openclaw/CHANGELOG/2026.3.24-beta.1.md
Hannes Rudolph 2227743f74
refactor: split release changelogs and synchronize docs mirrors (#145464)
* refactor: split release changelogs and synchronize docs mirrors

* fix: complete split changelog instructions and validation wiring

* fix: complete release changelog mirror integration

Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver.

* test: align docs agent Git ownership fixtures

Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 21:19:18 -07:00

7 KiB

2026.3.24-beta.1

Fixes

  • Doctor/image generation: seed migrated legacy Nano Banana Google provider config with the /v1beta API root and an empty model list so openclaw doctor --fix completes and the migrated native Google image path keeps hitting the correct endpoint. (#53757) Thanks @mahopan.
  • Models/google: normalize bare Google Generative AI API roots for custom provider names, and keep built-in Google model-id rewrites working when api is declared only on individual models, so custom Google lanes and older configs stop missing /v1beta or preview-id normalization. (#44969) Thanks @Kathie-yu.
  • Feishu/startup: treat unresolved SecretRef app credentials as not configured during account resolution so CLI startup and read-only Feishu config surfaces stop crashing before runtime-backed secret resolution is available. (#53675) Thanks @hpt.
  • Feishu/groups: when groupPolicy is open, stop implicitly requiring @mentions for unset requireMention, so image, file, audio, and other non-text group messages reach the bot unless operators explicitly keep mention gating on. (#54058) Thanks @byungsker.
  • Feishu/startup: keep requireMention enforcement strict when bot identity startup probes fail, raise the startup bot-info timeout to 30s, and add cancellable background identity recovery so mention-gated groups recover without noisy fallback. (#43788) Thanks @lefarcen.
  • Feishu/MSTeams message tool: keep provider-native card payloads optional in merged tool schemas so media-only sends stop failing validation before channel runtime dispatch. (#53715) Thanks @lndyzwdxhs.
  • Feishu/docx block ordering: preserve the document tree order from docx.document.convert when inserting blocks, fixing heading/paragraph/list misordering in newly written Feishu documents. (#40524) Thanks @TaoXieSZ.
  • Telegram/native commands: run native slash-command execution against the resolved runtime snapshot so DM commands still reply when fresh config reads surface unresolved SecretRefs. (#53179) Thanks @nimbleenigma.
  • Gateway/ports: parse Docker Compose-style OPENCLAW_GATEWAY_PORT host publish values correctly without reviving the legacy CLAWDBOT_GATEWAY_PORT override. (#44083) Thanks @bebule.
  • Plugins/memory-lancedb: bootstrap the env-configured HTTP/HTTPS proxy dispatcher before OpenAI embeddings requests so memory capture and recall work in proxy-required environments again. (#54119) Thanks @neeravmakwana.
  • Runtime/build: stabilize long-lived lazy dist runtime entry paths and harden bundled plugin npm staging so local rebuilds stop breaking on missing hashed chunks or broken shell npm shims. (#53855) Thanks @vincentkoc.
  • Security/skills: validate skill installer metadata against strict regex allowlists per package manager, sanitize skill metadata for terminal output, add URL protocol allowlisting in markdown preview and skill homepage links, warn on non-bundled skill install sources, and remove unsafe file:// workspace links. (#53471) Thanks @BunsDev.
  • Memory/builtin sqlite: cut redundant sync and status query churn by snapshotting file state once per source, reusing sync statements, and consolidating status aggregation reads, which reduces builtin memory overhead on sync/status/doctor-style paths. Thanks @vincentkoc.
  • TUI/chat: preserve pending user messages when a slow local run emits an empty final event, but still defer and flush the needed history reload after the newer active run finishes so silent/tool-only runs do not stay incomplete. (#53130) Thanks @joelnishanth.
  • DeepSeek/pricing: replace the zero-cost DeepSeek catalog rates with the current DeepSeek V3.2 pricing so usage totals stop showing $0.00 for DeepSeek sessions. (#54143) Thanks @arkyu2077.
  • CLI/logging: make pretty log timestamps always include an explicit timezone offset in default UTC and --local-time modes, so incident triage no longer mixes ambiguous clock displays. (#38904) Thanks @sahilsatralkar.
  • Browser/default detection: recognize macOS LaunchServices Edge bundle ids so default Chromium detection stops falling back to Chrome when Edge is the system default. (#48561) Thanks @zoherghadyali.
  • CLI/Telegram topics: route message thread create through Telegram topic-create with the required topic name field so Telegram forum topic creation works from the CLI again. (#54336) Thanks @andyliu.
  • Telegram/pairing: render pairing codes and approval commands as Telegram-only code blocks while keeping shared pairing replies plain text for other channels. (#52784) Thanks @sumukhj1219.
  • Agents/cron: suppress the default heartbeat system prompt for cron-triggered embedded runs even when they target non-cron session keys, so cron tasks stop reading HEARTBEAT.md and polluting unrelated threads. (#53152) Thanks @Protocol-zero-0.
  • Agents/cron: mark best-effort announce runs as not delivered when any payload fails, and log those partial delivery failures instead of silently reporting success. (#42535) Thanks @MoerAI.
  • Plugins: enforce terminal hook decision semantics for tool/message guards (#54241) Thanks @joshavant.
  • Marketplace/agents: correct the ClawHub skill URL in agent docs and stream marketplace archive downloads to disk so installs avoid excess memory use and fail cleanly on empty responses. (#54160) Thanks @QuinnH496.
  • Discord/config types: add missing autoArchiveDuration to DiscordGuildChannelConfig so TypeScript config definitions match the existing schema and runtime support. (#43427) Thanks @davidguttman.
  • Docs/IRC: fix five json55 code-fence typos in the IRC channel examples so Mintlify applies JSON5 syntax highlighting correctly. (#50842) Thanks @Hollychou924.
  • Discord/commands: trim overlong slash-command descriptions to Discord's 100-character limit and map rejected deploy indexes from Discord validation payloads back to command names/descriptions, so deploys stop failing on long descriptions and startup logs identify the rejected commands. (#54118) thanks @huntharo
  • Media/store: enforce the intended media file mode after writes and redirect downloads so restrictive umasks do not silently narrow saved media permissions.
  • Security/gateway auth: enforce operator.read and models.list on /v1/models so write-scoped callers cannot list models through the OpenAI-compatible HTTP surface.
  • Security/allowlist commands: require operator.admin for internal /allowlist mutations and channel allowlist persistence reached through chat.send.
  • Security/Feishu webhook: cap pre-auth webhook body reads with strict size and timeout guards before JSON parsing so slow-body requests cannot hold the webhook handler open.
  • Security/session policy: require sender ownership for /send policy changes so command-authorized non-owners cannot rewrite owner-only session delivery policy.
  • Security/bash stop: route /bash stop through the hardened process-tree killer so invalid or attacker-influenced SIGKILL targets cannot escape the intended bash-session scope.
  • Security/installer: hide staged project .npmrc files during skill and package installs so npm registry and git settings inside the stage directory cannot hijack trusted installs.