Commit graph

1375 commits

Author SHA1 Message Date
Peter Steinberger
ee98dce3bc
fix(release): defer plugin npm visibility to parent verification (#152438)
* fix(release): preserve plugin publish success during registry lag

Record published, visibility pending only after accepted plugin npm publication in a full parent release. The parent retains final registry authority; standalone repairs and identity, byte, malformed-selector, and ahead-selector conflicts remain strict. Reuse selector classification and remove the duplicate bootstrap selector readback. Related: #152176.

* fix(release): bind final plugin readback to publication evidence

Verify consumed qualification and planning receipts at the parent, including retained attempts. Require actual registry tarball integrity and archive identity on fresh-parent resumes that skip already-published versions; retain exact artifact byte checks for publisher jobs.

* fix(release): preserve qualified readback across failed child retries

Reconcile retained failed publishers with a verified newer skip plan and require their exact successful qualification-upload step. Keep original artifact byte verification. Register the dynamic verifier entrypoint and its isolated test inventory for CI.
2026-09-19 02:32:05 -07:00
Peter Steinberger
9af9783779
fix(state): preserve leases through heartbeat handoffs (#152681)
Renew the live durable owner during worker startup and before capture drainage while preserving strict expiry, ownership fencing, and the existing startup cap. Detach native Worker construction from caller context and use the existing compiled runtime owners for retention proof.

Related: #152387. Its retained pressure evidence led to startup, capture-admission, and caller-retention regressions; the fixed three-copy campaign passed 30/30 for each target file.
2026-09-19 02:31:38 -07:00
Peter Steinberger
dcb4847e48
feat(release): check publication gates before dispatch (#152470)
* feat(release): check publication gates before dispatch

* fix(release): accept empty draft bodies in publish preflight

* fix(release): wire publish preflight command and shared gate proof

* fix(release): discover draft state and await committed archive proof

* fix(ci): preserve release metadata types and catalog test lifetime

* fix(release): reuse resume authority and settle UI test phases

* style(release): satisfy typed metadata and UI fixture lint
2026-09-19 01:41:43 -07:00
Peter Steinberger
707cbebac5
fix(release): resume from signed npm publisher attempts (#152616)
Keep the original successful publication attempt after later child reruns. Carry its identity through recovery, final verification, diagnostics and release evidence while retaining all original publication trust checks. Related: #152434.
2026-09-19 00:45:04 -07:00
Peter Steinberger
1d9292ee1c
fix(release): reclaim orphaned ClawHub publication children (#152432)
* fix(release): reclaim orphaned ClawHub publication children

* test(release): expect ClawHub child lifecycle coverage

The changed-target selector discovers the new child lifecycle test through its reference to the release publish workflow. Keep the strict expected target set in sync.

* fix(release): scope ClawHub recovery to the release tag

* fix(release): preserve independent ClawHub validation slots
2026-09-19 00:32:21 -07:00
Peter Steinberger
600657d528
refactor(state): move fixed-read snapshot coordination off the main thread (#151829)
* perf(fleet): run registry operations in SQLite workers

* fix(state): preserve readonly admission error context

* test(gateway): retain catalog root failure diagnostics

* fix: preserve uncertain lease outcomes before caller recovery

* fix(state): reject retired read scopes and retain wrapper imports

Reject new admissions to closing or closed selected read scopes while keeping already-admitted readers owned through cleanup. Preserve typed invalidation at plugin discovery boundaries.

Include the retained-read eager dependencies in the canonical PR wrapper inventory.

* test(state): require rejection of retired read scopes

Update the three existing disposable-scope variants to expect the canonical
admission error while preserving active and unrelated source assertions.

* fix(state): keep ordinary reads in the SQLite worker

Use the existing independent readonly worker for ordinary fixed reads while
retaining cached writer custody. Validate captured file identity around opens
and acceptance, and bind previously missing paths when their first file appears.

Keep selected snapshots and native preparation scopes with their existing owners.

* fix: catalog refresh fails when previous discovery finishes

Retain selected plugin registries through awaited preparation and hand construction claims to the completed generation. Preserve stale-publication cleanup and borrowed Gateway-root ownership. Related: #151588, #148290.

* fix(test): retain Telegram suite output on subprocess errors

* fix(ci): require full compact proof for worker policy guards (#151427)

Fix compact CI policy guards that confused a two-worker budget with a parallel-to-serial transition. Preserve inherited job ceilings on already-serial recipients and reject redundant group-policy rewrites.

Select the complete compact plan on Blacksmith and hybrid runs when the owning planner-policy test changes; keep GitHub targeting precise. Production admission-before-placement, worker limits, and measurements remain unchanged.

Validation: focused host-profile and policy cases, serial-policy negative controls, and exact-head CI run 35343663468 passed. ClawSweeper and the retained scoped review found no actionable defects. No user-visible runtime change.

* refactor(state): move fixed-read snapshot tokens off the main thread

* perf(gateway): materialize archived session rows on demand (#151574)

* fix: avoid host-speed failures in catalog performance checks (#151732)

Replace the catalog benchmark's host-dependent 20 ms median limit with 20 times an independent in-process CPU reference. Check every composed list for exactly 20 SQLite reads, including three binding-authority reads, and zero plugin-state worker operations, while preserving the existing native-RPC, file-I/O, and session-payload guards.

This is a test reliability repair with no runtime or update behavior change. Production changes: 0 lines; tests and test support: +61/-7 across two files.

Validation: exact-head CI is green; the reviewed proof includes five passing local runs, two-CPU Testbox and hosted calibration, an extra-SELECT negative control, and a uniform CPU slowdown that fails the independent timing guard. Round-2 Codex autoreview and exact-head ClawSweeper review found no actionable defects.

* test(gateway): match catalog read budget to binding owner

* test(codex): synchronize agent-end context scenarios

Own the fixture clock and wait for turn start and ten response progress
events before selecting completion, cancellation, or refusal. Keep the
five-second budget and require the expected terminal outcome.

Restore real timers before cancelling and joining the run so a failed
assertion cannot discard cleanup deadlines.

Validation: 62 agent-end, deadline, and lifecycle tests; extension test
types; scoped lint and format; independent P2 review. A temporary assertion
failure also verified cancellation, unsubscribe, and joined cleanup.

* test(state): intercept asynchronous snapshot preparation in lifecycle controls

* fix(sqlite): name scoped worker declaration return type
2026-09-18 23:54:58 -07:00
Peter Steinberger
21aab7137b
fix(memory): bind lease recovery to its original database (#152480)
* fix(memory): recover indexing after SQLite lease cleanup failures

* fix(bench): drain session owners before history measurements

* test(memory): observe active workspace leases before repair

* test(memory): preserve acquisition failure diagnostics
2026-09-18 23:37:00 -07:00
Peter Steinberger
ed2192d22d
fix(state): avoid host SQLite waits during async state operations (#152377)
* fix(state): move shared-state lifecycle custody off-thread

Acquire and release fresh required per-command lifecycle leases on the existing
executing SQLite worker. Keep actual parent-held delegation, FIFO reservations,
bounded transfers, lock budgets, and current transaction/commit authority.

Retain the per-job port through preparation refusals and result framing so native
host writers can service progress. Preserve complete outcomes through failed
coordinator cleanup, joining native exit before settlement and credit release.
Retire exact unavailable shared-state entries without making nested callbacks
wait for their own close. Never replay a mutation.

Token lifecycle coordinator calls drop from ten to zero; actual Gateway task
creation, unstarted settlement, and live-flow retry each drop from two to zero.
Storage APIs, schemas, retention, and remaining native owners stay unchanged.

Validation: 178 tests in 13 files, normal build, full changed-file gates, and
independent P0-P2 review. Final compiled Node 24.21.0 and Bun 1.4.2 token flows
record zero host calls across all 28 SQLite counters, including initialization,
with natural exit and unchanged runtime artifacts.

* fix(state): include lifecycle worker in wrapper source bundles

Native PR wrappers eagerly import the worker broker from their extracted source
inventory. Include its lifecycle preparation dependency so cold provisioning and
extracted package validation can load the complete import closure.

Replace the hook-relay test's retired coordinator SQL allowance with strict
caller-thread SQL and close-zero observation through path-specific cleanup.
Preserve every record persistence and ownership assertion.

Validation: 36 tests passed across three existing files, with one existing
platform skip; changed-file gates and independent P0-P2 review passed. Isolated
provisioning fixtures used an adequately sized APFS temp directory with the
existing capacity guard unchanged. Application runtime source is unchanged.

* fix(state): avoid idle cleanup waiting on active callbacks

Keep background inspection retirement with the existing idle-generation owner.
Use the existing broker operation with captured schema context, current admission,
and required lifecycle custody, without foreground completion cleanup that can
wait on an enclosing callback. Retain a healthy idle actor only while the broker
also records it as available.

Observe lifecycle custody in the executing canonical worker fixture and pause
failed inspection after its real admission boundary. Cover nested callback
recovery and a healthy result from an unavailable actor without changing the
one-minute inspection or thirty-minute healthy retirement policy.

Validation: 186 focused tests in 14 files, normal build, changed-file gates, and
independent P0-P2 review passed. Fresh compiled Node 24.21.0 and Bun 1.4.2 token
flows each record zero across all 28 host SQLite counters, with natural exit.
2026-09-18 23:34:21 -07:00
Peter Steinberger
c09841409e
fix(release): resume public GitHub release pages (#152435)
* fix(release): resume public GitHub release pages

Resume canonical public pages with incomplete evidence while preserving immutable asset identity and the later docs publication owner. Add explicitly requested activation before Docker with one approval, the existing finalizer, and unchanged latest policy.

* test(release): update guards for resumable publication

Include the optional early finalizer in publication dependency assertions and model its explicit false default. Keep failed-child evidence visible without claiming that a resumed public release is a draft.
2026-09-18 23:33:35 -07:00
Peter Steinberger
778973de1e
improve: speed up restricted session searches (#152503) 2026-09-18 23:32:05 -07:00
Peter Steinberger
f9d9f3dffe
fix: reduce large-fleet validation delays (#152378)
* fix: reduce fleet certification overhead and settle worker cleanup

Reuse bounded canonical workers for stores needing certification and an
integrity child within each maintenance lease. Preserve generation-bound
receipts, fresh admission, and native-close ownership.

Share alias snapshots and speech roster facts within synchronous scopes.
Record snapshot cleanup failures per database, join all failed retirement
attempts, and preserve integrity errors when timeout races native exit.

Follow-up to #151295 and the prepared-fleet fixes already on main.

* test: adapt maintenance admission to worker transports

* test: observe pooled Gateway startup certification
2026-09-18 23:21:13 -07:00
Peter Steinberger
dafedff126
fix(release): recover original npm publishers automatically (#152434)
* fix(release): recover original npm publishers automatically

* test(release): refresh npm resume workflow fixtures
2026-09-18 22:45:56 -07:00
Peter Steinberger
cd1b8cdfa5
fix(release): reuse existing Linux release requests (#152425) 2026-09-18 22:33:16 -07:00
Peter Steinberger
71e436920c
fix(linux): complete protected updater channel publication (#152408) 2026-09-18 21:40:03 -07:00
Peter Steinberger
196cdbbfab
refactor: move profile enumeration off the Gateway thread (#152005)
* refactor: move profile enumeration off the Gateway thread

* docs: keep profile enumeration notes clear of Fleet insertion

* fix: complete async profile enumeration caller cutover

* fix: expose newly assigned profile roles in warm readers

* fix(gateway): publish mention directories under current policy
2026-09-18 21:24:06 -07:00
Peter Steinberger
731324ec78
fix(state): name the originating refusal on blocked migration receipts (#152335)
Preserve the originating step id, refusal code, and message in blocked execution receipts. Keep migration execution and update behavior unchanged.

Investigated after main CI run 35403665608; this closes the receipt diagnostic gap without claiming to fix the original intermittent failure.
2026-09-18 20:38:07 -07:00
Peter Steinberger
215f1c6e2a
improve(state): keep healthy databases open for 30 idle minutes (#152341)
* perf(state): retain healthy database workers for 30 idle minutes

* fix(state): satisfy idle worker validation gates

* fix(tooling): retain WAL split-brain helper in PR wrapper
2026-09-18 19:53:55 -07:00
Peter Steinberger
a5918b0875
fix(matrix): avoid credential reads in approval checks (#152246) 2026-09-18 19:34:09 -07:00
Peter Steinberger
b9940f3bd0
fix(node-host): avoid blocking configuration reads (#151411)
Connection, runner startup, and node-only status awaited configuration loaders that still performed SQLite queries on the calling thread. Delegate both loaders to the existing shared-state read worker through a fixed nodeHost.config command and the canonical metadata query kernel.

Preserve missing-store noncreation, JSON and timestamp validation, retired-file refusal, captured state-root identity, existing-schema admission, drift refusal without repair, and joined cleanup. Derive reply rows from the generated database schema to avoid a type-import cycle. Configuration replacement retains its existing synchronous transaction.

Validation: 38 focused configuration and reader tests, core/test types, architecture checks, formatting, normal builds, and scoped review passed. Fully compiled Node and Bun proof each recorded zero parent SQL across 17 required read and cleanup stages, including fresh/cached managed-schema reads and drift refusal. Exact-head CI and the required aggregate gate passed after a documented retry of one idle, unassigned shard. Bootstrap, explicit snapshot preparation, configuration writes, live operator state, and stalled-child testing are outside the zero-SQL claim.
2026-09-18 18:34:56 -07:00
Peter Steinberger
732f5fe0a7
fix(release): accept waived advisory performance evidence for stable publication (#152290) 2026-09-18 17:34:52 -07:00
Peter Steinberger
4d62efeccf
feat: open Crabbox apps beside the conversation (#152094)
* feat: open Crabbox apps beside the conversation

Attach temporary cloud environments without moving the session's primary workspace. Reuse private node transports for managed app processes, CUA, desktop observation, and web portals; let screen open the exact preview in the requesting browser. Preserve conversation lifecycle authority, one-shot command approvals, manual desktop control, and cleanup across reconnects.

* feat: show Crabbox startup before provisioning

* test: type Crabbox desktop startup fixture

* refactor: isolate worker environment summaries

* refactor: make partial computer action dispatch explicit

* fix: complete Crabbox preview integration

* test: rebalance agent runtime typecheck roots

* fix: preserve desktop control when showing its source again

* fix: fence Crabbox allocation at provider commands

* test(crabbox): move allocation authority proof to plugin owner

* fix(crabbox): keep allocation authority type internal

* test: fix preview validation assertions

* test(ui): exercise inventory recovery after reopening

* build: regenerate Workboard assets after main refresh
2026-09-18 17:12:51 -07:00
Peter Steinberger
c9584688c4
perf(sessions): move automatic maintenance database work to workers (#148630)
* perf(sessions): run automatic maintenance planning in workers

* fix(sessions): preserve maintenance admission and fixture lifetimes

* test(sessions): drain fixtures and scope maintenance observations

* test(sessions): align maintenance proof and suite teardown owners

* test(sessions): preserve maintenance commit ownership in timer fixture

* test(gateway): commit access changes before scan assertions

* test(gateway): preserve typed access mutation failures

* test(sessions): join pending history budget sweeps

* test(sessions): keep budget reset replacement live

* test(sessions): drain branch fixtures before removing roots

* test(codex): preserve native notification order in terminal fixtures

* refactor: extract maintenance publication and settled-turn test owners

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-19 08:06:58 +08:00
Peter Steinberger
119f485113
fix(update): reconcile completed updates after interrupted verification (#152202)
A completed update could later appear as failed/abandoned when its updater exited during restarted-Gateway verification, despite the target build serving successfully.

Record the installed candidate identity before post-core handoff and let the shared update-ledger reconciliation owner verify installed and serving builds before settling the latest interrupted run. Gateway monitoring and Doctor reuse the same owner. Preserve active or unobservable drivers, newer runs, repair/rollback evidence, and legacy rows without a receipt; recheck authority and row identity inside the transaction. Report verified completion with an interruption warning and explain unresolved older abandonment in Doctor.

The receipt uses existing ledger steps, without schema, configuration, CLI, or dependency changes. Keep after.version empty until serving verification to preserve released rollback behavior.

Validation: 135 focused regressions, full changed-file checks, and published 2026.9.4 updater-to-candidate proof on isolated systemd services. SIGINT and SIGHUP during verification changed from abandoned failures to successful settlement after 10.701 and 11.835 seconds. Recorded Codex review was scoped-clean; ClawSweeper found no actionable patch defect.
2026-09-18 16:24:10 -07:00
RoboClaw
f85c70d38f
docs: clarify WebChat commentary attachment compatibility (#152225)
* docs: clarify WebChat commentary attachment compatibility

Distinguish committed model-authored commentary in automatic mode from message-tool-only delivery and structured tool, plugin, and block payloads. Preserve the existing parsing and authorization boundaries.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* docs: clarify WebChat commentary attachment compatibility

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: eda64cf1-fc69-4526-aa06-c252f1f89025

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-18 16:20:06 -07:00
Galin Iliev
4269cd4e1a
fix: keep gateway responsive during sqlite recovery load (#151581)
* fix(sqlite): recover pinned WAL readers

Track active SQLite readers, retire unsettled or idle shared-state workers, and back off requester settlement after persistence failures.

Copilot-Session: 0bc14f4b-69ca-44ef-8873-2c4e64b9534f

* fix(sqlite): bound live snapshot and recovery load

Copilot-Session: 0bc14f4b-69ca-44ef-8873-2c4e64b9534f

* fix(sqlite): avoid raw copies for live fallback

Copilot-Session: 0bc14f4b-69ca-44ef-8873-2c4e64b9534f

* fix(sqlite): preserve snapshot and recovery settlement

Copilot-Session: 0bc14f4b-69ca-44ef-8873-2c4e64b9534f

* fix(sqlite): preserve diagnostic source artifacts

Copilot-Session: 0bc14f4b-69ca-44ef-8873-2c4e64b9534f

* fix(sqlite): finish cancellation and legacy cleanup ownership

Join cleanup before the last standalone snapshot caller returns, and avoid terminal observation without a recovery capacity lease. Preserve the full legacy grace period for nested snapshots.

Restore the extracted wrapper runtime closure and migrate scheduling, recovery, and timer fixtures to the integrated owners without weakening cleanup, admission, or resource assertions.

Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: galiniliev <5711535+galiniliev@users.noreply.github.com>

---------

Co-authored-by: jalehman <550978+jalehman@users.noreply.github.com>
Co-authored-by: galiniliev <5711535+galiniliev@users.noreply.github.com>
Copilot-Session: 0bc14f4b-69ca-44ef-8873-2c4e64b9534f
2026-09-18 16:00:26 -07:00
Peter Steinberger
ee1e5f21fd
fix(release): allow stable npm bootstrap under an operator soak waiver (#152206) 2026-09-18 15:53:07 -07:00
Peter Steinberger
6487c6e6f3
perf(browser): move dashboard event discovery to SQLite worker (#151952)
* perf(browser): move dashboard event discovery to SQLite worker

Keep board-change and deleted-session discovery off the Gateway thread through the existing keyed-store worker. Drain accepted discovery and reconciliation before service stop or restart, and discard late results from replaced runtimes. Preserve the canonical namespace and final browser-close authority.

* test(browser): align worker batch expectations
2026-09-18 15:43:09 -07:00
Dallin Romney
dde76b50e5
fix(release): reject incomplete legacy npm install trees (#152186)
* fix(release): reject incomplete legacy npm install trees

* test(release): include shrinkwrap guard in workflow fixtures
2026-09-18 22:40:23 +00:00
Peter Steinberger
f64c4e9256
fix(sqlite): service worker admission through retained path aliases (#152190)
Register the shared worker's already-admitted raw and canonical database paths with its grant service. Native handles can report a canonical pathname even when the caller opened a symlinked state directory; the service must remain reachable while a synchronous writer waits on the worker's transaction.

Keep current authority, the five-second admission budget, FIFO, and settlement ownership unchanged. Add real-worker forced-order regressions for successful renewal and revoked authority through an explicit directory alias, and document the retained identity boundary.
2026-09-18 15:32:22 -07:00
Peter Steinberger
6d7144de35
fix(gateway): avoid event-loop stalls during device-token storage (#151926)
* fix(gateway): avoid event-loop stalls during device-token storage

* fix: prevent shared-state writes timing out behind native writers

* fix(clickclack): finish SQLite cleanup between persistence tests

* test: bind shared-state admission probes to real instances

* test(gateway): align cron build admission with worker owner
2026-09-18 14:53:26 -07:00
Peter Steinberger
8a3d30de7d
fix: prevent large-fleet Gateway startup failures and stalls (#151805)
Large agent fleets could fail before the Gateway bound HTTP because SQLite workers competed for lifecycle custody. Unchanged stores, plugin metadata, and model catalogs also repeated startup preparation for each agent or workspace.

Keep canonical and transcript workers under the parent lifecycle owner through settlement, reuse prepared schema and metadata facts, and persist generation-bound canonical certification through the existing database validation owner. Certified unchanged stores stay read-only; changed, replaced, or revoked stores retain recertification, physical integrity checks, and current write authority. Empty stores now finish certification so the first agent request can proceed.

Historical isolated 632-agent proof reached readiness in 380 seconds cold and 131 seconds warm, where both control boots failed before bind. Matched hosted-class first-agent runtime proof passed 5/5 candidate and 5/5 control runs. The final reviewed head passed all 158 CI jobs (144 successful, 14 skipped), with 25 changed suites / 252 tests and check:changed passing.

The nullable canonical_ready receipt keeps the existing schema version and records derived certification only. Candidate-side tests cover additive installation, first-transaction rollback, and older-shape compatibility. Receipt-specific published-updater activation and backup-restoration proof are not included in this landing; the runtime and fleet measurements retain their documented historical pins.

Thanks to @609NFT for the detailed fleet description, startup traces, and repeated production measurements.

Related: #148529, #149538, #151074, #151295.
2026-09-18 14:43:19 -07:00
Peter Steinberger
bc9e86ff94
fix: prevent shared-state writes timing out behind native writers (#152050)
* fix: prevent shared-state writes timing out behind native writers

* fix(clickclack): finish SQLite cleanup between persistence tests

* test: bind shared-state admission probes to real instances
2026-09-18 14:39:04 -07:00
Peter Steinberger
1abf60d28c
fix(scripts): prevent host tooling drift from blocking PR workflows (#152078)
* fix(scripts): resolve pr tooling from a configurable root and preflight host git

* fix(scripts): preserve PR tooling contracts in dependency checks and fixtures

* test(scripts): match cross-checkout PR identity diagnostics

* fix(scripts): preserve GitHub CLI host selection for PR reads

* test(scripts): inject remote base drift at hosted verification
2026-09-18 14:34:18 -07:00
Shakker
d5b46dfea5
feat: recover abandoned Crabbox source staging (#152006)
Add local inspection and recovery of abandoned Crabbox source capsules after verifying writer settlement, native claims, retained source, and diagnostics.
2026-09-18 22:11:31 +01:00
Peter Steinberger
91603c27c3
fix: await initial task persistence before Gateway activation (#151634)
* fix(tasks): retain delayed flow repairs through cleanup

Move live flow retries and projection snapshots onto the shared task-domain
worker while retaining transaction-time live selection and lifecycle custody.
Join failed projection reads before releasing Gateway work, and give durable
retry timers their own async cleanup scope when they fire.

Preserve immediate synchronous compatibility, full-row compound writer checks,
and the existing retry schedule. No schema or retention changes.

* fix(tasks): avoid redundant mirrored-flow snapshot reads

Let the canonical write transaction classify dirty mirrored-flow targets
without first refreshing the full projection. Preserve clean missing and
managed no-entry behavior and use the existing getter on failure to retain
current failure metadata. Keep unrelated dirty obligations and query budgets.

* fix(test): remove duplicate Codex attempt inventory entries

* test(ci): distinguish retained job worker caps

* fix(test): preserve under-cap syntax repairs in validation

* refactor(tasks): share creation and transition operations

* fix: publish acknowledged managed task receipts

* fix: await initial task persistence before Gateway activation
2026-09-18 12:50:31 -07:00
Peter Steinberger
33c350a17c
fix(matrix): keep startup storage SQLite off the Gateway thread (#151994)
Related: #151845

## What Problem This Solves

Matrix client startup still runs storage-root selection, initial metadata, and legacy crypto imports through SQLite on the Gateway thread.

## User Impact

These startup operations now use the existing SQLite worker while preserving token-rotation selection, device identity, saved sync state, and migration recovery. Device backfill remains nonblocking at startup, and shutdown joins its admitted writes. No configuration, schema, or minimum host-version change is required.

Credential-readiness and package auth-presence probes retain their synchronous SDK contracts.

## Why This Change Was Made

The client factory awaits root selection, migration, and metadata before returning a client. Metadata comparisons preserve concurrent token claims and learned device IDs. The existing monitor task runner owns backfill cancellation and settlement, including disposal of its temporary identity client. Backfill rechecks credential lineage before publishing credentials after metadata persistence.

Claimed canonical roots still skip token-history scans. Rotated tokens reuse only active roots with matching devices; archived roots stay excluded. Imports still finish before archival, and interrupted archival preserves completed imports and unrelated files. Hosts without comparison support retain the named native compatibility path; a worker failure never selects it.

## Evidence

- The real client factory restored the seeded cursor but recorded 501 host SQLite `prepare` calls for a canonical root and 516 for token rotation before this change.
- Candidate factory tests record zero host `prepare`, `exec`, `get`, `all`, `run`, or `iterate` calls for canonical roots, rotated roots, and legacy crypto imports.
- Focused storage, Doctor, client factory, auth, startup verification, thread-binding, and monitor tests passed. Race tests cover initialization and token claims against a concurrently learned device, with explicit device inputs remaining authoritative. Other cases cover capability selection, worker failure, stale or cancelled backfill, and retirement settlement.
- Actual SDK HTTP fixtures on loopback verify that retirement closes an in-flight identity request and that token-only login disposes its identity client before returning. Request and cleanup failures remain available together.
- `pnpm build`, the changed-scope gate (including production/test typechecks and full extension lint), and the isolated built Matrix import profile passed. Fresh independent review found no actionable P0–P2 issues.
- No external Matrix account or live Gateway was used.
2026-09-18 11:54:22 -07:00
Peter Steinberger
513f94878d
fix(scripts): explain merge aborts and invalid review fields (#151996) 2026-09-18 11:35:37 -07:00
Peter Steinberger
af7834887a
fix(clickclack): drain discussion opens before shutdown (#151978)
Move pending discussion generation reads and mutations to the shared SQLite worker, preserving FIFO and conditional replacement checks. Recheck live creation authority after persistence waits and join accepted operations through recovery and timer reassessment before service retirement.

Retain the declared 2026.9.4 host compatibility path only when comparison capabilities are absent. Stored formats, limits, retention, bindings, revocations, and synchronous visibility remain unchanged.
2026-09-18 10:41:46 -07:00
Peter Steinberger
234e9e0c37
fix: publish acknowledged managed task receipts (#151590)
* fix(tasks): retain delayed flow repairs through cleanup

Move live flow retries and projection snapshots onto the shared task-domain
worker while retaining transaction-time live selection and lifecycle custody.
Join failed projection reads before releasing Gateway work, and give durable
retry timers their own async cleanup scope when they fire.

Preserve immediate synchronous compatibility, full-row compound writer checks,
and the existing retry schedule. No schema or retention changes.

* fix(tasks): avoid redundant mirrored-flow snapshot reads

Let the canonical write transaction classify dirty mirrored-flow targets
without first refreshing the full projection. Preserve clean missing and
managed no-entry behavior and use the existing getter on failure to retain
current failure metadata. Keep unrelated dirty obligations and query budgets.

* fix(test): remove duplicate Codex attempt inventory entries

* test(ci): distinguish retained job worker caps

* fix(test): preserve under-cap syntax repairs in validation

* refactor(tasks): share creation and transition operations

* fix: publish acknowledged managed task receipts

* test(gateway): match catalog read budget to binding owner
2026-09-18 09:59:08 -07:00
Shakker
9930cf44a7
fix: finish Crabbox wrapper cancellation cleanup (#151862)
Finish supported Crabbox wrapper cancellation before restoring retained lease ownership, preserving diagnostics, and removing disposable source.

Fixes https://github.com/openclaw/openclaw/issues/151804.
2026-09-18 17:38:42 +01:00
Peter Steinberger
a7d62b621a
perf(fleet): run registry operations in SQLite workers (#148290)
* perf(fleet): run registry operations in SQLite workers

* fix(state): preserve readonly admission error context

* test(gateway): retain catalog root failure diagnostics

* fix: preserve uncertain lease outcomes before caller recovery

* fix(state): reject retired read scopes and retain wrapper imports

Reject new admissions to closing or closed selected read scopes while keeping already-admitted readers owned through cleanup. Preserve typed invalidation at plugin discovery boundaries.

Include the retained-read eager dependencies in the canonical PR wrapper inventory.

* test(state): require rejection of retired read scopes

Update the three existing disposable-scope variants to expect the canonical
admission error while preserving active and unrelated source assertions.

* fix(state): keep ordinary reads in the SQLite worker

Use the existing independent readonly worker for ordinary fixed reads while
retaining cached writer custody. Validate captured file identity around opens
and acceptance, and bind previously missing paths when their first file appears.

Keep selected snapshots and native preparation scopes with their existing owners.

* fix: catalog refresh fails when previous discovery finishes

Retain selected plugin registries through awaited preparation and hand construction claims to the completed generation. Preserve stale-publication cleanup and borrowed Gateway-root ownership. Related: #151588, #148290.

* fix(test): retain Telegram suite output on subprocess errors

* fix(ci): require full compact proof for worker policy guards (#151427)

Fix compact CI policy guards that confused a two-worker budget with a parallel-to-serial transition. Preserve inherited job ceilings on already-serial recipients and reject redundant group-policy rewrites.

Select the complete compact plan on Blacksmith and hybrid runs when the owning planner-policy test changes; keep GitHub targeting precise. Production admission-before-placement, worker limits, and measurements remain unchanged.

Validation: focused host-profile and policy cases, serial-policy negative controls, and exact-head CI run 35343663468 passed. ClawSweeper and the retained scoped review found no actionable defects. No user-visible runtime change.

* perf(gateway): materialize archived session rows on demand (#151574)

* fix: avoid host-speed failures in catalog performance checks (#151732)

Replace the catalog benchmark's host-dependent 20 ms median limit with 20 times an independent in-process CPU reference. Check every composed list for exactly 20 SQLite reads, including three binding-authority reads, and zero plugin-state worker operations, while preserving the existing native-RPC, file-I/O, and session-payload guards.

This is a test reliability repair with no runtime or update behavior change. Production changes: 0 lines; tests and test support: +61/-7 across two files.

Validation: exact-head CI is green; the reviewed proof includes five passing local runs, two-CPU Testbox and hosted calibration, an extra-SELECT negative control, and a uniform CPU slowdown that fails the independent timing guard. Round-2 Codex autoreview and exact-head ClawSweeper review found no actionable defects.

* test(gateway): match catalog read budget to binding owner

* test(codex): synchronize agent-end context scenarios

Own the fixture clock and wait for turn start and ten response progress
events before selecting completion, cancellation, or refusal. Keep the
five-second budget and require the expected terminal outcome.

Restore real timers before cancelling and joining the run so a failed
assertion cannot discard cleanup deadlines.

Validation: 62 agent-end, deadline, and lifecycle tests; extension test
types; scoped lint and format; independent P2 review. A temporary assertion
failure also verified cancellation, unsubscribe, and joined cleanup.

* docs(state): reconcile Fleet and auth read contracts
2026-09-18 09:35:25 -07:00
Peter Steinberger
3bedfb0ecd
refactor(sessions): move watched upstream discovery off the Gateway thread (#151731)
* refactor(sessions): move watched upstream discovery to worker

* test(sessions): run descendant monitor proof with host broker

* fix(ci): require full compact proof for worker policy guards (#151427)

Fix compact CI policy guards that confused a two-worker budget with a parallel-to-serial transition. Preserve inherited job ceilings on already-serial recipients and reject redundant group-policy rewrites.

Select the complete compact plan on Blacksmith and hybrid runs when the owning planner-policy test changes; keep GitHub targeting precise. Production admission-before-placement, worker limits, and measurements remain unchanged.

Validation: focused host-profile and policy cases, serial-policy negative controls, and exact-head CI run 35343663468 passed. ClawSweeper and the retained scoped review found no actionable defects. No user-visible runtime change.

* perf(gateway): materialize archived session rows on demand (#151574)

* test(gateway): match catalog read budget to binding owner

* test(codex): control plugin refresh handoff clock
2026-09-18 09:04:08 -07:00
Peter Steinberger
135f934db6
refactor(transcripts): run stored lookups in the shared SQLite worker (#146547)
Related: #144592
Related: #147375
Related: #147246
Dependency: #151816

## What Problem This Solves

Stored transcript detail and note lookups return promises but still execute SQLite on the Gateway event loop.

## User Impact

Transcript identity, descriptor, note, summary, and utterance lookups execute in the shared SQLite worker. Existing selectors, content, ordering, limits, and error responses are preserved. No schema migration or configuration change is required.

Chronological list queries and streaming/export snapshots retain their current owners. Capture appends are a separate stacked change in #151760.

## Why This Change Was Made

Eleven typed commands call the existing read kernels through the canonical shared-state worker. Compound enumeration, matching, and library reads keep one deferred snapshot. First-use schema creation finishes before those reads, canonical close drains accepted work, and existing-only task inspection stays non-creating. Meeting fixtures stop producers before asynchronous database cleanup, and canonical test routing keeps worker consumers in their owning processes.

The composition preserves Doctor's device-token dispatch alongside all eleven transcript commands, shared transaction-settlement checks, plugin-reload ownership, and current test-routing changes. Chronological reads preserve their parent-timezone date function; exports preserve their snapshot lifetime.

Qualified dependency history from #151816 is incorporated through normal merge ancestry. It pins the deprecated message facade at its published exports, aligns three global surface limits with the resulting smaller counts, and carries the canonical catalog-materialization prerequisite with its strict 18-read assertion. The per-entry SDK compatibility limit remains unchanged. This does not claim that dependency PR #151816 has merged.

## Evidence

The current catalog carry passed a fresh normal production build in 319.083 seconds and all five real transcript/Doctor SQLite worker controls in 21.595 seconds. Fresh independent P2 review found no actionable issues. These checks cover the changed Gateway and shared-worker import closures. All 58 non-doc meeting feature files, including the combined Doctor/transcript dispatcher, remain byte-identical to `6b3c5acb8634`; storage docs only gain the qualified upstream task paragraph.

The SDK owner's strict catalog control and 25 archived-list/backfill controls are reused for matching owner inputs. The strict assertion retains three binding-authority checks and zero plugin-state worker operations while accounting for 18 SQLite reads after canonical materialization changes. The shared worker composition is separately covered by the five fresh controls above.

Retained compiled child CLI/Gateway proof belongs to the earlier captured-main `6c6dc44250` composition: the test body passed in 21.539 seconds under its unchanged 180-second bound, with 404.282 seconds for the supported wrapper and private-QA build. It checks canonical SQLite state, delegated missing-session cleanup while the isolated Gateway stays alive, transcript list/show/path commands, and exported bytes. This compiled scenario was not rerun on the latest catalog carry.

The preceding combined 62-file gate passed in 966.651 seconds, including production/test types, SDK/storage boundaries, formatting, lint, and three unused-export scans with zero findings. Six SDK facade tests and independent P2 review passed. The subsequent exact three SDK ratchet decreases passed all ten existing reporter tests, the canonical surface check, the changed-script gate, and fresh P2 review. Earlier reload and routing controls remain attributed to their qualified inputs.

CI at `6b3c5acb8634` completed with 140 successful jobs, 14 skipped, and one substantive failure plus its aggregate gate: the shared catalog benchmark expected 20 reads but the CI main composition performed 18. That matched the SDK owner's independently reproduced prerequisite issue. This carry includes its qualified canonical prerequisite and strict assertion correction; strict equality, authority-count, and zero-I/O checks remain intact, with unchanged deadlines. The new head requires its own hosted CI before landing.
2026-09-18 08:52:29 -07:00
Peter Steinberger
3a2dbb6f03
fix(matrix): keep sync-cache SQLite off the Gateway thread (#151845)
## What Problem This Solves

Matrix sync-cache restore, persistence, and deletion run SQLite on the Gateway thread even though the cache methods return promises.

## User Impact

These cache operations now run in the existing SQLite worker while preserving restart replay, clean-shutdown markers, and failure reporting. No configuration, schema, or minimum host-version change is required.

Matrix credentials, storage-root selection, and initial storage metadata remain separate work; this does not move every Matrix database operation off-thread.

## Why This Change Was Made

The client factory awaits the loaded cache before publishing the client, so the monitor's pre-start replay decision sees the persisted cursor. The live cache reuses the async keyed-store operations and chunk writer. A storage-root queue keeps a reader's generation intact until its chunk reads finish, while the client still owns debounce, flush, deletion, and quiescence. The obsolete synchronous cache helpers are removed, and QA Lab uses the same prepared-store path.

## Evidence

- The original cold-load/persist/restore/delete regression recorded 2,128 host SQLite `prepare` calls. The migrated flow records zero host `prepare`, `exec`, `get`, `all`, `run`, or `iterate` calls.
- A two-store regression reproduces a lost cursor when a writer removes chunks while another reader is paused after reading metadata; the storage-root queue preserves the reader's generation.
- 79 focused tests passed, including real `matrix-js-sdk` sync/crypto behavior against synthetic HTTP fixtures, published-schema Doctor repair, storage migration, and QA Lab. Final adjustments were rechecked with 26 cache/factory/SDK tests and 18 shutdown cases.
- `pnpm build`, the changed-scope gate, extension production/test typechecks, and `git diff --check` passed. The gate reported only a nonblocking max-lines warning in an untouched memory-manager file.
- No external Matrix account or live Gateway was used.
- Fresh independent review of the exact final diff found no actionable P0–P2 issues.
- Initial CI failed on the shared catalog test expecting 20 SQLite reads while observing 18. The follow-up reuses the canonical strict 18-read correction, qualified locally with 3 binding-authority reads and zero worker operations per list; all zero-I/O checks and the CPU bound remain intact. Matrix runtime code is unchanged.
2026-09-18 08:41:56 -07:00
Peter Steinberger
d41099ad9d
fix(release): allow an explicit operator soak waiver for stable publication (#151880) 2026-09-18 08:17:11 -07:00
Peter Steinberger
1d4202ddbc
refactor(auth): prepare runtime profile reads asynchronously (#149309)
Runtime model preparation now awaits isolated authentication-profile reads, avoiding synchronous SQLite work on the Gateway event loop and competition with memory's agent-database writer. Relocated shared credentials and personal accounts retain the existing shared-state owner; synchronous SDK readers and credential writes remain compatible.

The readonly child and synchronous reader share a narrow JSON inspection kernel. Auth reads keep captured admission through native cleanup, carry complete rows in framed IPC, and preserve selected-owner errors and recorded inherited-source refusal. Canonical consolidated snapshots remain supported by one protocol parser.

Validation: 153 focused Auth, readonly-worker, consolidated-state/preflight and catalog tests; core types; independent P0–P2 review; normal build; compiled Node and Bun probes returning the complete 10.8 MB envelope without changing database bytes. Exact-head CI passed 142 jobs with 14 skips, including the required gate: https://github.com/openclaw/openclaw/actions/runs/35353298957.

Inherited planner and catalog-count assertions were reproduced and reconciled with canonical source. Live provider sign-in was not exercised. No operator migration is required.
2026-09-18 07:56:22 -07:00
Peter Steinberger
5e0fba7b86
fix(test): retain Node for Node-owned tooling under Bun (#151772)
* fix(test): keep script erasability checks on Node

* test(tooling): preserve workflow Node heredoc ownership
2026-09-18 07:53:41 -07:00
Peter Steinberger
e56c3725ac
refactor(tasks): share creation and lifecycle transitions (#151454)
* fix(tasks): retain delayed flow repairs through cleanup

Move live flow retries and projection snapshots onto the shared task-domain
worker while retaining transaction-time live selection and lifecycle custody.
Join failed projection reads before releasing Gateway work, and give durable
retry timers their own async cleanup scope when they fire.

Preserve immediate synchronous compatibility, full-row compound writer checks,
and the existing retry schedule. No schema or retention changes.

* fix(tasks): avoid redundant mirrored-flow snapshot reads

Let the canonical write transaction classify dirty mirrored-flow targets
without first refreshing the full projection. Preserve clean missing and
managed no-entry behavior and use the existing getter on failure to retain
current failure metadata. Keep unrelated dirty obligations and query budgets.

* fix(test): remove duplicate Codex attempt inventory entries

* test(ci): distinguish retained job worker caps

* fix(test): preserve under-cap syntax repairs in validation

* refactor(tasks): share creation and transition operations
2026-09-18 05:55:36 -07:00
Peter Steinberger
488ff7c486
refactor(doctor): offload local device-token inventory (#151305)
* refactor(doctor): offload local device-token inventory

Run the diagnostic token-list operation in the existing shared-state worker. Preserve lint snapshot ownership, legacy checks, row ordering, malformed-row omission, and best-effort findings. Leave identity, pairing, and client token operations with their current owners.

* fix(test): remove duplicate Codex attempt inventory entries

* test(ci): preserve effective worker policy assertions

* test(ci): distinguish retained job worker caps

* test(ci): distinguish retained job worker caps

* fix(test): preserve under-cap syntax repairs in validation

* fix: restore Telegram QA helper contracts

* fix(test): retain Telegram suite output on subprocess errors
2026-09-18 05:13:49 -07:00
Peter Steinberger
d314668148
fix: keep historical state repairs in Doctor (#151418)
* fix: keep historical state repairs in Doctor

* fix: narrow added state column names before recording them

* fix: preserve Doctor repair ownership and prove retained history upgrades

* test: match native SQLite locations in ownership race proof

* test: distinguish published updater cron-history repairs
2026-09-18 01:31:24 -07:00