---
title: "v2026.9.9"
summary: "GPT-6.1 Sol in Codex, Claude Haiku 5.5 support, update recovery, and fixes for replies and scheduled jobs."
description: "OpenClaw v2026.9.9 release notes covering GPT-6.1 Sol in Codex, Claude Haiku 5.5, update recovery, missing replies, Windows workspaces and input policies."
keywords:
  - OpenClaw
  - v2026.9.9
  - release notes
---

# v2026.9.9

AI agents and tools can read these release notes as [plain Markdown](https://raw.githubusercontent.com/openclaw/openclaw/main/CHANGELOG/2026.9.9.md).

OpenClaw 2026.9.9 adds GPT-6.1 Sol to the Codex model list and supports Claude Haiku 5.5 through Anthropic and Claude CLI, improves recovery after failed updates, fixes missing iMessage replies, and keeps an old scheduled job from interrupting a newer conversation.

**Release scale:** 112 pull requests, 69 direct commits, and 91 contributors.

## Installation and Onboarding

- **Channel setup.** Adding channels one after another in guided setup no longer leaves saving stuck on Working while OpenClaw waits for the setup window itself. [#161116](https://github.com/openclaw/openclaw/pull/161116) by [@steipete](https://github.com/steipete).

## Web UI

- **Windows workspaces.** Creating an empty workspace on Windows no longer fails because of the way OpenClaw calls Git. You can choose **New workspace** and start a conversation without changing your global Git settings. First install Git for Windows using the [native Windows setup guidance](/platforms/windows#native-windows-cli-and-gateway). Folders nested too deeply can still hit a separate Git limit. [#164202](https://github.com/openclaw/openclaw/pull/164202) by [@steipete](https://github.com/steipete).
- **Conversation titles.** When your model server handles one request at a time, OpenClaw can try naming a new conversation again after its first reply finishes instead of leaving it with a random name. Names you choose yourself are preserved. [#163817](https://github.com/openclaw/openclaw/pull/163817) by [@MertBasar0](https://github.com/MertBasar0) and [@obviyus](https://github.com/obviyus).
- **Chat reading position.** After jumping to the latest message and scrolling back, resizing the chat no longer pulls you down to the newest messages. [#162411](https://github.com/openclaw/openclaw/pull/162411), with coauthor [@steipete](https://github.com/steipete).
- **Channel conversation history.** Messages sent from the dashboard into a channel keep their original conversation association. New messages from linked requesters also stop appearing twice in Claude CLI chat history, with internal requester instructions kept out of the displayed text. Existing records are not rewritten. [#151786](https://github.com/openclaw/openclaw/pull/151786) by [@Alix-007](https://github.com/Alix-007), reported by [@Rotocruz](https://github.com/Rotocruz); [#161012](https://github.com/openclaw/openclaw/pull/161012) by [@Marvinthebored](https://github.com/Marvinthebored) and [@Peetiegonzalez](https://github.com/Peetiegonzalez), with reports from [@Oldrich333](https://github.com/Oldrich333), [@holgergruenhagen](https://github.com/holgergruenhagen) and [@obnoxious2011-cmd](https://github.com/obnoxious2011-cmd).
- **Opening and updating chats.** Chats can open while their labels or activity details change, and saved background replies stay visible when an older history request finishes late. [#162681](https://github.com/openclaw/openclaw/pull/162681), [#162763](https://github.com/openclaw/openclaw/pull/162763), with contributions from [@VACInc](https://github.com/VACInc) and follow-up investigation by [@steipete](https://github.com/steipete).
- **Chat scrolling.** Chats keep following incoming turns and large updates when you are watching the latest messages, while scrolling back preserves your reading position. Expanding details and delayed layout changes retain that choice. Refreshing history without changing its height also avoids an unwanted jump. [be6713b](https://github.com/openclaw/openclaw/commit/be6713bf97f9a8044982a6fb0a2bbc3fdc3afec0), [0c01cc6](https://github.com/openclaw/openclaw/commit/0c01cc6e0aaa757700476db707785998391ff9b9), [#166239](https://github.com/openclaw/openclaw/pull/166239), [#166258](https://github.com/openclaw/openclaw/pull/166258), [#166301](https://github.com/openclaw/openclaw/pull/166301), [#166341](https://github.com/openclaw/openclaw/pull/166341), with contributions from [@steipete](https://github.com/steipete) and [@RomneyDa](https://github.com/RomneyDa).
- **Expanded chat details.** Opening a message's expandable details keeps the clicked content in place instead of pulling it toward the bottom of the chat. [#166200](https://github.com/openclaw/openclaw/pull/166200) by [@RomneyDa](https://github.com/RomneyDa), with included source work by [@steipete](https://github.com/steipete).
- **Streaming replies and composer spacing.** Replies keep scrolling as text arrives after a jump to the bottom that needed no movement. Empty notices also stop leaving a blank gap above the message box. [#166348](https://github.com/openclaw/openclaw/pull/166348) by [@RomneyDa](https://github.com/RomneyDa), with the spacing fix by [@vincentkoc](https://github.com/vincentkoc).

## Updates and Maintenance

- **Update completion.** Updating OpenClaw no longer fails just because it is saving data at the same time. Updates from affected older versions keep the files plugins need to finish their upgrades, and global npm installs avoid a false recovery-file check failure. Once required database work has finished, a stalled shutdown can also stop holding up the update result; that safeguard applies to subsequent updates run by the fixed installation. [30c180a](https://github.com/openclaw/openclaw/commit/30c180a4ece3ae149286b80174b0edb526aa88ae), [ecac0d3 (original migration fix)](https://github.com/openclaw/openclaw/commit/ecac0d3f0bdca5d127df1b4f269d007714697ce4), [55360c6](https://github.com/openclaw/openclaw/commit/55360c6bdbd479d4e784aed79c6350b61f6febb0) by [@RomneyDa](https://github.com/RomneyDa); [#161258](https://github.com/openclaw/openclaw/pull/161258) by [@steipete](https://github.com/steipete).
- **Maintenance errors.** Fixed a false maintenance warning that could interrupt an update and unnecessarily return OpenClaw to the previous version. [#164554](https://github.com/openclaw/openclaw/pull/164554) by [@RomneyDa](https://github.com/RomneyDa), with source work by [@steipete](https://github.com/steipete) and reporting and investigation by [@DasX](https://github.com/DasX).
- **Failed-update recovery.** Supported updaters can recover a compatible OpenClaw installation after a failed update while preserving data written during the attempt. Returning to 2026.9.8 also keeps later updates possible. An older updater already running cannot gain these safeguards. On macOS and Linux, restart stays blocked until Doctor processes are confirmed stopped. Follow the [repair steps](/cli/update/repair-and-recovery) and [rollback guidance](/install/updating/rollback-and-recovery). [#164497](https://github.com/openclaw/openclaw/pull/164497), [#164724](https://github.com/openclaw/openclaw/pull/164724) by [@RomneyDa](https://github.com/RomneyDa), with original recovery work by [@steipete](https://github.com/steipete) and reports from [@DasX](https://github.com/DasX) and [@jarvisnextgeneration20-lang](https://github.com/jarvisnextgeneration20-lang).
- **Backups on FUSE storage.** If you use storage mounted through FUSE, backups and restores no longer fail solely because a file's recorded times changed. OpenClaw checks that the contents still match before proceeding. This covers updates, Doctor repairs and rollbacks; see the [container upgrade guidance](/install/docker#upgrading-container-images). [3ecb62a (original FUSE fix)](https://github.com/openclaw/openclaw/commit/3ecb62aad260e3f871e7ae83d446404abfc83bed) by [@steipete](https://github.com/steipete).
- **Older memory databases.** Doctor can finish upgrading an older memory cache even if some saved entries are too large or damaged. It warns you about skipped entries, which rebuild as needed while your original data stays intact. Before a database upgrade, stop processes using it and take a verified backup as explained in the [migration guidance](/reference/database-schemas/agent-schema-history#compact-agent-payload-storage). [#164303](https://github.com/openclaw/openclaw/pull/164303) by [@steipete](https://github.com/steipete).
- **Package-manager updates.** pnpm updates avoid the “not a terminal” failure, and optional plugin syntax errors can produce warnings instead of blocking the update snapshot. Large npm installs can continue past a scan limit with a warning that full package contents are unverified. An older updater may need a [manual first update](/install/updating/update-methods#alternative-manual-npm-pnpm-or-bun) or the [plugin recovery steps](/install/update-troubleshooting). [df11aae](https://github.com/openclaw/openclaw/commit/df11aae60f49047bf56903b5fd0b79be4760a5b1) by [@alkor2000](https://github.com/alkor2000); [#161001](https://github.com/openclaw/openclaw/pull/161001), [#162298](https://github.com/openclaw/openclaw/pull/162298) by [@steipete](https://github.com/steipete), with reporting by [@jamiezigelbaum](https://github.com/jamiezigelbaum).
- **Windows update checks.** Fixed an older-updater compatibility problem that could make the first Doctor check fail and roll back a Windows update. [#162245](https://github.com/openclaw/openclaw/pull/162245) by [@steipete](https://github.com/steipete), reported and diagnosed by [@WG-Mojo](https://github.com/WG-Mojo).
- **Docker startup.** Fixed an upgrade loop on affected older Linux hosts that repeatedly rejected an unchanged database. Retries reuse verified rollback backups instead of making another full set each time; historical backups remain available. See the [Docker recovery guidance](/install/docker). [#162305](https://github.com/openclaw/openclaw/pull/162305) by [@steipete](https://github.com/steipete), with reports and investigation by [@Ludwigtheo0815](https://github.com/Ludwigtheo0815), [@rebarshop-24](https://github.com/rebarshop-24) and [@nweishar](https://github.com/nweishar).
- **Doctor maintenance.** Long database checks show progress and respond to Ctrl+C, waiting for work already underway to finish cleaning up before exiting. Rerun Doctor after interruption to finish the repair. Doctor can also continue when optional update-history checks are unavailable. Doctor also lets cleanup finish before closing, avoiding a Windows crash risk during shutdown. [Maintenance guidance](/cli/doctor/sqlite-maintenance), [#162213](https://github.com/openclaw/openclaw/pull/162213), [#163608](https://github.com/openclaw/openclaw/pull/163608) by [@steipete](https://github.com/steipete), with reports from [@fenglanhua](https://github.com/fenglanhua) and [@ringbe-cyber](https://github.com/ringbe-cyber). [5d7fa8e](https://github.com/openclaw/openclaw/commit/5d7fa8e9fa04a0202407891ba598b117908db3a8).
- **Session archive repairs.** Doctor can import sessions blocked by older migration records and retry interrupted archive repairs. Missing file copies stay flagged for recovery, with the original database content retained. Doctor also attempts to restore a managed Gateway it stopped once maintenance has finished. Rolling back OpenClaw does not undo archive changes already committed. [#164867](https://github.com/openclaw/openclaw/pull/164867) by [@steipete](https://github.com/steipete), reported by [@hshs38033-cmd](https://github.com/hshs38033-cmd); [#165854](https://github.com/openclaw/openclaw/pull/165854) by [@RomneyDa](https://github.com/RomneyDa) and [@Olli0103](https://github.com/Olli0103), with reports and investigation from [@A1fred-AI](https://github.com/A1fred-AI), [@mpquemel](https://github.com/mpquemel), [@goncalonc](https://github.com/goncalonc) and [@steipete](https://github.com/steipete).
- **Plugin installation records.** An upgrade encountering damaged old plugin metadata preserves the original record and its valid installation entries. Already-lost data still needs a backup, and a separate unresolved registry-refresh problem can overwrite preserved entries; do not use refresh as an assured recovery step. [#161485](https://github.com/openclaw/openclaw/pull/161485) by [@steipete](https://github.com/steipete), reported by [@aniruddhaadak80](https://github.com/aniruddhaadak80).
- **Quarantined databases.** Opening sessions now respects an existing corruption quarantine. Affected installations may lose read-only access until repair or restoration succeeds; preserve the database and its WAL file and follow the [recovery guide](/reference/database-schemas/integrity-and-recovery#a-database-is-quarantined-after-integrity-verification-failed). [#161783](https://github.com/openclaw/openclaw/pull/161783) by [@SunnyShu0925](https://github.com/SunnyShu0925), reported by [@steipete](https://github.com/steipete) and verified by [@Patrick-Erichsen](https://github.com/Patrick-Erichsen).
- **Restart recovery.** If automatic triage repairs a refused Gateway restart, OpenClaw tries starting once more. A failed retry, or an installed triage handler that declines or cannot finish, can now exit with an error. Foreground and container deployments need an external restart policy to recover from that exit. [#160173](https://github.com/openclaw/openclaw/pull/160173) by [@steipete](https://github.com/steipete), reported by [@dh-js](https://github.com/dh-js).
- **Monterey service commands.** On affected macOS 12 installations, Gateway stop, restart and update commands can run from an independent Terminal window when OpenClaw can establish that it is safe to do so. An unfixed older updater may still need the [one-time stop, update and start sequence](https://github.com/openclaw/openclaw/pull/163317). [#163317](https://github.com/openclaw/openclaw/pull/163317), [#165935](https://github.com/openclaw/openclaw/pull/165935) by [@NovaUnboundAi](https://github.com/NovaUnboundAi), [@xXG0DLessXx](https://github.com/xXG0DLessXx) and [@RomneyDa](https://github.com/RomneyDa).
- **Very old configurations.** Update errors for retired settings now explain the required intermediate upgrade through 2026.9.5 and `doctor --fix`. Keep the same profile and configuration paths and follow the [older-version upgrade guide](/install/updating#upgrading-very-old-versions). [#162150](https://github.com/openclaw/openclaw/pull/162150) by [@steipete](https://github.com/steipete).
- **September database compatibility.** Upgrading from September stable keeps shared data in the format used by 2026.9.8. Data already converted to the newer format by an October beta cannot be opened by this version and is left unchanged; this update cannot downgrade or repair it. [#166959](https://github.com/openclaw/openclaw/pull/166959) by [@RomneyDa](https://github.com/RomneyDa), with earlier compatibility work in [#166026](https://github.com/openclaw/openclaw/pull/166026) by [@RomneyDa](https://github.com/RomneyDa) and [@shakkernerd](https://github.com/shakkernerd).
- **Doctor repair recovery.** Archive repairs can continue past empty old session entries and resume saved progress after interruption. Doctor also retries failed resource cleanup and can restore the Gateway once cleanup is safe, while still reporting the error. [State-migration guidance](/cli/doctor/state-migrations), [ed472c0](https://github.com/openclaw/openclaw/commit/ed472c065b53fbecc342b549882b6eba41db2ec2), [fab3a66](https://github.com/openclaw/openclaw/commit/fab3a6622e20d76fb3e850854372e44479a9dd71) by [@RomneyDa](https://github.com/RomneyDa), with coauthors [@steipete](https://github.com/steipete) and [@victor-gurbani](https://github.com/victor-gurbani) on the Doctor and Claude CLI repairs.
- **Older ACP sessions.** Upgrades preserve older ACP session settings even when the original session file has already moved into an archive. [16398dc](https://github.com/openclaw/openclaw/commit/16398dcb4a1d3b2fdb96d2206a82074825f3754d) by [@RomneyDa](https://github.com/RomneyDa).
- **Windows Gateway discovery.** An unreadable launcher belonging to an unrelated Windows Scheduled Task no longer blocks Gateway discovery just because that task is running. Some custom Gateways launched through a single BAT file can still go undetected. [#166299](https://github.com/openclaw/openclaw/pull/166299) by [@RomneyDa](https://github.com/RomneyDa), with source work by [@steipete](https://github.com/steipete).

## Messaging

- **Telegram Control UI.** To open OpenClaw's Mini App in Telegram, send `/controlui` in a private chat with the bot. `/dashboard` now belongs to session dashboards. Follow the [migration guide](/channels/telegram/mini-app#upgrading-from-dashboard) to replace old shortcuts and get a fresh button. Access requires your numeric Telegram ID in the bot's owner settings; ask an administrator to add it if you relied on a wildcard or username. [#161369](https://github.com/openclaw/openclaw/pull/161369) by [@mmaps](https://github.com/mmaps), with command separation by [@joshavant](https://github.com/joshavant).
- **iMessage replies.** OpenClaw could finish writing an answer in an ordinary iMessage conversation but never send it. The affected replies are now sent. [#163742](https://github.com/openclaw/openclaw/pull/163742), with coauthors [@VACInc](https://github.com/VACInc), [@Kimiyu-186](https://github.com/Kimiyu-186) and [@steipete](https://github.com/steipete).
- **Discord task results.** A delegated task could post its answer in your Discord thread and still appear to have failed because it sent no further reply. OpenClaw now recognizes that answer as delivered. Replies sent through a webhook also use the webhook and identity assigned to your thread. [#163756](https://github.com/openclaw/openclaw/pull/163756) by [@MertBasar0](https://github.com/MertBasar0), reported by [@stuart-minion-ai](https://github.com/stuart-minion-ai) and landed by [@obviyus](https://github.com/obviyus).
- **Discord health checks.** Configuration and health checks can proceed when Discord activity or voice components fail to load. [f489f0f](https://github.com/openclaw/openclaw/commit/f489f0f62adee590e0d68ff75df0143a6015f41f).
- **Cancelling queued messages.** If you cancel a message that is still waiting to be processed, the reply already in progress can finish instead of getting stuck. A [separate unresolved issue](https://github.com/openclaw/openclaw/pull/164230#issuecomment-5968104212) can let pending plugin work continue while you reset or delete the conversation. [#164230](https://github.com/openclaw/openclaw/pull/164230) by [@vincentkoc](https://github.com/vincentkoc).
- **Google Chat and Slack threads.** Google Chat replies stay in their original thread when threading is enabled, even if typing indicators fail. Slack replies from CLI-backed agents also retain the originating thread when no other destination was requested. [Google Chat guidance](/channels/googlechat), [Slack thread guidance](/channels/slack/threads-and-sessions), [#136689](https://github.com/openclaw/openclaw/pull/136689) by [@ScientificProgrammer](https://github.com/ScientificProgrammer) and [@obviyus](https://github.com/obviyus), with validation by [@danieljimz](https://github.com/danieljimz); [#160751](https://github.com/openclaw/openclaw/pull/160751) by [@maxpuppet](https://github.com/maxpuppet) and [@obviyus](https://github.com/obviyus).
- **Feishu attachments.** Files sent with captions or together in Feishu/Lark posts reach the agent as documents instead of disappearing or being mistaken for video. [#151896](https://github.com/openclaw/openclaw/pull/151896) by [@gokay-ai](https://github.com/gokay-ai) and [@obviyus](https://github.com/obviyus), reported and diagnosed by [@WhitenessTiger](https://github.com/WhitenessTiger).
- **Discord follow-ups.** A waiting Discord message no longer blocks newer messages in the same channel from reaching the reply queue. Your [queue mode](/concepts/queue) determines how corrections and follow-ups are handled; ordering across different senders remains a separate limitation. [fe28b2c](https://github.com/openclaw/openclaw/commit/fe28b2c18f41f220e26c69f9311cb3328beeadac) by [@steipete](https://github.com/steipete).
- **Long voice replies.** In affected multi-agent setups, automatic voice summaries use the replying agent's provider access instead of failing and clipping the answer. That agent still needs credentials for the configured [summary model](/tools/tts/output). [#161454](https://github.com/openclaw/openclaw/pull/161454) by [@drakeo338](https://github.com/drakeo338) and [@obviyus](https://github.com/obviyus), reported by [@aounakram](https://github.com/aounakram).

## Memory

- **Saving memory before replies.** A long memory checkpoint before a reply no longer makes the channel time out and restart the same message while memory is still being saved. [#137359](https://github.com/openclaw/openclaw/pull/137359) by [@ericcaiwx-star](https://github.com/ericcaiwx-star), verified by [@obviyus](https://github.com/obviyus), with reports and investigation from [@big-hill](https://github.com/big-hill), [@alexph-dev](https://github.com/alexph-dev), [@ChuLaiTheGreat](https://github.com/ChuLaiTheGreat), [@FlagshipClaw](https://github.com/FlagshipClaw) and [@KirDE](https://github.com/KirDE).

## Skills

- **Plugin skills during updates.** In source-checkout installations, valid [plugin skills](/tools/skills) stay loadable during an update instead of temporarily disappearing with hardlink warnings. [#165882](https://github.com/openclaw/openclaw/pull/165882) by [@RomneyDa](https://github.com/RomneyDa).

## Models and Providers

- **GPT-6.1 Sol.** The Codex model list includes GPT-6.1 Sol, though using it still requires an eligible account and a compatible [Codex setup](/providers/openai/runtimes), including the [related provider support](https://github.com/openclaw/openclaw/pull/161400). When Codex repeatedly refuses an action, the request can also finish instead of remaining stuck until it times out. [65e89fc](https://github.com/openclaw/openclaw/commit/65e89fcc277cd26cf2f763112eaeb36325834a0e) by [@IstiqlalBhat](https://github.com/IstiqlalBhat), with coauthors [@RomneyDa](https://github.com/RomneyDa) and [@fuller-stack-dev](https://github.com/fuller-stack-dev).
- **Claude Haiku 5.5.** You can select Haiku 5.5 through the Anthropic API and Claude CLI. The `haiku` alias and Anthropic utility-model default now select 5.5, with adaptive thinking on by default. Choose an explicit Haiku 4.5 model to keep using it. API pricing rises for prompts above 100,000 tokens; see the [model, thinking and pricing guidance](/providers/anthropic). [#166706](https://github.com/openclaw/openclaw/pull/166706) by [@RomneyDa](https://github.com/RomneyDa).
- **Bundled Codex.** The copy of Codex included with OpenClaw is updated to 0.160.0, bringing fixes for starting sessions and recording diagnostic logs. This bundled copy is separate from any Codex command-line app you update yourself. [#163560](https://github.com/openclaw/openclaw/pull/163560) by [@vincentkoc](https://github.com/vincentkoc).
- **Copilot tool calls.** Plugin and MCP tools keep working after the first Copilot conversation turn instead of failing with “Async work scope is closed.” [#164598](https://github.com/openclaw/openclaw/pull/164598) by [@ericcurtin](https://github.com/ericcurtin), with diagnosis by [@takyyon](https://github.com/takyyon).
- **Model retries and context.** One-shot [model requests through the Gateway](/cli/infer) retain the original task when retrying the same model. Chat Completions conversations also use valid provider token counts to judge how full the conversation is, reducing reliance on estimates that can trigger recovery too early. [#160803](https://github.com/openclaw/openclaw/pull/160803) by [@changeroa](https://github.com/changeroa), reported by [@Oldrich333](https://github.com/Oldrich333) and verified by [@obviyus](https://github.com/obviyus); [ab24b53](https://github.com/openclaw/openclaw/commit/ab24b53b879078110a51ba0ee95899319927b683) by [@RileyJJY](https://github.com/RileyJJY).
- **Claude CLI background replies.** A child agent's completed task no longer takes the place of its parent's pending reply, allowing the parent to return its answer. [ed472c0](https://github.com/openclaw/openclaw/commit/ed472c065b53fbecc342b549882b6eba41db2ec2).

## Automations and Scheduling

- **Scheduled jobs and ongoing chats.** An older scheduled job reaching its time limit could stop a newer conversation in the same session and remove its access to tools. That [reported problem](https://github.com/openclaw/openclaw/issues/163568) is fixed. [#163704](https://github.com/openclaw/openclaw/pull/163704), thanks to [@jayzhou2309](https://github.com/jayzhou2309) for the fix, [@AXEG0](https://github.com/AXEG0) for reporting it, [@ekinnee](https://github.com/ekinnee) and [@MasterSwords1](https://github.com/MasterSwords1) for investigation, and [@obviyus](https://github.com/obviyus) for validation and landing work.
- **Starting background jobs.** Fixed a startup problem that could freeze chat or disconnect the web interface when a scheduled job or Skill Workshop review began. This applies to jobs using their agent's configured workspace, including while older chat history is condensed. Their [file access remains limited to the task folder](/plugins/architecture#plugin-metadata-snapshot-and-lookup-table). Scheduled jobs can also proceed using existing model information when a catalog refresh is slow. [#164049](https://github.com/openclaw/openclaw/pull/164049) by [@steipete](https://github.com/steipete); [#161132](https://github.com/openclaw/openclaw/pull/161132) by [@jayzhou2309](https://github.com/jayzhou2309), reported by [@Flakedict](https://github.com/Flakedict) and verified by [@obviyus](https://github.com/obviyus).
- **Editing scheduled jobs.** Agents can recover from supported mistakes in how a model formats a scheduled-job update, instead of repeatedly failing and leaving the old message in place. [#158543](https://github.com/openclaw/openclaw/pull/158543) by [@carlosjarenom](https://github.com/carlosjarenom), reported by [@louria](https://github.com/louria) and verified by [@obviyus](https://github.com/obviyus).
- **Interrupted one-shot jobs.** After a restart, an interrupted one-shot scheduled job can run again even if its first message already arrived, so you may receive a duplicate. [#166959](https://github.com/openclaw/openclaw/pull/166959).

## Plugins and Integrations

- **Model changes and plugin recovery.** Switching models can reuse large plugins already running instead of copying them again and freezing requests. Failed plugin reloads can recover healthy model access and replies without a restart, and a missing context-engine plugin can use the [built-in fallback](/concepts/context-engine). Initial loading can still block; unsuccessful recovery still needs a reload or restart. [#161267](https://github.com/openclaw/openclaw/pull/161267) by [@obviyus](https://github.com/obviyus), reported by [@cmrstudio56](https://github.com/cmrstudio56); [8abe351](https://github.com/openclaw/openclaw/commit/8abe351bf40fe16f6b134ab348cad9a1b381a754) by [@sahilsatralkar](https://github.com/sahilsatralkar); [#161023](https://github.com/openclaw/openclaw/pull/161023) by [@Patrick-Erichsen](https://github.com/Patrick-Erichsen).
- **Plugins under Bun on macOS.** Plugins such as iMessage can load when copying a larger dependency hits Bun's bad-file-descriptor error on macOS. [#159403](https://github.com/openclaw/openclaw/pull/159403) by [@sunlit-deng](https://github.com/sunlit-deng), reported by [@hannesrudolph](https://github.com/hannesrudolph), with follow-up work by [@steipete](https://github.com/steipete).
- **MCP connections.** Remote MCP plugins no longer stop native sessions from starting because OpenClaw gives them an unnecessary local working directory. An HTTP error from an MCP server also avoids the affected Node 26 crash path. [#162376](https://github.com/openclaw/openclaw/pull/162376) by [@Patrick-Erichsen](https://github.com/Patrick-Erichsen); [66c7c35](https://github.com/openclaw/openclaw/commit/66c7c35c35c7de9411ea4b38218b4a591e365096) by [@RvsL](https://github.com/RvsL).
- **Tool Search guidance.** If an agent tries to use an available direct-only tool through [Tool Search](/tools/tool-search), the error explains how to call it directly instead of sending the agent back to a fruitless search. [#161055](https://github.com/openclaw/openclaw/pull/161055) by [@obviyus](https://github.com/obviyus), reported by [@jgs-jeeves](https://github.com/jgs-jeeves).
- **Bundled MCP connections.** MCP servers imported from Claude and Codex bundles use the connection type their configuration requests instead of incorrectly falling back to another transport. [#166200](https://github.com/openclaw/openclaw/pull/166200).
- **MCP sign-in changes.** Background refresh preserves saved credentials when a server changes its sign-in provider. An explicit sign-in can register with the new provider; unused registrations with an outdated callback can also be replaced. [#166341](https://github.com/openclaw/openclaw/pull/166341), with contributions from [@RomneyDa](https://github.com/RomneyDa), [@Patrick-Erichsen](https://github.com/Patrick-Erichsen), [@steipete](https://github.com/steipete) and [@vincentkoc](https://github.com/vincentkoc).

## Security and Privacy

- **Windows MXC sandbox.** The optional [MXC sandbox](/plugins/reference/mxc) can start and run tools on compatible Windows computers without the old Windows service. If you chose your own MXC executable, update it to the documented requirements or switch back to the bundled copy, then restart the Gateway. A successful start can still warn that isolation is reduced. Keep secrets out of command arguments and environment values because people allowed to inspect processes on the host can read them. [#158303](https://github.com/openclaw/openclaw/pull/158303), thanks to [@paulcam206](https://github.com/paulcam206).
- **Request checks on paired computers.** Plugin [input policies](/plugins/hooks#choose-a-hook) can now reject a request before OpenClaw carries it out on a paired computer. A policy error also blocks the request. These checks cover OpenClaw jobs, not Codex or Copilot, and see only the prompt and history available at the Gateway. If a policy needs instructions or skill context added on the paired computer, run the job locally with a supported runner instead. Blocking a request does not erase text already saved in the conversation. [#164270](https://github.com/openclaw/openclaw/pull/164270) by [@steipete](https://github.com/steipete).
- **Secret rotation and recovery.** Replacing or importing a [credential](/cli/secrets) preserves its existing protection and allowed hosts unless you explicitly change them. Doctor also stores a recovered Gateway token in the secret store instead of copying it into configuration. That recovery requires [interactive confirmation](/gateway/doctor/gateway-and-services), even with `--yes`; earlier plaintext copies are not cleaned up. [#160926](https://github.com/openclaw/openclaw/pull/160926) by [@zachisfine](https://github.com/zachisfine), [@yetval](https://github.com/yetval) and [@steipete](https://github.com/steipete); [#162372](https://github.com/openclaw/openclaw/pull/162372) by [@steipete](https://github.com/steipete), reported by [@waynegault](https://github.com/waynegault).
- **Agent-to-agent credentials.** An A2A connection rejects a token whose environment variable is missing instead of accepting or sending the placeholder text. Supply the missing variable and reload or restart OpenClaw to restore the connection. [521ae23](https://github.com/openclaw/openclaw/commit/521ae2352ba13f1b63249b3d13945223eff39308) by [@eleqtrizit](https://github.com/eleqtrizit).
- **MCP sign-in.** OAuth login and token refresh refuse redirects that would send credentials to another origin. If a custom provider now fails with that refusal, configure direct token or registration endpoints. Ordinary MCP resource redirects keep their existing behavior. [#138263](https://github.com/openclaw/openclaw/pull/138263) by [@mmaps](https://github.com/mmaps), with prior work and coauthorship by [@hansraj316](https://github.com/hansraj316).
- **Export approvals.** Diagnostics and trajectory exports keep their designated approval device even when the prompt is delivered to a private chat. Other approval-only devices cannot approve the bound command; the administrator bypass remains. [#125663](https://github.com/openclaw/openclaw/pull/125663) by [@RomneyDa](https://github.com/RomneyDa).

## Quality-of-Life Improvements

- **Delegated task startup.** Cloud sessions can start with long assignments without shortening the task, and visible child sessions keep their own [worktree](/gateway/sandboxing/workspace-access) on later turns instead of failing a workspace check. [#159459](https://github.com/openclaw/openclaw/pull/159459), [#162308](https://github.com/openclaw/openclaw/pull/162308), with contributions from [@steipete](https://github.com/steipete).
- **Delegated task completion.** Parents receive complete new CLI-backed subagent answers instead of a shortened prefix. Finished child trees release capacity even when their completion notification is suspended, and same-model retries retain permitted follow-up delegation. Older truncated answers are not repaired. [#162843](https://github.com/openclaw/openclaw/pull/162843) by [@zyz619963502zyz](https://github.com/zyz619963502zyz), with diagnosis by [@holgergruenhagen](https://github.com/holgergruenhagen); [#162368](https://github.com/openclaw/openclaw/pull/162368) by [@armstrongsam25](https://github.com/armstrongsam25), reported by [@davidcittadini](https://github.com/davidcittadini), both verified by [@obviyus](https://github.com/obviyus); [#163032](https://github.com/openclaw/openclaw/pull/163032) by [@stackingrockss](https://github.com/stackingrockss).
- **Session maintenance commands.** Invalid reset targets are rejected before they can clear the main conversation. Compacting a missing session now reports an error, so scripts that relied on success must check the session exists or handle that error. [#161533](https://github.com/openclaw/openclaw/pull/161533) by [@steipete](https://github.com/steipete).

## Other Bug Fixes

- **Windows session storage.** Creating a session no longer fails when its database is reached through a Windows folder link, such as a junction. OpenClaw recognizes that the different paths point to the same database, including equivalent Windows long-path spellings. [bec0cfd](https://github.com/openclaw/openclaw/commit/bec0cfd9a21a1e6d5900fd0ac859c23f56b45d87) by [@cestercian](https://github.com/cestercian), with coauthor [@RomneyDa](https://github.com/RomneyDa); [#162332](https://github.com/openclaw/openclaw/pull/162332) by [@steipete](https://github.com/steipete), with reports and diagnosis from [@zhyx1996](https://github.com/zhyx1996), [@ngominhduc263](https://github.com/ngominhduc263), [@oxen-horse](https://github.com/oxen-horse), [@wuwo2119](https://github.com/wuwo2119), [@dapangkai11](https://github.com/dapangkai11) and [@ignamiranda](https://github.com/ignamiranda).
- **Commands that would not exit.** Fixed a Node problem that could leave commands running after they had printed all their output. The workaround also covers the Gateway service, hook relays and macOS node worker. Some commands may take longer, and advanced overrides can bypass the fix; see the [Node compatibility guide](/install/node-compatibility#v8-compiler-settings). [#163788](https://github.com/openclaw/openclaw/pull/163788) by [@steipete](https://github.com/steipete).
- **Sessions on paired computers.** A paired computer could appear unavailable while sending routine status updates, causing other [sessions running there](/nodes/session-hosting) to stall or fail. Updating the Gateway fixes this interruption. Requests also wait for worker reconnection instead of freezing the computer's OpenClaw host and its other workers. [#164087](https://github.com/openclaw/openclaw/pull/164087) by [@steipete](https://github.com/steipete); [#160812](https://github.com/openclaw/openclaw/pull/160812) by [@RileyJJY](https://github.com/RileyJJY) and [@altaywtf](https://github.com/altaywtf), reported by [@aniruddhaadak80](https://github.com/aniruddhaadak80).
