Use structured Tool Search config from 2026.9.7 while retaining the legacy code-mode migration specimen for older baselines. Read the existing coverage receipt version for baseline assertions; keep post-upgrade cleanup checks strict.
The legacy-operator survivor lane can reach a forced Gateway exit with a
detached child still in the unit cgroup. Its synthetic manager drained only
the original process group and cleared custody, so the strict stop verifier
correctly refused before the no-op updater was invoked. This predates the
SQLite predecessor-receipt migration and host-lifetime changes.
Honor the loaded KillMode=mixed policy in the existing manager: TERM the
main process, escalate remaining unit members after its exit or the loaded
deadline, then join group and cgroup extinction before exit or restart.
Track native PID/start-time identities and recheck exact membership before
signaling. The existing observer also settles newly discovered members.
Keep all deadlines, containment permissions, stop assertions and backup
custody unchanged.
Concurrent config write during admission: production warning and re-read
behavior is unchanged; this repair only corrects service-manager fixtures.
Doctor sees its own finished update row: production terminal settlement and
original-state capture are unchanged, and the survivor Doctor proof passes.
Published driver x candidate: the same 2026.9.6 driver, 2026.9.7 candidate
and plugin registry are used before and after. The no-op stop, already-
current update, foreground survival, Doctor and backup rollback pass.
The real cgroup negative control fails with a surviving detached child;
the repaired manager empties the cgroup while preserving an unrelated
process. Twenty concurrent real cgroup probes pass. The stop-policy suite
retains every prior case and assertion; its 21 Linux cases cost 3.73s.
Validation: whole tooling ran 909 files: 901 passed; the only three failing
cases were the SDK export leak fixed by the preceding commit, then proved
11/11 on the same Linux lease. Whole tooling-docker passed 150 cases;
all six helper importers and 20 pressured new-regression runs are covered.
Legacy before passed in 1170.22s. After replays passed in 1453.89s and
940.18s; one earlier replay failed during published-baseline startup,
before candidate installation. That unrelated timeout remains recorded.
Changed lint, boundary lint and independent review through P2 pass.
Record a bounded child tree, kernel waits, and sampled copy progress when
legacy operator-state updates time out. Keep the phase verdict visible in
the existing log tail without exposing process arguments or state contents.
Update behavior is unchanged: the installed updater runs first, with the
same deadlines, admission, assertions, stdout, and exit status. Diagnostic
reads cannot delay completion after the updater exits.
Preinstall probed absent or non-executable PATH Node candidates, creating Node spawn attempts during Bun-only installs. The smoke also omitted the documented Bun launcher marker and masked the resulting failure with an install-time Node fallback.
Check execute permission before probing persistent Node candidates, preserve Node engine enforcement and Bun lifecycle-shim exclusion, and make the smoke install through the documented Bun 1.4+ launcher without a Node fallback. Remove the resolved expected blocker.
Proof: 132 focused preinstall, spawn-ledger, and install-smoke workflow tests pass after a patch-identical rebase. The reviewed Linux Bun-only smoke passes all ten steps with zero preinstall Node attempts and no fallback; both classifier negative controls reject invalid blocker inventories.
The published-driver upgrade-survivor cell (legacy-operator-state) failed
at legacy-operator-update-noop for every candidate built after #160056.
That change reworded the managed-service rerun guidance, and the
already-current assertion hardcoded the full advisory text, so the only
difference was advisory.message.
Project each step's advisory to its kind plus a non-empty explanation.
The check still requires an already-current, repair-free result with no
steps or exactly one unexecuted managed-service-reconciliation entry
(same name, command, cwd, duration, exit code, and advisory kind).
Product text is unchanged.
Share repeated tooling parsing, projections, and fixture transforms while preserving command and generated-output contracts. Repair the OpenGrep help range so bootstrap code no longer replaces documented usage.
Standalone Doctor starts an already-offline owned Gateway after repair. Stop and join the fixture service again after Doctor and lint, before hashing the profile, so Gateway writes cannot be attributed to candidate admission.
Use the strict systemctl stop rather than the cleanup helper that ignores failures. Keep the existing byte-for-byte admission assertion unchanged.
Validation: Bash syntax, diff checks, and independent P1 review passed. The full Docker first-hop lane was not rerun within the bounded investigation.
(cherry picked from commit f0461973f6e9a92f0bf0b16a64a0b91ac25df7c8)
Use the shipped updater's explicit channel switch when an extended-stable
baseline upgrades to a non-extended-stable candidate. Apply the same rule
to update previews and verify that the completed update persists stable.
Extend the updater boundary cases and make the recovery fixture's line-count
comparison portable to macOS.
Hosted run 36506342273 exhausted the first-hop container's 1800s budget.
Project 1558s + 560s final candidate hop + ~5s assertions ~= 2125s;
x ~1.5 gives 3200s inner, plus 300s host margin gives 3500s per lane.
Six sources still need two waves at npm weight limit 5; 2 x 3500s
plus 10m setup ~= 127m, rounded to a 130m self-upgrade chunk.
Restart-auth exceeded 1515s in run 36506342273: x ~1.5 gives 2280s
inner plus 300s host margin, or 2580s per lane. Run 36506210440
measured an 856s restart update; 4-CPU Crabbox measured 993s, so
set a lane-only 1500s command timeout and retain the global 900s default.
The OpenAI/recovery row's five weight-3 npm lanes serialize at limit 5:
30 + 30 + 20 + 25 + 43 = 148m, plus 10m setup => 160m rounded.
The chat lane overlaps. CI Docker seed excludes restart-auth and keeps
its 60m job budget. No product code or scheduler concurrency changes.
Validation: all 185 tests in the three focused files passed (71.13s wall,
one worker). Bash syntax, oxfmt, oxlint, and git diff --check passed.
Independent Codex autoreview found no actionable P0/P1 findings.
* perf(sessions): separate hot facts from cold snapshots
Move saved skill, prompt-report, and diff snapshots into keyed agent-schema-24 rows. Keep full-entry compatibility through same-statement hydration, preserve revision fencing and Doctor/lifecycle ownership, and return immutable borrowed metadata without redundant clones. Metadata fixture list allocation falls about 96%; generic patch cost remains essentially unchanged.
* test(sessions): adapt storage fixtures to split snapshots
* test(sessions): read split snapshots in upgrade assertions
* ci: include main UI type shard rebalance
Apply main commit 52ae7e314d unchanged to unblock the inherited ui-other root-budget failure. Session storage and the measured product code are unchanged.
* fix(sessions): complete cold snapshot reader cutover
Hydrate bounded full-entry summaries through the canonical snapshot query, use prepared Kysely migration DML, and avoid repeated JSON bindings in snapshot upserts. Keep allocation and consistency limits intact while moving existing fixtures to split storage.
Includes the unchanged Doctor e2e mock repair from main 162dea17b0. Testbox tbx_01m3m1gy44kbw82fjdeb0y98fh passed architecture, focused lint and types, 242 focused tests, and the allocation benchmark. Fresh review through P2 was clean.
* test(sessions): synchronize recovery and heartbeat fixtures
Hold deferred recovery repair at its scheduler boundary while the real successor claims and releases ownership. The scheduler has its own retained execution proof, so teardown no longer drains unrelated timers during native SQLite work.
Wait for heartbeat delivery or its actual settlement instead of imposing a separate arrival timer. Preserve awareness/reset assertions and join admitted delivery after releasing the hook.
Original constrained shard replays passed and do not establish the exact CI trigger. Candidate proof passed 572 shard tests plus both scheduler-owner cases, focused lint/types and independent review through P2.
* test(ui): await startup request before coalescing assertion
* fix(file-transfer): declare node commands idle between invokes
A default headless node host could never pass the auto-update idle
barrier: file.stat, file.create, workspace.memory and workspace.skills
registered without hasActiveWork, and the node host treats a missing
idle hook as active work. Their work is invoke-scoped and already
counted by the runtime's in-flight invoke tracking.
* test(e2e): prove default-plugin nodes activate node auto-updates
* test(e2e): read the node-host subsystem console prefix
* docs(install): explain recovering 2026.9.6 nodes stuck before automatic updates
Release Checks 36479006821 saw both the published 2026.9.6 baseline and the
2026.9.7 candidate bind HTTP after 56-58 s and miss the fixed 90 s readiness
window on saturated runners, while the same phases pass in 36-41 s on idle
ones. Raise the default startup budget to 300 s and make the readiness wait
honor the configured budget instead of a hardcoded 360 polls, so the
OPENCLAW_UPGRADE_SURVIVOR_START_BUDGET_SECONDS override actually extends it.
* fix(node-host): prepare updates on Bun-only POSIX hosts
Read exact registry manifests and stream SHA-512-verified archives in process, then use shared Bun staging inside the private node runtime generation. Preserve npm preparation on Node and Windows, including existing schema and candidate checks.
Cover Bun preparation, private bins, retained generations, invalid registry archives, loopback discovery, and Windows npm selection. Remove the Linux smoke blocker and document the remaining Windows limitation.
* refactor(update): share registry package document reads
Consolidate registry URL construction, HTTP fetching, JSON consumption, deadlines, and response cleanup for update discovery and node runtime preparation. Preserve caller metadata mapping, HTTP error strings, diagnostic labels, and body timeout policies.
Remove the redundant registry status wrapper and share the existing discovery error return. This removes 25 production lines without changing preparation or its regression tests.
* fix(node-host): skip npm freshness probing for Bun preparation
* fix(node-host): create the private Bun node_modules root before staging
* fix(node-host): seed the private Bun global project manifest
* fix(node-host): skip Node engine checks for candidates run on Bun
* docs(bun): link node update preparation history row
* refactor(node-host): move registry archive reads out of install-source-utils
install-source-utils sits under plugin install owners; importing the shared
registry document reader from it closed an import cycle through the provider
and plugin metadata graph. The in-process manifest and archive reads now live
in a leaf module that only the node host imports.
Allow 1800s per first-hop container and 2100s per lane using measured
published/candidate hop durations with a slow-host margin. Give the
six-source release self-upgrade job 80 minutes for two resource-limited
waves and setup. Preserve phase timing and concise update-step evidence.
Keep updater behavior, live authority checks, source coverage, and runner
concurrency unchanged. OverlayFS runtime-copy and journal-read overhead
remain a separate product performance follow-up.
Validation: 211 focused tests passed locally with one worker (55.36s wall);
inner/outer budget assertions failed against the prior harness. Bash syntax,
formatting, lint, timing formatter smoke, and diff checks passed. Independent
Codex review found no actionable P0-P2 findings.
* fix(e2e): emit scheduler entry for Docker clients
Emit the scheduler imported by mounted release Docker clients and guard all Docker client runtime dist references against the configured build outputs.
Validation: generic guard fails on the original config; all 33 config tests pass on Blacksmith Testbox. pnpm test wall: 7.73s warm, 31.90s cold worker preparation; test time 192ms. Scoped lint, formatting, scripts/root-test types, and independent review passed.
* fix(e2e): reload first-hop service fixture between lanes
Reload the lane systemd shim after deleting its unit so a published updater does not see a stale loaded definition. Print both captured service-install streams when setup fails, preserving effective-service admission checks.
Validation: reset regression fails on original harness with the real fixture. All 17 systemd fixture tests pass on Blacksmith Testbox; pnpm test wall 13.62s, new case 556ms. Scoped formatting, lint, shell syntax, scripts/root-test types, and independent review passed.
* fix(e2e): stop gateway before restart recovery preparation
Standalone Doctor can start a stopped service. Use the existing confirmed-shutdown helper before preparing the separate recovery update, preserving restart, auth, and inactive-only start assertions.
Validation: all four new recovery cases fail on original harness and pass with the fix, including failed stop, active service, and open listener refusal. All 14 phase tests pass on Blacksmith Testbox; pnpm test wall 1.85s, new cases 15ms. Scoped checks and independent review passed.
* test(e2e): stop an inactive fixture service idempotently
* test(e2e): align survivor fixtures with recovery shutdown
Keep the verified shutdown phase before inference preparation. Model idempotent systemd stop in the prepared-service fixture and include the phase in companion and frozen-target harnesses without changing their auth, membership, restart, or survival contracts.
Validation: origin/main passes all 55 targeted tests; original branch reproduces 17 failures. Blacksmith Testbox passes all 898 survivor tests across 42 files, including recovery-phase and cron-seed. Changed-file test walls: mobile 2.33s, parking 7.36s, membership 3.41s. Formatting, shell syntax, focused lint, and independent review pass.
* test(e2e): include script clients in dist-entry guard
Scan both Docker client roots and resolve each runtime import against its own client URL. This closes the release guard gap for scripts/e2e without adding runtime entries or duplicate tests.
Validation: 33 config tests pass on Blacksmith Testbox; pnpm test wall 42.30s with cold worker compilation. Removing the scripts-only runtime-context entry passes the original guard and fails the extended guard. Formatting, scoped oxlint, and independent P2 review pass.
* chore(release): retire the Tideclaw alpha release track
Tideclaw alpha/nightly publication is retired. Alpha remains readable as
history (existing v*-alpha tags, published versions, changelog and
upgrade-survivor baselines, product version ordering), but it can no longer
authorize a release.
Every active release boundary now rejects an alpha version or -alpha.N tag,
the alpha npm dist-tag, and tideclaw/alpha/* workflow or tooling routes:
preparation, Full Release Validation publication selection, npm preflight,
approval receipts, core/plugin npm and ClawHub publication, native handoffs,
and finalization. Channel mappings throw for alpha instead of falling through
to latest. The Tideclaw branch routes, alpha dist-tag options, the alpha FRV
publication route, and the alpha-only Docker runtime-assets job are removed.
Beta, stable, extended-stable, and correction releases are unchanged.
The release-openclaw-nightly skill is deleted and the release skills and docs
no longer describe the alpha track.
* test(release): drop retired alpha preparation and finalization expectations
* test(release): drop remaining retired alpha references
Fixes four release-lane harness bugs that failed 2026.9.7 Full Release Validation independently of the product:
- openai-web-search-minimal selects the agent request by model and exact success prompt instead of the first request quoting the marker (Activity recaps quote it since #147441).
- plugin-update consent package updates use the existing 900 s update-lane budget; timeouts are reported as timeouts with stdout/stderr/ledger paths before JSON parsing.
- Windows packaged upgrade lanes pass the long spelling of the inherited TEMP/TMP/TMPDIR to published updaters (the immutable 2026.9.5 driver mis-compares 8.3 short paths; fixed on main by #151157).
- The QA mock calls session_status through dispatcher-aware capability detection, so the Telegram current-session scenario works under default Tool Search.
Each regression fails on the original harness code and passes with the fix (Testbox).
* fix(browser): keep Chrome MCP from probing npm on Bun-only installs
The pinned chrome-devtools-mcp server runs an update check that shells out
to `npm config get registry`. On a Bun-only install there is no npm, so the
Bun-only runtime smoke records an unlisted Node attempt in its browser step.
Launch the server with CHROME_DEVTOOLS_MCP_NO_UPDATE_CHECKS=1, which its
check-for-updates helper honors before spawning anything.
Drop three expected-node-blockers entries that no longer reproduce on main:
chrome-mcp-user-profile (fixed by #159422), tool-search-code-probe (source
removed with tool_search_code in #159398), and computer-control (the host
runs on the Gateway's runtime since #159462; never exercised on headless
Linux).
* fix(browser): leave custom Chrome MCP servers' update checks alone
Only the packaged, pinned chrome-devtools-mcp server gets the update-check
opt-out. Custom mcpCommand servers are operator-managed and keep their
upstream update notices; the transport now forwards the environment the
option normalizer chose.
Refresh OpenAI 7.20.0, Pi TUI 0.86.1, tsx 4.23.15, native TypeScript 7.1.0-dev.20260920.1, Tauri 2.11.6, single-instance 2.4.5, rand 0.10.3, and SimSlim 0.10.0 under the fixed 2026-09-20T18:25:54Z cutoff. Align companion manifests, native locks, Docker tooling, and SimSlim qualification. Preserve existing patches, overrides, the updater fork, and compatibility holds.
Validation includes 303 npm consumer cases, 148 Rust core cases, 63 desktop cases, 86 SimSlim cases, actual Linux container and SDK transport proof, four typecheck lanes, 102 npm lock mirrors, and cutoff/integrity audits. Synthetic terminal comparisons are attached to the PR and verified rendered. Independent reviews are clean through P2.
Land under explicit maintainer approval for proven pre-existing CI failures. Run 36376168824 exposed three unchanged Windows checkout-fixture inventory failures already repaired on main by #160024 (b9cd492ac6). The dependency delta does not touch that workflow/helper/test closure. No green full-CI result is claimed. No third-party PR, release, or deployment.
Preserve native-contained managed restart coverage for frozen targets whose committed runtime predates absent-membership recovery. Keep current targets on the strict absent-containment path with both warning receipts and run-ID matching.
The existing verified-source resolver owns selection and explicit sparse acquisition; Docker forwarding and preflight metadata carry the result. Updater, replacement, authentication, serving and survival assertions remain intact. Independent review is scoped-clean, with focused regression, sibling and acquisition proof documented in the PR. Installed-package release qualification remains separate.
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
Refresh application, plugin, native, build and container dependencies through the fixed 2026-09-19T16:27:11Z cutoff. Migrate native TypeScript snapshot/printer APIs while preserving compilation and filesystem contracts; retain existing patches and compatibility holds. Document offline container-image preparation.
Include the verified compiler process-census and loading-clock fixture repairs and deterministic warm-history regression. Adopt the canonical production history fixes from #159924 and #159955.
Land under the maintainer's explicit approval to treat proven pre-existing CI failures as non-blocking and repair main afterward. CI36365552098 failed an unchanged Android Compose fixture's asynchronous catalog projection assertion (3518 passed,1 failed); the Android/Gradle tree matches its main parent byte-for-byte. Security and dependency reviews passed. The final rebase preserves reviewed source changes and regenerates only the intentional Node-image documentation fingerprint. See PR159401 for complete validation and the follow-up repair obligation.
Use the fixture's admitted loaded-unit stop budget for policy inspection and cleanup. Preserve loaded snapshots until reload, retain supervisor custody through failed policy reads, and report failed stops only after observed cleanup. Adapt supervisor test callers without weakening their behavior checks.
Independent and ClawSweeper reviews resolved the outer-stop failure; installed-shim regressions cover policy loss, process extinction and uncertain settlement. Focused policy/cgroup and caller proofs passed. Full local suite setup limitations and exact-head hosted evidence are recorded in the PR. No product runtime changes or completed release qualification are claimed.
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
Bind upgrade-survivor Tool Search recipe coverage to the verified frozen target and expose the existing default-off manual Package Acceptance opt-in. Preserve all applicable migration assertions, package/plugin admission and other recipe coverage.
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
* fix(update): complete already-current updates before service membership guards
* refactor(update): prepare maintenance warnings in the no-op owner
* fix(update): manage updates when native containment is absent
Keep unreadable membership and genuine service descendants guarded while allowing verified external callers to use the existing managed stop/update/start lifecycle on hosts without native containment.
Record the lifecycle warning at terminal reporting, retain inspected service state for already-current maintenance, and exercise the managed Docker recovery and no-op paths.
* fix(update): bound readiness observation and backup cleanup
Reuse the restart deadline for native readiness reads and managed recovery. Restore the retained package and previous Gateway when startup never becomes ready, and retain obsolete backups with a warning when the cooperative cleanup budget expires.
* fix(plugins): retain source identities across native captures
* fix(update): preserve observed readiness timeout failures
Refine the existing phase only during recovery and restore it on success. Preserve updater exits, assertion short-circuiting, signal capture and cleanup ordering.
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
Add an advisory Bun-only runtime smoke to Install Smoke, run only by Release Checks (Full Release Validation). It
installs the verified candidate with the pinned Bun fork, hides every real Node inside a private mount namespace,
and exercises install, CLI, Gateway, node host pairing, a mocked agent turn, doctor, terminals, and the browser.
A PATH sentinel records every node/npm/pnpm/yarn/corepack execution with its exact path and process ancestry, a Bun
preload records the JS stack, and a classifier fails on any attempt missing from
scripts/e2e/lib/bun-only-runtime/expected-node-blockers.json or on a listed blocker that no longer reproduces.
Admin-merged with maintainer approval: the only failing required check was test/scripts/pr-wrappers.test.ts, a main
regression from b2e0e562 unrelated to this change. PR-owned tests (94), lint, workflow checks, check-dependencies,
docs, guards, and types passed at this head.
Resolve the probe route from the selected scenario attempt's surviving
messages and use the provisioned primary participant. Keep the first
sample fresh and reject replies from a different topic.
Preserve explicit probes and native observer admission. Rework the
original repair without migrating the scenario catalog.
Related: https://github.com/openclaw/openclaw/pull/137139
* fix(tool-search): run tool_search_code in the QuickJS sandbox
Tool Search code mode spawned a Node --permission child with a node:vm
guest. Under Bun it needed an installed Node, and without one an explicit
code config silently downgraded to structured tools mode.
Run the guest through the Code Mode executor contract with the bundled
quickjs executor on every runtime. openclaw.tools.search/describe/call use
the shared namespace bridge with lazy thenables; the host admits only those
three operations through ToolSearchRuntime. codeTimeoutMs still bounds the
whole invocation, now including executor preparation. A denied or disabled
code-mode-quickjs plugin fails explicitly with next-step guidance instead of
falling back.
Remove the child source, IPC types, stderr-tail handling, and the Node and
Electron capability probe.
* refactor(tool-search): retire the tool_search_code bridge
Keep structured Tool Search and generic Code Mode as the two large-catalog surfaces. Remove the superseded JavaScript bridge and its runtime, display, and QA paths.
Doctor migrates legacy code mode to tools and removes codeTimeoutMs while preserving activation. toolSearch: true now selects structured search; JavaScript orchestration uses Code Mode exec/wait.
* test(tool-search): cover runtime behavior through structured controls
Exercise retained catalog, policy, hook, cancellation, terminal, MCP and client behavior through structured controls and their runtime owner. Delete bridge-only sandbox and JavaScript envelope cases while preserving nested call-id compatibility.
* test(tool-search): drop retired code mode prompt case
* test: repair fixtures exposed by Tool Search retirement checks
Remove the remaining retired Tool Search mode row. Preserve the session reader owner through the media retention mock and remove an unreachable queued-only branch from the ACP controls/submission fixture.
* test(upgrade-survivor): seed retired Tool Search code mode config
Author the legacy mode and timeout through every supported representative baseline CLI recipe, then require structured search and timeout removal after candidate update and Doctor. Existing config validation proves the resulting effective config.
Include the diagnostics native assignment summary in frozen target staging; the required assertion suite exposed its missing import. Node recipe and assertion tests: 238 passed, 157.87s wall. Docker validation remains with the coordinator.
* refactor(tool-search): drop the retired code-mode recovery surface
* chore: shrink assertion baseline after Tool Search retirement
* test(tool-search): drop the unused Tool Search test API
* chore: drop the retired Tool Search test API assertion baseline
* fix(e2e): drop duplicate native assignment staging line
Main now stages native-assignment-summary.mjs for frozen upgrades itself; the branch copy from the Tool Search upgrade proof became a duplicate after merging.
* build(pr): list Tool Search migration in wrapper inventory
The scripts/pr wrapper loads the Doctor config migrations at runtime, so the new Tool Search retirement migration belongs in its extracted component inventory.
* test(e2e): ship the Tool Search recipe to prepared tooling workers
Prepared tooling workers copy only listed source-relative assets, while the
upgrade survivor config recipe reads every section file by name at import.
The new tools-tool-search.json was missing, so the Docker scheduler parent
signal test's runner died with ENOENT and its polling wait reported a generic
5 s timeout that looked like a flake.
List the asset, guard the recipe directory against the preserved list, and
make the scheduler readiness wait fail with the runner's stderr once it exits.
Failing check: checks-node-compact-small-3 (core-tooling-11), immutable
upgrade targets 2026.6.35 and 2026.7.33 in upgrade-survivor-assertions.
Tasks retirement added a static native-assignment-summary import to the
trusted diagnostics module, but frozen scenario staging omitted that
helper. Copy it beside the existing diagnostics helpers. Preserve the
selected historical runner and assertions; no runtime API or test changes.
The two reported core test type errors were already fixed by 0b6f02faae.
Proof on ff3c3cbb48 plus this patch:
- Reproduced exactly the two missing-module failures before the fix.
- All ten graphs from core-test stripes 3 and 5 passed.
- pnpm tsgo:core:test (all 25 graphs) and pnpm tsgo:core passed.
- Upgrade-survivor assertions and six siblings: 344 tests passed.
- Media retention, ACP preactive cancellation and accepted ownership:
24 tests passed.
- Changed-file gate, bash syntax, diff check and Codex P2 autoreview passed.
Broader sibling observations, unrelated to this one-line staging repair:
- docker-build-helper: 352 passed, 2 skipped, 2 June bundle-MCP failures.
Focused six-case replay moved the failure to log-removal cleanup.
The unchanged bundle-MCP runner's git archive | tar -x pipeline produced
empty-stderr SIGPIPE 141 in 15/30 standalone macOS trials despite correct
extracted bytes; --ignore-zeros passed 30/30. Left as a separate follow-up.
- Planner/mac/tooling selection: 2024 passed; mixed package/plugin consumer
planning timed out at 120 seconds, again on isolated reproduction.
Its inputs and planner are unchanged. The performance cause remains
unresolved; no timeout or assertion was weakened.
Remove Tasks and TaskFlow runtime, APIs, CLI, SDK surfaces and panels after the Cron, session, native execution and media completion ownership cutovers. Preserve stored rows and import provable legacy native assignments through Doctor; ambiguous ownership stays untouched with a warning.
Follows #158221, #158217, #158225, #158222, #158702 and #158776. Related: #156532. Task-specific public APIs retire immediately; retained responsibilities use their existing owners.
Maintainer-authorized administrative landing after full CI run 36312986498 attempt 2 passed on 274595e2, with subsequent actual conflicts reviewed and focused checks passing. Current PR CI preflight hits the 64 KiB changed-path metadata limit before tests (run 36335042695); its duplicate security-review status mirrors that planning failure. Review and scoped proof are recorded in the PR. Published 9.4 native import is proven; remaining native completion and 9.4 rollback witnesses are explicitly unproven.
* fix(ci): expose bounded Docker survivor failure metadata
Keep diagnostic artifacts and outcomes unchanged. Publish only redacted phase, exit and signal coordinates plus scheduler status and timeout flags as check annotations. Hosted review and CI remain pending; local dependency admission was unavailable.
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
* fix(ci): retain survivor metadata beyond clipped failure tails
Use a bounded host metadata pipe within the existing scheduler process owner. Validate the three fields and emit only after process-group and log cleanup. Preserve artifact bytes and all lane outcomes. Fix the publisher consistent-return lint defect.
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
* fix(ci): use typed Docker timeout flags directly
Remove two unnecessary boolean comparisons without changing annotation output or failure handling.
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
---------
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
Use transactions on the actual SQLite state and device databases for ordinary writes. Remove redundant coordination databases, transport, and exclusion layers while preserving bounded process ownership for startup, schema work, and offline maintenance.
Tie test and QA scratch retirement to settled workers and native resources, preserve active plugin captures, and join SDK declaration compiler processes before synchronous semantic rendering.
Validation: main-tier CI on 5e731c1f64 had 144 successful jobs and one Windows ACP initialization timeout. Qualified unchanged replay 36314027585 passed all 896 tests with the original 48-file order, six projects, toolchain, and deadlines. The original timeout remains unexplained and recorded in the PR. Reviewed main-conflict integration through 39caa592ef passes focused SQLite, Doctor, image, and Cron proof plus affected typechecks and lint. No accepted actionable independent-review findings remain.
Squash landing of #157413 under explicit maintainer authority to resolve logical main drift and admin-merge using the completed CI evidence. No PR-specific schema or public configuration migration.
* refactor: remove narrowly used helper dependencies
Replace markdown-it-task-lists and grammY runner sequencing with their local owners. Remove direct ms/pretty-ms usage and share the existing duration factors and formatting. Preserve rendering and parsing contracts, and keep overlapping Telegram lanes ordered when a predecessor fails.
Remove obsolete mocks, declarations, dependency metadata, and build references; regenerate the lockfile and Control UI boot manifest. Deduplicate an inherited over-limit replay test without changing coverage.
Closes#158499
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* refactor: remove narrowly used helper dependencies
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: f4ef665a-7e2b-47ce-a454-adc19e798bee
* refactor: remove narrowly used helper dependencies
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: abec5219-5bd0-4480-8604-a57c1063f638
* fix(ci): preserve base-only dependencies in UI comparison
Materialize removed dependency declarations from the archived base lockfile before overlaying the candidate toolchain. Keep both builds on the same Vite and compressor without restoring removed application dependencies.
Extend the real build regression with a dependency absent from the candidate and verify the original comparator fails to resolve it.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
* refactor: remove narrowly used helper dependencies
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 2db2eea4-87fe-4071-ab37-28da02f1bd24
* refactor: remove narrowly used helper dependencies
Worked on by:
- @steipete
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
OpenClaw-Publication: 8c381a6d-38f2-417f-85ee-9353cb5694dc
---------
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>