openclaw/extensions/code-mode-quickjs/openclaw.plugin.json
Peter Steinberger 33e92d9ec9
fix(release): repair 2026.9.6 validation failures (#155818)
## Problem

Full Release Validation run 35742760135 for the 2026.9.6 candidate failed on deterministic checks that reproduce on any release branch cut from current main:

- `CI / checks-node-core-tooling-15`: `test/scripts/tsgo-core-test-shards.test.ts` reported `gateway-server: 701 test roots exceeds the 700 limit` (the candidate was cut before the rebalance in #155734).
- `Plugin Prerelease / checks-node-extensions-shard-*`: `extensions/facetime/tests/package-manifest.test.ts:86` hardcodes the `>=2026.9.4` host contract, so the release-prep version bump to `2026.9.6` fails the test on every release branch.
- `Plugin Prerelease / checks-node-agentic-plugins`: `src/plugins/bundled-plugin-icons.test.ts` ENOENT on `extensions/code-mode-quickjs/assets/icon.png`, and `src/plugins/bundled-plugin-metadata.test.ts:545` found no `activation.onStartup` on the new QuickJS Code Mode manifest (#154522).
- `Plugin Prerelease / plugin-npm-security-scan`: five unreviewed `dangerous-exec` findings (`@openclaw/acpx test/codex-app-server.test.ts:15`, `@openclaw/codex src/app-server/managed-launcher-failure.ts:28`, `@openclaw/codex src/node-exec-server.test.ts:664`, `@openclaw/facetime src/audio-pump.ts:216`, `@openclaw/onnx src/worker-client.ts:162`) plus an `@openclaw/codex` reviewed inventory mismatch after #155612 removed two bounded child launches from `attempt-startup-retry.test.ts`.

## Solution

One commit per fix, no new configuration:

1. Shard cap: already fixed on main by #155734 (worker-environments roots moved to `gateway-other`; gateway-server now holds 481 roots). Verified here, no further change.
2. FaceTime manifest test derives the host contract (`peerDependencies`, `install.minHostVersion`, `compat.pluginApi`, `build.openclawVersion`) from the package version that release preparation bumps in lockstep.
3. QuickJS Code Mode ships the OpenClaw fallback identity tile and the sandbox activity glyph (both byte-for-byte reuse, recorded in `ICON_SOURCES.md` / `ACTIVITY_ICON_SOURCES.md`) and declares `activation.onStartup: false`; the executor is resolved lazily through its `codeModeExecutors` contract.
4. Plugin npm security scan inventory: each new site was read and is a fixed trusted launch with no untrusted interpolation.
   - `@openclaw/facetime src/audio-pump.ts:216`: `spawn(captureBinary, [], { env: sanitized })` where `captureBinary` comes from the plugin's own staged native install (`ensureCaptureBinary`). Required runtime entry.
   - `@openclaw/onnx src/worker-client.ts:162`: `spawn(process.execPath, resolveRuntimeWorkerArgv(workerUrl), { shell: false })` forking the plugin's bundled worker entry. Required runtime entry.
   - `@openclaw/codex src/app-server/managed-launcher-failure.ts:28`: no process launch; the `spawn(` match is inside a regex literal that classifies stderr. Reviewed as a current-only packed entry.
   - `@openclaw/acpx test/codex-app-server.test.ts:15`: `execFileSync(process.execPath, [checked-in fixture], { env: {}, timeout })`. Test-only packed entry.
   - `@openclaw/codex src/node-exec-server.test.ts:664`: inline `-e` script for `process.execPath` inside the exec server's owned workspace fixture. Test-only packed entry.
   - `@openclaw/codex src/app-server/attempt-startup-retry.test.ts`: reviewed count 6 -> 4 for the current inventory only.
   The pre-9.6 required-source inventory is frozen as `RELEASE_2026_9_5_REQUIRED_REVIEWED_SOURCE_FINDING_COUNTS` and pinned to the 9.3/9.4/9.5 contexts, so shipped release rescans do not start requiring files they never had.

## Impact

Unblocks 2026.9.6 validation on the next candidate cut. No runtime behaviour change except the QuickJS plugin now declaring lazy activation, which matches how the executor was already loaded.

## Evidence

- `test/scripts/tsgo-core-test-shards.test.ts`, `extensions/facetime/tests/package-manifest.test.ts`, `src/plugins/bundled-plugin-icons.test.ts`, `src/plugins/bundled-plugin-metadata.test.ts`: pass locally.
- `test/scripts/plugin-npm-security-scan.test.ts`: 44/44 pass.
- Local end-to-end scan (`plugin-npm-security-prepare.mts plan/prepare` + `plugin-npm-security-scan-runner.mjs`) for both the `""` and `release/2026.9.6` contexts: `unexpectedCriticalFindingCount: 0`, no inventory mismatch, layout `current`. The only remaining local errors are the gitignored `extensions/diffs/assets/viewer-runtime.js` build output exceeding the per-file byte limit, which is absent from the unbuilt CI candidate.
- `src/plugins/bundled-plugin-metadata.public-surfaces.test.ts` and `src/plugins/manifest-registry.test.ts` have three pre-existing host-only failures here (synthetic temp-root public-surface loading) unrelated to this change; CI is authoritative.
- FRV run: https://github.com/openclaw/openclaw/actions/runs/35742760135

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-22 10:00:48 -07:00

17 lines
401 B
JSON

{
"id": "code-mode-quickjs",
"name": "QuickJS Code Mode",
"description": "Hardened JavaScript execution for Code Mode using QuickJS in WebAssembly.",
"categories": ["infrastructure"],
"activation": {
"onStartup": false
},
"contracts": {
"codeModeExecutors": ["quickjs"]
},
"configSchema": {
"type": "object",
"additionalProperties": false,
"properties": {}
}
}