vincentkoc. - Anthropic/service tiers: support explicit
serviceTiermodel params for direct Anthropic requests and let them override/fastdefaults when both are set. (#45453) Thanks @vincentkoc. - Auto-reply/fast: accept
/fast statuson the directive-only path, align help/status text with the documentedstatus|on|offsyntax, and keep current-state replies consistent across command surfaces. Fixes #46095. Thanks @weissfl and @vincentkoc. - Telegram/native commands: prefix native command menu callback payloads and preserve
CommandSource: "native"when Telegram replays them through callback queries, so/fastand other native command menus keep working even when text-command routing is disabled. Thanks @vincentkoc. - Docs/anchors: fix broken English docs links and make Mint anchor audits run against the English-source docs tree. (#57039) thanks @velvet-shark.
- Cron/announce: preserve all deliverable text payloads for announce mode instead of collapsing to the last chunk, so multi-line cron reports deliver in full to Telegram forum topics (#57816). Thanks @ForestDengHK.
- Harden async approval followup delivery in webchat-only sessions (#57359) Thanks @joshavant.
- Status: fix cache hit rate exceeding 100% by deriving denominator from prompt-side token fields instead of potentially undersized totalTokens. Fixes #26643 (#57816). Thanks @ForestDengHK.
- Config/update: stop
openclaw doctorwrite-backs from persisting plugin-injected channel defaults, soopenclaw updateno longer seeds config keys that later break service refresh validation. (#56834) Thanks @openperf. - Agents/Anthropic failover: treat Anthropic
api_errorpayloads withAn unexpected error occurred while processing the responseas transient so retry/fallback can engage instead of surfacing a terminal failure. (#57441) Thanks @zijiess and @vincentkoc. - Agents/compaction: keep late compaction-retry rejections handled after the aggregate timeout path wins without swallowing real pre-timeout wait failures, so timed-out retries no longer surface an unhandled rejection on later unsubscribe. (#57451) Thanks @mpz4life and @vincentkoc.
- Matrix/delivery recovery: treat Synapse
User not in roomreplay failures as permanent during startup recovery so poisoned queued messages move tofailed/instead of crash-looping Matrix after restart. (#57426) thanks @dlardo. - Plugins/facades: guard bundled plugin facade loads with a cache-first sentinel so circular re-entry stops crashing
xai,sglang, andvllmduring gateway plugin startup. (#57508) Thanks @openperf. - Agents/MCP: dispose bundled MCP runtimes after one-shot
openclaw agent --localruns finish, while preserving bundled MCP state across in-run retries so local JSON runs exit cleanly without restarting stateful MCP tools mid-run (#57816). Thanks @ForestDengHK. - Gateway/OpenAI HTTP: restore default operator scopes for bearer-authenticated requests that omit
x-openclaw-scopes, so headless/v1/chat/completionsand session-history callers work again after the recent method-scope hardening. (#57596) Thanks @openperf. - Gateway/attachments: offload large inbound images without leaking
media://markers into text-only runs, preserve mixed attachment order for model input/transcripts, and fail closed when model image capability cannot be resolved. (#55513) Thanks @Syysean. - Agents/subagents: fix interim subagent runtime display so
/subagents listand/subagents infostop inflating short runtimes and show second-level durations correctly. (#57739) Thanks @samzong. - Diffs/config: preserve schema-shaped plugin config parsing from
diffsPluginConfigSchema.safeParse(), so direct callers keepdefaultsandsecuritysections instead of receiving flattened tool defaults. (#57904) Thanks @gumadeiras. - Diffs: fall back to plain text when
langhints are invalid during diff render and viewer hydration, so bad or stale language values no longer break the diff viewer. (#57902) Thanks @gumadeiras. - Doctor/plugins: skip false Matrix legacy-helper warnings when no migration plans exist, and keep bundled
enabledByDefaultplugins in the gateway startup set. (#57931) Thanks @dinakars777. - Matrix/CLI send: start one-off Matrix send clients before outbound delivery so
openclaw message send --channel matrixrestores E2EE in encrypted rooms instead of sending plain events. (#57936) Thanks @gumadeiras. - xAI/Responses: normalize image-bearing tool results for xAI responses payloads, including OpenResponses-style
input_image.sourceparts, so image tool replays no longer 422 on the follow-up turn. (#58017) Thanks @neeravmakwana. - Cron/isolated sessions: carry the full live-session provider, model, and auth-profile selection across retry restarts so cron jobs with model overrides no longer fail or loop on mid-run model-switch requests. (#57972) Thanks @issaba1.
- Matrix/direct rooms: stop trusting remote
is_direct, honor explicit localis_direct: falsefor discovered DM candidates, and avoid extra member-state lookups for shared rooms so DM routing and repair stay aligned. (#57124) Thanks @w-sss. - Agents/sandbox: make remote FS bridge reads pin the parent path and open the file atomically in the helper so read access cannot race path resolution. Thanks @AntAISecurityLab and @vincentkoc.
- Tools/web_fetch: add an explicit trusted env-proxy path for proxy-only installs while keeping strict SSRF fetches on the pinned direct path, so trusted proxy routing does not weaken strict destination binding. (#50650) Thanks @kkav004.
- Exec/env: block Python package index override variables from request-scoped host exec environment sanitization so package fetches cannot be redirected through a caller-supplied index. Thanks @nexrin and @vincentkoc.
- Telegram/audio: transcode Telegram voice-note
.oggattachments before the localwhisper-cliauto fallback runs, and keep mention-preflight transcription enabled in auto mode whentools.media.audiois unset (#65984). Thanks @mbelinky. - Matrix/direct rooms: recover fresh auto-joined 1:1 DMs without eagerly persisting invite-only
m.directmappings, while keeping named, aliased, and explicitly configured rooms on the room path. (#58024) Thanks @gumadeiras. - TTS: Restore 3.28 schema compatibility and fallback observability. (#57953) Thanks @joshavant.
- Telegram/forum topics: restore reply routing to the active topic and keep ACP
sessions_spawn(..., thread=true, mode="session")bound to that same topic instead of falling back to root chat or losing follow-up routing. (#56060) Thanks @one27001. - Config/SecretRef + Control UI: harden SecretRef redaction round-trip restore, block unsafe raw fallback (force Form mode when raw is unavailable), and preflight submitted-config SecretRefs before config write RPC persistence. (#58044) Thanks @joshavant.
- Config/Telegram: migrate removed
channels.telegram.groupMentionsOnlyintochannels.telegram.groups["*"].requireMentionon load so legacy configs no longer crash at startup. (#55336) thanks @jameslcowan. - Gateway/SecretRef: resolve restart token drift checks with merged service/runtime env sources and hard-fail unsupported mutable SecretRef plus OAuth-profile combinations so restart warnings and policy enforcement match runtime behavior. (#58141) Thanks @joshavant.
- Telegram/outbound chunking: use static markdown chunking when Telegram runtime state is unavailable so long outbound Telegram messages still split correctly after cold starts. (#57816) Thanks @ForestDengHK.
- Update/Corepack: disable interactive Corepack download prompts during update preflight install unless
COREPACK_ENABLE_DOWNLOAD_PROMPTis already explicitly set, soopenclaw updatecan fetch the repo-pinned pnpm version non-interactively. (#61456) Thanks @p6l-richard.