Skip to content

fix(state): avoid sqlite wal on nfs state volumes#91247

Merged
vincentkoc merged 2 commits into
openclaw:mainfrom
849261680:fix/90491-sqlite-nfs-journal
Jun 13, 2026
Merged

fix(state): avoid sqlite wal on nfs state volumes#91247
vincentkoc merged 2 commits into
openclaw:mainfrom
849261680:fix/90491-sqlite-nfs-journal

Conversation

@849261680

@849261680 849261680 commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Detect SQLite database paths on NFS-backed volumes and use rollback journaling instead of WAL.
  • Keep existing WAL behavior unchanged for local filesystems; detection uses Linux statfs magic first, then mount metadata (/proc/self/mountinfo or mount output) for platform-specific filesystem type names.
  • Pass the memory-core database path into the shared SQLite journal helper and add regression coverage for the helper plus shared state opener.

Fixes #90491

Real behavior proof

  • Behavior addressed: OpenClaw no longer forces SQLite WAL for state databases whose backing volume is reported as NFS, avoiding the WAL-on-NFS path that can corrupt persisted state during Azure Container Apps revision replacement.

  • Real environment tested: GitHub Actions Ubuntu 24.04 runner with a real localhost NFS export mounted at /mnt/openclaw-nfs-proof, Node v24.16.0, pnpm 11.2.2, and the production openOpenClawStateDatabase() opener from this branch. The proof run is https://github.com/849261680/openclaw/actions/runs/27105565187.

  • Exact steps or command run after this patch:

    • In the proof workflow, install nfs-kernel-server and nfs-common, export /tmp/openclaw-nfs-export, mount it as 127.0.0.1:/tmp/openclaw-nfs-export at /mnt/openclaw-nfs-proof, and verify the mount with mount, findmnt, and stat -f.
    • Run openOpenClawStateDatabase({ env: { OPENCLAW_STATE_DIR: "/mnt/openclaw-nfs-proof/openclaw-state" } }) through node --import tsx --input-type=module twice: first open and restart-open.
    • In each process, read PRAGMA journal_mode, write to a proof table, list the state DB directory, close the production opener, and fail if any *-wal or *-shm sidecar exists.
    • Local supporting checks: node scripts/run-vitest.mjs src/infra/sqlite-wal.test.ts src/state/openclaw-state-db.test.ts; node scripts/run-vitest.mjs extensions/memory-core/src/memory/manager.readonly-recovery.test.ts; targeted oxfmt/oxlint; corepack pnpm tsgo:core; corepack pnpm tsgo:extensions; .agents/skills/autoreview/scripts/autoreview --mode branch --base upstream/main.
  • Evidence after fix: Real NFS mount proof output from https://github.com/849261680/openclaw/actions/runs/27105565187:

    Operating System: Ubuntu
    Image: ubuntu-24.04
    127.0.0.1:/tmp/openclaw-nfs-export on /mnt/openclaw-nfs-proof type nfs (rw,relatime,vers=3,...)
    TARGET                  FSTYPE SOURCE                             OPTIONS
    /mnt/openclaw-nfs-proof nfs    127.0.0.1:/tmp/openclaw-nfs-export rw,relatime,vers=3,...
    statfs-type-name=nfs statfs-type-hex=6969
    

    First production opener on that NFS-mounted state directory:

    {
      "label": "first-open",
      "stateDir": "/mnt/openclaw-nfs-proof/openclaw-state",
      "databasePath": "/mnt/openclaw-nfs-proof/openclaw-state/state/openclaw.sqlite",
      "journalMode": "delete",
      "proofRows": 1,
      "hasWalSidecar": false,
      "files": [
        "openclaw.sqlite"
      ]
    }

    Restart-open production opener on the same NFS-mounted state directory:

    {
      "label": "restart-open",
      "stateDir": "/mnt/openclaw-nfs-proof/openclaw-state",
      "databasePath": "/mnt/openclaw-nfs-proof/openclaw-state/state/openclaw.sqlite",
      "journalMode": "delete",
      "proofRows": 2,
      "hasWalSidecar": false,
      "files": [
        "openclaw.sqlite"
      ]
    }

    Proof run final line:

    OpenClaw #90491 NFS proof passed
    

    Focused local Vitest output after the final patch:

     Test Files  1 passed (1)
          Tests  14 passed (14)
    
     Test Files  1 passed (1)
          Tests  7 passed (7)
    [test] passed 2 Vitest shards in 22.61s
    

    Memory-core supporting test output:

     Test Files  1 passed (1)
          Tests  9 passed (9)
    [test] passed 1 Vitest shard in 22.35s
    

    Autoreview output after the mount metadata fallback was added:

    autoreview clean: no accepted/actionable findings reported
    overall: patch is correct (0.78)
    
  • Observed result after fix: On a real Linux NFS mount, the production shared state opener selected journal_mode=delete, wrote state successfully across a restart-open, and created no -wal or -shm sidecar files. The default local shared state database still uses WAL in the local smoke, and tests cover Linux statfs, Linux mountinfo, and macOS/BSD-style mount output detection. The memory-core database path now reaches the same shared helper instead of opening without path context.

  • What was not tested: Did not run Azure Container Apps itself or a real overlapping ACA revision replacement. The required real Linux NFS storage behavior was tested on a GitHub-hosted Ubuntu runner with a real NFS mount.

Verification

  • GitHub Actions real NFS proof: https://github.com/849261680/openclaw/actions/runs/27105565187
  • node scripts/run-vitest.mjs src/infra/sqlite-wal.test.ts src/state/openclaw-state-db.test.ts
  • node scripts/run-vitest.mjs extensions/memory-core/src/memory/manager.readonly-recovery.test.ts
  • node --import tsx --input-type=module shared-state opener smoke on local disk and simulated Linux NFS statfs
  • corepack pnpm format:check -- src/infra/sqlite-wal.ts src/infra/sqlite-wal.test.ts src/state/openclaw-state-db.test.ts extensions/memory-core/src/memory/manager-db.ts
  • git diff --check
  • OPENCLAW_OXLINT_SKIP_LOCK=1 OPENCLAW_OXLINT_SKIP_PREPARE=1 node scripts/run-oxlint.mjs --tsconfig config/tsconfig/oxlint.core.json src/infra/sqlite-wal.ts src/infra/sqlite-wal.test.ts src/state/openclaw-state-db.test.ts
  • OPENCLAW_OXLINT_SKIP_LOCK=1 OPENCLAW_OXLINT_SKIP_PREPARE=1 node scripts/run-oxlint.mjs --tsconfig config/tsconfig/oxlint.extensions.json extensions/memory-core/src/memory/manager-db.ts
  • corepack pnpm tsgo:core
  • corepack pnpm tsgo:extensions
  • .agents/skills/autoreview/scripts/autoreview --mode branch --base upstream/main

@openclaw-barnacle openclaw-barnacle Bot added extensions: memory-core Extension: memory-core size: S proof: supplied External PR includes structured after-fix real behavior proof. labels Jun 7, 2026
@clawsweeper

clawsweeper Bot commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs real behavior proof before merge. Reviewed June 13, 2026, 3:29 PM ET / 19:29 UTC.

Summary
The branch adds NFS-backed SQLite volume detection to the shared WAL helper, switches detected databases to rollback journaling, passes database paths from memory-core and proxy-capture, and adds regression tests.

PR surface: Source +148, Tests +184. Total +332 across 6 files.

Reproducibility: no. live current-main Azure Container Apps corruption reproduction was run in this read-only review. The source path is clear: current main forces WAL, the linked issue supplies Azure/NFS logs, and the PR proof demonstrates the mitigation on a real Linux NFS mount.

Review metrics: 1 noteworthy metric.

  • SQLite Journal Behavior: 1 conditional default changed. Detected NFS-backed SQLite databases switch from WAL to rollback journaling, which is an upgrade-visible storage behavior change.

Stored data model
Persistent data-model change detected: serialized state: src/state/openclaw-state-db.test.ts, vector/embedding metadata: extensions/memory-core/src/memory/manager-db.ts. Confirm migration or upgrade compatibility proof before merge.

Merge readiness
Overall: 🦐 gold shrimp
Proof: 🦐 gold shrimp
Patch quality: 🐚 platinum hermit
Result: blocked until stronger real behavior proof is added.

Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch.

Rank-up moves:

  • Rerun the real NFS proof against the current PR head.
  • [P1] Have maintainers explicitly accept the automatic NFS rollback-journaling and fail-closed behavior.

Proof guidance:

  • [P1] Needs stronger real behavior proof before merge: The linked real NFS proof is strong but predates the current head's runtime NFS journal-setting change; rerun current-head proof and redact private paths, IPs, keys, phone numbers, endpoints, and other private details before posting. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.

Risk before merge

  • [P1] Detected NFS-backed state databases will automatically move from WAL to rollback journaling during upgrade, changing existing concurrency and performance behavior.
  • [P1] The latest PR head added a fail-closed NFS path when SQLite does not return DELETE, so maintainers should explicitly accept that startup/runtime stop rather than silently continuing with WAL on NFS.
  • [P1] The strongest real NFS proof was run before the current head changed the NFS journal-setting implementation, so exact-head proof is still the cleanest merge gate.

Maintainer options:

  1. Refresh Current-Head NFS Proof (recommended)
    Rerun the real NFS production-opener proof against 5967430 or a newer head so the DELETE-journal and fail-closed path are proven exactly before merge.
  2. Accept Prior NFS Proof
    Maintainership can accept the earlier real NFS proof plus current tests if the latest prepare/get change is considered low enough risk.
  3. Pause For Operator-Controlled Policy
    Pause the PR if automatic NFS journal switching and fail-closed behavior should become an explicit operator policy instead.

Next step before merge

  • [P1] No automated repair is needed; the remaining action is maintainer acceptance of the storage tradeoff plus current-head real proof or an explicit proof override.

Security
Cleared: No concrete security or supply-chain concern was found in this local SQLite journaling and test-only diff.

Review details

Best possible solution:

Land the centralized NFS journal-mode mitigation after current-head NFS proof or an explicit maintainer override, keeping local filesystems on WAL and avoiding a new config surface.

Do we have a high-confidence way to reproduce the issue?

No live current-main Azure Container Apps corruption reproduction was run in this read-only review. The source path is clear: current main forces WAL, the linked issue supplies Azure/NFS logs, and the PR proof demonstrates the mitigation on a real Linux NFS mount.

Is this the best way to solve the issue?

Yes, this appears to be the best fix shape: centralize the journal decision in the existing SQLite helper instead of adding the config surface proposed in #60349. The remaining question is maintainer acceptance of automatic rollback journaling plus exact-head proof.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against dbf24fe35af5.

Label changes

Label changes:

  • add merge-risk: 🚨 availability: The PR intentionally refuses to continue if a detected NFS-backed database cannot leave WAL mode.
  • add rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • add status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: The linked real NFS proof is strong but predates the current head's runtime NFS journal-setting change; rerun current-head proof and redact private paths, IPs, keys, phone numbers, endpoints, and other private details before posting. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
  • remove rating: 🐚 platinum hermit: Current PR rating is rating: 🦐 gold shrimp, so this older rating label is no longer current.
  • remove status: 👀 ready for maintainer look: Current PR status label is status: 📣 needs proof.

Label justifications:

  • P1: The linked regression can leave Docker/Azure Container Apps gateway and CLI state unusable after restart.
  • merge-risk: 🚨 compatibility: Existing NFS-backed state volumes would change SQLite journal mode automatically during upgrade.
  • merge-risk: 🚨 session-state: The affected SQLite databases store shared runtime, per-agent, plugin, proxy-capture, and memory-core state.
  • merge-risk: 🚨 availability: The PR intentionally refuses to continue if a detected NFS-backed database cannot leave WAL mode.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🐚 platinum hermit.
  • status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: The linked real NFS proof is strong but predates the current head's runtime NFS journal-setting change; rerun current-head proof and redact private paths, IPs, keys, phone numbers, endpoints, and other private details before posting. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Evidence reviewed

PR surface:

Source +148, Tests +184. Total +332 across 6 files.

View PR surface stats
Area Files Added Removed Net
Source 3 154 6 +148
Tests 3 190 6 +184
Docs 0 0 0 0
Config 0 0 0 0
Generated 0 0 0 0
Other 0 0 0 0
Total 6 344 12 +332

What I checked:

  • Repository policy: Root AGENTS.md and extensions/AGENTS.md were read fully; state/storage compatibility guidance and bundled plugin boundary guidance affected the review. (AGENTS.md:20, dbf24fe35af5)
  • Current main behavior: Current main still unconditionally enables WAL in the shared SQLite helper, so the central requested behavior is not already implemented on main. (src/infra/sqlite-wal.ts:53, dbf24fe35af5)
  • PR implementation: At PR head, the shared helper detects NFS-backed paths and requires DELETE journaling before returning no-op WAL maintenance. (src/infra/sqlite-wal.ts:191, 59674305ecd8)
  • Memory-core path coverage: Memory-core now passes its concrete database path through the SDK WAL helper, and the SDK facade already accepts the same options without adding a new plugin API. (extensions/memory-core/src/memory/manager-db.ts:40, 59674305ecd8)
  • Proxy capture path coverage: The latest maintainer push also routes proxy-capture's SQLite DB path into the shared helper, so this sibling WAL user is covered. (src/proxy-capture/store.sqlite.ts:36, 59674305ecd8)
  • Regression tests: The PR adds tests for Linux statfs NFS magic, mountinfo fallback, mount command fallback, DELETE journal selection, and refusing to continue if SQLite keeps WAL active on an NFS-backed path. (src/infra/sqlite-wal.test.ts:53, 59674305ecd8)

Likely related people:

  • steipete: GitHub file history shows the shared SQLite state database, WAL sidecar bounding, and recent state migration work concentrated in commits by this author. (role: state storage feature history; confidence: high; commits: bc848b367f0b, 287f531de6c4, 3bc29dd60448; files: src/infra/sqlite-wal.ts, src/state/openclaw-state-db.ts, src/proxy-capture/store.sqlite.ts)
  • vincentkoc: This login is assigned to the PR, authored the latest PR head commit, and appears in recent current-main history for adjacent agent/state SQLite work. (role: recent adjacent state contributor and assigned reviewer; confidence: medium; commits: 59674305ecd8, 7f1d82ab2518; files: src/infra/sqlite-wal.ts, src/proxy-capture/store.sqlite.ts, src/state/openclaw-agent-db.ts)
  • xydt-tanshanshan: Recent current-main history for memory-core manager database behavior includes the live SQLite index swap repair in this file. (role: recent memory-core storage contributor; confidence: medium; commits: 865fdab07501; files: extensions/memory-core/src/memory/manager-db.ts)
What the crustacean ranks mean
  • 🦀 challenger crab: rare, exceptional readiness with strong proof, clean implementation, and convincing validation.
  • 🦞 diamond lobster: very strong readiness with only minor maintainer review expected.
  • 🐚 platinum hermit: good normal PR, likely mergeable with ordinary maintainer review.
  • 🦐 gold shrimp: useful signal, but proof or patch confidence is still limited.
  • 🦪 silver shellfish: thin signal; proof, validation, or implementation needs work.
  • 🧂 unranked krab: not merge-ready because proof is missing/unusable or there are serious correctness or safety concerns.
  • 🌊 off-meta tidepool: rating does not apply to this item.

Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

How this review workflow works
  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@clawsweeper clawsweeper Bot added the rating: 🌊 off-meta tidepool PR readiness rating does not apply to this item. label Jun 7, 2026
@849261680
849261680 force-pushed the fix/90491-sqlite-nfs-journal branch from bbc50fb to d47ef2d Compare June 7, 2026 21:06
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. P1 High-priority user-facing bug, regression, or broken workflow. merge-risk: 🚨 compatibility 🚨 May break existing users, config, migrations, defaults, or upgrade paths. merge-risk: 🚨 session-state 🚨 May lose, corrupt, stale, or mis-associate session, agent, or context state. and removed rating: 🌊 off-meta tidepool PR readiness rating does not apply to this item. labels Jun 7, 2026
@849261680
849261680 force-pushed the fix/90491-sqlite-nfs-journal branch from d47ef2d to f967389 Compare June 7, 2026 21:14
@849261680

Copy link
Copy Markdown
Contributor Author

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

🦞🧹
ClawSweeper re-review requested.

I asked ClawSweeper to review this item again.
Action: item re-review queued (workflow sweep.yml, event repository_dispatch).
Result: the existing ClawSweeper review comment will be edited in place when the review finishes.

Re-review progress:

@849261680

Copy link
Copy Markdown
Contributor Author

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Jun 7, 2026

Copy link
Copy Markdown
Contributor

🦞🧹
ClawSweeper re-review requested.

I asked ClawSweeper to review this item again.
Action: item re-review queued (workflow sweep.yml, event repository_dispatch).
Result: the existing ClawSweeper review comment will be edited in place when the review finishes.

Re-review progress:

@clawsweeper clawsweeper Bot added proof: sufficient ClawSweeper judged the real behavior proof convincing. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Jun 7, 2026
@vincentkoc vincentkoc self-assigned this Jun 13, 2026
@vincentkoc
vincentkoc force-pushed the fix/90491-sqlite-nfs-journal branch from f967389 to 5967430 Compare June 13, 2026 19:23
@openclaw-barnacle openclaw-barnacle Bot removed the proof: sufficient ClawSweeper judged the real behavior proof convincing. label Jun 13, 2026
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. merge-risk: 🚨 availability 🚨 May cause crashes, hangs, restart loops, stalls, or process outages. and removed rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Jun 13, 2026

@vincentkoc vincentkoc left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No blocking findings.

Best-fix verdict: best, after maintainer fixup. The journal-mode decision is centralized in the shared SQLite WAL helper rather than per-caller policy, local filesystems keep WAL/checkpoint maintenance, and NFS-backed database paths switch to rollback journaling only after SQLite reports the effective journal_mode=delete. If SQLite refuses to leave WAL, the opener now fails closed instead of silently disabling WAL maintenance while WAL remains active.

I also checked cross-store coverage: shared state and per-agent DBs already pass databasePath; memory-core now passes it through the plugin SDK storage facade; proxy-capture was the remaining core SQLite helper caller missing path context and is fixed here. Workboard's extension-local SQLite store remains a separate plugin-owned implementation, not a core state helper call site.

Proof:

  • Local: node scripts/run-vitest.mjs src/infra/sqlite-wal.test.ts src/state/openclaw-state-db.test.ts src/proxy-capture/store.sqlite.test.ts extensions/memory-core/src/memory/manager.readonly-recovery.test.ts --maxWorkers=1
  • Local: targeted oxfmt --check, run-oxlint core + extension, git diff --check
  • Autoreview: first run found the journal_mode verification bug; fixed and reran clean. Final autoreview clean on 59674305ecd863d4815eec6098ccd3daab79ca4f, no accepted/actionable findings, no security/auth/exec/SSRF concern.
  • Crabbox AWS run_2ea7014350da / cbx_199aab089ebb: focused SQLite/state/proxy/memory tests passed.
  • Crabbox/Testbox tbx_01kv15fwqv126r5tjkskwdjmzr: infrastructure DNS failure before code execution; stopped.
  • Crabbox AWS run_c828bbfe7d23 / cbx_265750b7dc73: OPENCLAW_CHECK_CHANGED_REMOTE_CHILD=1 OPENCLAW_CHANGED_LANES_RAW_SYNC=1 CI=1 corepack pnpm check:changed passed for lanes core, coreTests, extensions, extensionTests.
  • GitHub exact-head CI on 59674305ecd863d4815eec6098ccd3daab79ca4f: required CI/security/check shards green or skipped; CodeQL neutral.

@vincentkoc
vincentkoc merged commit 5b21a03 into openclaw:main Jun 13, 2026
186 of 191 checks passed
eleboucher pushed a commit to eleboucher/homelab that referenced this pull request Jun 16, 2026
…26.6.8) (#1144)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/openclaw/openclaw](https://openclaw.ai) ([source](https://github.com/openclaw/openclaw)) | patch | `2026.6.6` → `2026.6.8` |

---

### Release Notes

<details>
<summary>openclaw/openclaw (ghcr.io/openclaw/openclaw)</summary>

### [`v2026.6.8`](https://github.com/openclaw/openclaw/blob/HEAD/CHANGELOG.md#202668)

[Compare Source](openclaw/openclaw@v2026.6.6...v2026.6.8)

##### Highlights

- Telegram and WhatsApp channel delivery are richer and less brittle: Telegram can send structured rich text with tables, lists, expandable blockquotes, prompt-preserving CLI backend delivery, retired native draft migration, and safer rich-media boundaries, while WhatsApp now honors configured ACP bindings. ([#&#8203;92679](openclaw/openclaw#92679), [#&#8203;84082](openclaw/openclaw#84082), [#&#8203;89421](openclaw/openclaw#89421), [#&#8203;92513](openclaw/openclaw#92513)) Thanks [@&#8203;obviyus](https://github.com/obviyus), [@&#8203;jzakirov](https://github.com/jzakirov), [@&#8203;spacegeologist](https://github.com/spacegeologist), and [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle).
- Agent and Gateway recovery is sharper across account-scoped DM sends, generated media completions, restart shutdown aborts, yielded subagent pauses, yielded cron media, heartbeat dedupe, session identity prompts, and unknown OpenAI agent selector rejection. ([#&#8203;92788](openclaw/openclaw#92788), [#&#8203;91246](openclaw/openclaw#91246), [#&#8203;91357](openclaw/openclaw#91357), [#&#8203;92631](openclaw/openclaw#92631), [#&#8203;92146](openclaw/openclaw#92146), [#&#8203;91287](openclaw/openclaw#91287), [#&#8203;92468](openclaw/openclaw#92468), [#&#8203;92510](openclaw/openclaw#92510)) Thanks [@&#8203;yetval](https://github.com/yetval), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;ooiuuii](https://github.com/ooiuuii), [@&#8203;openperf](https://github.com/openperf), [@&#8203;IWhatsskill](https://github.com/IWhatsskill), [@&#8203;ZengWen-DT](https://github.com/ZengWen-DT), and [@&#8203;zhangguiping-xydt](https://github.com/zhangguiping-xydt).
- Provider/model handling expands and tightens with GLM-5.2, Claude Haiku 4.5 catalog rows, OpenRouter and Google Vertex provider-prefix normalization, managed SecretRef auth, bounded model browse discovery, storeless OpenAI Responses replay gating, and Claude 4.5 Copilot tool-streaming safety. ([#&#8203;92796](openclaw/openclaw#92796), [#&#8203;90116](openclaw/openclaw#90116), [#&#8203;92627](openclaw/openclaw#92627), [#&#8203;91218](openclaw/openclaw#91218), [#&#8203;90686](openclaw/openclaw#90686), [#&#8203;92247](openclaw/openclaw#92247), [#&#8203;90706](openclaw/openclaw#90706), [#&#8203;75393](openclaw/openclaw#75393)) Thanks [@&#8203;arkyu2077](https://github.com/arkyu2077), [@&#8203;liuhao1024](https://github.com/liuhao1024), [@&#8203;bymle](https://github.com/bymle), [@&#8203;rohitjavvadi](https://github.com/rohitjavvadi), [@&#8203;samson910022](https://github.com/samson910022), [@&#8203;snowzlm](https://github.com/snowzlm), and [@&#8203;Kailigithub](https://github.com/Kailigithub).
- `/usage` and reply payload hooks now have a native full footer renderer, default template, fixed-decimal formatting, credential-aware limits, better partial-count handling, and warnings for broken templates instead of silent bad output. ([#&#8203;92657](openclaw/openclaw#92657), [#&#8203;89835](openclaw/openclaw#89835), [#&#8203;89629](openclaw/openclaw#89629)) Thanks [@&#8203;Marvinthebored](https://github.com/Marvinthebored).
- UI and mobile flows are steadier: workspace files can collapse and start collapsed, WebChat backscroll survives streaming, the sidebar session picker remains interactive above the desktop workbench, reset soft args survive UI dispatch, stale dashboard session parent lineage is preserved, and iOS reconnects stale foreground gateways. ([#&#8203;92779](openclaw/openclaw#92779), [#&#8203;92622](openclaw/openclaw#92622), [#&#8203;92705](openclaw/openclaw#92705), [#&#8203;91353](openclaw/openclaw#91353), [#&#8203;90658](openclaw/openclaw#90658), [#&#8203;92552](openclaw/openclaw#92552)) Thanks [@&#8203;shakkernerd](https://github.com/shakkernerd), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;NianJiuZst](https://github.com/NianJiuZst), [@&#8203;zhouhe-xydt](https://github.com/zhouhe-xydt), [@&#8203;luoyanglang](https://github.com/luoyanglang), and [@&#8203;Solvely-Colin](https://github.com/Solvely-Colin).
- Memory, state, and diagnostics recover cleaner: oversized OpenAI embedding batches split before 431s, QMD memory search stays available in transient mode, SQLite avoids WAL on NFS state volumes, stuck-session recovery scheduling no longer resets warning backoff, and Infinity chunk limits stay genuinely unbounded. ([#&#8203;92650](openclaw/openclaw#92650), [#&#8203;92618](openclaw/openclaw#92618), [#&#8203;92639](openclaw/openclaw#92639), [#&#8203;91247](openclaw/openclaw#91247), [#&#8203;92752](openclaw/openclaw#92752), [#&#8203;92735](openclaw/openclaw#92735)) Thanks [@&#8203;mushuiyu886](https://github.com/mushuiyu886), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;849261680](https://github.com/849261680), [@&#8203;gnanam1990](https://github.com/gnanam1990), and [@&#8203;yhterrance](https://github.com/yhterrance).

##### Changes

- Providers/models: add GLM-5.2 support and Claude Haiku 4.5 catalog entries while keeping provider-qualified model IDs normalized across OpenRouter and Google Vertex paths. ([#&#8203;92796](openclaw/openclaw#92796), [#&#8203;90116](openclaw/openclaw#90116), [#&#8203;92627](openclaw/openclaw#92627), [#&#8203;91218](openclaw/openclaw#91218)) Thanks [@&#8203;arkyu2077](https://github.com/arkyu2077), [@&#8203;liuhao1024](https://github.com/liuhao1024), and [@&#8203;bymle](https://github.com/bymle).
- Channel plugins: ship Telegram rich-message delivery and WhatsApp ACP binding support, including rich prompt handoff to CLI backends and transport fixtures for richer drafts. ([#&#8203;92679](openclaw/openclaw#92679), [#&#8203;92513](openclaw/openclaw#92513)) Thanks [@&#8203;obviyus](https://github.com/obviyus) and [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle).
- Agent commands: support `/btw` in CLI-backed sessions and keep CLI usage-error exits classified as usage failures instead of successful runs. ([#&#8203;92669](openclaw/openclaw#92669), [#&#8203;92162](openclaw/openclaw#92162)) Thanks [@&#8203;joshavant](https://github.com/joshavant) and [@&#8203;Pandah97](https://github.com/Pandah97).
- Usage hooks: add built-in full footer rendering, default footer templates, per-turn usage state, credential-aware limits, and fixed-decimal formatting for usage-bar templates. ([#&#8203;92657](openclaw/openclaw#92657), [#&#8203;89835](openclaw/openclaw#89835), [#&#8203;89629](openclaw/openclaw#89629)) Thanks [@&#8203;Marvinthebored](https://github.com/Marvinthebored).
- Docs and operator guidance: document node config examples, clarify before-install hook scope, correct agent default concurrency comments, refresh ZAI provider docs, and update channel/group docs for current Telegram and WhatsApp behavior. ([#&#8203;92677](openclaw/openclaw#92677), [#&#8203;92766](openclaw/openclaw#92766), [#&#8203;92695](openclaw/openclaw#92695)) Thanks [@&#8203;liuhao1024](https://github.com/liuhao1024), [@&#8203;sallyom](https://github.com/sallyom), and [@&#8203;ArielSmoliar](https://github.com/ArielSmoliar).

##### Fixes

- Onboarding/skills: show the Homebrew install recommendation only on macOS and Linux, so FreeBSD and other unsupported platforms no longer get a misleading brew prompt. Fixes [#&#8203;68893](openclaw/openclaw#68893); carries forward [#&#8203;68894](openclaw/openclaw#68894), [#&#8203;68910](openclaw/openclaw#68910), [#&#8203;68941](openclaw/openclaw#68941), [#&#8203;68943](openclaw/openclaw#68943), [#&#8203;69002](openclaw/openclaw#69002), and [#&#8203;69545](openclaw/openclaw#69545). Thanks [@&#8203;yurivict](https://github.com/yurivict), [@&#8203;Sanjays2402](https://github.com/Sanjays2402), [@&#8203;Eruditi](https://github.com/Eruditi), [@&#8203;JustInCache](https://github.com/JustInCache), [@&#8203;nnish16](https://github.com/nnish16), and [@&#8203;Mlightsnow](https://github.com/Mlightsnow).
- Channels and delivery: preserve account-scoped DM channel send policy, rich Telegram final replies, rich Telegram tables and lists, Telegram thread-create CLI remapping, Slack outbound `message_sent` hooks, contributed message-tool schema optionality, same-channel generated media completions, and channel chunking around surrogate pairs and Infinity limits. ([#&#8203;92788](openclaw/openclaw#92788), [#&#8203;92679](openclaw/openclaw#92679), [#&#8203;89421](openclaw/openclaw#89421), [#&#8203;89943](openclaw/openclaw#89943), [#&#8203;91137](openclaw/openclaw#91137), [#&#8203;91246](openclaw/openclaw#91246), [#&#8203;92735](openclaw/openclaw#92735)) Thanks [@&#8203;yetval](https://github.com/yetval), [@&#8203;obviyus](https://github.com/obviyus), [@&#8203;spacegeologist](https://github.com/spacegeologist), [@&#8203;rishitamrakar](https://github.com/rishitamrakar), [@&#8203;lundog](https://github.com/lundog), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), and [@&#8203;yhterrance](https://github.com/yhterrance).
- Auto-reply/groups: keep ordinary group text replies on automatic final-reply delivery while allowing `message(action=send)` for files, images, and other attachments to the same group or topic. Carries forward [#&#8203;43276](openclaw/openclaw#43276); refs [#&#8203;48004](openclaw/openclaw#48004). Thanks [@&#8203;NayukiChiba](https://github.com/NayukiChiba) and [@&#8203;ShakaRover](https://github.com/ShakaRover).
- Auto-reply/skills: preserve multiline payloads for `/skill` and direct skill slash commands while keeping command-head normalization for aliases, colon syntax, and bot mentions. Fixes [#&#8203;79155](openclaw/openclaw#79155); carries forward [#&#8203;81305](openclaw/openclaw#81305). Thanks [@&#8203;web3blind](https://github.com/web3blind).
- iMessage: normalize leading NUL sent-message echo prefixes while preserving interior NUL bytes and the leading attributedBody marker handling from [#&#8203;73942](openclaw/openclaw#73942). Carries forward [#&#8203;63581](openclaw/openclaw#63581). Thanks [@&#8203;drvoss](https://github.com/drvoss).
- Discord: give generated auto-thread titles a 60-second timeout and 4,096-token reasoning-model output budget, clamped to the selected model output cap. ([#&#8203;64734](openclaw/openclaw#64734)) Thanks [@&#8203;hanamizuki](https://github.com/hanamizuki).
- Agent, cron, and Gateway runtime: mark active main sessions before restart shutdown aborts, pause yielded subagent runs whose terminal also signals abort, preserve yielded media completions, de-duplicate main-session heartbeat events, expose session identity in runtime prompts, reject unknown OpenAI agent selectors, keep generated media completions and slash-command block replies in WebChat, preserve fresh post-compaction usage while clearing stale usage snapshots, and require admin privileges for HTTP session/model override surfaces. ([#&#8203;91357](openclaw/openclaw#91357), [#&#8203;92631](openclaw/openclaw#92631), [#&#8203;92146](openclaw/openclaw#92146), [#&#8203;91287](openclaw/openclaw#91287), [#&#8203;92468](openclaw/openclaw#92468), [#&#8203;92510](openclaw/openclaw#92510), [#&#8203;91246](openclaw/openclaw#91246), [#&#8203;50795](openclaw/openclaw#50795), [#&#8203;50845](openclaw/openclaw#50845), [#&#8203;82874](openclaw/openclaw#82874), [#&#8203;92651](openclaw/openclaw#92651), [#&#8203;92646](openclaw/openclaw#92646)) Thanks [@&#8203;ooiuuii](https://github.com/ooiuuii), [@&#8203;openperf](https://github.com/openperf), [@&#8203;IWhatsskill](https://github.com/IWhatsskill), [@&#8203;ZengWen-DT](https://github.com/ZengWen-DT), [@&#8203;zhangguiping-xydt](https://github.com/zhangguiping-xydt), [@&#8203;Hollychou924](https://github.com/Hollychou924), [@&#8203;leno23](https://github.com/leno23), and [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle).
- Agents/exec: default empty-success background completion notices on only for real chat channels, preserving explicit opt-outs and keeping generic providers silent while carrying forward the narrow UX intent from [#&#8203;39726](openclaw/openclaw#39726) and [#&#8203;46926](openclaw/openclaw#46926). Thanks [@&#8203;Sapientropic](https://github.com/Sapientropic) and [@&#8203;wenkang-xie](https://github.com/wenkang-xie).
- Providers and model replay: preserve storeless OpenAI Responses replay compatibility, avoid eager tool streaming for Claude 4.5 in Copilot, honor profile auth for SecretRef model entries, bound model browsing, strip provider prefixes where runtimes need bare IDs, and surface nested embedding fetch failures. ([#&#8203;90706](openclaw/openclaw#90706), [#&#8203;75393](openclaw/openclaw#75393), [#&#8203;90686](openclaw/openclaw#90686), [#&#8203;92247](openclaw/openclaw#92247), [#&#8203;92627](openclaw/openclaw#92627), [#&#8203;91218](openclaw/openclaw#91218), [#&#8203;92628](openclaw/openclaw#92628)) Thanks [@&#8203;snowzlm](https://github.com/snowzlm), [@&#8203;Kailigithub](https://github.com/Kailigithub), [@&#8203;rohitjavvadi](https://github.com/rohitjavvadi), [@&#8203;samson910022](https://github.com/samson910022), [@&#8203;liuhao1024](https://github.com/liuhao1024), [@&#8203;bymle](https://github.com/bymle), and [@&#8203;mushuiyu886](https://github.com/mushuiyu886).
- Memory, state, diagnostics, and config: split header-too-large embedding batches, keep QMD memory search enabled in transient mode, avoid SQLite WAL on NFS volumes, preserve recovery scheduling outside stuck-session warning backoff, and keep shell environment fallbacks contained in config write tests. ([#&#8203;92650](openclaw/openclaw#92650), [#&#8203;92618](openclaw/openclaw#92618), [#&#8203;92639](openclaw/openclaw#92639), [#&#8203;91247](openclaw/openclaw#91247), [#&#8203;92752](openclaw/openclaw#92752)) Thanks [@&#8203;mushuiyu886](https://github.com/mushuiyu886), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;849261680](https://github.com/849261680), and [@&#8203;gnanam1990](https://github.com/gnanam1990).
- Workspace setup state: store setup completion outside the workspace dot directory using an OpenClaw-named root file, migrate valid legacy state forward, and avoid clobbering generic root `workspace-state.json` files for TigerFS-style dot-path compatibility. This Clownfish replacement carries forward the focused [#&#8203;53326](openclaw/openclaw#53326) fix idea because the original branch was closed and uneditable. ([#&#8203;53326](openclaw/openclaw#53326), [#&#8203;44783](openclaw/openclaw#44783), [#&#8203;39446](openclaw/openclaw#39446)) Thanks [@&#8203;1qh](https://github.com/1qh).
- UI/mobile/TUI: preserve dashboard session parent lineage, WebChat backscroll, reset soft command args, sidebar session picker interactivity, collapsed workspace files, resolved `/model` confirmation refs, and stale foreground iOS Gateway reconnects. ([#&#8203;90658](openclaw/openclaw#90658), [#&#8203;92622](openclaw/openclaw#92622), [#&#8203;91353](openclaw/openclaw#91353), [#&#8203;92705](openclaw/openclaw#92705), [#&#8203;92779](openclaw/openclaw#92779), [#&#8203;92773](openclaw/openclaw#92773), [#&#8203;92552](openclaw/openclaw#92552)) Thanks [@&#8203;luoyanglang](https://github.com/luoyanglang), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;zhouhe-xydt](https://github.com/zhouhe-xydt), [@&#8203;NianJiuZst](https://github.com/NianJiuZst), [@&#8203;shakkernerd](https://github.com/shakkernerd), [@&#8203;NarahariRaghava](https://github.com/NarahariRaghava), and [@&#8203;Solvely-Colin](https://github.com/Solvely-Colin).
- TUI: reload the active session after external `/new` or `/reset` session-change events so stale transcript and stream state clear promptly. Fixes [#&#8203;38966](openclaw/openclaw#38966); carries forward [#&#8203;40472](openclaw/openclaw#40472). Thanks [@&#8203;yizhanzjz](https://github.com/yizhanzjz) and [@&#8203;wsyjh8](https://github.com/wsyjh8).
- Control UI: preserve Gateway Access tokens during same-normalized WebSocket URL edits and reload gateway-scoped tokens when switching endpoints. Fixes [#&#8203;41545](openclaw/openclaw#41545); repairs [#&#8203;42001](openclaw/openclaw#42001) with additional source PRs [#&#8203;41546](openclaw/openclaw#41546), [#&#8203;41552](openclaw/openclaw#41552), and [#&#8203;41718](openclaw/openclaw#41718). Thanks [@&#8203;wsyjh8](https://github.com/wsyjh8), [@&#8203;llagy0020](https://github.com/llagy0020), [@&#8203;llagy007](https://github.com/llagy007), [@&#8203;pingfanfan](https://github.com/pingfanfan), and [@&#8203;zheliu2](https://github.com/zheliu2).
- Gateway CLI: tolerate a single transient clean WebSocket close before `hello-ok` so one-shot RPC calls reconnect instead of failing noisily, while repeated clean pre-hello closes still surface. Carries forward source PRs [#&#8203;54475](openclaw/openclaw#54475) and [#&#8203;54774](openclaw/openclaw#54774); [#&#8203;85253](openclaw/openclaw#85253) covered adjacent connect assembly diagnostics. Thanks [@&#8203;ruanrrn](https://github.com/ruanrrn).
- Gateway/Linux: keep root-owned systemd user service lifecycle commands on root's user manager when a stale `SUDO_USER` remains in a root shell with root's user bus environment. Fixes [#&#8203;81410](openclaw/openclaw#81410). Thanks [@&#8203;Ericksza](https://github.com/Ericksza) and [@&#8203;ChuckClose-tech](https://github.com/ChuckClose-tech).
- Release and test reliability: extend slow Gateway/full-suite watchdogs, split local full-suite shards when throttled, stabilize plugin auth marker fixtures, avoid brittle provider-ref error text, and keep QA Lab bootstrap selection assertions aligned with flow-only scenarios. ([#&#8203;92652](openclaw/openclaw#92652))
- macOS Peekaboo bridge: update the embedded Peekaboo package to 3.5.2 and route bundled-skill CLI commands through the OpenClaw app bridge so they inherit its Screen Recording and Accessibility grants.
- Agent routing: route subagent RPC callbacks addressed to an agent-shaped `--to` target to the correct session key instead of falling back to the main session, so WeChat (and other channel) session-key callbacks reach the intended subagent session. ([#&#8203;90231](openclaw/openclaw#90231)) Thanks [@&#8203;zhangguiping-xydt](https://github.com/zhangguiping-xydt).
- Cron: preserve model, fallback, thinking, timeout, light-context, unsafe-content, and tool allow-list overrides on implicit text payloads by promoting them to agent turns, while explicit system events still prune those fields. Fixes [#&#8203;28905](openclaw/openclaw#28905); carries forward [#&#8203;64060](openclaw/openclaw#64060) and [#&#8203;73946](openclaw/openclaw#73946). Thanks [@&#8203;liaoandi](https://github.com/liaoandi).
- QQBot delivery: keep markdown table chunks self-contained across message boundaries by preserving table state across block deliveries, flushing unfinished table-row fragments as plain text, and detecting short pipe-terminated rows by column count so split rows are not sent as malformed markdown. ([#&#8203;92428](openclaw/openclaw#92428)) Thanks [@&#8203;sliverp](https://github.com/sliverp).

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/1144
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

extensions: memory-core Extension: memory-core merge-risk: 🚨 availability 🚨 May cause crashes, hangs, restart loops, stalls, or process outages. merge-risk: 🚨 compatibility 🚨 May break existing users, config, migrations, defaults, or upgrade paths. merge-risk: 🚨 session-state 🚨 May lose, corrupt, stale, or mis-associate session, agent, or context state. P1 High-priority user-facing bug, regression, or broken workflow. proof: supplied External PR includes structured after-fix real behavior proof. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. size: M status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: GatewayRequestError: Error: file is not a database: code=ERR_SQLITE_ERROR

2 participants