Commit graph

9 commits

Author SHA1 Message Date
Peter Steinberger
14cc3a4da8
chore(release): retire the internal Tideclaw alpha release track (#160261)
* chore(release): retire the Tideclaw alpha release track

Tideclaw alpha/nightly publication is retired. Alpha remains readable as
history (existing v*-alpha tags, published versions, changelog and
upgrade-survivor baselines, product version ordering), but it can no longer
authorize a release.

Every active release boundary now rejects an alpha version or -alpha.N tag,
the alpha npm dist-tag, and tideclaw/alpha/* workflow or tooling routes:
preparation, Full Release Validation publication selection, npm preflight,
approval receipts, core/plugin npm and ClawHub publication, native handoffs,
and finalization. Channel mappings throw for alpha instead of falling through
to latest. The Tideclaw branch routes, alpha dist-tag options, the alpha FRV
publication route, and the alpha-only Docker runtime-assets job are removed.
Beta, stable, extended-stable, and correction releases are unchanged.

The release-openclaw-nightly skill is deleted and the release skills and docs
no longer describe the alpha track.

* test(release): drop retired alpha preparation and finalization expectations

* test(release): drop remaining retired alpha references
2026-09-28 10:01:49 -07:00
Dallin Romney
348bd81b55
docs: keep release policy public and maintainer procedures in skills (#156946)
* docs: make the release guide readable and correct closeout policy

* docs: address release guide review feedback

* test: decouple release workflow checks from public guide prose

* docs: finish release procedure link migration

* docs: repair release procedure destinations and preserve packager steps

* docs: preserve release recovery procedures and legacy destinations
2026-09-26 00:18:17 +00:00
Dallin Romney
7e8732d9d7
fix: restore blocking release validation and remove publication waivers (#157864)
* fix: restore blocking release validation and remove publication waivers

* fix(release): align recovery proof with strict validation

* docs(release): preserve qualified beta promotion

* fix(release): require strict stable orchestration and retire waived replay

* fix: read waiver-free saved release state after retry removal

* fix: discard retired capability metadata from strict release state
2026-09-25 16:27:23 -07:00
Peter Steinberger
364f1ddf3b
feat(release): mint the protected tooling tag from a trusted main SHA (#157896)
* feat(release): mint the protected tooling tag from a trusted main SHA

Let release:publish-preflight and release:candidate accept --workflow-sha
<main-ancestor>. The helper proves main ancestry, reuses the newest
lightweight release-publish/<sha12>-<epoch> tag at that SHA or creates one
through the git refs API, verifies the ref, and prints the dispatch with
--ref <tag>. The candidate helper pins its trusted tooling checkout to the
same SHA and refuses a checkout mismatch before minting.

* fix(release): keep the recorded tooling tag when a candidate resumes by SHA

A newer release-publish tag at the same tooling SHA must not fail state
reconciliation: a resumed candidate reuses the exact tag it saved (still
verified against the tooling SHA) instead of the newest tag at that SHA.
2026-09-25 02:48:41 -07:00
Peter Steinberger
ebdab59f91
feat(release): redesign release validation and publication for faster stable releases (#156812)
* test(release): guard parallel validation dispatch

* feat(release): seal independent child workload evidence

Record immutable, attempt-aware child receipts independently of parent completion. Keep receipt collection advisory and preserve publisher-only retry evidence. Partial child-reuse discovery and consumption remain a follow-up.

* feat(release): reuse sealed child evidence independently

* fix(ci): plan frozen release shards with trusted tooling

* ci(release): generate hosted shard timing budgets

* fix(release): make non-proof validation lanes advisory

* feat(release): seal resolved publication inputs

* fix(release): accept candidate tags at the frozen target

* docs(release): record pending first-hop parallel lanes

Item 8: remote main d51f3607b9 does not contain bf7848ef23. The feat/first-hop-compat-parallel-lanes branch still owns that implementation. Verified remote refs read-only and inspected the main scenario source; do not duplicate it here. No source changes; prior item gates remain valid.

* ci(plugins): run release plugin coverage on relevant pull requests

* ci(release): support reserved validation runner groups

* docs(release): reconcile fast-path validation guidance

* test(release): reconcile final guards and record validation

* fix(release): retry transient GitHub API failures during evidence verification

* test(release): reconcile advisory Linux CI lane cases with the fast-path policy

* test(release): copy the sealed-evidence tooling closure into the frozen fixtures

* fix(release): keep package integrity blocking and require live operator authority for sealed SDK and soak inputs

* chore(release): record the landing follow-ups in the PR body

* test(ci): expect the four-hour Testbox lease default from #156614

* test(release): reconcile untouched release suites with the advisory policy and reserved runner groups

* fix(release): reconcile advisory-by-default with full coverage and strict stable defaults

Keep RomneyDa's coverage (nine cross-OS Gateway pairs, Linux Gateway lanes as
required proof, Windows/macOS recorded as advisory) and his strict stable
publication gates (stable-profile, soak, blocking performance) as the default,
while retaining Peter's operator fast path: stable_soak_waiver / lane_waiver
are the only way to publish a stable without soak/performance evidence or with
failed non-proof lanes, must name the target version, apply only while the
repository variable still holds them, and are recorded end to end. The stable
closeout accepts the same waivers so the 2026.9.6 closeout replay can proceed.
Adopt main's affected-consumer planner (#156729) with item 4's hosted-row
split re-applied.

* fix(release): revalidate sealed soak waivers at the plugin npm publish boundary

The stable bootstrap approval records whether its soak waiver was explicit or
sealed; the plugin npm child rereads the repository variable before its
token-backed publish and rejects a sealed waiver the variable no longer holds.
Read-only preflight reports sealed waivers with the same rule. Docs state the
nine-pair all-group cross-OS rule and the strict performance gate; the tracked
planner backup is removed and the fast-core worker keeps its runner-group
routing.

* fix(release): recheck sealed waivers before npm I/O and repair CI-surfaced drift

Assert a still-held sealed soak waiver immediately before the plugin
token-backed npm publish, carry the live variable into preflight's gate
evaluation, and state the strict performance gate in the fast-path guide.
Fold main-side drift the merge surfaced: the seal job waits for the new
baseline-ratchets worker, the wrapper closure lists the CLI root options chain,
the maturity publisher's runner-group route is evaluated rather than compared
literally, and two main-authored session test-support suppressions join the
allowlist.

* fix(release): fetch waiver authority live before the plugin npm publish

Read OPENCLAW_RELEASE_STABLE_SOAK_WAIVER from the repository immediately
before the token-backed npm publish (404 means revoked, other read errors
refuse to publish), keep a waiver-less recorded closeout manifest byte-identical
on replay, and describe release_profile=stable as the stable default with the
beta profile plus stable_soak_waiver as the explicit operator fast path.

* test(release): anchor the publish-boundary recheck to the npm publish command

* fix(release): fall back to the job-start waiver when the token cannot read Variables

Keep the live read before npm publish (404 means revoked) but warn and use
the job-start snapshot instead of refusing every bootstrap publish when the
job token lacks Variables access.

* fix(release): refuse the plugin npm publish when waiver authority cannot be read

Revoked (404) and unreadable variable states both stop the token-backed
publish; a job token without Variables read access fails loudly instead of
publishing on a job-start snapshot.
2026-09-24 05:15:18 -07:00
Dallin Romney
dbedb423e6
fix: require full stable validation before publication (#156934) 2026-09-23 19:39:02 -07:00
Dallin Romney
86f5656a2a
fix(release): require Gateway and Telegram validation (#156811)
* fix(release): ignore waivers for other release trains

* test(auto-reply): await active admission boundary

* fix(release): restore blocking validation without lane waivers

* fix(release): require Gateway install and upgrade checks on every OS

* test(ci): align Testbox timeout with its existing lease

* fix(ci): include readonly reuse in PR wrapper closure

* fix(release): restore blocking Telegram validation

* refactor(release): remove legacy waiver transition handling

* test(release): expect Telegram QA to block release checks
2026-09-23 19:04:50 -07:00
Peter Steinberger
0c38cb4867
feat(release): operator lane waiver keeps non-proof lane failures advisory (#156585)
* feat(release): operator lane waiver keeps non-proof lane failures advisory

* test(release): cover lane waiver gates and advisory evidence; document the waiver

* feat(release): carry the FRV lane waiver on a version-bound repository variable

* fix(release): keep Linux cross-OS and verifier failures blocking without a waiver

* test(release): align lane waiver advisory evidence expectations

* fix(release): build advisory job entries without map spread

* fix(release): type the advisory job entry for the test root

* fix(gateway): supply policyConfig in the placement lifecycle read view
2026-09-23 09:16:37 -07:00
Peter Steinberger
dcb4847e48
feat(release): check publication gates before dispatch (#152470)
* feat(release): check publication gates before dispatch

* fix(release): accept empty draft bodies in publish preflight

* fix(release): wire publish preflight command and shared gate proof

* fix(release): discover draft state and await committed archive proof

* fix(ci): preserve release metadata types and catalog test lifetime

* fix(release): reuse resume authority and settle UI test phases

* style(release): satisfy typed metadata and UI fixture lint
2026-09-19 01:41:43 -07:00