### 重点
- 安全边界在以下方面大幅收紧:转录、沙箱绑定、主机环境继承、MCP stdio、Codex HTTP访问、原生搜索策略、发件人检查升级、已删除代理的ACP绕过、回环工具、Discord审核以及Teams群组操作;执行审批现在超时时默认失败。(#91529, #91618, #91615, #91619, #91741, #91745, #91746, #91748, #91749, #91750, #91751, #91752, #91763, #89938) 感谢 @joshavant, @pgondhi987, @mmaps, @eleqtrizit, @shakkernerd 和 @drobison00。
- Telegram消息投递更安全且更连贯:按账户划分的话题会路由到正确的代理,流式文本在工具调用后仍能存活,`/compact` 在通用入口上生效,回调处理使用具体API,草稿分片逻辑共享,持久化去重移入SDK,未授权的私信文本不会进入缓存和提示上下文。(#91189, #88682, #89588, #90212, #91876, #91874, #91904, #91478, #91915) 感谢 @codysai001, @alexzhu0, @joelnishanth, @snowzlm, @obviyus 和 @sallyom。
- iMessage恢复和投递现在涵盖:始终在线的入站重启、持久化的回显标记、阻塞流式传输、空闲审批发现、强化的出站传输以及可操作的入站启动诊断。(#91335, #91449, #88969, #88530, #91783, #91785) 感谢 @omarshahine, @jmissig 和 @colmbrogan。
- 浏览器和MCP连接获得了:已有会话的CDP支持、WebSocket验证发现、默认配置文件的 `cdpUrl` 处理、更安全的浏览器输出边界、Streamable HTTP回环传输、纠正的OAuth/SSE授权处理以及更广泛的模式兼容性。(#91422, #89851, #91736, #91747, #91451, #80143) 感谢 @pgondhi987, @anagnorisis2peripeteia, @lifuyue, @eleqtrizit, @LiuwqGit 和 @HemantSudarshan。
- 控制UI启动和首次回复延迟降低,通过:缓存的模型元数据、移除启动时的目录等待、延迟斜杠命令加载、首次事件追踪以及慢回复诊断。(#91531, #91538, #91568, #91583, #91598)
- 提供商支持扩展:OpenRouter OAuth onboarding、Claude Fable 5自适应思考;同时Codex会话保持正确的压缩所有权、本地模型跳过守卫审查、动态工具进度正常清理、Gemma 4推理回放保留。(#91830, #91882, #91590, #88630, #88768, #91696) 感谢 @Patrick-Erichsen, @joshavant, @bdjben 和 @Coder-Wangyankun。
### 变更
- CLI进度:发出Claude CLI评论进度事件,并将工具间评论桥接到频道进度中,而不暴露内部协议脚手架。(#89834, #90883) 感谢 @anagnorisis2peripeteia。
- 可观测性:允许受信任的诊断频道捕获工具输入/输出内容,添加首次助手事件追踪,并在首次回复缓慢时发出警告。(#91256, #91568, #91583) 感谢 @amknight。
- 插件/ClawHub:自用可复用包发布,允许试运行跳过发布审批,允许声明已安装的受信任钩子,报告托管插件版本漂移,并在废弃的Skill Workshop配置上改为警告而非失败。(#91574, #91591, #90004, #90927, #90838) 感谢 @Patrick-Erichsen, @brokemac79 和 @lonexreb。
- 内存/提供商:将本地llama.cpp运行时移动到其提供商插件中,跨文件批量处理嵌入,持久化代理模型目录缓存,并保持QMD JSON搜索为一次性查询,同时过滤过时的REM召回预览。(#91324, #89138, #90457, #91837, #91851) 感谢 @osolmaz, @mushuiyu886, @ai-hpc 和 @TurboTheTurtle。
- 频道/移动端:添加QQBot群组提及开关,改进iPad和iPhone控制界面,并在TUI底部栏显示活动连接主机。(#91423, #91557, #89909) 感谢 @cxyhhhhh, @Solvely-Colin 和 @baskduf。
- 性能:预加载TUI运行时插件,去重插件自动启用的扇出,停止 `/models` 派生注册表的重新扫描风暴,修剪密集的文本delta快照,并复用预准备的启动模型元数据。(#90782, #89978, #92127, #91580, #91531) 感谢 @RomneyDa, @obuchowski 和 @ai-hpc。
### 修复
- 代理/会话恢复:在会话重新绑定后丢弃过时的审批后续任务,按身份移除已排干的回复队列项,恢复过时的主回复和可见回复,保留Codex上下文引擎的压缩所有权,通过SDK会话投影思考目录兼容性,在短速率限制窗口内重试同模型助手调用,将默认压缩超时降低至180秒同时尊重显式配置,并保持提供商失败时的终端生命周期状态正确。(#85679, #91450, #91566, #91840, #91590, #91911, #91361, #91895) 感谢 @openperf, @yetval, @joshavant, @lanzhi-lee, @wangmiao0668000666 和 @TurboTheTurtle。
- 用户可见内容边界:抑制Codex/Harmony协议工件,中和浏览器和LanceDB内存媒体指令,编辑转录图像,并通过源抑制保留原生 `/compact` 回复。(#89151, #91422, #91425, #91529, #90212) 感谢 @joelnishanth, @pgondhi987, @joshavant 和 @snowzlm。
- 频道投递:在重启后保持WhatsApp捕获的回复附加到后续控制器,重试飞书速率限制,保留Mattermost线程回复,规范LINE webhook路径,恢复Discord回复注入和运行时超时导出,并显示OpenAI Realtime WebRTC助手转录。(#85823, #89659, #91684, #91649, #90263, #91686, #90426) 感谢 @itsuzef, @ladygege, @jacobtomlinson, @fuller-stack-dev 和 @shushushv。
- Cron:干净地取消正在运行的任务运行,保留终端超时/取消状态,并恢复未投递的工具警告而非静默丢失结果。(#90666, #90678) 感谢 @ai-hpc。
- 网关/配置/认证:共享审批运行时套接字令牌,在 `config.patch` 中显式替换数组,防止索引的 `replacePaths` 同意扩展到整个数组,拒绝格式错误的网关RPC超时输入,仅对有效的ACP harness会话跳过已删除代理守卫,显示无头LaunchAgent状态,在清理前验证SQLite认证迁移,并执行QMD启动维护。(#87105, #91551, #91966, #54646, #40953, #91219, #91614, #91740, #91978) 感谢 @fuller-stack-dev, @yetval, @ruanrrn, @comeran 和 @scotthuang。
- 提供商/Codex:澄清配额错误,恢复Codex合成用量行,规范Codex协议资产,要求实时语音使用API密钥认证,规范ACP模型引用,保留Gemma 4的 `reasoning_content`,在SDK会话中遵循Ollama提供商声明的思考默认值,并避免对本地模型进行守卫审查。(#91390, #91709, #91507, #91567, #88630, #91657, #91696) 感谢 @hxy91819, @brokemac79, @RomneyDa, @joshavant, @openperf 和 @Coder-Wangyankun。
- 更新/构建:在刷新失败后恢复包网关重启,暴露插件收敛修复,在无PATH的pnpm环境中回退到Corepack,植入正确的Docker store包,保持ClawHub试运行和发布路径可复用,并在OpenClaw npm、依赖证据、发布后验证以及必需插件发布通过之前,保持beta GitHub发布页面为草稿状态。(#91581, #91599, #91547, #91591) 感谢 @fuller-stack-dev, @sallyom 和 @Patrick-Erichsen。
- UI:在打开聊天会话前要求明确的用户意图,并在会话切换后排空已恢复的聊天队列。(#91480) 感谢 @TurboTheTurtle。
- Android:对持久节点避免使用 `dataSync` 前台服务类型。(#80082) 感谢 @davelutztx。
- 原生钩子:绑定中继生命周期,使废弃的原生钩子连接不会无限期残留。(#91550) 感谢 @joshavant。
### 发布验证
- npm包:https://www.npmjs.com/package/openclaw/v/2026.6.6-beta.2
- registry压缩包:https://registry.npmjs.org/openclaw/-/openclaw-2026.6.6-beta.2.tgz
- 完整性校验:`sha512-617ITjTL0UxtQK4qGOc248nQBJjExX43/RR7CBr+0rEpqnA88i/VWABfTPrUnNT25181uZkOyzgguZjMW0u4Ug==`
- 发布SHA:`3129eed4de92d0ddc0209fbf195c790c3d73ab03`
- 完整发布CI报告:https://github.com/openclaw/releases/blob/main/evidence/2026.6.6-beta.2/release-evidence.md
- 发布发布:https://github.com/openclaw/openclaw/actions/runs/27392222148
- npm预检:https://github.com/openclaw/openclaw/actions/runs/27390602410
- 完整发布验证:https://github.com/openclaw/openclaw/actions/runs/27390601362
- 插件npm发布:https://github.com/openclaw/openclaw/actions/runs/27392305214
- 插件ClawHub发布:单独分发,不等待此证明:https://github.com/openclaw/openclaw/actions/runs/27392308021
- OpenClaw npm发布:https://github.com/openclaw/openclaw/actions/runs/27392531757
- npm Telegram beta E2E:https://github.com/openclaw/openclaw/actions/runs/27392727108
### Highlights
- Security boundaries are substantially tighter across transcripts, sandbox binds, host environment inheritance, MCP stdio, Codex HTTP access, native search policy, elevated sender checks, deleted-agent ACP bypasses, loopback tools, Discord moderation, and Teams group actions; exec approvals now fail closed on timeout. (#91529, #91618, #91615, #91619, #91741, #91745, #91746, #91748, #91749, #91750, #91751, #91752, #91763, #89938) Thanks @joshavant, @pgondhi987, @mmaps, @eleqtrizit, @shakkernerd, and @drobison00.
- Telegram delivery is safer and more coherent: account-scoped topics route to the right agent, streamed text survives tool calls, `/compact` works on generic ingress, callback handling uses concrete APIs, draft chunking is shared, durable dispatch dedupe moved into the SDK, and unauthorized DM text stays out of cache and prompt context. (#91189, #88682, #89588, #90212, #91876, #91874, #91904, #91478, #91915) Thanks @codysai001, @alexzhu0, @joelnishanth, @snowzlm, @obviyus, and @sallyom.
- iMessage recovery and delivery now cover always-on inbound restart, durable echo markers, block streaming, idle approval discovery, hardened outbound transport, and actionable inbound startup diagnostics. (#91335, #91449, #88969, #88530, #91783, #91785) Thanks @omarshahine, @jmissig, and @colmbrogan.
- Browser and MCP connectivity gained existing-session CDP support, discovered WebSocket validation, default-profile `cdpUrl` handling, safer browser-output boundaries, Streamable HTTP loopback transport, corrected OAuth/SSE authorization handling, and broader schema compatibility. (#91422, #89851, #91736, #91747, #91451, #80143) Thanks @pgondhi987, @anagnorisis2peripeteia, @lifuyue, @eleqtrizit, @LiuwqGit, and @HemantSudarshan.
- Control UI startup and first-reply latency are lower through cached model metadata, removal of the startup catalog wait, lazy slash-command loading, and first-event tracing with slow-reply diagnostics. (#91531, #91538, #91568, #91583, #91598)
- Provider support expands with OpenRouter OAuth onboarding and Claude Fable 5 adaptive thinking, while Codex sessions keep correct compaction ownership, local models skip guardian review, dynamic tool progress normalizes cleanly, and Gemma 4 reasoning replay is preserved. (#91830, #91882, #91590, #88630, #88768, #91696) Thanks @Patrick-Erichsen, @joshavant, @bdjben, and @Coder-Wangyankun.
### Changes
- CLI progress: emit Claude CLI commentary progress events and bridge inter-tool commentary into channel progress without exposing internal protocol scaffolding. (#89834, #90883) Thanks @anagnorisis2peripeteia.
- Observability: allow trusted diagnostics channels to capture tool input/output content, add first-assistant-event traces, and warn on slow initial replies. (#91256, #91568, #91583) Thanks @amknight.
- Plugins/ClawHub: dogfood reusable package publishing, let dry runs skip publish approval, allow declared installed trusted hooks, report managed plugin version drift, and warn instead of failing on retired Skill Workshop configuration. (#91574, #91591, #90004, #90927, #90838) Thanks @Patrick-Erichsen, @brokemac79, and @lonexreb.
- Memory/providers: move the local llama.cpp runtime into its provider plugin, batch embeddings across files, persist the agent model catalog cache, and keep QMD JSON search one-shot while filtering stale REM recall previews. (#91324, #89138, #90457, #91837, #91851) Thanks @osolmaz, @mushuiyu886, @ai-hpc, and @TurboTheTurtle.
- Channels/mobile: add the QQBot group mention toggle, improve iPad and iPhone control surfaces, and expose the active connection host in the TUI footer. (#91423, #91557, #89909) Thanks @cxyhhhhh, @Solvely-Colin, and @baskduf.
- Performance: prewarm TUI runtime plugins, deduplicate plugin auto-enable fanout, stop `/models` derived-registry rescan storms, trim dense text-delta snapshots, and reuse prepared startup model metadata. (#90782, #89978, #92127, #91580, #91531) Thanks @RomneyDa, @obuchowski, and @ai-hpc.
### Fixes
- Agent/session recovery: drop stale approval follow-ups after session rebind, remove drained reply-queue items by identity, recover stale main and visible replies, preserve Codex context-engine compaction ownership, project thinking catalog compatibility through SDK sessions, retry same-model assistant calls across short rate-limit windows, lower the default compaction timeout to 180 seconds while respecting explicit configuration, and keep provider-failure terminal lifecycle state correct. (#85679, #91450, #91566, #91840, #91590, #91911, #91361, #91895) Thanks @openperf, @yetval, @joshavant, @lanzhi-lee, @wangmiao0668000666, and @TurboTheTurtle.
- User-visible content boundaries: suppress Codex/Harmony protocol artifacts, neutralize browser and LanceDB memory media directives, redact transcript images, and preserve native `/compact` replies through source suppression. (#89151, #91422, #91425, #91529, #90212) Thanks @joelnishanth, @pgondhi987, @joshavant, and @snowzlm.
- Channel delivery: keep WhatsApp captured replies attached to the successor controller after restart, retry Feishu rate limits, preserve Mattermost thread replies, canonicalize LINE webhook paths, restore Discord reply hydration and runtime timeout exports, and show OpenAI Realtime WebRTC assistant transcripts. (#85823, #89659, #91684, #91649, #90263, #91686, #90426) Thanks @itsuzef, @ladygege, @jacobtomlinson, @fuller-stack-dev, and @shushushv.
- Cron: cancel active task runs cleanly, preserve terminal timeout/cancel state, and recover no-deliver tool warnings instead of silently losing the outcome. (#90666, #90678) Thanks @ai-hpc.
- Gateway/config/auth: share the approval runtime socket token, replace arrays explicitly in `config.patch`, keep indexed `replacePaths` consent from widening to whole arrays, reject malformed Gateway RPC timeout inputs, skip the deleted-agent guard only for valid ACP harness sessions, surface headless LaunchAgent state, verify SQLite auth migration before cleanup, and arm QMD startup maintenance. (#87105, #91551, #91966, #54646, #40953, #91219, #91614, #91740, #91978) Thanks @fuller-stack-dev, @yetval, @ruanrrn, @comeran, and @scotthuang.
- Providers/Codex: clarify quota errors, restore the Codex synthetic usage line, canonicalize Codex protocol assets, require API-key auth for realtime voice, normalize ACP model refs, preserve Gemma 4 `reasoning_content`, honor Ollama's provider-declared thinking default in SDK sessions, and avoid guardian review for local models. (#91390, #91709, #91507, #91567, #88630, #91657, #91696) Thanks @hxy91819, @brokemac79, @RomneyDa, @joshavant, @openperf, and @Coder-Wangyankun.
- Updates/builds: recover package Gateway restarts after refresh failure, expose plugin convergence repair, fall back to Corepack in PATH-less pnpm environments, seed the correct Docker store packages, keep ClawHub dry-run and publish paths reusable, and keep beta GitHub release pages draft until OpenClaw npm, dependency evidence, postpublish verification, and required plugin publishes pass. (#91581, #91599, #91547, #91591) Thanks @fuller-stack-dev, @sallyom, and @Patrick-Erichsen.
- UI: require explicit user intent before opening chat sessions and drain restored chat queues after session switches. (#91480) Thanks @TurboTheTurtle.
- Android: avoid the `dataSync` foreground-service type for persistent nodes. (#80082) Thanks @davelutztx.
- Native hooks: bound relay lifetimes so abandoned native hook connections cannot linger indefinitely. (#91550) Thanks @joshavant.
### Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.6.6-beta.2
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.6.6-beta.2.tgz
- integrity: `sha512-617ITjTL0UxtQK4qGOc248nQBJjExX43/RR7CBr+0rEpqnA88i/VWABfTPrUnNT25181uZkOyzgguZjMW0u4Ug==`
- release SHA: `3129eed4de92d0ddc0209fbf195c790c3d73ab03`
- full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.6.6-beta.2/release-evidence.md
- release publish: https://github.com/openclaw/openclaw/actions/runs/27392222148
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/27390602410
- full release validation: https://github.com/openclaw/openclaw/actions/runs/27390601362
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/27392305214
- plugin ClawHub publish: dispatched separately, not awaited by this proof: https://github.com/openclaw/openclaw/actions/runs/27392308021
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/27392531757
- npm Telegram beta E2E: https://github.com/openclaw/openclaw/actions/runs/27392727108