Peter Steinberger
1ca60fbc3a
refactor(agents): make multi-agent ownership explicit (H2-1 core) ( #114388 )
...
* refactor(agents): make roster ownership explicit
* feat(config): materialize legacy agent roles
* fix(cron): migrate legacy owners at startup
* feat(gateway): expose agent selection contracts
* fix(gateway): enforce agent-scoped authorization
* docs(config): document explicit agent ownership
* fix(config): pin retained owner workspace
* fix(gateway): target hook wakes at effective agent
* fix(sessions): preserve fixed-store ownership
* fix: preserve retained agent ownership
* fix: preserve legacy agent ownership across runtime surfaces
* fix: fail closed on ambiguous session ownership
* fix: preserve compatibility owners across dispatch and writes
* fix: preserve retained agent projections
* fix: preserve agent ownership compatibility
* fix: preserve per-agent heartbeat guidance
* fix: preserve compatibility owners in generic paths
* fix: enforce configured ownership in session paths
* fix: defer remote roster selection
* fix: preserve ownership across session and config writes
* fix: fail closed on ambiguous restored ownership
* fix: preserve explicit ACP and legacy ownership
* fix: honor durable fixed-store ownership
* fix: enforce fixed-store owner authority
* fix: preserve ownership evidence boundaries
* fix: honor resolved session ownership
* fix: align compatibility ownership paths
* fix: persist legacy main store ownership
* fix: close ownership fallback gaps
* fix(agents): close retained owner compatibility gaps
* fix(agents): enforce session owner resolution
* fix(agents): complete session owner resolution sweep
* fix(agents): preserve durable session ownership
* fix: complete persisted session owner routing
* fix: thread prepared session owners
* fix: preserve stable session ownership
* fix: enforce session ownership boundaries
* fix: close session ownership delta gaps
* fix: reconcile session ownership after rebase
* fix: reconcile ownership with current main
* fix: align session store path imports
* fix: align session store config path import
* fix: reconcile explicit ownership CI
* fix: reconcile ownership rebase checks
* fix: align ownership ci contracts
* fix: align ownership rebase checks
* fix: preserve compatibility owner during setup
* fix(doctor): migrate ownerless heartbeat monitors
* fix(gateway): preserve explicit session ownership
* test: align ownership fixtures after rebase
* test: complete plugin manifest fixture
* test: align runtime context mocks
* fix(gateway): preserve alias routing for existing sessions
* style: format agent routing update
* fix(gateway): preserve selected owner during alias routing
* style: normalize rebased ownership files
* fix(gateway): preserve owner through global alias routing
* fix(gateway): preserve explicit ownership at HTTP boundaries
* fix(gateway): validate compatibility model ownership
* fix(agents): reconcile strict session ownership
* fix(agents): contain media yield callback failures
* fix(agents): avoid eager bare-key owner resolution
* chore: refresh rebased ownership baselines
* chore: align hosted plugin SDK baseline
* chore: refresh ownership baselines after main sync
* chore: refresh ownership baselines after main sync
* test: align routed event owner fixtures
* chore: retrigger CI after runner startup failure
* chore: refresh ownership SDK budgets after main sync
* fix(tasks): require agent identity for bare owners
* chore: align Linux plugin SDK baseline
* chore: remove release-owned changelog entry
2026-08-12 15:55:16 -07:00
Peter Steinberger
b6548e509a
refactor(state): retire commitments schema ( #122176 )
...
* refactor(state): retire commitments schema
* fix(state): complete commitments retirement safeguards
* test(state): expect doctor retirement report
* test(state): prove doctor v7 markers atomically
* fix(state): align schema support metadata
* fix(state): report actual commitments retirement
* fix(state): validate retired commitments schema
* fix(state): preserve early commitments upgrades
* fix(state): require exact commitments index set
* fix(state): reject non-exact retired schemas
* fix(state): recognize supported retirement layouts
* fix(state): expose commitments retirement to doctor
* fix(voice-call): describe commitments retirement
* test(state): align v7 rebase proof
* fix(state): protect commitments retirement dependencies
* fix(state): accept partial commitments layouts
* chore(docs): refresh v7 api baselines
2026-08-12 14:21:34 -07:00
Peter Steinberger
dceb2c343c
refactor: retire due compat-ledger surfaces (context-engine host params, deactivate alias, logging internals) ( #121845 )
...
* refactor(plugins): retire deactivate hook alias
* refactor(plugin-sdk): prune retired facade exports
* test(logging): isolate logger test controls
* refactor(logging): internalize file transport controls
* test(plugin-sdk): preserve retired facade coverage
* test(auto-reply): remove stale diagnostic imports
* refactor(logging): delete dead config-read guard
shouldSkipMutatingLoggingConfigRead had no production caller even on main;
it survived the dead-export scan only via logger's testApi re-export. The
test-isolation commit removed that mask, exposing the fossil. Delete the
guard, its test-only re-export, its mock entry, and its dedicated test file.
* refactor(plugin-sdk): retire due compatibility subpaths
* test(plugin-sdk): type group policy predicates
* refactor(plugin-sdk): split removed subpath records
* refactor(secrets): remove retired collector barrel
* test(plugin-sdk): tighten wildcard surface pin
* refactor(plugin-sdk): retire matrix facade metadata
* style(plugin-sdk): format facade metadata
* fix(ci): load channel setup contracts from source
Repair the main-owned regression from 99d662473c (Peter Steinberger): the new env-contract test could consume stale ignored dist metadata instead of the checked-in plugin declaration.
* test(plugin-sdk): refresh API baseline after rebase
2026-08-12 12:41:27 -07:00
Peter Steinberger
9da43d67e1
refactor: remove residual normalization adapters ( #122771 )
2026-08-12 11:51:45 -07:00
Peter Steinberger
c23d66e3b5
refactor: consolidate coercion ownership ( #122692 )
...
* refactor: consolidate coercion ownership
* test: align shard check with weighted planning
* chore: refresh plugin SDK API baseline
2026-08-12 09:25:28 -07:00
Peter Steinberger
6d973d114f
test: trim duplicate target registry coverage ( #122555 )
...
Co-authored-by: Amp <amp@ampcode.com >
2026-08-12 01:46:38 -07:00
Peter Steinberger
e4da1c8d8b
improve: speed up secrets runtime coverage tests ( #122538 )
...
* test: speed up secrets runtime coverage
* test: respect extension contract boundary
---------
Co-authored-by: Amp <amp@ampcode.com >
2026-08-12 01:22:36 -07:00
Peter Steinberger
1da8fffbcb
improve: speed up secrets audit test shard ( #122504 )
...
* test: speed up secrets audit coverage
* test: complete daemon plugin fixtures
---------
Co-authored-by: Amp <amp@ampcode.com >
2026-08-12 00:23:34 -07:00
Sliverp
84c7d45f15
refactor(qqbot): install plugin from Tencent package ( #107295 )
...
* refactor(qqbot): remove bundled extension source
Mechanical deletion half of the #107295 squashed rebase; the catalog
repoint and host integration land in the follow-up commit.
Co-authored-by: sliverp <870080352@qq.com >
* refactor(qqbot): install plugin from Tencent package
Squashed rebase of #107295 onto current main. Repoints the official
external channel catalog at @tencent-connect/openclaw-qqbot@2.0.1 and
adapts onboarding, doctor migrations, secrets, build guards, and tests.
Documents the known limitation that the external package does not
support structured SecretRef clientSecret values; operators move those
to QQBOT_CLIENT_SECRET or clientSecretFile before upgrading.
Co-authored-by: sliverp <870080352@qq.com >
* fix(doctor): reuse shared hasOwnKey record helper
The rebased QQBot migration carried its own hasOwnKey export, colliding
with the one main now ships in legacy-config-record-shared.ts.
Co-authored-by: sliverp <870080352@qq.com >
* fix(plugins): carry catalog integrity through the update bridge
The externalized-bundled-plugin bridge dropped the official catalog's
expectedIntegrity pin, so bundled-user updates installed the external
npm package without integrity verification. The bridge now carries the
pin for the catalog's exact npm spec and both bridge install calls pass
it through; update-channel spec overrides intentionally skip the pin
since it only covers the pinned version.
Co-authored-by: sliverp <870080352@qq.com >
* chore(plugin-sdk): refresh per-entrypoint API baselines
The QQBot compat export and bundled-type removal shift 26 entrypoint
closure hashes in the new split baseline layout.
Co-authored-by: sliverp <870080352@qq.com >
* refactor(qqbot): drop helper reintroduced during rebase
Main's coercion consolidation added this file after the deletion
commit's base; its only consumers were the removed qqbot sources.
Co-authored-by: sliverp <870080352@qq.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-08-11 15:10:27 -07:00
Peter Steinberger
e74be5d41d
refactor: eliminate final wrapper-shadowing hazards ( #122157 )
...
* refactor: disambiguate wrapper-shadowed exports
* test: align renamed session and facade boundaries
* test: cover renamed runtime mock exports
* refactor: align remaining wrapper owner call sites
* test: align overlap-rebased runtime mocks
* refactor: preserve public SDK names after overlap rebase
* chore: regenerate wrapper shadowing baselines
* test: align cron model selection mocks
2026-08-11 13:34:24 -07:00
Peter Steinberger
3d76246792
refactor: eliminate final export name collisions ( #122083 )
...
* refactor: resolve final export name collisions
* refactor: update remaining collision rename consumers
* style: format rebased auth helpers
* test: update remaining session entry mocks
* test: update remaining runtime mock exports
* test: update delivery info path mock
* refactor: reconcile combined collision sweeps
* chore: regenerate collision and sdk baselines
2026-08-11 11:18:24 -07:00
Peter Steinberger
db73b59c04
refactor: burn wrapper shadowing baseline entries ( #122040 )
...
* refactor: burn wrapper shadowing entries
* chore: refresh wrapper shadowing baselines
* test: update secrets runtime state mocks
* fix(ci): absorb Control UI build identity variance
2026-08-11 08:24:03 -07:00
Peter Steinberger
b067a4dce3
fix(secrets): reject empty secret values and classify oversized input as validation ( #121947 )
2026-08-11 02:30:04 -07:00
Peter Steinberger
ea06d72e85
feat(secrets): manage team secrets in Control UI ( #121724 )
...
* feat(secrets): add gateway store settings
* perf(control-ui): trim secrets startup copy
* perf(control-ui): reduce secrets startup payload
* fix(secrets): harden store mutation refresh
* perf(control-ui): meet secrets startup budget
* test(control-ui): update secrets navigation copy
* fix(ui): pluralize secret-detection count and drop duplicated dialog hint
* chore(protocol): regenerate gateway clients and SDK baseline after rebase
* fix(gateway): merge secrets store methods after project RPCs in advertised order
* chore: leave changelog to release generation
* test(gateway): retain desktop launch train coverage
2026-08-11 07:20:38 +00:00
Peter Steinberger
d6a4cdad68
test(core): remove orphan internal test aliases ( #121879 )
2026-08-10 23:23:48 -07:00
Peter Steinberger
36fbd869ed
refactor(agents): eliminate export name collisions ( #121768 )
...
* refactor(auth): consolidate profile helper owners
* refactor(agents): consolidate subagent registry reads
* refactor(agents): disambiguate runtime placement helpers
* refactor(agents): disambiguate helper exports
* chore(scripts): burn export collision debt
* test(agents): follow moved subagent read owner
2026-08-10 22:24:33 -07:00
Peter Steinberger
768f53d345
fix(secrets): resolve default aliases by source ( #121630 )
2026-08-10 21:05:26 -07:00
Peter Steinberger
a381aa3e8b
fix(memory): restrict multimodal indexing to extra paths ( #121627 )
...
* fix(memory): restrict multimodal indexing to extra paths
* fix(state): add lazy secret store schema ensure
* fix(state): bound lazy secret store schema
* chore(plugin-sdk): refresh API baseline
2026-08-10 19:00:45 -07:00
Peter Steinberger
f4bac99a81
feat(secrets): add SQLite-backed secret store ( #121559 )
2026-08-10 07:08:40 -07:00
Peter Steinberger
3b3c540896
refactor: remove dead branches and test-only helpers ( #121345 )
...
* refactor: remove dead branches and test-only helpers
* fix: preserve codex cleanup error causes
* fix: preserve gateway error code compatibility
* chore: update plugin sdk api baseline
* docs: fix live cache runner path
2026-08-10 06:47:43 -07:00
Peter Steinberger
46c712fd7e
fix(gateway): align prepared model auth readiness ( #121090 )
2026-08-09 09:05:38 -07:00
Peter Steinberger
693b62f69e
fix(secrets): reuse prepared plugin metadata ( #120863 )
2026-08-09 03:37:29 -07:00
Peter Steinberger
da463bfef4
fix(gateway): hydrate auth snapshots at startup ( #120977 )
...
Refs #120951 .
2026-08-09 00:55:07 -07:00
Vincent Koc
38039f5ea8
fix(secrets): preserve Windows ACL diagnostics ( #120211 )
...
* fix(secrets): preserve Windows ACL diagnostics
* fix(secrets): make Windows path security proof deterministic
* test(secrets): isolate Windows ACL tool failures
* test(secrets): preserve ACL preload process contract
* test(ci): route Doctor ACL proof to Windows
* test(qa): normalize Clack note borders
* test(ci): register Windows ACL preload for deadcode checks
2026-08-09 03:48:42 +08:00
Peter Steinberger
0aa85c7f83
perf(gateway): reuse lifecycle plugin metadata instead of per-turn rescans ( #120344 )
...
* perf(gateway): reuse lifecycle plugin metadata
* test(commands): expect workspace-scoped snapshot reuse in sessions metadata prep
2026-08-07 14:20:21 -07:00
Peter Steinberger
10e60fa0ce
refactor(plugins): shared legacy-state doctor migration and simple secret contracts ( #120346 )
...
* refactor(plugins): share legacy JSON doctor migration
* refactor(discord): share account token inspection cascade
* refactor(plugins): share simple channel secret contracts
* refactor(discord): keep token inspector private
2026-08-07 13:55:31 -07:00
Peter Steinberger
b4a26783f7
refactor(test): consolidate duplicated requireRecord and provider HTTP mock helpers ( #119982 )
...
* refactor(test): consolidate duplicated test helpers
* test: remove stale record guard import
* fix(test): remove orphaned record guards
* refactor(test): keep record requirement messages exhaustively typed
* fix(test): keep packages/ai record guard package-local
2026-08-06 14:48:01 -07:00
Vincent Koc
fd1662f49c
fix(cli): retire invalid secret flags and prove doctor recovery ( #118926 )
...
* test(qa): add doctor CLI recovery coverage
* test(qa): secure doctor exec SecretRef proof
* test(qa): gate doctor systemd recovery proof
* test(qa): normalize doctor terminal output
* test(qa): close doctor probe sockets
* test(qa): classify doctor probe as foreign
* test(qa): track doctor probe sockets
* test(qa): retain doctor instance narrowing
* test(qa): preserve observed doctor recovery proof
* test(qa): keep doctor recovery on stable dist
* test(qa): honor Windows exec ACL blocking
* test(qa): use canonical home for systemd recovery
* test(qa): follow bounded gateway recovery
* test(qa): accept lifecycle service label
* test(qa): align doctor recovery contract
Punchcard-Session: crisp-lantern-orchard-nv
* docs(secrets): remove retired provider bypasses
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate doctor recovery target
Punchcard-Session: crisp-lantern-orchard-nv
* fix(cli): retire invalid secret provider flags
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate doctor supervisor mode
Punchcard-Session: crisp-lantern-orchard-nv
* fix(plugins): remove dead secret path bypass
Punchcard-Session: crisp-lantern-orchard-nv
* chore: drop release-owned changelog entry
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate doctor sudo scope
Punchcard-Session: crisp-lantern-orchard-nv
* fix(secrets): remove dead path bypass
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate systemd user bus
Punchcard-Session: crisp-lantern-orchard-nv
2026-08-05 11:20:23 +08:00
Peter Steinberger
c83dcc2bc0
fix(security): harden network tool output at canonical owner boundaries ( #118984 )
...
* fix(security): bound external tool content at its canonical owner boundary
* fix(plugin-sdk): document supported security boundary and restore facade parity
2026-08-03 15:34:33 -07:00
Peter Steinberger
8eaf917efb
fix(google): honor Cloud SDK credential location and Vertex billing project ( #118745 )
2026-08-03 10:47:13 -07:00
Peter Steinberger
836a9f8323
test(secrets): consolidate runtime fixtures ( #118162 )
2026-08-02 13:13:37 -07:00
Peter Steinberger
33ea3e16e9
refactor: consolidate core micro-helpers ( #117825 )
...
* refactor: centralize stable stringification
* refactor: reuse canonical record coercion
* refactor: reuse safe JSON parsing in cron storage
* refactor: centralize environment truthiness
* fix: enforce model scan and block reply timeouts
* refactor: consolidate signal-aware sleep helper
* fix: preserve plugin SDK sleep contract
* test: satisfy model scan timeout lint
2026-08-01 23:10:46 -07:00
Peter Steinberger
c5dd9c3095
test(secrets): dedupe runtime state fixtures ( #117563 )
2026-08-01 11:48:07 -07:00
Peter Steinberger
586e1fe10e
refactor: dedupe secrets runtime snapshot fixtures ( #117502 )
...
* test(secrets): dedupe runtime snapshot fixtures
* test(secrets): preserve runtime auth-store fixture type
2026-08-01 10:26:33 -07:00
Jesse Merhi
d3f4530ce8
feat(google): allow operator headers on Gemini web search ( #115549 )
...
* feat(google): support Gemini web search headers
* fix(google): validate Gemini search headers
* docs(changelog): credit Gemini headers
* test(secrets): route config contracts through collector
* chore: remove release-owned changelog entry
* test(google): cover resolved search headers
2026-08-02 01:41:09 +10:00
Peter Steinberger
383f8947c1
fix: doctor skips host services for isolated state ( #115922 )
...
* fix(doctor): isolate host service management
* fix(doctor): clarify service isolation recovery
* test(doctor): isolate service identity fixtures
* test(daemon): keep lifecycle fixtures lint-clean
* test(daemon): isolate install identity fixtures
2026-07-29 11:09:56 -04:00
Peter Steinberger
c5d0b7dd39
refactor: retire legacy provider and secret paths ( #115655 )
...
* refactor: retire legacy provider and secret paths
* fix: remove stale cache retention import
* test: remove retired secret marker fallback
2026-07-29 04:36:20 -04:00
Gio Della-Libera
47f654ea14
fix(claws): report plugin setup readiness ( #114899 )
...
* fix(claws): report plugin setup readiness
* fix(claws): keep setup readiness helper private
* fix(claws): honor local provider auth evidence
* fix(claws): require auth-method-only setup
* fix(azure-speech): keep setup envs credential-only
* revert(azure-speech): preserve compound setup metadata
2026-07-29 05:48:35 +00:00
Peter Steinberger
269bc5c89e
fix(cli): preserve machine-readable stdout ( #113654 )
...
Co-authored-by: 1052326311 <65798732+1052326311@users.noreply.github.com >
2026-07-27 05:44:16 -04:00
Peter Steinberger
fd6e042d87
fix(gateway): keep configured local auth authoritative ( #114462 )
...
* fix(gateway): align configured local credentials
* test(gateway): align local credential coverage
* chore(gateway): leave release note to release process
2026-07-27 05:43:31 -04:00
Peter Steinberger
3c67fcc45d
fix(release): stabilize beta validation and completion ( #114396 )
...
* test(release): fix rebased validation gates
* test(migrate-hermes): use canonical auth store fixture
* test(secrets): reset runtime state before migration isolation
* test(secrets): reload singleton graph for migration isolation
* test(secrets): isolate auth migration state
* fix(release): return completed validation run
* docs: refresh docs map after forward-port
2026-07-27 03:42:00 -04:00
Peter Steinberger
b6dcb8c323
test(auth): avoid broad profile discovery in migration isolation ( #114217 )
2026-07-26 21:12:33 -04:00
Peter Steinberger
19a98c873c
refactor(auth): finish SQLite-only auth profile cutover ( #114033 )
...
* refactor(auth): finish SQLite-only profile cutover
* test(auth): isolate SQLite shadow fixtures
* test(auth): satisfy OAuth refresh lint
* test(auth): infer legacy sidecar fixtures
* fix(auth): fail closed on unreadable stores
* fix(auth): recheck migration readiness on lookup
* fix(auth): preserve compatibility owner checks
* fix(auth): align SQLite cutover proof
* style(qa): format SQLite auth helpers
* fix(auth): recover interrupted SQLite migrations
* fix(auth): bind materialized SQLite refs
* style(auth): clarify receipt hash value
* fix(auth): preserve state-only OAuth routing
* fix(auth): snapshot receipted migration sources
* fix(auth): fail closed across recovery races
* fix(auth): close legacy recovery gaps
* fix(auth): serialize SQLite refresh recovery
2026-07-26 07:27:54 -04:00
Peter Steinberger
5347285d6b
improve(models): source pricing from hosted catalog ( #114060 )
...
* feat(model-catalog): serve hosted fallback pricing
* refactor(config): retire client pricing bootstrap settings
* refactor(gateway): delete client pricing refresh runtime
* docs(models): explain hosted catalog pricing
* fix(model-catalog): preserve pricing privacy and aliases
* fix(model-catalog): fingerprint pricing eligibility
* fix(model-catalog): harden pricing endpoint checks
* fix(model-catalog): materialize source-safe pricing aliases
* fix(model-catalog): keep unknown pricing fallbacks safe
* fix(model-catalog): reject zero-only hosted prices
* fix(model-catalog): fail closed without pricing policy metadata
* refactor(utils): extract usage pricing normalization
* fix(model-catalog): rebuild policy-owned pricing namespaces
* test(model-catalog): type publisher cost fixtures
* chore(config): regenerate schema baselines
* fix(utils): keep raw pricing tiers private
2026-07-26 03:48:25 -04:00
Peter Steinberger
481d826ff4
fix(vault): prevent insecure secrets plan writes ( #113707 )
...
* fix(vault): harden secrets plan writes
* fix(secrets): avoid env marker collision
* style(secrets): type plan write rejection
* refactor(onepassword): remove obsolete path resolver
* fix(secrets): preserve Windows plan path trust
* refactor(secrets): compact ACL token policy
* fix(secrets): route permission checks through facade
2026-07-25 08:27:33 -07:00
joshavant
f153858045
fix(onepassword): make SecretRef setup production-safe
2026-07-25 06:03:30 -05:00
Peter Steinberger
82d1a03f25
refactor(agents): move implicit-main fallback into load-time roster injection ( #112678 )
...
* refactor(agents): require explicit roster defaults
* feat(onboard): create named first roster agent
* refactor(agents): remove runtime main fallbacks
* style(agents): apply roster refactor formatting
* refactor(agents): finish roster-only runtime sweep
* fix(doctor): migrate legacy main session sqlite
* fix(doctor): harden roster session migrations
* fix(onboard): commit first agent atomically
* fix(config): support empty-roster analysis
* fix(agents): preserve legacy main state during creation
* fix(setup): materialize baseline agent roster
* fix(agents): harden legacy default transfer recovery
* fix(agents): simplify roster-only legacy compatibility
* fix(agents): preserve staged first-agent entries
* fix(config): migrate persisted implicit-main rosters
* fix(config): preserve staged empty rosters
* fix(agents): finalize roster-only upgrade paths
* fix(sessions): close legacy main migration outcomes
* fix(config): migrate legacy roster markers at load
* fix(sessions): preserve roster upgrade history
* refactor(sessions): restore lean legacy main compatibility
* fix(setup): prepare first-agent credentials before publish
* fix(config): stabilize roster snapshot migration
* refactor(sessions): shrink legacy main compatibility
* fix(agents): restore roster compatibility fidelity
* fix(sessions): preserve divergent legacy history
* refactor(agents): narrow roster-only scope
* fix(config): isolate roster migration
* test(agents): align roster-only fixtures
* fix(agents): keep main agent undeletable
* fix(agents): harden roster migration invariants
* fix(agents): close setup and audit scope gaps
* fix(cron): scope session reaper throttles by agent
* fix(agents): preserve scoped owner precedence
* fix(config): preserve authored config ownership
* fix(setup): keep default workspace and roster in sync
* fix(setup): preserve default entry workspace on bare runs
* fix(agents): adapt roster rebase to keyed entries
* fix(agents): honor both roster representations
* fix(agents): route roster reads through shared helpers
* fix(config): preserve canonical roster writes
* fix(cron): resolve dynamic default for session reaper
* fix(agents): close dynamic default migration gaps
* fix(agents): align scoped session ownership
* fix(sessions): preserve legacy main directory casing
* fix(agents): align cron and legacy auth ownership
* fix(setup): provision the committed default workspace
* fix(cron): align scoped ownership and reaping
* fix(cron): treat blank agent ids as absent
* fix(cron): retain configured session-store owners
* fix(agents): repair roster-aware CI boundaries
* fix(cron): preserve scoped ownership resolution
* fix(agents): preserve rosterless maintenance paths
* fix(agents): propagate roster ownership through runtime boundaries
* fix(agents): preserve roster ownership across runtime paths
* fix(agents): harden roster diagnostics and legacy routing
* fix(agents): remove redundant diagnostic import
* test(agents): type CLI policy fixture explicitly
* fix(config): preserve canonical roster mutation identity
* fix(doctor): read canonical agent rosters consistently
* fix(config): resolve compound roster unsets safely
* fix(config): finalize main-session reconciliation
* fix(doctor): read canonical session state safely
* fix(sessions): preserve current visibility alias
* fix(config): track roster include provenance
* test(config): type roster provenance cases
* fix(config): refine roster include ownership
* fix(agents): preserve staged roster invariants
* test(config): align fixtures with explicit roster ownership
* test(node-host): preserve optional plan typing
* fix(config): preserve authored roster projections
* test(config): keep raw roster fixtures explicit
* test(config): normalize rosters at runtime fixtures
* fix(config): protect authored roster ownership
* fix(agents): require explicit session ownership
* fix(agents): enforce scoped roster ownership
* fix(sessions): merge fixed-store agent partitions
* fix(agents): harden roster ownership boundaries
* fix(config): reject ambiguous roster projections
* fix(sessions): preserve persisted store ownership
* fix(sessions): keep collision diagnostics additive
* fix(security): scan malformed roster workspaces
* test(config): align snapshot fixtures after rebase
* test(agents): use explicit roster fixtures
* fix(config): harden roster diagnostic boundaries
* fix(sessions): isolate fixed-store agent databases
* test(agents): type malformed default markers
* refactor(sessions): extract store collision resolution
* test(system-agent): split oversized setup coverage
* style(system-agent): format split setup suite
* fix(sessions): preserve promoted store ownership
* fix(sessions): derive scoped owner before target
* fix(sessions): preserve explicit sqlite ownership
* fix(agents): restore roster compatibility across CI
* fix(agents): enforce roster-owned runtime boundaries
* fix(agents): satisfy default lookup lint
* test(sessions): split known-owner coverage
* fix(state): satisfy path identity lint
* fix(agents): preserve malformed roster safety boundaries
* fix(agents): restore roster compatibility at runtime boundaries
* fix(config): satisfy roster boundary type checks
* fix(agents): preserve roster ownership across runtime probes
Setup inference probes now execute as the configured roster owner. Malformed agent-prefixed session rows are intentionally omitted by the fail-closed visibility contract rather than normalized by tests.
* fix(agents): satisfy session list owner lint
* fix(agents): preserve roster-owned runtime boundaries
Restore shared logical rows for exact SQLite session locators while keeping their physical database owner separate. The ownership regression test now constructs an explicit sole-owner database directly instead of relying on first-touch capture, matching the intentional shared-store contract.
* fix(sessions): preserve multiply owned exact stores
* fix(sessions): restore runtime owner boundaries
Keep incognito sentinels agent-owned, fold default-agent approvals into the global snapshot, and preserve the configless legacy-main CLI policy fallback. Also repair the existing CLI watchdog test lifecycle so the compact shard observes its timeout without an unawaited assertion or async timer stall; product behavior is unchanged by that test-only fix.
* test(ci): align owner-scoped fixtures
These assertions are unchanged. The fixtures now declare the intended non-default runner, expose the session-key constant imported by production status code, and select the main approvals bucket explicitly on Windows.
* fix(agents): close final roster ownership gaps
2026-07-24 22:38:09 -07:00
Peter Steinberger
26e4dec8c9
fix(ios): native Talk respects session thinking level ( #112901 )
...
* fix(ios): inherit thinking in native Talk
* test(ios): verify native Talk thinking inheritance
* test(ios): keep Talk regression i18n-neutral
* test(ios): import Talk request builder module
* test(secrets): secure plugin preset fixture
---------
Co-authored-by: RECOVERI <alfred@recoveri.io >
2026-07-23 01:02:12 -04:00
Hiroshi Tanaka
52f412bf17
fix(browser): tab creation steals window focus during agent automation ( #105356 )
...
* fix(browser): tab creation steals window focus during agent automation
Agent-created tabs inherited CDP's foreground default: direct CDP
Target.createTarget omitted the background flag, and the extension
relay's createTab defaulted to active:true, so every agent tab open
activated the new tab (and, on the extension driver, focused the
window), interrupting whatever the human was doing in that browser.
Direct CDP tab creation now requests background:true (agent tab
ownership/selection is target-id based and never depended on
activation), and the extension relay defaults an omitted background
to true while preserving an explicit background:false, matching the
Codex/Claude-in-Chrome model the extension driver mirrors.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
* refactor(browser): keep focus fix LOC-neutral
Preserve background tab creation while keeping the oversized CDP and relay modules within the current LOC ratchet.\n\nCodex-Session: 019f5e93-780a-7350-88f9-1986cdb64914
* fix(browser): honor explicit CDP focus requests
Keep background-by-default automation while treating Target.createTarget focus=true as an explicit foreground request in the extension relay.
Codex-Session: 019f5e93-780a-7350-88f9-1986cdb64914
* fix(browser): preserve explicit CDP focus semantics
Apply the background-by-default automation policy only when focus is omitted, preserving focus=false foreground-tab requests as well as focus=true.
Codex-Session: 019f5e93-780a-7350-88f9-1986cdb64914
* fix(browser): preserve create target window focus
Carry the resolved CDP focus intent through the extension relay and explicitly focus the containing Chrome window when requested.\n\nCodex-Session: 019f5e93-780a-7350-88f9-1986cdb64914
* style(browser): refresh relay import order
* test(secrets): use secure node exec fixtures
* test(doctor): secure exec secret fixture
* test(doctor): retain narrowed temp path
* test(secrets): secure remaining exec fixtures
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-21 21:35:40 -07:00
Peter Steinberger
edecdbd05e
refactor(config): config-surface reduction tranche 3 — product consolidations (review request) ( #111527 )
...
* refactor(config): consolidate media model lists
* refactor(config): unify memory configuration
* refactor(config): consolidate TTS ownership
* refactor(config): move typing policy to agents
* refactor(config): retire product-level config surfaces
* refactor(config): share scoped tool policy type
* chore(config): refresh generated baselines
* fix(config): honor agent typing overrides
* fix(config): migrate sibling config consumers
* refactor(infra): keep base64url decoder private
* fix(config): strip invalid legacy TTS values
* chore(config): refresh rebased baseline hash
* fix(doctor): route legacy messages.tts.realtime voice to talk during tts move
* refactor(config): polish final layout names
* refactor(config): freeze retired tuning defaults
* feat(config): add fast mode default symmetry
* refactor(config): key agent entries by id
* docs(config): update final layout reference
* test(config): cover final layout migrations
* chore(config): refresh final layout baselines
* fix(config): align final layout runtime readers
* fix(config): align remaining readers
* fix(config): stabilize final layout migrations
* fix(config): finalize config projection proof
* fix(config): address final layout review
* docs(release): preserve historical config names
* fix(config): complete keyed agent migration
* fix(config): close final migration gaps
* fix(config): finish full-branch review
* fix(config): complete runtime secret detection
* fix(config): close final review findings
* fix(config): finish canonical docs and heartbeat migration
* fix(config): integrate latest main after rebase
* refactor(env): isolate test-only controls
* refactor(env): isolate build and development controls
* refactor(env): collapse process identity indirection
* refactor(env): remove duplicate config and temp aliases
* docs(env): define the operator-facing allowlist
* ci(env): ratchet production variable count
* fix(env): remove stale provider helper import
* fix(env): make ratchet sorting explicit
* test(env): keep test seam in dead-code audit
* test(env): cover ratchet growth and boundary; document surface budgets
* docs(config): document tier-eval consolidations
* docs(config): clarify speech preference ownership
* test(memory): align retired tuning fixtures
* refactor(memory): freeze engine heuristics
* refactor(config): apply tier-eval tranche
* refactor(tts): move persona shaping to providers
* refactor(compaction): move prompt policy to providers
* test(config): align hookified prompt fixtures
* chore(deadcode): classify test-only exports
* chore(github): remove unused spawn helper
* chore(deadcode): classify queue diagnostics
* chore(deadcode): remove unused lane snapshot export
* chore(plugin-sdk): ratchet consolidated surface
* fix(config): integrate latest main after rebase
2026-07-21 20:28:43 -07:00