* fix: preserve Windows credential reads with fs-safe 0.12.0 * test: preserve compiled fs-safe configuration checks on Windows * test: drain workspace page routes before closing fixtures * ci: move heavy main checks to 16-vCPU runners * perf(cli): avoid eager protocol schemas in cron registration * test: align prerelease workflow expectation with main CI * test: resume pending MCP Code Mode fixture calls * test(agents): cover cloned admitted normalizers Extend the canonical assembly-array fixture from #149662 with an admitted provider that returns cloned tools. Preserve its metadata, catalog, successful execution, abort-wrapper and post-disposal assertions. The production Array.from owner remains unchanged on main. * ci: spread Control UI checks across twelve shards * docs(ci): align runner guidance with current placement * ci: route trusted hybrid preflight to Blacksmith * test: align hybrid preflight runner table * ci: retain real-Gateway failure diagnostics Keep captured browser JSON and screenshots in an attempt-specific artifact when the real-Gateway CI job fails. Reuse the ordinary Control UI upload policy with seven-day retention and ignore absent captures, while preserving test commands and sanitized proof uploads. Extend the existing workflow guard and document that diagnostic artifacts are not sanitized public proof. The new guard fails before the fix; all 18 focused alias, workflow, and command cases pass afterward. Workflow lint, selected changed-file checks, and independent review pass. * fix(ui): preserve agent panel intent while route data loads A reused Agents page retained its initialized flag after its route data became pending. Roster initialization could then navigate through the default Overview panel, replacing an intended Files route. Require current route data before navigation and panel work, and clear initialization when the pending update applies. Keep explicit Settings selection revisions authoritative when the loader completes. Four focused regression cases fail before the repair with the reproduced Overview URL; 136 adjacent cases, targeted lint, formatting and independent review pass afterward. * ci: publish allowlisted UI failure summaries Keep raw browser reports and screenshots out of automatic CI artifacts. Write an explicit public projection from the existing failure owner and select only its fixed filename in ordinary and real-Gateway jobs. Raw captures remain local, and fixed private filenames keep sensitive labels out of logged paths. Older frozen targets without the summary produce no matching artifact. Preserve original failures and manual sanitized proof capture. Sensitive-sentinel regressions cover nested state, route parameters, labels, errors, models and content, including evaluation, screenshot and storage failures. All 10 helper cases, six workflow/command cases, workflow validation, plain Node import and selected changed-file checks pass; independent review found no actionable issues. * fix: align FileTransfer with fs-safe 0.12.0 Upgrade the FileTransfer dependency introduced by #148881 to the same exact version used by core, OpenShell and 1Password. Regenerate the importer with pnpm 12.3.4 and retain all other lock entries. Strengthen the existing orphan-WAL collision regression with equal-length, different-content bytes so recovery exercises the shared hash path and preserves the existing quarantine. Frozen installation, the 16-case sidecar suite, 18 tool-policy cases and 23 UI/diagnostic cases pass on the integrated source; independent review found no actionable issues. * test(ui): retain safe Canvas failure diagnostics * test(gateway): model live child execution in stop proof * test(ui): inspect HTML sandbox after render readiness * test(cron): cover event schedules after API state updates * ci: count hosted rows after hybrid preflight routing
8.5 KiB
| summary | title | read_when | ||||
|---|---|---|---|---|---|---|
| CI job graph, scope gates, release umbrellas, and local command equivalents | CI pipeline |
|
This page is an index. CI is documented on nine pages, one per reader job. Open the page that matches your task.
For the published-upgrade regression gate, see selection and routing, runner budgets, and Package Acceptance baselines. Weekly validation is listed under Update Migration.
Docs-only main pushes skip CI. Docker seed and QA Smoke use the same owner-path selection on pull requests and main; manual CI and Full Release Validation retain their coverage. Control UI performance uses its own UI/build/import scope. See scope selection for the coverage trade-off.
Android native resource preparation uses the Mermaid renderer's filtered dependency install, including optional build tooling. Pnpm retains root dependencies but omits unrelated plugin packages; Gradle still builds the assets and runs the selected native tests and lint. Historical targets keep their compatibility path.
Short hybrid jobs use a 40-row base threshold and 45-row hosted admission limit, with unchanged coverage and Blacksmith fallback when optional work does not fit.
Real-Gateway browser checks use job budgets matched to their selected runner.
| Page | Read it when |
|---|---|
| CI pipeline jobs | The job table, the fail-fast order, and the Control UI size budgets. |
| Watch a CI run | Wait on one pull request head, recover a stuck run, and pass the evidence gate. |
| CI checkout ownership | Shared checkout anchors, fetch retry budgets, and trusted action policy. |
| CI scope and routing | Why a job did or did not run: changed-scope detection and manual dispatch. |
| CI runner classes | Trust-based runner routing, preflight queue recovery, Blacksmith classes, and runner backend modes. |
| CI capacity and shard weights | The runner registration budget and the measured timings behind shard packing. |
| Release validation workflows | Full Release Validation, live and E2E shards, Package Acceptance, install smoke, Docker E2E, and Plugin Prerelease. |
| Scheduled and maintenance workflows | OpenClaw Performance, QA Lab, CodeQL, the maintenance jobs, and ClawSweeper activity forwarding. |
| Local checks and Testbox | Reproduce a lane locally, keep the shrink-only ratchets, and run Crabbox or Testbox proof. |
Where each section moved
Every section heading from the previous single-page version keeps its anchor here, so an existing link such as /ci#pipeline-overview still resolves. Each entry points at the page that now holds the content.
- Pipeline overview
- Fail-fast order
- Control UI size budgets
- Watching pull request CI
- Recover an existing PR run first
- PR context and evidence
- Checkout ownership
- Scope and routing
- Measured shard weights
- ClawSweeper activity forwarding
- Manual dispatches
- Windows Testbox Probe
- Runners
- Blacksmith runner capacity
- Runner backend modes
- Runner registration budget
- Surface ratchets
- Local equivalents
- OpenClaw Performance
- Vitest paired benchmark
- Full Release Validation
- Live and E2E shards
- Package Acceptance
- Jobs
- Candidate sources
- Suite profiles
- Legacy compatibility windows
- Examples
- Install smoke
- Local Docker E2E
- Tunables
- Reusable live/E2E workflow
- Release-path chunks
- Plugin Prerelease
- QA Lab
- CodeQL
- Security categories
- Platform-specific security shards
- Critical Quality categories
- Maintenance workflows
- Dependency Audit
- Docs Agent
- Duplicate PRs After Merge
- Local check gates and changed routing
- Config baseline count ratchet
- Testbox validation