Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.
Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.
The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.
The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.
Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.
Refs #144758#144901#144890#143292#146637#145252. Preserves the activation boundary from #147019.
* fix(runtime): gate node:sqlite on a NUL round-trip capability probe
Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465#140672.
* fix(runtime): expose capability diagnostics through doctor
Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.
* fix(update): preserve target Node version requirements
* fix(install): remove unused Node major probe state
* feat: offer Node.js updates when the CLI runtime is incompatible
* fix: include Node runtime recovery in duplicate scans
---------
Co-authored-by: Morrow <morrow@bluedot.it.com>
* fix(update): replace unsupported Gateway service Node runtimes
Treat unsupported recorded Node versions as a required service refresh,
prefer the supported CLI runtime, and preserve existing force and ownership
boundaries. Report successful Node replacement through POSIX installers
without exposing incidental child output.
Cover launchd/systemd definition repair and the target-engine guidance
already corrected by #142322.
Refs #107930
* fix(daemon): replace missing Gateway service Node on install
Recover missing or non-executable recorded Node paths through the existing
supported-runtime selection and service install plan. Keep genuine probe
failures actionable with the recorded path and a force-install hint, and
recognize the missing-runtime notice in the POSIX installers.
Refs #107930
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures
Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.
Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.
* fix(scripts): keep guarded portable scripts bash 3.2 compatible
* fix(scripts): keep macOS Bash CI coverage green
Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.
Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.
* docs(install): use system Bash in install and recovery commands
Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.
Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.
* fix(scripts): preserve streamed installs and CI packing
Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.
Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.
Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
* fix(runtime): require Node builds with lossless SQLite reads
* fix(runtime): preserve upgrades and guard sealed workers
Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.
* test(runtime): use typed process exports in worker fixture
* test(runtime): align installer fixtures without growing test shards
* test(runtime): align release and guest runtime fixtures
* fix(test): canonicalize Windows temp roots for Node 24
Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.
* test(ci): run Windows temp-root regressions in the native lane
Align source installs, trusted bootstrap, and paired benchmark tooling with the latest pnpm 12 release. Retain the existing application dependency lockfile and benchmark isolation contract.
Match local tarball lifecycle approvals to npm's normalized absolute file
identity across the installers and updater. Preserve directory links and the
shipped npm 11 advisory comma-path behavior without overriding npm policy.
Bind the mandatory npm 12 acceptance job to the already verified prepared
plugin registry so unpublished candidate dependencies do not require early
publication. Keep source, manifest, artifact and producer identities intact.
Update installer documentation and regression coverage, including the
Git-source-to-packed-tarball update path and its observed version outcome.
## Problem
A pnpm 11 global update from OpenClaw 2026.7.1-2 to 2026.8.1 fails verification and rolls back. The 2026.8.1 package puts `openclaw-install-guard` inside `dist/`, but the old updater treats every uninventoried `dist/` file as invalid.
## Root cause
Package lifecycle state was stored inside the closed `dist/` inventory. That made a valid pending lifecycle marker look like package corruption to an older updater.
## Fix
- Store pending lifecycle state at package root as `.openclaw-lifecycle-pending`.
- Let postinstall remove the marker only after all lifecycle work succeeds.
- Use one lifecycle completion owner from the updater, `dist/index.js`, and `openclaw.mjs`.
- Keep the lifecycle lock valid beyond the full preinstall and postinstall timeout budget.
- Keep temporary recovery support for the 2026.8.1 `dist/openclaw-install-guard` path.
- Keep source package preparation and worker package generation aligned with the new marker contract.
## Product proof
- Red: a published 2026.7.1-2 pnpm 11 install rejected the published 2026.8.1 package with `unexpected packaged dist file dist/openclaw-install-guard`, exited nonzero, and remained on 2026.7.1-2.
- Green: the built candidate passes the old-updater upgrade path, the pnpm 11 lifecycle-repair path, a forced postinstall failure and retry, and native npm controls.
- Anti-cheat: the proof checks the installed CLI version before and after the update.
## Validation
- `node scripts/run-vitest.mjs src/infra/package-lifecycle.test.ts src/infra/package-update-steps.pnpm11-guard.test.ts src/index.entrypoint.test.ts`
- Focused lifecycle, updater, tarball, postinstall, inventory, and entrypoint suites: 176 tests passed.
- Exact-head lifecycle lock suite: 4 tests passed, including the old 20-minute expiry boundary.
- Remote core and scripts checks passed.
- `git diff --check`
- GitHub CI is the full release and platform gate.
## Scope
- Production and release-tooling delta: +370/-162, net +208.
- Test and CI support delta: +370/-84, net +286.
- The production growth adds the shared lifecycle owner, crash-safe retry marker, and concurrent-launch lock. It removes the updater-only lifecycle sequence and keeps the closed `dist/` verifier unchanged.
- Sibling coverage: updater, package launcher, legacy package entrypoint, installers, tarball validator, worker bootstrap package, and Docker package preparation.
## ClawSweeper
- No actionable code findings.
- Rank-up skip: the package-upgrade trace came from an internal isolated runner and is not suitable for a public log attachment. Exact-head GitHub CI and the focused regression commands above remain the public proof.
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
- install-cli.sh --set-npm-prefix wrote an over-escaped PATH line: the
backslash-escaping expanded PATH at install time, appending a literal
\"-quoted, frozen PATH snapshot to .bashrc/.zshrc that never resolves
the npm-global bin dir. Use the same correct form as install.sh.
- install.sh finalization helpers (retire_npm_owner_after_git_install,
retire_git_wrapper_after_npm_install) could abort the install with
exit 1 and no output; each fatal path now prints an actionable error.
- prepare_git_wrapper_backup_for_npm no longer hard-fails when npm is
missing (Arch splits node/npm): there is nothing to back up, and the
npm install step already reports the missing npm with remediation.
- install-cli.sh --compatible-with with an unresolvable --version died
silently through set -e before its error message; the failed npm view
now reaches the explicit fail path (and the JSON error event).
Pair packaged apps with complete private arm64 and x86_64 workers whose full build identity matches the app. Preserve independently managed Gateways and complete recognized native-first state through the canonical initializer. Verify emitted-SDK filesystem calls, native capabilities, readiness and shutdown before app publication.
Derive elevation payloads without modifying canonical installed inputs. Preserve universal slices, resources and contained links; reject incomplete, malformed, escaping or mismatched payloads. Reuse descriptor-bound native inventory for signing while retaining the portable installer's independent distribution contract and every Foundation identity, entitlement, notarization and architecture gate.
Use the existing pinned-pnpm package path, including Corepack-only builders, and avoid recursive app-glob expansion. Centralize Mac CI ownership. Carry invocation-owned Git lock cleanup into main's canonical Git owner and regenerate its workflow projection, retaining lifetime fencing and pre-existing/junction-linked locks.
Fix the Android refresh race exposed by CI by removing the redundant reconnect after connect already replaces each role's socket. Preserve authentication, scopes and physical connection leases, with a controlled real-WebSocket regression.
Closes#131459
* fix(installer): isolate source bootstrap from ambient pnpm
Select temporary checkout-pinned launchers for source installs and nested builds without changing global tools. Preserve caller context and document the Corepack prerequisite and first-hop update constraint.
* test(installer): exercise native Windows pnpm bootstrap
Cover scoped Corepack and exact npm-prefix bootstrap, child context, failure cleanup, and caller environment restoration under native PowerShell. Include the installer owner tests in the existing Windows CI shard and test-only routing.
* fix(installer): preserve native Windows argument and environment boundaries
* fix(updater): preflight the fetched pnpm pin before checkout changes
* test(installer): normalize native wrapper publication paths
* fix(installer): restore commit-pinned source installs
Restore literal commit selection without weakening qualified branch/tag resolution. Anchor installer upgrade tests to the selected version so newer publications cannot silently turn them into downgrade proof.
Fixes#132456
* fix(installer): resolve Corepack shims from the target checkout
* test: drop superseded media migration fixture extraction
* build: migrate tooling and source installs to pnpm 12
Pin the verified native toolchain without changing application dependency
versions. Preserve the existing release-age policy explicitly and separate
package-manager lock metadata from the application dependency graph.
Use exact checkout pins for bootstrap and rollback, approve only the native
pnpm installer where npm requires it, and retain global install ownership
without equating the CLI major to the storage layout. Verify the Docker
runtime toolchain offline as its non-root user.
Remove duplicate bootstrap paths and obsolete prune input, update native
CLI flags and regression fixtures, and preserve UTF-8 in macOS Bash
installer NDJSON output.
* fix(build): isolate production dependency installs for pnpm 12
Build production dependencies from the same frozen manifest inputs instead
of pruning the inherited development tree. pnpm 12's native hoisted
importer cannot rename lower-layer OverlayFS directories during pruning.
Preserve native addon outputs, workspace builds, and offline non-root
Corepack use while deleting the obsolete production-store seeder.
Exercise runtime assembly and explicitly consent to the local agent-plugin
E2E fixture under the current plugin capability contract.
Validated full Matrix image and offline non-root runtime, focused Docker
regressions, full checks with test types and architecture, docs, real
agent-plugin gateway E2E, and isolated Codex autoreview.
* test: align package smoke with pnpm 12 global installs
* test: follow native pnpm artifact approval in distribution guard
* test: modernize pnpm fixtures for v12
* test: align rebased update fixtures with pnpm 12
* test: retain sanitized upgrade restart diagnostics
* test: expose CI navigation failures and register diagnostics
* test: retain post-core outcomes and plugin artifact identity
* chore(tooling): group upgrade diagnostic entrypoints
* fix(update): support native pnpm global installs and source links
Qualify local source and archive specs, carry verified global ownership through pnpm configuration, and verify intentional checkout links with shared runtime-readiness checks. Preserve strict packaged-install verification and manager ownership safeguards.
Verified the production updater with pnpm 11.22 and 12 using default and custom roots, source links, and tarball updates.
* test: preserve survivor diagnostics after service sealing
Promote incomplete exit-zero runs before failure capture and exercise the sealed-service manager fixture without inventing successful child exits.
* fix(update): preserve legacy pnpm global ownership
Carry the verified root and bin through both pnpm and npm configuration dialects after original-environment probes. Real pnpm 10 custom-root updates and pnpm 11/12 source and tarball matrices pass without redirecting the caller or weakening ownership checks.
* test(update): verify wizard consent through checkout handoff
Use the prepared checkout and fresh-process finalization boundary introduced by the updater repair. Preserve explicit consent forwarding before and after the wizard subcommand without assuming plugin callbacks run in the old process.
* refactor(update): validate checkout build metadata records
Use the canonical record coercer instead of carrying an unchecked assertion into the shared runtime verifier. Remove the now-unused grandfathered assertion entry; no allowance is added.
* docs(sandbox): document standalone common-image inputs
* test(packaging): account for required native prebuilds
Align installer and release size budgets at 235 MiB for the required native payload added on main. Keep both loader layouts, upstream binaries, explicit overrides, and missing-data rejection intact. Exercise actual defaults and the one-byte boundary. Retain bounded stderr diagnostics for the intermittent Bun signal test without claiming a production signal fix.
* test: align refreshed installer fixtures with pnpm 12
* fix(test): share Bun smoke force-kill ownership
Record the successful force-kill once across the timer and post-close drain. Native Darwin traces reproduced both duplicate-signal orders; genuine permission failures and uncleared groups still fail without extending deadlines.
Source installs must select the requested release commit and leave existing checkouts recoverable when updates fail.
This change qualifies Git refs, carries ref mutability into lockfile selection, restores conflicting rebases, and verifies unchanged state when a pre-rebase hook refuses before rebase metadata exists.
Co-authored-by: Jason O'Neal <jason.allen.oneal@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
Separate code-update ownership, effective launcher identity, native service control, and definition mutation. Guard actual definition publication before related config or token writes, and use the installed CLI's preserve-definition restart with renewed ownership and live port/version/build verification.
Consolidate unit/environment publication and conditional rollback, retain main's plugin convergence and fresh-Doctor ownership, and make post-core child termination belong to the winning completion path. Integrate current-main heap-argument provenance and process-marker handling; resolve the service Node from the executable rather than counting backward through flags.
Retain boundary-level sealed/writable/unknown/foreign, mount, platform, failure, and build-identity proof while consolidating redundant tests. The QA cleanup removes 399 maintained test/support lines; focused current-main integration proof passes 1,279 tests with one pre-existing platform skip. Production and installer growth remains +239 net.
Preserves the reviewed repair from ac86fdff61da9c0fea9f62da00a8c9f22df6790d while integrating main at 56d89073dd. No permission weakening, schema or lease policy change, deployment, or release.
The Linux desktop companion could complete a CLI install and still claim
'Installation did not finish' with circular update advice, discarding the
real failure. Verified end-to-end in a clean Ubuntu VM across all three
release channels:
- cli.rs: failed CLI commands now surface their stderr tail (deduped, last
12 lines) instead of being mislabeled as JSON parse failures.
- gateway.rs: missing dashboard --json support maps to an honest curated
message pointing at Beta/Development channels, not a circular npm-update
hint.
- main.rs: run 'doctor --fix --non-interactive' right after install so the
CLI repairs config/state before Gateway readiness checks; wrap
post-install failures as 'installed, but connecting failed: <reason>'.
- installer.rs: keep structured step events out of the prose failure tail.
- ui/main.js: humanize streamed install steps, render real errors on the
failure screen, and always offer Reinstall from connection failures.
- scripts/install-cli.sh: service refresh uses 'gateway status --json' with
the bundled node runtime, corepack failure falls back to npm, dev channel
clones with --filter=blob:none.
Fresh Dev installs now preflight disk space and stream honest stages, while Codex activation probes the refreshed request-scoped registry.
Closes#120779Closes#120780
* fix(install): reject runtimes with broken npm
* test(installer): use real Node for npm selection
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* fix: clarify SQLite version error message to prevent user confusion
The error message "3.44.6+" was misinterpreted by users as meaning "3.44.6 and above",
when it actually means "3.44.6+ for the 3.44.x series only". This commit clarifies the
error message to explicitly state that only specific patched versions (3.44.6+, 3.50.7+,
and 3.51.3+) are safe, and that SQLite 3.46.1 is not among them.
Changes:
- Update error message in src/infra/node-sqlite.ts to clarify version requirements
- Update test expectations in src/infra/node-sqlite.test.ts to match new error format
- Fix unnecessary template literal expressions flagged by oxlint
The code logic remains unchanged - SQLite 3.46.1 is correctly rejected as unsafe.
* fix: clarify SQLite version error message to prevent user confusion
The previous error message stated '3.44.6+' which users misinterpreted as
'3.44.6 and above', leading to confusion when versions like 3.46.1 were rejected.
The new message explicitly states '3.44.6+ in the 3.44.x series' and
'3.50.7+ in the 3.50.x series' to make it clear that only specific
minor version series received the WAL-reset bug fix.
This matches the SQLite team's actual fix announcement which only
backported the fix to 3.44.x and 3.50.x series, plus 3.51.3+.
* fix(sqlite): align unsafe version diagnostics
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>