Commit graph

187 commits

Author SHA1 Message Date
Peter Steinberger
0cbbec0272
fix: restore fs-safe native support after update fallback (#152349)
* fix: restore fs-safe native support after optional-free updates

* fix(docker): include fs-safe repair in dependency inputs
2026-09-18 20:33:14 -07:00
Peter Steinberger
3c4c111b0f
feat: automatically update idle headless nodes (#151545)
* feat(node): update headless runtimes automatically when idle

Stage private packaged node runtimes and activate only after all owned work
and cleanup settle. Preserve pairing and launch options, keep automatic
activations at least 12 hours apart, and leave shared-state migration and
Gateway installation ownership with the normal updater.

Document defaults, opt-outs, runtime version discovery, and recovery.
Support recoverable Windows selector replacement across service restarts.

Refs #151462

* fix(node): complete auto-update integration and settings defaults

Capture the launcher in compiled test runtimes and trusted wrapper inventories, register the package update proof, and use the canonical Kysely read path. Preserve the inherited enabled state in the config UI and align caller tests with the node shutdown lifecycle.

* fix(node): preserve retained plugin work during automatic updates

Require an explicit idle result from plugin commands, preserve older-plugin work, and connect bundled lifetime owners to automatic node updates. Join canceled inference and failed terminal cleanup before command settlement; keep historical state repair with Doctor. Document compatibility and extend installed-package proof for retained legacy plugin work.

* test(browser): align idle-work fixtures with runtime exports

* test(browser): extract proxy request fixtures

* test(node): retain idle assertions across native cleanup
2026-09-18 06:20:27 -07:00
RoboClaw
1c00cf14a7
fix(installer): stop rejecting verified 2026.9.4 upgrades (#150757)
Validate the successful update and fresh CLI before classifying the
published 2026.9.4 process's warning. Accept only the proved 9.4-to-9.5
case, with a fresh PATH entry bound to the updated global package.

Keep the original warning visible, preserve all other skew failures and
deadlines, and cover stale/foreign executables and failed update results.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
2026-09-17 08:24:23 -07:00
Peter Steinberger
f78f51359d
chore(deps): refresh dependencies with seven-day cutoff (#149908)
* chore(deps): refresh dependencies with seven-day cutoff

Advance eligible application, native, release, and development dependencies
published by 2026-09-09T06:51:52Z. Audit new registry resolutions and native
artifact hashes, preserving existing security pins and compatibility holds.

Adapt MCP Apps 2 tool discovery and host context, retain Clack cancellation
handling, and align the updater fixture with its runtime assembly owner.
Synchronize native artifact checks, operational docs, and tooling pins.

Validation includes frozen installation, full build, CLI rebuild, typechecks,
lint, 96 npm package locks, dependency audits, focused runtime and native
proofs, and independent review. Exact-head hosted CI is required before land.

* fix(deps): preserve scroll ownership and synchronize toolchain contracts

* fix(cli): preserve generic wizard option values after Clack update

* docs(lobster): clarify credentials for embedded remote calls

* test(cli): use Clack cancellation sentinel in prompt fixtures

* fix(ios): avoid opening audio input during relay cancellation

* test: reuse dependency update fixtures within line limits

* fix(crabbox): retain the previous trusted pnpm pin

* test(gateway): synchronize task access churn with page selection

* test(macos): isolate the challenge timeout transport fixture

* fix(macos): preserve hidden windows through deminiaturization

* fix(macos): exclude hidden dashboards from window selection
2026-09-16 09:06:40 -07:00
Peter Steinberger
05963f8b5e
fix(runtime): re-exec under an available supported Node before refusing (#143464)
* fix(runtime): reuse an available compatible Node at startup

Share startup recovery between the launcher and legacy CLI runtime admission
so older updaters can run target Doctor through dist/index.js under an
already installed compatible Node. Preserve process-contract exclusions,
arguments, environment, standard streams, and exit status.

Refs #140465

* test(runtime): include recovery proof in E2E routing

* fix(runtime): secure Node discovery and decode service scripts

Reject relative candidates and cwd-resolved runtimes before probing, except
for explicit absolute PATH directories. Parse generated Windows command
quoting and recorded code pages without loading application dependencies.

Skip CP850 and CP949 with a diagnostic instead of guessing executable paths.
Use real task-writer fixtures for encoding, quoting, and fallback coverage.

Refs #140465

* fix(runtime): reject cwd-local manager symlinks

* test(runtime): keep recovery home outside launcher cwd

* fix(runtime): isolate recovery from dotenv environment

* fix(runtime): canonicalize discovery paths before use

* fix(runtime): preserve private Node recovery from home

* refactor(runtime): trim Node recovery comments and aliases

Behavior-neutral cleanup of the recovery launcher module: fold the serviceHome and managerHome aliases into homeDir and shorten five comment blocks to the invariant they protect.
2026-09-10 01:35:39 -07:00
Peter Steinberger
bf6f74b280
fix(runtime): gate node:sqlite on a NUL round-trip capability probe (#143312)
* fix(runtime): gate node:sqlite on a NUL round-trip capability probe

Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465 #140672.

* fix(runtime): expose capability diagnostics through doctor

Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.

* fix(update): preserve target Node version requirements

* fix(install): remove unused Node major probe state
2026-09-09 13:32:29 -07:00
Vincent Koc
16fe99ff3d
fix(docker): restore source builds after dependency ownership guard (#142073)
* fix(docker): restore source builds after dependency ownership guard

* fix(docker): preserve existing lifecycle copy prefix
2026-09-08 17:59:28 +08:00
Peter Steinberger
299ea7c393
fix(scripts): run macOS tooling under /bin/bash and make the framework-merge fixture self-contained (#141884)
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures

Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.

Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.

* fix(scripts): keep guarded portable scripts bash 3.2 compatible

* fix(scripts): keep macOS Bash CI coverage green

Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.

Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.

* docs(install): use system Bash in install and recovery commands

Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.

Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.

* fix(scripts): preserve streamed installs and CI packing

Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.

Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.

Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
2026-09-08 01:21:30 -07:00
Dallin Romney
7038ee5f31
fix(ci): accept frozen legacy same-version updates (#141652) 2026-09-07 18:20:27 -07:00
Dallin Romney
ef66dc32d6
fix(docker): resolve fs-safe manifest through public export (#141534)
* fix(docker): resolve fs-safe manifest through public export

* fix(docker): locate fs-safe manifest from entrypoint root
2026-09-07 14:22:15 -07:00
Peter Steinberger
5e10ff81e3
fix(release): verify current package scan and installer outcomes (#141565)
* fix(release): freeze shipped plugin scan inventories before current shrink

* test(release): distinguish installer no-op from applied update

Keep the baseline-to-candidate update strict while separately validating the documented already-current outcome for the second identical-candidate invocation. Require unchanged build identity, successful staging without activation, and an idle service namespace; do not count the no-op as an applied upgrade.

* docs(release): name the already-current idle proof accurately
2026-09-07 14:21:06 -07:00
Dallin Romney
7e12d97124
fix(e2e): route installer agent turns through gateway (#134390) 2026-09-07 14:12:34 -07:00
Dallin Romney
295996d4e0
fix(e2e): accept image tool compatibility alias (#134454) 2026-09-07 14:10:31 -07:00
Peter Steinberger
0d0e2852b2
fix(release): restore verification inputs and supported upgrade proof (#140981)
* fix(qa): verify leased Telegram tester group access

Check tester membership and effective text permission in the leased user driver before group readiness. Reuse the check in doctor and select trusted skill scripts for frozen release candidate QA. Preserve supported private DM turns and leave credential repair to the pool owner.

* ci: install Chromium for native live browser tests

The native-live-test shard includes the real Gateway widget restart proof,
which launches Playwright after restoring the interrupted session. Chromium
was installed only in separate Repo E2E jobs, leaving the live shard without
its required executable.

Install the candidate UI's pinned Chromium and system dependencies only for
the selected native-live-test row. Preserve profile selection and all test
gates. Verified the unchanged dc420 widget restart test with real OpenAI,
Gateway process replacement, and interactive Chromium dashboard assertions
on Blacksmith Testbox; canonical workflow checks and formatting also pass.

* test(release): prove supported cross-OS 9.2 transition

Select the explicitly supported external package-manager and fresh Doctor
transition only for 2026.9.2 to 2026.9.3. Preserve the old updater's safe
schema-15 refusal as negative evidence and never report self-update passed.
Verify backup, exact package identity, schema migration, retained settings
and session history, candidate serving version, and a fresh persisted turn.
Keep credential-bearing backup archives out of CI evidence and remove them
on both successful and failed runs. Other release pairs retain existing
updater and Windows fallback behavior.

Validation: 13 cross-OS upgrade lane tests, two pre-fix regression failures,
full changed checks, and independent review. Real packaged cross-OS/live
qualification remains required against the aggregate candidate.

* test(installer): prove supported historical package transitions

* test(release): exercise same-schema updater boundaries

Keep updater-specific plugin repair and consent checks on the prepared
candidate, then target explicit synthetic later versions with the same
runtime and storage schema. Retain installed-version and plugin-policy
assertions, and remove the obsolete legacy post-update fallback.

Add versioned future-tarball generation to the existing first-hop fixture
owner, with immutable input and source/target digest receipts. Restore the
reserved runtime-promotion staging ignore in package-derived Git fixtures
so the updater's unchanged-source check stays meaningful.

Validation: 26 focused tests, a pre-fix Git staging regression, full changed
checks, exact candidate tarball fixture generation, and P2 review. Actual
Docker update/consent/channel qualification remains required in aggregate CI.

* test(release): verify channel update staging cleanup

Assert the real channel flow refuses ordinary untracked user files without changing source, then require successful channel updates to remove every reserved runtime staging entry. Preserve recovery data when the assertion detects leftovers. No ignore or production cleanup policy is broadened.

* test(onboard): select configured model through explicit picker

* ci: pin release performance checks to reviewed Kova accounting

Select the reviewed Linux process-lifetime CPU accounting and bounded worker-watchdog implementation from Kova PR #110 for canonical, legacy-list, and trusted live fixtures. Keep existing trust classification, timeout values, and performance thresholds.

* fix(ci): distinguish bundle build modes in job names

* test(release): build matching future runtime fixtures

Derive a synthetic Codex runtime cohort from its verified candidate package by changing only package.version and openclaw.build.openclawVersion. Require matching source metadata and preserve payload, constraints, immutable input, and source/target digest receipts. Reuse the existing private tarball lifecycle and sequence validation. Validated 11 focused tests, pre-change CLI failures, full changed checks, and P2 review.

* docs(release): prepare private QA before local E2E

* fix(release): admit package metadata before validation dispatch

Port the reviewed early source admission into trusted Tooling, preserving the current selected REST transport. Reject invalid version notes and misaligned core packages before any Git push, non-GET API write, or workflow dispatch; retain explicitly allowed substantive draft notes.

* test(release): qualify supported historical upgrade transitions

Prove the published 2026.8.2/2026.9.2 to 2026.9.3 external package-manager and fresh Doctor contract through one shared helper. Preserve the old in-process updater refusal and schema 15, require owner-stopped migration with a verified private backup, and verify schema 16 plus retained Gateway history afterward.

Keep current-runtime update coverage distinct: managed restart uses separately identified future core and matching runtime fixtures, with real updater, canary, service replacement, authentication, and serving checks. Fix fixture-only channel environment pollution and mock serving nonce responses.

Sealed Docker journey, historical first-hop, current-candidate survivor, root-managed VPS, and onboarding pass. Managed-auth historical preservation passes; its future canary exposes an independent existing plugin projection blocker, retained as failing proof for the candidate repair owner. No product schema or refusal guard changes.

* test(release): narrow recorded update command before indexing

* fix(ci): align historical upgrade fixture ownership

Keep all seven external transition assertion cases with the first-hop package fixtures: both own the historical upgrade boundary and now share its temporary-state lifecycle. Preserve helper test selection and all assertions while avoiding an additional standalone tooling group.

Provide the new inference and future-package preparation boundaries in isolated service, mobile, and cron bootstrap probes, and verify each updater argument without changing readiness or migration assertions. Register the path-launched assertion CLI as a Knip entry.

Validation: 67 related tests; 70 exact-merge planner and combined-suite tests; five 80-job stress plans; full Knip unused-file scans; scoped checks and P2 review.

* fix(ci): model upgrade preparation in isolated probes

Complete the companion fixture and Knip repairs for the preceding transition-test consolidation. Model the independent inference and future-package preparation producers, verify exact updater argument boundaries, and retain service-readiness, authored-state, and cron migration assertions. Declare the path-launched transition assertion CLI in the existing Knip entrypoint list.

* test(release): preserve fixture registry on managed restart

Capture the fake service manager registry alongside its endpoint paths, then refresh that owned context after preparing the future cohort. Projected native service callers cannot drop or replace it; transient update state still stays outside the managed child.

The executable service regression fails on the original shim and passes with missing and conflicting caller registries. Four focused tests, the changed gate, and P2 review pass. Reuse the existing d928 package for the final managed-upgrade replay.

* test(release): preserve prepared UI identity in future fixtures

Advance synthetic package versions while retaining the opaque build ID already embedded in unchanged Control UI assets. The canonical asset-health regression fails the prior builder as stale, then verifies readiness and unchanged UI bytes for both future fixture sequences. Package-version update admission and managed-restart proof remain unchanged.

* test(release): retain manager-owned fixture policy

Capture the existing automation and offline-channel policy with registry identity when generating the manager shim. Native service clients project these values away; losing them activated retained synthetic channel credentials and correctly failed readiness. Restore only this explicit manager allowlist and keep transient update/compatibility state excluded.

The executable service regression fails on missing manager flags and passes across projected or conflicting caller environments. Four focused tests, the full changed gate, and fresh P2 review pass. Actual corrected managed Docker proof remains pending.

* docs(ci): keep bundle identity with routing guidance

* fix(release): retry transient GraphQL EOF failures

Classify the observed gh unexpected EOF transport failure within the existing five-attempt retry budget. Preserve authentication, invalid-response, inventory and snapshot handling. Exercise recovery, exhaustion and fail-fast errors through the real verifier CLI with a fake gh transport; also modernize the existing disposable-array sort required by touched-test lint.

* test(release): align survivor fixtures with manager preparation

Supply manager environment JSON to directly launched supervisors, and model the independent manager preparation phase in config-parking and companion fixtures. Preserve service readiness, restart, diagnostics, and strict phase-order assertions without changing production behavior or test limits.

* test(release): align upgrades with deferred schema publication

Restore installed-updater survivor and first-hop coverage after shared migration ownership moved into the durable update ledger. Record applied schema content separately from published schema version, retain the genuine missing-chunk negative control, and label external installation as an alternate with no self-update attempt. Preserve production-owned unsupported migration refusals.

* test(release): restore supported packaged upgrade coverage

Restore real 2026.9.2 to 2026.9.3 self-update after ledger-driven schema migration support. Keep retained conversations, private backup, settings, candidate identity, and serving inference proof. Require migrated content independently of publication grace and remove obsolete external-install diversion from cross-OS and installer update smoke. Shared external helper remains separately owned.

* test(release): refresh legacy manager before updater restart

Bind the service manager to the candidate registry before the published baseline updater starts its managed service. Preserve restart verification for successful and recoverable outcomes alongside explicit future targets. Exercise stale registry capture, replacement failures, pre-update identity, and attribution without changing timeouts or caps.
2026-09-07 11:47:27 -07:00
Peter Steinberger
ce0e84d073
fix(runtime): require Node builds with lossless SQLite reads (#140672)
* fix(runtime): require Node builds with lossless SQLite reads

* fix(runtime): preserve upgrades and guard sealed workers

Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.

* test(runtime): use typed process exports in worker fixture

* test(runtime): align installer fixtures without growing test shards

* test(runtime): align release and guest runtime fixtures

* fix(test): canonicalize Windows temp roots for Node 24

Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.

* test(ci): run Windows temp-root regressions in the native lane
2026-09-07 10:31:31 -07:00
ooiuuii
09380ca1dd
fix(docker): preserve workspace project ownership during setup (#140993)
Prune the workspace bind mount during config ownership repair while retaining workspace-root and OpenClaw metadata repair. Preserve project ownership on same-filesystem mounts and keep the existing no-follow protections.

Verified with real offline Docker setup on current main and the candidate, fresh/rerun and sibling controls, and independent behavior validation.

Closes #140968

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-07 16:01:27 +05:30
Dallin Romney
86f5429e5a
fix(docker): support legacy fs-safe package exports (#137893)
* fix(docker): derive fs-safe proof from frozen source

Co-authored-by: Dallin Romney <dallin@openclaw.ai>

Co-authored-by: Vincent Koc <vincent@openclaw.ai>

* fix(ci): bind fs-safe omission to frozen release history

* fix(ci): hydrate frozen source ancestry for install smoke

* test(ci): narrow install smoke manifest run assertion

* fix(e2e): report skipped fs-safe native proof

---------

Co-authored-by: Vincent Koc <vincent@openclaw.ai>
2026-09-07 12:27:53 +08:00
Peter Steinberger
1421c21640
fix: restore package acceptance across install runtimes (#140062) 2026-09-06 04:41:04 -07:00
Dallin Romney
6d3a1b867f
build: consume platform-specific fs-safe packages (#132240)
* build: consume platform-specific fs-safe packages

* test: prove fs-safe optional fallback
2026-09-03 13:26:50 -07:00
Peter Steinberger
b026948c8f
fix(update): allow updates without a Gateway service (#136798)
The installed 2026.8.2 updater refuses the release smoke before package
mutation or candidate handoff. Current main has the same defect: strict
systemd command inspection cannot distinguish a missing manager from an
uninspectable existing service.

Let the native service-state owner record affirmative manager/unit absence,
then require strict Gateway lock inspection and a free configured port at
update preflight. Preserve unknown-state refusal and report skipped restart
when nothing is running. Lock discovery retains its existing contract.

Use the shipped baseline's documented --no-restart path only after proving
the dedicated smoke container idle, then repeat the candidate update with
default restart policy. Join the heartbeat timer exposed by that idle check.
Document the one-time 2026.8.2 upgrade workaround.

Proof: original baseline and packed-main Docker runs refused with exit 1;
managerless and strict-lock regressions fail before the fix. Final focused
suites pass 532 tests; the full update CLI suite passes 370 with 1 skipped.
Final Docker baseline/manual plus candidate/default updates and doctor
steps pass; pnpm check:changed passes. Independent review is clean through P2.

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 21:12:45 -07:00
Peter Steinberger
594f500309
fix(docker): include shared lifecycle marker in install stages (#134231)
* fix(docker): include package lifecycle marker before install

* test(agents): prepare CLI setup artifacts before compaction checks
2026-08-31 10:31:58 -07:00
Peter Steinberger
8fefe239bf
fix(installer): restore commit-pinned source installs (#132458)
* fix(installer): restore commit-pinned source installs

Restore literal commit selection without weakening qualified branch/tag resolution. Anchor installer upgrade tests to the selected version so newer publications cannot silently turn them into downgrade proof.

Fixes #132456

* fix(installer): resolve Corepack shims from the target checkout

* test: drop superseded media migration fixture extraction
2026-08-29 01:29:41 -07:00
Peter Steinberger
b85a049da5
chore: migrate tooling and source installs to pnpm 12 (#131043)
* build: migrate tooling and source installs to pnpm 12

Pin the verified native toolchain without changing application dependency
versions. Preserve the existing release-age policy explicitly and separate
package-manager lock metadata from the application dependency graph.

Use exact checkout pins for bootstrap and rollback, approve only the native
pnpm installer where npm requires it, and retain global install ownership
without equating the CLI major to the storage layout. Verify the Docker
runtime toolchain offline as its non-root user.

Remove duplicate bootstrap paths and obsolete prune input, update native
CLI flags and regression fixtures, and preserve UTF-8 in macOS Bash
installer NDJSON output.

* fix(build): isolate production dependency installs for pnpm 12

Build production dependencies from the same frozen manifest inputs instead
of pruning the inherited development tree. pnpm 12's native hoisted
importer cannot rename lower-layer OverlayFS directories during pruning.
Preserve native addon outputs, workspace builds, and offline non-root
Corepack use while deleting the obsolete production-store seeder.

Exercise runtime assembly and explicitly consent to the local agent-plugin
E2E fixture under the current plugin capability contract.

Validated full Matrix image and offline non-root runtime, focused Docker
regressions, full checks with test types and architecture, docs, real
agent-plugin gateway E2E, and isolated Codex autoreview.

* test: align package smoke with pnpm 12 global installs

* test: follow native pnpm artifact approval in distribution guard

* test: modernize pnpm fixtures for v12

* test: align rebased update fixtures with pnpm 12

* test: retain sanitized upgrade restart diagnostics

* test: expose CI navigation failures and register diagnostics

* test: retain post-core outcomes and plugin artifact identity

* chore(tooling): group upgrade diagnostic entrypoints

* fix(update): support native pnpm global installs and source links

Qualify local source and archive specs, carry verified global ownership through pnpm configuration, and verify intentional checkout links with shared runtime-readiness checks. Preserve strict packaged-install verification and manager ownership safeguards.

Verified the production updater with pnpm 11.22 and 12 using default and custom roots, source links, and tarball updates.

* test: preserve survivor diagnostics after service sealing

Promote incomplete exit-zero runs before failure capture and exercise the sealed-service manager fixture without inventing successful child exits.

* fix(update): preserve legacy pnpm global ownership

Carry the verified root and bin through both pnpm and npm configuration dialects after original-environment probes. Real pnpm 10 custom-root updates and pnpm 11/12 source and tarball matrices pass without redirecting the caller or weakening ownership checks.

* test(update): verify wizard consent through checkout handoff

Use the prepared checkout and fresh-process finalization boundary introduced by the updater repair. Preserve explicit consent forwarding before and after the wizard subcommand without assuming plugin callbacks run in the old process.

* refactor(update): validate checkout build metadata records

Use the canonical record coercer instead of carrying an unchecked assertion into the shared runtime verifier. Remove the now-unused grandfathered assertion entry; no allowance is added.

* docs(sandbox): document standalone common-image inputs

* test(packaging): account for required native prebuilds

Align installer and release size budgets at 235 MiB for the required native payload added on main. Keep both loader layouts, upstream binaries, explicit overrides, and missing-data rejection intact. Exercise actual defaults and the one-byte boundary. Retain bounded stderr diagnostics for the intermittent Bun signal test without claiming a production signal fix.

* test: align refreshed installer fixtures with pnpm 12

* fix(test): share Bun smoke force-kill ownership

Record the successful force-kill once across the timer and post-close drain. Native Darwin traces reproduced both duplicate-signal orders; genuine permission failures and uncleared groups still fail without extending deadlines.
2026-08-28 17:43:09 -07:00
Peter Steinberger
b4d6aff098
chore(deps): refresh seven-day-cooled providers and native tooling (#130653)
* chore(deps): refresh cooled provider and native tooling

* build: preserve installed SDK package identity

* test: isolate dependency validation fixtures
2026-08-27 00:57:31 -07:00
Peter Steinberger
234df15a6d
chore: refresh dependencies after seven-day cooldown (#128414)
* build(deps): refresh dependencies after cooldown

Apply dependency, toolchain, action, image, and exact tool updates released by the inclusive 2026-08-16 seven-day cutoff. Adapt owner boundaries for the resulting CUA, logging, Teams, Markdown, native, and test-harness contract changes while retaining versions blocked by upstream compatibility constraints.

* fix(ui): align markdown renderer env typing

* fix(deps): align postcss and mistral peer contracts

* fix(deps): repair refreshed dependency contracts

* fix(deps): retain tslog startup budget

* fix(ci): verify Android tools with SHA-256

* fix(ci): fence Android SDK cache version
2026-08-24 03:01:54 -07:00
Peter Steinberger
a917c99e92
fix(runtime): classify Node releases consistently across install and launch (#124812)
* fix(runtime): align Node release version guards

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(runtime): include Node version helper in source fixture

* fix(install): align Node release checks across boundaries

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix: keep node version guard legacy-compatible

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(runtime): exercise legacy launcher preflight

* fix(installer): validate installed Node release versions

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* fix(installer): compare Node version parts numerically

Amp-Thread-ID: https://ampcode.com/threads/T-01a00ae0-190d-718b-8a76-b75f3e8d1fae

* test(installer): cover 17-digit Node major

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-17 00:42:23 -07:00
thomas.szbay
ecc6d5a9fe
fix(e2e): download non-root installer before execution
Download the non-root Docker smoke installer before executing it.

- preserve the existing 30-second connection and 300-second transfer limits
- clean up the temporary installer on success or failure
- prove failed downloads cannot execute partial installer content

Co-authored-by: thomas.szbay <xydigit-zt@users.noreply.github.com>
Punchcard-Session: golden-lantern-meadow-0x
2026-08-11 18:12:52 +08:00
Vincent Koc
65d13cb80b
fix(ci): retry fresh artifact metadata reads (#121876) 2026-08-11 14:01:31 +08:00
Peter Steinberger
c70aee247e
refactor(scripts): migrate JavaScript tools to TypeScript (#121005)
* refactor(scripts): migrate JavaScript tools to TypeScript

* fix(ci): keep changed-scope preflight zero-install

* fix(ci): preserve zero-install script owners

* fix(ci): complete script migration follow-through

* fix(release): keep stable closeout zero-install

* fix(scripts): preserve standalone execution boundaries

* fix(scripts): repair standalone loader boundaries

* fix(scripts): normalize gateway observation ids

* fix(scripts): keep Docker packager standalone

* test(scripts): preserve rebase cleanup helpers

* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00
Vincent Koc
0d45efd5da
fix(ci): retry transient artifact API reads (#120654) 2026-08-09 02:05:04 +08:00
Vincent Koc
92b4757227
fix(diagnostics): honor signal-specific OTLP protocols (#119708)
* fix(diagnostics): honor signal-specific OTLP protocols

* fix(docker): forward signal-specific OTLP protocols
2026-08-06 05:39:26 +08:00
Vincent Koc
15b23cfc2d
fix(docker): use authenticated gateway health command (#118996)
* fix(docker): use authenticated gateway health command

* test(docker): prove documented compose health command
2026-08-04 07:10:36 +08:00
Vincent Koc
ffa99ca81d
fix(docker): validate timezone in runtime image (#116153) 2026-07-30 09:19:01 +08:00
Peter Steinberger
669db2968f
refactor(agents): retire TOOLS.md into an AGENTS.md section with a doctor migration (#113966)
* fix(agents): stop retired attestation hashes from faking a vanished workspace

* feat(agents): migrate TOOLS.md content into the AGENTS.md tools section

* refactor(agents): drop TOOLS.md from the workspace bootstrap set

* refactor(policy): read tool policy entries from AGENTS.md

* docs: describe local tool notes as an AGENTS.md section

* test(codex): drop TOOLS.md developer-instruction coverage with the removed path

* test(agents): cover the TOOLS.md doctor migration behaviors

* refactor(doctor): satisfy TOOLS.md migration lint

* test(agents): split workspace attestation survival coverage

* refactor(codex): simplify workspace context basenames

* refactor(doctor): keep TOOLS.md migration helpers module-local

* docs: regenerate docs map

* fix(doctor): keep migration claims fresh

* fix(doctor): preserve nested tool notes

* refactor(doctor): split tools migration helpers

* refactor(doctor): limit TOOLS.md migration to workspace root

* style(doctor): keep migration under line limit

* fix(doctor): recover interrupted AGENTS publish

* docs(hooks): describe root-only TOOLS.md migration accurately

* fix(doctor): preserve migrated tool guidance visibility

* test(agents): regenerate prompt snapshots after rebase

* fix(policy): block evaluation while TOOLS.md is unmigrated

* fix(doctor): check merged bootstrap budget per agent

* fix(doctor): keep budget helper internal

* refactor(doctor): keep migration budget helpers to their consumers
2026-07-27 03:56:30 -04:00
Peter Steinberger
d5a3740707
fix(package): prevent installs from deleting required runtime modules (#113821)
* fix(package): preserve imported runtime chunks after install

* fix(package): isolate public build from private QA

* test(package): prove installed postinstall dependency graph
2026-07-25 14:05:41 -07:00
Peter Steinberger
acd92f6a3d
chore(deps): refresh repository dependencies (#112453)
* build(deps): update QA broker dependency

* build(deps): refresh repository dependencies

* build(deps): reconcile rebased shrinkwraps

* test(plugins): remove stale loader test state

* test(deps): stabilize updated dependency coverage

* fix(swift): use caller-isolated TaskLocal overload

* build(deps): regenerate rebased shrinkwraps

* test(msteams): preserve DNS validation in fetch helper

* fix(deps): avoid vulnerable optional image stack

* test(deps): validate generated LRU override

* refactor(ui): extract chat resizable divider

* test(ui): update divider ownership path

* fix(matrix): retain restart-compatible SDK

* style(cron): format update test
2026-07-23 16:17:13 +00:00
xingzhou
66990b207f
fix(ci): bound CLI installer smoke curl with connect and max-time (#109927)
* fix(ci): bound CLI installer smoke curl with connect and max-time

The non-root CLI installer smoke pipes curl directly into bash under a
single docker-run timeout. curl has no default connect or total timeout,
so a stalled CDN connect or hung response body could pin the container
until the outer docker-run budget kills it. Bound the curl with the same
--connect-timeout 30 --max-time 300 shape already used by install-sh-smoke
and install-sh-e2e, and enable pipefail so curl failures are not masked
by the bash consumer.

* test(ci): cover bounded CLI installer pipeline

* fix(ci): bound preceding non-root installer download

* fix(ci): harden bounded installer URL handoff

Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com>

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-18 06:59:29 +01:00
LZY3538
45f36640dc
fix(docker): bound smoke installer curl with connect timeout (#109698)
* fix(docker): bound smoke installer curl with connect timeout

Add --connect-timeout 30 and --max-time 300 to the direct installer
one-liner curl in the smoke test runner. The run_installer_for_package_spec
function is already bounded by timeout(1), but this direct invocation had
no curl-level or wrapper-level timeout.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(docker): wrap complete installer pipeline in timeout, not just curl

Replace the stand-alone curl timeout flags on the direct installer one-liner
with a timeout(1) wrapper around the entire curl|bash pipeline, matching the
run_installer_for_package_spec pattern. This bounds the complete pipeline
(download + install) rather than just the network transfer.

The curl-level --connect-timeout 30 and --max-time 300 are retained as
defence-in-depth inside the timeout wrapper.

Co-Authored-By: Claude <noreply@anthropic.com>

* refactor: centralize installer smoke pipeline bounds

Co-authored-by: LZY3538 <liu.zhenye@xydigit.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-17 10:20:40 +01:00
Alix-007
66a4205c57
fix(e2e): bound official installer download (#108937)
* fix(e2e): bound official installer download

* test(e2e): cover downloaded installer execution

* fix(e2e): harden installer download proof

Co-authored-by: Alix-007 <li.long15@xydigit.com>

* test(e2e): type installer fixture environment

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-16 05:26:00 -07:00
Alix-007
f538addc66
fix(ci): bound non-root NodeSource setup download (#108911) 2026-07-16 04:08:47 -07:00
Alix-007
00be90dae7
fix(sandbox): bound common installer downloads (#108805) 2026-07-16 03:18:02 -07:00
ooiuuii
59a21e3429
fix(docker): keep setup chown from following symlinks (#107847)
* Fix Docker setup chown symlink handling

* fix(docker): harden setup ownership repair

Co-authored-by: luyifan <al3060388206@gmail.com>

* fix(docker): pin ownership repair path

* test(docker): assert ownership setup ordering

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
Co-authored-by: Peter Steinberger <peter@steipete.me>
2026-07-16 00:55:54 -07:00
Peter Steinberger
b58a64bbfa
fix(release): scan SQLite installer transcripts (#108458) 2026-07-15 13:52:05 -07:00
Vincent Koc
f33ab243cf
fix(sqlite): reject runtimes vulnerable to WAL corruption (#106065)
* fix(sqlite): require WAL-reset-safe Node runtime

* docs(sqlite): document safe Node runtime floor

* fix(sqlite): defer runtime library validation until use

* fix(ci): align startup memory with Node 24.15
2026-07-13 13:59:00 +08:00
Peter Steinberger
fa77fe10d5
chore: migrate active GPT-5.5 references to GPT-5.6 (#104452)
* chore(models): migrate active GPT-5.5 references

* test(workboard): expect GPT-5.6 Sol default

* chore: keep release notes in PR body

* test(models): align picker fixtures with Sol default

* test: update PDF default model expectation

* test(qa): migrate thinking smoke to Luna

* test(gateway): align mock catalog with Sol default

* ci: retrigger exact-head PR checks

* test(gateway): document default catalog invariant
2026-07-11 06:30:57 -07:00
Peter Steinberger
e43f225c81
fix(release): prevent stale beta validation evidence (#103798)
Some checks are pending
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Waiting to run
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Blocked by required conditions
Plugin Init Scaffold Validation / Validate provider scaffold (push) Waiting to run
Plugin NPM Release / preview_plugin_pack (push) Blocked by required conditions
Plugin NPM Release / preview_plugins_npm (push) Waiting to run
Plugin NPM Release / Validate release publish approval (push) Blocked by required conditions
Plugin NPM Release / publish_plugins_npm (push) Blocked by required conditions
Plugin NPM Release / verify_plugins_npm (push) Blocked by required conditions
Workflow Sanity / no-tabs (push) Waiting to run
Workflow Sanity / actionlint (push) Waiting to run
Workflow Sanity / generated-doc-baselines (push) Waiting to run
Native App Locale Refresh / Refresh native vi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-CN (push) Blocked by required conditions
Native App Locale Refresh / Refresh native zh-TW (push) Blocked by required conditions
Native App Locale Refresh / Commit native locale refresh (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ko (push) Blocked by required conditions
Native App Locale Refresh / Refresh native nl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pl (push) Blocked by required conditions
Native App Locale Refresh / Refresh native pt-BR (push) Blocked by required conditions
Native App Locale Refresh / resolve-base (push) Waiting to run
Native App Locale Refresh / Verify generated PR App permissions (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ar (push) Blocked by required conditions
Native App Locale Refresh / Refresh native de (push) Blocked by required conditions
Native App Locale Refresh / Refresh native es (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fa (push) Blocked by required conditions
Native App Locale Refresh / Refresh native fr (push) Blocked by required conditions
Native App Locale Refresh / Refresh native hi (push) Blocked by required conditions
Native App Locale Refresh / Refresh native id (push) Blocked by required conditions
Native App Locale Refresh / Refresh native it (push) Blocked by required conditions
Native App Locale Refresh / Refresh native ja-JP (push) Blocked by required conditions
* fix(release): ignore nested squash revert markers

* fix(release): preserve squash revert targets

* docs(release): state installer doctor contract

* fix(release): recognize conventional squash reverts
2026-07-10 17:26:56 +01:00
Vincent Koc
155e196e22
fix(release): preserve beta validation evidence (#103796)
* fix(release): proxy upgrade fixtures to npm

(cherry picked from commit 30f54a5fe1)

* fix(release): require installer doctor evidence

(cherry picked from commit 0782a94452)

* test(qa): scope aborted restart outcome to Codex

(cherry picked from commit ac54f80430)

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-10 09:05:14 -07:00
Vincent Koc
cbe3731f77
fix(release): make validation proof no-write (#103737)
* fix(release): make validation proof no-write

* test(release): align no-write workflow contracts
2026-07-10 08:18:44 -07:00
Peter Steinberger
7fe004d852
feat: show build identity in About screens (#103595)
* feat: show build identity in About screens

* chore: leave root changelog to release automation

* fix: translate Control UI About build details
2026-07-10 10:42:36 +01:00
Vincent Koc
8755077fe4
fix(release): bundle AI runtime in installer smoke (#103556)
* fix(release): bundle AI runtime in installer smoke

* fix(release): verify bundled AI runtime loadability

* fix(release): preserve advisory doctor exits

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-07-10 02:13:41 -07:00