Skip to content

[pull] main from openclaw:main - #198

Open
pull[bot] wants to merge 3958 commits into
vibecoder11200:mainfrom
openclaw:main
Open

pull[bot] wants to merge 3958 commits into
vibecoder11200:mainfrom
openclaw:main

Conversation

@pull

@pull pull Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

@pull pull Bot locked and limited conversation to collaborators Sep 30, 2026
@pull pull Bot added the ⤵️ pull label Sep 30, 2026
roboclaw-bot and others added 28 commits October 7, 2026 17:23
* fix(ui): clear collaborator typing previews when sending with Enter

Route keyboard, goal, and command-menu submissions through the composer submission owner so typing stops before dispatch and queued draft previews cannot survive the send.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): typing previews remain after sending with Enter

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: bf59bff1-af0e-4ea4-9ccb-e09c0d7027e1

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Remove obsolete Bun-only guards from scheduled and connection work coverage, read-only SQLite credential transports, and the shared broker fixture. Keep the existing Windows exclusions.

Linux proof: 230 tests per runtime on Bun 667c, Bun fc53, and Node 24.19.0, without skips. Scoped P2 review and focused lint/type checks pass; the baseline dead-export finding in publish-model-catalog remains documented.
Resolve bare Slack channel names in allowlists through the channel directory instead of treating them as channel IDs, while real IDs (including lowercase letter-second ones such as ca1234567) keep ID-first precedence, so a channel named like an ID cannot shadow the real one.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
…166841)

Use explicit source and exec captures in the prefilter and vendor guards.
This preserves read order and method identity while allowing type-aware
lint to check the code without expanding the approved suppression tail.

Combine adjacent null and deduplication guards in pattern resolution to
keep the existing line-count ratchet without changing resolution behavior.
Pass only a real source session to outbound session policy lookup for cron command announcements, so the synthetic cron notification key no longer aborts the lookup, logs "Session key does not contain an agent id" on every delivery, and skips persisting the destination session route. Reported by @JLahullier.

Fixes #166805.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(gateway): settle terminal runs before session mutations

Let manual compaction and history edits join existing terminal writers with a bounded wait outside lifecycle locks. Stop retaining session execution admission for metadata-only chat title generation. Preserve active and queued work exclusion and revalidate session ownership after settlement.

* fix(gateway): scope terminal settlement to captured owners
* refactor: remove experimental fleet management

* test(audit): reconstruct retired tables for pinned reader proof

* refactor: remove retired fleet diagnostics classification

* fix(catalog): keep recommended model reader internal

* test(memory): expect revoked transcript reservation to reject

* fix(test): run Telegram model callbacks with the SQLite host

(cherry picked from commit 87f1383)

* docs(database): refresh worker access inventory after rebase

* refactor(sessions): keep cold turn guard type internal

* fix(sessions): preserve transcript owner across storage resolution

---------

Co-authored-by: Dallin Romney <dallinromney@gmail.com>
Remove obsolete timer-resource and matcher guards, and the old revision-specific module-sync gate. Preserve existing assertions and timeout budgets.

Linux Node 24.19 and Bun 667c4ab22c/fc53bf8c0f each pass all 91 focused cases with zero skips.
Culprit de7c3b7 (#166539) moved health device-identity reads into the
shared SQLite worker. The threaded wizard fixture lacks its host broker.
Register the unchanged test with the existing isolated fork-based owner,
preserving real health authentication and ambient-endpoint isolation.

Validation: focused finalization/health/Doctor tests, whole wizard and
unit-fast configs, registry and planner guards, full test-types, typed and
boundary lint, complete check-changed, four real manifest shapes, and P2.
Whole tooling completed with 941 files passed and 7 skipped; its sole
failure is the inherited logging-suppression inventory from #166701.

Full infra config gate waived by coordinator: fleet at cap; registry/planner/tooling proof passed
Advance the shared CI and app Bun runtime from 667c to fc53, bringing worker heap-cap termination, GC cadence and idle-collector wakeup fixes. Regenerate the four Darwin/Linux artifact pins from the verified release manifest and update the current-pin documentation.

Gate A and the exact-tag Mac gate passed. Retain the UI known intermittent (#166780) and the baseline-only database teardown failure already fixed on main; their raw outcomes remain recorded under the qualification dispositions. No consumer admissions are added.

Verified with paired CI selections, 285 targeted invocations, Node-hidden Linux x64 smoke, supplemental JSC checks, Darwin runtime qualification, focused Node/Bun staging tests, changed-file checks, exact-head CI, and completed P2/ClawSweeper reviews.
…ry (#157739)

Closes #157782
Related: #157783 (declaration-stage memory; not addressed here)

## What Problem This Solves

`pnpm build` thrashes or is OOM-killed on hosts with about 10GB of memory during the `tsdown-unified` step. Since the unified group emits one tsdown config per bundled plugin (#144252), that runtime-only invocation admits all configs at once. The memory that grows is Rolldown's native allocation, so `OPENCLAW_TSDOWN_MAX_OLD_SPACE_MB` cannot bound it.

## Fix

`scripts/tsdown-build.mts` already honors an explicit `--concurrency`. The `tsdown-unified` step in `scripts/build-all.mts` now passes `--concurrency 1`. Same output, serial admission; each bundle keeps its internal parallelism.

## User Impact

The `tsdown-unified` step peaks at roughly half its previous memory, at the cost of a few seconds of extra step time. This does not by itself make a full cold build fit 10GB: native declaration compilers still peak higher and are tracked separately (#157783).

## Evidence

Contributor measurements (Ubuntu 26.04, Node 24.21.0, per-process RSS sampled every 2s during `pnpm build`):

| Checkout | `tsdown-unified` peak RSS | step time |
|---|---|---|
| main `0963fd5da97`, defaults | 9.2GB / 9.5GB (two runs) | 32–35s |
| main, `OPENCLAW_TSDOWN_MAX_OLD_SPACE_MB=4352` | 9.5GB | 35s |
| `ef9be3d8cfa` (before per-plugin configs) | 4.6GB | 19s |
| this branch (`--concurrency 1`) | 4.5GB | 50s |

Maintainer re-measurement on a Linux 32-vCPU builder (Node 24.21.0, tsdown 0.23.0, Rolldown 1.2.9), three runs each:

| Runtime policy | Median process-tree RSS | Median elapsed |
|---|---:|---:|
| Default | 10.86GiB | 28.6s |
| `--concurrency 1` | 6.11GiB | 34.0s |

- All 14,293 runtime output paths matched by hash, mode and symlink target across default/1/2/4 runs.
- Tracing observed 46 simultaneously admitted configs by default and 1 with this change.
- Full `pnpm build` from a clean `dist` completes on this branch.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(agents): reconcile interrupted subagents at startup

Settle restored interruptions after requester ownership transfer through the existing recovery coordinator and sweep overlap guard. Respect the Gateway crash-loop recovery pause and retry through scheduled maintenance, preserving owner checks after preparation.

Share restart outcome guidance between main-session recovery and retained native-child follow-ups without duplicating failure diagnostics. Preserve parent delivery retries across lifecycle consolidation and use the active collector capacity fence in the restored FIFO fixture.

* fix(agents): restore recovery runtime fixture type import
* fix(exec): advertise hosts supported by the session

No-sandbox sessions no longer advertise sandbox in direct exec schemas or code-mode index and describe output. Capture available choices once from the sandbox descriptor and configured host policy, sharing the existing override predicate across schema and runtime owners.

Keep authoritative runtime host rejection through the existing execution-schema binding. Cover parent and depth-1 child contracts, eager and lazy factories, sandbox and host-policy variants, and code-mode rejection/no-start behavior. Preserve metadata when instrumenting the existing subscribed-denial fixture.

* test(exec): align host guidance and completion surface coverage

* test(exec): compare prepared surfaces under matching host policy
Connect native iOS Gateway sockets and media through origin-bound Cloudflare Access admission. Preserve setup expiry, pending-work authority and unrelated ordinary routes. Settings sign-out and recovery guidance follow the focused saved profile, not manual-editor drafts.

Integrate the landed ingress prerequisite with a normal signed merge. Preserve unified autoconnect suppression and resolved-TLS selection before preflight; adapt HTTP fixture policies to the serial transport queue.

Published head 931ad46: CI run37709550960 passed (70 successful,14 skipped), iOS and shared Periphery passed including iOS build-for-testing, and iPhone/iPad screenshot jobs passed. Local workflow/lifecycle707tests passed; formatting, canonical iOS lint and inventory passed. Complete independent review has no unresolved actionable introduced defect; its repeated parser allegation was rejected against unchanged source and original Xcode27 execution.

Historical native/TLS/fleet/UI and reported physical revocation/chat proof retain their executing-source identity. The two new Swift regressions were not separately executed locally; elapsed-expiry and complete shared-participant final-I/O coverage remain bounded gaps. ClawSweeper remains Gold with those proof concerns, not a demonstrated bypass. Josh Avant approved prior head749ba0; GitHub automatically dismissed that review on base retarget. Current native admission rechecks actual maintainer-author security clearance and enforced reviews, without bypass. Colin authorized landing after SecOps review.

Original implementation: @vincentkoc. Follow-up repair and validation: @Solvely-Colin.

## Work sessions

- [Original discussion with @Solvely-Colin](https://team.openclaw.ai/chat/roboclaw/dashboard/166bc07c-3b33-4d45-9700-82a7704c1934)
- [Implementation and verification](https://team.openclaw.ai/chat/roboclaw/dashboard/62ed399f-e69f-4559-b854-6fffa58e789a)

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
Co-authored-by: Solvely-Colin <211764741+Solvely-Colin@users.noreply.github.com>
Co-authored-by: Colin <colin@solvely.net>
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
Record the two existing unbound-method exceptions used only to compare exec identity. Their source comments already document why binding would invalidate the mutation check; no production suppression or assertion is added.

(cherry picked from commit 1249238ae2f61acfaa710e9fce863af7204117ba)
Post-ready metadata maintenance legitimately owns the plugin lifecycle lease. Disable that automatic scheduler only in the manual-RPC startup-error fixture; retain independent maintenance tests and all reload failure assertions.

(cherry picked from commit e418b4d040b0bcf1382978345167451ccd921b05)
)

* fix: preserve native prompt provenance through database aliases

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>

* fix: preserve catalog continuation data through instance binding

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>

* test(codex): use a junction for Windows database aliases

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>

* fix: preserve native hosted search policy without a managed provider

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>

* fix(codex): preserve hosted search bindings across restricted turns

Separate persistent hosted availability from the current native surface; keep policy and memory restrictions enforced. Prove the real unrestricted/restricted/unrestricted binding flow.

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>

* fix(test): join startup maintenance before plugin reload assertions

* refactor(codex): keep search-policy coverage within source line caps

---------

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
…essions"

This reverts commit 652d596. #166841 already removed both unbound-method
suppressions, so the added inventory entries made the exact-list test fail.
Keep remaining child sessions usable during deletion by separating server pagination membership from locally hidden rows.

Fixes #165958.
Allow Gateway startup after Doctor retains historical ACP metadata without a current binding. Preserve those rows unchanged and leave them unavailable to canonical runtime readers; continue refusing live unmigrated bindings, unreadable candidate stores, unresolved recorded ownership, and embedded metadata.

Verified exact-head CI 37711937122, including 7 startup admission, 25 Doctor key repair, and 14 legacy migration cases. Independent P0–P3 autoreview and ClawSweeper found no actionable defects.

Closes #166834

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* fix(ui): consolidate repeated browser connections in Activity

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* chore(ui): use explicit braces in presence proof

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): keep image actions outside preview content

Replace the obscuring image overlay with a right-side overflow menu while preserving tap-to-full-screen and full-resolution exports.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): preserve image layout across directions and mobile galleries

Settle modal entry animation before geometry assertions and retain image-surface sizing checks independently of the action gutter.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(sqlite): preserve admission during transcript tracker setup

Extend the checked TEMP tracking owner introduced in #166698 to the fixed
transcript-index status table, pending queue, index and enqueue triggers.
Installing these connection-local objects must not revoke the agent database's
main-schema admission receipt. Ordinary DDL, unexpected object shapes,
reentrant mutations and partial installation failures still revoke it.

Move the existing SQL into the typed builder and migrate both tracking callers
to its shared operation. Preserve local read revisions, rollback staging and
INSERT OR REPLACE behavior. No persisted schema, stored bytes, migration,
public SDK contract, retry or timeout changes.

The existing status-owner regression fails on the parent at first tracker
installation. All six owner cases pass after the repair (1.78s invocation),
including drift, rollback, foreign writes and bounded cleanup. P2 review is
clean. The broader restart investigation and Linux gates remain recorded in
the task evidence; this commit alone is not a claim that the QA race is fixed.

* fix(state): retain valid admission across concurrent opens

A startup reader can publish canonical proof before native admission starts.
A concurrent fully checked host open then registered the same database by
revoking that proof, rejecting the pending native receipt and failing the
post-restart turn before a provider request could begin.

Publish the checked opener's registration through the validation owner and
promote live proof without retiring its pending handoff. Keep physical-file
replacement and explicit lifecycle revocation strict. Reject stale required
schema receipts before they can replace newer facts, and retain the shared
schema revocation cell for matching live schemas. Accepted schema changes
and schema-optional revocation reports retire the displaced borrowers.

Regressions cover canonical and empty promotion, physical replacement,
revocation, delayed publication, and borrowed-schema retirement. All 36
receipt-owner cases pass (30.60s Vitest, 34.03s wrapper); the corresponding
negative controls failed before their repairs. P2 review is clean. Linux
pressure, owner-suite, and static gates are tracked separately before landing.
No stored data, schema version, public SDK, retry, or timeout changes.
Stop ordinary yielded commands with their selected Gateway request, wait for physical cleanup, and retain cleanup uncertainty after output eviction. Preserve explicitly independent services and suppress cancellation completion notifications.
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
steipete and others added 30 commits October 8, 2026 05:56
…166997)

* fix(logging): clear watchdog stagnation on completed tool execution

When a tool execution completes successfully under the current run owner,
clear repeated-request stagnation evidence so the watchdog does not abort
a run that recently did useful work. Previously, only model-call semantic
results could clear stagnation, so a response truncated by max_output_tokens
after successful async tool calls was treated as no progress.

Error and blocked tool terminals do not clear stagnation. Stale owner
events are rejected by runId comparison against the current embedded run.

Fixes #166770

* fix(agents): count completed tools under their live watchdog owner

Replace completion markers with exact owner provenance on the existing semantic-progress event. Capture before execution and validate at FIFO delivery; preserve failure and stale-owner stagnation. Drop unrelated backend changes and lint exceptions.

Co-authored-by: SunnyShu0925 <shu.zongyu@xydigit.com>

* test(agents): use the current tool schema dependency

* test(agents): align watchdog replay with production timing

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: SunnyShu0925 <shu.zongyu@xydigit.com>
Keep the public conversation document in a neutral loading state until its existing protected access probe resolves. Preserve successful authenticated handoff, confirmed denial, no-JavaScript fallback, and immediate public-access revocation without changing authorization or adding a hide timer.

Co-authored-by: jacobtomlinson <1610850+jacobtomlinson@users.noreply.github.com>
Consolidate Telegram command and callback context, delivery variants, polling and throttle bookkeeping, and cache traversal within the existing transport owners. Preserve user-visible text, configuration, protocol fields, persisted records, authorization, recovery, and public SDK contracts.

Remove 1,159 net production lines. Keep existing test assertions; three support lookups follow the consolidated registration seam.

Validation: full Telegram directory (167 files, 2,327 tests), changed-file checks, focused correction tests, strict package compilation, zero runtime/static cycles, unchanged SDK API, exact-head hosted CI, and the canonical Telegram Test Server lifecycle. The live recording includes same-message progress edits, successful tool execution, a separate persistent final reply, native reply linkage, and progress deletion. PR evidence retains earlier local failures and their limitations.
* refactor(ui): consolidate page rendering and state ownership

Share explicit page and panel variants, group agent file editor state, and
remove redundant presentation bookkeeping while retaining request scopes,
recovery behavior, protocol payloads, and visible text.

Migrate tests that referenced the retired internal seams and prune only the
assertion baseline entries removed by the refactor.

* refactor(ui): keep chat consolidation separate
Reject cron script and scratch input that is not valid UTF-8, from files or stdin, with a clear error, instead of silently storing U+FFFD-mangled text. Valid UTF-8, including emoji and CJK, is stored unchanged.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
#167235)

Avoid re-entering plugin property writes through their own reflection traps and stop resolving exact session database candidates twice. Preserve inherited and derived receiver ownership, disposal fencing, and live filesystem custody checks.

Paired Node 26 measurements reduce allocation from 28,243 to 8,794 bytes per two plugin writes and from 13,342 to 5,991 bytes per normal agent-store capture. Whole-Gateway GC remains effectively unchanged in the measured mixed workload. Production code is five lines smaller.

Validated by the changed-file gate, 260 focused tests, built-Gateway comparisons, and independent review. Landed under the authorized inherited-CI-failure exception: generated Workboard manifest drift also fails on the exact main baseline (main run 37779390995; PR run 37780391546).
…ents) (#167203)

* refactor: deslop small lane leftovers (qa-lab, linux, worker environments)

Combine the d16, l427, and d15 cleanup lanes, removing 717 net production
lines while preserving existing lifecycle, authority, platform, and public
contracts. Publish the Parallels timeout fixture PID atomically after
installing its signal handler.

Keep main's rewritten Slack readiness handling, Rust authorization expression,
and worker-store dispatcher. Record complete local proof, conservative
exclusions, and unresolved baseline-comparison failures in the PR; exact-head
hosted CI supplies the final Linux and integration gates.

* fix(gateway): preserve serialized worker placement field order

Drop the placement-projector cleanup from the bundle. Spreading workspace
fields moved activeOwnerEpoch after the workspace fields and changed the
serialized base-row hash. Keep main's explicit property order and the golden
expectation unchanged.

The golden-row and placement-projector suites pass all 17 tests. Fresh review,
core types, typed lint, and both zero-cycle checks pass. The bundle now removes
713 net production lines across 72 paths.
…lers

#166988 inlined clearFailedSystemAgentSessionState at its single caller
while #167205 added a second caller, leaving main failing tsgo:core
(TS2304 in src/system-agent/agent-turn.ts). Restore the helper and use it
from both paths. Also drop the unused SessionPendingInputState re-export
left behind by #167106.
)

* refactor(auto-reply): share reply state and handler cores

Consolidate command projections, runtime presentation, queue settlement,
session publication, and delivery accounting while retaining caller-specific
authority, recovery, and replay boundaries. Revisit the previous pass with
measured shared-core trials and preserve public contracts and output text.

Remove 845 net production lines. Migrate only tests bound to retired private
presentation/count seams; retain their observable assertions.

* fix(auto-reply): complete shared helper validation

* test: align reply registry and session fixture cleanup

* refactor(reply): finish approval route consolidation

* test(reply): isolate model auth and complete logger fixtures

* refactor(reply): clarify callback bindings
…7220)

Show the repeated unknown ultrafast feature requirement diagnostic once per OpenClaw chat lifecycle, including native notification bursts, later turns, reconnects, and replacement threads. Keep first delivery for new/reset chats and preserve distinct policy and operational warnings.

Store bounded hashed receipts in existing plugin-owned session state through the canonical worker-backed writer. Retain failed-projection retry and fail-open persistence behavior without changing enterprise policy or enabling the unsupported feature.

Co-authored-by: jacobtomlinson <1610850+jacobtomlinson@users.noreply.github.com>
…anual refresh (#167230)

## What Problem This Solves

Fixes: when a provider's model discovery fails once (for example an OpenRouter timeout), the Gateway falls back to that provider's few built-in rows (OpenRouter 466 → 3) and keeps them until someone runs an explicit `models refresh`.

## User Impact

A transient provider outage no longer hides most of that provider's models for the life of the Gateway. The failed provider retries discovery in the background and its full model list comes back on its own once the provider is reachable.

## Why This Change Was Made

Failed discovery recorded no renewal deadline, and ordinary `models.list` reads intentionally no longer renew inventory (#167008), so nothing ever retried it. A failed provider now gets a backed-off retry deadline (30 s, doubling to a 30 min cap) on its retained inventory facts. The catalog owner keeps one timer for the earliest deadline, re-armed after each acquisition settles and cancelled when the catalog generation retires. Reads stay passive; a successful retry publishes the full rows and returns the provider to its normal cache deadline. A compatible reload keeps the failure facts and resumes the retry.

## Evidence

- Regression tests in `prepared-model-runtime.catalog-owner.test.ts`: discovery fails, then recovers with backoff and no read or refresh (fails on `main`: the worker is never called again); and a new failure episode is measured from its own failure.
- Live isolated Gateway with real OpenRouter discovery and a DNS-delay preload: OpenRouter discovery failed at startup and showed 3 built-in rows with `refreshFailed`. Background retries ran at the expected backoff (lookups at 12:17:38, 12:18:13, 12:19:19, 12:21:24, 12:25:29 UTC). After the network recovered at 12:29:40, passive `models.list` polling (no refresh) showed OpenRouter go from 3 to 466 rows at 12:33:35, on the next scheduled retry. OpenRouter's outcome is now `ready`.
- Focused prepared-catalog and models-list suites pass. Two `models-auth-*.catalog.integration` tests also fail on an unmodified `main` checkout locally.
- Test cost: `pnpm exec vitest run src/agents/prepared-model-runtime.catalog-owner.test.ts` takes 8.2 s wall time locally (19 tests; Vitest duration 4.2 s). The two new cases use fake timers and add about 0.4 s of CI test time.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Repair nine Control UI E2E failures introduced when #167054 moved live-text retirement into the Gateway. Feed only unsaved snapshot text, explicit retirement replacements, and terminal display projections while retaining all original one-answer, commentary, and no-stream assertions. Model native fallback answer and status-notice terminals separately.

The exact file failed 9/10 on b3196df and passes 10/10 with the current contract. All 488 chat unit/browser files pass (7046 tests; 3 existing skips). No production behavior or protocol changes.

Separate follow-up: an unpersisted status notice can be absorbed into a same-run durable answer by the older shared session projection matcher; notice visibility is not claimed fixed here.
Give each conversation one warm process and queue slot. Retire incompatible
account/auth owners before native resume, and retain standing approvals only
for the activated prepared turn.

Proved route alternation through an isolated Gateway: main retains two warm
processes and forks four parents; the fix retains one and preserves a linear
chain. Include lifecycle regressions and update caller expectations.

Fixes #167077
…167232)

* fix(ui): hold child attention until the child query answers

The chat pane seeds its child roster from the broad session list, which keeps
spawnedBy on children whose Gateway link has expired. Unread timed-out children
among them rendered as red attention cards until the canonical child query
replaced the seed about 250ms later.

* test(ui): drop duplicate child attention gate unit test
)

The Linux request dispatcher now holds a GitHub App private key and must
keep its ordinary GitHub-hosted label when release workers are reserved.
The heavy builder remains a separate workflow.

Preserve the App-token dispatch introduced by Dallin Romney in #167087.
The promotion dispatcher is already hosted; add coverage for that boundary
while preserving every existing assertion and strengthening credential coverage.
#167116)

When `openclaw connect` is given a target file whose name ends in a space, consume that exact file instead of the trimmed-name neighbor.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Reject an explicitly empty `--timeout-ms` in the meetings CLI before anything is sent to the Gateway. Valid timeouts still dispatch.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Drop LINE question postbacks with malformed or unsafe callback data instead of starting an unintended agent turn. Valid question postbacks still answer the pending question in the same turn. Webhook signature checks are unchanged.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
…67118)

Reject config input that is not valid UTF-8 (patch file, batch file or stdin) with a clear error before changing configuration, instead of silently storing U+FFFD-mangled values. The config stays byte-identical on rejection, and emoji and CJK still work.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
…es (#166359)

Use native local tool titles for ended activity without authoritative status while retaining a visible No result cue on iPhone. Unknown outcomes remain unknown even when raw output is present; known outcomes and desktop presentation retain their existing semantics.

Extend the existing rendered regression across unknown outcomes with and without output plus a known-success control, preserve the landed duplicate-stream fixture, and regenerate the two missing native source inventory entries.

Validation: exact-head CI passed. Colin supplied clean-source Mac validation of 10 shared activity tests, the native build and Swift checks, an intended pixel-assertion negative-control failure, and a passing rerun of the unchanged candidate. Inspected before/after simulator evidence is embedded in the PR. No physical-device or live Gateway proof is claimed.

Original implementation by @Marvinthebored; maintainer repair and native validation with @Solvely-Colin.

Co-authored-by: Solvely-Colin <211764741+Solvely-Colin@users.noreply.github.com>
Co-authored-by: Marvinthebored <peter@lindsey.jp>
* test(ui): deslop w1163 tests

* test(telegram): deslop w1167 tests

* test(gateway): deslop w1165 tests

* test(agent-core): deslop w1164 tests

* test(ui): deslop w1162 tests

* test(synology-chat): deslop w1169 tests

* test(discord): deslop w1171 tests

* test(gateway): deslop w1166 tests

* test(qa-lab): deslop w1168 tests

* test(openai): deslop w1173 tests

* test: retain reviewed boundary coverage in batch d018
Regenerate the manifest after #167227 changed Workboard browser code.
Refresh controlUi.entry and controlUi.styles to the current immutable bundle
hash so the build-artifacts generated-assets check matches source again.

Only generated metadata changes; plugin behavior and assertions are intact.
Align active-run follow-ups, placement recovery, and full-reload steering with #167054's explicit Gateway-owned unsaved-text and steers-after-run contract. Keep duplicate, overlap, durable-row, and prompt-order coverage while updating stale wire fixtures and the removed steer-splitting assumption.

Remove the obsolete exported stream-index helper at its remaining keyed-pruning owner. Preserve cumulative-baseline coverage through the public history-pruning function.

Current-main control: 6 failed / 20 passed; corrected cases: 26 passed. No new runtime behavior or public protocol changes.
The #167171 consolidation moved the helper's only production consumer into its own module, leaving a test-only export that fails the production unused-export scan. Exercise the existing public skill action and its actual config draft instead.

The Workshop exclusion remains unchanged; all unused-export scans pass.
Return the already-selected cron retention rows from the reader worker, removing ordinary-session preservation scans and unused whole-store counts while preserving validation, deletion snapshots, shared-store coverage, and live authority.

Matched synthetic Gateway profiles reduced registry sampled CPU from 215.257 ms to 6.699 ms and registry-associated >50 ms gaps from five to zero. Full session/cron sibling coverage: 5,503 tests passed.

Landed under the authorized inherited-CI exception: Workboard generated-asset drift also fails on unchanged main, with identical build inputs. See the PR for baseline proof, complete validation, and latency limitations.
Resolve Feishu mention placeholders in fetched text, quoted context, thread history, and forwarded text children through the existing shared single-pass normalizer. Preserve incoming-event behavior, literal placeholder-like display names, and native post/card rendering.

Closes #48786. Reported by @Raven-wy; implementation by @Leon-SK668.

Co-authored-by: Leon-SK668 <0668001470@xydigit.com>
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
Co-authored-by: Takhoffman <781889+Takhoffman@users.noreply.github.com>
* feat(ui): customize browser tab icons

Worked on by:
- @vyctorbrzezowski

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
OpenClaw-Publication: 066834d7-d7d5-40fa-9f90-45326b600d85

* refactor(ui): simplify tab icon settings

Restore source previews and align the custom-image control. Remove duplicate
upload state, one-use wrappers, repeated checks and overlapping test setup.
Keep image validation, profile isolation and mixed-write acknowledgment proof.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

* perf(ui): keep tab icon setup behind deferred owners

Connect artwork within the deferred favicon lifecycle and keep the preview asset fallback in Settings. Preserve status and image cleanup while avoiding invalidation of the unrelated default-source cache.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jacobtomlinson <1610850+jacobtomlinson@users.noreply.github.com>

* test(ui): complete appearance context fixtures

Provide the gateway snapshot and selected-agent stores required by the real ConfigPage host. Retain the existing behavior assertions; no production fallback or new test seam.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jacobtomlinson <1610850+jacobtomlinson@users.noreply.github.com>

---------

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
Co-authored-by: jacobtomlinson <1610850+jacobtomlinson@users.noreply.github.com>
Normalize OpenClaw loopback MCP names at the CLI channel-summary boundary so familiar labels and authored execution titles use the shared display formatter. Preserve safe-summary privacy, optional full output, nameless-result matching, and plan suppression.

Verified both regression failures before the repair, 34 passing focused tests afterward, clean independent P0–P3 review, ClawSweeper with no actionable findings, and green exact-head CI.

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.