### 亮点
- **OpenAI GPT-5.6 支持:** OpenClaw 现已在目录、能力和运行时选择路径中识别 GPT-5.6 模型家族。(#98333) 感谢 @steipete-oai。
- **外部测试工具挂载:** `openclaw attach` 针对现有 Gateway 会话启动外部测试工具,使交互式 Codex 风格的工作流更易于恢复和审查。(#96454) 感谢 @anagnorisis2peripeteia 和 @obviyus。
- **Telegram Codex 工作流:** Telegram 现可通过 `/login` 启动 Codex 配对,引导活跃的 Codex 运行,并在临时 API 故障中恢复最终回复。(#98006, #98126, #98786) 感谢 @100yenadmin, @Kyzcreig 和 @obviyus。
- **事件驱动的 cron 运行:** 新增的 `on-exit` 调度类型可在被监控命令退出时唤醒代理,而针对会话的运行可干净分离。(#92037, #98755) 感谢 @anagnorisis2peripeteia, @obviyus 和 @EthanSK。
- **原生应用刷新:** iOS 采用 iOS 26 视觉系统,提供更清晰的导航、设置、Chat、Talk 和入门引导流程,同时原生应用本地化覆盖 Apple 和 Android 平台。(#98452, #98736, #98811, #97110, #97111, #97112, #97113) 感谢 @vincentkoc。
- **更丰富的消息功能:** iMessage 获得原生投票创建、阅读和投票功能,内置的使用量页脚为聊天中的每轮对话提供更清晰的计数。(#98421, #92657, #92877) 感谢 @omarshahine, @lobster 和 @Marvinthebored。
- **更安全的作用域对话:** 能力配置文件为每个对话设置工具和访问边界,而不削弱现有的默认配置文件。(#98536)
### 变更
- **模型和提供商覆盖:** 添加 GPT-5.6 支持,使用 Nemotron Super 的 1M 上下文窗口,并保留显式的 OpenRouter 认证头。(#98333, #98726, #98187) 感谢 @steipete-oai, @eleqtrizit, @sunlit-deng 和 @laurencebrown。
- **CLI 和节点工作流:** 添加 `openclaw attach`、节点上下文路径支持、可操作的设备审批恢复指南以及更清晰的插件安装退出诊断。(#96454, #97679, #98115, #98146, #98497) 感谢 @anagnorisis2peripeteia, @obviyus, @wm0018, @welfo-beo, @RomneyDa, @Sanjays2402 和 @vincentkoc。
- **Cron 和用量:** 添加退出触发调度、分离的会话定向运行、飞行中任务医生警告以及内置完整用量页脚。(#92037, #98755, #98620, #92657, #92877) 感谢 @anagnorisis2peripeteia, @obviyus, @EthanSK, @masatohoshino 和 @Marvinthebored。
- **原生应用和本地化:** 现代化 iOS 导航、设置、呈现和 Talk 控制,添加 Gateway 语音提供商,改进 QR 入门引导和协议恢复,本地化核心 Apple 和 Android 界面,并添加瑞典移动端本地化。(#98452, #98736, #98811, #98376, #98302, #98385, #97110, #97111, #97112, #97113, #98043) 感谢 @Tony-ooo, @joelnishanth, @cursoragent, @joshavant, @vincentkoc 和 @yeager。
- **消息能力:** 添加原生 iMessage 投票以及 Telegram Codex 配对和引导流程。(#98421, #98006, #98126) 感谢 @omarshahine, @lobster, @100yenadmin 和 @Kyzcreig。
- **医生和诊断:** 暴露认证配置文件、工作区、设备配对、频道插件、内存提供商、systemd 耗尽和 Windows LAN 防火墙发现。(#97125, #97358, #97366, #97496, #97968, #98291, #98666) 感谢 @giodl73-repo, @masatohoshino 和 @joshavant。
- **对话和审查控制:** 准备作用域对话能力配置文件,并添加 Cursor Agent 作为自动审查引擎。(#98536, #97348) 感谢 @hxy91819。
### 修复
- **Telegram 持久性:** 恢复停滞的入站请求,重试重启时丢失的媒体,在临时轮询错误中存活,对毒化更新进行死信处理,保留转发的富文本,正确路由插件回调,并在富最终回复被拒绝时安全回退。(#97118, #98102, #98735, #98775, #98776, #97174, #98786) 感谢 @vincentkoc, @luoyanglang, @DaveArcher18, @obviyus 和 @goldmar。
- **代理和上下文可靠性:** 保留运行时覆盖和引导的子代理任务,防止隔离的 cron `sessions_send` 回复反馈回请求者,改进测试工具感知的上下文估计和压缩预检查,超时静默的本地流,恢复流中故障,并限制 Gateway 运行缓存增长。(#92237, #92283, #77539, #97928, #97861, #98525, #95430, #77973) 感谢 @sercada, @amittell, @liuhao1024, @yetval, @harjothkhara, @nailujac, @osolmaz, @lzyyzznl, @vincentkoc, @alexelgier 和 @fede-kamel。
- **提供商和网络安全:** 限制 Moonshot、MiniMax、Anthropic OAuth、Discord、Matrix、SMS、浏览器、更新、嵌入、Tlön 和 Inworld 路径中的超大或格式错误响应。(#96502, #96322, #96644, #97693, #97889, #97662, #97999, #98455, #98508, #98554, #98496, #98660) 感谢 @hugenshen, @cursoragent, @lsr911, @solodmd, @Alix-007, @wings1029, @lzyyzznl, @sunlit-deng, @vincentkoc 和 @Pandah97。
- **频道投递和路由:** 将 Slack 回复保留在活跃线程中,保留账户绑定的投递路由,应用响应前缀,抑制内部追踪和不必要的回退回复,清除 Nostr 中继发布定时器,并为不透明账户 ID 保留微信会话路由。(#97168, #98240, #89949, #93639, #97989, #80928, #98720, #93686) 感谢 @LiuwqGit, @gorkem2020, @yetval, @wangwllu, @ZengWen-DT, @alexuser, @UnClouded77, @wangmiao0668000666, @zhangLei99586, @zhangguiping-xydt 和 @htkillermax-gif。
- **Cron 正确性:** 在超时时保留提供商和模型选择,保留启动追赶延迟,保留需要操作的操作输出,清除空白的思考覆盖,并保留提供商拥有的每日重置会话。(#95943, #94022, #93810, #96393, #96293, #98356) 感谢 @ZengWen-DT, @cursoragent, @luke-renjoy, @RichChen01, @vincentkoc, @yetval, @snowzlmbot, @nz365guy 和 @takamasa-aiso。
- **内存和会话恢复:** 检测未索引的转录,在笔记更新和 ChatGPT 导入期间通过临时 Wiki 读取保留笔记和手动编辑的前置元数据,而不削弱目录和硬链接冲突防护,避免跨目录恢复,消除保留的 Wiki 索引页歧义,并跳过空的 QMD 同步工作。(#97857, #98360, #98787, #97785, #94326, #90030) 感谢 @zw-xysk, @CHE10X, @qingminglong, @yetval, @vincentkoc, @sahibzada-allahyar 和 @ruben2000de。
- **Windows 和执行:** 将白名单执行绑定到验证的 Windows 路径,传播 `PATHEXT`,对入站路径进行不区分大小写规范化,并防止 Windows 上的清理崩溃。(#98260, #98093, #97630, #97901) 感谢 @eleqtrizit, @wendy-chsy, @VectorPeak 和 @paulcam206。
- **移动端和 UI 稳定性:** 保留 iOS 聊天换行和最终回复,改进 Android 配对和 TLS 恢复,隐藏过期的配对卡片,并保持工作区文件导轨可滚动。(#98304, #98117, #98366, #98439, #98483, #98049, #98646, #98611) 感谢 @joshavant, @Jabato01, @ooiuuii, @wuqxuan, @645648406-max 和 @zw-xysk。
- **Codex 和审批流程:** 正确报告 ChatGPT 认证,在侧边对话中保留插件应用审批,将破坏性审批模式重命名为 `ask`,准确分类动态目标和会话工具结果,并从显式运行截止时间推导终端空闲超时。(#91240, #98812, #98501, #98659, #96856, #85296) 感谢 @849261680, @ukstem, @kevinslin, @yetval, @nxmxbbd, @alkor2000 和 @vincentkoc。
- **配置和插件健康:** 暴露无法加载的频道插件,在补丁期间保留默认的提供商基础 URL,通过清单合约验证捆绑的插件更新,并在需要时保留旧版 ClawHub 家族。(#96397, #98396, #98010, #98249) 感谢 @849261680, @momothemage, @weltmaister, @LiLan0125, @herove 和 @Patrick-Erichsen。
- **Gateway、浏览器和设置诊断:** 区分可达的 Gateway 和失败的状态探测,在设置期间拒绝松散解析的 Gateway 端口,并避免从空路径创建杂散的 Chrome 配置文件配置键。(#98183, #98689, #98138) 感谢 @masatohoshino, @qingminglong 和 @zhangLei99586。
### 完整的贡献记录
这份经过审计的记录涵盖了完整的 66e676d29b92d040716376a75aca32bad655cfac..HEAD 历史:222 个合并的 PR。生成清单也提供了直接提交作为编辑输入;上面的分组注释优先考虑用户影响。
#### 拉取请求
- **PR #96502** fix(moonshot): 限制视频描述 JSON 响应读取。感谢 @hugenshen 和 @cursoragent。
- **PR #98249** 为选定的插件保留旧版 ClawHub 家族。感谢 @Patrick-Erichsen。
- **PR #93767** fix(reasoning-tags): 剥离 MiniMax `mm:` 命名空间的推理标签。感谢 @DrHack1。
- **PR #93820** fix(imessage): 在反射防护中识别 MiniMax mm: 推理标签(完成 #93767)。感谢 @Alix-007。
- **PR #94096** fix(usage): 拒绝 usage.cost 和 sessions.usage 中反转的 startDate-endDate 范围。感谢 @Alix-007。
- **PR #97125** Doctor: 暴露认证配置文件发现。感谢 @giodl73-repo。
- **PR #98256** fix(mcp): 要求 Claude 权限回复的所有者。感谢 @eleqtrizit。
- **PR #98142** fix(cli): 防止 `pairing list` 在空频道枚举时崩溃。感谢 @RomneyDa。
- **PR #98260** fix(exec): 绑定 Windows 白名单执行路径。感谢 @eleqtrizit。
- **PR #97118** fix(telegram): 恢复停滞的入站请求。感谢 @vincentkoc。
- **PR #97168** fix(slack): 为继承的出站回复优先选择当前线程会话。相关 #96535。感谢 @LiuwqGit 和 @gorkem2020。
- **PR #97769** fix(plugins): 将输出文本转换应用于 toolcall_delta 和 toolcall_end 事件。相关 #97761。感谢 @ZOOWH 和 @get-viti。
- **PR #96544** fix(doctor): 合并冲突的模型引用映射键而不是丢弃。感谢 @yetval 和 @vincentkoc。
- **PR #97177** fix(memory-wiki): 优雅处理 vault 扫描中无法解析的 YAML 前置元数据 (#96125)。感谢 @SunnyShu0925 和 @cow11023。
- **PR #97167** 修复 #96840:[Bug]: 在 WebChat 中,无目标的消息发送失败,提示 'Action send requires a target',尽管文档说明源回复接收器应处理。感谢 @zhangguiping-xydt 和 @MantisCartography。
- **PR #98302** fix(ios): 在 QR 扫描后推进入门引导步骤。相关 #98297。感谢 @joelnishanth 和 @cursoragent。
- **PR #96644** fix(anthropic-oauth): 限制 OAuth 令牌端点响应读取。感谢 @solodmd。
- **PR #96397** fix: 当配置的频道插件无法加载时发出警告。感谢 @849261680。
- **PR #96359** test: 将 src/commands 测试迁移到共享临时目录助手。感谢 @xialonglee。
- **PR #96293** fix(cron): 通过清空字段清除 agentTurn 思考覆盖。相关 #96287。感谢 @ZengWen-DT 和 @takamasa-aiso。
- **PR #96058** test: 在自动回复和安装回退测试中优先使用共享临时目录助手。感谢 @xialonglee。
- **PR #87298** test: 添加临时目录助手指南。感谢 @hxy91819。
- **PR #97785** fix(sessions): 避免跨工作目录的近期恢复。相关 #96542。感谢 @qingminglong 和 @yetval。
- **PR #97698** fix(pdf): 在本机分析前拒绝空的解析页面范围。感谢 @zhangguiping-xydt。
- **PR #97693** fix(discord): 限制 requestDiscord 正常路径响应读取以防止 OOM。感谢 @Alix-007。
- **PR #97683** fix(irc): 在 \u 字面量转义解码器中保护替代范围码点。感谢 @llagy009。
- **PR #96938** fix(utils): 保持回复指令 ID 为 Unicode 安全。感谢 @ly-wang19。
- **PR #97857** fix(memory): 在状态模式下检测未索引的会话转录(修复 #97814)。感谢 @zw-xysk 和 @CHE10X。
- **PR #98094** fix(android): 澄清网关认证恢复状态。感谢 @qingminglong。
- **PR #98205** test(gateway): 为节点唤醒状态跟踪和测试接缝添加单元测试。感谢 @zenglingbiao。
- **PR #98115** fix: 从设备 CLI 表面节点审批指南。感谢 @welfo-beo。
- **PR #97898** docs: 澄清源检出 Node 最低版本。相关 #97792。感谢 @lin-hongkuan 和 @aniruddhaadak80。
- **PR #94526** test(telegram): 为带有流式推理的论坛主题 message_thread_id 添加回归测试。相关 #89352。感谢 @xialonglee 和 @pmika。
- **PR #98145** fix(device-pairing): 不在子集重新请求时搅动 requestId。感谢 @RomneyDa。
- **PR #98267** fix(system-prompt): 将执行审批 + 授权发送者移动到缓存边界下方。相关 #98261。感谢 @headbouyJB。
- **PR #98304** fix: 保留 iOS 聊天换行。相关 #98028。感谢 @joshavant 和 @Jabato01。
- **PR #98187** fix(openrouter): 发送显式认证头。相关 #97934。感谢 @sunlit-deng 和 @laurencebrown。
- **PR #95708** fix: 在工具活动期间显示 WebChat 前言进度。感谢 @ragesaq。
- **PR #98210** fix(gateway): iOS Talk 将 SecretRef 支持的 API 密钥视为缺失。相关 #98209。感谢 @ooiuuii。
- **PR #98009** test(infra): 为 SQLite 数字规范化添加单元测试。感谢 @dwc1997。
- **PR #98087** test(config): 为 resolveExecCommandHighlighting 添加单元测试。感谢 @solodmd。
- **PR #98219** test(utils): 为 chunkItems 添加单元测试。感谢 @zenglingbiao。
- **PR #98093** fix(core): 在 Windows 上通过 isExecutableFile 传播调用者环境 PATHEXT。感谢 @wendy-chsy。
- **PR #97973** fix(matrix): 防护 JSON.parse 免受畸形 homeserver 响应体影响。感谢 @lsr911。
- **PR #97999** fix(sms): 防护 Twilio JSON.parse 免受畸形 API 响应体影响。感谢 @lsr911。
- **PR #98043** 添加瑞典移动应用本地化。感谢 @yeager。
- **PR #98144** fix(tui): 更正设备范围升级的断开连接文本。感谢 @RomneyDa。
- **PR #98240** fix(agents): 保持合并的投递路由为账户绑定。感谢 @yetval。
- **PR #89949** fix(media): 在任务启动时固定请求者投递路由。感谢 @wangwllu。
- **PR #98226** 编辑裸 Fireworks API 密钥。相关 #98225。感谢 @ooiuuii。
- **PR #98319** docs: 发布 v2026.6.11 版本说明。感谢 @hannesrudolph。
- **PR #98257** fix: 显示频道运行中的状态。感谢 @scotthuang。
- **PR #97931** fix(gateway): 在每日默认重置中保持提供商拥有的 CLI 会话。感谢 @yetval。
- **PR #98325** docs: 刷新 v2026.6.11 文档地图。感谢 @hannesrudolph。
- **PR #97929** fix(auto-reply): 阻止级别指令吃掉下一个消息单词。感谢 @yetval。
- **PR #97928** fix(agents): 在上下文防护字符估算器中估算测试工具角色大小(修复 #97927)。感谢 @liuhao1024 和 @yetval。
- **PR #97861** fix(compaction): 在提示前溢出预检查中计数 bashExecution 和 summary 轮次。感谢 @yetval。
- **PR #97137** doctor: 添加内存搜索 lint 发现。感谢 @giodl73-repo。
- **PR #97358** Doctor: 暴露工作区状态发现。感谢 @giodl73-repo。
- **PR #95622** test(qa-lab): 加强 whatsapp qa 场景。感谢 @mcaxtr。
- **PR #98346** fix: 防止技能创建者绕过工作坊提案。相关 #96054。感谢 @momothemage 和 @xianshishan。
- **PR #98169** fix(heartbeat): 限制承诺扇出提示。感谢 @bdjben。
- **PR #97366** Doctor: 暴露设备配对发现。感谢 @giodl73-repo。
- **PR #98366** fix: Android TLS 指纹验证在慢速握手中超时。相关 #98365。感谢 @joshavant。
- **PR #98353** fix(ios): 默认在 Chat 中打开应用。感谢 @BsnizND。
- **PR #98352** fix(security): 警告代理技能 MCP 边界漂移。感谢 @momothemage。
- **PR #98347** fix: 重试图像描述回退模型。感谢 @momothemage。
- **PR #98117** fix(ios): 避免临时重复的最终回复。相关 #98116。感谢 @ooiuuii 和 @joshavant。
- **PR #98293** fix(gateway): 发出过期的执行审批后续诊断。感谢 @BsnizND。
- **PR #98376** fix(ios): 在 Talk 中使用 Gateway 语音提供商。相关 #98153。感谢 @Tony-ooo。
- **PR #66685** 抑制过期的执行审批后续警告。感谢 @pfrederiksen。
- **PR #98385** fix: 显示可操作的移动设备协议不匹配恢复。相关 #98384。感谢 @joshavant。
- **PR #98146** fix(cli): 解释如何从设备审批死锁中恢复。感谢 @RomneyDa。
- **PR #98423** improve(ios): 澄清 Control 和 Talk 视觉层次。相关 #98397。
- **PR #98217** fix(doctor): 跨设备恢复旧版 cron 归档。感谢 @masatohoshino。
- **PR #98333** feat(openai): 添加 GPT-5.6 系列支持。相关 #98296。感谢 @steipete-oai。
- **PR #96393** fix(cron): 保留需要操作的命令输出。相关 #96346。感谢 @snowzlmbot 和 @nz365guy。
- **PR #98429** fix(ios): 分类 TLS 指纹超时。感谢 @joshavant。
- **PR #98439** fix: Android 设置代码接受本地 mDNS 网关主机。感谢 @joshavant。
- **PR #98443** fix(ios): 改进浅色和深色外观对比度。相关 #98440。
- **PR #97742** fix(llm): 跨提供商保留结构化工具结果文本。感谢 @snowzlmbot。
- **PR #97968** fix(status): 表面未注册的内存嵌入提供商。感谢 @masatohoshino。
- **PR #92237** fix(agents): 保留运行时设置覆盖 [AI 辅助]。感谢 @sercada。
- **PR #95888** fix(active-memory): 警告可变操作事实;将截断的回忆标记为不完整。感谢 @spencer2211。
- **PR #98291** fix(gateway): 表面 systemd 启动限制耗尽。感谢 @masatohoshino。
- **PR #90517** fix(gateway): 提示 web 登录缺少外部插件。相关 #83277。感谢 @TUARAN 和 @carol-iung。
- **PR #98369** test(infra): 为 SQLite user_version pragma 助手添加单元测试。感谢 @dwc1997。
- **PR #98340** fix: 扩展 api.exec 在超时后留下子进程。相关 #98335。感谢 @ooiuuii。
- **PR #92063** fix(ui): 在分段流式传输期间折叠重复的助手组。相关 #63956。感谢 @harjothkhara 和 @contentfree。
- **PR #98354** fix(infra): 防护投递队列膨胀免受损坏的 entry_json 影响。感谢 @Pick-cat。
- **PR #90566** fix(agents): 警告 cron 公告跳过。相关 #68561。感谢 @sahibzada-allahyar 和 @Mibslee。
- **PR #98371** fix(ports): 在赋值前验证 lsof PID 解析。感谢 @lzyyzznl。
- **PR #98356** fix(cron): 在每日默认重置中保持提供商拥有的 CLI 会话。感谢 @yetval。
- **PR #98395** test(shared): 为账户启用防护添加单元测试。感谢 @dwc1997。
- **PR #98411** fix(agents): 从提供商主体中恢复思考错误。相关 #98308。感谢 @sunlit-deng 和 @clearhorizoninvestments。
- **PR #98494** docs(skills): 支持变量可着陆批次扫描。感谢 @vincentkoc。
- **PR #91240** fix: 报告 Codex ChatGPT 状态认证。相关 #91099。感谢 @849261680 和 @ukstem。
- **PR #98370** test(agents): 为思考块检测添加单元测试。感谢 @dwc1997。
- **PR #96711** test: 在配置、网关、cron、crestodian 和状态测试中优先使用共享临时目录助手。感谢 @xialonglee。
- **PR #98483** fix: Android QR 扫描启动网关配对。感谢 @joshavant。
- **PR #95230** 修复 docs-list-mdx-pages。感谢 @hugenshen。
- **PR #96322** fix(minimax): 限制 JSON 响应读取以防止 OOM。感谢 @lsr911。
- **PR #95348** 修复 config-chmod-warning。感谢 @hugenshen 和 @cursoragent。
- **PR #95229** fix(copilot): 在 cli-metadata 注册期间防护未定义的 runtime.state。相关 #94516。感谢 @sunlit-deng 和 @cuihaijun。
- **PR #94636** fix(memory): 在提升期间跳过原始片段。感谢 @tayoun。
- **PR #94013** [AI] fix(feishu): 在监视器启动中防护部分 channelRuntime。感谢 @xydt-tanshanshan。
- **PR #93466** [AI] fix(feishu): 在 channelRuntime 回退中防护缺失的入站。感谢 @xydt-tanshanshan。
- **PR #98049** fix: 在 Control UI 中隐藏过期的配对 QR 卡片。相关 #98039。感谢 @ooiuuii。
- **PR #96094** fix(memory): 在 CLI 重新索引后证明实时管理器恢复。相关 #91167。感谢 @849261680 和 @kiagentkronos-cell。
- **PR #98482** fix: 广告路由感知的 LAN Control UI 链接。感谢 @joshavant。
- **PR #71537** 在内存钩子和 session-logs 技能中恢复已归档(.reset)的会话转录。感谢 @injinj。
- **PR #96375** docs(config-agents): 更正 opus 和 gpt 的内置别名表。感谢 @niks999。
- **PR #98453** docs(gateway): 修正 config-channels.md 中 Telegram 流式传输默认值。感谢 @solodmd。
- **PR #98533** fix: 修复托管 CI 基线断言。
- **PR #98421** feat(imessage): 原生投票支持——创建、阅读、投票。感谢 @omarshahine 和 @lobster。
- **PR #98318** docs(matrix): 记录缺失的 streaming.progress 模式、进度子字段和 mentionPatterns 配置。感谢 @wm0018 和 @vincentkoc。
- **PR #97753** docs(onboard): 记录 11 个缺失的非交互式 CLI 标志。感谢 @wm0018 和 @vincentkoc。
- **PR #97851** fix(mattermost): 限制空主体错误响应读取。感谢 @Pick-cat。
- **PR #98360** fix(memory-wiki): 在临时页面读取后保留笔记。相关 #98345。感谢 @qingminglong 和 @yetval。
- **PR #98551** test: 修复陈旧的核心测试类型失败。感谢 @RomneyDa。
- **PR #98455** fix(browser): 在 fetchHttpJson 中限制错误主体读取以防止 OOM。感谢 @wings1029。
- **PR #95906** fix(code-mode): 将 QuickJS 错误名称和消息呈现给模型。感谢 @ZengWen-DT 和 @vincentkoc。
- **PR #97901** fix(agents): 停止 copilot 自动审查在 Windows 上的清理崩溃。感谢 @paulcam206。
- **PR #97923** fix(slack): 在替代边界上截断服务的 arg-menu 选项标签。感谢 @LEXES7。
- **PR #98010** fix(update): 通过清单合约验证捆绑的插件有效载荷。相关 #97985。感谢 @LiLan0125 和 @herove。
- **PR #85296** fix(codex): 从显式运行超时推导终端空闲看门狗。感谢 @alkor2000 和 @vincentkoc。
- **PR #97110** feat(i18n): 添加原生应用语言环境清单。感谢 @vincentkoc。
- **PR #98396** fix: 允许 config.patch 带有默认的提供商 baseUrl。相关 #98270。感谢 @momothemage 和 @weltmaister。
- **PR #98503** fix(usage-bar): 使用 Object.hasOwn 而不是 in 运算符以避免原型链污染。相关 #98466。感谢 @chenyangjun-xy 和 @zhangLei99586。
- **PR #97111** feat(android): 本地化核心网关界面。感谢 @vincentkoc。
- **PR #97630** fix(media): 对 Windows 入站路径进行不区分大小写规范化。感谢 @VectorPeak。
- **PR #82638** fix(agents): 当 models.mode 为 'replace' 时跳过隐式提供商发现 [AI 辅助]。相关 #66957。感谢 @eldar702 和 @wangzhengshu。
- **PR #87917** 修复 sessions json 谱系元数据。相关 #80286。感谢 @zhangguiping-xydt 和 @islandpreneur007。
- **PR #93639** fix(message-tool): 将 messages.responsePrefix 应用于出站发送。感谢 @ZengWen-DT。
- **PR #94440** fix: #94432 将 Cloudflare 挑战 403 分类为 upstream_html 而不是 auth_html。感谢 @lzyyzznl 和 @pbm9z95m6z-hue。
- **PR #98119** fix: 减少 Docker 构建内存压力。相关 #98118。感谢 @zyzo。
- **PR #97679** feat(node): 为 node run/install 添加 --context-path 标志以支持反向 p…。相关 #97678。感谢 @wm0018。
- **PR #98339** fix(irc): 将无主机 nick!user 白名单条目分类为可变。感谢 @yetval。
- **PR #97662** fix(matrix): 限制原始传输响应读取以防止 OOM。感谢 @Alix-007。
- **PR #98137** fix: 提升定时器声明以避免在可中止延迟中出现 TDZ ReferenceError。感谢 @zhangLei99586。
- **PR #98134** fix: 在 Tailscale 二进制探测 Promise.race 中清除超时定时器。感谢 @zhangLei99586。
- **PR #97989** fix(sms): 阻止内部工具追踪横幅到达 SMS 回复。感谢 @ZengWen-DT。
- **PR #97972** fix(browser): CDP 认证在百分比编码的凭据下失败。感谢 @VectorPeak。
- **PR #98063** fix(reply): 当 messages.suppressToolErrors 设置时抑制工具错误进度投递。感谢 @moeedahmed 和 @amittell。
- **PR #94964** fix(reload): 在进程内重启时取消延迟的频道重载。相关 #79487。感谢 @lzyyzznl 和 @tseller。
- **PR #98598** fix: 在定时器修复后恢复主 lint。相关 #98462, #98464。感谢 @zhangLei99586。
- **PR #98587** fix(slack): 防护中继 WebSocket 帧 JSON.parse 免受畸形输入影响。感谢 @lsr911 和 @vincentkoc。
- **PR #90030** fix(memory-core): 跳过 qmd 零命中搜索同步。相关 #90023。感谢 @sahibzada-allahyar 和 @ruben2000de。
- **PR #98493** fix(transcripts): 在错误退出时关闭 readline 接口并销毁读取流。相关 #98467。感谢 @wangmiao0668000666 和 @zhangLei99586。
- **PR #98497** fix(cli): 当插件 npm install 返回空输出时显示退出代码。感谢 @Sanjays2402 和 @vincentkoc。
- **PR #97112** feat(apple): 本地化核心原生应用界面。感谢 @vincentkoc。
- **PR #98610** fix: 在转录测试添加后恢复工具 CI。
- **PR #77539** fix(subagent): 在重启重新分发时保留引导的任务文本。感谢 @amittell。
- **PR #97113** feat(i18n): 刷新所有原生语言环境工件。感谢 @vincentkoc。
- **PR #98620** feat(doctor): 警告飞行中的 cron 作业。感谢 @masatohoshino。
- **PR #98605** test(shared): 为人类可读列表格式化添加单元测试。感谢 @dwc1997。
- **PR #97348** feat(autoreview): 支持 cursor-agent 引擎。感谢 @hxy91819。
- **PR #95943** fix(cron): 在隔离运行超时行中保留提供商/模型。相关 #95873。感谢 @ZengWen-DT, @cursoragent 和 @luke-renjoy。
- **PR #94149** fix(status): 限制 systemd 服务探测,使状态不会在卡住的 systemctl 上挂起 (#84698)。感谢 @ZengWen-DT, @cursoragent 和 @zus-assistant。
- **PR #88159** fix(cli): 在日志跟踪中 journal 回退后重试 logs.tail。感谢 @anyech 和 @vincentkoc。
- **PR #98508** fix(update-check): 限制 npm 注册表 JSON 响应读取以防止 OOM。感谢 @lzyyzznl。
- **PR #98496** fix(tlon): 限制错误响应体读取以防止 OOM。感谢 @Pandah97。
- **PR #98554** fix(openai): 限制嵌入批处理文件下载。感谢 @sunlit-deng 和 @vincentkoc。
- **PR #98652** fix: 停止无效消息超时卡住。
- **PR #77973** fix(gateway): 限制 agentRunCache 以防止在运行扇出时无限增长。相关 #77976。感谢 @fede-kamel 和 @vincentkoc。
- **PR #98525** fix(agents): 在没有第一个事件时超时本地流。感谢 @osolmaz。
- **PR #94022** fix(cron): 在服务状态中持久化启动追赶延迟 ID 以防止读取-RPC 覆盖。相关 #93935。感谢 @RichChen01, @vincentkoc 和 @yetval。
- **PR #93810** fix(cron): 在 start() 维护过程中保留启动溢出追赶延迟。感谢 @yetval 和 @vincentkoc。
- **PR #98623** fix: 媒体工具在自动选择模型时跳过 env-key 提供商插件。感谢 @medns。
- **PR #98665** fix(claude-cli): 在 can_use_tool 允许响应中为 Claude Code 2.1 返回 updatedInput。相关 #95171。感谢 @yetval 和 @carterdawson。
- **PR #94250** fix(feishu): 当 blockStreaming 启用时,将块作为独立消息发送。相关 #55027。感谢 @xialonglee, @vincentkoc 和 @ZichaoLong。
- **PR #93379** fix(whatsapp): 通过命令授权和所有者绕过 LID JID 解析线程化 authDir。相关 #77755。感谢 @xialonglee 和 @jiveshkalra。
- **PR #98646** fix: 保持工作区导轨文件部分可滚动。相关 #98566。感谢 @wuqxuan 和 @645648406-max。
- **PR #98602** fix: iOS Talk 回退设置打开 Voice & Talk。相关 #98593。感谢 @PollyBot13。
- **PR #98611** fix(ui): 为工作区导轨部分添加 overflow-y:auto 以防止文件列表溢出(修复 #98566)。感谢 @zw-xysk 和 @645648406-max。
- **PR #98619** fix(qa-lab): 凭据租约请求在过大的 Convex 代理响应上失败。感谢 @ZengWen-DT。
- **PR #94326** fix(memory-wiki): 消除保留索引页分叉用于合成和摄取。感谢 @yetval 和 @vincentkoc。
- **PR #98659** fix(codex): 将 get_goal 读取状态分类为成功的动态工具调用。感谢 @yetval。
- **PR #96856** fix(codex): 成功的 sessions_spawn 和 goal 工具结果被记录为失败。感谢 @nxmxbbd。
- **PR #98660** fix(inworld): 防护 voices JSON.parse 免受畸形 API 响应体影响。感谢 @solodmd。
- **PR #95430** fix(embedded-agent-runner): 通过 pumpStreamWithRecovery 泵送异步 streamFn 以进行流中错误恢复。相关 #95429。感谢 @lzyyzznl, @vincentkoc 和 @alexelgier。
- **PR #98644** fix: 工具摘要保留表情符号截断边界。感谢 @ZengWen-DT。
- **PR #80928** fix(telegram): 当插件命令返回 suppressReply: true 时抑制回退回复。相关 #80756。感谢 @alexuser 和 @UnClouded77。
- **PR #98701** fix: 防止 agents-tools 消息测试超时。
- **PR #92657** feat(usage): 提供内置的 /usage 完整页脚。感谢 @Marvinthebored。
- **PR #92877** fix(usage): 使内置页脚在 Telegram 上更易换行。感谢 @Marvinthebored。
- **PR #98126** 恢复 Telegram /steer 用于活跃的 Codex 运行。相关 #81594。感谢 @100yenadmin 和 @Kyzcreig。
- **PR #92037** feat(cron): on-exit 调度——在被监控命令退出时唤醒。感谢 @anagnorisis2peripeteia。
- **PR #98452** feat(ios): 使用 iOS 26 Liquid Glass 现代化应用。
- **PR #98006** 添加 Telegram /login Codex 配对流程。感谢 @100yenadmin。
- **PR #98735** fix(telegram): 保留富文本转发的消息。感谢 @obviyus。
- **PR #97962** refactor(qa): 在流程场景中使用传输原生动作。感谢 @RomneyDa。
- **PR #98726** fix(nvidia): 使用 Nemotron Super 1M 上下文。感谢 @eleqtrizit。
- **PR #98691** fix(imessage): 在投票回显匹配中移除任何位置的 emoji。感谢 @omarshahine。
- **PR #97174** 修复 Telegram 插件回调路由。感谢 @goldmar。
- **PR #89597** fix: 将 QQBot 凭据备份迁移到 SQLite KV。
- **PR #98536** feat: 准备作用域对话能力配置文件。
- **PR #92274** fix(agents): 将嵌入式提示锁定错误分类为永久性公告失败。相关 #91527。感谢 @fsdwen 和 @zackchiutw。
- **PR #98102** fix(telegram): 持久重试重启期间丢失的入站媒体 (#98076)。感谢 @luoyanglang 和 @DaveArcher18。
- **PR #98755** fix(cron): 分离会话定向运行。相关 #98121。感谢 @obviyus 和 @EthanSK。
- **PR #96065** fix(install): 通过 OPENCLAW_SERVICE_MANAGED_ENV_KEYS 管理 config-secretref 环境引用。感谢 @Darren2030 和 @obviyus。
- **PR #98666** fix: 诊断 Windows LAN Gateway 防火墙阻止。感谢 @joshavant。
- **PR #98501** fix(codex): 将破坏性审批模式重命名为 ask。相关 #98499。感谢 @kevinslin。
- **PR #98775** fix(telegram): 在临时 getUpdates 错误中存活并停止每次发送的缓存重写。相关 #98772, #98773。感谢 @obviyus。
- **PR #98776** fix(telegram): 退避、死信和墓碑化排队的更新,以便毒化消息不会阻塞或重复。相关 #98774。感谢 @obviyus。
- **PR #96454** feat(cli): openclaw attach——启动绑定到网关会话的外部测试工具。感谢 @anagnorisis2peripeteia 和 @obviyus。
- **PR #98786** fix(telegram): 最终回复不再因被拒绝的富实体、标题、引用或长洪水等待而丢失。相关 #98778。感谢 @obviyus。
- **PR #97496** Doctor: 暴露频道插件阻塞器发现。感谢 @giodl73-repo。
- **PR #98792** fix(ci): 恢复文档和测试类型检查。
- **PR #98736** improve(ios): 简化 Talk 控制和作曲家对齐。
- **PR #97889** fix(discord): 防护 JSON.parse 免受畸形 API 响应体影响。感谢 @lsr911。
- **PR #98812** fix(codex): 在侧边对话中保留插件应用审批。
- **PR #92283** fix(agents): 不将 A2A 轮次注入隔离的 cron sessions_send (#92257)。感谢 @harjothkhara 和 @nailujac。
- **PR #98138** fix: 在 Chrome 配置文件装饰中防护 setDeep 免受空键数组影响。感谢 @zhangLei99586。
- **PR #98183** fix(gateway): 区分可达网关和失败的状态探测。感谢 @masatohoshino。
- **PR #98689** fix(wizard): 拒绝松散网关端口输入。相关 #98681。感谢 @qingminglong。
- **PR #98720** fix(nostr): 清除每个中继的发布超时定时器以防止悬垂句柄。相关 #98463。感谢 @wangmiao0668000666 和 @zhangLei99586。
- **PR #98818** fix(ci): 恢复不完整的 Swift 构建缓存。
- **PR #98787** fix(memory-wiki): 在 wiki_apply 和 chatgpt 导入中重试临时现有页面读取。感谢 @yetval。
- **PR #98811** feat(ios): 现代化导航和设置。相关 #98803。
- **PR #98843** docs: 更新移动应用发布消息。感谢 @joshavant。
- **PR #93686** fix(weixin): startAccount 保留会话路由。相关 #93556。感谢 @zhangguiping-xydt 和 @htkillermax-gif。
### 发布验证
- npm 包:https://www.npmjs.com/package/openclaw/v/2026.7.1-beta.1
- 注册表 tarball:https://registry.npmjs.org/openclaw/-/openclaw-2026.7.1-beta.1.tgz
- 完整性:`sha512-Yu/ELLje9mxvFTlaxVGHnIkKvHcLnoEj3AQhzmhpP4k8Fi7/ln0NvYnBgaZ2BJ8tdAAsq3iZ8uroRUuXiMB0dg==`
- 发布 SHA:`4eb1d333cfeca440b796b6a3f70d3c2bef996243`
- 完整发布 CI 报告:https://github.com/openclaw/releases/blob/main/evidence/2026.7.1-beta.1/release-evidence.md
- 发布发布:https://github.com/openclaw/openclaw/actions/runs/28571485937
- npm 预检:https://github.com/openclaw/openclaw/actions/runs/28569693832
- 完整发布验证:https://github.com/openclaw/openclaw/actions/runs/28569693812
- 插件 npm 发布:https://github.com/openclaw/openclaw/actions/runs/28571834366
- 插件 ClawHub 发布:成功:https://github.com/openclaw/openclaw/actions/runs/28571835541
- 插件 ClawHub 引导:不需要
- OpenClaw npm 发布:https://github.com/openclaw/openclaw/actions/runs/28572195585
- 包 Telegram E2E:在发布检查中通过:https://github.com/openclaw/openclaw/actions/runs/28569815816/job/84705725486
- 咨询 WhatsApp 实时 QA:在两次尝试后因 Convex 凭据池耗尽而在场景前被阻止:https://github.com/openclaw/openclaw/actions/runs/28569693831
### Highlights
- **OpenAI GPT-5.6 support:** OpenClaw now recognizes the GPT-5.6 model family across catalog, capability, and runtime selection paths. (#98333) Thanks @steipete-oai.
- **External harness attachment:** `openclaw attach` launches an external harness against an existing Gateway session, making interactive Codex-style workflows easier to resume and inspect. (#96454) Thanks @anagnorisis2peripeteia and @obviyus.
- **Telegram Codex workflows:** Telegram can now start Codex pairing with `/login`, steer active Codex runs, and recover final replies across transient API failures. (#98006, #98126, #98786) Thanks @100yenadmin, @Kyzcreig, and @obviyus.
- **Event-driven cron runs:** the new `on-exit` schedule kind wakes an agent when a watched command exits, while session-targeted runs can detach cleanly. (#92037, #98755) Thanks @anagnorisis2peripeteia, @obviyus, and @EthanSK.
- **Native app refresh:** iOS adopts the iOS 26 visual system with clearer navigation, settings, Chat, Talk, and onboarding flows, while native app localization expands across Apple and Android surfaces. (#98452, #98736, #98811, #97110, #97111, #97112, #97113) Thanks @vincentkoc.
- **Richer messaging:** iMessage gains native poll creation, reading, and voting, and built-in usage footers provide clearer per-turn accounting in chat. (#98421, #92657, #92877) Thanks @omarshahine, @lobster, and @Marvinthebored.
- **Safer scoped conversations:** capability profiles prepare per-conversation tool and access boundaries without weakening the existing default profile. (#98536)
### Changes
- **Model and provider coverage:** add GPT-5.6 support, use Nemotron Super's 1M context window, and preserve explicit OpenRouter authentication headers. (#98333, #98726, #98187) Thanks @steipete-oai, @eleqtrizit, @sunlit-deng, and @laurencebrown.
- **CLI and node workflows:** add `openclaw attach`, node context-path support, actionable device-approval recovery guidance, and clearer plugin install exit diagnostics. (#96454, #97679, #98115, #98146, #98497) Thanks @anagnorisis2peripeteia, @obviyus, @wm0018, @welfo-beo, @RomneyDa, @Sanjays2402, and @vincentkoc.
- **Cron and usage:** add exit-triggered schedules, detached session-targeted runs, an in-flight job doctor warning, and a built-in full usage footer. (#92037, #98755, #98620, #92657, #92877) Thanks @anagnorisis2peripeteia, @obviyus, @EthanSK, @masatohoshino, and @Marvinthebored.
- **Native apps and localization:** modernize iOS navigation, settings, presentation, and Talk controls, add Gateway speech providers, improve QR onboarding and protocol recovery, localize core Apple and Android surfaces, and add Swedish mobile localization. (#98452, #98736, #98811, #98376, #98302, #98385, #97110, #97111, #97112, #97113, #98043) Thanks @Tony-ooo, @joelnishanth, @cursoragent, @joshavant, @vincentkoc, and @yeager.
- **Messaging capabilities:** add native iMessage polls and Telegram Codex pairing and steering flows. (#98421, #98006, #98126) Thanks @omarshahine, @lobster, @100yenadmin, and @Kyzcreig.
- **Doctor and diagnostics:** expose auth-profile, workspace, device-pairing, channel-plugin, memory-provider, systemd exhaustion, and Windows LAN firewall findings. (#97125, #97358, #97366, #97496, #97968, #98291, #98666) Thanks @giodl73-repo, @masatohoshino, and @joshavant.
- **Conversation and review controls:** prepare scoped conversation capability profiles and add Cursor Agent as an autoreview engine. (#98536, #97348) Thanks @hxy91819.
### Fixes
- **Telegram durability:** recover stalled ingress claims, retry restart-dropped media, survive transient polling errors, dead-letter poison updates, preserve forwarded rich text, route plugin callbacks correctly, and fall back safely when rich final replies are rejected. (#97118, #98102, #98735, #98775, #98776, #97174, #98786) Thanks @vincentkoc, @luoyanglang, @DaveArcher18, @obviyus, and @goldmar.
- **Agent and context reliability:** preserve runtime overrides and steered subagent tasks, keep isolated cron `sessions_send` replies from feeding back into the requester, improve harness-aware context estimation and compaction prechecks, time out silent local streams, recover mid-stream failures, and cap Gateway run-cache growth. (#92237, #92283, #77539, #97928, #97861, #98525, #95430, #77973) Thanks @sercada, @amittell, @liuhao1024, @yetval, @harjothkhara, @nailujac, @osolmaz, @lzyyzznl, @vincentkoc, @alexelgier, and @fede-kamel.
- **Provider and network safety:** bound oversized or malformed responses across Moonshot, MiniMax, Anthropic OAuth, Discord, Matrix, SMS, browser, update, embeddings, Tlön, and Inworld paths. (#96502, #96322, #96644, #97693, #97889, #97662, #97999, #98455, #98508, #98554, #98496, #98660) Thanks @hugenshen, @cursoragent, @lsr911, @solodmd, @Alix-007, @wings1029, @lzyyzznl, @sunlit-deng, @vincentkoc, and @Pandah97.
- **Channel delivery and routing:** keep Slack replies in the active thread, preserve account-bound delivery routes, apply response prefixes, suppress internal traces and unwanted fallback replies, clear Nostr relay publish timers, and retain WeChat session routing for opaque account ids. (#97168, #98240, #89949, #93639, #97989, #80928, #98720, #93686) Thanks @LiuwqGit, @gorkem2020, @yetval, @wangwllu, @ZengWen-DT, @alexuser, @UnClouded77, @wangmiao0668000666, @zhangLei99586, @zhangguiping-xydt, and @htkillermax-gif.
- **Cron correctness:** preserve provider and model selections on timeouts, retain startup catch-up deferrals, keep action-required output, clear blank thinking overrides, and preserve provider-owned daily-reset sessions. (#95943, #94022, #93810, #96393, #96293, #98356) Thanks @ZengWen-DT, @cursoragent, @luke-renjoy, @RichChen01, @vincentkoc, @yetval, @snowzlmbot, @nz365guy, and @takamasa-aiso.
- **Memory and session recovery:** detect unindexed transcripts, preserve notes and hand-edited frontmatter through transient wiki reads during note updates and ChatGPT imports without weakening directory and hardlink collision guards, avoid cross-directory resumes, disambiguate reserved wiki index pages, and skip empty QMD sync work. (#97857, #98360, #98787, #97785, #94326, #90030) Thanks @zw-xysk, @CHE10X, @qingminglong, @yetval, @vincentkoc, @sahibzada-allahyar, and @ruben2000de.
- **Windows and execution:** bind allowlisted execution to the validated Windows path, propagate `PATHEXT`, normalize inbound paths case-insensitively, and prevent cleanup crashes on Windows. (#98260, #98093, #97630, #97901) Thanks @eleqtrizit, @wendy-chsy, @VectorPeak, and @paulcam206.
- **Mobile and UI stability:** preserve iOS chat line breaks and final replies, improve Android pairing and TLS recovery, hide expired pairing cards, and keep workspace file rails scrollable. (#98304, #98117, #98366, #98439, #98483, #98049, #98646, #98611) Thanks @joshavant, @Jabato01, @ooiuuii, @wuqxuan, @645648406-max, and @zw-xysk.
- **Codex and approval flows:** report ChatGPT authentication correctly, preserve plugin app approvals in side conversations, rename destructive approval mode to `ask`, classify dynamic goal and session tool results accurately, and derive terminal-idle timeouts from the explicit run deadline. (#91240, #98812, #98501, #98659, #96856, #85296) Thanks @849261680, @ukstem, @kevinslin, @yetval, @nxmxbbd, @alkor2000, and @vincentkoc.
- **Configuration and plugin health:** surface unloadable channel plugins, preserve defaulted provider base URLs during patches, validate bundled plugin updates by manifest contract, and retain legacy ClawHub families where required. (#96397, #98396, #98010, #98249) Thanks @849261680, @momothemage, @weltmaister, @LiLan0125, @herove, and @Patrick-Erichsen.
- **Gateway, browser, and setup diagnostics:** distinguish a reachable Gateway from a failed status probe, reject loosely parsed Gateway ports during setup, and avoid creating stray Chrome profile configuration keys from empty paths. (#98183, #98689, #98138) Thanks @masatohoshino, @qingminglong, and @zhangLei99586.
### Complete contribution record
This audited record covers the complete 66e676d29b92d040716376a75aca32bad655cfac..HEAD history: 222 merged PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.
#### Pull requests
- **PR #96502** fix(moonshot): bound video description JSON response reads. Thanks @hugenshen and @cursoragent.
- **PR #98249** Preserve legacy ClawHub family for selected plugins. Thanks @Patrick-Erichsen.
- **PR #93767** fix(reasoning-tags): strip MiniMax `mm:` namespaced reasoning tags. Thanks @DrHack1.
- **PR #93820** fix(imessage): recognize MiniMax mm: reasoning tags in reflection guard (completes #93767). Thanks @Alix-007.
- **PR #94096** fix(usage): reject inverted startDate-endDate range in usage.cost and sessions.usage. Thanks @Alix-007.
- **PR #97125** Doctor: expose auth profile findings. Thanks @giodl73-repo.
- **PR #98256** fix(mcp): require owner for Claude permission replies. Thanks @eleqtrizit.
- **PR #98142** fix(cli): stop `pairing list` crashing with empty channel enum. Thanks @RomneyDa.
- **PR #98260** fix(exec): bind Windows allowlist execution path. Thanks @eleqtrizit.
- **PR #97118** fix(telegram): recover stalled ingress spool claims. Thanks @vincentkoc.
- **PR #97168** fix(slack): prefer current thread session for inherited outbound replies. Related #96535. Thanks @LiuwqGit and @gorkem2020.
- **PR #97769** fix(plugins): apply output text transforms to toolcall_delta and toolcall_end events. Related #97761. Thanks @ZOOWH and @get-viti.
- **PR #96544** fix(doctor): merge colliding model-ref map keys instead of dropping. Thanks @yetval and @vincentkoc.
- **PR #97177** fix(memory-wiki): gracefully handle unparsable YAML frontmatter in vault scans (#96125). Thanks @SunnyShu0925 and @cow11023.
- **PR #97167** fix #96840: [Bug]: Targetless message.send fails with 'Action send requires a target' in WebChat despite docs stating source-reply sink should handle it. Thanks @zhangguiping-xydt and @MantisCartography.
- **PR #98302** fix(ios): advance onboarding step after QR scan. Related #98297. Thanks @joelnishanth and @cursoragent.
- **PR #96644** fix(anthropic-oauth): bound OAuth token endpoint response reads. Thanks @solodmd.
- **PR #96397** fix: warn when configured channel plugins cannot load. Thanks @849261680.
- **PR #96359** test: migrate src/commands tests to shared temp dir helpers. Thanks @xialonglee.
- **PR #96293** fix(cron): clear agentTurn thinking override by blanking the field. Related #96287. Thanks @ZengWen-DT and @takamasa-aiso.
- **PR #96058** test: prefer shared temp dir helpers in auto-reply and install-fallback tests. Thanks @xialonglee.
- **PR #87298** test: add temp directory helper guidance. Thanks @hxy91819.
- **PR #97785** fix(sessions): avoid cross-cwd recent resumes. Related #96542. Thanks @qingminglong and @yetval.
- **PR #97698** fix(pdf): reject empty parsed page ranges before native analysis. Thanks @zhangguiping-xydt.
- **PR #97693** fix(discord): bound requestDiscord happy-path response reads to prevent OOM. Thanks @Alix-007.
- **PR #97683** fix(irc): guard surrogate-range codepoints in \u literal-escape decoder. Thanks @llagy009.
- **PR #96938** fix(utils): keep reply directive ids unicode-safe. Thanks @ly-wang19.
- **PR #97857** fix(memory): detect unindexed session transcripts in status mode (fixes #97814). Thanks @zw-xysk and @CHE10X.
- **PR #98094** fix(android): clarify gateway auth recovery states. Thanks @qingminglong.
- **PR #98205** test(gateway): add unit tests for node wake state tracking and testing seam. Thanks @zenglingbiao.
- **PR #98115** fix: surface node approval guidance from devices CLI. Thanks @welfo-beo.
- **PR #97898** docs: clarify source checkout Node floor. Related #97792. Thanks @lin-hongkuan and @aniruddhaadak80.
- **PR #94526** test(telegram): add regression test for forum topic message_thread_id with streamed reasoning. Related #89352. Thanks @xialonglee and @pmika.
- **PR #98145** fix(device-pairing): don't churn requestId on subset re-requests. Thanks @RomneyDa.
- **PR #98267** fix(system-prompt): move exec-approval + Authorized Senders below cache boundary. Related #98261. Thanks @headbouyJB.
- **PR #98304** fix: preserve iOS chat line breaks. Related #98028. Thanks @joshavant and @Jabato01.
- **PR #98187** fix(openrouter): send explicit auth headers. Related #97934. Thanks @sunlit-deng and @laurencebrown.
- **PR #95708** fix: show WebChat preamble progress during tool activity. Thanks @ragesaq.
- **PR #98210** fix(gateway): iOS Talk treats SecretRef-backed API keys as missing. Related #98209. Thanks @ooiuuii.
- **PR #98009** test(infra): add unit tests for SQLite number normalization. Thanks @dwc1997.
- **PR #98087** test(config): add unit tests for resolveExecCommandHighlighting. Thanks @solodmd.
- **PR #98219** test(utils): add unit tests for chunkItems. Thanks @zenglingbiao.
- **PR #98093** fix(core): propagate caller env PATHEXT through isExecutableFile on Windows. Thanks @wendy-chsy.
- **PR #97973** fix(matrix): guard JSON.parse against malformed homeserver response bodies. Thanks @lsr911.
- **PR #97999** fix(sms): guard Twilio JSON.parse against malformed API response bodies. Thanks @lsr911.
- **PR #98043** Add Swedish mobile app localization. Thanks @yeager.
- **PR #98144** fix(tui): correct disconnect copy for device scope upgrades. Thanks @RomneyDa.
- **PR #98240** fix(agents): keep merged delivery routes account-bound. Thanks @yetval.
- **PR #89949** fix(media): pin requester delivery route when task starts. Thanks @wangwllu.
- **PR #98226** Redact bare Fireworks API keys. Related #98225. Thanks @ooiuuii.
- **PR #98319** docs: publish release notes for v2026.6.11. Thanks @hannesrudolph.
- **PR #98257** fix: show in-progress status for channel runs. Thanks @scotthuang.
- **PR #97931** fix(gateway): keep provider-owned CLI sessions across the daily default reset. Thanks @yetval.
- **PR #98325** docs: refresh docs map for v2026.6.11. Thanks @hannesrudolph.
- **PR #97929** fix(auto-reply): stop level directives from eating the next message word. Thanks @yetval.
- **PR #97928** fix(agents): estimate harness role sizes in context guard char estimator (fixes #97927). Thanks @liuhao1024 and @yetval.
- **PR #97861** fix(compaction): count bashExecution and summary turns in pre-prompt overflow precheck. Thanks @yetval.
- **PR #97137** doctor: add memory search lint findings. Thanks @giodl73-repo.
- **PR #97358** Doctor: expose workspace status findings. Thanks @giodl73-repo.
- **PR #95622** test(qa-lab): harden whatsapp qa scenarios. Thanks @mcaxtr.
- **PR #98346** fix: prevent skill-creator from bypassing workshop proposals. Related #96054. Thanks @momothemage and @xianshishan.
- **PR #98169** fix(heartbeat): scope commitment fan-out prompts. Thanks @bdjben.
- **PR #97366** Doctor: expose device pairing findings. Thanks @giodl73-repo.
- **PR #98366** fix: Android TLS fingerprint verification times out on slow handshakes. Related #98365. Thanks @joshavant.
- **PR #98353** fix(ios): open app on Chat by default. Thanks @BsnizND.
- **PR #98352** fix(security): warn on agent skill MCP boundary drift. Thanks @momothemage.
- **PR #98347** fix: retry image describe fallback models. Thanks @momothemage.
- **PR #98117** fix(ios): avoid transient duplicate final replies. Related #98116. Thanks @ooiuuii and @joshavant.
- **PR #98293** fix(gateway): emit stale exec approval followup diagnostics. Thanks @BsnizND.
- **PR #98376** fix(ios): use Gateway speech providers in Talk. Related #98153. Thanks @Tony-ooo.
- **PR #66685** Suppress expired exec approval followup warnings. Thanks @pfrederiksen.
- **PR #98385** fix: show actionable mobile protocol mismatch recovery. Related #98384. Thanks @joshavant.
- **PR #98146** fix(cli): explain how to recover from device approve deadlock. Thanks @RomneyDa.
- **PR #98423** improve(ios): clarify Control and Talk visual hierarchy. Related #98397.
- **PR #98217** fix(doctor): recover legacy cron archive across devices. Thanks @masatohoshino.
- **PR #98333** feat(openai): add GPT-5.6 series support. Related #98296. Thanks @steipete-oai.
- **PR #96393** fix(cron): preserve action-required command output. Related #96346. Thanks @snowzlmbot and @nz365guy.
- **PR #98429** fix(ios): classify TLS fingerprint timeouts. Thanks @joshavant.
- **PR #98439** fix: Android setup codes accept local mDNS gateway hosts. Thanks @joshavant.
- **PR #98443** fix(ios): improve light and dark appearance contrast. Related #98440.
- **PR #97742** fix(llm): preserve structured tool result text across providers. Thanks @snowzlmbot.
- **PR #97968** fix(status): surface unregistered memory embedding providers. Thanks @masatohoshino.
- **PR #92237** fix(agents): preserve runtime settings overrides [AI-assisted]. Thanks @sercada.
- **PR #95888** fix(active-memory): caveat mutable ops facts; mark truncated recall as incomplete. Thanks @spencer2211.
- **PR #98291** fix(gateway): surface systemd start-limit exhaustion. Thanks @masatohoshino.
- **PR #90517** fix(gateway): hint missing external plugin for web login. Related #83277. Thanks @TUARAN and @carol-iung.
- **PR #98369** test(infra): add unit tests for SQLite user_version pragma helper. Thanks @dwc1997.
- **PR #98340** fix: extension api.exec leaves child processes after timeout. Related #98335. Thanks @ooiuuii.
- **PR #92063** fix(ui): collapse duplicate assistant groups during segmented streaming. Related #63956. Thanks @harjothkhara and @contentfree.
- **PR #98354** fix(infra): guard delivery queue inflate against corrupted entry_json. Thanks @Pick-cat.
- **PR #90566** fix(agents): warn on cron announce skip. Related #68561. Thanks @sahibzada-allahyar and @Mibslee.
- **PR #98371** fix(ports): validate lsof PID parsing before assignment. Thanks @lzyyzznl.
- **PR #98356** fix(cron): keep provider-owned CLI sessions across the daily default reset. Thanks @yetval.
- **PR #98395** test(shared): add unit tests for account enabled guard. Thanks @dwc1997.
- **PR #98411** fix(agents): recover thinking errors from provider body. Related #98308. Thanks @sunlit-deng and @clearhorizoninvestments.
- **PR #98494** docs(skills): support variable landable sweep batches. Thanks @vincentkoc.
- **PR #91240** fix: report Codex ChatGPT status auth. Related #91099. Thanks @849261680 and @ukstem.
- **PR #98370** test(agents): add unit tests for thinking block detection. Thanks @dwc1997.
- **PR #96711** test: prefer shared temp dir helpers in config, gateway, cron, crestodian, and state tests. Thanks @xialonglee.
- **PR #98483** fix: Android QR scan starts gateway pairing. Thanks @joshavant.
- **PR #95230** fix docs-list-mdx-pages. Thanks @hugenshen.
- **PR #96322** fix(minimax): bound JSON response reads to prevent OOM. Thanks @lsr911.
- **PR #95348** fix config-chmod-warning. Thanks @hugenshen and @cursoragent.
- **PR #95229** fix(copilot): guard against undefined runtime.state during cli-metadata registration. Related #94516. Thanks @sunlit-deng and @cuihaijun.
- **PR #94636** fix(memory): skip raw snippets during promotion. Thanks @tayoun.
- **PR #94013** [AI] fix(feishu): guard partial channelRuntime in monitor startup. Thanks @xydt-tanshanshan.
- **PR #93466** [AI] fix(feishu): guard against missing inbound in channelRuntime fallback. Thanks @xydt-tanshanshan.
- **PR #98049** fix: hide expired pairing QR cards in Control UI. Related #98039. Thanks @ooiuuii.
- **PR #96094** fix(memory): prove live manager recovery after CLI reindex. Related #91167. Thanks @849261680 and @kiagentkronos-cell.
- **PR #98482** fix: advertise route-aware LAN Control UI links. Thanks @joshavant.
- **PR #71537** Recover archived (.reset) session transcripts in memory hook + session-logs skill. Thanks @injinj.
- **PR #96375** docs(config-agents): correct built-in alias table for opus and gpt. Thanks @niks999.
- **PR #98453** docs(gateway): fix Telegram streaming default in config-channels.md. Thanks @solodmd.
- **PR #98533** fix: repair hosted CI baseline assertions.
- **PR #98421** feat(imessage): native poll support — create, read, vote. Thanks @omarshahine and @lobster.
- **PR #98318** docs(matrix): document missing streaming.progress mode, progress sub-fields, and mentionPatterns config. Thanks @wm0018 and @vincentkoc.
- **PR #97753** docs(onboard): document 11 missing non-interactive CLI flags. Thanks @wm0018 and @vincentkoc.
- **PR #97851** fix(mattermost): bound null-body error response reads. Thanks @Pick-cat.
- **PR #98360** fix(memory-wiki): preserve notes after transient page reads. Related #98345. Thanks @qingminglong and @yetval.
- **PR #98551** test: fix stale core test type failures. Thanks @RomneyDa.
- **PR #98455** fix(browser): bound error body read in fetchHttpJson to prevent OOM. Thanks @wings1029.
- **PR #95906** fix(code-mode): surface QuickJS error name and message to the model. Thanks @ZengWen-DT and @vincentkoc.
- **PR #97901** fix(agents): stop copilot autoreview cleanup crash on Windows. Thanks @paulcam206.
- **PR #97923** fix(slack): truncate served arg-menu option labels on a surrogate boundary. Thanks @LEXES7.
- **PR #98010** fix(update): validate bundle plugin payloads by manifest contract. Related #97985. Thanks @LiLan0125 and @herove.
- **PR #85296** fix(codex): derive terminal-idle watchdog from explicit run timeout. Thanks @alkor2000 and @vincentkoc.
- **PR #97110** feat(i18n): add native app locale inventory. Thanks @vincentkoc.
- **PR #98396** fix: allow config.patch with defaulted provider baseUrl. Related #98270. Thanks @momothemage and @weltmaister.
- **PR #98503** fix(usage-bar): use Object.hasOwn instead of in operator to avoid prototype chain pollution. Related #98466. Thanks @chenyangjun-xy and @zhangLei99586.
- **PR #97111** feat(android): localize core gateway surfaces. Thanks @vincentkoc.
- **PR #97630** fix(media): normalize Windows inbound paths case-insensitively. Thanks @VectorPeak.
- **PR #82638** fix(agents): skip implicit provider discovery when models.mode is 'replace' [AI-assisted]. Related #66957. Thanks @eldar702 and @wangzhengshu.
- **PR #87917** fix sessions json lineage metadata. Related #80286. Thanks @zhangguiping-xydt and @islandpreneur007.
- **PR #93639** fix(message-tool): apply messages.responsePrefix to outbound sends. Thanks @ZengWen-DT.
- **PR #94440** fix: #94432 classify Cloudflare challenge 403 as upstream_html instead of auth_html. Thanks @lzyyzznl and @pbm9z95m6z-hue.
- **PR #98119** fix: reduce Docker build memory pressure. Related #98118. Thanks @zyzo.
- **PR #97679** feat(node): add --context-path flag to node run/install for reverse-p…. Related #97678. Thanks @wm0018.
- **PR #98339** fix(irc): classify host-less nick!user allowlist entries as mutable. Thanks @yetval.
- **PR #97662** fix(matrix): bound raw transport response reads to prevent OOM. Thanks @Alix-007.
- **PR #98137** fix: hoist timer declaration to avoid TDZ ReferenceError in abortable delay. Thanks @zhangLei99586.
- **PR #98134** fix: clear timeout timer in Tailscale binary probe Promise.race. Thanks @zhangLei99586.
- **PR #97989** fix(sms): stop internal tool-trace banners from reaching SMS replies. Thanks @ZengWen-DT.
- **PR #97972** fix(browser): CDP auth fails with percent-encoded credentials. Thanks @VectorPeak.
- **PR #98063** fix(reply): suppress tool-error progress delivery when messages.suppressToolErrors is set. Thanks @moeedahmed and @amittell.
- **PR #94964** fix(reload): cancel deferred channel reload on in-process restart. Related #79487. Thanks @lzyyzznl and @tseller.
- **PR #98598** fix: restore main lint after timer repairs. Related #98462, #98464. Thanks @zhangLei99586.
- **PR #98587** fix(slack): guard relay WebSocket frame JSON.parse against malformed input. Thanks @lsr911 and @vincentkoc.
- **PR #90030** fix(memory-core): skip qmd zero-hit search sync. Related #90023. Thanks @sahibzada-allahyar and @ruben2000de.
- **PR #98493** fix(transcripts): close readline interface and destroy read stream on error exit. Related #98467. Thanks @wangmiao0668000666 and @zhangLei99586.
- **PR #98497** fix(cli): show exit code when plugin npm install returns empty output. Thanks @Sanjays2402 and @vincentkoc.
- **PR #97112** feat(apple): localize core native app surfaces. Thanks @vincentkoc.
- **PR #98610** fix: restore tooling CI after transcript test addition.
- **PR #77539** fix(subagent): preserve steered task text on restart redispatch. Thanks @amittell.
- **PR #97113** feat(i18n): refresh all native locale artifacts. Thanks @vincentkoc.
- **PR #98620** feat(doctor): warn about in-flight cron jobs. Thanks @masatohoshino.
- **PR #98605** test(shared): add unit tests for human-readable list formatting. Thanks @dwc1997.
- **PR #97348** feat(autoreview): support cursor-agent engine. Thanks @hxy91819.
- **PR #95943** fix(cron): preserve provider/model on isolated-run timeout row. Related #95873. Thanks @ZengWen-DT and @cursoragent and @luke-renjoy.
- **PR #94149** fix(status): bound systemd service probes so status cannot hang on a wedged systemctl (#84698). Thanks @ZengWen-DT and @cursoragent and @zus-assistant.
- **PR #88159** fix(cli): retry logs.tail after journal fallback in logs follow. Thanks @anyech and @vincentkoc.
- **PR #98508** fix(update-check): bound npm registry JSON response read to prevent OOM. Thanks @lzyyzznl.
- **PR #98496** fix(tlon): bound error response body reads to prevent OOM. Thanks @Pandah97.
- **PR #98554** fix(openai): bound embedding batch file downloads. Thanks @sunlit-deng and @vincentkoc.
- **PR #98652** fix: stop invalid message timeouts from stalling.
- **PR #77973** fix(gateway): cap agentRunCache to prevent unbounded growth under run fan-out. Related #77976. Thanks @fede-kamel and @vincentkoc.
- **PR #98525** fix(agents): time out local streams without first event. Thanks @osolmaz.
- **PR #94022** fix(cron): persist startup catch-up deferral ids in service state to prevent read-RPC clobber. Related #93935. Thanks @RichChen01 and @vincentkoc and @yetval.
- **PR #93810** fix(cron): preserve startup overflow catch-up deferrals in start() maintenance pass. Thanks @yetval and @vincentkoc.
- **PR #98623** fix: media tools skip env-key provider plugins when auto-selecting models. Thanks @medns.
- **PR #98665** fix(claude-cli): return updatedInput in can_use_tool allow response for Claude Code 2.1. Related #95171. Thanks @yetval and @carterdawson.
- **PR #94250** fix(feishu): send blocks as independent messages when blockStreaming is enabled. Related #55027. Thanks @xialonglee and @vincentkoc and @ZichaoLong.
- **PR #93379** fix(whatsapp): thread authDir through command authorization and owner bypass for LID JID resolution. Related #77755. Thanks @xialonglee and @jiveshkalra.
- **PR #98646** fix: keep workspace rail file sections scrollable. Related #98566. Thanks @wuqxuan and @645648406-max.
- **PR #98602** fix: iOS Talk fallback settings opens Voice & Talk. Related #98593. Thanks @PollyBot13.
- **PR #98611** fix(ui): add overflow-y:auto to workspace rail sections to prevent file list overflow (fixes #98566). Thanks @zw-xysk and @645648406-max.
- **PR #98619** fix(qa-lab): credential lease requests fail on oversized Convex broker responses. Thanks @ZengWen-DT.
- **PR #94326** fix(memory-wiki): disambiguate the reserved index page stem for synthesis and ingest. Thanks @yetval and @vincentkoc.
- **PR #98659** fix(codex): classify get_goal read statuses as successful dynamic tool calls. Thanks @yetval.
- **PR #96856** fix(codex): successful sessions_spawn and goal tool results recorded as failures. Thanks @nxmxbbd.
- **PR #98660** fix(inworld): guard voices JSON.parse against malformed API response bodies. Thanks @solodmd.
- **PR #95430** fix(embedded-agent-runner): pump async streamFn through pumpStreamWithRecovery for mid-stream error recovery. Related #95429. Thanks @lzyyzznl and @vincentkoc and @alexelgier.
- **PR #98644** fix: tool summaries preserve emoji truncation boundaries. Thanks @ZengWen-DT.
- **PR #80928** fix(telegram): suppress fallback reply when plugin command returns suppressReply: true. Related #80756. Thanks @alexuser and @UnClouded77.
- **PR #98701** fix: prevent agents-tools message test timeouts.
- **PR #92657** feat(usage): ship built-in /usage full footer. Thanks @Marvinthebored.
- **PR #92877** fix(usage): make built-in footer easier to wrap on Telegram. Thanks @Marvinthebored.
- **PR #98126** Restore Telegram /steer for active Codex runs. Related #81594. Thanks @100yenadmin and @Kyzcreig.
- **PR #92037** feat(cron): on-exit schedule — wake on a watched command's exit. Thanks @anagnorisis2peripeteia.
- **PR #98452** feat(ios): modernize the app with iOS 26 Liquid Glass.
- **PR #98006** Add Telegram /login Codex pairing flow. Thanks @100yenadmin.
- **PR #98735** fix(telegram): preserve rich forwarded message text. Thanks @obviyus.
- **PR #97962** refactor(qa): use transport-native actions in flow scenarios. Thanks @RomneyDa.
- **PR #98726** fix(nvidia): use Nemotron Super 1M context. Thanks @eleqtrizit.
- **PR #98691** fix(imessage): shed emoji anywhere in poll-vote echo match. Thanks @omarshahine.
- **PR #97174** Fix Telegram plugin callback routing. Thanks @goldmar.
- **PR #89597** fix: migrate QQBot credential backups to SQLite KV.
- **PR #98536** feat: prepare scoped conversation capability profiles.
- **PR #92274** fix(agents): classify embedded prompt lock error as permanent announce failure. Related #91527. Thanks @fsdwen and @zackchiutw.
- **PR #98102** fix(telegram): durably retry inbound media dropped during restart (#98076). Thanks @luoyanglang and @DaveArcher18.
- **PR #98755** fix(cron): detach session-targeted runs. Related #98121. Thanks @obviyus and @EthanSK.
- **PR #96065** fix(install): manage config-secretref env refs via OPENCLAW_SERVICE_MANAGED_ENV_KEYS. Thanks @Darren2030 and @obviyus.
- **PR #98666** fix: diagnose Windows LAN Gateway firewall blocks. Thanks @joshavant.
- **PR #98501** fix(codex): rename destructive approval mode to ask. Related #98499. Thanks @kevinslin.
- **PR #98775** fix(telegram): survive transient getUpdates errors and stop per-send cache rewrites. Related #98772, #98773. Thanks @obviyus.
- **PR #98776** fix(telegram): back off, dead-letter, and tombstone spooled updates so poison messages cannot block or duplicate. Related #98774. Thanks @obviyus.
- **PR #96454** feat(cli): openclaw attach — launch an external harness bound to a gateway session. Thanks @anagnorisis2peripeteia and @obviyus.
- **PR #98786** fix(telegram): final replies no longer drop on rejected rich entities, captions, quotes, or long flood waits. Related #98778. Thanks @obviyus.
- **PR #97496** Doctor: expose channel plugin blocker findings. Thanks @giodl73-repo.
- **PR #98792** fix(ci): restore docs and test type checks.
- **PR #98736** improve(ios): simplify Talk controls and composer alignment.
- **PR #97889** fix(discord): guard JSON.parse against malformed API response bodies. Thanks @lsr911.
- **PR #98812** fix(codex): preserve plugin app approvals in side conversations.
- **PR #92283** fix(agents): don't inject A2A turns into isolated-cron sessions_send (#92257). Thanks @harjothkhara and @nailujac.
- **PR #98138** fix: guard setDeep against empty keys array in Chrome profile decoration. Thanks @zhangLei99586.
- **PR #98183** fix(gateway): distinguish reachable gateway from failed status probe. Thanks @masatohoshino.
- **PR #98689** fix(wizard): reject loose gateway port input. Related #98681. Thanks @qingminglong.
- **PR #98720** fix(nostr): clear per-relay publish timeout timer to prevent dangling handles. Related #98463. Thanks @wangmiao0668000666 and @zhangLei99586.
- **PR #98818** fix(ci): recover incomplete Swift build caches.
- **PR #98787** fix(memory-wiki): retry transient existing-page reads in wiki_apply and chatgpt import. Thanks @yetval.
- **PR #98811** feat(ios): modernize navigation and settings. Related #98803.
- **PR #98843** docs: update mobile app release messaging. Thanks @joshavant.
- **PR #93686** fix(weixin): startAccount preserves session routing. Related #93556. Thanks @zhangguiping-xydt and @htkillermax-gif.
### Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.7.1-beta.1
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.7.1-beta.1.tgz
- integrity: `sha512-Yu/ELLje9mxvFTlaxVGHnIkKvHcLnoEj3AQhzmhpP4k8Fi7/ln0NvYnBgaZ2BJ8tdAAsq3iZ8uroRUuXiMB0dg==`
- release SHA: `4eb1d333cfeca440b796b6a3f70d3c2bef996243`
- full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.7.1-beta.1/release-evidence.md
- release publish: https://github.com/openclaw/openclaw/actions/runs/28571485937
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/28569693832
- full release validation: https://github.com/openclaw/openclaw/actions/runs/28569693812
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/28571834366
- plugin ClawHub publish: success: https://github.com/openclaw/openclaw/actions/runs/28571835541
- plugin ClawHub bootstrap: not needed
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/28572195585
- package Telegram E2E: passed in release checks: https://github.com/openclaw/openclaw/actions/runs/28569815816/job/84705725486
- advisory WhatsApp live QA: blocked before scenarios by exhausted Convex credential pool after two attempts: https://github.com/openclaw/openclaw/actions/runs/28569693831