Commit graph

1982 commits

Author SHA1 Message Date
Doksanbir
dd6f6aa4b3
fix(ci): preflight job outputs exceed 1 MiB on full-plan pull requests (#140018)
* fix(ci): keep preflight job outputs under GitHub's 1 MiB cap

Pull requests that need the full canonical Node test plan failed preflight
with "Job outputs exceed 1,048,576 bytes", which made ci-gate report every
lane as selected=missing. The compact plan lists 7,749 striped test files
explicitly, and GitHub measures job outputs in UTF-16, so the effective cap
for all preflight outputs is 524,288 characters. The manifest reached ~522K
characters on the github profile as the tracked test inventory grew.

Emit each Node matrix row's groups as gzip+base64 JSON at the manifest
boundary and unpack them in the shard runner. On current main this takes the
github-profile manifest from 522,522 to 195,410 characters and the blacksmith
profile from 450,639 to 158,571, with identical jobs and group membership.
The manifest imports the codec through the existing target-plan seam, the
trusted runner checkout lists it, and plain OPENCLAW_NODE_TEST_GROUPS_JSON
remains for the Vitest cache warmer.

Related to #139929 and #136820.

* fix(ci): load the Node test groups codec only for grouped rows

The manifest imported scripts/lib/ci-node-test-groups-codec.mts
unconditionally through importTargetPlan. An ordinary manual
workflow_dispatch whose target_ref predates the codec is not a
compatibility target, so the import threw before planning even though
such targets emit an ungrouped plan and never call the encoder.

Import the codec only when the emitted Node rows carry groups, and keep
the clear failure when a grouped plan comes from a target without it.
The workflow-guard fixture can now omit the codec so a codec-free manual
target runs the real manifest step.

* fix(ci): preserve grouped historical test plans

Negotiate the packed group codec against the selected target and fall back to the same five-field legacy projection when the codec is unavailable.

Five-field projection adapted from #140036.

Co-authored-by: Peter Steinberger <steipete@gmail.com>

---------

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-06 20:18:41 +08:00
Peter Steinberger
a25cd272ec
refactor: consolidate command and provider helpers (#140072)
* refactor: simplify command rendering and diagnostic plumbing

* refactor(providers): share exact effort profile parsing

Keep model overrides and API fallbacks in their provider owners. The shared helper has no runtime imports so eager policy loading retains its narrow dependency graph.

Official plugin packages gain a host runtime dependency. Publish this with the next synchronized core and plugin release, whose canonical release sync advances pluginApi floors; do not publish these plugins alone with the existing older API floor.

* chore: prune removed provider assertion allowances
2026-09-06 05:17:53 -07:00
Peter Steinberger
8319778f3e
fix: native worker turns fail to load WebSocket transport (#140071)
* fix: bundle WebSocket transports in portable workers

* test: include worker transports in declaration fixtures
2026-09-06 04:50:21 -07:00
Peter Steinberger
1421c21640
fix: restore package acceptance across install runtimes (#140062) 2026-09-06 04:41:04 -07:00
Peter Steinberger
76bf977fae
feat(update): recover failed updates with bounded repair (#139495)
* feat(update): integrate bounded repair and harden activation ownership

Run bounded candidate validation repair before activation and verification
repair when rollback cannot recover. Keep service authority with the
orchestrator, record attempts live, and use a fresh candidate worker after
activation. Preserve Windows suspension and compensation through terminal
verification, including cancellation at native mutation boundaries.

Preserve restored runtime identity through failed rollback verification and
report repair of the previous release as rolled back, keeping the update
failure and nonzero exit. Close native staging and Git promotion races. Share run
vocabularies and validation shapes, make ledger redaction precise and JSON
bounding non-mutating, and improve failure reasons, reports, phase visibility,
and unattended-repair documentation.

Validation: full changed-file gate including Knip, full build, focused
integration and native repair E2E, UI E2E, and Codex P0/P1 autoreview.
The explicitly protected lifecycle test remains unchanged; its source
loading exceeds the 30-second harness deadline even with fresh dist.

(cherry picked from commit d37a9418d9468c3e0894fd6d3cebf74b9c6051f4)

* fix(update): await origin notice before managed activation

Connect transferred helper activation to the serving gateway notice callback over the existing control pipe, with a ten-second bound before service parking. Preserve helper-owned cancellation and activation checks.

Record failure excerpts only for failed steps, so completed managed handoffs no longer report an unknown exit code. Cover internal transcript custody with the real helper and bounded simulated service-manager flows.

(cherry picked from commit 8a4db45aff48f6fc7b44add16e5756505450e26f)

* refactor(update): share repair budgets and validation cleanup

* fix(update): preserve transaction outcomes through repair

* refactor(update): remove unused package activation flags

* fix(update): settle the current Windows recovery owner

The regression "settles Windows recovery after candidate repair and plugin activation" failed for both terminal outcomes because the latest suspension retained signal listeners and an exit gate. Resolve the same current stop for restoration, plugin maintenance, and final settlement. Both cases and 103 surrounding tests now pass.

* fix(update): align shared types and repair test ownership

* docs(update): place fallback scope beside candidate staging

* fix(update): isolate staged repair and enforce requester authority

Run pre-activation repair against a disposable rehearsal shared by every
turn and oracle. Reject required config edits without promoting copies,
then independently validate surviving candidate changes before activation.

Carry the admitted chat requester's command-owner predicate into both
repair paths and revalidate it immediately before tool effects. Record
requester revocation and the repair target class in the update ledger.

Add observable helper authority, staged isolation, and activation
regressions. Preserve installation-scoped recovery guidance.

Refs #139495

* fix(update): defer plugin metadata until repair isolation

Read core config before staging and for command-owner policy checks.
Skipping plugin validation still materializes metadata and reads the
serving SQLite index, changing WAL shared-memory read marks even when
config observation is disabled. Load full metadata under the disposable
target instead.

Resolve the helper fixture's packaged snapshot worker from its canonical
runtime entrypoint descriptor.

Both staged-isolation cases and all four requester-effect cases pass their
assertions. The E2E process still fails teardown on the existing service
child cleanup identity error; that upstream blocker remains visible.

* fix(update): sanitize rehearsal env and remove helper cycle

* test(update): preserve repair proof across env sanitization

Load the spawn recorder through explicit arguments for the owned relay and anchor. Use the production daemon entry for requester checks so source plugin compilation does not consume the fixture deadline.

* fix(update): preserve requester errors and prepare helper tests

* test(update): follow the shared stdin write contract

* refactor(update): separate admission and failure reporting
2026-09-06 04:13:16 -07:00
Peter Steinberger
1b39fcd32b
fix(tooling): load TypeScript tooling under Bun (#139861)
* fix(tooling): preserve native TypeScript loading under Bun

* fix(tooling): use supported Bun source imports
2026-09-06 02:29:56 -07:00
Peter Steinberger
f5d4d6bf53
refactor(tooling): remove redundant Windows command helper bridge (#139932)
* refactor(tooling): remove redundant Windows command helper bridge

* test(tooling): track canonical Windows helper in declaration inputs
2026-09-06 01:56:15 -07:00
Peter Steinberger
2fba1d7c15
fix(net): load the installed Undici dispatcher under Bun (#139811) 2026-09-06 01:52:33 -07:00
Peter Steinberger
8b37368a4e
perf: reduce packaged runtime module-loading overhead (#139754)
* build: emit internal runtime chunks as explicit ESM

Avoid repeated Node package-format metadata parsing for internal chunks while preserving named JavaScript entrypoints, public SDK paths, stable runtime aliases, and historical upgrade aliases.

Validation: 242 focused tests, normal build, built status-runtime loading, actual package inventory/import-closure checks, and independent Codex P0 review passed. All typechecks passed. Local aggregate lint was blocked by an ancestor-checkout punycode manifest lookup; neutral Linux validation and original retention stress acceptance remain pending. Related: #136639.

* build: preserve private QA exclusions across chunk formats

Match the existing inventory-owned private QA namespace when packing reused build outputs. Add real npm-pack regression coverage and remove ignored promise-executor return values from startup metadata tests without changing their timing or cleanup behavior.

The new package regression failed before the exclusion repair and passed afterward. Package E2E: 63 passed, 3 Windows-only skipped. Startup metadata: 22 passed. Focused lint and independent Codex P0 review passed. Related: #136639.

* test: preserve user loader proof for ESM chunks

* test: recognize ESM chunks in remaining runtime fixtures

* test(docker): complete package lifecycle before read-only proof

* test(docker): consolidate the packaged-image lifecycle contract
2026-09-06 01:31:24 -07:00
Peter Steinberger
4b72445c44
fix(test): close remaining core HTTP fixture owners reliably (#139824) 2026-09-06 00:28:41 -07:00
Jason (Json)
6277d6da13
fix(doctor): preserve migration authority and stop refused repairs (#139683)
* fix(doctor): bind migration authority and ordered receipts

Keep live caller authority separate from artifact-preserving copied-state
planning. Carry planned endpoints and requiredness through ordered receipts,
close required refusals, and settle deferred plugin work after its writer.

Continue the migration work from openclaw/openclaw#136529 by Jason (Json),
@fuller-stack-dev, without replacing the original public branch or history.

* fix(doctor): preserve caller locks during snapshot hashing

Isolate snapshot file descriptors from caller-held SQLite transactions. Keep framed worker input and ordered refusal semantics, classify deliberate foreign-store omissions at their owner, and retain exact CLI controls.

* fix(doctor): preserve uncached caller locks during planning

* test(doctor): bind final traversal refusal diagnostics

* fix(sqlite): preserve publisher cleanup ownership
2026-09-06 01:18:42 -06:00
Peter Steinberger
d1a69c0b20
fix(update): validate candidates before stopping the Gateway (#138839)
* refactor(update): stage and retain package and Git transactions

Stage supported package-manager layouts and prebuilt Git runtimes before
activation. Expose candidate validation and activation boundaries, retain the
previous package and launcher until finalization, and preserve the original
failure when source exposure is cancelled.

Verify the requested package version before admitting a staged no-op. Replace
live Git install/build and rollback rebuild work with prepared runtime promotion.

(cherry picked from commit 0a1e09cb5350e1e1268d07753c11551d24549aa1)

* feat(update): validate online and verify activation or rollback

Keep the gateway serving during candidate staging, lint, config/plugin checks,
and an isolated SQLite-snapshot canary. Same-version and same-SHA no-ops never
stop the service. Limit activation downtime to swap, owned migrations, and start.

Record settle, version/build, plugin, channel, readiness, advisory inference,
and downtime in the existing run ledger. Restore retained package transactions
only across unchanged state schemas, using prior verification to authorize the
previous gateway restart. Hand migrated-state finalization to candidate code.

Park managed helpers only at activation. Give the spawn fallback runner sole
ownership of helper stdin so activation acknowledgements reach its child.
Protect active backups from cleanup and CLI-owned runs from premature notices.

Refs #137580, #136997, #124396.

(cherry picked from commit 5523f4f419652d7e6666fa53dc19c650528aba0d)

* docs(update): explain staged activation and schema-neutral recovery

Document no-op behavior, candidate validation, bounded activation, verified
package rollback, migration refusal, downtime, and managed-helper ownership.

(cherry picked from commit d1dc73c804e02626e89d677970744bf1b235269b)

* fix(update): preserve run ownership and explain skipped rollback

Record an explicit no-retained-package fact when post-core verification fails
without a rollback transaction, keeping the original failing oracle and service
policy. Verify the durable report with an isolated real ledger.

Keep staging and repair under CLI completion ownership too, so sentinel expiry
after an unrelated gateway boot cannot prematurely finish an active update run.
The existing phase regression fails for both phases before this fix.

(cherry picked from commit c212030ce05a41018c0d2f335d49e65ec999c92c)

* fix(update): restore a running previous generation after rollback

Restore package bytes and shims, the config writer version, the owned service
definition, and the previous Node runtime across unchanged config and schemas.
Scope the existing older-binary recovery allowance to service invocations.

Carry complete restoration proof into the managed helper, keep its ledger run
open through CLI unwind, and recover instead of unconditionally parking on
exit 79. Refresh observed service facts and retain restoration receipts when
bounded diagnostics are evicted. Successful recovery remains a failed update
but records rolled-back, the previous version, and verified downtime.

Wait on actual ownership validation readiness and isolate all helper test
coordinators while preserving real cross-process arbitration within fixtures.
Document the recovery boundary and the helper's observed verification limits.

Follow-up: review zero-wait coordinator admission under concurrent independent
updates; the existing lease reader maps SQLite contention to unavailable
identity. This change does not alter production store concurrency policy.

Validation: full CLI/ledger/report scope 948 passed (1 skipped); handoff/package
scope 176 passed (2 skipped); two concurrent lifecycle copies passed 154/154 each
during a separate checkout build; closing cross-process/CLI scope 114 passed
(1 skipped). pnpm build, the complete changed-files gate, and P1 autoreview pass.

(cherry picked from commit fe3fa2e7dd29ca98e9e5e8c375f9e7431d4733dc)

* fix(update): preserve sibling packages during late native rollback

Recheck the native global project before stopping a reachable candidate and
again before restoring any project or launcher bytes. Compare the finalized
staging fingerprint, excluding OpenClaw payloads, using the existing helper
with per-entry digests and direct sibling entries.

Refuse changed-project rollback with rollback-project-changed, preserve the
candidate and backups, record names-only details, and report recovery guidance.
Keep the run failed without automatically repairing the shared project. npm
package-root swaps retain their existing behavior.

Validation: 85 focused tests passed; three final fixture cases passed after
adding required service inspection fields. The new filesystem regression
failed on the parent for pnpm 10, pnpm 11, and Bun. Full changed-file checks and
fresh Codex P0/P1 autoreview passed. Production +112 lines, tests +179 lines,
docs +2 lines; no new fingerprint implementation, configuration, or schema.

(cherry picked from commit 0abb72b514226cc0b4cd4d0f99207e93aedad99b)

* fix(update): preserve verification and cancellation ownership

Verify metadata-refresh restarts through the same readiness and inference path, preserve rollback recovery ownership, and reject cancelled activation after asynchronous checks. Keep schema/protocol verification fields aligned and share update step and state-snapshot types.

Carry the cancellation-only hardening from campaign commit d37a9418d94 without its automatic repair integration. Regression proofs cover refresh readiness, Windows autostart compensation, and systemd/launchd cancellation boundaries.

* fix(update): require safe recovery before restoring autostart

Narrow the recovery verdict before consuming service health. Align native Windows fixtures with their actual enabled state, verify compensation after an enable commits and fails, and preserve the precise interrupted verification diagnostic. Keep npm staging and cleanup assertions on the current namespace.

* refactor(update): keep verified service recovery in its owner

Move failed-update restart into the existing recovery module, retain the service facade, and await Doctor lifecycle cleanup. Align Doctor tests with HTTP readiness and advisory inference, including a healthy service with unready HTTP and preserved probe-port coverage. Complete synthetic helper teardown before removing its files.

* fix(update): preserve staging and plugin maintenance boundaries

Use effective pnpm configuration arguments and verify staged root/bin destinations before installing. Preserve relative external dependency links during Git promotion through the same relocation owner as native package staging.

Centralize post-plugin completion in the parent updater after the fresh child finishes package work. Park the owned service only for required Doctor maintenance, retain Windows compensation through verification, and measure the full second outage. Keep downgrade writes in the target runtime and validate unchanged-plugin configuration with that runtime's schema.

Remove the recovery-to-command import cycle. Cover native destination refusal, promoted imports, fresh child/parent lease boundaries, target-owned downgrade stamps, and migration/restart timing. Isolated real pnpm and Doctor coordinator flows verify the dependency and maintenance contracts.

* fix(update): finalize unmanaged runs after gateway restart

Use the recorded CLI trigger or managed handoff identity to preserve verification ownership. An unmanaged RPC also reaches restarting, so its phase cannot imply an updater exists to finish it. Keep notice expiry bounded while preserving managed verification.

Reproduce four unmanaged completion failures before the fix; cover successful and expired unmanaged runs, managed API/chat/control-plane/campaign handoffs, and all CLI phases. Gateway owner, sentinel, and update method tests: 150 passed. Codex P1 local review clean.

* fix(update): retain complete candidate dependency stores

Retain configured Git virtual stores inside the exact preflight cleanup boundary, including sibling and symlinked stores. Rebase external store metadata and launchers, preserve rollback, and refuse source or destination checkout overlap through aliases.

Share native and Git relocation of links, manifests, and launchers. Keep pnpm candidate project stores private through the supported invocation environment so staging cannot prune the serving generation. Preserve operator configuration and ordinary subsequent package-manager operations.

Proof: five pre-fix Git regressions; 40 Git/native transaction and 27 post-update tests passed, followed by eight focused overlap/native tests. Real pnpm proof covers seven Git layouts and four native manager/store modes, imports, launchers, metadata, rollback, promotion, and subsequent global install. Codex P1 review clean.

* test(update): preserve online inspection through package executor

* test(update): align transaction fixtures and prune unused exports

* fix(update): retain Git runtime backups after failed restoration

* test(update): consolidate post-update fixtures for lint

* fix(update): preserve recovery ownership and CI prerequisites

Remove the history-based cleanup lock. A killed updater leaves a running
ledger row, but history is not retirement authority: migration cleanup
already verifies its own archives under exclusive maintenance ownership.
Package, shim, and Git runtime backups belong to separate transactions.
This also avoids opening the ledger before external state ownership checks.

Register the real candidate canary and migrated-update process fixtures
with their runtime build owner. Partition whole-config consumers before
striping, keeping one runtime build and removing the sibling-sharing
exception without changing CI caps or worker budgets.

Align installed-CLI validation, managed handoff, and native stop fixtures
with the transaction and service-owner contracts.

* test(ci): derive runtime exclusions from the consumer catalog

* fix(update): preserve report ownership across candidate migration

Suspend every old CLI progress reader at activation and resume only after schema compatibility is established. Let migrated candidates own final reporting, and keep the permanent finished-notice key available while CLI verification remains pending.

Preserve the merged update-surface contracts, truthful acknowledgement wording, and canonical restart successor ownership. Regression coverage includes real candidate migration in text and JSON modes plus sentinel expiry followed by verified completion.

* fix(update): preserve live SQLite artifacts during inspection

Use the canonical private snapshot owner for candidate copies and schema inspection. Discover registered databases from the same private generation instead of reopening the live registry, and preserve original locators in rollback receipts.

Keep the existing bounded inspection deadline and fail-closed rollback behavior. Regression coverage reproduces source WAL sidecar creation, checks closed WAL and rollback stores, and verifies committed schema visibility while a live writer retains its transaction.

* test(update): sort artifact entries without mutation

* fix(update): preserve active runtime ownership during staged updates

Keep candidate pnpm stores private across installs, nested lifecycle commands,
workspace configuration, native staging, and Git promotion so preparation cannot
prune the serving generation or leave activated dependencies behind.

Record the active package root at each activation and restoration boundary.
Launch post-activation schema inspection from that package and selected Node;
retain unknown identity after partial moves until recovery verifies the original.

Accumulate verified outage intervals independently of mutable ledger health,
excluding online plugin work. Register built schema-worker test prerequisites.

Refs #136997, #137580, #124396.

* test(ci): type build admission argument rows explicitly

* fix(update): await the async schema preflight before activation

Follow #138986's asynchronous database preflight contract before checking its result. Passing the promise to hasSchemaRefusal otherwise throws on package activation.

Keep Git's mutation fence after its post-stop schema check so interruption can restore the unchanged Windows task. Reject retained recovery handles as soon as settlement begins.

* fix(update): restart the unchanged gateway after native swap refusal

Record live mutation in the swap owner after its native project recheck, immediately before the first move. A sibling change during shutdown now preserves safe recovery of the original package without restoring over the sibling.

Extend the native refusal matrix with the original recovery version and exercise its safe restart outcome through finalization. Keep late rollback-project-changed behavior unchanged.

* fix(update): preserve finalization for older downgrade targets

Keep the shipped explicit downgrade contract when a candidate predates the migration-continuation worker. Record runtime validation as unavailable before invoking new-only canary commands, then use the established finalization owner.

Present workers must still report their schema contract, and database preflights remain mandatory when target schema metadata is available. Do not attempt the new schema-worker or rollback contract for targets that do not provide it.

* fix(update): make Windows Bun refusal actionable

Preserve the pre-stop refusal for Bun's Windows launchers. Carry the inspected install spec into staging so the failed step names the exact manual Bun install, Gateway restart, and update-status commands.

Bun is an opt-in runtime; keep one supported staging flow instead of adding an in-place fallback. Match the updating guide to the emitted recovery instructions.

* perf(update): avoid snapshot imports during schema inspection

Load the verified-snapshot dependency only when snapshot rehearsal runs. Schema-version workers do not need the snapshot module's memory and plugin import graph.

Keep the same private-copy inspection and 30-second worker deadline. This changes dependency loading without changing SQLite schemas, data, or recovery policy.

* fix(update): keep the owned managed-update environment when given process.env

The absent-service rollback regression exposed an aliased input: clearing process.env also cleared the environment supplied to the phase. Reuse the existing snapshot for that input and preserve restoration after failure. The environment-only regression fails before the repair; copied-input and rollback sibling paths pass.

* fix(triage): accept the unavailable canary advisory

Preserve failure diagnostics after a confirmed downgrade to a target without migration continuation. The diagnostic boundary accepts both advisory variants while retaining only actual failed steps; the new advisory row failed schema validation before this repair.

* test(ci): route real-worker update CLI tests to the process lane

Keep rollback, post-update recovery and service integration tests that launch built schema workers in the existing isolated serial process owner. Move their runtime prerequisites with them and preserve CI partition, concurrency and budget assertions. All three routing regressions failed before the owner correction.

* test(update): align downgrade and recovery fixtures with checks

Supply the required invariant diagnostic and construct recovery table rows without map-spread. Preserve all cases and assertions.

* test(ci): align CLI build admission with process ownership

The shared CLI config has no runtime consumers after moving the real-worker update tests. Test it in the no-build table and retain process-lane build, failure, exclusion and SIGTERM coverage. Fixes the stale build.pid expectation from CI run 33991347672 without changing deadlines or production behavior.

* test(update): verify candidate snapshots through the worker

Snapshot backup and VACUUM run in a dedicated production process so cancellation can join before cleanup. Direct Vitest DELETE and symlink cases hit their 120-second deadline, while the equivalent worker copies preserved source bytes in about seven seconds. Exercise the existing worker entrypoint, retain every registry and artifact assertion, and bound the child to 30 seconds.

* test(update): include helper logs in terminal outcome failures

A loaded-host run restored the Gateway but left the ledger running. The six-case and full 154-case reruns passed without a production change. Preserve helper diagnostics in the assertion so a recurrence exposes the terminal-writer failure; no behavioral fix or timeout relaxation is claimed.

* test(update): preserve launchd recovery identity proof after restack

Carry the real stripped helper environment and emulated recovery cleanup from #139393 into the extracted transaction boundary fixture.

* fix(update): retain runtime evidence across partial backup cleanup

A cross-device backup move can publish its backup, remove the source dist
inventory, then reject after deleting a runtime file. Directory order varies
by filesystem. Older packages may legitimately lack that inventory, so a
fresh verification using only surviving metadata could accept a gutted tree.

Retain the expected dist files before mutation and compare the surviving
runtime against them before accepting recovery without a completed rollback.
A partially removed package must never be reported as the active root.
Preserve recovery of an unchanged package after a refused backup move.

Make the existing cleanup regression exercise inventory-first deletion; it
fails before this fix with the same active-root assertion as CI. Recovery and
native transaction suites pass all 57 cases. Extend CLI finalization coverage
to ensure failed swaps with unsafe recovery never restart the package.

* fix(update): verify recovery inventory at the previous package root

* fix(update): retain backups until activation or restoration is verified

* test(update): isolate handoff workers and child result publication
2026-09-06 00:07:02 -07:00
Peter Steinberger
f4bde51ed1
fix: preserve targeted test selection under Bun (#139497)
* fix(test): preserve glob selection under Bun

Use the existing Minimatch dependency with Node-compatible matching semantics so negative-extglob UI ownership does not silently discard explicitly selected files under Bun. Preserve intentional empty unrelated project behavior and cover selection, intersection, and scoped configuration.

* fix(test): keep Node glob planning dependency-free

* fix(test): isolate runtime matching from dependency-free planning
2026-09-05 23:54:25 -07:00
Peter Steinberger
512d8f2ee5
chore(deps): refresh seven-day-cooled dependencies (#138199)
* chore(deps): refresh seven-day-cooled dependencies

* fix: resolve dependency refresh CI blockers

Recheck caller cancellation after the OpenAI SSE iterator ends and before
Chat Completions can promote provisional tool calls. OpenAI 7.8 may end
an aborted iterator normally; preserve the shared transport's abort contract.

Wait for the fake WebSocket receive callback before emitting replies in
three Watch journal fixtures, retaining their existing timeout and assertions.
Point the QA release-policy catalog at the repository-owned plugin guide
after main removed its duplicate ClawHub publishing page.

The existing OpenAI regression fails before the owner fix and passes after,
with 243 owner/sibling tests and both transports exercised over real loopback
HTTP. The 58-test QA catalog suite, changed gates, AI package build, and
independent scoped P0 review pass. Fresh exact-head hosted CI, including
iOS lifecycle and production advisory checks, remains required before merge.

* test(mattermost): control loopback timeout deadlines

* test(ai): cover cancellation at normal stream completion

Prove the shared Chat Completions parser rejects an abort immediately before normal iterator return and never finalizes the provisional tool call. The regression fails with only the post-loop guard removed; 312 owner and sibling tests and the changed-file gate pass with the guard intact.

* fix(ui): preserve focused popovers during sidebar updates

Keep community invitation geometry deferred while a DOM-owned popover item has keyboard focus, even when Chromium reports no sidebar focus-within. Exercise background presence updates after real menu focus.

Distinguish independent Swarm child hydration from canonical roster refreshes in the held unread acknowledgement test. Preserve immediate badge clearing and prove an extra canonical refresh still fails the assertion.

Validation: 12 Control UI E2E cases and 431 related UI tests pass; the focused invitation case fails on the previous production condition. Independent Codex P0 review is scoped-clean.

* chore(deps): upgrade CUA and preserve published docs anchors

Upgrade CUA 0.22.0 to 0.22.2 with its coordinated accepted native
artifact records, and slugify 2.2.0 to 2.2.1 under the frozen seven-day
cutoff. Preserve Mint's published heading and component anchors before
counter allocation.

Synchronize the docs publisher's independent slugify manifest and npm
lock atomically with its parser; reject unrelated dependency drift after
rebasing the publish commit. Preserve every existing product security
exception, patch, toolchain document, and public configuration contract.

209 selected owner tests, source/publisher anchor corpus comparisons,
full changed checks and build, the exact dependency age/integrity audit,
and independent managed P0 review passed. Native CUA execution and
fresh exact-head CI remain required before landing PR #138199.

* chore(deps): refresh newly cooled September 5 dependencies

Advance the frozen seven-day selection to 2026-08-29T18:40:39Z. Update AWS, ACP, TUI, Discord types, Matrix WASM and duration formatting; align standalone broker Node types. Preserve main security exceptions and hold incompatible direct Zod upgrades.

* fix: align dependency refresh CI fixtures

Model the atomic publisher manifest/lock handoff in the process-fault fixture and execute its real validator before push. Preserve strict command matching, drain ordering and terminal rejection semantics. Inline the single-use reasoning-effort resolver to keep the shared stream below its existing line limit without changing cancellation or reasoning behavior.

* test(ui): await settled skill-menu geometry

Wait for the existing semantic and animation readiness boundary before comparing list and action widths. Preserve exact width tolerance, viewport bounds and read-only pin assertions; do not fast-forward animation or alter production styling.

* test(ui): bind live browser disclosures to their owners

Adapt the run/tool identity repair from 90c51add82 while preserving the existing 15-second overall observation budget. Remove live page-wide positional disclosure polling; keep history and inert-route assertions, and capture optional synthetic proof.
2026-09-05 22:59:41 -07:00
Peter Steinberger
2bc46990ba
fix(tooling): diagnose declaration escapes into ancestor installs (#139766)
* fix(tooling): diagnose declaration escapes into ancestor installs

* fix(gateway): use current projection fields in session history test

#139753 renamed the projection result's streamErrorFallbackPending and
streamErrorFallbackRepaired to assistantErrorPending and
assistantErrorRecoveryObserved, but one call site in this test kept the old
names, leaving main red on check-test-types-core-2. Its targeted PR CI never
selected this shard, so the break first appeared on a full main run.
2026-09-05 22:55:00 -07:00
Peter Steinberger
1caa297678
perf(tooling): prepare source scan paths before sorting (#139763) 2026-09-05 22:31:50 -07:00
Doksanbir
a887336b1e
fix(docker): stage bundled plugin runtime dependencies under the packaged plugin root (#139117)
The official 2026.9.1 image cannot load its bundled externally distributed
plugins (codex, diagnostics-otel): doctor and plugins inspect report every
declared dependency as missing. Since the workspace moved to pnpm's isolated
linker (#135728) those packages live only in /app/node_modules/.pnpm and are
linked from /app/extensions/<id>/node_modules, neither of which is an ancestor
of the packaged root /app/dist/extensions/<id> that the dependency lookup
(src/plugins/status-dependencies-core.ts) and the managed Codex launcher
resolution (extensions/codex/src/app-server/managed-binary.ts) start from.
2026.8.2 worked only because the hoisted linker placed them in
/app/node_modules. Docker-selected plugins are built as unified outputs, so
the source-checkout dependency links added in #135903 never applied to them.

Move linkSourcePluginDependencies into a plain-Node module and have the
Docker assembly stage link each retained root-package-excluded plugin's
production install under dist/extensions/<id>/node_modules after package
lifecycle cleanup, failing the image build when a declared dependency still
does not resolve from the packaged root.

Fixes #138777. Reported by 8bitsforge.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-06 11:07:53 +08:00
Vincent Koc
0376869dad
fix(release): accept frozen targets before worker bundles (#136699)
* fix(release): accept frozen targets before worker bundles

* fix(release): fail closed for unreadable worker artifacts

* fix(release): use canonical package layout verifier

* refactor(scripts): remove obsolete package layout helpers

* fix(release): keep packed SDK smoke target-compatible

* refactor(scripts): remove unused static asset output helper

* fix(release): reject package-excluded extension payloads

* fix(release): validate packaged metadata contracts

* fix(release): restore package contract ownership

* test(scripts): model tarball verifier entry

* fix(release): reject empty worker contracts

* fix(release): honor npm required package files

* fix(release): enforce npm package path contracts

* fix(release): use npm pack inventory authority

* fix(release): stabilize npm inventory CI

* fix(release): accept npm 12 pack inventory JSON

* fix(release): allow npm-selected bundled dependencies

* fix(release): stabilize shrinkwrap inventory parity

* fix(release): enforce target package declarations

* fix(release): require populated package declarations

* fix(release): suppress npm pack lifecycle scripts

* fix(ci): stabilize Control UI performance comparison

* fix(release): preflight package tar extraction

* fix(release): harden tarball preflight parity

* fix(release): isolate npm pack config lookup

* test(release): narrow npm pack captures

* chore: drop release-only changelog edit

* fix(ci): pack hosted tooling runner tails

---------

Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-09-06 11:26:06 +09:00
Peter Steinberger
b8731bc88a
perf(test): reuse transforms within owned scheduler slots (#139553)
* perf(test): reuse transforms within owned scheduler slots

* test(ci): assert verified outer process completion receipts

* test(ci): assert joined Vitest progress completion

* test(ci): cover platform-specific cache lease policy
2026-09-05 18:50:40 -07:00
Jason (Json)
806356f4a9
perf(build): avoid unrelated gateway artifact scans (#127757)
* perf(build): bound runtime artifact validation

* test(build): consolidate gateway artifact build coverage

Keep the three real bundler cases beside the artifact checker tests and
reuse their temporary-root cleanup. This avoids an extra CI scheduling
group while preserving emitted-byte, source-map and subset-build proof.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

* fix(build): include gateway metadata integration dependencies

Copy the shared record helper into sparse declaration fixtures and use
the canonical supported metadata version in release validation.

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-05 16:43:24 -07:00
Peter Steinberger
7190241939
refactor(test): simplify Vitest launch and project ownership (#139377)
* refactor(test): simplify Vitest launch and project ownership

* fix(test): preserve compiler and report execution boundaries
2026-09-05 14:40:02 -07:00
Peter Steinberger
74ad6ba4f2
chore(release): bring 2026.9.2 release state to main (#139369)
* chore(release): carry shipped 2026.9.2 state onto main

Align main and official plugin versions with the published stable release and
preserve the exact tagged changelog. All ten canonical runtime/qualification
fix commits are already on main; retain its newer SQLite worker and Watch UI.

Refresh generated UI and native locale artifacts through their canonical
owners after provider failures left main's current inventories out of sync.
The release tag and published package bytes remain unchanged.

* chore(release): isolate generated locales from version closeout

Keep release version metadata and the exact published changelog in this PR.
Generated UI locales are covered by #139382; native locales use #139364.
2026-09-05 14:25:55 -07:00
Peter Steinberger
e6a0eb9ff3
fix: recognize 2026.9.3 plugin security release context (#139399) 2026-09-05 14:17:41 -07:00
Vishal Doshi
451ac303f4
perf(gateway): skip provider catalog rewarm on rate limits (#125906)
Carry profile failure reasons through the internal hook and preserve the prepared provider-auth catalog on rate limits. Authentication and billing failures retain the existing recovery path; cooldown recording and profile selection are unchanged.

Cover reason propagation and queued recovery with regressions, plus built-Gateway HTTP429-to-401 proof using synthetic credentials and real SQLite state. CI 33989197791 passed on source head 54c9fd565523b7fca8cfd451ba563d5d2428eade.

Refs #125315. Its separate CLI and device-identity proposals remain follow-ups. Original diagnosis and repair by @Grynn.

Co-authored-by: Grynn <grynn@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-05 13:28:16 -07:00
Vincent Koc
8e5a3f3638
chore(test): migrate to stable Vitest 5 (#138264)
* build(test): migrate to stable Vitest 5

Co-authored-by: Peter Steinberger <steipete@gmail.com>

* docs(test): document Vitest 5 contracts

* test(test): prove Vitest cache invalidation

* test(test): stabilize report config load proof

* test(test): restore Vitest 5 compatibility

Co-authored-by: Peter Steinberger <steipete@gmail.com>

* test(test): isolate pnpm cache fixture registry

* fix(test): keep pnpm 12 env lock portable

* fix(test): preserve explicit Vitest project roots

* fix(test): preserve nested Vitest project identity

* test(test): expect captured Vitest name prefix

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-06 04:17:59 +09:00
Peter Steinberger
a0980b9217
fix(release): avoid latest promotion while updating drafts (#139297)
Leave the latest selector out of existing-draft edits so GitHub does not
reject publication retries with HTTP422. Preserve initial draft creation,
canonical public-page handling and the existing finalization owner.
2026-09-05 12:07:19 -07:00
Jason (Json)
9986044541
feat(agents): allow bounded recursive session spawning by default (#138059)
* Agents: allow recursive session spawning by default

* test: preserve sandbox delegation confinement

* test: accept serialized authority rejection

* test(agents): prove recursive production dispatch

* test(agents): exercise recursive spawn admission

* test(agents): isolate recursive spawn authority suites

* test(agents): avoid duplicate recursive spawn dispatch mocks

* test(agents): serialize isolated runtime mocks

* test(agents): isolate recursive spawn boundary proof

* test(agents): bound recursive spawn proof stages

* test(agents): diagnose spawn boundary admission stalls

* test(agents): use deterministic spawn fixture config

* test(agents): trace spawn proof setup stages

* test(agents): defer gateway graph in spawn proof

* test(agents): defer production proof runtime imports

* test: stabilize recursive spawn production proof

* test: stabilize recursive spawn production proof

* test(agents): track gateway execution in spawn proof
2026-09-05 07:22:28 -06:00
Peter Steinberger
d37ed30158
ci: run prepared real-Gateway suites on two workers (#139081)
* ci: run prepared real-Gateway suites on two workers

* ci: keep the generated harness out of source status
2026-09-05 06:11:25 -07:00
Peter Steinberger
9e75cf16f0
refactor(sqlite): share reliability proof lifecycle (#139058) 2026-09-05 05:41:53 -07:00
Peter Steinberger
2299d11045
chore: update pnpm to 12.3.4 (#139065)
Align source installs, trusted bootstrap, and paired benchmark tooling with the latest pnpm 12 release. Retain the existing application dependency lockfile and benchmark isolation contract.
2026-09-05 05:21:58 -07:00
Peter Steinberger
9010252381
fix: qualify reviewed hardware probes in release checks (#139046) 2026-09-05 04:52:15 -07:00
Peter Steinberger
dbb6e1f00b
feat(macos): connect gateways through browser sign-in and website handoff (#138745)
* feat(macos): connect saved gateways through browser sign-in

* fix(macos): preserve browser session observers across reconnect

* fix(macos): await WebKit cookie deletion

* test(macos): isolate dashboard startup and WebKit cleanup

* fix(macos): preserve browser account ownership across reconnects

Bind native connections and cached queued work to the verified browser account. Retire old account and media authority before replacement or removal, and restore the explicitly selected Gateway after app restart using the existing preference.

Keep removal completion tied to its original owner and correct native test fixtures that assumed unconfigured startup always selected Primary. Release-note context: personal Gateway sign-in now survives restart without changing the machine Primary connection.

* fix(macos): isolate profile notification values

Capture immutable receipt and removal values before entering MainActor callbacks. Remove redundant mutable test state while retaining the real HTTP response gate and explicit deletion wait.

* fix(macos): scope browser stores to credential registries

Use the existing app-profile Keychain namespace in persistent WebKit store identity, so named app profiles at the same Gateway cannot overwrite or clear each other’s cookies. Cover independent persistent cookie replacement and removal.

* test(macos): use localhost for pinned media fixtures

Exercise real TLS through the certificate’s local hostname, retaining exact pins, origin and redirect checks, and cancellation timing. macOS ATS rejects the fixture’s untrusted IP-literal certificate before media authority checks; production trust policy remains unchanged.

* fix(macos): canonicalize gateway URLs before browser discovery

* fix(macos): apply TLS policy to streaming task challenges

* fix(macos): preserve browser state across account renewals

* chore(macos): refresh native localization source inventory

* test(macos): align browser preference fixtures with store lifetime

* fix(macos): initialize reconnect editor from saved gateway

* test(macos): evaluate gateway field predicate before expectation

* style(macos): format gateway editor documentation

* test(macos): retain browser store during account transitions
2026-09-05 03:11:56 -07:00
Vincent Koc
bf90b12fe5
feat(ci): add paired Vitest benchmark (#138937)
* feat(ci): add paired Vitest benchmark harness

* feat(ci): add opt-in Vitest pair mode

* docs(ci): document Vitest pair benchmarks

* fix(ci): enforce paired workload equivalence

* fix(ci): harden Vitest pair process ownership

* fix(ci): verify Vitest benchmark execution

* fix(ci): stabilize Vitest execution digests

* fix(ci): repair Vitest benchmark gates

* fix(ci): align Vitest benchmark acceptance

* test(ci): type-check Vitest threshold assertion
2026-09-05 16:30:50 +08:00
Peter Steinberger
c9ab58e195
fix: stop rejecting plugin-owned build dependencies in release checks (#138935) 2026-09-05 00:43:02 -07:00
Ayaan Zaidi
bfbf880320
fix(doctor): unblock service startup with retired plugin config (#138914)
Preserve validated retired plugin install records in the canonical index before Doctor repairs or restores configuration. Remove the retired key through the normal config writer with source freshness checked under its lock.

Keep malformed records intact, preserve existing canonical ownership and official provenance, and avoid replaying records after registry cleanup.

Installed Doctor and strict service startup pass for empty and populated maps, backups, includes, and repeated repair. Add process, source-change, and runtime-prerequisite regressions.

Closes #138652.

Thanks @worldtrading520 for the report.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-05 12:02:54 +05:30
Peter Steinberger
58d8871d18
refactor(anthropic): replace Agent SDK with direct CLI transport (#138707)
* refactor(anthropic): replace Agent SDK with direct CLI transport

* fix(anthropic): preserve direct CLI invocation contracts

* test(gateway): request exact CLI announcement proof marker

* test(ui): preserve dashboard resolution across navigation

Apply the upstream fixture correction from #138769 so chat startup and dashboard navigation resolve the same session.
2026-09-04 20:51:44 -07:00
Peter Steinberger
cf127a39cb
fix(claws): preserve active and shared agent data during removal (#138693)
* fix(claws): preserve active and shared agent data during removal

* fix(agents): keep session cleanup within deletion ownership

* refactor(state): remove deletion cleanup type cycle
2026-09-04 20:32:24 -07:00
Peter Steinberger
f91bb7b76d
chore(deps): update @openclaw/fs-safe to 0.8.1 (#138500)
* chore(deps): update @openclaw/fs-safe to 0.8.0

fs-safe 0.8.0 stops repairing existing secret-directory permissions and fails closed instead. Wrap OpenClaw secret writes to tighten OpenClaw-owned directory modes before delegating, preserving the documented tighten-then-write behavior. Move the cooldown exclusions to the 0.8.0 family.

* fix(infra): adapt to fs-safe 0.8.0 fail-closed boundaries

- privateFileStore: tighten OpenClaw-owned store roots to 0700 at creation, preserving tighten-then-write behavior for drifted dirs
- doctor transcripts: mask dirMode to permission bits; raw stat.mode includes file-type bits that the strict final directory-mode check rejects
- file-transfer: resolve the symlink canonical target locally when the fs-safe error no longer carries it
- archive test: 0.8.0 preserves the destination when a raced hardlink is rejected (PR197); update assertions

* chore(deps): update @openclaw/fs-safe to 0.8.1 and retain dist-artifact lock on exit

fs-safe 0.8.0 made process-exit sidecar release the default, which broke
the deliberately fail-closed dist-artifact owner record. 0.8.1 adds the
retainOnExit opt-out (openclaw/fs-safe#227); adopt it so only the explicit
release after a joined child removes the record. Also update the whatsapp
session assertion for the conditional parent-directory chmod.

* fix(infra): never chmod through a symlinked secret root

The 0.8.x tightening wrapper resolved rootDir with realpath before its
lstat walk, so a symlinked root had its destination chmodded before
fs-safe could reject the write. Walk the lexical chain instead; any
symlinked component, including the root, is left for fs-safe to reject.
Adds a regression test asserting the destination's mode is untouched.

* chore(deps): narrow the lockfile refresh to the fs-safe bump

The previous lockfile was rebuilt from scratch, drifting unrelated
resolutions. Regenerate from main's lockfile so only the fs-safe family
moves 0.7.2 -> 0.8.1 (temporarily allowing the old entries for the
supply-chain policy check during regeneration).

* fix(infra): pin directory identity through permission tightening

Both 0.8.x permission adapters checked a directory with lstat and then
chmodded it by pathname, leaving a check/use window where a swapped
component redirected the chmod. Open each component with
O_NOFOLLOW|O_DIRECTORY and fchmod the pinned descriptor instead; swapped
or symlinked directories are never mutated and remain fs-safe's to
reject. Adds private-file-store coverage for the tighten and
symlinked-root paths.

* refactor(infra): share descriptor-pinned directory tightening

Both permission adapters now use one module (private-dir-mode): an async
chain walk for secret writes and a sync single-root tighten for store
factories, eliminating the duplicated safety logic. The module documents
the residual same-principal bound: Node has no dirfd-relative open, so
inter-component traversal is by absolute pathname; an actor able to
replace an OpenClaw-owned directory mid-walk already holds write access
to that tree, and fs-safe still validates the final write.

* ci: retrigger checks-ui-e2e on the control-ui runner class

Reruns route to GitHub-hosted runners (run_attempt > 1), where the
dashboard-gallery Playwright test exceeds its 30s locator timeout. The
full shard passes locally (228/228) on this head and the identical UI
code passed CI at 9cbd8c6; a fresh run restores attempt-1 placement.
2026-09-04 20:16:04 -07:00
Peter Steinberger
b78612ac3a
fix(build): bound native declaration inputs to checkout (#138742)
* fix(build): reject cross-checkout native declaration inputs

Refuse ancestor and external dependency inputs before native declaration or package-boundary success records are accepted. Reuse the declared/native path boundary for compiler identity, reads and previous-snapshot keys while preserving consumed-byte, topology, ctime and publication fences. Remove implicit primary-install linking, retaining subdirectory and Windows alias support. The native engine is unchanged; this is fail-before-acceptance rather than hermetic execution. Fixes #138677.

* fix(build): align declaration owners with checkout paths

Use native-canonical namespace and output identities so Windows 8.3 paths
cannot make a declaration owner count its own emitted files as new inputs.
Keep declared cwd ownership for private child joins while snapshots and
publication share physical paths.

Bind the existing declaration-plugin cwd option before plugin construction;
its explicit entry patterns otherwise use ambient cwd and can select no
compiler roots. Preserve explicit overrides and all real receipt, byte,
ctime, topology, inventory, and publication checks.

Cover native short-entry/workspace junction cold and warm behavior, tsdown
alias writers, and explicit entries across node/workspace/AI configurations.

Refs #138677; related #138440.

* test(build): keep remaining compiler fixtures checkout-local

Give the root-lint fixture its own native compiler while retaining real lint tools, ambient types, and source aliases. Keep the shard recorder on its fixture-owned native binary and detach its launcher before replacement. Preserve all diagnostic, enumeration, and signal/join assertions.

Repairs the exact-head CI fixture failure in PR #138742 (native declaration input boundary); production admission remains unchanged.

* fix(build): validate native checkout before bootstrap

Resolve the containing checkout compiler while preserving caller-relative projects. Use the existing native Node shim so refusal and sparse skip precede shared-install or output mutation; keep execution under the artifact owner. Cover actual linked-worktree entries and replace the boundary signal fixture's notification-based readiness with its child-owned PID. Addresses review findings on #138742; preserves strict fail-before-acceptance for #138677.
2026-09-04 19:50:21 -07:00
Peter Steinberger
0229a108fe
chore(release): close out 2026.9.1 on main (#137506)
Set main to the shipped stable version 2026.9.1 (root, apps, plugins, and
version-owned generated metadata via `pnpm release:prepare`), make the
`## 2026.9.1` changelog section identical to the tagged release branch, and
carry the native locale refresh that the release preflight requires.

Release: https://github.com/openclaw/openclaw/releases/tag/v2026.9.1
npm: openclaw@2026.9.1 (latest, beta); 89 @openclaw/* plugins at 2026.9.1.
2026-09-04 17:40:27 -07:00
Peter Steinberger
477b41a201
refactor(build): simplify declaration hooks and regression fixtures (#138683) 2026-09-04 17:17:58 -07:00
Peter Steinberger
0d830e9e74
fix(gateway): keep received work inside its state lifetime (#136146)
* fix(gateway): keep received work inside its state lifetime

Join original WebSocket dispatch, cooperating refreshes and connection cleanup before releasing Gateway dependencies. Retire passive approval/question/run observers without inventing durable decisions, and preserve test state until native callbacks and first browser closes settle.

Remove the unused process-local approval implementation and forwarding adapters. The refactor removes 404 production lines from the initial repair while retaining boundary regressions and moving manager tests onto the real durable path.

Verified under enforced credential-free isolation: 2,143 distinct owner/native/process tests, a final 77-test rerun, changed gates, product/UI builds and scoped-clean Codex P0 review. Protected exact-order browser replay remains a pre-merge gate; historical incomplete audits are not acceptance.

* fix(gateway): join worker cleanup before closing transport

Fence ingress without disconnecting the supervisor needed for worker cleanup,
then join received work before releasing the remaining Gateway dependencies.
Preserve exact pending-node authority during direct and restart shutdown.

Keep startup logging and sidecar acquisition owned independently of fail-fast
readiness, and retire published plugin services only through their actual owner.
Join portal cleanup before reporting sibling shutdown failures.

Record positive test-Gateway closure at its owner. Retain fixture state and
selectors after incomplete shutdown, including across module reload, without
confusing a post-close diagnostic with an unfinished producer. Cover that
boundary through an isolated real-Gateway counterfactual and regression.

Consolidate UI finalization with the shared QA cleanup owner and separate the
lazy handler registry from dispatch without changing loading or method order.
Derive handler families from typed descriptor rows and remove the old casts.

Follow-up repair for the state-lifetime boundary in #136145 and #136146.

* fix(gateway): fence worker frames during ordinary close

Reject newly received worker frames once their connection generation starts closing, while retaining queued work and its completion owners. Cover the live-socket window through the real worker protocol and a checked synthetic node sink.

Synchronize the update-failure UI test with its intended Updates recovery navigation before reopening the Inbox.

Follow-up for #136146 (Gateway received-work lifetime), addressing the shutdown-admission gap from review.

* fix(browser): join SDK-initiated MCP transport cleanup

Route SDK initialization failure and transport close through the existing
Chrome MCP process owner before native close clears the child PID. Capture
the native closer separately so concurrent callers join one cleanup path
without recursion or losing descendant ownership.

Collect startup diagnostics after cleanup and stderr completion, while
never-spawned commands skip the unused pipe. Preserve cleanup failures and
the existing launch, environment, and process-group behavior. Exercise late
stderr, descendant cleanup, forced termination, ENOENT, and backpressure
through real subprocesses.

* fix(gateway): retain supervisors after worker shutdown failure

Require connection-dependent sidecars to stop successfully before draining their supervisor transports or releasing runtime dependencies. Cover public and startup-failure shutdown, retained-owner retry, and late sidecar registration.

* test(gateway): join policy writers after releasing handler gates

Preserve policy-revocation and response-order coverage under the received-work dispatcher completion contract. Retain all held calls and release/join them in finally so tests cannot wait on their own unreleased gates.

* fix(gateway): retain execution through required shutdown

Preserve early acknowledgements while joining original raw, typed, and
agent execution through final cleanup. Cancel this Gateway's runs before
the join, and fence late admission at controller publication.

Retain failed startup acquisitions and plugin cleanup owners, preserve both
startup and cleanup errors, and prevent CLI successors after incomplete
retirement. Keep deferred startup hooks and sentinel refresh in their owner.
Remove the monolithic close factory and redundant post-abort polling.

Declare compiled plugin dependencies for the full lifecycle fixture through
the existing pretest owner. Align the QA publishing reference with main.

Validated isolated before/after regressions, original-order execution,
startup/CLI/plugin suites, full build, types, lint, and Codex review.
The protected metadata audit remains unaccepted; this is not merge approval.

Refs #136145, #136146.

* test(agents): align Code Mode fixtures with main

Adopt the SessionManager fixture and structured-result classification from
#138238, preserving the attempted hidden namespace call and the checks that
neither the original preparer nor action executes. Remove redundant pass-through
mocks with the upstream fixture.

Both files match the successful upstream CI head ce42af56a82f exactly. Gateway
runtime code is unchanged; this resolves the parallel test-fix merge conflict.

* test(gateway): reuse tracked agent contexts

Replace three partial agent-handler contexts with the shared fixture. The missing
execution tracker threw after admission handoff and leaked session claims into
later continuation tests. Preserve their assertions, timers, and original order.

The complete 302-case file reproduces all six CI failures before this repair and
passes afterward in the same order. Type checks, type-aware lint, formatting,
and independent Codex review pass. No production code changes.

* test: fix gateway, Signal, and UI fixture lifetimes

Reset agent database handles, validation, and terminal latches only within
retired fixture roots before deleting or recreating their files. Preserve
ordinary runtime reopen behavior and unrelated roots.

Model the pending host question in Signal's partial-delivery fixture and
assert the accepted reaction binding. Use actual Settings navigation from
independent cold UI contexts so document reloads do not abort startup
scripts and masquerade as asset failures. Preserve existing assertions.

Reproduced the Node and Signal failures locally and the UI cancellation on
Linux. The Linux owner replay passes 30 tests across six files, the full
settings suite passes seven, and the final UI revision passes both cold
routes locally. Static checks and independent source review pass. The
isolated native fixture still times out on this Mac; Linux completes its
unchanged case in 13 seconds. Protected audit acceptance and final-head
hosted checks remain separate landing requirements for PR #136146.

* test(sessions): call database reset without hook context

Wrap the participant suite teardown in a zero-argument callback. Vitest
passes TestContext to registered hooks; the reset helper now accepts an
optional root path for selective fixture retirement.

The full seven-case file reproduced four teardown failures before this
change and passes all seven afterward. Assertions and cleanup semantics
are unchanged. The callback audit found no other direct registrations.

Refs #136146, #136145.
2026-09-04 16:02:31 -07:00
Peter Steinberger
e8c911a173
ci: avoid duplicate browser test work (#138496)
* test: skip unused real-gateway proof captures

* ci: run UI end-to-end tests only in their selected jobs

* test: reuse the page-owned Mermaid renderer across cases
2026-09-04 15:07:50 -07:00
Peter Steinberger
2329399cf6
fix(build): keep nested checkout declarations on pinned local inputs (#138440)
* fix(build): keep declaration inputs inside their checkout

Keep tsdown declaration resolution pinned to the declared checkout in nested
worktrees, including explicit and automatic type references, resolved dts
options, independent CommonJS emission, and relative compiler filesystem calls.

Preserve complete actual Program receipts, CompilerInputSnapshot mutation
checks, joined compilation, and staged publication. In-checkout pnpm links
remain supported; shared external declaration inputs fail explicitly.

Add real nested-checkout, lifecycle, override, cwd, mutation, and publication
regressions. Native tsgo declaration ownership remains a separate follow-up.

Fixes #138408

* fix(build): preserve native checkout identity in declarations

Normalize only the declared checkout prefix so Windows short and long path
spellings share one input owner without admitting ambient ancestor links.
Validate original Program members before projecting complete receipts.
Keep CompilerInputSnapshot and staged publication unchanged.

Cover real directory and Windows 8.3 aliases, preserve rejection of ancestor
symlinks pointing inside, and register the resolution suite in Windows CI.

Follow-up to the Windows failure in the declaration containment repair:
https://github.com/openclaw/openclaw/pull/138440
https://github.com/openclaw/openclaw/issues/138408

* fix(build): recognize symlink-resolved checkout prefixes

Map both the declared checkout and its symlink-resolved spelling onto one
native root, without canonicalizing arbitrary outside candidates into scope.
This covers junctions whose targets retain Windows short names.

Use native fixture roots for physical-path assertions and preserve explicit
three-spelling regressions with junction-to-8.3 and case-alias targets. Let
cmd.exe own its quotes in the controlled short-name query.

Keep CompilerInputSnapshot, complete receipts, and publication fences intact.
The real three-spelling regression fails before the owner correction and
passes after it; the full local resolution matrix passes 17 cases with two
Windows-only cases awaiting native CI.

https://github.com/openclaw/openclaw/pull/138440

* fix(ci): accept valid zero-RSS scanner samples

Linux can release a task's memory before its zombie state becomes visible.
Treat zero as a measured value instead of poisoning the scanner's failure
category. Keep negative/invalid samples fail-closed, and preserve all limits,
process-group accounting, cleanup, and exact report identities.

Add a real-CLI, readiness-coordinated regression for zero and four invalid
sample classes. The zero case fails before the comparison repair. All 23
scanner tests pass on Linux Node 24.19; 20 baseline and 20 fixed natural OOM
probes pass, but do not reproduce the original race, whose row was not logged.

Bounded CI repair discovered while landing declaration containment:
https://github.com/openclaw/openclaw/pull/138440
2026-09-04 14:32:14 -07:00
Peter Steinberger
818f1c72db
ci: run CLI tests with fewer jobs and builds (#138297)
* ci: share runtime builds across serial CLI test groups

* ci: pack serial CLI tests into fewer jobs
2026-09-04 13:44:53 -07:00
Peter Steinberger
52644b7af6
fix(talk): avoid full plugin imports during cold catalog discovery (#138483)
* fix(talk): avoid full plugin imports during cold catalog discovery

Use optional capability catalog entries backed by the same provider factories and native host operations as full registration. Preserve prepared generations, active descriptors, installed-plugin registration, and explicit empty-family semantics. Account for exactly three approved public catalog type exports.

* fix(plugins): complete cold catalog boundary integration

Keep catalog descriptors separate from native host-operation types, and
move DeepInfra shared model types and constants to their leaf owner.
Recognize manifest-loaded catalog entrypoints and remove the unused xAI
transcription wrapper while retaining the production factory tests.

Preserve real module exports under existing test overrides. Keep all
assertions, deadlines, public SDK exports, and approved budgets unchanged.
2026-09-04 13:21:21 -07:00
Peter Steinberger
06e8922367
perf(ui): defer login recovery text until needed (#138529)
Load unchanged recovery copy with its lazy consumers while preserving the eager subtitle and ordered source catalog.

Startup gzip drops from 350386 to 348859 bytes under the unchanged 350141-byte limit. Full changed checks, 85 focused tests, production-bundle browser proof, and independent P0-P2 review pass.
2026-09-04 12:58:36 -07:00
Peter Steinberger
26f87a3700
fix: allow environment-only agent runs without a native harness (#138449)
* fix: allow environment-only agent runs without a native harness

* chore(ui): reconcile measured main startup baseline

Unmodified main b6a4d0dad4 fails the startup gzip check at 350377 B in Linux CI; a pristine source build measures 350363 B. Record the measured main baseline while retaining the fixed cap and existing growth and variance allowances.
2026-09-04 11:37:51 -07:00
Peter Steinberger
6a97159ece
feat: add experimental plugin UI customization (#134943)
* feat: let plugins customize the Control UI

* fix: harden feature plugin lifecycle and artifact activation

* fix(plugins): complete native UI integration

* fix(plugins): preserve hook ownership and composer styling

* chore(workboard): refresh generated browser assets

* test(android): hold reconciliation replies until delivery checks

* refactor(plugins): simplify feature UI ownership

Share bundle validation and scoped host-handle cleanup. Consolidate
Workboard component and draft-save lifecycles, and remove unreachable
loading/enablement paths and retired select styles.

Keep both compiler regression matrices through shared fixtures, remove
duplicate tests, and regenerate the reduced locale catalog and browser
asset references.

* test(ui): return session snapshots from worker stop fixtures

* fix(ui): hydrate session rosters from selected agents

Use the application selection owner for bootstrap and reconnect, retain its filtered query for later refreshes, and remove duplicate sidebar refreshes. Cover delayed bootstrap, saved selection, and offline selection changes.

Refresh generated protocol and browser assets after the rebase, and share hydration fixtures and roster reconciliation helpers.

* perf(ui): defer plugin initialization and customization

Load plugin assets with the existing lazy SDK host and load customization controls on demand. Keep activation cleanup with the runtime and preserve dialog reload state across close and reopen.

Remove retired Workboard selectors, move glyph styling into the plugin, and regenerate its browser revision. Preserve the existing startup payload limits.

* refactor(ui): separate native asset loading from host services

* test(plugins): align UI integration with current main

Refresh canonical Workboard assets and the Control UI boot inventory after rebasing. Match the current bootstrap signature, delegated permission policy, and widget Delete label in existing regressions.

* chore(workboard): refresh browser revision after rebase

* chore(ui): refresh generated assets after main sync

* fix(plugins): preserve native UI lifetimes after main sync

Keep saved plugin panels closable while their registration is unavailable and prevent actions withdrawn during resolution from starting. Defer native view mounting code through plugin activation while preserving synchronous built-in rendering.

Integrate the shared Dashboard side-panel lifecycle, remove the session helper type cycle, reuse core Gateway classification, and consolidate menu coverage. Refresh generated assets after the main rebase.

Validated with focused Gateway/UI tests, failing/passing lifetime regressions, 14 browser scenarios, typechecks, lint, cycle and assertion guards, and the enforced Control UI performance check.

* chore(ui): refresh boot manifest after main rebase

* chore(ui): refresh feature integration after main update

Preserve current composer admission and sidebar ownership while adopting the canonical formatter output and browser assets. Complete the existing panel fixture with the new desktop-focus contract.

* test(ui): verify native plugin asset admission

* test(ui): await service worker activation in phone proof

* refactor(plugins): remove redundant UI plumbing

* feat(plugins): gate custom UI behind an experimental lab

* fix(plugins): align Labs helper types with callers

* style(ui): format retained plugin panel definitions

* test(ui): preserve minimized dashboard in native plugin flow

* fix: preserve plugin UI edits and refresh ordering

Synchronize reapplied template fields, fence shared widget reads across moves, and retain newer mutation errors through queued refreshes. Verify immutable browser assets when Windows reports a directory collision. Keep the checkout helper terminal exit outside exception handlers to avoid Python 3.9 context-cycle hangs.

* test: align plugin UI proof with current panel layout

* test: repair plugin UI validation and generated checkout helper

* test: bind session search fixtures to their selection owner

* fix: preserve session search ownership and execution denial proof

* test: use a real page element for plugin sidebar fixtures

* fix: respect native plugin UI deployment boundaries

* test: share UI fixture isolation across runners

* refactor: share the native plugin asset root

* test: check failure trailers on their owning stream
2026-09-04 09:50:51 -07:00
Peter Steinberger
cbaa21e6e3
feat(gateway): apply more settings without restarting (#138112)
* feat(gateway): apply more settings without restarting

Use one typed reload catalog and refresh retained resources through their
lifecycle owners. Stage internal hook replacement before publication,
drain old plugin channel generations, and keep failed teardown fenced.
Read current policy for retained tools, update checks, and cleanup sweeps.

Preserve stable in-place upgrade helpers and explicit per-run config.
Expand operation-based Gateway proof and regressions for stale owners,
source loss, precedence, manual stops, and pending account startup.

Related: #137591, #137706, #126547, #119444

Co-authored-by: NianJiuZst <180004567+NianJiuZst@users.noreply.github.com>
Co-authored-by: Yalçın Doksanbir <yalcindoksanbir@gmail.com>

* style(diffs): place snapshot invariant beside its assertion

* fix(gateway): keep reload auth lazy and simplify runtime owners

Avoid eager provider discovery on the Gateway event loop during config reload.
Keep prepared-auth invalidation and resolve the next provider auth lookup on demand.
Use the startup workspace owner for multi-agent internal hooks and remove the
unused reload barrel while retaining the shipped stable lazy-import entry.

Exercise config and auth changes through real Gateway fixtures, cancel their
restart timers during teardown, and preserve exact array replacement intent in
the live QA harness.

* test(gateway): clarify real config RPC fixture types

* test(gateway): align hot reload proof with runtime owners

Prepare built plugins before the real config suite, enable the intended fixture surfaces, and preserve explicit policy replacement and restoration. Keep identity databases within their cleanup owners so the long live run cannot retain a deleted WAL.

* fix(test): preserve config ownership during runtime admission

* test(browser): isolate periodic cleanup from managed tab caps

* fix(test): share UI mock isolation policy across runners

---------

Co-authored-by: NianJiuZst <180004567+NianJiuZst@users.noreply.github.com>
Co-authored-by: Yalçın Doksanbir <yalcindoksanbir@gmail.com>
2026-09-04 07:56:33 -07:00