## What Problem This Solves
Native clients still repeated connection plumbing, URL classification, attachment import, and model-construction logic across sibling owners. This maintainer-requested cleanup consolidates the remaining exact copies.
## User Impact
No intended user-visible change. Rendered controls, accessibility, text, TLS decisions, credential identity, node/operator separation, wire payloads, and persisted keys remain unchanged.
## Why This Change Was Made
Existing owners now serve their callers directly:
- iOS passes `GatewayConnectConfig` intact through connection starters and shares first-use TLS preflight while retaining setup-code trust and cancellation policy.
- Shared endpoint and plugin-surface helpers own the identical query-name, strict IP-literal, and capability URL operations. Platform target validation and normalization remain local.
- Android uses its existing attachment-import, status-publication, JSON parsing, microphone permission, and Wear route-predicate owners; unused preference aliases and duplicate Talk finalization are removed.
- Chat model initializers supply absent optional values directly. Redundant placeholder/image/completion wrappers, repeated transcript scans, trim-and-empty checks, and equivalent view-source branches are removed.
- Notification authorization uses its existing shared enum, with serving preference checks retained at callers.
Measured source reduction: **485 lines**, including 39 demo/preview/fixture lines; tests net **+21**. Existing fixture constructors were migrated without assertion changes. Two tautological coordinator assertions/helpers were removed while route lifecycle coverage remains. No changelog change is needed for this internal refactor.
## Evidence
- Independent isolated review completed with no accepted P0–P2 findings after inspecting the complete behavior owners.
- Blacksmith Testbox: `node scripts/check-changed.mjs --base 34aff4fa8e` passed.
- Both repository import-cycle checks passed with **0 cycles**. The final rebased commit was checked in a clean, bundle-pinned Blacksmith checkout; changed checks passed there too.
- Full `pnpm android:test` passed (Play, Wear, wear-shared; 9m52s including build), and `pnpm android:test:third-party` passed (6m57s including build).
- Swift formatting and `git diff --check` passed. All broad checks and Android suites ran remotely.
- Hosted run 36880331155 passed all 1,999 OpenClawKit tests, the full macOS app tests, iOS smoke, and all Android unit suites on the original refactor head. Its separate NativeState target failed with SQLite API misuse; the owning repair below is now being validated. Both Android native-access jobs failed downloading the emulator (HTTP 404) before test execution. These failures are not being bypassed or labeled passing.
- The expanded `GatewayConnectionSecurityTests` cases cover discovered TLS system trust and stale/cancelled probes; the current hosted iOS selection does not execute that suite, so its runtime and measured added cost are pending disposable-Mac proof. Shared/macOS suites and iOS compilation remain separate evidence.
- No TypeScript plugin/SDK imports or dependency manifests changed; plugin-contract/import-boundary expansion is not applicable.
The read-only census covered the four requested native scopes, used lower-threshold Swift/Kotlin clone scanning, and records fully read versus partial/unread files explicitly. Larger platform lifecycle/media-policy differences were retained rather than generalized.
## Fixes found along the way
The native-state initializer kept its local close defer active after all stored properties were initialized. A subsequent admission error also ran deinit, closing the same SQLite handle twice; under concurrent allocation the second close could corrupt an unrelated handle. Transfer cleanup ownership to the instance at the end of stored-property initialization, retaining local cleanup for earlier failures. Schema, transaction, admission and file-permission contracts are unchanged.
The exact NativeState source and both existing test files from the original PR head were replayed in an isolated SwiftPM package with the repository's Swift language settings. After remote Mac broker/capacity failures exceeded the permitted fallback window, this single target ran locally with `nice -n 15`, two build jobs, and only UUID temporary database fixtures. The unchanged 21-test concurrent suite reproduced the same busy-timeout API-misuse error on baseline repeat 3. The ownership repair passed the suite and **25 additional full-suite repeats**; no test assertions, timing, retries or production seams changed. NativeState test wall time was 0.209s in the first fixed run. The repair has a clean independent P2 review and remote changed checks. The rebase onto current main was patch-identical (`git range-diff`); updated-head CI remains required.
Plugin SDK API comparison against the original base passed with no changes; this repair touches no SDK input.