Commit graph

64 commits

Author SHA1 Message Date
RoboClaw
bb2d479926
feat(browser): unify local Chrome setup across desktop and terminal (#152057)
* feat(browser): unify local Chrome setup across desktop and terminal

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* feat(browser): unify local Chrome setup across desktop and terminal

OpenClaw-Publication: d19e865e-b5a0-4c70-8876-c1662f6e7ef2

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* chore(linux): format Chrome setup fixture

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* feat(browser): keep desktop Chrome setup local and preserve pairing

Delegate Windows registration to the shared native management owner, preserve
released native bridge compatibility and saved launcher profiles, and integrate
serialized desktop setup through isolated local runtimes.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): repair native setup CI contracts

Keep Windows installer dependencies acyclic, validate Unicode within the
package library target, and remove unused private exports. Require all
eight packaged native-host proof cases and update lazy CLI inventory.
Apply native Swift formatter diagnostics without changing behavior.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(cli): account for plugin-owned browser extension catalog

Keep the core-only registration invariant aligned with the Browser plugin
owner already exercised by its lazy registration tests.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(macos): retain released Chrome bridge request expectation

Align the native bridge test with the shipped contract1 request retained
by the canonical setup owner, and reject extra legacy payload fields.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(tui): give command handler harness a unique export

Rename the shared TUI test helper and both consumers to avoid the
Gateway placement harness export collision. No alias or guard waiver.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* chore(sdk): allow canonical browser config path resolver

Apply the approved single public-export and callable allowance for
resolveConfigPath. Preserve canonical pre-config path ownership and
all other SDK surface checks.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): preserve desktop setup selection and supported actions

Keep native automatic setup selector-free and resolve saved local browser
selection through the canonical setup owner before installation. Respect
Mac action advertisements and the released legacy install projection in
the Apps card, and document the public config-path resolver contract.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(auth): retry model selection after concurrent credential refresh

Adopt upstream PR #152426, commit 32298b10f6, without changing its five source files.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test: preserve native setup selection and await dashboard document

Match the selector-free native CLI arguments exactly and preserve a saved work-profile result. Wait through the existing document-readiness owner only at the quota test browser-proof boundary, after auth assertions.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): avoid preloading already imported modules

Remove exact direct static JavaScript imports from lazy preload tables using the emitted build graph. Preserve HTML, lazy-only JavaScript, CSS, and locale hints. Source-exact CI merge reproduction drops startup gzip from 363283 to 362968 bytes without changing budgets. Add a real emitted-bundle regression.

Apply rustfmt layout to the native Chrome selector-free expected arguments.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: preserve Chrome profiles and attachment follow-up branch binding

Let the TUI canonical setup controller retain its saved browser profile and project only a bounded returned name. Align both native first-run fixture expectations with selector-free setup.

Join pending chat history before the composer task handoff can expose an admitted attachment to restored-outbox delivery. Preserve idempotency, attachment custody, restored delivery semantics, and all existing assertions and timeouts. Add a deterministic regression reproduced on the exact failed CI merge and its main parent.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(state): adopt canonical worker-custody fixture repair

Adopt src/plugin-state/plugin-state-worker.test.ts byte-for-byte from upstream bfec65a2a0 (#152456).

The former fixture held its late competing owner until after awaiting off-thread acquisition. Preserve that overlap, assert continued host authority checks and noncompletion, release custody, then assert the original result and persisted state. No production locking, guard, deadline or outcome assertion is relaxed.

Both prior failures reproduced on the exact CI main parent with independently installed frozen dependencies and Node 24.19.0. All 12 repaired file tests, selected state-logging types, scoped typed lint and fresh P0-P2 review passed.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): retain saved Windows setup profiles

Recover configured extension profiles through bounded serial read-only C# inspection. Select only independently validated current matching descriptors, confirm the selected generation before effects, and leave the single mutation under the existing C# owner. Preserve POSIX behavior, existing manual relay verification and explicit same-profile repair.

Missing descriptors, runtime/origin drift and unknown or changing observations fail closed without automatic mutation. Keep raw management facts private and populate the existing browserProfile field only from validated binding metadata. No ABI, schema, SDK, configuration flag or registry/activation owner change.

29 actual CLI/controller/Windows-adapter boundary cases plus sibling coverage: 94 tests pass. Canonical changed checks, full production build and fresh independent P0-P2 review passed. Actual C# native proof remains separately coordinated.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): preserve saved profiles after POSIX bundle relocation

Separate validated native registration ownership from supported origin-migration readiness. Recover the profile only after full private manifest and exact launcher validation; preserve the existing one-slot migration rule and all unsupported-origin, ACL and foreign-host refusals. Fail closed before selector-free installation when the saved selection cannot be proved.

Extract the unchanged shared origin helpers into a cohesive sibling to satisfy the existing line-cap guard without waivers. Windows admission, ABI and selector behavior remain unchanged.

Actual Linux/Darwin CLI-to-filesystem relocation regressions: 18 failures on original production, all 22 cases repaired. Preserve the private relay key and inode, config, Chrome preferences, work relay19444 and explicit-profile intent. 137 focused tests, eight real POSIX native-host E2E cases, canonical changed checks, full production build and fresh P0-P2 review passed.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): retain input handoff through the shared outbox owner

Remove the superseded pending-history no-yield workaround after main introduced foreground submission custody in the shared outbox owner. Restore chat-submit-guard.ts exactly to pinned main cc7 rather than retaining competing timing policies. Keep passive drains fenced while the input task yields.

Preserve the retained history regression with explicit MessageChannel admission, no passive send before resume, and the same terminal leaf, idempotency key, attachment bytes and exactly-once assertions after completion. Original composed source fails all five focused cases; the repair passes 67 handoff/attachment cases and 20 real Chromium cases in the canonical secretless network-none runner. Canonical checks, UI build/performance and fresh P0-P2 review pass. No assertion, timeout, origin or proxy-policy weakening.

Browser POSIX/Windows repairs remain byte-identical to accepted255f. The failed e40e CI receipts remain preserved; fresh exact-head CI and parent handoff are still required.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(tasks): preserve reads across native event finalization

Hand joined event publication to its exact native successor after the native
flow and observer publication frame completes. Keep worker settlement and
cleanup, reversible claim transfer, current-authority and ABA checks, and
post-commit delivery in their existing owners without replaying writes.

Cover pre-result and readback finalization, native and reentrant successor
chains, rollback, failed publication, delivery, and terminal activity cleanup.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(ui): retain rail baseline geometry on readiness failure

Keep the exact existing readiness predicate, fixtures, case inventory, assertion and timeout. When the predicate is false, retain synthetic marker identity and numeric geometry so hosted CI can distinguish scroll, visibility and viewport failures.

This is diagnostic evidence, not a repair or waiver of the unresolved rail failure. Local rootless browser infrastructure is unavailable; the existing hosted CI lane will verify the reviewed task-publication repair and collect meaningful rail evidence. Canonical changed checks and P0-P2 diagnostic review pass.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* docs(linux): describe saved-profile Chrome setup selection

Match the selector-free adapter argument vector and its regression test. Address the fresh P3 review finding without changing runtime behavior. Markdown syntax and diff checks pass; the generic formatter excludes this subtree.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(transcripts): join configured startup before cleanup faults

Observe and await the real startTranscripts promise through a narrow call-through spy while retaining the configured service entry point and real SQLite/provider work. Bind the await to the existing test lifetime instead of charging startup to the subsequent short active-map poll.

Gate provider return after persisted utterance to prove readiness does not settle early; retain both missing/unreadable row injections and all cleanup, private-source, lifecycle-token and summary assertions. Cover real startup rejection explicitly. No production change, timeout increase, retries or broad module/storage mocks.

The deterministic ordering boundary fails with the old fire-and-forget readiness and passes with the real promise join. Final 39 tests across 3 files, canonical changed checks and full-owner P0-P2 review pass. This does not recover whether the historical CI startup was late or rejected.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(browser): preserve automatic desktop status inspection

Restore read-only Device-page inspection for current and released Mac bridges while keeping installation and verification explicit. Preserve the native filesystem prerequisite proof, split installer repair tests within the existing line cap, and remove the superseded constant export.

* fix(browser): preserve registered setup configuration

Require canonical setup to match an owned launcher's effective state and
config selection before installation or relay access. Preserve equivalent
implicit/explicit default selections and the saved launch context. Recheck
automatic profile selection before effects and the current manifest before
publication through the existing registration owner. Keep manual install
and relocation repair contracts unchanged.

Cover mismatched configs, legacy selectors, equivalent defaults, selection
drift, and actual bootstrap after refused setup. Restore the missing Command
import in the existing Unix-only companion CLI test.

Focused tests, types, lint, fresh review, clean package build and sealed Mac
ARM64 runtime proof pass. The separate historical clock-jump CI failure has
bounded replay evidence and remains documented without a speculative fix.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* fix(browser): keep setup registration types acyclic

Move the private registration status contract beside its context policy and
point both consumers at that owner. Remove the publication-module back-edge
without keeping an unused compatibility export.

The full architecture gate, extension production/test types, typed lint and
fresh independent review pass. Node's transformed JavaScript is byte-identical
for all three affected modules, so the existing runtime proof remains valid.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* test(linux): handle Chrome setup in desktop sharing fixture

Recognize the exact automatic Chrome setup invocation and require its native
no-respawn flag. Keep unknown-command rejection, selected-auth validation,
process-group ownership and joined teardown assertions unchanged.

The original fixture reproduces the CI rejection against the real Linux app.
The repaired fixture passes all nine checks against that same binary, with
five Chrome setup calls and five node starts and joined stops. Fresh review
is clean; production app behavior is unchanged.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

---------

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-22 06:28:29 -07:00
Vincent Koc
10b13070c4
fix(install): refuse unsupported FreeBSD source installs before setup (#151227) 2026-09-19 03:17:55 -06:00
thomas.szbay
d74b4a2a55
fix(install): bound curl connection setup with --connect-timeout 20 (#110657) 2026-09-16 15:59:19 -06:00
Vincent Koc
305bcbe12d
fix(install): preserve empty PATH search entries (#147249) 2026-09-14 03:46:26 +08:00
Vincent Koc
4d6ebf94e6
fix(install): preserve runtime links when Node validation fails (#147221)
* fix(install): preserve runtime links when Node validation fails

* fix(install): preserve relative runtime targets and empty aliases

* test(install): preserve runtime fixture tuple types
2026-09-14 03:17:04 +08:00
Peter Steinberger
290613f538
fix(update): derive update budgets from measured state instead of fixed literals (#145219)
Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.

Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.

The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.

The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.

Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.

Refs #144758 #144901 #144890 #143292 #146637 #145252. Preserves the activation boundary from #147019.
2026-09-13 09:41:59 -07:00
Peter Steinberger
58dce76576
fix(tests): isolate installer and Docker shell snippets (#146897) 2026-09-13 03:10:02 -07:00
Peter Steinberger
8c4ad0b2da
fix(macos): recover CLI setup from temporary directory permission errors (#146730) 2026-09-12 21:41:24 -07:00
Peter Steinberger
0d2c3a2292
refactor: share standalone installer test contracts (#146454) 2026-09-12 18:02:47 -07:00
Peter Steinberger
c22d12ede0
test: share installer git recovery fixtures (#145511) 2026-09-11 19:22:50 -07:00
Peter Steinberger
5c5a21087b
test: share installer git reference fixtures (#145368) 2026-09-11 16:12:14 -07:00
Jason O'Neal
cec6d16175
feat: offer Node.js updates when the CLI runtime is incompatible (#142742)
* feat: offer Node.js updates when the CLI runtime is incompatible

* fix: include Node runtime recovery in duplicate scans

---------

Co-authored-by: Morrow <morrow@bluedot.it.com>
2026-09-09 10:56:55 -07:00
Peter Steinberger
fe79d36c0d
fix(update): replace unsupported Gateway service Node runtimes (#143159)
* fix(update): replace unsupported Gateway service Node runtimes

Treat unsupported recorded Node versions as a required service refresh,
prefer the supported CLI runtime, and preserve existing force and ownership
boundaries. Report successful Node replacement through POSIX installers
without exposing incidental child output.

Cover launchd/systemd definition repair and the target-engine guidance
already corrected by #142322.

Refs #107930

* fix(daemon): replace missing Gateway service Node on install

Recover missing or non-executable recorded Node paths through the existing
supported-runtime selection and service install plan. Keep genuine probe
failures actionable with the recorded path and a force-install hint, and
recognize the missing-runtime notice in the POSIX installers.

Refs #107930
2026-09-09 08:26:48 -07:00
Peter Steinberger
299ea7c393
fix(scripts): run macOS tooling under /bin/bash and make the framework-merge fixture self-contained (#141884)
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures

Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.

Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.

* fix(scripts): keep guarded portable scripts bash 3.2 compatible

* fix(scripts): keep macOS Bash CI coverage green

Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.

Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.

* docs(install): use system Bash in install and recovery commands

Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.

Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.

* fix(scripts): preserve streamed installs and CI packing

Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.

Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.

Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
2026-09-08 01:21:30 -07:00
Peter Steinberger
ce0e84d073
fix(runtime): require Node builds with lossless SQLite reads (#140672)
* fix(runtime): require Node builds with lossless SQLite reads

* fix(runtime): preserve upgrades and guard sealed workers

Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.

* test(runtime): use typed process exports in worker fixture

* test(runtime): align installer fixtures without growing test shards

* test(runtime): align release and guest runtime fixtures

* fix(test): canonicalize Windows temp roots for Node 24

Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.

* test(ci): run Windows temp-root regressions in the native lane
2026-09-07 10:31:31 -07:00
Peter Steinberger
e024b63672
fix(test): preserve explicit Node tool contracts under Bun (#139841) 2026-09-06 03:22:24 -07:00
Peter Steinberger
a944ac24d5
fix(install): qualify npm 12 archives and prepared plugins (#136316)
Match local tarball lifecycle approvals to npm's normalized absolute file
identity across the installers and updater. Preserve directory links and the
shipped npm 11 advisory comma-path behavior without overriding npm policy.

Bind the mandatory npm 12 acceptance job to the already verified prepared
plugin registry so unpublished candidate dependencies do not require early
publication. Keep source, manifest, artifact and producer identities intact.

Update installer documentation and regression coverage, including the
Git-source-to-packed-tarball update path and its observed version outcome.
2026-09-02 07:14:46 -07:00
Peter Steinberger
dd4528b639
fix(macos): pair app builds with verified node workers (#131466)
Pair packaged apps with complete private arm64 and x86_64 workers whose full build identity matches the app. Preserve independently managed Gateways and complete recognized native-first state through the canonical initializer. Verify emitted-SDK filesystem calls, native capabilities, readiness and shutdown before app publication.

Derive elevation payloads without modifying canonical installed inputs. Preserve universal slices, resources and contained links; reject incomplete, malformed, escaping or mismatched payloads. Reuse descriptor-bound native inventory for signing while retaining the portable installer's independent distribution contract and every Foundation identity, entitlement, notarization and architecture gate.

Use the existing pinned-pnpm package path, including Corepack-only builders, and avoid recursive app-glob expansion. Centralize Mac CI ownership. Carry invocation-owned Git lock cleanup into main's canonical Git owner and regenerate its workflow projection, retaining lifetime fencing and pre-existing/junction-linked locks.

Fix the Android refresh race exposed by CI by removing the redundant reconnect after connect already replaces each role's socket. Preserve authentication, scopes and physical connection leases, with a controlled real-WebSocket regression.

Closes #131459
2026-08-29 14:47:55 -07:00
Peter Steinberger
5a20edf6a1
fix(installer): prevent source bootstrap from rewriting pnpm metadata (#132608)
* fix(installer): isolate source bootstrap from ambient pnpm

Select temporary checkout-pinned launchers for source installs and nested builds without changing global tools. Preserve caller context and document the Corepack prerequisite and first-hop update constraint.

* test(installer): exercise native Windows pnpm bootstrap

Cover scoped Corepack and exact npm-prefix bootstrap, child context, failure cleanup, and caller environment restoration under native PowerShell. Include the installer owner tests in the existing Windows CI shard and test-only routing.

* fix(installer): preserve native Windows argument and environment boundaries

* fix(updater): preflight the fetched pnpm pin before checkout changes

* test(installer): normalize native wrapper publication paths
2026-08-29 09:18:40 -07:00
Peter Steinberger
8fefe239bf
fix(installer): restore commit-pinned source installs (#132458)
* fix(installer): restore commit-pinned source installs

Restore literal commit selection without weakening qualified branch/tag resolution. Anchor installer upgrade tests to the selected version so newer publications cannot silently turn them into downgrade proof.

Fixes #132456

* fix(installer): resolve Corepack shims from the target checkout

* test: drop superseded media migration fixture extraction
2026-08-29 01:29:41 -07:00
Peter Steinberger
b85a049da5
chore: migrate tooling and source installs to pnpm 12 (#131043)
* build: migrate tooling and source installs to pnpm 12

Pin the verified native toolchain without changing application dependency
versions. Preserve the existing release-age policy explicitly and separate
package-manager lock metadata from the application dependency graph.

Use exact checkout pins for bootstrap and rollback, approve only the native
pnpm installer where npm requires it, and retain global install ownership
without equating the CLI major to the storage layout. Verify the Docker
runtime toolchain offline as its non-root user.

Remove duplicate bootstrap paths and obsolete prune input, update native
CLI flags and regression fixtures, and preserve UTF-8 in macOS Bash
installer NDJSON output.

* fix(build): isolate production dependency installs for pnpm 12

Build production dependencies from the same frozen manifest inputs instead
of pruning the inherited development tree. pnpm 12's native hoisted
importer cannot rename lower-layer OverlayFS directories during pruning.
Preserve native addon outputs, workspace builds, and offline non-root
Corepack use while deleting the obsolete production-store seeder.

Exercise runtime assembly and explicitly consent to the local agent-plugin
E2E fixture under the current plugin capability contract.

Validated full Matrix image and offline non-root runtime, focused Docker
regressions, full checks with test types and architecture, docs, real
agent-plugin gateway E2E, and isolated Codex autoreview.

* test: align package smoke with pnpm 12 global installs

* test: follow native pnpm artifact approval in distribution guard

* test: modernize pnpm fixtures for v12

* test: align rebased update fixtures with pnpm 12

* test: retain sanitized upgrade restart diagnostics

* test: expose CI navigation failures and register diagnostics

* test: retain post-core outcomes and plugin artifact identity

* chore(tooling): group upgrade diagnostic entrypoints

* fix(update): support native pnpm global installs and source links

Qualify local source and archive specs, carry verified global ownership through pnpm configuration, and verify intentional checkout links with shared runtime-readiness checks. Preserve strict packaged-install verification and manager ownership safeguards.

Verified the production updater with pnpm 11.22 and 12 using default and custom roots, source links, and tarball updates.

* test: preserve survivor diagnostics after service sealing

Promote incomplete exit-zero runs before failure capture and exercise the sealed-service manager fixture without inventing successful child exits.

* fix(update): preserve legacy pnpm global ownership

Carry the verified root and bin through both pnpm and npm configuration dialects after original-environment probes. Real pnpm 10 custom-root updates and pnpm 11/12 source and tarball matrices pass without redirecting the caller or weakening ownership checks.

* test(update): verify wizard consent through checkout handoff

Use the prepared checkout and fresh-process finalization boundary introduced by the updater repair. Preserve explicit consent forwarding before and after the wizard subcommand without assuming plugin callbacks run in the old process.

* refactor(update): validate checkout build metadata records

Use the canonical record coercer instead of carrying an unchecked assertion into the shared runtime verifier. Remove the now-unused grandfathered assertion entry; no allowance is added.

* docs(sandbox): document standalone common-image inputs

* test(packaging): account for required native prebuilds

Align installer and release size budgets at 235 MiB for the required native payload added on main. Keep both loader layouts, upstream binaries, explicit overrides, and missing-data rejection intact. Exercise actual defaults and the one-byte boundary. Retain bounded stderr diagnostics for the intermittent Bun signal test without claiming a production signal fix.

* test: align refreshed installer fixtures with pnpm 12

* fix(test): share Bun smoke force-kill ownership

Record the successful force-kill once across the timer and post-close drain. Native Darwin traces reproduced both duplicate-signal orders; genuine permission failures and uncleared groups still fail without extending deadlines.
2026-08-28 17:43:09 -07:00
Jason O'Neal
cd46f44661
improve(update): use local pnpm packages before the registry (#130902)
* perf(update): prefer cached pnpm packages

* fix(installer): preserve pnpm offline overrides

* fix(update): preserve pnpm preference in git updates

* fix(update): preserve pnpm config-file preferences

* fix(update): use the shared npm config scope type

* fix(installer): match canonical pnpm preference keys

* fix(update): type pnpm install environment

* fix(installer): preserve PowerShell pnpm preferences

* fix(installer): preserve pnpm config path policy

* fix(updater): preserve pnpm env precedence

* fix(installer): honor pnpm config policy

* fix(installer): match PowerShell pnpm config context

* chore: format pnpm install policy changes

* chore(ui): refresh startup gzip baseline after main fixes

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-08-28 15:00:31 -07:00
Jason O'Neal
a939d4bdd8
fix(installer): resolve source refs safely (#130907)
Source installs must select the requested release commit and leave existing checkouts recoverable when updates fail.

This change qualifies Git refs, carries ref mutability into lockfile selection, restores conflicting rebases, and verifies unchanged state when a pre-rebase hook refuses before rebase metadata exists.

Co-authored-by: Jason O'Neal <jason.allen.oneal@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-08-29 01:37:54 +05:30
Peter Steinberger
83dce46a7d
fix(update): preserve sealed service definitions during code updates (#131021)
Separate code-update ownership, effective launcher identity, native service control, and definition mutation. Guard actual definition publication before related config or token writes, and use the installed CLI's preserve-definition restart with renewed ownership and live port/version/build verification.

Consolidate unit/environment publication and conditional rollback, retain main's plugin convergence and fresh-Doctor ownership, and make post-core child termination belong to the winning completion path. Integrate current-main heap-argument provenance and process-marker handling; resolve the service Node from the executable rather than counting backward through flags.

Retain boundary-level sealed/writable/unknown/foreign, mount, platform, failure, and build-identity proof while consolidating redundant tests. The QA cleanup removes 399 maintained test/support lines; focused current-main integration proof passes 1,279 tests with one pre-existing platform skip. Production and installer growth remains +239 net.

Preserves the reviewed repair from ac86fdff61da9c0fea9f62da00a8c9f22df6790d while integrating main at 56d89073dd. No permission weakening, schema or lease policy change, deployment, or release.
2026-08-28 07:10:42 -07:00
Peter Steinberger
4377b6423c
fix(install): preserve Unicode in macOS JSON output (#131244)
* fix(install): preserve Unicode in macOS JSON output

* chore(install): keep release notes in PR context
2026-08-27 16:46:42 -07:00
xingzhou
ee2f5f2084
fix(install): --json preserves valid NDJSON for dynamic values (#128682)
* fix(install): preserve valid NDJSON for dynamic values

* fix(install): satisfy installer shell checks
2026-08-26 03:19:43 -07:00
Peter Steinberger
234df15a6d
chore: refresh dependencies after seven-day cooldown (#128414)
* build(deps): refresh dependencies after cooldown

Apply dependency, toolchain, action, image, and exact tool updates released by the inclusive 2026-08-16 seven-day cutoff. Adapt owner boundaries for the resulting CUA, logging, Teams, Markdown, native, and test-harness contract changes while retaining versions blocked by upstream compatibility constraints.

* fix(ui): align markdown renderer env typing

* fix(deps): align postcss and mistral peer contracts

* fix(deps): repair refreshed dependency contracts

* fix(deps): retain tslog startup budget

* fix(ci): verify Android tools with SHA-256

* fix(ci): fence Android SDK cache version
2026-08-24 03:01:54 -07:00
Peter Steinberger
b514fca522
refactor(update): simplify lifecycle transactions (#126240)
* refactor(update): simplify lifecycle transactions

* ci: use runner-provided ShellCheck

* test(infra): stabilize port-release probe
2026-08-19 01:50:35 -07:00
Peter Steinberger
7bc994aee8
fix(install): avoid success after incomplete lifecycle changes (#125992)
* fix(install): make lifecycle mutations transactional

Standalone installers now apply npm-version-aware lifecycle approval. Updates verify and repair the installation before reporting success and preserve the prior install owner during method switches. Uninstall now exits nonzero when requested cleanup is only partially completed. Plugin update behavior is unchanged.

Closes #125925

* test(uninstall): assert aggregated live-owner failure

* fix(install): satisfy standalone shell checks

* fix(update): scan PATH for prior Git wrapper

* test(hooks): await Gmail watcher descendant exit

* fix(install): verify Windows npm candidate

* fix(ci): normalize package acceptance version

* fix(update): preserve staged local package links

* test(update): fold staged symlink coverage

* fix(update): retire every legacy Git wrapper

* test(docs): align consolidated ownership checks
2026-08-18 20:50:15 -07:00
Peter Steinberger
076a8cc616
fix(install): avoid unusable checkout directories after failed clones (#124872)
* fix(install): publish fresh git clones transactionally

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(installer): preserve empty clone destinations transactionally

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(update): satisfy transactional clone lint

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(update): type recovery directory assertion

* fix(installer): retain canonical clone checkout

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(update): retain published checkout root

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(update): cover package preflight before clone

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-17 02:40:07 -07:00
Peter Steinberger
a917c99e92
fix(runtime): classify Node releases consistently across install and launch (#124812)
* fix(runtime): align Node release version guards

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(runtime): include Node version helper in source fixture

* fix(install): align Node release checks across boundaries

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix: keep node version guard legacy-compatible

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(runtime): exercise legacy launcher preflight

* fix(installer): validate installed Node release versions

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(installer): compare Node version parts numerically

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(installer): cover 17-digit Node major

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-17 00:42:23 -07:00
Peter Steinberger
2b2c11e748
fix(install): keep stable channel when npm install retries (#124778)
* fix(installer): keep npm channel target immutable

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(install): fail after repeated CLI package install errors

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(installer): verify npm package publication

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(install): satisfy shellcheck for entry validation

* fix(installer): link the packaged OpenClaw launcher

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(installer): keep retry fixture version-valid

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-17 00:17:26 -07:00
Peter Steinberger
3ac267fdd1
fix(installer): reject unusable prefix installs (#123716)
* fix(installer): reject unusable prefix installs

* test(installer): clean invalid package fixtures

* fix(installer): require successful version probe
2026-08-14 09:44:54 -07:00
Peter Steinberger
cc99d99f24
fix(installer): resolve relative CLI install paths (#122626) 2026-08-12 06:32:15 -07:00
Peter Steinberger
915c25d713
fix(macos): complete ChatGPT subscription setup (#120782)
Fresh Dev installs now preflight disk space and stream honest stages, while Codex activation probes the refreshed request-scoped registry.

Closes #120779
Closes #120780
2026-08-08 17:16:00 -07:00
Patrick Erichsen
355c107c09
fix(macos): unblock first-launch gateway setup (#119831)
* fix(macos): stop writing retired config metadata

* fix(macos): guard packaged CLI bootstrap versions

* chore(macos): refresh native i18n inventory

* fix(macos): repair retired metadata before gateway start
2026-08-05 22:25:17 -07:00
ooiuuii
807506381a
fix(install): reject commit-less git checkouts (#113809)
* fix(install): reject commit-less git checkouts

* test(install): fix incomplete-checkout coverage

* fix(install): pin incomplete checkout validation

* test(install): update pinned checkout stub

* fix(install): require checkout HEAD commit object
2026-08-02 08:05:42 -07:00
Peter Steinberger
902cc53279
refactor: batch of independent dedup wins (#113535)
* refactor(config): reuse session parent fork types

* refactor(channels): reuse setup adapter type

* refactor(discord): share model preference primitives

* refactor(whatsapp): share reaction eligibility

* test(auto-reply): deduplicate dispatch scenarios

* test(scripts): share scenario fixtures

* test: share process and registry fixtures

* test: satisfy dedup fixture lint

* fix(plugin-sdk): keep setup adapter contract acyclic
2026-07-25 02:56:05 -07:00
ooiuuii
396194b96b
fix(install): reject PATH runtimes with broken npm (#107825)
* fix(install): reject runtimes with broken npm

* test(installer): use real Node for npm selection

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-16 17:17:07 -07:00
lybnnnn
02f494b51e
fix: clarify SQLite version error message to prevent user confusion (#108382)
* fix: clarify SQLite version error message to prevent user confusion

The error message "3.44.6+" was misinterpreted by users as meaning "3.44.6 and above",
when it actually means "3.44.6+ for the 3.44.x series only". This commit clarifies the
error message to explicitly state that only specific patched versions (3.44.6+, 3.50.7+,
and 3.51.3+) are safe, and that SQLite 3.46.1 is not among them.

Changes:
- Update error message in src/infra/node-sqlite.ts to clarify version requirements
- Update test expectations in src/infra/node-sqlite.test.ts to match new error format
- Fix unnecessary template literal expressions flagged by oxlint

The code logic remains unchanged - SQLite 3.46.1 is correctly rejected as unsafe.

* fix: clarify SQLite version error message to prevent user confusion

The previous error message stated '3.44.6+' which users misinterpreted as
'3.44.6 and above', leading to confusion when versions like 3.46.1 were rejected.

The new message explicitly states '3.44.6+ in the 3.44.x series' and
'3.50.7+ in the 3.50.x series' to make it clear that only specific
minor version series received the WAL-reset bug fix.

This matches the SQLite team's actual fix announcement which only
backported the fix to 3.44.x and 3.50.x series, plus 3.51.3+.

* fix(sqlite): align unsafe version diagnostics

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-16 05:24:14 -07:00
Alix-007
5f2828b50a
fix(installer): time out stalled runtime downloads (#108619)
* fix(installer): bound curl download stalls

* chore: format installer timeout tests

* fix(installer): limit timeout to true download stalls

* fix(installer): scope timeout to transfer stalls
2026-07-15 23:01:31 -07:00
Peter Steinberger
2bbf5e6ca0
fix(macos): prevent clipped and stalled onboarding (#107598)
* fix(macos): harden onboarding on short screens

* chore: keep release notes in PR body

* chore(i18n): refresh macOS onboarding inventory
2026-07-14 10:07:41 -07:00
Vincent Koc
f33ab243cf
fix(sqlite): reject runtimes vulnerable to WAL corruption (#106065)
* fix(sqlite): require WAL-reset-safe Node runtime

* docs(sqlite): document safe Node runtime floor

* fix(sqlite): defer runtime library validation until use

* fix(ci): align startup memory with Node 24.15
2026-07-13 13:59:00 +08:00
Peter Steinberger
4b7a5a4e8b
fix(installer): default to Node 22.22.2 (#104073) 2026-07-10 19:28:49 -07:00
Sebastien Tardif
95b205eac2
fix(installer): clean temporary files on failure (#103725) 2026-07-10 17:53:23 -07:00
Jason (Json)
cccc856b82
fix: reject incompatible Node 23 runtimes (#99832)
* fix: reject incompatible Node 23 runtimes

* fix: repair installer CI coverage

* docs: clarify supported Node ranges

* fix: fail closed on unreadable runtime versions

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-04 00:03:49 -07:00
Peter Steinberger
6a7b62889e
feat(macos): install and run the local Gateway automatically (#99767)
* feat(macos): automate local gateway setup

* fix(macos): auto-approve the local Mac node

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata
2026-07-03 22:09:56 -07:00
Vincent Koc
bd74a62118
fix(install): use repo pnpm for git installs 2026-06-21 15:34:56 +02:00
Vincent Koc
00a06eab44
refactor(test): dedupe installer npm fixtures 2026-06-18 20:38:29 +08:00
Peter Steinberger
58c663920d docs: document script tests 2026-06-04 20:49:50 -04:00