Commit Graph

78784 Commits

Author SHA1 Message Date
Peter Steinberger e45a9460ce docs: repair spellcheck and anchor drift (#122960)
* docs: repair spellcheck and anchor drift

* docs: satisfy markdown anchor lint
2026-08-12 20:50:56 -07:00
Peter Steinberger 2c3e537cb8 fix(deploy): repair probes that silently pass and a blueprint that cannot boot (#122963)
Three defects proven by running the shipped configs:

Kubernetes probes checked only the status code against /startupz, but the
pinned image predates that route and the Control UI answers unknown paths
with a catch-all 200. A wedged pod was therefore marked Ready forever.
Probes now assert the JSON probe contract and target routes the pinned
image actually serves; verified in a kind cluster where the old command
exits 0 on the missing route and the new one exits 1.

render.yaml set no dockerCommand, so the image CMD ran without
--allow-unconfigured and a fresh Render disk exited 78 with 'Missing
config' before binding. Reproduced locally with Render's exact env.

The Cloudflare Container readiness poll had the same route mismatch
against operator-supplied official image digests; it now polls /healthz,
which every published image serves.

Also replaces an R2 verification step that could never fail: wrangler
cannot list object keys, so the documented command 404'd into || true.
2026-08-12 20:49:54 -07:00
Peter Steinberger 89a5507602 fix: GitHub project selection cloned repos before Start Session (#122906)
* fix(ui): defer GitHub project clone until submit

Keep remote project selection as draft state and materialize it before sessions.create on Start Session.

* fix(ui): consolidate deferred project selection

* test(ui): drop duplicate remote project assertion
2026-08-12 20:48:34 -07:00
Peter Steinberger aa35346a8e fix(cli): fail fast when onboarding profile is busy (#122968) 2026-08-12 20:44:22 -07:00
Peter Steinberger c61ee511ab fix(onboard): allow imports after runtime scaffolding (#122967) 2026-08-12 20:41:36 -07:00
Peter Steinberger d2628e430c fix(cli): avoid restart hint for unchanged config (#122953)
* fix(cli): avoid restart hint for unchanged config

* docs(cli): clarify no-op restart guidance
2026-08-12 20:40:30 -07:00
PIYUSH RATHORE 6cfc05ae2f fix(projects): avoid stale GitHub results after token rotation (#122613)
* fix(projects): avoid stale GitHub results after token rotation

* fix(gateway): scope GitHub caches by credential

* style(gateway): format GitHub credential scope

---------

Co-authored-by: FullerStackDev <263060202+fuller-stack-dev@users.noreply.github.com>
2026-08-12 20:39:30 -07:00
Peter Steinberger 4d54c3f1a1 refactor(config): retire dead streaming.progress.render key (#122927)
* refactor(config): retire dead streaming.progress.render key

The key had zero runtime consumers after #122552. Core doctor now strips it via stripRetiredTuningKnobs, and production LOC is net -13.

* fix(tooling): pin plugin SDK surface counts to the reduced export set

The retired progress-draft render reader counted twice via channel-outbound and channel-message's wildcard re-export.
2026-08-12 20:36:40 -07:00
Peter Steinberger 5db09954c7 fix(wizard): honor gateway overrides in manual flow (#122961) 2026-08-12 20:34:00 -07:00
Josh Avant 705f043e04 fix(qa): isolate staged auth state (#122958) 2026-08-12 22:30:46 -05:00
Peter Steinberger ffb2ed9e89 refactor: remove residual normalization aliases (#122956)
* refactor: remove residual normalization aliases

* test(gateway): isolate approval authority handshake
2026-08-12 20:26:30 -07:00
Peter Steinberger 061c9c2f7f fix(ai): honor embedded transport policy (#122946) 2026-08-12 20:20:18 -07:00
Feng 7dbe21b9cf fix(agents): hydrate CLI images from agent workspaces (#122684)
* fix(agents): hydrate CLI images from agent workspace

* fix(agents): preserve resolved CLI workspace owner

* fix(agents): keep workspace owner in prepared params

* fix(agents): resolve CLI owner before preparation

* fix(agents): preserve CLI runtime policy owner

---------

Co-authored-by: Adkid-Zephyr <169631528+Adkid-Zephyr@users.noreply.github.com>
Co-authored-by: FullerStackDev <263060202+fuller-stack-dev@users.noreply.github.com>
2026-08-12 20:18:15 -07:00
Josh Lehman edb941a508 oc-e35: restore explicit multi-agent UI ownership (#122889) 2026-08-13 03:17:13 +00:00
Vyctor H. Brzezowski aba94bbe0b fix: install or review the publisher you picked when ClawHub skills share a slug (#121697)
* fix(skills): keep ClawHub publisher identity from search through install

ClawHub search returns one entry per publisher, so several results can share a
slug. Every client collapsed the selection to that bare slug before calling
skills.detail and skills.install, and ClawHub answered 409 AMBIGUOUS_SKILL_SLUG
with no in-product way forward.

searchClawHubSkills now records the publisher-qualified reference once, on the
result that carries it, and the Gateway protocol documents it. skills.detail
parses the same reference grammar skills.install already accepted, so review and
install cannot resolve to different publishers. Control UI carries that one
reference through row actions, detail, busy state, and acknowledgement retries,
and shows it so otherwise identical rows are distinguishable.

Fixes #117633

* fix(apps): send the ClawHub publisher reference from native skill browsers

macOS, iOS, and Android read the qualified reference from search results and use
it for skills.detail, install, busy state, installed matching, and list identity,
so two publishers sharing a slug stay distinct instead of collapsing into one
ambiguous request.

* fix(skills): refuse external-source skill detail instead of reading a same-slug skill

ClawHub has no source-qualified read endpoint, so a skills-sh reference parsed
down to its bare slug would have returned a registry skill's card while install
resolved the external artifact. Review and install could name different skills.

skills.detail now fails closed on any reference that carries a source, and the
macOS and AgentPro rows show the publisher reference next to the summary instead
of only when a summary is missing, so same-slug rows stay distinguishable.

* chore(apps): refresh native i18n source baseline for the skill row references

* refactor(skills): drop the unread search-result ownerHandle field

installRef is the one reference clients send back, and no client reads the
publisher handle separately, so the protocol and Control UI carry one field
instead of two.

* fix(skills): name the next step when external skill detail is refused

Clients that gate install behind a successful review would otherwise see only a
refusal, so the error names the direct install path and the CLI equivalent.

* fix(macos): use a doc comment on the ClawHub row subtitle

swift-format's docComments rule requires doc comments on declarations; the
subtitle property carried a regular comment and failed macos-swift.

* fix(skills): carry ClawHub trust state to clients that can install

Forwarding installRef let clients install the exact publisher the operator
picked, including external skills-sh sources. It did not forward the trust
state that says ClawHub never scanned that source, so iOS AgentPro — the one
surface that installs in a single tap with no review step — could install an
unscanned artifact with nothing on screen saying so. The CLI already labels
these (docs/clawhub/cli.md, docs/cli/skills.md); native clients could not,
because trustState was never on the wire.

trustState becomes an optional field on SkillsSearchResultSchema. It is purely
additive: older clients ignore an unknown key and the field is absent for
registry results, so downgraded readers are unaffected and no protocol version
moves.

Every client that renders a search row now shows "Not scanned by ClawHub",
matching the CLI wording exactly: iOS AgentPro in the row above the install
button, macOS and Android beside the review action, and Control UI on the row
that explains why review is refused for these sources.

Covered by a wire assertion that the state reaches clients for an external
source and stays absent for registry rows, plus decode-and-label tests on the
shared Swift kit and the Android parser, and a Control UI render assertion.

* fix(ui): size the ClawHub detail dialog to a refusal message

Refusing detail for an external source made an error-only dialog reachable.
The shared preview panel reserves a tall reader height for skill documents, so
a two-line refusal rendered in a mostly empty dialog and read as broken rather
than deliberate. Found by inspecting the review captures.

* revert(ui,apps): drop the ClawHub trust label layer

Maintainer product decision: skills.sh runs its own scanners, so OpenClaw does
not add a second alert layer in the apps. Removes the label from Control UI,
iOS, macOS and Android, and drops the trustState wire field that nothing would
render. The CLI keeps its existing label; changing that is a separate call.

Publisher identity, the fail-closed detail refusal, and the message-only dialog
are unchanged. Splits the oversized skills view test file to satisfy max-lines
without a suppression.

* test(ui): fix ClawHub skill fixture checks

* chore(plugin-sdk): refresh API baseline

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-08-12 20:13:15 -07:00
Peter Steinberger f5ad8735d1 feat(ui): open subagent details in chat sidebar (#122941)
* feat(ui): open subagent details in chat sidebar

* chore: drop changelog edit (release generation owns it)

* refactor(ui): drop duplicate close in subagent detail panel

The sidebar region header already owns a Close Details control in both
wide and narrow layouts; the panel-local X duplicated it 40px away.

* fix(ui): stop subagent transcript loader when pane presentation retires

Pane retention wipes sidebarContent directly, so the detail slot's
render-time reset can never run again; a pending refresh timer plus
incoming task events kept refetching chat.history for a hidden panel.

* docs(ui): note close-control ownership in subagent detail header

* fix(ui): break transcript renderer import cycle

* fix(ui): use shared action cursor for subagent rows
2026-08-12 20:11:13 -07:00
Peter Steinberger 132299bcfa fix(gateway): allow downloading zero-byte artifacts (#122928)
* fix(gateway): preserve zero-byte artifacts

* fix(gateway): keep non-string data out of artifact lists

* test(gateway): compact zero-byte artifact coverage
2026-08-12 20:09:32 -07:00
Peter Steinberger 495f295f25 feat(ui): split new session place picker (#122938)
* feat(ui): split new session place picker

* test(ui): cover three-chip session picker
2026-08-12 20:09:27 -07:00
Colin Johnson ae20e2c163 fix(ui): model picker shifts when another user starts typing (#122809)
* fix(ui): keep composer model picker stable while typing

* test(ui): prove typing keeps model picker stable

Co-authored-by: Colin Johnson <colin@solvely.net>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-12 20:08:45 -07:00
Masato Hoshino 4c12c973ed fix(sessions): highWaterBytes 0 no longer deletes all session history (#119909)
* fix(sessions): zero highWaterBytes no longer clears all session history

resolveHighWaterBytes passed an explicit non-positive highWaterBytes through
verbatim. The resolved value is the disk-budget cleanup loop's stop condition,
so a zero target made enforce mode evict every unprotected session and prune
its extracted archives instead of trimming to the documented 80% default.

Route the non-positive case to the function's existing unusable-value branch
(computeDefault). Not null: that disables the budget and permits unbounded
growth, which is right for a cap but wrong for a target.

Sibling of #119422, which fixed the same harm for maxDiskBytes and guarded
only resolveMaxDiskBytes.

* test(infra): isolate worktree migration discovery

Keep worktree migration coverage focused on its real filesystem, Git, and SQLite owner while avoiding unrelated channel and plugin doctor cold starts on fork CI.

Co-authored-by: masatohoshino <g515hoshino@gmail.com>

* test(ci): carry owner-approved SDK and doctor gate repairs

Carry the already-approved plugin SDK contract manifest and focused doctor-flow test isolation from the maintainer-owned CI repair. Preserve real config migration, persistence, snapshot, and SQLite cleanup coverage; no production behavior changes.

Co-authored-by: masatohoshino <g515hoshino@gmail.com>

* fix(sessions): use the renamed withTestDir helper in the new budget test

* fix(sessions): align high-water zero contract

* style(sessions): format high-water changes

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: FullerStackDev <263060202+fuller-stack-dev@users.noreply.github.com>
2026-08-12 20:05:46 -07:00
Chinmay Rawat 1e19f22dbd fix: prompt caching breaks on Claude Opus 5 and Sonnet 5 (#121283)
* fix: prompt caching breaks on Claude Opus 5 and Sonnet 5

shouldPreserveThinkingBlocks() matched modern Claude ids with a hardcoded
family list plus /claude-[5-9]/ future-proofing. That regex assumes the
generation follows the prefix (claude-5-x), but shipped generation-5 ids
place the family in between (claude-opus-5, claude-sonnet-5, claude-mythos-5),
so none matched and dropThinkingBlocks flipped to true. Signed thinking blocks
were stripped from replayed history, diverging every request and invalidating
the Anthropic prompt cache on the default opus/sonnet aliases.

Read the generation from the id instead, preserving blocks for generation 4
and newer. This handles both id shapes and matches the idiom already used in
audit-extra.sync.ts and live-model-filter.ts.

Closes #121251

* fix: correct Claude thinking replay contract

Use the canonical Claude model identity and exact Anthropic preservation contract when deciding whether replay may retain prior thinking blocks. Carry deployment metadata through provider-family and fallback paths, and include canonicalModelId in the transcript policy cache key.

Release note: Restore prompt-cache reuse for Claude Opus 5 and Sonnet 5 while continuing to strip unsupported Sonnet and Haiku 4.5 thinking history.

* refactor: remove unused replay compatibility helper

Use the canonical Claude drop predicate at the remaining test call sites and remove the unconsumed preservation export so the dependency/dead-code gate stays clean.

* fix: keep Claude replay contract internal

Use canonical llm-core identity resolution without exporting a new llm-core capability, avoiding unintended Plugin SDK API drift.

---------

Co-authored-by: FullerStackDev <263060202+fuller-stack-dev@users.noreply.github.com>
2026-08-12 20:05:16 -07:00
Peter Steinberger 812bbd8884 docs(deploy): add verification, cost, observability, and troubleshooting to the Cloudflare guide (#122932)
The template shipped without the operator-facing half: no way to prove the
restore path works before depending on it, no cost signal for the always-on
versus webhook-only choice, no log surfaces, and no failure-mode index.

Adds an architecture diagram, a restore rehearsal, measured recovery numbers
from the real-R2 proof, provisioned-resource cost guidance, wrangler tail
observability, and a troubleshooting index covering image architecture,
Litestream S3 credentials, the startupz/readyz split, and ephemeral-disk
config loss.
2026-08-12 20:00:09 -07:00
Peter Steinberger c401f8a1a9 fix(ui): fence stale recovery scope work (#122944) 2026-08-12 19:59:30 -07:00
Peter Steinberger 08f9c3a5cb test(extensions): remove duplicate runtime replays (#122949) 2026-08-12 19:58:04 -07:00
Peter Steinberger 93d93d1d14 perf(test): cut workflow guard import overhead (#122940)
Co-authored-by: Amp <amp@ampcode.com>
2026-08-12 19:55:45 -07:00
Peter Steinberger a1c091fb1b test(gateway): stabilize sender avatar fixture (#122942) 2026-08-12 19:54:40 -07:00
Peter Steinberger cad7e7f9e1 fix: session model selection replaced by response aliases and fallback wins (#122910)
* fix(agents): keep session model selection canonical

Preserve configured session model identity across response aliases and turn-local fallbacks.

* fix(gateway): align session model projection consumers

* test(gateway): mark session event model selection
2026-08-12 19:46:56 -07:00
Peter Steinberger ddb0fad7df fix(ci): prevent flaky extension wrapper SIGTERM test (#122917)
* test(scripts): wait for valid wrapper pids

* test(scripts): harden PID marker reads
2026-08-12 19:45:22 -07:00
Vincent Koc ce3d1d22be fix(qa): preserve Code Mode reads in model-switch mock (#122935) 2026-08-13 10:41:42 +08:00
Peter Steinberger 73443ebed4 fix: stopping a session leaves subagents running with no stop control (#122909)
* fix(gateway): cascade session stop to subagents

Cascade exact and session-wide aborts through the subagent registry and keep Control UI Stop visible while descendants remain active.

* refactor(gateway): absorb stop cascade orchestration

* chore(gateway): refresh plugin SDK API contract for abort refactor

Regenerates the export-closure contract after the stop-cascade refactor
moved gateway abort orchestration exports, and drops a redundant Boolean()
wrapper flagged by lint. Public SDK surface gate is unchanged.

* chore(gateway): regenerate plugin SDK API baseline
2026-08-12 19:40:51 -07:00
Peter Steinberger c98b841b41 fix(ui): deliver failed steer retries as a new turn when the session is idle (#122919)
A steer rejected on the run/leaf fence parks as a failed steered queue row.
Retry previously refused whenever the target run was gone, leaving the
user's message permanently stuck with 'that run is no longer active'.
Retry now converts the parked row into a plain queued send when the session
is idle, so the text delivers as a fresh turn; active-run retries keep the
original steer binding, and disconnected retries keep the existing error.
2026-08-12 19:40:06 -07:00
Peter Steinberger c0b7ebd73e fix(tools): preserve partial web fetch status (#122866) 2026-08-12 19:35:56 -07:00
Peter Steinberger e0cd23d81f docs(agents): require screenshot/video proof for UI-visible and gateway-behavior changes (#122920)
Adds hard policy: UI-visible changes need before/after screenshots or a
short video as PR evidence; gateway-behavior changes provable in the
Control UI need an isolated dev-gateway live run with a recorded video.
Documents the verified video upload flow (user-attachments endpoint,
mp4/webm both served) and the bare-URL embed rule for GitHub's player.
2026-08-12 19:32:43 -07:00
Peter Steinberger cba8aff63f feat(ui): show useful environment facts in the picker (#122923)
* feat(ui): show environment facts in Where picker

Preserve environment platform, trust, session-host, and capability metadata through new-session discovery while keeping placement availability tied to live executable nodes. Render bounded quiet device/cloud facts and add mocked browser coverage for task #33.

* docs(plan): track picker environment facts

* refactor(ui): split place browser rendering
2026-08-12 19:32:34 -07:00
Peter Steinberger 5eebaf9e5c refactor(ai): internalize ChatGPT SSE protocol (#122930) 2026-08-12 19:31:00 -07:00
Colin Johnson 9d9c36c459 fix(ui): contain OAuth wizard modal content (#122892)
* fix(ui): contain OAuth wizard modal content

* test(ui): poll OAuth modal containment
2026-08-12 22:30:18 -04:00
Vincent Koc 3eef8ebfd5 fix(parallels): preserve plugin inventory during updates (#122912)
* fix(parallels): preserve plugin inventory during updates

* fix(parallels): preserve dev update plugin inventory
2026-08-13 10:26:02 +08:00
Vincent Koc dabf55727b fix(ci): prevent channel add command test timeout (#122879)
* test(channels): isolate add env setup contracts

* test(channels): cover adapter env setup
2026-08-12 19:24:31 -07:00
Peter Steinberger e6ca5266af fix: code mode dead-ends on oversized tool results instead of returning bounded output (#122924)
* fix(agents): bound code mode bridge results

Return oversized bridge, guest output, and final values as bounded successful projections with actionable narrowing guidance.

* refactor(agents): absorb code mode output bounds
2026-08-12 19:24:18 -07:00
Peter Steinberger 6076efc968 docs(gateway): clarify dynamic operator scopes (#122931) 2026-08-12 19:23:54 -07:00
Peter Steinberger 9992b893e7 fix(ci): rotate stale dependency snapshot (#122921)
Co-authored-by: Amp <amp@ampcode.com>
2026-08-12 19:23:33 -07:00
Peter Steinberger c43847313d fix: internal recovery prompts appear as operator-authored messages (#122908)
* fix(agents): hide recovery prompts from transcripts

Suppress settled-turn finalization and reasoning/empty-response control prompts at the session writer boundary.

* test(agents): align hidden recovery prompt expectations
2026-08-12 19:20:56 -07:00
Vincent Koc 9ddf16a195 fix(plugins): repair status and CLI fixtures (#122925) 2026-08-13 10:15:15 +08:00
Peter Steinberger 239087d448 improve: speed up CLI spawn tests (#122891)
* test(agents): trim cli spawn test imports

* test(agents): distinguish prerelease policies

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-12 19:07:19 -07:00
Daniel Cárdenas 326501fce3 fix(msteams): honor inbound channel media limit (#122315)
* fix(msteams): honor inbound channel media limit

* test(msteams): update lifecycle runtime mock

* style(msteams): avoid resolver config shadowing

* style(msteams): format lifecycle resolver mock

* refactor(msteams): inline media fallback

---------

Co-authored-by: DanielCardenas <djerez@lean-tech.io>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-08-12 19:06:47 -07:00
Calin Laurentiu Ilie 95bbd117ef fix(slack): prevent duplicate Socket Mode connections after reconnect errors (#122624)
* fix(codex): read canonical transcript session targets (#1)

* test(slack): reproduce reconnect timer surviving shutdown

* fix(slack): keep reconnects within one socket lifecycle

* test(slack): exercise native reconnect over loopback

* test(slack): satisfy reconnect integration checks
2026-08-12 18:57:04 -07:00
Vincent Koc d00e4ee324 fix(e2e): verify suspend control over WebSocket (#122888) 2026-08-13 09:56:26 +08:00
Peter Steinberger fd0fc80c8c test(microsoft-foundry): remove global test bridge (#122881)
* test(microsoft-foundry): remove global test bridge

* test(microsoft-foundry): type boundary fixtures

* perf(ui): keep route transition out of startup
2026-08-12 18:53:44 -07:00
Peter Steinberger 3a0cb17739 fix(gateway): resolve agent list model identity (#122907)
Publish canonical resolved primary models with matching runtime and thinking metadata in agents.list.
2026-08-12 18:52:41 -07:00
Peter Steinberger fba9ad43bc fix(ci): run affected extension suites when changed-test planning falls back (#122885)
The PR-changed test planner fails safe to the compact full-suite plan for any diff touching packages/**, but that compact plan excludes all extension test configs, so mixed package+extension PRs landed with zero extension test execution (escapes: PR #120534 breaking extensions/codex run-attempt.native-hook-relay.test.ts, PRs #122163/#121522 and cd7b7f639d breaking media-understanding-provider.test.ts and thread-lifecycle.test.ts on main full runs). The preflight now appends whole-config shards for the diff's touched extensions whenever the precise plan fails safe; whole configs (not precise targets) because the fail-safe cause leaves the non-extension diff's extension impact unbounded.
2026-08-12 18:51:00 -07:00