4 Commits
Author SHA1 Message Date
e3ce08cd5e feat(talk): support native realtime for thin audio clients (#134003)
* feat(talk): support native realtime for thin audio clients

Preserve native model and authentication selection while reusing the Gateway sideband for transcripts, readiness, spoken controls, and scoped agent consultations. Keep legacy browser ownership and the stable bridge binding intact; fence post-flush admission without cancelling accepted native work on detach.

Related: native realtime control for thin audio clients — https://github.com/openclaw/openclaw/issues/133844

* fix(talk): preserve intentional consult cancellation

Preserve canonical cancellation and timeout outcomes before projecting consult results into speech. Share native browser and relay cancellation handling and retain the GA canceled result, without changing accepted-work transport detach semantics.

Regression proof reproduces canceled empty, partial, and rejected backend results at the real Gateway owner boundary. Validation: 498 focused tests, changed checks, SDK surface, import cycles, and full build. Live native media proof remains pending for #134003; related feature request #133844.

* test(talk): load native provider through SDK public surface

* fix(talk): keep native controls out of agent delegation

Classify intrinsic status and cancellation before native task replacement, preserving active and pending work. Keep transcript-owned idle controls distinct from tool-capable late-ASR handling, and preserve the shipped transcript callback contract. Refs #133844 (native Gateway control for thin audio clients).

* fix(talk): require negotiated control binding

Make explicit Gateway control require its host command binding while preserving unclaimed requests and the stable GA full-bridge adapter. Cover valid and rejected SDK requests at compile time and retain the JavaScript ingress guard.

Refs: #134003, #133844

* test(talk): register intentional invalid-host coverage

Register the single approved negative-test inventory entry. Keep strict negotiated-control types, runtime rejection before session reservation, and the existing zero-unsafe-cast checks unchanged.

Refs: #134003

* fix(talk): isolate controls by logical voice call

Bind provider-attached native/GA and relay run selection to the live logical voice binding, including final-use checks. Preserve session-wide talk.client.steer and accepted work across same-call transport replacement.

The four two-call status/cancel regressions fail before this repair; 186 owner and sibling tests plus core typechecks pass afterward. Fresh scoped Codex autoreview found no actionable P0 findings. Live two-call proof and final build/CI remain required before landing.

Follow-up for #134003 and #133844.

* test(talk): avoid shadowing the native transcript event

* fix(talk): make native acknowledgments host-owned

Disable provider delegation fillers for host-classified native calls and send one neutral receipt only when a task launches. Status and cancellation wait for the authoritative host result; legacy browser and tool-call bridge defaults remain unchanged.

Refs: https://github.com/openclaw/openclaw/pull/134003 https://github.com/openclaw/openclaw/issues/133844

* fix(talk): bind native controls to live host authority

Admit native voice actions from delegation events instead of replaying
final transcripts. Keep status, steering, cancellation, and control replies
bound to the originating call and captured work, with visible bounded
queue refusal and recovery.

Prepare direct and maintenance run authority at the host execution owner,
project current caller policy, and revalidate exact registration and
lifetime at the final queue or question effect. Preserve rich chat-backed
Talk authority and the shipped SDK dependency callback contract.

Keep unrelated Discord attribution changes out of this candidate; its
existing missing-authority steering refusal remains unchanged.

Refs #134003, #133844, #126733.

* fix(talk): preserve queued reply and policy ownership

Preserve session-scoped Talk controls for an exact queued reply owner without relaxing voice-session backend fencing. Derive tool capability identity from the executing session while retaining independent sandbox policy classification. Covers the two exact-head CI regressions and publication-order boundaries for PR #134003.

* fix(talk): fence controls at final message injection

Keep accepted backing work alive after a voice call closes, but reject its
retained controls after call closure, claim reassignment, or backend replacement.
Carry a host-owned per-injection assertion through versioned core and Codex
queue, question, and physical-dispatch boundaries, including overload retries.
Preserve exact voice claim identity across genuine reassignment while allowing
identical registration replay.

Retain the shipped V1 SDK contract. Copilot remains explicitly unavailable for
source-bound steering until its SDK exposes a final-dispatch guard; ordinary
unscoped injection remains supported. No unchecked fallback or new SDK export
budget is introduced.

Native realtime thin-client work: https://github.com/openclaw/openclaw/pull/134003

Validation: real final-insertion RED/GREEN, 442 focused and sibling tests,
scoped compiler/lint/format, unchanged SDK budgets, full build, and independent
P0 autoreview. Aggregate changed checks reached the separately landed SDK
retention metadata repair, which is being brought forward before publication.

* fix(talk): preserve rejected SDP responses before connection close

Adopt the OpenAI offer portion of the shared HTTP rejection repair from
32b4abb341 without restoring the old inline
OAuth resolver or changing native Gateway-control ownership.

Use the existing response-before-close owner for body-limit and timeout
failures. Keep the SDP size and time bounds, security headers, single-use
reservations, and all post-await native authority checks. Reuse upstream
raw-socket tests and private-local test support; public SDK exports do not grow.

Native thin-client work: https://github.com/openclaw/openclaw/pull/134003
Upstream repair: https://github.com/openclaw/openclaw/commit/32b4abb3413cb53708d83d6932650dda7d4db91f

Validation: real TCP RED/GREEN, 158 focused/sibling tests, 48 HTTP tests on
Node 24, full build, required five-file changed gates, and independent P0
review. The adjacent auth-resolver move still requires Git ancestry integration
before publication; no claim of mergeability or final-source live proof.

Co-authored-by: Eden <aa9736195201@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>

* fix(talk): remove duplicate rejection after main integration

* test(talk): align guarded authority fixtures and suite ownership

Give the GA reply-authority fixture a contextually typed V2 backend that
asserts host authority before its fake queue effect. Preserve the existing
pre/post-publication, mismatched overlay, weaker caller, and once-only
assertions; keep shared legacy fixtures unchanged.

Register the existing Codex steering-authority regression in its canonical
full-suite project so focused and normal CI runs both execute it.

Reproduced both failures from CI 33595225280 before editing. The same tests,
canonical suite, and V1/V2/native/Copilot siblings pass: 160 tests, 23 focused
check phases, and fresh scoped P0 autoreview. No production changes.

PR: https://github.com/openclaw/openclaw/pull/134003

* fix(talk): require fresh current-call control results

Clarify native voice instructions: shared historical statuses do not establish current-call ownership. Every new control request needs a fresh host result; current receipts and results are not requests to redelegate.

The actual call-creation payload regression fails before the repair and passes afterward. Preserve shared context, unclaimed native behavior, and host authority. Focused tests and checks plus independent review passed; real-provider adherence remains a separate live acceptance gate.

Refs #133844 and #134003.

* fix(talk): honor generated transcript context exclusions

Record native consult scaffolding with the existing hidden and context-excluded metadata while delivering the full current prompt once. Select startup context before discarding metadata, keep ordinary display visibility separate, and preserve canonical explicit reset retention in bounded reads.

Keep raw archives, genuine speech, call authority, and phone/meeting retention unchanged. Independent producer, reader, and bounded-reset regressions fail before the repair; final 553 tests and 30 selected checks pass. Fresh independent review is clean. Live provider adherence remains a separate gate.

Refs #133844 and #134003.

* test(talk): assert model-context preview selection

* fix(talk): keep shared history out of native call turns

For negotiated host-controlled native calls, carry shared-session history as
quoted historical background instead of replaying prior assistant speech as
the new call's own output_text. Preserve speaker roles and useful history
within the existing entry, item, and UTF-8 budgets, including encoding overhead.
Legacy native conversation seeds, GA, empty-history relay calls, persisted
transcripts, context eligibility, and call-bound authority remain unchanged.

Protect the broker negotiation matrix, raw/display history across reopen,
separate backing answers and spoken readbacks, reset retention, UTF-8 bounds,
and hostile delimiters. The broker regression fails before the repair; 235
owner/sibling tests, the 23-case typing-correction rerun, the 69-case test
relocation rerun, and final changed checks pass. Full local build passes.

This repairs context representation, not a claim that the audible two-call
status failure is resolved; same-provider live verification remains required.

Refs: https://github.com/openclaw/openclaw/pull/134003

* fix(talk): fence pending-question controls at dispatch

Carry the exact source and backing-run assertion through Gateway preparation
and hello, then revalidate synchronously before sending question.resolve.
Refused answers and image-triggered cancellations release only their own
reservation, leaving the independent question and backing run usable.

Use one core-owned default question transport and an explicit V2 custom
dispatcher for source-bound input. Preserve the shipped legacy callback type
and ordinary input behavior. Remove dead answer buffering and redundant
default adapters, and keep prompt handoffs correct when a successor claim is
refused or accepted. Already-consumed answers remain non-replayable.

Validated with 392 owner/caller tests, 23 SDK runtime tests, the separate
152-test Gateway call suite, changed-file gates, a full build, and fresh
scoped Codex autoreview. Preserve the earlier collection timeout and the
build rejected after an ancestor dependency changed; neither is counted as
passing proof. Current-candidate live behavior and CI remain pre-merge gates.

Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk)

* refactor(talk): keep question transport contracts acyclic

Move the unchanged legacy callback type into the existing dispatcher owner
and update internal type imports. Preserve the public Plugin SDK export and
signature without keeping an internal alias or adding a new module.

This removes the type-only cycle caught by Madge in the native Talk CI run.
The full architecture check, 116 focused tests, changed-file checks, full
build, and fresh scoped Codex review pass. Runtime behavior is unchanged.

Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk)

* test(copilot): use the public question transport seam

Keep the real question owner and active-run queue in the full-attempt test,
but inject its synthetic transport through the public V2 dispatcher contract.
The old SDK callGatewayTool mock was bypassed by the new core-owned default.
Refuse unexpected RPCs rather than contacting a real Gateway.

Preserve prompt and answer-selection assertions, verify that only progress
reaches provider steering, and abort/join owned work with listener cleanup.
The complete Copilot attempt and direct siblings pass 172 tests; real core
question-owner tests pass 34. Changed-file checks and fresh scoped Codex
review pass. No production behavior changes.

Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk)

* fix(questions): bind lost-response recovery to committed input

An answered shared waiter did not prove that a particular plain-text input
was consumed. A connection failure before dispatch plus another resolver's
identical answer incorrectly dropped that input. Record a fresh resolution
receipt at the synchronous question owner and compare that exact receipt
when recovering a failed resolve request.

Make receipt delivery opt-in per waiter so strict shipped native decoders,
question records/events, and public harness answers keep their existing
shapes. Preserve already-committed answers after source closure or lost ACKs.
No new configuration, dependency, persistent store, protocol version, or SDK
export. Shrink the assertion inventory for the removed redundant cast.

The real WebSocket regression fails on both pre-fix question owners. The
repair passes 371 focused owner/caller tests, changed checks, full build,
stable/current Swift wire proof, a 23-check real Gateway/Control UI probe,
and independent scoped Codex review. Live transport faults are controlled;
separate regressions drop the actual WebSocket acknowledgment.

Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk)
Refs: https://github.com/openclaw/openclaw/issues/133844 (Gateway-owned native control)

* fix(state): preserve published heartbeat readiness

Settle maintenance-worker startup from its atomic shared state rather than
whether the parent's ready notification arrived before the timeout. A ready
worker must not be overwritten as lost; callback entry still requires a fresh
worker acknowledgement and exact persisted ownership checks.

The real-worker/database regression withholds only the owner's notification.
It fails on the previous code after observing worker readiness and passes with
the repair. All 38 lease/maintenance tests, scoped checks, CI-profile build,
and fresh Codex review pass. Lease durations, renewal, schema, and authority
contracts remain unchanged.

The encountered CI startup failure lacks shared-state timing, so this does
not attribute that historical occurrence conclusively to the confirmed race.

Refs: https://github.com/openclaw/openclaw/issues/135717
Refs: https://github.com/openclaw/openclaw/pull/134003

* test(talk): align CLI and ACP fixtures with admitted ownership

Bind the original prepared caller-policy snapshot before exercising CLI
fallback exhaustion, matching real reply admission. Assert the CLI actually
ran while retaining all exhausted-result and failure-lifecycle checks.

Require the real ACP dispatcher to deliver one uncertainty notice and mark
it queued, while retaining no-replay, error-diagnostic and canonical-owner
assertions. The older fixture incorrectly expected that notice to stay silent.

Reproduced four failures before editing; all 151 owner/sibling tests,
selected changed checks and fresh scoped P0 Codex review pass. Production
code is unchanged. The separate obsolete service-relay test is owned by
in-flight PR #137220 and is not duplicated here.

Context: https://github.com/openclaw/openclaw/pull/134003

* test(gateway): settle rejected steering before awaiting ACK

The captured-injection fixture reported provisional rejection, then waited
for chat.send to ACK before failing its unresolved delivery promise. The
correct acceptance owner waits for that terminal result, making the old
fixture circular and leaking admission into the rest of the suite.

Observe the queue call, assert no early ACK or fallback, reject delivery,
then await the request. Retain the existing exactly-once fallback checks
and join owned promises/operation in finally. Keep all global drain
assertions and deadlines unchanged.

Proof: original ordered selection reproduced four failures after the first
120-second timeout; the same five cases now pass. The complete Gateway
fixture plus injection-owner siblings pass 315 tests, and selected changed
checks and fresh scoped Codex review pass. No production changes.

Context: https://github.com/openclaw/openclaw/pull/134003

* test(process): port deterministic construction deadline coverage

Port only the four related test/support changes from the landed canonical
repair. Replace the obsolete Anthropic SDK-coupled probe with a registered
process-backend command test, observe real supervisor/child readiness, then
advance the existing construction deadline. Preserve blocked secret-fd
writes, timeout result/exit code and PID cleanup. Synchronize the sibling
service lifecycle cases with the same existing budgets.

No runtime changes, new production seams or larger deadlines. Unrelated
docs and link-audit changes from the canonical commit are intentionally
excluded. All four staged blobs match that commit exactly.

Proof: 114 command/construction/relay/cancellation tests; complete selected
checks; fresh scoped P0 Codex review. The previous CLI/ACP and Gateway
fixture repairs remain preserved. Exact-head CI and final native Talk proof
are still required before landing.

Canonical source: https://github.com/openclaw/openclaw/commit/c3a495d198fe16e5a698132983ee1d7f7117d91a
Context: https://github.com/openclaw/openclaw/pull/134003

* test(process): reuse race-safe cleanup for package runners

Reuse killPidIfAlive at the four package-runner teardown sites and the process-wait sibling. A process exiting between the liveness probe and SIGKILL already satisfies cleanup; other signal errors still propagate. Preserve all readiness, exact exit, signal, and bounded death assertions.\n\nObserved integration failure: PR #134003 CI33752905282, job100640618422, kill ESRCH in final cleanup. Verification: 65 tests across resolver, process-wait and existing ESRCH/EPERM helper regressions; selected checks; fresh scoped P0 autoreview. Production unchanged.

* test(qa): keep Slack behavior checks in Vitest's module graph

Load the real Slack test API through the narrow test-only runtime boundary instead of recompiling it through Jiti. Keep delivery operations and assertions real, and retain the separate production facade contract tests.

Drive the existing observation-settling fixture with its unchanged 10ms test clock and restore timers after each case, removing a separately observed wall-clock flake without extending deadlines.

The original CI merge reproduced the fallback timeout at 130425ms. The repaired 82-file shard passes 1521 tests with one platform skip; the fallback case takes 7ms. The unrebased PR head also passes all 62 tests. Complete selected checks and fresh scoped P0 review pass. Production LOC delta is zero.

Context: https://github.com/openclaw/openclaw/pull/134003
CI: https://github.com/openclaw/openclaw/actions/runs/33776451796

* fix(gateway): join session recovery before runtime teardown

Keep delayed session imports, startup recovery, scheduling, and admitted
session-delivery drains alive until their existing work and settlement finish.
Expose both recovery owners through the early Gateway close join, and retain
drain completions per runtime so an old stop cannot affect its replacement.
No queue decisions, stored representations, schema, retries, timeouts, or
provider contracts change.

Four controlled regressions failed before the repair because shutdown returned
while work was held. The repaired owner/import suites pass 65 tests; the saved
87-file Gateway CI inventory passes 1616 tests on this PR tree. The original
main EnvironmentTeardownError was not reproduced locally: its exact revision
passed 1629 tests, including 13 additional unrelated skill-transfer cases.
Do not attribute that nondeterministic failure uniquely from its stack.

All 123 sibling restart/settlement tests and the complete eight-file changed
check plan pass. Extract the unchanged mock fixture rather than raising the
test-file line limit; preserve Vitest hoisting with a separate named export.
Fresh scoped Codex review found no actionable P0 findings. Production delta is
+19 lines for missing lifecycle completion ownership, reusing the existing
recovery stop boundary and running-entry map.

Landing context: https://github.com/openclaw/openclaw/pull/134003

* test(qa): bind observer clock to its settle window

The CI merge combined main's 500 ms observation window with the PR's
hardcoded 10 ms fake-clock advance. Git merged the edits cleanly, but the
fixture then waited forever for the remaining timer.

Pass one observationParams object to the observer and advance its declared
settleMs value. Preserve the declared window on both branches, all message
assertions, real Slack operations, timer cleanup, and the test deadline.
No production changes or base refresh are needed.

Exact CI merge 4bc5cefbb8fa45a0a5233c443282ba65b3b91ecf reproduced the same
120020 ms timeout in the original 82-file QA shard. The same repair passes
1522 tests with one platform skip; the settling case takes 2 ms. All 62 PR-head
cases and the complete changed checks pass. Fresh scoped Codex review reports
no actionable P0 findings.

Context: https://github.com/openclaw/openclaw/pull/134003

* refactor(talk): simplify control and question helpers

Port the behavior-neutral cleanup from 02ab4443e5 onto the verified integration. Reuse inherited caller ownership, canonical settled-entry lookup, synchronous prepared-handle publication, and shared deferred/result construction without changing authority or JSON order.

Retain all 234 tests in their eleven-suite sequence. Current changed checks and fresh isolated Codex P0 review pass. Net -21 production and -24 test/support lines. The inherited iOS Watch CI failure remains under investigation; this cleanup is not claimed to repair it.

---------

Co-authored-by: Eden <aa9736195201@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-03 21:51:49 -07:00
Peter Steinberger 055a2dc6ce feat: continue dashboard sessions from CLI URLs (#120893)
* feat(cli): ingest session targets

* refactor(ui): remove gateway scope shim

* docs(cli): document session targets

* fix(cli): classify session target failures

* fix(cli): keep session target result private

* fix(cli): simplify timeout option warning

* build: declare session URL contract dependency

* fix(cli): parse bare session URL options symmetrically

* fix(cli): preserve command-owned URL arguments

* build: keep session URL contract build-only

* fix: address session URL review findings

* test: preserve session key mock exports

* fix: keep session URL helpers internal

* fix(tui): preserve URL agent for global sessions

* fix(tui): keep URL agent input internal

* fix(gateway): reconcile websocket protocol owner

* fix(attach): preserve global session agent ownership

* fix(attach): enforce global owner at grant boundary
2026-08-09 16:44:25 -07:00
Peter Steinberger f7d7148cf0 docs: rewrite published docs grounded in current source (#100142)
Source-grounded rewrite of 529 published docs pages with per-unit information-loss verification: 1,713 factual corrections cited to src/**, generated surfaces regenerated, frontmatter titles preserved for i18n, release notes pages untouched. All docs gates green.

Closes #100141
2026-07-05 00:32:47 -04:00
anagnorisis2peripeteiaandAyaan Zaidi 6df7db9f9e feat(cli): add attach launcher (#96454)
* feat(cli): openclaw attach — launch Claude Code bound to a gateway session with scoped MCP tools
* fix(cli): use token-only MCP config for attach

---------

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-07-01 15:52:39 -07:00