Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
2435 commits
Select commit Hold shift + click to select a range
76b3235
chore(changelog): soften sdk removal note
vincentkoc Mar 31, 2026
1a313ca
refactor(tasks): remove flow registry layer
vincentkoc Mar 31, 2026
fcb802e
refactor(plugins): remove before_install hook
vincentkoc Mar 31, 2026
dd3796a
fix: normalize MCP tool schemas missing properties field for OpenAI R…
yelog Mar 31, 2026
b4433a1
fix: normalize raw MCP schemas for OpenAI Responses (#58299) (thanks …
steipete Mar 31, 2026
5e0e46f
style: format config UI templates
steipete Mar 31, 2026
62e13bb
style: format sandbox and helper files
steipete Mar 31, 2026
a1cb2bd
OpenAI: omit disabled reasoning payloads
jalehman Mar 30, 2026
ae730d9
fix: cover Azure disabled reasoning omission (#58208) (thanks @jalehman)
steipete Mar 31, 2026
693d17c
fix: support edit tool edits[] payloads
steipete Mar 31, 2026
69fe999
fix(pairing): restore qr bootstrap onboarding handoff (#58382) (thank…
ngutman Mar 31, 2026
7cd0ff2
refactor(tasks): add owner-key task access boundaries (#58516)
vincentkoc Mar 31, 2026
3ec1432
test(ci): rebalance discord webhook activity timing
vincentkoc Mar 31, 2026
6d59ce3
test(ci): rebalance matrix extension timings
vincentkoc Mar 31, 2026
e5537f8
test(ci): rebalance bluebubbles webhook auth timing
vincentkoc Mar 31, 2026
cb66112
test(bluebubbles): trim webhook auth import cost
vincentkoc Mar 31, 2026
b7013ec
docs: fix changelog release placement
steipete Mar 31, 2026
0abd143
test: fix CI flakes and registry test API
steipete Mar 31, 2026
6641348
fix(tasks): make task-store writes atomic (#58521)
vincentkoc Mar 31, 2026
b87f33c
test(ci): deflake windows npm exec coverage
steipete Mar 31, 2026
797a70f
Codex: add native web search for embedded Pi runs
Mar 15, 2026
0a89154
Codex: use model-level API for native search relevance
Mar 15, 2026
13f1190
CLI: suppress Codex native search summary when web search is off
Mar 17, 2026
62a3938
fix: land codex native search follow-ups (#46579) (thanks @Evizero)
steipete Mar 31, 2026
91be36c
build: prepare 2026.3.31-beta.1 release
steipete Mar 31, 2026
6f76299
build: refresh beta release generated artifacts
steipete Mar 31, 2026
8fa5ac5
build: refresh plugin sdk api baseline
steipete Mar 31, 2026
338d313
fix(tasks): scope shared run updates by session
vincentkoc Mar 31, 2026
2d2c271
build: exclude source maps from release tarball
steipete Mar 31, 2026
5fdde9b
fix(tasks): restore session key registry compatibility
steipete Mar 31, 2026
80ed553
fix(tasks): restore owner-key task scope
vincentkoc Mar 31, 2026
1816d6a
fix(tasks): normalize task create compatibility
vincentkoc Mar 31, 2026
bb912da
test(openai): fix ModelRegistry constructor typing
vincentkoc Mar 31, 2026
d0bcd86
fix(tasks): restore registry build compatibility
steipete Mar 31, 2026
2a72a6d
test(tasks): allow task executor registry seam
vincentkoc Mar 31, 2026
a23b4dd
fix(ci): route task executor through runtime seam
steipete Mar 31, 2026
cc278a7
test(tasks): update registry seam allowlist
steipete Mar 31, 2026
b441e59
fix(build): isolate bundled runtime dependency staging
vincentkoc Mar 31, 2026
2001603
fix(amazon-bedrock): pin installable aws sdk build
steipete Mar 31, 2026
ce58f55
fix: require doctor migration for legacy web search config
steipete Mar 31, 2026
2e530fc
revert(amazon-bedrock): restore locked aws sdk version
vincentkoc Mar 31, 2026
6f5f0c0
fix(slack): restore callable directory facade exports
vincentkoc Mar 31, 2026
1216ecb
Docs: add missing changelog entries
jacobtomlinson Mar 31, 2026
9d1b443
fix: harden live docker auth harness
steipete Mar 31, 2026
64091ca
fix: preserve cli and slack fallback behavior
steipete Mar 31, 2026
0d742c3
test: skip unavailable live model providers
steipete Mar 31, 2026
49458fc
fix: pin parallels version checks to packed build commit
steipete Mar 31, 2026
ffa2143
build: refresh slack facade output
steipete Mar 31, 2026
a4f45c5
fix(slack): restore callable directory facade exports
vincentkoc Mar 31, 2026
913e7d5
fix: correct callable plugin sdk facades
steipete Mar 31, 2026
58ee76f
feat(status): show session task counts in slash status
vincentkoc Mar 31, 2026
fc16921
fix(exec): deliver approval followups directly to chat
vincentkoc Mar 31, 2026
eee37bf
fix(slack): prevent duplicate draft replies
steipete Mar 31, 2026
2a60e34
build: prepare 2026.3.31 stable release
steipete Mar 31, 2026
418fa12
fix: make overload failover configurable
steipete Mar 31, 2026
0a7024e
test(tasks): allow status command task-registry import
vincentkoc Mar 31, 2026
f425ea0
fix(pi): flush message-boundary block replies on message end
vincentkoc Mar 31, 2026
6f11151
docs: refresh plugin sdk api baseline
steipete Mar 31, 2026
107fefd
docs(changelog): note pi tui reply flush fix
vincentkoc Mar 31, 2026
44baf3b
build(pnpm): exclude openclaw from minimum release age
vincentkoc Mar 31, 2026
213a704
fix: unblock 2026.3.31 release preflight
steipete Mar 31, 2026
93e2d0e
build(bluebubbles): align openclaw dependency specifiers
vincentkoc Mar 31, 2026
fdad8ea
fix(status): show agent-local task counts when session tasks are empty
vincentkoc Mar 31, 2026
f85aba4
fix(approvals): restore native DM approval behavior
vincentkoc Mar 31, 2026
968bc3d
fix(ci): preserve workspace openclaw plugin links
steipete Mar 31, 2026
e1d2b29
fix(reply): avoid double status replies
vincentkoc Mar 31, 2026
211b5a5
docs(changelog): note status followups
vincentkoc Mar 31, 2026
b73dd9b
fix(approvals): suppress manual native approval narration
vincentkoc Mar 31, 2026
db0f7c2
changelog: note discord and telegram approval UX fixes
vincentkoc Mar 31, 2026
6679690
fix(regression): restore diffs viewer toolbar buttons
gumadeiras Mar 31, 2026
ad06d5a
build: reuse release preflight artifacts
steipete Mar 31, 2026
ee8baf6
fix(reply): stop mention-wrapped status double replies
vincentkoc Mar 31, 2026
94d72ef
fix(slack): accept bare approve fallback
vincentkoc Mar 31, 2026
11318ef
fix(status): align session_status with /status
vincentkoc Mar 31, 2026
313a27d
docs: update appcast for 2026.3.31
steipete Mar 31, 2026
9ea7e06
build: bump version to 2026.4.1
steipete Mar 31, 2026
5997317
docs: add NVIDIA sponsor logo
steipete Mar 31, 2026
ddce362
refactor(approvals): share native delivery runtime
steipete Mar 31, 2026
aa6cf87
refactor(approvals): share origin target reconciliation
steipete Mar 31, 2026
091c610
style(test): format skills install test
steipete Mar 31, 2026
4f83409
docs: add theme-aware sponsor logos
steipete Mar 31, 2026
d7e9d34
fix: require npm auth for dist-tag mirror
steipete Mar 31, 2026
adc329b
test: dedupe extension-owned coverage (#58554)
jalehman Mar 31, 2026
cdaf6d5
docs: allow sponsor table markup in markdownlint
steipete Mar 31, 2026
f21abb2
fix: harden queue cleanup lane resolution
steipete Mar 31, 2026
d771f7d
fix: harden acpx live startup
steipete Mar 31, 2026
78d1120
test: retry gateway acp bind warmup
steipete Mar 31, 2026
bf0f33d
fix(compaction): resolve model override in runtime context for all co…
oliviareid-svg Mar 31, 2026
bea53d7
Fix: move bootstrap session grammar into plugin-owned session-key sur…
gumadeiras Mar 31, 2026
302c047
hotfix(ollama): Show only Ollama models after provider selection (#55…
Luckymingxuan Mar 31, 2026
c41df48
test: consolidate package manifest and core-extension contracts
steipete Apr 1, 2026
b910cc5
test: remove extension manifest and core-extension wrappers
steipete Apr 1, 2026
63819bb
test: consolidate provider and web-search contracts
steipete Apr 1, 2026
78be556
test: consolidate plugin registration contracts
steipete Apr 1, 2026
4af52a7
test: centralize provider runtime, discovery, and auth contracts
steipete Apr 1, 2026
8567925
test: remove extension provider contract wrappers
steipete Apr 1, 2026
ba5b373
test: centralize channel catalog contracts
steipete Apr 1, 2026
7614c45
test: fix channel catalog contract import
steipete Apr 1, 2026
1f97f90
test: centralize registry-backed channel contracts
steipete Apr 1, 2026
aea016d
test: fix registry-backed contract import
steipete Apr 1, 2026
2db2b07
test: remove extension group policy wrappers
steipete Apr 1, 2026
ddf3918
test: remove extension dm policy wrappers
steipete Apr 1, 2026
051e31f
test: centralize outbound payload contracts
steipete Apr 1, 2026
b59adf9
test: fix outbound payload contract import
steipete Apr 1, 2026
5b8f0cf
test: centralize inbound contract suites
steipete Apr 1, 2026
b8fea43
fix(gateway): return default scopes when trusted HTTP request has no …
hclsys Apr 1, 2026
8b6b4b1
feat: add agents.defaults.params for global default provider params (…
lpender Apr 1, 2026
3a52b47
Docs: clarify first-contribution fallback when no good-first-issue la…
qkal Apr 1, 2026
4d8c07b
feat(cron): add --tools flag for per-job tool allow-list (#58504)
andyk-ms Apr 1, 2026
ee42e44
fix(auth): add qwen-dashscope and anthropic-openai to known API key e…
richard950825-sys Apr 1, 2026
915e15c
fix(gateway): skip restart when config.patch has no actual changes (#…
jalen0x Apr 1, 2026
0b3d31c
feat(auth): WHAM-aware Codex cooldown for multi-profile setups (#58625)
ryanngit Apr 1, 2026
2650ce3
fix(media): resolve relative MEDIA paths against agent workspace (#58…
bobashopcashier Apr 1, 2026
68ee311
Fix: CDP profiles prefer cdpPort over stale WebSocket cdpUrl (Resolve…
Mlightsnow Apr 1, 2026
350fe63
feat(macos): Voice Wake option to trigger Talk Mode (#58490)
SmoothExec Apr 1, 2026
5471548
Fix: live session model switch no longer blocks failover (Resolves #5…
Mlightsnow Apr 1, 2026
40b24df
fix(session-status): infer custom runtime providers from config (#58474)
luoyanglang Apr 1, 2026
eee185a
feat(amazon-bedrock): add Bedrock Guardrails support (#58588)
MikeORed Apr 1, 2026
187d3ed
fix(acpx): fall back to PATH node for shebang wrappers (#58614)
zssggle-rgb Apr 1, 2026
7941f21
fix(voice-call): clear connection timeout on successful STT connect (…
SharoonSharif Apr 1, 2026
8e0f495
fix(acpx): preserve control command error details (#58613)
zssggle-rgb Apr 1, 2026
a37c669
fix(acpx): retry backend health probes after ensure (#58612)
zssggle-rgb Apr 1, 2026
b86f5d5
fix(sandbox): resolve pinned fs helper python without PATH (#58573)
reed1898 Apr 1, 2026
b554516
routing: support wildcard peer bindings (peer.id="*") for multi-agent…
joelnishanth Apr 1, 2026
6c3eea3
fix(session): prevent heartbeat/cron/exec events from triggering sess…
Linux2010 Apr 1, 2026
d266326
Fix broken URL in Twitch extension README (#58563)
YonganZhang Apr 1, 2026
ed8e6b0
plugins: suppress provenance warning for allowlisted local plugins (#…
dudu1111685 Apr 1, 2026
50cc28c
fix: differentiate overloaded vs rate-limit user-facing error message…
Maninae Apr 1, 2026
be5a035
fix: harden embedded text normalization (#58555)
agent-morrow Apr 1, 2026
beb2171
test: move openrouter live test to live suite
steipete Apr 1, 2026
1226361
test: move memory lancedb live smoke to live suite
steipete Apr 1, 2026
f9c1818
test: move openai live smoke to live suite
steipete Apr 1, 2026
0614d99
test: drop redundant openai registration smoke
steipete Apr 1, 2026
3c69e1e
test: drop low-signal plugin runtime type contract
steipete Apr 1, 2026
09c03fc
test: drop low-signal memory plugin metadata check
steipete Apr 1, 2026
219116e
test: drop redundant status-issues skip checks
steipete Apr 1, 2026
7e02005
test: move plugin-sdk guardrails to contracts suite
steipete Apr 1, 2026
016f065
test: move remaining plugin-sdk guardrails to contracts
steipete Apr 1, 2026
f5a23b7
test: move plugin-sdk index and root alias guardrails
steipete Apr 1, 2026
08bbb51
test: merge allowlist resolution coverage
steipete Apr 1, 2026
5816294
test: merge request-url coverage into fetch auth
steipete Apr 1, 2026
49ac85b
test: merge secret input schema coverage
steipete Apr 1, 2026
73ead24
test: drop redundant web search registration smokes
steipete Apr 1, 2026
042a9ab
test: fix plugin-sdk subpaths contract imports
steipete Apr 1, 2026
4765ce3
test: drop low-signal extension registration smokes
steipete Apr 1, 2026
5c27f15
test: drop browser plugin registration smoke
steipete Apr 1, 2026
35c9372
test: merge diffs registration smoke into config defaults
steipete Apr 1, 2026
6e773cc
test: drop webhook registration smokes
steipete Apr 1, 2026
5e371fe
test: drop discord command registration smoke
steipete Apr 1, 2026
8076c78
test: drop subagent hook registration smokes
steipete Apr 1, 2026
3c6e0cf
test: drop feishu plugin registration smoke
steipete Apr 1, 2026
a59f2f4
test: drop thread-ownership hook registration smoke
steipete Apr 1, 2026
6e2738e
test: merge kilocode provider registration coverage
steipete Apr 1, 2026
655d528
test: merge channel send result stamping coverage
steipete Apr 1, 2026
54f2c8e
test: merge mattermost setup registration checks
steipete Apr 1, 2026
cb131a7
test: merge dm allowlist pairing policy cases
steipete Apr 1, 2026
fbca5bc
test: merge status helper default/explicit cases
steipete Apr 1, 2026
d65c290
test: merge temp download path cases
steipete Apr 1, 2026
d11df8e
test: merge approval auth helper cases
steipete Apr 1, 2026
cf3d7c8
test: merge account status helper cases
steipete Apr 1, 2026
a217e97
test: merge approval renderer cases
steipete Apr 1, 2026
ba80857
test: merge allowlist config helper cases
steipete Apr 1, 2026
7ae093c
test: merge command auth cases
steipete Apr 1, 2026
098125e
test: merge channel reply pipeline typing cases
steipete Apr 1, 2026
69685f9
fix: preserve Telegram local Bot API MIME types (#54603) (thanks @jza…
jzakirov Apr 1, 2026
97fd6c2
fix(tasks): prevent synchronous task registry sweep from blocking eve…
openperf Apr 1, 2026
2dbfd4e
refactor(tasks): distill task registry sweep scheduling
obviyus Apr 1, 2026
05c311e
fix: record task sweep gateway hang fix (#58670) (thanks @openperf)
obviyus Apr 1, 2026
ed83d79
fix: tighten reply payload typing and safe text coercion
joshavant Apr 1, 2026
ccb67bd
config: regenerate base config schema baseline
joshavant Apr 1, 2026
2c5796c
fix(tasks): recheck current state during maintenance sweep
obviyus Apr 1, 2026
21403a3
fix(whatsapp): pass Timestamp to finalizeInboundContext (#58590)
Maninae Apr 1, 2026
ac6db06
feat(whatsapp): add reaction guidance levels (#58622)
mcaxtr Apr 1, 2026
5836dde
test: fix amazon-bedrock extension test boundary (#58753)
jalehman Apr 1, 2026
e1d963e
fix: bound discord inbound media downloads (#58593) (thanks @aquaright1)
bobashopcashier Apr 1, 2026
26a891a
fix: preserve rewritten stream snapshots in webchat (#58641) (thanks …
neeravmakwana Apr 1, 2026
5f3737f
fix: auto-enable minimax plugin for API key auth route (#57127)
tars90percent Apr 1, 2026
c130eba
fix: verify linux gateway in parallels smoke
steipete Apr 1, 2026
25eaebb
test: drop duplicate telegram/discord command tests
steipete Apr 1, 2026
add54e1
test: trim low-signal matrix monitor tests
steipete Apr 1, 2026
709668c
test: trim line/twitch setup validations
steipete Apr 1, 2026
e441e8b
test: stabilize timed-heavy channel planner checks
steipete Apr 1, 2026
0350282
test: trim line webhook/slack setup prompts
steipete Apr 1, 2026
d9a2690
test: trim mattermost setup cases
steipete Apr 1, 2026
0a636ae
fix: catch per-stage errors in HTTP request pipeline to prevent casca…
yelog Apr 1, 2026
ffa1e5f
test: assert console.error in async-rejection stage test
yelog Apr 1, 2026
bd6c017
fix: skip failing gateway HTTP stages (#58746) (thanks @yelog)
steipete Apr 1, 2026
cad3da5
fix(memory): prefer --mask over --glob for qmd collection pattern fla…
GitZhangChi Apr 1, 2026
1b94e8c
feat: feishu comment event (#58497)
wittam-01 Apr 1, 2026
e643ba2
fix: preserve telegram topic routing in announce and delivery context
Mar 31, 2026
6776306
fix: preserve telegram topic delivery routing (#58489) (thanks @cwmine)
steipete Apr 1, 2026
622b91d
fix: queue model switches behind busy runs
steipete Apr 1, 2026
9ab3352
fix: avoid duplicate discord resolve logs
steipete Apr 1, 2026
340c99d
fix(status): filter stale task rows from status cards (#58810)
vincentkoc Apr 1, 2026
86b5198
refactor: consolidate cron delivery boundary parsing
steipete Apr 1, 2026
5a95d65
fix: restore bundled runtime dependency provisioning (#58782) (thanks…
obviyus Apr 1, 2026
cfa307b
fix(status): keep task snapshots pure
vincentkoc Apr 1, 2026
31ed09b
fix: run bundled deps postinstall for global npm
steipete Apr 1, 2026
802bdb0
refactor: move cron legacy delivery migration to doctor
steipete Apr 1, 2026
f5431bc
docs: clarify doctor cron migration guidance
steipete Apr 1, 2026
71f341c
docs: add /tasks chat command, cleanup-aware status, and QQ Bot troub…
vincentkoc Apr 1, 2026
7cf8ccf
fix: avoid startup gateway reload loop (#58678) (thanks @yelog)
steipete Apr 1, 2026
facdeb3
feat(tasks): add chat-native task board (#58828)
vincentkoc Apr 1, 2026
d4643e0
fix(line): resolve dist runtime contract path
vincentkoc Apr 1, 2026
edfac5f
docs(changelog): note line runtime packaging fix
vincentkoc Apr 1, 2026
95182d5
fix: harden bundled plugin runtime deps
steipete Apr 1, 2026
2d79c9c
docs: add WhatsApp reactionLevel and Feishu Drive comment actions
vincentkoc Apr 1, 2026
19d0c2d
refactor: remove cron legacy delivery from runtime
steipete Apr 1, 2026
2bc8a0d
refactor: add doctor cron migration helpers
steipete Apr 1, 2026
59c23de
refactor(anthropic): move stream wrappers into plugin
steipete Apr 1, 2026
32f392e
refactor(core): drop old anthropic stream wrapper file
steipete Apr 1, 2026
2b67f96
docs(anthropic): note oauth context1m fallback
steipete Apr 1, 2026
10750fb
Cron: avoid busy-wait drift for recurring main jobs (#58872)
scoootscooob Apr 1, 2026
1ce410a
fix(sandbox): use browser image for browser runtime matching (#58759)
kybrcore Apr 1, 2026
8fce663
fix(subagents): harden task-registry lifecycle writes (#58869)
vincentkoc Apr 1, 2026
4fa1163
fix: escalate to model fallback after rate-limit profile rotation cap…
Forgely3D Apr 1, 2026
63da2c7
fix(exec): resume agent session after approval completion
Nanako0129 Apr 1, 2026
7f53c1c
test(exec): cover delayed Discord approval continuation
Nanako0129 Apr 1, 2026
4590ac3
fix: note exec approval continuation in changelog (#58860) (thanks @N…
steipete Apr 1, 2026
db0cea5
refactor(gateway): extract node pairing reconciliation
steipete Apr 1, 2026
4ceb01f
docs(gateway): document node pairing repair flow
steipete Apr 1, 2026
2d53ffd
fix(exec): resolve remote approval regressions (#58792)
vincentkoc Apr 1, 2026
fb28b02
fix: preserve bundled channel plugin compat (#58873)
obviyus Apr 1, 2026
3b1f8e3
fix: strip inbound metadata before slash command detection (#58674)
Mlightsnow Apr 1, 2026
f559ea1
fix: land slash command metadata parsing (#58725) (thanks @Mlightsnow)
steipete Apr 1, 2026
92f1772
test: allow boundary test on main
steipete Apr 1, 2026
d005cc8
test: align cron abort regression with #58833
steipete Apr 1, 2026
fe57ee5
test: drop stale task boundary allowlist entries
steipete Apr 1, 2026
f6317fb
fix(gateway): stop pinning node commands to pairing state
steipete Apr 1, 2026
29784af
style(gateway): normalize node reconnect formatting
steipete Apr 1, 2026
8b2d24b
docs(security): clarify node pairing trust boundary
steipete Apr 1, 2026
07c60ae
fix(agent): treat webchat exec approvals as native UI (#58904)
vincentkoc Apr 1, 2026
72af92b
qqbot: require explicit allowlist for /bot-logs to prevent info discl…
vincentkoc Apr 1, 2026
fbe3ca4
fix(plugins): pass dangerouslyForceUnsafeInstall through archive and …
ryanlee-gemini Apr 1, 2026
4e63dc0
fix: hide raw provider errors from chat replies
ImLukeF Apr 1, 2026
101c31f
test: harden ci-sensitive unit suites
ImLukeF Apr 1, 2026
78b4873
test: restore fetch stubs in embedding suites
ImLukeF Apr 1, 2026
b2bb129
docs(changelog): note chat error fallback fix
ImLukeF Apr 1, 2026
1654c3a
feat(gateway): make chat history max chars configurable (#58900)
ImLukeF Apr 1, 2026
d766bfc
fix(memory): preserve session indexing during full reindex (#39732)
upupc Apr 1, 2026
f1595f5
fix(ci): allow plugin npm preview without publish token (#58929)
vincentkoc Apr 1, 2026
5c8d9da
docs: add SearXNG web search provider page and navigation
vincentkoc Apr 1, 2026
3f67581
fix: retry safe wrapped Telegram send failures (#51895) (thanks @chin…
chinar-amrutkar Apr 1, 2026
32ae841
feat(web-search): add SearXNG as bundled web search provider plugin (…
cgdusek Apr 1, 2026
00a49fe
docs: add gateway.webchat.chatHistoryMaxChars config reference
vincentkoc Apr 1, 2026
c65e152
fix: preserve anthropic thinking replay (#58916)
obviyus Apr 1, 2026
c7510e0
fix(hooks): skip full gate for docs-only commits
vincentkoc Apr 1, 2026
f70ad92
fix: align cache-ttl pruning with thinking replay sanitization
obviyus Apr 1, 2026
ef28698
test: fix context pruning runtime fixtures
obviyus Apr 1, 2026
a23877b
Merge remote-tracking branch 'upstream/main' into sync/upstream-2026-…
linfangw Apr 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
17 changes: 15 additions & 2 deletions .agents/skills/openclaw-parallels-smoke/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,13 @@ Use this skill for Parallels guest workflows and smoke interpretation. Do not lo
- Pass `--json` for machine-readable summaries.
- Per-phase logs land under `/tmp/openclaw-parallels-*`.
- Do not run local and gateway agent turns in parallel on the same fresh workspace or session.
- If `main` is moving under active multi-agent work, prefer a detached worktree pinned to one commit for long Parallels suites. The smoke scripts now verify the packed tgz commit instead of live `git rev-parse HEAD`, but a pinned worktree still avoids noisy rebuild/version drift during reruns.
- For `prlctl exec`, pass the VM name before `--current-user` (`prlctl exec "$VM" --current-user ...`), not the other way around.
- If the workflow installs OpenClaw from a repo checkout instead of the site installer/npm release, finish by installing a real guest CLI shim and verifying it in a fresh guest shell. `pnpm openclaw ...` inside the repo is not enough for handoff parity.
- On macOS guests, prefer a user-global install plus a stable PATH-visible shim:
- install with `NPM_CONFIG_PREFIX="$HOME/.npm-global" npm install -g .`
- make sure `~/.local/bin/openclaw` exists or `~/.npm-global/bin` is on PATH
- verify from a brand-new guest shell with `which openclaw` and `openclaw --version`

## npm install then update

Expand All @@ -27,6 +33,8 @@ Use this skill for Parallels guest workflows and smoke interpretation. Do not lo
- On Windows same-guest update checks, restart the gateway after the npm upgrade before `gateway status` / `agent`; in-place global npm updates can otherwise leave stale hashed `dist/*` module imports alive in the running service.
- For Windows same-guest update checks, prefer the done-file/log-drain PowerShell runner pattern over one long-lived `prlctl exec ... powershell -EncodedCommand ...` transport. The guest can finish successfully while the outer `prlctl exec` still hangs.
- Linux same-guest update verification should also export `HOME=/root`, pass `OPENAI_API_KEY` via `prlctl exec ... /usr/bin/env`, and use `openclaw agent --local`; the fresh Linux baseline does not rely on persisted gateway credentials.
- The npm-update wrapper now prints per-lane progress from the nested log files. If a lane still looks stuck, inspect the nested logs in `runDir` first (`macos-fresh.log`, `windows-fresh.log`, `linux-fresh.log`, `macos-update.log`, `windows-update.log`, `linux-update.log`) instead of assuming the outer wrapper hung.
- If the wrapper fails a lane, read the auto-dumped tail first, then the full nested lane log under `/tmp/openclaw-parallels-npm-update.*`.

## CLI invocation footgun

Expand All @@ -38,8 +46,10 @@ Use this skill for Parallels guest workflows and smoke interpretation. Do not lo
- Default to the snapshot closest to `macOS 26.3.1 latest`.
- On Peter's Tahoe VM, `fresh-latest-march-2026` can hang in `prlctl snapshot-switch`; if restore times out there, rerun with `--snapshot-hint 'macOS 26.3.1 latest'` before blaming auth or the harness.
- The macOS smoke should include a dashboard load phase after gateway health: resolve the tokenized URL with `openclaw dashboard --no-open`, verify the served HTML contains the Control UI title/root shell, then open Safari and require an established localhost TCP connection from Safari to the gateway port.
- If a packaged install regresses with `500` on `/`, `/healthz`, or `__openclaw/control-ui-config.json` after `fresh.install-main` or `upgrade.install-main`, suspect bundled plugin runtime deps resolving from the package root `node_modules` rather than `dist/extensions/*/node_modules`. Repro quickly with a real `npm pack`/global install lane before blaming dashboard auth or Safari.
- `prlctl exec` is fine for deterministic repo commands, but use the guest Terminal or `prlctl enter` when installer parity or shell-sensitive behavior matters.
- Multi-word `openclaw agent --message ...` checks should go through a guest shell wrapper (`guest_current_user_sh` / `guest_current_user_cli` or `/bin/sh -lc ...`), not raw `prlctl exec ... node openclaw.mjs ...`, or the message can be split into extra argv tokens and Commander reports `too many arguments for 'agent'`.
- When ref-mode onboarding stores `OPENAI_API_KEY` as an env secret ref, the post-onboard agent verification should also export `OPENAI_API_KEY` for the guest command. The gateway can still reject with pairing-required and fall back to embedded execution, and that fallback needs the env-backed credential available in the shell.
- On the fresh Tahoe snapshot, `brew` exists but `node` may be missing from PATH in noninteractive exec. Use `/opt/homebrew/bin/node` when needed.
- Fresh host-served tgz installs should install as guest root with `HOME=/var/root`, then run onboarding as the desktop user via `prlctl exec --current-user`.
- Root-installed tgz smoke can log plugin blocks for world-writable `extensions/*`; do not treat that as an onboarding or gateway failure unless plugin loading is the task.
Expand All @@ -54,6 +64,9 @@ Use this skill for Parallels guest workflows and smoke interpretation. Do not lo
- Multi-word `openclaw agent --message ...` checks should call `& $openclaw ...` inside PowerShell, not `Start-Process ... -ArgumentList` against `openclaw.cmd`, or Commander can see split argv and throw `too many arguments for 'agent'`.
- Windows installer/tgz phases now retry once after guest-ready recheck; keep new Windows smoke steps idempotent so a transport-flake retry is safe.
- Windows global `npm install -g` phases can stay quiet for a minute or more even when healthy; inspect the phase log before calling it hung, and only treat it as a regression once the retry wrapper or timeout trips.
- Fresh Windows ref-mode onboard should use the same background PowerShell runner plus done-file/log-drain pattern as the npm-update helper, including startup materialization checks, host-side timeouts on short poll `prlctl exec` calls, and retry-on-poll-failure behavior for transient transport flakes.
- Fresh Windows ref-mode agent verification should set `OPENAI_API_KEY` in the PowerShell environment before invoking `openclaw.cmd agent`, for the same pairing-required fallback reason as macOS.
- The Windows upgrade smoke lane should restart the managed gateway after `upgrade.install-main` and before `upgrade.onboard-ref`, or the old process can keep the previous gateway token and fail `gateway-health` with `unauthorized: gateway token mismatch`.
- Keep onboarding and status output ASCII-clean in logs; fancy punctuation becomes mojibake in current capture paths.
- If you hit an older run with `rc=255` plus an empty `fresh.install-main.log` or `upgrade.install-main.log`, treat it as a likely `prlctl exec` transport drop after guest start-up, not immediate proof of an npm/package failure.

Expand All @@ -66,8 +79,8 @@ Use this skill for Parallels guest workflows and smoke interpretation. Do not lo
- Fresh snapshots may be missing `curl`, and `apt-get update` can fail on clock skew. Bootstrap with `apt-get -o Acquire::Check-Date=false update` and install `curl ca-certificates`.
- Fresh `main` tgz smoke still needs the latest-release installer first because the snapshot has no Node or npm before bootstrap.
- This snapshot does not have a usable `systemd --user` session; managed daemon install is unsupported.
- `prlctl exec` reaps detached Linux child processes on this snapshot, so detached background gateway runs are not trustworthy smoke signals.
- Treat `gateway=skipped-no-detached-linux-gateway` plus `daemon=systemd-user-unavailable` as baseline on that Linux lane, not a regression.
- The Linux smoke now falls back to a manual `setsid openclaw gateway run --bind loopback --port 18789 --force` launch with `HOME=/root` and the provider secret exported, then verifies `gateway status --deep --require-rpc` when available.
- If Linux gateway bring-up fails, inspect `/tmp/openclaw-parallels-linux-gateway.log` in the guest phase logs first; the common failure mode is a missing provider secret in the launched gateway environment.

## Discord roundtrip

Expand Down
34 changes: 22 additions & 12 deletions .agents/skills/openclaw-release-maintainer/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Use this skill for release and publish-time workflow. Keep ordinary development

## Keep release channel naming aligned

- `stable`: tagged releases only, with npm dist-tag `latest`
- `stable`: tagged releases only, published to npm `latest` and then mirrored onto npm `beta` unless `beta` already points at a newer prerelease
- `beta`: prerelease tags like `vYYYY.M.D-beta.N`, with npm dist-tag `beta`
- Prefer `-beta.N`; do not mint new `-1` or `-2` beta suffixes
- `dev`: moving head on `main`
Expand Down Expand Up @@ -64,7 +64,8 @@ Use this skill for release and publish-time workflow. Keep ordinary development
Before tagging or publishing, run:

```bash
node --import tsx scripts/release-check.ts
pnpm build
pnpm ui:build
pnpm release:check
pnpm test:install:smoke
```
Expand Down Expand Up @@ -92,7 +93,7 @@ node --import tsx scripts/openclaw-npm-postpublish-verify.ts <published-version>
- Default release checks:
- `pnpm check`
- `pnpm build`
- `node --import tsx scripts/release-check.ts`
- `pnpm ui:build`
- `pnpm release:check`
- `OPENCLAW_INSTALL_SMOKE_SKIP_NONROOT=1 pnpm test:install:smoke`
- Check all release-related build surfaces touched by the release, not only the npm package.
Expand All @@ -119,6 +120,8 @@ node --import tsx scripts/openclaw-npm-postpublish-verify.ts <published-version>
- The npm workflow and the private mac publish workflow accept
`preflight_only=true` to run validation/build/package steps without uploading
public release assets.
- Both workflows also accept a prior successful preflight run id so a real
publish can promote the prepared artifacts without rebuilding them again.
- The private mac workflow also accepts `smoke_test_only=true` for branch-safe
workflow smoke tests that use ad-hoc signing, skip notarization, skip shared
appcast generation, and do not prove release readiness.
Expand Down Expand Up @@ -206,31 +209,38 @@ node --import tsx scripts/openclaw-npm-postpublish-verify.ts <published-version>
7. Create and push the git tag.
8. Create or refresh the matching GitHub release.
9. Start `.github/workflows/openclaw-npm-release.yml` with `preflight_only=true`
and wait for it to pass.
and wait for it to pass. Save that run id if you want the real publish to
reuse the prepared npm tarball.
10. Start `.github/workflows/macos-release.yml` in `openclaw/openclaw` and wait
for the public validation-only run to pass.
11. Start
`openclaw/releases-private/.github/workflows/openclaw-macos-publish.yml`
with `preflight_only=true` and wait for it to pass.
with `preflight_only=true` and wait for it to pass. Save that run id if you
want the real publish to reuse the notarized mac artifacts.
12. If any preflight or validation run fails, fix the issue on a new commit,
delete the tag and matching GitHub release, recreate them from the fixed
commit, and rerun all relevant preflights from scratch before continuing.
Never reuse old preflight results after the commit changes.
13. Start `.github/workflows/openclaw-npm-release.yml` with the same tag for
the real publish.
14. Wait for `npm-release` approval from `@openclaw/openclaw-release-managers`.
15. Start
the real publish. When the preflight run id is available, pass it via
`preflight_run_id` to skip the second npm rebuild.
14. Start the real private mac publish with the same tag. When the private
preflight run id is available, pass it via `preflight_run_id` to skip the
second mac build/sign/notarize cycle and promote those prepared artifacts
directly to the public release.
15. Wait for `npm-release` approval from `@openclaw/openclaw-release-managers`.
16. Start
`openclaw/releases-private/.github/workflows/openclaw-macos-publish.yml`
for the real publish and wait for success.
16. Verify the successful real private mac run uploaded the `.zip`, `.dmg`,
17. Verify the successful real private mac run uploaded the `.zip`, `.dmg`,
and `.dSYM.zip` artifacts to the existing GitHub release in
`openclaw/openclaw`.
17. For stable releases, download `macos-appcast-<tag>` from the successful
18. For stable releases, download `macos-appcast-<tag>` from the successful
private mac run, update `appcast.xml` on `main`, and verify the feed.
18. For beta releases, publish the mac assets but expect no shared production
19. For beta releases, publish the mac assets but expect no shared production
`appcast.xml` artifact and do not update the shared production feed unless a
separate beta feed exists.
19. After publish, verify npm and the attached release artifacts.
20. After publish, verify npm and the attached release artifacts.

## GHSA advisory work

Expand Down
28 changes: 16 additions & 12 deletions .agents/skills/openclaw-test-heap-leaks/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,11 @@
---
name: openclaw-test-heap-leaks
description: Investigate `pnpm test` memory growth, Vitest worker OOMs, and suspicious RSS increases in OpenClaw using the `scripts/test-parallel.mjs` heap snapshot tooling. Use when Codex needs to reproduce test-lane memory growth, collect repeated `.heapsnapshot` files, compare snapshots from the same worker PID, distinguish transformed-module retention from real data leaks, and fix or reduce the impact by patching cleanup logic or isolating hotspot tests.
description: Investigate `pnpm test` memory growth, Vitest worker OOMs, and suspicious RSS increases in OpenClaw using the `scripts/test-parallel.mjs` heap snapshot tooling. Use when Codex needs to reproduce test-lane memory growth, collect repeated `.heapsnapshot` files, compare snapshots from the same worker PID, triage likely transformed-module retention versus likely runtime leaks, and fix or reduce the impact by patching cleanup logic or isolating hotspot tests.
---

# OpenClaw Test Heap Leaks

Use this skill for test-memory investigations. Do not guess from RSS alone when heap snapshots are available.
Use this skill for test-memory investigations. Do not guess from RSS alone when heap snapshots are available. Treat snapshot-name deltas as triage evidence, not proof, until retainers or dominators support the call.

## Workflow

Expand All @@ -14,19 +14,23 @@ Use this skill for test-memory investigations. Do not guess from RSS alone when
- `pnpm canvas:a2ui:bundle && OPENCLAW_TEST_MEMORY_TRACE=1 OPENCLAW_TEST_HEAPSNAPSHOT_INTERVAL_MS=60000 OPENCLAW_TEST_HEAPSNAPSHOT_DIR=.tmp/heapsnap OPENCLAW_TEST_WORKERS=2 OPENCLAW_TEST_MAX_OLD_SPACE_SIZE_MB=6144 pnpm test`
- Keep `OPENCLAW_TEST_MEMORY_TRACE=1` enabled so the wrapper prints per-file RSS summaries alongside the snapshots.
- If the report is about a specific shard or worker budget, preserve that shape.
- Before you analyze snapshots, identify the real lane names from `[test-parallel] start ...` lines or `pnpm test --plan`. Do not assume a single `unit-fast` lane; local plans often split into `unit-fast-batch-*`.

2. Wait for repeated snapshots before concluding anything.
- Take at least two intervals from the same lane.
- Compare snapshots from the same PID inside one lane directory such as `.tmp/heapsnap/unit-fast/`.
- Use `scripts/heapsnapshot-delta.mjs` to compare either two files directly or the earliest/latest pair per PID in one lane directory.
- Compare snapshots from the same PID inside the real lane directory such as `.tmp/heapsnap/unit-fast-batch-2/`.
- Use `.agents/skills/openclaw-test-heap-leaks/scripts/heapsnapshot-delta.mjs` to compare either two files directly or the earliest/latest pair per PID in one lane directory.
- If the helper suggests transformed-module retention, confirm the top entries in DevTools retainers/dominators before calling it solved.

3. Classify the growth before choosing a fix.
- If growth is dominated by Vite/Vitest transformed source strings, `Module`, `system / Context`, bytecode, descriptor arrays, or property maps, treat it as retained module graph growth in long-lived workers.
- If growth is dominated by Vite/Vitest transformed source strings, `Module`, `system / Context`, bytecode, descriptor arrays, or property maps, treat it as likely retained module graph growth in long-lived workers.
- If growth is dominated by app objects, caches, buffers, server handles, timers, mock state, sqlite state, or similar runtime objects, treat it as a likely cleanup or lifecycle leak.
- If the names are ambiguous, stop short of a confident label and inspect retainers/dominators in DevTools for the top deltas.

4. Fix the right layer.
- For retained transformed-module growth in shared workers:
- Move hotspot files out of `unit-fast` by updating `test/fixtures/test-parallel.behavior.json`.
- For likely retained transformed-module growth in shared workers:
- Prefer timing and hotspot-driven scheduling fixes first. Check whether the file is already represented in `test/fixtures/test-timings.unit.json` and whether `scripts/test-update-memory-hotspots.mjs` should refresh the measured hotspot manifest before hand-editing behavior overrides.
- Move hotspot files out of the real shared lane by updating `test/fixtures/test-parallel.behavior.json` only when timing-driven peeling is insufficient.
- Prefer `singletonIsolated` for files that are safe alone but inflate shared worker heaps.
- If the file should already have been peeled out by timings but is absent from `test/fixtures/test-timings.unit.json`, call that out explicitly. Missing timings are a scheduling blind spot.
- For real leaks:
Expand All @@ -40,24 +44,24 @@ Use this skill for test-memory investigations. Do not guess from RSS alone when

## Heuristics

- Do not call everything a leak. In this repo, large `unit-fast` growth can be a worker-lifetime problem rather than an application object leak.
- Do not call everything a leak. In this repo, large `unit-fast` or `unit-fast-batch-*` growth can be a worker-lifetime problem rather than an application object leak.
- `scripts/test-parallel.mjs` and `scripts/test-parallel-memory.mjs` are the primary control points for wrapper diagnostics.
- The lane names printed by `[test-parallel] start ...` and `[test-parallel][mem] summary ...` tell you where to focus.
- When one or two files account for most of the delta and they are missing from timings, reducing impact by isolating them is usually the first pragmatic fix.
- When the same retained object families grow across multiple intervals in the same worker PID, trust the snapshots over intuition.
- When the same retained object families grow across multiple intervals in the same worker PID, trust the snapshots over intuition, then confirm ambiguous calls with retainer evidence.

## Snapshot Comparison

- Direct comparison:
- `node .agents/skills/openclaw-test-heap-leaks/scripts/heapsnapshot-delta.mjs before.heapsnapshot after.heapsnapshot`
- Auto-select earliest/latest snapshots per PID within one lane:
- `node .agents/skills/openclaw-test-heap-leaks/scripts/heapsnapshot-delta.mjs --lane-dir .tmp/heapsnap/unit-fast`
- `node .agents/skills/openclaw-test-heap-leaks/scripts/heapsnapshot-delta.mjs --lane-dir .tmp/heapsnap/unit-fast-batch-2`
- Useful flags:
- `--top 40`
- `--min-kb 32`
- `--pid 16133`

Read the top positive deltas first. Large positive growth in module-transform artifacts suggests lane isolation; large positive growth in runtime objects suggests a real leak.
Read the top positive deltas first. Large positive growth in module-transform artifacts suggests lane isolation; large positive growth in runtime objects suggests a real leak. If the names alone do not settle it, open the same snapshot pair in DevTools and inspect retainers/dominators for the top rows before declaring root cause.

## Output Expectations

Expand All @@ -66,6 +70,6 @@ When using this skill, report:
- The exact reproduce command.
- Which lane and PID were compared.
- The dominant retained object families from the snapshot delta.
- Whether the issue is a real leak or shared-worker retained module growth.
- Whether the issue is a likely real leak or likely shared-worker retained module growth, plus whether retainers/dominators confirmed it.
- The concrete fix or impact-reduction patch.
- What you verified, and what snapshot overhead prevented you from verifying.
Loading