Commit graph

400 commits

Author SHA1 Message Date
Peter Steinberger
8c39234ebf
refactor(doctor): observe serving Gateway ownership off thread (#162021)
* refactor(doctor): observe serving Gateway ownership off thread

* fix(doctor): complete lease reader import dependencies

* test(update): adapt serving lease observation fixture
2026-09-30 14:11:57 -07:00
Peter Steinberger
5381128b68
fix(update): reduce oversized sealed recovery packages (#161919)
* fix(update): keep recovery imports within their owners

Separate fixed public error codes from executable diagnostic catalogs. Move the existing active handoff map, lease reader, and current-process observer together so callers do not import the service launcher to inspect an existing handoff.

Preserve public identifiers, sanitization, store selection, lease validation, and sealed recovery behavior. Guard the production bundle against capturing Doctor and service controllers, with staged repair and retirement coverage.

* fix(tooling): include update codes in native wrapper inventory

* fix(ci): bound isolated Gateway fixture workers

Keep the Gateway isolated/database-worker cohort at its existing two-worker budget so cold startup has room within unchanged test deadlines. Preserve former eight-worker complete generations as conservative timing floors without relabeling them as current measurements.

Validation: 325 owning tests, selected changed checks, and fresh managed review. Generated job counts and coverage are unchanged. Exact changed CI remains required.
(cherry picked from commit 30e80e790d)

* test(ci): isolate runtime placement pricing fixtures

Control spare compact capacity and the two workload inputs before asserting co-location. Restore the real runtime timing reader so refitted observations still force the overloaded workloads into separate rows.

Validation: 207 owning cases passed; removing the refitted observations fails the after-placement assertion. Restored-case verification, selected checks, and fresh managed review passed.
(cherry picked from commit 450dba2dc6)
2026-09-30 11:25:10 -07:00
Peter Steinberger
ad8327f586
fix(pr): requalify admission when final main objects are missing
Main can advance during prior-CI verification, leaving the final local-only
reread without its newly observed commit. Return that exact tip to bounded
pre-authority qualification instead of requiring another operator attempt.

Require Git's successful raw-object missing result with empty stderr and
readable previous/verified pins. Discard the active authority proof before
materializing, preserve the captured tip as an ancestry lower bound, and
rerun full live verification against the original proof fingerprint. Refuse
after three rounds without intent or dispatch. REST brackets stay unchanged.

Validation: original two regressions fail; all 47 final main-owner cases and both
confirmed cancelled-auto recovery cases pass, including revoked authority/evidence and
retained history. 47 REST sibling cases pass; one unchanged quota scenario returned
143 under its existing 20s fixture limit after merge/audit/comment and branch
deletions. That failed invocation is retained, not counted as full completion;
no deadline was increased. Initial truncated negative runs are also retained.
2026-09-30 10:25:35 -07:00
Peter Steinberger
1f6754a855
fix(pr): qualify real Gateway failures in cancelled UI jobs
A CI job can finish cancelled after its real-Gateway test step has already
failed. Preserve that failed step as an independently attributed root rather
than refusing its audited UI workflow family or treating it as collateral.

Bind the existing failedStep evidence to the exact UI command, private-QA
build, matrix selection, live check-run and ordered source steps. Recognize
only the explicit runner setup/cleanup pair, and retain all source, review,
security and cancellation checks. Cancelled coverage remains unrun.

Validation: both UI admission cases fail on the original owner; 66 combined
UI/Node/production-type cases pass, followed by 21 final UI cases including
cleanup refusals. The real retained job's 17-step sequence matches the
12-step source workflow plus its explicit runner prelude/postlude.
2026-09-30 09:27:54 -07:00
Peter Steinberger
5c8dd21423
fix(pr): identify failed local-only prior-CI commit probes
Report the previous-main, reread-main, or verified-main OID and Git exit
status when the final local-only commit check refuses admission. Sanitize
stderr through the existing redactor before bounded JSON-escaped display,
and use the selected trusted wrapper's loader configuration.

Keep probe ordering, no-lazy-fetch enforcement, authority checks, and merge
refusal unchanged. Cover all three roles, unavailable commits, unsupported
Git, oversized diagnostics, and an invalid caller checkout configuration.

Validation: original six diagnostic cases fail before the repair; final six
pass. Both prior-CI main-drift and REST owner suites passed (84 tests) before
the failure-only loader pin; the focused cases cover that final correction.
2026-09-30 08:41:27 -07:00
Peter Steinberger
5b6f9ff463
fix(pr): retain deadline context in cancellation refusals
Keep deadline context in the shared GitHub check-run identity refusal,
which also serves failed-step admission. The production-type extension
generalized that diagnostic and broke the existing deadline rejection
controls; all qualification predicates remain unchanged.

The unchanged deadline suite passes 20 runs (560 cases). Changed checks,
script types, typed and boundary lint, and independent P2 review pass.
2026-09-30 07:35:02 -07:00
Peter Steinberger
40367c40bf
fix(tooling): finish REST admission before final authority
Complete the selected REST observation and main materialization before the last authority verification, without reopening a redundant local-only observation window. Preserve GraphQL and late fallback admission checks.

Drain fake GitHub CLI response pipes before exit so lifecycle tests retain complete evidence. Cover forward main movement, final authority revocation, and complete success/error output.
2026-09-30 05:46:29 -07:00
Peter Steinberger
e96303d3bc
fix(tooling): qualify cancelled production type-check failures
Recognize the audited check-prod-types failed-step shape under the existing prior-CI verifier. Bind the GitHub check-run, workflow command, matrix/task inputs, source-step positions, complete timestamps, and successful cleanup while retaining the cancelled conclusion.

Independent failure attribution, unchanged source inputs, exhaustive cancellations, security, admin authority, and enforced reviews remain required. The final fixture fails on the original Node-only owner; 67 verifier controls and selected checks pass with the repair. Managed P2 review is clean.
2026-09-30 05:00:59 -07:00
Peter Steinberger
fcd59e6bdf
improve: keep SQLite workers alive on Bun builds that release native handles (#161764)
Bun builds that release SQLite native handles still paid for conservative worker retirement because lifecycle policy checked the runtime name. Capture the native-close capability after library selection and reuse it across broker placement, retirement, reader cleanup, and inherited worker admission. Bound probe termination to five seconds; timeout/error admission returns conservatively while unreferenced cleanup retains any unconfirmed live worker’s private directory. Stock Bun and Windows stay conservative; Node retains its existing policy. Register the disposable native probe with the SQLite guard and include the diagnostic parser, probe, and worker in the maintainer wrapper source inventory so isolated provisioning loads its complete dependency closure.

Proof: recovery median 11.4 s -> 0.1 s with 0/0 measured transcript worker creations/retirements. Gateway 50x25 load replies improved 128 -> 263 versus Node 273. Node 24 and the signed Bun test fork cover touched lifecycle and startup tests; changed checks, import-cycle checks, and full build verify the rebased tree.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-30 04:50:56 -07:00
Peter Steinberger
509cb47840
refactor: move workspace journal storage off the Gateway thread (#161539)
* refactor: move workspace journal storage off the Gateway thread

* fix: include workspace journal contract in PR wrappers

* fix: preserve repository authority through journal commits

* test: capture first-signin startup and RPC timing on timeout
2026-09-30 04:16:02 -07:00
Peter Steinberger
10ea4739bd
fix(nodes): apply the same tool policy to node sessions as Gateway sessions (#160444)
* fix(nodes): apply the same tool policy to node sessions as Gateway sessions

Share Gateway tool preparation and resolved filesystem/apply_patch policy with worker turns. Deliver the issued surface during admission and route Gateway-owned tools through one build-gated transport. Move session-tool grants and durable operation journals to the SQLite worker broker while preserving live authority, replay, cancellation, and recovery.

* fix(nodes): repair worker tool surface CI contracts

Keep worker-only schemas outside the operator registry, distinguish worker tool proxies from Gateway executors, and split runtime and receipt contracts from their implementations. Extract coherent source and test siblings without weakening authority checks or removing coverage. Remove unused profile inputs and migrate their internal callers.

Validation: 67 focused test files pass on the isolated Linux lease; core, package, source-test, extension, and UI-test typechecks pass. Protocol generation, export contracts, architecture, formatting, assertion safety, and line-cap checks pass. The changed-set Node matrix has 93 rows against its 130-row cap; aggregate production LOC remains negative.

* refactor(nodes): retire unused worker tool exports

Keep worker protocol primitives, local tool grouping, and the Skill Workshop descriptor private now that shared constructors own their callers. Remove the unused worker session-tool name type; no runtime implementation or public package entry point changes.

Validation: full Knip production and export scans, protocol generation/checks, core and package typechecks, and nine affected test files pass on the isolated Linux lease. The export-only diff passed independent review through P2.

* fix(nodes): preserve authority receivers and async fixture ordering

Bind portal authority methods to their owner, await worker recovery and authorization in affected fixtures, and preserve immutable tool descriptors while projecting tools. Enforce required braces and exhaustive operation handling, remove obsolete policy inputs and duplicate projections, and retire the no-longer-needed max-lines allowance.

Validation: typed lint on all changed files, core and complete source-test typechecks, and 88 focused test files pass on the lease. The portal receiver regression fails against the prior implementation. Independent repair review is clean through P2.

* refactor(agents): colocate configured main-session helpers

Keep configured-main lookup and creation with the existing sessions-send delivery owner after rebasing. Preserve roster, sentinel, optional agent identity, and Cron authority behavior while removing the line-cap growth. The main-key constructor is the same owner called by the previous constant-main adapter.

* test(workers): reuse the shared gateway tool capability

The attached environment fixture already advertises worker-gateway-tools-v1. Appending it again violated the admission schema uniqueItems contract and rejected both queued launches before the browser custody assertions could complete. Remove only the redundant import and entry; keep skill-resource admission and every custody assertion unchanged.

* fix(workers): register tool cancellation before yielding

Admission already prepares and issues the exact tool handles. Consume those validated handles synchronously during invocation so immediate cancellation and close can see the call before it yields. Preserve live authority checks, FIFO barriers, active-call joining, four-call bounds, and cooperative settlement.

The Gateway RPC regression fails on the prior implementation and passes with the fix. All 210 tests in 11 affected files pass; production LOC is unchanged by this repair.

* fix(tooling): include worker tool protocol dependencies in PR wrapper

Keep the trusted wrapper extraction inventory closed over the worker-admission runtime imports by including the worker Gateway-tool schema and its validation-error dependency. Preserve the extracted-context and inventory closure assertions.

* fix(workers): preserve control budgets across mixed-media results

Share encoded frame accounting with transcripts and keep unreadable input rejection inside its owner. Verify fresh catalogs and handles across warm retained turns, preserve current node launch limits, and align the async authority fixture after the main rebase.

* fix(workers): preserve protocol imports and live sender authority

Share canonical session-tool schemas and collapse duplicate tool, receipt, and teardown plumbing. Preserve published 2026.9.6 decoding imports without advertising retired RPCs. Carry sender authority through direct steering to the final enqueue.

* fix(agents): retain the typed tool description projection

* style(workers): retain compact type import layout

* refactor(tools): construct projected tools in a single pass

* fix(workers): preserve acyclic tool and receipt contracts

Keep cross-owner tool and receipt types in leaf modules. Consolidate preparation and live/abort checks without changing validation order, and reuse the canonical timeout and captured caller facts.

* style(workers): distinguish the prepared catalog binding

* fix(workers): project claim data before database dispatch

* refactor(workers): share publication settlement and string normalization

Preserve commit, rollback, invalidation, and tool binding order after main integration. Reuse the canonical string normalization owner and keep the complete production diff net negative.

* test(gateway): track lazy prepared tool construction

* fix(cron): use the prepared capability profile contract

* test(agents): restore real tools in prepared delivery fixture

* fix(protocol): preserve published worker presence decoders

Retain the schemas, types, validator, and feature constant shipped in
@openclaw/gateway-protocol 2026.9.7 as decoding-only APIs. Keep the retired
worker RPC unadvertised and preserve the published error-code schema shape.

Extend the compatibility regression and share static inventory transport
normalization. Production remains net -11 lines against the PR base.
2026-09-30 01:14:31 -07:00
Peter Steinberger
9d2ef5e1da
feat: add process census evidence for retained artifacts (#160292)
Process-census capability needed to distinguish a dead managed-service handoff owner from a surviving descendant: a Windows process census (PID, start identity, command line, cwd, owner SID with the foreign-owner rule from the Unix contract), verified Unix UID provenance for incomplete observations, and retained-artifact reference matching that reports matching versus unverified PIDs. Existing callers keep their classification when the new evidence is absent.

Refs #159897 (the reclaim itself follows in #160488).

Landed under the pre-existing-red rule: the remaining CI failures were current main reds in the merge window (fast-lane config expectation fixed by e0ec544eb1; cron service tests fixed by 5f76cc437d; update-candidate-canary from b36eb3e7b1).
2026-09-29 19:59:42 -07:00
Peter Steinberger
a3bc205d7f
refactor(config): deslop config sixth pass (#161364)
* refactor(config): deslop config sixth pass

Share config I/O execution, channel normalization, and validation owners.
Derive duplicate request and worker types from their canonical contracts,
remove the retired Tasks backing reader, and simplify metadata projection.

Preserve schema output, defaults, environment behavior, Doctor migrations,
redaction, and persisted state. The combined cleanup removes 648 net
production lines; the PR includes the complete large-file coverage log.

Validated on Blacksmith Testbox: check-changed, build, full config/caller
selection (5960 passed), schema byte parity, import boundaries, and both
import-cycle checks. Existing native Windows and benchmark skips remain.

* docs(config): refresh worker inventory after reader cleanup

* docs(config): align worker inventory with current main

* refactor(config): retain main config context during cutover
2026-09-30 02:49:14 +00:00
Peter Steinberger
7cf9ad48b8
fix(pr): allow mergeability recalculation during auto cancellation
Compare every identity, head, main, request and policy fact while allowing the two advisory mergeability projections to change only during explicit auto cancellation. Ordinary merge admission stays unchanged.

Validation: both original cancellation failures reproduced; all 15 owning tests passed; selected static checks, Bash syntax and independent review passed.
2026-09-29 16:48:17 -07:00
Peter Steinberger
ed00b848ed
refactor(agents): deslop agents core fourth pass (#159856)
* refactor(agents): deslop agents core fourth pass

* refactor(agents): keep type owners acyclic and remove stale exports

* refactor(agents): preserve legacy display projection and wrapper inventory

* refactor(agents): retain lazy tool factory access
2026-09-29 16:18:54 -07:00
Peter Steinberger
f309dc4bf6
fix(pr): distinguish CI deadlines from matrix cancellation
Qualify the inspected historical package-boundary deadline through its
unchanged workflow owner, exact live check identity, complete annotations,
ordered terminal steps, elapsed 20-minute budget, and successful cleanup.
Keep successful-shard/one-annotation and cancelled-shard/two-annotation
shapes distinct, and retain the failed job and any unrun coverage honestly.

Bind Node matrix cancellation to its explicitly inspected, nonempty unique
subset of independently qualified failed causes and every cancelled row.
Unrelated UI or deadline roots stay in the aggregate's exhaustive failure
attribution without being misclassified as Node matrix members.

Preserve security, enforced review, head/source identity, and operator
qualification requirements. Extend native admission regressions and
rejection controls without changing the evidence version or timeouts.
2026-09-29 16:12:11 -07:00
Peter Steinberger
2d85731967
refactor(infra): deslop infra sixth pass (#160850)
* refactor(infra): deslop infra sixth pass

Consolidate canonical owners and remove redundant forwarding, projections,
type declarations, and unread state across infra. Preserve persistent stores,
filesystem/security boundaries, SSRF policy, and update/install behavior.

Keep Fleet hardlink archive coverage at the surviving owner. Retain the
SQLite bootstrap's dependency-free guard after import-boundary validation
rejected loading a package alias before Vitest configuration was ready.

Independent review is clean through P2. Validation remains incomplete after
Blacksmith source-sync failures and local artifact-preparation refusal;
keep the PR draft until the remaining scoped gates pass.

* refactor(infra): retain presence typing and shrink assertion allowances

* test(cron): align heartbeat prompt fixtures

* fix(infra): preserve astral comparisons and prepare Code Mode workers

Use equivalent Unicode property alternatives so astral comparison operands
survive plain-text sanitization on affected Node runtimes. Retain the tag
grammar, HTML element checks, matching-closer checks, and numeric right operand.

Prepare Code Mode's compiled worker generation through the existing runner
owner before timed cases start. Add deterministic regressions at both CLI
routes and retain the existing deadlines, import assertions, and cleanup checks.

* test(infra): exercise browser registry precedence through its owner

* refactor(infra): preserve explicit projections and cleanup ownership

* fix(infra): preserve native script import boundaries

Restore main's self-contained exact-duration formatter so native Node
entrypoints do not resolve a runtime .js import to a TypeScript source.
Include the existing npm JSON helper in the canonical PR wrapper inventory
so extracted wrappers retain their runtime dependency closure.

Keep test assertions and deadlines unchanged. The declaration file passes
three times; wrapper closure and provisioning pass on Blacksmith. Changed
checks and both cycle checks pass, with no cycles and clean P2 review.
2026-09-29 14:00:02 -07:00
Peter Steinberger
477cab2d71 fix(infra): preserve definite snapshot allocation refusals
The native allocation custody added in 9c93bc347c (#160946) treats an ordinary
invalid-root creation refusal as an unknown allocation. This replaces useful
staging-root diagnostics with a cleanup aggregate and makes final retirement
of valid concurrent or nested snapshots fail after a rejected request.

Record completed directory-creation refusals at the native producer without
replacing error identity or codes. Carry that fact through the existing
two-field worker result. Lost replies, token failures, incomplete cleanup,
and native errors after successful creation retain unresolved custody.
Extend the physical token-lifetime fixture with a failed allocation before a
valid nested one, and include the helper in the PR wrapper runtime inventory.

Validation on the reviewed candidate 8abecdbee2:
- macOS arm64 Node 24.21.0: 58 focused tests passed; 4 Windows-only skips.
- Windows x64 Node 24.21.0: 17 tests passed; 3 existing POSIX-only skips.
  Native creator refusal, async invalid-root diagnostics, nested cleanup,
  empty cache, and physical token-child exit assertions passed.
- Selected core, docs, and tooling checks, independent P2 review, and the
  existing PR wrapper eager-import closure check passed.

Windows proof: https://github.com/openclaw/openclaw/actions/runs/36611103478
The Windows workflow checked out the exact candidate source; its separately
reviewed workflow ref preserved the no-Defender-exclusion setting. Broader
runner-descendant settlement was not attested; Actions owned VM teardown.

Integrated patch-identically onto current main with unchanged snapshot owners
and dependency inputs, preserving the intervening updater fixture repairs.
2026-09-29 11:27:45 -07:00
Peter Steinberger
114c92cb45
fix(pr): complete interrupted prior-CI admin merges
Reconstruct and label a historical landing-parent audit before delayed cleanup checks. Retain the original admission proof and CI caveat without claiming an original at-landing audit or current-head CI success. Preserve exact receipt, source, CAS, and uncertain-comment protections.
2026-09-29 10:14:56 -07:00
Peter Steinberger
e47d0ce424
fix(update): preserve original state before direct updates (#161044)
Some checks are pending
ClawSweeper Dispatch / dispatch (push) Waiting to run
CodeQL / Security High (actions) (push) Waiting to run
CodeQL / Security High (channel-runtime-boundary) (push) Waiting to run
CodeQL / Security High (core-auth-secrets) (push) Waiting to run
CodeQL / Security High (mcp-process-tool-boundary) (push) Waiting to run
CodeQL / Security High (network-ssrf-boundary) (push) Waiting to run
CodeQL / Security High (plugin-trust-boundary) (push) Waiting to run
CodeQL / Security High (process-exec-boundary) (push) Waiting to run
Docs Sync Publish Repo / sync-publish-repo (push) Waiting to run
Docs / docs (push) Waiting to run
Node Runtime Conformance / scope (push) Waiting to run
Node Runtime Conformance / TypeScript contracts (push) Blocked by required conditions
Node Runtime Conformance / Rust workspace (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / scope (push) Waiting to run
Plugin Init Scaffold Validation / Validate provider scaffold (push) Blocked by required conditions
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / approve_plugins_npm_release (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
* fix(update): preserve original state before direct updates

Retain manual recovery evidence before direct update initialization and
Doctor state relocation, and carry the original reference through delegated
Doctor calls. Reuse the existing capture format, maintenance custody and
configuration reader, while deferring debug persistence until admission.

Distinguish manual and incomplete captures, and report restoration only
from evidence bound to the same manifest. Published legacy and inherited
updaters retain their existing limits; this does not add automatic restore.

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>

* test(update): admit contention fixture as an npm install

Preserve the real SQLite contention and history assertions by supplying package-manager ownership in the existing fixture mock. Clarify why updater debug persistence remains deferred until Doctor has admitted the schema.

* fix(tooling): include debug deferral in PR wrappers

* fix(update): preserve early refusal history and diagnostics

Capture originals before admitting refused updates to history. Preserve managed installation context and structured pending diagnostics without finalizing an uncertain run. Keep JSON refusals and ledger-only repair consistent with the recorded outcome.

* refactor(update): isolate initialization admission types

* fix(update): report tracing deferral during dry runs

Warn on stderr when the selected update environment enables HTTP capture,
while preserving tracing deferral and machine-readable JSON output. Extend
the existing preview controls and align the capacity refusal assertion
with the recorded failed-run contract.

---------

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-29 09:30:01 -07:00
Peter Steinberger
61732a9a36
fix(pr): recover a cancelled auto request on the same head
Allow an explicit --replacement-head selection to retain the reviewed and prepared SHA after confirmed auto retirement. Keep current prior-CI, review, security, admin, artifact, capture, and outcome-CAS checks. Preserve the separate no-argument rejected-admin REST recovery route and update the operator help.
2026-09-29 09:08:03 -07:00
Peter Steinberger
9c93bc347c
fix: retain shared-state snapshots through worker failures (#160946)
* fix: retain shared-state snapshots through worker failures

Keep preparation, query, and cleanup under the existing read owner.
Retain native child custody across disposable Worker loss, preserve admitted
source identities, and join cleanup before releasing the original directory.

Preserve existing schema, retention, SDK, and exact-native backup contracts.

* fix: preserve native wrapper imports and callback type contracts

* fix(tooling): retain dynamic snapshot cleanup dependencies

* fix(test): prepare package contract workers before tests

Prepare the Memory Core facade’s compiled worker dependencies through the existing runner owner before Vitest starts. Keep the runtime export assertion and its deadline unchanged.

Extend the actual pre-spawn lifecycle cases to cover direct and project-selected contract tests, including exclusions.

Validation: causal preparation-order failure, 35 artifact-owner cases, 19 unchanged package-contract cases, changed-file checks, and independent review.

* fix(sqlite): retain original snapshot cleanup across reloads

Carry the original complete-removal operation into re-imported callers instead of treating it as token retirement followed by another pathname deletion. Preserve both original and current reader fences, native join, and retry against the original cleanup owner. Remove the retired async registration path.

Exercise real replacement bytes and target loss, and inject Cron copy/removal failures in the actual workers. Both original regressions fail; the correction passes 35 Node cases, the canonical Bun lifecycle case, types, lint, export checks, and independent reviews.

* test(agents): share queued-registration context captures

Expose the read-context capture through the same synthetic source owner as the existing writer capture. This lets the uncertain-kill case finish canonical restoration instead of leaving its failed cleanup to contaminate subsequent registration cases.

* test(agents): run entry settlement with host broker

Route the existing run-entry suite through the database worker inventory
so asynchronous requester settlement can use the host broker.

The embedded thread lane failed five cases after #160778. All 32 cases
pass through normal infra fork routing. Scoped formatting, lint and
independent P2 review pass.
2026-09-29 07:40:30 -07:00
Peter Steinberger
255bcd032c
fix: prepare private QA artifacts for local PR gates (#161217)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-29 07:12:18 -07:00
Peter Steinberger
c374040735
fix(pr): qualify failed Node steps in cancelled CI roots
Keep explicitly attributed Node test failures as roots even when GitHub marks the job cancelled. Bind the failed step to its live check-run and unchanged audited workflow, preserve cancelled status, and retain independent baseline, review, security, and authority checks. Other cancelled jobs still require the existing deadline or collateral evidence.
2026-09-29 05:41:25 -07:00
Peter Steinberger
c82063902a
fix(pr): settle GraphQL projections after verified main advances
Apply the existing bounded prior-CI recalculation path to GraphQL snapshots
as well as REST. Keep all non-projection facts pinned, prove each forward
main composition, and require the projection to return to its known values
within the same three observations.

Recheck live authority when recalculation adds waits to the final local-only
window. Preserve persistent-UNKNOWN, changed-fact, revoked-authority, and
missing-local-object refusals, along with ordinary and retained-outcome rules.
2026-09-29 02:24:08 -07:00
Peter Steinberger
52992fb086
refactor: use fs-safe for file watching and preserve Doctor plugin captures (#159226)
* refactor(infra): share filesystem observation policy

Centralize polling overrides, guarded source admission and metadata sampling. Bound remote file notifications and join accepted output before shutdown.

* refactor: migrate config, skills, memory and dev watchers

Use fs-safe invalidations and scope replacement while keeping source selection, settling, reload and indexing policy with each owner. Remove first-party Chokidar, bespoke native transports and duplicate observation tests. Preserve joined application work and watch-limit degradation; isolate manual Gateway writer fixtures from filesystem readiness.

Supersedes #158182. Thanks @vincentkoc.

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>

* fix(memory): use host filesystem observation for captured plugins

Pair watch with SDK Root admission so captured plugin dependencies cannot split
fs-safe's module-local Root registry. Preserve the strong Root check and route
existing watcher tests through the host SDK boundary.

Keep the eager Skills subscriber snapshot with Array.from and remove the new
lint suppression without changing the production suppression allowlist.

* fix: preserve fs-safe fallback for legacy polling overrides

Treat legacy false, zero and empty polling overrides as a native preference
so Bun and installations without the native addon retain working observation.
Capture Config polling-recovery eligibility per observer to preserve the
explicit override retry limit.

Prepare the Skills recovery test through its existing worker owner and load
the real snapshot dependency before cases begin. Keep recovery assertions,
timeouts and artifact verification unchanged.

* test(memory): check resolved observation backend health

* fix(plugins): preserve native capture authority and lifetime

* test(ci): scope native Doctor proof to its runtime owners

* fix(plugins): break capture storage type import cycle

* fix(memory): import observation types through host SDK

* test(gateway): isolate operation journal fixtures

* fix(qa): point worktree lifecycle scenario at surviving run-end cleanup tests

#160308 deleted src/agents/worktrees/service.run-end-cleanup.test.ts, which the
managed-worktrees-workboard-lifecycle scenario still listed as a codeRef, so
extensions/qa-lab/src/scenario-catalog.test.ts failed on main. The surviving
run-end cleanup outcome coverage lives in service.test.ts (late claims, stale
lifecycle writes) and service.removal-safety.test.ts (dirty retention).

(cherry picked from commit 3a300c650a)

* test: isolate planner contracts and share installer shell

* refactor(gateway): schedule remote skill refresh (#160318)

## What Problem This Solves

Remote-node skill refresh still kept a private debounce timer and threaded its handle through Gateway startup and shutdown.

## User Impact

Skill changes keep the existing 30-second debounce, now owned by the kernel scheduler. Shutdown joins an active refresh and suppresses late broadcasts. Updating needs no operator action or config, storage, or public SDK migration.

## Why This Change Was Made

Schedule refresh directly with the existing scheduler. Remove the timer getter/setter, delay option, runtime handle, and redundant close hook.

Production **+18/-36/net -18**; tests **+100/-38/net +62**; docs **0**. Production counts use src/** and extensions/** with the work-order test exclusions.

## Evidence

Deslop and Codex autoreview completed with no actionable findings through P2. Focused proof passed on blacksmith-testbox lease `tbx_01m3k4y56rf9r63tzs4hck3pek`, [run 36378613468](https://github.com/openclaw/openclaw/actions/runs/36378613468); unchanged source/test hashes were verified in the later proof. Each command used `pnpm test <file> --maxWorkers=1`:

| File | Tests | Command wall |
|---|---:|---:|
| src/gateway/server-startup-early.test.ts | 14 | 14.763 s |
| src/gateway/server-close.test.ts | 80 | 23.385 s |
| src/gateway/server-startup-lifetime.test.ts | 14 | 37.299 s |

The closeout docs PR will carry the complete census and merged-main sleep/shutdown proof; that live proof is still pending.

Exact-head `node scripts/check-changed.mjs --base 5362ba0ca3 -- <all 6 changed paths>` passed on `4fafc2add7`: production typecheck, 25 dependent test type graphs, lint (0 warnings/errors), dead-export scans and boundary guards. Check wall **1610.89 s**. Provider blacksmith-testbox, lease `tbx_01m3khvbn4fa9jb0bhe5qqp3we`, [run 36397188865](https://github.com/openclaw/openclaw/actions/runs/36397188865). The candidate was materialized in a clean detached worktree because native sync retained its hydration HEAD.

## Inherited CI failures and landing evidence

Completed exact-head CI [36402003337](https://github.com/openclaw/openclaw/actions/runs/36402003337) has two underlying failures plus its aggregate gate. Both match independent PRs:

- `gateway-agent-skill-refresh.e2e.test.ts:304` (called from line192): expected lifecycle count3, actual2. Identical without this cutover on approval [run36401825740/job108861794753](https://github.com/openclaw/openclaw/actions/runs/36401825740/job/108861794753). The unchanged synchronous `src/skills/runtime/refresh-state.ts` producer invokes the test's earlier registered listener directly. This PR changes a separate downstream remote-bin refresh consumer; the failing lifecycle count precedes the debounce/broadcast assertion.
- `subagent-completion-blocked.e2e.test.ts:78`, ordinary delivery exhaustion: expected suspended, actual pending. Identical on questions [run36403551682/job108867383832](https://github.com/openclaw/openclaw/actions/runs/36403551682/job/108867383832). Neither PR touches that completion owner.

Focused tests and the complete exact-head Testbox gate passed. The maintainer's standing instruction authorizes pinned admin squash over these inherited failures. No CI rerun or weakened assertion was used. The installed wrapper rejects the CLI admin argument shape; the native workflow's protected GraphQL merge route preserves the same squash, message, and expected-head payload used by that CLI operation.

(cherry picked from commit df785c0971)

* test(gateway): adapt skills proof to fs-safe lifecycle

* test(skills): normalize Windows observation lookup

* test(memory): isolate guarded reconciliation from native hints

(cherry picked from commit f07aececc0b5641a00adfd0271c89e7c7162d38d)

* test(channels): update Synology context builder inventory

Match the selected builder spelling after the Synology inbound route was inlined in #160639. Preserve the existing caller inventory assertion and production behavior.

* test(skills): assert subscription renewal during recovery

* fix(ci): exchange hybrid parallel groups within the job cap

Reuse the existing bounded exchange optimizer for final hybrid consolidation. Preserve group ownership, child worker limits and admission budgets while reducing the fs-safe composition from 80 to 78 rows. Scope exchange by backend so valid Blacksmith layouts and cap-independent plan identity stay stable.

* fix(test): retire subagent sweepers before SQLite owners

Stop the original subagent registry before non-isolated file cleanup retires
its SQLite owners. Join accepted sweeps and cleanup tails while preserving
synchronous fixture resets, successor scheduling, and the actor path guard.
Await the new reset contract in the concurrency benchmark too.

Baseline controls demonstrate an old registry tick recreating a retired
shared-state owner and premature settlement of three in-flight retirements.
The receiving candidate passes 102 owning/sibling cases, including the
17-case nested fixture (16 passed, one expected skip). The benchmark with
eight child sessions also passes. The owning run took 156.42 seconds.
Types, lint, formatting, export scans, and repository guards were qualified.
The exact historical hosted timer schedule remains unobserved.

* test(ci): isolate worker boundary fixtures from prebuilt mode

Keep synthetic historical runner fixtures in their explicit no-dist mode so
an inherited CI prebuilt flag cannot enter package preparation before the
worker-owner boundary. Preserve all six fixture modes and their assertions.

* test(ci): align runner fixture with canonical main

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-29 01:05:11 -07:00
Peter Steinberger
22894943a7
fix(pr): retain prior-CI admission across late REST fallback
When a landing snapshot exhausts GraphQL quota after initially known
metadata, select the complete prior-CI REST observation instead of applying
ordinary all-green admission to explicitly attributed failed CI. Verify both
main boundaries and persist REST selection outside command substitutions so
the final live authority check still runs before the pinned merge request.

Preserve common PR facts during transport selection and pin REST policy on
subsequent reads. Ordinary and Crabbox admission remain unchanged; unavailable
mandatory GraphQL review evidence still refuses the merge. Cover early and
final observation fallback plus authority revocation during the final read.
2026-09-29 00:29:10 -07:00
Peter Steinberger
fb5f1954a2
perf(sqlite): prepare NOCOW stores and add offline btrfs repair (#160877)
* perf(sqlite): prepare NOCOW stores and add offline btrfs repair

* fix(sqlite): complete NOCOW integrity and tooling integration

* test(gateway): leave terminal fixture cleanup with its suite owner
2026-09-29 03:25:36 +00:00
Peter Steinberger
59490dc752
fix(pr): settle mergeability after verified main advances
A complete prior-CI REST observation can report UNKNOWN while GitHub
recalculates mergeability after main moves. Permit a bounded three-read
settlement window only after proving that forward transition. Keep the
original known projections and all identity, policy, and check facts pinned;
unknown or changed known projections still cannot authorize dispatch.

Track the latest validated main separately from the retained intent anchor,
so repeated same-main UNKNOWN and rollback to another descendant of the old
anchor remain refusals. Preserve local-only final reads and live authority
validation after the complete REST work.

Cover the actual native admission path at later stability and final authority,
plus exhausted waits, identity/policy drift, conflicts, rewind/divergence,
missing final objects, revoked authority, and retained-outcome fencing.
2026-09-28 20:17:16 -07:00
Peter Steinberger
9148fbb46a
fix(nodes): explain and recover session-host setup problems (#160188)
* fix(nodes): explain and recover session-host setup problems

Report unsafe workspace ancestry before dispatch, resume pending node pairing
after approval, explain runtime command availability at its authority owner,
and log inventory publication failures only when they change. Share inventory
validation and remove superseded policy and projection helpers.

* test(nodes): assert specific dispatch remediation messages

* test(nodes): align pairing retry coverage with node recovery

* fix(nodes): preserve desktop access after hosting failures

Keep connected-node environment availability separate from session hosting readiness and retain diagnostic placement refusal. Include Codex plugin installation in missing-command remediation. Cover the inventory-to-environment boundary with real connected-node enumeration.

* refactor(nodes): share runner declaration validation

Keep the status-wait capability added on main while extending the existing strict record schema with bounded hosting diagnostics. Remove the superseded declaration parser and clone closed worker-host snapshots through one path. Production code remains net zero against the refreshed base.

* fix(nodes): retain exhaustive command diagnostic states

* refactor(nodes): preserve explicit diagnostic return flow
2026-09-28 19:13:09 -07:00
Peter Steinberger
73182e751e fix(ci): add config-env-values to the PR wrapper inventory
PR #160843 moved the config env allowlist into src/config/config-env-values.ts,
which src/config/config-env-vars.ts re-exports, but scripts/pr-lib/wrapper-components.txt
was not updated. The materialized origin/main trust anchor therefore fails every
scripts/pr review-init with ERR_MODULE_NOT_FOUND, and
test/scripts/eager-import-closure.test.ts is red on main (5 of 16 cases).
Adding the inventory line restores the closure; the test passes 16/16.
2026-09-28 19:11:07 -07:00
Peter Steinberger
d5447648d4
fix(pr): validate main movement within prior-CI REST reads
Route the beginning and end of an active prior-CI REST observation through
the existing forward-main ancestry and merge-composition owner. Recheck
branch policy without replacing the original check snapshot, and preserve
strict main stability for ordinary REST admission and inactive recovery.

Verify the original main anchor and both endpoints locally after final
authority validation, suppress lazy fetch throughout composition, and keep
transient read bounds out of retained outcomes. Report endpoint and timing
facts without claiming an unobserved GitHub transport route.

Prove the former pre-dispatch refusal and valid forward movement, with
negative controls for rewind, divergence, conflict, empty change, policy
and authority drift, missing local endpoints, and uncertain outcomes.
2026-09-28 19:04:03 -07:00
Peter Steinberger
25df9ed0f5
fix(doctor): preserve the live plugin index during read-only checks (#160400)
* fix(plugins): keep Doctor native captures out of live state

* test(plugins): use complete metadata snapshot fixtures

* fix(doctor): retain native captures in the profile context

* fix(doctor): include capture resolver in trusted wrapper
2026-09-29 00:52:38 +00:00
Peter Steinberger
91a86e494e
refactor(plugins): deslop plugin runtime fifth pass (#159945)
* refactor(plugins): deslop plugin runtime fifth pass

Consolidate repeated provider, manifest, install, catalog, hook and registration projections under their existing owners. Preserve plugin loading, SDK, caching and source-security contracts.

Preserve provider wizard modelSelection preferences through registration so configured onboarding choices retain their documented model-picker behavior.

* fix(plugins): preserve build and type cleanup contracts

* fix(plugins): retain distinct public credential source types

* fix(plugins): preserve sparse catalog matching and cleanup contracts

* fix(plugins): preserve include ownership during uninstall

* fix(plugins): include request policy in PR wrapper inventory
2026-09-28 16:59:20 -07:00
Peter Steinberger
87702484d1
fix: worker turns fail on older session-host nodes after the Gateway adds a worker tool (#160147)
* fix(gateway): keep worker turns working on session hosts that predate new worker tools

A Gateway built from main added the `presence` worker session tool, and
every worker-turn launch to a published openclaw@2026.9.6 session-host
node failed with `INVALID_REQUEST: invalid worker launch descriptor`
followed by `node worker cancellation timed out`. The installed node
supervisor validates `toolAuthority.allowedToolNames` against a closed
vocabulary, and bundle refresh does not replace the supervisor.

The Gateway now negotiates the launch vocabulary per node, following the
existing capability pattern: it advertises
`node-worker-launch-tool-names-v1`, updated nodes declare
`workerHost.launchToolNames` only to Gateways that advertise it, and the
Gateway treats an absent declaration as the frozen 2026.9.6 vocabulary.
Tool authority filters the projected tool set by the destination
vocabulary, so turn authorization and the launch descriptor stay
identical. Unknown declared names are ignored, so future worker tools
need no further capability.

Update behavior: Gateway-first updates keep older nodes hosting turns
without newer tools (one info log names them); node-first updates keep
the declaration unchanged for older Gateways; updated pairs get presence.

* fix(scripts): add worker tool authority to the PR wrapper inventory

src/infra/node-runner-inventory.ts is in the trusted-anchor PR wrapper's runtime import closure and now imports src/worker/tool-authority.ts for launch tool-name negotiation; the extracted wrapper could not resolve it.

* test(gateway): await the shared async node tunnel manager fixture

Main moved createManager into node-worker-tunnel.test-support.ts as an async helper (#160415); the launch-vocabulary lifecycle test still called it synchronously.
2026-09-28 21:58:24 +00:00
Peter Steinberger
0b44647a90
fix(scripts): accept the CI workflow's fail-fast expression in admin landing (#160721) 2026-09-28 14:54:22 -07:00
Peter Steinberger
548a1b899f
fix(pr): qualify attributed CI job deadlines
GitHub Actions can report an exhausted Node job deadline as cancelled.
Recognize only an explicitly attributed root with a matching current Actions
check-run, complete deadline annotations, consistent timing and unchanged
workflow. Retain its cancelled status separately from fail-fast collateral.

Keep source attribution, reviews, security, authority and exact-head checks.
Native regression and refusal controls pass; isolated Linux qualification
preserves the existing command deadlines and retained incomplete CI coverage.
2026-09-28 13:14:13 -07:00
Peter Steinberger
3ad12d9287
perf(nodes): finish remote session turns without status polling delay (#160162)
* perf(nodes): finish remote session turns without status polling delay

Negotiate bounded status waits with paired nodes so completed turns return
as soon as their durable receipt settles. Retain polling for older nodes
and preserve current authority, exact receipt identity, cancellation, and
physical cleanup barriers.

Overlap independent tool cleanup and transcript settlement before the
terminal ACK. Reuse main's capacity parser, the closed hosting schema,
and canonical command/deferred owners; remove duplicated inventory
comparison and receipt validation paths.

Validated on the assigned Linux lease with 388 focused tests and
pnpm tsgo:core. Production LOC versus the rebased merge-base is net -3.

* perf(cli): keep node inventory schemas out of root help

* test(nodes): use the shared worker capacity constant

* refactor(nodes): simplify concurrent transcript settlement

Preserve concurrent cleanup and transcript barriers in the inlined worker turn owner after the prompt-caching integration. Keep main failure precedence and block terminal acknowledgment when transcript settlement fails.
2026-09-28 13:05:40 -07:00
Peter Steinberger
28340c41f8
fix(pr): read complete REST facts for prior-CI admission
When GraphQL keeps a valid merge projection UNKNOWN, explicitly approved prior-CI admission may select the existing complete writer-bound REST observation. Preserve known facts and REST provenance, and revalidate live authority after the final complete snapshot. Ordinary merge and security requirements remain enforced.

Validation: 138 composed native cases, causal original refusal and late-authority mutant, selected static/type/lint checks, and independent review. No partial snapshot or synthetic passing CI state is introduced.
2026-09-28 12:02:14 -07:00
Vincent Koc
4373f42f5f
fix(pr): keep correction publication valid after first push (#160587) 2026-09-29 00:58:00 +07:00
Peter Steinberger
3e4e9cd4ae
fix(pr): recover retired auto requests with replacement admin proof
Allow an explicitly selected different head after confirmed auto cancellation to use current prior-CI admin admission. Preserve the accepted intent, cancellation, captures, and CAS ancestry; rerun replacement-head review, preparation, security, authority, and CI attribution checks. Same-head provider-rejection recovery remains separate.

Validation: causal original refusal; 54 Linux native recovery cases; CLI forwarding; selected types, guards, lint and independent review. No failed CI or cancelled coverage is relabeled as passing.
2026-09-28 10:49:40 -07:00
Peter Steinberger
cb3755a343
perf(gateway): retain prepared state across channel config reloads (#160274)
* perf(gateway): retain prepared state across channel config reloads

Preserve session rows and model catalog readiness when channel transport settings change. Keep model/auth and roster invalidation under their existing owners and await atomic catalog replacement. A 7,908-row file-reload fixture drops from 1,253 ms to 46 ms with no rematerialization.

* test(gateway): align reload fixtures with runtime snapshots

Publish prior configuration through the runtime snapshot owner used by hot
reload. Keep the agent-local and neutral compaction assertions, share auth
fixture construction with the config test-support module, and use Vitest's
call-order matcher for credential publication ordering.

* test(ui): wait for lazy tooltip readiness before measuring motion

Wait for the open, positioned popup after the hover timer starts its lazy
module import. Preserve the existing motion and placement assertions instead
of reading shadow parts before custom-element registration completes.

* test(ui): share canonical liveness in progress widget fixtures

Seed the canonical session with the same running facts as its main-scoped
list response. Fresh descriptor snapshots can then reconcile without clearing
fixture-only liveness fields. Preserve the writer-scope negative control and
all existing progress and activity assertions.

* test: stabilize planner and heartbeat CI proof

Skip import parsing for files outside a targeted source scan while keeping full-graph reads complete. Synchronize heartbeat delivery fixtures on their existing lifecycle events instead of a shorter wall-clock deadline.

* test: stabilize CI fixture readiness and preparation

Keep independent planner inputs in separate cases, model completed AI declarations in the build stub, and wait for roster or composer readiness before UI interactions. Serve sharing evidence through the canonical mock session owner so owner-role fixtures render without a header error.
2026-09-28 17:47:34 +00:00
Peter Steinberger
b95394a915
perf(state): stop re-reading the ownership lock on every shared-state read (#160139)
* perf(state): monitor ownership for explicit shared-state reads

Keep process/projection exclusion, schema leases, native-handle custody,
physical database identity, maintenance admission, and SQLite transaction
and commit grants. The hot cost was repeated observation of the same
process owner at independent read lifetime boundaries.

Monitor owner/projection sidecars every second and cache canonical owner
paths for one second, invalidating them on ownership and schema lifecycle
transitions. Only the dedicated shared-state read transport opts in.
Reads tolerate that bounded window after out-of-band lock replacement or
alias retargeting; writes and generic broker jobs keep fresh checks.
Foreign and maintenance ownership remain strict. No schema or dependency
changes; update behavior is unchanged.

One warm Control UI reload on synthetic state (46 RPCs), base f5866a5d0bcc
versus candidate: realpathSync.native 1478 -> 913 (-38.2%), openSync
536 -> 275 (-48.7%). Counter windows were 8.087s and 9.810s. The top-40
stack buckets show explicit-read sidecar opens 256 -> 0; candidate
monitoring adds 20 opens. This is syscall evidence, not a latency claim.

Validation: fake-timer ownership/projection theft, alias expiry, lifecycle
and failed-cleanup invalidation, and no warm read ownership syscalls.
The transport regression fails on the base with an owner-sidecar open.
Both core typecheck lanes, touched-file CI oxlint, line-cap ratchet,
diff checks, and independent P2 review pass. Runtime/UI builds pass
with declaration emission disabled; runtime postbuild/stamps are included.

The broader run initially timed out the unchanged synchronous snapshot
test after 162.790s against its 120s deadline under heavy host load.
Its same-file-order replay with the original concurrent lifecycle suite
passed in 5.002s without a fix, so the original cause remains unresolved.
The selected 57 files finish with 852 passing tests and two existing skips
across the successful runs. No timeout or assertion was weakened.

New ownership test cost: 8 cases, 7.879s summed test time and 80.49s shard
wall under host load. The two changed read/borrow files shared a 417.61s
unit shard; initial worker transformation dominated that cold run.
Benchmark and broad-suite evidence use the original f5866a5d0bcc base;
rebase integration preserves the unchanged ownership implementation.

Benchmark limitations: an initial cold-start warmup timeout was discarded.
Both base and candidate reproduce existing Teams/Zoom plugin shutdown
cleanup failures, but both isolated Gateways stopped and state was removed.
Both UI builds retain the existing 363.4/362.9 KiB startup-JS advisory.

* fix(scripts): add gateway state owner directory to the PR wrapper inventory
2026-09-28 12:27:53 +00:00
Peter Steinberger
bff74e5f0b
fix(pr): recover explicit admin base-change rejections
Allow explicit same-head recovery when the retained prior-CI admin REST
request received the exact GitHub 405 base-branch-modified response.
Preserve each original intent and response in the outcome ancestry, bind
recovery to the current outcome with compare-and-swap, and repeat all live
review, security, authority, CI-evidence and head checks before dispatch.
Unknown, mixed, truncated or other provider responses remain ineligible.

Qualify the sent-request path through the native wrapper, including repeated
rejections, final-await tampering, stale outcomes and revoked authority.
Validation: 448 distinct recovery/CLI/sibling cases pass across retained
runs; fresh independent reviews are clean. The initial positive CLI fixture
needed an explicit main target; its causal original-code failure is retained.
All root type shards, coercion and dead-export checks, and script/test lint pass.
The pinned baseline's unrelated UI shard budget is already repaired on main
by 52ae7e314d.
2026-09-28 04:46:34 -07:00
Peter Steinberger
4576501026
fix(ci): qualify missing proof uploads after cancellation
Upload Discord proof only after its producer finishes with success or failure. Preserve diagnostics for real proof failures and keep missing-file errors strict, while skipped or cancelled producers no longer cause a secondary upload failure.

The explicitly authorized pre-existing-CI admin path can qualify the audited historical skipped-producer upload case using exact workflow, action, output, step, timing, and retained-log evidence. Keep the causal root and all cancelled coverage unchanged; every other failed cancelled step, review requirement, and security veto remains blocking.

Validation: paired original-condition and native-refusal controls, 150 focused workflow/native/closure cases, retained historical cancellation data compatibility, required changed-file checks, and independent review.
2026-09-28 02:23:20 -07:00
Peter Steinberger
809b62cc7e
fix(pr): reuse pinned heads and accept verified main advances
Avoid repeating immutable PR-head fetch negotiation when the exact direct task ref already exists, while retaining live source identity checks and Git branch safety. Missing, moved, hidden, or unsupported local refs keep canonical acquisition.

Allow active prior-CI admin admission to tolerate forward main-only movement after ancestry and conflict-free, nonempty tree checks. Materialize before final live authority verification; the final reread never fetches. Exact PR facts, review and security vetoes, Crabbox admission, and retained-outcome reconciliation remain strict.

Regression controls exercise original redundant-fetch and main-drift failures, revoked authority during a late fetch, and unchanged-head forward-main acceptance.
2026-09-28 01:22:04 -07:00
Peter Steinberger
b107d4af14
fix: recover interrupted npm package updates (#158491)
Recover interrupted POSIX npm package publication with one durable journal and an external-Node helper. Keep database, configuration, and service recovery with their existing owners, and settle delegated children before releasing update authority.

Remove the unused state-generation engine, inverse migrations, private store transport, and their tests. The result reduces net PR growth by about 64%; production growth is 4,168 lines. Preserve the read-only legacy-journal route and its original-helper guidance.

Installed Crabbox proof at d1621807 covers the published 2026.9.6 updater, automatic same-schema rollback preserving acknowledged cron/transcript writes, and helper recovery after updater SIGKILL followed by an explicit Gateway restart. Final integration proof is recorded in the PR body with its exact source binding and limits.

Related: #142770. Full-state checkpoint replay and reverse database migrations remain separate; #144005 and #145169 remain open.

Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-28 00:09:13 -07:00
Peter Steinberger
cf14554105
fix(process): a finished command is reported as timed out when the event loop lags (#159578)
* fix(process): preserve exits across delayed deadlines

Let pending child notifications run before accepting process deadlines, and preserve exited commands whose drained output precedes broker result delivery. Keep inherited-pipe deadlines and existing cancellation, output limits, and process-tree cleanup.

Use one watchdog for native and brokered runExec calls. Remove supervisor timeout inference based on delayed result observation. This prevents successful Gateway subprocesses from becoming spurious timeout failures during event-loop stalls.

Validation: deterministic regressions fail before their fixes; 126 focused tests pass with one platform skip; related supervisor and idle-timeout tests pass. Core and all 25 selected test typecheck graphs, changed-file lint, and independent review pass. The full changed-check command was stopped under the host time limit during import-cycle scanning after its preceding gates passed.

* build(pr): add the shared process deadline to the PR wrapper inventory

* test(process): isolate deadline regression spawn fixtures

Mock the spawn boundary for deterministic deadline tests so their fake children do not load the unrelated spawn and worker runtime closure. Keep all nine behavior assertions; standalone wall time falls from 30.84 seconds to 3.15 seconds.

Validation: 208 process tests passed with one platform skip; PR wrapper inventory and both requested provisioning cases passed. Scoped services tsgo, changed-file lint, formatting, and independent review passed. This commit does not change runtime timeout behavior; the independent backstop finding remains unresolved.

* fix(process): separate broker execution deadlines from output drain

Give brokered command wrappers an execution-only deadline with one second of scheduling grace. The broker checks the native root state, retains configured kill escalation, clears the backstop on exit or earlier host cancellation, and reports accepted timeouts even after a cooperative zero exit. Native commands retain their local primary watchdog.

Preserve observed root exits while EOF or broker results are pending. Apply the existing 100ms idle and 1000ms hard output drain bounds to successful tree roots, and join owned descendants without rewriting the root exit status. Raw Execa timeout contracts remain unchanged.

Validation: 250 process tests passed with one platform skip, including live broker execution with frozen Gateway timers; wrapper inventory and both provisioning cases passed. Core and services test tsgo, changed-file lint and format, and independent review passed. Deterministic deadline regressions take 3.77s standalone. The live broker proof takes 40.06s wall with 2.47s test execution; its real process and IPC are required to prove an independently running deadline, while shared worker artifact setup accounts for most of the overhead.

* fix(process): preserve descendant deadlines with bounded EOF grace

Restore the successful owned-tree output contract from #140927: retain descendant output until the command deadline and preserve timeout classification for held pipes. Remove early output release and group termination after a successful root exit.

At the deadline, give an already-successful root one fixed 100ms EOF grace using the existing stdio grace constant. Both streams reaching EOF preserve the exit result; a held stream enters the existing timeout and cleanup path. Keep runExec and non-tree post-exit handling, the broker execution-only backstop, and broker timeout propagation.

Validation: 314 process tests passed with one platform skip, including all requested process ownership suites. The 12-case deadline regression file passed in 5.72s wall; wrapper inventory and both provisioning cases passed. Core and services test tsgo, changed-file lint/format, and full-branch P2 autoreview with the macOS private temporary directory passed.

* test(daemon): let systemd deadline decisions settle after expiry

Command deadlines now take their timeout decision one timer turn after the deadline fires. The systemd availability test advanced fake time by exactly the deadline, leaving that decision pending until the real child exited and CI's 10 s test timeout expired. Advance to the next timer after the deadline. Failed 5/5 before, passes 5/5 after; process deadline suites pass (76).

* test(process): settle deferred deadlines in consumer tests

Advance fake clocks through the queued deadline decision before asserting cancellation or awaiting construction and process settlement. Preserve MCP authority, exec liveness, and native process-group cleanup assertions.

Keep the production timer: setImmediate preserves native exit handling but still requires another fake-clock tick. No new real waits or child processes are introduced.
2026-09-28 00:03:31 -07:00
Kimi Yu
1fe560c198
fix: preview files in remotely hosted workspaces (#159895) 2026-09-27 22:47:43 -07:00
Peter Steinberger
1ca6a5d0a8
fix(pr): honor conditional code-owner review requirements 2026-09-27 22:39:21 -07:00