Commit Graph

4556 Commits

Author SHA1 Message Date
Peter Steinberger 0b080b9c2e feat(apps): native session-list observer digests on iOS, Android, and macOS (#112597)
* feat(apps): native session-list observer digests on iOS, Android, and macOS

* fix(apps): satisfy swift, periphery, and lint gates for native digests
2026-07-22 01:53:29 -07:00
Peter Steinberger e10d004257 feat(agents): mobile_ui agent tool (PR 3/3) (#112255)
* feat(agents): mobile_ui agent tool for Android UI control (PR 3/3)

Add a dedicated model-facing tool that drives another Android app through the
PR2 mobile.ui.observe/act node commands, completing the vertical slice
(agent -> tool -> node.invoke -> AccessibilityService).

- Mirrors the desktop computer tool's safety model: owner-only + HTTP-denied
  (dangerous-tools), raw node.invoke of mobile.ui.* redirected to this tool so
  the generic nodes tool cannot bypass it, run/tool-call idempotency, and the
  phone-arm workflow (mobile.ui.* must be explicitly armed).
- One call is observe or one act; every act automatically re-observes for
  postcondition verification and preserves the landed outcome if re-observe fails.
- Fail-closed confirmation: all state-changing acts (activate, set_text, tap,
  swipe) require confirmed=true after the model reviews the proposed effect;
  observe, scroll, wait, and navigation global_actions do not. The keyword list
  only enriches the confirmation message and is never the sole gate (a11y labels
  are localized/iconographic/coordinate-blind).
- Node selection resolves an explicit id against the full device set first
  (case-insensitively) and rejects an ineligible or ambiguous match, so an
  explicit selection can never be silently redirected to the wrong phone.
- All observed UI text is treated as untrusted; the tool description forbids
  following instructions found in app UI.

Additive; no protocol bump. mobile-ui-tool + registration + policy tests pass;
core tsgo and lint verified on Testbox. On-device drive is exercised via the
PR1/PR2 emulator proof; this PR is the agent-side tool + tests.

Follow-up: computer-tool.ts has the same latent node-resolution ordering bug
(explicit id searched only among eligible nodes); tracked separately.

* fix(agents,phone-control): migrate mobile_ui arming hints/tests to gateway.nodes.commands.allow

Match main's node-command arming rename (gateway.nodes.allowCommands ->
gateway.nodes.commands.allow / commands.deny): update the mobile_ui tool arm-hint
matchers to the gateway's current rejection strings and fix the phone-control /
tool tests to the current config shape. Production write path was already correct.

* fix(agents): register mobile_ui in owner-only denylist; trim phone-control under max-lines

- tool-resolution.exclude.test.ts: mobile_ui joins the owner-only core
  tools, so add it to the expected plugin/inherited denylists.
- phone-control: derive ArmGroup from a single ARM_GROUPS const and
  collapse parseGroup's ||-chain, dropping index.ts back under 700 lines.

* fix(agents): centralize mobile_ui global-action names; regenerate tool-display snapshot

- Extract GLOBAL_ACTION_NAMES const so the schema, action type, and
  validator share one source. This also removes the bare `name: "back"`
  type-annotation literal that scripts/tool-display.ts's name-regex was
  misreading as a phantom runtime tool.
- Regenerate apps/.../tool-display.json to add the mobile_ui display entry
  (was missing from the Swift snapshot).
2026-07-22 01:49:14 -07:00
Peter Steinberger d4f19bfd79 feat(sessions): first-class archived-session handling (tri-state filter, pruning exemption, inline archived UI) (#112554)
* feat(sessions): first-class archived-session handling

Archived sessions are now exempt from every automatic maintenance path
(age prune, entry cap, model-run prune, disk budget, cleanup repairs);
only explicit sessions.delete removes them. sessions.list gains an
additive tri-state archived filter (true | false | "all"). The sidebar
gets a persisted Active/Archived/All status filter with inline dimmed
archived rows, replacing the nav-away View-archived button; the Sessions
page toggle becomes the same tri-state with dimmed+badged rows in All
mode; the chat composer's archived notice becomes a full-width banner
with an Unarchive action.

* chore(protocol): regenerate Swift gateway models for tri-state archived filter
2026-07-22 01:28:53 -07:00
Peter Steinberger d899dd7682 feat(android,gateway): mobile.ui node commands (PR 2/3) (#112241)
* feat(android,gateway): expose mobile.ui.observe/act as node commands (PR 2/3)

Wire the PR1 AccessibilityService executor over the existing node.invoke
transport. Additive: no gateway protocol version bump.

- New commands mobile.ui.observe / mobile.ui.act (capability mobileUI),
  generated into the protocol constants.
- thirdParty MobileUiHandler owns one mutex-serialized AccessibilityActionExecutor
  and bridges JSON <-> the PR1 snapshot/action model; play flavor ships a
  permanently-unavailable no-op stub (Play APK stays accessibility-free).
- Commands advertised only when accessibilityControlEnabled and the service is
  connected; NodeRuntime refreshes the advertised surface on connect/disconnect.
- Classified dangerous in node-command-policy (declarable-but-armed, mirroring
  computer.act): the transport cannot invoke them until gateway.nodes.allowCommands
  explicitly arms them. Screen reads are treated as dangerous too, so observe is
  gated as well as act.

Both flavors assemble; thirdParty/play unit tests, ktlint, android lint, and the
gateway node-command-policy tests pass; protocol generator is idempotent; Play
APK verified to contain zero accessibility classes. Emulator: no regression to
PR1 dev-screen observe.

* fix(gateway): migrate mobile.ui arming test/comment to gateway.nodes.commands.allow

Main renamed the node-command arming config from gateway.nodes.allowCommands to
gateway.nodes.commands.allow; update the mobile.ui policy test config shape and
the comment to the current contract. Production resolution already reads the new
path.

* chore(android): update native i18n baseline for PR2 line-number shifts
2026-07-22 01:10:49 -07:00
Peter Steinberger 9c7b034005 feat(android): port the zen, drummer, and peekaboo claw stances (#112571)
* feat(android): add rare claw stances

* chore(i18n): refresh native source anchors
2026-07-22 01:09:08 -07:00
Peter Steinberger 5610f24fc8 feat(apple): port the zen, drummer, and peekaboo claw stances (#112570)
* feat(apple): add rare working claw stances

Add zen, drummer, and peekaboo animations to the shared iOS and macOS working indicator, with deterministic stance and pose coverage.

* chore(i18n): refresh native source anchors
2026-07-22 01:06:51 -07:00
Peter Steinberger 88bf2d3350 test(macos): isolate flaky gateway and worker tests (#112563) 2026-07-22 00:37:58 -07:00
Peter Steinberger 12df806e90 feat(android): AccessibilityService UI executor (thirdParty, PR 1/3) (#112232)
* feat(android): AccessibilityService UI executor (thirdParty, PR 1/3)

Add a thirdParty-flavor-only AccessibilityService that observes the active
app's UI as a bounded semantic snapshot and performs typed actions, exercised
via a local developer screen. No gateway/agent wiring yet (PR 2 adds
node.invoke commands, PR 3 the agent tool + policy gates).

- Play APK stays accessibility-free: service, config, executor, and UI live
  entirely under src/thirdParty; SensitiveFeatureConfig.accessibilityControlEnabled
  gates it. Verified: 0 accessibility refs in every merged Play manifest and
  0 accessibility classes in the Play dex.
- Semantic-first executor: observe() returns a bounded snapshot (node/depth/text
  caps, deterministic order, password + sensitive-field redaction, stable action
  vocabulary, generation-scoped refs); act() performs one typed action with a
  closed ActionOutcomeCode result set.
- Safety model: coordinate gestures gated by package-match (fail-closed) + a UI
  epoch advanced on window/content/scroll/text mutation events; node actions
  gated by package-match + per-node refresh(); global actions ungated. Capture
  runs off the main thread. Dev UI honestly disables cross-app node controls
  (only reachable while the target is foreground; validated via the remote path).

Built and emulator-tested on API 36: live connection status, immediate observe,
a 103-node cross-app Settings capture, and global Home. Both flavors assemble;
thirdParty unit tests, ktlint, and android lint pass.

* feat(android): gate accessibility control behind an off-by-default opt-in

Make landing the accessibility feature a no-op for existing thirdParty users:
the service is invisible and inert until the user explicitly opts in.

- The AccessibilityService and its dev activity are declared
  android:enabled="false", so a fresh install exposes NO new accessibility
  service in system settings and nothing can bind it (verified on device:
  absent from the installed-services list and unbindable; shell cannot enable
  it either — only the app can).
- New thirdParty-only "Control other apps" toggle (persisted in the existing
  openclaw.node prefs, default OFF). Turning it on enables both components via
  PackageManager.setComponentEnabledSetting and deep-links to Accessibility
  settings so the user can grant it; turning it off disables them again
  (DONT_KILL_APP). A disclosure describes what enabling does.
- Play flavor is a no-op (FlavorPhoneCapabilitiesSettings = Unit); no
  accessibility component/controller/toggle references reach the Play APK.
- No new permissions or dependencies. The compile-time flavor gate and the
  gateway dangerous-command arming remain as additional layers.

* chore(android): update native i18n baseline for accessibility control strings
2026-07-22 00:36:13 -07:00
Peter Steinberger 59f63ccc3b refactor: declare subagent spawn lineage explicitly so forks and dashboard chats stay spawn-capable (#112535)
* refactor(gateway): declare spawn lineage explicitly at sessions.create

Spawn depth is now a declared fact, never inferred from parentSessionKey.
sessions.create accepts an optional spawnDepth (requires parentSessionKey) that
spawn-owned creations pass; every other fresh session persists spawnDepth 0,
making operator chats and UI forks spawn-capable roots. The visible spawn tool
declares callerDepth + 1, and subagent depth recovery no longer walks
parentSessionKey, which is UI threading only.

Accepted tradeoff (documented inline): pre-upgrade visible children whose only
lineage was parentSessionKey resolve as roots; the transient population may
spawn one extra generation, still capped by maxChildrenPerAgent.

* chore(protocol): regenerate Swift gateway models for sessions.create spawnDepth
2026-07-21 23:58:19 -07:00
Peter Steinberger 9231bcb38f fix(macos): keep permissions reachable on short screens (#112507)
* fix(macos): keep permissions reachable on short screens

* fix(macos): preserve onboarding i18n inventory
2026-07-21 21:53:07 -07:00
Peter Steinberger e81a2ce657 feat(ui): show chat run startup status (#112339)
* feat(ui): show chat run startup status

* refactor(agents): isolate run status emission

* chore(protocol): refresh startup status models

* refactor(swift): remove unused chat helpers

* test(swift): align retry and i18n fixtures

* fix(swift): restore outbox display helper
2026-07-21 21:25:23 -07:00
Peter Steinberger 1a8583ba45 feat(gateway,ui): ask-the-observer questions from the session HUD (#112448)
* feat(gateway,ui): ask-the-observer card input over sessions.observer.ask

* refactor(ui): single home for observer run-identity helper after restack

* test(ui): drop duplicated observer hud test after restack

* test(ui): give the observer ask flow its own colocated suite

* refactor(gateway): leaf observer contract and ask module split for ci gates

* refactor(gateway): drop observer contract re-export shims
2026-07-21 20:59:32 -07:00
Peter Steinberger c23ca5fda2 fix(linux): hide Quick Chat before widget cleanup (#112308) 2026-07-21 20:07:56 -07:00
Peter Steinberger 6c3caa38ab fix(ui): allow direct sessions in non-Git folders (#112433)
* fix(ui): allow direct sessions in non-Git folders

* test: align New Session fixtures with place picker

* fix(ui): preserve worktree intent on Git probe failures

* fix(types): keep worktree status alias internal
2026-07-21 19:36:53 -07:00
github-actions[bot] a8537805bd chore(i18n): refresh native locales 2026-07-22 10:22:42 +08:00
Peter Steinberger 0f066eec81 feat(dashboard): plugin widget kinds — native WorkBoard card and mini-board widgets (#112434)
* feat(board): add plugin widget kinds

* feat(ui): render native Workboard widgets

* fix(dashboard): compose plugin widgets with current main

* chore: internalize widget-kind contribution types

* fix(ui): retry plugin widget renderer loads

* fix(ui): harden Workboard widget refresh lifecycle

* fix(ci): clear plugin widget landing gates

* fix(boards): migrate plugin widget storage

* fix(db): migrate unreleased board widget constraint

* fix(ui): retry failed Workboard widget loads

* fix(ui): keep stale widget refresh cleanup inert

* fix(ci): align plugin widget landing guards
2026-07-21 17:59:20 -07:00
Peter Steinberger 1f0a3ecc68 feat(ui): session observer HUD, sidebar subtitles, and settings (#112260)
* feat(ui): session observer HUD, subtitle integration, and settings

* test(ui): observer demo fixtures for the mock control-ui harness

* fix(ui): satisfy lint and deadcode gates for observer surfaces

* test(ui): adopt renamed pull-request summary api after rebase

* fix(ui): clean rebase artifacts in observer test files
2026-07-21 17:05:14 -07:00
Vincent Koc 461583b5e3 chore(i18n): refresh Android branch count inventory 2026-07-22 06:33:27 +08:00
Vincent Koc 116a38c167 test(android): cover locale-neutral branch counts 2026-07-22 06:33:27 +08:00
Vincent Koc b622fc74c8 fix(android): make branch counts locale-neutral 2026-07-22 06:33:27 +08:00
Peter Steinberger c84921634d fix(macos): require explicit consent for privacy-sensitive access (#112321)
* fix(macos): avoid passive Automation prompts

* fix(macos): keep Voice Wake recognition on device

* fix(macos): require consent for activity presence

* chore(apps): refresh native i18n inventory

* fix(macos): preserve presence clears across gateway versions

* fix(macos): prioritize activity privacy opt-out

* chore(apps): refresh native i18n inventory

* fix(macos): scrub legacy presence activity

* fix(macos): migrate permission status caller

* fix(macos): preserve unknown permission state

* fix(macos): refresh privacy change artifacts

* refactor(macos): remove stale presence helper

* fix(deps): patch URI and Jaeger advisories

* test(gateway): adopt pairing-bound node sessions
2026-07-21 15:28:13 -07:00
Peter Steinberger b36342ee6f feat(android): chat rewind/fork actions and branch switcher with branch-safe outbox (#112284) 2026-07-21 14:31:47 -07:00
Jason (Json) 35e058711d fix(macos): reuse gateway with path advisory (#112381) 2026-07-21 15:17:47 -06:00
Peter Steinberger bd03b4d658 fix(i18n): regenerate native locale artifacts after Android inventory drift 2026-07-21 14:15:31 -07:00
Vincent Koc 5b2a084048 fix(i18n): refresh iOS location menu inventory 2026-07-22 05:11:45 +08:00
joshavant a69ebf3067 fix(ios): keep snapshot results outside upload tree 2026-07-21 13:44:11 -05:00
joshavant b3cdb49aca test(ios): stabilize appearance screenshot 2026-07-21 13:44:11 -05:00
joshavant 12515ad182 fix(ios): harden App Store release flow 2026-07-21 13:44:11 -05:00
Peter Steinberger 8f31892b55 feat(apps): native session branch switcher with branch-safe durable outbox (#112056)
Branch menu (list/switch) for macOS+iOS shared chat via sessions.branches.*;
rewind/fork/switch gated on run activity and pending outbox work through a
durable session-mutation lease; outbox rows carry branch-epoch ownership with
local-only flush checks, atomic confirm/park transitions, attempt-versioned
delivery callbacks, fresh retry identity for possibly-accepted rows, and
epoch-guarded branch evidence; 21-locale native translations for new strings.
2026-07-21 10:59:44 -07:00
Peter Steinberger 26165bbe80 fix(ios): smooth sidebar drags and remove background seams (#112299)
* fix(ios): polish sidebar drawer interaction

* fix(ios): latch sidebar drag direction
2026-07-21 08:40:30 -07:00
Peter Steinberger 5e7cb225e4 fix(mobile): load pinned and base-path Control UI pages (#112175)
* fix(mobile): harden Control UI webviews

* refactor(mobile): keep native inventory stable

* docs(android): clarify shared pinned trust

* fix(ios): preserve encoded Control UI base paths
2026-07-21 08:19:07 -07:00
Peter Steinberger 3a1351a303 fix(cron): show script automations across user clients (#112195)
* fix(cron): preserve script jobs across clients

* chore(i18n): refresh native cron strings

* chore(i18n): align rebased native catalogs

* chore(i18n): defer generated locale refresh
2026-07-21 08:02:59 -07:00
Papilionidae 3dfb4c9cd7 fix(anthropic): accept "cli" entrypoint in Claude session catalog discovery (#105162)
* fix(anthropic): accept "cli" entrypoint in Claude session catalog discovery

Claude Code v2.x writes entrypoint: "cli" in its JSONL session files.
Previously only "sdk-cli" was recognized, causing all v2.x sessions to
be silently skipped.

Extract CLI_ENTRYPOINTS set and isCliEntrypoint() helper, then apply
the same fix to both TypeScript catalog and macOS paired-node native
catalog. Add matching regression coverage on both platforms.

Closes #105164

* fix(anthropic): refresh Claude CLI session discovery

Apply the reviewed cli/sdk-cli allowlist, mirrored negative coverage, and fallback-scope documentation to current main.

Co-authored-by: 黄攀0668000858 <huang.pan@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-21 07:14:42 -07:00
liuhao1024 cd38cdef05 fix(macos): respect OPENCLAW_STATE_DIR in openclaw-mac CLI config resolution (fixes #98591) (#98631)
* fix(macos): resolve OPENCLAW_STATE_DIR in openclaw-mac CLI config resolution

Add shared resolveOpenClawConfigURL() to GatewayConfig.swift with
precedence: OPENCLAW_CONFIG_PATH > OPENCLAW_STATE_DIR > default home.
Switch ConfigureRemoteCommand and loadGatewayConfig to use it.
Add focused tests for all three precedence paths.

* fix(macos): honor state directory in openclaw-mac

Use one normalized config resolver for connect, wizard, and configure-remote, with explicit config path precedence over the selected state directory.

Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-21 05:59:21 -07:00
Vincent Koc 8187c09a58 style(android): satisfy compact token ktlint 2026-07-21 20:54:26 +08:00
Vincent Koc 85ba26ebad fix(android): localize compact token suffixes 2026-07-21 20:54:26 +08:00
Peter Steinberger e5610976cf fix(linux): harden Quick Chat widget lifecycle (#112261)
* fix(linux): harden Quick Chat widget lifecycle

* fix(linux): retry stale widget cleanup before reveal
2026-07-21 05:35:06 -07:00
Peter Steinberger b2aa21612d feat(ui): show PR status on Claude threads (#112180)
* feat(ui): show PR status on catalog threads

* fix(ui): complete PR summary protocol artifacts

* perf(anthropic): bound PR metadata deduplication
2026-07-21 05:01:04 -07:00
Peter Steinberger aeeff149b9 feat(android): port the working claw indicator, wait phrases, and turn recap (#112221)
* feat(android): decode session run metadata

* feat(android): animate the working claw

* feat(android): show settled turn recaps

* fix(android): preserve legacy cache migration

* fix(android): expire hidden recap watches

* chore(i18n): refresh native source anchors

* fix(android): drop unsettled hidden recaps

* fix(android): keep claw timing local

* fix(android): anchor settled turn recaps

* chore(i18n): refresh native source anchors after rebase

* fix(android): route chat status copy through native i18n
2026-07-21 04:43:27 -07:00
Peter Steinberger 8481c69cbe feat(apple): port the working claw indicator, wait phrases, and turn recap to iOS/macOS (#112188)
* feat(chat): add native working progress state

* feat(chat): port working claw indicator to Apple

* fix(apple): isolate generated locale catalog

* style(apple): use doc comments on ChatWorkingPhrase API declaration
2026-07-21 04:35:27 -07:00
Peter Steinberger 89fe452991 feat(gateway): session observer digests over the utility model (#112216)
* feat(gateway): session observer digests over the utility model

* fix(gateway): split session-observer modules and satisfy ci gates

* fix(gateway): observer reads session entries without materializing agent state
2026-07-21 04:04:13 -07:00
Peter Steinberger 312e656138 fix(ios): show agent avatars and use more sidebar space (#112082)
* fix(ios): improve agent sidebar menu layout

* chore(i18n): refresh native source inventory
2026-07-21 03:05:18 -07:00
Vincent Koc c6c1151c3a build(i18n): generate Wear locale resources 2026-07-21 17:36:49 +08:00
Vincent Koc 6a26f9f383 fix(android): localize Wear connection failures 2026-07-21 17:36:49 +08:00
Vincent Koc d4021c351c fix(macos): localize settings surfaces (#112185) 2026-07-21 16:15:40 +08:00
Peter Steinberger 262deec72c feat(mobile): session Dashboard on iOS and Android via authenticated Control UI webview (#112163)
* feat(mobile): session dashboard screens on iOS and Android via authenticated Control UI webview

* fix(android): keep configured Control UI base path in session dashboard URL

* docs(android): note system-trust boundary of the shared Control UI webview

* fix(android): origin-only document-start rule for Control UI auth script

* chore(i18n): refresh native inventory on rebased head

* fix(ios): swiftlint closure form in session dashboard toolbar

* fix(i18n): tolerate workflow-owned pending native rows in PR alignment checks

* fix(android): KTX toUri per lint and refresh native inventory

* fix(android): ktlint import order incl. main-inherited fleet test, refresh inventory
2026-07-21 01:13:23 -07:00
Vincent Koc 9e0c5f94b5 fix(macos): support background-only launches (#112168)
* fix(macos): support background-only launches

* fix(macos): refresh native i18n inventory

* fix(i18n): refresh native inventory after main sync
2026-07-21 15:41:49 +08:00
Peter Steinberger 6d1c215a78 fix(macos): reject public plaintext Gateway profiles (#112161)
* fix(macos): reject public ws gateway profiles

* fix(macos): normalize bracketed private IPv6 hosts

* test(macos): preserve bracketed localhost policy
2026-07-21 00:35:13 -07:00
Vincent Koc 2c316f51f7 fix(apps): harden mobile gateway and watch state 2026-07-21 09:00:21 +02:00
joshavant 985ec0650f Android: record 2026.7.3 correction metadata 2026-07-21 01:16:42 -05:00