Commit Graph

19830 Commits

Author SHA1 Message Date
Peter Steinberger b3d5265f58 fix(docker): harden runtime images against CVE surface (#123282)
* fix(docker): harden runtime image dependencies

* chore(deps): update container security dependencies

* docs(docker): explain image security contents

* test(browser): align file-chooser and install tests with #114506 contract

* test(browser): restore extension install test isolation

* test(browser): add temporary CI diagnostics for pre-registration refusal

* test(browser): make install fixture interpreter hermetic

The suite passed process.execPath as the native-host interpreter; on
GitHub-hosted runners the hostedtoolcache node binary is group/world-
writable, which installChromeExtensionBootstrap correctly refuses, so
every registration test failed CI-only. The fixture now provides an
owned 0700 interpreter; only the launcher-exec test keeps the real
node it must spawn.

* fix(qa-lab): stop re-polling after a probe consumes the discovery deadline

The Matrix health-probe loop re-entered when the probe timeout fired
marginally before Date.now() crossed the deadline, starting a doomed
extra probe. Flaked on contended CI runners as 'expected 1 fetch, got
2'. A timed-out probe now ends discovery.

* test(ui): poll the callout inset invariant in device-scope E2E

One-shot boundingBox reads raced the nav-collapse transition and
intermittently measured a 20px stale offset on CI.
2026-08-13 14:02:39 -07:00
Peter Steinberger faa6202412 fix(slack): keep thread freshness on routed agent (#123202) 2026-08-13 13:17:36 -07:00
ClawSweeper 036bcc1a65 fix(agents): self-heal unsupported harness transports (#123258)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-13 13:08:35 -07:00
Peter Steinberger bc8e51ce37 refactor(memory-core): strengthen dreaming boundaries (#123138)
Replace assertion-driven cleanup with real runtime narrowing and typed owner contracts across memory-core dreaming.

Reject the unsound one-file lint ratchet and document repository-wide rules against checker-gaming and baseline-driven enforcement.

Co-authored-by: Amp <amp@ampcode.com>
2026-08-13 11:32:25 -07:00
Peter Steinberger 249a38d29f fix: keep background work scoped to its selected agent (#123257)
* fix: preserve explicit agent ownership

Scoped route, session, and job owners now survive hooks, cron, process exits, global delivery, bindings, and media cleanup. Truly ownerless operations remain explicit errors.

* test: provide session memory hook owner

* test(ui): close failed-module page explicitly

* test(matrix): align ownership and replacement proof
2026-08-13 11:29:31 -07:00
Peter Steinberger 11b3bf374c feat(slack): unify the native progress turn into one streamed message (#122976)
* feat(slack): unify the native progress turn into one streamed message

Native progress mode now streams the whole turn into a single Slack message:
narration flows as markdown_text chunks interleaved with plan/task chunks,
task rows carry file-path details and +N/-N output, the terminal task links
the session via url_source, and the final answer lands through stopStream in
the same message. Media/oversized/error finals keep their normal-delivery
fallbacks.

Deletes the finished-card receipt collapse (the '\u{1F6E0} N tool calls · ⏱ Ns' edit)
outright: the card now stays as its finished self.

Live-verified on a real workspace: exactly one bot message per turn.

* fix(slack): serialize native stream updates and keep append-only rendered text monotonic

Overlapping progress updates (compositor render, narration payload, final)
computed their narration delta before awaiting the network and committed
state only afterwards, so concurrent updates re-appended identical
narration into the streamed message (each status line landed 3x live).
A single ordering chain now makes each update's compute -> append -> commit
atomic.

applyAppendOnlyStreamUpdate also replaced the accumulated rendered text
with the incoming cumulative partial once an appended chunk had diverged
rendered from source, dropping content the sink already displayed; rendered
now only ever extends.

* fix(slack): stop refreshing thread status once a turn has visible output

Slack clears the assistant thread status as soon as the app puts anything
in the thread, and renders its own rotating agent-working row ("Generating
response...", "Finding answers...") for every status write after that -- it
ignores the app-supplied string. The typing keepalive re-set the status
every 3s for up to 60s, so each turn painted a duplicate status row under
the streamed card or progress message.

The status write is now gated on the turn having visible output, which the
dispatcher already tracks (delivered reply, committed preview, or posted
draft message). The first status still fires before any output, so slow
turns keep their indicator, and the typing reaction is tracked separately
so a suppressed status write still cleans up its reaction.

* fix(slack): let the plan card own the status line instead of echoing it

The status headline and plan explanation fed both the streamed narration
markdown and the plan card title, so every headline rendered twice: once as
static text and once in the card that keeps updating it in place. Narration
now carries only authored commentary and reasoning, and a preamble payload
whose text the card title already shows is not streamed again.

* feat(slack): make the native agent card the default progress surface

Slack's native plan/task card was opt-in behind streaming.progress
.nativeTaskCards while the Block Kit session card shipped as the default.
The native surface is the better product on every axis we can measure --
one streamed message instead of three artifacts, live task rows with file
paths and diff counts, and Slack's own agent chrome -- so it becomes the
default and an explicit false selects the Block Kit card instead.

The session link is now emitted only when it can actually work: the
operator set gateway.publicOrigin and left the Control UI enabled.
Installations with no externally reachable Gateway get no link rather than
a dead one.

The progress card still only appears for turns that do real work; the
existing compositor start gate keeps plain question-and-answer turns
card-free.

* fix(slack): finish the final inside a buffered native stream

A short narration leaves the SDK session un-flushed, so `delivered` stays
false until `stop` makes its first network call. Requiring delivery before
finishing in-stream sent the final through normal delivery and then
finalized the stream anyway, producing exactly the second message this path
exists to prevent. Stop-time rejection already falls back via
SlackStreamNotDeliveredError, so a live session is enough.

Addresses the ClawSweeper P1/P2 finding on this PR.

* refactor(slack): collapse duplicate streaming surfaces and drop dead code

Cleanup pass over the progress/streaming neighborhood, all verified unused
by exhaustive reference search:

- Deleted buildSlackProgressStreamStartChunks/UpdateChunks: byte-identical
  pass-throughs to the same builder, plus the render-module branch that
  chose between them. One exported builder now.
- Collapsed slackStreaming.draftMode, a lossless restatement of the mode it
  was derived from, and its outbound mapper; nine comparisons now read the
  mode directly. Inbound legacy parsing stays for doctor migration.
- Dropped stopSlackStream's text parameter, the draft stream's stop() member
  and onMessageSent hook, a redundant nativeStreaming argument, four dead
  members on the progress runtime, and two single-expression wrappers.
- Deduped the native card title, which was computed twice per render.

Production LOC for the whole PR drops from +216 to +114.

* chore(config): regenerate bundled channel metadata for the Slack card default

The generated metadata still carried the old opt-in help text and
default-false description for streaming.progress.nativeTaskCards, so
config UI and diagnostics would publish stale guidance.

* fix(slack): un-export the now-internal legacy draft-mode type

Collapsing draftMode removed the type's only external consumer, so knip
flagged it as an unused export. Doctor migration still parses these legacy
values inbound, so the type stays module-local.
2026-08-13 11:19:32 -07:00
Ayaan Zaidi f70d5b8ba5 fix(reasoning-tags): prevent internal reflections in replies (#123196)
Treat <internal> blocks as private reasoning in the shared parser and remove Telegram raw-reasoning fallbacks. This keeps model reflections out of user-visible replies while preserving surrounding answer text.

Closes #122623

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Co-authored-by: WangYan <wang.yan29@xydigit.com>
2026-08-13 20:36:48 +05:30
sunlit-deng 0e5855be8b fix(memory-wiki): guard malformed wiki_apply input (#123050)
Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
2026-08-13 09:26:21 -05:00
Peter Steinberger c3d843eb24 test: remove residual duplicate assertions (#123134)
* test: remove residual duplicate assertions

* test: repair stale routing and capability fixtures

* fix(cli): bound one-shot stream drain exit
2026-08-13 04:41:37 -07:00
Peter Steinberger baf85e6868 fix(raft): report missing CLI in channel status (#123140) 2026-08-13 04:21:13 -07:00
Vincent Koc 033247ab42 fix(codex): resume parent after terminal subagent fan-out (#123124)
* fix(codex): settle terminal tool releases immediately

Punchcard-Session: quiet-workshop-river-e5

* fix(agents): materialize requester ownership at launch

Punchcard-Session: quiet-workshop-river-e5
2026-08-13 19:15:58 +08:00
Peter Steinberger c218187244 fix(ci): stop killing healthy discord Vitest runs and repair partial runtime-env mocks (#123131)
The discord extension shard's silent transform/import startup (~210s measured
on a loaded macOS host) exceeded the run-vitest wrapper's 120s default
no-output timeout, so the watchdog killed healthy runs (#123025). The config
now gets the extra-long budget like the other large shards.

Three discord tests mocked openclaw/plugin-sdk/runtime-env with bare factories
missing most exports; under isolate=false they poison the shared worker module
cache and break later files that bind logVerbose/sleepWithAbort through the
shared process test harness. They now spread importOriginal and override only
their stubs.

Fixes #123025
2026-08-13 03:54:22 -07:00
Peter Steinberger ccc1920068 improve(telegram): cut cold channel setup import latency (#122955)
* perf(telegram): keep setup entry on light graph

* fix(plugin-sdk): complete private UI hint boundaries
2026-08-13 01:55:47 -07:00
Peter Steinberger 792b2054df refactor(agents): move recovery tests to owners (#123022)
* test(agents): move recovery tests to owners

* test(discord): split send coverage by surface

* test(discord): share send mock lifecycle

* test(discord): isolate draft timer coverage
2026-08-13 01:29:05 -07:00
Peter Steinberger b54034d5c2 fix: isolated gateways list and open the operator's HOME Claude/Codex/OpenCode/Pi sessions (#122983)
* fix(sessions): isolated gateways no longer inherit HOME external session catalogs

A gateway on isolated state (custom OPENCLAW_STATE_DIR/CONFIG_PATH/OPENCLAW_HOME,
relocated home, or any named profile) listed, read, continued, archived, and
reopened the operator's real Claude Code/Codex/OpenCode/Pi sessions from the
process HOME. External catalogs now require the default install identity for
process-HOME scans: every catalog verb receives the isolation policy and rejects
HOME-fallback local targets, unknown providers fail closed unless they declare
supportsProcessHomeIsolation, and one structured warning records the skip.
Paired-node hosts and explicitly rooted stores (CLAUDE_CONFIG_DIR, CODEX_HOME,
OPENCODE_DB, Pi session dirs) keep working; default-identity gateways are
unchanged.

* fix(sessions): inject catalog HOME-isolation fact at registry construction

* chore(sdk): regenerate plugin API baselines after rebase

* chore(sdk): regenerate plugin API baselines after rebase
2026-08-13 01:12:03 -07:00
Peter Steinberger 683d37a35f test(telegram): align ingress fixtures with Bot API (#123059) 2026-08-13 00:58:17 -07:00
Peter Steinberger dbe4ce9f33 fix(telegram): prevent multi-agent cache ownership startup failures (#123029)
* fix(telegram): scope runtime caches by account owner

* test(telegram): type partial owner runtime stub

* refactor(telegram): remove obsolete default owner seam

* fix(telegram): tolerate partial durable updates

* test(telegram): request raw progress detail explicitly
2026-08-13 00:33:38 -07:00
Dallin Romney 1d45930162 chore(cua-computer): upgrade CUA Driver to 0.19.3 (#122191)
* chore(cua-computer): upgrade CUA Driver to 0.19.3

* test(cua-computer): verify CUA Driver enum contract
2026-08-13 15:19:35 +08:00
Ayaan Zaidi 0b9842d138 fix(agent): finish turns when providers fail after tools complete (#123005)
Safely finalize settled Codex turns when an overload arrives after tool completion. Keep other provider failures fail-closed and preserve channel delivery.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-08-13 12:17:28 +05:30
joshavant be7a2c23e9 fix(discord): cancel started ingress jobs on abort 2026-08-13 01:34:05 -05:00
joshavant 0bea408976 fix(discord): cancel skipped queued ingress 2026-08-13 01:34:05 -05:00
joshavant 59c382b717 fix(tests): respect plugin helper boundary 2026-08-13 01:34:05 -05:00
joshavant 13750feff3 fix(plugin-sdk): preserve cancellation receivers 2026-08-13 01:34:05 -05:00
joshavant b0a8cdb6f7 fix(discord): settle mixed cancellation fan-in 2026-08-13 01:34:05 -05:00
joshavant 0901efe3dd test(mattermost): align tool preview fixture with privacy default 2026-08-13 01:34:05 -05:00
joshavant 5af3d49621 fix(plugin-sdk): make ingress cancellation fan-in safe 2026-08-13 01:34:05 -05:00
joshavant 06600e2ca0 fix(discord): unblock ingress after retry exhaustion 2026-08-13 01:34:05 -05:00
Peter Steinberger 3f4f57a021 test(extensions): scope remaining multi-agent fixtures to explicit owners (#123021)
Class provenance: #114388 made multi-agent ownership explicit; prior partial sweeps #122883 and #122978 repaired Codex, Copilot, ClickClack, and policy fixtures.

Per-file changes:
- extensions/telegram/src/bot.create-telegram-bot.test.ts: declare startup owners for the four reload fixtures and add the default Telegram binding for the topic override case while preserving dynamic account/topic routing assertions.
2026-08-12 23:14:34 -07:00
machine3at 7620a58b29 fix(memory-wiki): guard wiki_get against missing or wrong-typed lookup (#122549)
* fix(memory-wiki): return clean error from wiki_get on missing lookup

wiki_get crashed with "Cannot read properties of undefined (reading
'trim')" when called with a wrong parameter name (e.g. path instead of
lookup), leaving lookup undefined.

- Validate and trim lookup at the wiki_get tool boundary; return a clean
  error (found: false) when it is missing or empty instead of falling
  through to page resolution
- Add regression test covering the wrong-param call path

* fix(memory-wiki): normalize wiki_get parameters

Punchcard-Session: calm-workshop-cedar-hx

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-08-13 14:08:36 +08:00
Peter Steinberger 7c8f08a88c fix(ci): split discord thread-creation tests under the max-lines cap
#117354 added 246 lines of thread initial-message chunking coverage, taking send.creates-thread.test.ts to 1082 counted lines against the 1000-line cap and leaving main check-lint red.

Move the 9 chunking tests to a sibling file. The suite remains 51 tests total: 51 before; 42 + 9 after.
2026-08-12 22:57:48 -07:00
Peter Steinberger 009e53d582 fix(signal): fail probe when RPC verification fails (#123001) 2026-08-12 22:19:46 -07:00
Peter Steinberger cd0fb355c7 refactor(plugin-sdk): remove retired Copilot login chain (#122988)
* refactor(plugin-sdk): remove retired Copilot login chain

* chore(plugin-sdk): refresh generated API baselines

* build(github-copilot): remove unused prompt dependency

* chore(plugin-sdk): reconcile API baselines after rebase
2026-08-12 22:07:33 -07:00
xingzhou 329ed12fcf fix(discord): chunk long thread initial messages (#117354)
Discord rejected over-limit starter messages and could leave ordinary threads empty after creation.

Split initial content through the existing Discord chunking and nonce-retry path while preserving confirmed-versus-ambiguous partial-delivery results.

Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com>
2026-08-13 10:37:14 +05:30
Patrick Erichsen 074d75d372 test(buzz): add opt-in thread QA coverage (#116081)
* test(buzz): add opt-in thread QA coverage

* fix(buzz): preserve QA conversation kind

---------

Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-08-13 12:54:36 +08:00
sunlit-deng b05d2308e7 fix(memory): keep session reconciliation off search path (#120837)
* fix(memory): keep session reconciliation off search path

* test(memory): decouple reconciliation test from provider fixture

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-08-12 21:42:01 -07:00
Peter Steinberger 05ffeee016 test(oc-path): make perf budgets robust to CI scheduler noise (#122994) 2026-08-12 21:40:44 -07:00
kiranmagic7 095f3e1a44 feat(xai): add Grok 4.6 catalog and preserve OAuth xhigh (#122762)
* feat(xai): add Grok 4.6 catalog and preserve OAuth xhigh

Add first-class Grok 4.6 discovery, pricing, and reasoning metadata while
keeping the existing Grok 4.3 API-key and server-tool defaults unchanged.
Preserve xhigh only for Grok 4.6 so OAuth auto no longer inherits the
Grok 4.5 high downgrade.

Closes nothing; tracks #122734.

* fix(xai): resolve the OAuth auto alias to its canonical model in the thinking policy

The OAuth catalog row keeps id "auto" and records the provider-selected
target in params.canonicalModelId; judging the raw alias collapsed the
default OAuth route to an off-only thinking picker for every model.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* test(xai): refresh catalog-order assertions and restore stream deadlines for Grok 4.6

Exact-order catalog and onboarding arrays now include the new row with its
metadata assertion; payload-capture timeouts return to their original
values, Grok 4.5 off-clamp and Grok 4.3 modern-model coverage are
restored, and the Grok 4.6 xhigh boundary test passes its id explicitly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* feat(agents): add Grok 4.6 to the curated high-signal live matrix

xai is a curated-only high-signal provider, so the new flagship was
structurally excluded from default live sweeps; add it alongside
Grok 4.5 with its test and docs mirrors, matching the 4.5 precedent.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(xai): align Grok frontier metadata

* fix(xai): align Grok 4.6 catalog contract

Remove the unsupported moving alias, centralize OAuth auto target resolution, correct cached pricing, and keep live coverage on the stable xhigh completion path.

Co-authored-by: Kiran Magic <262980978+kiranmagic7@users.noreply.github.com>

---------

Co-authored-by: Kiran Magic <262980978+kiranmagic7@users.noreply.github.com>
Co-authored-by: Kiran Magic <kiran@Alices-Laptop.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Kiran <kiranmagic7@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-12 21:29:51 -07:00
Peter Steinberger bac7a79260 test(extensions): repair stale full-config extension tests (#122978)
clickclack inbound mention gating: #114388 (1ca60fbc3a) made multi-agent fallback ownership explicit, so the #115484 fixture now declares its clickclack:default service-bot binding.

policy CLI: #114388 (1ca60fbc3a) removed ambient ownership from normalized multi-agent configs, so the #111087 routing-probe fixture uses the sole main agent and still reaches the intended findings exit.

Teams and Zoom node invoke policy: #118451 (7d4066639e) added trusted audio backend, buffer size, and format forwarding; assert those fields alongside the configured commands.

Teams node host: #118451 (7d4066639e) made default audio commands platform-dependent at import time after #111455 added the sox dedupe test; reset modules and mock Darwin before importing defaults.
2026-08-12 21:09:42 -07:00
Vyctor H. Brzezowski e647794c20 feat(ui): open bare pair command without a chat turn (#120855)
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-08-12 21:09:13 -07:00
Sarah Fortune 3f731db90c fix(slack): accept org-wide user IDs in Enterprise Grid policies (#122934)
* test(slack): accept org-wide enterprise users

* fix(slack): allow org-wide enterprise users

* style(slack): format enterprise user policy

* test(slack): preserve enterprise user identity scope

* fix(slack): preserve enterprise user identity scope

* fix(slack): import workspace identity normalizer

* fix(slack): normalize enterprise owner ids

---------

Co-authored-by: Sarah Fortune <sarah.fortune@gmail.com>
2026-08-12 21:01:05 -07:00
Peter Steinberger 4d54c3f1a1 refactor(config): retire dead streaming.progress.render key (#122927)
* refactor(config): retire dead streaming.progress.render key

The key had zero runtime consumers after #122552. Core doctor now strips it via stripRetiredTuningKnobs, and production LOC is net -13.

* fix(tooling): pin plugin SDK surface counts to the reduced export set

The retired progress-draft render reader counted twice via channel-outbound and channel-message's wildcard re-export.
2026-08-12 20:36:40 -07:00
Josh Avant 705f043e04 fix(qa): isolate staged auth state (#122958) 2026-08-12 22:30:46 -05:00
Peter Steinberger 08f9c3a5cb test(extensions): remove duplicate runtime replays (#122949) 2026-08-12 19:58:04 -07:00
Vincent Koc ce3d1d22be fix(qa): preserve Code Mode reads in model-switch mock (#122935) 2026-08-13 10:41:42 +08:00
Vincent Koc dabf55727b fix(ci): prevent channel add command test timeout (#122879)
* test(channels): isolate add env setup contracts

* test(channels): cover adapter env setup
2026-08-12 19:24:31 -07:00
Daniel Cárdenas 326501fce3 fix(msteams): honor inbound channel media limit (#122315)
* fix(msteams): honor inbound channel media limit

* test(msteams): update lifecycle runtime mock

* style(msteams): avoid resolver config shadowing

* style(msteams): format lifecycle resolver mock

* refactor(msteams): inline media fallback

---------

Co-authored-by: DanielCardenas <djerez@lean-tech.io>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-08-12 19:06:47 -07:00
Calin Laurentiu Ilie 95bbd117ef fix(slack): prevent duplicate Socket Mode connections after reconnect errors (#122624)
* fix(codex): read canonical transcript session targets (#1)

* test(slack): reproduce reconnect timer surviving shutdown

* fix(slack): keep reconnects within one socket lifecycle

* test(slack): exercise native reconnect over loopback

* test(slack): satisfy reconnect integration checks
2026-08-12 18:57:04 -07:00
Peter Steinberger fd0fc80c8c test(microsoft-foundry): remove global test bridge (#122881)
* test(microsoft-foundry): remove global test bridge

* test(microsoft-foundry): type boundary fixtures

* perf(ui): keep route transition out of startup
2026-08-12 18:53:44 -07:00
Peter Steinberger 10a1a43f4b fix(zalo): keep packaged setup wizard loadable (#122902)
* fix(zalo): package setup runtime surface

* fix(tooling): track setup surface artifacts
2026-08-12 18:49:41 -07:00
joshavant 93cf912695 fix(matrix): retain visible drafts on handler abort 2026-08-12 20:32:32 -05:00