* fix(release): bound publish preflight observation, narrate frv continue, and surface SDK acknowledgement early
* fix(release): replay failed preflight reads with their exact filter
* test(release): model the exact-tag release lookup in preflight inventory fixtures
* feat(release): accept exact-job recorded flakes in release validation
A release lead can classify one failed Normal CI job of a Full Release
Validation run as a flake through the trusted classification workflow. The
receipt binds the exact job id and attempt, CI child run, FRV parent run and
attempt, and Release SHA, and carries a tracking issue or PR plus a reason.
Release Decision, the manifest, the publisher's live re-derivation, the step
summary, and the GitHub release notes tail treat it as a visible advisory.
Required classes and every other child stay blocking.
* docs(release): fold recorded flakes into the shared release boundaries
* fix(release): scope flake receipt discovery to the CI child run
* fix(release): require main lineage for flake receipt producers
* test(release): copy the flake classification module into tooling fixtures
* fix(release): keep advisory-only release notes verifiable
Adds `pnpm frv watch --run <parent>`: it resolves Full Release Validation children from the parent's dispatch-job logs and reports each attempt transition and failed job once, with runner labels. It tolerates transient GitHub failures and resumes from a small state file.
Adds `pnpm frv rerun --run <parent> --child <key|run-id> [--max-attempts N]`: a bounded, audited single rerun-failed-jobs request. It reruns the green producer when a consumer binds its run attempt (#161317) and checks the new attempt for duplicate or missing jobs.
Retires `pnpm frv prioritize --run`, since the priority variable no longer controls admission. `--restore` stays.
* test(release): guard parallel validation dispatch
* feat(release): seal independent child workload evidence
Record immutable, attempt-aware child receipts independently of parent completion. Keep receipt collection advisory and preserve publisher-only retry evidence. Partial child-reuse discovery and consumption remain a follow-up.
* feat(release): reuse sealed child evidence independently
* fix(ci): plan frozen release shards with trusted tooling
* ci(release): generate hosted shard timing budgets
* fix(release): make non-proof validation lanes advisory
* feat(release): seal resolved publication inputs
* fix(release): accept candidate tags at the frozen target
* docs(release): record pending first-hop parallel lanes
Item 8: remote main d51f3607b9 does not contain bf7848ef23. The feat/first-hop-compat-parallel-lanes branch still owns that implementation. Verified remote refs read-only and inspected the main scenario source; do not duplicate it here. No source changes; prior item gates remain valid.
* ci(plugins): run release plugin coverage on relevant pull requests
* ci(release): support reserved validation runner groups
* docs(release): reconcile fast-path validation guidance
* test(release): reconcile final guards and record validation
* fix(release): retry transient GitHub API failures during evidence verification
* test(release): reconcile advisory Linux CI lane cases with the fast-path policy
* test(release): copy the sealed-evidence tooling closure into the frozen fixtures
* fix(release): keep package integrity blocking and require live operator authority for sealed SDK and soak inputs
* chore(release): record the landing follow-ups in the PR body
* test(ci): expect the four-hour Testbox lease default from #156614
* test(release): reconcile untouched release suites with the advisory policy and reserved runner groups
* fix(release): reconcile advisory-by-default with full coverage and strict stable defaults
Keep RomneyDa's coverage (nine cross-OS Gateway pairs, Linux Gateway lanes as
required proof, Windows/macOS recorded as advisory) and his strict stable
publication gates (stable-profile, soak, blocking performance) as the default,
while retaining Peter's operator fast path: stable_soak_waiver / lane_waiver
are the only way to publish a stable without soak/performance evidence or with
failed non-proof lanes, must name the target version, apply only while the
repository variable still holds them, and are recorded end to end. The stable
closeout accepts the same waivers so the 2026.9.6 closeout replay can proceed.
Adopt main's affected-consumer planner (#156729) with item 4's hosted-row
split re-applied.
* fix(release): revalidate sealed soak waivers at the plugin npm publish boundary
The stable bootstrap approval records whether its soak waiver was explicit or
sealed; the plugin npm child rereads the repository variable before its
token-backed publish and rejects a sealed waiver the variable no longer holds.
Read-only preflight reports sealed waivers with the same rule. Docs state the
nine-pair all-group cross-OS rule and the strict performance gate; the tracked
planner backup is removed and the fast-core worker keeps its runner-group
routing.
* fix(release): recheck sealed waivers before npm I/O and repair CI-surfaced drift
Assert a still-held sealed soak waiver immediately before the plugin
token-backed npm publish, carry the live variable into preflight's gate
evaluation, and state the strict performance gate in the fast-path guide.
Fold main-side drift the merge surfaced: the seal job waits for the new
baseline-ratchets worker, the wrapper closure lists the CLI root options chain,
the maturity publisher's runner-group route is evaluated rather than compared
literally, and two main-authored session test-support suppressions join the
allowlist.
* fix(release): fetch waiver authority live before the plugin npm publish
Read OPENCLAW_RELEASE_STABLE_SOAK_WAIVER from the repository immediately
before the token-backed npm publish (404 means revoked, other read errors
refuse to publish), keep a waiver-less recorded closeout manifest byte-identical
on replay, and describe release_profile=stable as the stable default with the
beta profile plus stable_soak_waiver as the explicit operator fast path.
* test(release): anchor the publish-boundary recheck to the npm publish command
* fix(release): fall back to the job-start waiver when the token cannot read Variables
Keep the live read before npm publish (404 means revoked) but warn and use
the job-start snapshot instead of refusing every bootstrap publish when the
job token lacks Variables access.
* fix(release): refuse the plugin npm publish when waiver authority cannot be read
Revoked (404) and unreadable variable states both stop the token-backed
publish; a job token without Variables read access fails loudly instead of
publishing on a job-start snapshot.
Live, Docker, channel and release wrappers could repeat failed validation
or downgrade failed jobs automatically. Run each test invocation once,
remove known-flake redispatch, and require an explicit recorded waiver
when the release policy permits one.
Wait for the original plugin publisher to settle before reporting failure.
Keep bounded artifact-download recovery before tests. Read published
v2026.9.6 empty retry metadata without restoring executable allowances or
automatic waivers, preserving the sealed plan digest. Use the existing
fresh-read owner for release-priority cleanup.
Testbox owner/sibling proof and three CI-config replays passed. The two
freshness regressions passed 20 repetitions. Published evidence retained
its original digest; nonempty retry metadata remained rejected. The stale
Testbox assertion now matches its already-landed four-hour lease; this
change raises no runtime, test, hook or watchdog budget.
* feat(frv): retry declared flaky jobs once per child
Freeze exact flaky-job declarations into the execution plan and admit one
automatic retry wave from child attempt one to two. Retain intent and
rejection witnesses across parent recovery without replaying requests.
Coordinate manual retries with automatic owners, preserve confirmed
no-effect outcomes through later operator attempts, and finish batch
provenance admission before issuing sibling mutations. Refuse unsupported
frozen tooling before creating refs or dispatching validation.
* fix(frv): bind immutable retry cache and workflow fixtures
Limit retry-intent cache saves to parent attempt one after the intent
witness succeeds. Qualify only that exact proof-cache path, key, workflow,
and job under cache isolation.
Refresh frozen dispatch fixture defaults and bind the expanded collector
dependencies and artifact downloads to their owning jobs.
* docs(frv): clarify when retry rejection evidence exists
Rerun one executed job as soon as its child finishes, and recover failed children without waiting for siblings. Preserve immutable plan and attempt bindings, carry valid performance guards, and prove the targeted GitHub API with the isolated broker. Related #156253.
Reconcile transient duplicate jobs only in the newest retry attempt, pin run provenance, and bound controller and transport reads by the same deadline. Persistent ambiguity and older-attempt conflicts remain errors. Related #156253.
The FRV controller validated the normal CI child's dispatch scope without the
sealed plan's coverage policy, so every npm-stable-v1 plan (CI_RELEASE_SCOPE:
npm-stable since #136790) was rejected with "release normal CI dispatch scope
differs from its coverage policy" and `pnpm frv continue --failed` could not
recover a flaky child. Pass plan.coveragePolicy like the workflow-side summary
already does.
Owner: scripts/frv.mjs (same-parent recovery preflight).
Proof: new frv.test.ts case fails before the fix and passes after; 45/45
controller tests pass; observed on Full Release Validation 33722524584.