Get started

v2026.8.1: Updates and Maintenance

Users could sometimes experience instability after updating OpenClaw. Supported update paths now inspect the installation before replacing it and stop unsafe candidates while leaving the previous CLI runnable. In the Control UI, updates identify the target, ask for confirmation, and keep progress and the final outcome visible.

Maintenance tools now provide clearer recovery paths. Configuration errors point to the setting that needs attention, Doctor focuses on problems and the next action, new backups are checked against the guarded restore path, destructive cleanup stops when ownership is unclear, and supported restarts give tracked work time to finish before handoff.

Installing OpenClaw Updates

Gateway updates started in the Control UI now identify the target, require confirmation, show progress through the update and restart, and report the final outcome. On eligible signed Mac apps, that flow updates the app first and then only the app-managed local Gateway; browser and user-managed installs keep their Gateway-only path.

Supported CLI updates check Node compatibility, package-manager lifecycle rules, and whether npm, pnpm, or Bun owns the installation before replacement. An unsafe candidate stops while leaving the previous CLI runnable, and an exact openclaw update --dry-run previews the path without changing configuration, handoff, cleanup, or restart state.

On Linux, code updates can preserve an administrator-owned service definition instead of trying to rewrite it, while an unsafe or uninspectable service handoff still fails visibly. If a plugin replacement asks for new capabilities, OpenClaw keeps the known-good plugin available while the replacement waits for review; openclaw update --accept-capabilities or openclaw update repair --accept-capabilities approves only the staged artifact for that invocation, and --yes does not.

One upgrade path still needs a manual repair. If you are on OpenClaw 2026.7.1 with pnpm 11, run pnpm add -g openclaw@latest once. OpenClaw does not upgrade Node for you.

Sources and complete change list

Improvements

  • Add persistent update cards and app-first macOS updates #104171
  • Coordinate macOS app and managed runtime updates #107634
  • Add signed updates to the Linux companion app #108770
  • Add safe extended-stable Docker channels #112494
  • Allow experimental OpenClaw use on node:sqlite-capable Bun builds #114256
  • Add scheduled update campaigns and an Updates settings page #120506
  • Confirm Control UI updates before installing and restarting #121234
  • Refresh moving Docker image tags weekly #123348
  • Speed up the Bash Git installer with a blobless clone #123835
  • Add typed update recovery in the Control UI #125098
  • Retire pre-2026.4 compatibility paths #104650
  • Standardize update and plugin version ordering with SemVer #105944
  • Let Linux development builds choose the install channel #109242
  • Add a safe update path for source-checkout Gateway servers #112557
  • Recommend and provision Node 26 for new installs #114399
  • Move Synthetic to an official external provider plugin #116720
  • Move the Xiaomi provider to an official external plugin #116861
  • Speed up dev-channel source updates #117246
  • improve(update): use local pnpm packages before the registry #130902
  • improve(update): reuse unchanged dependency work during preflight #130903
  • chore: migrate tooling and source installs to pnpm 12 #131043
  • Add a separate update channel for macOS and Windows test builds #109244
  • Unify plugin installs and retire legacy worktree records #114749
  • Reuse macOS Gateway executable search paths #116323

Bug fixes

  • Make the update card reachable and route macOS updates correctly #104316
  • Preserve working installs on unsupported Node versions #106994
  • Preserve Codex plugin policy during upgrades #107285
  • Clarify Mac app and Gateway update actions #107793
  • Preserve pnpm 11 and Bun ownership during updates #107802
  • Repair obsolete managed Gateway Node runtimes during update #108668
  • Preserve unrelated Node compile caches during install #113837
  • Keep update dry runs truly read-only #114803
  • Stop macOS app replacement retry storms #114975
  • Refuse symlinked build output roots #116705
  • Repair stale plugin host packages after upgrades #118304
  • Keep extended-stable installs on their update channel #118518
  • Keep targeted official plugin updates on the core channel #119799
  • Keep node hosts compatible across Gateway protocol v3 and v4 #119981
  • show authoritative dev checkout update status #120769
  • Complete high-volume stable upgrades without cleanup stalls #124651
  • Make package lifecycle trust explicit during install and update #124727
  • Keep npm installer retries on the requested channel #124778
  • Prevent Gateway polling stalls and unnecessary hidden-tab refreshes #124891
  • Make install, update, and uninstall outcomes transactional #125992
  • fix(update): keep code updates working with sealed service definitions #131021
  • fix(plugins): keep Gateway available while upgrades await consent #131290
  • fix(update): preserve explicit plugin capability consent #131301
  • Retry failed npm installs once in the Windows installer 8dd204e
  • Stop timed-out updater process trees #103406
  • Update managed macOS Gateways from validated runtime snapshots #104946
  • Preserve ClawHub plugins after core updates #105405
  • Let Android connect to Gateway protocol v3 #106205
  • Let Apple node sessions connect to protocol v3 gateways #106294
  • Reject PATH Node runtimes with broken npm #107825
  • Make Windows installs resilient to stale short TEMP paths #108050
  • Preserve working installs during pnpm and Bun updates #108090
  • Let npm 12 global updates complete safely #108100
  • Preserve official plugin config and harden npm metadata installs #108336
  • Stop shell installers from hanging on stalled downloads #108619
  • Relaunch trusted macOS app replacements #108991
  • Fail closed on corrupt post-core update handoffs #109989
  • Recover when Control UI styles fail after an update #110523
  • Report newer releases for pinned npm plugins #111169
  • Verify managed updates and keep Skill Workshop within mobile screens #112987
  • Keep source-checkout updates clean after builds #113094
  • Repair legacy channel config after plugin installation #113317
  • Repair legacy plugin configuration during upgrades #113324
  • Reject incomplete Git installer checkouts #113809
  • Prevent package cleanup from deleting required runtime modules #113821
  • Keep managed Gateway updates in the owning profile #113901
  • Finish ClawHub plugin cleanup and unblock immediate retries #114090
  • Surface manual Linux update-check results #114312
  • Keep bulk official-plugin updates on the installed beta channel #115083
  • Finish package and git source switches in a fresh CLI #115292
  • Reject invalid plugin installs before mutations #115427
  • Let macOS Dev source installs finish cold builds #116072
  • Restore installs with an available TypeBox release #116333
  • Preserve configured channel plugin access after updates #116540
  • Restore runnable builds after failed Git updates #117294
  • Reject unknown targeted plugin updates #117333
  • Reject cyclic plugin marketplace aliases #117440
  • Keep update dry-runs from changing local state #118856
  • Report failed Windows migration checks honestly #120033
  • Repair cross-OS release checks and legacy node metadata #120442
  • Keep pinned dev update campaigns working after restart #121328
  • Keep automatic update countdowns stable #121504
  • Show truthful Gateway update progress and outcomes #121686
  • Avoid duplicate plugin installs during updates #122161
  • Prevent stale state from carrying into post-update finalization #122309
  • Stop bundled plugin startup convergence loops #122871
  • Restore plugin CLI access after retained reinstall #123043
  • Install externalized configured plugins after upgrades #123399
  • Reject unusable local-prefix installations #123716
  • Keep the Codex plugin matched to stable OpenClaw upgrades #124209
  • Enforce one cooldown across automatic dev updates #124626
  • Align Node version checks across install, launch, and workers #124812
  • Keep failed Git clones from poisoning install directories #124872
  • Reject invalid Windows installer options before setup #124882
  • Restore installs and updates on npm 11.13 through 11.15 #125452
  • Schedule dev updates after slower Git fetches #125705
  • Validate target config before managed Gateway handoff #126270
  • fix(doctor): repair plugin host links before startup migration #126830
  • Report Unix installer success only after required checks #126871
  • fix: installing an official plugin on a beta gateway lands the stable release #127791
  • fix(update): use prepared Gateway install identity #128187
  • fix(update): reject incomplete Control UI bundles #128825
  • fix(update): bind managed handoffs to exact targets #128868
  • fix(plugins): make marketplace installs transactional #129266
  • fix(update): keep custom Bun global updates on their original installation #129589
  • fix(release): normalize package tarball modes and prove non-root install #130335
  • Fix linked hook and nested pack discovery #130813
  • fix(installer): avoid checking out the wrong Git ref during pinned installs #130907
  • fix: Git update can report success while Web UI serves old build #130957
  • fix(update): LaunchAgent refresh no longer self-identifies as Gateway #131013
  • fix(update): preserve plugin convergence through package restart #131062
  • fix: interactive update can leave the Gateway stopped when completion refresh fails #131393
  • fix(update): avoid declaration build timeouts when switching to dev #131746
  • fix(update): dev upgrades exhaust small POSIX temporary filesystems #132085
  • fix(doctor): repair channel config after external plugin installation #132446
  • fix(installer): restore commit-pinned source installs #132458
  • fix(installer): prevent source bootstrap from rewriting pnpm metadata #132608
  • fix: prevent restart after dirty rollback builds #132813
  • fix(doctor): preserve health repairs during stable upgrades #132934
  • Verify profile-scoped macOS updater jobs before cleanup #97264
  • Clean up CLI installer temporary files after failures #103725
  • Remove installer temporary files after commands finish #104049
  • Restore July release guards and current-main validation #107462
  • Hide the update guide after Mac app-only updates #108034
  • Bound update checks when registry response bodies stall #108606
  • Stop stalled Windows installer downloads from hanging forever #108791
  • Bound sandbox installer downloads before execution #108805
  • Split plugin updates and preserve fallback install policy #108877
  • Handle live-updater lock creation races and stabilize tooling tests #109877
  • Verify ACPX native adapter packages during install #111682
  • Add one-click refresh for protocol mismatch #111772
  • Hide update divergence for incomparable Git histories #111946
  • Report Windows source UI build failures correctly #112053
  • Keep versioned plugin installs registry-backed in source checkouts #112829
  • Recognize Bun text lockfiles in update status #114416
  • Use managed runtime dependencies for Twitch packages #115147
  • Label beta updates in the Control UI #115518
  • Honor configured channels for targeted plugin updates #115604
  • Restore the legacy Docker apt-package fallback #116466
  • Accept npm ranges and tags in staged global updates #116585
  • Return failure when local changes block an update #117452
  • Detect lockless global Bun installations correctly #118143
  • Allow plugin update previews in immutable Nix mode #118431
  • Select the correct root-help bundle during source builds #119590
  • Handle vanished updater process groups correctly #119614
  • Preserve startup version during plugin repair #120085
  • Retire stale managed shadows of bundled plugins after updates #121261
  • Keep dev auto-updates running after failed handoff checks #121664
  • Let updated plugins migrate legacy config before validation #122199
  • Restore update tracking for detached Dev checkouts #122415
  • Keep relative-path CLI installations working after directory changes #122626
  • Remove stale Plugin SDK declarations from build caches #122837
  • fix(update): route stored dev channel to the git update flow [AI-assisted] #123083
  • Find the correct checkout when updating from version-managed launchers #123197
  • Report Linux build-tool installation failures honestly #123817
  • Reject blank required update fields in the Control UI #124264
  • Report accurate update status for detached development installs #124611
  • Stop reporting valid dependency installs as stale #124627
  • Recognize successful Windows installs with deferred PATH refresh #124678
  • Defer updater migrations until an update will proceed #125124
  • Preserve committed plugin updates when stopping the helper #125150
  • Report plugin updates only after they commit #125739
  • Fail fast when package users request --tag main #125949
  • Rebuild incomplete managed-update cache hits #125954
  • Keep default plugin slots implicit #126442
  • fix(plugins): plugins update reports a version downgrade as a successful update #127874
  • fix(cli): installed hook packs cannot update by npm package name #128281
  • fix(installer): honor explicit git target inside another checkout #128407
  • fix(install): preserve Git command when npm verification fails #128502
  • fix(plugins): report Git plugin updates when their package version is unchanged #128841
  • fix(update): fail the git updater when the final HEAD verification probe errors #129036
  • fix(cli): start under Bun 1.4 without warning filter #129142
  • fix(docker): correction-release images report their full version #129178
  • fix(update): retain registry failures in update status #130931
  • fix(cli): reject unsupported inherited --dry-run on update status #132195
  • fix: git updates fail while restarted gateway is starting #132879
  • fix: remove repeated installer finalization delays #133190

Documentation

  • Fix pnpm global build approval instructions #106180
  • Recommend Node 26 across installation entry guides #115064
  • Document npm 12 lifecycle-script approval for global installs #115224
  • improve: verify packaged runtime on Bun 1.4 #129552
Configuration Errors and Service Repairs

Bad configuration now stops with a useful answer instead of quietly starting OpenClaw with something else. Packaged builds, CLI checks, service preflight, and Gateway startup show the file, line, full setting path, allowed values when available, and a safe version of what was received; malformed top-level scalar files fail closed instead of loading defaults.

If you are upgrading a configuration that still contains retired keys, run openclaw doctor --fix before September 18, 2026. Doctor keeps canonical values when old and new keys conflict and removes settings that no longer do anything, although explicitly retired tuning values return to the built-in defaults.

Supported Gateway service repairs preserve the installed state directory, config path, port, managed environment, and eligible file-backed credentials instead of silently retargeting the service. Changing those targets intentionally requires openclaw gateway install --force; on Linux, service commands also refuse conflicting user and system units and show which unit owns the Gateway.

Sources and complete change list

Improvements

  • Add Fleet cells for isolated multi-tenant hosting #104527
  • Harden Fleet cell creation and operator guidance #104814
  • Add Fleet cell backups, limits, egress controls, and diagnostics #104828
  • Reduce and standardize the configuration surface #111142
  • Remove tuning-only configuration knobs with stable built-in defaults #111382
  • Consolidate OpenClaw configuration and legacy migrations #111527
  • Switch macOS dashboards between gateways #113965
  • Scale agent concurrency to the host CPU #114047
  • Move macOS gateway settings into the Dashboard #115999
  • Add an experimental Cloudflare Containers deployment template #122768
  • Add a managed macOS elevation-host workflow #123569
  • feat(daemon): support Bun 1.4 managed services #129593
  • Add supervisor-owned Fleet cell log streaming #104669
  • Make config validation errors easier to locate #106526
  • Retire redundant configuration settings #113174
  • Retire obsolete diagnostics configuration shapes #113946
  • Add multi-gateway controls to the Mac menus #114038
  • Show the active Gateway in the Mac sidebar footer #114059
  • Reduce repeated macOS config polling work #115886
  • Remove unsupported environment-variable overrides #105970
  • Compact the native macOS Gateway picker #115977
  • Refresh native translations for current gateway settings #118356

Bug fixes

  • Stop stale device pairing buildup and unify the Nodes inventory #102810
  • Restore detailed config errors in packaged builds #104026
  • Fix Windows gateway launchers for CJK profile paths #107751
  • Restore replies when compaction modes are omitted #114759
  • Prevent gateway repairs from retargeting managed services #115935
  • Make config patch delete only the requested array entry #116463
  • Accept documented configWrites settings across bundled channels #117206
  • Preserve file-backed gateway credentials during service updates #120458
  • Keep the macOS Gateway supervised during reinstall failures #120699
  • Stop false stale-service warnings after upgrades #120702
  • Make config validation errors actionable #124763
  • Apply documented defaults before the first config file exists #125110
  • feat(gateway): auto-apply safe doctor config migrations at startup #132135
  • Restore macOS dashboard auth from gateway service secrets #101375
  • Keep inherited values out of configuration writes #102231
  • Keep the macOS app running after login launch #102465
  • Stop cancelled Gateway configuration reads #104093
  • Reject oversized multibyte JSONC in OC Path #104140
  • Make macOS LaunchAgent plists readable by launchd #104228
  • Respect filesystem case rules for agent directories #105402
  • Preserve nested defaults across configuration merges #105953
  • Retry config snapshots after transient failures #106105
  • Restore environment variables after config-load failures #106181
  • Preserve JSONC formatting during OC Path insertion #106858
  • Pin Fleet logs to verified container generations and repair restore guidance #106918
  • Keep explicit Gateway loopback binds canonical #107731
  • Keep suppressed gateways quiet and web terminals interactive #108871
  • Fix Windows launchers for non-ASCII profile paths #108967
  • Reject ambiguous config paths after bracket segments #109580
  • Warn when an already-running Gateway needs restart repair #110583
  • Ignore blank gateway credentials during configure wizard probes #113096
  • Preserve Control UI question access after upgrades #113153
  • Fix forgetting paired gateways on iOS #114083
  • Preserve exact ownership for included config writes #114251
  • Reject ambiguous config patches and correct auth disconnects #115579
  • Preserve config includes during Doctor cleanup #115723
  • Prevent Doctor from writing unsupported extension-channel config #116025
  • Block conflicting systemd gateway installs #116162
  • Let gateway start recover crash-looped systemd services #116178
  • Prevent wildcard pairing routes from crashing Gateway upgrades #116610
  • Preserve config dry-run errors and reject empty batches #116833
  • fix(bootstrap): treat blank NODE_EXTRA_CA_CERTS as unset for startup TLS env #117317
  • Preserve quotes and backslashes in generated systemd units #117375
  • Preserve custom CA trust across Gateway reinstalls #117944
  • Preserve external macOS remote-Gateway config edits #118046
  • Migrate redundant native Codex service tiers #118738
  • Show remote Gateway authentication failures in macOS status #118841
  • Keep macOS gateway recovery working with unlabeled system plists #119091
  • Apply managed dotenv changes on systemd Gateway restart #119441
  • Make Linux systemd unit cleanup report failures and reload removed legacy units #120027
  • Emit valid wide-area DNS configuration #121392
  • Require validated Node for managed services #122070
  • fix(infra): prevent $-pattern injection in home directory tilde expansion #122991
  • Keep valid CoreDNS zones when updates fail #123928
  • Reject malformed scalar config files instead of loading defaults #124945
  • Distinguish missing environment references from literal placeholders #125455
  • fix(doctor): skip host service management in container environments #125796
  • Show outcomes for native reconnect, Gateway links, and notifications #125909
  • fix(macos): prevent invalid Gateway ports from crashing remote connections #128260
  • fix(systemd): report service commands replaced by drop-ins #128604
  • fix(systemd): honor effective drop-in configuration #129170
  • fix(doctor): preserve managed container services #129527
  • fix(daemon): prevent macOS node startup hangs from inherited compile cache #130097
  • fix(daemon): preserve structured command termination outcomes #130634
  • fix: preserve systemd units when interrupted status cannot authorize cleanup #131080
  • fix(cli): preserve authored config during channel auth #131117
  • fix(channels): preserve authored config during setup #131235
  • fix(config): preserve indexed and whole-list agent edits #131369
  • fix(channels): single-source bundled channel schemas from generated metadata #131564
  • fix(config): ignore discarded SecretRefs when applying batches #131656
  • fix(daemon): node install reports a supported Node runtime as unsupported when the working directory is unreadable #131998
  • Connect bootstrap clients to self-signed WSS gateways #80204
  • Safely resolve conflicting Linux gateway services #91221
  • Preserve secure local dashboard access for specific Gateway binds #98479
  • fix(irc): retire unused mentionPatterns config (#119356) 0612928
  • Preserve complete Unicode characters in config hints #102512
  • Restore environment after invalid config snapshots #103786
  • Render identity-avatar array indices correctly #104935
  • Reject retired no-op configuration keys #106031
  • Warn before config writes strip JSON5 comments #107604
  • Parse APNs relay timeouts as decimal values #107883
  • Ignore blank Synology Chat account tokens #108922
  • Ignore blank Google Chat service-account environment values #108948
  • Bound legacy macOS launchd cleanup #109116
  • Use the effective daemon port flag #109294
  • Ignore blank Synology Chat environment fallbacks #109495
  • Include retry timing in rate-limited Gateway authentication errors #109630
  • Preserve emoji in truncated config validation errors #109664
  • Reject invalid Gateway TCP ports safely #109875
  • Ignore blank APNs relay timeout overrides #110677
  • Reject unusable Tlon URLs during setup #111099
  • Repair the active profile and config location in doctor #111555
  • Keep bundled provider overlays valid after revalidation #112334
  • Reject and safely migrate sandbox browser network none #115250
  • Stop macOS DNS setup from hanging on Homebrew probes #115782
  • Hide duplicate SSH Gateways in the macOS dashboard #115963
  • Accept documentation URLs in config hints #116063
  • Recover the macOS dashboard after Gateway authentication #116080
  • Reject trailing escapes in configuration paths #116738
  • Correct Linux systemd service environment parsing #117484
  • Restore fresh dev gateway startup #118003
  • fix(cli): reject Infinity/NaN in config set/batch/patch values #120156
  • Let macOS gateway repair skip unreadable foreign daemons #120481
  • fix(config): keep core channels keys in the generated config schema #120736
  • Reject blank configuration section filters #121145
  • Avoid restart hints for unchanged configuration #122953
  • Make config.patch failures explain the working next step #124127
  • fix(dns): keep wide-area SOA serial monotonic across skew and rollover #124144
  • Surface legacy configuration copy failures in Doctor #124948
  • Warn when a post-write config reread degrades #125075
  • Point local CLI authentication errors to local gateway credentials #125488
  • Make config unset fail for missing paths #125958
  • fix(cli): tell config get apart a typo from an unset key #127369
  • fix(cli): tell operators a racing config set changed nothing #127554
  • fix(config): diagnose an unwritable config directory instead of leaking EACCES #127703
  • fix(config): match the config directory through symlinks when diagnosing permissions #127734
  • fix(macos): escape all login LaunchAgent plist paths #128378
  • fix(config): finalize runtime overrides when config is missing #128600
  • fix(daemon): detect effective systemd service overrides #128705
  • fix(doctor): migrate deprecated bindings match.peer.kind dm to direct #130553
  • fix(config): omit unauthored agents parent on writes #131413
  • fix(daemon): explain unsafe service publication failures #132279
  • fix(doctor): preserve config when service repair is refused #132375
  • fix(state): stamp unset application versions after canonical repair #133225
  • Restore cross-platform SSH gateway probes #93030
  • Retire unsupported diagnostics OTel gRPC configuration #93087

Documentation

  • Add a Daytona cloud-sandbox hosting guide #116411
  • Replace retired configuration keys in documentation #121330
  • Keep documented configuration examples aligned with the schema #121336
  • Complete the Cloudflare deployment operator guide #122932
  • Correct unsafe and nonworking hosting guides #122971
  • Clarify missing config unset target behavior #126036
  • Clarify Fleet's current scope without MVP framing b573a3b
  • Align configuration docs with retired keys and current defaults #113956
  • Fix the custom Control UI home-directory example #114594
  • Correct timezone configuration guidance #116102
  • Correct retired Gateway reload settings in the docs #116975
  • Add a stable private Gateway URL guide #118340
  • Document Cloudflare Tunnel and Access deployment #126029
  • docs: align Linux host tuning with managed systemd policy [AI-assisted] #128752
  • docs(gateway): clarify independent HTTP endpoint switches #130690
OpenClaw Restarts and Running Work

Before a supported snapshot or targeted restart, Gateway suspend and resume can pause new ordinary work, report blockers, and drain the agent runs, deliveries, scheduled jobs, queues, sessions, and background commands OpenClaw already tracks. Failed configuration reloads keep the prior coherent state, and rapid configuration writes retain pending restart intent instead of dropping it.

After restart, health checks, the agent list, and core controls become usable before optional catalog, plugin, and migration work finishes. That work is deferred rather than removed, so the first explicit catalog request can still take longer.

The wait covers work OpenClaw tracks. New channel or external ingress, existing plugin connections, unregistered background work, and durable receipt of incoming messages remain outside it, and externally supervised installations must consume the handoff and complete their own restart.

Sources and complete change list

Improvements

  • Add cooperative Gateway suspension for host snapshots #103618
  • Speed up same-build Gateway restarts #105099
  • Speed up Gateway cold starts and first agent turns #105801
  • Speed up pristine plugin-heavy Gateway startup #106195
  • Support externally supervised Gateway restarts #109162
  • Guard gateway lifecycle commands against accidental disruption #110323
  • Defer inactive plugin runtimes for faster Gateway and agent startup #119733
  • Let updates proceed with open Gateway terminals #121601
  • Start fresh gateways without legacy migration delay #121639
  • Add usable Gateway suspend and resume commands #122100
  • Add a channel-independent Gateway startup probe #122477
  • feat(gateway): add renewable cooperative suspension draining #130003
  • Reduce Gateway startup work before readiness #105913
  • Make Gateway restart recovery SQLite-owned and replay-safe #110014
  • Start fresh Gateways faster with stateless plugin paths #115578
  • Skip inactive session stores during gateway restart recovery #117498
  • Mark abandoned sessions before model preparation #117544
  • Skip empty per-agent session databases during Gateway startup #117589
  • Reduce cold first-turn latency after Gateway restart #120809
  • Defer non-startup Gateway imports #121780
  • Reduce repeated Gateway logging and delivery work #126147
  • Scope gateway startup model catalog planning to configured models #127117
  • perf(gateway): index targeted connections #128198
  • improve(gateway): overlap macOS system-CA warmup with startup #128422
  • improve(gateway): cut warm session maintenance latency #128513
  • Remove obsolete macOS Gateway startup probing #121439
  • Reduce duplicate restart-recovery scans #125712
  • perf(gateway): reduce session-event delivery filesystem work #132439
  • improve(gateway): reduce idle worker startup memory #133176

Bug fixes

  • Reliably relaunch macOS Gateways after restart #104637
  • Make Gateway hot reload transactional #105289
  • Prevent gateways from getting permanently stuck in draining mode #107339
  • Verify Windows gateway listener ownership before termination #108023
  • Harden network errors, session IDs, and extension loading #110196
  • Prevent macOS reload restarts from stranding the Gateway #110213
  • Prevent macOS Gateway startup freezes during TLS setup #111473
  • Preflight gateway restarts for credential migration #114715
  • Finish failed Gateway HTTP responses without hanging clients #116874
  • Prevent macOS gateway restart from stranding the LaunchAgent #116875
  • Let early gateway probes run before background startup work #117083
  • Keep large-history Gateways responsive after restart #117108
  • Keep large-history Gateways responsive after restart #117118
  • Prevent heartbeat settings from blocking gateway startup #117992
  • Clear stale runtime state on gateway close and restart #118271
  • Prevent stalled live updates from leaving the Gateway offline #119116
  • Stop agent roster requests from blocking Gateway startup #119208
  • Prevent gateway stalls after queue drop-policy changes #119331
  • Keep chat metadata from delaying other Gateway requests #119369
  • Stop post-ready session-catalog work from stalling the Gateway #119377
  • Keep Gateway requests responsive during context-cache warmup #119562
  • Reduce multi-agent gateway stalls after agent turns #120075
  • Keep the Gateway reachable when restart state is invalid #120966
  • Keep Gateway controls responsive during concurrent turns #123608
  • Keep supervised restarts from migrating live Gateway state #123920
  • Show Gateway startup progress and harden lifecycle cleanup #124309
  • Prevent large retired-agent registries from wedging the gateway #124516
  • Keep Gateway readiness responsive under sustained turns #124528
  • Stop the macOS idle node setup CPU loop #124599
  • Drain all active Gateway work before direct stops #126024
  • Avoid Tailscale restart loops after upgrades #126069
  • Preserve managed Tailscale Funnel access and cleanup #126519
  • fix(gateway): plugin metadata lifecycle staleness in auth-bypass cache and config reload #127664
  • perf(gateway): fix event-loop convoys from per-session hot paths under concurrent sessions #129135
  • fix(gateway): keep loaded conversations responsive under heavy load #130071
  • fix: recover active sessions across repeated gateway restarts #131527
  • fix(gateway): preserve active turns across event-loop stalls #131966
  • fix(codex): force bounded settlement when a terminal turn notification stalls #132413
  • fix(gateway): stop restart loops for newer database schemas #132916
  • Release startup migration lease before controlled gateway exit #103157
  • Keep session suspensions safe through Gateway restart #103211
  • Recover unbounded gateway requests from stalled connections #103407
  • Prevent Gateway respawns during managed package updates #103537
  • Detect hung channel runs behind disconnected transports #103793
  • Keep renamed-checkout macOS gateways running #103972
  • Include plugin HTTP work in Gateway suspension readiness #104112
  • Keep reconnect delivery recovery inside suspension admission #104143
  • Wait for background commands before suspension or restart #104172
  • Force-stop stalled managed Mac app processes during restart #104268
  • Coordinate channel recovery during gateway reload and shutdown #104811
  • Make gateway suspension wait for accepted node work #105134
  • Repair managed Gateway port drift and Crestodian cleanup errors #105153
  • Restart unmanaged Gateways on their active port #105241
  • Prevent false restart failures during startup migrations #105544
  • Start the Gateway during banner animation #105774
  • Finish session-end hooks before gateway shutdown #105848
  • Defer context-cache prewarm until after gateway readiness #106117
  • Keep pristine Gateway startup fast and migration-safe #106282
  • Hot-apply worktree cleanup limit changes #106525
  • Clear restart and suspension state between Gateway lifecycles #106691
  • Honor attach-only mode during macOS gateway restart #107402
  • Prevent overlapping Signal daemons during Gateway restart #107409
  • Stop Bonjour self-probe retry loops #107710
  • Skip the macOS post-update window when no Gateway work is needed #108146
  • Bound Gateway WebSocket opening waits #108348
  • Bound and stage Gateway TLS certificate generation #109139
  • Prevent externally supervised Gateway restart timeouts #109273
  • Keep config hot-reload active after recovered watcher errors #109682
  • Keep the Gateway running when a web provider SecretRef fails #109687
  • Continue stale Gateway cleanup after signal errors #109702
  • Avoid false macOS Gateway restart failures #109955
  • Isolate missing media credentials to the affected model #110042
  • Exit cleanly when startup migrations refuse readiness #110207
  • Preserve restart intent across coalesced config writes #110397
  • Audit managed gateway service starts across platforms #110497
  • Reload external config edits after watcher recovery #111049
  • Fall back to cmd.exe for blank Windows ComSpec #111260
  • Hot-reload changes from included config files #111511
  • Keep macOS Gateway startup responsive during trust initialization #111533
  • Repair inherited cross-user D-Bus settings during Linux updates #111534
  • Keep healthy macOS gateways running for PATH-only advisories #112381
  • Prevent Gateway crashes on unreachable pinned addresses #113905
  • Preserve click order for Linux Gateway controls #114291
  • Stop idle Scheduled Tasks reliably on localized Windows #114434
  • Stop completed embedded runs from growing gateway memory #114767
  • Keep Gateway teardown running after cron failures #114848
  • Reconnect Gateway nodes after temporary socket setup failures #115539
  • Prevent startup timeouts with many configured models #116039
  • Reset Gateway event ordering after reconnects #116043
  • Back off repeated macOS Gateway connection failures #116114
  • Prevent stale macOS remote Gateway tunnels from restarting #116172
  • Return valid rate-limit responses for WebSocket upgrades #116557
  • Avoid false Gateway port-busy reports behind Tailscale Serve #116579
  • Keep custom-port Docker containers healthy #116639
  • Include standalone MCP App work in Gateway draining #116727
  • Verify daemon start and installation outcomes #116815
  • Cancel disconnected Gateway requests and retain response error handling #116835
  • Allow slower Gateway readiness after live updates #117032
  • Allow slower macOS listener scans during gateway restart #117036
  • Cancel stale Gateway work during close and restart #117242
  • Keep unavailable Gateway routes out of the Control UI fallback #117436
  • Make agent-approved Gateway restarts safe and reliable #117530
  • Keep channel watchdog failures from crashing the gateway #117652
  • Hot-reload automatic compaction settings #118010
  • Let transient sender and audio-probe failures recover #118245
  • Preserve plugin metadata when no config file exists #119421
  • Keep Gateway RPCs responsive during context warmup #119607
  • Keep device-pair polling out of Gateway startup #119936
  • Bound channel bootstrap memory and preserve workspace lock ownership #120939
  • Keep managed updates bound to their originating checkout #121288
  • Drain ACP agent processes during gateway shutdown #121359
  • Verify the macOS Gateway after launchd bootstrap errors #121747
  • Repair deployment probes and Render first boot #122963
  • Avoid false Gateway restart failures on systemd probe errors #123069
  • Prevent overlapping managed updates across Gateway restarts #123116
  • Keep macOS model changes and node shutdown ordered #123529
  • Finish canceled macOS node-worker requests promptly #124151
  • Allow exact targeted restarts through prepared Gateway suspension #124157
  • fix(gateway): Apple node commands recover after reconnect #124195
  • Keep Gateway readiness truthful during restart #124514
  • Keep Gateway shutdown reliable during in-place updates #124582
  • Restart disabled installed systemd services #124786
  • Prevent false plugin migration failures during Gateway restart #124924
  • Let Gateway controls reach schema-ahead processes #125133
  • Refresh hook target policy after Gateway hot reload #125490
  • Reclaim locks held by Linux zombie processes #125658
  • Complete managed updates after late Gateway exits #125759
  • Enforce Gateway shutdown deadlines during event-loop stalls #125863
  • fix: gateway stop throws when port is busy without identified owner #126085
  • Restore Gateway startup for catalog-backed model overrides #126123
  • Abort failed partial Gateway HTTP responses #126130
  • Stop retrying unsupported Gateway protocol versions #126600
  • fix(sessions): avoid startup stalls with many empty agent stores #126685
  • Keep Gateway liveness probes healthy during config reload failures #126736
  • Prevent provider-auth rewarm from exiting Gateway during restart #126855
  • Clean up Bonjour when Gateway startup fails #127062
  • fix: /restart restarts the gateway over and over instead of once #127179
  • fix(daemon): preserve the Gateway when stopping or restarting a Mac node #127707
  • fix(update): keep managed handoff as successor owner #128212
  • fix(update): avoid rollback while systemd service is still stopping #129007
  • fix: streamed replies rescan the whole accumulated buffer on every delta to test an 8-character silent-reply token #129130
  • fix(ios): retire stale foreground gateway health probes #129194
  • fix: avoid rebuilding unchanged agent runtimes on reload #129257
  • fix(gateway): wait for config hot-apply before acknowledging writes #129321
  • fix(macos): failed service commands incorrectly report success #129615
  • fix(macos): keep the node channel alive and visible when the node-host worker cannot start #129925
  • fix(sessions): fence restart-recovery tombstones independently of archive state #130196
  • fix(portals): event streams stall before the first event #130727
  • fix: channel config updates no longer wait on themselves #131180
  • fix: open terminals block cooperative release updates #131314
  • fix: gateway shutdown cannot cancel deferred context-engine maintenance #131394
  • fix(gateway): keep config writes pending through watcher handoff #131515
  • fix(gateway): preserve config receipts across reload supersession #131545
  • fix: restart continuation never runs for agents without a heartbeat schedule #131888
  • fix: dashboard asset retention delays gateway restarts #131930
  • fix(daemon): preserve recovery after Startup entry removal #132056
  • fix: completed restart recovery no longer blocks sessions #132121
  • fix(gateway): drain supervised processes on restart #132566
  • fix(codex): reap orphaned app-servers before reconnect #132610
  • fix(codex): reaper could kill a recycled-pid process and skipped cleanup until next use #132745
  • fix(gateway): avoid shutdown stalls with paired workers #132877
  • fix(state): stop gateways after incompatible schema upgrades #133081
  • fix: show gateway restart progress instead of tool failure #133119
  • fix(gateway): preserve native runtime selection across reloads #133195
  • Keep the Gateway online when an auth profile has a stale secret reference #77213
  • Allow macOS gateway restart while its LaunchAgent owns the port #89096
  • Prevent duplicate macOS gateway managers #97285
  • fix(windows): verify Startup fallback launch and readable script (#116570) e05dae2
  • fix(state): tolerate disappearing SQLite sidecars (#125451) f5eea31
  • Prevent plugin metadata drift from blocking gateway restarts f7b372a
  • Speed up sanitizing large chat messages #102971
  • Keep the Gateway running when update handoff fails #103278
  • Keep macOS Gateway updates safe through launchd teardown #105022
  • Stop stalled Mattermost handshakes from blocking reconnects #105553
  • Avoid Codex shutdown warnings after live updates #106418
  • Cancel deferred provider-error work when the Gateway stops #108451
  • Bound port-inspection helpers during forced startup #108706
  • Prevent concurrent managed updates from taking the Gateway offline #108925
  • Bound macOS metadata probes #109241
  • Ignore vanished gateway targets during signaling #109590
  • Return failure when a non-gateway owns the gateway port #110310
  • fix(gateway): preserve distinct Unicode boot replies #110641
  • Stop foreground gateways without a service manager #111378
  • Reject malformed Gateway upgrade requests #115038
  • Keep forced gateway startup working after listener exit #115568
  • Keep gateway shutdown moving when a plugin stalls #115619
  • Prevent oversized discovery timeouts from ending Gateway startup early #117204
  • Skip deleted agent stores during Gateway restart recovery #118023
  • Return truthful statuses for non-HTML gateway probes #118048
  • Fix the authenticated Docker Gateway health command #118996
  • Add Content-Length to Gateway HEAD responses #120210
  • Restore restart-preflight compatibility for Gateway clients #121757
  • Report Gateway draining during unfinished startup #123204
  • Suppress false chat-metadata warnings during Gateway restart #123433
  • Fail absent Gateway and Node service start or restart requests #124711
  • Report existing Tailscale route ownership conflicts #126449
  • fix(macos): preserve externally owned Gateways in attach-only mode #128134
  • fix(gateway): clarify skip-deferral reply drain #128178
  • fix(reef): avoid shutdown delays during friend reconciliation #129016
  • fix(gateway): preserve portal retry page on target port collision #129075
  • fix(http): stop waiting on already disconnected requests #129588
  • fix(gateway): stop dispatch after HTTP responses finish #129619
  • fix(macos): show how to recover when the Mac node fails to start #129874
  • fix(macos): show recovery steps when the Gateway service fails #129943
  • fix(gateway): preserve target context in suspension resume hints #129956
  • fix(gateway): return complete errors after HTTP route failures #130383
  • fix(gateway): suppress hello from closing client transports #132448
  • fix: running Gateway can report a checkout commit it never loaded #132854
  • fix(codex): keep shutdown diagnostics best effort #132953
  • Skip terminal one-shot ACP sessions during startup reconciliation #86711
  • Recover Tailscale Serve hostname after startup races #91553
  • Keep source gateways running during rebuilds #99972

Documentation

  • Document gateway restart and crash recovery #103985
  • Document crash-loop safe-mode channel recovery #113091
  • docs(install): use managed gateway restart in Ansible guide #128522
  • Add a macOS launchd restart-loop recovery runbook #89816
Troubleshooting, System Health, and Logs

Doctor now spends less time reciting healthy inventory and more time showing what broke and what to do next. A recoverable interactive startup failure can offer one confirmed doctor --fix attempt, while an unrecoverable configuration stays unchanged with exact instructions to inspect, edit, or move it aside. Bare openclaw doctor --json is a read-only advisory check; use openclaw doctor --lint --all when you need the advisory checks omitted from the default run.

Logs now fill their bounded tail window across short reads, preserve Unicode at file boundaries, distinguish line and byte truncation from rollover, and report unavailable storage instead of an empty success. Status keeps its base report when optional health details fail, so missing information remains unknown rather than being shown as healthy.

In the admin Control UI, Ask OpenClaw can turn consequential health state into a diagnostic question and keep the system-care conversation docked as you move around, while the System overlay shows a short history of scheduler pressure, CPU, memory, event-loop delay, and optional disk activity. These controls require admin or operator access and do not appear during onboarding or to read-scoped clients.

Sources and complete change list

Improvements

  • Show exact build identity in every About screen #103595
  • Add click-to-diagnose health nudges to OpenClaw system care #110708
  • Add system change history to Ask OpenClaw #111286
  • Add a state-aware caretaker welcome with quick actions #111615
  • Add a dedicated OpenClaw settings chat to Android #112788
  • Add a dockable Ask OpenClaw companion in the Control UI #115123
  • Reuse plugin metadata throughout Doctor runs #119482
  • Add actionable QQBot setup errors #119780
  • Show telemetry exporter health in Doctor and status #119816
  • Start Doctor migration checks without loading every plugin runtime #120678
  • Keep Doctor security conditions as single findings #124666
  • Make Ask OpenClaw persistent and globally accessible #125107
  • Move Ask OpenClaw to the sidebar footer #125486
  • Add live Gateway busyness diagnostics #125591
  • feat(ui): add live CPU/memory/delay sparkline graphs to the system busyness overlay #127650
  • feat(cli): add openclaw triage for sanitized agent debugging handoffs #128756
  • Add at-a-glance gateway resource meters #102714
  • Correlate ClickClack agent turns with ClawRouter audits #103476
  • Make gateway and channel logs clearer and less repetitive #104174
  • Add redacted Gateway startup outcome summaries #104183
  • Make regular doctor output shorter and problem-focused #106968
  • Consolidate operator diagnostics and migration safeguards #109211
  • Offer guided repair after invalid configuration blocks startup #110533
  • Give Ask OpenClaw the regular chat experience #110934
  • Continue upstream traces through Gateway WebSocket requests #113189
  • Configure OpenTelemetry metric name prefixes #116687
  • Standardize error messages across core, plugins, and the Control UI #117818
  • Track persistent Gateway event-loop degradation #118193
  • Expose safe live-updater recovery diagnostics #119096
  • Render status as native rich tables on supported channels #120167
  • Speed up bundled plugin doctor-contract loading #120698
  • Show blocked inbound lanes in health checks #123234
  • Include Gateway build identity in status JSON #123917
  • Show migration progress during interactive doctor runs #124692
  • Report managed update finalization timings #126107
  • fix(ui): make login recovery commands copyable #128047
  • feat(ui): show disk space in diagnostics overlay #128552
  • improve: speed up large history upgrades and Doctor checks #133068
  • improve: speed up Doctor checks on large session histories #133100
  • improve: speed up transcript migration and Doctor scans #133127
  • Include redacted worker stderr in turn failures b69e047
  • Add acknowledgement state to worker stall errors f264f45
  • Make default Doctor lint quieter for automation #100361
  • Stop reporting superseded config reloads as errors #106165
  • Share overlapping macOS Tailscale status refreshes #116321
  • Add CLI startup phases to diagnostics timeline #117702
  • Make startup migration recovery guidance install-neutral #119406
  • Log scheduled update campaign lifecycle events #120669
  • Report state-v9 registry migration decisions #124862
  • improve(gateway): reduce health snapshot session work #127744
  • perf(logging): reuse log level thresholds #128061
  • fix(agents): record what agents re-read after auto-compaction #128148
  • perf(status): batch text report output #128168
  • improve: resolve config once per status scan #129494
  • perf(status): skip hidden session detail projection #133014
  • Add actionable recovery steps when node exec approval is unavailable #91280

Bug fixes

  • Preserve unrecoverable config during doctor repairs #109362
  • Stop macOS app probes from hanging #115938
  • Record channel account lifecycle states #117300
  • Prevent duplicate and leaked diagnostics lifecycle spans #119791
  • Keep OpenTelemetry exporting after in-process restarts #120131
  • Keep published official plugins loading after core upgrades #124086
  • Preserve unknown Gateway service state #125734
  • fix(sessions): migrate long histories without exhausting heap #131276
  • Prevent Gateway out-of-memory crash loops under sustained load #96250
  • Warn when open chats expose gateway or cron controls #100965
  • Route shared OTLP endpoints by telemetry signal #101655
  • Bound mcporter registry reads during security audits #101772
  • Preserve characters in truncated HTTP response snippets #103136
  • Keep status diagnostics read-only #103252
  • Keep truncated support diagnostics Unicode-safe #103580
  • Restore clawlog defaults and clear option errors #104059
  • Preserve complete log tails across short reads #105066
  • Preserve Unicode across session-tail follow reads #108151
  • Report each state-schema migration correctly in Doctor #108947
  • Bound Node runtime capability probes #109127
  • Bound daemon Node binary lookup #109239
  • Scan SKILL.md instructions in deep security audits #109363
  • Retain diagnostic context across short transcript reads #109401
  • Preserve checkout commit identity after short Git metadata reads #109419
  • Bound SKILL.md reads during deep security audits #110589
  • Repair stale model references after provider deletion #110648
  • Preserve doctor config repairs when session maintenance is locked #111280
  • Bound Mattermost probe DNS and proxy preflight #111314
  • Check every configured agent in doctor #111758
  • Doctor checks workspace suggestions for every agent #111840
  • Propagate actual exported OpenTelemetry span context #112283
  • Separate Gateway logs for named profiles #112777
  • Report usable agent config paths in security diagnostics #113603
  • Detect CLI-only Tailscale on macOS #114179
  • Make system-agent recovery guidance usable from browser and app surfaces #114633
  • Persist safe doctor migrations before runtime timeouts #114703
  • Move file logging off the Gateway request path #114769
  • Scale heap-pressure thresholds with V8 limits #115153
  • Exclude provider-private thinking from telemetry #115261
  • Reduce health diagnostic noise and refresh churn #115602
  • Batch macOS listener checks during multi-port status collection #115813
  • Remove subprocess polling from macOS tunnel readiness #115846
  • Prevent macOS remote Gateway discovery hangs #115852
  • Keep late agent work in one OpenTelemetry trace tree #116246
  • fix(channels): attribute zero-payload turn warnings and stop false silent-drop alarms #116486
  • Preserve live probes during concurrent Gateway health refreshes #116681
  • Make status and provider diagnostics report real failures #116776
  • Report real service-removal failures on every platform #116819
  • Keep log collection read-only #116869
  • Show dead-ingress and busy channel health in status tools #117236
  • Align release validation with current runtime contracts #117494
  • Separate Debug diagnostics from Manual RPC results #117546
  • Keep Gateway status scoped to the active environment #119015
  • Keep raw diagnostic write failures from ending agent runs #119400
  • Preserve OpenTelemetry diagnostics during shutdown #119705
  • Honor per-signal OTLP protocol settings #119708
  • Preserve the real OTEL startup error during rollback #119747
  • Make OTEL_SDK_DISABLED fully disable OpenClaw telemetry #119961
  • Explain unverified Windows SecretRef path security #120211
  • Give Gateway connection failures consistent recovery guidance #120505
  • Speed up doctor checks and restore Discord repairs #120882
  • Restore selected external plugin state migrations in Doctor #120908
  • Preserve external plugin session ownership during upgrades #121082
  • Preserve legacy plugin runtime-doctor imports #121220
  • fix(diagnostics): stalled lanes go unreported while messages keep arriving #121380
  • Parse localized Windows process names for port hints #122126
  • Make diagnostics ZIP replacement atomic and private #122130
  • Stop Doctor after failed migration writes #123045
  • Report line-limit truncation in log tails #123358
  • Let doctor exit after reporting malformed config #123430
  • fix(gateway): preserve worker tunnel exit diagnostics #123611
  • Explain stale Gateway files after upgrades #123842
  • Stop duplicate root records in file logs #123936
  • Report normally stopped services as stopped #123961
  • Surface telemetry-exporter probe failures in Doctor #123971
  • Explain stale Gateway installs during WebSocket connection failures #123998
  • Keep doctor lint from migrating shared state #124110
  • Keep Control UI log tails tied to the correct file #124369
  • Return typed errors for unserializable Gateway responses #124375
  • Report only Doctor fixes that reached disk #124462
  • Scale Gateway RSS diagnostics to runtime memory limits #124914
  • Diagnose Gateways that cannot host nodes #125132
  • Show live Gateway degradation in status commands #125888
  • Keep status reports available when enrichment fails #126072
  • Show actionable telemetry failures in status output #126092
  • Report unavailable log storage instead of empty logs #126481
  • Give operators a recovery path for unparseable configs #126757
  • Record Discord poll and sticker outbound activity #126791
  • Clarify empty channel status and gateway connection failures #126984
  • Report degraded Gateway secrets in structured Doctor lint #126998
  • fix(cli): reject conflicting read-only doctor postures #128142
  • fix(telemetry): report only publicly known plugin identities #128603
  • fix(ui): distinguish pending and failed empty states #128746
  • fix: keep verbose health available when channel probes stall #128915
  • fix(telemetry): suppress reporting from automated environments #129155
  • fix(doctor): run health checks for the installed Codex plugin #129276
  • fix(agents): make terminal CLI failures diagnosable #129481
  • fix(status): preserve service inspection errors in overview #130365
  • fix(cli): honor selected port when tailing logs #130513
  • fix(doctor): surface unreadable legacy plugin state instead of silently skipping migration #130956
  • fix(doctor): repair agent workspace and heartbeat values on the canonical roster shape #130959
  • fix(canvas): retire the legacy document root only after migration completes #131038
  • fix: gateway status normalizes runtime inspection errors #131495
  • fix(logging): report dropped file log records #132672
  • fix(cli): reduce gateway status memory on constrained hosts #132784
  • fix(doctor): recover generated model metadata after upgrades #132835
  • fix(status): group shared session stores by canonical owner #133038
  • fix(cli): keep Doctor JSON reports complete when piped #133259
  • fix(status): self-heal status lazy-loader failures and contain render errors #94806
  • Keep truncated diagnostics and metadata valid around emoji 0ac8933
  • Honor custom config paths in Swabble status checks 251f54b
  • Export OpenTelemetry from one-shot local agent runs #100845
  • Bound session-maintenance warning deduplication memory #101643
  • Keep emoji intact in restart diagnostics #101934
  • Keep truncated Doctor errors UTF-16 safe #102066
  • Keep truncated Discord gateway close diagnostics readable #102246
  • Keep channel log previews UTF-16 safe #102407
  • Keep proxy-capture previews on valid UTF-8 boundaries #102409
  • Keep emoji intact in truncated Gateway config paths #102513
  • Keep Discord deploy error truncation emoji-safe #102525
  • Keep truncated log messages valid Unicode #102560
  • Keep gateway WebSocket log previews valid Unicode #102561
  • Keep cleanup timeout warnings readable #102565
  • Keep diagnostic logs valid around emoji #102570
  • Keep QQBot debug previews valid around emoji #102572
  • Keep Prometheus diagnostic error logs Unicode-safe #102591
  • Keep gateway command metadata truncation Unicode-safe #102816
  • Reduce MCP loopback schema warning noise #103171
  • Stop clean Doctor runs from suggesting unnecessary repairs #103233
  • Report the correct JSONL session line after blank rows #103645
  • Keep exported diagnostics JSON Unicode-safe #103646
  • Keep restart log tails Unicode-safe #103757
  • Keep truncated timeout URLs valid Unicode #104301
  • Reduce benign macOS startup socket warnings #104610
  • Keep worker bootstrap error text UTF-16 safe #104619
  • Preserve valid characters in worker SSH tunnel diagnostics #104621
  • Demote benign Gateway startup close races #104625
  • Avoid false Gateway warnings for clean Mac app startup closes #104655
  • Quiet false warnings during successful macOS updates #104813
  • Keep channel token hints valid around emoji #104850
  • Session migration reports preserve complete Unicode characters #104851
  • Preserve Unicode in compact gateway WebSocket log IDs #105001
  • Scope managed Gateway restart logs to the active checkout #105030
  • Preserve UTF-8 SSH identity output at Windows byte limits #105274
  • Return Logs to the newest entry when Auto-follow is re-enabled #105809
  • Warn when restart-state persistence fails #106385
  • Log failures while reading HTTP error details #106393
  • Bound port-inspection process enrichment concurrency #107121
  • Keep cloud worker failure details UTF-16 safe #107718
  • Clear resolved TaskFlow and OAuth doctor warnings #108123
  • Keep capped CLI output diagnostics UTF-8 safe #108355
  • Log non-blocking Gateway restart hook failures #108847
  • Keep QQBot log exports complete after short file reads #108955
  • Bound long-lived config warning caches #109000
  • Prevent macOS doctor from hanging on launchctl probes #109115
  • Stop Doctor from hanging on stalled GitHub issue creation #109253
  • Preserve Unicode in Doctor migration issue reports #109592
  • Bound stalled gateway process probes #109731
  • Report occupied browser-control ports at startup #109994
  • Preserve UTF-8 in APNs response diagnostics #110483
  • Ignore blank OTLP protocol environment overrides #110674
  • Stop stalled Linux journal lookups from hanging logs #111215
  • Keep xdg-open failure messages UTF-16 safe #111323
  • Show stopped channels as disconnected #112518
  • Doctor preserves active Gateway session locks on Linux #112855
  • Clarify unavailable system Node versions in Doctor #114325
  • Preserve Windows PATH delimiters in node status #114505
  • Prevent active steering from leaving false queued-work diagnostics #114780
  • Restore workspace suggestions in openclaw doctor #115512
  • Show gateway probe duration in health output #115520
  • Show stopped channels in status and doctor #116781
  • Replace false Gateway-overload notices for stalled replies #116959
  • Correct Control UI asset checks in packaged installs #117003
  • Preserve unresolved Doctor findings after incomplete repairs #117448
  • Reject conflicting Doctor lint selectors #117495
  • Honor explicit status command timeouts #117519
  • Preserve runnable Doctor checks when selectors partially overlap #117543
  • Preserve channel filters in offline status output #117570
  • Bound gateway status service-manager reads #117636
  • Surface actionable session-history migration conflicts #117656
  • Show complete persisted messages in Gateway Logs #117666
  • Surface sanitized WhatsApp media-download failures in normal logs #117717
  • Stop exact-limit searches from reporting truncation #117747
  • Make channels status show all channels #118124
  • Unify Gateway method registration and redact terminal failures #118232
  • Mark truncated malformed-row lists in session exports #119230
  • Stop labeling stale diagnostic phases as recent #119625
  • Show invalid configuration details on separate lines #119871
  • Report Prometheus metrics length on HEAD requests #120212
  • Enforce strict diagnostics query integers #120446
  • Report indeterminate Windows port availability accurately #120845
  • Report incomplete legacy cache scans in Doctor #122585
  • Make doctor --json run the read-only deployment preflight #122662
  • Report recovered compaction runs as completed #122974
  • Report Signal RPC probe failures accurately #123001
  • fix(logs): report truncated channel tails #123699
  • Return Doctor machine failures as JSON on stdout #123752
  • fix(doctor): follow a macOS cloud symlink when the state dir leaf is absent #124299
  • Stop false agent-roster security warnings #124398
  • Report aborted unconfirmed steers truthfully in gateway audits #124409
  • Guide device approval to the current pairing request #124637
  • Warn when session-history disk cleanup fails #124681
  • Show config paths in Doctor migration notices #124719
  • Give actionable managed Gateway recovery #124783
  • Explain best-effort config fallbacks #125010
  • Warn when group rooms share the main session #125054
  • Report failed remote Gateway health checks #125203
  • Report refused Doctor config repairs as incomplete #125282
  • Make Doctor fail error gates on critical disk exhaustion #125644
  • Bound macOS Gateway status probes #126394
  • Show Gateway restart and update probe failures #126645
  • Make macOS clawlog JSON output parseable and failure-safe #126651
  • Preserve structured details from wrapped error causes #126654
  • Stop warning on successful Discord description truncation #126824
  • Reject invalid gateway status timeouts #126977
  • Prevent stale success from Gateway health checks #127174
  • fix(status): surface an invalid config instead of reporting a healthy system #127402
  • fix(channels): stop false no-payload warnings for queued replies #127667
  • fix(logging): preserve incomplete tail records #127810
  • fix(ui): show channel probe progress while refreshing #127903
  • fix(doctor): show disabled automations during authority reauthorization #127998
  • fix(health): secondary account failures incorrectly appear healthy #129088
  • fix(macos): expose channel account failures in settings #129400
  • fix(status): scope doctor hints to active profile and container #129418
  • fix(gateway): scope crash loop channel recovery hints #129697
  • fix(ios): prioritize active gateway errors over connection names #129709
  • fix(cli): stop doctor JSON mode from silently filtering health checks #129919
  • fix(config): structure noninteractive preflight warnings #129954
  • fix(daemon): recovery hints target the wrong profile or container #130216
  • fix: preserve Gateway error reasons in text logs #130645
  • refactor(models): simplify picker and thinking projections #130694
  • fix(status): show healthy channels as OK in deep health #130794
  • fix(cli): honor gateway --port on the status leaf #130847
  • fix(otel): preserve trailing slashes in collector query values #130934
  • Classify Node process warnings correctly in Gateway logs #131333
  • fix(doctor): restore warnings for ignored agent settings #131443
  • fix(doctor): preserve large media migration timestamps #132099
  • fix(cli): accurately preview suppressed telemetry requests #132222
  • fix(doctor): report schema upgrades separately from media repairs #132314
  • fix(imessage): avoid unnecessary startup work in Doctor #132435
  • fix(logs): only report rotation when the log file actually shrank #74252
  • Skip missing lsof warnings during Gateway startup #76364
  • Avoid false gateway warnings for shell-wrapped LaunchAgents #81778
  • Fix Doctor sandbox repair for symlinked OpenClaw launchers #90942
  • Avoid duplicate channel scans in status commands #95263

Documentation

  • Document the status probe timeout option #102363
  • Document managed Gateway heap sizing and repair #111027
Command-Line Output and Shell Completion

Commands used by scripts now have a more predictable machine interface. The named JSON and JSONL commands keep terminal-reset bytes out of stdout and return a consistent structured error when an invocation fails, so automation no longer has to special-case them.

Shell completion installation and refresh preserve unrelated profile content and permissions while publishing profiles and caches atomically across Bash, Zsh, Fish, and PowerShell. Remote Gateway turns and common read-only commands also skip startup work they do not need, while local probes and human output keep fuller validation; mistyped commands now point to the command tree that rejected them, nearby commands, and the correct help.

The predictable machine-output contract covers the named command paths. Human diagnostics can still appear on stderr, successful degraded results remain command-specific, and raw lifecycle-error redaction is not yet universal.

Sources and complete change list

Improvements

  • Speed up Gateway-backed CLI agent turns #117705
  • Add consistent JSON output across CLI reporting commands #117928
  • Speed up common read-only CLI commands #117932
  • Reduce startup overhead for Gateway-backed CLI commands #115294
  • Unify CLI config-guard behavior across dispatch paths #117880
  • Speed up cold read-only CLI commands #117957
  • Speed up cold CLI status and plugin reads #118460
  • Speed up fitting ASCII table rendering #127221
  • improve(cli): speed up config help startup #128113
  • perf(startup): short-circuit dist-internal ESM resolution with explicit module format #128541
  • perf(startup): measure default resolve path and gate debug-capture imports #131181
  • improve(cli): cut ordinary gateway status startup memory #133114
  • Improve fuzzy matching in TUI selectors #107576
  • Reduce memory for routine status commands #116668
  • Keep CLI help from loading inactive provider runtimes #121997
  • Speed up openclaw audit startup #124595
  • improve(tui): speed up unchanged transcript redraws #127767

Bug fixes

  • Keep JSON console logs structured across CLI routes #113654
  • Make CLI commands, completion, and JSON output reliable #116033
  • Preserve CLI option values and machine-readable output #116389
  • Preserve shell profiles and complete option values #116906
  • Restore fast local TUI and embedded-agent startup #117396
  • Preserve shell profiles when completion installation fails #117987
  • Reuse the prepared runtime across embedded local TUI turns #120051
  • Keep terminal chat history visible after silent activity #121337
  • Standardize CLI JSON failure output #124849
  • Clean terminal exits for logs and hooks CLI errors #105863
  • Show clear CLI errors for missing input files #105874
  • Move macOS CLI PATH discovery off the main actor #106089
  • Preserve literal --update values in CLI subcommands #106144
  • Make Git Bash core utilities available on Windows #108136
  • Preserve emoji in TUI local shell output #108268
  • Prevent Fish completions from truncating a file named -l #109324
  • Stop repeated TUI searches from retaining stale regexes #109451
  • Write CLI JSON results to stdout #109808
  • Let one-shot macOS CLI commands exit promptly #110341
  • Let the TUI exit cleanly after quitting #110595
  • Guarantee TUI exit after Gateway teardown hangs #111015
  • Stop command-group help from hanging after output #111433
  • Make CLI failures and signals return truthful status #112210
  • Restore macOS Keychain CA trust for one-shot commands #113112
  • Keep update JSON valid during post-core resume #113298
  • Recognize Bash completion installed in login profiles #113790
  • Reject empty update timeout arguments #114700
  • Install cached shell completions without loading plugins #114761
  • Restore PowerShell completion after CLI options #114950
  • Speed up machine-readable Gateway health probes #115244
  • Keep CLI help, update previews, and plugin pinning correct #115464
  • Accept inherited CLI flags after nested commands #116587
  • Release the terminal after TUI backend shutdown failures #116609
  • fix(cli): restore accurate operator diagnostics and safe input handling #116652
  • Show completion-repair failures and stop failed verification progress #116825
  • Honor shell-owned completion profile locations #117002
  • Keep Unicode terminal-table columns aligned #117062
  • Cancel buffered TUI input during shutdown #117331
  • Preserve machine-readable CLI output on fatal exits #117487
  • Keep JSON channel status startup cold #117751
  • Preserve consecutive Backspaces in the terminal UI #117989
  • Preserve shell completion caches when refreshes fail #118715
  • Show why background processes failed in the TUI #120724
  • Return structured errors from system CLI machine-output commands #123614
  • Keep CLI table identifiers intact when wider columns can wrap #123934
  • Redact caught errors in CLI JSON output #124075
  • Remove internal class names from Gateway and CLI failures #124329
  • Remove JavaScript class names from proven Gateway RPC errors #124563
  • Improve CLI errors and status tables #124581
  • Report unknown nested commands even with help #124707
  • Keep routine CLI errors concise #124887
  • Show actionable guidance for mistyped CLI commands #124892
  • Render missing Gateway credentials consistently in the CLI #125007
  • Exit the local TUI cleanly during authentication #126476
  • fix(tui): stop local shell descendants on exit #127652
  • fix(cli): show human errors when required values consume --json #128557
  • fix(install): --json preserves valid NDJSON for dynamic values #128682
  • fix(tui): keep sentence punctuation out of terminal hyperlink targets #128727
  • fix(cli): explain empty capability listings #128852
  • fix(cli): return JSON errors when machine-readable commands fail to parse #128861
  • fix(cli): render Gateway validation JSON failures #129043
  • fix(cli): nested command help stalls while loading routed commands #129112
  • fix(cli): preserve structured core send failures #129728
  • fix(channels): keep configured accounts in JSON inventory #130738
  • fix(cli): show real options in lazy command help #130951
  • fix(install): preserve Unicode in macOS JSON output #131244
  • fix(cli): preserve source resolution outside checkout #131479
  • fix: include stored session colors in CLI JSON #132982
  • fix(cli): keep setup and agent help startup lazy #133272
  • fix: align session tables with Unicode keys and long model names #133283
  • Refresh cached CLI help for every build 63f497a
  • Strip C1 OSC metadata from terminal output #103672
  • Preserve terminal links and styling across wrapped table cells #103717
  • Report blank task JSON filters as absent #103981
  • Keep emoji intact when the TUI wraps long text #104024
  • Report accurate UTF-8 byte counts from openclaw path set #104496
  • Clarify malformed gateway call parameters #105217
  • Show a clear error for malformed docs search responses #108364
  • Emit absolute config paths from machine-facing CLI output #109361
  • Submit exact TUI command arguments with one Enter #109809
  • Keep config schema JSON parseable at debug level #110496
  • Preserve literal dollar patterns in displayed home paths #111398
  • Allow docs search with unrelated invalid config #111803
  • Restore public TLS trust for macOS one-shot commands #112868
  • Restore short-option completion in Bash #113811
  • Restore Ctrl+D forward deletion in the TUI #113872
  • Clarify fresh-install exec approval defaults #114417
  • Keep config file path queries fast and read-only #114660
  • Keep read-only config commands from writing state #114847
  • Scope Fish completions to the active command #115180
  • Avoid no-op SQLite repair during routine CLI startup #115193
  • Restore Fish completions after global CLI options #115222
  • Keep JSON CLI stdout valid through process exit #115315
  • Keep JSON command stdout free of exit-time diagnostics #115327
  • Keep shell completion consistent across Bash, Fish, and PowerShell #115332
  • Report the commit embedded in the running CLI build #115544
  • Keep Gateway credential failures parseable in JSON #116597
  • Keep config file output raw under JSON logging #116968
  • Return Canvas control results in JSON mode #117297
  • fix(tui): cancel history retries when the Gateway stops #117318
  • Preserve Gateway startup policy with parent options #117675
  • Reject oversized Gateway TUI history limits early #117773
  • Report failed TUI shell commands once and in order #118452
  • List supported TUI commands from one shared registry #118515
  • Preserve Gateway request errors in health JSON #118645
  • Make Gateway RPC calls honor a custom local port #119046
  • Keep pairing QR codes within standard terminal widths #120827
  • Preserve Windows CLI arguments named node.exe #121064
  • Clean version output for the legacy package entrypoint #121690
  • Avoid creating profiles for rejected CLI commands #122970
  • Bound one-shot CLI exits when stream drains stall #123134
  • Emit structured JSON errors from Directory CLI commands #123390
  • Return structured Gmail setup errors #123646
  • Suggest a valid migration preview command #124149
  • Show relevant help for unknown subcommands #124544
  • Show accurate errors for mistyped nested CLI commands #124661
  • Show each TUI reconnect failure cause #124700
  • Explain empty directory lookup results #124753
  • Fail clearly when agent creation cannot prompt #124940
  • Default Windows shell completion to PowerShell #125211
  • Stop repeating cause text in error messages #125687
  • Block TUI sends until session events are subscribed #125928
  • Return machine-readable JSON when docs search fails #126331
  • Accept daemon JSON output before lifecycle subcommands #126447
  • Honor custom Gateway ports for usage and stability queries #126832
  • Return JSON for QR option validation failures #126884
  • Return canonical JSON for sandbox CLI failures #126915
  • Return parseable JSON for missing task and flow lookups #127080
  • fix(cli): return JSON for invalid status timeouts #127721
  • fix(cli): return JSON for task validation failures #127750
  • fix(tui): honor system-agent history limit #127993
  • fix(cli): return JSON for channel capability failures #128155
  • fix(cli): render agent binding JSON failures #128484
  • fix(cli): render agents add JSON failures #128517
  • fix(cli): render agent identity JSON failures #128590
  • fix(cli): write telemetry JSON to stdout #129003
  • fix(tui): preserve slash command alias completions #129039
  • fix(cli): failing one-shot commands incorrectly exit successfully #129066
  • fix(cli): render Gateway health JSON failures #129106
  • fix(plugins): report update failures on stderr #129189
  • fix(cli): honor reaction listing limits #129308
  • fix: report unattended completion install outcomes #129320
  • fix(cli): honor container selection in root help #130403
  • fix(tui): show agent-scoped session example #130519
  • fix(tasks): skip completed deleted-agent stores #130554
  • fix(update): keep repair JSON stdout parseable #131411
  • fix(cli): report failed local agent turns as unsuccessful #132155
  • fix(cli): preserve Gateway run IDs in agent JSON failures #133006
  • fix(cli): honor profile selection before cached help #133148
  • fix: keep CLI table rows aligned with CRLF values #133249

Documentation

  • Show absolute config paths in CLI examples #114595
  • docs: correct directory JSON failure envelope #124989
  • Document the Zsh completion profile selected by ZDOTDIR #125247
Backup, restore, reset, and uninstall

Reset and uninstall now refuse to remove data until the Gateway service is torn down and OpenClaw can establish that no other process owns the state. If teardown or ownership checks fail, the state stays put, and a state-only uninstall leaves configured workspaces alone.

New full backups preserve configured agent state roots and safe relative links, avoid mistaking active archive work for a stall, and restore default or custom layouts through the same guarded flow. Managed dev/ checkouts and local source edits still need a separate backup, while older archives containing absolute generated plugin-skills/ links remain rejected.

Known-vulnerable Node and SQLite combinations now stop before state opens, with guidance for whether the embedded Node runtime or shared system SQLite library needs upgrading.

Sources and complete change list

Improvements

  • Add scheduled, versioned Git backups with freshness tracking #122485
  • Add verify-first staging restore for whole backups #122750
  • perf(sqlite): skip schema write lock on current state #126825
  • Remove redundant healthy-database integrity scans #115005
  • perf(state): avoid duplicate ownership reads in cached transactions #128161

Bug fixes

  • fix(sqlite): reject runtimes vulnerable to WAL corruption #106065
  • Validate exact backups before config recovery #117100
  • Migrate and validate config backups before recovery #120475
  • Prevent Windows startup stalls during shared-state checks #122518
  • Make newly created default-profile backups restorable #123504
  • Reject unrestorable symbolic links before publishing backups #123672
  • Refuse duplicate Gateway startup before touching live state #124653
  • fix(backup): preserve full backups with managed runtime symlinks #124821
  • Refuse reset or uninstall while live state is owned #125253
  • fix(backup): preserve configured agent state roots #129773
  • Keep gateway model probes stateless #103651
  • Restore Gateway startup on WSL2 when private-state chmod reports EROFS #108258
  • Prevent Gateway outage after remote catalog upgrade #113875
  • Preserve user data when Gateway removal fails #113887
  • Keep uninstalled npm plugins from returning #113902
  • Keep Gateway cleanup hints scoped to detected extra services #115559
  • Prevent false backup stalls and sparse verification failures #122213
  • Prevent false backup timeouts during large file reads #122235
  • Exclude transient state temp files from backups #122250
  • Let Windows security gates survive cold PowerShell starts #123633
  • Remove isolated npm plugin projects on uninstall #123973
  • Restrict npm plugin cleanup to owned roots #124608
  • Make backup create output errors actionable #124894
  • Repair older placement-move tables during startup #125583
  • Prevent partial or raced Fleet backup archives from being lost #126942
  • fix(backup): declare external managed-skill symlink targets as backup assets #132973
  • Surface config backup cleanup failures #105307
  • Correct SQLite safety guidance for Node builds using a shared library #107771
  • Tailor system Node SQLite warnings to the linked SQLite build #107990
  • Clarify safe SQLite maintenance lines #108382
  • Bound macOS process start-time probes #109064
  • Report agent-delete cleanup failures instead of silent success #110560
  • Keep legacy workspace attestation rows readable #113686
  • Clean managed plugin peers after npm override errors #116675
  • Report the real backup tar attempt count #119197
  • Stop failed backups from claiming completion #124135
  • Explain invalid backup and config file inputs #124510
  • fix(plugins): normalize managed npm overrides before peer planning #124532
  • Report offline agent deletion failures in JSON #125715
  • fix(backup): reject malformed git log limits #127875
  • fix(backup): restore verified archive-relative hardlinks #131199
  • Make path-based proxy-capture cleanup atomic #98852

Documentation

  • Document verified backup and rollback workflows #108159
  • Add a complete operator backups guide #122196
  • Document the manual full-archive restore flow #86971
  • Document backup volatile-path exclusions #99007
Was this useful?