Sliverp
84c7d45f15
refactor(qqbot): install plugin from Tencent package ( #107295 )
...
* refactor(qqbot): remove bundled extension source
Mechanical deletion half of the #107295 squashed rebase; the catalog
repoint and host integration land in the follow-up commit.
Co-authored-by: sliverp <870080352@qq.com >
* refactor(qqbot): install plugin from Tencent package
Squashed rebase of #107295 onto current main. Repoints the official
external channel catalog at @tencent-connect/openclaw-qqbot@2.0.1 and
adapts onboarding, doctor migrations, secrets, build guards, and tests.
Documents the known limitation that the external package does not
support structured SecretRef clientSecret values; operators move those
to QQBOT_CLIENT_SECRET or clientSecretFile before upgrading.
Co-authored-by: sliverp <870080352@qq.com >
* fix(doctor): reuse shared hasOwnKey record helper
The rebased QQBot migration carried its own hasOwnKey export, colliding
with the one main now ships in legacy-config-record-shared.ts.
Co-authored-by: sliverp <870080352@qq.com >
* fix(plugins): carry catalog integrity through the update bridge
The externalized-bundled-plugin bridge dropped the official catalog's
expectedIntegrity pin, so bundled-user updates installed the external
npm package without integrity verification. The bridge now carries the
pin for the catalog's exact npm spec and both bridge install calls pass
it through; update-channel spec overrides intentionally skip the pin
since it only covers the pinned version.
Co-authored-by: sliverp <870080352@qq.com >
* chore(plugin-sdk): refresh per-entrypoint API baselines
The QQBot compat export and bundled-type removal shift 26 entrypoint
closure hashes in the new split baseline layout.
Co-authored-by: sliverp <870080352@qq.com >
* refactor(qqbot): drop helper reintroduced during rebase
Main's coercion consolidation added this file after the deletion
commit's base; its only consumers were the removed qqbot sources.
Co-authored-by: sliverp <870080352@qq.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-08-11 15:10:27 -07:00
Josh Lehman
d035dba6c7
chore: scope SQLite session lifecycle CI ( #121917 )
...
* oc-358: scope SQLite lifecycle CI
* chore(ci): cover shared session lifecycle owner
2026-08-11 15:06:46 -07:00
Vincent Koc
653ab3b2aa
fix(ci): restore duplicate scans with jscpd 5 ( #122124 )
2026-08-12 01:39:40 +08:00
Peter Steinberger
cad77fb39c
refactor: consolidate remaining coercion helpers ( #122020 )
2026-08-11 10:22:01 -07:00
Vincent Koc
afc644464d
fix(ci): bound hosted Android build memory ( #122088 )
2026-08-11 23:57:22 +08:00
Vincent Koc
6472d22a77
fix(ci): budget expanded survivor groups ( #122058 )
2026-08-11 22:44:21 +08:00
Peter Steinberger
8dace97c2e
perf(test): cut workflow guard overhead ( #122038 )
...
Co-authored-by: Amp <amp@ampcode.com >
2026-08-11 06:29:08 -07:00
Vincent Koc
0f6885141b
fix(ci): use Node 24.16 for release workflows ( #121967 )
2026-08-11 17:11:35 +08:00
Peter Steinberger
2b8dbc3a7b
refactor(agents): split message-tool into concept modules ( #121901 )
...
* refactor(agents): split message-tool into concept modules
* fix(agents): restore message-tool split imports
* ci: preserve message-tool CodeQL boundary
2026-08-11 00:31:14 -07:00
Peter Steinberger
fa03d9b913
refactor: consolidate coercion helpers ( #121366 )
...
* refactor: consolidate coercion helpers
* fix: remove duplicate coercion imports
* fix: preserve serialized coercion guard
* chore: ratchet coercion helper carve-outs
* fix(test): keep gauntlet subprocess startup lean
* fix: preserve imported session timestamp semantics
* fix: preserve catalog timestamp string semantics
* chore: align plugin SDK surface ratchet
* fix: preserve trajectory and SDK string contracts
* fix(test): preserve QA record assertion semantics
* fix: complete standalone record guard rename
* refactor(cron): use canonical string coercion
* fix(acpx): preserve Pi timestamp parsing
* test(channels): adapt custody test harnesses
* test(telegram): classify media harness as test support
* test(acpx): split timestamp contract coverage
* test(channels): support generated custody contracts
* chore: ban the full coercion helper name set
Extends the declaration guard to all eleven consolidated helper names and
renames the cron schedule-identity readNumber wrapper to readScheduleInteger
so the banned generic name cannot regrow.
* fix(scripts): repair release-validation guard drift and lint cause
Restores the renamed isJsonRecord guard in assertTrustedWorkflowHarness after
main added isRecord call sites in parallel, and attaches the caught YAML error
as the thrown error cause (preserve-caught-error was red on main).
* fix: preserve Claude timestamp string semantics
* fix: preserve persisted timestamp string semantics
* fix: preserve date-first timestamp contracts
* fix(openai): harden delegation failure formatting
* chore: close coercion helper guard gaps
* test(openai): model non-error delegation rejection
* chore: refresh plugin SDK API contract
* fix(tasks): use canonical string field reader
* fix(ai): use canonical provider error field coercion
* fix(browser): migrate native bootstrap coercion
* docs(plugin-sdk): clarify text record export compatibility
* fix(gateway): normalize approval execution identity
* test(outbound): isolate message action poll harness
2026-08-11 00:02:18 -07:00
Vincent Koc
6dbea69515
fix(ci): separate frozen target context from candidate identity ( #121835 )
2026-08-11 12:14:19 +08:00
Peter Steinberger
ebfd3ba154
improve: cut CI critical path without more workers ( #121807 )
...
* test(ci): remove redundant builds from critical path
Amp-Thread-ID: https://ampcode.com/threads/T-019fee8d-665d-707b-a380-23f2a6a1ce03
Co-authored-by: Peter Steinberger <steipete@gmail.com >
* docs(ci): format runner table
Amp-Thread-ID: https://ampcode.com/threads/T-019fee8d-665d-707b-a380-23f2a6a1ce03
Co-authored-by: Peter Steinberger <steipete@gmail.com >
---------
Co-authored-by: Amp <amp@ampcode.com >
2026-08-10 20:21:20 -07:00
Vincent Koc
c87f77185d
fix(release): preserve frozen candidate identity ( #121786 )
...
* commit 'c3e3f276f2b520ffdf28e453eb464a6f4e50dfa0':
fix(release): preserve frozen candidate identity
2026-08-11 11:08:13 +08:00
Vincent Koc
c3e3f276f2
fix(release): preserve frozen candidate identity
2026-08-11 10:48:08 +08:00
Peter Steinberger
fada067277
feat(browser): add zero-click Chrome extension bootstrap ( #121586 )
...
* feat(browser): add zero-click extension bootstrap
Pre-register deterministic path-derived extension IDs and install a strict native messaging host.
Keep the popup and options UI minimal while removing the obsolete copilot and page-share flows.
* fix(browser): satisfy native bootstrap CI guards
* test(browser): isolate native bootstrap Chrome roots
* test(browser): flush native bootstrap profile before status
* test(browser): seed Linux native bootstrap identity
* fix(browser): preserve native bootstrap upgrade safety
Allow immutable root-owned package inputs while keeping mutable state, manifests, and launchers user-owned. Preserve all retired copilot keys whenever active or unrecognized recovery custody remains.
* fix(browser): preserve pending copilot custody
Retired cleanup now removes copilot state only when the durable registry is exactly empty. Any session, archive, malformed value, future shape, or read failure preserves every retired key.
* fix(browser): guard native bootstrap upgrades
Fail closed while retired copilot custody remains and make discard durable across partial failures.
Require exact launcher-embedded origins and repair full launcher drift without accepting mismatched registrations.
* fix(browser): remove stale layout export
* chore(release): leave changelog to release flow
2026-08-10 19:31:13 -07:00
Josh Avant
bdd35432dd
perf(checks): accelerate fresh changed gates ( #121805 )
2026-08-10 21:30:24 -05:00
Patrick Erichsen
abb856ece4
fix(release): restore frozen beta validation ( #121791 )
...
Punchcard-Session: coral-summit-brook-8j
2026-08-10 18:45:42 -07:00
Vincent Koc
7e03fe3ba0
Merge commit '546bb29055b3e204b981dc27d4375c4d7679c7dd' into HEAD
...
* commit '546bb29055b3e204b981dc27d4375c4d7679c7dd':
fix(release): support frozen validation tooling
2026-08-11 07:34:47 +08:00
Vincent Koc
546bb29055
fix(release): support frozen validation tooling
2026-08-11 07:20:44 +08:00
Patrick Erichsen
c6b9be2646
fix(release): run plugin tooling against source checkout ( #121762 )
2026-08-10 16:16:33 -07:00
Peter Steinberger
3cd034f7a8
fix(ci): release workflow checks fail on macOS Bash 3.2 ( #121669 )
...
* fix(ci): keep release workflow checks portable on macOS
* fix(ci): repair current main compact shard regressions
* fix(ci): repair latest main validation drift
* fix(approvals): restore native account ownership gates
* fix(ci): repair skill workshop validation drift
* fix(ci): align approval route selection with main
* fix(ci): remove stale skill workshop test exports
* fix(ci): align repairs with latest main
2026-08-10 16:11:53 -07:00
Martin Cleary
e0a4146f55
fix(ci): carry branch authority to ClawSweeper ( #121674 )
...
Co-authored-by: brokemac79 <255583030+brokemac79@users.noreply.github.com >
2026-08-10 22:50:44 +01:00
Patrick Erichsen
105038e658
ci: mirror Docker release images to Vercel registry ( #120058 )
...
* ci: publish release images to Vercel registry
* ci: publish beta images to Vercel registry
* fix(ci): allow beta Vercel dispatch
* fix(ci): publish VCR-compatible image indexes
* fix(ci): allow VCR readiness propagation
* fix(ci): use Sandbox as VCR readiness proof
* fix(ci): promote clean VCR channel indexes
* fix(release): harden VCR publication
* fix(release): bind VCR publishing to verified inputs
* fix(test): follow script declaration migration
* fix(release): isolate VCR mirroring
* test(release): align VCR secret ownership
2026-08-10 14:45:05 -07:00
Peter Steinberger
25a9a2e020
fix(ci): guard empty QA-live filter token join in release checks
...
An all-QA live_suite_filter leaves repo_filter_tokens empty; joining the
empty array under set -u aborts the scheduling script on bash <4.4.
Default the expansion and update the workflow-content assertion.
2026-08-10 09:35:51 -07:00
Vincent Koc
1f591bba56
fix(release): bound validation retries and soak
2026-08-10 22:31:32 +08:00
Vincent Koc
a994d2ad5f
fix(qa): provide protocol base to evidence runs ( #120710 )
...
Co-authored-by: Dallin Romney <6581799+RomneyDa@users.noreply.github.com >
Punchcard-Session: amber-workshop-workshop-36
2026-08-10 16:59:58 +08:00
Vincent Koc
f4987deb94
fix(ci): support frozen validation scripts ( #121458 )
2026-08-10 14:49:51 +08:00
Peter Steinberger
eb9cac065f
fix(security): unify secret-redaction and SSRF policy ownership ( #121335 )
...
* fix(security): unify secret-redaction and SSRF policy ownership
Memory-host errors now redact through the canonical redactor (payment/card/CVV
coverage included) via the existing core facade instead of a stale local
pattern table; ACP error redaction is wired through a single barrel so the
injected canonical redactor no longer depends on module load order, and the
acp-core fallback table shrinks to the minimal standalone set (structured
auth-header patterns proven load-bearing stay). The memory-host SsrFPolicy
structural copy is deleted in favor of the canonical src/infra/net/ssrf.ts
type re-exported through the network facade.
* fix(build): keep memory-core doctor closure execa-free
Import the canonical redactor directly from src/logging/redact.js instead of
the openclaw-runtime-io facade (which reaches execa through the full runtime
graph), and regenerate the plugin SDK API baseline for the intentional
canonical-SsrFPolicy surface change.
* fix(security): merge operator redact patterns with defaults in injected redactors
ClawSweeper found that ACP injected the general redactor, where nonempty logging.redactPatterns replace the built-in provider-token patterns. Use the tool-payload redactor for ACP and memory-host error formatting so operator patterns extend defaults and redaction remains forced for these security boundaries.
2026-08-09 22:40:58 -07:00
Peter Steinberger
3156b67708
ci(labeler): fix dead rules, cover all plugin dirs, drop vendored artifacts ( #121348 )
...
* ci(labeler): fix dead rules and cover unlabeled plugin dirs
* chore: drop vendored swabble workflow and empty ActivityWidget asset catalog
2026-08-09 22:28:02 -07:00
Peter Steinberger
ff10db092b
ci(mantis): extract shared request-resolution, ref-trust, and reaction workflows ( #121339 )
...
* ci(mantis): extract shared request, trust, and reaction workflows
* ci(mantis): drop caller-less params from shared resolve workflow
* test(mantis): read candidate-override parsing from shared resolve workflow
2026-08-09 22:04:27 -07:00
Peter Steinberger
f44c5e2e5e
fix(plugins): surface manifest-only bundled capabilities ( #121354 )
...
Use a manifest-first inventory with independent coverage for manifest-only bundled capabilities.
Retire the undocumented thread-ownership plugin while Doctor removes stale references.
Document Talk voice and persist only provider-scoped voice selection.
Closes #121353
2026-08-09 19:43:49 -07:00
Peter Steinberger
88fc335323
fix(ci): support frozen script entrypoints ( #121208 )
...
* fix(ci): support frozen script entrypoints
* fix(ci): route frozen plugin tests through package script
* fix(release): support compiled candidate test helpers
* fix(release): support compiled upgrade helpers
* fix(release): mount trusted upgrade runtime
* fix(release): preserve trusted tsx resolution
2026-08-10 10:31:21 +08:00
Peter Steinberger
64695e5024
chore: detect export name collisions ( #121300 )
...
* chore(scripts): add export-name-collision check with debt baseline
* chore(scripts): allowlist per-module test-hook export idiom
* chore(scripts): recognize const forwarders, harness files, and JS sources in collision check
2026-08-09 18:58:28 -07:00
Peter Steinberger
0ef798d28d
fix(gateway): keep hello authorization aligned with RPC access ( #120888 )
...
* fix(gateway): separate socket and device token scopes
* chore(i18n): refresh native source baseline
* style(ios): keep gateway channel within lint limit
* refactor(gateway): simplify scope metadata decoding
* ci(ui): isolate real-gateway e2e suites
* docs(ci): align runner table formatting
* chore(plugin-sdk): refresh api baseline
* ci(ui): route real-gateway retries to hosted runners
* chore(plugin-sdk): repair generated api baseline
* test(ui): select Labs toggles by title
* fix(gateway): preserve stored scopes without wire metadata
2026-08-09 14:50:07 -07:00
Peter Steinberger
a828bfe04e
fix(release): bootstrap typed Docker planner ( #121088 )
...
* fix(release): bootstrap typed Docker planner
* test(release): handle optional workflow steps
* fix(release): isolate trusted planner dependencies
Punchcard-Session: amber-workshop-workshop-36
* test(release): update trusted harness contract
Punchcard-Session: amber-workshop-workshop-36
* fix(release): bootstrap every trusted Docker planner
Punchcard-Session: amber-workshop-workshop-36
* fix(release): centralize trusted harness bootstrap
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-09 11:14:23 -07:00
Vincent Koc
106cdd18a9
fix(ci): shard release merge-tree lint ( #120421 )
...
* fix(ci): shard release merge-tree lint
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): resolve branch-creation push base
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): follow Oxlint shard runner rename
Punchcard-Session: amber-workshop-workshop-36
2026-08-10 00:48:44 +08:00
Peter Steinberger
4b85d834ed
fix(ci): sparse-checkout the renamed local-heavy-check-runtime.mts on the frozen shard lane ( #121097 )
2026-08-09 08:59:30 -07:00
Peter Steinberger
623866a30e
fix(release): preserve SHA evidence identity ( #121080 )
2026-08-09 07:51:57 -07:00
Peter Steinberger
c70aee247e
refactor(scripts): migrate JavaScript tools to TypeScript ( #121005 )
...
* refactor(scripts): migrate JavaScript tools to TypeScript
* fix(ci): keep changed-scope preflight zero-install
* fix(ci): preserve zero-install script owners
* fix(ci): complete script migration follow-through
* fix(release): keep stable closeout zero-install
* fix(scripts): preserve standalone execution boundaries
* fix(scripts): repair standalone loader boundaries
* fix(scripts): normalize gateway observation ids
* fix(scripts): keep Docker packager standalone
* test(scripts): preserve rebase cleanup helpers
* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00
Vincent Koc
f83ba2b326
fix(ci): route UI E2E PR retries to hosted runners ( #120997 )
...
* fix(ci): route UI E2E PR retries to hosted runners
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): align UI E2E retry cache routing
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): clarify UI E2E retry routing
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): validate workflow expression capture
Punchcard-Session: amber-workshop-workshop-36
2026-08-09 19:50:24 +08:00
Peter Steinberger
b869d5e73f
fix(workers): skip shared-host quiescence sweeps ( #120969 )
...
* fix(workers): skip shared-host quiescence sweeps
Refs #120952 .
* test(workers): update shared-host fixtures
Refs #120952 .
* fix(workers): reconcile shared-host lease metadata
* fix(workers): fence unknown lease isolation
* chore(plugin-sdk): refresh API baseline
* fix(workers): fence tunnel isolation updates
* docs(workers): clarify shared-host final fences
* ci: invalidate Vitest cache for state schemas
* refactor(workers): import stableWorkerPathComponent from its defining module
workspace-sync.ts crossed the 700-line lint budget by one; drop its
re-export and point consumers at workspace-sync-helpers directly.
2026-08-09 04:34:39 -07:00
Peter Steinberger
8b0735e89f
refactor(memory)!: remove the QMD backend; builtin is the only memory engine ( #120936 )
...
* refactor(memory): remove qmd backend
Make builtin the sole memory-core engine, rename the retained session helper barrel, retire QMD config with doctor migrations, and remove QMD runtime/UI/policy surfaces.
* docs(memory): remove qmd backend guidance
Delete the QMD concept page, rewrite memory documentation for builtin retrieval, and remove QMD from navigation and taxonomy source.
* refactor(memory): remove qmd-only leftovers
* refactor(memory): finish qmd integration cleanup
* build(deps): align root string-width types
* build(deps): model root string-width tooling
* refactor(memory): align qmd removal ui and docs
* fix(memory): preserve qmd external paths in doctor
* test(memory): remove obsolete backend probe case
* test(plugin-sdk): refresh private type baseline
2026-08-09 03:05:47 -07:00
Peter Steinberger
0df1a89e3a
fix(telegram): preserve visible draft recovery ( #120626 )
...
* fix(telegram): preserve visible draft recovery
* fix(telegram): await visible draft send
* test(telegram): use const in draft recovery test
* test(telegram): add live partial failure proof
* test(telegram): register live recovery coverage
* ci(qa): support mock Telegram proof scenarios
* test(telegram): isolate live recovery fallback
* test(telegram): assert live recovery behavior
* fix(agents): join partial reply delivery
* test(telegram): keep settlement proof at core boundary
2026-08-09 02:54:38 -07:00
Peter Steinberger
29c442d483
fix(ci): recheck ClawSweeper PR ack marker before posting ( #120990 )
...
Propagates the canonical dispatcher step from openclaw/clawsweeper#1083
byte-identically: the acknowledgement step waits 15s after a clean
marker check and rechecks immediately before posting, so near-simultaneous
opened and ready_for_review runs (draft PR marked ready within seconds,
as on #120974 ) post exactly one receipt ack.
2026-08-09 01:37:34 -07:00
Peter Steinberger
adcf5bd93a
ci: acknowledge pull request receipts in clawsweeper dispatch ( #120934 )
...
Propagate the receipt-acknowledgment steps from the canonical
ClawSweeper dispatch template (openclaw/clawsweeper#1080 ): mint a
minimal issues:write App token and post an idempotent
clawsweeper-pr-ack marker comment for non-draft opened and
ready_for_review pull requests, before review dispatch.
2026-08-09 00:15:08 -07:00
Peter Steinberger
26ee1b4935
fix(doctor): enforce deprecation registry deadlines ( #120868 )
2026-08-08 21:19:04 -07:00
Peter Steinberger
5cf9c9cda6
ci: extend watchdog for cold migration proofs ( #120700 )
2026-08-08 18:03:16 -07:00
Peter Steinberger
c5085b9152
fix(ci): isolate performance cron fixture ( #120648 )
...
Keep cron suppression local to the direct source-performance gateway child and remove the unrelated memory dreaming override.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-08 15:54:29 -07:00
Vincent Koc
0d45efd5da
fix(ci): retry transient artifact API reads ( #120654 )
2026-08-09 02:05:04 +08:00
Vincent Koc
49161dee60
fix(release): unblock deferred Telegram beta validation ( #120630 )
...
* fix(release): allow deferring package Telegram validation
* fix(qa): mount taxonomy in package Telegram harness
* fix(release): restrict Telegram deferral to beta
2026-08-09 01:03:02 +08:00