On this page
On this page
Release notes
v2026.10.1
OpenClaw v2026.10.1
AI agents and tools can read these release notes as plain Markdown.
OpenClaw v2026.10.1 helps your agent find a relevant installed skill when a task needs it, without putting the whole skill library in the prompt. You can then work with compatible, opt-in MCP Apps beside chat, using supported forms and workspace files. To keep your setup recoverable, full backups can now live on external storage or Cloudflare R2 and restore into a fresh staging directory.
Editorial snapshot: These proposed notes cover the frozen review checkpoint, not final release coverage. The reviewed inventory contains 2,391 pull requests, 601 direct commits, and 358 contributors; it differs from the release branch’s complete contribution record. Final release reconciliation and publication review remain pending.
New and expanded features · Fixes and refinements
New and expanded features
Installed-skill discovery
Your agent can use installed-skill search to find a relevant skill when a task needs it, without loading the whole skill library into the conversation. This works in supported embedded agents, Code Mode and Codex sessions.
Searching instruction text follows the agent's current read permission and may cover only part of a file, so no match does not mean no suitable skill exists. The agent reads a selected skill's full instructions separately; that read grants no permission to install or run it.
Sources and complete change list
- Eligible installed skills remain discoverable when the prompt's size limit leaves them out of its skill list. Disabled skills and those unavailable for model use remain excluded. #158089. Thanks @vincentkoc and @eltonwf-del.
- Installed-skill search returns matching names and descriptions, while an exact-name read returns complete instructions or an explicit size error. New instruction reads support files up to 256 KiB. #158090. Thanks @vincentkoc, @eltonwf-del and @Jarvis-Baba.
- Embedded agents, Code Mode and Codex gain the installed-skill search and read tools. Codex reads use the correct workspace or delivered sandbox copy and return complete instructions or an error. #158091. Thanks @vincentkoc and @eltonwf-del.
- Search can find capabilities described inside skill instructions under the agent's current native read permission. Removing that permission also suppresses cached or in-progress instruction matches. #160538. Thanks @vincentkoc.
- Agents receive guidance to search for task-relevant skills even when their prompt contains no skill list. Simple conversation can skip discovery, and known skill names can be read directly. #162842. Thanks @vincentkoc.
- Exact capitalization takes priority when matching skill names, so a request for
Deploycan distinguish it fromdeploy. #162849. Thanks @vincentkoc. - Long local instruction files contribute their beginning to search instead of losing all instruction-text matches. Coverage remains partial, with up to 16 KiB per file within the total search budget. Words beyond that prefix are not matched. #162856. Thanks @vincentkoc.
- Discovery guidance also works when filtering leaves only notices or an empty skill list. Existing notices remain visible, and the guidance reflects the tools the agent is allowed to use. #162963. Thanks @vincentkoc.
- If selected instructions and supporting files exceed the combined 8 MiB limit, the agent receives an explanation to select fewer skills even when diagnostics are off. #164012. Thanks @vincentkoc.
MCP Apps with conversations and files
With MCP Apps enabled and a compatible server configured, you can work in an app beside chat and attach selected content to your next message. Supported apps can also view or edit workspace files and offer richer forms with previews and resource choices.
Messages and file opens show their approval controls in the app pane, with temporary approval available for repeated use of one app tool. File editors can overwrite a newer edit if they do not check for stale saves. Native Codex forms need a prompting approval policy.
Reference-app demo with sample workspace data, supplied in #161747.
App panels fill the available space in fullscreen and split layouts, and transparent apps that follow the host theme match light and dark dashboards. File views update after edits, and dashboard content reflects accepted board changes.
Changes and sources
- Open apps directly, use their settings, attach removable content, and view or edit advertised workspace-file formats. #161747. Thanks @steipete.
- File views follow appended or replaced files, consumed context clears without losing newer selections, and inactive panels explain how to restore interaction. #164277. Thanks @steipete.
- App messages, workspace file opens and confirmed board prompts use visible approval controls inside their pane. #164493. Thanks @steipete.
- Repeated calls to one app tool can share a temporary approval for the current view. #164496. Thanks @steipete.
- Tool and resource-template listings preserve server pagination tokens, including empty and whitespace-only tokens, to retrieve the correct next page. #164368. Thanks @ooiuuii, @obviyus.
- MCP session controls follow current metadata, withdrawn previews disappear, and access revoked during preparation returns an authorization error. #163548. Thanks @steipete.
- Transparent, theme-aware MCP Apps blend with the dashboard in light and dark modes; apps with their own opaque background retain it. #161494. Thanks @steipete.
- Dashboard, widget and MCP App reads follow previously accepted board writes, avoiding older widget revisions. A changed destination rejects the read instead of serving from its former location. #164448. Thanks @steipete.
- MCP Apps fill their dashboard panel again in fullscreen, resized and split layouts instead of shrinking above a blank gap. 11515ce. Thanks @steipete.
Backups on external storage
You can keep full backups on an external drive, mounted storage or Cloudflare R2 and restore them into a fresh staging directory before activation. Scheduled backups are opt-in, with optional retention that removes eligible older copies after a successful backup and keeps the newest one.
Choose a passphrase for encrypted uploads or explicitly choose none for plaintext. Destination names and markers stay visible, and --output keeps a plaintext local archive even when the upload is encrypted. Keep the passphrase, marker and namespace for recovery. Give running installations separate namespaces, and take over an existing one only after its previous owner stops. Restore settings, databases and credentials from one matching backup generation.
Follow the guides for initializing backup destinations, configuring storage locations and Cloudflare R2, and backup and restore.
Backup and storage controls also gain translated status and setup guidance in the existing locales.
Sources and complete change list
- Full backups support external storage and Cloudflare R2, optional schedules and retention, destination checks and restoration into fresh staging. #161913. Thanks @steipete.
- Full restore checks archive size plus a 256 MiB free-space reserve before extraction when destination capacity can be measured. #164492. Thanks @RomneyDa, @smoe.
- Restore guides explain extra extraction space and recovering configuration, databases and credentials from one matching backup generation. #164491. Thanks @RomneyDa.
- Backup and storage controls, status and provider or encryption guidance use the existing translated locales. #162578.
Code Mode working values
In interactive Code Mode, your agent can save small JSON results and reuse them in later cells, follow-up replies and after a restart. Only completed cells save their data, and ordinary cell variables still start fresh.
Overwriting or deleting a value leaves older versions in conversation history and exports. Saved values have size limits, while their accumulated history can grow beyond those limits. If saving reports a warning, check the transcript before assuming it succeeded. See the session store guide.
Sources and complete change list
- Save small JSON working values across interactive Code Mode cells, replies and restarts. Only completed cells save them; older versions remain in conversation history after overwrite or deletion. #164086. Thanks to @steipete.
- Wait for Code Mode workers when their Gateway or CLI host shuts down, while another live host retains its own reusable workers. The shutdown ordering applies after restart. #162141. Thanks to @steipete.
Conversation snooze
You can snooze an eligible conversation in the web Control UI to clear it from the Active sidebar while its work continues. Find it in Snoozed or All and wake it yourself, or let it return at the chosen time or earlier after interaction, completion or pinning. Archived, child and protected conversations are excluded.
Control UI demonstration with sample conversations, supplied in #161960.
Sources and complete change list
- Snooze hides eligible active web conversations until a chosen time while work continues. Snoozed and All views, Wake and Undo make them accessible; interaction, completion or pinning can wake them early. Native controls and archived, child or protected conversations are excluded. #161960. Thanks @steipete.
Bundled desktop setup
Fresh packaged Mac app setup can run OpenClaw through This Mac without installing Node or a separate CLI. It stops with the app by default. Enable Keep OpenClaw running when the app is closed to keep channels and automations running in the background; a paused Gateway stays paused.
Eligible older app-managed Node installations can move to the bundled runtime; independent installations and pinned runtimes keep their own setup. Save any settings held only in the service definition to profile configuration or .env before retrying a switch. Installs using the current bundled CLI refuse to overwrite a newer service or runtime choice; inspect it before retrying. See the bundled Gateway guide.
Fresh Linux companion setups also use bundled Bun. Existing installations switch only when you confirm Use bundled runtime… in the tray, with the Gateway running first. A failed switch needs manual recovery, with no automatic rollback. See Linux runtime adoption and Bun compatibility, including how to return to Node.
Mac setup demonstration with sample state, supplied in #161779 by @steipete.
Sources and complete change list
- App-owned Mac update and repair actions use the app updater, and hosted processes shut down when their app connection is lost. #161583. Thanks to @steipete.
- The Mac private worker and browser setup use bundled Bun and SQLite support without separate Node or Homebrew SQLite. See Mac app signing. #161603. Thanks to @steipete.
- Fresh This Mac setup starts the included Gateway for the app lifetime, while eligible existing installations retain their ownership. #161709. Thanks to @steipete.
- The Mac startup dependency-target mismatch is corrected while the macOS 15 minimum remains. #161754. Thanks to @steipete, @coygeek.
- Mac app-managed hosting gains the app-closed background toggle and eligible Node migration and paused-service recovery. #161779. Thanks to @steipete.
- An earlier bundled Mac runtime update improves compatibility when copying large files. #161825. Thanks to @steipete, @hannesrudolph.
- The Mac x64 worker avoids a native process-reader startup crash under Rosetta. #161876. Thanks to @steipete.
- An earlier bundled Mac runtime update fixes worker environment handling, canceled requests, default certificates and local file paths. #162570. Thanks to @steipete.
- An earlier bundled Mac runtime update fixes streams retaining their parent process and adds module-loading and process-callback compatibility. #163081. Thanks to @steipete.
- The bundled Mac runtime sequence improves individual-file change, replacement and deletion notifications, plus pipe and module compatibility. Recursive directory watches retain host-dependent delays. #163170. Thanks to @steipete.
- An earlier bundled Mac runtime update fixes output shutdown, worker messaging, preload ordering and canceled network requests. #163687. Thanks to @steipete.
- The bundled Mac runtime sequence fixes affected package loading for hook-using plugins and tools; the hook-free hosted Gateway was unaffected. #163831. Thanks to @steipete.
- Remote or unconfigured Mac profiles without a local service avoid false uninstall failures. A loaded service whose definition was removed outside the app is not stopped by this path. #164069. Thanks to @steipete.
- The bundled Mac runtime sequence includes equivalent-path module crash fixes, filesystem defaults and package validation. #164121. Thanks to @steipete.
- Linux fresh setup uses bundled Bun, with a confirmed tray switch for eligible running Gateways, preserved runtime choices and manual recovery on failure. #164401. Thanks to @steipete.
- The final shared desktop Bun version
1.4.3-canary.1+c999d9cb9includes plugin-file and symlink resolution, concurrent module lookup, child-process messaging and stack-format fixes. #164606. Thanks to @steipete. - Mac installs through the current bundled CLI preserve newer service or runtime choices and require inspection after refusal instead of automatic recovery. #164616. Thanks to @steipete.
- Mac Gateway setup, preparation and update-error guidance gains translations. #162265.
- Mac background hosting, update, migration and retry guidance gains translations. #162834.
Model discovery and live catalog updates
Model choices and prices can update without restarting OpenClaw, at a catalog check or after an explicit model-list refresh. Work already underway keeps its original model information and prices. If a downloaded catalog contains incorrect choices or prices, disable remote catalog refresh until a corrected newer catalog is available.
OpenAI API-key users can select supported chat models their account lists before those models reach the bundled catalog. These entries use conservative, text-only limits, and an omitted cost means the price is unknown. Model-list fixes also reduce repeated preparation and duplicated data, keep DeepInfra discovery working with unexpected metadata, and prevent overflowing Vercel prices from appearing as infinite costs.
Sources
- Refresh model lists while unused Anthropic credentials remain saved — Thanks serg0x, RomneyDa, yoyo837.
- Adopt downloaded model choices and prices without restarting the Gateway — Thanks obviyus.
- Prepare model catalogs without blocking database reads and keep selected credential sources isolated — Thanks steipete.
- Keep DeepInfra live model discovery when metadata contains unexpected or repeated tags — Thanks steipete.
- Avoid repeated model-picker preparation when clients reconnect — Thanks steipete.
- Let canceled model-list requests finish while discovery continues for other callers — Thanks vincentkoc.
- Discover supported OpenAI API-key account chat models absent from the bundled catalog — Thanks obviyus.
- Use fallback catalog prices when Vercel live rates overflow — Thanks steipete.
- Retain less duplicated data in the model-catalog worker — Thanks steipete.
- Avoid activating every native agent integration just to build a model catalog — Thanks RomneyDa.
- Reduce memory used while building model catalogs — Thanks RomneyDa.
Workboard conversations and navigation
The optional Workboard plugin lets you organize conversations on Sessions boards using run status, rules and persistent pins. Personal filters focus on conversations involving you or a chosen person without changing anyone else's view. Nested sidebar links make boards easier to reach, and the Board agent can help reshape a board when asked.
Rules and pins now determine placement, replacing model classification and its instructions and Refresh control. Use rules for any placement you previously described in column text. Large boards can open while optional PR details arrive in the background; a board-only view needs a session or PR-watcher event to refresh. Deleting a Sessions board keeps its conversations and Board agent conversation.
Workboard KV data from before July 2026 needs an intermediate upgrade. Run doctor --fix on OpenClaw 2026.9.7 before upgrading, following the older-data recovery instructions. Current Doctor preserves that data and warns instead of importing it. If you roll back, older releases show Sessions boards as empty Cards boards; cards added there are rejected when you return.
Changes and sources
- Sessions boards combine current conversation status with placement rules and persistent pins, including active or failed runs without an observer health summary. #161958, #163761, #163823. Thanks @steipete.
- Everyone, Involving me and person filters keep your board focus local to your browser and device. #162283. Thanks @steipete.
- Nested board links and removable, reorderable sidebar pins make boards easier to reach. #164604. Thanks @steipete.
- Sessions-board requests share prepared facts and concurrent refresh work, with missing PR details filled through background updates. #164218. Thanks @steipete.
- Repeated reads of unchanged cards share server work, and committed changes invalidate the saved result. #164301. Thanks @steipete.
- Saving proof, artifacts and worker logs avoids repeated card reads and database preparation. #164120. Thanks @steipete.
- A rejected attachment is deleted once, preserving the original metadata-limit error. #162805. Thanks @steipete.
- Older Workboard KV records require the intermediate Doctor migration, while malformed Quick Chat widget URLs are rejected without a panic. #163713. Thanks @steipete.
Bun-only installation
Supported Bun-only installations on macOS and Linux can run the ordinary openclaw command without Node. Use the documented Bun 1.4 or newer launcher and keep the command on your PATH; reinstalling or approving its repair with doctor --fix refreshes it. Older installed updaters still need a supported upgrade route.
Bun now reports useful Codex startup errors and lets valid messages follow a malformed one. Native dependency repair keeps existing packages and warns when it cannot repair them. Large computer-control screenshots and piped MCP responses avoid the affected output failures, and affected macOS builds leave intended background processes running after command output ends.
Sources and complete change list
- First install on a Bun-only machine skips Node checks when Node is absent or unusable. This still requires the supported explicit Bun 1.4 or newer launcher, and older published updaters do not gain Bun-only update support retroactively. #161512, thanks to @steipete.
- Eligible trusted Bun-only global installs on macOS and Linux can run plain
openclawwithout Node using the selected Bun executable. The OpenClaw command still needs to be on your PATH. Reinstall to refresh the launcher, or invoke the installed entry through Bun and usedoctor --fixto approve its repair. #162541, thanks to @steipete. - Bun native-dependency repair preserves existing packages and warns when a repair is unavailable. Codex startup retains useful missing-file, permission and architecture errors, while malformed JSON produces a redacted warning and no longer blocks later valid messages. #162559, thanks to @steipete.
- Preserve large computer-control and MCP responses under Bun on Linux and macOS, while retaining process cleanup. #163456 Thanks @steipete.
- Affected Bun builds on macOS leave intended background descendants running after command output completes. Thanks to @steipete.
Resumable worker installation
Interrupted worker downloads can resume within the same installation attempt and are checked before use. Cloud setup keeps retrying while bytes arrive, and pairing can finish after a download passes ten minutes while enrollment remains active. Recovery still stops after repeated failures without progress or when its deadline expires.
Update saved scripts to use the revised cloud-worker setup example, which handles first-boot package locks and the Node version selected by nvm. The installation guide and troubleshooting guidance cover remaining prerequisites. Previously issued pairing credentials can gain a longer lifetime after upgrading; keep them private, and do not rely on closing enrollment alone to revoke existing approvals or bound credentials.
Sources and complete change list
- Cloud-worker pairing can complete after downloads exceed ten minutes while enrollment is still active. The ten-minute lifetime of generic setup tokens is unchanged. #161552, thanks to @steipete.
- Cloud bootstrap retries continue while the download gains bytes, avoiding an early stop after several interruptions that still made progress. Three consecutive transient failures with no progress end the attempt, and the existing overall deadlines still apply. #162408, thanks to @steipete and @vincentkoc.
- Preparing and checking cloud-node packages no longer holds up the Gateway's main thread, so it can handle other work during that step. #163446, thanks to @steipete.
- Interrupted worker-bundle downloads resume from bytes retained during the same installation, then check the complete size and hash before use. Three consecutive failures with no progress stop the attempt, and cancellation or failure removes the temporary download. #164114, thanks to @steipete.
- The revised Debian and Ubuntu cloud setup example waits for first-boot initialization when Node needs installation and gives package-manager locks up to ten minutes to clear. Existing saved setup profiles need the revised script. #164133, thanks to @steipete.
- The revised cloud setup example repairs the Node version selected by nvm and reports its path and version. Update saved scripts to use it. If prerequisites remain missing, check GitHub CLI installation as well.. Thanks to @steipete.
Smaller npm installations
npm installations use less disk by excluding native binaries for unrelated platforms and avoid the update failures those extra files caused. Worker support stays included, and Docker installation gains the missing package-preparation files. See the package installation details.
Already oversized installations keep their extra files. If an older updater refuses the package, use a supported manual reinstall route.
Sources and complete change list
- npm packages bundle worker files in an archive so their file count no longer trips the updater's entry limit, while retaining worker support. #163985, thanks to @RomneyDa.
- npm installs filter optional native packages by platform, reducing the disk used by unrelated binaries. Existing oversized installations are not automatically pruned, and an older updater that rejects the package may require a supported manual reinstall. #165997, thanks to @steipete, @tommyfive and @kenmege.
- Published packages now include the generator and helper files needed by the prepare hook, fixing a package-integrity failure during Docker seed installation. 98421de, thanks to @steipete.
Browser images in workspace-only sessions
Agents in workspace-only host sessions can inspect screenshots, staged attachments and generated images in the Gateway media store, including images saved outside their workspace.
This store is shared across sessions. On a multi-user Gateway, an agent with the exact path can also read another session's media there. Other directory restrictions remain, and sandboxed tools gain no host-filesystem access.
Sources and complete change list
Conversation search and Online views
You can find conversation titles despite differences in punctuation or spacing, and search messages before finishing the last word. Earlier query words still need to be complete. Results show formatted previews and highlight matching URLs while keeping links and images passive.
The Online sidebar lets you focus on people with running work and sort by presence, running work, open-chat count or name. These choices are temporary, and counts cover accessible open chats.
Sources and complete change list
- Message-search previews show basic inline formatting and highlighted URL matches while keeping links and images passive. #162279. Thanks @steipete.
- Conversation-title search normalizes punctuation and spacing, and message search supports a prefix in the final query term. Earlier message terms still need complete words. #162517. Thanks @steipete.
- Online offers All and Running filters, plus presence, running-count, open-chat-count and name sorting. Counts cover accessible open chats rather than lifetime history. #163664. Thanks @steipete, @Patrick-Erichsen, @vyctorbrzezowski and @jesse-merhi.
Chat during connection loss
You can keep reading cached conversations, editing drafts and queuing messages during connection loss. A prepared browser can reopen Chat and New Session when it reports that it is offline, but sending waits for account revalidation. Loaded widgets keep their local state through a temporary disconnect; a full reload discards it.
Anyone with access to that browser profile can read its cached conversations and drafts. Older unowned drafts and queues require recovery review and never send automatically. Clearing site data can remove saved copies, and rolling back to an older UI can make new queues unreadable. See offline and reconnect guidance.
Sources and complete change list
- Cached conversation content, drafts and queues remain usable during connection loss. Prepared Chat and New Session pages can reopen when the browser is explicitly offline, with completed cache and retained access information. Uncertain sends wait for receipt checks and recovery review; cached data remains readable to anyone who can use that browser profile. #162428. Thanks @steipete.
- Eligible cached conversation routes can display before Gateway reconnect finishes. Missing or ambiguous cached routing still waits for live verification. #162794. Thanks @steipete.
- Send waits during account recovery while the draft remains editable. It becomes available after account recovery even if ordinary history is still loading, and never sends the held draft automatically. #161695. Thanks @steipete.
- After a reconnect or profile change, the Control UI preserves the conversation lists and chat-startup information saved by the new connection. 943286f. Thanks @steipete.
Saved drafts and message recovery
Sidebar pencil markers help you find saved drafts after reload or in a fresh tab, including attachments, replies and goals. Queued messages show an image preview, and their attachments leave the composer without clearing newer input. Incognito is excluded; without browser storage, drafts stay only in the current tab, and changes do not sync live to already-open tabs.
Draft and Unsent rows show previews with Restore and Delete controls, while confirmed delivery clears saved queue copies. Restore moves input into an empty eligible chat without sending it. If a message may already have been sent, check its original conversation first. Deleting a recovery copy removes its saved files and leaves sent history intact.
Sources and complete change list
- Saved-draft pencil markers include text, attachments, replies and goals after reload or a fresh tab. Incognito is excluded, and unavailable browser storage falls back to the current tab. #162049. Thanks @steipete.
- Saved recovery shows meaningful previews, attachment and message counts, and a source conversation when known. Restoration moves the saved input into an empty eligible chat without sending; uncertain delivery remains paused for checking in the original chat. Confirmed deletion removes the displayed saved copies and files, not sent history. #163717. Thanks @fuller-stack-dev.
- Saved queue copies disappear when loaded history proves the exact message was delivered in the same conversation and recorded session. Remaining Draft or Unsent rows retain Restore, Delete and possible-send warnings; recovery never sends automatically. #164486. Thanks @steipete.
- Successfully queued, unchanged attachments leave the composer while newly edited text and files remain. Storage or connection changes prevent stale cleanup. #162898. Thanks @steipete.
- Queued messages show a small preview of their first image. #161459. Thanks @vyctorbrzezowski.
- Queued messages and their remove controls remain visible when a plugin replaces, delegates or fails to mount the composer. 1571690. Thanks @RomneyDa.
Video and attachments in chat
Assistant replies can show playable YouTube cards, with start times and an external watch link when inline playback is unavailable. Thumbnails contact Google before you press Play. The Control UI also supports inline playback and seeking for allowed native local audio and video up to 4 GiB, subject to browser format support. Remote-workspace and channel limits stay unchanged.
New inbound images and authored progress attachments from session-bound runs remain visible after history reloads or temporary files disappear. Generated media on retained rewind branches is available when you return to that branch and uses disk until the branch is removed. Previously lost files cannot be recovered by this change.
Sources and complete change list
- Assistant replies can show YouTube thumbnail cards with Play, supported start times and an external watch link. Thumbnails contact Google before Play; strict mode, narrow cards and provider restrictions can require external playback. #164576. Thanks @steipete.
- Allowed native local audio and video can play and seek inline up to 4 GiB. Remote-workspace, channel and transcoding limits remain unchanged, and browser codecs still govern playback. Rejected links show Media not attached without exposing the URL, and rejected-only replies avoid duplicate history rows. #164137. Thanks @steipete.
- New authored progress attachments from session-bound agent runs remain in history after temporary files disappear or the page reloads, including recovered runs. Previously lost files are not restored. #165275. Thanks @steipete.
- Newly staged inbound images retain their display references when history is reopened or reloaded, without exposing private workspace paths. Already-damaged older transcripts are not repaired. #161842. Thanks @brandon-julio-t and @obviyus.
- Generated media from retained rewind branches remains available when returning to that branch after file cleanup. Retention uses disk until the branch is removed, and already-deleted files cannot be restored. #163043. Thanks @steipete and @yetval.
Shared-chat reactions
Authorized, identified participants can react to eligible saved prompts and replies without starting another agent turn. Other readers see counts and names, and the agent learns about reactions on its next turn. Some imported messages cannot receive reactions.
Reactions to supported channel-origin prompts can appear on the channel as the bot; reactions to assistant replies stay local. Local reactions survive a failed mirror. Telegram and WhatsApp can restore a remaining emoji after removal, but channel reactions can still be wrong when several people chose the same emoji.
Sources and complete change list
- Identified participants can react to eligible saved shared-chat prompts and replies without waking the agent. Some imported messages cannot receive reactions. Supported channel-origin prompts can mirror as the bot; assistant replies stay local and failed mirrors retain the local reaction. #161053. Thanks @steipete.
- Durable reactions keep local changes even when a changed channel route prevents mirroring. Telegram and WhatsApp removals can restore another reaction, with a remaining limitation when several people chose the same emoji. #162434. Thanks @steipete.
- Reaction labels, hints and participant text use the existing twenty translated locales. #161785.
Pull-request controls
Admins can use the CI popup to schedule PR repair and comment response, merge when ready, or archiving independently. These agent jobs use model allowance, need a running Gateway and scheduler, and continue after browser close or restart under existing approvals and repository conditions. Turning one off stops future runs but cannot undo an accepted external action; changing the enabling user's role does not cancel it. Archiving can also clean the session's managed worktree.
Eligible guests can publish changes from their own sessions through a configured shared account and supported target. Personal publication still requires broader write access. A single account gets a direct button, while choosing from several accounts leaves publication for the next action. PR cards show current status separately from earlier failed attempts and clear obsolete warnings once publication is verified.
Sources and complete change list
- Admins can separately schedule PR repair or comments, merge when ready, and archive controls from the CI popup. Jobs run every five minutes, use model allowance and can survive browser close or Gateway restart. Canceling prevents future runs but cannot undo an action already accepted by GitHub. #161492. Thanks @steipete.
- PR automation controls, status, help and errors use the existing translated locales. #161688.
- The CI popup uses less space while retaining its three automation controls, status, job links and errors. #162444. Thanks @steipete.
- Eligible guests can publish a PR from their own session through a shared account and qualified target. Personal publication still requires broader write access. #162988. Thanks @shakkernerd.
- A single permitted publishing destination uses a direct button. Choosing a personal account explicitly can request publication; picking an account in a multi-account menu leaves publication for the next action. #160967. Thanks @steipete.
- Current PR status is separated from a previous failed publishing attempt. Failure details remain expandable, and pending confirmation stays visible. #162173. Thanks @steipete.
- The previous-failed-attempt label uses the existing translated locales. #162185.
- A shared-publication warning retires when GitHub proves the same accepted work was already published. Newer, unverified or unavailable results keep the recovery warning. #162257. Thanks @steipete.
- Chat-scoped connections avoid unauthorized PR and Discussion reads, clear stale badges after access loss and retain permitted shared-publication options. bf2883a. Thanks @Patrick-Erichsen and @shakkernerd.
File and HTML previews
Chat file links open from the sending conversation's workspace, and supported HTML previews can load nearby images, media, styles and scripts, including in unsaved drafts. Outside-workspace previews need the agent's current authorization and stay read-only within account and sandbox restrictions. Local fonts, CSS imports and attachments without a session folder remain unsupported.
Sources and complete change list
- File links use the sender's workspace, and authorized outside-workspace previews stay read-only. Session-folder HTML and unsaved drafts can load relative images, media, styles and scripts. Local fonts, CSS imports and folderless attachments remain unsupported. Relative assets have limits of 64 references, 1 MiB each and 4 MiB per request; cloud assets retain the 256 KiB cap. #163185. Thanks @steipete.
Reply navigation
Select the compact Replying to author line to return to the original message, with collapsed work opened or search cleared when needed. Unavailable originals show an explanation. Reply and copy controls follow the message you hover, focus or tap, and reply context stays with its completed work after resumptions or partial-history loading.
Sources and complete change list
- Replying to uses the original author's avatar and name instead of repeating a quoted excerpt. Selecting it returns to and highlights the original, opening collapsed work or clearing search when needed. Unknown authors are not guessed, and unavailable originals are not clickable. ed9d2c1. Thanks @vyctorbrzezowski.
- Reply and copy controls follow hover, keyboard focus and touch selection without shifting the message footer. #160612. Thanks @vyctorbrzezowski.
- Your own replies keep Original message unavailable visible when the source cannot be found. #162040. Thanks @steipete.
- Replying to stays with its completed work and answer after resumptions or partial history. Earlier failures remain visible without marking a later successful answer as failed. #162322. Thanks @vyctorbrzezowski.
- Reply-context help and cold-history loading labels use the existing twenty translated locales. #161664.
Updates from other conversations
Consecutive updates from the same outside conversation share a compact row you can expand to read the original messages, times and available source links. Search and reply navigation open the relevant messages for you.
Sources and complete change list
Delegated-work activity
Chat shows Waiting on subagents when an agent has handed off work and its delegated agents are still active. Handoff and resumption remain visible with tool details hidden, and a link appears when one active direct child can be identified in the loaded sidebar. Delegated rows show the assignment and readable task titles.
Sources and complete change list
- A selected conversation shows Waiting on subagents when only its descendants are active, with a child link when exactly one active direct child is identifiable. Successful handoff and later resumption remain visible when tool details are hidden. #164190. Thanks @steipete.
- Delegated-work rows show the task and plain named child titles, with Subagent as the unnamed fallback. #163745. Thanks @Patrick-Erichsen.
Return to Discord and Slack
Supported Discord and Slack browser plugins add a header link back to the conversation where a session began. Slack and GovSlack open the channel or DM. Older sessions gain the link after a later inbound event, and it appears only when a valid source link and supporting plugin are available.
Sources and complete change list
- Supported Discord and Slack browser plugins can link the session header back to its first source conversation. Slack and GovSlack open the channel or DM rather than an exact message or thread; older sessions acquire a link from a later inbound event. a49a332. Thanks @Patrick-Erichsen.
Progress-card controls
You can hide a progress card from your pane with its X while the work continues. Reloading or changing Gateway connections brings it back. Writers can use the separate Clear saved progress for everyone action to remove the saved card for peers.
Sources and complete change list
- Progress-card X hides the card only in the current pane, including for viewers. Reload or a Gateway connection change restores it. Writers use the separate Clear saved progress for everyone trash action to remove the saved card for peers. 4e529ba. Thanks @Patrick-Erichsen.
Plugin setup information
Plugin overviews put the README beneath capabilities and let you expand published MCP setup, authentication and permission information. Missing or withheld details are labeled, and this setup information does not indicate that an account is connected.
Recommendation cards keep their artwork while status loads and show the publisher beside the title. Clearing a settled search brings back the loaded Featured and Trending shelves, though rapid filter changes followed by clearing can still show the previous category.
Sources and complete change list
- Plugin details can expand published MCP connection, transport, authentication, permissions and setup information, with missing or withheld details stated explicitly. These details describe setup, not a live connection or login status. #163849. Thanks @Patrick-Erichsen.
- Clearing a settled plugin search reuses Featured and Trending shelves, avoids duplicate equivalent searches and keeps loading placeholders filling the view. Rapid category and type changes followed by clearing can still leave the previous category displayed. #163836. Thanks @Patrick-Erichsen.
- Recommendation cards keep available artwork during status loading, refresh or failure and show the publisher beside the title. Current status still governs installation. #163860. Thanks @Patrick-Erichsen.
Agent identity controls
Agent identity editing brings related fields together and adds a searchable emoji picker alongside direct entry. Text and emoji avatars appear larger when starting chat, and name or avatar changes show the latest saved result. Clearing a saved emoji remains unsupported. If you still use an unmigrated browser-wide avatar, set each agent's avatar again in Overview under Identity.
Sources and complete change list
- Identity editing adds an optional searchable emoji picker, retains direct entry and shows larger text or emoji welcome avatars. Clearing a saved emoji remains unsupported. #160950. Thanks @Patrick-Erichsen and @vyctorbrzezowski.
- The identity emoji-picker button sits inside its input. #161236. Thanks @vyctorbrzezowski.
- Profile name and avatar updates display the latest committed result even when writes finish out of order. #162571. Thanks @steipete.
- The old browser-wide avatar is no longer migrated automatically. Set an agent's avatar in Overview under Identity. #163209. Thanks @steipete.
Quiet Hours settings
Quiet Hours keeps its time window and timezone together, with a menu for choosing the zone. Saved aliases remain available, but you cannot type an unsaved zone missing from the browser's catalog. Some browsers offer only the local zone, UTC and the saved zone.
Sources and complete change list
- Quiet Hours groups its time window and timezone and adds a menu with saved aliases. An unsaved zone outside the browser catalog cannot be entered; without enumeration, choices may be only local, UTC and the saved zone. #149048. Thanks @nancymx-dev and @vyctorbrzezowski.
Immutable Linux updates
Supported immutable Linux installations can switch to a prepared release, verify startup and recover interrupted updates. Activation requires a separate opt-in after establishing a healthy bridge release and stopping the previous updater's scheduling; ordinary adoption and --no-restart only prepare a candidate.
Follow the immutable installation guide for the required root, systemd, launcher, cgroup, Node and matching-schema setup. An inconclusive startup stays pending, and recovery cannot rewind database schemas. The detector can still mistake an ordinary checkout containing both current and releases for an immutable installation and block update or status.
Sources and complete change list
- Supported Linux immutable installations add explicitly enabled generation switching and recovery with documented root, service, launcher and schema requirements. #164306. Thanks @steipete.
- Explicit adoption prepares sealed Linux candidates away from the serving generation, with activation requiring separate opt-in. SQLite worker cleanup releases native writers after the final borrower closes. The initial immutable detector can misidentify an ordinary checkout containing current and releases. 99babf27. Thanks @steipete.
Database space reclamation
Updates can let eligible older databases return disk space freed by deleted records while keeping retained data and retention settings. The first conversion takes time with the Gateway stopped and needs temporary free space. Follow the offline SQLite maintenance instructions if it is deferred, and inspect a failed conversion before restarting.
Sources and complete change list
- Updates prepare eligible older databases to reclaim deleted pages while retaining records and retention settings. Initial conversion needs a stopped Gateway, time and temporary free space; inspect a failed conversion before restarting. #163105. Thanks @fuller-stack-dev.
Btrfs database maintenance
Linux btrfs installations prepare new databases for in-place writes and offer offline Doctor conversion for existing stores. Repair messages identify blocking processes or inspection errors, with support for eligible large stores, ordinary symlinks and empty files. Managed updates defer this optional conversion by default.
In-place writes disable btrfs checksums and compression for these files. Before converting, stop the Gateway and other database users, keep verified backups and follow the tool and space requirements in SQLite maintenance. Conversion does not preserve all extended attributes or security labels; check required metadata before replacing a store.
Sources and complete change list
- Linux btrfs stores gain in-place-write preparation and offline Doctor conversion, disabling filesystem checksums and compression. Stop database users, retain verified backups, meet tool and space requirements, and check required non-ACL extended attributes or security labels, which are not all preserved. #160877. Thanks @steipete.
- Offline Doctor btrfs repair no longer falsely refuses shared and agent stores because of ownership checks or a newly created empty database log; the Gateway must remain stopped. #161501. Thanks @steipete.
- Managed updates defer optional btrfs NOCOW database rewrites by default, leaving directories in place while retaining advice; explicit Doctor repair outside managed updates keeps its existing behavior. #162786. Thanks @steipete.
- Offline btrfs repair refusals now distinguish process holders from failed inspection and show useful process IDs or errors while leaving the original store in place. #162809. Thanks @steipete.
- Doctor releases its own authentication readers and checks large btrfs stores in bounded batches before offline NOCOW repair; external holders or inspection failures still block replacement. #162919. Thanks @steipete.
- Optional offline btrfs NOCOW repair preserves ordinary symbolic links and empty files without following link targets; unsupported file types and database aliases remain refused. #163023. Thanks @steipete.
- Doctor checks the SQLite directory again after checking open files, refusing unexpected new files before NOCOW replacement. 4d1890a3. Thanks @steipete.
Recovery copies before repairs
Direct updates from the fixed installed updater and standalone Doctor repairs attempt to keep original settings, databases and migration files before changing them. Incomplete copies point to retained files and manual recovery guidance. Keep a verified full backup, and preserve current data before restoring an older recovery copy.
Recovery copies can use less physical storage on supporting filesystems while later edits remain independent; free-space requirements still apply. After a successful fresh capture, Doctor can remove eligible completed standalone copies older than 30 days, so keep lasting backups separately. See the original-state recovery guide.
Sources and complete change list
- Direct updates and standalone Doctor repairs attempt to retain original state before changing it, with clearer incomplete-capture status; complete recovery still needs a verified backup. #161044. Thanks @steipete, @fuller-stack-dev.
- Unresolved original-state captures now point to the retained manifest and manual recovery guide, with instructions to preserve current data before restoring anything. #161292. Thanks @steipete.
- Doctor reduces pre-repair capture overhead and, after a successful fresh capture, removes eligible completed standalone recovery copies older than 30 days; use a verified backup for lasting recovery. #162364. Thanks @steipete.
- Recovery copies can share unchanged filesystem pages without sharing later edits; ordinary-copy fallback and free-space requirements remain. #162466. Thanks @fuller-stack-dev.
- Doctor captures relevant Wiki and Teams migration files; blocked Teams archival keeps the token source and reports a warning. #163780. Thanks @fuller-stack-dev, @steipete.
- Doctor stops before repairs when an explicitly supplied original-state capture cannot be verified; inspect retained update evidence before retrying. #163808. Thanks @fuller-stack-dev, @steipete.
- Doctor can repair temporary update rehearsal databases under verified maintenance ownership while preserving protection for stores outside the rehearsal. #163869. Thanks @fuller-stack-dev, @steipete.
Repairing interrupted updates
Update repair can clear eligible abandoned work that blocks later updates, either retiring unused preparation or checking a candidate already installed. It also handles specific recovery blocks after supported manual installation or replacement of the update-ownership database. Backups and helpers remain available; changed installed files or launchers, live updaters and unfinished rollback still block repair.
For an abandoned handoff, use the failed update's exact profile and state paths, keep its lease database and artifacts, and wait at least 45 minutes from recorded activity or the longer recorded timeout. Live or unverifiable processes still cause refusal. An older updater blocked before staging needs a fixed CLI manually installed at the same package root, with a verified backup and managed-Gateway stop precautions, followed by Doctor and repair. Follow the update repair and manual installation guides.
Sources and complete change list
- Explicit update repair can reclaim eligible abandoned handoffs after the required grace period, with retained evidence, dead-process checks and unfinished-rollback refusals. 9680e57a. Thanks @steipete, @taihartman.
- A fixed installed CLI can retire unused preparation or verify an already installed interrupted candidate while retaining recovery evidence. It checks packaged content and launchers; launcher targets outside dist receive resolution checks rather than full-content verification. Live updaters and unfinished restoration still block settlement. 5a5966fa. Thanks @RomneyDa, @steipete.
- Non-root macOS updates tolerate launcher ownership they cannot reproduce; stranded operations have a guarded recovery path after manual installation of a fixed CLI at the same root. #164636. Thanks @steipete, @hrp6vv9mwr-glitch, @cmillwat.
- A fixed CLI can repair a package update blocked by replacement of its ownership database while retaining staged files, the helper and recovery evidence. #164849. Thanks @steipete, @szef-svg, @izrl613.
Startup with large databases
The Control UI and healthy agents can open while eligible large agent databases finish checking. Agents still being checked remain unavailable, with retry hints for clients that support them; the CLI does not retry automatically. Startup probes keep waiting for those checks. Restarts also finish accepted subagent cleanup and let deferred databases prepare without waiting for unrelated subagents.
Sources and complete change list
- The Control UI and healthy agents can become ready while eligible large agent databases finish checking; pending agents remain unavailable until admitted. #163690. Thanks @steipete.
- Pending agent database checks return retry hints and keep startup probes waiting while healthy agents and the Control UI remain available. #163839. Thanks @steipete.
- Restarts wait for accepted subagent cleanup, and eligible agent-database preparation can start before unrelated subagents finish restoring. #164403. Thanks @steipete.
Runtime memory diagnostics
Node diagnostics help operators investigate memory pressure with heap details, reply sizes and approximate memory changes during individual requests. Samples exclude overlapping handlers and report their coverage; a missing sample means unavailable coverage. These heap measurements cover Node's main JavaScript engine, excluding workers and external or native allocations. Built-source tools also provide isolated workloads and snapshot references for investigating retained objects.
The Gateway diagnostics and Prometheus metrics guides explain the measurements and their limits.
Sources and complete change list
- Built-source memory diagnostics add an isolated workload and snapshot reference paths for investigating retained objects. #163764. Thanks @steipete.
- Node memory diagnostics expose heap-space metrics and before-and-after heap-profile breakdowns for the main V8 isolate. #164057. Thanks @steipete.
- Gateway diagnostics measure reply sizes and approximate memory changes; later exclusive sampling excludes overlapping handlers. #164335. Thanks @steipete.
- RPC memory samples exclude overlapping handlers and report sample coverage; an omitted sample does not mean zero memory use. #164418. Thanks @steipete.
A channel request that stalls before answering can try once to continue from saved conversation context, with a matching queued follow-up allowing it to answer both questions. Web UI and group-thread requests require that follow-up, and a failed continuation still gives the usual retry notice. See the message queue guide.
Sources and supporting fixes
- An eligible stalled channel request can make one continuation from saved context. Web UI and group-thread requests need a matching queued follow-up; the continuation can still fail. #161069, thanks to @obviyus.
- Model-timeout recovery after compaction can use an already-saved user turn without attempting to append it again. #162260, thanks to @steipete.
- A waiting follow-up cannot replace the original question during that question's existing model retries or fallback; the follow-up receives a separate turn. #162439, thanks to @obviyus.
- An answer already sent to the source chat suppresses a later false stalled-turn recovery notice; progress and partial sends do not count as completed answers. #162756, thanks to @obviyus.
Channel webhook setup
New Telegram, Feishu, Microsoft Teams and Nextcloud Talk webhook installations share Gateway routes by default. Existing installations keep their previous callback listeners, and Telegram keeps its old listener until the replacement is registered successfully.
Move and verify callbacks before removing old listener settings, retaining the marker in the configuration migration guide. Old Teams and Nextcloud listeners can remain accessible on all network interfaces until migrated. Upgrade core to at least 2026.9.9 before manually replacing these standalone plugins. If Nextcloud Talk still uses the retired private-network setting, follow the guide's 2026.9.5 intermediate upgrade first.
Sources and supporting fixes
- Fresh Telegram, Feishu, Microsoft Teams and Nextcloud Talk webhook installations use Gateway routes by default. Existing eligible accounts retain historical listener pins, and Telegram keeps its old listener until replacement registration succeeds. Move and verify callbacks before removing pins, retain
meta.migrations.webhookListeners, and upgrade core to at least 2026.9.9 before manually replacing these standalone plugins. Retired Nextcloud TalkallowPrivateNetworksettings require the documented 2026.9.5 bridge. c7c937a, thanks to @steipete. - Doctor skips inferred historical Nextcloud Talk listeners when the channel is absent, incomplete or disabled, avoiding a startup refusal on installations that do not use it. 96622c4, thanks to @steipete.
Memory provider recall
Compatible memory plugins can bring their stored records into recall, Memory Wiki and realtime voice. With a native provider selected, OpenClaw checks access to private or conversation-specific memory, including what spawned agents inherit. Resetting or replacing the parent ends that inherited access, and status reports the selected provider's health separately from Memory Core.
Each recall feature requires a plugin that supports it. Recreate older spawned sessions from their parent to restore native memory access; if the parent predates reset tracking, do this after its next reset. Custom native-provider search clients must use API version 2. Memory Core search and deep index diagnostics refuse to use its separate index when another provider is selected.
Sources and complete change list
Memory saves before compaction
Supporting memory plugins can save important context before a long conversation is summarized, using their own storage even when the workspace is read-only and permissions allow it. Saving is best effort, so compaction still proceeds if a save fails or is skipped. Memory Core continues using workspace files.
Sources and complete change list
Skills on paired devices
You can install, track, update and remove skills on configured paired-device workspaces with the required workspace read and write permissions. Skill files and instructions stay on the correct device, even when two computers use identical paths.
Cancelled replacements or revoked access can restore the previous skill, although forcibly stopping a stuck installer may prevent recovery. Disconnected devices return an error, and an agent may need to reread an updated skill.
Sources and complete change list
- Configured paired-node sources own skill installation, tracking, ClawHub updates and removal under the required workspace permissions. Native version and local-edit checks remain in place, and replacement can restore the previous skill after cancellation or revoked access, with limited rollback after a forced worker stop. #162960. Thanks @Kimiyu-186.
- Managed remote skill instructions and supporting files are read from the correct host, including when local and remote paths match. A stopped node returns a failure instead of stale local content. #161440. Thanks @RomneyDa, @sallyom and @steipete.
Codex Workshop reviews
Scheduled Workshop skill reviews can use compatible Codex runtimes to read and edit within the assigned Workshop directory. They run through restricted host tools, without shell access, external MCP tools or delegation, and refuse to start if those restrictions cannot be verified.
Background reviews can find and improve pending proposals, with each draft still awaiting separate acceptance.
Sources and complete change list
- Scheduled Workshop reviews add a compatible Codex path using host tools within the captured Workshop directory. It excludes shell, process and native tools, MCP, delegation and hooks, and refuses to run when restrictions cannot be verified or required host tools are missing. #162406. Thanks @vincentkoc.
- Workshop retires a pending review when its activity check throws instead of leaving it stuck. Queued skill selections retain the choices made when submitted, and selector text counts toward the existing size limit. #161316. Thanks @steipete.
- Background reviews are guided to list pending proposals and use a returned proposal ID to inspect or revise one. The result remains a pending proposal, awaiting acceptance. #164292. Thanks @steipete.
- Eligible Workshop runs that allow silence can end with
NO_REPLYafter tool rejections have settled, without being prompted for an unnecessary closing reply. A rejected tool still remains a failure, and runs requiring a visible response retain reply recovery. 4b08683. Thanks @steipete.
Conversation organization on Mac
The experimental native Mac sidebar adds groups, colors and owners to help you organize conversations and find the one you need. You can copy transcripts or links and open a selected conversation in another window. Group defaults can start new conversations in selected folders or eligible separate Git working copies; editor shortcuts need a local working copy.
Select several visible root conversations to manage them together, or drag them into groups and pinned Pages. Deletion requires confirmation, successful changes survive partial failure, and write permissions apply. Pin placement and ordering require administrator access. Archive Undo lasts six seconds, pauses while hovered or focused, and ends on reconnect.
With a supporting Gateway UI, draft and queued-message markers show what needs attention without sharing draft text. Web actions and connection settings are also within reach. See the Mac chat guide.
Sources and complete change list
- Full Mac chat windows show consistent conversation facts, immediate renames and reconciled late or failed updates across navigation surfaces. #161745. Thanks to @steipete.
- Experimental Mac conversation rows show clearer names, status, channels, descendant summaries and supplied previews, with Pin and Archive controls. #161973. Thanks to @steipete.
- Mac Online people cards show reported activity, environment and conversation links, with other-viewer counts excluding yourself. #162022. Thanks to @steipete.
- Mac transport forwards permission/tool guards and replacements supplied by callers, rejecting unsupported Gateway capabilities before sending. #162043. Thanks to @steipete.
- Apple child lists retain larger reported totals and available partial rows. Custom Swift child-list callbacks must return
OpenClawChatChildSessionsResult(rows:isComplete:); old array overloads can yield empty defaults. #162278. Thanks to @steipete. - Mac conversations gain icon and color organization, owner assignment, transcript and link copying, and correctly targeted new windows. Deleting a group retains its conversations. #163001. Thanks to @steipete.
- Mac group defaults select a starting Gateway folder and eligible separate Git working copy for new conversations; failed saves retain selections for retry. #163162. Thanks to @steipete.
- Mac sidebar draft markers and queued-message attention counts accompany More actions for the selected conversation when the Gateway UI supports it. Only draft presence and attention counts are shared. #163193. Thanks to @steipete.
- Mac More actions waits for the selected conversation menu to render and cancels a late popup after switching. #163351. Thanks to @steipete.
- Abandoned Mac conversation-menu requests finish promptly without a misleading timeout or late popup. #163672. Thanks to @steipete.
- Experimental Mac visible-root multiselection adds batch actions and drag organization, retaining successful operations through partial failure. #164013. Thanks to @steipete.
- Experimental Mac archive Undo and selected-thread group creation preserve successful results; restored threads return to Active and cross-agent names remain distinct. #164073. Thanks to @steipete.
- Mac sidebar identity and Gateway menus route Dashboard, Settings and Usage to the window’s Gateway. The request badge counts the oldest request kind rather than all kinds together. #164591. Thanks to @steipete.
- Existing shared-owner, active and idle labels gain native translations. #161733.
- Existing Apple conversation, status and cloud-warning messages gain translations. #162030.
- Native activity, people, retry and connection explanations gain translations. #162060.
- Native conversation, group and copy controls gain translations. #163050.
- Apple group, folder, filter, draft and pull-request labels gain translations. #163219.
- Apple sidebar, agent, accessibility and child-loading error text gains translations. #163793.
- Native selection prompts, configuration-save, restart and audio labels gain translations. #163935.
- Apple selection, deletion, archive, error and preserved-working-copy messages gain translations. #164050.
- Apple archive, Undo, group creation and Gateway recovery messages gain translations. #164155.
- Mac Set as primary and iOS Primary and Retry now gain translated labels. #164623.
Finding and inspecting Mac conversations
You can load older conversations for the selected agent and search names, details and messages from the Mac sidebar. Search combines immediate local matches with Gateway results and explains when indexing or archived transcripts leave results incomplete. View options remembers your filters, grouping and display choices for each Gateway profile.
Expandable follow-up trees and Pages across agents keep related conversations within reach. Hover over or keyboard-focus a conversation to preview available people, workspace and progress details without opening it. Pull-request cards identify last-known status when a refresh fails. The Mac chat guide covers navigation and keyboard access.
Sources and complete change list
- Mac Load more reaches older selected-agent threads; local and Gateway search retain results and expose retry or incomplete-index notices. #163114. Thanks to @steipete.
- Mac filters, owner views, grouping, sorting, previews and reset choices persist per Gateway profile. #163164. Thanks to @steipete.
- Full Mac chat detail cards expose available people, workspace, branch, pull request, progress, notepad and preview information, with last-known notices when needed. #163165. Thanks to @steipete.
- Mac follow-up trees, expandable agent rosters and cross-agent Pages retain loaded children and use configured image avatars with text fallback. #163699. Thanks to @steipete.
- Apple conversation search, loading, indexing and archive notices gain translations. #163159.
Plugin conversations in the Mac sidebar
You can browse supported plugin conversations beside OpenClaw conversations in the selected-agent Mac view, organized by project, person or owner. Visibility is saved for each Gateway profile, and sending the first message brings the source conversation into OpenClaw. Source deletion requires support, write or administrator permission, and confirmation that another runner is not using it.
Paired Macs also find Claude Code conversations in a custom CLAUDE_CONFIG_DIR when it is set in the app's launch environment. Setting it only in another shell will not configure the app.
Sources and complete change list
- Mac plugin catalogs add project or person grouping, owner filters, profile-specific visibility, independent paging and retry, and supported source actions. #164436. Thanks to @steipete.
- Paired Mac Claude Code discovery respects nonblank
CLAUDE_CONFIG_DIRin the app launch environment, otherwise using the home-directory default. #163787. Thanks to @steipete. - Apple session source, catalog, owner, open, hide, delete and retry messages gain translations. #164481.
Snooze in native apps
You can put eligible root conversations aside until later with Snooze on iOS, Android and the experimental native Mac sidebar, then find them in Snoozed or wake them early. Work continues while they are hidden, and incoming messages or completed runs can wake them. Pinning or archiving clears snooze; protected, child and archived conversations are excluded, and changes require write permission.
On iOS you can browse cached Active and Snoozed lists offline, while archives and changes require a connection. Android may briefly show an old snoozed row when starting offline. See iOS conversation controls and the Mac chat guide.
Sources and complete change list
- Android long-press Snooze presets, the Snoozed list and early Wake apply to eligible root conversations while work continues. Pinning or archiving clears snooze. #162293. Thanks to @steipete.
- iOS Snooze and Wake add Active, Snoozed and Archived views, including cached Active and Snoozed browsing offline. #162399. Thanks to @steipete.
- Mac eligible root conversations gain Snooze and Wake, preserving existing pins while messages or run completion can wake them. #163241. Thanks to @steipete.
- Android Snooze and Wake controls gain translations. #162363.
- Apple snooze choices and iOS snooze status gain translations. #162630.
- Mac snooze and wake labels gain translations. #163293.
Reactions on iOS and Android
iOS and Android let you view and add emoji reactions to eligible saved messages in shared conversations, with counts, accessible pickers and live updates without extra notifications. Android includes media-only messages through long-press. Reaction controls follow conversation permissions and are unavailable for archived, source-catalog or unsaved messages.
If iOS cannot identify you when first connecting, your own reactions may not highlight or be removable until you reconnect or switch conversations. See iOS reactions and shared-conversation reactions.
Sources and complete change list
- iOS saved-message reactions add counted chips, an emoji picker and VoiceOver controls, with live updates and permission checks. #162296. Thanks to @steipete.
- Android saved, nonstreaming message reactions add chips, media-message long-press access and TalkBack controls; inline add appears alongside existing reactions. #162307. Thanks to @steipete.
- Apple reaction controls and accessibility labels gain translations. #162475.
- Android emoji, reaction-count and reaction-name labels gain translations. #162568.
Image paste on iPhone and iPad
You can paste a copied screenshot or supported image into an attachment-enabled iPhone or iPad chat without saving it to Photos first, then remove it before sending. Images take precedence over text in a mixed paste. File links copied from Files are not supported, and attachment limits still apply.
Sources and complete change list
- iOS pastes copied images as removable attachments in enabled composers; Files URLs are not included. #161627. Thanks to @Marvinthebored, @Patrick-Erichsen.
Mac automation windows
Mac automation can open chat or Dashboard windows behind the app you are using with --no-activate. LaunchServices callers also need open -g -n. If an action needs a permission prompt, file selection, interactive Keychain access or external navigation, relaunch normally and retry it. See the launch and debugging guide.
Sources and complete change list
Android daily test delivery
Android daily-build tooling adds Firebase distribution of the signed phone and Wear test builds after Play upload, with recovery of a failed Firebase stage without another build or Play upload. For phone/watch communication tests, use the same distribution channel on both devices because their signing certificates differ. Release operators must configure Firebase and pass preflight before building or uploading to Play.
Sources and complete change list
- Android daily Firebase test distribution supports retained-stage recovery and notification safeguards after Play delivery. #162371. Thanks to @joshavant.
Provider models and thinking controls
GitHub Copilot adds bundled Claude Sonnet 5.5 and Opus 5.5 definitions for accounts with access. Ollama Cloud can honor maximum thinking for GLM 5.3, GLM 5.3 Flash, Kimi K3 and DeepSeek V4.1 Flash, including verified models reached directly at ollama.com; local relays still use high effort for compatibility. Eligible Daybreak Blue and Red accounts regain xhigh and max, while supported Codex and other provider replies retain your chosen thinking settings.
New Baseten setups start with DeepSeek V4.1 Flash, with supported Flash image and thinking options and current Pro conversation replay restored. If your saved Inkling model is unavailable, select a replacement manually. Thinking Off does not always stop reasoning. On Ollama Cloud GLM 5.3 and GLM 5.3 Flash it uses low effort and keeps reasoning out of the answer; on xAI models without effort controls it leaves native reasoning in place.
Sources
- Send maximum thinking effort to GLM 5.3, GLM 5.3 Flash, Kimi K3 and DeepSeek V4.1 Flash on Ollama Cloud — Thanks Ram-G, RomneyDa, serg0x, g0st1n, steipete.
- Honor supported maximum thinking in Codex chat and channel replies — Thanks yashas-13, obviyus, Oldrich333.
- Restore xhigh and max reasoning choices for eligible Daybreak Blue and Red accounts — Thanks VACInc.
- Add bundled Claude Sonnet 5.5 and Opus 5.5 definitions for Copilot — Thanks roslinmahmud, steipete.
- Honor maximum thinking on verified models connected directly to Ollama Cloud through an ordinary Ollama provider — Thanks serg0x, RomneyDa.
- Keep GLM 5.3 and GLM 5.3 Flash reasoning separate from replies when Ollama thinking is Off — Thanks serg0x.
- Honor prepared reasoning settings in affected xAI, MiniMax and custom-provider chat replies — Thanks steipete, Oldrich333, yashas-13.
- Allow Off on xAI models without effort controls while retaining their native reasoning — Thanks steipete.
- Use DeepSeek V4.1 Flash for new Baseten setups, restore Flash image and thinking options, and preserve current Pro conversation replay — Thanks steipete.
Ultrafast selection
You can choose Ultrafast on supported embedded OpenAI Responses routes with an API-key profile or a direct key. Codex requires an explicit Ultrafast choice and native account support for the selected model. If you relied on Fast or Auto upgrading automatically, select Ultrafast in the picker or with /fast ultrafast. See the shared speed controls.
Providers may return a different tier, so choosing Ultrafast does not guarantee speed or price. Custom Responses endpoints now receive service_tier from saved Fast or authored tier settings and may reject it; check your endpoint's compatibility before relying on those settings.
Selected Speed settings also reach background workers, and distinct indicators show Fast and Ultrafast. Codex falls back to Fast when the choice is unavailable; disabling Ultrafast hides it and makes saved selections use ordinary Fast.
Sources
- Configure Codex Ultrafast and its shared speed controls — Thanks steipete.
- Preserve explicitly requested Ultrafast in OpenClaw-runtime OpenAI and ChatGPT Responses requests — Thanks VACInc.
- Offer Ultrafast on available embedded API-key Responses routes and carry selected Speed through worker calls — Thanks steipete.
- Offer Ultrafast with direct API keys and require an explicit eligible selection in Codex — Thanks steipete.
- Eligible sessions can select Ultrafast in the model picker or with
/fast ultrafast. Availability depends on the account, model and runtime, and an unavailable choice may fall back to Fast. #160352. Thanks @steipete. - Fast and Ultrafast use distinct bolt icons, with full accessible names and compact effort controls. #162356. Thanks @vyctorbrzezowski.
Background model routes
Model settings show which runtime and account handle background summaries, titles and progress narration. Eligible automatically selected background models for the same provider can use your primary model's CLI runtime when their API credentials are unavailable. Usable API credentials and explicit model or runtime choices keep their own routes and billing. See the CLI backend guide.
Sources
- Show the runtime and account context used by background utility models — Thanks etzelm, Patrick-Erichsen, miguelarios, asikorskiy, cbhawthorne84.
- Let eligible automatic background tasks borrow the primary model’s CLI runtime when API credentials are absent — Thanks etzelm, Patrick-Erichsen, miguelarios, cbhawthorne84.
Agents API native tools and session access
Agents API operators can choose which supported native tools a hosted conversation uses, including web-search options. Restart the Gateway and start or reset a session after changing them. Your list replaces native defaults, leaving OpenClaw and MCP permissions separate. An empty list removes web search but leaves programmatic calling enabled; disable it explicitly using the programmatic tool-calling guide.
Attachment follow-ups can retain usable originals and show when uploads are unavailable. Hosted machines do not automatically receive your local files or skills. See the runtime guide for setup and returned-file checks.
New-format sessions keep their remote ID when credentials change, although hosted access still requires the creating key. Older authFingerprint bindings, including those from 9.7, can no longer continue, reset or delete, and have no automatic migration. Model, environment or effective HTTP MCP changes still require reset. Check previous tool results before repeating an interrupted operation. See the Agents API access guide.
Sources
- Correct Agents API runtime selection and explain how to verify execution and returned files — Thanks sjf-oa, sjf.
- Continue hosted Agents API attachment turns with usable originals and honest upload feedback — Thanks sjf-oa, sjf.
- Choose native tools and web-search options when creating or resetting Agents API sessions after restart — Thanks sjf-oa, sjf.
- Identify native OpenAI Agents API requests with the OpenClaw product and version — Thanks sjf-oa, sjf.
- Preserve new-format Agents API session identity across credential changes and document unsupported older bindings and access recovery — Thanks sjf-oa, sjf.
Claude CLI forks and background work
Whole-conversation forks of compatible Claude CLI sessions can preserve the model's context in an independent child. Per-message forks, missing checkpoints and changed accounts or environments start fresh native sessions. You can also find and read existing sdk-ts transcripts through the Gateway, although the native Mac node reader does not gain that support.
Ordinary local Claude CLI chats using bundled Gateway MCP can return control while long shell work continues under configured permissions and deadlines. Background answers retain parent context, permitted tools remain available for verified local child results, and Gateway tools work on later CLI turns. Conversations blocked by a completed consult or handoff can resume without resetting; recovered runs preserve their provider connection, and cancelled remote turns avoid new approval prompts. See CLI backends and child tool policy.
Sources
- Find and read existing sdk-ts Claude transcripts through the Gateway, with the native Mac node reader unchanged — Thanks nimarosa, obviyus.
- Preserve Claude CLI context in independent whole-conversation forks — Thanks Marvinthebored, Patrick-Erichsen, Peetiegonzalez.
- Resume Claude CLI conversations after a completed consult, fallback or handoff — Thanks SunnyShu0925, Patrick-Erichsen, Oldrich333, vincentkoc.
- Finish Claude CLI turns after background commands and retain overlapping task answers — Thanks VACInc.
- Find CLI backends using the selected custom state directory — Thanks steipete.
- Return a process handle for long local Claude CLI shell work through Gateway MCP — Thanks VACInc.
- Restore permitted tools for verified automatic Claude CLI child-result turns — Thanks Stronggenetics, VACInc, Jeehut, abacha, glaiveai, pibur, ranukadf82-hub, nano-richtera, aspalagin, Oldrich333, davidcittadini, Marvinthebored, aikohoshinoai-prog.
- Keep CLI parent-conversation context when child tasks complete — Thanks steipete.
- Avoid new approval requests after canceling a paired-node Claude CLI turn — Thanks steipete.
- Keep Gateway tools available to CLI agents after the first turn ends — Thanks steipete, nano-richtera.
- Save provider conversation bindings after CLI history-writer recovery — Thanks steipete.
- Avoid starting a remote Claude approval request after cancellation.
Claude instruction updates
Supported direct Anthropic API-key conversations can keep reusing cached instructions when workspace guidance or skills change, while Claude receives the updates later in the conversation. OAuth, proxy and other hosted routes keep their existing behavior, and compaction, route or tool changes can still invalidate caching.
Temporary context stops consuming model input on your next message but remains in the saved transcript. Failed, rolled-back plugin registrations also stop blocking otherwise healthy agent turns. See Anthropic retained context and the context guide.
Sources
Shared workspace context in Codex
Codex connections without the managed inference relay now receive shared workspace persona and memory guidance, with edits reaching persistent conversations on the next turn. Selected personal USER.md profiles are omitted on these connections, so some previous preferences may disappear. Use the managed parent-only relay when you need those personal preferences.
Native children may inherit shared instructions. Incognito conversations just after native compaction, and fresh children without inherited history, may briefly use the instructions from creation before refresh. Removing persona does not erase it from earlier history.
Sources
OpenAI conversation continuation
Eligible OpenAI Responses HTTP conversations can resume after pauses of up to 90 minutes using only new input when the saved history still matches. If that local record expires or is cleared sooner, OpenClaw sends full history instead. Tool continuations also retain eligible compaction checkpoints during tool-call ID repairs. This does not change provider storage or guarantee lower charges. See OpenAI advanced guidance.
Sources
Separate model runtimes for Node integrations
Node developers can use createNodeLlmRuntime to run multiple model integrations with separate credential and request policies, connections and cleanup. Supply each runtime's policies and use Node asynchronous-context support. Browser integrations retain the default runtime, and cleanup without a specified owner still affects all owners.
Sources
Experimental Decision assistance
With experimental Decision assistance enabled and a model selected, a conversational turn can leave out optional tools judged unnecessary. Required tools and permissions remain intact, and later turns start with their normal tools. It is off by default, but a saved opt-in can start this automatic behavior after upgrading. Unsupported runtimes, including Codex app-server, keep their normal tools.
The selected provider receives bounded request text, up to two recent visible exchanges, tool-return and error counts, and prompt-hook text. Hosted evaluations can cost money, and judgments can be wrong. Turning assistance off stops new automatic evaluations; evaluations already sent may still transmit data and restrict tools. Explicit decision_evaluate calls have separate controls.
Sources
Automation search and run history
You can search scheduled jobs by name, description, ID or agent in the terminal, then inspect failures across visible jobs without opening each one. Completed messages also link directly to their job's History and transcript, with labels that follow job renames.
Usage keeps each recurring run's recorded creator when the next run starts, though already-lost attribution cannot be recovered. The CLI index also makes the existing cron show and cron scratch commands easier to find, with usage in the cron reference.
Sources and changes
- Query history across visible automations with
runs --all, retaining filters and pagination. Use it without a positional job ID or--id. #148947 Thanks @Alix-007 and @Patrick-Erichsen. - Search job IDs, names, descriptions and agent names with
list --query; message and script contents are outside this search. #150097 Thanks @Alix-007 and @Patrick-Erichsen. - Open the job History page from a completed message's From link. Older runs may need manual paging, and deleted jobs cannot be opened. #161643 Thanks @steipete.
- Keep automation names current across history and live messages; deleted jobs retain the Automation label. #163797 Thanks @steipete.
- Preserve recorded creators of prior recurring runs when the next run starts, rather than moving them into Unattributed. #161806 Thanks @PollyBot13, @Conan-Scott and @obviyus.
- Omit a stale next-run time from newly completed one-time jobs that delete themselves. An early manual run still retains its future scheduled occurrence; existing historical entries are unchanged. #161554 Thanks @steipete.
- Make the existing
cron showandcron scratchcommands discoverable in the main CLI index. #145034 Thanks @qingminglong.
Tools for scheduled jobs
Default scheduled agent jobs can use their owning conversation's current tools, including eligible older jobs held back by outdated tool lists. These jobs now follow the conversation's current permissions, losing restrictions tied only to the original sender or its plugin hooks. Explicit tool limits, scripts, condition-trigger jobs and app- or runtime-bound jobs keep their restrictions, and saved execution hosts stay pinned.
The model picker retains the provider you selected even when providers share a model ID, and the CLI catches misspelled thinking levels before saving an agent job. To remove a thinking override, use --clear-thinking; a blank value does not clear it.
Sources and changes
- Give eligible default scheduled agent jobs current owner-conversation tools without rewriting saved rows. Converting one to a script or adding a condition captures a concrete tool list. Claude CLI wildcard jobs use ordinary chat behavior without a CLI tool cap. #162432 Thanks @obviyus, @jalehman, @steipete and @joshavant.
- Reject invalid nonblank CLI thinking levels before agent-job creation or editing. Recognized values still depend on model support, and previously saved invalid values need correction. #149968 Thanks @Alix-007 and @Patrick-Erichsen.
- Preserve the selected provider when saving a newly discovered automation model. Existing saved bare model overrides stay unchanged, and only models eligible for manual selection are offered. 425d77a8 Thanks @ooiuuii and @obviyus.
On-demand automation results
When you ask an agent to run an automation, short jobs can return their outcome directly. Longer jobs keep running with a run ID for follow-up. Jobs that need the calling conversation acknowledge promptly so its turn can finish, and their reports can arrive afterward.
Delegated jobs retain the child's answer instead of echoing their instructions. Eligible jobs with delivery turned off keep that answer in private run history, waiting within the existing deadline. They can take longer and reveal previously unrecorded failures; intentional silence still counts as success. A captured answer remains temporarily available after its child session is deleted.
Sources and changes
- Return completed short-run outcomes to the agent and give longer runs an exact run ID for later inspection. A wait timeout leaves accepted work running; the calling agent must inspect the run later for its outcome. CLI waiting is unchanged. #162481 Thanks @obviyus.
- Avoid holding the caller's turn while waiting for work that needs that same conversation, including named main-session aliases and current-session announcements. #162683 Thanks @obviyus.
- Deliver chat-triggered automation reports after the initiating turn ends and retain affected transcript copies. #162780 Thanks @obviyus.
- Record and announce the child's final answer when a delegated job's parent has no substantive reply, instead of sending the job prompt. #162460 Thanks @obviyus.
- Keep child results in private history for isolated, no-delivery jobs whose parent only delegates. Missing or late output follows normal error accounting, with alerts only where configured. #162474 Thanks @obviyus.
- Recover the full scheduled reply when history marks its display preview as truncated. If recovery fails, the incomplete preview is not treated as the complete answer. #160520 Thanks @jayzhou2309, @xiao398008, @obviyus and @markoub.
- Retain a scheduled child's captured answer after
cleanupis set todelete, while still deleting its session. The answer expires at the existing archive deadline, normally 60 minutes, or after five minutes when archiving is disabled. #162962 Thanks @obviyus. - Restore follow-up messages addressed to an automation's stable session key after a scheduled execution. They reach its latest local detached run and stay in that run's transcript without inheriting the original conversation's worktree or cloud worker. A newer run cancels an older in-flight follow-up, without undoing completed effects. #161085 Thanks @steipete and @ysumatta.
Automation failures and repair requests
Repeatedly failing jobs can ask their owning conversation to repair workspace problems before another qualifying failed run triggers an alert, including for eligible existing jobs after upgrading. Repairs use the conversation's ordinary permissions, and changing the job itself requires a user reply. Each failure streak gets one repair request; jobs with no further run keep their direct alert. Setting failureAlert:false disables both repair requests and alerts.
Agents can explicitly report failed scheduled work with AUTOMATION_FAILED alone on the first line, including in a child's answer. History records the explanation as an error, and announcements omit the marker. One-time jobs treat these reports as permanent failures. Silent recurring jobs without an alert route stay enabled through them, with increasing delays up to hourly; runtime faults or interrupted saving can still disable those jobs. See failure notifications and scheduled payload guidance.
Sources and changes
- Request diagnosis and workspace repair in the owning conversation for eligible repeated failures. Command jobs, stream or on-exit schedules, webhook routes and jobs without an owner keep their alert path. Rejected requests fall back on the next qualifying failure. #161007 Thanks @obviyus.
- Request repair once per failure streak even when the error changes, preserve final alerts for jobs without another scheduled attempt, and keep ordinary cooldowns after the fallback alert. #162702 Thanks @obviyus.
- Record explicit agent-reported task failures with their explanation, including for otherwise silent jobs. An unconfigured no-delivery job stays silent without alerts or repair requests. #162391 Thanks @obviyus.
- Classify adopted child failure reports correctly and retain failed-run transcripts. Deliberately silent recurring jobs without an alert route stay enabled for agent-reported failures. A later runtime fault after accumulated failures, or a crash between saving history and job state, can still disable the job. #162686 Thanks @obviyus.
- Clearing a failure-alert override with
nullrestores inherited policy instead of disabling alerts. Jobs previously saved withfalsestill need an explicit correction. #158869 Thanks @masatohoshino and @obviyus. - Show a sanitized unresolved execution warning in job details and history even when the agent turn succeeds. The warning omits raw errors and arguments; see cron troubleshooting. #158929 Thanks @Ayushdevo, @elvisquirino, @MertBasar0 and @obviyus.
- Keep failure-alert webhooks Unknown when delivery is ambiguous, avoiding a fallback based on an incorrect Not delivered status. Known rejection or proven pre-send failure still permits fallback; Unknown does not confirm receipt. #161750 Thanks @steipete.
- Suppress generic runtime try-again warnings from failed automatic repair turns while retaining authored replies and job-failure alerts. A repair resumed after restart can still emit its timeout warning. #162772 Thanks @obviyus.
- Correct guidance about failed-run output versus threshold-based failure alerts. Ordinary output follows the job's delivery setting; alerts can wait for repeated failures. #162695 Thanks @obviyus.
MCP checks in scheduled scripts
Scheduled conditions and scripts can check explicitly allowed MCP services and skip the payload and model call when nothing changed. Enable tools by name or a server-specific pattern; a bare wildcard enables none. Conditions keep their time and tool-call limits, and requester-scoped services remain unavailable. See condition watchers and payloads.
The recurring-job authoring guide helps agents use scripts for repeatable checks and bookkeeping. Scripts must throw to record failure; returning an error object counts as success.
Sources and changes
- Let conditions and script payloads query explicitly allowed MCP server tools and skip payload execution when a condition does not fire. Unavailable servers remain absent with diagnostics. #160995 Thanks @obviyus.
- Guide agents toward scripts for repeatable automation work, precise tool choices and explicit script failures. Script-specific advice follows whether triggers are enabled. #160996 Thanks @obviyus.
Interactive Lobster workflows
With the optional Lobster plugin, you can answer workflow questions in chat, correct rejected answers and continue from saved progress, or cancel the remaining steps. Keep resume tokens secret. Anyone holding one can resume the workflow; tokens are not tied to your OpenClaw user or session. See Lobster structured input.
- Support feedback and selection checkpoints, corrected JSON or schema answers, successive pauses and explicit cancellation. The installed Lobster runtime owns saved progress and validation. #162003 Thanks @miguelbranco80, @Patrick-Erichsen and @Alix-007.
Plugin conversations and side panels
Plugins can bring a conversation beside their page, including drafts, attachments and removable page context, or open their registered side panel beside the conversation that requested it. This requires the plugin to adopt the Control UI host capabilities on a supported host; opening a panel through a tool needs operator.write permission.
Changes and sources
- Plugins adopting the conversation dock can place a chosen conversation beside their page, with drafts, attachments and removable page context. #161957. Thanks @steipete.
- On a supported host, plugins can open their own registered side panel beside the requesting conversation with
operator.writepermission. #163428. Thanks @jalehman.
Enterprise repositories and prepared cloud workers
Enterprise teams can offer a default GitHub repository and branch in New Session and prepare matching cloud workers while eligible Control UI browsers are connected. People can still choose another project, and prepared capacity stays within the configured pool limits. When those browsers disconnect or lose access, refill stops and unused reserves retire; active sessions keep their own worker lifetime.
Credentials must match the configured Enterprise host, with public GitHub sign-in kept separate. Configuring the repository does not complete GitHub authentication on stock cloud workers. Local repository recovery requires restoring the recorded host configuration.
Changes and sources
- Configured Enterprise repository defaults and authorized browser presence prepare matching cloud-worker capacity within the chosen pool limits. db01f6d520b8. Thanks @galiniliev.
Agents API tools and attachments
Agents API sessions can use configured Streamable HTTP MCP tools reachable from their execution environment, including private services. Resolved credential headers are passed to the API. Use /new or /reset after changing MCP setup or credentials; existing conversations may also need a reset after this upgrade. Other MCP transports and Gateway OAuth remain unsupported.
Self-hosted users can submit input files when their registered workspace provider prepares them for the executor. Native image input and automatic output-file transfer remain unavailable. Agents API also has its own plugin selections that can change without restarting the Gateway; copy supported selections from Codex explicitly, since this alone does not enable native apps or connectors.
Changes and sources
- Fresh Agents API sessions discover and call configured Streamable HTTP MCP tools with resolved credential headers. #160931. Thanks @sjf-oa, @sjf.
- Agents API gains an independent plugin-selection configuration block that needs no Gateway restart; it does not activate native apps or connectors. #161048. Thanks @sjf-oa, @sjf.
- Self-hosted turns can submit staged attachments when their workspace provider makes the complete batch readable to the executor. #161312. Thanks @sjf-oa, @sjf.
- Accepted follow-up instructions no longer prevent an Agents API task from retrying a temporary failure; the next turn reads fresh history. #161444. Thanks @sjf-oa, @sjf.
- The dedicated plugin guide brings Agents API setup and capabilities together, replacing the older runtime-fragment bookmarks. #162255. Thanks @sjf-oa.
Existing agents in Claw management
With experimental Claws enabled, you can bring an existing configured local agent under Claw management while keeping its ID and workspace. Preview the migration plan before applying it using the Claws guide. It adopts supported settings and selected prompt files, leaving credentials and conversation data outside Claw ownership. Removing an adopted Claw retains the original resources, but older Claw readers reject the new ownership format.
Changes and sources
- Experimental Claw migration previews enrollment of an existing configured agent and retains its original resources on removal. #162329. Thanks @Patrick-Erichsen, @sasan1200, @jalehman.
Plugin state and conversation endings
Loaded local, linked and community plugins can save their own managed state and incoming-message queues, with storage limits and trust requirements for privileged operations retained. Normal stops and restarts preserve plugin session state. Disabling or removing a plugin still deletes that state, and earlier losses cannot be recovered.
Plugins can adopt a reader for the end of a conversation, including after a reset, without accidentally reading its replacement. External plugins must opt into conversation access and read within the handler's lifetime. Tracked start and end work can also finish after the request closes.
Changes and sources
- Ordinary stop/restart preserves plugin session state and reports settled callback errors as named warnings. #164975. Thanks @steipete.
- Every loaded plugin can save its own managed state and process durable incoming-message queues without the former storage trust refusal. #165063. Thanks @steipete.
- Delayed session-start and session-end callbacks can finish after the triggering request closes, including
/newrollover. e9e1134c1809. Thanks @xialonglee, @vincentkoc, @Patrick-Erichsen. - Adopting session-end plugins can read an authorized bounded tail of the ended conversation during the handler lifetime; external plugins must opt into conversation access. #161451. Thanks @ekinnee, @jalehman, @PaulClawitzki, @xydigitLybnnnn, @azuretek.
Plugin authoring APIs
Plugin authors can wait for conversation history, session changes and provider replay metadata to be saved before using the results, with similar methods for workspace results, publication and Mention Inbox. Follow the persistence migration guide, especially for transcript rewrites that require awaiting both preparation and its returned commit. The documented synchronous adapters remain during the compatibility window.
Plugins can subscribe to session changes instead of repeatedly reading everything, with cleanup and fallback reads for changes outside the subscription. Authors also gain draft-reset controls and reusable meeting builders and thread-binding validation.
Changes and sources
- Plugin authors can await session history, extension changes and replay metadata. Transcript rewrites require awaiting both preparation and its returned commit; see persistence migration. #163264. Thanks @steipete.
- Awaited workspace-result and publication readers are available alongside deprecated synchronous adapters that retain their return values and completion timing. #163819. Thanks @steipete.
- Plugins can subscribe to changed session keys and invalidation tags, with unsubscribe and fallback reads for changes outside the subscription. #163820. Thanks @steipete.
- Mention Inbox uses background storage and settles accepted records and dismissals on orderly shutdown; plugin authors gain awaited methods while synchronous methods remain with deprecation warnings. Publication callbacks must send their response synchronously and await dependent mutations afterward. #164291. Thanks @steipete.
- Plugin authors can retain a draft throttle deadline during reset and defer stale-message retirement through optional lifecycle arguments. #162219. Thanks @steipete.
- Meeting authors can reuse documented browser-adapter and page-script builders for existing Zoom, Teams and Slack huddles behavior. 19f112eaabcb. Thanks @steipete.
ChannelThreadBindingsSchemaexposes existing validation through the channel-config-schema facade for reuse by plugin authors. 1a158881cd01. Thanks @steipete.
ClawHub release inspection
Client developers can show available README text, release notes and trust information for a selected ClawHub plugin or skill release before a user decides to install it. Missing information stays explicit, including incomplete capability summaries and unknown download availability; inspecting a listing does not authorize installation.
Changes and sources
- Client developers can retrieve selected ClawHub plugin and skill release details before installation, with missing metadata and incomplete remote capability summaries explicit. #163460. Thanks @jacobtomlinson.
Roles by verified GitHub login
Team administrators can assign roles by verified GitHub login before people first sign in, then see each person's effective role and its source. Explicit assignments take priority. Mappings use the cached verified primary identity, and applying changes immediately requires live configuration reload.
- Optional
gateway.roles.assignments.byGithubLoginmappings use the cached verified primary GitHub login. An explicit role assignment takes priority, then the mapping, then the default; administrators can see the effective role and its source. #163825. Thanks @steipete.
Visitor invitations and revocation
Visitor Access can invite a GitHub account with a private email and keep the invitation attached to the account when its login changes. Administrators can revoke a person's recorded invitations across verified email aliases or cancel one before first sign-in, preserving saved work and independent access.
GitHub invitations need an existing verified Cloudflare OIDC account-ID mapping. Choose a single GitHub or email target and use the profile or invitation ID for revocation. Person-wide revocation requires host support and ends recorded grants, so independent access can remain. See the user model and identity requirements.
- Visitor invitations accept a GitHub selector without requiring a public email. Use exactly one GitHub or email selector and an existing verified Cloudflare OIDC account-ID mapping; the invitation plugin does not configure the sign-in provider. #162666. Thanks @shakkernerd.
- Administrators can revoke a person's recorded visitor grants across verified email aliases by profile ID, or revoke one invitation by grant ID before sign-in. This requires host support and affects the recorded grants, leaving independent access intact. #162207. Thanks @shakkernerd.
- Visitor access lists and revocation use the current verified GitHub identity to avoid matching someone else with the same handle. Explicit email selection takes priority, with exact-email fallback when identity is missing or ambiguous. #160497. Thanks @shakkernerd.
Hosted session network controls
Agents API users can allow, disable or restrict network access for an OpenAI-hosted session. Restricted access matches exact hostnames, so include needed subdomains and redirect destinations. Reset the session whenever you add, change or remove a policy. Hosted stdio MCP requires enabled networking; service-origin remote MCP connections use a separate path. See hosted network controls.
- Agents API hosted VMs can use enabled, disabled or restricted networking with 1–100 exact hosts. Subdomains and redirects need their own entries, and adding, changing or removing the policy requires a session reset. Hosted stdio MCP requires enabled networking. See hosted network controls. #161004. Thanks @sjf-oa, @sjf.
GitHub identity in sandboxes
Administrators can let an agent use its managed GitHub identity while working inside a supported Docker or Podman sandbox. The per-agent opt-in defaults to off and requires suitable nonshared isolation, GitHub tools and authentication, and permitted network access. Recreate the container when mounts change.
Opting in exposes the full selected profile credentials to sandbox code and background processes, including refreshed credentials. A read-only mount still permits credential use, and opting out does not revoke credentials already held by running processes.
- The default-off per-agent GitHub opt-in supports built-in Docker and Podman backends. Missing or insecure managed credentials refuse execution, and security audit reports each opted-in agent. #163784. Thanks @steipete.
Required results and child-agent follow-ups
Agents can use awaitResults:true to wait for needed command and child results, including failures, without repeatedly asking the model to poll. Code Mode resumes the same waiting program within its existing limits. If you adopted the earlier required argument, switch to awaitResults; the old key is ignored.
Parent agents can wait for queued follow-ups and continue active visible or hidden children, with separate answers retained when completions overlap or another task starts quickly. A child waiting for a message still needs an authorized sender to continue it.
Internal work can no longer use a silence placeholder to hide a missing result. If your configuration uses silentReply.internal, use Doctor's normal backup and validation flow to remove it. External-group silence preferences remain supported.
Workflows using sessions_send must explicitly send again to continue an exchange and use message with a channel and target to post to people. Each send returns one peer reply; automatic exchanges and target-channel posts are removed. Isolated scheduled jobs receive inline replies but no detached peer replies or failure notices, and ANNOUNCE_SKIP and REPLY_SKIP no longer control delivery. See session-tool guidance.
Sources and complete change list
- Keep required command and child results pending until collection, resuming the same Code Mode program from completion events. The option introduced as
requiredis nowawaitResults; detached services and existing deadlines retain their behavior. #162707. Thanks to @VACInc, @SparcleAI, @jalehman. - Avoid a stale command-completion message after a visible child agent has already finished. #147432. Thanks to @Tosko4, @obviyus, @VACInc.
- Guide ordinary agents to handle routine work directly and delegate when independent work has a clear benefit. #151599. Thanks to @jalehman.
- Deliver the parent’s answer after private child-agent waiting, following the conversation’s reply policy while keeping child findings private. #156540. Thanks to @obviyus.
- Recover a parent’s continuation after supported failures publishing a completed child result, without repeating the saved change or answer. Recovery waits when the original queued request cannot be verified. #160472. Thanks to @steipete.
- Prepare initial child waits, result handoffs and saved-agent restoration in background storage work, retaining the original caller and interrupted handoff progress. #160778. Thanks to @steipete.
- Read less saved-session data during child recovery. Browser cleanup leaves tabs untouched and asks for an update when the installed Browser lacks the required cleanup support. #160831. Thanks to @steipete.
- Preserve a resumed child’s time allowance within the same session. Restart-recovered work and older records without session identity use ordinary agent policy, normally 48 hours unless that policy is unlimited. #161078. Thanks to @steipete.
- Notify a parent when a completion-announcing child explicitly pauses for a message. The parent must send the continuation; already-paused records receive no retroactive notice. #161114. Thanks to @steipete.
- Wait for accepted watched follow-ups to existing children, including queued work, and retain their separate answers. If steering reports
sentBeforeError, inspect the target before retrying. #161130. Thanks to @steipete. - Resume the parent after child completion without completion bookkeeping leaving it stuck or interrupting its reply, including after a restart. #161194. Thanks to @steipete.
- Preserve a waiting agent’s handoff through tool cleanup so it can resume without a premature ended-turn error. #161197. Thanks to @steipete.
- Allow a valid follow-up to a finished child while its completion record is still being saved, using a bounded additional wait while still rejecting retired callers and replaced runs. #161279. Thanks to @steipete.
- Avoid unnecessary parent replies for successful child tasks that request no announcement, alongside the explicit single-reply delivery rules. #161542. Thanks to @steipete.
- Keep a finished private child’s answer available when its parent checks status before yielding. #161820. Thanks to @steipete.
- Return one peer reply from
sessions_send. Continue with another send and post to people with an explicitmessagecall. Usemessageanddelivery.status; the old aliases,delivery.mode,ANNOUNCE_SKIPandREPLY_SKIPcontrols are removed. #162227. Thanks to @steipete. - Record a failed or timed-out child’s explanation in its own transcript when it has not produced an assistant reply, even after the requester finishes. #162297. Thanks to @steipete.
- Let eligible peer and child replies arrive after the requester’s original turn ends. A nonblocking send waits for handoff; revoked access, restart or lost ownership can still stop later delivery. #162299. Thanks to @steipete.
- Show the normal waiting acknowledgment for an accepted child message wait instead of a false missing-continuation warning. #162306. Thanks to @steipete.
- Include a successful child with an empty final reply in the parent’s result batch, retaining its task identity and explicit no-output result without reviving old text or intentionally silent announcements. #162542. Thanks to @steipete.
- Retain delegated follow-ups until their answer is processed and recover missing answers without repeating completed tool effects. Doctor removes retired
silentReply.internalsettings using its normal backup and validation path. Worker-upload cancellation also avoids an unhandled file-opening error. #162567. Thanks to @steipete. - Preserve the parent’s wakeup when sibling child tasks finish together, and prevent delayed result reads from overwriting newer retry timing or counts. #162760. Thanks to @VACInc.
- Keep compact child-agent lists consistent with full lists when a saved record repeats metadata fields. #163135. Thanks to @steipete.
- Preserve parent wakeups when child completions overlap yields, pauses, cancellation or recovery. #163195. Thanks to @steipete.
- Use the child’s recorded owning agent for follow-ups, steering and cancellation when session keys overlap. Older records without an owner retain key-only matching. #163282. Thanks to @steipete.
- Allow completed-child cleanup to notify its context engine after the initiating request ends, and show readable redacted errors when cleanup fails. #163331. Thanks to @steipete.
- Retain a child’s completed first answer when another ordinary task starts before delivery, keeping separate answers. Paused continuations and steering retain their replacement behavior. #163352. Thanks to @steipete.
- Deliver required child results when silent siblings share the batch, while silent-only work can finish cleanup without starting an unnecessary parent reply. #163677. Thanks to @steipete.
- Avoid a false browser-cleanup failure when another completion callback or newer child run owns cleanup. #163741. Thanks to @vincentkoc.
- Suppress obsolete pause notices after a quick default child follow-up; later follow-up adoption preserves eligible replies for the original requester. #163814. Thanks to @steipete.
- Deliver an eligible still-running plugin follow-up once when it was accepted just before a child pause. Completed-before-pause follow-ups and restarts before adoption remain outside this repair. #164101. Thanks to @steipete.
- Allow active registered visible and hidden native children to wait for incoming messages. An authorized sender must provide the continuation, and required background results still need collection. #164463. Thanks to @steipete.
- Let queued shared-compute work reach another eligible worker checkpoint instead of repeatedly targeting a worker waiting for a host response. #164537. Thanks to @steipete.
- Accept a completed child’s follow-up while browser cleanup is pending, keeping old cleanup from taking over the replacement. b725cc7. Thanks to @steipete.
- Deliver completed child results when unrelated bookkeeping changes during delivery preparation, while rejecting genuinely replaced replies. dab6c79. Thanks to @steipete.
Native conversation imports
You can keep a readable copy of a native-tool conversation in OpenClaw using Import to OpenClaw or the sessions import CLI. Repeat imports append unseen items when you use the same agent and full source locator. New copies are creator/admin-visible drafts when drafts are enabled, otherwise configured defaults apply.
Import needs a reachable source and copies text, leaving native files and native-tool resumption with the source. Large conversations retain only the newest portion within provider and import limits, with incomplete copies reported. Use consistent source-home selection to avoid duplicate copies; identical items without stable IDs can be skipped once the import window fills.
Sources and complete change list
Shared-session assignment
Channel users can again ask an agent to assign a visible work session to a registered person or configured agent. This identifies who is responsible without transferring access or credentials. Using “me” requires an administrator-attested profile link.
Keep private information out of an assignee's personal instructions. Those instructions can apply to later turns from other participants in the shared session.
Sources and complete change list
Managed worktrees
Hidden native child agents can use separate managed Git checkouts and report back without adding persistent sidebar sessions. Keeping a child retains its checkout; deleting it saves a snapshot first. These options do not support ACP or hidden cloud placement.
Eligible new private Docker or Podman worktrees can reuse pnpm dependencies after a verified first installation. Unsupported or failed preparation leaves a source-only checkout, and existing sessions do not automatically reinstall after lockfile edits. Slow Git preparation can also keep its allocation alive until it finishes.
Worktree creation uses the running local Gateway and requires operator.admin. Upgrade an older Gateway or stop it to use the supported offline path. If the creation result is uncertain, inspect worktrees list --json and the repository before retrying.
Sources and complete change list
- Give hidden native children separate managed Git checkouts without persistent sidebar sessions. Keep retains the checkout; delete saves a snapshot before removal. ACP does not support these worktree options. #163124. Thanks to @steipete.
- Reuse verified pnpm dependencies in eligible new private Docker or Podman checkouts. The first generation installs them; failed or unsupported preparation falls back to source-only files. Existing sessions keep independent checkouts. #164517. Thanks to @steipete.
- Create worktrees through the authenticated local Gateway with
operator.admin, or through the supported exclusive offline path. Upgrade or stop older Gateways, and inspect the worktree list and repository after an uncertain result before retrying. #163853. Thanks to @steipete. - Coordinate in-process setup of the same local workspace through bootstrap and sandbox preparation. Cancelled or revoked queued requests stop before creating files; separate directories remain independent. #164377. Thanks to @steipete.
- Retain allocation renewal during slow Git preparation. Fetches skip inline automatic maintenance, which moves to hourly cleanup or
worktrees gcwith a 30-minute maintenance timeout. #164521. Thanks to @steipete. - Keep allocation renewal during long worktree creation and restoration while deferring automatic Git maintenance. b8f5fea.
Paired devices and remote workspaces
Agents on paired devices regain permitted web, memory, session, installed-skill and GitHub identity tools while file and process work stays on the device. Larger tool batches queue, and browser or computer access depends on the device's capabilities. See node session hosting and cloud-worker guidance.
Windows workers can return edits from deeply nested repositories, while already-running workers on supported Linux paired devices spend less time finishing replies. Update the native node host for the Linux improvements; refreshing the worker bundle alone is insufficient. Replies still wait for saved workspace changes and report conflicts or failures. Replacement work waits when the old remote work cannot be confirmed stopped.
Sources and complete change list
- Wait for cancelled remote work to finish entered workspace changes and process cleanup before starting replacement work. An unconfirmed remote stop can keep the replacement waiting. #161759. Thanks to @RomneyDa, @sallyom, @steipete.
- Keep an existing cloud worker’s original session and workspace when main-session aliases change, removing that cause of recovery and Stop failures while new requests still follow current aliases. #163133. Thanks to @steipete.
- Reduce reply-completion overhead on supported Linux paired nodes by reusing the native watchdog connection. Update the native node host; a worker-bundle refresh alone does not enable it. #163866. Thanks to @steipete.
- Reuse an idle native helper for already-running supported Linux paired-node workers. Update the native host; final replies still wait for saved workspace reconciliation and show conflicts or failures. #163954. Thanks to @steipete.
- Pause advisory disk probes and repeated warnings while a paired device is offline or session hosting is disabled. Keep its workspace and last sample, then refresh on the next scheduled sweep after reconnecting. #164048. Thanks to @jayzhou2309, @steipete, @wynxo.
- Reject cloud-workspace uploads after the result loses authorization, and wait for local recovery and any started upload before releasing the transfer. #164104. Thanks to @steipete.
- Overlap worker-bundle download with runtime installation during Crabbox setup, and stop the owned installer before removing temporary files on failure or cancellation. #164187. Thanks to @steipete.
- Restore permitted Gateway web, memory, session, installed-skill and GitHub identity tools to node-hosted agents. File and process work stays on the node, larger tool batches queue, and browser/computer tools depend on placement capabilities. #164296. Thanks to @steipete.
- Return Windows worker edits from deeply nested Git repositories using command-scoped long-path support. The repository’s saved setting stays unchanged; other Git clients may still need their own long-path setting. #164331. Thanks to @steipete.
- Reject changed or missing worker session targets before workspace preparation starts. be13aee. Thanks to @steipete.
- Load the remote turn runtime after admission and tool validation, avoiding preparation for rejected or cancelled work. Verified installations include the required split runtime files. 4aa24e3. Thanks to @steipete.
- Show a worker’s failed status and recovery reason after cleanup. Worker commands avoid secret-store reads from temporary local state, while separately delegated GitHub credentials remain available when supplied. 2e33b81. Thanks to @steipete.
Heap and CPU profiles
Operators can capture up to 15 minutes of live-only Node Gateway heap samples to investigate new allocations that survive the capture. Including already-collected objects keeps the 30-second limit. Heap and CPU profiles now identify dependency packages and frames without JavaScript source while hiding detailed paths, versions and function names. See diagnostics guidance.
Sources and complete change list
- Allow up to 15 minutes of live-only Node Gateway heap sampling. Including objects collected by either garbage-collection flag retains the 30-second cap; profiles describe allocations made during capture that remain at its end. #163813. Thanks to @steipete.
- Identify dependency packages and frames without JavaScript source in heap and CPU profiles, while hiding detailed dependency paths, versions and function names. Package/native labels change the redacted-node counts, and native labels do not identify a specific allocator. #163922. Thanks to @steipete.
Plugin traffic in monitoring
Prometheus and OpenTelemetry now identify registered plugin and auxiliary traffic by method name. Update dashboard queries for registered traffic moving from other to named methods and generic traffic moving from unknown to other. Prometheus can still drop new series when its shared sample cap fills, with omissions recorded by the dropped-series counter.
Sources and complete change list
Fixes and refinements
Installation and Onboarding
- Model setup lets you correct a bad LM Studio or llama.cpp address and continue. If the Gateway restarts during web setup, a successful settings refresh can reopen provider selection or offer verification of a saved model. Check again retries a failed refresh; a saved model still needs verification. See the setup reference.
- You can use guided
agents addto recreate a fully deleted agent after cleanup finishes, with copied or new sign-in credentials. Starting a Gateway directly or in a container also checks whether another Gateway already owns its saved data, even on another port; startup may wait up to five minutes before reporting the conflict. - If replacing a sign-in fails, setup restores the previous credential before reconnecting. Copilot setup can reuse an authorized saved token or secret reference on the same host domain; changing domains still requires a fresh login. Rerunning setup preserves trusted-proxy sign-in unless you explicitly change it; combining it with Tailscale Funnel is refused, so choose password sign-in or leave public exposure off.
- Mobile Settings links work with a custom web-interface path when pairing uses a new code. Affected clients need a new code and must re-pair. Setup also shows its fixed welcomes and choices in the selected Simplified or Traditional Chinese language.
- The configuration examples no longer suggest an accidental ten-minute limit for an entire agent run. If you copied it into your settings, remove or change that override yourself. Multi-agent examples now explain which agent owns the data and receives each conversation. After a manual binary upgrade with a legacy agent roster, run
openclaw doctor --fixbefore startup; the roster migration guide covers configurations split across files. - Installing in a macOS VM has clearer guidance for the installer, Node, npm and background service setup in the VM guide. Check Node platform requirements; reported CLI operation on older macOS does not make those systems supported. Source installs without Corepack use the checkout’s pinned pnpm version. Canvas build fallbacks also reject incomplete renderer bundles.
- The optional macOS DNS guide explains what happens when Homebrew times out or is terminated. Fresh installs with no Matrix configuration or old Matrix data no longer receive an irrelevant migration warning. Configured installations and incomplete scans retain the migration checks.
Sources and complete change list
- Recreate a fully deleted agent with its previous ID through guided
agents add, using copied or new sign-in credentials. Recreation remains blocked while deletion cleanup is pending. #143991, thanks to @Giannoulakos, @ioannis-giannoulakos, @steipete and @Arslan-Mehmood1. - Configuration examples drop an accidental 600-second limit on the whole agent run. Existing copied configurations need a manual change, and the runtime default is unchanged. #158513, thanks to @HunterStile, @100yenadmin and @obviyus.
- Starting a Gateway directly or in a container now prevents a second instance from sharing state already owned by a running Gateway, even on another port. Startup can wait up to five minutes before reporting the conflict. #160193, thanks to @steipete, @grtninja and @R3NK0R.
- The fresh macOS VM guide uses the existing installer to provide Node and npm, then directs you to stop the foreground Gateway with Ctrl+C, run
openclaw gateway install, and check status before headless setup. #160239, thanks to @samadarsh. - Source-install instructions without Corepack now select the pnpm version pinned by the checkout, removing its integrity suffix before installation. The required install scripts and optional dependencies remain part of the instructions. #160513, thanks to @Irish-Joseph.
- Correct an invalid local-model server address in either web or terminal setup. LM Studio and external llama.cpp addresses accept HTTP or HTTPS without embedded credentials, and shorthand addresses still work. #160720, thanks to @steipete.
- Optional macOS DNS setup explains when its Homebrew-prefix lookup hits the existing 15-second timeout or is terminated. The messages clarify a failed step without adding a new timeout. #160797, thanks to @ericcurtin and @steipete.
- When a normal source build falls back to prebuilt Canvas assets, it now rejects an incomplete renderer set instead of accepting a bundle missing a required version. #161390, thanks to @steipete.
- New mobile QR and setup codes retain the Control UI mount path in setup and join addresses, fixing Settings links that returned 404. Affected clients need a new code and must re-pair. #161620, thanks to @Marvinthebored, @Peetiegonzalez and @Patrick-Erichsen.
- The setup welcome and options follow your selected Simplified or Traditional Chinese language even when it differs from the browser language or translations are still loading. #162913, thanks to @steipete.
- macOS documentation distinguishes Node's official macOS 13.5 build target from reported CLI and Gateway operation on macOS 12 with Node 24. Older macOS remains unsupported and untested, and native binaries and the app have separate requirements. #163324, thanks to @NovaUnboundAi, @xXG0DLessXx and @Patrick-Erichsen.
- Multi-agent documentation uses the correct configuration shape and makes ownership and routing explicit. If you manually replace the binary while keeping a legacy configuration, run
openclaw doctor --fixbefore startup. Normal updates already run Doctor through their backup flow. #163475, thanks to @steipete. - Web model setup can recover after a Gateway restart by successfully refreshing saved settings. A saved model needs explicit verification before continuing. If the refresh fails, the setup guard stays in place and offers Check again. #164602, thanks to @steipete.
- Fresh installations avoid irrelevant Matrix migration work when Matrix is unconfigured and a complete scan finds no legacy state. Configured Matrix installations and incomplete scans retain the migration checks. #165209, thanks to @steipete.
- If replacement sign-in credentials fail to activate, the previous saved credential is restored before reconnecting. cd75f44, thanks to @steipete.
- Interactive Copilot setup recognizes a saved token or secret reference already authorized for the same host domain. Secret references stay references, and changing domains requires a fresh login. 332e4d3, thanks to @steipete.
- Setup reruns preserve trusted-proxy sign-in and its trust policy unless you explicitly change them. Completion checks use the configured local Gateway and its local password, preserving secret references. An incompatible Tailscale Funnel choice is refused before rewriting the policy. 1f74f3c, thanks to @wangmiao0668000666 and @steipete.
Web UI
- Organizing chats keeps the list in step with your actions. Custom groups survive
/newand/reset, marking a chat read does not move it up the list, and confirmed Archive, Restore or Undo appears immediately. Sidebar Reset restores Display settings as well as Filters, and titles drop outdated decorations when the profile or connection changes. - Short chat panes keep Send and Stop within reach, and restricted drafts retain their text and attachments. A failed camera preview leaves the camera action available; confirming composed characters no longer sends or saves the affected draft. Comment editors remain readable while scrolling, completed work keeps its widgets in order, and saved safety refusals explain why a partial answer stopped.
- Opening and navigating long chats requires less repeated download, history and layout work, while keeping your reading position and Stop available. After a restart, normal agent preparation shows Starting up and loads chat and sidebar data when ready. Reconnect bursts prioritize establishing connections, so initial session lists can take longer. Older tabs whose retained files were pruned need to reload. Restricted container deployments need a repaired image installed or built to apply the whole-UI 503 repair.
- Workspace folders: Workspace views open the prepared checkout and keep invalid folder text available for correction. Native Windows workspace creation handles deeper repositories, with cross-drive and deep-reference limits remaining.
- Browser terminals: Browser terminals preserve pending output, wait for overlapping shutdowns to finish before reopening, and advertise supported RGB colors.
- Widgets: Widgets follow supported themes, let scrolling continue into chat and keep controls usable beside the browser dock.
- Video previews: New video previews can download media before Play.
- Tool activity names the tool that ran and shows whether it is still running, finished or has an unknown outcome. Activity also corrects time-range totals, screenshot strips and filters; assignment menus offer one searchable list of loaded people and agents, and Mention Inbox failures retry on schedule. Eligible Activity changes appear immediately from session events, but compact lists can still retain some previous-model details after a model change.
- Model choices: Choosing a model focuses search immediately, keeps long choices readable and distinguishes configured Codex alternatives.
- Credentials: New credential fields accept the full masked value while stored redacted secrets stay protected.
- Preference edits: Preference-only edits avoid an unnecessary restart when plugin defaults arrive between loading and saving.
- Browser and client updates: Browser selections saved before July 1 need reselection, with conversations preserved; unsupported v2026.6.1 web clients need a supported client.
- Community invitations: Community invitations now offer Reddit, Discord and X and may appear once after an older dismissal; opt-out and later dismissals remain honored.
Sources and complete change list
- Custom workspace-group defaults show the required admin access and offer Retry after folder inspection fails. Saving still requires permission and a successful inspection. #139024. Thanks @LiuwqGit, @hewal-dev and @obviyus.
- Long model names wrap inside the model menu while the closed picker stays on one line. #150464. Thanks @SunnyShu0925, @dh-js and @obviyus.
- Sessions avoid unnecessary refreshes when their effective settings are unchanged. Changed values and resolved secrets still refresh them. #155300. Thanks @azuretek, @obviyus, @VACInc and @jbfranklin.
- Pasted-text and grouped-comment attachments load near the visible conversation or when focused, keeping keyboard focus as their details arrive. #156277. Thanks @vincentkoc.
- Simplified Chinese displays the existing translations for Approvals, Telemetry and Cloud Workers. #157414. Thanks @chaitongxue.
- The browser dock and embedded panels share page space without competing layouts. Panel guide. #157533. Thanks @sonofakel and @obviyus.
- Reading a conversation clears its unread marker without making it more recent. Marking it unread can still change its position. #158577. Thanks @sxh313, @hannesrudolph and @obviyus.
- Context-usage warnings mark estimated values as approximate. #159549. Thanks @steipete.
- Checking for a pending question avoids rereading history that cannot contain it. #159556. Thanks @Marvinthebored and @Peetiegonzalez.
- Enabled sidebar progress can show tool icons on a second line while retaining readable activity text and accessible names. #160066. Thanks @steipete.
- Split-dashboard widgets use one full-width title, with resize controls in the task menu. #160117. Thanks @steipete.
- Cold remote conversations can show the transcript earlier, and permitted favicon reuse avoids repeat downloads within the current credentials. #160293. Thanks @steipete.
- Use device camera remains available after a denied or failed preview so the browser can handle another camera attempt. #160359. Thanks @steipete.
- Selected-text comment pins avoid unnecessary repositioning when new content streams below their source. #160799. Thanks @steipete.
- Large sidebars avoid repeated work on unrelated updates while activity subtitles continue refreshing. #160876. Thanks @steipete and @jalehman.
- New channel conversations retain an already-known sender name for the sharing Owner field. Older conversations and missing names keep their existing fallback. #160923. Thanks @stevenlee-oai.
- Theme-aware inline widgets can follow dark mode where their widget theme messages support it. #160940. Thanks @steipete.
- The navigation rail uses the configured agent identity, with a generic fallback when its name is empty. #160941. Thanks @Patrick-Erichsen.
- Interrupted provider sign-in closes its reserved blank tab and explains the reconnect or startup timeout. Check again handles a sign-in whose result is no longer known. #160954. Thanks @obviyus.
- A restricted composer explains why sending is unavailable and retains its draft and attachments. Queued sends recheck access for the relevant agent. #160977. Thanks @stevenlee-oai.
- Host-information views avoid unauthorized requests and retire stale results. Host statistics stay unavailable when the account lacks access. #160982. Thanks @Patrick-Erichsen.
- Accounts with portal read access can open the panel, while previews require write access. Accounts without read access see an access explanation. #160984. Thanks @Patrick-Erichsen.
- Focusing an embedded dashboard dismisses Inbox without taking focus or discarding notes. Ordinary window blur leaves it open. #160997. Thanks @vyctorbrzezowski.
- Scroll to latest shows hover feedback. #161009. Thanks @vyctorbrzezowski.
- Review and Files follow a newly ready checkout during the first run, keeping an existing diff on same-workspace refreshes and showing no changes while preparation is pending. #161010. Thanks @steipete.
- Activity screenshot strips use downloadable images, retain their layout during refresh and show an unavailable tile when a remote image fails. Large images require a reachable download reference. #161021. Thanks @steipete.
- Bun-based Gateways reuse their state reader during startup to reduce congestion that could delay sign-in and conversation lists. #161040. Thanks @steipete.
- Activity totals use the complete matching time range, including sessions beyond the displayed list. The all-time chart shows the latest twelve months of activity. #161060. Thanks @steipete.
- Channel
/newand/resetkeep custom conversation groups. #161066. Thanks @jayzhou2309, @catnipluss and @obviyus. - The Applying indicator animates before the settings page finishes loading. #161102. Thanks @steipete.
- Short chat panes and installed-app canvases keep the editor and Send or Stop controls reachable. Very short panes may hide the transcript to make room. #161134. Thanks @hxy91819.
- Confirming composed characters keeps the chat draft, annotations and rename input from acting on that same Enter key. #161302. Thanks @NianJiuZst, @obviyus and @stbtyx747.
- Enter on a hovered Assign to control keeps the person menu open instead of assigning the session to yourself. Multi-user guide. #161393. Thanks @steipete.
- Conversation links discard old or late titles after Gateway, profile or connection changes while the underlying link remains usable. #161433. Thanks @steipete.
- Sidebar Reset restores visible Display settings alongside Filters, while preserving hidden all-agent preferences. #161437. Thanks @vyctorbrzezowski.
- New conversations avoid repeated background reads when their parent is missing while showing the new row and slash commands promptly. #161442. Thanks @steipete.
- Feature-reference navigation restores its existing anchor and removes the retired Tasks entry. #161453. Thanks @steipete.
- Collapsed completed work keeps widgets and browser previews in their execution order. #161473. Thanks @steipete.
- Confirmed non-Git folders hide checkout controls, and switching from cloud or device storage to local does not carry forced isolation. A failed Git check requires a successful retry before creation. #161475. Thanks @steipete.
- Conversation image previews gain faint borders that follow the theme. #161478. Thanks @vyctorbrzezowski.
- System and danger notices have balanced spacing in desktop and touch conversations. #161479. Thanks @vyctorbrzezowski.
- Chat activity uses tool icons with exact names on hover or through assistive technology, while expansion keeps the details and outcomes available. #161483. Thanks @steipete.
- The permission picker uses a compact icon with a named menu, tooltip and accessible label. #161484. Thanks @steipete.
- Open person cards retain up to three already-loaded accessible conversation links, keeping their targets steady while times and presence update. Removed entries do not refill until the card is reopened. #161493. Thanks @vyctorbrzezowski.
- Screenshot-only recap updates no longer leave a misleading omitted-messages notice. Genuine omitted messages still show the notice. #161518. Thanks @steipete.
- Assignment failures display the Gateway error, and the current owner is checked and disabled in the picker. #161562. Thanks @steipete.
- Eligible same-origin HTTPS still screenshots can use a smaller preview while opening keeps the original. Animated images and failed or larger conversions keep the original preview. #161602. Thanks @steipete.
- Short history pages avoid parsing older messages that are already indexed. #161638. Thanks @steipete.
- Initial Control UI loading makes fewer JavaScript requests, with remote desktop available when opened. #161648. Thanks @steipete.
- Signed-in startup avoids premature sign-in downloads and duplicate matching self-avatar requests. Authentication rejection still loads the sign-in view. #161649. Thanks @steipete.
- GitHub hovercards bound their upstream wait and can omit optional pictures or coauthors. Slow required information offers a retryable unavailable result; a partial card may need refresh. GitHub guide. #161653. Thanks @steipete.
- Branch statistics include untracked text files whose names start with whitespace. #161723. Thanks @steipete.
- Returning to Live activity restores the active tool filter, including after an older unselected tool disappears. #161860. Thanks @steipete.
- IP-location labels recover when their component returns, ignore late detached results and clear when the address disappears. #161911. Thanks @steipete.
- Switching through large rosters avoids unnecessary archive lookups for ordinary and restored conversations. #161995. Thanks @steipete.
- Long-chat local saving reduces repeated serialization and uses idle time when available, with immediate saving on lifecycle changes. #162004. Thanks @steipete.
- Live conversation updates avoid an unrelated display-refresh wait. Slow subscriptions gain diagnostic phase logs. A scoped restoration check lets Windows update cleanup proceed after interruption; it cannot repair an older update already in progress. #162013. Thanks @steipete.
- Typing, streaming and scrolling through loaded long conversations avoid repeated history processing. #162035. Thanks @steipete.
- Large-session views and long chats reduce repeated local run checks and saved-stream selection while keeping Stop available. #162092. Thanks @steipete.
- Confirmed Archive, Restore and Undo update the loaded sidebar immediately, without waiting for a separate event or page reload. #162208. Thanks @steipete.
- Model choices distinguish configured Codex alternatives with a codex suffix when both runtimes are offered. A single runtime keeps its plain label. Model guide. #162292. Thanks @steipete.
- Opening the Control UI no longer downloads as much Review display code before it is needed. #162294. Thanks @steipete.
- System busyness expand and minimize animations survive unrelated updates and still respond to real size changes. #162315. Thanks @steipete.
- Conversation titles no longer gain repeated translated prefixes when those prefixes contain punctuation, and hiding the prefix works too. #162331. Thanks @steipete.
- Cmd+K on Apple devices or Ctrl+K elsewhere opens the command palette from a normal-chat dashboard widget. Escape returns to the same input, caret and draft. #162369. Thanks @vyctorbrzezowski.
- Cold New Session loading downloads less initial JavaScript and makes fewer requests. #162382. Thanks @steipete.
- Existing translations cover import results, admin access to folders outside the workspace and catalog-check guidance. #162451.
- Saved OpenAI safety refusals that contain only an older code now display their explanation and guidance beside a partial answer. #162469. Thanks @steipete.
- An eligible web-chat attempt that stalls before answering can make one recovery attempt in the same conversation. Failure leaves retry guidance; personal or workspace skill-write permission requires a fresh user message. Queue and recovery guide. #162490. Thanks @obviyus.
- The browser terminal keeps its pending output and reports the original cleanup error. #162520. Thanks @vincentkoc.
- Chat controls and viewer avatars avoid redundant updates while real content, access and presence changes still refresh them. #162536. Thanks @steipete.
- Tooltips create their popup on first use and reuse it while keeping keyboard focus and accessible descriptions available. #162539. Thanks @steipete.
- Large conversations and lists avoid unnecessary styling work and measure offscreen labels when they first become visible. #162589. Thanks @steipete.
- Switching, scrolling and resizing chats avoid repeated layout work while preserving reading position and end anchoring. #162617. Thanks @steipete.
- Simultaneous clients have more bounded waiting capacity for setup and session requests. Overloaded Gateways can still refuse requests. #162668. Thanks @steipete.
- If both the original and recovery attempts stall before output, Please try again returns instead of leaving the conversation stuck. #162713. Thanks @obviyus.
- Codex reasoning and compaction activity no longer appear as empty completed tool cards. Genuine tool activity remains visible. #162758. Thanks @jayzhou2309, @DarkJuanFra and @obviyus.
- Opening Approvals for the first time avoids initializing unrelated chat and redaction work. #162808. Thanks @steipete.
- Opening the model picker focuses its search without disturbing the unsent conversation draft. #162832. Thanks @eleqtrizit.
- Local workspace icons load without opening chat and can recover after cache eviction, falling back to a folder icon after bounded retries. #162885. Thanks @fuller-stack-dev.
- Offscreen sidebar indicators pause their animation while sessions continue working. #162905. Thanks @steipete.
- Existing translations cover automation-delivery guidance. #162926.
- The first stored conversation after startup can load sooner. #162936. Thanks @steipete.
- Session-only users avoid catalog permission errors, and revoked or late catalog results stop appearing as current. #162944. Thanks @shakkernerd.
- GitHub icons stay beside the first line of wrapped labels in narrow and right-to-left layouts. #163047. Thanks @steipete.
- Hidden retained chat panes pause updates and apply them on return, while visible split panes continue updating. #163073. Thanks @steipete.
- Browser selections saved before July 1 require reselection, with conversations preserved. An old token alone is not restored as a credential. #163083. Thanks @steipete.
- Older open tabs wait for retained UI-file inventory after a Gateway restart. Tabs whose files have been pruned still need to reload. #163090. Thanks @steipete.
- Retained UI builds avoid storing compressed duplicates, keeping earlier tabs usable within the existing three-generation and 96 MiB limits. Earlier-build downloads use larger uncompressed files. #163099. Thanks @steipete.
- The community invitation links to Reddit, Discord and X and renews an old dismissal once. A new dismissal is retained when browser storage is available, and the opt-out setting is honored. #163109. Thanks @hannesrudolph and @steipete.
- The first browser connection after a restart avoids heavier startup-scheduling preparation. #163173. Thanks @steipete.
- Existing translations cover model connections, accounts and billing controls. #163176.
- A failed Mention Inbox refresh retries after a minute instead of waiting for a distant expiry. #163229. Thanks @steipete.
- Enter on an invalid relative folder path preserves the input and listing while keeping that path unselectable. #163284. Thanks @steipete.
- Review stays unloaded when its tab is absent, while an existing hidden Review tab retains its content. #163346. Thanks @steipete.
- Notification settings do less database preparation on the Gateway request thread, with saves completed before pending subscription changes proceed. #163355. Thanks @steipete.
- New credential fields accept the full masked value and receive focus. Previously redacted secrets and structured secret references remain protected and cannot be replaced in these forms. #163487. Thanks @ericcurtin, @jonathanlindsay and @obviyus.
- Paired Codex disconnection keeps guidance to start a fresh attempt. Placement guidance. #163515. Thanks @vincentkoc and @RomneyDa.
- Tool cards distinguish unfinished work from reported success, failure or interruption, including recognized Wait and matching agent-completion events. An unknown outcome stays unknown. #163545. Thanks @RomneyDa.
- Reconnect bursts prioritize connection handshakes and spread retries, which can leave the first session lists taking longer to arrive. #163714. Thanks @steipete.
- The community invitation uses themed light and dark artwork and labeled Reddit, Discord and X controls with larger touch targets. #163734. Thanks @hannesrudolph.
- The community invitation refreshes its copy in the existing translated locales. #163738. Thanks @hannesrudolph.
- Unused vertical scrolling inside an inline widget passes through to chat. New video guidance can load a preview before Play, so it may download media in advance. #163762. Thanks @steipete.
- Concurrent conversation-history reads do less preparation on the Gateway request thread. Local terminal startup also avoids an authentication-reader maintenance race. #163771. Thanks @steipete.
- Add to chat comment editors stay readable while scrolling in desktop and mobile create or edit views. Chat guide. #163772. Thanks @Patrick-Erichsen.
- The Execution permissions heading is separate from Learn more, so clicking the heading keeps the menu open. Permission modes. #163776. Thanks @Patrick-Erichsen.
- Tool Search activity cards show the tool actually called and its query, file or command instead of only the dispatcher. #163829. Thanks @steipete.
- Session status and Workboard digests accept valid observer replies wrapped in plain or JSON code blocks, while rejecting malformed content. #163878. Thanks @steipete.
- Resizing chats avoids redundant redraws while retaining scroll anchoring and hidden-pane geometry. #163898. Thanks @steipete.
- Malformed terminal attachments release their listener, slash commands retain their supplied help text, and MCP setup can continue when the browser has supported cryptography but lacks its UUID helper. #164011. Thanks @steipete.
- The terminal stays closed until overlapping shutdown waits have all ended, preventing partial or duplicate releases from reopening it early. #164014. Thanks @steipete.
- Avatar lookup stops on a temporary primary Gravatar error and tries a secondary address after a definite miss. Unsupported v2026.6.1 Control UI clients need a supported client because the retired configuration route is removed. Migration guidance. #164022. Thanks @steipete.
- PR previews reuse unchanged checkout information while selected-ref, staged, configuration and ancestry changes remain visible on the next read. Unstaged-only counts can stay stale for five minutes, including after refresh. #164035. Thanks @steipete.
- An agent still preparing keeps a startup message instead of a settled failure, even after a minute. #164041. Thanks @RomneyDa.
- Native Windows managed workspaces can be created or reused from deeply nested source repositories that hit Git's metadata-path-too-big error. Cross-drive metadata and separate deep-reference reconciliation limits remain. #164249. Thanks @steipete.
- RGB-aware programs in local browser terminals use their intended colors when the host lacks COLORTERM. Explicit environment choices and catalog overrides retain precedence. #164325. Thanks @ooiuuii.
- Large Claude CLI conversations use ordinary bounded pages and backscroll for local and native-only messages. Initial indexing still scans history, and an unavailable native transcript can still block loading despite readable local history. #164419. Thanks @steipete.
- Completed-work headings spell out elapsed time, with call totals on expansion and non-success outcomes visible while collapsed. Missing timing leaves Worked without an invented duration. #164430. Thanks @steipete.
- Tool activity keeps a readable label such as Wait or Session Status when there is no distinct detail to show. #164437. Thanks @steipete.
- Preference-only edits avoid an unnecessary Gateway restart when plugin defaults become available between reading and saving settings. #164450. Thanks @RomneyDa, @wenwenxiong and @SuperMarioYL.
- Assignment and membership menus show all already-loaded matching people and agents in one scrollable list with search kept visible. #164469. Thanks @steipete.
- Normal agent preparation shows Starting up and automatically loads chat and sidebar data when ready. Preparation can take minutes; real failures keep their diagnostics. #164532. Thanks @steipete.
- Confirming composed characters keeps queued-message editing open and preserves the Side chat draft without sending. A later deliberate shortcut performs the intended save or send. #164560. Thanks @steipete and @NianJiuZst.
- Eligible Activity and Current Work changes appear directly from session events, with smaller sidebar and dashboard list responses. Filtered or incomplete views still refresh, and a model change can leave some compact-row model details from the previous model. #164573. Thanks @steipete.
- Device-control text loads when Devices needs it, reducing the initial JavaScript download. #164735. Thanks @shakkernerd and @steipete.
- Repaired container bundles let restricted arbitrary user IDs read the core Control UI assets, addressing the whole-UI 503 failure. Install or build the repaired image; existing deployments are not changed automatically, and private runtime files remain restricted. #165937. Thanks @RomneyDa and @Conan-Scott.
- New Session ends a stalled model-catalog wait after a shared twenty-second deadline, explains that no session was created and retains the draft for retry. This deadline covers catalog waiting rather than the full workspace setup or first answer. #165989. Thanks @steipete, @DonnieFi and @dprev.
- Chat updates return to on-demand scheduling after removal of the frame wait that could hold working indicators and draft updates. d1dc3cd. Thanks @steipete.
- Direct-linked automation editors and unsaved edits survive delayed initial agent information. Deliberate agent-filter changes and connection retirement keep their existing reset behavior. a7d093b. Thanks @steipete.
- Completed tools stop showing Running while the assistant continues. Without a definite result they show Outcome unknown; partial output alone keeps the tool running. 7b3972c. Thanks @steipete.
- Preparing the bundled web interface checks up to four retained files at once, verifying each before making it available. 4cf8c4d. Thanks @RomneyDa.
Updates and Maintenance
- Update efficiency: Package and source updates do less repeated checking and copying, keep the selected runtime and package manager, and retain recovery tools through replacement.
- Installed updater limits: Several fixes must be present in the installed updater that starts the operation. If an older updater refuses before staging, follow the manual update procedure with a verified backup, then use the new CLI's Doctor and repair commands.
- Windows 2026.9.4 automatic updates: Affected automatic updates from Windows 2026.9.4 refuse an incompatible candidate; wait for the updater to exit, make a verified backup, and update manually from an independent shell using the same account, installation and profile.
- Other Gateways and stopped services: Stop other Gateways and installation-modifying tools yourself during updates; restart sibling Gateways separately. A stopped service stays stopped unless the updater owns its restoration.
- Saving compatible settings during update checks can now be followed by a fresh check instead of an immediate failure. The updater keeps caller and service profiles separate and still refuses incompatible or repeatedly changing settings. Rollback prepares restore copies before moving live databases and refuses restoration that would discard newer changes. Even legitimate Doctor migrations disable automatic restoration of changed databases, so recovery after a later failure may need manual action. See rollback and recovery.
- Update reports stay visible through the final result, keep JSON output parseable and explain failures without exposing private details. An old failure can be labeled historical when the Gateway is ready and serving the intended target; its original result is retained. Eligible Linux update receipts can refresh after the filesystem's device number changes, allowing another update. The initial
update --dry-runpath can also rewrite those receipts, so that preview is not read-only. - Doctor can repair supported session ownership and quarantined data, do less repeated archive work, and repair writable state with read-only configuration. Required configuration edits still belong in the deployment source. Accepted settings and repair permissions remain protected, and explicit recovery references must verify before repair. If Doctor finishes while the managed Gateway is still starting, check
openclaw gateway statusafterward. Empty-transcript recovery can still break another agent's reference to a shared file; keep the originals and backups together at their reported paths. See running Doctor. - Very old configurations and saved-data formats may need an intermediate release before this upgrade can proceed; refusals preserve the old files. Back up complete configuration, state and queue-owned media first. The documented configuration forms need 2026.9.5 Doctor; Matrix's five retired files also need Matrix started once, and older flat layouts first need 2026.6 Doctor and Gateway startup. Retired outgoing/session JSON queues, cron files, encrypted OAuth sidecars, Voice Call logs and nested workspace setup files need 2026.9.7 on the original host, then Doctor. Do not rename migrated queue artifacts to replay messages. Supported July routing aliases, supported JSON imports and current SQLite state remain supported. Follow state migrations, Matrix migrations and incoming-queue migration for the affected format.
- Doctor gives eligible single-file Talk configurations their own saved provider settings, so later Voice Call edits do not change Talk. Configurations split across included files can lose inherited settings and need separate correction; see Talk migration. Supported command-approval policies also receive repair with a private original copy, but ordinary pre-Doctor exports can omit old command permissions or MCP grants. Run Doctor against the correct state directory before relying on an older-format export. Retired embedded session settings and shortcuts require backed-up manual correction; current Doctor does not repair them. Follow session-setting migrations.
- Stopping the Gateway waits for accepted database maintenance and worker cleanup. A plugin cleanup timeout no longer turns a successful message command into a failure, though cleanup can remain pending. A final native-worker cleanup failure leaves that source unavailable until the process restarts. Restarts continue after duplicate configuration notifications, and crash-loop pauses keep interrupted-turn retries for replay after a full stable window. Running or queued work survives an access-policy change only while its original access remains valid. See restart recovery and message commands.
- Containers recognize a verified live owner of shared Gateway data even when process IDs differ between containers. A foreign or unverifiable owner needs a heartbeat older than 90 seconds before eligible recovery; Doctor refuses a fresh unknown owner. Use the documented shared process namespace for a separate Docker CLI container, or run the TUI inside the Gateway container. Windows recovery can re-enable a verified disabled Gateway task while refusing a foreign launcher. See Windows guidance.
- Archive cleanup and integrity checks: Session and archive cleanup moves supported database work into background workers while keeping retention rules and denied-access checks. Automatic five-minute and daily full database integrity scans stop; requested quick checks cover less corruption than those full scans.
- Source Control UI rebuilds: When a source Control UI rebuild fails, the previous bundle is retained, but the wrapper still overrides custom
--outDirwithdist/control-ui.
Sources and complete change list
- Idle browser nodes can update while upload files are retained, with restart recovery for interrupted cleanup. #154384. Thanks @xialonglee, @Patrick-Erichsen.
- Doctor checks that an explicitly selected session store belongs to the requested agent; scripts with mismatched selectors must use its actual owner. #156907. Thanks @Alix-007, @obviyus.
- Older compacted sessions can enter enabled cold storage after the configured idle period while references to required history remain protected. #157994. Thanks @anyech, @obviyus.
- Keeping a deleted agent’s history no longer blocks the affected plugin-store cleanup during Gateway shutdown. #158473. Thanks @anyech, @obviyus.
- Doctor accepts a service home override pointing to the account’s canonical home, restoring the existing credential-repair path. #160056. Thanks @steipete, @oscarsixsecllc, @vincentkoc.
- An already-stopped Gateway stays stopped when Doctor cannot verify its current ownership and offline state; inspect deep status before starting it manually. #160083. Thanks @steipete.
- Doctor can remove abandoned update files beside unrelated Node or Bun apps when readable process and package evidence confirms they do not use those files. #160158. Thanks @steipete, @Marvinthebored.
- Failed-update recovery preserves databases changed during Doctor, including legitimate migrations; restoring those databases then requires manual recovery. #160167. Thanks @steipete, @RomneyDa, @vyctorbrzezowski, @jalehman.
- A restart can skip repeated database scans after idle or finished writers close successfully, even when other shutdown cleanup reaches its deadline. #160201. Thanks @steipete.
- Repair preserves settings for incompatible plugins and finishes pending saved-data confirmation after compatibility is corrected, including when packages are unchanged. #160344. Thanks @steipete, @EndeavorPioneer.
- Eligible database rollback retains current update attempts and failure details while leaving the original snapshots unchanged. #160614. Thanks @steipete, @fuller-stack-dev.
- Updates refuse to replace a shared installation while an observed sibling Gateway is running; stop that service yourself and restart it after the update. #160663. Thanks @steipete.
- Gateways already running this fix retain cleanup code through package replacement and save final speech with heuristic notes; model notes can be regenerated after restart. #160674. Thanks @steipete.
- Windows Gateway inspection and update repair preserve empty arguments, quotes, backslashes and Unicode when identifying running processes. #160680. Thanks @steipete.
- Doctor and plugin maintenance can continue through brief competing database writes without immediately failing admission or losing maintenance ownership. #160702. Thanks @RomneyDa, @Ludwigtheo0815, @laurentschwartz.
- Incompatible automatic updates from Windows 2026.9.4 stop before activation; wait for the updater to exit, create a verified backup and follow the manual update procedure. #160718. Thanks @steipete.
- Busy database writers move automatic checkpoint work away from saving changes, addressing one source of pauses on large stores; idle-worker checkpoint completion remains uncertain. #160818. Thanks @steipete.
- Cloud workers retain their new runtime after a Gateway update until installation is recorded, avoiding a missing-runtime failure on the next turn. #160820. Thanks @steipete.
- Eligible scheduled session cleanup runs in the background and preserves publication records belonging to a recreated session. #160858. Thanks @steipete.
- New request errors distinguish a Gateway restart, shutdown or temporary pause and explain when to try again. #160869. Thanks @RomneyDa.
- Running and queued work can survive live connection-policy changes when its original access remains valid; clients still reconnect, and actual access loss still cancels affected work. #160909. Thanks @steipete.
- A delayed node-connection alert is suppressed when its pairing check finishes after Gateway shutdown begins. #160915. Thanks @steipete.
- Session-history cleanup can resume after its blocking writes are safely checkpointed even while unrelated writes continue; relevant open readers still postpone cleanup. #161061. Thanks @steipete.
- Interrupted update validation waits for accepted progress writes and retains temporary recovery data when their outcome is uncertain. #161104. Thanks @steipete.
- The current automatic source-server update script checks a private candidate before stopping the Gateway; preparation failures preserve the serving installation, while shared sibling services remain yours to stop. #161110. Thanks @steipete.
- Active session updates can commit while background maintenance performs its initial database check. #161181. Thanks @steipete.
- Doctor can recover interrupted imports of old MCP sign-in files without replaying retired credentials or undoing a later logout; uncertain outcomes retain recovery state and warn. #161219. Thanks @steipete.
- Updates and source rebuilds identify discovered sibling Gateways by their actual service name, including loaded Linux services with missing unit files, and explain which service to stop. #161238. Thanks @steipete.
- Source update completion and update repair refuse to replace files used by a discovered running sibling Gateway; stop overlapping services yourself and retry. #161239. Thanks @steipete.
- Unmanaged foreground Gateways can remain alive for manual configuration repair after restart triage declines or fails; requests resume only after startup succeeds. #161294. Thanks @steipete, @dh-js.
- Older updaters no longer falsely report a changed database inventory and roll back because optional ownership details were omitted. #161411. Thanks @steipete.
- Failed update recovery skips waiting for a Gateway known to be absent, while retaining the original failure and restoration checks. #161426. Thanks @steipete.
- Source installations retain the previous Control UI bundle after a failed rebuild and can recover an interrupted replacement on the next build; the wrapper overrides custom --outDir with dist/control-ui. #161438. Thanks @steipete.
- Doctor clears eligible installation-only upgrade warnings for disabled SMS and unconfigured Mistral without enabling the channel or adding settings; real migration work still needs completion. #161535. Thanks @steipete, @akennedytog, @g62nkcx4q7-wq.
- Docker package JSON receipts no longer leave an extra copy of the finished archive in the shared npm cache; initial packing can still use that cache. #161548. Thanks @steipete.
- Shutdown and restart close shared native workers and their supervisor after accepted work finishes; cleanup failures remain visible. #161558. Thanks @steipete.
- Doctor recognizes verified Skill Workshop history archives after their original workspace is retired, stopping repeated warnings while retaining original backups. #161586. Thanks @steipete, @percilabs, @sunlit-deng.
- Updates record and check the previous Gateway’s stop in background database workers while still waiting for durable confirmation before maintenance proceeds. #161813. Thanks @steipete.
- Doctor archives strictly verified empty retired Telegram binding files so updates can continue, while preserving their original bytes and refusing meaningful or uncertain state. #161832. Thanks @ericcaiwx-star, @PennyVibe.
- Managed updates record activation before stopping the Gateway and refuse a stop after ownership changes; accepted rollback can finish during interruption. #161851. Thanks @steipete, @vincentkoc.
- Doctor refuses to overwrite a recovery record after another owner replaces its maintenance files, retaining the existing recovery information. #161861. Thanks @steipete.
- Update recovery loads fewer bundled components while keeping its existing service and recovery checks. #161919. Thanks @steipete.
- Doctor and local TLS Gateway checks work with a managed proxy enabled while retaining loopback routing policy and certificate fingerprint checks. #161946. Thanks @obviyus, @saizero-dr.
- Windows updates run by the fixed installed version restore the original task autostart state after cancellation following successful suspension and before installation changes. #161990. Thanks @steipete.
- Automatic five-minute and daily full database scans stop; requested quick checks provide less coverage for index and page corruption. #162015. Thanks @steipete.
- Doctor moves its initial contended Gateway ownership inspection into a background worker and checks cancellation and permission again before stopping a service. #162021. Thanks @steipete.
- Windows update cancellation can restore previously enabled autostart when disabling the task took effect before reporting failure, provided the original updater still owns recovery. #162050. Thanks @steipete.
- Updates started by the fixed installed updater retain SQLite verification workers after package replacement, avoiding the missing-worker startup failure. #162076. Thanks @steipete, @xilopaint, @paweldrozd.
- Gateway shutdown cancels future background maintenance and waits for running callbacks before releasing resources; stopping one subsystem leaves unrelated schedules active. #162079. Thanks @steipete.
- Updates wait for saved progress before advancing, preserve authorized recovery after recording refusal and retain both operation and reporting errors. #162098. Thanks @steipete.
- Shutdown retains native worker cleanup errors after the supervisor exits; terminal cleanup failure requires a process restart before that source can accept new work. #162128. Thanks @steipete.
- Doctor preserves existing scheduled-task history archives and saves newly imported legacy logs byte-for-byte under a numbered name, warning when archival needs retry. #162152. Thanks @steipete.
- Orderly shutdown waits for accepted database maintenance before closing storage; emergency process-exit cleanup remains best effort. #162166. Thanks @steipete.
- Direct binary upgrades with retired context budgets or the Copilot discovery switch must run openclaw doctor --fix before startup; managed updates apply these migrations before validating settings. #162184. Thanks @steipete.
- Chat-requested updates avoid repeated whole-database copies while Doctor checks current permissions; removing or replacing the requester still stops further changes. #162200. Thanks @steipete, @DasX, @xilopaint.
- Doctor recovers supported old Telegram incoming queues without repeating imports or replaying historical failures; retired outgoing and session JSON queues use the separate 2026.9.7 repair route. #162206. Thanks @steipete.
- Automatic session cleanup stands down during Gateway shutdown, avoiding repeated maintenance-worker startup; later writes can resume cleanup after restart. #162212. Thanks @steipete.
- Doctor skips loading Codex recovery helpers when there is no legacy assignment state to inspect, reducing unnecessary work in empty scans. #162215. Thanks @steipete.
- Windows updates run by the fixed installed updater retry brief package-folder locks during backup for up to 57.75 seconds, retain warnings and explain persistent failures. #162231. Thanks @steipete, @miguelpt2026.
- Doctor reuses its update-history discovery snapshot to reduce repeated reads and offers optional phase timings for diagnosing slow repairs. #162232. Thanks @steipete.
- Fixed npm updaters exclude historical package backups from dependency scans and retire only eligible captured backups after verified activation; older running updaters still need the documented backup-preserving recovery. #162246. Thanks @steipete, @DonnieFi.
- Deleting an agent or running path-scoped maintenance now closes its session cleanup worker when the state directory is reached through a symlink. #162248. Thanks @steipete.
- Update database checks retry transient changes when an inactive agent database becomes active, returning only a consistent snapshot; persistent changes and cleanup failures still stop inspection. #162258. Thanks @RomneyDa.
- Successful update and repair progress is logged as information, advisories as warnings and failed phases as errors, while progress remains on stderr and JSON stdout stays clean. #162270. Thanks @RomneyDa.
- Failed archival of verified empty retired Telegram bindings now warns and preserves the source for retry; uncertain or nonempty files still block migration with readable recovery guidance. #162290. Thanks @steipete, @PennyVibe, @ericcaiwx-star.
- Doctor repairs deep chains of session owners without a stack overflow, preserving the terminal session and conversation history without shortening the chain. #162321. Thanks @steipete, @jasdeepohri-max.
- Failed updates with --no-restart retain recovery diagnostics through one inspection without waiting for unrequested startup, while package activation and required maintenance remain in effect. #162327. Thanks @steipete, @PennyVibe.
- Doctor setting-conflict notices consistently name the full current-setting path when removing an obsolete alias whose replacement is already set. #162336. Thanks @steipete.
- Startup progress no longer hides actual errors from older updaters; reports retain useful redacted error details. #162344. Thanks @steipete, @jamiezigelbaum.
- Updates started by the fixed installed updater avoid repeated whole-database copying and stalls from progress polling while retaining committed phases and the final report. #162345. Thanks @steipete, @xilopaint.
- Fixed installed updaters tolerate narrowly defined npm bookkeeping changes during package rollback and report bounded details about genuine mismatches; older running updaters retain their prior checks. #162365. Thanks @steipete, @nessim-liamani.
- Database backups captured by a fixed installed updater retain their originally verified content facts so rollback can reject later changes before replacing live databases. #162383. Thanks @steipete.
- Source builds skip redundant plugin file checks and preserve tracked special filenames on supporting filesystems; add new auto-discovered packages and entries to the Git index before a root build. #162384. Thanks @steipete.
- npm plugin updates reuse metadata already resolved for the same installation attempt, avoiding a duplicate registry lookup while retaining compatibility, integrity, policy and consent checks. #162385. Thanks @steipete.
- Updates using the repaired verifier warn about non-object plugin manifests and continue checking later plugins, while other configuration, ownership and readiness failures retain their existing handling. #162386. Thanks @steipete.
- Git update staging can use native directory copying when no disposable caches need filtering, avoiding unnecessary staging work while retaining real exclusions. #162387. Thanks @steipete.
- Doctor uses less memory preparing large fleets with equivalent plugin sources, while preserving distinct plugin selections and workspaces. #162394. Thanks @steipete, @609NFT.
- Newer updaters can avoid recopying a private rehearsal database and preserve its original row IDs for migration checks; existing free-space requirements and older-updater limits remain. #162403. Thanks @fuller-stack-dev.
- Doctor prepares unchanged transcript archives before stopping a managed Gateway and reuses verified work on later same-version runs, reducing archive-dependent downtime while rechecking changed or restored sources. #162404. Thanks @steipete, @boeingchoco, @MikyWang, @harshitgupta31415.
- Doctor migrates covered sender tool policies to typed keys such as id:Alice while preserving the first effective policy; direct binary upgrades need Doctor before startup, and external-channel policies may require explicit migration. #162427. Thanks @steipete.
- Update rehearsals avoid redundant backups of verified disposable core database copies while retaining ordinary recovery backups and separate configuration, plugin and Workshop captures. #162429. Thanks @fuller-stack-dev.
- Compatibility checks preserve current values when identifying older sandbox and embedded-agent settings; retired forms follow intermediate-version guidance. #162430. Thanks @steipete.
- Doctor skips unused plugin completion checks when there is no deferred migration or verified retained legacy session source, avoiding an unnecessary detector pass while retaining ordinary repair checks. #162486. Thanks @steipete.
- Supported POSIX npm updates can recover interrupted package replacement with the selected Node or Bun executable, retaining the macOS SQLite library; recovery leaves the Gateway stopped for a separate restart. #162586. Thanks @steipete.
- Doctor backs up and converts older pending-reply, fallback-notice and memory-flush state; sessions that still need conversion request a stopped Gateway and openclaw doctor --fix. #162595. Thanks @steipete.
- Updates with matching recovery receipts can restore the previous package after SQLite moves already-captured data, while still refusing restoration that would discard newer changes; older updater receipt formats remain a limitation. #162599. Thanks @steipete.
- An installed updater containing this fix keeps progress recording from disrupting its own validation copy and reports progress errors without relabeling successful checks as failed. #162604. Thanks @steipete.
- Doctor preserves existing agent data and workspace ownership when converting older rosters; direct binary replacement requires repair before startup or ordinary configuration edits, with extra care for included configuration. #162612. Thanks @steipete.
- Gateway shutdown keeps the database worker available to finish accepted memory writes, reducing repeated worker starts without discarding writes or shortening shutdown deadlines. #162616. Thanks @steipete.
- Doctor preserves previously accepted settings when a plugin repair fails or reports no changes, continues later repairs and retains warning-only guidance. #162641. Thanks @steipete.
- Doctor migrates inherited Talk provider settings in eligible single-file configurations; include-backed configurations can lose those settings and need separate correction. #162644. Thanks @steipete.
- A present but broken channel repair module now stops Doctor with its original load error instead of silently selecting fallback repairs; genuinely absent modules remain optional. #162645. Thanks @wangmiao0668000666, @vincentkoc.
- Bun updates from the supported 2026.9.7 updater can finish candidate Doctor and activate the replacement Gateway instead of hanging; this repair arrives in the candidate package. #162655. Thanks @steipete.
- Once a stop or restart signal is accepted, the Gateway immediately refuses new work while continuing its existing shutdown and restart policy. #162679. Thanks @steipete.
- Doctor repairs supported command-approval policies with a private original copy; ordinary exports before Doctor can omit legacy permissions and MCP grants. Run Doctor against the correct state directory first. #162687. Thanks @steipete.
- Agent deletion and state-root cleanup through symlinks can release execution and history resources retained by archive pruning, preview and related storage maintenance. #162700. Thanks @steipete.
- Rollback prepares restore copies before moving current databases, so allocation or disk-space refusal leaves current databases and journals in place; later publication failures retain recovery files. #162726. Thanks @fuller-stack-dev.
- Doctor retires verified completed plugin-import obligations so later history can be imported, and update cleanup inventories recorded migration backups with guarded retirement after a later successful update; retain backups needed for rollback. #162771. Thanks @steipete, @shadow-enthusiast, @islandpreneur007.
- macOS service diagnostics read the selected Gateway job’s own state and report unknown when launchd output cannot identify that job. #162838. Thanks @steipete.
- Update timeout reports retain the check name, elapsed time and last sanitized progress; old installed updater deadlines still apply and observed progress does not prove completion. #162883. Thanks @steipete, @nachoratico-source.
- Doctor can remove eligible abandoned updater runtimes after its inspection workers finish, identifies independent processes that still block cleanup and advises rerunning repair after their work ends. #162886. Thanks @steipete.
- Failed update reports put plain runtime-check guidance and the selected next step first, and label saved recovery observations so they are not mistaken for current Gateway health. #162887. Thanks @vincentkoc.
- When updates hand finalization to a fresh candidate after schema migration, transferred progress is confirmed in order before finalization; a refused write stops further work. #162909. Thanks @steipete.
- Doctor recovers supported empty transcripts from verified backups or canonical history. With shared owners, recovery may move an empty original before every agent verifies it, leaving another agent's recovery record unable to find the file; keep originals and backups together at their reported paths. #162946. Thanks @steipete, @leoreq.
- Cleanup can release a worker lease after first database creation even when read permission was revoked before its receipt arrived; the revoked operation still fails and leaves the session unchanged. #162950. Thanks @steipete.
- Doctor repairs supported older credential fields independently of unsafe account renames, keeps usable current credentials and verified originals, and gives affected runtime readers the repair command. #162958. Thanks @steipete.
- An updater containing this change reduces repeated filesystem scans while preserving its runtime, with fallback progress inspection retained when copying stalls; older installed updaters do not gain this on their first attempt. #162995. Thanks @steipete, @vincentkoc.
- Update snapshots avoid redundant intermediate integrity scans while retaining source and final checks; the published 2026.9.7 updater’s initial snapshot still uses its older implementation. #162996. Thanks @steipete, @vincentkoc.
- Selected source builds avoid generating pure plugin assets twice while keeping manifest-writing hooks early and validating completed assets before staging. #162997. Thanks @steipete, @vincentkoc.
- Temporary update-validation Gateways skip restoring retained subagent runs, leaving recovery to the serving Gateway while retaining required configuration, database and readiness checks. #162998. Thanks @steipete.
- An updater containing this change verifies package contents with bounded concurrent reads while preserving fingerprints and fresh recovery checks; the benefit applies to verification work rather than a guaranteed whole-update speedup. #162999. Thanks @steipete, @vincentkoc.
- On POSIX, an updater containing this fix settles its retained local database writer before capture, avoiding a false rollback refusal after Doctor errors while still protecting genuine newer data. #163008. Thanks @steipete.
- More retired configuration forms now require the documented 2026.9.5 intermediate repair before upgrading, including old agent runtime, sandbox, Browser, queue, webchat and authored plugin-install formats. #163015. Thanks @steipete.
- The Bun guide explains the installed 2026.9.7 updater’s temporary Node 24 workaround, keeping Gateway and updater on the same runtime and state, and distinguishing restored package files from completed Gateway recovery. #163017. Thanks @steipete.
- The 2026.9.7 Bun workaround now uses the ordinary published-release update by default; a particular version or local package remains optional, with the same readiness and state-preservation steps. #163034. Thanks @steipete.
- Retired pre-July formats receive source-preserving refusals; supported July routing aliases and JSON imports remain separately supported. #163036. Thanks @steipete.
- A repaired updater retries eligible named npm or Bun dependency-cache failures once and preserves safe phase, error-code and package details in reports without exposing commands, credentials or private paths. #163039. Thanks @steipete, @ttcmourao, @akrosliving.
- Archive discovery leaves very old global session files untouched; use a recorded or explicit path to inspect supported history. #163055. Thanks @steipete.
- Doctor preserves unsupported pre-July plugin install JSON and requires the documented 2026.9.5 repair with a compatible pre-update backup; supported SQLite upgrades refresh plugin discovery after schema repair. #163075. Thanks @steipete.
- Maintenance errors identify the operation that first lost access and distinguish storage failure from unavailable ownership. #163103. Thanks @vincentkoc.
- Database heartbeat errors retain ownership-loss details already received before a worker fails. #163134. Thanks @vincentkoc.
- Unconfigured old global session indexes no longer block startup; select the former store explicitly to import its supported history. #163160. Thanks @steipete.
- Doctor restores supported July session-routing aliases while preserving backups; retired room-only grouping still needs an intermediate repair. #163171. Thanks @steipete.
- Retired Telegram DM, thread and streaming settings now require Doctor in 2026.9.5 before upgrading; canonical nested streaming remains supported. #163181. Thanks @steipete.
- Historical encrypted OAuth sidecars stop upgrades without changing state; the documented repair uses 2026.9.7 on the original host, and residual-file recovery is not guaranteed. #163186. Thanks @steipete.
- Five old Talk realtime selectors need 2026.9.5 Doctor; refusal preserves settings and backups, including recoverable prefixed JSON. #163189. Thanks @steipete.
- Cold-storage maintenance selects inactive archives in workers while protecting active sessions and retaining existing limits. #163200. Thanks @steipete.
- Reload checks retire obsolete task-result and singular model fallbacks while preserving supported task envelopes and model settings. #163207. Thanks @steipete.
- Archive retention runs ordinary database cleanup in workers and rechecks changed references and files before deletion; retention rules stay the same. #163218. Thanks @steipete.
- Doctor correctly names the installed plugin index in its existing manifest-drift warning. #163220. Thanks @steipete.
- Old cron jobs, split-state and run-history files require 2026.9.7 Doctor on the original host; supported SQLite jobs and quarantine imports remain. #163221. Thanks @steipete.
- Bun-driven Git updates use compatible Node from PATH consistently for candidate tooling while retaining the chosen Gateway runtime. #163227. Thanks @vincentkoc.
- An obsolete memory-index layout now refuses upgrade without dropping its tables; recovery guidance calls for a July-or-newer backup. #163271. Thanks @steipete.
- Retired agent and subagent model timeout fields require the 2026.9.5 repair step; tool-model timeouts remain supported. #163280. Thanks @steipete.
- Source updates preserve the selected package-manager launcher when the qualified Node directory also contains pnpm. #163310. Thanks @steipete.
- Chat update notices show a short outcome and next step, with full diagnostics in Settings → Updates or openclaw update status. #163318. Thanks @vincentkoc.
- Doctor continues authorized database repairs when an older updater cannot supply capture history, without inventing recovery copies or extending package rollback. #163344. Thanks @steipete.
- Saving restart and update notices moves off the request thread while required saves remain enforced. #163364. Thanks @steipete.
- Doctor archive maintenance avoids repeated full-database hashing and copying while checking current repair permissions. #163369. Thanks @victor-gurbani, @Olli0103, @steipete.
- Updates repeat fewer package scans; completed runtime copies can remain when their layout prevents later cleanup discovery. #163370. Thanks @steipete.
- Git updates keep scoped pnpm ahead of competing copies even when the selected Node directory already leads or repeats on PATH. #163380. Thanks @steipete.
- Five retired Matrix state files require 2026.9.5 Doctor and starting Matrix once; older flat layouts first need 2026.6 Doctor and Gateway startup. Refused originals remain intact. #163383. Thanks @steipete.
- Later npm updates reuse settled file checks to shorten downtime; stop other tools that modify the installation while updating. #163432. Thanks @steipete.
- Optional orphan-result cleanup checks small idle batches after restart and provides fixed Git operation names for diagnostics. #163445. Thanks @steipete.
- Restart recovery checks durable session stores in workers and rejects stale or cancelled results. #163457. Thanks @steipete.
- Routine package-backup cleanup is logged as progress instead of a misleading update error. #163477. Thanks @Patrick-Erichsen.
- npm upgrades retain installation identity through macOS directory aliases while the package directory is temporarily absent. #163479. Thanks @RomneyDa, @vincentkoc.
- Startup Git discovery retries one timeout and reports unavailable facts; exhausted results stay cached, with Dev refresh or restart needed to recover. #163500. Thanks @steipete.
- Unrelated ancestor packages stop falsely blocking update checks, and two matching candidate-Doctor failures pause automatic retries until a new candidate or manual intervention. #163541. Thanks @steipete, @iJaack.
- Legacy memory conversion processes vectors one row at a time, and updated updaters retain crash signals and bounded redacted diagnostics. #163640. Thanks @steipete, @fenglanhua.
- Git update and rollback reports show both recorded version numbers and short commits. #163683. Thanks @fuller-stack-dev.
- Experimental pre-schema-8 session and retired search layouts require complete-copy recovery through 2026.9.7 Doctor; released memory, auth and cache formats stay supported. #163723. Thanks @steipete.
- Doctor guidance distinguishes supported provider-alias repair from the separate 2026.9.5 route for room-to-groupChannel state. #163729. Thanks @steipete.
- Eligible update recovery checks and completes pending shared and agent migrations before restarting; unresolved or newer schemas refuse with manual guidance. #163803. Thanks @steipete, @chffhc.
- Doctor recognizes verified Linux systemd environment overrides and still reports genuinely missing managed settings. #163847. Thanks @steipete, @travellingsoldier85.
- Gateway logs identify the client requesting a valid chat or session stop, including fast requests previously missing attribution. #163851. Thanks @steipete.
- Doctor restores Teams warnings directing retired JSON data through OpenClaw 2026.9.5 and doctor --fix before upgrading. #163896. Thanks @steipete.
- Failed updates retain their specific reason and original installer error on stderr in normal and JSON modes. #163901. Thanks @steipete.
- Verified session-import receipts survive macOS VM device-number changes; Doctor upgrades older receipts without replaying completed imports. #163904. Thanks @steipete, @paulotvlincelia.
- Retired embedded session settings and shortcuts need backed-up manual correction. Setup utility-model selection, inline Pi API inheritance and prototype-named Talk voice aliases also receive fixes. #163919. Thanks @steipete.
- Sandbox permission edits avoid unrelated service restarts; slow service cleanup stays isolated and required restarts retain bounded shutdown grace. #163931. Thanks @steipete.
- Diagnostic export retires automatic conversion of pre-July trajectory entries while preserving source files and current SQLite export. #163934. Thanks @steipete.
- Git backups restore triggers containing CASE expressions; retired same-file memory indexes require a preserved compatible copy through 2026.9.7. #163945. Thanks @steipete.
- Worktree cleanup and recovery use the owning Gateway; uncertain outcomes require inspection and sandbox recreation requires exclusive offline ownership. #163953. Thanks @steipete.
- Status marks a saved update failure as historical when the ready local Gateway serves the intended target, preserving the original failure record. #163991. Thanks @steipete, @sergiorodriguez-sudo.
- Migration planning explains an invalid copied-state path before inspecting delivery queues. #164007. Thanks @steipete.
- Future npm updates using the fixed installed updater verify fresh package contents with bounded hashing workers and unchanged integrity checks. #164052. Thanks @steipete.
- Updated nodes accept the Skill Workshop launch field used by a 2026.9.8 Gateway, preserving affected hosted turns. #164068. Thanks @steipete.
- Database opening and index repair avoid repeated metadata checks while retaining full integrity and foreign-key safeguards. #164099. Thanks @steipete.
- Failed-delivery health counts avoid unrelated history scans without planner statistics, with a one-time writable index rebuild. #164131. Thanks @steipete.
- Doctor media repair removes redundant table scans and still refuses concurrent changes; stop competing database users before retrying. #164139. Thanks @steipete.
- Supported service recovery and local diagnostics remain usable with invalid configuration while startup validation and newer-version guards remain. #164158. Thanks @steipete.
- Update reports retain recognized worker error causes while removing private paths and filename suffixes. #164169. Thanks @steipete.
- Fixed installed updaters avoid discarded duplicate configuration reads while retaining fresh edits and database compatibility checks. #164182. Thanks @steipete.
- Plugin snapshots and runtime preparation overlap bounded metadata checks without changing discovery order or integrity checks. #164183. Thanks @steipete.
- Verified pnpm 11 and 12 isolated updates skip an unnecessary global-root subprocess while retaining fallback discovery. #164184. Thanks @steipete.
- Trusted official plugin prerelease updates reuse successful package-selection metadata within the same attempt, retaining integrity, consent and warnings. #164185. Thanks @steipete.
- Caller and service profiles using the exact same state path share one database backup per checkpoint, with fresh checks retained. #164186. Thanks @steipete.
- Failed-update advice correctly identifies a verified serving Gateway while preserving failed status and restart or rollback restrictions. #164193. Thanks @steipete, @DonnieFi.
- Doctor repairs writable state under externally managed read-only config and reports required source edits; older-image rollback may need a matched backup. #164235. Thanks @steipete, @JD8855122.
- Docker CLI containers preserve fresh Gateway ownership across process namespaces and explain how to share the namespace or run TUI inside the Gateway container. #164236. Thanks @steipete, @JakeMalis.
- Completed Doctor repairs warn and exit successfully when the managed Gateway is still starting; check gateway status afterward to confirm readiness. #164261. Thanks @steipete, @waynegault.
- Update JSON output omits the human cleanup-progress line while retaining structured cleanup results. #164312. Thanks @steipete.
- Updates detect retired Voice Call logs before replacing the Gateway and direct affected users through 2026.9.7 Doctor first. #164330. Thanks @steipete.
- Repair timeout JSON retains the failed result and original stuck phase even when Gateway restoration also fails. #164337. Thanks @steipete.
- Doctor can publish unchanged pre-migration backups when Linux creation-time metadata is unavailable, retaining file identity, size, hash and ownership checks. #164363. Thanks @jayzhou2309, @steipete, @StevenKrebs, @kirylh, @stunt4711.
- Nested workspace setup files require 2026.9.7 doctor --fix before further upgrades; retired nested bytes remain untouched and root-level imports remain supported. #164399. Thanks @steipete.
- Fixed updaters accept recreated command links with unchanged targets; older Claude Code recovery prompts warn that normal customization applies. #164438. Thanks @steipete.
- Doctor finishes database cleanup before releasing maintenance resources, preventing its leftover leases from blocking a later repair. #164503. Thanks @RomneyDa.
- Updates proceed around retained agent-deletion holds while Doctor preserves uncertain stores and explains reserved-agent recovery. #164509. Thanks @steipete, @rosmiroslav-create, @PollyBot13.
- Container ownership recovery uses proven process death or a heartbeat older than 90 seconds, protecting verified live owners. #164546. Thanks @steipete, @Alex-vonAllmen, @coygeek.
- Doctor reports the actual newer-database or recovery-manifest result; failed deletion of a disposable inspection snapshot warns after its reader closes. #164697. Thanks @steipete.
- Doctor and gateway start can re-enable a verified disabled Windows Gateway task, with profile-aware guidance and foreign-launcher refusal. #164728. Thanks @steipete, @taoxia255-del.
- Reports retain Doctor’s check-completion message after a later crash; a nonzero or signal exit still fails validation. #164853. Thanks @steipete, @cunzai007-hub.
- Message commands keep their action result when a plugin shutdown hook times out, with unfinished shared-state cleanup reported as deferred. #164915. Thanks @steipete.
- Updates from 2026.10.1-beta.1 retain the cleanup imports needed after package replacement. #165855. Thanks @shakkernerd.
- Doctor imports legacy pending replies from JSON sessions without repeating the repair refusal, preserving exact session IDs, transcripts and original archive bytes. #165866. Thanks @SunnyShu0925, @steipete, @609NFT.
- Crash-loop safe mode preserves interrupted-turn retries and resumes replay after the full stable window, unless another crash or shutdown intervenes. #166238. Thanks @steipete, @masatohoshino, @KoalaShen.
- The new updater refreshes eligible completed Linux receipts after device-number changes; initial update dry-run can also rewrite those receipts. #166394. Thanks @steipete, @neilofneils404.
- The 2026.10.1-beta.2 updater bridge inventory is restored and excludes standalone worker copies from bridge selection. #167091. Thanks @RomneyDa, @ericcurtin, @obviyus, @steipete, @adele-with-a-b, @Patrick-Erichsen, @vincentkoc.
- Candidate compatibility checks leave original profile databases and their SQLite sidecar files unchanged when preservation is requested. 5a19f360. Thanks @steipete.
- Candidate checks preserve original agent database files when requested and still refuse newer schemas saved only in the log. 89217d3b. Thanks @steipete.
- Temporary database snapshots survive module reloads; shutdown waits for readers and stale cleanup cannot remove a replacement snapshot. 7b64dada. Thanks @steipete.
- Explicit channel changes keep caller and managed-service compatibility checks separate, preserving each profile’s settings. 1794d8b4. Thanks @steipete.
- Updates recheck settings saved during validation and reselect an implicit channel when needed; incompatible or repeatedly changing settings still stop activation. b36eb3e7. Thanks @steipete.
- Update progress saves run in database workers; delayed saves cannot let a replaced or revoked update continue. ea4aaef1. Thanks @steipete.
- Configuration-triggered Gateway restarts continue after duplicate file-watcher notifications while retaining readiness and secret checks. a4cc77c3. Thanks @steipete.
- Update verification can continue when its starting directory disappears by launching the read-only worker from a valid temporary directory. 8e303782. Thanks @steipete.
- Corrected installed updaters preserve relative user, session and local-package paths while replacing an installation that contains their starting directory. 6830c82e. Thanks @steipete.
- Interactive update progress remains visible through final verification and result reporting. 82fe5e96. Thanks @steipete.
- Eligible Windows updates settle pending database log writes before rollback capture; another connection still limits snapshots to manual recovery. 9863e3f9. Thanks @steipete.
- Pending session-maintenance callbacks stop when database access is refused, avoiding unhandled errors without changing the restriction. 5ca95288. Thanks @steipete.
- Gateway inspection recognizes Bun watch and hot commands and separate Node heap-limit values; worker diagnostics omit runtime stack fields. 4c7d05d9. Thanks @steipete.
- Blank migration-plan snapshot paths receive the specific argument error in both human and machine output. 71b857a7. Thanks @steipete.
- Retired outgoing and session JSON queues require a complete state-and-media backup, original-host 2026.9.7 and its Doctor before retrying; retained recovery artifacts must not be replayed. ff96d47c. Thanks @steipete.
- Gateway startup leaves webhook config bytes unchanged for completion-only markers; actual repairs require Doctor and a subsequent restart. b978fc0e. Thanks @steipete.
- Doctor backs up and repairs supported Claw ownership-history columns before planning; package removal retains current ownership and protects modified or shared files. de1f4385. Thanks @steipete.
- Overlapping session-recovery requests read after the preceding recovery is saved, avoiding false conflicts while retaining access checks. 2a206318. Thanks @steipete.
- Shareable failed-update reports retain a public-safe reason after private details are removed, including failures before any command ran. fc7e71ba. Thanks @steipete.
- Doctor and temporary agent commands wait for their background database maintenance before releasing access or removing storage. b58e6e98. Thanks @steipete.
- Snapshot errors keep their original explanation when temporary-file cleanup also fails. 20f485c7. Thanks @steipete.
- Doctor can inspect quarantined state to begin repair when no active or unverifiable Gateway owner blocks maintenance; ordinary reads still respect quarantine. 6d4ee0af. Thanks @steipete.
- Already-current updates can apply recognized legacy configuration repairs without a channel option, preserving the stored channel. d1006ac0. Thanks @RomneyDa.
- Candidate configuration checks retain supported legacy repair plans without switching channels or writing the original file. 107b2353. Thanks @RomneyDa.
- Update rehearsals preserve historical webhook listener settings for Telegram, Feishu, Teams and Nextcloud Talk when a missing official plugin install is deferred. 237b7b91. Thanks @RomneyDa.
- Update, Doctor and delivery ownership timers handle backward clock changes and distant deadlines without expiring prematurely. 15405665. Thanks @steipete.
Messaging
- Telegram replies can use the related photos, forwarded notes and attachments together when they are already queued on a busy host or an eligible attachment download is slow. Albums keep their arrival order within each chat or topic, and successive messages from one sender can queue separately behind a busy agent. Collection remains bounded, so late arrivals can still form another turn.
- Telegram agents can see supported images sent as files when they have image capability. Hyphenated commands remain copyable, deeply nested replies become readable text with media links, and rich messages keep explicit numeric user mentions. Long single-agent tasks can deliver completed progress messages through reply plugins, respecting streaming opt-outs. Progress links remain clickable without website preview cards.
- Sending several files in a supported quoted list or compact array keeps every attachment in order, including filenames with spaces or commas. Long code blocks and unusual line endings keep their formatting and captions. Supported speech-only answers can complete alongside model reasoning without filler chat text. See the TTS reply guide and restricted-profile setup.
- Replies from a remote worker attach its actual files, including completed replies sent before the workspace is copied back. Copy outputs from outside its assigned workspace into that workspace before attaching them; unreadable files produce a labeled failure instead of substituting a Gateway file.
- A queued follow-up can still finish after its original request closes, and a system-clock change no longer stretches its normal quiet period. Canceling while model settings load frees the conversation for your next message. Reset and deletion wait for channel work that has already started to settle.
- Background-command and restart replies return to the eligible web conversation they belong to. Affected channels keep answering after wake-from-sleep maintenance, and a channel with unchanged settings can finish a prepared reply after an unrelated plugin reload. Successful background media requests no longer show a false missing-reply notice while waiting for the result.
- Allowing a Discord parent channel lets the agent discover its active threads without a server-wide wildcard; explicit thread denies remain effective. Long model IDs retain the full selection through Submit; reopen
/modelsif the catalog no longer resolves it. Voice joins and playback use elapsed time, so changing the system clock does not stretch or cut short that allowance. - Slack fallback progress cards show quieter narration by default; the existing option still enables detailed tool activity. Slack and Matrix previews wait before displaying fragments that might be a silent-reply instruction. Matrix preserves unrelated contacts by stopping contact-map writes when account reads fail; retry the repair after reads recover.
- Each WhatsApp named account uses its own group reply preference, falling back to its configured mention policy. If a group relied on the old shared setting, rerun
/activation alwaysor/activation mentionin that group with the intended account. Doctor preserves configured accounts and warns about ambiguous unlinked defaults; review them yourself and preserve needed shared policy before removing an unwanted default. - IMAP catch-up batches messages, Tlon invitations can be renewed, malformed Mattermost callbacks receive an invalid-request response, and Twilio disconnects clear stale call-stream registrations. Early Reef sends without delivery records can remain unknown; check with the recipient before resending. A late rejection of those old sends no longer starts the 15-minute cooldown, so a later rejection may allow one automatic rephrased resend.
- Upgrading very old channel settings or data can require a bridge release. Keep a complete pre-update backup and follow the old-version upgrade guide. Retired Nextcloud Talk replay caches, Discord JSON preferences/bindings, Telegram sidecars and selected Matrix/Slack settings require the 2026.9.5 bridge. Retired Discord voice-TTS and guild-channel settings require 2026.9.7 Doctor. Migrate old Matrix JSON state before updating, and never run an older release against an already upgraded shared database. Very old Mattermost
allowPrivateNetworkaliases lose their Doctor conversion; preserve the original configuration because a confirmed recovery path remains unresolved. - If Telegram settings contain a full bot endpoint instead of an API root, run
openclaw doctor --fixand restart; read-only sources need manual correction. After manual package replacement, affected older Telegram polling offsets and shared-root WhatsApp credentials also need Doctor before account startup. Old unversioned Telegram reply context is unavailable until messages are observed again, and assistant replies without recorded identity can appear twice in context. Supported conversation history remains available.
Sources and complete fix list
Telegram albums and forwarded messages
- Eligible forwarded attachments are buffered before download, keeping their note and context together during slow downloads; retryable download failures leave the burst pending. #162787, thanks to @steipete.
- Telegram forwarded text and media can combine across separate polls within a one-second quiet window and the five-second batch deadline. #163286, thanks to @steipete.
- Photo albums queued behind a busy agent retain their chat or topic arrival order, avoiding retries that could replay or misplace photos while waiting. #163926, thanks to @steipete.
- Same-sender Telegram messages and forward batches can take separate places in the queue while the agent is busy, avoiding timeout-related replays and accidental merging while waiting. #164549, thanks to @steipete.
- Telegram holds album and forward collection for matching items already queued under local backlog. Collection remains bounded, so later arrivals can form another turn. db966d6, thanks to @steipete.
Telegram replies, rich messages and progress
- Telegram routes supported image files to image-capable agents without requiring users to resend them as compressed photos; PDFs remain documents. #141292, thanks to @ooiuuii, @obviyus, @sercada.
- Hyphenated plugin commands remain complete and copyable in Telegram command help, including across list pages. #141332, thanks to @ooiuuii, @obviyus.
- When Telegram cannot delete a replaced media message, it attempts to clear the old inline controls; controls can remain if the edit also fails. #159012, thanks to @wakqasahmed, @aniruddhaadak80, @obviyus.
- A guarded preview from a replaced Telegram turn cannot overwrite the current turn's message after a scheduling delay or flood wait. #160137, thanks to @steipete, @obviyus.
- Deeply nested Telegram rich replies render excess nesting as readable text with media source links instead of overflowing the call stack. #160437, thanks to @Ayushdevo, @obviyus, @hpyhandsome.
- Completed Telegram streaming progress blocks can appear during a long single-agent task with reply plugins applied, while explicit streaming and block opt-outs remain effective. #161546, thanks to @VACInc, @sercada.
- Invalid Telegram topic zero is rejected before sending; use a positive topic ID or omit the topic for an ordinary chat. #162197, thanks to @adamczhang, @aniruddhaadak80, @obviyus.
- Telegram rich messages turn safe numeric
tg://user?id=links into named mentions when sending or editing. #162523, thanks to @jayzhou2309, @alexph-dev, @obviyus. - Telegram progress links suppress website cards without changing the account's final-answer preview preference, including when progress and final text match. #163727, thanks to @ivan-magda.
- Telegram message-tool sends, including native inline buttons, work after affected ACP or chat handoffs without an invalid inferred reply target. #165137, thanks to @mbelinky.
Attachments, text and voice replies
- Completed subagent work sent through the direct-message fallback retains attachments, captionless media and voice-note intent when the requester cannot be awakened; a partial terminal send is not automatically repeated. #142852, thanks to @Finn763, @obviyus, @hotfemale.
- Several whitespace-separated, fully quoted paths on one legacy
MEDIA:line deliver as separate attachments in order, preserving spaces and punctuation in filenames. #150958, thanks to @zhangguiping-xydt, @obviyus. - TTS documentation shows
tools.alsoAllow: ["tts"]for restricted tool profiles, with separate automatic speech-output guidance; restricted profiles do not gain TTS by default. #155950, thanks to @fede-kamel. - Plain-text outbound replies preserve comparison text following affected emoji or astral Unicode letters instead of removing it as apparent markup. #160850, thanks to @steipete.
- Outgoing structured channel data preserves its own
__proto__field when internal text is removed. #160938, thanks to @steipete. - Discord and LINE preserve fenced code across long messages when newline-based streaming chunks are selected. #162412, thanks to @boeingchoco, @altaywtf.
- Newline chunking with a zero or negative limit keeps a fenced block and its following paragraph together. #163255, thanks to @vincentkoc.
- Comma-separated, quoted
MEDIA:paths deliver every attachment in order while retaining punctuation in names. #163448, thanks to @sxh313. - Compact
MEDIA:arrays retain every listed attachment and its order, including filenames containing spaces or commas. #163627, thanks to @sxh313. - Replies using carriage-return-only or mixed line endings retain attachments, captions and literal fenced content. #163665, thanks to @ly85206559, @obviyus.
- Newline chunking preserves Unicode line and paragraph separators inside fenced or inline code. #163697, thanks to @ly85206559.
- A selected zero or negative media limit uses the existing bounded fallback instead of rejecting every buffer, restoring affected Matrix buffer sends. #163701, thanks to @sxh313, @obviyus.
- Remote-worker attachments use the remote bytes and enforce the assigned-workspace path boundary, including in completed live replies. #164219, thanks to @steipete.
- A nonblank paired
[[tts:text]]speech block counts as a complete answer when the model also returns reasoning, allowing supported inbound channels to deliver audio without visible filler text. #164285, thanks to @obviyus, @Twilight-Networks.
Queued messages and reply delivery
- Queued follow-ups resume after their normal quiet period when the system clock moves backward. #160836, thanks to @nwang783, @aniruddhaadak80, @obviyus.
- Eligible Control UI and WebChat background-command or restart replies return to their own conversation instead of the configured heartbeat destination; failed restart replies remain retryable. #161006, thanks to @Marvinthebored, @Patrick-Erichsen, @oywino.
- Channel-reformatted replies retain the original conversation association needed for queued delivery and completion tracking. #161123, thanks to @steipete.
- Successful background media requests can acknowledge the request and later deliver the result without a false missing-reply or yield-failure notice while waiting. #161154, thanks to @obviyus.
- Canceling a reply during model-settings discovery releases that reply so it does not block the next conversation message. #161319, thanks to @Baumus, @obviyus.
- Custom channels using the direct message drain with
deferredLaneOccupancy: releasecan start the next same-lane message when the previous handler immediately defers. #161476, thanks to @xydigitLybnnnn, @aniruddhaadak80. - When a turn ends after its successful source-chat progress batch, OpenClaw avoids a redundant final-answer request. #162367, thanks to @obviyus.
- A sent final reply keeps its completion result and sent notification if notification for an earlier suppressed reply fails; the earlier error remains reportable. #162509, thanks to @steipete.
- Deliberately silent unauthorized group commands avoid false missing-delivery warnings. #163148, thanks to @obviyus.
- Conversation delivery records preserve send order, and a saved reply remains consumed when its waiting request expires. #163222, thanks to @steipete.
- Affected channel listeners can continue sending replies after the maintenance work started on host wake has closed. #163268, thanks to @scotthuang, @obviyus, @ChenGuoShun1979, @Harvey-XuH.
- Logs identify an unsupported action on a loaded channel instead of incorrectly reporting that its plugin is missing. #163551, thanks to @jayzhou2309, @axeg0.
- A definite rejection before dispatch no longer produces a false uncertain-delivery notice on the next turn. #163769, thanks to @steipete.
- Prepared sends on channels without a preparation callback can finish after an unrelated plugin reload when their registration and settings remain unchanged. #163893, thanks to @VACInc.
- Completed approvals notify channel cleanup, including Telegram approval tracking. #163969, thanks to @steipete.
- Message-tool-only answers retain completion history while its database work runs in the background. #164112, thanks to @steipete.
- Conversation reset or deletion waits for already-started channel processing to settle after queued cancellation; an idle canceled turn releases promptly. #164247, thanks to @vincentkoc.
- Chat retries report a retryable unavailable response when the original-message comparison cannot be read, instead of replaying an unverified answer. #164313, thanks to @steipete.
- Replies without a session key retain the session-ID and file fallback without attempting invalid keyed lookups or draining keyed events. 4a1c078, thanks to @steipete.
- Delayed queued follow-ups can complete after the triggering request closes instead of repeatedly failing against its closed work lifetime. 3400fd9, thanks to @xialonglee, @Patrick-Erichsen. Related proposal: #148025 (context).
- Incoming messages wait for session metadata to finish saving, avoiding a first-use database initialization race. 4324af4, thanks to @steipete.
- Retrying an affected canceled chat request returns its recorded timeout even after its reservation was lost; changed input using the same request ID still conflicts. 9b83d35, thanks to @steipete.
Discord threads, models and voice
- Discord voice joins retain their connection allowance when the system clock changes. #156979, thanks to @SunnyShu0925, @altaywtf.
- Agents allowed to read a Discord parent channel can discover its permitted active threads and member records without a server-wide wildcard. Explicit thread denies still apply. #160629, thanks to @PollyBot13, @Patrick-Erichsen, @postoso.
- Discord attachment uploads retain the caller's mention restrictions when component delivery falls back to classic messages. #161604, thanks to @steipete.
- Discord and OpenAI realtime voice codec handling adds input validation and cleanup after allocation or partial-initialization failures. #162592, thanks to @vincentkoc.
- Discord playback deadlines tolerate system-clock changes, avoiding cutoff or delayed cleanup caused by that trigger. #163652, thanks to @ly85206559.
- Discord's picker shortens display labels for model IDs over 100 characters while retaining the exact full selection through Submit. If the catalog no longer resolves the selection, reopen
/models; shared prefixes can still produce identical displayed labels. #164311, thanks to @ooiuuii, @obviyus.
Slack, Matrix, WhatsApp and other channels
- The Nextcloud Talk guide explains message receipt, permission checks and reply delivery separately, so a webhook acknowledgment is not mistaken for a completed answer. #157715, thanks to @deepujain, @jm9151821.
- The optional IMAP plugin fetches pending message bodies in batches of 20 during catch-up, preserving ordered retries without retaining every body at once. #160413, thanks to @Ayushdevo, @obviyus, @addyCooks.
- Slack and Matrix draft previews hold a possible lone-
Nsilence-marker fragment while ordinary words beginning with N and a genuine final N remain deliverable. #160582, thanks to @jayzhou2309, @imabotone-ui, @nashtu3000, @obviyus. - Automatic channel resolution accepts Slack workspace-qualified user IDs without the
--kind userworkaround. #160619, thanks to @LinzeShi, @obviyus. - Slack fallback cards use quiet narration by default. Set
channels.slack.streaming.progress.toolProgress: truefor detailed activity; when explicitly disabling it while keeping fallback cards, also selectstyle: card. #161472, thanks to @steipete. - Tlon can process a renewed group invitation after the preceding invitation ends, under its existing auto-accept and inviter rules. #161596, thanks to @steipete.
- A failed Matrix account-data read stops the direct-room mapping write instead of erasing unrelated contacts. #161727, thanks to @steipete.
- Matrix silently declines excess requests when its pending pairing queue is full instead of sending an empty code or false approval reminder. #161767, thanks to @steipete.
- Mattermost interaction callbacks containing JSON
nullreturn the invalid-body response instead of throwing a context exception. #162603, thanks to @steipete. - WhatsApp named accounts no longer inherit the old unscoped group activation setting; rerun the desired
/activationcommand in the intended account's group when needed. #162799, thanks to @steipete. - Reef's model guard accepts the exact
gpt-6.1-solID under its existing validation rules. #162955, thanks to @steipete. - Early Reef sends without canonical receipts retain unknown delivery status without imposing a historical-rejection cooldown. Check with the recipient before resending; later recorded rejections retain the guarded rephrasing rules. #163205, thanks to @steipete.
- Tlon displays configured model names such as
constructorandtoStringas ordinary strings. #163438, thanks to @steipete. - Twilio clears even an empty stream-ID registration on disconnect so the next inbound call can stream. The ngrok loopback option requires valid Twilio signatures. Very old Mattermost
allowPrivateNetworkaliases lose their Doctor conversion; keep the original configuration because a confirmed recovery path remains unresolved. #163767, thanks to @steipete. - Doctor preserves existing channel account maps and WhatsApp shared policy. It warns about ambiguous unlinked defaults for operator review instead of deleting them; preserve needed shared policy before explicitly removing an unwanted default. #163974, thanks to @steipete, @ooiuuii.
- Matrix partial message previews hold punctuation-prefixed silence-marker fragments such as
.NO_REP; divergent text resumes streaming and genuine final fragments remain deliverable. #164259, thanks to @ooiuuii, @obviyus.
Channel setup and upgrades
- Telegram troubleshooting distinguishes the Node networking threshold from OpenClaw's maintained supported-runtime requirements. #159240, thanks to @AmelioMansour, @aniruddhaadak80.
- Doctor imports implicit shared-root WhatsApp credentials into
credentials/whatsapp/defaultwith private.migratedbackups and conflict preservation. After manual replacement, runopenclaw doctor --fix, upgrading core first if needed. ExplicitauthDirstays authoritative. Remove the reported ignoredexposeErrorTextkey, including false values, or use its documented 2026.9.5 Doctor bridge. #163203, thanks to @steipete. - Nextcloud Talk preserves and refuses retired replay-deduplication JSON files; migrate affected state with 2026.9.5 Doctor in the same profile before upgrading. #163216, thanks to @steipete.
- Matrix preserves and refuses active
thread-bindings.jsonandstartup-verification.jsonfiles. Migrate before updating and retain a compatible pre-update backup; an older release must not open an already upgraded shared database. #163292, thanks to @steipete. - Discord preserves and refuses old model-picker-preference and thread-binding JSON files. Use a pre-update backup and the 2026.9.5 Doctor bridge before upgrading. #163329, thanks to @steipete.
- Zalo Personal Doctor repairs supported older direct-message keys for named agents without converting genuine groups; run
openclaw doctor --fixfor affected state. #163399, thanks to @steipete. - Normal updates back up and repair older Telegram SQLite polling offsets before startup. Manual replacements need
openclaw doctor --fix; sidecar-only historical state needs a complete pre-update backup and the 2026.9.5 bridge. Replace retiredgroupMentionsOnlywithgroups["*"].requireMentionthrough the documented migration path. #163418, thanks to @steipete. - Discord audits honor
allowFrom, including an explicit empty override, and timed-out operations retain timeout errors. Doctor correctly namesdangerouslyAllowNameMatching. Retired Discord voice-TTS provider and guild-channelalloworagentIdsettings require 2026.9.7 Doctor before upgrading; replacements usevoice.tts.providers, channelenabledand top-level bindings. #163728, thanks to @steipete. - Matrix bounds pairing tracking and keeps original whitespace text when its compatibility chunker receives a nonpositive limit. Retired Matrix trusted-DM, flat private-network and room/group allow settings, plus Slack channel allow settings, require 2026.9.5 Doctor before upgrading. #163740, thanks to @steipete.
- Old unversioned Telegram reply context becomes unavailable until messages are observed again, and assistant replies without recorded identity can appear in both reply context and transcript. Supported history remains available. #164173, thanks to @steipete.
- Telegram reports full bot-endpoint configuration and directs operators to Doctor repair before startup, probing or sending instead of silently trimming the URL. #164414, thanks to @steipete.
Memory
- Search and Dreaming keep distinct memories in different languages, and Wiki searches retain accented and non-Latin words. Supported Brazilian Portuguese questions can prompt deeper lookup, and ordinary Conversation Summary notes become eligible for Dreaming. Blank searches offer keyword-retry guidance, filename searches avoid repeated scans, and recall instructions account for an optional Wiki. See the session search guide, Active Memory lookup explanation and recall setup guide.
- Long conversations can finish a summary that needs several stages when a plugin delegates to built-in compaction. Each request remains bounded; plugin authors must pass the original host cancellation signal for this fix to apply. Automatic summaries use your reasoning setting and current conversation size, keep requested AGENTS.md excerpts separate from unrelated material, and distinguish completed checks from work still needed. See the context-engine guide, compaction settings, compaction policy and overview.
- Large conversation histories can become searchable again after database limits or a deadlock prevented indexing. Memory updates and cleanup put more database work in the background, and excluded system-only sessions stop falsely showing that the index needs updating. Forget keeps the original transcripts and excludes selected sessions from future indexing; if its result is uncertain, retry explicitly.
- Memory search can resume with your primary embedding provider after an outage, without restarting or rebuilding the index. A later search attempts recovery when the provider, model and settings match the saved index and the fallback is incompatible; attempts have a 30-second cooldown, and a working compatible fallback stays in use. Bedrock indexing also shares credential lookups without preventing rotation, while Zhipu batches split and retry when its 64-item limit is reported in Chinese.
- Memory search can again use an eligible saved Codex OAuth account for OpenAI embeddings without a separate API key. The account must have the required access: the separate Sign in with ChatGPT token-sharing grant does not authorize embeddings.
- Memory and skill edits use a 30-second polling default when native file watching is unavailable or polling is selected.
CHOKIDAR_INTERVALoverrides that default, down to 20 ms; shorter intervals mean more background scanning. Allow for the interval plus scan and debounce time before an edit appears. Status explains the watching mode and fallback reason; restart OpenClaw after repairing the native backend to try native watching again. - Very old Dreaming and Wiki installations need an upgrade recovery plan: Doctor no longer imports four pre-July Dreaming JSON journals or two older Wiki JSON formats. The files stay intact, and ordinary Markdown memories remain supported. Preserve a backup compatible with your current version before upgrading. A verified recovery route without a newer backup or established SQLite state remains missing; moving the old files aside does not migrate their data. See memory guidance and upgrading very old versions.
- Check older Wiki settings and preserve retired Active Memory JSON preferences before upgrading. Doctor no longer repairs Wiki's
bridge.readMemoryCoresetting or warns about those preferences; an old Wiki configuration can fail validation without the former repair guidance.
Sources and complete change list
Search and recall
- Ask for a keyword retry when a conversation search is blank #129120. Thanks @ruel225, @obviyus and @brainatworkharris.
- Recognize supported Brazilian Portuguese retrospective questions for deeper Active Memory lookup #135137. Thanks @wangyan2026, @obviyus and @wave-workflow.
- Avoid repeated full-index scans for filename and path searches #152585. Thanks @sahilsatralkar, @personaltrainerkoichan, @aron-intframe and @obviyus.
- Guide the assistant to use successful configured recall without treating an absent optional Wiki as a failure #157089. Thanks @LLagoon3 and @obviyus.
- Keep accented and non-Latin words in Memory Wiki multi-word searches #159683. Thanks @Yigtwxx and @altaywtf.
- Clarify when configured recall runs and how to enable remembering across conversations #161179. Thanks @yashas-13, @obviyus and @Raven-Gt.
- Make ordinary Conversation Summary notes eligible for Dreaming while filtering raw conversation turns #161363. Thanks @Irish-Joseph, @obviyus and @Gabrielnkl.
- Resume search after the configured embedding provider recovers from an outage #163936. Thanks @obviyus, @cknzraposo and @hubofvalley.
- Preserve distinct multilingual memories in search and Dreaming selection #164062. Thanks @harshitgupta31415 and @jarimustonen for the fix and acknowledged prior work.
Conversation compaction
- Estimate active conversation context without recounting history already replaced by a summary #150623. Thanks @goutamadwant, @obviyus, @BillBOT33 and @he-yufeng.
- Honor the configured compaction reasoning level during automatic summaries #159476. Thanks @MoerAI, @obviyus, @rtfcv and @he-yufeng.
- Improve summary instructions to retain completed checks that found a problem and separate remaining remediation #161293. Thanks @itayzit and @jacobtomlinson.
- Keep requested AGENTS.md sections separate from unrelated appendices while preserving fenced examples #162735. Thanks @boeingchoco.
- Restore transcript-based context estimates in affected non-Codex Bun conversation paths and missing Cloudflare plugin identity and activity artwork #163051. Thanks @steipete.
- Refresh the timeout between built-in summarization stages reached through delegating plugins #163636. Thanks @obviyus.
Indexing and maintenance
- Run saved conditional instructions' database work in a background worker #161395. Thanks @steipete.
- Reuse watcher paths to avoid redundant work when processing file changes #161495. Thanks @steipete.
- Move memory maintenance planning and forgotten-session reads into workers #161741. Thanks @steipete.
- Save generated search-vector cache entries in a worker while checking that the index is still current #161831. Thanks @steipete.
- Count and prune cached embeddings in a worker, yielding between batches #161884. Thanks @steipete.
- Finish Forget checks and writes in a worker, retaining previews and requiring explicit recovery after an uncertain result #161959. Thanks @steipete.
- Move Forget preview and apply index scans into the retrieval worker #162045. Thanks @steipete.
- Introduce a 30-second polling default and expose fallback health; a later fix restores explicit shorter overrides #162271. Thanks @steipete.
- Read source hashes and reusable cached embeddings off the Gateway thread during indexing #162528. Thanks @steipete.
- Move durable-session memory accounting and side-chat history preparation into workers, stopping delayed accounting from starting maintenance after access expires #163045. Thanks @steipete.
- Scan session-memory startup statistics in the indexing worker #163194. Thanks @vincentkoc.
- Discover stored conversations for indexing, archived search and selective forgetting in the history worker #163234. Thanks @steipete.
- Plan durable recall and Dreaming cleanup in the history worker #163269. Thanks @steipete.
- Skip unnecessary embedding-cache eviction scans and remove only the oldest excess entries #164083. Thanks @steipete.
- Share Bedrock instance-role credential lookup during indexing while allowing later credential rotation #161164. Thanks @obviyus and @slinkoff.
- Stop excluded system-only sessions from falsely marking the memory index dirty #161834. Thanks @obviyus and @alfred429.
- Keep unresolved-session Forget dry runs from creating a missing memory database #162155. Thanks @steipete.
- Restore memory catch-up, updates and cleanup for large session selections #164336. Thanks @jayzhou2309 and @nkarkare.
- Fix the rollback-journal indexing deadlock that kept affected large sessions out of search #164624. Thanks @triciah73 and @steipete.
- Split and retry oversized Zhipu embedding requests when its 64-item limit is returned in Chinese 00c09b7. Thanks @SunnyShu0925 and @obviyus.
- Select eligible stored Codex OAuth credentials for OpenAI memory embeddings f6883b3. Thanks @astra-openclaw and @Patrick-Erichsen.
Older-installation upgrade changes
- Retire automatic imports of
memory/.dreams/daily-ingestion.json,session-ingestion.json,short-term-recall.jsonandphase-signals.jsonwhile leaving their bytes intact #163334. Thanks @steipete. - Retire automatic imports of
.openclaw-wiki/source-sync.jsonand.openclaw-wiki/import-runs/<runId>.jsonwhile preserving current SQLite rollback support #163391. Thanks @steipete. - Remove the old Wiki
bridge.readMemoryCoretoreadMemoryArtifactsrepair and retiredplugins/active-memory/session-toggles.jsonwarning, without replacement recovery guidance #163667. Thanks @steipete.
Skills
- You can check whether a skill was found, meets its prerequisites, and is actually visible to the agent using skill troubleshooting. After the next agent turn,
/context listshows the catalog that reached the prompt. Browsing and choosing from your personal skill library also moves database queries into the background. - Installing an invalid skill no longer replaces a working copy, even with a forced local or Git install. Sandbox skill copies can refresh from read-only installations on POSIX systems, with affected copies repaired on the next full sync. SDK sessions also recover nested skills mistakenly hidden by root-only ignore rules.
- Skills remain available after file notifications that report no content change, and development sessions avoid the resulting false restarts. Scanning skips temporary activity while still refreshing supporting files and rediscovering skills when needed. Skills and Memory now honor existing
CHOKIDAR_INTERVALoverrides: the default is 30 seconds, the minimum is 20 ms, and shorter settings increase background scanning. - Older skills and hooks need a manual metadata update to retain prerequisites, installation hints and hook events: rename
metadata.clawdbottometadata.openclaw, preserving existing canonical values if both blocks are present. Reconcile.clawdhubtracking into.clawhubwithout overwriting records. Where node clients are equally matched, select an exact node ID; the April 2026 macOS setup PATH-check exemption is also retired. - Skill instructions give clearer routes for finding integrations: general requests use existing ClawHub plugins, while explicit skill requests use skills; installing either still needs separate authorization. Feishu Wiki instructions use supported browsing or a known wiki token. Callers must adopt the corrected tmux completion-marker example to distinguish fresh output from echoed commands and older results.
- Telegram skill shortcuts no longer take over the built-in
/export_sessioncommand; a colliding skill gets a numbered alias that affected users should use instead. Multiline arguments beginning on the command line keep their interior indentation, tabs and blank paragraphs as received from the channel.
Sources and complete change list
- After the next agent turn,
/context listand verbose diagnostics report the skill catalog actually included in the prompt. Counts now reflect omitted catalogs and prompt overrides. #145775. Thanks @tianhaotian, @obviyus, @adembektas, @aron-intframe and @bulingbuling688. - Troubleshooting documentation distinguishes a discovered skill from one whose prerequisites are met or whose instructions are visible to the agent. #146951. Thanks @Frosmans.
- Personal skill-library browsing, revision lookup and selection preparation load their records without doing database work on the main Gateway thread. New selections check current permissions and exact revisions, while existing sessions retain access to their pinned revisions. #164165. Thanks @steipete.
- Local and Git installs fail clearly on unusable or oversized skill roots before copying files. An invalid forced replacement leaves the existing valid skill in place. Scripts that previously accepted an unusable source now receive failure status 1. #160492. Thanks @Yun-0000, @obviyus, @suninweb and @ooiuuii.
- Refresh cleanup removes stale sandbox skill copies while protecting mount targets and symlink targets outside the managed copy. #162295. Thanks @steipete.
- On POSIX systems, sandbox skill copies refresh from read-only installations and existing copies repair on the next full sync. Source permissions, executable files and the guest's configured read-only access are preserved. #162304. Thanks @steipete.
- SDK resource matching treats a root-only
/buildexclusion as root-only, allowing skills under a nested path such asdeploy/buildto remain discoverable. Anchored exceptions retain the same root scope. #162455. Thanks @boeingchoco and @obviyus. - Skill scanning skips more irrelevant and temporary files while preserving file classifications between partial scans. If the classification cache fills, the next scan rediscovers files. #161881. Thanks @steipete.
- Unchanged watched content avoids false development restarts, and Claude catalog watchers let one-shot commands exit. Skills and Memory polling honor
CHOKIDAR_INTERVAL, with a 30-second default and 20 ms minimum. fcdd870. Thanks @steipete and @vincentkoc. - Legacy
metadata.clawdbotis no longer read in skill and hook files. Migrate the needed fields tometadata.openclawmanually to retain prerequisites, installation hints and hook events. #163104. Thanks @steipete. - Legacy
.clawdhubrecords are no longer read and need manual reconciliation into.clawhub, preserving existing canonical records. Equally matched nodes now require an exact node ID instead of the old-client tie-break, and the April 2026 macOS PATH-audit exemption is removed. #163965. Thanks @steipete. - ClawHub guidance searches existing plugins for general integrations and skills for explicit skill requests. Installation still requires separate authorization. #163848. Thanks @Patrick-Erichsen.
- Feishu wiki guidance uses node listing for a known space or parent and direct lookup for a wiki token, avoiding the unavailable search action. #161755. Thanks @steipete.
- The tmux skill's completion-marker example uses a fresh randomized marker split across
printfarguments, so an echoed command or old output does not look like a completed task. Callers need to adopt the updated example. #146329. Thanks @GodBlf, @mrzeepek and @obviyus. - Telegram keeps the built-in
/export_sessioncommand. A colliding skill receives/export_session_2or another unique suffix, so its command alias changes. See slash-command guidance. #163149. Thanks @ooiuuii. - Multiline skill-command payloads preserve interior indentation, tabs and blank paragraphs when text begins on the command line. Whitespace already transformed by a channel remains subject to that channel's handling. #164151. Thanks @ooiuuii and @obviyus.
Native Apps
- Mac chat stays open while its Gateway finishes setup or reconnects, and opening a completed conversation can restore a failed Dashboard. Refreshing an unrelated profile preserves sign-in for the same connection. Switching the primary Gateway clears the old chat and preview cache, and dismissing an older notification no longer hides its replacement.
- You can sign in to eligible Cloudflare Access apps inside the Mac Dashboard and keep those app sessions across restarts. Use an updated Mac app with an observed HTTPS app on port 443 on the same site, Access team and account. WebKit restrictions can still require the embedded app's own sign-in link.
- Saved remote Mac Gateways can reconnect, open and switch after a valid certificate renewal for the same host and port that macOS trusts, including administrator-installed roots. An explicit
gateway.remote.tlsFingerprintstays fixed and needs a deliberate update; expired, untrusted and wrong-host replacements remain rejected. - Canceled Mac and iOS recordings stay canceled when microphone permission arrives late, and Android dictation keeps listening after an older attempt ends. Mac push-to-talk finishes on right-Option release, sometimes waiting briefly for final speech results; cancellation sends nothing. Voice fixes also preserve iOS stereo audio, repeated Voice Wake commands and opening words in Apple realtime playback through ordinary bursts and brief microphone delays. iOS Talk keeps voice directives out of later speech segments, and retired health checks stop reporting stale failures.
- Switching Apple conversations no longer lets a late summary, fork, rewind or settings save overwrite the chat you're viewing. Mac attachments stay with the chat where you selected or dropped them, case-distinct conversation IDs stay separate, and link previews match the current URL. Local database cleanup avoids a double-close failure, and Watch replies avoid an unnecessary retry pause after reconnecting.
- Android group edits stay with their original Gateway: switching connections rejects stale rename and delete dialogs, and deleting a group leaves its conversations Ungrouped. iPhone and iPad demo captures hide real saved Gateway and credential controls. Android keeps current notification forwarding while removing older recent-app suggestions.
- Update pre-July-2026 Gateways before relying on retired native-app connection fallbacks. Apple and Android retries with a saved device token now require explicit Gateway permission, and Android stops accepting older incoming field aliases. Apple apps also stop importing selected settings and certificate trust from before July 1, 2026, so older-only setups may need to reconnect and establish trust again. iOS and its share extension now use
openclaw-ios; old client identity overrides and app-local Talk keys are retired, with local Talk using Gateway-configured keys. - Reading and searching skills on Android has translated labels in 21 existing non-English locales.
Sources and complete change list
- Opening a completed conversation restores a failed Mac Dashboard; queued native actions can recover after a canceled replacement load. #160886. Thanks to @steipete.
- A replacement Mac notification stays visible when an older dismissal animation finishes. #161250. Thanks to @steipete.
- Saved Mac Dashboard sign-in survives unrelated profile refreshes on the same active connection. #161464. Thanks to @steipete, @fuller-stack-dev.
- Eligible Cloudflare Access dashboards support in-app sign-in and persistent app-specific browser sessions. #161474. Thanks to @steipete.
- Mac menu-bar conversation and preview caches follow the primary Gateway, clearing former data on a switch. #163892. Thanks to @steipete.
- Mac chat stays open while its unchanged Gateway completes setup or reconnects, including command-line chat launches. #163971. Thanks to @steipete.
- Mac learned certificate pins accept hostname-valid renewal trusted by macOS, including saved-Gateway opening and switching; explicit fingerprints remain fixed. #164435. Thanks to @fuller-stack-dev, @joryirving.
- Mac push-to-talk retires the correct hold on key release, permission delay or voice-mode replacement. #143064. Thanks to @vincentkoc.
- iOS Voice Wake preserves both channels of queued stereo microphone audio when the capture buffer is reused. #161148. Thanks to @steipete.
- Restarted Android dictation keeps listening when an older permission or recognition attempt is canceled late. #161391. Thanks to @steipete.
- iOS Talk removes directives from cumulative text, repeated Voice Wake commands work after listening restarts, and retired health checks cannot publish stale failures. #161639. Thanks to @steipete.
- Late Apple compact, fork and rewind results cannot replace newer conversation errors or history. #161799. Thanks to @steipete.
- Apple local-state storage avoids duplicate closing after rejected initialization and concurrent database misuse. #162782. Thanks to @steipete.
- Apple transcripts keep case-distinct Matrix, Signal and catalog conversation keys separate while retaining structural aliases. #162818. Thanks to @steipete.
- Apple realtime voice playback preserves opening words and ordinary bursts through brief microphone delays. #163146. Thanks to @Marvinthebored, @Peetiegonzalez.
- Apple requires explicit stored-token retry permission, and late microphone permission cannot revive a canceled or replaced voice note. #163433. Thanks to @steipete.
- A failed Apple settings save from a departed thread cannot replace the current thread’s visible errors while its queued messages are put on hold. #164037. Thanks to @steipete.
- Delayed Mac file selections and drops stay bound to their original conversation, and Apple link previews show only their current URL’s title and image. 669db5d36e. Thanks to @steipete.
- Watch reply recovery starts promptly when reconnect cancels an old history request, avoiding its unnecessary retry pause. 287a4003d3. Thanks to @steipete.
- iPhone and iPad demo captures hide saved Gateway and credential controls and remove contradictory pairing prompts. #160857. Thanks to @steipete.
- iOS and its share extension retire old client identities and overrides. Local Talk uses Gateway-configured keys; Gateway-routed credentials stay on the Gateway. #163339. Thanks to @steipete.
- Android honors explicit stored-token retry permission and denial instead of the retired code-only fallback. #163347. Thanks to @steipete.
- Android in-flight group rename and delete remain on their original Gateway and reject stale responses. #163420. Thanks to @steipete.
- Android inbound events use canonical
payloadandparamsJSONfields; retired inbound aliases require dependent Gateways to update. #163441. Thanks to @steipete. - Android dismisses stale or restored group dialogs on Gateway changes. Deleting a group leaves its conversations Ungrouped. #163455. Thanks to @steipete.
- Android stops importing the older recent-notification-app suggestion setting while preserving the current forwarding setting. #163675. Thanks to @steipete.
- Existing Android skill reading and search labels gain translations. #162602.
- Apple retires selected pre-July settings and certificate imports; older-only setups may need Gateway reconnection and renewed trust. #163002. Thanks to @steipete.
Models and Providers
- Choosing a provider now keeps your model on that provider when an alias collides with its name.
openai/gpt-4o-miniselects OpenAI; useopenrouter/openai/gpt-4o-minito retain the former OpenRouter alias route. Check affected selections, because the route can change credentials, availability and cost. Adding fallbacks keeps the primary model, queued choices survive older cleanup, and shared fallback changes require omitting--agent. - Model status uses your saved nickname, and local terminal chat shows the model actually attempted after a fallback. Embedding output gives an eight-value preview, with full vectors available through
--json; migration links lead to the relevant model guidance. - Bedrock can use externally rotated AWS profile credentials without a restart and continue after an earlier malformed tool argument. Setup preserves your chosen configuration when attempts are canceled, avoids unused connections, and reports self-hosted credential-storage failures before claiming success. Queue overflow also keeps protected entries while removing eligible ones.
- Windows local-model setup can recover when llama.cpp is missing Visual C++ runtime files by placing them beside the managed server. If that recovery fails, rerun setup or configure a compatible server manually.
- Older ZAI and Ollama Cloud configurations may need manual changes. ZAI usage checks now use supported configuration, the auth store,
ZAI_API_KEYorZ_AI_API_KEY. Replace Ollama Cloud's retiredhttps://ai.ollama.comaddress withhttps://ollama.cominmodels.providers.ollama-cloud.baseUrl; Doctor no longer corrects or warns about the old address. - Official OpenRouter, Vercel and Perplexity requests identify OpenClaw to the provider through app headers. OpenRouter still receives that identification when install telemetry is disabled, and its Anthropic Messages requests replace configured Referer and Title values. Custom proxy hosts do not receive automatic attribution.
- Image generation with OAuth can retry using a supported OpenAI chat model in
agents.defaults.modelif the account rejects the default. Runway and Together video requests also honor longer timeouts. For ElevenLabs speech, manually replace the oldmodelsetting withmodelIdto select the intended model; see the speech configuration guide and field reference. - OpenAI and Azure Responses keep your requested JSON output format, and recovered DeepSeek calls keep literal names and empty-string arguments. Models that see images directly avoid unrelated media-provider loading errors.
- Astra preserves completed answers after silent tool results without sending them twice. Custom OpenAI-compatible routes can opt into stale-output pruning. Image guidance explains replay costs and replacing images with descriptions, which removes access to their pixels for that turn. Kimi K3's Code Mode fix renames the result-waiting argument to
awaitResultsonexec,shellexecandagents_wait; callers must replacerequired, which is now ignored. - Failed requests give clearer retry hints and preserve the original rejection, while local SQLite errors stop pointless model switching. Eligible malformed or output-limited tool calls get at most one recovery attempt; incomplete calls do not execute, and completed results stay available. Check results before repeating work, because earlier actions may already have finished. Remote Codex launch failures point to execution approval without rotating healthy credentials.
- A solo Codex conversation can delegate even when native admission hooks are unavailable; another signed-in person's message is queued as a follow-up. Conversations affected by the earlier source-main regression need a new conversation to recover. A stale readiness check gets one refresh before a child follow-up is refused.
- Switching or replacing a Codex chat protects the new chat from delayed commands and cleanup. Child assignments survive parent-thread replacement on the same connection, and an interrupted chat can resume after stopping and subscription cleanup succeed, while sibling chats continue.
- Codex avoids repeated history preparation, defers unused catalogs and servers, and fixes the fleet configuration-copy path that exhausted memory. Failed commands and supported simple Code Mode actions retain saved outcomes; sandbox listings and copies preserve tabs and line breaks in filenames. Missed file notifications can still leave listings stale until restart. Older schema-1 sidecar bindings stay available for diagnosis but are no longer imported or converted.
- Codex startup diagnostics identify the stage reached, launcher and pending requests, while known process-wide log notices stop repeating in chats. A managed launcher failure needs installation repair and a Gateway restart to retry. After updating, run standalone Doctor to diagnose sandbox loopback restrictions in affected local Linux Docker or Podman runtimes; it does not make blocked shell commands succeed.
Sources
- Keep explicit provider choices from being redirected by colliding model aliases — Thanks steipete, RXQ6, yunligou711-commits.
- Keep the selected primary model when adding fallbacks or supported tool-model timeouts — Thanks steipete, jayzhou2309, boeingchoco.
- Reject agent-scoped commands that would change shared text or image fallbacks — Thanks ericcurtin, steipete.
- Show embedding dimensions and the first eight vector values in normal CLI output — Thanks obviyus, LinzeShi.
- Keep a newer queued model, runtime or account selection pending for the next safe switch — Thanks steipete.
- Show each agent’s own model nicknames correctly in status summaries — Thanks ooiuuii, obviyus.
- Show the fallback model being attempted in local terminal chat — Thanks ooiuuii.
- Repair the Apple Foundation Models and Doctor links to primary-model migration guidance — Thanks LinzeShi.
- Pick up externally rotated AWS profile credentials in Bedrock without restarting — Thanks ayoakouh, obviyus, paweldrozd.
- Continue Bedrock conversations after an earlier tool call stored malformed arguments — Thanks RileyJJY, obviyus, odrodash, ruel225.
- Identify custom OpenRouter routes as OpenClaw consistently — Thanks obviyus.
- Use the vendor’s app-identification headers for Vercel AI Gateway and Perplexity — Thanks obviyus.
- Honor cancellation before an OAuth lookup returns its fallback credential — Thanks steipete.
- Avoid constructing a second unused provider connection for worker turns — Thanks joshavant.
- Stop a Copilot reconnect when authority is revoked during saved-token lookup — Thanks steipete.
- Preserve provider login configuration and discard worker previews retired during connection readiness — Thanks steipete.
- Honor Copilot cancellation during setup and clean up failed authentication or proxy preparation — Thanks steipete.
- Supply missing Visual C++ runtime files during managed llama.cpp setup on Windows — Thanks RomneyDa.
- Avoid unnecessary model-catalog writes when logging out a saved provider profile — Thanks steipete.
- Use supported ZAI usage credentials and set the canonical Ollama Cloud endpoint manually — Thanks steipete.
- Report self-hosted credential-storage failure before setup succeeds, and remove eligible queue overflow while retaining protected entries — Thanks steipete.
- Move personal model-account success and failure bookkeeping off the Gateway’s main thread — Thanks steipete.
- Keep an accepted agent turn’s selected configuration and workspace through authentication refresh — Thanks steipete.
- Retry OAuth image generation with configured OpenAI chat models when the default is rejected — Thanks TeaCup404, obviyus.
- Use modelId to choose the intended ElevenLabs speech model — Thanks obviyus, hartra344.
- Honor longer requested video-generation timeouts for Runway and Together — Thanks steipete.
- Preserve requested JSON formats on OpenAI and Azure Responses — Thanks kevin2966n, obviyus, axiom-ncis.
- Honor stale-tool-output pruning on explicitly opted-in custom OpenAI-compatible routes — Thanks chopin-op60, joelwp, obviyus.
- Explain image replay costs and the tradeoff of replacing selected images with descriptions — Thanks monde, Patrick-Erichsen.
- Skip unused media-provider loading when the model reads images itself — Thanks alexeysophia, obviyus.
- Preserve literal argument names when recovering DeepSeek tool calls — Thanks steipete.
- Preserve intentional empty-string arguments in recovered DeepSeek tool calls — Thanks ly85206559.
- Avoid unrelated media-provider failures on image turns with audio/video-only media models — Thanks ly85206559.
- Keep opening tool-call markers out of answer text after a completion without a final newline — Thanks steipete.
- Use the same normalized reasoning signatures in fresh node continuations and saved history — Thanks steipete.
- Keep completed Astra answers after silent tool follow-ups and avoid duplicate final delivery — Thanks obviyus.
- Avoid malformed Kimi K3 Code Mode calls by renaming the result-waiting argument — Thanks steipete.
- Keep provider reset hints when all fallback models fail — Thanks ayaangazali, obviyus.
- Use another configured agent’s working model for helper conversations and greetings — Thanks FtlC-ian, obviyus, Colton-Harris, MaikiMolto, jj5638521.
- Give malformed tool-use replies one guarded recovery attempt — Thanks namest504, obviyus, hogawa000.
- Give output-limited OpenAI tool calls one recovery continuation with smaller-call guidance — Thanks steipete.
- Report invalid Anthropic requests without an unnecessary thinking-history retry — Thanks jayzhou2309, abacha, altaywtf.
- Handle a provider setup failure that arrives after cancellation — Thanks steipete.
- Show fallback CLI startup errors without stale details from the previous provider — Thanks steipete.
- Stop model fallback after local SQLite worker failures — Thanks ericcurtin, Jeehut.
- Give neutral retry guidance for request timeouts without claiming a provider HTTP response — Thanks vincentkoc.
- Continue the same conversation after acknowledging supported provider-review findings — Thanks steipete.
- Retain Anthropic streaming error types for existing retry and model fallback — Thanks steipete.
- Treat expired or denied remote Codex launch approvals as execution-approval failures without rotating healthy credentials — Thanks steipete.
- Preserve solo Codex delegation when native admission hooks are unavailable — Thanks steipete.
- Refresh stale Codex readiness once before rejecting a follow-up child task — Thanks b4rRa, obviyus, Olli0103.
- Keep Codex interrupt retries consistent when the system clock changes — Thanks SunnyShu0925, altaywtf.
- Resume remote Codex reconnection after a client closes before monitoring begins — Thanks steipete.
- Keep Codex subscriptions, quota snapshots and child cleanup consistent across duplicate loads of the same plugin build — Thanks anyech, Patrick-Erichsen.
- Retain Codex child assignments and completed results when a parent thread is replaced on the same connection — Thanks steipete.
- Map Codex workspaces from filesystem roots and recover compressed-history discovery errors — Thanks steipete.
- Preserve valid Codex tool-context fields and keep app diagnostics tied to the latest refresh — Thanks steipete.
- Reuse unchanged Codex session inspection and read current bindings outside the Gateway thread — Thanks steipete.
- Preserve tabs and line breaks in Codex sandbox directory listings and recursive copies — Thanks steipete.
- Prevent fleet configuration copies from exhausting Gateway memory during Codex session discovery — Thanks obviyus, 609NFT.
- Load idle agents’ Codex session catalogs when requested instead of at Gateway startup — Thanks obviyus, 609NFT.
- Report early workspace-write rejection as a failed Codex shell command with its original arguments — Thanks joshavant, 100yenadmin, vincentkoc.
- Reduce repeated file checks and display preparation when browsing large Codex histories — Thanks steipete.
- Retain older Codex sidecar bindings for diagnosis without importing or converting them — Thanks steipete.
- Keep linked failed patch and shell actions in saved Codex conversations for supported simple Code Mode calls — Thanks joshavant.
- Protect replacement Codex conversations from delayed commands and cleanup belonging to an older session — Thanks steipete, galiniliev, KirDE.
- Resume an interrupted Codex chat while sibling chats continue — Thanks steipete.
- Preserve useful managed Codex startup errors when the launcher exits before its error arrives — Thanks steipete.
- Stop replaying known process-wide Codex diagnostic-log notices across chats — Thanks vyctorbrzezowski.
- Use standalone Doctor to detect local Linux Codex sandbox loopback failures — Thanks steipete, eugifa, oc-jarvis, sallyom, tedassur, Thinkscape, vincentkoc.
- Show the observed phase and awaited request counts in Codex timeout diagnostics — Thanks vincentkoc.
- Show the last observed Codex startup stage and whether a client was started, joined or reused — Thanks vincentkoc.
- Distinguish Codex initialization writes, native responses and version checks in timeout diagnostics — Thanks vincentkoc.
- Identify the registered Codex launcher in startup timeout diagnostics — Thanks vincentkoc.
Automations and Scheduling
- Older scheduled jobs keep their original agent and delivery intent instead of silently changing during routine activity or edits. Run
openclaw doctor --fixwhen prompted, or use the normal updater's Doctor phase. Affected jobs wait before running, editing or removal, with a due one-time occurrence preserved. Unknown delivery modes need review and an explicit choice in the editor before saving. - Interrupted one-time messages and webhooks stay disabled with Unknown delivery status after restart when they may already have been sent, including jobs set to delete themselves. Check the recipient before retrying, because Unknown can mean sent or unsent. Before upgrading, make a verified SQLite backup that includes its write-ahead log. Older runtimes refuse migrated state outside the updater's temporary grace period; reverting the binary alone is insufficient. Restoring an older backup loses later delivery records and cannot undo messages or webhooks already sent.
- OpenClaw keeps handling events while task edits, results and scratch notes wait to save, preserving newer changes, recorded recipients and cancellation checks. Scheduled-session cleanup does less work in large stores, and background runs can reuse matching prepared plugins without changing their workspace or file-access boundaries. Removing a running job requests cancellation; the acknowledgment does not mean work has stopped or undo completed effects.
- Running only due jobs manually now follows the same retry backoff and trigger spacing as scheduling. Force can bypass timing and enablement, while active-run, ownership and delivery checks still apply. Stopping a scheduling source waits for callbacks underway. Logbook starts each repeat interval after the callback finishes, so longer callbacks lengthen its cadence; Team Reports keeps absolute due times.
- Gmail watchers can recover from short port conflicts during restart, and repeated rejected attempts to process the same email produce fewer duplicate notices while retries continue. For a persistent conflict, stop the occupying process and restart OpenClaw or the foreground watcher. Failure messages distinguish periodic checks from event-driven work and explain how to follow the logs.
- You can follow an isolated scheduled run from messages through agent activity and available billed usage in one trace with
diagnostics-otel.
Sources and changes
- Preserve historical job owners and delivery intent through Doctor repair, with verified backups and the pending occurrence intact. Within stored delivery objects, missing or null modes and the old
deliverspelling becomeannounce; unknown modes need review. Completely omitted delivery settings keep their normal defaults. Update rehearsals retain live legacy files for the real import. d89da759 Thanks @steipete. - Hold interrupted one-time message and webhook deliveries when replay could send them again; runs proven never to have started delivery remain recoverable. #159873 Thanks @joshavant.
- Reject malformed stored-job saves supplying only the obsolete identity alias before changing any bundled job rows. Supported jobs and public
jobIdRPC parameters keep their behavior. #163247 Thanks @steipete. - Recheck current job state after another process causes an edit to be refused, allowing a later edit once that run finishes while retaining ownership checks. 0193905d Thanks @steipete.
- Keep Gateway events moving while completed manual or timer jobs wait to save their results, with job and execution records updated together. #161142 Thanks @steipete.
- Save task edits in background workers while preserving newer edits and run markers. Confirmed changes are not replayed if a worker reply is lost, although the caller can still see a reply-loss error. #161241 Thanks @steipete.
- Save scratch notes and heartbeat proposals without blocking the Gateway thread; queued saves refuse changed jobs, revoked permissions and stale originating turns. #161332 Thanks @steipete.
- Reduce periodic scheduled-session cleanup pauses in large stores by avoiding unnecessary loading of ordinary sessions' saved snapshots. #161510 Thanks @steipete and @todddickerson.
- Further reduce scheduled-session cleanup work by selecting relevant saved data before decoding it, retaining the same checks and retention rules. #161645 Thanks @steipete.
- Save results for jobs with long histories while holding the shared database writer lock for less time, and identify the operation behind slow writes more clearly. #161655 Thanks @steipete.
- Use less temporary memory when repeatedly listing automations or reading restart status by reusing unchanged snapshots. #164160 Thanks @steipete.
- Disclose active-run cancellation requests when removing an automation, retaining run history. An admitted run can remove its own job without cancelling itself. #159586 Thanks @ericcaiwx-star, @dh-js and @obviyus.
- Keep skipped-run history and startup notices tied to the agent and recipient captured when saved, including an absent default recipient. Interrupted cleanup avoids stuck local reservations and replay of uncertain writes. #161703 Thanks @steipete.
- Check execution records away from the Gateway thread and stop the next affected event, result publication or webhook if its job is removed during that check. #161935 Thanks @steipete.
- Avoid redundant plugin loading for Gateway background runs in other workspaces and for matching disabled or failed plugin records. Execution directories and file-access restrictions remain in place. #164594 Thanks @steipete.
- Preserve stream-job status and nondecreasing loss counters when sources change or shutdown loses a worker reply. Obsolete updates cannot overwrite a replacement stream, and uncertain outcomes remain errors. #161502 Thanks @steipete.
- Align manual due-only timing with scheduled retries and settle started work when a scheduling source stops. Sibling schedules continue, and elapsed stream deadlines are handled once after sleep. #163228 Thanks @steipete.
- Tie Logbook and Team Reports schedules to service lifetimes, waiting for admitted work before closing reporting resources. Logbook uses intervals after completion, while Team Reports retains absolute due times and its existing cancellation deadline. #163918 Thanks @steipete.
- Retry Gmail watcher port conflicts after 5, 10 and 20 seconds for managed watchers and the foreground command, recovering from short restart overlaps. #161503 Thanks @obviyus and @kazuyuki-eguchi.
- Suppress repeat failure notices when the same retained email cannot start processing within five minutes, while retries and diagnostics continue. Expiry, eviction or restart can permit another notice. Failures after processing starts remain visible. #164206 Thanks @jayzhou2309, @obviyus and @TrevorDGreen33.
- Describe a failed heartbeat as an incomplete background check, with
openclaw logs --followtroubleshooting guidance and optional diagnostic details governed by disclosure settings. #162869 Thanks @vincentkoc. - Match failure wording to the selected work, so event-driven requests do not falsely appear to be failed periodic checks. Selected periodic tasks and monitor checks retain heartbeat wording. ac85f6dc Thanks @juyterman1000 and @Patrick-Erichsen.
- Point the Automations index directly to the existing mapped-webhook instructions for custom
POST /hooks/<name>routes. 0ad243f9 Thanks @LinzeShi. - Keep an isolated scheduled run's activity and available billed usage together in its diagnostic trace when using
diagnostics-otel. #161304 Thanks @NianJiuZst, @ryan-dyer-sp and @obviyus.
Browser and Computer Use
- Managed browsers can find installed Playwright Chromium on Linux ARM64 and when
XDG_CACHE_HOMEredirects the cache. Browser Doctor checks the launch settings your profile actually uses, including remote, attached and customized browsers. - Native Codex application control no longer reports a false browser-authentication error for API-key installations. Setup keeps its timeout allowance across clock changes, and agents get instructions for locating windows and providing browser and page references together.
- Mac desktop automation uses Peekaboo 4.7.0. If an exact-window menu action cannot be dispatched safely,
actionOnlyrefuses it; use the supportedactionFirstfallback. - Browser connection addresses keep their explicit default port even when a path, query or fragment contains an at-sign. Firecrawl fetches also honor
--format textthrough bothinfer web fetchandcapability web fetch, though some Markdown formatting can remain. - Tab cleanup and Dashboard reconciliation continue after the request that started them ends, until the Browser service stops. Cleanup retries produce fewer repeated warnings for stopped profiles, and rate-limit errors return without hanging on response cancellation. See browser configuration.
- Desktop reconnects no longer accumulate repeated attempts to clean up a failed session. Reconnecting alone no longer retries a cleanup failure, even if it was transient. Inspect the reported process or filesystem error and perform lifecycle cleanup, such as turning Host Desktop off in Labs; a replacement starts only after cleanup succeeds. See desktop configuration.
- Keeping private-network browser access requires the canonical
browser.ssrfPolicy.dangerouslyAllowPrivateNetworksetting. Replace the retiredbrowser.ssrfPolicy.allowPrivateNetworkkey if your configuration still uses it; the old browser key is no longer honored. - Browser inspection shows the registered tool, and sandbox reservation and cleanup work moves into the background while keeping its order. Old unconfigured
browser/clawddirectories now stay on disk instead of being offered for Doctor archival; configured profiles remain supported.
Sources and complete change list
- Reduce repeated stopped-profile unreachable-tab warnings without stopping cleanup retries. #155211 Thanks @LiuwqGit, @obviyus, @ghowkay.
- Preserve setup-request timeout allowances across system-clock changes. #155873 Thanks @SunnyShu0925, @altaywtf.
- Show the Browser tool’s name in runtime plugin inspection. #158823 Thanks @chopin-op60, @priyabrataedu-droid, @Spheresta, @altaywtf.
- Bound failed desktop cleanup across reconnects and require explicit cleanup before replacement. #161621 Thanks @steipete.
- Match Browser Doctor prerequisites to effective profiles, including explicit Chrome MCP endpoints and local auto-connect choices. #161694 Thanks @steipete.
- Keep explicit default ports in the correct part of browser connection addresses containing an at-sign. #161984 Thanks @steipete.
- Honor the existing text-output option in both web-fetch command aliases. #162036 Thanks @LinzeShi.
- Explain window discovery, preparation prerequisites and paired browser/page references to agents. #162286 Thanks @steipete.
- Keep tab cleanup and dashboard reconciliation active for the Browser service’s lifetime. #162312 Thanks @steipete.
- Avoid false browser-authentication failures in native Computer Use readiness checks. #162467 Thanks @RomneyDa.
- Update macOS desktop automation to Peekaboo 4.7.0 with its exact-window refusal and fallback behavior. #162746 Thanks @vincentkoc, @steipete.
- Stop honoring the retired browser private-network key and use the canonical setting. #163168 Thanks @steipete.
- Find installed Playwright Chromium automatically on Linux ARM64. #163281 Thanks @jesse-merhi.
- Find Chromium in redirected Linux caches while preserving explicit executable and cache choices. #163510 Thanks @ly85206559.
- Retire Doctor’s detection and archival of old unconfigured browser profile residue, leaving existing directories in place. #163709 Thanks @steipete.
- Sandbox browser reservation, activity and cleanup bookkeeping runs outside the Gateway’s main thread while preserving reservation and cleanup order and protecting replacement browser instances.. Thanks to @steipete.
- Return browser rate-limit errors without hanging on response cancellation. 88b1a534 Thanks @obviyus.
Plugins and Integrations
- Plugin upgrades. Keep affected plugins working by updating them before the OpenClaw host; the SDK migration guide explains retired imports and replacements. Legacy extension-only installs need an explicit supported installation or 2026.9.7 Doctor repair before upgrading. Updated Zoom, Teams, ClickClack, Google Chat, IRC, Slack, SMS and Zalo packages using the refactored helpers require host 2026.9.8 or newer. Historical conversation bindings without recognized plugin ownership can refuse reassignment, with recovery still unresolved.
- Loading and reloads. You can read model lists, sign-in status and session metadata while a plugin reload waits for work to finish. If that wait fails, retry
openclaw plugins reload <id> --waitor revert pending settings; a model call blocking its own reload fails promptly and can be retried afterward. Loading avoids repeated native-plugin scans and supports managed npm layouts across filesystems and symlinks. After editing bundled TypeScript, restart OpenClaw; compiled installations also need a rebuild first. - Background work and older files. Stopping or replacing a service cancels pending callbacks and waits for work already admitted after owner cleanup. Before this upgrade, migrate old Device Pair notify files, Discord model/thread files and iMessage reply, sent-echo or catchup files through 2026.9.5 and Doctor; Voice Call
calls.jsonlneeds 2026.9.7. Verify migration before backing up or moving the preserved originals and retrying. Standalone Voice Call keeps its webhook serving after printing a result; SIGINT or SIGTERM ends it and finishes cleanup. - Cloud workers and GitHub. Worker cleanup and re-enrollment respect your selected profile and platform, with bounded retries for qualifying timeouts. Worker and remote-proof paths require Crabbox 0.69.0 or newer. Definitively unsupported Linux snapshot captures can use existing recovery; older paused captures still need recovery. GitHub publication choices and status stay readable during conflicting snapshot activity. Follow cloud-worker troubleshooting and retain
--lease-idwhen a command refuses to proceed. - Tool discovery and input. Tool Search finds tools with trusted arguments nested in combined schemas. Repeated tool or skill searches reuse unchanged indexes. Inputs keep referenced types and defaults and accept custom strings alongside presets; overly nested MCP results explain the need for flatter output. Meeting captions and Logbook skip completed history, though their first index build can take time and temporary disk space.
- Integration setup and recovery. Voice Call keeps an active call's recorded agent; hang up old unowned calls through the provider and start a new call.
openclaw doctor --fixrepairs legacy MCP transport aliases, and Gmail setup accepts Python paths with spaces. Supported Ollama models sent directly toollama.comcan use maximum thinking; local and local:cloudrelay routes keep the compatible high mapping. The removed Diffs Language Packapi.tsentrypoint may affect external imports; replacement guidance remains unresolved.
Changes and sources
- Whole-store and transcript-file SDK bridges are removed; affected plugins must adopt the supported focused APIs before the host update. #162220. Thanks @steipete.
- The
channel-lifecycle,channel-message,channel-reply-pipeline,config-runtimeandinfra-runtimeimports are retired, with replacement calls documented in the migration guide. #162333. Thanks @steipete. - The
command-auth,discordandtelegram-accountSDK facades are retired; use the supported channel contracts and injected runtime. #163366. Thanks @steipete. - Plugins using the retired Copilot token-exchange helpers must move to registered authentication hooks and provider-owned endpoint resolution. #163587. Thanks @steipete.
- Provider plugins replace eight retired stream/replay constants with the existing family constructors; the compatibility guide lists replacements and retained aliases. #163591. Thanks @steipete.
- The refactored Zoom and Teams plugin packages require host 2026.9.8 or newer. #161628. Thanks @steipete.
- Updated ClickClack, Google Chat, IRC, Slack, SMS and Zalo packages using the shared secret helper require host 2026.9.8 or newer. #162827. Thanks @steipete.
- Old extension-only npm stubs need an explicit supported installation or pre-upgrade Doctor repair. #163231. Thanks @steipete, @Dylanzhang1128, @vincentkoc.
- Bundled source plugins share loaded host code, so source edits take effect after restarting the Gateway. #163639. Thanks @steipete.
- Supported older Codex harness plugins retain
sourceVisibleReplies;visibleRepliesis the canonical field and explicit message configuration takes precedence. #163497, #163786. Thanks @steipete. - Typed approval hooks must omit the retired
requireApproval.timeoutBehaviorfield;timeoutMsandtimeoutReasonremain supported. #163333. Thanks @steipete. - Typed configuration uses
models[ref].agentRuntimeandagents.defaults.compactioninstead of the retired per-agent fields. #164586. Thanks @steipete. - The newer meeting page-script factory uses
statusPreludeandstatusCalldescriptors; older standalone builders remain available. #163983. Thanks @steipete. - Installed QA runner plugins using legacy-only registration must move their runner registration to
qa-runner-api.tsor.js. #164058. Thanks @steipete. - Feishu broadcasts and agent selection accept canonical keyed rosters, while source types reject retired roster/default fields earlier. #164103. Thanks @steipete.
- Fixed-proxy helper users should review zero-valued connection options. Most use Node defaults, but
maxTotalSockets: 0fails during construction. #161624. Thanks @steipete. - Callable provider catalogs retain lifetime checks, and historical ownerless conversation bindings now refuse reassignment rather than entering the old migration flow. #164047. Thanks @steipete.
- Migration-index links reach the matching replacement-API sections directly. 80f68b8862fc. Thanks @LinzeShi.
- Plugin reloads keep passive model, sign-in and chat metadata available through waiting and failed drains. #162301. Thanks @steipete.
- Session lists, inspection and health can use the active thinking policy while a retired registry transitions to its replacement. #162470. Thanks @jalehman.
- A plugin model call that would prevent its own reload fails promptly with instructions to retry afterward. #162484. Thanks @jalehman.
- Ongoing sessions can use current tool-policy handlers after old plugin generations retire. #164451. Thanks @RomneyDa.
- Reply model lookup honors disabled plugins for custom providers, aliases and model overrides. 120b43633fde. Thanks @steipete.
- Native-prebuild loading avoids repeated full captured-file scans during inspection and startup. #165301. Thanks @goutamadwant, @steipete, @exGeni.
- Managed npm plugins with native dependencies load across filesystem boundaries and supported symlink layouts. For a wrong-host installation, run
doctor --fixon the intended host, then reload. #163876. Thanks @steipete, @wlassalle724, @EmisvaldoSilva. - Bun loading follows captured dependency metadata, and its portable worker/recovery bundles include JavaScript dependencies needed by supported Node destinations. #163052. Thanks @steipete.
- Bun plugins resolve valid wildcard package-import aliases with filename suffixes. #163232. Thanks @steipete.
- Deferred Bun SDK imports retain the source or built host selected by their plugin generation. #163360. Thanks @steipete.
- Bun retains its intended plugin loader when it exposes Node-compatible module hooks. #163539. Thanks @steipete.
- Shared plugin caches follow the selected state location, and failed setup preserves its diagnostic error while attempting cleanup. #161351. Thanks @steipete.
- Quarantined-tool and context-engine health reads move off the calling thread while continuing to report stored status. #161375. Thanks @steipete.
- Doctor and scheduled cleanup warnings preserve both filesystem and ownership-token release failures. #161488. Thanks @steipete.
- Plugins forwarding provider streams through multiple layers avoid inspecting the same event repeatedly. #161696. Thanks @steipete.
- Stream and result handoff removes repeated boundary wrapping; plugin authors retain responsibility for leaving delivered payloads unchanged. #163818. Thanks @steipete.
- Native hooks retry brief database locks within the existing deadline before declaring their authenticated bridge unavailable. #161822. Thanks @steipete.
- Context-engine startup and reload wait for accepted health cleanup without letting an obsolete activation clear a newer failure. #161952. Thanks @steipete.
- Standalone SDK sandbox preparation refuses shared state owned by a live or unverified runtime. Use the owning runtime, or stop it through the service owner and wait for embedded activity before retrying offline. #164203. Thanks @steipete.
- Remote-exec bootstrap includes required published
.setupruntime chunks for affected external plugins such as Codex. #165669. Thanks @LiuwqGit, @JakeBotFleet. - CLI help and command discovery release executable-owned plugin metadata resources and retain reported cleanup failures. bfdb432570ac. Thanks @steipete, @vincentkoc.
- Completed disposal can finish shutdown while still reporting its error; unfinished cleanup and failed prerequisites remain blocking. cf78e6443477. Thanks @steipete.
- Saved Control UI plugin descriptors remain readable after retirement without invoking the retired plugin. dc8393473d09. Thanks @steipete.
- Catalog-created resource controls keep their factory's plugin context, including the repaired speech-stream release callback. a388b8f1a736. Thanks @steipete.
- Worker-runtime imports resolve through the registered main, worker and lifecycle package entry points. 6c31d857a79c. Thanks @RomneyDa.
- Installed-plugin ownership and conflict checks reuse resolved paths within each check. 6fc676c5b563. Thanks @RomneyDa.
- Service/account scheduling cancels pending work and joins admitted callbacks after owner cleanup, with the separate legacy-file upgrade requirements above. 7f0410c2e66e. Thanks @steipete.
- Claw cleanup and MCP setup-status saving run in the background; cleanup waits until its ownership record is saved. #163112. Thanks @steipete.
- Stopping Beam and Codex desktop watchers cancels polls and retries and waits for admitted work, preventing late generation publication. #163914. Thanks @steipete.
- Custom legacy PCM Talk integrations avoid starting an obsolete reply when cancellation arrives after its replacement. #163732. Thanks @steipete.
- Global MCP cleanup continues reporting an earlier unconfirmed disposal instead of losing that uncertainty on a later empty cleanup. a6089edc5cd9. Thanks @steipete.
- Crabbox 0.69.0 or newer supports recovery from definitive unsupported Linux snapshot capture without treating every capture error as a fallback. #161465, #162334. Thanks @steipete.
- A healthy macOS Crabbox worker can re-enroll on a busy host without a false reprovisioning error. #162233. Thanks @steipete.
- Crabbox cleanup stays with the selected profile, and concurrent requests share executable preparation. #164128. Thanks @steipete.
- Linux profiles request Linux explicitly, and sanitized worker errors retain useful status and recent log details. #164129. Thanks @steipete.
- Qualifying coordinator timeouts get at most three attempts within the original budget; fresh unsupported-backend refusals identify the profile problem. #164231. Thanks @steipete.
- GitHub publication account choices and status remain readable during conflicting retained-snapshot activity. #161551. Thanks @steipete.
- Personal GitHub confirmation status follows session archive/restore and rejects reads made stale by archive changes. #141994. Thanks @wangmiao0668000666, @steipete.
- Tool Search discovers trusted tool arguments inside combined schemas and tuple items. See Tool Search. #164032. Thanks @harshitgupta31415, @obviyus.
- Repeated tool and installed-skill searches reuse an unchanged word index across turns and Code Mode cells. #164166. Thanks @steipete.
- Control UI guidance explains the rendered tab, widget and link-reader contribution surfaces. See host hooks. #147599. Thanks @Colton-Harris, @Patrick-Erichsen.
- Client guidance distinguishes session metadata, recent stored messages and display-normalized history. See session RPC readers. #155449. Thanks @winddd666, @datus1982.
- Affected plugin and MCP tool schemas accept valid custom strings alongside named presets. #159755. Thanks @Shenrui-Ma.
- Overly nested MCP results fail with flatter-output guidance, including consistent Code Mode output errors. #160825. Thanks @wangmiao0668000666, @hpyhandsome.
- Encoded plugin schema references retain separators and defaults; use
~1for a literal slash in a key and~0for a tilde. #161954. Thanks @boeingchoco, @obviyus. - Encoded local tool references retain input types and supported numeric conversions while rejecting invalid text. #162435. Thanks @boeingchoco, @obviyus, @he-yufeng.
- Native plugin preparation reuses successful checks on unchanged captured files in affected hardlink installations. #162254. Thanks @steipete, @WG-Mojo, @eddiekk, @NickM83.
- Bun-backed npm plugin operations use bundled npm 12.1.0 while preserving explicit Git and remote-tarball source restrictions. #162581. Thanks @vincentkoc.
- Running Bun plugins retain selected dependency contents reached through supported package aliases after source edits. #164223. Thanks @steipete.
- Repeated configuration checks avoid compiling temporary conditional-default validators again. #164208. Thanks @steipete.
- Meeting caption retries use a narrower index while exact retries stay deduplicated and revisions remain distinct. #164127. Thanks @steipete.
- Logbook pending-analysis polls avoid scanning completed history while preserving pending order and retries. #164130. Thanks @steipete.
- The Lobster plugin's runtime 2026.9.14 update corrects structured LLM task request/result translation. #162558. Thanks @vincentkoc.
- Comfy guidance separates hosted MCP account sign-in from workflow-plugin API keys. See MCP OAuth and Comfy MCP. #163197. Thanks @vincentkoc.
- QA Lab Multipass accepts a valid repository child such as
..qa-artifactswhile rejecting parent, root and symlink escapes. #163223. Thanks @steipete. - QuickJS Code Mode cards and setup use the shared white-background mascot. #163804. Thanks @Patrick-Erichsen.
- Voice Call preserves recorded ownership and leaves old unowned active calls for provider-side hangup and a fresh call. #163118. Thanks @steipete.
- Doctor repairs old MCP
typealiases, and an explicit canonical transport wins over a conflicting legacy type. #162256. Thanks @steipete. - MCP listings preserve opaque pagination tokens, and supported models sent directly to
ollama.comreceive maximum thinking without changing local-relay compatibility. db0c17463643. - Gmail setup keeps the full discovered Python executable path when its directories contain spaces. fd333c7e1773. Thanks @steipete.
- The Firecrawl guide links directly to the provider website and API-key dashboard. #157257. Thanks @JuampiHernandez.
- Malformed Claude Workshop replies reject the waiting MCP request promptly instead of leaving it until the SDK timeout. #158916. Thanks @steipete, @VACInc.
- Diffs screenshots honor the readiness deadline, Canvas assets can retry after a transient read failure, and failed Twitch startup clears its deadline timer. Diffs Language Pack authors should check imports of the removed top-level
api.ts; a replacement is unverified. #161096. Thanks @steipete. - Saved ClickClack discussion updates begin with service startup rather than falling back to premature polling. #161150. Thanks @ericcurtin, @steipete.
- Canvas reconnects avoid duplicate actions, Logbook rejects reversed trimmed intervals, Tavily skips impossible dates, and failed LanceDB table discovery closes its connection. #161706. Thanks @steipete.
- Memory Wiki imports backtick-heavy text, and Plivo V3 verifies valid webhooks with prototype-named parameters. #162425. Thanks @steipete.
- Parallel search caches distinguish delimiter-sensitive requests and an explicitly named
defaultsession. #163911. Thanks @steipete.
- Guests can again launch private sandboxed helpers, notify their child agents and ask agents to rename conversations they created without broad write access. Shared work follows the chosen verified participant's permissions and the original run's limits, within a shared trust boundary. On multi-user installations, only creators or administrators can archive or restore threads; assigned noncreators lose those actions after upgrading, including on existing threads.
- Sharing controls, agent discovery and command lists recheck access after delays or reconnects. Session read access works for shared GitHub publication options and receipts, while automation hides private working notes after access or ownership changes.
- Approval links show supplied payment, recipient, posting and automation details before you decide. Unrelated edits preserve pending approvals; relevant authority changes invalidate them. Commands suppressing audit output follow ordinary read/write approval policy, including eligible automatic review.
- Pairing and execution-approval settings use the running Gateway's current state. A newer CLI refuses an older Gateway without the required support; update it or stop it through its service owner before retrying. Inspect current requests or settings before repeating a mutation whose result is uncertain. For a narrowed browser token, recover administrator access with
openclaw dashboard --jsonon the Gateway host and open the fresh URL in the same browser, origin and Gateway within ten minutes. - Work on a node respects current workspace and patch-tool restrictions. Eligible native apps on the same machine avoid repeated initial approvals under existing local policy, and reused writable SSH sandboxes receive new uploads. Strict filesystem mode can refuse recursive cleanup on Windows or Linux without
openat2, leaving directories behind; use a platform supporting the required protection. Migrate old filesystem mode variable names to their native-mode equivalents. - Credential prompts confirm a completed save, even when an accepted save finishes privately after reset. If runtime refresh then fails, use
secrets.reloadinstead of submitting the answer again. Older core secret references without a provider requireopenclaw doctor --fix. Preserve the original backups and inspect the repair, especially for Talk and realtime Talk, whose setup can discard an older providerless API-key object before repair. - Logout removes copied catalog credentials from still-saved profiles, and secret-excluded Git backups omit catalog keys and headers. Profiles already removed by older logouts and previously created or pushed backups need separate inspection. Permitted CLI commands and literal-loopback HTTP requests work with the secret egress proxy; secret substitution remains refused over HTTP. Provider errors hide reflected credentials, shared OAuth profiles avoid unnecessary copies, and A2A status identifies token settings needing repair.
- Secret masking preserves ordinary text after
pass:and reduces the affected long-output pauses, including with custom patterns. Chunked custom scanning can miss cross-boundary matches and treat chunk starts as anchors; not every pattern avoids stalls. Fallback diagnostics also mask secrets. Reserved private runtime entries stay out of compaction summaries and saved CLI notes without rewriting transcripts; an unresolved resumed-session issue may discard newly queued text or images in the affected legacy-context case. - Starting OpenClaw with its managed Bun runtime or the macOS bundled runtime no longer installs missing packages implicitly. Install dependencies explicitly; existing services receive the launch flag through normal reinstall or update, and direct stock-Bun launches should use
--no-install. Private-network Matrix and Mattermost settings need Doctor repair on 2026.9.7 before upgrading; Tlon retains update-time migration, while direct replacement needsopenclaw doctor --fix. See Bun installation and the configuration migration guide.
Sources and complete change list
- Shared turns and their children use the chosen verified participant's permissions, bounded by the original run. Model-account credentials stay the same, and permissions can be revoked during retained work. #160525. Thanks @steipete.
- Guests with own-session write permission can launch hidden sandboxed helpers and receive their results, including after yielding. The helper retains the initiating person's model and sandbox restrictions. #163367. Thanks @shakkernerd.
- Session-only writers can notify an authorized child they own without starting a new run. Notifications live in memory for the process lifetime, so restarting does not provide durable delivery. #162986. Thanks @shakkernerd.
- Guests can ask agents to change the displayed name of a conversation they created, including under default sandbox policy. Explicit tool restrictions still apply, and renaming another created conversation requires its durable session ID. #163421. Thanks @shakkernerd.
- In multi-user installations, only a thread's creator or an administrator can archive or restore it. This also applies to existing threads; being assigned responsibility alone no longer grants that permission. See multi-user conversations. #160932. Thanks @stevenlee-oai.
- Session-scoped users can read shared GitHub publication options and receipts for conversations they may view. Options require a supported current managed repository or worktree; personal accounts and publication mutations retain their own permissions. #162984. Thanks @shakkernerd.
- Shared GitHub publication options remain readable when both the connection grant and role imply session read using different permission names. Later role revocation still prevents the read. #163910. Thanks @steipete.
- Agent discovery follows the current role and waits for a fresh roster after reconnecting. Draft identity edits survive when they still refer to the same profile and intent, and a Stop/completion race no longer leaves a capacity slot occupied. #161019. Thanks @Patrick-Erichsen.
- Sharing controls check fresh stored permissions and visibility after waiting. Outdated membership or ownership cannot carry a request into a replacement conversation, and stale cached visibility no longer turns a needed update into a no-op. #163572. Thanks @steipete.
- Command and skill lists for shared conversations are withheld if access, the conversation or selected skill revisions change during discovery. #163643. Thanks @steipete.
- Delayed owner, membership and suggestion changes reject outdated permissions. Cancelled or revoked suggestions cannot become new input; already accepted suggestions can settle without becoming available for replay. Provider-review pauses block new suggestions and edits while allowing dismissal and accepted settlement. ef27c1fc2b. Thanks @steipete.
- Authorized agent work no longer fails a false permission check when runtime modules load independently or reload. Revocation, cancellation and scope limits still apply. #163725. Thanks @vincentkoc.
- Private automation working notes are withheld after caller access is revoked or ownership changes. Older jobs also avoid false conflicts caused by their creation metadata. #161387. Thanks @steipete.
- Standalone approval pages display supplied payment amounts and recipients, automation terms and duration, message recipients or posting destinations. This supplies decision context without granting permission. #164534. Thanks @steipete.
- Approvals bound to a request survive unrelated agent and secret-store edits. Relevant permission or routing changes permanently revoke the pending approval, even if those settings are later restored. #160856. Thanks @steipete.
- Commands that suppress audit output use the ordinary approval policy for both reads and writes. Eligible requests can use automatic review instead of a special human-only prompt; explicit denial, allowlists and always-ask policy remain effective. #161718. Thanks @jesse-merhi.
- Listing and revoking standing scheduled-command grants moves database administration off the Gateway main thread, with permission checks around changes. Grant validation and consumption at command launch retain their existing path. See execution approvals. #162549. Thanks @steipete.
- Pairing list/approve and default approvals get/set/allowlist edits use authenticated Gateway routing or exclusive offline ownership. Refusal, missing credentials or a lost reply never triggers an automatic local replay; explicit Gateway and node targeting remains available. #164075. Thanks @steipete.
- Prepared node commands with invalid file bindings or policy metadata stay rejected before execution approval. Retired top-level command-text fallbacks are removed; supported
plan.rawCommandremains the canonical input. #164544. Thanks @steipete. - Authorized GitHub publication can include unchanged Actions workflows inherited exactly from the verified target when ancestry is unambiguous. Authored workflow edits and conflict resolutions still require full write authority. #162396. Thanks @steipete.
- A browser using a narrowed token explains insufficient permissions instead of offering a futile Retry. To recover administrator access, run
openclaw dashboard --jsonon the Gateway host and open its fresh browser URL in the same browser, origin and Gateway within ten minutes. #162951. Thanks @steipete. - A CLI
/btwside-question execution context closes even when backend cleanup fails, so later work cannot reuse it. The cleanup error remains visible. #162070. Thanks @steipete. - Unexpected
openclaw security audit --fixerrors stop before the audit and return exit status 1. JSON callers receive the CLI failure response; run a separateopenclaw security auditto inspect the current state. #164159. Thanks @steipete. - Security audits retire the model-age and provider-tier advisories
models.legacyandmodels.weak_tier. Structured-report consumers should account for those removed IDs; the separate small-model tool-exposure check remains. ecb897146e. Thanks @jesse-merhi. - Node turns receive the current filesystem, model and patch-tool policy from the Gateway. Global and agent-specific workspace-only and
applyPatchsettings apply with session-permission precedence, and warm workers refresh their tool catalog for each turn. See the cloud-worker security model. 10ea4739bd. Thanks @steipete. - Codex host-backed file bridges that adopt the supported access contract check actual file targets for reads, opens and metadata. Denied aliases and targets changed after preparation are refused; this contract does not cover every bridge or file operation. #150731. Thanks @vincentkoc, @eleqtrizit.
- New uploads reach reused writable SSH sandboxes, with managed originals and preprocessing or preview files retained for restart. Read-only sandboxes continue to reject writes; this covers inbound uploads. #158026. Thanks @Olli0103, @obviyus, @DaveFan-NCHC, @FelixIsaac.
- Strict
OPENCLAW_FS_SAFE_NATIVE_MODE=requireuses stronger native checks for file mutations. Recursive cleanup can refuse on Windows or Linux withoutopenat2, leaving directories behind; use a supported platform when those guarantees are required. Default automatic mode remains best effort. #160617. Thanks @steipete. - Filesystem upgrades preserve legacy
requiresettings instead of silently relaxing them and add the Windows dangling-symlink exclusive-create safeguard. MoveFS_SAFE_PYTHON_MODEandOPENCLAW_FS_SAFE_PYTHON_MODEto their*_NATIVE_MODEnames. RemoveFS_SAFE_PYTHON,OPENCLAW_FS_SAFE_PYTHON,OPENCLAW_PINNED_PYTHONandOPENCLAW_PINNED_WRITE_PYTHON. Deprecated Plugin SDK hints remain accepted but ignored; direct fs-safe consumers must useconfigureFsSafeNativeandFsSafeNativeConfigwithoutpythonPath. #163408. Thanks @steipete. - Windows plugin paths reject foreign shares and ambiguous device paths before inspection. Use an admitted relative path or the root's host/share spelling for a rejected alias; removing namespace prefixes is not a safe repair. #162574. Thanks @steipete.
- An already-paired local native app can add its first node role with the same key under the existing local auto-approval policy, including an eligible pending retry. Token replacement, revocation, remote and browser connections retain approval requirements. See pairing. #163730. Thanks @steipete.
- Eligible silently paired same-machine native nodes can receive their initial permitted capabilities without an extra review panel, including an app in remote mode whose actual connection is local.
autoApproveLocal=falseretains manual approval; later capability additions, command denies, OS permissions and execution approvals still apply. #163862. Thanks @steipete. - Secret-setting operations run through database workers and wait for acknowledged persistence. Credential questions publish only the safe stored marker; accepted saves survive reset, and compensating rollback cannot overwrite a newer writer's entry. 31806d84f3. Thanks @steipete.
- Core credential readers require explicit
source,providerandid. Doctor repairs registered legacy paths and reports removed extra fields; public SDK input adapters still accept plain providerless references, while extended providerless auth inputs reject before saving. Keep extra metadata outside reference objects. Runopenclaw doctor --fixfor older core references and preserve original backups; Talk and realtime Talk may discard a providerless API-key object before repair. 2c0278b46c. Thanks @steipete. - Profile logout scrubs matching copied catalog credentials while the profile is still saved, and prevents in-flight work from restoring them. Profiles already removed by an older logout cannot be retroactively cleaned this way; an incomplete guarded restoration needs profile inspection. #143647. Thanks @jason-allen-oneal, @obviyus, @steipete, @NovaUnboundAi, @CHAESH, @matthewmoroz, @sunhsiao, @ndakota79.
- Agent command environments and configured secret values are read in a worker instead of querying on the Gateway main thread. Commands reuse one snapshot per run and refresh next run; cancellation prevents launch without poisoning later reuse. Snapshots over 32 MiB fail visibly instead of supplying a partial environment, and individual values retain the 64 KiB limit. #164242. Thanks @steipete.
- Permitted CLI commands work with the secret egress proxy by using the admitted run context. Existing approvals and retired-run restrictions continue to apply. #160760. Thanks @VACInc.
- The secret egress proxy can forward permitted HTTP requests to literal
localhost,127.0.0.1and[::1]addresses. DNS aliases are excluded, and secret substitution remains refused over HTTP. See secret storage and egress. #160974. Thanks @steipete. - LM Studio loading and Copilot discovery or embedding errors mask credentials reflected from encoded request headers. Chutes also accepts the IPv6 loopback OAuth callback
[::1]while retaining the redirect URI. #162488. Thanks @steipete. - Multi-agent OAuth synchronization visits the shared credential owner before sibling agents, preserving inheritance without unnecessary new credential copies. Previously duplicated stored credentials are not removed by this fix. #163243. Thanks @steipete.
- The secrets index opens the existing Bitwarden Secrets Manager and password-store recipes at their correct sections. 721efcefc0. Thanks @Shenrui-Ma.
- A2A status identifies peers with unresolved token settings and tells operators what to repair before reload or restart. Automatic plugin setup retains credential-resolution facts through configuration rewrites, and adding another peer preserves unavailable peers in saved configuration. Deliberately tokenless outbound peers retain anonymous sending. cb24ec1fa7. Thanks @eleqtrizit.
- Ordinary prose following
pass:remains readable, while supported password records and affected long-input Bun cases keep their default masking. Previously lost words in stored output are not restored. #160888. Thanks @steipete. - Built-in token masking handles affected long strings containing plus signs, slashes or equals signs without the previous stalls. #161089. Thanks @steipete.
- Custom
logging.redactPatternsuse 16 KiB chunks again. Matches spanning chunks can be missed, and anchored patterns apply at each chunk's start; built-in data-URL handling remains separate. #161514. Thanks @steipete. - WebSocket log values use secret masking and length limits when JSON serialization fails. Invalid log-level warnings also mask values recognized by the existing redactors before writing to stderr. #164177. Thanks @steipete.
- Secret masking reuses compiled matchers to reduce temporary regular-expression allocations while keeping the same masked output. #164152. Thanks @steipete.
- Cleanup of old generated-HTML trust records preserves a newer record written for the same path while filesystem inspection waits. Existing exact-byte trust and path restrictions continue to apply. #164424. Thanks @steipete.
- Reserved private runtime-context entries are excluded when compaction summaries and saved CLI notes read existing transcripts, including entries lacking replay metadata or opting out of replay. Stored transcript bytes are not rewritten. In the affected legacy-context case, resumed sessions may discard newly queued text or images; resolution of that issue is unconfirmed. #164561. Thanks @steipete.
- Managed Bun services and OpenClaw-owned subprocesses fail locally on missing imports instead of installing packages at runtime. User commands,
bunx, arbitrary third-party launchers and worker-thread resolution remain outside this launch policy. #163270. Thanks @steipete. - The bundled macOS runtime disables implicit package installation across helpers and children using that executable. Explicit installation controls remain available. Its dependency update also reduces duplicate file-watch events and fixes queued WebSocket upgrades, event-listener exception propagation, process-title visibility and worker heap reporting. #163313. Thanks @steipete.
- Matrix, Mattermost and Tlon use the supported nested private-network setting; an old flat key no longer grants access or defeats it. Matrix still permits access when either the root or account-level canonical opt-in is true, so account-level false does not override root-level true. #163535. Thanks @steipete.
- Project
.envfiles no longer control the eight Homebrew download, source and configuration variables involved in installation. Move needed overrides to the launching shell or global environment; ordinary project preferences remain supported. #150912. Thanks @mmaps. - Docker builds from a source checkout exclude root and nested
.crabboxdirectories, keeping their transient credentials and per-run state out of build images. #164163. Thanks @steipete. - The locked dependency graph uses patched
source-map-js1.2.2 for the indexed-source-map denial-of-service advisory GHSA-68fv-2mgg-jv7q. 6d86072f8c. Thanks @steipete, with review by @shakkernerd.
Quality-of-Life Improvements
- Child stops retain completed cancellations through overlapping updates or later cleanup failures. Swarm Stop waits for execution and cleanup, which can remain pending after terminal status appears. After a timeout or incomplete result, inspect remaining children with
subagents action=listand retry; replacement work needs its own Stop. Failed registration retains the child IDs for inspection before retrying. See child operations. - Interrupted replies can still use completed tool results. A silent command timeout can notify its conversation when automatic completion wake is enabled. Check external effects before repeating work. See background-process handling.
- Conversation controls preserve other agents' replies and queued work when short session keys overlap. Files, images and usage reports stay with the selected conversation, and clearing export search restores the sidebar. See session controls.
- Adding a clarification mid-turn preserves the first executable tool or parallel batch; unstarted sequential calls can still be skipped. Use
/stopor/queue interruptto cancel. Cloud-worker context with unsupported media asks you to stop or reclaim the session and retry locally. See steering and transcript handling. - Common command errors explain how to correct or recover the request. Missing results remain unknown, so inspect current state before retrying an action with side effects.
gateway callchecks connection settings; useconfig validatefor a full configuration check. See Gateway calls, command arguments and optional tool-loop detection. - A disconnected terminal send keeps your unsent draft. Custom usage footers refresh after repeated saves, and existing blocker answers no longer need redundant replacement explanations. Older ACPX file-state imports and the legacy Copilot URL rewrite are removed.
- Tool-heavy conversations retain fewer duplicate results and discarded strings; reusable readers release completed requests. Plugin and SDK callers must treat transcript payloads as immutable as soon as they submit them, even while an asynchronous save is pending. Create new values for later updates. Hooks receive saved rewritten activity and omit suppressed entries. See the SDK runtime guide.
- More history, usage and session bookkeeping runs in background database workers, leaving less storage work on the thread handling requests. Confirmed saves publish once; uncertain outcomes stay pending or return recovery guidance. See the worker-access reference.
- Workspace saves and recovery wait for durable records before changing files or reporting success. Stock persona files stay in the configured agent workspace when work runs in a separate project.
Sources and complete change list
- Resume an unfinished built-in-runtime conversation after compaction followed by a Gateway restart, preserving the original request once and retaining distinct queued follow-ups. #160128. Thanks to @steipete.
- Explain when recent messages exceed the context limit and suggest a new session with a brief summary. #160934. Thanks to @RomneyDa.
- Keep completed background tool results available for final answers and empty-answer retries, and keep internal finalization prompts out of user-message history. #161091. Thanks to @steipete.
- Finish stopping a child during an overlapping session metadata update, preserving both the update and recorded stop across retry or restart. Cleanup still checks ownership before affecting replacement sessions. #161461. Thanks to @steipete.
- Let stopped collector children finish recording completion and free their slot during simultaneous session metadata writes, allowing queued work to start while preserving labels and delivery identity. #161676. Thanks to @steipete, @VACInc.
- Record the owning agent when cancelling a watched child with an unqualified session key, preserving other agents’ running work and queued messages under the same key. Older ownerless records still use current configuration. #162540. Thanks to @steipete.
- Return the accepted terminal cancellation when stopping a child overlaps a session metadata update, while refusing to publish an old run’s outcome into a replacement session. #163096. Thanks to @steipete.
- Avoid an unnecessary preparation write when stopping a Swarm child whose session is already ready. Pending changes for that session and final cancellation publication still finish in their normal order. #163485. Thanks to @steipete.
- Make Swarm Stop wait for the selected children’s execution and queued-launch cleanup and report cleanup failures. Terminal task status can appear before cleanup finishes; after a timeout or incomplete cancellation, inspect remaining children with subagents action=list and retry. #163558. Thanks to @steipete.
- Resume the originating conversation after a silent background-command timeout when automatic completion wake is enabled. Check external effects before retrying non-idempotent work. #164171. Thanks to @etzelm, @obviyus.
- Save worker transcripts through symbolic links or directory junctions using the admitted native database location, avoiding the path-alias persistence failure after response generation. #164289. Thanks to @vincentkoc.
- Distinguish confirmed session removal from incomplete or skipped cleanup when handling Stop. 28885d3. Thanks to @steipete.
- Retain counts of child cancellations already committed when later Stop cleanup fails, and show the cleanup error. Inspect remaining runs with subagents; replacement work requires its own Stop request. 6123d17. Thanks to @steipete.
- Let cleanup save a child cancellation it has accepted instead of competing with a sweeper save. e9571d7. Thanks to @steipete.
- Keep child cancellation and its saved abort marker consistent during overlapping metadata updates without stopping replacement work. fef7992. Thanks to @steipete.
- Keep responsibility for cancelling the exact child after required registration fails. Errors retain child session/run IDs and pending-cleanup status; capacity stays reserved until cleanup settles, so inspect the retained child before retrying. Session-maintenance planning also runs separately from archive waits. 7555e3f. Thanks to @steipete.
- Avoid a false permanent cancellation error when subagent metadata is still being saved after selected children have stopped. Wait for that metadata before continuing tree discovery. cf5b871. Thanks to @steipete.
- Keep run files and completion records attached to their original agent and conversation after active run context clears. #161119. Thanks to @steipete.
- Share a pending local identity lookup across simultaneous Codex and Session Share discovery requests, reducing duplicate startup database work without changing discovered nodes and sessions. Missing or failed identity reads remain retryable. #161496. Thanks to @steipete.
- Avoid duplicate validation when Gateway clients establish warm message subscriptions, while preserving access checks and approval replay. #161555. Thanks to @steipete.
- Preserve another agent’s active reply, queued messages and commands when stopping, deleting, resetting or archiving a conversation with a colliding session key. The selected agent’s own work is still cancelled. #161736. Thanks to @steipete.
- Preserve other agents’ queued replies and commands during review pauses, workspace placement changes, rewinds, broad aborts and interrupts sharing a short session key. Broad cleanup removes only the selected agent’s own work across session incarnations. #162179. Thanks to @steipete.
- Prepare requested session-list rows before rebuilding unrelated rows after metadata changes, so overlapping requests can share preparation. #162280. Thanks to @steipete.
- Omit nested tool-result cards from recalled history unless includeTools is explicitly true. #162904. Thanks to @steipete, @RomneyDa, @fuller-stack-dev, @jalehman, @vincentkoc.
- Keep session owners and participant details visible after background updates, preserve newer overlapping changes and publish committed updates despite an observer error. #163030. Thanks to @steipete.
- Find a run’s files and images in its original owning conversation after session aliases change, while explicit session selection still follows current aliases. Current visibility checks apply, and changed or replaced sessions return a retryable failure. #163054. Thanks to @steipete.
- Read usage summaries, charts, logs and costs from the selected transcript or validated store, refusing stale or mixed source locations. #163182. Thanks to @steipete.
- Preserve valid shared-session access while restoring archived history, avoiding an unnecessary retry when forking, rewinding or switching branches. #163669. Thanks to @steipete.
- Save accepted messages and steering input once with current approved content when database paths use aliases or a session manager is reused. #163753. Thanks to @joshavant.
- Keep the first executable tool and parallel tool batches when a clarification arrives mid-turn, delivering real results before the new message. After a sequential tool starts, remaining unstarted calls can still be skipped; use /stop or /queue interrupt to cancel work. #163852. Thanks to @steipete.
- Reuse session ordering for repeated large lists as metadata and filters change. #163941. Thanks to @steipete.
- Restore the full sidebar in HTML conversation exports when Escape clears search, and display malformed stored read-range values as literal text. Valid numeric ranges retain their display. #163997. Thanks to @steipete.
- Keep session usage and context-weight reports available when an unrelated database registration changes during their read, while still checking the selected store and agent attribution. #164217. Thanks to @steipete.
- Keep replacement subscribers receiving activity, context, model and reconnect updates when an old unsubscribe repeats. Remove temporary HTTP listeners after an immediate bind failure. #164221. Thanks to @steipete.
- Repair the session-tool guide’s link to Gateway timeout examples, which explain caller wait separately from the receiving agent’s execution budget. 0338bb3. Thanks to @LinzeShi.
- Release a deleted agent’s model, authentication, memory and database resources without restarting the Gateway. Recreated agents can use external session stores again, while deletion preserves the existing choice to keep files and protects surviving agents’ stores. 40d284f. Thanks to @ceckert, @steipete.
- Keep literal internal status blocks out of streamed and final replies, and keep application context attached to the correct steering message. Cloud-worker context with unsupported media now explicitly asks you to stop or reclaim the session and retry locally. cd9913f. Thanks to @RomneyDa.
- Let simultaneous first-session requests for a fresh agent share database creation, avoiding false replacement errors when another request creates the same store first. 36507e7. Thanks to @RomneyDa.
- Reject unsupported process wait arguments with instructions to use
timeout, keeping output available for a corrected request. #153844. Thanks to @wangmiao0668000666, @obviyus. - Reject unsupported
execworking-directory arguments before a command runs, with guidance to useworkdir. #154248. Thanks to @wangmiao0668000666, @obviyus. - Recognize repeated tool calls rejected for invalid arguments when tool-loop detection is enabled, so the agent can correct the request. #158709. Thanks to @ali-log, @51Google, @obviyus, @VACInc.
- Preserve unusual keybinding names and their string or array overrides when loading and reloading them. #161749. Thanks to @steipete.
- Move repetitive recurring-job starts from debug to trace, retaining useful diagnostic history. Use trace logging to see every recurring start; one-shot starts and failures keep their existing levels. #161895. Thanks to @matthematics1137, @obviyus.
- Honor an explicit session-creation transport timeout in either fallback branch, including inherited spawn policy. Bundled callers using default or null deadlines retain their existing waits. #161969. Thanks to @steipete.
- Guide agents to report requested undelivered results, meaningful changes and unresolved problems, while staying quiet about already-handled background results. #162302. Thanks to @jalehman.
- Keep manual result-collection reminders in running process status, logs and lists when completion notifications were disabled at command launch. Structured followUp and no-exit-wake labels remain until completion; execution and notification policy stay unchanged. #162303. Thanks to @VACInc.
- Avoid command-cleanup modules for affected version queries and package-root library imports. #162311. Thanks to @SunnyShu0925, @love-ai-open-source.
- Preserve unrelated paths when shortening home directories in tool details and CLI diagnostics, including containers whose home is the filesystem root. #162483. Thanks to @boeingchoco, @obviyus.
- Avoid a false blocked-tool warning when steering skips a pending tool that never started. #162513. Thanks to @steipete, @RileyJJY, @dori-jitter, @VACInc.
- Select the intended local transcription program when a home-relative PATH entry passes through a symbolic link and its parent, preserving configured precedence and home directories containing PATH separators. #162680. Thanks to @vincentkoc.
- Refresh file-based custom usage footers after repeated editor saves that replace the file, including deletion and recreation. Refresh still depends on filesystem notifications, which an open old-file handle can delay on Linux. #162733. Thanks to @boeingchoco.
- Preserve intended emoji boundaries on affected Bun runtimes when splitting messages or truncating terminal text, avoiding unnecessary cuts that waste the available space. #162749. Thanks to @steipete.
- Keep POSIX sibling paths containing literal backslashes absolute in CLI diagnostics while shortening actual home-directory descendants. #162800. Thanks to @ly85206559, @boeingchoco.
- Guide agents to leave a note with the unfinished task, blocker, owner and resume condition when paused work has no authorized next step. #162903. Thanks to @steipete, @RomneyDa, @fuller-stack-dev, @jalehman, @vincentkoc.
- Keep unsent slash-prefixed terminal chat after a disconnected send is rejected, preserve newer drafts and allow retry after reconnecting. #163201. Thanks to @ooiuuii, @obviyus.
- Treat a missing tool result as an unknown outcome and guide agents to check current state before repeating actions with side effects. Warn operators when request history changes unexpectedly. #163379. Thanks to @steipete.
- Give common chat, terminal and Control UI errors a short explanation and recovery step, with expandable details. Keep uncertain dispatched outcomes, manual database recovery and Stop-saving warnings visible. #163381. Thanks to @vincentkoc.
- Restore specific recovery guidance for disconnected Codex devices, outdated workers and offline runners. #163538. Thanks to @vincentkoc, @steipete.
- Explain that an allowed nested configuration parameter is unset and point to config set instead of calling it unknown. The message does not establish provider support for that parameter. #163682. Thanks to @steipete.
- Cap oversized log-follow intervals so timer overflow cannot turn a long wait into rapid Gateway polling. #163791. Thanks to @LinzeShi.
- Show the Gateway’s specific error when a visible child session fails startup or registration, including unconfirmed cleanup. #163798. Thanks to @obviyus, @DonnieFi.
- Let Bun source installations launch from external agent workspaces, retain the selected agent in shared-store usage reports, and keep admitted child completion work tracked through graceful restart or suspension. #163821. Thanks to @steipete.
- Restore standard MIT license recognition while keeping the same terms and third-party notices available through the README and package. #163838. Thanks to @Patrick-Erichsen.
- Observe model-preparation failures while the terminal UI is idle, preventing an extra unhandled-rejection report while retaining the original error. #163842. Thanks to @jalehman.
- Suppress late approval messages after terminal shutdown. Older ACPX file-state imports and the legacy Copilot-host-to-Codex URL rewrite are removed. #163854. Thanks to @steipete.
- Send literal
constructorand__proto__text to interactive processes even when cursor-key mode is unknown. #163963. Thanks to @steipete. - Keep queued voice, Talk and upload diagnostics attached to the submitting request instead of a preceding task’s trace. #164105. Thanks to @harshitgupta31415, @obviyus.
- Close the temporary agent and shared databases before deleting one-shot agent exec state, including when worker registration finishes late. #164483. Thanks to @RomneyDa.
- Preserve an answer that already reports results and explains a concrete approval, input or dependency blocker. Its completion check can finish silently while authorized unfinished work still receives the check. #164896. Thanks to @obviyus.
- Start replies in the current session working directory, using the configured default if its override was cleared. 863e377. Thanks to @steipete.
- Make Gateway CLI option links jump to their descriptions on the running, query and discovery reference pages. 1edf7ea. Thanks to @qingminglong.
- Give
config patchrefusals usable--replace-pathretry advice, including punctuation and quotes in provider names. Show separate bash/zsh and PowerShell spellings when needed. e6b3a11. Thanks to @sxh313, @obviyus. - Avoid unused CLI startup imports and let
gateway callvalidate connection settings without checking unrelated configuration. Useconfig validatefor a full check. Preserve literal resolved credentials and report cleanup permission failures after identifying a listener. 01d59ff. Thanks to @steipete. - Reduce repeated copying when selecting child sessions that must be protected during maintenance. #161526. Thanks to @steipete.
- Copy only relevant child-run records for control and prompt context, avoiding unrelated tasks in large histories. #161690. Thanks to @steipete.
- Reuse database workers on macOS and Linux Bun builds that pass native SQLite cleanup checks. Stock Bun 1.4.2, Windows and inconclusive checks retain conservative worker retirement. #161764. Thanks to @steipete, @vincentkoc.
- Load fewer unrelated modules when starting session, history and usage readers. #162609. Thanks to @steipete.
- Share preparation for session updates sent to several clients and avoid repeated secret-filter checks within one output pass. #162810. Thanks to @steipete.
- Release catalog listeners and disconnected-client caches after stalled discovery or reconnects, while continuing to track genuinely unfinished native work. #163688. Thanks to @steipete.
- Avoid copying the old transcript while validating and adopting concurrent history updates. #163710. Thanks to @steipete.
- Avoid rebuilding full session lists or copying unrelated details during lifecycle actions in large stores. Background storage handoffs can still add to total request time. #163815. Thanks to @steipete.
- Share immutable published session and worker facts instead of repeatedly copying them for inventory and placement reads. #164102. Thanks to @steipete.
- Retain less unnecessary data from settled tools, private Code Mode results and published child records during long tool-heavy runs. Persist trajectory events in batches within the existing rolling retention limit. #164199. Thanks to @steipete.
- Share submitted transcript data to retain fewer duplicate tool results. Plugin and SDK callers must treat payloads as immutable immediately, including while an asynchronous save is pending, and create new values for updates. #164251. Thanks to @steipete.
- Release discarded large tool output when a transcript keeps only a short excerpt, including excerpts carried through prepared redaction metadata. #164361. Thanks to @steipete.
- Release completed read requests and their prompt or transcript data from reusable SQLite read workers while keeping those workers available for later reads. #164370. Thanks to @steipete.
- Release duplicate completed tool data and finished-run state during long Code Mode sessions, retaining saved history and the five-minute warm-worker window. Lifecycle hooks receive saved rewritten activity and omit suppressed entries. #164386. Thanks to @steipete.
- Reuse frozen configuration captures during reply and tool preparation instead of repeatedly copying unchanged settings. Active turns retain their admitted policy and new work receives updated settings. #164398. Thanks to @steipete.
- Retain less nested transcript bookkeeping and share compiled validators for equivalent schemas. Schema contents determine reuse; the SDK’s
cacheKeyno longer selects it. #164467. Thanks to @steipete. - Share equal immutable data between initial history and model context, including incognito sessions, while keeping private fields outside the model’s view. #164502. Thanks to @steipete.
- Let eligible idle history readers release their database using their recorded capability, and defer the default heap-limit probe until memory diagnostics need it. 9137cfc. Thanks to @steipete.
- Reduce transcript-worker imports to the board and progress-card schemas they use, avoiding the broader Gateway protocol dependency. a02d441. Thanks to @RomneyDa.
- Read shared GitHub publication status and recovery records in database workers, reducing storage work on the Gateway request thread. #161214. Thanks to @steipete.
- Reduce repeated database checks for cached state, profile access and session listings while detecting schema changes and revoked ownership. #161678. Thanks to @steipete.
- Gather cloud-worker idle-suspension candidates in a database worker while retaining the existing suspension policy and pending-recovery exclusions. #161849. Thanks to @steipete.
- Gather remote-worker disk-monitor candidates in a database worker while retaining the existing probes and disk warnings. #161878. Thanks to @steipete.
- Resolve requester profiles in database workers for the covered metadata, model-list, search and profile requests, checking current access before effects. #162414. Thanks to @steipete.
- Keep newer upstream-session links intact when delayed monitoring results arrive, preserve retry progress after a failed event write, and continue processing other provider results. #162518. Thanks to @steipete.
- Run conversation archive checks in database workers before writing durable history. #162521. Thanks to @steipete.
- Gather health and status session summaries in database workers while preserving counts, recent-session order and current store ownership. #162625. Thanks to @steipete.
- Save remote-worker acknowledgments in database workers before continuing workspace-result recovery. #162975. Thanks to @steipete.
- Let the Gateway handle other pending work between session-list preparation batches, while concurrent callers still share preparation and receive the same ordered visible results. #163031. Thanks to @steipete.
- Read archived-session status in database workers and send restore notifications only after a successful settled restore. #163041. Thanks to @steipete.
- Check attachment ownership in database workers and recheck current session access and download tickets before returning protected media. #163049. Thanks to @steipete.
- Read long histories for recovery, usage totals and MCP App restoration in database workers, publishing prepared messages after commit. #163053. Thanks to @steipete.
- Prepare covered agent and recovery session reads in database workers, rejecting delayed results after cancellation or session replacement. #163115. Thanks to @steipete.
- Copy and relink restart-interrupted conversations in database workers while keeping recovery atomic. #163119. Thanks to @steipete.
- Move completion and reply-preparation transcript reads into database workers, adopting committed messages before notifying observers. #163120. Thanks to @steipete.
- Avoid scanning every saved session key when checking an agent-specific store during session creation. #163163. Thanks to @steipete.
- Prepare covered conversation lists, routing addresses and manual-compaction bindings in database workers. #163208. Thanks to @steipete.
- Save and prune durable usage-report cache data in database workers, keeping refresh locks and known lost-reply recovery without repeating writes. #163287. Thanks to @steipete.
- Move selected routine session-metadata transactions into database workers and publish after confirmed commits. Lost worker replies do not repeat committed writes. #163378. Thanks to @steipete.
- Read session versions, bounded history, update watches and notice acknowledgments in database workers without losing queued events during a handoff to the same database. #163513. Thanks to @steipete.
- Read shared-session suggestions in a database worker and filter them by current access before returning them. #163546. Thanks to @steipete.
- Read durable pending messages for chat history and startup in database workers, and retain confirmed interruption status after a lost worker reply. #163582. Thanks to @steipete.
- Move worker-transcript replay bookkeeping into database workers while preserving sequence order and duplicate detection. Unknown writes stay pending for recovery. #163594. Thanks to @steipete.
- Read saved history for compaction, reset hooks, side questions, exports and asynchronous SDK consumers in database workers. Worker failure does not fall back to a blocking durable read. #163605. Thanks to @steipete.
- Save supported transcript, queued-input, session and Goal changes together in background storage work. Publish confirmed saves once; unknown outcomes stop without repeating writes. #163889. Thanks to @steipete.
- Keep checking incognito workers when disk-backed session preparation fails, leaving affected disk sessions unknown rather than treating them as absent. #163972. Thanks to @RomneyDa.
- Batch database-schema metadata reads instead of repeating queries for every table and index. #164077. Thanks to @steipete.
- Avoid serializing unchanged prompt, skill and diff snapshots during routine metadata updates, while fully saving changed or cleared snapshots. #164093. Thanks to @steipete.
- Check board membership once per session-list batch instead of once per row, using one committed snapshot for the results. #164094. Thanks to @steipete.
- Track conversation-environment activity with one fewer database read per touch while retaining current attachment and ownership checks. #164108. Thanks to @steipete.
- Use indexed ownership checks for already-admitted state handles while retaining conservative checks for other connections. #164110. Thanks to @steipete.
- Reuse bounded prepared database statements while each query still reads current data. #164117. Thanks to @steipete.
- Read needed activity and lifecycle details without loading unused saved prompts, skills or diff baselines. #164125. Thanks to @steipete.
- Save pending chat and agent input in background storage work. Final outcomes and cleanup wait for accepted saves; SDK callers can explicitly await completion without replaying an uncertain write. #164284. Thanks to @steipete.
- Prepare watched-conversation context in background storage work with current visibility checks. Plugin authors can await the new authority-bound helper; the synchronous helper remains supported. #164288. Thanks to @steipete.
- Record session creation, compaction and child-launch signals, and prune lifecycle history in database workers. #164367. Thanks to @steipete.
- Remove or restore saved Codex and Agents API session bindings in background storage work, blocking reuse after uncertain outcomes. #164391. Thanks to @steipete.
- Move selected chat writer claims, model-switch updates and final-delivery bookkeeping into database workers. #164514. Thanks to @steipete.
- Reread selected session-creation metadata in a database worker while checking current routing and intervening writes. #165360. Thanks to @steipete.
- Allow concurrent first transcript writes to create a new session store without mistaking another writer’s creation for a replacement. 922d989. Thanks to @steipete.
- Avoid a repeated database admission read during cold-transcript preparation. 0853228. Thanks to @steipete.
- Run durable single-session reset storage in a database worker and publish acknowledged resets after a lost reply without repeating their writes. 850c49c. Thanks to @steipete.
- Keep new stock persona templates in the configured agent workspace when direct, child or session-bound scheduled work runs in a separate project. The project retains its working directory and AGENTS.md instructions; existing files remain. #161088. Thanks to @obviyus, @nikosml.
- Store workspace save and recovery journals in database workers. Wait for durable records before changing files or reporting success; uncertain commits retain files and recovery records. #161539. Thanks to @steipete.
- Prepare workspace snapshots, aliases, setup updates and expiry cleanup in background storage work. Plugin authors can adopt a SQLite-free
guard.assertHost;beforePersistentApplyremains supported until the next SDK major. #163496. Thanks to @steipete. - Share Git discovery for matching concurrent opt-in observed-project requests. Default project listing is unchanged, and a slow bulk discovery can still delay unrelated metadata reads. #162016. Thanks to @steipete.
Other Bug Fixes
- A Linux command that runs out of file handles fails without stopping other streaming commands. On restrictive Linux hosts using Node and matching native host and worker builds, cleanup can release a worker for the next turn despite denied process-group signals. If cleanup cannot be confirmed, the worker remains unavailable; restarting alone does not clear that condition. Cloud-worker moves and dispatches can recover a finished result without waiting for a timeout.
- Cancelling worker chat lets the current turn clean up without another provider call. Startup cleanup remains retryable when a supervisor disappears before its broker is ready. Shutdown attempts worker-connection and transfer cleanup even when inventory is unreadable, then reports that error.
- Credential saves preserve a paired host's launch reply. Linux cleanup no longer mistakes the covered exited tasks for running ones; permission errors remain inconclusive. Saved workspace-recovery errors retain the readable process diagnostics shown on screen.
- Repository sessions retain saved workspace identity, and unrelated writes preserve new session-state events. Lost category-edit replies no longer repeat unrelated reads. Temporary database contention before work starts gets bounded retries; workers lost before dispatch can be replaced without resending the turn. Doctor warnings show underlying failures.
- Snapshot cleanup preserves replacements at reused paths. The covered staging, lock and rollback failures retain their original errors while valid cleanup finishes. If the snapshot-management process is lost, unresolved files remain protected until service recovery. Restarting it alone does not make manual deletion safe; consult the database recovery guidance.
- Native Incognito conversations delete successfully. Archives, pending inputs and transcript checks recognize aliases for the same database. Session discovery retains valid Incognito and placement information despite unrelated registry changes or invalid disk candidates.
- Scheduled turns and Control UI chats on native Windows avoid the affected session-read errors. Commands and workers can skip an optional compile cache when its long path is unsafe. If an externally set
NODE_COMPILE_CACHEhangs before OpenClaw starts, useNODE_DISABLE_COMPILE_CACHE=1. SQLite inspection subprocesses also preserve explicit recognized Node compiler settings. - Commands containing a literal NUL are rejected before helpers start or running work is replaced, with correction guidance. Valid multiline commands remain supported in the exec tool. On POSIX systems,
config patch --fileandconfig set --batch-filereject named pipes without a writer instead of waiting indefinitely; regular files and symlinks remain supported. - Configuration errors show which file failed validation and why. If an external edit invalidates or removes the file while a change is being applied, the request reports an error and keeps the last working runtime settings. Repair the file, call
config.get, then reapply the change. Pairing lists skip malformed entries, reject invalid schema type lists, and keep existing system-agent approval details. - Network updates fix compressed responses and redirects while preserving Slack proxy compatibility. Replaced skill folders can be watched again, with polling fallback available. Doctor retains loaded native plugin files after cleanup.
- Finished chats, old display rows, disconnected tool subscriptions and short previews release unneeded data without interrupting accepted work. Non-Windows Bash and Zsh caches retain recent shell snapshots. Abandoned HTTP responses can release buffers when garbage collection runs; SDK callers should still finish or cancel response bodies for prompt cleanup.
Sources and complete change list
- Linux streaming commands fail individually when file descriptors run out, leaving unrelated commands running. Thanks to @awss1i, @obviyus.
- Native Windows scheduled turns and Control UI chats avoid session-read DataCloneError failures, including configured session stores. Thanks to @steipete, @aniketkrs, @yashas-13, @WG-Mojo, @hailongguo0530-alt, @jonathanlindsay, @chiyunshen, @jocojolo, @mick-lu-lingyue, @zouxiao777, @zhangming678, @yihan331313, @godinpt-floada, @webdood, @veritasaiflows-cell, @aron-intframe, @Monkeykingll, @avirtudazo-officeconnect.
- Restrictive Linux hosts can finish descendant-process cleanup when process-group signals are denied, with matching native host and worker builds. Thanks to @sallyom, @steipete, @RomneyDa.
- Moving or dispatching a session to a cloud worker can settle recoverable finished results instead of waiting for a timeout. Thanks to @steipete.
- Saving Gateway credentials preserves the paired host launch reply when reads of an unchanged environment are blocked. Calls that can no longer complete report failure instead of waiting for a misleading timeout.. Thanks to @steipete.
- A lost reply to a committed category edit no longer invalidates unrelated session reads. Thanks to @vincentkoc.
- Interrupted database reads retain snapshots still in use until their original owner finishes cleanup. Thanks to @steipete.
- Malformed pairing-list entries no longer abort the whole read, invalid schema type lists are rejected, and SDK readers retain existing system-agent approval details.. Thanks to @steipete.
- Repository sessions retain their committed workspace identity when a reply is lost, and cleanup preserves replacement database files. Thanks to @steipete.
- Late cleanup of an old temporary database snapshot leaves a replacement at the same path intact. Thanks to @steipete.
- Database contention before a snapshot directory is created reports the original retry error without a false cleanup failure. Thanks to @steipete.
- Cleanup remains retryable when a supervisor disappears before its command broker is ready. Thanks to @steipete.
- Unrelated database or session-metadata writes no longer discard newly recorded session-state events. Thanks to @steipete.
- Invalid or missing external configuration edits return an application error instead of leaving the request waiting. Thanks to @steipete.
- Database rollback cleanup finishes even when a callback throws, while retaining the original error. Thanks to @steipete.
- Temporary database contention before agent work starts gets bounded retries, and later requests can try again after failure. Doctor repair warnings also show underlying failures.. Thanks to @steipete, @marcoschierhorn, @waynegault, @produtoramaxvision, @hannnnn-l, @islandpreneur007, @yaohd100, @RomneyDa.
- HTTP dependency updates fix compressed-response and redirect handling while preserving Slack proxy compatibility. Thanks to @vincentkoc.
- Windows CLI launches and child processes can skip the optional compile cache when its path is too long. Thanks to @steipete, @NickM83.
- Non-Windows Gateway Bash and Zsh shell snapshots retain only the 128 most recent working-directory and environment cache entries. Thanks to @steipete, @aniruddhaadak80.
- Cancelling a worker chat lets its existing turn finish cleanup without starting another provider call. Thanks to @Patrick-Erichsen.
- An unavailable agent database worker is replaced before dispatch, so a pending turn need not be resent. Thanks to @goutamadwant, @steipete, @hawkit.
- Pending session inputs append correctly when the state directory is accessed through a filesystem alias. Thanks to @RomneyDa, @vincentkoc.
- Old parent display rows release obsolete child data while preserving links and viewer information. Thanks to @steipete.
- Completed chat registrations and obsolete usage and prompt data are released. Disconnected session reads stop further preparation retries after accepted work settles.. Thanks to @steipete.
- Abandoned provider, MCP and plugin HTTP responses can release their retained buffers and readers when garbage collection runs. Thanks to @steipete.
- On POSIX systems, config patch --file and config set --batch-file reject named pipes without a writer instead of hanging. Thanks to @GoldArowana.
- Disconnected clients release tool-event subscriptions, and late visibility requests cannot recreate those subscriptions. Already accepted agent work continues.. Thanks to @steipete.
- Short command tails, Memory Wiki previews and web-fetch metadata no longer keep discarded large strings in memory. Thanks to @steipete.
- Shutdown attempts worker-tunnel and shared-transfer cleanup even when worker inventory cannot be read, then reports the inventory error. Thanks to @steipete.
- SQLite inspection subprocesses retain recognized explicit Node compiler enable and disable flags in their original order.. Thanks to @RomneyDa.
- Commands containing a literal NUL character are rejected before helper startup or replacement of running work. Thanks to @shakkernerd, @IWhatsskill.
- Replaced skill folders can be watched again, file watching retains its polling fallback, and Doctor keeps loaded native plugin files available after cleanup.. Thanks to @steipete, @vincentkoc.
- Native Incognito sessions delete successfully, and archives stay in the configured store’s artifact directory when its database path is an alias. Thanks to @steipete.
- Refused snapshot-directory creation keeps its original error and lets other valid snapshots finish cleanup. Thanks to @steipete.
- Worker cancellation can finish when the last native operation ends between cleanup checks. Thanks to @steipete.
- Linux process checks confirm an exit when a status file disappears between checks, without treating permission errors as proof of exit. Thanks to @steipete.
- Saved workspace recovery errors match displayed diagnostics when process start dates contain padded spacing. Thanks to @steipete.
- Linux cleanup recognizes exited processes during kernel reaping while preserving live-thread and permission safeguards. Thanks to @steipete.
- Gateway requests unrelated to image routes avoid unnecessary image-handler session-context lookup. Thanks to @steipete.
- Concise CLI configuration errors include the file path and validation reason when those details have not already been printed. Thanks to @steipete.
- Session discovery retains valid Incognito and placement information despite unrelated registry changes or invalid disk candidates. Thanks to @steipete.
- Transcript and question-answer receipt checks accept equivalent paths to the same database, including filesystem aliases. Thanks to @vincentkoc.


