The published-driver update cell ran serially after build-artifacts on every PR it was selected for, adding about 13.5 minutes of critical path. PR selection is now limited to the updater, activation, managed-service handoff, and canary-emitter owners (scheduled main and release validation still run the cell unconditionally); published-install caches have main-only writers with explicit cache-mode gating and read-only PR consumers; PR runs skip initial Doctor seeding and use shorter readiness waits. PR-mode cell measured at 3m32s with a cold image-builder cache. The cleanup tests no longer touch host Docker.
* fix: prevent delegated work from stopping silently
* fix: preserve frozen bootstrap metadata and refresh task prompts
* test: retain a foreign manager in frozen hydration proof
* test: exercise Corepack bootstrap warnings during hydration
* test: align completion fixtures with required private replies
Verify meaningful private outcomes, retained completion authority after inline waits, and one real write with no recovery replay. Start the browser fixture completion deadline when its held model is released.
* fix(node): recheck upload cancellation after opening snapshots
* test: group subagent typechecks with session ownership
Reuse the extension-lint comparison-base action for PR boundary checks. Keep its bounded exact-SHA fetch and existing fallback policy, and leave checkout refs unchanged.
A depth-one merge stays an ancestry boundary even after its parent is fetched. Validate the pinned raw first parent, then compare the two trees; retain ordinary ancestry validation for other shapes. Shallow checkout regressions cover package, core and deleted public SDK changes, including blobless base inventory hydration.
The published-driver cell timed out on scheduled main runs: the Docker fixture forced tens of thousands of OverlayFS copies on the candidate tree during the managed update. The cell now stages the update on a fresh private native volume per invocation (cleaned up on exit), which brings retention from 39 s to 12 s and the whole cell to about four minutes; checksum failures print both digests and reject before the update starts. The earlier "digest-mismatch: error" log line was an action setting echo, not a mismatch.
Package recovery treated checked Bun executables as Node and dropped configured macOS SQLite selection. Carry admitted runtime facts and the shared environment choice into durable standalone recovery, preserving version-1 journals, backup custody, and separately owned service restart.
Verified focused suites on Node and Bun, real macOS custom-library recovery from a clean shell, published-driver updates and Node-free interrupted recovery on AWS, static/import checks, and independent review. CI fixture and cell-lifetime repairs retain the existing assertions and product timeout policies.
The published-driver update cell rebuilt the candidate inside its own job and overran its ten-minute bound on the 12:46Z main hourly, cancelling the whole run. The cell now consumes the checksummed candidate from the same run's build-artifacts job (explicit digest comparison, portable across GNU and BSD tools), runs the managed update in about five minutes, and reports a command timeout as a job failure naming the active phase instead of cancelling the workflow. Scheduled-main coverage and omission on unrelated PRs are verified by the plan tests.
PR boundary selection: check only extension packages the PR's own diff can affect. When core/SDK declaration inputs change, select directly touched extension packages, a fixed smoke set of at most three broad SDK consumers, and packages that import a changed public plugin-sdk entry directly; skip transitive declaration fan-out. Hourly/schedule and release keep the full boundary check and the negative canary. Kill switch: repository variable OPENCLAW_CI_BOUNDARY_SELECTION=full restores full PR selection (unset means aggressive).
Backtest: all 10 historical PR boundary failures remain selected. 20-PR replay: modeled boundary median 7:22 -> 2:55 (conservative 4:49).
Merged past one inherited red: published-driver-update / Published driver update was cancelled at its 10-minute job timeout. It is cancelled the same way on main in hourlies 36863974207 and 36869865743, and its owner is fixing it (reuse build artifacts; timeout becomes a failure with reason). All other 67 jobs, including tooling, passed.
Include published-driver-update in the release evidence sealer's complete direct workload dependency list. The job added in #162629 was already joined by ci-gate, but its omission broke the existing evidence inventory assertion.
Keep that assertion unchanged. No job, permission, timeout, or repository setting changes.
Validation: five full-file Linux repetitions passed (90/90 test executions). Full test types, check-changed, boundary lint, both preflight shapes and P2 passed. The whole tooling config was replayed across four native shards; its separate jsdom focus and subprocess deadline failures are covered by the already-landed c3425e1d7b and 23172d8b8c repairs.
Adds a CI cell that installs the latest published stable openclaw as the driver and runs a managed update to the candidate built from the current revision, asserting a finished run, the candidate version, Gateway readiness, and no canary, identity, or lease warnings. It is path-gated to the updater, lease/identity, state-database-open, plugin native admission, and startup-trace surfaces and counted by the aggregate gate; on the dispatch-fallback path (checkout revision differs from github.sha) it skips with a recorded reason. Motivation: the four 2026.9.7-only update regressions (#162131, #162130, #161746, #162047) were landed by PRs whose tests exercised encoder and decoder in-process; this cell fails on the pre-fix tree. The reusable workflow checks out github.sha with read-only permissions, no persisted credentials, no cache writes, and no secrets.
Select changed extension packages and consumers of changed public source through the existing import graph, including type-only imports. Keep the complete typed programs, native lint chunks, resource limits, artifact preparation, and non-extension checks.
Retain full extension lint for scheduled/hourly main and release validation, shared lint/type policy, uncertain prior source types, and the OPENCLAW_CI_EXTENSION_LINT_FULL repository switch. Read the pinned diff base so removing a global augmentation cannot hide its consumers. Publish selected package reasons in the check-plan summary.
Twenty recent PR path scenarios emit 54 -> 40 hosted extension-lint rows (25.9% fewer): four 3 -> 0, one 3 -> 1, two already 0 -> 0, and thirteen unchanged. On Linux with four CPUs and a 16 GiB limit, warm maximum full-stripe compute was 64.44 s and the qa-lab-only stripe was 14.58 s. Shared artifact preparation took 114.24 s separately; these are not end-to-end Actions job timings. Full typed programs are unchanged. Shared loose extension consumers still retain full coverage.
The bounded historical search found one source-attributed extension-lint failure among 42 inspected runs; all three failing packages remain covered. Ten causal runs were unavailable, so this is limited historical evidence.
Proof on Linux Testboxes: whole tooling plus both owning fast configs; full core/extension/root test types; final check-changed, typed lint, boundary guards, architecture, source contracts and dead exports; eight same/different-SHA native preflight cells; native before/after manifests for twenty PR scenarios; final helper parity for all twenty plus two probes; and P2 review. Initial new-fixture errors were corrected and replayed. The sole inherited suppression-inventory failure reproduces on the unmodified parent and passes with already-landed d346309979. No workflow dispatches or CI reruns. New helper tests cost 5.25 s locally, with their Linux replay included in the focused proof.
Keep app and XCTest compilation on every admitted iOS smoke job. Select the
voice/media/typography and Access/chat lifecycle simulator groups from their
runtime, test, fixture and build owners, and omit simulator preparation when
neither group is selected. Preserve full scheduled/manual/release coverage.
Add OPENCLAW_CI_IOS_SIMULATOR_FULL to restore both PR groups, emit selection
reasons in preflight and job summaries, and include the planner in the trusted
preflight/platform harnesses. Retain every existing test case and assertion.
Test cost: the complete iOS workflow file passed 67 cases in 70.65s locally
while native compilation overlapped; the three integrated workflow/checkout
files passed 653 cases in 182.09s on Linux. Native build-only and lifecycle-only
paths passed with an unchanged app executable hash and no simulator use for build-only.
CI still used the separately maintained Bun artifact and kept native-compiler tests on Node. Pin the OpenClaw Bun fork prerelease at 57fadf566d with release metadata verification and independent archive/executable checksums. Admit the 17 compiler files and library through their existing runtime owners, retain Node siblings and dual-mode coverage, and require native PTY success in the Bun-only smoke.
Proof: all ten Linux AWS selections passed (44,534 case executions), Node focused tests passed 243/243, Bun routing tests passed 208/208, and changed-file, workflow, and import-cycle checks passed. The old-first full smoke was fail/pass/pass/pass, attributing Chrome's fresh-host first launch to a shared startup issue. Eight forced-Bun ledger global-stub failures reproduce unchanged on main; that tooling suite stays on Node.
Supersedes only the pin portion of #159988. The batch-2 pin bump remains separate.
Adds named storage locations as a generic, pluggable capability, with backup as its first consumer.
- Core storage owner (src/storage): storage.locations config, a location marker that binds identity (runtime never creates it, so unplugged disks and different disks at the same path are refused), client-side streaming encryption (scrypt key from a SecretRef passphrase, per-object HKDF keys, AES-256-GCM segments), and a built-in filesystem provider for external disks and mounts.
- Plugin SDK: api.registerStorageProvider plus manifest contracts.storageProviders; providers move opaque bytes only.
- Bundled cloudflare plugin: an r2 provider over the S3 API with conditional writes and bounded multipart uploads; auto-enabled when a location uses provider "r2".
- Backups: backup create --to <location> with verified archives, UTC retention, list/verify/restore --from, Gateway-owned offsite schedules (installed Git schedules unchanged), per-installation namespace claims fenced at publication and deletion, backup record for external jobs, backup.status RPC, Doctor/status hints, and a Systems page Backups section.
No config or state migration; the storage section is new and optional. Proof: live R2 and mounted-disk round trips, namespace takeover trace, and a published 2026.9.7 upgrade cell with an existing Git backup schedule.
Limit supplemental protected-test expansion to depth two instead of whole owner areas. Preserve the previous PR selection behind OPENCLAW_CI_NODE_SELECTION=full and summarize selected files and rules. Keep six non-import inventory guards on source edits, including the wrapper and swap-fixture regressions from #162200 and #162246. Scheduled and ordinary release inventories stay complete.
* perf(doctor): read update history through one shared snapshot
`openclaw doctor --repair` spent 2.4 s on an empty `update_runs` table
because `noteStaleUpdateRuns` issued three independent shared-state reads,
each preparing its own private snapshot (a snapshot-staging worker thread
plus a read-only child). Read the interrupted candidate, active runs, and
history through one artifact-preserving snapshot, hand the pre-read
candidate to reconciliation, and re-read fresh only after reconciliation
writes. Notes are unchanged; write-side revalidation stays in the worker.
Add env-gated Doctor phase timings (`doctor.*`) through the existing
startup-trace owner so future cost regressions are attributable, and run
the built-CLI Doctor proof before the parallel verifier wave in CI because
its fixed 30 s per-command budget is load-sensitive.
Idle 32-core Mac, fresh install: stale-update phase 2.4 s -> 0.4-0.7 s,
snapshot-staging boots 4 -> 1 per run, whole Doctor run 18.1 s -> ~16 s.
Under heavy host load the old path took 17.5 s for that phase alone.
* test(ci): count the Doctor proof barrier in workflow guards
The built-CLI Doctor proof now waits before the parallel verifier wave, which adds a wait_checks barrier; the workflow guard counts barriers and now also asserts the Doctor barrier's position.
Use the existing PR-exempt inventory, policy watches and import graph to
select Control UI browser proofs for changed route/component owners, while
retaining five cross-cutting smoke files and tests without proven ownership.
Shared UI, harness and build inputs retain full coverage. Publish each
selected file and its reasons; OPENCLAW_CI_UI_E2E_FULL restores full PR runs.
Scheduled main and full release keep all 654 Control UI files and the
separately owned 36 real-Gateway files.
A representative usage diff selects 239/654 Control UI files. Committed
weights project test work from 441.171 to 190.808 seconds; with a conservative
200-second setup reserve this is 6m31s, not a measured 5.5-minute result.
Natural PR timing remains follow-up. Ten causal historical failing PR runs
across nine PRs retain their failing files (zero misses); eight use shared
fallback, so narrow-selection backtest evidence remains limited.
Proof: Linux full test-types, full tooling with final affected-file deltas,
explicit-path check-changed, boundary lint, source contracts and architecture;
seven real manifest preflight cells cover same/different workflow SHA,
PR/schedule, kill-switch true/1 and full release. Independent P2 review clean.
Whole unit-fast: 1,498 files / 16,784 tests passed. Whole unit-fast-isolated:
138 files / 1,669 tests passed. Final affected planner proof repairs all
candidate failures from the whole-tooling run. Remaining tooling failures
are unchanged-parent PR review-expiry, Windows partition, and update-backup
fixture mismatches. Production behavior, browser assertions, screenshots,
workers and deadlines are unchanged.
* build(android): generate localization projections at build time
Generate the native Kotlin lookup and XML rows as cached Gradle source outputs. Keep tool-display translations in the native inventory so clean builds preserve the existing localized bytes, and retain manual resources and locale validation.
* style(android): format localization generation task
* fix(android): retire generated lookup from locale publisher
Tests must not race real timers (docs/help/testing/writing-tests.md, Cost
budget and Flake triage), yet withTestTimeout and raceWithTimeoutResult call
sites grew from 123 (2026-09-01) to 478 (2026-09-26). #161691 audited them,
fixed the worst files, and added the timer-free replacements
awaitGateBeforeSettlement and withinTest. This stops new uses.
check:test-timeout-race-ratchet keeps per-file counts in
config/test-timeout-race-baseline.txt (172 files, 403 sites) and only lets
them shrink. It parses every repository code file that mentions either helper
and counts each identifier reference except import specifiers: plain and
generic calls, namespace calls, aliases, re-exports, and local copies such as
the private raceWithTimeoutResult in fetch-guard.ssrf.test.ts. Comments and
strings do not count; test/helpers/promise.ts owns the helpers and is
excluded. Failures point authors at awaitGateBeforeSettlement, withinTest, or
fake timers through the owner's clock seam; removed sites require --prune.
The per-file count lifecycle (merge-base comparison, verified renames, base
drift allowance, prune, shrink demand) moves from the assertion-safety ratchet
into scripts/lib/shrink-ratchet.mts so both ratchets share one owner. The
assertion-safety output and exit codes are unchanged.
Wiring: scripts/check.mts preflight, check:changed routing for any code file
or the baseline, and one added line each in the existing PR baseline-ratchet
step and the main-push ratchet step (ci.yml +164 bytes, no new steps).
Proof (Linux Testbox, pre-rebase tree; baseline refreshed after rebase): new ratchet passes in under 1 s; injecting a call into
a baselined file and a new test file fails with the guidance; assertion-safety
reports its unchanged totals; tsgo:scripts, tsgo:test:root, and
check:changed --base origin/main pass; the affected test/scripts files pass.
New test file: 4 s with --maxWorkers=1.
Release note context: maintainer tooling only; no user-visible change.
CI: run 36812237216 green except checks-windows-node-test-3, which fails the same
package-update-swap.windows.test.ts assertion on main (scheduled run 36807764485);
fix owned by #162361.
Related: #161691
Keep the extension package-boundary check on Blacksmith during optional hybrid/runson hosted overflow. Hosted boundary jobs could not restore the self-hosted compiled-declaration archives (restore key includes runner.environment) and took 22-23 minutes; 2 of 25 boundary jobs in a 40-run census ran hosted. Explicit GitHub overrides, retry/manual/trust fallbacks, compiler checks, canary, deadlines and concurrency are unchanged.
Merged past one inherited red: checks-windows-node-test-3 src/infra/package-update-swap.windows.test.ts "preserves the package after persistent EPERM on linux (retries=false)" came from b5555b0bd9 (#162231), is red on main in hourly 36811800156, and is fixed on main by d7b029347f (#162352). This PR touches no Windows or updater code.
* fix(release): require signed publication tags
* fix(release): accept SSH-signed tag retries
* fix(release): reject lightweight signed-commit tags
* fix(release): re-sign local publication tags
* fix(release): pin signed tags across publication
* test(release): stage signed-tag finalization helper
* test(release): model signed finalization tag
* test(release): model signed Android tag resolution
* test(release): model signed finalization refs
Disable native Node matrix fail-fast for every openclaw/openclaw PR
attempt. Run 36804915849 attempt 2 cancelled 57 jobs after an inherited
main failure, preventing the remaining green proof needed by the
explicit prior-CI admin landing route.
Keep first-attempt monitoring, runner caps, routing, timeouts, and other
matrices unchanged. Qualify cancellation against each run's tested
workflow: retain historical expressions and accept the new expression
only for PRs in other workflow repositories. Align CI and landing docs.
Local proof: cancellation verifier 41 tests, workflow control 14 tests,
monitor 65 tests, hourly CI 22 tests, focused Node planning 1 test,
runner-cap and workflow-size guards 2 tests. The new regression failed
on the original workflow. Workflow sanity, formatting, and focused lint
passed; ci.yml is 404072 bytes under the 480000-byte budget. Codex P2
review found no actionable findings. No CI dispatch or rerun requested.
Build current PR smoke products once for testing, then run both focused simulator groups without rebuilding. Preserve test selectors, Debug settings, destination, separate group logs and historical/non-smoke actions.
Validation: cold/warm Xcode proof passed all 139 focused tests with unchanged app hashes; missing-product and preparation-failure controls fail explicitly. Full test-types, whole tooling config, changed checks, boundary lint, workflow validation, both manifest harness shapes and P2 review passed on the scoped candidate.
Select the simulator before compilation, then boot and slim that exact
simulator alongside the app build. Join preparation before XCTest, retain
its failure log, and bound a hung join without changing test selection or
build settings.
Validate both focused groups on cold and warm native runs (139 tests each),
plus preparation failure and timeout controls. Linux proof includes full
test types, the whole tooling config, changed checks, source contracts,
and both preflight harness shapes for PR and scheduled-main inputs.
## What Problem This Solves
The maintainer-requested eighth config cleanup removes redundant schema construction and helper plumbing left after the earlier passes.
## User Impact
No user-visible change. Config fields, generated schemas, defaults, environment precedence and preservation, Doctor normalization, redaction, and persisted state retain their existing contracts. The protected SQLite accessor files and the 698-line config environment owner are untouched.
## Why This Change Was Made
- Construct 202 strict Zod objects directly instead of constructing and then cloning each object to make it strict. Permissive objects, catchalls, refinements, field metadata, and non-immediate strict chains stay intact.
- Use the shared promise-cache owner for config observation roots, retaining successful identities and evicting only the rejected promise.
- Remove a plugin normalization cache used once, duplicate schema types, and copied suppression records; keep Doctor migration cloning explicit.
- Share history option capture and inline single-use transcript helpers without changing storage, authority, or projection behavior.
- Remove a redundant override cast and guard, inline the Nix error's single-use formatter, and shrink the assertion allowance for the removed cast. The core schema also fits its actual line limit now, so its grandfathered suppression and baseline entry are removed.
Production diff: 1,018 added / 1,356 removed, **338 net lines removed**. No tests were added or weakened. Coverage records 152 production files over 200 lines read, with 83 protected SQLite accessor files explicitly excluded.
## Evidence
- Independent Codex review completed with no actionable P0-P2 findings.
- Blacksmith Testbox `tbx_01m3skp23vxamk2c0ggwd6mx4r`, [run 36747330340](https://github.com/openclaw/openclaw/actions/runs/36747330340): all changed-source hashes matched the candidate based on `870c5b6b7f`.
- Full config suite: 471 files passed, 3 skipped; 5,661 tests passed, 10 skipped. Focused config, history, and shared-helper tests also passed.
- `pnpm build` passed. Both import-cycle checks reported zero cycles. Filesystem import-boundary suite: 23 passed.
- Schema generation, generated channel metadata, and config docs baseline checks passed with no generated changes.
- `check-changed` passed core and all test typechecking, dead-export scans, and its other guards. Its final lint failure identified an obsolete max-lines suppression after the file shrank; that suppression and baseline entry were deleted, and the affected lint and max-lines checks passed separately. The removed cast's assertion allowance was also reduced.
- Final base/candidate schema comparison: all **835,669 bytes identical**, SHA-256 `f222f2a568c39b9d3ef4ef09e595701161562faf07a08190d304f608d92f4b0a`. Both refreshed cycle checks again reported zero. Final lint and suppression checks ran locally at reduced priority after remote transport failures; the full config suite, build, and typechecks ran on Testbox.
### Fixes found along the way
The first hosted run exposed a formatting assumption in performance target metadata detection: it required exactly four spaces before the canonical `mediaModels` field. Direct strict-object construction changed that indentation while leaving the schema identical. Both canonical marker checks now ignore leading whitespace; metadata remains unevaluated and all trust, legacy-layout, and pinned-ref rules remain unchanged.
The existing sparse-checkout regression failed on the first PR head and passed after the repair. Fresh Blacksmith Testbox `tbx_01m3svxdk2ajybnbxw6s7eng2n`, [run 36764456521](https://github.com/openclaw/openclaw/actions/runs/36764456521): all 56 performance workflow tests passed (12.52s wall), both cycle checks reported zero, and workflow sanity passed. Independent review of the repair found no actionable P0-P2 issues. No tests, assertions, retries, timeouts, or snapshots were changed.
### Inherited main failure
The SDK surface-budget failures in `test/scripts/plugin-sdk-surface-report.test.ts` also occur on current hourly main [run 36760032986, job 110040129161](https://github.com/openclaw/openclaw/actions/runs/36760032986/job/110040129161), main SHA `112df95f5e`. Both main and the first PR run report 4,595 exports / 2,699 callables against budgets of 4,594 / 2,698, failing the same three assertions. This PR changes no SDK entrypoint inventory, budget, or exported name. The reporter traverses config types, but the counted export invariant already fails with the same totals on main; its budgets remain with the main-CI coordinator.
### Final head and compatibility assessment
At `5b39f39a50e31942efb4edb9b9636a8e7a1b9df6`, [CI run 36766041963](https://github.com/openclaw/openclaw/actions/runs/36766041963) completed. The repaired performance-workflow shard passed. The only failed test job is `checks-node-compact-small-15`, containing the same three SDK surface-budget failures documented on main above; the CI-gate failures are downstream of it. Security-fast, dependency review, and security-sensitive review passed.
The review's data-model flag names `config-write-guard.ts`, where this diff only inlines the existing Nix error formatter. No storage operation, migration, serialization format, updater marker, or lifecycle step changed. Streaming normalization retains the same clones and precedence; plugin normalization retains the same input and result after removing a cache used once. The complete generated schema is byte-identical, and config/Doctor-facing suites passed. This introduces no new migration or upgrade contract. A published-updater integration run is not claimed; the path-based data-model classification does not describe the actual change.
The ClawHub release planner and prepared-artifact resolver read the new public publication-state endpoint (/api/v1/packages/{name}/versions/{version}/publication). Only absent versions are republished; pending ones are skipped, and failed ones are excluded, with the recover command printed to the step summary. A 404, or a 200 without a state field, falls back to the legacy version probe.
Move third-party app lint back to the existing Wear row and budget
Blacksmith phone tests across up to four isolated JVMs. Each JVM receives
its share of the available CPUs; the existing 1 GiB heaps remain unchanged.
On the same eight-CPU Linux Testbox, clean project outputs and warm
dependency caches reduced the affected phone row from 446.13 to 233.34
seconds of Gradle wall time. Wear moved from 20.49 to 174.36 seconds;
the two rows together fell from 466.62 to 407.70 runner-seconds.
All 3,665 third-party and 3,533 Play tests passed, along with Wear/shared
tests and the selected Android lint tasks.
Keep all four normal rows, all six full-validation rows, test assertions,
Gradle tasks, hosted settings and timeout budgets. Actions job-wall
measurement remains a follow-up for the next natural hourly.
Validation: complete 905-file tooling inventory across the interrupted and
resumed runs; 897 files passed, seven retained existing skips, and three
assertions in pr-merge-prior-ci-timeout.test.ts failed identically on the
unmodified parent (25 passed, three failed). Full test-types, main/PR/full
preflight smoke, workflow validation, boundary lint, six-file check-changed
and direct-API P2 review passed. No test or assertion was weakened.
The intact published-upgrade-survivor runs in every admitted hourly main CI run
and Full Release Verification through its normal_ci child. Preserve the exact
legacy-operator-state scenario with auto-auth when the target declares it.
No PR owner changes select this survivor, including updater, Doctor,
state-migration, or direct survivor changes. The other five Docker seed lanes
keep their existing PR owner selection.
Frozen historical targets retain their supported base fallback; invalid
catalogs fail. No survivor scenario case or assertion is removed.
Reuse the existing main smoke package profile for owner-selected PR Docker seed checks. Keep runtime builds, SDK declarations, tarball validation, and upgrade survivor assertions; full declarations remain in hourly cache warming and Full Release Validation.
Move the existing dependency row to the admitted preflight-only family on narrow PRs. Preserve its commands, runner policy, total job count, and central ownership when that family is disabled.
* fix(release): honor ClawHub Retry-After, bump the reviewed publish workflow, and document staged-attempt recovery
* fix(release): expose the ClawHub recovery helper as a package script
* fix(release): sweep stale publish children before dispatch and wait for the beta-floor sync
* test(release): drive stale-child guards before dispatch in workflow fixtures
* fix(qa): pair Inspector pages with fresh dashboard links
Acquire a fresh single-use dashboard handoff for every Inspector page.
Cover real pairing, replay rejection, identity and receipt selection,
reload, and Chat draft preservation in a release-only browser fixture.
Real Gateway proof: 81.29s wall including prerequisites, 17.84s test body.
* fix(ci): complete Inspector pairing fixture inventories
Align private-server discovery and non-release counts with the Inspector
fixture, and include it in the frozen-target fallback command. Shorten
nearby comments to preserve the existing workflow size limit.
Workflow guards: 137 passed, 8 skipped; 85.65s wall.
Focused routing: 6 passed; 11.77s wall.
* fix(ci): include preflight manifest in trusted checkout
* test(ui): deslop s148 tests
Remove 32 duplicate table rows and 16 redundant cases covered by stronger
component and lifecycle tests. Factor local fixtures without changing the
remaining security, config, platform, ordering, or race assertions.
Shard tests: 1207 -> 1159, all passing. Test/support LOC: 35940 -> 35449.
Coverage: statements 19889 -> 19891; branches 14370 -> 14363; functions unchanged.
The 30% target is not met; remaining cases protect distinct contracts.
Formatting, typechecks, lint and stylelint passed. check-changed stops at
three pre-existing Telegram test-support export findings already recorded
by the preceding shard commit; production and script dead-export scans pass.
* test(infra): deslop s142 tests
Remove 174 duplicate routing, media, payload, delivery, and scalar-input cases. Reuse local fixtures while retaining distinct custody, authorization, migration, platform, and type contracts.
Validate the full shard, check-changed, and all four coverage groups: covered statements 14682 to 14683 and branches 10743 to 10742. The six-statement device identity storage drop is covered by the retained device-identity.test.ts case that creates and reuses the primary identity in SQLite.
* test(auto-reply): deslop s141 tests
* test(sms): deslop s150 tests
* test(ui): deslop s149 tests
* test(audit): deslop s152 tests
* test(gateway): deslop s145 tests
* test(clickclack): deslop s151 tests
* test(memory-lancedb): deslop s154 tests
* test(commands): deslop s139 tests
* test: adapt d022 cleanup to current test owners
Since #161534 the preflight "Build CI manifest" step runs
.ci-harness/scripts/ci-build-manifest.mjs, but checkout_harness did not
export it, so every pull_request preflight failed until 6c07ebfaf4
added it to preflight_scripts. No test caught the gap: every existing
test builds .ci-harness by hand from all of scripts/lib, and the
dependency-free manifest test ran the builder from the repository path
where every sibling exists.
The dependency-free manifest test now runs the builder from a harness
exported by the real owner.py checkout_harness for the preflight kind
(real git ls-files and checkout-index over a fixture index staged from
the checkout), and asserts that every .ci-harness path referenced by a
preflight step's run or uses exists in that export. It is skipped on
Windows, where the owner launches python rather than python3.
Also drop the preflight clause 6c07ebfaf4 added to the different-SHA
sparse branch: checkout() calls checkout_harness for preflight only when
HEAD equals WORKFLOW_SHA, so that branch is unreachable for preflight.
ci.yml is regenerated with scripts/generate-ci-git-owner.mts (399,898
bytes, under the 480,000-byte guard).
Proof (Blacksmith Testbox): full ci-workflow-guards (145 passed) and
ci-git-owner (159 passed) suites; the owner's tuple without the builder
fails with "Missing preflight harness paths: scripts/ci-build-manifest.mjs",
and without release-version.mjs fails with ERR_MODULE_NOT_FOUND for
.ci-harness/scripts/lib/release-version.mjs; oxfmt and the
test/scripts tsgo project pass. The changed test costs about 0.95 s
(3-4 s wall with --maxWorkers=1, +0.3 s over the repo-path version).
* feat(release): accept exact-job recorded flakes in release validation
A release lead can classify one failed Normal CI job of a Full Release
Validation run as a flake through the trusted classification workflow. The
receipt binds the exact job id and attempt, CI child run, FRV parent run and
attempt, and Release SHA, and carries a tracking issue or PR plus a reason.
Release Decision, the manifest, the publisher's live re-derivation, the step
summary, and the GitHub release notes tail treat it as a visible advisory.
Required classes and every other child stay blocking.
* docs(release): fold recorded flakes into the shared release boundaries
* fix(release): scope flake receipt discovery to the CI child run
* fix(release): require main lineage for flake receipt producers
* test(release): copy the flake classification module into tooling fixtures
* fix(release): keep advisory-only release notes verifiable