Peter Steinberger
1ca60fbc3a
refactor(agents): make multi-agent ownership explicit (H2-1 core) ( #114388 )
...
* refactor(agents): make roster ownership explicit
* feat(config): materialize legacy agent roles
* fix(cron): migrate legacy owners at startup
* feat(gateway): expose agent selection contracts
* fix(gateway): enforce agent-scoped authorization
* docs(config): document explicit agent ownership
* fix(config): pin retained owner workspace
* fix(gateway): target hook wakes at effective agent
* fix(sessions): preserve fixed-store ownership
* fix: preserve retained agent ownership
* fix: preserve legacy agent ownership across runtime surfaces
* fix: fail closed on ambiguous session ownership
* fix: preserve compatibility owners across dispatch and writes
* fix: preserve retained agent projections
* fix: preserve agent ownership compatibility
* fix: preserve per-agent heartbeat guidance
* fix: preserve compatibility owners in generic paths
* fix: enforce configured ownership in session paths
* fix: defer remote roster selection
* fix: preserve ownership across session and config writes
* fix: fail closed on ambiguous restored ownership
* fix: preserve explicit ACP and legacy ownership
* fix: honor durable fixed-store ownership
* fix: enforce fixed-store owner authority
* fix: preserve ownership evidence boundaries
* fix: honor resolved session ownership
* fix: align compatibility ownership paths
* fix: persist legacy main store ownership
* fix: close ownership fallback gaps
* fix(agents): close retained owner compatibility gaps
* fix(agents): enforce session owner resolution
* fix(agents): complete session owner resolution sweep
* fix(agents): preserve durable session ownership
* fix: complete persisted session owner routing
* fix: thread prepared session owners
* fix: preserve stable session ownership
* fix: enforce session ownership boundaries
* fix: close session ownership delta gaps
* fix: reconcile session ownership after rebase
* fix: reconcile ownership with current main
* fix: align session store path imports
* fix: align session store config path import
* fix: reconcile explicit ownership CI
* fix: reconcile ownership rebase checks
* fix: align ownership ci contracts
* fix: align ownership rebase checks
* fix: preserve compatibility owner during setup
* fix(doctor): migrate ownerless heartbeat monitors
* fix(gateway): preserve explicit session ownership
* test: align ownership fixtures after rebase
* test: complete plugin manifest fixture
* test: align runtime context mocks
* fix(gateway): preserve alias routing for existing sessions
* style: format agent routing update
* fix(gateway): preserve selected owner during alias routing
* style: normalize rebased ownership files
* fix(gateway): preserve owner through global alias routing
* fix(gateway): preserve explicit ownership at HTTP boundaries
* fix(gateway): validate compatibility model ownership
* fix(agents): reconcile strict session ownership
* fix(agents): contain media yield callback failures
* fix(agents): avoid eager bare-key owner resolution
* chore: refresh rebased ownership baselines
* chore: align hosted plugin SDK baseline
* chore: refresh ownership baselines after main sync
* chore: refresh ownership baselines after main sync
* test: align routed event owner fixtures
* chore: retrigger CI after runner startup failure
* chore: refresh ownership SDK budgets after main sync
* fix(tasks): require agent identity for bare owners
* chore: align Linux plugin SDK baseline
* chore: remove release-owned changelog entry
2026-08-12 15:55:16 -07:00
Peter Steinberger
d003e08756
refactor(plugin-sdk): remove final test-only facades ( #122844 )
2026-08-12 15:28:22 -07:00
Peter Steinberger
dceb2c343c
refactor: retire due compat-ledger surfaces (context-engine host params, deactivate alias, logging internals) ( #121845 )
...
* refactor(plugins): retire deactivate hook alias
* refactor(plugin-sdk): prune retired facade exports
* test(logging): isolate logger test controls
* refactor(logging): internalize file transport controls
* test(plugin-sdk): preserve retired facade coverage
* test(auto-reply): remove stale diagnostic imports
* refactor(logging): delete dead config-read guard
shouldSkipMutatingLoggingConfigRead had no production caller even on main;
it survived the dead-export scan only via logger's testApi re-export. The
test-isolation commit removed that mask, exposing the fossil. Delete the
guard, its test-only re-export, its mock entry, and its dedicated test file.
* refactor(plugin-sdk): retire due compatibility subpaths
* test(plugin-sdk): type group policy predicates
* refactor(plugin-sdk): split removed subpath records
* refactor(secrets): remove retired collector barrel
* test(plugin-sdk): tighten wildcard surface pin
* refactor(plugin-sdk): retire matrix facade metadata
* style(plugin-sdk): format facade metadata
* fix(ci): load channel setup contracts from source
Repair the main-owned regression from 99d662473c (Peter Steinberger): the new env-contract test could consume stale ignored dist metadata instead of the checked-in plugin declaration.
* test(plugin-sdk): refresh API baseline after rebase
2026-08-12 12:41:27 -07:00
Gio Della-Libera
1ec4e4582e
fix(claws): freeze installed tool profile authority ( #121327 )
...
* fix(claws): freeze installed tool profile authority
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): normalize consent helper file modes
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): preserve consented tool authority
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): normalize source file modes
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): allowlist runtime provenance probe
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): close consent review gaps
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* docs(claws): require concrete frozen tool grants
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): reject dynamic MCP selectors
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): type profile resolution at parse boundary
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): preserve bounded update authority
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): prepare consent provenance at config load
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): isolate consent provenance failures
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): keep runtime grants inside consent
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): own consent cache in state lifecycle
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): guide legacy full profile repair
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): keep consent cache internals private
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): satisfy strict consent cache types
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): fail closed when state cache closes
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): integrate consent cache with state owner
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): fail closed before consent state opens
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): resume legacy v1 profile installs
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(claws): isolate legacy resume regression
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): follow tool policy normalizer rename
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): bind runtime consent to agent config
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(claws): normalize digest helper mode
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): drop stale digest helper import
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(runtime): keep snapshot mocks complete
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): retain bounded legacy profile plans
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): verify ownership before runtime consent
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(claws): remove stale runtime import
* fix(claws): drop stale add import
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* fix(claws): resume failed v1 promotion
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* test(claws): codify cold-state authority fence
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
* chore(plugin-sdk): refresh API baseline
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
---------
Co-authored-by: Gio Della-Libera <235387111+giodl73-repo@users.noreply.github.com >
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: db3a73db-01ff-428e-a451-b7b710cd5085
2026-08-12 11:37:04 -07:00
Peter Steinberger
42f4322464
refactor(plugin-sdk): prune unreachable facades ( #122745 )
2026-08-12 10:54:06 -07:00
Peter Steinberger
99d662473c
fix(channels): fail-fast headless channel setup with plugin-declared env contracts ( #122530 )
...
* fix(channels): validate headless channel setup
* docs(channels): document headless provisioning
* fix(channels): repair setup metadata typing
* chore(channels): regenerate official channel catalog for env metadata
* fix(slack): keep mode-conditional env contract plugin-owned
Static --use-env declaration keeps only the unconditional SLACK_BOT_TOKEN;
socket-vs-HTTP conditional requirements (app token, signing secret) stay in
Slack's own setup validation so HTTP mode no longer demands an irrelevant
SLACK_APP_TOKEN.
* chore(sdk): regenerate api baselines and catalog after rebase
* fix(slack): align manifest env declaration with runtime contract
* chore(sdk): regenerate api baselines after rebase
* chore(sdk): regenerate api baselines after rebase
* chore(sdk): regenerate api baselines after rebase
2026-08-12 17:12:15 +00:00
Peter Steinberger
c23d66e3b5
refactor: consolidate coercion ownership ( #122692 )
...
* refactor: consolidate coercion ownership
* test: align shard check with weighted planning
* chore: refresh plugin SDK API baseline
2026-08-12 09:25:28 -07:00
Vincent Koc
1672d78d17
refactor(plugins): share bounded run id tracking ( #122362 )
2026-08-12 16:23:33 +08:00
Peter Steinberger
08142099da
refactor(plugins): remove test-only facades and adapter ( #122532 )
...
* refactor(plugins): trim test-only facades
* refactor(whatsapp): remove legacy outbound adapter
2026-08-12 01:20:09 -07:00
Vincent Koc
b8a0fa2e7a
fix(plugins): derive media aliases from exports ( #122523 )
2026-08-12 16:03:34 +08:00
Peter Steinberger
5a643e3543
fix(plugins): keep packed entries consistent through package lifecycle ( #121174 )
...
* fix(plugins): own packed entry lifecycles by package
Persist package ownership per runtime child, route lifecycle actions through one closed resolver, reconcile removed child policy during updates, and retain rollback generations until durable config/index commit.
* fix(plugins): break uninstall policy import cycle
* test(plugins): model package ownership in lifecycle fixtures
2026-08-12 00:49:29 -07:00
Peter Steinberger
59ea107d09
refactor(agents): delete dead model-selection surface and consolidate compaction targets ( #122474 )
...
* refactor(agents): delete dead model-selection surface, consolidate compaction target assembly
Removes production surface with zero live callers: buildConfiguredAllowlistKeys
(orphaned since fallback allowlist filtering was split out), the
retryTransientProviderRuntimeMiss resolveModelAsync option (its gateway startup
prewarming caller was replaced by prepared runtime snapshots), the ignored
useAsyncModelResolution plumbing (kept only as a deprecated no-op field on the
plugin-SDK-shipped prepareSimpleCompletionModelForAgent), and dead facade
re-exports (inferUniqueProviderFromCatalog, ThinkLevel, ModelRefStatus).
Consolidates resolveEmbeddedCompactionTarget's five hand-built result sites into
one assembleTarget helper owning the auth-profile-drop-on-provider-change rule;
resolution precedence is unchanged and now pinned by new table-driven cases
(unique-provider inference, ambiguous literal, profile-suffix preservation).
Net -93 production LOC, -106 test LOC.
* chore(sdk): regenerate plugin SDK API baseline after facade export removals
2026-08-11 23:37:15 -07:00
Peter Steinberger
0b4701677b
test(core): remove residual duplicate cases ( #122487 )
2026-08-11 23:34:31 -07:00
Peter Steinberger
b080dd1e76
refactor: consolidate coercion contracts ( #122458 )
...
* refactor: consolidate coercion contracts
Centralize exact string, record, numeric, date, Boolean, argument, and structured-error coercions while preserving call-site semantics.
Migrate canonical-name collisions and deprecated internal SDK bypasses, deleting 55 net production/tooling lines. Expand declaration ownership enforcement to 101 allowed helpers and add a narrow export-completeness audit.
* fix: preserve standalone script coercions
Keep copied Control UI tooling self-contained and retain the trusted release harness module-relative source seam when the harness runs against an old target cwd.
2026-08-11 23:26:37 -07:00
Peter Steinberger
7ecad45a7d
refactor(context-engine): retire legacy host param default ( #122434 )
2026-08-11 21:57:46 -07:00
Vincent Koc
8cd74ab4bf
refactor(plugins): consolidate public artifact resolution ( #122339 )
2026-08-12 08:44:39 +08:00
Peter Steinberger
964c8c84c1
refactor: consolidate coercion ownership ( #122299 )
...
* refactor: consolidate coercion ownership
Centralize four canonical coercion helpers, migrate exact core and plugin duplicates through narrow Plugin SDK facades, and enforce declaration and plugin-normalization ownership boundaries.
The sweep adds eight focused SDK exports while deleting more production and tooling code than it adds. User-visible behavior is unchanged except for safer equivalent object and UI parsing at existing boundaries.
* fix: guard integer option ownership
Register resolveIntegerOption with the canonical function owner and extend the declaration-guard fixture so future local duplicates fail validation.
* fix: keep integer helpers on numeric facade
Remove the unshipped duplicate string-coerce exports and route every affected plugin consumer through the existing number-runtime contract.
* fix: point numeric coercion to number runtime
Make boundary and declaration diagnostics recommend the canonical numeric facade, with failing-before coverage for both guidance paths.
2026-08-11 17:14:53 -07:00
Peter Steinberger
cd0a1235a3
feat: sync new-session preferences and recents by identity ( #121816 )
...
* feat(gateway): add identity preferences and project recents
* feat(ui): sync new-session identity state
* docs: explain identity-scoped session state
* test: track preference temp directories
* fix(gateway): preserve identity preference boundaries
* chore(protocol): refresh identity preference bindings
* test: refresh historical schema hashes
* style(gateway): format method order assertion
* fix(protocol): emit project recent Swift models
* test(gateway): track preference RPC release train
* fix(gateway): harden identity preference state
* fix(state): keep preference errors internal
* chore: refresh split plugin SDK baseline
* fix(gateway): use core session store loader
* refactor(state): fold additive migration checks
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* test(ui): relocate identity recents e2e
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
* chore: regenerate plugin SDK baseline
2026-08-11 16:52:59 -07:00
Peter Steinberger
db9bdb4a11
fix(gateway): preserve session identity through archive transitions ( #121169 )
...
* fix(sessions): fence lifecycle mutations by identity
* fix(sessions): finalize lifecycle identity fences
2026-08-11 16:43:10 -07:00
Sliverp
84c7d45f15
refactor(qqbot): install plugin from Tencent package ( #107295 )
...
* refactor(qqbot): remove bundled extension source
Mechanical deletion half of the #107295 squashed rebase; the catalog
repoint and host integration land in the follow-up commit.
Co-authored-by: sliverp <870080352@qq.com >
* refactor(qqbot): install plugin from Tencent package
Squashed rebase of #107295 onto current main. Repoints the official
external channel catalog at @tencent-connect/openclaw-qqbot@2.0.1 and
adapts onboarding, doctor migrations, secrets, build guards, and tests.
Documents the known limitation that the external package does not
support structured SecretRef clientSecret values; operators move those
to QQBOT_CLIENT_SECRET or clientSecretFile before upgrading.
Co-authored-by: sliverp <870080352@qq.com >
* fix(doctor): reuse shared hasOwnKey record helper
The rebased QQBot migration carried its own hasOwnKey export, colliding
with the one main now ships in legacy-config-record-shared.ts.
Co-authored-by: sliverp <870080352@qq.com >
* fix(plugins): carry catalog integrity through the update bridge
The externalized-bundled-plugin bridge dropped the official catalog's
expectedIntegrity pin, so bundled-user updates installed the external
npm package without integrity verification. The bridge now carries the
pin for the catalog's exact npm spec and both bridge install calls pass
it through; update-channel spec overrides intentionally skip the pin
since it only covers the pinned version.
Co-authored-by: sliverp <870080352@qq.com >
* chore(plugin-sdk): refresh per-entrypoint API baselines
The QQBot compat export and bundled-type removal shift 26 entrypoint
closure hashes in the new split baseline layout.
Co-authored-by: sliverp <870080352@qq.com >
* refactor(qqbot): drop helper reintroduced during rebase
Main's coercion consolidation added this file after the deletion
commit's base; its only consumers were the removed qqbot sources.
Co-authored-by: sliverp <870080352@qq.com >
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-08-11 15:10:27 -07:00
tangtaizong666
4ccbdf58bf
fix(plugins): refresh stale source plugin registry ( #96046 ) ( #96080 )
...
* fix(plugins): refresh stale source plugin registry
* fix(plugins): port registry snapshot to core manifest loader
---------
Co-authored-by: tangtaizong666 <212687958+tangtaizong666@users.noreply.github.com >
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-12 06:05:01 +08:00
Mariano
edb7a1692e
fix(telegram): expose live location updates to hooks ( #122185 )
...
* fix(telegram): expose live location updates to hooks
* test(telegram): keep location coverage focused
* fix(telegram): emit stopped live locations
* test(plugin-sdk): refresh location hook contracts
* docs(changelog): note Telegram live location hooks
* fix(telegram): complete live-location observer path
---------
Co-authored-by: mbelinky <mbelinky@users.noreply.github.com >
2026-08-11 23:26:23 +02:00
Peter Steinberger
e74be5d41d
refactor: eliminate final wrapper-shadowing hazards ( #122157 )
...
* refactor: disambiguate wrapper-shadowed exports
* test: align renamed session and facade boundaries
* test: cover renamed runtime mock exports
* refactor: align remaining wrapper owner call sites
* test: align overlap-rebased runtime mocks
* refactor: preserve public SDK names after overlap rebase
* chore: regenerate wrapper shadowing baselines
* test: align cron model selection mocks
2026-08-11 13:34:24 -07:00
tharuntejmeta
a57e8c70f5
feat(meta): add Muse Spark 1.2 models ( #120373 )
...
* feat(meta): add Muse Spark 1.2 models
* fix(meta): verify Muse Spark 1.2 catalog metadata
* fix(meta): verify Muse Spark 1.2 contracts
* docs(meta): quote discounted services terms
* fix(meta): preserve replay fields for simple completions
* test(meta): align stream host adapter types
* fix(meta): apply catalog cap for zero max tokens
* fix(meta): preserve omitted output cap
* fix(meta): scope responses stream wrapper
* fix(ai): preserve source API for stream wrappers
* fix(ai): distinguish hook and dispatch APIs
* test(ai): adapt plugin streams synchronously
* chore(plugin-sdk): refresh API baseline
* chore(plugin-sdk): refresh sharded API baseline
---------
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com >
2026-08-11 11:26:58 -07:00
Peter Steinberger
3d76246792
refactor: eliminate final export name collisions ( #122083 )
...
* refactor: resolve final export name collisions
* refactor: update remaining collision rename consumers
* style: format rebased auth helpers
* test: update remaining session entry mocks
* test: update remaining runtime mock exports
* test: update delivery info path mock
* refactor: reconcile combined collision sweeps
* chore: regenerate collision and sdk baselines
2026-08-11 11:18:24 -07:00
Peter Steinberger
ebb2770000
refactor: eliminate export name collisions ( #122084 )
...
* refactor: eliminate export name collisions
* chore(scripts): burn resolved collision baselines
* refactor: narrow legacy session load options
* chore: refresh SDK and session debt baselines
* refactor: adopt upstream secrets collision fix
* test(plugin-sdk): mock renamed session store core
* fix(scripts): track renamed session accessor core
2026-08-11 10:41:50 -07:00
Peter Steinberger
cad77fb39c
refactor: consolidate remaining coercion helpers ( #122020 )
2026-08-11 10:22:01 -07:00
Patrick Erichsen
ad704f35c4
fix(control-ui): hide unusable models from picker ( #121852 )
...
* fix(ui): hide unusable models from picker
* refactor(ui): remove stale model availability helper
* refactor(ui): simplify catalog state guards
* style: format provider catalog imports
* chore: refresh plugin SDK API baseline
* refactor(core): break provider catalog type cycle
* chore(protocol): refresh models list Swift output
* chore: refresh plugin SDK API baseline after rebase
* fix(gateway): preserve full catalog preload semantics
* fix(ui): keep model status within startup budget
* fix(ui): preserve provider status within startup budget
* fix(models): scope live catalog outcomes
* test(ui): expect agent-scoped model refresh
* test(ui): align model refresh e2e fixtures
2026-08-11 09:13:44 -07:00
Vincent Koc
32e3bd3797
refactor(plugins): centralize bundled tree detection ( #122093 )
2026-08-11 23:59:38 +08:00
Peter Steinberger
db73b59c04
refactor: burn wrapper shadowing baseline entries ( #122040 )
...
* refactor: burn wrapper shadowing entries
* chore: refresh wrapper shadowing baselines
* test: update secrets runtime state mocks
* fix(ci): absorb Control UI build identity variance
2026-08-11 08:24:03 -07:00
Peter Steinberger
e390781534
refactor: burn cross-directory export name collisions ( #121893 )
...
* refactor: name subsystem logger exports
* refactor(test): distinguish exported test doubles
* refactor: consolidate canonical owner helpers
* refactor: give cross-domain helpers distinct names
* chore(lint): ratchet collision debt baselines
* fix(test): complete collision rename consumers
* fix(test): update remaining collision mock consumers
* fix(test): update transcript reader mock export
* refactor: keep embedded logger name at its owner
* fix(test): align embedded logger mock with owner
* refactor: name shared assistant phase extraction
* fix(ui): update assistant phase extractor import
* chore(generated): refresh collision and SDK baselines
* style(test): format merged plugin mocks
* chore(sdk): refresh API content hashes
2026-08-11 06:50:22 -07:00
Ayaan Zaidi
2c8ed54ddb
feat(heartbeat): default delivery to the configured owner, never groups ( #121988 )
...
Unset heartbeat.target now resolves "owner": elected heartbeat notifications deliver to the operator's DM resolved from commands.ownerAllowFrom or the channel allowFrom (first concrete entry; wildcards and channel-scoped wildcards excluded; configured owners exhausted across channels before any channel-local fallback). Delivery requires the channel's own classifier to positively prove a direct destination — every bundled messaging plugin now ships an inferTargetChatType contract — and unproven or group-shaped destinations fail closed to the visible no-route state. The first implicitly-routed delivery carries a one-line self-explanation naming the target: "none" opt-out. Explicit target "last" remains as the follow-the-conversation opt-in. Refines the unreleased #121892 default before it ships; refs #121880 .
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-08-11 13:18:22 +00:00
Peter Steinberger
59dc87290f
test(plugins): remove cache resize test knob ( #121904 )
...
* test(plugins): remove cache resize test knob
* chore(plugin-sdk): refresh cache closure hashes
2026-08-11 06:05:32 -07:00
Peter Steinberger
686294f9f8
test(sqlite): right-size reliability crash payloads ( #122016 )
...
* test(sqlite): right-size reliability crash payloads
* test(agents): replace hanging provider error integration
---------
Co-authored-by: Amp <amp@ampcode.com >
2026-08-11 05:26:07 -07:00
Peter Steinberger
02e8470bb8
refactor: burn SDK export collision debt ( #121888 )
...
* refactor: burn SDK export collision debt
* chore: regenerate collision debt baselines
* fix: update durable delivery core import
* fix: remove stale channel metadata type import
* fix: preserve config write SDK parameter type
* fix: preserve chat metadata SDK return type
* chore: refresh plugin SDK API baseline
* test: update plugin enable mock import
* fix: remove duplicate status helper re-export
* fix: preserve strict QA runtime availability errors
2026-08-11 05:06:11 -07:00
Peter Steinberger
12165769c7
refactor(agents): move OpenRouter failover ownership to its plugin and derive reason schemas from one tuple ( #121898 )
...
* refactor(agents): centralize failover ownership and reasons
* test(agents): move OpenRouter failover cases to plugin owner
* fix(agents): preserve prepared provider failover ownership
* test(agents): avoid failover mock shadowing
* fix(agents): preserve provider owner in error copy
* fix(agents): complete provider owner propagation
* chore(plugins): refresh failover type closure hashes
2026-08-11 04:30:18 -07:00
Peter Steinberger
bcaec0cf14
fix: resume main sessions after gateway restarts ( #121969 )
...
* fix(agents): always resume main sessions after restart
* fix(ui): render internal messages as system rows
* docs: update gateway restart recovery semantics
* refactor(sessions): simplify restart hook checkpoints
* refactor(agents): consolidate restart recovery claims
* test(agents): update delivery recovery revision guard
* fix(plugin-sdk): preserve restart hook state contract
* fix(ui): localize system row label
* test(agents): remove obsolete recovery import
* test(agents): align abort-code propagation with always-resume recovery
* fix(ui): share notice-aware turn boundaries
* test(agents): reconcile restart recovery ownership
* fix(ci): reconcile rebased recovery and UI checks
2026-08-11 04:01:34 -07:00
Peter Steinberger
2731dc24e5
fix(plugin-sdk): keep inbound reply shim through next SDK major ( #121922 )
...
* fix(plugin-sdk): honor major-gated reply shim retirement
* fix(plugin-sdk): preserve compat code literals
* chore(plugin-sdk): refresh compatibility API baseline
2026-08-11 03:18:07 -07:00
Ayaan Zaidi
73d4c07bd5
fix(delivery): record ambiguous final loss as durable notice debt ( #121833 )
...
A final reply whose platform send was accepted but whose response was lost
previously ended in silence. Custody that stays unknown after a claimed send
now records durable pendingDeliveryNotice debt; the next same-route turn
delivers one "could not confirm delivery" notice and acknowledges it into the
transcript. Restart recovery completes ambiguous sessions with the same debt
instead of a fire-and-forget notice; the debt survives reset and rollover, and
suppressed notice sends retain it instead of faking delivery. Permanent typed
no-send rejections settle as terminal suppression (no replay, no false
notice); retryable ones restore prepared custody for safe replay. Google Chat
media-only rejections use the typed no-send contract; Telegram native-command
replies join pending-final custody.
Fixes #80362
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
2026-08-11 09:25:04 +00:00
Peter Steinberger
e71d56d557
feat(cloud): let cloud sessions spawn and message cloud children ( #121846 )
...
* feat(cloud): add nested worker session capabilities
Amp-Thread-ID: https://ampcode.com/threads/T-019feaaa-c7ed-769e-9f29-a3612bec72e7
* fix(cloud): harden nested worker sessions
Amp-Thread-ID: https://ampcode.com/threads/T-019feaaa-c7ed-769e-9f29-a3612bec72e7
* fix(cloud): repair exact-head integration
Amp-Thread-ID: https://ampcode.com/threads/T-019feaaa-c7ed-769e-9f29-a3612bec72e7
---------
Co-authored-by: Amp <amp@ampcode.com >
2026-08-11 02:07:49 -07:00
Ayaan Zaidi
ba9e72c17f
fix(heartbeat): deliver to the last conversation by default ( #121892 )
...
Unset heartbeat.target silently collapsed into the explicit "none" opt-out: heartbeats ran every 30m by default, elected notifications were dropped with only an in-memory event, and health read fine. Unset now resolves to "last" (the most recent conversation); explicit target: "none" keeps its internal-only contract. Polls skip pre-model with reason no-route while no route exists yet, and status/doctor surface the waiting-for-route state. Deliberate maintainer-owned default cutover: existing installs without a configured target start receiving heartbeat alerts in their last conversation after upgrade.
Fixes #121880
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-08-11 08:45:30 +00:00
Peter Steinberger
fa03d9b913
refactor: consolidate coercion helpers ( #121366 )
...
* refactor: consolidate coercion helpers
* fix: remove duplicate coercion imports
* fix: preserve serialized coercion guard
* chore: ratchet coercion helper carve-outs
* fix(test): keep gauntlet subprocess startup lean
* fix: preserve imported session timestamp semantics
* fix: preserve catalog timestamp string semantics
* chore: align plugin SDK surface ratchet
* fix: preserve trajectory and SDK string contracts
* fix(test): preserve QA record assertion semantics
* fix: complete standalone record guard rename
* refactor(cron): use canonical string coercion
* fix(acpx): preserve Pi timestamp parsing
* test(channels): adapt custody test harnesses
* test(telegram): classify media harness as test support
* test(acpx): split timestamp contract coverage
* test(channels): support generated custody contracts
* chore: ban the full coercion helper name set
Extends the declaration guard to all eleven consolidated helper names and
renames the cron schedule-identity readNumber wrapper to readScheduleInteger
so the banned generic name cannot regrow.
* fix(scripts): repair release-validation guard drift and lint cause
Restores the renamed isJsonRecord guard in assertTrustedWorkflowHarness after
main added isRecord call sites in parallel, and attaches the caught YAML error
as the thrown error cause (preserve-caught-error was red on main).
* fix: preserve Claude timestamp string semantics
* fix: preserve persisted timestamp string semantics
* fix: preserve date-first timestamp contracts
* fix(openai): harden delegation failure formatting
* chore: close coercion helper guard gaps
* test(openai): model non-error delegation rejection
* chore: refresh plugin SDK API contract
* fix(tasks): use canonical string field reader
* fix(ai): use canonical provider error field coercion
* fix(browser): migrate native bootstrap coercion
* docs(plugin-sdk): clarify text record export compatibility
* fix(gateway): normalize approval execution identity
* test(outbound): isolate message action poll harness
2026-08-11 00:02:18 -07:00
Peter Steinberger
1220a7609a
refactor: consolidate promise-like guards ( #121861 )
...
* feat(normalization-core): add promise-like guard
* refactor: consolidate promise-like guards
* fix(normalization-core): keep isPromiseLike non-throwing on hostile then getters
ClawSweeper finding on #121861 : the diagnostics-path local guard caught throwing
then getters; the canonical guard must classify, never throw.
* test(normalization-core): annotate intentional hostile-thenable fixture
2026-08-10 22:50:48 -07:00
Peter Steinberger
069f6e1c34
test(plugins): reuse Vitest for doctor contracts ( #121878 )
...
Amp-Thread-ID: https://ampcode.com/threads/T-019fee8d-665d-707b-a380-23f2a6a1ce03
Co-authored-by: Amp <amp@ampcode.com >
2026-08-10 22:49:40 -07:00
Peter Steinberger
eb28964522
test(plugins): remove provider family meta-test ( #121875 )
2026-08-10 22:46:34 -07:00
Peter Steinberger
36fbd869ed
refactor(agents): eliminate export name collisions ( #121768 )
...
* refactor(auth): consolidate profile helper owners
* refactor(agents): consolidate subagent registry reads
* refactor(agents): disambiguate runtime placement helpers
* refactor(agents): disambiguate helper exports
* chore(scripts): burn export collision debt
* test(agents): follow moved subagent read owner
2026-08-10 22:24:33 -07:00
Josh Avant
73a9eed95b
refactor(audit): add canonical admitted-run context ( #120534 )
...
* feat(audit): carry canonical admitted execution context
* fix(agents): preserve admitted context across retries
* fix(worker): fence legacy launch dialect
* test(gateway): track approval temp dirs
* fix(plugin-sdk): preserve harness attempt compatibility
* fix: close delegated run authority at owner boundaries
* fix: internalize delegated authority validators
* refactor: split delegated authority proof surfaces
* refactor: centralize command admission identity
* test: claim runtime tool authority
* fix(gateway): keep lifecycle cleanup within static budgets
* fix(agents): revalidate harness policy authority
* fix(agents): fence awaited approval capability results
* test(copilot): supply required harness capability fixtures
* fix(agent): preserve scoped embedded run admission
* fix(agent): preserve keyless and worker authority
* test(agent): bind incomplete-turn authority
* docs: preserve execution authority invariants
* chore(plugin-sdk): regenerate API baseline
* fix(gateway): notify pending claim closure
* fix(gateway): revalidate delegated tool authority
* fix(plugin-sdk): keep source guard internal
* fix: close delegated authority races
* fix: revalidate delegated side effects
* fix: close harness authority projection gaps
* fix: align authority integration types
* fix: isolate settled harness finalization
* fix: fence recovery identity finalization
* fix: preserve committed session worktrees
* fix: preserve worker placement agent identity
* fix: fence active harness tool work
* fix(plugins): restore embedded run admission owner
* chore(plugin-sdk): compose integrated surface budgets
* fix(copilot): keep finalization attempt type internal
* fix(plugins): complete admission owner type imports
* test(harness): use settled finalization attempt shape
* fix(security): retain exact side-run and approval authority
* fix(security): preserve protected authority through terminal sweep
* fix(agents): follow moved recovery store owner
* fix(ci): align integrated authority owners with gates
* fix(plugins): distinguish embedded agent adapter export
* chore(plugin-sdk): regenerate API baseline after rolling integration
* refactor(gateway): keep session authority within owner budgets
* fix(gateway): keep session helpers private
* docs(plugin-sdk): name the V2 parameter subpath
* chore(integration): reconcile worker and SDK surfaces
* docs(plugin-sdk): require the V2 host API floor
* chore(plugin-sdk): regenerate after proxy-auth integration
2026-08-10 23:15:20 -05:00
Peter Steinberger
b5d5ec340f
feat(cloud-workers): add desktop apps and browser autonomy ( #121475 )
...
* feat(cloud-workers): add desktop apps and browser autonomy
provider-attested Browser/Terminal launchers, shared visible loopback CDP Browser tool, no MCP/cookies/generic command.
* feat(ui): add cloud desktop app launcher
* docs(gateway): document cloud desktop apps and browser autonomy
* perf(ui): trim desktop launcher startup copy
* refactor(ui): simplify desktop launch feedback
* perf(ui): reuse desktop app labels
* fix(ui): keep desktop launch failures actionable
* fix(crabbox): allow browser bootstrap to finish
* fix(cloud-workers): honor provider provision budgets
* fix(cloud-workers): persist browser screenshot receipts
* fix(cloud-workers): bound browser screenshot lifecycle
* fix(cloud-workers): avoid replaying desktop launches
* test(cloud-workers): isolate browser runtime integration
* refactor(cloud-workers): tighten desktop runtime boundaries
* test(cloud-workers): keep browser runtime mock synchronous
* fix(cloud-workers): break gateway type import cycle
* fix(ci): settle admitted setup sessions in tests
* build(plugin-sdk): refresh desktop app contract
* ci: refresh merge-tree validation
* build(plugin-sdk): regenerate desktop app baseline
* style(gateway): format merged method order test
2026-08-10 20:31:07 -07:00
Peter Steinberger
d6f70a96cb
fix(plugins): native commands execute the selected plugin ( #121544 )
...
* fix(plugins): preserve selected command identity
* test(telegram): use scoped command registries
* test(telegram): isolate command runtime fixtures
* test(telegram): warm native command runtime
* refactor(plugins): keep command metadata private
* fix(plugins): accept synchronous command handlers
* fix(plugins): scope command drain bypass to live execution
* test(telegram): use scoped command registry fixtures
* test(telegram): isolate native menu runtime fixtures
* test(telegram): isolate login session store
* test(telegram): surface login flow failures
* test(telegram): preload native login module
* test(telegram): scope native command registries
* fix(plugins): complete command dispatch contracts
* fix(plugins): break command dispatch import cycles
* fix(plugins): stabilize command dispatch contracts
* fix(channels): keep plugin dispatch options internal
* fix(plugins): keep command dispatch carrier opaque
* test(channels): align delivery adapter fixtures
* test(delivery): align custody ownership coverage
* test(delivery): align latest queue reconciliation
* test(channels): drop obsolete delivery wrappers
* fix(plugins): rebind channel reload starts
* fix(plugins): scope command catalog reloads
* fix(ci): align current runtime contracts
* chore(plugin-sdk): refresh API baseline
2026-08-10 19:30:47 -07:00
Jesse Merhi
d90e47783d
fix(plugins): remove local dependency denylist ( #101813 )
2026-08-11 12:21:29 +10:00