openclaw/qa
Teddy Tennant 996c928205
fix(auto-reply): show usage for invalid approval decisions (#137877)
## What Problem This Solves

`/approve abc constructor` and `/approve abc __proto__` returned a failed-submission error instead of usage. The parser read inherited object properties as decisions. It also misread `constructor` when used as an approval ID before a valid decision.

## Why This Change Was Made

Both supported argument layouts now check that a decision is a declared alias before reading its value. The ten aliases and downstream authorization and resolver behavior remain unchanged.

Downstream validation already rejected these values before making a Gateway request. This change gives the caller the normal usage reply at parsing.

## User Impact

Unknown decisions return the usage reply. Valid decisions still resolve pending exec and plugin approvals. An approval ID such as `constructor` also works when followed by a declared decision.

## Evidence

Verified candidate `b03792933d42978e969d9da25748f15fa0f79326` against pinned main `d3a2fb0296`, using separate installs and state on one isolated Linux Testbox.

- Real source Gateway and QA channel: baseline returns the invalid-decision submission error; candidate returns usage. The expanded matrix records 54 cases per pin, including every alias in both layouts, real pending exec/plugin records, duplicates, conflicts, unknown and expired IDs, whitespace, and prototype-like IDs.
- Real Telegram Test Server user and bot: the same before/after behavior, with one lease shared by both pins within each pair. Fast approval commands make zero provider requests. Owner records and resolution events confirm valid decisions take effect once and invalid inputs leave pending approvals unchanged.
- Separate controls cover the named account, unauthorized sender, disabled approval capability, disabled text/native commands, foreign-bot commands, and a real Gateway client missing approval scope. Disabled text handling follows normal deterministic model dispatch without resolving the pending approval.
- Fresh-pending syntax controls preserve whitespace and extra-token behavior. The earlier timed duplicate probe is retained separately because it crossed the existing resolved-entry grace window.
- All 71 focused approval/parser tests and 134 QA catalog tests passed. Changed-file formatting and lint passed. [Exact-head CI](https://github.com/openclaw/openclaw/actions/runs/33940306696) is green.

`toString` and `valueOf` were already rejected after lowercasing; they are preservation controls. Normal channel delivery may update message state. The approval invariant concerns decision and grant effects; audit-row absence is not treated as proof of absence. No execution-identity diagnostics or production approvals were enabled for this proof.

AI-assisted.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-09 00:49:19 +05:30
..
convex-credential-broker chore(deps): refresh four seven-day-cooled packages (#140732) 2026-09-06 21:45:52 -07:00
scenarios fix(auto-reply): show usage for invalid approval decisions (#137877) 2026-09-09 00:49:19 +05:30
frontier-harness-plan.md chore: migrate active GPT-5.5 references to GPT-5.6 (#104452) 2026-07-11 06:30:57 -07:00
maturity-scores.yaml docs: update maturity scorecard (#142114) 2026-09-08 11:06:56 -07:00
README.md Convert QA scenarios to YAML files (#92915) 2026-06-14 17:31:18 -07:00
scenarios.md Convert QA scenarios to YAML files (#92915) 2026-06-14 17:31:18 -07:00

QA Scenarios

Seed QA assets for the private qa-lab extension.

Files:

  • scenarios/index.yaml - canonical QA scenario pack, kickoff mission, and operator identity.
  • scenarios/<theme>/*.yaml - one runnable scenario per YAML file.
  • frontier-harness-plan.md - big-model bakeoff and tuning loop for harness work.
  • convex-credential-broker/ - standalone Convex v1 lease broker for pooled live credentials.

Key workflow:

  • qa suite is the executable frontier subset / regression loop.
  • qa manual is the scoped personality and style probe after the executable subset is green.
  • qa coverage prints the scenario coverage inventory from scenario YAML.

Operator workflows:

  • Use the openclaw-qa-testing skill for QA Lab live lanes, Convex credential pool operations, and WhatsApp live credential setup/replacement.

Keep this folder in git. Add new scenarios here before wiring them into automation.