## What Problem This Solves
Doctor still carries migrations for config formats last written before the July 2026 support window.
## User Impact
Upgrades from pre-July-2026 versions are no longer migrated for retired whole-agent runtime/embedded settings, sandbox `perSession`, prompt overrides, direct silent replies, custom memory index paths, queue aliases, parent-fork limits, Browser relay/SSRF aliases, Gateway WebChat config, and authored `plugins.installs`.
Doctor preserves these inputs and directs the operator through OpenClaw 2026.9.5 with `openclaw doctor --fix` before upgrading again. Config written by July-or-later shipped releases remains supported, including June extended-stable releases published after July 1.
## Why This Change Was Made
Removes the old migration steps, detectors, config-install import/receipt lifecycle, whole-agent route readers, obsolete tests, and exact inventory entries. The whole-agent cutover also removes a duplicate config rewrite pass used only to predict whether old pins would be cleared. Doctor remains the single migration owner; its existing unsupported-input guard protects preflight, backup planning, and the locked config write.
Current provider/model runtime policies, transient plugin install carriers, canonical SQLite install records/provenance, roster/ownership conversion, streaming/channel migrations, and migrations with uncertain writer history remain. No SQLite schema/version steps or public plugin SDK APIs change. `CHANGELOG.md` stays release-owned.
Writer history was checked against real persistence code and strict shipped schemas, including `v2026.7.1-beta.1` (published July 2 UTC) and `v2026.6.35` (September extended-stable):
| Retired source | Writer cutover | Last producing release |
| --- | --- | --- |
| Browser relay bind / SSRF alias | `476d948732` March 15 / `c7a947dc0a` April 4 | `v2026.3.13-1` / `v2026.4.2` |
| Authored plugin install records | `888448facc` April 25 | `v2026.4.24` |
| Parent-fork limit / queue aliases | `10b89a3b55` May 2 / `70df2b8fe2` May 13 | `v2026.4.30-beta.1` / `v2026.5.12` |
| Direct silent-reply/rewrite | `f0ceb3c5aa` May 15 | `v2026.5.14-beta.2` |
| Whole-agent runtime / embedded settings | `bb46b79d3c` May 27 | `v2026.5.27` |
| System prompt override / Gateway WebChat | `e12a6d6a67` May 29 / `d1b514af2e` May 31 | `v2026.5.28-alpha.1` / `v2026.5.31-alpha.1` |
| Custom memory index path | `f324f7e281` June 19 | `v2026.6.9-alpha.6` |
The local census records per-item source locations, release dates, DELETE/KEEP decisions, retained uncertainty, and full-read coverage for the migration owners.
## Evidence
- Both import-cycle checks: **0** on the exact candidate tree.
- Focused Doctor/config owner suites exercised migration, registry/provenance, backup/refusal, include write authority, runtime routes, and wrapper extraction. The first run found two leftover pre-window fixture expectations; those were removed. An earlier three-file rerun passed **86 tests** with one worker in **73.57 s wall**.
- Test execution times in that rerun: legacy config migrations 4.277 s; plugin registry 4.560 s; existing workspace persistence suite 38.696 s. The latter exercises real config backups, workspace/cron ownership and idempotence; the new refusal and July-shape assertions reuse its existing fixture lifecycle.
- Oldest July config fixture migrates, persists canonical agent entries, and stays unchanged on a second Doctor pass. Unsupported settings preserve authored bytes, backups, and canonical install records, including late root/include changes.
- Full `node scripts/check-changed.mjs` **passed** on final head `9ca6bc214e`, including lint, typechecks, dead-export scans and architecture guards. The full remote proof command completed successfully in 26m06s.
- Independent review completed. One backup-recovery finding was rejected: the cited function already throws for retired formats before either recovery fallback; the real preflight test proves active config and backup preservation.
- Net reduction: **1,136 production lines**, **947 test/support lines**, plus 9 docs/tooling lines. Runtime tests and full changed-file checks ran remotely; one local frozen install refreshed landing-tooling dependencies. After the last docs-only conflict, coordinator timeouts exceeded ten minutes, so cycle/docs checks used the authorized serial local fallback at nice 15.
Conflict recovery preserved main's session-entry-state repair (#162595). The later CI-planner inventory failure was fixed by the coordinator in #163071; that fix is included in the final base, with no duplicate inventory change in this PR.
Final correction head `9ca6bc214e` has both cycle checks at zero and **37 passing tests across four focused files**, including the real CLI exec-approval migration, include persistence, July upgrade fixture, and planner inventory. Full `check-changed` passed on that exact committed tree.
### Fixes found along the way
- Keep queue-refusal paths typed as strings rather than inferring unknown tuple keys.
- Keep the existing browser include/rotation regression on the supported July `browser.color` migration trigger.
- Remove the pre-July custom memory-index path from the retained real-CLI approval-import regression; its durable approval and memory-merge assertions stay intact.
The final rebase to `5d93ba471bb` resolved only duplicate wording of the July cutoff already landed on main. It keeps main’s wording; `git range-diff` confirms the production/test patch is unchanged. Both cycle checks remain **0**, docs link audit checked **14,738 links with 0 broken**, and `git diff --check` passed. Prior-head full CI run [36943104907](https://github.com/openclaw/openclaw/actions/runs/36943104907) passed; the final head is awaiting its own hosted gate.