mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 17:53:39 +00:00
* feat(telegram): add isolated Test Server proof workflow Add maintainer-only exact-head admission, durable at-most-once QA lease consumption, isolated candidate execution, and normalized trusted Telegram Test Server observations. Co-authored-by: brokemac79 <255583030+brokemac79@users.noreply.github.com> * feat(proof): bind named Web UI and canonical Telegram QA evidence Reuse the existing formatting QA recipe, preserve isolated exact-candidate execution and produce the consumer request-bound receipt. Keep named smoke scenarios distinct and protect stationary harness ancestry. Co-authored-by: brokemac79 <255583030+brokemac79@users.noreply.github.com> * fix(proof): complete isolated QA execution and bounded failure capture Reuse canonical ephemeral device pairing and QA RPC scopes, preserve strict startup probes and recorder locks, and retain bounded wrong-text attempts without Telegram delivery. Co-authored-by: brokemac79 <255583030+brokemac79@users.noreply.github.com> * fix(mantis): revoke proof forwarding and enforce lease roles * fix(mantis): close proof producer CI gates * test(mantis): consolidate related proof suites within CI budget * test(mantis): preserve fast QA ownership when grouping integration cases * fix(mantis): accept exact branch-qualified workflow paths * fix(mantis): align live admission workflow path checks * feat(mantis): collect selected proof inside the originating review * fix(mantis): bound proof storage and preserve failure evidence Reuse verified storage across request-bound candidates, reserve backing capacity, retain sanitized rejection evidence, and repair cleanup and observation finalization. Scoped checks and dirty review pass; full Gateway and sandboxed browser runtime proof remain required before publication. * fix(mantis): retain bridge identity before startup * fix(mantis): keep candidate config readable under private umask * fix(qa): use verified rootless networking and join candidate shutdown * fix(qa): repair proof tooling checks and deterministic recorder fixture --------- Co-authored-by: brokemac79 <255583030+brokemac79@users.noreply.github.com>
39 lines
1.2 KiB
JavaScript
39 lines
1.2 KiB
JavaScript
// Runs only in the trusted bridge container on the candidate-only internal network.
|
|
import http from "node:http";
|
|
const socketPath = process.argv[2];
|
|
if (socketPath !== "/bridge.sock") {
|
|
throw new Error("Expected the controller-owned socket mount");
|
|
}
|
|
const server = http.createServer((incoming, outgoing) => {
|
|
const request = http.request(
|
|
{
|
|
socketPath,
|
|
path: incoming.url,
|
|
method: incoming.method,
|
|
headers: {
|
|
"content-type": incoming.headers["content-type"] ?? "application/json",
|
|
...(incoming.headers.authorization
|
|
? { authorization: incoming.headers.authorization }
|
|
: {}),
|
|
},
|
|
},
|
|
(response) => {
|
|
outgoing.writeHead(response.statusCode ?? 502, {
|
|
"content-type": response.headers["content-type"] ?? "application/json",
|
|
});
|
|
response.pipe(outgoing);
|
|
},
|
|
);
|
|
request.on("error", () => {
|
|
if (!outgoing.headersSent) {
|
|
outgoing.writeHead(502);
|
|
}
|
|
outgoing.end();
|
|
});
|
|
incoming.on("aborted", () => request.destroy());
|
|
outgoing.on("close", () => request.destroy());
|
|
incoming.pipe(request);
|
|
});
|
|
server.requestTimeout = 45_000;
|
|
server.headersTimeout = 10_000;
|
|
server.listen(8080, "0.0.0.0");
|