### 亮点
- **OpenAI GPT-5.6 支持:** OpenClaw 现在在目录、能力和运行时选择路径中识别 GPT-5.6 模型系列。(#98333)感谢 @steipete-oai。
- **外部测试工具挂载:** `openclaw attach` 针对现有 Gateway 会话启动外部测试工具,使交互式 Codex 风格工作流程更易于恢复和检查。(#96454)感谢 @anagnorisis2peripeteia 和 @obviyus。
- **Telegram Codex 工作流程:** Telegram 现在可以通过 `/login` 启动 Codex 配对,引导活跃的 Codex 运行,并在临时 API 故障中恢复最终回复。(#98006, #98126, #98786)感谢 @100yenadmin, @Kyzcreig 和 @obviyus。
- **事件驱动型 Cron 运行:** 新增 `on-exit` 调度类型,当被监视的命令退出时唤醒代理,而会话目标运行可以干净地分离。(#92037, #98755)感谢 @anagnorisis2peripeteia, @obviyus 和 @EthanSK。
- **原生应用刷新:** iOS 采用 iOS 26 视觉系统,拥有更清晰的聊天、通话、引导和重连流程,同时原生应用本地化扩展到苹果和安卓平台。(#98452, #98736, #99243, #97110, #97111, #97112, #97113)感谢 @jcooley8 和 @vincentkoc。
- **更丰富的消息功能:** iMessage 获得原生投票创建、阅读和投票功能,内置使用量页脚在聊天中提供更清晰的每轮计费。(#98421, #92657, #92877)感谢 @omarshahine, @lobster 和 @Marvinthebored。
- **更安全的范围会话:** 能力配置文件在不削弱现有默认配置文件的情况下,为每个会话准备工具和访问边界。(#98536)
- **Mac 本地 Gateway 设置:** macOS 应用现在可以自动安装和启动其本地 Gateway,减少首次使用前的手动设置。(#99767)
- **控制 UI 导航:** 会话优先的侧边栏、紧凑上下文计量器、暖光主题、推理努力滑块、精简的编辑器以及斜杠命令选择器,使活跃会话和命令更易于访问。(#99289, #99426, #99838)感谢 @VicZhang6 和 @Solvely-Colin。
### 变更
- **ClawRouter 路由和配额:** 添加捆绑的 ClawRouter 提供程序插件,支持基于凭证的动态模型发现、兼容 OpenAI 的原生 Anthropic/Gemini 传输,以及跨 OpenClaw 使用面的管理预算报告。(#99658)
- **模型和提供程序覆盖:** 添加 GPT-5.6 支持,使用 Nemotron Super 的 100 万上下文窗口,并保留显式的 OpenRouter 认证头。(#98333, #98726, #98187)感谢 @steipete-oai, @eleqtrizit, @sunlit-deng 和 @laurencebrown。
- **CLI 和节点工作流程:** 添加 `openclaw attach`、节点上下文路径支持、可操作的设备批准恢复指南、当提示元数据更改时的软恢复 CLI 会话,以及更清晰的插件安装退出诊断。(#96454, #97679, #98115, #98146, #98497, #99822)感谢 @anagnorisis2peripeteia, @obviyus, @wm0018, @welfo-beo, @RomneyDa, @Sanjays2402 和 @vincentkoc。
- **Cron 和使用量:** 添加退出触发的调度、分离的会话目标运行、飞行中作业的医生警告,以及内置的完整使用量页脚。(#92037, #98755, #98620, #92657, #92877)感谢 @anagnorisis2peripeteia, @obviyus, @EthanSK, @masatohoshino 和 @Marvinthebored。
- **原生应用和本地化:** 现代化 iOS 呈现、聊天、通话、引导和重连流程;添加 Gateway 语音提供程序;改进二维码引导和协议恢复;从 macOS 安装本地 Gateway;本地化核心苹果和安卓界面;并添加瑞典语移动端本地化。(#98452, #98736, #99243, #98376, #98302, #98385, #99767, #97110, #97111, #97112, #97113, #98043)感谢 @jcooley8, @Tony-ooo, @joelnishanth, @cursoragent, @joshavant, @vincentkoc 和 @yeager。
- **消息能力:** 添加原生 iMessage 投票、Telegram Codex 配对和引导、Telegram 多通道进度摘要,以及 Signal 目标别名。(#98421, #98006, #98126, #98907, #95738)感谢 @omarshahine, @lobster, @100yenadmin, @Kyzcreig, @Marvinthebored 和 @jesse-merhi。
- **本地推理和聊天控件:** 自动发现 Ollama 推理节点,添加控制 UI 会话优先导航、推理控件和命令选择,并在延迟工具搜索选择了错误工具系列时保持 OpenClaw 控制工具可用。(#99234, #99289, #99426, #99838, #99561)感谢 @100yenadmin, @joshavant, @VicZhang6 和 @Solvely-Colin。
- **医生和诊断:** 暴露认证配置文件、工作区、设备配对、通道插件、内存提供程序、systemd 耗尽和 Windows LAN 防火墙的发现结果。(#97125, #97358, #97366, #97496, #97968, #98291, #98666)感谢 @giodl73-repo, @masatohoshino 和 @joshavant。
- **会话和审查控件:** 准备范围会话能力配置文件,并添加 Cursor Agent 作为自动审查引擎。(#98536, #97348)感谢 @hxy91819。
### 修复
- **ClawRouter 认证配置文件:** 在代理运行期间,当代理密钥存储在认证配置文件中时,解析基于凭证的目录模型,并记录插件和模型允许列表。
- **Telegram 持久性:** 恢复停滞的入口声明,重试重启时丢失的媒体,承受临时轮询错误、死信有毒更新,保留转发的富文本,正确路由插件回调,将进度更新保持在一个稳定的多行窗口中,限制重连队列的耗尽速率,使快速健康轮询不会饿死活跃回复,并在 Telegram 拒绝富文本最终回复时安全回退。(#97118, #98102, #98735, #98775, #98776, #97174, #98907, #98786)感谢 @vincentkoc, @luoyanglang, @DaveArcher18, @obviyus, @goldmar, @Marvinthebored 和 @shakkernerd。
- **代理和上下文可靠性:** 保留运行时覆盖、引导的子代理任务、回退工具调用提示和旧的重种附件;在仅提示漂移时软恢复 CLI 会话;尊重在提供程序提示开始之前在急切会话锁获取期间到达的停止信号;改进与测试工具相关的上下文估计和压缩预检查;超时静默本地流;恢复流中故障;并限制 Gateway 运行缓存增长。(#92237, #77539, #99851, #99839, #99822, #97928, #97861, #98525, #95430, #77973)感谢 @sercada, @amittell, @obviyus, @liuhao1024, @yetval, @osolmaz, @lzyyzznl, @vincentkoc, @alexelgier 和 @fede-kamel。
- **提供程序和网络安全:** 限制 Moonshot、MiniMax、Anthropic OAuth、Discord、Matrix、SMS、浏览器、更新、嵌入、Tlön 和 Inworld 路径中过大或格式错误的响应。(#96502, #96322, #96644, #97693, #97662, #97999, #98455, #98508, #98554, #98496, #98660)感谢 @hugenshen, @cursoragent, @lsr911, @solodmd, @Alix-007, @wings1029, @lzyyzznl, @sunlit-deng, @vincentkoc 和 @Pandah97。
- **通道交付和路由:** 将 Slack 回复保留在活跃线程中,保留基于账户的交付路由,应用响应前缀,抑制内部跟踪和不必要的回退回复,并为不透明账户 ID 保留微信会话路由。(#97168, #98240, #89949, #93639, #97989, #80928, #93686)感谢 @LiuwqGit, @gorkem2020, @yetval, @wangwllu, @ZengWen-DT, @alexuser, @UnClouded77, @zhangguiping-xydt, @htkillermax-gif 和 @vincentkoc。
- **Cron 正确性:** 在超时时保留提供程序和模型选择,保留启动追赶延迟,保留需要操作的输出,清除空白思考覆盖,并保留提供程序拥有的每日重置会话。(#95943, #94022, #93810, #96393, #96293, #98356)感谢 @ZengWen-DT, @cursoragent, @luke-renjoy, @RichChen01, @vincentkoc, @yetval, @snowzlmbot, @nz365guy 和 @takamasa-aiso。
- **内存和会话恢复:** 检测未索引的转录,在临时读取期间保留笔记,避免跨目录恢复,消除保留 wiki 索引页的歧义,并跳过空 QMD 同步工作。(#97857, #98360, #97785, #94326, #90030)感谢 @zw-xysk, @CHE10X, @qingminglong, @yetval, @vincentkoc, @sahibzada-allahyar 和 @ruben2000de。
- **Windows 和执行:** 将允许列表执行绑定到已验证的 Windows 路径,传播 `PATHEXT`,不区分大小写地标准化入站路径,并防止 Windows 上的清理崩溃。(#98260, #98093, #97630, #97901)感谢 @eleqtrizit, @wendy-chsy, @VectorPeak 和 @paulcam206。
- **移动端和 UI 稳定性:** 保留 iOS 聊天换行和最终回复,改进 Android 配对和 TLS 恢复,隐藏过期配对卡片,保持工作区文件导轨可滚动,通过纯 HTTP 恢复复制路径,并停止 Mac 应用控制 UI 中的橡皮筋滚动。(#98304, #98117, #98366, #98439, #98483, #98049, #98646, #98611, #98764, #99830)感谢 @joshavant, @Jabato01, @ooiuuii, @wuqxuan, @645648406-max, @zw-xysk, @ZengWen-DT 和 @adinballew。
- **Codex 和批准流程:** 正确报告 ChatGPT 认证状态,将破坏性批准模式重命名为 `ask`,准确分类动态目标和会话工具结果,并从显式运行截止时间推导终端空闲超时。(#91240, #98501, #98659, #96856, #85296)感谢 @849261680, @ukstem, @kevinslin, @yetval, @nxmxbbd, @alkor2000 和 @vincentkoc。
- **配置和插件健康:** 限制配置遍历到自有属性,保留配置健康恢复状态,显示无法加载的通道插件,在补丁期间保留默认的提供程序基础 URL,按清单合约验证捆绑插件更新,在解析包根时优先安装的启动器目标,以便捆绑通道设置条目从嵌套安装中加载,从安装的插件根解析公共工件,并在需要时保留旧版 ClawHub 系列。(#99846, #99728, #96397, #98396, #98010, #98819, #98249)感谢 @vincentkoc, @zenglingbiao, @joshavant, @jalehman, @ccbridle, @849261680, @momothemage, @weltmaister, @LiLan0125, @herove, @amknight, @KelTech-Services 和 @Patrick-Erichsen。
- **运行时进程安全:** 防止 SSH 隧道、管理器和 MCP stdio 传输中未处理的子流错误;阻止自动回复等待转录镜像;避免在批准预览和 LINE 出站字段中分割 Unicode 字符。(#99800, #99802, #99803, #99549, #99566, #98994)感谢 @cxbAsDev, @vincentkoc, @Shagrat2, @mikasa0818 和 @LEXES7。
- **节点运行时兼容性:** 安装程序、CLI 启动器、医生和 macOS 应用现在拒绝不兼容的 Node 23 运行时,并引导用户使用支持的 Node 22 或 24 版本。(#99832)感谢 @vincentkoc 和 @fuller-stack-dev。
- **QQBot 媒体交付:** 将沙箱生成的媒体发送范围限定到活跃会话的工作区,以便 `/workspace/...` 和相对生成文件路径在 QQBot 媒体标签、结构化负载和流式传输中安全解析。(#92872)感谢 @zhangguiping-xydt 和 @sliverp。
### 完整贡献记录
本审计记录覆盖了从 66e676d29b92d040716376a75aca32bad655cfac 到 1e20f15581f9fe9132768379bd80cc74c047b8cc 的完整历史:455 个合并的 PR。生成清单也提供了直接提交作为编辑输入;上述分组说明优先考虑了用户影响。
#### 拉取请求
- **PR #96502** fix(moonshot): 限制视频描述 JSON 响应读取。感谢 @hugenshen 和 @cursoragent.
- **PR #98249** 为选定插件保留旧版 ClawHub 系列。感谢 @Patrick-Erichsen.
- **PR #93767** fix(reasoning-tags): 去除 MiniMax `mm:` 命名空间的推理标签。感谢 @DrHack1.
- **PR #93820** fix(imessage): 在反射防护中识别 MiniMax mm: 推理标签(完成 #93767)。感谢 @Alix-007.
- **PR #94096** fix(usage): 拒绝 usage.cost 和 sessions.usage 中反转的 startDate-endDate 范围。感谢 @Alix-007.
- **PR #97125** Doctor: 暴露认证配置文件发现结果。感谢 @giodl73-repo.
- **PR #98256** fix(mcp): 要求所有者处理 Claude 权限回复。感谢 @eleqtrizit.
- **PR #98142** fix(cli): 修复 `pairing list` 在空通道枚举时崩溃。感谢 @RomneyDa.
- **PR #98260** fix(exec): 绑定 Windows 允许列表执行路径。感谢 @eleqtrizit.
- **PR #97118** fix(telegram): 恢复停滞的入口存储声明。感谢 @vincentkoc.
- **PR #97168** fix(slack): 优先选择当前线程会话用于继承的出站回复。相关 #96535。感谢 @LiuwqGit 和 @gorkem2020.
- **PR #97769** fix(plugins): 对 toolcall_delta 和 toolcall_end 事件应用输出文本转换。相关 #97761。感谢 @ZOOWH 和 @get-viti.
- **PR #96544** fix(doctor): 合并冲突的模型引用映射键而非丢弃。感谢 @yetval 和 @vincentkoc.
- **PR #97177** fix(memory-wiki): 优雅处理保险库扫描中不可解析的 YAML 前置元数据 (#96125)。感谢 @SunnyShu0925 和 @cow11023.
- **PR #97167** 修复 #96840: [Bug]: 在 WebChat 中,无目标消息发送失败,提示 'Action send requires a target',尽管文档指出源回复接收器应处理。感谢 @zhangguiping-xydt 和 @MantisCartography.
- **PR #98302** fix(ios): 在二维码扫描后前进引导步骤。相关 #98297。感谢 @joelnishanth 和 @cursoragent.
- **PR #96644** fix(anthropic-oauth): 限制 OAuth 令牌端点响应读取。感谢 @solodmd.
- **PR #96397** fix: 当配置的通道插件无法加载时发出警告。感谢 @849261680.
- **PR #96359** test: 将 src/commands 测试迁移到共享临时目录辅助函数。感谢 @xialonglee.
- **PR #96293** fix(cron): 通过清空字段清除 agentTurn 思考覆盖。相关 #96287。感谢 @ZengWen-DT 和 @takamasa-aiso.
- **PR #96058** test: 在自动回复和安装回退测试中优先使用共享临时目录辅助函数。感谢 @xialonglee.
- **PR #87298** test: 添加临时目录辅助函数指南。感谢 @hxy91819.
- **PR #97785** fix(sessions): 避免跨 cwd 的最近恢复。相关 #96542。感谢 @qingminglong 和 @yetval.
- **PR #97698** fix(pdf): 在原生分析之前拒绝空的解析页面范围。感谢 @zhangguiping-xydt.
- **PR #97693** fix(discord): 限制 requestDiscord 正常路径响应读取以防止 OOM。感谢 @Alix-007.
- **PR #97683** fix(irc): 在 \u 字面量转义解码器中保护代理对码点。感谢 @llagy009.
- **PR #96938** fix(utils): 保持回复指令 ID 的 Unicode 安全。感谢 @ly-wang19.
- **PR #97857** fix(memory): 在状态模式下检测未索引的会话转录(修复 #97814)。感谢 @zw-xysk 和 @CHE10X.
- **PR #98094** fix(android): 阐明网关认证恢复状态。感谢 @qingminglong.
- **PR #98205** test(gateway): 为节点唤醒状态跟踪和测试接缝添加单元测试。感谢 @zenglingbiao.
- **PR #98115** fix: 从设备 CLI 展示节点批准指南。感谢 @welfo-beo.
- **PR #97898** docs: 阐明源码检出 Node 下限。相关 #97792。感谢 @lin-hongkuan 和 @aniruddhaadak80.
- **PR #94526** test(telegram): 为带有流式推理的论坛主题 message_thread_id 添加回归测试。相关 #89352。感谢 @xialonglee 和 @pmika.
- **PR #98145** fix(device-pairing): 在子集重新请求时不更改 requestId。感谢 @RomneyDa.
- **PR #98267** fix(system-prompt): 将 exec-approval + Authorized Senders 移动到缓存边界以下。相关 #98261。感谢 @headbouyJB.
- **PR #98304** fix: 保留 iOS 聊天换行。相关 #98028。感谢 @joshavant 和 @Jabato01.
- **PR #98187** fix(openrouter): 发送显式认证头。相关 #97934。感谢 @sunlit-deng 和 @laurencebrown.
- **PR #95708** fix: 在工具活动期间显示 WebChat 前置进度。感谢 @ragesaq.
- **PR #98210** fix(gateway): iOS Talk 将 SecretRef 支持的 API 密钥视为缺失。相关 #98209。感谢 @ooiuuii.
- **PR #98009** test(infra): 为 SQLite 数字规范化添加单元测试。感谢 @dwc1997.
- **PR #98087** test(config): 为 resolveExecCommandHighlighting 添加单元测试。感谢 @solodmd.
- **PR #98219** test(utils): 为 chunkItems 添加单元测试。感谢 @zenglingbiao.
- **PR #98093** fix(core): 在 Windows 上通过 isExecutableFile 传播调用者环境 PATHEXT。感谢 @wendy-chsy.
- **PR #97973** fix(matrix): 保护 JSON.parse 免受格式错误的 homeserver 响应体的影响。感谢 @lsr911.
- **PR #97999** fix(sms): 保护 Twilio JSON.parse 免受格式错误的 API 响应体的影响。感谢 @lsr911.
- **PR #98043** 添加瑞典语移动应用本地化。感谢 @yeager.
- **PR #98144** fix(tui): 更正设备范围升级的断开连接副本。感谢 @RomneyDa.
- **PR #98240** fix(agents): 将合并的交付路由保留为账户绑定。感谢 @yetval.
- **PR #89949** fix(media): 在任务开始时固定请求者交付路由。感谢 @wangwllu.
- **PR #98226** 编辑裸露的 Fireworks API 密钥。相关 #98225。感谢 @ooiuuii.
- **PR #98319** docs: 发布 v2026.6.11 发行说明。感谢 @hannesrudolph.
- **PR #98257** fix: 显示通道运行的进行中状态。感谢 @scotthuang.
- **PR #97931** fix(gateway): 在每日默认重置中保留提供程序拥有的 CLI 会话。感谢 @yetval.
- **PR #98325** docs: 为 v2026.6.11 刷新文档地图。感谢 @hannesrudolph.
- **PR #97929** fix(auto-reply): 阻止级别指令吃掉下一条消息单词。感谢 @yetval.
- **PR #97928** fix(agents): 在上下文防护字符估计器中估算测试工具角色大小(修复 #97927)。感谢 @liuhao1024 和 @yetval.
- **PR #97861** fix(compaction): 在提示前溢出预检查中计算 bashExecution 和 summary 轮次。感谢 @yetval.
- **PR #97137** doctor: 添加内存搜索 lint 发现结果。感谢 @giodl73-repo.
- **PR #97358** Doctor: 暴露工作区状态发现结果。感谢 @giodl73-repo.
- **PR #95622** test(qa-lab): 加固 whatsapp qa 场景。感谢 @mcaxtr.
- **PR #98346** fix: 防止技能创建者绕过工作坊提案。相关 #96054。感谢 @momothemage 和 @xianshishan.
- **PR #98169** fix(heartbeat): 限定承诺扇出提示的范围。感谢 @bdjben.
- **PR #97366** Doctor: 暴露设备配对发现结果。感谢 @giodl73-repo.
- **PR #98366** fix: Android TLS 指纹验证在慢速握手时超时。相关 #98365。感谢 @joshavant.
- **PR #98353** fix(ios): 默认在聊天中打开应用。感谢 @BsnizND.
- **PR #98352** fix(security): 在代理技能 MCP 边界漂移时发出警告。感谢 @momothemage.
- **PR #98347** fix: 重试图像描述回退模型。感谢 @momothemage.
- **PR #98117** fix(ios): 避免临时重复的最终回复。相关 #98116。感谢 @ooiuuii 和 @joshavant.
- **PR #98293** fix(gateway): 发出过期的执行批准跟进诊断。感谢 @BsnizND.
- **PR #98376** fix(ios): 在通话中使用 Gateway 语音提供程序。相关 #98153。感谢 @Tony-ooo.
- **PR #66685** 抑制过期的执行批准跟进警告。感谢 @pfrederiksen.
- **PR #98385** fix: 显示可操作的移动端协议不匹配恢复。相关 #98384。感谢 @joshavant.
- **PR #98146** fix(cli): 解释如何从设备批准死锁中恢复。感谢 @RomneyDa.
- **PR #98423** improve(ios): 阐明控制和通话的视觉层次。相关 #98397.
- **PR #98217** fix(doctor): 跨设备恢复旧版 cron 存档。感谢 @masatohoshino.
- **PR #98333** feat(openai): 添加 GPT-5.6 系列支持。相关 #98296。感谢 @steipete-oai.
- **PR #96393** fix(cron): 保留需要操作的命令输出。相关 #96346。感谢 @snowzlmbot 和 @nz365guy.
- **PR #98429** fix(ios): 分类 TLS 指纹超时。感谢 @joshavant.
- **PR #98439** fix: Android 设置代码接受本地 mDNS 网关主机。感谢 @joshavant.
- **PR #98443** fix(ios): 改进浅色和深色外观对比度。相关 #98440.
- **PR #97742** fix(llm): 跨提供程序保留结构化工具结果文本。感谢 @snowzlmbot.
- **PR #97968** fix(status): 显示未注册的内存嵌入提供程序。感谢 @masatohoshino.
- **PR #92237** fix(agents): 保留运行时设置覆盖 [AI 辅助]。感谢 @sercada.
- **PR #95888** fix(active-memory): 对可变操作事实添加警告;将截断的召回标记为不完整。感谢 @spencer2211.
- **PR #98291** fix(gateway): 显示 systemd 启动限制耗尽。感谢 @masatohoshino.
- **PR #90517** fix(gateway): 提示 Web 登录缺少外部插件。相关 #83277。感谢 @TUARAN 和 @carol-iung.
- **PR #98369** test(infra): 为 SQLite user_version pragma 辅助函数添加单元测试。感谢 @dwc1997.
- **PR #98340** fix: 扩展 api.exec 在超时后留下子进程。相关 #98335。感谢 @ooiuuii.
- **PR #92063** fix(ui): 在分段流式传输期间折叠重复的助手组。相关 #63956。感谢 @harjothkhara 和 @contentfree.
- **PR #98354** fix(infra): 保护交付队列 inflate 免受损坏的 entry_json 的影响。感谢 @Pick-cat.
- **PR #90566** fix(agents): 在 cron 公告跳过时发出警告。相关 #68561。感谢 @sahibzada-allahyar 和 @Mibslee.
- **PR #98371** fix(ports): 在赋值前验证 lsof PID 解析。感谢 @lzyyzznl.
- **PR #98356** fix(cron): 在每日默认重置中保留提供程序拥有的 CLI 会话。感谢 @yetval.
- **PR #98395** test(shared): 为账户启用保护添加单元测试。感谢 @dwc1997.
- **PR #98411** fix(agents): 从提供程序主体恢复思考错误。相关 #98308。感谢 @sunlit-deng 和 @clearhorizoninvestments.
- **PR #98494** docs(skills): 支持可变着陆批量扫描。感谢 @vincentkoc.
- **PR #91240** fix: 正确报告 Codex ChatGPT 状态认证。相关 #91099。感谢 @849261680 和 @ukstem.
- **PR #98370** test(agents): 为思考块检测添加单元测试。感谢 @dwc1997.
- **PR #96711** test: 在 config、gateway、cron、crestodian 和 state 测试中优先使用共享临时目录辅助函数。感谢 @xialonglee.
- **PR #98483** fix: Android 二维码扫描启动网关配对。感谢 @joshavant.
- **PR #95230** 修复 docs-list-mdx-pages。感谢 @hugenshen.
- **PR #96322** fix(minimax): 限制 JSON 响应读取以防止 OOM。感谢 @lsr911.
- **PR #95348** 修复 config-chmod-warning。感谢 @hugenshen 和 @cursoragent.
- **PR #95229** fix(copilot): 在 cli-metadata 注册期间保护 undefined runtime.state。相关 #94516。感谢 @sunlit-deng 和 @cuihaijun.
- **PR #94636** fix(memory): 在提升期间跳过原始片段。感谢 @tayoun.
- **PR #94013** [AI] fix(feishu): 在监视器启动中保护部分 channelRuntime。感谢 @xydt-tanshanshan.
- **PR #93466** [AI] fix(feishu): 在 channelRuntime 回退中保护缺少的入站。感谢 @xydt-tanshanshan.
- **PR #98049** fix: 在控制 UI 中隐藏过期的配对二维码卡片。相关 #98039。感谢 @ooiuuii.
- **PR #96094** fix(memory): 在 CLI 重新索引后证明实时管理器恢复。相关 #91167。感谢 @849261680 和 @kiagentkronos-cell.
- **PR #98482** fix: 广播路由感知的 LAN 控制 UI 链接。感谢 @joshavant.
- **PR #71537** 在内存钩子 + session-logs 技能中恢复存档的 (.reset) 会话转录。感谢 @injinj.
- **PR #96375** docs(config-agents): 更正 opus 和 gpt 的内置别名表。感谢 @niks999.
- **PR #98453** docs(gateway): 在 config-channels.md 中修复 Telegram 流式传输默认值。感谢 @solodmd.
- **PR #98533** fix: 修复托管 CI 基线断言。
- **PR #98421** feat(imessage): 原生投票支持——创建、阅读、投票。感谢 @omarshahine 和 @lobster.
- **PR #98318** docs(matrix): 记录缺失的 streaming.progress 模式、进度子字段和 mentionPatterns 配置。感谢 @wm0018 和 @vincentkoc.
- **PR #97753** docs(onboard): 记录 11 个缺失的非交互式 CLI 标志。感谢 @wm0018 和 @vincentkoc.
- **PR #97851** fix(mattermost): 限制空主体错误响应读取。感谢 @Pick-cat.
- **PR #98360** fix(memory-wiki): 在临时页面读取后保留笔记。相关 #98345。感谢 @qingminglong, @vincentkoc 和 @yetval.
- **PR #98551** test: 修复过时的核心测试类型失败。感谢 @RomneyDa.
- **PR #98455** fix(browser): 在 fetchHttpJson 中限制错误主体读取以防止 OOM。感谢 @wings1029.
- **PR #95906** fix(code-mode): 向模型展示 QuickJS 错误名称和消息。感谢 @ZengWen-DT 和 @vincentkoc.
- **PR #97901** fix(agents): 停止 copilot autoreview 在 Windows 上的清理崩溃。感谢 @paulcam206.
- **PR #97923** fix(slack): 在代理对边界截断提供的参数菜单选项标签。感谢 @LEXES7.
- **PR #98010** fix(update): 按清单合约验证捆绑插件负载。相关 #97985。感谢 @LiLan0125 和 @herove.
- **PR #85296** fix(codex): 从显式运行超时推导终端空闲监视器。感谢 @alkor2000 和 @vincentkoc.
- **PR #97110** feat(i18n): 添加原生应用本地化清单。感谢 @vincentkoc.
- **PR #98396** fix: 允许使用默认的提供程序 baseUrl 进行 config.patch。相关 #98270。感谢 @momothemage 和 @weltmaister.
- **PR #98503** fix(usage-bar): 使用 Object.hasOwn 而非 in 运算符以避免原型链污染。相关 #98466。感谢 @chenyangjun-xy 和 @zhangLei99586.
- **PR #97111** feat(android): 本地化核心网关界面。感谢 @vincentkoc.
- **PR #97630** fix(media): 不区分大小写地规范化 Windows 入站路径。感谢 @VectorPeak.
- **PR #82638** fix(agents): 当 models.mode 为 'replace' 时跳过隐式提供程序发现 [AI 辅助]。相关 #66957。感谢 @eldar702 和 @wangzhengshu.
- **PR #87917** 修复 sessions json 谱系元数据。相关 #80286。感谢 @zhangguiping-xydt 和 @islandpreneur007.
- **PR #93639** fix(message-tool): 对出站发送应用 messages.responsePrefix。感谢 @ZengWen-DT.
- **PR #94440** fix: #94432 将 Cloudflare 挑战 403 分类为 upstream_html 而非 auth_html。感谢 @lzyyzznl 和 @pbm9z95m6z-hue.
- **PR #98119** fix: 减少 Docker 构建内存压力。相关 #98118。感谢 @zyzo.
- **PR #97679** feat(node): 为 node run/install 添加 --context-path 标志,用于反向映射……。相关 #97678。感谢 @wm0018.
- **PR #98339** fix(irc): 将无主机的 nick!user 允许列表条目分类为可变的。感谢 @yetval.
- **PR #97662** fix(matrix): 限制原始传输响应读取以防止 OOM。感谢 @Alix-007.
- **PR #98137** fix: 提升计时器声明以避免 abortable 延迟中的 TDZ ReferenceError。感谢 @zhangLei99586.
- **PR #98134** fix: 在 Tailscale 二进制探测 Promise.race 中清除超时计时器。感谢 @zhangLei99586.
- **PR #97989** fix(sms): 阻止内部工具跟踪横幅到达 SMS 回复。感谢 @ZengWen-DT.
- **PR #97972** fix(browser): CDP 认证因百分号编码的凭证而失败。感谢 @VectorPeak.
- **PR #98063** fix(reply): 当 messages.suppressToolErrors 设置时抑制工具错误进度交付。感谢 @moeedahmed 和 @amittell.
- **PR #94964** fix(reload): 在进程内重启时取消延迟的通道重新加载。相关 #79487。感谢 @lzyyzznl 和 @tseller.
- **PR #98598** fix: 在计时器修复后恢复主 lint。相关 #98462, #98464。感谢 @zhangLei99586.
- **PR #98587** fix(slack): 保护中继 WebSocket 帧 JSON.parse 免受格式错误的输入影响。感谢 @lsr911 和 @vincentkoc.
- **PR #90030** fix(memory-core): 跳过 qmd 零命中搜索同步。相关 #90023。感谢 @sahibzada-allahyar 和 @ruben2000de.
- **PR #98493** fix(transcripts): 在错误退出时关闭 readline 接口并销毁读取流。相关 #98467。感谢 @wangmiao0668000666 和 @zhangLei99586.
- **PR #98497** fix(cli): 当插件 npm install 返回空输出时显示退出代码。感谢 @Sanjays2402 和 @vincentkoc.
- **PR #97112** feat(apple): 本地化核心原生应用界面。感谢 @vincentkoc.
- **PR #98610** fix: 在添加转录测试后恢复工具 CI。
- **PR #77539** fix(subagent): 在重启重新分发时保留引导的任务文本。感谢 @amittell.
- **PR #97113** feat(i18n): 刷新所有原生本地化工件。感谢 @vincentkoc.
- **PR #98620** feat(doctor): 警告飞行中的 cron 作业。感谢 @masatohoshino.
- **PR #98605** test(shared): 为人类可读的列表格式化添加单元测试。感谢 @dwc1997.
- **PR #97348** feat(autoreview): 支持 cursor-agent 引擎。感谢 @hxy91819.
- **PR #95943** fix(cron): 在隔离运行超时行中保留提供程序/模型。相关 #95873。感谢 @ZengWen-DT, @cursoragent 和 @luke-renjoy.
- **PR #94149** fix(status): 限制 systemd 服务探测,使状态不会在卡住的 systemctl 上挂起 (#84698)。感谢 @ZengWen-DT, @cursoragent 和 @zus-assistant.
- **PR #88159** fix(cli): 在日志跟踪中 journal 回退后重试 logs.tail。感谢 @anyech 和 @vincentkoc.
- **PR #98508** fix(update-check): 限制 npm 注册表 JSON 响应读取以防止 OOM。感谢 @lzyyzznl.
- **PR #98496** fix(tlon): 限制错误响应主体读取以防止 OOM。感谢 @Pandah97.
- **PR #98554** fix(openai): 限制嵌入批次文件下载。感谢 @sunlit-deng 和 @vincentkoc.
- **PR #98652** fix: 阻止无效消息超时导致停滞。
- **PR #77973** fix(gateway): 限制 agentRunCache 以防止在运行扇出时无限制增长。相关 #77976。感谢 @fede-kamel 和 @vincentkoc.
- **PR #98525** fix(agents): 在没有第一个事件的情况下超时本地流。感谢 @osolmaz.
- **PR #94022** fix(cron): 在服务状态中持久化启动追赶延迟 ID,以防止读 RPC 破坏。相关 #93935。感谢 @RichChen01, @vincentkoc 和 @yetval.
- **PR #93810** fix(cron): 在 start() 维护传递中保留启动溢出追赶延迟。感谢 @yetval 和 @vincentkoc.
- **PR #98623** fix: 媒体工具在自动选择模型时跳过环境密钥提供程序插件。感谢 @medns.
- **PR #98665** fix(claude-cli): 为 Claude Code 2.1 在 can_use_tool 允许响应中返回 updatedInput。相关 #95171。感谢 @yetval 和 @carterdawson.
- **PR #94250** fix(feishu): 当 blockStreaming 启用时,将块作为独立消息发送。相关 #55027。感谢 @xialonglee, @vincentkoc 和 @ZichaoLong.
- **PR #93379** fix(whatsapp): 通过命令授权和所有者绕过为 LID JID 解析线程 authDir。相关 #77755。感谢 @xialonglee 和 @jiveshkalra.
- **PR #98646** fix: 保持工作区导轨文件部分可滚动。相关 #98566。感谢 @wuqxuan 和 @645648406-max.
- **PR #98602** fix: iOS Talk 回退设置打开语音与通话。相关 #98593。感谢 @PollyBot13.
- **PR #98611** fix(ui): 为工作区导轨部分添加 overflow-y:auto 以防止文件列表溢出(修复 #98566)。感谢 @zw-xysk 和 @645648406-max.
- **PR #98619** fix(qa-lab): 凭证租赁请求因过大的 Convex 代理响应而失败。感谢 @ZengWen-DT.
- **PR #94326** fix(memory-wiki): 消除保留索引页面词干在合成和摄取中的歧义。感谢 @yetval 和 @vincentkoc.
- **PR #98659** fix(codex): 将 get_goal 读取状态分类为成功的动态工具调用。感谢 @yetval.
- **PR #96856** fix(codex): 成功的 sessions_spawn 和 goal 工具结果被记录为失败。感谢 @nxmxbbd.
- **PR #98660** fix(inworld): 保护 voices JSON.parse 免受格式错误的 API 响应体的影响。感谢 @solodmd.
- **PR #95430** fix(embedded-agent-runner): 通过 pumpStreamWithRecovery 泵送异步 streamFn 以进行流中错误恢复。相关 #95429。感谢 @lzyyzznl, @vincentkoc 和 @alexelgier.
- **PR #98644** fix: 工具摘要保留表情符号截断边界。感谢 @ZengWen-DT.
- **PR #80928** fix(telegram): 当插件命令返回 suppressReply: true 时抑制回退回复。相关 #80756。感谢 @alexuser 和 @UnClouded77.
- **PR #98701** fix: 防止 agents-tools 消息测试超时。
- **PR #92657** feat(usage): 提供内置 /usage 完整页脚。感谢 @Marvinthebored.
- **PR #92877** fix(usage): 使内置页脚在 Telegram 上更易换行。感谢 @Marvinthebored.
- **PR #98126** 为活跃 Codex 运行恢复 Telegram /steer。相关 #81594。感谢 @100yenadmin 和 @Kyzcreig.
- **PR #92037** feat(cron): on-exit 调度——在被监视的命令退出时唤醒。感谢 @anagnorisis2peripeteia.
- **PR #98452** feat(ios): 使用 iOS 26 Liquid Glass 现代化应用。
- **PR #98006** 添加 Telegram /login Codex 配对流程。感谢 @100yenadmin.
- **PR #98735** fix(telegram): 保留转发的富消息文本。感谢 @obviyus.
- **PR #97962** refactor(qa): 在流场景中使用传输原生操作。感谢 @RomneyDa.
- **PR #98726** fix(nvidia): 使用 Nemotron Super 100万上下文。感谢 @eleqtrizit.
- **PR #98691** fix(imessage): 在投票-投票回显匹配中去除任何位置的表情符号。感谢 @omarshahine.
- **PR #97174** 修复 Telegram 插件回调路由。感谢 @goldmar.
- **PR #89597** fix: 将 QQBot 凭证备份迁移到 SQLite KV。
- **PR #98536** feat: 准备范围会话能力配置文件。
- **PR #92274** fix(agents): 将嵌入式提示锁定错误分类为永久公告失败。相关 #91527。感谢 @fsdwen 和 @zackchiutw.
- **PR #98102** fix(telegram): 持久重试重启期间丢弃的入站媒体 (#98076)。感谢 @luoyanglang 和 @DaveArcher18.
- **PR #98755** fix(cron): 分离会话目标运行。相关 #98121。感谢 @obviyus 和 @EthanSK.
- **PR #96065** fix(install): 通过 OPENCLAW_SERVICE_MANAGED_ENV_KEYS 管理 config-secretref 环境引用。感谢 @Darren2030 和 @obviyus.
- **PR #98666** fix: 诊断 Windows LAN Gateway 防火墙拦截。感谢 @joshavant.
- **PR #98501** fix(codex): 将破坏性批准模式重命名为 ask。相关 #98499。感谢 @kevinslin.
- **PR #98775** fix(telegram): 承受临时 getUpdates 错误并停止每次发送缓存重写。相关 #98772, #98773。感谢 @obviyus.
- **PR #98776** fix(telegram): 回退、死信和墓碑存储更新,使有毒消息无法阻塞或重复。相关 #98774。感谢 @obviyus.
- **PR #96454** feat(cli): openclaw attach——启动绑定到网关会话的外部测试工具。感谢 @anagnorisis2peripeteia 和 @obviyus.
- **PR #98786** fix(telegram): 最终回复不再因拒绝的富实体、标题、引用或长洪水等待而丢失。相关 #98778。感谢 @obviyus.
- **PR #97496** Doctor: 暴露通道插件拦截器发现结果。感谢 @giodl73-repo.
- **PR #98792** fix(ci): 恢复文档和测试类型检查。
- **PR #98736** improve(ios): 简化通话控件和编辑器对齐。
- **PR #98183** fix(gateway): 区分可达网关和失败状态探测。感谢 @masatohoshino.
- **PR #98808** docs(telegram): 将维护者决策移至范围 AGENTS.md 并附带可靠性不变性。感谢 @obviyus.
- **PR #98138** fix: 在 Chrome 配置文件装饰中保护 setDeep 免受空键数组的影响。感谢 @zhangLei99586.
- **PR #92283** fix(agents): 不要将 A2A 轮次注入隔离 cron sessions_send (#92257)。感谢 @harjothkhara, @vincentkoc 和 @nailujac.
- **PR #98812** fix(codex): 在侧边对话中保留插件应用批准。
- **PR #97889** fix(discord): 保护 JSON.parse 免受格式错误的 API 响应体的影响。感谢 @lsr911.
- **PR #98689** fix(wizard): 拒绝宽松的网关端口输入。相关 #98681。感谢 @qingminglong.
- **PR #98720** fix(nostr): 清除每次中继发布超时计时器以防止悬垂句柄。相关 #98463。感谢 @wangmiao0668000666 和 @zhangLei99586.
- **PR #98787** fix(memory-wiki): 在 wiki_apply 和 chatgpt 导入中重试临时现有页面读取。感谢 @yetval 和 @vincentkoc.
- **PR #98818** fix(ci): 恢复不完整的 Swift 构建缓存。
- **PR #98811** feat(ios): 现代化导航和设置。相关 #98803.
- **PR #98843** docs: 更新移动应用发布消息。感谢 @joshavant.
- **PR #93209** test: 优先使用自动清理的临时目录辅助函数。感谢 @hxy91819.
- **PR #98789** fix(telegram): 没有账户 ID 的发送和操作忽略配置的 defaultAccount。感谢 @yetval.
- **PR #98806** fix(telegram): Webhook 更新通过持久存储存活崩溃和重启。相关 #98777。感谢 @obviyus.
- **PR #98688** fix(fal): 将 grok-imagine 和 nano-banana-2-lite 编辑路由到正确的端点。感谢 @davenicoll 和 @vincentkoc.
- **PR #98891** fix(agents): 在转录摄取时规范化非数组工具结果内容。相关 #98825。感谢 @obviyus 和 @snowzlmbot.
- **PR #98781** fix(imessage): 投票渲染投票提示、跨运行回显抑制和评论折叠。感谢 @omarshahine.
- **PR #97500** Doctor: 暴露工具结果上限发现结果。感谢 @giodl73-repo.
- **PR #98769** fix: Telegram 回复在发送回复后复制最近上下文。相关 #98767。感谢 @rabsef-bicrym.
- **PR #98933** fix(agents): 停止网关因卡住的 claude-cli 轮次而崩溃,并持久化心跳会话绑定。相关 #98894, #98895。感谢 @obviyus.
- **PR #98934** fix(agents): 恢复 claude-cli 上下文溢出会话并保持重试工件存活。相关 #98897。感谢 @obviyus.
- **PR #98908** refactor(agents): 将助手字符串规范化折叠到转录摄取中。感谢 @obviyus.
- **PR #98738** fix(agents): 在 MCP stdio 会话中途死亡后快速失败并提供可归因原因。感谢 @masatohoshino 和 @vincentkoc.
- **PR #98879** fix: 备份跳过易失缓存路径。相关 #98865。感谢 @ZengWen-DT, @vincentkoc 和 @carterstebbins23-spec.
- **PR #98942** fix(agents): 统一跨实时和单次路径的 claude-cli 输出分类。相关 #98896。感谢 @obviyus.
- **PR #98932** fix(anthropic): 恢复 Fable 5 Vertex 简单补全。
- **PR #98947** fix(cron): 恢复持久会话目标。
- **PR #96523** fix(agents): 保留嵌入式 OpenAI 补全使用量。感谢 @ly85206559 和 @vincentkoc.
- **PR #98758** perf(build): 减少插件 SDK 声明包大小。相关 #98757。感谢 @RomneyDa.
- **PR #98877** fix(mattermost): 在对等目录中包含后期团队成员。相关 #98871。感谢 @qingminglong.
- **PR #98953** feat(ios): 优化聊天体验。相关 #98929.
- **PR #98876** fix(terminal): 保留同级 home-prefix 路径。相关 #98872。感谢 @qingminglong.
- **PR #98930** feat(ios): PR1 品牌调色板大修。感谢 @joelnishanth.
- **PR #94566** fix(android): 使离线聊天可操作。感谢 @Tosko4.
- **PR #98955** fix(agents): 在聚合上限下保留新鲜工具结果文本。相关 #98874。感谢 @momothemage 和 @lamkan0210.
- **PR #98059** [codex] 支持 Android 选定照片访问。感谢 @NianJiuZst.
- **PR #98914** fix(android): 按 Back 键将设置详情返回到其原始标签页。感谢 @Lokimorty.
- **PR #98898** fix(ios): 从设置详情返回时返回到原始屏幕。感谢 @Lokimorty.
- **PR #98235** fix(feishu): 包含视频上传时长。感谢 @areslp.
- **PR #98966** fix(discord): 限制公会元数据读取 [AI]。感谢 @pgondhi987.
- **PR #98985** fix: 清理 iOS 关于页面副本。相关 #98943。感谢 @sahilsatralkar.
- **PR #98856** fix(ios): 网关错误在设置网关页面中显示两次。感谢 @Lokimorty.
- **PR #98936** fix: 控制行图标使用不一致的行样式 (iOS)。相关 #98916。感谢 @sahilsatralkar.
- **PR #98040** [codex] 修复 Android 相机快照清理。感谢 @NianJiuZst.
- **PR #99039** fix(macos): 停止运行时配置健康 sidecar 访问。相关 #98917。感谢 @momothemage 和 @P51moustache.
- **PR #92667** ci: 添加进程 exec CodeQL 安全分片。感谢 @hxy91819.
- **PR #98055** [codex] 限制 Android Talk 捕获在后台启动。感谢 @NianJiuZst.
- **PR #98067** [codex] 在关闭时取消 Android 网关待处理 RPC。感谢 @NianJiuZst.
- **PR #98698** fix(android): 显示特定网关认证恢复原因而非通用标签。相关 #98046。感谢 @masatohoshino 和 @ccaprani.
- **PR #83826** test(android): 在认证测试中轮询过时 TLS 探测清理。感谢 @NeatGuyCoding.
- **PR #98983** fix(agents): 处理可变参数 claude --mcp-config 并序列化 gemini 凭证暂存。相关 #98944, #98945。感谢 @obviyus.
- **PR #99145** fix(auto-reply): 抑制房间事件通知泄漏。感谢 @obviyus.
- **PR #99144** fix(auto-reply): 默认将房间事件设为静默。感谢 @obviyus.
- **PR #98608** fix: Mattermost 在配置的插件修复后无法加载。相关 #98564。感谢 @jacobtomlinson.
- **PR #99143** fix(telegram): 始终保持群组历史记录开启。相关 #99142。感谢 @obviyus.
- **PR #99159** fix(agents): claude-cli 生命周期清理——环回失败-大声、退出-0 故障转移、有界重种、图像扫描、一次准备清理所有者。相关 #98946。感谢 @obviyus.
- **PR #98391** 暴露磁盘空间医生 lint 发现结果。感谢 @giodl73-repo.
- **PR #98835** fix(config/sessions): 将回复会话初始化修订范围缩小到身份字段。相关 #98672。感谢 @moguangyu5-design, @jalehman 和 @AaronFaby.
- **PR #99123** fix(android): 在语音文本提取中忽略缺少助手角色的聊天事件。感谢 @ly85206559 和 @cursoragent.
- **PR #99147** fix(android): 保留拆分 SMS 权限授予。感谢 @NianJiuZst.
- **PR #99107** fix(android): 在手动网关 URL 组合中括号 IPv6 主机。感谢 @ly85206559 和 @cursoragent.
- **PR #99158** fix: 在引导中要求 Android 联系人和日历写入权限。感谢 @NianJiuZst.
- **PR #99110** fix(android): 从手动网关主机输入中去除 ws 方案前缀。相关 #87216。感谢 @ly85206559, @cursoragent 和 @ruben2000de.
- **PR #99212** fix(ci): 子握手期间的会话并发测试不稳定。
- **PR #94385** fix(feishu): 在回退文本中保留按钮命令值,并添加带有回调隐私的飞书评论指南。相关 #69754。感谢 @xialonglee 和 @1yihui.
- **PR #98563** fix: 通过 WebRTC 路由 iOS OpenAI 实时通话。感谢 @PollyBot13.
- **PR #99204** fix: 要求 Android 联系人和日历写入权限。感谢 @NianJiuZst.
- **PR #99134** fix: OAuth 刷新失败报告重新认证而非过时成功。相关 #99120。感谢 @100yenadmin.
- **PR #99153** fix: 取消时清理 Android 相机剪辑。感谢 @NianJiuZst.
- **PR #99118** [codex] fix(memory-lancedb): 对齐 apache arrow 对等依赖。相关 #90295。感谢 @allenhurff 和 @joshavant.
- **PR #98066** fix: 在引导后保持 iOS LAN 二维码配对认证。相关 #98064。感谢 @ooiuuii.
- **PR #99155** fix: 取消后停止 iOS 屏幕录制。感谢 @NianJiuZst.
- **PR #95973** fix(telegram): 解释禁用的插件批准失败。相关 #95800。感谢 @MonkeyLeeT 和 @ChrisBot2026.
- **PR #99233** fix: 忽略仅测试的网络 CI 防护线。感谢 @joshavant.
- **PR #98951** fix: 严格防护的获取在托管代理 DNS 之前失败。相关 #98925。感谢 @momothemage 和 @sandl99.
- **PR #99137** fix: 防止语音唤醒在通话音频捕获后崩溃。感谢 @PollyBot13.
- **PR #99052** fix: 更新暗/亮模式 UI 控件外观。相关 #98995。感谢 @sahilsatralkar.
- **PR #99245** fix(ios): 将聊天返回到原始控制详情。感谢 @Solvely-Colin.
- **PR #92602** fix(android): 在网关连接前排队节点事件。相关 #79552。感谢 @ashishpatel26 和 @hectorrp13.
- **PR #98277** fix: 保持 Android 网关设置保存幂等。感谢 @Solvely-Colin.
- **PR #99256** fix(auto-reply): 单一规范群组历史和去重的轮次元数据。相关 #99218。感谢 @obviyus.
- **PR #99259** fix(android): 使用蓝牙麦克风进行语音捕获。相关 #96241。感谢 @gwtaylor.
- **PR #98751** test(qa): 证明跨 QA 传输的原生命令定位。感谢 @RomneyDa.
- **PR #98779** test(qa): 覆盖扩展的 Crabline 绑定。感谢 @RomneyDa.
- **PR #99262** test(qa): 覆盖 Crabline Signal 发送。感谢 @RomneyDa.
- **PR #99261** refactor(shared): 建立惰性运行时加载器基础。感谢 @RomneyDa.
- **PR #99264** test(qa): 覆盖 Crabline Mattermost 发送。感谢 @RomneyDa.
- **PR #99265** test(qa): 覆盖 Crabline Matrix 发送。感谢 @RomneyDa.
- **PR #98400** 暴露心跳模板医生 lint 发现结果。感谢 @giodl73-repo.
- **PR #98695** 暴露旧版插件清单医生 lint 发现结果。感谢 @giodl73-repo.
- **PR #99278** refactor(shared): 合并核心叶子惰性加载器。感谢 @RomneyDa.
- **PR #99274** fix(zalo): 匹配原生机器人身份字段。感谢 @RomneyDa.
- **PR #99126** test(discord): 阐明并护栏网关代理选择。相关 #98266。感谢 @svuppala2006, @joshavant 和 @sallyom.
- **PR #99290** feat(ios): 添加许可证设置屏幕。感谢 @joshavant.
- **PR #98907** fix(telegram): 区分并渲染流式推理/评论进度通道。感谢 @Marvinthebored.
- **PR #99294** fix(qa): 错开隔离工作器启动。感谢 @RomneyDa.
- **PR #99276** fix(memory-wiki): 源导入在不可读页面上崩溃。感谢 @obviyus.
- **PR #99296** refactor(shared): 合并网关和有状态运行时惰性加载器。感谢 @RomneyDa.
- **PR #98768** 允许替代 Zalo Bot API 根。感谢 @RomneyDa.
- **PR #99298** refactor(shared): 合并 Discord Slack 和 Telegram 惰性加载器。感谢 @RomneyDa.
- **PR #99307** fix(memory-wiki): 避免隐式错误强制转换。感谢 @RomneyDa.
- **PR #99306** feat(auto-reply): 将环境房间事件持久化为转录行。相关 #99257。感谢 @obviyus.
- **PR #99302** refactor(shared): 合并其余通道惰性加载器。感谢 @RomneyDa.
- **PR #99303** test(qa): 覆盖 Crabline Zalo 传输。感谢 @RomneyDa.
- **PR #99299** feat(android): 添加许可证设置屏幕。感谢 @joshavant.
- **PR #99220** fix(ios): 在编辑网关详情后,引导的“重试连接”不起作用。相关 #99219。感谢 @abdullahtas0.
- **PR #98749** refactor(shared): 合并提供程序和工具惰性加载器。感谢 @RomneyDa.
- **PR #99355** fix(ci): 恢复 Telegram 和插件 SDK 防护检查。感谢 @RomneyDa.
- **PR #88899** fix(android): 通过 Markdown 渲染聊天内容。相关 #88014。感谢 @Pluviobyte 和 @Iman-Sharif.
- **PR #99310** test(qa): 将通道流证据迁移到传输流。感谢 @RomneyDa.
- **PR #99350** fix(ios): 添加照片权限控件。相关 #99046。感谢 @Tony-ooo.
- **PR #99361** refactor(plugins): 合并记录防护。感谢 @RomneyDa.
- **PR #99359** refactor(shared): 合并核心记录防护。感谢 @RomneyDa.
- **PR #97208** fix: 避免在 OpenRouter V4 上使用 DeepSeek 原生思维。相关 #97196。感谢 @NianJiuZst 和 @patelmm79.
- **PR #99385** fix(sessions): 将环境转录水印范围限定到会话 ID。相关 #99373。感谢 @obviyus.
- **PR #99389** fix(auto-reply): 恢复每轮消息工具交付合约。相关 #99371。感谢 @obviyus.
- **PR #98269** fix(android): 从 Gateway 目录推导语音就绪状态。相关 #98268。感谢 @Solvely-Colin.
- **PR #92872** fix(qqbot): 允许作用域沙箱媒体发送。感谢 @zhangguiping-xydt 和 @sliverp.
- **PR #99414** fix(android): 暴露精确的网关恢复操作。相关 #98045, #98046。感谢 @ccaprani.
- **PR #99289** feat: 控制 UI 的会话优先侧边栏、紧凑上下文环和暖光主题。相关 #99288.
- **PR #99234** feat(nodes): 添加自动发现的 Ollama 推理。相关 #99228.
- **PR #97095** fix: memory_search 遵守通用嵌入提供程序。感谢 @849261680.
- **PR #98841** fix(gateway): 在 deriveSessionTitle 回退链中包含会话标签。相关 #98742。感谢 @SunnyShu0925 和 @BSG2000.
- **PR #99301** fix(feishu): 捕获流式卡片刷新计时器中未处理的 Promise 拒绝。感谢 @lwy-2.
- **PR #99391** fix(compaction): 计算嵌套工具结果内容。相关 #99375。感谢 @LZY3538 和 @imchloe92.
- **PR #99407** fix(daemon): 在诊断期间避免加载完整网关日志。感谢 @sunlit-deng.
- **PR #99291** Fix/issue 98958 网关锁文件描述符泄漏。相关 #98958。感谢 @chenyangjun-xy 和 @zhangLei99586.
- **PR #99475** fix(ios): contacts.add 因未获取的 CNContactFormatter 键而崩溃应用。感谢 @abdullahtas0.
- **PR #98003** fix(anthropic): 将 buildGuardedModelFetch 接入 Cloudflare createClient 分支。感谢 @wangmiao0668000666.
- **PR #99425** fix: 从主机工具运行中去除 conda 环境标记。相关 #99424。感谢 @ooiuuii 和 @krissding.
- **PR #99398** fix(cli): 拒绝不安全的 sessions tail 计数。感谢 @qingminglong.
- **PR #98855** fix: chat.send 在设置思考元数据时不回复。感谢 @jesse-merhi.
- **PR #98752** 重做 Android 网关引导设置。感谢 @jesse-merhi.
- **PR #99446** fix(agents): 保留 fd 查找失败。感谢 @zhangguiping-xydt.
- **PR #99152** fix(config): 在 restoreOriginalValueOrThrow 中使用 Object.hasOwn 而非 in 运算符。感谢 @zenglingbiao.
- **PR #99460** fix: 编辑带点的 API 密钥活动预览。相关 #99459。感谢 @ooiuuii.
- **PR #99455** fix: 长移动媒体录制超时。感谢 @NianJiuZst.
- **PR #99410** fix(subagents): 当 controllerSessionKey 在列表过滤器中不同时匹配 requesterSessionKey。相关 #75593。感谢 @sheyanmin 和 @aaajiao.
- **PR #98791** feat(signal): 在入站回复期间显示状态反应。感谢 @jesse-merhi.
- **PR #98683** fix(ui): 保持横屏编辑器紧凑。相关 #98615。感谢 @qingminglong 和 @jin-li.
- **PR #99428** fix(logging): 从超时 URL 中编辑 Telegram 机器人令牌。相关 #96982。感谢 @xialonglee 和 @liuhaiyang14.
- **PR #99217** 在缺失轮次完成后保留 Codex 输出。感谢 @100yenadmin, @Sedrak-Hovhannisyan 和 @fuller-stack-dev.
- **PR #99520** fix(gateway): 声明网关 e2e 会话键所需的 dev 代理。相关 #99513。感谢 @masatohoshino.
- **PR #95738** feat(signal): 添加目标别名。感谢 @jesse-merhi.
- **PR #98258** improve: 使原生聊天滚动由阅读器管理。相关 #98255。感谢 @christopheraaronhogg.
- **PR #99506** fix: 在调度中保持始终在线群组回退消息。相关 #99457。感谢 @LZY3538 和 @zqchris.
- **PR #89671** fix(google-meet): 通过 hl=en 强制英语 Meet UI,使自动化在任何区域设置下工作。感谢 @Unayung.
- **PR #98130** fix(infra): 限制 jsonl-socket 响应缓冲区以防止 OOM。感谢 @Pick-cat.
- **PR #99526** fix(agents): 保留原始工具结果输出。相关 #99523。感谢 @snowzlm.
- **PR #99525** fix(imessage): 将裸十六进制群组聊天标识符识别为聊天目标。相关 #89235。感谢 @MatthewDelprado.
- **PR #99098** fix: 加固原生 i18n 标识符过滤。感谢 @hxy91819.
- **PR #99099** fix: 加固文档地图标题渲染。感谢 @hxy91819.
- **PR #98725** 暴露旧版插件依赖医生 lint 发现结果。感谢 @giodl73-repo.
- **PR #99595** fix(agents): 保持 cli 会话绑定事实会话稳定。相关 #99372。感谢 @obviyus.
- **PR #90152** fix(telegram): 在最终回复后调度失败时停止重复回退。感谢 @zhangguiping-xydt.
- **PR #98729** 暴露旧版插件运行时符号链接医生 lint 发现结果。感谢 @giodl73-repo.
- **PR #99591** fix(android): 保留数字调用错误代码。感谢 @ly85206559.
- **PR #98406** 暴露 WhatsApp 响应性医生 lint 发现结果。感谢 @giodl73-repo.
- **PR #99570** fix(android): 拒绝网关端点 URL 中的 IPv6 区域 ID。感谢 @ly85206559 和 @cursoragent.
- **PR #99557** fix(android): 从线程选择器中过滤设备和内部会话。感谢 @ly85206559 和 @cursoragent.
- **PR #99568** fix(android): 在允许列表模式下阻止自包通知转发。感谢 @ly85206559 和 @cursoragent.
- **PR #99592** fix(android): 不区分大小写地解析通话指令别名。感谢 @ly85206559.
- **PR #99477** fix: 避免 iOS 节点权限提示。感谢 @NianJiuZst.
- **PR #99374** improve(qa): 标准化脚本证据输出。感谢 @RomneyDa.
- **PR #99468** improve: 收紧 iOS 控制行密度。相关 #99439。感谢 @sahilsatralkar.
- **PR #99642** test: 避免跨操作系统套接字关闭事件竞态。感谢 @RomneyDa.
- **PR #89967** fix(macos): LaunchAgent 在外部 home 卷上启动网关。相关 #87199。感谢 @zhangguiping-xydt 和 @joshdaynard.
- **PR #98613** fix(media): 保护 ffprobe JSON 解析免受格式错误输出的影响。感谢 @Pick-cat.
- **PR #97839** fix: 记录终端会话持久化失败。相关 #97795。感谢 @LZY3538 和 @aniruddhaadak80.
- **PR #99247** feat: 阐明 iOS 位置始终权限流程。感谢 @PollyBot13.
- **PR #98224** fix(auto-reply): 在静默回复令牌检测前去除杂散标点。感谢 @SunnyShu0925.
- **PR #97328** fix(google): 为 LLM 请求轮换 Gemini API 密钥。感谢 @MonkeyLeeT.
- **PR #99661** fix(macos): 远程模式因托管 SSH 别名失败。
- **PR #99649** fix(qa): 延迟部分 Crabline 记录器行。相关 #99648。感谢 @RomneyDa.
- **PR #99211** 暴露旧版 cron 存储医生 lint 发现结果。感谢 @giodl73-repo.
- **PR #99629** test(qa): 编辑脚本证据诊断。感谢 @RomneyDa.
- **PR #99647** 修复 Slack 重试会话初始化冲突。感谢 @steipete-oai.
- **PR #99628** improve: 强制规范 QA 场景所有权。相关 #99627。感谢 @RomneyDa.
- **PR #99632** refactor(qa): 简化传输适配器合约。相关 #99622。感谢 @RomneyDa.
- **PR #99656** test(qa): 为原生停止恢复使用完整轮次预算。相关 #99655。感谢 @RomneyDa.
- **PR #99605** fix(google): 限制 OAuth 令牌错误响应读取。感谢 @mushuiyu886.
- **PR #99679** fix(qa): 消费 Crabline 事件而无需记录器轮询。相关 #99664。感谢 @RomneyDa.
- **PR #99687** refactor(infra): 合并 SHA-256 摘要辅助函数。相关 #99675。感谢 @RomneyDa.
- **PR #98796** [AI 辅助] feat(android): 添加聊天命令控件。感谢 @IWhatsskill.
- **PR #99671** refactor: 合并数字强制转换调用者。相关 #99667。感谢 @RomneyDa.
- **PR #99640** fix: CLI 代理会话恢复在群组中所有者和非所有者交替时搅动。相关 #99633。感谢 @obviyus.
- **PR #99682** refactor(models): 合并目录引用解析。相关 #99674。感谢 @RomneyDa.
- **PR #99566** fix(exec): 避免在批准显示中分割代理对。感谢 @mikasa0818.
- **PR #99702** refactor: 删除冗余的唯一列表别名。相关 #99697。感谢 @RomneyDa.
- **PR #99246** feat(ios): 实现品牌字体设计系统。感谢 @joelnishanth 和 @cursoragent.
- **PR #99710** fix(build): Docker 包准备缺少插件 SDK 声明。感谢 @RomneyDa.
- **PR #99715** refactor: 合并图像数据 URL 格式化。感谢 @RomneyDa.
- **PR #98764** fix(ui): 通过纯 HTTP 复制工作区文件路径。相关 #98759。感谢 @ZengWen-DT 和 @adinballew.
- **PR #99678** fix(build): 通过稳定的运行时别名转发默认导出。相关 #99677。感谢 @headbouyJB 和 @vincentkoc.
- **PR #99370** fix(file-transfer): 不要将零字节文件内联为图像内容块。感谢 @2loch-ness6 和 @vincentkoc.
- **PR #99540** fix(doctor): 当配置文件只读时 shell 补全安装导致医生失败。相关 #99237。感谢 @rballiance 和 @hunglp6d.
- **PR #99718** refactor(text): 合并清理所有者。感谢 @RomneyDa.
- **PR #98819** fix(plugins): 从安装的插件根解析公共工件。相关 #98740。感谢 @amknight 和 @KelTech-Services.
- **PR #99721** refactor: 合并异步定时辅助函数。感谢 @RomneyDa.
- **PR #99722** fix: 当消息在 @-mention 和纯文本之间切换时,群组代理会话恢复搅动。相关 #99696。感谢 @obviyus.
- **PR #99676** refactor: 合并字符串读取器机制。相关 #99663。感谢 @RomneyDa.
- **PR #99705** improve(qa): 通过 Docker 执行运行时场景。感谢 @RomneyDa.
- **PR #99231** improve: 使用原生 SwiftUI 导航、表单、聊天和通话可视化器实现 iOS 原生外观。相关 #99195。感谢 @marvkr.
- **PR #99549** fix(auto-reply): 不要因转录镜像而阻塞回复完成。感谢 @Shagrat2.
- **PR #99736** fix(qa): 防止烟雾网关丢失构建文件。相关 #99734。感谢 @RomneyDa.
- **PR #99658** feat(providers): 添加 ClawRouter 路由和配额。相关 #99657.
- **PR #99238** 暴露通道预览警告医生发现结果。感谢 @giodl73-repo.
- **PR #99759** fix(providers): 解析 ClawRouter 认证配置文件模型。
- **PR #99561** fix: 当 tool_search 错误路由时保持 OpenClaw 控制工具可用。相关 #99464。感谢 @100yenadmin 和 @joshavant.
- **PR #99750** refactor: 合并精确布尔强制转换。感谢 @RomneyDa.
- **PR #99753** refactor: 合并中止原语。感谢 @RomneyDa.
- **PR #99426** feat: 在聊天编辑器中添加斜杠命令选择器。感谢 @VicZhang6 和 @Solvely-Colin.
- **PR #99771** refactor: 合并空闲端口测试辅助函数。感谢 @RomneyDa.
- **PR #99755** refactor: 合并无策略延迟承诺。感谢 @RomneyDa.
- **PR #99719** refactor(net): 合并 URL 协议谓词。感谢 @RomneyDa.
- **PR #99743** fix: 避免 CI 争用下原生命令 QA 超时。感谢 @RomneyDa.
- **PR #99368** fix(qa): 防止 QA 烟雾 CI 在网关并发下超时。感谢 @RomneyDa.
- **PR #99778** refactor(scripts): 共享正则表达式字面量转义。感谢 @RomneyDa.
- **PR #99737** test: 添加可执行运行时固定金丝雀。感谢 @RomneyDa.
- **PR #99735** test(qa): 通过真实传输测试 Gateway 和 MCP 场景。感谢 @RomneyDa.
- **PR #99784** fix(qa): 稳定主要烟雾运行时证据。感谢 @RomneyDa.
- **PR #99726** fix(onboard): 通过生命周期就绪预检跳过不可用的技能安装程序。感谢 @fuller-stack-dev 和 @Sedrak-Hovhannisyan.
- **PR #99793** ci: 在 QA 烟雾中重用同一包。
- **PR #99767** feat(macos): 自动安装和运行本地 Gateway。相关 #99764.
- **PR #99820** ci: 增加工件 Testbox 内存。
- **PR #99822** feat: 在提示漂移时软恢复 CLI 会话而非硬失效。相关 #99729。感谢 @obviyus.
- **PR #99129** fix(markdown-core): 在 parseFrontmatterBlock 中使用 Object.hasOwn 而非 in 运算符。感谢 @zenglingbiao 和 @vincentkoc.
- **PR #99803** fix(mcp): 抑制 stdio 传输中 stderr 管道上未处理的错误。感谢 @cxbAsDev 和 @vincentkoc.
- **PR #99802** fix(supervisor): 抑制子进程 stdout/stderr 上未处理的流错误。感谢 @cxbAsDev 和 @vincentkoc.
- **PR #99800** fix(ssh-tunnel): 处理 spawn 错误以防止未处理的拒绝崩溃。感谢 @cxbAsDev 和 @vincentkoc.
- **PR #99653** fix(cli): 隐藏合成的 Claude 重种提示。相关 #99646。感谢 @ZOOWH, @vincentkoc 和 @Jeehut.
- **PR #99728** fix(config): 在配置健康迁移期间保留恢复状态。相关 #99280。感谢 @joshavant, @jalehman 和 @ccbridle.
- **PR #99839** fix(gateway): 保留旧版重种附件。感谢 @vincentkoc.
- **PR #99830** fix: 在 Mac 应用 Web 视图中停止控制 UI 外壳的橡皮筋弹跳。
- **PR #99851** fix(agents): 保留回退工具调用提示。感谢 @vincentkoc.
- **PR #98994** fix(line): 在码点边界截断出站 altText、location、menu 和 code 字段。感谢 @LEXES7 和 @vincentkoc.
- **PR #99846** fix(config): 将配置路径限制为自有属性。感谢 @vincentkoc 和 @zenglingbiao.
- **PR #99861** fix(telegram): 一个出站富 HTML 规范化器和一个富到纯文本回退策略。相关 #99833。感谢 @obviyus.
- **PR #99866** fix(telegram): 根据规范提及决策分类入站事件,以便直接提及停止潜伏。相关 #99854。感谢 @obviyus.
- **PR #99832** fix: 拒绝不兼容的 Node 23 运行时。感谢 @fuller-stack-dev.
- **PR #99243** 完善 iOS 引导和聊天评论修复。感谢 @jcooley8.
- **PR #99714** perf(usage): 缩小持久使用量缓存条目。相关 #99511。感谢 @dexhunter 和 @wayne524.
- **PR #99838** feat: 精简控制 UI 外壳——推理努力滑块、无边框编辑器控件、版本移出侧边栏。相关 #99837.
- **PR #93686** fix(weixin): startAccount 保留会话路由。相关 #93556。感谢 @zhangguiping-xydt 和 @htkillermax-gif.
### 发布验证
- npm 包:https://www.npmjs.com/package/openclaw/v/2026.7.1-beta.2
- 注册表 tarball:https://registry.npmjs.org/openclaw/-/openclaw-2026.7.1-beta.2.tgz
- 完整性:`sha512-KYPBQnAfEb/9qrxlw/96a90mMQeKdAZdUABMROOue9Ph2oFbnDGezZjd5Bmw4WhRyzgyvHOHqHje/swGipC4xA==`
- 发布 SHA:`a580a7fe3fbd1b3329c978d58ca2f70e8ca37aee`
- 完整发布 CI 报告:https://github.com/openclaw/releases/blob/main/evidence/2026.7.1-beta.2/release-evidence.md
- 发布发布:https://github.com/openclaw/openclaw/actions/runs/28735224348
- npm 预检:https://github.com/openclaw/openclaw/actions/runs/28717730132
- 完整发布验证:https://github.com/openclaw/openclaw/actions/runs/28717729503
- 插件 npm 发布:https://github.com/openclaw/openclaw/actions/runs/28735371120
- 插件 ClawHub 发布:单独分发,此证明不依赖:https://github.com/openclaw/openclaw/actions/runs/28735371597
- 插件 ClawHub 引导:不需要
- OpenClaw npm 发布:https://github.com/openclaw/openclaw/actions/runs/28735575588
- npm Telegram beta E2E:未提供
### Highlights
- **OpenAI GPT-5.6 support:** OpenClaw now recognizes the GPT-5.6 model family across catalog, capability, and runtime selection paths. (#98333) Thanks @steipete-oai.
- **External harness attachment:** `openclaw attach` launches an external harness against an existing Gateway session, making interactive Codex-style workflows easier to resume and inspect. (#96454) Thanks @anagnorisis2peripeteia and @obviyus.
- **Telegram Codex workflows:** Telegram can now start Codex pairing with `/login`, steer active Codex runs, and recover final replies across transient API failures. (#98006, #98126, #98786) Thanks @100yenadmin, @Kyzcreig, and @obviyus.
- **Event-driven cron runs:** the new `on-exit` schedule kind wakes an agent when a watched command exits, while session-targeted runs can detach cleanly. (#92037, #98755) Thanks @anagnorisis2peripeteia, @obviyus, and @EthanSK.
- **Native app refresh:** iOS adopts the iOS 26 visual system with clearer Chat, Talk, onboarding, and reconnect flows, while native app localization expands across Apple and Android surfaces. (#98452, #98736, #99243, #97110, #97111, #97112, #97113) Thanks @jcooley8 and @vincentkoc.
- **Richer messaging:** iMessage gains native poll creation, reading, and voting, and built-in usage footers provide clearer per-turn accounting in chat. (#98421, #92657, #92877) Thanks @omarshahine, @lobster, and @Marvinthebored.
- **Safer scoped conversations:** capability profiles prepare per-conversation tool and access boundaries without weakening the existing default profile. (#98536)
- **Mac local Gateway setup:** the macOS app can now install and start its local Gateway automatically, reducing the manual setup needed before first use. (#99767)
- **Control UI navigation:** a session-first sidebar, compact context meter, warm light theme, reasoning-effort slider, streamlined composer, and slash-command picker make active conversations and commands easier to reach. (#99289, #99426, #99838) Thanks @VicZhang6 and @Solvely-Colin.
### Changes
- **ClawRouter routing and quotas:** add the bundled ClawRouter provider plugin with credential-scoped dynamic model discovery, OpenAI-compatible and native Anthropic/Gemini transports, and managed budget reporting across OpenClaw usage surfaces. (#99658)
- **Model and provider coverage:** add GPT-5.6 support, use Nemotron Super's 1M context window, and preserve explicit OpenRouter authentication headers. (#98333, #98726, #98187) Thanks @steipete-oai, @eleqtrizit, @sunlit-deng, and @laurencebrown.
- **CLI and node workflows:** add `openclaw attach`, node context-path support, actionable device-approval recovery guidance, soft-resume CLI sessions when prompt metadata changes, and clearer plugin install exit diagnostics. (#96454, #97679, #98115, #98146, #98497, #99822) Thanks @anagnorisis2peripeteia, @obviyus, @wm0018, @welfo-beo, @RomneyDa, @Sanjays2402, and @vincentkoc.
- **Cron and usage:** add exit-triggered schedules, detached session-targeted runs, an in-flight job doctor warning, and a built-in full usage footer. (#92037, #98755, #98620, #92657, #92877) Thanks @anagnorisis2peripeteia, @obviyus, @EthanSK, @masatohoshino, and @Marvinthebored.
- **Native apps and localization:** modernize iOS presentation, Chat, Talk, onboarding, and reconnect flows; add Gateway speech providers; improve QR onboarding and protocol recovery; install the local Gateway from macOS; localize core Apple and Android surfaces; and add Swedish mobile localization. (#98452, #98736, #99243, #98376, #98302, #98385, #99767, #97110, #97111, #97112, #97113, #98043) Thanks @jcooley8, @Tony-ooo, @joelnishanth, @cursoragent, @joshavant, @vincentkoc, and @yeager.
- **Messaging capabilities:** add native iMessage polls, Telegram Codex pairing and steering, Telegram multi-lane progress summaries, and Signal target aliases. (#98421, #98006, #98126, #98907, #95738) Thanks @omarshahine, @lobster, @100yenadmin, @Kyzcreig, @Marvinthebored, and @jesse-merhi.
- **Local inference and chat controls:** auto-discover Ollama inference nodes, add Control UI session-first navigation, reasoning controls, and command picking, and keep OpenClaw control tools available when deferred tool search selects the wrong tool family. (#99234, #99289, #99426, #99838, #99561) Thanks @100yenadmin, @joshavant, @VicZhang6, and @Solvely-Colin.
- **Doctor and diagnostics:** expose auth-profile, workspace, device-pairing, channel-plugin, memory-provider, systemd exhaustion, and Windows LAN firewall findings. (#97125, #97358, #97366, #97496, #97968, #98291, #98666) Thanks @giodl73-repo, @masatohoshino, and @joshavant.
- **Conversation and review controls:** prepare scoped conversation capability profiles and add Cursor Agent as an autoreview engine. (#98536, #97348) Thanks @hxy91819.
### Fixes
- **ClawRouter auth profiles:** resolve credential-scoped catalog models during agent runs when the proxy key is stored in an auth profile, and document plugin and model allowlists.
- **Telegram durability:** recover stalled ingress claims, retry restart-dropped media, survive transient polling errors, dead-letter poison updates, preserve forwarded rich text, route plugin callbacks correctly, keep progress updates in one stable multi-line window, throttle reconnect queue drains so fast healthy polls cannot starve active replies, and fall back safely when Telegram rejects rich final replies. (#97118, #98102, #98735, #98775, #98776, #97174, #98907, #98786) Thanks @vincentkoc, @luoyanglang, @DaveArcher18, @obviyus, @goldmar, @Marvinthebored, and @shakkernerd.
- **Agent and context reliability:** preserve runtime overrides, steered subagent tasks, fallback tool-call hints, and legacy reseed attachments; soft-resume CLI sessions across prompt-only drift; honor stop signals that arrive during eager session-lock acquisition before any provider prompt starts; improve harness-aware context estimation and compaction prechecks; time out silent local streams; recover mid-stream failures; and cap Gateway run-cache growth. (#92237, #77539, #99851, #99839, #99822, #97928, #97861, #98525, #95430, #77973) Thanks @sercada, @amittell, @obviyus, @liuhao1024, @yetval, @osolmaz, @lzyyzznl, @vincentkoc, @alexelgier, and @fede-kamel.
- **Provider and network safety:** bound oversized or malformed responses across Moonshot, MiniMax, Anthropic OAuth, Discord, Matrix, SMS, browser, update, embeddings, Tlön, and Inworld paths. (#96502, #96322, #96644, #97693, #97662, #97999, #98455, #98508, #98554, #98496, #98660) Thanks @hugenshen, @cursoragent, @lsr911, @solodmd, @Alix-007, @wings1029, @lzyyzznl, @sunlit-deng, @vincentkoc, and @Pandah97.
- **Channel delivery and routing:** keep Slack replies in the active thread, preserve account-bound delivery routes, apply response prefixes, suppress internal traces and unwanted fallback replies, and retain WeChat session routing for opaque account ids. (#97168, #98240, #89949, #93639, #97989, #80928, #93686) Thanks @LiuwqGit, @gorkem2020, @yetval, @wangwllu, @ZengWen-DT, @alexuser, @UnClouded77, @zhangguiping-xydt, @htkillermax-gif, and @vincentkoc.
- **Cron correctness:** preserve provider and model selections on timeouts, retain startup catch-up deferrals, keep action-required output, clear blank thinking overrides, and preserve provider-owned daily-reset sessions. (#95943, #94022, #93810, #96393, #96293, #98356) Thanks @ZengWen-DT, @cursoragent, @luke-renjoy, @RichChen01, @vincentkoc, @yetval, @snowzlmbot, @nz365guy, and @takamasa-aiso.
- **Memory and session recovery:** detect unindexed transcripts, preserve notes through transient reads, avoid cross-directory resumes, disambiguate reserved wiki index pages, and skip empty QMD sync work. (#97857, #98360, #97785, #94326, #90030) Thanks @zw-xysk, @CHE10X, @qingminglong, @yetval, @vincentkoc, @sahibzada-allahyar, and @ruben2000de.
- **Windows and execution:** bind allowlisted execution to the validated Windows path, propagate `PATHEXT`, normalize inbound paths case-insensitively, and prevent cleanup crashes on Windows. (#98260, #98093, #97630, #97901) Thanks @eleqtrizit, @wendy-chsy, @VectorPeak, and @paulcam206.
- **Mobile and UI stability:** preserve iOS chat line breaks and final replies, improve Android pairing and TLS recovery, hide expired pairing cards, keep workspace file rails scrollable, restore copy-path over plain HTTP, and stop rubber-band scrolling in the Mac app Control UI. (#98304, #98117, #98366, #98439, #98483, #98049, #98646, #98611, #98764, #99830) Thanks @joshavant, @Jabato01, @ooiuuii, @wuqxuan, @645648406-max, @zw-xysk, @ZengWen-DT, and @adinballew.
- **Codex and approval flows:** report ChatGPT authentication correctly, rename destructive approval mode to `ask`, classify dynamic goal and session tool results accurately, and derive terminal-idle timeouts from the explicit run deadline. (#91240, #98501, #98659, #96856, #85296) Thanks @849261680, @ukstem, @kevinslin, @yetval, @nxmxbbd, @alkor2000, and @vincentkoc.
- **Configuration and plugin health:** restrict config traversal to owned properties, preserve config-health recovery state, surface unloadable channel plugins, preserve defaulted provider base URLs during patches, validate bundled plugin updates by manifest contract, prefer installed launcher targets when resolving package roots so bundled channel setup entries load from nested installs, resolve public artifacts from installed plugin roots, and retain legacy ClawHub families where required. (#99846, #99728, #96397, #98396, #98010, #98819, #98249) Thanks @vincentkoc, @zenglingbiao, @joshavant, @jalehman, @ccbridle, @849261680, @momothemage, @weltmaister, @LiLan0125, @herove, @amknight, @KelTech-Services, and @Patrick-Erichsen.
- **Runtime process safety:** prevent unhandled child-stream errors in SSH tunnels, supervisors, and MCP stdio transports; keep auto-replies from waiting on transcript mirroring; and avoid splitting Unicode characters in approval previews and LINE outbound fields. (#99800, #99802, #99803, #99549, #99566, #98994) Thanks @cxbAsDev, @vincentkoc, @Shagrat2, @mikasa0818, and @LEXES7.
- **Node runtime compatibility:** installers, the CLI launcher, doctor, and the macOS app now reject incompatible Node 23 runtimes and guide users toward supported Node 22 or 24 releases. (#99832) Thanks @vincentkoc and @fuller-stack-dev.
- **QQBot media delivery:** scope sandbox-generated media sends to the active session's workspace so `/workspace/...` and relative generated-file paths resolve safely across QQBot media tags, structured payloads, and streaming delivery. (#92872) Thanks @zhangguiping-xydt and @sliverp.
### Complete contribution record
This audited record covers the complete 66e676d29b92d040716376a75aca32bad655cfac..1e20f15581f9fe9132768379bd80cc74c047b8cc history: 455 merged PRs. The generation manifest also supplies direct commits as editorial input; the grouped notes above prioritize user impact.
#### Pull requests
- **PR #96502** fix(moonshot): bound video description JSON response reads. Thanks @hugenshen and @cursoragent.
- **PR #98249** Preserve legacy ClawHub family for selected plugins. Thanks @Patrick-Erichsen.
- **PR #93767** fix(reasoning-tags): strip MiniMax `mm:` namespaced reasoning tags. Thanks @DrHack1.
- **PR #93820** fix(imessage): recognize MiniMax mm: reasoning tags in reflection guard (completes #93767). Thanks @Alix-007.
- **PR #94096** fix(usage): reject inverted startDate-endDate range in usage.cost and sessions.usage. Thanks @Alix-007.
- **PR #97125** Doctor: expose auth profile findings. Thanks @giodl73-repo.
- **PR #98256** fix(mcp): require owner for Claude permission replies. Thanks @eleqtrizit.
- **PR #98142** fix(cli): stop `pairing list` crashing with empty channel enum. Thanks @RomneyDa.
- **PR #98260** fix(exec): bind Windows allowlist execution path. Thanks @eleqtrizit.
- **PR #97118** fix(telegram): recover stalled ingress spool claims. Thanks @vincentkoc.
- **PR #97168** fix(slack): prefer current thread session for inherited outbound replies. Related #96535. Thanks @LiuwqGit and @gorkem2020.
- **PR #97769** fix(plugins): apply output text transforms to toolcall_delta and toolcall_end events. Related #97761. Thanks @ZOOWH and @get-viti.
- **PR #96544** fix(doctor): merge colliding model-ref map keys instead of dropping. Thanks @yetval and @vincentkoc.
- **PR #97177** fix(memory-wiki): gracefully handle unparsable YAML frontmatter in vault scans (#96125). Thanks @SunnyShu0925 and @cow11023.
- **PR #97167** fix #96840: [Bug]: Targetless message.send fails with 'Action send requires a target' in WebChat despite docs stating source-reply sink should handle it. Thanks @zhangguiping-xydt and @MantisCartography.
- **PR #98302** fix(ios): advance onboarding step after QR scan. Related #98297. Thanks @joelnishanth and @cursoragent.
- **PR #96644** fix(anthropic-oauth): bound OAuth token endpoint response reads. Thanks @solodmd.
- **PR #96397** fix: warn when configured channel plugins cannot load. Thanks @849261680.
- **PR #96359** test: migrate src/commands tests to shared temp dir helpers. Thanks @xialonglee.
- **PR #96293** fix(cron): clear agentTurn thinking override by blanking the field. Related #96287. Thanks @ZengWen-DT and @takamasa-aiso.
- **PR #96058** test: prefer shared temp dir helpers in auto-reply and install-fallback tests. Thanks @xialonglee.
- **PR #87298** test: add temp directory helper guidance. Thanks @hxy91819.
- **PR #97785** fix(sessions): avoid cross-cwd recent resumes. Related #96542. Thanks @qingminglong and @yetval.
- **PR #97698** fix(pdf): reject empty parsed page ranges before native analysis. Thanks @zhangguiping-xydt.
- **PR #97693** fix(discord): bound requestDiscord happy-path response reads to prevent OOM. Thanks @Alix-007.
- **PR #97683** fix(irc): guard surrogate-range codepoints in \u literal-escape decoder. Thanks @llagy009.
- **PR #96938** fix(utils): keep reply directive ids unicode-safe. Thanks @ly-wang19.
- **PR #97857** fix(memory): detect unindexed session transcripts in status mode (fixes #97814). Thanks @zw-xysk and @CHE10X.
- **PR #98094** fix(android): clarify gateway auth recovery states. Thanks @qingminglong.
- **PR #98205** test(gateway): add unit tests for node wake state tracking and testing seam. Thanks @zenglingbiao.
- **PR #98115** fix: surface node approval guidance from devices CLI. Thanks @welfo-beo.
- **PR #97898** docs: clarify source checkout Node floor. Related #97792. Thanks @lin-hongkuan and @aniruddhaadak80.
- **PR #94526** test(telegram): add regression test for forum topic message_thread_id with streamed reasoning. Related #89352. Thanks @xialonglee and @pmika.
- **PR #98145** fix(device-pairing): don't churn requestId on subset re-requests. Thanks @RomneyDa.
- **PR #98267** fix(system-prompt): move exec-approval + Authorized Senders below cache boundary. Related #98261. Thanks @headbouyJB.
- **PR #98304** fix: preserve iOS chat line breaks. Related #98028. Thanks @joshavant and @Jabato01.
- **PR #98187** fix(openrouter): send explicit auth headers. Related #97934. Thanks @sunlit-deng and @laurencebrown.
- **PR #95708** fix: show WebChat preamble progress during tool activity. Thanks @ragesaq.
- **PR #98210** fix(gateway): iOS Talk treats SecretRef-backed API keys as missing. Related #98209. Thanks @ooiuuii.
- **PR #98009** test(infra): add unit tests for SQLite number normalization. Thanks @dwc1997.
- **PR #98087** test(config): add unit tests for resolveExecCommandHighlighting. Thanks @solodmd.
- **PR #98219** test(utils): add unit tests for chunkItems. Thanks @zenglingbiao.
- **PR #98093** fix(core): propagate caller env PATHEXT through isExecutableFile on Windows. Thanks @wendy-chsy.
- **PR #97973** fix(matrix): guard JSON.parse against malformed homeserver response bodies. Thanks @lsr911.
- **PR #97999** fix(sms): guard Twilio JSON.parse against malformed API response bodies. Thanks @lsr911.
- **PR #98043** Add Swedish mobile app localization. Thanks @yeager.
- **PR #98144** fix(tui): correct disconnect copy for device scope upgrades. Thanks @RomneyDa.
- **PR #98240** fix(agents): keep merged delivery routes account-bound. Thanks @yetval.
- **PR #89949** fix(media): pin requester delivery route when task starts. Thanks @wangwllu.
- **PR #98226** Redact bare Fireworks API keys. Related #98225. Thanks @ooiuuii.
- **PR #98319** docs: publish release notes for v2026.6.11. Thanks @hannesrudolph.
- **PR #98257** fix: show in-progress status for channel runs. Thanks @scotthuang.
- **PR #97931** fix(gateway): keep provider-owned CLI sessions across the daily default reset. Thanks @yetval.
- **PR #98325** docs: refresh docs map for v2026.6.11. Thanks @hannesrudolph.
- **PR #97929** fix(auto-reply): stop level directives from eating the next message word. Thanks @yetval.
- **PR #97928** fix(agents): estimate harness role sizes in context guard char estimator (fixes #97927). Thanks @liuhao1024 and @yetval.
- **PR #97861** fix(compaction): count bashExecution and summary turns in pre-prompt overflow precheck. Thanks @yetval.
- **PR #97137** doctor: add memory search lint findings. Thanks @giodl73-repo.
- **PR #97358** Doctor: expose workspace status findings. Thanks @giodl73-repo.
- **PR #95622** test(qa-lab): harden whatsapp qa scenarios. Thanks @mcaxtr.
- **PR #98346** fix: prevent skill-creator from bypassing workshop proposals. Related #96054. Thanks @momothemage and @xianshishan.
- **PR #98169** fix(heartbeat): scope commitment fan-out prompts. Thanks @bdjben.
- **PR #97366** Doctor: expose device pairing findings. Thanks @giodl73-repo.
- **PR #98366** fix: Android TLS fingerprint verification times out on slow handshakes. Related #98365. Thanks @joshavant.
- **PR #98353** fix(ios): open app on Chat by default. Thanks @BsnizND.
- **PR #98352** fix(security): warn on agent skill MCP boundary drift. Thanks @momothemage.
- **PR #98347** fix: retry image describe fallback models. Thanks @momothemage.
- **PR #98117** fix(ios): avoid transient duplicate final replies. Related #98116. Thanks @ooiuuii and @joshavant.
- **PR #98293** fix(gateway): emit stale exec approval followup diagnostics. Thanks @BsnizND.
- **PR #98376** fix(ios): use Gateway speech providers in Talk. Related #98153. Thanks @Tony-ooo.
- **PR #66685** Suppress expired exec approval followup warnings. Thanks @pfrederiksen.
- **PR #98385** fix: show actionable mobile protocol mismatch recovery. Related #98384. Thanks @joshavant.
- **PR #98146** fix(cli): explain how to recover from device approve deadlock. Thanks @RomneyDa.
- **PR #98423** improve(ios): clarify Control and Talk visual hierarchy. Related #98397.
- **PR #98217** fix(doctor): recover legacy cron archive across devices. Thanks @masatohoshino.
- **PR #98333** feat(openai): add GPT-5.6 series support. Related #98296. Thanks @steipete-oai.
- **PR #96393** fix(cron): preserve action-required command output. Related #96346. Thanks @snowzlmbot and @nz365guy.
- **PR #98429** fix(ios): classify TLS fingerprint timeouts. Thanks @joshavant.
- **PR #98439** fix: Android setup codes accept local mDNS gateway hosts. Thanks @joshavant.
- **PR #98443** fix(ios): improve light and dark appearance contrast. Related #98440.
- **PR #97742** fix(llm): preserve structured tool result text across providers. Thanks @snowzlmbot.
- **PR #97968** fix(status): surface unregistered memory embedding providers. Thanks @masatohoshino.
- **PR #92237** fix(agents): preserve runtime settings overrides [AI-assisted]. Thanks @sercada.
- **PR #95888** fix(active-memory): caveat mutable ops facts; mark truncated recall as incomplete. Thanks @spencer2211.
- **PR #98291** fix(gateway): surface systemd start-limit exhaustion. Thanks @masatohoshino.
- **PR #90517** fix(gateway): hint missing external plugin for web login. Related #83277. Thanks @TUARAN and @carol-iung.
- **PR #98369** test(infra): add unit tests for SQLite user_version pragma helper. Thanks @dwc1997.
- **PR #98340** fix: extension api.exec leaves child processes after timeout. Related #98335. Thanks @ooiuuii.
- **PR #92063** fix(ui): collapse duplicate assistant groups during segmented streaming. Related #63956. Thanks @harjothkhara and @contentfree.
- **PR #98354** fix(infra): guard delivery queue inflate against corrupted entry_json. Thanks @Pick-cat.
- **PR #90566** fix(agents): warn on cron announce skip. Related #68561. Thanks @sahibzada-allahyar and @Mibslee.
- **PR #98371** fix(ports): validate lsof PID parsing before assignment. Thanks @lzyyzznl.
- **PR #98356** fix(cron): keep provider-owned CLI sessions across the daily default reset. Thanks @yetval.
- **PR #98395** test(shared): add unit tests for account enabled guard. Thanks @dwc1997.
- **PR #98411** fix(agents): recover thinking errors from provider body. Related #98308. Thanks @sunlit-deng and @clearhorizoninvestments.
- **PR #98494** docs(skills): support variable landable sweep batches. Thanks @vincentkoc.
- **PR #91240** fix: report Codex ChatGPT status auth. Related #91099. Thanks @849261680 and @ukstem.
- **PR #98370** test(agents): add unit tests for thinking block detection. Thanks @dwc1997.
- **PR #96711** test: prefer shared temp dir helpers in config, gateway, cron, crestodian, and state tests. Thanks @xialonglee.
- **PR #98483** fix: Android QR scan starts gateway pairing. Thanks @joshavant.
- **PR #95230** fix docs-list-mdx-pages. Thanks @hugenshen.
- **PR #96322** fix(minimax): bound JSON response reads to prevent OOM. Thanks @lsr911.
- **PR #95348** fix config-chmod-warning. Thanks @hugenshen and @cursoragent.
- **PR #95229** fix(copilot): guard against undefined runtime.state during cli-metadata registration. Related #94516. Thanks @sunlit-deng and @cuihaijun.
- **PR #94636** fix(memory): skip raw snippets during promotion. Thanks @tayoun.
- **PR #94013** [AI] fix(feishu): guard partial channelRuntime in monitor startup. Thanks @xydt-tanshanshan.
- **PR #93466** [AI] fix(feishu): guard against missing inbound in channelRuntime fallback. Thanks @xydt-tanshanshan.
- **PR #98049** fix: hide expired pairing QR cards in Control UI. Related #98039. Thanks @ooiuuii.
- **PR #96094** fix(memory): prove live manager recovery after CLI reindex. Related #91167. Thanks @849261680 and @kiagentkronos-cell.
- **PR #98482** fix: advertise route-aware LAN Control UI links. Thanks @joshavant.
- **PR #71537** Recover archived (.reset) session transcripts in memory hook + session-logs skill. Thanks @injinj.
- **PR #96375** docs(config-agents): correct built-in alias table for opus and gpt. Thanks @niks999.
- **PR #98453** docs(gateway): fix Telegram streaming default in config-channels.md. Thanks @solodmd.
- **PR #98533** fix: repair hosted CI baseline assertions.
- **PR #98421** feat(imessage): native poll support — create, read, vote. Thanks @omarshahine and @lobster.
- **PR #98318** docs(matrix): document missing streaming.progress mode, progress sub-fields, and mentionPatterns config. Thanks @wm0018 and @vincentkoc.
- **PR #97753** docs(onboard): document 11 missing non-interactive CLI flags. Thanks @wm0018 and @vincentkoc.
- **PR #97851** fix(mattermost): bound null-body error response reads. Thanks @Pick-cat.
- **PR #98360** fix(memory-wiki): preserve notes after transient page reads. Related #98345. Thanks @qingminglong and @vincentkoc and @yetval.
- **PR #98551** test: fix stale core test type failures. Thanks @RomneyDa.
- **PR #98455** fix(browser): bound error body read in fetchHttpJson to prevent OOM. Thanks @wings1029.
- **PR #95906** fix(code-mode): surface QuickJS error name and message to the model. Thanks @ZengWen-DT and @vincentkoc.
- **PR #97901** fix(agents): stop copilot autoreview cleanup crash on Windows. Thanks @paulcam206.
- **PR #97923** fix(slack): truncate served arg-menu option labels on a surrogate boundary. Thanks @LEXES7.
- **PR #98010** fix(update): validate bundle plugin payloads by manifest contract. Related #97985. Thanks @LiLan0125 and @herove.
- **PR #85296** fix(codex): derive terminal-idle watchdog from explicit run timeout. Thanks @alkor2000 and @vincentkoc.
- **PR #97110** feat(i18n): add native app locale inventory. Thanks @vincentkoc.
- **PR #98396** fix: allow config.patch with defaulted provider baseUrl. Related #98270. Thanks @momothemage and @weltmaister.
- **PR #98503** fix(usage-bar): use Object.hasOwn instead of in operator to avoid prototype chain pollution. Related #98466. Thanks @chenyangjun-xy and @zhangLei99586.
- **PR #97111** feat(android): localize core gateway surfaces. Thanks @vincentkoc.
- **PR #97630** fix(media): normalize Windows inbound paths case-insensitively. Thanks @VectorPeak.
- **PR #82638** fix(agents): skip implicit provider discovery when models.mode is 'replace' [AI-assisted]. Related #66957. Thanks @eldar702 and @wangzhengshu.
- **PR #87917** fix sessions json lineage metadata. Related #80286. Thanks @zhangguiping-xydt and @islandpreneur007.
- **PR #93639** fix(message-tool): apply messages.responsePrefix to outbound sends. Thanks @ZengWen-DT.
- **PR #94440** fix: #94432 classify Cloudflare challenge 403 as upstream_html instead of auth_html. Thanks @lzyyzznl and @pbm9z95m6z-hue.
- **PR #98119** fix: reduce Docker build memory pressure. Related #98118. Thanks @zyzo.
- **PR #97679** feat(node): add --context-path flag to node run/install for reverse-p…. Related #97678. Thanks @wm0018.
- **PR #98339** fix(irc): classify host-less nick!user allowlist entries as mutable. Thanks @yetval.
- **PR #97662** fix(matrix): bound raw transport response reads to prevent OOM. Thanks @Alix-007.
- **PR #98137** fix: hoist timer declaration to avoid TDZ ReferenceError in abortable delay. Thanks @zhangLei99586.
- **PR #98134** fix: clear timeout timer in Tailscale binary probe Promise.race. Thanks @zhangLei99586.
- **PR #97989** fix(sms): stop internal tool-trace banners from reaching SMS replies. Thanks @ZengWen-DT.
- **PR #97972** fix(browser): CDP auth fails with percent-encoded credentials. Thanks @VectorPeak.
- **PR #98063** fix(reply): suppress tool-error progress delivery when messages.suppressToolErrors is set. Thanks @moeedahmed and @amittell.
- **PR #94964** fix(reload): cancel deferred channel reload on in-process restart. Related #79487. Thanks @lzyyzznl and @tseller.
- **PR #98598** fix: restore main lint after timer repairs. Related #98462, #98464. Thanks @zhangLei99586.
- **PR #98587** fix(slack): guard relay WebSocket frame JSON.parse against malformed input. Thanks @lsr911 and @vincentkoc.
- **PR #90030** fix(memory-core): skip qmd zero-hit search sync. Related #90023. Thanks @sahibzada-allahyar and @ruben2000de.
- **PR #98493** fix(transcripts): close readline interface and destroy read stream on error exit. Related #98467. Thanks @wangmiao0668000666 and @zhangLei99586.
- **PR #98497** fix(cli): show exit code when plugin npm install returns empty output. Thanks @Sanjays2402 and @vincentkoc.
- **PR #97112** feat(apple): localize core native app surfaces. Thanks @vincentkoc.
- **PR #98610** fix: restore tooling CI after transcript test addition.
- **PR #77539** fix(subagent): preserve steered task text on restart redispatch. Thanks @amittell.
- **PR #97113** feat(i18n): refresh all native locale artifacts. Thanks @vincentkoc.
- **PR #98620** feat(doctor): warn about in-flight cron jobs. Thanks @masatohoshino.
- **PR #98605** test(shared): add unit tests for human-readable list formatting. Thanks @dwc1997.
- **PR #97348** feat(autoreview): support cursor-agent engine. Thanks @hxy91819.
- **PR #95943** fix(cron): preserve provider/model on isolated-run timeout row. Related #95873. Thanks @ZengWen-DT and @cursoragent and @luke-renjoy.
- **PR #94149** fix(status): bound systemd service probes so status cannot hang on a wedged systemctl (#84698). Thanks @ZengWen-DT and @cursoragent and @zus-assistant.
- **PR #88159** fix(cli): retry logs.tail after journal fallback in logs follow. Thanks @anyech and @vincentkoc.
- **PR #98508** fix(update-check): bound npm registry JSON response read to prevent OOM. Thanks @lzyyzznl.
- **PR #98496** fix(tlon): bound error response body reads to prevent OOM. Thanks @Pandah97.
- **PR #98554** fix(openai): bound embedding batch file downloads. Thanks @sunlit-deng and @vincentkoc.
- **PR #98652** fix: stop invalid message timeouts from stalling.
- **PR #77973** fix(gateway): cap agentRunCache to prevent unbounded growth under run fan-out. Related #77976. Thanks @fede-kamel and @vincentkoc.
- **PR #98525** fix(agents): time out local streams without first event. Thanks @osolmaz.
- **PR #94022** fix(cron): persist startup catch-up deferral ids in service state to prevent read-RPC clobber. Related #93935. Thanks @RichChen01 and @vincentkoc and @yetval.
- **PR #93810** fix(cron): preserve startup overflow catch-up deferrals in start() maintenance pass. Thanks @yetval and @vincentkoc.
- **PR #98623** fix: media tools skip env-key provider plugins when auto-selecting models. Thanks @medns.
- **PR #98665** fix(claude-cli): return updatedInput in can_use_tool allow response for Claude Code 2.1. Related #95171. Thanks @yetval and @carterdawson.
- **PR #94250** fix(feishu): send blocks as independent messages when blockStreaming is enabled. Related #55027. Thanks @xialonglee and @vincentkoc and @ZichaoLong.
- **PR #93379** fix(whatsapp): thread authDir through command authorization and owner bypass for LID JID resolution. Related #77755. Thanks @xialonglee and @jiveshkalra.
- **PR #98646** fix: keep workspace rail file sections scrollable. Related #98566. Thanks @wuqxuan and @645648406-max.
- **PR #98602** fix: iOS Talk fallback settings opens Voice & Talk. Related #98593. Thanks @PollyBot13.
- **PR #98611** fix(ui): add overflow-y:auto to workspace rail sections to prevent file list overflow (fixes #98566). Thanks @zw-xysk and @645648406-max.
- **PR #98619** fix(qa-lab): credential lease requests fail on oversized Convex broker responses. Thanks @ZengWen-DT.
- **PR #94326** fix(memory-wiki): disambiguate the reserved index page stem for synthesis and ingest. Thanks @yetval and @vincentkoc.
- **PR #98659** fix(codex): classify get_goal read statuses as successful dynamic tool calls. Thanks @yetval.
- **PR #96856** fix(codex): successful sessions_spawn and goal tool results recorded as failures. Thanks @nxmxbbd.
- **PR #98660** fix(inworld): guard voices JSON.parse against malformed API response bodies. Thanks @solodmd.
- **PR #95430** fix(embedded-agent-runner): pump async streamFn through pumpStreamWithRecovery for mid-stream error recovery. Related #95429. Thanks @lzyyzznl and @vincentkoc and @alexelgier.
- **PR #98644** fix: tool summaries preserve emoji truncation boundaries. Thanks @ZengWen-DT.
- **PR #80928** fix(telegram): suppress fallback reply when plugin command returns suppressReply: true. Related #80756. Thanks @alexuser and @UnClouded77.
- **PR #98701** fix: prevent agents-tools message test timeouts.
- **PR #92657** feat(usage): ship built-in /usage full footer. Thanks @Marvinthebored.
- **PR #92877** fix(usage): make built-in footer easier to wrap on Telegram. Thanks @Marvinthebored.
- **PR #98126** Restore Telegram /steer for active Codex runs. Related #81594. Thanks @100yenadmin and @Kyzcreig.
- **PR #92037** feat(cron): on-exit schedule — wake on a watched command's exit. Thanks @anagnorisis2peripeteia.
- **PR #98452** feat(ios): modernize the app with iOS 26 Liquid Glass.
- **PR #98006** Add Telegram /login Codex pairing flow. Thanks @100yenadmin.
- **PR #98735** fix(telegram): preserve rich forwarded message text. Thanks @obviyus.
- **PR #97962** refactor(qa): use transport-native actions in flow scenarios. Thanks @RomneyDa.
- **PR #98726** fix(nvidia): use Nemotron Super 1M context. Thanks @eleqtrizit.
- **PR #98691** fix(imessage): shed emoji anywhere in poll-vote echo match. Thanks @omarshahine.
- **PR #97174** Fix Telegram plugin callback routing. Thanks @goldmar.
- **PR #89597** fix: migrate QQBot credential backups to SQLite KV.
- **PR #98536** feat: prepare scoped conversation capability profiles.
- **PR #92274** fix(agents): classify embedded prompt lock error as permanent announce failure. Related #91527. Thanks @fsdwen and @zackchiutw.
- **PR #98102** fix(telegram): durably retry inbound media dropped during restart (#98076). Thanks @luoyanglang and @DaveArcher18.
- **PR #98755** fix(cron): detach session-targeted runs. Related #98121. Thanks @obviyus and @EthanSK.
- **PR #96065** fix(install): manage config-secretref env refs via OPENCLAW_SERVICE_MANAGED_ENV_KEYS. Thanks @Darren2030 and @obviyus.
- **PR #98666** fix: diagnose Windows LAN Gateway firewall blocks. Thanks @joshavant.
- **PR #98501** fix(codex): rename destructive approval mode to ask. Related #98499. Thanks @kevinslin.
- **PR #98775** fix(telegram): survive transient getUpdates errors and stop per-send cache rewrites. Related #98772, #98773. Thanks @obviyus.
- **PR #98776** fix(telegram): back off, dead-letter, and tombstone spooled updates so poison messages cannot block or duplicate. Related #98774. Thanks @obviyus.
- **PR #96454** feat(cli): openclaw attach — launch an external harness bound to a gateway session. Thanks @anagnorisis2peripeteia and @obviyus.
- **PR #98786** fix(telegram): final replies no longer drop on rejected rich entities, captions, quotes, or long flood waits. Related #98778. Thanks @obviyus.
- **PR #97496** Doctor: expose channel plugin blocker findings. Thanks @giodl73-repo.
- **PR #98792** fix(ci): restore docs and test type checks.
- **PR #98736** improve(ios): simplify Talk controls and composer alignment.
- **PR #98183** fix(gateway): distinguish reachable gateway from failed status probe. Thanks @masatohoshino.
- **PR #98808** docs(telegram): move maintainer decisions into scoped AGENTS.md with reliability invariants. Thanks @obviyus.
- **PR #98138** fix: guard setDeep against empty keys array in Chrome profile decoration. Thanks @zhangLei99586.
- **PR #92283** fix(agents): don't inject A2A turns into isolated-cron sessions_send (#92257). Thanks @harjothkhara and @vincentkoc and @nailujac.
- **PR #98812** fix(codex): preserve plugin app approvals in side conversations.
- **PR #97889** fix(discord): guard JSON.parse against malformed API response bodies. Thanks @lsr911.
- **PR #98689** fix(wizard): reject loose gateway port input. Related #98681. Thanks @qingminglong.
- **PR #98720** fix(nostr): clear per-relay publish timeout timer to prevent dangling handles. Related #98463. Thanks @wangmiao0668000666 and @zhangLei99586.
- **PR #98787** fix(memory-wiki): retry transient existing-page reads in wiki_apply and chatgpt import. Thanks @yetval and @vincentkoc.
- **PR #98818** fix(ci): recover incomplete Swift build caches.
- **PR #98811** feat(ios): modernize navigation and settings. Related #98803.
- **PR #98843** docs: update mobile app release messaging. Thanks @joshavant.
- **PR #93209** test: prefer auto-cleaning temp dir helper. Thanks @hxy91819.
- **PR #98789** fix(telegram): sends and actions without an account id ignore the configured defaultAccount. Thanks @yetval.
- **PR #98806** fix(telegram): webhook updates survive crashes and restarts via durable spooling. Related #98777. Thanks @obviyus.
- **PR #98688** fix(fal): route grok-imagine and nano-banana-2-lite edits to correct endpoints. Thanks @davenicoll and @vincentkoc.
- **PR #98891** fix(agents): normalize non-array tool-result content at transcript ingest. Related #98825. Thanks @obviyus and @snowzlmbot.
- **PR #98781** fix(imessage): poll render vote-cue, cross-run echo suppression, and comment fold. Thanks @omarshahine.
- **PR #97500** Doctor: expose tool result cap findings. Thanks @giodl73-repo.
- **PR #98769** fix: Telegram replies duplicate recent context after sent replies. Related #98767. Thanks @rabsef-bicrym.
- **PR #98933** fix(agents): stop gateway crash from wedged claude-cli turns and persist heartbeat session bindings. Related #98894, #98895. Thanks @obviyus.
- **PR #98934** fix(agents): recover claude-cli context-overflow sessions and keep retry artifacts alive. Related #98897. Thanks @obviyus.
- **PR #98908** refactor(agents): fold assistant string normalization into transcript ingest. Thanks @obviyus.
- **PR #98738** fix(agents): fail fast with attributable reason after MCP stdio session dies mid-run. Thanks @masatohoshino and @vincentkoc.
- **PR #98879** fix: backup skips volatile cache paths. Related #98865. Thanks @ZengWen-DT and @vincentkoc and @carterstebbins23-spec.
- **PR #98942** fix(agents): unify claude-cli output classification across live and one-shot paths. Related #98896. Thanks @obviyus.
- **PR #98932** fix(anthropic): restore Fable 5 Vertex simple completions.
- **PR #98947** fix(cron): restore persistent session targets.
- **PR #96523** fix(agents): preserve embedded OpenAI completions usage. Thanks @ly85206559 and @vincentkoc.
- **PR #98758** perf(build): reduce plugin SDK declaration package size. Related #98757. Thanks @RomneyDa.
- **PR #98877** fix(mattermost): include later team members in peer directory. Related #98871. Thanks @qingminglong.
- **PR #98953** feat(ios): refine the chat experience. Related #98929.
- **PR #98876** fix(terminal): preserve sibling home-prefix paths. Related #98872. Thanks @qingminglong.
- **PR #98930** feat(ios): PR1 brand color palette overhaul. Thanks @joelnishanth.
- **PR #94566** fix(android): make offline chat actionable. Thanks @Tosko4.
- **PR #98955** fix(agents): preserve fresh tool result text under aggregate cap. Related #98874. Thanks @momothemage and @lamkan0210.
- **PR #98059** [codex] Support Android selected photo access. Thanks @NianJiuZst.
- **PR #98914** fix(android): return settings details to their originating tab on Back. Thanks @Lokimorty.
- **PR #98898** fix(ios): back from settings details returns to the originating screen. Thanks @Lokimorty.
- **PR #98235** fix(feishu): include video upload duration. Thanks @areslp.
- **PR #98966** fix(discord): gate guild metadata reads [AI]. Thanks @pgondhi987.
- **PR #98985** fix: clean up iOS About page copy. Related #98943. Thanks @sahilsatralkar.
- **PR #98856** fix(ios): gateway error shows twice on the Settings Gateway page. Thanks @Lokimorty.
- **PR #98936** fix: Control row icons use inconsistent row styling (iOS). Related #98916. Thanks @sahilsatralkar.
- **PR #98040** [codex] Fix Android camera snap cleanup. Thanks @NianJiuZst.
- **PR #99039** fix(macos): stop runtime config-health sidecar access. Related #98917. Thanks @momothemage and @P51moustache.
- **PR #92667** ci: add process exec CodeQL security shard. Thanks @hxy91819.
- **PR #98055** [codex] Gate Android Talk capture starts in background. Thanks @NianJiuZst.
- **PR #98067** [codex] Cancel Android gateway pending RPCs on close. Thanks @NianJiuZst.
- **PR #98698** fix(android): show specific gateway auth-recovery reason instead of generic label. Related #98046. Thanks @masatohoshino and @ccaprani.
- **PR #83826** test(android): poll for stale TLS probe cleanup in auth test. Thanks @NeatGuyCoding.
- **PR #98983** fix(agents): handle variadic claude --mcp-config and serialize gemini credential staging. Related #98944, #98945. Thanks @obviyus.
- **PR #99145** fix(auto-reply): suppress room-event notice leaks. Thanks @obviyus.
- **PR #99144** fix(auto-reply): default room events to silence. Thanks @obviyus.
- **PR #98608** fix: Mattermost fails to load after configured plugin repair. Related #98564. Thanks @jacobtomlinson.
- **PR #99143** fix(telegram): keep group history always on. Related #99142. Thanks @obviyus.
- **PR #99159** fix(agents): claude-cli lifecycle cleanup — loopback fail-loud, exit-0 failover, bounded reseed, image sweep, one prepare cleanup owner. Related #98946. Thanks @obviyus.
- **PR #98391** Expose disk space doctor lint findings. Thanks @giodl73-repo.
- **PR #98835** fix(config/sessions): narrow reply-session initialization revision to identity fields. Related #98672. Thanks @moguangyu5-design and @jalehman and @AaronFaby.
- **PR #99123** fix(android): ignore chat events with missing assistant role in voice text extraction. Thanks @ly85206559 and @cursoragent.
- **PR #99147** fix(android): preserve split SMS permission grants. Thanks @NianJiuZst.
- **PR #99107** fix(android): bracket IPv6 hosts in manual gateway URL composition. Thanks @ly85206559 and @cursoragent.
- **PR #99158** fix: require Android contact and calendar write permissions in onboarding. Thanks @NianJiuZst.
- **PR #99110** fix(android): strip ws scheme prefix from manual gateway host input. Related #87216. Thanks @ly85206559 and @cursoragent and @ruben2000de.
- **PR #99212** fix(ci): session concurrency test flakes during child handshake.
- **PR #94385** fix(feishu): preserve button command values in fallback text and add Feishu comment guidance with callback privacy. Related #69754. Thanks @xialonglee and @1yihui.
- **PR #98563** fix: route iOS OpenAI realtime Talk through WebRTC. Thanks @PollyBot13.
- **PR #99204** fix: require Android contact and calendar write permissions. Thanks @NianJiuZst.
- **PR #99134** fix: OAuth refresh failures report reauth instead of stale success. Related #99120. Thanks @100yenadmin.
- **PR #99153** fix: clean up Android camera clips on cancellation. Thanks @NianJiuZst.
- **PR #99118** [codex] fix(memory-lancedb): align apache arrow peer dependency. Related #90295. Thanks @allenhurff and @joshavant.
- **PR #98066** fix: keep iOS LAN QR pairing authenticated after bootstrap. Related #98064. Thanks @ooiuuii.
- **PR #99155** fix: stop iOS screen recording after cancellation. Thanks @NianJiuZst.
- **PR #95973** fix(telegram): explain disabled plugin approval failures. Related #95800. Thanks @MonkeyLeeT and @ChrisBot2026.
- **PR #99233** fix: ignore test-only network CI guard lines. Thanks @joshavant.
- **PR #98951** fix: strict guarded fetch fails before managed proxy DNS. Related #98925. Thanks @momothemage and @sandl99.
- **PR #99137** fix: prevent Voice Wake crash after Talk audio capture. Thanks @PollyBot13.
- **PR #99052** fix: Update Dark/Light mode UI control appearance. Related #98995. Thanks @sahilsatralkar.
- **PR #99245** fix(ios): return chat to originating control detail. Thanks @Solvely-Colin.
- **PR #92602** fix(android): queue node events until gateway connect. Related #79552. Thanks @ashishpatel26 and @hectorrp13.
- **PR #98277** fix: keep Android gateway settings save idempotent. Thanks @Solvely-Colin.
- **PR #99256** fix(auto-reply): single canonical group history and deduped turn metadata. Related #99218. Thanks @obviyus.
- **PR #99259** fix(android): use Bluetooth microphones for voice capture. Related #96241. Thanks @gwtaylor.
- **PR #98751** test(qa): prove native command targeting across QA transports. Thanks @RomneyDa.
- **PR #98779** test(qa): cover expanded Crabline bindings. Thanks @RomneyDa.
- **PR #99262** test(qa): cover Crabline Signal sends. Thanks @RomneyDa.
- **PR #99261** refactor(shared): establish lazy runtime loader foundation. Thanks @RomneyDa.
- **PR #99264** test(qa): cover Crabline Mattermost sends. Thanks @RomneyDa.
- **PR #99265** test(qa): cover Crabline Matrix sends. Thanks @RomneyDa.
- **PR #98400** Expose heartbeat template doctor lint findings. Thanks @giodl73-repo.
- **PR #98695** Expose legacy plugin manifest doctor lint findings. Thanks @giodl73-repo.
- **PR #99278** refactor(shared): consolidate core leaf lazy loaders. Thanks @RomneyDa.
- **PR #99274** fix(zalo): match native bot identity fields. Thanks @RomneyDa.
- **PR #99126** test(discord): clarify and guardrail gateway proxy selection. Related #98266. Thanks @svuppala2006 and @joshavant and @sallyom.
- **PR #99290** feat(ios): add licenses settings screen. Thanks @joshavant.
- **PR #98907** fix(telegram): distinguish and render streamed reasoning/commentary progress lanes. Thanks @Marvinthebored.
- **PR #99294** fix(qa): stagger isolated worker startup. Thanks @RomneyDa.
- **PR #99276** fix(memory-wiki): source imports crash on unreadable pages. Thanks @obviyus.
- **PR #99296** refactor(shared): consolidate gateway and stateful runtime lazy loaders. Thanks @RomneyDa.
- **PR #98768** Allow alternate Zalo Bot API roots. Thanks @RomneyDa.
- **PR #99298** refactor(shared): consolidate Discord Slack and Telegram lazy loaders. Thanks @RomneyDa.
- **PR #99307** fix(memory-wiki): avoid implicit error coercion. Thanks @RomneyDa.
- **PR #99306** feat(auto-reply): persist ambient room events as transcript rows. Related #99257. Thanks @obviyus.
- **PR #99302** refactor(shared): consolidate remaining channel lazy loaders. Thanks @RomneyDa.
- **PR #99303** test(qa): cover Crabline Zalo transport. Thanks @RomneyDa.
- **PR #99299** feat(android): add licenses settings screen. Thanks @joshavant.
- **PR #99220** fix(ios): onboarding Retry Connection does nothing after editing gateway details. Related #99219. Thanks @abdullahtas0.
- **PR #98749** refactor(shared): consolidate provider and utility lazy loaders. Thanks @RomneyDa.
- **PR #99355** fix(ci): restore Telegram and plugin SDK guard checks. Thanks @RomneyDa.
- **PR #88899** fix(android): render chat content through Markdown. Related #88014. Thanks @Pluviobyte and @Iman-Sharif.
- **PR #99310** test(qa): migrate channel streaming evidence to transport flow. Thanks @RomneyDa.
- **PR #99350** fix(ios): add Photos permission controls. Related #99046. Thanks @Tony-ooo.
- **PR #99361** refactor(plugins): consolidate record guards. Thanks @RomneyDa.
- **PR #99359** refactor(shared): consolidate core record guards. Thanks @RomneyDa.
- **PR #97208** fix: avoid DeepSeek-native thinking on OpenRouter V4. Related #97196. Thanks @NianJiuZst and @patelmm79.
- **PR #99385** fix(sessions): scope ambient transcript watermark to session id. Related #99373. Thanks @obviyus.
- **PR #99389** fix(auto-reply): restore per-turn message-tool delivery contract. Related #99371. Thanks @obviyus.
- **PR #98269** fix(android): derive Voice readiness from Gateway catalog. Related #98268. Thanks @Solvely-Colin.
- **PR #92872** fix(qqbot): allow scoped sandbox media sends. Thanks @zhangguiping-xydt and @sliverp.
- **PR #99414** fix(android): expose exact gateway recovery actions. Related #98045, #98046. Thanks @ccaprani.
- **PR #99289** feat: session-first sidebar, compact context ring, and warm light theme for the Control UI. Related #99288.
- **PR #99234** feat(nodes): add auto-discovered Ollama inference. Related #99228.
- **PR #97095** fix: memory_search honors generic embedding providers. Thanks @849261680.
- **PR #98841** fix(gateway): include session label in deriveSessionTitle fallback chain. Related #98742. Thanks @SunnyShu0925 and @BSG2000.
- **PR #99301** fix(feishu): catch unhandled promise rejection in streaming card flush timer. Thanks @lwy-2.
- **PR #99391** fix(compaction): count nested tool result content. Related #99375. Thanks @LZY3538 and @imchloe92.
- **PR #99407** fix(daemon): avoid loading full gateway logs during diagnostics. Thanks @sunlit-deng.
- **PR #99291** Fix/issue 98958 gateway lock fd leak. Related #98958. Thanks @chenyangjun-xy and @zhangLei99586.
- **PR #99475** fix(ios): contacts.add crashes the app via unfetched CNContactFormatter keys. Thanks @abdullahtas0.
- **PR #98003** fix(anthropic): wire buildGuardedModelFetch into the Cloudflare createClient branch. Thanks @wangmiao0668000666.
- **PR #99425** fix: strip conda env marker from host tool runs. Related #99424. Thanks @ooiuuii and @krissding.
- **PR #99398** fix(cli): reject unsafe sessions tail counts. Thanks @qingminglong.
- **PR #98855** fix: chat.send no reply when thinking metadata is set. Thanks @jesse-merhi.
- **PR #98752** Rework Android gateway onboarding setup. Thanks @jesse-merhi.
- **PR #99446** fix(agents): preserve fd find failures. Thanks @zhangguiping-xydt.
- **PR #99152** fix(config): use Object.hasOwn instead of in operator in restoreOriginalValueOrThrow. Thanks @zenglingbiao.
- **PR #99460** fix: redact dotted API key activity previews. Related #99459. Thanks @ooiuuii.
- **PR #99455** fix: long mobile media recordings time out. Thanks @NianJiuZst.
- **PR #99410** fix(subagents): match requesterSessionKey when controllerSessionKey differs in list filter. Related #75593. Thanks @sheyanmin and @aaajiao.
- **PR #98791** feat(signal): show status reactions during inbound replies. Thanks @jesse-merhi.
- **PR #98683** fix(ui): keep landscape composer compact. Related #98615. Thanks @qingminglong and @jin-li.
- **PR #99428** fix(logging): redact Telegram bot tokens from timeout URLs. Related #96982. Thanks @xialonglee and @liuhaiyang14.
- **PR #99217** Preserve Codex output after missing turn completion. Thanks @100yenadmin and @Sedrak-Hovhannisyan and @fuller-stack-dev.
- **PR #99520** fix(gateway): declare the dev agent required by the gateway e2e session key. Related #99513. Thanks @masatohoshino.
- **PR #95738** feat(signal): add target aliases. Thanks @jesse-merhi.
- **PR #98258** improve: make native chat scrolling reader-managed. Related #98255. Thanks @christopheraaronhogg.
- **PR #99506** fix: keep always-on group fallback messages in dispatch. Related #99457. Thanks @LZY3538 and @zqchris.
- **PR #89671** fix(google-meet): force English Meet UI via hl=en so automation works on any locale. Thanks @Unayung.
- **PR #98130** fix(infra): bound jsonl-socket response buffer to prevent OOM. Thanks @Pick-cat.
- **PR #99526** fix(agents): preserve primitive tool result output. Related #99523. Thanks @snowzlm.
- **PR #99525** fix(imessage): recognize bare hex group chat identifiers as chat targets. Related #89235. Thanks @MatthewDelprado.
- **PR #99098** fix: harden native i18n identifier filtering. Thanks @hxy91819.
- **PR #99099** fix: harden docs map heading rendering. Thanks @hxy91819.
- **PR #98725** Expose legacy plugin dependency doctor lint findings. Thanks @giodl73-repo.
- **PR #99595** fix(agents): keep cli session binding facts session-stable. Related #99372. Thanks @obviyus.
- **PR #90152** fix(telegram): stop duplicate fallback when dispatch fails after final reply. Thanks @zhangguiping-xydt.
- **PR #98729** Expose stale plugin runtime symlink doctor lint findings. Thanks @giodl73-repo.
- **PR #99591** fix(android): preserve numeric invoke error codes. Thanks @ly85206559.
- **PR #98406** Expose WhatsApp responsiveness doctor lint findings. Thanks @giodl73-repo.
- **PR #99570** fix(android): reject IPv6 zone IDs in gateway endpoint URLs. Thanks @ly85206559 and @cursoragent.
- **PR #99557** fix(android): filter device and internal sessions from thread picker. Thanks @ly85206559 and @cursoragent.
- **PR #99568** fix(android): block self-package notification forwarding in allowlist mode. Thanks @ly85206559 and @cursoragent.
- **PR #99592** fix(android): parse talk directive aliases case-insensitively. Thanks @ly85206559.
- **PR #99477** fix: avoid iOS node permission prompts. Thanks @NianJiuZst.
- **PR #99374** improve(qa): standardize script evidence output. Thanks @RomneyDa.
- **PR #99468** improve: tighten iOS Control row density. Related #99439. Thanks @sahilsatralkar.
- **PR #99642** test: avoid cross-OS socket close event race. Thanks @RomneyDa.
- **PR #89967** fix(macos): LaunchAgent starts gateway on external home volumes. Related #87199. Thanks @zhangguiping-xydt and @joshdaynard.
- **PR #98613** fix(media): guard ffprobe JSON parse against malformed output. Thanks @Pick-cat.
- **PR #97839** fix: log terminal session persistence failures. Related #97795. Thanks @LZY3538 and @aniruddhaadak80.
- **PR #99247** feat: clarify iOS Location Always permission flow. Thanks @PollyBot13.
- **PR #98224** fix(auto-reply): strip stray punctuation before silent-reply token detection. Thanks @SunnyShu0925.
- **PR #97328** fix(google): rotate Gemini API keys for LLM requests. Thanks @MonkeyLeeT.
- **PR #99661** fix(macos): remote mode fails with managed SSH aliases.
- **PR #99649** fix(qa): defer partial Crabline recorder rows. Related #99648. Thanks @RomneyDa.
- **PR #99211** Expose legacy cron store doctor lint findings. Thanks @giodl73-repo.
- **PR #99629** test(qa): redact script evidence diagnostics. Thanks @RomneyDa.
- **PR #99647** Fix Slack retry for session init conflicts. Thanks @steipete-oai.
- **PR #99628** improve: enforce canonical QA scenario ownership. Related #99627. Thanks @RomneyDa.
- **PR #99632** refactor(qa): simplify transport adapter contracts. Related #99622. Thanks @RomneyDa.
- **PR #99656** test(qa): use full-turn budget for native stop recovery. Related #99655. Thanks @RomneyDa.
- **PR #99605** fix(google): bound OAuth token error response reads. Thanks @mushuiyu886.
- **PR #99679** fix(qa): consume Crabline events without recorder polling. Related #99664. Thanks @RomneyDa.
- **PR #99687** refactor(infra): consolidate SHA-256 digest helpers. Related #99675. Thanks @RomneyDa.
- **PR #98796** [AI-assisted] feat(android): add chat command controls. Thanks @IWhatsskill.
- **PR #99671** refactor: consolidate number coercion callers. Related #99667. Thanks @RomneyDa.
- **PR #99640** fix: CLI agent session resume churns when owner and non-owner alternate in a group. Related #99633. Thanks @obviyus.
- **PR #99682** refactor(models): consolidate catalog ref parsing. Related #99674. Thanks @RomneyDa.
- **PR #99566** fix(exec): avoid splitting surrogate pairs in approval display. Thanks @mikasa0818.
- **PR #99702** refactor: remove redundant unique-list aliases. Related #99697. Thanks @RomneyDa.
- **PR #99246** feat(ios): implement branded typography design system. Thanks @joelnishanth and @cursoragent.
- **PR #99710** fix(build): Docker package preparation misses plugin SDK declarations. Thanks @RomneyDa.
- **PR #99715** refactor: consolidate image data URL formatting. Thanks @RomneyDa.
- **PR #98764** fix(ui): copy workspace file paths over plain HTTP. Related #98759. Thanks @ZengWen-DT and @adinballew.
- **PR #99678** fix(build): forward default exports through stable runtime aliases. Related #99677. Thanks @headbouyJB and @vincentkoc.
- **PR #99370** fix(file-transfer): don't inline zero-byte files as image content blocks. Thanks @2loch-ness6 and @vincentkoc.
- **PR #99540** fix(doctor): shell completion install fails doctor when profile is read-only. Related #99237. Thanks @rballiance and @hunglp6d.
- **PR #99718** refactor(text): consolidate cleanup owners. Thanks @RomneyDa.
- **PR #98819** fix(plugins): resolve public artifacts from installed plugin roots. Related #98740. Thanks @amknight and @KelTech-Services.
- **PR #99721** refactor: consolidate async timing helpers. Thanks @RomneyDa.
- **PR #99722** fix: group agent session resume churns when messages toggle between @-mention and plain. Related #99696. Thanks @obviyus.
- **PR #99676** refactor: consolidate string reader mechanics. Related #99663. Thanks @RomneyDa.
- **PR #99705** improve(qa): execute runtime scenarios through Docker. Thanks @RomneyDa.
- **PR #99231** improve: native iOS look with stock SwiftUI navigation, forms, chat, and talk visualizer. Related #99195. Thanks @marvkr.
- **PR #99549** fix(auto-reply): don't block reply completion on transcript mirror. Thanks @Shagrat2.
- **PR #99736** fix(qa): prevent smoke gateways from losing built files. Related #99734. Thanks @RomneyDa.
- **PR #99658** feat(providers): add ClawRouter routing and quotas. Related #99657.
- **PR #99238** Expose channel preview warning doctor findings. Thanks @giodl73-repo.
- **PR #99759** fix(providers): resolve ClawRouter auth-profile models.
- **PR #99561** fix: keep OpenClaw control tools available when tool_search misroutes. Related #99464. Thanks @100yenadmin and @joshavant.
- **PR #99750** refactor: consolidate exact boolean coercion. Thanks @RomneyDa.
- **PR #99753** refactor: consolidate abort primitives. Thanks @RomneyDa.
- **PR #99426** feat: add slash command picker in chat composer. Thanks @VicZhang6 and @Solvely-Colin.
- **PR #99771** refactor: consolidate free-port test helpers. Thanks @RomneyDa.
- **PR #99755** refactor: consolidate policy-free deferred promises. Thanks @RomneyDa.
- **PR #99719** refactor(net): consolidate URL protocol predicates. Thanks @RomneyDa.
- **PR #99743** fix: avoid native command QA timeout under CI contention. Thanks @RomneyDa.
- **PR #99368** fix(qa): prevent qa smoke ci timeouts under gateway concurrency. Thanks @RomneyDa.
- **PR #99778** refactor(scripts): share regexp literal escaping. Thanks @RomneyDa.
- **PR #99737** test: add executable runtime fixture canaries. Thanks @RomneyDa.
- **PR #99735** test(qa): exercise Gateway and MCP scenarios over real transports. Thanks @RomneyDa.
- **PR #99784** fix(qa): stabilize primary smoke runtime evidence. Thanks @RomneyDa.
- **PR #99726** fix(onboard): skip unavailable skill installers via lifecycle readiness preflight. Thanks @fuller-stack-dev and @Sedrak-Hovhannisyan.
- **PR #99793** ci: reuse one package in QA smoke.
- **PR #99767** feat(macos): install and run the local Gateway automatically. Related #99764.
- **PR #99820** ci: increase artifact Testbox memory.
- **PR #99822** feat: soft-resume CLI sessions on prompt drift instead of hard invalidation. Related #99729. Thanks @obviyus.
- **PR #99129** fix(markdown-core): use Object.hasOwn instead of in operator in parseFrontmatterBlock. Thanks @zenglingbiao and @vincentkoc.
- **PR #99803** fix(mcp): suppress unhandled error on stderr pipe in stdio transport. Thanks @cxbAsDev and @vincentkoc.
- **PR #99802** fix(supervisor): suppress unhandled stream errors on child stdout/stderr. Thanks @cxbAsDev and @vincentkoc.
- **PR #99800** fix(ssh-tunnel): handle spawn error to prevent unhandled rejection crash. Thanks @cxbAsDev and @vincentkoc.
- **PR #99653** fix(cli): hide synthetic Claude reseed prompts. Related #99646. Thanks @ZOOWH and @vincentkoc and @Jeehut.
- **PR #99728** fix(config): preserve recovery state during config-health migration. Related #99280. Thanks @joshavant and @jalehman and @ccbridle.
- **PR #99839** fix(gateway): preserve legacy reseed attachments. Thanks @vincentkoc.
- **PR #99830** fix: stop rubber-band bounce of the Control UI shell in the Mac app web view.
- **PR #99851** fix(agents): preserve fallback tool-call hints. Thanks @vincentkoc.
- **PR #98994** fix(line): truncate outbound altText, location, menu, and code fields on code point boundaries. Thanks @LEXES7 and @vincentkoc.
- **PR #99846** fix(config): restrict config paths to own properties. Thanks @vincentkoc and @zenglingbiao.
- **PR #99861** fix(telegram): one outbound rich-HTML normalizer and one rich-to-plain fallback policy. Related #99833. Thanks @obviyus.
- **PR #99866** fix(telegram): classify inbound events from the canonical mention decision so direct mentions stop lurking. Related #99854. Thanks @obviyus.
- **PR #99832** fix: reject incompatible Node 23 runtimes. Thanks @fuller-stack-dev.
- **PR #99243** Polish iOS onboarding and chat critique fixes. Thanks @jcooley8.
- **PR #99714** perf(usage): shrink durable usage cache entries. Related #99511. Thanks @dexhunter and @wayne524.
- **PR #99838** feat: declutter the Control UI shell — reasoning effort slider, borderless composer controls, version out of the sidebar. Related #99837.
- **PR #93686** fix(weixin): startAccount preserves session routing. Related #93556. Thanks @zhangguiping-xydt and @htkillermax-gif.
### Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.7.1-beta.2
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.7.1-beta.2.tgz
- integrity: `sha512-KYPBQnAfEb/9qrxlw/96a90mMQeKdAZdUABMROOue9Ph2oFbnDGezZjd5Bmw4WhRyzgyvHOHqHje/swGipC4xA==`
- release SHA: `a580a7fe3fbd1b3329c978d58ca2f70e8ca37aee`
- full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.7.1-beta.2/release-evidence.md
- release publish: https://github.com/openclaw/openclaw/actions/runs/28735224348
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/28717730132
- full release validation: https://github.com/openclaw/openclaw/actions/runs/28717729503
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/28735371120
- plugin ClawHub publish: dispatched separately, not awaited by this proof: https://github.com/openclaw/openclaw/actions/runs/28735371597
- plugin ClawHub bootstrap: not needed
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/28735575588
- npm Telegram beta E2E: not supplied