Galin Iliev
7f74f1e45d
fix(memory): validate broker IPC boundaries
2026-08-19 11:20:29 -07:00
Galin Iliev
c40c08e071
fix(memory): fence brokered runtime during gateway updates
2026-08-19 11:04:47 -07:00
Galin Iliev
e5fdf6dd2d
fix(memory): package broker child entry
2026-08-19 07:40:03 -07:00
Galin Iliev
32ec272e75
feat(memory): isolate selected runtime behind broker
2026-08-19 07:01:45 -07:00
Galin Iliev
04ac2f5365
fix(memory): reject unenclosed worker turns
2026-08-18 21:59:55 -07:00
Galin Iliev
b0dc48da1f
test(memory): repair enforced invocation inventory
2026-08-18 21:30:53 -07:00
Galin Iliev
e2a3c688db
feat(memory): isolate scoped runtime in broker
2026-08-18 18:09:00 -07:00
Galin Iliev
c872b1b6ef
feat(memory): add enterprise identity operations
2026-08-18 18:04:57 -07:00
Galin Iliev
7879db09fd
feat(memory): complete explicit sharing and postbox
2026-08-18 18:02:05 -07:00
Galin Iliev
ba98eaf3e8
feat(memory): resolve gateway profile principals
2026-08-18 17:59:12 -07:00
Galin Iliev
73fd65c2df
feat(memory): bind postbox deposits to verified turns
2026-08-18 17:59:12 -07:00
Galin Iliev
418403280b
feat(memory): persist projection expiry and refresh
2026-08-18 17:58:47 -07:00
Galin Iliev
0c2d7b1d3f
feat(memory): add sharing and postbox foundation
2026-08-18 17:58:47 -07:00
Galin Iliev
93d50ddee8
feat(memory): seal derived artifact lineage
2026-08-18 17:58:47 -07:00
Galin Iliev
0d20184587
feat(memory): retain transcript policy lineage
2026-08-18 17:53:21 -07:00
Galin Iliev
a352d639f7
feat(memory): add authorized write lifecycle
2026-08-18 13:02:38 -07:00
Galin Iliev
0320a4fb02
feat(memory): confine filesystem and egress
2026-08-18 13:02:02 -07:00
Galin Iliev
16fa3eb4c7
fix(memory): keep cutover reads brokered
2026-08-18 12:53:01 -07:00
Galin Iliev
4449aee2d2
fix(memory): complete Phase 1C read isolation
2026-08-18 12:52:46 -07:00
Galin Iliev
ecbe94b81f
wip(memory): checkpoint Phase 1C read isolation rebase
2026-08-18 12:52:23 -07:00
Galin Iliev
85657038e2
wip(memory): checkpoint Phase 1C read isolation
2026-08-18 12:51:10 -07:00
Galin Iliev
02a08c73f6
fix(memory): keep migration host APIs private
2026-08-18 12:48:35 -07:00
Galin Iliev
95ef18ce8c
feat(memory): add scoped store and policy foundation
2026-08-18 12:48:34 -07:00
Galin Iliev
1042984b7d
feat(memory): bind verified DM identities to session subjects
2026-08-18 12:48:15 -07:00
Galin Iliev
a1f295feb3
test(memory): split authorization inventory helper
2026-08-18 12:47:09 -07:00
Galin Iliev
3c3aa24957
test(memory): keep inventory helper types internal
2026-08-18 12:47:09 -07:00
Galin Iliev
5b7ecccfae
test(memory): inventory Control UI migration routes
2026-08-18 12:47:09 -07:00
Galin Iliev
a960a193d4
test(memory): keep Phase 0 inventory test-only
2026-08-18 12:47:08 -07:00
Galin Iliev
35d22eb476
test(memory): inventory manager sync repro acquisition
2026-08-18 12:47:08 -07:00
Galin Iliev
330b63212e
test(memory): inventory session memory hook capture
2026-08-18 12:47:08 -07:00
Galin Iliev
c584f15af3
test(memory): simplify migration inventory roots
2026-08-18 12:47:08 -07:00
Galin Iliev
4a311813e4
test(memory): guard remaining recall inventory paths
2026-08-18 12:47:08 -07:00
Galin Iliev
b61a43cf76
test(memory): inventory remaining Phase 0 ingress paths
2026-08-18 12:47:08 -07:00
Galin Iliev
deedd526bf
test(memory): inventory Doctor and promotion paths
2026-08-18 12:47:08 -07:00
Galin Iliev
0c30b883a5
test(memory): measure selected runtime shadow overhead
2026-08-18 12:47:08 -07:00
Galin Iliev
41d45cd677
fix(memory): cache selected runtime shadow inspection
2026-08-18 12:47:08 -07:00
Galin Iliev
283729f718
fix(memory): inspect selected capability in shadow mode
2026-08-18 12:47:08 -07:00
Galin Iliev
d65305026a
fix(memory): keep authorization inspection types internal
2026-08-18 12:47:08 -07:00
Galin Iliev
4b21da753e
feat(memory): wire authorization shadow interfaces
2026-08-18 12:47:08 -07:00
Galin Iliev
b98b67d6ec
fix(plugin-sdk): require serializable memory handles
2026-08-18 12:47:02 -07:00
Galin Iliev
d38119c9dd
fix(plugin-sdk): reject metadata-bearing handles
2026-08-18 12:47:02 -07:00
Galin Iliev
a6f72e3e0a
feat(plugin-sdk): add memory authorization contract
2026-08-18 12:46:51 -07:00
Peter Steinberger
a99253f73e
perf(test): reuse plugin load-context modules ( #125965 )
2026-08-18 12:26:24 -07:00
Peter Steinberger
bb92dc61c8
fix: stop --tag main from failing during npm pack ( #125949 )
...
* fix: refuse unsupported OpenClaw source package updates
* refactor: narrow main update refusal
2026-08-18 12:22:45 -07:00
Peter Steinberger
110be8ccb6
fix: resume turns settled during gateway restart drain ( #125955 )
...
Keep drain-owned recovery state authoritative when the pre-restart run reaches a normal terminal event, so startup continues the original request without requiring a manual retry.\n\nRelated: #57425
2026-08-18 12:14:16 -07:00
Peter Steinberger
7ae9cbf3bc
fix(cli): stop claiming a write when approvals mutations are no-ops ( #125960 )
...
`openclaw approvals allowlist add|remove` printed "Writing local approvals."
from the shared target-resolution helper, before the mutation decision was
made. Both idempotent paths ("Already allowlisted.", "Pattern not found.")
returned without saving, so the CLI announced a write that never happened.
`approvals set` had the same problem: it announced the write and then rejected
unparseable input.
Move the announcement from `loadWritableSnapshotTarget` into the local branch
of `saveSnapshotTargeted`, the function that owns the write. Every caller of
the shared seam is fixed at once and exit codes are unchanged: idempotent add
and remove still leave the requested end state satisfied and exit 0.
2026-08-18 12:12:37 -07:00
Peter Steinberger
153ad5ec27
fix(cli): preserve migration agent ownership ( #125948 )
2026-08-18 12:10:09 -07:00
Peter Steinberger
82d48e0c03
fix(gateway): clean sessionless agent media ( #125938 )
2026-08-18 12:00:16 -07:00
Peter Steinberger
5301fb5e7f
fix(codex): preserve harness trajectories ( #125941 )
2026-08-18 11:47:09 -07:00
Peter Steinberger
97a4d324f5
fix(gateway): allow non-admin cloud sessions ( #125787 )
...
* fix(gateway): allow non-admin cloud sessions
Admin-provisioned shared runners are now usable by operator.write while raw environment, config, and pairing controls remain admin-only.
Closes #125602
* chore(test): prune assertion safety baseline
* refactor(gateway): isolate cloud reclaim lifecycle
* test(gateway): declare Codex dispatch ownership
* test(ui): cover session-scoped cloud cleanup
* perf(ui): trim tooltip startup path
* fix(gateway): fence cloud placement activation
* test(gateway): update move recovery dispatch contract
* fix(gateway): fail closed on placement recovery
* docs(gateway): explain fail-closed move recovery
* refactor(gateway): consolidate session mutation target keys
2026-08-18 11:33:54 -07:00