### 重点亮点
- **更可靠的智能体轮次与会话状态:** OpenClaw 现可保留挂起的子智能体完成宣告、保持聊天历史记录非空、维持媒体索引对齐、重启休眠的后续处理队列,并一致地解析压缩模型别名。(#94349, #92383, #94257, #95039, #90885)感谢 @sallyom、@oiGaDio、@Hidetsugu55、@Nas01010101、@SFVVC、@Pick-cat 和 @vincentkoc。
- **更强的 Codex 与审批流程:** Codex 应用服务器 SecretRefs、线程上下文、有界轮次文本、路由审批上下文以及带类型的 SDK 审批/会话辅助工具现在能够更可预测地协同工作。(#94093, #94324, #94756, #90918, #95144, #95188, #95196, #95169)感谢 @VACInc、@kevinlin-openai、@kevinslin、@Nas01010101、@849261680、@choury 和 @vincentkoc。
- **更丰富的渠道投递:** Telegram、Discord 和 Slack 现可保留更丰富的进度/推理/线程输出、处理结构化发送错误、支持 Slack 快捷方式,并更可靠地记录规范的已发送线程。(#94891, #94856, #94810, #95029, #94881, #78536, #95250)感谢 @obviyus、@zhangqueping、@jairrab、@ZOOWH、@parveshsaini、@vincentkoc、@Marvinthebored、@chrisbaker2000、@KennanHoa、@bek91 和 @rockyloveswine。
- **更安全的发布与网络边界:** SSH 隧道预检仅限回环范围、移除了设备支持的节点配对、doctor 会暴露易失的 SQLite 状态、遗留 Codex 路由得到修复而不会静默保留过时状态。(#94607, #90373, #94725, #94478)感谢 @wangwllu、@Alix-007、@manju-rn、@vincentkoc、@TurboTheTurtle 和 @Sleepyarno。
- **实用的新 CLI 与状态工作流:** 从聊天中重命名会话、显式压缩会话、显示会话持续时间、保留命令进度详情、并通过 dry-run 输出预览消息发送/投票。(#88581, #91378, #88988, #94868, #94684)感谢 @BSG2000、@Alix-007、@sallyom、@redasadki、@marshall-gordfam、@vincentkoc、@lzyyzznl 和 @YB0y。
- **更强大的移动端和桌面客户端:** Android 设置按意图分组、iOS 通知状态更干净、Watch 应用使用兼容 Xcode 27 的目标布局、macOS 文件输入通过原生面板打开。(#94539, #91923, #92477, #94612)感谢 @Tosko4、@zats、@joshavant、@bbblending、@DINGDANGMAOUP 和 @vincentkoc。
- **更广泛的插件与技能覆盖:** Zalo 可作为外部渠道入口、Trello 技能声明其 curl 依赖、过时的托管技能链接重新定位、工具发现不再清除活跃提供商。(#89586, #94729, #86719, #93276)感谢 @ken-kuro、@liuhao1024、@berkgungor、@stevenepalmer、@shakkernerd、@medns 和 @vincentkoc。
### 变更
- **智能体与提供商行为:** Codex 轮次限制、CLI 拥有的认证、提供商内部错误措辞、重复的 cron 退避、显式的 cron 投递目标,以及隔离的 cron 密钥要求现在能更清晰地失败或恢复。(#94756, #88551, #94737, #93051, #94453, #92318, #91685)感谢 @Nas01010101、@yu-xin-c、@snowzlmbot、@Alix-007、@jincheng-xydt、@sallyom、@davectr、@hxy91819、@nxmxbbd 和 @vincentkoc。
- **渠道与集成:** WhatsApp 在媒体失败后重试开头文本块、飞书避免 axios 内部实现、Slack 记录入站提及并保留缓冲流、外部 Zalo/Slack 快捷方式通过当前渠道接缝接入。(#93823, #89806, #94790, #78536, #89586, #94881)感谢 @yetval、@sweetcornna、@davinci282828、@ZengWen-DT、@BryceMurray、@vincentkoc、@KennanHoa、@ken-kuro 和 @chrisbaker2000。
- **技能与设置:** OnePassword 认证在桌面应用可用时不再强制使用 tmux、过时的插件技能符号链接已修复、Trello 需求与其示例匹配。(#81825, #86719, #94729)感谢 @koshaji、@tylerbittner、@stevenepalmer、@shakkernerd、@liuhao1024、@berkgungor 和 @vincentkoc。
- **应用与平台支持:** iOS 通知清理、单目标 Watch 迁移、Android 意图分组、原生 macOS 文件面板、显式实时 SDP 边界,使应用界面与 Gateway 保持一致。(#91923, #92477, #94539, #94612, #95093)感谢 @zats、@joshavant、@Tosko4、@bbblending、@DINGDANGMAOUP 和 @vincentkoc。
- **运维诊断:** Gateway 探测现可区分可达但出错与不可达、插件方法通过附加的注册表授权、会话状态暴露持续时间、提供商定价流有限制。(#93948, #94343, #88988, #95103)感谢 @xialonglee、@MAdArab872、@wangmiao0668000666、@RDavies8、@Alix-007、@marshall-gordfam、@vincentkoc、@ozthedivine 和 @shakkernerd。
### 修复
- **回复与记录正确性:** OpenClaw 现可在重试和部分轮次中保持挂起的完成、非空历史记录、媒体字段、排队后续操作、缓冲的 Slack 回复以及推理投递完好无损。(#94349, #92383, #94257, #95039, #78536, #95029, #84292)感谢 @sallyom、@oiGaDio、@Hidetsugu55、@Nas01010101、@SFVVC、@vincentkoc、@KennanHoa、@Marvinthebored、@zerone0x 和 @pearl-dot。
- **安全与有界输入处理:** SSH 隧道检查仅限回环、不安全的聊天/工具/包/响应长度被拒绝、设备支持的配对已被移除、过时的中断标记不再影响新的聊天事件。(#94607, #95066, #95078, #95085, #95090, #90373, #91013)感谢 @wangwllu、@vincentkoc、@Alix-007、@manju-rn 和 @nxmxbbd。
- **Telegram、WhatsApp 和 Slack 投递:** 丰富的进度预览、结构化 Telegram 错误、WhatsApp 监听器恢复、以及规范的 Slack 线程/发送行为现可应对新版发布所涵盖的边界情况。(#94891, #94856, #94810, #93873, #95250)感谢 @obviyus、@zhangqueping、@jairrab、@ZOOWH、@parveshsaini、@xialonglee、@octaivermatt、@bek91 和 @rockyloveswine。
- **Cron 与队列安全:** 重复错误退避遵循配置的下限、隐式隔离投递需要显式目标、休眠的后续操作排水重启而不是消失。(#93051, #91685, #92318, #95039)感谢 @Alix-007、@nxmxbbd、@hxy91819 和 @SFVVC。
- **提供商、认证和迁移修复:** CLI 拥有的传输跳过错误的认证入口、压缩别名规范解析、遗留 Codex 路由已修复、工具发现不再清除活跃提供商。(#88551, #90885, #94478, #93276)感谢 @yu-xin-c、@Pick-cat、@TurboTheTurtle、@Sleepyarno、@medns 和 @vincentkoc。
- **SDK 与发布工具:** 审批/会话 RPC 参数类型更严格、过时的打包 tarball 被忽略、DMG 输出目录可靠创建。(#95144, #95152, #95188, #95196, #95169, #95126, #95133)感谢 @vincentkoc。
### 完整贡献记录
此审核记录涵盖了完整的 v2026.6.9-beta.1..HEAD 历史:共 109 个合并 PR。生成清单也提供了直接提交作为编辑输入;上述分组说明优先考虑用户影响。
#### Pull requests
- **PR #93685** 重构(auto-reply):添加生命周期存储接缝。感谢 @jalehman。
- **PR #94349** 修复(agents):保留挂起的子智能体完成宣告。关联 #93323。感谢 @sallyom 和 @oiGaDio。
- **PR #93174** 测试:将渠道消息流程折叠到 QA e2e。感谢 @RomneyDa。
- **PR #94093** 阻止 Codex 线程轮换丢失下一步上下文。感谢 @VACInc。
- **PR #53920** 修复(scripts):在设置期间避免修改跟踪的 auth-monitor 模板。感谢 @JackWuGlobal。
- **PR #94702** 标准化 QA 覆盖 ID 为点号命名。感谢 @RomneyDa。
- **PR #81825** 修复(skills/1password):停止在桌面应用认证时强制使用 tmux(#52540)。感谢 @koshaji 和 @tylerbittner。
- **PR #94725** 修复(doctor):警告易失的 SQLite 状态。感谢 @vincentkoc。
- **PR #88551** 修复(agents):为 CLI 拥有的传输跳过认证入口。感谢 @yu-xin-c。
- **PR #88581** 特性(commands):添加 /name 以从聊天中重命名当前会话。感谢 @BSG2000。
- **PR #94324** 特性(codex):支持应用服务器 SecretRefs。感谢 @kevinlin-openai 和 @kevinslin。
- **PR #90882** 修复:在系统提示中添加自我知识文档规则。关联 #90713。感谢 @SutraHsing。
- **PR #94684** 修复:#80507 为消息发送/投票显示 dry-run 输出。感谢 @lzyyzznl 和 @YB0y。
- **PR #93823** 修复(whatsapp):当多块回复中第一个媒体失败时保持开头文本块。感谢 @yetval。
- **PR #89203** 重构:通过接缝路由 SDK 会话兼容性。感谢 @jalehman。
- **PR #94453** 修复:将 cron runMode 默认值从 "force" 改为 "due"(#94270)。感谢 @jincheng-xydt、@sallyom 和 @davectr。
- **PR #94746** 修复(note):防止 clack 重新破坏复制敏感的令牌。关联 #94730。感谢 @xzh-icenter 和 @berkgungor。
- **PR #89904** 重构:通过访问器路由 SDK 会话兼容性。感谢 @jalehman。
- **PR #86719** 修复(skills):重新定位过时的插件技能符号链接。关联 #85925。感谢 @stevenepalmer 和 @shakkernerd。
- **PR #94337** 修复(tui):在页脚中为全新会话上下文令牌显示 0 而不是 ?。感谢 @mushuiyu886。
- **PR #94539** 修复(android):按意图分组设置。感谢 @Tosko4。
- **PR #92383** 修复(gateway):永远不返回空的 chat.history 转录。感谢 @Hidetsugu55。
- **PR #92574** 测试(browser):覆盖动作输入 CLI 请求体。关联 #83877。感谢 @yu-xin-c 和 @davinci282828。
- **PR #92873** 测试(diffs):添加 viewerState、工具栏切换、影子 DOM 和 hydrateProps 测试(修复 #83915)。感谢 @liuhao1024 和 @davinci282828。
- **PR #94257** 修复(sessions):在读取用户轮次字段时保留 Media\* 索引对齐。感谢 @Nas01010101。
- **PR #94756** 修复(codex):当上下文预算为非正数时限制轮次/起始文本。关联 #94748。感谢 @Nas01010101。
- **PR #94729** 修复(skills/trello):将 curl 添加到 requires.bins 以匹配正文示例(修复 #94727)。感谢 @liuhao1024 和 @berkgungor。
- **PR #94790** 特性(slack):为入站 app_mention 事件记录 INFO 收据。关联 #94691。感谢 @ZengWen-DT 和 @BryceMurray。
- **PR #81696** 修复:保护工具事件回调(AI 辅助)。感谢 @enjoylife1243。
- **PR #94809** 杂项:向前移植 alpha 版本修复。
- **PR #94612** 修复(macos):为嵌入式 Control UI 文件输入打开 NSOpenPanel(#94468)。感谢 @bbblending 和 @DINGDANGMAOUP。
- **PR #89806** 修复(feishu):避免 axios 拦截器内部实现。关联 #83913。感谢 @sweetcornna 和 @davinci282828。
- **PR #91923** 修复(ios):清理通知设置状态。感谢 @zats。
- **PR #91345** 修复:建议关闭 CLI 命令。关联 #83999。感谢 @glenn-agent 和 @HannesOberreiter。
- **PR #94561** 添加 stdout 诊断 OTEL 日志导出器。感谢 @jesse-merhi。
- **PR #91013** 修复(gateway):为新的聊天事件忽略过时的中断标记。关联 #91012。感谢 @nxmxbbd。
- **PR #89279** 修复(tasks):将 ACP 完成投递给绑定的 Discord 线程。关联 #84022。感谢 @anyech 和 @h-mascot。
- **PR #91656** 测试(cron):将 parseAbsoluteTimeMs 测试覆盖扩展到 39 个用例。关联 #91654。感谢 @SpecialLeon。
- **PR #94810** 修复(telegram):通过结构化 error_code 而非裸子字符串匹配来分类 sendChatAction 401。关联 #94787。感谢 @ZOOWH 和 @parveshsaini。
- **PR #94737** 修复(reply):澄清提供商内部错误副本。感谢 @snowzlmbot。
- **PR #94868** 修复(channels):保留命令进度详情。感谢 @vincentkoc。
- **PR #94891** 修复(telegram):将进度预览作为 html 文本发送。感谢 @obviyus。
- **PR #94683** 修复(outbound):将仅直连目标保留在群组会话之外。关联 #92384。感谢 @scotthuang 和 @haiwei01。
- **PR #92477** 修复:将 watch 应用迁移为单目标应用(Xcode 27+ 兼容)。感谢 @zats 和 @joshavant。
- **PR #94812** 测试(perf):比较保存的 CLI 启动基准。感谢 @FelixIsaac。
- **PR #94856** 修复(telegram):在富消息中进行实体转义前规范化所有 HTML 表格。关联 #94317。感谢 @zhangqueping 和 @jairrab。
- **PR #91685** 修复(cron):拒绝从共享的 agent-main 桶继承的无密钥隐式隔离 cron 投递。感谢 @nxmxbbd。
- **PR #88988** 特性(status):在页脚中显示会话持续时间。关联 #68226。感谢 @Alix-007 和 @marshall-gordfam。
- **PR #94020** 文档(browser):解决浏览器文档中 networkidle 的矛盾。关联 #80587。感谢 @ZengWen-DT 和 @esqandil。
- **PR #93948** 修复(gateway):在探测诊断中区分可达但出错与不可达。关联 #79099。感谢 @xialonglee 和 @ozthedivine。
- **PR #93276** 修复(plugins):阻止工具发现加载清除活跃提供商。感谢 @medns。
- **PR #94343** 修复(gateway):从附加的注册表授权插件方法。关联 #92044。感谢 @wangmiao0668000666 和 @RDavies8。
- **PR #94589** 修复(channels):阻止在系统事件中重复入站预览。关联 #94549。感谢 @hugenshen 和 @gorkem2020。
- **PR #93873** 修复(whatsapp):在 selfChatMode 配置更改时重启监听器。关联 #86888。感谢 @xialonglee 和 @octaivermatt。
- **PR #93969** 修复(xai):在运行时回退前拒绝不支持的多智能体模型引用。关联 #85106。感谢 @xialonglee 和 @tess020126-cmyk。
- **PR #89586** 特性(channels):添加 Zalo ClawBot 外部渠道入口及文档。感谢 @ken-kuro。
- **PR #78536** 修复(slack):保留缓冲的线程流回复。关联 #78061。感谢 @vincentkoc 和 @KennanHoa。
- **PR #89236** 修复(slack):将成员信息 userId 默认设为入站发送者。感谢 @stroupaloop。
- **PR #94881** 特性(slack):处理全局和消息快捷方式。关联 #63920。感谢 @chrisbaker2000。
- **PR #90885** 修复(agent):将压缩模型别名解析为规范的模型引用。感谢 @Pick-cat。
- **PR #90918** 修复(agents):将轮次源路由字段转发到 plugin.approval.request。关联 #74003。感谢 @849261680 和 @choury。
- **PR #95029** 修复(discord):投递推理回复。关联 #94936。感谢 @vincentkoc 和 @Marvinthebored。
- **PR #89581** 重构:使用规范的转录阅读器身份。感谢 @jalehman。
- **PR #94607** 修复(ssh):将隧道端口预检限定为回环(#94603)。感谢 @wangwllu。
- **PR #95060** 修复(test):强化脚本探测边界。感谢 @vincentkoc。
- **PR #95066** 修复(e2e):拒绝不安全的聊天工具正文长度。感谢 @vincentkoc。
- **PR #93941** 文档:修复两个损坏的交叉引用锚点。感谢 @Alix-007。
- **PR #92996** 修复(cli):在状态/健康快速路径上拒绝存在但无效的 --timeout。感谢 @Alix-007。
- **PR #94314** 重构(policy):拆分医生模块。感谢 @giodl73-repo。
- **PR #93051** 修复(cron):为重复错误退避下限遵守配置的 retry.backoffMs。感谢 @Alix-007。
- **PR #95078** 修复(scripts):拒绝不安全的包下载长度。感谢 @vincentkoc。
- **PR #91378** 特性(cli):添加 `openclaw sessions compact` 并在 CLI `/compact` 上大声失败(修复 #90640)。感谢 @Alix-007、@sallyom 和 @redasadki。
- **PR #94676** 改进:简化 PR 上下文和证据。感谢 @hannesrudolph。
- **PR #95085** 修复(scripts):拒绝不安全的有限制响应长度。感谢 @vincentkoc。
- **PR #95090** 修复(e2e):拒绝不安全的有限制响应文本长度。感谢 @vincentkoc。
- **PR #95076** [codex] 文档:澄清 PR 正文证据更新。感谢 @brokemac79。
- **PR #84292** 修复(agents):保留已投递消息的发送结果。关联 #84271。感谢 @zerone0x 和 @pearl-dot。
- **PR #95039** 修复(queue):重启休眠的后续操作排水。关联 #91909。感谢 @SFVVC。
- **PR #90373** 修复(gateway):移除设备支持的节点配对。关联 #88488。感谢 @Alix-007 和 @manju-rn。
- **PR #95093** 修复(dev):限制实时 SDP 应答读取。感谢 @vincentkoc。
- **PR #95103** 修复(gateway):限制定价目录流。感谢 @vincentkoc。
- **PR #95108** 修复(agents):限制 Anthropic 错误流。感谢 @vincentkoc。
- **PR #95111** 修复(memory):中止批量上传响应读取。感谢 @vincentkoc。
- **PR #95105** 修复(ci):取消过时的 Testbox PR 运行。感谢 @RomneyDa。
- **PR #95114** 修复(test):稳定工具守卫探测。感谢 @vincentkoc。
- **PR #94478** 修复(doctor):修复遗留 Codex 路由持久化。关联 #94184。感谢 @TurboTheTurtle 和 @Sleepyarno。
- **PR #95119** 修复(test):流式输出 QA Lab stdout 工件。感谢 @vincentkoc。
- **PR #95116** 修复(ci):取消过时的 CodeQL 运行。感谢 @RomneyDa。
- **PR #95126** 修复(package):忽略过时的打包 tarball。感谢 @vincentkoc。
- **PR #95133** 修复(macos):创建 DMG 输出目录。感谢 @vincentkoc。
- **PR #95137** 测试(docker):稳定构建信号探测。感谢 @vincentkoc。
- **PR #95144** 修复(sdk):发送 exec 审批解析 ID。感谢 @vincentkoc。
- **PR #95152** 修复(sdk):列出辅助工具无需过滤器即可工作。感谢 @vincentkoc。
- **PR #95207** 修复(scripts):保留厨房水槽 RPC 请求错误。感谢 @vincentkoc。
- **PR #95203** 修复(scripts):保护重用的 testbox 密钥。感谢 @vincentkoc。
- **PR #95188** 修复(sdk):为智能体突变 RPC 参数添加类型。感谢 @vincentkoc。
- **PR #95196** 修复(sdk):收紧审批响应参数。感谢 @vincentkoc。
- **PR #95169** 修复(sdk):要求会话密钥用于有效工具。感谢 @vincentkoc。
- **PR #95250** 修复(slack):记录规范的已发送线程。关联 #95235。感谢 @bek91 和 @rockyloveswine。
- **PR #86627** 保持核心医生健康按贡献顺序。感谢 @giodl73-repo。
- **PR #93580** 修复:为目标会话保留 cron 投递意识。感谢 @scotthuang 和 @jalehman。
- **PR #95030** 重构:添加 SDK 转录身份目标 API。感谢 @jalehman。
- **PR #94838** 重构(copilot):完成 harness 生命周期对等。感谢 @vincentkoc。
- **PR #95328** 修复(sessions):在渠道切换时重置过时的每渠道源字段。关联 #95325。感谢 @ZengWen-DT、@jalehman 和 @gorkem2020。
- **PR #94461** 修复(zai):回退到清单 baseUrl 以合成 GLM-5 模型。关联 #94269。感谢 @Pandah97 和 @chrysb。
- **PR #93241** 修复(agents):将智谱 GLM 过载分类为用于故障转移的过载。关联 #93211。感谢 @0xghost42 和 @zhengli0922。
- **PR #94067** 修复(channels):通过运行时目录解析原生 /think 菜单级别以发现实时发现的模型。关联 #93835。感谢 @openperf 和 @civiltox。
- **PR #94136** 修复(zai):暴露 GLM-5.2 推理级别 [AI 辅助]。感谢 @BorClaw。
- **PR #92318** 修复(cron):要求显式消息目标证明。感谢 @hxy91819。
### 发布验证
- npm 包:https://www.npmjs.com/package/openclaw/v/2026.6.10-beta.1
- registry tarball:https://registry.npmjs.org/openclaw/-/openclaw-2026.6.10-beta.1.tgz
- 完整性:`sha512-OgdN7P0Scm8rNgcXUrCGFyrMPJGdC3TdMxdS95jPbEzws9tp3CgZnehcmBNyBqCc9QU4uK0QUk7bnNSW+3ohbw==`
- 发布 SHA:`d91c1607c4d254b6dafa2ea052aef82e68b0c1b0`
- 完整发布 CI 报告:https://github.com/openclaw/releases/blob/main/evidence/2026.6.10-beta.1/release-evidence.md
- 发布发布:https://github.com/openclaw/openclaw/actions/runs/27898612086
- npm 预检:https://github.com/openclaw/openclaw/actions/runs/27897098428
- 完整发布验证:https://github.com/openclaw/openclaw/actions/runs/27897098492
- 插件 npm 发布:https://github.com/openclaw/openclaw/actions/runs/27898772805
- 插件 ClawHub 发布:单独分发,此证明不等待:https://github.com/openclaw/openclaw/actions/runs/27898773498
- 插件 ClawHub 引导:不需要
- OpenClaw npm 发布:https://github.com/openclaw/openclaw/actions/runs/27899322972
- npm Telegram beta E2E:未提供
### Highlights
- **More reliable agent turns and session state:** OpenClaw now preserves pending subagent completion announcements, keeps chat history transcripts non-empty, maintains media index alignment, restarts dormant follow-up drains, and resolves compaction model aliases consistently. (#94349, #92383, #94257, #95039, #90885) Thanks @sallyom, @oiGaDio, @Hidetsugu55, @Nas01010101, @SFVVC, @Pick-cat, and @vincentkoc.
- **Stronger Codex and approval flows:** Codex app-server SecretRefs, thread context, bounded turn text, routed approval context, and typed SDK approval/session helpers now work together more predictably. (#94093, #94324, #94756, #90918, #95144, #95188, #95196, #95169) Thanks @VACInc, @kevinlin-openai, @kevinslin, @Nas01010101, @849261680, @choury, and @vincentkoc.
- **Richer channel delivery:** Telegram, Discord, and Slack now preserve richer progress/reasoning/thread output, handle structured send errors, support Slack shortcuts, and record canonical sent threads more reliably. (#94891, #94856, #94810, #95029, #94881, #78536, #95250) Thanks @obviyus, @zhangqueping, @jairrab, @ZOOWH, @parveshsaini, @vincentkoc, @Marvinthebored, @chrisbaker2000, @KennanHoa, @bek91, and @rockyloveswine.
- **Safer release and network boundaries:** SSH tunnel preflight is loopback-scoped, device-backed node pairings are removed, volatile SQLite state is surfaced by doctor, and legacy Codex routes are repaired instead of silently persisting stale state. (#94607, #90373, #94725, #94478) Thanks @wangwllu, @Alix-007, @manju-rn, @vincentkoc, @TurboTheTurtle, and @Sleepyarno.
- **Useful new CLI and status workflows:** Rename sessions from chat, compact sessions explicitly, show session duration, preserve command progress detail, and preview message sends/polls with dry-run output. (#88581, #91378, #88988, #94868, #94684) Thanks @BSG2000, @Alix-007, @sallyom, @redasadki, @marshall-gordfam, @vincentkoc, @lzyyzznl, and @YB0y.
- **More capable mobile and desktop clients:** Android settings are grouped by intent, iOS notification state is cleaner, the Watch app uses the Xcode 27-compatible target layout, and macOS file inputs open through the native panel. (#94539, #91923, #92477, #94612) Thanks @Tosko4, @zats, @joshavant, @bbblending, @DINGDANGMAOUP, and @vincentkoc.
- **Broader plugin and skill coverage:** Zalo is available as an external channel entry, Trello skills declare their curl dependency, stale managed skill links are retargeted, and tool discovery no longer clears active providers. (#89586, #94729, #86719, #93276) Thanks @ken-kuro, @liuhao1024, @berkgungor, @stevenepalmer, @shakkernerd, @medns, and @vincentkoc.
### Changes
- **Agent and provider behavior:** Codex turn limits, CLI-owned auth, provider-internal error wording, recurring cron backoff, explicit cron delivery targets, and isolated cron key requirements now fail or recover more clearly. (#94756, #88551, #94737, #93051, #94453, #92318, #91685) Thanks @Nas01010101, @yu-xin-c, @snowzlmbot, @Alix-007, @jincheng-xydt, @sallyom, @davectr, @hxy91819, @nxmxbbd, and @vincentkoc.
- **Channels and integrations:** WhatsApp retries the opening text chunk after media failure, Feishu avoids axios internals, Slack records inbound mentions and preserves buffered streams, and external Zalo/Slack shortcuts are wired through the current channel seams. (#93823, #89806, #94790, #78536, #89586, #94881) Thanks @yetval, @sweetcornna, @davinci282828, @ZengWen-DT, @BryceMurray, @vincentkoc, @KennanHoa, @ken-kuro, and @chrisbaker2000.
- **Skills and setup:** OnePassword auth no longer forces tmux when the desktop app is available, stale plugin skill symlinks are repaired, and Trello requirements match their examples. (#81825, #86719, #94729) Thanks @koshaji, @tylerbittner, @stevenepalmer, @shakkernerd, @liuhao1024, @berkgungor, and @vincentkoc.
- **Apps and platform support:** iOS notification cleanup, the single-target Watch migration, Android intent grouping, native macOS file panels, and explicit realtime SDP bounds keep the app surfaces aligned with the Gateway. (#91923, #92477, #94539, #94612, #95093) Thanks @zats, @joshavant, @Tosko4, @bbblending, @DINGDANGMAOUP, and @vincentkoc.
- **Operator diagnostics:** Gateway probes now distinguish reachable-but-errored from unreachable, plugin methods authorize through the attached registry, session status exposes duration, and provider pricing streams are bounded. (#93948, #94343, #88988, #95103) Thanks @xialonglee, @MAdArab872, @wangmiao0668000666, @RDavies8, @Alix-007, @marshall-gordfam, @vincentkoc, @ozthedivine, and @shakkernerd.
### Fixes
- **Reply and transcript correctness:** OpenClaw now keeps pending completions, non-empty histories, media fields, queued follow-ups, buffered Slack replies, and reasoning deliveries intact across retries and partial turns. (#94349, #92383, #94257, #95039, #78536, #95029, #84292) Thanks @sallyom, @oiGaDio, @Hidetsugu55, @Nas01010101, @SFVVC, @vincentkoc, @KennanHoa, @Marvinthebored, @zerone0x, and @pearl-dot.
- **Security and bounded input handling:** SSH tunnel checks stay on loopback, unsafe chat/tool/package/response lengths are rejected, device-backed pairings are removed, and stale abort markers no longer affect fresh chat events. (#94607, #95066, #95078, #95085, #95090, #90373, #91013) Thanks @wangwllu, @vincentkoc, @Alix-007, @manju-rn, and @nxmxbbd.
- **Telegram, WhatsApp, and Slack delivery:** Rich progress previews, structured Telegram errors, WhatsApp listener recovery, and canonical Slack thread/send behavior now survive the edge cases covered by the new release. (#94891, #94856, #94810, #93873, #95250) Thanks @obviyus, @zhangqueping, @jairrab, @ZOOWH, @parveshsaini, @xialonglee, @octaivermatt, @bek91, and @rockyloveswine.
- **Cron and queue safety:** Recurring error backoff honors configured floors, implicit isolated delivery requires an explicit target, and dormant follow-up drains restart instead of disappearing. (#93051, #91685, #92318, #95039) Thanks @Alix-007, @nxmxbbd, @hxy91819, and @SFVVC.
- **Provider, auth, and migration repair:** CLI-owned transports skip the wrong auth gate, compaction aliases resolve canonically, legacy Codex routes are repaired, and tool discovery no longer clears active providers. (#88551, #90885, #94478, #93276) Thanks @yu-xin-c, @Pick-cat, @TurboTheTurtle, @Sleepyarno, @medns, and @vincentkoc.
- **SDK and release tooling:** Approval/session RPC params are typed more strictly, stale packed tarballs are ignored, and DMG output directories are created reliably. (#95144, #95152, #95188, #95196, #95169, #95126, #95133) Thanks @vincentkoc.
### Complete contribution record
This audited record covers the complete v2026.6.9-beta.1..HEAD history: 109 merged PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.
#### Pull requests
- **PR #93685** refactor(auto-reply): add lifecycle storage seams. Thanks @jalehman.
- **PR #94349** fix(agents): preserve pending subagent completion announces. Related #93323. Thanks @sallyom and @oiGaDio.
- **PR #93174** test: fold channel message flows into qa e2e. Thanks @RomneyDa.
- **PR #94093** Prevent Codex thread rotation from losing next-step context. Thanks @VACInc.
- **PR #53920** fix(scripts): avoid mutating tracked auth-monitor template during setup. Thanks @JackWuGlobal.
- **PR #94702** Standardize QA coverage IDs on dotted names. Thanks @RomneyDa.
- **PR #81825** fix(skills/1password): stop forcing tmux for desktop app auth (#52540). Thanks @koshaji and @tylerbittner.
- **PR #94725** fix(doctor): warn on volatile SQLite state. Thanks @vincentkoc.
- **PR #88551** fix(agents): skip auth gate for CLI-owned transport. Thanks @yu-xin-c.
- **PR #88581** feat(commands): add /name to rename the current session from chat. Thanks @BSG2000.
- **PR #94324** feat(codex): support app-server SecretRefs. Thanks @kevinlin-openai and @kevinslin.
- **PR #90882** fix: add self-knowledge docs rule to system prompt. Related #90713. Thanks @SutraHsing.
- **PR #94684** fix: #80507 show dry-run output for message send/poll. Thanks @lzyyzznl and @YB0y.
- **PR #93823** fix(whatsapp): keep opening text chunk when first media fails on multi-chunk reply. Thanks @yetval.
- **PR #89203** refactor: route SDK session compatibility through seam. Thanks @jalehman.
- **PR #94453** fix: default cron runMode to "due" instead of "force" (#94270). Thanks @jincheng-xydt and @sallyom and @davectr.
- **PR #94746** fix(note): prevent clack from re-breaking copy-sensitive tokens. Related #94730. Thanks @xzh-icenter and @berkgungor.
- **PR #89904** refactor: route sdk session compatibility through accessor. Thanks @jalehman.
- **PR #86719** fix(skills): retarget stale plugin skill symlinks. Related #85925. Thanks @stevenepalmer and @shakkernerd.
- **PR #94337** fix(tui): show 0 not ? for fresh-session context tokens in footer. Thanks @mushuiyu886.
- **PR #94539** fix(android): group settings by intent. Thanks @Tosko4.
- **PR #92383** fix(gateway): never return an empty chat.history transcript. Thanks @Hidetsugu55.
- **PR #92574** test(browser): cover action-input CLI request bodies. Related #83877. Thanks @yu-xin-c and @davinci282828.
- **PR #92873** test(diffs): add viewerState, toolbar toggle, shadow root, and hydrateProps tests (fixes #83915). Thanks @liuhao1024 and @davinci282828.
- **PR #94257** fix(sessions): preserve Media\* index alignment when reading user-turn fields. Thanks @Nas01010101.
- **PR #94756** fix(codex): bound turn/start text when context budget is non-positive. Related #94748. Thanks @Nas01010101.
- **PR #94729** fix(skills/trello): add curl to requires.bins to match body examples (fixes #94727). Thanks @liuhao1024 and @berkgungor.
- **PR #94790** feat(slack): log INFO receipt for inbound app_mention events. Related #94691. Thanks @ZengWen-DT and @BryceMurray.
- **PR #81696** fix: guard tool event callbacks (AI-assisted). Thanks @enjoylife1243.
- **PR #94809** chore: forward-port alpha release fixes.
- **PR #94612** fix(macos): open NSOpenPanel for embedded Control UI file inputs (#94468). Thanks @bbblending and @DINGDANGMAOUP.
- **PR #89806** fix(feishu): avoid axios interceptor internals. Related #83913. Thanks @sweetcornna and @davinci282828.
- **PR #91923** fix(ios): clean up notification settings state. Thanks @zats.
- **PR #91345** fix: suggest close CLI commands. Related #83999. Thanks @glenn-agent and @HannesOberreiter.
- **PR #94561** Add stdout diagnostics OTEL log exporter. Thanks @jesse-merhi.
- **PR #91013** fix(gateway): ignore stale abort markers for fresh chat events. Related #91012. Thanks @nxmxbbd.
- **PR #89279** fix(tasks): deliver ACP completions to bound Discord threads. Related #84022. Thanks @anyech and @h-mascot.
- **PR #91656** test(cron): expand parseAbsoluteTimeMs test coverage to 39 cases. Related #91654. Thanks @SpecialLeon.
- **PR #94810** fix(telegram): classify sendChatAction 401 by structured error_code, not bare substring match. Related #94787. Thanks @ZOOWH and @parveshsaini.
- **PR #94737** fix(reply): clarify provider internal error copy. Thanks @snowzlmbot.
- **PR #94868** fix(channels): preserve command progress detail. Thanks @vincentkoc.
- **PR #94891** fix(telegram): send progress previews as html text. Thanks @obviyus.
- **PR #94683** fix(outbound): keep direct-only targets out of group sessions. Related #92384. Thanks @scotthuang and @haiwei01.
- **PR #92477** fix: migrate watch app to single-target app (Xcode 27+ compat). Thanks @zats and @joshavant.
- **PR #94812** test(perf): compare saved CLI startup benchmarks. Thanks @FelixIsaac.
- **PR #94856** fix(telegram): normalize all HTML tables before entity-escaping in rich messages. Related #94317. Thanks @zhangqueping and @jairrab.
- **PR #91685** fix(cron): refuse keyless implicit isolated cron delivery inherited from shared agent-main bucket. Thanks @nxmxbbd.
- **PR #88988** feat(status): show session duration in footer. Related #68226. Thanks @Alix-007 and @marshall-gordfam.
- **PR #94020** docs(browser): resolve networkidle contradiction across browser docs. Related #80587. Thanks @ZengWen-DT and @esqandil.
- **PR #93948** fix(gateway): distinguish reachable-but-errored from unreachable in probe diagnostics. Related #79099. Thanks @xialonglee and @ozthedivine.
- **PR #93276** fix(plugins): stop tool-discovery loads from clearing active providers. Thanks @medns.
- **PR #94343** fix(gateway): authorize plugin methods from attached registry. Related #92044. Thanks @wangmiao0668000666 and @RDavies8.
- **PR #94589** fix(channels): stop duplicating inbound previews in system events. Related #94549. Thanks @hugenshen and @gorkem2020.
- **PR #93873** fix(whatsapp): restart listener on selfChatMode config change. Related #86888. Thanks @xialonglee and @octaivermatt.
- **PR #93969** fix(xai): reject unsupported multi-agent model refs before runtime fallback. Related #85106. Thanks @xialonglee and @tess020126-cmyk.
- **PR #89586** feat(channels): add Zalo ClawBot external channel entry and documenta…. Thanks @ken-kuro.
- **PR #78536** fix(slack): preserve buffered thread stream replies. Related #78061. Thanks @vincentkoc and @KennanHoa.
- **PR #89236** fix(slack): default member-info userId to inbound sender. Thanks @stroupaloop.
- **PR #94881** feat(slack): handle global and message shortcuts. Related #63920. Thanks @chrisbaker2000.
- **PR #90885** fix(agent): resolve compaction model alias to canonical model ref. Thanks @Pick-cat.
- **PR #90918** fix(agents): forward turn-source routing fields to plugin.approval.request. Related #74003. Thanks @849261680 and @choury.
- **PR #95029** fix(discord): deliver reasoning replies. Related #94936. Thanks @vincentkoc and @Marvinthebored.
- **PR #89581** refactor: use canonical transcript reader identity. Thanks @jalehman.
- **PR #94607** fix(ssh): scope tunnel port preflight to loopback (#94603). Thanks @wangwllu.
- **PR #95060** fix(test): harden script probe bounds. Thanks @vincentkoc.
- **PR #95066** fix(e2e): reject unsafe chat tools body lengths. Thanks @vincentkoc.
- **PR #93941** docs: fix two broken cross-reference anchors. Thanks @Alix-007.
- **PR #92996** fix(cli): reject present-but-invalid --timeout on status/health fast path. Thanks @Alix-007.
- **PR #94314** refactor(policy): split doctor modules. Thanks @giodl73-repo.
- **PR #93051** fix(cron): honor configured retry.backoffMs for recurring error backoff floor. Thanks @Alix-007.
- **PR #95078** fix(scripts): reject unsafe package download lengths. Thanks @vincentkoc.
- **PR #91378** feat(cli): add `openclaw sessions compact` and fail loudly on CLI `/compact` (fixes #90640). Thanks @Alix-007 and @sallyom and @redasadki.
- **PR #94676** improve: simplify PR context and evidence. Thanks @hannesrudolph.
- **PR #95085** fix(scripts): reject unsafe bounded response lengths. Thanks @vincentkoc.
- **PR #95090** fix(e2e): reject unsafe bounded response text lengths. Thanks @vincentkoc.
- **PR #95076** [codex] docs: clarify PR body evidence updates. Thanks @brokemac79.
- **PR #84292** fix(agents): preserve delivered message send results. Related #84271. Thanks @zerone0x and @pearl-dot.
- **PR #95039** fix(queue): restart dormant followup drains. Related #91909. Thanks @SFVVC.
- **PR #90373** fix(gateway): remove device-backed node pairings. Related #88488. Thanks @Alix-007 and @manju-rn.
- **PR #95093** fix(dev): bound realtime SDP answer reads. Thanks @vincentkoc.
- **PR #95103** fix(gateway): bound pricing catalog streams. Thanks @vincentkoc.
- **PR #95108** fix(agents): bound Anthropic error streams. Thanks @vincentkoc.
- **PR #95111** fix(memory): abort batch upload response reads. Thanks @vincentkoc.
- **PR #95105** fix(ci): cancel stale Testbox PR runs. Thanks @RomneyDa.
- **PR #95114** fix(test): stabilize tooling guard probes. Thanks @vincentkoc.
- **PR #94478** fix(doctor): repair legacy Codex route persistence. Related #94184. Thanks @TurboTheTurtle and @Sleepyarno.
- **PR #95119** fix(test): stream QA Lab stdout artifacts. Thanks @vincentkoc.
- **PR #95116** fix(ci): cancel stale CodeQL runs. Thanks @RomneyDa.
- **PR #95126** fix(package): ignore stale packed tarballs. Thanks @vincentkoc.
- **PR #95133** fix(macos): create DMG output directories. Thanks @vincentkoc.
- **PR #95137** test(docker): stabilize build signal probe. Thanks @vincentkoc.
- **PR #95144** fix(sdk): send exec approval resolve id. Thanks @vincentkoc.
- **PR #95152** fix(sdk): list helpers work without filters. Thanks @vincentkoc.
- **PR #95207** fix(scripts): preserve kitchen sink RPC request errors. Thanks @vincentkoc.
- **PR #95203** fix(scripts): guard reused testbox keys. Thanks @vincentkoc.
- **PR #95188** fix(sdk): type agent mutation RPC params. Thanks @vincentkoc.
- **PR #95196** fix(sdk): tighten approval response params. Thanks @vincentkoc.
- **PR #95169** fix(sdk): require session key for effective tools. Thanks @vincentkoc.
- **PR #95250** fix(slack): record canonical sent thread. Related #95235. Thanks @bek91 and @rockyloveswine.
- **PR #86627** Keep core doctor health in contribution order. Thanks @giodl73-repo.
- **PR #93580** fix: preserve cron delivery awareness for target sessions. Thanks @scotthuang and @jalehman.
- **PR #95030** refactor: add SDK transcript identity target API. Thanks @jalehman.
- **PR #94838** refactor(copilot): complete harness lifecycle parity. Thanks @vincentkoc.
- **PR #95328** fix(sessions): reset stale per-channel origin fields on channel switch. Related #95325. Thanks @ZengWen-DT and @jalehman and @gorkem2020.
- **PR #94461** fix(zai): fall back to manifest baseUrl for synthesized GLM-5 models. Related #94269. Thanks @Pandah97 and @chrysb.
- **PR #93241** fix(agents): classify Zhipu GLM overload as overloaded for failover. Related #93211. Thanks @0xghost42 and @zhengli0922.
- **PR #94067** fix(channels): resolve native /think menu levels via runtime catalog for live-discovered models. Related #93835. Thanks @openperf and @civiltox.
- **PR #94136** fix(zai): expose GLM-5.2 reasoning levels [AI-assisted]. Thanks @BorClaw.
- **PR #92318** fix(cron): require explicit message target proof. Thanks @hxy91819.
### Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.6.10-beta.1
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.6.10-beta.1.tgz
- integrity: `sha512-OgdN7P0Scm8rNgcXUrCGFyrMPJGdC3TdMxdS95jPbEzws9tp3CgZnehcmBNyBqCc9QU4uK0QUk7bnNSW+3ohbw==`
- release SHA: `d91c1607c4d254b6dafa2ea052aef82e68b0c1b0`
- full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.6.10-beta.1/release-evidence.md
- release publish: https://github.com/openclaw/openclaw/actions/runs/27898612086
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/27897098428
- full release validation: https://github.com/openclaw/openclaw/actions/runs/27897098492
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/27898772805
- plugin ClawHub publish: dispatched separately, not awaited by this proof: https://github.com/openclaw/openclaw/actions/runs/27898773498
- plugin ClawHub bootstrap: not needed
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/27899322972
- npm Telegram beta E2E: not supplied