Commit graph

2411 commits

Author SHA1 Message Date
RoboClaw
ca6a7d9818
feat(release): add non-Latest extended-stable releases (#154515)
* feat(release): add non-Latest extended-stable releases

Reconcile #120522 with current main while preserving qualified artifacts, publication approvals, active-line checks, and supported recovery routes.

* feat(release): add non-Latest extended-stable releases

OpenClaw-Publication: c2238e25-fc84-40bf-ba4d-a6d9d11f4a5b

---------

Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
2026-09-21 00:29:24 -07:00
Peter Steinberger
98caef935f
fix(ci): let infra tests use their assigned workers (#154520)
* test: isolate infrastructure fixture ports and temporary paths

* test: isolate cwd regressions and compile command fixtures

* test(system-agent): reuse the prepared activation provider

* ci: let infrastructure tests follow the shared worker policy

* test(infra): make archive workspace fixtures private

* docs(ci): separate infrastructure worker policy notes
2026-09-21 00:15:35 -07:00
Vincent Koc
35f817f060
fix(release): package bundled sources with isolated installs (#154506)
* fix(release): use canonical root package preparation

* test(release): mirror prepared workspace script policy
2026-09-21 14:50:39 +08:00
Peter Steinberger
5084bde521
fix: run agents-core CI files safely in parallel (#154133)
* fix(agents): retain local service ownership through shutdown

* test(agents): await heartbeat cleanup completion

* test(agents): inject permission failures into native filesystem bindings

* perf(agents): narrow watched-session title import

* ci: parallelize agents-core files with effective worker costs

* test(ci): retain agents-core split timing assertions
2026-09-21 06:48:26 +00:00
Peter Steinberger
0af08749bb
perf(test): tier process proofs and balance Windows CI (#153950)
* perf(test): tier process proofs and balance Windows CI

* fix(ci): import Windows planner directly and align tier guards

* perf(test): share Windows preparation and pack measured projects

* fix(ci): return explicit Windows shard fields

* docs(ci): clarify Docker proof coverage after tiering

Document PR boundary coverage, main owner selection, release survivor coverage, and the proof gap for coalesced main pushes. Confirm the existing guards consume the selected Docker inventory and dispatch exact-target release CI.

* style(test): format rebased Windows workflow assertion

* test(ci): satisfy planner inventory lint contracts
2026-09-21 06:05:45 +00:00
Peter Steinberger
6319111df2 fix(test): compile Discord audio worker fixtures once
Use the existing invocation-owned compiled worker graph for the real Discord
lifecycle and pacing tests, retaining their timeouts and audio assertions.
Keep the voice SDK loader at its plugin-owned module location and record it
as a compiler input so dynamic dependency lookup and cache invalidation hold.
2026-09-20 22:25:45 -07:00
Peter Steinberger
cb4682640e
ci(codex): isolate ordinary extension test files (#154319)
Keep ordinary file globals and mocked module graphs isolated while inheriting the shared thread-worker budget. Bound ordinary processes at 24 files and preserve the independent 12-file native database-worker boundary. Timing weights remain unchanged. Controlled Linux envelope comparisons are required before this draft is ready.
2026-09-20 22:16:23 -07:00
Peter Steinberger
65485f6ade
fix(browser): preserve references across waits and renderer changes (#154215)
* fix(browser): preserve references across waits and renderer changes

Pin and bundle the patched Chrome DevTools MCP 1.8.0 runtime so source and npm installs receive the same identity repair. Verify packaged bytes and exercise real browser waits, cross-origin frames, stale-reference rejection, and recovery.

* fix(browser): declare bundled MCP dependency ownership

* test(browser): remove unused tarball fixture imports

* ci(browser): remove retired MCP download prewarming

* test(browser): pack MCP bundles with portable npm runner
2026-09-20 22:05:49 -07:00
Peter Steinberger
62f5950ba4
improve: publish CI dependencies promptly and warm hosted JavaScript caches (#154156)
* ci: publish dependencies independently and warm hosted caches

* ci: warm hosted transforms through their consumer entrypoints

* test(ci): guard compiled worker ownership after warmer split

* docs(ci): record rejected Windows store cache experiment

* docs(ci): describe Vitest-owned bytecode coverage safeguards

* ci: expose cache warmer entrypoints to dependency checks
2026-09-20 21:36:44 -07:00
Peter Steinberger
54abbae585
fix: refresh stale Gateway shutdown budgets during updates and Doctor (#153636)
* fix: refresh stale Gateway stop policies before maintenance

Main recognized historical systemd timeouts, but maintenance could stop the
resident before repair, and Doctor and already-current or no-restart updates
could preserve stale computed policy. A published 2026.9.5 resident also retains
its startup shutdown budget after the unit changes.

Refresh owned policy through the existing definition-mutation and backup owners,
confirm daemon reload, preserve operator drop-ins, and retain restore/reload/input
retirement ordering. Share maintenance between update and Doctor, and warn when
a non-stopping refresh still has a short effective manager timeout.

Publish process-owned shutdown budgets and lifecycle write-custody facts. Reuse
the suspension owner and existing update deadline: stop when idle, warn and stop
at the deadline for ordinary work or unknown custody, and refuse only current
reported write custody with its exact owner phase. Reread native policy when the
new Gateway accepts shutdown without resetting its elapsed budget or watchdog.

Thanks @ezimerman for the installed-unit and shutdown evidence.
Fixes #153153. Refs #150898, #152879, #153017.

* fix: preserve the resident shutdown budget in Gateway status

The kernel request-context adapter copied host lifecycle control methods but
dropped the recorded shutdown-budget getter. Real Linux package proof observed
a 325-second startup budget while status omitted it, forcing maintenance onto
the legacy unknown-budget path.

Forward the live getter through the existing adapter without changing request
authority or adding another budget owner. Add a real-kernel registered-status
regression for short and adequate budgets; the corrected test fails on the
original adapter and passes with the forwarding line.

Refs #153153.

* test: control the Gateway shutdown clock consistently

Restore the explicit node:perf_hooks performance import for the run-loop regressions that retain their own fake-clock assertions. They must control the same monotonic clock as the production shutdown-budget owner. Keep the deadline assertions, timers, and production behavior unchanged.

* fix: preserve Doctor legacy reads during Gateway preflight

The stale-Gateway probe opened the canonical owner-lease database without
Doctor's existing legacy-catalog admission. With a built install and a busy
Gateway port, that read created WAL/SHM files and rejected a supported repair
before maintenance could stop the Gateway.

Carry the existing read admission through restart inspection to the lease owner.
Keep ordinary restart validation unchanged and preserve canonical artifacts.
Use synthetic port, build, and reachability facts in the regression fixture while
retaining real lease reads and byte-preservation assertions.

Refs #153153.

* refactor: keep Gateway maintenance owners within line limits

The L903 stop-policy repair exceeded the existing line-growth gate after
composition with current restart and service identity handling. Move request
upgrade policy into its existing request owner and service revalidation into
one sibling implementation without changing their behavior.

Preserve original request admission time and Doctor's statically primed
maintenance facade across package replacement. The bounded drain, recorded
custody-only refusal, warning policy, and native backup/reload ordering remain
unchanged. No options, schema changes, suppressions, or baseline growth.

Validation: 398 focused tests, core typecheck, line-growth ratchet, and fresh
Codex P1 review passed. Full changed checks continue on the frozen source.

* test: retain backup custody coverage through the archive walker

The rebase incorporated the maintained archive walker, but the L903 custody
regression still referenced the retired tar-create mock. Use the existing
walker mock bound to the real backup command without changing assertions or
production code.

Validation: 132 backup, migration, cron, coordinator, and suspension tests
passed. Fresh Codex P1 review is clean. Full changed checks continue.

* fix: preserve maintenance lifecycle and wrapper contracts

Doctor fixtures advertised a running native service without the matching
resident identity, effective policy, or lifecycle readiness response. Supply
those facts through the same RPC and native-query boundaries used by the real
maintenance owner, including fresh readiness without a resident budget.

Keep exact suspension assertions current with the additive custody category.
Install the model-acquisition fixture's manager after normal PATH setup so
startup and shutdown observe the same policy under the original deadlines.
Include the custody owner in the canonical PR-wrapper source inventory.

Move the unchanged Doctor inspection assertion and shared fixtures into their
existing policy/support owners to preserve the line-growth ratchet. Do not
change the bounded-deferral, warning, or reported-write-custody refusal policy.

* fix: preserve Stop ownership through shutdown budget refresh

An asynchronous systemd budget read could resume after Stop captured a
foreground updater and re-arm the hard-exit worker. Keep watchdog admission
with the run loop's current successor owner, and represent an absent cleanup
deadline with no process-cleanup budget.

Preserve foreground no-op service ownership and the full native allowance
after verified parking. Keep one fake clock for boundary tests, prepare
fixture operations before held scripts, and join cancelled fixture work
before the next case. Move unchanged budget cases into their support owner.

Retain the ruling that unknown custody cannot block an update and only
reported write custody may refuse maintenance. Preserve all existing test
assertions and limits. The full Linux changed gate, 790 focused Linux tests,
and a fresh P1 review passed; local host limitations are recorded in the PR.

* refactor(doctor): extract update-run admission from doctor-maintenance

* fix: preserve native policy and write custody during maintenance

* fix: keep shutdown integration within source and type gates

* fix(test): own survivor model endpoint before baseline setup

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-21 12:31:05 +08:00
Peter Steinberger
a94962e9ca
chore(ci): run compatible PR tests on the pinned Bun fork (#154340)
* ci: run compatible PR tests on the pinned Bun fork

* fix(ci): include Bun runtime helper in PR wrapper extraction
2026-09-21 04:08:42 +00:00
Peter Steinberger
f5138cb0b2
ci(codex): refresh extension timing calibration (#154243)
Replace pre-fixture Codex test estimates with wrapper timings from three successful PR runs after shared database-worker fixture reuse. Preserve ordinary serial/non-isolated execution, native isolated forks, worker budgets, and both 12-file process caps.

Refresh ordinary Codex to 2.490 seconds/file, the database-worker aggregate to 7.599, and the native app-server floor to 17.31. Assert the selected native child's own measured cost and document calibration units and source runs. Both requested replay sets preserve all 124 envelopes while reducing extension rows from 50 to 48 and the Codex prediction from 609 to 291 seconds.

Validation: 2,673 planner/config tests; scoped changed-file, type-aware lint, formatting, MDX and whitespace checks; P2 review clean. Exact-head CI run 35554354798 passed on its first attempt. These are calibrated estimates, not a claim of lower measured CI wall time. Parallel scheduling and its controlled performance investigation are isolated in draft #154319.

Refs #153539, #154057.
2026-09-20 20:09:08 -07:00
Peter Steinberger
bdb935f50e
improve(workers): reduce worker startup time and memory (#154293) 2026-09-20 19:45:53 -07:00
Peter Steinberger
5acfb83d9f
feat(typesafe): support local System One decision models (#154059)
* fix(typesafe): distribute as an official external plugin

Exclude TypeSafe runtime from the core package and enroll @openclaw/typesafe in npm and ClawHub publication. Preserve the plugin ID, protected credentials, and decision-model configuration. Require the post-2026.9.5 decision API and document the pending supporting release.

* fix(typesafe): register the official external install catalog

Keep official package discovery and trust aligned with the TypeSafe distribution cutover. Existing catalog completeness and ClawHub-counterpart checks pass.

* feat(typesafe): support local System One decision models

Add an explicit loopback endpoint for Kev, without forwarding hosted credentials or changing managed proxy authority. Preserve strict answer validation while adapting local instructions, Score legends, and timing metadata. Keep the declared local model out of hosted inference. Document endpoint scope and runtime ownership.

* fix(typesafe): validate local payload types and document Kev

Preserve discriminated question types without assertions and regenerate config documentation for the requested baseUrl field. Add the pinned Kev setup and API-test commands exercised in live inference. Core and channel config budgets remain unchanged; the plugin budget grows by one intentional field.

* docs(agents): allow exact synthetic scanner fixture qualification
2026-09-20 19:44:29 -07:00
Kimi Yu
20db76a792
feat: use paired-node workspaces for attachments, Memory, and Skills (#154087) 2026-09-20 19:26:33 -07:00
Peter Steinberger
953999f1cf
fix: keep service update replacement tests meaningful and fast (#154263) 2026-09-20 19:16:40 -07:00
Peter Steinberger
01050a71f2
improve(ci): run Gateway server tests in parallel (#154181)
* test(gateway): isolate server fixtures by file

Keep fixture identity across module resets within one file, then retire mutable state for the next file. Use the configured workspace root in session fixtures and avoid changing the process working directory.

* test(gateway): await complete placement hydration

Use the full session-list read before asserting sibling materialization. Preserve the keyed describe payload and exact placement-read assertions, and verify list/describe agreement across the background hydration boundary.

* test(gateway): retain port claims through server startup

Transfer reserved port blocks through shared WebSocket and HTTP startup helpers and their callers. Release claims once after shutdown or failed acquisition while preserving retained cleanup ownership. Remove the retired auth-helper port re-export.

* test(gateway): settle fixture maintenance before validation

Drain seeded disk maintenance before injecting table loss so placement evidence retains current reader authority. Join real audit writer readiness before metadata fixture callers replace timers, preserving exact timer and shutdown assertions.

* test(gateway): await managed recovery emission

* ci: parallelize Gateway server test files

* fix(ci): align Gateway project discovery and timing fixtures
2026-09-20 18:59:54 -07:00
Peter Steinberger
a4e3a5d5f8
fix(ci): restore Vitest cache reuse (#154121)
* fix(ci): restore Vitest cache reuse

* test(ci): keep cache fingerprint fixtures strictly typed

* fix(test): preserve UI dependency identities with optimization
2026-09-20 18:12:59 -07:00
Peter Steinberger
5941d999dc
ci: reserve plugin rows in compact Node admission (#154126)
Apply the remaining final Node budget before hosted tooling compaction, counting dist descriptors separately while preserving existing caps and coverage.
2026-09-20 18:02:58 -07:00
Peter Steinberger
4912a41dbc
perf: reduce Code Mode source preparation overhead (#154209) 2026-09-20 17:53:24 -07:00
Vincent Koc
fbb42c7f95
fix(goals): recover unconfirmed controls after reconnects (#153910)
* fix(goals): recover unconfirmed controls after reconnects

* fix(ui): keep Goal recovery types below the composer

* fix(goals): reject invalid edits before arming recovery

* test(anthropic): make controlled watcher arming deterministic

Start the synthetic monotonic clock at an exact integer and cover a
fractional ambient clock through the real watcher owner. This fixes the
diagnosed Goal CI failure without changing production timing or assertions.
2026-09-21 07:46:12 +08:00
Peter Steinberger
5607b5e422
fix(ci): isolate large workspace inventory proof (#153466)
Run the 13,000-file workspace recovery proof in its own CI planner invocation and preserve exclusive admission when compact jobs are packed. This removes competition with sibling Vitest files while retaining complete staging, apply, serialized-journal, and recovery coverage and the existing 120-second deadline.

No installed-product behavior changes. The Linux replay passed 1,256 tests in both layouts; the large case improved from 27.647s to 19.972s, with total runner time increasing by 6.98s for the separate invocation. The original eight-worker timeout was not reproduced. Planner regression coverage spans all three runner backends and PR/push plans; focused validation and independent review passed.

Related: #153360
2026-09-20 16:15:24 -07:00
Peter Steinberger
911f63ab91
fix(doctor): recover verified session imports with missing or replaced files (#153655)
Doctor now recovers verified session imports when the original legacy index is missing, a restored source has a different inode, or the import database has been replaced. The receipt owner verifies hashes and ordered canonical transcript events before refreshing existing receipt evidence; conflicting sources remain protected, and current session settings and deletions remain authoritative.

Gateway readiness can admit usable SQLite stores while retained inputs await Doctor repair. Readiness does not grant archival authority. Recovery reports include remaining issue codes without claiming successful validation.

Published 2026.9.4 and 2026.9.5 updater cells cover missing indexes, copied sources, and replaced databases, preserving transcripts, hashes, schemas, and SQLite integrity. Reordered replacement history remains refused. No schema, dependency, configuration, or CLI option changes.

Thanks @cpsleepy, @mmm7053455-tech, @blackeyes-boy, and @Albertyn87 for the reports and recovery evidence.

Fixes #152884.
Fixes #153606.
Fixes #153619.
Follow-up to #153097.
2026-09-20 16:10:56 -07:00
Peter Steinberger
aed59efc4b
refactor(code-mode): execute JavaScript with typed API discovery (#154001)
* refactor(code-mode): execute JavaScript with typed API discovery

Keep schema-derived tool declarations available to agents while removing TypeScript compilation, optional preflight, and language selection from Code Mode. Retire the saved languages setting through shared Doctor/startup migration, preserving activation and limits. Existing TypeScript cells must be rewritten as JavaScript.

Related: #153889

* fix(code-mode): complete JavaScript cutover checks

* docs(config): regenerate JavaScript-only Code Mode baseline

* test(code-mode): match public names in live validation errors

* test(code-mode): avoid shadowing the selected call

* test(code-mode): allow fixture rereads in live evidence
2026-09-20 15:57:08 -07:00
Peter Steinberger
7d1371e25f
fix(ci): parallelize cron files within the shared worker budget (#154097) 2026-09-20 15:37:08 -07:00
Peter Steinberger
0a9d65e3b7
ci: reuse verified test workers across jobs (#154095) 2026-09-20 15:32:27 -07:00
Peter Steinberger
7627a337b5
fix(ci): split agent session test type graph (#153943) 2026-09-20 15:20:37 -07:00
Peter Steinberger
9034c0aa26
perf(pr): batch REST author reads during landing (#154040) 2026-09-20 14:24:38 -07:00
Peter Steinberger
1ba74856d2
fix(tooling): avoid redundant reads and incomplete CI success (#153880)
* fix(tooling): avoid redundant reads and incomplete CI success

* test(tooling): align admin fixture with compact author reads
2026-09-20 11:18:55 -07:00
RoboClaw
d03914402d
fix(ui): restore JSON tree and raw views in chat (#153272)
* fix(ui): restore JSON tree and raw views in chat

Restore the shared source-faithful JSON tree and raw controls for code fences and bare assistant JSON, preserving exact copy payloads and static user previews. Remove the legacy JSON chip renderer and cover browser controls, source fidelity, and transcript geometry.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

* fix(ui): restore JSON tree and raw views in chat

Worked on by:
- @vyctorbrzezowski

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
OpenClaw-Publication: 54ab65f3-06ea-4708-a4f3-d521b65566b5

* test(ui): repair JSON restoration CI coverage

Keep private-server inventory sorted and move JSON retention coverage into its owning test suite without changing runtime behavior.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

* test(ui): preserve current tool inspector coverage

Drop the obsolete sanitizer import after composing the JSON restoration with the current raw tool inspector.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

* fix(ui): preserve long user JSON disclosure

Reuse the message-level disclosure owner for literal JSON while keeping user and pending-preview content free of JSON controls. Reuse JSON node classifications and remove the empty render fragment without changing performance budgets.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

* fix(ui): keep code-block copy off startup

Load code-block English with its rendering owners, preserve complete catalog composition, refresh the measured boot manifest, and remove retired JSON-chip copy and CSS. Keep startup budgets and compression unchanged.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

* fix(ui): prevent duplicate managed image retries

Cancel the queued automatic refresh when a render or explicit retry claims the same retry. Preserve the bounded retry policy and unchanged auth-recovery browser assertions. Both new regression cases fail before this repair with three requests instead of two.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

* test(gateway): isolate cron handoff wakes

Disable the unrelated periodic heartbeat in the two-on-exit handoff fixture and assert that the second wake targets its job. Preserve existing assertions and registration order while moving the intact case into the receipt-test support module to satisfy the line-cap ratchet. Production scheduler behavior is unchanged.

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>

---------

Co-authored-by: vyctorbrzezowski <51521767+vyctorbrzezowski@users.noreply.github.com>
2026-09-20 10:39:33 -07:00
Vincent Koc
209dc0e6d5
fix(control-ui): make teammate assignment searchable and preserve current identity (#153798)
* fix(ui): make session assignment and member pickers searchable

* fix(ui): defer people-picker copy and align sharing pagination proof
2026-09-21 01:22:42 +08:00
Peter Steinberger
ce8b5078ef
ci: collect measured timings for PR-only tooling (#153676)
* ci: collect measured timings for PR-only tooling

* test: align timing fixtures and workflow routing
2026-09-20 07:12:46 -07:00
Peter Steinberger
d98c427379
test(config): parallelize the complete state startup corpus (#153532)
* test(config): parallelize the complete state startup corpus

Keep all 34 release/config pairs and both startup passes. Share the matrix and file inventory, retain fresh historical state per cell, and reuse lifecycle-owned SQLite inspection workers and Gateway plugin metadata. Route every partition through CI coverage receipts and runtime prerequisites.

* fix(ci): register startup corpus inventory for extracted tools

Declare the JavaScript inventory for production type checking and include it in the maintained wrapper closure. The complete matrix and benchmarked runtime remain unchanged.

* test(ci): compare precise owners before runtime relocation

Precise selection intentionally retains pre-relocation capacity. Build the comparison template without placement observations, restore real timing reads, and retain all routing, preparation, timing, and coverage assertions.
2026-09-20 04:53:34 -07:00
Peter Steinberger
61bbd59ea8
ci: budget changed-extension envelopes from measured costs (#153515)
* ci: budget changed-extension envelopes from measured costs

* ci: fit measured extension envelopes within landed row caps
2026-09-20 04:24:50 -07:00
Peter Steinberger
06ba5109fe
fix: keep Workshop event reads off the Gateway request thread (#152583) 2026-09-20 03:43:24 -07:00
Peter Steinberger
8f82ec8ad2
feat(onnx): add local decision models and provider guides (#153476)
* feat(onnx): add local decision models and provider guides

* fix(onnx): complete standalone plugin packaging

* fix(onnx): register official plugin discovery metadata

* fix(onnx): reject hosts without decision-provider support
2026-09-20 03:34:46 -07:00
Peter Steinberger
e021aac62f
chore(update): parallelize managed handoff lifecycle proofs (#153569)
* test(update): parallelize managed handoff lifecycle proofs

Retain all 181 scenarios and real helper processes across focused files. Retire mocked handoff owners through the existing cancellation lifecycle, and keep each entry with its infra runner and runtime prerequisites.

Update behavior, timing budgets, and the installed-driver/candidate proof composition are unchanged.

* test(update): keep handoff type roots within shard limits
2026-09-20 03:20:19 -07:00
Peter Steinberger
8b2c9fbcc8
fix(test): reuse compiled runtime workers across local runs (#153558)
* perf(test): reuse verified runtime worker artifacts locally

Retain joined compiler generations in exclusive checkout-local slots and
reuse their content-verified outputs on unchanged invocations. Preserve
source, output, resolution, toolchain, and borrower-lifetime checks while
avoiding repeated native compilation. CI routing and fresh-build policy,
Bun, custom loaders, test assertions, and timeouts remain unchanged.

Batch prepared fixture copies, relocate the complete fs-safe runtime
closure with its native packages, and inject one compiler fault child
per lifetime so receipt writers cannot race.

Related: #132712, #139428.

* fix(test): repair worker cache harness CI fixtures
2026-09-20 03:02:54 -07:00
Peter Steinberger
123b8acdcd
ci: raise compact and Node matrix row caps slightly (#153519)
Raise compact plans to 90 rows and final Node matrices to 70 push / 130 PR rows. Preserve overflow rejection, runner policies, workers, timeouts, and test coverage.

Update capacity documentation and boundary tests. Keep the dependency-free preflight fixture focused on its import contract without relaxing its deadline or forbidden-import guard.

Validated by the green CI run on the refreshed PR head, exact scope checks, and the completed independent review.
2026-09-20 03:01:58 -07:00
Peter Steinberger
7995f8fbc4
fix(tooling): continue CI and squash landing after GraphQL exhaustion (#153563)
* fix(tooling): continue CI and squash landing after GraphQL exhaustion

* fix(tooling): register REST merge CLI for unused-file checks
2026-09-20 02:00:09 -07:00
Peter Steinberger
45c9e5c465
fix(plugins): reclaim catalog captures after Gateway crashes (#153468)
Model-catalog capture directories could accumulate after a Gateway crash or
SIGKILL because both producers allocated outside managed capture custody.
Allocate through the existing plugin capture owner and retain custody until
worker exit is confirmed, so abandoned-instance cleanup can reclaim them
without removing resources from a live or terminating worker.

Preserve the shipped worker SDK temporaryDirectory cleanup contract and order
producer cleanup after legacy-directory cleanup. Doctor now reports legacy
capture roots and an explicitly offline cleanup command; it leaves them
unchanged even with --fix, and update passes skip the informational traversal.
No schema, dependency, configuration, or CLI option changes.

Thanks @ZaneChen76 for reporting accumulating capture directories.

Validation: scoped-clean independent review; exact-head CI; existing native
custody, SIGKILL reclamation, worker-pool cleanup, Doctor, package-capture,
and test-planner proof recorded in the PR. No published-updater transition
was exercised; that proof gap remains documented in the PR.
2026-09-20 01:56:30 -07:00
Peter Steinberger
880fdd449b
fix(update): avoid repeating candidate checks before repair (#153188)
Reuse completed candidate validation and its safely retained migrated private state when automatic repair starts. A later check failure no longer triggers another multi-gigabyte snapshot and Doctor pass before discovering that inference is unavailable.

Keep the existing repair owner responsible for consuming the cached result once, validating every subsequent repair turn, draining workers, and cleanup. Incomplete migrations or unconfirmed teardown still require a fresh copy, and activation always requires fresh-copy validation. Keep source configuration hashes bound and bound diagnostic redaction to the existing IPC limit.

Recorded Linux package proof covers published 2026.9.4 to candidate, injected recovery failure with one snapshot and no repeated Doctor, and the next-version fixture. All 13,600 cache rows and database sizes were preserved. Exact-head CI passed; scoped review found no actionable findings. Runtime package evidence belongs to the earlier proof revision with review-confirmed continuity, and does not establish macOS or managed-service package-update coverage.

Thanks to @BodegaClaw for the measurements and follow-up evidence.

Refs: #153049, #153077, #144447, #153099, #144858.
2026-09-20 01:55:39 -07:00
Peter Steinberger
6584af0ae9
perf(state): skip full agent scans on clean same-version restarts (#153463)
Keep verification records in the quarantine store and let the existing
lease owner consume clean proof and certify the last checkpointed close.
Share gate eligibility with readiness, queue quick verification after
listening, and invalidate proof across crashes, aliases, and maintenance.

The warmed 899.5 MB fixture gate falls from 1094 ms to 17.8 ms (98.4%).
Full checks remain for updates, migrations, unclean or replaced files,
Doctor, shared state, snapshot fallback, and daily verification.
2026-09-20 01:50:31 -07:00
Peter Steinberger
e375277a9b
fix(doctor): restore Gateways after systemd inspection failures (#153017)
Doctor could leave a healthy systemd Gateway stopped when repeated update-admission checks exhausted restoration inspection. Use lightweight custody for metadata reads, retain the native service identity before shutdown, and restore with a warning after inconclusive diagnostics while verifying readiness. Revalidate broker, manager, unit, account, and current authority at activation; preserve explicit ownership refusals without an unbound fallback.

Keep failed Doctor lint output compatible with published updaters by retaining the readiness envelope, redacted error metadata, and exit 2. No persistent schema, configuration, CLI, or dependency contract changes.

Thanks @xilopaint for isolating the LoadUnit delays and providing the timing trace.

Validated by green exact-head CI, focused regression coverage, real Linux recovery and native refusal observations, and a published 2026.9.5-to-candidate update that completed successfully without rollback. The frozen released reader accepts success, warning, and repaired failure output. Independent Codex review found no actionable P0/P1 findings.

Fixes #152879.
2026-09-19 23:49:02 -07:00
Peter Steinberger
017eb0db64
fix(ui): show gateway lifecycle status once (#153321)
* fix(ui): show gateway lifecycle status once

* fix(ui): keep gateway recovery visible across layouts

* test(ui): remove retired settings refresh prop assertion

* fix(ui): stabilize initial gateway recovery and retain fallback status

Keep transient first recovery out of the separate status row while preserving reconnect recovery. Keep retry reachable when sidebar code is unavailable. Reset the artifact-authority fixture listener before each case to prevent shared-worker contamination.

* refactor(ui): keep the sidebar registration tag in one constant
2026-09-19 23:22:19 -07:00
Peter Steinberger
ca128370df
perf(tooling): skip tsx for native compiler shard entry (#153446) 2026-09-19 22:44:55 -07:00
Peter Steinberger
e7f5b8f57a
refactor(package): reuse fs-safe staging-debris traversal (#153400) 2026-09-19 21:54:58 -07:00
Bảo Võ
184cdd4eff
test(update): preserve unverified restart outcomes after package swaps (#142102)
* fix(update): keep a managed update from stranding the gateway after the install swap

A managed package update stages the new version, swaps it over the live
install root, and only then restarts and verifies the gateway. That
restart runs inside the updater process, which is still executing the
build that was just replaced. The bundled dist is split into
content-hashed chunks, so any `import()` reached for the first time after
the swap resolves to a chunk name that only the old tree contained:

  Gateway: restart failed: Error: ENOENT: no such file or directory,
  open '.../node_modules/openclaw/dist/shared-DFJEouXv.js'

`maybeRestartService` caught that as a restart failure, which became
`recovery.serviceRestartSafe: false`, which made the update helper exit
with the unsafe code and log "keep the gateway stopped until the
installation is repaired". The installation was fine -- npm install, the
swap, and doctor had all exited 0 -- but the gateway stayed down until
someone restarted it by hand. Observed on a 2026.9.1 -> 2026.9.2 npm
update: a 3h outage from a successful upgrade.

Two changes:

- Warm the restart path's lazy modules in `beforeActivate`, the last
  point where this process can still read its own install tree. The probe
  gained a loader for `gateway/call.js`, which was a bare dynamic import
  and so could not be warmed.

- Recognize a missing module inside our own install root and stop
  treating it as a verdict on the new install. Restarting the service is
  strictly better than parking it: the old process is gone either way,
  and a genuinely broken install still surfaces through the service's own
  supervision. A missing *data* file in the install root is still a real
  failure.

Claude-Session: https://claude.ai/code/session_01WKVaMWLzdHNJCa82nnTfWg

* test(update): use canonical normalization in restart regression

* test(update): register package-swap regression in its CI owner

* test(gateway): join task events before reset fixture cleanup

* test(gateway): join task events before in-test settlement

* test(gateway): prepare auth command runtime before handshake

* fix(ci): bound serial storage-state test stripes

* fix(ci): scope storage file ceiling to hosted jobs

* test(transcripts): wait for routed provider startup

* test: honor delivery and session fixture ownership

* test(transcripts): join configured provider startup

---------

Co-authored-by: baovo15 <duybao.vin@gmail.com>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 22:50:18 -06:00
Omar Shahine
88c56ec432
feat(plugins): add experimental FaceTime realtime voice bridge (#119291)
* feat(plugins): add experimental FaceTime realtime voice bridge

Co-authored-by: Peter Steinberger <steipete@gmail.com>

Co-authored-by: Dallin Romney <dallinromney@gmail.com>

* test(facetime): align portable release gates

* ci: refresh FaceTime PR checks

* fix(facetime): retain startup suppression through hangup

Begin carrier closure before startup teardown and keep native suppression pending until carrier absence is confirmed.

* fix(facetime): retain cancellation until carrier safety is confirmed

* fix(facetime): separate carrier closure from startup teardown

* test(pr): model authoritative repository identity in sibling fixtures

* fix(facetime): retain suppression without carrier proof

Do not treat the capture watchdog shutdown as evidence that the native carrier terminated. Keep the call unresolved and process suppression retained until exact termination or stable absence is observed.\n\nCo-authored-by: Codex <noreply@openai.com>

* fix(facetime): retain disconnected carrier proof

* fix(facetime): stabilize live audio startup and routing

* fix(facetime): refresh merged lockfile

* refactor(facetime): separate helper result projection

* fix(facetime): align published package metadata

* fix(facetime): satisfy preflight lint checks

* fix(facetime): preserve consult and carrier ownership

* test(facetime): declare regression fixture types

* test(release): align merged publisher inventory

* fix(facetime): retain runtime across safe uninstall

* fix(facetime): restore responsive call opening

* refactor(facetime): keep greeting policy localized

* fix(facetime): accept trusted stock Xcode

* fix(facetime): use compiler link drivers

* fix(facetime): repair portable lifecycle checks

* fix(facetime): normalize installed driver permissions

* fix(facetime): preserve consults during caller speech

* fix(facetime): make answered-call greeting reliable

* fix(facetime): honor explicit agent session owner

* fix(facetime): finish voice consults promptly

* fix(facetime): preserve repeated voice consults

* fix(facetime): settle consult delivery before reporting success

* fix(facetime): retain suppression until carrier closure is proven

* docs(facetime): refresh merged plugin reference count

* fix(facetime): preserve installed driver when backup fails

* test(facetime): prove rejected calls cannot start media

* fix(facetime): verify unknown SIP status before setup advice

* test(facetime): prove caller rejection at authenticated media boundary

---------

Co-authored-by: Omar Shahine <10343873+omarshahine@users.noreply.github.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-09-19 20:36:04 -07:00
RoboClaw
066a93fbda
fix(release): recognize the reviewed 2026.9.6 plugin inventory (#153372)
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-19 19:59:19 -07:00