openclaw/docs/plugins/hooks
Peter Steinberger c81d86e82f
fix: node turns bypass before_agent_run policies (#164270)
* fix: enforce input policies before node worker turns

Run before_agent_run under the retained plugin generation before node input
persistence or worker launch. Reuse the local/CLI fail-closed gate and redacted
message owner, fence blocked writes, and release the placement claim.

Lease proof: 148 owner/sibling tests; five regressions fail on original code;
core and core-test types, typed lint, and changed structural checks passed.
Live blocked input produced no node deltas/tools; a following tool turn passed.

Committed with --no-verify because the sparse worktree has no dependencies.
The full changed-file oxfmt check passed on the isolated AWS validation lease.

* refactor: consolidate node input preparation

Keep policy admission and admitted transcript context at the user-message owner. Reuse the standard hook context projection and remove narration and one-use type aliases.

Rebased owner/sibling proof: 71 tests pass; core types, typed lint, line cap, and formatting pass on the AWS lease. The sparse local pre-commit hook was skipped only after that remote formatting proof. Independent review found no actionable P0-P2 findings.
2026-10-03 04:37:28 -07:00
..
lifecycle.md
messages.md
prompt-and-session.md
reference.md fix: node turns bypass before_agent_run policies (#164270) 2026-10-03 04:37:28 -07:00
tool-policy.md test(config): author canonical agent rosters in fixtures and docs examples (#163475) 2026-10-02 04:42:31 -07:00