Commit graph

8694 commits

Author SHA1 Message Date
Peter Steinberger
94cbbecd46
test(ci,gateway,integration): remove low-value tests (batch d151) (#163532)
* test(ci): deslop s1016 tests

* test(gateway): deslop s842 tests

Port s842 commits 77c589897919272a876fe407c3b567a26ee4df11 and
9cccf18820d7eb027e39ed7f22f94a99a29d647f onto the campaign lane.
The abort fixture fixes are already present on the lane.

Consolidate yield setup while preserving HEAD's eight yield/resume cases,
transactional pause, requester retirement, acknowledgement recovery, and
unknown-write reconciliation assertions. Apply the shard's dispatch and
approval replay cleanup to files unchanged since its parent.

Validation: Testbox on origin/main baa26a6ad5
plus all five resolved shard files: 5 files, 25 tests passed, no skips,
82.86s Vitest duration. No timeouts raised. oxlint, oxfmt --check,
git diff --check, and independent review passed.

* test(tooling): deslop s1009 tests

* test(integration): deslop s1007 tests

* test(helpers): deslop s1010 tests

* test(plugins): deslop s1011 tests

* test(integration): deslop s1006 tests

* test(scripts): deslop s1022 tests

* test(scripts): deslop s1021 tests

* test(plugins): deslop s1012 tests
2026-10-02 13:03:08 +00:00
Peter Steinberger
889f54b266
test(state,shared,integration): remove low-value tests (batch d150) (#163514)
* test(state): deslop s978 tests

* test(shared): deslop s962 tests

* test(trajectory): deslop s998 tests

* test(state): deslop s983 tests

* test(status): deslop s986 tests

* test(transcripts): deslop s999 tests

* test(integration): deslop s1005 tests

* test(integration): deslop s1008 tests

* test(core): deslop s1003 tests

* test(scripts): deslop s1014 tests

* test(state): await mapped read failures

Handle synchronous throws and asynchronous rejections while retaining the exact mapped-error identity assertion. Fixes the type-aware no-floating-promises CI failure from the batch replay.
2026-10-02 13:00:00 +00:00
Peter Steinberger
cae2f937ce
test(release): fix volume session provider metadata (#163404)
Complete the volume-specific fixture contract after the generic per-agent cutover in #163360. Seed modelProvider and check that durable field after migration, preserving the existing session, transcript, archive, and model assertions.

Exercise the actual phase-produced stores through the canonical session reader in the existing baseline-order fixture. The unchanged volume writer fails the retired-provider guard while the base control passes; all four affected cells pass after the repair. Scoped lint, root types, syntax, Docker boundaries, line-cap checks, and independent P2 review pass.

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-10-02 04:49:31 -07:00
Peter Steinberger
375fb61402
fix: preserve large CUA responses under Bun (#163456)
* fix: preserve large CUA responses under Bun

Use runtime stdio streams for anchor output backpressure, then publish
socket EOF through Bun's built-in POSIX shutdown binding after flush.
This preserves process cleanup authority and works before the fork's
duplicated-descriptor fix as well as on the current fork.

Keep stdin and signal handling unchanged, and fund the output adapter
with behavior-preserving type and envelope simplification (net zero LOC).

The existing CUA consumer passes 13/13 on Node 24, old Bun b368, and the
current fork on AWS Linux; old Bun previously failed two large-output
cases. All three pass real retirement and stdin readiness tests. Both
output descriptors preserve 11 MiB and publish EOF while the owner stays
alive, including stock musl Bun and macOS. Scoped P2 review, changed-file
checks, and import-cycle checks pass.

* fix(build): recognize Bun FFI in sealed worker artifacts

The CUA output fix uses Bun's runtime-provided FFI module behind a Bun-only
guard. Admit that exact builtin in the worker closure check while retaining
the Node CLI eager-import policy and rejecting native npm dependencies.

The added fixture fails before this correction and passes afterward on
Node and Bun. A real qaRuntime build passes its artifact guard, and the
sealed anchor runs without project dependencies on Node, old Bun, and the
current fork with full output and EOF before process-owner retirement.

Scoped P2 review and changed-script checks pass. Production LOC stays flat.
2026-10-02 06:40:31 -05:00
RoboClaw
45fd3352ba
fix(release): recognize 2026.9.8 plugin scan policy (#163464)
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-10-02 04:35:24 -07:00
Vincent Koc
df93a28f0b
fix(pr): recover stale admin intents on replacement heads (#163429) 2026-10-02 11:16:15 +00:00
Dallin Romney
63b125d6f8
fix(release): require Windows Node validation to pass (#163373)
* fix(release): restore Windows Node validation gate

* test(release): cover Windows gate transition
2026-10-02 10:47:18 +00:00
Peter Steinberger
4ee88721f0
fix(test): follow short auth failure copy in worker-artifact TUI hooks 2026-10-02 03:31:16 -07:00
Peter Steinberger
9562d84d90
fix(release): qualify exact native persona fixture (#163327)
Bind the synthetic native persona fixture qualification to its packed SHA-256, package, source path, rule, and count while preserving frozen release policies. Keep every source file scanned and reject modified fixture bytes or identities.

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-10-02 05:29:15 -05:00
Peter Steinberger
83ecb29d4d
refactor: consolidate updater fixtures and unused test plumbing (#163359) 2026-10-02 10:11:58 +00:00
Dallin Romney
eb13b4fa6b
fix(release): recognize reviewed llama VC extraction (#163430)
* fix(release): review llama VC runtime extraction

* fix(release): freeze September security inventories
2026-10-02 03:08:26 -07:00
Dallin Romney
ca0159f1c2
fix(release): remove unused flake classification bypass (#163412)
* fix(release): remove FRV flake receipts

* docs(release): require successful FRV CI gate
2026-10-02 03:02:01 -07:00
Peter Steinberger
aa31aeefb7
fix(ci): parse npm 12 first-hop pack output (#163400)
The first-hop release lane exited silently before Docker when npm 12 returned
name-keyed pack JSON. Move filename extraction into the existing fixture
helper and use the canonical npm JSON normalizer. Keep the single-result and
nonempty filename checks, with a useful error for malformed output, and
leave recorded package integrity and identity admission unchanged.

Real pinned npm 12.1.0 packing a synthetic package reproduced the original
silent exit; the repaired helper resolves that output to the actual tarball.
The existing shell boundary regression now covers both array and keyed JSON
in its recorded source sweep and fails before the repair. Five negative CLI
cases retain malformed-output rejection. Full fixture suite: 34 passed,
43.00s wrapper wall; the new rejection cases total 0.80s.

Changed checks, Node/Bash syntax checks, and independent review passed.

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-10-02 02:42:37 -07:00
Peter Steinberger
f859694212
fix(plugins): preserve SDK host identity in deferred Bun imports (#163360)
Deferred Bun plugin SDK imports could fall through to a linked built host after their captured generation survived cache replacement. Reuse the existing scoped resolver under the retained cache so the generation keeps its selected SDK host and admission boundary.

Correct the serialization, cancellation and source-prescan fixtures without weakening their contracts. Update the published-upgrade survivor to the supported per-agent source layout and current model metadata, preserving migration and source-custody assertions.

Proof: 105 plugin/boundary cases and 202 upgrade-harness cases on each runtime; full build and changed checks; clean P2 review; exact-head CI; published 2026.9.7 updater through full state/plugin/Gateway survivor with all 11,350 immutable entries matching the candidate. The unchanged Bun CallSite column runtime gap remains documented.
2026-10-02 04:29:15 -05:00
Peter Steinberger
5ec7d7f3b0
fix(ci): provision ripgrep for SQLite ratchet tests (#163311)
The SQLite worker ratchet inventories working-tree source with rg. Include its fixture in the existing prerequisite mapping so clean runners install ripgrep before testing an unchanged baseline. Cover exact targets, exact and glob includes, and grouped tooling selection in the existing manifest regression.

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-10-02 04:18:04 -05:00
Peter Steinberger
0d530ea5b0
refactor(plugin-sdk)!: retire unused command-auth, discord, and telegram-account facades (#163366)
Retire the public plugin-sdk/command-auth, plugin-sdk/discord, and plugin-sdk/telegram-account subpaths early, with the Plugin SDK owner's approval (2026-10-02). No bundled runtime imports them. No official external plugin at latest or extended-stable imports them either, and the only older @openclaw/discord releases that did (2026.3.7-3.13, 2026.5.2) already import subpaths main removed earlier.

Remove the modules, package exports, entrypoint inventory, compat registrations, and obsolete tests. Move the three surviving contract tests to their focused SDK subpaths. Drop 15 internal exports orphaned by the retirement and the dead isCommandMessage and resolveDualTextControlCommandGate wrappers. Shrink the SDK surface budgets by exactly 3 entrypoints, 128 exports, 79 callable exports, and 128 deprecated exports.

Breaking change for third-party plugins that import these paths: use channel-ingress-runtime, command-auth-native, command-status, or models-provider-runtime, as described in docs/plugins/sdk-migration/import-paths.md and the removal timeline.

Landed over inherited main reds only (Codex model/list sequence tests from #163320, the memory-host-sdk boundary test fixed by 2516be90f1).
2026-10-02 02:09:07 -07:00
Peter Steinberger
2ab22d8772
fix(test): remaining suites time out on their first test or hook while compiled worker subprocesses prepare (#163254)
* test(core): split oversized subprocess consumer suites

Separate CLI lifecycle, Gateway startup, command dispatch, and bare-root
flows; media reads and storage; catalog metadata and hosted persistence.
Prepare workers during collection only for the six observed consumers.
Keep all 221 cases, assertions, and fixture initialization order; the
exit-only and catalog metadata files remain declaration-free.

Prune the two split baselines and one already-stale baseline entry.

Validation: 221 passing cases; six collection loads and two none results.
Changed-file formatting/lint, affected tsgo graphs, both line-cap ratchets,
and diff checks pass. The global changed-path typecheck remains blocked
by the inherited agents-other root budget (724/720); affected graphs pass.
The review's baseline concern was rejected against the native stale-entry
check and direct lint of the unchanged target file.

* fix(test): collect extension subprocess dependencies

Move Anthropic's real process helper acquisition to collection while
retaining vi.importActual and its mock reset behavior. Move DeepInfra
and xAI's one-time subject imports and mock setup to collection, keeping
their real HTTP transport and negative SSRF assertions intact.

Validation: all 20 cases pass and first declaration loads are collection;
all case names/counts are unchanged. Formatting and extension test types
pass. The normal extension lint lane was blocked while preparing Plugin
SDK declarations by its existing 300000 ms timeout; no timeout or guard
was changed. The final candidate received the scoped P2 review recorded
with the preceding core split commit.

* test(plugin-sdk): preload compiled subprocesses for extension tests

Move worker preparation into collection through a repo-local, non-production
SDK subpath. Let Codex app-server setup preload declarations while keeping
worker-cpu imports after file mocks; preserve per-test imports and assertions.

Register private source and declaration aliases without adding package exports
or production artifacts. Remove unused CLI fixture exports and reuse the alias
normalization owner so the existing dead-export and line-cap gates pass.

* fix(test): preload compiled subprocesses for newly screened suites

* fix(test): preload remaining screened subprocess declarations

Move compiled subprocess preparation out of test and hook deadlines in six confirmed declaration consumers. Preserve lazy imports, mock ordering, and assertions; keep the shared meeting plugin helper unchanged so platform-scoped loading retains its existing order.

* style(test): keep Parallel suite separator

* fix(ci): keep protected selection for split CLI and catalog suites

The owner splits moved protected run-main and official-catalog cases into
four new suites. Add them to PR_PROTECTED_RUNTIME_TEST_FILES so global inputs
such as pnpm-lock.yaml still select them, and assert that in the existing
global-input planner test.
2026-10-02 03:37:13 -05:00
Peter Steinberger
d1ba4d9bdb
fix(ci): repair Telegram launcher lifetime handoff (#163316)
Forward the Gateway stdin lifeline after the parent-PID contract migration. Keep process isolation tied to the live privileged launcher and remove its private identity before candidate startup. Disable Bash startup files for socket-backed QA stdin.

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-10-02 03:33:30 -05:00
Vincent Koc
0a188c4f03
test(build): include required normalization exports in declaration fixtures 2026-10-02 08:31:47 +00:00
Peter Steinberger
3ee9fb5c21
fix(test): tsgo changed-test typecheck test times out on loaded hosts (#163057)
The compiler interceptor adds a Node boot with the inherited NODE_OPTIONS
preload and spawns a second process for every compiler query, consuming the
transitive-consumer test budget on loaded hosts.

Use a /bin/sh interceptor to record arguments and exec the native compiler.
Each query stays one native process, matching the production resolver.
Keep the fixture-local TypeScript install and all assertions unchanged.
2026-10-02 03:24:23 -05:00
Peter Steinberger
430eeb8296
fix(test): process-wait helpers race their own wall-clock deadlines; bind them to the test's abort signal (#163321)
test/helpers/process-wait.ts still owned wall-clock deadlines: waitForFile, waitForPidFile, waitForDead, and waitForChildClose each raced the awaited condition against their own timeoutMs, so every caller inherited a hidden race that healthy work could lose on a loaded host. This is the final step of the polling audit from #162274; earlier batches converted the call sites that had an owned signal.

The helpers now take the AbortSignal that bounds them. waitForFile, waitForPidFile, and waitForDead share one private observation loop (the existing 5 ms re-check, one final observation before rejecting on abort, path/PID diagnostics with signal.reason as the cause, timer/listener cleanup on settle; fake-clock callers keep an injectable real delay). waitForChildClose resolves from the child's own close event and rejects only on abort, and documents registering at spawn because exitCode/signalCode cannot recover a missed close. All 35 calls in 17 files moved: test bodies pass the Vitest test signal; cleanup paths that may run after the test signal has aborted use an explicit named AbortSignal.timeout(<old value>) cleanup guard at the call site, keeping each old bound exactly; five readiness waits that cannot reach a test signal keep a named guard as a recorded escape hatch. process-wait.test.ts replaces its deadline-specific cases with signal and real-child contracts. No product source, Vitest timeout, TERM-to-KILL timing, or caller assertion changed.

Proof: process-wait.test.ts 20/20 locally; on Blacksmith Testbox 20/20 standalone runs for six changed files and the Gateway E2E agent-exec plugin test, 10/10 for the other six (Testbox saturation blocked the second ten), the Windows-native file collect-only on Linux and green in CI's Windows shards, five owning-shard replays (failures only in main reds since fixed by #163310); tsgo:test:root, tsgo:core:test, tsgo core boundary, CI lint wrapper, deadcode, base-aware timeout-race ratchet; Codex autoreview and ClawSweeper clean.
2026-10-02 00:48:49 -07:00
Peter Steinberger
6d4f04cdf6
fix: keep test runtime facts consistent across Node and Bun (#163260)
Correct Node-only assumptions in Doctor, update, storage, and process fixtures while preserving their behavior checks.

Use shared Node executable/version facts for service and runner fixtures, preserve the real host identity for schema/state workers, and make diagnostic, filesystem, preload, parsing, and crash fixtures explicit about the runtime facts they exercise.

Validation covers every repaired owner and affected sibling on Node 24 and verified Bun b368, plus Linux directory and zombie cases. Exact-head CI and P2 review passed. Four unchanged files have source-backed Bun runtime stop reports; local timeout evidence remains recorded alongside separate Darwin controls.
2026-10-02 02:43:05 -05:00
Peter Steinberger
5a33528c7b
chore(ci): restore other and infra core type graph headroom (#163102)
The other (710) and infra (706) core tsgo test graphs were within 14 roots
of the 720-root budget that fails local boundary checks and check-changed.

Move the node-side remote-execution tests (src/node-host/, src/worker/,
116 roots) into gateway-other, which already owns
src/gateway/worker-environments/, and the root-level
src/infra/state-migrations* tests (79 roots) into state-logging, which
already owns src/state/ and src/infra/sqlite-*. Result: other 594,
infra 627, gateway-other 465, state-logging 555.

Pin the new ownership, drop a duplicated system-agent include from the
services graph, and refresh the runners.md ownership paragraph (cron
lives in services-cron, heartbeat in infra, and the root cap is
advisory in GitHub Actions).
2026-10-02 02:39:12 -05:00
Vincent Koc
295a324d1a
fix: use file payloads for native GitHub operations (#163279)
* fix: use file payloads for native GitHub operations

* fix: preserve native GitHub failure capture bytes

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-10-02 14:38:15 +07:00
Chris Eckert
40d284f9a6
fix(agents): release model and auth readers when deleting agents (#159013)
* fix: release deleted agents' model and auth resources

* fix: await only existing deleted-agent builds

* fix: close deleted agents' native memory managers

* fix(agents): close deleted database readers across worker isolates

* fix(agents): revive deleted stores by their captured owner

* refactor(state): remove superseded reader-close entry points

* fix(agents): preserve commit outcomes and close readers before trash

* fix(tooling): include agent readers in native wrapper inventory

* fix(agents): adapt deleted-reader cleanup to native worker owners

* fix(agents): preserve deletion fences across worker generations

* fix(agents): release deletion guards and repair CI proof

Release worker heartbeat references when a deletion lease closes. Keep the
journal authority SELECT in its worker-only module and route the catalog
reader fixture through the existing database-worker lane.

Close the survivor fixture's seed writer before recovery, establish archive
LRU order, and restore the shared logger mock's trace contract. Add effect
boundary coverage for revoked deletion authority and move bounded transport,
channel logging, and fixture code to their existing modules.

Preserves the agent deletion and recreation repair for #159007.

Co-authored-by: Chris Eckert <christopher.k.eckert@gmail.com>

* test(ci): retain native command and auth retirement diagnostics

Wait for a native command receipt before checking its result so a terminal
failure exposes its reason immediately. Include isolated Gateway logs in the
removed-profile assertion, with a debug-only publication retirement summary
that identifies cache, owner, pending-build, and Gateway-loan state.

This diagnoses UI and auth failures from CI run 36965599681 without relaxing
assertions, extending timeouts, or changing retirement/recovery authority.

Co-authored-by: Chris Eckert <christopher.k.eckert@gmail.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Chris Eckert <christopher.k.eckert@gmail.com>
2026-10-02 02:30:07 -05:00
Peter Steinberger
f8821e0209
fix(lint): remove redundant artifact-loader suppression
Load the Doctor artifact through the existing typed public-surface loader.
Restore the optional channel adapter's object contract for its remaining
callers instead of retaining a second return-only generic exception.
Preserve the missing-artifact and initialization-error behavior from #162645.

Explicitly allowlist the worker fixture's Node BroadcastChannel exception:
its postMessage API has no browser targetOrigin argument. Keep the fixture
and the suppression scanner unchanged.

Fixes the production suppression guard from hourly run 36969503477.
Validation: suppression guard plus 21 channel tests, touched-file and
boundary lint, check-changed, full architecture checks, build, and P2 review.
Checks ran locally after the Testbox request was canceled while queued;
full owning Vitest suites were not run. Compatibility records are untouched.
2026-10-02 00:15:44 -07:00
Peter Steinberger
2d4422fe70
ci(apple): avoid unrelated Mermaid cache misses
An MCP SDK-only update invalidated Apple Mermaid assets because the key
hashed the entire root manifest and lockfile. Fingerprint the renderer's
workspace and resolved dependency closure, retaining optional/peer
metadata, package integrity, sources, patches and build configuration.
Keep key calculation install-free and preserve output verification and
cold rebuilds.

The exact main/PR input pair now shares a key. Frozen Vite 8.3.1 proof:
0.919s cold to 0.082s verified reuse, with identical bundle bytes.
Final cache and macOS fixture tests, root type lanes, boundary lint,
check-changed, architecture and P2 review passed. The cache file measured
8.15s pnpm wall; final native macOS wrapper proof passed all 168 cases.

Whole tooling: 25,950 passed, 501 existing skips, 26 inherited failures in
untouched updater and suppression-inventory fixtures. Two updater cases
reproduced in isolation; both additional suppression entries are already
present at the source base. No assertion, skip, or baseline was weakened.
2026-10-02 00:12:32 -07:00
Peter Steinberger
c4a1d35536
fix(ci): freeze lockfiles before pnpm bootstrap (#162862)
## What Problem This Solves

Older selected-source installers can invoke pnpm before their install-only frozen-lockfile flag takes effect, allowing package-manager bootstrap to rewrite the selected source lockfile.

## User Impact

The source receiver supplies frozen policy before starting the selected installer. Source verification, dependency pins, and false-input behavior stay unchanged. No schema or runtime storage change.

## Why This Change Was Made

Current main already fixes its shared installer with early native policy and an explicit install flag. This PR preserves that implementation and adds only the receiver process-boundary setting, plus distinct regression coverage. The explicit flag remains necessary for older pnpm workspace-configuration precedence. The final production/tooling delta is one added line.

## Evidence

Actual pnpm 12.5.1 originally reproduced the lockfile mutation. The repaired Linux receiver preserved the selected source through the unchanged post-install verifier; its later SQLite diagnostic failure remains separate and is not claimed fixed.

On the corrected composition, all 14 hydration cases passed in 38.273 seconds. Actual pnpm 10.23.0 conflicting-workspace and false/invalid-input cells preserved the expected lockfile behavior. Prior receiver boundary proof remains applicable to unchanged source. Independent full-diff P2 review is clean.

The earlier broad gate attempt and historical diagnostic failures remain recorded. The maintainer explicitly waived further test execution and approved landing this reviewed correction; no current-head full-suite or hosted-CI success is claimed. Independent code review, security review, and exact-head merge admission remain required.
2026-10-01 23:48:58 -07:00
Shakker
652dab4549
fix: avoid import-cycle cleanup failures (#163312)
Wait for the import-cycle checker's native compiler to close before reporting completion.
2026-10-02 07:40:19 +01:00
Dallin Romney
90563ee83b
ci: allow disabling PR fail-fast with a label (#163246)
* ci: allow PR label to disable fail-fast

* ci: align fail-fast label with final gate
2026-10-01 23:27:49 -07:00
Peter Steinberger
9c9b424251
fix(ci): prepare runtime for changed E2E execution routes (#163289)
Derive the prerequisite from the file route executed by target children instead of its remapped canonical selection owner. Reuse the existing private-QA runtime-only preparation and successful-build prebuilt gate; keep all selected files and assertions.

Proof: three real-route regressions fail before and pass after; 61 planner tests pass; four shallow preflight manifest shapes pass; single E2E file passes all 9 tests after runtime prep; check-changed and boundary lint pass; independent P2 review is clean. No workflow, job, dependency, export, or repository-variable changes.
2026-10-01 22:51:03 -07:00
Peter Steinberger
db20d75239
ci: pin the OpenClaw Bun fork b368 prerelease (#163251)
Pin the verified b368 Bun fork for Linux CI and admit three files whose CommonJS exports, post-script argv, and native pipe-output gaps are fixed. Keep mixed, broad, and V8-specific selections on Node; preserve complete oxlint diagnostic capture with a bounded fixture buffer.

Proof: no regressions in the eleven-selection fc90/b368 Linux comparison; final fast lane passed 16,608 cases on each pin; all 103 newly admitted cases passed through CI groups. Both Node-hidden smokes passed 10/10 with zero Node attempts. Final focused Node/Bun checks, local changed-file checks, and P2 reviews passed. WebKit remains unchanged at fb1167ebf2.
2026-10-01 23:53:23 -05:00
Peter Steinberger
7968463a06
fix: preserve shared auth and build receipts across runtimes (#163243)
Preserve read-through OAuth inheritance and declaration receipt reuse when filesystem enumeration order differs. Prioritize the discovered shared auth owner and canonicalize compiler membership, keeping the existing primary write and target set.

Make cleanup fixtures explicitly own separate connections, pending response bodies, child admission, and pre-removal holds. Keep all concurrency, resource-drain, and native database-exclusion assertions.

Validation: 136 focused tests pass on Node 24.21.0 and checksum-verified fork Bun b368; changed-file checks, Madge, and P2 Codex review pass. Production delta: +3 lines.
2026-10-01 23:42:15 -05:00
Peter Steinberger
5e81e62b87
perf(build): avoid duplicate isolated asset generation (#162997)
* perf(build): generate isolated plugin assets once

* fix(build): bound isolated plugin asset execution

* test(ui): inherit model picker readiness fix

Apply the existing fixture correction from dd2a7baba6 (#162869). The picker can be visible while its controls still await catalog hydration; assert readiness before interacting.

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-10-01 23:29:41 -05:00
Vincent Koc
2e705107ff
fix(crabbox): start remote checks from code-only worktrees (#163035)
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-10-02 12:07:18 +08:00
Dallin Romney
0fa2dddedb
ci(release): pin reachable live provider models (#163177) 2026-10-01 21:05:33 -07:00
Peter Steinberger
29cb3d82c0
fix(ci): complete Apple cache traversal and fixture checks
Traverse fingerprint inputs by file type and use immutable sorting. Give the macOS wrapper fixture the source and configuration files read by the real preparer, retaining every pnpm/corepack ordering and resource replacement assertion.

The cache boundary cases and all 168 macOS wrapper cases pass on Linux. Normal lint, boundary lint, root tooling types, and the changed-file gate are verified; the correction has a clean P2 review.
2026-10-01 21:02:28 -07:00
Peter Steinberger
fb338924f5
ci(ios): cache verified Apple smoke build inputs
Reuse content-verified Mermaid assets and Watch RTC static slices, and cache SwiftPM sources and binary artifacts without disabling package resolution. Fresh rust-src timestamps invalidate Cargo target caches, so fingerprint the finished Watch slice instead.

PRs restore only; trusted main push and schedule runs publish exact input keys. Frozen targets retain their cold path. Keep every scheme, target, Swift lint phase, build-for-testing action, and simulator selection.

Local Xcode 27 smoke: 185.9s cold to 89.4s warm with fresh Swift build products and isolated package support caches; all 17 Swift compilation targets retained. P2 review is clean.
2026-10-01 21:02:28 -07:00
Peter Steinberger
1edb1f76d2 test: assert advisory deadlines on the owned request
Main CI 36956896474 observed an unrelated 25ms timer after the advisory
request deadline. Assert the stalled request's abort signal and exact
reason while retaining cancellation, findings, and partial coverage.

A controlled canceled-timer injection reproduced both former assertions;
the corrected assertions passed. Final 146 focused/sibling tests and all
selected checks passed. The original 52-file replay was interrupted after
523.4s with this file passing; it is not full-shard passing evidence.
Independent P2 review is clean. Per-file: 76 tests, 150ms test time,
8.946s command wall.
2026-10-01 21:00:10 -07:00
Peter Steinberger
9833b0f563
test(discord): update bundled asset build hook expectation
The Discord return-link feature in #158742 expanded the build hook to
produce both the Embedded App SDK and Control UI bundle through the
repository tsx wrapper. Keep the exact command expectation in sync while
preserving the package, phase, plugin identity, and single-hook assertions.

Fixes the bundled-plugin-assets assertion in hourly run 36956896474.
Validation: five focused runs (65 passing tests, 6.21-6.77s per run),
check-changed, boundary lint, and independent P2 review. Used the requested
local fallback; the full tooling suite was not run because Testbox was
unavailable.
2026-10-01 20:33:54 -07:00
Peter Steinberger
7fc0cfb379
ci: batch compiler planning and start guards after preflight (#163196)
Read complete compiler memberships from one native snapshot while retaining
canonical graph ownership checks and conservative full selection. Keep the
serial CLI boundary owner and provide OPENCLAW_CI_TYPE_PLAN_SERIAL=true (or 1)
as an operator fallback; unset uses snapshot discovery. No repository setting
is created.

Move existing narrow-PR guards into the preflight-ready additional matrix,
reusing their commands, setup, runner and comparison base. Preserve full and
frozen layouts, coercion deduplication and the versioned observer count.

Four fresh Linux PR-input replays preserved every output field. Compiler
planning fell from 77-91s to 17-21s; complete materialization fell from 85-101s
to 25-32s. The materializer peaked at 14.8 GiB RSS, so the existing eligible
hybrid planner uses the 16-class. Hosted and trust fallbacks stay unchanged;
no jobs or permissions are added.
2026-10-02 03:09:15 +00:00
Dallin Romney
9ce1498432
ci(release): install Chromium for A-K live tests (#163178) 2026-10-01 19:54:21 -07:00
Vincent Koc
d6411f28a1
fix(ci): keep admitted Testboxes alive and enforce current workflow limits (#163021) 2026-10-02 09:51:59 +07:00
Vincent Koc
30aec15c05
fix(ci): run full type checks when selectors are absent (#163123)
* fix(ci): run full type checks when selectors are absent

* Merge branch 'main' into fix/ci-type-selector-fallback

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-10-02 02:45:56 +00:00
Peter Steinberger
2ff7b76c8b
ci(android): overlap fork PR rows on Blacksmith
Canonical fork PR first attempts already use Blacksmith, but the Android
matrix cap still required a same-repository head. Admit all four normal rows
together instead of imposing a second 9.6-10.6 minute queue wave.

Keep two-way overlap for the GitHub backend override, retries, manual and
scheduled runs, and noncanonical repositories. Preserve runner routing,
row counts, registration allowances, cache trust, coverage, and deadlines.
Update the capacity docs and evaluate runner labels alongside concurrency
for fork backend/attempt combinations.
2026-10-01 19:39:57 -07:00
Patrick Erichsen
a49a3321fa
feat: return to Discord and Slack from session headers (#158742)
* prototype(discord): add session header return link

* fix(discord): open session return link without hover UI

* fix(sessions): retain store aliases during creation

* fix(ui): separate session plugin content from conversation

* feat(channels): share session conversation return links

* fix(build): preserve plugin browser assets during staging

* fix(ui): let channel plugins own session return links

* fix: keep channel return links off reply path

* fix: respect native cursor behavior on session link

* test: cover legacy session entry without conversation link

* fix: reconcile session return link CI contracts

* test: route persistent embedded attempts through database owner
2026-10-01 18:52:16 -07:00
Jason O'Neal
e0d16ecdd5
fix(models): purge plugin catalog credentials on logout (#143647)
* fix(models): purge plugin catalog credentials on logout

* fix(models): resolve catalog logout CI failures

* fix(models): queue catalog fingerprint reads with writes

* fix(auth): retire exact credentials without suppressing survivors

* fix(auth): compare removal snapshots with physical owners

* fix(models): keep committed catalog inventory readable during writes

* test: rebalance agent approval typecheck roots

* test: correct catalog redaction assertions and formatting

* fix: scrub retained and malformed catalogs through agent worker

* fix: reject stale catalog credentials and compensate failed logout

* fix: bind catalog execution guard and register worker protocol

* test: await catalog worker custody before deleting auth fixtures

* fix: preserve catalog cleanup cause and capture explicit owner fields

* fix(models): align catalog worker fixtures with host admission

Return the explicit void result from credential cleanup, consume the canonical
observation type in production, and extract catalog worker orchestration without
changing admission or settlement. Route real database consumers through their
existing forked owners and preserve Doctor's rejection test with TEMP fixtures.

Retain a surviving canonical account in held-refresh publication regressions.
GitHub CI is the contributor execution route; prior failures were diagnosed
before this correction. Independent corrective review is clean through P2.

Co-authored-by: Jason O'Neal <jason.allen.oneal@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>

* test(models): drain shared catalog fixture owners before cleanup

Close pooled auth readers and await shared-state owner retirement after agent
worker cleanup, before removing the fixture roots. This prevents deleted file
identities from colliding with retained shared actors in subsequent cases.

Exact-head CI exposed the collision in native, metadata, and catalog integration
suites sharing this fixture. Keep real broker guards and assertions unchanged.

Co-authored-by: Jason O'Neal <jason.allen.oneal@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>

---------

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Jason O'Neal <jason.allen.oneal@gmail.com>
2026-10-01 20:20:28 -05:00
Patrick Erichsen
ec1fb60ba6
fix(plugins): queue compatibility removals pending reader migration (#163127) 2026-10-01 18:13:25 -07:00
Peter Steinberger
4c7d05d917
fix(runtime): make Bun diagnostics and Node worker builds portable (#162537)
Recognize Bun watch/hot commands and Node heap-limit operands during Gateway inspection, apply ACP bridge filtering to Bun and the current runtime executable, and omit stack fields from bounded worker inference diagnostics. Preserve conservative artifact-custody checks and existing redaction/classification.

The relocated worker archive regression now executes on Node even when Bun hosts its build/test. The bundling implementation landed independently in #163052. Production code is net zero lines.

Validation: eight focused files (248 tests) pass on Node 24 and checksum-verified fork Bun 17c9; madge and P2 Codex autoreview pass. Final published-driver, custody, local-check attribution, and exact-head CI results are recorded in the PR body. The independent published-2026.9.7/system-Node limitation is documented by #163017.
2026-10-01 17:58:44 -07:00
Dallin Romney
fc6809fda3
fix(release): clarify extended-stable version context (#163076) 2026-10-01 17:46:06 -07:00