Commit graph

140 commits

Author SHA1 Message Date
Peter Steinberger
9726512367
ci(security-review): reconcile ci-gate statuses when CI completion delivery is lost (#155392)
Some checks are pending
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
Native App Locale Refresh / resolve-base (push) Waiting to run
Native App Locale Refresh / Verify generated PR App permissions (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ar (push) Blocked by required conditions
Native App Locale Refresh / Refresh native de (push) Blocked by required conditions
Native App Locale Refresh / Refresh native es (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fa (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native hi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native id (push) Blocked by required conditions
Node Runtime Conformance / scope (push) Waiting to run
Node Runtime Conformance / TypeScript contracts (push) Blocked by required conditions
Node Runtime Conformance / Rust workspace (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Blocked by required conditions
Plugin Init Scaffold Validation / scope (push) Waiting to run
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / Preflight plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / Seal prepared plugin npm release (push) Blocked by required conditions
Plugin NPM Release / Trusted publisher OIDC exchange (push) Blocked by required conditions
Plugin NPM Release / approve_plugins_npm_release (push) Blocked by required conditions
Plugin NPM Release / Publish plugin npm package () (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Vitest Cache Warm / dependencies (push) Waiting to run
Vitest Cache Warm / warm (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Lost CI-completion deliveries can leave the required ci-gate status pending after CI finishes. Add scheduled reconciliation through the existing trusted Security Review resolver and enforcement job.

Preserve overlapping completion windows, reject incomplete listings before publication, keep provisional statuses eligible, and trust only Actions-owned gate statuses. Bound each pass to the oldest 100 heads and retain the successful window anchor while a backlog remains.

Reruns whose original creation time predates the three-hour listing margin retain the documented existing recovery path through a push or Security Review rerun.

Validation: exact-head CI passed, focused entry-point and workflow regressions passed, and live read-only GitHub transport proof completed. Production scheduled recovery remains post-merge proof.
2026-09-27 14:08:14 -07:00
Peter Steinberger
f8a3418494
refactor(scripts): deslop tooling subdirectories and agent skill helpers (#159218)
Consolidate repeated tooling flows while preserving command contracts. Fix swallowed HTML translation errors and browser-realm error handling in the Google Live smoke. Owner tests and CLI parity passed on Testbox; final broad gate replay follows a fixture lint correction.
2026-09-26 18:13:40 -07:00
Hannes Rudolph
340092231c
docs: remove stale showcase section (#158575) 2026-09-25 21:11:35 -06:00
Josh Avant
bf6de07f15
fix(ci): recover interrupted Security Review response bodies (#157651) 2026-09-24 20:11:01 -05:00
Josh Avant
507b137ff0
fix: clarify lockfile cleanup fallback when write access is unavailable (#157008)
* fix: clarify lockfile cleanup fallback when write access is unavailable

* test: use findLast for dependency review status assertion
2026-09-23 23:44:07 -05:00
Josh Avant
b770a861bd
fix(ci): recover Security Review from read timeouts (#156176) 2026-09-24 03:47:25 +00:00
RoboClaw
45920b3853
fix(ci): stop obsolete security review reads after new pushes (#156798)
Stop obsolete Security Review reads and non-quota recovery waits after a newer PR head supersedes the evaluated revision. Reuse the existing supersession outcome and preserve per-SHA publication serialization, final approval checks, and autoscrub writes/cleanup.

Regression coverage proves early exit before further pagination or recovery waiting; the unchanged-head control completes. In-flight request deadlines, server-directed quota waits, checkout, and runtime setup are unchanged.

Contributor credit: VACInc and vincentkoc.

## Work sessions

- [Original discussion](https://team.openclaw.ai/chat/roboclaw/dashboard/1b82108b-d6ca-44f2-95d5-63a6831c6bb7)
- [Implementation and verification](https://team.openclaw.ai/chat/roboclaw/68b61c50)

---
[View the OpenClaw team session](https://team.openclaw.ai/chat/roboclaw/dashboard/68b61c50-c2d0-461b-ab98-37947c99b1f1)

Co-authored-by: VACInc <3279061+VACInc@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-09-23 20:24:31 -07:00
Dallin Romney
86f5656a2a
fix(release): require Gateway and Telegram validation (#156811)
* fix(release): ignore waivers for other release trains

* test(auto-reply): await active admission boundary

* fix(release): restore blocking validation without lane waivers

* fix(release): require Gateway install and upgrade checks on every OS

* test(ci): align Testbox timeout with its existing lease

* fix(ci): include readonly reuse in PR wrapper closure

* fix(release): restore blocking Telegram validation

* refactor(release): remove legacy waiver transition handling

* test(release): expect Telegram QA to block release checks
2026-09-23 19:04:50 -07:00
Peter Steinberger
0708f975ab
fix(ci): stop reviving canceled test workflows
Cancellation did not prove an infrastructure error or absence of executed
and failed tests, yet the sweeper automatically replayed whole workflows.
The three-day census found nine such reruns, including five CI workflows.

Remove canceled-run revival. Keep bounded recovery for missing or
startup-failed CI before tests execute, with infrastructure warnings and
the existing live head/PR checks.

The actual sweeper boundary changed from one canceled-run replay to zero
without a PR mutation. Both shared-fixture importers passed 20 standalone
runs and three replays under their CI configs on Testbox.
2026-09-23 18:27:19 -07:00
Josh Avant
ae53b4f777
fix(ci): remove lockfile changes after main advances (#156171) 2026-09-23 13:32:34 -05:00
Josh Avant
e6bd12b4cd
fix(ci): avoid dependency warnings from unrelated main updates (#156040) 2026-09-22 19:52:41 -05:00
Josh Avant
a98b766352
fix(ci): recover Security Review when diff data settles slowly (#155921) 2026-09-22 15:12:41 -05:00
Josh Avant
0c98d387e8
fix(ci): identify changed PR fields in Security Review errors (#155266) 2026-09-21 18:47:03 -05:00
Josh Avant
0dc39583dd
fix: recover Security Review after transient status failures (#155248) 2026-09-21 18:08:41 -05:00
Josh Avant
f7c0c42c04
fix(ci): prevent false Security Review failures (#155231) 2026-09-21 17:22:30 -05:00
Josh Avant
25b469ec73
fix(ci): retry Security Review HTTP 500 reads (#155196) 2026-09-21 16:27:12 -05:00
Josh Avant
6615891cc3
fix(ci): skip superseded security review runs (#155170) 2026-09-21 15:52:39 -05:00
Josh Avant
9d5c532435
fix(ci): recover security review from inconsistent file lists (#155129) 2026-09-21 15:00:29 -05:00
Josh Avant
d70d5c1248
fix(ci): reduce Security Review fetches and handle rate limits (#155054)
* fix(ci): narrow security review checkout

* fix(ci): retry rate-limited security reviews
2026-09-21 13:34:34 -05:00
Peter Steinberger
3a722d4c62
fix(ci): keep security review pending while CI runs (#153005)
Distinguish missing or active CI from failed CI. Keep the required combined status pending without failing the waiting review job, and fail visibly on approval, CI, metadata, or evaluation errors. Preserve workflow, head, attempt, and authority checks.
2026-09-19 12:24:53 -07:00
Josh Avant
fda6fb3016
fix(ci): avoid stale Security Review failures after reevaluation (#153089) 2026-09-19 13:31:50 -05:00
Josh Avant
2a06fe7235
fix: clarify maintainer security warning introductions (#152634) 2026-09-19 01:44:43 -05:00
Josh Avant
5a2bc22ce9
fix(ci): clarify security review comments (#152578)
* fix(ci): clarify security review warning comments

* fix(ci): simplify security approval comments

* fix(ci): remove hyphen from maintainer security warning

* fix(ci): list dependency changes in maintainer warnings

* fix(ci): simplify dependency graph filename lists
2026-09-19 01:27:07 -05:00
Josh Avant
debd174b3a
fix(ci): restore security review comments and labels (#152526) 2026-09-19 00:10:53 -05:00
Josh Avant
c2b84506a9
feat(ci): split security review into maintainer and SecOps tiers (#152415)
* feat(ci): split security review into two tiers

* refactor(ci): move security review paths into YAML

* fix(ci): require explicit maintainer approval commands

* feat(ci): integrate automatic security review with CI

* fix(ci): filter security review comment events

* test(ci): include security review workflow routes
2026-09-18 23:39:46 -05:00
Hannes Rudolph
2227743f74
refactor: split release changelogs and synchronize docs mirrors (#145464)
* refactor: split release changelogs and synchronize docs mirrors

* fix: complete split changelog instructions and validation wiring

* fix: complete release changelog mirror integration

Regenerate existing docs mirrors within the docs-agent publication boundary, preserve one HTML release heading, and package links for oversized mirrors without changing frozen records. Update release publisher and test-routing fixtures for the shared changelog resolver.

* test: align docs agent Git ownership fixtures

Keep failure injection aligned with staged-index validation and mirror staging. Preserve native Git producer exit codes and verify both cached-index producers without weakening process-drain assertions.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-11 21:19:18 -07:00
Vincent Koc
81f1b2edf1
fix(github): point the stuck-FAQ auto-response at a live anchor (#143194)
The r: support auto-response links to
/help/faq#im-stuck-whats-the-fastest-way-to-get-unstuck. That anchor does
not exist on /help/faq and did not before the FAQ split — the content moved
to the first-run FAQ in an earlier split, and the id changed spelling at the
same time. Anyone closed with this label has been sent to a page that scrolls
nowhere.

The live target is /help/faq-first-run#i-am-stuck-fastest-way-to-get-unstuck,
which the first-run FAQ index publishes as an authored stub.

docs-link-audit does not cover this because the URL lives in a script rather
than a docs page.
2026-09-09 23:57:25 +09:00
Peter Steinberger
299ea7c393
fix(scripts): run macOS tooling under /bin/bash and make the framework-merge fixture self-contained (#141884)
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures

Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.

Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.

* fix(scripts): keep guarded portable scripts bash 3.2 compatible

* fix(scripts): keep macOS Bash CI coverage green

Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.

Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.

* docs(install): use system Bash in install and recovery commands

Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.

Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.

* fix(scripts): preserve streamed installs and CI packing

Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.

Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.

Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
2026-09-08 01:21:30 -07:00
Peter Steinberger
862c1f7c65
fix(ci): labeler no longer fails when a PR already has 100 labels (#138841)
* fix(ci): labeler no longer fails when a PR already has 100 labels

PR #137637 taught the size-label step to tolerate GitHub's HTTP 422
"Issues cannot have more than 100 labels", but every other label-adding
step still threw it. On the 2026.9.1 closeout PR #137506 the maintainer
author-role step failed that way and turned the cosmetic Labeler check red.

Move the cap handling into one owner, scripts/github/labeler-label-cap.mjs,
and route all eight addLabels sites across the label, label-issues, and
backfill-pr-labels jobs through it: warn naming the skipped label, succeed,
rethrow anything else. Each job checks out the trusted base commit
(ref: github.sha, persist-credentials: false) like auto-response.yml so the
github-script steps can import the module; no PR code runs. Delete the size
step's pre-count guard so the 422 is the single canonical cap path.

Rename test/scripts/labeler-size-label.test.ts to labeler-label-cap.test.ts;
it executes the real step scripts with the real helper and adds maintainer
step cap coverage plus a workflow-wide invariant that no script calls
issues.addLabels directly.

* test(ci): cover labeler cap helper return value and keep knip aware of it

The knip full-tree unused-file scan flagged scripts/github/labeler-label-cap.mjs
because only the workflow loads it dynamically. Import it from its owner test,
like every other scripts/github module, with a case for the boolean result the
backfill job's label bookkeeping depends on.
2026-09-04 22:56:18 -07:00
Peter Steinberger
5e91162db5
fix(ci): preserve draft conversions during PR CI sweeps (#138467)
Respect draft conversions observed by the final PR revalidation before closing and reopening to re-fire CI. Record the existing changed-during-sweep skip without spending the re-fire budget.

Cover missing-CI and startup-failure-only candidates with exact final-snapshot regressions; eligible non-draft behavior is unchanged.
2026-09-04 12:59:11 -07:00
Vincent Koc
62fba6cb1c
refactor(scripts): share timeout error factory (#135907) 2026-09-03 12:33:35 +08:00
Peter Steinberger
1643aaa0c2
feat(release): make Windows and macOS cross-OS validation advisory (#136788)
Honor Peter Steinberger's 2026-09-03 operator decision to let macOS and
Windows work proceed in parallel with or after npm publication. Record
advisory cross-OS conclusions without turning them into release blockers,
and permit all-group selectors that retain every required Linux suite.

Keep Linux execution and shared preparation, normal CI, npm qualification,
Docker, Package Acceptance, performance, and soak gates intact. Native
signing, appcast, and Windows asset promotion workflows stay unchanged.

Proof: focused policy/filter/summary regressions; full-release script tests;
pnpm check:changed; pnpm check:workflows with pinned tooling; ShellCheck;
independent autoreview. Hosted cross-OS orchestration remains unexecuted
locally. Six policy regressions fail against the previous policy.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 18:31:14 -07:00
Peter Steinberger
41ff392b26
ci: shorten beta release qualification (#134966)
* ci: shorten beta release qualification

* test: align beta qualification CI fixtures

* test: use built runtime for Doctor process checks
2026-09-01 02:15:20 -07:00
Mert Başar
13d17fb10d
fix(github): confine Barnacle skill auto-close (#131619)
Only apply the destructive skill routing label when every changed path belongs to a newly added ordinary skill root. Preserve grouped layouts and maintainer overrides, reject Custodian submissions, and validate rename source paths.
2026-08-31 21:12:34 -07:00
Peter Steinberger
59976298ff
perf(release): shorten full validation evidence collection (#134694) 2026-08-31 20:08:22 -07:00
Peter Steinberger
3b609ec685
fix(ci): make Telegram release tests best effort (#133357)
* fix(ci): make Telegram release tests best effort

* fix(ci): require terminal Telegram advisory evidence
2026-08-30 09:29:13 -07:00
Peter Steinberger
479510607f
fix(release): record approved Telegram waiver for 2026.8.1 (#133321)
* fix(release): record approved Telegram waiver for 2026.8.1

* test(release): type waiver evidence fixtures precisely

* fix(release): read waiver metadata without target checkout

* test(release): supply default waiver in sibling workflow fixtures

* fix(release): reject Telegram-selecting aggregate waiver filters
2026-08-30 08:21:22 -07:00
Patrick Erichsen
6886458244
fix(github): classify new skills before Barnacle close (#132225)
* fix(github): classify new skills before Barnacle close

* fix(github): classify grouped bundled skills
2026-08-28 18:04:23 -07:00
Vincent Koc
f30e480a70
perf(release): pipeline full release validation (#131914)
* feat(release): split release child phases

* feat(release): acquire shared candidates once

* fix(release): seal candidate publisher identity

* fix(release): separate published package inputs

* fix(release): rebuild overridden acceptance images

* fix(release): preserve phased candidate identity

* test(release): cover phased validation workflows

* fix(release): integrate phased candidate acquisition

* fix(release): type phased recovery fixtures

* test(release): cover phased validation inputs
2026-08-29 05:11:05 +08:00
Vincent Koc
38fd9ad6e4
fix(release): accept trusted tooling lineage evidence (#130865) 2026-08-27 17:59:48 +08:00
Peter Steinberger
5e81a346d7
fix(ci): narrow release validation GitHub contract (#129783)
Replace the checker-only broad Octokit shape with exact issue request and response contracts, and make the test harness reject impossible missing issue responses.

Co-authored-by: Dallin Romney <dallinromney@gmail.com>
2026-08-25 19:47:59 -07:00
Peter Steinberger
637da87a5d
fix(gateway): tools.invoke must carry the caller's host-minted role authority (#129725)
* fix(gateway): tools.invoke must carry the caller's host-minted role authority

The connect handshake resolves each connection's authority once and stores it
server-side (shared-secret operator owners mint system authority there).
tools.invoke discarded that fact and re-derived ownership from scopes, so a
shared-secret caller with no durable profile resolved to the deny-by-default
role and was refused dispatch on its own agents — while the same connection
could still mutate sessions directly.

Carry client.internal.operatorRoleActor into the synthetic dispatch client and
keep the scope-derived fallback for callers that have no connection actor
(HTTP). Regression test fails pre-fix with the FORBIDDEN agent-allowlist error.

* test(opencode): close the fake CLI before exec to stop ETXTBSY flakes

The catalog suite wrote the fake opencode executable and spawned it
immediately. Under parallel CI shards the write handle could still be open
at exec time, so the launch failed with ETXTBSY and failed the shard.

Write through an explicit file handle with an fsync before close so the
binary is fully durable before the first spawn.

* fix(ci): repair red main type and lint gates

Two gates were failing on main independently of this branch:

- extensions/qa-lab cleanup tests still built OpenClawCrablineChannelDriverSelection
  with the retired smokeArtifactPath and a stale capabilityMatrixPath, so
  check:test-types failed after the readiness-artifact change (#124189).
  Align both fixtures with the current type and its pinned constants.
- scripts/github/release-validation-campaign.d.mts declared the Actions Octokit
  client as any (#129726), tripping no-explicit-any. Declare the structural
  subset the publisher actually calls instead of suppressing the rule.

Verified failing on clean origin/main before the fix.
2026-08-25 19:15:01 -07:00
Patrick Erichsen
004b06b6a0
Release validation: add isolated campaign skill runner (#129726) 2026-08-25 17:58:39 -07:00
Vincent Koc
fa86caf94f
fix(release): keep protected tooling trusted after main moves (#126881)
* fix(release): keep protected tooling trusted after main moves

* fix(release): cover protected tooling recovery paths

* fix(release): honor live tooling contracts

* fix(release): revalidate tooling at npm publish

* fix(release): bind npm publishers to live tooling

* fix(release): preserve trusted dispatch identity

* fix(release): revalidate parent authorization

* fix(release): bind ClawHub to release parent

* docs(release): define frozen tooling identity

* test(release): align ClawHub protected dispatch ref

* fix(release): trust protected plugin npm preflight tooling

* docs(release): scope protected writer guarantees

* fix(release): keep protected tooling foundation npm-only

* test(release): cover trusted npm preflight tooling
2026-08-21 07:24:31 +00:00
Vincent Koc
750f2f3762
fix(release): require concrete validation retry groups (#127012)
* fix(release): require concrete validation retry groups

* fix(release): reject mismatched retry filters

* fix(release): align retry controller vocabulary

* fix(release): preserve historical validation evidence

* fix(release): validate retry filters before scheduling

* test(release): follow shared filter validator

* docs(testing): clarify release QA retry groups
2026-08-20 23:35:16 -07:00
joshavant
b52d2f08f5
fix(ci): trust maintainer-authored dependency changes 2026-08-20 15:09:22 -05:00
Peter Steinberger
b822e6e425
refactor(github): consolidate guard display sanitization (#123620) 2026-08-14 13:29:21 -07:00
Peter Steinberger
27c4433939
fix(ci): trust dependency approvers before graph compare (#123456) 2026-08-13 21:03:34 -07:00
Vincent Koc
9794a4a49c
fix(release): bind reusable evidence verifier source (#123115) 2026-08-13 18:19:28 +08:00
Peter Steinberger
c23d66e3b5
refactor: consolidate coercion ownership (#122692)
* refactor: consolidate coercion ownership

* test: align shard check with weighted planning

* chore: refresh plugin SDK API baseline
2026-08-12 09:25:28 -07:00