Peter Steinberger
e7d7075865
test: stabilize extension lifecycle isolation ( #126309 )
...
* test(msteams): synchronize SDK stream lifecycle
* test(plugins): preserve error runtime exports in mocks
2026-08-19 04:56:42 -07:00
Peter Steinberger
3378e07d50
refactor(plugin-sdk): promote shared runtime primitives ( #126193 )
...
* refactor(plugin-sdk): promote shared runtime primitives
* test(codex): keep one attempt tools owner
2026-08-19 01:10:18 -07:00
Peter Steinberger
e38a06439e
refactor: trim locale and QA fixture debt ( #126139 )
...
* refactor: trim locale and QA fixture debt
* fix(qa): preserve shared flow portability
* chore(qa): document shared flow branch
* fix(docs): align plugin SDK subpath catalog
* fix(ci): align shared docs and flow contracts
2026-08-18 22:17:19 -07:00
Peter Steinberger
9329e4d76a
refactor(approvals): consolidate channel approval kind ( #125215 )
2026-08-17 04:08:10 -07:00
Peter Steinberger
5ebfbbf8d7
fix(plugins): honor per-agent runtime config ( #124978 )
...
* fix(plugins): resolve per-agent config through SDK
* test(codex): preserve agent runtime exports
* test(telegram): make default owner explicit
* refactor(plugins): use lightweight agent scope runtime
* fix(codex): preserve multi-agent execution ownership
* chore(plugin-sdk): record approved agent scope exports
* fix(codex): keep scoped sandbox ownership authoritative
* fix(codex): preserve agent scope in native side actions
* fix(ci): avoid counting node check as environment variable
2026-08-17 01:53:08 -07:00
Peter Steinberger
313cb134fe
refactor(channels): align approval reaction bindings ( #124942 )
...
Split Signal approval routing into its concept-owned module and call the shared SDK binding helpers directly.
Reject persisted reaction targets when any allowed decision is invalid or duplicated, rather than retaining a valid subset from a corrupt transient record.
2026-08-16 18:48:39 -07:00
Peter Steinberger
568b920b21
feat(lint): enforce import ordering and deduplication ( #124730 )
...
* refactor(imports): dedupe and hoist imports
* feat(lint): enforce import/no-duplicates and import/first
2026-08-16 11:44:52 -07:00
Peter Steinberger
63401b730b
fix: keep doctor security conditions as single findings ( #124666 )
...
* fix(doctor): record security finding severity
* refactor(security): keep audit severity internal
* fix(security): preserve channel finding severity
2026-08-16 10:24:40 -07:00
Peter Steinberger
6aa27d6ecd
refactor: retire August compat windows (embedding API, pi aliases, target parser, spawning hook, setup exports, WhatsApp inbound aliases) ( #124416 )
...
* refactor(plugin-sdk): retire embedded Pi aliases
* refactor(channels): retire explicit target compatibility
* refactor(plugins): retire subagent spawning hook
* refactor(plugin-sdk): retire shipped channel setup exports
* refactor(whatsapp): retire inbound callback aliases
Proof: focused build and WhatsApp E2E green; broad WhatsApp suite 188/189 files green. extensions/whatsapp/src/monitor-inbox.policy.test.ts flakes only in the parallel batch and passes isolated (10/10).
* refactor(plugin-sdk): retire memory embedding registrar
Migrate every bundled provider and manifest to registerEmbeddingProvider and contracts.embeddingProviders. Preserve memory-specific batching, local-service acquisition, index identity, and auto-selection through the canonical generic registry adapter, then remove the parallel registrar, registry, diagnostics, contracts, tests, and docs.
* chore(plugin-sdk): tighten retired surface budgets
Pin the post-retirement public SDK surface to 144 entrypoints, 4,312 exports, 2,564 callable exports, and 1,133 deprecated exports; agent-harness-runtime now permits exactly nine deprecated exports.
2026-08-15 22:43:47 -07:00
Josh Avant
97a53a9b35
feat: audit admitted channel participant identity ( #122863 )
...
* feat: audit admitted channel participant identity
* fix: preserve Telegram identity through thread recovery
* fix: signal held gateway process groups
* fix: keep audit evidence passive in collect routing
* fix: validate copied channel participant evidence
* fix: bind channel participant evidence to host ingress
* fix: honor Telegram proof credential roles
* fix: restart held Telegram proof through gateway
* fix: repair channel identity CI regressions
* test(matrix): bind thread routing owner
* fix: preserve direct DM SDK compatibility
* fix: bind channel provenance at host runtime
* test(feishu): provide channel context builder
* fix: defer record-bound channel runtime resolution
* fix: keep channel admission evidence core-private
* fix(audit): bind channel admission to plugin lifecycle
* fix(audit): bind ingress provenance to final context
* refactor(audit): split admission scope keys
* test(queue): cover combined metadata carriers
* refactor(audit): keep lifecycle helpers private
* fix(queue): preserve combined turn authority
* test(channels): provide ingress context builders
* test(channels): align integrated CI fixtures
* test(clickclack): resolve model-loop ingress
* docs: preserve channel participant evidence invariant
2026-08-14 08:57:01 -05:00
Peter Steinberger
9013ab80a8
fix(whatsapp): keep distinct-id repeated messages ( #122785 )
2026-08-12 13:07:22 -07:00
Peter Steinberger
b4ffa3106f
refactor(extensions): remove orphan test exports ( #122784 )
2026-08-12 12:45:33 -07:00
Peter Steinberger
c23d66e3b5
refactor: consolidate coercion ownership ( #122692 )
...
* refactor: consolidate coercion ownership
* test: align shard check with weighted planning
* chore: refresh plugin SDK API baseline
2026-08-12 09:25:28 -07:00
zhifu gao
42ad83142e
fix(whatsapp): label voice transcripts as untrusted ( #113111 )
...
* fix(whatsapp): label voice transcripts as untrusted
* fix(whatsapp): preserve audio provenance in group history
Frame deferred voice transcripts while retaining their structured audio facts for later model-visible replay.
Refs #87269
---------
Signed-off-by: zhifu gao <lauragpt@users.noreply.github.com >
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
Co-authored-by: zhifu gao <lauragpt@users.noreply.github.com >
2026-08-12 17:14:55 +08:00
Peter Steinberger
08142099da
refactor(plugins): remove test-only facades and adapter ( #122532 )
...
* refactor(plugins): trim test-only facades
* refactor(whatsapp): remove legacy outbound adapter
2026-08-12 01:20:09 -07:00
Peter Steinberger
fc0147b529
test(plugins): remove duplicate setup cases ( #122515 )
2026-08-12 00:19:22 -07:00
Peter Steinberger
b080dd1e76
refactor: consolidate coercion contracts ( #122458 )
...
* refactor: consolidate coercion contracts
Centralize exact string, record, numeric, date, Boolean, argument, and structured-error coercions while preserving call-site semantics.
Migrate canonical-name collisions and deprecated internal SDK bypasses, deleting 55 net production/tooling lines. Expand declaration ownership enforcement to 101 allowed helpers and add a narrow export-completeness audit.
* fix: preserve standalone script coercions
Keep copied Control UI tooling self-contained and retain the trusted release harness module-relative source seam when the harness runs against an old target cwd.
2026-08-11 23:26:37 -07:00
Peter Steinberger
964c8c84c1
refactor: consolidate coercion ownership ( #122299 )
...
* refactor: consolidate coercion ownership
Centralize four canonical coercion helpers, migrate exact core and plugin duplicates through narrow Plugin SDK facades, and enforce declaration and plugin-normalization ownership boundaries.
The sweep adds eight focused SDK exports while deleting more production and tooling code than it adds. User-visible behavior is unchanged except for safer equivalent object and UI parsing at existing boundaries.
* fix: guard integer option ownership
Register resolveIntegerOption with the canonical function owner and extend the declaration-guard fixture so future local duplicates fail validation.
* fix: keep integer helpers on numeric facade
Remove the unshipped duplicate string-coerce exports and route every affected plugin consumer through the existing number-runtime contract.
* fix: point numeric coercion to number runtime
Make boundary and declaration diagnostics recommend the canonical numeric facade, with failing-before coverage for both guidance paths.
2026-08-11 17:14:53 -07:00
Peter Steinberger
b350f76484
fix(channels): preserve failed agent run reactions ( #122009 )
2026-08-11 15:26:44 -07:00
Peter Steinberger
86bc5aa726
test(plugins): remove stale test plumbing ( #122175 )
2026-08-11 11:01:05 -07:00
Peter Steinberger
fa03d9b913
refactor: consolidate coercion helpers ( #121366 )
...
* refactor: consolidate coercion helpers
* fix: remove duplicate coercion imports
* fix: preserve serialized coercion guard
* chore: ratchet coercion helper carve-outs
* fix(test): keep gauntlet subprocess startup lean
* fix: preserve imported session timestamp semantics
* fix: preserve catalog timestamp string semantics
* chore: align plugin SDK surface ratchet
* fix: preserve trajectory and SDK string contracts
* fix(test): preserve QA record assertion semantics
* fix: complete standalone record guard rename
* refactor(cron): use canonical string coercion
* fix(acpx): preserve Pi timestamp parsing
* test(channels): adapt custody test harnesses
* test(telegram): classify media harness as test support
* test(acpx): split timestamp contract coverage
* test(channels): support generated custody contracts
* chore: ban the full coercion helper name set
Extends the declaration guard to all eleven consolidated helper names and
renames the cron schedule-identity readNumber wrapper to readScheduleInteger
so the banned generic name cannot regrow.
* fix(scripts): repair release-validation guard drift and lint cause
Restores the renamed isJsonRecord guard in assertTrustedWorkflowHarness after
main added isRecord call sites in parallel, and attaches the caught YAML error
as the thrown error cause (preserve-caught-error was red on main).
* fix: preserve Claude timestamp string semantics
* fix: preserve persisted timestamp string semantics
* fix: preserve date-first timestamp contracts
* fix(openai): harden delegation failure formatting
* chore: close coercion helper guard gaps
* test(openai): model non-error delegation rejection
* chore: refresh plugin SDK API contract
* fix(tasks): use canonical string field reader
* fix(ai): use canonical provider error field coercion
* fix(browser): migrate native bootstrap coercion
* docs(plugin-sdk): clarify text record export compatibility
* fix(gateway): normalize approval execution identity
* test(outbound): isolate message action poll harness
2026-08-11 00:02:18 -07:00
Ayaan Zaidi
9935ca3b30
fix(approvals): bind native requests to channel accounts ( #121673 )
...
Native approval delivery and resolution now stay bound to the originating or explicitly targeted channel account. Unbound requests fail closed across multiple eligible accounts; trusted reviewer-less SDK callers remain compatible.
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-11 01:42:41 +05:30
Peter Steinberger
3b3c540896
refactor: remove dead branches and test-only helpers ( #121345 )
...
* refactor: remove dead branches and test-only helpers
* fix: preserve codex cleanup error causes
* fix: preserve gateway error code compatibility
* chore: update plugin sdk api baseline
* docs: fix live cache runner path
2026-08-10 06:47:43 -07:00
Peter Steinberger
0efd5b4bc9
refactor(channels): move owner policy into plugins ( #121257 )
...
* refactor(channels): move owner policy into plugins
* test(plugin-sdk): lower surface budget after export removal
2026-08-09 15:46:18 -07:00
Peter Steinberger
54ae94530c
refactor(approvals): simplify resolver plumbing ( #120923 )
2026-08-08 23:09:24 -07:00
Peter Steinberger
e1ec95dcbf
refactor(auth): dedupe profile upserts and approval resolvers ( #120831 )
...
* refactor(auth): dedupe profile upserts and approval resolvers
* test(auth): mock canonical locked upsert
* test(auth): mock locked upsert during onboarding
2026-08-08 21:14:16 -07:00
Peter Steinberger
75dbe52e3e
refactor: one code path behind doctor legacy-state migrations ( #120716 )
...
* refactor(doctor): prefer manifest route-state owners
* refactor(doctor): unify config repair declarations
* refactor(doctor): unify legacy state migrations
* fix(doctor): satisfy migration pipeline guards
* fix(plugin-sdk): keep doctor adapter inside boundary
2026-08-08 18:23:15 -07:00
Peter Steinberger
8cb53c7b55
perf(doctor): keep bundled doctor contract closures dependency-light ( #120698 )
...
* perf(doctor): keep bundled doctor contract closures dependency-light
Doctor contract enumeration cold-loads each plugin's doctor-contract-api
closure via jiti, so a static value import of openclaw/plugin-sdk/runtime-doctor
pulled the state-db/kysely graph (~4.3s per closure) into
listPluginDoctorLegacyConfigRules / listPluginDoctorStateMigrationEntries.
- migrate all light doctor-contract closures (66 files) to the
dependency-light openclaw/plugin-sdk/runtime-doctor-migrations subpath
- voice-call: load detect/repairOpenClawStateDatabaseSchema* lazily inside
the migration bodies; keep only a type-only static runtime-doctor import
- matrix: split pure credential record shapes/normalizers into
credentials-state.ts so the doctor closure no longer imports the sync
plugin-state store through credentials-read
- guard: doctor-contract-closure-guard.test.ts now forbids static value
imports of runtime-doctor in closures alongside agent-runtime
* fix(matrix): keep credential revocation record type module-local
Knip production scan flags the export as consumer-less; the type is only
referenced by the exported union and revocation guard signature.
2026-08-08 17:51:31 -07:00
joshavant
87156bab23
fix(typing): keep long active turns visible
2026-08-07 16:11:52 -05:00
Josh Avant
c691f2e41c
fix(progress): preserve callback acceptance results ( #120171 )
...
* fix(progress): preserve callback acceptance results
* fix(progress): require transport acknowledgements
* fix(progress): preserve direct acceptance outcomes
2026-08-07 14:40:33 -05:00
Peter Steinberger
b4a26783f7
refactor(test): consolidate duplicated requireRecord and provider HTTP mock helpers ( #119982 )
...
* refactor(test): consolidate duplicated test helpers
* test: remove stale record guard import
* fix(test): remove orphaned record guards
* refactor(test): keep record requirement messages exhaustively typed
* fix(test): keep packages/ai record guard package-local
2026-08-06 14:48:01 -07:00
Peter Steinberger
f5e3b5ef54
refactor(plugins): single-source question reactions and preflight audio ( #119987 )
2026-08-06 14:47:36 -07:00
Peter Steinberger
6aee2792d9
fix(whatsapp): exercise descriptor-safe credential persistence ( #119621 )
2026-08-05 10:36:36 -07:00
Peter Steinberger
60a8ec821c
refactor(plugins): reuse canonical error coercion ( #119451 )
2026-08-04 21:05:45 -07:00
Peter Steinberger
f9d9d1225a
refactor(channels): own the lifecycle status contract in SDK patch factories ( #118795 )
...
* refactor(sdk): add channel lifecycle patch factories
* refactor(channels): adopt lifecycle patches in a-m
* refactor(channels): adopt lifecycle patches in n-z
* refactor(runtime): lifecycle-own ambient registries
* test(slack): assert lifecycle factory fields
* fix(sdk): preserve lifecycle patch extras types
* test(zalouser): widen lifecycle status sink
* test(irc): avoid shadowed status patch
* fix(zalo): reuse account-agnostic media route
* fix(gateway): accept explicit channel ready recovery
* test(qa): assert terminal Slack block fact
* test(qa): restore Slack blocked lifecycle scenario
* test(gateway): lock explicit lifecycle recovery contract
2026-08-03 12:39:48 -07:00
Peter Steinberger
09e40d0b74
fix(whatsapp): honor disabled self-chat without widening group access ( #118711 )
2026-08-03 07:57:23 -07:00
Peter Steinberger
3b6cad7e31
fix(whatsapp): preserve terminal retry exhaustion lifecycle ( #118659 )
...
Co-authored-by: Peter Steinberger <steipete@macos.shared >
2026-08-03 06:19:00 -07:00
Peter Steinberger
fe6fa891ea
fix(whatsapp): clear and migrate every Baileys credential class ( #118610 )
...
* fix(whatsapp): clear and migrate every auth credential class
* test(whatsapp): await nullable legacy migration detector
2026-08-03 03:54:41 -07:00
Peter Steinberger
8e35fb4963
test(channels): consolidate remaining channel scaffolding ( #118493 )
...
* test(channels): consolidate channel scaffolding
* test(channels): fix helper typings
2026-08-02 23:03:54 -07:00
Vincent Koc
f32a266134
fix(whatsapp): render quoted self-chat replies with cached LIDs ( #116814 )
...
* fix(whatsapp): align quoted replies with resolved jid
* fix(whatsapp): preserve inbound media type import
2026-08-03 12:54:28 +08:00
Vincent Koc
f5637c0685
fix(qa): restore prerelease validation ( #118255 )
...
* test(whatsapp): return accepted monitor send results
* fix(qa): recognize Code Mode write results
2026-08-03 10:09:19 +08:00
Vincent Koc
b35b8e286d
fix(plugins): unblock prerelease validation ( #118103 )
...
* fix(plugins): align compatibility registry identity
* fix(slack): compact response URL native fallbacks
* test(plugins): stabilize prerelease runtime checks
* fix(packaging): include CUA driver in root package
* fix(packaging): declare CUA runtime dependency
* fix(cua): defer native driver loading
2026-08-03 04:48:05 +08:00
Peter Steinberger
0c32879d45
feat(channels): publish recorded lifecycle from bundled channel transitions ( #118110 )
...
* feat(channels): publish recorded lifecycle from bundled channel transitions
* chore: remove lifecycle changelog entry
2026-08-02 13:04:49 -07:00
Peter Steinberger
641a4bf7b0
fix(whatsapp): reject unaccepted provider deliveries ( #118114 )
...
Co-authored-by: Peter Steinberger <steipete@macos.shared >
2026-08-02 12:01:38 -07:00
Dinesh H Suthar
35b00ddd14
fix(reply): preserve retryable final delivery recovery ( #117597 )
...
* fix(reply): preserve retryable final recovery
* fix(reply): preserve partial-delivery recovery markers
* fix(reply): keep delivery classification cycle-free
---------
Co-authored-by: Peter Steinberger <steipete@macos.shared >
2026-08-02 05:17:02 -07:00
Peter Steinberger
0aa262a795
fix(whatsapp): keep inbound media diagnostics safely redacted ( #117939 )
2026-08-02 03:16:24 -07:00
clawsweeper[bot]
c8688051ed
fix(whatsapp): log terminal inbound media failures ( #117717 )
...
* fix(whatsapp): log terminal inbound media failures
* fix(whatsapp): log terminal inbound media failures
* fix(whatsapp): surface media enrichment failures
* test(whatsapp): preserve caught media errors
---------
Co-authored-by: clawsweeper <274271284+clawsweeper[bot]@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@macos.shared >
2026-08-02 17:13:16 +08:00
Peter Steinberger
d6aafb3dfc
refactor(whatsapp): split inbox lifecycle coverage ( #117910 )
...
* test(whatsapp): split inbox lifecycle coverage
* test(whatsapp): import metadata cache type
2026-08-02 02:09:47 -07:00
Peter Steinberger
dc38411ca4
test: consolidate WhatsApp monitor suites ( #117854 )
...
* test: consolidate WhatsApp monitor suites
* test: preserve WhatsApp max-lines ratchet path
2026-08-02 00:20:17 -07:00
Peter Steinberger
e7f1202bbb
refactor(whatsapp): consolidate QA message extraction ( #117836 )
2026-08-01 23:18:09 -07:00