openclaw/.github/codeql
Peter Steinberger 6e6a0e59fd
fix(qa): keep leases when Gateway startup teardown fails (#131740)
* fix(qa): keep leases when Gateway startup teardown fails

Retain a synchronous QA child owner through startup, replacement, and explicit finalization. Release Gateway-backed transport leases only after authoritative process settlement, independently of cleanup diagnostics. Preserve failure artifacts and primary fixture errors.

Fixes #131643

* test(qa): keep fixture cleanup inside plugin boundaries

* test(qa): retain integrated fixture owners and stop observations

* ci: follow renamed local JSONL socket owner in CodeQL

* test(qa): record reviewed cleanup error suppressions

* test(ci): exercise PR-native network semantic review

Route sensitive changes into the existing semantic gate and restore configured net-policy coverage. Add actual query fixtures, including an intentional red checkpoint for JavaScript-family raw clients before the follow-up predicate repair. PR remains draft until semantic proof and final CI pass.

* fix(ci): classify supported JavaScript network sources

Preserve the existing directory and owner boundaries across TS, MTS, JS, and MJS. Hosted semantic regression 33190472078 failed on exactly the three missing executable rows; expected findings and test exclusions remain unchanged.

* test(ci): isolate network fixtures and retain guard coverage

Use independent fixture stems and explicit MTS extractor inputs while preserving every expected finding. Scan the semantic fixture root for duplicates and keep the exact socket-owner assertion insensitive to formatting.

* test(qa): return confirmed stop in WhatsApp cleanup fixture

* test(qa): own Discord attachment gateway before startup

* ci: fail closed on unavailable CodeQL diff metadata

* test(oc-path): measure synchronous worker CPU budgets
2026-08-28 14:31:29 -07:00
..
openclaw-boundary fix(qa): keep leases when Gateway startup teardown fails (#131740) 2026-08-28 14:31:29 -07:00
codeql-actions-critical-security.yml
codeql-agent-runtime-boundary-critical-quality.yml
codeql-android-critical-security.yml
codeql-channel-runtime-boundary-critical-quality.yml refactor(qqbot): install plugin from Tencent package (#107295) 2026-08-11 15:10:27 -07:00
codeql-channel-runtime-boundary-critical-security.yml refactor: extract gateway client package (#87797) 2026-05-29 02:23:42 +01:00
codeql-config-boundary-critical-quality.yml
codeql-core-auth-secrets-critical-quality.yml refactor: extract gateway client package (#87797) 2026-05-29 02:23:42 +01:00
codeql-core-auth-secrets-critical-security.yml refactor: extract gateway client package (#87797) 2026-05-29 02:23:42 +01:00
codeql-gateway-runtime-boundary-critical-quality.yml refactor: extract gateway client package (#87797) 2026-05-29 02:23:42 +01:00
codeql-macos-critical-security.yml
codeql-mcp-process-runtime-boundary-critical-quality.yml
codeql-mcp-process-tool-boundary-critical-security.yml refactor(agents): split message-tool into concept modules (#121901) 2026-08-11 00:31:14 -07:00
codeql-memory-runtime-boundary-critical-quality.yml refactor(memory)!: remove the QMD backend; builtin is the only memory engine (#120936) 2026-08-09 03:05:47 -07:00
codeql-network-runtime-boundary-critical-quality.yml feat(secrets): authenticated egress substitution proxy with destination binding (#123216) 2026-08-13 20:49:31 -07:00
codeql-network-ssrf-boundary-critical-security.yml fix(security): unify secret-redaction and SSRF policy ownership (#121335) 2026-08-09 22:40:58 -07:00
codeql-plugin-boundary-critical-quality.yml chore(deadcode): prune stale codeql paths 2026-06-22 08:33:19 +08:00
codeql-plugin-sdk-package-contract-critical-quality.yml
codeql-plugin-sdk-reply-runtime-critical-quality.yml
codeql-plugin-trust-boundary-critical-security.yml chore(deadcode): prune stale codeql paths 2026-06-22 08:33:19 +08:00
codeql-process-exec-boundary-critical-security.yml refactor(memory)!: remove the QMD backend; builtin is the only memory engine (#120936) 2026-08-09 03:05:47 -07:00
codeql-provider-runtime-boundary-critical-quality.yml
codeql-session-diagnostics-boundary-critical-quality.yml
codeql-ui-control-plane-critical-quality.yml
codeql-web-media-runtime-boundary-critical-quality.yml refactor(packages): DM-policy contract suite, dead routes, package folds (#114776) 2026-07-27 20:20:13 -04:00