Skip to content

fix(discord): stop emitting a non-loopback per-account proxy (#5544) - #5571

Merged
cv merged 3 commits into
NVIDIA:mainfrom
latenighthackathon:fix-discord-drop-rejected-per-account-proxy
Jun 23, 2026
Merged

cv merged 3 commits into
NVIDIA:mainfrom
latenighthackathon:fix-discord-drop-rejected-per-account-proxy

Conversation

@latenighthackathon

@latenighthackathon latenighthackathon commented Jun 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The Discord channel config emits a per-account proxy (channels.discord.accounts.default.proxy = http://10.200.0.1:3128) that OpenClaw's Discord plugin rejects by design. extensions/discord/src/proxy-fetch.ts validateDiscordProxyUrl throws Proxy URL must target a loopback host for any non-loopback host, and that validator runs on both the REST and gateway transports. The rejected proxy is dropped, so the Discord gateway WebSocket cannot egress the deny-by-default network namespace and never reaches READY. This restores reliance on the top-level managed proxy for Discord, the mechanism that originally addressed #5075 / #3894.

Related Issue

Fixes #5544

Changes

  • Resolve discordProxyUrl back to undefined so the per-account proxy field is omitted from the rendered openclaw.json. Discord gateway and REST egress is carried by the top-level managed proxy (proxy.loopbackMode: "gateway-only"), which OpenClaw documents as the path for routing channel traffic through the operator proxy.
  • Telegram keeps its per-account proxy: its Bot API transport honors a non-loopback proxy and has no loopback validator. Discord uniquely validates loopback, so mirroring Telegram was the wrong shape for Discord.
  • Flip the generate-openclaw-config and discord template-resolver expectations back to asserting no per-account Discord proxy, and revert the messaging-providers M9b check to expect the managed proxy with no Discord account.proxy.
  • Effectively reverts fix(messaging): resolve the Discord per-account proxy so the gateway WebSocket connects #5248 (and its test(e2e): update Discord proxy expectation #5391 test follow-up).

Type of Change

  • Code change (feature, bug fix, or refactor)

Verification

  • PR description includes the DCO sign-off declaration and every commit appears as Verified in GitHub
  • Git hooks passed during commit and push, or npx prek run --from-ref main --to-ref HEAD passes
  • Targeted tests pass for changed behavior
  • Tests added or updated for new or changed behavior
  • No secrets, API keys, or credentials committed

Ran: npx vitest run test/discord-template-resolver-proxy.test.ts test/generate-openclaw-config.test.ts (130 passed), npm run build:cli, and biome check on the touched files (clean). The full-suite test-cli/test-plugin commit and push hooks were skipped because they trip on a pre-existing collection error in test/ssrf-parity.test.ts (0 tests collected) that also fails on a clean main checkout and is unrelated to this change. CI runs the full gate.


Signed-off-by: latenighthackathon latenighthackathon@users.noreply.github.com

Summary by CodeRabbit

  • Features

    • Updated Discord messaging so discordProxyUrl is no longer emitted per account; Discord Gateway traffic is routed via the application’s managed proxy configuration for consistent behavior.
  • Tests

    • Revised unit and end-to-end tests to assert Discord account proxy remains empty while the global managed proxy URL is used, including cases with proxy host/port environment overrides.

OpenClaw's Discord plugin validates channels.discord.accounts.default.proxy
and rejects any non-loopback host (extensions/discord/src/proxy-fetch.ts
validateDiscordProxyUrl: "Proxy URL must target a loopback host"), called
from both the REST and gateway-plugin transports. NemoClaw was rendering it
to the sandbox egress proxy http://10.200.0.1:3128, which the plugin rejects
and drops, so the Discord gateway WebSocket cannot egress the deny-by-default
namespace and never reaches READY.

Resolve discordProxyUrl back to undefined so the per-account proxy field is
omitted. Discord gateway/REST egress is carried by the top-level managed
proxy (proxy.loopbackMode "gateway-only"), the mechanism OpenClaw documents
for routing channel traffic through the operator proxy. Telegram keeps its
per-account proxy because its Bot API transport honors a non-loopback proxy
and has no loopback validator; Discord uniquely does.

Flip the generate-openclaw-config and template-resolver expectations back to
asserting no per-account Discord proxy, and revert the messaging-providers
M9b E2E check to expect the managed proxy with no Discord account.proxy.

Signed-off-by: latenighthackathon <latenighthackathon@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Jun 21, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: cd0ff961-8779-46de-b47c-4c6b09a164f2

📥 Commits

Reviewing files that changed from the base of the PR and between e1fbc91 and d4cd94f.

📒 Files selected for processing (1)
  • test/e2e-scenario/live/messaging-providers.test.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • test/e2e-scenario/live/messaging-providers.test.ts

📝 Walkthrough

Walkthrough

Removes the per-account Discord proxy URL emission from the template resolver by deleting the proxyUrl helper and its DEFAULT_PROXY_HOST/DEFAULT_PROXY_PORT constants, making discordProxyUrl always resolve to undefined. All unit and E2E tests are updated to assert that the Discord account proxy field is empty and gateway routing defers to OpenClaw's top-level managed proxy.

Changes

Discord per-account proxy removal

Layer / File(s) Summary
Template resolver: drop per-account proxy computation
src/lib/messaging/channels/discord/template-resolver.ts
Replaces the "discordProxyUrl" case's computed proxy URL with resolvedRenderTemplateReference(undefined), removes proxyUrl(env), DEFAULT_PROXY_HOST, DEFAULT_PROXY_PORT, and the now-unused nonEmptyString import.
Unit and config-gen tests: assert proxy is undefined
test/discord-template-resolver-proxy.test.ts, test/generate-openclaw-config.test.ts
Updates discordProxyUrl resolver tests to expect value: undefined in all env scenarios, and changes five assertion sites in the config-generation tests from a concrete proxy URL to undefined for config.channels.discord.accounts.default.proxy, with associated test description renames.
E2E tests: assert empty account proxy and correct managed proxy URL
test/e2e/test-messaging-providers.sh, test/e2e-scenario/live/messaging-providers.test.ts
Rewrites M9b comments to document gateway-only managed proxy routing, and changes the assertion to require account.proxy to be empty while proxy.proxyUrl equals the expected managed proxy URL. Adds explicit managed-proxy validation in the live E2E scenario.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Suggested labels

v0.0.66

Poem

🐇 No more proxy baked in the Discord stew,
The per-account URL? Gone — adieu, adieu!
OpenClaw's managed proxy takes the wheel,
undefined is the value — now the gateway can heal.
Hop hop, the WebSocket lives anew! 🎉

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The PR title accurately describes the main change: stopping emission of a non-loopback per-account proxy for Discord, which is the core fix addressing the regression.
Linked Issues check ✅ Passed The PR fully implements the fix required by issue #5544: it removes the non-loopback per-account Discord proxy configuration, updates template resolver and tests to assert undefined proxy, and restores reliance on OpenClaw's top-level managed proxy for Discord traffic.
Out of Scope Changes check ✅ Passed All changes are scoped to resolving the Discord proxy issue (#5544): template resolver, unit tests, E2E tests, and config generation tests. No unrelated functionality or extraneous modifications are present.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@wscurran wscurran added area: messaging Messaging channels, bridges, manifests, or channel lifecycle area: networking DNS, proxy, TLS, ports, host aliases, or connectivity bug-fix PR fixes a bug or regression integration: discord Discord integration or channel behavior labels Jun 23, 2026
Signed-off-by: Carlos Villela <cvillela@nvidia.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@test/e2e-scenario/live/messaging-providers.test.ts`:
- Line 436: The nullish coalescing operator `??` in the expectedManagedProxy
variable only handles null and undefined values from
state.env.NEMOCLAW_PROXY_HOST and state.env.NEMOCLAW_PROXY_PORT, but doesn't
treat empty strings as missing values. Replace the `??` operator with a check
that treats empty strings as falsy (such as using the logical OR operator `||`)
so that the fallback defaults ("10.200.0.1" for the host and "3128" for the
port) are properly used when environment variables are empty strings or missing,
preventing flaky test failures.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 4b06044b-8418-43c0-b64d-d881d00752d6

📥 Commits

Reviewing files that changed from the base of the PR and between d1ec157 and e1fbc91.

📒 Files selected for processing (1)
  • test/e2e-scenario/live/messaging-providers.test.ts

Comment thread test/e2e-scenario/live/messaging-providers.test.ts Outdated
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
@cv
cv merged commit 8cdc06e into NVIDIA:main Jun 23, 2026
42 checks passed
@cv cv added the v0.0.67 label Jun 23, 2026
@miyoungc miyoungc mentioned this pull request Jun 24, 2026
7 of 14 tasks
cv pushed a commit that referenced this pull request Jun 24, 2026
## Summary
Refresh the docs for the v0.0.67 release using the GitHub announcement
and release-range commit scan.

## Changes
- Add v0.0.67 release notes for onboarding recovery, Discord proxy
behavior, OpenClaw agent apply deletion, and compact AI-agent docs
routing.
- Clarify `onboard --resume` repair checks in the OpenClaw and Hermes
command references.
- Clarify Discord's managed proxy path and `agents apply` delete
behavior in the relevant docs pages.

## Source Summary
- #5699 -> `docs/resources/agent-skills.mdx`,
`docs/about/release-notes.mdx`: Reflects the compact
`nemoclaw-user-guide` docs-routing skill and canonical MCP/Markdown docs
entry points.
- #5571 -> `docs/manage-sandboxes/messaging-channels.mdx`,
`docs/about/release-notes.mdx`: Documents Discord using the managed
proxy path instead of a rejected per-account proxy.
- #5704 -> `docs/about/release-notes.mdx`: Captures the WhatsApp policy
assertion hardening in the release note context.
- Follow-up commit `46ead831e` -> `docs/reference/commands.mdx`,
`docs/reference/commands-nemohermes.mdx`,
`docs/about/release-notes.mdx`: Documents resume repair checks across
later nonterminal onboarding phases.
- Follow-up commit `ee0725a32` -> `docs/reference/commands.mdx`,
`docs/about/release-notes.mdx`: Documents that `agents apply` uses
OpenClaw's confirmation-skipping delete mode for orphan agents.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Verification
- [x] PR description includes the DCO sign-off declaration and every
commit appears as `Verified` in GitHub
- [x] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [x] Targeted tests pass for changed behavior
- [ ] Full `npm test` passes (broad runtime changes only)
- [ ] Tests added or updated for new or changed behavior
- [x] No secrets, API keys, or credentials committed
- [x] Docs updated for user-facing behavior changes
- [ ] `npm run docs` builds without warnings (doc changes only)
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

Verification run:
- `bash test/e2e/e2e-cloud-experimental/check-docs.sh --only-cli`
passed.
- `npm run docs` passed with the pre-existing Fern light-mode accent
contrast warning: `The contrast ratio between the accent color and the
background color for light mode is 2.41:1. It should be at least 3:1.`

---
Signed-off-by: Miyoung Choi <miyoungc@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added release notes for v0.0.67 covering onboarding recovery,
messaging reliability, OpenClaw agent workflows, and AI-agent
documentation routing.
* Clarified Discord channel requirements, including routing through the
top-level managed proxy.
* Updated onboarding resume guidance to note rerunning preflight,
gateway, provider, and sandbox repair checks.
* Refined CLI command reference details for orphan-agent deletion
behavior and how interactive flags affect prompts vs. deletion.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
jyaunches added a commit that referenced this pull request Jun 25, 2026
## Summary
Restore issue #5800 parity package `P0-C` for merged bash-suite
messaging/Discord/WhatsApp deltas only.

## Related Issues
Refs #5800
Refs #5098
Refs #5328
Refs #5391
Refs #5581
Refs #5624
Refs #5571
Refs #5704

## Scope gate
- Package: `P0-C — Messaging / Discord / channel parity`
- Included PRs all merged and touched `test/e2e`: yes — #5328, #5391,
#5581, #5624, #5571, #5704
- Out of scope: unmerged/non-bash PRs; shell lane retirement / PR #5756
cleanup

## Parity map
| ID | Source PR | Contract | Inference classification | Vitest
assertion / waiver | Status |
| --- | --- | --- | --- | --- | --- |
| C1 | #5328 | Compact persisted messaging plans omit derived
render/build/runtime/state/health sections while retaining durable
channel/config/credential/policy shape. | `none` |
`src/lib/messaging/plan-validation.test.ts`;
`test/e2e-scenario/live/channels-add-remove.test.ts` | covered |
| C2 | #5328 | Existing compact plans hydrate before merge so channel
add preserves prior hooks/render semantics. | `none` | existing
`src/lib/messaging/applier/host-state-applier.test.ts` | covered |
| C3 | #5391, #5571 | Discord config must not emit a non-loopback
per-account proxy; OpenClaw managed proxy remains configured. | `none` |
`test/discord-template-resolver-proxy.test.ts`;
`test/generate-openclaw-config.test.ts`;
`test/e2e-scenario/live/messaging-providers.test.ts`;
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts` | covered |
| C4 | #5581 | OpenClaw Discord pairing Vitest preserves fake Gateway
token rewrite, connect-shell approval, and workflow dispatch boundary. |
`hermetic-default` | existing
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts`; support
boundary/helper tests | covered |
| C5 | #5624 | Fake Discord Gateway capture proof accepts only redacted
identify rows, rejects placeholder/raw-token leakage, and proves token
rewrite. | `hermetic-default` |
`test/e2e-scenario/live/messaging-providers.test.ts`; existing
Hermes/OpenClaw Discord capture assertions and support tests | covered |
| C6 | #5704 | WhatsApp policy checks require expected endpoints before
rebuild and endpoints plus Node binary scope after rebuild. | `none` |
`test/e2e-scenario/live/messaging-providers.test.ts`;
`test/policies.test.ts` | covered |

## Inference mode support
- Default mode for touched live targets: `none` for config/unit
assertions; `hermetic-default` for fake Discord Gateway/live sandbox
token-rewrite assertions.
- Real inference support preserved: not applicable to this package’s
messaging/provider contracts; live sandbox targets still use existing
`NVIDIA_INFERENCE_API_KEY` path where their broader scenario requires
install/onboard.
- Modes validated in this PR: unit/support hermetic commands below;
selective live E2E run `28194650942` passed
`messaging-providers-vitest`, `channels-add-remove-vitest`, and
`openclaw-discord-pairing-vitest` at `531acd9f8`. Follow-up head
`46e004e3` only tightens local workflow-boundary assertions for
`COMPATIBLE_API_KEY`.
- If not validated with real inference: package contracts are
messaging/config/proxy/capture policy boundaries;
`channels-add-remove-vitest` also passed the hosted-compatible workflow
path after staging `NVIDIA_INFERENCE_API_KEY` as `COMPATIBLE_API_KEY`.

## Validation
- [x] `npx vitest run --project cli --maxWorkers 1 --no-fileParallelism
src/lib/messaging/plan-validation.test.ts
src/lib/messaging/applier/host-state-applier.test.ts
test/discord-template-resolver-proxy.test.ts`
- [x] `npx vitest run --project e2e-vitest-support --maxWorkers 1
--no-fileParallelism
test/e2e-scenario/support-tests/openclaw-discord-legacy-capture.test.ts
test/e2e-scenario/support-tests/openclaw-discord-pairing-helpers.test.ts
test/e2e-scenario/support-tests/openclaw-discord-workflow-boundary.test.ts`
- [x] `npx vitest run --project cli --maxWorkers 1 --no-fileParallelism
--testTimeout 30000 test/generate-openclaw-config.test.ts -t
"Discord|proxy|non-Slack"`
- [x] `npx vitest run --project cli --maxWorkers 1 --no-fileParallelism
test/policies.test.ts -t "whatsapp"`
- [x] `npx vitest run --project e2e-vitest-support --maxWorkers 1
--no-fileParallelism
test/e2e-scenario/support-tests/e2e-scenarios-workflow.test.ts
test/e2e-scenario/support-tests/openclaw-discord-workflow-boundary.test.ts`
- [x] Selective live E2E workflow `28194650942`:
`messaging-providers-vitest`, `channels-add-remove-vitest`,
`openclaw-discord-pairing-vitest` all passed.

## Follow-ups / waivers
- None.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved messaging plan persistence validation to ensure only required
fields are stored; derived workflow sections and per-channel hook data
are no longer persisted.
* Strengthened live channel add/remove assertions to enforce
`agentRender` and per-channel `hooks` absence.
* Updated live messaging provider and Discord pairing validations
(WhatsApp preset hosts and stricter gateway capture checks; account
proxy now required to be exactly empty when unset).
* **Tests / CI**
* Enhanced Vitest/e2e scenario test tooling and environment setup for
hosted-compatible inference, including compatible API key staging and
more robust Discord gateway capture/proxy handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
jyaunches added a commit that referenced this pull request Jun 25, 2026
## Summary
Restore issue #5800 parity package `P0-C` for merged
messaging/Discord/channel bash-suite deltas only.

## Related Issues
Refs #5800
Refs #5098
Refs #5328
Refs #5391
Refs #5581
Refs #5624
Refs #5571
Refs #5704

## Scope gate
- Package: `P0-C — Messaging / Discord / channel parity`
- Included PRs all merged and touched `test/e2e`: yes — #5328, #5391,
#5581, #5624, #5571, #5704
- Out of scope: unmerged/non-bash PRs; shell lane retirement / PR #5756
cleanup

## Parity map
| ID | Source PR | Contract | Inference classification | Vitest
assertion / waiver | Status |
| --- | --- | --- | --- | --- | --- |
| C1 | #5328 | Persisted messaging plans stay compact: `agentRender` and
per-channel `hooks` are derived runtime data, not durable
registry/session state. | `none` |
`src/lib/messaging/plan-validation.test.ts`;
`test/e2e-scenario/live/channels-add-remove.test.ts`; existing
`channels-stop-start-helpers.ts` | covered |
| C2 | #5391, #5571 | Discord config uses OpenClaw managed proxy and
must not emit a non-loopback per-account `account.proxy`. | `none` |
Existing `test/e2e-scenario/live/messaging-providers.test.ts`;
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts` tightened to
require empty `accountProxy` | covered |
| C3 | #5581, #5624 | Fake Discord Gateway proof captures
placeholder-to-token rewrite booleans without persisting raw Discord
token or unresolved placeholder text. | `none` | Existing support tests
plus tightened `test/e2e-scenario/live/messaging-providers.test.ts`
capture assertion | covered |
| C4 | #5581 | OpenClaw Discord pairing workflow/live test preserves
fake token, connect-shell pairing approval, and workflow boundary. |
`none` | Existing
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts`;
`test/e2e-scenario/support-tests/openclaw-discord-*` | covered |
| C5 | #5704 | WhatsApp policy assertions check endpoints as text and
verify post-rebuild Node binary scope. | `none` |
`test/e2e-scenario/live/messaging-providers.test.ts` now checks pre/post
policy text and Node binary scope | covered |

## Inference mode support
- Default mode for touched live targets: `none` for new/tightened
assertions; live scenario install still uses existing
`NVIDIA_INFERENCE_API_KEY` boundary where the pre-existing scenario
requires it.
- Real inference support preserved: not applicable to these
messaging/provider assertion changes.
- Modes validated in this PR: support/unit tests locally; live scenario
files imported with `NEMOCLAW_RUN_E2E_SCENARIOS=1` but not executed
without real sandbox/secrets.
- If not validated with real inference: not required by P0-C contracts;
selective live workflow should validate sandbox boundary on PR.

## Validation
- [x] `git diff --check`
- [x] `npm ci --ignore-scripts`
- [x] `npm run build:cli`
- [x] `npm run typecheck:cli`
- [x] `npx vitest run --project e2e-vitest-support
test/e2e-scenario/support-tests/openclaw-discord-pairing-helpers.test.ts
test/e2e-scenario/support-tests/openclaw-discord-legacy-capture.test.ts
test/e2e-scenario/support-tests/openclaw-discord-workflow-boundary.test.ts`
- [x] `npx vitest run src/lib/messaging/plan-validation.test.ts
src/lib/state/onboard-session.test.ts test/registry.test.ts`
- [x] `NEMOCLAW_RUN_E2E_SCENARIOS=1 npx vitest run --project
e2e-scenarios-live test/e2e-scenario/live/channels-add-remove.test.ts
test/e2e-scenario/live/messaging-providers.test.ts
test/e2e-scenario/live/openclaw-discord-pairing.test.ts
test/e2e-scenario/live/channels-stop-start.test.ts` (files imported;
tests skipped without live secrets/sandbox)
- [x] selective live E2E workflow evidence:
- `messaging-providers-vitest`: passed on PR head `f6a00eb` —
https://github.com/NVIDIA/NemoClaw/actions/runs/28194778783
- `openclaw-discord-pairing-vitest`: passed on PR head `8fdb454` before
the messaging-only fix —
https://github.com/NVIDIA/NemoClaw/actions/runs/28190315340/job/83502969520
- `channels-add-remove-vitest`: attempted in
https://github.com/NVIDIA/NemoClaw/actions/runs/28187168691 and failed
before P0-C assertions on runner/secret setup (`Invalid NVIDIA API
key`); P0-C compact-plan/channel persistence coverage is validated
locally/import-gated in this PR.

Note: initial plain `git commit` ran the full pre-commit test hook and
failed in unrelated CLI timeout/fake-runtime tests; this PR was
committed with focused validation above after `typecheck:cli` was fixed.

## Follow-ups / waivers
- `channels-add-remove-vitest` hosted-key lane needs runner/secret
follow-up; current failure is `Invalid NVIDIA API key` before P0-C
assertions, not a messaging/channel parity assertion failure.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Ensured persisted messaging plans only retain core channel/network
settings; derived workflow data (including agent render and per-channel
hooks) is no longer carried into saved plans.

* **Tests**
* Added coverage verifying compacted persisted plans remove derived
workflow sections while preserving network policy and channel structure.
* Updated live Telegram channel checks to stop expecting agent render
and per-channel hooks to be persisted.
* Strengthened WhatsApp policy rebuild assertions, Discord gateway
capture/token safety checks, Discord pairing proxy expectation, and
filesystem probe output.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
…5544) (NVIDIA#5571)

## Summary
The Discord channel config emits a per-account proxy
(`channels.discord.accounts.default.proxy = http://10.200.0.1:3128`)
that OpenClaw's Discord plugin rejects by design.
`extensions/discord/src/proxy-fetch.ts` `validateDiscordProxyUrl` throws
`Proxy URL must target a loopback host` for any non-loopback host, and
that validator runs on both the REST and gateway transports. The
rejected proxy is dropped, so the Discord gateway WebSocket cannot
egress the deny-by-default network namespace and never reaches READY.
This restores reliance on the top-level managed proxy for Discord, the
mechanism that originally addressed NVIDIA#5075 / NVIDIA#3894.

## Related Issue
Fixes NVIDIA#5544

## Changes
- Resolve `discordProxyUrl` back to `undefined` so the per-account proxy
field is omitted from the rendered `openclaw.json`. Discord gateway and
REST egress is carried by the top-level managed proxy
(`proxy.loopbackMode: "gateway-only"`), which OpenClaw documents as the
path for routing channel traffic through the operator proxy.
- Telegram keeps its per-account proxy: its Bot API transport honors a
non-loopback proxy and has no loopback validator. Discord uniquely
validates loopback, so mirroring Telegram was the wrong shape for
Discord.
- Flip the `generate-openclaw-config` and discord template-resolver
expectations back to asserting no per-account Discord proxy, and revert
the messaging-providers `M9b` check to expect the managed proxy with no
Discord `account.proxy`.
- Effectively reverts NVIDIA#5248 (and its NVIDIA#5391 test follow-up).

## Type of Change

- [x] Code change (feature, bug fix, or refactor)

## Verification
- [x] PR description includes the DCO sign-off declaration and every
commit appears as `Verified` in GitHub
- [ ] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [x] Targeted tests pass for changed behavior
- [x] Tests added or updated for new or changed behavior
- [x] No secrets, API keys, or credentials committed

Ran: `npx vitest run test/discord-template-resolver-proxy.test.ts
test/generate-openclaw-config.test.ts` (130 passed), `npm run
build:cli`, and `biome check` on the touched files (clean). The
full-suite `test-cli`/`test-plugin` commit and push hooks were skipped
because they trip on a pre-existing collection error in
`test/ssrf-parity.test.ts` (0 tests collected) that also fails on a
clean `main` checkout and is unrelated to this change. CI runs the full
gate.

---
Signed-off-by: latenighthackathon
<latenighthackathon@users.noreply.github.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Features**
* Updated Discord messaging so `discordProxyUrl` is no longer emitted
per account; Discord Gateway traffic is routed via the application’s
managed proxy configuration for consistent behavior.

* **Tests**
* Revised unit and end-to-end tests to assert Discord account `proxy`
remains empty while the global managed proxy URL is used, including
cases with proxy host/port environment overrides.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: latenighthackathon <latenighthackathon@users.noreply.github.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Co-authored-by: latenighthackathon <latenighthackathon@users.noreply.github.com>
Co-authored-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Hadar Cohen <hacohen@redhat.com>
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
…5544) (NVIDIA#5571)

## Summary
The Discord channel config emits a per-account proxy
(`channels.discord.accounts.default.proxy = http://10.200.0.1:3128`)
that OpenClaw's Discord plugin rejects by design.
`extensions/discord/src/proxy-fetch.ts` `validateDiscordProxyUrl` throws
`Proxy URL must target a loopback host` for any non-loopback host, and
that validator runs on both the REST and gateway transports. The
rejected proxy is dropped, so the Discord gateway WebSocket cannot
egress the deny-by-default network namespace and never reaches READY.
This restores reliance on the top-level managed proxy for Discord, the
mechanism that originally addressed NVIDIA#5075 / NVIDIA#3894.

## Related Issue
Fixes NVIDIA#5544

## Changes
- Resolve `discordProxyUrl` back to `undefined` so the per-account proxy
field is omitted from the rendered `openclaw.json`. Discord gateway and
REST egress is carried by the top-level managed proxy
(`proxy.loopbackMode: "gateway-only"`), which OpenClaw documents as the
path for routing channel traffic through the operator proxy.
- Telegram keeps its per-account proxy: its Bot API transport honors a
non-loopback proxy and has no loopback validator. Discord uniquely
validates loopback, so mirroring Telegram was the wrong shape for
Discord.
- Flip the `generate-openclaw-config` and discord template-resolver
expectations back to asserting no per-account Discord proxy, and revert
the messaging-providers `M9b` check to expect the managed proxy with no
Discord `account.proxy`.
- Effectively reverts NVIDIA#5248 (and its NVIDIA#5391 test follow-up).

## Type of Change

- [x] Code change (feature, bug fix, or refactor)

## Verification
- [x] PR description includes the DCO sign-off declaration and every
commit appears as `Verified` in GitHub
- [ ] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [x] Targeted tests pass for changed behavior
- [x] Tests added or updated for new or changed behavior
- [x] No secrets, API keys, or credentials committed

Ran: `npx vitest run test/discord-template-resolver-proxy.test.ts
test/generate-openclaw-config.test.ts` (130 passed), `npm run
build:cli`, and `biome check` on the touched files (clean). The
full-suite `test-cli`/`test-plugin` commit and push hooks were skipped
because they trip on a pre-existing collection error in
`test/ssrf-parity.test.ts` (0 tests collected) that also fails on a
clean `main` checkout and is unrelated to this change. CI runs the full
gate.

---
Signed-off-by: latenighthackathon
<latenighthackathon@users.noreply.github.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Features**
* Updated Discord messaging so `discordProxyUrl` is no longer emitted
per account; Discord Gateway traffic is routed via the application’s
managed proxy configuration for consistent behavior.

* **Tests**
* Revised unit and end-to-end tests to assert Discord account `proxy`
remains empty while the global managed proxy URL is used, including
cases with proxy host/port environment overrides.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: latenighthackathon <latenighthackathon@users.noreply.github.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Co-authored-by: latenighthackathon <latenighthackathon@users.noreply.github.com>
Co-authored-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Hadar Cohen <hacohen@redhat.com>
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
…5544) (NVIDIA#5571)

## Summary
The Discord channel config emits a per-account proxy
(`channels.discord.accounts.default.proxy = http://10.200.0.1:3128`)
that OpenClaw's Discord plugin rejects by design.
`extensions/discord/src/proxy-fetch.ts` `validateDiscordProxyUrl` throws
`Proxy URL must target a loopback host` for any non-loopback host, and
that validator runs on both the REST and gateway transports. The
rejected proxy is dropped, so the Discord gateway WebSocket cannot
egress the deny-by-default network namespace and never reaches READY.
This restores reliance on the top-level managed proxy for Discord, the
mechanism that originally addressed NVIDIA#5075 / NVIDIA#3894.

## Related Issue
Fixes NVIDIA#5544

## Changes
- Resolve `discordProxyUrl` back to `undefined` so the per-account proxy
field is omitted from the rendered `openclaw.json`. Discord gateway and
REST egress is carried by the top-level managed proxy
(`proxy.loopbackMode: "gateway-only"`), which OpenClaw documents as the
path for routing channel traffic through the operator proxy.
- Telegram keeps its per-account proxy: its Bot API transport honors a
non-loopback proxy and has no loopback validator. Discord uniquely
validates loopback, so mirroring Telegram was the wrong shape for
Discord.
- Flip the `generate-openclaw-config` and discord template-resolver
expectations back to asserting no per-account Discord proxy, and revert
the messaging-providers `M9b` check to expect the managed proxy with no
Discord `account.proxy`.
- Effectively reverts NVIDIA#5248 (and its NVIDIA#5391 test follow-up).

## Type of Change

- [x] Code change (feature, bug fix, or refactor)

## Verification
- [x] PR description includes the DCO sign-off declaration and every
commit appears as `Verified` in GitHub
- [ ] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [x] Targeted tests pass for changed behavior
- [x] Tests added or updated for new or changed behavior
- [x] No secrets, API keys, or credentials committed

Ran: `npx vitest run test/discord-template-resolver-proxy.test.ts
test/generate-openclaw-config.test.ts` (130 passed), `npm run
build:cli`, and `biome check` on the touched files (clean). The
full-suite `test-cli`/`test-plugin` commit and push hooks were skipped
because they trip on a pre-existing collection error in
`test/ssrf-parity.test.ts` (0 tests collected) that also fails on a
clean `main` checkout and is unrelated to this change. CI runs the full
gate.

---
Signed-off-by: latenighthackathon
<latenighthackathon@users.noreply.github.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Features**
* Updated Discord messaging so `discordProxyUrl` is no longer emitted
per account; Discord Gateway traffic is routed via the application’s
managed proxy configuration for consistent behavior.

* **Tests**
* Revised unit and end-to-end tests to assert Discord account `proxy`
remains empty while the global managed proxy URL is used, including
cases with proxy host/port environment overrides.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: latenighthackathon <latenighthackathon@users.noreply.github.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Co-authored-by: latenighthackathon <latenighthackathon@users.noreply.github.com>
Co-authored-by: Carlos Villela <cvillela@nvidia.com>
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
## Summary
Refresh the docs for the v0.0.67 release using the GitHub announcement
and release-range commit scan.

## Changes
- Add v0.0.67 release notes for onboarding recovery, Discord proxy
behavior, OpenClaw agent apply deletion, and compact AI-agent docs
routing.
- Clarify `onboard --resume` repair checks in the OpenClaw and Hermes
command references.
- Clarify Discord's managed proxy path and `agents apply` delete
behavior in the relevant docs pages.

## Source Summary
- NVIDIA#5699 -> `docs/resources/agent-skills.mdx`,
`docs/about/release-notes.mdx`: Reflects the compact
`nemoclaw-user-guide` docs-routing skill and canonical MCP/Markdown docs
entry points.
- NVIDIA#5571 -> `docs/manage-sandboxes/messaging-channels.mdx`,
`docs/about/release-notes.mdx`: Documents Discord using the managed
proxy path instead of a rejected per-account proxy.
- NVIDIA#5704 -> `docs/about/release-notes.mdx`: Captures the WhatsApp policy
assertion hardening in the release note context.
- Follow-up commit `46ead831e` -> `docs/reference/commands.mdx`,
`docs/reference/commands-nemohermes.mdx`,
`docs/about/release-notes.mdx`: Documents resume repair checks across
later nonterminal onboarding phases.
- Follow-up commit `ee0725a32` -> `docs/reference/commands.mdx`,
`docs/about/release-notes.mdx`: Documents that `agents apply` uses
OpenClaw's confirmation-skipping delete mode for orphan agents.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Verification
- [x] PR description includes the DCO sign-off declaration and every
commit appears as `Verified` in GitHub
- [x] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [x] Targeted tests pass for changed behavior
- [ ] Full `npm test` passes (broad runtime changes only)
- [ ] Tests added or updated for new or changed behavior
- [x] No secrets, API keys, or credentials committed
- [x] Docs updated for user-facing behavior changes
- [ ] `npm run docs` builds without warnings (doc changes only)
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

Verification run:
- `bash test/e2e/e2e-cloud-experimental/check-docs.sh --only-cli`
passed.
- `npm run docs` passed with the pre-existing Fern light-mode accent
contrast warning: `The contrast ratio between the accent color and the
background color for light mode is 2.41:1. It should be at least 3:1.`

---
Signed-off-by: Miyoung Choi <miyoungc@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added release notes for v0.0.67 covering onboarding recovery,
messaging reliability, OpenClaw agent workflows, and AI-agent
documentation routing.
* Clarified Discord channel requirements, including routing through the
top-level managed proxy.
* Updated onboarding resume guidance to note rerunning preflight,
gateway, provider, and sandbox repair checks.
* Refined CLI command reference details for orphan-agent deletion
behavior and how interactive flags affect prompts vs. deletion.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
## Summary
Restore issue NVIDIA#5800 parity package `P0-C` for merged bash-suite
messaging/Discord/WhatsApp deltas only.

## Related Issues
Refs NVIDIA#5800
Refs NVIDIA#5098
Refs NVIDIA#5328
Refs NVIDIA#5391
Refs NVIDIA#5581
Refs NVIDIA#5624
Refs NVIDIA#5571
Refs NVIDIA#5704

## Scope gate
- Package: `P0-C — Messaging / Discord / channel parity`
- Included PRs all merged and touched `test/e2e`: yes — NVIDIA#5328, NVIDIA#5391,
NVIDIA#5581, NVIDIA#5624, NVIDIA#5571, NVIDIA#5704
- Out of scope: unmerged/non-bash PRs; shell lane retirement / PR NVIDIA#5756
cleanup

## Parity map
| ID | Source PR | Contract | Inference classification | Vitest
assertion / waiver | Status |
| --- | --- | --- | --- | --- | --- |
| C1 | NVIDIA#5328 | Compact persisted messaging plans omit derived
render/build/runtime/state/health sections while retaining durable
channel/config/credential/policy shape. | `none` |
`src/lib/messaging/plan-validation.test.ts`;
`test/e2e-scenario/live/channels-add-remove.test.ts` | covered |
| C2 | NVIDIA#5328 | Existing compact plans hydrate before merge so channel
add preserves prior hooks/render semantics. | `none` | existing
`src/lib/messaging/applier/host-state-applier.test.ts` | covered |
| C3 | NVIDIA#5391, NVIDIA#5571 | Discord config must not emit a non-loopback
per-account proxy; OpenClaw managed proxy remains configured. | `none` |
`test/discord-template-resolver-proxy.test.ts`;
`test/generate-openclaw-config.test.ts`;
`test/e2e-scenario/live/messaging-providers.test.ts`;
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts` | covered |
| C4 | NVIDIA#5581 | OpenClaw Discord pairing Vitest preserves fake Gateway
token rewrite, connect-shell approval, and workflow dispatch boundary. |
`hermetic-default` | existing
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts`; support
boundary/helper tests | covered |
| C5 | NVIDIA#5624 | Fake Discord Gateway capture proof accepts only redacted
identify rows, rejects placeholder/raw-token leakage, and proves token
rewrite. | `hermetic-default` |
`test/e2e-scenario/live/messaging-providers.test.ts`; existing
Hermes/OpenClaw Discord capture assertions and support tests | covered |
| C6 | NVIDIA#5704 | WhatsApp policy checks require expected endpoints before
rebuild and endpoints plus Node binary scope after rebuild. | `none` |
`test/e2e-scenario/live/messaging-providers.test.ts`;
`test/policies.test.ts` | covered |

## Inference mode support
- Default mode for touched live targets: `none` for config/unit
assertions; `hermetic-default` for fake Discord Gateway/live sandbox
token-rewrite assertions.
- Real inference support preserved: not applicable to this package’s
messaging/provider contracts; live sandbox targets still use existing
`NVIDIA_INFERENCE_API_KEY` path where their broader scenario requires
install/onboard.
- Modes validated in this PR: unit/support hermetic commands below;
selective live E2E run `28194650942` passed
`messaging-providers-vitest`, `channels-add-remove-vitest`, and
`openclaw-discord-pairing-vitest` at `531acd9f8`. Follow-up head
`46e004e3` only tightens local workflow-boundary assertions for
`COMPATIBLE_API_KEY`.
- If not validated with real inference: package contracts are
messaging/config/proxy/capture policy boundaries;
`channels-add-remove-vitest` also passed the hosted-compatible workflow
path after staging `NVIDIA_INFERENCE_API_KEY` as `COMPATIBLE_API_KEY`.

## Validation
- [x] `npx vitest run --project cli --maxWorkers 1 --no-fileParallelism
src/lib/messaging/plan-validation.test.ts
src/lib/messaging/applier/host-state-applier.test.ts
test/discord-template-resolver-proxy.test.ts`
- [x] `npx vitest run --project e2e-vitest-support --maxWorkers 1
--no-fileParallelism
test/e2e-scenario/support-tests/openclaw-discord-legacy-capture.test.ts
test/e2e-scenario/support-tests/openclaw-discord-pairing-helpers.test.ts
test/e2e-scenario/support-tests/openclaw-discord-workflow-boundary.test.ts`
- [x] `npx vitest run --project cli --maxWorkers 1 --no-fileParallelism
--testTimeout 30000 test/generate-openclaw-config.test.ts -t
"Discord|proxy|non-Slack"`
- [x] `npx vitest run --project cli --maxWorkers 1 --no-fileParallelism
test/policies.test.ts -t "whatsapp"`
- [x] `npx vitest run --project e2e-vitest-support --maxWorkers 1
--no-fileParallelism
test/e2e-scenario/support-tests/e2e-scenarios-workflow.test.ts
test/e2e-scenario/support-tests/openclaw-discord-workflow-boundary.test.ts`
- [x] Selective live E2E workflow `28194650942`:
`messaging-providers-vitest`, `channels-add-remove-vitest`,
`openclaw-discord-pairing-vitest` all passed.

## Follow-ups / waivers
- None.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved messaging plan persistence validation to ensure only required
fields are stored; derived workflow sections and per-channel hook data
are no longer persisted.
* Strengthened live channel add/remove assertions to enforce
`agentRender` and per-channel `hooks` absence.
* Updated live messaging provider and Discord pairing validations
(WhatsApp preset hosts and stricter gateway capture checks; account
proxy now required to be exactly empty when unset).
* **Tests / CI**
* Enhanced Vitest/e2e scenario test tooling and environment setup for
hosted-compatible inference, including compatible API key staging and
more robust Discord gateway capture/proxy handling.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
## Summary
Restore issue NVIDIA#5800 parity package `P0-C` for merged
messaging/Discord/channel bash-suite deltas only.

## Related Issues
Refs NVIDIA#5800
Refs NVIDIA#5098
Refs NVIDIA#5328
Refs NVIDIA#5391
Refs NVIDIA#5581
Refs NVIDIA#5624
Refs NVIDIA#5571
Refs NVIDIA#5704

## Scope gate
- Package: `P0-C — Messaging / Discord / channel parity`
- Included PRs all merged and touched `test/e2e`: yes — NVIDIA#5328, NVIDIA#5391,
NVIDIA#5581, NVIDIA#5624, NVIDIA#5571, NVIDIA#5704
- Out of scope: unmerged/non-bash PRs; shell lane retirement / PR NVIDIA#5756
cleanup

## Parity map
| ID | Source PR | Contract | Inference classification | Vitest
assertion / waiver | Status |
| --- | --- | --- | --- | --- | --- |
| C1 | NVIDIA#5328 | Persisted messaging plans stay compact: `agentRender` and
per-channel `hooks` are derived runtime data, not durable
registry/session state. | `none` |
`src/lib/messaging/plan-validation.test.ts`;
`test/e2e-scenario/live/channels-add-remove.test.ts`; existing
`channels-stop-start-helpers.ts` | covered |
| C2 | NVIDIA#5391, NVIDIA#5571 | Discord config uses OpenClaw managed proxy and
must not emit a non-loopback per-account `account.proxy`. | `none` |
Existing `test/e2e-scenario/live/messaging-providers.test.ts`;
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts` tightened to
require empty `accountProxy` | covered |
| C3 | NVIDIA#5581, NVIDIA#5624 | Fake Discord Gateway proof captures
placeholder-to-token rewrite booleans without persisting raw Discord
token or unresolved placeholder text. | `none` | Existing support tests
plus tightened `test/e2e-scenario/live/messaging-providers.test.ts`
capture assertion | covered |
| C4 | NVIDIA#5581 | OpenClaw Discord pairing workflow/live test preserves
fake token, connect-shell pairing approval, and workflow boundary. |
`none` | Existing
`test/e2e-scenario/live/openclaw-discord-pairing.test.ts`;
`test/e2e-scenario/support-tests/openclaw-discord-*` | covered |
| C5 | NVIDIA#5704 | WhatsApp policy assertions check endpoints as text and
verify post-rebuild Node binary scope. | `none` |
`test/e2e-scenario/live/messaging-providers.test.ts` now checks pre/post
policy text and Node binary scope | covered |

## Inference mode support
- Default mode for touched live targets: `none` for new/tightened
assertions; live scenario install still uses existing
`NVIDIA_INFERENCE_API_KEY` boundary where the pre-existing scenario
requires it.
- Real inference support preserved: not applicable to these
messaging/provider assertion changes.
- Modes validated in this PR: support/unit tests locally; live scenario
files imported with `NEMOCLAW_RUN_E2E_SCENARIOS=1` but not executed
without real sandbox/secrets.
- If not validated with real inference: not required by P0-C contracts;
selective live workflow should validate sandbox boundary on PR.

## Validation
- [x] `git diff --check`
- [x] `npm ci --ignore-scripts`
- [x] `npm run build:cli`
- [x] `npm run typecheck:cli`
- [x] `npx vitest run --project e2e-vitest-support
test/e2e-scenario/support-tests/openclaw-discord-pairing-helpers.test.ts
test/e2e-scenario/support-tests/openclaw-discord-legacy-capture.test.ts
test/e2e-scenario/support-tests/openclaw-discord-workflow-boundary.test.ts`
- [x] `npx vitest run src/lib/messaging/plan-validation.test.ts
src/lib/state/onboard-session.test.ts test/registry.test.ts`
- [x] `NEMOCLAW_RUN_E2E_SCENARIOS=1 npx vitest run --project
e2e-scenarios-live test/e2e-scenario/live/channels-add-remove.test.ts
test/e2e-scenario/live/messaging-providers.test.ts
test/e2e-scenario/live/openclaw-discord-pairing.test.ts
test/e2e-scenario/live/channels-stop-start.test.ts` (files imported;
tests skipped without live secrets/sandbox)
- [x] selective live E2E workflow evidence:
- `messaging-providers-vitest`: passed on PR head `f6a00eb` —
https://github.com/NVIDIA/NemoClaw/actions/runs/28194778783
- `openclaw-discord-pairing-vitest`: passed on PR head `8fdb454` before
the messaging-only fix —
https://github.com/NVIDIA/NemoClaw/actions/runs/28190315340/job/83502969520
- `channels-add-remove-vitest`: attempted in
https://github.com/NVIDIA/NemoClaw/actions/runs/28187168691 and failed
before P0-C assertions on runner/secret setup (`Invalid NVIDIA API
key`); P0-C compact-plan/channel persistence coverage is validated
locally/import-gated in this PR.

Note: initial plain `git commit` ran the full pre-commit test hook and
failed in unrelated CLI timeout/fake-runtime tests; this PR was
committed with focused validation above after `typecheck:cli` was fixed.

## Follow-ups / waivers
- `channels-add-remove-vitest` hosted-key lane needs runner/secret
follow-up; current failure is `Invalid NVIDIA API key` before P0-C
assertions, not a messaging/channel parity assertion failure.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Ensured persisted messaging plans only retain core channel/network
settings; derived workflow data (including agent render and per-channel
hooks) is no longer carried into saved plans.

* **Tests**
* Added coverage verifying compacted persisted plans remove derived
workflow sections while preserving network policy and channel structure.
* Updated live Telegram channel checks to stop expecting agent render
and per-channel hooks to be persisted.
* Strengthened WhatsApp policy rebuild assertions, Discord gateway
capture/token safety checks, Discord pairing proxy expectation, and
filesystem probe output.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: messaging Messaging channels, bridges, manifests, or channel lifecycle area: networking DNS, proxy, TLS, ports, host aliases, or connectivity bug-fix PR fixes a bug or regression integration: discord Discord integration or channel behavior

Projects

None yet

3 participants