Commit graph

972 commits

Author SHA1 Message Date
Ayaan Zaidi
856dbe9017
fix: spawned workers take over the chat you were talking in (#158992)
* fix(agents): keep spawned workers out of the current conversation

Agent-spawned workers (sessions_spawn thread=true, native and ACP) may only bind a new child thread. Channels whose spawn placement is the current conversation (Telegram, Feishu, LINE, generic current-conversation bindings) now reject thread=true instead of handing the user's chat to the worker. Legacy spawn-created bindings on those channels are ignored by the binding service, so the conversation routes to its normal agent again. Discord/Matrix child-thread sessions and defaultSpawnContext are unchanged.

* test(telegram): expect parent routing after worker-takeover upgrade

* test(agents): refresh prompt snapshots for child-only thread spawns

* test(telegram): keep parent-phase checkpoint codes in public upgrade evidence
2026-09-27 11:31:21 +05:30
RoboClaw
b29a7f67c0
fix(test): reap detached children in isolated Vitest runs (#157577)
Use Podman native init for PID 1 and verify HostConfig.Init before starting the isolated test container. Native diagnosis found the terminated watchdog retained as a zombie with the same process-start identity; the unchanged disappearance assertion passes with init. Preserve all isolation, cancellation, joining, snapshot-retention and assertion budgets; document the existing init-helper prerequisite.

Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-09-26 19:14:11 -07:00
Peter Steinberger
387689c418
fix(e2e): keep older upgrade baselines valid (#159150)
Scope the missing-load-path fixture to published drivers that admit invalid configuration before staging. Retain ordinary update and migration checks for older drivers, preserve exact-row reruns, and record fixture applicability in the published receipt.
2026-09-26 14:12:24 -07:00
Peter Steinberger
5a27fda950
improve(check): skip typecheck lanes for comment-only TypeScript edits (#158796)
* perf(check): skip typecheck lanes for comment-only TypeScript changes

Compare regular TypeScript sources against the merge base with the native parser and shared AST-aware token walker. Preserve ASI boundaries, directives, path lifecycle safety, and all non-typecheck gates; keep unguarded release metadata comparisons conservative.

* fix(check): reject lossy UTF-8 in comment-only typecheck classification

* fix(check): treat TypeScript pragmas case-insensitively in comment-only classification

* fix(check): keep token adjacency in comment-only typecheck classification

* test(check): satisfy array destructuring lint in classifier cases

* fix(check): keep tagged JSDoc pinned in comment-only typecheck classification

* fix(check): pin trivia around tagged JSDoc in comment-only classification

* fix(test): keep the comment-only classifier test on Node
2026-09-26 10:49:27 -07:00
Patrick Erichsen
8863d446a1
fix(ui): normalize official plugin icon tiles (#158745)
* fix(ui): normalize official plugin icon tiles

* test: block retired Kitchen Sink ClawHub flows

* docs: retire Kitchen Sink live ClawHub instructions
2026-09-26 01:37:46 -07:00
Hannes Rudolph
340092231c
docs: remove stale showcase section (#158575) 2026-09-25 21:11:35 -06:00
Dallin Romney
1276071e99
fix: let CLI commands exit during cache maintenance (#157884)
* fix: let CLI commands exit during cache maintenance

* test: declare empty data in synthetic worker fixture

* test: declare thread context in heartbeat fixtures

* test(cli): coordinate stalled cleanup through events

* fix(cli): isolate cache maintenance worker preloads

* fix(cli): respect Node permissions during cache maintenance
2026-09-25 14:26:22 -07:00
Peter Steinberger
b83fb77e5a
fix(e2e): give update channel switches their own Docker lane budget (#155961) 2026-09-25 13:18:37 -07:00
Josh Avant
39183aef1d
fix: preserve owed final replies when restart retires the sender (#157127)
* fix: preserve owed final replies when restart retires the sender

* fix: retain live owner checks during restart delivery

* refactor: consolidate final delivery rejection handling

* fix: distinguish source read failures from owner revocation

* fix: recover queued finals with original owner authority

* fix(agents): reject finals after source read failures

Keep custody retryable only for recognized restart retirement. Unknown source assertion failures cannot transfer continuity checks to recovery after the live closure disappears.

Prove source-read failure followed by intervening input cannot replay at either adapter handoff, with bound and unbound owners. Preserve genuine restart retention and revocation coverage; retain suppression reason literals in the batch recovery table.

* fix(ci): register channel owner policy scenario with Knip

The upgrade-survivor shell invokes this CLI by path. Model it in the shared executable-root list alongside sibling scenarios so the full-tree unused-file audit recognizes the real consumer.

The canonical unused-file check reproduced one unused file before registration and passes with zero entries afterward. pnpm deadcode:full and formatting also pass.

* test(gateway): await watcher-owned notice completion
2026-09-25 13:14:20 -05:00
Peter Steinberger
71bb516084
refactor(telegram): persist topic bindings through SQLite workers (#156688)
* refactor(telegram): move bundled thread bindings to workers

Await binding hydration and persistence through the existing plugin-state worker. Keep public synchronous SDK compatibility on the same owner while bundled callers use awaited operations. Preserve FIFO admission, current authority, committed acknowledgements, and shutdown drainage.

Validation on the frozen source: Focused binding, bot lifecycle and ingress tests, extension production and test typechecks, scoped lint, fresh review, a normal full build, and the built Telegram import profile.

This private checkpoint retains proof from base 78d5bedb34. It does not resolve the inherited TS1619/current-main qualification limit or the unchanged baseline TSGO_CORE_TEST_MAX_ROOTS unused-export finding. ACP startup metadata reads remain separately owned.

* test(telegram): dispatch sticker checks through the admitted handler

* test(telegram): verify published-driver binding upgrades

* test(telegram): keep upgrade runner private

* fix(telegram): await binding activity on bundled routes

* test(telegram): bind stop fixture to the active routing facade
2026-09-25 04:57:36 -07:00
Vincent Koc
4c9869c6fd
docs: fix 12 concrete defects from the ux audit remainder (#144128)
Missing prerequisites for two test lanes, a copy-paste slip in an SDK
sample, three undeclared identifiers in a quick start, a colon promising
keys named two paragraphs later, duplicated Related lists, two unlinked
pages that exist, an unbracketed placeholder, and a bare doctor invocation.

The thirteenth fix, an ffmpeg prerequisite on docs/tools/tts/quickstart.md,
is held back: every PR touching that page is refused by the secret scanner
before review.
2026-09-25 17:28:14 +08:00
Peter Steinberger
286b9b0780
test(update): verify same-version survivor payloads (#157849) 2026-09-24 22:16:49 -07:00
Peter Steinberger
3fadd8c3f7
perf(plugins): reuse and bound CLI compile caches (#157528)
Share build-scoped compile-cache ownership between the launcher and runtime. Reuse inherited namespaces, avoid redundant respawns, and retire superseded builds with best-effort seven-day and 512 MiB maintenance.

Testbox: 304 focused tests passed with one Bun-only skip; pinned changed-file checks passed. Thirty child launches used 41,544 bytes instead of 1,185,000 bytes, and same-build launch time fell from 2.46 s to 1.22 s. Persistent external-plugin source capture reuse remains outside this scoped change.
2026-09-24 20:18:39 +00:00
Peter Steinberger
881ad1ca49
fix(ci): scope PR tests to affected consumers (#156729)
* ci: narrow PR tests by import and dependency impact

Resolve affected tests through the existing runtime import graph, workspace
and SDK aliases, configured Vitest inputs, and explicit policy owners.
Compare exact-base dependency closures instead of treating every lockfile
or package metadata change as global. Keep documentation and localization
data out of PR Node test rows.

Preserve canonical execution metadata and complete automatic main coverage.
Retain diagnostic fallbacks for global inputs and unverifiable ownership.
The 40-run replay reduces explicit fallbacks from 30 to 6 and median selected
jobs from 132 to 122, with no unexplained historical failure omissions.
The remaining large import closures do not meet the requested cost target.

* fix(ci): run test selector parsing under Node

Bun workers cannot provide the Node TypeScript parser used by the selector. Resolve the existing Node executable at the scanner boundary and retain that built-in-only dependency in materialized wrappers and standalone fixtures. Preserve real shard inventory exports in the command planner fixture.

* test(ci): isolate changed-gate compiler fixtures

Source-aware selection reaches inline compiler checks that bypassed the fixtures’ subprocess stubs, repeatedly compiling the real repository during gate-order and root-lint tests. Bind that owner to the shared synthetic recorder while preserving the real CLI, lint execution, serial-order assertions, and failure sentinels.

* fix(ci): retain compiler gates for TypeScript catalogs

Catalog-only PRs suppress Node test rows, but their TypeScript modules still need compiler validation. Admit the existing check owner independently of Node tests while preserving documentation and JSON-only skips. The catalog fixtures retain main and manual coverage and distinguish compiler admission from test execution.
2026-09-24 02:46:40 +00:00
Peter Steinberger
01b253c681
refactor: retire pre-June config and upgrade test support (#156859)
* refactor: retire pre-June config and upgrade test support

Retire obsolete Doctor keys and their runtime fallbacks. Older configurations use the documented 2026.9.5 Doctor bridge; current upgrade verification starts at June 2026 while historical receipts remain readable.

* fix: preserve retired config when the upgrade bridge is skipped

* test: align upgrade fixtures with retained migration contracts
2026-09-23 19:26:23 -07:00
Peter Steinberger
36baa2cd98
fix(test): preserve the first Vitest timeout
The project runner replaced timed-out configurations with another attempt
and could turn their failed hooks into a green job. CI run 35928401414,
job 107409413294, masked seven settlement-hook failures this way.

Remove replacement dispatch and its expanded retry deadline. Keep the first
watchdog failure even when a child exits zero, retain incomplete reports,
and preserve process/cache cleanup.

Proof: the temporary fail-first test failed the real CI shard entry point
with exit 143 and one attempt. The runner owner passed 20 standalone runs
and three CI-config replays on Testbox; shared-helper importers passed.
2026-09-23 18:27:19 -07:00
Peter Steinberger
60d25b947d
ci: shorten and split real-Gateway UI validation (#156270)
* ci: shorten real-Gateway UI validation

Use runtime-only preparation while build-artifacts retains SDK declaration checks. Preserve four exhaustive Gateway tours in full manual and release validation with their faster owner-boundary siblings in ordinary CI.

* test(ci): align real-Gateway preparation guards

Keep the paired runtime and UI build contract, assert the existing runtime-only mode, and document SDK validation ownership in the artifact job.

* ci: split real-Gateway UI validation into two jobs

* fix(ci): declare the shared real-Gateway parallel inventory

* test(ci): require manifest strings before decoding

* ci: balance standalone UI proofs across Gateway shards

* ci: defer desktop transport tour to release validation

* perf(test): reuse prebuilt Control UI assets

* test(ui): align Gateway fixtures with catalog and build contracts
2026-09-23 08:04:22 -07:00
Peter Steinberger
3e4ab6bed8
refactor: retire pre-June import and verification compatibility (#156285)
* refactor: retire pre-June import and verification compatibility

Remove pre-June task, flow, and plugin-state sidecar imports, obsolete
runtime chunks, package/installer validation exceptions, the old MCP
attachment fallback, and the April self-upgrade lane with its orphan helpers.

Leave retired data files untouched and document migration through 2026.6.1.
Preserve June-and-later contracts and September delivery recovery receipts.

Refs #156190

* docs: route legacy upgrades through 2026.9.5

* test: await Telegram fixture lifecycle events

Replace the setup stopwatch with the actual stop event or terminal run outcome. Keep cancellation assertions and outer execution bounds, and prove early terminal outcomes fail promptly.
2026-09-23 02:22:22 -07:00
RoboClaw
5e5f9c2755
fix(anthropic): finish Opus 5.5 defaults and thinking display (#156093)
* fix(anthropic): finish Opus 5.5 defaults and thinking display

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* fix(anthropic): preserve authored model selections during CLI setup

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* test(qa): assert rolling Opus defaults without redundant resolution

Replace the ineffective real-time deadline probe with deterministic fake-clock coverage beyond the watchdog grace.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* test: align remaining Opus default fixtures

Keep explicit version pins, assert immutable numeric pricing, and consolidate PDF selection fixtures without dropping cases.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

---------

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-22 23:59:18 -07:00
Dallin Romney
35b95b2aa6 feat(xiaomi): add MiMo V2.6 support 2026-09-21 22:27:51 -07:00
Dallin Romney
2a2d28d578
feat(xai): add Grok 4.7 support (#155379) 2026-09-21 20:27:04 -07:00
Peter Steinberger
836aeaa718
ci: defer maintainer tooling on product-only PRs (#153962)
* ci: defer unrelated report composition to release validation

* ci: keep unrelated tests out of release owner watches

* ci: preserve exact report tier owner routing

* ci: defer full tooling family on product-only PRs

* test: align CI guards with tooling owner routing

* ci: retain canonical UI consumers with the tooling tier
2026-09-21 22:31:16 +00:00
Peter Steinberger
3a632e1dd0
test(update): cover multi-provider published upgrade turns (#155158)
* test(update): cover multiple providers in upgrade survivor

* test(update): use supported live survivor model configuration

* test(update): include command helper in isolated assertion fixture

* test(update): align survivor credential fixture assertion

* test(update): refuse live selections for frozen survivor runners
2026-09-21 14:02:12 -07:00
Peter Steinberger
438046f8d9
fix(test): prevent Windows worker pipe inheritance
Use process workers on Windows so concurrent Vitest workers do not share temporary inheritable subprocess pipe handles. Preserve worker limits, file parallelism, and strict process/output cleanup. Route shared worker-policy changes through Windows CI.
2026-09-21 12:15:56 -07:00
Peter Steinberger
ed5937fbd9
improve: profile concurrent Gateway sessions with live OpenAI (#154845)
Some checks are pending
Native App Locale Refresh / resolve-base (push) Waiting to run
Native App Locale Refresh / Verify generated PR App permissions (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ar (push) Blocked by required conditions
Native App Locale Refresh / Refresh native de (push) Blocked by required conditions
Native App Locale Refresh / Refresh native es (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fa (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native hi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native id (push) Blocked by required conditions
Native App Locale Refresh / Refresh native it (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Node Runtime Conformance / TypeScript contracts (push) Waiting to run
Node Runtime Conformance / Rust workspace (push) Waiting to run
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Waiting to run
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / no-tabs (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
* improve: profile live Gateway concurrency

* fix: align Gateway benchmark with CI contracts
2026-09-21 13:33:16 +00:00
Peter Steinberger
52e2aafccf
fix: keep web chat steering working after completed turns (#154424)
* fix: keep web chat steering working after completed turns

* fix: observe completed progress refresh runs

* test: wait for durable startup recovery admission

Observe committed session rows before stopping startup recovery. Dispatch invocation precedes durable admission, so stopping after a call-count assertion can cancel the write and leave abortedLastRun set. Preserve restored-store capacity sequencing and wait for both stores without assuming recovery order.

Controlled original synchronization reproduces the CI assertion failure; corrected synchronization passes. Ten startup and cancellation cases pass in 26.64 seconds, with owner types, lint, formatting, line-cap guards and independent review through P2 clean.
2026-09-21 05:02:36 -07:00
Peter Steinberger
1f4ddebf12
fix(ci): preserve published plugin bytes in upgrade fixtures (#154374) 2026-09-21 04:08:34 +00:00
Peter Steinberger
fa1640994c
ci: reuse workers across provider test files (#154290)
Use the shared cleanup runner for provider test shards and track xAI fetch mocks so they cannot leak into later transport tests. The same 73-file shard improved from 88.658s to 41.593s across three runs per setting. All four native provider partitions passed: 290 files, 5,234 tests, and one existing opt-in live-test skip.
2026-09-20 21:07:08 -07:00
Peter Steinberger
0a9d65e3b7
ci: reuse verified test workers across jobs (#154095) 2026-09-20 15:32:27 -07:00
Peter Steinberger
3b76ad8461
docs(agents): require root-causing flaky tests and budgeting CI time
A test failure without a related change is a defect: re-running, re-pushing,
or refreshing a PR to get green is prohibited, and a failure outside the diff
is not "unrelated" until its cause and owning fix are identified. New or
changed tests state their measured cost and stay within the budgets in the
testing guide, which gains a cost-budget section and a flake-triage recipe.
2026-09-20 13:04:08 -07:00
Peter Steinberger
814f26c9e6
fix(qa): bootstrap isolated fixtures beside an installed Gateway (#153659)
* fix(qa): isolate child profiles from installed gateways

* test(qa): separate child environment isolation coverage
2026-09-20 11:55:45 -07:00
Peter Steinberger
8b2c9fbcc8
fix(test): reuse compiled runtime workers across local runs (#153558)
* perf(test): reuse verified runtime worker artifacts locally

Retain joined compiler generations in exclusive checkout-local slots and
reuse their content-verified outputs on unchanged invocations. Preserve
source, output, resolution, toolchain, and borrower-lifetime checks while
avoiding repeated native compilation. CI routing and fresh-build policy,
Bun, custom loaders, test assertions, and timeouts remain unchanged.

Batch prepared fixture copies, relocate the complete fs-safe runtime
closure with its native packages, and inject one compiler fault child
per lifetime so receipt writers cannot race.

Related: #132712, #139428.

* fix(test): repair worker cache harness CI fixtures
2026-09-20 03:02:54 -07:00
Eric Curtin
f786111973
docs(providers): expand llmman guidance and add hybrid inference (#139606)
* docs(providers): expand llmman guidance and add hybrid inference

Rewrite docs/providers/llmman.md into a full provider topic page: modes
table, auth rules, getting started, model discovery, smoke tests, vision,
configuration tabs, recipes, advanced accordions, troubleshooting.

Add a Hybrid inference section covering llmman.hybrid/<local>,<provider>/<model>
refs (qwen3.8 + openai/gpt-5.6-luna), routing rules, key handling,
x-llmman-route pinning via provider headers, and how it composes with
OpenClaw fallbacks. Document llmman.provider/... hosted refs.

Use qwen3.8 as the reference model throughout, call `llmman serve` with no
arguments everywhere (daemon settings go in its environment), and adopt the
LLMMAN_API_KEY=llmman-local / apiKey: "${LLMMAN_API_KEY}" convention.

Cross-link from local-models, local-model-services, model-providers,
infer CLI, provider index, and the models FAQ. Add the new provider index
label to the zh-CN glossary.

Verified against llmman v0.1.334 with qwen3.8: text and vision probes via
openclaw infer model run, a full tool-calling agent turn, hybrid routing
(local by default, cloud on pin or oversized body), and
chat_template_kwargs passthrough for thinking control.

Co-authored-by: sallyom <11166065+sallyom@users.noreply.github.com>

* docs(llmman): correct verified runtime guidance

Clarify Qwen thinking compatibility, daemon-wide hybrid budgets, and idle service lifetime. Preserve the existing integration and live proof.

Co-authored-by: sallyom <11166065+sallyom@users.noreply.github.com>

* docs(llmman): align service startup reference

Keep the shared local-service example consistent with llmman optional model preloading.

Co-authored-by: sallyom <11166065+sallyom@users.noreply.github.com>

---------

Co-authored-by: sallyom <11166065+sallyom@users.noreply.github.com>
2026-09-19 10:07:03 -07:00
Peter Steinberger
f6d3da2272
ci(test): size Vitest workers from measured CI headroom (#152864)
Use measured CI-only six/eight-worker memory tiers for roomy serial self-hosted jobs. Retain local behavior, actual-host fallback limits, Gateway exclusivity, unproven group caps, and historical timing floors. The twelve predefined Blacksmith probe samples passed; native PR CI remains a separate validation step.
2026-09-19 06:37:55 -07:00
RoboClaw
91dd566294
fix(test): report local Gateway transport failures early (#152309)
* fix: avoid proxy-blocked local UI E2E readiness waits

Fail early on restricted loopback transport, provide a secretless rootless isolated runner, and preserve meaningful HTTP readiness failures without changing Gateway semantics or proxy policy.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: avoid proxy-blocked local UI E2E readiness waits

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: fc4d675b-1e2a-45e0-9494-70f01e9fdd35

* fix(test): report local Gateway transport failures early

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 69d67c9d-c404-4ccf-ab4e-34ca9f134cdf

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 01:57:53 -07:00
RoboClaw
7191378214
fix(test): run local Gateway tests behind protected exec egress (#152318)
* fix(test): run local Gateway tests behind protected exec egress

Worked on by:
- @steipete

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: b694aecd-a905-4c37-b65d-e05463cc1a7a

* fix(test): register isolated Vitest process entry for audits

Model the actual path-launched container entry in the existing development-root registry so full-tree dead-code checks follow its imports.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(test): retain isolated inputs until Podman processes join

Preserve nested unjoined host-command failures even when the container is absent. Retain the snapshot and original error rather than releasing inputs or suppressing unresolved cleanup as a signal exit.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-18 18:36:58 -07:00
Peter Steinberger
3c4c111b0f
feat: automatically update idle headless nodes (#151545)
* feat(node): update headless runtimes automatically when idle

Stage private packaged node runtimes and activate only after all owned work
and cleanup settle. Preserve pairing and launch options, keep automatic
activations at least 12 hours apart, and leave shared-state migration and
Gateway installation ownership with the normal updater.

Document defaults, opt-outs, runtime version discovery, and recovery.
Support recoverable Windows selector replacement across service restarts.

Refs #151462

* fix(node): complete auto-update integration and settings defaults

Capture the launcher in compiled test runtimes and trusted wrapper inventories, register the package update proof, and use the canonical Kysely read path. Preserve the inherited enabled state in the config UI and align caller tests with the node shutdown lifecycle.

* fix(node): preserve retained plugin work during automatic updates

Require an explicit idle result from plugin commands, preserve older-plugin work, and connect bundled lifetime owners to automatic node updates. Join canceled inference and failed terminal cleanup before command settlement; keep historical state repair with Doctor. Document compatibility and extend installed-package proof for retained legacy plugin work.

* test(browser): align idle-work fixtures with runtime exports

* test(browser): extract proxy request fixtures

* test(node): retain idle assertions across native cleanup
2026-09-18 06:20:27 -07:00
Peter Steinberger
f4e9d06bd3
fix(e2e): verify worktree repair stays in Doctor (#150365)
* fix(e2e): prove Doctor-owned worktree repair

Keep the published project-worktree upgrade scenario aligned with Doctor-only repair after #150110. Verify updater Doctor on one specimen and startup preservation, explicit Doctor repair, and stable restart on an independent published-owner specimen.

* fix(e2e): prepare fixture schemas through Doctor

Upgrade the independent published specimen through the existing Doctor migration owner before Gateway startup, preserving legacy workspace metadata and exact session and transcript bytes for the subsequent workspace repair proof.

* fix(e2e): resolve defining Doctor package owners

Distinguish defining function chunks from generated forwarding entries with the installed package parser while retaining the existing general export resolver behavior and package hash checks.
2026-09-17 04:32:06 -07:00
Ayaan Zaidi
ba057a52ae
fix(onboarding): default to Full tools and unify catalog discovery (#150596)
The diff includes an unchanged four-test file split to meet the line limit; production shrinks by 54 lines.

## What Problem This Solves

New local setups use Coding, which excludes messaging. The existing `openclaw` setup helper is also missing from the tool catalog.

## Why This Change Was Made

The owner approved Full for unprofiled local onboarding, including reruns, and the helper's group allow/deny membership. This intentionally revises #39012. The onboarding default has one writer. Security and Agents now save Full consistently; the UI uses the canonical tool catalog instead of a duplicate list.

## User Impact

New setups get broad tool selection. “Available tools” is distinct from “Execution permissions”; Full does not mean Full Access.

## Evidence

Real isolated onboarding: `coding` before → `full` after. [Commands and browser proof](https://gist.github.com/obviyus/3ba9dd83878ff416c0c462468926e79a).

| Before | After |
| --- | --- |
| ![Security before](https://gist.githubusercontent.com/obviyus/3ba9dd83878ff416c0c462468926e79a/raw/2a71c2931e6ab1106951669898da69b298200603/before-security.png) | ![Security after](https://gist.githubusercontent.com/obviyus/3ba9dd83878ff416c0c462468926e79a/raw/8a283ae74173f52403f233bd954180dc9162ed11/after-security.png) |
| ![Catalog before](https://gist.githubusercontent.com/obviyus/3ba9dd83878ff416c0c462468926e79a/raw/e309d6966c18457200c4a4b3095a5feda77173a1/before-catalog.png) | ![Catalog after](https://gist.githubusercontent.com/obviyus/3ba9dd83878ff416c0c462468926e79a/raw/1bc4551e27cdd72675119ec96c078dab10e73c36/after-catalog.png) |

## Compatibility

No migration or new settings. Existing explicit profiles and independent execution rules stay intact during normal upgrade. Re-onboarding an unprofiled config selects Full. Helper membership extends automation/OpenClaw group allows **and denies**; owner and sandbox checks remain.

[Compatibility proof](https://github.com/openclaw/openclaw/pull/150596#issuecomment-5709214174): published 2026.9.3 updater → candidate `d80239aace2d`, healthy Gateway, 12 Doctor scenarios twice, and 202 migration tests pass. The conflict-only rebase preserves those profile/helper changes. Existing Doctor repairs can rewrite conflicting profile/allow settings; tested helper policy access survives.

## Consumers

CLI, wizard, setup repair, Gateway catalog, and Tools UI share existing owners. Full also selects available optional plugin tools.

## Invalidation

Existing config reload and catalog refresh remain unchanged.

## Tests

412 core/plugin tests and 152 UI tests pass on the earlier proof merge; 54 affected UI tests pass after the conflict-only rebase. Type-aware changed lint, core types, script/root types, format, architecture, unused-export, UI size, and docs checks pass.

CI corrections move the two optional-plugin cases into a focused test and update the full settings save/reload test. All 134 cases pass locally, including the repaired E2E, and the new file-growth check passes. Production behavior is unchanged.

The prior CI run also hit Slack test/type failures from #150608, reproduced on its main and absent on its parent. Main now fixes those separately in `8f463a22`; this PR carries no Slack edits.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-17 12:46:58 +05:30
Peter Steinberger
388584f9d9
fix(test): verify workspace repair during update (#150375) 2026-09-16 18:34:12 -07:00
Peter Steinberger
638b0d3646
fix(cli): ignore unset home overrides in path displays (#149897)
Reuse canonical home-value normalization in both display-prefix producers so
literal undefined/null overrides show fallback home paths with ~. Preserve
home resolution, path matching, and valid override labels.

Original-source regressions failed 12 sentinel cases with nine controls
passing. Owner/sibling proof passed 181 tests with four existing Windows-only
skips; all 21 final display cases passed. Selected checks and fresh P2 review
passed after resolving the added test file line-count failure.
2026-09-16 13:38:44 -07:00
Peter Steinberger
a3017f76b5
improve(upgrade): cover project workspace startup migration (#150077)
* test(upgrade): cover project workspace startup migration

* fix(upgrade): keep survivor catalogs dependency-free

* test(upgrade): copy current catalog into frozen target fixtures

* test(upgrade): recognize formatted shutdown results
2026-09-16 09:36:42 -07:00
Peter Steinberger
c1f00edb04
fix(ci): reject line-cap growth on pull requests (#149622)
* fix(ci): ratchet line caps without blocking main

Independently green PRs can combine to exceed max-lines and block main.
Use explicit hosted warnings and an oxlint-backed changed-file growth check.
Keep canonical caps, suppression inventory, and strict local/landing lint.

* fix(ci): preserve warning counts and isolated lint runners

Count native colored diagnostics and load cumulative config only when
warning mode is requested. Restore strict-runner fixture isolation and
accurate hosted warning totals.

* fix(ci): align line-cap ratchet with global warnings

Main now warns for all max-lines scopes, making hosted-only demotion redundant. Keep the PR growth ratchet and document the shared warning policy and shrink-only maintenance.
2026-09-16 04:25:37 -07:00
Peter Steinberger
135a685b5d
fix: allow cross-provider messaging by default (#149875)
* fix: allow cross-provider messaging by default

* docs: clarify cross-provider isolation settings
2026-09-16 01:54:39 -07:00
Peter Steinberger
b884e39bb2
test(e2e): select prerelease companions, keep failed outcomes, retain Doctor diagnostics in the upgrade survivor (#149705)
* test(e2e): repair upgrade survivor fixtures and diagnostics

Select published prerelease companion cohorts through moving tags, record
unpublished companions without dropping the remaining operator-state proof,
keep unknown and failed update outcomes, and retain bounded Doctor migration
evidence. Separate historical keyed rosters from explicit ownership.

Consolidates harness work from upd-matrix-L7, upd-matrix-L8, and
upd-matrix-L9, with availability and diagnostics findings from upd-matrix-L4
and upd-matrix-L6. Product code is unchanged.

* test(e2e): isolate survivor fixture execution

Materialize injected shell runners so the Darwin Bash guard can replay them. Use the current source redactor in installed-version unit diagnostics so existing build artifacts do not consume the command timeout. Preserve all assertions and timeout values.
2026-09-16 01:40:47 -07:00
Peter Steinberger
86a119a3a1
fix: preserve context and ownership across compaction (#149840)
Preserve complete Anthropic checkpoints, bound branch summary requests,
and keep recovery attached to the active session. Clear inherited runtime
claims when branching or restoring a checkpoint, preserve committed
compactions through later cancellation, and count native completions once.

Remove obsolete test-only compaction exports and copied retry tests.
Exercise real provider compaction, SQLite reopening, and tool-only memory
recall through the supported transport and managed-runner paths.
2026-09-16 01:33:06 -07:00
Peter Steinberger
759bdc439e
chore(lint): make max-lines a warning (#149805)
* chore(lint): make max-lines a warning

Peter decided on 2026-09-16 that max-lines should warn in CI rather than
block main. The chat-pane-render.ts failure exposed unnecessary lint
burden after #149697.

Change all six max-lines scopes to warn while preserving every threshold
and all other rules. Document warning behavior and the retained suppression
ratchet. The runners and CI already preserve warning output and exit codes.

Proof: check-changed, formatting, and git diff --check pass. The current
chat-pane-render.ts passes single-file core lint; the exact 702-line
revision from failed main run 35060497703 prints one max-lines warning and
exits 0 through run-oxlint with CI-style output. The sample UI tsconfig
command hit the existing nested-checkout declaration boundary, so proof
uses CI's source-only core tsconfig.

* test(lint): expect max-lines warnings

Align the existing config-policy test with Peter’s 2026-09-16 decision. Preserve all six budgets and exclusions. The prior PR run correctly exposed the stale error expectations.

Proof: all 13 oxlint config tests, check-changed, and git diff --check pass. Fresh independent review found no actionable P0/P1 findings.
2026-09-16 00:04:18 -07:00
Peter Steinberger
ec66133ba0
chore: cover worker state in published upgrade tests (#149487)
* test: add worker state upgrade survivor cells

Add opt-in Projects Doctor and terminal task/flow restoration cells using the unchanged published updater, verified package bytes, and the canonical survivor lifecycle. Preserve failed synthetic state until the outer Docker owner has joined.

Validation: 161 focused tests, selected changed checks, and P2 review. Actual package upgrade cells remain separately qualified against frozen candidate artifacts.

* test: activate taskflow survivor fixture on Gateway startup

* test: clean worker runtime with container ownership

* fix(test): preserve Docker status through exit traps
2026-09-15 21:51:41 -07:00
Vincent Koc
f3579e762e
fix(e2e): use a maintained ClawHub install fixture (#148902)
* fix(e2e): use a maintained ClawHub install fixture

* test(e2e): model Docker package mount in wrapper probe
2026-09-16 11:57:19 +08:00
Peter Steinberger
1ac3cf63b8
fix(ci): publish receipts for successful upgrade checks (#148245)
Publish bounded, host-redacted receipts after successful published-baseline
upgrade runs. Reuse the diagnostic owner and retain the initial post-core
result separately from repair and recovery output. Preserve Docker outcomes
and existing failure reports.
2026-09-14 13:01:06 -07:00