Repository navigation
Releases: KCNyu/clawock
Release list
clawock v0.3.1
Install from PyPI:
python -m pip install clawock==0.3.1A maintenance release for the Python package and clawock-dsh, with corrected
session accounting, clearer evidence and delivery readouts, and task-panel
improvements. Restart DeepSeek Harness after upgrading clawock-dsh so its
host methods and client bundle come from the same version.
Added
clawock-dsh:/dispatch-listfor OpenClaw, sharing the sidebar's
provider balances, task queue, recent completions and patrol view (#2168).clawock-dsh: task timelines, append history and patrol coverage, with
readable findings, links to full task logs and Markdown chat layouts
(#2425, #2426, #2443, #2518, #2529).
Changed
- Dependency updates: Python now requires
requests>=2.32.4to include
the credential-leak fix; the DSH protocol, client store and UI slots move
to the0.2.0-rc.2line (#2165, #2578). - The README and its diagrams explain the complete workflow before setup,
with separate US/HK return curves, evidence and judgment feedback loops,
and consistent icons and flow types (#2664, #2735, #2736, #2740, #2749).
Fixed
- Portfolio accounting follows each market's trading session. Per-lot
daily P&L handles same-session buys; malformed ledger rows are reported;
unknown sessions fail the integrity check without crashing; quote refreshes
preserve concurrent ledger edits and previous closes (#2355, #2400, #2408,
#2505, #2650). Leveraged bars are checked against their underlying where
evidence is available, and suspect settlement marks carry refusal reasons
(#2357, #2601). - Lifecycle CLI flags match the selected phase and report mode, optional
dependency errors name the required extra, and brief fallback honors the
selected workspace (#2554, #2619, #2651, #2734). - Brief and intraday evidence checks use complete, dated sources. News
windows follow publication time, stale-news checks cover all reference
families, trigger text and currency totals are grounded in source data,
and scorecard provenance detects rewritten rows (#2236, #2257, #2357,
#2475, #2584, #2598). - Delivery and health checks preserve failures and recovery evidence.
Watchdogs wait for an in-flight attempt, WeChat backstops deduplicate across
checkouts, due slots with no record are counted, and rollups retain actual
delivery timestamps and degradation reasons (#2237, #2314, #2483, #2487,
#2602, #2648, #2649, #2718). - Dashboard tabs and financial readouts are reliable on first use.
Inactive panels are inert; tab switching no longer waits on a failed load;
negative amounts keep their sign; return windows, exposure bases, sample
counts, source dates and holding sessions are labelled consistently
(#2511, #2513, #2555, #2581, #2582, #2583, #2600, #2611, #2697, #2719). clawock-dshreports unreadable balances and queues as unavailable,
expires trace caches, and re-renders changed FX provenance instead of
retaining stale labels (#2184, #2319, #2360, #2586, #2659, #2696).- Published Markdown rejects unsafe link targets and escapes model HTML;
public workflow records redact host paths (#2192, #2235, #2314, #2356). - Release npm verification tolerates registry propagation and compares
the served package with a fresh build in a separate readback job, allowing
the GitHub Release after both registries accept publication (#2156, #2319).
npm
clawock-dsh@0.3.1 published to npm.
clawock v0.3.0
Install from PyPI:
python -m pip install clawock==0.3.0A minor bump: a new public command, new intraday harness surfaces and a new
DSH plugin panel. Nothing was removed and no dependency changed. The DSH plugin
ships on the same version. Restart DeepSeek Harness after upgrading
clawock-dsh: the panel adds host methods, and the host half of a plugin
loads only at start, so a new client stays paired with the old host until then.
Added
clawock live-sources(#1935). Free live news and disclosures
(HKEXnews, EDGAR full-text search, Google News, Yahoo RSS, 同花顺 and 东财
7×24) for any harness. It is budgeted and timed, and each item is labelled
with its publication time.- Intraday harness: a core packet plus an addressable reference layer
(#1882).intraday preflight --judgment-packetprints only the
judgment-relevant fields; the rest is fetched on demand with
clawock tool intraday_reference. There is also an information lane with
timestamped items (#1885) and one web search per mover per session
(#1887). - Add-side reads (#1872, #1888, #1953). The brief and the intraday
card share one implementation. Evidence is graded, pullback candidates are
allowed, and discipline downgrades a read. Left-side scale-in runs in
observe mode: its rows carry no size (#2040). clawock-dsh: one provider panel (#2037). Claude and Codex quota
windows, the DeepSeek and MiniMax balances and the OpenCode free pool sit in
one sidebar cell. On a host that runs clawock's agent-dispatch, the panel
also shows the task queue, which can be steered from the chip (#1951).
Each row opens a detail layer (#1775, #2136), and every row shares one
grid with role-coloured status chips (#2129).clawock-dsh: localized client (#1660), withLICENSEand
SECURITY.mdshipped in the package (#1524).
Changed
clawock-dsh: the balance lives in the sidebar foot and opens as a
popover (#1529, #1533), instead of replacing the main column.- Every intraday slot sends a card (#1865). A slot with no change says
so in one line, rather than staying silent. - The README (the PyPI project page) was rebuilt around what a first-time
reader needs (#2150). It adds a two-line install at the top, a linked
logo wall of the supported harnesses, real OpenClaw and DSH captures, and a
plugin section.
Fixed
- The Finnhub key is sent as a header (#1845), so a provider error
message can no longer echo it into a published artifact. - Model prose is escaped in the published brief (#2111).
- HK quote timestamps are parsed for the staleness gate (#2117).
- Writes to the decision ledger can be read back by a strict parser
(#1739), and portfolio reconciliation is serialized against quote
writes (#1812). clawock-dshloads on hosts that ship React 18 (#1655). It also keeps
malformed share counts out of the traces wire (#1824), and state chips in
the sidebar are no longer clipped (#2138).
npm
clawock-dsh@0.3.0 published to npm.
clawock v0.2.0
Install from PyPI:
python -m pip install clawock==0.2.0A minor bump rather than 0.1.10: numpy and scipy became required
dependencies and the compute extra is gone. The DSH plugin ships on the same
version.
Changed
numpyandscipyare required (#1202).portfolio/risk.py, the
module behind the packagedportfolio-riskcommand, imported numpy at the top
level while numpy sat in an optional extra, so on a clean install that command
failed on its first line. scipy joins it for the covariance, allocation and
stress work that landed in the same change.- The empty
computeextra is removed;clawock[market]installs the
yfinancequote fallback (#1321, #1325). yfinance is the last hop of
the HK quote chain and the fifth of seven US providers. It was declared
nowhere, so an install that followed the metadata silently lost that hop. - The pre-open brief is rendered by the harness, not written by the model
(#1232, #1234). The model supplies the judgment (schema v3) and
clawock.harness.brief_renderproduces the report and the WeChat card;
clawock brief renderruns that step on its own, with--dry-runand
--date. - Report and intraday postflights accept only the prose form (#1279). The
legacy input, where the model handed back a whole report including its own
copy of the data block, is removed together with
validation.check_raw_tables_verbatim. - Run cards use schema 2 (#1203). Reproduction keys now cover registered
seeds, library versions and configuration contents; old keys no longer match
reruns.clawock run-card --diffand--verifyexplain changes and check the
recorded environment, with a separate digest for the resulting metrics. - Module workspace defaults no longer follow the process's current directory
(#1254). They resolve from the package tree;CLAWOCK_WORKSPACEstill
overrides that default for an external book. - The packaged automation LLM client uses MiniMax only (#1488). The
OpenCode fallback and itsfallback_*arguments are removed. Influence-feed
filtering failures retain only fresh, previously scored entries instead of
publishing unscored candidates. - Automation validates model output before publishing (#1267). Empty,
stub-length or incomplete reports are refused; structured influence-feed
scores are checked before use. - Delivered postflights with advisory warnings exit 0; failed products exit
2 (#1433). Report, intraday and brief now share this exit-code contract.
Added
clawock calendar <market> --status(#1429) printsOPEN/CLOSED
and always exits 0, for callers that read the output rather than the exit
code. The bare command still exits 1 on a closed session.- Covariance, allocation and stress modules for portfolio risk (#1162,
#1165, #1186). clawock signal-panelevaluates registered signals on the cross-section
(#1131, #1199, #1201, #1236). It reports rank IC, quantile returns,
turnover and persistence, fixed-horizon and triple-barrier outcomes, placebo
tests and leave-one-ticker-out checks.- Evaluation modules for selection uncertainty, drift and attribution
(#1128, #1197, #1204, #1205). These add purged CSCV/PBO, block
bootstrap intervals, deflated Sharpe, distribution-drift diagnostics, factor
attribution and a combined evaluation grade. clawock validate-regime-hmmandclawock evaluate-add-shapes
(#1208, #1341) compare probabilistic regimes and entry shapes against
baselines. They measure alternatives without changing live decision rules.- Daily-bar liquidity and volatility estimators (#1200) include spread
and illiquidity estimates, EWMA and GARCH volatility, with explicit missing
values when the data cannot support an estimate. - Scorecard provenance and net shadow returns (#1127, #1218).
clawock scorecard-provenance --check --recomputetraces metrics to ledger
rows. Shadow results retain the gross curve and add a net curve under stated
commission and spread assumptions. - Optional decision debate and magnitude forecasts (#1129, #1239).
Decisions can retain their supporting/opposing cases andexpected_move_pct;
coverage and forecast-magnitude errors are reported separately. - Decision-packet section queries accept
thesis,execution,history,
informationandstatus(#1374) as well as the original seven sections. clawock decision-map(#1206) joins decisions to the signal snapshots
available when they were made, with explicit payload-size degradation.clawock cron-trigger --job-name ...(#1443, #1498) queues an
OpenClaw job from a host scheduler after checking ownership and current job
state;--checkvalidates without triggering a run.clawock-dshshows Codex quota (#1480). Codex is a fourth balance
provider, read through the officialcodex app-serverrate-limit call, with
the 5-hour and weekly windows. Codex OAuth tokens are never read or
forwarded. A quota warning now names the window that crossed the line
(#1486).
Fixed
clawock-dshloads on DeepSeek Harness 0.1.2 (#1310). 0.1.2 retired
@deepseek-ai/dsh-client-runtime, which the plugin still required, and that
one stale module id took the whole dsh UI down with "Failed to load plugins".
The plugin now importsdefineStorefrom@deepseek-ai/dsh-client-store.- The published profile schema matches the loader (#1308). It no longer
requires the retiredtemplatesfield or acceptsworkflows.*.template. - Decision IDs and ledger writes preserve episode identity and concurrent
updates (#1433, #1483). Harness-owned IDs are normalized rather than
trusting model-supplied episode IDs, and read/modify/write operations hold a
cross-process ledger lock. - Artifact reads and interrupted writes preserve complete data
(#1499, #1500, #1506). Git artifact reads stay on one fetched commit;
canonical bars and fallback brief files use atomic writes. - Market-data failures remain distinguishable from valid data
(#1124, #1130, #1397, #1505). Degraded quotes retain quality labels,
HK peer discovery uses the working industry endpoint, benchmark fetch errors
are reported, and non-positive closes no longer crash regime calculations.
npm
clawock-dsh@0.2.0 published to npm.
clawock v0.1.9
Install from PyPI:
python -m pip install clawock==0.1.9Refresh release: same version train for the Python package and the DSH
plugin; the plugin's published tree is unchanged from 0.1.8 (the desk's
Decision Mind UI work landed in the data plane, not the npm package).
Changed
- Breakout is now a third evidence family for add authority ([#1086]). A
confirmed, un-overheated 20-day breakout counts as an independent family;
any two families authorise a capped exploration slice, while validated
tranches still require decision-usable evidence on both the price and the
information side. The README wording was aligned with the shipped behaviour. - Earnings quality requires at least four comparable periods on every
cadence ([#1097]), matching the documented contract (annual filers now need
four fiscal years). - The thesis registry is a pure kill-switch ([#1085]): an
intactthesis
sizes exactly like an undocumented one, and onlybroken/damaged/
weakeningstates reduce tranches. The emptymin(x, x)identity was
removed and a test pins the subtract-only semantics.
Added
add_alpha_walkforwardnow splits fills by price structure and volatility
regime ([#1107]) — measurement only, no behaviour change.
npm
clawock-dsh@0.1.9 published to npm.
clawock v0.1.8
Install from PyPI:
python -m pip install clawock==0.1.8The Python package's code is identical to 0.1.7. This version exists to ship the
plugin: clawock-dsh is the release.
Fixed
- The Decision Mind plugin rendered the same four copy/verdict
misrepresentations the dashboard card fixed in #742 — written by hand on that
side, so fixing one side never fixed the other ([#741]).execution.status
is the plan's self-report, not the fill's outcome, yet it headed the fill's
timeline node as 执行/未执行 —「未执行」on a completed buy read as a flat
contradiction. The 盈亏 label loaded two different quantities (this fill's
realized money and the whole position's floating percent) into one word. The
pairing was called 挂接决策, jargon that implied evidence the data did not
carry. The T+1 chip only showed a verdict foraction === 'sell', silently
dropping cut/trim/trim_on_rebound. Now the fill node is 真实成交 with the
plan-vs-fill relation stated as 与计划同向/反向 (alignment, host-computed;
live data is 22/40 reversals),execution.statussurvives only as a labelled
账本自评 chip, the P&L node splits into 本笔已实现 vs 该持仓当前浮动(非本笔),
pairing reads 有当日计划/无当日计划, every header stat shows the denominator
it is a fraction of (判出 X/Y 笔卖出, not a buy-and-sell-mixed total), and
unjudged fills say T+1 未判 instead of lying by omission. The browser bundle
keeps no second copy of the action set —sideis computed host-side — and
the alignment/action-set/breach-strip rules are now pinned against the
dashboard half intests/test_decision_trace_parity.py, which previously
claimed to pin them without doing so. ([#744])
npm
clawock-dsh@0.1.8 published to npm.
clawock v0.1.7
Install from PyPI:
python -m pip install clawock==0.1.7The Python package's code is identical to 0.1.6. This version exists to ship the
plugin: clawock-dsh is the release.
Fixed
clawock-dshon npm was a different build than its version number
claimed. npm'slatestwas 0.1.5 for a day, whose
tarball is the pre-#708 layout —client.jsat the root, no
lib/typert.*, no./typertor./remoteexport, nozoddependency —
sodsh plugin add clawock-dshinstalled a plugin that registers and then
shows no data. The two tag-triggered 0.1.6 publishes died inside
npm itself (Exit handler never called!): the plugin'spackage-lock.jsonhad been
regenerated on a machine behind a mirror registry, so all 169resolved
URLs pointed at a host the GitHub runner cannot reach and every fetch
stalled through npm's retry ladder. The lockfile is back on
registry.npmjs.org and the publish job pins the npm that does the publishing
and records which registry it used; with those in place a manual npm-only run
did land 0.1.6 on 2026-08-17 at 06:16Z, so the registry was already correct
before this version. What 0.1.7 adds is the part that makes that claim
checkable rather than assumed: because "publish exited 0" was never evidence,
publishing now downloads the registry copy back and asserts file-for-file,
export-for-export and dependency-for-dependency that it is what was packed.
(#732, #728)
Changed
- The DSH plugin follows the official Harness client rules instead of a
reverse-engineered shape. Styles ship as CSS Modules whose
<style data-plugin="clawock-dsh">tag the module loader owns and removes on
unload, so nothing touchesdocumentwhile the bundle is loading; the UI
store is acreateDecisionMindStore()factory called insideapplyrather
than a module-level singleton shared across plugin reloads; the trace cache
lives in the plugin instance and reaches the view through its props; the
scroll container comes from an element ref instead of a global selector; and
the browser bundle carries no businessany— it consumes the same wire
types the host declares. The generated Typert reflection is now emitted by
the official generator running in place over the real source tree (the
package moved toexamples/dsh/packages/clawock-dshbecause rc.6 discovers
packages only under a workspace root'spackages/), the build is
reproducible, and CI rebuildslib/on every plugin change and fails if the
committed artifacts differ. (#729, #730, #731) - Installing the plugin from a checkout goes through the official
installer.ops/host/install_dsh_plugin.shpacks the package and hands the
tarball todsh plugin --profile web add, which installs it the way a
registry package is installed and reconciles the profile's bundle rows
itself. It no longer hand-copies a source directory and hand-edits the
profile manifest — a directory spec is only linked, which is how a plugin
dependency went uninstalled and crash-looped dsh in the first place. The
tarball's file name carries a content hash, because pnpm keys afile:
tarball by path and would otherwise serve the previous build from its store
while every step reported success. (#731)
npm
clawock-dsh@0.1.7 published to npm.
clawock v0.1.5
Install from PyPI:
python -m pip install clawock==0.1.5Fixed
- The
clawock-dshDSH plugin's T+1 result color was inverted for sell
actions. It applied one sign rule to every action, so a rising price after
a sell (a loss for the seller — 卖飞) rendered green, and a falling price
after a buy rendered green too. The color is now action-aware: rising is
good (green) for a buyer, bad (red) for a seller, and vice versa. (#665)
Added
clawock record --source <harness>is now the single write path for the
decision-mind ledger (memory/decisions.jsonl); every harness (OpenClaw,
Claude, Codex, DSH, CLI) tags its own conversational judgments through it
instead of hand-writing JSONL, andvalidate_decisionaccepts the resulting
schema-version-0 records from any of them. (#661, #662)- The DSH plugin's Decision Studio tab is now a single "决策轨迹" (decision
trace) timeline built from real trade fills, not a separate, disconnected
ledger view: each row pairs an actual execution with its T+1 result chip and
expands into the plan → execution → outcome sequence. It renders only the
most recent activity by default, with a "show all" control for the rest.
(#676, #684)
npm
clawock-dsh@0.1.5 published to npm.
clawock v0.1.4
Install from PyPI:
python -m pip install clawock==0.1.4Fixed
- Harness-agnostic examples and the
clawock-dshskill now match the real
validator. The tutorial taught--artifact decision=..., a six-field
decision shape and a fixed.clawock/work/request.jsonpath; the validator
requires the artifact to be nameddecision.json, nine top-level fields
(schema_version / workflow / decision_id / as_of / subject / evidence /
debate / thesis / decision) and the<run_id>-scoped request file
prepareactually writes. The examples were rewritten against the pack's
decision.example.jsonand the whole prepare → decision.json → publish
loop is verified end-to-end. (clawock-dshnpm package bumped to 0.1.4.) - No more double-writer races on a missing brief. The 09:05 watchdog no
longer queues a local re-run and the off-host fallback at the same time —
two LLMs writing the same artifacts produced duplicate WeChat/Telegram
pushes. The re-run is now evidence-gated (a run that ended OK today does not
stack another queue entry). - Report delivery gaps are now named. When a postflight sender dies
mid-send (claim present, no completion marker), the watchdog says "WeChat
delivery unconfirmed" out loud instead of silently only mirroring Telegram. - User risk overrides settle the ledger. An overridden risk_rule cut is
settled (execution.status=overridden_by_user) instead of accumulating as
unknownforever and flooding the open queue when the override TTL expires. - The 30-bar data-quality gate is restored. The short-history fallback now
requires a registrylisting_datewithin 45 days, so a mature name with a
partial feed can no longer enter the universe with half a signal set.
Changed
- The AI watch list (智谱 / 迅策) now rides the brief's
marketbundle — the
model boundary can actually read it — and its thresholds
(opportunity_near_pct,early_no_chase_zscore) moved into
add-alpha-policy.jsonas a single source shared with the intraday radar. - Intraday slots fetch each code once per slot instead of three times
(~540 → ~180 requests/day). - Intraday push gating: opportunity/early-trend sub-state flips around a price
threshold no longer retrigger a full push every slot.
npm
clawock-dsh@0.1.4 published to npm.
clawock v0.1.3
Install from PyPI:
python -m pip install clawock==0.1.3Added
- Harness-agnostic decision contract. The workflow is files + CLI, so the
same decision run works from a pure CLI, an OpenClaw skill, a Claude Code
instruction, a CodexAGENTS.md, or a DeepSeek Harness agent — see
examples/harness-agnostic/(each runnable, executed byrelease.yml). clawock-dshskill package on npm. DSH users install one command:
dsh plugin --profile web add clawock-dsh. A puredsh.skillspackage (no
Node code) that walks the agent through prepare →decision.json→ publish.- README rewritten around the live record. First-line hook (90 days live,
−15.95%, every loss on the page), four-line scorecard reconciliation
(ledger / directional hit / shadow portfolio / real account), reproducible
auditing (clawock audit-resettle), and the influencer radar (Trump /
Musk) now documented in both languages. Live numbers are maintained by
ops/growth/refresh_readme_metrics.pyplaceholders, refreshed weekly by CI. ops/publish/publish_dsh_plugin.sh— single entry point for publishing the
npm side of a release, shared byrelease.ymland manual bumps.
Changed
- README.zh.md and README.md now share a locked 12-section structure (CI
parity tests); the information-layer tables are checked against
config/information-layers.jsonand the per-run block counts against the
preflights themselves.
npm
clawock-dsh@0.1.3 published to npm.
clawock v0.1.2
Install from PyPI:
python -m pip install clawock==0.1.2Mostly documentation and repository policy. It is a release because README.md
is shipped verbatim as the PyPI long_description, and a published page cannot
be re-rendered — the same reason 0.1.1 existed.
Fixed
- The numeric provenance advisory now recognises
%,pp,x/×andσ, and
matches context per unit rather than against one flat set of numbers, so a
figure like2.3xis no longer waved through by a match on an unrelated
quantity. The intraday insights sidecar is normalised before publication:
model-owned narrative is kept, thegenerated_atstamp is the harness's own
UTC clock, and a missing or malformed sidecar stays warn-only so report
delivery is not held hostage to it. (#485) - The README's widest claim about the system — "26 fetch and compute modules
across 8 layers" — had no artifact behind it and had survived #429, which
moved every module it counted. The catalog is now
config/information-layers.json: every packaged command sits in exactly one
layer or on an exclusion list with the reason it is not information
collection, and the tables in both READMEs are checked against it. The
partition covers both distributions' command registries, so nothing counted
can be typed by hand. Re-derived, the count is 39, and two layer names that no
longer described their members were corrected. (#476)
Added
SECURITY.mdnaming GitHub private vulnerability reporting — now enabled on
the repository, so the channel it points at exists — a
CONTRIBUTING.mdstating which parts of the repository can accept a patch
(the package can; the live book cannot), and a bug-report issue template.
Installable packages need a disclosure channel; a repository someone only
reads does not. (#477)- The runtime-coupling ratchet now also enumerates shell entry points naming the
live host, against a per-file allowlist with a reason each. Its Python count
stays 0, and the claim now states what it covers. (#478)