Commit graph

104064 commits

Author SHA1 Message Date
Dallin Romney
ccab514b10
fix(release): validate frozen npm bundle versions (#163673) 2026-10-02 17:43:05 +00:00
Peter Steinberger
cf43499dc9
fix: preserve retained children after Bun output shutdown (#163633)
Preserve retained descendants when Bun completes supervised command output. Keep the older-Bun FFI half-close, but do not treat Darwin's benign repeated-shutdown ENOTCONN as lost lineage; the host still independently requires output EOF and process extinction.

The retained-child regression passes 3/3 on Node 24, Bun 86bd, and Bun 1e6f on macOS arm64 and Linux x64. Full applicable process/CUA and Mac-gate coverage, explicit desktop controls, P2 review, changed-file checks, and exact-head CI pass. Related: #163456 and openclaw/bun#76.
2026-10-02 10:40:33 -07:00
Peter Steinberger
b26dde75dc
fix(test): Telegram skill follow-up control and binding checkpoint tests fail on loaded hosts (#163326)
Both cases raced wall-clock deadlines that were not the behavior under
test. The follow-up control test bounded its child with a 5 s spawnSync
timeout and a 2 s polling budget. The binding checkpoint test ran the
product checkpoint on the real clock, so its 90 s readiness and 60 s
verification budgets, which bound live runs, failed routing tests with
VERIFICATION_DEADLINE when the host stalled. Sampling stuck children
showed them blocked in kernel rename() for up to 194 s.

Children now run through an async helper bounded by a 90 s node:test
timeout, with one after hook per test that kills each process group,
joins every child, and only then removes the temp root. The follow-up
child waits for the product's status sequence and names the step it is
waiting for. The checkpoint child freezes performance.now() through a
data: preload, and its three cases run concurrently so the file stays
inside the harness's 120 s budget. Assertions are unchanged.
2026-10-02 10:38:01 -07:00
Peter Steinberger
be5b7292d8
ci: pin the OpenClaw Bun fork 1e6f prerelease (#163658)
Pin Linux CI to the checksum-verified 1e6f Bun fork prerelease and qualify complete Quicksilver worker, broker event-order, and broker group-custody coverage. Preserve V8/registerHooks exclusions, Windows skips, and the shutdown workaround required by stock Bun.

Proof: every existing Bun selection compared against 86bd without new failures or skips; final admitted CI groups passed on 1e6f; the candidate passed all ten Node-hidden smoke steps with an empty blocker list. Focused Node/Bun checks, changed-file checks, and both P2 reviews passed. Three unchanged provider-message assertions failed equally in the frozen baseline comparison, and the old smoke's Chrome startup failure is recorded in the PR evidence.
2026-10-02 10:37:38 -07:00
Peter Steinberger
24bdc542d2
test: stabilize flaky fixtures (batch f160) (#163670)
* test(gateway): stabilize s840 fixtures

Port the remaining argument-forwarding fix from 3fb94312b32b45134098870e7c8cf566bfe60a22. The lane already contains the other fixture updates; preserve all existing cases and assertions.

Validation: 35/35 tests across all three shard files passed on Blacksmith Testbox from a fresh-main small-delta proof checkout. Oxlint, oxfmt, git diff --check, and isolated review passed.

* test(node-host): stabilize Node runtime process fixture
2026-10-02 17:35:24 +00:00
Peter Steinberger
698e6d2e74
test(cron): hoist diagnostic auth source mock
Initialize the mock before static imports can evaluate its vi.mock factory.
The failure-copy import added in 3c5010ebfa reaches the auth store through
the provider failover chain before this test's ordinary const initializer.
Keep the mock behavior and all nine diagnostic assertions unchanged.

Validation: authorized single-file test-only exception. Five baseline
runs fail collection; five fixed runs pass 45/45 tests. Local oxfmt,
oxlint including boundary guards, the services-cron test type graph, and
P2 review pass.
2026-10-02 10:34:19 -07:00
Peter Steinberger
331a6f0d1d test(swift): use draining players in off-main relay fixtures
The startup and routing tests added in 646916d1c2 enqueue real output
playback but supplied UnusedPCMStreamingAudioPlayer, whose play method
traps. Whether cancellation reaches the playback task first determines
whether the fixture aborts the entire OpenClawKit test bundle.

Use the existing DrainingPCMStreamingAudioPlayer in both fixtures that
enqueue audio. Preserve every assertion and the real off-main playback probe;
production code is unchanged.

Hosted Xcode 27 proof, using CI's serial OpenClawKit command filtered to
RealtimeTalkRelaySession:
- Base 3562b697df reproduced the same startup fatal error (331.54 s wall):
  https://github.com/openclaw/openclaw/actions/runs/37035309053
- The fixed source tree passed 62 tests in 7 suites, then 20 consecutive
  --skip-build runs of all 3 RealtimeTalkRelaySessionOffMainTests:
  https://github.com/openclaw/openclaw/actions/runs/37036759038

This source tree matches the hosted candidate; the temporary proof
workflow is excluded. No native tests ran on the operator Mac.

Test cost: hosted Xcode 27 cold Swift build/test 232.95 s wall; 20 warm off-main runs 24.67 s total (1.23 s/run).
2026-10-02 10:32:59 -07:00
Peter Steinberger
4214c389a1
fix(test): Telegram runtime test leaks temp roots when a case times out on a loaded host (#163624)
Telegram skill runtime test (`telegram-runtime.test.mjs`) removed its temp root before stopping the uv/Python children of a timed-out case, so on loaded hosts those children kept writing under the removed tree and the directory leaked.

Each case registered `fs.rmSync(root)` as its first after hook and every `run()` registered its own kill-and-join hook later. node:test runs after hooks in registration order and stops at the first one that throws (verified on Node 24.21.0), so the root was removed while stalled children were live, and a throwing removal skipped every kill hook.

Each case now registers one after hook at test start: SIGKILL every tracked child's process group (unconditional, tolerating ESRCH/EPERM), await every close, then remove the root via useAutoCleanupTempDirTracker. run()/stopChildren() match the sibling follow-up/checkpoint tests in #163326. Assertions unchanged; test-only, no user-visible change.

Proof on head 34c45c4b75: in-process SIGSTOP probe (uv and sandboxed uv/Python groups) shows main's version removing roots with live children 6/6 vs 0/6 here, no surviving PIDs or roots; natural-load timeouts leaked roots on main in 2 of 3 timed-out runs vs 0 of 3 here; flake proof bar met with 20/20 standalone runs and 3/3 telegram-e2e-userbot-skill harness runs. run-mock-sut-user-e2e.test.mjs was checked and already joins its run scope before temp cleanup.

Follow-up to #163108.
2026-10-02 10:31:54 -07:00
Peter Steinberger
60dda33dbf
test(codex): make native sandbox and compaction tests hermetic on macOS (#163656)
transport-stdio.sandbox.test.ts (darwin-only, skipped on Linux CI) passed the
partial user-input bridge fixture to buildTurnStartParams, which reads the
required EmbeddedRunAttemptParamsV2.hostCapabilities. Attach the shared test
host capabilities at that call site; the bridge suites never read the field
and would otherwise import the full coding-tools graph.

compact.native.test.ts uses a user-scoped Codex home, which intentionally
resolves managed starts desktop-first. On Macs with ChatGPT.app installed the
test spawned the desktop codex instead of the pinned package it asserts. Pin
package-only managed selection in the test's client factory; production
precedence is unchanged.
2026-10-02 10:31:30 -07:00
Peter Steinberger
e0f01cda74
test(plugins): remove low-value tests (batch d159) (#163666)
* test(plugins): deslop s1107 tests

* test(plugins): retain third-party artwork isolation coverage
2026-10-02 17:30:51 +00:00
Peter Steinberger
d6929f854d
refactor(sessions): move prepared metadata patches into workers (#163378)
* refactor(sessions): commit prepared entry patches in workers

Move audited durable metadata updaters through the existing agent executor. Retain host callbacks and authority, physical-database FIFO, full snapshot CAS, and acknowledged publication. Preserve opaque plugin callbacks, incognito storage, and maintenance scopes on their native owners; schemas and update behavior are unchanged.

* test(sessions): verify patch transaction visibility and drain workers

* test(sessions): complete worker-backed fixture cleanup

* test(sessions): settle workers before retiring database fixtures

* fix(sessions): keep maintenance running after worker entry commits

* test(sessions): respect worker admission and fixture lifetime

* fix(sessions): retire protection after maintenance finalization

* test(sessions): align fixtures with worker-owned commits
2026-10-02 10:28:20 -07:00
sxh
4e9dec17f3
fix(media): attach every file a reply lists as a serialized JSON array on a MEDIA line (#163627)
Fixes #163615.

A serialized JSON array on a MEDIA line (`MEDIA:["/ws/a.png","/ws/b.png"]`) now delivers every listed file in order, through the existing quote-aware MEDIA splitter. Space- and comma-separated quoted forms, separate lines, and literal paths containing brackets are unchanged.

Proof: Telegram Test Server with real gpt-5-mini through a passive recording proxy. Replaying the exact recorded replies through the main parser delivered one photo; this change delivered both photos in order. All four controls delivered the same seven ordered photos on both. Regression tests fail on main (5 cases) and pass here.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-10-03 01:21:10 +08:00
Peter Steinberger
4e3ab7babc
test(scripts): copy only the native compiler parts each fixture uses (#163374)
Some checks are pending
Native App Locale Refresh / Refresh native fr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native hi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native id (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / approve_plugins_npm_release (push) Blocked by required conditions
Native App Locale Refresh / Refresh native de (push) Blocked by required conditions
Native App Locale Refresh / Refresh native es (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fa (push) Blocked by required conditions
Native App Locale Refresh / Refresh native it (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Node Runtime Conformance / scope (push) Waiting to run
Node Runtime Conformance / TypeScript contracts (push) Blocked by required conditions
Node Runtime Conformance / Rust workspace (push) Blocked by required conditions
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Blocked by required conditions
Plugin Init Scaffold Validation / scope (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
materializeNativeCompiler copied the whole native typescript package into
every fixture. 482 of its 493 files are dist/ (the typescript/unstable/*
JavaScript API) and vendor/ (that API's JSON-RPC transport), which only
toolchain identity hashing and fixture-resolved API imports read.

Per consumer:
- changed-lanes: root-test lint is boundary-free and parses config with the
  repository's own API, so the copy was never read; drop it.
- write-plugin-sdk-entry-dts / write-unified-entry-dts: createFixture already
  copies the same package with its platform binary since the TypeScript 7
  cutover; drop the redundant overlay.
- run-tsgo-worktree, ownership --version preflight, Windows long-path
  resolution: launcher-only copies (javaScriptApi: false).
- interceptor fixtures that exec a real compiler: exec the installed binary
  (resolveInstalledNativeCompiler); the lint-consumption case keeps its full
  fixture-local install and binary because preparation hashes it and admits
  default-library reads inside the checkout.
- shard concurrency: its synthetic compiler needs no install.

Build-artifact, extension-boundary, native-declaration, prepare/check
boundary, and tsdown-config fixtures keep the full copy. Copies stay on the
filtered close-on-exec cpSync path; assertions and timeouts are unchanged.
2026-10-02 10:13:53 -07:00
Dallin Romney
935563c38d
improve(ci): run first-hop post-convergence proof once (#163631)
* perf(ci): deduplicate post-convergence first-hop proof

* test(ci): cover canonical first-hop lane admission
2026-10-02 10:12:15 -07:00
Peter Steinberger
dd5ff2c382
fix(test): avoid runtime rebuilds after test utility edits (#163571)
Exclude dotted .test-utils.ts and .test-utils.tsx paths through the existing build-input owner. Preserve runtime support inputs and extend the existing build-stamp regression.

The controlled prepared test-utility-edit workflow at db793644 improved from 67.205s to 27.870s mean wall time. Current-source correctness and changed-file gates remain pending in the draft PR.
2026-10-02 10:10:28 -07:00
Peter Steinberger
b5a41c2001
perf(plugins): share host code identity for bundled TypeScript plugins (#163639)
Bundled plugins only shared the host loader when their entry was compiled
JavaScript, so a source checkout captured all 87 bundled packages (copy, hash,
and dependency materialization) on every prepared model runtime publication:
79.5 s of plugin discovery per agent turn, which exceeded the 120 s budget on
a loaded host. Bundled plugins now take the shared host loader regardless of
entry extension, the edited-code warning keys on the canonical export so it
survives loader interop wrappers, and the docs describe source and compiled
bundled identity together.

Discovery for the live embedded-runner case fell from 79.5 s to 12-13 s and the
case from ~100 s to ~25 s on the same host. Editing a bundled plugin's
TypeScript source now needs a Gateway restart, matching compiled bundled code;
installed, external, workspace-path, and standalone plugins keep captured
source reload semantics.
2026-10-02 17:05:16 +00:00
Peter Steinberger
f8015dfe3f
test(agents): align provider-error assertions with friendly copy (#163642)
Fix red main after #163381 changed friendly provider-error copy. Align five expectations with the existing connection and model-not-found formatting owners while preserving required-answer finalization, permanent WebSocket failure, and model-catalog lifecycle assertions. No production changes.

Proof: provider-error 19/19 and model-dispatch 3/3 on Node 24.21.0 and Bun 1.4.3; changed-file checks and git diff --check passed; P2 autoreview scoped-clean; exact-head ClawSweeper found no actionable defects.
2026-10-02 17:04:05 +00:00
Peter Steinberger
a324281c67
fix(test): stop run-tsgo worktree fixture from staging all of scripts/lib (#163322)
The linked-worktree fixture copied, committed, and checked out the whole
scripts/lib directory (490 files with the top-level scripts), so its
`git add .` exceeded the 10 s spawnSync budget on loaded hosts before any
wrapper behavior ran. Commit only the wrapper's runtime import closure
(29 files), computed by collectRuntimeImportClosure, plus the two files
the CLI shim loads by path (run-tsgo.mts and tsx.mjs).

Interleaved A/B at load 46-78: git add 36.2 s -> 3.0 s median, worktree
add 16.4 s -> 6.1 s, copy 15.3 s -> 1.6 s. Wrapper status/stdout/stderr
are byte-identical between the old and new fixtures; timeouts and
assertions are unchanged.
2026-10-02 10:01:58 -07:00
Peter Steinberger
2e99109a93
fix(doctor): migrate memory vectors one row at a time and keep native crash diagnostics (#163640)
A 2026.9.5 to 9.7 candidate Doctor died after about five minutes in "Checking data migrations" with a native stack through node::sqlite::DatabaseSync::Exec, and the recorded failure kept only an adjacent plugin warning (#163531). The memory schema storage migration called its UDF in bulk and retained every row embedding JSON in the JavaScript heap until the native call returned, which exhausts the heap on large legacy embedding caches; it now validates and converts one memory vector at a time inside the same transaction, preserving row identities, 64-bit rowids and stored text. Candidate validation now records a signal termination with its phase, fatal header and a bounded stderr tail in the update-run record and report instead of letting an unrelated warning take precedence. Thanks @fenglanhua for the stack.

Refs #163531
2026-10-02 09:58:45 -07:00
Peter Steinberger
0c85846ff8
refactor(reef): stop reconstructing historical delivery bindings (#163205) 2026-10-02 09:58:08 -07:00
Peter Steinberger
5ab66a5fe4
fix(ci): run Telegram skill tests when a PR changes only skill test files (#163328)
The Telegram userbot skill's node:test (*.test.mjs) and Python (*.test.py)
files are not Vitest-routable, so aggressive PR selection drops them as
direct targets. Their only CI owner is the Vitest wrapper
test/scripts/telegram-e2e-userbot-skill.test.ts, which the policy watch
selected for 20 named non-test scripts only. Test-only skill PRs (e.g.
#162968) and later scripts (reply-policy-*, telegram-runtime) planned
nothing in either selection mode.

Watch the skill's whole scripts/ directory, the agents/openai.yaml the
wrapper parses, and the fixture it loads by URL. The wrapper stays in the
release-only core-tooling family; it now also runs on PRs that touch the
skill, the only PRs that can break these self-contained scripts.
2026-10-02 09:55:09 -07:00
Jacob Tomlinson
d20ba7392c
test: preserve Gateway storage in composed worker fixtures (#163637) 2026-10-02 16:51:41 +00:00
Peter Steinberger
5b13ede5ea
fix(test): 20 more suites prepare compiled worker subprocesses inside their first test (#163554)
* test(core): split oversized subprocess consumer suites

Separate CLI lifecycle, Gateway startup, command dispatch, and bare-root
flows; media reads and storage; catalog metadata and hosted persistence.
Prepare workers during collection only for the six observed consumers.
Keep all 221 cases, assertions, and fixture initialization order; the
exit-only and catalog metadata files remain declaration-free.

Prune the two split baselines and one already-stale baseline entry.

Validation: 221 passing cases; six collection loads and two none results.
Changed-file formatting/lint, affected tsgo graphs, both line-cap ratchets,
and diff checks pass. The global changed-path typecheck remains blocked
by the inherited agents-other root budget (724/720); affected graphs pass.
The review's baseline concern was rejected against the native stale-entry
check and direct lint of the unchanged target file.

* fix(test): collect extension subprocess dependencies

Move Anthropic's real process helper acquisition to collection while
retaining vi.importActual and its mock reset behavior. Move DeepInfra
and xAI's one-time subject imports and mock setup to collection, keeping
their real HTTP transport and negative SSRF assertions intact.

Validation: all 20 cases pass and first declaration loads are collection;
all case names/counts are unchanged. Formatting and extension test types
pass. The normal extension lint lane was blocked while preparing Plugin
SDK declarations by its existing 300000 ms timeout; no timeout or guard
was changed. The final candidate received the scoped P2 review recorded
with the preceding core split commit.

* test(plugin-sdk): preload compiled subprocesses for extension tests

Move worker preparation into collection through a repo-local, non-production
SDK subpath. Let Codex app-server setup preload declarations while keeping
worker-cpu imports after file mocks; preserve per-test imports and assertions.

Register private source and declaration aliases without adding package exports
or production artifacts. Remove unused CLI fixture exports and reuse the alias
normalization owner so the existing dead-export and line-cap gates pass.

* fix(test): preload compiled subprocesses for newly screened suites

* fix(test): preload remaining screened subprocess declarations

Move compiled subprocess preparation out of test and hook deadlines in six confirmed declaration consumers. Preserve lazy imports, mock ordering, and assertions; keep the shared meeting plugin helper unchanged so platform-scoped loading retains its existing order.

* style(test): keep Parallel suite separator

* fix(test): preload compiled subprocesses for the remaining screened suites

Finish the compiled-subprocess deadline screen that #163254 left at its
direct-signal tier. Twenty more suites reached their first
compiled-subprocess declaration inside a test body, so the invocation's
worker preparation ran inside that test's deadline.

Nineteen suites hit the declaration through a production-owned lazy
import (lazy runtimes, lazy CLI command loading, lazy SDK media, secret
and schema loaders) and take the existing preload: the core module for
src suites, openclaw/plugin-sdk/compiled-subprocess-testing for
extensions. control-ui-assets moves its in-test vi.importActual of the
real exec module to collection instead.

* fix(test): preload compiled subprocesses for the Discord state migration suite

Main's #163329 rewrote this suite and retired the lazy thread-binding
import that the first commit targeted, so the merge took main's file.
A re-screen of the merged tree still recorded its first declaration load
inside the first test: migrateLegacyState now reaches it through the SDK
doctor-migration plan adapter's lazy state-migrations import. Restore the
preload; the suite loads the declaration at collection again.
2026-10-02 09:49:00 -07:00
ooiuuii
555ac8413e
fix(telegram): recognize images sent as documents (#141292)
Fixes #141291.

Telegram documents whose downloaded bytes are a PNG or JPEG are now treated as images, so a vision model sees an image sent as a file. PDFs and text documents stay documents.

Proof: real Telegram Test Server with real gpt-5-mini. A PNG sent as a document reached the model as 0 image parts on main (the model said it could not open it) and as 1 byte-identical image part with this change (the model described the red square and its text). A PDF sent as a document stayed a document on both. Regression tests fail on main and pass here.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-10-03 00:48:48 +08:00
Vincent Koc
62650e4c77
test(agents): stop pinning legacy tool-result wording 2026-10-02 18:44:53 +02:00
Vincent Koc
af0390499c
refactor(config): remove unused metadata timestamp argument (#163622)
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-10-02 16:44:41 +00:00
Peter Steinberger
bc4afcf0af
test(ui): remove low-value tests (batch d158) (#163632)
* test(ui): deslop s1088 tests

* test(ui): deslop s1104 tests

* test(profile): deslop s1109 tests

* test(ui): deslop s1106 tests

* test(cron): deslop s1101 tests

* test(usage): deslop s1112 tests

* test(ui): deslop s1105 tests

* test(plugins): deslop s1108 tests

* test(talk): deslop s1099 tests

* test(ui): deslop s1111 tests
2026-10-02 16:39:41 +00:00
Peter Steinberger
6cd18ec96d
refactor(agents): deslop subagent retirement and reactivation paths (#163614)
Compute the "owes a completion" predicate once in retireSupersededSubagentRun
and drop the cohort array whose only remaining use was cohort.includes(entry).
Collapse the three names and repeated live lookups in
reactivateCompletedSubagentSession, keep the prepared announce result instead
of an optional callback sentinel, and give the attachments-removal policy one
exported owner next to safeRemoveAttachmentsDir, replacing four inlined copies
and a protected method. No behavior change.
2026-10-02 09:31:24 -07:00
Vincent Koc
6834c5fe96
fix(codex): authorize canonical sandbox reads (#150731)
* fix(codex): authorize canonical sandbox reads

* fix(sandbox): integrate canonical read authorization with current main

Preserve source-bearing reads and current filesystem owners while binding policy checks to admitted paths. Keep identity-validation failures distinct from missing paths.

Local integration checkpoint for PR #150731. Remote tests and changed checks remain pending; this commit is not landing qualification.

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-10-03 00:26:11 +08:00
Peter Steinberger
3562b697df
test(update): inject handoff cancellation at the worker-owned sentinel seam (#163626)
update-command-handoff cancel and cancel-output-first failed on main (exit 75 instead of 23): d8b18a62a3 moved sentinel publication into the worker, so the caller-only fault injection missed it and production correctly reported the transfer exit. The shared preload support now targets the caller and its worker while allowing helper cancellation publication. Test-support only.

Refs d8b18a62a3
2026-10-02 09:21:21 -07:00
Josh Avant
721501021b
test(qa): stabilize completion policy continuation (#163398) 2026-10-02 11:19:23 -05:00
Dallin Romney
bfeca6756c
fix(release): apply 2026.9.8 live shard waivers (#163621) 2026-10-02 16:17:01 +00:00
Dallin Romney
b2c302324f
test(gateway): use canonical steer fixture config (#163618) 2026-10-02 16:15:12 +00:00
Peter Steinberger
fcdd870217
fix(watch): complete cache migration and ignore unchanged invalidations (#161543)
Complete the fs-safe watcher migration for catalog and usage-template caches, with non-persistent subscriptions so one-shot commands exit naturally. Preserve atomic-save and missing-root recovery behavior.

Re-read selected sources after undetailed invalidations and restart the dev child only when content changes. Keep unchanged Skills coverage available, and honor CHOKIDAR_INTERVAL for forced polling and automatic fallback. Remove redundant native transports and transport-specific fixtures.

Completes #159226 and supersedes #158182. Dependency pins remain owned by main.

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-10-02 09:14:04 -07:00
Josh Avant
d0f7dcca06
fix: prove Codex native workspace execution in QA (#163427)
* test(qa): prove Codex native workspace behavior

* fix(qa): validate native workspace receipts

* fix(qa): preserve native command narrowing

* fix(qa): isolate native workspace proof sessions

* docs(qa): align native write criterion

* fix(codex): project rejected exec fallback as bash
2026-10-02 11:09:56 -05:00
Vito Cappello
32e30e59d9
fix: let long Claude shell jobs release chat turns (#161780)
* fix: let long Claude shell jobs release chat turns

* fix(agents): preserve native shell for node exec defaults

---------

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
2026-10-02 12:01:23 -04:00
Peter Steinberger
e4dc2512b8
refactor(state): move transient disposal to the database lifecycle owner (#163426)
* refactor: split oversized agent and backup files

Move transient agent database disposal into its existing lifecycle owner
while preserving the database facade used by probe and migration callers.

Move backup catalog redaction and agent creation persistence checks to
focused test owners, preserving assertions, cleanup, and protected coverage.
Bring three files below the strict local max-lines limits without changing
GitHub Actions advisory limit policy.

* test: isolate catalog reader retention from fleet refresh

Use individual publication and the existing catalog-worker observation owner
for the agent database cleanup proof. Preserve four agents, one shared worker,
all deletion/liveness assertions, and a live survivor-reader prerequisite.

Owner tracing showed background catalog renewal closing pooled readers during
the old assertion. The focused case, targeted types/lint, formatting, and
independent P2 review pass with the final two-file fixture change.

* test: drain shared state before usage fixture teardown

Join shared-state worker cleanup after agent database retirement while each
usage fixture's environment and temporary root are still valid. Preserve all
five case bodies and preload assertions.

CI exposed stale temporary database references; the exact original shard
passed locally. The bounded cleanup change passes all five cases, targeted
types/lint, formatting, and independent P2 review.
2026-10-02 16:00:20 +00:00
Vincent Koc
3c5010ebfa
fix(agents): preserve actionable public failure guidance (#163538) 2026-10-02 22:53:47 +07:00
Peter Steinberger
7f232d4e64
refactor(sessions): move watch and version operations into workers (#163513)
* refactor(sessions): move watch and version operations into workers

* fix(sessions): preserve caller authority across worker watch operations
2026-10-02 08:51:58 -07:00
Peter Steinberger
f02d16e758
fix(i18n): stop parallel native PRs from conflicting in the string inventory (#163330)
The generated native inventory stored one line per string with every
extraction site inline, sorted alphabetically. Two PRs reusing a string
("Retry") both rewrote its line, and a feature's new strings ("Group by",
"Group chat") landed in the same insertion gap, so parallel native PRs
conflicted in apps/.i18n/native-source.json and needed a rebase plus a
full CI rerun.

Inventory v3 writes one line per extraction site, clustered by source
file, with clusters ordered by a hash of the path so new sibling files do
not share a gap. Each row's position depends only on its own content, so
independent edits merge cleanly (including GitHub's server-side merge)
and the merged text equals a fresh baseline. The new
scripts/native-i18n-inventory.ts owns serialization and parsing; the
generator, Android/Gradle and Apple readers migrate to it together and
receive the same entries in the same order as before.
2026-10-02 15:48:17 +00:00
Peter Steinberger
14fd53f8f6
test(ui,state): remove low-value tests (batch d157) (#163609)
* test(ui): deslop s1094 tests

* test(ui): deslop s1090 tests

* test(ui): deslop s1083 tests

* test(ui): deslop s1098 tests

* test(ui): deslop s1086 tests

* test(ui): deslop s1089 tests

* test(ui): deslop s1093 tests

* test(ui): deslop s1085 tests

* test(state): deslop s975 tests

* test(ui): deslop s1103 tests
2026-10-02 15:46:18 +00:00
Peter Steinberger
22f4d8ffbf
fix(update): keep registry mutations and Doctor repairs working when update-history reconciliation cannot run (#163608)
Every registry-mutating CLI command (doctor, doctor --fix, plugins install, plugins registry --refresh) failed for a non-root service user with "Update history reconciliation could not complete: spawn /usr/bin/node EACCES ... free disk space/quota or set XDG_CACHE_HOME", and the same path made a 2026.9.6 to 9.7 upgrade unrecoverable (#163547). The native snapshot launcher no longer forces a redundant chdir into an inherited working directory the service user cannot enter, and the Doctor history owner no longer aborts repairs on an update-history read failure: the failure is classified by its real errno class (executable not runnable vs. disk space) and persisted as a warning in the update-run record while the mutation proceeds; unsettled process-cleanup errors still block. Thanks @ringbe-cyber for the diagnosis.

Closes #163547
2026-10-02 08:45:39 -07:00
Dallin Romney
2e3544b40b
fix(qa): classify transport readiness failures (#163602)
* fix(qa): classify transport readiness failures

* test(qa): narrow captured readiness failure
2026-10-02 15:43:40 +00:00
Peter Steinberger
8bb49fa67a
test(update): load Doctor delegation fixtures before the writer-readiness deadline (#163610)
update-command-doctor-delegation flaked on main hourlies (3 cases, 37020939466): source loading exhausted the fixture deadline before the standalone Doctor writer reached readiness, so the settle-after-reject assertion observed a null record. Production already awaits custody settlement; the shared compiled-fixture owner now supplies every import up front. Test-support only.

Refs #162614
2026-10-02 08:40:24 -07:00
Peter Steinberger
eb50c3a61b
fix: keep Bun plugins on their native loader when module hooks exist (#163539)
Keep Bun plugin resolution on its native/Jiti and Bun.plugin path even when Module.registerHooks exists. Share one runtime predicate across all five loader decisions; Node keeps its hooks path. Preserve Bun's independently evolving require.resolve.paths capability through the existing legacy Jiti control, and document runtime ownership.

The real throwing-hook regression fails before and passes after. All 282 plugin files match old Bun exactly, historical interop passes 68/68 on all three runtimes, and candidate plugin hooks fall from 177 to zero. Old-Bun median load time is unchanged; the residual 2.84% candidate-binary cost is assigned to the fork's registerHooks landing by the maintainer. Production LOC is neutral.

P2 review is scoped-clean and exact-head CI37022559011 passes. The inherited local environment-count check remains477/476 on main; no variable or budget change is included.
2026-10-02 15:37:51 +00:00
Vincent Koc
1b8d4594fe
fix(codex): update managed runtime to 0.160.0 (#163560) 2026-10-02 22:36:54 +07:00
Dallin Romney
35126bbe59
fix(qa): retain Telegram proxy failure facts (#163598) 2026-10-02 08:36:47 -07:00
Dallin Romney
93e27de58f
fix: macOS release upgrade checks fail during updater recovery (#163580)
* fix(release): canonicalize macOS upgrade temp paths

* test(release): canonicalize macOS temp fixture
2026-10-02 08:35:42 -07:00
Dallin Romney
b7eac4df09
fix(e2e): repair Feishu survivor config recipe (#163604) 2026-10-02 08:35:25 -07:00
Peter Steinberger
6c8c06fec3
refactor(gateway): scope Mention Inbox scheduling and disposal (#163229)
Move Mention expiry and retry scheduling into an Inbox-owned scheduler scope. Fence new work when shutdown begins and join descendant work outside callbacks, preserving sibling schedules and durable Mention state.

Fix the cold-reopen fixture to await Inbox/database disposal before reusing its parent scheduler. Exact-head CI, original-code negative controls, original shard order, focused tests and the published 2026.9.7 update with authenticated public SDK reads pass on Testbox. The unrelated expired plugin-registry guard remains recorded with its owning main fixes.
2026-10-02 08:33:46 -07:00