Repository navigation
sync up - #4
Open
tearsofphoenix wants to merge 10000 commits into
Open
sync up#4tearsofphoenix wants to merge 10000 commits into
tearsofphoenix wants to merge 10000 commits into
Conversation
* test(gateway): deslop s819 tests * test(desktop): deslop s820 tests * test(gateway): deslop s821 tests * test(gateway): deslop s818 tests * test(gateway): deslop s809 tests * test(gateway): deslop s822 tests * test(gateway): deslop s823 tests * test(gateway): retain distinct audit contracts * test(gateway): retain bare token redaction coverage
Derive model-catalog and browser-download pending flags from their active request controllers, and project MCP server rows from the subscribed runtime configuration snapshot. Remove seven net production lines while preserving request lifecycle checks, rendering notifications, configuration writes, and persisted data. No tests or baselines changed. Validated with 173 focused UI tests, lint-suppression tests, zero runtime/static import cycles, type/lint/Knip gates, independent P2 review, and green hosted CI on the exact PR head.
…153545) Charge recognized nonempty text, thinking and tool-input stream deltas for their encoded payload plus a fixed per-frame allowance, so long streamed Claude CLI turns keep their final reply and tool arguments while the 8 MiB budget still bounds tiny-delta floods. Ordinary records keep the 20,000-frame limit and the per-line limit is unchanged. Closes #150132. Co-authored-by: Ayaan Zaidi <[email protected]>
…#166329) Give wiki_search a deadline and thread the abort signal through page reading, scoring and shared-memory search, so a large vault returns a deadline error instead of hanging the turn, and chat.abort stops the CPU-bound scoring. No stored data or persisted format changes. Fixes #166303. Co-authored-by: Ayaan Zaidi <[email protected]>
Ask for confirmation before switching the exec approvals target in Devices when the current draft has unsaved changes; Cancel keeps the target and edits, Discard switches and clears them. Closes #127500. Co-authored-by: Ayaan Zaidi <[email protected]>
Encode and decode the error and suppressed branches of native and downlevel SuppressedError across the worker boundary, so broker-delivered disposal errors keep both the operation failure and the cleanup failure. Co-authored-by: Ayaan Zaidi <[email protected]>
Co-authored-by: Vincent Koc <[email protected]>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
…ches (#166355) Admit digest candidates whose metadata contains every query token, matching the live page scorer, so multi-term wiki_search queries no longer fall back to reading the whole vault. Analysis by @etzelm. Fixes #166302. Co-authored-by: Ayaan Zaidi <[email protected]>
) Add the togetherai catalog alias to the Together plugin manifest so models.dev togetherai/... refs resolve through the owning Together plugin; existing together/... refs are unchanged. Co-authored-by: Cursor <[email protected]> Co-authored-by: Ayaan Zaidi <[email protected]>
Use the existing normalization, AST, and carrier HTTP owners directly across non-channel plugins. Remove duplicate projections, unused private parameters, forwarding layers, and comments that restate code across plugins and shared packages. Preserve configuration, stored data, protocol and tool shapes, error messages, cleanup, security checks, and legacy state-directory autodetection. Remove 1,113 net production lines; shrink the assertion baseline without adding suppressions. Validation: zero import cycles; production and test typechecks, changed-file lint and guards, unused-export scans, 2,595 focused tests, 1,140 plugin contract cases, and 3 suppression cases passed on Testbox. Existing platform skips remain unchanged.
Reuse the existing Plugin SDK map-pruning and configured-account-value helpers in llama.cpp, Ollama, and Policy. Preserve both cache bounds, their distinct eviction ordering, and account-value interpretation. No public API, configuration, protocol, or persisted-data changes. Net production reduction: 13 lines. The PR records the BELOW-1000 coverage log and semantic differences that prevented larger safe replacements. Validation: 404 focused extension tests, lint-suppression and map-helper tests, complete changed-file checks, both extension typecheck graphs, zero runtime/static import cycles, and clean independent review. Exact-head CI passed in run 37552079752; four cancelled auxiliary jobs passed on rerun.
…#162067) Raise the background session observer utility-call cap from 10s to 30s so CLI-backed utility models such as claude-cli, which spend most of a call on process startup, can produce digests. A stuck call is still aborted at the cap and the observer runs off the turn path. Co-authored-by: Rogério Chaves <[email protected]> Co-authored-by: Ayaan Zaidi <[email protected]>
* perf(gateway): bound anchored history pages and message groups * fix(gateway): bound history continuation metadata * test(gateway): align history budget and output recovery expectations * test(ui): narrow history recovery request parameters
Add the stepfun-ai and stepfun-ai-step-plan catalog aliases to the StepFun plugin manifest so models.dev refs resolve through the owning StepFun providers; canonical refs are unchanged. Co-authored-by: Cursor <[email protected]> Co-authored-by: Ayaan Zaidi <[email protected]>
…ion cannot load on this host (#165820) Closes #165791 Reported by @NovaUnboundAi.
Preserve browser reply destinations when background completion delegates and yields, so the final reply settles once. Fixes #166344.
* refactor(gateway): share successful agent test setup * chore: incorporate canonical dependency repair for gateway fixture proof Co-authored-by: Vincent Koc <[email protected]>
…nts trust the egress proxy (#165818) Closes #139151 Supersedes #139818 Refs #165789 Co-authored-by: Vortex Openclaw <[email protected]> LibreSSL root cause by @A1fred-AI.
… updater is signaled mid-activation (#165863) Refs #164074 Reported by @chrisreed14 and @dankarization.
…ime (#166060) * fix(worktrees): reserve pending slots for parallel creation Reserve names, owners, and live-plus-pending capacity under short allocation custody; materialize and set up checkouts under their own mutation leases. Publish atomically and retain custody until rollback settles. Give templates independent persisted build and reader custody, and preserve uncertain native artifacts through existing GC recovery. Reuse state_leases without a schema migration. Existing state loads unchanged. Deterministic owner regressions fail on the original global-lease path; local Git, SQLite, acceleration, source, restore, and eviction checks pass. Five-create isolated sample improves from 24.272s to 9.652s with higher peak RSS. Recovery retains uncertain paths and template readers rather than deleting potentially active native work. * fix(worktrees): recover custody after creator crashes Reclaim dead pending admissions before allocation and reap dead template readers without waiting for another OS boot. Preserve incomplete checkout paths and reject retained explicit names with recovery guidance. Share the existing contention budget across create retries. Keep parallel materialization outside the global lease. Cover restart, owner/name reuse, deadline exhaustion, and the checkout mutation lease used by W16 fault injection tests. No schema or configuration migration. * fix(worktrees): complete reservation recovery integration Preserve current-main index cloning, pack-index repair, and complete cleanup outcomes. Recover dead pending admissions after queued contenders release checkout custody, without changing live-owner refusal or lease ordering. Remove the superseded template touch path, bind stale-GC proof to template custody, and include reservation dependencies in extracted PR wrappers. Existing owner and downstream suites pass; new waiter cases fail before the repair. Core types retain the pinned-main missing gatewayLog error outside this owner. * fix(worktrees): consolidate template SQL in worker owner Use the admitted worker database for template reads, writes, and reader custody. Remove the synchronous registry implementation and its nested transaction; migrate test callers to the async owner. Keep transaction and commit admission and native settlement intact. The SQLite worker ratchet falls from 850 T1 operations to 838 (base: 846). A real broker regression fails on the previous implementation when an explicit database differs from the environment default, and passes through the selected worker database after the cutover. Existing schema and retention contracts are unchanged. * test(worktrees): route provisioning proof through database broker * fix(worktrees): route pending recovery through provisioning worker Keep allocation recovery available in the extracted PR wrapper without loading the application command runtime. Reuse the existing run-end transaction, lease validation, and recovery kernel; remove the superseded dispatcher registration and consume the central command contract. Exercise allocation recovery in the extracted bootstrap regression and align the GC ranking fixture with its synthetic slot inventory. Both the native PR flow and the upgraded bootstrap test failed on the previous routing; the bootstrap passes after the cutover. No schema, retention, or public command changes. * fix(worktrees): exclude preparation from contention waits Share cumulative acquisition time across admission, checkout, and template lease waits. Completed preparation can acquire a free publication lease even after exhausting its contention budget; further contention retains actionable timeout diagnostics. Preserve create cleanup operation diagnostics and the branch-exists refusal for retained sparse checkouts. Correct provisioning test ownership and isolate recovery settlement in project cancellation fixtures without weakening outcome assertions. Add fake-clock regressions that fail before the repair. * fix(worktrees): keep template validation index read-only
* refactor(channels): deslop channels Reuse canonical normalization and delivery facts, remove redundant forwarding and error layers, and delete narrating comments while preserving protocol, lifecycle and authority contracts. Full production coverage for lane l406 is recorded with the PR. * refactor(channels): finish small-module deslop sweep * refactor(channels): preserve async snapshots and tighten fixtures * refactor(channels): finish owner and normalization cleanup * test(zalo): await polling image processing before assertions * refactor(channels): finish owner cleanup and repair lane checks
Maintainer-approved designs with green review and exact-head proof land autonomously; size, persistent state, or refactor breadth alone no longer park a ready PR for sign-off. Undecided product/contract choices, open defects, bad proof, and security changes needing their owner still hold.
* refactor(macos): consolidate native app state and handlers Share catalog validation, capture resources, socket lifecycle settlement, and native handler variants while retaining existing configuration, wire shapes, user-visible text, and authority checks. Derive parallel state from its existing owners and migrate tests off removed internal seams. * fix(macos): preserve localization keys during consolidation
…166444) * refactor(placement): run lifecycle and grant preparation in workers * test(placement): retain lifecycle boundaries in worker fixtures * test(placement): align startup and recovery owner lifetimes * perf(placement): avoid single-query projection transactions * fix(placement): retire cached stores and preserve move cancellation errors Invalidate the embedded placement cache when its physical database owner retires, keeping previously retained stores revoked. Return an explicit no-change receipt when conditional move cancellation loses its local generation so the original abort remains visible and no stale intent is deleted or published. Restore the canonical ordering of worker test paths. Existing user-flow regression assertions remain unchanged; the internal conditional cancellation test now asserts false and preserved intent. * test(placement): update worker lifecycle fixture contracts Model the asynchronous placement readers, move lookup, and retirement methods consumed by the worker cutover. Preserve existing destination, recovery publication, and session-event assertions. * fix(sdk): keep final grant consumption out of deprecation metadata The consume method remains the synchronous final authorization boundary and has no async replacement. Keep its compatibility type assertion while removing the incorrect deprecated-surface marker. * fix(gateway): settle concurrent placement retirement Treat an already-absent placement as a completed worker retirement while preserving state, generation, and live-claim fences. Keep released synchronous retirement strict and avoid publishing a fabricated state change. * fix(gateway): keep retirement absence checks in worker * test(gateway): bind retirement regression to its placement owner * test(gateway): let recovery fixture settle work before closing
* fix(diagnostics): expose live session and run gauges * fix(gateway): reconcile public reads before delivery * test(gateway): align channel status fixture with inspection
Consolidate guarded refresh, approval and Workshop, chat mutation, device/voice, and presentation logic. Remove unused internal plumbing and redundant state while preserving features, text, authority checks, cancellation, recovery, and protocol/storage shapes. Remove 3,028 net production Kotlin lines (2.87%), excluding tests, fixtures, test support, and generated files. Preserve test assertions and existing lint exceptions; both final Android flavor builds, lint gates, and hosted full unit suites pass. The pre-existing local foreground-service timeout and its passing hosted counterpart are documented in the PR.
Answer skills/list with its required data array so recovered startup paths reach the retry and shared-client assertions. Preserve every existing case, assertion, ordering, and timeout.
* perf(session-readers): reuse captured admission facts * chore(session-readers): shrink assertion safety baseline * refactor(session-readers): keep index collector private * refactor(session-readers): make custody predicates explicit * test(session-readers): retire the current projection cache in lifetime checks Main moved ordered metadata reads to the projection lane in #166365. Retire that cache before checking for leaked request registrations, preserving all existing response, authority, and no-resource assertions. A diagnostic at the integrated head reproduced the failure and identified only the idle projection reader's physical path and alias. Both corrected files pass all 112 cases locally. Fresh P2 review, targeted types, lint, and formatting pass. Production source is byte-identical to 853cefe.
* test(qa): repair live frontier scenario drift Align approval response assertions, require concrete runtime tool operations, and use the live turn budget for persisted completion evidence. Verify fanout through retained parent synthesis and linked spawn receipts after child cleanup. Private QA only; no shipped product changes. Eight selected scenarios pass with live OpenAI on a fresh Testbox and with the local mock provider. Owner regressions fail against the original harness. * test(qa): require completed child runs for fanout proof Correlate accepted child sessions and run IDs with retained successful terminal results before accepting parent synthesis. Reject unfinished, failed, yielded, mismatched, and empty child results while preserving delete-cleanup support. Match the existing distinct mock worker outputs.
Read declared capabilities and recorded runtime health during agent tool discovery. Prepare a native helper only when computer use needs it, preserving the shipped RPC default, cold V2 action discovery, and live generation/caller fencing. Keep CUA declarations free of driver acquisition. Validated with focused and sibling suites, complete changed-plan checks, a full build, and a real-helper Linux comparison: cold discovery 1628-1786 ms to 0.42-5.24 ms; passive p99 below 0.039 ms. CI infrastructure exception: run 37640765640 recorded 64 successful and 20 skipped jobs but failed with a GitHub workflow-level Internal server error. Independent security/dependency reviews and final-head code review passed. No CI rerun.
Pin the macOS app to Peekaboo 4.9.0. Resolution moves AXorcist to 0.2.1 and Commander to 0.3.0, so the local Swabble package now pins Commander 0.3.0 as well and resolves its root-command-first argument tail through resolve(arguments:), matching Swabble 0.1.1 upstream.
Capture storage routing with the admitted worker turn and use that binding for trajectory and transcript persistence. When a worker and Gateway share a process, the worker's temporary state directory could otherwise bind the Gateway agent file to the wrong shared-state owner and block commits. Preserve the trajectory capture toggle and live source authority. Replace the composed fixture's separate commit-only environment override with the same prepared target used by production. Extend storage, opt-out, and immutable-target coverage without changing cancellation assertions or waits. Complements the terminal transcript rejection fix in 5dcf668 and builds on the composed storage fixture work in #163637. Co-authored-by: Jacob Tomlinson <[email protected]>
…e low-value tests (batch d006) (#166642) * test(agents): deslop w1060 tests * test(sessions): deslop w1059 tests * test(cron): deslop w1057 tests * test(plugins): deslop w1062 tests * test(infra): deslop w1058 tests Remove redundant cases and consolidate four split files while retaining ownership races, version regressions, and Windows/Bun CI routing. No case folding. Declarations 94 to 84; counter-expanded cases 182 to 133; test LOC 5777 to 5471. Testbox: 134 passed, 5 platform skips. Repaired-baseline coverage: statements 7610 to 7598, branches 4157 to 4154, reproduced twice. Targeted typed lint and dead-export scans passed. Full changed checks retain the independently reproduced baseline UI signal type error and four unchanged max-lines violations. * test(infra): deslop w1066 tests * test(exec): deslop w1063 tests * test(agents): deslop w1065 tests * test(channels): deslop w1064 tests * test(gateway): deslop w1067 tests * test: preserve protected CI routing for consolidated suites * test: retain independent security and migration regressions
…166631) Drive transcript anchor resolution from the requested IDs through the existing event identity primary key. Preserve snapshot sequence fences and existing string-set binding while avoiding unrelated history reads after restart.
…66575) * refactor(codex): consolidate internal lifecycle and adapter paths * fix(codex): preserve promise compatibility in package builds
Show identical saved or sealed commentary and live assistant text once within the latest user turn in the shared Apple chat UI. Preserve the underlying stream, canonical transcript, and run lifecycle; different live text and later user turns remain visible. Original implementation and native regression proof by @Marvinthebored. Reused source-bound hosted/simulator proof, exact-head CI, and a fresh independent P0-P2 review. No new live-provider or physical-device execution is claimed. Co-authored-by: Solvely-Colin <[email protected]> Co-authored-by: Marvinthebored <[email protected]>
…166621) * refactor(gateway): share chat preparation and reply finalization * refactor(gateway): consolidate session read and mutation paths * refactor(gateway): consolidate method handlers and response projections * refactor(gateway): simplify ordered patch validation and final aliases * refactor(gateway): make shared callback contracts explicit * refactor(gateway): reuse the initial artifact target * refactor(gateway): keep queued node policy checks explicit
Allow a new OpenAI-compatible or plugin ingress turn once canonical recovery custody has settled. The old abortedLastRun check mistook the historical Stop outcome for unfinished recovery and rejected the turn with SESSION_WORK_START_CHANGED. Reuse the existing claim predicate while preserving session identity, generation, pending-final, and delivery protections. Extend the SQLite owner's recovery-authority regression with interrupted and real Stop-produced outcomes. Both cases fail before the correction. A direct-ingress probe also rejects before the fix and completes one model invocation with the expected delivery text afterward. Validation: 269 recovery owner/caller tests; fresh-main owner file 40/40 in 548.25s wall; direct-ingress before/after; four real-Gateway compatibility cases; lint-suppression tests 3/3; changed-file type, lint, and guard stages; both cycle checks. Production and full-tree Knip scans passed on AWS under the unchanged 600s deadlines after local scans timed out.
The grapheme lookahead added in 627d16b split an otherwise complete cap-sized tail into a short prefix and a final fragment. Twelve ASCII characters with a four-character budget produced 4/4/3/1 blocks. Keep that whole pending tail until another delta or final drain establishes its boundary. Preserve grapheme safety and the existing leading/oversized cluster progress exception. The no-replay assertion remains unchanged; the owner test also verifies full-sized ASCII chunks during incremental input.
…all back to the exact npm release when ClawHub lags (#166588) Refs #166554 Reported by @CodeForcer.
…166636) Consolidate Telegram transport preparation, delivery operations, and per-variant handling. Derive lifecycle state from its owning promises, queues, and accepted-message records, and remove redundant parameter forwarding. Remove 1,683 net production lines (3.10%) while preserving message text, authorization, recovery, configuration, protocol fields, and persisted records. Tests and assertions are unchanged; the assertion-safety baseline shrinks by 11 removed assertions. Validated all 172 Telegram test files, routing integration, typechecks, zero runtime/static cycles, SDK and schema identity, full changed checks, and lint-suppression checks. Exact-head hosted CI passed after rerunning 13 matrix jobs that never started in the first attempt. Real Telegram Test Server proof observed typing, same-message progress edits, native reply linkage, persistent final delivery, and progress deletion.
* perf(cli): reduce gateway call cold-start imports Let the Gateway transport own dispatch configuration, preserving environment resolution facts for literal credentials and rereading only after shell env fallback changes its inputs. Defer plugin-install policy, SecretRef resolution, and TLS certificate inspection until needed, and retire the unused program barrel after moving its callers to the builder. Keep raw Gateway calls usable without validating unrelated configuration. Regression coverage preserves escaped credentials, authentication, CLI output, and read-only state behavior. Paired cold-process timing on the Linux rig improved from 1.904s to 1.617s median; the 500ms target remains unmet. * test(cli): prepare smoke workers before action deadlines * fix(cli): keep force cleanup signal errors outside discovery fallback * test(cli): harden port cleanup fixtures * test(cli): exercise config read recovery through gateway probe
…166659) * refactor(outbound): simplify heartbeat target resolution * refactor: consolidate outbound delivery and auth profile lifecycles * fix(outbound): preserve the public queue failure callback contract * test(outbound): preserve completion mock exports * refactor: finish auth and delivery export cutovers * refactor: preserve lint contracts in outbound and auth consolidation
…#166610) Feishu streaming replies now replace obsolete pending previews when a CardKit write is delayed, instead of replaying each stale preview before the completed answer. Snapshot admission remains ordered; the existing streaming session still owns provider writes, finalization, and accepted delivery receipts. Related: #91941 Validated with delayed loopback HTTPS before/after regression proof, Feishu and shared-control tests, changed checks, build, and upstream CI. This does not claim authenticated Feishu-tenant latency testing. Co-authored-by: Rudy Celekli <[email protected]> Co-authored-by: Tak Hoffman <[email protected]> Co-authored-by: Takhoffman <[email protected]>
* fix(slack): keep final replies below later human messages * fix(slack): preserve ingress scope and Stop across stream rotation * test(slack): retire repaired mock export baseline --------- Co-authored-by: Patrick Erichsen <[email protected]>
Align the exact facts-listener expectation with f6e6805, which marks runtime-only lifecycle and observer updates as unchanged stored facts so prepared sharing authority survives presentation updates. Public row notifications still omit these internal facts. Keep the accepted-commit contract strict for both listeners: rejected writes emit nothing, accepted writes emit exactly once, and stale or duplicate work emits nothing further. No production behavior or test deadline changes.
Load the CLI version fast path only for executable startup, so package-root library imports no longer load the version helper. --version still returns early. Related: #162199 Co-authored-by: Ayaan Zaidi <[email protected]>
Let the OpenClaw helper run on its own verified default route when its caller was admitted on a different runtime generation or a benign inventory reload landed between calls, instead of rejecting the call. A genuinely changed model definition is still rejected. Related: #139710 Co-authored-by: Ayaan Zaidi <[email protected]>
Restores artifact-preserving reads for Doctor's device-identity detector during migration planning (regressed in #166523). Proven with a published-driver (2026.9.8) x candidate cell.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Describe the problem and fix in 2–5 bullets:
If this PR fixes a plugin beta-release blocker, title it
fix(<plugin-id>): beta blocker - <summary>and link the matchingBeta blocker: <plugin-name> - <summary>issue labeledbeta-blocker. Contributors cannot label PRs, so the title is the PR-side signal for maintainers and automation.Change Type (select all)
Scope (select all touched areas)
Linked Issue/PR
Root Cause (if applicable)
For bug fixes or regressions, explain why this happened, not just what changed. Otherwise write
N/A. If the cause is unclear, writeUnknown.Regression Test Plan (if applicable)
For bug fixes or regressions, name the smallest reliable test coverage that should catch this. Otherwise write
N/A.User-visible / Behavior Changes
List user-visible changes (including defaults/config).
If none, write
None.Diagram (if applicable)
For UI changes or non-trivial logic flows, include a small ASCII diagram reviewers can scan quickly. Otherwise write
N/A.Security Impact (required)
Yes/No)Yes/No)Yes/No)Yes/No)Yes/No)Yes, explain risk + mitigation:Repro + Verification
Environment
Steps
Expected
Actual
Evidence
Attach at least one:
Human Verification (required)
What you personally verified (not just CI), and how:
Review Conversations
If a bot review conversation is addressed by this PR, resolve that conversation yourself. Do not leave bot review conversation cleanup for maintainers.
Compatibility / Migration
Yes/No)Yes/No)Yes/No)Risks and Mitigations
List only real risks for this PR. Add/remove entries as needed. If none, write
None.