v2026.7.2-beta.2
AIニュース価値スコアβ
通常リリースAI関連度、新規性、日本での有用性など6軸を公開検証中です。現在、掲載順には使用していません。
- AI関連度
- 75
- 情報源の信頼性
- 100
- 新規性
- 25
- 検索具体性
- 25
- 重複の少なさ
- 100
- 日本での有用性
- 25
AI エージェント運用や自動化機能の強化など技術的な詳細が含まれるものの、これは定期的なソフトウェア更新(beta バージョン)の記録であり、新規性スコアは低く設定されます。検索機会については、タイトルに明確なバージョン番号が含まれているため高評価とします。
2026.7.2
ハイライト
必ず JSON 形式で返してください。translation フィールドのみ。他のフィールドは一切追加しないこと — 余計なフィールドを書こうとして本文がトークン上限で打ち切られる事故を防ぐため:
- リモートコーディングセッション: クラウドワーカー上で Control UI セッションを実行し、それぞれのホスト端末で Codex や Claude カタログのセッションを起動し、OpenCode や Pi のセッションは直接ターミナル内で再開できるようにしました。(#107670, #107086, #107200)
- ネイティブ自動化とノード: モバイルでも自動化機能を同等レベルに引き上げ、Android で画面表示時の音声起動(フォアグラウンド・ボイスウェイク)を追加し、ヘッドレス Linux ノードからカメラ、位置情報、通知機能を利用可能にしました。(#106355, #107081, #107193)
- より安全なチャンネル操作: リスタート後に Telegram の永続的イングレスが失われるのを防止し、Signal ではアクティブなターン中も停止と承認コントロールを即座に反応させるように改善しました。また、チャンネルの許可リストが所有者権限を与えてしまう不具合を修正しました。(#107288, #107422, #107403) @obviyus さん、@arduano さん、@yetval さんの貢献に感謝します。
- ガイド付き Control UI セットアップ: 設定画面からモデルプロバイダーを構成し、ガイド付きセットアップページを通じてチャンネルを追加できるようにしました。セッション作成時には画像やモデルの選択も可能です。(#106490, #106469, #107358) @alexandre-leng さん、@fuller-stack-dev さんの貢献に感謝します。
- ゲートウェイとセッションの回復: リスタート時の承認処理でゲートウェイがフリーズするのを防止し、最終化処理が停止した後の返信セッションを復元できるようにしました。ライフサイクル競合時でもワンショット cron ジョブが有効なまま維持されます。(#107339, #106792, #107236) @obviyus さん、@joshavant さん、@charliemeyer2000 さん、@SL4N さんの貢献に感謝します。
- インストールとパッケージング: ゲートウェイのガイダンス付きで Linux の deb パッケージと AppImage バンドルを追加し、安定版メインベースリリースから公開しました。Windows インストールでは、winget で Node.js が追加された直後に即座に完了できるようになりました。(#106533, #106891, #106862)
変更点
必ず JSON 形式で出力してください。translation フィールドのみを含めてください。他のフィールドは一切追加しないでください。余計なフィールドを追加しようとして本文がトークン上限に達し、出力が途中で切れてしまう事故を防ぐためです:
外部ゲートウェイの監視機能強化: OPENCLAW_SUPERVISOR_MODE=external を設定することで、OCM などのライフサイクルオーナーが、ネイティブサービスの権限を公開することなく、検証済みの再起動や延期機能を維持できます。これにより、ネイティブサービスの変更や自己更新がブロックされ、バージョン管理された原子的な再起動ハンドオフ契約が提供されます。@shakkernerd さんありがとうございます。
ClickClack のガイド付きセットアップ: openclaw onboard または openclaw channels add clickclack コマンドで URL、トークン、ワークスペースのプロンプトを入力して ClickClack を設定できます。デフォルトアカウントの環境変数フォールバックもサポートされ、死活接続検証は致命的なエラーにはなりません。OpenClaw が既に実行中の場合は、ゲートウェイを意識した次のステップが自動的に接続されます。@shakkernerd さんありがとうございます。
ClickClack コマンドメニュー: ゲートウェイ起動時に、各ボットのネイティブ OpenClaw コマンドを ClickClack のコンポーザー補完リストに公開します。アカウントごとのオプトアウトが可能で、古いトークンやサーバーへの互換性処理も致命的なエラーにはなりません。@shakkernerd さんと @vincentkoc さんありがとうございます。
スキルワークショップの承認: デフォルトでは追加の承認プロンプトなしにエージェントが適用、拒否、隔離アクションを実行できるようにしました。ただし skills.workshop.approvalPolicy: "pending" を設定することで、承認ゲートとしてオプトインできる機能は維持されます。@shakkernerd さんありがとうございます。
TUI のファジーセレクター: リストのマッチングを pi-tui に委譲し、スラッシュトークンと英数字マッチングを追加しました。これに伴い、ローカルマッチャーのフォーク版は削除されています。
macOS ペアードノード端末: 埋め込みノードホストから双方向の Codex および Claude 端末再開コマンドを公開し、ネイティブアプリブリッジを通じてインタラクティブな入力とキャンセル操作を転送します。(#107335)
コントロール UI カタログ端末: 対象となる Codex や Claude Code セッションを、ゲートウェイまたはペアードノードホスト上のネイティブ CLI で開きます。ビューアとターミナルの切り替え設定や検証済みの再開コマンド、インタラクティブな PTY リレーをサポートします。(#107086) @vincentkoc さんありがとうございます。
スキルワークショップ履歴の確認: 手動で最新順にセッションをスキャンし、古くから蓄積された実用的な作業の中から慎重なスキルアイデアを探します。保存するのは SQLite のカーソルメタデータのみで、自律的な自己学習がオフになっている場合でも最大 3 つの結果を保留中の提案として残します。(#106182)
OpenAI GPT-5.6 デフォルト: 新しい API キー設定では openai/gpt-5.6(Sol エイリアス)を、新しい Codex/OAuth 設定では正確に openai/gpt-5.6-sol を使用します。両方のランタイムで Sol の推論レベルはデフォルトで「ミディアム」に設定されます。既存のプライマリ、フォールバック、エイリアス、および明示的な GPT-5.5 選択は維持されます。(#103234)
iOS オフラインチャット: 保護されたバウンド型のゲートウェイキャッシュから直近のセッションと正規のトランスクリプトを事前描画します。オフライン時は送信が禁止され、ペアリングのリセット時にキャッシュされた会話テキストは削除されます。(#100194)
Slack の進行状況インジケーター: デフォルトで Slack ネイティブのアシスタントスレッドステータスとローテーションする読み込みメッセージを使用します。承認リアクションは静的に保たれ、ライフサイクルのリアクション更新には messages.statusReactions.enabled: true の設定が必要です。
コントロール UI 通話コントロール: 音声、モデル、感度などのリアルタイムデフォルト設定は「設定 → コミュニケーション → 通話」画面に維持されます。コンポーザーのマイクカーソルを使用すれば、ブラウザ上の任意のオーディオ入力を選択できます。(#101046)
コントロール UI セッションワークスペースショートカット: ⇧⌘B でアクティブなチャットパネルのセッションワークスペースレールを展開または折りたためますが、メインアプリサイドバーや個別の詳細・キャンバスプレビューパネルには影響しません。@shakkernerd さんありがとうございます。
コントロール UI 設定ショートカット: ⇧⌘, で設定画面を開きます。ブラウザ側の ⌘, ショートカットは変更されません。@shakkernerd さんありがとうございます。
コントロール UI チャットレイアウト: トランスクリプトをコンポーザー軸の中央に配置します。アシスタントとツールの出力は左、ユーザーの発言は右に表示し、同じ可読フレーム内に収めます。カスタムメッセージ幅のオーバーライドも維持されます。(#104474) @shakkernerd さん、@vincentkoc さん、@zw-xysk さんありがとうございます。
コントロール UI コンポーザーフッター: チャット設定チップとモデル制御を、デコレーターに固定するのではなく、デコレーターとカードエッジの間に中央配置します。(#105866)
コントロール UI アシスタントアクション: アシスタント名と時刻は先頭に維持し、ホバー時のアクションは左端ではなく、その隣に配置します。@shakkernerd さんありがとうございます。
コントロール UI メッセージコンテキスト: 個別のトークン、コンテキスト、モデル詳細は、別々の「コンテキスト」ボタンを表示するのではなく、タイムスタンプ上でホバーまたはアクティブ化すると表示されます。
コントロール UI セッションタイトル: 直近のセッション名が切り捨てられている場合でも、モーションを抑制した安全なアニメーションでホバー時に全称を表示します。
コントロール UI サイドバーの使用状況: 拡張されたサイドバーからプロバイダーの使用量クォータ行を削除しました。ただし使用量の詳細はチャットコンポーザーと「使用状況」ページから引き続き確認できます。@shakkernerd さん、@vincentkoc さんありがとうございます。
Workboard のディスパッチ制限: リクエストスコープの --max-starts オバーライドを追加し、デフォルトの制限値や順次開始、オーナーごとの 1 カード制限は維持します。(#100174) @souvikDevloper さん、@Souvikalp さん、@jwest75674 さんありがとうございます。
プラグインインストールの信頼性警告: CLI およびチャットでの任意の実行可能ソースからのプラグインインストールには、明示的な --force 確認が必要です。Trusted ClawHub、バンドル版、公式カタログ、追跡済み更新フローは摩擦なく動作し続けます。Crestodian のインストールは信頼できるソースに制限されます。(#102197) @jesse-merhi さんありがとうございます。
クラウドワーカー: リモートセッション実行のためのセッション配置、ディスパッチ、ワーカーターンルーティングを追加しました。(#106332)
ペアードノードコーディングエージェント: OpenCode や Pi セッションの検出、および Codex や Claude カタログセッションの継続を、ストリーミング CLI エージェント実行を通じて実現します。(#106941, #106927, #105833)
カタログセッション: 対象となるカタログセッションを、コントロール UI サイドバーから直接作成できるようになりました。(#105810) @fuller-stack-dev さんありがとうございます。
管理されたワークツリー: 「設定」画面から、削除制限の件数と総サイズを設定できます。(#106224)
クロン履歴: 実行予定タスクの履歴をタスクリッジから提供します。(#106392)
コーディングエージェントメモリ: Codex と Claude Code のメモリ情報をコントロール UI にインポートしました。(#106406)
MCP アイソレーション: MCP サーバー接続を、要求元のセッションにスコープ制限をかけました。(#106359) @obviyus さんありがとうございます。
Discord 音声: ボイスチャンネルの参加者変更時にエージェントへ通知します。(#107004)
Codex の使用状況: アプリサーバーの使用量ウィンドウ alongside に、サインインしたアカウントのメールアドレスを表示します。(#106500)
スキルワークショップ: 過去のセッション履歴をスキャンし、慎重にレビュー可能なスキルアイデアを探します。(#106766)
タスクプレビュー: 実行中のタスクステータス行から最新のタスクを表示します。(#107297)
セッション変更: コントロール UI セッションで、アクティブなブランチとローカルの変更ファイル状態を表示します。(#106835)
チャンネル進行状況: 長時間稼働する作業には進行状況のドラフトを予約し、ステータス見出しにはモデル自身のプレアンブルを使用します。(#106026)
Codex CLI: バンドルされたプラグインを Codex CLI 0.144.4 にアップグレードしました。
修正点
- JSON 形式での出力を必須とします。
translationフィールドのみを含めてください。 - 他のフィールドは一切追加しないでください。余計な項目を追加しようとして本文がトークン上限に達し、出力が途中で切れてしまう事故を防ぐためです。
外部監視プロセスの再起動健全性: 置換ゲートウェイのロックとリスナー PID が一致する場合のみ、デバイス識別ポリシーに基づく閉じ処理を受け付けるようにしました。これにより、正常なハンドオフ完了後に OCM 管理による再起動がタイムアウトする不具合を防ぎます。@shakkernerd さんありがとうございます。
ACPX クリーンアッププロセスの点検: ホストのプロセステーブル読み取りに上限を設けました。これにより、ps コマンドが停止してもゲートウェイの起動やセッションクリーンアップが止まることなく、失敗時のクローズド所有権チェックは維持されます。@Alix-007 さんありがとうございます。
Cron ライフサイクル競合のリトライ: 実行フェーズでのリトライ判断を、スケジュール済み・手動・起動復旧のすべてのケースで保持するようにしました。これにより、実行後の主張競合によって完了したメッセージやツールが再プレイされるのを防ぎます。#108428 を修正。@yetval さんありがとうございます。
Discord ゲートウェイメタデータの期限: 既存の検索期限を DNS およびプロキシ事前チェック、リクエストヘッダー、レスポンスボディ全体に引き継ぐようにしました。これにより、起動が停止した場合でもゲートウェイは正常に中止されます。#104580。@hugenshen さんありがとうございます。
コントロール UI クラウドセッションの推論: 「新しいセッション」モデルピッカーで推論レベルを公開し、クラウド送信前に選択されたレベルを保存するようにしました。
iOS 新規インストールセットアップ: キーチェーンクリーンアップの前に使用済みのセットアップ認証情報を原子操作で隠蔽(redact)しました。これにより、遅延された項目削除が正常にペアリングされたデバイスの切断を引き起こすのを防ぎます。#107591 を修正。@dagmarjeeves-lab さんと @vincentkoc さんありがとうございます。
Tlon SSE 接続クリーンアップ: HTTP レスポンスの失敗やストリームオープンの拒否後、開封期限を解除しました。これにより、再接続試行が古いタイマーを残すのを防ぎます。#104585。@hugenshen さんありがとうございます。
LINE リプライトークンメディア種別: 受信リプライの動画および音声メタデータを尊重し、能動的な送信にも共通のメディアビルダーを共有しました。また、空のメディアのみが配信された場合でも目に見える形でエラーとし、記録しないようにしました。#106515。@edenfunf さんありがとうございます。
Mattermost WebSocket 接続期限: 開封ハンドシェイクに上限を設けました。これにより、停止した TCP ピアがチャンネル起動を無限に止めることがなくなり、タイムアウト後に再接続制御が再開されます。#105553。@hugenshen さんありがとうございます。
キュー待ち TTS リトライ: エンキュー前にローカル送信メディアをキュー所有ストレージへコピーしました。これにより、プロデューサーの一時クリーンアップや再起動復旧時でも音声リプライが生存し、リトライバックオフ中に参照されたアーティファクトを保持します。また、1 日後に未参照のスプールファイルを削除します。#108501 および #108502 を修正。@masatohoshino さんありがとうございます。
Feishu アプリ登録期限: OAuth デバイス登録リクエストをガード付きフェッチ境界を通じて 10 秒に制限しました。これにより、停止したレスポンスヘッダーでセットアップが無限に止まるのを防ぎます。#105549。@hugenshen さんありがとうございます。
LINE コマンド_mentions: メンション除去前に許可されたスラッシュコマンドを検知しました。これにより、インライングループおよびダイレクトメッセージの制御で元の取り込みメタデータが保持されます。#107230。@edenfunf さんありがとうございます。
Feishu ドキュメント画像読み取り: 選択したアカウントのタイムアウトを用いて、リモートドキュメント画像ヘッダーと停止したボディに上限を設けました。また、プラグインの MDAST パイプラインを通じてドキュメント Markdown を解析し、画像やブロックのアライメントを保持します。さらに、空の画像ブロックを作成する前にアップロード入力の失敗を検証して拒否しました。@Alix-007 さんありがとうございます。
ClawHub レジストリ読み取り: 他の一時的なゲートウェイ障害と同様に、HTTP 500 レスポンスを制限付きで再試行するようにしました。これにより、レジストリの孤立したエラーがあってもマルチパッケージリリーススキャンが生存します。
Slack Socket Mode 健全性: auth.test の失敗または構成されたボットトークンが bot_id を持たないユーザーに解決される場合、接続された Socket Mode トランスポートを「劣化」として報告しました。ただし、正常なエンタープライズ組織のインストールは保持されます。@zw-xysk さんありがとうございます。
Synology Chat レスポンス制限: ユーザーリスト応答読み取りに上限を設け、過大なストリームを即座に停止しました。また、NAS がサポートされる範囲を超えた場合でも、古いキャッシュされたアイデンティティは保持されます。@zw-xysk さんありがとうございます。
使用日付範囲: 時系列データのないレガシー転記行を有限セッション範囲から除外しましたが、全期間合計には残しました。また、新しいセマンティクスを提供する前に古い使用キャッシュを再構築しました。#89709 を修正。@TurboTheTurtle さんありがとうございます。
LINE グループ履歴競合: アクティブなメンションターン中に受信した環境グループメッセージを、次のターンで保持するようにしました。ただし、ターン前のスナップショットは正確に一度だけ消費します。#107367。@edenfunf さんありがとうございます。
Mattermost プログレスコマンド詳細: チャンネル設定検証およびバンドルメタデータにおいて、文書化された streaming.preview.commandText および streaming.progress.commandText モードを受け付けるようにしました。@shakkernerd さんありがとうございます。
1Password 認証ハンドオフ: ノンバウンドの保留承認を共有プラグイン状態に保存しました。これにより、ブローカーインスタンス間でのフックおよびツール実行が単一使用となり、失敗時にクローズド処理されます。
コントロール UI チャット転記: セッションやペインからの戻りAcrossで読み込まれた履歴を保持し、自動バックスクロール読み取りに上限を設けました。また、長い転記を仮想化し、隠されたネイティブ実行境界を保持しました。これにより、プリペンデンド、ストリーミング、レスポンシブレイアウトが点滅したりジャンプしたりするのを防ぎます。@shakkernerd さんありがとうございます。
Codex ダイナミックツール結果: 任意のライフサイクルメタデータに共通のツール結果失敗契約を使用しました。これにより、Skill Workshop の成功した結果が失敗した呼び出しとして表示・保存されるのを防ぎます。#107684 を修正。@shakkernerd さんありがとうございます。
Codex /status コンテキスト鮮度: rawResponse/completed を発行する Codex アプリサーバーから、レスポンスごとの正確な使用量を消費するようにしました。正確な使用量が利用できないか省略されている場合、累積 lifetime 合計を再利用せず、コンテキストは「不明」として保持します。#107813。@wuqxuan さんありがとうございます。
ネストされたリソースの無視: スキルおよびリソース発見時に、ネストされた無視ファイル内のスラッシュなしパターンとエスケープされたリテラル感嘆符を尊重しました。@moguangyu5-design さんありがとうございます。
プロキシバイパス優先度: no_proxy の空白小文字値が NO_PROXY を上書きする際、Undici と一貫して処理し、Telegram フォールバック選択に共通のマッチャーを再利用しました。
Tokenjuice 実行圧縮: 圧縮されたミドルウェアメタデータ内に生のコマンド出力を保持しないようにしました。これにより、大規模な成功した圧縮がミドルウェア詳細サイズガードで失敗するのを防ぎます。
エージェント Git パッケージ識別子: ホストリポジトリ解析前に refs を削除し、トラバーサルセグメントを拒否しました。これにより、GitLab ブランチ refs が正規の管理インストールパスに解決されます。@vincentkoc さんありがとうございます。
Tlon カスタム S3 アップロード: ストレージエンドポイントを AWS SDK のネイティブパーサー経由で渡すようにしました。これにより、プレサイン前にカスタム S3 互換アップロードが失敗するのを防ぎます。
Signal アクティブラン制御: 通常のおよび状態保持ターンを正規セッション受付に保持しつつ、アクティブなターン中に許可された停止・ステータス・承認・キュー読み取り制御の応答性を維持しました。また、停止時にすべての保留中のグループ送信レーンをキャンセルします。#107422。@arduano さんありがとうございます。
エージェント認証ストレージロック: proper-lockfile からロックが侵害されたという報告を受けた後、冗長な解放試行を避けつつ、通常の解放失敗を表面化するようにしました。
ペアリング済みノードセッションカタログ: バンドルされた Anthropic および Codex カタログリクエストに対し、コントロール UI 読み取りフローから読み取り専用ノードコマンドを実行する権限を与えました。これにより、リモート Claude/Codex の行とターミナル再開の可用性が復元されます。#107406 を修正。@vincentkoc さんありがとうございます。
サンドボックス再作成確認: Clack キャンセルを「拒否」として扱うようにしました。これにより、Ctrl-C でコンテナ削除が進行するのを防ぎます。
Microsoft Teams HTML テキスト: 引用メッセージおよび Graph フォッチメッセージの両方で HTML5 エンティティを一貫してデコードし、リテラルエスケープされたエンティティテキストは保持しました。
ClawHub プラグイン API 範囲: 各サポートされる比較子を semver に委譲しました。これにより、チルダ、部分ワイルドカード、プレリリースキャレットの境界が正しくなりつつ、OpenClaw のバージョン正規化と既存の制限付き範囲文法は保持されます。#106877。
Web 可読性相対リンク: パーシストされたドキュメントにリクエスト URL を初期化しました。これにより、記事リンクが正しく解決されつつ、プラグインの重複する遅延ローダーファサードが削除されます。#106860。
ブラウザ自動ルーティング: 暗黙的に選択されたブラウザノードが制御ホストに到達できないと報告した場合、Gateway ホストへフォールバックするようにしました。ただし、明示的なノードピンおよび曖昧なアクションの失敗は保持します。
Discord ボイス参加者コンテキスト: ライブ Gateway のボイス状態ロスターを維持し、現在のチャンネル参加者を許可されたボイスエージェントターンに含めました。これにより、エージェントが誰がいるかを回答できるようになります。@vincentkoc さんありがとうございます。
OC Path JSONC 挿入: jsonc-parser を通じてオブジェクトおよび配列の挿入をパッチ適用しました。これにより、コメント、末尾のカンマ、CRLF フォーマットが保持されます。#106847。
Windows winget インストール: マシン PATH の更新が見える前に winget が Node.js をインストールした場合、現在の PowerShell セッション内で継続するようにしました。これにより、「Node.js が見つかりません」という誤ったエラーを回避します。#106862。
コントロール UI リアルタイム Talk フィードバック: すべてのマイクトランスポートに対してブラウザのエコーキャンセレーション、ノイズ抑制、自動ゲイン制御をリクエストしました。また、PCM キャプチャプロセッサをゼロゲains スンクスに接続したまま維持し、ローカルでのマイク入力再生を防ぎます。
エージェントソースリプライ回復: Code Mode を通じて実行されたメッセージ送信に対して、現在のチャット配信証拠を保持しました。これにより、成功したリプライが冗長な再試行を引き起こして配信失敗の診断を誤らせるのを防ぎます。@vincentkoc さんありがとうございます。
ゲートウェイインプロセス再起動: 古い SIGUSR1 再起動状態をクリアし、ランタイム受付を再構築する前に準備されたホストサスペンションを再開しました。これにより、再起動クールダウンや一時停止スケジュールが次のライフサイクルに漏れるのを防ぎます。@vincentkoc さんありがとうございます。
ClickClack 永続メディア配信: メディアリプライを必須の配信経路へルーティングし、所有者スコープのアップロードおよびメッセージノンバを再試行間で再利用しました。また、ソースメディアを再読まずに保存された添付状態を修復し、古い ClickClack サーバーが未知の送信を証明できない場合はクローズド処理します。さらに、チャネルレベルのトークンキャップではなく、選択したプロバイダーとモデルの実行出力予算を使用します。@jjjhenriksen さんと @shakkernerd さんありがとうございます。
Deepgram リアルタイムカスタムエンドポイント: Voice Call ストリーミングベース URL を秘密保護されたエラーで検証し、明示的な ws:// および wss:// エンドポイントを保持しました。また、HTTP スキームを対応する WebSocket トランスポートにマッピングし、専用およびセルフホストデプロイに対応します。#105334。@dwc1997 さん、@vincentkoc さん、@zw-xysk さんありがとうございます。
コントロール UI 新しいセッション再接続: エージェント、ノード、リポジトリブランチ、フォルダーブラウザ状態を再発見し、派生ワークスペースを更新しました。また、未検証デバイスをゲートし、Gateway クライアント置換後に曖昧な再試行をブロックしましたが、型付きタスクと明示的な選択は保持しました。#106372 を修正。@vincentkoc さんありがとうございます。
macOS リモートノード準備: ノード受付時にオペレーター接続を開くのではなく、ノード hello スナップショットからメインセッションキーを取得するようにしました。これにより、リモートトンネル復旧が Computer Use やノード実行をライフサイクル遷移のままにするのを防ぎます。
Claude CLI コンテキスト予算: Anthropic モデルおよび各エージェントの contextTokens 制限を尊重し、有効な制限を Claude Code のネイティブ自動コンパクターへ渡して保存しました。また、OpenClaw セッション状態にも同じ準備済み予算を保存します。#80933 および #93198 を修正。@mushuiyu886 さん、@gorkem2020 さんありがとうございます。
転記読み取り失敗: ストリーミング JSONL セッション読み取りからの権限および I/O 失敗を伝播するようにしました。読めない転記を空として扱うのをやめます。#106412。@zenglingbiao さんありがとうございます。
再起動センティネル診断: SQLite の読み書きおよびレガシーファイルクリーンアップの失敗を報告しつつ、ベストエフォート型の再起動回復動作は保持しました。#106385。@zenglingbiao さんと @wendy-chsy さんありがとうございます。
ネイティブアプリ接続およびリレー信頼性: Android の切断をアクティビティ再作成 across で停止したままに保ち、リモートカメラコマンドは権限プロンプトを開かずに失敗するようにしました。また、機能変更後にモバイルノード登録を更新し、iOS のオンボーディング接続失敗を表面化しました。セッション切り替え時に古い Talk 所有者をキャンセルし、無効な Watch 確認を拒否し、起動中に受信した Watch イベントを保持しました。さらに、古いエージェント概要リクエストが新しい Gateway 状態を置き換えるのを防ぎます。@vincentkoc さんありがとうございます。
ゲートウェイソースウォッチ: tmux ウォッチャー開始前に、インストールされたサービスから設定済みポートを手渡すようにしました。また、失敗したペインはアタッチ/キャプチャ用に保持し、明示的な代替ポートウォッチを管理される Gateway と並列で維持します。@vincentkoc さんありがとうございます。
Claude CLI 最大ターン診断: OpenClaw および Claude セッションコンテキストとともターミナルの最大ターン結果を保持しました。また、ツールアクションが既に実行された可能性がある場合や、副作用を持つターンの不安全な認証プロファイルまたはモデル再プレイを行う場合に警告し、停止するようにしました。#94130。@zhangguiping-xydt さん、@tdrose01 さんありがとうございます。
プロバイダーネットワークリトライ: 一時的な接続エラーに対するプロバイダー読み取り/ポーリング/ダウンロードおよびエージェント待機回復を整合させました。また、プロバイダーの ENOTFOUND 失敗を制限付きで再試行しますが、Gateway の ENOTFOUND および非冪等作成操作は即座に失敗するようにしました。#101496。@xialonglee さんありがとうございます。
セッションリトライ分類: 識別子またはペイロード詳細が単に 429/5xx の数字シーケンスを含む永続的なプロバイダーエラーについて、完全なコンテキストの再送信を停止しました。また、リトライパス間で制限付きレート制限ウィンドウ解析を共有しました。#105258。@destire-mio さん、@yetval さんありがとうございます。
LINE ディレクティブテンプレート: 必須フィールドが空白またはアクションのラベルがない場合、確認およびボタンを抑制しました。ただし、有効なタイトルなしボタンと周囲のリプライテキストは保持します。#105520。@edenfunf さんありがとうございます。
SQLite メンテナンススキーマ検証: コンパクト化前に、現在のバージョングローバルおよびエージェントデータベースから、欠落または逸脱した正規テーブル、制約、インデックス、トリガー、またはテーブルオプションを含むものを拒否しました。ただし、サポートされる追加マイグレーションレイアウトは受け入れます。
Matrix 起動診断: バウンドされた stdout および stderr タイルに完全な UTF-8 コードポイントを保持しました。これにより、暗号化依存関係の失敗が保持境界で置換文字として表示されるのを防ぎます。#105475。@qingminlong さんありがとうございます。
iOS Watch リレーコマンド: ペアリングされた iPhone ノードがデフォルト Gateway ポリシーを通じて watch.status および watch.notify を広告・実行できるようにしました。ただし、直接の watchOS ノードの固定最小コマンド表面は保持します。@vincentkoc さんありがとうございます。
Swabble ステータス設定: サービスステータス読み取り時にデフォルト設定を黙って使用せず、グローバル --config パスを尊重するようにしました。
ClawHub リトライタイミング: 分数の遅延秒およびカレンダー正規化された無効な Retry-After 日付を拒否しました。これにより、ランタイムおよびリリース読み取りが制限付きフォールバックスケジュールのまま維持されます。#105479。@qingminlong さんありがとうございます。
Discord スレッドアーカイブデフォルト: 作成されたスレッドに強制 60 分ではなく、各親チャンネルの構成済み自動アーカイブ期間を引き継ぐようにしました。ただし、明示的なオーバーライドは保持します。#103413。@wings1029 さんありがとうございます。
インストール済みプラグイン読み込み: ネイティブモジュールフォールバックが jiti の変換パスを使用するように変更し、同じ同期 ESM ロードを再試行しないようにしました。これにより、公式プラグインが SDK 契約モジュールをインポートする際の Node 24 起動競合を防ぎます。@vincentkoc さんありがとうございます。
QA プロファイルチャンネル実行: 混在した Crabline チャンネルシナリオを 1 つの集約ホストスイートに分割しました。これにより、分類法に基づくプロファイルコマンドおよび証拠ワークフローが実行前に中止されるのを防ぎます。
プラグイン SDK API ベースライン: すべての公開エントリーポイントを網羅し、ソース行の変更なしで完全な宣言形状を保持しました。また、変更ファイル検証からベースラインおよびエクスポート表面ガードを実行しました。@vincentkoc さん、@zw-xysk さんありがとうございます。
SQLite ターミナルセッション回復: エージェントデータベースに物理転記変更時間を追跡するようにしました。これにより、転記書き込みがレジストリ更新より長く生存する場合、終了またはタイムアウトしたメインセッションを回転させます。ただし、ドクターインポート中はレガシー転記 mtimes は保持します。@vincentkoc さんありがとうございます。
ゲートウェイチャット型チェック: 廃止された集約型モジュール削除後、チャクトイベントタイプを所有するプロトコルスキーマからインポートしました。これにより、プロジェクト全体の型チェックが復元されます。@vincentkoc さんありがとうございます。
パッケージ化 Crabbox コマンド: 公開ラッパーでインポートされるリース鮮度ヘルパーを含めました。これにより、npm インストールで crabbox:* コマンドが ERR_MODULE_NOT_FOUND で失敗するのを防ぎます。@vincentkoc さんありがとうございます。
プラグインセッションカタログ: 不明なカタログフィルターを拒否し、カタログをプラグイン機能として報告しました。また、SDK 登録キャプチャに保持するようにしました。これにより、空の結果を黙って返したり、カタログ専用プラグインを機能なしと分類するのを防ぎます。@vincentkoc さんありがとうございます。
ゲートウェイサービス監査: ポックスシェル -c ラッパーをゲートサブコマンドチェックに対して不透明として扱いました。これにより、内部コマンドやポートを解析せずに、シェルラップされた macOS LaunchAgents で誤ってコマンドが見つからない警告が出るのを防ぎます。#81751 および #81778 を修正。@liaoandi さんありがとうございます。
アウトバウンドチャンネル起動: 同じチャンネル、設定、レジストリ生成に対する繰り返し失敗するプラグインアクティベーションを抑制しました。ただし、設定またはレジストリの再読み込み後は再試行します。#100377。@xialonglee さんありがとうございます。
OpenAI Realtime クライアントシークレット期限: 音声および文字起こしシークレットの取得をガード付きフェッチ境界を通じて 30 秒に制限しました。ただし、認証と制限付きレスポンス解析は保持します。#102860。@Alix-007 さん、@Leon-SK668 さんありがとうございます。
ゲートウェイクライアントウォッチドッグ: 無制限および混合保留リクエストに対してトランスポート停止検知を継続して有効にしました。これにより、デッドソケットは保留リクエストを拒否し、再接続し、拒否されたリクエストを再プレイしません。#103407。@NianJiuZst さんありがとうございます。
iOS シェアエクステンション下書き: スキャフォールドのようなプレフィックスで始まる正当な共有テキストは保持し、正確なレガシースキャフォールド行のみを削除しました。また、スクリプトのような文章を URL とみなすのを避け、ホストミラーされたコンテンツの重複を排除しました。#103453。@lin-hongkuan さん、@harjothkhara さんありがとうございます。
Telegram 推論プレビュー: 遅延削除を通じて分割された推論プレビューの位置を再配置しました。これにより、以前のプレビューメッセージが古くなったまま残るのを防ぎつつ、クライアントのスクロール位置は保持されます。#97828。@ly-wang19 さん、@kyle20026 さんありがとうございます。
Feishu ネイティブカードスレッド: 空白リプライターゲットを正規化して一度処理し、共有リプレイモードをカードおよびメディアパーツで再利用しました。これにより、ネイティブカードのトピックリプライがスレッド内に留まります。#102804。@sunlit-deng さんありがとうございます。
QQBot トークンリクエスト: 共有された 30 秒のガード付きフェッチ期限を通じてトークン取得を制限しました。これにより、停止したシングルフライト呼び出しは同時に失敗し、クリーンアップされ、再試行できるようになります。
(#102897) @maweibin さん、ありがとうございます。
- Canvas A2UI の検証強化: CLI、エージェントツール、最終ノード呼び出しの境界において、不正または非対応の JSONL を拒否します。ただし、ネイティブ v0.8 のディスパッチ機能は維持されます。(#103713)@qingminglong さん、ありがとうございます。
- Twilio RCS 着信ルーティング: 送信者の一致確認やセッション処理が正常に動作するよう、署名付き Webhook の検証完了後にのみ RCS コンシューマーのアドレスを正規化します。これにより、発信 RCS のセマンティクスを変更することなく機能します。(#102373)@clawSean さん、ありがとうございます。
- ClickClack 出力のサニタイズ: 送信側境界で内部ツールや XML スケフォールディングを除去し、スケフォールディングのみによる送信を抑制します。ただし、オプションのモダン配信 ID は保持されます。(#103142)@masatohoshino さん、@vincentkoc さん、@zw-xysk さん、ありがとうございます。
- エージェントコアの切り捨て: ヘッド側での切り上げ処理で負の行数やバイト上限が指定された場合でも、空出力によるクラッシュを回避します。(#103425)@qingminglong さん、ありがとうございます。
- Windows ノード解決: 敵対的な
PATH値の下で、大文字小文字を区別しないnode.exeエントリを解決する際、現在の実行ファイルを保持します。(#103907)@soldforaloss さん、@vincentkoc さん、ありがとうございます。
- Codex ランタイムの切り替え:
codex/*およびopenai/*モデルルートの両方でバンドルされた Codex ランタイムを受け入れます。ただし、非対応のプロバイダーとランタイムの組み合わせは拒否し続けます。(#103762)
- エージェント中止後のクリーンアップ: 端末のクリーンアップ処理とプロンプトロックの再取得を直列化することで、キャンセルされた埋め込み実行がセッションロックで最大 60 秒にわたって競合しないようにします。
- Chutes OAuth の期限管理: トークン交換、プロフィール参照、リフレッシュ要求に期限を設定し、オプションのユーザー情報補完が停止した場合でも発行済みのトークンを保持します。(#102026)@Alix-007 さん、ありがとうございます。
- コントロール UI ワークスペースのアバター: 検証済みアバターファイルをブートストラップとアイデンティティレスポンスに埋め込むことで、認証不要なアバタールートを要求せずにパーソナルカード画像をレンダリングできるようにします。ただし、設定された絵文字の優先順位は維持されます。(#102892, #97602)@LZY3538 さん、@mtuwei さん、ありがとうございます。
- Exec セーフバインのフラグ: デフォルトの stdin のみフィルタに対して、カーテッドな読み取り専用ブール値フラグを自動承認します。ただし、不明なフラグ、末尾の追跡・再試行モード、ファイル演算子、カスタムプロファイルは失敗時にクローズ(拒否)されます。(#88953)@yetval さん、ありがとうございます。
- iOS セッションの変更: リネーム、アーカイブ、ピン留め、削除、フォークの要求を、選択されたエージェントにスコープを限定します。フォークされたセッションでは親エージェントを保持し、マルチエージェントチャット操作が誤ったエージェントの下でセッションを変更したり作成したりしないようにします。(#103366, #103415)@lin-hongkuan さん、@harjothkhara さん、ありがとうございます。
- Swift プロトコルの初期化子: スキーマのオプションとして生成された初期化子のすべてのパラメータを
nilにデフォルト設定します。これにより、プロトコルフィールドの追加が SDK の構築呼び出し-site を破綻させることがなくなります。
- OpenCode Go MiMo カタログ: エージェントリクエストを拒否する非推奨のエイリアス
mimo-v2-omniとmimo-v2-proの公開を停止します。アクティブな MiMo V2.5 ルートに対するリリース検証は維持されます。(#103311, #103329)@krissding さん、ありがとうございます。
- 監査時間のフィルター:
openclaw audit --afterおよび--beforeに対して、ありえないカレンダー日付を拒否します。意図しない期間に巻き込まれるのを防ぎつつ、タイムゾーン非依存のタイムスタンプセマンティクスは維持されます。(#103433)@qingminglong さん、ありがとうございます。
- OpenAI 互換ストリーミングツール呼び出し: SSE
data: [DONE]で終了するがfinish_reasonを含まないストリームから、完全なネイティブツール呼び出しを実行します。ただし、転送の EOF や可視テキストの場合は失敗時にクローズ(拒否)されます。(#98124, #97994)@SunnyShu0925 さん、@wszhhx さん、ありがとうございます。
- xAI プロバイダーエイリアス: モデルが shipped
x-aiプロバイダーエイリアスを使用する場合、有効な思考リクエストをminimalに制限するのではなく、Grok 4.3 および Grok 4.5 の思考プロファイル、高速モデルルーティング、暗号化された推論再生を保持します。(#103315)
- Doctor ステート分離:
OPENCLAW_STATE_DIRが別の場所を指している場合、自動更新や Gateway ウォッチ修復がデフォルトホームの実行やプラグインバインド承認をインポート・アーカイブするのを防ぎます。CLI の事前チェック通知は暗黙的に表示のみとし、クロスステートインポートは直接のオペレーターによる Doctor 実行に限定します。(#103247, #103317)@vincentkoc さん、ありがとうございます。
- Doctor クリーンステートのガイダンス: 設定変更がないクリーン実行後、
openclaw doctor --fixを提案するのを停止します。ただし、ターゲットを絞った修復のヒントは維持されます。(#103233)@kewang-pika さん、@nonplace さん、ありがとうございます。
- Google ミュージック生成: 契約上必要なオーディオを欠落させた Lyria のレスポンスがブロックされていない場合、1 回再試行します。ただし、プロンプトブロックや端末での生成停止は再試行不可のままです。(#103318)
- OpenCode Zen モデルカタログ: Claude Sonnet 5、Grok 4.5、Hy3 Free、Kimi K2.7 Code、MiniMax M3 のプロバイダー所有の静的シードを更新します。検証済みのルーティング、価格、制限、入力機能を備え、廃止された無料ティアの行を削除し、認証不要なモデルリストからも同じカタログを公開します。(#103184)
- マネージドブラウザ起動: 非同期 Chrome のブートストラップやランタイム起動時の失敗をブラウザエラーとして表示しますが、Gateway は稼働状態を維持します。また、ライフサイクルの後の失敗に対してもプロセスエラーハンドリングを保持します。@vincentkoc さん、ありがとうございます。
- ブラウザノードプロキシダウンロード: すべてのアクション生成されたダウンロードを Gateway メディアストアへ転送し、ファイルあたり 10 MiB、合計 16 MiB の転送予算に合わせます。ページ制御の結果データを横断することなく、複数のダウンロードパスを Gateway ローカルファイルとして書き換えます。
- Gateway 起動マイグレーション: 起動中に選択された設定が変更された場合、終了前に共有マイグレーションリースを解放します。これにより、5 分間のリース期限まで待機して準備状態をブロックするのではなく、即座に再試行が可能になります。(#103145)
- Apple タイムアウト回復: プラットフォーム側がキャンセルを無視している場合でも、共有操作の期限や呼び出し元のキャンセルから素早く復帰します。ただし、遅れた Gateway のハンドシェイクは分離し、ロケーションと権限の待機者をクリーンアップします。(#103066)@NianJiuZst さん、ありがとうございます。
- Claude CLI ウォームセッション: Claude がネイティブトランスクリプトを出力しない場合でも、マネージド stdio の連続性を保持します。正確なライブ子プロセスが消滅または変更した場合のみ、制限付きの OpenClaw 履歴にフォールバックし、ステートレス実行が CLI バインディングを永続化しないようにします。(#96841)@bradreaves さん、ありがとうございます。
- CLI プラグイン一覧: レガシーな入力がない場合、状態マイグレーションのランタイム読み込みをスキップします。これによりパッケージされたコールドスタート時のメモリ使用量を削減しつつ、レガシープラグインインデックスや設定済みセッションストアに対するマイグレーションは維持されます。
- Unicode 対応の制限付きテキスト: コントロール UI、CLI、Gateway、プラグイン、QA、メモリ、Android などのすべての表面において、プレビュー、プロンプト、診断、ラベル、セッションキー、リンクメタデータ、アイデンティティ値を短縮する際、完全な UTF-16 サロゲートペアを保持します。(#102625, #102626, #102627, #102816, #102823, #102833, #102877, #102949, #102963, #102969, #102988, #103010, #103034, #103210, #103341, #103487, #103543, #103580, #103646)@zhangguiping-xydt さん、@wings1029 さん、@wangyan2026 さん、@Pandah97 さん、@MoerAI さん、@SunnyShu0925 さん、@zhangqueping さん、@zw-xysk さん、@cxbAsDev さん、@lzyyzznl さん、@coder-master-0915 さん、@LeonidasLux さん、@mushuiyu886 さん、@ly85206559 さん、@Simon-XYDT さん、@lsr911 さん、@vincentkoc さん、@chengzhichao-xydt さん、@wangmiao0668000666 さん、ありがとうございます。
- Cron リストテーブル: CJK(中国語・日本語・韓国語)、絵文字、結合記号、端末制御入力による整列や出力の破損を防ぐため、端末表示幅に応じてセルをサニタイズしサイズ調整します。(#103616)@mushuiyu886 さん、ありがとうございます。
- CLI モデルテーブル: エンコードされた端末幅に基づいてモデルリストのセルをサニタイズ、切り詰め、パディングすることで、絵文字や CJK、その他の広域グラフェームが列の整列を保つようにします。(#102819)@Kevin23-design さん、@vincentkoc さん、ありがとうございます。
- スキルプロンプトの圧縮: 短縮された UTF-16 対応の説明にプロンプト予算の残りを割り当てる前に、含まれるすべてのスキルのアイデンティティを保持します。トリガーガイダンスは維持しつつ、ハードリミットを超えないようにします。(#88426)@abel-zer0 さん、@vincentkoc さん、@chengzhichao-xydt さん、@wangmiao0668000666 さん、@Pandah97 さん、ありがとうございます。
- チャネル Markdown コードテーブル: CJK、絵文字、混合幅のセルが共有 Telegram および Discord 出力で整列を保つよう、列をレンダリング表示幅に合わせてサイズ調整します。(#55596, #55512)@sparkyrider さん、@zjy282 さん、ありがとうございます。
- QQ Bot 承認プレビュー: デスクトップ QQ のレビューで可読性を保ちつつコマンド内容を変更しないよう、長いサニタイズ済みコマンドとメタデータをグラフェーム境界で折り返し、可視的な継続マーカーと安全なフェンスを追加します。(#102119, #101979)@Bartok9 さん、@xuzhi5858 さん、ありがとうございます。
- Codex コンピュータ制御: 固定長の座標ペアを同型配列スキーマとして公開します。これにより、Codex アプリサーバーは
itemsがタプル値であるために拒否されることなく、computerツールでスレッドを開始できるようになります。
- Google Chat リクエスト期限: コントロール呼び出しを 30 秒に制限し、メディア転送にはサイズに応じた総予算と、個別の 30 秒間の停止ボディガードを設定します。これにより、大規模な添付ファイルアップロードを壊すことなく、Chat API の応答待ちを防ぎます。(#102227)@hugenshen さん、ありがとうございます。
- Google Gemini プレフィックス付きモデル ID: マルチモーダル関数レスポンス動作の選択時に
google/gemini-*およびmodels/gemini-*を認識します。これにより、Gemini 2 の画像フォールバックを維持しつつ、Gemini 3 のインライン画像応答が後退しないようにします。(#102382)@LiLan0125 さん、@yetval さん、ありがとうございます。
- 生成されたプロバイダーモデルカタログ: MiniMax および NVIDIA のカタログ行は、オーディオまたはビデオメタデータを謳っている場合も保持します。ただし、ランタイムモデルの入力はテキスト/画像に投影され、設定済みマルチモーダルプライマリがドロップされてフォールバックするのを防ぎます。
(#97858, #97048) @ly-wang19 さん、@zackchiutw さんに感謝します。
- DeepSeek カタログメタデータの更新: V4 Flash と Pro の価格設定を、現在のキャッシュヒット・ミス率および出力レートに合わせます。また、古いオンボーディングフローで記述された正確なカタログメタデータを刷新し、レガシーな
deepseek-chatおよびdeepseek-reasoner互換名が 7 月 24 日に廃止されることを明記します。(#103192)
- CLI の音声トランスクリプトファイル: Whisper や Parakeet から推測されたテキストファイルを権威ある情報として扱います。これにより、空または欠落した出力によって進捗やステータスが標準出力(stdout)としてユーザーの発話と誤認されるのを防ぎます。(#87393, #87384)@kesslerio さんに感謝します。
- Node 24 におけるブラウザ操作: ブラウザのリクエストキャンセルを、Node 24.16 以降の早期に破棄されたボディストリームシグナルではなく、クライアント側とレスポンスの存続期間に紐付けます。これにより、JSON パース完了後に正当な POST 操作が失敗するのを防ぎます。@obviyus さん、@vincentkoc さんに感謝します。
- Android のハードウェアキーボードでのチャット: 物理キーボードでは未修正の Enter キーで送信し、Shift+Enter やその他の修飾付き Enter キーは複数行入力として維持します。(#101239)@3ninyt3nin-creator さんに感謝します。
- Codex が生成したネイティブサブエージェント: 親アプリサーバーのサブスクリプションと共有クライアントを、生成されたネイティブサブエージェントの完了通知が処理されるまで維持します。これにより、目覚め信号の消失やワンショットクリーンアップのリークを防ぎます。
- コントロール UI のセッション作成: 他のセッションを選択した後でも、新しく作成されたセッションは安定したサイドバーの最前面に配置されます。@shakkernerd さんに感謝します。
- FTS(全文検索)専用メモリの起動:
memorySearch.providerが明示的にnoneに設定されている場合、プラグイン機能の検出をスキップし、不要なコールドスタートスキャンを防ぎます。
- iOS の埋め込みターミナル: ネイティブ Gateway 認証が接続している間は Web UI のログイン画面を表示せず、ターミナル専用のコントロールサーフェースを直接開きます。
- ソースビルドの移植性: tsdown 設定を自己完結型に保ちます。これにより、
unrunの一時モジュールディレクトリからtsdownパッケージを解決する必要がないため、ビルドが依存関係に縛られません。@vincentkoc さんに感謝します。
- ブラウザタブの採用: 新しい MCP、Playwright、または CDP ターゲットが最終的な安全性検証に失敗した場合、作成後に中止された場合、再発見できない場合に、以前の暗黙的タブと安定したエイリアスを維持します。タブ作成前にラベルを検証し、管理対象のクリーンアップは採用済みターゲットに限定されます。(#105301)@hugenshen さんに感謝します。
- Mattermost ブロックストリーミング: ドラフトプレビューモードでは完全で重複しないテキストとツールブロックを維持し、プレビューストリーミングが無効化されている場合は通常のブロックストリーミングに従います。(#87449)@yetval さん、@Senseonics-AI さんに感謝します。
- iOS 開発用アプリの識別: 開発用アプリは「OpenClaw」としてラベル付けし、リリースビルドと区別するために独自のデバッグアイコンを使用します。
- Android のチャット復元:再接続やシーケンスギャップ履歴のスナップショットが追いつく間、楽観的なユーザーメッセージとローカル所有のランを維持します。これにより、送信済みメッセージが消えたり、古いランが所有権を取得したりするのを防ぎます。(#100197)
- iOS の音声起動(Voice Wake)クリーンアップ: 無効な Voice Wake を無効化している間にマイクオーディオパイプラインを初期化しないようにします。これにより、シミュレータの起動中止や不要なオーディオセットアップを防ぎます。
- エージェント停止の復元: テardown(終了処理)後に遅れて破棄されたプロンプトが、孤児化したセッションロックを再取得するのを防ぎます。これにより
/stopコマンド実行後も会話を次のターンにすぐに準備できます。
- ローカル Gateway CLI 認証: ループバック CLI トークン/パスワード呼び出しを永続的なデバイススコープから外します。これにより、読み取りプローブが古いペアリング基準のせいで後続の書き込みや管理コマンドをブロックするのを防ぎます。(#95997)@vincentkoc さんに感謝します。
- MCP スキーマ診断: draft-2020-12 コンパイラの失敗を外部 MCP スキーマに起因するものとして扱います。これにより、不正なパターンが実行可能なセットアップエラーとして報告されます。@vincentkoc さんに感謝します。
- Amazon Bedrock コントロールプレーンの期限: モデルの検出とアプリケーション推論プロファイルの参照を制限し、呼び出し元のキャンセルを維持します。また、各リクエストパス終了後に短命な SDK クライアントを閉じます。@Alix-007 さん、@vincentkoc さんに感謝します。
- 返信事前配信復元: 各事前配信コールバックに所有者が上書き可能な期限を設定し、フリーズしたプラグイン処理の後にシリアライズされた返信レーンを解放します。また、トランスポートが一度も開始されていない場合にのみ、永続的な最終配信再試行状態を維持します。(#104256)@NianJiuZst さん、@BenjaminBrossi さんに感謝します。
- Signal ネイティブ引用返信: エージェント、明示的、永続的、チャンク化された送信のいずれにおいても、アクティブな受信メッセージをネイティブ引用として維持し、返信モードポリシーは Signal プラグイン内に保持します。(#105347)@jesse-merhi さん、@vincentkoc さんに感謝します。
- メディアストア遠隔ダウンロード: レスポンスヘッダー待機と停止したボディを制限し、放棄されたリダイレクトやエラーレスポンスを閉じます。また、不完全な一時ファイルを削除することで、フリーズしたソースが呼び出し元をロックするのを防ぎます。(#104624)@hugenshen さんに感謝します。
- Cron llama.cpp ツールスキーマ: gateway およびランタイムでの非空白検証を維持しつつ、モデル側の cron 宣言スキーマを llama.cpp と互換性のある状態に保ちます。#107449 を修正。(#108360)@lee-xydt さん、@Patt92 さんに感謝します。
- ターミナルセッション: 初期のキー入力を維持し、ペアリングされたノードでのターミナル操作を有効化し、ペアリングされたノードのカタログ読み取りを許可します。また、古いコントロール UI 接続からの復元や、大量出力下でも低速クライアントをアタッチしたままに保ちます。(#107214, #107361, #107410, #107419, #107348)@vincentkoc さん、@zw-xysk さんに感謝します。
- コントロール UI 設定: 検証された編集を自動保存し、自動保存のゲートを復元し、未適用のリスタート状態を表示します。また、通常のコンテンツスクロールと選択動作を維持します。(#107458, #107477, #107577, #107349)
- Signal 復元: ストールしたコンテナハンドシェイク後に再接続し、再起動中の重複するデーモンを防ぎます。また、電話番号正規化中にユーザー名ターゲットを維持します。(#107386, #107409, #107365)@hugenshen さん、@ZHOUKAILIAN さん、@UberKitten さん、@ly-wang19 さんに感謝します。
- 権限の境界: ペアリングされたノードディレクトリの閲覧にはオペレーター管理者権限を要求し、移行設定マージにおけるプロトタイプ汚染を防ぎます。(#106004, #106116)@yangxiansheng さん、@joshavant さん、@yetval さん、@ruel225 さんに感謝します。
- 会話のアイデンティティ: グループターン全体で話者属性を保持し、不正な Discord ギルド返信ツール呼び出しを減らします。(#107025, #107474)@lonexreb さんに感謝します。
- プロバイダー設定: OpenRouter の OAuth 拒否エラーを表示し、認証エイリアス下に保存された資格情報を検索します。また、未解決の API キープロバイダーは修復可能として表示したままにします。(#105448, #106736, #106754)@VectorPeak さん、@altaywtf さんに感謝します。
- Claude と Codex セッション: Claude のターンをネイティブバックグラウンド処理のために開いたままにし、ライブ更新後の Codex シャットダウン警告を回避します。また、Codex オンボーディングのログインハンドオフを完了し、完了したフックリレーを廃止します。(#106347, #106418, #107174, #106899)@obviyus さん、@fuller-stack-dev さん、@bek91 さんに感謝します。
- Apple アプリ: iPhone と Watch クライアントをプロトコル v3 Gateway に接続し、不完全な添付ファイル共有を拒否します。また、iOS リリースアーカイブで固定された Swift ツールチェーンに従います。(#106294, #106513, #107188)@jincheng-xydt さん、@harjothkhara さん、@joshavant さんに感謝します。
- メモリの信頼性: QMD 出力の分割時にも UTF-8 を維持し、レガシー移行中は正規キャッシュ行を保持します。また、先頭ゼロ付きの JSON コンテンツ長も受け入れます。(#107263, #107243, #105916)@wahaha1223 さん、@felirami さん、@Tony-ooo さん、@qingminlong さん、@vincentkoc さん、@zw-xysk さんに感謝します。
- スキルとワークショップ: グローバルにインストールされた ClawHub スキルを追跡し、孤児化した使用行をクリーンアップします。検証エラーを表示し、ワークショップ承認のデフォルトを自動処理に変更します。(#106479, #107144, #107143, #107690)@ml12580 さん、@mnowrot さん、@SunnyShu0925 さん、@shakkernerd さんに感謝します。
- 制限付きネットワーク呼び出し: Google チャット認証、Slack ディレクトリおよび読み取りモードの呼び出し、Twitch ユーザー検索にタイムアウトを設定し、フリーズしないようにします。(#106178, #106643, #107103, #105883, #107360)@QiuYuang さん、@Monkey-wusky さん、@maweibin さん、@zw-xysk さん、@Alix-007 さんに感謝します。
- チャンネル配信: スカラーストリーミングがフォールバックした場合に警告し、選択されたモデルのランタイム予算を使用して ClickClack のメディア配信を永続化します。(#106796, #105775)@jjjhenriksen さんに感謝します。
- プラグイン管理: 標準的な ClawHub API コンパレータに従い、コントロール UI 管理者がインストール済みプラグインを有効化できるようにします。(#106889, #106318)
- ランタイム設定: 解決済みのキャッシュ保持値を維持し、明示的な環境変数の削除を適用します。また、ディスパッチされた Workboard カードが実行状態で残らないようにします。(#106069, #107258, #107271)@krissding さん、@jalfaro2876 さん、@pgondhi987 さんに感謝します。
- 入力と出力の安全性: 機密性の高い移行ターミナル出力をマスクし、管理対象の git パッケージ ID を正規化します。また、圧縮された Tokenjuice メタデータに生のコマンド出力を保持しないようにします。(#106806, #107637, #107705)@yetval さんに感謝します。
- ネットワークとリソースのマッチング: 正規の NO_PROXY 動作を共有し、ネストされた無視パターンおよびエスケープされた文字列の感嘆符(!)に従います。(#107711, #106258)@moguangyu5-design さんに感謝します。
- Markdown フロントマター: YAML ノードを直接表現できない場合に、強制されたフォールバック値を維持します。
コントリビューション記録の完全版
すべてのコントリビューションの詳細は、タグ固定された CHANGELOG.md で確認できます。
リリース検証情報
- npm パッケージ:https://www.npmjs.com/package/openclaw/v/2026.7.2-beta.2
- レジストリ tarball:https://registry.npmjs.org/openclaw/-/openclaw-2026.7.2-beta.2.tgz
- 整合性チェック(integrity):
sha512-Pjp6VcPQtGF2Q2d6faFOJ75IGpTt3Xucuxclz//n4eP89Wds5wMhZzGf0Oiqd1uSncm5LgCcZzm31Igp6lOR0w== - リリース SHA:
54d98a47251d3216443f9446830dec1a0aaddc43 - 完全なリリース CI レポート:https://github.com/openclaw/releases/blob/main/evidence/2026.7.2-beta.2/release-evidence.md
- リリース公開ログ:https://github.com/openclaw/openclaw/actions/runs/29566151276
- npm 事前チェック(preflight): https://github.com/openclaw/openclaw/actions/runs/29548071521
- 完全なリリース検証:https://github.com/openclaw/openclaw/actions/runs/29546250316
- プラグイン npm 公開ログ:https://github.com/openclaw/openclaw/actions/runs/29566735890
- プラグイン ClawHub 公開:別プロセスで実行済み。本検証では待機していません(非同期): https://github.com/openclaw/openclaw/actions/runs/29566738448
- プラグイン ClawHub 初期化(bootstrap): 別プロセスで実行済み。本検証では待機していません(非同期): https://github.com/openclaw/openclaw/actions/runs/29566741033
- npm Telegram ベータ版 E2E テスト:https://github.com/openclaw/openclaw/actions/runs/29553869058
原文を表示
2026.7.2
Highlights
- Remote coding sessions: run Control UI sessions on cloud workers, open Codex and Claude catalog sessions in terminals on their owning hosts, and resume OpenCode and Pi sessions directly in a terminal. (#107670, #107086, #107200)
- Native automation and nodes: bring Automations parity to mobile, add foreground Voice Wake on Android, and expose camera, location, and notification capabilities from headless Linux nodes. (#106355, #107081, #107193)
- Safer channel operation: prevent Telegram durable-ingress loss after restarts, keep Signal stop and approval controls responsive during active turns, and stop channel allowlists from granting owner access. (#107288, #107422, #107403) Thanks @obviyus, @arduano, and @yetval.
- Guided Control UI setup: configure model providers from Settings, onboard channels through a guided setup page, and choose images and models while creating sessions. (#106490, #106469, #107358) Thanks @alexandre-leng and @fuller-stack-dev.
- Gateway and session recovery: prevent restart admission from wedging the Gateway, recover reply sessions after finalization stalls, and keep one-shot cron jobs enabled through lifecycle claim races. (#107339, #106792, #107236) Thanks @obviyus, @joshavant, @charliemeyer2000, and @SL4N.
- Install and packaging: add Linux deb and AppImage bundles with Gateway guidance, publish them from stable main-based releases, and let Windows installs continue immediately after winget adds Node.js. (#106533, #106891, #106862)
Changes
- External gateway supervision: add
OPENCLAW_SUPERVISOR_MODE=externalfor lifecycle owners such as OCM, preserving verified restart and deferral behavior without exposing native service authority, blocking native service mutation and self-update, and providing a versioned atomic restart-handoff consume contract. Thanks @shakkernerd. - ClickClack guided setup: configure ClickClack from
openclaw onboardoropenclaw channels add clickclackwith URL, token, and workspace prompts, default-account env fallback, nonfatal live connection validation, and gateway-aware next steps that connect automatically when OpenClaw is already running. Thanks @shakkernerd. - ClickClack command menus: publish each bot's native OpenClaw commands to ClickClack composer autocomplete at gateway startup, with per-account opt-out and nonfatal compatibility handling for older tokens and servers. Thanks @shakkernerd and @vincentkoc.
- Skill Workshop approvals: run agent-initiated apply, reject, and quarantine actions without an additional approval prompt by default while preserving
skills.workshop.approvalPolicy: "pending"as an opt-in approval gate. Thanks @shakkernerd. - TUI fuzzy selectors: delegate list matching to pi-tui, adding slash-token and alpha-number matching while removing the local matcher fork.
- macOS paired-node terminals: advertise duplex Codex and Claude terminal resume commands from the embedded node host and forward interactive input and cancellation through the native app bridge. (#107335)
- Control UI catalog terminals: open eligible Codex and Claude Code sessions in the native CLI on their Gateway or paired-node host, with viewer-versus-terminal preferences, validated resume commands, and an interactive PTY relay. (#107086) Thanks @vincentkoc.
- Skill Workshop history review: add a manual, newest-first session scan that progressively searches older substantial work for conservative skill ideas, stores only SQLite cursor metadata, and leaves up to three results as pending proposals even when autonomous self-learning is disabled. (#106182)
- OpenAI GPT-5.6 defaults: use
openai/gpt-5.6(Sol alias) for fresh API-key setup and exactopenai/gpt-5.6-solfor fresh Codex/OAuth setup, default Sol to medium reasoning across both runtimes, and preserve existing primaries, fallbacks, aliases, and explicit GPT-5.5 selections. (#103234) - iOS offline chat: pre-paint recent sessions and canonical transcripts from a protected, bounded per-gateway cache, keep sending disabled offline, and purge cached conversation text when pairing is reset. (#100194)
- Slack progress indicators: use Slack's native assistant thread status and rotating loading messages by default while keeping acknowledgement reactions static; lifecycle reaction updates now require
messages.statusReactions.enabled: true. - Control UI Talk controls: keep voice, model, sensitivity, and other realtime defaults in Settings → Communications → Talk, and use the composer microphone caret to select any browser audio input. (#101046)
- Control UI session workspace shortcut: expand or collapse the active Chat pane's session workspace rail with ⇧⌘B without changing the main app sidebar or the separate detail and Canvas preview panel. Thanks @shakkernerd.
- Control UI Settings shortcut: open Settings with ⇧⌘, while leaving the browser-owned ⌘, shortcut unchanged. Thanks @shakkernerd.
- Control UI chat layout: center the transcript on the composer axis, keep assistant and tool output left and user bubbles right within the same readable frame, and preserve custom message-width overrides. (#104474) Thanks @shakkernerd, @vincentkoc, and @zw-xysk.
- Control UI composer footer: center the chat settings chip and model controls between the divider and the card edge instead of pinning them to the divider. (#105866)
- Control UI assistant actions: keep assistant name and time first while placing hover actions beside them on the left instead of at the far edge. Thanks @shakkernerd.
- Control UI message context: reveal per-message token, context, and model details from the timestamp on hover or activation instead of showing a separate Context button.
- Control UI session titles: reveal truncated recent-session names with a reduced-motion-safe hover animation.
- Control UI sidebar usage: remove the provider usage quota row from the expanded sidebar while keeping usage details available in the chat composer and Usage page. Thanks @shakkernerd and @vincentkoc.
- Workboard dispatch cap: add a request-scoped
--max-startsoverride while preserving the default cap, sequential starts, and one-card-per-owner guard. (#100174) Thanks @souvikDevloper, @Souvikalp, and @jwest75674. - Plugin install provenance warnings: require explicit
--forceacknowledgement for arbitrary executable plugin sources in CLI and chat installs, keep trusted ClawHub, bundled, official-catalog, and tracked-update flows frictionless, and restrict Crestodian installs to trusted sources. (#102197) Thanks @jesse-merhi. - Cloud workers: add session placement, dispatch, and worker-turn routing for remote session execution. (#106332)
- Paired-node coding agents: discover OpenCode and Pi sessions and continue Codex and Claude catalog sessions through streaming CLI agent runs. (#106941, #106927, #105833)
- Catalog sessions: create eligible catalog sessions directly from the Control UI sidebar. (#105810) Thanks @fuller-stack-dev.
- Managed worktrees: configure cleanup limits by count and total size from Settings. (#106224)
- Cron history: serve scheduled-run history from the task ledger. (#106392)
- Coding-agent memory: import Codex and Claude Code memory into the Control UI. (#106406)
- MCP isolation: scope MCP server connections to their requesting session. (#106359) Thanks @obviyus.
- Discord voice: notify agents when voice-channel participants change. (#107004)
- Codex usage: show the signed-in account email alongside app-server usage windows. (#106500)
- Skill Workshop: scan prior session history for conservative, reviewable skill ideas. (#106766)
- Task previews: show the latest tasks from the running-tasks status row. (#107297)
- Session changes: show the active branch and local changed-file state in Control UI sessions. (#106835)
- Channel progress: reserve progress drafts for long-running work and use the model's own preamble as the status headline. (#106026)
- Codex CLI: bump the bundled plugin to Codex CLI 0.144.4.
Fixes
- External supervisor restart health: accept device-identity policy closes only when the replacement gateway lock and listener PID agree, preventing OCM-managed restarts from timing out after a successful handoff. Thanks @shakkernerd.
- ACPX cleanup process inspection: bound host process-table reads so stalled
pscalls cannot hang gateway startup or session cleanup while retaining fail-closed ownership checks. Thanks @Alix-007. - Cron lifecycle conflict retries: preserve execution-phase retry decisions across scheduled, manual, and startup-recovered runs so post-execution claim conflicts cannot replay completed messages or tools. Fixes #108428. Thanks @yetval.
- Discord gateway metadata deadline: carry the existing lookup deadline through DNS and proxy preflight, request headers, and response bodies so stalled gateway startup aborts cleanly. (#104580) Thanks @hugenshen.
- Control UI cloud session thinking: expose reasoning level in the New Session model picker and persist the selected level before cloud dispatch.
- iOS fresh-install setup: atomically redact spent setup credentials before Keychain cleanup so a deferred item deletion no longer disconnects a successfully paired device. Fixes #107591 Thanks @dagmarjeeves-lab and @vincentkoc.
- Tlon SSE connect cleanup: disarm opening deadlines after failed HTTP responses and rejected stream opens so reconnect attempts cannot leave stale timers behind. (#104585) Thanks @hugenshen.
- LINE reply-token media kinds: honor video and audio metadata on inbound replies, share the canonical media builder with proactive sends, and fail visibly instead of recording empty media-only deliveries. (#106515) Thanks @edenfunf.
- Mattermost websocket connection deadlines: bound opening handshakes so stalled TCP peers cannot hang channel startup indefinitely and reconnect control resumes after timeout. (#105553) Thanks @hugenshen.
- Queued TTS retries: copy local outbound media into queue-owned storage before enqueueing so voice replies survive producer temp cleanup and restart recovery, retain referenced artifacts through retry backoff, and prune unreferenced spool files after one day. Fixes #108501. (#108502) Thanks @masatohoshino.
- Feishu app registration deadlines: bound OAuth device-registration requests to 10 seconds through the guarded fetch boundary so setup cannot hang indefinitely on stalled response headers. (#105549) Thanks @hugenshen.
- LINE control-command mentions: detect authorized slash commands before mention stripping so inline group and direct-message controls preserve the original ingress metadata. (#107230) Thanks @edenfunf.
- Feishu document image reads: bound remote document-image headers and stalled bodies with the selected account timeout, parse document Markdown through the plugin's MDAST pipeline, preserve image/block alignment, and reject failed upload input before creating empty image blocks. Thanks @Alix-007.
- ClawHub registry reads: retry bounded HTTP 500 responses alongside other transient gateway failures so multi-package release scans survive isolated registry errors.
- Slack Socket Mode health: report connected Socket Mode transports as degraded when
auth.testfails or the configured bot token resolves to a user withoutbot_id, while preserving healthy enterprise-org installs. Thanks @zw-xysk. - Synology Chat response limits: bound user-list response reads, stop oversized streams immediately, and retain stale cached identities when a NAS exceeds the supported envelope. Thanks @zw-xysk.
- Usage date ranges: exclude legacy transcript rows without timestamps from finite session ranges while preserving them in all-time totals, and rebuild older usage caches before serving the new semantics. Fixes #89709. Thanks @TurboTheTurtle.
- LINE group history races: retain ambient group messages received during an active mention turn for the next turn while consuming the pre-turn snapshot exactly once. (#107367) Thanks @edenfunf.
- Mattermost progress command details: accept the documented
streaming.preview.commandTextandstreaming.progress.commandTextmodes in channel config validation and bundled metadata. Thanks @shakkernerd. - 1Password authorization handoff: persist nonce-bound pending approvals in shared plugin state so hook and tool execution across broker instances remain single-use and fail closed.
- Control UI chat transcripts: preserve loaded history across session and pane returns, bound automatic backscroll loading, virtualize long transcripts, retain hidden native run boundaries, and keep prepends, streaming, and responsive layouts from flickering or jumping. Thanks @shakkernerd.
- Codex dynamic tool outcomes: use the shared tool-result failure contract for arbitrary lifecycle metadata, preventing successful Skill Workshop results from being displayed and persisted as failed calls. Fixes #107684. Thanks @shakkernerd.
- Codex
/statuscontext freshness: consume exact per-response usage from Codex app servers that emitrawResponse/completed; when exact usage is unavailable or omitted, keep context unknown instead of reusing cumulative lifetime totals. (#107813) Thanks @wuqxuan. - Nested resource ignores: honor slash-free patterns and escaped literal exclamation marks in nested ignore files during skill and resource discovery. Thanks @moguangyu5-design.
- Proxy bypass precedence: honor blank lower-case
no_proxyvalues shadowing upper-caseNO_PROXYconsistently with Undici, and reuse the canonical matcher for Telegram fallback selection. - Tokenjuice exec compaction: avoid retaining raw command output inside compacted middleware metadata, preventing large successful compactions from failing the middleware details-size guard.
- Agent git package identities: strip refs before hosted-repository parsing and reject traversal segments so GitLab branch refs resolve to the canonical managed install path. Thanks @vincentkoc.
- Tlon custom S3 uploads: pass storage endpoints through the AWS SDK's native parser so custom S3-compatible uploads no longer fail before presigning.
- Signal active-run controls: keep authorized stop, status, approval, and queue-read controls responsive during active turns while preserving ordinary and stateful turns in canonical session admission, and cancel every pending group sender lane on stop. (#107422) Thanks @arduano.
- Agent auth storage locks: surface normal release failures while avoiding redundant release attempts after
proper-lockfilereports a compromised lock. - Paired-node session catalogs: authorize bundled Anthropic and Codex catalog requests to invoke their read-only node commands from Control UI read flows, restoring remote Claude/Codex rows and terminal resume availability. Fixes #107406 Thanks @vincentkoc.
- Sandbox recreate confirmation: treat Clack cancellation as a decline so Ctrl-C cannot proceed with container removal.
- Microsoft Teams HTML text: decode HTML5 entities consistently in quoted and Graph-fetched messages while preserving literal escaped entity text.
- ClawHub plugin API ranges: delegate each supported comparator to
semverso tilde, partial-wildcard, and prerelease caret bounds are correct while preserving OpenClaw version normalization and the existing restricted range grammar. (#106877) - Web Readability relative links: seed parsed documents with the request URL so article links resolve correctly while removing the plugin's duplicate lazy-loader facade. (#106860)
- Browser auto-routing: fall back to the Gateway host when an implicitly selected browser node reports that its control host is unreachable, while preserving explicit node pins and ambiguous action failures.
- Discord voice participant context: maintain the live Gateway voice-state roster and include current channel participants in authorized voice agent turns so agents can answer who is present. Thanks @vincentkoc.
- OC Path JSONC insertion: patch object and array insertions through
jsonc-parserso comments, trailing commas, and CRLF formatting survive. (#106847) - Windows winget installs: continue in the current PowerShell session when winget installs Node.js before the machine PATH update becomes visible, avoiding a false
Node.js not foundfailure. (#106862) - Control UI realtime Talk feedback: request browser echo cancellation, noise suppression, and automatic gain control for every microphone transport, and keep PCM capture processors connected through zero-gain sinks so microphone input cannot play locally.
- Agent source-reply recovery: preserve current-chat delivery evidence for message sends executed through Code Mode, preventing successful replies from triggering a redundant retry and misleading delivery-failure diagnostic. Thanks @vincentkoc.
- Gateway in-process restarts: clear stale SIGUSR1 restart state and resume prepared host suspensions before rebuilding runtime admission, preventing restart cooldowns or paused scheduling from leaking into the next lifecycle. Thanks @vincentkoc.
- ClickClack durable media delivery: route media replies through required delivery, reuse owner-scoped upload and message nonces across retries, repair persisted attachment state without rereading source media, fail closed when an older ClickClack server cannot prove an unknown send, and use the selected provider and model's runtime output budget instead of a channel-level token cap. Thanks @jjjhenriksen and @shakkernerd.
- Deepgram realtime custom endpoints: validate Voice Call streaming base URLs with secret-safe errors, preserve explicit
ws://andwss://endpoints, and map HTTP schemes to their matching WebSocket transport for dedicated and self-hosted deployments. (#105334) Thanks @dwc1997, @vincentkoc, and @zw-xysk. - Control UI New Session reconnects: rediscover agents, nodes, repository branches, and folder-browser state, refresh derived workspaces, gate unvalidated devices, and block ambiguous retries after Gateway client replacement while preserving the typed task and explicit choices. Fixes #106372 Thanks @vincentkoc.
- macOS remote node readiness: take the main-session key from the node hello snapshot instead of opening an operator connection during node admission, preventing remote tunnel recovery from leaving Computer Use and node exec stuck in lifecycle transition.
- Claude CLI context budgets: honor Anthropic model and per-agent
contextTokenslimits by passing the effective limit to Claude Code's native auto-compactor and persisting the same prepared budget in OpenClaw session state. Fixes #80933. (#93198) Thanks @mushuiyu886 and @gorkem2020. - Transcript read failures: propagate permission and I/O failures from streaming JSONL session reads instead of treating unreadable transcripts as empty. (#106412) Thanks @zenglingbiao.
- Restart sentinel diagnostics: report SQLite read/write and legacy-file cleanup failures while preserving best-effort restart recovery behavior. (#106385) Thanks @zenglingbiao and @wendy-chsy.
- Native app connection and relay reliability: keep Android disconnects stopped across Activity recreation, fail remote camera commands without opening permission prompts, refresh mobile node registration after capability changes, surface iOS onboarding connection failures, cancel stale Talk owners on session switches, reject invalid Watch acknowledgments, preserve Watch events received during startup, and prevent older agent overview requests from replacing newer gateway state. Thanks @vincentkoc.
- Gateway source watch: hand the configured port off from the installed service before starting the tmux watcher, preserve failed panes for attach/capture, and keep explicit alternate-port watches side by side with the managed Gateway. Thanks @vincentkoc.
- Claude CLI max-turn diagnostics: preserve terminal max-turn results with OpenClaw and Claude session context, warn when tool actions may already have run, and stop unsafe auth-profile or model replay for potentially side-effecting turns. (#94130) Thanks @zhangguiping-xydt and @tdrose01.
- Provider network retries: align provider read/poll/download and agent-wait recovery for transient connection errors, retry bounded provider
ENOTFOUNDfailures while leaving gatewayENOTFOUNDand non-idempotent create operations fail-fast. (#101496) Thanks @xialonglee. - Session retry classification: stop permanent provider errors whose identifiers or payload details merely contain 429/5xx digit sequences from re-sending full context, and share bounded rate-limit-window parsing across retry paths. (#105258) Thanks @destire-mio and @yetval.
- LINE directive templates: suppress confirms and buttons with blank required fields or unlabeled actions while preserving valid titleless buttons and surrounding reply text. (#105520) Thanks @edenfunf.
- SQLite maintenance schema validation: reject current-version global and agent databases with missing or drifted canonical tables, constraints, indexes, triggers, or table options before compaction, while accepting supported additive-migration layouts.
- Matrix bootstrap diagnostics: preserve complete UTF-8 code points in bounded stdout and stderr tails so crypto dependency failures do not show replacement characters at retention boundaries. (#105475) Thanks @qingminlong.
- iOS Watch relay commands: allow paired iPhone nodes to advertise and invoke
watch.statusandwatch.notifythrough the default Gateway policy while preserving the direct watchOS node's fixed minimal command surface. Thanks @vincentkoc. - Swabble status config: honor the global
--configpath when reading service status instead of silently using the default configuration. - ClawHub retry timing: reject fractional delay-seconds and calendar-normalized invalid Retry-After dates so runtime and release reads stay on their bounded fallback schedule. (#105479) Thanks @qingminlong.
- Discord thread archive defaults: inherit each parent channel's configured auto-archive duration for binding-created threads instead of forcing 60 minutes, while preserving explicit overrides. (#103413) Thanks @wings1029.
- Installed plugin loading: make native-module fallback use jiti's transform path instead of retrying the same synchronous ESM load, preventing Node 24 startup races when official plugins import SDK contract modules. Thanks @vincentkoc.
- QA profile channel execution: partition mixed Crabline channel scenarios into one aggregate host suite so taxonomy-backed profile commands and evidence workflows no longer abort before execution.
- Plugin SDK API baseline: cover every public entrypoint, preserve complete declaration shapes without source-line churn, and run baseline and export-surface guards from changed-file validation. Thanks @vincentkoc and @zw-xysk.
- SQLite terminal session recovery: track physical transcript mutation time in the agent database so killed or timed-out main sessions rotate when transcript writes outlive the registry update, while preserving legacy transcript mtimes during doctor import. Thanks @vincentkoc.
- Gateway chat typecheck: import chat event types from their owning protocol schema after the retired aggregate type module was removed, restoring full project typechecks. Thanks @vincentkoc.
- Packaged Crabbox commands: include the lease-freshness helper imported by the published wrapper so
crabbox:*commands do not fail withERR_MODULE_NOT_FOUNDin npm installs. Thanks @vincentkoc. - Plugin session catalogs: reject unknown catalog filters, report catalogs as plugin capabilities, and preserve them in SDK registration captures instead of silently returning empty results or classifying catalog-only plugins as capability-free. Thanks @vincentkoc.
- Gateway service audit: treat POSIX shell
-cwrappers as opaque for the gateway-subcommand check, avoiding false missing-command warnings for shell-wrapped macOS LaunchAgents without parsing inner commands or ports. Fixes #81751. (#81778) Thanks @liaoandi. - Outbound channel bootstrap: suppress repeated failed plugin activation for the same channel, config, and registry generation while retrying after config or registry reloads. (#100377) Thanks @xialonglee.
- OpenAI Realtime client-secret deadlines: bound voice and transcription secret acquisition to 30 seconds through the guarded fetch boundary while preserving authentication and bounded response parsing. (#102860) Thanks @Alix-007 and @Leon-SK668.
- Gateway client watchdog: keep transport-stall detection active for unbounded and mixed pending requests so dead sockets reject pending requests, reconnect, and never replay rejected requests. (#103407) Thanks @NianJiuZst.
- iOS Share Extension drafts: preserve legitimate shared text beginning with scaffold-like prefixes, remove only exact legacy scaffold lines, avoid treating scheme-like prose as a URL, and deduplicate host-mirrored content. (#103453) Thanks @lin-hongkuan and @harjothkhara.
- Telegram reasoning previews: reposition split reasoning previews through deferred deletion so prior preview messages do not remain stale while preserving client scroll position. (#97828) Thanks @ly-wang19 and @kyle20026.
- Feishu native-card threading: normalize whitespace reply targets once and reuse the shared reply mode for card and media parts so native-card topic replies stay in their thread. (#102804) Thanks @sunlit-deng.
- QQBot token requests: bound token acquisition with the shared 30-second guarded-fetch deadline so stalled singleflight callers fail together, clean up, and can retry. (#102897) Thanks @maweibin.
- Canvas A2UI validation: reject malformed or unsupported JSONL at CLI, agent-tool, and final node-invoke boundaries while preserving native v0.8 dispatch. (#103713) Thanks @qingminglong.
- Twilio RCS inbound routing: normalize RCS consumer addresses only after signed webhook validation so sender matching and sessions work without changing outbound RCS semantics. (#102373) Thanks @clawSean.
- ClickClack output sanitization: strip internal tool and XML scaffolding at the sender boundary, suppress scaffold-only sends, and preserve optional modern delivery IDs. (#103142) Thanks @masatohoshino, @vincentkoc, and @zw-xysk.
- Agent-core truncation: avoid empty-output crashes when head truncation receives negative line or byte ceilings. (#103425) Thanks @qingminglong.
- Windows Node resolution: preserve the current executable when resolving bare case-insensitive
node.exeentries under hostilePATHvalues. (#103907) Thanks @soldforaloss and @vincentkoc. - Codex runtime switching: accept the bundled Codex runtime for both
codex/*andopenai/*model routes while keeping unsupported provider/runtime pairs rejected. (#103762) - Agent abort cleanup: serialize prompt lock reacquisition with terminal cleanup so canceled embedded runs do not self-contend on session locks for up to 60 seconds.
- Chutes OAuth deadlines: bound token exchange, profile lookup, and refresh requests, and keep issued tokens when optional userinfo enrichment stalls. (#102026) Thanks @Alix-007.
- Control UI workspace avatars: inline validated agent avatar files in bootstrap and identity responses so Personal card images render without unauthenticated avatar-route requests, while preserving configured emoji precedence. (#102892, #97602) Thanks @LZY3538 and @mtuwei.
- Exec safe-bin flags: auto-approve curated read-only boolean flags for default stdin-only filters while keeping unknown flags, tail follow/retry modes, file operands, and custom profiles fail-closed. (#88953) Thanks @yetval.
- iOS session mutations: scope rename, archive, pin, delete, and fork requests to the selected agent, preserving the parent agent for forked sessions so multi-agent chat actions cannot mutate or create sessions under the wrong agent. (#103366, #103415) Thanks @lin-hongkuan and @harjothkhara.
- Swift protocol initializers: default every schema-optional generated initializer parameter to
nilso additive protocol fields no longer break SDK construction call sites. - OpenCode Go MiMo catalog: stop exposing the deprecated
mimo-v2-omniandmimo-v2-proaliases that reject agent requests, and keep release validation on the active MiMo V2.5 routes. (#103311, #103329) Thanks @krissding. - Audit time filters: reject impossible calendar dates for
openclaw audit --afterand--beforeinstead of rolling them into unintended intervals, while preserving timezone-less timestamp semantics. (#103433) Thanks @qingminglong. - OpenAI-compatible streamed tool calls: execute complete native tool calls from streams that end with SSE
data: [DONE]but omitfinish_reason, while keeping transport EOF and visible-text cases fail-closed. (#98124, #97994) Thanks @SunnyShu0925 and @wszhhx. - xAI provider aliases: preserve Grok 4.3 and Grok 4.5 thinking profiles, fast-model routing, and encrypted reasoning replay when models use the shipped
x-aiprovider alias instead of clamping valid thinking requests tominimal. (#103315) - Doctor state isolation: prevent automated update and Gateway watch repair from importing and archiving default-home exec or plugin-binding approvals when
OPENCLAW_STATE_DIRpoints elsewhere, keep implicit CLI preflight notice-only, and reserve cross-state imports for direct operator doctor runs. (#103247, #103317) Thanks @vincentkoc. - Doctor clean-state guidance: stop suggesting
openclaw doctor --fixafter a clean run with no config changes while preserving targeted repair hints. (#103233) Thanks @kewang-pika and @nonplace. - Google music generation: retry one unblocked Lyria response that omits its contractually required audio while keeping prompt blocks and terminal generation stops non-retryable. (#103318)
- OpenCode Zen model catalog: refresh the provider-owned static seed for Claude Sonnet 5, Grok 4.5, Hy3 Free, Kimi K2.7 Code, and MiniMax M3 with verified routing, pricing, limits, and input capabilities, remove retired free-tier rows, and expose the same catalog through unauthenticated model listing. (#103184)
- Managed browser launch: surface asynchronous Chrome bootstrap and runtime spawn failures as browser errors while keeping Gateway alive, and retain process error handling through later lifecycle failures. Thanks @vincentkoc.
- Browser node-proxy downloads: transfer every action-produced download to the Gateway media store, align a 10 MiB per-file and 16 MiB aggregate transport budget, and rewrite plural download paths to Gateway-local files without traversing page-controlled result data.
- Gateway startup migrations: release the shared migration lease before exiting when the selected config changes during startup, allowing immediate retries instead of blocking readiness until the five-minute lease expires. (#103145)
- Apple timeout recovery: return promptly from shared operation deadlines and caller cancellation even when platform work ignores cancellation, while isolating late Gateway handshakes and cleaning up location and permission waiters. (#103066) Thanks @NianJiuZst.
- Claude CLI warm sessions: preserve managed stdio continuity when Claude writes no native transcript, fall back to bounded OpenClaw history only when the exact live child disappears or changes, and keep stateless runs from persisting CLI bindings. (#96841) Thanks @bradreaves.
- CLI plugin listing: skip state-migration runtime loading when no legacy inputs exist, reducing packaged cold-start memory while preserving migrations for legacy plugin indexes and configured session stores.
- Unicode-safe bounded text: preserve complete UTF-16 surrogate pairs when shortening previews, prompts, diagnostics, labels, session keys, link metadata, and identity values across Control UI, CLI, Gateway, plugins, QA, memory, and Android surfaces. (#102625, #102626, #102627, #102816, #102823, #102833, #102877, #102949, #102963, #102969, #102988, #103010, #103034, #103210, #103341, #103487, #103543, #103580, #103646) Thanks @zhangguiping-xydt, @wings1029, @wangyan2026, @Pandah97, @MoerAI, @SunnyShu0925, @zhangqueping, @zw-xysk, @cxbAsDev, @lzyyzznl, @coder-master-0915, @LeonidasLux, @mushuiyu886, @ly85206559, @Simon-XYDT, @lsr911, @vincentkoc, @chengzhichao-xydt, and @wangmiao0668000666.
- Cron list table: sanitize and size bounded cells by terminal display width so CJK, emoji, combining marks, and terminal-control input cannot corrupt alignment or output. (#103616) Thanks @mushuiyu886.
- CLI model tables: sanitize, truncate, and pad model-list cells by rendered terminal width so emoji, CJK, and other wide graphemes keep columns aligned. (#102819) Thanks @Kevin23-design and @vincentkoc.
- Skills prompt compaction: preserve every included skill identity before using the remaining prompt budget for shortened, UTF-16-safe descriptions, retaining trigger guidance without exceeding the hard limit. (#88426) Thanks @abel-zer0, @vincentkoc, @chengzhichao-xydt, @wangmiao0668000666, and @Pandah97.
- Channel Markdown code tables: size columns by rendered display width so CJK, emoji, and mixed-width cells stay aligned across shared Telegram and Discord output. (#55596, #55512) Thanks @sparkyrider and @zjy282.
- QQ Bot approval previews: wrap long sanitized commands and metadata at grapheme boundaries with visible continuation markers and safe fences, keeping desktop QQ reviews readable without changing command content. (#102119, #101979) Thanks @Bartok9 and @xuzhi5858.
- Codex computer control: publish fixed-length coordinate pairs as homogeneous array schemas so Codex app-server can start threads with the
computertool instead of rejecting tuple-valueditems. - Google Chat request deadlines: bound control calls to 30 seconds while giving media transfers size-aware total budgets and a separate 30-second stalled-body guard, preventing hung Chat API requests without breaking large attachment uploads. (#102227) Thanks @hugenshen.
- Google Gemini prefixed model IDs: recognize
google/gemini-*andmodels/gemini-*when selecting multimodal function-response behavior, preserving the Gemini 2 image fallback without regressing Gemini 3 inline image responses. (#102382) Thanks @LiLan0125 and @yetval. - Generated provider model catalogs: keep MiniMax and NVIDIA catalog rows when they advertise audio or video metadata while projecting runtime model inputs to text/image, preventing configured multimodal primaries from being dropped and falling back. (#97858, #97048) Thanks @ly-wang19 and @zackchiutw.
- DeepSeek catalog metadata: align V4 Flash and Pro pricing with DeepSeek's current cache-hit, cache-miss, and output rates; refresh exact catalog metadata written by older onboarding flows; and document the July 24 retirement of the legacy
deepseek-chatanddeepseek-reasonercompatibility names. (#103192) - CLI audio transcript files: treat inferred Whisper and Parakeet text files as authoritative so empty or missing output cannot expose progress/status stdout as user speech. (#87393, #87384) Thanks @kesslerio.
- Browser actions on Node 24: keep browser request cancellation bound to the client and response lifetime instead of Node 24.16+'s prematurely aborted body-stream signal, preventing valid POST actions from failing after JSON parsing. Thanks @obviyus and @vincentkoc.
- Android hardware keyboard chat: send with unmodified Enter on physical keyboards while preserving Shift+Enter and other modified Enter combinations for multiline input. (#101239) Thanks @3ninyt3nin-creator.
- Codex yielded native subagents: keep the parent app-server subscription and shared client alive until yielded native subagent completion delivery settles, preventing lost wakeups and leaked one-shot cleanup.
- Control UI session creation: keep newly created sessions at the front of the stable sidebar order after selecting another session. Thanks @shakkernerd.
- FTS-only memory startup: skip plugin capability discovery when
memorySearch.provideris explicitlynone, avoiding an unnecessary cold-start scan. - iOS embedded terminal: open the terminal-only Control surface directly while native Gateway authentication connects instead of exposing the Web UI login screen.
- Source build portability: keep tsdown configuration self-contained so builds do not depend on resolving the tsdown package from unrun's temporary module directory. Thanks @vincentkoc.
- Browser tab adoption: preserve the prior implicit tab and stable aliases when new MCP, Playwright, or CDP targets fail final safety validation, abort after creation, or cannot be rediscovered; validate labels before creating tabs and limit managed cleanup to adopted targets. (#105301) Thanks @hugenshen.
- Mattermost block streaming: preserve complete, non-duplicated text and tool blocks in draft preview mode, and honor normal block streaming when preview streaming is disabled. (#87449) Thanks @yetval and @Senseonics-AI.
- iOS development app identity: keep the development app labeled OpenClaw while using its distinct debug icon to differentiate it from release builds.
- Android chat recovery: preserve optimistic user messages and locally owned runs while reconnect and sequence-gap history snapshots catch up, preventing sent messages from disappearing or stale runs from taking ownership. (#100197)
- iOS Voice Wake cleanup: avoid initializing the microphone audio pipeline while disabling inactive Voice Wake, preventing simulator launch aborts and unnecessary audio setup.
- Agent stop recovery: prevent late-aborting prompts from reacquiring orphaned session locks after teardown, so
/stopleaves the conversation ready for the next turn. - Local Gateway CLI auth: keep loopback CLI token/password calls off durable device scopes so read probes cannot block later write/admin commands behind a stale pairing baseline. (#95997) Thanks @vincentkoc.
- MCP schema diagnostics: attribute draft-2020-12 compiler failures to the external MCP schema so malformed patterns produce actionable setup errors. Thanks @vincentkoc.
- Amazon Bedrock control-plane deadlines: bound model discovery and application inference-profile lookups, preserve caller cancellation, and close short-lived SDK clients after each request path. Thanks @Alix-007 and @vincentkoc.
- Reply pre-delivery recovery: bound each pre-delivery callback with an owner-overridable deadline, release serialized reply lanes after hung plugin work, and preserve durable final-delivery retry state only when transport never started. (#104256) Thanks @NianJiuZst and @BenjaminBrossi.
- Signal native quote replies: preserve the active inbound message as a native quote across agent, explicit, durable, and chunked sends while keeping reply-mode policy inside the Signal plugin. (#105347) Thanks @jesse-merhi and @vincentkoc.
- Media-store remote downloads: bound response-header waits and stalled bodies, close abandoned redirect and error responses, and remove partial temp files so hung sources cannot pin callers. (#104624) Thanks @hugenshen.
- Cron llama.cpp tool schemas: keep the model-facing cron declaration schema compatible with llama.cpp while retaining gateway and runtime nonblank validation. Fixes #107449. (#108360) Thanks @lee-xydt and @Patt92.
- Terminal sessions: preserve early keystrokes, enable paired-node terminal actions, authorize paired-node catalog reads, recover after stale Control UI connections, and keep slow clients attached under heavy output. (#107214, #107361, #107410, #107419, #107348) Thanks @vincentkoc and @zw-xysk.
- Control UI configuration: auto-save validated edits, restore autosave gates, show unapplied-restart state, and keep normal content scrolling and selection behavior. (#107458, #107477, #107577, #107349)
- Signal recovery: reconnect after stalled container handshakes, prevent overlapping daemons during restart, and preserve username targets during phone normalization. (#107386, #107409, #107365) Thanks @hugenshen, @ZHOUKAILIAN, @UberKitten, and @ly-wang19.
- Authorization boundaries: require operator-admin authority for paired-node directory browsing and block prototype pollution in migration config merges. (#106004, #106116) Thanks @yangxiansheng, @joshavant, @yetval, and @ruel225.
- Conversation identity: retain speaker attribution across group turns and reduce malformed Discord guild reply tool calls. (#107025, #107474) Thanks @lonexreb.
- Provider setup: show OpenRouter OAuth denial errors, find credentials stored under auth aliases, and keep unresolved API-key providers visible for repair. (#105448, #106736, #106754) Thanks @VectorPeak and @altaywtf.
- Claude and Codex sessions: keep Claude turns open for native background work, avoid Codex shutdown warnings after live updates, complete Codex onboarding login handoff, and retire completed hook relays. (#106347, #106418, #107174, #106899) Thanks @obviyus, @fuller-stack-dev, and @bek91.
- Apple apps: connect iPhone and Watch clients to protocol-v3 Gateways, reject incomplete attachment shares, and honor the pinned Swift toolchain in iOS release archives. (#106294, #106513, #107188) Thanks @jincheng-xydt, @harjothkhara, and @joshavant.
- Memory reliability: preserve UTF-8 across split QMD output, keep canonical cache rows during legacy migration, and accept leading-zero JSON content lengths. (#107263, #107243, #105916) Thanks @wahaha1223, @felirami, @Tony-ooo, @qingminlong, @vincentkoc, and @zw-xysk.
- Skills and Workshop: keep globally installed ClawHub skills tracked, clean orphaned usage rows, surface verification errors, and default Workshop approvals to automatic handling. (#106479, #107144, #107143, #107690) Thanks @ml12580, @mnowrot, @SunnyShu0925, and @shakkernerd.
- Bounded network calls: time out Google Chat authentication, Slack directory and read-mode calls, and Twitch user lookups instead of hanging. (#106178, #106643, #107103, #105883, #107360) Thanks @QiuYuang, @Monkey-wusky, @maweibin, @zw-xysk, and @Alix-007.
- Channel delivery: warn when scalar streaming falls back and make ClickClack media delivery durable while using the selected model's runtime budget. (#106796, #105775) Thanks @jjjhenriksen.
- Plugin management: honor standard ClawHub API comparators and let Control UI administrators enable installed plugins. (#106889, #106318)
- Runtime configuration: preserve resolved cache-retention values, apply explicit environment-variable removals, and keep dispatched Workboard cards from sticking in running state. (#106069, #107258, #107271) Thanks @krissding, @jalfaro2876, and @pgondhi987.
- Input and output safety: redact sensitive migration terminal output, normalize managed git-package identities, and avoid retaining raw command output in compacted Tokenjuice metadata. (#106806, #107637, #107705) Thanks @yetval.
- Network and resource matching: share canonical NO_PROXY behavior and honor nested ignore patterns plus escaped literal exclamation marks. (#107711, #106258) Thanks @moguangyu5-design.
- Markdown frontmatter: preserve coerced fallback values when YAML nodes cannot be represented directly.
Complete contribution record
The full contribution record is available in the tag-pinned CHANGELOG.md.
Release verification
- npm package: https://www.npmjs.com/package/openclaw/v/2026.7.2-beta.2
- registry tarball: https://registry.npmjs.org/openclaw/-/openclaw-2026.7.2-beta.2.tgz
- integrity:
sha512-Pjp6VcPQtGF2Q2d6faFOJ75IGpTt3Xucuxclz//n4eP89Wds5wMhZzGf0Oiqd1uSncm5LgCcZzm31Igp6lOR0w== - release SHA:
54d98a47251d3216443f9446830dec1a0aaddc43 - full release CI report: https://github.com/openclaw/releases/blob/main/evidence/2026.7.2-beta.2/release-evidence.md
- release publish: https://github.com/openclaw/openclaw/actions/runs/29566151276
- npm preflight: https://github.com/openclaw/openclaw/actions/runs/29548071521
- full release validation: https://github.com/openclaw/openclaw/actions/runs/29546250316
- plugin npm publish: https://github.com/openclaw/openclaw/actions/runs/29566735890
- plugin ClawHub publish: dispatched separately, not awaited by this proof: https://github.com/openclaw/openclaw/actions/runs/29566738448
- plugin ClawHub bootstrap: dispatched separately, not awaited by this proof: https://github.com/openclaw/openclaw/actions/runs/29566741033
- npm Telegram beta E2E: https://github.com/openclaw/openclaw/actions/runs/29553869058
関連記事
今日のまとめ
AI日報で今日の重要ニュースをまとめ読み