Ayaan Zaidi
90e39c49e4
feat(skills): reviewer patch contract, active learning bias, shallow-turn accumulation
...
Self-learning reviewer edits existing skills via targeted patches: it quotes the exact live text (or appends a section) and the service composes the full body inside the receipt-pinned read that hash-binds the proposal — untouched content survives by construction, and patches auto-apply through the scanner-gated pipeline. Full-body rewrites and oversized-skill edits stay pending for the operator. The review prompt shifts to active capture within the existing evidence gates, and shallow same-sender turns accumulate per session (provider-identity scoped, zero-iteration and duplicate-run contracts honored, aborted provenance carried, bounded state) so quick corrections get reviewed with their own transcripts. Replaces closed #119856 .
2026-08-06 17:52:03 +05:30
Onur Solmaz
1f10ef8050
fix(agents): recover once from critical tool loops ( #118647 )
...
* feat(agents): add bounded tool-loop recovery
* feat(agents): wire loop detection into batch recovery
* test(agents): cover bounded tool-loop recovery
* fix(agents): enforce loop thresholds within tool batches
* fix(agents): retain rejected loop batch evidence
* test(agents): update embedded session recovery fixture
* fix(agents): surface terminal loop recovery failures
* fix(agents): preserve loop recovery across retries
* fix(agents): isolate rejected loop evidence
* fix(agents): terminate native critical tool loops
* fix(agents): canonicalize tool loop actions
* fix(agents): preserve tool loop recovery guidance
* fix(agents): preserve code mode tool identity
* fix(agents): preserve prebatch loop evidence
* fix(agents): order native loop termination
* fix(agents): clean up rebased tool validation
* fix(agents): interrupt codex side turns on critical tool loops
* fix(agents): tighten loop recovery batch lifecycle
* fix(agents): drop unconsumed loop detector type export
* fix(agents): drop unconsumed loop relay exports
* test(agents): add agent subscribe to embedded session doubles
* fix(agents): scope critical loop recovery to embedded runs
2026-08-06 14:09:10 +08:00
Ayaan Zaidi
874c63318b
fix(skills): remove regex correction capture; self-learning is reviewer-only
...
Deletes the deterministic regex capture path that templated raw chat text into skill proposals (junk like a proposal whose whole procedure was one slugified user message). All autonomous learning now flows through the isolated experience reviewer: it sees a bounded workspace skill list, prefers revising pending proposals or updating the governing skill over creating new ones, and treats durable user corrections as first-class evidence. Update proposals are reviewer-only (explicit opt-in) and never auto-apply, since the reviewer drafts them without the live skill body. Removes the producerless pending-suggestion session machinery. Regression test proves the junk path is gone; real-Telegram E2E verdict in the PR body.
2026-08-06 11:01:59 +05:30
Jerry-Xin
b8f6086411
fix(tts): deliver Telegram final speech without text churn
...
Defer Telegram final-mode text until speech settles, then deliver one captioned voice note or a proven-safe text fallback.
Co-authored-by: Jerry-Xin <jerryxin0@gmail.com >
2026-08-06 10:41:40 +05:30
Jesse Merhi
95d7d95515
feat(tools): support batched tool search queries ( #118623 )
...
* feat(tools): support batched tool search queries
* fix(tools): harden batched tool search
* fix(tools): preserve batch search contracts
* fix(tools): bound batch search processing
* fix(tools): bound batch candidate metadata
* fix(tools): preserve callable batch candidates
* docs(tools): align batch search QA proof
* refactor(tools): isolate search request parsing
* test(qa): strengthen structured search proof
* test(qa): align structured directory proof
* fix(tools): preserve scalar search compatibility
* test(qa): disable batch scenario retries
* test(qa): allow direct-only tools in structured proof
* test(qa): verify nested catalog call result
* test(qa): remove obsolete result scanner
2026-08-05 16:28:10 +10:00
Ayaan Gazali
347398311a
docs: fix stale 2gb session disk budget default on chrome extension page ( #110624 )
2026-08-04 05:24:23 +08:00
joshavant
d9393bd3cb
fix: make subagent completion delivery durable
2026-08-03 02:48:34 -05:00
Peter Steinberger
e04caa6aee
fix(openai): support flexible GPT Image 2 dimensions ( #118476 )
...
* fix(openai): support flexible GPT Image 2 dimensions
* docs(openai): explain flexible GPT Image 2 dimensions
2026-08-02 22:40:07 -07:00
Peter Steinberger
e9d88696b5
feat(cron): add webhook SSRF policy ( #118237 ) ( #118286 )
2026-08-02 17:02:20 -07:00
Jason (Json)
01565bdc47
fix(agents): make requested threads sidebar-visible ( #118073 )
...
* fix(agents): make requested threads sidebar-visible
* fix(agents): preserve visible spawn authority
2026-08-02 14:26:24 -06:00
Peter Steinberger
4133fe925f
docs(browser): note mcporter auto-detects the extension relay ( #118066 )
...
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local >
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-08-02 09:51:06 -07:00
Vincent Koc
2844876be3
fix(google): align unsupported CLI auth paths ( #118034 )
2026-08-03 00:13:19 +08:00
Peter Steinberger
f599ff520d
feat(browser): relay CDP compat for Puppeteer clients (chrome-devtools-mcp) ( #117915 )
...
* feat(browser): relay CDP compat for Puppeteer clients
Answer Target.getBrowserContexts with the always-empty context list so
puppeteer.connect() (chrome-devtools-mcp) can drive the paired Chrome
through the extension relay without the remote-debugging prompt. Serve
DevTools-style /json/list descriptors (id + type), which also makes the
HTTP tab-list fallback see extension-profile tabs, and add
`openclaw browser extension cdp` to print the relay endpoint and auth
header for external CDP clients.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
* fix(browser): avoid map-spread in relay target descriptors
oxc(no-map-spread): build the /json/list descriptor object explicitly
instead of spreading RelayTabInfo inside map().
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
---------
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local >
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-08-02 01:59:44 -07:00
Vincent Koc
fb087bf947
fix(agents): identify Tool Search counter lifetimes ( #116070 )
...
* fix(agents): scope Tool Search telemetry counters
* fix(agents): keep tool-search scopes visible
* docs(tool-search): document counter scopes
---------
Co-authored-by: Peter Steinberger <steipete@macos.shared >
2026-08-01 22:50:16 -07:00
Jesse Merhi
8b21c23cc2
feat(web-fetch): add tools.web.fetch.headers for operator request headers ( #115545 )
...
* feat(web-fetch): add tools.web.fetch.headers for operator request headers
* docs(web-fetch): update cache discriminator comment
* fix(web-fetch): reserve runtime and cookie headers
* fix(web-fetch): harden operator header normalization
* fix(web-fetch): align header safety contracts
* fix(web-fetch): close header logging gaps
* fix(web-fetch): report case-colliding headers
* fix(web-fetch): reject stale colliding headers
* fix(web-fetch): refuse credential token aliases
* fix(web-fetch): preserve empty header values
* fix(web-fetch): refuse credential-shaped headers
* chore(config): refresh web fetch header baselines
* test(web-fetch): cover header security contracts
* fix(web-fetch): narrow credential header refusal
* fix(web-fetch): preserve trace metadata headers
* fix(web-fetch): keep header validation internal
* test(web-fetch): satisfy strict test contracts
* fix(web-fetch): refuse vendor credential headers
* fix(web-fetch): refuse authentication signatures
* fix(web-fetch): detect qualified auth signatures
* fix(web-fetch): refuse auth-suffixed headers
* fix(web-fetch): refuse compact credential headers
* fix(secrets): audit authentication signatures
* fix(web-fetch): redact operator headers in captures
* fix(web-fetch): keep capture metadata internal
* fix(web-fetch): allow sensitive operator headers
* test(web-fetch): cover normalized operator headers
* docs: note web fetch request headers
* chore(config): refresh web fetch header baseline
* chore: remove release-owned changelog entry
2026-08-02 02:07:25 +10:00
Jesse Merhi
d3f4530ce8
feat(google): allow operator headers on Gemini web search ( #115549 )
...
* feat(google): support Gemini web search headers
* fix(google): validate Gemini search headers
* docs(changelog): credit Gemini headers
* test(secrets): route config contracts through collector
* chore: remove release-owned changelog entry
* test(google): cover resolved search headers
2026-08-02 01:41:09 +10:00
Peter Steinberger
cb16d739cf
fix(inference): harden Codex streaming, cancellation, and live QA ( #116012 )
...
* fix(inference): harden Codex turns, streams, and live QA
* fix(inference): dispatch open CR-delimited response frames
* fix(inference): finish live goal and split streaming regressions
* fix(codex): wait for interrupted turn completion
* fix(codex): narrow terminal collector notification ownership
* fix(inference): harden completion authority and lifecycle
* fix(inference): use canonical source delivery contract
* test(inference): align lifecycle probes with current main
* style(inference): format source delivery verification
* fix(goals): prevent premature completion across staged work
* fix(qa): settle streamed goal turns before continuation
* fix(goals): require visible replies after goal completion
* test(qa): keep goal flow regressions within lint limits
2026-07-31 21:29:33 -07:00
Vincent Koc
a4faeae9df
Merge pull request #101358 from mrunalp/podman-sandbox-backend
...
Add Podman sandbox backend
2026-08-01 00:00:18 +08:00
Vincent Koc
a1026663ae
feat(plugins): externalize ComfyUI provider ( #116888 )
2026-07-31 23:26:51 +08:00
Vincent Koc
e93de36081
feat(plugins): externalize BytePlus provider ( #116866 )
2026-07-31 22:37:47 +08:00
Vincent Koc
ba1a6722bb
feat(plugins): externalize Vydra provider ( #116813 )
2026-07-31 20:35:43 +08:00
Vincent Koc
6830820755
feat(plugins): externalize DuckDuckGo search ( #116740 )
2026-07-31 18:49:07 +08:00
sallyom
4ba02b83e8
refactor(sandbox): share container backend with Podman
...
Signed-off-by: sallyom <somalley@redhat.com >
2026-07-31 00:06:33 -04:00
Mrunal Patel
903276c798
Add Podman sandbox backend
...
Closes #101348
Adds a bundled podman sandbox backend, SDK helper exports, policy/Codex integration, generated plugin docs, and focused tests.
2026-07-30 20:20:42 -04:00
Josh Avant
ce67ffb70e
feat(agents): add tool-free isolated completion ( #114343 )
...
* feat: add isolated pure-inference completion
* fix(google): block ambient system prompt writes
* docs: refresh generated map
2026-07-30 13:24:45 -05:00
Omar Shahine
944cf08f94
docs(automation): rename scheduled-tasks feature wording to Automations ( #114855 )
...
* docs(automation): rename scheduled-tasks feature wording to Automations
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
Claude-Session: https://claude.ai/code/session_01WhJ8EiMXue6ADLmHfb7FL6
* docs: regenerate docs map and add Automations glossary entries
* docs(templates): follow renamed automations-vs-heartbeat anchor
* docs(automation): fix markdown formatting drift
* docs(automation): teach the canonical automations tool and sync the copied heartbeat default
Review follow-ups: normal instructions use the automations tool with cron as
an explicit compatibility alias; every verbatim copy of the default heartbeat
prompt matches the new shipped text from the strings PR.
---------
Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com >
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-07-30 07:21:56 -07:00
Peter Steinberger
7fa95e2656
feat(ui): add composable skill references ( #116330 )
...
* feat(ui): add composable skill references
* fix(ui): align skill reference CI contracts
* fix(ui): scope skill references to WebChat
2026-07-30 04:07:02 -07:00
Peter Steinberger
23e151a016
fix(config): reject reserved __proto__ MCP server name ( #116112 )
2026-07-29 16:09:26 -07:00
Peter Steinberger
b9377f6048
fix(codex): enforce native MCP tool access ( #116054 )
...
* fix(codex): enforce native MCP tool access
* chore: remove prerelease changelog entry
* chore: restore changelog to main
* refactor(codex): build MCP server patches from entries
2026-07-29 17:06:49 -04:00
Peter Steinberger
03a2c8208d
docs(control-ui): document composer capability menu ( #115858 )
...
* docs(control-ui): document composer capability menu
* docs(control-ui): explain tool access discovery states
* docs(map): regenerate docs map
2026-07-29 15:26:56 -04:00
Peter Steinberger
ca07207649
docs(security): add safe Gmail reader setup ( #116041 )
...
* docs(security): add safe Gmail reader setup
* docs: leave release notes to release flow
* docs: refresh documentation map
2026-07-29 15:07:35 -04:00
Peter Steinberger
3f4d65a672
feat(harness): report copilot code-mode engagement on the attempt result ( #115913 )
...
* feat(harness): report copilot code-mode engagement on the attempt result
* test(copilot): prove code-mode engagement through the production tool bridge
* docs: describe the normalized codeModeEngaged value for native harnesses
2026-07-29 14:44:15 -04:00
Peter Steinberger
d7d3fc5dad
feat(ui): enable tool-loop detection from Labs ( #115983 )
...
* feat(ui): add tool loop detection lab
* docs(tools): mention loop detection lab
2026-07-29 13:21:52 -04:00
Brandon
bfc99c97c5
docs(plugins): clarify hook runtime activation ( #77629 )
...
* docs(plugins): clarify hook runtime activation
* docs(plugins): correct hook startup activation guidance
* docs(plugins): clarify hook runtime activation
* docs(plugins): clarify hook runtime startup
Co-authored-by: Brandon Zarnitz <bzarnitz13@gmail.com >
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-07-30 01:02:31 +08:00
Peter Steinberger
ca36be96e0
docs: add cross-client media playback guide ( #116005 )
...
* docs: add media playback guide
* docs: complete media playback glossary
2026-07-29 13:00:40 -04:00
Peter Steinberger
d16e33e08e
fix: restore trustworthy end-to-end QA and cross-channel delivery ( #115404 )
...
* fix(qa): repair verified end-to-end and channel regressions
* fix(gateway): make interrupted restart recovery lifecycle-safe
* test(heartbeat): target the canonical recovery session store
* fix(gateway): prioritize durable restart recovery before heartbeat
* fix(qa): preserve safe restart recovery and channel expiry
* fix(qa): fail closed and fence restart recovery
* test(agents): isolate restart recovery timing
* test(agents): prove actual restart retry timing
* fix(qa): report incompatible profile scenarios
* fix(scripts): resolve symlinked docker scheduler entrypoints
* fix(qa): require fresh native test evidence
* fix(heartbeat): fence active restart recovery delivery
* fix(gateway): consume untargeted restart acknowledgements
* fix(qa): satisfy exhaustive hosted validation gates
* fix(agents): fence stopped restart recovery dispatch
* style(agents): format restart recovery lifecycle regression
* test(gateway): isolate context prewarm sidecar lifecycle
* test(qa): make scenario process timeout cleanup deterministic
* fix(qa): stamp synthetic gateway configs with current version
* fix(openai): preserve vision capabilities in stale model catalogs
* test(qa): align profile channel rejection with current main
* fix(openai): forward supported moderation for image edits
* fix: restore latest-main CI and image edit documentation
* fix(qa): retain relocated code-mode evidence validation
* fix(openai): expose GPT-5.4 vision in static catalog
* fix(pricing): honor explicit model cost overrides
* test(pricing): keep isolated provider regressions deterministic
* fix(openai): inherit transport for discovered static models
* fix(gateway): honor agent-owned static image capabilities
* test(gateway): preserve prepared-snapshot attachment races
* test(gateway): isolate subagent persistence failure injection
* test(gateway): exercise concurrent voice replay admission
* fix(gateway): restore stale model image capabilities
* fix(agents): publish configured model vision capabilities
* fix(agents): isolate detached media transcript ownership
* test(agents): preserve generic transcript lock regression
* fix(gateway): require proven static model route identity
* fix(qa): accept bounded full-size generated image attachments
* fix(qa): require fresh script producer evidence
* test(qa): prove native E2E scenario execution
2026-07-29 12:45:27 -04:00
Peter Steinberger
095f30ae26
feat(skills): review interrupted deep turns in experience review ( #115887 )
...
* feat(skills): review interrupted deep turns in experience review
* test(skills): stabilize experience-review live eval and cover interrupted turns
2026-07-29 09:11:02 -04:00
Yuval Dinodia
edf4aca7bc
fix(agents): apply_patch destroys an existing file when a patch creates that path ( #114911 )
...
* fix(agents): stop apply_patch from silently overwriting existing files
An "*** Add File:" hunk wrote its target unconditionally. When the path
already existed, apply_patch replaced the entire file, returned Success,
and listed the path under "added", so neither the model nor the UI got
any signal that existing content had been destroyed. The "*** Move to:"
destination of an update hunk had the same gap and reported the clobbered
path as merely modified.
The add and move-to branches now check the destination through the patch
file ops before writing and fail closed when it exists. Routing the check
through fileOps keeps it correct on all three backends (workspace-scoped
fs-safe root, raw fs, sandbox bridge). The check runs per hunk in patch
order, so deleting a path earlier in the same patch and recreating it
still works.
* fix(agents): make apply_patch destination creation atomic
The previous guard checked that an add or move-to destination was absent
and then wrote it. A competing writer could create the path in that gap,
after which the write still replaced it, so the no-clobber guarantee did
not hold under contention.
Destination creation now goes through a single exclusive create-if-absent
operation on every patch backend: Root.create for the workspace-scoped
default, an O_EXCL write for the raw filesystem, and a new pinned create
operation in the sandbox mutation helper that opens the target with
O_CREAT|O_EXCL and reports a reserved exit code when it already exists.
PatchFileOps drops its separate existence check.
Resolving the host ops behind an early return removes the repeated
workspaceOnly branch inside each operation and the optional-call dance
that let a missing root silently skip a write.
* fix(agents): complete atomic apply-patch creation
* fix(agents): preserve raced create replacements
* fix(agents): handle fs-safe patch collisions
* fix(agents): publish sandbox creates atomically
* test(agents): cover exclusive create provenance rollback
* fix(agents): use typed exclusive-create signal
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-07-29 20:17:54 +08:00
Peter Steinberger
e8524a5839
feat: add Fish Audio S2.1 and local MLX speech ( #115790 )
...
* feat: add Fish Audio speech support
* chore: remove unused speech exports
* chore: keep Fish API constant private
* test: remove stale code mode import
* style: use bracket access for Fish voice ids
* test: restore QA evidence validator import
2026-07-29 05:15:33 -04:00
Vincent Koc
14940edf15
feat(skills): add Skill Workshop lifecycle hooks ( #115606 )
...
* feat(skills): add lifecycle hook contracts
* feat(plugins): expose skill hook contracts
* feat(plugins): identify skill evaluators
* feat(skills): persist proposal evaluation lifecycle
* feat(skills): add agent evaluation action
* feat(skills): emit committed skill lifecycle changes
* feat(gateway): expose skill proposal evaluation lifecycle
* feat(ui): add Skill Workshop evaluations
* fix(skills): bind lifecycle state to proposal revisions
* fix(skills): preserve lifecycle events without artifacts
* feat(cli): evaluate skill proposals
* fix(ui): bind evaluations to proposal revisions
* docs(skills): document lifecycle hook primitives
* chore(plugin-sdk): refresh skill hook surface
* fix(skills): harden proposal evaluator execution
* fix(plugins): isolate skill evaluator inputs
* fix(cli): align skill lifecycle deadlines
* fix(skills): preserve evaluation replay invariants
* test(ui): capture Skill Workshop evaluation proof
* fix(skills): bind apply to evaluated target tree
* fix(skills): preserve evaluation contract edges
* fix(skills): bound evaluation event storage
* chore(skills): keep lifecycle helpers internal
* refactor(skills): isolate evaluation persistence
* fix(skills): satisfy lifecycle validation gates
* chore(protocol): refresh Skill Workshop clients
* docs: refresh Skill Workshop map
* chore: keep release notes in PR metadata
* docs: refresh merged docs map
* fix(ci): type Code Mode catch errors
* fix(skills): freeze lifecycle observation payloads
* fix(protocol): keep proposal inspect backward-decodable
* fix(skills): enforce final evaluator bundle limits
* fix(skills): preserve lifecycle caller attribution
* chore: drop subsumed Code Mode formatting
* test(plugins): adapt lifecycle hook mocks
2026-07-29 15:49:44 +08:00
Peter Steinberger
8fd49c84aa
feat: make self-learning automatic by default ( #115576 )
...
* feat: make self-learning automatic by default
* fix: preserve capture authorization boundaries
* test: split autonomous capture coverage
2026-07-29 02:04:57 -04:00
Peter Steinberger
04eb57d299
feat(ui): add contextual Settings documentation links ( #115560 )
...
* feat(config): add contextual settings docs URLs
* feat(ui): add contextual settings guide links
* docs: add settings guide pages
* docs: refresh generated docs map
* docs: polish settings guide pages prose
2026-07-29 01:00:15 -04:00
Shakker
7620475a2f
docs: explain native subagent handoff
2026-07-29 02:22:09 +01:00
Peter Steinberger
98591fda13
fix(skills): persist workshop apply reason; correct Skill Workshop docs ( #114471 )
...
* fix(skills): persist workshop apply reason and correct docs
* docs: refresh self-learning map
2026-07-28 14:53:35 -04:00
Peter Steinberger
826beb724d
feat(skills): enable self-learning review for Codex sessions ( #114501 )
...
* feat(skills): enable Codex experience review
* style(codex): keep event projector within ratchet
2026-07-28 14:21:42 -04:00
Peter Steinberger
0f91859382
fix: keep isolated gateway workspaces and skills inside state dir ( #114487 )
...
* fix: isolate non-default state workspaces and skills
* fix(codex): isolate native personal skills
* chore: refresh plugin SDK API manifest
* fix: keep SDK manifest generation scoped
* refactor(codex): keep isolation plugin-local
* test: satisfy optional skill snapshot typing
* refactor(codex): extract thread lifecycle preflight
2026-07-28 13:48:21 -04:00
ivan-digital
8a35dd3ef9
docs: document local TTS on macOS, Linux, and Windows ( #110230 )
...
* docs: add local speech TTS setup
* docs: clarify local HTTP release requirement
* docs: require Speech Swift v0.0.23
* docs: use released speech-core Windows package
* docs: use current TTS config in local recipes
Co-authored-by: ivan-digital <root@ivan.digital >
---------
Co-authored-by: ivan-digital <root@ivan.digital >
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-28 13:40:46 -04:00
Peter Steinberger
970b2d257b
feat(skills): shared authoring standards make learned skills routable ( #115103 )
...
* feat(skills): share authoring standards
* fix(skills): derive routable autocapture proposals
* docs(skills): document proposal authoring standards
* refactor(skills): simplify autocapture derivation
* fix(skills): preserve explicit reflection rules
* docs(skills): state the accepted heuristic-detection tradeoff
* fix(skills): preserve explicit directive syntax
* style(skills): keep signal parser within ratchets
2026-07-28 12:48:30 -04:00
Vincent Koc
0f41b401fd
docs(browser): correct Docker sandbox setup ( #115254 )
2026-07-28 23:18:40 +08:00
Peter Steinberger
206f989069
fix: preserve skill proposals across apply crashes and workspace moves ( #114535 )
...
* fix: move skill workshop proposals to sqlite
* fix(doctor): make workshop manifest cleanup idempotent
* fix(skills): resolve post-rebase static checks
* ci: retrigger exact-head checks
2026-07-28 10:42:32 -04:00