openclaw/.agents
Ayaan Zaidi 824b12c7de
fix(qa): make Telegram delivery-failure proof deterministic (#155899)
## What Problem This Solves

Telegram Test Server proof could not deterministically reject one final Bot API request, and starting a prebuilt QA provider through the source launcher could rebuild during the credential lease and miss readiness.

## User Impact

No production behavior or configuration changes. Maintainers can exercise final-send and deletion failures against a real Telegram Test Server user without changing the application under test or introducing a second lease.

## Why This Change Was Made

The existing local proxy gains one method/occurrence/body-filtered, pre-upstream Bot API rejection. The QA runner keeps the development launcher for `--source-gateway` and uses the exact built entry for its prebuilt provider, explicitly enabling the private source-only QA command. The same runner still owns the credential, Test Server proxy, Gateway, user recorder, and cleanup.

## Evidence

- 36 focused Node tests pass. The exact-head ClawSweeper review identified a file-download failure when no rejection was armed; the proxy now requires an armed fault before comparing methods. The HTTP-boundary regression proves `/file/bot…` downloads are forwarded before, during, and after a one-shot rejection, with the rejected request never forwarded. Focused command: `node --test .agents/skills/telegram-e2e-userbot/scripts/telegram-test-api-proxy.test.mjs .agents/skills/telegram-e2e-userbot/scripts/scenario.test.mjs .agents/skills/telegram-e2e-userbot/scripts/run-mock-sut-user-e2e.test.mjs`; 36 passed, 0 failed, runner duration 2.66 seconds, wrapper wall 3.36 seconds.
- A loopback private QA provider started from each independently built baseline/candidate entry in under four seconds and served `/debug/requests`.
- Telegram Test Server: an independently recorded 20-second tool turn and one injected final-send rejection produced a visible baseline failure and a candidate terminal status without rerunning the tool. The comparison uses one frozen harness revision for both builds.
- One timed-out username discovery and a separate failed provider setup are retained as setup failures, not product verdicts; the bounded native chat preparation for the final runs remained outside this PR.
- After integrating `main`, the 17 focused wrapper-import/source-closure regressions passed, including the SQLite reader modules required by current main. Exact-head hosted CI's `openclaw/ci-gate` job passed; the security review status is awaiting its automatic reevaluation.

The production repair and its real-flow evidence are in #155906.

Merged current `main` (`86d353b748`) to align the older branch with its SQLite reader and PR wrapper inventory. The two earlier cherry-picked upstream CI fixes retain Peter Steinberger's commit authorship; they are already on `main` and disappear from the PR diff. The QA change remains six files, with no production behavior added.
2026-09-23 09:12:32 +05:30
..
skills fix(qa): make Telegram delivery-failure proof deterministic (#155899) 2026-09-23 09:12:32 +05:30
resume chore: prepare fresh Amp orb lifecycle (#126933) 2026-08-20 19:03:46 -07:00
setup chore: prepare fresh Amp orb lifecycle (#126933) 2026-08-20 19:03:46 -07:00