Commit Graph

78555 Commits

Author SHA1 Message Date
joshavant 50cc620f0b docs(whatsapp): clarify typing cleanup timing 2026-08-07 16:38:27 -05:00
Peter Steinberger b53c02b2f2 fix(ui): preserve slow build-link navigation (#120334)
* fix(ui): preserve slow build-link navigation

* test(ui): stabilize slow build-link e2e
2026-08-07 14:32:14 -07:00
Peter Steinberger 0aa85c7f83 perf(gateway): reuse lifecycle plugin metadata instead of per-turn rescans (#120344)
* perf(gateway): reuse lifecycle plugin metadata

* test(commands): expect workspace-scoped snapshot reuse in sessions metadata prep
2026-08-07 14:20:21 -07:00
Peter Steinberger 45b1dbf962 test(qa): add managed-worktrees CLI lifecycle scenario coverage (#120335)
* test(qa): add managed-worktrees CLI lifecycle scenario coverage

Managed worktrees had zero QA scenario-pack coverage despite being a
headline feature. Mint agent-runtime.managed-worktrees-lifecycle in the
taxonomy, add a runtime scenario, and prove the real child CLI through
create with .worktreeinclude provisioning and the .openclaw setup hook,
dirty removal pinning a snapshot ref, restore rebuilding tracked,
untracked, and provisioned files with their modes, and gc preserving
manual worktrees.

* fix(qa): align model-switch catalog assertion with expectedAlternate flow

qa/scenarios/models/model-switch-follow-up.yaml switched to
expectedAlternate.model in 5a795f4dda but the catalog test still greps
for the retired alternate?.model literal; the test is outside the PR
change-classification lanes, so the break only surfaces on direct runs.

* test(qa): narrow managed-worktrees taxonomy description to proven manual-owner gc

ClawSweeper P2 on #120335: the scenario proves manual-owner gc retention
only; session and Workboard cleanup lifecycles are not exercised, so the
coverage description must not claim them.
2026-08-07 14:18:12 -07:00
joshavant 87156bab23 fix(typing): keep long active turns visible 2026-08-07 16:11:52 -05:00
Peter Steinberger 32361e749a fix(voice-call): isolate runtime generations (#120289)
Prevent retained plugin closures from recreating, adopting, or stopping successor runtimes across shutdown and restart.

Add deterministic lifecycle regressions for pending startup, exact-owner stop, retained tools, and generation restart.
2026-08-07 13:56:26 -07:00
Peter Steinberger 10e60fa0ce refactor(plugins): shared legacy-state doctor migration and simple secret contracts (#120346)
* refactor(plugins): share legacy JSON doctor migration

* refactor(discord): share account token inspection cascade

* refactor(plugins): share simple channel secret contracts

* refactor(discord): keep token inspector private
2026-08-07 13:55:31 -07:00
Vincent Koc 3a0216ce29 fix(ci): accept neutral draft gate runs (#120310)
* fix(ci): accept neutral draft gate runs

* fix(ci): retain decisive gate success

* fix(ci): keep pending gate runs authoritative

* fix(ci): order hosted gates by creation
2026-08-08 04:53:10 +08:00
Vincent Koc 588d8bb853 fix(qa): preserve script evidence coverage (#120286) 2026-08-08 04:42:21 +08:00
WhatsSkiLL 62937ea6fc fix(android): keep Wear chat on the latest reply (#120307)
Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-08-07 16:32:30 -04:00
joshavant ac2994a0e2 fix(ios): keep permission actions readable 2026-08-07 15:27:58 -05:00
joshavant 0bcbaf2eda fix(ios): remove permission pre-prompts 2026-08-07 15:27:58 -05:00
Vincent Koc 8c68f74ef9 fix(ci): align hosted gates with workflow applicability (#120313) 2026-08-08 03:59:27 +08:00
Josh Avant c691f2e41c fix(progress): preserve callback acceptance results (#120171)
* fix(progress): preserve callback acceptance results

* fix(progress): require transport acknowledgements

* fix(progress): preserve direct acceptance outcomes
2026-08-07 14:40:33 -05:00
Peter Steinberger b99c507ce6 docs(plugins): include Agent Plugins in the plugins page read-when hints (#120323) 2026-08-07 12:35:03 -07:00
Shakker a3cf376258 fix: isolate debug diagnostics failures (#117546) 2026-08-07 20:24:38 +01:00
Peter Steinberger 3d4a7d4962 fix(ui): isolate debug diagnostics and supersede stale RPC calls 2026-08-07 20:24:37 +01:00
Peter Steinberger 6543e6f7c9 fix(discord): thread archive/delete closes sessions in each agent's store (#120259)
* fix(discord): thread archive/delete closes sessions in each agent's store

closeDiscordThreadSessions resolved the sessions store with the Discord
account id as agentId ('default' on the default path), which points at a
nonexistent agent's store — archiving or deleting a thread silently closed
nothing. The store now resolves per routed agent via listAgentIds and every
agent's matching sessions are deleted.

* fix(discord): type thread session cleanup across agent stores

* fix(discord): scope thread-session scan per agent and keep it read-only

* test(discord): cover thread deletion across agent stores
2026-08-07 12:08:36 -07:00
Peter Steinberger 5a795f4dda fix(qa): require a fresh reply and real tool use after switching models (#119662)
* fix(qa): require a fresh reply after switching models

* fix(qa): prove successful tool use after model switching

* fix(qa): wait for the new persisted model-switch tool result

* fix(qa): authenticate canonical model-switch attempt evidence

* fix(ai): preserve effective response model evidence

Punchcard-Session: golden-valley-workshop-br

* fix(agent): publish run-owned terminal receipts

Punchcard-Session: golden-valley-workshop-br

* fix(qa): require run-owned model-switch evidence

Punchcard-Session: golden-valley-workshop-br

* fix(agent): record explicit tool completion outcomes

Punchcard-Session: golden-valley-workshop-br

* fix(agent): exclude unavailable approvals from receipts

Punchcard-Session: golden-valley-workshop-br

* fix(agent): derive receipt visibility from terminal reply

Punchcard-Session: golden-valley-workshop-br

* fix(qa): bind model-switch continuity to terminal reply

Punchcard-Session: golden-valley-workshop-br

* fix(qa): project Crabline Telegram visible text

Punchcard-Session: golden-valley-workshop-br

* fix(qa): record run-owned delivery evidence

Punchcard-Session: golden-valley-workshop-br

* fix(qa): bind primary model-switch delivery

Punchcard-Session: golden-valley-workshop-br

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-08-08 03:05:32 +08:00
Peter Steinberger b12616b444 fix(agents): quota suspension resolves the real owning agent instead of no-opping (#120262)
* fix(agents): session quota suspension resolves the real owning agent

suspendSession derived the agent id from path.basename(agentDir), which is
always the literal 'agent' in the default <state>/agents/<id>/agent layout —
the quota-suspension marker landed in a nonexistent agent's store and the
suspension silently no-opped. Callers now pass the explicit agentId through
runWithModelFallback/throwFallbackFailureSummary, with the agent-dir registry
as fallback for dir-only callers.

* fix(agents): embedded failure suspensions carry the run's agent id
2026-08-07 11:56:15 -07:00
Peter Steinberger d448a25a8a refactor(test): compress repetitive fixtures in mega-tests, batch 3 (#120294)
* refactor(test): compress subagent lifecycle fixtures

* refactor(test): compress model resolution fixtures

* refactor(test): compress Telegram bot fixtures

* refactor(test): compress reply-agent e2e fixtures

* refactor(test): compress Matrix SDK fixtures

* refactor(test): compress QMD manager fixtures

* refactor(test): compress gateway chat fixtures

* refactor(test): compress gateway reload fixtures

* fix(test): preserve raw Telegram secret fixture

* fix(test): retain session fixture key type

* fix(test): preserve raw reload secrets fixture

* fix(test): retain gateway fixture parameter types
2026-08-07 11:48:46 -07:00
Peter Steinberger 2fa9a29c77 test(plugins): add Agent Plugins gateway e2e with model-driven MCP tool call (#120303)
* test(plugins): add Agent Plugins gateway e2e with model-driven MCP tool call

* fix(test): wire Agent Plugins gateway E2E and assert activation
2026-08-07 11:47:07 -07:00
Peter Steinberger c25671cf27 fix(imessage): stop dropping user text that collides with recent outbound sends (#120260)
* fix(imessage): text echo matching honors message-id conflicts; own sends stop feeding the loop limiter

Two silent-drop paths in the iMessage monitor:
1. The persisted 12h echo cache matched inbound user text against old
outbound text even when the GUIDs conflicted — a user sending 'ok' within
12h of the agent sending 'ok' was dropped as an echo. The text branch now
applies the same hasConflictingMessageIds guard the media branch has;
genuine reconnect echoes still match by id or id-less entries.
2. Every from-me row fed the echo loop rate limiter, so a normal outbound
burst (agent replies, multi-chunk sends, operator phone traffic) could trip
the limiter and silently suppress the next legitimate inbound message.
'from me' is no longer counted as a loop signal, and a tripped limiter now
logs a default-level warning once per conversation instead of verbose-only.

* fix(imessage): preserve delayed echo guards
2026-08-07 11:17:06 -07:00
Peter Steinberger a68ff9961c fix(discord): surface inbound attachment download failures (#120269)
* fix(discord): surface inbound attachment download failures

* fix(discord): carry the media-unavailable notice into the agent text
2026-08-07 11:14:49 -07:00
Peter Steinberger c93b3f7045 fix(agents): failed compaction no longer zeroes live assistant usage (#120264)
* fix(agents): failed compaction no longer zeroes live assistant usage

* test(agents): pin usage-zeroing to completed compaction ends
2026-08-07 11:12:26 -07:00
wanyongstar fcdc8460e3 fix(plugins): reject malformed percent-encoding in local JSON Schema $ref anchors (#120254)
…$ref anchors

resolveLocalRef decoded plain-anchor fragments with a bare
decodeURIComponent while the pointer branch already tolerated bad
escapes via decodePointerSegment's try/catch. A schema carrying
$ref: "#%" (a single typo'd hand-written anchor) made
findJsonSchemaShapeError throw a raw URIError that escaped
validateJsonSchemaValue, crashing plugin/channel config validation,
doctor, and gateway startup with a message that pointed nowhere near
the offending schema.

Decode anchor fragments with the same tolerance: a malformed escape
now resolves to { found: false } and surfaces as the intended
"<path>.$ref: unresolved ref" diagnostic.

Co-authored-by: Tak Hoffman <781889+Takhoffman@users.noreply.github.com>
2026-08-07 13:11:49 -05:00
Peter Steinberger 824cf2dcd9 fix(cron): isolate post-persist notification failures from the store write (#120266) 2026-08-07 11:09:54 -07:00
Peter Steinberger 4188f6892d refactor(test): replace logic-bearing vi.mock factories with boundary fakes, batch 3 (#120291)
* refactor(test): exercise real session rewind policy

* refactor(test): use real Telegram media policy

* refactor(test): exercise real HTTP cancellation lifecycle

* test(gateway): prove mutations clear queued session work
2026-08-07 10:54:58 -07:00
Jason (Json) ab4761f3fc fix(ui): preserve structured login error codes (#120069) 2026-08-07 11:09:11 -06:00
Peter Steinberger dcb125d202 fix: remove retired insecure auth guidance (#120295) 2026-08-07 09:45:48 -07:00
Vyctor H. Brzezowski b738e25780 docs: promote Release and CI navigation (#119802) 2026-08-07 09:21:57 -07:00
Vincent Koc c549250bfa test(diagnostics): cover OTEL exporter contracts (#120261) 2026-08-07 23:45:32 +08:00
Ayaan Zaidi 5e477aff2a feat(status): render /status as a native rich card and declutter the plain body (#120167)
* feat(status): render /status as native rich tables on channels that support them
* feat(status): tighten rich /status layout into a titled native table card
* feat(status): trim rich /status tail to one clock-and-uptime context line
* feat(status): context meter, hot-window warning, and default-noise trim in rich card
* test(status): satisfy SessionEntry sessionId in meter fixture
* fix(telegram): gate rich table islands off legacy HTML sends and cover payload sends
* test(telegram): split outbound-adapter presentation tests to satisfy max-lines
* fix(outbound): make presentation capability resolution formatting-aware
* fix(telegram): defer presentation canonicalization on rich accounts until send
* feat(status): one fact per line in the plain status body
* feat(status): group the plain status body into blank-line sections
* feat(status): lead the rich status card with the version title

---------

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-07 20:46:52 +05:30
WhatsSkiLL a23444fc74 fix(android): gate Wear model controls by operator scope (#120016)
* fix(android): gate Wear model controls by operator scope

* chore(android): refresh native i18n inventory

---------

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
Co-authored-by: Colin Johnson <colin@solvely.net>
2026-08-07 11:00:41 -04:00
SunnyShu 3bc188efe5 fix(diagnostics-otel): keep telemetry exporting across in-process restarts (#120131)
* [AI] fix(diagnostics-otel): keep telemetry exporting across in-process restarts

Owned diagnostics-otel generations previously registered their OpenTelemetry
providers globally and only shut the providers down on stop. The pinned
sdk-node registers globals without override and never unregisters them, so a
second in-process generation (config-watcher reload, OPENCLAW_NO_RESPAWN=1,
containers) kept exporting through the first, already-shutdown providers and
telemetry silently stopped.

Switch owned mode to private BasicTracerProvider + MeterProvider instances
whose handles are injected directly into the existing recorder runtime, and
keep the preloaded (OPENCLAW_OTEL_PRELOADED=1) mode on the host's global
providers without ever registering or replacing globals. Resource detection
honors the pinned NodeSDK OTEL_NODE_RESOURCE_DETECTORS contract (unset
defaults to env+process+host; none/subset/all are respected), and the unused
@opentelemetry/sdk-node dependency is removed with a minimal lockfile update.

Adds a real-SDK two-generation restart regression, real-SDK resource-detector
selection coverage, migrates the unit mocks to the provider lifecycle, and
updates the OpenTelemetry docs.

Fixes #119997

Co-Authored-By: glm-5.2 <noreply@anthropic.com>

* [AI] test(diagnostics-otel): restore OpenTelemetry globals after restart test

The restart regression disables global context, metrics, propagation, and
trace APIs and forces OPENCLAW_OTEL_PRELOADED=0, but its cleanup only reset
diagnostic events, so a later test in the same worker could inherit no-op
providers. Snapshot the prior global registrations and preloaded env at
module load, and re-register/restore them in afterEach, matching the
existing exporter-health integration test pattern.

Co-Authored-By: glm-5.2 <noreply@anthropic.com>

* [AI] fix(diagnostics-otel): reconcile private providers with OTEL_SDK_DISABLED

Rebase onto main after #119961 (honor OTEL_SDK_DISABLED) changed the
disabled admission path to return before SDK construction. Restore the
removed getBooleanFromEnv import, drop the stale ownedNodeSdkDisabled
guard, and update disabled-mode tests to the new semantics (all routes
off, disabled runtime registered) plus the private-provider signal
path for the integration suite.

Related to #119997

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(diagnostics-otel): isolate restartable provider generations

* test(diagnostics-otel): prove same-pid generation routing

* test(diagnostics-otel): use supported watcher reload mode

* test(diagnostics-otel): satisfy ownership proof gates

* test(diagnostics-otel): use managed proof cleanup

* test(diagnostics-otel): verify injected trace ancestry

---------

Co-authored-by: glm-5.2 <noreply@anthropic.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-08-07 22:24:18 +08:00
Sally O'Malley 4cbbfc2159 fix(systemd): apply dotenv changes on gateway restart (#119441)
* fix(systemd): load state dotenv at gateway startup

Signed-off-by: sallyom <somalley@redhat.com>

* fix(systemd): refresh managed dotenv values on restart

Signed-off-by: sallyom <somalley@redhat.com>

* fix(gateway): clear removed managed dotenv values

Signed-off-by: sallyom <somalley@redhat.com>

* fix(dotenv): canonicalize managed override keys

Signed-off-by: sallyom <somalley@redhat.com>

* fix(secrets): preserve providerless env refs

Signed-off-by: sallyom <somalley@redhat.com>

---------

Signed-off-by: sallyom <somalley@redhat.com>
2026-08-07 10:04:04 -04:00
Peter Steinberger 01cc71060d test(tui): gate built CLI PTY cases (#120221) 2026-08-07 04:25:47 -07:00
Gio Della-Libera 60fc2fe64d feat(claws): adopt portable profiles and native bootstrap (#115237) 2026-08-07 04:04:51 -07:00
Peter Steinberger 8994c7799b fix(agents): subagent hard-deny list cannot be overridden by allow config (#120025)
* fix(agents): make subagent hard-deny list non-overridable and deny message tool

The always-deny list for subagent sessions (gateway, cron, message, sessions_send,
conversations_*) could be overridden by ordinary allow/alsoAllow config entries,
letting a configured subagent profile re-enable direct user delivery outside the
announce chain. The hard-deny layer now applies unconditionally; message joins the
list so resumed/visible subagent sessions cannot send directly either (hidden
launches already disabled it at spawn time).

* chore: re-fire CI

* chore: re-fire CI against fixed main baseline

* test(agents): workspace authority reflects non-overridable subagent deny list

The delegating-worker rejection case relied on alsoAllow bypassing the
subagent hard-deny list; with the bypass closed the policy owner blocks
sessions_spawn and the worker stays confined, so the guard has nothing to
reject.
2026-08-07 03:58:02 -07:00
Peter Steinberger e910324f10 fix(gateway): redact credentials from gateway URLs in status and logs diagnostics (#120024)
* fix(gateway): redact credentials from gateway URLs in status and logs diagnostics

Gateway URLs can carry basic-auth credentials or token query params. Status
output, status-all JSON, and logs-cli error diagnostics now project connection
details through a single diagnostics projection (projectGatewayConnectionDetailsForDiagnostics /
projectGatewayUrlForDiagnostics) so no diagnostic surface prints a raw URL;
the probe itself keeps using the unredacted URL.

* chore: re-fire CI

* fix(gateway): close remaining credential-leak paths in status diagnostics

ClawSweeper P1s: probe failure text (close reasons/transport errors) now
redacts URL-like credentials before status renderers print it; the status-all
remote-missing fallback line projects the environment gateway URL; gateway
transport-error JSON redacts the remote-controlled close reason and derived
message.
2026-08-07 03:57:08 -07:00
Peter Steinberger 44a5c40e11 fix(cron): on-exit watcher retries transient failures instead of silently dropping the watch (#120023)
* fix(cron): retry on-exit watcher spawn/wait failures with backoff

A transient supervisor failure while arming or waiting on an on-exit watch
previously dropped the watch with only a log line: the job would never fire
and nothing recorded why. Failures now persist lastError/consecutiveErrors on
job state via the gateway cron service and re-arm with bounded backoff
(1s/5s/30s/5m); cancel clears any pending retry timer.

* chore: re-fire CI

* fix(cron): guard watcher-state writes against replaced on-exit jobs

ClawSweeper P1: an old watcher's failure write could land on a job that was
edited or converted to a different schedule, pushing the replacement into
failure backoff or auto-disable. Watcher-state persistence now uses the same
identity precondition as persistCompletion (enabled, on-exit, updatedAtMs
match) and treats a mismatch as a no-op.
2026-08-07 03:56:16 -07:00
Peter Steinberger 4fb43b59e6 fix(slack): workspace-scoped thread cache and durable channel-id migration (#120022)
* fix(slack): scope thread-starter cache per workspace and persist channel-id migration durably

Thread-starter cache keys now always include accountId+teamId so multi-workspace
installs cannot cross-read cached thread starters. channel_id_changed migration
previews against the persisted config snapshot and only mutates the in-memory
monitor config after the durable write succeeds; new-channel ingress traffic
serializes behind the migration lane via new_channel_id.

* chore: re-fire CI

* chore: re-fire CI against fixed main baseline
2026-08-07 03:55:24 -07:00
Peter Steinberger 75a3cf298d feat(plugins): read the ai.openclaw Agent Plugins extension namespace (#120214) 2026-08-07 03:49:12 -07:00
Peter Steinberger f4387b7a5e feat(plugins): support the Agent Plugins bundle format (#120115)
* feat(plugins): support the Agent Plugins bundle format

* docs(plugins): document the Agent Plugins bundle format

* test(agents): preserve agent bundle runtime discovery

* fix(plugins): isolate Agent Plugins data-dir failures and align MCP support reporting

* docs(plugins): list Agent Plugins in the canonical plugin-format guides

* fix(plugins): gate Agent Plugins detection on schema, pure inspection, root-relative cwd

* fix(plugins): record Agent Plugins data-dir ownership explicitly

* docs(plugins): cover Agent Plugins in the CLI install detection guide

* fix(plugins): carry Agent Plugins data-dir and transport contracts through external MCP projections
2026-08-07 02:55:08 -07:00
Peter Steinberger 06d5e4457f fix(gateway): refresh session lists after external identity writes (#120203)
* fix(gateway): invalidate session lists on external mutations

* test(sessions): cover identity mutation fence
2026-08-07 02:45:14 -07:00
Peter Steinberger 2dd0e9b950 fix(gateway): prevent approval E2E startup timeout (#120195)
* test(gateway): isolate approval client startup

* test(gateway): share manual RPC startup scope
2026-08-07 02:01:53 -07:00
Vincent Koc 095227dd21 fix(diagnostics): honor OTEL_SDK_DISABLED (#119961)
* fix(diagnostics): honor OTEL_SDK_DISABLED

* fix(diagnostics): own OpenTelemetry lifecycle

* fix(diagnostics): keep SDK options private

* test(diagnostics): type async resource export

* fix(diagnostics): preserve OpenTelemetry env defaults

* fix(diagnostics): restore narrow OTEL disabled admission

* fix(diagnostics): surface disabled propagator warnings

* fix(diagnostics): preserve preloaded rejection guard

* fix(diagnostics): probe context manager ownership
2026-08-07 17:01:14 +08:00
Peter Steinberger 74500f334e fix(ai): truncated Anthropic streams error; proxies exempt from message_stop contract (#120030)
* fix(ai): enforce message_stop only for direct Anthropic models

The Anthropic SSE transport threw 'stream ended before message_stop' only when
a refusal buffer happened to be non-empty, so a truncated first-party stream
could pass silently while compatible proxy providers that legitimately omit
message_stop failed intermittently. The invariant now keys off the transport
contract owner: direct Anthropic models always require message_stop; proxy
providers are exempt.

* test(ai): cover proxy streams ending without message_stop

ClawSweeper P1: the proxy exemption had no focused test, so the lenient
branch could regress silently. A non-anthropic provider through a custom
endpoint now proves stopReason=stop with no error when the stream ends
without message_stop.
2026-08-07 01:49:46 -07:00
Peter Steinberger aa7cf44c75 fix(install): Windows installer no longer reports failed doctor migration as complete (#120033)
* fix(install): Windows installer surfaces doctor migration failures

Invoke-OpenClawCommand ignored the child exit code, so a failed
'openclaw doctor --non-interactive' still printed '[OK] Migration complete'.
The wrapper now throws on nonzero exit and Run-Doctor reports the failure
with the exact command to rerun instead of claiming success.

* chore: re-fire CI

* chore: re-fire CI against fixed main baseline
2026-08-07 01:19:59 -07:00
Vito Cappello 5621979a46 fix(models): preserve session selection across fallback turns (#119325)
* feat(models): add session-only model selection

* fix(models): use trailing session scope option

* test(models): satisfy session scope lint

* fix(models): reject duplicate model options

* fix(models): clarify default and session scope

* fix(models): require complete session option tokens

* fix(models): report configured default dispatch

* fix(models): keep directive handler within lint limit

* fix(models): parse model options in either order

* fix(models): apply session scope to aliases

* fix(models): align alias scope with reply routing

* fix(discord): surface model selection scope in picker

* fix(models): preserve mixed-text model selection

* fix(models): centralize command selection ownership

* fix(models): align session scope lifecycle

* fix(models): preserve command and auth ownership

* fixup! fix(models): preserve command and auth ownership

* fix(auth): preserve scoped CLI provider discovery

* test(models): align result and cron fixtures

* test(models): nest result timing metadata

* fix(discord): narrow silent dispatch results

* fix(transcript): preserve admitted turn identity

* fix(context-engine): fence the admitted transcript turn

* fix(context-engine): stabilize plugin compatibility contract

* chore(plugin-sdk): refresh context engine API baseline

* chore(plugin-sdk): use Linux context engine API baseline

* fix(context-engine): align fallback ownership

* fix(fallback): scope auth skip cache by profile

* fix(context-engine): settle only accepted fallback turns

* refactor(sessions): issue canonical turn admissions

* refactor(context-engine): own logical turn advancement

* fix(context-engine): settle cron fallback winners

* fix(models): align picker and fallback transactions

* fix(delivery): notify block admission after queueing

* fix(sessions): preserve canonical admission receipts

* chore(plugin-sdk): refresh API baseline hash

* fix(context-engine): commit accepted turns durably

* fix(context-engine): validate durable host transitions

* fix(context-engine): preserve fallback turn ownership

* fix(context-engine): preserve queued turn order

* fix(models): preserve fallback retry ownership

* fix(context-engine): enforce durable transcript anchors

* fix(runtime): close fallback persistence gaps

* fix(context-engine): preflight fallback harnesses

* chore(plugin-sdk): use Linux API baseline

* fix(context-engine): drain durable commits before reads

* fix(models): scope harness auth failures by profile

* fix(codex): fence legacy transcript history

* fix(commands): honor suppressed directive interpretation

* chore(runtime): remove unused branch exports

* test(context-engine): derive private outbox payload type

* fix(context-engine): apply durable drain degradation

* fix(context-engine): recover durable turn intents

* fix(context-engine): settle durable turn intents

* refactor(context-engine): satisfy branch quality gates

* fix(context-engine): close durable recovery gaps

* fix(discord): preserve dropped model command outcome

* test(copilot): keep journal fixture types local

* fix(auto-reply): preserve model alias provenance

* fix: close model scope review gaps

* fix(models): close review-found scope leaks

* fix(review): satisfy branch line budgets

* fix(agents): preserve context engine turn facts

* fix(agents): finalize silent context turns

* fix(context-engine): preserve compatibility window

* test(agents): cover both harness preparations

* fix(context-engine): retain blocked turn advancements

* fix(models): parse compact runtime options

* fix(telegram): report runtime resets accurately

* fix(models): isolate automatic auth failure skips

* fix(context-engine): project commit turn host params

---------

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-08-07 16:19:12 +08:00