Commit Graph

39780 Commits

Author SHA1 Message Date
Jesse Merhi 4a2a600809 feat(channels): add channel-owned setup contracts (#112176)
* feat(channels): add channel-owned setup contracts

* test(channels): align legacy setup fixtures

* chore(channels): regenerate config and SDK baselines after rebase

* fix(update): run fresh doctor after current-process core changes

* fix(channels): align add pre-scan with execution precedence

* style(cli): format channels-cli test additions

* fix(channels): restore option-before-positional channel resolution via metadata arity scan

* fix(channels): keep help flags out of metadata arity escalation

* test(update): mock fresh post-update doctor in current-process suites

* style: format review fixes and correct entrypoint mock type

* fix(channels): register only modern contract options for dual-publishing plugins

* test(update): align downgrade suites with fresh-doctor child invocation

* docs(channels): record empty-contract and input-forwarding invariants

* fix(line): keep the shipped --token switch as a channel access token alias

* fix(signal): stop treating exact cross-family loopback endpoints as bind-aligned

* chore(config): regenerate docs config baselines after second rebase

* style: format rebased channels add tests

* fix(channels): enforce field-key and flag-name agreement in setup contracts

* fix(signal): detect container endpoints for bare --http-url setup

* fix(signal): ignore unconfigured accounts in transport collision checks

* fix(channels): validate negated setup flags in contract and normalizer

* fix(signal): preserve existing transport kind when setup detection is unreachable

* style(signal): use direct boolean check in collision guard

* style(signal): type test config literals

* docs(update): record two-read design of fresh-doctor validation gate

* fix(channels): satisfy post-rebase architecture gates

* docs: refresh channel setup map

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-22 19:57:42 -04:00
Peter Steinberger b375776acf fix: forced cloud worker teardown cannot be blocked by recovery (#112781)
* fix(cloud-workers): make forced environment destruction unstoppable

* fix(cloud-workers): retain failed workspace rollback journals

* chore: defer cloud worker release note

* fix(cloud-workers): preserve forced rollback retries
2026-07-22 19:39:49 -04:00
Peter Steinberger e085b379f8 refactor(agents): thread plugin metadata snapshots per turn (#112769)
* refactor(agents): thread plugin metadata snapshots per turn

* fix(agents): validate threaded plugin metadata

* fix(agents): preserve prepared metadata fallbacks

* fix(commands): preserve snapshot auth refs typing

* fix(commands): use indexed synthetic auth refs

* test(auto-reply): isolate completed goal session store

* test(agents): serialize embedded runner harness files

* test(auto-reply): serialize reply runtime files

* test(auto-reply): isolate goal context admission

* test(auto-reply): allow persisted goal admission under CI load

* test(agents): allow embedded harness warmup under CI load
2026-07-22 19:33:45 -04:00
Peter Steinberger a677b00dae test: consolidate restart recovery fixtures (#112789) 2026-07-22 19:25:39 -04:00
Peter Steinberger e13bc7c63e refactor(agents): remove unused JSONL session paths (#112775)
* refactor(agents): remove legacy session file discovery

* refactor(agents): remove dead sessions directory helper
2026-07-22 19:22:26 -04:00
Peter Steinberger cdb8d32bcc refactor(agents): consolidate model normalization (#112772)
* refactor(agents): consolidate model normalization

* docs(agents): clarify normalization boundary
2026-07-22 19:19:41 -04:00
Peter Steinberger dbd6662976 refactor(cloud-workers): audit staged finalize fences (#112739) 2026-07-22 19:18:44 -04:00
Peter Steinberger 637afd0114 refactor(config): move Slack and Signal schemas to plugins (#112792)
* refactor(config): move Slack and Signal schemas to plugins

* build(signal): declare schema runtime dependency

* build(signal): refresh plugin shrinkwrap
2026-07-22 19:14:56 -04:00
Peter Steinberger 9b1e9a5e66 test: trim update CLI boilerplate (#112793) 2026-07-22 19:10:02 -04:00
Peter Steinberger f5562748de fix(logging): give non-default profiles their own gateway log file (#112777)
* fix(logging): give non-default profiles their own gateway log file

* chore: defer profile log release note
2026-07-22 19:08:41 -04:00
Peter Steinberger bf922f59fe fix(onboard): keep setup effects on the default agent (#112738)
* fix(onboard): align default agent setup ownership

* chore(onboard): remove stale target assignments

* fix(onboard): preserve workspace provisioning boundary
2026-07-22 19:05:21 -04:00
Peter Steinberger 0724dfda21 refactor(channels): share retry and text break helpers (#112786)
* refactor(channels): share retry and text break helpers

* fix(sdk): keep helper internals private
2026-07-22 19:05:00 -04:00
Peter Steinberger 939ecb5ef8 refactor(meeting-bot): hoist meeting adapter runtime glue (#112785)
* refactor(meeting-bot): hoist adapter runtime glue

* refactor(meeting-bot): specialize runtime adapters

* refactor(google-meet): reuse runtime adapter alias

* refactor(meeting-bot): privatize consult internals

* refactor(plugin-sdk): ratchet meeting runtime surface
2026-07-22 18:52:17 -04:00
Peter Steinberger 30c651d5bf docs(control-ui): clarify loopback gateway auth (#112746)
* docs(control-ui): clarify loopback gateway auth

* fix(gateway): preserve control ui settings auth hint
2026-07-22 18:45:56 -04:00
Peter Steinberger c4bd3f5b2e refactor: consolidate CLI runner test fixtures (#112779)
* test: consolidate cli runner fixtures

* test: satisfy CLI fixture guards
2026-07-22 15:28:48 -07:00
Peter Steinberger 85e2a43229 refactor: share subagent test fixtures (#112778)
* test(agents): share subagent fixtures

* test(agents): keep gateway mock private
2026-07-22 15:04:02 -07:00
Peter Steinberger 1650faf6a1 refactor(plugin-sdk): remove unread setup helpers (#112767)
* refactor(plugin-sdk): remove unread setup helpers

* refactor(plugin-sdk): privatize removed setup edges

* test(channels): remove stale proxy mock import
2026-07-22 14:57:32 -07:00
Jason (Json) dc5f14f442 fix(onboarding): reuse active Codex API-key authentication (#112770)
* fix(onboarding): import Codex API key auth

* fix(onboarding): honor active Codex API-key auth

* fix(onboarding): remove unused Codex auth export
2026-07-22 15:52:27 -06:00
wahaha1223 2287d65cda fix(infra): preserve git metadata across short reads (#109419)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: ZengWen-DT <ceng.wen@xydigit.com>
2026-07-22 14:49:53 -07:00
Peter Steinberger 18f70922de fix(cron): harden live automation lifecycle (#112766) 2026-07-22 14:47:58 -07:00
Dallin Romney 635d396755 refactor(talk): run the Gateway realtime relay through the shared session harness (#112590)
* refactor(talk): adopt session harness in gateway relay

* fix(talk): preserve relay harness behavior

* style(talk): format relay barge-in call

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-22 14:40:32 -07:00
sunlit-deng 74c5415e2e fix(google-meet): reject malformed audio base64 (#106474)
* fix(google-meet): reject malformed audio base64

* refactor(meeting-bot): validate node audio centrally

Make the shared meeting-bot owner reject malformed push and pull audio for Google Meet, Teams, and Zoom without plugin-specific callbacks or permissive fallbacks.

Co-authored-by: sunlit-deng <yang.jiajun1@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-22 14:25:42 -07:00
Md Abrar Ibn Habib d2d3171bb7 fix(agents): strip current exec failure traces (#111877)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: xbrxr03 <abrarhabib03@gmail.com>
2026-07-22 14:19:59 -07:00
Peter Steinberger ef872829c3 perf(models): scope provider-filtered catalog discovery (#112752)
* perf(models): scope provider-filtered catalog discovery

* fix(models): gate scoped discovery on catalog ownership

* test(models): type catalog ownership fixtures
2026-07-22 14:17:47 -07:00
Gwydion Nanashi Ferrinas Solidor 4e6a6bdbcc fix: message sends fail when optional location is blank (#112013)
* fix(outbound): ignore blank shared-schema send location

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: b529c5fd-6822-4c0d-ab8d-9906bd7dc8d9

* fix(outbound): normalize blank send locations

Co-authored-by: ronan-dandelion-cult <ronan.dandelion.cult@hotmail.com>

---------

Co-authored-by: ronan-dandelion-cult <ronan.dandelion.cult@hotmail.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-22 14:16:18 -07:00
Peter Steinberger 267d9f89ef fix(compaction): preserve summary conversation anchors (#112755)
Co-authored-by: rune-dandelion-cult <rune.dandelion.cult@hotmail.com>
2026-07-22 14:15:32 -07:00
Masato Hoshino fd461d423c fix(agents): give bash stdout and stderr independent decode lanes (#112325)
* fix(agents): give bash stdout and stderr independent decode lanes

stdout and stderr are independent pipes, but the local bash execution path
fed both into one onData callback sharing a single TextDecoder and one
streaming ANSI/OSC sanitizer. A multibyte UTF-8 character split across a
stdout read boundary was corrupted when stderr wrote between its bytes, and
an unterminated OSC on stdout swallowed subsequent stderr output. This
contradicts the documented invariant in shell-utils.ts ('Keep one ANSI
parser per process stream so control sequences can span callbacks').

Tag onData with an optional stream identifier and give each lane its own
TextDecoder and text-transform state; finish() flushes every lane. Untagged
callers keep the single shared lane for backward compatibility.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(agents): harden bash stream isolation

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-22 14:14:14 -07:00
LZY3538 d94a192143 fix(path): follow mise data directory precedence (#111258)
* fix(path): follow mise data directory precedence

* test(path): tighten mise precedence coverage

Co-authored-by: LZY3538 <liu.zhenye@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-22 14:10:19 -07:00
Peter Steinberger 4e9ae9fbff feat(cron): system-owned heartbeat monitor jobs replace the dedicated interval scheduler (#112585)
* feat(cron): system-owned heartbeat monitor jobs replace the interval scheduler

- new internal cron payload kind {kind:"heartbeat"}: execution pokes
  requestHeartbeat({source:"interval"}); reported in the protocol job
  schema, not accepted from client create/patch
- gateway converges one declaration-keyed monitor job per heartbeat-enabled
  agent (schedule every+deterministic phase anchor) at startup and on
  config reload; removes monitors for unconfigured agents
- heartbeat runner loses its interval setTimeout machinery; nextDueMs
  stays as the cooldown gate, event wakes unchanged

* test(cron): heartbeat monitor regressions; docs for cron-owned cadence

- converge/prune/failure-containment tests for heartbeat monitor jobs
- heartbeat payload run fires an interval wake, no system event
- scheduler tests converted from timer self-fire to wake-queue pokes;
  timer-mechanics-only tests deleted with the timer
- persisted-shape accepts the heartbeat payload kind
- docs: heartbeat cadence ownership + system payload kind

* fix(cron): heartbeat monitor review round 1

- targeted cron-monitor interval ticks use the full per-agent path so
  due-commitment sessions still deliver
- cron-disabled gateways keep a local fallback interval timer (shipped
  cron.enabled=false contract; removed when heartbeat config folds into
  cron in #110950)
- heartbeat job reconciliations serialize with latest-wins epochs and a
  bounded 30s retry after a failed convergence pass

* fix(cron): chain clamped fallback heartbeat timers past the setTimeout cap

* fix(cron): heartbeat monitor review round 3

- targeted monitor redirect skips wakes carrying heartbeat overrides and
  surfaces the per-agent terminal skip reason instead of not-due
- cron-disabled fallback timer re-arms with a 1s floor after each firing
  so a dropped wake cannot end the chain
- heartbeat payloads are system-owned at the service boundary: add requires
  the gateway opt-in, patches to the kind are rejected

* fix(cron): heartbeat monitor review round 4 — full ownership enforcement

- prune only jobs proven to be monitors (prefix AND heartbeat payload)
- existing monitors reject every update patch; declarative upserts on the
  monitor key require the gateway opt-in even with a different payload

* fix(cron): complete heartbeat monitor ownership boundary

- converge scopes declarative matching to real monitors so a colliding
  user job with the same key is never adopted or overwritten
- monitor removal requires the gateway systemOwned opt-in; ad-hoc
  API/CLI deletion is rejected, reconciliation cleanup still prunes

* docs(cron): record intentional enrollment-snapshot semantics for monitor ticks

* fix(cron): repair heartbeat monitor CI gates
2026-07-22 14:03:29 -07:00
Po-Han Shih 7cf6bd5e4b fix: treat EPERM as alive in isPidAlive (#110235)
* fix(pid): treat EPERM as alive in isPidAlive

Match isPidDefinitelyDead: process.kill(pid, 0) throwing EPERM means the
PID exists but cannot be signaled, so it should not look dead.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(pid): check Linux zombies after EPERM existence probe

EPERM means the PID exists but cannot be signaled; still run the zombie check so Linux zombies are not reported as alive.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(pid): isolate EPERM liveness probe

Co-authored-by: stantheman0128 <stanshih888@gmail.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-22 13:56:09 -07:00
Gio Della-Libera f004d76a0e Plan grouped Claw agent updates (#102959)
* Plan grouped Claw agent updates

* test(claws): cover update planning

* docs(claws): document update preview

* fix(claws): bind update capability effects

* fix(claws): redact update capability effects

* fix(claws): bind capability previews to exact changes

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-07-22 13:44:09 -07:00
Gio Della-Libera 31ff00fe82 Add experimental Claw lifecycle diagnostics (#102427)
* Add experimental Claw lifecycle diagnostics

* test(claws): cover lifecycle diagnostics

* docs(claws): document doctor diagnostics

* test(claws): derive future state schema version

* test(claws): clean doctor restack fixture

* test(claws): align doctor drift fixture with agent entries

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-07-22 11:55:47 -07:00
Yuval Dinodia 5419a94587 fix(doctor): merge legacy flat auth repair into existing SQLite store (#98245)
maybeRepairLegacyFlatAuthProfileStores rewrote the per-agent SQLite auth
profile store with a store built solely from the legacy flat
auth-profiles.json, and backed up only that flat JSON. Any credential
present in SQLite but absent from the flat file (for example an OAuth
refresh token from a login after the SQLite migration) was destroyed and
was not in the backup, so a routine openclaw doctor caused unrecoverable
credential loss.

Load the existing SQLite store and merge the legacy flat profiles into
it, preserving credentials already present, then verify the imported
profiles persisted before removing the flat file, mirroring the SQLite
migration path.
2026-07-22 11:37:26 -07:00
Peter Steinberger 2b405755b1 fix(plugins): refresh prepared provider metadata (#112699)
* fix(plugins): refresh prepared provider metadata

* test(agents): tolerate minimal metadata snapshots

* test(agents): cover snapshot endpoint precedence
2026-07-22 11:07:35 -07:00
Peter Steinberger 32d4323049 docs(plugins): link setup-input deprecations to the migration pattern and document reader sweeps (#112692)
* docs(plugins): link setup-input deprecations to the migration pattern and document reader sweeps

* ci: retrigger queued run

* docs: regenerate docs map
2026-07-22 11:04:19 -07:00
Gio Della-Libera b56006babf Manage Claw MCP server ownership (#102406)
* Manage Claw MCP server ownership

* test(claws): cover MCP resource lifecycle

* docs(claws): document MCP resources

* fix(claws): preserve lifecycle status contracts

* fix(claws): reconcile missing MCP removals

* fix(claws): recheck restored MCP before releasing provenance

* fix(claws): protect restored MCP identity

* refactor(claws): isolate MCP removal lifecycle

* fix(claws): export lifecycle status record

* style(claws): remove obsolete lifecycle lint exemption

* fix(claws): read MCP status from agent entries

* test(claws): clean MCP restack fixtures

* fix(claws): repair MCP state schema restack

* test(claws): remove stale MCP status import

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-07-22 08:37:44 -07:00
Gio Della-Libera 96e3051838 Manage Claw cron jobs through the gateway (#102383)
* Manage Claw cron jobs through the gateway

* test(claws): cover scheduled work lifecycle

* docs(claws): document scheduled work

* fix(claws): preserve modified cron jobs

* fix(claws): internalize cron gateway payloads

* fix(claws): make cron removal convergent

* style(claws): satisfy intermediate lifecycle lint

* refactor(claws): extract lifecycle state contracts

* test(claws): clean cron restack fixtures

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-07-22 08:04:54 -07:00
Pavan Kumar Gondhi ab2ad22533 fix: block cpp host env overrides (#112560) 2026-07-22 19:54:24 +05:30
Peter Steinberger 68d6c8ec8f refactor(sessions): remove gateway legacy JSON fallback (#112676) 2026-07-22 06:57:13 -07:00
Peter Steinberger 1a121da22c fix(onboarding): honor classic gateway options (#112396)
* fix(onboarding): honor classic gateway options

* test(wizard): type gateway setup mock

* docs(onboarding): document quickstart gateway flags

* chore(release): defer changelog entry
2026-07-22 06:47:57 -07:00
Peter Steinberger 685fb849bb fix(onboarding): recover expired wizard sessions (#112286)
* fix(onboarding): recover expired wizard sessions

* build(protocol): project expired wizard detail to Swift
2026-07-22 06:42:25 -07:00
Gio Della-Libera 6134fdfdcd Export installed agents as grouped Claw packages (#102306)
* Export installed agents as grouped Claw packages

* test(claws): cover exact agent export

* docs(claws): document agent export

* fix(claws): use current bounded file reader

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-07-22 06:40:29 -07:00
Peter Steinberger df3ff35277 refactor(state): move device auth tokens to SQLite (#112663)
* refactor(state): store device auth tokens in sqlite

* fix(state): keep device auth migration types acyclic

* fix(state): keep migration detection type private
2026-07-22 06:13:03 -07:00
Peter Steinberger cf2f591161 feat(sessions): permanent creator attribution, owner avatars, person filter, multi-user docs (#112658)
* feat(sessions): persist creator attribution

* feat(ui): add session creator filtering

* chore(sessions): refresh sqlite schema baseline

* docs(security): explain shared-agent trust

* fix(sessions): project catalog creator ownership

* fix(ui): restore startup JS budget headroom for creator attribution
2026-07-22 05:47:21 -07:00
Peter Steinberger c4fc4a70ee refactor(cloud-workers): collapse duplicated workspace conflict and quiescence paths (#112646)
1. Centralize conflict projection, supersession, cleanup, and settlement across live turns, recovery, and reclaim while keeping resume and reclaim terminal states explicit.
2. Reuse an entries-only changed-path helper for file and symlink staging.
3. Reuse the unchanged-branch reconcile preflight when no filesystem mutation occurred.
4. Move all quiescence scripts into one owner and share their process and lease engines. Deliberate micro-change: give quiesce processes() the same 2000 ms ps timeout added to renew by #112186.
5. Replace active-turn-claim message matching with ActiveTurnClaimError while preserving the message.
6. Document each staged-finalize stability and active-lease fence by its protected race.
7. Remove the unshipped locale-collated accepted-ref fallback and locale argv plumbing. Writer 8631832048 was replaced by canonical collation in 792f5b7b74e433f9471eed5abcb0fc334d28bdeb; git tag --contains returned no release tags for either commit.
2026-07-22 04:57:17 -07:00
Peter Steinberger 0c99a4e362 feat(ui): manage DM pairing requests in Channels (#112401)
* feat(ui): manage DM pairing requests

* fix(ui): clear pairing data across auth changes

* test(ui): tighten pairing page fixture type

* fix(gateway): complete pairing protocol contracts

* fix(ui): guard pairing mutations across epochs

* fix(ui): restore chat teardown gates

* fix(ui): isolate channel auth lifecycles

* fix(ui): remove stale chat view export
2026-07-22 04:54:20 -07:00
joshavant 6eea20ce18 fix(agents): finalize settled tool turns safely 2026-07-22 06:04:27 -05:00
joshavant c004cac6df fix(cron): finalize settled announce turns 2026-07-22 06:04:27 -05:00
joshavant 0ebcfc9bbf fix(agent): gate settled finalization by harness capability 2026-07-22 06:04:27 -05:00
joshavant 60f49dcc04 fix(agents): isolate settled-turn finalization 2026-07-22 06:04:27 -05:00