* fix(test): checkout fixture budgets cut healthy runs on loaded hosts
On a loaded macOS host (load 55-83), ci-platform-checkout.test.ts and the
other checkout fixture consumers failed through three fixture-internal
wall-clock budgets, not through the workflow under test:
- the supervisor's mock-resolution preflight ran bash under its own 2 s
timeout ("mock command resolution failed: spawnSync bash ETIMEDOUT");
- the POSIX process census shadowed its caller's operation deadline with a
fresh 1 s budget for all singleton ps queries ("Fixture process census
failed (ETIMEDOUT)"); the owner-ancestry walk had the same 1 s shape;
- the supervisor cut every run at 45 s ("fixture deadline exceeded"), nested
under the helper's 50 s close race only because the helper could not see
the Vitest test timeout.
Measured breakdown: a multi-attempt scenario serially starts 25-36 Node
actors plus the Python owner; at load ~72 Linux git-failure spent 19.4 s,
of which the fixture's own 82 ps calls were 1.6 s. The work scales with
scheduler latency and is the contract under test, so the fix is ownership
of the time bound, not less work.
The owning test's AbortSignal now bounds a supervised run.
withCiCheckoutFixture takes it, rejects its close join on abort, and asks
the live supervisor to cancel over IPC so its own stop() retires the
detached shell group and actors, keeping the SIGKILL fallback for a wedged
supervisor. The supervisor drops its 45 s watchdog; its operation deadline
becomes the existing 60 s actor lifetime ceiling, which only bounds orphans.
Census, preflight, and ancestry queries borrow that operation deadline, as
the Windows census witness already did.
Every runCiGitStep and withCiCheckoutFixture caller passes its test signal;
.each registrations that need the context move to .for, which is the only
form Vitest 5 hands the context to.
Regressions: the shared slow-witness preload now gives POSIX supervisors a
first native query that spends 1.1 s on their clock (fails main's fixture
7/7 with "census failed (unverified)"), and the outer-runner retention
proof gains a cancel fault proving the aborted supervisor retires its shell.
* fix(test): keep checkout signal bindings lint-clean
* chore(release): retire the Tideclaw alpha release track
Tideclaw alpha/nightly publication is retired. Alpha remains readable as
history (existing v*-alpha tags, published versions, changelog and
upgrade-survivor baselines, product version ordering), but it can no longer
authorize a release.
Every active release boundary now rejects an alpha version or -alpha.N tag,
the alpha npm dist-tag, and tideclaw/alpha/* workflow or tooling routes:
preparation, Full Release Validation publication selection, npm preflight,
approval receipts, core/plugin npm and ClawHub publication, native handoffs,
and finalization. Channel mappings throw for alpha instead of falling through
to latest. The Tideclaw branch routes, alpha dist-tag options, the alpha FRV
publication route, and the alpha-only Docker runtime-assets job are removed.
Beta, stable, extended-stable, and correction releases are unchanged.
The release-openclaw-nightly skill is deleted and the release skills and docs
no longer describe the alpha track.
* test(release): drop retired alpha preparation and finalization expectations
* test(release): drop remaining retired alpha references
* feat(release): publish npm children in npm-publish behind the single parent approval
The parent's npm-release approval already mints an attested receipt. The npm
children now publish in the npm-publish environment (release-publish/* tags
only, no reviewers) where the npm trusted publishers are rebound, and skip
their own human gate when the receipt verifies. Direct, manual, and recovery
dispatch keeps a separate npm-release approval job. On the receipt route the
publish job waits for the parent attempt's authorization through the shared
awaiter that ClawHub uses, which also requires the parent to still be live.
Real publishes and OIDC preflight fail fast unless dispatched from a protected
release-publish tag. Extended-stable core receipts now verify from trusted
tooling. The parent no longer approves or prints npm child gates, and
release:stable detects npm-publish tooling before printing child approval
commands.
* fix(release): require a live parent before receipt-route npm publication
On the receipt route no human approves the npm child, so every final plugin
publish step (artifact check, OIDC publish, token-bootstrap publish) now
re-verifies the release parent with the live-only policy immediately before
npm I/O; a parent that completed with any conclusion refuses. The
human-approved route keeps active-or-failure, and core's publish step was
already live-only. Document tag-based manual recovery.
* test(release): expect waiting npm child cleanup without gate rejection
* test(release): align plugin npm ref admission fixtures with protected-tag publication
* feat(release): prepare npm and ClawHub for one-button publication
Stage complete plugin inventories in non-publishing owner workflows and
publish the original tarballs through the existing protected npm and
ClawHub publishers from one readiness receipt.
Bind source, tooling, producer attempts, and artifact digests. Require
established ClawHub publishers before readiness, verify every prepared
package before writers, and activate GitHub visibility only after exact
parent and canonical registry readback checks.
Share bounded artifact download recovery and verified archive reuse.
Retain partial dispatch requests, support explicit preparation adoption
and the existing successful-core resume path, and never blindly repeat
an uncertain registry mutation. Document native/platform boundaries and
the existing failed-core-child reconciliation limit.
Refs #136392
* fix(release): preserve prepared npm qualification
* fix(ci): retain postpublish diagnostics when verification fails (#142938)
* fix(ci): retain postpublish diagnostics when verification fails
* fix(ci): invoke publication diagnostics through guarded entrypoint
* fix(release): preserve prepared npm qualification
(cherry picked from commit a9eb4c8371069a1d14466d22d934a0cf8ad6b4f6)
* fix(ci): block cancelled plugin npm publication
* fix(release): scope artifact deadlines per phase
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
* ci: own plugin publication Git lifecycle
* fix(testing): run offline batches with installed Vitest
Remove the redundant pnpm bootstrap and keep orchestration alive until child cleanup and cancellation report completion. Preserve native signal termination across Vite's signal-exit hook.
* test(ci): clarify plugin ref fallback ownership
Document the preserved ordinary probe fallback separately from trust admission. Exercise terminal cleanup and cancellation inside that probe and forbid repeated matching operations.
* fix(testing): honor canonical Node flags in batches
Use the existing Vitest Node-argument resolver with the supplied batch environment. Exercise default and explicit Maglev opt-in behavior through the real installed CLI with no package-manager PATH.
* test: retire gateway admission between files
Fence suspended admission waiters before existing asynchronous cleanup, then retire prior roots and reopen admission before module invalidation. Prove the boundary with ordered native producer/observer fixtures without changing Gateway runtime or shutdown assertions.