Share This Mac gains browser viewing, opt-in folder sharing, multi-display streaming, system audio, and QUIC transport with TCP fallback. This release also fixes repeated QUIC certificates accumulating in the login keychain and keeps terminal sessions responsive during slow resize authorization.
- Fix the QUIC host identity leaking a new self-signed "Crabfleet QUIC" certificate into the login keychain on every launch: reuse the stored certificate by matching the stable host public key instead of a label macOS never persists, and collapse any already-accumulated duplicates back to one, restoring fast system-CA trust evaluation.
- Fix Share This Mac connections on current macOS by binding the listener port wide and requiring the exact Tailscale local address per accepted connection before any protocol bytes; the previous required-local-endpoint bind made every accepted connection fail with EADDRINUSE.
- Fix the Crabfleet Connect Linux X11 backend disabling capture entirely on keyboards with multiple XKB groups: bind only the primary group's base/shift levels so real screen capture and input injection work instead of silently falling back to the synthetic test pattern (validated on a headless Xvfb X server: real 1920x1080 Tight framebuffer + XTest pointer injection).
- Keep slow terminal resize authorization off the shared multiplexed connection queue so other sessions and pings remain responsive, thanks @anagnorisis2peripeteia.
- Preserve live terminal resubscriptions when stale upstream close, error, or revocation callbacks arrive for a replaced subscription, thanks @anagnorisis2peripeteia.
- Reject native-VNC grant issuance unless the session remains live and controllable before and after minting, preventing teardown races from returning stale workspace credentials, thanks @anagnorisis2peripeteia.
- Preserve stalled card-run provenance by fencing lane completion and its audit event in one guarded D1 batch, preventing concurrent completion from overwriting terminal state, thanks @anagnorisis2peripeteia.
- Add opt-in single-folder sharing to Share This Mac with security-scoped bookmark persistence, negotiated
FSH1browsing, bounded native and browser download/upload streams, strict realpath containment, 512 MiB file and 256 KiB chunk limits, root-local temporary uploads with atomic rename and teardown cleanup, and host-controlled remote writes. - Add first-party browser access for registered Share This Mac desktops with a registration-owner-scoped Worker relay, WebCodecs H.264 and Tight/JPEG fallback, remote input, clipboard sync, resize pacing, and an ownership-token macOS publisher.
- Add persisted four-display Share This Mac selection with consecutive per-display Tailscale listeners and Fleet rows, four concurrent authorized viewers per display, multicast clipboard and aggregate viewer diagnostics, single-viewer resize fencing, independent per-session video pipelines, and primary-display refcounted system-audio capture.
- Add SPKI-pinned QUIC-first direct tailnet viewing on per-display ports 5911+, with the unchanged single-stream RFB protocol, a transparent two-second TCP fallback, shared session accounting, stable same-publication capability refresh across host recovery, host and viewer transport diagnostics, and opaque Fleet capability forwarding for future WebTransport probing.
- Require every direct Share This Mac tailnet listener to authenticate with a per-run in-memory 12-character password through ARD or VNC DES, add bounded source-IP failure backoff and lockout without serializing concurrent transports, native Keychain and browser sessionStorage credential flows with one-time-code autofill semantics, and an explicit relay-only RFB authentication bypass while leaving the owner-authenticated Worker relay wire unchanged.
- Bring the browser desktop viewer to near-native parity with feature-probed HEVC Main and RExt 4:4:4 decoding plus H.264/Tight renegotiation, negotiated AAC-LC
CAF1playback through a bounded AudioWorklet jitter buffer with gesture and visibility muting, and a hidden-by-default local codec, fps, throughput, audio-drop, and jitter overlay. - Add preferred hardware HEVC sharing with H.264 and Tight/JPEG fallback, Annex-B VPS/SPS/PPS decoding, ScreenCaptureKit dirty-rectangle idle suppression, persisted live Auto/Sharp/Smooth quality modes with mode-specific VideoToolbox maximum-frame-QP text-sharpness floors and one-shot static-text settling refreshes, throughput- and latency-aware bitrate control, and codec, target-bitrate, and changed-area stream diagnostics.
- Add decode-probed
C444negotiation for full-chroma HEVC Main 4:4:4 between Crabfleet Macs, SPS-verified host fallback, chroma-fenced keyframe resets, RExthvcCconstruction in the native viewer, 4:4:4-aware bitrate bounds, and active/fallback stream diagnostics while preserving 4:2:0 for Smooth and older peers. - Add negotiated system-audio streaming to Share This Mac with opt-in ScreenCaptureKit capture, AAC-LC at 48 kHz, serialized bounded
CAF1RFB messages, native jitter-buffered playback, live host audio control, and focus-aware viewer muting while leaving third-party VNC clients video-only. - Add bilaterally negotiated
QCTLper-viewer Auto/Sharp/Smooth quality control with strict fail-closed message parsing, independent session rate and chroma policy, per-host native and session-scoped browser pickers, host default fallback for older peers, and active viewer-mode diagnostics. - Add negotiated client-side cursors to Share This Mac with standard CursorWithAlpha, classic Cursor, and PointerPos RFB rectangles, all-viewer capture-baking reconciliation, 60 Hz deduplicated host polling with local-input echo suppression, and native and browser remote-pointer overlays.
- Add a VideoToolbox-backed Open H.264 RFB pipeline for Share This Mac with up to 60 fps capture, adaptive 1.5–30 Mbit/s rate control, automatic Tight/JPEG fallback, live stream stats, larger resize limits, and a persisted host-enforced view-only mode.
- Exchange full UTF-8 clipboard text between the native Mac viewer, Share This Mac hosts, and any Extended Clipboard-capable VNC server by completing the RoyalVNCKit fork's extension stub, keeping Latin-1 cut text as the fallback and dropping malformed extension bodies without tearing down the connection.
- Sync the host Mac's clipboard with the connected peer in both directions during Share This Mac sessions, with a pre-share opt-out, echo suppression, and the shared 1 MiB text bound; previously client cut text was discarded and the host never sent its clipboard.
- Add persisted send-only and receive-only clipboard directions to the native viewer's focus toolbar; automatic sync respects the direction while the explicit Send and Get actions keep working.
- Honor viewer desktop-size requests in Share This Mac by announcing ExtendedDesktopSize, aspect-fitting the request up to the display's native pixel resolution, and re-targeting the live capture, so the shared desktop follows the viewer window.
- Let Share This Mac capture a chosen display instead of always the primary one.
- Add saved-host Wake-on-LAN to the native macOS client with validated optional MAC and broadcast profile metadata, manual UDP port 9 and 7 magic packets, non-fatal notices, and an off-by-default single wake-and-TCP-retry path limited to initial transport failures, with same-L2 and subnet-router relay constraints documented.
- Add a "Start sharing when I log in" toggle that registers the bundled app as a login item and auto-starts the private share for unattended access.
- Keep Share This Mac permission status and start availability synchronized with Screen Recording and Accessibility grants made in System Settings while the sheet is open.
- Harden Share This Mac tailnet identity resolution with stable multi-IPv4 selection and candidate exposure, MagicDNS-free hostname fallback, actionable backend-state and malformed-status errors, and an explicit unsupported IPv6-only listener result.
- Warn without blocking Share This Mac when Tailscale reports a numerically suffixed duplicate registration, while continuing to advertise the current
Selfnode address. - Add the Crabfleet Connect foundation with a shared Go RFB 3.8 host core, per-run VNC-DES authentication, Tight/JPEG and client-side cursor/input support, a CI-safe synthetic backend, and a Linux X11 MIT-SHM/XFixes/XTest backend plus cross-compiled CLI, while documenting deferred codecs, Wayland, ARD, audio, and hardware validation.
- Add a pure-Go Windows Crabfleet Connect backend with synchronized GDI BitBlt primary-display capture, full-frame RGBA dirty updates, SendInput absolute pointer, wheel, and keyboard injection, active-layout shortcuts, Unicode and legacy X11 keysym text mapping, retry-safe teardown, and amd64/arm64 cross-build proof, while deferring DXGI, multi-monitor, per-monitor-DPI, packaging, and real-hardware validation.
- Extend the deck design language to the Quick Connect and desktop connection sheets: card-based fields and switches, gradient headers, pinned dark scheme, and a shared height-capped scrolling sheet container.
- Redesign the Share This Mac sheet in the app's dark deck design language: pulsing readiness beacons with two-line status rows, custom capsule switches with icon tiles and captions, an animated segmented quality control, a live phase badge, and a restyled connect card — no behavior changes.
- Blend the macOS title bar into the desktop deck, align its unified top band, and add hover, focus, refresh-progress, and empty-state interaction polish.
- Add a default-off Share This Mac Remote Desktop-permission experiment with persisted Privacy Settings selection, live ScreenCaptureKit capability polling, direct System Settings guidance, and unchanged Screen Recording defaults for macOS 26 capture-indicator research.
- Make terminal input delivery durable across multiplex subscribers, apply backpressure until an attachment owns initial output while waking blocked readers to discard and acknowledge output for one-shot confirmed messages, retain pre-attach closure, prefer completed input over later transport shutdown, reject denied or unacknowledged input explicitly, prevent delivery into retired attachments and wait for their frame consumers even when input reads cannot be canceled, bound serialized browser input backlog by frame count and bytes while preserving one ordered completion per dropped frame, enforce relay-owned runner generations before forwarding GitHub Actions input and acknowledgements, snapshot SSH connection limits before launching handlers, make confirmation serialization cancelable, bound attachment confirmation waits, serialize every acknowledgement-aware input source and per-subscription completion event, wake uncancelable attachments when their context ends, retire connections after ambiguous confirmation timeouts, negotiate bounded one-shot input acknowledgements across rolling upgrades without waiting on empty payloads, keep configured HTTP timeouts from canceling established sockets, scope rejected writes without dropping live subscriptions, and send attributed commands atomically to prevent interleaving.
- Add connection-query-negotiated
CFR1input, output, and acknowledgement frames across GitHub Actions runner and internal viewer relay boundaries, confirm viewer negotiation before leaving raw fallback during mixed deployments, document the independent legacy viewer fallback, buffer split UTF-8 within byte, frame, and age bounds until the string-only Node adapter delivers it to the PTY before acknowledging every contributing frame, define that adapter's UTF-8-only output contract while preserving opaque bytes for byte-oriented adapters, close the runner socket when its PTY exits, prevent binary PTY output from colliding with relay control frames, and keep multiplex dispatch responsive while framed input acknowledgements are pending. - Harden Share This Mac against stale starts and responses, canceled starts stranded in transition, self-connections, leaked subprocess environment, stalled Tailscale and RFB handshakes, successful commands whose descendants retain output pipes, stale desktop registrations including listener-failure, ambiguous committed publication reconciled by stable publication identity, and application-termination races with durably retained cleanup retries, legacy publishers mutating or deleting token-owned registrations, concurrent teardown calls that could outpace application termination, completed teardown operations coalescing a later stop, dropped auto-starts, stuck remote input including releases retained through revoked Accessibility trust and teardown with bounded retries and no retry when no input is held, and destructive non-text or empty clipboard changes while preserving repeated remote text, X11 Unicode input, proxy, custom-CA networking, and validated Crabbox config/state paths.
- Fence Share This Mac registry cleanup with explicitly negotiated per-registration ownership tokens, require a valid publication identity before selecting token ownership, and return the exact atomically written registration row so delayed or overlapping current publishers cannot displace cleanup authority, while preserving tokenless registration and cleanup for rolling upgrades with legacy clients or servers.
- Harden the bundled RoyalVNCKit fork across ARD and UltraVNC authentication and parameter validation, composed Unicode keysyms with legacy ASCII scalars, Tight and ZRLE parsing, non-trapping bounded zlib streams, RFB Fence-synchronized color-depth transitions with atomic capability publication, premature-response rejection, and fail-closed legacy handling, CopyRect, EOF handling, reconnects, credential cancellation and release after handoff, and cursor channel preservation.
- Harden session lifecycle concurrency with atomic card claims and duplicate-first claim results, single-winner GitHub Actions credential rotation, monotonic exact authenticated-revision fences on runner writes, terminal session-status fences, revision-fenced lifecycle updates and grant revocation, exclusively claimed rollback recovery for Sandbox credential rotation, rejection of live legacy registration claims during migration without staging renewable legacy claims, staged-rotation fences that block legacy policy mutation while new-worker claims are live but release abandoned rows for rollback compatibility, persisted staged lookup identities across namespace changes with exact current-identity fallback for mixed-version rows, ownership-fenced repair of incomplete and rotated lookup sets before credential rotation, explicit retirement of obsolete durable identities, idempotent recovery after ambiguous committed promotion, R2-clean reservation rollback, preserved Sandbox attachment state, retained registration data for superseded runtime workspace cleanup, and durable observed-deletion markers that terminate cleanup after post-delete crashes.
- Close final terminal and desktop publication race windows by carrying the initial GitHub Actions runner generation through viewer authorization, translating generation-fenced acknowledgements for legacy framed viewers, serializing and bounding per-runner PTY input by frames, bytes, and age, matching generation-fenced local send failures, ordering raw and confirmed Go client acknowledgements, bounding shutdown when terminal writers block, rejecting malformed desktop recovery IDs as client errors, preserving idempotent publication retries across mixed worker versions, and retaining uncertain Share This Mac publications when older servers lack the recovery route.
- Preserve bounded opaque profile IDs for fixed runtime adapters while rejecting unroutable or ambiguous adapter routes only when provisioning depends on them, so mixed migration configuration cannot break unrelated control-plane reads; durably claim and retry superseded workspace cleanup without touching the replacement workspace; also reject malformed encoded session routes, numeric literals that become integers only after precision loss, and invalid-Unicode JSON event values, and reconcile browser history drawers and focus on back/forward navigation.
- Preserve upgrade and teardown authority by leaving pre-lookup-migration credential registrations recoverable from current and historical runtime identities, retaining GitHub Actions runner generations after queues drain, scoping Share This Mac recovery state to the normalized API origin and stable owner, allowing idle termination after unavailable recovery lookup while retaining active cleanup vetoes, terminating timed-out or canceled Tailscale descendant process groups, clearing only definitive failed publication intent, quiescing remote-input producers before final release, rejecting UltraVNC Diffie-Hellman elements at
p - 1, and synchronizing complete RFB pixel-format and encoding transitions with protocol-required ZRLE resets. - Finish the audited terminal, credential, runtime, and native-app lifecycle boundaries by explicitly negotiating the generation-fenced GitHub Actions runner protocol, retiring stale and overflowing runner input queues, capturing relay replacement during viewer authorization, fencing retired Go terminal attachments, repairing credential lookup namespaces with rollback-compatible staging, requiring replayable runtime-adapter deletion tombstones, validating Apple Remote Desktop Diffie-Hellman groups, keying desktop publication cleanup by the API host ID, and requiring exact retained identity before uncertain publication recovery; the runner guide now preserves raw fallback, bounds admission before serialized restricted steering, and distinguishes unknown delivery from rejection.
- Close the final review blockers by requiring an exact live credential-policy lease at promotion, negotiating strict runtime-adapter deletion tombstones without breaking legacy
404release semantics, disconnecting VNC sessions when pixel-format capability probes cannot establish a safe ZRLE boundary, classifying aborted JSON body streams as bad requests, and preserving live terminal subscriptions when browser history restores the sessions grid. - Complete the final audit follow-up by fencing rollback against newer legacy credential generations, keeping viewer acknowledgement timeouts from detaching live GitHub Actions sessions, fencing queued documented-runner input after relay replacement, generating ignored embedded assets before parity tests import them, resetting ZRLE exactly at pixel-format boundaries, preventing delayed tokenless desktop cleanup from deleting replacement publishers, skipping idle recovery I/O when no local state exists, and stopping canceled auto-share preflight.
- Resolve final audit blockers by preserving unknown GitHub Actions input outcomes across runner replacement, disconnect, upstream close or error, bounded PTY-write failure, and post-write confirmation loss, making terminal confirmation races prefer completed delivery, retiring terminal connections after late detached-writer failures, replaying control grants across attachment gaps, retaining rollback recovery and authorized namespace retirement after a staged credential write begins, reserving expired write-started credential rows for recovery, requiring active credential generations to match the exact current lookup set, proving interrupted pre-fence migration recovery, blocking session deletion while staged credential rows remain, validating ARD safe-prime groups and nonzero key material with bounded accepted-prime caching, deferring partial-fence ZRLE resets to a trailing synchronization boundary, rejecting legacy mutations and deletions of token-owned desktop registrations, discarding definitively unowned publication recovery without tokenless cleanup, documenting the opaque publication-ID contract, completing ambiguous legacy publication cleanup despite persistence failures, and holding generated-asset tests under a crash-released lock through module consumption.
- Replace the vendored D3DES implementation carrying unlicensed 1998 VNC modifications with a per-call CommonCrypto DES shim implementing the VNC bit-reversed-key variant, remove the process-global key schedule so concurrent VNC password authentication is safe, drop the d3des build target, and add known-answer coverage.
- Drop the RoyalVNCKit fork's last third-party crypto dependency, CryptoSwift: use CryptoKit for MD5, CommonCrypto for AES-128-ECB, and an in-fork constant-free pure-Swift big integer with
SecRandomCopyByteskey generation and Miller-Rabin safe-prime checks for Apple Remote Desktop Diffie-Hellman, with known-answer coverage. - Refresh Worker, browser, Go CLI, container, and CI dependencies, including Cloudflare Sandbox SDK and image 0.12.8 with a parity regression test; adopt pnpm 11 while preserving the build allowlist and 48-hour release-age policy, and hold Wrangler at 4.116.0 because newer Miniflare 5 alpha versions reject the existing D1 test fixture (#119).
- Pin Crabbox coordinator deployment to an immutable source revision and verify downloaded Crabbox release archives before image assembly, always enforcing the repository digest for the default version and requiring an explicit architecture checksum for non-default versions.
- Disable the retired
openclaw/clawsweeper-homeandopenclaw/crabbox-fleetrepository targets while keepingopenclaw/test-permissions-checkenabled for permission probes. - Stabilize the required macOS test gate by prewarming ARD before QUIC listener-readiness deadlines, bounding general test concurrency, isolating environment-sensitive integration tests, and waiting for complete subprocess PID fixtures; production authentication and listener admission remain unchanged (#115, #116).
- Reject cross-origin browser terminal WebSocket handshakes before ambient session cookies can reach the terminal hub, while preserving authenticated service clients and originless non-browser clients, thanks @Hinotoi-agent.
- Require every GitHub Actions session resume to prove the existing stable owner before rotating its agent credential, preventing ownerless
workKeyreuse from taking over another action session, thanks @Hinotoi-agent. - Fit the native Mac VNC desktop flush to the available window, continuously synchronize its remote resolution to the viewport and current display pixel density when supported, compact the surrounding controls, and use an available stable signing identity for local app bundles so Keychain access survives rebuilds.
- Preserve the real same-origin
Originheader on browser-approved native Mac authorization forms so Chromium can complete the device link without weakening CSRF validation. - Connect desktop-capable Crabbox Fleet sessions directly in the macOS app through session-scoped, one-time Crabbox grants and a coordinator-backed VNC relay, without publishing provider lease IDs in Fleet or exposing coordinator SSH keys; grants reach the CLI only on stdin and helper teardown remains tied to viewer lifecycle.
- Classify stalled or errored workspace provisioning as attention, exclude it from the Starting count, and surface the redacted reconciliation reason in Fleet.
- Add private per-user desktop-host registration so native macOS shares appear in Fleet with direct same-tailnet VNC endpoints.
- Let the macOS app use saved and ad-hoc VNC connections without requiring a deployment session.
- Negotiate Apple Remote Desktop authentication with current macOS Screen Sharing servers.
- Add browser-approved native macOS device linking with live GitHub authorization checks, 24-hour read-only Fleet tokens, deployment-scoped Keychain storage, and real Fleet data instead of preview fixtures or raw session cookies.
- Let the macOS app fall back to OAuth 2.0 discovery, explicit external-provider trust, dynamic client registration, PKCE, a loopback callback, audience matching, and a fresh Keychain namespace with refresh-token rotation when an identity gateway protects Crabfleet's exact read-only native session and Fleet ingress.
- Add app-owned macOS desktop hosting with ScreenCaptureKit, bounded Tight/JPEG RFB streaming, Accessibility-authorized input, an exact active-tailnet bind, and same-user Tailscale peer admission without Apple Screen Sharing or a public relay.
- Let app-owned macOS desktop hosting start in view-only mode with Screen Recording alone; Accessibility is now optional and enables remote keyboard and pointer input.
- Use Tailscale's CLI entry point for unattended macOS desktop hosting so background startup can resolve the active tailnet without trying to launch the Tailscale GUI.
- Let the native macOS bundle use a stable Apple Development or Developer ID signing identity, with optional hardened-runtime timestamping, so privacy grants can survive iterative rebuilds and distribution builds are ready for notarization.
- Move browser terminal transport onto the shared
@openclaw/libterminalhub while keeping Crabfleet authorization and session policy local. - Update
@openclaw/libterminalto 0.3.1 for terminal lifecycle, Worker asset generation, and package-validation fixes. - Add private-by-default tenant isolation for cards and sessions, trusted-proxy automatic onboarding, stable owner identities, expiring named viewer/controller grants with UI/API revocation, and current authorization checks across terminal, desktop, diagnostics, checkpoints, logs, transcripts, metadata, cleanup, and child-session paths.
- Revalidate named principals against current authentication policy, migrate only unambiguous legacy subjects, reject subjectless private control approvals, and scope Fleet policy totals to visible sessions.
- Complete the tenant-isolation cutover by removing legacy-writer triggers, repeated backfill/finalizer commands, mutable actor fallbacks, owner adoption, and legacy OpenClaw replay hashes.
- Keep teardown revocation available, bind OpenClaw replay identity and Sandbox refresh to stable owners, conceal hidden terminal state, and render destructive controls only from server-computed per-session authority.
- Keep shared-mode live terminal reads behind control or a named grant, revision-fence concurrent grant revocation, and bind OpenClaw replays to exact stable-owner request hashes.
- Bind every OpenClaw crabbox and GitHub Actions session to an explicit stable human owner, retain service authority only across validated OpenClaw lineage, and keep bootstrap ownership stable across token rotation.
- Fix local Vite development with
@openclaw/libterminalby reserving Worker-served Ghostty aliases for production builds and serving the local WASM, icons, and logo without generated placeholders. - Keep the mobile navigation and named-access dialog within narrow viewports.
- Keep each agent credential scoped to its authenticated session and direct children instead of inheriting access to every session owned by the same human.
- Add atomically claimed recurring card intervals with constant-time catch-up, crash-recoverable leases, scheduler/API proof, and coalescing for active or capacity-blocked runs, thanks @Jhacarreiro.
- Reuse
@openclaw/libterminalfor terminal protocol codecs, Worker relays, Ghostty assets, and browser lifecycle while keeping Crabfleet authorization and session policy local. - Fix automated Worker deployments by converging the app Custom Domain with the DNS-scoped deployment token instead of requiring zone-route access from the Worker token.
- Add session-scoped OpenClaw terminal embed tickets, deployment-configured interactive runtime choices, explicit Ghostty WASM delivery, and shared embedded PTY readiness without restoring provider or protocol compatibility paths.
- Keep SSH terminal dimensions synchronized after attach and verify the TypeScript and Go multiplex clients against shared protocol vectors.
- Remove the configurable PTY bridge so managed terminal upstreams are limited to built-in Sandbox, versioned runtime-adapter attach, and GitHub Actions relay behind the multiplex terminal protocol.
- Remove generic create-only provisioning, the external Cloudflare runner, and the ClawFleet compatibility provider so managed workspaces use only built-in Sandbox or the versioned runtime adapter.
- Extract SSH gateway authentication, key linking, and session creation; remove the old Crabbox SSH environment and fingerprint-header aliases plus the
stopCLI alias. - Remove unsupported provider stop/recovery compatibility so live lifecycle mutations are limited to Sandbox, runtime-v1, and GitHub Actions.
- Remove legacy app/product hosts, product path rewrites, Workers.dev exposure, the
lsCLI alias, and obsolete provider cleanup warnings. - Remove legacy Sandbox credential-policy storage migration, repair claims, and read retries; reject old generations, rotate stale SQL references on registration, and purge unreadable stored credentials during fenced cleanup.
- Extract terminal multiplex composition, upstream routing, lifecycle transitions, sharing authorization, multiplayer input, and clipboard uploads into one service; harden pasted filenames against dot-prefixed path-like input.
- Extract runtime-adapter desktop connection minting and durable access revalidation into one service; remove the live legacy
vncUrlredirect fallback. - Extract Sandbox diagnostics and checkpoint authorization, orchestration, backup/restore, and registry access into a directly tested session-resource service.
- Extract card creation, run claims, heartbeat/stall transitions, actions, projections, and SQL persistence into a directly tested lifecycle service and repository.
- Extract CRABBOX.md parsing, fetch/cache policy, failure fallback, summaries, and SQL persistence into a directly tested workflow service and repository.
- Extract control-plane policy, allowlist, repository administration, validation, audit ordering, and SQL persistence into a directly tested admin service and repository.
- Extract GitHub issue/PR reference validation, repository selection, GraphQL batching, public fallback, mapping, and rate-limit handling into a directly tested service.
- Extract superseded runtime-adapter stop recovery and confirmed-release CAS persistence into a directly tested release service and repository.
- Move interactive-session normalization, reservation retries, provisioning, recovery, audit, and durable result assembly into the creation service.
- Move GitHub Actions registration, work-state, and runner-connection persistence into one repository with shared service composition.
- Move OpenClaw stop eligibility, agent credential reads, session ID allocation, and audit persistence out of the Worker entry point into their owning repositories.
- Extract OpenClaw GitHub branch validation, lookup, creation, and concurrent-create recovery into a directly tested service.
- Move interactive-session summary and purpose authorization, validation, fenced persistence, archive refresh, and reread into the metadata service.
- Extract GitHub Actions stop persistence, runner disconnect, archive refresh, and terminal finalization ordering into a directly tested service.
- Extract browser session credential policy and browser-visible link origins into directly tested Worker services.
- Centralize failed provisioning results and provider-error redaction across managed Sandbox, standalone Sandbox, and runtime-adapter lifecycle paths.
- Extract OpenClaw nudge and stop validation, audit ordering, terminal delivery, and best-effort delivery records into a directly tested mutation service.
- Extract OpenClaw crabbox normalization, replay handling, branch preparation, timeout policy, and creation audit into a directly tested service.
- Extract interactive-session lineage normalization, parent visibility, and canonical root derivation into a directly tested service.
- Extract interactive-session reservation supervision, preparation rollback, activation, request evidence, and provisioning order into a directly tested service.
- Extract visible interactive-session reads and atomic session/replay reservation inserts into a directly tested repository.
- Move interactive-session reservation retry and idempotent replay recovery into the creation service.
- Extract runtime-adapter configuration, control-plane, token, and create-preflight policy into a directly tested module.
- Extract provisioning-result compare-and-set persistence, pending-adapter fallback, event recording, and terminal finalization ordering.
- Centralize interactive-session reservation row defaults, adapter preparation state, replay identity, and sandbox lease ownership.
- Centralize interactive-session create request defaults, profile policy, capability selection, and descriptive fields.
- Centralize interactive-session reservation tokens, sandbox lease ownership, and runtime-adapter create identity.
- Extract superseded runtime-adapter and Sandbox provision recovery from session creation.
- Move bounded interactive-session logs, event pagination/counts, and archive reads into the session repository.
- Centralize shared-session visibility and redaction of provider, terminal, lease, reconciliation, and control authority.
- Assemble visible interactive-session rows, recent logs, and archive metadata in the session repository.
- Move atomic interactive-session metadata/event persistence and terminal snapshot invalidation into the session repository.
- Extract sharing, multiplayer, and delegated-control mutations into a directly tested session metadata service.
- Extract terminal attach policy into a directly tested service and persist attach state plus evidence atomically.
- Extract interactive-session stop authorization, runtime routing, idempotency, cleanup sequencing, conflicts, and audits into a directly tested service.
- Extract runtime-adapter stop claim, provider outcome, retry evidence, create-resolution, and confirmed-release orchestration into a directly tested service.
- Move GitHub Actions stop transitions plus stop-state lookups into the session repository.
- Extract interactive-session ownership, management, multiplayer, and delegated-control authorization into one directly tested policy module.
- Move interactive-session archive cadence, D1 snapshots, R2 objects, cleanup, transcripts, and summaries into one archive module.
- Extract interactive-session capability, control, provider redaction, desktop, and Codex SSH presentation policy behind direct tests.
- Move terminal completion evidence, archive freshness checks, and finalization-marker persistence into one lifecycle module.
- Unify session event batching, message bounds, finalization invalidation, and best-effort archive refresh behind one service.
- Extract finalized-session admission, fenced transactional deletion, authorization filtering, and archive-object cleanup behind one service.
- Extract runtime-adapter reconciliation claims, transition projection, atomic evidence persistence, race recovery, and terminal finalization behind one service.
- Extract scheduled and targeted reconciliation admission, cadence limits, and terminal archive backfill behind one scheduler.
- Replace duplicate bounded-concurrency loops with one directly tested worker utility.
- Extract agent-session authentication and remove the legacy
X-Crabbox-Session-IDalias. - Extract GitHub Actions session validation, idempotent registration, token rotation, resume reset, runner replacement, and evidence ordering.
- Extract GitHub Actions work-state projection, heartbeat persistence, event suppression, terminal mapping, runner disconnect, and reread.
- Extract GitHub Actions runner-connect validation, lifecycle projection, heartbeat persistence, and durable connection evidence.
- Extract interactive terminal route selection, signed attach preservation, adapter authorization, and headers.
- Extract terminal WebSocket relay queues, output acknowledgements, message normalization, authorization polling, and peer close handling.
- Extract runtime-adapter lifecycle and terminal transport, coordinator binding selection, redirect refusal, and bounded response parsing.
- Centralize OpenClaw room visibility, log-free summaries, and bounded transcript sentinel/truncation policy behind direct query tests.
- Isolate OpenClaw recursive root-stop admission, reservation cleanup, lifecycle retries, reconciliation, and stable-completion polling behind a directly tested service.
- Extract OpenClaw root-scoped authorization, lineage supervision, reservation outcomes, rollback, and activation orchestration into a directly tested service boundary.
- Move OpenClaw room reads, reservation fencing, activation, rollback, cleanup polling, admission state, completion counts, and lineage reads into a directly tested repository boundary.
- Centralize repository normalization and OpenClaw request identity, semantic hashing, and durable replay lookup behind direct behavior tests.
- Centralize interactive-session types, capability defaults, hidden adapter identity, and database row/event/archive mapping in a directly tested model module.
- Give Worker users, allowlist roles, cookie sessions, trusted-proxy identities, GitHub OAuth/API membership, session-owned credentials, and secret encryption dedicated auth modules with behavioral coverage.
- Isolate Worker ingress authentication, trusted-proxy credential stripping, and independent service-route policy behind direct behavioral tests.
- Centralize Worker HTTP responses, security headers, status errors, JSON parsing, bearer authentication, and cookie handling behind a directly tested module.
- Give shared Worker models and the complete Kysely/D1 schema, dialect, factory, and batch execution dedicated foundation modules.
- Extract Worker environment and deployment/profile policy into testable foundation modules, replacing source inspection with behavioral coverage for public and client configuration.
- Centralize secure URL, origin, and literal-loopback validation across OAuth, trusted proxy, runtime adapter, and Fleet routing.
- De-duplicate the Go CLI and SSH gateway around shared control-plane models, authentication, lifecycle semantics, API calls, terminal operations, and terminal-safe session rendering.
- Unify managed terminal clients on the multiplex
/api/terminal/wsprotocol, remove direct PTY routes, and share one framed Go transport across the CLI and SSH gateway. - Connect Crabfleet lifecycle and terminal traffic to Crabbox through a Cloudflare service binding and deploy an identical route-scoped credential atomically across both coordinators.
- Make OpenClaw room trees recoverable with idempotent Crabbox creation and root-level admission freeze plus recursive stop.
- Add root-fenced OpenClaw service supervision for Crabbox room trees, including current state, bounded transcript evidence, targeted terminal nudges, audited stop requests, and canonical browser URLs.
- Allow MultiCodex to use a dedicated service capability without rotating the existing OpenClaw automation token.
- Safely reserve room capacity and prepare missing service-requested branches from an explicit base branch before Crabbox provisioning.
- Add deployment-configured Codex SSH handoffs for ready provider workspaces, with safe alias templating, manager-only session metadata, and copyable local setup commands that keep provider behavior outside Crabfleet.
- Route generic runtime profiles to distinct versioned adapters through a validated deployment URL template, reject profile-rewriting responses, and preserve immutable lifecycle control-plane fences.
- Add a deployment-configured runtime profile selector with generic labels, targets, capability previews, server-side allowlisting, and CLI/SSH profile overrides.
- Reconcile and de-duplicate the full documentation set against shipped runtime, session, persistence, security, API, native-client, and deployment behavior.
- Strip upstream authorization credentials from authenticated trusted-proxy requests before app and terminal routing.
- Add deployment-neutral trusted reverse-proxy identity with exact-origin and shared-secret proof, existing allowlist authorization, cross-origin mutation rejection, fail-closed assertions, cookie isolation, and downstream credential stripping.
- Add a native macOS Crabfleet VNC control deck with generic RFB 3.3/3.7/3.8 connections, Metal rendering, six warm desktops, paced previews, fast focus transitions, saved profiles, and stabilized opt-in clipboard synchronization.
- Redirect
crabfleet.ai,www.crabfleet.ai, and product aliases to the canonical Crabfleet docs while keeping login and app traffic oncrabfleet.openclaw.ai. - Reject runtime-adapter redirects with Cloudflare-compatible manual redirect handling instead of using unsupported Worker fetch semantics.
- Make create, run, and admin drawers real modal dialogs with keyboard focus containment and restoration.
- Move the public product hosts to safely converged Worker Custom Domains and fail deploys unless app and product endpoints are reachable.
- Bound Crabbox terminal output with negotiated acknowledgements on the multiplex terminal hub.
- Enable the OpenClaw deployment's versioned Crabbox runtime adapter with a stable tenant namespace.
- Add comprehensive documentation for durable GitHub Actions sessions, including registration, runner and viewer relay, work-state heartbeats, Codex steering, resumption, completion, cancellation, authentication, archives, and troubleshooting.
- Name versioned provider-backed workspace lifecycle actions Delete across Fleet, the Go CLI, and SSH; keep the provider stop wire action internal; and fail closed without adopting or deleting a pre-existing adapter workspace on an explicit ID conflict.
- Keep GitHub Actions sessions out of legacy workspace-stop reconciliation and let operators end their Crabfleet terminal session without claiming to cancel the underlying workflow run.
- Add durable steerable GitHub Actions sessions with service registration, scoped runner URLs, work-state heartbeats, Fleet metadata, and a SessionControlDO PTY relay.
- Add a tenant-namespaced versioned runtime lifecycle adapter with replayable idempotent create, monotonic workspace identities, CAS reconciliation, durable terminal finalization, confirmed provider release before failure/stop, presence-aware capability/expiry tracking, authenticated transient VNC redirects, and deployment-neutral configuration.
- Reconcile runtime lifecycles and every adapter's terminal archives on cron and direct access, preserve partial capability-object defaults while honoring authoritative lists and explicit terminal withdrawal, make PTY availability server-authoritative, preserve opaque signed terminal and desktop URLs byte-for-byte, retain adapter failure evidence through confirmed release and exact session-version archive finalization, preflight adapter credentials before session allocation, bind every external lifecycle to its immutable registered control plane, generation-fence managed and standalone Sandbox credential ownership across crashes and late requests, repair incomplete equal-count archives, run teardown only after an exact cleanup CAS, use unique concurrent archive attempts, and transactionally remove D1 archive pointers before best-effort R2 object cleanup.
- Harden adapter and terminal boundaries by redacting connection credentials from durable messages, requiring byte-exact grammar-valid workspace identity echoes, rejecting malformed non-null expiries, keeping recurring WebSocket authorization provider-free, and paging credential cleanup with durable fair-progress cursors while retaining Sandbox failure evidence.
- Fence ambiguous create replay during stop to the exact registered lifecycle, require immutable-request ownership claims before the stateless hook can provision a managed session ID, expose standalone Sandbox terminals through their own bearer-authenticated WebSocket route, atomically pair terminal events with archive-finalization markers, and prevent older equal-count session snapshots from replacing newer archive pointers.
- Require an exact durable lease or provision/refresh claim for every Sandbox credential-policy transition, atomically activate standalone owners with their matching policy generation, redact structured and header-form provider credentials, fence slow reconciliation by the original session revision and completion time, and reject adapter base URLs containing raw query or fragment delimiters.
- Atomically fence credential-policy cleanup against its durable owner and revalidate ownership before unregistering, keep versioned-adapter terminal credentials behind Worker-owned PTY routes, and rotate a fresh agent token into every managed Sandbox provision claim.
- Make Sandbox terminal intent monotonic under stop/failure races, fence initial provision completion against managed retries and refresh ownership without rejecting concurrent metadata writes, atomically version terminal metadata with its event and finalization marker, keep live credential-registration failures retryable, clean both sides of interrupted refreshes, expire standalone Sandboxes with authenticated stop, and exactly reserve managed session IDs from standalone use.
- Keep standalone Sandbox terminals behind a lifetime-authorized Worker WebSocket proxy and terminate their execution sessions during durable cleanup, fail closed legacy unfenced credential policies, isolate and persist per-owner cleanup failures, reserve managed IDs case-insensitively across upgrades, preserve SSH-link state across canonical OAuth redirects, reject lost runtime-stop claims, redact arbitrary escaped connection URLs, make terminal completion/release revisions monotonic, and retain single-read redacted adapter create/DELETE evidence through final archives.
- Reject stale same-generation credential-policy registrations, preflight and atomically stage failed managed Sandbox claims, require the provision bearer for standalone stop after backend removal, and backfill D1-only terminal archives when R2 is enabled later.
- Proactively generation-wrap migrated legacy Sandbox credential policies under a live durable lease before cleanup, preserve live pre-token sessions, and use crash-safe cron retries that retain unattended session credentials.
- Bound every runtime-adapter response stream, revalidate desktop authorization after minting, make legacy local stops atomic with scheduled crash recovery, and redact credentials before opaque provider identifiers.
- Recover active credential policies after a post-registration crash and redact provider identities from structured adapter errors.
- Support an optional authoritative
GITHUB_REDIRECT_URIdeployment binding with strict HTTPS callback validation, canonical-origin login handoff, and callback host/path enforcement while retaining safe request-origin defaults. - Replace native browser confirms and prompts with accessible Crabfleet dialogs for session cleanup, shutdown, and share links; keep dialogs above drawer navigation on Escape.
- Sharpen the app visual system with flatter controls, tighter surfaces, and restrained overlay elevation.
- Add Crabfleet session supervision metadata, owner/session tree listing, transcript retrieval, PTY messaging, and summary updates for Codex-spawned Codex sessions.
- Redesign Fleet as an operational command view with real readiness data, compact connection paths, clearer operator groups, and denser session cards.
- De-duplicate interactive lifecycle, status, terminal-ready, log URL, icon, and copy-command behavior across the app.
- Fix GitHub OAuth login after the canonical host move by honoring the registered
crabfleet.openclaw.aicallback URL. - Add the Crabfleet v2 fleet-control spec, redacted fleet registry API, and dashboard summary for visible Codex crabboxes.
- Make
crabfleet.openclaw.aithe OpenClaw app/API canonical URL, redirect old OpenClaw aliases there, and keepcrabfleet.aiindependent as the public product site. - Deploy the source-controlled
crabfleet.aiproduct router before the app Worker so product traffic cannot drift back to an app redirect. - Make manual product and aggregate deploys converge their Cloudflare routes instead of silently depending on existing bindings.
- Route the built-in interactive provision hook in-process and default new sessions to Cloudflare Sandbox so production creates usable Codex terminals without a crabbox adapter.
- Keep Cloudflare Sandbox model and GitHub credentials in the Worker path, add DO-backed sandbox credential/checkpoint state, and add CLI lifecycle commands for doctor/status/stop/checkpoint/restore.
- Show failed and expired Codex sessions as stable log replays instead of remounting Ghostty terminals.
- Keep
docs.crabfleet.aiconverged to the GitHub Pages CNAME instead of the Crabfleet wildcard redirect. - Document GitHub/SSH as normal Crabfleet onboarding and bootstrap token as owner break-glass only.
- Add durable crabbox session log archives, Fleet WebVNC/log actions, and
crabfleet logsplus SSH gateway log viewing. - Split Fleet and Board into separate app pages, with Fleet as the default grouped view of every visible crabbox by person.
- Tighten the login SSH command width for
crabd.shand tuck bootstrap-token login behind a recovery disclosure. - Redesign the Crabfleet logo and favicon around a single fleet node-grid mark, and serve a real 1200×630 social card instead of stretching the 96px logo.
- Move SSH onboarding defaults to
crabd.sh, with deploy-time domain enforcement.
- Rename the remaining old runtime, cookie, docs, asset, migration, and SSH gateway surfaces to Crabbox names, expiring old sessions and requiring SSH keys to be relinked.
- Add an OpenClaw service crabbox creation endpoint and make the Go CLI attach by default after API-created crabboxes.
- Add GoReleaser release automation for the
crabfleetCLI and dispatch Homebrew formula updates toopenclaw/homebrew-tap. - Rename the product surface to Crabfleet, make Crabbox the app/CLI default, add fleet-by-person dashboard tiles with WebVNC actions, and introduce a Go/Kong
crabfleetCLI. - Restyle the generated docs site and Worker
/docs/page with the new Crabfleet dashboard look. - Keep unauthenticated app loads on the Crabfleet login screen unless the browser has already completed GitHub sign-in before.
- Redesign the Crabfleet login and app shell with SSH-first onboarding, live dashboard metrics, session charts, and a Codex session list.
- Add a Go SSH gateway with GitHub OAuth key onboarding, linked-key auth, session listing, Codex session creation, and PTY attach support.
- Treat missing Cloudflare Sandbox terminal sessions as already removed before recreation so fresh Codex session provisioning can recover instead of failing with
Session 'terminal-...' not found. - Persist per-session GitHub OAuth credentials inside Cloudflare Sandbox terminals so
ghandgit pushkeep working after Codex starts. - Add opt-in multiplayer mode for interactive Codex sessions so submitted prompts are prefixed with the current actor. Thanks @RomneyDa.
- Expand the Codex sessions grid to full available height when only one session is visible.
- Pre-bake Cloudflare Sandbox images with Codex, pnpm, GitHub CLI, Crabbox, and common build/debug tools, plus a session diagnostics endpoint.
- Trust the Cloudflare Sandbox workspace root as well as the checked-out repo so provisioned Codex sessions skip the directory trust prompt.
- Provision Cloudflare Sandbox Codex workspaces through explicit setup and PTY sessions so new sessions open with the selected repo checked out.
- Expose the Cloudflare Sandbox control port from the Crabfleet container image so production Codex sessions can create workspaces.
- Use the fresh per-session Cloudflare Sandbox default session instead of a second named execution session for Codex workspace provisioning.
- Retry transient Cloudflare API failures during automatic Worker deploys.
- Auto-start the configured Codex command once when a new Cloudflare Sandbox shell opens, then return to bash after Codex exits.
- Require Cloudflare Sandbox workspaces to contain a real repo checkout before marking interactive Codex sessions ready.
- Start Cloudflare Sandbox terminals with plain bash from the prepared workspace instead of a generated startup script.
- Start each Cloudflare Sandbox Codex session with a fresh sandbox/terminal lease so recycled session IDs do not attach to stale shells.
- Open Cloudflare Sandbox Codex sessions into a reusable shell with Codex pre-authenticated from the Worker OpenAI key instead of making Codex the terminal process.
- Build each Cloudflare Sandbox workspace inside the terminal execution session and recreate it on attach so PTY disconnects do not permanently strand a live Codex shell.
- Use the Worker GitHub token as a fallback for Cloudflare Sandbox checkout and
ghsetup when the browser session has no stored GitHub OAuth token. - Keep failed Codex session cleanup from leaving stale focused terminals behind, and make Sandbox checkout failures non-fatal with visible diagnostics.
- Auto-continue to GitHub OAuth for unauthenticated app loads when GitHub login is available.
- Normalize interactive Codex commands so
--yolocannot be stored or launched as--yolosandbox. - Pass encrypted per-session GitHub OAuth credentials into Cloudflare Sandbox Codex sessions so
ghand git can push/open PRs as the signed-in user. - Render
/sessions/:idlinks as best-effort Codex session cards before authenticated or shared data loads. - Keep provisioning Codex session tiles on a polished loading surface instead of replaying stale terminal logs.
- Show a clean provisioning placeholder for new Codex sessions and dispose stale terminal mounts when switching sessions.
- Answer Ghostty OSC foreground/background color queries and advertise truecolor Ghostty env in Codex sessions.
- Update provisioned Codex CLI sessions to npm
@openai/codex@latestbefore launch. - Keep the new Codex session drawer above the full-screen sessions grid.
- Hide Chrome's native contenteditable caret inside Ghostty session tiles.
- Add persistent new Codex session actions to the sessions grid empty state and toolbar.
- Keep inactive card runs out of the Codex session grid after dead session cleanup.
- Add dead Codex session cleanup actions and suppress redundant
mainlabels in session tiles. - Clean up the Codex session grid columns control so it no longer looks like nested buttons.
- Stop Codex session terminals from stealing grid scroll position while tiles mount or reconnect.
- Make
/sessionsthe Codex session grid route and reduce each session tile to maximize, share, and confirmed close actions. - Stop dead Codex PTYs from auto-retrying forever and keep passive terminal reconnects from reordering the session grid.
- Rewrite the Codex session grid with fixed non-overlapping terminal tiles and lazy offscreen terminal mounting.
- Stabilize Codex session grid headers so live status and controls no longer flicker or shift during scrolling.
- Add a GitHub Actions Worker deploy workflow for automatic Cloudflare deploys on
mainpushes. - Simplify the Codex session grid with larger terminal tiles, hover-only actions, and a quieter layout menu.
- Migrate the app shell to Preact/Vite modules while preserving inlined Worker assets.
- Add an editable, persisted Codex session grid with column density, drag reorder, and per-tile sizing.
- Add browser clipboard copy/paste controls for live Codex terminals, including image/file paste into Cloudflare Sandbox workspaces.
- Add a multiplexed binary terminal WebSocket protocol for Codex session grids and shared viewers.
- Add read-only Codex session share links with owner-approved terminal control requests.
- Install bubblewrap and default interactive Codex sessions to yolo mode with a clean PTY buffer.
- Keep Escape routed to focused Codex terminals instead of closing the session drawer.
- Enable the experimental Codex goals feature in provisioned interactive sessions.
- Fix interactive Codex session provisioning to show the terminal immediately and stream live PTY bytes into Ghostty.
- Add a built-in interactive provision endpoint with durable standalone Sandbox ownership.
- Add standalone interactive Codex CLI sessions with Ghostty grid attach and an external runtime provision hook.
- Document the real deployed control-plane status, runtime adapter boundary, workflow config, and test stack.
- Close open side drawers with Escape.
- Preserve completed run attempt status when operators mark stale cards stalled.
- Add runtime adapter descriptors with persisted selection reasons and capability-gated takeover.
- Add repo
CRABBOX.mdworkflow evaluation for runtime and merge defaults. - Add durable D1 run attempts with heartbeat, stall handling, run history, and active-run state.
- Vendor local app icons and remove external icon runtime dependency.
- Serve
/docs/from the Worker documentation page. - Switch the Worker typecheck/build path from
tsctotsgo. - Fix the default OpenClaw maintainer team allowlist slug.
- Add a fullscreen Ghostty WASM Codex session grid for attach/watch/takeover workflows.
- Add a persistent light/dark mode toggle to the app rail.
- Make new card titles optional and derive blank titles from the prompt.
- Add
#numberissue/PR previews across enabled OpenClaw repos and default new cards toopenclaw/openclaw. - Add card-level diff metadata, tile previews, and run-drawer patch rendering for changed files.
- Add GitHub Pages documentation for docs.crabbox.ai.
- Clear seeded and smoke-test cards from production boards.
- Add Crabfleet logo branding to the app and hide unavailable GitHub OAuth login.
- Migrate Worker persistence to a typed Kysely D1 query layer.
- Add D1-backed authentication, sessions, admin APIs, card persistence, and run event logging for the deployed Worker.
- Add initial Crabfleet web app shell with board, card creation, admin allowlists/repos/policy controls, run logs, attach/watch/takeover actions, and deployed spec routes.