Commit graph

213 commits

Author SHA1 Message Date
Vincent Koc
d72936b37e
docs(reference): split the testing reference by reader job (#141221)
* docs(reference): split the testing reference by reader job

docs/reference/test.md was 92,671 characters and mixed agent proof policy,
how-to steps, reference tables, and runner-internals explanation on one page.
It is now a short index over six children, one per reader job:

- reference/test/local            Routine local order, core commands, PR gate
- reference/test/lanes            Control UI, TUI, extension, Gateway, E2E lanes
- reference/test/docker           Docker scheduler knobs and the notable lanes
- reference/test/performance      Profiling, shard timings, benchmark scripts
- reference/test/runner-internals Build locks, test state, JSON report merging
- reference/test/remote-proof     Crabbox/Testbox policy, wrapper, lease, trust

Anchor strategy: per-anchor redirect routes are impossible here, because
redirectSource() in scripts/lib/docs-redirects.mjs rejects any source
containing [?#]. Every pre-split anchor instead stays alive on the parent as
an authored <a id="..." /> stub in the "Where each section moved" list, the
same mechanism docs/ci.md uses. All 30 ids were enumerated with
parseDocsDocument, never a hand-rolled slug, so the four punctuated headings
keep both the encoded and the cleaned id (for example
full-docker-suite-(pnpm-test%3Adocker%3Aall) and
full-docker-suite-pnpm-testdockerall). 29 ids are stubbed; `related` is not,
because the index still publishes that heading itself, and stubbing it would
raise a duplicate authored/canonical ID collision.

Verified independently of docs-link-audit, which cannot see the regression:
the split rewrote the repo's own links, so the audit reads clean even when
external deep links break. Resolving all 30 pre-split ids against the parsed
post-split index gives 30 resolved, 0 dead, 0 collisions, and all 24 onward
deep links land on a real fragment of a real child.

Losslessness (bodies, frontmatter excluded):
  code fences        20 -> 20   (+0)
  table rows         47 -> 47   (+0)
  inline code spans 530 -> 530  (+0, byte-identical multiset)
  fenced blocks      10 -> 10   (byte-identical, so commands are unchanged)
  chars           92,523 -> 92,253 on children + 5,093 on the index
  words           10,008 ->  9,981 on children +   381 on the index
  links               13 ->      9 on children +    35 on the index
The chars/words/links deltas reconcile exactly: the two intro bullets (170
chars) and the Related list (139 chars, 3 links) stay on the index, and one
declared edit adds 40 chars and one link.

The single declared prose edit: "Local test commands below are the normal
trusted development path" pointed at a section the split moves to another
page, so "below" became a link to /reference/test/local. No other prose was
rewritten; the remaining prose findings stay open for a follow-up.

Test pins repointed. test/scripts/docs-sync-publish.test.ts pins the exact
Release & CI navigation page list and breaks on the docs.json nav addition;
its route list now includes the six children. The two QA Lab producers point
their docsRefs at reference/test/local.md, the page that now owns the
commands they run, instead of the index. changed-lanes.test.ts needs no
change: it uses the path only as a docs-path example and asserts nothing
about the content.

Closes audit findings: r3-0695, r3-0696

* docs(reference): link the relocated local test commands

ClawSweeper found a second orphaned cross-reference the split missed.
remote-proof.md said "Local test commands below", but after the split
those commands live at /reference/test/local while this page continues
with remote-proof instructions, so "below" pointed at nothing.

docs-link-audit --anchors: 0 broken links.
2026-09-09 02:15:05 +08:00
Peter Steinberger
17cefca633
fix: prepare provider runtimes before sticker selection tests (#142234) 2026-09-08 07:57:28 -07:00
Peter Steinberger
62395281ff
fix(tooling): prevent accidental shared dependency installs (#141719)
* fix(tooling): prevent accidental shared dependency installs

Stop creating implicit checkout-root dependency links during tool bootstrap.
Refuse default pnpm reconciliation through borrowed roots before linking,
while preserving explicit hydrated aliases, existing read-only borrows,
and configured-to-local toolchain fallback.

Include the early guard in package files and document its checkout-root
scope, lifecycle bypasses, and concurrent-path limits.

Validation: 127 focused Linux tests, seven real pnpm install cases,
packaged-root command proof, full checks plus final scoped loader checks,
and independent P0-P2 review.

* fix(tooling): audit install hook and align bootstrap coverage

Include the dependency ownership guard in the exact install lifecycle
contract and dependency fingerprint inputs so CI admits the hook and
invalidates cached dependencies when its implementation changes.

Update the existing wrapper expectation for the intentionally removed
implicit primary-checkout borrowing path while retaining hydration proof.

Validation: reproduced both failures, 517 workflow guards (2 existing
skips), 98 bootstrap/ownership tests, full scoped Linux checks, and
independent P0-P2 review.

* test(tooling): align isolated harness and routing contracts

Provision the copied Docker harness's TypeScript package explicitly and
update the preflight diagnostic and dedicated shim test routing expectations.

Validate compact tooling runner capacity from each resulting group's compiler
membership, preserving all file-policy and negative mutation checks without
freezing incidental compiler co-tenants onto a larger runner.

Validation: all 604 affected Linux tests, complete scoped checks, original
failure reproductions, planner inventory attribution and independent P0-P2
review. No production dependency or capacity policy changed in this follow-up.

* test(tooling): keep bootstrap cases in the runtime owner suite

Preserve all eight bootstrap cases and fixture logic in the existing local
runtime suite, with scoped environment cleanup and precise test routing.
The standalone filename fragmented the integrated GitHub compact plan into
81 jobs; the actual consolidated merge fits all three plans within80.

Keep the cap, estimates, compiler capacity, assertions and test coverage.
Validation: identical moved AST/token bodies, 571 local tests, 624 integrated
Linux tests and full scoped checks, exact merged planner proof, and clean
independent P0-P2 review.
2026-09-07 20:09:36 -07:00
Peter Steinberger
5c307536ef
test: reuse compiled modules in Doctor process cases (#141549) 2026-09-07 14:09:30 -07:00
Peter Steinberger
26d322a675
perf: compile catalog workers once per test invocation (#141422) 2026-09-07 11:29:31 -07:00
Peter Steinberger
ce0e84d073
fix(runtime): require Node builds with lossless SQLite reads (#140672)
* fix(runtime): require Node builds with lossless SQLite reads

* fix(runtime): preserve upgrades and guard sealed workers

Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.

* test(runtime): use typed process exports in worker fixture

* test(runtime): align installer fixtures without growing test shards

* test(runtime): align release and guest runtime fixtures

* fix(test): canonicalize Windows temp roots for Node 24

Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.

* test(ci): run Windows temp-root regressions in the native lane
2026-09-07 10:31:31 -07:00
Vincent Koc
e136a5cc1c
docs(ci): split the CI page by reader job (#140501)
* wip

* docs(i18n): add zh-CN glossary entries for the new CI page titles

* docs(ci): apply oxfmt to the CI index page

* docs(ci): keep every legacy section anchor alive on the index

ClawSweeper blocked the split on a real regression: a path redirect
cannot preserve a fragment. The added /ci/pipeline-overview route
addresses a different path from /ci#pipeline-overview, and
redirectSource() in scripts/lib/docs-redirects.mjs rejects any source
carrying a fragment. So existing links and bookmarks such as
/ci#pipeline-overview and /ci#control-ui-size-budgets silently lost
their destination.

The index now carries an authored <a id> stub for all 46 legacy section
anchors, each linking to the page that holds the content. This is the
pattern already used for the gateway configuration reference split.

Each destination id comes from the repository's own publishing parser
(parseDocsDocument), not from a slug approximation, because the parser
percent-encodes punctuation: "Reusable live/E2E workflow" is not
reusable-livee2e-workflow. The Related anchor is not stubbed because
the index keeps its own Related section.

docs-link-audit --anchors: 0 broken links.

* test(tooling): follow the CI docs across the split

package-acceptance-workflow.test.ts reads docs/ci.md and asserts the
documented raw Full Release Validation callers pin an exact SHA. The
split moved those snippets into docs/ci/release-validation.md and
docs/ci/scope-and-routing.md, so the assertion failed against the index.

Reads docs/ci.md plus every docs/ci/*.md instead, so the assertion
follows the content rather than one file path and survives later moves.

This is the third lane found pinning a docs path, after the navigation
test and the cloud-workers config test. Only this one runs on docs-only
pull requests.
2026-09-07 17:13:42 +08:00
Peter Steinberger
5f8a40d5dc
fix: native declaration preparation fails from aliased checkouts (#140652) 2026-09-06 19:53:53 -07:00
Peter Steinberger
4972d5608e
fix(tooling): correct advice for nested declaration failures (#140617)
Explain ancestor manifest probes despite a complete local install and checkout-local final resolution. Direct validation to a physically isolated checkout without changing input membership or fail-closed containment. Add native regression coverage for manifest-only probes, standalone receipt reuse, and consumed-manifest invalidation.

Related: #139766
2026-09-06 19:15:34 -07:00
Peter Steinberger
e07af7166c
feat(triage): start installation-owned recovery after update and startup failures (#135868)
* feat(triage): start installation-owned recovery after failures

Run automatic update and startup recovery through the fresh installed CLI,
with one live lease, requester revalidation, and native cleanup ownership.
Keep manual triage on the bounded update repair loop and retain the original
failure outcome. Includes the coupled runtime build closure and boundary proof.

Stage 5 of the #135868 split.

* refactor(update): reuse formatted completion guidance

* test(update): create canonical maintenance inspection leases

* fix(build): register the sealed handoff entry consistently

* refactor(update): reuse typed capability consent outcomes

* test(update): isolate automatic triage at the command boundary

* fix(doctor): carry mutation state into migrated finalization

* fix(build): expose a uniform tsdown config collection

* test(update): preserve native identity reads in command fixtures

* fix(triage): keep automatic inference under recovery authority

* refactor(update): share guarded autostart restoration
2026-09-06 16:09:42 -07:00
Peter Steinberger
c6a0874729
fix(ui): retain real-Gateway browser proof across reruns (#134274)
Port PR #134274 onto the current native fixture lifecycle. Logs and Usage use the shared lazy per-attempt artifact owner, Usage preserves distinct owner-view stages, and MCP retains one suite-owned report directory without clearing previous proof.

Preserve existing assertions, deadlines, capture gates, native fixture cleanup ordering, and viewport-safe Logs capture. Keep documentation aligned with current ownership and diagnostic provenance. No production runtime changes.
2026-09-05 19:47:46 -07:00
Peter Steinberger
b8731bc88a
perf(test): reuse transforms within owned scheduler slots (#139553)
* perf(test): reuse transforms within owned scheduler slots

* test(ci): assert verified outer process completion receipts

* test(ci): assert joined Vitest progress completion

* test(ci): cover platform-specific cache lease policy
2026-09-05 18:50:40 -07:00
Peter Steinberger
2dea108755
fix(crabbox): preserve payload output and script options (#139405)
Route selected-source installer diagnostics to stderr and retain its source revalidation. Preserve repeated and disabled script-source flags, reject non-regular source policies, and use the existing Windows command-shim invocation for selection. Prepare named Testbox jobs with frozen dependencies and disable redundant implicit gate installs.

Related: #135868 and #139273.
2026-09-05 14:54:33 -07:00
Vincent Koc
8e5a3f3638
chore(test): migrate to stable Vitest 5 (#138264)
* build(test): migrate to stable Vitest 5

Co-authored-by: Peter Steinberger <steipete@gmail.com>

* docs(test): document Vitest 5 contracts

* test(test): prove Vitest cache invalidation

* test(test): stabilize report config load proof

* test(test): restore Vitest 5 compatibility

Co-authored-by: Peter Steinberger <steipete@gmail.com>

* test(test): isolate pnpm cache fixture registry

* fix(test): keep pnpm 12 env lock portable

* fix(test): preserve explicit Vitest project roots

* fix(test): preserve nested Vitest project identity

* test(test): expect captured Vitest name prefix

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-06 04:17:59 +09:00
Peter Steinberger
2116c9a967
ci: reduce Doctor test startup and core lint jobs (#138796) 2026-09-04 20:20:16 -07:00
Peter Steinberger
b78612ac3a
fix(build): bound native declaration inputs to checkout (#138742)
* fix(build): reject cross-checkout native declaration inputs

Refuse ancestor and external dependency inputs before native declaration or package-boundary success records are accepted. Reuse the declared/native path boundary for compiler identity, reads and previous-snapshot keys while preserving consumed-byte, topology, ctime and publication fences. Remove implicit primary-install linking, retaining subdirectory and Windows alias support. The native engine is unchanged; this is fail-before-acceptance rather than hermetic execution. Fixes #138677.

* fix(build): align declaration owners with checkout paths

Use native-canonical namespace and output identities so Windows 8.3 paths
cannot make a declaration owner count its own emitted files as new inputs.
Keep declared cwd ownership for private child joins while snapshots and
publication share physical paths.

Bind the existing declaration-plugin cwd option before plugin construction;
its explicit entry patterns otherwise use ambient cwd and can select no
compiler roots. Preserve explicit overrides and all real receipt, byte,
ctime, topology, inventory, and publication checks.

Cover native short-entry/workspace junction cold and warm behavior, tsdown
alias writers, and explicit entries across node/workspace/AI configurations.

Refs #138677; related #138440.

* test(build): keep remaining compiler fixtures checkout-local

Give the root-lint fixture its own native compiler while retaining real lint tools, ambient types, and source aliases. Keep the shard recorder on its fixture-owned native binary and detach its launcher before replacement. Preserve all diagnostic, enumeration, and signal/join assertions.

Repairs the exact-head CI fixture failure in PR #138742 (native declaration input boundary); production admission remains unchanged.

* fix(build): validate native checkout before bootstrap

Resolve the containing checkout compiler while preserving caller-relative projects. Use the existing native Node shim so refusal and sparse skip precede shared-install or output mutation; keep execution under the artifact owner. Cover actual linked-worktree entries and replace the boundary signal fixture's notification-based readiness with its child-owned PID. Addresses review findings on #138742; preserves strict fail-before-acceptance for #138677.
2026-09-04 19:50:21 -07:00
Peter Steinberger
1426e49d2b
fix(crabbox): retain diagnostics safely across capsule cleanup (#138715) 2026-09-04 18:24:58 -07:00
Peter Steinberger
0d830e9e74
fix(gateway): keep received work inside its state lifetime (#136146)
* fix(gateway): keep received work inside its state lifetime

Join original WebSocket dispatch, cooperating refreshes and connection cleanup before releasing Gateway dependencies. Retire passive approval/question/run observers without inventing durable decisions, and preserve test state until native callbacks and first browser closes settle.

Remove the unused process-local approval implementation and forwarding adapters. The refactor removes 404 production lines from the initial repair while retaining boundary regressions and moving manager tests onto the real durable path.

Verified under enforced credential-free isolation: 2,143 distinct owner/native/process tests, a final 77-test rerun, changed gates, product/UI builds and scoped-clean Codex P0 review. Protected exact-order browser replay remains a pre-merge gate; historical incomplete audits are not acceptance.

* fix(gateway): join worker cleanup before closing transport

Fence ingress without disconnecting the supervisor needed for worker cleanup,
then join received work before releasing the remaining Gateway dependencies.
Preserve exact pending-node authority during direct and restart shutdown.

Keep startup logging and sidecar acquisition owned independently of fail-fast
readiness, and retire published plugin services only through their actual owner.
Join portal cleanup before reporting sibling shutdown failures.

Record positive test-Gateway closure at its owner. Retain fixture state and
selectors after incomplete shutdown, including across module reload, without
confusing a post-close diagnostic with an unfinished producer. Cover that
boundary through an isolated real-Gateway counterfactual and regression.

Consolidate UI finalization with the shared QA cleanup owner and separate the
lazy handler registry from dispatch without changing loading or method order.
Derive handler families from typed descriptor rows and remove the old casts.

Follow-up repair for the state-lifetime boundary in #136145 and #136146.

* fix(gateway): fence worker frames during ordinary close

Reject newly received worker frames once their connection generation starts closing, while retaining queued work and its completion owners. Cover the live-socket window through the real worker protocol and a checked synthetic node sink.

Synchronize the update-failure UI test with its intended Updates recovery navigation before reopening the Inbox.

Follow-up for #136146 (Gateway received-work lifetime), addressing the shutdown-admission gap from review.

* fix(browser): join SDK-initiated MCP transport cleanup

Route SDK initialization failure and transport close through the existing
Chrome MCP process owner before native close clears the child PID. Capture
the native closer separately so concurrent callers join one cleanup path
without recursion or losing descendant ownership.

Collect startup diagnostics after cleanup and stderr completion, while
never-spawned commands skip the unused pipe. Preserve cleanup failures and
the existing launch, environment, and process-group behavior. Exercise late
stderr, descendant cleanup, forced termination, ENOENT, and backpressure
through real subprocesses.

* fix(gateway): retain supervisors after worker shutdown failure

Require connection-dependent sidecars to stop successfully before draining their supervisor transports or releasing runtime dependencies. Cover public and startup-failure shutdown, retained-owner retry, and late sidecar registration.

* test(gateway): join policy writers after releasing handler gates

Preserve policy-revocation and response-order coverage under the received-work dispatcher completion contract. Retain all held calls and release/join them in finally so tests cannot wait on their own unreleased gates.

* fix(gateway): retain execution through required shutdown

Preserve early acknowledgements while joining original raw, typed, and
agent execution through final cleanup. Cancel this Gateway's runs before
the join, and fence late admission at controller publication.

Retain failed startup acquisitions and plugin cleanup owners, preserve both
startup and cleanup errors, and prevent CLI successors after incomplete
retirement. Keep deferred startup hooks and sentinel refresh in their owner.
Remove the monolithic close factory and redundant post-abort polling.

Declare compiled plugin dependencies for the full lifecycle fixture through
the existing pretest owner. Align the QA publishing reference with main.

Validated isolated before/after regressions, original-order execution,
startup/CLI/plugin suites, full build, types, lint, and Codex review.
The protected metadata audit remains unaccepted; this is not merge approval.

Refs #136145, #136146.

* test(agents): align Code Mode fixtures with main

Adopt the SessionManager fixture and structured-result classification from
#138238, preserving the attempted hidden namespace call and the checks that
neither the original preparer nor action executes. Remove redundant pass-through
mocks with the upstream fixture.

Both files match the successful upstream CI head ce42af56a82f exactly. Gateway
runtime code is unchanged; this resolves the parallel test-fix merge conflict.

* test(gateway): reuse tracked agent contexts

Replace three partial agent-handler contexts with the shared fixture. The missing
execution tracker threw after admission handoff and leaked session claims into
later continuation tests. Preserve their assertions, timers, and original order.

The complete 302-case file reproduces all six CI failures before this repair and
passes afterward in the same order. Type checks, type-aware lint, formatting,
and independent Codex review pass. No production code changes.

* test: fix gateway, Signal, and UI fixture lifetimes

Reset agent database handles, validation, and terminal latches only within
retired fixture roots before deleting or recreating their files. Preserve
ordinary runtime reopen behavior and unrelated roots.

Model the pending host question in Signal's partial-delivery fixture and
assert the accepted reaction binding. Use actual Settings navigation from
independent cold UI contexts so document reloads do not abort startup
scripts and masquerade as asset failures. Preserve existing assertions.

Reproduced the Node and Signal failures locally and the UI cancellation on
Linux. The Linux owner replay passes 30 tests across six files, the full
settings suite passes seven, and the final UI revision passes both cold
routes locally. Static checks and independent source review pass. The
isolated native fixture still times out on this Mac; Linux completes its
unchanged case in 13 seconds. Protected audit acceptance and final-head
hosted checks remain separate landing requirements for PR #136146.

* test(sessions): call database reset without hook context

Wrap the participant suite teardown in a zero-argument callback. Vitest
passes TestContext to registered hooks; the reset helper now accepts an
optional root path for selective fixture retirement.

The full seven-case file reproduced four teardown failures before this
change and passes all seven afterward. Assertions and cleanup semantics
are unchanged. The callback audit found no other direct registrations.

Refs #136146, #136145.
2026-09-04 16:02:31 -07:00
Peter Steinberger
f0811ca62e
fix(testbox): preserve hydrated runtime across native sync (#138612)
* fix(testbox): reject rsync that deletes ignored runtime

Require GNU rsync before delegated Testbox sync so Apple openrsync cannot erase hydrated dependencies and ignored runtime data. Preserve caller-owned PATH, source verification, and administrative commands; document the explicit prerequisite and fresh-lease recovery.

Follow-up to #138404 and #138153.

* fix(testbox): resolve rsync before its compatibility probe

* fix(testbox): isolate sync from the hydrated execution workspace

Keep native Git cleanup and rsync in a disposable transport checkout, then apply the verified source bundle and run payloads in the original prepared workspace. Preserve runtime paths and raw source/privacy/deletion checks; invalidate leases when workspace preparation or the selected workflow changes.

Discard the GNU-only prerequisite after live proof showed native cleanup removes newly ignored runtime before rsync. Require the advertised prepared-artifact-workspace capability for artifact requests so older Crabbox clients cannot collect stale transport files.

Runtime-preservation follow-up to #138404 and #138153. No release or merge.
2026-09-04 15:39:01 -07:00
Peter Steinberger
7697286a56
fix(ci): retain failure diagnostics and shard provenance (#138651)
Preserve native run and capture artifacts per temporary-sync invocation, retain the source checkout on preservation failure, and use the canonical CI shard index in UI failure reports.

Fixes #138650 (failure captures lost during temporary sync cleanup). Related: #138482 (CI admission keeps ready PR checks alive). Diagnostic tooling only; no backend, scheduling, cache, permission, or product-runtime changes.
2026-09-04 15:22:59 -07:00
Peter Steinberger
2329399cf6
fix(build): keep nested checkout declarations on pinned local inputs (#138440)
* fix(build): keep declaration inputs inside their checkout

Keep tsdown declaration resolution pinned to the declared checkout in nested
worktrees, including explicit and automatic type references, resolved dts
options, independent CommonJS emission, and relative compiler filesystem calls.

Preserve complete actual Program receipts, CompilerInputSnapshot mutation
checks, joined compilation, and staged publication. In-checkout pnpm links
remain supported; shared external declaration inputs fail explicitly.

Add real nested-checkout, lifecycle, override, cwd, mutation, and publication
regressions. Native tsgo declaration ownership remains a separate follow-up.

Fixes #138408

* fix(build): preserve native checkout identity in declarations

Normalize only the declared checkout prefix so Windows short and long path
spellings share one input owner without admitting ambient ancestor links.
Validate original Program members before projecting complete receipts.
Keep CompilerInputSnapshot and staged publication unchanged.

Cover real directory and Windows 8.3 aliases, preserve rejection of ancestor
symlinks pointing inside, and register the resolution suite in Windows CI.

Follow-up to the Windows failure in the declaration containment repair:
https://github.com/openclaw/openclaw/pull/138440
https://github.com/openclaw/openclaw/issues/138408

* fix(build): recognize symlink-resolved checkout prefixes

Map both the declared checkout and its symlink-resolved spelling onto one
native root, without canonicalizing arbitrary outside candidates into scope.
This covers junctions whose targets retain Windows short names.

Use native fixture roots for physical-path assertions and preserve explicit
three-spelling regressions with junction-to-8.3 and case-alias targets. Let
cmd.exe own its quotes in the controlled short-name query.

Keep CompilerInputSnapshot, complete receipts, and publication fences intact.
The real three-spelling regression fails before the owner correction and
passes after it; the full local resolution matrix passes 17 cases with two
Windows-only cases awaiting native CI.

https://github.com/openclaw/openclaw/pull/138440

* fix(ci): accept valid zero-RSS scanner samples

Linux can release a task's memory before its zombie state becomes visible.
Treat zero as a measured value instead of poisoning the scanner's failure
category. Keep negative/invalid samples fail-closed, and preserve all limits,
process-group accounting, cleanup, and exact report identities.

Add a real-CLI, readiness-coordinated regression for zero and four invalid
sample classes. The zero case fails before the comparison repair. All 23
scanner tests pass on Linux Node 24.19; 20 baseline and 20 fixed natural OOM
probes pass, but do not reproduce the original race, whose row was not logged.

Bounded CI repair discovered while landing declaration containment:
https://github.com/openclaw/openclaw/pull/138440
2026-09-04 14:32:14 -07:00
Peter Steinberger
a86a1b505d
fix(testbox): preserve complete source snapshots (#138404)
Freeze policy-selected raw source into the existing Git-bundle path and verify filesystem bytes, symlink targets, executable flags, and producer-owned deletions before executing Testbox proof. Remove the unverified remote auto-commit and fingerprint the actual source-owner modules.

Closes #138153. Verified native checksum-full recovery against the complete source hash; 284/284 Linux owner tests passed with an unchanged candidate manifest. Native openrsync deletion of ignored runtime directories remains a separate limitation.
2026-09-04 10:13:36 -07:00
Peter Steinberger
f94fff4d0f
fix(qa): preserve viewport recordings during screenshots (#138104)
* fix(qa): preserve viewport recordings during screenshots

* docs(qa): scope recording guidance to verified capture owner
2026-09-04 03:41:44 -07:00
Peter Steinberger
7eec7219a1
fix(test): preserve native compound-help semantics (#137906)
Reserve wrapper usage for a sole help flag and let compound requests
reach the existing Vitest parser. Delete the premature raw-token scanner
so negated help executes, invalid scalar options fail, and native help
keeps its own metadata behavior.

Production is net -12 lines. Real CLI regressions fail before the repair
and pass afterward; standalone wrapper help remains unchanged.
2026-09-04 03:10:10 -07:00
Peter Steinberger
8c6653a78d
fix(gateway): preserve desktop readiness and worker outcomes (#136297)
Some checks are pending
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pt-BR (push) Blocked by required conditions
Native App Locale Refresh / resolve-base (push) Waiting to run
Native App Locale Refresh / Verify generated PR App permissions (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ar (push) Blocked by required conditions
Native App Locale Refresh / Refresh native de (push) Blocked by required conditions
Native App Locale Refresh / Refresh native es (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fa (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native hi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native id (push) Blocked by required conditions
Native App Locale Refresh / Refresh native it (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / publish_plugins_npm (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / warm (linux) (push) Waiting to run
Vitest Cache Warm / warm (macos) (push) Waiting to run
Workflow Sanity / no-tabs (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Cloud session Desktop availability could remain stale after approval, replace an explicitly selected source during placement changes, or lose a dispatched worker to its discovery deadline. Offline Continue on Gateway also needed to retire the exact old owner while retaining cleanup responsibility, and aborted model calls could be reported as ordinary transport failures.

Consolidate Desktop inventory and session updates, retain explicit source/control/popout intent through placement updates, and retire the discovery deadline after dispatch. Move teardown orchestration to its canonical owner, preserve the exact abandonment decision through retries, and keep ordinary reclaim dependent on physical cleanup acknowledgment. Reuse the canonical diagnostic terminal owner and remove the duplicate adapter.

Apply the maintainer-approved, exact-version noVNC 1.7.0 repair: consume ignored extended-clipboard payloads so the following framebuffer message is parsed correctly. Load Desktop-only English with the existing lazy viewer, consolidate package-bin resolution, and register the unchanged retention subprocess with the existing compiled test-fixture owner.

Proof on head 8211f9f3: 57 Desktop unit and 39 real-browser tests; full runtime-change gate plus focused fixture checks; full package/install verification; one real Linux model turn completing five CUA select-all/type cycles with 13 computer results and 20 uninterrupted passive WebVNC observations. Normal reclaim synchronized the exact 300-byte file and completed provider cleanup with no pending reconciliation. Earlier native Windows/macOS, stale-authority and offline-continuation proof retains its original build identity in the PR. The AWS Mac and Dedicated Host remain intentionally retained.

Related: #136018; openclaw/crabbox#1724, openclaw/crabbox#1740, openclaw/crabbox#1743, openclaw/crabbox#1782. No configuration, SQLite schema, or public protocol change. See PR #136297 for dependency provenance, review dispositions, production/test LOC classification, and explicitly unresolved diagnostic follow-ups.
2026-09-03 15:32:01 -07:00
Peter Steinberger
6f77913ec3
test(cli): reuse compiled runtime in fork recovery process test (#137460) 2026-09-03 11:13:47 -07:00
Peter Steinberger
c3761c68dd
fix(ui): prevent blank retained auth proof screenshots (#137031)
* fix(ui): prevent blank retained auth proof screenshots

Wait for meaningful content and finite presentation-owner motion before retaining raw Chromium viewport captures. Reuse the splash readiness policy and prove entrance/lazy-content failures with pixel regressions. Preserve current Gateway/context cleanup and allocate auth evidence per invocation.

* fix(ui): guard auth cleanup report after setup failure
2026-09-02 23:31:25 -07:00
Peter Steinberger
44b5c51eef
fix(ci): tolerate small Control UI CSS changes (#136972)
Keep startup CSS at a 45 KiB advisory target with a 50 KiB hard ceiling and reject growth of 1 KiB or more against the exact base. Enforce budgets in a separate required CI job while artifact builds retain integrity checks and report sizes. Compare both sources with the candidate toolchain and canonical CSS compression.
2026-09-02 21:42:19 -07:00
Peter Steinberger
63974421ae
fix(bench): keep synthetic Gateways off LAN discovery (#136793)
Keep synthetic Gateway startup, restart, and concurrency benchmarks out of LAN discovery on macOS by setting the existing discovery.mdns.mode to off in their shared fixture. Loopback listener binding does not suppress Bonjour publication.

Preserve product discovery defaults, Bonjour plugin enablement, the child environment allowlist, and operator state. Add real serialized-fixture/startup boundary coverage with a fake publisher and an enabled positive control, plus a short benchmark isolation note.

Validation: failing pre-fix/passing post-fix boundary regression; 106 focused tests; changed-file type/lint/format/guard checks; fresh independent Codex autoreview; runtime-only build and one real macOS startup smoke with health/readiness HTTP 200 and clean shutdown. No real pre-fix Gateway, live deployment, operator configuration, or production database was used.

Fixes #136791.
2026-09-02 18:43:23 -07:00
Peter Steinberger
6187bd6faf
fix(gateway): honor Full Access for delegated OpenClaw changes (#136036)
* fix(gateway): honor Full Access for delegated OpenClaw changes

Use the requesting run’s effective permission policy to authorize exact delegated proposals without an extra operator card. Preserve restricted approvals and late run/worker guards, and discard canceled proposals before a later turn can execute them.

Fixes #136032. Covers default and explicit Full Access with actual isolated Gateway config persistence, proposal-route regressions, and cancellation ordering.

* test(qa): include delegation proof in E2E ownership inventory

* fix(setup): retain scoped runtime artifacts during verification

Preserve the requesting registry’s built/source selection when loading fresh inference-owner metadata. Otherwise a healthy built Gateway probe is revalidated against source TypeScript and rejected as plugin artifact drift.

Discovered and reproduced with live Codex while validating #136036. Keep exact artifact/auth guards and standalone source defaults unchanged; cover both contextual selection modes.

* docs(gateway): align delegated change approval guidance

* fix(gateway): bind delegated proposals to their requesting run

Reconcile foreign and terminal proposals before routing new input, preserve exact live approval ownership, and clear executable state even if approval cancellation fails. A concurrent Full Access read must never apply another run's pending write. Keep model-facing summaries policy-neutral. Covers live and closed run boundaries, storage failure, worker claim reuse, and rendered prompts for #136032.

* test(gateway): admit delegated session ownership fixture

Use a real live run claim for the cross-connection delegation assertion, release it in finally, and verify the retained caller cannot invoke the engine after closure. Keep the production authority guard intact.

* fix(gateway): join metadata work before shutdown

Give every Gateway lifetime a metadata stop owner, including lazy minimal-Gateway preparation. Close new work through the existing generation fences and join pending readers, refreshes, commands and projections before model/config teardown.

The minimal and ordinary lifecycle regressions fail before this repair; 68 focused tests, full changed checks and fresh P0 autoreview pass. Found during real-Gateway validation for #136036. The broader pre-entry RPC shutdown gap remains separate; no timeout, logger, schema or dependency policy is weakened.

* test(ui): isolate pairing help navigation from live docs

Own the popup document through an exact BrowserContext route before clicking. Preserve the real popup, secure target/rel, focus and credential-lifecycle assertions; check the full anchored destination and controlled response.

CI33632492208 stalled waiting for the external page load after opening pairing help. The live canonical URL is valid. Four focused browser tests, scoped checks and fresh P0 review pass; production behavior and timeouts are unchanged.

* fix(gateway): retire failed delegated proposals before reuse

Retire exact session approval ownership, its record and the engine proposal through one cleanup owner. Cover failures before resolver entry and registration as well as application, retaining delayed cleanup inside the serialized task so it cannot cancel a later same-hash proposal.

Real handler/run regressions fail before the repair: a closed run's unregistered proposal was executed by the next Full Access read, and a real database-open failure retained a partial approval owner. The fix passes 174 focused/sibling tests, scoped checks and fresh P0 review. Follow-through for #136036; no configuration, schema or protocol change.

* test: preserve complete CLI output before parsing

Keep finite command results separate from bounded Gateway diagnostics. The Linux artifact proof emitted valid plugin JSON above256KiB; reusing the log tail corrupted that successful result. Preserve bounded timeout diagnostics and report actual inventory-command failures.

Real UTF-8 child regression fails before the change;56 helper and sibling tests, scoped checks, and independent P0 review pass. CLI exit/close lifetime work remains separately owned by #136286. CI follow-through for #136036.

* test: separate refusal ordering from deadline policy

Keep native startup, inherited stderr, retry state, and cleanup real while controlling policy time in the positive refusal table. A 1250ms fixture delay reproduced SIGTERM instead of status 1 under the unchanged 1000ms budget; the repaired table passes with the same delay. Dedicated readiness and drain expiry cases still enforce their deadlines.
2026-09-02 18:01:06 -07:00
Peter Steinberger
1a54844f3b
fix(ci): catch missing mobile event coverage in local checks (#136470)
* fix(ci): catch missing mobile event coverage in local checks

* fix(ci): cover protocol guard execution helpers
2026-09-02 13:21:22 -07:00
Peter Steinberger
feff169c05
perf(ui): reduce New Session payload and repeated settings reads (#136362)
* perf(ui): streamline startup runtime ownership

Keep phone formatting and transcript-only styles out of New Session startup. Bind token-free presentation preferences to the mounted Gateway, carry them through composer renders, and suppress unchanged agent publications. Reuse the canonical authenticated-hello recovery owner from #133789 and retire stale discovery tasks synchronously.

Proof: isolated full build and changed-file checks, focused preference/discovery tests, 93-state CSS parity, real Gateway PTY/create/stream/settle/history flow, and independent P0-scoped autoreview. The final broad suites and matched timing measurements remain in progress before publication.

* test(ui): preserve pending session titlebar insets

Assert that the pending Chat classes preserve New Session scroll padding across the existing viewport, theme, and motion matrix. Browser CSSOM checks on the reviewed build and baseline confirm the shared stylesheet precedes New Session overrides; no production cascade change is needed.

* test(gateway): publish RPC fixture config before yielding

Keep mutable testState agent entries in the pinned snapshot before real-IO readers or admitted runs can observe an RPC refresh. Extend the managed-worktree case with the observed interleaving, preserving agent validation and initial/follow-up cwd assertions. Controlled original-order proof fails before the helper repair and passes all 314 cases afterward.
2026-09-02 11:10:30 -07:00
Peter Steinberger
cc6769b892
fix(test): keep mixed UI directory runs scoped (#136136) 2026-09-02 01:32:03 -07:00
Peter Steinberger
29bd1cde92
improve(ui): avoid unused bundle builds in standalone E2E runs (#135962)
* perf(test): avoid unused Control UI E2E bundle setup

* test(browser): wait for restored MCP target inventory
2026-09-01 23:25:21 -07:00
Peter Steinberger
7de6d2a8fb
fix(test): keep test wrappers responsive during shutdown (#135439)
* fix(test): keep wrapper shutdown responsive

Verify compiled subprocess artifacts with bounded asynchronous reads, retain admission work until disposal, and preserve native signal outcomes after cleanup. Keep one public failure trailer and remove duplicate Vitest-side verification.

Avoid whole-repository source analysis for exact test targets. Add signal, read-drainage, live-borrower closure, and cold-planner regressions. Refs #135365.

* fix(test): keep generation deletion responsive

Await artifact removal under the existing disposal owner so signal handlers remain active through slow filesystem cleanup. Extend the direct and serial signal matrix without changing deadlines or the original case order.

Scope the catalog-row marquee test to its session label after main added marquee headers, preserving existing assertions and checking both labels. Refs #135439 (wrapper shutdown repair) and #135365 (post-summary wrapper stalls).

* test: observe shutdown without signal emitter hooks

Probe held-I/O responsiveness without adding signal listeners or relying on Node's cached process.emit binding. Make admission borrowers fail with ordinary code 1 so the owner's native signal result is independent. Keep status, footer, generation, process-group, and deadline assertions; negative controls still reject synchronous cleanup and missing invocation handlers.

Refs #135439 (wrapper shutdown repair) and #135365 (post-summary wrapper stalls).

* test: observe shutdown controls without native watch events

Poll persistent fixture control files with the existing readiness convention. Keep signal ownership, native status, footer, generation and process-group assertions unchanged. Fault-inject unavailable native notifications; blocking cleanup and missing signal-handler negative controls still fail.
2026-09-01 19:45:16 -07:00
Peter Steinberger
1cf0c31f30
fix(test): preserve retained inputs across nested Vitest cleanup (#135647)
* fix(test): preserve retained inputs across nested Vitest cleanup

Register resource claims before admitting nested namespace, fixture, and managed-command work. Require positive release evidence before outer namespace deletion, preserving uncertainty across module resets, caught failures, and worker crashes without weakening process-group checks or deadlines.

Add real detached-writer proof for threads and forks, maintain standalone and native-wrapper import closures, and document exact-path recovery. Fixes #135630.

* test: isolate deliberate nested cleanup failures

Give lost-owner fault fixtures explicit resource namespaces and verify their independent writer recovery before disposal. Keep real managed cleanup uncertainty enrolled with its owning runner, and include the new helper in the sparse release preflight checkout.

Addresses the failed compact shards in CI run 33570526716 for #135647. The local compiler uncertain-output case remains limited by its unchanged pre-existing 120-second timeout; exact-head Linux CI must provide the final proof.

* fix(test): retain claims through asynchronous fixture removal

Drain work and roots admitted while asynchronous directory removal yields before publishing the fixture release receipt. Preserve current main native-home and asynchronous-cleanup semantics while preventing premature nested ownership release.

The deterministic admission-during-removal regression fails before this fix and passes afterward. Keeps the existing process-group checks and deadlines for #135647.

* test: clean joined nested retention fixtures

Remove the complete generated fixture only after the scenario and every cleanup phase succeed. Preserve evidence and inputs on body or cleanup failure, and assert disposal in each real detached-writer regression.
2026-09-01 19:04:09 -07:00
Peter Steinberger
c7277fb99e
fix(test): fail empty routed file selections by default (#135609)
Require nonempty native discovery for finite routed exact-test-file requests
when the caller supplied no passWithNoTests policy. Preserve explicit opt-ins,
native invalid-input handling, direct configured policy, and broader/plugin
selection contracts.

Exercise real CLI/config boundaries with independently owned fixture discovery
and cleanup. Synchronize build-admission checks on preparation rather than
entrypoint import completion.

Refs: https://github.com/openclaw/openclaw/issues/135352
2026-09-01 17:43:27 -07:00
Peter Steinberger
80ae248de1
fix(update): preserve configuration and hand failed upgrades to triage (#134490)
* fix(update): preserve configuration and verify upgrade recovery

Prefer npm before ClawHub only among declared plugin identities, preserving explicit source/version intent, artifact integrity and capability consent. Keep the exact installed beta cohort and require typed target absence before fallback.

Preserve authored environment references through both Doctor writers, resolve snapshot destinations at operation time, and keep migration-only metadata out of redacted snapshots. Avoid loading channel runtimes for unused pairing account facts while retaining captured migration-owner attribution.

Record activation safety at package/Git mutation boundaries. Keep installed-CLI recovery, verify runtime/native-service identity, fence Windows autostart, preserve child status, and avoid duplicating consumed notifications or rejecting completed install switches. Surface update-specific disconnect diagnostics without changing explicit-restart guidance in Model Setup.

Retain the upgrade-survivor first-hop, approval and installed-version oracles. Repair CI's type-only Doctor cycle and stale source-policy, final-Doctor and Teams whitespace expectations without weakening timeouts, gates or the main-owned Markdown fix.

PR: https://github.com/openclaw/openclaw/pull/134490

* test(msteams): align the corrected main whitespace fixture

* perf(ui): remove unreachable update translations

Remove superseded version-only verification copy and the unused idle label from the eager catalog. Keep identity-aware verification and all recovery guidance unchanged, align translation fixtures, and restore the existing merged startup budget without increasing its baseline or limits.

* fix(update): retain consent failures and isolate validation homes

Carry unresolved non-retained plugin capability refusals from missing-install
repair through post-core convergence as typed outcomes, preserving the existing
update failure and restart boundary. Keep usable retained artifacts and
transient fetch failures on their existing notice/warning paths.

Give test invocations a native process HOME before config imports and worker
creation. Preserve bounded live/profile context, report selection, installed
tool caches, and process-group/pipe-owned namespace cleanup or truthful
retention. Keep unknown or mixed explicit real-home selections closed.
Resolve the repo-owned staging helper from its owning cwd and await complete
PID readiness before cancelling native report fixtures.

Align the survivor recovery oracle with typed consent errors that intentionally
have no Doctor reason. Preserve strict plugin/code/version/core-step checks and
historical warning-only reports; successful-update admission still rejects
refusals. Keep the local TestHomeMode alias private and satisfy helper lint.

PR: https://github.com/openclaw/openclaw/pull/134490

* fix(plugins): preserve declared catalog identity during upgrade integration

Carry the prepared, provenance-validated ClawHub package instead of discarding
it into a boolean. Suppress the declared installed counterpart without deriving
an npm identity from overlaid display metadata or hiding an npm namesake.
Keep lazy prepared catalog facts and first-normalized-record icon behavior.

Retain explicit ClawHub-only actions and npm-first dual-source actions, and
cover the selected source's pinned inspection metadata with existing tables.
The incoming duplicate-row cases fail before the provenance fact is retained.

PR: https://github.com/openclaw/openclaw/pull/134490

* fix(ci): include home isolation in PR anchor closure

Register the three runtime dependencies in the canonical extraction and trust inventory. Extracted planners and publishers now load the real home policy, context, and selection modules without stubs or weaker assertions. The existing extracted-anchor regression fails before this change and the full wrapper suite passes afterward.

* fix(update): hand failed upgrades to local coding agents

Route interactive update failures through triage after updater ownership is
released. Preserve the captured installation, invocation directory, bounded
diagnostics and original update result while the installed coding agent
repairs and verifies the machine using its existing permissions.

Keep background and JSON guidance consistent, preserve config references,
and fix resolved consent failures and selected catalog source provenance.

Validation: complete combined P2 review, 639 focused tests, 71 UI unit
tests, and four Chromium scenarios passed. Full changed-code checks passed
all typegraphs but stopped on one no-map-spread lint error in a test fixture.

Local integration checkpoint: fix that fixture and combine the current main
triage owner before final review, package proof, publication, or landing.

* fix(update): preserve configuration and verify upgrade recovery

Prefer npm before ClawHub only among declared plugin identities, preserving explicit source/version intent, artifact integrity and capability consent. Keep the exact installed beta cohort and require typed target absence before fallback.

Preserve authored environment references through both Doctor writers, resolve snapshot destinations at operation time, and keep migration-only metadata out of redacted snapshots. Avoid loading channel runtimes for unused pairing account facts while retaining captured migration-owner attribution.

Record activation safety at package/Git mutation boundaries. Keep installed-CLI recovery, verify runtime/native-service identity, fence Windows autostart, preserve child status, and avoid duplicating consumed notifications or rejecting completed install switches. Surface update-specific disconnect diagnostics without changing explicit-restart guidance in Model Setup.

Retain the upgrade-survivor first-hop, approval and installed-version oracles. Repair CI's type-only Doctor cycle and stale source-policy, final-Doctor and Teams whitespace expectations without weakening timeouts, gates or the main-owned Markdown fix.

PR: https://github.com/openclaw/openclaw/pull/134490

* test(msteams): align the corrected main whitespace fixture

* perf(ui): remove unreachable update translations

Remove superseded version-only verification copy and the unused idle label from the eager catalog. Keep identity-aware verification and all recovery guidance unchanged, align translation fixtures, and restore the existing merged startup budget without increasing its baseline or limits.

* fix(update): retain consent failures and isolate validation homes

Carry unresolved non-retained plugin capability refusals from missing-install
repair through post-core convergence as typed outcomes, preserving the existing
update failure and restart boundary. Keep usable retained artifacts and
transient fetch failures on their existing notice/warning paths.

Give test invocations a native process HOME before config imports and worker
creation. Preserve bounded live/profile context, report selection, installed
tool caches, and process-group/pipe-owned namespace cleanup or truthful
retention. Keep unknown or mixed explicit real-home selections closed.
Resolve the repo-owned staging helper from its owning cwd and await complete
PID readiness before cancelling native report fixtures.

Align the survivor recovery oracle with typed consent errors that intentionally
have no Doctor reason. Preserve strict plugin/code/version/core-step checks and
historical warning-only reports; successful-update admission still rejects
refusals. Keep the local TestHomeMode alias private and satisfy helper lint.

PR: https://github.com/openclaw/openclaw/pull/134490

* fix(plugins): preserve declared catalog identity during upgrade integration

Carry the prepared, provenance-validated ClawHub package instead of discarding
it into a boolean. Suppress the declared installed counterpart without deriving
an npm identity from overlaid display metadata or hiding an npm namesake.
Keep lazy prepared catalog facts and first-normalized-record icon behavior.

Retain explicit ClawHub-only actions and npm-first dual-source actions, and
cover the selected source's pinned inspection metadata with existing tables.
The incoming duplicate-row cases fail before the provenance fact is retained.

PR: https://github.com/openclaw/openclaw/pull/134490

* fix(ci): include home isolation in PR anchor closure

Register the three runtime dependencies in the canonical extraction and trust inventory. Extracted planners and publishers now load the real home policy, context, and selection modules without stubs or weaker assertions. The existing extracted-anchor regression fails before this change and the full wrapper suite passes afterward.

* fix(test): preserve source home when loading profiles

Read the explicitly selected profile with a non-login Bash command so
system and user login startup cannot replace the source HOME first.
Keep positional profile quoting, child-only HOME/USERPROFILE, existing
profile opt-in and test/native-home isolation unchanged.

The existing six profile-home matrix cases failed on Linux CI run
33536959196, job 99953769387. New exact-head Linux CI remains required;
this local repair does not refresh or admit the prior native proof.

PR: https://github.com/openclaw/openclaw/pull/134490

* fix(update): complete failure triage integration

Keep landed failure diagnosis after recovery and cleanup decisions without
letting diagnostic exports authorize activation or overwrite updater exits.
Preserve exact unsafe handoff and nested foreground results, consumed
notifications, successful install-root switches, typed consent failures and
update-specific disconnected guidance alongside main's triage takeover.

Contain diagnostic read failures inside the diagnostic owner so a completed
recovery still releases its lease and sensitive files. Retain phase-labelled
updater, recovery and diagnostic exits plus helper terminal completion.
Remove the trivial aggregate-error wrapper while preserving both failures,
and consolidate launchd/notification coverage into canonical test support.

Focused CLI, Doctor, handoff, UI and profile-home proof passed under external
synthetic homes. Complete integrated P0 review is scoped-clean; exact-head
Linux CI and native/package qualification remain with the parent workflow.
The unchanged main models-cli auth-login test-type error remains a follow-up.

PR: https://github.com/openclaw/openclaw/pull/134490

* test(update): split Doctor and service recovery fixtures

Move the existing Windows Doctor recovery matrix and shared fixtures into
focused files, and keep managed terminal-outcome tests in their existing
result helper. Preserve all case bodies, assertions, and hook cleanup.

Keep Windows restore failure in a local variable and narrow the triage
prompt-write fixture path before string matching. Scoped type-aware lint,
all affected existing suites, and independent follow-up review pass.

The full repository gate and final packaged Crabbox recovery and upgrade
proof remain required before landing.

* fix(update): retain plugin attempt spec on consent failure

* test(update): preserve runtime exports in option mocks

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-01 17:33:22 -06:00
Peter Steinberger
75bcd267f5
feat(skills): add personal libraries for shared Gateways (#134068)
* feat(skills): add personal libraries for shared Gateways

* fix(skills): validate ZIP imports with fs-safe 0.7.0

Use the published platform-package boundary and remove copied native assets.
Keep CLI bootstrap imports lazy, preserve sealed-worker defaults, and align
archive fixtures and current-main contracts with the stricter dependency.

* fix: own partial output staging before publication

* docs(skills): clarify Claude library delivery

* docs: leave skills release notes to release automation

* fix(skills): simplify library dispatch and preserve resource identity

Share the Workshop schema and descriptor across local and worker paths, remove redundant adapters and UI/import/CLI duplication, and preserve lossless directory identities in remote skill transfer. The cleanup removes 114 production lines; a child-process regression proves adjacent large file indexes cannot share authority.

* fix(skills): preserve declaration and compiled worker boundaries

Keep the exact protocol fragment types named during declaration emission to avoid TS7056 without changing runtime schemas. Observe resolved subprocess entry URLs in generation tests and derive full-tree audit roots from the canonical worker build registry.

Cold real Gateway and node-worker E2E: 2 passed. Protocol checks and package declarations passed. Fresh P0-scoped Codex autoreview returned no findings. Local artifact tests and hosted CI continue before landing.

* test(auth): type the optional stdin fixture property honestly

The ReadStream intersection kept isTTY required, so deleting an originally absent own property failed TS2790. Use the optional property surface the fixture actually owns, without a cast. The auth-login integration test and exact CI type-check stripe 4/5 pass; fresh P0-scoped Codex review is clean.

* fix(gateway): keep health discovery out of credential migration

Passive post-connect health synchronously loaded dormant Matrix credential checkers and blocked the Gateway event loop for 6.5 seconds on clean Linux. Keep loaded and configured channel inventory while leaving persisted-only discovery to setup and migration. Real resolver regression fails before and passes after; original Linux guard cases pass at unchanged deadlines. Health and inventory coverage: 49 passing tests.

* test(node): synchronize worker prewarm cancellation by readiness

Replace competing readiness and completion timers with a held HTTP request from the real child. Require peer close, cancellation rejection, and queued install completion, then join owned operations on every exit. The full installer suite passes all 27 cases; Windows hosted proof remains pending.
2026-09-01 13:15:37 -07:00
Peter Steinberger
4a49cebb37
ci: distribute lint and reuse native SDK declarations (#135302)
* ci: prepare only SDK declarations for lint

* test: align lint preparation resource fixture

* ci: distribute lint and publish reusable SDK cache

* docs: distinguish lint and package-boundary declarations

* docs(ci): clarify backend-local cache seeds
2026-09-01 11:05:47 -07:00
Peter Steinberger
83e75f5e31
fix(tooling): preserve compiled plugin loading in source Gateways (#135077)
Select the documented ESM-only tsx preload so compiled dependencies keep their import export conditions. Preserve existing cache policy and regression-test wrapper/direct preload module identity, TypeScript aliases, and CommonJS callers.

Fixes #134864.
2026-09-01 09:51:03 -07:00
Peter Steinberger
e6ae941d8b
fix(ci): native Windows Testbox rejects its session SSH key (#134828)
* chore(ci): inspect native Windows Testbox SSH identity

* fix(ci): install Testbox keys for native Windows SSH

Use the effective Windows OpenSSH administrator key file with SID-based restricted ACLs, preserving provider keys. Report hydration_failed after setup errors and print the actual native SSH user.

This repairs the workflow half only. Blacksmith CLI 0.4.57 still selects the absent runner account and has no supported native username override; CLI sync/run remains blocked. No dependency or audit-migration changes.

* fix(test): prepare title retention runtime before child deadline
2026-09-01 02:40:27 -07:00
Peter Steinberger
c904e712f9
fix(test): report one final failure per invocation (#134850)
* fix(test): report one final failure per invocation

Make public test CLIs own the final failure trailer after child execution, cleanup, and report publication. Internal execution entrypoints preserve process and signal lifetimes without duplicate reporting.

Closes #134841

* fix(test): register spawned test runners with Knip

* fix(test): classify spawned runners as development entries

* fix(test): include trailer helper in native wrapper closure

* test(pr): allow source directory in wrapper fixtures
2026-09-01 01:51:02 -07:00
Peter Steinberger
be0b14e5ae
fix(ci): keep native Windows Testbox alive during SSH (#134927)
Derive the running Windows sshd service's local listener ports instead of
matching Blacksmith's externally forwarded port against native netstat.
Match exact local established endpoints, preserve short-command marker
expiry, and report socket observation errors rather than treating them as idle.

Native before/after proof: the old monitor expired at 60 seconds during a
95-second SSH command; the repair survived and expired normally 72 seconds
after a subsequent short-command marker. Add executable monitor regressions
and document the lifecycle contract. Authentication and the separate CLI
username limitation remain outside this repair.

Fixes #134919. Related: #134718, #134828.
2026-08-31 23:57:56 -07:00
Galin Iliev
14e26a380d
fix(gateway): recover startup under load (#132186)
* fix(gateway): recover startup under load

* fix(ci): preserve gateway recovery checks after rebase

* refactor(ui): split bootstrap theme runtime

* fix(ui): handle reactive gateway refreshes

* fix(agents): preserve yielded requester settlement

* fix(cli): cover gateway readiness mocks

* test(ui): await scheduled profile appearance refresh

* fix(ci): keep daemon lifecycle suite within its limit

* fix(gateway): probe TLS readiness

* fix(gateway): remove unused probe exports

* fix(agents): gate continuations on completion owners

* refactor(agents): isolate ACP spawn results

* fix(ui): remove duplicate bootstrap ownership

* fix(ui): compact reconnect bootstrap work

* fix: complete continuation and bootstrap cleanup

* refactor(reply): split deferred final flush

* fix(ci): restore startup checks

* perf(ui): compact connection bootstrap

* perf(ui): defer connection bootstrap scheduler

* test(ui): await deduplicated bootstrap work

* test(ci): track qa setup suppression

* test(infra): split media persistence fixtures

* fix(ci): restore daemon lifecycle fixture

* test(auto-reply): cover revoked continuation delivery

* fix(ci): clear rebase lint drift

* test(agents): split terminal resolution state coverage

* fix(daemon): preserve interactive task logon

* fix(gateway): load current TLS runtime

* test(cli): align TLS probe mock

* perf(ui): defer workshop admission owner

* chore(ui): refresh boot manifest

* fix(ui): keep session roster immediate

* fix(reply): release continuation after commentary failure

* fix(ui): capture connected client for bootstrap work

* test(cli): keep lifecycle mock within lint budget

---------

Co-authored-by: Galin Iliev <galin.iliev@microsoft.com>
2026-08-31 23:09:09 -07:00
Peter Steinberger
f898552b50
fix(exec): prevent native GitHub fallback after managed profile loss (#134351)
* fix(exec): bind managed GitHub identity at local launch

Keep selected credentials private to OpenClaw-owned local commands and fail closed when their profile is missing or tokenless. Preserve non-secret supervision, node/sandbox isolation, and native Codex's documented separate contract.

Unify pipe/PTY argv ownership and retire service cancellation only on the anchor's closing receipt. Verified with secretless regressions, focused checks, a full build, and fourteen synthetic-credential live application cases.

* fix(exec): use canonical filesystem policy wrappers
2026-08-31 21:46:21 -07:00
Peter Steinberger
2c257e8839
fix(lint): report final failures after owned child cleanup (#134668) 2026-08-31 20:54:09 -07:00
Peter Steinberger
cc797c0491
perf(ci): shard UI checks and reuse SDK compiler inputs (#134528)
* perf(ci): shard UI checks and reuse SDK compiler inputs

* fix(build): resolve compiler namespace links from canonical parents

* fix(ci): normalize Windows compiler cache paths
2026-08-31 17:00:46 -07:00
Peter Steinberger
82d27ddc04
perf(build): reuse staged SDK declarations across profiles (#134414)
* perf(build): reuse staged SDK declarations across profiles

* fix(ci): refresh complete protected build cache generations

* test(build): expose SDK relocation cache identity on failure
2026-08-31 14:13:01 -07:00
Peter Steinberger
4ee565c6d2
perf(ci): remove repeated setup and balance complete test workloads (#134038)
* perf(ci): reduce Windows test setup and worker time

* perf(anthropic): defer auth loading until hook execution

* perf(test): narrow selected config startup work

* fix(ci): bound compiler memory on constrained lint runners

* test(ci): prepare media fixture input capabilities

* perf(test): scope selected unit configuration discovery

* fix(ci): release cancelled runs and route hybrid control jobs

* fix(ci): resolve merge bases before Testbox preparation

* fix(ci): align gateway recovery validation with runtime contracts

* perf(ci): avoid rename blob fetches during docs classification

* test(ci): consolidate Testbox base preparation coverage

* perf(ci): account for tooling work and shared build prerequisites

* fix(ci): declare serial plugin config worker ownership

* perf(ci): overlap independent performance Git lifecycle fixtures

* perf(ci): partition the complete plugin catch-all with native sharding

* perf(ci): reuse compiled session workers

* perf(test): compare complete SQLite snapshots natively

* test(ci): reuse race-safe process cleanup in report fixtures

* fix(ci): preserve the trusted PR helper closure

* test(ci): derive PR fixtures from the trusted helper closure

* perf(ci): reuse matching checkout for harness actions

* fix(ci): replace retained harness files during index export

* perf(ci): restore exact caches on hybrid runners

* fix(ci): include pnpm metadata in dependency archives

* test(ci): own direct compiler checkpoints in dist fixtures

* perf(ci): balance Windows projects by selected test costs

* perf(ci): seed UI transforms and scope tooling prerequisites

Keep package timeout observations joined across PID discovery, and test planner measurements against stable fixtures while preserving actual runtime-build singleton costs.

* docs(ci): drop the note for the already-landed Telegram type fix

* perf(ci): reuse preflight checkout and route hybrid macOS

* test(ci): wait for command readiness before timeout proof
2026-08-31 13:32:32 -07:00