mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
* test(release): guard parallel validation dispatch * feat(release): seal independent child workload evidence Record immutable, attempt-aware child receipts independently of parent completion. Keep receipt collection advisory and preserve publisher-only retry evidence. Partial child-reuse discovery and consumption remain a follow-up. * feat(release): reuse sealed child evidence independently * fix(ci): plan frozen release shards with trusted tooling * ci(release): generate hosted shard timing budgets * fix(release): make non-proof validation lanes advisory * feat(release): seal resolved publication inputs * fix(release): accept candidate tags at the frozen target * docs(release): record pending first-hop parallel lanes Item 8: remote maind51f3607b9does not containbf7848ef23. The feat/first-hop-compat-parallel-lanes branch still owns that implementation. Verified remote refs read-only and inspected the main scenario source; do not duplicate it here. No source changes; prior item gates remain valid. * ci(plugins): run release plugin coverage on relevant pull requests * ci(release): support reserved validation runner groups * docs(release): reconcile fast-path validation guidance * test(release): reconcile final guards and record validation * fix(release): retry transient GitHub API failures during evidence verification * test(release): reconcile advisory Linux CI lane cases with the fast-path policy * test(release): copy the sealed-evidence tooling closure into the frozen fixtures * fix(release): keep package integrity blocking and require live operator authority for sealed SDK and soak inputs * chore(release): record the landing follow-ups in the PR body * test(ci): expect the four-hour Testbox lease default from #156614 * test(release): reconcile untouched release suites with the advisory policy and reserved runner groups * fix(release): reconcile advisory-by-default with full coverage and strict stable defaults Keep RomneyDa's coverage (nine cross-OS Gateway pairs, Linux Gateway lanes as required proof, Windows/macOS recorded as advisory) and his strict stable publication gates (stable-profile, soak, blocking performance) as the default, while retaining Peter's operator fast path: stable_soak_waiver / lane_waiver are the only way to publish a stable without soak/performance evidence or with failed non-proof lanes, must name the target version, apply only while the repository variable still holds them, and are recorded end to end. The stable closeout accepts the same waivers so the 2026.9.6 closeout replay can proceed. Adopt main's affected-consumer planner (#156729) with item 4's hosted-row split re-applied. * fix(release): revalidate sealed soak waivers at the plugin npm publish boundary The stable bootstrap approval records whether its soak waiver was explicit or sealed; the plugin npm child rereads the repository variable before its token-backed publish and rejects a sealed waiver the variable no longer holds. Read-only preflight reports sealed waivers with the same rule. Docs state the nine-pair all-group cross-OS rule and the strict performance gate; the tracked planner backup is removed and the fast-core worker keeps its runner-group routing. * fix(release): recheck sealed waivers before npm I/O and repair CI-surfaced drift Assert a still-held sealed soak waiver immediately before the plugin token-backed npm publish, carry the live variable into preflight's gate evaluation, and state the strict performance gate in the fast-path guide. Fold main-side drift the merge surfaced: the seal job waits for the new baseline-ratchets worker, the wrapper closure lists the CLI root options chain, the maturity publisher's runner-group route is evaluated rather than compared literally, and two main-authored session test-support suppressions join the allowlist. * fix(release): fetch waiver authority live before the plugin npm publish Read OPENCLAW_RELEASE_STABLE_SOAK_WAIVER from the repository immediately before the token-backed npm publish (404 means revoked, other read errors refuse to publish), keep a waiver-less recorded closeout manifest byte-identical on replay, and describe release_profile=stable as the stable default with the beta profile plus stable_soak_waiver as the explicit operator fast path. * test(release): anchor the publish-boundary recheck to the npm publish command * fix(release): fall back to the job-start waiver when the token cannot read Variables Keep the live read before npm publish (404 means revoked) but warn and use the job-start snapshot instead of refusing every bootstrap publish when the job token lacks Variables access. * fix(release): refuse the plugin npm publish when waiver authority cannot be read Revoked (404) and unreadable variable states both stop the token-backed publish; a job token without Variables read access fails loudly instead of publishing on a job-start snapshot.
2 lines
169 B
TypeScript
2 lines
169 B
TypeScript
export function releaseChildReuseSha256(selection: unknown): string;
|
|
export function releaseChildDispatchInputs(source: string, args: string[]): Record<string, string>;
|