onnx.5: sync dev (fail-closed sub-agent approvals #1616 + fixes), prepare 0.25.0-alpha.onnx.5#1619
Merged
Aaronontheweb merged 10 commits intoJul 12, 2026
Conversation
) Updated ModelContextProtocol package versions to use a variable for versioning. Signed-off-by: Aaron Stannard <[email protected]>
Co-authored-by: Aaron Stannard <[email protected]>
--- updated-dependencies: - dependency-name: MessagePack dependency-version: 3.1.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…tclaw-dev#1127) (netclaw-dev#1610) * fix(cli): model set/picker preserve hand-set modalities on re-set (netclaw-dev#1127) Re-selecting a model that is already configured wiped operator-set attributes on it. The write path rebuilt the Models[role] entry from scratch via ModelEntryWriter, which only writes modalities it was handed (a probe result). Modalities have no CLI input and can only be hand-edited, so a manual 'model set' (or a context-window tweak, or the TUI picker re-selecting the same model) passed null and silently deleted a hand-set InputModalities/OutputModalities — the concrete netclaw-dev#1127 loss. Add ModelEntryWriter.WriteRole, a non-destructive persist: when the role already points at the same (provider, modelId), preserve the existing modalities and context window the caller did not supply; switching to a different model still starts clean (old attributes belonged to the old model). Routed 'model set' and the TUI model manager through it. Verified against the shipped binary: on stock beta 0.25.0, 'model set main <same-model> --context-window N' wipes InputModalities; with this fix the same command preserves it. No config-shape or schema change, so this is fully backwards compatible. Tests: WriteRole_SameModelWithoutModalities_PreservesHandSetModalities, WriteRole_DifferentModel_DropsPreviousModelModalities. * fix(cli): make model-set metadata operator-owned; discovery never clobbers it Hardens the non-destructive `model set`/picker rewrite (netclaw-dev#1127) against every issue surfaced reviewing netclaw-dev#1610, and closes the loop on modality overrides. ContextWindow and modalities are documented to "take precedence over provider-reported capability detection", so they are now treated as operator-owned overrides with a single precedence rule: explicit operator input > existing stored value > probe. A fresh probe seeds a first-time set or a model switch but never overwrites a value already on disk. Changes: 1. ContextWindow clamp preserved on same-model re-set. WriteRole takes the explicit --context-window and the probe default separately; the old callers collapsed them (`contextWindow ?? discovered`), so probe/picker paths always passed a non-null value and the operator's clamp was overwritten on every re-selection. 2. Modalities are no longer silently overwritten by discovery. Previously a probe that reported modalities replaced a stored override (the netclaw-dev#1127 loss's twin); now the stored value wins, matching the field's "manual override bypasses detection" contract. 3. Operators can change/remove those overrides. Since discovery no longer edits them, add `--input-modalities`, `--output-modalities`, and `--clear-modalities` to `model set`. Explicit set replaces the stored value; clear removes it (runtime detection resolves). Supplying any of them (like --context-window) skips the probe as manual configuration. 4. Corrupt/legacy existing entry no longer aborts the command. ReadSameModelEntry guards the deserialize (catch JsonException): an unreadable entry (e.g. an unrecognized modality enum string) degrades to "nothing to preserve" and the command overwrites/repairs it. 5. No false-match on ModelReference defaults. Provider/ModelId default to the stock local-ollama model, so an entry omitting either key deserialized to that default and would false-match a re-set of the stock model; preservation now requires both keys. 6. Provenance not downgraded. A same-model re-set that did not re-resolve the ID (no probe → Manual) keeps a previously discovered origin (Live/Defaults); only a fresh discovery updates it. Tests: ModelEntryWriter unit coverage for each precedence path (clamp-over-probe, probe- does-not-override-existing-modalities, explicit set, clear-over-probe, first-time seeding, default-model false-match, corrupt-entry overwrite, provenance preserve/update) plus CLI end-to-end coverage for the new flags. Full CLI suite green; slopwatch clean; model-manager smoke tape passes. * fix(cli): harden model-set overrides + add --clear-context-window (netclaw-dev#1610) Addresses code-review findings on the non-destructive model-set change: - probe gate: only --context-window short-circuits the probe; a modality flag no longer skips model-existence validation and context-window discovery - preservation read: a corrupt modality enum string no longer discards a valid operator-owned ContextWindow (field-tolerant recovery) - arg parsing: missing flag values and unknown args fail loudly instead of being silently dropped - cleared modality is now sticky: discovery is hands-off once a same-model entry exists, so a later probe cannot resurrect a --clear-modalities removal - TryParseModalities rejects raw numeric strings (named flags only) - provenance: preserve a prior discovered origin on any non-Live re-set (was only guarding Manual) - new --clear-context-window flag to force window re-detection (symmetry with --clear-modalities) Also hardens LoadModelSelection: a corrupt/legacy config no longer crashes `model set` (repairs it) or `model list` (reports it cleanly) or the TUI. Generalizes ModalityOverride into a shared ValueOverride<T> tri-state. Updates netclaw-operations skill (providers.md). Docs website tracked in netclaw-dev/netclaw-website#83. * feat(config): preserve model definitions across role switches * fix(config): validate named model role references * fix(cli): preserve models when editing providers
) Bumps [dotnet-sdk](https://github.com/dotnet/sdk) from 10.0.300 to 10.0.301. - [Release notes](https://github.com/dotnet/sdk/releases) - [Commits](dotnet/sdk@v10.0.300...v10.0.301) --- updated-dependencies: - dependency-name: dotnet-sdk dependency-version: 10.0.301 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Aaronontheweb
merged commit Jul 12, 2026
3ee94a9
into
netclaw-dev:feature/memory-embeddings
23 of 24 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fifth experimental prerelease in the memory-embeddings series. No memory/embeddings behavior change vs
0.25.0-alpha.onnx.4— this brings the experimental line current with mainlinedevand stamps0.25.0-alpha.onnx.5.What's in it
Clean merge of
upstream/dev(through2f0b72df1) into the feature branch — auto-merged, zero conflicts:Plus the release-prep commit:
VersionSuffix→alpha.onnx.5, new RELEASE_NOTES section.Verification
71431707a+ dev2f0b72df1.SubAgentSpawnerhas a single fail-closedApprovalBridgeassignment gated onSupportsInteractiveApproval, coexisting with the fix(subagents): record sub-agent LLM token usage to daily stats (#1597) #1600ISessionMetricsconstructor — verified in the merged tree by hand.dotnet build0 warnings / 0 errors;Netclaw.Actors.Tests(SubAgent + Memory filter) 454/454 pass, including the by-name fail-closed assertions across Reminder / Headless / Webhook channel types, and the sub-agent token-usage tests.Directory.Build.props=0.25.0-alpha.onnx.5, matches the intended tag; RELEASE_NOTES top section is## 0.25.0-alpha.onnx.5.Deliberately excluded
dev's
72b520432(the0.25.0-beta.3release stamp) — metadata-only (version + release notes on a different channel). onnx.5 already carries all of dev's code fixes; pulling the beta.3 stamp would only churn the version files.After merge
Cut tag
0.25.0-alpha.onnx.5on canonical to fire the release pipeline.alpha.*sorts belowbeta.3, so the tag stays channel-neutral — it won't advance:betaor the manifestlatestPrerelease. Install is exact-pin only (NETCLAW_VERSION=0.25.0-alpha.onnx.5); upgrade from onnx.4 is a binary swap with no config/data/unit changes.