openclaw/CHANGELOG/2026.4.18.md
Hannes Rudolph 2227743f74
refactor: split release changelogs and synchronize docs mirrors (#145464)
* refactor: split release changelogs and synchronize docs mirrors

* fix: complete split changelog instructions and validation wiring

* fix: complete release changelog mirror integration

Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver.

* test: align docs agent Git ownership fixtures

Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 21:19:18 -07:00

16 KiB

2026.4.18

Changes

  • Anthropic/models: add Claude Opus 4.7 xhigh reasoning effort support and keep it separate from adaptive thinking.
  • Control UI/settings: overhaul the settings and slash-command experience with faster presets, quick-create flows, and refreshed command discovery. (#67819) Thanks @BunsDev.
  • macOS/gateway: add screen.snapshot support for macOS app nodes, including runtime plumbing, default macOS allowlisting, and docs for monitor preview flows. (#67954) Thanks @BunsDev.

Fixes

  • Codex/gateway: fix gateway crashes when the codex-acp subprocess terminates abruptly; pending requests now shut down gracefully instead of propagating an uncaught EPIPE through the gateway daemon and connected channels. Fixes #67886. (#67947) Thanks @openperf.
  • Agents/bootstrap: resolve bootstrap from workspace truth instead of stale session transcript markers, keep embedded bootstrap instructions on a hidden user-context prelude, suppress normal /new and /reset greetings while BOOTSTRAP.md is still pending, and make the embedded runner read the bootstrap ritual before replying normally (#68000). Thanks @Takhoffman.
  • Agents/bootstrap: dedupe repeated bootstrap-truncation warnings so startup logs stay actionable. (#67906) Thanks @rubencu.
  • WhatsApp/multi-account: centralize named-account inbound policy, isolate per-account group activation and scoped session keys, preserve legacy activation backfill, and keep accounts.default shared defaults aligned across runtime, setup, and compat migration paths. Thanks @mcaxtr.
  • Cron/delivery: clean up isolated sessions after direct deliveries when deleteAfterRun is enabled, covering structured and threaded branches that previously bypassed cleanup. (#67807) Thanks @MonkeyLeeT.
  • Gateway/hello-ok: always report negotiated auth metadata and preserve scopes for reused device tokens on successful shared-auth handshakes, including control-ui bypass coverage when no device token is issued. (#67810, #68039) Thanks @BunsDev.
  • Onboarding/non-interactive: preserve existing gateway auth tokens during re-onboard so active local gateway clients are not disconnected by an implicit token rotation. (#67821) Thanks @BKF-Gitty.
  • OpenAI Codex/Responses: unify native Responses API capability detection so Codex OAuth requests emit the required store: false field on the native Responses path. (#67918) Thanks @obviyus.
  • WhatsApp/setup: guard personal-phone and allowlist prompt values so setup fails with clear validation errors instead of crashing on undefined prompt text. (#67895) Thanks @lawrence3699.
  • Models/config: preserve an existing models.json provider baseUrl during merge-mode regeneration so custom endpoints do not get reset on restart. (#67893) Thanks @lawrence3699.
  • Plugin SDK: preserve secret-input-runtime function exports in published builds so provider plugins can read SecretRef-backed setup inputs.
  • Plugins/discovery: reuse bundled and global plugin discovery results across workspace cache misses so Windows multi-workspace startup stops redoing the shared synchronous scan. (#67940) Thanks @obviyus.
  • Bundled plugins/install: keep staged bundled plugin runtime imports resolving through the packaged Plugin SDK while omitting checkout-only aliases from the dist inventory, so published installs do not fail on repo-local paths.
  • Plugins/webhooks: enforce synchronous plugin registration with full rollback of failed plugin side effects, and cache SecretRef-backed webhook auth per route so plugin startup and inbound webhook auth stay deterministic. (#67941) Thanks @obviyus.
  • Telegram/polling transport: give the Telegram undici dispatcher pool bounded keep-alive defaults and an explicit lifecycle. Previously every recoverable network error and stall watchdog trip silently replaced the transport, abandoning the old dispatcher pool and its sockets; long-running gateway processes accumulated hundreds of ESTABLISHED connections to api.telegram.org, saturating per-IP upstream proxy quotas and causing the actively-used outbound proxy node to time out while every other node still tested healthy. Transports now expose close(), TelegramPollingTransportState destroys the stale transport on dirty-rebuild, and TelegramPollingSession disposes the transport when polling exits — backed by a strict per-origin pool cap on every constructed Agent, ProxyAgent, and EnvHttpProxyAgent as defence in depth (#69476).
  • Telegram/polling: publish successful getUpdates calls as account health liveness, avoid false stall restarts after recoverable getUpdates errors, and force Telegram API dispatchers to HTTP/1.1 so stalled polling recovers instead of sitting connected-but-dead (#69476).
  • Telegram/ACP bindings: drop persisted DM bindings that still point at missing or failed ACP sessions on restart, while preserving plugin-owned bindings and uncertain store reads. (#67822) Thanks @chinar-amrutkar.
  • Telegram/streaming: keep a transient preview on the same Telegram message when auto-compaction retries an in-flight answer, so streamed replies no longer appear duplicated after compaction. (#66939) Thanks @rubencu.
  • Memory/sqlite-vec: emit the degraded sqlite-vec warning once per degraded episode instead of repeating it for every file write, while preserving the latch across safe-reindex rollback and resetting it when vector state is genuinely rebuilt. (#67898) Thanks @rubencu.
  • Memory-core: preserve stored vector dimensions during read-only recovery so memory indexes do not lose vector metadata while repairing read-only state.
  • Reply/block streaming: preserve post-stream incomplete-turn error payloads after block streaming already emitted content, so users get the warning instead of silence. (#67991) Thanks @obviyus.
  • Telegram/streaming: clear the compaction replay guard after visible non-final boundaries so a post-tool assistant reply rotates to a fresh preview instead of editing the pre-compaction message. (#67993) Thanks @obviyus.
  • Matrix: fix sessions_spawn --thread subagent session spawning — thread binding creation, cleanup on session end, and completion-message delivery target resolution now work end-to-end. (#67643) Thanks @eejohnso-ops and @gumadeiras.
  • Slack/streaming: resolve native streaming recipient teams from the inbound user when available, with a monitor-team fallback, so DM and shared-workspace streams target the right recipient more reliably.
  • macOS/webchat: enable Undo and Redo in the composer text input by turning on the native NSTextView undo manager. (#34962) Thanks @tylerbittner.
  • macOS/remote SSH: require an already-trusted host key on the macOS remote command, gateway probe, port tunnel, and pairing probe paths by switching StrictHostKeyChecking=accept-new to StrictHostKeyChecking=yes and centralizing the shared SSH option fragments in CommandResolver, so first-time macOS remote connections no longer silently accept an unknown host key and must be trusted ahead of time via ~/.ssh/known_hosts. (#68199) Thanks @drobison00.
  • CLI/configure: show the channel picker before probing statuses and let remove mode delete configured channel blocks directly from config. (#68007) Thanks @gumadeiras.
  • Control UI/settings: reset scroll position when switching settings pages and align details headers. (#68150) Thanks @BunsDev.
  • WhatsApp/gateway: harden WhatsApp auth persistence and backup recovery, model unstable auth state explicitly in setup/status/health, recover backup-backed login without forcing a fresh QR, and keep local gateway handoff and channel restarts truthful after login. Thanks @mcaxtr.
  • OpenAI Codex/OAuth: keep OpenClaw as the canonical owner for imported Codex CLI OAuth sessions, stop writing refreshed credentials back into .codex, and prefer fresher OpenClaw credentials over stale imported CLI state so refresh recovery stays stable. Thanks @vincentkoc.
  • OpenAI Codex/OAuth: treat the OpenAI TLS prerequisites probe as advisory instead of a hard blocker, so Codex sign-in can still proceed when the speculative Node/OpenSSL precheck fails but the real OAuth flow still works. Thanks @vincentkoc.
  • Models status/OAuth health: align OAuth health reporting with the same effective credential view runtime uses, so expired refreshable sessions stop showing healthy by default and fresher imported Codex CLI credentials surface correctly in models status, doctor, and gateway auth status. Thanks @vincentkoc.
  • OpenAI Codex/OAuth: keep external CLI OAuth imports runtime-only by overlaying fresher Codex CLI credentials without mutating auth-profiles.json, so .codex stays a bootstrap/runtime input instead of becoming durable OpenClaw state. Thanks @vincentkoc.
  • OpenAI Codex/OAuth: drop legacy CLI-manager routing from the remaining bootstrap path so Codex and MiniMax CLI imports are matched by their canonical OpenClaw profile ids instead of stale managedBy metadata. Thanks @vincentkoc.
  • OpenAI Codex/OAuth: only bootstrap from external CLI OAuth when the local OpenClaw profile is missing or unusable, so healthy local sessions are no longer overridden by fresher .codex tokens. Thanks @vincentkoc.
  • OpenAI Codex/OAuth: rename the external CLI bootstrap helper, reuse the same usable-oauth check across runtime fallback paths, and add debug logs plus health coverage so bootstrap decisions stay legible. Thanks @vincentkoc.
  • Twitch/setup: load Twitch through the bundled setup-entry discovery path and keep setup/status account detection aligned with runtime config. (#68008) Thanks @gumadeiras.
  • Feishu/card actions: resolve card-action chat type from the Feishu chat API when stored context is missing, preferring chat_mode over chat_type, so DM-originated card actions no longer bypass dmPolicy by falling through to the group handling path. (#68201) Thanks @drobison00.
  • Cron/isolated-agent: preserve trusted: false on isolated cron awareness events mirrored into the main session, and forward the optional trusted flag through the gateway cron wrapper so explicit trust downgrades survive session-key scoping. (#68210) Thanks @drobison00.
  • Agents/fallback: recognize bare leading ZenMux 402 ... quota-refresh errors without misclassifying plain numeric 402 ... text, and keep the embedded fallback regression coverage stable. (#47579) Thanks @bwjoke.
  • Failover/google: only treat INTERNAL status payloads as retryable timeouts when they also carry a 500 code, so malformed non-500 payloads do not enter the retry path. (#68238) Thanks @altaywtf and @Openbling.
  • Agents/tools: filter bundled MCP/LSP tools through the final owner-only and tool-policy pipeline after merging them into the effective tool list, so existing allowlists, deny rules, sandbox policy, subagent policy, and owner-only restrictions apply to bundled tools the same way they apply to core tools. (#68195) Thanks @drobison00.
  • Gateway/assistant media: require operator.read scope for assistant-media file and metadata requests on identity-bearing HTTP auth paths so callers without a read scope can no longer access assistant media. (#68175) Thanks @eleqtrizit.
  • Gateway/web: allow same-origin microphone access in the Permissions-Policy header so browser voice capture can work from the Control UI and webchat origin. (#68368).
  • Exec approvals/display: escape raw control characters (including newline and carriage return) in the shared and macOS approval-prompt command sanitizers, so trailing command payloads no longer render on hidden extra lines in the approval UI. (#68198) Thanks @drobison00.
  • Telegram/streaming: fence same-session stale preview and finalization work after aborts so Telegram no longer replays an older reply or flushes a hidden short preview after the abort confirmation lands. (#68100) Thanks @rubencu.
  • OpenAI Codex/OAuth + Pi: keep imported Codex CLI OAuth bootstrap, Pi auth export, and runtime overlay handling aligned so Codex sessions survive refresh and health checks without leaking transient CLI state into saved auth files. Thanks @vincentkoc.
  • OpenAI Codex/OAuth: keep Codex-specific auth bridging inside the owning plugins, preserve canonical imported CLI profiles, and allow legacy identity-less main-store OAuth sessions to upgrade during refresh mirroring. (#68284) Thanks @vincentkoc.
  • Config/redact: add browser.cdpUrl and browser.profiles.*.cdpUrl to sensitive URL config paths so embedded credentials (query tokens and HTTP Basic auth) are properly redacted in config.get API responses and availability error messages. (#67679) Thanks @Ziy1-Tan.
  • Agents/TTS: report failed speech synthesis as a real tool error so unconfigured providers no longer feed successful TTS failure output back into agent loops. (#67980) Thanks @lawrence3699.
  • Gateway/wake: allow unknown properties on wake payloads so external senders like Paperclip can attach opaque metadata without failing schema validation. (#68355) Thanks @kagura-agent.
  • Matrix: honor channels.matrix.network.dangerouslyAllowPrivateNetwork when creating clients for private-network homeservers. (#68332) Thanks @kagura-agent.
  • Cron/message tool: keep cron-owned runs with delivery.mode: "none" on the normal message-tool path so they can still send explicit messages, create threads, and route conditionally when no runner-owned delivery target is active. (#68482) Thanks @obviyus.
  • Agents/failover: avoid treating bare leading 402 ... prose as billing errors while still recognizing proxy subscription failures. (#45827) Thanks @junyuc25.
  • Config/$schema: preserve root-authored $schema during partial config rewrites without injecting include-only schema URLs into the root config. (#47322) Thanks @EfeDurmaz16.
  • Agents/CLI delivery: run the same reply-media path normalizer the auto-reply flow uses before shipping openclaw agent --deliver payloads, so relative MEDIA:./out/photo.png tokens resolve against the agent workspace instead of being rejected downstream with LocalMediaAccessError: Local media path is not under an allowed directory. Thanks @frankekn.
  • Agents/Google: strip thinkingBudget=0 for the thinking-required gemini-2.5-pro model in embedded-runner and native Google payloads, so requests no longer fail with Budget 0 is invalid. This model only works in thinking mode. and the API uses its default thinking behavior instead. (#68607) Thanks @josmithiii.
  • Slack/threads: log failed thread starter and history fetches at verbose level while preserving best-effort fallback behavior, so missing Slack thread context is diagnosable without interrupting inbound handling. (#68594) Thanks @martingarramon.
  • Gateway/restart: keep stale-gateway cleanup from terminating the current process's parent or ancestors, so plugin sidecars like WeChat no longer kill the active gateway and trigger an infinite supervisor restart loop. Fixes #68451. (#68517) Thanks @openperf.
  • Gateway/auth: reject gateway auth credentials that match published example placeholders at startup and secret reload, and keep cloud install snippets from publishing copy-paste gateway/keyring secrets. (#68404) Thanks @coygeek.
  • CLI/update: preserve macOS restart helper launchctl failures in the update restart log without letting log setup block the restart path. (#68492) Thanks @hclsys.
  • Slack/threads: keep file-only root messages as starter context so first thread replies can still hydrate starter media. (#68594) Thanks @martingarramon.
  • Google/Antigravity: resolve forward-compatible Gemini 3.1 Pro custom-tools and Flash variants from the bundled Google plugin templates, so google-antigravity/gemini-3.1-pro-preview-customtools no longer falls through to an unknown-model error. Fixes #35512.
  • Active Memory: raise the blocking recall timeout ceiling to 120 seconds and reject larger config values during plugin schema validation. Fixes #68410. (#68480) Thanks @Bartok9.
  • Control UI/chat: keep history-backed user image uploads visible after chat reload while filtering blocked or non-image transcript media paths. (#68415) Thanks @mraleko.
  • Matrix/plugins: keep remaining Matrix event helpers on the canonical matrix-js-sdk subpath so build and plugin-load entrypoint checks stay consistent. (#68498) Thanks @masatohoshino.