Peter Steinberger
4f715eb37b
docs: align classic onboarding setup flow ( #124712 )
...
* docs(onboarding): align classic setup flow
Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae
* docs(onboard): clarify import reset incompatibility
Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae
---------
Co-authored-by: Amp <amp@ampcode.com >
2026-08-16 21:15:39 -07:00
Pavan Kumar Gondhi
6e026c2fe3
fix(gateway): reject unattributable loopback proxy traffic [AI] ( #119950 )
...
* fix(gateway): bind auth limits to ingress attribution
* fix(gateway): close remaining ingress auth gaps
* fix(gateway): carry attribution into new ingress paths
* fix(gateway): close ingress ownership gaps
* fix(gateway): complete proxy ingress hardening
* fix(gateway): stabilize managed Tailscale ingress
* fix(gateway): make Tailscale cleanup ownership-safe
Refuse reset-on-exit publication until Tailscale exposes an atomic owner-bound cleanup operation, and migrate legacy configs with Doctor.
* fix(gateway): finish ingress ownership repair
* fix(gateway): own managed Tailscale route lifetime
Run managed Serve and Funnel routes as foreground claims tied to the Gateway lifecycle. Retire named Service config through Doctor because Tailscale Services cannot run in foreground mode.
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com >
* fix(gateway): align Tailscale consumers and build guards
Remove the retired named-service config from Telegram Mini App URL resolution and register the lifecycle worker as an explicit production entry.
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com >
* fix(gateway): preserve retired Tailscale inputs
Keep Funnel enabled when removing an ignored named-Service setting and accept the legacy positive reset flag as a no-op now that managed routes always follow Gateway lifetime.
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com >
* fix(gateway): preserve Tailscale route diagnostics
Prefer the actionable foreground CLI failure captured during timeout cleanup, and cover the original delayed-failure ordering.
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com >
* fix(gateway): reconcile Tailscale ingress with main
Preserve current ingress ownership contracts after the rebase, retire the obsolete device-auth migration check, validate route-owner IPC, and move Tailscale auth coverage onto the managed listener.
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com >
* fix(gateway): finish ingress rebase coverage
Unify the rebased net imports and let module-reset WebSocket tests prepare attribution through the same fresh module instance as the handler.
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com >
* test(gateway): align run-loop server fixture
---------
Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com >
2026-08-16 21:01:20 -07:00
Peter Steinberger
992a88b728
docs: cover groupScope in faq and security guide ( #125006 )
2026-08-16 20:28:27 -07:00
Peter Steinberger
462fe4d0e0
feat(agents): preserve create request provenance ( #124963 )
2026-08-16 19:18:28 -07:00
Peter Steinberger
6205cf3bb3
fix(cron): stop advertising inactive JSON defaults ( #124903 )
...
* fix(cron): make --json help match behavior
* fix(cron): preserve scratch write JSON output
* test(cli): classify cron JSON result commands
2026-08-16 17:32:49 -07:00
Peter Steinberger
572e9f907a
fix(skills): expand explicit references on agent turns ( #124784 )
...
* fix(skills): expand explicit references on agent turns
Route generic Gateway, CLI, webhook, and local agent turns through the same explicit skill-reference renderer as channel auto-replies. Keep original transcript text, preserve unknown slash behavior, and fail visibly for allowlist-hidden skills.
Maintainer review: scoped Option 1 — generic agent turns expand both $skill-name and leading /skill-name args through shared skill rendering; they do not run the channel command dispatcher, and all other slash commands retain their existing behavior.
* fix(skills): bound explicit reference prompts
* fix(skills): prefer allowed reference collisions
* fix(skills): preserve command invocation boundaries
* fix(skills): reject hidden channel slash commands
* perf(skills): skip literal dollar discovery
2026-08-16 16:09:21 -07:00
Peter Steinberger
6c66f48a7c
fix(cli): emit one JSON failure contract for --json invocations ( #124849 )
...
* fix(cli): unify JSON failure output
* test(cli): update skills verify failure envelope
2026-08-16 15:09:58 -07:00
Peter Steinberger
63a3a958f4
fix(browser): support Chrome Web Store native bootstrap ( #124775 )
...
* fix(browser): support Chrome Web Store native bootstrap
* chore: keep browser release note in PR body
* docs(browser): document Store identity trust boundary
* docs(browser): correct Store recovery guidance
2026-08-16 14:20:47 -07:00
Peter Steinberger
046a9ffdf4
fix(mcp): make Codex approval dead ends actionable ( #124766 )
...
* fix(mcp): make Codex approval dead ends actionable
* fix(mcp): preserve native approval fallback
* fix(mcp): configure saved approval modes
* fix(mcp): preserve saved Codex metadata
* style(mcp): simplify saved metadata spread
2026-08-16 14:00:08 -07:00
Peter Steinberger
d5db5854fe
fix(cli): explain empty directory lookups ( #124753 )
...
* fix(cli): explain empty directory lookups instead of printing nothing
* fix(cli): distinguish unsupported self lookups
2026-08-16 12:39:36 -07:00
Peter Steinberger
ebe7af218c
fix(cli): allow hook toggles to select an agent ( #124761 )
2026-08-16 12:11:44 -07:00
Peter Steinberger
57ebd20566
fix(cli): fail absent service start and restart ( #124711 )
...
* fix(cli): fail uninstalled service mutations
Treat Gateway and Node start/restart as failures when no managed service is installed, while preserving absent-service stop as an idempotent success.
* docs(cli): clarify gateway restart recovery
2026-08-16 11:38:45 -07:00
Peter Steinberger
15a01bcc5e
fix(sessions): reject invalid explicit store paths ( #124515 )
...
* fix(sessions): validate operator-supplied store paths
* fix(sessions): preserve legacy store selectors
* style(sessions): avoid unchecked store assertions
* fix(sessions): keep store errors concise
* chore(sessions): document SQLite schema probe
2026-08-16 03:06:43 -07:00
Jason (Json)
5f1bbed42d
fix(doctor): report missing managed local embedding setup ( #123575 )
...
* fix(gateway): expose startup blockers before cutover
* fix(gateway): include session blockers in preflight
* fix(gateway): keep preflight finding type private
* fix(gateway): preflight startup auth blockers
* fix(gateway): complete startup preflight readiness
* fix(llama-cpp): keep preflight remediation private
* fix(gateway): keep preflight passive and activation-aware
* fix(gateway): apply startup guard in preflight
* fix(gateway): align auth mode preflight
* fix(gateway): keep preflight state reads isolated
Share the read-only inspection snapshot scope across duplicated runtime chunks so blocked gateway preflight remains non-mutating when bundled provider artifacts read canonical state.
* fix(gateway): keep startup preflight passive
* fix(gateway): ignore inactive embedding owner shadows
* fix(gateway): preserve startup preflight parity
* fix(llama-cpp): keep cache inspection types private
* fix(gateway): close startup preflight parity gaps
* fix(gateway): handle uninitialized memory databases
* test(gateway): observe shell fallback portably
* fix(llama-cpp): normalize embedding model paths
* refactor(gateway): drop broad startup preflight surface
* fix(doctor): report missing managed local embedding setup
* style(memory): simplify setup enablement check
* fix(memory): keep diagnostic result type private
* fix(memory): inspect local setup with remote secret refs
* fix(memory): keep doctor index inspection immutable
* fix(memory): make readiness inspection owner-aware
* fix(doctor): mirror memory slot allowlist policy
* test(doctor): use canonical memory slot id
* fix(doctor): normalize memory provider ids
* fix(doctor): resolve external embedding readiness owner
* fix(plugins): keep embedding inspection result internal
* fix(doctor): isolate plugin state during lint
* fix(doctor): route lint metadata through snapshot
* fix(cli): keep doctor lint startup source-only
* fix(cli): keep doctor lint compile-cache free
* fix(doctor): keep local embedding readiness opt-in
* test(doctor): preserve plugin artifact roots during lint
* fix(doctor): refresh memory readiness registration
* test(doctor): type nullable provider policy mock
* fix(doctor): scope lint state snapshot to provider check
* fix(doctor): isolate selected plugin state checks
* test(doctor): restore only scoped environment
* fix(doctor): defer readiness state inspection
* fix(doctor): keep deferred config reads isolated
* fix(doctor): keep plugin state mode internal
* fix(config): preserve default plugin validation
2026-08-15 20:15:06 -06:00
Pavan Kumar Gondhi
8668aeb969
fix(discord): bind transcript capture to source account [AI] ( #118579 )
...
* fix(discord): bind transcript capture to source account
* style(agents): keep transcript tool wiring compact
* fix(transcripts): declare account binding channels
* fix(transcripts): report effective capture account
* fix(transcripts): enforce account lifecycle ownership
* fix(transcripts): preserve cross-surface control
* fix(copilot): preserve transcript channel context
* fix(transcripts): fail closed for legacy channel owners
* fix(transcripts): add trusted legacy recovery
* fix(transcripts): preserve auto-start cleanup ownership
* fix(transcripts): reject untrusted account starts
* fix(transcripts): keep persisted ownership authoritative
* fix(transcripts): harden legacy recovery
* fix(transcripts): preserve agent ownership boundary
* fix(transcripts): scope account binding to source channel
* fix(transcripts): preserve unattributed owner isolation
* fix(transcripts): own configured captures by account
* docs(plugins): clarify transcript auto-start ownership
* test(transcripts): cover account-less recovery
* docs(transcripts): scope legacy recovery by provider
* fix(discord): reuse eligible account ordering for transcripts
* test(discord): use neutral transcript account fixtures
* fix(transcripts): keep accountless recovery local
* fix(discord): resolve transcript accounts by voice capability
* fix(transcripts): bound account resolution failures
* fix(transcripts): bound account tool output
* fix(transcripts): honor unresolved provider accounts
* fix(transcripts): preserve binding when providers are missing
* fix(transcripts): fail closed on unknown binding provenance
* fix(transcripts): qualify account lifecycle capability
* fix(transcripts): normalize provable legacy owners
* fix(transcripts): bind scheduled capture to caller authority
* fix(transcripts): preserve scheduled caller identity tuple
* fix(transcripts): preserve channel-less scheduled authority
* fix(plugin-sdk): publish transcript provider types
* fix(transcripts): use exact lifecycle ownership tokens
* fix(transcripts): preserve local ownerless lifecycle access
* fix(transcripts): allow local configured capture control
* fix(transcripts): preserve scheduled caller channel
* fix(transcripts): retain named-agent legacy recovery
* fix(transcripts): deny unrelated remote channels
* fix(doctor): validate transcript owner inference
* fix(transcripts): restrict legacy remote recovery
* fix(ci): align transcript Doctor checks
* fix(transcripts): require Doctor-owned legacy metadata
* fix(transcripts): reject unowned remote capture starts
* fix(transcripts): reject unbound Discord lifecycle calls
* fix(transcripts): distinguish legacy owner rows
* test(discord): keep unavailable account fixture typed
* fix(transcripts): mark current imports for Doctor
* fix(transcripts): complete account ownership validation
* fix(discord): restore transcript package boundary
* fix(discord): preserve bundled transcript entry boundary
* docs(transcripts): clarify Discord auto-start account
* fix(transcripts): bind account-owned imports
* fix: preserve transcript and cron policy state
* fix(cron): preserve scheduled transcript authority
* fix(discord): keep legacy transcript rows local
* fix(transcripts): narrow account ownership boundary
* fix(transcripts): preserve trusted caller ownership
* fix(discord): enforce transcript source authorization
* fix(ci): bound Control UI gzip build variance
* test(qa): align transcript scenario contracts
* fix(agents): repair rebased caller context
* fix(discord): restore rebased account ownership
* test(discord): restore voice account fixtures
---------
Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com >
2026-08-15 12:10:43 -07:00
Josh Lehman
56798ae085
fix(cli): accept inherited flags after nested subcommands ( #116587 )
...
* fix(cli): accept auth agent flag after subcommands
* openclaw-87a: normalize inherited skills options
* test(cli): classify curator leaf JSON flags
* test(cli): cover all auth agent leaves
2026-08-15 09:52:24 -07:00
Peter Steinberger
124847928d
fix(cli): name the agent escapes each command supports ( #124018 )
...
* fix(cli): name supported agent selection escapes
* refactor(cli): keep selection context compact
* fix(cli): preserve caught selection errors
2026-08-14 21:58:11 -07:00
Peter Steinberger
6e5bf3ec55
fix(doctor): stop false failures on multi-agent profiles ( #124010 )
...
* fix(doctor): resolve multi-agent health owners
* fix(doctor): keep bare json exit advisory
2026-08-14 21:45:55 -07:00
Gio Della-Libera
103e1a4cc9
fix(claws): recover lifecycle state safely ( #123254 )
...
* fix(claws): preserve runtime lifecycle state
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: 34377cd6-beac-4e49-8ab0-22cfaf8b54a5
* fix(claws): harden lifecycle reconciliation
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: 34377cd6-beac-4e49-8ab0-22cfaf8b54a5
* fix(mcp): serialize ownership mutations
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: 34377cd6-beac-4e49-8ab0-22cfaf8b54a5
* test(mcp): prove lifecycle lease ordering
* fix(claws): page cron recovery inventory
* fix(claws): fail closed on missing cron ownership
* refactor(claws): keep pending cron recovery unchanged
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Co-authored-by: Gio Della-Libera <235387111+giodl73-repo@users.noreply.github.com >
Copilot-Session: 34377cd6-beac-4e49-8ab0-22cfaf8b54a5
2026-08-14 20:52:45 -07:00
Peter Steinberger
d8cd661517
fix(gateway): keep supervised restarts from migrating live state ( #123920 )
...
* fix(gateway): fence supervised restart schema ownership
* fix(gateway): target supervised safe restarts
* chore: leave changelog to release automation
* fix(gateway): satisfy restart control checks
2026-08-14 19:31:15 -07:00
Peter Steinberger
156af00a78
fix(memory): report truthful index outcomes ( #123863 )
2026-08-14 17:17:16 -07:00
Dallin Romney
a01d40bfb9
fix(sessions): honor total entry cap with protected history ( #123081 )
...
* fix(sessions): count protected rows toward entry cap
* perf(sessions): defer maintenance snapshot loading
* test(sessions): assert total maintenance cap
* fix(sessions): align warning preservation
* fix(sessions): guard malformed maintenance rows
2026-08-15 08:03:57 +08:00
Peter Steinberger
72e67904be
fix(cli): infer provider lists respect selected agent ( #123884 )
...
* fix(cli): require inference provider owners
* test(cli): type provider owner fixtures
* chore: leave infer release note to release
2026-08-14 16:45:37 -07:00
Peter Steinberger
bd1814bede
fix(policy): require --agent for explicit workspaces ( #123880 )
...
* fix(policy): require explicit CLI agent owner
* chore(policy): leave release notes to release flow
2026-08-14 16:15:17 -07:00
Peter Steinberger
1c055ba5e5
fix(cli): preserve explicit read-only agent targets ( #123868 )
...
* fix(cli): preserve explicit read-only agent targets
* chore: leave release changelog to release flow
2026-08-14 15:39:24 -07:00
Peter Steinberger
1b98bc35a0
fix(onboard): stop failing intentionally unstarted gateway ( #123857 )
2026-08-14 14:59:54 -07:00
Peter Steinberger
d5c194f4ea
fix(status): keep explicit fleets ownerless in diagnostics ( #123831 )
...
* fix(status): preserve explicit agent ownership
* chore: leave status notes to release
* style(status): format reconciled imports
2026-08-14 14:54:52 -07:00
Peter Steinberger
b3f1cd36db
fix(status): keep multi-agent diagnostics owner-safe ( #123826 )
...
* fix(status): preserve explicit multi-agent inventory ownership
* chore: leave changelog to release automation
2026-08-14 14:10:23 -07:00
Jesse Merhi
bf40269cb7
feat(security): require acknowledgement for policy warnings ( #116489 )
2026-08-15 03:58:45 +10:00
Josh Avant
97a53a9b35
feat: audit admitted channel participant identity ( #122863 )
...
* feat: audit admitted channel participant identity
* fix: preserve Telegram identity through thread recovery
* fix: signal held gateway process groups
* fix: keep audit evidence passive in collect routing
* fix: validate copied channel participant evidence
* fix: bind channel participant evidence to host ingress
* fix: honor Telegram proof credential roles
* fix: restart held Telegram proof through gateway
* fix: repair channel identity CI regressions
* test(matrix): bind thread routing owner
* fix: preserve direct DM SDK compatibility
* fix: bind channel provenance at host runtime
* test(feishu): provide channel context builder
* fix: defer record-bound channel runtime resolution
* fix: keep channel admission evidence core-private
* fix(audit): bind channel admission to plugin lifecycle
* fix(audit): bind ingress provenance to final context
* refactor(audit): split admission scope keys
* test(queue): cover combined metadata carriers
* refactor(audit): keep lifecycle helpers private
* fix(queue): preserve combined turn authority
* test(channels): provide ingress context builders
* test(channels): align integrated CI fixtures
* test(clickclack): resolve model-loop ingress
* docs: preserve channel participant evidence invariant
2026-08-14 08:57:01 -05:00
Peter Steinberger
ad6bc6d3ae
fix(delivery): keep failed queue rows payload-free ( #123642 )
...
* refactor(delivery): collapse failed-row lifecycle
Replace the unshipped failure-operations platform with payload-free terminal receipts owned by existing queue boundaries. Keep bounded/permanent idempotency only for reusable or crash-ambiguous producers, move physical expiry to queue maintenance, and preserve migration and media-cleanup safety.\n\nTogether with #123410 , production code is net negative by 11 lines; tests, docs, and generated protocol mirrors are accounted separately.
* fix(delivery): break state DB import cycle
* fix(delivery): classify SQLite boundary uses
* test(gateway): mark retained health fixture
2026-08-14 06:22:51 -07:00
Peter Steinberger
e6eebc5ad8
feat(agents): un-reserve literal main ( #123609 )
...
* feat(agents): un-reserve literal main
* fix(agents): scan legacy sessions before reusing main
2026-08-14 04:23:19 -07:00
Peter Steinberger
2a77e6e5a0
feat(onboard): named first agent ( #123521 )
...
* feat(onboard): named first agent
* fix(onboard): harden named-agent handoff
* test(onboard): preserve authored roster provenance
* test(gateway): restore authorized steering coverage
* fix(onboard): report imported roster name conflicts
2026-08-14 02:54:55 -07:00
Peter Steinberger
65597f93b0
fix: restore default-profile backup archives ( #123504 )
...
* fix(backup): make default-profile backups restorable
* fix(backup): preserve restore cleanup context
* refactor(backup): drop preserve-caught-error suppression via hoisted cleanup error
* refactor(backup): hoist restore failure handling out of catch scopes
2026-08-14 01:39:08 -07:00
Peter Steinberger
2ef92d0bbe
feat: cookie sync from Mac to a remote Gateway browser profile ( #123494 )
...
* feat(browser): sync system cookies to a remote gateway profile
Add `openclaw browser cookie-sync`: decrypt allowlisted macOS Chrome-family
cookies locally and push them into a managed profile on a possibly-remote
Gateway over the existing operator channel. --watch re-syncs on cookie-DB
changes with a single Keychain prompt per session.
- New POST /cookies/set-many batch route (mirrors /cookies/set)
- Extract one canonical readSystemProfileCookies reused by import + sync
- Mandatory domain allowlist (never syncs an unrestricted cookie jar)
- Decryption stays host-local (macOS); no cookie values are logged
* feat(macos): cookie sync checkbox and configuration UI
Add an off-by-default 'Cookie sync' section (Settings > General): a toggle, an
editable domain allowlist editor, and a target-profile field, actionable only in
remote-gateway mode. CookieSyncManager supervises `openclaw browser cookie-sync
--watch` against the connected Gateway when enabled, resolving a LOCAL CLI (never
the SSH-redirect path, since decryption is host-local) and injecting gateway
URL + token/password via environment, never argv. A status row surfaces
running/stopped/error and the last sync summary.
* fix(macos): satisfy cookie sync lint gates
* chore(i18n): register cookie sync native source strings
Regenerate apps/.i18n/native-source.json baseline for the new macOS Cookie
sync settings strings (additive only). Satisfies the native:i18n:verify gate;
generated locale artifacts are refreshed separately by the locale-refresh job.
2026-08-13 23:47:26 -07:00
Peter Steinberger
7026cf2f21
fix(delivery): bound failed-row retention lifecycle ( #123410 )
2026-08-13 22:03:33 -07:00
Peter Steinberger
b9c6789560
feat(secrets): authenticated egress substitution proxy with destination binding ( #123216 )
...
* feat(secrets): add authenticated egress substitution proxy
* feat(secrets): bind egress substitution to hosts
* ci(codeql): classify egress proxy bypass tunnel in network boundary query
* refactor(proxy-capture): use the canonical IP parser instead of node:net
* fix(secrets): compare proxy tokens with a process-keyed MAC
2026-08-13 20:49:31 -07:00
Peter Steinberger
d2dad76ecd
feat(doctor): relocate shared auth store into state DB ( #123349 )
...
* feat(doctor): relocate shared auth store into state DB
* fix(doctor): make shared auth relocation crash-safe
* fix(doctor): skip disabled shared auth inspection
* fix(doctor): break shared auth migration cycle
* fix(doctor): remove unused migration type export
* fix(test): remove duplicate Codex attempt shard
2026-08-13 17:44:02 -07:00
Peter Steinberger
b233ea7957
fix(health): surface blocked ingress lanes ( #123234 )
2026-08-13 12:44:59 -07:00
Peter Steinberger
8e0f464a5f
fix(gateway): suppress ambient channel auto-enable ( #123174 )
2026-08-13 11:20:40 -07:00
Dallin Romney
4afccbdaa4
fix(sessions): exclude protected sessions from entry cap ( #123014 )
2026-08-13 15:42:55 +08:00
Peter Steinberger
e45a9460ce
docs: repair spellcheck and anchor drift ( #122960 )
...
* docs: repair spellcheck and anchor drift
* docs: satisfy markdown anchor lint
2026-08-12 20:50:56 -07:00
Peter Steinberger
d2628e430c
fix(cli): avoid restart hint for unchanged config ( #122953 )
...
* fix(cli): avoid restart hint for unchanged config
* docs(cli): clarify no-op restart guidance
2026-08-12 20:40:30 -07:00
Peter Steinberger
6076efc968
docs(gateway): clarify dynamic operator scopes ( #122931 )
2026-08-12 19:23:54 -07:00
Jacqueline Henriksen
800328f14e
feat(cli): allow editing automation display names ( #122702 )
...
* feat(cli): allow editing automation display names
* feat(cli): allow clearing automation display names
2026-08-12 17:15:21 -07:00
Peter Steinberger
08b134324f
feat: continue web sessions in the terminal ( #122870 )
...
* feat: continue sessions in terminal
Add a credential-free Control UI continuation command and allow openclaw resume to reuse current-profile authentication only for byte-exact configured Gateway targets.
* fix(gateway): separate public origin TLS ownership
Allow exact public-origin resume targets to reuse local authentication without inheriting the direct local listener certificate fingerprint.
* fix(gateway): scope exact targets to gateway mode
Prevent remote profiles from reusing dormant local Gateway authentication for explicit loopback or public-origin targets.
* fix(cli): encode terminal resume handoffs
Replace shell-specific quoting with a strict credential-free base64url handoff, gate configured auth reuse to validated handoffs, and skip unused session discovery.
* fix(gateway): isolate handoff auth identity
Suppress ambient Gateway auth fallback for validated handoffs while preserving explicit credentials, configured SecretRefs, stored device auth, and exact-target TLS ownership.
* fix(cli): harden terminal resume handoffs
* fix(cli): parse terminal handoff outcomes
* fix(cli): bind handoffs to resolved agent
* test(ui): align terminal continuation proof
* docs(plan): track terminal continuation
* refactor(ui): keep terminal handoff result local
2026-08-12 17:07:48 -07:00
Gio Della-Libera
1ec4e4582e
fix(claws): freeze installed tool profile authority ( #121327 )
...
* fix(claws): freeze installed tool profile authority
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): normalize consent helper file modes
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): preserve consented tool authority
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): normalize source file modes
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): allowlist runtime provenance probe
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): close consent review gaps
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* docs(claws): require concrete frozen tool grants
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): reject dynamic MCP selectors
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): type profile resolution at parse boundary
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): preserve bounded update authority
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): prepare consent provenance at config load
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): isolate consent provenance failures
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): keep runtime grants inside consent
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): own consent cache in state lifecycle
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): guide legacy full profile repair
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): keep consent cache internals private
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): satisfy strict consent cache types
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): fail closed when state cache closes
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): integrate consent cache with state owner
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): fail closed before consent state opens
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): resume legacy v1 profile installs
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(claws): isolate legacy resume regression
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): follow tool policy normalizer rename
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): bind runtime consent to agent config
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): normalize digest helper mode
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): drop stale digest helper import
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(runtime): keep snapshot mocks complete
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): retain bounded legacy profile plans
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): verify ownership before runtime consent
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(claws): remove stale runtime import
* fix(claws): drop stale add import
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): resume failed v1 promotion
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(claws): codify cold-state authority fence
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(plugin-sdk): refresh API baseline
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
---------
Co-authored-by: Gio Della-Libera <235387111+giodl73-repo@users.noreply.github.com >
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
2026-08-12 11:37:04 -07:00
Peter Steinberger
e69a973bfb
feat(backup): add whole-archive restore into a fresh staging directory ( #122750 )
...
* feat(backup): add whole-archive restore into a fresh staging directory
Verify-first extraction with fresh-target and live-state-dir guards,
cleanup on failure, and explicit rollback warnings (ratchet-bearing
channel credentials, approvals, delivery state). Activation stays an
explicit operator step.
* fix(cli): sync backup catalog description with registered command
2026-08-12 18:03:28 +00:00
Peter Steinberger
99d662473c
fix(channels): fail-fast headless channel setup with plugin-declared env contracts ( #122530 )
...
* fix(channels): validate headless channel setup
* docs(channels): document headless provisioning
* fix(channels): repair setup metadata typing
* chore(channels): regenerate official channel catalog for env metadata
* fix(slack): keep mode-conditional env contract plugin-owned
Static --use-env declaration keeps only the unconditional SLACK_BOT_TOKEN;
socket-vs-HTTP conditional requirements (app token, signing secret) stay in
Slack's own setup validation so HTTP mode no longer demands an irrelevant
SLACK_APP_TOKEN.
* chore(sdk): regenerate api baselines and catalog after rebase
* fix(slack): align manifest env declaration with runtime contract
* chore(sdk): regenerate api baselines after rebase
* chore(sdk): regenerate api baselines after rebase
* chore(sdk): regenerate api baselines after rebase
2026-08-12 17:12:15 +00:00
Peter Steinberger
6093e3477d
fix(cli): make doctor --json imply read-only lint mode ( #122662 )
...
* fix(cli): make doctor json imply lint
* fix(cli): preserve doctor session selector errors
2026-08-12 09:04:51 -07:00