---
title: "v2026.9.8"
summary: "Update recovery, Windows startup and reply fixes, plus GPT-6.1 Sol support."
description: "OpenClaw v2026.9.8 release notes covering updates, messaging, Codex resource use, local models and GPT-6.1 Sol."
keywords:
  - OpenClaw
  - v2026.9.8
  - release notes
  - GPT-6.1 Sol
---

# v2026.9.8

AI agents and tools can read these release notes as [plain Markdown](https://raw.githubusercontent.com/openclaw/openclaw/main/CHANGELOG/2026.9.8.md).

OpenClaw 2026.9.8 adds GPT-6.1 Sol as a model choice through the OpenAI provider for accounts with access. It keeps delegated results tied to the conversation that requested them, reduces unnecessary memory use in larger Codex setups, and addresses failed updates and Windows startup problems.

**Release scale:** 43 pull requests, 12 direct commits, and 8 contributors.

## Web UI

The Control UI fixes view loading in tabs left open through updates and accidental session assignment from the keyboard.

<AccordionGroup>

<Accordion title="Browser tabs after updates">

Tabs left open in the bundled Control UI can continue loading views after a restart or update while their version's files are retained. OpenClaw now waits for those files to become available and leaves more room to keep them. Retention is limited, so older tabs may still need a reload; the [Control UI guidance](/web/control-ui/development) explains those limits.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Keep retained Control UI files available to older tabs [#163478](https://github.com/openclaw/openclaw/pull/163478). Missing-file requests wait for cache verification before reporting a miss. Newly retained builds omit Brotli and gzip copies and serve retained files uncompressed, reducing copying and leaving more of the existing budget for previous builds. Regression coverage includes requests during inventory, uncompressed responses, cancellation of pending lookups, coexistence with older cache formats, and budget eviction. Budget tests are consolidated into the existing publication suite. This backports the fixes from [#163090](https://github.com/openclaw/openclaw/pull/163090) and [#163099](https://github.com/openclaw/openclaw/pull/163099). Contributions from [vincentkoc](https://github.com/vincentkoc).

**Limits and compatibility**

The cache retains at most three generations and 96 MiB. An unusually large build can still evict the previous generation, with a Gateway warning when that happens. Custom `gateway.controlUi.root` installations do not use this cache. The updated development documentation records these limits and how retained files are served.

</details>

</Accordion>

<Accordion title="Session assignment menu">

Pressing Enter on “Assign to…” after hovering over it now opens the assignment menu without accidentally assigning the session to the person highlighted in its submenu.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Prevent unintended assignment when opening the session menu [#163467](https://github.com/openclaw/openclaw/pull/163467). Both shipped Web Awesome dropdown bundles now respect the focused menu item, with updated dependency-patch hashes and a browser regression covering hover followed by Enter. This backports [#161393](https://github.com/openclaw/openclaw/pull/161393). Coauthored by [RomneyDa](https://github.com/RomneyDa) and [vincentkoc](https://github.com/vincentkoc).

  The same change removes the obsolete empty-subagent-completion QA scenario and its catalog test, following the policy in [#162567](https://github.com/openclaw/openclaw/pull/162567). It does not include the separate parent-wakeup repair discussed in [#163195](https://github.com/openclaw/openclaw/pull/163195).

</details>

</Accordion>

<Accordion title="Silent-reply help">

Twenty existing Control UI translations now explain that silent-reply settings apply to groups, while direct chats and internal sessions require a reply. This updates the settings help without changing reply behavior or adding languages.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Documentation**

- Clarify translated silent-reply settings help [#163409](https://github.com/openclaw/openclaw/pull/163409). One message is updated in each of 20 existing locales, with translation rows and catalog metadata synchronized across 41 generated files. The change reuses the translations from [#162942](https://github.com/openclaw/openclaw/pull/162942). Contributions from [vincentkoc](https://github.com/vincentkoc).

</details>

</Accordion>

</AccordionGroup>

## Updates and Maintenance

Update repair preserves your plugin choices and recovers from temporary file locks. Other fixes address startup failures and work interrupted by configuration reloads.

<AccordionGroup>

<Accordion title="Update recovery">

Update repair preserves your plugin allowlist and enabled entries when a plugin is incompatible. A fresh Doctor run can finish pending migration confirmations even when no packages need changing, and completed migrations stop producing obsolete warnings.

If you are recovering from Windows 2026.9.4, automatic updating still refuses the unsafe migration while old drivers are running. Back up first and follow the independent-shell recovery procedure in the [update guidance](/cli/update), using the original service account and installation settings. Recovery requires stopping the old processes, upgrading manually, running the new Doctor, then restarting and verifying the installation.

<details class="release-source-toggle" id="update-recovery-sources">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Preserve update settings and repair startup, replies and session maintenance [#162959](https://github.com/openclaw/openclaw/pull/162959). Backport by [RomneyDa](https://github.com/RomneyDa), with included work by [VACInc](https://github.com/VACInc), [obviyus](https://github.com/obviyus) and [ericcaiwx-star](https://github.com/ericcaiwx-star).
  - Update repair retains incompatible plugin allowlists and enabled entries. Fresh Doctor can complete deferred confirmations without package changes, and completion receipts suppress stale warnings without rewriting update history.
  - Windows startup shortens compile-cache paths and disables paths that remain too long, with a warning. Child processes also avoid unsafe inherited cache paths.
  - Direct Gateway starts and container onboarding enforce exclusive ownership of shared state. Managed starts retain their existing ownership, including through shutdown and failed cleanup. Brief SQLite contention gets bounded retries while the maintenance lease remains valid.
  - Doctor archives only verified empty retired version-1 Telegram binding files. Nonempty or uncertain files remain for operator review, and an archive failure leaves the original bytes available with a recoverable warning. Queued Telegram previews carrying writer authority recheck that authority before sending, preventing a replaced writer from issuing a stale edit on that path.
  - Anthropic background Bash, agent and workflow results stay attached to their turn until consumed. Failures still terminate the turn.
  - Codex catalog generations reuse a captured configuration, and Doctor shares compatible provider registrations while keeping different plugin selections and explicit workspace owners separate.
  - Session repair walks deep ownership chains without recursive stack overflow and preserves transcript ownership and history.
  - Sandbox, workspace and Claude CLI skill copies from read-only installations receive writable copied directories and bounded retries when removing legacy copies. Original source files, file permissions and symlink targets remain unchanged.

**Security and trust**

Local TLS health probes preserve the managed proxy policy and verify the configured certificate fingerprint on each connection.

**Documentation**

The included documentation covers plugin recovery, package-lifecycle checks, Windows compile-cache limits, Gateway ownership, proxy-aware health probes, Telegram migration and preview handling, and scalable Doctor checks. Contextual original repairs are [#160344](https://github.com/openclaw/openclaw/pull/160344), [#160193](https://github.com/openclaw/openclaw/pull/160193), [#160718](https://github.com/openclaw/openclaw/pull/160718), [#160702](https://github.com/openclaw/openclaw/pull/160702), [#161946](https://github.com/openclaw/openclaw/pull/161946), [#161832](https://github.com/openclaw/openclaw/pull/161832), [#162290](https://github.com/openclaw/openclaw/pull/162290), [#162321](https://github.com/openclaw/openclaw/pull/162321), [#162912](https://github.com/openclaw/openclaw/pull/162912), [#161260](https://github.com/openclaw/openclaw/pull/161260), [#162841](https://github.com/openclaw/openclaw/pull/162841), [#160137](https://github.com/openclaw/openclaw/pull/160137), [#162304](https://github.com/openclaw/openclaw/pull/162304) and [#162394](https://github.com/openclaw/openclaw/pull/162394).

**Limits and compatibility**

Windows 2026.9.4 containment refuses a shared-state migration that the running old database reader cannot safely use. Manual recovery must preserve the backup and original service account, npm prefix, profile and overrides, stop the old drivers in order, upgrade from an independent shell, run fresh Doctor, then restart and verify. If package scripts were skipped, the old updater's cleanup error can obscure the refusal. Telegram preview protection applies to requests carrying writer authority. Synthetic fleet and deep-history checks do not establish a universal memory or speed improvement.

</details>

</Accordion>

<Accordion title="Windows and macOS updates">

Windows updates retry temporary file locks during package replacement and leave the installed package in place if those retries run out. On macOS, npm updates recognize installation paths reached through aliases such as `/var`, including the brief interval when npm has removed the old package directory.

These fixes apply once the updated updater is in use. An older updater already running cannot acquire them mid-update, including the documented 2026.9.6 first-hop limitation. Check the [update guidance](/cli/update) if an upgrade from an older installation fails.

<details class="release-source-toggle" id="platform-update-sources">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Recover package replacement interruptions and deliver delegated results once [#163074](https://github.com/openclaw/openclaw/pull/163074). Backport by [RomneyDa](https://github.com/RomneyDa), with included work by [fuller-stack-dev](https://github.com/fuller-stack-dev) and [obviyus](https://github.com/obviyus).
  - Windows backup renames retry transient `EPERM`, `EBUSY` and `EACCES` failures up to 16 attempts, with 57.75 seconds of bounded waits. Identity and authority checks remain active. Exhausted retries identify the affected paths and preserve the installed package.
  - Activation accepts equivalent canonical POSIX installation paths, including macOS aliases. SQLite verification workers retain access to their runtime after package removal. Update rehearsal preserves row identities and avoids redundant full database copies when supported; unfiltered Git directory copies can use native copying.
  - Internal sessions, including subagents and Control UI sessions, return a result or continue working instead of completing with `NO_REPLY`. `sessions_send` returns a settled reply inline or delivers it once later, using the original requester identity and checking the current requester incarnation. Isolated Cron callers do not create detached reply waiters.
  - Codex catalog-only processes start on an authorized catalog request instead of fleet activation. Shell snapshots retain at most 128 recent in-memory keys. Session publication avoids repeated work, and shutdown releases idle database work while an accepted memory-publication sequence retains its lease until close.
  - Supporting regression coverage protects the state-reader dependency graph. That guard is not an additional runtime memory repair. Test fixtures also cover the update and session behavior above.
- Recognize aliased macOS installations while their package directory is absent [#163481](https://github.com/openclaw/openclaw/pull/163481), with work by [vincentkoc](https://github.com/vincentkoc). The resolver uses the existing parent directory to recover the installation's canonical path during npm replacement. An existing dangling symlink remains distinct from an absent directory, and inspection errors retain the existing fallback. This backports the corresponding main-branch repair [#163479](https://github.com/openclaw/openclaw/pull/163479) without adding a setting or changing the activation API.

**Security and trust**

Log redaction avoids repeated work and fixes missed long obfuscated assignments on Bun. This is a repair to that redaction path, not a guarantee that arbitrary logs contain no secrets.

**Documentation**

Updated guidance covers [row-preserving update rehearsal](/install/updating), [Codex catalog loading](/plugins/codex-harness), [shell snapshots](/tools/exec), [required internal replies](/concepts/messages) and [Doctor's configuration migration](/gateway/doctor/config-migrations).

Contextual upstream repairs for the backport bundle include [#161003](https://github.com/openclaw/openclaw/pull/161003), [#162076](https://github.com/openclaw/openclaw/pull/162076), [#162231](https://github.com/openclaw/openclaw/pull/162231), [#162352](https://github.com/openclaw/openclaw/pull/162352), [#162403](https://github.com/openclaw/openclaw/pull/162403), [#162387](https://github.com/openclaw/openclaw/pull/162387), [#162616](https://github.com/openclaw/openclaw/pull/162616), [#162810](https://github.com/openclaw/openclaw/pull/162810), [#162967](https://github.com/openclaw/openclaw/pull/162967), [#162227](https://github.com/openclaw/openclaw/pull/162227), [#162567](https://github.com/openclaw/openclaw/pull/162567) and [#163129](https://github.com/openclaw/openclaw/pull/163129). [#163086](https://github.com/openclaw/openclaw/pull/163086) is the main-branch counterpart of the activation-path change.

**Limits and compatibility**

Automatic peer back-and-forth and target announcement turns are removed. Custom workflows must use explicit follow-up or message-tool calls for further conversation or channel delivery. `REPLY_SKIP` and `ANNOUNCE_SKIP` no longer suppress returned text through the retired loop. Doctor removes `silentReply.internal` and `silentReply.direct` through normal backup and validation while preserving `silentReply.group` and unrelated settings. External group silence remains configurable.

The first authorized Codex catalog request may still receive the existing progressive pending response. The update repairs do not retroactively change an older running updater or guarantee every Windows, macOS or npm upgrade will succeed.

</details>

</Accordion>

<Accordion title="Gateway startup and shutdown">

Starting OpenClaw directly or in a container now prevents competing Gateways from using the same stored state. Windows startup avoids hangs caused by overly long cache paths, and shutdown can finish while memory synchronization is idle without interrupting a write already in progress.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

Startup ownership, Windows compile-cache handling and bounded SQLite retries are accounted for in [Update recovery](#update-recovery-sources). Idle database shutdown and accepted memory-publication handling are accounted for in [Windows and macOS updates](#platform-update-sources). These changes concern startup and maintenance; they do not add memory recall behavior.

</details>

</Accordion>

<Accordion title="Work during configuration reloads">

Work that OpenClaw has accepted can finish through [connection-policy reloads](/gateway/configuration/hot-reload) when the user's access remains valid. Clients reconnect before sending new requests, while revoked access still cancels affected work. Changes to the authentication mode or listener setup continue to require a restart.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Preserve accepted work across connection-policy reloads [#163174](https://github.com/openclaw/openclaw/pull/163174), backported by [RomneyDa](https://github.com/RomneyDa) from the contextual original repair [#160909](https://github.com/openclaw/openclaw/pull/160909). Proxy-header, OIDC-mapping, device-auto-approval and trusted-proxy-address changes no longer cancel accepted runs, queued inputs or a committed session's requested initial turn solely because the originating connection retires.

**Security and trust**

Revoking identity scope, a proxy allowlist entry, an admitted browser origin, an authentication method or a credential still cancels the affected work permanently. Rotating a local proxy fallback password cancels password-authenticated work without cancelling unrelated proxy-authenticated work. The backport also carries effective startup authentication-mode overrides into proxy-policy and fallback-password decisions.

**Documentation**

The [hot-reload guidance](/gateway/configuration/hot-reload) and [trusted-proxy authentication guidance](/gateway/trusted-proxy-auth) explain reconnects, access revocation and shared-secret rotation. Authentication-mode and listener-topology changes remain restart operations.

</details>

</Accordion>

</AccordionGroup>

## Messaging

Messaging fixes address missing delegated results and channels that appeared connected but stopped replying after a reload or wake.

<AccordionGroup>

<Accordion title="Delegated replies">

When one agent asks another for help, the result now returns to the original requester once, either immediately or when the work finishes. [Internal sessions](/concepts/messages) must return a result or keep working instead of ending silently.

If your custom workflows rely on silent internal completion or automatic back-and-forth between agents, update them to handle returned results and use explicit follow-up or message calls for further conversation. [Doctor migrates the retired silence settings](/gateway/doctor/config-migrations); silence in external group chats remains configurable.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

The delegated-reply changes are included in the [Windows and macOS update source accounting](#platform-update-sources). `sessions_send` returns the settled reply inline or delivers it once later, retaining the original requester identity and checking the current session incarnation. Isolated Cron callers do not create detached reply waiters.

**Limits and compatibility**

Internal sessions, including subagents and Control UI sessions, can no longer complete with `NO_REPLY`. Automatic peer ping-pong and target announcement turns are removed. `REPLY_SKIP` and `ANNOUNCE_SKIP` no longer suppress returned text from that retired loop; further conversation and channel delivery require explicit follow-up or message-tool calls. Doctor removes `silentReply.internal` and `silentReply.direct` through normal backup and validation, preserving `silentReply.group` and unrelated settings.

</details>

</Accordion>

<Accordion title="Replies after reloads and wake">

Channels restarted during a reload or after the computer wakes can continue receiving messages and sending replies when recovery finishes. This fixes a failure reported with Matrix where a channel could appear connected while its reply work failed.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Keep channel listeners active after the reload or recovery operation that started them has finished. The shared channel manager now separates listener startup from that temporary work scope while retaining plugin lifecycle and generation boundaries. Explicitly stopping a channel still cancels its listener, and no new setting or migration is required. [#163504](https://github.com/openclaw/openclaw/pull/163504), backport of [#163268](https://github.com/openclaw/openclaw/pull/163268). Thanks to upstream author [scotthuang](https://github.com/scotthuang) and contributor [vincentkoc](https://github.com/vincentkoc).

**Limits and compatibility**

The regression exercises replies after the host-wake maintenance scope closes and verifies explicit cancellation. Matrix supplied the reported failures; the shared repair addresses that listener-lifetime fault rather than every possible wake-related problem.

</details>

</Accordion>

<Accordion title="Telegram cleanup and previews">

Doctor can archive verified empty files left by retired Telegram bindings, while leaving nonempty or uncertain files for review. Queued previews that track the active writer now check it again before sending, preventing delayed edits from a writer that has since been replaced.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

These Telegram changes are included in the [update recovery source accounting](#update-recovery-sources). Doctor recognizes verified empty version-1 binding files and reports archive failures as recoverable warnings while preserving the original bytes. Preview requests carrying writer authority recheck it after queueing.

**Limits and compatibility**

Uncertain or nonempty binding files still require operator review. The preview guard applies to requests carrying writer authority.

</details>

</Accordion>

</AccordionGroup>

## Skills

Skills copied from a read-only installation can be kept up to date.

<AccordionGroup>

<Accordion title="Skills from read-only installations">

Refreshing skill copies in sandboxed workspaces or Claude CLI sessions could fail because the copies inherited read-only directory permissions. OpenClaw now makes those copied directories writable so refreshes can proceed, while preserving the original installation.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

The repair applies to POSIX skill copies and includes bounded retries when removing older copies. File permissions and symlink targets remain unchanged. See the [update recovery change list and contributor credits](#update-recovery-sources) for the source of this repair.

</details>

</Accordion>

</AccordionGroup>

## Models and Providers

GPT-6.1 Sol joins the available model choices, alongside fixes for local-model setup and work running through Codex and Anthropic.

<AccordionGroup>

<Accordion title="GPT-6.1 Sol">

You can select [GPT-6.1 Sol](/providers/openai/models) through the existing OpenAI provider with API-key access or a ChatGPT/Codex subscription whose account offers the model. It supports text, images and tool use, with reasoning required and set to medium by default. Your current model stays selected until you change it.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Improvements**

- Add GPT-6.1 Sol selection, API-key and account-discovered subscription routing, text and image inputs, Responses tool calls, reasoning controls and usage estimates. Select it with `openclaw models set openai/gpt-6.1-sol`. The accompanying model documentation covers access, runtime differences, limits and pricing. [#161400](https://github.com/openclaw/openclaw/pull/161400)
- Bring the same model support to the release branch, including mandatory reasoning when discovery supplies account-specific capabilities and request handling that omits unsupported sampling parameters. Backport by [RomneyDa](https://github.com/RomneyDa). [#163132](https://github.com/openclaw/openclaw/pull/163132)

**Limits and compatibility**

The model's declared context window is 1,050,000 tokens with up to 128,000 output tokens. OpenClaw retains a 272,000-token active input budget, while native Codex follows the limits advertised by the account. Subscription discovery does not grant access, and the Astra setup default is unchanged.

Reasoning cannot be turned off. The `minimal` setting maps to `low`, and standard efforts run from `low` through `max`. OpenClaw's existing `ultra` orchestration is separate from the effort choices advertised to native Codex.

The implemented cost estimates use rates per million tokens of $2 for input, $0.10 for cache reads, $2.50 for cache writes and $10 for output. Above 272,000 input tokens, input and cache rates double and output costs $15 per million tokens for the whole request. These are the rates recorded in this release's metadata.

</details>

</Accordion>

<Accordion title="Local models on Windows">

Managed llama.cpp setup can now supply missing Microsoft runtime files when the local server fails its first startup check, helping local chat and embeddings start on clean Windows installations. It downloads the files beside the server without requiring a separate system-wide runtime installation. If startup still fails, rerun setup or configure a compatible server manually.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Recover missing Visual C++ runtime files during managed setup for Windows ARM64 and x64 CPU servers and the x64 CUDA server. After a failed startup probe, setup downloads a pinned Microsoft bundle, verifies its size and SHA-256, extracts selected regular DLL files beside the server and retries. The redistributable installer is not executed. By [RomneyDa](https://github.com/RomneyDa). [#163093](https://github.com/openclaw/openclaw/pull/163093)
- Bring the same conditional runtime recovery to the release branch, preserving both the original launch error and the fallback error if recovery fails. Backport by [RomneyDa](https://github.com/RomneyDa). [#163128](https://github.com/openclaw/openclaw/pull/163128)

**Limits and compatibility**

Recovery adds an approximately 12–19 MB download only after the initial startup probe fails. A server that starts successfully needs no extra download. Wrong-version output and CUDA device validation failures retain their existing error handling, and this fallback cannot repair every startup failure. macOS and Linux setup paths are unchanged.

</details>

</Accordion>

<Accordion title="Codex resource use">

OpenClaw avoids starting a separate session-catalog process for every idle Codex agent. Those processes now start when their catalogs are requested, while compatible agents reuse captured settings to reduce duplicate memory use in larger collections of [native Codex sessions](/plugins/codex-harness).

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Improvements**

Catalog requests start processes on authorized demand, and the first request may show the existing pending response while results arrive. The complete source entry and credits appear under [Windows and macOS updates](#platform-update-sources).

Catalog generations reuse configuration captures, and Doctor shares compatible provider registrations while keeping distinct plugin selections and explicit workspace owners separate. The complete source entry and credits appear under [Update recovery](#update-recovery-sources).

</details>

</Accordion>

<Accordion title="Anthropic background results">

Anthropic sessions now wait for background command, agent and workflow results to be picked up before finishing the turn, fixing cases that could hang or end too early.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

Keep pending background Bash, agent and workflow results associated with their Anthropic turn until consumption. Background failures still terminate the turn. The complete source entry and credits appear under [Update recovery](#update-recovery-sources).

</details>

</Accordion>

</AccordionGroup>

## Browser and Computer Use

This release corrects how native Computer Use checks access to desktop apps.

<AccordionGroup>

<Accordion title="Native app readiness">

If you use [Codex Computer Use](/plugins/codex-computer-use) with an API key, its native app readiness check no longer gets blocked by an unrelated browser sign-in requirement. The check now tests desktop app access directly.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

The native probe uses `cua.listApps()` for explicit status and install checks, strict-readiness startup, and periodic health checks when enabled. See the [Windows sessions source accounting](#windows-session-sources) for the shared fix, backport provenance and contributor credits.

**Limits and compatibility**

MCP tool errors still fail readiness. Browser use retains its authentication requirements, and the legacy `list_apps` probe remains supported.

</details>

</Accordion>

</AccordionGroup>

## Security and Privacy

This release repairs local connection checks and a case where sensitive log values could escape redaction.

<AccordionGroup>

<Accordion title="Local TLS health checks">

Local HTTPS health checks work with managed proxy settings and verify the configured certificate fingerprint on every connection, so checking whether OpenClaw is running retains that protection.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Security and trust**

The proxy-aware local health-check repair and per-connection certificate verification are included in the [update recovery sources and credits](#update-recovery-sources).

</details>

</Accordion>

<Accordion title="Log redaction">

When running on Bun, OpenClaw now hides sensitive values in long, obfuscated log assignments that its redaction could previously miss.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Security and trust**

The Bun redaction repair replaces a pattern-matching lookbehind that could miss these assignments and avoids repeated work. Its provenance and credits are included in the [Windows and macOS update sources](#platform-update-sources).

</details>

</Accordion>

</AccordionGroup>

## Other Bug Fixes

These fixes address opening stored conversations on Windows and repairing complex session histories.

<AccordionGroup>

<Accordion title="Windows sessions">

Windows users can open stored conversations and prepare scheduled agent sessions again after a shared data-transfer error could block both operations. No new configuration or database migration is required.

<details class="release-source-toggle" id="windows-session-sources">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Restore Windows session access and native Computer Use readiness in [#162931](https://github.com/openclaw/openclaw/pull/162931), authored by [RomneyDa](https://github.com/RomneyDa).
  - Pass plain storage-environment values to the session-history worker and restore Windows case-insensitive lookup inside it. This prevents the `DataCloneError` during session admission, history discovery and scheduled-agent preparation without reading unrelated environment getters. The Windows repair backports [#160075](https://github.com/openclaw/openclaw/pull/160075), whose commit references fixes for [#157067](https://github.com/openclaw/openclaw/issues/157067) and [#159339](https://github.com/openclaw/openclaw/issues/159339).
  - Check native Codex Computer Use readiness with `cua.listApps()` instead of entering browser inventory. API-key users can pass the native-app check without unrelated browser authentication. This covers explicit status/install checks, strict-readiness startup and enabled periodic health checks; MCP tool errors still fail readiness. The repair backports [#162467](https://github.com/openclaw/openclaw/pull/162467).
  - Normalize padded process start dates into consistent single-line workspace-recovery diagnostics while retaining raw process identities for signal guards.
  - Round Windows CI shard timing totals to tenths to avoid floating-point drift, and align package, plugin, channel-catalog, macOS app and changelog metadata with v2026.9.8, including declared minimum host/API versions where present.

**Documentation**

The [Codex Computer Use documentation](/plugins/codex-computer-use) explains the native-app-only readiness probe, retained legacy `list_apps` behavior and handling of MCP errors.

**Limits and compatibility**

Browser control retains its authentication requirements. The version-metadata updates do not add plugin capabilities, and the Windows session repair preserves the existing database lifecycle.

</details>

</Accordion>

<Accordion title="Session history repair">

Long chains of linked sessions no longer cause session-history repair to crash from a stack overflow. The repair preserves existing conversation history and keeps transcripts attached to their owners.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

Session-owner repair follows the chain iteratively instead of using recursive calls. The source and contributor accounting are included in [Update recovery](#update-recovery-sources).

</details>

</Accordion>

</AccordionGroup>

## Maintainer and Internal Changes

This release includes 42 maintainer-only changes to release qualification, package publication, tests, and repository records.

<AccordionGroup>

<Accordion title="Release validation policy">

Release qualification records version-specific coverage exceptions and eligible failed checks as visible advisories. The [dependency policy](/gateway/security/dependency-locking) also makes non-malware findings advisory, including findings in shipped dependencies. These exceptions change what can qualify for release; they do not turn failed checks into passes or repair vulnerabilities.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Limits and compatibility**

- Recognize the Telegram and Matrix QA waiver for exactly version 2026.9.7. The policy adds the named waiver and a matching stable-profile regression case, without changing either channel's behavior. Direct commit [9015311](https://github.com/openclaw/openclaw/commit/9015311b3cca62a2bbbcd35f5860d060f0d846a5).
- Exclude the waived progress-refresh, response-output-limit, and subagent-restart live-test files before checking for passing assertions, only for candidate 2026.9.7. Unknown versions retain ordinary selection. This original filter is inactive for 2026.9.8; that version's extension appears below. Direct commit [b6dae4a](https://github.com/openclaw/openclaw/commit/b6dae4acd049964010ae1b6b8732059652d92ac8).
- Allow completed `checks-windows-node-*` shard failures or timeouts in the release validation's `normalCi` child to become advisories when exactly one completed, successful CI gate establishes coverage. Packaging, Windows installation and upgrade checks, other selected checks, cancellations, and missing or unsuccessful gates remain blocking; ordinary CI remains strict. Advisory evidence is rechecked through publication, without adding operator waiver controls. The supporting process-census test helper now uses its owning operation's deadline and still rejects late replies. The advisory rule identifies eligible jobs, not whether their failures are intermittent. [#161256](https://github.com/openclaw/openclaw/pull/161256).
- Record non-malware dependency findings of every severity and dependency graph as advisories, remove the per-release risk-acceptance table, and retain blocking for findings already classified as malware. Reports retain findings and warning summaries. A separate CI audit wrapper turns every nonzero audit result into a warning for `workflow_dispatch` requests whose IDs begin with `full-release-validation-` or `release-native-android-`; ordinary and scheduled audit contexts retain failures. This can also suppress incomplete audits, and the prefix is caller-supplied. Blocking classified malware does not guarantee detection of every malware finding. Updated guidance covers deferred dependency fixes, unrelated main-CI failures, and bounded flake handling; individual flake acceptance is implemented separately below. [#161463](https://github.com/openclaw/openclaw/pull/161463).
- Add individual tracked-flake classification for eligible failed or timed-out `normalCi` jobs. Records bind the exact job, attempt, parent, release commit, actor, reason, and tracking reference; continuation can then reseal an advisory-only parent without rerunning that child. Summaries, manifests, and release verification retain the failure. Protected package, installation, update, artifact, and evidence checks remain blocking, and an old record cannot cover a new rerun. The workflow has no dedicated current-release-lead check or second approver; the two-rerun guidance is operator policy, not enforced by the record writer. Earlier parents need the supported tooling update, and limitations around pre-publication advisory size checks and older release bodies remain. [#161515](https://github.com/openclaw/openclaw/pull/161515).
- Extend the bounded exception set to 2026.9.8 for Telegram and Matrix coverage, the three omitted live-test files, and the existing reviewed plugin security inventory on `release/2026.9.8`. Later or unknown contexts retain their normal treatment. This changes qualification policy without repairing the omitted checks or accepted plugin security findings. [#162981](https://github.com/openclaw/openclaw/pull/162981), by [RomneyDa](https://github.com/RomneyDa).

</details>

</Accordion>

<Accordion title="Upgrade validation">

Stable release qualification again includes the published-version self-upgrade checks, with fewer simultaneous runs and more time for the combined job. Repairs to the [upgrade test setup](/ci/release-validation/install-smoke-and-docker-e2e) also address Windows cleanup, outdated fixtures, and unreadable registry helpers.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Wait for confirmed Windows process-tree termination and updater closure before a release test falls back to installation. Unverified cleanup remains a distinct failure. Package-directory removal retries only `EPERM` and `EBUSY`, with bounded delays; it does not retry npm. Windows update-step budgets use 1.5 times the measured baseline installation, bounded to 600–1200 seconds, and the wrapper allows two steps plus 120 seconds. Only Windows packaged-upgrade jobs receive the expanded 180-minute workflow deadline. Direct commit [bbbde77](https://github.com/openclaw/openclaw/commit/bbbde7780b2ee7ba06ed54672800e7b326763f79).
- Define the simulated child process ID through `Object.defineProperty` instead of assigning to Node's readonly `pid` property. The Windows cleanup, closure, and fallback assertions remain; this is a test-fixture correction. Direct commit [c939110](https://github.com/openclaw/openclaw/commit/c9391109ae16fb2ac855b6d8aefcbc8198bc36d2).
- Accept reworded service advice in the already-current second-update test while still checking the advisory kind, a nonblank explanation, and unchanged step, command, directory, duration, and exit result. The test continues to require no package mutation or repair. The Doctor service-home change belongs to contextual [#160056](https://github.com/openclaw/openclaw/pull/160056); this adjustment changes only its validation. [#161079](https://github.com/openclaw/openclaw/pull/161079).
- Remove retired `webhookHost` and `webhookPort` fields from the Feishu upgrade-survivor recipe, retaining the verification token, encryption key, webhook path, and account settings. Listener binding stays with its existing owner. [#163184](https://github.com/openclaw/openclaw/pull/163184), by [RomneyDa](https://github.com/RomneyDa).
- Copy the temporary npm registry server and its bounded-response helper into the Docker validation image with mode `0644`, so its unprivileged user can read files from a restrictive checkout. This extends the adjacent permission repair in contextual [#145919](https://github.com/openclaw/openclaw/pull/145919). [#163188](https://github.com/openclaw/openclaw/pull/163188), by [RomneyDa](https://github.com/RomneyDa).

**Limits and compatibility**

- Temporarily remove the combined self-upgrade job from stable validation after contention between upgrade-survivor and six initial-update lanes. Beta, minimum, and full profiles retained the job with its then-current 130-minute limit. The final stable restoration appears in the next entry. The related older-updater rollback concern in [issue #161257](https://github.com/openclaw/openclaw/issues/161257) was not repaired by this scheduling change. [#161291](https://github.com/openclaw/openclaw/pull/161291).
- Restore stable self-upgrade coverage and increase the combined job budget from 130 to 210 minutes. First-hop checks now consume two scheduler slots under the existing five-slot limit, allowing at most two together or one alongside the three-slot survivor check. Individual lane budgets and upgrade commands stay unchanged, with matching planning tests and documentation. This is the backport of contextual [#161774](https://github.com/openclaw/openclaw/pull/161774). [#163215](https://github.com/openclaw/openclaw/pull/163215), backported by [RomneyDa](https://github.com/RomneyDa).

</details>

</Accordion>

<Accordion title="Validation progress and recovery">

Release operators can follow child-check progress, request a bounded retry, and reuse successful checks when the release and tooling revisions match. Preparation also reports missing SDK acknowledgements earlier. The [continuation workflow](/reference/full-release-validation/continuation) still requires a final continuation step after child retries, and an observation timeout leaves evidence unresolved.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Improvements**

- Add `pnpm frv watch` with saved transition state, one-shot and interval controls, and NDJSON output, plus `frv rerun` with child selection and a default two-attempt budget counted from the planned attempt. Named non-root installer failures can rerun the payload producer and dependents; passed children and standalone artifact producers are refused. Runner diagnostics accompany the retry. Callers must retire `prioritize --run`, which now fails; historical `prioritize --restore` remains, and `continue --failed` still performs final resealing. Known limits include early watcher termination on partial job lists, accepting a retry before later duplicates appear, and missing audit records when verification fails after sending a retry. Related [issue #161317](https://github.com/openclaw/openclaw/issues/161317) supplies installer-attempt context. [#161516](https://github.com/openclaw/openclaw/pull/161516).
- Show GitHub observation phases, continuation transitions, five-minute heartbeats, and confirmed attempt URLs. The configurable observation budget defaults to 180 seconds, with each read capped at 60 seconds and the remaining budget. Failed or unread observations carry warnings and replay commands; known concurrent publishers remain failures. Exact-tag lookup uses authenticated, filtered inventory for draft detection after a 404. Existing-evidence preparation checks SDK acknowledgement immediately after authentication and supplies a quoted rerun command when needed. Temporary cleanup removes its own file tree before targeted Git worktree removal. Operator guidance also covers clean candidate checkouts and package-store lock diagnosis. The observation budget is not a whole-preparation deadline, and a warning is not permission to publish. [#161633](https://github.com/openclaw/openclaw/pull/161633).

**Bug fixes**

- Reuse successful child checks from failed, cancelled, or active validation parents only when both release and tooling revisions match. Empty and omitted inputs compare equally; nonempty defaults and candidate descriptor bytes still must match. Discovery remains bounded to 100 runs, 40 receipt probes, and five full candidate validations within the deadline, with logs explaining reuse, rejection, or fresh dispatch. Sealing and final verification enforce the same tooling identity. Cross-tooling reuse is not implemented. [#161520](https://github.com/openclaw/openclaw/pull/161520).
- Ignore a queued duplicate only in a superseded attempt when it has no runner, an explicitly empty steps array, and a completed same-name sibling. Effective-attempt duplicates and executed or unmatched copies retain strict checks. Queued copies with nonempty copied steps remain outside this exception, and the unchanged receipt-sealing path may still reject predecessor jobs. [#161404](https://github.com/openclaw/openclaw/pull/161404).

</details>

</Accordion>

<Accordion title="Package publication recovery">

Publication checks for stale publishers before starting new work and shows progress while beta tags synchronize. Plugin uploads gain bounded backoff and commands for recovering recorded staged attempts. Recovery still needs the original evidence, available artifacts, and an authorized operator; hidden staged packages can remain indistinguishable from absent versions.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Improvements**

- Add server-aware exponential backoff for packed plugin publication, normally starting at 60 seconds, capped at 300 seconds per sleep and 900 seconds of cumulative sleep. Packed identity is checked before every attempt, including timeout retries; source-tree publication refuses automatic replay. `pnpm release:clawhub-recovery` validates recorded package identities, statuses, and unique attempts, skips published packages, and prints quoted recovery commands without executing them. The reusable publisher pin is updated; the npm-distributed `clawhub@0.23.3` remains unchanged and lacks the recovery command, so the documented pinned-source route is required. Older transports may omit retry headers, and server delays above the cap cannot be honored. [#161713](https://github.com/openclaw/openclaw/pull/161713).

**Bug fixes**

- Check stale publishing jobs before any fresh dispatch. Occupied plugin slots block with reviewer rejection or cancellation guidance; core npm can warn and proceed under its distinct existing slot and live-parent safeguards. The publication parent allows 180 minutes, and its configurable beta-sync wait defaults to 50 minutes with status updates and five-minute heartbeats. A still-running owned sync explicitly fails at the deadline before beta verification; other sync failures retain their existing handling. [#161632](https://github.com/openclaw/openclaw/pull/161632).
- Include selected `@openclaw/ai`, `@openclaw/gateway-client`, and `@openclaw/gateway-protocol` packages in beta-floor verification. Shared selection with bundle preparation validates package identity and version, aggregates stale-tag diagnostics, and blocks the later postpublish stage on core failures. Reused versions and superseded selectors remain supported without requiring the selected tag to equal the release version. This verifies tags; it does not synchronize them or change publication selection. [#161968](https://github.com/openclaw/openclaw/pull/161968).
- Share exact package/version publication-state validation between plugin planning and prepared-artifact resolution. Recognized pending or failed versions stay out of writer jobs, published prepared packages can be adopted, and dry runs retain the full roster. Failed attempts receive manual recovery guidance requiring a human publisher token; the recovery CLI also handles symlinked invocation. Unknown or malformed states fail validation, but a hidden first publication can return 404 from both probes and still be treated as absent. [#161985](https://github.com/openclaw/openclaw/pull/161985).

</details>

</Accordion>

<Accordion title="Test fixtures and live checks">

Tests now wait for the events they need, keep shared resources reserved through cleanup, and distinguish deliberately disabled live suites from missing assertions. Provider expectations and mock responses also match existing behavior more closely. MiniMax remains in full validation while its intermittent stable-profile checks are excluded.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Limits and compatibility**

- Keep the intermittent MiniMax and MiniMax Portal gateway suite in the full profile while removing it from stable selection. This changes test coverage, not model behavior or user settings. The prompt clarification below leaves that profile selection unchanged. Direct commit [1925798](https://github.com/openclaw/openclaw/commit/1925798db6c9006001d23421af52b6b0e0d7edcd).

**Bug fixes**

- Register five opt-in live suites with the shard guard so intentionally disabled files do not fail for lacking passing assertions. The mappings cover the Claude compaction watchdog, subagent continuation, late replies, yield/resume, and peer messaging under their respective compaction, end-to-end, or stress flags. Enabled suites still require passing assertions. Direct commit [533fcd5](https://github.com/openclaw/openclaw/commit/533fcd59a2591a4d3453e642d6948fb5b69c044b).
- Register six more optional suites covering Claude CLI compaction, Codex approval requester, asynchronous questions and restricted MCP scenarios, Ollama, and Twitch. Their existing environment flags control intentional skips, while enabled suites retain the assertion requirement. This adds no provider or channel capability. Direct commit [8498629](https://github.com/openclaw/openclaw/commit/8498629e767ed097cc678508933ba1c320e306f7).
- Update three xAI search and code-execution test expectations to the existing Grok 4.7 default, retaining the other response and provider checks. This neither adds the model nor changes the runtime default. [#163175](https://github.com/openclaw/openclaw/pull/163175), by [RomneyDa](https://github.com/RomneyDa).
- Replace fixed IRC test deadlines with waits for actual admission, completion, reconnection, and socket events. The helper respects test cancellation and removes its listener after settlement; the sanitized-empty reply case explicitly waits for admission before completion. Behavioral assertions remain, without changing IRC message handling or reconnect policy. [#163180](https://github.com/openclaw/openclaw/pull/163180), by [RomneyDa](https://github.com/RomneyDa).
- Exercise the registered Matrix account-schema migration directly, avoiding unrelated full-CLI startup in its account-repair test. Released fixtures, stale-schema write rejection, detection warnings, account-row preservation, untouched archived bytes, repaired writes, reopening, and cleanup checks remain. This changes test execution rather than production repair speed. [#163183](https://github.com/openclaw/openclaw/pull/163183), by [RomneyDa](https://github.com/RomneyDa).
- Run four expensive declaration-build fixture cases sequentially on every platform, preserving compiler assertions and time limits. Windows contention motivated the repair, but production compilation stays unchanged. The full Windows test file still includes a fixture that requires symlink privileges. [#163217](https://github.com/openclaw/openclaw/pull/163217), by [RomneyDa](https://github.com/RomneyDa).
- Align private-subagent QA with existing internal-review outcomes. The mock returns a worker-started status after handoff and a private-review-complete status after the second result; direct and catalog-routed tests and the scenario wording follow those responses. This supplies fixture alignment for the earlier delegated-work changes, without adding completion or privacy behavior. [#163503](https://github.com/openclaw/openclaw/pull/163503), with contributions from [RomneyDa](https://github.com/RomneyDa) and [vincentkoc](https://github.com/vincentkoc).
- Stop requiring xAI's inconsistent interruption acknowledgement in the voice live test, while retaining speech detection, the outbound truncation request, cleared playback, and subsequent transcription and response-completion checks. This backports contextual [#163529](https://github.com/openclaw/openclaw/pull/163529). [#163530](https://github.com/openclaw/openclaw/pull/163530), with a contribution from [vincentkoc](https://github.com/vincentkoc).
- Wait for persisted recovery admission in the restart test instead of relying on a one-second Gateway-call polling window. The subsequent recovery stop and Gateway-parameter assertions remain, without changing session recovery itself. [#163606](https://github.com/openclaw/openclaw/pull/163606), by [RomneyDa](https://github.com/RomneyDa).
- Give both strict and non-strict live file-read prompts an explicit JavaScript read-and-text example. The prompt recognizes Code Mode by the `exec` tool's JavaScript interface, allows additional directly exposed tools, and retains the requirement to return both file markers. It refines contextual [#157779](https://github.com/openclaw/openclaw/pull/157779); related [issue #161072](https://github.com/openclaw/openclaw/issues/161072) remains open, including its broader retry and recovery concerns. [#163619](https://github.com/openclaw/openclaw/pull/163619), by [RomneyDa](https://github.com/RomneyDa).
- Retain the cron ownership test's five-port Gateway reservation until its instance has finished cleanup, preventing another cooperating fixture from taking the selected port before startup. Existing cron assertions remain. This backports the cron fixture change from contextual [#163003](https://github.com/openclaw/openclaw/pull/163003); it changes no production scheduling behavior and does not cover every possible port conflict. [#163620](https://github.com/openclaw/openclaw/pull/163620), by [RomneyDa](https://github.com/RomneyDa).

</details>

</Accordion>

<Accordion title="Dependency and compatibility records">

Package evidence can describe dependencies bundled inside npm and handle narrowly defined missing bundle markers. The [plugin compatibility records](/plugins/compatibility) also keep overdue removals pending until migration and usage checks are complete, preserving the existing APIs while that work continues.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Bug fixes**

- Account for bundled npm dependencies through their nearest non-bundled enclosing package, requiring that carrier's download and integrity metadata. Reports add a path-sorted `bundledDependencies` list and per-package and total counts while preserving the original lock payload. Malformed bundled entries and incomplete ordinary dependencies still fail. Metadata checks do not themselves fetch or cryptographically authenticate archive bytes. Direct commit [c434cbe](https://github.com/openclaw/openclaw/commit/c434cbefd4d1428c47d020346fdd8480bf0a2a87).
- Normalize omitted bundle markers only under the existing exact npm version, dependency path, version, and name exception; explicit false markers remain rejected, and final authentication against the locked npm archive remains required. The same change makes Telegram test cleanup await actual transcript-append promises before deleting its database, preventing delayed writes from recreating fixture state. Dependency versions, production Telegram delivery, and locales do not change. [#163392](https://github.com/openclaw/openclaw/pull/163392), with a contribution from [vincentkoc](https://github.com/vincentkoc).

**Security and trust**

- Upgrade both locked Undici copies and the override in the Vercel release tool from 6.28.0 to 6.28.1, refreshing the installer checksum for the changed lock. This addresses the WebSocket denial-of-service advisory `GHSA-rfgv-xxqx-mfg5` in tooling used for registry mirroring. That tooling does not ship in OpenClaw packages, so this is not an installed-product vulnerability fix. [#161418](https://github.com/openclaw/openclaw/pull/161418).

**Limits and compatibility**

- Move ten compatibility annotation families and the legacy media record to `removal-pending`, preserving their original review dates and documenting outstanding migration and published-plugin checks. No API is removed. The registry tracks twenty pending records, including existing branch-specific records, with none eligible for removal. This backports contextual [#163127](https://github.com/openclaw/openclaw/pull/163127), with corresponding registry, test, and compatibility-documentation updates. [#163354](https://github.com/openclaw/openclaw/pull/163354), with contributions from [Patrick-Erichsen](https://github.com/Patrick-Erichsen) and [RomneyDa](https://github.com/RomneyDa).

</details>

</Accordion>

<Accordion title="Release records and CI maintenance">

Repository maintenance updates the release records and gives the extension-boundary check more time to finish. It also repairs the tools that collect hosted test timings and rebuild historical update-compatibility records.

<details class="release-source-toggle">
<summary>Sources and complete change list</summary>

**Documentation**

- Expand the 2026.9.8 changelog, update its acknowledgements, and add a separate contribution record. Direct commit [0ea96bc](https://github.com/openclaw/openclaw/commit/0ea96bc2c594db037b960c8fd81bfef25f85cb40).
- Shorten nine CI workflow comments to fit the 480,000-byte file-size guard while preserving all executable settings, including the preceding timeout adjustment. Direct commit [2e4ea3f](https://github.com/openclaw/openclaw/commit/2e4ea3f995213493379d8875c85fc8a4c3842304).
- Restore the comment wording expected by the workflow-planning test after the trimming change. Only a comment changes; the workflow's executable behavior remains the same. Direct commit [fcfa665](https://github.com/openclaw/openclaw/commit/fcfa66550ddb31707634004245101cef1f0a3bb9).

**Bug fixes**

- Increase the extension-package-boundary CI job's allowance from 20 to 30 minutes, keeping other additional checks at 20 minutes. Regression guards and [CI documentation](/ci) reflect the scoped budget; compiler concurrency, check selection, caches, and validation requirements stay unchanged. Direct commit [c305d7a](https://github.com/openclaw/openclaw/commit/c305d7adbbc147dfb6395d28cf7d463e6ed44d07).
- Select hosted timing jobs by the exact test-shard step, preserving hosting and compact-job exclusions and still rejecting missing or ambiguous shard descriptors. Historical compatibility tracing additionally recognizes one frozen wrapper body, checking its digest, target, generated bindings, and provenance while rejecting altered or unknown wrappers. These repairs restore collection and regeneration tools without changing stored timing costs, the compatibility inventory itself, or current wrapper generation. The timing repair closes [issue #161550](https://github.com/openclaw/openclaw/issues/161550). [#161635](https://github.com/openclaw/openclaw/pull/161635).

</details>

</Accordion>

</AccordionGroup>

<details class="release-source-toggle">
<summary>Release contributors</summary>

Thanks to [ericcaiwx-star](https://github.com/ericcaiwx-star), [fuller-stack-dev](https://github.com/fuller-stack-dev), [obviyus](https://github.com/obviyus), [Patrick-Erichsen](https://github.com/Patrick-Erichsen), [RomneyDa](https://github.com/RomneyDa), [scotthuang](https://github.com/scotthuang), [VACInc](https://github.com/VACInc) and [vincentkoc](https://github.com/vincentkoc) for their contributions across this release.

</details>
