## inclusionAI/Avernet — v2026.07.30…v2026.08.04

_124 commits._

### Features
- **feat(openapi): align bot-scoped Skills API contract (#718)** (2c3f08a)
- **feat(gateway): require non-empty creator/modifier on app and access-key registration (#764)** (b228007)
- **feat: add log for gateway** (b9f2d49)
- **feat: add log for gateway** (2519a3b)
- **feat: rename openapi path (#748)** (bfa6161)
- **feat(baas): raise ChatRequestError on ok=False in chat_send/chat_inje… (#744)** (6b9295f)
- **feat(gateway): integrate bcn collaboration routing (#739)** (9555807)
- **feat: remove init bare data (#720)** (c6c3965)
- **feat(session-files): route uploads through active bindings (#721)** (8b2f9ae)
- **Support gateway (#711)** (46c553f)
- **feat(singlebox): add local OpenAI-compatible mock model server (#448)** (460e107)
- **feat(bcs): unify BCN APIs under collaboration prefix (#694)** (992911b)
- **feat(bcs): add Anthropic LLM judge provider (#667)** (5f860cf)
- **feat(bcs): namespace collaboration API paths (#690)** (1e1bc0c)
- **feat-add bot-level rsync excludes configuration (#689)** (132991a)
- **feat(bcs): enforce V1 gateway principal authorization (#686)** (984b3a8)
- **feat(gateway): serve the tenant engine socket as a websocket domain (#683)** (b5c9938)
- **feat(openapi-v1): admit only callers that name an end user (#681)** (c0808db)
- **feat(backend): resolve the gateway principal key via SecretResolver (#670)** (e6f385f)
- **feat(bcs): expand BCN OpenAPI v1 contract to 27 operations (batch 2) (#621)** (bf4de39)
- **feat(gateway): resolve principal signing key via SecretResolver SPI (#673)** (6e950b2)
- **feat(frontend): add collaboration flow preview (#665)** (b278609)
- **feat(bcs): expose collaboration definition graph preview (#663)** (295eadf)
- **feat(skills): isolate default exclusions and layout state** (f17b36e)
- **feat(skills): isolate pool control-plane records** (b1d583e)
- **feat(skills): isolate catalog records by tenant** (91ede91)
- **feat(openapi-v1): Track C — wrap the engine runtime surface (16 endpoints) (#630)** (5e94584)
- **feat(backend): verify the gateway's forwarded principal on /openapi/v1** (796e087)
- **feat(gateway): DB-backed app_token + signed principal forwardingFeat/principal signer (#599)** (4b6648f)
- **feat(backend): Track B — public API mcp category (#610)** (c022e94)
- **feat(gateway): migrate auth/cache/database/authn plugins from entry points to DI (#612)** (1bac165)
- **feat(bcs-cli): sniff charset for text uploads to fix Chinese preview mojibake (#620)** (f369e38)
- **feat(bcs): add first BCN OpenAPI v1 group endpoints (#514)** (3561e48)
- **feat(baas): record provider_device_id into baas_publish_record.extra_config (#608)** (e4196f0)
- **feat(backend): Track A stage 5 — MCP configuration tenant isolation (#564)** (c8d1fb1)
- **feat(bcs-cli): infer session file upload mime from extension (#603)** (3ded9b9)
- **feat(bcs): support one-shot state machine runs in sessions (#562)** (b3dcdbc)
- **feat(bcs-cli): expose OAuth provider extension point and split run() entry (#561)** (6c2029d)
- **feat(bcs): list session files newest-first by default (#567)** (e9942f3)
- **feat(backend): support service bot draft restoration (#499)** (7da462f)
- **feat(backend): implement /openapi/v1/bots (Track B) (#494)** (7bae055)
- **feat(bcs): add ?show= query param for inline file display on content endpoint (#550)** (47eb83b)

### Fixes
- **fix(gateway): remove the dev signing-key fallback and make key mismatches diagnosable (#785)** (96ddde6)
- **fix(service-bot): drive restart completion with a durable poll (#780)** (c33b8a1)
- **fix: handle protected common config toggles** (f3d9326)
- **fix(backend): stabilize dormant activation not-found contract** (21ec603)
- **fix: return not found for dormant activation** (2ffe342)
- **fix(engine): reject active repo bridges after cutover** (36699ed)
- **fix: scope teclaw routing to directory downloads** (f3fa1af)
- **fix: support teclaw directory downloads** (6b0a85e)
- **fix(engine): restore canonical repo bridge after Desktop rollback** (74f1215)
- **fix(engine): keep legacy BCS DM sessions visible (#762)** (4364d5b)
- **fix baas openapi (#760)** (90e8dde)
- **fix(skills-pool): canonicalize Desktop repo and converge cutover mappings (#752)** (88df3ee)
- **fix(gateway,backend): move the bot socket under a ws segment (#740)** (5807d69)
- **fix(gateway): handle a client that leaves before the relay accepts (#719)** (5c949d0)
- **fix: complete verified wakeups after quarantine cleanup** (d016070)
- **fix: guard active bridge runtime repair** (e38f90a)
- **fix: reconcile active aicoding repo bridge mappings** (9b7119d)
- **fix(baas): honor active runtime engine type (#709)** (a78ae32)
- **fix: keep skill upload lookup owner scoped** (332fde7)
- **fix: fail closed skill collaborator mutations** (dfe7a69)
- **fix: scope skill owner repair and collaborator delete** (67b2b18)
- **fix: restore bot ownership for uploaded skills** (7ad421d)
- **fix(engine): reconcile trusted AICoding repo bridge links** (694e3e0)
- **fix: harden skill deletion identities and probes** (e6a409f)
- **fix: preserve bot owner and center version semantics** (ea2df4f)
- **fix: disambiguate legacy bot context on skill delete** (b2f36f9)
- **fix: preserve legacy deletion without device binding** (845cffc)
- **fix: address skill deletion review feedback** (2ffe7f1)
- **fix: block deletion of referenced skills** (de7a7aa)
- **fix: resolve skill delete from persisted bot context** (9ea2024)
- **fix(bcs-cli): detect charset from truncated prefix and UTF-16 BOM (#696)** (a1bef49)
- **fix: preserve pool layout for empty mappings** (dda2af3)
- **fix(session-files): harden materialization and proxypass access (#680)** (03bd3d1)
- **fix(bcs): gate timeout scans on current leader (#676)** (302e881)
- **fix(skills): scope bot control records globally** (c0a75d8)
- **fix(skills): report rejected association writes** (2879485)
- **fix(skills): close tenant isolation gaps** (15f60e6)
- **fix(baas): propagate callback_timeout_seconds on update_bot and update_devices (#653)** (1c983fb)
- **fix(backend): confine the "default" bot_id to the default tenant (#556) (#625)** (0e8b264)
- **fix(backend): resolve skill parameters with bot owner (#591)** (5c8ad03)
- **fix(bcs): resolve full display-name mentions (#636)** (27c6332)
- **fix codereview (#627)** (b667996)
- **chore(review) CODE_REVIEW.md was referenced from the incorrect location, fix it (#638)** (d30278b)
- **fix(bcs): run state-machine timeout scanner on leader (#524)** (738cd2f)
- **fix(singlebox): mock IAM token endpoint** (441a85f)
- **fix: validate engine config payload** (67ae585)
- **fix: validate legacy bot name updates** (dfe6d08)
- **fix(engine): use singlebox model config for defaults** (05449ed)
- **fix(bcs): recall HumanInput acknowledgement reaction (#614)** (c48f65a)
- **fix(bcs): resolve HumanInput recipients without IM history (#602)** (cec746c)
- **fix(bcs): thread content_type through session file prepare + CLI upload PUT (#581)** (d57f422)
- **fix(bcs): exclude deleted friends from /bots/{id}/friends (#579)** (98209e3)
- **fix(engine): preserve truncated file tree directories (#580)** (11fe164)
- **fix(bcs): defer IM collaboration initial run (#571)** (0c66f5f)
- **fix(community): filter notify polling by engine (#573)** (878662c)
- **fix(backend): keep bot chat relation labels consistent (#572)** (19b7548)
- **fix(publish-flow): clear restarting flag on stable-state restart success (#568)** (c6c30ee)
- **fix(bcs-storage-baas): delete transfer via sessions transfers path, not files (#546)** (ea93ff7)
- **fix(bcs): keep frontend HumanInput channel optional (#553)** (bd18566)

### Backend
- **don't log header** (c089f84)
- **Connection endpoint: gateway URL and query-parameter credential (#671)** (f0586a0)
- **merge config file to application (#632)** (edc58f7)
- **Rongzhi 0727 (#543)** (cd90aa5)

### Tests
- **test: cover dormant bot service adapter** (58782a1)
- **test: cover backend engine bridge repair contract** (7a389f1)
- **test: cover collaborator skill mutation guards** (8073dac)
- **test(engine): cover trusted repo bridge reconciliation** (4fb4828)

### Docs
- **docs(baas): update baas openapi to expose the gateway routers** (13ff817)
- **docs(readme): clarify OSS scope, capability status, and proof boundaries (#463)** (d29a2ce)
- **docs(repo): define PR title and description conventions (#674)** (72a71d7)
- **docs(skills): add track a specification** (fdd6fb4)
- **docs(openapi-v1): point the verifier board row at PR #634** (020b1ad)
- **docs(openapi-v1): record Track B bots (#494) on the handoff board** (f911608)

### Chore
- **build(gateway): republish the bots description for the ratified Skills contract (#786)** (163a678)
- **refactor: split skills pool reconcile helpers** (72479a5)
- **refactor(gateway): route domains by path pattern and move the bot socket under bots (#713)** (78f6b3f)
- **refactor(backend): normalize /openapi/v1/bots paths and drop channels (#706)** (770d677)
- **refactor(bot): retire default bot_id for global uniqueness (#668)** (78f2e27)
- **chore: sync REL20260730 changes back to dev (#678)** (339556a)
- **refactor(gateway): fix DI architecture and standardize implementation (#664)** (a7ee0fa)
- **refactor(LLM): Improve exception handling and logging (#629)** (4d628bd)
- **chore(dev-ops): update Codex review instructions and gitignore (#594)** (d089ef6)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/inclusionAI/Avernet?utm_source=github-action)._