Peter Steinberger
f92e9367e8
fix(build): rebuild incomplete managed-update cache hits ( #125954 )
...
* fix(build): invalidate incomplete cache hits
* test(qa): align empty completion lifecycle
2026-08-18 23:25:04 -07:00
Peter Steinberger
e38a06439e
refactor: trim locale and QA fixture debt ( #126139 )
...
* refactor: trim locale and QA fixture debt
* fix(qa): preserve shared flow portability
* chore(qa): document shared flow branch
* fix(docs): align plugin SDK subpath catalog
* fix(ci): align shared docs and flow contracts
2026-08-18 22:17:19 -07:00
Peter Steinberger
dc37ed8f63
fix(agents): record empty subagent completion delivery ( #126179 )
...
* fix(agents): preserve delivery after incomplete completion
* test(qa): distinguish failed delivered completions
2026-08-18 21:46:38 -07:00
Peter Steinberger
fe816d69ef
fix(gateway): route detached announce by instance ( #125946 )
...
* test(qa): cover worker generation reload
* test(qa): anchor worker generation fixture
* test(qa): strengthen worker generation proof
* test(qa): stabilize terminal reply smoke waits
* test(qa): widen terminal reply CI budget
* test(qa): drop superseded timeout workaround
* fix(gateway): route detached announce by instance
2026-08-18 17:14:43 -07:00
Dallin Romney
f263e75260
test(matrix): expose raw command mention safety ( #125685 )
...
* test(matrix): expose raw command mention safety
* refactor(qa): consolidate Matrix preview snapshot
* fix(matrix): project command text through progress
* refactor(matrix): keep QA projection within lint boundary
* style(matrix): apply canonical transport formatting
2026-08-18 08:51:50 -07:00
Josh Avant
916aca13f3
feat: record subagent execution lineage ( #122015 )
...
* feat(audit): record subagent execution lineage
* fix(audit): type-check spawn lineage validation
* docs: preserve spawned-run lineage invariants
* fix(audit): preserve lineage for worker spawns
* fix(audit): bind worker lineage to live authority
* fix(audit): keep lineage carrier private
* fix(sessions): preserve ACP participant recording
* fix(audit): keep lineage out of runtime bearer
* fix(audit): keep lineage type private
* test(audit): match current worker claim shape
* test(audit): preserve readonly lineage result
* fix(audit): redeem spawn lineage privately
* fix(audit): preserve lineage redemption on copy
* test(audit): prove nested worker spawn lineage
* fix(audit): restore execution identity CI gates
2026-08-17 21:41:30 -07:00
Peter Steinberger
7170a6231a
feat(agents): unify agent status into a durable progress_card ( #125125 )
...
* feat(agents): unify agent status into a durable progress_card
Replace the write-only update_plan to-do tool and the fragmented plan
rendering with one durable status artifact per session: progress_card
({plan?, markdown?}, replace-on-write, 8 KiB markdown / 50-step caps).
Cards persist in a lazy-additive session_progress_cards table in the
per-agent DB (no schema-version bump), broadcast progressCard.changed,
and render from the store with exactly one live placement per view
(session rail when visible, else the composer-adjacent bar); transcripts
collapse to one-line receipts, and the sidebar hovercard shows other
sessions' cards inline (markdown + <progress>, DOMPurify allowlist, no
iframes). The three stream-derived plan renderers and their dedup
heuristics are deleted.
Codex runs disable the native plan tool per thread
(tools.update_plan.enabled=false) and receive progress_card via the
dynamic-tool bridge; compaction restore now reinjects the card (steps +
bounded markdown). Card writes still emit the legacy plan stream event so
native apps and channels keep working until their per-platform
migrations. Policy names map update_plan -> progress_card; the shipped
tools.updatePlan=false kill switch is honored.
Net -277 production LOC; -480 test LOC.
* test(agents): regenerate Codex prompt snapshots for update_plan thread-config disable
* chore(protocol): allowlist progressCard.changed for native apps pending card migration
* fix(ci): repair progress card integration checks
* fix(codex): canonicalize native progress cards
* test(gateway): reconcile progress card method order
* test(codex): stabilize native approval fixture
2026-08-17 09:44:04 -07:00
Peter Steinberger
185b1ab726
fix(discord): retain progress drafts after error finals ( #125140 )
...
* fix(discord): retain error progress drafts
* test(discord): parse REST probe request URLs
* test(qa): force Discord error-final path
* test(qa): match Discord overload final
2026-08-17 02:22:02 -07:00
Peter Steinberger
1027837d96
fix(msteams): avoid ambiguous delivery replay ( #125127 )
2026-08-17 00:13:59 -07:00
Peter Steinberger
a3578c7790
test(qa): cover Discord progress draft lifecycle ( #125089 )
...
* test(qa): cover Discord progress draft lifecycle
* test(qa): allow live Discord draft proof
* ci(qa): select Discord provider mode
2026-08-16 23:17:53 -07:00
Peter Steinberger
2af054fb9a
fix(qa): prove repeated gateway restart recovery ( #125052 )
2026-08-16 22:34:55 -07:00
Josh Avant
f7a8638282
feat(audit): explain outbound message delivery ( #123709 )
...
* feat(audit): explain outbound message delivery
* fix(audit): record early message policy denials
* refactor(audit): split message delivery readers
* test(outbound): cover delivery audit lifecycle
* fix(audit): preserve message progress across downgrade
* fix(audit): keep progress out of activity protocol
* docs(audit): keep activity outcomes terminal-only
* fix(audit): bound merged delivery paging
* fix(audit): trust decision channel references
* fix(audit): keep retention constant private
* fix(audit): record broadcast target denials
* fix(audit): distinguish broadcast denial receipts
* test(qa): enforce message delivery receipt proof
* fix(audit): integrate C04 with schema v9 owners
* chore(audit): satisfy assertion safety gate
* refactor(agents): split explicit message target guard
* test(audit): materialize pinned reader in shallow CI
* test(qa): poll terminal audit persistence
* fix(delivery): defer audit terminal to recovery
* test(qa): isolate message delivery restart proof
* test(qa): keep gateway restart config canonical
* test(qa): exclude unrelated restart plugins
* test(qa): remove unused restart plugins
* test(qa): disable automatic memory plugin
* test(qa): converge replacement gateway startup
* fix(plugins): stabilize registry fingerprints
* fix(plugins): use public normalization export
* test(plugins): keep fingerprint fixture immutable
* fix(audit): bind delivery receipts to exact executions
* chore(audit): keep terminal binding helper private
* test(reply): cover unbound admission callbacks
* docs(agents): preserve durable delivery ownership
2026-08-16 21:26:27 -07:00
Peter Steinberger
7349177ce3
feat: main-session agent-wide visibility + session.groupScope routing ( #124965 )
...
* feat: add main session group routing
* docs: explain main session routing scopes
* fix: align memory session visibility
* test(qa): cover main-scoped group bindings
* fix(sessions): preserve binding-scoped outbound routes
* fix(routing): preserve explicit outbound owners
* fix(sessions): recognize global main visibility
* chore(ci): prune assertion safety baseline
2026-08-16 19:57:18 -07:00
Peter Steinberger
72ddf22b93
fix(qa): recover repeated gateway restarts through channel ingress ( #124746 )
...
* fix(qa): repair repeated gateway restart recovery
* test(qa): satisfy restart recovery checks
* fix(audit): rekey repeated recovery identity
* fix(plugin-sdk): expose authored context cap
* test(android): synchronize process tree readiness
2026-08-16 15:47:31 -07:00
Peter Steinberger
91e537da15
fix(runners): preserve device sessions through lifecycle faults ( #124744 )
...
* test(runners): cover paired-node lifecycle wire
* fix(runners): preserve retryable device lifecycle
* test(runners): keep wire fixture internals local
* fix(runners): stop fallback on device capacity
2026-08-16 12:29:07 -07:00
Peter Steinberger
6aa27d6ecd
refactor: retire August compat windows (embedding API, pi aliases, target parser, spawning hook, setup exports, WhatsApp inbound aliases) ( #124416 )
...
* refactor(plugin-sdk): retire embedded Pi aliases
* refactor(channels): retire explicit target compatibility
* refactor(plugins): retire subagent spawning hook
* refactor(plugin-sdk): retire shipped channel setup exports
* refactor(whatsapp): retire inbound callback aliases
Proof: focused build and WhatsApp E2E green; broad WhatsApp suite 188/189 files green. extensions/whatsapp/src/monitor-inbox.policy.test.ts flakes only in the parallel batch and passes isolated (10/10).
* refactor(plugin-sdk): retire memory embedding registrar
Migrate every bundled provider and manifest to registerEmbeddingProvider and contracts.embeddingProviders. Preserve memory-specific batching, local-service acquisition, index identity, and auto-selection through the canonical generic registry adapter, then remove the parallel registrar, registry, diagnostics, contracts, tests, and docs.
* chore(plugin-sdk): tighten retired surface budgets
Pin the post-retirement public SDK surface to 144 entrypoints, 4,312 exports, 2,564 callable exports, and 1,133 deprecated exports; agent-harness-runtime now permits exactly nine deprecated exports.
2026-08-15 22:43:47 -07:00
Eden
a61417fef4
fix(mentions): match decorated identity names ( #115278 )
...
Allow group members to type an agent name without optional emoji or symbol decoration while preserving literal separators and Unicode boundaries. Bound raw joiner matching and replay QA startup patches in order.
Co-authored-by: 許元豪 <146086744+edenfunf@users.noreply.github.com >
Co-authored-by: Eden <146086744+edenfunf@users.noreply.github.com >
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-16 11:09:03 +05:30
Vito Cappello
9474e55076
fix: consume prepared images once in CLI-backed turns ( #120721 )
...
* fix(agents): preserve images across CLI dispatch
* test(agents): format CLI dispatch coverage
* fix(reply): consume prepared images once
* test: cover CLI inbound image reply path
* fix(auto-reply): preserve prepared image state
* fix(auto-reply): preserve queued image fallback
* fix(agents): keep CLI image marker internal
* fix(agents): keep image admission marker private
* fix(agents): preserve internal image admission state
* fix(auto-reply): keep image admission marker internal
* test: keep image preparation marker internal
* fix(cli): preserve queued image metadata
* test(cli): cover filtered media image indexes
* test: restore media fixture cleanup
* test: align filtered media fixture with resolver mock
* style: format CLI image forwarding changes
* fix(auto-reply): preserve queued media slot type
* fix(auto-reply): avoid spread in media slot mapping
---------
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com >
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com >
2026-08-15 20:49:08 -07:00
Pavan Kumar Gondhi
8668aeb969
fix(discord): bind transcript capture to source account [AI] ( #118579 )
...
* fix(discord): bind transcript capture to source account
* style(agents): keep transcript tool wiring compact
* fix(transcripts): declare account binding channels
* fix(transcripts): report effective capture account
* fix(transcripts): enforce account lifecycle ownership
* fix(transcripts): preserve cross-surface control
* fix(copilot): preserve transcript channel context
* fix(transcripts): fail closed for legacy channel owners
* fix(transcripts): add trusted legacy recovery
* fix(transcripts): preserve auto-start cleanup ownership
* fix(transcripts): reject untrusted account starts
* fix(transcripts): keep persisted ownership authoritative
* fix(transcripts): harden legacy recovery
* fix(transcripts): preserve agent ownership boundary
* fix(transcripts): scope account binding to source channel
* fix(transcripts): preserve unattributed owner isolation
* fix(transcripts): own configured captures by account
* docs(plugins): clarify transcript auto-start ownership
* test(transcripts): cover account-less recovery
* docs(transcripts): scope legacy recovery by provider
* fix(discord): reuse eligible account ordering for transcripts
* test(discord): use neutral transcript account fixtures
* fix(transcripts): keep accountless recovery local
* fix(discord): resolve transcript accounts by voice capability
* fix(transcripts): bound account resolution failures
* fix(transcripts): bound account tool output
* fix(transcripts): honor unresolved provider accounts
* fix(transcripts): preserve binding when providers are missing
* fix(transcripts): fail closed on unknown binding provenance
* fix(transcripts): qualify account lifecycle capability
* fix(transcripts): normalize provable legacy owners
* fix(transcripts): bind scheduled capture to caller authority
* fix(transcripts): preserve scheduled caller identity tuple
* fix(transcripts): preserve channel-less scheduled authority
* fix(plugin-sdk): publish transcript provider types
* fix(transcripts): use exact lifecycle ownership tokens
* fix(transcripts): preserve local ownerless lifecycle access
* fix(transcripts): allow local configured capture control
* fix(transcripts): preserve scheduled caller channel
* fix(transcripts): retain named-agent legacy recovery
* fix(transcripts): deny unrelated remote channels
* fix(doctor): validate transcript owner inference
* fix(transcripts): restrict legacy remote recovery
* fix(ci): align transcript Doctor checks
* fix(transcripts): require Doctor-owned legacy metadata
* fix(transcripts): reject unowned remote capture starts
* fix(transcripts): reject unbound Discord lifecycle calls
* fix(transcripts): distinguish legacy owner rows
* test(discord): keep unavailable account fixture typed
* fix(transcripts): mark current imports for Doctor
* fix(transcripts): complete account ownership validation
* fix(discord): restore transcript package boundary
* fix(discord): preserve bundled transcript entry boundary
* docs(transcripts): clarify Discord auto-start account
* fix(transcripts): bind account-owned imports
* fix: preserve transcript and cron policy state
* fix(cron): preserve scheduled transcript authority
* fix(discord): keep legacy transcript rows local
* fix(transcripts): narrow account ownership boundary
* fix(transcripts): preserve trusted caller ownership
* fix(discord): enforce transcript source authorization
* fix(ci): bound Control UI gzip build variance
* test(qa): align transcript scenario contracts
* fix(agents): repair rebased caller context
* fix(discord): restore rebased account ownership
* test(discord): restore voice account fixtures
---------
Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com >
2026-08-15 12:10:43 -07:00
Josh Lehman
cd5076770e
fix(qa): restore Buzz canary selection ( #124200 )
...
* oc-2f4: fix Buzz QA scenario selection
* oc-2f4: align canary catalog contract
2026-08-15 09:27:39 -07:00
Ayaan Zaidi
a8a986af1d
fix(qa): preserve Telegram reply defaults in live canary ( #123662 )
...
Make Telegram live QA inherit the production reply default instead of forcing threaded replies. Keep the portable one-visible-reply canary invariant while removing Telegram-specific policy.
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-14 23:15:35 +05:30
Josh Avant
97a53a9b35
feat: audit admitted channel participant identity ( #122863 )
...
* feat: audit admitted channel participant identity
* fix: preserve Telegram identity through thread recovery
* fix: signal held gateway process groups
* fix: keep audit evidence passive in collect routing
* fix: validate copied channel participant evidence
* fix: bind channel participant evidence to host ingress
* fix: honor Telegram proof credential roles
* fix: restart held Telegram proof through gateway
* fix: repair channel identity CI regressions
* test(matrix): bind thread routing owner
* fix: preserve direct DM SDK compatibility
* fix: bind channel provenance at host runtime
* test(feishu): provide channel context builder
* fix: defer record-bound channel runtime resolution
* fix: keep channel admission evidence core-private
* fix(audit): bind channel admission to plugin lifecycle
* fix(audit): bind ingress provenance to final context
* refactor(audit): split admission scope keys
* test(queue): cover combined metadata carriers
* refactor(audit): keep lifecycle helpers private
* fix(queue): preserve combined turn authority
* test(channels): provide ingress context builders
* test(channels): align integrated CI fixtures
* test(clickclack): resolve model-loop ingress
* docs: preserve channel participant evidence invariant
2026-08-14 08:57:01 -05:00
Peter Steinberger
6ad5d1104c
test(agents): move recovery transcript proof to QA ( #123006 )
2026-08-12 22:04:15 -07:00
Patrick Erichsen
074d75d372
test(buzz): add opt-in thread QA coverage ( #116081 )
...
* test(buzz): add opt-in thread QA coverage
* fix(buzz): preserve QA conversation kind
---------
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
2026-08-13 12:54:36 +08:00
joshavant
4408ceb68e
fix(matrix): retain previews when replacement delivery fails
2026-08-12 20:32:32 -05:00
Vitor Cepeda Lopes
a9ee6618fe
fix(memory): recall prior conversation after session reset ( #122051 )
...
* fix(memory): recall archived session generations after reset
* test(memory): prove private recall across reset
* fix(memory): keep deleted transcripts outside reset recall
* fix(memory): reject deleted archives from reset recall
* fix(memory): isolate recall across sqlite resets
* test(memory): split reset recall coverage
* fix(memory): keep reset recall metadata private
* fix(memory): keep reset authority scoped
---------
Co-authored-by: TheAngryPit <16145902+TheAngryPit@users.noreply.github.com >
2026-08-12 12:38:13 -07:00
Josh Avant
1b36f42653
fix(audit): preserve numeric decision cursors ( #122619 )
2026-08-12 13:08:25 -05:00
Vincent Koc
6e880b5107
fix(qa): preserve model switch failure evidence ( #122710 )
2026-08-13 01:24:10 +08:00
Peter Steinberger
c23d66e3b5
refactor: consolidate coercion ownership ( #122692 )
...
* refactor: consolidate coercion ownership
* test: align shard check with weighted planning
* chore: refresh plugin SDK API baseline
2026-08-12 09:25:28 -07:00
Vincent Koc
7fa5442fc1
fix(qa): accept cumulative compaction counts ( #122680 )
2026-08-13 00:19:49 +08:00
Peter Steinberger
71e8cc033b
refactor(qa): remove gateway child test facade ( #122693 )
...
* refactor(qa): remove gateway child test facade
* test(qa): refresh scenario source references
* fix(qa): preserve packaged auth redaction boundary
2026-08-12 09:03:40 -07:00
Josh Avant
562391b9af
feat(audit): explain denied operator approvals ( #119815 )
...
* Audit: add durable decision receipts
* Audit: route generic decision facts through writer
* Audit: satisfy strict decision count typing
* Test: align decision writer type coverage
* Refactor: isolate decision receipt projection
* Fix: preserve ambiguous approval correlation
* Fix decision coverage across pages
* Fix approval coverage across corrupt pages
* Fix decision summaries across retention and paging
* Remove superseded decision fact count path
* Keep session-derived approval links conservative
* Test decision paging at owner boundary
* Audit: bind approval receipts to exact execution
* Test: keep decision receipt coverage focused
* docs(agents): preserve decision receipt ownership
* Docs: refresh Plugin SDK split baselines
* Docs: require opt-in for future decision facts
* Fix: bound decision receipt inspection
2026-08-12 05:23:29 -05:00
Vincent Koc
2c26f13606
fix(qa): accept staged compaction summaries ( #122528 )
2026-08-12 17:52:14 +08:00
Peter Steinberger
ae2158c0da
fix(cloud-workers): start source bundles with vendored packages ( #122400 )
...
* test(qa): prove cloud worker mid-turn loss
* fix(cloud-workers): prune vendored workspace dependencies
* test(qa): keep SSH fixture type private
2026-08-11 20:32:54 -07:00
Alix-007
d76f71cee7
fix(auto-reply): omit heartbeat inbound metadata ( #122075 )
...
* fix(auto-reply): omit heartbeat inbound metadata
Prevent synthetic heartbeat routes from appearing as user-role Conversation info while preserving delivery routing. Fixes #97067 . Reported by @xxtyyq.
* test(auto-reply): use complete heartbeat model state
* test(qa): prove heartbeat metadata boundary
* test(auto-reply): deduplicate heartbeat metadata coverage
Co-authored-by: Alix-007 <li.long15@xydigit.com >
Punchcard-Session: frost-cedar-harbor-2n
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-12 03:02:22 +08:00
Peter Steinberger
f1bb7cd919
test(sdk): consolidate packed consumer evidence ( #122001 )
...
* test(sdk): consolidate packed consumer evidence
* test(qa): refresh scenario owner references
* test(qa): narrow script execution assertion
2026-08-11 04:18:20 -07:00
Peter Steinberger
fa03d9b913
refactor: consolidate coercion helpers ( #121366 )
...
* refactor: consolidate coercion helpers
* fix: remove duplicate coercion imports
* fix: preserve serialized coercion guard
* chore: ratchet coercion helper carve-outs
* fix(test): keep gauntlet subprocess startup lean
* fix: preserve imported session timestamp semantics
* fix: preserve catalog timestamp string semantics
* chore: align plugin SDK surface ratchet
* fix: preserve trajectory and SDK string contracts
* fix(test): preserve QA record assertion semantics
* fix: complete standalone record guard rename
* refactor(cron): use canonical string coercion
* fix(acpx): preserve Pi timestamp parsing
* test(channels): adapt custody test harnesses
* test(telegram): classify media harness as test support
* test(acpx): split timestamp contract coverage
* test(channels): support generated custody contracts
* chore: ban the full coercion helper name set
Extends the declaration guard to all eleven consolidated helper names and
renames the cron schedule-identity readNumber wrapper to readScheduleInteger
so the banned generic name cannot regrow.
* fix(scripts): repair release-validation guard drift and lint cause
Restores the renamed isJsonRecord guard in assertTrustedWorkflowHarness after
main added isRecord call sites in parallel, and attaches the caught YAML error
as the thrown error cause (preserve-caught-error was red on main).
* fix: preserve Claude timestamp string semantics
* fix: preserve persisted timestamp string semantics
* fix: preserve date-first timestamp contracts
* fix(openai): harden delegation failure formatting
* chore: close coercion helper guard gaps
* test(openai): model non-error delegation rejection
* chore: refresh plugin SDK API contract
* fix(tasks): use canonical string field reader
* fix(ai): use canonical provider error field coercion
* fix(browser): migrate native bootstrap coercion
* docs(plugin-sdk): clarify text record export compatibility
* fix(gateway): normalize approval execution identity
* test(outbound): isolate message action poll harness
2026-08-11 00:02:18 -07:00
Peter Steinberger
1ced7441eb
refactor(agents): move announce, completion, recovery, and registry families into concept directories ( #121553 )
...
* refactor(agents): move announce family into subagents/announce/
* refactor(agents): move completion and main-session recovery families
* refactor(agents): move registry family into subagents/registry
* refactor(agents): update registry state type imports
* style(agents): format moved subagent imports
* test(agents): preserve isolated registry test routing
* fix(scripts): recognize relocated subagent announce seams
2026-08-10 16:06:39 -07:00
Ayaan Zaidi
4b0151682e
refactor(commitments): remove inferred follow-up subsystem
...
Remove hidden follow-up extraction, heartbeat delivery, CLI, docs, and supporting tests/tooling. Existing commitment records remain inert pending separately approved cleanup.
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-10 13:48:32 +05:30
Peter Steinberger
f6298bf84d
fix(workers): preserve disappeared-worker failures across restarts ( #121122 )
...
* fix(workers): persist placement terminal failures
* fix(workers): refresh placement protocol clients
* refactor(workers): isolate error formatting
* fix: integrate cloud terminal state with current main
* chore(plugin-sdk): refresh API baseline
* refactor(ui): inline one-use cloud terminal-reason banner helper
Keeps the Control UI startup JS bundle inside its 317 KiB gzip budget
(the helper + type-only import tipped it by 16 bytes).
* refactor(ui): trim terminal-reason lookup to type-erased optional access
Recovers the last gzip byte of the Control UI startup budget
(324609 B vs the 324608 B limit).
2026-08-10 00:36:52 -07:00
Dallin Romney
e422317cce
fix(qa): record blocked SSH evidence ( #121011 )
...
Extracted from #120588 at 2d0fdeb61fa06f9fa97b9626bb5a2f9016e45202.
2026-08-10 13:42:48 +08:00
Peter Steinberger
aba6f26be3
refactor: eliminate wrapper export shadowing hazards ( #121388 )
...
* refactor(queue): rename core resolveQueueSettings to resolveQueueSettingsCore
* refactor(channels): make configured binding registry canonical
* refactor(gateway): disambiguate node pending handlers
* refactor(acp): rename gateway session key resolver
* chore(scripts): burn resolved entries from collision baseline
2026-08-09 21:36:46 -07:00
Peter Steinberger
8430fc0e3b
refactor(agents): move spawn family into subagents/spawn ( #121350 )
...
* refactor(agents): move spawn family into subagents/spawn
* refactor(agents): keep spawn imports within lint budget
2026-08-09 19:51:29 -07:00
Peter Steinberger
b05a308351
refactor(agents): consolidate prompt and stream attempt steps ( #121305 )
...
* refactor(agents): consolidate prompt-phase attempt steps
* refactor(agents): move stream transport into settlement module
* refactor(agents): remove absorbed stream transport step
* test(agents): preserve merged prompt mock exports
2026-08-09 18:25:43 -07:00
Vincent Koc
2e4683ba7f
fix(qa): finish aggregate suites without shared cache races ( #120816 )
...
* fix(qa): bound parallel aggregate script runs
Punchcard-Session: amber-workshop-workshop-36
Co-authored-by: Dallin Romney <6581799+RomneyDa@users.noreply.github.com >
* test(tui): wait for adopted session frame
Punchcard-Session: amber-workshop-workshop-36
---------
Co-authored-by: Dallin Romney <6581799+RomneyDa@users.noreply.github.com >
2026-08-10 03:32:04 +08:00
Peter Steinberger
c70aee247e
refactor(scripts): migrate JavaScript tools to TypeScript ( #121005 )
...
* refactor(scripts): migrate JavaScript tools to TypeScript
* fix(ci): keep changed-scope preflight zero-install
* fix(ci): preserve zero-install script owners
* fix(ci): complete script migration follow-through
* fix(release): keep stable closeout zero-install
* fix(scripts): preserve standalone execution boundaries
* fix(scripts): repair standalone loader boundaries
* fix(scripts): normalize gateway observation ids
* fix(scripts): keep Docker packager standalone
* test(scripts): preserve rebase cleanup helpers
* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00
Vincent Koc
c8a99f7aab
test(gateway): cover rolling node compatibility ( #119991 )
...
Punchcard-Session: calm-lantern-timber-wa
2026-08-09 18:45:08 +08:00
Peter Steinberger
0df1a89e3a
fix(telegram): preserve visible draft recovery ( #120626 )
...
* fix(telegram): preserve visible draft recovery
* fix(telegram): await visible draft send
* test(telegram): use const in draft recovery test
* test(telegram): add live partial failure proof
* test(telegram): register live recovery coverage
* ci(qa): support mock Telegram proof scenarios
* test(telegram): isolate live recovery fallback
* test(telegram): assert live recovery behavior
* fix(agents): join partial reply delivery
* test(telegram): keep settlement proof at core boundary
2026-08-09 02:54:38 -07:00
Peter Steinberger
73bdb4b924
feat(agents): record run-end worktree cleanup outcome; prove Workboard dirty retention ( #120434 )
...
* feat(agents): record run-end worktree cleanup outcome
Persist removed, retained, and failed run-end cleanup outcomes on managed worktree records. Operators and QA can inspect the durable fact through worktrees.list and openclaw worktrees list --json.
Release note: Managed worktree run-end cleanup now records why a checkout was removed or retained in worktree list JSON.
* test(qa): prove dirty worktree retention outcome
* chore(protocol): regenerate swift gateway models
* fix(agents): harden worktree cleanup recovery
Register run_end_cleanup_json as a lazy compatible column so same-version v6 index repair and read-only doctor migration can recover databases created before the column existed.
Type removal contention at the registry boundary; unexpected claim failures now best-effort record a bounded failed outcome and rethrow the original error.
* fix(ci): clear repo-wide lint debt blocking merge gates
The red-main landing rule requires this PR to repair repository-wide merge-gate debt instead of bypassing it. Apply the current lint contracts mechanically and split turn-transition coverage into a concept-named sibling with per-file-safe test state.
Exact line delta: +676/-574 (net +102) across 44 test/support files.
* fix(ci): preserve cached health refresh proof
Require the public refresh call to exist before accepting that sensitive fields were omitted, so the boundary proof cannot pass on a missing call.
* fix(ci): correct test typing left by the lint sweep
Literal-widened totalTokensVersion fixtures, a WebSocket RawData overload
mismatch, and the protocol schema document cast broke check-test-types
after the repo-wide lint repair. Aligns the fixtures with SessionEntry,
narrows Buffer handling per RawData, and keeps the JSON-shaped undefined
omission under structuredClone.
* test(agents): reuse upstream resource-loader test support
The session-loop split and #120463 's helper extraction landed the same
createResourceLoader/createCompactionHandlers twice; the rebase kept both,
orphaning main's agent-session-loop-resource-loader.test-support.ts and
failing the dead-code gate. Import the upstream helpers and delete the
duplicates.
* fix(agents): reject finalized rows at the worktree removal claim
Address the accepted ClawSweeper late-claim finding by rereading and rejecting missing or finalized worktree rows inside the synchronous removal-claim transaction.
Preserve the authoritative cleanup invariant: finalized contenders record nothing, while retained-busy is written only while the row remains live.
* refactor(agents): reuse registry update for busy outcomes
Keep the live-row conditional write in the canonical registry update path so the finalized-claim repair stays below the registry max-lines ratchet without weakening the authoritative-outcome invariant.
* test(agents): drop session test duplicates after rebase
Keep current main as the canonical owner of next-turn lifecycle coverage and correctness test support after replaying the older lint-debt split.
* fix(agents): guard post-abort cleanup outcomes against finalization
After abortWorktreeRemoval releases a stale remover's claim, its retained or
failed write raced a finalizing remover and could overwrite the authoritative
removed-lossless fact. Route every retained/failed write through the live-row
condition; only the finalizing remover's own removed-lossless write stays
unconditional.
* fix(agents): persist the removal outcome atomically with finalization
A delayed removed-lossless write after remove() finalized could race a
restore plus newer cleanup and overwrite the newer operator-visible fact.
The run-end outcome now rides remove()'s finalization update; every other
cleanup write stays live-row conditional, so no post-finalize write path
remains.
* test(qa): restore strict cached-health contract assertions
The lint sweep's Boolean() coercions let truthy non-booleans satisfy the
wire-typed cached-meta contract. Assert the literal boolean for unknown-typed
fields and use nullish-coalesced strict equivalents for boolean chains.
* fix(agents): clear the stale cleanup outcome when restoring a worktree
A restored checkout begins a new lifecycle; leaving the removed-lossless
fact on the live row showed operators a stale result until the next
cleanup. Restore clears the recorded outcome and the regression asserts
the cleared state before the next cleanup records fresh truth.
* fix(agents): scope stale cleanup outcomes to their observed lifecycle
A stale remover's retained/failed write raced a concurrent remove-plus-
restore: the revived row is live again, so the live-row condition alone
could stamp a prior-lifecycle outcome. Condition those writes on the
activity stamp the remover observed; restore bumps lastActiveAt, making
any prior-lifecycle write a no-op.
* fix(agents): advance the restore activity stamp within one millisecond
Stale cleanup writes fence on the activity stamp they observed; a restore
completing in the same millisecond could revive the row with an identical
stamp and let the fence match. Restore now always advances past the
stored value, and the ABA regression pins the clock to prove the
same-millisecond case.
2026-08-08 20:32:11 -07:00
Vincent Koc
e14b36cdbf
fix(qa): update Control UI scenario code references ( #120801 )
2026-08-09 09:42:38 +08:00