## 2026.7.1
### 亮点
- **新模型与提供商:** 新增 Featherless、Claude Sonnet 5、Mythos 5、Meta Muse Spark 1.1 及 ClawRouter;将 GPT-5.6 设为全新安装的默认模型,为 Sol 和 Terra 启用 `/think ultra`,为 Luna 启用 `max`,尊重 Z.AI 的 `max` 设置,并在 OAuth 续期后刷新模型可用性。(#101092, #98254, #101238, #102873, #103070, #103163, #99658, #99759, #98333, #103581, #98021, #104778, #102289)感谢 @vincentkoc、@vortexopenclaw、@HamidShojanazeri、@davemorin、@Solvely-Colin、@jalehman、@steipete-oai、@bdjben、@obviyus、@sallyom、@anyech、@100yenadmin 及 @fuller-stack-dev。
- **控制界面与原生 macOS 聊天:** 将会话设为主要视图,采用最小化可搜索侧边栏、紧凑上下文环、推理努力度滑块、更简洁的仪表盘框架,以及原生 macOS 会话浏览器,支持模型与思考模式选择、斜杠命令、对话导出和上下文使用量显示。(#99289, #99838, #100386, #101103, #101497)
- **对话式引导流程:** Crestodian 现在在 CLI、Web 安装和 macOS 应用中运行真正的代理循环设置,包括 AI 引导的提供商配置、绑定到精确操作的模型审批、掩码凭证提示,以及无可用模型时的确定性回退。(#99935, #100029, #100656, #101887)感谢 @fuller-stack-dev。
- **离线与语音移动聊天:** iOS 和 Android 现在可在离线时预绘制每个网关的会话和对话缓存;Apple Watch 获得完整语音交互,iOS 可通过配置的 Gateway TTS 朗读回复,并支持设备端回退。(#100219, #100227, #100283, #100770, #100771)
- **会话组织与自动标题:** 通过工具模型路由生成简洁的会话标题,新增基于网关的分组、未读状态、重命名、分支、归档和删除控制,并在 Web、iOS 和 Android 上提供分组管理。(#87643, #100814, #101117, #101234)感谢 @zhangguiping-xydt 和 @Juliangsm。
- **Telegram 与 Codex 连续性:** 通过私密 `/login` 配对 Codex,使用 `/steer` 和 `/tell` 控制运行中的任务,在对话确认缺失时保留消息,安全采用持久轮次,并在 Telegram 格式化和洪流等待失败后恢复最终发送。(#98006, #98126, #98786, #103664, #103916)感谢 @100yenadmin、@Kyzcreig、@obviyus 和 @jalehman。
- **启动与升级恢复:** 在 Gateway 就绪前运行容器迁移,阻止可恢复的遗留状态阻塞启动,并在多次非正常启动后进入控制平面安全模式,而非反复重启。(#101881, #104529)修复 #98565。感谢 @sallyom、@jacobtomlinson、@bdjben、@obviyus 和 @shakkernerd。
### 变更
- **Meta 提供商:** 新增捆绑的 `muse-spark-1.1` Responses API 支持,包含流式传输、工具调用、加密推理回放、引导流程、精确模型实时验证,以及作为 `@openclaw/meta-provider` 的独立 npm/ClawHub 发行版。(#102873, #103070, #103163)感谢 @HamidShojanazeri、@davemorin、@Solvely-Colin、@jalehman 和 @vincentkoc。
- **Android 聊天代理选择器:** 在实时聊天屏幕上直接切换活动代理,同时保持聊天、对话模式和主页画布在同一规范会话中。(#80422)感谢 @bcperry 和 @joshavant。
- **Gateway 主机状态:** 在控制界面设置中显示已连接 Gateway 的主机、网络地址、操作系统、运行时间、CPU、内存和磁盘详情。(#100478)
- **Gateway 崩溃循环恢复:** 持久化启动结果,在多次非正常启动后进入控制平面安全模式,暂缓传输和提供商激活直至恢复,并对致命配置错误退出 `EX_CONFIG`,使 systemd 和 launchd 停止反复重启。感谢 @obviyus。
- **iOS 离线聊天:** 从受保护的、按网关限定的缓存中预绘制最近的会话和规范对话,离线时保持发送禁用,并在配对重置时清除缓存的对话文本。(#100219)
- **Slack 进度指示器:** 默认使用 Slack 原生的助手线程状态和轮转加载消息,同时保持确认反应静态;生命周期反应更新现在需要 `messages.statusReactions.enabled: true`。
- **控制界面对话控制:** 将语音、模型、灵敏度及其他实时默认设置保留在 设置 → 通讯 → 对话 中,并使用编辑器麦克风图标选择任何浏览器音频输入。(#101046)
- **Cron 模型选择:** 在控制界面快速创建中选择代理轮次模型,并在 cron 任务行和详情中显示已配置或默认模型。(#95341)感谢 @ly85206559。
- **控制界面 GitHub 预览:** 在悬停和键盘聚焦卡片中显示 issue 和 PR 的状态、标题、作者、活动、评论及变更统计。(#100434)
- **日志手册工作日志:** 新增默认禁用的捆绑插件,将配对节点的屏幕截图转换为私密时间线、每日站会和基于时间线的问答,显示在插件贡献的控制界面标签页中。(#99930)
- **控制界面消息上下文:** 通过悬停或点击时间戳显示每条消息的 token、上下文和模型详情,而非显示单独的“上下文”按钮。
- **控制界面会话标题:** 显示截断的近期会话名称,并带有减少动效安全的悬停动画。
- **控制界面侧边栏导航:** 显示一个小型可定制的固定目标集合,其余页面置于“更多”下,将设置移至页脚,并在浏览器中持久化侧边栏自定义。(#100296)感谢 @vincentkoc。
- **控制界面侧边栏用量:** 从展开的侧边栏中移除提供商用量配额行,同时保留聊天编辑器和用量页面中的用量详情。感谢 @shakkernerd。
- **Android 聊天代码高亮:** 渲染 fenced 的 Kotlin、Swift、TypeScript、JavaScript、Python、Bash 和 JSON 代码块,使用有限制的、主题感知的语法颜色,同时对未知、部分或过大的代码块保持纯文本渲染。(#100217)
- **Gateway TTS 播放:** 新增操作符作用域的 `tts.speak` RPC,返回配置提供商的语音作为内联整段音频,供远程客户端使用。(#100770)
- **控制界面上下文用量:** 当聊天上下文环打开时,显示上下文窗口进度、最近运行的输入/输出 token 以及当前活动模型。
- **Apple Watch 语音轮次:** 从 Watch 聊天界面口述消息,并在 Watch 上听到新的 OpenClaw 回复语音,配有明确的静音和停止说话控制。(#100224)感谢 @vincentkoc。
- **对话式引导流程:** 在 CLI、Gateway、Web 安装和 macOS 应用中新增真正的代理循环 Crestodian 设置流程,具备类型化操作、精确审批绑定、掩码凭证提示、隔离的会话对话以及安全交接给常规代理。感谢 @vincentkoc。
- **生成的会话标题:** 根据第一条消息为新的控制界面会话命名,并添加默认/每代理的 `utilityModel` 路由,用于更低成本的会话、主题和线程标题生成。感谢 @Juliangsm、@zhangguiping-xydt 和 @vincentkoc。
- **ClawRouter 路由与配额:** 新增捆绑的 ClawRouter 提供商插件,具备凭据作用域的动态模型发现、OpenAI 兼容及原生 Anthropic/Gemini 传输,以及跨 OpenClaw 用量表面的管理预算报告。(#99658)
- **模型与提供商覆盖:** 新增 GPT-5.6 支持,使用 Nemotron Super 的 100 万上下文窗口,并保留显式的 OpenRouter 认证头。(#98333, #98726, #98187)感谢 @steipete-oai、@eleqtrizit、@sunlit-deng、@laurencebrown 和 @shakkernerd。
- **CLI 与节点工作流:** 新增 `openclaw attach`、节点上下文路径支持、可操作的设备审批恢复指南、提示元数据变化时的软恢复 CLI 会话,以及更清晰的插件安装退出诊断。(#96454, #97679, #98115, #98146, #98497, #99822)感谢 @anagnorisis2peripeteia、@obviyus、@wm0018、@welfo-beo、@RomneyDa、@Sanjays2402 和 @vincentkoc。
- **Cron 与用量:** 新增退出触发的调度、分离的会话目标运行,以及飞行中任务医生警告,同时使现有用量页脚在 Telegram 上更易换行。(#92037, #98755, #98620, #92877)感谢 @anagnorisis2peripeteia、@obviyus、@EthanSK、@masatohoshino、@Marvinthebored 和 @vincentkoc。
- **原生应用与本地化:** 现代化 iOS 展示、聊天、对话、引导和重连流程;新增 Gateway 语音提供商;改进二维码引导和协议恢复;从 macOS 安装本地 Gateway;本地化核心 Apple 和 Android 界面;新增瑞典语移动本地化。(#98452, #98736, #99243, #98376, #98302, #98385, #99767, #97110, #97111, #97112, #97113, #98043)感谢 @jcooley8、@Tony-ooo、@joelnishanth、@cursoragent、@joshavant、@vincentkoc 和 @yeager。
- **消息功能:** 新增原生 iMessage 投票、Telegram Codex 配对与引导、Telegram 多通道进度摘要,以及 Signal 目标别名。(#98421, #98006, #98126, #98907, #95738)感谢 @omarshahine、@lobster、@100yenadmin、@Kyzcreig、@Marvinthebored 和 @jesse-merhi。
- **本地推理与聊天控制:** 自动发现 Ollama 推理节点,新增控制界面会话优先导航、推理控制和命令选择,并确保当延迟工具搜索选择了错误工具族时,OpenClaw 控制工具仍可用。(#99234, #99289, #99426, #99838, #99561)感谢 @100yenadmin、@joshavant、@VicZhang6、@Solvely-Colin 和 @vincentkoc。
- **诊断与检查:** 暴露认证配置文件、工作区、设备配对、通道插件、内存提供商、systemd 资源耗尽以及 Windows LAN 防火墙的检查结果。(#97125, #97358, #97366, #97496, #97968, #98291, #98666)感谢 @giodl73-repo、@masatohoshino 和 @joshavant。
- **策略修复预览:** 在 `doctor --fix` 期间显示需要审查的 Gateway 绑定和被拒绝的节点命令变更,但不应用它们,也不将其计为已修复。(#99776)感谢 @giodl73-repo。
- **对话与审查控制:** 准备作用域化的对话能力配置文件,并新增 Cursor Agent 作为自动审查引擎。(#98536, #97348)感谢 @hxy91819。
### 修复
- **Codex 运行时切换:** 接受捆绑的 Codex 运行时用于 `codex/*` 和 `openai/*` 模型路由,同时拒绝不支持的提供商/运行时对。(#103762)
- **LM Studio 与 xAI 修复工具调用:** 在提升序列化纯文本工具调用时,在完成前发出终端工具调用事件,为消费者保留完整的流式生命周期。
- **Node 24 上的浏览器操作:** 将浏览器请求取消绑定到客户端和响应生命周期,而非 Node 24.16+ 中过早中止的 body-stream 信号,防止有效的 POST 操作在 JSON 解析后失败。感谢 @obviyus 和 @vincentkoc。
- **SecretRef 模型凭据:** 将通过认证存储、流设置、SDK 配置以及托管本地提供商探测保留的提供商密钥置于进程本地哨兵之后,仅在最终的网络或提供商插件边界注入明文,同时保留精确值的日志隐藏。(#102008, #102009)
- **Telegram token 隐藏:** 即使日志传输将 token 分割成多个块,也隐藏机器人 token,防止碎片化凭据从结构化和流式日志中泄露。(#103861)感谢 @vincentkoc。
- **Telegram 持久轮次采用:** 仅在持久代理采用后完成堆积的更新,将已采用的轮次从入口回复 fence 中分离,并抑制被取代的回复,以便恢复不会泄露过期或重复的响应。(#103664, #103952, #103965)感谢 @obviyus 和 @vincentkoc。
- **任务投递恢复:** 在恢复任务记录时规范化遗留的投递状态,使旧的排队任务变为可运行,而非中止注册表恢复。(#103946)修复 #103168。感谢 @bek91、@theo674 和 @obviyus。
- **诊断提供商证据:** 为每次完成或失败的模型调用发出一个去重的 `provider.request` 时间线事件,以便选择加入的时间线能够证明真实的提供商流量,而不会重复计算终端路径。修复 #103063。感谢 @vincentkoc。
- **精益本地模型 shell 访问:** 将 `exec` 直接可见地置于默认的结构化工具搜索控件旁,使面向编码的本地模型能够使用其 shell 回退,而非搜索缺失的领域工具。(#101607)感谢 @vincentkoc 和 @maweibin。
- **OAuth 刷新竞争诊断:** 将本地锁定路径排除在面向用户的刷新失败之外,并避免重复失败前缀,同时保留结构化的提供商和配置文件分类。(#101573)感谢 @vincentkoc。
- **执行审批提示:** 将后台禁用的回退警告排除在待处理的网关/节点审批之外,仅在命令实际在前台运行时才显示它们。(#101561)感谢 @vincentkoc。
- **直接轮询投递:** 通过所属的出站适配器路由直接和混合通道轮询,同时保留网关模式路由和通道选项检查。(#99950)感谢 @NianJiuZst 和 @shakkernerd。
- **代理等待硬超时快照:** 当外部 `agent.wait` 计时器在重试宽限竞赛中获胜时,保留规范的硬超时阶段和时间戳,同时使队列、排空和重启取消等待可纠正。(#89367)感谢 @Pick-cat 和 @sunnydongbo。
- **控制界面类型化审批:** 在代理运行被阻塞时,立即通过授权的 Gateway 命令路径发送 `/approve` 命令,而非将其排队在该运行之后。(#101532)感谢 @vincentkoc。
- **Microsoft Teams Graph 响应边界:** 限制成功的文件上传和聊天 JSON 读取,防止过大的 Microsoft Graph 响应无限制缓冲。(#97784)感谢 @Alix-007。
- **打包的语音运行时:** 停止将包支持的 `speech-core` 视为捆绑插件 sidecar,在 npm 安装中恢复 TTS 启动,同时发布检查确保真正的激活旁路外观保持包完整。(#89899, #89425)感谢 @zhangguiping-xydt、@ant1b0t 和 @vincentkoc。
- **容器镜像升级:** 在重用挂载状态时,在 Gateway 就绪前运行版本化状态迁移和插件收敛,失败时提供 `doctor --fix` 恢复指导,而非提供半升级状态。(#101881)修复 #98565。感谢 @sallyom、@jacobtomlinson 和 @shakkernerd。
- **插件更新可靠性:** 在核心更新期间,保留已通过 ClawHub 成功切换的插件,而非对它们进行第二次处理,并在冗余的瞬态失败后禁用它们。(#105405)感谢 @vincentkoc。
- **Codex 应用服务器协议:** 要求 app-server 0.143 或更高版本,移除前 0.142 的线格式兼容性,将已退役的 `on-failure` 审批设置迁移到 Codex 配置和已保存绑定中的 `on-request`,教会 Codex 通过 `tool_search` 检索延迟的原生 `spawn_agent`,以便原生子代理任务镜像能够在支持搜索的模型上工作,并将托管运行时更新到 0.144.1 以提高代码模式主机安装和缺失主机回退的可靠性。感谢 @vincentkoc。
- **Android 硬件键盘聊天:** 在物理键盘上使用未修改的 Enter 发送,同时保留 Shift+Enter 及其他修改的 Enter 组合用于多行输入。(#101239)感谢 @3ninyt3nin-creator 和 @vincentkoc。
- **CJK Markdown 强调:** 渲染相邻的中文、日文和韩文强调标点符号时,通过共享的 Markdown 管道处理,而非跨通道泄露字面标记。(#101230, #101120)感谢 @nicknmorty 和 @j08577600-jpg。
- **备份重试清理:** 在实时写入失败后关闭部分归档输出句柄并隔离每个重试路径,防止 Windows `EBUSY` 锁跨尝试级联或留下过期的临时归档。(#101449, #101464)感谢 @ZOOWH、@LiLan0125、@vincentkoc、@aniruddhaadak80、@shakkernerd 和 @obviyus。
- **Codex 生成的原生子代理:** 保持父应用服务器订阅和共享客户端存活,直到生成的子代理完成投递稳定,防止丢失唤醒和泄露的一次性清理。感谢 @vincentkoc。
- **投递恢复节奏:** 在网关启动后,对符合条件的出站和重启延续重放进行节奏控制,以便停机积压不会爆发到通道速率限制,同时保留挂钟恢复预算。(#101118, #101058)感谢 @ZengWen-DT、@aniruddhaadak80 和 @vincentkoc。
- **出站预连接恢复:** 当连接或 DNS 失败证明未发送请求时,原子性地清除过期的平台发送证据,允许排队的 Discord 及其他通道消息在连接恢复后重放,同时不削弱未知发送的重复保护。(#101024, #100979)感谢 @SunnyShu0925 和 @tiffanychum。
- **Discord 流式最终消息:** 将完成回复作为新消息发送,使非活跃通道变为未读,同时保留定向提及而不升级 `@everyone` 或 `@here`。(#99711, #99662)感谢 @davelutztx 和 @xena68。
- **OpenAI 兼容的 SSE 解析:** 识别被误标为 JSON 的事件流,而不在其前面添加第二个 `data:` 前缀,保留来自不合规提供商的有效流式响应。(#96503)感谢 @ZengWen-DT 和 @54meteor。
- **Meta 模型 API 合约:** 使用当前 Meta 端点和输出 token 字段,使 `muse-spark-1.1` 验证和实时请求与提供商合约匹配。(#103680)修复 #103667。感谢 @vincentkoc、@HamidShojanazeri、@davemorin、@Solvely-Colin 和 @jalehman。
- **LM Studio 嵌入预加载:** 在预加载嵌入模型时,遵循模型和提供商的上下文窗口限制,防止可避免的 GPU 内存不足失败。(#100750)感谢 @zak-li、@ZOOWH 和 @hxz398。
- **提供商过载消息:** 当提供商未提供明确的重试详情时,将限速响应分类为可重试和回退行为,同时使用过载措辞。(#98165)感谢 @SunnyShu0925。
- **Microsoft Teams 附件元数据:** 限制 Bot Framework `attachmentInfo` JSON 读取,并在过大的流耗尽 Gateway 内存之前取消它们。(#99125)感谢 @ly85206559。
- **代理认证复制顺序:** 在将凭据复制到新代理时,保留源代理的可移植认证配置文件优先级,同时排除跳过的配置文件和瞬态认证状态。(#100833)感谢 @machine3at。
- **内存会话修复:** 将日常梦境摄取簿记排除在会话语料审计和修复之外,以便 `memory status --fix` 保留健康的日常状态。(#93389)感谢 @Alix-007 和 @vincentkoc。
- **远程浏览器 CDP 策略:** 允许配置的 CDP 控制主机通过现有的主机名白名单,而不扩大页面导航策略,同时将严格策略发现绑定到配置的控制权限。(#100986, #100819)感谢 @NianJiuZst、@SarinV 和 @vincentkoc。
- **配置未设置诊断:** 当继承或默认的配置值无法取消设置时,解释原因,而非报告误导性的成功删除。(#96557)感谢 @moeghashim。
- **Crestodian 命令探测:** 包含 stdout 和 stderr 流失败,同时保持子进程关闭和生成错误的权威性,防止未处理的探测崩溃。(#100741)感谢 @lsr911。
- **飞书提及转发:** 当机器人 Open ID 不可用时,失败关闭,防止群消息被错误分类为显式的机器人提及。(#100891)感谢 @zhangguiping-xydt。
- **Cron 编辑投递:** 在应用部分投递更新时,保留每个作业的隐式投递模式,以便禁用尽力投递不再关闭分离的作业公告。(#100846)感谢 @machine3at 和 @vincentkoc。
- **控制界面会话创建:** 在选择另一个会话后,保持新创建的会话位于稳定侧边栏顺序的前端。感谢 @shakkernerd。
- **控制界面文件预览:** 通过缓存、屏幕外包含的文本块保持大型 Skill Workshop 文件响应,同时保留换行内容、稳定的文件切换、全文件复制和清晰的焦点行为。(#101319)感谢 @xianshishan、@shakkernerd 和 @vincentkoc。
- **仅 FTS 内存启动:** 当 `memorySearch.provider` 显式为 `none` 时,跳过插件能力发现,避免不必要的冷启动扫描。
- **控制界面代理模型标签:** 在默认选择器选项中显示每个选定代理的有效模型,而非全局模型。(#100719, #77440)感谢 @hyspacex 和 @jwong-art。
- **控制界面入站图片预览:** 在聊天历史重新加载后,通过认证票据路由渲染规范的入站媒体引用。(#100725, #89591)感谢 @sweetcornna、@vergissberlin 和 @shakkernerd。
- **小上下文压缩:** 根据已知模型上下文窗口限制有效保留,使小型本地模型不会从第一个 token 就开始压缩。(#100621)感谢 @vincentkoc。
- **无详细信息提供商失败:** 防止不透明的上游失败冷却 API 密钥认证配置文件,同时保留 WHAM 支持的 OpenAI OAuth 健康检查和配置的模型回退。(#100617)感谢 @fabasi、@fengjikui 和 @vincentkoc。
- **插件安装诊断:** 仅在钩子清单缺失时,抑制插件安装失败后的误导性钩子包回退,同时保留可操作的格式错误钩子包错误。(#100554)感谢 @vincentkoc 和 @obviyus。
- **配置验证诊断:** 每个配置路径仅发出一次未更改的清理验证警告负载,在干净验证后重置去重,并在瞬态无效读取和失败刷新期间保留警告指纹。(#100569, #25574)感谢 @vincentkoc 和 @mcaxtr。
- **配置大小下降保护:** 将写入与规范字节进行比较,用于可解析的对象配置,而非原始 BOM 和缩进开销,同时保留原始审计遥测和保守的格式错误输入回退。(#100591, #71865)感谢 @vincentkoc 和 @balric-seo。
- **控制界面合并更新:** 当更新加入已经运行的 Gateway 重启时,显示清晰的排队重启完成横幅。(#93082)感谢 @goutamadwant 和 @motacola。
- **控制界面连接错误:** 保留结构化的配对和认证失败信息,用于待处理的 RPC 调用方,同时保持通用断开行为不变。(#54758)感谢 @ruanrrn。
- **iOS 嵌入式终端:** 在原生 Gateway 认证连接时,直接打开仅终端的控制界面,而非暴露 Web UI 登录屏幕。
- **TUI 启动状态:** 在连接后初始化期间显示 `starting up`,而不覆盖运行中或重连状态。(#93999)感谢 @ml12580 和 @sanjarcode。
- **控制界面重启恢复:** 在 Gateway 更新或重启后,通过有限的全文档刷新恢复过期的捆绑页面。(#99111)感谢 @ZengWen-DT 和 @ITOrity。
- **TUI 活动网关端口:** 当未配置显式 URL、端口或远程目标时,遵循已验证的活动本地网关端口。(#73338, #42461)感谢 @haishmg、@vincentkoc 和 @jackm1688。
- **Apple 聊天运行恢复:** 在重连、前台恢复和事件间隙后,从规范的 Gateway 历史中恢复活动响应,同时保留网关用户轮次身份,防止 Codex 和 Copilot 对话镜像中出现重复行。(#100277)
- **Claude CLI 流式回复:** 当 Claude CLI 的终端结果信封为空时,保留已接收的助手文本,防止在完整的流式回答后出现错误的空响应故障转移。(#90450)感谢 @totobusnello。
- **电话号码标准化:** 规范化多余的正号,保留非电话的 iMessage 句柄,并在共享通道路由中拒绝无数字的 Signal 身份。(#100467)感谢 @morluto。
- **Tlon scry 响应边界:** 限制成功的 Urbit scry JSON 读取,并取消过大的流,而非缓冲无界的对等响应。(#100376)感谢 @hugenshen。
- **源码构建可移植性:** 保持 tsdown 配置自包含,使构建不依赖从 unrun 的临时模块目录解析 tsdown 包。感谢 @vincentkoc。
- **代理工具调用解码:** 将代理范围数值 HTML 实体保留为字面文本,同时仍解码有效的补充平面值,防止格式错误的模型输出向工具参数注入孤立的 UTF-16 代理对。(#99564)感谢 @mikasa0818、@vincentkoc、@shakkernerd 和 @maweibin。
- **Gateway 事件分发:** 捕获并记录惰性订阅者设置和处理程序失败,而非泄露未处理的 Promise 拒绝。(#100401)感谢 @cxbAsDev。
- **Ollama 回退路由:** 通过 Ollama 提供商钩子分类不完整的原生流,以便配置的模型回退可以推进。(#100482)感谢 @TurboTheTurtle、@8kfcf95jvp-oss 和 @vincentkoc。
- **差异渲染:** 从单个 SSR 预加载渲染查看器和图像输出,通过 hydration 保留语言包高亮,不区分大小写地规范化语言提示,跳过相同的前后输入并显式返回 `changed` 结果,报告真实的文件渲染和输入错误,缓存哈希固定的查看器运行时,并优先使用规范文件设置而非过期的别名。(#100487)感谢 @vincentkoc。
- **远程浏览器可靠性:** 通过现有远程 CDP 超时预算限制持久的 Playwright 标签枚举,并淘汰超时的连接尝试,使迟到的完成不能恢复卡住的连接。(#80147, #58968)感谢 @HemantSudarshan 和 @KeaneYan。
- **浏览器附件下载:** 当直接的 Playwright 导航启动附件下载时,返回托管的 URL、文件名和路径元数据,同时在保存字节前验证最终 URL,并保留单一所有者的显式下载。(#48045, #89416)感谢 @zhangguiping-xydt 和 @roinou532。
- **浏览器操作下载:** 当代理操作触发下载时,返回托管的 URL、文件名和路径元数据,同时保留显式所有权,在保存字节前验证最终 URL,并将策略拒绝的标签页隔离而不关闭它们。(#93250, #93307)感谢 @sunlit-deng 和 @scorpiord。
- **托管浏览器 Cookie 持久化:** 使用非交互式加密密钥初始化新的隔离 macOS 无头配置文件,同时保留现有配置文件密钥,并通过 CDP 关闭 Chromium,然后进行有界信号回退,使持久登录在优雅的浏览器和 Gateway 重启后存活。(#96704, #98284)感谢 @TurboTheTurtle 和 @shakkernerd。
- **MCP OAuth 响应边界:** 拒绝无体的外部错误体,不调用其本质上无界的 `text()` 回退,同时保留 HTTP 状态和头部,用于安全的 SDK 诊断。(#98143)感谢 @Pick-cat、@wangmiao0668000666 和 @vincentkoc。
- **Tlon 图片上传边界:** 在上传前限制远程图片获取,并对过大或停滞的响应失败关闭,而非无限制地缓冲它们。(#100374)感谢 @hugenshen。
- **控制界面审批提示:** 防止过期的解决失败和忙状态清理泄露到更新的审批或 Gateway 重连中。(#98394)感谢 @haruaiclone-droid。
- **macOS 服务 SecretRefs:** 当过期的 Gateway LaunchAgent 被修复或重新安装,且调用 shell 中没有这些变量时,保留仍在配置中的 SecretRefs 的生成 env 文件值。(#99124)感谢 @mushuiyu886 和 @1Wanker。
- **Anthropic OAuth 回调:** 保持提供商要求的 `localhost` 重定向 URI 稳定,同时允许本地回调监听器绑定显式的环回主机。(#96917)感谢 @xialonglee、@riazrahaman 和 @vincentkoc。
- **提示释放媒体投递:** 当嵌入式运行暂时释放其会话锁时,接受保留活动叶子状态的侧追加,使连续的消息工具媒体回复合并,而不会出现错误的会话接管失败。(#100490)感谢 @scotthuang 和 @vincentkoc。
- **控制界面技能过滤器:** 对齐代理和搜索控件,使用翻译后的标签,并保留原生复选框和单选按钮大小。(#100526)感谢 @evan-YM 和 @vincentkoc。
- **控制界面已完成运行状态:** 将活动和完成更新绑定到运行身份,使过期的完成保留“发送”可用,同时较新的运行保持活动。(#100527)感谢 @tiffanychum、@davidstoll 和 @shakkernerd。
- **控制界面上下文用量:** 将过期的缓存总计保留为近似值,不触发警告样式或压缩操作。(#89772)感谢 @bladin 和 @snsczssl。
- **控制界面文件预览:** 移除重复的 Escape 头部提示,同时保留关闭按钮快捷键提示和 Escape 行为。(#100528)感谢 @xianshishan 和 @vincentkoc。
- **控制界面自主工具失败:** 在后续的自主恢复轮次中,保留较早的工具错误结果。(#100514)感谢 @qingminglong 和 @yetval。
- **代理空回复:** 当完成的交互轮次没有可投递的回复(包括排队的后续消息)时,显示可见的失败,同时保留显式静默、待处理的延续和已提交的副作用,尊重排队发送策略,并将压缩通知视为进展。(#100456)感谢 @mushuiyu886 和 @grox2012。
- **子进程、维护与输出加固:** 防止子输出失败崩溃 exec 和 TUI 会话,隔离远程技能刷新和子代理扫描,暴露技能扫描和审批诊断,清理 ANSI 和杂散参数标记而不丢失可见文本,并在设备丢失时干净地停止 Android 音频捕获。(#100440)感谢 @cxbAsDev、@wendy-chsy、@tzy-17、@nankingjing、@NianJiuZst、@LavyaTandel 和 @maweibin。
- **Docker 沙箱命令输出:** 当 stdout/stderr 捕获中断时,失败并终止 Docker 沙箱操作,而非返回成功但不完整输出。(#100523)感谢 @cxbAsDev 和 @vincentkoc。
- **Android 按键通话生命周期:** 将网关 PTT 准备与应用前台和手动麦克风所有权序列化,使延迟工作不能重启、替换或拆除较新的捕获。(#100552)感谢 @xialonglee。
- **精益本地模型工具:** 从精益代理界面中修剪媒体生成、TTS 和 PDF 工具,同时保留显式配置和运行时选择加入。(#88881)感谢 @vincentkoc。
- **iOS 开发应用身份:** 保持开发应用标记为 OpenClaw,同时使用其不同的调试图标以区别于发布版本。
- **Android 聊天恢复:** 在重连和序列间隙历史快照追赶时,保留乐观的用户消息和本地拥有的运行,防止已发送的消息消失或过期的运行夺取所有权。(#100197)
- **iOS QR 网关交接:** 在交付扫描的设置码之前停止 VisionKit,并将延迟的认证、审批、Watch 和前台节点工作绑定到其原始网关,跨重连保持。(#99572)感谢 @PollyBot13。
- **代理终端失败:** 当代理运行结束但无可见输出时,显示安全交互回复,同时保留已完成的消息工具投递和心跳特定指导。(#99304)感谢 @moeedahmed 和 @maweibin。
- **MCP 回环工具结果:** 通过 HTTP 工具调用保留模式有效的文本、图像和嵌入式资源内容,同时将格式错误或协议不兼容的块渲染为安全文本。(#100336)感谢 @tzy-17、@OpenClawKobian99、@vincentkoc、@shakkernerd 和 @maweibin。
- **控制界面工具结果图片:** 直接从 Gateway 历史渲染图像内容块,并使延迟发送滚动 E2E 设置确定。(#100295)感谢 @lzyyzznl、@Pandah97、@rquinones84 和 @maweibin。
- **控制界面实时工具排序:** 当浏览器和 Gateway 时间戳不一致时,保持助手流文本在其匹配的工具卡片之前。(#93184)感谢 @Pick-cat 和 @lileilei-camera。
- **IRC Unicode 消息:** 在 UTF-16 码点边界上分割出站 PRIVMSG 负载,使 emoji 不会被切割成孤立的代理对。(#96572)感谢 @WeeLi-009、@vincentkoc、@mushuiyu886 和 @cursoragent。
- **OpenAI 实时语音问候:** 防止服务器 VAD 在显式问候响应拥有该轮次时创建第二个出站问候,同时不禁用呼叫者中断。(#86285)感谢 @giodl73-repo 和 @jnikolaidis。
- **实时语音工具:** 在每个 OpenAI、Azure 和 Google 实时负载边界过滤格式错误的工具名称,同时保留提供商特定的有效名称。(#89175)感谢 @vincentkoc。
- **Discord 语音状态:** 将 Discord 错误 10065 视为正常断开状态,同时保留无关的 REST 失败。(#90969)感谢 @asock。
- **Discord 语音账号:** 按 Discord 账号隔离 `@discordjs/voice` 连接,并在网关就绪早于监听器注册时恢复自动加入。(#87530)感谢 @geekhuashan。
- **iOS Voice Wake 清理:** 在禁用非活动 Voice Wake 时,避免初始化麦克风音频管道,防止模拟器启动中止和不必要的音频设置。
- **可靠性边界情况:** 拒绝亚毫秒 cron 持续时间,保留生成提案中的换行符,规范化空白整数输入,及时失败嵌入式 LSP 启动,暴露持久化和内存关闭失败,保持 UTF-16 和插件包验证正确,传播 Android 取消,并延迟 Codex 中继注册表写入直到监听就绪。(#100399)感谢 @cxbAsDev、@snotty、@lin-hongkuan、@849261680、@qingminglong、@anyech、@masatohoshino、@Simon-XYDT、@xialonglee、@nankingjing、@609NFT 和 @vincentkoc。
- **语音通话完成状态:** 从完整保留的事件存储中解析最终确定的通话,跨越 Gateway、工具和 CLI 状态路径,同时保留活动通话查找性能。(#99797)感谢 @Darren2030、@NiTeCoMM-code 和 @maweibin。
- **代理停止恢复:** 防止延迟中止的提示在拆除后重新获取孤立的会话锁,使 `/stop` 将对话准备好用于下一轮次。
- **消息投递状态:** 报告失败和部分失败的尽力通道投递,而非返回成功形状的消息工具结果。(#99928)感谢 @masatohoshino。
- **WhatsApp 凭据恢复:** 在启动时从有效备份中恢复格式错误的主认证状态。(#99070)感谢 @LeonidasLux。
- **WhatsApp 引用回复:** 保留机器人撰写的出站引用元数据,使对这些消息的回复在 WhatsApp Desktop 中保持其回复气泡。(#94879)感谢 @Bartok9、@seikosantana 和 @vincentkoc。
- **WhatsApp 重连追赶:** 在有界的重连窗口内,承认最近错过的 Baileys `append` 消息,同时保留启动时的过期历史保护。(#80642)感谢 @VishalJ99。
- **WhatsApp 重启恢复:** 在登出或连接被替换的断开后,停止自动重启循环,直到账号重新连接。(#78511)感谢 @openperf 和 @rutherlesdev。
- **本地 Gateway CLI 认证:** 将回环 CLI token/密码调用排除在持久设备作用域之外,防止读探测在过时的配对基线后阻塞后续的写/管理命令。(#95997)感谢 @vincentkoc。
- **插件模块身份:** 当 jiti 转换插件条目时,保持 OpenClaw 包块在 Node 的原生模块图上,防止重复评估和类身份漂移。(#88384)感谢 @vincentkoc 和 @ScientificProgrammer。
- **Shell 补全修复:** 在 doctor 和更新修复期间生成仅核心的缓存,同时为引导流程和显式用户重建保留完整的插件命令补全。(#76235)感谢 @joshavant。
- **MCP 模式诊断:** 将 draft-2020-12 编译失败归因于外部 MCP 模式,使格式错误的模式产生可操作的设置错误。感谢 @vincentkoc。
- **Windows Scheduled Task 恢复:** 将干净的提前退出保留在现有的有界启动轮询内,仅当任务进程和 Gateway 监听器都不可见时回退。
- **iMessage 群组警告:** 当有效的群组发送者白名单可以允许群组时,抑制错误的“全部丢弃”启动警告,并将真正的空白名单配置指向正确的补救措施。(#100046)
- **控制界面移动端登录:** 在连接失败后保持 Gateway 恢复指导可见,使断开的网关在受限屏幕上安全滚动,并改善移动键盘和点击目标行为。(#100208)
- **TUI 流式传输:** 在实时 Gateway 和嵌入式 TUI 会话中渲染仅增量的助手事件,而非等待最终响应。(#83000)感谢 @flashosophy。
- **模型别名:** 在会话和聊天命令模型切换时,解析提供商限定的别名,防止提供商共享显示别名时发生冲突。(#100209)感谢 @sahilsatralkar、@david-r-jones、@shakkernerd 和 @vincentkoc。
- **TUI 新会话钩子:** 通过共享的 Gateway 生命周期创建 `/new` 会话,使命令和会话钩子在 Gateway 和嵌入式模式下都能接收到完整的父会话对话,同时防止在活动轮次期间滚动。(#100241, #49918)感谢 @BingqingLyu、@caopulan、@LonExplorer-coder 和 @vincentkoc。
- **TUI 中止诊断:** 在 Gateway 和本地 TUI 模式下,为中止的运行显示清理后的工具参数验证摘要,而不暴露原始模型参数。(#91002)感谢 @wsyjh8 和 @taerlandsen。
- **iOS Watch 回复:** 将排队的快速回复持久化到网关作用域的聊天发件箱中,并通过幂等聊天投递提交,防止在重连后丢失、重复和跨网关发送。(#100372)感谢 @NianJiuZst。
- **iOS Gateway 认证重试:** 将存储的设备 token 重试限制为已解析的环回主机,并拒绝通配符绑定地址,防止远程仿冒主机名接收受信任的重试凭据。(#99859)感谢 @ly85206559 和 @vincentkoc。
- **Bedrock Mantle 发现:** 限制模型目录获取时间和响应大小,并释放被拒绝的响应体,使停滞、过大或失败的提供商响应安全回退。(#99961)感谢 @zhangguiping-xydt 和 @shakkernerd。
- **Discord 线程标题提示:** 在 UTF-16 边界上截断生成的标题消息和通道上下文,防止 emoji 留下格式错误的模型提示文本。(#101551)感谢 @Alix-007、@vincentkoc、@mushuiyu886 和 @cursoragent。
- **移动端配对路由:** 在 `gateway.bind=lan` 设置 URL 旁宣告已验证的持久 Tailscale Serve 回退,在控制界面和 CLI 中显示每条路由,并让 iOS 保存第一个可到达的端点。(#100280)感谢 @shakkernerd。
- **控制界面终端标签页:** 将新会话按钮垂直居中于终端标签条中。
- **控制界面编辑器滚动条:** 仅当草稿实际溢出其自动高度时,显示消息字段滚动条。
- **控制界面终端光标:** 隐藏浏览器原生的 contenteditable 插入符,使集成终端仅显示其画布渲染的光标。
- **macOS SSH 隧道:** 通过应用管理的 PATH 解析用户安装的 SSH `ProxyCommand` 辅助程序,同时保留继承的连接环境,使远程别名在 Finder 和清理脚本启动后正常工作。
- **控制界面 OpenAI 速度选择器:** 仅为 OpenAI 模型显示“标准”和“快速”选项。
- **控制界面终端渲染:** 采用共享的 `@openclaw/libterminal` 浏览器生命周期,并添加 Nerd Font 回退,使启用图标的 shell 列表在安装兼容本地字体时渲染其字形。
- **Slack 对话历史:** 让 Codex 应用服务器拥有其持久化的助手回复,使 Slack 不附加冗余的投递镜像行,同时控制界面保持隐藏旧的重复镜像。感谢 @bek91。
- **控制界面聊天历史:** 当前面的应用服务器助手回复已显示相同文本时,隐藏冗余的通道最终投递镜像。
- **控制界面聊天间距:** 使用响应式最小对话内边距,使第一条消息与顶部栏保持舒适距离。
- **ClawRouter 认证配置文件:** 当代理密钥存储在认证配置文件中时,在代理运行期间解析凭据作用域的目录模型,并记录插件和模型白名单。
- **Telegram 持久性:** 重试重启丢弃的媒体,存活瞬态轮询错误,死信毒化更新,保留转发的富文本,正确路由插件回调,在一个稳定的多行窗口中保持进度更新,通过受信任的主机根映射自托管 Bot API 容器路径,并在 Telegram 拒绝富文本最终回复时安全回退。(#98102, #98735, #98775, #98776, #97174, #98907, #91984, #98786)感谢 @luoyanglang、@DaveArcher18、@obviyus、@goldmar、@Marvinthebored、@Dizesales、@shakkernerd、@AiLucasdz 和 @RomneyDa。
- **跨通道入站媒体:** 当 WhatsApp、LINE、Signal、iMessage、Microsoft Teams、飞书、Mattermost 或 Zalo 无法物化入站媒体时,保留标题并暴露不可用附件的通知,而非分发幻影占位符或丢弃仅媒体轮次。(#100092)
- **代理与上下文可靠性:** 保留运行时覆盖、引导的子代理任务、回退工具调用提示和遗留重播种附件;在仅提示漂移时软恢复 CLI 会话;改进 harness 感知的上下文估算;超时静默本地流;恢复流中失败;并限制 Gateway 运行缓存增长。(#92237, #77539, #99851, #99839, #99822, #97928, #98525, #95430, #77973)感谢 @sercada、@amittell、@obviyus、@liuhao1024、@yetval、@osolmaz、@lzyyzznl、@vincentkoc、@alexelgier 和 @fede-kamel。
- **提供商与网络安全:** 在 Moonshot、MiniMax、Anthropic OAuth、Discord、Matrix、SMS、浏览器、更新、嵌入、Tlön 和 Inworld 路径中限制过大或格式错误的响应。(#96502, #96322, #96644, #97693, #97662, #97999, #98455, #98508, #98554, #98496, #98660)感谢 @hugenshen、@cursoragent、@lsr911、@solodmd、@Alix-007、@wings1029、@lzyyzznl、@sunlit-deng、@vincentkoc 和 @Pandah97。
- **通道投递与路由:** 将 Slack 回复保留在活动线程会话中,保留账号绑定的投递路由,应用回复前缀,并抑制内部跟踪和不希望的回退回复。(#97168, #98240, #93639, #97989, #80928)感谢 @LiuwqGit、@gorkem2020、@yetval、@ZengWen-DT、@alexuser、@UnClouded77 和 @vincentkoc。
- **Cron 正确性:** 在超时时保留提供商和模型选择,在维护读取间保留启动追赶延迟,保留需要操作的输出,清除空白的思考覆盖,并保留提供商拥有的每日重置会话。(#95943, #94022, #96393, #96293, #98356)感谢 @ZengWen-DT、@cursoragent、@luke-renjoy、@RichChen01、@vincentkoc、@yetval、@snowzlmbot、@nz365guy、@takamasa-aiso 和 @shakkernerd。
- **内存与会话恢复:** 检测未索引的对话,在瞬态读取间保留笔记,避免跨目录恢复,消除保留的 wiki 索引页歧义,并跳过空的 QMD 同步工作。(#97857, #98360, #97785, #94326, #90030)感谢 @zw-xysk、@CHE10X、@qingminglong、@yetval、@vincentkoc、@sahibzada-allahyar 和 @ruben2000de。
- **Windows 与执行:** 将白名单执行绑定到验证的 Windows 路径,传播 `PATHEXT`,不区分大小写地规范化入站路径,并防止 Windows 上的清理崩溃。(#98260, #98093, #97630, #97901)感谢 @eleqtrizit、@wendy-chsy、@VectorPeak、@paulcam206 和 @shakkernerd。
- **移动端与 UI 稳定性:** 保留 iOS 聊天换行和最终回复,改进 Android 配对和 TLS 恢复,隐藏过期的配对卡片,保持工作区文件导轨可滚动,恢复纯 HTTP 上的复制路径,并停止 Mac 应用控制界面中的弹性滚动。(#98304, #98117, #98366, #98439, #98483, #98049, #98646, #98611, #98764, #99830)感谢 @joshavant、@Jabato01、@ooiuuii、@wuqxuan、@645648406-max、@zw-xysk、@ZengWen-DT 和 @adinballew。
- **Codex 与审批流程:** 正确报告 ChatGPT 认证,将破坏性审批模式重命名为 `ask`,准确分类 `get_goal` 读取状态,并从显式运行截止时间推导终端空闲超时。(#91240, #98501, #98659, #85296)感谢 @849261680、@ukstem、@kevinslin、@yetval、@alkor200、@vincentkoc 和 @alkor2000。
- **配置与插件健康:** 将配置遍历限制为自有属性,保留配置健康恢复状态,暴露不可加载的通道插件,在补丁期间保留默认的提供商基础 URL,通过清单合约验证捆绑插件更新,从已安装的插件根解析公共工件,并在需要时保留遗留的 ClawHub 家族。(#99846, #99728, #96397, #98396, #98010, #98819, #98249)感谢 @vincentkoc、@zenglingbiao、@joshavant、@jalehman、@ccbridle、@849261680、@momothemage、@weltmaister、@LiLan0125、@herove、@amknight、@KelTech-Services 和 @Patrick-Erichsen。
- **运行时进程安全:** 防止 SSH 隧道、监督器和 MCP stdio 传输中未处理的子流错误;使自动回复不等待对话镜像;并避免在审批预览和 LINE 出站字段中拆分 Unicode 字符。(#99800, #99802, #99803, #99549, #99566, #98994)感谢 @cxbAsDev、@vincentkoc、@Shagrat2、@mikasa0818 和 @LEXES7。
- **Node 运行时兼容性:** 安装程序、CLI 启动器、doctor 和 macOS 应用现在拒绝不兼容的 Node 23 运行时,并引导用户使用受支持的 Node 22 或 24 版本。(#99832)感谢 @vincentkoc 和 @fuller-stack-dev。
- **SQLite WAL 安全性:** 要求 Node 版本包含修补后的 SQLite 运行时,在打开状态数据库前验证加载的库,并使安装程序跨支持平台升级和验证不安全的运行时。(#106065)感谢 @vincentkoc。
- **安装程序临时文件清理:** 当下载或重写失败时,移除 Node 暂存目录和 pnpm 工作区重写文件。(#103725)感谢 @SebTardif。
- **QQBot 媒体投递:** 将沙箱生成的媒体发送限定到活动会话的工作区,使 `/workspace/...` 和相对生成文件路径在 QQBot 媒体标签、结构化负载和流式投递中安全解析。(#92872)感谢 @zhangguiping-xydt 和 @sliverp。
### 完整贡献记录
完整贡献记录请参见标签固定的 [CHANGELOG.md](https://github.com/openclaw/openclaw/blob/v2026.7.1/CHANGELOG.md#complete-contribution-record)。
### 发布验证
- npm 包:https://www.npmjs.com/package/openclaw/v/2026.7.1
- 注册表 tarball:https://registry.npmjs.org/openclaw/-/openclaw-2026.7.1.tgz
- 完整性校验:`sha256-ge/Xss99CHAjPL/ikmH/UFoiOrjcxDB4sW3y9mhycd+dYW3wzV7TKbAVdkrXFgAG2d2BjpJofP97zUZ+umxo8g==`
- 发布 SHA:`2d2ddc43d0dcf71f31283d780f9fe9ff4cc04fe4`
- 完整发布 CI 报告:https://github.com/openclaw/releases/blob/main/evidence/2026.7.1/release-evidence.md
- 发布推送:https://github.com/openclaw/openclaw/actions/runs/29269577304
- npm 预检:https://github.com/openclaw/openclaw/actions/runs/29268707256
- 完整发布验证:https://github.com/openclaw/openclaw/actions/runs/29257432684
- 插件 npm 发布:https://github.com/openclaw/openclaw/actions/runs/29270283750
- 插件 ClawHub 发布:https://github.com/openclaw/openclaw/actions/runs/29270285823
- 插件 ClawHub 引导:不需要
- OpenClaw npm 发布:https://github.com/openclaw/openclaw/actions/runs/29272090669
- npm Telegram beta E2E:未提供
- Windows Hub 晋升:https://github.com/openclaw/openclaw/actions/runs/29274408977 来自 openclaw/
[email protected]
- macOS 预检:[https://github.com/openclaw/releases/actions/runs/29293062505](https://github.com/openclaw/releases/actions/runs/29293062505)
- macOS 验证:[https://github.com/openclaw/releases/actions/runs/29293060837](https://github.com/openclaw/releases/actions/runs/29293060837)
- macOS 发布:[https://github.com/openclaw/releases/actions/runs/29299988328](https://github.com/openclaw/releases/actions/runs/29299988328)
- macOS appcast:[https://github.com/openclaw/openclaw/pull/106993](https://github.com/openclaw/openclaw/pull/106993)
- Android 发布:[https://github.com/openclaw/openclaw/actions/runs/29293423573](https://github.com/openclaw/openclaw/actions/runs/29293423573)
- 稳定主分支结项:[https://github.com/openclaw/openclaw/actions/runs/29302553990](https://github.com/openclaw/openclaw/actions/runs/29302553990)
- 不可变结项清单:[manifest](https://github.com/openclaw/openclaw/releases/download/v2026.7.1/openclaw-2026.7.1-stable-main-closeout.json) · [checksum](https://github.com/openclaw/openclaw/releases/download/v2026.7.1/openclaw-2026.7.1-stable-main-closeout.json.sha256)
- Linux 包与 Gateway 冒烟测试:[https://crabbox.openclaw.ai/portal/runs/run_c3257c19e269](https://crabbox.openclaw.ai/portal/runs/run_c3257c19e269)
## 2026.7.1
### Highlights
- **New models and providers:** add Featherless, Claude Sonnet 5 and Mythos 5, Meta Muse Spark 1.1, and ClawRouter; make GPT-5.6 the new-setup default with `/think ultra` for Sol and Terra plus `max` for Luna, honor Z.AI `max`, and refresh model availability after OAuth renewal. (#101092, #98254, #101238, #102873, #103070, #103163, #99658, #99759, #98333, #103581, #98021, #104778, #102289) Thanks @vincentkoc, @vortexopenclaw, @HamidShojanazeri, @davemorin, @Solvely-Colin, @jalehman, @steipete-oai, @bdjben, @obviyus, @sallyom, @anyech, @100yenadmin, and @fuller-stack-dev.
- **Control UI and native macOS chat:** make sessions primary with a minimal searchable sidebar, compact context ring, reasoning-effort slider, cleaner dashboard chrome, and a native macOS session browser with model and thinking pickers, slash commands, transcript export, and context usage. (#99289, #99838, #100386, #101103, #101497)
- **Conversational onboarding:** Crestodian now runs a real agent-loop setup across the CLI, web install, and macOS app, with AI-guided provider setup, model-judged approvals bound to exact operations, masked credential prompts, and deterministic fallback when no model is available. (#99935, #100029, #100656, #101887) Thanks @fuller-stack-dev.
- **Offline and spoken mobile chat:** iOS and Android now pre-paint bounded per-gateway session and transcript caches offline; Apple Watch gains full voice turns, and iOS can speak replies through configured Gateway TTS with on-device fallback. (#100219, #100227, #100283, #100770, #100771)
- **Session organization and generated titles:** generate concise session titles through utility-model routing and add Gateway-backed groups, unread state, rename, fork, archive, and delete controls, plus group management across web, iOS, and Android. (#87643, #100814, #101117, #101234) Thanks @zhangguiping-xydt and @Juliangsm.
- **Telegram and Codex continuity:** pair Codex through private `/login`, steer active runs with `/steer` and `/tell`, preserve messages when transcript acknowledgement is missing, adopt durable turns safely, and recover final sends across Telegram formatting and flood-wait failures. (#98006, #98126, #98786, #103664, #103916) Thanks @100yenadmin, @Kyzcreig, @obviyus, and @jalehman.
- **Startup and upgrade recovery:** run container migrations before Gateway readiness, stop recoverable legacy state from blocking startup, and enter control-plane-safe mode after repeated unclean boots instead of restart flapping. (#101881, #104529) Fixes #98565 Thanks @sallyom, @jacobtomlinson, @bdjben, @obviyus, and @shakkernerd.
### Changes
- **Meta provider:** add bundled `muse-spark-1.1` Responses API support with streaming, tool calls, encrypted reasoning replay, onboarding, exact-model live validation, and standalone npm/ClawHub distribution as `@openclaw/meta-provider`. (#102873, #103070, #103163) Thanks @HamidShojanazeri, @davemorin, @Solvely-Colin, @jalehman, and @vincentkoc.
- **Android chat agent selector:** switch the active agent directly from the live chat screen while keeping chat, Talk mode, and home canvas on the same canonical session. (#80422) Thanks @bcperry and @joshavant.
- **Gateway host status:** show the connected Gateway's host, network address, OS, runtime, uptime, CPU, memory, and disk details in Control UI Settings. (#100478)
- **Gateway crash-loop recovery:** persist boot outcomes, enter control-plane-safe mode after repeated unclean starts, hold transport and provider activation until recovery, and exit with `EX_CONFIG` for fatal configuration errors so systemd and launchd stop restart flapping. Thanks @obviyus.
- **iOS offline chat:** pre-paint recent sessions and canonical transcripts from a protected, bounded per-gateway cache, keep sending disabled offline, and purge cached conversation text when pairing is reset. (#100219)
- **Slack progress indicators:** use Slack's native assistant thread status and rotating loading messages by default while keeping acknowledgement reactions static; lifecycle reaction updates now require `messages.statusReactions.enabled: true`.
- **Control UI Talk controls:** keep voice, model, sensitivity, and other realtime defaults in Settings → Communications → Talk, and use the composer microphone caret to select any browser audio input. (#101046)
- **Cron model selection:** choose an agent-turn model in Control UI Quick Create and show configured or default models in cron job rows and details. (#95341) Thanks @ly85206559.
- **Control UI GitHub previews:** show issue and pull request state, title, author, activity, comments, and change statistics in hover and keyboard-focus cards. (#100434)
- **Logbook work journal:** add a disabled-by-default bundled plugin that turns paired-node screen snapshots into a private timeline, daily standup, and timeline-grounded Q&A in a plugin-contributed Control UI tab. (#99930)
- **Control UI message context:** reveal per-message token, context, and model details from the timestamp on hover or activation instead of showing a separate Context button.
- **Control UI session titles:** reveal truncated recent-session names with a reduced-motion-safe hover animation.
- **Control UI sidebar navigation:** show a small customizable pinned destination set, keep the remaining pages under More, move Settings to the footer, and persist sidebar customization in the browser. (#100296) Thanks @vincentkoc.
- **Control UI sidebar usage:** remove the provider usage quota row from the expanded sidebar while keeping usage details available in the chat composer and Usage page. Thanks @shakkernerd.
- **Android chat code highlighting:** render fenced Kotlin, Swift, TypeScript, JavaScript, Python, Bash, and JSON blocks with bounded, theme-aware syntax colors while preserving plain rendering for unknown, partial, or oversized blocks. (#100217)
- **Gateway TTS playback:** add an operator-scoped `tts.speak` RPC that returns configured-provider speech as inline whole-clip audio for remote clients. (#100770)
- **Control UI context usage:** show context-window progress, latest-run input/output tokens, and the active model when the chat context ring is opened.
- **Apple Watch voice turns:** dictate a message from the Watch chat and hear the new OpenClaw reply spoken on the Watch, with explicit silent-message and stop-speaking controls. (#100224) Thanks @vincentkoc.
- **Conversational onboarding:** add a real agent-loop Crestodian setup flow across the CLI, Gateway, web install, and macOS app, with typed operations, exact approval binding, masked credential prompts, isolated session transcripts, and safe handoff to the normal agent. Thanks @vincentkoc.
- **Generated session titles:** name new Control UI sessions from their first message, and add default/per-agent `utilityModel` routing for lower-cost session, topic, and thread title generation. Thanks @Juliangsm, @zhangguiping-xydt, and @vincentkoc.
- **ClawRouter routing and quotas:** add the bundled ClawRouter provider plugin with credential-scoped dynamic model discovery, OpenAI-compatible and native Anthropic/Gemini transports, and managed budget reporting across OpenClaw usage surfaces. (#99658)
- **Model and provider coverage:** add GPT-5.6 support, use Nemotron Super's 1M context window, and preserve explicit OpenRouter authentication headers. (#98333, #98726, #98187) Thanks @steipete-oai, @eleqtrizit, @sunlit-deng, @laurencebrown, and @shakkernerd.
- **CLI and node workflows:** add `openclaw attach`, node context-path support, actionable device-approval recovery guidance, soft-resume CLI sessions when prompt metadata changes, and clearer plugin install exit diagnostics. (#96454, #97679, #98115, #98146, #98497, #99822) Thanks @anagnorisis2peripeteia, @obviyus, @wm0018, @welfo-beo, @RomneyDa, @Sanjays2402, and @vincentkoc.
- **Cron and usage:** add exit-triggered schedules, detached session-targeted runs, and an in-flight job doctor warning, while making the existing usage footer easier to wrap on Telegram. (#92037, #98755, #98620, #92877) Thanks @anagnorisis2peripeteia, @obviyus, @EthanSK, @masatohoshino, @Marvinthebored, and @vincentkoc.
- **Native apps and localization:** modernize iOS presentation, Chat, Talk, onboarding, and reconnect flows; add Gateway speech providers; improve QR onboarding and protocol recovery; install the local Gateway from macOS; localize core Apple and Android surfaces; and add Swedish mobile localization. (#98452, #98736, #99243, #98376, #98302, #98385, #99767, #97110, #97111, #97112, #97113, #98043) Thanks @jcooley8, @Tony-ooo, @joelnishanth, @cursoragent, @joshavant, @vincentkoc, and @yeager.
- **Messaging capabilities:** add native iMessage polls, Telegram Codex pairing and steering, Telegram multi-lane progress summaries, and Signal target aliases. (#98421, #98006, #98126, #98907, #95738) Thanks @omarshahine, @lobster, @100yenadmin, @Kyzcreig, @Marvinthebored, and @jesse-merhi.
- **Local inference and chat controls:** auto-discover Ollama inference nodes, add Control UI session-first navigation, reasoning controls, and command picking, and keep OpenClaw control tools available when deferred tool search selects the wrong tool family. (#99234, #99289, #99426, #99838, #99561) Thanks @100yenadmin, @joshavant, @VicZhang6, @Solvely-Colin, and @vincentkoc.
- **Doctor and diagnostics:** expose auth-profile, workspace, device-pairing, channel-plugin, memory-provider, systemd exhaustion, and Windows LAN firewall findings. (#97125, #97358, #97366, #97496, #97968, #98291, #98666) Thanks @giodl73-repo, @masatohoshino, and @joshavant.
- **Policy repair previews:** show review-required Gateway bind and denied node-command changes during `doctor --fix` without applying them or counting the findings as repaired. (#99776) Thanks @giodl73-repo.
- **Conversation and review controls:** prepare scoped conversation capability profiles and add Cursor Agent as an autoreview engine. (#98536, #97348) Thanks @hxy91819.
### Fixes
- **Codex runtime switching:** accept the bundled Codex runtime for both `codex/*` and `openai/*` model routes while keeping unsupported provider/runtime pairs rejected. (#103762)
- **LM Studio and xAI repaired tool calls:** emit the terminal tool-call event before completion when promoting serialized plain-text tool calls, preserving the complete streaming lifecycle for consumers.
- **Browser actions on Node 24:** keep browser request cancellation bound to the client and response lifetime instead of Node 24.16+'s prematurely aborted body-stream signal, preventing valid POST actions from failing after JSON parsing. Thanks @obviyus and @vincentkoc.
- **SecretRef model credentials:** keep resolved provider secrets behind process-local sentinels through auth storage, stream setup, SDK configuration, and managed local-provider probing, then inject plaintext only at the final network or provider-plugin boundary while retaining exact-value log redaction. (#102008, #102009)
- **Telegram token redaction:** redact bot tokens even when log transports split them across chunks, preventing fragmented credentials from escaping structured and streamed logs. (#103861) Thanks @vincentkoc.
- **Telegram durable turn adoption:** complete spooled updates only after durable agent adoption, detach adopted turns from the ingress reply fence, and suppress superseded replies so recovery cannot leak stale or duplicate responses. (#103664, #103952, #103965) Thanks @obviyus and @vincentkoc.
- **Task delivery recovery:** normalize legacy delivery statuses while restoring task records so older queued work becomes runnable instead of aborting registry recovery. (#103946) Fixes #103168 Thanks @bek91, @theo674, and @obviyus.
- **Diagnostics provider evidence:** emit one deduplicated `provider.request` timeline event for every completed or failed model call, so opt-in timelines can prove real provider traffic without double-counting terminal paths. Fixes #103063 Thanks @vincentkoc.
- **Lean local model shell access:** keep `exec` directly visible beside the default structured Tool Search controls so coding-tuned local models can use their shell fallback instead of searching for missing domain tools. (#101607) Thanks @vincentkoc and @maweibin.
- **OAuth refresh contention diagnostics:** keep local lock paths out of user-facing refresh failures and avoid duplicate failure prefixes while preserving structured provider and profile classification. (#101573) Thanks @vincentkoc.
- **Exec approval prompts:** keep background-disabled fallback warnings out of pending gateway/node approvals and show them only after a command actually runs in the foreground. (#101561) Thanks @vincentkoc.
- **Direct poll delivery:** route direct and hybrid channel polls through the owning outbound adapter while preserving gateway-mode routing and channel option checks. (#99950) Thanks @NianJiuZst and @shakkernerd.
- **Agent wait hard-timeout snapshots:** preserve canonical hard-timeout phase and timestamps when the outer `agent.wait` timer wins the retry-grace race, while leaving queue, draining, and restart-cancelled waits correctable. (#89367) Thanks @Pick-cat and @sunnydongbo.
- **Control UI typed approvals:** send `/approve` commands immediately through the authorized Gateway command path while an agent run is blocked instead of queueing the command behind that run. (#101532) Thanks @vincentkoc.
- **Microsoft Teams Graph response bounds:** cap successful file-upload and chat JSON reads so oversized Microsoft Graph responses cannot be buffered without limit. (#97784) Thanks @Alix-007.
- **Packaged speech runtime:** stop treating package-backed `speech-core` as a bundled plugin sidecar, restoring TTS startup in npm installs while release checks keep true activation-bypassing facades package-complete. (#89899, #89425) Thanks @zhangguiping-xydt, @ant1b0t, and @vincentkoc.
- **Container image upgrades:** run versioned state migrations and plugin convergence before Gateway readiness when reusing mounted state, failing closed with `doctor --fix` recovery guidance instead of serving half-upgraded state. (#101881) Fixes #98565 Thanks @sallyom, @jacobtomlinson, and @shakkernerd.
- **Plugin update reliability:** preserve plugins successfully switched through ClawHub during core updates instead of processing them a second time and disabling them after a redundant transient failure. (#105405) Thanks @vincentkoc.
- **Codex app-server protocol:** require app-server 0.143 or newer, remove pre-0.142 wire-shape compatibility, migrate retired `on-failure` approval settings to `on-request` in Codex configuration and saved bindings, teach Codex to retrieve deferred native `spawn_agent` through `tool_search` so native subagent task mirroring works on search-capable models, and update the managed runtime to 0.144.1 for code-mode host installation and missing-host fallback reliability. Thanks @vincentkoc.
- **Android hardware keyboard chat:** send with unmodified Enter on physical keyboards while preserving Shift+Enter and other modified Enter combinations for multiline input. (#101239) Thanks @3ninyt3nin-creator and @vincentkoc.
- **CJK Markdown emphasis:** render adjacent Chinese, Japanese, and Korean emphasis punctuation through the shared Markdown pipeline instead of leaking literal markers across channels. (#101230, #101120) Thanks @nicknmorty and @j08577600-jpg.
- **Backup retry cleanup:** close partial archive output handles and isolate each retry path after live-write failures, preventing Windows `EBUSY` locks from cascading across attempts or leaving stale temp archives. (#101449, #101464) Thanks @ZOOWH, @LiLan0125, @vincentkoc, @aniruddhaadak80, @shakkernerd, and @obviyus.
- **Codex yielded native subagents:** keep the parent app-server subscription and shared client alive until yielded native subagent completion delivery settles, preventing lost wakeups and leaked one-shot cleanup. Thanks @vincentkoc.
- **Delivery recovery pacing:** pace eligible outbound and restart-continuation replays after gateway startup so outage backlogs do not burst into channel rate limits, while preserving the wall-clock recovery budget. (#101118, #101058) Thanks @ZengWen-DT, @aniruddhaadak80, and @vincentkoc.
- **Outbound pre-connect recovery:** clear stale platform-send evidence atomically when a connect or DNS failure proves no request was sent, allowing queued Discord and other channel messages to replay after connectivity returns without weakening the unknown-send duplicate guard. (#101024, #100979) Thanks @SunnyShu0925 and @tiffanychum.
- **Discord streamed finals:** send completion replies as fresh messages so inactive channels become unread, while preserving targeted mentions without escalating `@everyone` or `@here`. (#99711, #99662) Thanks @davelutztx and @xena68.
- **OpenAI-compatible SSE parsing:** recognize event streams mislabeled as JSON without prepending a second `data:` prefix, preserving valid streamed responses from non-conforming providers. (#96503) Thanks @ZengWen-DT and @54meteor.
- **Meta Model API contract:** use the current Meta endpoint and output-token field so `muse-spark-1.1` validation and live requests match the provider contract. (#103680) Fixes #103667 Thanks @vincentkoc, @HamidShojanazeri, @davemorin, @Solvely-Colin, and @jalehman.
- **LM Studio embedding preload:** honor model- and provider-level context-window limits when preloading embedding models, preventing avoidable GPU out-of-memory failures. (#100750) Thanks @zak-li, @ZOOWH, and @hxz398.
- **Provider overload messaging:** keep rate-limited responses classified for retry and fallback behavior while using overload wording when the provider supplies no explicit retry detail. (#98165) Thanks @SunnyShu0925.
- **Microsoft Teams attachment metadata:** bound Bot Framework `attachmentInfo` JSON reads and cancel oversized streams before they can exhaust Gateway memory. (#99125) Thanks @ly85206559.
- **Agent auth copy order:** preserve the source agent's portable auth-profile precedence when copying credentials to a new agent while excluding skipped profiles and transient auth state. (#100833) Thanks @machine3at.
- **Memory session repair:** keep daily dreaming ingestion bookkeeping outside session-corpus audit and repair so `memory status --fix` preserves healthy daily state. (#93389) Thanks @Alix-007 and @vincentkoc.
- **Remote browser CDP policy:** allow the configured CDP control host through an existing hostname allowlist without widening page navigation policy, while keeping strict-policy discovery bound to the configured control authority. (#100986, #100819) Thanks @NianJiuZst, @SarinV, and @vincentkoc.
- **Config unset diagnostics:** explain when an inherited or default configuration value cannot be unset instead of reporting a misleading successful deletion. (#96557) Thanks @moeghashim.
- **Crestodian command probes:** contain stdout and stderr stream failures while keeping child-process close and spawn errors authoritative, preventing unhandled probe crashes. (#100741) Thanks @lsr911.
- **Feishu mention forwarding:** fail closed when the bot Open ID is unavailable so group messages cannot be misclassified as explicit bot mentions. (#100891) Thanks @zhangguiping-xydt.
- **Cron edit delivery:** preserve each job's implicit delivery mode when applying partial delivery updates, so disabling best-effort delivery no longer turns detached job announcements off. (#100846) Thanks @machine3at and @vincentkoc.
- **Control UI session creation:** keep newly created sessions at the front of the stable sidebar order after selecting another session. Thanks @shakkernerd.
- **Control UI file previews:** keep large Skill Workshop files responsive with cached, offscreen-contained text chunks while preserving wrapped content, stable file switching, full-file copy, and clean focus behavior. (#101319) Thanks @xianshishan, @shakkernerd, and @vincentkoc.
- **FTS-only memory startup:** skip plugin capability discovery when `memorySearch.provider` is explicitly `none`, avoiding an unnecessary cold-start scan.
- **Control UI agent model labels:** show each selected agent's effective model in the Default picker option instead of the global model. (#100719, #77440) Thanks @hyspacex and @jwong-art.
- **Control UI inbound image previews:** render canonical inbound media references through the authenticated ticket route after chat-history reloads. (#100725, #89591) Thanks @sweetcornna, @vergissberlin, and @shakkernerd.
- **Small-context compaction:** cap the effective reserve against the known model context window so small local models do not enter compaction from the first token. (#100621) Thanks @vincentkoc.
- **Detail-less provider failures:** keep opaque upstream failures from cooling API-key auth profiles while preserving WHAM-backed OpenAI OAuth health checks and configured model fallback. (#100617) Thanks @fabasi, @fengjikui, and @vincentkoc.
- **Plugin install diagnostics:** suppress the misleading hook-pack fallback after plugin install failures only when the hook manifest is absent, while preserving actionable malformed hook-pack errors. (#100554) Thanks @vincentkoc and @obviyus.
- **Config validation diagnostics:** emit each unchanged sanitized validation-warning payload once per config path, reset deduplication after a clean validation, and preserve the warning fingerprint across transient invalid reads and failed refreshes. (#100569, #25574) Thanks @vincentkoc and @mcaxtr.
- **Config size-drop guard:** compare writes against canonical bytes for parseable object configs instead of raw BOM and indentation overhead, while preserving raw audit telemetry and the conservative malformed-input fallback. (#100591, #71865) Thanks @vincentkoc and @balric-seo.
- **Control UI coalesced updates:** show a clear queued-restart completion banner when an update joins an already-running Gateway restart. (#93082) Thanks @goutamadwant and @motacola.
- **Control UI connection errors:** preserve structured pairing and authentication failures for pending RPC callers while keeping generic disconnect behavior unchanged. (#54758) Thanks @ruanrrn.
- **iOS embedded terminal:** open the terminal-only Control surface directly while native Gateway authentication connects instead of exposing the Web UI login screen.
- **TUI startup status:** show `starting up` during post-connect initialization without overwriting active-run or reconnect state. (#93999) Thanks @ml12580 and @sanjarcode.
- **Control UI restart recovery:** recover stale bundle pages through a bounded whole-document refresh after Gateway updates or restarts. (#99111) Thanks @ZengWen-DT and @ITOrity.
- **TUI active Gateway ports:** follow the verified active local Gateway port when no explicit URL, port, or remote target is configured. (#73338, #42461) Thanks @haishmg, @vincentkoc, and @jackm1688.
- **Apple chat run recovery:** restore active responses from canonical Gateway history after reconnects, foreground resumes, and event gaps, while preserving gateway user-turn identity across Codex and Copilot transcript mirrors to prevent duplicate rows. (#100277)
- **Claude CLI streamed replies:** preserve assistant text already received from Claude CLI when its terminal result envelope is empty, preventing false empty-response failover after a complete streamed answer. (#90450) Thanks @totobusnello.
- **Phone identity normalization:** canonicalize stray plus signs, preserve non-phone iMessage handles, and reject digit-free Signal identities across shared channel routing. (#100467) Thanks @morluto.
- **Tlon scry response bounds:** cap successful Urbit scry JSON reads and cancel oversized streams instead of buffering unbounded peer responses. (#100376) Thanks @hugenshen.
- **Source build portability:** keep tsdown configuration self-contained so builds do not depend on resolving the tsdown package from unrun's temporary module directory. Thanks @vincentkoc.
- **Agent tool-call decoding:** preserve surrogate-range numeric HTML entities as literal text while still decoding valid supplementary-plane values, preventing malformed model output from injecting lone UTF-16 surrogates into tool arguments. (#99564) Thanks @mikasa0818, @vincentkoc, @shakkernerd, and @maweibin.
- **Gateway event dispatch:** catch and log lazy subscriber setup and handler failures instead of leaking unhandled promise rejections. (#100401) Thanks @cxbAsDev.
- **Ollama fallback routing:** classify incomplete native streams through the Ollama provider hook so configured model fallbacks can advance. (#100482) Thanks @TurboTheTurtle, @8kfcf95jvp-oss, and @vincentkoc.
- **Diffs rendering:** render viewer and image output from one SSR preload, preserve language-pack highlighting through hydration, normalize language hints case-insensitively, skip identical before/after inputs with an explicit `changed` result, report truthful file-render and input errors, cache hash-pinned viewer runtimes, and prefer canonical file settings over stale aliases. (#100487) Thanks @vincentkoc.
- **Remote browser reliability:** bound persistent Playwright tab enumeration by the existing remote CDP timeout budget and retire timed-out connection attempts so late completions cannot restore a stuck connection. (#80147, #58968) Thanks @HemantSudarshan and @KeaneYan.
- **Browser attachment downloads:** return managed URL, filename, and path metadata when direct Playwright navigation starts an attachment download, while validating final URLs before saving bytes and preserving single-owner explicit downloads. (#48045, #89416) Thanks @zhangguiping-xydt and @roinou532.
- **Browser action downloads:** return managed URL, filename, and path metadata when agent actions trigger downloads, while preserving explicit ownership, validating final URLs before saving bytes, and quarantining policy-denied tabs without closing them. (#93250, #93307) Thanks @sunlit-deng and @scorpiord.
- **Managed browser cookie persistence:** initialize new isolated macOS headless profiles with a non-interactive encryption key while preserving existing profile keys, and close Chromium through CDP before bounded signal fallback so persistent logins survive graceful browser and Gateway restarts. (#96704, #98284) Thanks @TurboTheTurtle and @shakkernerd.
- **MCP OAuth response bounds:** reject body-less foreign error bodies without calling their inherently unbounded `text()` fallback, while preserving HTTP status and headers for safe SDK diagnostics. (#98143) Thanks @Pick-cat, @wangmiao0668000666, and @vincentkoc.
- **Tlon image upload bounds:** cap remote image fetches before upload and fail closed on oversized or stalled responses instead of buffering them without a limit. (#100374) Thanks @hugenshen.
- **Control UI approval prompts:** keep stale resolve failures and busy-state cleanup from leaking across newer approvals or Gateway reconnects. (#98394) Thanks @haruaiclone-droid.
- **macOS service SecretRefs:** preserve generated env-file values for SecretRefs that remain in config when stale Gateway LaunchAgents are repaired or reinstalled without those variables in the invoking shell. (#99124) Thanks @mushuiyu886 and @1Wanker.
- **Anthropic OAuth callbacks:** keep the provider-required `localhost` redirect URI stable while allowing the local callback listener to bind an explicit loopback host. (#96917) Thanks @xialonglee, @riazrahaman, and @vincentkoc.
- **Prompt-release media delivery:** accept active-leaf-preserving side appends while an embedded run temporarily releases its session lock, so successive message-tool media replies merge without a false session-takeover failure. (#100490) Thanks @scotthuang and @vincentkoc.
- **Control UI Skills filters:** align agent and search controls, use translated labels, and preserve native checkbox and radio sizing. (#100526) Thanks @evan-YM and @vincentkoc.
- **Control UI completed-run state:** bind active and completed updates to run identities so stale completions keep Send available while newer runs remain active. (#100527) Thanks @tiffanychum, @davidstoll, and @shakkernerd.
- **Control UI context usage:** keep stale cached totals visible as approximate without triggering warning styling or Compact actions. (#89772) Thanks @bladin and @snsczssl.
- **Control UI file previews:** remove the duplicate Escape header hint while retaining the Close-button shortcut hint and Escape behavior. (#100528) Thanks @xianshishan and @vincentkoc.
- **Control UI autonomous tool failures:** preserve an earlier Tool error outcome across later autonomous recovery turns. (#100514) Thanks @qingminglong and @yetval.
- **Agent empty replies:** surface a visible failure when a completed interactive turn has no deliverable reply, including queued follow-ups, while preserving explicit silence, pending continuations, and committed side effects, honoring queued send policies, and treating compaction notices as progress. (#100456) Thanks @mushuiyu886 and @grox2012.
- **Subprocess, maintenance, and output hardening:** keep child output failures from crashing exec and TUI sessions, isolate remote skill refresh and subagent sweeps, surface skill-scan and approval diagnostics, sanitize ANSI and stray parameter markup without losing visible text, and stop Android audio capture cleanly on device loss. (#100440) Thanks @cxbAsDev, @wendy-chsy, @tzy-17, @nankingjing, @NianJiuZst, @LavyaTandel, and @maweibin.
- **Docker sandbox command output:** fail and terminate Docker sandbox operations when stdout/stderr capture breaks instead of returning success with incomplete output. (#100523) Thanks @cxbAsDev and @vincentkoc.
- **Android push-to-talk lifecycle:** serialize gateway PTT preparation with app foreground and Manual Mic ownership so delayed work cannot restart, replace, or tear down a newer capture. (#100552) Thanks @xialonglee.
- **Lean local-model tools:** trim media generation, TTS, and PDF tools from lean agent surfaces while preserving explicit config and runtime opt-ins. (#88881) Thanks @vincentkoc.
- **iOS development app identity:** keep the development app labeled OpenClaw while using its distinct debug icon to differentiate it from release builds.
- **Android chat recovery:** preserve optimistic user messages and locally owned runs while reconnect and sequence-gap history snapshots catch up, preventing sent messages from disappearing or stale runs from taking ownership. (#100197)
- **iOS QR gateway handoff:** stop VisionKit before delivering scanned setup codes, and keep deferred auth, approval, Watch, and foreground-node work bound to its originating gateway across reconnects. (#99572) Thanks @PollyBot13.
- **Agent terminal failures:** surface a safe interactive reply when an agent run ends without visible output, while preserving completed message-tool delivery and heartbeat-specific guidance. (#99304) Thanks @moeedahmed and @maweibin.
- **MCP loopback tool results:** preserve schema-valid text, image, and embedded-resource content through HTTP tool calls while rendering malformed or protocol-incompatible blocks as safe text. (#100336) Thanks @tzy-17, @OpenClawKobian99, @vincentkoc, @shakkernerd, and @maweibin.
- **Control UI tool-result images:** render direct image content blocks from Gateway history and make the delayed-send scroll E2E setup deterministic. (#100295) Thanks @lzyyzznl, @Pandah97, @rquinones84, and @maweibin.
- **Control UI live tool ordering:** keep assistant stream text before its matching tool card when browser and Gateway timestamps disagree. (#93184) Thanks @Pick-cat and @lileilei-camera.
- **IRC Unicode messages:** split outbound PRIVMSG payloads on UTF-16 code-point boundaries so emoji cannot be cut into lone surrogates. (#96572) Thanks @WeeLi-009, @vincentkoc, @mushuiyu886, and @cursoragent.
- **OpenAI realtime voice greetings:** prevent server VAD from creating a second outbound greeting while an explicit greeting response owns the turn, without disabling caller interruption. (#86285) Thanks @giodl73-repo and @jnikolaidis.
- **Realtime voice tools:** filter malformed tool names at each OpenAI, Azure, and Google realtime payload boundary while preserving provider-specific valid names. (#89175) Thanks @vincentkoc.
- **Discord voice status:** treat Discord error 10065 as a normal disconnected state while preserving unrelated REST failures. (#90969) Thanks @asock.
- **Discord voice accounts:** isolate `@discordjs/voice` connections by Discord account and recover auto-join when gateway readiness predates listener registration. (#87530) Thanks @geekhuashan.
- **iOS Voice Wake cleanup:** avoid initializing the microphone audio pipeline while disabling inactive Voice Wake, preventing simulator launch aborts and unnecessary audio setup.
- **Reliability edge cases:** reject sub-millisecond cron durations, preserve generated proposal newlines, normalize blank integer inputs and fail embedded LSP startup promptly, surface persistence and memory-close failures, keep UTF-16 and plugin package verification correct, propagate Android cancellation, and defer Codex relay registry writes until listening. (#100399) Thanks @cxbAsDev, @snotty, @lin-hongkuan, @849261680, @qingminglong, @anyech, @masatohoshino, @Simon-XYDT, @xialonglee, @nankingjing, @609NFT, and @vincentkoc.
- **Voice Call completed status:** resolve finalized calls from the full retained event store across Gateway, tool, and CLI status paths while preserving active-call lookup performance. (#99797) Thanks @Darren2030, @NiTeCoMM-code, and @maweibin.
- **Agent stop recovery:** prevent late-aborting prompts from reacquiring orphaned session locks after teardown, so `/stop` leaves the conversation ready for the next turn.
- **Message delivery status:** report failed and partially failed best-effort channel delivery instead of returning a success-shaped message-tool result. (#99928) Thanks @masatohoshino.
- **WhatsApp credential recovery:** restore malformed primary auth state from a valid backup during startup. (#99070) Thanks @LeonidasLux.
- **WhatsApp quoted replies:** preserve bot-authored outbound quote metadata so replies to those messages keep their reply bubble in WhatsApp Desktop. (#94879) Thanks @Bartok9, @seikosantana, and @vincentkoc.
- **WhatsApp reconnect catch-up:** admit recently missed Baileys `append` messages during a bounded reconnect window while preserving startup stale-history guards. (#80642) Thanks @VishalJ99.
- **WhatsApp restart recovery:** stop automatic restart loops after logged-out or connection-replaced disconnects until the account reconnects. (#78511) Thanks @openperf and @rutherlesdev.
- **Local Gateway CLI auth:** keep loopback CLI token/password calls off durable device scopes so read probes cannot block later write/admin commands behind a stale pairing baseline. (#95997) Thanks @vincentkoc.
- **Plugin module identity:** keep OpenClaw package chunks on Node's native module graph when jiti transforms plugin entries, preventing duplicate evaluation and class identity drift. (#88384) Thanks @vincentkoc and @ScientificProgrammer.
- **Shell completion repair:** generate core-only caches during doctor and update repair while preserving full plugin command completion for onboarding and explicit user rebuilds. (#76235) Thanks @joshavant.
- **MCP schema diagnostics:** attribute draft-2020-12 compiler failures to the external MCP schema so malformed patterns produce actionable setup errors. Thanks @vincentkoc.
- **Windows Scheduled Task recovery:** keep clean early exits inside the existing bounded launch poll, falling back only when neither the task process nor Gateway listener becomes observable.
- **iMessage group warnings:** suppress the false drop-all startup warning when an effective group sender allowlist can admit groups, and point true empty-allowlist configurations at the correct remedy. (#100046)
- **Control UI mobile login:** keep Gateway recovery guidance visible after connection failures, make the disconnected gate scroll safely on constrained screens, and improve mobile keyboard and tap-target behavior. (#100208)
- **TUI streaming:** render delta-only assistant events in live Gateway and embedded TUI sessions instead of waiting for the final response. (#83000) Thanks @flashosophy.
- **Model aliases:** resolve provider-qualified aliases during session and chat-command model switches without collisions when providers share a display alias. (#100209) Thanks @sahilsatralkar, @david-r-jones, @shakkernerd, and @vincentkoc.
- **TUI new-session hooks:** create `/new` sessions through the shared Gateway lifecycle so command and session hooks receive the completed parent transcript in both Gateway and embedded modes, while preventing rollover during an active turn. (#100241, #49918) Thanks @BingqingLyu, @caopulan, @LonExplorer-coder, and @vincentkoc.
- **TUI abort diagnostics:** show sanitized tool argument-validation summaries for aborted runs in both Gateway and local TUI modes without exposing raw model arguments. (#91002) Thanks @wsyjh8 and @taerlandsen.
- **iOS Watch replies:** persist queued quick replies in the gateway-scoped chat outbox and submit them through idempotent chat delivery, preventing losses, duplicates, and cross-gateway sends after reconnects. (#100372) Thanks @NianJiuZst.
- **iOS Gateway auth retry:** restrict stored device-token retry to parsed loopback hosts and reject wildcard bind addresses, preventing remote lookalike hostnames from receiving trusted retry credentials. (#99859) Thanks @ly85206559 and @vincentkoc.
- **Bedrock Mantle discovery:** bound model-catalog fetch time and response size, and release rejected response bodies so stalled, oversized, or failed provider responses fall back safely. (#99961) Thanks @zhangguiping-xydt and @shakkernerd.
- **Discord thread-title prompts:** truncate generated-title message and channel context on UTF-16 boundaries so emoji cannot leave malformed model prompt text. (#101551) Thanks @Alix-007, @vincentkoc, @mushuiyu886, and @cursoragent.
- **Mobile pairing routes:** advertise verified persistent Tailscale Serve fallbacks alongside `gateway.bind=lan` setup URLs, show every route in the Control UI and CLI, and let iOS save the first reachable endpoint. (#100280) Thanks @shakkernerd.
- **Control UI terminal tabs:** vertically center the new-session button in the terminal tab strip.
- **Control UI composer scrollbar:** show the message-field scrollbar only when the draft actually overflows its autosized height.
- **Control UI terminal cursor:** hide the browser-native contenteditable caret so the integrated terminal shows only its canvas-rendered cursor.
- **macOS SSH tunnels:** resolve user-installed SSH `ProxyCommand` helpers through the app's managed PATH while preserving inherited connection environment, so remote aliases work after Finder and sanitized-script launches.
- **Control UI OpenAI speed picker:** show only Standard and Fast choices for OpenAI models.
- **Control UI terminal rendering:** adopt the shared `@openclaw/libterminal` browser lifecycle and add Nerd Font fallbacks so icon-enabled shell listings render their glyphs when a compatible local font is installed.
- **Slack transcript history:** let Codex app-server own its persisted assistant replies so Slack does not append redundant delivery-mirror rows, while the Control UI keeps legacy duplicate mirrors hidden. Thanks @bek91.
- **Control UI chat history:** hide redundant channel-final delivery mirrors when the preceding app-server assistant reply already shows the same text.
- **Control UI chat spacing:** keep the first message comfortably clear of the topbar with a responsive minimum transcript inset.
- **ClawRouter auth profiles:** resolve credential-scoped catalog models during agent runs when the proxy key is stored in an auth profile, and document plugin and model allowlists.
- **Telegram durability:** retry restart-dropped media, survive transient polling errors, dead-letter poison updates, preserve forwarded rich text, route plugin callbacks correctly, keep progress updates in one stable multi-line window, map self-hosted Bot API container paths through trusted host roots, and fall back safely when Telegram rejects rich final replies. (#98102, #98735, #98775, #98776, #97174, #98907, #91984, #98786) Thanks @luoyanglang, @DaveArcher18, @obviyus, @goldmar, @Marvinthebored, @Dizesales, @shakkernerd, @AiLucasdz, and @RomneyDa.
- **Cross-channel inbound media:** preserve captions and expose unavailable-attachment notices when WhatsApp, LINE, Signal, iMessage, Microsoft Teams, Feishu, Mattermost, or Zalo cannot materialize inbound media, instead of dispatching phantom placeholders or dropping media-only turns. (#100092)
- **Agent and context reliability:** preserve runtime overrides, steered subagent tasks, fallback tool-call hints, and legacy reseed attachments; soft-resume CLI sessions across prompt-only drift; improve harness-aware context estimation; time out silent local streams; recover mid-stream failures; and cap Gateway run-cache growth. (#92237, #77539, #99851, #99839, #99822, #97928, #98525, #95430, #77973) Thanks @sercada, @amittell, @obviyus, @liuhao1024, @yetval, @osolmaz, @lzyyzznl, @vincentkoc, @alexelgier, and @fede-kamel.
- **Provider and network safety:** bound oversized or malformed responses across Moonshot, MiniMax, Anthropic OAuth, Discord, Matrix, SMS, browser, update, embeddings, Tlön, and Inworld paths. (#96502, #96322, #96644, #97693, #97662, #97999, #98455, #98508, #98554, #98496, #98660) Thanks @hugenshen, @cursoragent, @lsr911, @solodmd, @Alix-007, @wings1029, @lzyyzznl, @sunlit-deng, @vincentkoc, and @Pandah97.
- **Channel delivery and routing:** keep Slack replies in active thread sessions, preserve account-bound delivery routes, apply response prefixes, and suppress internal traces and unwanted fallback replies. (#97168, #98240, #93639, #97989, #80928) Thanks @LiuwqGit, @gorkem2020, @yetval, @ZengWen-DT, @alexuser, @UnClouded77, and @vincentkoc.
- **Cron correctness:** preserve provider and model selections on timeouts, retain startup catch-up deferrals across maintenance reads, keep action-required output, clear blank thinking overrides, and preserve provider-owned daily-reset sessions. (#95943, #94022, #96393, #96293, #98356) Thanks @ZengWen-DT, @cursoragent, @luke-renjoy, @RichChen01, @vincentkoc, @yetval, @snowzlmbot, @nz365guy, @takamasa-aiso, and @shakkernerd.
- **Memory and session recovery:** detect unindexed transcripts, preserve notes through transient reads, avoid cross-directory resumes, disambiguate reserved wiki index pages, and skip empty QMD sync work. (#97857, #98360, #97785, #94326, #90030) Thanks @zw-xysk, @CHE10X, @qingminglong, @yetval, @vincentkoc, @sahibzada-allahyar, and @ruben2000de.
- **Windows and execution:** bind allowlisted execution to the validated Windows path, propagate `PATHEXT`, normalize inbound paths case-insensitively, and prevent cleanup crashes on Windows. (#98260, #98093, #97630, #97901) Thanks @eleqtrizit, @wendy-chsy, @VectorPeak, @paulcam206, and @shakkernerd.
- **Mobile and UI stability:** preserve iOS chat line breaks and final replies, improve Android pairing and TLS recovery, hide expired pairing cards, keep workspace file rails scrollable, restore copy-path over plain HTTP, and stop rubber-band scrolling in the Mac app Control UI. (#98304, #98117, #98366, #98439, #98483, #98049, #98646, #98611, #98764, #99830) Thanks @joshavant, @Jabato01, @ooiuuii, @wuqxuan, @645648406-max, @zw-xysk, @ZengWen-DT, and @adinballew.
- **Codex and approval flows:** report ChatGPT authentication correctly, rename destructive approval mode to `ask`, classify `get_goal` read statuses accurately, and derive terminal-idle timeouts from the explicit run deadline. (#91240, #98501, #98659, #85296) Thanks @849261680, @ukstem, @kevinslin, @yetval, @alkor200, @vincentkoc, and @alkor2000.
- **Configuration and plugin health:** restrict config traversal to owned properties, preserve config-health recovery state, surface unloadable channel plugins, preserve defaulted provider base URLs during patches, validate bundled plugin updates by manifest contract, resolve public artifacts from installed plugin roots, and retain legacy ClawHub families where required. (#99846, #99728, #96397, #98396, #98010, #98819, #98249) Thanks @vincentkoc, @zenglingbiao, @joshavant, @jalehman, @ccbridle, @849261680, @momothemage, @weltmaister, @LiLan0125, @herove, @amknight, @KelTech-Services, and @Patrick-Erichsen.
- **Runtime process safety:** prevent unhandled child-stream errors in SSH tunnels, supervisors, and MCP stdio transports; keep auto-replies from waiting on transcript mirroring; and avoid splitting Unicode characters in approval previews and LINE outbound fields. (#99800, #99802, #99803, #99549, #99566, #98994) Thanks @cxbAsDev, @vincentkoc, @Shagrat2, @mikasa0818, and @LEXES7.
- **Node runtime compatibility:** installers, the CLI launcher, doctor, and the macOS app now reject incompatible Node 23 runtimes and guide users toward supported Node 22 or 24 releases. (#99832) Thanks @vincentkoc and @fuller-stack-dev.
- **SQLite WAL safety:** require Node releases with a patched SQLite runtime, verify the loaded library before opening state databases, and make installers upgrade and validate unsafe runtimes across supported platforms. (#106065) Thanks @vincentkoc.
- **Installer temporary-file cleanup:** remove Node staging directories and pnpm workspace rewrite files when downloads or rewrites fail. (#103725) Thanks @SebTardif.
- **QQBot media delivery:** scope sandbox-generated media sends to the active session's workspace so `/workspace/...` and relative generated-file paths resolve safely across QQBot media tags, structured payloads, and streaming delivery. (#92872) Thanks @zhangguiping-xydt and @sliverp.
### Complete contribution record
The full contribution record is available in the tag-pinned [CHANGELOG.md](https://github.com/openclaw/openclaw/blob/v2026.7.1/CHANGELOG.md#complete-contribution-record).
### Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.7.1
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.7.1.tgz
- integrity: `sha512-ge/Xss99CHAjPL/ikmH/UFoiOrjcxDB4sW3y9mhyCD+dYW3wzV7TKbAVdkrXFgAG2d2BjpJofP97zUZ+umxo8g==`
- release SHA: `2d2ddc43d0dcf71f31283d780f9fe9ff4cc04fe4`
- full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.7.1/release-evidence.md
- release publish: https://github.com/openclaw/openclaw/actions/runs/29269577304
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/29268707256
- full release validation: https://github.com/openclaw/openclaw/actions/runs/29257432684
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/29270283750
- plugin ClawHub publish: https://github.com/openclaw/openclaw/actions/runs/29270285823
- plugin ClawHub bootstrap: not needed
- OpenClaw npm publish: https://github.com/openclaw/openclaw/actions/runs/29272090669
- npm Telegram beta E2E: not supplied
- Windows Hub promotion: https://github.com/openclaw/openclaw/actions/runs/29274408977 from openclaw/
[email protected]
- macOS preflight: [https://github.com/openclaw/releases/actions/runs/29293062505](https://github.com/openclaw/releases/actions/runs/29293062505)
- macOS validation: [https://github.com/openclaw/releases/actions/runs/29293060837](https://github.com/openclaw/releases/actions/runs/29293060837)
- macOS publish: [https://github.com/openclaw/releases/actions/runs/29299988328](https://github.com/openclaw/releases/actions/runs/29299988328)
- macOS appcast: [https://github.com/openclaw/openclaw/pull/106993](https://github.com/openclaw/openclaw/pull/106993)
- Android release: [https://github.com/openclaw/openclaw/actions/runs/29293423573](https://github.com/openclaw/openclaw/actions/runs/29293423573)
- stable main closeout: [https://github.com/openclaw/openclaw/actions/runs/29302553990](https://github.com/openclaw/openclaw/actions/runs/29302553990)
- immutable closeout manifest: [manifest](https://github.com/openclaw/openclaw/releases/download/v2026.7.1/openclaw-2026.7.1-stable-main-closeout.json) · [checksum](https://github.com/openclaw/openclaw/releases/download/v2026.7.1/openclaw-2026.7.1-stable-main-closeout.json.sha256)
- Linux package and Gateway smoke: [https://crabbox.openclaw.ai/portal/runs/run_c3257c19e269](https://crabbox.openclaw.ai/portal/runs/run_c3257c19e269)