## 2026.5.28
### 亮点
- Agent 和 Codex 运行时恢复更加稳定:子 Agent 保持当前工作目录/工作区分离,钩子上下文保持提示本地化,会话锁在超时中止时释放,避免使用过时的重启延续,Codex 应用服务器/辅助程序故障不再破坏共享运行时状态。(#87218, #86875, #87409, #87399, #87375)
- 频道投递和会话身份在出站插件钩子、Matrix 房间 ID、iMessage 反应/批准、Slack 最终回复、Discord 恢复工具警告以及 Microsoft Teams 服务 URL 信任检查方面变得更加安全。(#73706, #75670, #87366, #87451, #87334)
- 移动端和聊天界面获得更广泛的刷新:iOS Pro 界面、Gateway 聊天传输、入门引导、Talk 权限、WebChat 重连投递以及会话选择器行为现可在重连和空搜索时保留更多状态。(#87367, #87531, #87682)
- CLI、认证、诊断和提供商路径更快失败且恢复更清晰:拒绝格式错误的数字/版本选项,限制 OAuth 和本地服务启动请求,旧版 `api_key` 认证配置文件迁移至规范形式,重启指导具有可操作性。(#87398, #86281, #87361)
- 插件和 Gateway 热路径减少重复工作,同时保持缓存正确性,涉及安装记录、配置 JSON 解析、工具搜索目录、会话存储、清单模型行、自动启用插件配置、浏览器令牌和查看器资源。(#86699)
- 发布、QA 和 E2E 验证现在对更多日志、工件、工具套件和跨操作系统等待进行限制,使失败通道能提供证据,而非挂起或误报为绿色。
### 变更
- 状态:在状态输出中显示活跃子 Agent 详情。
- Diffs:拆分默认语言包并扩展默认 Diffs 语言覆盖范围,同时保持宿主楼层对齐。(#87370, #87372) 感谢 @RomneyDa。
- ClawHub:添加插件显示名称以及技能验证和信任界面。(#87354, #86699) 感谢 @thewilloftheshadow 和 @Patrick-Erichsen。
- iOS:刷新开发应用,集成 Pro Command、Chat、Agents 和 Settings 标签页,连接到 Gateway 会话、诊断、聊天和实时 Talk。(#87367) 感谢 @Solvely-Colin。
- 文档:澄清 Codex 计算机使用设置、粘贴令牌标准输入认证设置、macOS Gateway 睡眠故障排除、原生 Codex 钩子中继恢复、容器模型认证、安装部署卡片、设备令牌管理员控制以及向后移植目标。(#87313, #63050) 感谢 @bdjben、@liaoandi 和 @thewilloftheshadow。
- PDF/工具:使用 ClawPDF 进行 PDF 提取,并在 Agent 工具结果中展示 MCP 结构化内容。(#87670)
### 修复
- Agent:当可选的 `agents delete` Gateway 探测无法认证时,回退到本地配置修剪,使离线安装仍可删除 Agent 而不移除共享工作区。
- 收紧手机控制变更授权 [AI]。(#87150) 感谢 @pgondhi987。
- 明确指令持久化授权策略 [AI]。(#86369) 感谢 @pgondhi987。
- Agent/Codex:保持派生 Agent 当前工作目录/工作区状态分离,保持钩子上下文提示本地化,在超时中止时释放会话锁,避免会话事件队列自等待,在启动或辅助程序故障时保留共享应用服务器状态,在重启期间保持原生钩子中继活跃,通过工具路由工作区内存,先解析 Codex 运行时模型,报告隔离的动态工具,格式化 `skills` 命令输出,并限制压缩/引导重试。(#87218, #86875, #86123, #87399, #87375, #87383, #87400) 感谢 @mbelinky、@Alix-007、@luoyanglang、@yetval 和 @sjf。
- 频道:将规范会话密钥线程化到出站钩子中,保留 Matrix 房间 ID 大小写,使回退工具警告提及无效,在后期清理期间保留已投递的 Slack 最终回复,在拒绝反应后继续 iMessage 轮询,抑制重复的原生执行批准,保留 Telegram SecretRef 提示配置,抑制 Discord 恢复工具警告,并阻止不信任的 Teams 服务 URL。(#73706, #75670, #87366, #87451, #87334) 感谢 @zeroaltitude、@lukeboyett、@xiaotian 和 @eleqtrizit。
- CLI/认证/诊断/提供商:拒绝格式错误的数字/超时/子命令版本输入,等待重生子进程关闭,限制 Codex 和 GitHub Copilot OAuth/令牌请求,在主线程外预热提供商认证,尊重 Codex 响应超时,限制本地服务启动,无需缓存目录即可解析 GPT-5.5,迁移旧版内存自动提供商配置,重写非规范 `api_key` 认证配置文件,并使诊断重启后续操作具有可操作性。(#87398, #86281, #87361) 感谢 @Patrick-Erichsen、@samzong、@giodl73-repo 和 @alkor2000。
- Gateway/安全/会话状态:在认证轮换后过期浏览器令牌,限定助手幂等性去重,排空探测客户端关闭,避免重复使用过时的重启延续,保留重试后回退,限制 WebChat 图像和工件转录扫描,在入站元数据时间戳中包含秒数,并在行上限时驱逐当前插件状态命名空间。
- 配置/解析/网络:拒绝部分数字解析,严格解析提供商/Discord 重试头部和日期,支持 IPv6 和裸 IPv6 `no_proxy` 条目,规范化密钥目标数组索引,并拒绝格式错误的内容长度、已检查的 TCP 端口、市场内容长度、cron 纪元以及沙箱状态字段。
- 提供商/Agent:保留种子化的 Anthropic 签名,连接签名增量块,在层级后缀间保留 DeepSeek `reasoning_content` 重放,将 OpenRouter strict9 ID 应用于 Mistral 路由,提升 Ollama 纯文本工具调用,并恢复空预检压缩。(#87593)
- 文件传输:在归档验证或解包已完成后,处理迟到的 tar 标准输入管道错误。
- 性能:在重新加载之间信任安装记录缓存,优先使用原生 JSON 解析,重用未更改的工具搜索目录,跳过未更改的存储序列化,添加预计算会话补丁写入器,减少存储克隆分配,缓存清单模型目录行和自动启用插件配置,并精简当前元数据身份缓存。
- Docker/发布/QA:打包运行时工作区模板,流式传输跨操作系统服务工件,保留稀疏 Crabbox 运行工件,限制 OpenClaw 实例日志、插件严酷测试中继日志、MCP 通道缓冲区、综合扫描、Agent 轮次断言和发布场景日志,并保持发布/Google 实时防护最新。
### 发布验证
- npm 包:https://www.npmjs.com/package/openclaw/v/2026.5.28-beta.1
- 注册表 tarball:https://registry.npmjs.org/openclaw/-/openclaw-2026.5.28-beta.1.tgz
- 完整性校验:sha512-xMvO9tcAzIlzJsJhR3E8iAWk21bIC9E/94Dy3PQgul7fpowTM2VXp3zpAQUoY/hxJ9oJRK6PyeNfwVtIvYK2bw==
- OpenClaw npm 发布:https://github.com/openclaw/openclaw/actions/runs/26619000832
- npm 预检:https://github.com/openclaw/openclaw/actions/runs/26617230525
- 完整发布验证:https://github.com/openclaw/openclaw/actions/runs/26617230543
- 性能证据:https://github.com/openclaw/openclaw/actions/runs/26617230578
- 发布发布总览:https://github.com/openclaw/openclaw/actions/runs/26618553779
- 插件 npm 发布:https://github.com/openclaw/openclaw/actions/runs/26618634658(因 @openclaw/diffs-language-pack 首次发布受阻;现有可发布插件在该失败前已完成)
- 插件 ClawHub 发布:https://github.com/openclaw/openclaw/actions/runs/26618636481(因缺少 @openclaw/diffs-language-pack 的 ClawHub 行而受阻)
## 2026.5.28
### Highlights
- Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime state. (#87218, #86875, #87409, #87399, #87375)
- Channel delivery and session identity got safer across outbound plugin hooks, Matrix room ids, iMessage reactions/approvals, Slack final replies, Discord recovered tool warnings, and Microsoft Teams service URL trust checks. (#73706, #75670, #87366, #87451, #87334)
- Mobile and chat surfaces got a broader refresh: the iOS Pro UI, Gateway chat transport, onboarding, Talk permissions, WebChat reconnect delivery, and session picker behavior now preserve more state across reconnects and empty searches. (#87367, #87531, #87682)
- CLI, auth, doctor, and provider paths fail faster and recover more clearly: malformed numeric/version options are rejected, OAuth and local service startup requests are bounded, legacy `api_key` auth profiles migrate to canonical form, and restart guidance is actionable. (#87398, #86281, #87361)
- Plugin and Gateway hot paths do less repeated work while preserving cache correctness for install records, config JSON parsing, tool search catalogs, session stores, manifest model rows, auto-enabled plugin config, browser tokens, and viewer assets. (#86699)
- Release, QA, and E2E validation now bound more log, artifact, harness, and cross-OS waits so failing lanes produce proof instead of hanging or false-greening.
### Changes
- Status: show active subagent details in status output.
- Diffs: split the default language pack and expand default Diffs language coverage while keeping the host floor aligned. (#87370, #87372) Thanks @RomneyDa.
- ClawHub: add plugin display names plus skill verification and trust surfaces. (#87354, #86699) Thanks @thewilloftheshadow and @Patrick-Erichsen.
- iOS: refresh the dev app with Pro Command, Chat, Agents, and Settings tabs wired to gateway sessions, diagnostics, chat, and realtime Talk. (#87367) Thanks @Solvely-Colin.
- Docs: clarify Codex computer-use setup, paste-token stdin auth setup, macOS gateway sleep troubleshooting, native Codex hook relay recovery, container model auth, install deployment cards, device-token admin gating, and backport targets. (#87313, #63050) Thanks @bdjben, @liaoandi, and @thewilloftheshadow.
- PDF/tools: use ClawPDF for PDF extraction and surface MCP structured content in agent tool results. (#87670)
### Fixes
- Agents: fall back to local config pruning when the optional `agents delete` Gateway probe cannot authenticate, so offline installs can still delete agents without removing shared workspaces.
- Tighten phone-control mutation authorization [AI]. (#87150) Thanks @pgondhi987.
- Clarify directive persistence authorization policy [AI]. (#86369) Thanks @pgondhi987.
- Agents/Codex: keep spawned agent cwd/workspace state separated, keep hook context prompt-local, release session locks on timeout abort, avoid session event queue self-wait, preserve shared app-server state across startup or helper failures, keep native hook relay alive across restarts, route workspace memory through tools, resolve Codex runtime models first, report quarantined dynamic tools, format `skills` command output, and bound compaction/steering retries. (#87218, #86875, #86123, #87399, #87375, #87383, #87400) Thanks @mbelinky, @Alix-007, @luoyanglang, @yetval, and @sjf.
- Channels: thread canonical session keys into outbound hooks, preserve Matrix room-id case, keep fallback tool warnings mention-inert, retain delivered Slack final replies during late cleanup, continue iMessage polling after denied reactions, suppress duplicate native exec approvals, preserve Telegram SecretRef prompt config, suppress Discord recovered tool warnings, and block untrusted Teams service URLs. (#73706, #75670, #87366, #87451, #87334) Thanks @zeroaltitude, @lukeboyett, @xiaotian, and @eleqtrizit.
- CLI/auth/doctor/providers: reject malformed numeric/timeout/subcommand-version inputs, wait for respawn child shutdown, bound Codex and GitHub Copilot OAuth/token requests, warm provider auth off the main thread, honor Codex response timeouts, bound local service startup, resolve GPT-5.5 without cached catalog, migrate legacy memory auto-provider config, rewrite non-canonical `api_key` auth profiles, and make doctor restart follow-ups actionable. (#87398, #86281, #87361) Thanks @Patrick-Erichsen, @samzong, @giodl73-repo, and @alkor2000.
- Gateway/security/session state: expire browser tokens after auth rotation, scope assistant idempotency dedupe, drain probe client closes, avoid stale restart continuation reuse, preserve retry-after fallbacks, bound webchat image and artifact transcript scans, include seconds in inbound metadata timestamps, and evict current plugin-state namespaces at row caps.
- Config/parsing/network: reject partial numeric parsing, parse provider/Discord retry headers and dates strictly, honor IPv6 and bare IPv6 `no_proxy` entries, canonicalize secret target array indexes, and reject malformed media content lengths, inspected TCP ports, marketplace content lengths, cron epochs, and sandbox stat fields.
- Providers/agents: preserve seeded Anthropic signatures, concatenate signature-delta chunks, preserve DeepSeek `reasoning_content` replay across tier suffixes, apply OpenRouter strict9 ids to Mistral routes, promote Ollama plain-text tool calls, and recover empty preflight compaction. (#87593)
- File transfer: handle late tar stdin pipe errors after archive validation or unpacking has already settled.
- Performance: trust install-record caches between reloads, prefer native JSON parsing, reuse unchanged tool-search catalogs, skip unchanged store serialization, add precomputed session patch writers, reduce store clone allocations, cache manifest model catalog rows and auto-enabled plugin config, and slim current metadata identity caches.
- Docker/release/QA: package runtime workspace templates, stream cross-OS served artifacts, preserve sparse Crabbox run artifacts, bound OpenClaw instance logs, plugin gauntlet relay logs, MCP channel buffers, kitchen-sink scans, agent-turn assertions, and release scenario logs, and keep release/google live guards current.
### Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.5.28-beta.1
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.5.28-beta.1.tgz
- integrity: sha512-xMvO9tcAzIlzJsJhR3E8iAWk21bIC9E/94Dy3PQgul7fpowTM2VXp3zpAQUoY/hxJ9oJRK6PyeNfwVtIvYK2bw==
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/26619000832
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/26617230525
- full release validation: https://github.com/openclaw/openclaw/actions/runs/26617230543
- performance evidence: https://github.com/openclaw/openclaw/actions/runs/26617230578
- release publish umbrella: https://github.com/openclaw/openclaw/actions/runs/26618553779
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/26618634658 (blocked on first publish of @openclaw/diffs-language-pack; existing publishable plugins completed before that failure)
- plugin ClawHub publish: https://github.com/openclaw/openclaw/actions/runs/26618636481 (blocked on missing ClawHub row for @openclaw/diffs-language-pack)