Commit graph

10267 commits

Author SHA1 Message Date
Peter Steinberger
d1a550d938
refactor(boards): execute mutations on the agent worker (#153159) 2026-09-19 23:22:57 -07:00
RoboClaw
07d04cb79f
fix(test): restore the installed Code Mode live fixture (#153442)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 22:55:17 -07:00
Peter Steinberger
4b1c45066b
perf(ui): reuse session snapshots across subagent trees (#152510)
Publish bounded, deduplicated ancestor snapshots through the existing per-viewer
Gateway presenter, and refresh derived facts on keyed registry publications.
Apply complete rows with their own identity and field receipts while retaining
conservative membership and pagination refreshes. Skip recap-only invalidation
in the agent roster.

The 28-viewer fixture eliminates window reads for repeated child, terminal-child,
and recap changes while preserving initial pages and broad invalidations.
Rendering is unchanged; protocol-v4 snapshot additions are documented.
2026-09-20 05:52:58 +00:00
Peter Steinberger
ca128370df
perf(tooling): skip tsx for native compiler shard entry (#153446) 2026-09-19 22:44:55 -07:00
Peter Steinberger
2ce0573b02
fix(gateway): preserve active work during recovered Node restarts (#153435)
* fix(gateway): preserve work during recovered Node restarts

Let Unix Node recovery wrappers respect the existing Gateway stop budget.
Share startup-safe command classification and deadline facts, and resolve
managed restart intent against the live serving owner in its write
transaction with current update authority.

Preserve the existing public PID intent API, record format, and Windows
behavior. Keep cold lifecycle test preparation outside timed hooks.

Inspired by @ly85206559's wrapper-grace approach in #147054; this repair
is independently authored from main. Related: #146956. Windows cooperative
shutdown remains a follow-up.

* refactor(gateway): stabilize restart callback and test setup

Declare receiver-independent restart intent callbacks as arrows and retain typed signal spy handles for lint-safe assertions. Move cold lifecycle imports into test collection so worker preparation cannot consume timed setup hooks.
2026-09-19 22:41:17 -07:00
Peter Steinberger
af83e3e98d
improve: reduce GitHub API work in PR review and CI polling (#153424)
* perf(scripts): avoid eager PR check expansion

* test: align cross-checkout fixture with lean PR metadata
2026-09-19 22:21:31 -07:00
Peter Steinberger
50ba6c0475
fix(onboarding): avoid blocking recommendation storage (#152445)
* fix(onboarding): avoid blocking recommendation storage

Keep recommendation reads on the independent read-only worker and route all five mutations through the existing shared-state actor. Preserve workspace identity, no-create reads, transaction and CAS behavior, and await persistence in registered CLI actions and both wizard completion paths.

* refactor(onboarding): keep state decoding and dispatch with owners
2026-09-19 22:20:14 -07:00
Peter Steinberger
44b0127030
fix(github): distinguish publication locks from unavailable storage (#152437)
Publication and confirmation now distinguish held workspace leases from unavailable storage and caller-canceled acquisition. The shared SQLite lease owner records these outcomes, replacing the publication-specific retry inference while preserving caller authority, native settlement, and retired-owner fencing.

Doctor records pre-grant cancellation as a visible inspection warning without changing its signal budget or mutating source state. No new configuration, CLI options, schemas, dependencies, or wait limits are introduced.

Validation: scoped-clean Codex review; native SQLite/worker, registered publication RPC, Doctor, updater-authority, and wrapper-boundary proof; exact-head CI gate success. The current candidate's published-updater through healthy Gateway restart scenario remains an explicitly accepted, bounded validation gap recorded in the PR body.
2026-09-19 22:14:42 -07:00
Peter Steinberger
7e5d6bdc9b
refactor(auth): prepare bounded shared auth scopes asynchronously (#152286)
* refactor(auth): prepare bounded shared auth scopes asynchronously

Read shared ownership and portable credentials through the existing state
worker before entering bounded CLI and provider-setup auth scopes. Resolve
paths before awaiting and recheck admission and ownership before entry.

Preserve local overrides, OAuth refresh ownership, and personal-account
isolation. Record the cold-worker latency and memory tradeoff in PR evidence.

Related: #149309

* fix(test): await scoped auth while staging live fixtures

Wait for the portable auth view and target persistence before fixture
installation continues. Drain the CLI's existing maintenance owner before
exit and run direct helper tests through the host database-worker lane.

* test(auth): include cacheability in scoped read fixtures

* test(auth): align cancellation fixture with current row metadata

* test(outbound): clean up ACK fixtures with their owner

(cherry picked from commit 4681239a66)
2026-09-19 21:54:00 -07:00
Bảo Võ
184cdd4eff
test(update): preserve unverified restart outcomes after package swaps (#142102)
* fix(update): keep a managed update from stranding the gateway after the install swap

A managed package update stages the new version, swaps it over the live
install root, and only then restarts and verifies the gateway. That
restart runs inside the updater process, which is still executing the
build that was just replaced. The bundled dist is split into
content-hashed chunks, so any `import()` reached for the first time after
the swap resolves to a chunk name that only the old tree contained:

  Gateway: restart failed: Error: ENOENT: no such file or directory,
  open '.../node_modules/openclaw/dist/shared-DFJEouXv.js'

`maybeRestartService` caught that as a restart failure, which became
`recovery.serviceRestartSafe: false`, which made the update helper exit
with the unsafe code and log "keep the gateway stopped until the
installation is repaired". The installation was fine -- npm install, the
swap, and doctor had all exited 0 -- but the gateway stayed down until
someone restarted it by hand. Observed on a 2026.9.1 -> 2026.9.2 npm
update: a 3h outage from a successful upgrade.

Two changes:

- Warm the restart path's lazy modules in `beforeActivate`, the last
  point where this process can still read its own install tree. The probe
  gained a loader for `gateway/call.js`, which was a bare dynamic import
  and so could not be warmed.

- Recognize a missing module inside our own install root and stop
  treating it as a verdict on the new install. Restarting the service is
  strictly better than parking it: the old process is gone either way,
  and a genuinely broken install still surfaces through the service's own
  supervision. A missing *data* file in the install root is still a real
  failure.

Claude-Session: https://claude.ai/code/session_01WKVaMWLzdHNJCa82nnTfWg

* test(update): use canonical normalization in restart regression

* test(update): register package-swap regression in its CI owner

* test(gateway): join task events before reset fixture cleanup

* test(gateway): join task events before in-test settlement

* test(gateway): prepare auth command runtime before handshake

* fix(ci): bound serial storage-state test stripes

* fix(ci): scope storage file ceiling to hosted jobs

* test(transcripts): wait for routed provider startup

* test: honor delivery and session fixture ownership

* test(transcripts): join configured provider startup

---------

Co-authored-by: baovo15 <duybao.vin@gmail.com>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 22:50:18 -06:00
Peter Steinberger
de92b65a62
fix: await queued registry and task persistence (#151303)
* fix: avoid blocking Gateway work on queued collector registry writes

* fix(tasks): retain delayed flow repairs through cleanup

Move live flow retries and projection snapshots onto the shared task-domain
worker while retaining transaction-time live selection and lifecycle custody.
Join failed projection reads before releasing Gateway work, and give durable
retry timers their own async cleanup scope when they fire.

Preserve immediate synchronous compatibility, full-row compound writer checks,
and the existing retry schedule. No schema or retention changes.

* fix(tasks): avoid redundant mirrored-flow snapshot reads

Let the canonical write transaction classify dirty mirrored-flow targets
without first refreshing the full projection. Preserve clean missing and
managed no-entry behavior and use the existing getter on failure to retain
current failure metadata. Keep unrelated dirty obligations and query budgets.

* fix(test): remove duplicate Codex attempt inventory entries

* test(ci): distinguish retained job worker caps

* fix(test): preserve under-cap syntax repairs in validation

* refactor(tasks): share creation and transition operations

* fix: publish acknowledged managed task receipts

* fix: await initial task persistence before Gateway activation

* fix(subagents): settle cancelled queued launch metadata

* fix(test): await registration in waiting reply fixtures

* test: await routed transcript provider readiness

* test(outbound): clean up ACK fixtures with their owner
2026-09-19 21:41:39 -07:00
Peter Steinberger
fc60bf09f2
fix: restore Mac presence context and Canvas media playback (#153381)
* fix: restore Mac presence context and Canvas media playback

* refactor(gateway): separate the node session type contract

* test(codex): cover active presence in prompt fixtures

* test: include active computer in Codex context ordering

* test: supply snapshot auth-profile store

* test: align presence search and CLI prompt expectations
2026-09-19 21:37:59 -07:00
RoboClaw
5fa791c28c
fix(e2e): recognize compiled baseline plugin activation (#153410)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 21:28:08 -07:00
RoboClaw
a665c714ee
fix: isolate release verification test state (#153384)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 20:39:31 -07:00
Peter Steinberger
1b5c7dd511
fix(macos): honor worker package timeout budgets (#153380) 2026-09-19 20:37:14 -07:00
Omar Shahine
88c56ec432
feat(plugins): add experimental FaceTime realtime voice bridge (#119291)
* feat(plugins): add experimental FaceTime realtime voice bridge

Co-authored-by: Peter Steinberger <steipete@gmail.com>

Co-authored-by: Dallin Romney <dallinromney@gmail.com>

* test(facetime): align portable release gates

* ci: refresh FaceTime PR checks

* fix(facetime): retain startup suppression through hangup

Begin carrier closure before startup teardown and keep native suppression pending until carrier absence is confirmed.

* fix(facetime): retain cancellation until carrier safety is confirmed

* fix(facetime): separate carrier closure from startup teardown

* test(pr): model authoritative repository identity in sibling fixtures

* fix(facetime): retain suppression without carrier proof

Do not treat the capture watchdog shutdown as evidence that the native carrier terminated. Keep the call unresolved and process suppression retained until exact termination or stable absence is observed.\n\nCo-authored-by: Codex <noreply@openai.com>

* fix(facetime): retain disconnected carrier proof

* fix(facetime): stabilize live audio startup and routing

* fix(facetime): refresh merged lockfile

* refactor(facetime): separate helper result projection

* fix(facetime): align published package metadata

* fix(facetime): satisfy preflight lint checks

* fix(facetime): preserve consult and carrier ownership

* test(facetime): declare regression fixture types

* test(release): align merged publisher inventory

* fix(facetime): retain runtime across safe uninstall

* fix(facetime): restore responsive call opening

* refactor(facetime): keep greeting policy localized

* fix(facetime): accept trusted stock Xcode

* fix(facetime): use compiler link drivers

* fix(facetime): repair portable lifecycle checks

* fix(facetime): normalize installed driver permissions

* fix(facetime): preserve consults during caller speech

* fix(facetime): make answered-call greeting reliable

* fix(facetime): honor explicit agent session owner

* fix(facetime): finish voice consults promptly

* fix(facetime): preserve repeated voice consults

* fix(facetime): settle consult delivery before reporting success

* fix(facetime): retain suppression until carrier closure is proven

* docs(facetime): refresh merged plugin reference count

* fix(facetime): preserve installed driver when backup fails

* test(facetime): prove rejected calls cannot start media

* fix(facetime): verify unknown SIP status before setup advice

* test(facetime): prove caller rejection at authenticated media boundary

---------

Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-09-19 20:36:04 -07:00
RoboClaw
eadd90b8fa
test(e2e): overwrite converged baseline companion fixtures (#153382)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 20:34:48 -07:00
Peter Steinberger
3bbb9a3f10
perf(crabbox): move Doctor warm-image reads to the state worker (#149889) 2026-09-19 20:28:42 -07:00
RoboClaw
066a93fbda
fix(release): recognize the reviewed 2026.9.6 plugin inventory (#153372)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 19:59:19 -07:00
Peter Steinberger
883b2a9441
fix: keep PR identity checks working when GraphQL quota is exhausted (#153296)
* fix(scripts): use REST for writer identity and reviewer claims

Use included-header REST identity reads through the protected selected CLI, preserving the actual mutation writer and quota diagnostics. Verify reviewer assignment through the REST assignees response. Keep GraphQL contracts for queue state, squash previews, required-check app binding, and atomic publication. Refs #153199.

* test: preserve acknowledgement worker owner checks
2026-09-19 19:50:55 -07:00
Dallin Romney
f8e68c5e23
test(telegram): remove rate waits from recovery fence (#151424) 2026-09-19 19:49:14 -07:00
Peter Steinberger
52daee5b27
perf(events): retain the shared event state handle (#152729) 2026-09-19 19:47:36 -07:00
RoboClaw
8cae393bca
fix(test): stop requiring retired iOS location copy (#153363)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 19:45:58 -07:00
Kimi Yu
59916acb71
feat(agents): send input attachments to remote workspaces (#152652) 2026-09-19 19:34:55 -07:00
RoboClaw
286487d234
fix(ui): keep attached context out of message text (#152539)
* fix(ui): keep attached context out of message text

Preserve bounded send-time reference snapshots separately from authored text through queued sends, retries, transcript display, and edit actions. Keep raw context inspectable behind a disclosure without changing its authority.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): complete context attachment CI coverage

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(state): align custody proof with worker acquisition

Apply the already-landed test correction from bfec65a2a0. Release the late competing host owner before awaiting the worker, while preserving authority checks, operation outcomes, and persisted-state assertions. Reproduces and repairs both failures in CI job 105859785996 without production changes or longer timeouts.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(ui): keep simulated history fling events contiguous

Drive the final contact movement, release, and initial inertia in one browser task so RPC latency cannot split the intended continuous gesture. Preserve total movement, stationary-touch coverage, omitted scrollend, and every-frame anchoring assertions.

* test(ui): avoid shadowing the momentum fixture parameter

* test: fix native shutdown and session fixture races

Keep Sparkplug compilation synchronous in test Node processes and propagate the shared argv policy to Vitest fork workers. This avoids a proven compiler/GC deadlock during process.exit without changing production shutdown, assertions, or deadlines. Join background session disk measurements before closing and handing off SQLite fixtures.

* test: fix compiler policy assertion and rebalance UI typechecks

Retain the independent Sparkplug shutdown policy when opting into Maglev. Split chat test roots into an appended shard without changing coverage or root limits.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-19 19:19:31 -07:00
Peter Steinberger
9e7a575155
fix: keep Gateway responsive while admitting outbound messages (#153076)
* fix: keep Gateway responsive while admitting outbound messages

* test: run durable delivery flows with the host database broker

* test: complete durable delivery test routing

* test: include WhatsApp in the database-worker batch expectation
2026-09-19 19:15:18 -07:00
Dallin Romney
3444c7d3dc
fix(release): wait longer for npm publication readback (#151421) 2026-09-20 02:04:34 +00:00
Peter Steinberger
2db3e1fec7
refactor(matrix): resolve direct-room encryption from account config (#152353) 2026-09-19 18:54:51 -07:00
Kimi Yu
14cf1689a8
feat(memory): read and update files on remote workspaces (#153124) 2026-09-19 18:53:57 -07:00
Peter Steinberger
044f78eeae
test: isolate retired agent cleanup transport fixture (#153286) 2026-09-19 18:15:21 -07:00
David
c6bb12b061
fix(plugins): reject hollow installs and repair missing dependencies (#103398)
* test(plugins): repro hollow npm dependency tree accepted by install

* fix(plugins): reject managed npm installs with missing required dependencies

npm can exit 0 while leaving the installed plugin's declared dependency
tree unmaterialized; the hollow install previously passed lock-metadata
verification and loaded at startup only to die at import time. Verify the
declared required dependencies resolve from the installed package dir and
roll the managed root back when they do not.

* fix(doctor): detect and repair installed plugins with missing required dependencies

Status surfaces already point users at doctor --fix when an installed
plugin's dependency tree is broken, but doctor only recognized entry
diagnostics and stale runtime packages as repairable. Walk record-backed
snapshot plugins with buildPluginDependencyStatus, surface the missing
package names in the health finding, and route the plugin through the
existing repairable-install flows so --fix reinstalls the package.

* test(doctor): cover missing required dependency detection and repair

* style: apply oxfmt to touched plugin install files

* test(plugins): assert hollow install rollback state

* test(doctor): cover dependency repair eligibility

* fix(doctor): scope dependency repair to active installs

* test(doctor): cover fresh dependency repair generation

* fix(doctor): reinstall broken plugin in fresh generation

* test(doctor): use managed root retention fixtures

* test(plugins): cover optional dependency override installs

* fix(plugins): honor optional dependency overrides

* fix(doctor): preserve intentional disabled-plugin skips

* style(doctor): format capability consent forwarding

* test(doctor): preserve repaired plugin record generation

* fix(doctor): carry repaired records into metadata refresh

* test(doctor): include workspace in record refresh proof

* test(doctor): assert rebuilt cleanup metadata index

* test(doctor): reproduce registry record rollback

* fix(doctor): reload install records before registry repair

* test(doctor): isolate registry cache regression

* test(doctor): reproduce disabled dependency repair

* fix(doctor): ignore disabled dependency repairs

* test(doctor): reproduce hollow runtime cohort drift

* test(doctor): review staged cohort repair artifact

* test(doctor): accept cohort repair capabilities

* test(doctor): stage a valid cohort repair artifact

* test(doctor): materialize cohort repair target

* fix(plugins): carry cohort policy through update specs

* fix(plugins): resolve version-bound updates per target

* fix(doctor): keep hollow runtimes on core cohort

* test(doctor): cover current and pinned hollow runtimes

* test(doctor): expose cohort override drift

* fix(doctor): override hollow runtimes with canonical specs

* fix(plugins): pin canonical runtime overrides to cohort

* test(doctor): reject runtime package identity collision

* fix(doctor): bind cohort override to package identity

* test(doctor): reject conflicting runtime package identity

* fix(doctor): bind cohort override to active package

* test(doctor): respect runtime package selector identity

* fix(doctor): respect runtime package selector

* test(doctor): reject stale runtime identity collision

* fix(doctor): bind stale runtime repair to package identity

* refactor(doctor): isolate runtime package staleness

* test(doctor): enforce runtime cohort acceptance

* test(doctor): model runtime cohort payloads

* fix(doctor): define runtime cohort acceptance

* fix(doctor): reject stale runtime repair payloads

* fix(doctor): pass runtime version to cohort check

* style(doctor): avoid repair input shadowing

* test(doctor): require a fresh runtime generation

* refactor(doctor): name fresh generation failures

* fix(doctor): require fresh dependency repair roots

* test(doctor): model fresh repair generations

* test(doctor): materialize repaired generation payload

* test(doctor): materialize official repair payload

* test(doctor): classify against compatibility host

* fix(doctor): share compatibility host version

* test(doctor): isolate compatibility host cases

* chore: tighten env var name budget

* refactor(doctor): narrow runtime payload metadata

* refactor(doctor): keep cohort matcher internal

* test(doctor): expose runtime cohort source drift

* fix(doctor): classify the active runtime payload

* test(doctor): isolate cohort source cases

* test(doctor): align runtime payload fixtures

* test(doctor): expose cohort rejection commit leak

* fix(doctor): reject stale cohorts before npm commit

* test(doctor): allow updater preflight warnings

* test(plugins): cover npm precommit fallback wiring

* test(plugins): expose rejected generation leak

* fix(plugins): remove rejected fresh npm roots

* refactor(plugins): inline npm update attempt

* test(doctor): reject npm artifact identity drift

* fix(plugins): reject npm package identity drift

* fix(plugins): preserve npm resolution diagnostics

* test(plugins): cover npm identity mismatch diagnostics

* fix(plugins): report canonical npm identity mismatch

* fix(doctor): validate runtime package JSON shape

* test(plugins): reject exact npm selector drift

* fix(plugins): reject npm selector metadata drift

* test(plugins): preserve semver-like npm dist-tags

* test(plugins): preserve npm 12 semver-like dist-tags

* fix(plugins): preserve semver-like npm dist-tags

* test(plugins): cover npm array exact selector drift

* fix(plugins): classify npm array selector drift

* test(plugins): lock exact selector metadata parity

* test(doctor): cover beta convergence identity gate

* test(doctor): cover post-install cohort rollback

* fix(doctor): defer runtime commit through record validation

* test(doctor): cover accepted runtime transaction commit

* test(doctor): cover install rollback on index failure

* fix(doctor): settle runtime installs after index write

* test(doctor): cover deferred cleanup failure

* fix(doctor): preserve committed repair on cleanup failure

* test(doctor): fence runtime repair lease ownership

* fix(doctor): fence runtime repair lifecycle writes

* test(doctor): expose updater repair transaction gap

* fix(doctor): defer updater repair transactions

* test(doctor): cover updater rollback ordering

* refactor(doctor): keep lifecycle lease type internal

* refactor(doctor): centralize repair rollback errors

* docs(doctor): tighten lease cleanup invariant

* refactor(doctor): return lease write promise directly

* fix: mark plugin repair rollback paths terminal

* test(plugins): reproduce hollow dependency package detection

* fix(plugins): require dependency package manifests for install health

* test(plugins): model a complete installed snapshot dependency

* test(plugins): reject successful npm installs with missing dependencies

* fix(plugins): reject incomplete managed npm dependencies before publication

* test(doctor): diagnose active npm dependency corruption

* test(doctor): create complete dependency-health fixture roots

* test(doctor): retain bundled ownership in dependency control

* fix(doctor): attribute missing dependencies to active npm roots

* fix(doctor): report missing required plugin dependencies

* test(doctor): cover dependency repair retention ownership and failures

* test(doctor): materialize successful updater replacement fixtures

* fix(doctor): repair incomplete dependencies through retained npm generations

* test(doctor): cover deferred dependency repair and cleanup failures

* fix(doctor): report dependency repairs deferred by package updates

* fix(doctor): retain visible outcomes for deferred dependency repairs

* style(plugins): keep managed npm dependency imports together

* style(plugins): format dependency status regression fixtures

* test(doctor): cover mixed dependency repair marker ownership

* test(plugins): preserve literal npm tags in singleton metadata

* test(plugins): keep malformed metadata fixtures as array values

* fix(plugins): honor literal tags in npm 12 view metadata

* fix(doctor): narrow optional dependency repair install record

* test(plugins): reject dependencies outside managed projects

* test(doctor): distinguish owned dependency hoists from ancestors

* test(plugins): cover bounded and generic dependency lookup

* test(plugins): compare project alias identity instead of spelling

* fix(plugins): bound managed dependency lookup to its owner

* fix(plugins): verify dependencies within the installed npm project

* fix(doctor): check dependencies against the recorded npm project

* refactor(doctor): isolate configured npm dependency health collection

* refactor(doctor): keep candidate discovery within its module budget

* refactor(doctor): settle marker cleanup before returning or throwing

* style(doctor): format the dependency health collector

* fix(plugins): make dependency boundary exit explicit

* test(doctor): cover stale runtime dependency repair collisions

* style(doctor): format dependency collision regressions

* test(plugins): preserve direct host links during managed installs

* test(plugins): inspect the returned update generation for host links

* test(doctor): preserve healthy canonical host dependencies

* test(doctor): initialize the host dependency fixture directory

* fix(plugins): audit canonical hosts in managed dependency checks

* fix(plugins): preserve audited hosts in staged npm installs

* fix(doctor): reuse canonical host dependency audit

* fix(doctor): await audited managed dependency health

* test(plugins): cover audited host and managed dependency boundaries

* test(plugins): inspect hollow dependencies in the npm stage

* fix(plugins): reject hollow installs and repair required dependencies

Share managed dependency admission with eligible same-version Doctor repair.
Preserve deferred transaction ownership, conditional index publication, and
current timeout forwarding through existing updater and lease owners.

Co-authored-by: nxmxbbd <32288+nxmxbbd@users.noreply.github.com>

* test(plugins): preserve hollow-install coverage within CI boundaries

* test(gateway): await private timeout registration settlement

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: nxmxbbd <32288+nxmxbbd@users.noreply.github.com>
2026-09-19 18:51:06 -06:00
Kimi Yu
7d7e26a0be
fix(agents): return attachments from remote workspaces (#152633) 2026-09-19 17:31:00 -07:00
Peter Steinberger
d22782a7f0
refactor(state): share the agent database worker lifecycle (#153150)
* refactor(state): share the agent database worker lifecycle

* fix(state): retain canonical worker identity during cleanup
2026-09-19 17:08:16 -07:00
Peter Steinberger
18f1c117e6
fix: resume unfinished tasks after Gateway restarts (#153243)
Recover interrupted parent turns regardless of subagent-result provenance. Settle interrupted children through normal completion and let the parent inspect retained state before continuing or replacing them. Remove automatic child relaunch and retry machinery, preserve existing receipt reconciliation, and fence cleanup against newer owners.
2026-09-19 17:07:32 -07:00
Peter Steinberger
8e7443e653
fix(codex): preserve delivery facts and native approval semantics (#151863)
* fix(codex): preserve delivery facts and native approval semantics

Keep failed sends from suppressing replies or recording false delivery. Share the host delivery facts before presentation middleware, preserve per-artifact media and finalized native text, and honor native approval lifetimes and explicit form answers.

Replace duplicate delivery and quota decisions with their existing owners. Document the seven shared SDK helpers and apply the approved seven-export and seven-callable surface budget increase.

* test(codex): align native fixtures with canonical outcomes

* test(codex): align mirrored transcript assertions

* fix(codex): retain core conversation delivery receipts
2026-09-19 16:45:20 -07:00
Peter Steinberger
0a3302711b
fix(macos): show About in native connection settings (#153184)
Open About beside Connection and Gateways without requiring a Gateway connection. Replace the obsolete menu-bar description with the current homepage tagline, retain build metadata and resource links, and add Copy Build Info.
2026-09-19 23:40:58 +00:00
Jason (Json)
97c7b35933
fix: complete Gateway upgrades after Node prefix changes (#145335)
Complete managed Gateway upgrades after Node prefix changes while preserving the verified service during preparation and recovering only owned failed activations.

Keep requester/executor and original/candidate ownership through native children; retain uncertain cleanup and original failure outcomes. Source and isolated native component checks are documented in the canonical PR. The wider first-hop installer and other platform journeys remain separate program work.

Closes #107930. Canonical PR history retains the original contributor commits; repository-supported squash preserves explicit contributor credit.

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-09-19 16:58:05 -06:00
Peter Steinberger
bfd1ce8be3
test: load compiler signal fixtures under both runtimes (#153170) 2026-09-19 15:45:42 -07:00
Peter Steinberger
9bae08c873
test: reuse expected CI planner inventories per host case (#153165) 2026-09-19 15:43:00 -07:00
Dallin Romney
91926f9b61
fix(release): repair 7.34 validation gates (#153190) 2026-09-19 15:26:30 -07:00
Peter Steinberger
a5fa4fee55
test(transcripts): await persisted Discord capture retirement (#153117) 2026-09-19 14:51:21 -07:00
Ben.Li
216998cac9
fix(install): fall back to portable Node after package manager failure (#134386)
Windows installations can now recover automatically when winget, Chocolatey, or Scoop fails or leaves an unsupported Node.js runtime. Guarded package-manager attempts warn and continue through the remaining methods to the existing elevation-free portable Node installer. Runtime validation still gates OpenClaw installation.

The installer remains the sole owner of runtime provisioning. Updated Windows documentation and regression coverage describe and protect failure fallthrough, successful recovery, and final refusal when no usable runtime can be provisioned.

Validation: all 99 exact-head checks completed without failures, including Windows installer CI and openclaw/ci-gate. The isolated Windows recovery trace exercised real portable download, extraction, PATH recovery, and runtime/SQLite validation after an injected Chocolatey failure. Codex review was scoped-clean; ClawSweeper reported no actionable findings or Rank-up moves.

Related: #133869
2026-09-19 14:51:05 -07:00
Peter Steinberger
e959b8f021
refactor: settle outbound acknowledgements in the SQLite worker (#152840)
* refactor: settle outbound acknowledgements in the SQLite worker

* test: route Twitch delivery through SQLite worker lane

* fix(ci): align status timeout fixture with shared auth

(cherry picked from commit 575eabe93d0e99d5a6ea74e2392e771dcfc9e478)

* test(codex): await durable checkpoint projection

(cherry picked from commit af8dd1b845)
2026-09-19 14:43:50 -07:00
Josh Lehman
cde6bbdcfe
feat(plugins): add decision models with per-agent selection (#152237)
* fix(plugins): preserve authored config through runtime load plans

* feat(judgments): add typed provider runtime and plugin SDK

* feat(plugins): add per-agent decision models

Add an opt-in decisionModel role for typed choices, scores, and boolean
probabilities, with global defaults and per-agent inheritance or disablement.
Keep provider lifecycle and prepared credentials host-owned, and expose
manifest-only decision choices separately from conversational model catalogs.

Adapt the provider foundation from #152237 to the decisions contract. Existing
configurations keep decision calls disabled until a model is selected.

Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>

* fix(plugins): complete decision inspection and preserve authored config

Expose optional decision-provider health through the Gateway wire schema
and generated native DTOs. Preserve the landed SecretRef prerequisite’s
identity behavior for unchanged activation plans. Move model mocks into
one private sibling factory without expanding the public helper surface.

Validation: 51 handler/protocol tests, 18 post-extraction tests, 52 runtime
and integration tests, generated protocol checks, and clean P0-P2 review.
The SDK surface-budget increase remains pending maintainer approval.

Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>

* perf(plugins): reduce decision overhead and unnecessary reloads

Keep one full provider input snapshot and an independent question rubric. Recognize decision-only catalog providers with the existing normalization policy, and reload plugins only for decision-model changes while preserving roster actions. Apply the approved SDK surface increment and behavior-neutral cleanup.

Validation: 58 runtime/config/loader tests, 610 Gateway regression/sibling tests plus 15 final catalog cases, full core typechecks, scoped lint and clean managed review. A 143155-attempt synthetic stress run settles all 18104 provider calls at max concurrency four.

* fix(plugins): preserve reload boundaries and decision test contracts

Materialize only present decision-selector leaves so Telegram account creation/removal retains its parent lifecycle action. Select UI controls by model role, preserve independent chat and decision catalogs in tests, remove an unused probe, and rebalance existing typecheck shards without raising their limits.

Validation: 588 reload tests, 58 shard/loader tests, 38 UI catalog tests, 9 browser tests, affected typechecks, unused-file scans, and clean managed review.

* test(ui): address model pickers by role in gateway flows

Disambiguate Primary from the new Decision picker in the real-Gateway catalog test, alias browser test, and Agents view assertions. Preserve draft and publication checks. Unit/browser/typecheck proof and managed review pass; real-Gateway execution follows on the integrated build.

* test(plugins): isolate runtime metadata and preserve shard headroom

Move the existing lazy-runtime metadata contract intact into its own focused module. Group CLI program tests with commands so newer main tests keep every typecheck shard within existing limits. No production changes or limit increases.

Validation: 57 tests, four typecheck graphs, canonical line guards against the CI main snapshot, targeted lint and clean managed review.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Josh Lehman <550978+jalehman@users.noreply.github.com>
2026-09-19 14:37:53 -07:00
Peter Steinberger
24518cf42b
refactor: simplify worker placement and node execution (#153019)
* refactor: simplify worker placement and node execution

* chore: retire worker inference line-limit exception

* fix: break worker type cycles and await fixture cleanup

* fix: preserve shipped plugin worker creation calls

* test: rebalance Gateway test type roots

Move worker environment tests into the existing Gateway server graph while preserving root coverage, shard limits, and compiler concurrency.
2026-09-19 14:33:43 -07:00
Peter Steinberger
a6b667ced3
fix(audit): keep queued persistence off the Gateway thread (#152745)
* fix(audit): keep queued persistence off the Gateway thread

* test(audit): route audit roots into state logging type shard
2026-09-19 14:33:25 -07:00
Peter Steinberger
a8c423006e
refactor: adopt fs-safe 0.16 and remove duplicate filesystem logic (#152972)
* refactor: reuse fs-safe 0.16 filesystem helpers

Upgrade core and plugin dependencies to the published release. Delegate missing-suffix probing and positional snapshot copying while retaining database identity policy, cache, durability, and cleanup ownership. Remove 333 production lines and document bounded alias diagnostics.

* fix: retain exact directory identities for fs-safe 0.16

Preserve bigint directory identity in updater handoffs, backup publication, and snapshot staging. Keep initial receipts through durability checks, retain published update-state compatibility, and share snapshot directory policy. Cover real publication phases and large filesystem IDs while documenting the released dependency declaration gap.

* test: record approved fs-safe receipt type exceptions

* test: rebalance Gateway type-check groups
2026-09-19 13:50:32 -07:00
Peter Steinberger
88004e9cc6
improve: keep project listings responsive during database reads (#152691)
* perf(projects): move durable listings to retained workers

* fix(ci): align status timeout fixture with shared auth
2026-09-19 13:44:35 -07:00
Peter Steinberger
5bc6dc8325
fix(tasks): keep the Gateway responsive during database contention (#152655)
* fix(tasks): keep agent event ingestion responsive during database contention

Persist ordered, coalesced task-event metadata through the existing shared-state
worker and canonical publication owner. Preserve exact counts, lifecycle and
identity fences, native overlap, joined shutdown, and notification ownership.
Recover confirmed commits after result or settlement failures without replay.

Record receipt-owned writes independently of projection-byte changes while
keeping canonical refreshes and unpersisted observations distinct. Registered
Gateway task reads retain their synchronous native wait boundary.

Validation: 352-test full sibling campaign before final publication refinements;
114 affected tests on the final behavior, final core/test type checks, targeted
lint, formatting, line caps, and clean managed review. Full changed checks and
build passed before the bounded publication-only/type-only delta. Synthetic
Node/macOS contention proof keeps event emission below 0.4 ms with exact counts.

* test(tasks): settle accepted events before restoring state

* fix(tasks): retain committed event targets before worker settlement

* style(infra): specify worker message transfer lists

* fix(tasks): prepare progress authority without blocking the event loop

* fix(tasks): finish asynchronous progress read integration
2026-09-19 13:43:07 -07:00
Peter Steinberger
2b27c55da6
fix(ci): run Gateway database-worker tests in parallel (#153144)
Retain the fork pool, non-isolated cleanup, exclusive CI plan, and worker ceiling. Share Gateway fixture port claims, retire file-local redaction state after teardown, and wait for actual fixture readiness.
2026-09-19 13:41:53 -07:00