惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
D
Darknet – Hacking Tools, Hacker News & Cyber Security
M
MIT News - Artificial intelligence
腾讯CDC
IT之家
IT之家
Microsoft Azure Blog
Microsoft Azure Blog
M
Microsoft Research Blog - Microsoft Research
阮一峰的网络日志
阮一峰的网络日志
H
Help Net Security
L
LangChain Blog
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
人人都是产品经理
人人都是产品经理
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
博客园 - 【当耐特】
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
U
Unit 42
Recent Announcements
Recent Announcements
S
SegmentFault 最新的问题
大猫的无限游戏
大猫的无限游戏
博客园 - Franky
T
The Blog of Author Tim Ferriss
罗磊的独立博客
宝玉的分享
宝玉的分享
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网
D
DataBreaches.Net
爱范儿
爱范儿
Schneier on Security
Schneier on Security
P
Palo Alto Networks Blog
Spread Privacy
Spread Privacy
Hugging Face - Blog
Hugging Face - Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
K
Kaspersky official blog
P
Privacy & Cybersecurity Law Blog
博客园_首页
T
Threat Research - Cisco Blogs
I
InfoQ
有赞技术团队
有赞技术团队
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Recorded Future
Recorded Future
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
GbyAI
GbyAI
Cyberwarzone
Cyberwarzone
B
Blog
C
Check Point Blog
P
Proofpoint News Feed
S
Securelist
A
Arctic Wolf

Recent Commits to openclaw:main

chore(release): refresh plugin sdk baseline · openclaw/openclaw@7c7fb7d fix(discord): fence tool warning fallback delivery (#87465) · openclaw/openclaw@0e262d2 fix(doctor): validate tool schemas for configured agents · openclaw/openclaw@748510b fix: reject partial numeric runtime values · openclaw/openclaw@45e6af5 fix: reject partial numeric command values fix(hooks): pass media metadata to received hook fix(heartbeat): stop pending final replay · openclaw/openclaw@d00e764 test(discord): use reply payload SDK test helper (#87454) · openclaw/openclaw@c86667c fix: accept uncommitted autoreview mode · openclaw/openclaw@ff0990d fix(outbound): thread session keys into outbound hooks (#73706) · openclaw/openclaw@05db911 fix(provider): bound local service startup · openclaw/openclaw@c9151ba chore: forward gateway profiling env · openclaw/openclaw@1f1cdd8 fix(discord): suppress recovered tool warnings (#87451) · openclaw/openclaw@da27904 fix(cron): stabilize isolated prompt cache affinity · openclaw/openclaw@3f9d241 fix(agents): keep hook context prompt-local (#86875) · openclaw/openclaw@8b7a482 fix(doctor): rewrite non-canonical api_key auth profiles · openclaw/openclaw@603aa8a fix(sessions): preserve Matrix room-id case in session keys (#75670) … · openclaw/openclaw@b5bd6e8 test(gateway): retry live exec read probe wording · openclaw/openclaw@92043f7 fix(imessage): continue polling after denied reactions · openclaw/openclaw@59c3ee7 fix(agents): release session lock on timeout abort · openclaw/openclaw@65fb565 fix(provider): honor Codex response timeouts · openclaw/openclaw@c20a055 fix(codex): report quarantined dynamic tools · openclaw/openclaw@da5fe99 fix(imessage): suppress duplicate native exec approvals · openclaw/openclaw@40bca6d fix(sessions): avoid stale restart continuation reuse · openclaw/openclaw@d8641a6 fix(gateway): drain probe client close test(ci): bound image tool iMessage fixtures feat(status): show active subagent details fix(codex): format skills command output (#87400) Improve stale Codex auth recovery guidance [Fix] Warm provider auth off main thread (#86281) · openclaw/openclaw@316fd5b fix(agents): resolve Codex runtime models first · openclaw/openclaw@5cef288 fix(doctor): make restart follow-up actionable (#87361) · openclaw/openclaw@f3e2851 fix(crabbox): preserve sparse run artifacts · openclaw/openclaw@53ad531 docs(changelog): require contributor thanks · openclaw/openclaw@78c5eea fix(web-search): preserve runtime-only provider config · openclaw/openclaw@5d437de fix(slack): retain delivered final replies during late cleanup · openclaw/openclaw@fb1dfd4 test(ci): align startup and model fixtures fix: preserve retry-after fallback · openclaw/openclaw@efbd00f fix: reject partial numeric parsing · openclaw/openclaw@f24844d fix(agents): bound compaction wake retry timeouts · openclaw/openclaw@db54913 fix(agents): wait for compaction before requester steering fallback · openclaw/openclaw@a7b8e6a fix(agents): clamp compaction steer retry wait to remaining delivery … · openclaw/openclaw@ea2e9ce Fix sub-agent cwd/workspace separation (#87218) · openclaw/openclaw@7299c56 fix(agent-job): preserve grace for pending error diagnostics · openclaw/openclaw@039fcba Revert "feat: expose plugin approval action metadata" (#87419) · openclaw/openclaw@bb752c2 test(openai): stabilize live audio transcription · openclaw/openclaw@5ad8036 test(agents): clarify live subagent steering prompt · openclaw/openclaw@dfcf211 fix(oauth): bound GitHub Copilot requests · openclaw/openclaw@7b967c5 fix(cli): respect subcommand version options (#87398) · openclaw/openclaw@b4e5038 fix(oauth): bound Codex token requests fix(agents): move session write lock into owned session runtime (#87409) · openclaw/openclaw@5f68291 fix(gateway): quarantine unsupported effective tool schemas · openclaw/openclaw@21d9609 fix: migrate legacy memory auto provider · openclaw/openclaw@a7d2d9c fix(openai): resolve gpt-5.5 without cached catalog · openclaw/openclaw@09d2682 fix(cli): wait for respawn child shutdown · openclaw/openclaw@00004ca fix(codex): preserve shared app-server after startup app errors (#87399) · openclaw/openclaw@7f7eca1 chore(ui): mark generated locale artifacts (#87406) · openclaw/openclaw@87944c0 fix(e2e): bound MCP channel harness buffers · openclaw/openclaw@f39f1a4 fix(testing): bound openclaw instance logs test(config): clear install record cache in validation fixture · openclaw/openclaw@9ff071f fix(inbound-meta): include seconds in timestamps · openclaw/openclaw@2900c1c fix(agents): bound plugin system context · openclaw/openclaw@f4329fe perf(plugins): trust install records cache between reloads · openclaw/openclaw@b257b98 fix(gateway): expire browser tokens after auth rotation · openclaw/openclaw@c923b07 fix(gateway): scope assistant idempotency dedupe · openclaw/openclaw@d905115 fix(ci): stabilize model picker and release checks · openclaw/openclaw@4ff944c docs: clarify backport target · openclaw/openclaw@171675b fix(ci): satisfy codex extension lint · openclaw/openclaw@d30ba7f fix(codex): narrow legacy hook generation grace (#87386) · openclaw/openclaw@cc2948d perf(config): prefer native JSON parsing · openclaw/openclaw@4da2b5f fix(ci): address lint and test type failures fix(tool-search): reuse unchanged catalogs · openclaw/openclaw@60e8e60 fix(codex): route workspace memory through tools (#87383) · openclaw/openclaw@d93524d fix(codex): preserve shared app-server when spawned helper run fails … · openclaw/openclaw@74f9d6b perf(sessions): add precomputed patch writer · openclaw/openclaw@15b1e99 fix(ci): align release and image tests · openclaw/openclaw@26a8432 fix(cli): reject malformed numeric inputs · openclaw/openclaw@94749b0 fix(agents): avoid session event queue self-wait (#86123) · openclaw/openclaw@b789e71 fix(plugin-state): evict current namespace on plugin row cap · openclaw/openclaw@e339586 fix(channels): preserve Telegram SecretRef prompt config · openclaw/openclaw@90f3007 Add ClawHub skill verification and trust surfaces (#86699) · openclaw/openclaw@ee57f34 perf(sessions): skip unchanged store serialization · openclaw/openclaw@431eb9c fix(gateway): bound webchat image data scans · openclaw/openclaw@bde1bad fix(ci): avoid deprecated sdk import in canvas cli · openclaw/openclaw@2f710f5 fix(codex): preserve native hook relay across restarts · openclaw/openclaw@42e9504 docs: add macOS gateway sleep troubleshooting · openclaw/openclaw@6727985 docs: document native Codex hook relay recovery fix(qa): make matrix block streaming deterministic · openclaw/openclaw@fdbf3cf fix(diffs): use root viewer runtime builder · openclaw/openclaw@163df25 fix(cli): reject partial numeric options · openclaw/openclaw@9755241 fix(cli): reject partial numeric options · openclaw/openclaw@0f5ea87 fix(gateway): bound artifact transcript scans · openclaw/openclaw@ac176d4 refactor: internalize OpenClaw agent runtime (#85341) · openclaw/openclaw@bb46b79 perf(sessions): reduce store clone allocations · openclaw/openclaw@99b27cd test(agents): make live subagent steering explicit · openclaw/openclaw@f40275c test(matrix): quarantine live block-streaming scenario · openclaw/openclaw@dfe49ae expand default diffs languages (#87372) · openclaw/openclaw@cff8e43 fix(diffs): align language pack host floor (#87370) · openclaw/openclaw@2c95752 fix(qa): make matrix block streaming deterministic · openclaw/openclaw@140cede ci(release): smoke Docker runtime templates in full validation · openclaw/openclaw@c0f1646
chore(release): prepare 2026.5.28 · openclaw/openclaw@cee2a50
steipete · 2026-05-28 · via Recent Commits to openclaw:main

@@ -2,6 +2,32 @@

2233

Docs: https://docs.openclaw.ai

445+

## 2026.5.28

6+7+

### Highlights

8+9+

- Agent and Codex runtime recovery is steadier: subagents keep cwd/workspace separation, hook context stays prompt-local, session locks release on timeout abort, stale restart continuations are avoided, and Codex app-server/helper failures no longer tear down shared runtime state. (#87218, #86875, #87409, #87399, #87375)

10+

- Channel delivery and session identity got safer across outbound plugin hooks, Matrix room ids, iMessage reactions/approvals, Slack final replies, Discord recovered tool warnings, and Microsoft Teams service URL trust checks. (#73706, #75670, #87366, #87451, #87334)

11+

- CLI, auth, doctor, and provider paths fail faster and recover more clearly: malformed numeric/version options are rejected, OAuth and local service startup requests are bounded, legacy `api_key` auth profiles migrate to canonical form, and restart guidance is actionable. (#87398, #86281, #87361)

12+

- Plugin and Gateway hot paths do less repeated work while preserving cache correctness for install records, config JSON parsing, tool search catalogs, session stores, manifest model rows, auto-enabled plugin config, browser tokens, and viewer assets. (#86699)

13+

- Release, QA, and E2E validation now bound more log, artifact, harness, and cross-OS waits so failing lanes produce proof instead of hanging or false-greening.

14+15+

### Changes

16+17+

- Status: show active subagent details in status output.

18+

- Diffs: split the default language pack and expand default Diffs language coverage while keeping the host floor aligned. (#87370, #87372) Thanks @RomneyDa.

19+

- ClawHub: add plugin display names plus skill verification and trust surfaces. (#87354, #86699) Thanks @thewilloftheshadow and @Patrick-Erichsen.

20+

- Docs: clarify Codex computer-use setup, paste-token stdin auth setup, macOS gateway sleep troubleshooting, native Codex hook relay recovery, container model auth, install deployment cards, device-token admin gating, and backport targets. (#87313, #63050) Thanks @bdjben, @liaoandi, and @thewilloftheshadow.

21+22+

### Fixes

23+24+

- Agents/Codex: keep spawned agent cwd/workspace state separated, keep hook context prompt-local, release session locks on timeout abort, avoid session event queue self-wait, preserve shared app-server state across startup or helper failures, keep native hook relay alive across restarts, route workspace memory through tools, resolve Codex runtime models first, report quarantined dynamic tools, format `skills` command output, and bound compaction/steering retries. (#87218, #86875, #86123, #87399, #87375, #87383, #87400) Thanks @mbelinky, @Alix-007, @luoyanglang, @yetval, and @sjf.

25+

- Channels: thread canonical session keys into outbound hooks, preserve Matrix room-id case, keep fallback tool warnings mention-inert, retain delivered Slack final replies during late cleanup, continue iMessage polling after denied reactions, suppress duplicate native exec approvals, preserve Telegram SecretRef prompt config, suppress Discord recovered tool warnings, and block untrusted Teams service URLs. (#73706, #75670, #87366, #87451, #87334) Thanks @zeroaltitude, @lukeboyett, @xiaotian, and @eleqtrizit.

26+

- CLI/auth/doctor/providers: reject malformed numeric/timeout/subcommand-version inputs, wait for respawn child shutdown, bound Codex and GitHub Copilot OAuth/token requests, warm provider auth off the main thread, honor Codex response timeouts, bound local service startup, resolve GPT-5.5 without cached catalog, migrate legacy memory auto-provider config, rewrite non-canonical `api_key` auth profiles, and make doctor restart follow-ups actionable. (#87398, #86281, #87361) Thanks @Patrick-Erichsen, @samzong, @giodl73-repo, and @alkor2000.

27+

- Gateway/security/session state: expire browser tokens after auth rotation, scope assistant idempotency dedupe, drain probe client closes, avoid stale restart continuation reuse, preserve retry-after fallbacks, bound webchat image and artifact transcript scans, include seconds in inbound metadata timestamps, and evict current plugin-state namespaces at row caps.

28+

- Performance: trust install-record caches between reloads, prefer native JSON parsing, reuse unchanged tool-search catalogs, skip unchanged store serialization, add precomputed session patch writers, reduce store clone allocations, cache manifest model catalog rows and auto-enabled plugin config, and slim current metadata identity caches.

29+

- Docker/release/QA: package runtime workspace templates, stream cross-OS served artifacts, preserve sparse Crabbox run artifacts, bound OpenClaw instance logs, plugin gauntlet relay logs, MCP channel buffers, kitchen-sink scans, agent-turn assertions, and release scenario logs, and keep release/google live guards current.

30+531

## 2026.5.27

632733

### Highlights