Syu
b316c9cacf
fix(channels): honor explicit preview streaming settings
...
Explicit Telegram and Discord preview modes now override inherited block streaming while explicit channel block settings remain authoritative.
Co-authored-by: Syu <zhuqimo@gmail.com >
2026-08-05 09:04:49 +05:30
Vincent Koc
e35d22807e
perf(xai): lazy-load optional capability runtimes ( #119374 )
...
Punchcard-Session: coral-workshop-workshop-3f
2026-08-05 11:26:40 +08:00
Vincent Koc
fd1662f49c
fix(cli): retire invalid secret flags and prove doctor recovery ( #118926 )
...
* test(qa): add doctor CLI recovery coverage
* test(qa): secure doctor exec SecretRef proof
* test(qa): gate doctor systemd recovery proof
* test(qa): normalize doctor terminal output
* test(qa): close doctor probe sockets
* test(qa): classify doctor probe as foreign
* test(qa): track doctor probe sockets
* test(qa): retain doctor instance narrowing
* test(qa): preserve observed doctor recovery proof
* test(qa): keep doctor recovery on stable dist
* test(qa): honor Windows exec ACL blocking
* test(qa): use canonical home for systemd recovery
* test(qa): follow bounded gateway recovery
* test(qa): accept lifecycle service label
* test(qa): align doctor recovery contract
Punchcard-Session: crisp-lantern-orchard-nv
* docs(secrets): remove retired provider bypasses
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate doctor recovery target
Punchcard-Session: crisp-lantern-orchard-nv
* fix(cli): retire invalid secret provider flags
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate doctor supervisor mode
Punchcard-Session: crisp-lantern-orchard-nv
* fix(plugins): remove dead secret path bypass
Punchcard-Session: crisp-lantern-orchard-nv
* chore: drop release-owned changelog entry
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate doctor sudo scope
Punchcard-Session: crisp-lantern-orchard-nv
* fix(secrets): remove dead path bypass
Punchcard-Session: crisp-lantern-orchard-nv
* test(qa): isolate systemd user bus
Punchcard-Session: crisp-lantern-orchard-nv
2026-08-05 11:20:23 +08:00
Vincent Koc
17ef7771a6
fix(ci): stabilize TUI PTY proof ownership ( #119420 )
...
* fix(ci): stabilize TUI PTY proof ownership
Punchcard-Session: cobalt-brook-meadow-m9
* fix(test): align TUI PTY event typings
Punchcard-Session: cobalt-brook-meadow-m9
2026-08-05 11:08:56 +08:00
Peter Steinberger
22de30f998
fix(media): decouple playback cache retention ( #119417 )
2026-08-04 19:57:48 -07:00
Vincent Koc
392e1c0620
fix(ci): preserve cache warmer shard envelopes ( #119403 )
...
Punchcard-Session: amber-orchard-valley-s4
2026-08-05 10:20:55 +08:00
Dinesh H Suthar
50c7444edf
fix(sessions): preserve compatible auth profiles on model changes ( #117550 )
...
* fix(model-picker): preserve compatible auth profiles
* chore(plugin-sdk): refresh API baseline
* fix(model-picker): keep profile policy core-owned
* fix(model-picker): preserve profiles across auth aliases
* chore(plugin-sdk): update public surface budgets
* fix(model-picker): honor explicit profile clearing
* fix: preserve compatible auth profiles on model changes
* perf: reuse prepared auth profile metadata
* docs(plugin-sdk): document direct model persistence fallback
* test: expose auth snapshot in directive mock
Co-authored-by: Ayaan Zaidi <hi@obviy.us >
Co-authored-by: Dinesh Suthar <dineshsld20@gmail.com >
2026-08-05 07:40:00 +05:30
Vincent Koc
8f2850d83e
fix(ci): isolate cache warmer configs ( #119381 )
...
Punchcard-Session: amber-orchard-valley-s4
2026-08-05 09:12:28 +08:00
Josh Avant
618fba92bf
feat(audit): add execution identity inspection ( #117034 )
...
* feat(audit): add opt-in execution identity inspection
* fix(audit): gate recovery identity retention
* fix(audit): keep recovery identity type private
* test(audit): type internal recovery fixture
* test(audit): split recovery identity coverage
* docs(audit): define operator read trust boundary
* test(qa): register identity scenario child
* fix(audit): enforce shared identity retention bounds
* fix(audit): seal public ingress identity boundary
* fix(audit): keep ingress guard lint-clean
* fix(gateway): preserve advertised method order
* chore(protocol): sync advertised method order
* fix(protocol): encode audit selector invariants
* test(audit): prove exact execution guard
* fix(audit): keep identity storage lazy
2026-08-04 20:05:15 -05:00
Peter Steinberger
58025dd33c
fix(fs): adopt fs-safe 0.5.2 untrusted filename sanitization ( #119363 )
...
* fix(fs): adopt fs-safe 0.5.2 untrusted filename sanitization
* fix(media): classify pre-open identity drift as access denial
* chore(checks): refresh SDK baseline and env-var budget for fs-safe adoption
* test(media): compact sanitizer cases under max-lines
* fix(agents): keep workspace symlink contract under fs-safe 0.5.2
* fix(infra): align path normalization and atomic-write proofs with fs-safe 0.5.2
* fix(fs): keep operator symlink contracts on config, control-ui, skills, hooks
* fix(fs): restore sandbox and session-lock contracts under fs-safe 0.5.2
* test(claws): expect symlink diagnostic for tampered plan parents
* fix(agents): canonicalize apply-patch mutations through contained aliases
* test(agents): split alias-update regression into focused file
---------
Co-authored-by: Peter Steinberger <steipete@mac-studio-sf2.local >
2026-08-04 17:53:44 -07:00
Vincent Koc
9ff9aac71a
fix(ci): isolate built TUI PTY fixture ( #119339 )
...
Run the built local TUI PTY lane after the other artifact checks so its real Gateway fixture has exclusive process and event-loop capacity.
Punchcard-Session: cobalt-brook-meadow-m9
2026-08-05 08:00:29 +08:00
Charles
c81aee5a96
docs: add ChromeOS (Crostini) platform install guide ( #107663 )
...
* docs: add ChromeOS (Crostini) platform install guide
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
* docs: correct ChromeOS Linux container setup path
* docs: add zh-CN glossary entries for ChromeOS page terms
---------
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com >
Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com >
2026-08-04 15:41:42 -07:00
Dallin Romney
7c93cff84a
fix(release): accept trusted extended-stable validation evidence ( #119264 )
...
* fix(release): accept trusted extended-stable validation evidence
* fix(release): document trusted candidate promotion
* docs(release): clarify validation evidence recovery
2026-08-05 04:14:30 +08:00
Vincent Koc
e99c289f3b
fix(ci): avoid duplicate Matrix release QA runs ( #119171 )
...
* fix(ci): gate reusable Matrix QA runs
* docs(ci): document Matrix release QA budget
2026-08-05 03:31:00 +08:00
Vincent Koc
d06fc25a0c
fix(agents): protect private memory in shared chats ( #119198 )
...
* fix(agents): protect private memory in shared chats
Fixes #84466
Co-authored-by: Peter Steinberger <steipete@gmail.com >
* fix(agents): propagate shared chat type across runtimes
* fix(agents): enforce bootstrap privacy after hooks
* test(agents): cover final bootstrap filtering
* fix(agents): filter private memory before allowlists
* fix(agents): preserve bootstrap source identity
* refactor(agents): simplify bootstrap source identity
* fix(agents): keep bootstrap source identity private
* fix(agents): unify CLI runtime chat type
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-08-04 23:01:38 +08:00
vovapetry
b5876a1086
fix(telegram): route reactions to their originating forum topics
...
Recover Telegram forum reaction topics from provider-observed message context before authorization, and drop unknown topics instead of routing them to General. Serialize each forum message with its reaction update to avoid cache races. Thanks @vovapetry.
2026-08-04 18:49:57 +05:30
joshavant
8393b37779
fix(setup): keep compatible Claude wrappers selectable
2026-08-04 02:08:23 -05:00
joshavant
d636f5f8e0
fix(agents): gate Claude live session protocol
2026-08-04 02:08:23 -05:00
Peter Steinberger
25e3b6c9b7
fix(cli): honor local port in gateway call ( #119046 )
2026-08-03 18:50:21 -07:00
Michael Christenson II
7f7a709b1d
fix: Ollama missing from onboarding when its service is reachable ( #118020 )
2026-08-03 17:49:31 -06:00
clawSean
5cd6694349
docs(sms): add Twilio A2P delivery guidance ( #88743 )
...
* docs(sms): add A2P delivery guidance
* fix(docs): correct Twilio A2P guidance
---------
Co-authored-by: clawSean <260045960+clawSean@users.noreply.github.com >
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-04 07:43:21 +08:00
Vincent Koc
15b23cfc2d
fix(docker): use authenticated gateway health command ( #118996 )
...
* fix(docker): use authenticated gateway health command
* test(docker): prove documented compose health command
2026-08-04 07:10:36 +08:00
Vincent Koc
0758316883
feat(sms): track Twilio delivery status ( #118665 )
...
* feat(sms): track Twilio delivery status
* fix(sms): preserve Twilio delivery callbacks under inbound load
* fix(sms): correct delivery status contracts
* fix(sms): retry transient Twilio callback reads
* fix(sms): bound delivery callback admission
* docs(sms): clarify delivery callback recovery
2026-08-04 06:39:17 +08:00
Peter Steinberger
c83dcc2bc0
fix(security): harden network tool output at canonical owner boundaries ( #118984 )
...
* fix(security): bound external tool content at its canonical owner boundary
* fix(plugin-sdk): document supported security boundary and restore facade parity
2026-08-03 15:34:33 -07:00
Vincent Koc
1d446ad2cc
fix(plugins): remove stale load paths during uninstall ( #118930 )
...
* test(qa): prove marketplace plugin updates
* fix(plugins): clean exact install load paths on uninstall
* fix(ci): register marketplace lifecycle assertions
2026-08-03 21:57:54 +00:00
Peter Steinberger
14fe739ee9
fix(feishu): enforce exact signed webhook request boundaries ( #118758 )
...
* fix(feishu): enforce exact signed webhook request targets
* fix(feishu): preserve explicitly configured signed webhook query targets
* fix(feishu): preserve shipped relative webhook paths
* fix(feishu): normalize and migrate legacy webhook callback paths
* fix(feishu): preserve transformed webhook schema defaults
* fix(feishu): require canonical webhook paths before runtime startup
* docs(feishu): document canonical webhook routes and doctor recovery
2026-08-03 14:52:58 -07:00
Vincent Koc
554a6f3bbf
feat(sms): add Twilio MMS support ( #118664 )
...
* feat(sms): add Twilio MMS support
* fix(sms): harden hosted media bearer handling
* fix(sms): discard staged media before dispatch
* fix(sms): close staged media cleanup races
* fix(sms): finalize MMS metadata and race proof
* fix(media): bind local reads to authorized descriptors
* fix(sms): close MMS review gaps
* fix(media): make inbound root matching type-safe
* fix(media): route bounded reads through fs-safe facade
* test(media): satisfy async lint contracts
2026-08-04 05:46:37 +08:00
Peter Steinberger
108cec388e
fix(skills): provide safe workspace-specific malicious skill remediation ( #118969 )
2026-08-03 14:39:02 -07:00
Ayaan Gazali
347398311a
docs: fix stale 2gb session disk budget default on chrome extension page ( #110624 )
2026-08-04 05:24:23 +08:00
Peter Steinberger
76cc60a452
docs: correct onboarding risk flags and Google Chat credential shapes ( #118936 )
2026-08-03 13:59:29 -07:00
kiranmagic7
682f60ce56
fix(config): reject unsupported diagnostics otel grpc ( #93087 )
2026-08-03 16:28:08 -04:00
Peter Steinberger
990fdcf6fd
fix(providers): recognize configured media credentials across provider boundaries ( #118761 )
...
* fix(providers): honor configured media credentials across owner boundaries
* test(providers): align configured auth fixtures and derived SDK surfaces
* fix(providers): enforce shared DashScope media credential policy
2026-08-03 13:26:31 -07:00
Peter Steinberger
f9d9d1225a
refactor(channels): own the lifecycle status contract in SDK patch factories ( #118795 )
...
* refactor(sdk): add channel lifecycle patch factories
* refactor(channels): adopt lifecycle patches in a-m
* refactor(channels): adopt lifecycle patches in n-z
* refactor(runtime): lifecycle-own ambient registries
* test(slack): assert lifecycle factory fields
* fix(sdk): preserve lifecycle patch extras types
* test(zalouser): widen lifecycle status sink
* test(irc): avoid shadowed status patch
* fix(zalo): reuse account-agnostic media route
* fix(gateway): accept explicit channel ready recovery
* test(qa): assert terminal Slack block fact
* test(qa): restore Slack blocked lifecycle scenario
* test(gateway): lock explicit lifecycle recovery contract
2026-08-03 12:39:48 -07:00
Peter Steinberger
bbde865b9c
docs(gateway): fix invalid heartbeat visibility examples ( #118827 )
2026-08-03 11:17:14 -07:00
Vincent Koc
21a767639f
fix(plugins): unify HTTP route conflict handling ( #118203 )
...
* fix(plugins): unify HTTP route conflict handling
* fix(plugins): preserve source-less route replacement
* test(line): type webhook route source
2026-08-04 02:15:00 +08:00
Peter Steinberger
2efac6c999
feat(cli): add session archive and delete commands ( #118791 )
...
* feat(cli): add session lifecycle commands
* fix(deps): update brace-expansion security pin
* chore: defer session lifecycle release note
2026-08-03 11:00:17 -07:00
Pavan Kumar Gondhi
f63f2fd3db
fix(reef): restrict management commands to owners [AI] ( #118578 )
...
* fix(reef): require owner for management commands
* fix(reef): preserve general command access
* fix: preserve explicit owner authority
* fix(discord): separate voice admission from ownership
* docs(reef): explain owner command recovery
* docs(reef): clarify owner recovery paths
2026-08-03 23:18:05 +05:30
Peter Steinberger
e7950261b6
docs(openrouter): repair invalid canonical configuration examples ( #118747 )
2026-08-03 09:53:01 -07:00
Vincent Koc
f9baa3e894
fix(channels): generate discovery docs from catalog ( #118106 )
2026-08-03 23:42:55 +08:00
Peter Steinberger
7fafaf50f4
fix(onboard): keep referenced provider secrets out of plaintext ( #118702 )
...
* fix(onboard): keep referenced provider secrets out of plaintext
* fix(onboard): retain public credential owner type usage
* docs(onboarding): explain preserved credential profiles in reference mode
2026-08-03 08:34:47 -07:00
Peter Steinberger
1e06fd4430
docs: show canonical agent roster configuration ( #118722 )
...
Co-authored-by: Peter Steinberger <steipete@macos.shared >
2026-08-03 08:24:40 -07:00
Peter Steinberger
a6f9da8bdb
refactor: centralize cron, doctor, and TUI ownership ( #118515 )
...
* refactor(cron): centralize queued run activation
* refactor(doctor): share session SQLite report scaffolding
* refactor(tui): unify slash command registry
* fix(tui): satisfy command registry lint
* fix(tui): align shared command usage help
* fix(btw): preserve outbound usage placeholder
2026-08-03 04:08:54 -07:00
Peter Steinberger
6d8c1ed30d
fix(voice-call): prevent unrelated session recall in fast context ( #118498 )
...
* fix(talk): authorize fast session context
* test(plugins): preserve memory runtime mock types
* fix(plugins): preserve memory authorizer binding
* fix(memory): forward search authorization in lazy runtime
* test(memory): verify lazy authorizer host binding
* docs(plugins): define memory search authorization contract
2026-08-03 03:38:02 -07:00
Peter Steinberger
deb682abfe
refactor(plugins): consolidate extension runtime helpers ( #118509 )
...
* refactor(plugins): consolidate extension runtime helpers
* fix(ci): satisfy extension type and lint checks
* chore(plugin-sdk): regenerate API baseline for #118509
2026-08-03 02:56:43 -07:00
Peter Steinberger
ecc49b5a87
refactor(tts): absorb speech core package ( #118513 )
...
* refactor(tts): absorb speech core package
* fix(tts): preserve runtime SDK exports
* refactor(tts): remove private package exports
* test(tts): align canonical runtime mocks
* test(tts): complete canonical settings mocks
* chore(plugin-sdk): regenerate API baseline for #118513
2026-08-03 02:25:48 -07:00
joshavant
d9393bd3cb
fix: make subagent completion delivery durable
2026-08-03 02:48:34 -05:00
Peter Steinberger
fad7632a51
docs: explain model usage events and supported usage APIs ( #118483 )
2026-08-02 23:52:11 -07:00
Mislav Ivanda
a98852c938
docs: add Daytona hosting guide ( #116411 )
...
Adds a Daytona hosting guide covering sandbox creation, onboarding, secure preview-URL dashboard access, channel setup, updates, and troubleshooting, and links it from the hosting navigation.
Prepared head SHA: 4faf05211b
Co-authored-by: Mislav Ivanda <72461767+mislavivanda@users.noreply.github.com >
Co-authored-by: Shakker <165377636+shakkernerd@users.noreply.github.com >
Reviewed-by: @shakkernerd
2026-08-03 07:17:18 +01:00
Peter Steinberger
5de84bfc4d
fix(openai): support the current speech model snapshot ( #118475 )
...
* fix(openai): support the current speech model snapshot
* docs(openai): clarify speech instructions apply to the model family
2026-08-02 23:00:46 -07:00
Peter Steinberger
e04caa6aee
fix(openai): support flexible GPT Image 2 dimensions ( #118476 )
...
* fix(openai): support flexible GPT Image 2 dimensions
* docs(openai): explain flexible GPT Image 2 dimensions
2026-08-02 22:40:07 -07:00