Peter Steinberger
9cd50c51b0
fix(discord): harden voice DAVE receive reliability ( #25861 )
...
Reimplements and consolidates related work:
- #24339 stale disconnect/destroyed session guards
- #25312 voice listener cleanup on stop
- #23036 restore @snazzah/davey runtime dependency
Adds Discord voice DAVE config passthrough, repeated decrypt failure
rejoin recovery, regression tests, docs, and changelog updates.
Co-authored-by: Frank Yang <frank.ekn@gmail.com >
Co-authored-by: Do Cao Hieu <admin@docaohieu.com >
2026-02-25 00:19:50 +00:00
Vincent Koc
1839ba8ccb
Changelog: note allowlist stale-catalog model selection fix
2026-02-24 19:16:02 -05:00
Peter Steinberger
16b228e4a6
fix(macos): resolve webchat panel corner clipping ( #22458 )
...
Co-authored-by: apethree <3081182+apethree@users.noreply.github.com >
Co-authored-by: agisilaos <3073709+agisilaos@users.noreply.github.com >
2026-02-25 00:14:56 +00:00
Peter Steinberger
57c9a18180
fix(security): block env depth-overflow approval bypass
2026-02-25 00:14:13 +00:00
Peter Steinberger
1970a1e9e5
fix(macos): keep Return for IME marked text commit ( #25178 )
...
Co-authored-by: jft0m <9837901+bottotl@users.noreply.github.com >
2026-02-25 00:14:00 +00:00
Peter Steinberger
11a0495d5f
fix(macos): default voice wake forwarding to webchat ( #25440 )
...
Co-authored-by: Peter Machona <7957943+chilu18@users.noreply.github.com >
2026-02-25 00:12:44 +00:00
Vincent Koc
30082c9af1
Update CHANGELOG.md
2026-02-24 19:12:08 -05:00
Vincent Koc
99dd3448e8
Changelog: remove unrelated session entries from PR
2026-02-24 19:12:08 -05:00
Vincent Koc
1cb14fcf1c
Changelog: note OpenRouter cooldown bypass
2026-02-24 19:12:08 -05:00
Peter Steinberger
31e6d18538
fix(macos): prefer openclaw binary while keeping pnpm fallback ( #25512 )
...
Co-authored-by: Peter Machona <7957943+chilu18@users.noreply.github.com >
2026-02-25 00:11:53 +00:00
Peter Steinberger
236b22b6a2
fix(macos): guard voice audio paths with no input device ( #25817 )
...
Co-authored-by: Stefan Förster <103369858+sfo2001@users.noreply.github.com >
2026-02-25 00:10:14 +00:00
Peter Steinberger
e11e510f5b
docs(changelog): add reporter credit for exec companion hardening
2026-02-25 00:06:14 +00:00
Peter Steinberger
97e56cb73c
fix(discord): land proxy/media/reaction/model-picker regressions
...
Reimplements core Discord fixes from #25277 #25523 #25575 #25588 #25731 with expanded tests.
- thread proxy-aware fetch into inbound attachment/sticker downloads
- fetch /gateway/bot via proxy dispatcher before ws connect
- wire statusReactions emojis/timing overrides into controller
- compact model-picker custom_id keys with backward-compatible parsing
Co-authored-by: openperf <openperf@users.noreply.github.com >
Co-authored-by: chilu18 <chilu18@users.noreply.github.com >
Co-authored-by: Yipsh <Yipsh@users.noreply.github.com >
Co-authored-by: lbo728 <lbo728@users.noreply.github.com >
Co-authored-by: s1korrrr <s1korrrr@users.noreply.github.com >
2026-02-25 00:03:30 +00:00
Peter Steinberger
55cf92578d
fix(security): harden system.run companion command binding
2026-02-25 00:02:03 +00:00
Peter Steinberger
8680240f7e
docs(changelog): backfill landed fix PR entries
2026-02-24 23:59:04 +00:00
Vincent Koc
de586373e0
Changelog: note exact do not do that stop trigger
2026-02-24 18:50:53 -05:00
Peter Steinberger
53f9b7d4e7
fix(automation): harden announce delivery + cron coding profile ( #25813 #25821 #25822 )
...
Co-authored-by: Shawn <shenghuikevin@shenghuideMac-mini.local >
Co-authored-by: 不做了睡大觉 <user@example.com >
Co-authored-by: Marcus Widing <widing.marcus@gmail.com >
2026-02-24 23:49:34 +00:00
Brian Mendonca
43a3ff3beb
Changelog: add entry for exec env sanitization
2026-02-24 23:46:39 +00:00
Peter Steinberger
9514201fb9
fix(telegram): block unauthorized DM media downloads
2026-02-24 23:44:50 +00:00
Peter Steinberger
79a7b3d22e
test(line): align tmp-root expectation after sandbox hardening
2026-02-24 23:31:54 +00:00
Peter Steinberger
79e2328935
docs: update changelog for safe-bin hardening
2026-02-24 23:30:55 +00:00
Peter Steinberger
b4010a0b62
fix(zalo): enforce group sender policy in groups
2026-02-24 23:30:43 +00:00
Peter Steinberger
e7a5f9f4d8
fix(channels,sandbox): land hard breakage cluster from reviewed PR bases
...
Lands reviewed fixes based on #25839 (@pewallin), #25841 (@joshjhall), and #25737/@25713 (@DennisGoldfinger/@peteragility), with additional hardening + regression tests for queue cleanup and shell script safety.
Fixes #25836
Fixes #25840
Fixes #25824
Fixes #25868
Co-authored-by: Peter Wallin <pwallin@gmail.com >
Co-authored-by: Joshua Hall <josh@yaplabs.com >
Co-authored-by: Dennis Goldfinger <dennisgoldfinger@gmail.com >
Co-authored-by: peteragility <peteragility@users.noreply.github.com >
2026-02-24 23:27:56 +00:00
Peter Steinberger
14b6eea6e3
feat(sandbox): block container namespace joins by default
2026-02-24 23:20:34 +00:00
Peter Steinberger
ccbeb332e0
fix: harden routing/session isolation for followups and heartbeat
2026-02-24 23:20:27 +00:00
Peter Steinberger
7655c0cb3a
docs(changelog): add synology-chat allowlist fail-closed note
2026-02-24 23:18:18 +00:00
Peter Steinberger
270ab03e37
fix: enforce local media root checks for attachment hydration
2026-02-24 23:17:48 +00:00
Peter Steinberger
b67e600bff
fix(security): restrict default safe-bin trusted dirs
2026-02-24 23:13:37 +00:00
Peter Steinberger
d3da67c7a9
fix(security): lock sandbox tmp media paths to openclaw roots
2026-02-24 23:10:19 +00:00
Peter Steinberger
bf8ca07deb
fix(config): soften antigravity removal fallout ( #25538 )
...
Land #25538 by @chilu18 to keep legacy google-antigravity-auth config entries non-fatal after removal (see #25862 ).
Co-authored-by: chilu18 <chilu.machona@icloud.com >
2026-02-24 23:02:45 +00:00
Shakker
853f75592f
changelog: include #25847 in chat image safety entry ( #25847 ) (thanks @shakkernerd)
2026-02-24 22:28:58 +00:00
Shakker
e7298b844f
changelog: credit both chat-image fix contributors
2026-02-24 22:28:58 +00:00
Peter Steinberger
9ef0fc2ff8
fix(sandbox): block @-prefixed workspace path bypass
2026-02-24 17:23:14 +00:00
Ayaan Zaidi
f154926cc0
fix: land telegram empty-html fallback hardening ( #25096 ) (thanks @Glucksberg)
2026-02-24 22:34:21 +05:30
Peter Steinberger
0f0a680d3d
fix(exec): block shell-wrapper positional argv approval smuggling
2026-02-24 15:17:03 +00:00
Mariano Belinky
0121fa6f1a
Changelog: add PR 23636 iOS/watch notes
2026-02-24 15:16:11 +00:00
Peter Steinberger
fd07861bc3
fix(ios): harden team-id profile fallback and tests
2026-02-24 15:02:27 +00:00
Peter Steinberger
9ccc15f3a6
docs: update changelog note for native image workspace fix
2026-02-24 14:55:42 +00:00
Peter Steinberger
3b4dac764b
fix: doctor plugin-id mapping for channel auto-enable ( #25275 ) (thanks @zerone0x)
2026-02-24 14:55:23 +00:00
Peter Steinberger
3f07d725b1
fix: changelog credit for Telegram IPv4 fallback fix ( #24295 ) (thanks @Glucksberg)
...
Co-Authored-By: Glucksberg <80581902+Glucksberg@users.noreply.github.com >
2026-02-24 14:53:01 +00:00
Peter Steinberger
fb8edebc32
fix(ui): stabilize chat-image open browser test and changelog
2026-02-24 14:48:10 +00:00
Peter Steinberger
370d115549
fix: enforce workspaceOnly for native prompt image autoload
2026-02-24 14:47:59 +00:00
Peter Steinberger
c3680c2277
docs(changelog): credit reporter for sandbox bind-path fix
2026-02-24 14:47:56 +00:00
Peter Steinberger
6da03eabe2
fix: add changelog and clean regression comment for tool-result guard ( #25429 ) (thanks @mikaeldiakhate-cell)
2026-02-24 14:42:09 +00:00
Peter Steinberger
760671e31c
fix: add changelog for kimi cache usage parsing ( #25436 ) (thanks @Elarwei001)
2026-02-24 14:40:52 +00:00
Peter Steinberger
b511a38fc8
fix: add changelog for doctor sandbox docker warning ( #25438 ) (thanks @mcaxtr)
2026-02-24 14:40:06 +00:00
Peter Steinberger
d2c031de84
fix: add changelog for meta timestamp coercion ( #25491 ) (thanks @mcaxtr)
2026-02-24 14:39:12 +00:00
Peter Steinberger
b5787e4abb
fix(sandbox): harden bind validation for symlink missing-leaf paths
2026-02-24 14:37:35 +00:00
Peter Steinberger
0365125c21
fix: add changelog for reset hook fallback coverage ( #25459 ) (thanks @chilu18)
2026-02-24 14:27:48 +00:00
Peter Steinberger
bbdf895d42
fix: add changelog for slug generator model resolution ( #25485 ) (thanks @SudeepMalipeddi)
2026-02-24 14:27:01 +00:00