* fix(bun): preserve Node worker dependencies and spawn diagnostics
* fix(models): preserve nested catalog cleanup diagnostics
* test(gateway): own pending embeddings provider cleanup
* test(bench): retain subprocess failure diagnostics
Include status, signal, stdout, and stderr when the history benchmark subprocess fails. Keep both profiles, every assertion, and the existing 30-second child and 35-second test deadlines unchanged. This exposes the failing phase without claiming to fix the timeout.
* chore: reconcile Bun compatibility with current main
Preserve the independently reviewed c134c8d7 tree while adopting the canonical embeddings cleanup and history benchmark repairs from main. Retain the existing PR ancestry for GitHub head synchronization.
* fix(runtime): preserve Bun diagnostics after owner extraction
Resolve the mainline diagnostics extraction by keeping spawn-diagnostics.ts as the sole owner and retaining the Bun family classification and existing regression assertions. The other compatibility changes are unchanged. Independent P0-P2 review and targeted formatting passed; refreshed hosted CI is required before landing.
* chore: adopt canonical PR wrapper inventory repair
Merge main including 3a4bbc6882, which restores the SQLite reader context and spawn diagnostics to the extracted PR wrapper source inventory. The eight-file Bun compatibility patch retains identical stable patch ID 43645b39aa8a317656d1047afccfa79137314e66 and its existing reviews. Refresh hosted CI before landing.
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* feat(browser): unify local Chrome setup across desktop and terminal
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* feat(browser): unify local Chrome setup across desktop and terminal
OpenClaw-Publication: d19e865e-b5a0-4c70-8876-c1662f6e7ef2
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* chore(linux): format Chrome setup fixture
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* feat(browser): keep desktop Chrome setup local and preserve pairing
Delegate Windows registration to the shared native management owner, preserve
released native bridge compatibility and saved launcher profiles, and integrate
serialized desktop setup through isolated local runtimes.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): repair native setup CI contracts
Keep Windows installer dependencies acyclic, validate Unicode within the
package library target, and remove unused private exports. Require all
eight packaged native-host proof cases and update lazy CLI inventory.
Apply native Swift formatter diagnostics without changing behavior.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(cli): account for plugin-owned browser extension catalog
Keep the core-only registration invariant aligned with the Browser plugin
owner already exercised by its lazy registration tests.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(macos): retain released Chrome bridge request expectation
Align the native bridge test with the shipped contract1 request retained
by the canonical setup owner, and reject extra legacy payload fields.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(tui): give command handler harness a unique export
Rename the shared TUI test helper and both consumers to avoid the
Gateway placement harness export collision. No alias or guard waiver.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* chore(sdk): allow canonical browser config path resolver
Apply the approved single public-export and callable allowance for
resolveConfigPath. Preserve canonical pre-config path ownership and
all other SDK surface checks.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): preserve desktop setup selection and supported actions
Keep native automatic setup selector-free and resolve saved local browser
selection through the canonical setup owner before installation. Respect
Mac action advertisements and the released legacy install projection in
the Apps card, and document the public config-path resolver contract.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(auth): retry model selection after concurrent credential refresh
Adopt upstream PR #152426, commit 32298b10f6, without changing its five source files.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test: preserve native setup selection and await dashboard document
Match the selector-free native CLI arguments exactly and preserve a saved work-profile result. Wait through the existing document-readiness owner only at the quota test browser-proof boundary, after auth assertions.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): avoid preloading already imported modules
Remove exact direct static JavaScript imports from lazy preload tables using the emitted build graph. Preserve HTML, lazy-only JavaScript, CSS, and locale hints. Source-exact CI merge reproduction drops startup gzip from 363283 to 362968 bytes without changing budgets. Add a real emitted-bundle regression.
Apply rustfmt layout to the native Chrome selector-free expected arguments.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix: preserve Chrome profiles and attachment follow-up branch binding
Let the TUI canonical setup controller retain its saved browser profile and project only a bounded returned name. Align both native first-run fixture expectations with selector-free setup.
Join pending chat history before the composer task handoff can expose an admitted attachment to restored-outbox delivery. Preserve idempotency, attachment custody, restored delivery semantics, and all existing assertions and timeouts. Add a deterministic regression reproduced on the exact failed CI merge and its main parent.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(state): adopt canonical worker-custody fixture repair
Adopt src/plugin-state/plugin-state-worker.test.ts byte-for-byte from upstream bfec65a2a0 (#152456).
The former fixture held its late competing owner until after awaiting off-thread acquisition. Preserve that overlap, assert continued host authority checks and noncompletion, release custody, then assert the original result and persisted state. No production locking, guard, deadline or outcome assertion is relaxed.
Both prior failures reproduced on the exact CI main parent with independently installed frozen dependencies and Node 24.19.0. All 12 repaired file tests, selected state-logging types, scoped typed lint and fresh P0-P2 review passed.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): retain saved Windows setup profiles
Recover configured extension profiles through bounded serial read-only C# inspection. Select only independently validated current matching descriptors, confirm the selected generation before effects, and leave the single mutation under the existing C# owner. Preserve POSIX behavior, existing manual relay verification and explicit same-profile repair.
Missing descriptors, runtime/origin drift and unknown or changing observations fail closed without automatic mutation. Keep raw management facts private and populate the existing browserProfile field only from validated binding metadata. No ABI, schema, SDK, configuration flag or registry/activation owner change.
29 actual CLI/controller/Windows-adapter boundary cases plus sibling coverage: 94 tests pass. Canonical changed checks, full production build and fresh independent P0-P2 review passed. Actual C# native proof remains separately coordinated.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): preserve saved profiles after POSIX bundle relocation
Separate validated native registration ownership from supported origin-migration readiness. Recover the profile only after full private manifest and exact launcher validation; preserve the existing one-slot migration rule and all unsupported-origin, ACL and foreign-host refusals. Fail closed before selector-free installation when the saved selection cannot be proved.
Extract the unchanged shared origin helpers into a cohesive sibling to satisfy the existing line-cap guard without waivers. Windows admission, ABI and selector behavior remain unchanged.
Actual Linux/Darwin CLI-to-filesystem relocation regressions: 18 failures on original production, all 22 cases repaired. Preserve the private relay key and inode, config, Chrome preferences, work relay19444 and explicit-profile intent. 137 focused tests, eight real POSIX native-host E2E cases, canonical changed checks, full production build and fresh P0-P2 review passed.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(ui): retain input handoff through the shared outbox owner
Remove the superseded pending-history no-yield workaround after main introduced foreground submission custody in the shared outbox owner. Restore chat-submit-guard.ts exactly to pinned main cc7 rather than retaining competing timing policies. Keep passive drains fenced while the input task yields.
Preserve the retained history regression with explicit MessageChannel admission, no passive send before resume, and the same terminal leaf, idempotency key, attachment bytes and exactly-once assertions after completion. Original composed source fails all five focused cases; the repair passes 67 handoff/attachment cases and 20 real Chromium cases in the canonical secretless network-none runner. Canonical checks, UI build/performance and fresh P0-P2 review pass. No assertion, timeout, origin or proxy-policy weakening.
Browser POSIX/Windows repairs remain byte-identical to accepted255f. The failed e40e CI receipts remain preserved; fresh exact-head CI and parent handoff are still required.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(tasks): preserve reads across native event finalization
Hand joined event publication to its exact native successor after the native
flow and observer publication frame completes. Keep worker settlement and
cleanup, reversible claim transfer, current-authority and ABA checks, and
post-commit delivery in their existing owners without replaying writes.
Cover pre-result and readback finalization, native and reentrant successor
chains, rollback, failed publication, delivery, and terminal activity cleanup.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(ui): retain rail baseline geometry on readiness failure
Keep the exact existing readiness predicate, fixtures, case inventory, assertion and timeout. When the predicate is false, retain synthetic marker identity and numeric geometry so hosted CI can distinguish scroll, visibility and viewport failures.
This is diagnostic evidence, not a repair or waiver of the unresolved rail failure. Local rootless browser infrastructure is unavailable; the existing hosted CI lane will verify the reviewed task-publication repair and collect meaningful rail evidence. Canonical changed checks and P0-P2 diagnostic review pass.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* docs(linux): describe saved-profile Chrome setup selection
Match the selector-free adapter argument vector and its regression test. Address the fresh P3 review finding without changing runtime behavior. Markdown syntax and diff checks pass; the generic formatter excludes this subtree.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* test(transcripts): join configured startup before cleanup faults
Observe and await the real startTranscripts promise through a narrow call-through spy while retaining the configured service entry point and real SQLite/provider work. Bind the await to the existing test lifetime instead of charging startup to the subsequent short active-map poll.
Gate provider return after persisted utterance to prove readiness does not settle early; retain both missing/unreadable row injections and all cleanup, private-source, lifecycle-token and summary assertions. Cover real startup rejection explicitly. No production change, timeout increase, retries or broad module/storage mocks.
The deterministic ordering boundary fails with the old fire-and-forget readiness and passes with the real promise join. Final 39 tests across 3 files, canonical changed checks and full-owner P0-P2 review pass. This does not recover whether the historical CI startup was late or rejected.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* fix(browser): preserve automatic desktop status inspection
Restore read-only Device-page inspection for current and released Mac bridges while keeping installation and verification explicit. Preserve the native filesystem prerequisite proof, split installer repair tests within the existing line cap, and remove the superseded constant export.
* fix(browser): preserve registered setup configuration
Require canonical setup to match an owned launcher's effective state and
config selection before installation or relay access. Preserve equivalent
implicit/explicit default selections and the saved launch context. Recheck
automatic profile selection before effects and the current manifest before
publication through the existing registration owner. Keep manual install
and relocation repair contracts unchanged.
Cover mismatched configs, legacy selectors, equivalent defaults, selection
drift, and actual bootstrap after refused setup. Restore the missing Command
import in the existing Unix-only companion CLI test.
Focused tests, types, lint, fresh review, clean package build and sealed Mac
ARM64 runtime proof pass. The separate historical clock-jump CI failure has
bounded replay evidence and remains documented without a speculative fix.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* fix(browser): keep setup registration types acyclic
Move the private registration status contract beside its context policy and
point both consumers at that owner. Remove the publication-module back-edge
without keeping an unused compatibility export.
The full architecture gate, extension production/test types, typed lint and
fresh independent review pass. Node's transformed JavaScript is byte-identical
for all three affected modules, so the existing runtime proof remains valid.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
* test(linux): handle Chrome setup in desktop sharing fixture
Recognize the exact automatic Chrome setup invocation and require its native
no-respawn flag. Keep unknown-command rejection, selected-auth validation,
process-group ownership and joined teardown assertions unchanged.
The original fixture reproduces the CI rejection against the real Linux app.
The repaired fixture passes all nine checks against that same binary, with
five Chrome setup calls and five node starts and joined stops. Fresh review
is clean; production app behavior is unchanged.
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
---------
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* fix(node-host): retain upload snapshots until HTTP writes settle
Scope response consumption, upload writer cancellation, and request cleanup
under one HTTP owner so early responses cannot retire active snapshot files.
Use fs-safe scoped temporary workspaces and root-bound snapshot reads while
preserving source size, digest, identity, hardlink, and literal-path contracts.
* chore: integrate upstream SQLite reclamation repair
Merge bef4401 so post-commit page maintenance waits for the parent's
commit-settlement probe to release its writer lock.
The authored worker upload patch is unchanged against the refreshed main.
Focused reclamation and upload proof passes. Original CI and replay failures
remain recorded; the original CI schedule was not independently observed.
* chore: merge main into worker upload snapshot cleanup
Incorporate the landed commentary-media fixture repair and released fs-safe 0.18.0 while preserving the worker-upload patch.
* Merge commit '473d38b61b' into codex/fs-safe-worker-upload-snapshot
* fix(node-host): confine transfer staging and settle failed writers
* chore: incorporate verified shared main repairs
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Add native computer use and Browser/Terminal launchers for prepared macOS and Windows cloud workers through Crabbox's existing authenticated transport, placement, and teardown.
Launch the separately signed Mac Cloud Worker app through LaunchServices and let it own Node/CUA, desktop permissions, and the renewable idle assertion. Bind Windows enrollment and replay to the worker's interactive account and session. Preserve uncertain launch evidence for reprovisioning, and require confirmed lease teardown before downgrading readers of newer desktop metadata.
Preserve chat end-follow during coalesced composer and goal resizing by carrying the actual scroll correction through the existing resize event and offset owner. Retain the canonical rail, progress, and approval lifecycle implementations.
Validation: exact-head CI passed 165 jobs with seven skips; 142 focused approval cases passed locally. Historical native platform proof and the remaining current-driver, lock/account-loss, enrollment, and downgrade qualification limits are recorded in #152060 under the requested best-effort testing scope.
Refs #152060.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Move node identity output, local node ID resolution, approval requester
preparation, the Gateway identity RPC, and worker-environment startup onto
the existing shared-state worker. Keep key creation and validation with the
identity owner, including legacy refusal before cold database bootstrap,
first-writer convergence, process-lifetime caching, and noncreating reads.
Keep current worker admission and runtime preparation, account for serialized
opening preparation, and drain affected fixtures before state cleanup. Preserve
the current pairing worker migration and its zero-host-query proof.
Identity output, stored keys, schema, permissions, and update behavior are
unchanged. Synchronous constructor, Doctor, and other callers remain outside
this selected cut. Follow-up to #150313; related to #144592.
Validation: focused identity and Gateway/startup tests, actual caller and
opening-budget source red/green proof, routing/closure coverage with its
obsolete build expectation repaired, full changed-file checks, final focused
checks, and independent P2 review. Exact-commit build and compiled CLI proof
are performed after this private commit; historical CI causes remain unknown.
Wait for the matching journal finish before child readiness and keep the launch receipt protocol unchanged. Await initialization and close directly, and synchronize initial capacity from its callback.
Proof: original-order affected shard 5/5 red before and 5/5 green after; check:changed and P1 autoreview pass.
A completed turn can precede its worker lineage-settled publication. Wait for the existing physical cleanup barrier before capturing the receipt used for the exact idempotent replay assertion, and always close the fixture supervisor.
* feat(process): support awaited stdout consumers
* refactor(node-host): move launch and turn journals to the state worker
Preserve journal transactions and live-owner checks while retaining result persistence and native settlement. Carry the existing shared admission component from #148623; process consumption remains in the #149442 parent.
* fix(node-host): preserve receipt reads after supervisor shutdown
* test(node-host): await worker inventory reconciliation
* test(node-host): route prepared journal fixture through broker owner
* test(node-host): route background worker cleanup through SQLite broker
* refactor(node-host): clarify async pause and output loop contracts
Keep failed update operations identifiable in reports and issue titles while preserving redaction of private command arguments, paths, and diagnostic text. Separate stable step identifiers from command text in package, Git, candidate-validation, and CLI producers, and clear stale diagnostics after a successful retry.
Use one released-key adapter for ledger writes, restart sentinels, and report joins so restored readers retain exact package/fetch keys and measured exit codes. Preserve authoritative recovery keys and existing update admission, execution, rollback, schemas, defaults, and operator options.
Related: #153230, #152193. Thanks to @marcio-absmartly for identifying the indistinguishable failure reports.
Validation: scoped-clean recorded Codex review; green exact-head CI; 196 Gateway run-loop and 100 package recovery tests; changed-file gates; published 2026.9.4 reader replay against unchanged production bytes. Historical installed-runtime evidence covers upgrade, rollback, retry, and rerun at its recorded source head.
* feat: enable paired desktop sharing with a Mac settings control
Offer authenticated desktop streams by default on supported persistent nodes while preserving explicit opt-outs, pairing approval, and Gateway deny policy. Add a native Desktop sharing control that reconnects the node and reflects the worker’s resolved configuration.
* feat: add desktop sharing to the Tauri companion
Give the Tauri companion the same persistent desktop-sharing control as the native Mac app, backed by an app-owned desktop-only node for its Primary Gateway. Preserve explicit node opt-outs and require interactive reapproval for legacy desktop grants when the old allowlist was removed.
Keep node authority in the existing CLI and pairing owners. Join owned process trees on preference changes, Primary changes, and Quit; reject stale native setting snapshots.
* test: format launcher shutdown cases
* test: align desktop sharing proof fixtures
* test: clean up desktop sharing lint findings
* test: keep desktop sharing proof reports in order
* test: verify retired dashboard sharing authority
* test: drain shared state before harness fixture cleanup
* test: extract harness transcript fixtures
* test(ui): wait for rendered theme toggle state
* test: adopt main harness cleanup owner
* test: observe Windows wrapper child readiness
* fix(config): preserve references across plugin owner migrations
* fix(config): keep authored provenance out of config responses
Keep include-expanded authored snapshots internal across valid, invalid, and cached config reads. Cover read-scoped root/include responses while preserving the paired internal trees.
Defer alias migration helpers and their direct resolved-source API tests to the first consumer layer; preserve existing env-reference entrypoint coverage here.
* test(config): invalidate cached provenance fixtures
* test(models): keep native auth refresh fixture passive
* test(node): keep prepared workspace fixture owner private
Create the fixture owner root with the same private permissions as project
preparation so permissive host umasks cannot invalidate transfer tests.
* refactor(config): split authored env-reference accounting
Move unchanged authored-reference helpers and private snapshot tests into
coherent siblings so the provenance change satisfies the line-cap ratchet.
* fix(tooling): include authored env helper in PR wrapper archive
Keep the extracted wrapper source inventory complete after the config
helper extraction; preserve eager-import closure and provisioning guards.
---------
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* perf(projects): move durable listings to retained workers
* perf(sessions): move placement evidence reads into workers
* refactor(state): remove placement reader type cycles
* refactor(state): query registry schema through Kysely
* fix(ci): align status timeout fixture with shared auth
* test(gateway): adopt timeout persistence synchronization
Carry the exact reviewed test-only fix from #153342. Await the captured
terminal persistence owner before advancing the abandoned producer's grace.
Preserve all original deadlines, clock steps, receipt, removal, and retry
assertions. No production changes or diagnostic delay are included.
The patch and relevant lifecycle owners match the donor's 35-test,
selected-check, and independent review evidence byte-for-byte.
* test(outbound): retain live claim during ACK fixture cleanup
Related: #141559. Adjacent execution-stage guidance: #130972.
## What Problem This Solves
Fixes approval-preparation refusals that look like a human denied execution, even though the command could not be prepared and no approval request was created.
## User Impact
The error now distinguishes an unsupported command shape from an operator decision and gives recovery guidance specific to the execution path. Node callers are directed toward supported single-executable commands, without promising that nested interpreter scripts can run. Native CLI callers can retry supported direct executable/script forms with explicit paths.
Unsupported commands remain denied. Binding checks, approval decisions, revalidation, error codes, and public protocol fields are unchanged. This does not enable currently unsupported node interpreter execution or resolve the broader error-classification concerns in the linked issue.
## Why This Change Was Made
The binding owner now carries an internal failure classification instead of making callers identify that failure from diagnostic prose. The two existing preparation presentation sites explain the phase and their different capabilities. The internal classification is removed at the opaque harness boundary; it is not a new SDK or wire field.
## Evidence
Baseline `acbeb3a071` and candidate `d83eff8ac3b5` were exercised through an isolated real Gateway:
| Entry and control | Observed result |
| --- | --- |
| `chat.send → exec(host=node) → paired headless node`, unsupported command | Baseline returned only the binding refusal. Candidate explains that no approval request was created; both create zero approval records and leave the workload marker absent. |
| Node shell chain rewritten as one supported absolute-path executable | An ordinary exec approval is created; `allow-once` executes it. An explicit `deny` does not. |
| Registered Anthropic CLI backend and permission callback, unsupported Perl lookup form | Candidate explains the preparation refusal without claiming a user denial; no approval or command execution occurs. |
| Same Perl runtime using an absolute script path on the native CLI path | An ordinary plugin approval is created; `allow-once` executes the script. Explicit denial and script changes after preparation remain rejected without execution. |
The native transport peer and loopback model responses were synthetic; Gateway routing, the registered plugin/callback, approval records, CLI resolution, binder, filesystem, and permitted local commands were real. No vendor authentication or paid model request is claimed.
A node absolute-script retry remains unsupported, so the contributor's blanket script-file advice is not included. Gateway and node state were task-owned, and OS sandboxing restricted network traffic to loopback.
After colocating the existing Perl option and node preparation helpers with their owners, candidate `1e5fee5d0ccf` repeated both registered preparation-refusal paths with the same diagnostics, zero approval records, and no execution. All 356 focused binding, node-host, native-approval, and Codex-bridge tests passed again, and the changed-source line-cap ratchet passed. Existing rejection tests now assert structured outcomes instead of pinning prose. Full static and matrix validation remain in hosted CI.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(nodes): prevent orphaned work after cancellation and crashes
Keep hosted-worker capacity occupied until the process owner confirms descendant cleanup. Preserve completed turn results, peer isolation, and recoverable cleanup ownership when a replacement node host shuts down.
Allow the exact cancelled worker to settle its finishing acknowledgment without recreating publication or execution authority. Carry private lineage descriptors through the existing worker-start channel and package the sealed relay and anchor with the worker bundle.
* fix(nodes): preserve compatible starts across fleet upgrades
Keep released workers on their supported type-only startup and detached process-group owner. Select stronger relay ownership from the worker build capability.
Negotiate captured exec-policy support separately at node inventory so unsupported hosts show the existing update-required outcome before OpenClaw worker dispatch. Preserve remote-exec eligibility, current-authority checks, and cleanup operations.
Validated with released-worker startup and termination proof, registered inventory and dispatch regressions, focused sibling tests, changed checks, and independent review.
* test(nodes): keep current-worker fixtures eligible
Declare captured exec-policy support on the five current-node fixtures that exercise prepared dispatch, replay, authority revocation, and admission. Forward execution mode through the prepared fixture currentness callback independently of slot consumption.
Preserve assertions and deliberate legacy and remote-exec fixtures. All16 reproduced failures are fixed;243 tests across16 files and selected checks pass. Production, build, and dependency inputs are unchanged from97fe.
* ci: refresh node lifecycle merge validation
* fix(node-host): preserve cleanup evidence during worker recovery
Restore released process-group recovery after the leader exits. Record the selected transport before admission and retain exact-anchor root/lineage completion in a journal-owned companion table before releasing capacity after restart.
Use existing-file completion transactions so late cleanup cannot recreate removed state. Preserve public receipts, schema version and terminal retention; drain active modern workers before rollback to an older writer.
* fix(node-host): keep schema DDL annotation beside its call
Preserve the existing canonical first-use schema exception at the leading callsite recognized by the SQL guard. No SQL, guard rule or runtime behavior changes.
* fix(node-host): load journal writer before source helper cleanup
* test(macos): gate readiness recovery after owner failure
Hold the failed startup owner beyond an explicit waiter budget, then require a fresh health request and cleared failure state. Preserve the owner deadline and join cancellation cleanup. Production inputs are unchanged by this commit; disposable native proof runs on a separate task branch.
* fix(nodes): keep free capacity available during recovery
Bound observation of an unfinished cleanup anchor without releasing its reservation or escalating against it. Reconcile retained physical owners through status even when their requested turn has completed, preserving the turn outcome and requiring both lineage completion and tree extinction before freeing capacity.
* fix(nodes): recover capacity after bounded restart observation
Retain exact cleanup observation in the node supervisor after startup returns, publish freed capacity automatically after verified cleanup, and stop and join observation on shutdown. Share cancellation intent and preserve completed turn results.
Restore node-host workspace downloads on hosts using umask 0002. The runtime, contained-directory, and seed-cache owners now create directories at 0700 and repair existing 0775 ancestry through the shared descriptor-based permission helpers. Filesystem safety validation and transferred payload permissions remain unchanged.
Cover fresh private-directory creation and legacy reopening through a child process and real HTTP workspace transfer. Give related test fixtures explicit private modes and document recovery without changing the host umask.
Validation: 30 transfer/startup tests under umask 0002, 28 seed/retention tests, 32 shared-state tests, hosted Testbox 70 passed, selected changed-file gates, and scoped-clean Codex review. Exact-head CI verified by the campaign lead.
Related: #152120
* fix(codex): keep catalog actions on the selected native session
Keep stop and steer on the active client, settle native fork ownership under
the binding lease, and retain canceled resume reservations until cleanup has
settled. Preserve ordered inbound images and confirm native thread absence
through an authoritative read.
Require current source support for node catalog continuation, scope resume
reservations by canonical store and thread, and preserve source identity
through terminal routing. Older nodes retain readable catalogs and unqualified
slash-command bindings; catalog continuation requires the upgraded capability.
Production delta: +95 net lines. Focused proof: 1,200 passing cases across 27
files with one Windows-specific skip. Official P2 review 5 covers the original
67-file snapshot; review 7 covers the exact final five-file follow-up. Both are
scoped-clean. The unchanged CLI test-support core-lint error is recorded in the
handoff; final composed CI, live proof, and screenshot publication remain with
the integration owner.
* fix(codex): keep captured homes stable across alias changes
Capture the physical agent directory and Codex home once per config
generation, including missing home leaves, and carry that prepared path
through native startup and bound CLI resume. A client restart cannot
follow a retargeted alias under an older source-home identity.
Preserve requested home ownership while aligning cache and fence keys,
native config reads, skill isolation, and binding rotation with the
captured path. Configuration reload remains the invalidation boundary.
Validation: four intended original-code failures; 503 focused and
sibling cases pass across ten files. Extension types, changed lint,
formatting, line caps, and independent scoped P2 review pass.
* test(codex): align integration fixtures with runtime contracts
Load Codex metadata through the core manifest owner in the broker
cancellation integration test, preserving the core/plugin boundary.
Match refreshed quota-fixture lifetime to its existing fixed JWT expiry
so the healthy-status assertion respects the CLI warning window.
Resolve the Swift TLS retry endpoint from its updated stored pin.
Preserve behavioral assertions, production thresholds, and timeouts.
Validation: 11 boundary/broker cases, test-root types/lint, formatting,
line caps, and scoped P2 review pass. All three quota UI replay cases
pass on the verified integration runtime; native Swift CI remains the
execution proof for the final candidate.
* fix(plugins): preserve reactivated registries during retirement
Recheck registry liveness after asynchronous command draining before
marking a no-host-cleanup registry retired. A temporary registry can
restore the previous one while displaced cleanup is still pending.
Also collect widget dropdown rows and computed fonts in one browser
evaluation so a removed loading row cannot corrupt the typography
assertion. Keep the existing full-font equality assertion unchanged.
Validation: scoped P2 reviews, physical core production types, targeted
core test graph types, 28 catalog registry/broker cases, 37 registry
owner/sibling cases, 43 original-order QA/prompt/Copilot cases, and
4 normal plus 15 bounded timing browser cases pass.
* refactor(ui): deduplicate catalog key parsing
Normalize catalog URL fields together and keep empty-component rejection in the decoded key validation. Preserve routing and source-home identity while reducing the startup bundle without changing performance limits.
* fix(crabbox): support native cloud desktop viewers
Use native Screen Sharing and VNC for macOS and Windows instead of applying Linux desktop setup to every target. Keep managed account credentials on the node/Gateway path, honor native display resize restrictions, and provision non-Linux targets cold when a shared profile enables warm images.
* test(workers): cover native desktop teardown before downgrade
Connection, runner startup, and node-only status awaited configuration loaders that still performed SQLite queries on the calling thread. Delegate both loaders to the existing shared-state read worker through a fixed nodeHost.config command and the canonical metadata query kernel.
Preserve missing-store noncreation, JSON and timestamp validation, retired-file refusal, captured state-root identity, existing-schema admission, drift refusal without repair, and joined cleanup. Derive reply rows from the generated database schema to avoid a type-import cycle. Configuration replacement retains its existing synchronous transaction.
Validation: 38 focused configuration and reader tests, core/test types, architecture checks, formatting, normal builds, and scoped review passed. Fully compiled Node and Bun proof each recorded zero parent SQL across 17 required read and cleanup stages, including fresh/cached managed-schema reads and drift refusal. Exact-head CI and the required aggregate gate passed after a documented retry of one idle, unassigned shard. Bootstrap, explicit snapshot preparation, configuration writes, live operator state, and stalled-child testing are outside the zero-SQL claim.
Windows owned stdio children now use the existing retained Job owner to confirm descendant cleanup after the parent exits, preserving interactive input and worker IPC.
Keep native support optional: unavailable or failed Job setup falls back to ordinary command startup and reports typed uncertainty. Tree-required cleanup retains state locks and temporary artifacts until extinction is certified; transport-only cleanup remains independent. Claude prompt and skill artifacts are retained with a warning when cleanup is uncertain.
Related: #151325, #150427, #150244.
Validation: exact-head CI run 35354835669 is green, including both Windows node-test jobs; 243 focused tests passed locally on macOS with six native Windows skips. The P1 review is scoped-clean, and all 13 reviewed commits are preserved by a semantic-equivalent rebase. Hosted Windows proof and the capability matrix satisfy the maintainer's compatibility-proof ruling.
* feat(node): update headless runtimes automatically when idle
Stage private packaged node runtimes and activate only after all owned work
and cleanup settle. Preserve pairing and launch options, keep automatic
activations at least 12 hours apart, and leave shared-state migration and
Gateway installation ownership with the normal updater.
Document defaults, opt-outs, runtime version discovery, and recovery.
Support recoverable Windows selector replacement across service restarts.
Refs #151462
* fix(node): complete auto-update integration and settings defaults
Capture the launcher in compiled test runtimes and trusted wrapper inventories, register the package update proof, and use the canonical Kysely read path. Preserve the inherited enabled state in the config UI and align caller tests with the node shutdown lifecycle.
* fix(node): preserve retained plugin work during automatic updates
Require an explicit idle result from plugin commands, preserve older-plugin work, and connect bundled lifetime owners to automatic node updates. Join canceled inference and failed terminal cleanup before command settlement; keep historical state repair with Doctor. Document compatibility and extend installed-package proof for retained legacy plugin work.
* test(browser): align idle-work fixtures with runtime exports
* test(browser): extract proxy request fixtures
* test(node): retain idle assertions across native cleanup
Keep platform probing and cache ownership in the production modules.
Use typed module mocks for the existing hardware-model and node-host
identity cases instead of private dependency override parameters.
Move runCommand into the production-used execution module and remove the
VITEST-only Symbol publication, test bridge, and publication registry entry.
Keep cwd diagnostics private and exercise them through command results.
Preserve launch-policy callbacks, cancellation, output bounds, and stdin
closure. Retain the original lifecycle timeout and diagnostic evidence;
this extraction does not claim a timeout or performance fix.
* fix(nodes): preserve cancelled turns when workers reject terminal events
Keep an accepted node turn cancellation separate from the physical worker failure when no result frame arrives. Preserve failure diagnostics, exact ownership, journal retry, and process cleanup before returning capacity.
Report standalone worker failures with the shared redacted CLI formatter and bounded output drain so Node does not dump bundled source or leave a failed worker alive with open handles.
* test(worker): isolate caught runtime entry exits
* perf(workspace): offload inventory and manifest processing
Keep the Gateway and paired nodes responsive during large workspace transfers with bounded computation workers. Hosts retain session authority, Git processes, file writes, durable acceptance, and cleanup.
Use transferable UTF-8 payloads for supported Unicode inventories, preserve independent errors during cancellation, and compare already-decoded manifests without copying their object graphs between threads.
* test(workspace): finish manifest fixture ownership
* refactor(workspace): distinguish stage input implementation
* test: register workspace benchmark and honor system Bash