Final review findings:
- Wrap the operator-approval copy/drop/rename in a single immediate
transaction so a crash mid-migration cannot strand or lose rows.
- The inference fallback marked a provider attempted before probing, so a
stale requester credential blocked another agent's valid same-provider
route. Dedup by credential owner and only retire a whole provider on
provider-wide failures (auth/billing may differ per credential owner).
Refs #107237
New openclaw delegation tool relays to openclaw.chat in-process; persistent
writes surface through the existing durable operator-approval registry as a
third system-agent kind (no parallel store), armed only by a human operator
in the Control UI — a delegated agent can never self-approve. Setup wizards
(channel/model/open-setup/open-tui) are refused in delegated mode so a
machine agent cannot complete setup or persist credentials unattended.
Vendor-neutral inference fallback ladder (requester route first, then other
authed providers by provider id). update.run removed from the gateway tool.
Caveman system-prompt fragment steers config/channels/plugins/agents/updates
to the openclaw tool. Doctor-owned state migration widens the approval-kind
constraint; runtime stays canonical-only.
Refs #107237
The Crestodian->OpenClaw reconciliation restored a pre-#102197 `if (opts.approved)`
wrapper around the execute-time plugin-install trust check, so an unapproved
plugin-install op produced a formatted plan for an arbitrary npm/url/file
source instead of rejecting it. Validate unconditionally, matching #102197,
and restore its dropped regression test. Also fix a stale
crestodian-ring-zero-setup id in the CI compat list and a doubled
openclaw-openclaw-planner tmpdir prefix from the mechanical rename.
Rebase onto main pulled in the ClawHub plugin-install trust check (#102197);
ported it into the renamed system-agent operations/tool/tests, refreshed
native i18n, deadcode, and max-lines baselines for the renamed paths.
Refs #107237
Review findings on the rename: macOS resume store now migrates activation
leases persisted under the retired crestodian UserDefaults key so an app
upgrade cannot orphan a live activation; open-tui results carry
returnToShell so bare /openclaw re-enters the OpenClaw shell instead of
exiting the CLI.
Refs #107237
Identifiers ending in TOKEN false-positive secret scanners on every diff
touching this file; ARG_WORD also describes the grammar role better.
Refs #107237
User-facing name is now OpenClaw (the system speaks); internal code name is
system-agent. Gateway methods crestodian.* -> openclaw.chat/openclaw.setup.*,
agent tool -> openclaw, reserved agent ids openclaw + retired crestodian.
openclaw setup routes: onboarding flags -> onboard, -m/--yes -> system agent,
bare configured interactive -> OpenClaw chat, unconfigured -> onboarding.
Hidden crestodian CLI and /crestodian TUI aliases kept; docs moved to
docs/cli/openclaw.md with redirect stub. macOS/Android strings in lockstep.
Refs #107237