openclaw/extensions/facetime
Peter Steinberger d0f21752ee
refactor(plugins): deslop feature plugin helpers (#162992)
Reuse existing normalization, URL, catalog and lifecycle helpers across feature plugins. Fix retained Copilot abort listeners when pre-session auth or proxy setup fails. Preserve tool descriptors, plugin manifests, persisted state and URL admission policy.

Remote changed checks, non-Browser sibling suites, focused Browser tests, plugin contracts, SDK checks and both zero-cycle gates pass. The independently attributed partial-refresh UI failure is documented in the PR evidence.
2026-10-01 17:48:15 -07:00
..
assets improve(plugins): give bundled logos consistent white icon tiles (#155259) 2026-09-23 19:09:26 -07:00
docs
scripts refactor: remove Tasks and TaskFlow runtime (#159179) 2026-09-27 10:40:29 -07:00
skills/facetime
src refactor(plugins): deslop feature plugin helpers (#162992) 2026-10-01 17:48:15 -07:00
tests refactor(plugins): deslop feature plugin helpers (#162805) 2026-10-01 11:37:40 -07:00
.gitignore
doctor-contract-api.ts refactor(compat): deslop compatibility shims 2026-10-01 15:11:01 +00:00
helper-endpoint.json
index.test.ts test(discord,crabbox,plugins): remove low-value tests (batch d058) (#159513) 2026-09-27 07:34:12 +00:00
index.ts
LICENSE
openclaw.plugin.json fix(plugins): add missing categories and artwork for FaceTime, GitHub, ONNX, TypeSafe (#154888) 2026-09-21 07:57:43 -07:00
package.json chore(release): close out 2026.9.7 on main (#161587) 2026-09-29 22:39:14 -07:00
README.md perf(facetime): move pending-call storage off the Gateway thread (#154241) 2026-09-20 23:00:39 -07:00
runtime-api.ts
THIRD_PARTY_NOTICES.md

OpenClaw FaceTime

Experimental FaceTime carrier plugin for a dedicated Apple Silicon Mac. The public setup, security, operation, and removal guides are:

Install the plugin from npm. Its signed and notarized native helpers are released separately from openclaw/openclaw-facetime:

openclaw plugins install @openclaw/facetime
brew install openclaw/tap/openclaw-facetime
openclaw gateway restart

Ownership boundaries

  • src/call-lifecycle.ts owns the closed carrier/model state machine, generation fencing, serialized native commands, and the complete alias index.
  • src/pending-dial-store.ts persists the one exact approved pending dial in plugin-owned SQLite state. Current hosts execute these operations in the shared-state worker, preserving write order and conditional dial-ID cleanup. Runtime startup, helper dispatch, and shutdown await the required publications. Pending outbound calls reserve admission while persistence waits, preserving the same incoming-call policy before and after durable publication.
  • src/helper-rpc.ts owns bounded loopback IPC with mutual authentication, connection-epoch message MACs, replay sequencing, and typed native postcondition projection.
  • src/helper-supervisor.ts owns generation-bound LLDB injection and joins in-flight work on stop.
  • src/audio-pump.ts owns bounded native capture, SoX playback, and child teardown.
  • openclaw/openclaw-facetime owns the native process tap and injected helper. This plugin validates native protocol version 1, the exact OpenClaw Foundation Developer ID identity, and Apple notarization before activation.
  • src/talk-driver.ts owns provider response/tool generations and exact agent consult cancellation.

Carrier hangup is terminal only after a native ended event or stable complete topology absence. A helper reply only acknowledges the request. Capture death, Gateway handoff, and unproven shutdown escalate before local suppression is released.

Configuration

ownerHandles is the only caller list. Every accepted identity receives owner authority. realtime.toolPolicy is one of safe-read-only, owner, or none; invalid explicit values fail validation. realtime.provider, realtime.model, and realtime.voice are optional session overrides. Registered realtime providers own auto-selection, authentication, and their model and voice defaults.

The helper endpoint is not configurable. Node and the native helper consume helper-endpoint.json, bind loopback only, and derive the port from the user ID. The helper creates each connection epoch and authenticates the Gateway before accepting commands; every command, response, and event is direction-bound and strictly sequenced within that epoch.

Development checks

node scripts/run-vitest.mjs extensions/facetime
sh -n extensions/facetime/scripts/*.sh
(cd extensions/facetime && npm pack --dry-run)

Do not run live calls, install/uninstall the driver, change SIP, enable developer tools, or modify TCC during automated validation.

Native and licensing boundary

The privileged driver script pins BlackHole v0.7.1 and its SHA-256, builds the renamed OpenClawBridge.driver in a root-only temporary directory, and accepts no caller-built artifact, digest, or compiler path. Before compilation it requires the canonical Xcode bundle and its selected build tools to be Apple-signed, root-owned, and not group/world writable, then performs a transactional swap. Generated BlackHole/driver artifacts are GPL-3.0 and are excluded from the package. See THIRD_PARTY_NOTICES.md.

The separately released Objective-C and Swift native sources, their adapted third-party notices, and their signing pipeline live in openclaw/openclaw-facetime.