Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
323 commits
Select commit Hold shift + click to select a range
bb24952
Merge branch 'main' into staging-promote/455f543b-23329172268
henrypark133 Mar 25, 2026
cdc6255
Merge pull request #1451 from nearai/staging-promote/455f543b-2332917…
henrypark133 Mar 25, 2026
0b4e7c7
chore: release v0.22.0 (#1601)
ironclaw-ci[bot] Mar 25, 2026
4c043bf
feat: complete multi-tenant isolation — phases 2–4 (#1614)
ilblackdragon Mar 26, 2026
f02345f
fix: allow publishing ironclaw_common (#1657)
henrypark133 Mar 26, 2026
ab67f02
fix: publish ironclaw_safety 0.2.0 (#1659)
henrypark133 Mar 26, 2026
6b8a38e
chore: update WASM artifact SHA256 checksums [skip ci] (#1663)
github-actions[bot] Mar 26, 2026
b3fbef5
fix(llm): filter XML tool-call recovery by context (#1641)
serrrfirat Mar 26, 2026
ed4d929
fix(agent): discard truncated tool calls when finish_reason == Length…
rajulbhatnagar Mar 26, 2026
9c63d18
Merge pull request #1612 from nearai/main
henrypark133 Mar 26, 2026
f40019a
Merge pull request #1682 from nearai/staging-promote/9c63d189-2361088…
henrypark133 Mar 26, 2026
adf4e25
fix(extensions): channel-relay auth dead-end, observability, and URL …
PierreLeGuen Mar 26, 2026
07c32b7
Merge pull request #1685 from nearai/staging-promote/adf4e25c-2361809…
henrypark133 Mar 26, 2026
00aba92
Merge pull request #1668 from nearai/staging-promote/ed4d9293-2358252…
henrypark133 Mar 26, 2026
b92d333
Merge pull request #1661 from nearai/staging-promote/4c043bf0-2357303…
henrypark133 Mar 26, 2026
1d57778
fix(mcp): handle 202 Accepted and wire session manager for Streamable…
jr42 Mar 26, 2026
dd0a0e1
fix(routines): recover delete name after failed update fallback (#1108)
G7CNF Mar 26, 2026
5b95d22
Support direct hosted OAuth callbacks with proxy auth token (#1684)
henrypark133 Mar 26, 2026
018416d
Merge pull request #1690 from nearai/staging-promote/5b95d222-2362447…
henrypark133 Mar 27, 2026
db6450c
Merge pull request #1687 from nearai/staging-promote/1d577782-2362040…
henrypark133 Mar 27, 2026
52551f0
chore(ironclaw): release v0.23.0 (#1658)
ironclaw-ci[bot] Mar 27, 2026
45cd668
fix: downgrade excessive debug logging in hot path (closes #1686) (#1…
Mar 27, 2026
9c5ba43
feat(gateway): add OpenAI Responses API endpoints (#1656)
ilblackdragon Mar 27, 2026
7234700
fix(llm): prevent UTF-8 panic in line_bounds() (fixes #1669) (#1679)
willamhou Mar 27, 2026
30db07c
fix: require Feishu webhook authentication (#1638)
serrrfirat Mar 27, 2026
2f4eb08
fix: sanitize tool error results before llm injection (#1639)
serrrfirat Mar 27, 2026
b3533e2
Merge pull request #1703 from nearai/staging-promote/2f4eb086-2363723…
henrypark133 Mar 27, 2026
8f8cb7f
feat: DB-backed user management, admin secrets provisioning, and mult…
ilblackdragon Mar 28, 2026
f49f368
Clean up extension credentials on uninstall (#1718)
henrypark133 Mar 28, 2026
27e8d6f
fix(wasm): use typed WASM schema as advertised schema when available …
Mar 28, 2026
9ba10ea
fix(db): add tracing warn for naive timestamp fallback and improve pa…
Mar 28, 2026
0b33ca9
fix(oauth): tighten legacy state validation and fallback handling (#1…
Mar 28, 2026
9bb19a9
fix(web): redact database error details from API responses (#1711)
Mar 28, 2026
9ce3a9f
feat(discord): implement on_broadcast via DM channel creation (#1693)
Mar 28, 2026
de5a1c7
fix(worker): replace script -qfc with pty-process for injection-safe …
j-bloggs Mar 28, 2026
fd41bdf
fix(worker): treat empty LLM response after text output as completion…
j-bloggs Mar 28, 2026
8a320ae
fix(routines): complete full_job execution reliability overhaul (#1650)
ilblackdragon Mar 28, 2026
a8e8321
feat(discord): add gateway channel flow in wasm (#944)
hdward-dev Mar 29, 2026
e0e530e
docs: tighten contribution and PR guidance (#1704)
serrrfirat Mar 29, 2026
6f6a5f1
feat(skills): recursive bundle directory scanning for skill discovery…
rajulbhatnagar Mar 29, 2026
d97c014
Clarify message tool vs channel setup guidance (#1715)
henrypark133 Mar 29, 2026
fcab4f0
fix: pin staging ci jobs to a single tested sha (#1628)
henrypark133 Mar 29, 2026
86389da
fix(gemini): preserve thought signatures on all tool calls (#1565)
G7CNF Mar 29, 2026
64fe9ba
fix: prevent UTF-8 panics in byte-index string truncation (#1688)
zmanian Mar 29, 2026
70214c4
fix(bedrock): strip tool blocks from messages when toolConfig is abse…
rajulbhatnagar Mar 29, 2026
de384b0
feat: support custom LLM provider configuration via web UI (#1340)
italic-jinxin Mar 29, 2026
4f277c9
Handle empty tool completions in autonomous jobs (#1720)
henrypark133 Mar 29, 2026
368d2f5
feat(gateway): OIDC JWT authentication for reverse-proxy deployments …
synner88 Mar 29, 2026
1346e2e
fix(mcp): deserialize tool annotations with camelCase (MCP spec) (#1571)
jr42 Mar 30, 2026
8acdd08
fix(wasm): inject Content-Length: 0 for bodyless mutating HTTP reques…
werdan Mar 30, 2026
c75dea0
fix(auth): make shared Google tool status scope-aware (#1532)
G7CNF Mar 30, 2026
10d5a53
fix: resolve 11 test failures from multi-tenant bootstrap and sandbox…
ilblackdragon Mar 30, 2026
d0f7862
fix(slack): respond to thread replies without requiring @mention (#1405)
synner88 Mar 30, 2026
d567d94
fix(routines): clone Arc before await in web handler event cache refr…
ilblackdragon Mar 30, 2026
21f613f
test(e2e): align WASM reinstall expectation with uninstall cleanup (#…
henrypark133 Mar 30, 2026
8be61c2
Merge pull request #1763 from nearai/staging-promote/21f613ff-2376117…
henrypark133 Mar 30, 2026
ac79803
Merge pull request #1761 from nearai/staging-promote/d567d94c-2375525…
henrypark133 Mar 30, 2026
30a3e59
Merge pull request #1755 from nearai/staging-promote/d0f7862a-2373313…
henrypark133 Mar 30, 2026
e6c568a
Merge pull request #1753 from nearai/staging-promote/c75dea0e-2373121…
henrypark133 Mar 30, 2026
527b88e
Merge pull request #1747 from nearai/staging-promote/8acdd080-2372603…
henrypark133 Mar 30, 2026
afc8342
Merge pull request #1744 from nearai/staging-promote/368d2f52-2372018…
henrypark133 Mar 30, 2026
a3e20d3
Merge pull request #1743 from nearai/staging-promote/70214c4a-2371907…
henrypark133 Mar 30, 2026
ef9283c
fix(feishu): bump registry version for webhook auth changes (#1765)
henrypark133 Mar 30, 2026
af7925e
Merge pull request #1737 from nearai/staging-promote/86389dab-2370669…
henrypark133 Mar 30, 2026
26f7919
Merge pull request #1735 from nearai/staging-promote/e0e530e6-2370308…
henrypark133 Mar 30, 2026
57aa387
Merge pull request #1733 from nearai/staging-promote/a8e83210-2370234…
henrypark133 Mar 30, 2026
1eac17e
Merge pull request #1732 from nearai/staging-promote/8a320ae9-2369326…
henrypark133 Mar 30, 2026
7e07c9d
Merge pull request #1730 from nearai/staging-promote/fd41bdf4-2369114…
henrypark133 Mar 30, 2026
ce0096f
Merge pull request #1728 from nearai/staging-promote/de5a1c7b-2368897…
henrypark133 Mar 30, 2026
e24be45
Merge pull request #1727 from nearai/staging-promote/9bb19a98-2368792…
henrypark133 Mar 30, 2026
6c2c47b
Merge pull request #1726 from nearai/staging-promote/9ba10eac-2368692…
henrypark133 Mar 30, 2026
71418bb
Merge pull request #1724 from nearai/staging-promote/8f8cb7f7-2368099…
henrypark133 Mar 30, 2026
2d02919
fix(channels): bump discord and slack registry versions (#1766)
henrypark133 Mar 30, 2026
419b47d
Merge pull request #1698 from nearai/staging-promote/7234700c-2363580…
henrypark133 Mar 30, 2026
adb30b6
Track routine verification state across updates (#1716)
henrypark133 Mar 30, 2026
8fe6298
Fix hosted MCP OAuth refresh flow (#1767)
henrypark133 Mar 30, 2026
ffff743
Stabilize MCP refresh regression tests (#1772)
henrypark133 Mar 31, 2026
efa62da
Merge pull request #1773 from nearai/staging-promote/ffff743d-2377692…
henrypark133 Mar 31, 2026
853915e
Merge pull request #1769 from nearai/staging-promote/8fe6298a-2377409…
henrypark133 Mar 31, 2026
22e5ba6
Merge pull request #1768 from nearai/staging-promote/adb30b69-2377014…
henrypark133 Mar 31, 2026
42623ed
fix(builder): add approval context propagation for sub-tool execution…
roelven Mar 31, 2026
27fa292
fix(security): block cross-channel approval thread hijacking (#1590)
zmanian Mar 31, 2026
33e3ce0
Merge pull request #1745 from nearai/release-plz-2026-03-30T00-59-23Z
ironclaw-ci[bot] Mar 31, 2026
78e448d
feat(setup): build ironclaw-worker Docker image in setup wizard (#1757)
ilblackdragon Mar 31, 2026
732c23e
chore: update WASM artifact SHA256 checksums [skip ci] (#1831)
github-actions[bot] Mar 31, 2026
b6b3ffa
feat(telegram): add sendVoice support for audio/ogg attachments (#1314)
TheWolfOfWalmart Mar 31, 2026
bb9a760
chore: whats app lock file (#1824)
hanakannzashi Mar 31, 2026
f441d78
fix(relay): route async Slack messages to correct channel instead of …
PierreLeGuen Mar 31, 2026
684a9d3
fix(gemini): preserve and echo thoughtSignature for Gemini 3.x functi…
h19overflow Apr 1, 2026
7375925
fix(builder): accept inline-table and object-map dependency formats f…
Apr 1, 2026
27a2fab
fix(telegram): auto-generate webhook secret during setup (#1536)
G7CNF Apr 1, 2026
83d3d24
feat(config): unify all settings to DB > env > default priority (#1722)
ilblackdragon Apr 1, 2026
81bb705
feat(jobs): per-job MCP server filtering and max_iterations cap (#1243)
nick-stebbings Apr 1, 2026
58b01f1
fix(worker): Improve command execution parameter validation (#1692)
ArakawaHenri Apr 1, 2026
eb3fa0e
chore: telegram lock file (#1853)
hanakannzashi Apr 1, 2026
510fe19
fix(relay): thread responses under original message in Slack channels…
PierreLeGuen Apr 1, 2026
2f2ad26
test: add routine coverage for issue 1781 (#1856)
henrypark133 Apr 1, 2026
0c89ac5
test(e2e): cover chat approval parity across channels (#1858)
henrypark133 Apr 1, 2026
97ccfd4
Expand GitHub WASM tool surface (#1884)
henrypark133 Apr 1, 2026
a640eb4
test: disable cooldown in gateway webhook workflow test (#1889)
henrypark133 Apr 1, 2026
420f165
test(e2e): add agent loop recovery coverage (#1854)
henrypark133 Apr 1, 2026
9c6d8cb
Merge pull request #1891 from nearai/main
henrypark133 Apr 1, 2026
a55aff9
Add Docker Hub workflow and optimize Dockerfile for size (#1886)
Evrard-Nil Apr 2, 2026
5435b38
feat(workspace): metadata-driven indexing/hygiene, document versionin…
ilblackdragon Apr 2, 2026
d12b8bd
feat: Add ACP (Agent Client Protocol) job mode for delegating to any …
rajulbhatnagar Apr 2, 2026
db5903f
fix(routines): add bounded retry for transient lightweight failures (…
zmanian Apr 2, 2026
5c35b58
feat(auth): direct OAuth/social login with Google, GitHub, Apple, and…
ilblackdragon Apr 2, 2026
a683580
fix(db): resolve V15 migration numbering conflict (#1923)
ilblackdragon Apr 2, 2026
3974163
fix(db): keep V15=conversation_source_channel to match production PG …
ilblackdragon Apr 2, 2026
a3cf7b4
Only tag :latest/:version on release, allow :staging via manual dispa…
Evrard-Nil Apr 2, 2026
d789a5d
fix(db): swap V16/V17 to match production PG (document_versions befor…
ilblackdragon Apr 2, 2026
2b6f22f
fix(docker): switch to glibc to fix libSQL segfault on DB reopen (#1930)
Evrard-Nil Apr 2, 2026
4c9a985
feat(engine): Unified Thread-Capability-CodeAct execution engine (v2 …
ilblackdragon Apr 3, 2026
aa59ca0
Fix bootstrap paths and webhook defaults
ilblackdragon Apr 3, 2026
37a7de4
[codex] Move safety benches into ironclaw_safety crate (#1954)
ilblackdragon Apr 3, 2026
fd7dd6c
fix: update CLI help snapshots for --auto-approve and acp command (#1…
zmanian Apr 3, 2026
1e2d335
fix(llm): add sanitize_tool_messages to OpenAiCodexProvider (#1971)
serrrfirat Apr 3, 2026
b91bdbd
feat(tools): persistent per-user tool permission system (#1911)
henrypark133 Apr 3, 2026
994f960
Publish ironclaw-worker image from Dockerfile.worker (#1979)
Evrard-Nil Apr 3, 2026
3004583
feat(ownership): centralized ownership model with typed identities, D…
henrypark133 Apr 4, 2026
e7c8901
Fix turn cost footer and per-turn usage accounting (#1951)
henrypark133 Apr 4, 2026
0588dd1
fix(llm): invert reasoning default — unknown models skip think/final …
henrypark133 Apr 4, 2026
5451977
fix: unblock bootstrap ownership on dynamic_tools (#2005)
henrypark133 Apr 4, 2026
833dd32
feat: add AWS Bedrock embeddings provider (#1568)
G7CNF Apr 5, 2026
f303638
fix(security): safety layer bypass via output truncation [HIGH] (#1851)
lycheepuppy Apr 5, 2026
e169591
test(workspace): add direct regression tests for scoped_to_user rebin…
reidliu41 Apr 5, 2026
42cbe5f
fix(self-repair): skip built-in tools in broken tool detection and re…
j-bloggs Apr 5, 2026
733678d
Ignore default model override and empty WASM polls (#1914)
serrrfirat Apr 5, 2026
1c2d2f2
feat(test): dual-mode live/replay test harness with LLM judge (#2039)
ilblackdragon Apr 5, 2026
5083aed
fix(agent): prevent self-repair notification spam for stuck jobs (#1867)
j-bloggs Apr 5, 2026
13852ff
fix(docker): ensure ironclaw runtime home exists (#1918)
serrrfirat Apr 6, 2026
98f4471
fix(bridge): sanitize orphaned tool results in v2 adapter (#1975)
serrrfirat Apr 6, 2026
792357b
(fix) WASM channel HTTP SSRF protections (#1976)
serrrfirat Apr 6, 2026
f073eb6
fix: honor auto-approve tools in engine v2 (#2013)
serrrfirat Apr 6, 2026
f9ed815
test: add Telegram E2E tests and Rust integration tests (#2037)
serrrfirat Apr 6, 2026
dfd73cb
feat(llm): hot-reload provider chain from settings
G7CNF Apr 6, 2026
f7a929d
Update src/llm/runtime.rs
G7CNF Apr 6, 2026
83fc942
fix(llm): restore hot-reload snapshot refresh
G7CNF Apr 6, 2026
d0096df
feat: NEAR AI MCP server (#2009)
hanakannzashi Apr 6, 2026
9cf3736
fix(staging): repair broken test build and macOS-incompatible SSRF te…
ilblackdragon Apr 6, 2026
508b526
test(e2e): expand SSE resilience coverage (#1897)
henrypark133 Apr 6, 2026
8b62985
feat(i18n): add Korean translation, fix zh-CN drift, and prevent futu…
ilblackdragon Apr 6, 2026
5d6a247
fix(channels): allow telegram wasm channel name (#2051)
serrrfirat Apr 6, 2026
e7fa167
fix(safety): add credential patterns and sensitive path blocklist (#1…
j-bloggs Apr 7, 2026
0ab1a47
fix(registry): use canonical underscore names in manifests to fix WAS…
ilblackdragon Apr 7, 2026
6fa2d0e
fix: color for tools use (#2096)
hanakannzashi Apr 7, 2026
13774cc
fix(acp): propagate follow-up prompt failures as job errors (#1981)
rajulbhatnagar Apr 7, 2026
f765958
fix(tools): gate claude_code and acp modes behind enabled flags (#2003)
rajulbhatnagar Apr 7, 2026
00fd2e8
fix(web): emit Done after response — SSE ordering fix (#2079) (#2104)
serrrfirat Apr 7, 2026
86c1590
feat(slack): implement on_broadcast and fix message tool hints (#2113)
serrrfirat Apr 7, 2026
a1ef85f
fix(staging): repair 4 categories of CI test failures (#2091)
henrypark133 Apr 7, 2026
79c1b0f
Improve channel onboarding and Telegram pairing flow (#2103)
henrypark133 Apr 7, 2026
5c86184
fix(web): intercept approval text input in chat (#2124)
henrypark133 Apr 7, 2026
755116a
fix(ownership): unify ownership checks via Owned trait and fix missio…
henrypark133 Apr 7, 2026
ecd8826
fix(e2e): canonicalize extension names + fix remaining test failures …
henrypark133 Apr 7, 2026
265fe0e
fix(engine): repair mission ACL regression and 4 stale engine tests (…
henrypark133 Apr 7, 2026
288fe49
fix(ownership): remove silent cross-tenant credential fallback (#2099)
henrypark133 Apr 7, 2026
e82ee33
fix: universal engine-version tool visibility filtering (#2132)
henrypark133 Apr 8, 2026
a56fec7
perf: fix multi-tenant inference latency (per-conversation locking + …
henrypark133 Apr 8, 2026
fdb093f
chore(engine): rename ENGINE_V2_TRACE to IRONCLAW_RECORD_TRACE (#2114)
ilblackdragon Apr 8, 2026
f2b5813
test(channels): add Slack E2E tests, integration tests, and smoke run…
serrrfirat Apr 8, 2026
10d970d
Fix routine Telegram notification summaries (#2033)
serrrfirat Apr 8, 2026
3df1bf3
chore(ci): add Dependabot and pin GitHub Actions by SHA (#2043)
ilblackdragon Apr 8, 2026
482ee57
feat(tui): port full-featured Ratatui terminal UI onto staging (#1973)
serrrfirat Apr 8, 2026
8aa0941
feat(engine): restage skill repair learning loop on staging (#1962)
serrrfirat Apr 8, 2026
315c4cf
[codex] allow private local llm endpoints (#1955)
ilblackdragon Apr 8, 2026
d75e2b2
feat(workspace): admin system prompt shared with all users (#2109)
serrrfirat Apr 8, 2026
bb2c3e1
fix (skills) installs for invalid catalog names (#2040)
serrrfirat Apr 8, 2026
1eaea59
fix(test): use canonical extension name in setup submit test (#2158)
henrypark133 Apr 8, 2026
63a48e4
fix(ci): target wasm32-wasip2 in WASM build script (#2175)
henrypark133 Apr 9, 2026
6895cda
fix(db): repair V6 migration checksum and guard against re-modificati…
ilblackdragon Apr 9, 2026
13c458e
docs: Add mintlify docs (#2189)
gagdiez Apr 9, 2026
980d60e
[codex] Stabilize auth readiness and gate flows (#2050)
ilblackdragon Apr 9, 2026
af9b59a
feat: unified tool dispatch + schema-validated workspace (#2049)
ilblackdragon Apr 9, 2026
b819d70
feat(web): add scroll-to-bottom arrow in gateway chat (#2202)
ilblackdragon Apr 9, 2026
9399fcc
fix(auth) first-pass Gmail OAuth auth prompt in chat (#2038)
serrrfirat Apr 9, 2026
e0bdd74
feat(admin): admin tool policy to disable tools for users (#2154)
serrrfirat Apr 9, 2026
aaeb904
feat(tui): ship TUI in default binary (#2195)
serrrfirat Apr 9, 2026
26e5e4c
feat(docker): pre-bundle WASM extensions in staging image (#2210)
henrypark133 Apr 9, 2026
6a8e581
fix(wasm): upgrade Wasmtime to 43.0.1 and restore CI (#2224)
henrypark133 Apr 10, 2026
580165c
feat(railway): build staging target with pre-bundled WASM extensions …
henrypark133 Apr 10, 2026
2d8e6e6
fix(ci): resolve 3 staging test failures (#2207)
henrypark133 Apr 10, 2026
e0e0fcd
fix(agent): stop intercepting bare yes/no/always as approval when not…
henrypark133 Apr 10, 2026
b9b239e
fix(gateway): suppress duplicate text response during auth flow and u…
henrypark133 Apr 10, 2026
efdb738
fix(docker): consume CACHE_BUST arg so BuildKit invalidates cache
henrypark133 Apr 10, 2026
bd7f2b7
Create QA Bug Report issue template (#2228)
joe-rlo Apr 10, 2026
4147c6d
feat(gateway): extract gateway frontend into ironclaw_gateway crate w…
ilblackdragon Apr 10, 2026
55cdbf2
fix(docs): explain in more details `activation` block & installation …
denbite Apr 10, 2026
e5b82fc
fix(bridge): sanitize auth_url on engine v2 path (#2206) (#2215)
ilblackdragon Apr 10, 2026
494636d
docs: add amazon tutorial (#2261)
matiasbenary Apr 10, 2026
a8e6533
fix(oauth): use localhost for redirect URI when bound to 0.0.0.0 (#2247)
ilblackdragon Apr 10, 2026
8dfedfa
feat: add native Composio tool for third-party app integrations (#920)
vutran1710 Apr 10, 2026
cd8f3f2
feat(skills): commitments system — active intake for personal AI assi…
ilblackdragon Apr 10, 2026
56eb0ad
ci: trigger ironclaw-dind image build (#2190)
think-in-universe Apr 10, 2026
f37a26f
fix(engine): mission cron scheduling + timezone propagation (#1944) (…
ilblackdragon Apr 10, 2026
152e8b0
feat: add extensible deployment profiles (IRONCLAW_PROFILE) (#2203)
serrrfirat Apr 10, 2026
2cc5546
feat(tools): production-grade coding tools, file history, and skills …
ilblackdragon Apr 10, 2026
1b8e1cc
fix(docker): copy profiles/ into build stages (#2289)
henrypark133 Apr 10, 2026
b4502cf
fix(ci): resolve 4 staging test failures (#2273)
henrypark133 Apr 10, 2026
33580d4
fix(v2): tool naming, auth gates, schema flatten, WASM traps, workspa…
ilblackdragon Apr 10, 2026
2f2fe30
fix(test): case-insensitive hint matching in TraceLlm step_matches (#…
henrypark133 Apr 10, 2026
a53eac5
fix(ci): bump 5 channel versions + fix lifetime desync in panics chec…
henrypark133 Apr 10, 2026
a7401ec
fix(gateway): scope chat approvals to the active thread (#2267)
serrrfirat Apr 11, 2026
4032f6d
Fix paired Telegram owner scope routine visibility (#2258)
serrrfirat Apr 11, 2026
7d66d83
fix(engine): always append ActionResult for every tool call (#2322)
ilblackdragon Apr 11, 2026
764e586
feat(engine): LLM council via per-call model override in CodeAct (#2320)
ilblackdragon Apr 11, 2026
70862ed
feat(config): default CLI_MODE to TUI instead of REPL (#2329)
serrrfirat Apr 11, 2026
207c4d4
ci: build docker image in release process (#2321)
think-in-universe Apr 11, 2026
cd9b60c
fix: re-apply Telegram UTF-16 splitting and DB MIGRATION label (#2304)
henrypark133 Apr 11, 2026
88b87c0
feat: user-facing temperature setting (#2275)
ilblackdragon Apr 11, 2026
fdb0a13
chore: sync staging and main (#2337)
henrypark133 Apr 12, 2026
3cb77fe
fix: resolve cargo-deny failures (wildcard deps + rand advisory) (#2370)
ilblackdragon Apr 12, 2026
ed2d6dc
fix web chat refresh active thread (#2330)
serrrfirat Apr 12, 2026
66ccafb
chore(engine): update monty to v0.0.11 (#2364)
ilblackdragon Apr 13, 2026
4529f00
fix(engine): track consecutive action errors in orchestrator Tier 0 p…
zmanian Apr 13, 2026
50fc280
fix(agent): detect and escalate repeated identical failing tool calls…
zmanian Apr 13, 2026
3f6149c
feat(cli): add `ironclaw profile list` subcommand (#2288)
serrrfirat Apr 13, 2026
625cd85
Suppress LLM_BACKEND warning when config.toml and .env values match (…
IYENTeam Apr 13, 2026
a9cea6c
fix(ci): skip NearAI URL DNS validation for non-NearAI backends (#2080)
zmanian Apr 13, 2026
160a75e
fix(llm): image detail field + /v1 base URL normalization (#2380)
zmanian Apr 13, 2026
4dbb44c
fix(docker): make runtime-staging the default Docker target for Railw…
henrypark133 Apr 13, 2026
532fc61
feat: admin management panel — web UI for users and usage monitoring …
serrrfirat Apr 14, 2026
16b7b06
feat(web): add ironclaw docs link (#2398)
italic-jinxin Apr 14, 2026
ba81044
fix(mcp): Install NEAR AI MCP server from environment config (#2181)
hanakannzashi Apr 14, 2026
57d7b54
Fix Feishu webhook auth refresh and extension card overflow (#2443)
hanakannzashi Apr 14, 2026
7425dc0
fix(security): harden approval thread safety (TOCTOU + error handling…
zmanian Apr 14, 2026
86a9d0b
fix: image generation with nearai models (#1819)
hanakannzashi Apr 14, 2026
46ff740
docs(setup): warn that Telegram open mode splits history (#2427)
G7CNF Apr 14, 2026
aea2e87
fix(ux): actionable auth errors and improved CLI help for new users (…
ilblackdragon Apr 14, 2026
ab1f279
fix: more strict check for registry to avoid false positives (#2222)
gagdiez Apr 14, 2026
019c048
refactor(llm): promote decorator chain settings from NearAiConfig to …
Apr 14, 2026
b6f5da8
perf(tunnel): reuse HTTP client in CustomTunnel health checks (#1201)
willamhou Apr 14, 2026
fe2b134
fix(engine): guard consecutive-error checks against None limit (#2460)
ilblackdragon Apr 14, 2026
37669e6
fix(web): prevent browser crash from timer leaks, DOM growth, SSE buf…
henrypark133 Apr 14, 2026
1041094
style: fix cargo fmt line wrapping in thread_ops.rs (#2451)
serrrfirat Apr 14, 2026
0a9d816
fix(responses-api): thread creation, GET by ID, streaming delta, cont…
pranavraja99 Apr 14, 2026
be04fad
merge staging into codex/issue-1350-llm-hot-reload-currentbase
G7CNF Apr 14, 2026
f18c963
Merge branch 'staging' into codex/issue-1350-llm-hot-reload-currentbase
G7CNF Apr 14, 2026
1fa73a4
docs: add Responses API section to USER_MANAGEMENT_API (#2440)
pranavraja99 Apr 14, 2026
5140279
docs: guide how to host ironclaw on google cloud (#2262)
matiasbenary Apr 14, 2026
d85c11d
fix(telegram): route WASM owner_id fallback (#2349)
serrrfirat Apr 14, 2026
28c6a15
fix(ci): exclude test files from PR size classification (#2387)
serrrfirat Apr 14, 2026
d63601e
fix(security): gate test URL rewriters behind #[cfg(test)] (fixes #20…
serrrfirat Apr 14, 2026
82d341d
fix(sandbox): try Docker socket before CLI binary check (#2467)
ymcrcat Apr 14, 2026
2dc78b2
feat(db): add per-user CachedSettingsStore decorator (#2425)
henrypark133 Apr 14, 2026
8973d1b
fix: use gateway owner_id for relay OAuth nonce storage (#2473)
henrypark133 Apr 14, 2026
16a0731
test(e2e): add Playwright persistence happy-path test (#2475)
henrypark133 Apr 14, 2026
5928365
Merge branch 'staging' into codex/issue-1350-llm-hot-reload-currentbase
G7CNF Apr 15, 2026
3e211ab
fix(llm): clear PR 2059 CI blockers
G7CNF Apr 15, 2026
834254c
style(testing): format helper reference
G7CNF Apr 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
7 changes: 6 additions & 1 deletion .claude/rules/database.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,8 @@ See `src/db/CLAUDE.md` for full schema, dialect differences, and libSQL limitati
4. Implement in `src/db/libsql/<module>.rs` (use `self.connect().await?` per operation)
5. Add migration if needed:
- PostgreSQL: new `migrations/VN__description.sql`
- libSQL: add `CREATE TABLE IF NOT EXISTS` to `libsql_migrations.rs`
- libSQL: add entry to `INCREMENTAL_MIGRATIONS` in `libsql_migrations.rs`
- **Version numbering**: always number after the highest version on `staging`/`main` — those migrations may already be in production. Check with `git ls-tree origin/staging migrations/` and staging's `INCREMENTAL_MIGRATIONS`. Never reuse or insert before an existing version.
6. Test feature isolation:
```bash
cargo check # postgres (default)
Expand Down Expand Up @@ -58,6 +59,10 @@ Multi-step operations (INSERT+INSERT, UPDATE+DELETE, read-modify-write) MUST be

`LibSqlBackend::connect()` creates a fresh connection per operation with `PRAGMA busy_timeout = 5000`. This is intentional -- no pool exists. Never hold connections open across `await` points. Satellite stores (`LibSqlSecretsStore`, `LibSqlWasmToolStore`) receive `Arc<LibSqlDatabase>` via `shared_db()` and call `.connect()` themselves -- never pass a live `Connection`.

## Never Delete LLM Output Data

All LLM execution data — thread messages, steps, events, tool call parameters and results — must **never** be deleted from the database. This is the most valuable data in the system. No `DELETE` statements, no `DROP`, no truncation of LLM-generated content. In-memory caches (HashMaps in `HybridStore`) may evict entries for memory pressure, but database rows are permanent. Load methods must fall back to the database on a cache miss.

## Fix the Pattern, Not the Instance

When fixing a bug in one backend's SQL, always grep for the same pattern in the other. A fix to `postgres.rs` that doesn't also fix `libsql/jobs.rs` is half a fix. Same applies to satellite stores.
13 changes: 8 additions & 5 deletions .claude/rules/skills.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,16 +31,19 @@ activation:
tags:
- "devops"
max_context_tokens: 2000
metadata:
openclaw:
requires:
bins: [docker, kubectl]
env: [KUBECONFIG]
requires:
bins: [docker, kubectl]
env: [KUBECONFIG]
---

# Skill instructions here...
```

Only the top-level `requires:` block is supported. The legacy nested shape
`metadata.openclaw.requires` is unsupported and ignored by the current parser,
so older external skills must be migrated instead of relying on silent
compatibility.

## Selection Pipeline

1. **Gating** -- Check binary/env/config requirements; skip skills whose prerequisites are missing
Expand Down
41 changes: 41 additions & 0 deletions .claude/rules/testing.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,3 +23,44 @@ Run `bash scripts/check-boundaries.sh` to verify test tier gating.
- Use `tempfile` crate for test directories, never hardcode `/tmp/`
- Regression test with every bug fix (enforced by commit-msg hook)
- Integration tests (`--test workspace_integration`) require PostgreSQL; skipped if DB is unreachable

## Test Through the Caller, Not Just the Helper

**When a helper gates a side-effecting flow, the test must go through the caller — not just the helper in isolation.**

A whole class of bugs in this repo has the same shape: a wrapper function silently loses one of its inputs, and the unit test for the helper passes because it never crosses the layer where the input gets dropped.

Real examples (do not let these recur):

| Bug | Helper | What got lost | How a caller-level test would have caught it |
|-----|--------|--------------|------------------------------------------------|
| nearai/ironclaw#1948 | `McpServerConfig::has_custom_auth_header()` | Helper existed but `requires_auth()` never consulted it, so MCP triggered OAuth/DCR even with a user-set `Authorization` header | A test driving `mcp::factory::create_client_from_config()` with a header-bearing config and asserting zero OAuth-state side effects |
| nearai/ironclaw#1921 | `derive_activation_status(ext, has_owner_binding)` | Wrapper hardcodes the underlying classifier's `has_paired` axis to `false`, even though `classify_wasm_channel_activation` takes both bools | A test driving `extensions_list_handler` against a DB with a real `channel_identities` row and asserting `Active`, not `Pairing` |
| nearai/ironclaw#1502 | `window.open` mock `(url) => { window._lastOpenedUrl = url }` | Mock captured only the URL, silently swallowing `target` and `windowFeatures`; a regression to same-tab open would not fail | A mock capturing all three args plus an assert that `target === '_blank'` |

### When the rule applies

You must add a caller-level test (not just a helper-level unit test) when **all** of the following are true:

1. The helper is a **predicate, classifier, or transform** whose return value gates a side effect (HTTP call, DB write, UI mutation, OAuth flow, secret read, tool execution, sandbox launch, etc.).
2. There is **at least one wrapper or call site** between the helper and the side effect.
3. The helper has **more than one input** *or* its caller computes any of the inputs from the surrounding context.

If all three are true, a unit test on the helper alone is **not sufficient regression coverage**. You must additionally either:

- Add a test that drives the call site (`*_handler`, `factory::create_*`, `manager::*`), **or**
- Inline the helper into its single caller so there is no wrapper to silently drop an input.

### Where the test belongs

Most of these gaps are above unit-test scope and below e2e scope. Default to the **integration tier** (`cargo test --features integration`):

- `tests/<module>_integration.rs` for Rust integration tests against the public handler/factory surface
- `tests/multi_tenant_integration.rs` when the lost axis is per-user state
- `tests/e2e/scenarios/test_*.py` when the lost axis is browser-visible

Unit tests in `mod tests {}` are still fine for the helper itself, but they do not satisfy this rule.

### Mock hygiene corollary

When you mock a browser/runtime API in a test, the mock's signature must match the production call site's signature, and assertions should cover **every argument** the production code passes. A `(url) => {}` stub for a `window.open(url, target, features)` call site is a silent argument-loss bug waiting to happen.
101 changes: 101 additions & 0 deletions .claude/rules/tools.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,8 @@
paths:
- "src/tools/**"
- "tools-src/**"
- "src/channels/**"
- "src/cli/**"
---
# Tool Architecture

Expand Down Expand Up @@ -37,3 +39,102 @@ impl Tool for MyTool {
fn requires_sanitization(&self) -> bool { true } // External data
}
```

## Everything Goes Through Tools

**All actions originating from any non-agent caller — gateway handlers, CLI
commands, routine engine, WASM channels, future channel extensions — MUST
go through `ToolDispatcher::dispatch()`, never directly through the
database, workspace, or domain managers.**

This is the core design principle behind #2049. The reasons are concrete:

1. **Audit trail.** Every dispatched call creates an `ActionRecord` linked
to a system job, so UI-initiated mutations are visible in job history
alongside agent-initiated ones. Direct DB calls bypass this entirely.
2. **Safety pipeline parity.** The dispatcher runs the same pipeline as
`Worker::execute_tool`: parameter normalization, schema validation,
`sensitive_params()` redaction, per-tool timeout, output sanitization.
Direct calls skip all of it and risk leaking secrets into logs or
persisting unsafe content.
3. **Channel-agnostic.** Channels are interchangeable extensions (gateway,
CLI, telegram, WASM, future custom channels). Routing through a single
dispatch function means new channels inherit the full pipeline for free.
4. **Agent parity.** The agent can do anything channels can do (and vice
versa), because both call the same tools. No more "the UI can install
extensions but the agent can only list them" gaps.

### Required pattern

```rust
// In any gateway handler, CLI command, or routine engine callback:
use crate::tools::dispatch::{DispatchSource, ToolDispatcher};

let dispatcher: &ToolDispatcher = state
.tool_dispatcher
.as_ref()
.ok_or((StatusCode::SERVICE_UNAVAILABLE, "dispatcher unavailable"))?;

let output = dispatcher
.dispatch(
"memory_write",
serde_json::json!({ "target": path, "content": content }),
&user.user_id,
DispatchSource::Channel("gateway".into()),
)
.await
.map_err(|e| (StatusCode::INTERNAL_SERVER_ERROR, e.to_string()))?;
```

### Forbidden pattern

```rust
// DO NOT do this in a gateway handler, CLI command, or routine callback:
let store = state.store.as_ref().ok_or(...)?;
store.set_setting(&user.user_id, &key, &value).await?; // BYPASSES dispatch

let workspace = resolve_workspace(&state, &user).await?;
workspace.write(path, content).await?; // BYPASSES dispatch + safety pipeline

let ext_mgr = state.extension_manager.as_ref().ok_or(...)?;
ext_mgr.install(name, url, kind, &user.user_id).await?; // BYPASSES audit trail
```

### When direct access IS allowed

The dispatch principle applies to **non-agent callers** acting on behalf of
a user. These are exempt:

| Layer | Why exempt |
|---|---|
| `Worker::execute_tool()` (agent loop) | Has its own atomic sequence-numbered audit trail; the dispatcher would conflict |
| `EffectBridgeAdapter::execute_action()` (v2 engine) | Same — its own audit via `ThreadEvent` event sourcing |
| The tool implementations themselves | Tools are the leaves; they need direct `Workspace`, `Database`, etc. handles to do their work |
| Background jobs (scheduler, hygiene, mission runner) inside the engine | These ARE the engine; they emit their own events |
| Pure read endpoints that need to JOIN/aggregate from multiple sources | A single tool call cannot express "list all jobs across users with filters X, Y, Z" — these are queries, not actions, and the audit value is low |

### Annotating intentional exceptions

If a handler legitimately needs direct access (rare — usually only for
read aggregation), suppress the pre-commit check with a trailing comment
on the offending line:

```rust
let rows = state.store.list_agent_jobs().await?; // dispatch-exempt: read-only aggregation
```

The pre-commit hook (`scripts/pre-commit-safety.sh`) flags any newly
added line in `src/channels/web/handlers/*.rs` or `src/cli/*.rs` that
touches `state.{store,workspace,workspace_pool,extension_manager,
skill_registry,session_manager}.*` without a trailing
`// dispatch-exempt: <reason>` comment on the same line. The check only
looks at added lines (`+` lines in the diff), so existing untouched code
doesn't trip it during incremental migration.

### Migration status

As of #2049, `ToolDispatcher` is wired into `GatewayState` but per-handler
migration is incomplete. New handlers MUST use the dispatcher. Existing
handlers should be migrated incrementally; each handler family
(settings, memory, extensions, skills, routines, jobs, threads) is its
own follow-up PR.
Loading