Commit Graph

5527 Commits

Author SHA1 Message Date
Dallin Romney dc34dc4ff3 test(release): align GPT-5.6 default contracts 2026-07-31 17:13:32 +08:00
Dallin Romney ec500af40a fix(release): isolate extended-stable Docker aliases (#112822)
* fix(release): isolate extended-stable Docker aliases

(cherry picked from commit db9915fedb)

# Conflicts:
#	.agents/skills/release-openclaw-maintainer/SKILL.md
#	.agents/skills/release-openclaw-maintainer/references/extended-stable-backports.md
#	.github/workflows/docker-release.yml
#	docs/docs_map.md
#	docs/install/docker.md
#	docs/reference/RELEASING.md

* fix(release): harden Docker channel promotion

(cherry picked from commit 505a6fe922)

* docs(release): pin Docker policy into tagged tree

(cherry picked from commit 3ff98457ba)

# Conflicts:
#	.agents/skills/release-openclaw-maintainer/SKILL.md
#	.agents/skills/release-openclaw-maintainer/references/extended-stable-backports.md
#	docs/reference/RELEASING.md

* refactor(release): isolate Docker channel promotion

(cherry picked from commit 3d02c5c821)

# Conflicts:
#	.agents/skills/release-openclaw-maintainer/SKILL.md
#	docs/reference/RELEASING.md

* fix(release): queue Docker publications

(cherry picked from commit b7cb1697ea)

* fix(release): harden docker channel promotion

(cherry picked from commit 7510aa52ce)

# Conflicts:
#	docs/reference/RELEASING.md
#	scripts/lib/npm-publish-plan.d.mts
#	scripts/lib/npm-publish-plan.mjs
#	scripts/openclaw-npm-postpublish-verify.ts

* fix(release): promote Docker aliases after verification

(cherry picked from commit a13cba1484)

# Conflicts:
#	.agents/skills/release-openclaw-maintainer/SKILL.md
#	docs/reference/RELEASING.md

* fix(release): harden Docker channel promotion

(cherry picked from commit ecc07ba7a3)

# Conflicts:
#	docs/ci.md
#	scripts/verify-docker-attestations.d.mts

* fix(release): adapt Docker promotion to maintenance policy helpers
2026-07-22 18:19:35 -07:00
Dallin Romney 496c84bf61 chore(release): prepare 2026.6.34 extended-stable (#112513)
* fix: gate diagnostics command to owners

(cherry picked from commit 170bf72e64)

* fix(agent): replace self-wait with deferred release in retained-lock abort cleanup (#96100)

* fix(agent): wait for retained session write before releasing held lock on abort

* fix(agent): replace self-wait with deferred release in retained-lock abort cleanup

* fix(test): reject fallback acquire with SessionWriteLockTimeoutError in active-scope cleanup test

* fix(agent): trim retained-lock comments

Signed-off-by: sallyom <somalley@redhat.com>

---------

Signed-off-by: sallyom <somalley@redhat.com>
Co-authored-by: sallyom <somalley@redhat.com>
(cherry picked from commit 0a042f68df)

* fix(gateway): resume channel after pending task recovery

(cherry picked from commit 6039da3ed6)

* fix(gateway): resume channel after pending task recovery

(cherry picked from commit ecd29fe572)

* fix(outbound): ignore empty delivery receipts (#79811)

(cherry picked from commit 9a735bea03)

* fix(agents): guard delivery-evidence attachment recursion against cycles (#97041)

* fix(agents): guard delivery-evidence attachment recursion against cycles

* fix(agents): guard delivery-evidence attachment recursion against cycles

* fix(agents): guard delivery-evidence attachment recursion against cycles

---------

Co-authored-by: Pick-cat <266665499+Pick-cat@users.noreply.github.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
(cherry picked from commit 498567190d)

* fix(opencode-go): re-arm idle timer on block-boundary events to prevent false stalled-stream abort (#97128)

* fix(opencode-go): re-arm idle timer on block-boundary events to prevent false stalled-stream abort

When the opencode-go model finalizes a tool call and deliberates before
the next one, the provider emits real block-boundary SSE events
(text_end, thinking_end, toolcall_start, toolcall_end) that prove the
socket is alive, but the watchdog's isProviderProgressEvent only
returned true for token deltas (text_delta, thinking_delta,
toolcall_delta). This caused the idle timer to fire and falsely abort a
live stream, replacing a completed answer with a stalled error and
dropping the provider's real done event.

Fix: include block-boundary events in isProviderProgressEvent so the
idle timer is re-armed on any forward-progress provider event.
text_start and thinking_start are intentionally excluded because they
are synthetic preamble events that should not shorten the first-event
window.

Closes #96518

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(opencode-go): satisfy lint in stream regression

* test(opencode-go): satisfy lint in stream regression

* test(opencode-go): satisfy lint in stream regression

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
(cherry picked from commit 552ec2b49d)

* fix(model-fallback): don't rethrow provider-side AbortErrors as user cancellations (#90908)

* fix(model-fallback): don't rethrow provider-side AbortErrors as user cancellations

When the LLM API closes the connection mid-stream, the fetch layer
surfaces AbortError("This operation was aborted") with no external
abort signal triggered. The old guard `shouldRethrowAbort()` returned
false for these errors (because isTimeoutError matched the message),
so they fell through to the fallback loop but were never retried —
the error propagated up and produced SILENT_REPLY_TOKEN in group
sessions, permanently silencing the topic.

Replace the guard with a direct check: only rethrow AbortError when
the external abort signal is actually set (user/gateway cancellation).
Provider-side AbortErrors without an external signal now fall through
to the next fallback candidate, giving the system a chance to recover.

* fix(cron): forward abort signal into runWithModelFallback

Thread the cron executor's abort signal into the shared
runWithModelFallback call so that cron timeouts and cancellations
stop the fallback chain instead of retrying with the next candidate.

Previously, the run callback checked params.abortSignal?.aborted and
threw, but runWithModelFallback itself had no signal — so the new
guard in model-fallback.ts could not distinguish a caller abort from
a provider-side AbortError and would retry silently.

Also adds a focused regression test verifying the signal is forwarded.

---------

Co-authored-by: Shengting Xie <shengting@openclaw.ai>
Co-authored-by: yayu <yayu@yayuMacStudio.local>
(cherry picked from commit 98ed83f848)

* fix(browser): block node routes when sandbox host control is disabled (#97958)

(cherry picked from commit 2cf765f732)

* fix(exec): bind Windows allowlist execution path (#98260)

* fix(exec): bind windows allowlist execution path

* fix(exec): add windows shadow execution proof

* fix(exec): preserve wildcard allowlist behavior

* fix(exec): correct blocked plan test fixture

(cherry picked from commit 3811001d27)

* fix(mcp): suppress unhandled error on stderr pipe in stdio transport (#99803)

* fix(mcp): suppress unhandled error on stderr pipe in stdio transport

When child.stderr is piped to stderrStream without an error
handler, a stream-level error (EPIPE, I/O failure) crashes the
process. Add a noop error handler before the pipe, consistent
with the error handlers already present on stdin and stdout.

Co-Authored-By: Claude <noreply@anthropic.com>

* test(mcp): add regression test for stderr pipe error suppression

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(mcp): report stderr stream errors

* fix(mcp): report stderr stream errors

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
(cherry picked from commit 1b84316a91)

* Harden macOS SQLite WAL checkpoints (#99067)

(cherry picked from commit f7f1be276a)

* fix(secrets): suppress unhandled stdout/stderr stream errors in exec resolver (#100521)

* fix(secrets): suppress unhandled stdout/stderr stream errors in exec resolver

* proof(secrets): add real behavior proof script for exec resolver stream error catch

* proof(secrets): replace wrapper with real exec resolver stream error proof

* style: apply oxfmt to changed files

(cherry picked from commit c9a0783922)

* fix(agents): retry transient filesystem races when reading workspace bootstrap files (#100910)

* fix(agents): retry transient filesystem races when reading workspace bootstrap files

* fix(agents): retry transient boundary resolution

---------

Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>
(cherry picked from commit f36d170bc6)

* fix(gateway): finish plugin HTTP responses after post-header failures (#102125)

* fix(gateway): finish plugin HTTP responses after post-header failures

* test(gateway): satisfy plugin HTTP regression lint

* fix(gateway): skip ending destroyed plugin responses

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
(cherry picked from commit 240d350c7f)

* fix(gateway): validate exact custom browser origins (#38290)

Co-authored-by: Peter Steinberger <steipete@gmail.com>
(cherry picked from commit fa0349aa44)

* fix: block unspecified trusted DNS targets (#103075)

(cherry picked from commit c70f3d0dae)

* fix(channels): make nack callbacks idempotent (#104919)

* fix(channels): make nack callbacks idempotent

* fix(channels): coalesce overlapping nack callbacks

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
(cherry picked from commit 02d307e1b8)

* fix(channels): prevent base URL credentials in status output (#107754)

* fix(channels): redact credentials in account URLs

* fix(channels): sanitize final status summaries

(cherry picked from commit 210340fe93)

* fix(channels): prevent lifecycle listener buildup (#109108)

(cherry picked from commit 0e1fad711c)

* fix(sandbox): use Buffer.byteLength for env var value size limit (#105017)

* fix(sandbox): use Buffer.byteLength for env var value size limit

validateEnvVarValue checked value.length (UTF-16 code units) against
the 32768-byte limit, so multi-byte CJK values like "值".repeat(11000)
passed the check despite exceeding 33 KB in UTF-8. Switch to
Buffer.byteLength(value, "utf8") so the limit matches the actual byte
count the OS and child processes see.

* test(sandbox): simplify env byte-limit coverage

Co-authored-by: 唐梓夷0668001293 <tang.ziyi@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
(cherry picked from commit 84fb48c3be)

* fix(gateway): guard process.kill ESRCH race in signalVerifiedGatewayPidSync (#109590)

* fix(gateway): guard process.kill ESRCH race in signalVerifiedGatewayPidSync

A verified gateway process can exit between the argv validation check and
the process.kill call, causing an unhandled ESRCH error. Wrap the kill in
try-catch and silently swallow ESRCH (process already gone = signal
already delivered).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* docs(gateway): explain ESRCH signal race

Co-authored-by: 丁宇婷0668001435 <ding.yuting@xydigit.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
(cherry picked from commit 853b1a8d11)

* fix(litellm): guard loopback hostname auto-allow with isIP to prevent DNS SSRF bypass (#110693)

* fix(litellm): guard loopback hostname auto-allow with isIP to prevent DNS bypass

The isAutoAllowedLitellmHostname helper auto-enables private-network access
for loopback-style hosts. Before this fix, lowered.startsWith("127.")
matched DNS hostnames like 127.evil.com, letting remote endpoints bypass
the explicit allowPrivateNetwork opt-in — a SSRF risk.

Add isIP(host)===4 guard so only literal IPv4 loopback addresses qualify.
Same canonical pattern as extensions/slack/src/monitor/relay-source.ts:271
and the codex loopback fix.

Co-Authored-By: Claude <noreply@anthropic.com>

* test(litellm): cover loopback endpoint policy

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
(cherry picked from commit 3d03b60da9)

* fix(discord): sustained gateway bursts stop growing memory (#110954)

* fix(discord): sustained gateway bursts stop growing memory

* fix(discord): contain gateway queue overflow

* fix(discord): drop oldest saturated gateway sends

Co-authored-by: 张贵萍0668001030 <zhang.guiping@xydigit.com>

* fix(discord): surface gateway overflow warnings

Co-authored-by: 张贵萍0668001030 <zhang.guiping@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
(cherry picked from commit 69aeba9d86)

* fix(gateway): bound busy channel health by real run age (#103793)

* fix(gateway): bound busy channel health by real run age

The channel health policy treats a channel as healthy-busy even while
disconnected, bounded only by a 25 minute stale ceiling measured from
lastRunActivityAt. The run-state heartbeat refreshes lastRunActivityAt
every 60 seconds for as long as any run is active, so a run that hangs
forever (for example a send blocking on a dead socket after the
transport already reported connected:false) keeps that timestamp fresh
and the stuck ceiling is never reached. The account is then reported
healthy forever by the health monitor, readiness probe, and health CLI,
and no restart ever fires.

createRunStateMachine now tracks each in-flight run's start time keyed by
an opaque run handle and publishes the oldest still-active run's start as
activeRunStartedAt. The health policy busy override keys its ceiling off
the real run age, so a run stuck longer than the threshold reports stuck
and the monitor can restart it. Because the reported start is the oldest
active run and advances to the next-oldest as runs complete, a channel
churning through many short overlapping runs (activeRuns above 1 across
concurrent queue keys) stays healthy; only a genuinely hung run breaches
the ceiling. Short and active runs stay healthy and the existing
lastRunActivityAt fallback is preserved for snapshots without a start
time.

* fix(channels): retain run-state callback compatibility

Keep the released zero-argument onRunEnd callback source-compatible while allowing internal queue callers to pass a run handle for exact concurrent-run accounting. The compatibility path closes the oldest active run, preserving existing lifecycle behavior for consumers that do not use handles.

* fix(channels): keep anonymous runs out of age tracking

The zero-argument lifecycle callbacks cannot identify which concurrent run completed, so they must not update the identity-sensitive run start used by channel health. Keep their busy count separately and reserve exact start tracking for the shared queue's handle-aware lifecycle path.

* fix(channels): keep tracked runs internal

Keep the public run-state lifecycle callbacks unchanged. The channel queue now owns opaque run identity and augments its status updates with the oldest active queue run, so implementation details do not expand the SDK surface.

* fix(channels): type queue run start status

Keep activeRunStartedAt in the internal status patch type so the queue can publish its private tracked-run age through the existing status sink.

* fix(channels): wrap isActive to satisfy unbound-method lint

* fix(gateway): gate busy run-age ceiling on disconnected transport

(cherry picked from commit 18b79d99ab)

* fix(deps): update fast-uri past advisory

(cherry picked from commit 1be9db038f)

* fix(release): adapt maintenance-line hardening

Backport/adapt 18ec9ce8f7, dea1fe1f11, 7f32b6c984, 1da345e9d3, 931ac3e2b5, 89780d5a60, and c0d99ed26e for the 2026.6 extended-stable maintenance line.

* fix(deps): bump protobufjs to 7.6.5

Backport-adapted from a230f742f2.

* test(gateway): cover bounded macOS process probe

* chore(release): prepare 2026.6.34

* test(dotenv): share path override environment assertions

* fix(release): resolve 2026.6.34 CI blockers

---------

Signed-off-by: sallyom <somalley@redhat.com>
Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com>
Co-authored-by: Peter Lee <li.xialong@xydigit.com>
Co-authored-by: sallyom <somalley@redhat.com>
Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com>
Co-authored-by: Liu Wenyu <117838866+indulgeback@users.noreply.github.com>
Co-authored-by: pick-cat <huang.ting3@xydigit.com>
Co-authored-by: Pick-cat <266665499+Pick-cat@users.noreply.github.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
Co-authored-by: weiqinl <liu.weiqin@xydigit.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: shengting <xieyayu@163.com>
Co-authored-by: Shengting Xie <shengting@openclaw.ai>
Co-authored-by: yayu <yayu@yayuMacStudio.local>
Co-authored-by: Agustin Rivera <31522568+eleqtrizit@users.noreply.github.com>
Co-authored-by: cxbAsDev <chen.xianbiao@xydigit.com>
Co-authored-by: ooiuuii <al3060388206@gmail.com>
Co-authored-by: Masato Hoshino <g515hoshino@gmail.com>
Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: mushuiyu886 <yang.haoyu@xydigit.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Bruno Wowk (Volky) <bruno.wowk@gmail.com>
Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com>
Co-authored-by: Glucksberg <80581902+Glucksberg@users.noreply.github.com>
Co-authored-by: xingzhou <zhang.guiping@xydigit.com>
Co-authored-by: tzy-17 <tang.ziyi@xydigit.com>
Co-authored-by: krissding <ding.yuting@xydigit.com>
Co-authored-by: lsr911 <liao.shirong@xydigit.com>
Co-authored-by: Yuval Dinodia <102706514+yetval@users.noreply.github.com>
2026-07-21 22:13:20 -07:00
Dallin Romney cc4fc8c78f test: tolerate stale mcp pairing approvals
Backports the release-harness fix from a472002384 while keeping the regression test independent of built dist output.
2026-07-18 14:46:14 -07:00
Dallin Romney c257894946 fix(release): scan SQLite installer transcripts (#110266)
(cherry picked from commit 66e15906b5)

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-17 17:43:09 -07:00
Dallin Romney 30bde936ef fix(release): carry the Z.AI API Platform waiver (#110243)
* test(ci): temporarily omit Z.AI API Platform validation (#109246)

* test(ci): temporarily omit Z.AI API Platform validation

* test(ci): align disabled provider count

(cherry picked from commit 954c77d4ef)

* fix(release): keep waived Z.AI probe out of broad shard

Adapt the Z.AI shard portion of upstream c4b2183db6 (#109272). Exclude the waived API Platform file from the broad agents shard while retaining the dedicated Coding Plan proof.

(cherry picked from commit c4b2183db6)
2026-07-17 16:48:48 -07:00
Dallin Romney 6bcd4e0efe fix(release): route core to extended-stable
Adapt the closed publish-plan and tarball identity checks from upstream c7810fc697 for the v6.11 publisher.
2026-07-14 08:53:27 -07:00
Dallin Romney ad47bc72c7 fix(release): complete plugin npm preflight contract
Adapt the missing publish-tag and metadata-check portions of upstream 9d2d517296 and the pack-mode portion of 9eeebf7cb1.
2026-07-14 08:41:57 -07:00
Dallin Romney 24a7c9bff5 fix(release): restore extended-stable plugin plan
Adapt the missing publication-plan portion of upstream 9d2d517296 for the v6.11 release surface.
2026-07-14 08:29:34 -07:00
Dallin Romney 403d47ab9f fix(release): require publish-grade validation evidence 2026-07-14 07:46:03 -07:00
Dallin Romney 9a87128cea fix(release): validate candidate installer evidence 2026-07-14 07:13:01 -07:00
Dallin Romney 4a8e527f92 chore(plugin-sdk): account for provider text reader 2026-07-14 05:07:01 -07:00
Dallin Romney f70f268bc5 chore(plugin-sdk): refresh v6 surface budget 2026-07-14 03:56:25 -07:00
Dallin Romney 452d217984 fix(release): validate npm-only evidence versions 2026-07-14 03:44:00 -07:00
Dallin Romney 4588175df7 build(release): add release-note renderer prerequisite 2026-07-14 03:20:14 -07:00
Peter Steinberger c45dc961f5 fix(ci): validate frozen release candidates safely (#104697)
* fix(ci): validate frozen release candidates safely

* test(ci): align release workflow types

* fix(ci): validate frozen release tags safely

(cherry picked from commit dbdc61e897)
2026-07-14 03:17:16 -07:00
Vincent Koc 1281148184 improve(release): reuse exact-SHA validation evidence (#104162)
* perf(release): share changelog verification snapshots

* perf(release): reuse exact-SHA validation evidence

* feat(release): checkpoint candidate workflow state

* feat(release): watch CI transitions compactly

* fix(testbox): rotate stale reusable leases

* refactor(release): move CI verifier into scripts

* fix(release): preserve verifier executable mode

* fix(testbox): force noninteractive remote hydration

* perf(testbox): skip sync for proven clean heads

* fix(testbox): keep changed gates synchronized

* fix(testbox): isolate git state probes

* fix(testbox): isolate wrapper git commands

* fix(testbox): preserve git command contracts

* fix(release): validate reused SHA evidence

* fix(release): resume serialized plugin selections

* fix(testbox): sync source on every lease reuse

* fix(release): verify from trusted workflow checkout

* fix(release): gate evidence reuse on trusted lineage

* fix(release): support legacy verifier checkouts

* fix(testbox): export CI across shell snippets

* fix(release): revalidate reused evidence before publish

* fix(release): reject untrusted reuse before lookup

* fix(release): reuse SHA-pinned root evidence

* fix(ci): allow unreleased notes in QA packages

* fix(release): satisfy script lint contracts

* fix(release): handle Unicode workflow refs safely

(cherry picked from commit c47ceb0f3d)
2026-07-14 03:15:26 -07:00
Peter Steinberger 089fadb2f7 fix(release): keep validation evidence immutable across reruns (#103906)
* fix(release): bind validation evidence to exact attempts

* test(release): cover exact validation attempts

(cherry picked from commit fece8c9f54)
2026-07-14 03:12:05 -07:00
Vincent Koc 8dd6ce19c1 ci(release): add plugin npm artifact preflight (#103759)
* ci(release): add plugin npm preflight proof

* fix(release): bind plugin preflight package evidence

* fix(release): harden plugin preflight trust

* fix(release): bind plugin registry readback

* fix(release): retry npm packument bodies

* fix(release): retry malformed npm packuments

* fix(release): satisfy npm preflight lint

(cherry picked from commit daa653c5cc)
2026-07-14 03:08:07 -07:00
Vincent Koc e920880ca7 fix(release): make validation proof no-write (#103737)
* fix(release): make validation proof no-write

* test(release): align no-write workflow contracts

(cherry picked from commit cbe3731f77)
2026-07-14 03:06:41 -07:00
Vincent Koc 5e02ed4048 fix(release): validate exact prepared npm package sets (#102759)
* fix(release): validate prepared npm package sets

Forward-port the beta3 package-set preflight, Telegram, and Parallels validation to main while preserving main's existing Bun install smoke. Recompute decoded proxy response lengths and require artifact tarballs to exactly match the verified manifest.

* fix(release): lock fixture registry proxy origin

(cherry picked from commit 0535679083)
2026-07-14 02:56:25 -07:00
Kevin Lin 93ca33704b feat(update): support extended-stable package updates (#99811)
* feat(update): add extended-stable channel contract

* feat(update): implement extended-stable package flow

* docs(update): document extended-stable behavior

* fix(update): preserve extended-stable preflight guarantees

* fix(update): reject extended-stable Git repair

* fix(update): support loopback extended-stable canaries

* fix(update): preserve scoped package roots

(cherry picked from commit d214622320)
2026-07-14 02:43:39 -07:00
Dallin Romney d21c485f00 fix(installer): use supported Node 22 patch
(cherry picked from commit de63d91e4b)
2026-07-14 02:42:58 -07:00
Dallin Romney eaeb408205 fix(release): validate Claude smoke response exactly
(cherry picked from commit 79189a2cb1)
2026-07-14 02:42:29 -07:00
Peter Steinberger 8ea7470508 fix(release): avoid token-shaped Claude live probe (#103994)
(cherry picked from commit b71e0c78f0)
2026-07-14 02:42:29 -07:00
Vincent Koc b5a09dc300 fix(release): harden Claude CLI live probe
(cherry picked from commit ff5d3d06fb)
2026-07-14 02:42:29 -07:00
Dallin Romney 0a9400bb74 test(release): align codex guardian proof with auth mode
(cherry picked from commit abdae27b7a)
2026-07-14 02:42:09 -07:00
Peter Steinberger 5921671d39 fix(secrets): harden exec provider diagnostics (#105082)
(cherry picked from commit b6c171901e)
2026-07-14 02:24:09 -07:00
Peter Steinberger 8d13a35d51 fix(channels): tombstone corrupt ingress rows (#105259)
* fix(infra): guard channel ingress queue parseJson against corrupted JSON

* fix(infra): fix type assertion in ingress queue test

* fix(infra): use tagged parse result and validate payload before claiming

* fix(infra): remove unnecessary non-null assertion in ingress queue test

* fix(infra): scan corrupt ingress rows in claimNext

* test(gateway): avoid typed empty mock call tuple access

* fix(infra): tombstone corrupt ingress rows on duplicate enqueue and stale recovery

Two P1 gaps: enqueue() threw on duplicate when the existing row had corrupt
payload_json, and recoverStaleClaims() silently skipped corrupt claimed rows,
leaving them invisible to recovery. Both paths now tombstone the unrecoverable
row as failed with reason "corrupt_payload" and return a proper result.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(infra): resolve lint shadow and await-thenable in recoverStaleClaims

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix(channels): tombstone corrupt ingress rows

* test(channels): use explicit placeholder claim tokens

* refactor(channels): name claim token values

* refactor(channels): keep claim projection direct

* fix(channels): preserve active ingress claims

* fix(channels): make corrupt recovery policy-aware

* refactor(channels): name corrupt claim token

* fix(channels): bound corrupt ingress reconciliation

* fix(channels): paginate pending ingress by key

* refactor(telegram): return live owner check directly

* build(plugin-sdk): refresh public export budget

---------

Co-authored-by: Pick-cat <huang.ting3@xydigit.com>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
(cherry picked from commit a824078101)
2026-07-14 02:22:12 -07:00
Peter Steinberger c8c43e4e10 fix(doctor): keep automated repair from moving approval state (#103353)
* fix(doctor): isolate automated cross-state imports

* test(update): cover isolated doctor finalization

(cherry picked from commit cd9db5ed9a)
2026-07-14 02:10:23 -07:00
NIO cf6f4c9537 fix(telegram): bound Bot API response reads to prevent OOM (#97271)
* fix(telegram): bound Bot API response reads to prevent OOM

* fix(scripts): make proof-telegram-bound.mjs lint-clean

---------

Co-authored-by: NIO <nocodet@mail.com>
(cherry picked from commit a07d59e014)
2026-07-14 01:55:13 -07:00
Vincent Koc 0a4d0daa8c fix(parallels): stabilize Windows beta smoke transport 2026-06-28 11:47:10 -07:00
Vincent Koc d42b864219 fix(qa): accept pnpm separator for lab up (#96246) 2026-06-24 10:22:56 +08:00
Vincent Koc da15cf48bf fix(maint): keep PR landing on squash 2026-06-24 09:28:03 +08:00
Vincent Koc 4d034639ad fix(crabbox): require Xcode for macOS proof 2026-06-24 09:01:42 +08:00
Vincent Koc cd7e3df1ea fix(macos): drop Textual from chat packaging
* fix(macos): drop Textual from chat packaging

* fix(macos): declare concurrency extras dependency
2026-06-24 08:31:05 +08:00
joshavant b93eeceac0 build(ios): attach app review notes PDF 2026-06-23 19:18:51 -05:00
Josh Lehman 96cee6cb64 refactor: route live model reads through session accessor (#96206) 2026-06-23 16:52:22 -07:00
Josh Lehman 5839ef519a refactor: migrate command session persistence to accessor (#96204)
* refactor: migrate command session writes to accessor

* refactor: narrow command session persistence params
2026-06-23 16:52:11 -07:00
Josh Lehman ae433525f0 refactor(gateway): add alias mutation accessor (#96213)
* refactor: add gateway alias mutation accessor

* test: align gateway session entry mocks
2026-06-23 16:51:36 -07:00
Josh Lehman 6f2869c296 refactor: migrate agent session accessors (#96182)
* refactor: migrate agent session accessor writes

* refactor: move subagent orphan lookup to reconciliation

* test: align session accessor mocks
2026-06-23 16:31:43 -07:00
Josh Lehman 9512294e8f fix: bridge ACP metadata to session accessors (#96195)
* fix: bridge ACP metadata to session accessors

* fix: simplify ACP accessor key ownership

* fix: bind ACP metadata after session canonicalization
2026-06-23 16:14:53 -07:00
Josh Lehman 8a7b3c755a fix(memory-core): migrate dreaming cleanup lifecycle (#96193)
* fix(memory-core): migrate dreaming cleanup lifecycle

* fix(sessions): resolve lifecycle session files explicitly

* fix(ci): refresh dreaming lifecycle proof ratchets
2026-06-23 16:08:44 -07:00
Josh Lehman f8ed4de460 refactor: add abort target session accessor (#96201)
* refactor: add abort target session accessor

* refactor: centralize command abort session lookup

* fix: keep abort runtime path best effort

* fix: preserve abort target identity on persistence failure

* fix: remember abort target when persistence is skipped

* fix: abort runtime before metadata persistence

* fix: preserve abort target fallback typing

* fix: avoid stale abort memory fallback

* fix: keep abort accessor ratchet narrow

* fix: type abort persistence test mock

* fix: align abort accessor ratchet test
2026-06-23 16:06:04 -07:00
Josh Lehman b08d901dd2 fix: route gateway history through session accessor target (#96179) 2026-06-23 14:42:43 -07:00
Josh Lehman a8f387ba19 refactor: route plugin host hook state through accessor (#96191)
* refactor: route plugin host hook state through accessor

* refactor: hide session accessor store internals
2026-06-23 14:38:40 -07:00
Josh Lehman 132d70bfb3 refactor: migrate bundled transcript target lookups (#89911) 2026-06-23 14:32:21 -07:00
Vincent Koc 252673d5b1 fix(qa): bootstrap raw macos package scripts 2026-06-23 22:51:04 +02:00
Vincent Koc cc981f8a73 ci: build iOS app for iOS changes 2026-06-24 04:32:08 +08:00
Josh Lehman c24d266b2d refactor: use accessor-backed transcript corpus for memory (#96162)
* refactor: ratchet memory transcript corpus access

* test: use narrow runtime config snapshot import

* test: update plugin sdk surface budgets

* refactor: split memory transcript corpus module
2026-06-23 12:37:44 -07:00