Commit graph

10569 commits

Author SHA1 Message Date
Peter Steinberger
f8a3418494
refactor(scripts): deslop tooling subdirectories and agent skill helpers (#159218)
Consolidate repeated tooling flows while preserving command contracts. Fix swallowed HTML translation errors and browser-realm error handling in the Google Live smoke. Owner tests and CLI parity passed on Testbox; final broad gate replay follows a fixture lint correction.
2026-09-26 18:13:40 -07:00
Ben.Li
10e9c41a9a
fix(install): fail when OpenClaw is not on PATH (#134406) 2026-09-26 18:35:06 -06:00
Peter Steinberger
d06b334112
improve(state): speed up repeated session database cleanup (#158763)
* perf(state): avoid redundant worker startup during database cleanup

Close idle reader resources without discarding their loaded worker code. Trust a matching completed native close to avoid starting another writer for an already released lease, while retaining recovery for uncertain exits. Bound concurrent cleanup to one exit listener per worker.

* fix(infra): join worker retirement during resource cleanup

* fix(sessions): retire warm readers during runtime shutdown

* fix(sessions): release reader validation metadata after cleanup

* fix(pr): include agent resource owner in sealed source bundle

* test(gateway): surface workspace recovery callback failures

* test(sessions): gate stale checkpoint proof on native close

* test(gateway): serialize foreign writes in recovery fixture
2026-09-26 17:31:18 -07:00
Peter Steinberger
e68cfe26f1
ci: defer 195 slow integration tests from unrelated PRs (#158267)
* ci: defer slow integration tours from unrelated PRs

* fix(ci): keep shared runtime tests in their owning projects

* fix(ci): resolve PR-exempt inventory from the checkout
2026-09-27 00:17:32 +00:00
Peter Steinberger
0027d1c951
fix(plugins): reduce long garbage collection pauses during streaming (#159103)
* perf(plugins): carry host value ownership in private fields

Reduce ephemeron marking during streamed replies by keeping host view, native continuation, original-value, and iterator-reader metadata on the objects themselves. Preserve foreign associations, source caches, receiver binding, lazy getters, and exact instance and consumer admission.

* fix(plugins): make value ownership storage a typed leaf

Pass the exact owner type from the existing process singleton instead of importing the scope contract back into the storage implementation. Keep the private brand within the once-created store so SDK and native callers retain one ownership identity without a static import cycle.

* fix(tooling): include plugin ownership in PR wrapper sources
2026-09-27 00:16:03 +00:00
Josh Avant
8d3f946089
improve(ios): shorten CI failure diagnostic collection (#159261) 2026-09-26 19:10:23 -05:00
Peter Steinberger
0a9fa7dafa fix(pr): include session config classifier in wrapper inventory
Include runtime-session-changes.ts, imported by the already-extracted
runtime-snapshot.ts since 945ec9ff56 (#159155). Its runtime dependencies
are already in the inventory. This restores trusted-anchor extraction and
native PR source provisioning without expanding the wrapper entry points.

Reproduced both closure failures and three macOS provisioning failures
before the fix. Replayed the exact failing CI shard selections through
ci-run-node-test-shard: 32 passed, one Linux-only case skipped on macOS.
The code-mode Gateway evidence file passed all five tests; its logged
harness_error is an intentional synthetic failure, not a broken test.

Validation: check:import-cycles (zero cycles), scripts typecheck,
changed-file guards and lint/format checks, and autoreview clean through P2.
2026-09-26 16:56:08 -07:00
Josh Avant
8fc5038f8c
fix(ios): stabilize native release qualification (#159065)
* fix(ios): qualify chat from an empty conversation

* fix(ios): seed chat history before dismissal checks

* fix(ios): request pairing setup from the ready Gateway

* fix(ios): retain safe XCTest failure locations

* test(ios): diagnose missing release qualification replies

* fix(ios): preserve pending messages and qualify current replies

* chore(ci): refresh checks after main lint repair

* test(ios): capture hosted chat submission state

* fix(ios): preserve drafts during initial agent resolution
2026-09-26 18:37:43 -05:00
Peter Steinberger
cec2db630d
refactor(qa-lab): deslop qa-lab third pass (#158889)
* refactor(qa-lab): deslop qa-lab third pass

* chore(qa-lab): shrink browser fetch callsite allowance
2026-09-26 22:41:22 +00:00
Peter Steinberger
c5b5d5ac95
perf(crabbox): shrink source-mirror allocation critical section and wait briefly instead of cold fallback (#159195) 2026-09-26 22:19:21 +00:00
Peter Steinberger
c147e0e652
refactor(ios): deslop iOS app second pass (#159091)
* refactor(ios): deslop iOS app second pass

* test(ios): follow inlined onboarding source paths

* chore(ios): refresh CI after upstream cron fixture repair

The prior merge-ref run failed core test-type stripes 2 and 5 on missing scheduler dependencies. Main commit c0e6951d6f repairs all affected fixtures. Preserve the reviewed iOS source tree and run fresh merge-ref CI with that upstream repair.
2026-09-26 14:57:04 -07:00
Peter Steinberger
439940bf0b
improve: speed up updater Doctor startup (#159044)
* perf: defer updater Doctor inspection imports until worker handoff

* refactor: route triage directly to the Doctor findings runner

* fix: seal compiler inputs from their captured read bytes
2026-09-26 14:52:58 -07:00
Peter Steinberger
a1019cb759
fix(android): accept ImageMagick 7 RGB metadata (#159158) 2026-09-26 14:22:08 -07:00
Peter Steinberger
387689c418
fix(e2e): keep older upgrade baselines valid (#159150)
Scope the missing-load-path fixture to published drivers that admit invalid configuration before staging. Retain ordinary update and migration checks for older drivers, preserve exact-row reruns, and record fixture applicability in the published receipt.
2026-09-26 14:12:24 -07:00
Peter Steinberger
19c6ef8d9e
fix(proxy): keep capture persistence off the main thread (#158848)
* fix(proxy): keep capture persistence off the main thread

Move bundled capture writes, payload compression, and inspection through the canonical SQLite workers. Preserve shipped synchronous SDK compatibility and exact database, maintenance, and accepted-callback ownership.

Drain accepted capture before shutdown, release partial proxy startup, and charge queued payload preparation through the existing broker. Preserve schemas, stored bytes, and retention. Related: #148336.

* chore(proxy): reconcile capture activation with current main

* chore(proxy): preserve current SDK surface counts

* refactor(proxy): isolate async capture store contract

* fix(proxy): include worker dependencies in PR wrapper

* chore(proxy): compose capture migration with current main

* test(proxy): finish database worker lane routing

* test(proxy): retain Node coverage after worker lane migration

* fix(proxy): drain active captures before signal exit

* fix(proxy): preserve legacy capture cleanup in mixed sessions

* fix(proxy): preserve capture metadata and composed worker routes

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-26 13:45:36 -07:00
Vincent Koc
0e27650f8e
fix(release): reconcile an existing iOS beta build (#159109)
* fix(release): reconcile existing iOS beta build

* fix(release): complete iOS reconciliation checks

* test(release): verify inherited reconciliation env

* test(release): scope reconciliation API fixtures
2026-09-27 04:39:52 +08:00
Peter Steinberger
734f865896
fix(test): restore update restart outcome fixture (#159127)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-26 13:10:22 -07:00
Peter Steinberger
718bf2ccae
refactor(cron): own retained run transcript access (#158776)
* refactor(cron): own retained run transcript access

* fix(cron): preserve worker-owned history visibility and current filters

Prepare exact session sharing facts through the existing history worker and rebuild current job names and filters after awaited preparation. Add packaged cron.history pagination proof and keep the transcript renderer private.

Validation: four registered rename race controls fail before the fix; 15 run-history cases and 280 affected Cron cases pass. Shared worker/caller proof, affected types, lint and independent review pass. Packaged published-updater proof follows on this source.

* refactor(gateway): keep session source requests with store types

Move the unchanged source-discovery request out of its runtime owner so retained-history transport types do not create a static import cycle. Both consumers use the existing store contract module.

Validation: Madge reproduces the cycle on the prior head and passes on both the repaired head and exact CI merge; runtime cycles, core types, lint and independent P2 review pass. Executable ESM is unchanged apart from whitespace, and package proof retains its original source identity.

* fix(gateway): keep history discovery inside its worker dispatcher

Supply canonical lazy source discovery from the admitted history worker. The read-only kernel consumes the callback and retains its per-operation cache without importing acquisition or transcript mutation owners.

Validation: unchanged import guard reproduces eight forbidden paths before the fix and passes after it; 121 focused cases pass with one optional benchmark skip. Real worker compilation, lifecycle, cancellation, cache and source-custody cases, both cycle gates, affected types, lint and fresh independent P2 review pass.

* refactor(gateway): distinguish history reader and request targets

Rename the worker reader target binding so message lookup and recent-page targets retain their existing local names without shadowing. Exact typed lint, formatting and fresh P2 review pass; runtime behavior is unchanged.

* test(gateway): verify store warnings at the collision owner

Keep cached-head history assertions independent of incidental eager discovery and host-only logger mocks. The actual worker still emits the original warning when discovery is needed; verify that exact diagnostic in the existing real collision-owner case alongside target mapping and physical database separation.

Validation: original ordered CI entry reproduced the failure; real chat.history worker diagnostic probe preserved the warning. All 57 focused cursor/collision/source tests pass (141.38s wrapper), both affected type graphs, exact lint and fresh P2 review pass. No production behavior or new fixture boot.
2026-09-26 19:17:22 +00:00
Vincent Koc
910145c419
fix(ci): resume interrupted protected PR preparation (#159045)
* fix(ci): resume interrupted protected PR preparation

* fix(ci): recover completed legacy gate receipts
2026-09-27 02:40:25 +08:00
Peter Steinberger
f0b78f55d6
refactor(channels): route ingress queue through the state broker (#159073)
## What Problem This Solves

The shared channel ingress queue still performs operational reads and writes synchronously on the Gateway thread, despite exposing an asynchronous API.

## User Impact

Inbound persistence and replay use the existing shared-state SQLite broker. Admission returns only after commit; claim fencing, per-account ordering, dedupe, retention, and accepted-write settlement remain intact. Operational listings observe earlier committed writes and still create a missing database for ordinary read-write queues. Explicit read-only inspection remains noncreating.

Update behavior: no schema, stored-byte, config, port, webhook path, signature, dedupe-window, or retention change; no migration or operator action. The maintainer approved the worker-access change and the broker-ordered listing adjustment. Legacy pre-May-31 Telegram spool import and Telegram startup profiling remain documented follow-ups, as directed.

## Why This Change Was Made

All twelve mutations and the operational listings cut over together to preserve one FIFO owner. Diagnostic failed-health, pressure, and account discovery already use read-only workers. Channel parsing and lane policy stay on the host; the worker verifies the prepared ordered snapshot before applying a claim or recovery decision. Custom claim clocks are sampled at transaction admission. Accepted commits settle even if caller authority later revokes.

The drain consumes one coherent pending/claimed snapshot. `listUnsettled` is optional for existing external queue implementations through the next SDK major. `purge` accepts an optional cancellation signal, and Telegram passes its existing signal. Runtime construction binds live plugin authority to every operation, replacing the purge-only wrapper. The existing table and database version are unchanged.

Deletes the main-thread queue SQL path and superseded runtime wrapper. The final write cutover is intentionally larger than the fixture slices because mixing native and broker mutations would break admission ordering. Earlier slices removed Telegram directory helpers and consolidated shared fixture scaffolding.

Production +964/-942/net +22; tests and test support +837/-315/net +522; docs +41/-18/net +23; tooling +3/-0/net +3. The runtime growth preserves authority and settlement across a worker boundary. All earlier slices plus this candidate total production net +446; test fixture consolidation reduced the original +517 growth to +386 before the final routing/regression coverage.

## Evidence

Provider: blacksmith-testbox. Lease `tbx_01m3f53n667mcj031n55vm5tj8` ([run](https://github.com/openclaw/openclaw/actions/runs/36251856365)), frozen install, `pnpm tsgo:core` (41.13s), `pnpm tsgo:extensions:test` (78.55s), and inventory generation/check passed. Nine focused owner files passed 144 tests. Single-worker wall cost per file: queue 33.02s; claim ownership 9.28s; readonly access 8.07s; pruning 7.20s; drain lanes 8.50s; monitor 9.44s; plugin-state runtime 14.12s; registry runtime-config 11.08s; Telegram monitor 15.15s. The two changed tooling files passed 381 tests in a combined 192.99s single-worker wall.

The additional 72-file per-config run used `pnpm test <explicit routed ingress paths> --maxWorkers=1`: 128 core tests and 855 extension tests passed, with two fixture failures over 518.11s. LINE and MS Teams waited for a `listPending` spy that the coherent snapshot intentionally replaces. Both fixtures now capture the real monitor and await its pump, preserving the eight-delivery cap and queued-row assertions.

Lease `tbx_01m3faw6necd61h11wcf6se4hs` ([run](https://github.com/openclaw/openclaw/actions/runs/36257798905)) proved the corrections: `pnpm test extensions/line/src/webhook-spool.test.ts --maxWorkers=1` passed 14 tests in 31.09s; `pnpm test extensions/msteams/src/msteams-ingress.test.ts --maxWorkers=1` passed 15 in 18.32s. Extension types (79.74s), runtime import cycles (9.38s; zero), Madge cycles (26.36s; zero), SDK exports (0.22s), and docs sanity (54.79s) passed. The existing pruning case with padded protected IDs passed (five tests, 8.46s). Negative controls failed for the intended reasons: removing normalization deleted a protected row; raising either channel's cap to nine caused nine deliveries where eight were required. The production controls were restored and checked.

Worker routing is covered by actual queue operations with calling-thread SQLite primitives refusing execution. Regression probes also cover missing database creation, committed-then-list inside an older ambient snapshot, live authority after awaited policy, custom-clock transaction grants, post-grant settlement, and coherent lane inspection. No weaker guards or assertions were substituted.

Deslop is clean. Codex P0–P2 review is clean after supplying the full unchanged worker kernel: two earlier allegations were disproven by existing normalization and corrupt-row filtering, with direct tests. The final review used a byte-verified capture of the full 35-file diff and the broker/kernel context. Rebase onto `4ab72dd0d2` was patch-identical. The maintainer authorized GitHub exact-head auto-merge; required CI remains the gate.

Fresh proof on published source head `b828403ef8f309ffda1e4859f6eca3268fdc66cb` (same lease): queue/claim/readonly regression suites passed 47 tests in 38.51s; regenerated inventory and its check passed (545 source files, 2543 primitive calls). `pnpm plugin-sdk:api:diff --base 4ab72dd0d2 --head b828403ef8f309ffda1e4859f6eca3268fdc66cb` passed in 242.79s; exports passed in 0.17s. The SDK acknowledgement digest is `e2cba13f`. No entrypoints were added or removed; the additive queue contract is intentional and documented. Final head `0b24c42b9242b07e1a7c60147b4cba5f46d5bd91` only refreshes two generated source-line references.

Merged-main signed-SMS SIGKILL/replay proof is the remaining post-merge task and will be recorded in this PR.

## Stack

Landed: #157687 → #158203 → #158233 → #158288 → #158412 → #158477 → #158628 → #158637 → #158860 → #158887 → #158896 → #158928 → #158933 → #158980 → #158987 → #159006 → #159008. This is the final atomic broker cutover and inventory slice. Signed-SMS crash/replay proof follows on merged main.
2026-09-26 18:38:19 +00:00
Peter Steinberger
12bc123ec9
test: stabilize flaky fixtures (batch f036) (#159046)
* test(gateway): stabilize CLI question authority fixtures

Align the webchat fixture's runtime registry with its disabled-plugin config.
Shared channel stubs otherwise load bundled message adapters during tool
resolution, delaying the test deadline and letting stale teardown interrupt
the following case.

Proof: both reported cases passed 10 isolated runs; the complete 13-case file
passed twice. Formatting, typechecking, targeted lint, and P2 autoreview
passed. check-changed hit only Knip ETIMEDOUT on both permitted attempts.

* test(slack): stabilize auth monitor fixtures

Align supplied and ambient fixture config to avoid cold bundled-plugin discovery. Own and join dispatch work before resetting shared state, and wait on Bolt readiness events. Control the stalled-auth deadline through real request and socket-close events, with cancellation-aware cleanup and fixture-owned database setup.

* test(gateway): stabilize mock provider readiness

Wait for the existing bound-port announcement on an OS-assigned port instead of racing the implicit one-second startup poll. Preserve the real health check, cancellation, cleanup, and stream assertions. The final full-shard run passes both streams and global run observation.

* test(commands): stabilize doctor preflight fixtures

Scope real plugin discovery to each fixture and prepare the compiled Discord package needed by config migration coverage. Keep cold unrelated plugin imports outside the existing test deadlines.

* test(cli): stabilize startup and broadcast fixtures

* test(scripts): stabilize Android qualification fixture

* test(auto-reply): stabilize SCP cancellation fixture

* test: preserve existing CLI runtime shard budget

Keep the broadcast fixture stabilization but drop the startup-only build prerequisite that pushes the retained CLI runtime cohort beyond its existing prediction bound. Preserve main startup behavior and all bounds. Include Doctor preflight in its exact runtime ownership expectations.
2026-09-26 18:33:26 +00:00
Peter Steinberger
e67317ae3b
fix(tooling): let the CI watcher run from worktrees without node_modules (#158754)
* fix(tooling): resolve standalone CI watcher dependencies

Resolve missing bare imports from the scripts/pr tooling root in dependency-free worktrees. Keep local resolution first and scope the hook to the watcher child without creating a node_modules link or changing wrapper selection.

* fix(tooling): keep configured modules dirs on the watcher link path

* fix(tooling): validate CI watcher fallback dependencies

Validate explicitly selected tooling roots against repository identity and check fallback package versions against the caller manifest before loading code. Preserve canonical-default identity handling and successful local resolution.
2026-09-26 18:27:32 +00:00
Peter Steinberger
da76ab304a
test(core, plugins): remove low-value tests (batch d039) (#159090)
* test(status): deslop s223 tests

* test(onepassword): deslop s225 tests

* test(mcp): deslop s224 tests

* test(scripts): deslop s215 tests

* test(fal): deslop s226 tests

* test(feishu): deslop s227 tests

* test(amazon-bedrock-mantle): deslop s229 tests

* test(lobster): deslop s234 tests

* test(comfy): deslop s228 tests

* test(irc): deslop s230 tests
2026-09-26 18:26:30 +00:00
Peter Steinberger
605cc417c0
fix(plugins): load current plugins while update rollback trees are retained (#159052)
* fix(plugins): load current plugins while update rollback trees are retained

* fix: preserve plugin capture dependencies in PR wrapper extraction
2026-09-26 18:02:34 +00:00
Peter Steinberger
5a27fda950
improve(check): skip typecheck lanes for comment-only TypeScript edits (#158796)
* perf(check): skip typecheck lanes for comment-only TypeScript changes

Compare regular TypeScript sources against the merge base with the native parser and shared AST-aware token walker. Preserve ASI boundaries, directives, path lifecycle safety, and all non-typecheck gates; keep unguarded release metadata comparisons conservative.

* fix(check): reject lossy UTF-8 in comment-only typecheck classification

* fix(check): treat TypeScript pragmas case-insensitively in comment-only classification

* fix(check): keep token adjacency in comment-only typecheck classification

* test(check): satisfy array destructuring lint in classifier cases

* fix(check): keep tagged JSDoc pinned in comment-only typecheck classification

* fix(check): pin trivia around tagged JSDoc in comment-only classification

* fix(test): keep the comment-only classifier test on Node
2026-09-26 10:49:27 -07:00
Peter Steinberger
960f702292
fix(test): clean up completed shard scratch caches (#159051) 2026-09-26 17:30:15 +00:00
Peter Steinberger
614aa3acff perf(build): avoid duplicate native declaration transforms
Native SDK preparation transformed declarations separately for diagnostics,
then repeated preflight and transformation during in-memory emission. Keep
configuration and requested semantic validation, collect declaration errors
from EmitResult, and reject errors or skipped emission before publication.
Remove the unused includeDeclaration diagnostic option.

Measured cold Node 24 preparation fell from 156.294s to 89.817s; sampled
process-group memory fell from 8.845 to 6.961 GiB. The existing 300-second
limit and Go memory settings are unchanged. This removes proven duplicate
work; it does not conclusively reproduce the historical CI timeout.

Proof: real native tests reject TS4094 and lazy-global TS2318 in both
modes, reject TS2322 in all mode, and accept valid declarations. Focused
suite: 14 passed/3 platform skips, 6.176s wall. Sibling preparation and
tsdown integration: 52 passed/7 platform skips. Changed-file checks,
types/lint, and final independent review through P2 pass.

The native API global-diagnostics handler already forces semantic checking
before collecting fileless diagnostics; source inspection and real API
probes resolve the apparent late-global diagnostic gap. Declaration member
order and synthesized readonly modifiers vary across unchanged original
compiler runs, so generated byte equivalence is not claimed.
2026-09-26 10:07:01 -07:00
Peter Steinberger
4506110398 fix(ci): settle cron notifications and preserve upgrade diagnostics
Repair failures observed in main CI run 36252117384. The cross-tick
cron test used wall-clock deadlines and counted independent notification
admissions before they settled. Use the existing fake clock, advance the
armed wake, and join captured delivery scopes before exact root assertions.

Capture no-op upgrade stdout/stderr through the existing bounded,
redacted diagnostics owner and clear stale files before each attempt.

Proof: delayed-notification negative control reproduced the cron failure;
20 isolated passes and 3 original-order 130-file/1462-test shard passes.
Cron case cost fell from 2.035s in CI to 0.116-0.120s locally. The existing
39 diagnostics cases pass (3.673s wall), including capture, redaction,
bounds and cleanup. Targeted types/lint/format and independent review pass.

The unrelated inherited OpenRouter max-lines guard has separate active
repairs. Diagnostics do not fix the underlying upgrade failure; its fixture
owner was subsequently repaired in 39db93e000. The parallel UI thinking
metadata assertion fix landed as fbaafc381f and is excluded here.
2026-09-26 09:53:47 -07:00
Peter Steinberger
39db93e000
fix(ci): run survivor no-op with a foreground gateway
Commit 6209f31ce9 correctly requires native service membership for update
maintenance. The survivor's systemd emulator cannot provide cgroup ownership,
so scheduled Docker seed changed from green at 8778b46ccf (36232986428) to
red at 468039ab18 (36235938832) during the final same-version update.

Keep the published-driver managed restart proof, then hand over the unchanged
no-op and state-survival assertions to a live foreground Gateway on the same
migrated state. Verify that it survives and the shim stays inactive; restore
the existing service and refresh status before checking Doctor. Keep native
membership guards and every existing assertion intact. The managed no-op
contract remains covered by update-cli.already-current.test.ts, "never stops
an unchanged same-version managed gateway (restart=%s)".

Linux Testbox: reproduced exit 1 / service-membership-unverified before;
identical product tarball passes the full scenario after (398s). New lifecycle
handover costs 26.7s in this release-tier Docker scenario. All 21 direct script
consumers plus updater and native-membership tests pass: 3369 tests, 23 files,
4 CI configs, 274.94s. P2 autoreview, changed checks, shell syntax, and diff
whitespace checks pass. Focused boundary lint has no applicable shell input.
2026-09-26 09:41:45 -07:00
Josh Avant
d8dfa4be3f
fix(ios): qualify releases with installed simulator runtimes (#158865)
Co-authored-by: joshavant <830519+joshavant@users.noreply.github.com>
2026-09-26 11:26:52 -05:00
Vincent Koc
2864f56579
fix(tooling): let check implementations own cancellation (#157272)
* fix(tooling): let check implementations own cancellation

* fix(tooling): integrate cancellation ownership with current main

Co-authored-by: Vincent Koc <vincentkoc@ieee.org>
2026-09-26 23:52:17 +08:00
Josh Avant
3304be1be3
fix(android): accept historical uploaded version codes (#158864) 2026-09-26 10:38:05 -05:00
Peter Steinberger
7fbe426cda
test(core,plugins,scripts): remove low-value tests (batch d023) (#158911)
* test(media): deslop s155 tests

* test(googlechat): deslop s156 tests

* test(scripts): deslop s140 tests

* test(reef): deslop s158 tests

* test(infra): deslop s153 tests

* test(microsoft-foundry): deslop s163 tests

* test(ai): deslop s164 tests

* test(sessions): deslop s160 tests

* test(browser): deslop s165 tests

* test(config): deslop s162 tests

* test: preserve redaction and current release identity coverage

* test: retain helpers used by current main regressions

* test(googlechat): use current config type owner

* test(googlechat): remove unused config type import
2026-09-26 15:29:21 +00:00
Peter Steinberger
7b68c81b60
test(core,plugins,tooling): remove low-value tests (batch d011) (#158811)
* test(agents): deslop s035 tests

* test(scripts): deslop s030 tests

* test(browser): deslop s039 tests

* test(gateway): deslop s034 tests

* test(copilot): deslop s040 tests

* test(auto-reply): deslop s042 tests

* test(agents): deslop s041 tests

* test(scripts): deslop s022 tests

* test(sessions): deslop s036 tests

* test(cli): deslop s037 tests

* test: adapt d011 fixtures to current owners

* test: preserve current native i18n guidance

* test: preserve d011 authorization coverage and diagnostic assertions

* test: retain fixture imports used by newer main tests

* test: fix lint in d011 test reductions

* test(copilot): remove obsolete max-lines suppression
2026-09-26 14:41:59 +00:00
Peter Steinberger
10453a8d8b
fix(doctor): migrate every agent database before repairs open it (#158584)
* fix(doctor): migrate every agent database before repairs open it

Complete configured session-store targets before media/schema repair.
Recognize intact pre-journal v1 state without releasing lost-history holds,
and fail explicit Doctor repair when those holds remain unresolved.

Refs #158359.

* fix(tooling): include journal admission in wrapper inventory

* fix(doctor): admit pre-journal v1 stores with writer metadata

Treat app_version as optional writer metadata rather than evidence that a
schema-v1 store had a deletion journal. Keep the schema, ownership, newer-table,
journal-receipt, and recovery-hold guards intact.

Register the agent database ordering regression with the runtime-build
prerequisite owner so it runs in a clean checkout. The two CI runtime-inventory
expectation updates add exactly this newly registered test input; they preserve
exact equality, runtime preparation, ownership, and worker-bound checks.

Refs #158359.

* test(state): require initialized journal after v1 admission

The accepted production behavior intentionally initializes the canonical
agent_deletion_journal when admitting a valid pre-journal v1 store. Update the
v2026.7.1-2 fixture contract to require the complete canonical schema and assert
that the deletion-history owner reports known-empty history.

This expectation changes because journal initialization changed intentionally
in production, not to silence the check. Preserve the full schema comparison,
frozen fixture hashes, retained-data checks, and modern lost-history assertions.

Refs #158359.
2026-09-26 13:38:18 +00:00
RoboClaw
002288fc66
fix(workers): stop checkpoint writes after authority closes (#150611)
Prevent repository checkpoints from publishing after worker or remote-editor authority closes, while retaining independently verified recovery data. Recheck live authority and workspace revision at preparation, import and final Git input admission.

Prepare publication companions through the existing bounded worker Git-input writer instead of copying every blob on the Gateway. Preserve stored companion identities and remove per-blob synchronous SQLite amplification. Cover drained/live reconciliation, cancellation, revision fences, cleanup and legacy/direct Git equivalence.

Co-authored-by: sallyom <11166065+sallyom@users.noreply.github.com>
Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
2026-09-26 06:19:45 -07:00
Ayaan Zaidi
09a60518fc
feat: reserve ordered model recommendations in catalog v2 (#158863)
## What Problem This Solves

Provider authors need one ordered, curated model shortlist in the catalog, without scattering recommendation flags across model rows.

## User Impact

No user-visible change. `recommendedModels` remains dormant: no bundled manifest sets it, and no picker or runtime consumes it. Released v1 readers retain their existing strict contract.

## Why This Change Was Made

Add optional provider-owned `recommendedModels` beside the existing model defaults. Lists retain order, trim ids, reject duplicates, and reference only the same provider's models. Manifest normalization omits invalid lists like other invalid optional metadata; the strict v2 parser rejects them. The generator projects this metadata directly from manifests into v2 and excludes it from v1. The manifest reference documents its reserved status.

The approved scope is to reserve this provider-owned shortlist now and leave it dormant, rather than attach a picker consumer. It does not supersede existing manifest row ordering: current picker ordering remains unchanged, and any future consumer's precedence and behavior are outside this change.

## Evidence

- Ran the real catalog generator with `--pricing` on base and candidate: both versions were byte-identical after excluding `generatedAt` and `sourceCommit` (44 providers, 1,070 model rows).
- Temporarily enabled an ordered two-model shortlist in a local manifest, ran the real generator again, and parsed both outputs: v2 retained the ordered ids, v1 contained no `recommendedModels`. Removed the temporary manifest setting.
- All 53 focused tests passed in 3.18 seconds wall (one worker), covering valid ordering, unknown/foreign ids, duplicates after trimming, blank/non-string ids, and strict v1 exclusion.
- The publisher uses the same manifest normalization owner before v2 projection. A real priced paired-generator run with an unknown recommended id completed successfully and omitted the list; the paired-output regression covers invalid and valid lists together (4 tests passed, 1.56 seconds runner wall).
- A direct normalization/parser smoke retained twelve ordered recommendations; catalog metadata does not choose how many a future picker presents.
- Production/tooling delta: net +46 lines; test delta: net +68. No runtime consumer, new module, or UI change.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-26 18:13:21 +05:30
Peter Steinberger
9faa93d44c
perf(plugins): stop reading native plugin artifacts at startup (#158414)
* perf(plugins): bound native artifact capture memory

Preserve source verification and raw-byte generation receipts while hashing in bounded chunks and copying from admitted descriptors.

Refs #157815 #157791 #157545

* test(doctor): inject plugin capture failures into native copies

* perf(plugins): stop reading native plugin artifacts at startup
2026-09-26 05:21:17 -07:00
Peter Steinberger
98104757ce
perf(crabbox): share the final source mirror inventory (#158828)
* perf(crabbox): share the final source mirror inventory

Collect mirror stamps during the fresh staging manifest walk, retaining the separate pre-Git integrity scan and both source freeze checks. Remove one complete payload traversal without changing persisted formats or cache custody.

* fix(crabbox): require recorded mirror allocations

Enforce the staging owner contract before opening the mirror database, including cold rebuilds. Dispose invalid allocations and report the invariant instead of accepting an empty final inventory.
2026-09-26 11:37:11 +00:00
Peter Steinberger
2ff07dbab3
fix(update): check artifact ownership before stopping the Gateway on source updates (#158849)
* fix(update): reserve source artifacts before Gateway shutdown

Validate the installed checkout before activation and hold its artifact ownership through joined completion. Retained owners include exact recovery guidance and are never reclaimed based on PID death. Preserve published source adapters and fail closed when child cleanup remains uncertain.

Fixes #158281. Reported by @hannesrudolph.

* refactor(update): keep Git candidate rejection in admission

* refactor(update): carry native artifact admission into completion

* refactor(ui): inline sidebar navigation lookup input

* fix(update): keep artifact ownership declarations portable
2026-09-26 11:28:41 +00:00
Josh Avant
cd2724e432
feat(release): automate iOS and Android store releases (#158807)
Add manually triggered iOS Store Release and Android Store Release workflows with the same local release commands. Derive store versions and OpenAI release notes at build time, retain recovery artifacts, and avoid generated metadata commits.

Pin queued releases to their dispatch commit, qualify native iOS behavior before signing, and improve Android screenshots and interrupted artifact recovery.

Validation includes focused release/planner tests, workflow and type checks, native iOS qualification, Android screenshot capture, and historical release-note exercises. CI failure attribution and remaining hosted release verification are documented in the PR.

Closes #158806
2026-09-26 06:28:29 -05:00
Peter Steinberger
11a11ef164
feat(gateway): preserve callback ports on plugin routes (#158360)
* feat(gateway): add compatibility listeners to plugin routes

* fix(gateway): preserve legacy listener wire contracts

* fix(plugins): reject conflicting legacy listener profiles

* fix(gateway): drain retired webhook listeners before release

* fix(gateway): avoid shadowing the active legacy endpoint
2026-09-26 04:27:10 -07:00
Peter Steinberger
813169e282
fix: allow builds and lint in nested checkouts (#158674)
* fix: allow builds and lint in nested checkouts

Use the pinned native TypeScript 7.1 API to bound declaration resolution before ancestor installations can influence build and lint inputs. Keep portable input receipts, mutation fences, cache validation, and child cleanup, while preserving the SDK revision renderer dependency contract.

* fix: admit pinned prerelease native compilers

Accept the exact TypeScript prerelease version used by bounded declaration emission before trusted frozen-client parsing. Preserve lock, package, native executable, ownership, and integrity validation, with explicit range and tag rejection coverage.

* test: include compiler worker in artifact ownership fixture
2026-09-26 11:19:13 +00:00
Peter Steinberger
2bdf8709fc
test(core): remove low-value tests (batch d009) (#158725)
* test(codex): deslop s003 tests

* test(gateway): deslop s010 tests

* test(agents): deslop s013 tests

* test(commands): deslop s011 tests

* test(gateway): deslop s014 tests

* test(gateway): deslop s019 tests

* test(infra): deslop s016 tests

* test(agents): deslop s020 tests

* test(scripts): deslop s017 tests

* test(auto-reply): deslop s021 tests

* test: align d009 replay with current fixture contracts

* test(agents): remove orphaned BTW fixture export

* test: preserve independent regression coverage in d009

Restore eight independent authentication, retry, transcript, goal, reply ownership, and Xcode coverage contracts identified during review. Final correction review passed; final Testbox validation remains pending after lease and transport failures.
2026-09-26 11:08:36 +00:00
Peter Steinberger
443a0676b9
refactor(channels): extract ingress mutation kernels (#158628)
* refactor(channels): extract ingress mutation kernels

* docs(state): refresh ingress kernel inventory

* docs(state): refresh ingress worker inventory
2026-09-26 04:05:43 -07:00
Peter Steinberger
2a53c32dc2
test(channels,infra,sdk): remove low-value tests (batch d016) (#158764)
* test(signal): deslop s080 tests

* test(node-host): deslop s085 tests

* test(imessage): deslop s084 tests

* test(scripts): deslop s075 tests

* test(flows): deslop s089 tests

* test(slack): deslop s087 tests

* test(mattermost): deslop s091 tests

* test(infra): deslop s086 tests

* test(plugin-sdk): deslop s090 tests

* test(voice-call): deslop s092 tests

* style(test): format batch d016 replay

* test(mattermost): preserve retained reaction regression

* test: retain independent contracts in batch d016

* test(plugin-sdk): avoid shadowed table labels

* test(node-host): remove unused runtime test type
2026-09-26 10:51:39 +00:00
Peter Steinberger
35f17c7f5d
test(core,plugins,scripts): remove low-value tests (batch d012) (#158802)
* test(agents): deslop s047 tests

* test(codex): deslop s045 tests

* test(gateway): deslop s049 tests

* test(commands): deslop s048 tests

* test(scripts): deslop s012 tests

* test(scripts): deslop s046 tests

* test(workboard): deslop s053 tests

* test(plugins): deslop s051 tests

* test(slack): deslop s054 tests

* test: preserve current fixture contracts after replay

* test: retain distinct cleanup contracts and fixture scopes

* test(gateway): retain idle suspension coverage for local claims
2026-09-26 03:46:53 -07:00
Peter Steinberger
cc75881752
perf(gateway): avoid chat stalls during WAL maintenance (#158570)
* perf(sqlite): move periodic WAL maintenance off the Gateway thread

* test(sqlite): verify WAL identity refusal and release test observers

* test(sqlite): await asynchronous periodic containment

* style(sqlite): make WAL failure types and cancellation returns explicit

* style(sqlite): align the maintenance cancellation return

* fix(sqlite): break WAL worker context import cycle

Share context capture behind explicit lifecycle admission so WAL registration does not import its owning cache. Preserve synchronous schema and maintenance authority capture.

Validation: import-cycle guard, targeted lint, 41 lifecycle and schema-policy tests, and independent Codex review passed. Initial test compilation overlapped SDK declaration generation; the sequential run passed after generation settled.

* fix(sqlite): satisfy worker context and fixture contracts

Distinguish admission-injected context helpers from the canonical cache-backed facade. Remove the MCP reconstruction fixture session-key mock so shared storage cleanup can consume the real routing exports.

Validation: full architecture checks and independent Codex review passed. Original Gateway shard reproduced all 11 MCP failures; the repaired focused suite passed all 11 in 18.39 seconds.

* fix(maintainer): include WAL context capture in wrapper

Keep the materialized native PR wrapper complete after extracting the shared-state worker context capture module. The missing import prevented provisioner private-store injection.

Validation: reproduced the missing-module error before the fix; provisioning, extracted dependency closure and wrapper lease bootstrap passed afterward (3 tests, 92.08s wall). Independent Codex review passed.

* test(sqlite): observe periodic reclamation in its worker

Move settlement-order observations from the parent connection SQL spy to real worker transaction and commit admission. Retain authorization, rejected reclamation, page budget, original owner and reclamation-worker shutdown assertions; require zero parent vacuum calls.

Validation: reproduced both old fixture failures; all 13 reclamation and agent WAL admission tests passed (137.90s wall), targeted lint and independent Codex review passed.

* test(sqlite): preserve real coordinator error exports

Remove redundant pure-helper mocks in device and lease fixtures so shared storage cleanup can use real coordinator errors. Preserve worker metadata in the broker cleanup fixture while continuing to forbid native worker and channel construction.

Validation: reproduced all missing-export failures, then 42 tests across five fixtures passed in 20.92 seconds; targeted lint, formatting and independent Codex review passed. No assertions or native-access fences were relaxed.

* test(sqlite): expect periodic vacuum in the worker

Keep the publication-order fixture aligned with periodic maintenance execution placement. Assert no parent vacuum after settlement while retaining real freelist reduction, page budget and committed-row proof.

Validation: both original failures reproduced; all 20 worker-store tests passed in 50.76 seconds. Formatting, diff checks and independent Codex review passed.

* fix(sqlite): preserve published-handle sidecar containment

Keep the original Linux sidecar tripwire at timer entry before physical identity admission can refuse worker dispatch. The existing synchronous scan preserves fatal no-cleanup ordering; checkpoint, vacuum and file-size work remain in workers.

Extend the existing process fixture through registered agent and shared-state owners with replaced main files and sidecars. Both cases fail on the original production path; all 83 Linux WAL/admission/coordinator tests pass after the fix with source hashes verified. Typecheck, lint and independent Codex review passed.

* test(sqlite): retain native metadata in worker mocks

Preserve real worker-thread and OS metadata while retaining the existing fake workers, forbidden constructors and two-worker pool limit. This keeps shared storage teardown from failing on incomplete built-in mocks.

Validation: all 41 existing tests across five affected fixtures passed in 17.89 seconds after reproducing the missing-export failures; lint, formatting and independent Codex review passed. No assertions or native-access fences were relaxed.

* test(sqlite): forward captured timer arguments safely

Use native reflective invocation for the unchanged callback and argument list, avoiding the Node timer generic tuple mismatch without casts or relaxed checks.

Validation: reproduced TS2345 in the production core graph, then the graph, targeted lint, formatting and independent Codex review passed.

* fix(sqlite): keep writer admission free of database startup

Place agent WAL registration with the database publisher instead of the lightweight writer queue. Preserve the registration body and shared queue owner while removing eager lifecycle and compiled-worker imports from queue-only callers.

The unchanged report-owner shard previously timed out during cold worker preparation. After the move, the focused child emits no worker-build output and all 83 tests pass under the same deadline. WAL publication/admission (26 tests), extracted wrapper closure, core types, lint, import-cycle checks and independent review passed.

* fix(state): preserve sealed private binding publication

* test(state): consume published identity in pending close fixture
2026-09-26 03:16:38 -07:00
Patrick Erichsen
7f41da0c7e
feat: curate plugin categories and add Computer use discovery (#158686)
* feat: prioritize plugin categories with ClawHub curation

* feat: prepare CUA for trusted ClawHub discovery

* docs: regenerate CUA plugin distribution inventory

* docs: refresh generated CUA install reference

* fix: keep CUA publication staged with bundled host

* test: give discovery page fixtures visible categories

* test: run chat retention proof on Node

* test: align plugin browser fixtures with curated shelves

* test: retain icon coverage in curated plugin shelves
2026-09-26 02:55:54 -07:00
Peter Steinberger
6209f31ce9
fix(update): name managed-service preflight refusals and stop trusting inherited service markers (#158314)
* fix(update): preserve refusal codes and verify service ancestry

* fix(update): preserve native service membership after reparenting

* test(update): provide native membership facts for rollback fixture

* fix(codex): use SDK error helpers for filesystem checks
2026-09-26 09:34:38 +00:00