OpenClaw 2026.5.27
ช่องทาง: Stable เผยแพร่บน GitHub: 28 พฤษภาคม 2569 เวลา 18:41 อ่าน Release Notes ต้นฉบับ: GitHub Releases
OpenClaw 2026.5.27 เป็น release ที่เน้น Codex และเส้นทาง OpenAI, ระบบปลั๊กอิน, เสถียรภาพของ Gateway มากเป็นพิเศษ และถ้าดูจากรายการเปลี่ยนแปลงจริงจะเห็นว่ารอบนี้ทีมไม่ได้แค่เติมฟีเจอร์ใหม่แบบกระจาย แต่พยายามลด friction ในจุดที่คนใช้งานจริงมักเจอ ทั้งตอนตั้งค่า, รัน agent ต่อเนื่อง, เชื่อม plugin, และดูแลระบบผ่านแชนเนลต่าง ๆ ซึ่งเป็นเรื่องที่มีผลกับผู้ใช้ไทยโดยตรง เพราะหลายทีมที่ใช้ OpenClaw ในไทยมักใช้งานแบบผสมหลายเครื่องมือและต้องอาศัยความนิ่งของ workflow มากกว่าการโชว์ capability อย่างเดียว
อีกจุดที่น่าสนใจคือ release นี้สะท้อนทิศทางของ OpenClaw ว่ากำลังขยับไปเป็นแพลตฟอร์ม automation ที่ดูแลง่ายขึ้นเรื่อย ๆ ไม่ว่าจะเป็นเรื่อง runtime, channel, plugin, หรือ tooling สำหรับ recovery เมื่อมีอาการแปลกใน production พอเอามาแปลเป็นภาษาคนใช้งานจริง ความหมายก็คือทีมจะเสียเวลาน้อยลงกับงานแก้ระบบ และมีเวลาไปโฟกัสกับ use case ที่สร้างคุณค่าให้ธุรกิจหรือชุมชนมากกว่าเดิม
สิ่งที่เปลี่ยนแปลงหลัก
Highlights - Stronger security and content boundaries: group prompt text is kept out of the system prompt, repeated-dot hostnames are normalized, side-effecting command wrappers and unsafe Node runtime env overrides are blocked, no-auth Tailscale exposure is rejected, and node/device-role approvals now require admin authority. ( 87144, 87305, 87292, 87308, 87146) Thanks @eleqtrizit and @pgondhi987. แม้จะไม่ใช่ฟีเจอร์โชว์หน้า UI แต่สำคัญมากกับ production เพราะช่วยลดช่องว่างเรื่องสิทธิ์, trust boundary, และการตั้งค่าที่ทำให้ระบบเผลอเปิดกว้างเกินไป
Highlights - More reliable Codex app-server runs: Codex runtime models resolve first, workspace memory is routed through tools, shared app-server clients survive startup and spawned-helper failures, native hook relay generations survive restarts and rotate on fresh fallbacks, and false runtime live switches are avoided. ( 87383, 87403, 87375, 72574, 87428) Thanks @yetval. จุดนี้สำคัญกับทีมที่ใช้ GPT-5.x หรือ Codex OAuth เพราะลดความเสี่ยงที่ routing ผิดเส้นทางแล้วทำให้ agent ไปใช้ auth mode คนละแบบโดยไม่ตั้งใจ
Highlights - Faster Gateway and reply paths: session reads, plugin metadata fingerprints, auth env snapshots, auto-enabled plugin config, tool-search catalogs, and stable metadata caches do less hot-path rediscovery while visible replies no longer inherit hidden cleanup timeouts. ( 86439, 87044) Thanks @keshavbotagent. สำหรับทีมที่ต่อ plugin หลายตัว การแก้ส่วนนี้ช่วยลดปัญหาติดตั้งไม่ครบ, metadata เพี้ยน หรือ runtime ล้มหลังอัปเดต ซึ่งเป็น pain point ที่เจอบ่อยในงานจริง
Highlights - Better provider and model coverage: OpenAI-compatible embedding providers are core, DeepInfra catalog browsing loads the full credential-aware model set, Pixverse adds video generation and API region selection, VLLM thinking params are wired, Claude CLI OAuth overlays load for PI auth profiles, and bare direct Anthropic model ids work. ( 85269, 84549, 87167) Thanks @dutifulbob, @ats3v, and @joshavant. จุดนี้สำคัญกับทีมที่ใช้ GPT-5.x หรือ Codex OAuth เพราะลดความเสี่ยงที่ routing ผิดเส้นทางแล้วทำให้ agent ไปใช้ auth mode คนละแบบโดยไม่ตั้งใจ
Highlights - Channel delivery is steadier: Telegram sendMessage actions use durable outbound delivery, iMessage suppresses duplicate native exec approval prompts and sends, Slack keeps delivered final replies during late cleanup, Matrix mention previews/finals are stricter, QQBot fallback approval buttons honor slash-command auth, Discord guild requester checks are tighter, recovered Discord tool-warning artifacts stay out of successful replies, and Google Chat stops thread sends in DMs. ( 87261, 87154) Thanks @mbelinky and @eleqtrizit. ใครที่ใช้ OpenClaw เป็น multi-channel bot จะรู้สึกได้ง่ายที่สุด เพราะการแก้เลเยอร์ส่งข้อความช่วยลดเคสตอบซ้ำ, routing หลุด, หรือ approval ค้าง
Highlights - Release, package, and CI proof paths are harder to wedge: npm/package inventory honors dist exclusions, shrinkwrap override pins merge correctly, Docker runtime workspace templates are packaged and smoked, release postpublish checks are stricter, beta smoke rejects empty runs, and E2E log/probe waits are bounded. สำหรับผู้ใช้ทั่วไป นี่คือการเก็บรายละเอียดที่ทำให้ release นี้พร้อมใช้งานใน production มากขึ้น ไม่ได้มีดีแค่รายการเปลี่ยนแปลงบนกระดาษ
Bug Fixes ที่น่าสนใจ
- Security/content boundaries: route untrusted group prompt metadata outside system prompts, normalize repeated trailing hostname dots, block side-effecting command wrappers, reject unsafe Node runtime env overrides, reject no-auth Tailscale exposure, block untrusted Microsoft Teams service URLs, enforce /allowlist configWrites origin policy, gate QQBot fallback approval buttons, and require admin for node/device-role approvals. ( 87144, 87305, 87292, 87308, 87146, 87154, 87334) Thanks @eleqtrizit and @pgondhi987.
- Codex: resolve Codex runtime models before generic routing, route workspace memory through tools, preserve shared app-server clients after startup and spawned-helper failures, preserve native hook relay generations across restarts and fresh fallbacks, keep raw reasoning/source-reply guards intact, report quarantined dynamic tools, keep the attempt watchdog armed for queued terminal turns, and route Codex OAuth compaction through OpenAI-Codex. ( 87383, 87403, 87375, 72574, 87428) Thanks @yetval.
- Agents/runtime: avoid session event queue self-waits, bound compaction wake and steering retries, preserve grace for pending error diagnostics, avoid false Codex runtime live switches, avoid stale restart continuation reuse, preserve session fallback errors, suppress duplicate Claude CLI skill prompts, keep runtime context before active user turns, strip stale Anthropic thinking, quarantine unsupported tool schemas, recover completed write timeouts safely, release retained session write locks on timeout abort, and validate forced plugin harness support before pinning. ( 86123, 55424, 86855, 74341, 87278) Thanks @luoyanglang, @cathrynlavery, and @openperf.
- Reply/session delivery: keep visible turn admission unbounded, keep visible fallback delivery on latest targets, preserve bridge hook context, classify direct fallback targets by channel grammar, report approval resolutions in bridge mode, and avoid stale source-reply artifacts. ( 87044) Thanks @keshavbotagent.
- Channels: make Telegram sendMessage action replies durable and preserve SecretRef prompt config, suppress duplicate iMessage native exec approval prompts and sends, keep iMessage approval polling alive after denied reactions, keep Slack delivered final replies during late cleanup, keep Matrix mention previews/finals mention-inert and normally delivered, ignore filename-embedded Matrix IDs, suppress recovered Discord tool-warning artifacts from successful replies, suppress Google Chat thread sends in DMs, and harden Discord guild requester checks. ( 87261, 87452) Thanks @mbelinky.
- Memory: salvage QMD search JSON after nonzero exits and keep workspace memory routing through the Codex tool path where possible. ( 87225, 87383, 87403) Thanks @osolmaz.
- Providers/models: forward cached token usage in OpenAI-compatible chat completions, load Claude CLI OAuth overlays for PI auth profiles, send bare direct Anthropic model ids, wire configured VLLM thinking params, honor OpenAI-compatible cache retention, normalize OpenAI Responses replay tool ids, resolve OpenAI gpt-5.5 without a cached catalog, preserve retry-after fallback handling, bound GitHub Copilot auth requests, and load DeepInfra custom/live catalogs consistently. ( 82062, 87167, 84549) Thanks @caz0075, @joshavant, and @ats3v.
- Gateway/performance: borrow read-only session metadata and active session working stores, cache current/stable plugin metadata fingerprints, cache auto-enabled plugin config, slim metadata identity caches, trust current metadata lifecycle caches, stabilize isolated cron prompt-cache affinity, persist model auth profile suffixes, drain probe client closes, expire browser tokens after auth rotation, and keep default status fast paths bounded. Thanks @ferminquant.
ผลกระทบต่อผู้ใช้ไทย
สำหรับผู้ใช้ไทย release stable อย่าง 2026.5.27 มีความหมายมากกว่าแค่ "อัปเดตแล้วได้ของใหม่" เพราะมันช่วยให้ Codex และเส้นทาง OpenAI และ ระบบปลั๊กอิน และ เสถียรภาพของ Gateway อยู่ในจุดที่เชื่อถือได้ขึ้น เวลาเอา OpenClaw ไปใช้กับงาน support, internal ops, automation เชื่อมหลายบริการ หรือ workflow ที่ต้องรักษาความต่อเนื่องทั้งวัน ทีมจะเสียเวลาตามอาการแปลก ๆ น้อยลง และกล้าขยายการใช้งานจริงมากขึ้น
ในเชิงปฏิบัติ จุดที่ควรสังเกตหลังอัปเดตคือ workflow ที่ทีมใช้งานทุกวัน เช่น การคุยผ่านแชนเนลหลัก, plugin ที่เรียกบ่อย, การเช็กสถานะผ่าน control UI หรือคำสั่ง CLI, และเส้นทาง auth/provider ที่เป็นหัวใจของ agent ถ้าระบบของคุณเคยเจออาการหลุดบ้างเป็นครั้งคราว release ประเภทนี้มักช่วยลบ "ปัญหาเล็กแต่บั่นทอน" ได้ดีมาก และผลลัพธ์จะออกมาเป็นความรู้สึกว่าระบบนิ่งขึ้นทั้งก้อน แม้ใน release notes จะไม่ได้เรียกมันว่า feature ใหญ่ก็ตาม
คำแนะนำในการอัปเกรด
ถ้าระบบของคุณเจอ pain point ใกล้กับหัวข้อใน release notes ชุดนี้ ควรอัปเกรดค่อนข้างเร็ว เพราะหลายรายการเป็น fix เชิง reliability มากกว่าฟีเจอร์โชว์หน้า UI แต่ถ้า production ของคุณมี plugin หรือ channel ที่ custom หนัก ควรทดสอบ workflow หลักสักหนึ่งรอบหลังอัปเดต เพื่อยืนยันว่า behavior หลัง fix เป็นไปตามที่คาด
หลังอัปเดต แนะนำให้ลอง smoke test อย่างน้อยหนึ่งรอบกับงานสำคัญ เช่น เปิด session ใหม่, ส่งข้อความผ่าน channel ที่ใช้ประจำ, เรียก plugin หลัก, และดู log หรือ status สั้น ๆ เพื่อยืนยันว่า behavior หลังอัปเดตตรงกับสิ่งที่ release นี้ตั้งใจแก้
วิธีติดตั้ง
~~~bash npm install -g openclaw@2026.5.27 ~~~
