## 2026.6.5
### 重点
- QQBot 现在会在原生投递前剥离模型推理/思考脚手架,防止原始 `<thinking>` 内容泄露到频道回复中。(#89913, #90132) 感谢 @openperf。
- MCP 工具结果现在会在物化边界强制转换 `resource_link`、`resource`、`audio`、格式错误的图像以及未来非文本/图像块,防止工具返回更丰富的 MCP 内容后引发 Anthropic 400 错误和中毒的会话历史。(#90710, #90728) 感谢 @RanSHammer 和 @849261680。
- Anthropic 扩展思考会话在提示缓存过期或网关重启后能够恢复,因为流启动事件会等待 `message_start`,使预生成签名错误触发现有的恢复重试。(#90667, #90697) 感谢 @openperf。
- Parallel 现在是一个捆绑的 `web_search` 提供商,具备 `PARALLEL_API_KEY` 自动发现、受保护的端点处理、缓存安全的会话 ID、引导选择器支持以及文档。(#85158) 感谢 @NormallyGaussian。
- Google Vertex ADC 用户再次获得静态目录行和运行时模型解析,同时单提供商冷却恢复和内存适配器状态检查更加可靠。(#90506, #90609, #90717, #90816) 感谢 @849261680。
- Matrix 可以在提及门控前预检语音笔记,通过 Matrix 关系分页保留线程读取/回复,并为语音和线程流程提供 QA 覆盖。(#78016, #90415)
- 认证和插件安装状态更加持久:认证配置文件现在保存在 SQLite 中,官方 npm 插件安装记录保留其受信任的固定版本,预发布回退完整性检查避免携带过时的完整性信息。(#89102, #88585)
- 代理、工具和提供者循环在 MCP 租约时间戳、提示缓存工具名称、本地工具目录、不可读的动态工具、仅所有者 HTTP 工具以及提供者目录元数据方面更加严格,减少了隐藏的重试和不安全暴露。(#91124, #91233, #90022, #90261)
- macOS 节点模式不再静默地从健康的直接网关会话自动重新连接,减少了意外的配套应用会话变动。(#90668, #90815) 感谢 @vrurg。
- 升级和服务路径更加安全:cron 旧版 JSON 存储在医生预检期间迁移,服务环境占位符不再掩盖状态目录密钥,WhatsApp 启动等待有界,禁用的 WhatsApp 账户在配置重载时拆除。(#90072, #90208, #90277, #90488, #90486, #87951, #87965) 感谢 @MonkeyLeeT、@sallyom、@mcaxtr 和 @MukundaKatta。
### 变更
- 搜索/提供者:添加了 Parallel 捆绑的 web 搜索插件、实时提供者测试、注册合同、引导/文档接线以及受保护的 `api.parallel.ai/v1/search` 支持。(#85158) 感谢 @NormallyGaussian。
- Matrix/频道:添加了语音消息预检和线程感知的读/回复行为,包括 Matrix QA 场景接线和语音消息行为文档。(#78016, #90415)
- 技能/ClawHub:通过解析安装 API 安装由 GitHub 仓库支持的 ClawHub 技能,下载固定的 GitHub 提交,保留安装策略检查,并在成功后报告安装遥测。(#90478) 感谢 @Patrick-Erichsen。
- Google Chat/频道:添加了原生审批卡片操作和点击处理,使 Google Chat 审批使用平台原生卡片而非通用消息流。
- 移动端:Android 提供者/模型屏幕现在更清晰地显示过期、不可用、未解决和注意状态,Android 添加了主题模式选择,iOS 设置和 Talk 选项卡保持诊断、网关行、附件标签、后备复制和不可用的 Talk 控件可访问。(#90752, #91201)
- 记忆:QMD 搜索可以使用新的重新排序开关,记忆适配器状态在检查普通状态时使用已解析的默认模型身份。(#61834)
- 文档/工具:添加了 Parallel 搜索文档,刷新天气技能指南指向 `web_fetch`,澄清旧版 `openai-codex` 认证,记录发布/测试辅助脚本,并为 CI/调试工作收紧更改的测试路由文档。(#90028, #90250) 感谢 @fuller-stack-dev。
- 发布/流程:将发布列车切换为 `YYYY.M.PATCH` 月度补丁编号方式,保持过渡前标签兼容,并在已发布的 beta 版之后将 2026 年 6 月基线固定为 `2026.6.5`。
- 发布元数据:将 OpenClaw、可发布插件清单、生成的 shrinkwrap、应用版本元数据、iOS 发布说明、Matrix 插件变更日志以及生成的发布基线对齐到 `2026.6.5` beta 列车。
- 平台维护:为此发布列车刷新 Android、Swift/macOS、Docker、CodeQL、Buildx、Docker 构建/推送以及 Codex Action 依赖项。(#74980, #81757, #86481, #86483, #90601)
### 修复
- 频道内容边界:QQBot 现在在发送前剥离推理/思考标签,保留最终答案,同时向用户隐藏内部模型叙述。(#89913, #90132) 感谢 @openperf。
- 代理/MCP/提供者:在非文本/图像 MCP 工具结果块到达提供者转换器之前强制转换它们,保留有效图像,并将更丰富的 MCP 内容转换为文本而不是格式错误的图像块。(#90710, #90728) 感谢 @RanSHammer 和 @849261680。
- Anthropic/Codex/ACP/代理恢复:将 Anthropic 流启动事件延迟到 `message_start`,在 Anthropic 重放前剥离过时的压缩思考签名,检测未签名的纯思考停顿,在压缩写入后刷新提示围栏,拒绝空完成交接,保留父级流式关闭覆盖/共享进度注释,将心跳元数据转发到上下文引擎钩子,并覆盖 Codex 会话/线程迁移边缘情况。(#90667, #90697, #90163, #90108, #89874, #89505, #90632, #89302, #90729, #90317, #90319) 感谢 @openperf、@100yenadmin 和 @ooiuuii。
- 代理/Codex/工具:MCP 租约释放不再刷新 `lastUsedAt`,提示缓存工具名称有保护,精简本地工具目录保持紧凑,不可读的动态工具被隔离,孤立工具错误仍然显示,原生子代理完成结果在应用服务器监控下存活,后台会话名称推导避免正则回溯风险。(#91124, #90612, #90022, #91235, #91233)
- 提供者/模型解析:在生成的目录中保留 Google Vertex ADC 认证标记,在冷却后重新探测单提供商主节点,共享 Codex 模型可见性,对未知模型认证关闭失败,保留 Codex 别名可用性,保持未解决的配置文件引用为未知,并避免在列出模型时解析认证。(#90506, #90609, #90717, #90702) 感谢 @849261680。
- 提供者/模型解析:实时提供者模型目录保持辅助覆盖,Ollama 目录元数据得到保留,Google 提供者前缀从 Gemini 路径中剥离,Foundry Responses 推理重放 ID 存活,MiniMax M3 思考保持启用,Vertex 多区域调用使用正确的区域主机,OpenRouter 流式生成成本得到核对。(#91125)
- 网关/macOS/移动端:通过身份避免重复的网关探测警告,限制节点配对请求速率同时保留已配对节点的重新连接,保持 macOS 节点模式在健康的直接网关会话上,保持 iOS 诊断和网关行可访问,并避免 Android 构建期间出现 Linux ARM Gradle 资源任务。(#85791, #90147, #90668, #90815) 感谢 @giodl73-repo 和 @vrurg。
- 网关/安全/配置:仅所有者 HTTP 工具被门控,沙盒技能在可写沙盒中仍可读取,旧版代理注册表和 Codex 模型元数据安全迁移,卡住的 MCP 响应体会超时而不是占用网关工作线程。(#90261)
- 插件/网关:来自已发布 JavaScript 插件的旧版扁平 Control UI 描述符现在将 `name` 和缺失的表面字段规范化为会话描述符,为基于包的插件验证恢复 Kitchen Sink RPC 描述符证明。
- TUI/聊天/Workboard/自动回复:乐观用户消息在过时历史重载、runId 重新分配和中止窗口中保持稳定,不会消失、跳跃或作为幽灵行残留;Workboard 过时生命周期批量更新不再覆盖较新的状态/来源;消息工具发送现在算作投递。(#86205, #89600, #88592, #90123) 感谢 @RomneyDa。
- Cron/更新/服务环境:医生配置预检现在在运行时读取之前将旧版 cron JSON 存储迁移到 SQLite,隔离的代理回合负载消息保留超时上下文,服务环境规划跳过会掩盖状态目录 `.env` 值的未解析占位符,会话转录重写保持注册表标记/判别符一致。(#90072, #90208, #91230, #90277, #90488) 感谢 @MonkeyLeeT 和 @sallyom。
- 状态/存储:Matrix 同步和加密侧车、记忆维基导入/源同步状态、沙盒注册表状态、ACPX 进程状态、设备配对通知状态、Zalo 托管媒体以及插件 SDK 去重状态现在使用 SQLite 拥有的存储而不是临时运行时文件。(#91100, #91108, #91056)
- 安全/配置/工具:保护 MCP HTTP 重定向,保护全局代理配置默认值,并保持发布/测试/工具证明失败有界且明确。(#89732, #90145)
- 频道:WhatsApp 在每个账户配置更改时重启,限制后台启动等待,关闭失败的套接字,并保留重新连接行为;Mattermost 斜杠命令将其状态保留在 `globalThis` 上;飞书流式卡片保留完整的合并内容;iMessage 私有 API 失败和发送超时会自行解释,同时拆分发送合并尊重气球元数据;语音呼叫在连接后跟踪 Twilio 流;ClickClack 回复工具尊重 `toolsAllow`;Discord 运行时适配器保持可解析;出站投递重试在预算延期后存活。(#87951, #87965, #90486, #68113, #90534, #90181, #90607, #89500, #91041, #90858, #91119, #91241) 感谢 @MukundaKatta、@mcaxtr、@infoanton、@mushuiyu886 和 @sahibzada-allahyar。
- 发布/CI/E2E:主要 CI 守卫漂移、PR 合并差异范围、实时 Docker 凭证暂存、基础镜像限定、安装程序 Docker 分类、Playwright 依赖安装恢复、Codex 实时 Docker 通道的 API 密钥认证、Parallels 选项终止符以及 JSON 模式进度处理更加严格,使发布证明失败更清晰。(#90532, #90287, #90058) 感谢 @RomneyDa、@hxy91819 和 @mrunalp。
- 发布/CI/E2E:已安装包根目录 dist 验证现在允许当前包的 JavaScript 文件数量,同时保持依赖项、每个文件大小和扫描边界检查处于活动状态。
- 发布/CI/E2E:Chutes OAuth 模型发现证明现在接受标准 `Headers` 请求,QR 包安装烟雾将 Docker CPU 请求上限限制到托管运行器容量,使 beta 验证在真实包回归上失败。
- 发布/CI/E2E:Matrix 和 Slack 发布验证夹具现在植入 SQLite 支持的会话元数据,使频道证明与当前会话存储对齐。
- 发布/CI/E2E:Matrix exec 审批和 WhatsApp 组激活发布夹具现在植入 SQLite 支持的会话元数据,QA Lab 功能翻转证明仅在恢复的图像媒体证明落地后容忍重启中止的等待。
- 发布/CI/E2E:Discord 原生 `/think` 自动完成发布夹具现在植入 SQLite 支持的会话覆盖,使特定于提供者的推理选择与当前会话存储对齐。
- 发布/CI/E2E:Telegram 原生审批发布夹具现在植入 SQLite 支持的会话来源元数据,使插件审批路由与当前会话存储对齐。
- 发布/CI/E2E:Memory Core 梦境发布夹具现在植入 SQLite 支持的会话元数据,使过时梦境清理和会话摄取证明与当前会话存储对齐。
- 发布/CI/E2E:Docker E2E 和实时 Docker 测试现在应用默认内存、CPU 和进程上限,同时保留每通道显式覆盖。
- 发布/CI/E2E:Docker E2E CPU 限制现在上限到运行器容量,使托管 8-vCPU 运行器上的包 Telegram 验收测试专注于包回归而非不可能的 Docker 资源请求。
- 发布/CI/E2E:任务维护发布检查现在在隔离的临时状态目录周围重置固定配置和一次性会话迁移状态,使普通 CI 专注于活动会话存储夹具而非过时进程快照。
- 发布/CI/E2E:插件生命周期矩阵资源采样现在使超过 RSS、挂钟时间或 CPU 上限的阶段失败,而不仅仅是记录测量值。
- 发布/CI/E2E:Codex npm 插件实时断言现在上限转录发现和诊断日志读取,使失败证明保持有界。
- 发布/CI/E2E:浏览器快照、发布场景、发布用户旅程、Telegram 桌面/RTT/包、web 搜索、Parallels 更新、插件更新、医生切换和升级幸存者诊断现在流式或限制日志/工件读取,使失败的证明在无界输出下仍可检查。
- 测试/状态隔离:QA Lab 有效工具调用指标现在在运行时奇偶数据可用时需要运行时工具调用证据,而不是仅计算基于工具的场景通过状态。
- 测试/状态隔离:QA Lab 运行时奇偶现在使仅有计划的工具调用行在没有匹配工具结果时失败,而不是将匹配的模拟计划视为真实工具证据。
- 测试/状态隔离:QA Lab 运行时奇偶现在将匹配的受控工具错误视为等效,并在模拟调试行缺少异步图像生成开始时回退到转录工具结果。
- 测试/状态隔离:QA 套件现在在跳过摘要、缺少运行时工具证明、仅有计划的行、宽松的发布限制、缺少实时/提供者工件、失败的代理回复标记以及包 Telegram 摘要失败时关闭失败。
- 测试/状态隔离:提供者、媒体、认证、cron、任务、会话、沙盒、网关和 Codex 超时夹具现在每个测试限定更多 home/state/env 数据,减少跨测试泄漏,使发布验证失败更少噪音。(#90027, #89974)
### 发布验证
- npm 包:`
[email protected]` 位于 dist-tag `beta`。
- npm tarball:https://registry.npmjs.org/openclaw/-/openclaw-2026.6.5-beta.3.tgz
- npm 完整性:`sha512-OUmv5kb3nEa9DZsnF4dVhwKlSApzr7KNgN+PCO7U5pbEQBlemAyLEgZDruiKmmoS6wlPjq73+PdD9i9c5zihOA==`
- npm 预检:https://github.com/openclaw/openclaw/actions/runs/27165128882
- Docker 发布:https://github.com/openclaw/openclaw/actions/runs/27165128944
- 完整发布验证:https://github.com/openclaw/openclaw/actions/runs/27165128963
- 插件 npm 发布:https://github.com/openclaw/openclaw/actions/runs/27167497019
- 插件 ClawHub 发布:https://github.com/openclaw/openclaw/actions/runs/27168216099
- OpenClaw npm 发布:https://github.com/openclaw/openclaw/actions/runs/27167084540
- 发布发布包装器恢复:https://github.com/openclaw/openclaw/actions/runs/27167309611 在其重新运行命中已发布的 npm 守卫后被取消;发布证明由上述成功的 beta.3 发布运行完成。
- 发布后验证:通过,包含 OpenClaw npm、插件 npm 和 ClawHub;证据资产附加到此发布。
## 2026.6.5
### Highlights
- QQBot now strips model reasoning/thinking scaffolding before native delivery, preventing raw `<thinking>` content from leaking into channel replies. (#89913, #90132) Thanks @openperf.
- MCP tool results now coerce `resource_link`, `resource`, `audio`, malformed image, and future non-text/image blocks at the materialize boundary, preventing Anthropic 400s and poisoned session history after a tool returns richer MCP content. (#90710, #90728) Thanks @RanSHammer and @849261680.
- Anthropic extended-thinking sessions recover after prompt-cache expiry or Gateway restart because stream start events wait for `message_start`, letting pre-generation signature errors trigger the existing recovery retry. (#90667, #90697) Thanks @openperf.
- Parallel is now a bundled `web_search` provider with `PARALLEL_API_KEY` discovery, guarded endpoint handling, cache-safe session ids, onboarding picker support, and docs. (#85158) Thanks @NormallyGaussian.
- Google Vertex ADC users get static catalog rows and runtime model resolution again, while single-provider cooldown recovery and memory adapter status checks are more reliable. (#90506, #90609, #90717, #90816) Thanks @849261680.
- Matrix can preflight voice notes before mention gating, preserve thread reads/replies through Matrix relations pagination, and carry QA coverage for voice and thread flows. (#78016, #90415)
- Auth and plugin install state is more durable: auth profiles now live in SQLite, official npm plugin install records keep their trusted pins, and prerelease fallback integrity checks avoid carrying stale integrity forward. (#89102, #88585)
- Agent, tool, and provider loops are stricter around MCP lease timestamps, prompt-cache tool names, local tool catalogs, unreadable dynamic tools, owner-only HTTP tools, and provider catalog metadata, reducing hidden retries and unsafe exposure. (#91124, #91233, #90022, #90261)
- macOS node mode no longer silently self-reconnects away from a healthy direct Gateway session, reducing unexpected companion app session churn. (#90668, #90815) Thanks @vrurg.
- Upgrade and service paths are safer: cron legacy JSON stores migrate during doctor preflight, service env placeholders no longer mask state-dir secrets, WhatsApp startup waits are bounded, and disabled WhatsApp accounts tear down on config reload. (#90072, #90208, #90277, #90488, #90486, #87951, #87965) Thanks @MonkeyLeeT, @sallyom, @mcaxtr, and @MukundaKatta.
### Changes
- Search/providers: add the Parallel bundled web-search plugin, live provider tests, registration contracts, onboarding/docs wiring, and guarded `api.parallel.ai/v1/search` support. (#85158) Thanks @NormallyGaussian.
- Matrix/channels: add voice-message preflight and thread-aware read/reply behavior, including Matrix QA scenario wiring and docs for voice-message behavior. (#78016, #90415)
- Skills/ClawHub: install ClawHub skills backed by GitHub repositories through the resolved install API, download the pinned GitHub commit, keep install-policy checks, and report install telemetry after success. (#90478) Thanks @Patrick-Erichsen.
- Google Chat/channels: add native approval card actions and click handling so Google Chat approvals use platform-native cards instead of generic message flow.
- Mobile: Android provider/model screens now surface expiring, unavailable, unresolved, and attention states more clearly, Android adds theme mode selection, and iOS settings and Talk tabs keep diagnostics, gateway rows, attachment labels, fallback copy, and unavailable Talk controls reachable. (#90752, #91201)
- Memory: QMD search can use the new rerank toggle, and memory adapter status uses the resolved default model identity when checking plain status. (#61834)
- Docs/tooling: add Parallel search docs, refresh weather-skill guidance toward `web_fetch`, clarify legacy `openai-codex` auth, document release/test helper scripts, and tighten changed-test routing docs for CI/debugging work. (#90028, #90250) Thanks @fuller-stack-dev.
- Release/process: switch release trains to `YYYY.M.PATCH` monthly patch numbering, keep pre-transition tags compatible, and pin the June 2026 floor at `2026.6.5` after the published beta.
- Release metadata: align OpenClaw, publishable plugin manifests, generated shrinkwraps, app version metadata, iOS release notes, Matrix plugin changelog, and generated release baselines with the `2026.6.5` beta train.
- Platform maintenance: refresh Android, Swift/macOS, Docker, CodeQL, Buildx, Docker build/push, and Codex Action dependencies for this release train. (#74980, #81757, #86481, #86483, #90601)
### Fixes
- Channel content boundaries: QQBot now strips reasoning/thinking tags before sending, preserving final answers while hiding internal model narration from users. (#89913, #90132) Thanks @openperf.
- Agents/MCP/providers: coerce non-text/image MCP tool-result blocks before they reach provider converters, preserving valid images and turning richer MCP content into text instead of malformed image blocks. (#90710, #90728) Thanks @RanSHammer and @849261680.
- Anthropic/Codex/ACP/agent recovery: defer Anthropic stream start events until `message_start`, strip stale compaction thinking signatures before Anthropic replay, detect unsigned thinking-only stalls, refresh prompt fences after compaction writes, reject empty completion handoffs, preserve parent streaming-off overrides/shared progress commentary, forward heartbeat metadata to context-engine hooks, and cover Codex session/thread migration edge cases. (#90667, #90697, #90163, #90108, #89874, #89505, #90632, #89302, #90729, #90317, #90319) Thanks @openperf, @100yenadmin, and @ooiuuii.
- Agents/Codex/tools: MCP lease release no longer refreshes `lastUsedAt`, prompt-cache tool names are guarded, lean local tool catalogs stay compact, unreadable dynamic tools are quarantined, orphan tool errors still surface, native subagent completion results survive app-server monitoring, and background-session name derivation avoids regex backtracking risk. (#91124, #90612, #90022, #91235, #91233)
- Provider/model resolution: preserve Google Vertex ADC auth markers in generated catalogs, re-probe a single-provider primary after cooldown, share Codex model visibility, fail closed for unknown model auth, preserve Codex alias availability, keep unresolved profile refs unknown, and avoid resolving auth while listing models. (#90506, #90609, #90717, #90702) Thanks @849261680.
- Provider/model resolution: live provider model catalogs keep helper coverage, Ollama catalog metadata is preserved, Google provider prefixes are stripped from Gemini paths, Foundry Responses reasoning replay ids survive, MiniMax M3 thinking stays enabled, Vertex multi-region calls use the right regional host, and OpenRouter streamed generation cost is reconciled. (#91125)
- Gateway/macOS/mobile: avoid duplicate Gateway probe warnings by identity, rate-limit node pairing requests while preserving paired-node reconnects, keep macOS node mode on a healthy direct Gateway session, keep iOS diagnostics and gateway rows reachable, and avoid Linux ARM Gradle resource tasks during Android builds. (#85791, #90147, #90668, #90815) Thanks @giodl73-repo and @vrurg.
- Gateway/security/config: owner-only HTTP tools are gated, sandbox skills remain readable in writable sandboxes, legacy agent registry and Codex model metadata migrate safely, and stalled MCP response bodies time out instead of tying up Gateway workers. (#90261)
- Plugins/Gateway: legacy flat Control UI descriptors from shipped JavaScript plugins now normalize `name` and missing surface fields into session descriptors, restoring Kitchen Sink RPC descriptor proof for package-backed plugin validation.
- TUI/chat/Workboard/auto-reply: optimistic user messages stay stable across stale history reloads, runId reassignment, and abort windows instead of disappearing, jumping, or lingering as ghost rows; Workboard stale lifecycle bulk updates no longer overwrite newer status/provenance; message-tool sends now count as delivery. (#86205, #89600, #88592, #90123) Thanks @RomneyDa.
- Cron/update/service env: doctor config preflight now migrates legacy cron JSON stores into SQLite before runtime reads, isolated agent turn payload messages preserve timeout context, service env planning skips unresolved placeholders that would mask state-dir `.env` values, and session transcript rewrites keep registry markers/discriminants consistent. (#90072, #90208, #91230, #90277, #90488) Thanks @MonkeyLeeT and @sallyom.
- State/storage: Matrix sync and crypto sidecars, memory-wiki import/source-sync state, sandbox registry state, ACPX process state, device-pair notify state, Zalo hosted media, and plugin SDK dedupe state now use SQLite-owned storage instead of ad hoc runtime files. (#91100, #91108, #91056)
- Security/config/tooling: guard MCP HTTP redirects, protect global agent config defaults, and keep release/test/tooling proof failures bounded and explicit. (#89732, #90145)
- Channels: WhatsApp restarts when per-account config changes, bounds background startup waits, closes failed sockets, and preserves reconnect behavior; Mattermost slash commands keep their state on `globalThis`; Feishu streaming cards preserve full merged content; iMessage private-API failures and send timeouts explain themselves while split-send coalescing honors balloon metadata; voice-call tracks Twilio streams after connect; ClickClack reply tools respect `toolsAllow`; Discord runtime adapters stay resolvable; and outbound delivery retries survive budget deferrals. (#87951, #87965, #90486, #68113, #90534, #90181, #90607, #89500, #91041, #90858, #91119, #91241) Thanks @MukundaKatta, @mcaxtr, @infoanton, @mushuiyu886, and @sahibzada-allahyar.
- Release/CI/E2E: main CI guard drift, PR merge diff scoping, live Docker credential staging, base-image qualification, installer Docker classification, Playwright dependency install recovery, API-key auth for Codex live Docker lanes, Parallels option terminators, and JSON-mode progress handling are tighter so release proof fails cleaner. (#90532, #90287, #90058) Thanks @RomneyDa, @hxy91819, and @mrunalp.
- Release/CI/E2E: installed-package root dist verification now allows the current package's JavaScript file count while keeping dependency, per-file-size, and scan-bound checks active.
- Release/CI/E2E: Chutes OAuth model-discovery proof now accepts standard `Headers` requests, and QR package install smoke caps Docker CPU requests to the hosted runner capacity so beta validation fails on real package regressions.
- Release/CI/E2E: Matrix and Slack release validation fixtures now seed SQLite-backed session metadata, keeping channel proof aligned with the current session store.
- Release/CI/E2E: Matrix exec approval and WhatsApp group activation release fixtures now seed SQLite-backed session metadata, and QA Lab capability-flip proof tolerates restart-aborted waits only after restored image media proof lands.
- Release/CI/E2E: Discord native `/think` autocomplete release fixtures now seed SQLite-backed session overrides, keeping provider-specific reasoning choices aligned with the current session store.
- Release/CI/E2E: Telegram native approval release fixtures now seed SQLite-backed session origin metadata, keeping plugin approval routing aligned with the current session store.
- Release/CI/E2E: Memory Core dreaming release fixtures now seed SQLite-backed session metadata, keeping stale dreaming cleanup and session ingestion proof aligned with the current session store.
- Release/CI/E2E: Docker E2E and live Docker harness runs now apply default memory, CPU, and process ceilings while preserving explicit per-lane overrides.
- Release/CI/E2E: Docker E2E CPU limits now cap to the runner capacity, keeping package Telegram acceptance on hosted 8-vCPU runners focused on package regressions instead of impossible Docker resource requests.
- Release/CI/E2E: task maintenance release checks now reset pinned config and one-time session migration state around isolated temp state dirs, keeping normal CI focused on the active session-store fixture instead of stale process snapshots.
- Release/CI/E2E: plugin lifecycle matrix resource sampling now fails phases that exceed RSS, wall-clock, or CPU ceilings instead of only logging the measurements.
- Release/CI/E2E: Codex npm plugin live assertions now cap transcript discovery and diagnostic log reads so failure proof stays bounded.
- Release/CI/E2E: browser snapshot, release-scenario, release-user-journey, Telegram desktop/RTT/package, web-search, Parallels update, plugin update, doctor switch, and upgrade-survivor diagnostics now stream or bound log/artifact reads so failed proof stays inspectable without unbounded output.
- Tests/state isolation: QA Lab valid-tool-call metrics now require runtime tool-call evidence when runtime parity data is available instead of counting tool-backed scenario pass status alone.
- Tests/state isolation: QA Lab runtime parity now fails planned-only tool-call rows without matching tool results instead of treating matching mock plans as real tool evidence.
- Tests/state isolation: QA Lab runtime parity now treats matching controlled tool errors as equivalent and falls back to transcript tool results when mock debug rows miss async image-generation starts.
- Tests/state isolation: QA suites now fail closed on skipped summaries, missing runtime tool proof, planned-only rows, loose release limits, missing live/provider artifacts, failed agent reply markers, and package Telegram summary failures.
- Tests/state isolation: provider, media, auth, cron, task, session, sandbox, Gateway, and Codex timeout fixtures now scope more home/state/env data per test, reducing cross-test leakage and making release validation failures less noisy. (#90027, #89974)
### Release verification
- npm package: `
[email protected]` on dist-tag `beta`.
- npm tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.6.5-beta.3.tgz
- npm integrity: `sha512-OUmv5kb3nEa9DZsnF4dVhwKlSApzr7KNgN+PCO7U5pbEQBlemAyLEgZDruiKmmoS6wlPjq73+PdD9i9c5zihOA==`
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/27165128882
- Docker release: https://github.com/openclaw/openclaw/actions/runs/27165128944
- full release validation: https://github.com/openclaw/openclaw/actions/runs/27165128963
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/27167497019
- plugin ClawHub publish: https://github.com/openclaw/openclaw/actions/runs/27168216099
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/27167084540
- release publish wrapper recovery: https://github.com/openclaw/openclaw/actions/runs/27167309611 was cancelled after its rerun hit the already-published npm guard; release proof was completed from the successful beta.3 publish runs above.
- postpublish verification: passed with OpenClaw npm, plugin npm, and ClawHub included; evidence assets are attached to this release.