Complete managed Gateway upgrades after Node prefix changes while preserving the verified service during preparation and recovering only owned failed activations.
Keep requester/executor and original/candidate ownership through native children; retain uncertain cleanup and original failure outcomes. Source and isolated native component checks are documented in the canonical PR. The wider first-hop installer and other platform journeys remain separate program work.
Closes#107930. Canonical PR history retains the original contributor commits; repository-supported squash preserves explicit contributor credit.
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Dallin Romney <dallinromney@gmail.com>
Windows installations can now recover automatically when winget, Chocolatey, or Scoop fails or leaves an unsupported Node.js runtime. Guarded package-manager attempts warn and continue through the remaining methods to the existing elevation-free portable Node installer. Runtime validation still gates OpenClaw installation.
The installer remains the sole owner of runtime provisioning. Updated Windows documentation and regression coverage describe and protect failure fallthrough, successful recovery, and final refusal when no usable runtime can be provisioned.
Validation: all 99 exact-head checks completed without failures, including Windows installer CI and openclaw/ci-gate. The isolated Windows recovery trace exercised real portable download, extraction, PATH recovery, and runtime/SQLite validation after an injected Chocolatey failure. Codex review was scoped-clean; ClawSweeper reported no actionable findings or Rank-up moves.
Related: #133869
Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.
Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.
The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.
The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.
Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.
Refs #144758#144901#144890#143292#146637#145252. Preserves the activation boundary from #147019.
* fix(runtime): gate node:sqlite on a NUL round-trip capability probe
Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465#140672.
* fix(runtime): expose capability diagnostics through doctor
Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.
* fix(update): preserve target Node version requirements
* fix(install): remove unused Node major probe state
* feat: offer Node.js updates when the CLI runtime is incompatible
* fix: include Node runtime recovery in duplicate scans
---------
Co-authored-by: Morrow <morrow@bluedot.it.com>
* fix(runtime): require Node builds with lossless SQLite reads
* fix(runtime): preserve upgrades and guard sealed workers
Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.
* test(runtime): use typed process exports in worker fixture
* test(runtime): align installer fixtures without growing test shards
* test(runtime): align release and guest runtime fixtures
* fix(test): canonicalize Windows temp roots for Node 24
Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.
* test(ci): run Windows temp-root regressions in the native lane
Match local tarball lifecycle approvals to npm's normalized absolute file
identity across the installers and updater. Preserve directory links and the
shipped npm 11 advisory comma-path behavior without overriding npm policy.
Bind the mandatory npm 12 acceptance job to the already verified prepared
plugin registry so unpublished candidate dependencies do not require early
publication. Keep source, manifest, artifact and producer identities intact.
Update installer documentation and regression coverage, including the
Git-source-to-packed-tarball update path and its observed version outcome.
* fix(install): use basic parsing for MinGit download
* test(install): cover MinGit basic parsing switch
* test(install): exercise MinGit parsing in both Windows shells
Observe basic parsing through the executable archive fixture and run that
existing owner case in Windows PowerShell 5.1 as well as PowerShell 7.
Keep the existing multi-root extraction and temporary cleanup checks.
Co-authored-by: ben.li <li.yang6@xydigit.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: ben.li <li.yang6@xydigit.com>
## Problem
A pnpm 11 global update from OpenClaw 2026.7.1-2 to 2026.8.1 fails verification and rolls back. The 2026.8.1 package puts `openclaw-install-guard` inside `dist/`, but the old updater treats every uninventoried `dist/` file as invalid.
## Root cause
Package lifecycle state was stored inside the closed `dist/` inventory. That made a valid pending lifecycle marker look like package corruption to an older updater.
## Fix
- Store pending lifecycle state at package root as `.openclaw-lifecycle-pending`.
- Let postinstall remove the marker only after all lifecycle work succeeds.
- Use one lifecycle completion owner from the updater, `dist/index.js`, and `openclaw.mjs`.
- Keep the lifecycle lock valid beyond the full preinstall and postinstall timeout budget.
- Keep temporary recovery support for the 2026.8.1 `dist/openclaw-install-guard` path.
- Keep source package preparation and worker package generation aligned with the new marker contract.
## Product proof
- Red: a published 2026.7.1-2 pnpm 11 install rejected the published 2026.8.1 package with `unexpected packaged dist file dist/openclaw-install-guard`, exited nonzero, and remained on 2026.7.1-2.
- Green: the built candidate passes the old-updater upgrade path, the pnpm 11 lifecycle-repair path, a forced postinstall failure and retry, and native npm controls.
- Anti-cheat: the proof checks the installed CLI version before and after the update.
## Validation
- `node scripts/run-vitest.mjs src/infra/package-lifecycle.test.ts src/infra/package-update-steps.pnpm11-guard.test.ts src/index.entrypoint.test.ts`
- Focused lifecycle, updater, tarball, postinstall, inventory, and entrypoint suites: 176 tests passed.
- Exact-head lifecycle lock suite: 4 tests passed, including the old 20-minute expiry boundary.
- Remote core and scripts checks passed.
- `git diff --check`
- GitHub CI is the full release and platform gate.
## Scope
- Production and release-tooling delta: +370/-162, net +208.
- Test and CI support delta: +370/-84, net +286.
- The production growth adds the shared lifecycle owner, crash-safe retry marker, and concurrent-launch lock. It removes the updater-only lifecycle sequence and keeps the closed `dist/` verifier unchanged.
- Sibling coverage: updater, package launcher, legacy package entrypoint, installers, tarball validator, worker bootstrap package, and Docker package preparation.
## ClawSweeper
- No actionable code findings.
- Rank-up skip: the package-upgrade trace came from an internal isolated runner and is not suitable for a public log attachment. Exact-head GitHub CI and the focused regression commands above remain the public proof.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
* fix(installer): isolate source bootstrap from ambient pnpm
Select temporary checkout-pinned launchers for source installs and nested builds without changing global tools. Preserve caller context and document the Corepack prerequisite and first-hop update constraint.
* test(installer): exercise native Windows pnpm bootstrap
Cover scoped Corepack and exact npm-prefix bootstrap, child context, failure cleanup, and caller environment restoration under native PowerShell. Include the installer owner tests in the existing Windows CI shard and test-only routing.
* fix(installer): preserve native Windows argument and environment boundaries
* fix(updater): preflight the fetched pnpm pin before checkout changes
* test(installer): normalize native wrapper publication paths
* build: migrate tooling and source installs to pnpm 12
Pin the verified native toolchain without changing application dependency
versions. Preserve the existing release-age policy explicitly and separate
package-manager lock metadata from the application dependency graph.
Use exact checkout pins for bootstrap and rollback, approve only the native
pnpm installer where npm requires it, and retain global install ownership
without equating the CLI major to the storage layout. Verify the Docker
runtime toolchain offline as its non-root user.
Remove duplicate bootstrap paths and obsolete prune input, update native
CLI flags and regression fixtures, and preserve UTF-8 in macOS Bash
installer NDJSON output.
* fix(build): isolate production dependency installs for pnpm 12
Build production dependencies from the same frozen manifest inputs instead
of pruning the inherited development tree. pnpm 12's native hoisted
importer cannot rename lower-layer OverlayFS directories during pruning.
Preserve native addon outputs, workspace builds, and offline non-root
Corepack use while deleting the obsolete production-store seeder.
Exercise runtime assembly and explicitly consent to the local agent-plugin
E2E fixture under the current plugin capability contract.
Validated full Matrix image and offline non-root runtime, focused Docker
regressions, full checks with test types and architecture, docs, real
agent-plugin gateway E2E, and isolated Codex autoreview.
* test: align package smoke with pnpm 12 global installs
* test: follow native pnpm artifact approval in distribution guard
* test: modernize pnpm fixtures for v12
* test: align rebased update fixtures with pnpm 12
* test: retain sanitized upgrade restart diagnostics
* test: expose CI navigation failures and register diagnostics
* test: retain post-core outcomes and plugin artifact identity
* chore(tooling): group upgrade diagnostic entrypoints
* fix(update): support native pnpm global installs and source links
Qualify local source and archive specs, carry verified global ownership through pnpm configuration, and verify intentional checkout links with shared runtime-readiness checks. Preserve strict packaged-install verification and manager ownership safeguards.
Verified the production updater with pnpm 11.22 and 12 using default and custom roots, source links, and tarball updates.
* test: preserve survivor diagnostics after service sealing
Promote incomplete exit-zero runs before failure capture and exercise the sealed-service manager fixture without inventing successful child exits.
* fix(update): preserve legacy pnpm global ownership
Carry the verified root and bin through both pnpm and npm configuration dialects after original-environment probes. Real pnpm 10 custom-root updates and pnpm 11/12 source and tarball matrices pass without redirecting the caller or weakening ownership checks.
* test(update): verify wizard consent through checkout handoff
Use the prepared checkout and fresh-process finalization boundary introduced by the updater repair. Preserve explicit consent forwarding before and after the wizard subcommand without assuming plugin callbacks run in the old process.
* refactor(update): validate checkout build metadata records
Use the canonical record coercer instead of carrying an unchecked assertion into the shared runtime verifier. Remove the now-unused grandfathered assertion entry; no allowance is added.
* docs(sandbox): document standalone common-image inputs
* test(packaging): account for required native prebuilds
Align installer and release size budgets at 235 MiB for the required native payload added on main. Keep both loader layouts, upstream binaries, explicit overrides, and missing-data rejection intact. Exercise actual defaults and the one-byte boundary. Retain bounded stderr diagnostics for the intermittent Bun signal test without claiming a production signal fix.
* test: align refreshed installer fixtures with pnpm 12
* fix(test): share Bun smoke force-kill ownership
Record the successful force-kill once across the timer and post-close drain. Native Darwin traces reproduced both duplicate-signal orders; genuine permission failures and uncleared groups still fail without extending deadlines.
Move llama.cpp chat and local embeddings onto a verified externally managed llama-server runtime. Remove the in-process native runtime, forked embedding workers, and node-llama-cpp dependency while preserving guided setup, local GGUF models, tool-capable agent runs, diagnostics, and operator docs.
* fix(install): Windows installer surfaces doctor migration failures
Invoke-OpenClawCommand ignored the child exit code, so a failed
'openclaw doctor --non-interactive' still printed '[OK] Migration complete'.
The wrapper now throws on nonzero exit and Run-Doctor reports the failure
with the exact command to rerun instead of claiming success.
* chore: re-fire CI
* chore: re-fire CI against fixed main baseline
* fix: clarify SQLite version error message to prevent user confusion
The error message "3.44.6+" was misinterpreted by users as meaning "3.44.6 and above",
when it actually means "3.44.6+ for the 3.44.x series only". This commit clarifies the
error message to explicitly state that only specific patched versions (3.44.6+, 3.50.7+,
and 3.51.3+) are safe, and that SQLite 3.46.1 is not among them.
Changes:
- Update error message in src/infra/node-sqlite.ts to clarify version requirements
- Update test expectations in src/infra/node-sqlite.test.ts to match new error format
- Fix unnecessary template literal expressions flagged by oxlint
The code logic remains unchanged - SQLite 3.46.1 is correctly rejected as unsafe.
* fix: clarify SQLite version error message to prevent user confusion
The previous error message stated '3.44.6+' which users misinterpreted as
'3.44.6 and above', leading to confusion when versions like 3.46.1 were rejected.
The new message explicitly states '3.44.6+ in the 3.44.x series' and
'3.50.7+ in the 3.50.x series' to make it clear that only specific
minor version series received the WAL-reset bug fix.
This matches the SQLite team's actual fix announcement which only
backported the fix to 3.44.x and 3.50.x series, plus 3.51.3+.
* fix(sqlite): align unsafe version diagnostics
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
Replays #84749 because the contributor fork branch became conflicted and was no longer maintainer-writable.
Co-authored-by: TeodoroRodrigo <rodrigoteodoro.90@gmail.com>