## inclusionAI/Avernet — v2026.08.04…v2026.08.24

_353+ commits._

### Features
- **feat(bcs): encode channel source in session ids (#989)** (1bd9521)
- **feat(evolverun): introduce taskguard plugin with hello-demo pack and evolvetrace updates (#1398)** (ed206ec)
- **feat(backend): opt-in immediate execution for enqueued task types (#1381)** (21268bf)
- **feat(bcs): refine event webhook contract and direct A2A handling (#1359)** (960ee9e)
- **feat(baas): add public interaction ids (#1317)** (2d13b04)
- **feat(bcs): propagate group participant tags to providers (#1218)** (7de529c)
- **feat(bcs): add group event webhook subscriptions (#1309)** (7c0aa92)
- **feat(backend): ship teclaw with an empty default MCP roster (#1307)** (80a7a3a)
- **feat(baas): add cookie auth to cache read endpoint (#1260)** (246c9f2)
- **feat: allow coding bots to ensure DIMA workspace** (5a55cfd)
- **feat(baas): support BCN interaction SSE and resolution** (073afc6)
- **feat(baas): add gated SSE interaction resolution** (6d22e68)
- **support interaction** (31973a4)
- **feat(bcs): support mode-switch metadata and answer headers** (7c65181)
- **feat(bot_collaborator): 允许 personalCoding bot 增加成员 (#1296)** (c63759f)
- **feat(evolverun): add evolvetrace module and clean up taskguard scripts (#1272)** (39f482f)
- **feat(bcs-app-session): emit join/left system messages on openapi participant add/remove (#1278)** (66cdfbd)
- **feat(bcs): configure provider chat run timeout** (46bead7)
- **feat(backend): wire task framework into app + di + integration specs + testcases (#1157)** (f2820ed)
- **feat(backend): expose the harness surface through the gateway (#1129)** (da4755e)
- **feat(bcs-app-session): emit participant-mode-changed system message on openapi path (#1212)** (082470a)
- **feat(bcs-interaction): enrich ask_user resolve answers with origin question** (7ea333d)
- **feat(bcs): V1 create-group authorizes caller↔originator, not caller↔driver** (94f054f)
- **feat(bcs): plumb originator field through V1 create-group contract** (0cfbec5)
- **feat(backend): consolidate task_discovery module with notification integration (#1163)** (dd96faf)
- **feat(backend): restore teclaw's default MCP roster** (6c8b592)
- **feat(bcs-channel): add /new slash command to archive session and start fresh (#1106)** (542bf94)
- **feat(baas): add cookie auth to cache write endpoint** (c639895)
- **feat(backend): empty teclaw's default MCP roster (#1155)** (e04d25f)
- **feat(backend): flatten stdio MCP launch instruction onto artifact server entries (#1136)** (1ecdc63)
- **feat(baas): run startup scripts unbounded and bracket runs with log markers (#1123)** (5422971)
- **feat(backend): poll openapi v1 bot auth-status via POST, retiring the GET (#1116)** (a218951)
- **feat(mcp): give teclaw its own default MCP server list (#1112)** (a0a4752)
- **feat(config-compose): carry stdio MCP servers in the bot-config artifact (#1083)** (462d9a9)
- **feat(baas): env-scope ARCA TTL renew dist lock (#1090)** (7ce8a00)
- **feat(bcs): add channels/bindings OpenAPI contract + regenerate bcn.openapi.json** (fcf6acd)
- **feat(bcs-bootstrap): mount Arc<dyn ChannelService> into ApiState (Task 5)** (fc2ac41)
- **feat(bcs-api-http): mount channels/bindings OpenAPI routes (5 op, human-only)** (97639e1)
- **feat(bcs-api-http): add channels/bindings V1 DTOs + bcs-domain dep** (cb8fda9)
- **feat(bcs-api-http): add optional channel_service slot to ApiState** (fe94ff2)
- **feat(bcs): unify V1 and legacy session launch (#1131)** (4073e3b)
- **feat(backend): goal-driven task execution framework — core implementation (#1147)** (d09773b)
- **feat(gateway): add singlebox lifecycle scripts (#1135)** (56258bf)
- **feat(bcs-api-http): surface collected state in openapi list sessions (#1118)** (691bcc5)
- **feat(backend): support template preset CLI defaults (#1125)** (3d11395)
- **feat(bcs): support human session participant modes (#1102)** (e393887)
- **feat(bcs): query DingTalk conversation ids by session (#1104)** (5805ac7)
- **feat(baas): add Aliyun ACK sandbox config block to deploy configs** (05262a5)
- **feat(baas): add Aliyun ACK-backed Arca sandbox plugin** (d254f37)
- **feat(baas): unify Arca sandbox info model in community SPI** (e43369a)
- **feat(bcs): add Provider SSE HITL interactions (#1081)** (ce52dd2)
- **feat(backend): address published runtimes on the per-bot file endpoints (#1075)** (d8315ca)

### Fixes
- **fix(bcs): allow HTTP for private webhook endpoints (#1362)** (afaaaea)
- **fix(baas): accept custom and skipped ask-user answers (#1335)** (3edefb3)
- **fix(baas): forward exec interactions without command (#1330)** (b1f54dc)
- **fix(bot_run): cancel local timed-out tasks and force-done stale remote RUNNING records (#1308)** (5270c9b)
- **fix(bcs): accept custom and skipped ask-user answers (#1336)** (f6fcb62)
- **fix(bcs): accept exec interactions without command (#1329)** (dc5a172)
- **fix(bcs): replay pending interactions on legacy websocket reconnect (#1324)** (cd6d3df)
- **fix(bcs): log interaction SSE payloads** (54cd22d)
- **fix(bcs): log interaction resolve payloads** (4342360)
- **fix(skill_center): 恢复 get_symlink_mappings 未知引擎 default 兜底语义 (teclaw 激活报错) (#1303)** (dc83311)
- **fix(backend): resolve publish provider from the bot, not the record's ext** (5ac7a70)
- **fix(bot-service): let PaasError pass through without retry in binding request** (aa0e1c6)
- **fix(bot-runtime), catch base execption, retry for all case** (4733f1b)
- **fix(bcs): authorize conversation lookup for session members (#1288)** (c350822)
- **fix(bcs): classify spaced timeout text (#1285)** (e1a98c7)
- **fix(bcs-session): allow group originator to leave a session (#1281)** (19c2ad2)
- **fix(aicoding): restore sessions/cron-tasks.json sync when admin cannot stat NAS file (#1271)** (3a229c7)
- **fix(bcs-app-session): allow collecting a session as the human's own actor (#1270)** (82ee094)
- **Arca renewwal fix (#1266)** (00e2a79)
- **fix(aicoding): skip declared code repos cloned under .aicoding/workspace in publish rsync (#1259)** (e0d7d84)
- **fix(skill-center): use null global defaults for aicoding fallback (#1240)** (24896be)
- **fix(bcs): scope provider timeout to chat runs** (d1facc7)
- **fix(bcs): preserve bot uuid on connect errors** (a219566)
- **fix(bcs): log bot identity on websocket errors** (b91857b)
- **fix(skill-center): scope routed default skillsets by bot (#1232)** (e63df33)
- **fix(bcs): align candidate search gateway principals** (005209e)
- **fix(skill-center): fallback default skillsets for routed claude code (#1214)** (f5b975a)
- **fix(bot-service): catch CancelledError in aiohttp request retry loop (#1203)** (4a65941)
- **fix(bcs): skip driver-reachability when originator equals the driver** (60e26a3)
- **fix(bcs): give V1 facade a dedicated for_v1_openapi group-management instance** (b89ee21)
- **fix(skill-center): select compatible default skillset (#1202)** (990a8c5)
- **fix(release): preserve own-bot admission in auth-status backflow** (e3e94b6)
- **fix: omit bot type env for service publish (#1143)** (50992d8)
- **fix(backend): keep bot-config artifact schema_version at 4 (#1140)** (1011368)
- **fix(engine): find sessions beyond gateway default limit (#1120)** (4baeb5b)
- **fix(baas): target ARCA TTL at now+23h to stay under 24h cap** (5e447e1)
- **fix(skills): explain invalid upload packages** (06b5a18)
- **fix(skills): recreate missing local package on upload** (137873a)
- **fix(skills): remove durable local cleanup work** (72819a2)
- **fix(bot_runtime) (#1099)** (accc7c8)
- **fix(skills): document upload lock failures** (cf5b7b1)
- **fix(skills): retain legacy edit serialization** (682b4e4)
- **fix(skills): gate edit locks by layout state** (187a59b)
- **fix(bot_runtime): strip agent:main: prefix on create_session affinity path** (3942326)
- **fix(skills): keep uploaded skill locators canonical** (0aed367)
- **fix(bcs): widen session add-participant eligibility to group driver/originator** (8e15fce)
- **fix(bcs): clean up channel bindings when deleting provider bot (#1149)** (cf57525)
- **fix(bcs): constrain channels PATCH/DELETE success data to null** (cf4fc0d)
- **fix(bcs): describe channel error responses + skip mounting disabled channel service** (2eb6bab)
- **fix(bcs-api-http): map list provider-unavailable to 500 (GET stays 500-only)** (33cf7ce)
- **fix(bcs): keep bcs-api-http on the application-service boundary; nullable created_by** (960f9eb)
- **fix(bcs): make response group_chat_scope nullable + advertise PATCH invalid_channel_params** (7ff609b)
- **fix(bcs): type PATCH `active` as boolean in the channels/bindings contract** (03dae8b)
- **fix(bcs): map duplicate channel binding to 409 Conflict** (51e4128)
- **fix(bcs): support legacy group context updates (#1152)** (4168a15)
- **fix(bcs): restore merchant profile fusion compatibility (#1137)** (62c110f)
- **fix(bcs): support legacy group patch updates (#1117)** (cbe5fac)
- **fix(bcs): classify direct chat timeout failures (#1132)** (ea44692)
- **fix(backend): preserve aicoding cron task config (#1126)** (90d7fbc)
- **fix(bcs): allow HTTP file downloads in BCN plugin (#1108)** (179d09a)
- **fix(bcs): route bcs-cli chats through callbacks (#1101)** (4a422e4)
- **fix(gateway): allow optional principals for internal collaboration APIs (#1087)** (9b0d504)
- **fix(baas): use canonical plugin-sandbox logger in Aliyun ACK plugin** (590a795)
- **fix(bot-run): set max_size=10mb on WebSocket client to allow large event (#1085)** (acabd19)
- **fix(gateway): reject malformed internal docs schemas** (e4d2a37)
- **fix(bcs): route internal collaboration APIs through gateway** (73341b0)
- **fix(bcs): address inner api review feedback** (af6fcd9)

### Backend
- **Rel20260818 haoqian (#1095)** (3b9ec2a)

### Tests
- **test(bcs): V1 group create accepts optional originator field** (5daa96f)
- **test(skills): cover invalid package failures** (906bf50)
- **test(bot_runtime): align affinity tests with strip-at-callsite refactor** (e4578b9)
- **test(skills): cover stable locator failure paths** (3d460e3)
- **test(bcs): pin session add-participant anchor-set eligibility** (c9df954)
- **test(skill-center): cover runtime path endpoints (#1192)** (a197fce)
- **test(bcs-api-http): stub list_conversations_by_session in FakeChannelService** (5cc4eaa)
- **test(bcs-api-http): add channel_routes integration tests (9 cases)** (123c50c)
- **test(bcs): skip merchant profile fusion fixture** (5a1847d)
- **test(gateway): cover internal OpenAPI docs branches** (eafdbec)

### Docs
- **docs(bcs): document interaction payload logging** (33c6d72)
- **docs(bcs): plan interaction log unredaction** (efd4b84)
- **docs(bcs): design interaction log unredaction** (e1bdd58)
- **docs(bcs): plan provider chat timeout configuration** (ee505f9)
- **docs(bcs): design configurable provider chat timeout** (e83c25c)
- **docs(bcs): move websocket logging plans into bcs** (fa68fd5)
- **docs(bcs): design bot websocket error identity logging** (7e2aaf0)
- **docs(gateway): regenerate bcn.openapi.json with V1 group originator field** (67ec3e6)
- **docs(bcs): document originator in the V1 create-group OpenAPI contract** (35bc3c0)
- **docs(bcs): document add-session-participant sponsorship eligibility (#1195)** (5135d6a)
- **docs(bcs): relocate channels/bindings spec+plan into src/bcs/docs/superpowers** (bc94320)
- **docs(bcs): add implementation plan for channels/bindings OpenAPI** (aab7291)
- **docs(bcs): add OpenAPI design for POST /channels/bindings** (411e3c8)

### Chore
- **refactor(backend): split the image-policy decoder from the resolver** (88d1d93)
- **refactor(backend): resolve devices from BotFacts identity only** (50ed941)
- **chore(codeowners): cover task test dirs under adapters/http and api (#1144)** (03c96fd)
- **chore(backend): add callback errors, jieba dev-dep, ignore .codegraph (#1127)** (692dbcd)
- **refactor(backend): split grant check into per-admission-mode dependencies (#1111)** (778bbee)
- **chore(gateway): republish the bots schema with the stage parameter (#1084)** (d3ca0c2)
- **refactor(backend): key engine-runtime lookups off the bot row, not BotFacts (#1082)** (0939701)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/inclusionAI/Avernet?utm_source=github-action)._