Skip to content

fix: require admin for HTTP model overrides#92646

Merged
steipete-oai merged 1 commit into
mainfrom
codex/openclaw-security-audit
Jun 13, 2026
Merged

fix: require admin for HTTP model overrides#92646
steipete-oai merged 1 commit into
mainfrom
codex/openclaw-security-audit

Conversation

@steipete-oai

@steipete-oai steipete-oai commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Require operator.admin before identity-bearing OpenAI-compatible HTTP callers can use x-openclaw-model.
  • Preserve existing shared-secret bearer behavior and admin-scoped trusted-proxy/private ingress behavior.
  • Add regression coverage for chat completions, Responses, embeddings, and the shared auth helper; update Gateway docs for the owner-level header contract.

Verification

  • git diff --check
  • node scripts/run-vitest.mjs src/gateway/http-utils.request-context.test.ts src/gateway/openai-http.test.ts src/gateway/openresponses-http.test.ts src/gateway/embeddings-http.test.ts
    • 13 files passed, 235 tests passed
  • Autoreview: clean, no accepted/actionable findings
  • Remote devbox proof attempted on two fresh leases; both environments failed before OpenClaw code ran because package-registry auth was unavailable.

@steipete-oai
steipete-oai requested a review from a team as a code owner June 13, 2026 09:00
@openclaw-barnacle openclaw-barnacle Bot added docs Improvements or additions to documentation gateway Gateway runtime size: S maintainer Maintainer-authored PR labels Jun 13, 2026
@clawsweeper

clawsweeper Bot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Codex review: needs real behavior proof before merge. Reviewed June 13, 2026, 5:07 AM ET / 09:07 UTC.

Summary
The PR tightens x-openclaw-model authorization across OpenAI-compatible chat, Responses, and embeddings Gateway endpoints, adds regression tests, and updates Gateway docs.

PR surface: Source +42, Tests +111, Docs +1. Total +154 across 11 files.

Reproducibility: yes. from source inspection: current main lets an identity-bearing operator.write request pass chat.send scope checks and then passes x-openclaw-model into the model override path. I did not run live repro commands because this review is read-only.

Review metrics: 1 noteworthy metric.

  • Header auth contract: 1 owner-level HTTP header tightened. x-openclaw-model changes from usable by narrowed identity-bearing write callers to admin-only, which is a compatibility decision before merge.

Stored data model
Persistent data-model change detected: serialized state: src/gateway/embeddings-http.test.ts, vector/embedding metadata: src/gateway/embeddings-http.test.ts. Confirm migration or upgrade compatibility proof before merge.

Merge readiness
Overall: 🧂 unranked krab
Proof: 🧂 unranked krab
Patch quality: 🐚 platinum hermit
Result: blocked until real behavior proof from a real setup is added.

Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch.

Rank-up moves:

  • [P1] Add redacted real Gateway proof for shared-secret success, trusted admin success, and trusted write-only x-openclaw-model denial.
  • Consider mirroring the admin caveat in the OpenResponses and Gateway overview bullets so every header mention is self-contained.

Proof guidance:

  • [P1] Needs real behavior proof before merge: The PR body lists focused tests and failed remote proof attempts, but no after-fix real Gateway output showing the write-only denial and admin/shared-secret success; add redacted terminal output or logs, then update the PR body to trigger a fresh ClawSweeper review or ask for @clawsweeper re-review.

Risk before merge

  • [P1] Merging intentionally changes existing identity-bearing HTTP callers that narrow scopes and send x-openclaw-model from allowed behavior to 403 missing scope: operator.admin, so maintainers need to accept that upgrade break.
  • [P1] No after-fix real Gateway proof is attached; the reported validation is focused tests plus failed remote proof attempts before OpenClaw code ran.

Maintainer options:

  1. Verify the fail-closed contract (recommended)
    Capture redacted curl or terminal proof against a real Gateway showing shared-secret success, trusted admin success, and trusted write-only 403 before merge.
  2. Land with an explicit upgrade note
    If maintainers accept the break, keep the fail-closed behavior and document that narrowed identity-bearing clients must add operator.admin or stop sending x-openclaw-model.
  3. Pause for a compatibility design
    If write-only identity-bearing overrides are considered supported, pause this PR and redesign around a migration window or explicit strict mode.

Next step before merge

  • [P1] Protected maintainer label, auth-boundary compatibility risk, and missing real behavior proof make this a maintainer-review item rather than an automated repair candidate.

Security
Cleared: The diff tightens an existing authorization boundary and does not add dependencies, workflows, secret handling, package metadata, or code download/execution paths.

Review details

Best possible solution:

Adopt the fail-closed owner/admin contract after maintainer acceptance of the compatibility impact, with redacted real Gateway proof and docs that make the header requirement clear wherever the header is documented.

Do we have a high-confidence way to reproduce the issue?

Yes, from source inspection: current main lets an identity-bearing operator.write request pass chat.send scope checks and then passes x-openclaw-model into the model override path. I did not run live repro commands because this review is read-only.

Is this the best way to solve the issue?

Yes, with one merge gate: centralizing the owner/admin check and applying it before all three compat endpoints consume x-openclaw-model is the clean boundary. The remaining question is maintainer acceptance of the compatibility break plus real Gateway proof.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 1c655008cd0c.

Label changes

Label changes:

  • add P2: This is a bounded Gateway auth hardening PR with compatibility impact but no evidence of an active P0/P1 outage.
  • add merge-risk: 🚨 compatibility: Existing narrowed identity-bearing clients that currently send x-openclaw-model will start receiving 403 after merge.
  • add merge-risk: 🚨 auth-provider: The PR changes authorization for model-choice routing on OpenAI-compatible HTTP requests.
  • add rating: 🧂 unranked krab: Overall readiness is 🧂 unranked krab; proof is 🧂 unranked krab and patch quality is 🐚 platinum hermit.
  • add status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs real behavior proof before merge: The PR body lists focused tests and failed remote proof attempts, but no after-fix real Gateway output showing the write-only denial and admin/shared-secret success; add redacted terminal output or logs, then update the PR body to trigger a fresh ClawSweeper review or ask for @clawsweeper re-review.

Label justifications:

  • P2: This is a bounded Gateway auth hardening PR with compatibility impact but no evidence of an active P0/P1 outage.
  • merge-risk: 🚨 compatibility: Existing narrowed identity-bearing clients that currently send x-openclaw-model will start receiving 403 after merge.
  • merge-risk: 🚨 auth-provider: The PR changes authorization for model-choice routing on OpenAI-compatible HTTP requests.
  • rating: 🧂 unranked krab: Overall readiness is 🧂 unranked krab; proof is 🧂 unranked krab and patch quality is 🐚 platinum hermit.
  • status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs real behavior proof before merge: The PR body lists focused tests and failed remote proof attempts, but no after-fix real Gateway output showing the write-only denial and admin/shared-secret success; add redacted terminal output or logs, then update the PR body to trigger a fresh ClawSweeper review or ask for @clawsweeper re-review.
Evidence reviewed

PR surface:

Source +42, Tests +111, Docs +1. Total +154 across 11 files.

View PR surface stats
Area Files Added Removed Net
Source 5 47 5 +42
Tests 4 114 3 +111
Docs 2 7 6 +1
Config 0 0 0 0
Generated 0 0 0 0
Other 0 0 0 0
Total 11 168 14 +154

What I checked:

Likely related people:

  • joshavant: Blame and PR history show the current OpenAI-compatible Gateway HTTP auth/model override implementation and docs came from commit f3eb8e9714 via Fix OTLP log trace correlation #92276. (role: recent area contributor; confidence: high; commits: f3eb8e9714d8; files: src/gateway/http-auth-utils.ts, src/gateway/http-utils.ts, src/gateway/openai-http.ts)
What the crustacean ranks mean
  • 🦀 challenger crab: rare, exceptional readiness with strong proof, clean implementation, and convincing validation.
  • 🦞 diamond lobster: very strong readiness with only minor maintainer review expected.
  • 🐚 platinum hermit: good normal PR, likely mergeable with ordinary maintainer review.
  • 🦐 gold shrimp: useful signal, but proof or patch confidence is still limited.
  • 🦪 silver shellfish: thin signal; proof, validation, or implementation needs work.
  • 🧂 unranked krab: not merge-ready because proof is missing/unusable or there are serious correctness or safety concerns.
  • 🌊 off-meta tidepool: rating does not apply to this item.

Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

How this review workflow works
  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

@steipete-oai

Copy link
Copy Markdown
Contributor Author

Land-ready proof for 02eb3c9b7f5de5eea5ae8b91569976a86533ac74:

  • Local format sanity: git diff --check
  • Focused regression suite: node scripts/run-vitest.mjs src/gateway/http-utils.request-context.test.ts src/gateway/openai-http.test.ts src/gateway/openresponses-http.test.ts src/gateway/embeddings-http.test.ts -> 13 files / 235 tests passed
  • Fresh autoreview: clean, no accepted/actionable findings
  • CI at head is clean, including security-fast, Security High shards, Critical Quality core-auth-secrets, changed-path scan, lint/types/docs/build/check shards

Known proof gap: fresh remote Linux devbox proof could not reach OpenClaw runtime because dependency install failed before project code ran. No OpenClaw failure was observed there; local focused tests plus the full PR CI matrix are green.

@clawsweeper clawsweeper Bot added rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. P2 Normal backlog priority with limited blast radius. merge-risk: 🚨 compatibility 🚨 May break existing users, config, migrations, defaults, or upgrade paths. labels Jun 13, 2026
@steipete-oai
steipete-oai merged commit 26b9736 into main Jun 13, 2026
206 of 212 checks passed
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 auth-provider 🚨 May break OAuth, tokens, provider routing, model choice, or credentials. label Jun 13, 2026
@steipete-oai
steipete-oai deleted the codex/openclaw-security-audit branch June 13, 2026 09:08
@eleqtrizit

eleqtrizit commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

Behavioral proof

Real Gateway HTTP proof refreshed against current main on June 15, 2026. The proof started loopback Gateway servers with the OpenAI-compatible chat, Responses, and embeddings endpoints enabled:

  • shared-secret server: auth: { mode: "token" }; bearer value redacted below
  • trusted identity-bearing server: auth: { mode: "none" }; request scopes supplied through x-openclaw-scopes

Command run:

OPENCLAW_VITEST_MAX_WORKERS=1 node scripts/run-vitest.mjs src/gateway/model-override-behavior-proof.test.ts --config test/vitest/vitest.gateway-server.config.ts --reporter=verbose

Result:

Test Files  1 passed (1)
Tests       1 passed (1)

Redacted terminal output from the proof run:

{
  "label": "/v1/chat/completions shared-secret bearer allows x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/chat/completions",
  "requestHeaders": {
    "authorization": "Bearer REDACTED",
    "x-openclaw-model": "openai/gpt-5.4",
    "x-openclaw-scopes": "operator.write"
  },
  "status": 200,
  "observedModel": "openai/gpt-5.4",
  "response": { "ok": true, "object": "chat.completion" }
}
{
  "label": "/v1/chat/completions trusted admin allows x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/chat/completions",
  "requestHeaders": {
    "x-openclaw-model": "openai/gpt-5.4",
    "x-openclaw-scopes": "operator.admin, operator.write"
  },
  "status": 200,
  "observedModel": "openai/gpt-5.4",
  "response": { "ok": true, "object": "chat.completion" }
}
{
  "label": "/v1/chat/completions trusted write-only rejects x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/chat/completions",
  "requestHeaders": {
    "x-openclaw-model": "openai/gpt-5.4",
    "x-openclaw-scopes": "operator.write"
  },
  "status": 403,
  "observedModel": null,
  "response": {
    "ok": false,
    "error": { "type": "forbidden", "message": "missing scope: operator.admin" }
  }
}
{
  "label": "/v1/responses shared-secret bearer allows x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/responses",
  "requestHeaders": {
    "authorization": "Bearer REDACTED",
    "x-openclaw-model": "openai/gpt-5.4",
    "x-openclaw-scopes": "operator.write"
  },
  "status": 200,
  "observedModel": "openai/gpt-5.4",
  "response": { "ok": true, "object": "response" }
}
{
  "label": "/v1/responses trusted admin allows x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/responses",
  "requestHeaders": {
    "x-openclaw-model": "openai/gpt-5.4",
    "x-openclaw-scopes": "operator.admin, operator.write"
  },
  "status": 200,
  "observedModel": "openai/gpt-5.4",
  "response": { "ok": true, "object": "response" }
}
{
  "label": "/v1/responses trusted write-only rejects x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/responses",
  "requestHeaders": {
    "x-openclaw-model": "openai/gpt-5.4",
    "x-openclaw-scopes": "operator.write"
  },
  "status": 403,
  "observedModel": null,
  "response": {
    "ok": false,
    "error": { "type": "forbidden", "message": "missing scope: operator.admin" }
  }
}
{
  "label": "/v1/embeddings shared-secret bearer allows x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/embeddings",
  "requestHeaders": {
    "authorization": "Bearer REDACTED",
    "x-openclaw-model": "openai/text-embedding-3-small",
    "x-openclaw-scopes": "operator.write"
  },
  "status": 200,
  "observedModel": "text-embedding-3-small",
  "response": { "ok": true, "object": "list" }
}
{
  "label": "/v1/embeddings trusted admin allows x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/embeddings",
  "requestHeaders": {
    "x-openclaw-model": "openai/text-embedding-3-small",
    "x-openclaw-scopes": "operator.admin, operator.write"
  },
  "status": 200,
  "observedModel": "text-embedding-3-small",
  "response": { "ok": true, "object": "list" }
}
{
  "label": "/v1/embeddings trusted write-only rejects x-openclaw-model",
  "command": "curl -sS -i -X POST http://127.0.0.1:<port>/v1/embeddings",
  "requestHeaders": {
    "x-openclaw-model": "openai/text-embedding-3-small",
    "x-openclaw-scopes": "operator.write"
  },
  "status": 403,
  "observedModel": null,
  "response": {
    "ok": false,
    "error": { "type": "forbidden", "message": "missing scope: operator.admin" }
  }
}

This proves the requested after-fix contract on the real Gateway HTTP path: shared-secret bearer callers keep model override behavior, trusted admin callers keep model override behavior, and trusted write-only callers fail closed with 403 missing scope: operator.admin before model dispatch on all three OpenAI-compatible endpoints.

@eleqtrizit

Copy link
Copy Markdown
Contributor

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Command router queued. I will update this comment with the next step.

@eleqtrizit

Copy link
Copy Markdown
Contributor

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Command router queued. I will update this comment with the next step.

@eleqtrizit

Copy link
Copy Markdown
Contributor

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Command router queued. I will update this comment with the next step.

eleboucher pushed a commit to eleboucher/homelab that referenced this pull request Jun 16, 2026
…26.6.8) (#1144)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/openclaw/openclaw](https://openclaw.ai) ([source](https://github.com/openclaw/openclaw)) | patch | `2026.6.6` → `2026.6.8` |

---

### Release Notes

<details>
<summary>openclaw/openclaw (ghcr.io/openclaw/openclaw)</summary>

### [`v2026.6.8`](https://github.com/openclaw/openclaw/blob/HEAD/CHANGELOG.md#202668)

[Compare Source](openclaw/openclaw@v2026.6.6...v2026.6.8)

##### Highlights

- Telegram and WhatsApp channel delivery are richer and less brittle: Telegram can send structured rich text with tables, lists, expandable blockquotes, prompt-preserving CLI backend delivery, retired native draft migration, and safer rich-media boundaries, while WhatsApp now honors configured ACP bindings. ([#&#8203;92679](openclaw/openclaw#92679), [#&#8203;84082](openclaw/openclaw#84082), [#&#8203;89421](openclaw/openclaw#89421), [#&#8203;92513](openclaw/openclaw#92513)) Thanks [@&#8203;obviyus](https://github.com/obviyus), [@&#8203;jzakirov](https://github.com/jzakirov), [@&#8203;spacegeologist](https://github.com/spacegeologist), and [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle).
- Agent and Gateway recovery is sharper across account-scoped DM sends, generated media completions, restart shutdown aborts, yielded subagent pauses, yielded cron media, heartbeat dedupe, session identity prompts, and unknown OpenAI agent selector rejection. ([#&#8203;92788](openclaw/openclaw#92788), [#&#8203;91246](openclaw/openclaw#91246), [#&#8203;91357](openclaw/openclaw#91357), [#&#8203;92631](openclaw/openclaw#92631), [#&#8203;92146](openclaw/openclaw#92146), [#&#8203;91287](openclaw/openclaw#91287), [#&#8203;92468](openclaw/openclaw#92468), [#&#8203;92510](openclaw/openclaw#92510)) Thanks [@&#8203;yetval](https://github.com/yetval), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;ooiuuii](https://github.com/ooiuuii), [@&#8203;openperf](https://github.com/openperf), [@&#8203;IWhatsskill](https://github.com/IWhatsskill), [@&#8203;ZengWen-DT](https://github.com/ZengWen-DT), and [@&#8203;zhangguiping-xydt](https://github.com/zhangguiping-xydt).
- Provider/model handling expands and tightens with GLM-5.2, Claude Haiku 4.5 catalog rows, OpenRouter and Google Vertex provider-prefix normalization, managed SecretRef auth, bounded model browse discovery, storeless OpenAI Responses replay gating, and Claude 4.5 Copilot tool-streaming safety. ([#&#8203;92796](openclaw/openclaw#92796), [#&#8203;90116](openclaw/openclaw#90116), [#&#8203;92627](openclaw/openclaw#92627), [#&#8203;91218](openclaw/openclaw#91218), [#&#8203;90686](openclaw/openclaw#90686), [#&#8203;92247](openclaw/openclaw#92247), [#&#8203;90706](openclaw/openclaw#90706), [#&#8203;75393](openclaw/openclaw#75393)) Thanks [@&#8203;arkyu2077](https://github.com/arkyu2077), [@&#8203;liuhao1024](https://github.com/liuhao1024), [@&#8203;bymle](https://github.com/bymle), [@&#8203;rohitjavvadi](https://github.com/rohitjavvadi), [@&#8203;samson910022](https://github.com/samson910022), [@&#8203;snowzlm](https://github.com/snowzlm), and [@&#8203;Kailigithub](https://github.com/Kailigithub).
- `/usage` and reply payload hooks now have a native full footer renderer, default template, fixed-decimal formatting, credential-aware limits, better partial-count handling, and warnings for broken templates instead of silent bad output. ([#&#8203;92657](openclaw/openclaw#92657), [#&#8203;89835](openclaw/openclaw#89835), [#&#8203;89629](openclaw/openclaw#89629)) Thanks [@&#8203;Marvinthebored](https://github.com/Marvinthebored).
- UI and mobile flows are steadier: workspace files can collapse and start collapsed, WebChat backscroll survives streaming, the sidebar session picker remains interactive above the desktop workbench, reset soft args survive UI dispatch, stale dashboard session parent lineage is preserved, and iOS reconnects stale foreground gateways. ([#&#8203;92779](openclaw/openclaw#92779), [#&#8203;92622](openclaw/openclaw#92622), [#&#8203;92705](openclaw/openclaw#92705), [#&#8203;91353](openclaw/openclaw#91353), [#&#8203;90658](openclaw/openclaw#90658), [#&#8203;92552](openclaw/openclaw#92552)) Thanks [@&#8203;shakkernerd](https://github.com/shakkernerd), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;NianJiuZst](https://github.com/NianJiuZst), [@&#8203;zhouhe-xydt](https://github.com/zhouhe-xydt), [@&#8203;luoyanglang](https://github.com/luoyanglang), and [@&#8203;Solvely-Colin](https://github.com/Solvely-Colin).
- Memory, state, and diagnostics recover cleaner: oversized OpenAI embedding batches split before 431s, QMD memory search stays available in transient mode, SQLite avoids WAL on NFS state volumes, stuck-session recovery scheduling no longer resets warning backoff, and Infinity chunk limits stay genuinely unbounded. ([#&#8203;92650](openclaw/openclaw#92650), [#&#8203;92618](openclaw/openclaw#92618), [#&#8203;92639](openclaw/openclaw#92639), [#&#8203;91247](openclaw/openclaw#91247), [#&#8203;92752](openclaw/openclaw#92752), [#&#8203;92735](openclaw/openclaw#92735)) Thanks [@&#8203;mushuiyu886](https://github.com/mushuiyu886), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;849261680](https://github.com/849261680), [@&#8203;gnanam1990](https://github.com/gnanam1990), and [@&#8203;yhterrance](https://github.com/yhterrance).

##### Changes

- Providers/models: add GLM-5.2 support and Claude Haiku 4.5 catalog entries while keeping provider-qualified model IDs normalized across OpenRouter and Google Vertex paths. ([#&#8203;92796](openclaw/openclaw#92796), [#&#8203;90116](openclaw/openclaw#90116), [#&#8203;92627](openclaw/openclaw#92627), [#&#8203;91218](openclaw/openclaw#91218)) Thanks [@&#8203;arkyu2077](https://github.com/arkyu2077), [@&#8203;liuhao1024](https://github.com/liuhao1024), and [@&#8203;bymle](https://github.com/bymle).
- Channel plugins: ship Telegram rich-message delivery and WhatsApp ACP binding support, including rich prompt handoff to CLI backends and transport fixtures for richer drafts. ([#&#8203;92679](openclaw/openclaw#92679), [#&#8203;92513](openclaw/openclaw#92513)) Thanks [@&#8203;obviyus](https://github.com/obviyus) and [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle).
- Agent commands: support `/btw` in CLI-backed sessions and keep CLI usage-error exits classified as usage failures instead of successful runs. ([#&#8203;92669](openclaw/openclaw#92669), [#&#8203;92162](openclaw/openclaw#92162)) Thanks [@&#8203;joshavant](https://github.com/joshavant) and [@&#8203;Pandah97](https://github.com/Pandah97).
- Usage hooks: add built-in full footer rendering, default footer templates, per-turn usage state, credential-aware limits, and fixed-decimal formatting for usage-bar templates. ([#&#8203;92657](openclaw/openclaw#92657), [#&#8203;89835](openclaw/openclaw#89835), [#&#8203;89629](openclaw/openclaw#89629)) Thanks [@&#8203;Marvinthebored](https://github.com/Marvinthebored).
- Docs and operator guidance: document node config examples, clarify before-install hook scope, correct agent default concurrency comments, refresh ZAI provider docs, and update channel/group docs for current Telegram and WhatsApp behavior. ([#&#8203;92677](openclaw/openclaw#92677), [#&#8203;92766](openclaw/openclaw#92766), [#&#8203;92695](openclaw/openclaw#92695)) Thanks [@&#8203;liuhao1024](https://github.com/liuhao1024), [@&#8203;sallyom](https://github.com/sallyom), and [@&#8203;ArielSmoliar](https://github.com/ArielSmoliar).

##### Fixes

- Onboarding/skills: show the Homebrew install recommendation only on macOS and Linux, so FreeBSD and other unsupported platforms no longer get a misleading brew prompt. Fixes [#&#8203;68893](openclaw/openclaw#68893); carries forward [#&#8203;68894](openclaw/openclaw#68894), [#&#8203;68910](openclaw/openclaw#68910), [#&#8203;68941](openclaw/openclaw#68941), [#&#8203;68943](openclaw/openclaw#68943), [#&#8203;69002](openclaw/openclaw#69002), and [#&#8203;69545](openclaw/openclaw#69545). Thanks [@&#8203;yurivict](https://github.com/yurivict), [@&#8203;Sanjays2402](https://github.com/Sanjays2402), [@&#8203;Eruditi](https://github.com/Eruditi), [@&#8203;JustInCache](https://github.com/JustInCache), [@&#8203;nnish16](https://github.com/nnish16), and [@&#8203;Mlightsnow](https://github.com/Mlightsnow).
- Channels and delivery: preserve account-scoped DM channel send policy, rich Telegram final replies, rich Telegram tables and lists, Telegram thread-create CLI remapping, Slack outbound `message_sent` hooks, contributed message-tool schema optionality, same-channel generated media completions, and channel chunking around surrogate pairs and Infinity limits. ([#&#8203;92788](openclaw/openclaw#92788), [#&#8203;92679](openclaw/openclaw#92679), [#&#8203;89421](openclaw/openclaw#89421), [#&#8203;89943](openclaw/openclaw#89943), [#&#8203;91137](openclaw/openclaw#91137), [#&#8203;91246](openclaw/openclaw#91246), [#&#8203;92735](openclaw/openclaw#92735)) Thanks [@&#8203;yetval](https://github.com/yetval), [@&#8203;obviyus](https://github.com/obviyus), [@&#8203;spacegeologist](https://github.com/spacegeologist), [@&#8203;rishitamrakar](https://github.com/rishitamrakar), [@&#8203;lundog](https://github.com/lundog), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), and [@&#8203;yhterrance](https://github.com/yhterrance).
- Auto-reply/groups: keep ordinary group text replies on automatic final-reply delivery while allowing `message(action=send)` for files, images, and other attachments to the same group or topic. Carries forward [#&#8203;43276](openclaw/openclaw#43276); refs [#&#8203;48004](openclaw/openclaw#48004). Thanks [@&#8203;NayukiChiba](https://github.com/NayukiChiba) and [@&#8203;ShakaRover](https://github.com/ShakaRover).
- Auto-reply/skills: preserve multiline payloads for `/skill` and direct skill slash commands while keeping command-head normalization for aliases, colon syntax, and bot mentions. Fixes [#&#8203;79155](openclaw/openclaw#79155); carries forward [#&#8203;81305](openclaw/openclaw#81305). Thanks [@&#8203;web3blind](https://github.com/web3blind).
- iMessage: normalize leading NUL sent-message echo prefixes while preserving interior NUL bytes and the leading attributedBody marker handling from [#&#8203;73942](openclaw/openclaw#73942). Carries forward [#&#8203;63581](openclaw/openclaw#63581). Thanks [@&#8203;drvoss](https://github.com/drvoss).
- Discord: give generated auto-thread titles a 60-second timeout and 4,096-token reasoning-model output budget, clamped to the selected model output cap. ([#&#8203;64734](openclaw/openclaw#64734)) Thanks [@&#8203;hanamizuki](https://github.com/hanamizuki).
- Agent, cron, and Gateway runtime: mark active main sessions before restart shutdown aborts, pause yielded subagent runs whose terminal also signals abort, preserve yielded media completions, de-duplicate main-session heartbeat events, expose session identity in runtime prompts, reject unknown OpenAI agent selectors, keep generated media completions and slash-command block replies in WebChat, preserve fresh post-compaction usage while clearing stale usage snapshots, and require admin privileges for HTTP session/model override surfaces. ([#&#8203;91357](openclaw/openclaw#91357), [#&#8203;92631](openclaw/openclaw#92631), [#&#8203;92146](openclaw/openclaw#92146), [#&#8203;91287](openclaw/openclaw#91287), [#&#8203;92468](openclaw/openclaw#92468), [#&#8203;92510](openclaw/openclaw#92510), [#&#8203;91246](openclaw/openclaw#91246), [#&#8203;50795](openclaw/openclaw#50795), [#&#8203;50845](openclaw/openclaw#50845), [#&#8203;82874](openclaw/openclaw#82874), [#&#8203;92651](openclaw/openclaw#92651), [#&#8203;92646](openclaw/openclaw#92646)) Thanks [@&#8203;ooiuuii](https://github.com/ooiuuii), [@&#8203;openperf](https://github.com/openperf), [@&#8203;IWhatsskill](https://github.com/IWhatsskill), [@&#8203;ZengWen-DT](https://github.com/ZengWen-DT), [@&#8203;zhangguiping-xydt](https://github.com/zhangguiping-xydt), [@&#8203;Hollychou924](https://github.com/Hollychou924), [@&#8203;leno23](https://github.com/leno23), and [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle).
- Agents/exec: default empty-success background completion notices on only for real chat channels, preserving explicit opt-outs and keeping generic providers silent while carrying forward the narrow UX intent from [#&#8203;39726](openclaw/openclaw#39726) and [#&#8203;46926](openclaw/openclaw#46926). Thanks [@&#8203;Sapientropic](https://github.com/Sapientropic) and [@&#8203;wenkang-xie](https://github.com/wenkang-xie).
- Providers and model replay: preserve storeless OpenAI Responses replay compatibility, avoid eager tool streaming for Claude 4.5 in Copilot, honor profile auth for SecretRef model entries, bound model browsing, strip provider prefixes where runtimes need bare IDs, and surface nested embedding fetch failures. ([#&#8203;90706](openclaw/openclaw#90706), [#&#8203;75393](openclaw/openclaw#75393), [#&#8203;90686](openclaw/openclaw#90686), [#&#8203;92247](openclaw/openclaw#92247), [#&#8203;92627](openclaw/openclaw#92627), [#&#8203;91218](openclaw/openclaw#91218), [#&#8203;92628](openclaw/openclaw#92628)) Thanks [@&#8203;snowzlm](https://github.com/snowzlm), [@&#8203;Kailigithub](https://github.com/Kailigithub), [@&#8203;rohitjavvadi](https://github.com/rohitjavvadi), [@&#8203;samson910022](https://github.com/samson910022), [@&#8203;liuhao1024](https://github.com/liuhao1024), [@&#8203;bymle](https://github.com/bymle), and [@&#8203;mushuiyu886](https://github.com/mushuiyu886).
- Memory, state, diagnostics, and config: split header-too-large embedding batches, keep QMD memory search enabled in transient mode, avoid SQLite WAL on NFS volumes, preserve recovery scheduling outside stuck-session warning backoff, and keep shell environment fallbacks contained in config write tests. ([#&#8203;92650](openclaw/openclaw#92650), [#&#8203;92618](openclaw/openclaw#92618), [#&#8203;92639](openclaw/openclaw#92639), [#&#8203;91247](openclaw/openclaw#91247), [#&#8203;92752](openclaw/openclaw#92752)) Thanks [@&#8203;mushuiyu886](https://github.com/mushuiyu886), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;849261680](https://github.com/849261680), and [@&#8203;gnanam1990](https://github.com/gnanam1990).
- Workspace setup state: store setup completion outside the workspace dot directory using an OpenClaw-named root file, migrate valid legacy state forward, and avoid clobbering generic root `workspace-state.json` files for TigerFS-style dot-path compatibility. This Clownfish replacement carries forward the focused [#&#8203;53326](openclaw/openclaw#53326) fix idea because the original branch was closed and uneditable. ([#&#8203;53326](openclaw/openclaw#53326), [#&#8203;44783](openclaw/openclaw#44783), [#&#8203;39446](openclaw/openclaw#39446)) Thanks [@&#8203;1qh](https://github.com/1qh).
- UI/mobile/TUI: preserve dashboard session parent lineage, WebChat backscroll, reset soft command args, sidebar session picker interactivity, collapsed workspace files, resolved `/model` confirmation refs, and stale foreground iOS Gateway reconnects. ([#&#8203;90658](openclaw/openclaw#90658), [#&#8203;92622](openclaw/openclaw#92622), [#&#8203;91353](openclaw/openclaw#91353), [#&#8203;92705](openclaw/openclaw#92705), [#&#8203;92779](openclaw/openclaw#92779), [#&#8203;92773](openclaw/openclaw#92773), [#&#8203;92552](openclaw/openclaw#92552)) Thanks [@&#8203;luoyanglang](https://github.com/luoyanglang), [@&#8203;TurboTheTurtle](https://github.com/TurboTheTurtle), [@&#8203;zhouhe-xydt](https://github.com/zhouhe-xydt), [@&#8203;NianJiuZst](https://github.com/NianJiuZst), [@&#8203;shakkernerd](https://github.com/shakkernerd), [@&#8203;NarahariRaghava](https://github.com/NarahariRaghava), and [@&#8203;Solvely-Colin](https://github.com/Solvely-Colin).
- TUI: reload the active session after external `/new` or `/reset` session-change events so stale transcript and stream state clear promptly. Fixes [#&#8203;38966](openclaw/openclaw#38966); carries forward [#&#8203;40472](openclaw/openclaw#40472). Thanks [@&#8203;yizhanzjz](https://github.com/yizhanzjz) and [@&#8203;wsyjh8](https://github.com/wsyjh8).
- Control UI: preserve Gateway Access tokens during same-normalized WebSocket URL edits and reload gateway-scoped tokens when switching endpoints. Fixes [#&#8203;41545](openclaw/openclaw#41545); repairs [#&#8203;42001](openclaw/openclaw#42001) with additional source PRs [#&#8203;41546](openclaw/openclaw#41546), [#&#8203;41552](openclaw/openclaw#41552), and [#&#8203;41718](openclaw/openclaw#41718). Thanks [@&#8203;wsyjh8](https://github.com/wsyjh8), [@&#8203;llagy0020](https://github.com/llagy0020), [@&#8203;llagy007](https://github.com/llagy007), [@&#8203;pingfanfan](https://github.com/pingfanfan), and [@&#8203;zheliu2](https://github.com/zheliu2).
- Gateway CLI: tolerate a single transient clean WebSocket close before `hello-ok` so one-shot RPC calls reconnect instead of failing noisily, while repeated clean pre-hello closes still surface. Carries forward source PRs [#&#8203;54475](openclaw/openclaw#54475) and [#&#8203;54774](openclaw/openclaw#54774); [#&#8203;85253](openclaw/openclaw#85253) covered adjacent connect assembly diagnostics. Thanks [@&#8203;ruanrrn](https://github.com/ruanrrn).
- Gateway/Linux: keep root-owned systemd user service lifecycle commands on root's user manager when a stale `SUDO_USER` remains in a root shell with root's user bus environment. Fixes [#&#8203;81410](openclaw/openclaw#81410). Thanks [@&#8203;Ericksza](https://github.com/Ericksza) and [@&#8203;ChuckClose-tech](https://github.com/ChuckClose-tech).
- Release and test reliability: extend slow Gateway/full-suite watchdogs, split local full-suite shards when throttled, stabilize plugin auth marker fixtures, avoid brittle provider-ref error text, and keep QA Lab bootstrap selection assertions aligned with flow-only scenarios. ([#&#8203;92652](openclaw/openclaw#92652))
- macOS Peekaboo bridge: update the embedded Peekaboo package to 3.5.2 and route bundled-skill CLI commands through the OpenClaw app bridge so they inherit its Screen Recording and Accessibility grants.
- Agent routing: route subagent RPC callbacks addressed to an agent-shaped `--to` target to the correct session key instead of falling back to the main session, so WeChat (and other channel) session-key callbacks reach the intended subagent session. ([#&#8203;90231](openclaw/openclaw#90231)) Thanks [@&#8203;zhangguiping-xydt](https://github.com/zhangguiping-xydt).
- Cron: preserve model, fallback, thinking, timeout, light-context, unsafe-content, and tool allow-list overrides on implicit text payloads by promoting them to agent turns, while explicit system events still prune those fields. Fixes [#&#8203;28905](openclaw/openclaw#28905); carries forward [#&#8203;64060](openclaw/openclaw#64060) and [#&#8203;73946](openclaw/openclaw#73946). Thanks [@&#8203;liaoandi](https://github.com/liaoandi).
- QQBot delivery: keep markdown table chunks self-contained across message boundaries by preserving table state across block deliveries, flushing unfinished table-row fragments as plain text, and detecting short pipe-terminated rows by column count so split rows are not sent as malformed markdown. ([#&#8203;92428](openclaw/openclaw#92428)) Thanks [@&#8203;sliverp](https://github.com/sliverp).

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEwMS4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->

Reviewed-on: https://git.erwanleboucher.dev/eleboucher/homelab/pulls/1144
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

docs Improvements or additions to documentation gateway Gateway runtime maintainer Maintainer-authored PR merge-risk: 🚨 auth-provider 🚨 May break OAuth, tokens, provider routing, model choice, or credentials. merge-risk: 🚨 compatibility 🚨 May break existing users, config, migrations, defaults, or upgrade paths. P2 Normal backlog priority with limited blast radius. rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. size: S status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants