* fix: gate diagnostics command to owners (cherry picked from commit170bf72e64) * fix(agent): replace self-wait with deferred release in retained-lock abort cleanup (#96100) * fix(agent): wait for retained session write before releasing held lock on abort * fix(agent): replace self-wait with deferred release in retained-lock abort cleanup * fix(test): reject fallback acquire with SessionWriteLockTimeoutError in active-scope cleanup test * fix(agent): trim retained-lock comments Signed-off-by: sallyom <somalley@redhat.com> --------- Signed-off-by: sallyom <somalley@redhat.com> Co-authored-by: sallyom <somalley@redhat.com> (cherry picked from commit0a042f68df) * fix(gateway): resume channel after pending task recovery (cherry picked from commit6039da3ed6) * fix(gateway): resume channel after pending task recovery (cherry picked from commitecd29fe572) * fix(outbound): ignore empty delivery receipts (#79811) (cherry picked from commit9a735bea03) * fix(agents): guard delivery-evidence attachment recursion against cycles (#97041) * fix(agents): guard delivery-evidence attachment recursion against cycles * fix(agents): guard delivery-evidence attachment recursion against cycles * fix(agents): guard delivery-evidence attachment recursion against cycles --------- Co-authored-by: Pick-cat <266665499+Pick-cat@users.noreply.github.com> Co-authored-by: Vincent Koc <vincentkoc@ieee.org> (cherry picked from commit498567190d) * fix(opencode-go): re-arm idle timer on block-boundary events to prevent false stalled-stream abort (#97128) * fix(opencode-go): re-arm idle timer on block-boundary events to prevent false stalled-stream abort When the opencode-go model finalizes a tool call and deliberates before the next one, the provider emits real block-boundary SSE events (text_end, thinking_end, toolcall_start, toolcall_end) that prove the socket is alive, but the watchdog's isProviderProgressEvent only returned true for token deltas (text_delta, thinking_delta, toolcall_delta). This caused the idle timer to fire and falsely abort a live stream, replacing a completed answer with a stalled error and dropping the provider's real done event. Fix: include block-boundary events in isProviderProgressEvent so the idle timer is re-armed on any forward-progress provider event. text_start and thinking_start are intentionally excluded because they are synthetic preamble events that should not shorten the first-event window. Closes #96518 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(opencode-go): satisfy lint in stream regression * test(opencode-go): satisfy lint in stream regression * test(opencode-go): satisfy lint in stream regression --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: Vincent Koc <vincentkoc@ieee.org> (cherry picked from commit552ec2b49d) * fix(model-fallback): don't rethrow provider-side AbortErrors as user cancellations (#90908) * fix(model-fallback): don't rethrow provider-side AbortErrors as user cancellations When the LLM API closes the connection mid-stream, the fetch layer surfaces AbortError("This operation was aborted") with no external abort signal triggered. The old guard `shouldRethrowAbort()` returned false for these errors (because isTimeoutError matched the message), so they fell through to the fallback loop but were never retried — the error propagated up and produced SILENT_REPLY_TOKEN in group sessions, permanently silencing the topic. Replace the guard with a direct check: only rethrow AbortError when the external abort signal is actually set (user/gateway cancellation). Provider-side AbortErrors without an external signal now fall through to the next fallback candidate, giving the system a chance to recover. * fix(cron): forward abort signal into runWithModelFallback Thread the cron executor's abort signal into the shared runWithModelFallback call so that cron timeouts and cancellations stop the fallback chain instead of retrying with the next candidate. Previously, the run callback checked params.abortSignal?.aborted and threw, but runWithModelFallback itself had no signal — so the new guard in model-fallback.ts could not distinguish a caller abort from a provider-side AbortError and would retry silently. Also adds a focused regression test verifying the signal is forwarded. --------- Co-authored-by: Shengting Xie <shengting@openclaw.ai> Co-authored-by: yayu <yayu@yayuMacStudio.local> (cherry picked from commit98ed83f848) * fix(browser): block node routes when sandbox host control is disabled (#97958) (cherry picked from commit2cf765f732) * fix(exec): bind Windows allowlist execution path (#98260) * fix(exec): bind windows allowlist execution path * fix(exec): add windows shadow execution proof * fix(exec): preserve wildcard allowlist behavior * fix(exec): correct blocked plan test fixture (cherry picked from commit3811001d27) * fix(mcp): suppress unhandled error on stderr pipe in stdio transport (#99803) * fix(mcp): suppress unhandled error on stderr pipe in stdio transport When child.stderr is piped to stderrStream without an error handler, a stream-level error (EPIPE, I/O failure) crashes the process. Add a noop error handler before the pipe, consistent with the error handlers already present on stdin and stdout. Co-Authored-By: Claude <noreply@anthropic.com> * test(mcp): add regression test for stderr pipe error suppression Co-Authored-By: Claude <noreply@anthropic.com> * fix(mcp): report stderr stream errors * fix(mcp): report stderr stream errors --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Vincent Koc <vincentkoc@ieee.org> (cherry picked from commit1b84316a91) * Harden macOS SQLite WAL checkpoints (#99067) (cherry picked from commitf7f1be276a) * fix(secrets): suppress unhandled stdout/stderr stream errors in exec resolver (#100521) * fix(secrets): suppress unhandled stdout/stderr stream errors in exec resolver * proof(secrets): add real behavior proof script for exec resolver stream error catch * proof(secrets): replace wrapper with real exec resolver stream error proof * style: apply oxfmt to changed files (cherry picked from commitc9a0783922) * fix(agents): retry transient filesystem races when reading workspace bootstrap files (#100910) * fix(agents): retry transient filesystem races when reading workspace bootstrap files * fix(agents): retry transient boundary resolution --------- Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com> (cherry picked from commitf36d170bc6) * fix(gateway): finish plugin HTTP responses after post-header failures (#102125) * fix(gateway): finish plugin HTTP responses after post-header failures * test(gateway): satisfy plugin HTTP regression lint * fix(gateway): skip ending destroyed plugin responses --------- Co-authored-by: Peter Steinberger <steipete@gmail.com> (cherry picked from commit240d350c7f) * fix(gateway): validate exact custom browser origins (#38290) Co-authored-by: Peter Steinberger <steipete@gmail.com> (cherry picked from commitfa0349aa44) * fix: block unspecified trusted DNS targets (#103075) (cherry picked from commitc70f3d0dae) * fix(channels): make nack callbacks idempotent (#104919) * fix(channels): make nack callbacks idempotent * fix(channels): coalesce overlapping nack callbacks --------- Co-authored-by: Peter Steinberger <steipete@gmail.com> (cherry picked from commit02d307e1b8) * fix(channels): prevent base URL credentials in status output (#107754) * fix(channels): redact credentials in account URLs * fix(channels): sanitize final status summaries (cherry picked from commit210340fe93) * fix(channels): prevent lifecycle listener buildup (#109108) (cherry picked from commit0e1fad711c) * fix(sandbox): use Buffer.byteLength for env var value size limit (#105017) * fix(sandbox): use Buffer.byteLength for env var value size limit validateEnvVarValue checked value.length (UTF-16 code units) against the 32768-byte limit, so multi-byte CJK values like "值".repeat(11000) passed the check despite exceeding 33 KB in UTF-8. Switch to Buffer.byteLength(value, "utf8") so the limit matches the actual byte count the OS and child processes see. * test(sandbox): simplify env byte-limit coverage Co-authored-by: 唐梓夷0668001293 <tang.ziyi@xydigit.com> --------- Co-authored-by: Peter Steinberger <steipete@gmail.com> (cherry picked from commit84fb48c3be) * fix(gateway): guard process.kill ESRCH race in signalVerifiedGatewayPidSync (#109590) * fix(gateway): guard process.kill ESRCH race in signalVerifiedGatewayPidSync A verified gateway process can exit between the argv validation check and the process.kill call, causing an unhandled ESRCH error. Wrap the kill in try-catch and silently swallow ESRCH (process already gone = signal already delivered). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(gateway): explain ESRCH signal race Co-authored-by: 丁宇婷0668001435 <ding.yuting@xydigit.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Peter Steinberger <steipete@gmail.com> (cherry picked from commit853b1a8d11) * fix(litellm): guard loopback hostname auto-allow with isIP to prevent DNS SSRF bypass (#110693) * fix(litellm): guard loopback hostname auto-allow with isIP to prevent DNS bypass The isAutoAllowedLitellmHostname helper auto-enables private-network access for loopback-style hosts. Before this fix, lowered.startsWith("127.") matched DNS hostnames like 127.evil.com, letting remote endpoints bypass the explicit allowPrivateNetwork opt-in — a SSRF risk. Add isIP(host)===4 guard so only literal IPv4 loopback addresses qualify. Same canonical pattern as extensions/slack/src/monitor/relay-source.ts:271 and the codex loopback fix. Co-Authored-By: Claude <noreply@anthropic.com> * test(litellm): cover loopback endpoint policy --------- Co-authored-by: Claude <noreply@anthropic.com> Co-authored-by: Peter Steinberger <steipete@gmail.com> (cherry picked from commit3d03b60da9) * fix(discord): sustained gateway bursts stop growing memory (#110954) * fix(discord): sustained gateway bursts stop growing memory * fix(discord): contain gateway queue overflow * fix(discord): drop oldest saturated gateway sends Co-authored-by: 张贵萍0668001030 <zhang.guiping@xydigit.com> * fix(discord): surface gateway overflow warnings Co-authored-by: 张贵萍0668001030 <zhang.guiping@xydigit.com> --------- Co-authored-by: Peter Steinberger <steipete@gmail.com> (cherry picked from commit69aeba9d86) * fix(gateway): bound busy channel health by real run age (#103793) * fix(gateway): bound busy channel health by real run age The channel health policy treats a channel as healthy-busy even while disconnected, bounded only by a 25 minute stale ceiling measured from lastRunActivityAt. The run-state heartbeat refreshes lastRunActivityAt every 60 seconds for as long as any run is active, so a run that hangs forever (for example a send blocking on a dead socket after the transport already reported connected:false) keeps that timestamp fresh and the stuck ceiling is never reached. The account is then reported healthy forever by the health monitor, readiness probe, and health CLI, and no restart ever fires. createRunStateMachine now tracks each in-flight run's start time keyed by an opaque run handle and publishes the oldest still-active run's start as activeRunStartedAt. The health policy busy override keys its ceiling off the real run age, so a run stuck longer than the threshold reports stuck and the monitor can restart it. Because the reported start is the oldest active run and advances to the next-oldest as runs complete, a channel churning through many short overlapping runs (activeRuns above 1 across concurrent queue keys) stays healthy; only a genuinely hung run breaches the ceiling. Short and active runs stay healthy and the existing lastRunActivityAt fallback is preserved for snapshots without a start time. * fix(channels): retain run-state callback compatibility Keep the released zero-argument onRunEnd callback source-compatible while allowing internal queue callers to pass a run handle for exact concurrent-run accounting. The compatibility path closes the oldest active run, preserving existing lifecycle behavior for consumers that do not use handles. * fix(channels): keep anonymous runs out of age tracking The zero-argument lifecycle callbacks cannot identify which concurrent run completed, so they must not update the identity-sensitive run start used by channel health. Keep their busy count separately and reserve exact start tracking for the shared queue's handle-aware lifecycle path. * fix(channels): keep tracked runs internal Keep the public run-state lifecycle callbacks unchanged. The channel queue now owns opaque run identity and augments its status updates with the oldest active queue run, so implementation details do not expand the SDK surface. * fix(channels): type queue run start status Keep activeRunStartedAt in the internal status patch type so the queue can publish its private tracked-run age through the existing status sink. * fix(channels): wrap isActive to satisfy unbound-method lint * fix(gateway): gate busy run-age ceiling on disconnected transport (cherry picked from commit18b79d99ab) * fix(deps): update fast-uri past advisory (cherry picked from commit1be9db038f) * fix(release): adapt maintenance-line hardening Backport/adapt18ec9ce8f7,dea1fe1f11,7f32b6c984,1da345e9d3,931ac3e2b5,89780d5a60, andc0d99ed26efor the 2026.6 extended-stable maintenance line. * fix(deps): bump protobufjs to 7.6.5 Backport-adapted froma230f742f2. * test(gateway): cover bounded macOS process probe * chore(release): prepare 2026.6.34 * test(dotenv): share path override environment assertions * fix(release): resolve 2026.6.34 CI blockers --------- Signed-off-by: sallyom <somalley@redhat.com> Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com> Co-authored-by: Peter Lee <li.xialong@xydigit.com> Co-authored-by: sallyom <somalley@redhat.com> Co-authored-by: openclaw-clownfish[bot] <280122609+openclaw-clownfish[bot]@users.noreply.github.com> Co-authored-by: Liu Wenyu <117838866+indulgeback@users.noreply.github.com> Co-authored-by: pick-cat <huang.ting3@xydigit.com> Co-authored-by: Pick-cat <266665499+Pick-cat@users.noreply.github.com> Co-authored-by: Vincent Koc <vincentkoc@ieee.org> Co-authored-by: weiqinl <liu.weiqin@xydigit.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: shengting <xieyayu@163.com> Co-authored-by: Shengting Xie <shengting@openclaw.ai> Co-authored-by: yayu <yayu@yayuMacStudio.local> Co-authored-by: Agustin Rivera <31522568+eleqtrizit@users.noreply.github.com> Co-authored-by: cxbAsDev <chen.xianbiao@xydigit.com> Co-authored-by: ooiuuii <al3060388206@gmail.com> Co-authored-by: Masato Hoshino <g515hoshino@gmail.com> Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com> Co-authored-by: mushuiyu886 <yang.haoyu@xydigit.com> Co-authored-by: Peter Steinberger <steipete@gmail.com> Co-authored-by: Bruno Wowk (Volky) <bruno.wowk@gmail.com> Co-authored-by: Pavan Kumar Gondhi <pavangondhi@gmail.com> Co-authored-by: Glucksberg <80581902+Glucksberg@users.noreply.github.com> Co-authored-by: xingzhou <zhang.guiping@xydigit.com> Co-authored-by: tzy-17 <tang.ziyi@xydigit.com> Co-authored-by: krissding <ding.yuting@xydigit.com> Co-authored-by: lsr911 <liao.shirong@xydigit.com> Co-authored-by: Yuval Dinodia <102706514+yetval@users.noreply.github.com>
@openclaw/diffs
Read-only diff viewer plugin for OpenClaw agents.
Install
openclaw plugins install @openclaw/diffs
Restart the Gateway after installing or updating the plugin.
It gives agents one tool, diffs, that can:
- render a gateway-hosted diff viewer for canvas use
- render the same diff to a file (PNG or PDF)
- accept either arbitrary
beforeandaftertext or a unified patch
What Agents Get
The tool can return:
details.viewerUrl: a gateway URL that can be opened in the canvasdetails.filePath: a local rendered artifact path when file rendering is requesteddetails.fileFormat: the rendered file format (pngorpdf)details.artifactIdanddetails.expiresAt: artifact identity and TTL metadatadetails.context: available routing metadata such asagentId,sessionId,messageChannel, andagentAccountId
When the plugin is enabled, it also ships a companion skill from skills/ and prepends stable tool-usage guidance into system-prompt space via before_prompt_build. The hook uses prependSystemContext, so the guidance stays out of user-prompt space while still being available every turn.
This means an agent can:
- call
diffswithmode=view, then passdetails.viewerUrltocanvas present - call
diffswithmode=file, then send the file through the normalmessagetool usingpathorfilePath - call
diffswithmode=bothwhen it wants both outputs
Tool Inputs
Before and after:
{
"before": "# Hello\n\nOne",
"after": "# Hello\n\nTwo",
"path": "docs/example.md",
"mode": "view"
}
Patch:
{
"patch": "diff --git a/src/example.ts b/src/example.ts\n--- a/src/example.ts\n+++ b/src/example.ts\n@@ -1 +1 @@\n-const x = 1;\n+const x = 2;\n",
"mode": "both"
}
Useful options:
mode:view,file, orbothDeprecated alias:imagebehaves likefileand is still accepted for backward compatibility.layout:unifiedorsplittheme:lightordark(default:dark)fileFormat:pngorpdf(default:png)fileQuality:standard,hq, orprintfileScale: device scale override (1-4)fileMaxWidth: max width override in CSS pixels (640-2400)expandUnchanged: expand unchanged sections (per-call option only, not a plugin default key)path: display name for before and after inputlang: language hint for before/after input; unknown values fall back to plain text- Default syntax highlighting covers common source, config, and documentation languages. Install
diffs-language-packfor the extended language catalog. title: explicit viewer titlettlSeconds: artifact lifetime for viewer and standalone file outputsbaseUrl: override the gateway base URL used in the returned viewer link (origin or origin+base path only; no query/hash)viewerBaseUrlplugin config: persistent fallback used when a tool call omitsbaseUrl
Legacy input aliases still accepted for backward compatibility:
format->fileFormatimageFormat->fileFormatimageQuality->fileQualityimageScale->fileScaleimageMaxWidth->fileMaxWidth
Input safety limits:
beforeandafter: max 512 KiB eachpatch: max 2 MiB- patch rendering cap: max 128 files / 120,000 lines
Plugin Defaults
Set plugin-wide defaults in ~/.openclaw/openclaw.json:
{
plugins: {
entries: {
diffs: {
enabled: true,
config: {
defaults: {
fontFamily: "Fira Code",
fontSize: 15,
lineSpacing: 1.6,
layout: "unified",
showLineNumbers: true,
diffIndicators: "bars",
wordWrap: true,
background: true,
theme: "dark",
fileFormat: "png",
fileQuality: "standard",
fileScale: 2,
fileMaxWidth: 960,
mode: "both",
ttlSeconds: 21600,
},
},
},
},
},
}
Explicit tool parameters still win over these defaults.
Docs
Package
- Plugin id:
diffs - Package:
@openclaw/diffs - Minimum OpenClaw host:
2026.4.30
Security options:
security.allowRemoteViewer(defaultfalse): allows non-loopback access to/plugins/diffs/view/...token URLsviewerBaseUrl(optional): persistent viewer-link origin/path fallback for shareable URLsdefaults.ttlSeconds(default1800, max21600): default artifact lifetime for viewer and standalone file outputs
Example:
{
plugins: {
entries: {
diffs: {
enabled: true,
config: {
viewerBaseUrl: "https://gateway.example.com/openclaw",
},
},
},
},
}
Example Agent Prompts
Open in canvas:
Use the `diffs` tool in `view` mode for this before and after content, then open the returned viewer URL in the canvas.
Path: docs/example.md
Before:
# Hello
This is version one.
After:
# Hello
This is version two.
Render a file (PNG or PDF):
Use the `diffs` tool in `file` mode for this before and after input. After it returns `details.filePath`, use the `message` tool with `path` or `filePath` to send me the rendered diff file.
Path: README.md
Before:
OpenClaw supports plugins.
After:
OpenClaw supports plugins and hosted diff views.
Do both:
Use the `diffs` tool in `both` mode for this diff. Open the viewer in the canvas and then send the rendered file by passing `details.filePath` to the `message` tool.
Path: src/demo.ts
Before:
const status = "old";
After:
const status = "new";
Patch input:
Use the `diffs` tool with this unified patch in `view` mode. After it returns the viewer URL, present it in the canvas.
diff --git a/src/example.ts b/src/example.ts
--- a/src/example.ts
+++ b/src/example.ts
@@ -1,3 +1,3 @@
export function add(a: number, b: number) {
- return a + b;
+ return a + b + 1;
}
Notes
- The viewer is hosted locally through the gateway under
/plugins/diffs/.... - Artifacts are ephemeral and stored in the plugin temp subfolder (
$TMPDIR/openclaw-diffs). - Default viewer URLs use loopback (
127.0.0.1) unless you set pluginviewerBaseUrl, passbaseUrl, or usegateway.bind=custom+gateway.customBindHost. - If
gateway.trustedProxiesincludes loopback for a same-host proxy (for example Tailscale Serve), raw127.0.0.1viewer requests without forwarded client-IP headers fail closed by design. - In that topology, prefer
mode=file/mode=bothfor attachments, or intentionally enable remote viewers and set pluginviewerBaseUrl(or pass a proxy/publicbaseUrl) when you need a shareable viewer URL. - Remote viewer misses are throttled to reduce token-guess abuse.
- PNG or PDF rendering requires a Chromium-compatible browser. Set
browser.executablePathif auto-detection is not enough. - If your delivery channel compresses images heavily (for example Telegram or WhatsApp), prefer
fileFormat: "pdf"to preserve readability. N unmodified linesrows may not always include expand controls for patch input, because many patch hunks do not carry full expandable context data.- Diff rendering is powered by Diffs.