mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 01:29:56 +00:00
## What Problem This Solves
Telegram Test Server proof could not deterministically reject one final Bot API request, and starting a prebuilt QA provider through the source launcher could rebuild during the credential lease and miss readiness.
## User Impact
No production behavior or configuration changes. Maintainers can exercise final-send and deletion failures against a real Telegram Test Server user without changing the application under test or introducing a second lease.
## Why This Change Was Made
The existing local proxy gains one method/occurrence/body-filtered, pre-upstream Bot API rejection. The QA runner keeps the development launcher for `--source-gateway` and uses the exact built entry for its prebuilt provider, explicitly enabling the private source-only QA command. The same runner still owns the credential, Test Server proxy, Gateway, user recorder, and cleanup.
## Evidence
- 36 focused Node tests pass. The exact-head ClawSweeper review identified a file-download failure when no rejection was armed; the proxy now requires an armed fault before comparing methods. The HTTP-boundary regression proves `/file/bot…` downloads are forwarded before, during, and after a one-shot rejection, with the rejected request never forwarded. Focused command: `node --test .agents/skills/telegram-e2e-userbot/scripts/telegram-test-api-proxy.test.mjs .agents/skills/telegram-e2e-userbot/scripts/scenario.test.mjs .agents/skills/telegram-e2e-userbot/scripts/run-mock-sut-user-e2e.test.mjs`; 36 passed, 0 failed, runner duration 2.66 seconds, wrapper wall 3.36 seconds.
- A loopback private QA provider started from each independently built baseline/candidate entry in under four seconds and served `/debug/requests`.
- Telegram Test Server: an independently recorded 20-second tool turn and one injected final-send rejection produced a visible baseline failure and a candidate terminal status without rerunning the tool. The comparison uses one frozen harness revision for both builds.
- One timed-out username discovery and a separate failed provider setup are retained as setup failures, not product verdicts; the bounded native chat preparation for the final runs remained outside this PR.
- After integrating `main`, the 17 focused wrapper-import/source-closure regressions passed, including the SQLite reader modules required by current main. Exact-head hosted CI's `openclaw/ci-gate` job passed; the security review status is awaiting its automatic reevaluation.
The production repair and its real-flow evidence are in #155906.
Merged current `main` (`
|
||
|---|---|---|
| .. | ||
| skills | ||
| resume | ||
| setup | ||