Lost CI-completion deliveries can leave the required ci-gate status pending after CI finishes. Add scheduled reconciliation through the existing trusted Security Review resolver and enforcement job.
Preserve overlapping completion windows, reject incomplete listings before publication, keep provisional statuses eligible, and trust only Actions-owned gate statuses. Bound each pass to the oldest 100 heads and retain the successful window anchor while a backlog remains.
Reruns whose original creation time predates the three-hour listing margin retain the documented existing recovery path through a push or Security Review rerun.
Validation: exact-head CI passed, focused entry-point and workflow regressions passed, and live read-only GitHub transport proof completed. Production scheduled recovery remains post-merge proof.
Consolidate repeated tooling flows while preserving command contracts. Fix swallowed HTML translation errors and browser-realm error handling in the Google Live smoke. Owner tests and CLI parity passed on Testbox; final broad gate replay follows a fixture lint correction.
Stop obsolete Security Review reads and non-quota recovery waits after a newer PR head supersedes the evaluated revision. Reuse the existing supersession outcome and preserve per-SHA publication serialization, final approval checks, and autoscrub writes/cleanup.
Regression coverage proves early exit before further pagination or recovery waiting; the unchanged-head control completes. In-flight request deadlines, server-directed quota waits, checkout, and runtime setup are unchanged.
Contributor credit: VACInc and vincentkoc.
## Work sessions
- [Original discussion](https://team.openclaw.ai/chat/roboclaw/dashboard/1b82108b-d6ca-44f2-95d5-63a6831c6bb7)
- [Implementation and verification](https://team.openclaw.ai/chat/roboclaw/68b61c50)
---
[View the OpenClaw team session](https://team.openclaw.ai/chat/roboclaw/dashboard/68b61c50-c2d0-461b-ab98-37947c99b1f1)
Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Cancellation did not prove an infrastructure error or absence of executed
and failed tests, yet the sweeper automatically replayed whole workflows.
The three-day census found nine such reruns, including five CI workflows.
Remove canceled-run revival. Keep bounded recovery for missing or
startup-failed CI before tests execute, with infrastructure warnings and
the existing live head/PR checks.
The actual sweeper boundary changed from one canceled-run replay to zero
without a PR mutation. Both shared-fixture importers passed 20 standalone
runs and three replays under their CI configs on Testbox.
Distinguish missing or active CI from failed CI. Keep the required combined status pending without failing the waiting review job, and fail visibly on approval, CI, metadata, or evaluation errors. Preserve workflow, head, attempt, and authority checks.
The r: support auto-response links to
/help/faq#im-stuck-whats-the-fastest-way-to-get-unstuck. That anchor does
not exist on /help/faq and did not before the FAQ split — the content moved
to the first-run FAQ in an earlier split, and the id changed spelling at the
same time. Anyone closed with this label has been sent to a page that scrolls
nowhere.
The live target is /help/faq-first-run#i-am-stuck-fastest-way-to-get-unstuck,
which the first-run FAQ index publishes as an authored stub.
docs-link-audit does not cover this because the URL lives in a script rather
than a docs page.
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures
Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.
Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.
* fix(scripts): keep guarded portable scripts bash 3.2 compatible
* fix(scripts): keep macOS Bash CI coverage green
Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.
Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.
* docs(install): use system Bash in install and recovery commands
Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.
Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.
* fix(scripts): preserve streamed installs and CI packing
Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.
Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.
Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
* fix(ci): labeler no longer fails when a PR already has 100 labels
PR #137637 taught the size-label step to tolerate GitHub's HTTP 422
"Issues cannot have more than 100 labels", but every other label-adding
step still threw it. On the 2026.9.1 closeout PR #137506 the maintainer
author-role step failed that way and turned the cosmetic Labeler check red.
Move the cap handling into one owner, scripts/github/labeler-label-cap.mjs,
and route all eight addLabels sites across the label, label-issues, and
backfill-pr-labels jobs through it: warn naming the skipped label, succeed,
rethrow anything else. Each job checks out the trusted base commit
(ref: github.sha, persist-credentials: false) like auto-response.yml so the
github-script steps can import the module; no PR code runs. Delete the size
step's pre-count guard so the 422 is the single canonical cap path.
Rename test/scripts/labeler-size-label.test.ts to labeler-label-cap.test.ts;
it executes the real step scripts with the real helper and adds maintainer
step cap coverage plus a workflow-wide invariant that no script calls
issues.addLabels directly.
* test(ci): cover labeler cap helper return value and keep knip aware of it
The knip full-tree unused-file scan flagged scripts/github/labeler-label-cap.mjs
because only the workflow loads it dynamically. Import it from its owner test,
like every other scripts/github module, with a case for the boolean result the
backfill job's label bookkeeping depends on.
Respect draft conversions observed by the final PR revalidation before closing and reopening to re-fire CI. Record the existing changed-during-sweep skip without spending the re-fire budget.
Cover missing-CI and startup-failure-only candidates with exact final-snapshot regressions; eligible non-draft behavior is unchanged.
Honor Peter Steinberger's 2026-09-03 operator decision to let macOS and
Windows work proceed in parallel with or after npm publication. Record
advisory cross-OS conclusions without turning them into release blockers,
and permit all-group selectors that retain every required Linux suite.
Keep Linux execution and shared preparation, normal CI, npm qualification,
Docker, Package Acceptance, performance, and soak gates intact. Native
signing, appcast, and Windows asset promotion workflows stay unchanged.
Proof: focused policy/filter/summary regressions; full-release script tests;
pnpm check:changed; pnpm check:workflows with pinned tooling; ShellCheck;
independent autoreview. Hosted cross-OS orchestration remains unexecuted
locally. Six policy regressions fail against the previous policy.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Only apply the destructive skill routing label when every changed path belongs to a newly added ordinary skill root. Preserve grouped layouts and maintainer overrides, reject Custodian submissions, and validate rename source paths.
Replace the checker-only broad Octokit shape with exact issue request and response contracts, and make the test harness reject impossible missing issue responses.
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
* fix(gateway): tools.invoke must carry the caller's host-minted role authority
The connect handshake resolves each connection's authority once and stores it
server-side (shared-secret operator owners mint system authority there).
tools.invoke discarded that fact and re-derived ownership from scopes, so a
shared-secret caller with no durable profile resolved to the deny-by-default
role and was refused dispatch on its own agents — while the same connection
could still mutate sessions directly.
Carry client.internal.operatorRoleActor into the synthetic dispatch client and
keep the scope-derived fallback for callers that have no connection actor
(HTTP). Regression test fails pre-fix with the FORBIDDEN agent-allowlist error.
* test(opencode): close the fake CLI before exec to stop ETXTBSY flakes
The catalog suite wrote the fake opencode executable and spawned it
immediately. Under parallel CI shards the write handle could still be open
at exec time, so the launch failed with ETXTBSY and failed the shard.
Write through an explicit file handle with an fsync before close so the
binary is fully durable before the first spawn.
* fix(ci): repair red main type and lint gates
Two gates were failing on main independently of this branch:
- extensions/qa-lab cleanup tests still built OpenClawCrablineChannelDriverSelection
with the retired smokeArtifactPath and a stale capabilityMatrixPath, so
check:test-types failed after the readiness-artifact change (#124189).
Align both fixtures with the current type and its pinned constants.
- scripts/github/release-validation-campaign.d.mts declared the Actions Octokit
client as any (#129726), tripping no-explicit-any. Declare the structural
subset the publisher actually calls instead of suppressing the rule.
Verified failing on clean origin/main before the fix.