Commit graph

63 commits

Author SHA1 Message Date
Vincent Koc
305bcbe12d
fix(install): preserve empty PATH search entries (#147249) 2026-09-14 03:46:26 +08:00
Vincent Koc
4d6ebf94e6
fix(install): preserve runtime links when Node validation fails (#147221)
* fix(install): preserve runtime links when Node validation fails

* fix(install): preserve relative runtime targets and empty aliases

* test(install): preserve runtime fixture tuple types
2026-09-14 03:17:04 +08:00
Vincent Koc
c2eb6a2a0e
fix(install): use system Node for FreeBSD CLI setup (#147204)
* fix(install): use system Node for FreeBSD CLI setup

* test(install): use system Bash for sourced macOS fixtures
2026-09-14 02:43:28 +08:00
Peter Steinberger
290613f538
fix(update): derive update budgets from measured state instead of fixed literals (#145219)
Derive update inspection, candidate startup, activation, and finalization allowances from measured SQLite state, observed startup, plugin count, and the caller's step budget. Forward the owning allowance through service commands, readiness, Doctor, and migrated finalization instead of imposing competing short cutoffs. Keep metadata and progress probes cancellable in child processes.

Preserve update-activation-timeout settlement, integrity checks, live authority, and unsettled-writer ownership. Expiry alone never authorizes rollback, restart, or lease release. Installer network operations share the documented allowance. No new configuration, dependencies, schema, retries, or persistent retention/recovery semantics.

The activation regression failed with the original resolver and passed with the repair; focused proof passed 102 tests in six files. Native POSIX FIFO cancellation and Chrome boundary proof are recorded in the PR. CI 34767727811 passed 129 jobs with 11 skips on a verified current-base merge checkout. The final refresh commit is tree-identical to the reviewed source.

The maintainer accepts longer recovery waits and the incomplete slow-state published-driver/native Windows recovery qualification. An already-installed driver retains its loaded timers; containing-release delivery and reporter recovery remain unverified.

Reported by @rlosito (#146637); the initiating timeout cause remains unproved. Related update-timeout reports are tracked in #145252.

Refs #144758 #144901 #144890 #143292 #146637 #145252. Preserves the activation boundary from #147019.
2026-09-13 09:41:59 -07:00
Peter Steinberger
8c4ad0b2da
fix(macos): recover CLI setup from temporary directory permission errors (#146730) 2026-09-12 21:41:24 -07:00
Peter Steinberger
bf6f74b280
fix(runtime): gate node:sqlite on a NUL round-trip capability probe (#143312)
* fix(runtime): gate node:sqlite on a NUL round-trip capability probe

Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465 #140672.

* fix(runtime): expose capability diagnostics through doctor

Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.

* fix(update): preserve target Node version requirements

* fix(install): remove unused Node major probe state
2026-09-09 13:32:29 -07:00
Jason O'Neal
cec6d16175
feat: offer Node.js updates when the CLI runtime is incompatible (#142742)
* feat: offer Node.js updates when the CLI runtime is incompatible

* fix: include Node runtime recovery in duplicate scans

---------

Co-authored-by: Morrow <morrow@bluedot.it.com>
2026-09-09 10:56:55 -07:00
Peter Steinberger
fe79d36c0d
fix(update): replace unsupported Gateway service Node runtimes (#143159)
* fix(update): replace unsupported Gateway service Node runtimes

Treat unsupported recorded Node versions as a required service refresh,
prefer the supported CLI runtime, and preserve existing force and ownership
boundaries. Report successful Node replacement through POSIX installers
without exposing incidental child output.

Cover launchd/systemd definition repair and the target-engine guidance
already corrected by #142322.

Refs #107930

* fix(daemon): replace missing Gateway service Node on install

Recover missing or non-executable recorded Node paths through the existing
supported-runtime selection and service install plan. Keep genuine probe
failures actionable with the recorded path and a force-install hint, and
recognize the missing-runtime notice in the POSIX installers.

Refs #107930
2026-09-09 08:26:48 -07:00
Peter Steinberger
299ea7c393
fix(scripts): run macOS tooling under /bin/bash and make the framework-merge fixture self-contained (#141884)
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures

Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.

Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.

* fix(scripts): keep guarded portable scripts bash 3.2 compatible

* fix(scripts): keep macOS Bash CI coverage green

Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.

Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.

* docs(install): use system Bash in install and recovery commands

Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.

Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.

* fix(scripts): preserve streamed installs and CI packing

Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.

Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.

Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
2026-09-08 01:21:30 -07:00
Peter Steinberger
ce0e84d073
fix(runtime): require Node builds with lossless SQLite reads (#140672)
* fix(runtime): require Node builds with lossless SQLite reads

* fix(runtime): preserve upgrades and guard sealed workers

Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.

* test(runtime): use typed process exports in worker fixture

* test(runtime): align installer fixtures without growing test shards

* test(runtime): align release and guest runtime fixtures

* fix(test): canonicalize Windows temp roots for Node 24

Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.

* test(ci): run Windows temp-root regressions in the native lane
2026-09-07 10:31:31 -07:00
Peter Steinberger
2299d11045
chore: update pnpm to 12.3.4 (#139065)
Align source installs, trusted bootstrap, and paired benchmark tooling with the latest pnpm 12 release. Retain the existing application dependency lockfile and benchmark isolation contract.
2026-09-05 05:21:58 -07:00
Peter Steinberger
a944ac24d5
fix(install): qualify npm 12 archives and prepared plugins (#136316)
Match local tarball lifecycle approvals to npm's normalized absolute file
identity across the installers and updater. Preserve directory links and the
shipped npm 11 advisory comma-path behavior without overriding npm policy.

Bind the mandatory npm 12 acceptance job to the already verified prepared
plugin registry so unpublished candidate dependencies do not require early
publication. Keep source, manifest, artifact and producer identities intact.

Update installer documentation and regression coverage, including the
Git-source-to-packed-tarball update path and its observed version outcome.
2026-09-02 07:14:46 -07:00
Ayaan Zaidi
ae3aff5c28
fix(update): complete package lifecycle outside dist inventory
## Problem

A pnpm 11 global update from OpenClaw 2026.7.1-2 to 2026.8.1 fails verification and rolls back. The 2026.8.1 package puts `openclaw-install-guard` inside `dist/`, but the old updater treats every uninventoried `dist/` file as invalid.

## Root cause

Package lifecycle state was stored inside the closed `dist/` inventory. That made a valid pending lifecycle marker look like package corruption to an older updater.

## Fix

- Store pending lifecycle state at package root as `.openclaw-lifecycle-pending`.
- Let postinstall remove the marker only after all lifecycle work succeeds.
- Use one lifecycle completion owner from the updater, `dist/index.js`, and `openclaw.mjs`.
- Keep the lifecycle lock valid beyond the full preinstall and postinstall timeout budget.
- Keep temporary recovery support for the 2026.8.1 `dist/openclaw-install-guard` path.
- Keep source package preparation and worker package generation aligned with the new marker contract.

## Product proof

- Red: a published 2026.7.1-2 pnpm 11 install rejected the published 2026.8.1 package with `unexpected packaged dist file dist/openclaw-install-guard`, exited nonzero, and remained on 2026.7.1-2.
- Green: the built candidate passes the old-updater upgrade path, the pnpm 11 lifecycle-repair path, a forced postinstall failure and retry, and native npm controls.
- Anti-cheat: the proof checks the installed CLI version before and after the update.

## Validation

- `node scripts/run-vitest.mjs src/infra/package-lifecycle.test.ts src/infra/package-update-steps.pnpm11-guard.test.ts src/index.entrypoint.test.ts`
- Focused lifecycle, updater, tarball, postinstall, inventory, and entrypoint suites: 176 tests passed.
- Exact-head lifecycle lock suite: 4 tests passed, including the old 20-minute expiry boundary.
- Remote core and scripts checks passed.
- `git diff --check`
- GitHub CI is the full release and platform gate.

## Scope

- Production and release-tooling delta: +370/-162, net +208.
- Test and CI support delta: +370/-84, net +286.
- The production growth adds the shared lifecycle owner, crash-safe retry marker, and concurrent-launch lock. It removes the updater-only lifecycle sequence and keeps the closed `dist/` verifier unchanged.
- Sibling coverage: updater, package launcher, legacy package entrypoint, installers, tarball validator, worker bootstrap package, and Docker package preparation.

## ClawSweeper

- No actionable code findings.
- Rank-up skip: the package-upgrade trace came from an internal isolated runner and is not suitable for a public log attachment. Exact-head GitHub CI and the focused regression commands above remain the public proof.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-08-31 15:12:42 +05:30
Peter Steinberger
a91edbcefa
fix(install): repair set-npm-prefix rc line and surface silent finalization failures (#133869)
- install-cli.sh --set-npm-prefix wrote an over-escaped PATH line: the
  backslash-escaping expanded PATH at install time, appending a literal
  \"-quoted, frozen PATH snapshot to .bashrc/.zshrc that never resolves
  the npm-global bin dir. Use the same correct form as install.sh.
- install.sh finalization helpers (retire_npm_owner_after_git_install,
  retire_git_wrapper_after_npm_install) could abort the install with
  exit 1 and no output; each fatal path now prints an actionable error.
- prepare_git_wrapper_backup_for_npm no longer hard-fails when npm is
  missing (Arch splits node/npm): there is nothing to back up, and the
  npm install step already reports the missing npm with remediation.
- install-cli.sh --compatible-with with an unresolvable --version died
  silently through set -e before its error message; the failed npm view
  now reaches the explicit fail path (and the JSON error event).
2026-08-31 06:41:43 +00:00
Peter Steinberger
a199f9cb7a
chore: update pnpm to 12.1.0 (#132980) 2026-08-29 18:56:00 -07:00
Peter Steinberger
dd4528b639
fix(macos): pair app builds with verified node workers (#131466)
Pair packaged apps with complete private arm64 and x86_64 workers whose full build identity matches the app. Preserve independently managed Gateways and complete recognized native-first state through the canonical initializer. Verify emitted-SDK filesystem calls, native capabilities, readiness and shutdown before app publication.

Derive elevation payloads without modifying canonical installed inputs. Preserve universal slices, resources and contained links; reject incomplete, malformed, escaping or mismatched payloads. Reuse descriptor-bound native inventory for signing while retaining the portable installer's independent distribution contract and every Foundation identity, entitlement, notarization and architecture gate.

Use the existing pinned-pnpm package path, including Corepack-only builders, and avoid recursive app-glob expansion. Centralize Mac CI ownership. Carry invocation-owned Git lock cleanup into main's canonical Git owner and regenerate its workflow projection, retaining lifetime fencing and pre-existing/junction-linked locks.

Fix the Android refresh race exposed by CI by removing the redundant reconnect after connect already replaces each role's socket. Preserve authentication, scopes and physical connection leases, with a controlled real-WebSocket regression.

Closes #131459
2026-08-29 14:47:55 -07:00
Peter Steinberger
5a20edf6a1
fix(installer): prevent source bootstrap from rewriting pnpm metadata (#132608)
* fix(installer): isolate source bootstrap from ambient pnpm

Select temporary checkout-pinned launchers for source installs and nested builds without changing global tools. Preserve caller context and document the Corepack prerequisite and first-hop update constraint.

* test(installer): exercise native Windows pnpm bootstrap

Cover scoped Corepack and exact npm-prefix bootstrap, child context, failure cleanup, and caller environment restoration under native PowerShell. Include the installer owner tests in the existing Windows CI shard and test-only routing.

* fix(installer): preserve native Windows argument and environment boundaries

* fix(updater): preflight the fetched pnpm pin before checkout changes

* test(installer): normalize native wrapper publication paths
2026-08-29 09:18:40 -07:00
Peter Steinberger
8fefe239bf
fix(installer): restore commit-pinned source installs (#132458)
* fix(installer): restore commit-pinned source installs

Restore literal commit selection without weakening qualified branch/tag resolution. Anchor installer upgrade tests to the selected version so newer publications cannot silently turn them into downgrade proof.

Fixes #132456

* fix(installer): resolve Corepack shims from the target checkout

* test: drop superseded media migration fixture extraction
2026-08-29 01:29:41 -07:00
Peter Steinberger
b85a049da5
chore: migrate tooling and source installs to pnpm 12 (#131043)
* build: migrate tooling and source installs to pnpm 12

Pin the verified native toolchain without changing application dependency
versions. Preserve the existing release-age policy explicitly and separate
package-manager lock metadata from the application dependency graph.

Use exact checkout pins for bootstrap and rollback, approve only the native
pnpm installer where npm requires it, and retain global install ownership
without equating the CLI major to the storage layout. Verify the Docker
runtime toolchain offline as its non-root user.

Remove duplicate bootstrap paths and obsolete prune input, update native
CLI flags and regression fixtures, and preserve UTF-8 in macOS Bash
installer NDJSON output.

* fix(build): isolate production dependency installs for pnpm 12

Build production dependencies from the same frozen manifest inputs instead
of pruning the inherited development tree. pnpm 12's native hoisted
importer cannot rename lower-layer OverlayFS directories during pruning.
Preserve native addon outputs, workspace builds, and offline non-root
Corepack use while deleting the obsolete production-store seeder.

Exercise runtime assembly and explicitly consent to the local agent-plugin
E2E fixture under the current plugin capability contract.

Validated full Matrix image and offline non-root runtime, focused Docker
regressions, full checks with test types and architecture, docs, real
agent-plugin gateway E2E, and isolated Codex autoreview.

* test: align package smoke with pnpm 12 global installs

* test: follow native pnpm artifact approval in distribution guard

* test: modernize pnpm fixtures for v12

* test: align rebased update fixtures with pnpm 12

* test: retain sanitized upgrade restart diagnostics

* test: expose CI navigation failures and register diagnostics

* test: retain post-core outcomes and plugin artifact identity

* chore(tooling): group upgrade diagnostic entrypoints

* fix(update): support native pnpm global installs and source links

Qualify local source and archive specs, carry verified global ownership through pnpm configuration, and verify intentional checkout links with shared runtime-readiness checks. Preserve strict packaged-install verification and manager ownership safeguards.

Verified the production updater with pnpm 11.22 and 12 using default and custom roots, source links, and tarball updates.

* test: preserve survivor diagnostics after service sealing

Promote incomplete exit-zero runs before failure capture and exercise the sealed-service manager fixture without inventing successful child exits.

* fix(update): preserve legacy pnpm global ownership

Carry the verified root and bin through both pnpm and npm configuration dialects after original-environment probes. Real pnpm 10 custom-root updates and pnpm 11/12 source and tarball matrices pass without redirecting the caller or weakening ownership checks.

* test(update): verify wizard consent through checkout handoff

Use the prepared checkout and fresh-process finalization boundary introduced by the updater repair. Preserve explicit consent forwarding before and after the wizard subcommand without assuming plugin callbacks run in the old process.

* refactor(update): validate checkout build metadata records

Use the canonical record coercer instead of carrying an unchecked assertion into the shared runtime verifier. Remove the now-unused grandfathered assertion entry; no allowance is added.

* docs(sandbox): document standalone common-image inputs

* test(packaging): account for required native prebuilds

Align installer and release size budgets at 235 MiB for the required native payload added on main. Keep both loader layouts, upstream binaries, explicit overrides, and missing-data rejection intact. Exercise actual defaults and the one-byte boundary. Retain bounded stderr diagnostics for the intermittent Bun signal test without claiming a production signal fix.

* test: align refreshed installer fixtures with pnpm 12

* fix(test): share Bun smoke force-kill ownership

Record the successful force-kill once across the timer and post-close drain. Native Darwin traces reproduced both duplicate-signal orders; genuine permission failures and uncleared groups still fail without extending deadlines.
2026-08-28 17:43:09 -07:00
Jason O'Neal
cd46f44661
improve(update): use local pnpm packages before the registry (#130902)
* perf(update): prefer cached pnpm packages

* fix(installer): preserve pnpm offline overrides

* fix(update): preserve pnpm preference in git updates

* fix(update): preserve pnpm config-file preferences

* fix(update): use the shared npm config scope type

* fix(installer): match canonical pnpm preference keys

* fix(update): type pnpm install environment

* fix(installer): preserve PowerShell pnpm preferences

* fix(installer): preserve pnpm config path policy

* fix(updater): preserve pnpm env precedence

* fix(installer): honor pnpm config policy

* fix(installer): match PowerShell pnpm config context

* chore: format pnpm install policy changes

* chore(ui): refresh startup gzip baseline after main fixes

---------

Co-authored-by: Patrick Erichsen <patrick.a.erichsen@gmail.com>
2026-08-28 15:00:31 -07:00
Jason O'Neal
a939d4bdd8
fix(installer): resolve source refs safely (#130907)
Source installs must select the requested release commit and leave existing checkouts recoverable when updates fail.

This change qualifies Git refs, carries ref mutability into lockfile selection, restores conflicting rebases, and verifies unchanged state when a pre-rebase hook refuses before rebase metadata exists.

Co-authored-by: Jason O'Neal <jason.allen.oneal@gmail.com>
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-08-29 01:37:54 +05:30
Peter Steinberger
83dce46a7d
fix(update): preserve sealed service definitions during code updates (#131021)
Separate code-update ownership, effective launcher identity, native service control, and definition mutation. Guard actual definition publication before related config or token writes, and use the installed CLI's preserve-definition restart with renewed ownership and live port/version/build verification.

Consolidate unit/environment publication and conditional rollback, retain main's plugin convergence and fresh-Doctor ownership, and make post-core child termination belong to the winning completion path. Integrate current-main heap-argument provenance and process-marker handling; resolve the service Node from the executable rather than counting backward through flags.

Retain boundary-level sealed/writable/unknown/foreign, mount, platform, failure, and build-identity proof while consolidating redundant tests. The QA cleanup removes 399 maintained test/support lines; focused current-main integration proof passes 1,279 tests with one pre-existing platform skip. Production and installer growth remains +239 net.

Preserves the reviewed repair from ac86fdff61da9c0fea9f62da00a8c9f22df6790d while integrating main at 56d89073dd. No permission weakening, schema or lease policy change, deployment, or release.
2026-08-28 07:10:42 -07:00
Peter Steinberger
4377b6423c
fix(install): preserve Unicode in macOS JSON output (#131244)
* fix(install): preserve Unicode in macOS JSON output

* chore(install): keep release notes in PR context
2026-08-27 16:46:42 -07:00
xingzhou
ee2f5f2084
fix(install): --json preserves valid NDJSON for dynamic values (#128682)
* fix(install): preserve valid NDJSON for dynamic values

* fix(install): satisfy installer shell checks
2026-08-26 03:19:43 -07:00
Peter Steinberger
234df15a6d
chore: refresh dependencies after seven-day cooldown (#128414)
* build(deps): refresh dependencies after cooldown

Apply dependency, toolchain, action, image, and exact tool updates released by the inclusive 2026-08-16 seven-day cutoff. Adapt owner boundaries for the resulting CUA, logging, Teams, Markdown, native, and test-harness contract changes while retaining versions blocked by upstream compatibility constraints.

* fix(ui): align markdown renderer env typing

* fix(deps): align postcss and mistral peer contracts

* fix(deps): repair refreshed dependency contracts

* fix(deps): retain tslog startup budget

* fix(ci): verify Android tools with SHA-256

* fix(ci): fence Android SDK cache version
2026-08-24 03:01:54 -07:00
Peter Steinberger
f6aa7c24f1
fix(linux): truthful install failures, post-install repair, reachable reinstall (#128614)
The Linux desktop companion could complete a CLI install and still claim
'Installation did not finish' with circular update advice, discarding the
real failure. Verified end-to-end in a clean Ubuntu VM across all three
release channels:

- cli.rs: failed CLI commands now surface their stderr tail (deduped, last
  12 lines) instead of being mislabeled as JSON parse failures.
- gateway.rs: missing dashboard --json support maps to an honest curated
  message pointing at Beta/Development channels, not a circular npm-update
  hint.
- main.rs: run 'doctor --fix --non-interactive' right after install so the
  CLI repairs config/state before Gateway readiness checks; wrap
  post-install failures as 'installed, but connecting failed: <reason>'.
- installer.rs: keep structured step events out of the prose failure tail.
- ui/main.js: humanize streamed install steps, render real errors on the
  failure screen, and always offer Reinstall from connection failures.
- scripts/install-cli.sh: service refresh uses 'gateway status --json' with
  the bundled node runtime, corepack failure falls back to npm, dev channel
  clones with --filter=blob:none.
2026-08-24 02:01:15 -07:00
Peter Steinberger
b514fca522
refactor(update): simplify lifecycle transactions (#126240)
* refactor(update): simplify lifecycle transactions

* ci: use runner-provided ShellCheck

* test(infra): stabilize port-release probe
2026-08-19 01:50:35 -07:00
Peter Steinberger
7bc994aee8
fix(install): avoid success after incomplete lifecycle changes (#125992)
* fix(install): make lifecycle mutations transactional

Standalone installers now apply npm-version-aware lifecycle approval. Updates verify and repair the installation before reporting success and preserve the prior install owner during method switches. Uninstall now exits nonzero when requested cleanup is only partially completed. Plugin update behavior is unchanged.

Closes #125925

* test(uninstall): assert aggregated live-owner failure

* fix(install): satisfy standalone shell checks

* fix(update): scan PATH for prior Git wrapper

* test(hooks): await Gmail watcher descendant exit

* fix(install): verify Windows npm candidate

* fix(ci): normalize package acceptance version

* fix(update): preserve staged local package links

* test(update): fold staged symlink coverage

* fix(update): retire every legacy Git wrapper

* test(docs): align consolidated ownership checks
2026-08-18 20:50:15 -07:00
Peter Steinberger
076a8cc616
fix(install): avoid unusable checkout directories after failed clones (#124872)
* fix(install): publish fresh git clones transactionally

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(installer): preserve empty clone destinations transactionally

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(update): satisfy transactional clone lint

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(update): type recovery directory assertion

* fix(installer): retain canonical clone checkout

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(update): retain published checkout root

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(update): cover package preflight before clone

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-17 02:40:07 -07:00
Peter Steinberger
a917c99e92
fix(runtime): classify Node releases consistently across install and launch (#124812)
* fix(runtime): align Node release version guards

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(runtime): include Node version helper in source fixture

* fix(install): align Node release checks across boundaries

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix: keep node version guard legacy-compatible

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(runtime): exercise legacy launcher preflight

* fix(installer): validate installed Node release versions

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(installer): compare Node version parts numerically

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(installer): cover 17-digit Node major

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-17 00:42:23 -07:00
Peter Steinberger
2b2c11e748
fix(install): keep stable channel when npm install retries (#124778)
* fix(installer): keep npm channel target immutable

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(install): fail after repeated CLI package install errors

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(installer): verify npm package publication

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(install): satisfy shellcheck for entry validation

* fix(installer): link the packaged OpenClaw launcher

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(installer): keep retry fixture version-valid

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-17 00:17:26 -07:00
Peter Steinberger
3ac267fdd1
fix(installer): reject unusable prefix installs (#123716)
* fix(installer): reject unusable prefix installs

* test(installer): clean invalid package fixtures

* fix(installer): require successful version probe
2026-08-14 09:44:54 -07:00
Peter Steinberger
cc99d99f24
fix(installer): resolve relative CLI install paths (#122626) 2026-08-12 06:32:15 -07:00
Peter Steinberger
915c25d713
fix(macos): complete ChatGPT subscription setup (#120782)
Fresh Dev installs now preflight disk space and stream honest stages, while Codex activation probes the refreshed request-scoped registry.

Closes #120779
Closes #120780
2026-08-08 17:16:00 -07:00
Patrick Erichsen
355c107c09
fix(macos): unblock first-launch gateway setup (#119831)
* fix(macos): stop writing retired config metadata

* fix(macos): guard packaged CLI bootstrap versions

* chore(macos): refresh native i18n inventory

* fix(macos): repair retired metadata before gateway start
2026-08-05 22:25:17 -07:00
ooiuuii
807506381a
fix(install): reject commit-less git checkouts (#113809)
* fix(install): reject commit-less git checkouts

* test(install): fix incomplete-checkout coverage

* fix(install): pin incomplete checkout validation

* test(install): update pinned checkout stub

* fix(install): require checkout HEAD commit object
2026-08-02 08:05:42 -07:00
ooiuuii
396194b96b
fix(install): reject PATH runtimes with broken npm (#107825)
* fix(install): reject runtimes with broken npm

* test(installer): use real Node for npm selection

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-16 17:17:07 -07:00
lybnnnn
02f494b51e
fix: clarify SQLite version error message to prevent user confusion (#108382)
* fix: clarify SQLite version error message to prevent user confusion

The error message "3.44.6+" was misinterpreted by users as meaning "3.44.6 and above",
when it actually means "3.44.6+ for the 3.44.x series only". This commit clarifies the
error message to explicitly state that only specific patched versions (3.44.6+, 3.50.7+,
and 3.51.3+) are safe, and that SQLite 3.46.1 is not among them.

Changes:
- Update error message in src/infra/node-sqlite.ts to clarify version requirements
- Update test expectations in src/infra/node-sqlite.test.ts to match new error format
- Fix unnecessary template literal expressions flagged by oxlint

The code logic remains unchanged - SQLite 3.46.1 is correctly rejected as unsafe.

* fix: clarify SQLite version error message to prevent user confusion

The previous error message stated '3.44.6+' which users misinterpreted as
'3.44.6 and above', leading to confusion when versions like 3.46.1 were rejected.

The new message explicitly states '3.44.6+ in the 3.44.x series' and
'3.50.7+ in the 3.50.x series' to make it clear that only specific
minor version series received the WAL-reset bug fix.

This matches the SQLite team's actual fix announcement which only
backported the fix to 3.44.x and 3.50.x series, plus 3.51.3+.

* fix(sqlite): align unsafe version diagnostics

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-16 05:24:14 -07:00
Alix-007
5f2828b50a
fix(installer): time out stalled runtime downloads (#108619)
* fix(installer): bound curl download stalls

* chore: format installer timeout tests

* fix(installer): limit timeout to true download stalls

* fix(installer): scope timeout to transfer stalls
2026-07-15 23:01:31 -07:00
Peter Steinberger
2bbf5e6ca0
fix(macos): prevent clipped and stalled onboarding (#107598)
* fix(macos): harden onboarding on short screens

* chore: keep release notes in PR body

* chore(i18n): refresh macOS onboarding inventory
2026-07-14 10:07:41 -07:00
Vincent Koc
f33ab243cf
fix(sqlite): reject runtimes vulnerable to WAL corruption (#106065)
* fix(sqlite): require WAL-reset-safe Node runtime

* docs(sqlite): document safe Node runtime floor

* fix(sqlite): defer runtime library validation until use

* fix(ci): align startup memory with Node 24.15
2026-07-13 13:59:00 +08:00
Peter Steinberger
4b7a5a4e8b
fix(installer): default to Node 22.22.2 (#104073) 2026-07-10 19:28:49 -07:00
Sebastien Tardif
95b205eac2
fix(installer): clean temporary files on failure (#103725) 2026-07-10 17:53:23 -07:00
Jason (Json)
cccc856b82
fix: reject incompatible Node 23 runtimes (#99832)
* fix: reject incompatible Node 23 runtimes

* fix: repair installer CI coverage

* docs: clarify supported Node ranges

* fix: fail closed on unreadable runtime versions

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-04 00:03:49 -07:00
Peter Steinberger
6a7b62889e
feat(macos): install and run the local Gateway automatically (#99767)
* feat(macos): automate local gateway setup

* fix(macos): auto-approve the local Mac node

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata

* chore(macos): refresh generated setup metadata
2026-07-03 22:09:56 -07:00
Josh Avant
cee2aca409
Scope agent cron operations to the calling agent (#96883)
* Scope agent cron operations to caller

* Scope OpenClaw tools MCP cron by session

* Address cron scope review feedback

* Preserve unscoped cron update retargeting

* Move cron caller identity into gateway context

* Clarify Gateway restart guidance

* Add cron caller identity regression proof
2026-06-26 21:41:14 -05:00
Vincent Koc
bd74a62118
fix(install): use repo pnpm for git installs 2026-06-21 15:34:56 +02:00
Vincent Koc
49d605ece7
fix(installer): reject stale cli node runtimes 2026-05-27 05:31:03 +02:00
Vincent Koc
6c5b39291f
fix(installer): reject invalid shell options 2026-05-26 08:51:50 +02:00
Peter Steinberger
b9f975b64e
Replace Sharp image backend with Photon (#86437)
* refactor: replace sharp image backend with photon

* refactor: remove whatsapp jimp dependency

* chore: remove stale sharp install workarounds

* test: keep image fixtures off photon

* test: use valid prompt image fixtures

* test: account for optimized PNG fixtures

* test: use valid minimax image fixtures
2026-05-25 15:04:44 +01:00