15 Commits
Author SHA1 Message Date
Peter Steinberger ede3447b10 chore(deps): refresh dependencies with seven-day cutoff (#158298)
* chore(deps): refresh dependencies with seven-day cutoff

* fix(deps): complete dependency integration checks

* chore: tighten Discord assertion allowances

* test(acpx): align Claude adapter version references

* chore(deps): align remaining dependency references

* fix(deps): preserve schema diagnostics with escaped pointers

* fix(deps): decode pointer paths across schema diagnostics

* build(deps): carry refresh through main changes

* test(bench): isolate healthy probe from scheduler delay
2026-09-26 20:42:53 -07:00
Peter Steinberger 2abecd703d chore(deps): refresh dependencies with a seven-day cutoff (#157238)
* chore(deps): refresh dependencies with a seven-day cutoff

* fix(deps): preserve Teams and jsdom integration contracts

Use the Teams SDK public token and processing APIs while keeping SSO sender
checks ahead of native token operations. Remove obsolete ambient declarations
and route workarounds, and cover the SDK routing with real processing tests.

Adapt the test environment to jsdom private-field bindings, preserve file bytes
and registry cleanup, and preload it through native Node and Bun workers.

* fix(test): preserve jsdom window and fixture contracts

* fix(ci): keep typecheck cache reuse within matching inputs
2026-09-25 02:38:45 +00:00
Peter Steinberger f78f51359d chore(deps): refresh dependencies with seven-day cutoff (#149908)
* chore(deps): refresh dependencies with seven-day cutoff

Advance eligible application, native, release, and development dependencies
published by 2026-09-09T06:51:52Z. Audit new registry resolutions and native
artifact hashes, preserving existing security pins and compatibility holds.

Adapt MCP Apps 2 tool discovery and host context, retain Clack cancellation
handling, and align the updater fixture with its runtime assembly owner.
Synchronize native artifact checks, operational docs, and tooling pins.

Validation includes frozen installation, full build, CLI rebuild, typechecks,
lint, 96 npm package locks, dependency audits, focused runtime and native
proofs, and independent review. Exact-head hosted CI is required before land.

* fix(deps): preserve scroll ownership and synchronize toolchain contracts

* fix(cli): preserve generic wizard option values after Clack update

* docs(lobster): clarify credentials for embedded remote calls

* test(cli): use Clack cancellation sentinel in prompt fixtures

* fix(ios): avoid opening audio input during relay cancellation

* test: reuse dependency update fixtures within line limits

* fix(crabbox): retain the previous trusted pnpm pin

* test(gateway): synchronize task access churn with page selection

* test(macos): isolate the challenge timeout transport fixture

* fix(macos): preserve hidden windows through deminiaturization

* fix(macos): exclude hidden dashboards from window selection
2026-09-16 09:06:40 -07:00
Peter Steinberger d13f07b1c2 chore(deps): advance cooled dependencies and major upgrades (#146258)
* chore(deps): advance cooled dependencies and major upgrades

* test(logging): migrate failed-sink regression to tslog 5

* test: retain dependency upgrade coverage within lint limits

* fix(deps): preserve compiler launches, Matrix sync and chat metadata

Keep copied script harnesses independent of declaration modules and preserve
Windows executable prefixes after admission. Audit the Matrix sync guard for
42.3, align CI toolchain/cache pins, and refresh session facts after accepted
model-catalog invalidation without relying on picker timing.

* fix(ui): preserve scoped session reconciliation after catalog refresh
2026-09-12 13:28:12 -07:00
Peter Steinberger 6f1185305d chore(deps): advance cooled TypeBox, AWS and Copilot SDKs (#145381)
* chore(deps): advance cooled TypeBox, AWS and Copilot SDKs

Update six direct package targets after the frozen 2026-09-04T22:10:05Z seven-day cutoff. All 15 new resolved artifacts match registry integrity and publication-age requirements.

Keep TypeBox pins and plugin examples aligned, and describe Copilot SDK native runtime packaging accurately. Regenerate the Workboard asset references with the updated graph.

Validation: independent P0-P2 review clean; live S3-compatible signed upload/readback/delete passed. Remaining full checks and Copilot live proof run in an isolated Testbox after local dependency-store loss.

* test(copilot): handle the SDK session detach handshake

Keep the held cleanup boundary and all cancellation and host-lifetime assertions while answering session.detach with success. The previous fake session.destroy handler left the real SDK test waiting until its deadline.

* fix(ui): clean up environment picker validation gates
2026-09-11 20:15:55 -07:00
Peter Steinberger cd6fe8252e chore(deps): refresh seven-day-cooled npm dependencies (#145124)
* chore(deps): refresh seven-day-cooled npm dependencies

Update 64 direct dependency targets and six pinned transitive targets using
registry publications on or before 2026-09-04T16:49:00Z. Verify publication
timestamps and registry integrity for all 164 newly resolved versions.

Deduplicate compatible resolutions so CodeMirror shares one state instance.
Retire expired cooldown exclusions and Mailparser's redundant security
scopes, retaining Mailauth's fixes at its new parent version. Synchronize
Claude ACP fallback assertions, plugin examples, and generated Workboard
asset metadata. Preserve patched packages and intentional migration holds.

Build, repository-wide formatting, 627 SDK/schema tests, 3613 plugin tests,
142 native/terminal/ACP tests, and independent P0-P2 review passed. Final
changed checks, browser editor proof, and exact-head CI are tracked in the PR.

Closes #145096

* test(tui): complete updated overlay handle fixtures

* fix(diffs): retain read-only types with updated renderer

* fix(validation): retain compact TypeBox rejection diagnostics

Normalize complete boolean child groups immediately before their matching
additional-property aggregate at the shared JSON-schema owner. Preserve
unrelated failures, literal-path collisions, typed/nested property errors,
truncated lists, and original error object identity. Both normalized-error
producers use the helper; validation decisions remain unchanged.

Use one oversized property in the Codex truncation regression so the test
continues exercising its original bound under TypeBox's new error layout.
Keep all rejection and non-execution assertions. Remove one unnecessary
validation-error cast and shrink its assertion ratchet accordingly.

The original Gateway assertions, 342 owner and sibling tests, native type
checks, targeted lint, and independent P0-P2 review pass. A real collision
regression failed the initial implementation and passes with ordered groups.
2026-09-11 14:29:57 -07:00
Peter Steinberger f52713cd64 chore(deps): refresh seven-day eligible packages (#135177)
* chore(deps): refresh cooled packages and trusted Codex

Refresh 17 direct targets and owner-constrained transitive families using the
fixed 2026-08-25T02:09:07Z cutoff. Preserve the seven-day policy, trusted Codex
family and exact grammY exceptions. Pair native digests, runtime constants,
current-version documentation, UI boot manifest and Vercel lock fingerprint.
Apply only the approved TypeBox/Codex override bumps and remove the obsolete
Mailparser HTML-converter override now owned directly by Mailparser 3.9.16.

Consumer validation exposed an empty-reply outcome bug: final payload filtering
could report failure without notifying dispatch, hiding the diagnostic from
Gateway clients. Record failed outcomes at both existing payload failure
producers. Preserve deliberate silence, continuations and committed delivery.
Regression coverage checks directive-only output, real Gateway/TUI errors and
successful subsequent turns. Align the reset assertion with its existing
clear-context boundary; no reset behavior or schema changes.

Clarify release-only changelog edits in contributor guidance. No changelog,
OpenClaw release version, new configuration, or protocol version changes.

Proof: full builds, 993 dependency-owner tests, 111 reply/Gateway tests, 28
original-order PTY cases, full static/package checks and 29 repair checks;
exact-tag Codex protocol gate; real native SDK/Codex/CUA probes and inspected
synthetic Control UI before/after screenshots/video. The loaded-host PTY retry,
three preexisting exploratory library defects and partial advisory coverage
remain documented, not presented as a clean upstream security sweep.

* fix(codex): align catalog and fixture runtime versions

* test: expose Windows gateway cleanup failures

Preserve original cron assertion errors and report bounded taskkill/process/pipe diagnostics without changing shutdown policy or deadlines. Correct the Codex model/list cache-side-effect wording. The original Windows failure still requires diagnosis from native CI evidence.

* test: align native validation and late-filter proof

Keep Windows projects serial within each machine while retaining both matrix jobs and all assertions. Use valid Responses events and a late-filtered heartbeat marker to protect the terminal-failure callback after upstream streaming changes. Assert the exact error and successful next turn, not erasure of earlier PTY stream history.

* test(ci): align Windows guard with serial projects

* chore(deps): regenerate boot groups after integration

* test: remove empty package manifest suites

Delete eight plugin-only registrations that declare no assertions. The existing manifest helper registers only dependency-ownership and host-floor checks, so these rows fail Vitest collection while protecting no contract. Preserve all 501 manifest/dependency assertions; the original scoped command now passes. Independent Codex review found no actionable P0 issues.

* fix(talk): retain playback ownership until the player drains

Integrate the focused playback-owner repair from
59c2767bee in #136049 to unblock the native
CI failure in dependency refresh #135177. Remove estimated-duration
completion; only the generation-checked PCM player result completes normal
output. Explicit cancellation, clear, replacement and teardown retain their
existing ownership.

Keep the turn, playback marks and microphone echo suppression while queued
audio remains pending. The deterministic regression uses the existing
microphone timestamp seam; the original stale-player failure case is
unchanged. Document actual-drain behavior for Apple clients.

Also retain the canonical boot-generator refresh after the required conflict
rebase: main's gateway-suspend schema and download helper join the captured
shared boot group. No manual budget change or new dependency selection.

Local focused Swift proof passed 35 tests in four suites with synthetic
transport/capture/player boundaries. Full candidate isolated P0 review is
scoped-clean. Hosted toolchain parity and remaining landing gates remain
required; no merge-recovery or publication bypass.
2026-09-02 18:43:03 -07:00
Peter Steinberger 1f71c763ea chore(deps): refresh eligible seven-day npm dependencies (#133772)
* chore(deps): refresh eligible seven-day npm dependencies

* docs(plugins): align embedded TypeBox dependency pins

* test(deps): align evidence and Escape ownership

* fix(ci): repair native PID imports and cancellation assertions

* test(ui): make effort Escape ownership explicit

* fix(agents): keep error presentation on prepared policy

* fix(agents): preserve loaded provider policy in error presentation

* fix(agents): carry prepared provider owners into lifecycle errors

Preserve endpoint-owned recovery guidance for custom provider routes in terminal events and callbacks. Reuse the prepared model handle and full-signal classifier, with a real Agent/AgentSession boundary regression.

* fix(agents): reconcile explicit diagnostic ownership and structured errors

Keep presentation on explicit prepared owners, preserve full assistant error facts ahead of generic request wrappers, and retain raw-schema diagnostics. Carry prepared owners into terminal observations and prove source/compiled scope boundaries. Complete the shared attempt fixture with the real model-handle getter.

* fix(agents): carry full classified facts into safe failure copy

Share explicit-owner assistant classification between direct formatting and the user-facing wrapper. Preserve structured codes, types and body evidence in safe provider/model/status copy, including message-less failures, while retaining raw-schema diagnostics and ownerless policy boundaries.

* fix(ui): keep Home work context lazy and current

Let the existing deferred assistant panel prepare page work context once,
using the shell's validated route facts. Keep explicit agent ownership
through global/main aliases and refresh the quoted reference when session,
agent or Gateway snapshots change.

Reuse the frozen refinement from PR #134059:
6e2a8f9550e6e6da957b0352fa674024f198118e.
Add source-bound roster-refresh/send proof, extend the existing owner
fixture for snapshot updates and cleanup, and regenerate the boot manifest
for the pinned dependency graph. Startup gzip is 347243 B under the
unchanged 347353 B gate. The UI repair removes two production lines net.

* test(agents): align generation fixtures with prepared metadata

Use the captured main generation-scope contract in lifecycle and
source/compiled provider-owner fixtures. Remove its retired config input
while preserving provider selection and empty-generation fencing.

Integrate captured main 10564e2 with the Home context refinement from
PR #134059 and the assistant dock cleanup from PR #134435. Preserve the
existing contributor credit and canonical catalog owner already on main.

The integrated candidate passes the normal full build, scoped checks,
679 original-order model cases, 400 backend owner cases, both catalog
E2Es, 290 UI cases and 18 browser cases. Final grouped startup gzip is
347299 B under the unchanged 347353 B enforcement limit.

* refactor(ui): keep submission projection in lazy chat owner

Keep the app store responsible for bounded retained bytes and client lifetime.
Move receipt adaptation and display retirement into the existing history
projection owner, shared by both lazy chat consumers. Preserve missing-store
behavior and the retained-prompt, attachment and reconnect contracts.

Continue the retained-submission owner from PR #134059
(0f3e17e56b).

Validation: 808 owner tests, 21 Chromium cases, grouped-bundle Home and
retired-prompt proof, changed checks and fresh full-candidate autoreview.
Startup gzip: 347588 -> 347320 bytes; unchanged limit 347353.
2026-08-31 16:48:58 -07:00
Peter Steinberger 395e5db41b chore(deps): refresh dependencies after seven-day cooldown (#130296)
* chore(deps): refresh cooled npm and plugin dependencies

* chore(deps): refresh cooled build and workflow tooling

* chore(deps): retain formatter compatibility

* chore(deps): retain lint compatibility
2026-08-26 16:13:18 -07:00
Peter Steinberger 1605dbd3ef chore(deps): refresh dependencies after seven-day cooldown (#129941)
* chore(deps): refresh dependencies after cooldown

* chore(deps): refresh sherpa-onnx runtime to v1.13.6

* test(ios): refresh Fastlane pin expectations
2026-08-26 01:37:37 -07:00
Peter Steinberger 53bdac249d docs: restore source-backed contract details (#100182) 2026-07-05 01:26:25 -04:00
Peter Steinberger f7d7148cf0 docs: rewrite published docs grounded in current source (#100142)
Source-grounded rewrite of 529 published docs pages with per-unit information-loss verification: 1,713 factual corrections cited to src/**, generated surfaces regenerated, frontmatter titles preserved for i18n, release notes pages untouched. All docs gates green.

Closes #100141
2026-07-05 00:32:47 -04:00
Peter Steinberger fc4f8dddaa docs: sync plugin package snippets (#99973) 2026-07-04 10:00:04 -04:00
Shakker 13987b726a docs: show explicit startup activation in plugin examples 2026-04-28 03:13:20 +01:00
George Zhang e133924047 [codex] harden clawhub plugin publishing and install (#56870)
* fix: harden clawhub plugin publishing and install

* fix(process): preserve windows shim exit success
2026-03-29 11:59:19 -07:00