Share the boundary selector's package policy: directly changed plugins,
Telegram/Codex/Slack smoke for shared sources, and direct consumers of changed
public SDK entries, including test imports. Defer transitive and ambient
consumer fan-out to hourly main and release validation. Keep full lint for
lint/type policy and directly changed loose extension sources so their own
canonical lint coverage remains intact. Log selected roots and reasons in
addition to the existing job summary.
Twenty complete recent PR path scenarios reduce the median selection from
164 to 3 packages and aggregate selections from 2461 to 237; full cases fall
from 15 to 1. The one confirmed own-diff historical lint failure retains all
three failing roots, with no observed miss. This is limited historical proof.
The existing OPENCLAW_CI_EXTENSION_LINT_FULL=true or 1 switch restores full PR
coverage; unset keeps the aggressive default. No variable or setting changed.
Full SDK preparation and typed lint programs remain. A scoped-preparation
experiment did not improve the measured cold smoke stripes, so it is not part
of this change. Existing preparation plus selected lint takes 133-144 seconds
on a four-CPU, 16-GiB Linux Testbox; adding observed median setup models about
3m12s per cold job, not the two-minute target or measured Actions wall.
Proof: whole tooling across 927 files, full test types, changed-file and
boundary lint, architecture, source-contract checks, real preflight in both
checkout shapes, and P2 review. Three unrelated upgrade-survivor fixture
failures reproduce on the unmodified parent. The peer's declaration-fixture
repair is preserved and passes the final owner replay. Selector tests cost
3.26 seconds in the local single-file diagnostic and also passed on Linux.
Select changed extension packages and consumers of changed public source through the existing import graph, including type-only imports. Keep the complete typed programs, native lint chunks, resource limits, artifact preparation, and non-extension checks.
Retain full extension lint for scheduled/hourly main and release validation, shared lint/type policy, uncertain prior source types, and the OPENCLAW_CI_EXTENSION_LINT_FULL repository switch. Read the pinned diff base so removing a global augmentation cannot hide its consumers. Publish selected package reasons in the check-plan summary.
Twenty recent PR path scenarios emit 54 -> 40 hosted extension-lint rows (25.9% fewer): four 3 -> 0, one 3 -> 1, two already 0 -> 0, and thirteen unchanged. On Linux with four CPUs and a 16 GiB limit, warm maximum full-stripe compute was 64.44 s and the qa-lab-only stripe was 14.58 s. Shared artifact preparation took 114.24 s separately; these are not end-to-end Actions job timings. Full typed programs are unchanged. Shared loose extension consumers still retain full coverage.
The bounded historical search found one source-attributed extension-lint failure among 42 inspected runs; all three failing packages remain covered. Ten causal runs were unavailable, so this is limited historical evidence.
Proof on Linux Testboxes: whole tooling plus both owning fast configs; full core/extension/root test types; final check-changed, typed lint, boundary guards, architecture, source contracts and dead exports; eight same/different-SHA native preflight cells; native before/after manifests for twenty PR scenarios; final helper parity for all twenty plus two probes; and P2 review. Initial new-fixture errors were corrected and replayed. The sole inherited suppression-inventory failure reproduces on the unmodified parent and passes with already-landed d346309979. No workflow dispatches or CI reruns. New helper tests cost 5.25 s locally, with their Linux replay included in the focused proof.
Retain complete core graph validation in the existing required parallel boundary row for canonical extension-only changes. Discover all four noncore compiler consumers while preserving full fallback for aliases, missing inputs, mixed changes and incomplete inventories.
Keep the same bounded chunks, rules, and serial compiler processes while removing three repeated checkouts, dependency setups, and SDK preparations. Targeted and frozen layouts retain their existing ownership.
* ci: select PR checks from affected inputs
Resolve compiler consumers and complete touched lint packages after dependency
setup, then feed the existing execution rows. Scope guard and contract families
to their inputs, retain source proof when dist is unnecessary, and keep main,
manual validation, and broad fallbacks unchanged.
Reuse admitted import graphs for repeated consumer queries. Keep four complete
checkout integration scenarios in the release tier while retaining direct-test
admission and a fast first-signin representative in the ordinary selector suite.
* ci: await check planning before sealing release evidence
The new check-plan workload was missing from the release child receipt's
complete dependency set. The existing evidence guard detected the omission
in run 36075684694, job 107898033461.
Include check-plan in seal_release_child_evidence.needs so the receipt
retains its contract of waiting for every workload job before sealing.
* ci: publish exact check-plan workload counts
Preflight retains lint and compiler templates that the dependency-aware
check planner can later shrink. A concurrent failure observer needs the
final admitted cardinality to recognize healthy completion.
Count those four check families at their planner owner and publish the
bounded count in a final successful step name. The existing Jobs API can
carry that fact without delaying observation behind the planner or adding
permissions, jobs, or artifacts.