Commit graph

10941 commits

Author SHA1 Message Date
Peter Steinberger
8a981770fe
fix(tooling): verify Darwin zombie groups after EPERM
Darwin killpg excludes zombies and returns EPERM when no signalable group
member remains. Strict normal-exit cleanup mistook this terminal state for
a surviving process group, even when later drainage observed termination.

Reuse the existing zombie census for Darwin, including BSD state flags,
and reconcile a group reaped during the census with a fresh ESRCH probe.
Both observation and termination require positive completion evidence;
live, mixed, and uninspectable groups retain their cleanup failures.
Keep snapshot work inside the existing escalation and drainage deadlines.

Native same-uid Z and ZN groups reproduce EPERM for signal 0 and SIGKILL.
The original owner fails four regression cases; the repair passes all 13.
Shared owner/output tests pass (146 passed, one platform skip). The full
mac-elevation-host shard passes all 123 cases in 383.63s; final metadata
replay passes all 13 selected cases. Independent review is scoped-clean.
Production delta: +44 lines for bounded Darwin termination evidence.

Test cost: node scripts/run-vitest.mjs test/scripts/managed-child-process.termination.test.ts --maxWorkers=1: 5.83s wall; node scripts/run-vitest.mjs test/scripts/managed-child-process.tree.test.ts --maxWorkers=1: 5.05s wall.
2026-09-30 18:04:04 -07:00
Peter Steinberger
dac3c15a0d
test(core,plugins): remove low-value tests (batch d119) (#162202)
* test(pr): deslop t0431 tests

* test(plugins): deslop t0430 tests

* test(mattermost): deslop t0415 tests

* test(telegram): deslop t0427 tests

* test(process): deslop t0424 tests

* test(state): deslop t0434 tests

* test(voice-call): deslop t0437 tests

* test(telegram): deslop t0428 tests

* test(gateway): deslop t0443 tests

* test(agents): deslop t0436 tests

* test: preserve lifecycle and authorization contracts in d119
2026-09-30 23:33:21 +00:00
Josh Avant
e09dfc8897
feat(android): add daily internal testing builds (#161812) 2026-09-30 18:01:07 -05:00
Peter Steinberger
bfdb432570
fix(cli): release plugin resources when help finishes (#160181)
* fix(cli): release plugin resources when help finishes

Uncached CLI metadata loads now use the existing inspection acquisition when an executable invocation owns them. The source-plugin regression verifies that invocation release joins module disposal. Caller-owned programs retain their existing lifetime.

* fix(plugins): release retired registry preparation scope

Create the aggregate retirement observer outside the registry preparation
scope so it retains only child waiters. Preserve per-observation options,
cleanup ordering, failure identity, and deferred consumer results.

The unchanged cold registry-retention regression failed on the CI Bun
runtime before this change and passes after it. The original seven-file
shard passes all 172 cases, and Node retirement coverage passes 20 cases.

* fix(ci): carry the chat attachment lint repair

Carry the exact two-file fix from 2e95cdba84
(#160159). Move the unchanged image decoder into its existing helper
to restore the 700-line limit without changing attachment behavior.

Targeted lint and all 21 attachment tests pass on this candidate.
Independent review found no actionable defects.

* test: retain complete lifecycle helpers in lease fixtures

* test: isolate local command fixtures and join recovery cleanup

* test(ci): preserve CLI runtime ownership and harness staging

Keep the moved CLI command fixture in its runtime prerequisite group and
preserve complete agent coverage across the core and CLI process owners.

Carry the test-only trusted-harness fixture fix from #160024.

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>

* fix(tests): scope Vitest preload to test workers

Apply the jsdom adapter only at Vitest worker entry points while preserving
package-local runtime resolution. Ordinary Workers may inherit the preload
without having a Vitest dependency. Exercise default native inheritance and
await worker termination.

Copy the static-check evidence helper into lint fixtures so the real oxlint
entry point can load its current import closure.

Validation: reproduced both original failure causes before repair; all 76
affected tests pass (351.44 seconds in Vitest), as do canonical changed-file
checks and independent review.

* test: isolate public runtime surface planning fixtures

Verify public runtime entries and packaged assets with a synthetic publishable plugin after the Diffs forwarding APIs were retired. Preserve the existing planner assertions without depending on one bundled plugin layout.

* fix(ci): carry shared lint repairs into CLI preparation

* test(tooling): repair extracted PR and npm fixtures

* test: retain gateway cleanup and isolate Windows temp paths

Close the prewarm gateway when client connection fails and retain cleanup
errors during orphaned recovery. Keep Windows-under-Bun coverage on
host-owned temporary directories, matching the fixture fix in #160985.

Validation: 13 focused fixture tests and canonical changed-file checks.

* fix(ci): keep extracted manifest within script contracts

Resolve inherited manifest lint errors without changing job selection. Move its closed true/1 flag parsing to the dependency-free argument owner and include that helper in trusted fixture copies. Validation passed 718 tests with eight existing skips, canonical changed checks, fixture lint, and independent review. The 74-case argument helper file took 1.79 seconds at one worker with warm inputs.

* test(state): apply upstream snapshot custody fixture isolation

Reuse the fixture repair from #161598 (af16b80a22). Keep the real exit callback and every custody assertion while isolating the synthetic cleanup owner from preceding files.

* test(pr): drain fake GitHub streams before exit

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-30 15:28:57 -07:00
Peter Steinberger
eb65a6c5f1
ci: overlap iOS simulator preparation with builds
Select the simulator before compilation, then boot and slim that exact
simulator alongside the app build. Join preparation before XCTest, retain
its failure log, and bound a hung join without changing test selection or
build settings.

Validate both focused groups on cold and warm native runs (139 tests each),
plus preparation failure and timeout controls. Linux proof includes full
test types, the whole tooling config, changed checks, source contracts,
and both preflight harness shapes for PR and scheduled-main inputs.
2026-09-30 14:48:59 -07:00
Peter Steinberger
59b8097d75
test(core,plugins): remove low-value tests (batch d117) (#162104)
* test(cli): deslop t0406 tests

* test(agents): deslop t0407 tests

* test(onboarding): deslop t0404 tests

* test(infra): deslop t0411 tests

* test(openai): deslop t0412 tests

* test(telegram): deslop t0418 tests

* test(tool-call-repair): deslop t0413 tests

* test(plugins): deslop t0419 tests

* test(codex): deslop t0408 tests

* test(agents): deslop t0417 tests

* test: retain distinct lifecycle and transport contracts in d117

* test(infra): apply update opt-out in restored fixture
2026-09-30 21:48:00 +00:00
Peter Steinberger
be25a24f10
test(core,plugins): remove low-value tests (batch d118) (#162138)
* test(scripts): deslop t0421 tests

* test(node-host): deslop t0420 tests

Remove repeated policy-drift inputs, generic route checks, and replays of
pager, wrapper-depth, and approval-plan owner tests. Consolidate durable
approval fixtures and lifecycle cleanup; infer mock result types instead
of casting partial copies of production contracts. Preserve Vitest routing.

The 50% campaign target is not reached. Retention ledger below names each
remaining case (table rows expanded), using the requested rules:
1 = unique covered execution path; 2 = historical regression; 3 = distinct
security boundary. No unrelated behaviors were combined to reduce counts.

- Native cwd refusal: 2, d88e10a752, preserve preparation-refusal classification.
- Lost companion response: 3, disabled fallback must never replay locally.
- Already-cancelled command: 1, entry cancellation return.
- Cancelled local completion: 1, post-run cancellation return and signal forwarding.
- Pending Mac cancellation: 1, post-bridge cancellation return without replay/publication.
- Medium-risk auto review: 2, 3b26947669, ordinary audit-related argv must reach review and execution.
- Auto review without a plan: 3, unbound commands cannot obtain model authority.
- Login-shell startup: 3, startup effects cannot bypass review through a forged plan.
- Reviewer asks: 1, defer-to-human switch branch.
- Reviewer denies: 3, explicit model refusal cannot execute.
- Approved env wrapper argv: 3, preserve approved positional execution semantics locally and over the bridge.
- Transparent versus semantic env wrappers: 3, only transparent carriers may unwrap into an allowlisted executable.
- Nested safe-bin chains: 3, bind rewritten shell payloads to canonical safe-bin paths.
- PowerShell wrappers: 1, non-POSIX transport must bypass POSIX rewriting.
- PATH-token allowlist execution: 3, launch the canonical approved executable rather than a mutable PATH alias.
- Live policy revocation at commit: 3, recheck authority after awaited persistence before real launch.
- Live policy revocation at callback: 3, the launch adapter must recheck immediately before spawning.
- Live policy unchanged at callback: 3, positive control proves authorized real execution succeeds.
- Unbindable auto executable identity: 3, model review cannot authorize an unbound dispatch chain.
- Human executable identity drift at commit: 3, changed executable resolution invalidates the approved command.
- Script drift after commit: 3, recheck mutable operands after the persistence await.
- Runtime script binding at dispatch: 3, reject changed operands and omitted required bindings.
- Relative skill-bin invocation: 3, skill trust cannot authorize an arbitrary relative executable.
- Unsafe environment inputs: 3, block dangerous overrides, argv assignments, and invalid env keys.
- Shell executable env allowlist: 3, filter shell environments even without an inline payload.
- Revoked rule during allow-always commit: 3, do not resurrect revoked authority through grant persistence.
- Unprompted ask tightening during commit: 3, current-policy authority must not survive a newly required prompt.
- Auto-review ask tightening during commit: 3, forwarded model authority remains bound to its prepared policy snapshot.
- Exact-plan forwarded strict inline review: 3, authenticated one-shot authority remains scoped to its bound plan.
- Unavailable screen recording: 3, deny before execution or durable grant mutation.
- Tightened timeout fallback policy: 3, reevaluate fallback authority at commit.
- Fallback without canonical plan: 3, reject unbound fallback provenance.
- Explicit approval without canonical plan: 3, reject unbound explicit authority.
- Delayed approval without policy snapshot: 3, require the prepared policy identity.
- Allowlist revocation after prepare: 3, reject stale authority before committing.
- Mixed fallback and explicit provenance: 3, refuse contradictory authority sources.
- Durable allowlist timeout fallback: 3, positive control for an exact durable grant.
- Revoked durable timeout source: 3, source downgrade removes fallback authority.
- Mac fallback bridge: 3, forward fallback provenance without inventing explicit approval.
- Fallback versus strict inline review: 3, timeout fallback cannot satisfy mandatory review.
- Unknown approval provenance: 3, reject unsupported authority markers.
- Benign awk durable grant: 3, a file-based grant must not reopen inline programs.
- Make inline grant: 3, explicitly approved runtime payloads remain one-shot.
- Windows cmd transport: 3, unwrap transport before deciding shell approval requirements.
- Windows durable trust downgrade: 3, revalidate the exact durable source at commit.
- Durable cwd replacement: 3, directory identity remains bound through execution.
- Safe builtin with redundant exact grant: 1, builtin authorization must survive revocation of an unused grant.
- Socket response loss: 2, adf5c67382, real completed execution must never replay after its reply is lost.

Measurements and validation:
- Executed tests: 90 -> 48, down 46.67%.
- Shard test LOC: 3431 -> 2045, down 40.40%.
- Covered statements: 357 -> 354 (-0.84%).
- Covered branches: 438 -> 435 (-0.68%). Functions: 34 -> 34.
- Only invoke-system-run-plan.ts drops coverage: 3 statements, 3 branches.
  These are removed preparation-only probes; no source file drops >5 statements.
- Both Vitest coverage groups succeeded; no groups were excluded.
- Blacksmith Testbox: both shard files pass (47 infra + 1 unit tests).
  Final file durations: 2.80s infra; 1.95s unit.
- check:changed passes, including core-test types, boundary checks, all
  dead-export scans, and type-aware lint (0 warnings, 0 errors).
- Local oxfmt, plain oxlint, and git diff --check pass.
- No production or shared test-support changes; no bugs or flakes found.
- Proof workflow: https://github.com/openclaw/openclaw/actions/runs/36738903333

* test(ai): deslop t0414 tests

* test(commands): deslop t0423 tests

* test(google): deslop t0416 tests

* test(board): deslop t0409 tests

* test(infra): deslop t0410 tests

* test(gateway): deslop t0429 tests

* test(doctor): deslop t0422 tests

* test(signal): deslop t0426 tests

* test: retain distinct regressions in batch d118
2026-09-30 21:36:05 +00:00
Peter Steinberger
8c39234ebf
refactor(doctor): observe serving Gateway ownership off thread (#162021)
* refactor(doctor): observe serving Gateway ownership off thread

* fix(doctor): complete lease reader import dependencies

* test(update): adapt serving lease observation fixture
2026-09-30 14:11:57 -07:00
Peter Steinberger
33513de8d9
refactor: reuse XML decoding in Apple localization tools (#162102)
Some checks are pending
Native App Locale Refresh / Refresh native es (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fa (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native hi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native id (push) Blocked by required conditions
Native App Locale Refresh / Refresh native it (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pl (push) Blocked by required conditions
Node Runtime Conformance / scope (push) Waiting to run
Node Runtime Conformance / TypeScript contracts (push) Blocked by required conditions
Node Runtime Conformance / Rust workspace (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / scope (push) Waiting to run
Plugin Init Scaffold Validation / Validate provider scaffold (push) Blocked by required conditions
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / approve_plugins_npm_release (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Use the shared ampersand-last decoder in native and Apple localization tooling, and inline the JSON.stringify forwarding helper. Preserve generated strings and catalogs without modifying locale or generated files.
2026-09-30 13:47:57 -07:00
Peter Steinberger
a948e56619
fix(test): adapt Tool Search recipe to published baseline
Use structured Tool Search config from 2026.9.7 while retaining the legacy code-mode migration specimen for older baselines. Read the existing coverage receipt version for baseline assertions; keep post-upgrade cleanup checks strict.
2026-09-30 13:23:51 -07:00
Peter Steinberger
f9eabc4a0b
fix(test): settle detached survivor service processes (#162101)
The legacy-operator survivor lane can reach a forced Gateway exit with a
detached child still in the unit cgroup. Its synthetic manager drained only
the original process group and cleared custody, so the strict stop verifier
correctly refused before the no-op updater was invoked. This predates the
SQLite predecessor-receipt migration and host-lifetime changes.

Honor the loaded KillMode=mixed policy in the existing manager: TERM the
main process, escalate remaining unit members after its exit or the loaded
deadline, then join group and cgroup extinction before exit or restart.
Track native PID/start-time identities and recheck exact membership before
signaling. The existing observer also settles newly discovered members.
Keep all deadlines, containment permissions, stop assertions and backup
custody unchanged.

Concurrent config write during admission: production warning and re-read
behavior is unchanged; this repair only corrects service-manager fixtures.
Doctor sees its own finished update row: production terminal settlement and
original-state capture are unchanged, and the survivor Doctor proof passes.

Published driver x candidate: the same 2026.9.6 driver, 2026.9.7 candidate
and plugin registry are used before and after. The no-op stop, already-
current update, foreground survival, Doctor and backup rollback pass.

The real cgroup negative control fails with a surviving detached child;
the repaired manager empties the cgroup while preserving an unrelated
process. Twenty concurrent real cgroup probes pass. The stop-policy suite
retains every prior case and assertion; its 21 Linux cases cost 3.73s.

Validation: whole tooling ran 909 files: 901 passed; the only three failing
cases were the SDK export leak fixed by the preceding commit, then proved
11/11 on the same Linux lease. Whole tooling-docker passed 150 cases;
all six helper importers and 20 pressured new-regression runs are covered.
Legacy before passed in 1170.22s. After replays passed in 1453.89s and
940.18s; one earlier replay failed during published-baseline startup,
before candidate installation. That unrelated timeout remains recorded.
Changed lint, boundary lint and independent review through P2 pass.
2026-09-30 20:21:05 +00:00
Peter Steinberger
441e664f94
refactor(memory): move Forget planning reads to the worker (#162045)
Use the existing memory retrieval pool for noncreating index selection, counts, and vector inspection. Capture caller placement and matching facts before dispatch, share the existing scrub rules, and return only selected row identities and counts. Keep final lineage checks and write settlement with their existing transaction owner.

Validation: causal host count regression, 150 owning tests, native fetched-row and byte bounds, captured-input and read-error controls, full changed-file gate, and independent review.
2026-09-30 13:11:03 -07:00
Peter Steinberger
ba80dfbee5
perf(state): retire periodic runtime integrity scans (#162015)
* perf(state): retire periodic runtime integrity scans

Remove delayed and daily full-database scans from the Gateway while preserving requested agent quick checks, live-owner confirmation, and quarantine. Keep full verification with admission, migrations, and Doctor maintenance. No config or schema migration is required.

* fix(update): restore Windows task autostart after cancellation

Carry the existing restoration phase through Windows task recovery so SIGINT fences forward work without rejecting compensation. Preserve executor and native task ownership checks before side effects.

The original 40-file CI shard reproduced 821 passes and one SIGINT failure; it passes all 822 tests with this change. Testbox focused tests and changed checks passed, and independent Codex review found no actionable findings.

* fix(plugin-sdk): keep updater path context private

Pin the legacy home-directory facade to its existing eight exports so new internal updater helpers do not become public SDK contracts. Reduce the wildcard ratchet by one without expanding export or callable budgets.

All 11 SDK surface tests passed against the exact failed CI merge plus this fix on Testbox, along with core/script types, targeted lint, export guards, and formatting. Independent Codex review found no actionable findings.
2026-09-30 19:44:01 +00:00
Peter Steinberger
a58e5babbe
fix(test): keep extension batches inside requested directories (#162009)
* fix(test): keep extension batches inside requested directories

Preserve canonical plugin roots as directory filters and intersect plain directory test globs with their owning scope. Prevent policy batches from selecting sibling policy filenames or nested policy directories while retaining watch discovery, explicit files, exclusions, and complex owner patterns.

Add real runner-to-selector regression cases, proven failing before the fix, and keep existing aggregation and scoped-config assertions aligned.

* fix(test): preserve explicit extension file filters
2026-09-30 11:58:15 -07:00
Peter Steinberger
404e47a13c
test(core,plugins,ui): remove low-value tests (batch d116) (#162019)
* test(custodian): deslop t0394 tests

* test(media): deslop t0397 tests

* test(imessage): deslop t0396 tests

* test(agents): deslop t0392 tests

* test(plugins): deslop t0383 tests

* test(cli-runner): deslop t0388 tests

* test(config): deslop t0405 tests

* test(ui): deslop t0403 tests

* test(channels): deslop t0400 tests

* test(voice-call): deslop t0398 tests

* test: preserve independent contracts in d116 cleanup
2026-09-30 11:50:25 -07:00
Peter Steinberger
5381128b68
fix(update): reduce oversized sealed recovery packages (#161919)
* fix(update): keep recovery imports within their owners

Separate fixed public error codes from executable diagnostic catalogs. Move the existing active handoff map, lease reader, and current-process observer together so callers do not import the service launcher to inspect an existing handoff.

Preserve public identifiers, sanitization, store selection, lease validation, and sealed recovery behavior. Guard the production bundle against capturing Doctor and service controllers, with staged repair and retirement coverage.

* fix(tooling): include update codes in native wrapper inventory

* fix(ci): bound isolated Gateway fixture workers

Keep the Gateway isolated/database-worker cohort at its existing two-worker budget so cold startup has room within unchanged test deadlines. Preserve former eight-worker complete generations as conservative timing floors without relabeling them as current measurements.

Validation: 325 owning tests, selected changed checks, and fresh managed review. Generated job counts and coverage are unchanged. Exact changed CI remains required.
(cherry picked from commit 30e80e790d)

* test(ci): isolate runtime placement pricing fixtures

Control spare compact capacity and the two workload inputs before asserting co-location. Restore the real runtime timing reader so refitted observations still force the overloaded workloads into separate rows.

Validation: 207 owning cases passed; removing the refitted observations fails the after-placement assertion. Restored-case verification, selected checks, and fresh managed review passed.
(cherry picked from commit 450dba2dc6)
2026-09-30 11:25:10 -07:00
Peter Steinberger
f6948d0bbf
fix(scripts): restore Codex protocol config-edit type probe (#162012)
The generated Codex protocol probe still imported a private type alias removed from the maintained protocol barrel. Derive the edit type from the existing config/batchWrite request contract while preserving the upstream ConfigEdit assignability assertion.

The real pinned upstream generator reproduces TS2305 on the base and passes the maintained type probe after this fix. The 11 pre-existing JSON schema diagnostics remain identical. Focused tests, changed-file checks, independent review, fresh cycle checks, and import-boundary tests pass; schemas and runtime contracts are unchanged.
2026-09-30 17:35:07 +00:00
Peter Steinberger
8e047c3ce4
test(core,plugins,ui): remove low-value tests (batch d114) (#161993)
* test(copilot): deslop t0366 tests

* test(config): deslop t0377 tests

* test(plugins): deslop t0368 tests

* test(auth): deslop t0381 tests

* test(ui): deslop t0382 tests

* test(release): deslop t0384 tests

Port the shard while preserving newer SDK acknowledgement coverage and all six strengthened trusted-tooling cleanup scenarios.

Validation: 109 tests passed with no skips on Blacksmith Testbox from a fresh-main proof checkout; oxlint, oxfmt, diff checks, and independent review passed.

* test(agents): deslop t0369 tests

Port 2533d418dcab93da1aec73ee224072e29402ba08 onto the campaign lane, preserving all 25 test blocks changed on the lane and its four test removals. Retain the existing max-lines baseline because preserving that coverage keeps the planner suite above the limit.

Validation: all 60 tests passed on Blacksmith Testbox from a fresh-main proof checkout, with no skips. Scoped oxlint, oxfmt, diff checks, and independent review passed.

* test(pdf): deslop t0374 tests

* test(auto-reply): deslop t0378 tests

* test(gateway): deslop t0371 tests

* test: preserve persistence and release workflow coverage

Retain cold logout reload, persisted plugin-state reopening, and real workflow-input compatibility while keeping the batch test reductions.
2026-09-30 10:34:56 -07:00
Peter Steinberger
96d66fed3e
refactor(memory): move Forget transactions off the host thread (#161959) 2026-09-30 10:31:20 -07:00
Peter Steinberger
ad8327f586
fix(pr): requalify admission when final main objects are missing
Main can advance during prior-CI verification, leaving the final local-only
reread without its newly observed commit. Return that exact tip to bounded
pre-authority qualification instead of requiring another operator attempt.

Require Git's successful raw-object missing result with empty stderr and
readable previous/verified pins. Discard the active authority proof before
materializing, preserve the captured tip as an ancestry lower bound, and
rerun full live verification against the original proof fingerprint. Refuse
after three rounds without intent or dispatch. REST brackets stay unchanged.

Validation: original two regressions fail; all 47 final main-owner cases and both
confirmed cancelled-auto recovery cases pass, including revoked authority/evidence and
retained history. 47 REST sibling cases pass; one unchanged quota scenario returned
143 under its existing 20s fixture limit after merge/audit/comment and branch
deletions. That failed invocation is retained, not counted as full completion;
no deadline was increased. Initial truncated negative runs are also retained.
2026-09-30 10:25:35 -07:00
Peter Steinberger
a8703d701e
test(update): verify context activation after published upgrade 2026-09-30 09:48:47 -07:00
Peter Steinberger
cfd219c519
fix(release): skip pending ClawHub publications and surface recovery for failed ones (#161985)
The ClawHub release planner and prepared-artifact resolver read the new public publication-state endpoint (/api/v1/packages/{name}/versions/{version}/publication). Only absent versions are republished; pending ones are skipped, and failed ones are excluded, with the recover command printed to the step summary. A 404, or a 200 without a state field, falls back to the legacy version probe.
2026-09-30 09:35:54 -07:00
Peter Steinberger
1f6754a855
fix(pr): qualify real Gateway failures in cancelled UI jobs
A CI job can finish cancelled after its real-Gateway test step has already
failed. Preserve that failed step as an independently attributed root rather
than refusing its audited UI workflow family or treating it as collateral.

Bind the existing failedStep evidence to the exact UI command, private-QA
build, matrix selection, live check-run and ordered source steps. Recognize
only the explicit runner setup/cleanup pair, and retain all source, review,
security and cancellation checks. Cancelled coverage remains unrun.

Validation: both UI admission cases fail on the original owner; 66 combined
UI/Node/production-type cases pass, followed by 21 final UI cases including
cleanup refusals. The real retained job's 17-step sequence matches the
12-step source workflow plus its explicit runner prelude/postlude.
2026-09-30 09:27:54 -07:00
Peter Steinberger
dc49c824d3
fix(release): verify beta floor for core npm packages (#161968)
Share filesystem core package discovery with npm bundle preparation. Include every selected core package in beta-floor diagnostics and block postpublish on any core floor failure, while preserving reused and superseded core selectors.
2026-09-30 16:21:44 +00:00
Peter Steinberger
a3e3b0b9df
refactor(scripts): deslop tooling scripts fifth pass (#161972)
Replace 46 repeated protocol-check records with an ordered file-to-snippets map and import the canonical JSON normalizer directly. Reuse canonical environment snapshot/restoration and oversized-response errors in the standalone MCP proof.

Preserves protocol assertions, diagnostic order, generated probe bytes, CLI contracts, and cleanup behavior. Removes 125 net tooling lines. Verified with independent review, zero import cycles, focused tests and import boundaries, check-changed, and a full Linux Testbox build.
2026-09-30 16:21:41 +00:00
Peter Steinberger
30e80e790d
fix(ci): bound isolated Gateway fixture workers
Keep the Gateway isolated/database-worker cohort at its existing two-worker budget so cold startup has room within unchanged test deadlines. Preserve former eight-worker complete generations as conservative timing floors without relabeling them as current measurements.

Validation: 325 owning tests, selected changed checks, and fresh managed review. Generated job counts and coverage are unchanged. Exact changed CI remains required.
2026-09-30 09:20:07 -07:00
Peter Steinberger
e15fa0b879
test(core,browser): remove low-value tests (batch d105) (#161658)
* test(daemon): deslop t0250 tests

* test(net): deslop t0248 tests

* test(auto-reply): deslop t0231 tests

* test(browser): deslop t0260 tests

* test(mcp): deslop t0255 tests

* test(commands): deslop t0245 tests

* test(auth-profiles): deslop t0253 tests

* test(agents): deslop t0244 tests

* test(doctor): deslop t0268 tests

* test(test): deslop t0252 tests

* test: retain boundary coverage and repair d105 checks

* test: preserve distinct d105 lifecycle and boundary contracts
2026-09-30 08:54:27 -07:00
Peter Steinberger
0b3de8ae20
fix(update): settle service receipts and interrupted rollback (#161851)
* fix(update): settle service receipts and interrupted rollback

Await the existing bound worker phase receipt before native service stop,
then revalidate the original executor/requester. Retain already admitted
compensation through signal settlement, including its later phase writes,
without retaining the unbounded forward operation.

Keep current-core and rollback authority policies distinct. Preserve the
existing ledger kernel, records, schema and recovery semantics.

Related: #161385
Canonical stale-baseline context: #161766

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>

* fix(test): register post-update worker fixture once

Keep its existing worker registration instead of adding a duplicate that
prevents CI compact timing generation. Preserve the strict uniqueness
guard and the three newly required worker routes.

The actual CI merge failed manifest generation and its existing registry
regression; the baseline and one-entry correction passed the same selector.

* test(update): retain real owners in module failure fixtures

Load the mutable-signal and execution-guard owners in the existing VM
fixture so post-update failures reach their original backup-retention
assertions. Keep all19 inner cases and the synthetic service boundary.

The original three-file CI group failed on the unexpected dependency call;
the two real-module additions restore17 outer passes and19 inner passes.

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-30 08:49:22 -07:00
Peter Steinberger
5c8dd21423
fix(pr): identify failed local-only prior-CI commit probes
Report the previous-main, reread-main, or verified-main OID and Git exit
status when the final local-only commit check refuses admission. Sanitize
stderr through the existing redactor before bounded JSON-escaped display,
and use the selected trusted wrapper's loader configuration.

Keep probe ordering, no-lazy-fetch enforcement, authority checks, and merge
refusal unchanged. Cover all three roles, unavailable commits, unsupported
Git, oversized diagnostics, and an invalid caller checkout configuration.

Validation: original six diagnostic cases fail before the repair; final six
pass. Both prior-CI main-drift and REST owner suites passed (84 tests) before
the failure-only loader pin; the focused cases cover that final correction.
2026-09-30 08:41:27 -07:00
Peter Steinberger
ebe57ef28a
ci(android): restore headroom for phone test rows
Move third-party app lint back to the existing Wear row and budget
Blacksmith phone tests across up to four isolated JVMs. Each JVM receives
its share of the available CPUs; the existing 1 GiB heaps remain unchanged.

On the same eight-CPU Linux Testbox, clean project outputs and warm
dependency caches reduced the affected phone row from 446.13 to 233.34
seconds of Gradle wall time. Wear moved from 20.49 to 174.36 seconds;
the two rows together fell from 466.62 to 407.70 runner-seconds.
All 3,665 third-party and 3,533 Play tests passed, along with Wear/shared
tests and the selected Android lint tasks.

Keep all four normal rows, all six full-validation rows, test assertions,
Gradle tasks, hosted settings and timeout budgets. Actions job-wall
measurement remains a follow-up for the next natural hourly.

Validation: complete 905-file tooling inventory across the interrupted and
resumed runs; 897 files passed, seven retained existing skips, and three
assertions in pr-merge-prior-ci-timeout.test.ts failed identically on the
unmodified parent (25 passed, three failed). Full test-types, main/PR/full
preflight smoke, workflow validation, boundary lint, six-file check-changed
and direct-API P2 review passed. No test or assertion was weakened.
2026-09-30 07:51:27 -07:00
Peter Steinberger
5b6f9ff463
fix(pr): retain deadline context in cancellation refusals
Keep deadline context in the shared GitHub check-run identity refusal,
which also serves failed-step admission. The production-type extension
generalized that diagnostic and broke the existing deadline rejection
controls; all qualification predicates remain unchanged.

The unchanged deadline suite passes 20 runs (560 cases). Changed checks,
script types, typed and boundary lint, and independent P2 review pass.
2026-09-30 07:35:02 -07:00
RoboClaw
1ea44e0b68
fix(test): Gateway fixtures overlap in parallel runs (#161880)
Apply the existing exclusive-plan barrier to full-suite and explicit-parallel routes without changing deadlines, worker limits, or failure policy.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-30 14:14:10 +00:00
Peter Steinberger
379ccff689
fix(ci): unblock gates for Vitest inventory changes (#161910) 2026-09-30 07:09:52 -07:00
RoboClaw
182f79b926
fix(test): updater outcome checks reject async receipt reads (#161889)
Supply the asynchronous absent-row fixture binding while retaining synchronous verification and recovery readers. Preserve all nineteen native regression cases and the strict unexpected-dependency guard.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-30 06:52:48 -07:00
Peter Steinberger
192b90aaae
ci: plan extension types without serial core discovery
Retain complete core graph validation in the existing required parallel boundary row for canonical extension-only changes. Discover all four noncore compiler consumers while preserving full fallback for aliases, missing inputs, mixed changes and incomplete inventories.
2026-09-30 06:45:23 -07:00
Shakker
058adf3f06
fix: retain compatible Testboxes across source commits (#161266)
Retain compatible trusted Testboxes across source commits while preserving allocation provenance and per-command source verification. Reject incomplete allocation receipts.

Fixes #161263.
2026-09-30 14:22:15 +01:00
Peter Steinberger
cbb17e87e9
ci: stabilize native declaration emission
Keep native declaration visits deterministic so regenerated SDK types preserve valid extension package receipts. Type-check-only workers retain their existing concurrency and all diagnostics and boundary seals remain enforced.
2026-09-30 06:08:43 -07:00
Peter Steinberger
40367c40bf
fix(tooling): finish REST admission before final authority
Complete the selected REST observation and main materialization before the last authority verification, without reopening a redundant local-only observation window. Preserve GraphQL and late fallback admission checks.

Drain fake GitHub CLI response pipes before exit so lifecycle tests retain complete evidence. Cover forward main movement, final authority revocation, and complete success/error output.
2026-09-30 05:46:29 -07:00
Peter Steinberger
71156a00c9
fix(hooks): retry native relay lookup after SQLite contention (#161822)
Some checks are pending
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pt-BR (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ru (push) Blocked by required conditions
Native App Locale Refresh / Refresh native sv (push) Blocked by required conditions
Native App Locale Refresh / Refresh native th (push) Blocked by required conditions
Native App Locale Refresh / Refresh native tr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native uk (push) Blocked by required conditions
Native App Locale Refresh / Refresh native vi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
Node Runtime Conformance / TypeScript contracts (push) Blocked by required conditions
Node Runtime Conformance / scope (push) Waiting to run
Node Runtime Conformance / Rust workspace (push) Blocked by required conditions
Plugin Init Scaffold Validation / scope (push) Waiting to run
Plugin Init Scaffold Validation / Validate provider scaffold (push) Blocked by required conditions
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / approve_plugins_npm_release (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-30 05:01:13 -07:00
Peter Steinberger
e96303d3bc
fix(tooling): qualify cancelled production type-check failures
Recognize the audited check-prod-types failed-step shape under the existing prior-CI verifier. Bind the GitHub check-run, workflow command, matrix/task inputs, source-step positions, complete timestamps, and successful cleanup while retaining the cancelled conclusion.

Independent failure attribution, unchanged source inputs, exhaustive cancellations, security, admin authority, and enforced reviews remain required. The final fixture fails on the original Node-only owner; 67 verifier controls and selected checks pass with the repair. Managed P2 review is clean.
2026-09-30 05:00:59 -07:00
Peter Steinberger
72cca0df98
test(agents, memory, ui, tooling): remove low-value tests (batch d112) (#161835)
* test(transcripts): deslop t0348 tests

* test(memory-core): deslop t0340 tests

* test(agents): deslop t0334 tests

* test(line): deslop t0361 tests

* test(docker-e2e): deslop t0362 tests

* test(scripts): deslop t0338 tests

* test(release): deslop t0359 tests

* test(markdown): deslop t0357 tests

* test(ui): deslop t0360 tests

* test(vitest): deslop t0363 tests

* test(ci): align config owner expectation after test cleanup
2026-09-30 11:59:03 +00:00
Peter Steinberger
b06666e3ad
test(runtime): remove low-value tests (batch d110) (#161714)
* test(auto-reply): deslop t0258 tests

* test(config): deslop t0331 tests

* test(memory-core): deslop t0285 tests

* test(updater): deslop t0320 tests

* test(telegram): deslop t0333 tests

* test(gateway): deslop t0341 tests

* test(agents): deslop t0318 tests

* test(gateway): deslop t0345 tests

* test(gateway): deslop t0328 tests

* test(gateway): deslop t0337 tests

* test: retain unique safety contracts in reduction batch

* fix(ci): keep native compiler import proof on Node
2026-09-30 11:58:18 +00:00
Peter Steinberger
fcd59e6bdf
improve: keep SQLite workers alive on Bun builds that release native handles (#161764)
Bun builds that release SQLite native handles still paid for conservative worker retirement because lifecycle policy checked the runtime name. Capture the native-close capability after library selection and reuse it across broker placement, retirement, reader cleanup, and inherited worker admission. Bound probe termination to five seconds; timeout/error admission returns conservatively while unreferenced cleanup retains any unconfirmed live worker’s private directory. Stock Bun and Windows stay conservative; Node retains its existing policy. Register the disposable native probe with the SQLite guard and include the diagnostic parser, probe, and worker in the maintainer wrapper source inventory so isolated provisioning loads its complete dependency closure.

Proof: recovery median 11.4 s -> 0.1 s with 0/0 measured transcript worker creations/retirements. Gateway 50x25 load replies improved 128 -> 263 versus Node 273. Node 24 and the signed Bun test fork cover touched lifecycle and startup tests; changed checks, import-cycle checks, and full build verify the rebased tree.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-30 04:50:56 -07:00
Peter Steinberger
4d63cbedc6
test(core,plugins,ui): remove low-value tests (batch d111) (#161796)
* test(agents): deslop t0342 tests

* test(config): deslop t0347 tests

* test(ui): deslop t0336 tests

* test(gateway): deslop t0335 tests

* test(gateway): deslop t0349 tests

* test(logging): deslop t0315 tests

* test(copilot): deslop t0353 tests

* test(system-agent): deslop t0339 tests

* test(plugin-state): deslop t0344 tests

Consolidate nine files into five while retaining cursor release, schema ownership, rollback, expiry bounds, and runtime authority checks. Testbox: 46 tests pass; covered statements remain 746 and covered branches drop from 395 to 392. Existing script guard and lint failures in ci-build-manifest.mjs remain outside this shard.

* test(plugins): deslop t0346 tests

* test: retain distinct security and preference coverage

* test(plugins): match archive security errors correctly

* test: retain lifecycle and import boundary coverage

* test(gateway): type browser projection cases as named records
2026-09-30 11:44:03 +00:00
Peter Steinberger
bf4b16a81d
refactor(meeting): declare browser meeting plugins through one factory (#161628)
Zoom meetings, Teams meetings and Slack huddles each carried the same
thirteen-file glue layer (entry, CLI, CLI metadata, config, errors, node
host, node invoke policy, runtime facade, probes, setup, Chrome transport,
types), feeding one platform adapter into a dozen separate
MeetingPlatformAdapter helpers. A new MeetingPlatformAdapter member,
defineBrowserMeetingPlugin, composes those helpers from one declaration,
so each plugin now declares only what is genuinely platform-specific. A
fourth browser meeting platform costs one declaration.

The helpers the factory replaces stay exported and are marked deprecated,
since published plugin versions call them. Tests inject Chrome bindings
through the factory's public spec instead of mocking core internals. The
three plugins drop their unused typebox dependency.

Zoom and Teams now require OpenClaw 2026.9.8 (install and plugin API
floors, catalog, docs), like Slack huddles, because they call a member
2026.9.7 lacks. Released plugin packages already require a matching host.

All plugin registrations and 42 generated page-script hashes are
identical to main.

Release note: Zoom meetings and Microsoft Teams meetings plugins require
OpenClaw 2026.9.8 or newer.
2026-09-30 04:36:48 -07:00
Peter Steinberger
0c0faf026c
test(core,plugins,scripts): remove low-value tests (batch d106) (#161661)
* test(scripts): deslop t0269 tests

* test(gateway): deslop t0267 tests

* test(doctor): deslop t0262 tests

* test(auto-reply): deslop t0259 tests

* test(scripts): deslop t0263 tests

* test(skills): deslop t0261 tests

* test(plugins): deslop t0256 tests

* test(cli): deslop t0266 tests

* test(config): deslop t0265 tests

* test(codex): deslop t0277 tests

* test(cron): fix reduced fixture lint and prune stale baseline

* test: remove dangling references to retired fixtures

* test(gateway): preserve distinct media retention coverage
2026-09-30 11:20:15 +00:00
Peter Steinberger
509cb47840
refactor: move workspace journal storage off the Gateway thread (#161539)
* refactor: move workspace journal storage off the Gateway thread

* fix: include workspace journal contract in PR wrappers

* fix: preserve repository authority through journal commits

* test: capture first-signin startup and RPC timing on timeout
2026-09-30 04:16:02 -07:00
Peter Steinberger
c2ac326cb0
build(macos): pin the app runtime to OpenClaw Bun 57fadf566d (#161825)
Moves the bundled runtime from fork release ee83b78b18 to
openclaw-v1.4.3-20260930-57fadf566d-webkit-f20ce77445: the upstream Bun
sync through ba3f27d1d1, the full CI-line compatibility port, the macOS
/dev/fd copy fix, child_process stdio handles, bounded compile-cache exit
persistence, TLS over paused CONNECT transports, and the net/fs/
structuredClone parity fixes.
2026-09-30 04:08:34 -07:00
Peter Steinberger
92108db80c
fix(tooling): keep max-lines baseline shrinks on targeted lint
Some checks are pending
Native App Locale Refresh / Refresh native sv (push) Blocked by required conditions
Native App Locale Refresh / Refresh native th (push) Blocked by required conditions
Native App Locale Refresh / Refresh native tr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native uk (push) Blocked by required conditions
Native App Locale Refresh / Refresh native vi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
Native App Locale Refresh / resolve-base (push) Waiting to run
Native App Locale Refresh / Verify generated PR App permissions (push) Blocked by required conditions
Node Runtime Conformance / scope (push) Waiting to run
Node Runtime Conformance / TypeScript contracts (push) Blocked by required conditions
Node Runtime Conformance / Rust workspace (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / scope (push) Waiting to run
Plugin Init Scaffold Validation / Validate provider scaffold (push) Blocked by required conditions
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / approve_plugins_npm_release (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
The max-lines baseline is consumed by its existing ratchet, not Oxlint. Keep this exact path neutral when selecting changed-file lint, with the same guard and broad-input fallbacks.

Extend the mixed-owner planner regression across guarded baselines. The max-lines row failed before the fix; nine focused planner and fallback cases pass afterward. Scoped guards, lint, and typechecks pass after consuming the canonical workflow fixture type correction.
2026-09-30 03:11:17 -07:00
Peter Steinberger
f6bba09343
ci: pack regular CLI stripes within the existing budget
Include generated regular CLI children in both serial packing paths while preserving the 150-second child and 250-second job limits. Keep runner, worker, preparation and process policies intact.

The focused planner regression and neighboring budget case pass in 33.87 seconds on macOS. A local manifest probe emits 88 instead of 89 rows with the identical 3,884-target inventory; Linux integration proof remains required before landing.
2026-09-30 02:57:50 -07:00