## inclusionAI/Avernet — v2026.07.15…v2026.07.28

_344+ commits._

### Features
- **feat(service-bot): apply provider-aware decision + cleanup to restart (SDD task 6)** (22e47f3)
- **feat(service-bot): retire lingering bot on DEVICE_NOT_FOUND upgrade fallback (SDD task 5)** (ffb8f62)
- **feat(service-bot): provider-aware online reuse decision + dispatch (SDD tasks 3,4)** (bc06e32)
- **feat(service-bot): carry gone-bot error_code through TargetBotGoneError (SDD task 2)** (7f90ef2)
- **feat(service-bot): add BotBuildService.retire_superseded_bot (SDD task 1)** (0f1cc4a)
- **feat(bot_run): treat agent final event as session termination (#518)** (62a90fa)
- **feat: support owner-scoped skills pool rollout** (10c1786)
- **feat(mcp): show real names for claude_code default MCPs (#504)** (2f0653a)
- **feat(mcp): add app info to claude code defaults (#477)** (0490e2d)
- **feat: safely finalize Skills Pool cutover (#459)** (476bbfe)
- **add relay ws_url (#462)** (5fd1200)
- **feat(bcs): fire system message on session file upload complete (#445)** (5d42b2c)
- **feat(gateway): backward-compat checker + gate-and-publish script** (113c7f8)
- **feat(backend): expose all groups under /openapi/v1/bots (path move, dedicated subdir)** (6433130)
- **feat(gateway): wire config-driven app + retire #389 stub routers** (4efadee)
- **feat(gateway): catch-all forwarding entrypoint** (6d1802d)
- **feat(gateway): served-OpenAPI generator** (e7c643f)
- **feat(gateway): SchemaCatalog SPI + bare file loader with background refresh** (f6cf9cd)
- **feat(gateway): Forwarder SPI + bare httpx plugin** (d5df2ef)
- **feat(gateway): domain map config + resolver** (65e1915)
- **feat: add Skills Pool rollout operations** (40b776a)
- **feat: manage skills pool migration quarantine** (67b33e2)
- **feat: add skills pool recovery and rollback** (162720c)
- **feat: freeze service bot skills layout artifact (#375)** (aa70123)
- **feat(bcs): support human input state machine nodes (#421)** (041cb3a)
- **feat(bcs): propagate channel source message ids (#432)** (d89c9e5)
- **feat(frontend): improve custom collaboration YAML validation and role… (#425)** (7e3281f)
- **feat: add Hermes skills pool migration (#415)** (34dc90f)
- **feat: add AICoding skills pool migration** (138b305)
- **feat: add Claude Code skills pool migration** (63074b0)
- **feat: wire skills pool lifecycle reconciliation (#410)** (b7fc634)
- **feat: migrate complete OpenClaw filesystem truth (#370)** (62b26ac)
- **feat: activate OpenClaw skills pool migration (#369)** (b914fa9)
- **feat(bcs): session workspace — shared per-session files, pluggable storage, CLI (#343)** (808db45)
- **feat: add skills pool layout claim gate (#367)** (a60cef2)
- **feat(bcs): complete custom collaboration workflow (#385)** (8e7af0e)
- **feat(bcs): auto-join humans for session chat (#364)** (6b6c05d)

### Fixes
- **Revert "fix: serialize BaaS bootstrap with container init (#519)"** (b61a93d)
- **fix(teclaw): replay delivery idempotently and cover the tri-state contract** (c217fd8)
- **fix(teclaw): make the token delivery retryable and tri-state aware** (9272fa9)
- **fix(teclaw): deliver the passport token after the container actually starts** (c23cb38)
- **fix(service-bot): release stale binding on restart BOT_NOT_FOUND fallback too** (95cce0c)
- **fix(service-bot): require a destroy workflow id + release stale binding on BOT_NOT_FOUND fallback** (cc1959a)
- **fix(service-bot): release stale binding on FIRST_RELEASE restart + refresh teclaw MCP rule on restart-recreate** (a277533)
- **fix(service-bot): preserve the teclaw publish handle when activating a restart binding** (9faaad6)
- **fix(service-bot): activate the recreated binding on restart-success for stable records** (5366d4d)
- **fix(service-bot): release the superseded binding in the restart DEVICE_NOT_FOUND fallback** (6e6df42)
- **fix(service-bot): harden supersede decision — wait on STOPPING, release stale binding, tolerate already-gone** (f9427ef)
- **fix(service-bot): refuse to recreate on an ambiguous empty BaaS status** (0283db7)
- **fix(service-bot): propagate deploy status/lifecycle failures instead of masking them** (885a02f)
- **fix: serialize BaaS bootstrap with container init (#519)** (1287bab)
- **fix(baas): use gmt_modified instead of gmt_create for publish timeout baseline (#513)** (315baa5)
- **fix: close skills pool rollout gaps** (8c1455a)
- **fix: harden multi-engine skills pool runtime** (31aa2ad)
- **fix(community): route notify probe by device_provider (BaaS ENGINE_HTTP_500) (#508)** (03e5c68)
- **fix: fail closed on invalid pool skill mappings** (9be393c)
- **fix: keep Teclaw skill locators logical** (5b241ba)
- **fix: route pool-active skill CRUD to canonical paths** (c498846)
- **fix: retire legacy skills storage without exchange** (03e4756)
- **fix: recover skills pool cutover exchange retries** (0f6b41f)
- **fix lock (#489)** (d6c4d3f)
- **fix auth on api resources  url and node** (062a680)
- **fix auth on api resources  url and node** (f4d2a87)
- **fix: support legacy skills pool rollout config CAS** (69e025e)
- **Bugfix/fix error status (#466)** (20ba726)
- **fix: domain-bots remove auth and remove iam_token (cherry-pick #442 to REL20260728) (#472)** (45c7a5f)
- **fix(backend): recover bots stuck in pending** (cd07096)
- **fix lock (#460)** (d56fcf3)
- **fix: release pool claim for incapable runtimes** (efccc1b)
- **fix(backend): green the Backend-unit-test gates for the openapi_v1 package** (315f3c8)
- **fix(gateway): prune published components + tighten compat checker (D-E review)** (ae078a3)
- **fix(gateway): collect component refs beyond $ref; harden refresher (Task 3-4 review)** (6b8bdff)
- **fix(gateway): preserve duplicate response headers + strip Connection-named (Task 2 review)** (d2c3ef0)
- **fix(service-bot): re-publish after offline recreates the destroyed online bot** (dcce9a6)
- **fix: align skills pool ddl with database standards** (2b81649)
- **fix: harden skills pool rollout operations** (11f6d72)
- **fix: log missing quarantine cutover evidence** (9d061a8)
- **fix: retry uncertain quarantine cleanup** (d84830b)
- **perf: stop runtime probes after pool finalization** (c17c3c6)
- **fix: bound quarantine cleanup retries** (2911b75)
- **fix: fence quarantine cleanup on runtime health** (415ed95)
- **fix: harden skills pool recovery rollback** (a587296)
- **fix(baas): prevent SQLAlchemy isce error from concurrent orm_session calls in distributed lock renew thread (#441)** (0a1f63a)
- **fix(bcs): allow driver bot and its owner to delete a session (#433)** (e7ce54d)
- **fix(baas): do not return 503 when device not available (#429)** (7b25f11)
- **fix(bcs): allow bot owner to remove their bot from a session (#426)** (1e7b8ad)
- **fix(baas): bind singlebox gateways to loopback** (f64e3d1)
- **fix(health_check): 调整沙盒设备告警处理逻辑 (#422)** (df50e47)
- **fix(bcs): gate session-file access on session participants and relax share authz (#423)** (f858b89)
- **fix(bcs): exclude requester from discovery (#400)** (ad11180)
- **fix(bcs): avoid single upload multipart misclassification (#412)** (b6d16aa)
- **fix(bcn): emit empty final for tool-only runs (#296)** (5c6d3ce)
- **fix(baas): convert aicoding command output (#407)** (407b03b)
- **fix(bcs): emit human join event for session chat (#403)** (3f261d0)
- **fix(baas): preserve configured engine venv symlink** (cfea90a)
- **fix(harness): raise LLM call success rate for diagnostics and patch g… (#402)** (e4a6d17)
- **fix(backend): preserve per-bot notify probe failures — Refs ocb#9 (#388)** (2b8ef84)
- **fix(bcs): unify provider callback timeout (#386)** (89c02db)
- **fix(bcs-cli): restore discover JSON output (#380)** (c81a982)
- **fix(bcs): reject invalid explicit bot credentials (#365)** (7f4349f)
- **fix: avoid reusing incomplete singlebox bot sessions** (7f4c422)
- **fix(bcs): expose async judge progress and cover provider timeout (#384)** (7744024)
- **fix(bcs): scope channel bindings by environment (#362)** (f1b4f84)

### Backend
- **Oss endpoint div (#520)** (c09affe)
- **remove packages (#505)** (767abfd)
- **Session fs v2 (#486)** (d5b4b4e)
- **Make pre-push lint-only by default instead of full CI (#450)** (9e68d21)
- **Remove the retired ac_file table and its dead call graph** (47c6e96)
- **feat(backend)botchat统一接口+开放api (#366)** (8915835)
- **Rel20260723 to dev (#413)** (583c5ff)
- **Gateway v1 API — remaining groups: channels, skills, identity, resources, mcp, routines (#389)** (ff80eb4)
- **[Skills Pool P3] OpenClaw 暗准备 Pool 并支持运行时探测 (#392)** (0d32b5a)

### Tests
- **test(service-bot): E2E actually exercises RETIRE_THEN_FIRST_RELEASE (single-live-bot guard)** (007b4b2)
- **test(service-bot): regression, crash-safety, E2E guards for supersede cleanup (SDD task 7)** (2f54b6f)
- **test: cover rollout config entry normalization** (caf8d07)
- **test: cover skills pool quarantine contracts** (9c899ba)
- **test: bind skills pool edit guard in upload API fixtures** (b647224)
- **test(engine): make unreadable skill fixture root-safe** (7764cff)
- **test: drop unrelated baas coverage** (c67bb5c)
- **test(gateway): add ci coverage check (#406)** (7e3070d)
- **test(engine): cover Claude skills pool runtime seams** (6820daf)

### Docs
- **docs(service-bot): align SDD tasks/plan with final propagate semantics** (6413299)
- **docs(service-bot): task breakdown for online bot supersede cleanup (SDD phase 3)** (7ecc7c1)
- **docs(service-bot): correct plan — teclaw gone container fails publish, not DEVICE_NOT_FOUND** (1e8e5ed)
- **docs(service-bot): technical plan for online bot supersede cleanup (SDD phase 2)** (f13a404)
- **docs(service-bot): spec for online bot supersede cleanup (SDD phase 1)** (aa44af0)
- **docs(gateway): mark SDD tasks complete (verification)** (2c314a8)
- **docs(gateway): JWT owned by auth workstream; move all backend groups under /openapi/v1/bots** (0f90df4)
- **docs(gateway): task breakdown for config-driven forwarding (SDD phase 3)** (2aa53f8)
- **docs(gateway): domain-transparent forwarding + auto-adopt published schema** (a9c2935)
- **docs(gateway): default to verbatim path forwarding (identity mapping)** (8d2dd78)
- **docs(gateway): technical plan for config-driven forwarding (SDD phase 2)** (6133e58)
- **docs(gateway): drop redundant per-op domain; clarify gateway/upstream path mapping** (c69c70b)
- **docs(gateway): spec for config-driven forwarding (SDD phase 1)** (0fa2e33)
- **docs: clarify asynchronous skills pool claim state** (2523239)
- **docs: complete WAIC demo tutorial docs (#337)** (e60247f)

### Chore
- **refactor(service-bot): make online deploy decision handling exhaustive** (7943af6)
- **chore(service-bot): revert accidental uv.lock churn from test-index override** (2e1634c)
- **refactor: split skills pool capability persistence** (9f85fd9)
- **refactor(gateway): drop dead public-contract stubs; vendor-neutral object_store schema source** (d5d666e)
- **refactor(backend): drop x-avernet-security markers from public routers** (fa48651)
- **refactor(backend): new definition-only /openapi/v1/bots routers (not a re-home)** (b872240)
- **chore(gateway): don't commit the generated OpenAPI artifact** (d70dd46)
- **chore: keep uv.lock unchanged from dev** (d374419)
- **refactor: extract skills pool cutover diagnostics** (7a3cbc5)
- **refactor: minimize service skills manifest** (aba355f)
- **refactor: name service skills metadata as manifest** (e8e9b38)
- **refactor: tighten service artifact dependencies** (de17d17)
- **chore(baas): Revert code change for device_template_router.py (#424)** (e7cd9d5)
- **chore: remove unused skills pool ddl** (d460ebb)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/inclusionAI/Avernet?utm_source=github-action)._