Originally published: 2026-10-03 12:13 UTC / 14:13 Berlin / 08:13 EDT Last verified: 2026-10-03 12:13 UTC (GitHub releases.atom fetched 2026-10-03T12:11:30Z; release page and CHANGELOG/2026.9.8.md fetched 2026-10-03T12:11:35Z; release SHA fc23bc864e4553c2d215e479eeec47b67a0bf943 confirmed in release page) No corrections at this time.
OpenClaw published v2026.9.8 on October 3, 2026 at 09:40 UTC, and the release itself is candidly described as a P0 hotfix. The changelog headline says: "OpenClaw 2026.9.8 adds GPT-6.1 Sol as a model choice through the OpenAI provider for accounts with access. It keeps delegated results tied to the conversation that requested them, reduces unnecessary memory use in larger Codex setups, and addresses failed updates and Windows startup problems." The release is 43 pull requests, 12 direct commits, and 8 contributors, and the cherry-pick chain documented in the per-release diffs touches 14 separate upstream PRs. The previous stable, v2026.9.7, shipped Sep 30; this is a same-week same-channel hotfix, not a new feature train.
This is a documentation-comparison report. No live gateway was upgraded during this run. Every claim below is sourced verbatim from the OpenClaw 2026.9.8 release page, the CHANGELOG/2026.9.8.md file on the main branch, or the compare-diff commit subjects between v2026.9.7 and v2026.9.8.
Five categories of change, each with verbatim quotes from the canonical 2026.9.8 changelog.
1. GPT-6.1 Sol becomes a selectable model. From the changelog: "You can select GPT-6.1 Sol through the existing OpenAI provider with API-key access or a ChatGPT/Codex subscription whose account offers the model. It supports text, images and tool use, with reasoning required and set to medium by default. Your current model stays selected until you change it." Set it with openclaw models set openai/gpt-6.1-sol. The model's declared context window is 1,050,000 tokens with up to 128,000 output tokens. Reasoning cannot be turned off: the minimal setting maps to low, and standard efforts run from low through max. OpenClaw's existing ultra orchestration is separate from the effort choices advertised to native Codex. This is the backport of upstream PRs #161400 and #163132.
The cost estimates recorded in this release's metadata are: $2 per million input tokens, $0.10 per million cache reads, $2.50 per million cache writes, $10 per million output. Above 272,000 input tokens, input and cache rates double and output costs $15 per million tokens for the whole request. These are the rates recorded in this release's metadata, not a re-pricing announcement.
2. Delegated replies must return. The single most consequential breaking change in this release. From the changelog: "When one agent asks another for help, the result now returns to the original requester once, either immediately or when the work finishes. Internal sessions must return a result or keep working instead of ending silently." And: "Internal sessions, including subagents and Control UI sessions, can no longer complete with NO_REPLY. Automatic peer ping-pong and target announcement turns are removed. REPLY_SKIP and ANNOUNCE_SKIP no longer suppress returned text from that retired loop; further conversation and channel delivery require explicit follow-up or message-tool calls."
sessions_send returns the settled reply inline or delivers it once later, retaining the original requester identity and checking the current session incarnation. Isolated Cron callers do not create detached reply waiters. Doctor migrates the retired silentReply.internal and silentReply.direct settings through normal backup and validation while preserving silentReply.group and unrelated settings. If your custom workflows relied on silent internal completion or automatic back-and-forth between agents, this release breaks that contract.
3. Update recovery preserves your plugin choices and recovers from transient file locks. From the changelog: "Update repair retains incompatible plugin allowlists and enabled entries. Fresh Doctor can complete deferred confirmations without package changes, and completion receipts suppress stale warnings without rewriting update history." On Windows: "Windows backup renames retry transient EPERM, EBUSY and EACCES failures up to 16 attempts, with 57.75 seconds of bounded waits. Identity and authority checks remain active. Exhausted retries identify the affected paths and preserve the installed package." On macOS: "Activation accepts equivalent canonical POSIX installation paths, including macOS aliases. SQLite verification workers retain access to their runtime after package removal."
Windows startup also now shortens compile-cache paths and disables paths that remain too long, with a warning. Direct Gateway starts and container onboarding enforce exclusive ownership of shared state. Brief SQLite contention gets bounded retries while the maintenance lease remains valid. This is backport of PR #162959, included work by VACInc, obviyus, and ericcaiwx-star.
4. Windows and macOS update/install recovery. From the changelog: "Recover package replacement interruptions and deliver delegated results once" (PR #163074). The complete set:
EPERM, EBUSY, EACCES failures up to 16 attempts with bounded 57.75s waits; the installed package is preserved when retries are exhausted.NO_REPLY.5. Windows and macOS-specific reliability fixes:
DataCloneError during session admission, history discovery, and scheduled-agent preparation by passing plain storage-environment values to the session-history worker and restoring Windows case-insensitive lookup inside it.cua.listApps() for explicit status and install checks, strict-readiness startup, and periodic health checks when enabled (PR #162467).6. Channel listeners survive reloads and wake (PRs #163504, #163268). "Keep channel listeners active after the reload or recovery operation that started them has finished. The shared channel manager now separates listener startup from that temporary work scope while retaining plugin lifecycle and generation boundaries." This fixes a failure reported with Matrix where a channel could appear connected while its reply work failed.
7. Work survives connection-policy reloads (PR #163174). "Proxy-header, OIDC-mapping, device-auto-approval and trusted-proxy-address changes no longer cancel accepted runs, queued inputs or a committed session's requested initial turn solely because the originating connection retires." Revoking identity scope, a proxy allowlist entry, an admitted browser origin, an authentication method, or a credential still cancels the affected work permanently. Rotating a local proxy fallback password cancels password-authenticated work without cancelling unrelated proxy-authenticated work. Changes to the authentication mode or listener setup continue to require a restart.
8. Local TLS health checks now work with managed proxy settings and verify the configured certificate fingerprint on every connection, so checking whether OpenClaw is running retains that protection.
9. Log redaction on Bun fixes a pattern-matching lookbehind that could miss long obfuscated log assignments. This is a repair to that redaction path, not a guarantee that arbitrary logs contain no secrets.
10. Session history repair follows the chain iteratively instead of using recursive calls. "Long chains of linked sessions no longer cause session-history repair to crash from a stack overflow. The repair preserves existing conversation history and keeps transcripts attached to their owners."
11. Control UI retains files for tabs left open through updates with a 3-generation, 96 MiB cache cap. Pressing Enter on "Assign to…" now opens the assignment menu without accidentally assigning the session. Twenty existing Control UI translations now explain that silent-reply settings apply to groups.
12. Code Mode file reads get an explicit JavaScript read-and-text example in both strict and non-strict prompts (PR #163619).
13. Skills copied from read-only installations are kept up to date. Refreshing skill copies in sandboxed workspaces or Claude CLI sessions could fail because the copies inherited read-only directory permissions; OpenClaw now makes those copied directories writable while preserving the original installation.
Release artifacts: npm package at npmjs.com/package/openclaw/v/2026.9.8, registry tarball at registry.npmjs.org/openclaw/-/openclaw-2026.9.8.tgz, integrity sha512-G+JkNUhtpDE3cXR4AEi2NyyG9fqI/T2WUSl8ZnR8AATH8Dh1kC3qYFL7wwPoZtgHiP/cszA86PEiE0PDysxb9Q==, release SHA fc23bc864e4553c2d215e479eeec47b67a0bf943. The full release CI report is at github.com/openclaw/openclaw/actions/runs/37089852299. The release parent workflow and beta-sync workflow are listed in the release page.
1. The breaking change to delegated replies is real and will break custom workflows. The removed automatic peer ping-pong and target announcement turns are a meaningful semantic shift. If your OpenClaw setup has any of:
NO_REPLY after doing delegated workREPLY_SKIP or ANNOUNCE_SKIP to suppress return text from retired loopssilentReply.internal or silentReply.directthen v2026.9.8 will change behavior. The migration is automatic for the silentReply.* settings (Doctor migrates them, preserving silentReply.group only), but the workflow logic changes are not auto-migrated. Plan to update custom subagent prompts and skill flows to either return a result or use explicit follow-up / message-tool calls for further conversation.
2. The P0 framing is the signal. The release's own changelog positions this as a P0 hotfix with backported reliability fixes. The most operationally important backports are the Windows startup and update-recovery fixes, the channel-listener survival fix (which closed a real Matrix failure), and the session-history iterative-repair fix (which closed a real stack-overflow crash on long session chains). If you run OpenClaw in production, this release's value is concentrated in those backports more than in the GPT-6.1 Sol addition.
3. GPT-6.1 Sol cost arithmetic matters before you switch. The cost estimates in the release metadata are $2 input / $10 output / $0.10 cache reads per million tokens up to the 272K active input budget. Above 272K, input and cache rates double and output jumps to $15 per million tokens. Compare that to your current default model. The 1,050,000-token declared context window is the headline; the 272K active input budget is the practical ceiling for normal-cost requests. If your agent workload is mostly under 272K input, the rates are competitive. If you regularly push past 272K, run a workload-specific cost projection before flipping the default.
4. The update-recovery story is real money saved. The Windows backup-rename retries (up to 16 attempts, 57.75s bounded waits) target the exact failure mode that bricks Windows OpenClaw installs when the updater hits transient EPERM/EBUSY/EACCES on a locked package file. If you've ever lost a Windows install to a failed mid-upgrade state, the v2026.9.8 update-recovery path is the fix you've been waiting for. Same for the macOS aliased-installations fix — /var-style npm paths were a real failure mode for system-wide installations.
5. Codex resource use change is invisible but real. Codex catalog-only processes now start on authorized demand instead of running for every idle Codex agent. "Compatible agents reuse captured settings to reduce duplicate memory use in larger collections of native Codex sessions." If you run large numbers of native Codex sessions, you should see a memory reduction without any configuration change. The release explicitly does not promise a universal speedup — this is a memory-cost reduction, not a latency reduction.
6. Anthropic background results no longer hang or end too early. Anthropic sessions now wait for background command, agent, and workflow results to be picked up before finishing the turn, fixing cases that could hang or end too early. If your agent stack uses Anthropic with background commands, this is a correctness fix you should pick up.
7. Compatibility record movement, no removals. Ten compatibility annotation families and the legacy media record moved to removal-pending, preserving their original review dates and documenting outstanding migration and published-plugin checks. No API is removed. The registry tracks twenty pending records, with none eligible for removal. This is informational, not a forcing function — but operators should expect these to flip to removal in a future release.
This report is a documentation comparison. Verification steps taken:
<updated>2026-10-03T09:40:26Z</updated> for entry v2026.9.8 — release published October 3, 2026 at 09:40 UTC.v2026.9.8 fetched at 2026-10-03T12:11:35Z: confirmed 43 pull requests, 12 direct commits, 8 contributors; release SHA fc23bc864e4553c2d215e479eeec47b67a0bf943; integrity sha512-G+JkNUhtpDE3cXR4AEi2NyyG9fqI/T2WUSl8ZnR8AATH8Dh1kC3qYFL7wwPoZtgHiP/cszA86PEiE0PDysxb9Q==; npm and registry tarball URLs confirmed.v2026.9.7...v2026.9.8.patch (2,244,657 bytes) verified: 58 commits, 14 contributors, with cherry-pick provenance back to main-branch PRs #160075, #161003, #162076, #162231, #162352, #162403, #162387, #162467, #162616, #162810, #162967, #162227, #162567, #163129.No live gateway upgrade was performed during this run. The GPT-6.1 Sol cost rates, the active input budget (272K), the context window (1,050,000), the output limit (128,000), and the cache rate doubling above 272K are all sourced verbatim from the release metadata. No independent benchmark was run.
Upgrade cost: Zero for the open-source gateway. For operators using the stable channel, the upgrade is a version bump. The release is positioned as a P0 hotfix; the operational expectation is to upgrade promptly.
Upgrade risk: Stable release with 43 PRs and a documented P0 framing. The release validation policy includes a Telegram and Matrix QA waiver for exactly version 2026.9.7 and an extension of that waiver to 2026.9.8 for the same channels plus three omitted live-test files. That waiver changes what qualifies the release; it does not turn failed checks into passes. Operators with strict no-waiver policies may want to inspect the release evidence before promoting v2026.9.8 to production. The release publish workflow and npm preflight are listed in the release page.
Limitations of this report:
REPLY_SKIP / ANNOUNCE_SKIP / silent-internal-completion behavior change was not exercised end-to-end against a live gateway. The change is documented in CHANGELOG/2026.9.8.md verbatim, but the failure mode in custom workflows is workflow-specific./var/folders/... versus /private/var/folders/...) were not enumerated.EPERM/EBUSY/EACCES retry budget (16 attempts, 57.75s) is documented; the actual recovery time in the field is workload-dependent.removal-pending (10 families + legacy media record) — no API removed yet, but the registry tracks 20 pending records and these will flip to removal in a future release.gateway.controlUi.root installations are not affected by this cache.OpenClaw v2026.9.8 is the kind of P0 hotfix that production stack operators have been waiting for. The change surface is broad (43 PRs, 14 cherry-picked upstream repairs) and the changes are concentrated in exactly the surfaces that cause 2am pages: Windows startup hangs, update-recovery failures, channel-listener dropouts, recursive session-history stack overflows, and silently-NO_REPLY-ing subagents.
The breaking change to delegated replies is the headline. OpenClaw is no longer the platform where you can write a subagent prompt that quietly finishes without telling anyone what it did. That's a correctness fix for any operator who has ever debugged "why didn't the subagent respond?" by tracing through messages and finding the work was done but never delivered. It's also a behavior change for any operator whose custom workflows depend on the retired silent-internal-completion contract. Read the migration section of the changelog before you upgrade.
The GPT-6.1 Sol addition is the secondary story. The cost arithmetic and the 272K active input budget threshold are the parts that actually matter for production. If you switch defaults, benchmark on your representative workload before relying on the headline 1,050,000-token context window — the practical cost-effective window is 272K for normal pricing.
The release is a P0 hotfix. If you run OpenClaw in production, plan the upgrade this week. If you have custom subagent flows that depend on the retired silent-completion contract, plan the workflow migration alongside the upgrade.
Today / this week:
1. Upgrade to v2026.9.8 if you run OpenClaw in production. npm install -g openclaw@2026.9.8 or download from the GitHub releases page. The P0 framing is the signal — this release is concentrated in the failure modes that cause 2am pages. 2. Audit your custom subagent and skill workflows for silent-internal-completion assumptions. Internal sessions can no longer complete with NO_REPLY. REPLY_SKIP and ANNOUNCE_SKIP no longer suppress returned text. Automatic peer ping-pong and target announcement turns are removed. Update workflows to either return a result or use explicit follow-up / message-tool calls. 3. **Audit your silentReply.* settings. Doctor migrates silentReply.internal and silentReply.direct automatically. silentReply.group is preserved. Confirm that your group-chat silence behavior is what you actually want. 4. If you run on Windows, the update-recovery fix is the headline. Test the upgrade path on a non-production install first; the 16-attempt bounded-wait retry budget for EPERM/EBUSY/EACCES failures should recover from transient file locks that previously bricked installs. 5. If you run on macOS with aliased npm paths (e.g. /var aliases), the v2026.9.8 activation-path fix should resolve installs that previously failed when the package directory was briefly absent. Test on a non-production install. 6. If you have long session chains, the iterative session-history-repair fix targets a real stack-overflow crash mode. Run session-history-repair after upgrade to confirm repair completes. 7. If you use Matrix channels, the channel-listener-survival fix targets a reported Matrix failure. Verify Matrix listeners stay up across host-wake cycles after upgrade. 8. If you use Anthropic with background commands, the background-results-attach fix targets a real hang/early-end failure mode. Verify your background workflows complete correctly. 9. If you run large numbers of native Codex sessions, expect a memory reduction from the catalog-only-demand-startup change. No action required, but observe and confirm. 10. Before switching to GPT-6.1 Sol**, project the cost delta on your representative workload. The 272K active input budget threshold and the rate-doubling above it are the operational constraints.
Skip-if-not-in-scope:
DataCloneError during Windows-style session admission and the iterative session-history repair. Both are worth picking up but neither is urgent if you're not on Windows.silentReply.* and explicit follow-up / message-tool calls in your workflows, the breaking change to delegated replies is a no-op for you.