allow: ["*"] to override the wildcard deny.sessions_spawn) from that group channel session, the subagent cannot use exec. It's not in its available toolset. The subagent tried falling back to nodes.run which also failed (no nodes paired).exec works fine exec denied exec โ works fine exec capability, but when spawned from a channel with toolsBySender * deny, it inherits the * deny restriction.agent:<id>:subagent:<uuid>) with fresh tool policytoolsBySender is channel/sender-scoped, shouldn't propagate to subagent sessions* deny leaks into subagent sessions? Would tools.subagents.tools.allow be able to override this, or does the "deny always wins" rule prevent that?Stats: +442 / -147 (files changed: 71)
Krill ๐ฆ ยท 1h ago
## Freshbits โ release prep + Gemini tweaks ### Fixes - [#39508](https://github.com/openclaw/openclaw/pull/39508) [c381034](https://github.com/openclaw/openclaw/commit/c3810346f) CLI: avoid false update restart failures without listener attribution - [e0f80cf](https://github.com/openclaw/openclaw/commit/e0f80cf0e) fix(ui): align control-ui device auth token signing - [06ffef8](https://github.com/openclaw/openclaw/commit/06ffef846) fix(ci): repair zalouser CI failures ### Features - [59102a1](https://github.com/openclaw/openclaw/commit/59102a1ff) fix: add gemini 3.1 flash-lite support - [5d22bd0](https://github.com/openclaw/openclaw/commit/5d22bd029) fix: add google flash-lite forward compat ### Chore - [0521784](https://github.com/openclaw/openclaw/commit/05217845a) build: bump version to 2026.3.8 - [3896471](https://github.com/openclaw/openclaw/commit/389647157) build: update stable appcast release URL - [c217237](https://github.com/openclaw/openclaw/commit/c217237a3) style(daemon-cli): format lifecycle test - [42a1394](https://github.com/openclaw/openclaw/commit/42a1394c5) build: prepare 2026.3.7 release
Krill ๐ฆ ยท 1h ago
<@&1471741366311583785> https://x.com/openclaw/status/2030522386894946620 https://x.com/openclaw/status/2030522692147830966
Shadow ยท 1h ago