* feat(node): update headless runtimes automatically when idle
Stage private packaged node runtimes and activate only after all owned work
and cleanup settle. Preserve pairing and launch options, keep automatic
activations at least 12 hours apart, and leave shared-state migration and
Gateway installation ownership with the normal updater.
Document defaults, opt-outs, runtime version discovery, and recovery.
Support recoverable Windows selector replacement across service restarts.
Refs #151462
* fix(node): complete auto-update integration and settings defaults
Capture the launcher in compiled test runtimes and trusted wrapper inventories, register the package update proof, and use the canonical Kysely read path. Preserve the inherited enabled state in the config UI and align caller tests with the node shutdown lifecycle.
* fix(node): preserve retained plugin work during automatic updates
Require an explicit idle result from plugin commands, preserve older-plugin work, and connect bundled lifetime owners to automatic node updates. Join canceled inference and failed terminal cleanup before command settlement; keep historical state repair with Doctor. Document compatibility and extend installed-package proof for retained legacy plugin work.
* test(browser): align idle-work fixtures with runtime exports
* test(browser): extract proxy request fixtures
* test(node): retain idle assertions across native cleanup
Validate the successful update and fresh CLI before classifying the
published 2026.9.4 process's warning. Accept only the proved 9.4-to-9.5
case, with a fresh PATH entry bound to the updated global package.
Keep the original warning visible, preserve all other skew failures and
deadlines, and cover stale/foreign executables and failed update results.
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
* fix(runtime): reuse an available compatible Node at startup
Share startup recovery between the launcher and legacy CLI runtime admission
so older updaters can run target Doctor through dist/index.js under an
already installed compatible Node. Preserve process-contract exclusions,
arguments, environment, standard streams, and exit status.
Refs #140465
* test(runtime): include recovery proof in E2E routing
* fix(runtime): secure Node discovery and decode service scripts
Reject relative candidates and cwd-resolved runtimes before probing, except
for explicit absolute PATH directories. Parse generated Windows command
quoting and recorded code pages without loading application dependencies.
Skip CP850 and CP949 with a diagnostic instead of guessing executable paths.
Use real task-writer fixtures for encoding, quoting, and fallback coverage.
Refs #140465
* fix(runtime): reject cwd-local manager symlinks
* test(runtime): keep recovery home outside launcher cwd
* fix(runtime): isolate recovery from dotenv environment
* fix(runtime): canonicalize discovery paths before use
* fix(runtime): preserve private Node recovery from home
* refactor(runtime): trim Node recovery comments and aliases
Behavior-neutral cleanup of the recovery launcher module: fold the serviceHome and managerHome aliases into homeDir and shorten five comment blocks to the invariant they protect.
* fix(runtime): gate node:sqlite on a NUL round-trip capability probe
Validate the loaded SQLite library and TEXT, BLOB, and JSON round trips across startup, doctor, Gateway install, update preflight, and installers. Admit capable Node 24+ vendor builds with a support-policy note while retaining the package engines and Node 22 exclusion. Refs #140465#140672.
* fix(runtime): expose capability diagnostics through doctor
Register the runtime check in the ordered Doctor contribution catalog. Keep shared audit types in a leaf module, include the bootstrap probe in duplicate scanning, and update native runtime and compiled-worker fixtures for the capability protocol.
* fix(update): preserve target Node version requirements
* fix(install): remove unused Node major probe state
* fix(scripts): use system Bash for macOS tooling and owned Mach-O fixtures
Pin native entrypoints and package commands to /bin/bash, guard portable heredoc callers on Darwin, and preserve Bash 3.2 boolean parsing. Streamed installers explain how to use system Bash when their input cannot be replayed.
Generate deterministic x86_64, arm64, and arm64e framework fixtures instead of borrowing /bin/ls. Preserve the existing framework pipeline repair from #141056 and verify merged slice bytes.
* fix(scripts): keep guarded portable scripts bash 3.2 compatible
* fix(scripts): keep macOS Bash CI coverage green
Distinguish sourced installer returns from stdin exits without ShellCheck unreachable-code warnings. Retain the shebang regression suite in changed-target routing, and repartition hosted tooling tails toward 50-second groups within the existing 150-second budget and 80-job cap.
Validation: 635 interpreter and routing tests plus 53 planner tests passed; ShellCheck, targeted lint, formatting, and fresh Codex review passed. The broader local changed-file check hit an unrelated existing dependency graph crossing through extensions/reef/node_modules/@noble/hashes; exact-head hosted CI remains required.
* docs(install): use system Bash in install and recovery commands
Align macOS-facing copy-and-paste commands and emitted installer guidance with the supported streamed interpreter. This addresses the remaining installer-command review finding without changing the PR body.
Validation: streamed help for both installers, install.sh dry-run, 16 selected fresh-install and upgrade lifecycle tests, formatting, diff check, and fresh Codex review passed. Landing remains blocked by unrelated provider-transport integration CI failure caused by an unchanged incomplete plugin-registry mock.
* fix(scripts): preserve streamed installs and CI packing
Keep public installer commands portable while replaying Darwin Bash 5.3+
stdin under system Bash through an immediately unlinked private temp file.
Retain actionable sourced-install rejection and the SC2317-safe check.
Restore the original CI packing policy and move the Bash policy scan into
its existing macOS tooling owner without adding a routed test file.
Validation: real Homebrew Bash streamed help and cleanup; 642 scan/routing
tests; 23 selected installer tests under both PATH orders; planner cap and
coverage tests; 139 Bash syntax checks; ShellCheck; 1,135 changed-gate tests;
focused lint/changed-check repair; fresh Codex review with no P0/P1 findings.
* fix(release): freeze shipped plugin scan inventories before current shrink
* test(release): distinguish installer no-op from applied update
Keep the baseline-to-candidate update strict while separately validating the documented already-current outcome for the second identical-candidate invocation. Require unchanged build identity, successful staging without activation, and an idle service namespace; do not count the no-op as an applied upgrade.
* docs(release): name the already-current idle proof accurately
* fix(qa): verify leased Telegram tester group access
Check tester membership and effective text permission in the leased user driver before group readiness. Reuse the check in doctor and select trusted skill scripts for frozen release candidate QA. Preserve supported private DM turns and leave credential repair to the pool owner.
* ci: install Chromium for native live browser tests
The native-live-test shard includes the real Gateway widget restart proof,
which launches Playwright after restoring the interrupted session. Chromium
was installed only in separate Repo E2E jobs, leaving the live shard without
its required executable.
Install the candidate UI's pinned Chromium and system dependencies only for
the selected native-live-test row. Preserve profile selection and all test
gates. Verified the unchanged dc420 widget restart test with real OpenAI,
Gateway process replacement, and interactive Chromium dashboard assertions
on Blacksmith Testbox; canonical workflow checks and formatting also pass.
* test(release): prove supported cross-OS 9.2 transition
Select the explicitly supported external package-manager and fresh Doctor
transition only for 2026.9.2 to 2026.9.3. Preserve the old updater's safe
schema-15 refusal as negative evidence and never report self-update passed.
Verify backup, exact package identity, schema migration, retained settings
and session history, candidate serving version, and a fresh persisted turn.
Keep credential-bearing backup archives out of CI evidence and remove them
on both successful and failed runs. Other release pairs retain existing
updater and Windows fallback behavior.
Validation: 13 cross-OS upgrade lane tests, two pre-fix regression failures,
full changed checks, and independent review. Real packaged cross-OS/live
qualification remains required against the aggregate candidate.
* test(installer): prove supported historical package transitions
* test(release): exercise same-schema updater boundaries
Keep updater-specific plugin repair and consent checks on the prepared
candidate, then target explicit synthetic later versions with the same
runtime and storage schema. Retain installed-version and plugin-policy
assertions, and remove the obsolete legacy post-update fallback.
Add versioned future-tarball generation to the existing first-hop fixture
owner, with immutable input and source/target digest receipts. Restore the
reserved runtime-promotion staging ignore in package-derived Git fixtures
so the updater's unchanged-source check stays meaningful.
Validation: 26 focused tests, a pre-fix Git staging regression, full changed
checks, exact candidate tarball fixture generation, and P2 review. Actual
Docker update/consent/channel qualification remains required in aggregate CI.
* test(release): verify channel update staging cleanup
Assert the real channel flow refuses ordinary untracked user files without changing source, then require successful channel updates to remove every reserved runtime staging entry. Preserve recovery data when the assertion detects leftovers. No ignore or production cleanup policy is broadened.
* test(onboard): select configured model through explicit picker
* ci: pin release performance checks to reviewed Kova accounting
Select the reviewed Linux process-lifetime CPU accounting and bounded worker-watchdog implementation from Kova PR #110 for canonical, legacy-list, and trusted live fixtures. Keep existing trust classification, timeout values, and performance thresholds.
* fix(ci): distinguish bundle build modes in job names
* test(release): build matching future runtime fixtures
Derive a synthetic Codex runtime cohort from its verified candidate package by changing only package.version and openclaw.build.openclawVersion. Require matching source metadata and preserve payload, constraints, immutable input, and source/target digest receipts. Reuse the existing private tarball lifecycle and sequence validation. Validated 11 focused tests, pre-change CLI failures, full changed checks, and P2 review.
* docs(release): prepare private QA before local E2E
* fix(release): admit package metadata before validation dispatch
Port the reviewed early source admission into trusted Tooling, preserving the current selected REST transport. Reject invalid version notes and misaligned core packages before any Git push, non-GET API write, or workflow dispatch; retain explicitly allowed substantive draft notes.
* test(release): qualify supported historical upgrade transitions
Prove the published 2026.8.2/2026.9.2 to 2026.9.3 external package-manager and fresh Doctor contract through one shared helper. Preserve the old in-process updater refusal and schema 15, require owner-stopped migration with a verified private backup, and verify schema 16 plus retained Gateway history afterward.
Keep current-runtime update coverage distinct: managed restart uses separately identified future core and matching runtime fixtures, with real updater, canary, service replacement, authentication, and serving checks. Fix fixture-only channel environment pollution and mock serving nonce responses.
Sealed Docker journey, historical first-hop, current-candidate survivor, root-managed VPS, and onboarding pass. Managed-auth historical preservation passes; its future canary exposes an independent existing plugin projection blocker, retained as failing proof for the candidate repair owner. No product schema or refusal guard changes.
* test(release): narrow recorded update command before indexing
* fix(ci): align historical upgrade fixture ownership
Keep all seven external transition assertion cases with the first-hop package fixtures: both own the historical upgrade boundary and now share its temporary-state lifecycle. Preserve helper test selection and all assertions while avoiding an additional standalone tooling group.
Provide the new inference and future-package preparation boundaries in isolated service, mobile, and cron bootstrap probes, and verify each updater argument without changing readiness or migration assertions. Register the path-launched assertion CLI as a Knip entry.
Validation: 67 related tests; 70 exact-merge planner and combined-suite tests; five 80-job stress plans; full Knip unused-file scans; scoped checks and P2 review.
* fix(ci): model upgrade preparation in isolated probes
Complete the companion fixture and Knip repairs for the preceding transition-test consolidation. Model the independent inference and future-package preparation producers, verify exact updater argument boundaries, and retain service-readiness, authored-state, and cron migration assertions. Declare the path-launched transition assertion CLI in the existing Knip entrypoint list.
* test(release): preserve fixture registry on managed restart
Capture the fake service manager registry alongside its endpoint paths, then refresh that owned context after preparing the future cohort. Projected native service callers cannot drop or replace it; transient update state still stays outside the managed child.
The executable service regression fails on the original shim and passes with missing and conflicting caller registries. Four focused tests, the changed gate, and P2 review pass. Reuse the existing d928 package for the final managed-upgrade replay.
* test(release): preserve prepared UI identity in future fixtures
Advance synthetic package versions while retaining the opaque build ID already embedded in unchanged Control UI assets. The canonical asset-health regression fails the prior builder as stale, then verifies readiness and unchanged UI bytes for both future fixture sequences. Package-version update admission and managed-restart proof remain unchanged.
* test(release): retain manager-owned fixture policy
Capture the existing automation and offline-channel policy with registry identity when generating the manager shim. Native service clients project these values away; losing them activated retained synthetic channel credentials and correctly failed readiness. Restore only this explicit manager allowlist and keep transient update/compatibility state excluded.
The executable service regression fails on missing manager flags and passes across projected or conflicting caller environments. Four focused tests, the full changed gate, and fresh P2 review pass. Actual corrected managed Docker proof remains pending.
* docs(ci): keep bundle identity with routing guidance
* fix(release): retry transient GraphQL EOF failures
Classify the observed gh unexpected EOF transport failure within the existing five-attempt retry budget. Preserve authentication, invalid-response, inventory and snapshot handling. Exercise recovery, exhaustion and fail-fast errors through the real verifier CLI with a fake gh transport; also modernize the existing disposable-array sort required by touched-test lint.
* test(release): align survivor fixtures with manager preparation
Supply manager environment JSON to directly launched supervisors, and model the independent manager preparation phase in config-parking and companion fixtures. Preserve service readiness, restart, diagnostics, and strict phase-order assertions without changing production behavior or test limits.
* test(release): align upgrades with deferred schema publication
Restore installed-updater survivor and first-hop coverage after shared migration ownership moved into the durable update ledger. Record applied schema content separately from published schema version, retain the genuine missing-chunk negative control, and label external installation as an alternate with no self-update attempt. Preserve production-owned unsupported migration refusals.
* test(release): restore supported packaged upgrade coverage
Restore real 2026.9.2 to 2026.9.3 self-update after ledger-driven schema migration support. Keep retained conversations, private backup, settings, candidate identity, and serving inference proof. Require migrated content independently of publication grace and remove obsolete external-install diversion from cross-OS and installer update smoke. Shared external helper remains separately owned.
* test(release): refresh legacy manager before updater restart
Bind the service manager to the candidate registry before the published baseline updater starts its managed service. Preserve restart verification for successful and recoverable outcomes alongside explicit future targets. Exercise stale registry capture, replacement failures, pre-update identity, and attribution without changing timeouts or caps.
* fix(runtime): require Node builds with lossless SQLite reads
* fix(runtime): preserve upgrades and guard sealed workers
Validate downloaded Node before switching the active runtime alias, reject unsupported sealed-worker runtimes, and keep the Gateway error fixture on a supported Node release. Document the approved ARMv7 and older macOS compatibility losses and decoder fix boundaries.
* test(runtime): use typed process exports in worker fixture
* test(runtime): align installer fixtures without growing test shards
* test(runtime): align release and guest runtime fixtures
* fix(test): canonicalize Windows temp roots for Node 24
Expand Windows short paths before creating test directories and owned child environments. Node 24 filesystem watchers otherwise abort when native long event paths differ from inherited short temporary paths. Preserve explicit custom-root spelling and existing cleanup ownership.
* test(ci): run Windows temp-root regressions in the native lane
Prune the workspace bind mount during config ownership repair while retaining workspace-root and OpenClaw metadata repair. Preserve project ownership on same-filesystem mounts and keep the existing no-follow protections.
Verified with real offline Docker setup on current main and the candidate, fresh/rerun and sibling controls, and independent behavior validation.
Closes#140968
Co-authored-by: Ayaan Zaidi <hi@obviy.us>
The installed 2026.8.2 updater refuses the release smoke before package
mutation or candidate handoff. Current main has the same defect: strict
systemd command inspection cannot distinguish a missing manager from an
uninspectable existing service.
Let the native service-state owner record affirmative manager/unit absence,
then require strict Gateway lock inspection and a free configured port at
update preflight. Preserve unknown-state refusal and report skipped restart
when nothing is running. Lock discovery retains its existing contract.
Use the shipped baseline's documented --no-restart path only after proving
the dedicated smoke container idle, then repeat the candidate update with
default restart policy. Join the heartbeat timer exposed by that idle check.
Document the one-time 2026.8.2 upgrade workaround.
Proof: original baseline and packed-main Docker runs refused with exit 1;
managerless and strict-lock regressions fail before the fix. Final focused
suites pass 532 tests; the full update CLI suite passes 370 with 1 skipped.
Final Docker baseline/manual plus candidate/default updates and doctor
steps pass; pnpm check:changed passes. Independent review is clean through P2.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* fix(installer): restore commit-pinned source installs
Restore literal commit selection without weakening qualified branch/tag resolution. Anchor installer upgrade tests to the selected version so newer publications cannot silently turn them into downgrade proof.
Fixes#132456
* fix(installer): resolve Corepack shims from the target checkout
* test: drop superseded media migration fixture extraction
* build: migrate tooling and source installs to pnpm 12
Pin the verified native toolchain without changing application dependency
versions. Preserve the existing release-age policy explicitly and separate
package-manager lock metadata from the application dependency graph.
Use exact checkout pins for bootstrap and rollback, approve only the native
pnpm installer where npm requires it, and retain global install ownership
without equating the CLI major to the storage layout. Verify the Docker
runtime toolchain offline as its non-root user.
Remove duplicate bootstrap paths and obsolete prune input, update native
CLI flags and regression fixtures, and preserve UTF-8 in macOS Bash
installer NDJSON output.
* fix(build): isolate production dependency installs for pnpm 12
Build production dependencies from the same frozen manifest inputs instead
of pruning the inherited development tree. pnpm 12's native hoisted
importer cannot rename lower-layer OverlayFS directories during pruning.
Preserve native addon outputs, workspace builds, and offline non-root
Corepack use while deleting the obsolete production-store seeder.
Exercise runtime assembly and explicitly consent to the local agent-plugin
E2E fixture under the current plugin capability contract.
Validated full Matrix image and offline non-root runtime, focused Docker
regressions, full checks with test types and architecture, docs, real
agent-plugin gateway E2E, and isolated Codex autoreview.
* test: align package smoke with pnpm 12 global installs
* test: follow native pnpm artifact approval in distribution guard
* test: modernize pnpm fixtures for v12
* test: align rebased update fixtures with pnpm 12
* test: retain sanitized upgrade restart diagnostics
* test: expose CI navigation failures and register diagnostics
* test: retain post-core outcomes and plugin artifact identity
* chore(tooling): group upgrade diagnostic entrypoints
* fix(update): support native pnpm global installs and source links
Qualify local source and archive specs, carry verified global ownership through pnpm configuration, and verify intentional checkout links with shared runtime-readiness checks. Preserve strict packaged-install verification and manager ownership safeguards.
Verified the production updater with pnpm 11.22 and 12 using default and custom roots, source links, and tarball updates.
* test: preserve survivor diagnostics after service sealing
Promote incomplete exit-zero runs before failure capture and exercise the sealed-service manager fixture without inventing successful child exits.
* fix(update): preserve legacy pnpm global ownership
Carry the verified root and bin through both pnpm and npm configuration dialects after original-environment probes. Real pnpm 10 custom-root updates and pnpm 11/12 source and tarball matrices pass without redirecting the caller or weakening ownership checks.
* test(update): verify wizard consent through checkout handoff
Use the prepared checkout and fresh-process finalization boundary introduced by the updater repair. Preserve explicit consent forwarding before and after the wizard subcommand without assuming plugin callbacks run in the old process.
* refactor(update): validate checkout build metadata records
Use the canonical record coercer instead of carrying an unchecked assertion into the shared runtime verifier. Remove the now-unused grandfathered assertion entry; no allowance is added.
* docs(sandbox): document standalone common-image inputs
* test(packaging): account for required native prebuilds
Align installer and release size budgets at 235 MiB for the required native payload added on main. Keep both loader layouts, upstream binaries, explicit overrides, and missing-data rejection intact. Exercise actual defaults and the one-byte boundary. Retain bounded stderr diagnostics for the intermittent Bun signal test without claiming a production signal fix.
* test: align refreshed installer fixtures with pnpm 12
* fix(test): share Bun smoke force-kill ownership
Record the successful force-kill once across the timer and post-close drain. Native Darwin traces reproduced both duplicate-signal orders; genuine permission failures and uncleared groups still fail without extending deadlines.
Download the non-root Docker smoke installer before executing it.
- preserve the existing 30-second connection and 300-second transfer limits
- clean up the temporary installer on success or failure
- prove failed downloads cannot execute partial installer content
Co-authored-by: thomas.szbay <xydigit-zt@users.noreply.github.com>
Punchcard-Session: golden-lantern-meadow-0x
* fix(ci): bound CLI installer smoke curl with connect and max-time
The non-root CLI installer smoke pipes curl directly into bash under a
single docker-run timeout. curl has no default connect or total timeout,
so a stalled CDN connect or hung response body could pin the container
until the outer docker-run budget kills it. Bound the curl with the same
--connect-timeout 30 --max-time 300 shape already used by install-sh-smoke
and install-sh-e2e, and enable pipefail so curl failures are not masked
by the bash consumer.
* test(ci): cover bounded CLI installer pipeline
* fix(ci): bound preceding non-root installer download
* fix(ci): harden bounded installer URL handoff
Co-authored-by: zhang-guiping <zhang.guiping@xydigit.com>
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com>
* fix(docker): bound smoke installer curl with connect timeout
Add --connect-timeout 30 and --max-time 300 to the direct installer
one-liner curl in the smoke test runner. The run_installer_for_package_spec
function is already bounded by timeout(1), but this direct invocation had
no curl-level or wrapper-level timeout.
Co-Authored-By: Claude <noreply@anthropic.com>
* fix(docker): wrap complete installer pipeline in timeout, not just curl
Replace the stand-alone curl timeout flags on the direct installer one-liner
with a timeout(1) wrapper around the entire curl|bash pipeline, matching the
run_installer_for_package_spec pattern. This bounds the complete pipeline
(download + install) rather than just the network transfer.
The curl-level --connect-timeout 30 and --max-time 300 are retained as
defence-in-depth inside the timeout wrapper.
Co-Authored-By: Claude <noreply@anthropic.com>
* refactor: centralize installer smoke pipeline bounds
Co-authored-by: LZY3538 <liu.zhenye@xydigit.com>
---------
Co-authored-by: Claude <noreply@anthropic.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>