openclaw/extensions/openshell
Dallin Romney 8fb780c4e1
chore: prepare extended-stable 2026.8.33 (#151452)
* feat(meta): add Muse Spark 1.3 models (#136553)

* feat(meta): add Muse Spark 1.3 models

* docs(meta): cite Muse Spark 1.3 recommendation

Co-authored-by: Tharun Tej Tammineni <tharuntej@meta.com>

---------

Co-authored-by: Dallin Romney <dallinromney@gmail.com>
(cherry picked from commit 194b7f2a16)

* feat(anthropic): support Fable 5.1 from shared model metadata (#135638)

* feat(anthropic): support Fable 5.1 from shared model metadata

* test(anthropic): keep alias coverage within the file limit

* fix(media): decouple image limits from catalog augmentation

(cherry picked from commit 0a9b08c13a)

* feat(openai): support GPT Image 2.5 variants (#143068)

* feat(openai): support GPT Image 2.5 variants

* docs(openai): correct GPT Image 2.5 section link

(cherry picked from commit f93881f90f)

* feat(fal): support GPT Image 2.5 variants (#143069)

* feat(fal): support GPT Image 2.5 variants

* test(agents): restore Windows media fixture isolation

(cherry picked from commit a57c799c86)

* fix(bedrock): preserve images returned by tools (#149336)

## What Problem This Solves
Tool-returned images make the next request fail with `ValidationException` on affected Bedrock routes. Fixes #149332.

## Why This Change Was Made
The serializer generates image labels from each tool-call ID; input images need no labels. All consecutive tool results come first, followed by image groups in the same tool order. Request state has one writer. `stream.runtime.ts`: +28/−1 for this conversion.

Growth accepted under the owner's standing acceptance (2026-09-15).

## User Impact
Image-reading turns can finish without losing image bytes, tool associations, or error status.

## Evidence
Authenticated `chat.send` → registered `read` on a synthetic PNG: main sent a nested image and failed; candidate sent a sibling image and completed with the scripted “Red square; blue circle.” Our run used a recording HTTP transport.

The [contributor's real two-tool run](https://github.com/openclaw/openclaw/pull/149336#issuecomment-5689009422) confirms image interpretation and association.

## Compatibility
Concrete route identities select the conversion. Opaque aliases keep their layout. The general schema permits nested images for some routes; this repair addresses the affected route’s observed rejection. No config or public interface changes.

## Consumers
All clients use the existing Bedrock serializer.

## Invalidation
Conversion is request-local. Stored transcript rows and original image bytes remain unchanged.

## Tests
`node scripts/run-vitest.mjs run --config test/vitest/vitest.extension-providers.config.ts extensions/amazon-bedrock`: 289 tests across 12 files passed on a fresh merge with main. Types, lint, formatting, file-size and assertion limits, and unused-export checks passed.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
(cherry picked from commit 115522a653)

* fix: preserve Ultra across model runtime boundaries (#135397)

* fix: preserve Ultra across model runtime boundaries

Keep native Codex Ultra as a runtime mode instead of clamping it against
physical Responses effort tiers. Share the selected collaboration effort
between turn fields and remove the redundant forwarding wrapper.

Carry the active parent thinking level through existing spawn context so
one-shot overrides reach native subagents without changing saved preferences.
Keep explicit child overrides and configured child defaults authoritative.

Scope Control UI thinking catalog fallback to the selected runtime, sharing
one prepared entry for picker options and the inherited default. Document
the native orchestration/budget boundary and active-turn inheritance.

* refactor: simplify Ultra reasoning fixtures

* fix: preserve active thinking across shared tool contexts

* docs: clarify Off thinking for side questions

(cherry picked from commit ee9e22b521)

* fix(anthropic): Fable 5.1 sessions lose reasoning after model switches and runtime events (#136782)

* fix(anthropic): keep Fable 5.1 thinking valid across model switches and runtime context

Claude Fable 5.1 binds each thinking block to the producing model and to the
exact request prefix that preceded it. Three harness behaviors conflicted with
that contract on Anthropic-family routes:

- Moving a session onto Fable 5.1 (from Opus 5, Sonnet 5, Opus 4.8, Fable 5)
  dropped readable reasoning client-side; the replay contract now preserves it
  while leaving Fable 5.1 still drops.
- The per-turn runtime-context carrier was injected transiently after the
  active user turn, stripped on the next request, relocated inside tool loops,
  and removed by the context-engine assembly. It is now persisted right after
  its user turn and replayed in place; inline inbound metadata stays in place
  too, and consecutive user turns are no longer merged at load for the
  Messages API because the merged form lost the second turn's timestamp stamp.
- Direct API-key requests with adaptive thinking send the
  thinking-binding-controls beta with prefix_mismatch_behavior=drop_block, so
  a residual mismatch degrades to a server-side unbilled drop with a warning
  listing the dropped paths instead of a 400, a duplicate request, and a
  transcript-wide thinking wipe. OAuth, proxies, Bedrock, Vertex, and Foundry
  keep the existing strip-and-retry recovery.

Live-verified against api.anthropic.com: nine-request Fable/Opus/Fable session
with tool loops and carriers reports input_transformations: [] on every
request with four retained thinking blocks; a /think change on the direct API
yields a logged server-side drop and no retry.

* fix(anthropic): limit the preserved-thinking replay target to Fable 5.1

Mythos 5.1 is not registered in the bundled catalog and has no cross-model
replay proof, so unregistered Mythos targets keep the existing drop path.

(cherry picked from commit 30837ae703)

* feat(openai): support GPT-6 Astra (#137550)

* feat(openai): support GPT-6 Astra

* fix(models): preserve declared pricing tiers during catalog refresh

(cherry picked from commit eb7209375a)

* fix(openai): require discovery before offering Astra for OAuth (#137561)

(cherry picked from commit 8b1add5c41)

* fix(diagnostics-prometheus): reject unauthorized metric scrapes (#140903)

* fix(diagnostics-prometheus): require operator.read for metric scrapes

The Prometheus scrape route registers under the trusted-operator runtime
scope surface, so the Gateway authenticates the caller and applies its
named-role scope ceiling before dispatch. The handler never consulted
those scopes, so an authenticated identity whose role grants no operator
scopes still received the full diagnostics document with 200, while the
same caller was correctly refused on equivalent read operations.

Check the runtime request scopes inside the handler and fail closed with
403 "missing scope: operator.read" unless the caller holds operator.read,
operator.write, or operator.admin, mirroring the Gateway read implication
set. The guard runs before rendering so HEAD probes cannot disclose the
document size either.

* test(diagnostics-prometheus): prove role-limited scrape denial

(cherry picked from commit 0c9330b4c3)

* fix(discord): enforce sender media policy on guild asset uploads (#140334)

The Discord emoji-upload, sticker-upload, and event-create branches dropped
the sender-scoped media access options before dispatching the action, so the
guild runtime loaded the requested host-local path with only a byte limit. A
sender permitted to run those actions could therefore place bytes from a file
outside their allowed media roots into an outbound Discord emoji, sticker, or
event-cover request.

Forward the resolved action options from all three branches, carry
mediaAccess/mediaLocalRoots/mediaReadFile through the guild runtime, and load
upload sources through buildOutboundMediaLoadOptions like every other outbound
Discord media path. Adds regression coverage that a source outside the sender
roots is rejected before any request is issued, with an in-roots control.

(cherry picked from commit e5e77649a9)

* fix(discord): preserve realtime speaker and playback ownership (#137433)

* fix(discord): preserve realtime speaker and playback ownership

Bind provider connections to one Discord principal so delayed transcripts
and native consultations cannot inherit another speaker's authority.
Keep the shared agent route and serialize response-owned audio on one
room player, preserving continuations and recovery after playback gaps.

Admit host-requested responses before dispatch and map Google Live turn
completion to canonical terminal outcomes so queued speech can finish.

Closes #137349
Related: #136982, #123243
Follow-up: #137417

* test(discord): preserve room capture across speaker recovery

(cherry picked from commit 85d510c135)

* fix(doctor): preserve enabled skills during automatic updates (#138730)

Use runtime-repair approval for optional skill disabling. Keep standalone explicit repair and required config migrations unchanged.

(cherry picked from commit acc9a65a61)

* fix: generated images disappear after failed tool calls (#131226)

## What Problem This Solves

WebChat drops generated media when a later tool failure is the turn's only reply payload.

## Root cause

The embedded-run terminal projection assigned successful tool media to the first non-reasoning payload. A later error warning could become that owner. Gateway error projection then discarded the attached media.

## Fix

- Attach tool media only to a successful, non-reasoning reply.
- Emit a separate media-only payload when the turn has no successful reply.
- Preserve the newer host-owned and automatic-delivery media paths from current `main`.
- Keep regression coverage at the payload owner and physical-delivery boundaries.
- Remove the mocked browser test that manually inserted its expected result.

## Evidence

- Baseline: current `main` at `8544aed05a`.
- Real path: branch-built Control UI → real Gateway → mock OpenAI Responses provider → successful image tool → later failing tool → terminal WebChat event.
- Red: current `main` rendered zero generated images.
- Green: `d2a10d40c633bfe796ad4ab19222aa831184a327` rendered one generated image.
- Anti-cheat: the proof recorded `image-success` before `later-failure` and verified that Chromium loaded the exact Gateway-served asset from the branch build.

## Validation

- Focused unit and integration tests: 19 passed across 2 Vitest shards.
- Real Gateway and built Control UI proof: passed on current `main` and the candidate head with opposite image assertions.
- Targeted format, Oxlint, conflict-marker, max-lines, assertion-safety, and diff checks passed.
- Type checks run in continuous integration because repository policy forbids them on this host.

Production change: `+3/-3`, net zero. Test change: `+23/-1`, net `+22`.

Co-authored-by: A28Hui <yonghui.ng@area28.io>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
(cherry picked from commit 88be1b80f5)

* fix(matrix): refresh verification status before reporting device trust (#136226)

* fix(matrix): refresh verification status before reporting device trust

Refresh own-device keys after crypto preparation and before the authoritative trust read. Keep the missing-device preflight and use the Matrix SDK’s existing query contract.

* test(slack): remove core-coupled threading duplicate

---------

Co-authored-by: Dallin Romney <dallinromney@gmail.com>
(cherry picked from commit a812054f66)

* chore(release): prepare extended-stable 2026.8.33

* fix(release): integrate model and Discord security backports

* docs(release): clarify extended-stable workflow baseline

* fix(release): complete stable-line backport integration

* fix(ios): restore dependency resolution with WebRTC 152 (#134942)

* fix(release): repair frozen validation inputs

* fix(discord): stop error replies after voice consult cancellation (#135380)

* fix(discord): stop error replies after voice consult cancellation

Treat host-cancelled Discord realtime consults as terminal cancellation, preserve late-call dedupe, and wait for every native delivery before returning forced playback ownership. Timeouts and genuine errors retain their normal handling.

Closes #135340. Related phone cancellation helper: #134924.

* test(acp): run CLI lifecycle checks against prepared runtime

* test(cli): cover selective runtime build admission

* test(ci): account for ACP runtime preparation

* fix(release): complete Discord cancellation backport

* test(release): keep candidate fixtures current

* test(update): isolate frozen release version

---------

Co-authored-by: tharuntejmeta <129321782+tharuntejmeta@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
Co-authored-by: dclosefuturex <130100793+dclosefuturex@users.noreply.github.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: CGlashu <130156887+CGlashu@users.noreply.github.com>
Co-authored-by: A28Hui <yonghui.ng@area28.io>
2026-09-19 12:45:09 -07:00
..
src test: bind fixture unix sockets under a path the platform can hold (#132965) 2026-08-29 18:18:34 -07:00
.npmignore fix(release): restore bundled plugin package validation (#130875) 2026-08-27 19:32:29 +08:00
index.test.ts fix(sandbox): retire plugin backends with registry lifecycle (#130662) 2026-08-27 12:54:25 -07:00
index.ts fix(sandbox): retire plugin backends with registry lifecycle (#130662) 2026-08-27 12:54:25 -07:00
openclaw.plugin.json fix(openshell): sandbox cleanup, workspace sync, and gateway setup failures (#129641) 2026-08-25 18:08:55 -07:00
package.json chore: prepare extended-stable 2026.8.33 (#151452) 2026-09-19 12:45:09 -07:00
README.md fix(sandbox): restore reliable OpenShell execution and workspace integrity (#130031) 2026-08-26 03:10:07 -07:00
tsconfig.json

@openclaw/openshell-sandbox

Official NVIDIA OpenShell sandbox backend for OpenClaw.

This plugin lets OpenClaw use OpenShell-managed local or remote sandboxes with SSH command execution. Choose mirror mode for a synchronized local workspace or remote mode for a remote-canonical workspace.

Mirror operations sharing a workspace run sequentially so concurrent agent turns cannot overwrite one another. Outbound attachments resolve against the configured remote workspace, which defaults to /sandbox.

Configuring an OpenShell workspace requires OpenShell v0.0.88 or newer. The plugin supports OpenShell control-plane workspaces through plugins.entries.openshell.config.workspace; this is separate from OpenClaw's local/remote filesystem workspace mode. The setting applies to the whole plugin instance, not individual agents or sessions. When unset, the plugin preserves the OpenShell CLI's ambient OPENSHELL_WORKSPACE selection, or its default fallback when no ambient selection exists.

Install

openclaw plugins install @openclaw/openshell-sandbox

Restart the Gateway after installing or updating the plugin.

Configure

Install and configure the OpenShell CLI before enabling the backend. As the same operating system user that runs the OpenClaw Gateway, verify:

openshell --version
openshell gateway list
openshell sandbox list

Set agents.defaults.sandbox.backend to "openshell", enable plugins.entries.openshell, and restart the OpenClaw Gateway. OpenShell settings belong under plugins.entries.openshell.config.

The optional policy setting must be the path to a readable OpenShell policy YAML file on the Gateway host; it is not a policy name or ID. Use an absolute path to avoid resolving it relative to an agent workspace.

Use the OpenShell docs for credentials, workspace mirroring, runtime selection, and troubleshooting:

Package

  • Plugin id: openshell
  • Package: @openclaw/openshell-sandbox
  • Minimum OpenClaw host: 2026.5.12-beta.1