Peter Steinberger
a3b2700dff
fix(deps): bump @openclaw/fs-safe to 0.5.5 for win32 zero-inode identity ( #122427 )
2026-08-11 21:46:22 -07:00
Peter Steinberger
964c8c84c1
refactor: consolidate coercion ownership ( #122299 )
...
* refactor: consolidate coercion ownership
Centralize four canonical coercion helpers, migrate exact core and plugin duplicates through narrow Plugin SDK facades, and enforce declaration and plugin-normalization ownership boundaries.
The sweep adds eight focused SDK exports while deleting more production and tooling code than it adds. User-visible behavior is unchanged except for safer equivalent object and UI parsing at existing boundaries.
* fix: guard integer option ownership
Register resolveIntegerOption with the canonical function owner and extend the declaration-guard fixture so future local duplicates fail validation.
* fix: keep integer helpers on numeric facade
Remove the unshipped duplicate string-coerce exports and route every affected plugin consumer through the existing number-runtime contract.
* fix: point numeric coercion to number runtime
Make boundary and declaration diagnostics recommend the canonical numeric facade, with failing-before coverage for both guidance paths.
2026-08-11 17:14:53 -07:00
Peter Steinberger
cad77fb39c
refactor: consolidate remaining coercion helpers ( #122020 )
2026-08-11 10:22:01 -07:00
Peter Steinberger
fa03d9b913
refactor: consolidate coercion helpers ( #121366 )
...
* refactor: consolidate coercion helpers
* fix: remove duplicate coercion imports
* fix: preserve serialized coercion guard
* chore: ratchet coercion helper carve-outs
* fix(test): keep gauntlet subprocess startup lean
* fix: preserve imported session timestamp semantics
* fix: preserve catalog timestamp string semantics
* chore: align plugin SDK surface ratchet
* fix: preserve trajectory and SDK string contracts
* fix(test): preserve QA record assertion semantics
* fix: complete standalone record guard rename
* refactor(cron): use canonical string coercion
* fix(acpx): preserve Pi timestamp parsing
* test(channels): adapt custody test harnesses
* test(telegram): classify media harness as test support
* test(acpx): split timestamp contract coverage
* test(channels): support generated custody contracts
* chore: ban the full coercion helper name set
Extends the declaration guard to all eleven consolidated helper names and
renames the cron schedule-identity readNumber wrapper to readScheduleInteger
so the banned generic name cannot regrow.
* fix(scripts): repair release-validation guard drift and lint cause
Restores the renamed isJsonRecord guard in assertTrustedWorkflowHarness after
main added isRecord call sites in parallel, and attaches the caught YAML error
as the thrown error cause (preserve-caught-error was red on main).
* fix: preserve Claude timestamp string semantics
* fix: preserve persisted timestamp string semantics
* fix: preserve date-first timestamp contracts
* fix(openai): harden delegation failure formatting
* chore: close coercion helper guard gaps
* test(openai): model non-error delegation rejection
* chore: refresh plugin SDK API contract
* fix(tasks): use canonical string field reader
* fix(ai): use canonical provider error field coercion
* fix(browser): migrate native bootstrap coercion
* docs(plugin-sdk): clarify text record export compatibility
* fix(gateway): normalize approval execution identity
* test(outbound): isolate message action poll harness
2026-08-11 00:02:18 -07:00
Peter Steinberger
b6b937d6ac
chore(types): give test helpers nameable exported types ( #121783 )
2026-08-10 18:17:50 -07:00
Ayaan Zaidi
5295f2578e
fix(agents): make file reads safe and explicit ( #121508 )
...
Use fs-safe 0.5.4 for nonblocking, descriptor-validated reads. Resolve one unambiguous Unicode-equivalent path and return explicit empty/EOF results.
Default local reads now reject final symlinks and special files.
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-10 20:17:53 +05:30
Peter Steinberger
8616c0c374
refactor: finish shared test helper migrations ( #120996 )
...
* test: finish shared helper migrations
* test: fix helper migration CI
* style: fix test import ordering
* test(acpx): restore deferred void types
* test: fix helper migrations after rebase
2026-08-09 06:00:06 -07:00
Peter Steinberger
48639663b0
chore(release): prepare 2026.8.1 ( #120375 )
2026-08-07 18:44:12 -07:00
Peter Steinberger
58025dd33c
fix(fs): adopt fs-safe 0.5.2 untrusted filename sanitization ( #119363 )
...
* fix(fs): adopt fs-safe 0.5.2 untrusted filename sanitization
* fix(media): classify pre-open identity drift as access denial
* chore(checks): refresh SDK baseline and env-var budget for fs-safe adoption
* test(media): compact sanitizer cases under max-lines
* fix(agents): keep workspace symlink contract under fs-safe 0.5.2
* fix(infra): align path normalization and atomic-write proofs with fs-safe 0.5.2
* fix(fs): keep operator symlink contracts on config, control-ui, skills, hooks
* fix(fs): restore sandbox and session-lock contracts under fs-safe 0.5.2
* test(claws): expect symlink diagnostic for tampered plan parents
* fix(agents): canonicalize apply-patch mutations through contained aliases
* test(agents): split alias-update regression into focused file
---------
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local >
2026-08-04 17:53:44 -07:00
Peter Steinberger
deb682abfe
refactor(plugins): consolidate extension runtime helpers ( #118509 )
...
* refactor(plugins): consolidate extension runtime helpers
* fix(ci): satisfy extension type and lint checks
* chore(plugin-sdk): regenerate API baseline for #118509
2026-08-03 02:56:43 -07:00
Peter Steinberger
7c70571683
chore(lint): clear 172 lint:all baseline violations in five batches ( #118098 )
...
* chore(lint): clean Android-Linux app assets batch
* chore(lint): clean setup-launcher-plugin batch
* chore(lint): clean changelog-updater batch
* chore(lint): clean QA-runtime-helper batch
* chore(lint): clean script-tests batch
* fix(mxc): await sandbox spawn before bridge selection
* fix(test): make fake plutil metacharacter escaping survive the template hop
2026-08-02 14:08:09 -07:00
Peter Steinberger
30b7a3acb7
test(onepassword): speed resolver process fixtures ( #118102 )
...
* test(onepassword): speed resolver process fixtures
* test(onepassword): relax staged resolver deadline
* test(onepassword): canonicalize timeout fixture shell
---------
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local >
2026-08-02 11:31:08 -07:00
Peter Steinberger
4b26a15a1f
refactor: remove dead internal exports ( #117819 )
2026-08-01 22:01:38 -07:00
Peter Steinberger
4232126bba
chore: update dependencies across workspace ( #115677 )
...
* chore(deps): update dependencies
* fix(deps): restore CI compatibility
2026-07-29 05:16:42 -04:00
Peter Steinberger
302f262e6b
refactor: deduplicate extension normalization primitives ( #115650 )
...
* refactor(plugins): reuse SDK normalization primitives
* fix(ci): repair code-mode matrix checks
* fix(ci): satisfy code-mode matrix gates
* fix(ci): use matrix evidence export
* fix(ci): validate matrix evidence artifact
2026-07-29 04:10:06 -04:00
Peter Steinberger
3e4c57dbeb
fix(onepassword): resolve secret refs under Bun by dropping execa buffer encoding ( #114346 )
2026-07-27 03:15:17 -04:00
Peter Steinberger
f6131a4fbf
build(deps): remove npm shrinkwrap; mirror pnpm lock into transient package locks ( #114006 )
...
* build(deps): remove npm shrinkwrap; mirror pnpm lock into transient package locks
npm 12 removed shrinkwrap (command + tarball/root loading). Delete all 82
committed npm-shrinkwrap.json files and stop publishing lockfiles; keep
pnpm-lock.yaml as the single reviewed dependency boundary. The generator
becomes scripts/generate-npm-package-lock.mjs and feeds plugin bundling via
a transient package-lock.json + npm ci (works on npm 11 and 12). Tarball
validation treats the published 2026.7.2 beta train as a shrinkwrap
transition; self-update npm detection now uses install topology instead of
the shipped shrinkwrap.
* fix(deps): repair lint, deadcode, and test-type lanes for the npm 12 migration
- sort integrity comparisons with an explicit comparator (oxlint)
- keep resolveBunGlobalNodeModules module-local (knip unused-export gate)
- model npm pack --json as npm<=11 array / npm 12 name-keyed object
- default calver destructuring in the tarball test fixture
2026-07-26 01:29:55 -04:00
Peter Steinberger
7be5c0a7c9
test(plugins): repair prerelease fixture contracts ( #113877 )
...
* test(plugins): repair prerelease fixtures
* test(onepassword): run resolver fixture from source
* test(moonshot): align catalog input fixtures
2026-07-25 14:54:39 -07:00
Peter Steinberger
481d826ff4
fix(vault): prevent insecure secrets plan writes ( #113707 )
...
* fix(vault): harden secrets plan writes
* fix(secrets): avoid env marker collision
* style(secrets): type plan write rejection
* refactor(onepassword): remove obsolete path resolver
* fix(secrets): preserve Windows plan path trust
* refactor(secrets): compact ACL token policy
* fix(secrets): route permission checks through facade
2026-07-25 08:27:33 -07:00
joshavant
f153858045
fix(onepassword): make SecretRef setup production-safe
2026-07-25 06:03:30 -05:00
joshavant
56bf326371
fix(onepassword): bound SecretRef resolution lifecycle
2026-07-25 06:03:30 -05:00
joshavant
fb8589ebdb
fix(onepassword): harden trusted op execution
2026-07-25 06:03:30 -05:00
sallyom
f045f33a62
feat(onepassword): add managed SecretRef integration
2026-07-25 06:03:30 -05:00
Peter Steinberger
8bf4d388b0
fix(onepassword): disable desktop-app integration on broker op calls ( #109157 )
...
Without OP_LOAD_DESKTOP_APP_SETTINGS=false and OP_BIOMETRIC_UNLOCK_ENABLED=false,
op 2.35 on macOS reads the 1Password desktop app's settings even on the
service-account path and can block on a per-PID App Data Protection dialog,
hanging the broker until timeoutMs on Mac gateway hosts.
2026-07-16 09:15:03 -07:00
Peter Steinberger
e1fda44ecc
fix(onepassword): preserve oversized token diagnostics ( #108964 )
2026-07-16 04:52:36 -07:00
wahaha1223
df72216580
fix(onepassword): reject oversized service account token files ( #108596 )
...
* fix(onepassword): reject oversized service account token files
* fix(onepassword): clarify oversized token errors
Co-authored-by: wahaha1223 <0668001153@xydigit.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-16 02:48:49 -07:00
Peter Steinberger
30738a3c3b
fix(onepassword): preserve authorization handoff
2026-07-14 23:23:17 -04:00
Peter Steinberger
3d15bf513e
fix(onepassword): preserve pending tool authorization ( #107275 )
...
* fix(onepassword): preserve pending tool authorization
* refactor(onepassword): consume pending authorization in helper
* chore: defer release note generation
2026-07-14 01:12:04 -07:00
mushuiyu886
ef25cefc8e
fix(onepassword): validate audit limit strictly ( #106926 )
...
* fix(onepassword): validate audit limit strictly
* test(onepassword): strengthen audit limit coverage
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-13 21:37:07 -07:00
Leon-SK668
5864fa2dbf
fix(onepassword): preserve Unicode in audit reason truncation ( #106424 )
...
* fix(onepassword): preserve Unicode in audit reason truncation
* test(onepassword): strengthen Unicode audit boundary proof
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-13 17:01:14 -07:00
Peter Steinberger
db02a96c4c
refactor(process): route bounded commands through Execa ( #106495 )
...
* refactor(process): centralize bounded command execution
* refactor(process): migrate core one-shot commands
* refactor(plugins): migrate one-shot commands
* fix(process): await Windows tree termination
* chore(plugin-sdk): refresh process runtime surface
* refactor(process): migrate remaining bounded commands
* refactor(process): normalize command result handling
* refactor(process): split execution responsibilities
* chore(plugin-sdk): refresh API baseline
* chore(process): remove release-owned changelog entry
* fix(process): narrow binary command input checks
* fix(process): cap sandbox command output
* fix(qa-lab): preserve exact node probe env
* chore(ci): refresh dead export baseline
* fix(process): preserve force-kill command deadlines
* fix(process): avoid post-exit timeout reclassification
* test(process): update scp staging wrapper mock
* test(process): update remaining wrapper mocks
* refactor(qa-lab): preserve Execa tar execution
2026-07-13 11:07:35 -07:00
Peter Steinberger
6bb85f177f
feat(onepassword): optional 1Password secrets broker plugin ( #106133 )
...
* feat(onepassword): add optional 1Password secrets broker plugin
Curated slug registry with per-item auto/approve/deny policy, plugin-approval
gating with expiring allow-always grants, SQLite audit history, onepassword
status/audit CLI, and a single-attempt op client (--cache=false, minimal env).
Closes #105924
* docs(plugins): refresh generated inventory count after rebase
* fix(onepassword): scope grants and field reads
* fix(onepassword): bound grant retention
* fix(onepassword): satisfy deadcode ratchet and hook allowlist contract
* fix(onepassword): honor live policy reloads
* refactor(onepassword): trim private exports
* test(onepassword): satisfy plugin boundaries
* test(onepassword): document temp directory boundary
2026-07-13 03:12:47 -07:00