* fix(ui): preserve steering stream order
Record exact steering provenance and keep cumulative assistant output on its causal side of persisted user turns across live streaming, terminal events, tool boundaries, and history reloads.
* chore(ci): refresh post-rebase gates
Tighten the inherited environment-variable budget and remove a stale test import exposed by the rebased lint gate.
* fix(ui): preserve terminal steer stream segment
Assert the causal stream rollover when a steer lands and move persisted split-layout normalization off the startup path to keep the Control UI bundle within budget.
* refactor(ui): extract split layout types
Keep the persisted split-layout normalizer off the interactive module cycle while preserving the Control UI startup bundle reduction.
* fix(gateway): resolve steering provenance at injection
* fix(gateway): confirm steering provenance after persistence
* refactor(ui): move live tool filtering to identity owner
* fix(ui): preserve queued user stream ceiling
Plugins holding a remote URL had no non-deprecated Plugin SDK path to turn it into managed media; saveMediaSource was only reachable through the deprecated media-runtime barrel while docs pointed at media-store. Re-export it from the focused subpath and move the bundled qa-channel plugin off the deprecated barrel. Maintainer decision: full saveMediaSource (local path + HTTP(S)) is the supported media-store contract.
Fixes#125259
Show an explicit waiting acknowledgment when sessions_yield ends an otherwise-silent interactive turn, while keeping private resume context out of channel delivery and preserving existing visible replies.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(agents): report interrupted tool outcomes honestly
Prevent restart recovery from claiming that an interrupted tool call completed when no successful matching result was recorded.
* fix(agents): keep ambiguous recovery restart-safe
Classify failed replay-unsafe tool results at the shared restart-recovery owner so interrupted side effects remain unavailable until their external state is verified.
* fix(agents): distinguish missing tool outcomes
Carry the existing missing_tool_result fact into projected Codex transcripts so restart recovery restricts only genuinely unknown outcomes, while confirmed failures remain retryable.
* feat(sessions): teach session tools the Control UI link rule
Gate guidance on publicOrigin plus enabled Control UI, with exact literal-URL fallback after short-link misses.
* feat(ui): linkify session keys in chat markdown
Match agent session keys structurally in plain text and inline code, then delegate canonical chat navigation.
Allowlist data-session-key through markdown sanitization.
Pathfinder: keep internal Control UI route anchors in-app by removing target="_blank" and external-link rel attributes while preserving external link behavior.
* feat(ui): session hovercard + titled session chips backed by controlUi.sessionPreview
* fix(gateway): scope controlUi.sessionPreview to caller-visible sessions
Hover previews now apply the same createSessionListEntryFilter predicate as
sessions.list, so identity-bearing non-admin callers cannot preview-by-key
incognito rows or non-owner drafts the sidebar hides. Regression test proves
the viewer/admin split; pre-fix run leaked ok-status metadata.
* feat(sessions): carry the session-link rule in tool result envelopes
Deferred-description mode hides prose tool descriptions at decision time. Carry the shared Control UI session-link sentence in successful session lookup result envelopes so every tool mode sees the rule.
* fix(ui): upgrade session chips on appearance, not first pointer event
* fix(android): regenerate gateway protocol methods
* test(gateway): track session preview release train
* perf(ui): lazy-load session hovercard registration
* fix(ui): keep session hovercards off sidebar navigation
* fix(ui): cancel routed session-link navigation
* fix(sessions): advertise forced-literal ~key URLs so short-ID collisions cannot misroute
* test(sessions): update forced-literal guidance expectation
* fix(ui): collision-proof raw-key navigation and SPA-route internal session URLs
* perf(ui): preserve session route lazy boundary
* fix(ui): defer unseeded session-preview fetches to hover intent
* fix(sessions): hard-cap the model-visible session-link base
* fix(cli): keep gateway diagnostics read-only
Direct gateway calls and diagnostic probes now preserve shared SQLite ownership instead of creating or mutating state during read-only operations.
Related: #101290
Follow-up to #125102
* fix(cli): keep required status probes read-only
* feat(sessions): stamp agent identity on spawned sessions and return spawn receipts
Agent-spawned sessions recorded the requesting session key as createdActor.id,
so the Control UI creator chip rendered an opaque key. Spawn producers now stamp
the canonical requester agent id; parent-authority validation moves to a new
trusted requesterSessionKey field. projectSessionActor enriches agent actors
with configured identity name/avatar at read time, and visible sessions_spawn
returns a sessionUrl + owner receipt with URL-first acknowledgement guidance.
* feat(sessions): assignable session ownership with owner facet and menus
GitHub-assignee-style ownership: sessions get a mutable owner (defaulting to
the immutable createdActor) stored in additive bare-nullable SQLite columns
with first-use lazy ensure. New operator.write sessions.assignOwner validates
targets, requires an identified caller, authorizes by session visibility, and
records assignedBy/assignedAt inside the write transaction. The sessions agent
tool gains assign_owner; the Control UI adds Assign-to-me/Assign-to menus in
sidebar rows and chat headers, renders the effective owner chip, and the
creator facet/filter now keys on effective owner. Sharing authority stays
anchored on createdActor.
* feat(sessions): record session participants and stack them in the owner chip
Records every distinct external prompter (human profile/channel sender, or a
requesting agent) per session in an additive session_participants table at the
turn-admission boundary — best-effort, deferred, never blocking the turn; the
session's own agent and viewers are never recorded, capped at 32 per session.
The session row projects a bounded participants list (owner excluded) plus a
total count with the same actor enrichment as owner/createdActor. The sidebar
chip becomes a pair-stack when others have prompted (owner front, one peeking
participant or +N behind), the chat header shows the full facepile, and an
authenticated involvingMe list filter adds an Involving-me sidebar predicate.
Participant projection is excluded from logical-session CAS equality so display
history never invalidates session writes.
* fix(sessions): identify built-in agent tool callers for owner assignment
The sessions tool's assign_owner dispatched through the in-process synthetic
client, which carries neither a signed agent-runtime identity nor a human
profile, so agent-initiated reassignment always failed with FORBIDDEN. The
tool now captures its trusted requester agent identity and carries it across
in-process dispatch as internal client state (never wire params); the handler
derives assignedBy as signed runtime identity, then trusted agent-tool caller,
then authenticated human. Live-verified end-to-end on a dev gateway.
* fix(ci): split oversized session modules and refresh prompt snapshots
Split the max-lines offenders at concept boundaries for session equality, tool overrides, and protocol owner schemas. Remove the redundant Number conversion from the node:sqlite participant count. Refresh prompt snapshots after drift from the sessions and sessions_spawn tool description updates.
* fix(ci): restore solo-mode chip suppression and conform new method descriptors
Solo-mode root cause: owner-assignment submenu options reused the permanent owner-chip custom element, so hidden menu avatars were counted as attribution chrome. Menus now use viewer avatars while gateway-gated owner chips remain exclusive to collaborative sessions.
Conform sessions.assignOwner to the 2026.8 descriptor and append-only advertised-method inventories, and regenerate the Swift and Kotlin protocol surfaces.
Keep historical v15/v14 fixtures frozen by stripping the new owner columns; the existing range already excludes the participant table. Replace the new raw SQLite schema probes with synchronous Kysely queries.
Clear max-lines by splitting the organizer host contract, pure agent-navigation projections, and ownership/filtering sidebar cases at their concept boundaries.
* fix(ci): integrate ownership series with latest main surfaces
Wire the sessions-page assign-owner action, merge capability imports, narrow the navigation export scope, and apply sessions-create formatting.
The owner-presence regression came from hidden assign-owner menu avatars emitting data-viewer-id, so owner and menu chrome now opt out of presence markers while real facepiles retain them.
* fix(sessions): scope the involving-me filter to profile-backed participants
Session participant history mixed channel-native sender ids with authenticated Gateway profile ids, so involving-me missed real sessions and could accept numeric collisions.
Record the actor_source namespace at each producer, carry it through the internal SQLite projection, and match authenticated viewers only against profile-backed human participants. Legacy NULL sources fail closed for filtering, while channel ids remain available for display.
* build(ui): raise startup budget baseline for session ownership surfaces
Ownership chips, assignment menus, and the participant stack add ~0.7 KiB
gzip to the startup path; CI compression landed just over the previous
baseline+tolerance. Hard cap (350 KiB) unchanged.
* refactor(sessions): drop raw NULL projection for the lazy actor_source column
The Kysely guardrail rejects typed raw sql snippets outside allowlisted
boundaries; select the lazily-ensured column only when present and let the
row projection treat its absence as unknown/legacy.
* build(ui): refresh combined startup baseline
* fix(cli): keep gateway controls off plugin state
Use core-only config validation for gateway call and restart so schema-ahead recovery can reach the running Gateway without opening newer persisted plugin metadata.\n\nFixes #125115
* test(infra): isolate browser open SSH environment
* test(cli): cover gateway call validation policy
update-cli.test.ts used a fixed /tmp/openclaw-update-tests root with
deterministic case-dir names; some cases write real fixture files there
and cleanup rm -rf's them, so concurrent runs on one machine (CI shards,
sibling checkouts) deleted each other's live fixtures — observed as 34
spurious failures on PR #124997 run 31992421445. migrate.test.ts had the
same shape via a fixed mocked resolveStateDir root rm -rf'd in
beforeEach/afterEach.
Both suites now use per-run mkdtemp roots, realpath'd for the macOS
/var -> /private/var symlink, removed on suite exit.
Classify text interrupted by resumed reasoning at the OpenAI-completions producer boundary, so channels deliver only the confirmed final answer.
Defer phase-ambiguous replies until terminal classification while preserving live partial delivery for ordinary completions.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Teach isolated cron delivery prompts to return only recipient-facing text, without adding lexical filtering to the delivery transport.
Co-authored-by: Jeremy Sasson <jeremy.sasson@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>