Skip to content

refactor: route command session reads through seam#89122

Merged
jalehman merged 6 commits into
mainfrom
clawdbot-d9a/31b-cron-infra-command-seam
Jun 14, 2026
Merged

refactor: route command session reads through seam#89122
jalehman merged 6 commits into
mainfrom
clawdbot-d9a/31b-cron-infra-command-seam

Conversation

@jalehman

@jalehman jalehman commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

What

Path 3 / PR 3.1b cron/infra/commands slice for #88838. This routes cron, infra, and command session-entry read callers through the 3.1a session accessor seam while preserving the current file-backed runtime behavior.

Why

This prepares the cron/infra/command read surface for the SQLite session-store foundation without flipping production storage. The disposable SQLite validation branch proved the migrated read callers can run against the SQLite foundation, and the remaining writer-store race is tracked separately as a 3.2 follow-up outside this PR.

Changes

  • Route command session reads through accessor
  • Route status/export/health read paths
  • Route cron/TTS/delivery read paths
  • Preserve shared file-store semantics
  • Add focused agent-scope coverage
  • No storage flip or dual-read fallback
  • No SQLite schema/store changes

Testing

Source branch proof:

  • OPENCLAW_HEAVY_CHECK_LOCK_SCOPE=worktree node scripts/run-vitest.mjs src/commands/sessions.test.ts src/commands/sessions.default-agent-store.test.ts src/commands/sessions-tail.test.ts src/commands/status.summary.test.ts src/commands/status.test.ts src/commands/export-trajectory.test.ts src/commands/health.test.ts src/commands/health.snapshot.test.ts src/commands/sandbox-explain.test.ts src/cron/isolated-agent/delivery-target.test.ts src/infra/exec-approval-session-target.test.ts passed before the final agent-scope backport.
  • OPENCLAW_HEAVY_CHECK_LOCK_SCOPE=worktree node scripts/run-vitest.mjs src/commands/status.summary.test.ts src/commands/health.test.ts src/commands/health.snapshot.test.ts src/commands/status.test.ts passed after source backport commit ed3f914005.
  • pnpm tsgo:core passed.
  • pnpm tsgo:core:test passed.
  • pnpm exec oxfmt --check ... passed.
  • node scripts/run-oxlint.mjs ... passed.
  • git diff --check passed.
  • Local autoreview passed with no accepted/actionable findings.

Disposable SQLite validation proof:

  • Branch: integration/sqlite-flip-cron-infra-command.
  • Validation commits: e5fc2ef023, 5d04dd2a35, 729b97bf18.
  • File-backed focused integration proof passed across sessions/status/export/health/sandbox/cron/infra tests.
  • OPENCLAW_SQLITE_SESSION_STORE_FOR_VALIDATION=1 node scripts/run-vitest.mjs src/commands/sqlite-session-validation.test.ts passed.
  • node scripts/run-vitest.mjs src/config/sessions/session-accessor.conformance.test.ts passed without the SQLite validation env.
  • Integration pnpm tsgo:core, pnpm tsgo:core:test, pnpm exec oxfmt --check ..., node scripts/run-oxlint.mjs ..., and git diff --check passed.

Source blockers: none.

External follow-up: clawdbot-3b8 / clawdbot-d02.1.9.1.17 tracks a 3.2 SQLite writer-store atomicity/idempotency race found during disposable branch review. That issue is outside this read-only cron/infra/command PR.

Real behavior proof

Behavior addressed: Command, cron, infra, health, status, session-list, session-tail, and trajectory-export read paths on PR #89122 route through the session accessor seam while preserving the current file-backed runtime behavior. This proof specifically covered the refreshed PR head after rebasing over #90463 and the follow-up fix for live placeholder session-store rows without transcript session ids.

Real environment tested: Local macOS OpenClaw gateway running from the live source checkout at ~/Projects/clawdbot, with the LaunchAgent gateway bound to 127.0.0.1:18789. PR head loaded detached at 0b8ce0a. Earlier baseline/rollback proof restored the gateway to main at fc6d448 before loading this updated PR head.

Exact steps or command run after this patch:

cd ~/Projects/clawdbot

git fetch ~/.codex/worktrees/4b4c/clawdbot clawdbot-d9a/31b-cron-infra-command-seam # local branch fetch, path normalized during run
git switch --detach 0b8ce0a2aad995cc25e4a673d7d96f357eb2bb96
node scripts/run-node.mjs gateway restart

node openclaw.mjs gateway status --deep
curl -sS --max-time 5 http://127.0.0.1:18789/health
node openclaw.mjs health --json
node openclaw.mjs status --json
node openclaw.mjs sessions --json
node openclaw.mjs sessions --all-agents --json
node openclaw.mjs sessions tail --session-key 'agent:main:main' --agent main --tail 5
node openclaw.mjs sessions export-trajectory --session-key 'agent:main:main' --agent main --output pr89122-live-export-0ff37c --json
node openclaw.mjs cron status --json
node openclaw.mjs cron list --json
node openclaw.mjs cron show ad5ab66a-15b3-46b8-87a5-5aca971daf5c --json
node openclaw.mjs cron runs --id '<job-id>' --limit 5 # repeated for all 6 listed jobs
node scripts/check-session-accessor-boundary.mjs

tail -n 300 /tmp/openclaw/openclaw-2026-06-14.log > /tmp/pr89122-gateway-log-0ff37c-tail.txt

Evidence after fix: The PR runtime rebuilt and restarted the LaunchAgent gateway successfully. Gateway status reported runtime running, connectivity probe ok, and admin-capable. HTTP /health returned {"ok":true,"status":"live"}. health --json returned ok true with session summary keys present. status --json returned runtimeVersion 2026.6.2, sessionCount 16, and recentCount 10. sessions --json returned count 16, totalCount 16, and hasMore false. sessions --all-agents --json returned 21 sessions across main and codex. sessions tail for agent:main:main returned 5 lines, 343 bytes, and no TypeError/error text. sessions export-trajectory wrote an 8-file redacted export with eventCount 846, runtimeEventCount 185, and transcriptEventCount 661. cron status --json returned enabled true and storage sqlite. cron list --json returned 6 jobs. cron show --json returned the inspected job with delivery, sessionTarget, and payload fields. cron runs --id --limit 5 exited 0 for all 6 listed jobs. The local boundary guard printed "session accessor boundary guard passed." After the stale helper cleanup, git grep -n "store-read\|readSessionStoreReadOnly" -- src test scripts .github only reported intentional boundary-guard references, node scripts/check-deadcode-unused-files.mjs passed, and pnpm deadcode:dependencies passed. After maintainer-visible channel checks, gateway logs showed Telegram message received at 2026-06-14T07:31:23-07:00 and 2026-06-14T07:31:51-07:00, Discord message received at 2026-06-14T07:31:33-07:00, matching model runs, dispatch completed, and message processed for both channels. Telegram session tail returned 20 lines with no error text; Discord session tail returned 7 lines with no error text. The sampled post-channel gateway log tail had 1200 structured JSON log lines with 0 log-level warn, 0 log-level error, and 0 uncaught entries. Post-rebase/current-head proof at 73218cc7cd336c7389785960364aed4049a1affd also passed: focused command/cron/session Vitest proof, session accessor boundary guard, deadcode guard, git diff --check, targeted oxfmt/oxlint, core/test tsgo probes, and branch autoreview with no accepted/actionable findings. The current-head fix preserves sessions tail for sessionFile-only entries, including pointer-backed and OPENCLAW_TRAJECTORY_DIR trajectory paths, and updates cron delivery-target tests to mock the session accessor seam directly.

Observed result after fix: The command/cron/infra/status/health/session-list/session-tail/export read surfaces exercised against the live gateway continued to work on PR head 0b8ce0a, including the previously failing live sessions tail path. Current head 73218cc was rebased onto latest main and covered by focused local/CI proof rather than a second live gateway load. The slice-specific boundary guard exercised the intended migrated-file ratchet. Maintainer-run Telegram and Discord visible messages both worked: the gateway received, queued, ran, dispatched, and processed both channel turns. Telegram displayed a client-side "unsupported message / update" wrapper; logs showed Telegram Bot API sends succeeded with operation=sendRichMessage and no Telegram send error, and this rich-message operation appeared in the same day log before this PR proof window, so it was classified as existing Telegram rich-message/client behavior rather than a #89122 session-read regression.

What was not tested: No broad/full suite, Docker, or cross-OS proof was run as part of this local proof. The configured cron jobs are real enabled production jobs with delivery/sessionTarget/payload fields, so cron run was not fired without maintainer approval because it could spend model tokens or produce external/user-visible effects. The Telegram/Discord visible path was exercised by the maintainer and then verified from gateway/session logs.

@openclaw-barnacle openclaw-barnacle Bot added commands Command implementations docker Docker and sandbox tooling labels Jun 1, 2026
@openclaw-barnacle openclaw-barnacle Bot added size: M maintainer Maintainer-authored PR labels Jun 1, 2026
@clawsweeper

clawsweeper Bot commented Jun 1, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed June 14, 2026, 11:46 AM ET / 15:46 UTC.

Summary
The PR routes command, cron, infra, status, health, session-list, session-tail, and trajectory-export session reads through the session accessor seam while preserving file-backed storage behavior.

PR surface: Source +73, Tests +260, Other +22. Total +355 across 21 files.

Reproducibility: not applicable. as a user bug reproduction; this is an internal refactor PR. The relevant check is behavior-preservation proof for existing session read surfaces, and the PR body plus focused tests cover the touched paths.

Review metrics: 2 noteworthy metrics.

  • Migrated read surfaces: 10 production reader files added to the seam ratchet. The change is wider than a local refactor and reaches multiple user-visible session read paths.
  • Boundary guard expansion: 3 legacy reader names added; 10 migrated files added. The stricter guard changes future CI behavior for direct session-store reader use in these paths.

Stored data model
Persistent data-model change detected: serialized state: src/commands/sessions-tail.test.ts, serialized state: src/commands/sessions-tail.ts, serialized state: src/commands/sessions.default-agent-store.test.ts, serialized state: src/commands/sessions.ts, serialized state: src/config/sessions/store-read.test.ts, serialized state: src/config/sessions/store-read.ts, and 5 more. Confirm migration or upgrade compatibility proof before merge.

Merge readiness
Overall: 🦞 diamond lobster
Proof: 🦞 diamond lobster
Patch quality: 🦞 diamond lobster
Result: ready for maintainer review.

Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch.

Risk before merge

  • [P1] The migrated read paths span user-visible session listing, tail, status, health, export, cron delivery, timer, and TTS behavior; a scope mismatch could hide or mis-associate persisted sessions.
  • [P1] The boundary guard intentionally expands the CI ratchet, so future direct session-reader use in these files will fail automation until maintainers accept the new boundary.
  • [P1] Real behavior proof is strong but mostly local/macOS and not broad Docker or cross-OS proof for this storage-adjacent migration slice.

Maintainer options:

  1. Land With Maintainer Acceptance (recommended)
    Maintainers can land once they accept this as the next behavior-neutral accessor-adoption slice and current required checks remain green.
  2. Ask For Broader Runtime Proof
    Maintainers can request Docker, Linux, or cross-OS runtime proof if local macOS live-gateway proof is not enough for this storage-adjacent path.
  3. Pause Under The Migration Tracker
    If the command/cron/infra boundary shape still needs design changes, pause this PR under the canonical session SQLite tracker instead of landing a partial direction.

Next step before merge

  • [P2] Protected maintainer review and explicit acceptance of session-state compatibility risk are the remaining actions; there is no narrow automated repair to queue.

Security
Cleared: No concrete security or supply-chain issue found; the diff does not add dependencies, workflows, permissions, secret handling, downloads, or third-party execution paths.

Review details

Best possible solution:

Land this seam-adoption slice only after maintainers accept the session-state compatibility and boundary-ratchet tradeoff, while keeping the SQLite storage flip and writer-store race under #88838.

Do we have a high-confidence way to reproduce the issue?

Not applicable as a user bug reproduction; this is an internal refactor PR. The relevant check is behavior-preservation proof for existing session read surfaces, and the PR body plus focused tests cover the touched paths.

Is this the best way to solve the issue?

Yes, if maintainers accept the staged migration plan: this adopts the already-merged accessor seam without flipping storage or adding runtime dual-read fallback. The safer alternative would be to pause under the canonical tracker if maintainers want a different seam boundary before more caller slices land.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 2e240e772b83.

Label changes

Label changes:

  • add rating: 🦞 diamond lobster: Overall readiness is 🦞 diamond lobster; proof is 🦞 diamond lobster and patch quality is 🦞 diamond lobster.
  • remove rating: 🐚 platinum hermit: Current PR rating is rating: 🦞 diamond lobster, so this older rating label is no longer current.

Label justifications:

  • P2: This is a normal-priority staged session-state refactor with meaningful but bounded compatibility risk, not an active outage or security emergency.
  • merge-risk: 🚨 compatibility: The PR changes how existing file-backed persisted session reads are reached and must preserve current upgrade/runtime behavior.
  • merge-risk: 🚨 session-state: Incorrect agent/store scoping in these migrated readers could hide, duplicate, or mis-associate persisted sessions.
  • merge-risk: 🚨 automation: The diff expands the session-accessor boundary guard and can change which future direct-reader imports fail CI.
  • rating: 🦞 diamond lobster: Overall readiness is 🦞 diamond lobster; proof is 🦞 diamond lobster and patch quality is 🦞 diamond lobster.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (logs): The PR body includes after-fix live gateway terminal/log proof for health, status, sessions, tail, export, cron reads, the boundary guard, and Telegram/Discord processing, plus focused current-head proof for the final fallback fix.
  • proof: sufficient: Contributor real behavior proof is sufficient. The PR body includes after-fix live gateway terminal/log proof for health, status, sessions, tail, export, cron reads, the boundary guard, and Telegram/Discord processing, plus focused current-head proof for the final fallback fix.
Evidence reviewed

PR surface:

Source +73, Tests +260, Other +22. Total +355 across 21 files.

View PR surface stats
Area Files Added Removed Net
Source 11 197 124 +73
Tests 9 426 166 +260
Docs 0 0 0 0
Config 0 0 0 0
Generated 0 0 0 0
Other 1 24 2 +22
Total 21 647 292 +355

What I checked:

  • Repository policy applied: Root AGENTS.md and relevant scoped guides for scripts, outbound helpers, and tests were read fully; the review applied the session-state, migration, proof, and boundary-guard guidance. (AGENTS.md:28, 2e240e772b83)
  • PR patch surface verified: The merge-base diff contains the expected 21 files and no whitespace errors; it is not already implemented on current main. (99156999ce44)
  • Accessor contract checked: The session accessor module defines the storage-neutral domain boundary and exposes loadSessionEntry and listSessionEntries, which the migrated readers now use. (src/config/sessions/session-accessor.ts:35, 99156999ce44)
  • Status aggregation preserves agent scoping: Status summary now lists session candidates through the accessor with store path plus agent scope, and aggregates shared store paths only once for the global recent list. (src/commands/status.summary.ts:149, 99156999ce44)
  • Session tail fallback checked: The tail command skips placeholder entries with no usable transcript target and preserves sessionFile-only trajectory fallback, pointer-backed runtime files, and OPENCLAW_TRAJECTORY_DIR behavior. (src/commands/sessions-tail.ts:355, 99156999ce44)
  • Boundary ratchet checked: The guard expands migrated files and legacy reader names so this command/cron/infra slice cannot reintroduce direct file-store readers in the ratcheted files. (scripts/check-session-accessor-boundary.mjs:14, 99156999ce44)

Likely related people:

  • jalehman: Authored the merged session-accessor foundation in refactor: add session accessor seam with gateway consumer #90463 and authored this staged command/cron/infra migration slice. (role: session accessor feature owner; confidence: high; commits: ef47dd610c87, 99156999ce44; files: src/config/sessions/session-accessor.ts, scripts/check-session-accessor-boundary.mjs, src/commands/sessions-tail.ts)
  • Dallin Romney: Current-main blame/log history for the baseline status summary, session tail, and store-read surfaces points to recent work by this contributor before the accessor migration. (role: recent area contributor; confidence: medium; commits: 1affe4fcdf5f; files: src/commands/status.summary.ts, src/commands/sessions-tail.ts, src/config/sessions/store-read.ts)
  • ghitafilali: Recent current-main history touches cron runtime behavior adjacent to the delivery-target/timer reads migrated by this PR. (role: adjacent cron contributor; confidence: low; commits: b2c5e790b441; files: src/cron/isolated-agent/delivery-target.ts, src/cron/service/timer.ts)
What the crustacean ranks mean
  • 🦀 challenger crab: rare, exceptional readiness with strong proof, clean implementation, and convincing validation.
  • 🦞 diamond lobster: very strong readiness with only minor maintainer review expected.
  • 🐚 platinum hermit: good normal PR, likely mergeable with ordinary maintainer review.
  • 🦐 gold shrimp: useful signal, but proof or patch confidence is still limited.
  • 🦪 silver shellfish: thin signal; proof, validation, or implementation needs work.
  • 🧂 unranked krab: not merge-ready because proof is missing/unusable or there are serious correctness or safety concerns.
  • 🌊 off-meta tidepool: rating does not apply to this item.

Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

How this review workflow works
  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@clawsweeper clawsweeper Bot added rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. P2 Normal backlog priority with limited blast radius. merge-risk: 🚨 session-state 🚨 May lose, corrupt, stale, or mis-associate session, agent, or context state. labels Jun 1, 2026
@jalehman
jalehman marked this pull request as draft June 1, 2026 18:10
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. and removed rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. labels Jun 1, 2026
@jalehman
jalehman force-pushed the clawdbot-9c3/session-accessor-seam branch from f18f99c to b39023f Compare June 4, 2026 20:31
@jalehman
jalehman force-pushed the clawdbot-d9a/31b-cron-infra-command-seam branch from ed3f914 to c682c25 Compare June 4, 2026 21:24
@jalehman
jalehman changed the base branch from clawdbot-9c3/session-accessor-seam to clawdbot-9c3-ce2/session-accessor-gateway-entry June 4, 2026 21:24
@jalehman
jalehman force-pushed the clawdbot-9c3-ce2/session-accessor-gateway-entry branch from 1c31222 to 4b0e698 Compare June 4, 2026 21:31
@clawsweeper clawsweeper Bot added rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. and removed rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. labels Jun 4, 2026
@jalehman
jalehman force-pushed the clawdbot-9c3-ce2/session-accessor-gateway-entry branch 2 times, most recently from 890d5e3 to b496b4b Compare June 10, 2026 22:16
@jalehman
jalehman force-pushed the clawdbot-d9a/31b-cron-infra-command-seam branch from c682c25 to 681123f Compare June 11, 2026 05:03
@clawsweeper clawsweeper Bot added rating: 🌊 off-meta tidepool PR readiness rating does not apply to this item. and removed rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Jun 11, 2026
@jalehman
jalehman force-pushed the clawdbot-9c3-ce2/session-accessor-gateway-entry branch from 1e31abd to 094f9b5 Compare June 13, 2026 23:20
@clawsweeper clawsweeper Bot added the rating: 🦞 diamond lobster Very strong PR readiness with only minor maintainer review expected. label Jun 14, 2026
@jalehman
jalehman force-pushed the clawdbot-d9a/31b-cron-infra-command-seam branch from 9915699 to 73218cc Compare June 14, 2026 15:52
@jalehman
jalehman merged commit e174418 into main Jun 14, 2026
168 of 170 checks passed
@jalehman
jalehman deleted the clawdbot-d9a/31b-cron-infra-command-seam branch June 14, 2026 16:01
@jalehman

Copy link
Copy Markdown
Contributor Author

Merged via squash.

Thanks @jalehman!

NianJiuZst pushed a commit to NianJiuZst/openclaw that referenced this pull request Jun 14, 2026
Merged via squash.

Prepared head SHA: 73218cc
Co-authored-by: jalehman <[email protected]>
Co-authored-by: jalehman <[email protected]>
Reviewed-by: @jalehman
github-actions Bot pushed a commit to Desicool/openclaw that referenced this pull request Jun 15, 2026
Merged via squash.

Prepared head SHA: 73218cc
Co-authored-by: jalehman <[email protected]>
Co-authored-by: jalehman <[email protected]>
Reviewed-by: @jalehman
saml212 added a commit to Rockielab/rockie-claw that referenced this pull request Jun 16, 2026
)

* fix(chunking): preserve surrogate pairs

* test(telegram): cover rich list and table limits

* fix(telegram): migrate retired native draft config

* fix(telegram): keep rich text media-free

* feat(telegram): nudge agents toward rich text

* fix(telegram): clean rich message CI gates

* test(telegram): align message flow fixture with rich drafts

* fix(telegram): allow rich tables in group prompts

* fix(telegram): show rich text prompt for final replies

* fix(telegram): pass rich text prompts to cli backends

* fix(ui): restore sidebar session picker interactivity above desktop workbench (#92705)

* fix(ui): restore sidebar session picker interactivity above desktop workbench

The collapsed sidebar session picker was covered by the chat content
area when the workspace rail was visible at wider viewports. Two
issues caused this:

1. .sidebar-session-select--collapsed .chat-session-picker used
   var(--z-dropdown) which was never defined, creating an invalid
   z-index declaration (falls back to auto).

2. .shell-nav and .content--chat are grid siblings with equal
   z-index (auto), and .content--chat (later DOM) paints above
   .shell-nav, covering the session picker that extends from the
   nav column into the content column.

Fix: add position:relative + z-index:10 to .shell-nav so it stacks
above .content--chat; change overflow from hidden to visible so
the session picker extends beyond the nav rail; replace undefined
var(--z-dropdown) with z-index:100.

* fix(ui): keep sidebar picker z-index tokenized

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(google): strip provider prefix from Vertex model path

Summary:
- Strip the redundant `google/` provider prefix before embedding Google Vertex model ids under `/publishers/google/models/`.
- Keep bare Vertex model ids unchanged.
- Add regression coverage for the provider-qualified Vertex path.

Verification:
- `node_modules/.bin/oxfmt --check --threads=1 extensions/google/transport-stream.ts extensions/google/transport-stream.test.ts`
- `node scripts/run-oxlint.mjs extensions/google/transport-stream.ts extensions/google/transport-stream.test.ts`
- `node scripts/run-vitest.mjs extensions/google/transport-stream.test.ts --maxWorkers=1 -t 'strips redundant google provider prefixes from Google Vertex model paths'`
- Autoreview clean
- AWS Crabbox `run_649b209478d2` focused Node 24 regression proof
- AWS Crabbox `run_e193db2707ad` remote `check:changed`
- Exact-head CI green for `23aca6f46f596e220df37d939317b433f7044ec6`
- Contributor live Google Vertex proof recorded in the PR body

* feat: support /btw in CLI-backed sessions (#92669)

* feat: support CLI btw side questions

* test: fix CLI prepare test fixture types

* fix: lazy load local btw runner

* fix(gateway): mark active main sessions before restart shutdown aborts (#91357)

* Mark active main sessions during restart shutdown

* Type restart marker mock in close tests

* fix(gateway): preserve active run ownership across restart

* fix(gateway): preserve active runs across restart

* fix(gateway): close restart recovery edge cases

* fix(cron): preserve lifecycle ownership across restart

* fix(gateway): release rejected run contexts

* fix(gateway): preserve restart lifecycle ownership

* fix(cron): retain overlapping run ownership

* fix(agents): preserve restart terminal precedence

---------

Co-authored-by: Peter Steinberger <[email protected]>

* fix(parallel): send User-Agent on free MCP requests

Adds the OpenClaw Parallel User-Agent to free Parallel Search MCP requests so the zero-config web_search path is identifiable at the HTTP layer, matching the paid REST transport.\n\nProof: local focused format/lint/Vitest; live anonymous Parallel MCP handshake; autoreview clean; Crabbox AWS run_bf41ce86e862 focused regression; Crabbox AWS run_ee9b8954b081 check:changed; exact-head GitHub CI green on b7e45e3bfc83cec6ca8df3d9d2708e2c45f093a9.

* fix(ui): preserve dashboard session parent lineage

Preserves the selected Control UI session as the parent when creating dashboard child sessions even if the session list is stale or filtered, while avoiding the synthetic unknown session as a parent.\n\nFixes #90623.\n\nProof: local focused format/lint/Vitest/browser test; autoreview clean; Crabbox AWS run_a2bfdcd2315a UI proof; Crabbox AWS run_ce60fdc546ff check:changed; exact-head GitHub CI green on 03d1c6f646caeed2813e673446109751a50c610f.

* fix(ios): force stale foreground gateway reconnects (#92552)

* fix(telegram): expose thread create CLI remap

Exposes Telegram's thread-create CLI remap through the exported Telegram channel action adapter, preserving the existing plugin-owned mapping to topic-create before gateway dispatch.\n\nFixes #81581.\n\nProof: local focused format/lint/Vitest and dry-run; autoreview clean; Crabbox AWS run_07b98c939fce focused tests; Crabbox AWS run_1b7b35ce1de1 check:changed; exact-head GitHub CI green on 16f6afbdd7d8e1f1df81b71eaf10436e9771181c.

* feat: make workspace files panel collapsible

Signed-off-by: sallyom <[email protected]>

* fix: start workspace files collapsed

* fix(state): avoid sqlite wal on nfs state volumes

Detects NFS-backed SQLite database paths in the shared WAL helper and uses rollback journaling for those paths while preserving WAL/checkpoint maintenance on local filesystems. The NFS path now verifies SQLite's effective journal mode before disabling WAL maintenance, and core/memory/proxy-capture callers pass database path context into the centralized helper.

Fixes #90491.

Proof: local focused Vitest/format/lint; autoreview clean after fixing the journal-mode verification finding; Crabbox AWS focused test run `run_2ea7014350da`; Crabbox AWS changed gate `run_c828bbfe7d23`; exact-head GitHub CI green on `59674305ecd863d4815eec6098ccd3daab79ca4f`.

* fix(tui): show resolved model ref in confirmation

Uses the canonical model ref returned by `sessions.patch` for the TUI `/model` confirmation so alias inputs report the model that was actually applied. The fallback still shows the raw input when a backend does not return `resolved`, and the display path uses `modelKey` so nested model ids keep the provider prefix without double-prefixing self-prefixed ids.

Proof: local focused TUI Vitest/format/lint; autoreview clean; Crabbox AWS focused TUI test run `run_7d7cc5b040e8`; exact-head GitHub CI green on `6db4acfb08f9d477ee1bdab429bd7189b78ffc92`.

* fix(diagnostics): keep recovery scheduling out of the stuck-session warning backoff (#92752)

Summary:
- The branch changes diagnostic stuck/long-running warning backoff so recovery-eligible classifications are still returned during throttled warning ticks and updates the diagnostic tests.
- PR surface: Source +17, Tests +48. Total +65 across 2 files.
- Reproducibility: yes. Current main source shows logSessionAttention can return undefined during stuck or lon ... g backoff before the heartbeat reaches requestStuckSessionRecovery; I did not run a live QQ gateway replay.

Automerge notes:
- PR branch already contained follow-up commit before automerge: fix(diagnostics): keep recovery scheduling out of the stuck-session w…

Validation:
- ClawSweeper review passed for head f61ec3a33f2c48b03306df38264b3ce9bd062f08.
- Required merge gates passed before the squash merge.

Prepared head SHA: f61ec3a33f2c48b03306df38264b3ce9bd062f08
Review: https://github.com/openclaw/openclaw/pull/92752#issuecomment-4699298908

Co-authored-by: Gnanam <[email protected]>
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: clawsweeper[bot] <274271284+clawsweeper[bot]@users.noreply.github.com>
Approved-by: takhoffman
Co-authored-by: takhoffman <[email protected]>

* fix(markdown-core): treat infinity chunk limit as unbounded

Fix render-aware markdown chunking so `Number.POSITIVE_INFINITY` is treated as an explicit unbounded chunk limit instead of falling back to `1`.

This preserves full Signal media captions and disabled Signal text chunking while keeping invalid non-finite limits on the existing fallback path.

Fixes #92734.
Thanks @yhterrance for the report and fix.

* docs(config): correct agent defaults concurrency comments

Correct the exported agent defaults type comments for `maxConcurrent` and `subagents.maxConcurrent` so they match the runtime defaults of 4 and 8.

No runtime behavior changes.
Thanks @ArielSmoliar for the fix.

* docs: clarify before_install hook scope (#92766)

Signed-off-by: sallyom <[email protected]>

* docs(nodes): add node config example

Add a Nodes overview `openclaw.json` example for node pairing, command allow/deny policy, node exec routing, and per-agent node pinning.

Also clarifies exact `denyCommands` matching and links readers to the config reference for pairing and command-policy field details.

Fixes #92662.
Thanks @liuhao1024 for the fix and @ZengWen-DT for the parallel docs wording on exact node command policy.

* Honor WhatsApp configured ACP bindings (#92513)

Merged via squash.

Prepared head SHA: 665080f48278a6af9d5595708bd9cfd30e36a29c
Co-authored-by: TurboTheTurtle <[email protected]>
Co-authored-by: mcaxtr <[email protected]>
Reviewed-by: @mcaxtr

* fix(memory): split header-too-large embedding batches

Route OpenAI/OpenAI-compatible request_headers_too_large embedding failures into the existing memory-core batch splitter instead of aborting bulk memory indexing.

Tighten the classifier to require header-too-large wording rather than a bare 431 status token, so unrelated provider errors do not fan out into recursive requests.

Fixes #92465.
Thanks @mushuiyu886 for the fix and @BrettHamlin for the report and proof.

* feat(providers): add GLM-5.2 support (#92796)

* feat(providers): add GLM-5.2 support

* ci(live): add GLM-5.2 provider shard

* fix(sessions): enforce channel send policy for account-scoped DMs

Derive the channel from canonical account-scoped DM session keys when resolving session.sendPolicy, so channel-scoped allow/deny rules apply to per-account-channel-peer sessions.

Keep derivation limited to canonical channel peer key shapes and add malformed-key regressions so incomplete or non-channel keys do not accidentally match channel rules.

Compatibility note: existing channel-scoped send-policy rules can now block account-scoped DM sends that were previously allowed by this bug.

Thanks @yetval for the fix.

* docs(changelog): refresh 2026.6.8 notes

* fix(ui): localize workspace file rail labels

* fix(docker): remove stale nested openclaw package

Remove the stale nested openclaw package, its .bin shim, and the pnpm virtual-store copy from the runtime Docker image before final runtime assets are copied.

Run the package dist import-closure check after the cleanup so the check validates the final runtime-assets tree that the image ships.

Compatibility note: private Docker paths under /app/node_modules/openclaw and /app/node_modules/.bin/openclaw are removed; downstream images should use the documented /usr/local/bin/openclaw launcher or /app/openclaw.mjs.

Fixes #92551.
Thanks @lzyyzznl for the fix and @fxstein for the report.

* fix(release): repair beta validation fixtures

* chore(deps): bump macOS Swift dependencies

Updates the macOS Swift package resolution for patch releases of Peekaboo, Sparkle, and swift-log.

Verification:
- `swift package describe --type json`
- `swift build --target OpenClawIPC`
- `swift build --target OpenClawDiscovery`
- upstream tag/revision checks for Peekaboo 3.4.1, Sparkle 2.9.3, and swift-log 1.13.2
- autoreview clean
- exact PR head CI green for macOS, dependency, and security checks

* fix(qa): read rich Telegram replies in live checks

(cherry picked from commit 9c8b8803535b38ec204ead00c29c35e4ea1a8ee7)

* fix(agents): preserve compatible CLI session runtime pins

Preserves provider-compatible CLI runtime session pins across reply execution, follow-up execution, dispatch visibility, preflight compaction, and memory flush.

This keeps sessions pinned to compatible CLI runtimes such as `claude-cli` from leaking into embedded OpenClaw maintenance paths while still rejecting cross-provider runtime pins.

Original PR by @yu-xin-c; includes maintainer follow-up for the sibling memory paths.

Verification:
- `node scripts/run-vitest.mjs src/auto-reply/reply/agent-runner-execution.test.ts src/auto-reply/reply/agent-runner-memory.test.ts src/agents/model-runtime-aliases.test.ts --maxWorkers=1`
- autoreview clean
- Crabbox AWS `cbx_44400b494e97` / `coral-prawn`, run `run_69dd43475e39`: `check:changed` passed
- exact PR head CI green: `303b2f794f6c01fcf21b62b27c536b5f6eceb421`

* test(macos): isolate exec approvals env

* test(macos): avoid real approvals migration in tests

* fix(matrix): validate CLI numeric option ranges

Validates Matrix CLI numeric option ranges before invoking setup or verification side effects.

`--initial-sync-limit` must now be non-negative, and `--timeout-ms` must now be positive.

Original PR by @rohitjavvadi.

Verification:
- `node scripts/run-vitest.mjs extensions/matrix/src/cli.test.ts --maxWorkers=1`
- autoreview clean
- Crabbox AWS `cbx_5c32f138ab3a` / `swift-lobster`, run `run_6e133b8b82e7`: `check:changed` passed
- exact PR head CI green: `d75f118299029b0516311646276cd2d6582379c5`

* fix(qa): accept rich Telegram canary presence

(cherry picked from commit e86eb7567a79fd3fe90115d3840222a292eefa55)

* test(matrix): avoid racy inbound dedupe TTL

(cherry picked from commit 8ae3662b1c7ad32fb79039ff3465e0b1c835fe4e)

* fix(canvas): validate CLI numeric options

Validate Canvas CLI numeric arguments before node invocation.

- Reject malformed `--invoke-timeout` values through the shared Canvas invoke path before resolving a node.
- Keep snapshot `--quality` bounded to the existing Canvas tool schema range of 0..1.
- Add focused CLI regressions for timeout validation, quality bounds, and accepted boundary values.

Verification:
- `node scripts/run-vitest.mjs extensions/canvas/src/cli.test.ts --maxWorkers=1`
- `.agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main ...`
- AWS Crabbox `cbx_b7838c58daba`, run `run_bbb58ca536f4`: `check:changed`
- Exact PR head `a970ce594ea6e7284ace519352fc258b1b81cb80`: GitHub checks green

* fix: reflow composer beside workspace rail

Reflow the Control UI chat composer into the main chat column when the Workspace Files rail is expanded, so the composer stays beside the rail instead of extending underneath it.

Prepared head SHA: 7108d88cdad8c5e1c23d3f0e8b8965d723cea99d
Co-authored-by: Colin Johnson <[email protected]>
Co-authored-by: shakkernerd <[email protected]>
Reviewed-by: @shakkernerd

* fix(configure): mask gateway token prompts

Mask gateway token/password prompts while preserving blank-token generation. Verified with focused configure wizard tests and clean CI.

* fix(ports): avoid stale cleanup for non-gateway SSH listeners

Limit SSH tunnel classification to actual queried-port forwards and keep SSH-like non-gateway listeners out of stale gateway cleanup. Verified with focused port/restart tests and clean CI.

* fix(tavily): keep web search contract executable

Keep the Tavily public artifact lightweight while lazily executing through the provider runtime. Verified with focused Tavily/provider artifact tests and clean CI.

* fix(daemon): keep duplicate Windows gateway tasks visible

Normalize Windows schtasks default gateway names without hiding similarly prefixed duplicate tasks. Verified with focused daemon tests, type proof, autoreview, and clean CI.

* fix(cron): isolate transient auth cooldowns

Keep cron-local transient auth failures from polluting shared cooldowns while preserving real auth/billing/rate-limit propagation. Verified with focused auth/cron tests, type proof, autoreview, and clean CI.

* fix(heartbeat): route outbound mirror to isolated session key (#92807)

* fix(heartbeat): route outbound mirror to isolated session key

Co-authored-by: Merkava <[email protected]>

* fix(clownfish): address review for ghcrawl-143801-autonomous-smoke (1)

Co-authored-by: Merkava <[email protected]>

* fix(clownfish): address review for ghcrawl-143801-autonomous-smoke (1)

Co-authored-by: Merkava <[email protected]>

---------

Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com>
Co-authored-by: Merkava <[email protected]>

* test(gateway): preserve live Codex api-key auth

(cherry picked from commit 4aa50732f607d84e23c4e7d3ac8e77292c8c774e)

* fix(memory): surface skipped short-term recall hits (#92745)

Record diagnostic events when memory_search returns durable memory hits that are intentionally excluded from short-term promotion, so users can distinguish eligibility decisions from recall tracking failures.

* fix(gateway): forward image-only input on /v1/responses (parity with chat completions) (#92488)

* fix(gateway): accept image-only input on /v1/responses

The OpenResponses endpoint rejected requests whose `input` contained only
an `input_image` (no `input_text`) with `400 Missing user message in
input.`, even though the image was parsed and collected into `images`.
The guard only checked `prompt.message` and ignored `images`, unlike the
equivalent /v1/chat/completions guard which uses
`!prompt.message && images.length === 0`.

Align the OpenResponses guard with Chat Completions so image-only turns
are forwarded to the agent. Empty input (no text and no image) still
returns 400.

Adds regression tests: image-only base64 input -> 200 with image reaching
the agent, and empty content -> 400.

Co-authored-by: Cursor <[email protected]>

* fix(gateway): pass image-only /v1/responses turns to the agent

The one-line guard alone was insufficient: even after letting image-only
input past the `Missing user message` check, the downstream agent command
(`prepareAgentCommandExecution`) throws `Message (--message) is required`
for an empty message, so image-only `/v1/responses` returned 500.

Mirror the /v1/chat/completions prompt builder: substitute the shared
IMAGE_ONLY_USER_MESSAGE placeholder for the active image-only user turn so
the turn is not dropped and the real image is still attached via `images`.
Promote the placeholder constant to the shared gateway agent-prompt module
so both endpoints stay in sync, and revert the responses guard back to the
original `!prompt.message` check (responses images are not scoped to the
active turn, so the placeholder is the correct, single source of truth).

Co-authored-by: Cursor <[email protected]>

* chore: retrigger CI (flaky startup-core test timeout, unrelated to change)

Co-authored-by: Cursor <[email protected]>

---------

Co-authored-by: songwendong <[email protected]>
Co-authored-by: Cursor <[email protected]>

* fix(status): avoid cumulative usage for context percent (#92604)

* fix(status): avoid cumulative usage for context percent

* fix(status): preserve legacy context totals

* fix: reject unvalidated voice media streams

Reject voice media stream start frames when no acceptance validator is configured, preventing fail-open STT/TTS session creation. Verified locally, with autoreview, in a remote Linux dev box, and by green CI.

* test(gateway): wait for trajectory export guidance

(cherry picked from commit 4675423788a0ef48b0c46ed31b199762e1576c81)

* fix(telegram): acknowledge callbacks before sequentialize

Fixes #42156.

Answer Telegram callback queries before per-chat/topic sequentialize can queue the handler behind an active turn, and carry the in-flight answer promise on the grammY context so the normal handler reuses it instead of double-answering.

Proof:
- node scripts/run-vitest.mjs extensions/telegram/src/bot.create-telegram-bot.test.ts -- -t "answers callback queries before same-chat sequentialize delays handlers|sequentializes updates by chat and thread|routes callback_query payloads as messages"
- node scripts/run-vitest.mjs extensions/telegram/src/bot.test.ts extensions/telegram/src/bot-handlers.runtime.test.ts
- node_modules/.bin/oxfmt --check extensions/telegram/src/bot-core.ts extensions/telegram/src/bot-handlers.runtime.ts extensions/telegram/src/callback-query-answer-state.ts extensions/telegram/src/bot.create-telegram-bot.test.ts
- git diff --check origin/main...HEAD
- .agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main
- Azure Crabbox cbx_cba20c462ad5 / silver-barnacle: OPENCLAW_TESTBOX=1 node scripts/crabbox-wrapper.mjs run --provider azure --class Standard_D4ads_v6 --idle-timeout 90m --ttl 240m --timing-json -- env OPENCLAW_CHECK_CHANGED_REMOTE_CHILD=1 OPENCLAW_CHANGED_LANES_RAW_SYNC=1 corepack pnpm check:changed

Proof gap: live Telegram Desktop/burner-account proof was not run because openclaw-telegram-user-crabbox-proof is not installed in this shell.

* fix(nodes): surface pending reapproval diagnostics (#92547)

* fix(nodes): surface pending reapproval diagnostics

* fix(nodes): harden reapproval diagnostics

* fix(nodes): scope pending diagnostics

* fix(nodes): request pairing diagnostics in cli

* fix(nodes): reuse stored auth for diagnostics

* fix(nodes): preserve selected diagnostics credentials

* fix(nodes): prefer approved diagnostics auth

* fix(nodes): narrow diagnostics fallbacks

* fix(nodes): recover from stale diagnostics auth

* fix(gateway): preserve connect error narrowing

* fix(nodes): isolate privileged diagnostics auth

* fix(nodes): constrain privileged diagnostics auth

* fix(nodes): close diagnostics review gaps

* fix(nodes): guard reapproval cleanup races

* fix(nodes): defer stale pairing cleanup

* fix(nodes): preserve reapproval on hello failure

* test(nodes): await post-handshake reapproval cleanup

* test(nodes): avoid unbound websocket send capture

* fix(nodes): allow local auth-none diagnostics

* fix(nodes): preserve overlapping reapproval

* fix(nodes): preserve pending node metadata

* fix(nodes): keep connection age with status

* fix(nodes): preserve reapproval during reconnect races

* fix(nodes): serialize reapproval cleanup

* fix(nodes): bound reapproval reconnect races

* test(nodes): satisfy cleanup claim lint

---------

Co-authored-by: Peter Steinberger <[email protected]>

* fix(memory): keep skipped recall diagnostics opt-in

Follow-up to #92745 after maintainer autoreview found that the skipped recall event widened the shipped MemoryHostEvent union and changed limited legacy reads.

Keep readMemoryHostEvents() source-compatible by filtering diagnostic records before applying limits, and expose skipped recall diagnostics through the opt-in MemoryHostEventRecord/readMemoryHostEventRecords path.

Original skipped-recall behavior landed in #92745 by @mushuiyu886.

* fix(doctor): avoid false-positive legacy cron store warning when store was already migrated (fixes #92683) (#92690)

* fix(doctor): avoid false-positive legacy cron store warning when store was already migrated

When rawJobs.length > 0 and other issues exist (notifyCount, dreamingStaleCount)
but legacyStoreDetected is false (file already removed after migration), the doctor
unconditionally printed 'Legacy cron job storage detected at ...' — misleading users
into thinking the migration was incomplete.

Fix: conditionally use 'Cron store issues detected' heading when no legacy store file
exists, reserving 'Legacy cron job storage detected' for actual legacy store presence.

Fixes #92683

* test(doctor): add test for false-positive legacy cron store warning (#92683)

* fix(telegram): skip IPv4 fallback when user explicitly configures non-ipv4first dnsResultOrder (fixes #41671) (#92806)

* fix(telegram): skip IPv4 fallback when user configures non-ipv4first dnsResultOrder

When the user explicitly configures channels.telegram.network.dnsResultOrder
to a non-ipv4first value (e.g. verbatim), the sticky IPv4 fallback dispatcher
should not be armed. Forcing autoSelectFamily=false + dnsResultOrder=ipv4first
overrides the user's explicit IPv6-friendly config, causing media downloads to
fail on hosts where IPv4 is broken but IPv6 works.

Fixes #41671

* fix(telegram): respect explicit DNS fallback policy

---------

Co-authored-by: Vincent Koc <[email protected]>

* test(gateway): capture trajectory export command events

(cherry picked from commit b656a510468279aacad51515123b960b56a3fa87)

* fix(macos): defer isOverflowing mutation to break SwiftUI render loop (fixes #43480) (#92778)

* fix(macos): defer isOverflowing mutation to break SwiftUI render loop

measuredHeight() mutated model.isOverflowing synchronously during a SwiftUI
view update cycle. The onChange(of: attributed) handler triggered
updateWindowFrame → targetFrame → measuredHeight, which set isOverflowing,
invalidating the view and re-triggering onChange — an infinite render loop
causing 100% CPU pinwheel.

Fix: defer the isOverflowing mutation via DispatchQueue.main.async with an
equality guard to prevent redundant updates. The frame calculation itself
remains synchronous so the window size is correct immediately.

Fixes #43480

* fix(macos): preserve latest overflow measurement

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(gateway): use resolveNonNegativeNumber for totalTokens to display 0 instead of ? (fixes #43009) (#92795)

* fix(gateway): use resolveNonNegativeNumber for totalTokens to display 0 instead of ?

resolvePositiveNumber requires value > 0, filtering out the valid
totalTokens = 0 case (new session, no usage yet). This caused the TUI
to display 'tokens ?/200k' instead of 'tokens 0/200k (0%)'.

Use resolveNonNegativeNumber (>= 0) for the final totalTokens value
used in session display. The needsTranscriptTotalTokens check at line
2041 still correctly uses resolvePositiveNumber to decide whether to
fetch transcript data.

Fixes #43009

* fix(gateway): preserve fresh zero-token sessions

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(gateway): preserve active runs during plugin finalization (#92746)

* fix(gateway): preserve active run during plugin finalization

* fix(ui): skip session.message history reload while gateway reports active run

* fix(ui): remove unused eslint-disable directive

* fix(ui): preserve active runs through finalization

---------

Co-authored-by: scotthuang <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>

* UI: localize Logs tab labels (#92820)

Repair #61080 by routing Logs tab user-facing labels through Control UI locale keys while keeping export filename suffixes stable.

Validation:
- pnpm ui:i18n:check
- pnpm check:changed
- ui/src/ui/views/logs.test.ts
- Codex /review
- GitHub PR checks

Source PR credit: continues @rubensfox20's work from https://github.com/openclaw/openclaw/pull/61080.

Co-authored-by: rubensfox20 <[email protected]>

* test(release): harden trajectory export live check

(cherry picked from commit b2d4cb7f868a7bd3abae1b775a0c26f32ec9a288)

* test(release): accept trajectory command session final

(cherry picked from commit 9458ffa7e8598608e582fd233fccb586ecc7b10b)

* fix(telegram): preserve command callbacks while prefixing generic callback data (#92825)

Fixes #54909.

Repair #54962 by preserving raw slash-command callbacks while routing generic callback data to agents as `callback_data: <value>`.

Validation:
- pnpm check:changed
- pnpm -s vitest run extensions/telegram/src/bot.create-telegram-bot.test.ts
- Codex /review
- Real behavior proof
- GitHub PR checks

Source PR credit: continues @hnshah's work from #54962 and preserves @timt80's report credit from #54909.

Co-authored-by: Hiten Shah <[email protected]>

* fix: refresh model context metadata safely

Cap configured session context overrides by the selected model's known context window, refresh provider/model metadata consistently, and preserve the fixed Anthropic 1M context contract.

Fixes #39857

Co-authored-by: Kros Dai <[email protected]>

* fix(copilot): strip replayed thinking blocks

Remove replayed thinking and redacted-thinking blocks from GitHub Copilot Claude history and final Anthropic payloads while preserving visible content, tool turns, and non-empty assistant structure.

Fixes #81520
Supersedes #87060 and #81534

Co-authored-by: Gio Della-Libera <[email protected]>

* feat(browser): extend --labels overlay to full-page and element captures (#92834)

Summary:
- The replacement PR extends Browser plugin labeled screenshots to honor Playwright full-page/ref/element scope, returns annotation bounding boxes, and updates docs, tests, and skill guidance.
- PR surface: Source +415, Tests +550, Docs +24. Total +989 across 12 files.
- Reproducibility: yes. Current main source shows the labeled Playwright helper ignores fullPage/ref/element and omits annotations, and the source PR supplies live before/after commands for the Browser plugin path.

Automerge notes:
- PR branch already contained follow-up commit before automerge: docs(browser): correct raw-CDP labels caveat in automation skill
- PR branch already contained follow-up commit before automerge: fix(browser): preserve labelsSkipped semantics for off-viewport refs
- PR branch already contained follow-up commit before automerge: docs(browser): scope labels docs by driver
- PR branch already contained follow-up commit before automerge: docs(browser): fix labels annotation indent and document scope fix
- PR branch already contained follow-up commit before automerge: docs(browser): indent annotations box schema under --labels bullet
- PR branch already contained follow-up commit before automerge: docs(browser): indent labels annotation schema

Validation:
- ClawSweeper review passed for head 70aca6c5065ae68bbf1037949e28045f479c0355.
- Required merge gates passed before the squash merge.

Prepared head SHA: 70aca6c5065ae68bbf1037949e28045f479c0355
Review: https://github.com/openclaw/openclaw/pull/92834#issuecomment-4700431344

Co-authored-by: FMLS <[email protected]>
Co-authored-by: Cursor <[email protected]>
Co-authored-by: Mason Huang <[email protected]>
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: clawsweeper[bot] <274271284+clawsweeper[bot]@users.noreply.github.com>
Approved-by: hxy91819
Co-authored-by: hxy91819 <[email protected]>

* fix(discord): raise thread title timeout and tokens

Source PR: https://github.com/openclaw/openclaw/pull/64734

Co-authored-by: Hana Chang <[email protected]>

* fix(whatsapp): require durable auth before login success (#92095)

* fix(stale): exempt ClawSweeper actionable labels from stale lifecycle (#92801)

Add clawsweeper:queueable-fix, clawsweeper:source-repro, and
clawsweeper:fix-shape-clear to exempt-issue-labels in all 4 stale
workflow steps and the backfill-closures script's issueExemptLabels
set.

Previously, issues classified by ClawSweeper as actionable fix
candidates could still be marked stale and auto-closed, creating
a conflict between the two automation systems (e.g. #78640,
#81078, #81122 had both 'stale' and 'clawsweeper:queueable-fix').

Fixes #89564

* fix(status): render sub-1000 token counts as plain integers (#89736)

* fix(status): render sub-1000 token counts as plain integers

formatKTokens always divided by 1000 and appended "k", so token counts
below 1000 rendered as misleading fractional k in `openclaw status`
output (e.g. 999 rounded up across the boundary to "1.0k", 420 -> "0.4k",
a 300-token cache write -> "write 0.3k").

Guard value < 1000 to render the plain rounded integer, matching the
canonical formatTokenCount convention (src/utils/usage-format.ts). The
>=1000 "k" behavior is unchanged. Adds focused regression tests for the
0/420/999/1000/12000 boundary and small-session/small-cache status lines.

Fixes #89735

* fix(status): reuse canonical token formatter

* refactor(status): extract lightweight token formatter

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(agents): catch malformed image blocks in sanitizeContentBlocksImages (#92792)

* fix(agents): catch malformed image blocks in sanitizeContentBlocksImages

* fix(agents): sanitize malformed-only image results

---------

Co-authored-by: Vincent Koc <[email protected]>

* ci: gate stable releases on Windows companion assets (#92555)

* ci: gate stable releases on Windows companion assets

* fix(release): reject malformed Windows checksum manifests

* fix(release): make Windows recovery fail closed

* fix(release): tighten Windows asset identity checks

* fix(release): validate prepared candidate tarballs

---------

Co-authored-by: Peter Steinberger <[email protected]>

* fix(agents): add usage guidance to sessions_spawn tool description (fixes #91814) (#91824)

* fix(agents): add usage guidance to sessions_spawn tool description (fixes #91814)

* fix(agents): tighten sessions spawn guidance

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(feishu): await HTTP server shutdown during monitor cleanup

Source PR: https://github.com/openclaw/openclaw/pull/48588

Co-authored-by: alex sagit <[email protected]>

* feat: add tool search directory mode

Add an experimental directory mode that keeps large authorized tool schemas deferred while exposing bounded discovery, exact deferred hydration, and normal OpenClaw policy/hook execution. Client tools remain directly visible; ambiguous hidden names fail closed.

* fix(qqbot): surface failed media sends (#92823)

* fix(qqbot): surface media send failures

* test(qqbot): cover text send failures

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(tailscale): preserve parse errors for malformed JSON

Accept the fail-closed behavior for malformed `tailscale funnel status --json`: noisy valid JSON should parse, but malformed status output should not silently become “route absent”.

Source PR: https://github.com/openclaw/openclaw/pull/63321

Co-authored-by: Francisco Maestre Torreblanca <[email protected]>

* Add diagnostics OTEL capability contract tests (#92045)

* fix(acp): accept MCP date protocolVersion in ACP server

Repairs https://github.com/openclaw/openclaw/pull/56176.
Fixes https://github.com/openclaw/openclaw/issues/56102.

Co-authored-by: Saurabh Mishra <[email protected]>

* fix(hooks): reject slug-generator error payloads

Repairs https://github.com/openclaw/openclaw/pull/64181.

Co-authored-by: Cypher <[email protected]>

* fix(ui): repair iOS Safari chat viewport handling

Repairs https://github.com/openclaw/openclaw/pull/63644.

Review proof: local structured autoreview on branch review/pr-92855 against origin/main exited clean with no accepted/actionable findings.

Co-authored-by: Xi Qi <[email protected]>

* fix(update): continue after package doctor warnings (#91586)

* fix(update): continue after package doctor warnings

* fix(update): type advisory step rendering

* fix(update): preserve advisory doctor step state

* fix(update): share advisory doctor state

* fix(update): keep timed-out doctor failures blocking

* fix(update): require explicit doctor advisory result

* fix(update): reject malformed doctor advisory results

* fix(update): bound doctor advisory diagnostics

* fix(update): keep doctor advisory restart-neutral

* fix(update): protect doctor advisory IPC

* fix(update): scope doctor advisories to converging updater

* fix(update): scope doctor advisories to deferred repairs

* fix(update): secure doctor advisory IPC

---------

Co-authored-by: Peter Steinberger <[email protected]>

* fix(feishu): target typing reaction on inbound message

Target Feishu Typing reactions at the inbound message id while preserving reply and thread routing to the topic root.

This keeps the fallback to replyToMessageId for flows without a separate inbound target, and adds regression coverage for topic/replyInThread behavior and synthetic Feishu turn sources.

Based on and credits #67783 by @huiwen01. This replacement branch carries the same user-visible fix forward because #67783 is dirty against main and earlier automation could not update the fork branch with available permissions. This intentionally does not reuse or expand #73958; root_id routing remains separate.

Validation:
- pnpm check:changed
- pnpm -s vitest run extensions/feishu/src/bot.test.ts extensions/feishu/src/reply-dispatcher.test.ts extensions/feishu/src/monitor.reaction.test.ts
- autoreview clean: no accepted/actionable findings
- GitHub checks: 127 pass, 0 fail, 0 pending

Co-authored-by: huiwen01 <[email protected]>

* fix(lobster): surface workflow path errors

Surface missing bare Lobster workflow file paths instead of silently falling through to inline pipeline parsing.

The runner now treats plain workflow file inputs as file paths, keeps inline commands with file-like arguments as pipelines, and preserves existing workflow file paths that contain spaces. Regression coverage covers missing bare workflow paths, inline false positives, and spaced workflow filenames.

Fixes #68101.

Based on and credits #68106 by @vvitovec. This replacement branch carries the focused fix forward because #68106 is dirty against current main and could not be repaired on the fork branch with available bot permissions.

Validation:
- node scripts/run-vitest.mjs extensions/lobster/src/lobster-runner.test.ts
- autoreview clean: no accepted/actionable findings after the spaced-path fix
- GitHub checks: 127 pass, 0 fail, 0 pending

Co-authored-by: Viktor Vítovec <[email protected]>

* fix(cli): clarify --tz help text for offset-less --at values

Clarifies cron edit --at help after maintainer rebase and preserves the Gateway-host timezone wording for cron --tz help.

Validation:
- git diff --check
- node scripts/run-vitest.mjs src/cli/cron-cli.test.ts
- local Codex autoreview clean, no actionable findings

Co-authored-by: rrrrrredy <[email protected]>

* fix(agents): preserve valid reasoning replay metadata (#90682)

Preserve validated provider reasoning ciphertext, signatures, and replay identifiers through transcript redaction without exempting malformed, nested, or credential-shaped values.

Fixes #90093.

Co-authored-by: Elfka Toruviel <[email protected]>

* fix(anthropic): omit stale thinking from disabled requests (#92373)

Preserve signed thinking for active Anthropic tool-result continuation while omitting native thinking from completed history when the new request disables or omits thinking. Applies the same replay rule to the legacy SDK provider and managed Anthropic transport. Fixes #92360.

* docs(crabbox): warm Testbox in parallel

* fix(anthropic): merge consecutive assistant replay turns (#87346)

Merge adjacent Anthropic assistant turns before dangling tool-use validation so signed tool calls remain immediately paired with their tool results. Preserve contributor credit. Fixes #87329.

* fix(anthropic): quarantine invalid direct tool schemas (#92896)

Quarantine unreadable and structurally invalid direct/custom Anthropic tool schemas in both canonical request builders while preserving healthy siblings, forced-choice semantics, OAuth name mapping, and official OpenAI behavior.

Supersedes #89418, #89221, #90228, #89622, #89229, and #90278.

Co-authored-by: Vincent Koc <[email protected]>

* fix(active-memory): preserve verbose recall summaries (#90739)

* fix(active-memory): preserve verbose recall summaries

* fix(active-memory): require recall evidence for recovery

* fix(active-memory): recognize capped recall results

* fix(active-memory): preserve grounded recall state

* refactor(active-memory): limit recovery to completed recalls

* fix(active-memory): ground terminal recall recovery

* fix(active-memory): limit unavailable recovery to completed replies

* fix(active-memory): harden recall evidence recovery

* fix(active-memory): preserve timeout recovery contract

* fix(active-memory): preserve capped failure evidence

* fix(active-memory): reject content-only recall failures

* fix(active-memory): ground completed recall summaries

* fix(active-memory): separate hook and recall timeouts

* fix(active-memory): classify custom tool failures

* fix(active-memory): preserve harness tool evidence

* fix(active-memory): reject explicit empty results

* fix(active-memory): wait for fallback recall evidence

* fix(codex): report dynamic tool results

* fix(active-memory): separate preflight recall deadline

* fix(active-memory): normalize recall tool names

* fix(agents): classify unavailable approvals

* docs(active-memory): clarify hook timeout phases

* test(active-memory): stabilize timeout abort proof

* fix(agents): preserve successful cancellation outcomes

---------

Co-authored-by: Peter Steinberger <[email protected]>

* fix(gateway): deliver command block replies in webchat

(cherry picked from commit 33390ee88f5c8325efc60d1793c532a9489a5a72)

* docs(changelog): refresh 2026.6.8 notes

(cherry picked from commit 0b5cb00980c68a39b8fb1d77f6c04e9733bcbb09)

* fix(gateway): preserve slash command media replies

* Simplify QA scorecard mapping shape (#92558)

* test(qa): simplify scorecard mapping shape

* test(qa): use typed scorecard evidence refs

* test(qa): map scorecard categories by coverage id

* feat: align qa coverage with taxonomy features

* refactor: keep qa coverage ids canonical

* refactor: minimize qa coverage id churn

* test: align qa coverage id assertions

* test: update qa evidence coverage expectations

* refactor qa taxonomy coverage ids

* style qa taxonomy coverage ids

* test qa coverage lint fix

* test qa coverage type fix

* fix(memory-wiki): stop flagging raw source pages as malformed (#92876)

* fix(memory-wiki): stop flagging raw source pages as malformed

* fix(clownfish): address review for gitcrawl-11828-autonomous-smoke (1)

* fix(memory-wiki): skip freshness lint for raw source pages

* fix(memory-wiki): keep raw source ids linted

---------

Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com>
Co-authored-by: Vincent Koc <[email protected]>

* fix(providers): quarantine unreadable Anthropic payload tools (#92908)

Quarantine unreadable and invalid Anthropic-family tool schemas before OpenAI-compatible serialization, keep tool choices aligned with surviving tools, and preserve provider metadata.

Co-authored-by: Vincent Koc <[email protected]>

* fix(memory): preserve reindex rollback recovery (#92881)

* fix(memory): preserve reindex rollback recovery

Co-authored-by: Shiwen Han <[email protected]>

* fix(clownfish): address review for gitcrawl-5644-autonomous-smoke (1)

Co-authored-by: Shiwen Han <[email protected]>

* test: update memory reindex test routing expectation

* chore(memory): remove release changelog entry

* fix(memory): complete reindex retry recovery

---------

Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com>
Co-authored-by: Shiwen Han <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>

* test(agents): skip anthropic billing drift in live tool checks

* test(qa): align tool coverage CLI expectation

* test(gateway): keep trajectory export live proof correlated

* fix(openai): quarantine unreadable tool schemas (#92921)

Snapshot unreadable OpenAI tool descriptors and schemas before payload construction, preserve healthy siblings, and reconcile hard tool choices with the surviving function inventory.

Adds live-tested Responses and Chat Completions coverage, including allowed_tools, while keeping Anthropic regressions green.

Related: #89413, #89013, #89016, #89378, #89543, #90200, #90283, #90286, #90397

Co-authored-by: Vincent Koc <[email protected]>

* Fold Telegram RTT sampling into live QA evidence (#92550)

* refactor(qa): fold telegram rtt into live evidence

* test: default package telegram rtt samples

* refactor(qa-lab): fold telegram rtt into live evidence

* fix(qa-lab): keep package telegram rtt optional for focused runs

* fix(qa-lab): avoid stale rtt evidence on failed samples

* fix(qa-lab): pass telegram live env into credential leasing

* fix(qa-lab): update telegram canary remediation artifacts

* docs(qa): remove stale telegram observed artifact guidance

* fix(qa-lab): clarify telegram empty-reply remediation

* fix(qa-lab): honor telegram rtt timeout

* ci(qa): drop stale telegram capture env

* refactor: align telegram evidence coverage fields

* fix: ignore stale telegram observed artifacts

* fix: preserve telegram rtt coverage mapping

* fix: omit unused telegram rtt catch binding

* docs: document telegram rtt check selector

* test(gateway): allow trajectory export instruction latency

* fix(media): route OAuth image defaults through Codex (#92824)

Route implicit OpenAI image understanding through the Codex app-server for eligible OpenAI OAuth profiles. Preserve scoped and persisted credential ownership plus the rotating-token refresh lifecycle for isolated clients.

Fixes #87168

Thanks @bek91.

* fix(cli): avoid false downgrade prompt for latest tag

Keep unresolved latest package targets moving while preserving downgrade confirmation for unresolved non-latest dist-tags.

Validation:

- node scripts/run-vitest.mjs src/cli/update-cli.test.ts

- node scripts/run-tsgo.mjs -p test/tsconfig/tsconfig.test.src.json --incremental --tsBuildInfoFile .artifacts/tsgo-cache/test-src-pr92911.tsbuildinfo

- git diff --check origin/main...HEAD && git diff --check

Direct-landed from #92911 because the source branch has maintainer edits disabled and ClawSweeper requested changelog removal plus behavior proof.

Co-authored-by: Andy Wu <[email protected]>

Co-authored-by: Vincent Koc <[email protected]>

* fix(openai): guard post-hook tool payloads (#92928)

Guard OpenAI post-hook tool inspection and code-mode filtering against unreadable accessors and asynchronous payload replacements. Preserve valid official `exec` and `wait` function tools across Responses and Chat Completions paths.

Supersedes #89703.

Co-authored-by: Vincent Koc <[email protected]>

* fix(sessions): restore reset archive fallback reads

Fall back to valid reset transcript archives when active async session transcripts are missing, while keeping active transcript priority and choosing the newest valid archive across roots.

Validation:

- node scripts/run-vitest.mjs src/gateway/session-utils.fs.test.ts src/gateway/sessions-history-http.test.ts src/gateway/sessions-history-http.revocation.test.ts src/gateway/session-history-state.test.ts src/gateway/server.chat.gateway-server-chat-b.test.ts src/gateway/managed-image-attachments.test.ts src/agents/tools/embedded-gateway-stub.test.ts src/tui/embedded-backend.test.ts

- node scripts/run-tsgo.mjs -p test/tsconfig/tsconfig.test.src.json --incremental --tsBuildInfoFile .artifacts/tsgo-cache/test-src-pr92879.tsbuildinfo

- git diff --check origin/main...HEAD && git diff --check

- autoreview --mode branch --base origin/main: clean

Direct-landed from #92879 because the source branch has maintainer edits disabled and the landed diff needed maintainer repair before merge.

Co-authored-by: Masato Hoshino <[email protected]>

Co-authored-by: Hu Yitao <[email protected]>

Co-authored-by: Vincent Koc <[email protected]>

* fix(feishu): re-resolve route when dynamic agent binding already exists in runtime config (fixes #42837) (#92814)

* fix(feishu): re-resolve route when dynamic agent binding already exists in runtime config

When dynamicAgentCreation is enabled and a binding was previously written
to the config file (e.g. from a prior message), the in-memory cfg may be
stale and not contain the binding. Previously, maybeCreateDynamicAgent
returned { created: false, updatedCfg: cfg } with the stale cfg, and
bot.ts only re-resolved the route when created === true. This caused
subsequent messages to still route to agent:main.

Fix: check runtime.config.current() for the binding when it is missing
from the in-memory cfg. When found, return the runtime's current config
so the caller can re-resolve the route with up-to-date bindings.

Fixes #42837

* fix(feishu): serialize dynamic agent config updates

* fix(feishu): route with refreshed runtime config

* fix(feishu): use current dynamic-agent policy

* fix(feishu): reauthorize refreshed dynamic routes

* fix(feishu): authorize dynamic agent mutations

* fix(feishu): complete account-scoped dynamic routing

* fix(feishu): revalidate current direct routes

* fix(feishu): isolate named-account dynamic agents

* fix(feishu): bound named dynamic agent ids

* docs(feishu): explain legacy dynamic agent cap

* test(feishu): fix dynamic routing check types

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(release): harden beta validation gates

(cherry picked from commit 91eeda0d708c2d8dac7c09c259b7cf390193f83f)

* test(release): unblock beta validation checks

* fix: restart gateway after isolated cron setup timeout

Restart the gateway after isolated cron setup timeouts and harden stale cron-task finalization around restart/reload boundaries.

Verification: focused cron/tasks/CLI regression suites, gateway filesystem/session regression suite, test typecheck, core lint shards, git diff --check, autoreview, Blacksmith Testbox changed gate tbx_01kv2srgbex71w9ce5rwv2wtr4, and clean GitHub PR checks on 13d06b5d6f9be057510942314b133316aff0d7cc.

* fix(openai): omit gpt-5.5 tool reasoning effort (#90574)

Fix GPT-5.5 Chat Completions tool requests by omitting the incompatible reasoning effort only on verified OpenAI and Azure routes. Preserve no-tool requests and nonblank custom OpenAI-compatible providers; add official regional endpoint metadata plus OpenAI and Anthropic live regression proof.

Co-authored-by: Thomas Krohnfuß <[email protected]>

* test(gateway): isolate trajectory export live seed turn

* test(installer): stabilize npm prefix probe test

* fix(openai): recover invalid reasoning signatures (#92941)

* test(gateway): authorize trajectory export live command

* fix(agents): clamp subagent spawn thinking overrides

Fixes #92412.

Subagent spawns that request an unsupported explicit thinking level now clamp through the existing provider/model thinking fallback instead of hard-failing after the orchestrator has already received an accepted ack. The exception is limited to trusted subagent spawn runs by requiring both the subagent lane and a subagent-shaped session key, so interactive and non-subagent explicit `--thinking` validation still fails loudly.

Verification:
- `node scripts/run-vitest.mjs src/agents/agent-command.live-model-switch.test.ts --maxWorkers=1`
- `.agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main`
- Testbox-through-Crabbox `tbx_01kv2wt0nqavsmnvzzzy2antrc`: `OPENCLAW_CHECK_CHANGED_REMOTE_CHILD=1 OPENCLAW_CHANGED_LANES_RAW_SYNC=1 corepack pnpm check:changed`
- GitHub PR checks clean on `c71186863337d9dfb9a18e5349ebef634a7d5ccd`

* test(openai): extend live STT fixture timeout

* fix(subagents): preserve config-selected child model overrides

* fix(subagents): handle configured bare model provenance

* fix(gateway): degrade config watcher to polling

Fixes #92851.

When native filesystem watching exhausts its retry budget, the gateway config reloader now falls back to polling instead of disabling hot reload for the rest of the process. The watcher state tracks the effective Chokidar polling mode, including CHOKIDAR_USEPOLLING overrides, so forced polling avoids a redundant native phase and forced native mode reports an accurate native-mode disable.

Verification:
- node scripts/run-vitest.mjs src/gateway/config-reload.test.ts --maxWorkers=1
- .agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main
- Testbox-through-Crabbox tbx_01kv2xvbqkv4dmvvvsswzm75hz: OPENCLAW_CHECK_CHANGED_REMOTE_CHILD=1 OPENCLAW_CHANGED_LANES_RAW_SYNC=1 corepack pnpm check:changed
- GitHub PR checks clean on c9762c5159a2ef75aa23d2af2a5435d0d8bf6b63

* fix(gateway): build row metadata for single session lists

Refs #92057.

Build the request-scoped row metadata context for every non-empty sessions.list result, including limit=1, so single-row lists use the shared subagent metadata read index instead of direct per-row registry snapshot lookups. This keeps the existing single-row store child-session candidate optimization intact while removing the single-row metadata-cache gap.

Verification:
- node scripts/run-vitest.mjs src/gateway/session-utils.single-row-cache.test.ts --maxWorkers=1
- .agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main
- Crabbox run_f89b56ffea83 / cbx_f1b1f5013225: OPENCLAW_CHECK_CHANGED_REMOTE_CHILD=1 OPENCLAW_CHANGED_LANES_RAW_SYNC=1 corepack pnpm check:changed
- GitHub PR checks clean on 1ba6619f2ee6491c40b49dd425597bb1b50638ca

* fix(memory-wiki): tolerate artifacts without agent ids

Fixes #92207.

Normalize public memory artifacts at the memory host boundary so providers that omit agentIds produce an empty list instead of throwing during artifact cloning, sorting, or memory-wiki bridge import. The bridge now renders those artifacts with unknown agents while downstream consumers still receive stable array-shaped metadata.

Verification:
- node scripts/run-vitest.mjs src/plugins/memory-state.test.ts extensions/memory-wiki/src/bridge.test.ts --maxWorkers=1
- .agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main
- Crabbox run_2a30de5d0a00 / cbx_3684cb0b7ea5: OPENCLAW_CHECK_CHANGED_REMOTE_CHILD=1 OPENCLAW_CHANGED_LANES_RAW_SYNC=1 corepack pnpm check:changed
- GitHub PR checks clean on 19678ed60f79778f407700dc35f675cde0357054

* test(gateway): unblock trajectory export live release gate

* fix(lmstudio): honor thinking off for binary reasoning models (#92002)

Scope disabled-thinking payload repair to LM Studio's lightweight provider stream hook. Preserve official OpenAI and Anthropic tool-calling paths.

Co-authored-by: David <[email protected]>

* fix(auto-reply): deliver channel message-tool final replies

Clarify that interim assistant text remains visible under message_tool_only delivery while the final answer must use the message tool, and forward progress for channel message-tool turns once the message tool has delivered the final reply.

Co-authored-by: Forge <[email protected]>

Co-authored-by: Chisel <[email protected]>

* fix(auto-reply): align message-tool progress gating

* test(auto-reply): assert allowed suppressed progress gating

* test(auto-reply): trim duplicate progress assertion

* fix(auto-reply): share message-tool delivery hints

* fix(plugin-sdk): expose delivery hints without utility imports

* fix(auto-reply): strip delivery hints from leading metadata

* fix(release): preserve child release check refs

* fix(agents): recover genericized Anthropic thinking errors (#92916)

Recover invalid Anthropic thinking replays when provider details survive genericization in SDK, failover, cause-chain, or terminal stream error fields.

The recovery matcher now uses cycle-safe named error carriers, avoids scanning assistant content and tool arguments, and retains one retry per provider call. Focused regressions cover each carrier, cyclic causes, terminal errors, and false-positive payload text.

Addresses the recovery path in #92201. The separate root cause that creates or persists invalid signatures remains open for investigation.

Co-authored-by: wlzeng0668001202 <[email protected]>

* refactor: add session accessor seam with gateway consumer (#90463)

Merged via squash.

Prepared head SHA: 58aa59eaf8059c31a2a70f859eeb96ee35e5beb2
Co-authored-by: jalehman <[email protected]>
Co-authored-by: jalehman <[email protected]>
Reviewed-by: @jalehman

* fix(webchat): route trajectory slash export before agent dispatch

* fix(ci): skip session accessor guard for older targets

* fix(agents): drop incomplete reasoning replay turns (#88656)

Drop assistant replay turns that ended at the token limit with only incomplete hidden reasoning while preserving visible text, tool calls, empty turns, and unknown content shapes. Apply the same classification to embedded replay and public transport transforms, with focused regression, live OpenAI/Anthropic provider proof, docs, autoreview, Testbox, and green CI.

Co-authored-by: clawstation <[email protected]>

* fix(gateway): async trajectory export approvals

* feat(webui): add session workspace rail (#92856)

* feat(webui): add session workspace rail

* fix(webui): address session workspace review

* fix(webui): secure session workspace previews

* fix(webui): handle nested session workspace paths

* fix(webui): update session file protocol models

* fix(webui): clear session rail lint

* docs(browser-control): document OPENCLAW_EAGER_BROWSER_CONTROL_SERVER requirement (#92845)

The standalone loopback HTTP API only starts when
OPENCLAW_EAGER_BROWSER_CONTROL_SERVER=1 is set in the gateway
service environment. Without it, browser control works via CLI and
agent tools but nothing listens on the loopback control port.

Fixes #92841

* fix: use passive periodic sqlite wal checkpoints

Use PASSIVE for periodic SQLite WAL checkpoints while keeping explicit checkpoint() and close() on TRUNCATE by default.

Preserve the old interval export as a compatibility alias, add the neutral interval export, and update the task storage docs contract.

Fixes #81715.

* fix(google): route Gemini CLI OAuth through the env proxy (#46184) (#92815)

* fix(mattermost): merge progress preview lines by identity (#91331)

* fix(mattermost): merge progress preview lines by identity

* fix(mattermost): preserve progress across assistant boundaries

* fix(mattermost): compose reasoning with progress previews

* fix(channels): reset reasoning progress at block boundaries

* fix(channels): align tool progress line identities

* fix(channels): keep tool call identity mapping injective

---------

Co-authored-by: leon <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>

* fix(tui): keep spinner active when toggling tools (#92909)

* fix(tui): keep spinner active when toggling tools

* fix(tui): preserve finishing status when toggling tools

---------

Co-authored-by: zengwen <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>

* fix(elevenlabs): use current TTS model ids (#92904)

* fix(elevenlabs): use current TTS model ids

* fix(elevenlabs): preserve served legacy model choices

---------

Co-authored-by: Ariel Bravy <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>

* fix(gateway): run export helpers through cli entry

* fix #86872: Subagent run reports success but fails to write output file (#92642)

* fix(codex): wait for native subagent completion

Codex native subagent lifecycle status is only a progress signal; the task row should not report success until the transcript or native completion result is available.

* fix(codex): preserve later native subagent failures

* test(codex): freeze authoritative subagent results

* fix(codex): preserve remote V1 completion fallback

---------

Co-authored-by: Vincent Koc <[email protected]>

* fix(gateway): track effective watcher polling mode

* test(gateway): allow optional trajectory metadata bundle

* test(gateway): expect trajectory session branch bundle

* refactor: route command session reads through seam (#89122)

Merged via squash.

Prepared head SHA: 73218cc7cd336c7389785960364aed4049a1affd
Co-authored-by: jalehman <[email protected]>
Co-authored-by: jalehman <[email protected]>
Reviewed-by: @jalehman

* fix(reply): deliver final reply when queued follow-up claims session; scope dedupe to routed thread (#90943)

* fix(reply): deliver final reply when queued follow-up claims session; scope dedupe to routed thread

Two core bugs caused composed replies to be silently dropped (no delivery,
no error) when a second message arrived in the same thread mid-run:

1. dispatch-from-config: ensureDispatchReplyOperation only kept the
   dispatch-owned operation authoritative while it had no result. Once
   runReplyAgent completed the operation to drain queued follow-ups, a
   second same-thread inbound could claim the session and the first final
   reply would try to re-acquire the lane instead of finishing delivery,
   deadlocking behind the queued work. Keep the dispatch-owned operation
   authoritative through final delivery.

2. reply-payloads-dedupe: messaging-tool reply dedupe compared only the
   channel target, not the routed thread, so a send in one thread could
   suppress a later reply in a different thread. Thread the routed thread
   id through buildReplyPayloads + follow-up delivery and only fall back to
   channel-only matching for providers without a thread-aware suppression
   matcher when neither side carries thread evidence.

Adds regression tests; existing Telegram topic-suppression behavior is
preserved by gating the thread guard to providers lacking a plugin matcher.

* fix(reply): preserve threaded message delivery evidence

* fix(reply): dedupe final payloads by delivery route

* fix(slack): preserve native send thread evidence

* fix(reply): preserve explicit reply thread evidence

* fix(reply): align explicit reply route dedupe

* fix(reply): preserve delivery lane through final dispatch

* fix(mattermost): preserve threaded tool send routes

* chore(plugin-sdk): refresh API baseline

* fix(reply): align final delivery route dedupe

* fix(reply): gate followups on final delivery

* fix(reply): keep send receipts private

* fix(reply): infer implicit message provider

* fix(reply): align routed threading policy

* fix(reply): preserve queued delivery context

* fix(reply): hydrate queued system event routes

* fix(reply): hydrate queued execution routes

* fix(reply): scope final delivery barriers

* fix(slack): preserve DM target aliases

* fix(reply): mirror resolved source thread routes

* fix(mattermost): retain delayed delivery barrier

* fix(codex): separate message routing from tool policy

* fix(reply): consume normalized Slack DM targets once

* fix(slack): remove stale target alias

* style(reply): satisfy changed lint gates

* fix(mattermost): preserve explicit reply targets

* test: align Slack reply branch checks

* fix(reply): persist overflow summaries to admitted session

---------

Co-authored-by: Peter Steinberger <[email protected]>

* fix(skills): keep managed prompt paths readable (#92894)

* fix(skills): keep managed prompt paths readable

* fix(skills): preserve only managed skill prompt paths

* chore: refresh proof gate

* fix(skills): refresh managed prompt snapshots

* fix(skills): preserve plugin prompt paths in state roots

* test(skills): use generic state-root path names

Signed-off-by: sallyom <[email protected]>

---------

Signed-off-by: sallyom <[email protected]>
Co-authored-by: sallyom <[email protected]>

* test(gateway): retry chat temp cleanup

* fix: refresh slash command routing config (#39617)

Use the active runtime snapshot for Discord and Slack native command routing and Discord autocomplete after config hot writes.

Fixes #39605

Co-authored-by: Peter Steinberger <[email protected]>

* fix(agents): retry thinking-only errored turns (#92191)

Retry replay-safe reasoning-only provider errors before assistant failover while preserving classified fallback and terminal-output ownership. Adds deterministic Anthropic gateway fault-injection coverage and focused regression tests.\n\nCo-authored-by: ai-hpc <[email protected]>

* fix(memory): clean stale reindex temp files (#92891)

* fix(memory): clean stale reindex temp files

* fix(memory): harden stale reindex cleanup

* fix(memory): serialize safe reindex cleanup

* fix(memory): satisfy reindex lock lint

---------

Co-authored-by: zengwen <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>

* feat(openrouter): surface Fusion panel config (#93005)

Signed-off-by: sallyom <[email protected]>

* fix(state): harden sqlite path caching

Resolve explicit relative SQLite DB paths before caching handles and centralize durable SQLite connection pragmas so busy_timeout is applied before WAL/NFS negotiation.

* fix(gateway): repair usage cost aggregation across agents (#93022)

* fix(gateway): aggregate usage co…
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

commands Command implementations docker Docker and sandbox tooling maintainer Maintainer-authored PR merge-risk: 🚨 automation 🚨 May affect CI, automerge, proof capture, label sync, or maintainer automation. merge-risk: 🚨 compatibility 🚨 May break existing users, config, migrations, defaults, or upgrade paths. merge-risk: 🚨 session-state 🚨 May lose, corrupt, stale, or mis-associate session, agent, or context state. P2 Normal backlog priority with limited blast radius. proof: sufficient ClawSweeper judged the real behavior proof convincing. rating: 🦞 diamond lobster Very strong PR readiness with only minor maintainer review expected. scripts Repository scripts size: L status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant