Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
581 commits
Select commit Hold shift + click to select a range
535b792
fix: delete subagent runs after announce give-up
Takhoffman Mar 24, 2026
013385e
refactor: polish trigger and manifest seams
steipete Mar 24, 2026
9082795
refactor(ui): extract chat model resolution state
steipete Mar 24, 2026
0b54b64
fix(feishu): preserve docx block tree order (openclaw#40524)
TaoXieSZ Mar 24, 2026
0f84aac
fix: stabilize matrix and teams ci assertions
steipete Mar 24, 2026
3689a82
fix: preserve subagent ended hooks until runtime init
Takhoffman Mar 24, 2026
da10b60
test: prune low-signal live model sweeps
steipete Mar 24, 2026
687ce31
test: harden parallels smoke harness
steipete Mar 24, 2026
0fc2740
fix: preserve direct subagent dispatch failures on abort
Takhoffman Mar 24, 2026
ab8c834
fix: report dropped subagent announce queue deliveries
Takhoffman Mar 24, 2026
a2d3b9f
fix: unblock live harness provider discovery
steipete Mar 24, 2026
c3744fb
fix: finalize resumed subagent cleanup give-ups
Takhoffman Mar 24, 2026
fd0fa97
refactor: centralize plugin install config policy
steipete Mar 24, 2026
5dc42df
fix: format subagent registry test
steipete Mar 24, 2026
5e9ea80
fix: finalize deferred subagent expiry cleanup
Takhoffman Mar 24, 2026
cc8ed8d
fix(tui): preserve user message during slow model responses (#53115)
joelnishanth Mar 23, 2026
ff2e9a5
fix: preserve deferred TUI history sync (#53130) (thanks @joelnishanth)
steipete Mar 24, 2026
ecb3aa7
test: sync app chat model override expectation
steipete Mar 24, 2026
a710366
feat(ui): Control UI polish — skills revamp, markdown preview, agent …
BunsDev Mar 24, 2026
cb58e45
fix(security): resolve Aisle findings — skill installer validation, t…
BunsDev Mar 24, 2026
b61a875
fix: widen installer regex allowlists and deduplicate safeExternalHre…
BunsDev Mar 24, 2026
d41b92f
docs: update CONTRIBUTING.md
obviyus Mar 24, 2026
2833b27
test: continue vitest threads migration
steipete Mar 24, 2026
e7817ad
test: continue vitest threads migration
steipete Mar 24, 2026
43131dc
test: harden threaded shared-worker suites
steipete Mar 24, 2026
b1b162f
test: harden threaded channel follow-ups
steipete Mar 24, 2026
60cd98a
test: defer slack bolt interop for helper-only suites
steipete Mar 24, 2026
922f4e6
fix(agents): harden edit tool recovery (#52516)
mbelinky Mar 24, 2026
c84c630
fix(docs): correct json55 typo to json5 in IRC channel docs (#50831) …
Hollychou924 Mar 24, 2026
ac07d88
fix(secrets): prevent unresolved SecretRef from crashing embedded age…
Lukavyi Mar 24, 2026
0a04ef4
fix: merge explicit reply config overrides onto fresh config
obviyus Mar 24, 2026
b72d0c8
fix: clean up failed non-thread subagent spawns
Takhoffman Mar 24, 2026
e6e2407
fix: initialize plugins before killed subagent hooks
Takhoffman Mar 24, 2026
f56a79f
fix: report qmd status counts from real qmd manager (#53683) (thanks …
neeravmakwana Mar 24, 2026
d7e48d4
fix: ci
Takhoffman Mar 24, 2026
807daf5
fix: finalize killed delete-mode subagent cleanup
Takhoffman Mar 24, 2026
dd11bdd
fix: clean up attachments for killed subagent runs
Takhoffman Mar 24, 2026
91adc5e
feat(cli): support targeting running containerized openclaw instances…
sallyom Mar 24, 2026
8754d8e
fix: ci
Takhoffman Mar 24, 2026
35de467
Telegram: recover General topic bindings (#53699)
huntharo Mar 24, 2026
938f8f4
fix: clean up attachments for released subagent runs
Takhoffman Mar 24, 2026
075ece3
fix(ci): do not cancel in-progress main runs
Takhoffman Mar 24, 2026
df2f900
fix: clean up attachments for orphaned subagent runs
Takhoffman Mar 24, 2026
88f49c2
test: speed up discord extension suites
steipete Mar 24, 2026
db4572b
test: speed up slack extension suites
steipete Mar 24, 2026
83bb647
test: speed up telegram extension suites
steipete Mar 24, 2026
d884676
test: speed up whatsapp and shared test suites
steipete Mar 24, 2026
0bda670
fix(ci): do not cancel in-progress bun runs on main
Takhoffman Mar 24, 2026
3f99a30
fix: clean up attachments when replacing subagent runs
Takhoffman Mar 24, 2026
aa91000
feat(discord): add autoThreadName 'generated' strategy (#43366)
davidguttman Mar 24, 2026
66e9548
add missing autoArchiveDuration to DiscordGuildChannelConfig type (#4…
davidguttman Mar 24, 2026
781295c
refactor: dedupe test and script helpers
steipete Mar 24, 2026
1d4db99
test: speed up discord extension suites
steipete Mar 24, 2026
a29b9f2
test: speed up slack extension suites
steipete Mar 24, 2026
86921b6
test: speed up telegram extension suites
steipete Mar 24, 2026
49ae71f
test: speed up signal and whatsapp extension suites
steipete Mar 24, 2026
3e9ff16
fix(discord): avoid bundling pi-ai runtime deps
Takhoffman Mar 24, 2026
f0761b4
fix(lockfile): sync discord dependency removal
Takhoffman Mar 24, 2026
5edba12
test: speed up discord slack telegram suites
steipete Mar 24, 2026
332d2eb
test: speed up whatsapp and signal suites
steipete Mar 24, 2026
27b92f8
test: speed up google and twitch suites
steipete Mar 24, 2026
49e3f2d
test: speed up core unit suites
steipete Mar 24, 2026
79ef86c
fix: preserve cleanup hooks after subagent register failure
Takhoffman Mar 24, 2026
ada703a
fix: preserve session cleanup hooks after subagent announce
Takhoffman Mar 24, 2026
a1cb302
Feishu: avoid CLI startup failure on unresolved SecretRef
hpt Mar 24, 2026
2f238b5
fix(doctor): add missing baseUrl and models when migrating nano-banan…
mahopan Mar 24, 2026
700ec2f
fix: use v1beta for migrated google nano banana provider (#53757) (th…
steipete Mar 24, 2026
72300e8
docs: add changelog for PR #53675 (thanks @hpt)
steipete Mar 24, 2026
e727ad6
fix(msteams): harden feedback reflection follow-ups
steipete Mar 24, 2026
559b3a5
test: stabilize preaction process title assertion (#53808)
jalehman Mar 24, 2026
bbe6f7f
fix(auth): protect fresher codex reauth state
giulio-leone Mar 24, 2026
129b1b5
fix: return structured errors for subagent control send failures
Takhoffman Mar 24, 2026
9f47892
refactor: centralize google API base URL handling
steipete Mar 24, 2026
27448c3
refactor(msteams): split reply and reflection helpers
steipete Mar 24, 2026
8e9e2d2
refactor(auth): unify external CLI credential sync
steipete Mar 24, 2026
ba95d43
refactor: split feishu runtime and inspect secret resolution
steipete Mar 24, 2026
7eefddd
test(memory): clear browser and plugin caches between cases
vincentkoc Mar 24, 2026
44d5e6d
fix(types): add workspace module shims
steipete Mar 24, 2026
2990446
fix: avoid duplicate orphaned subagent resumes
Takhoffman Mar 24, 2026
14f1b65
test(memory): enable lower-interval heap snapshots
vincentkoc Mar 24, 2026
f527528
fix: audit clobbered config reads
steipete Mar 24, 2026
0d4b47a
fix(whatsapp): filter fromMe messages in groups to prevent infinite l…
w-sss Mar 24, 2026
b11f483
fix: suppress only recent whatsapp group echoes (#53624) (thanks @w-sss)
steipete Mar 24, 2026
4518f6e
test: speed up slack and telegram suites
steipete Mar 24, 2026
6e20c26
test: speed up cli and model command suites
steipete Mar 24, 2026
cc9d110
test: speed up command runtime suites
steipete Mar 24, 2026
f47549c
test: speed up backup and doctor suites
steipete Mar 24, 2026
a1c91bd
fix(memory): avoid caching status-only managers
vincentkoc Mar 24, 2026
398d58f
fix: stabilize logging config imports
steipete Mar 24, 2026
f2475a7
fix(slack): improve interactive reply parity (#53389)
vincentkoc Mar 24, 2026
a37ed72
test: preserve child_process exports in restart bun mock
steipete Mar 24, 2026
435e2c5
fix(memory): avoid caching qmd status managers
vincentkoc Mar 24, 2026
a8bf75f
test: speed up browser and gateway suites
steipete Mar 24, 2026
d2e0cfc
test: speed up media fetch suite
steipete Mar 24, 2026
7b81429
fix(acp): deliver final result text as fallback when no blocks routed
w-sss Mar 24, 2026
69a0a6c
fix: tighten ACP final fallback semantics (#53692) (thanks @w-sss)
steipete Mar 24, 2026
822563d
fix: unify pi runner usage snapshot fallback
steipete Mar 24, 2026
d58d900
refactor: isolate ACP final delivery flow
steipete Mar 24, 2026
240479a
fix(ci): stop dropping pending main workflow runs
Takhoffman Mar 24, 2026
fbe5f45
test(memory): isolate new unit hotspot files
vincentkoc Mar 24, 2026
a088109
test(memory): isolate browser remote-tab hotspot
vincentkoc Mar 24, 2026
86de8b6
test(memory): isolate plugin-core hotspot
vincentkoc Mar 24, 2026
488ad4a
test(memory): isolate telegram bot hotspot
vincentkoc Mar 24, 2026
7ab4630
fix: continue subagent kill after session store write failures
Takhoffman Mar 24, 2026
e7ae7d9
test(memory): isolate telegram fetch hotspot
vincentkoc Mar 24, 2026
217cb0a
test: speed up plugin-sdk and cron suites
steipete Mar 24, 2026
6e9591c
test: speed up browser suites
steipete Mar 24, 2026
548c201
test(memory): isolate telegram monitor hotspot
vincentkoc Mar 24, 2026
3b03ff1
test(memory): isolate slack action-runtime hotspot
vincentkoc Mar 24, 2026
7daaefd
test(memory): recycle shared channels batches
vincentkoc Mar 24, 2026
d25b4a2
fix: fail closed when subagent steer remap fails
Takhoffman Mar 24, 2026
9acb4c8
Providers: fix kimi-coding thinking normalization
scoootscooob Mar 24, 2026
8633c7f
Providers: fix kimi fallback normalization
scoootscooob Mar 24, 2026
f163759
Plugins: resolve sdk aliases from the running CLI
scoootscooob Mar 24, 2026
fc60ced
Plugins: trust only startup cli sdk roots
scoootscooob Mar 24, 2026
01d3442
Plugins: sanitize sdk export subpaths
scoootscooob Mar 24, 2026
44e27c6
Webchat: handle bare /compact as session compaction
scoootscooob Mar 24, 2026
1909311
Chat UI: tighten compact transport handling
scoootscooob Mar 24, 2026
a395c75
Chat UI: guard compact retries
scoootscooob Mar 24, 2026
03ed0bc
fix: ignore stale subagent steer targets
Takhoffman Mar 24, 2026
7fab2c2
fix(discord): notify user on discord when inbound worker times out (#…
dutifulbob Mar 24, 2026
e16f0cf
refactor(channels): route registry lookups through runtime
vincentkoc Mar 24, 2026
6451bed
refactor(plugins): make runtime registry lazy
vincentkoc Mar 24, 2026
f41bdf3
refactor(plugins): make hook runner global lazy
vincentkoc Mar 24, 2026
6bef8de
refactor(plugins): make command registry lazy
vincentkoc Mar 24, 2026
3a4cc89
fix: allow compact retry after failed session compaction (#53875)
scoootscooob Mar 24, 2026
d0002c5
refactor(gateway): make plugin fallback state lazy
vincentkoc Mar 24, 2026
0caafa5
refactor(plugins): make interactive state lazy
vincentkoc Mar 24, 2026
0cdd4db
fix(memory): align status manager concurrency test
vincentkoc Mar 24, 2026
e4ce1d9
fix(runtime): stabilize dist runtime artifacts (#53855)
vincentkoc Mar 24, 2026
a97188c
ci: start required checks earlier (#53844)
vincentkoc Mar 24, 2026
2383107
fix: unblock supervisor and memory gate failures
steipete Mar 24, 2026
f6b3377
test: stabilize low-profile parallel gate
steipete Mar 24, 2026
a9da52d
refactor(core): make event and queue state lazy
vincentkoc Mar 24, 2026
783cbd1
fix(ci): refresh plugin sdk baseline and formatting
vincentkoc Mar 24, 2026
7101ddc
chore: refresh plugin sdk api baseline
steipete Mar 24, 2026
627ab89
fix: ignore stale subagent kill targets
Takhoffman Mar 24, 2026
4031555
perf(plugins): scope web search plugin loads
vincentkoc Mar 24, 2026
870c52a
fix: ignore stale subagent send targets
Takhoffman Mar 24, 2026
d601122
fix: validate agent workspace paths before writing identity files (#5…
drobison00 Mar 24, 2026
a4327ad
refactor: dedupe tests and harden suite isolation
steipete Mar 24, 2026
ec23552
test: fix manifest registry fixture typing
Takhoffman Mar 24, 2026
91b1e41
fix: ignore stale bulk subagent kill targets
Takhoffman Mar 24, 2026
805bff6
fix(cli): precompute bare root help startup path
vincentkoc Mar 24, 2026
87919de
fix(test): stabilize npm runner path assertion
vincentkoc Mar 24, 2026
698c02e
test(gateway): align safe open error code
vincentkoc Mar 24, 2026
4029ce7
test: speed up targeted unit suites
steipete Mar 24, 2026
231d625
fix: prefer current subagent targets over stale rows
Takhoffman Mar 24, 2026
1beda4a
fix(ci): use target-platform npm path semantics
vincentkoc Mar 24, 2026
c2fb7f1
Adjust CLI backend environment handling before spawn (#53921)
drobison00 Mar 24, 2026
db0f957
fix: surface finished subagent send targets
Takhoffman Mar 24, 2026
7330e2c
perf(memory): avoid eager provider init on empty search
vincentkoc Mar 24, 2026
aaf2d63
fix(test): satisfy cli backend config typing
vincentkoc Mar 24, 2026
f6a0cdc
fix: let subagent kill cascade through ended parents
Takhoffman Mar 24, 2026
7d6d112
perf(sqlite): use existence probes for empty memory search
vincentkoc Mar 24, 2026
e99c270
fix: allow follow-up sends to finished subagents
Takhoffman Mar 24, 2026
caa718a
fix: steer ended subagent orchestrators with live descendants
Takhoffman Mar 24, 2026
e2acfcf
test: speed up browser pw-tools-core suites
steipete Mar 24, 2026
ddf65a9
test: speed up memory and secrets suites
steipete Mar 24, 2026
eda1ef7
fix(ci): align lazy memory provider tests
vincentkoc Mar 24, 2026
6bf90a1
fix(test): stabilize memory vector dedupe assertion
vincentkoc Mar 24, 2026
0d2315e
fix(test): isolate github copilot token imports
vincentkoc Mar 24, 2026
ebe18c0
fix: keep active-descendant subagents visible in reply status
Takhoffman Mar 24, 2026
bcd61f0
refactor: dedupe helpers and source seams
steipete Mar 24, 2026
68b36cd
test: fix rebase gate regressions
steipete Mar 24, 2026
3031f06
Adjust Feishu webhook request body limits (#53933)
drobison00 Mar 24, 2026
69d6e95
fix: dedupe stale subagent rows in reply views
Takhoffman Mar 24, 2026
cf96fa6
ci: batch shared extensions test lane
steipete Mar 24, 2026
51e5998
fix: report deduped subagent totals
Takhoffman Mar 24, 2026
a4ccd75
fix: dedupe verbose subagent status counts
Takhoffman Mar 24, 2026
9f4f997
fix: align /agents ids with subagent targets
Takhoffman Mar 24, 2026
23a4ae4
refactor: dedupe test helpers and harnesses
steipete Mar 24, 2026
d648aeb
perf(memory): builtin sqlite hot-path follow-ups (#53939)
vincentkoc Mar 24, 2026
3622569
test: speed up memory provider suites
steipete Mar 24, 2026
e5173af
test: speed up slack monitor suites
steipete Mar 24, 2026
14e3c2d
test: speed up discord channel suites
steipete Mar 24, 2026
a18e156
test: speed up telegram and whatsapp suites
steipete Mar 24, 2026
ac8a5a6
ci: increase test shard fanout
vincentkoc Mar 24, 2026
eb40f0b
fix: clean up matrix /agents binding labels
Takhoffman Mar 24, 2026
e24704d
fix: dedupe active child session counts
Takhoffman Mar 24, 2026
c541cde
fix: dedupe restarted descendant session counts
Takhoffman Mar 24, 2026
47dc7fe
fix: blcok non-owner authorized senders from chaning /send policy (#5…
drobison00 Mar 24, 2026
e28b516
fix(slack): trim DM reply overhead and restore Codex auto transport (…
vincentkoc Mar 24, 2026
3dc139b
test: speed up discord monitor suites
steipete Mar 24, 2026
d282667
test: speed up cli and command suites
steipete Mar 24, 2026
40ab7ac
test: speed up slack monitor suites
steipete Mar 24, 2026
b8a0258
fix: ignore stale rows in subagent activity checks
Takhoffman Mar 24, 2026
c90ae1e
fix: prefer latest subagent rows for session control
Takhoffman Mar 24, 2026
2c5c5ac
fix: ignore stale rows in subagent admin kill
Takhoffman Mar 24, 2026
fee9d4c
fix: dedupe stale child completion announces
Takhoffman Mar 24, 2026
b6031a9
fix: ignore stale rows in subagent steer
Takhoffman Mar 24, 2026
a03bbca
fix: cascade bulk subagent kills past stale rows
Takhoffman Mar 24, 2026
1fd6843
fix: ignore stale rows in fast abort
Takhoffman Mar 24, 2026
907b525
fix: ignore stale rows in subagent kill cascade
Takhoffman Mar 24, 2026
1d7cb6f
fix: close sandbox media root bypass for mediaUrl/fileUrl aliases (#5…
drobison00 Mar 24, 2026
369119b
fix: ignore stale parent rows in session child lists
Takhoffman Mar 24, 2026
6f64680
refactor: dedupe test and runtime seams
steipete Mar 24, 2026
dbb806d
Docker: avoid setup CLI namespace loop
Mar 24, 2026
81be4b4
Docker: seed localhost control UI origin
Mar 24, 2026
3ce09bd
Tests: reset docker setup log before isolated assert
Mar 24, 2026
d21ecd7
Tests: match any pre-start openclaw-cli run
Mar 24, 2026
e10ea53
fix: add changelog for docker setup namespace loop (#53385) (thanks @…
steipete Mar 24, 2026
63b0036
fix: normalize baseUrl for custom Google Generative AI providers
Kathie-yu Mar 13, 2026
c9f4dd3
test: speed up browser control suites
steipete Mar 24, 2026
1a79145
test: speed up infra and shared suites
steipete Mar 24, 2026
1ba436b
test: speed up media and image-generation suites
steipete Mar 24, 2026
33e9e48
refactor: clarify docker setup cli phases
steipete Mar 24, 2026
e48a0b8
fix: ignore moved subagent children on stale parents
Takhoffman Mar 24, 2026
b665749
Gateway: parse Compose-style gateway port env values
bebule Mar 11, 2026
ac7ca52
Gateway: harden Compose-style gateway port parsing
bebule Mar 12, 2026
0709224
fix: tighten gateway compose port parsing (#44083) (thanks @bebule)
steipete Mar 24, 2026
eaad4ad
feat(gateway): add missing OpenAI-compatible endpoints (models and em…
vincentkoc Mar 24, 2026
ca578a9
fix: mark card field as optional in message tool schema
Mar 24, 2026
d4fda79
fix: add merged message tool schema guardrail (#53715) (thanks @lndyz…
steipete Mar 24, 2026
b9f4870
fix(feishu): prevent silent group message drops when bot-info probe t…
Mar 12, 2026
3664c2c
fix: polish feishu retry helper (#43788) (thanks @lefarcen)
steipete Mar 24, 2026
639706f
fix: ignore moved child rows in subagent status
Takhoffman Mar 24, 2026
561acd1
test: tighten shared card schema coverage
steipete Mar 25, 2026
56eeec4
fix: require operator.admin for mutating internal /allowlist commands…
drobison00 Mar 25, 2026
5cdb50a
refactor: unify Google Generative AI normalization
steipete Mar 25, 2026
f6205de
refactor: split feishu helpers and tests
steipete Mar 25, 2026
e6db1dd
fix: hide moved subagents from stale command targets
Takhoffman Mar 25, 2026
3a1b517
fix: repair CI regression checks
steipete Mar 25, 2026
83591fa
test: consolidate plugin provider suites
steipete Mar 25, 2026
f7de5c3
test: collapse search helper suites
steipete Mar 25, 2026
16d2e68
fix: ignore stale store ownership in session child lists
Takhoffman Mar 25, 2026
6eaff70
fix: ignore moved child rows in subagent announces
Takhoffman Mar 25, 2026
ad818bd
fix: ignore moved child rows in spawnedBy session filters
Takhoffman Mar 25, 2026
475983a
fix: prefer current subagent owners in session rows
Takhoffman Mar 25, 2026
1b5b23d
fix: prefer current parents in session rows
Takhoffman Mar 25, 2026
8d87e85
test(browser): stabilize default browser detection mocks
vincentkoc Mar 25, 2026
e1d16ba
test(parallel): force unit-fast batch planning
vincentkoc Mar 25, 2026
d106696
feat(gateway): make openai compatibility agent-first
vincentkoc Mar 25, 2026
2069e12
chore(agents): normalize pi embedded runner imports
vincentkoc Mar 25, 2026
5799322
Discord: resolve /think autocomplete from session model (#49176)
MonkeyLeeT Mar 25, 2026
154e14f
fix: resolve exact session ids without fuzzy limits
Takhoffman Mar 25, 2026
57fd0a9
fix: enforce spawned session visibility in key resolve
Takhoffman Mar 25, 2026
6651511
fix: verify exact spawned session visibility
Takhoffman Mar 25, 2026
2c1d16e
fix: drop spawned visibility list caps
Takhoffman Mar 25, 2026
fb04801
fix: enforce sandbox visibility for session_status ids
Takhoffman Mar 25, 2026
9c78233
feat: add /tools runtime availability view (#54088)
Takhoffman Mar 25, 2026
df58b4f
fix: prefer deterministic session id resume targets
Takhoffman Mar 25, 2026
7a7e4cd
fix: prefer deterministic session usage targets
Takhoffman Mar 25, 2026
3c46e03
fix: prefer deterministic transcript session keys
Takhoffman Mar 25, 2026
64432f8
test: disable Vitest fs cache on Windows
Takhoffman Mar 25, 2026
0c35ac4
fix: prefer freshest transcript session owners
Takhoffman Mar 25, 2026
f3eb620
fix: refresh available tools when the session model changes (#54184)
Takhoffman Mar 25, 2026
93656da
test: make vitest config tests platform-aware
Takhoffman Mar 25, 2026
40f820f
fix: prefer freshest duplicate session rows in reads
Takhoffman Mar 25, 2026
ecb9bb3
Merge remote-tracking branch 'upstream/main' into sync/upstream-2026-…
linfangw Mar 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
21 changes: 21 additions & 0 deletions .agents/skills/openclaw-parallels-smoke/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,13 +16,30 @@ Use this skill for Parallels guest workflows and smoke interpretation. Do not lo
- Pass `--json` for machine-readable summaries.
- Per-phase logs land under `/tmp/openclaw-parallels-*`.
- Do not run local and gateway agent turns in parallel on the same fresh workspace or session.
- For `prlctl exec`, pass the VM name before `--current-user` (`prlctl exec "$VM" --current-user ...`), not the other way around.

## npm install then update

- Preferred entrypoint: `pnpm test:parallels:npm-update`
- Flow: fresh snapshot -> install npm package baseline -> smoke -> install current main tgz on the same guest -> smoke again.
- Same-guest update verification should set the default model explicitly to `openai/gpt-5.4` before the agent turn and use a fresh explicit `--session-id` so old session model state does not leak into the check.
- The aggregate npm-update wrapper must resolve the Linux VM with the same Ubuntu fallback policy as `parallels-linux-smoke.sh` before both fresh and update lanes. On Peter's current host, missing `Ubuntu 24.04.3 ARM64` should fall back to `Ubuntu 25.10`.
- On Windows same-guest update checks, restart the gateway after the npm upgrade before `gateway status` / `agent`; in-place global npm updates can otherwise leave stale hashed `dist/*` module imports alive in the running service.
- For Windows same-guest update checks, prefer the done-file/log-drain PowerShell runner pattern over one long-lived `prlctl exec ... powershell -EncodedCommand ...` transport. The guest can finish successfully while the outer `prlctl exec` still hangs.
- Linux same-guest update verification should also export `HOME=/root`, pass `OPENAI_API_KEY` via `prlctl exec ... /usr/bin/env`, and use `openclaw agent --local`; the fresh Linux baseline does not rely on persisted gateway credentials.

## CLI invocation footgun

- The Parallels smoke shell scripts should tolerate a literal bare `--` arg so `pnpm test:parallels:* -- --json` and similar forwarded invocations work without needing to call `bash scripts/e2e/...` directly.

## macOS flow

- Preferred entrypoint: `pnpm test:parallels:macos`
- Default to the snapshot closest to `macOS 26.3.1 latest`.
- On Peter's Tahoe VM, `fresh-latest-march-2026` can hang in `prlctl snapshot-switch`; if restore times out there, rerun with `--snapshot-hint 'macOS 26.3.1 latest'` before blaming auth or the harness.
- The macOS smoke should include a dashboard load phase after gateway health: resolve the tokenized URL with `openclaw dashboard --no-open`, verify the served HTML contains the Control UI title/root shell, then open Safari and require an established localhost TCP connection from Safari to the gateway port.
- `prlctl exec` is fine for deterministic repo commands, but use the guest Terminal or `prlctl enter` when installer parity or shell-sensitive behavior matters.
- Multi-word `openclaw agent --message ...` checks should go through a guest shell wrapper (`guest_current_user_sh` / `guest_current_user_cli` or `/bin/sh -lc ...`), not raw `prlctl exec ... node openclaw.mjs ...`, or the message can be split into extra argv tokens and Commander reports `too many arguments for 'agent'`.
- On the fresh Tahoe snapshot, `brew` exists but `node` may be missing from PATH in noninteractive exec. Use `/opt/homebrew/bin/node` when needed.
- Fresh host-served tgz installs should install as guest root with `HOME=/var/root`, then run onboarding as the desktop user via `prlctl exec --current-user`.
- Root-installed tgz smoke can log plugin blocks for world-writable `extensions/*`; do not treat that as an onboarding or gateway failure unless plugin loading is the task.
Expand All @@ -34,7 +51,11 @@ Use this skill for Parallels guest workflows and smoke interpretation. Do not lo
- Always use `prlctl exec --current-user`; plain `prlctl exec` lands in `NT AUTHORITY\\SYSTEM`.
- Prefer explicit `npm.cmd` and `openclaw.cmd`.
- Use PowerShell only as the transport with `-ExecutionPolicy Bypass`, then call the `.cmd` shims from inside it.
- Multi-word `openclaw agent --message ...` checks should call `& $openclaw ...` inside PowerShell, not `Start-Process ... -ArgumentList` against `openclaw.cmd`, or Commander can see split argv and throw `too many arguments for 'agent'`.
- Windows installer/tgz phases now retry once after guest-ready recheck; keep new Windows smoke steps idempotent so a transport-flake retry is safe.
- Windows global `npm install -g` phases can stay quiet for a minute or more even when healthy; inspect the phase log before calling it hung, and only treat it as a regression once the retry wrapper or timeout trips.
- Keep onboarding and status output ASCII-clean in logs; fancy punctuation becomes mojibake in current capture paths.
- If you hit an older run with `rc=255` plus an empty `fresh.install-main.log` or `upgrade.install-main.log`, treat it as a likely `prlctl exec` transport drop after guest start-up, not immediate proof of an npm/package failure.

## Linux flow

Expand Down
171 changes: 167 additions & 4 deletions .agents/skills/openclaw-release-maintainer/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,9 @@ Use this skill for release and publish-time workflow. Keep ordinary development

- Do not change version numbers without explicit operator approval.
- Ask permission before any npm publish or release step.
- Use the private maintainer release docs for the actual runbook and `docs/reference/RELEASING.md` for public policy.
- This skill should be sufficient to drive the normal release flow end-to-end.
- Use the private maintainer release docs for credentials, recovery steps, and mac signing/notary specifics, and use `docs/reference/RELEASING.md` for public policy.
- Core `openclaw` publish is manual `workflow_dispatch`; creating or pushing a tag does not publish by itself.

## Keep release channel naming aligned

Expand All @@ -31,8 +33,19 @@ Use this skill for release and publish-time workflow. Keep ordinary development
- `apps/macos/Sources/OpenClaw/Resources/Info.plist`
- `docs/install/updating.md`
- Peekaboo Xcode project and plist version fields
- Before creating a release tag, make every version location above match the version encoded by that tag.
- For fallback correction tags like `vYYYY.M.D-N`, the repo version locations still stay at `YYYY.M.D`.
- “Bump version everywhere” means all version locations above except `appcast.xml`.
- Release signing and notary credentials live outside the repo in the private maintainer docs.
- Every OpenClaw release ships the npm package and macOS app together.
- The production Sparkle feed lives at `https://raw.githubusercontent.com/openclaw/openclaw/main/appcast.xml`, and the canonical published file is `appcast.xml` on `main` in the `openclaw` repo.
- That shared production Sparkle feed is stable-only. Beta mac releases may
upload assets to the GitHub prerelease, but they must not replace the shared
`appcast.xml` unless a separate beta feed exists.
- For fallback correction tags like `vYYYY.M.D-N`, the repo version still stays
at `YYYY.M.D`, but the mac release must use a strictly higher numeric
`APP_BUILD` / Sparkle build than the original release so existing installs
see it as newer.

## Build changelog-backed release notes

Expand All @@ -59,16 +72,166 @@ pnpm test:install:smoke
For a non-root smoke path:

```bash
OPENCLAW_INSTALL_SMOKE_SKIP_NONROOT=1 pnpm test:install:smoke
OPENCLAW_INSTALL_SMOKE_SKIP_NONROOT=1 pnpm test:install:smoke
```

After npm publish, run:

```bash
node --import tsx scripts/openclaw-npm-postpublish-verify.ts <published-version>
```

- This verifies the published registry install path in a fresh temp prefix.
- For stable correction releases like `YYYY.M.D-N`, it also verifies the
upgrade path from `YYYY.M.D` to `YYYY.M.D-N` so a correction publish cannot
silently leave existing global installs on the old base stable payload.

## Check all relevant release builds

- Always validate the OpenClaw npm release path before creating the tag.
- Default release checks:
- `pnpm check`
- `pnpm build`
- `node --import tsx scripts/release-check.ts`
- `pnpm release:check`
- `OPENCLAW_INSTALL_SMOKE_SKIP_NONROOT=1 pnpm test:install:smoke`
- Check all release-related build surfaces touched by the release, not only the npm package.
- Include mac release readiness in preflight by running the public validation
workflow in `openclaw/openclaw` and the real mac preflight in
`openclaw/releases-private` for every release.
- Treat the `appcast.xml` update on `main` as part of mac release readiness, not an optional follow-up.
- The workflows remain tag-based. The agent is responsible for making sure
preflight runs complete successfully before any publish run starts.
- Any fix after preflight means a new commit. Delete and recreate the tag and
matching GitHub release from the fixed commit, then rerun preflight from
scratch before publishing.
- For stable mac releases, generate the signed `appcast.xml` before uploading
public release assets so the updater feed cannot lag the published binaries.
- Serialize stable appcast-producing runs across tags so two releases do not
generate replacement `appcast.xml` files from the same stale seed.
- For stable releases, confirm the latest beta already passed the broader release workflows before cutting stable.
- If any required build, packaging step, or release workflow is red, do not say the release is ready.

## Use the right auth flow

- Core `openclaw` publish uses GitHub trusted publishing.
- Do not use `NPM_TOKEN` or the plugin OTP flow for core releases.
- OpenClaw publish uses GitHub trusted publishing.
- The publish run must be started manually with `workflow_dispatch`.
- The npm workflow and the private mac publish workflow accept
`preflight_only=true` to run validation/build/package steps without uploading
public release assets.
- The private mac workflow also accepts `smoke_test_only=true` for branch-safe
workflow smoke tests that use ad-hoc signing, skip notarization, skip shared
appcast generation, and do not prove release readiness.
- `preflight_only=true` on the npm workflow is also the right way to validate an
existing tag after publish; it should keep running the build checks even when
the npm version is already published.
- Validation-only runs may be dispatched from a branch when you are testing a
workflow change before merge.
- `.github/workflows/macos-release.yml` in `openclaw/openclaw` is now a
public validation-only handoff. It validates the tag/release state and points
operators to the private repo; it does not build or publish macOS artifacts.
- Real mac preflight and real mac publish both use
`openclaw/releases-private/.github/workflows/openclaw-macos-publish.yml`.
- The private mac workflow runs on GitHub's xlarge macOS runner and uses a
SwiftPM cache because the Swift build/test/package path is CPU-heavy.
- Private mac preflight uploads notarized build artifacts as workflow artifacts
instead of uploading public GitHub release assets.
- Private smoke-test runs upload ad-hoc, non-notarized build artifacts as
workflow artifacts and intentionally skip stable `appcast.xml` generation.
- npm preflight, public mac validation, and private mac preflight must all pass
before any real publish run starts.
- Real publish runs must be dispatched from `main`; branch-dispatched publish
attempts should fail before the protected environment is reached.
- The release workflows stay tag-based; rely on the documented release sequence
rather than workflow-level SHA pinning.
- The `npm-release` environment must be approved by `@openclaw/openclaw-release-managers` before publish continues.
- Mac publish uses
`openclaw/releases-private/.github/workflows/openclaw-macos-publish.yml` for
build, signing, notarization, packaged mac artifact generation, and
stable-feed `appcast.xml` artifact generation.
- Real private mac publish uploads the packaged `.zip`, `.dmg`, and
`.dSYM.zip` assets to the existing GitHub release in `openclaw/openclaw`
automatically when `OPENCLAW_PUBLIC_REPO_RELEASE_TOKEN` is present in the
private repo `mac-release` environment.
- For stable releases, the agent must also download the signed
`macos-appcast-<tag>` artifact from the successful private mac workflow and
then update `appcast.xml` on `main`.
- For beta mac releases, do not update the shared production `appcast.xml`
unless a separate beta Sparkle feed exists.
- The private repo targets a dedicated `mac-release` environment. If the GitHub
plan does not yet support required reviewers there, do not assume the
environment alone is the approval boundary; rely on private repo access and
CODEOWNERS until those settings can be enabled.
- Do not use `NPM_TOKEN` or the plugin OTP flow for OpenClaw releases.
- `@openclaw/*` plugin publishes use a separate maintainer-only flow.
- Only publish plugins that already exist on npm; bundled disk-tree-only plugins stay unpublished.

## Fallback local mac publish

- Keep the original local macOS publish workflow available as a fallback in case
CI/CD mac publishing is unavailable or broken.
- Preserve the existing maintainer workflow Peter uses: run it on a real Mac
with local signing, notary, and Sparkle credentials already configured.
- Follow the private maintainer macOS runbook for the local steps:
`scripts/package-mac-dist.sh` to build, sign, notarize, and package the app;
manual GitHub release asset upload; then `scripts/make_appcast.sh` plus the
`appcast.xml` commit to `main`.
- `scripts/package-mac-dist.sh` now fails closed for release builds if the
bundled app comes out with a debug bundle id, an empty Sparkle feed URL, or a
`CFBundleVersion` below the canonical Sparkle build floor for that short
version. For correction tags, set a higher explicit `APP_BUILD`.
- `scripts/make_appcast.sh` first uses `generate_appcast` from `PATH`, then
falls back to the SwiftPM Sparkle tool output under `apps/macos/.build`.
- For stable tags, the local fallback may update the shared production
`appcast.xml`.
- For beta tags, the local fallback still publishes the mac assets but must not
update the shared production `appcast.xml` unless a separate beta feed exists.
- Treat the local workflow as fallback only. Prefer the CI/CD publish workflow
when it is working.
- After any stable mac publish, verify all of the following before you call the
release finished:
- the GitHub release has `.zip`, `.dmg`, and `.dSYM.zip` assets
- `appcast.xml` on `main` points at the new stable zip
- the packaged app reports the expected short version and a numeric
`CFBundleVersion` at or above the canonical Sparkle build floor

## Run the release sequence

1. Confirm the operator explicitly wants to cut a release.
2. Choose the exact target version and git tag.
3. Make every repo version location match that tag before creating it.
4. Update `CHANGELOG.md` and assemble the matching GitHub release notes.
5. Run the full preflight for all relevant release builds, including mac readiness.
6. Confirm the target npm version is not already published.
7. Create and push the git tag.
8. Create or refresh the matching GitHub release.
9. Start `.github/workflows/openclaw-npm-release.yml` with `preflight_only=true`
and wait for it to pass.
10. Start `.github/workflows/macos-release.yml` in `openclaw/openclaw` and wait
for the public validation-only run to pass.
11. Start
`openclaw/releases-private/.github/workflows/openclaw-macos-publish.yml`
with `preflight_only=true` and wait for it to pass.
12. If any preflight or validation run fails, fix the issue on a new commit,
delete the tag and matching GitHub release, recreate them from the fixed
commit, and rerun all relevant preflights from scratch before continuing.
Never reuse old preflight results after the commit changes.
13. Start `.github/workflows/openclaw-npm-release.yml` with the same tag for
the real publish.
14. Wait for `npm-release` approval from `@openclaw/openclaw-release-managers`.
15. Start
`openclaw/releases-private/.github/workflows/openclaw-macos-publish.yml`
for the real publish and wait for success.
16. Verify the successful real private mac run uploaded the `.zip`, `.dmg`,
and `.dSYM.zip` artifacts to the existing GitHub release in
`openclaw/openclaw`.
17. For stable releases, download `macos-appcast-<tag>` from the successful
private mac run, update `appcast.xml` on `main`, and verify the feed.
18. For beta releases, publish the mac assets but expect no shared production
`appcast.xml` artifact and do not update the shared production feed unless a
separate beta feed exists.
19. After publish, verify npm and the attached release artifacts.

## GHSA advisory work

- Use `openclaw-ghsa-maintainer` for GHSA advisory inspection, patch/publish flow, private-fork validation, and GHSA API-specific publish checks.
14 changes: 12 additions & 2 deletions .github/actions/ensure-base-commit/action.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,14 +23,24 @@ runs:
exit 0
fi

if ! [[ "$BASE_SHA" =~ ^[0-9a-fA-F]{7,40}$ ]]; then
echo "::error title=ensure-base-commit invalid base sha::Refusing invalid base SHA: $BASE_SHA"
exit 2
fi

if ! git check-ref-format --branch "$FETCH_REF" >/dev/null 2>&1; then
echo "::error title=ensure-base-commit invalid fetch ref::Refusing invalid fetch ref: $FETCH_REF"
exit 2
fi

if git rev-parse --verify "$BASE_SHA^{commit}" >/dev/null 2>&1; then
echo "Base commit already present: $BASE_SHA"
exit 0
fi

for deepen_by in 25 100 300; do
echo "Base commit missing; deepening $FETCH_REF by $deepen_by."
if ! git fetch --no-tags --deepen="$deepen_by" origin "$FETCH_REF"; then
if ! git fetch --no-tags --deepen="$deepen_by" origin -- "$FETCH_REF"; then
echo "::warning title=ensure-base-commit fetch failed::Failed to deepen $FETCH_REF by $deepen_by while looking for $BASE_SHA"
fi
if git rev-parse --verify "$BASE_SHA^{commit}" >/dev/null 2>&1; then
Expand All @@ -40,7 +50,7 @@ runs:
done

echo "Base commit still missing; fetching full history for $FETCH_REF."
if ! git fetch --no-tags origin "$FETCH_REF"; then
if ! git fetch --no-tags origin -- "$FETCH_REF"; then
echo "::warning title=ensure-base-commit fetch failed::Failed to fetch full history for $FETCH_REF while looking for $BASE_SHA"
fi
if git rev-parse --verify "$BASE_SHA^{commit}" >/dev/null 2>&1; then
Expand Down
4 changes: 4 additions & 0 deletions .github/labeler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -246,6 +246,10 @@
- changed-files:
- any-glob-to-any-file:
- "extensions/byteplus/**"
"extensions: deepseek":
- changed-files:
- any-glob-to-any-file:
- "extensions/deepseek/**"
"extensions: anthropic":
- changed-files:
- any-glob-to-any-file:
Expand Down
26 changes: 26 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,6 +31,32 @@ Describe the problem and fix in 2–5 bullets:

- Closes #
- Related #
- [ ] This PR fixes a bug or regression

## Root Cause / Regression History (if applicable)

For bug fixes or regressions, explain why this happened, not just what changed. Otherwise write `N/A`. If the cause is unclear, write `Unknown`.

- Root cause:
- Missing detection / guardrail:
- Prior context (`git blame`, prior PR, issue, or refactor if known):
- Why this regressed now:
- If unknown, what was ruled out:

## Regression Test Plan (if applicable)

For bug fixes or regressions, name the smallest reliable test coverage that should have caught this. Otherwise write `N/A`.

- Coverage level that should have caught this:
- [ ] Unit test
- [ ] Seam / integration test
- [ ] End-to-end test
- [ ] Existing coverage already sufficient
- Target test or file:
- Scenario the test should lock in:
- Why this is the smallest reliable guardrail:
- Existing test that already covers this (if any):
- If no new test is added, why not:

## User-visible / Behavior Changes

Expand Down
4 changes: 4 additions & 0 deletions .github/workflows/auto-response.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,10 @@ on:
env:
FORCE_JAVASCRIPT_ACTIONS_TO_NODE24: "true"

concurrency:
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref || github.run_id }}
cancel-in-progress: ${{ github.event_name == 'pull_request_target' }}

permissions: {}

jobs:
Expand Down
Loading
Loading