Distinguish missing or active CI from failed CI. Keep the required combined status pending without failing the waiting review job, and fail visibly on approval, CI, metadata, or evaluation errors. Preserve workflow, head, attempt, and authority checks.
The r: support auto-response links to
/help/faq#im-stuck-whats-the-fastest-way-to-get-unstuck. That anchor does
not exist on /help/faq and did not before the FAQ split — the content moved
to the first-run FAQ in an earlier split, and the id changed spelling at the
same time. Anyone closed with this label has been sent to a page that scrolls
nowhere.
The live target is /help/faq-first-run#i-am-stuck-fastest-way-to-get-unstuck,
which the first-run FAQ index publishes as an authored stub.
docs-link-audit does not cover this because the URL lives in a script rather
than a docs page.
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures
Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.
Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.
* fix(scripts): keep guarded portable scripts bash 3.2 compatible
* fix(scripts): keep macOS Bash CI coverage green
Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.
Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.
* docs(install): use system Bash in install and recovery commands
Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.
Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.
* fix(scripts): preserve streamed installs and CI packing
Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.
Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.
Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
* fix(ci): labeler no longer fails when a PR already has 100 labels
PR #137637 taught the size-label step to tolerate GitHub's HTTP 422
"Issues cannot have more than 100 labels", but every other label-adding
step still threw it. On the 2026.9.1 closeout PR #137506 the maintainer
author-role step failed that way and turned the cosmetic Labeler check red.
Move the cap handling into one owner, scripts/github/labeler-label-cap.mjs,
and route all eight addLabels sites across the label, label-issues, and
backfill-pr-labels jobs through it: warn naming the skipped label, succeed,
rethrow anything else. Each job checks out the trusted base commit
(ref: github.sha, persist-credentials: false) like auto-response.yml so the
github-script steps can import the module; no PR code runs. Delete the size
step's pre-count guard so the 422 is the single canonical cap path.
Rename test/scripts/labeler-size-label.test.ts to labeler-label-cap.test.ts;
it executes the real step scripts with the real helper and adds maintainer
step cap coverage plus a workflow-wide invariant that no script calls
issues.addLabels directly.
* test(ci): cover labeler cap helper return value and keep knip aware of it
The knip full-tree unused-file scan flagged scripts/github/labeler-label-cap.mjs
because only the workflow loads it dynamically. Import it from its owner test,
like every other scripts/github module, with a case for the boolean result the
backfill job's label bookkeeping depends on.
Respect draft conversions observed by the final PR revalidation before closing and reopening to re-fire CI. Record the existing changed-during-sweep skip without spending the re-fire budget.
Cover missing-CI and startup-failure-only candidates with exact final-snapshot regressions; eligible non-draft behavior is unchanged.
Honor Peter Steinberger's 2026-09-03 operator decision to let macOS and
Windows work proceed in parallel with or after npm publication. Record
advisory cross-OS conclusions without turning them into release blockers,
and permit all-group selectors that retain every required Linux suite.
Keep Linux execution and shared preparation, normal CI, npm qualification,
Docker, Package Acceptance, performance, and soak gates intact. Native
signing, appcast, and Windows asset promotion workflows stay unchanged.
Proof: focused policy/filter/summary regressions; full-release script tests;
pnpm check:changed; pnpm check:workflows with pinned tooling; ShellCheck;
independent autoreview. Hosted cross-OS orchestration remains unexecuted
locally. Six policy regressions fail against the previous policy.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Only apply the destructive skill routing label when every changed path belongs to a newly added ordinary skill root. Preserve grouped layouts and maintainer overrides, reject Custodian submissions, and validate rename source paths.
Replace the checker-only broad Octokit shape with exact issue request and response contracts, and make the test harness reject impossible missing issue responses.
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* fix(gateway): tools.invoke must carry the caller's host-minted role authority
The connect handshake resolves each connection's authority once and stores it
server-side (shared-secret operator owners mint system authority there).
tools.invoke discarded that fact and re-derived ownership from scopes, so a
shared-secret caller with no durable profile resolved to the deny-by-default
role and was refused dispatch on its own agents — while the same connection
could still mutate sessions directly.
Carry client.internal.operatorRoleActor into the synthetic dispatch client and
keep the scope-derived fallback for callers that have no connection actor
(HTTP). Regression test fails pre-fix with the FORBIDDEN agent-allowlist error.
* test(opencode): close the fake CLI before exec to stop ETXTBSY flakes
The catalog suite wrote the fake opencode executable and spawned it
immediately. Under parallel CI shards the write handle could still be open
at exec time, so the launch failed with ETXTBSY and failed the shard.
Write through an explicit file handle with an fsync before close so the
binary is fully durable before the first spawn.
* fix(ci): repair red main type and lint gates
Two gates were failing on main independently of this branch:
- extensions/qa-lab cleanup tests still built OpenClawCrablineChannelDriverSelection
with the retired smokeArtifactPath and a stale capabilityMatrixPath, so
check:test-types failed after the readiness-artifact change (#124189).
Align both fixtures with the current type and its pinned constants.
- scripts/github/release-validation-campaign.d.mts declared the Actions Octokit
client as any (#129726), tripping no-explicit-any. Declare the structural
subset the publisher actually calls instead of suppressing the rule.
Verified failing on clean origin/main before the fix.
* build(deps): remove npm shrinkwrap; mirror pnpm lock into transient package locks
npm 12 removed shrinkwrap (command + tarball/root loading). Delete all 82
committed npm-shrinkwrap.json files and stop publishing lockfiles; keep
pnpm-lock.yaml as the single reviewed dependency boundary. The generator
becomes scripts/generate-npm-package-lock.mjs and feeds plugin bundling via
a transient package-lock.json + npm ci (works on npm 11 and 12). Tarball
validation treats the published 2026.7.2 beta train as a shrinkwrap
transition; self-update npm detection now uses install topology instead of
the shipped shrinkwrap.
* fix(deps): repair lint, deadcode, and test-type lanes for the npm 12 migration
- sort integrity comparisons with an explicit comparator (oxlint)
- keep resolveBunGlobalNodeModules module-local (knip unused-export gate)
- model npm pack --json as npm<=11 array / npm 12 name-keyed object
- default calver destructuring in the tarball test fixture
* feat(ci): weekly Codex sweep for date-carrying to-dos
Mondays 06:23 UTC (plus default-branch-only manual dispatch with
dry_run): a deterministic prefilter collects candidate lines where
to-do markers co-occur with date tokens, plus every deprecated compat
record from the plugin registry; a pinned openai/codex-action step
judges each candidate in context (genuine dated commitment vs
historical date or fixture) and writes an OVERDUE / DUE-30-days /
FUTURE report; a separate privileged job validates the report (tracked
file:line locations, date shape, inert text) and upserts one
marker-tagged tracking issue via the Barnacle app token, commenting
only when items newly become due.
The app token is minted on a fresh runner and checkout — never beside
Codex or its child processes; only the validated report artifact
crosses jobs. No permission-* subsets on token minting (installations
reject explicit subsets; see pr-ci-sweeper).
* chore(ci): localize upsert helpers with no external consumers
Live verification showed dropped-CI PRs report mergeable=null and
mergeable_state=unknown indefinitely: the stuck merge-ref computation is
the same failure that dropped their CI, and close/reopen is what
un-sticks it. The pending-mergeability skip therefore made the primary
repair population permanently unsweepable (three real dropped PRs skipped
across three consecutive sweeps). Keep skipping computed conflicts; a
not-yet-computed conflict costs at most one budgeted re-fire.
* ci: add hourly PR CI sweeper for dropped pull_request runs
Fresh PRs race GitHub's merge-ref computation: the open-event CI run can
drop entirely or be created as an un-rerunnable startup_failure (~10-16
runs daily). The sweeper lists recently updated open PRs hourly, finds
heads whose only pull_request-event CI runs are startup failures (or
missing), and re-fires the event by close/reopen with the Barnacle app
token (GITHUB_TOKEN events would not trigger workflows).
Safety: 10-minute quiet window, 24h lookback, skips drafts, merge
conflicts, pending mergeability, and auto-merge PRs (close cancels
auto-merge); revalidates state, head, and CI attachment immediately
before mutating; per-PR budget of two sweeper closes and a per-sweep cap
of ten; reopen-on-unknown ownership so a stranded close (silent) always
loses to a spurious reopen (visible); manual dispatch supports dry_run.
Accepted tradeoffs are documented inline: shared-SHA PR topologies can
mask a dropped run (skip-only miss; run.pull_requests matching would
break fork PRs), and app-auth failover at worst doubles the close budget.
* test(ci): exercise pr-ci-sweeper runner with a faked client
* fix(test): lint-clean pr-ci-sweeper runner fakes