Commit Graph

17117 Commits

Author SHA1 Message Date
Peter Steinberger 4dd8a2be76 improve(browser): batch navigation guard, snapshot delta markers, tool output schema, code-mode recipe (#113749)
* feat(browser): guard batches and annotate snapshot deltas

* docs(browser): document reliable automation loops

* test(browser): align batch guard mocks

* fix(browser): reset snapshot deltas after navigation

* fix(browser): detect document navigation without URL equality

* fix(browser): require stable identity for snapshot deltas

* fix(browser): keep snapshot delta helper private
2026-07-25 10:58:03 -07:00
Peter Steinberger 0ff2c82033 refactor(mattermost): split inbound monitor (#113775)
* refactor(mattermost): split inbound monitor

* test(channels): follow mattermost history split
2026-07-25 10:56:58 -07:00
Peter Steinberger fe4972b12b fix(browser): keep shared page text inside producer limits (#113768)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 10:41:06 -07:00
Jason (Json) 8028a3a5b2 feat(anthropic): gate live model discovery on contract coverage (#113757)
* feat(anthropic): gate live model discovery on contract coverage

Live catalog discovery cloned a template for any newly discovered Claude id, so
a future model generation would be selectable while request shaping treated it
as pre-4.6 and 400d. Add an opt-in acceptUnknownModel gate to the shared live
catalog seam and have the Anthropic plugin accept a discovered model only when
Anthropic's advertised capabilities agree with the contracts we would apply.
Manifest-published ids bypass the gate and keep their metadata.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(plugins): document the live-discovery admission hook

Record acceptUnknownModel in the provider-plugin SDK reference: when to use
it, that manifest-published ids bypass it, and the fail-closed guidance.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-25 11:27:58 -06:00
Peter Steinberger 2c933adcd9 fix(meta): align manifest inputs with runtime (#113758) 2026-07-25 10:00:26 -07:00
Peter Steinberger dd606796c1 fix(browser): clean up failed guarded navigation routes (#113753)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 09:17:53 -07:00
Peter Steinberger 511d759c50 fix(browser): prevent IME composition from sending copilot messages (#113752)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 09:14:20 -07:00
Peter Steinberger 06548ae57f fix(browser): prevent copilot popup hang when a tab closes (#113744)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 08:39:30 -07:00
Peter Steinberger e19841c725 feat: continue Pi and OpenCode sessions from the session catalog (#113718)
* feat(plugins): add acpSessionBinding seam for ACP session adoption

* feat(acpx,opencode): adopt existing Pi and OpenCode sessions from the catalog

* fix(ci): satisfy dead-code and temp-path guards

* docs(acpx): record why pi-acp session-root resolution stays strict
2026-07-25 08:35:47 -07:00
Peter Steinberger e5999c7316 fix(microsoft-foundry): honor Azure device-code lifetime (#113741)
* fix(microsoft-foundry): honor device-code lifetime

Co-authored-by: wangmiao0668000666 <wang.miao86@xydigit.com>

* fix(microsoft-foundry): allow login completion grace

---------

Co-authored-by: wangmiao0668000666 <wang.miao86@xydigit.com>
2026-07-25 08:33:05 -07:00
Peter Steinberger 481d826ff4 fix(vault): prevent insecure secrets plan writes (#113707)
* fix(vault): harden secrets plan writes

* fix(secrets): avoid env marker collision

* style(secrets): type plan write rejection

* refactor(onepassword): remove obsolete path resolver

* fix(secrets): preserve Windows plan path trust

* refactor(secrets): compact ACL token policy

* fix(secrets): route permission checks through facade
2026-07-25 08:27:33 -07:00
zengLingbiao c459a1876b fix(volcengine): reject malformed TTS audio (#113109)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-25 08:15:14 -07:00
Peter Steinberger 42515c4f07 fix(openai): prevent realtime transcript turns from reordering (#113723)
* fix(openai): preserve realtime transcript order

* chore: defer realtime note to release

* test(openai): align heartbeat prompt contract

* test(openai): align direct context contract
2026-07-25 08:11:09 -07:00
zengLingbiao cff22e83ca fix(xiaomi): reject malformed base64 audio in TTS responses (#113106)
* fix(xiaomi): reject malformed TTS audio

Co-authored-by: zenglingbiao <zeng.lingbiao@xydigit.com>

* fix(media): reject noncanonical base64 padding

* style(xiaomi): format malformed audio test

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-25 07:52:23 -07:00
Peter Steinberger 8376daad6c fix(qa): record live channel evidence from actual driver (#113710)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 07:25:29 -07:00
Peter Steinberger f703d803cc chore(models): curate all provider model catalogs to current-generation lineups (#113681)
* chore(models): fleet-wide provider catalog curation

* fix(models): sync provider runtime catalogs and tests with curated manifests

* test(models): align venice lifecycle assertions and copilot auth default with curated catalogs

* test(models): align catalog lifecycle contract checks
2026-07-25 07:21:17 -07:00
wangmiao0668000666 6935293626 fix(microsoft-foundry): bound az login device-code subprocess (#112369)
* fix(microsoft-foundry): bound az login device-code subprocess

Add a 5-minute timeout to the az login spawn so a stalled Azure CLI
does not block the caller indefinitely. The timeout kills the child
process and rejects the promise with a descriptive message.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(microsoft-foundry): reject login timeout immediately

* refactor(microsoft-foundry): use shared process timeout

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-25 07:20:19 -07:00
Peter Steinberger 47601cf5b4 fix(qa): count skipped scenarios in suite summaries (#113696)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 06:43:30 -07:00
Peter Steinberger 4aa4ff7250 refactor(matrix): split CLI command groups (#113664)
* refactor(matrix): split CLI command groups

* refactor(matrix): keep CLI helpers private

* refactor(matrix): retain profile result type contract
2026-07-25 06:37:08 -07:00
Peter Steinberger 504e5bbf89 perf(agents): compact JSON in commitments and heartbeat prompts (#113657) 2026-07-25 06:19:01 -07:00
Peter Steinberger 9a7a5791c7 refactor(memory): split QMD manager by domain (#113659)
* refactor(memory): split QMD manager by domain

* refactor(memory): keep QMD base types private
2026-07-25 06:18:05 -07:00
苟文 2579e4a420 docs: fix incorrect CLI command in extension READMEs (#112057)
Replace non-existent 'openclaw plugin add' with the correct
'openclaw plugins install' command in 14 extension README files.

The CLI only registers 'openclaw plugins install' (src/cli/plugins-cli.ts),
and the previous command would fail for users following the docs.

Co-authored-by: hilbert <xuxiaojing@tojoy.com>
2026-07-25 05:50:13 -07:00
Peter Steinberger 26cb29a171 refactor(channels): finish factory migrations for line/tlon/zalouser (#113646)
* refactor(line): use shared DM policy factory

* refactor(line): use shared channel probe runner

* refactor(zalouser): use shared channel probe runner

* refactor(tlon): use shared channel probe runner

Honor the status adapter timeoutMs instead of discarding it.

* refactor(line): use canonical inbound context builder

* refactor(line): drop stale setup policy export

* fix(tlon): honor adapter probe timeoutMs
2026-07-25 05:46:32 -07:00
Peter Steinberger 7f70fb3521 test(qa): restore session turn ordering coverage (#113653)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 05:39:03 -07:00
Peter Steinberger b06f40a821 refactor(plugin-sdk): share ingress lifecycle fan-in (#113648)
* refactor(channels): share ingress lifecycle fan-in

* chore(plugin-sdk): refresh ingress API baseline
2026-07-25 05:34:35 -07:00
Peter Steinberger 332006bc1f test: consolidate OpenClaw test state fixtures (#113576)
* test: consolidate OpenClaw test state fixtures

* test(plugin-sdk): expose isolated test state

Promote the isolated OpenClaw test-state lifecycle through a narrow published Plugin SDK subpath so extension tests no longer import private core helpers. This intentional SDK surface addition is maintainer-approved.

* test: use SDK test-state seam in extensions

Route bundled extension suites through the focused repo-local Plugin SDK test-state entrypoint and remove the Codex projector harness exports made stale by fixture consolidation. Keep the seam out of production builds and published package artifacts while auditing its real consumers in the full-tree deadcode scan.

* test(plugins): map test-state in package boundaries
2026-07-25 05:30:52 -07:00
Peter Steinberger 3d1369ff4f test(telegram): consolidate bot test harness (#113571)
* test(telegram): consolidate bot test harness

* test(plugin-sdk): expose isolated test state

Promote the isolated OpenClaw test-state lifecycle through a narrow published Plugin SDK subpath so extension tests no longer import private core helpers. This intentional SDK surface addition is maintainer-approved.

* test(telegram): use public test-state seam

* test(plugin-sdk): keep test state local-only

Match the existing channel test-helper boundary: bundled extension tests can import the focused SDK source entrypoint, while ordinary builds and the published npm package exclude it. The earlier public classification existed only on this unmerged PR branch and was never a shipped contract.

* test(plugins): map test-state in package boundaries
2026-07-25 05:28:26 -07:00
Masato Hoshino bdcc5d54a5 fix(agents): honor run abort signal in image and pdf tools (#112644)
* fix(agents): honor run abort signal in image and pdf tools

The image and pdf agent tools declared `execute: async (_toolCallId, args)`
and dropped the run abort signal that `wrapToolWithAbortSignal` supplies as
the third execute argument. The wrapper only races the execute promise, so an
aborted run kept sequentially downloading images/PDFs (up to the per-tool cap,
each up to the byte cap) and still issued a paid vision/PDF-model call for a
dead run.

Thread the signal into the existing `requestInit: { signal }` seam (which the
media fetch layer already merges into the download fetch) and add
`signal.throwIfAborted()` between sequential loop items and before the paid
model call. No new media-options signal field; non-abort behavior is unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(agents): keep the pdf test suite under the lint ceiling; guard model dispatch

Follow-up on the abort-signal change, resolving the check-lint failure and a
review finding on the same seam.

max-lines
---------
Adding the two pdf abort tests pushed src/agents/tools/pdf-tool.test.ts to 1018
effective lines against a ceiling of 1000, failing check-lint. Resolved without
touching config/max-lines-baseline.txt — a suppression there would also have
tripped the max-lines ratchet.

- The new tests declared their own `describe` with `beforeEach`/`afterEach`
  hooks identical to the existing `describe("createPdfTool")`. They exercise
  that same tool, so they now live in it and the duplicated scaffolding is gone.
- `stubPdfToolInfra`, `createPdfModelRegistry` and `FAKE_PDF_MEDIA` moved to
  pdf-tool.test-support.ts, which already exists for exactly this. They go
  through `createPdfToolInfraStub(completeMock)` rather than being exported
  directly, because the stub wires the suite's own `complete` mock into the
  model registry and vi.mock handles are file-scoped. All 21 existing call
  sites are unchanged.

Abort propagation into model dispatch
-------------------------------------
The previous revision stopped cancellation at download boundaries and before
the first model call, but `runImagePrompt`/`runPdfPrompt` never saw the signal.
A run cancelled while the first provider request was in flight could still
issue the remaining ones — the image path dispatches `describeImage` once per
image in a sequential loop, so a dead run kept paying for every later image.

Both now take an optional `signal` and check it immediately before each
provider dispatch (3 sites in image-tool, 4 in pdf-tool).

Forwarding the signal further, into the provider transports themselves, is a
different seam and is deliberately left out of this PR.

Also declares `requestInit` on `ImageToolLoadWebMediaOptions`. The local facade
omitted it while the underlying loader accepts it (web-media.ts declares it and
forwards it to readRemoteMediaBuffer), so the option worked at runtime and only
compiled because spread properties skip excess-property checking. A non-spread
call site would not have.

tsgo core + core-test, oxlint, oxfmt clean; pdf-tool and image-tool suites 266
tests pass.

* test(agents): prove in-flight media aborts

* test(agents): narrow PDF loader options

* test(agents): reject abort mocks with errors

* fix(agents): propagate media cancellation

* test(agents): type PDF abort fixture

* test(agents): type prepared runtime snapshot

* fix(agents): normalize abort rejection errors

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-25 05:17:09 -07:00
Peter Steinberger c8e6adc929 fix(qa): run documented channel message flows on supported drivers (#113642)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 05:09:13 -07:00
Peter Steinberger 3890a5efb6 fix(qa): restore current scenario source and documentation references (#113639)
Co-authored-by: Peter Steinberger <steipete@golden-gate.local>
2026-07-25 05:04:05 -07:00
Vincent Koc 001319f1ad Merge pull request #113633 from openclaw/feat/anthropic-opus-5-parity 2026-07-25 20:01:37 +08:00
ooiuuii 591e029095 fix(browser): skip non-executable auto-discovery candidates (#111951)
* fix(browser): skip non-executable candidates

* test(browser): preserve fs constants in mocks

* fix(browser): simplify executable candidate checks

* fix(browser): require regular executable files

* style(browser): format executable candidates

* test(ci): allow sqlite proof on fork runners

* style(test): keep sqlite timeout diff compact

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-25 04:50:40 -07:00
Vincent Koc 618f910377 refactor(matrix): share bounded cache insertion (#113636) 2026-07-25 19:43:58 +08:00
Peter Steinberger 825d6f7f1f fix(openai): align Codex discovery client version (#113615)
* fix(openai): align Codex discovery client version

* chore: leave release notes to release workflow
2026-07-25 04:33:12 -07:00
Vincent Koc 4df130d0be fix(anthropic): honor opus 5 aliases 2026-07-25 19:30:49 +08:00
Vincent Koc 3764d6739e fix(anthropic): use native fast mode for opus 2026-07-25 19:30:48 +08:00
Vincent Koc e42401bce7 refactor(anthropic): centralize 1m context capability 2026-07-25 19:30:48 +08:00
Vincent Koc 92188c9e5a refactor(matrix): use shared string normalization (#113627) 2026-07-25 19:26:25 +08:00
Vincent Koc 13126e4bd7 refactor(workboard): share claim token redaction (#113618) 2026-07-25 19:06:18 +08:00
joshavant f153858045 fix(onepassword): make SecretRef setup production-safe 2026-07-25 06:03:30 -05:00
joshavant 56bf326371 fix(onepassword): bound SecretRef resolution lifecycle 2026-07-25 06:03:30 -05:00
joshavant fb8589ebdb fix(onepassword): harden trusted op execution 2026-07-25 06:03:30 -05:00
sallyom f045f33a62 feat(onepassword): add managed SecretRef integration 2026-07-25 06:03:30 -05:00
Peter Steinberger 64daf8dd23 refactor(slack): split message dispatch (#113602) 2026-07-25 03:43:24 -07:00
Vincent Koc 967dd9538a refactor(discord): share handle normalization (#113608) 2026-07-25 18:38:43 +08:00
Peter Steinberger 589ac0372e refactor(zalouser): compile blocks from CommonMark IR (#113590)
* refactor(zalouser): compile blocks from commonmark ir

* refactor(markdown-core): keep block metadata internal

* test(markdown-core): type hidden block metadata

* refactor(zalouser): drop split-module leftovers

* test(markdown-core): assert serialized metadata shape

* refactor(zalouser): satisfy formatter lint contracts

* refactor(zalouser): internalize source span helpers

* fix(zalouser): preserve nested container semantics
2026-07-25 03:34:53 -07:00
Peter Steinberger b0603cb443 refactor(fs): adopt shared safe filesystem primitives (#113596)
* refactor(fs): adopt fs-safe helpers

* fix(zalouser): keep stable per-profile QR temp path

* fix(fs): route adoption through owned facades
2026-07-25 03:24:19 -07:00
Peter Steinberger 91b5b43d78 feat(models): curate default model picker to current-generation catalogs (#113594)
* feat(models): curate default picker visibility

* chore(models): curate provider catalogs

* test(openai): generalize static-catalog transport guard after row curation (#91710)

* fix(models): propagate catalog lifecycle metadata

* test(models): keep picker suite within line budget
2026-07-25 03:22:42 -07:00
Peter Steinberger 902cc53279 refactor: batch of independent dedup wins (#113535)
* refactor(config): reuse session parent fork types

* refactor(channels): reuse setup adapter type

* refactor(discord): share model preference primitives

* refactor(whatsapp): share reaction eligibility

* test(auto-reply): deduplicate dispatch scenarios

* test(scripts): share scenario fixtures

* test: share process and registry fixtures

* test: satisfy dedup fixture lint

* fix(plugin-sdk): keep setup adapter contract acyclic
2026-07-25 02:56:05 -07:00
xingzhou 87b424aca8 fix(browser): control results can contain corrupted text from malformed UTF-8 (#111898)
* fix(browser): reject malformed UTF-8 control responses

* test(browser): cover malformed UTF-8 error responses

* test(browser): strengthen UTF-8 transport coverage

* fix(browser): preserve retry guidance on decode errors

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-25 02:30:36 -07:00