* improve(ui): make Control UI feel native on mobile
* fix(ui): keep coarse-pointer input floor text-scale aware
* fix(ui): let self-sized controls opt out of the touch input floor
* fix(ui): fold per-control coarse-pointer font floors into the shared touch floor
* feat(gateway): projects.list groups known checkouts by repo identity
Implements docs/plan/runners.md milestone 4 derived projects read model.
* feat(ui): regroup the Where picker by gateway, devices, and cloud
* feat(ui): placement chip shows where a session runs with reclaim
Implements docs/plan/runners.md milestone 4 placement display and reclaim.
* test(ui): advertise terminal and browser panels in the mock harness
The mocked Control UI never advertised browser.request or terminal.open and
left terminalEnabled false, so the chat header's panel toggles were invisible
in the harness and could not be visually verified.
* fix(ui): give the chat pane header the only panel toggle row
The session workspace rail header rendered Terminal, Browser, Ask OpenClaw and
Changes alongside its own dock/refresh/collapse controls. Terminal and Changes
already lived in the chat pane header, so both rendered twice at once, while
Browser was reachable only from inside a files rail and Ask OpenClaw sat in a
per-session rail despite being a global surface that already owns a sidebar
entry (settings route 'custodian').
The rail header now owns workspace-file actions only. Browser moves up to the
pane header beside Terminal and into the narrow-header overflow menu; the
duplicated Terminal and Changes buttons and the Ask OpenClaw toggle are gone.
Production LOC: +21 -84.
* test(ui): stop the vite stub from shadowing the mock bootstrap config
ui/vite.config.ts registers a placeholder /control-ui-config.json middleware
and config-file plugins load before inline ones, so the mock gateway plugin's
bootstrap body never reached the app and every scenario bootstrap field was
silently dropped. Marking the mock plugin 'pre' lets it answer first.
* refactor(gateway): extract source-agnostic desktop relay core
Split the cloud-worker desktop observer into a reusable core under
src/gateway/desktop/ so upcoming desktop sources (gateway host, nodes)
plug into one relay pipeline:
- attachment.ts: RfbAttachment union (unix socket | loopback TCP)
- session-registry.ts: generic observer lifecycle (8-observer cap,
controller eviction, 60s linger, owner-epoch fencing) with typed
stale-owner/stopped errors
- observe-bridge.ts: single-use observe tokens + WS relay, path moves
to /desktop/observe (clients consume wsPath verbatim)
- rfb-view-only-filter.ts: pure move
desktop-tunnel.ts keeps only worker SSH acquisition and app launch,
plugged into the shared registry; external API unchanged. Behavior
is identical; worker desktop tests pass unmodified apart from import
and path renames. Drops the never-used now() option.
* fix(gateway): fence only superseded desktop sessions
The desktop core extraction replaced the owner fence's "stop strictly
older owners" check with an unconditional session stop. A launcher that
claims an owner epoch first, then reaches its async fencing pass after a
same-epoch observe has already created the session, tore that session
down and failed the observer with "stopped before connecting".
Restore the original invariant in the registry that owns it:
stopSuperseded() retires an entry only when its epoch is strictly lower
than the claimant's, so peers sharing a generation keep the session.
The regression test drives launch-then-observe at one epoch and fails on
the pre-fix code inside fenceReplacedOwners.
* refactor(gateway): drop unused WorkerDesktopTunnels type export
Use successful per-attachment staging results in unsupported-document guidance so sandboxed agents receive only workspace-readable paths. Failed or partial staging keeps the existing fallback.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* feat(webui): auto-request notification permission on first chat send
The Control UI now asks for notification permission automatically on the first chat message you send (once per browser/origin; web push in browsers, native prompt in the macOS app; denied permission is never re-asked automatically — Settings -> Notifications stays the manual path).
* fix(webui): preserve notification prompt gesture boundary
Restrict the one-shot notification prompt to direct non-command composer sends, invoke browser permission synchronously, and keep Settings documented as the management and recovery path.
* fix(webui): exclude deferred notification sends
Require an actively dispatching browser input event before consuming the notification one-shot, so retained catalog handoffs and other deferred sends cannot suppress the first real composer prompt.
* refactor(agents): delete dead model-selection surface, consolidate compaction target assembly
Removes production surface with zero live callers: buildConfiguredAllowlistKeys
(orphaned since fallback allowlist filtering was split out), the
retryTransientProviderRuntimeMiss resolveModelAsync option (its gateway startup
prewarming caller was replaced by prepared runtime snapshots), the ignored
useAsyncModelResolution plumbing (kept only as a deprecated no-op field on the
plugin-SDK-shipped prepareSimpleCompletionModelForAgent), and dead facade
re-exports (inferUniqueProviderFromCatalog, ThinkLevel, ModelRefStatus).
Consolidates resolveEmbeddedCompactionTarget's five hand-built result sites into
one assembleTarget helper owning the auth-profile-drop-on-provider-change rule;
resolution precedence is unchanged and now pinned by new table-driven cases
(unique-provider inference, ambiguous literal, profile-suffix preservation).
Net -93 production LOC, -106 test LOC.
* chore(sdk): regenerate plugin SDK API baseline after facade export removals
* feat(gateway): add /startupz startup probe with auth-gated version detail
Startup/traffic-admission probe that excludes downstream channel health:
200 started once startup work completes and the gateway is not draining,
503 starting/draining otherwise. Version and uptime are only included for
local-direct or authenticated callers, reusing the /readyz detail gate.
* fix(deploy): use /startupz for traffic admission in bundled templates
fly.toml gains its missing HTTP check; render.yaml stops using pure
liveness as admission; k8s pins an immutable image tag, seeds config
only when missing, and adds a startupProbe; stale Fly healthcheck-port
doc corrected (healthcheck follows the active gateway lock port since
bc4221a07e).
* docs(k8s): make persistent-file config ownership explicit with reseed path
Canonical beta branch head exact-SHA provenance; unique merged-PR attribution for GitHub web-flow signed transport; extract duplicated gate into one trusted helper.
Remove Discord's duplicate whole-turn session serialization so corrections reach shared reply admission and steer the active run. Preserve shared steer, followup, collect, and interrupt behavior.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(agents): use unique isolated completion ids
Prevent same-millisecond CLI completions from sharing run authority by minting a UUID-backed wrapper identity.
* test(agents): type isolated completion release barrier
Let eligible embedded host runs inspect root-approved unsupported documents after final sandbox, filesystem, provider, owner, and tool-policy gates. Generic ACP, sandboxed, URL-only, and restricted-tool paths retain the plain marker.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(agents): scope quota failures to auth profiles
* test: repair provider suspension CI coverage
* test: keep suspension reset fixture internal
* fix(agents): spend cooldown probe only on transient candidates
Consume the one-run cooldown probe only when the candidate’s own unavailable reason is transient, so a billing-disabled pin cannot block a recoverable backup.\n\nFinding from the ClawSweeper review on openclaw/openclaw#121278.
* refactor(sessions): deprecate QuotaSuspension.laneId instead of removing
The shipped plugin-SDK surface deprecation policy requires keeping the inert field until the next surface window.
* fix(agents): extend transient probe policy to plugin-harness auth path
* fix(agents): keep provider overload from cooling auth profiles
* fix(agents): exhaust rotation candidates without cooldown records
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* test(agents): align auth rotation mocks with current main
* docs: regenerate plugin SDK API baseline
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
* style(agents): format session-suspension test after rename resolution
---------
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* docs(plan): rewrite runners plan as revision 2 — everything is a node
Operator-decided direction change: paired nodes host full agent sessions
through the worker admission path; openclaw worker becomes a node-supervised
child; SSH is deleted as the device transport in favor of an outbound-only
two-connection shape (node control channel + direct-dial worker connection).
Folds in verified code reads (admission/tunnel/sync/node-channel/scopes), an
industry survey, an Amp CLI teardown, and a fresh adversarial review; scopes
milestone 6 honestly (transport/sync net-new, admission/placement reused) and
bounds v1 trust to admin-paired shared infrastructure.
* docs(plan): record revision-2 PR number in milestone table
`attachGatewayWsConnectionHandler` took both a `resolvedAuth` snapshot and an
optional `getResolvedAuth`, and used the snapshot for nothing except defaulting
the getter. Every production caller already passed the getter, so the snapshot
was a second signal for a fact that rotates on config reload — the exact shape
that goes stale as sibling paths evolve.
Collapse it to one required getter and drop the argument from
`server-ws-runtime.ts` and `server-startup-finish.ts`. That also puts
`server-startup-finish.ts` back under the 700-line cap, which the preflight
change's `getResolvedAuth` pass-through had pushed one line over; the file was
already sitting exactly at the limit on `main`.
* feat(gateway): make suspend/resume operator-usable end to end
A prepared Gateway now accepts authenticated WebSocket connects while
keeping every method except gateway.suspend.* fenced, so a fresh CLI or
controller process can resume a suspension instead of dead-ending on a
rejected upgrade until the two-minute lease expires. Restart drain,
worker ingress, and desktop-observe streams stay fully closed.
The gateway client surfaces non-101 upgrade responses (bounded body
read) as typed retryable errors instead of an opaque 1006 close, and
new openclaw gateway suspend / resume commands drive the whole
handshake, including bounded --wait polling with blocker output.
Live-verified on an isolated dev gateway: prepare, SIGSTOP/SIGCONT
freeze, resume, over-TTL expiry self-heal, conflict and mismatch paths.
* refactor(gateway-client): move wire-client contract types to protocol-client-contract
The connectError addition pushed protocol-client.ts over the 700-line
max-lines gate; split the adapter-facing contract types into their own
module instead of suppressing.
* refactor(gateway-client): keep contract-internal option types unexported
Knip deadcode gates reject exported types with no importer; the connect
and close decision shapes are only referenced inside the contract module.
* chore(plugin-sdk): refresh gateway-runtime API baseline after rebase
* fix(gateway-client): preserve hello type after rebase
* test(gateway): support websocket upgrade rejection events
* test(gateway): expect connection errors in close info
* fix(gateway): keep prepared-suspension connects control-only
Address ClawSweeper review: node and worker connects stay refused while
suspension is prepared (only operator control connects pass), and the
CLI never issues another suspend prepare after its --wait deadline.
* fix(agents): unify tiered model resolution for chat and compaction
Manual /compact failed with Unknown_model when the agent model was
configured as an undated ref (e.g. anthropic/claude-haiku-4-5): the chat
run resolved models through a two-tier path (discovery-free lookup, then
prepared stores with bundled static-catalog fallback) while both
compaction entry points made a single bare resolveModelAsync call and
dead-ended before the static catalog could resolve the undated id.
resolveTieredModel is now the canonical resolution owner used by the
chat run, direct compaction, and queued compaction; the duplicated
chat-only tier logic and both bare compaction lookups are removed.
Regression test proves chat and manual compaction resolve the same
undated configured model through the shared owner.
* fix(agents): satisfy lint and test-types on tiered resolution call sites
Drop the redundant ?? {} spread fallbacks (spreading undefined is a
no-op) and give the test registry mock its real (provider, modelId)
signature for check:test-types.
Supervisor-capture tests asserted real telegram/slack channel ids, so
their pass/fail depended on which channel plugins the selected vitest
lane loads (stubs when focused, real normalizers under unit-fast);
switch to a neutral synthetic channel. Two embedded-runner tests
carried a shared literal /tmp/openclaw.sqlite storePath — one actually
opened it, colliding with stale artifacts across parallel runs; both
now use realpath'd auto-cleaned per-test temp dirs.
Evidence in PR #122164 body; pre-fix aggregates failed 12/1202 (cli)
and 4/4750 (embedded), post-fix green in default and shuffled order.
Require an account-bound confirmation before deleting WhatsApp credentials, and revalidate Gateway ownership plus account state after the modal resolves.
Clear stale uncertainty debt when the same final reaches an authoritative terminal outcome, preventing false notices on the next inbound turn.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(delivery): preserve suppressed send outcomes
Preserve authoritative durable-send suppression outcomes so task, subagent, and exec followups no longer report false delivery or duplicate ambiguous adapter dispatches.
* fix(delivery): keep suppression reason internal
Derive the outbound projection from the existing durable batch result union so the repair does not change the public plugin SDK contract.
* fix(delivery): avoid retrying ambiguous task updates
Advance the state-change event cursor after an adapter returns no identity so a possibly visible progress notification is not sent twice; intentional suppression remains retryable.