* feat(talk): support native realtime for thin audio clients Preserve native model and authentication selection while reusing the Gateway sideband for transcripts, readiness, spoken controls, and scoped agent consultations. Keep legacy browser ownership and the stable bridge binding intact; fence post-flush admission without cancelling accepted native work on detach. Related: native realtime control for thin audio clients — https://github.com/openclaw/openclaw/issues/133844 * fix(talk): preserve intentional consult cancellation Preserve canonical cancellation and timeout outcomes before projecting consult results into speech. Share native browser and relay cancellation handling and retain the GA canceled result, without changing accepted-work transport detach semantics. Regression proof reproduces canceled empty, partial, and rejected backend results at the real Gateway owner boundary. Validation: 498 focused tests, changed checks, SDK surface, import cycles, and full build. Live native media proof remains pending for #134003; related feature request #133844. * test(talk): load native provider through SDK public surface * fix(talk): keep native controls out of agent delegation Classify intrinsic status and cancellation before native task replacement, preserving active and pending work. Keep transcript-owned idle controls distinct from tool-capable late-ASR handling, and preserve the shipped transcript callback contract. Refs #133844 (native Gateway control for thin audio clients). * fix(talk): require negotiated control binding Make explicit Gateway control require its host command binding while preserving unclaimed requests and the stable GA full-bridge adapter. Cover valid and rejected SDK requests at compile time and retain the JavaScript ingress guard. Refs: #134003, #133844 * test(talk): register intentional invalid-host coverage Register the single approved negative-test inventory entry. Keep strict negotiated-control types, runtime rejection before session reservation, and the existing zero-unsafe-cast checks unchanged. Refs: #134003 * fix(talk): isolate controls by logical voice call Bind provider-attached native/GA and relay run selection to the live logical voice binding, including final-use checks. Preserve session-wide talk.client.steer and accepted work across same-call transport replacement. The four two-call status/cancel regressions fail before this repair; 186 owner and sibling tests plus core typechecks pass afterward. Fresh scoped Codex autoreview found no actionable P0 findings. Live two-call proof and final build/CI remain required before landing. Follow-up for #134003 and #133844. * test(talk): avoid shadowing the native transcript event * fix(talk): make native acknowledgments host-owned Disable provider delegation fillers for host-classified native calls and send one neutral receipt only when a task launches. Status and cancellation wait for the authoritative host result; legacy browser and tool-call bridge defaults remain unchanged. Refs: https://github.com/openclaw/openclaw/pull/134003 https://github.com/openclaw/openclaw/issues/133844 * fix(talk): bind native controls to live host authority Admit native voice actions from delegation events instead of replaying final transcripts. Keep status, steering, cancellation, and control replies bound to the originating call and captured work, with visible bounded queue refusal and recovery. Prepare direct and maintenance run authority at the host execution owner, project current caller policy, and revalidate exact registration and lifetime at the final queue or question effect. Preserve rich chat-backed Talk authority and the shipped SDK dependency callback contract. Keep unrelated Discord attribution changes out of this candidate; its existing missing-authority steering refusal remains unchanged. Refs #134003, #133844, #126733. * fix(talk): preserve queued reply and policy ownership Preserve session-scoped Talk controls for an exact queued reply owner without relaxing voice-session backend fencing. Derive tool capability identity from the executing session while retaining independent sandbox policy classification. Covers the two exact-head CI regressions and publication-order boundaries for PR #134003. * fix(talk): fence controls at final message injection Keep accepted backing work alive after a voice call closes, but reject its retained controls after call closure, claim reassignment, or backend replacement. Carry a host-owned per-injection assertion through versioned core and Codex queue, question, and physical-dispatch boundaries, including overload retries. Preserve exact voice claim identity across genuine reassignment while allowing identical registration replay. Retain the shipped V1 SDK contract. Copilot remains explicitly unavailable for source-bound steering until its SDK exposes a final-dispatch guard; ordinary unscoped injection remains supported. No unchecked fallback or new SDK export budget is introduced. Native realtime thin-client work: https://github.com/openclaw/openclaw/pull/134003 Validation: real final-insertion RED/GREEN, 442 focused and sibling tests, scoped compiler/lint/format, unchanged SDK budgets, full build, and independent P0 autoreview. Aggregate changed checks reached the separately landed SDK retention metadata repair, which is being brought forward before publication. * fix(talk): preserve rejected SDP responses before connection close Adopt the OpenAI offer portion of the shared HTTP rejection repair from32b4abb341without restoring the old inline OAuth resolver or changing native Gateway-control ownership. Use the existing response-before-close owner for body-limit and timeout failures. Keep the SDP size and time bounds, security headers, single-use reservations, and all post-await native authority checks. Reuse upstream raw-socket tests and private-local test support; public SDK exports do not grow. Native thin-client work: https://github.com/openclaw/openclaw/pull/134003 Upstream repair: https://github.com/openclaw/openclaw/commit/32b4abb3413cb53708d83d6932650dda7d4db91f Validation: real TCP RED/GREEN, 158 focused/sibling tests, 48 HTTP tests on Node 24, full build, required five-file changed gates, and independent P0 review. The adjacent auth-resolver move still requires Git ancestry integration before publication; no claim of mergeability or final-source live proof. Co-authored-by: Eden <aa9736195201@gmail.com> Co-authored-by: Ayaan Zaidi <hi@obviy.us> * fix(talk): remove duplicate rejection after main integration * test(talk): align guarded authority fixtures and suite ownership Give the GA reply-authority fixture a contextually typed V2 backend that asserts host authority before its fake queue effect. Preserve the existing pre/post-publication, mismatched overlay, weaker caller, and once-only assertions; keep shared legacy fixtures unchanged. Register the existing Codex steering-authority regression in its canonical full-suite project so focused and normal CI runs both execute it. Reproduced both failures from CI 33595225280 before editing. The same tests, canonical suite, and V1/V2/native/Copilot siblings pass: 160 tests, 23 focused check phases, and fresh scoped P0 autoreview. No production changes. PR: https://github.com/openclaw/openclaw/pull/134003 * fix(talk): require fresh current-call control results Clarify native voice instructions: shared historical statuses do not establish current-call ownership. Every new control request needs a fresh host result; current receipts and results are not requests to redelegate. The actual call-creation payload regression fails before the repair and passes afterward. Preserve shared context, unclaimed native behavior, and host authority. Focused tests and checks plus independent review passed; real-provider adherence remains a separate live acceptance gate. Refs #133844 and #134003. * fix(talk): honor generated transcript context exclusions Record native consult scaffolding with the existing hidden and context-excluded metadata while delivering the full current prompt once. Select startup context before discarding metadata, keep ordinary display visibility separate, and preserve canonical explicit reset retention in bounded reads. Keep raw archives, genuine speech, call authority, and phone/meeting retention unchanged. Independent producer, reader, and bounded-reset regressions fail before the repair; final 553 tests and 30 selected checks pass. Fresh independent review is clean. Live provider adherence remains a separate gate. Refs #133844 and #134003. * test(talk): assert model-context preview selection * fix(talk): keep shared history out of native call turns For negotiated host-controlled native calls, carry shared-session history as quoted historical background instead of replaying prior assistant speech as the new call's own output_text. Preserve speaker roles and useful history within the existing entry, item, and UTF-8 budgets, including encoding overhead. Legacy native conversation seeds, GA, empty-history relay calls, persisted transcripts, context eligibility, and call-bound authority remain unchanged. Protect the broker negotiation matrix, raw/display history across reopen, separate backing answers and spoken readbacks, reset retention, UTF-8 bounds, and hostile delimiters. The broker regression fails before the repair; 235 owner/sibling tests, the 23-case typing-correction rerun, the 69-case test relocation rerun, and final changed checks pass. Full local build passes. This repairs context representation, not a claim that the audible two-call status failure is resolved; same-provider live verification remains required. Refs: https://github.com/openclaw/openclaw/pull/134003 * fix(talk): fence pending-question controls at dispatch Carry the exact source and backing-run assertion through Gateway preparation and hello, then revalidate synchronously before sending question.resolve. Refused answers and image-triggered cancellations release only their own reservation, leaving the independent question and backing run usable. Use one core-owned default question transport and an explicit V2 custom dispatcher for source-bound input. Preserve the shipped legacy callback type and ordinary input behavior. Remove dead answer buffering and redundant default adapters, and keep prompt handoffs correct when a successor claim is refused or accepted. Already-consumed answers remain non-replayable. Validated with 392 owner/caller tests, 23 SDK runtime tests, the separate 152-test Gateway call suite, changed-file gates, a full build, and fresh scoped Codex autoreview. Preserve the earlier collection timeout and the build rejected after an ancestor dependency changed; neither is counted as passing proof. Current-candidate live behavior and CI remain pre-merge gates. Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk) * refactor(talk): keep question transport contracts acyclic Move the unchanged legacy callback type into the existing dispatcher owner and update internal type imports. Preserve the public Plugin SDK export and signature without keeping an internal alias or adding a new module. This removes the type-only cycle caught by Madge in the native Talk CI run. The full architecture check, 116 focused tests, changed-file checks, full build, and fresh scoped Codex review pass. Runtime behavior is unchanged. Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk) * test(copilot): use the public question transport seam Keep the real question owner and active-run queue in the full-attempt test, but inject its synthetic transport through the public V2 dispatcher contract. The old SDK callGatewayTool mock was bypassed by the new core-owned default. Refuse unexpected RPCs rather than contacting a real Gateway. Preserve prompt and answer-selection assertions, verify that only progress reaches provider steering, and abort/join owned work with listener cleanup. The complete Copilot attempt and direct siblings pass 172 tests; real core question-owner tests pass 34. Changed-file checks and fresh scoped Codex review pass. No production behavior changes. Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk) * fix(questions): bind lost-response recovery to committed input An answered shared waiter did not prove that a particular plain-text input was consumed. A connection failure before dispatch plus another resolver's identical answer incorrectly dropped that input. Record a fresh resolution receipt at the synchronous question owner and compare that exact receipt when recovering a failed resolve request. Make receipt delivery opt-in per waiter so strict shipped native decoders, question records/events, and public harness answers keep their existing shapes. Preserve already-committed answers after source closure or lost ACKs. No new configuration, dependency, persistent store, protocol version, or SDK export. Shrink the assertion inventory for the removed redundant cast. The real WebSocket regression fails on both pre-fix question owners. The repair passes 371 focused owner/caller tests, changed checks, full build, stable/current Swift wire proof, a 23-check real Gateway/Control UI probe, and independent scoped Codex review. Live transport faults are controlled; separate regressions drop the actual WebSocket acknowledgment. Refs: https://github.com/openclaw/openclaw/pull/134003 (native thin-client Talk) Refs: https://github.com/openclaw/openclaw/issues/133844 (Gateway-owned native control) * fix(state): preserve published heartbeat readiness Settle maintenance-worker startup from its atomic shared state rather than whether the parent's ready notification arrived before the timeout. A ready worker must not be overwritten as lost; callback entry still requires a fresh worker acknowledgement and exact persisted ownership checks. The real-worker/database regression withholds only the owner's notification. It fails on the previous code after observing worker readiness and passes with the repair. All 38 lease/maintenance tests, scoped checks, CI-profile build, and fresh Codex review pass. Lease durations, renewal, schema, and authority contracts remain unchanged. The encountered CI startup failure lacks shared-state timing, so this does not attribute that historical occurrence conclusively to the confirmed race. Refs: https://github.com/openclaw/openclaw/issues/135717 Refs: https://github.com/openclaw/openclaw/pull/134003 * test(talk): align CLI and ACP fixtures with admitted ownership Bind the original prepared caller-policy snapshot before exercising CLI fallback exhaustion, matching real reply admission. Assert the CLI actually ran while retaining all exhausted-result and failure-lifecycle checks. Require the real ACP dispatcher to deliver one uncertainty notice and mark it queued, while retaining no-replay, error-diagnostic and canonical-owner assertions. The older fixture incorrectly expected that notice to stay silent. Reproduced four failures before editing; all 151 owner/sibling tests, selected changed checks and fresh scoped P0 Codex review pass. Production code is unchanged. The separate obsolete service-relay test is owned by in-flight PR #137220 and is not duplicated here. Context: https://github.com/openclaw/openclaw/pull/134003 * test(gateway): settle rejected steering before awaiting ACK The captured-injection fixture reported provisional rejection, then waited for chat.send to ACK before failing its unresolved delivery promise. The correct acceptance owner waits for that terminal result, making the old fixture circular and leaking admission into the rest of the suite. Observe the queue call, assert no early ACK or fallback, reject delivery, then await the request. Retain the existing exactly-once fallback checks and join owned promises/operation in finally. Keep all global drain assertions and deadlines unchanged. Proof: original ordered selection reproduced four failures after the first 120-second timeout; the same five cases now pass. The complete Gateway fixture plus injection-owner siblings pass 315 tests, and selected changed checks and fresh scoped Codex review pass. No production changes. Context: https://github.com/openclaw/openclaw/pull/134003 * test(process): port deterministic construction deadline coverage Port only the four related test/support changes from the landed canonical repair. Replace the obsolete Anthropic SDK-coupled probe with a registered process-backend command test, observe real supervisor/child readiness, then advance the existing construction deadline. Preserve blocked secret-fd writes, timeout result/exit code and PID cleanup. Synchronize the sibling service lifecycle cases with the same existing budgets. No runtime changes, new production seams or larger deadlines. Unrelated docs and link-audit changes from the canonical commit are intentionally excluded. All four staged blobs match that commit exactly. Proof: 114 command/construction/relay/cancellation tests; complete selected checks; fresh scoped P0 Codex review. The previous CLI/ACP and Gateway fixture repairs remain preserved. Exact-head CI and final native Talk proof are still required before landing. Canonical source: https://github.com/openclaw/openclaw/commit/c3a495d198fe16e5a698132983ee1d7f7117d91a Context: https://github.com/openclaw/openclaw/pull/134003 * test(process): reuse race-safe cleanup for package runners Reuse killPidIfAlive at the four package-runner teardown sites and the process-wait sibling. A process exiting between the liveness probe and SIGKILL already satisfies cleanup; other signal errors still propagate. Preserve all readiness, exact exit, signal, and bounded death assertions.\n\nObserved integration failure: PR #134003 CI33752905282, job100640618422, kill ESRCH in final cleanup. Verification: 65 tests across resolver, process-wait and existing ESRCH/EPERM helper regressions; selected checks; fresh scoped P0 autoreview. Production unchanged. * test(qa): keep Slack behavior checks in Vitest's module graph Load the real Slack test API through the narrow test-only runtime boundary instead of recompiling it through Jiti. Keep delivery operations and assertions real, and retain the separate production facade contract tests. Drive the existing observation-settling fixture with its unchanged 10ms test clock and restore timers after each case, removing a separately observed wall-clock flake without extending deadlines. The original CI merge reproduced the fallback timeout at 130425ms. The repaired 82-file shard passes 1521 tests with one platform skip; the fallback case takes 7ms. The unrebased PR head also passes all 62 tests. Complete selected checks and fresh scoped P0 review pass. Production LOC delta is zero. Context: https://github.com/openclaw/openclaw/pull/134003 CI: https://github.com/openclaw/openclaw/actions/runs/33776451796 * fix(gateway): join session recovery before runtime teardown Keep delayed session imports, startup recovery, scheduling, and admitted session-delivery drains alive until their existing work and settlement finish. Expose both recovery owners through the early Gateway close join, and retain drain completions per runtime so an old stop cannot affect its replacement. No queue decisions, stored representations, schema, retries, timeouts, or provider contracts change. Four controlled regressions failed before the repair because shutdown returned while work was held. The repaired owner/import suites pass 65 tests; the saved 87-file Gateway CI inventory passes 1616 tests on this PR tree. The original main EnvironmentTeardownError was not reproduced locally: its exact revision passed 1629 tests, including 13 additional unrelated skill-transfer cases. Do not attribute that nondeterministic failure uniquely from its stack. All 123 sibling restart/settlement tests and the complete eight-file changed check plan pass. Extract the unchanged mock fixture rather than raising the test-file line limit; preserve Vitest hoisting with a separate named export. Fresh scoped Codex review found no actionable P0 findings. Production delta is +19 lines for missing lifecycle completion ownership, reusing the existing recovery stop boundary and running-entry map. Landing context: https://github.com/openclaw/openclaw/pull/134003 * test(qa): bind observer clock to its settle window The CI merge combined main's 500 ms observation window with the PR's hardcoded 10 ms fake-clock advance. Git merged the edits cleanly, but the fixture then waited forever for the remaining timer. Pass one observationParams object to the observer and advance its declared settleMs value. Preserve the declared window on both branches, all message assertions, real Slack operations, timer cleanup, and the test deadline. No production changes or base refresh are needed. Exact CI merge 4bc5cefbb8fa45a0a5233c443282ba65b3b91ecf reproduced the same 120020 ms timeout in the original 82-file QA shard. The same repair passes 1522 tests with one platform skip; the settling case takes 2 ms. All 62 PR-head cases and the complete changed checks pass. Fresh scoped Codex review reports no actionable P0 findings. Context: https://github.com/openclaw/openclaw/pull/134003 * refactor(talk): simplify control and question helpers Port the behavior-neutral cleanup from02ab4443e5onto the verified integration. Reuse inherited caller ownership, canonical settled-entry lookup, synchronous prepared-handle publication, and shared deferred/result construction without changing authority or JSON order. Retain all 234 tests in their eleven-suite sequence. Current changed checks and fresh isolated Codex P0 review pass. Net -21 production and -24 test/support lines. The inherited iOS Watch CI failure remains under investigation; this cleanup is not claimed to repair it. --------- Co-authored-by: Eden <aa9736195201@gmail.com> Co-authored-by: Ayaan Zaidi <hi@obviy.us>
3.1 KiB
summary, read_when, title
| summary | read_when | title | ||
|---|---|---|---|---|
| CLI reference for `openclaw attach` (launch Claude Code with a scoped Gateway MCP grant) |
|
Attach CLI |
openclaw attach launches Claude Code with a strict temporary MCP config bound to one Gateway session.
openclaw attach [target]
target accepts a Control UI session URL, a compact host/agent/ref, a bare
short reference, or a literal agent:... session key. A URL or host target
authoritatively selects that Gateway; a bare reference uses the configured or
default Gateway.
openclaw attach
openclaw attach https://gateway.example/dashboard/main/movies-a1166b81
openclaw attach movies-a1166b81
openclaw attach --session agent:main:telegram:123 --ttl 600000
openclaw attach --print-config
Options:
--session <key>binds the grant to a Gateway session. Defaults to the main session.--url <url>selects a Gateway for a bare reference or--sessionkey. Do not combine it with a URL target.--token <token>and--password <password>provide explicit Gateway auth.--tls-fingerprint <sha256>pins the Gateway TLS certificate.--ttl <ms>requests a positive grant TTL in milliseconds. The Gateway applies its own ceiling.--bin <path>selects the Claude Code binary. Default:claude.--print-configwrites the temporary.mcp.json, prints the launch command and env, and leaves the grant live until TTL expiry (it does not spawn Claude Code or revoke the grant).
Pass either a positional target or --session, not both. Short references are
resolved before the scoped attach grant is minted; a missing session is never
created implicitly.
A URL or host target never reuses configured credentials or
OPENCLAW_GATEWAY_TOKEN / OPENCLAW_GATEWAY_PASSWORD. It uses the stored
device token for that exact Gateway origin, or explicit --token/--password
credentials. On first contact, pass one of those credentials once, approve the
pairing request in that Gateway's Control UI, and retry; see
Devices. Session URLs must stay credential-free: userinfo and
sensitive query or fragment parameters such as token and password are
rejected.
Target resolution uses the same session target error matrix
as openclaw tui.
The bearer token is passed through environment variables, not argv. OpenClaw launches Claude Code with --strict-mcp-config --mcp-config <path> so ambient Claude MCP servers do not join the attached session. Normal launches (without --print-config) revoke the grant when the Claude Code process exits.
If an attached tool asks a structured question, answer it through the question controls in the Control UI or native app. An attach grant scopes tools to a session but does not identify an active OpenClaw run or its original caller permissions, so ordinary channel text cannot claim that question. See Ask user.
See also: Control UI URLs, Devices, Gateway CLI, MCP CLI, and ACP CLI.