fix(channels): keep contributed message-tool schema properties optional#91137
Conversation
|
Codex review: needs maintainer review before merge. Reviewed June 7, 2026, 5:52 AM ET / 09:52 UTC. Summary PR surface: Source +5, Tests +42. Total +47 across 2 files. Reproducibility: yes. Source inspection shows current main passes markerless contributed schemas directly into Review metrics: 1 noteworthy metric.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Next step before merge
Security Review detailsBest possible solution: Land the centralized optional-contribution invariant once maintainers accept the plugin API semantics and checks pass; avoid making individual plugin optionality patches the permanent fix. Do we have a high-confidence way to reproduce the issue? Yes. Source inspection shows current main passes markerless contributed schemas directly into Is this the best way to solve the issue? Yes. Normalizing at AGENTS.md: found and applied where relevant. Codex review notes: model gpt-5.5, reasoning high; reviewed against 5d7e0b73a7b0. Label changesLabel changes:
Label justifications:
Evidence reviewedPR surface: Source +5, Tests +42. Total +47 across 2 files. View PR surface stats
What I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
e284d2d to
e22964f
Compare
vincentkoc
left a comment
There was a problem hiding this comment.
No blocking findings.
What changed: message-tool schema contributions now stay optional when merged into the channel action schema, including schemas whose TypeBox optional marker was lost through structured cloning. This is the right owner boundary: the merge helper owns the contributed schema normalization, while core action dispatch remains the only required parameter.
Best-fix verdict: best. Alternatives considered: requiring every plugin to mark optional parameters correctly would not cover serialized/manifest-derived schemas; making the message tool tolerate required contributed fields later would leave the exported schema misleading. Normalizing at mergeToolSchemaProperties fixes the compatibility seam directly.
Verification:
git diff --check origin/main...HEADnode_modules/.bin/oxfmt --check src/channels/plugins/message-action-discovery.ts src/channels/plugins/message-actions.test.tsnode scripts/run-vitest.mjs src/channels/plugins/message-actions.test.ts src/agents/tools/message-tool.test.ts— 110 tests passed locally.agents/skills/autoreview/scripts/autoreview --mode branch --base origin/main— clean, no accepted/actionable findings- Azure Crabbox
cbx_1078b198872e/ runrun_4e27a7f8a8e0:node scripts/run-vitest.mjs src/channels/plugins/message-actions.test.ts src/agents/tools/message-tool.test.ts— 110 tests passed; lease stopped - GitHub exact head
e22964f3209250adcca9118b25e0d7be7cf50d78: 132 successful, 0 failing; only one CodeQL Critical Quality aggregate row still pending when reviewed
…al (openclaw#91137) Co-authored-by: Lundog <[email protected]>
…26.6.8) (#1144) This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/openclaw/openclaw](https://openclaw.ai) ([source](https://github.com/openclaw/openclaw)) | patch | `2026.6.6` → `2026.6.8` | --- ### Release Notes <details> <summary>openclaw/openclaw (ghcr.io/openclaw/openclaw)</summary> ### [`v2026.6.8`](https://github.com/openclaw/openclaw/blob/HEAD/CHANGELOG.md#202668) [Compare Source](openclaw/openclaw@v2026.6.6...v2026.6.8) ##### Highlights - Telegram and WhatsApp channel delivery are richer and less brittle: Telegram can send structured rich text with tables, lists, expandable blockquotes, prompt-preserving CLI backend delivery, retired native draft migration, and safer rich-media boundaries, while WhatsApp now honors configured ACP bindings. ([#​92679](openclaw/openclaw#92679), [#​84082](openclaw/openclaw#84082), [#​89421](openclaw/openclaw#89421), [#​92513](openclaw/openclaw#92513)) Thanks [@​obviyus](https://github.com/obviyus), [@​jzakirov](https://github.com/jzakirov), [@​spacegeologist](https://github.com/spacegeologist), and [@​TurboTheTurtle](https://github.com/TurboTheTurtle). - Agent and Gateway recovery is sharper across account-scoped DM sends, generated media completions, restart shutdown aborts, yielded subagent pauses, yielded cron media, heartbeat dedupe, session identity prompts, and unknown OpenAI agent selector rejection. ([#​92788](openclaw/openclaw#92788), [#​91246](openclaw/openclaw#91246), [#​91357](openclaw/openclaw#91357), [#​92631](openclaw/openclaw#92631), [#​92146](openclaw/openclaw#92146), [#​91287](openclaw/openclaw#91287), [#​92468](openclaw/openclaw#92468), [#​92510](openclaw/openclaw#92510)) Thanks [@​yetval](https://github.com/yetval), [@​TurboTheTurtle](https://github.com/TurboTheTurtle), [@​ooiuuii](https://github.com/ooiuuii), [@​openperf](https://github.com/openperf), [@​IWhatsskill](https://github.com/IWhatsskill), [@​ZengWen-DT](https://github.com/ZengWen-DT), and [@​zhangguiping-xydt](https://github.com/zhangguiping-xydt). - Provider/model handling expands and tightens with GLM-5.2, Claude Haiku 4.5 catalog rows, OpenRouter and Google Vertex provider-prefix normalization, managed SecretRef auth, bounded model browse discovery, storeless OpenAI Responses replay gating, and Claude 4.5 Copilot tool-streaming safety. ([#​92796](openclaw/openclaw#92796), [#​90116](openclaw/openclaw#90116), [#​92627](openclaw/openclaw#92627), [#​91218](openclaw/openclaw#91218), [#​90686](openclaw/openclaw#90686), [#​92247](openclaw/openclaw#92247), [#​90706](openclaw/openclaw#90706), [#​75393](openclaw/openclaw#75393)) Thanks [@​arkyu2077](https://github.com/arkyu2077), [@​liuhao1024](https://github.com/liuhao1024), [@​bymle](https://github.com/bymle), [@​rohitjavvadi](https://github.com/rohitjavvadi), [@​samson910022](https://github.com/samson910022), [@​snowzlm](https://github.com/snowzlm), and [@​Kailigithub](https://github.com/Kailigithub). - `/usage` and reply payload hooks now have a native full footer renderer, default template, fixed-decimal formatting, credential-aware limits, better partial-count handling, and warnings for broken templates instead of silent bad output. ([#​92657](openclaw/openclaw#92657), [#​89835](openclaw/openclaw#89835), [#​89629](openclaw/openclaw#89629)) Thanks [@​Marvinthebored](https://github.com/Marvinthebored). - UI and mobile flows are steadier: workspace files can collapse and start collapsed, WebChat backscroll survives streaming, the sidebar session picker remains interactive above the desktop workbench, reset soft args survive UI dispatch, stale dashboard session parent lineage is preserved, and iOS reconnects stale foreground gateways. ([#​92779](openclaw/openclaw#92779), [#​92622](openclaw/openclaw#92622), [#​92705](openclaw/openclaw#92705), [#​91353](openclaw/openclaw#91353), [#​90658](openclaw/openclaw#90658), [#​92552](openclaw/openclaw#92552)) Thanks [@​shakkernerd](https://github.com/shakkernerd), [@​TurboTheTurtle](https://github.com/TurboTheTurtle), [@​NianJiuZst](https://github.com/NianJiuZst), [@​zhouhe-xydt](https://github.com/zhouhe-xydt), [@​luoyanglang](https://github.com/luoyanglang), and [@​Solvely-Colin](https://github.com/Solvely-Colin). - Memory, state, and diagnostics recover cleaner: oversized OpenAI embedding batches split before 431s, QMD memory search stays available in transient mode, SQLite avoids WAL on NFS state volumes, stuck-session recovery scheduling no longer resets warning backoff, and Infinity chunk limits stay genuinely unbounded. ([#​92650](openclaw/openclaw#92650), [#​92618](openclaw/openclaw#92618), [#​92639](openclaw/openclaw#92639), [#​91247](openclaw/openclaw#91247), [#​92752](openclaw/openclaw#92752), [#​92735](openclaw/openclaw#92735)) Thanks [@​mushuiyu886](https://github.com/mushuiyu886), [@​TurboTheTurtle](https://github.com/TurboTheTurtle), [@​849261680](https://github.com/849261680), [@​gnanam1990](https://github.com/gnanam1990), and [@​yhterrance](https://github.com/yhterrance). ##### Changes - Providers/models: add GLM-5.2 support and Claude Haiku 4.5 catalog entries while keeping provider-qualified model IDs normalized across OpenRouter and Google Vertex paths. ([#​92796](openclaw/openclaw#92796), [#​90116](openclaw/openclaw#90116), [#​92627](openclaw/openclaw#92627), [#​91218](openclaw/openclaw#91218)) Thanks [@​arkyu2077](https://github.com/arkyu2077), [@​liuhao1024](https://github.com/liuhao1024), and [@​bymle](https://github.com/bymle). - Channel plugins: ship Telegram rich-message delivery and WhatsApp ACP binding support, including rich prompt handoff to CLI backends and transport fixtures for richer drafts. ([#​92679](openclaw/openclaw#92679), [#​92513](openclaw/openclaw#92513)) Thanks [@​obviyus](https://github.com/obviyus) and [@​TurboTheTurtle](https://github.com/TurboTheTurtle). - Agent commands: support `/btw` in CLI-backed sessions and keep CLI usage-error exits classified as usage failures instead of successful runs. ([#​92669](openclaw/openclaw#92669), [#​92162](openclaw/openclaw#92162)) Thanks [@​joshavant](https://github.com/joshavant) and [@​Pandah97](https://github.com/Pandah97). - Usage hooks: add built-in full footer rendering, default footer templates, per-turn usage state, credential-aware limits, and fixed-decimal formatting for usage-bar templates. ([#​92657](openclaw/openclaw#92657), [#​89835](openclaw/openclaw#89835), [#​89629](openclaw/openclaw#89629)) Thanks [@​Marvinthebored](https://github.com/Marvinthebored). - Docs and operator guidance: document node config examples, clarify before-install hook scope, correct agent default concurrency comments, refresh ZAI provider docs, and update channel/group docs for current Telegram and WhatsApp behavior. ([#​92677](openclaw/openclaw#92677), [#​92766](openclaw/openclaw#92766), [#​92695](openclaw/openclaw#92695)) Thanks [@​liuhao1024](https://github.com/liuhao1024), [@​sallyom](https://github.com/sallyom), and [@​ArielSmoliar](https://github.com/ArielSmoliar). ##### Fixes - Onboarding/skills: show the Homebrew install recommendation only on macOS and Linux, so FreeBSD and other unsupported platforms no longer get a misleading brew prompt. Fixes [#​68893](openclaw/openclaw#68893); carries forward [#​68894](openclaw/openclaw#68894), [#​68910](openclaw/openclaw#68910), [#​68941](openclaw/openclaw#68941), [#​68943](openclaw/openclaw#68943), [#​69002](openclaw/openclaw#69002), and [#​69545](openclaw/openclaw#69545). Thanks [@​yurivict](https://github.com/yurivict), [@​Sanjays2402](https://github.com/Sanjays2402), [@​Eruditi](https://github.com/Eruditi), [@​JustInCache](https://github.com/JustInCache), [@​nnish16](https://github.com/nnish16), and [@​Mlightsnow](https://github.com/Mlightsnow). - Channels and delivery: preserve account-scoped DM channel send policy, rich Telegram final replies, rich Telegram tables and lists, Telegram thread-create CLI remapping, Slack outbound `message_sent` hooks, contributed message-tool schema optionality, same-channel generated media completions, and channel chunking around surrogate pairs and Infinity limits. ([#​92788](openclaw/openclaw#92788), [#​92679](openclaw/openclaw#92679), [#​89421](openclaw/openclaw#89421), [#​89943](openclaw/openclaw#89943), [#​91137](openclaw/openclaw#91137), [#​91246](openclaw/openclaw#91246), [#​92735](openclaw/openclaw#92735)) Thanks [@​yetval](https://github.com/yetval), [@​obviyus](https://github.com/obviyus), [@​spacegeologist](https://github.com/spacegeologist), [@​rishitamrakar](https://github.com/rishitamrakar), [@​lundog](https://github.com/lundog), [@​TurboTheTurtle](https://github.com/TurboTheTurtle), and [@​yhterrance](https://github.com/yhterrance). - Auto-reply/groups: keep ordinary group text replies on automatic final-reply delivery while allowing `message(action=send)` for files, images, and other attachments to the same group or topic. Carries forward [#​43276](openclaw/openclaw#43276); refs [#​48004](openclaw/openclaw#48004). Thanks [@​NayukiChiba](https://github.com/NayukiChiba) and [@​ShakaRover](https://github.com/ShakaRover). - Auto-reply/skills: preserve multiline payloads for `/skill` and direct skill slash commands while keeping command-head normalization for aliases, colon syntax, and bot mentions. Fixes [#​79155](openclaw/openclaw#79155); carries forward [#​81305](openclaw/openclaw#81305). Thanks [@​web3blind](https://github.com/web3blind). - iMessage: normalize leading NUL sent-message echo prefixes while preserving interior NUL bytes and the leading attributedBody marker handling from [#​73942](openclaw/openclaw#73942). Carries forward [#​63581](openclaw/openclaw#63581). Thanks [@​drvoss](https://github.com/drvoss). - Discord: give generated auto-thread titles a 60-second timeout and 4,096-token reasoning-model output budget, clamped to the selected model output cap. ([#​64734](openclaw/openclaw#64734)) Thanks [@​hanamizuki](https://github.com/hanamizuki). - Agent, cron, and Gateway runtime: mark active main sessions before restart shutdown aborts, pause yielded subagent runs whose terminal also signals abort, preserve yielded media completions, de-duplicate main-session heartbeat events, expose session identity in runtime prompts, reject unknown OpenAI agent selectors, keep generated media completions and slash-command block replies in WebChat, preserve fresh post-compaction usage while clearing stale usage snapshots, and require admin privileges for HTTP session/model override surfaces. ([#​91357](openclaw/openclaw#91357), [#​92631](openclaw/openclaw#92631), [#​92146](openclaw/openclaw#92146), [#​91287](openclaw/openclaw#91287), [#​92468](openclaw/openclaw#92468), [#​92510](openclaw/openclaw#92510), [#​91246](openclaw/openclaw#91246), [#​50795](openclaw/openclaw#50795), [#​50845](openclaw/openclaw#50845), [#​82874](openclaw/openclaw#82874), [#​92651](openclaw/openclaw#92651), [#​92646](openclaw/openclaw#92646)) Thanks [@​ooiuuii](https://github.com/ooiuuii), [@​openperf](https://github.com/openperf), [@​IWhatsskill](https://github.com/IWhatsskill), [@​ZengWen-DT](https://github.com/ZengWen-DT), [@​zhangguiping-xydt](https://github.com/zhangguiping-xydt), [@​Hollychou924](https://github.com/Hollychou924), [@​leno23](https://github.com/leno23), and [@​TurboTheTurtle](https://github.com/TurboTheTurtle). - Agents/exec: default empty-success background completion notices on only for real chat channels, preserving explicit opt-outs and keeping generic providers silent while carrying forward the narrow UX intent from [#​39726](openclaw/openclaw#39726) and [#​46926](openclaw/openclaw#46926). Thanks [@​Sapientropic](https://github.com/Sapientropic) and [@​wenkang-xie](https://github.com/wenkang-xie). - Providers and model replay: preserve storeless OpenAI Responses replay compatibility, avoid eager tool streaming for Claude 4.5 in Copilot, honor profile auth for SecretRef model entries, bound model browsing, strip provider prefixes where runtimes need bare IDs, and surface nested embedding fetch failures. ([#​90706](openclaw/openclaw#90706), [#​75393](openclaw/openclaw#75393), [#​90686](openclaw/openclaw#90686), [#​92247](openclaw/openclaw#92247), [#​92627](openclaw/openclaw#92627), [#​91218](openclaw/openclaw#91218), [#​92628](openclaw/openclaw#92628)) Thanks [@​snowzlm](https://github.com/snowzlm), [@​Kailigithub](https://github.com/Kailigithub), [@​rohitjavvadi](https://github.com/rohitjavvadi), [@​samson910022](https://github.com/samson910022), [@​liuhao1024](https://github.com/liuhao1024), [@​bymle](https://github.com/bymle), and [@​mushuiyu886](https://github.com/mushuiyu886). - Memory, state, diagnostics, and config: split header-too-large embedding batches, keep QMD memory search enabled in transient mode, avoid SQLite WAL on NFS volumes, preserve recovery scheduling outside stuck-session warning backoff, and keep shell environment fallbacks contained in config write tests. ([#​92650](openclaw/openclaw#92650), [#​92618](openclaw/openclaw#92618), [#​92639](openclaw/openclaw#92639), [#​91247](openclaw/openclaw#91247), [#​92752](openclaw/openclaw#92752)) Thanks [@​mushuiyu886](https://github.com/mushuiyu886), [@​TurboTheTurtle](https://github.com/TurboTheTurtle), [@​849261680](https://github.com/849261680), and [@​gnanam1990](https://github.com/gnanam1990). - Workspace setup state: store setup completion outside the workspace dot directory using an OpenClaw-named root file, migrate valid legacy state forward, and avoid clobbering generic root `workspace-state.json` files for TigerFS-style dot-path compatibility. This Clownfish replacement carries forward the focused [#​53326](openclaw/openclaw#53326) fix idea because the original branch was closed and uneditable. ([#​53326](openclaw/openclaw#53326), [#​44783](openclaw/openclaw#44783), [#​39446](openclaw/openclaw#39446)) Thanks [@​1qh](https://github.com/1qh). - UI/mobile/TUI: preserve dashboard session parent lineage, WebChat backscroll, reset soft command args, sidebar session picker interactivity, collapsed workspace files, resolved `/model` confirmation refs, and stale foreground iOS Gateway reconnects. ([#​90658](openclaw/openclaw#90658), [#​92622](openclaw/openclaw#92622), [#​91353](openclaw/openclaw#91353), [#​92705](openclaw/openclaw#92705), [#​92779](openclaw/openclaw#92779), [#​92773](openclaw/openclaw#92773), [#​92552](openclaw/openclaw#92552)) Thanks [@​luoyanglang](https://github.com/luoyanglang), [@​TurboTheTurtle](https://github.com/TurboTheTurtle), [@​zhouhe-xydt](https://github.com/zhouhe-xydt), [@​NianJiuZst](https://github.com/NianJiuZst), [@​shakkernerd](https://github.com/shakkernerd), [@​NarahariRaghava](https://github.com/NarahariRaghava), and [@​Solvely-Colin](https://github.com/Solvely-Colin). - TUI: reload the active session after external `/new` or `/reset` session-change events so stale transcript and stream state clear promptly. Fixes [#​38966](openclaw/openclaw#38966); carries forward [#​40472](openclaw/openclaw#40472). Thanks [@​yizhanzjz](https://github.com/yizhanzjz) and [@​wsyjh8](https://github.com/wsyjh8). - Control UI: preserve Gateway Access tokens during same-normalized WebSocket URL edits and reload gateway-scoped tokens when switching endpoints. Fixes [#​41545](openclaw/openclaw#41545); repairs [#​42001](openclaw/openclaw#42001) with additional source PRs [#​41546](openclaw/openclaw#41546), [#​41552](openclaw/openclaw#41552), and [#​41718](openclaw/openclaw#41718). Thanks [@​wsyjh8](https://github.com/wsyjh8), [@​llagy0020](https://github.com/llagy0020), [@​llagy007](https://github.com/llagy007), [@​pingfanfan](https://github.com/pingfanfan), and [@​zheliu2](https://github.com/zheliu2). - Gateway CLI: tolerate a single transient clean WebSocket close before `hello-ok` so one-shot RPC calls reconnect instead of failing noisily, while repeated clean pre-hello closes still surface. Carries forward source PRs [#​54475](openclaw/openclaw#54475) and [#​54774](openclaw/openclaw#54774); [#​85253](openclaw/openclaw#85253) covered adjacent connect assembly diagnostics. Thanks [@​ruanrrn](https://github.com/ruanrrn). - Gateway/Linux: keep root-owned systemd user service lifecycle commands on root's user manager when a stale `SUDO_USER` remains in a root shell with root's user bus environment. Fixes [#​81410](openclaw/openclaw#81410). Thanks [@​Ericksza](https://github.com/Ericksza) and [@​ChuckClose-tech](https://github.com/ChuckClose-tech). - Release and test reliability: extend slow Gateway/full-suite watchdogs, split local full-suite shards when throttled, stabilize plugin auth marker fixtures, avoid brittle provider-ref error text, and keep QA Lab bootstrap selection assertions aligned with flow-only scenarios. ([#​92652](openclaw/openclaw#92652)) - macOS Peekaboo bridge: update the embedded Peekaboo package to 3.5.2 and route bundled-skill CLI commands through the OpenClaw app bridge so they inherit its Screen Recording and Accessibility grants. - Agent routing: route subagent RPC callbacks addressed to an agent-shaped `--to` target to the correct session key instead of falling back to the main session, so WeChat (and other channel) session-key callbacks reach the intended subagent session. ([#​90231](openclaw/openclaw#90231)) Thanks [@​zhangguiping-xydt](https://github.com/zhangguiping-xydt). - Cron: preserve model, fallback, thinking, timeout, light-context, unsafe-content, and tool allow-list overrides on implicit text payloads by promoting them to agent turns, while explicit system events still prune those fields. Fixes [#​28905](openclaw/openclaw#28905); carries forward [#​64060](openclaw/openclaw#64060) and [#​73946](openclaw/openclaw#73946). Thanks [@​liaoandi](https://github.com/liaoandi). - QQBot delivery: keep markdown table chunks self-contained across message boundaries by preserving table state across block deliveries, flushing unfinished table-row fragments as plain text, and detecting short pipe-terminated rows by column count so split rows are not sent as malformed markdown. ([#​92428](openclaw/openclaw#92428)) Thanks [@​sliverp](https://github.com/sliverp). </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19--> Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/1144
…al (openclaw#91137) Co-authored-by: Lundog <[email protected]>
…al (openclaw#91137) Co-authored-by: Lundog <[email protected]>
Summary
describeMessageToolschema contributions are merged into themessagetool'sType.Object. typebox 1.1.39 marks optionality with a non-enumerable~optionalproperty, so any contribution that is plain JSON, or a TypeBox schema that crossed a clone/serialization boundary (spread,structuredClone, JSON round-trip), silently loses the marker andType.Objectpromotes it to required.buildMessageToolSchemaProps, so they can also shadow core optional props (message,media,caption, ...) and drag those intorequiredtoo. Result: everymessage(action="send", ...)call fails validation withmust have required properties ...across all channels. Symptoms vary by which channels are configured, which made the bug look non-deterministic.mergeToolSchemaPropertiesinsrc/channels/plugins/message-action-discovery.ts): wrap any non-optional contributed property withType.Optional. The message tool dispatches onaction;actionis the only required property by contract.buttons/componentsbugs (message() tool requires 'buttons' property for plain action=send — breaks all non-button sends #54385/[Bug]: message tool schema requires buttons parameter for all actions including react, delete, edit, poll #56496/message tool (action=send) requiresbuttonsfield even for plain text messages #57108, PR fix: make buttons schema optional in message tool #54418). fix: make buttons schema optional in message tool #54418 fixed one contributor; this fixes the seam so no contributor can regress it again.agent-tools-parameter-schema.ts(verified not the cause) and any per-plugin schema changes.mergeToolSchemaPropertiesand whether forcing optionality at this seam is the right ownership boundary (vs. per-plugin fixes).Linked context
Closes #67852
Related #56496, #57108, #54385, #54800 (prior instances of the same required-leak class; #54418 fixed the
buttonscontributor, this fixes the merge seam)Was this requested by a maintainer or owner? No — bug encountered in production on v2026.6.1.
Real behavior proof (required for external PRs)
messagetool failed schema validation on every call (must have required properties media, caption, asVoice, chatRef, ...) on OpenClaw 2026.6.1 across SimpleX, Signal, Discord, and Telegram.2e08f0f+ this commit cherry-picked), Node v22.22.3, macOS, channels: SimpleX, Signal.message(action="send", target=..., message=...)on each channel.message(action="send")validates and delivers on all configured channels.Validation failed for tool "message": ... must have required properties media, caption, asVoice, messageId, ...BEFORE

AFTER

Tests and validation
Which commands did you run?
pnpm test src/channels/plugins/message-actions.test.ts— 11/11 passedpnpm test src/agents/tools/message-tool.test.ts— 98/98 passedv2026.6.1(11/11, 94/94)What regression coverage was added or updated?
src/channels/plugins/message-actions.test.ts: a plugin contributing (a) a non-optional TypeBox schema and (b) astructuredClone-stripped optional schema; asserts the assembled tool schema'srequiredis exactly["action"].What failed before this fix, if known?
The new test fails on
mainwithrequired: ["action", "components", "chatRef"]. At runtime, everymessagetool call failed validation when any configured channel contributed a marker-less schema property.If no test was added, why not?
n/a — test added.
Risk checklist
Did user-visible behavior change? (
Yes/No)Yes —
messagetool calls validate again; contributed params are now uniformly optional.Did config, environment, or migration behavior change? (
Yes/No)No.
Did security, auth, secrets, network, or tool execution behavior change? (
Yes/No)No.
What is the highest-risk area?
A plugin that intended a contributed property to be object-level required would lose that.
How is that risk mitigated?
No in-tree contributor does this, and a cross-action required param cannot work on a multi-action tool — that is the bug class itself (see #56496).
Current review state
What is the next action?
Maintainer review.
What is still waiting on author, maintainer, CI, or external proof?
Nothing waiting on author; after-fix screenshots attached above.
Which bot or reviewer comments were addressed?
None yet.