mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-12 21:53:00 -06:00
fix(release): bound validation retries and soak
This commit is contained in:
+13
-10
@@ -86,6 +86,7 @@ gh workflow run openclaw-npm-release.yml \
|
||||
gh workflow run full-release-validation.yml \
|
||||
--ref extended-stable/YYYY.M.33 \
|
||||
-f ref=extended-stable/YYYY.M.33 \
|
||||
-f expected_sha="$RELEASE_SHA" \
|
||||
-f release_profile=stable
|
||||
```
|
||||
|
||||
@@ -229,8 +230,8 @@ This checklist is the public shape of the release flow. Private credentials, sig
|
||||
|
||||
1. Start from current `main`: pull latest, confirm the target commit is pushed, and confirm `main` CI is green enough to branch from.
|
||||
2. Create `release/YYYY.M.PATCH` from that commit. Backports are optional; apply only the operator-selected set. Bump every required version location, run `pnpm release:prep`, finish release fixes and required forward-ports, and review `src/plugins/compat/registry.ts` plus `src/commands/doctor/shared/deprecation-compat.ts`.
|
||||
3. Freeze the product-complete pre-changelog commit as the **Code SHA**. Run the deterministic source preflight, then use `node scripts/full-release-validation-at-sha.mjs --sha <code-sha> --target-ref release/YYYY.M.PATCH`. This pins trusted workflow tooling while the full Vitest, Docker, QA, package, and performance matrix targets the exact Code SHA.
|
||||
4. Classify failures before editing. A product/code failure creates a new Code SHA and requires green full validation for that SHA. A workflow, harness, credential, approval, or infrastructure failure is repaired in its owning surface and rerun against the same Code SHA.
|
||||
3. Freeze the product-complete pre-changelog commit as the **Code SHA** and record the trusted **Tooling SHA**. Run the deterministic source preflight, then use `node scripts/full-release-validation-at-sha.mjs --sha <code-sha> --target-ref release/YYYY.M.PATCH`. Beta-publish uses `release_profile=beta` without soak; postpublish-confidence owns broad live, QA-live, mobile, and Parallels work.
|
||||
4. Classify failures before editing as product, harness/tooling/provenance, infrastructure/credential, or wrapper. Only confirmed product failure creates a new Code SHA. Use one diagnosis, one fix when needed, and one narrow retry, then reassess.
|
||||
5. Only after the Code SHA is green, generate the top `CHANGELOG.md` section from merged PRs and direct commits since the last reachable shipped tag. Keep entries user-facing and deduplicated. When a divergent shipped tag or later forward-port re-associates already-released PRs, pass it explicitly as `--shipped-ref`.
|
||||
6. Commit only `CHANGELOG.md`. This commit is the **Release SHA**. The complete diff from Code SHA to Release SHA must be exactly `CHANGELOG.md`; any other changed path returns the release to step 2.
|
||||
7. Run SHA-pinned Full Release Validation for the Release SHA with evidence reuse enabled. The lightweight parent must record `changelog-only-release-v1`, point at the green Code SHA, and dispatch no product child lanes. This reuses product evidence; it does not reuse package bytes.
|
||||
@@ -246,7 +247,7 @@ This checklist is the public shape of the release flow. Private credentials, sig
|
||||
--skip-dispatch
|
||||
```
|
||||
|
||||
For stable, also pass `--windows-node-tag vX.Y.Z`. The helper verifies release-note provenance, npm preflight bytes, Parallels install/update proof, Telegram package proof, and plugin publish plans, then prints the publish command. After it completes green, create and push the final signed tag at that same Release SHA, then run the printed publish command.
|
||||
For stable, also pass `--windows-node-tag vX.Y.Z`. Beta and alpha candidates defer Parallels install/update proof to the postpublish `pnpm release:beta-smoke` roster by default; pass `--run-parallels` only when the operator explicitly wants that proof before publish. Stable and full candidates run Parallels by default. The helper still verifies release-note provenance, npm preflight bytes, Telegram package proof, and plugin publish plans, then prints the publish command. After it completes green, create and push the final signed tag at that same Release SHA, then run the printed publish command.
|
||||
|
||||
`pnpm release:candidate` validates the current frozen branch tip by default (or the explicit `--target-sha`), and rejects a tag that already exists. It records evidence before the final signed tag is pushed.
|
||||
|
||||
@@ -328,7 +329,7 @@ A legacy fallback correction tag may reuse base-package evidence only when the c
|
||||
|
||||
Manually dispatch `Windows Node Release` only for recovery, and always pass an exact tag, never `latest`, plus the explicit `expected_installer_digests` JSON map from the approved source release. Website download links should target exact OpenClaw release asset URLs for the current stable release, or `releases/latest/download/...` only after verifying GitHub's latest redirect points at that same release; do not link only to the companion repo release page.
|
||||
|
||||
- Release checks now run in a separate manual workflow: `OpenClaw Release Checks`. It also runs the QA Lab mock parity lane plus the Matrix catalog and Telegram QA lane before release approval. The live lanes use the `qa-live-shared` environment; Telegram also uses Convex CI credential leases.
|
||||
- Release checks now run in a separate manual workflow: `OpenClaw Release Checks`. It always runs the QA Lab mock parity lane. The Matrix catalog and Telegram QA-live lanes run for stable/full validation, soak-enabled validation, or an explicit `qa`/`qa-live` rerun group. Bounded beta-publish `all` without soak defers those live lanes to postpublish-confidence. The live lanes use the `qa-live-shared` environment; Telegram also uses Convex CI credential leases.
|
||||
- Cross-OS install and upgrade runtime validation is part of public `OpenClaw Release Checks` and `Full Release Validation`, which call the reusable workflow `.github/workflows/openclaw-cross-os-release-checks-reusable.yml` directly. This split is intentional: keep the real npm release path short, deterministic, and artifact-focused, while slower live checks stay in their own lane so they do not stall or block publish.
|
||||
- Secret-bearing release checks should be dispatched through `Full Release Validation` or from the `main`/release workflow ref so workflow logic and secrets stay controlled.
|
||||
- `OpenClaw Release Checks` accepts a branch, tag, or full commit SHA as long as the resolved commit is reachable from an OpenClaw branch or release tag.
|
||||
@@ -367,7 +368,7 @@ pnpm ci:full-release \
|
||||
--target-ref release/YYYY.M.PATCH
|
||||
```
|
||||
|
||||
The helper fetches current `origin/main`, pushes `release-ci/<workflow-sha>-...` at that trusted workflow commit, infers `beta` from alpha/beta package versions and `stable` otherwise, dispatches `Full Release Validation` from the temporary branch with `ref=<target-sha>`, verifies every child workflow `headSha` matches the pinned parent workflow SHA, then deletes the temporary branch. Pass `-f reuse_evidence=false` to force a fresh run, `-f release_profile=full` for the broad advisory sweep, or `--workflow-sha <trusted-main-sha>` to pin an older commit that is still reachable from current `origin/main`. The workflow itself never writes repository refs. This keeps main-only release tooling available without adding tooling commits to the candidate and avoids proving a newer `main` child run by accident.
|
||||
The helper fetches current `origin/main`, pushes `release-ci/<workflow-sha>-...` at that trusted Tooling SHA, infers `beta` from alpha/beta package versions and `stable` otherwise, and dispatches `Full Release Validation` with the Validation SHA as `expected_sha`. Target resolution rejects a mismatch before child dispatch. Every child workflow `headSha` must match the Tooling SHA. Pass `-f reuse_evidence=false` to force a fresh run, `-f release_profile=full` for the broad advisory sweep, or `--workflow-sha <trusted-main-sha>` to pin a compatible older commit still reachable from current `origin/main`. The helper rejects pinned tooling that lacks the `expected_sha` dispatch input and never silently selects a newer Tooling SHA. The workflow itself never writes repository refs.
|
||||
|
||||
After the Code SHA is green, commit only `CHANGELOG.md` and run the same helper with the Release SHA:
|
||||
|
||||
@@ -379,7 +380,7 @@ pnpm ci:full-release \
|
||||
|
||||
The second parent reuses product evidence only when GitHub proves the Release SHA descends from the Code SHA and the complete changed path set is exactly `CHANGELOG.md`. It records `changelog-only-release-v1` and dispatches no product children. Npm preflight and package/install acceptance still run on the Release SHA because its tarball bytes changed.
|
||||
|
||||
For a fresh Code SHA, the workflow resolves the target, dispatches manual `CI`, then dispatches `OpenClaw Release Checks`. `OpenClaw Release Checks` fans out install smoke, cross-OS release checks, live/E2E Docker release-path coverage when soak is enabled, Package Acceptance with the canonical Telegram package E2E, QA Lab parity, live Matrix, and live Telegram. A full/all run is only acceptable when the `Full Release Validation` summary shows `normal_ci`, `plugin_prerelease`, and `release_checks` as successful, unless a focused rerun intentionally skipped the separate `Plugin Prerelease` child. Use the standalone `npm-telegram` child only for a focused published-package rerun with `release_package_spec` or `npm_telegram_package_spec`. The final verifier summary includes slowest-job tables for each child run, so the release manager can see the current critical path without downloading logs.
|
||||
For a fresh Code SHA, the workflow resolves the target, dispatches manual `CI`, then dispatches `OpenClaw Release Checks`. Beta-publish maps to `release_profile=beta` and `run_release_soak=false`; its `all` run excludes broad live/E2E and QA-live lanes. Postpublish-confidence uses the exact published package with soak or explicit focused groups. Stable-publish maps to `release_profile=stable`. The final verifier summary includes slowest-job tables for each child run.
|
||||
|
||||
The product-performance child is artifact-only in this release path. The
|
||||
umbrella dispatches it with `publish_reports=false`, and validation is rejected
|
||||
@@ -421,10 +422,11 @@ pnpm ci:full-release \
|
||||
--target-ref release/YYYY.M.PATCH \
|
||||
-f release_package_spec=openclaw@YYYY.M.PATCH-beta.N \
|
||||
-f evidence_package_spec=openclaw@YYYY.M.PATCH-beta.N \
|
||||
-f run_release_soak=true \
|
||||
-f npm_telegram_provider_mode=mock-openai
|
||||
```
|
||||
|
||||
Do not use the full umbrella as the first rerun after a focused fix. If one box fails, use the failed child workflow, job, Docker lane, package profile, model provider, or QA lane for the next proof. Run the full umbrella again only when the fix changed shared release orchestration or made earlier all-box evidence stale. The umbrella's final verifier re-checks the recorded child workflow run ids, so after a child workflow is rerun successfully, rerun only the failed `Verify full validation` parent job.
|
||||
Do not use the full umbrella as the first rerun after a focused fix. Classify the failure as product, harness/tooling/provenance, infrastructure/credential, or wrapper. Only confirmed product failure changes the Code SHA. Use one diagnosis, one fix when needed, and one narrow retry, then reassess. A narrow green run is evidence, not publish authorization by itself; there is no standalone parent finalizer.
|
||||
|
||||
`rerun_group=all` may reuse a prior green umbrella run when the release profile,
|
||||
effective soak setting, and validation inputs match and either the target SHA
|
||||
@@ -435,9 +437,10 @@ is exactly `CHANGELOG.md`. Exact-target reuse records
|
||||
preflight, package bytes, release-note provenance, and install/update acceptance
|
||||
must still run against the Release SHA. Any version, source, generated,
|
||||
dependency, package, or workflow-owned target change requires a new Code SHA
|
||||
and fresh full validation. Newer umbrella runs for the same `release/*` ref and
|
||||
rerun group supersede in-progress ones automatically. Pass
|
||||
`reuse_evidence=false` to force a fresh full run.
|
||||
and fresh full validation. Concurrency is keyed by Validation SHA, Tooling SHA,
|
||||
and rerun group and does not cancel prior runs. Parent cancellation leaves
|
||||
adopted children running until the operator cancels the exact child. Pass
|
||||
`reuse_evidence=false` only when a fresh full run is intentionally required.
|
||||
|
||||
For bounded recovery, pass `rerun_group` to the umbrella. `all` is the real release-candidate run, `ci` runs only the normal CI child, `plugin-prerelease` runs only the release-only plugin child, `release-checks` runs every release box, and the narrower release groups are `install-smoke`, `cross-os`, `live-e2e`, `package`, `qa`, `qa-parity`, `qa-live`, and `npm-telegram`. Focused `npm-telegram` reruns require `release_package_spec` or `npm_telegram_package_spec`; full/all runs use the canonical package Telegram E2E inside Package Acceptance. Focused cross-OS reruns can add `cross_os_suite_filter=windows/packaged-upgrade` or another OS/suite filter. QA release-check failures block normal release validation, including OpenClaw dynamic tool drift in the core runtime-pair lane. Tideclaw alpha runs may still treat non-package-safety release-check lanes as advisory. With `release_profile=beta`, the `Run repo/live E2E validation` live-provider suites are advisory (warnings, not blockers); stable and full profiles keep them blocking. When `live_suite_filter` explicitly requests a gated QA live lane such as Discord, WhatsApp, or Slack, the matching `OPENCLAW_RELEASE_QA_*_LIVE_CI_ENABLED` repo variable must be enabled; otherwise input capture fails instead of silently skipping the lane.
|
||||
|
||||
|
||||
@@ -14,7 +14,8 @@ whole release. Run release preparation before freezing the Code SHA; it
|
||||
refreshes Control UI locale output when the background bot has not landed it
|
||||
yet, then enforces the same strict zero-fallback check used by release CI.
|
||||
|
||||
Freeze the product-complete pre-changelog commit as the **Code SHA**, then run:
|
||||
Freeze the product-complete pre-changelog commit as the **Code SHA** and select
|
||||
one trusted workflow commit as the **Tooling SHA**, then run:
|
||||
|
||||
```bash
|
||||
pnpm ci:full-release \
|
||||
@@ -30,13 +31,18 @@ package versions and `stable` otherwise. Pass alternate workflow inputs with
|
||||
independent failures together. Pass `-f fail_fast=true` when the shorter
|
||||
first-failure cancellation path is preferable.
|
||||
|
||||
The helper creates a temporary `release-ci/*` ref pinned to one trusted
|
||||
`origin/main` workflow SHA, passes the target SHA only as the candidate `ref`,
|
||||
and deletes the temporary ref after validation. Every dispatched child must
|
||||
report that same workflow SHA. Pass
|
||||
The helper creates a temporary `release-ci/*` ref pinned to the Tooling SHA,
|
||||
passes the Validation SHA as both the candidate ref and `expected_sha`, and
|
||||
deletes the temporary ref after validation. The Validation SHA equals the Code
|
||||
SHA for product validation or the Release SHA for changelog-only validation; it
|
||||
is not a third release identity. The workflow rejects malformed or mismatched
|
||||
expected SHAs before child dispatch. Every child must report the same Tooling
|
||||
SHA. Pass
|
||||
`-f reuse_evidence=false` to force a fresh run or
|
||||
`--workflow-sha <trusted-main-sha>` to select an older workflow commit still
|
||||
reachable from current `origin/main`. The workflow never creates or updates
|
||||
`--workflow-sha <trusted-main-sha>` to select a compatible older workflow
|
||||
commit still reachable from current `origin/main`. The helper rejects a pinned
|
||||
Tooling SHA that does not declare the `expected_sha` dispatch input; it never
|
||||
silently substitutes newer tooling. The workflow never creates or updates
|
||||
repository refs itself.
|
||||
|
||||
## Extended-stable exception
|
||||
@@ -45,9 +51,11 @@ Extended-stable publish requires a run whose workflow and target are both the
|
||||
canonical branch:
|
||||
|
||||
```bash
|
||||
RELEASE_SHA="$(git rev-parse HEAD)"
|
||||
gh workflow run full-release-validation.yml \
|
||||
--ref extended-stable/YYYY.M.33 \
|
||||
-f ref=extended-stable/YYYY.M.33 \
|
||||
-f expected_sha="$RELEASE_SHA" \
|
||||
-f release_profile=stable
|
||||
```
|
||||
|
||||
@@ -67,10 +75,16 @@ SHA descends from the Code SHA and the complete changed path set is exactly
|
||||
`CHANGELOG.md`; npm preflight and package/install acceptance still run on the
|
||||
Release SHA.
|
||||
|
||||
`release_profile=stable` and `release_profile=full` always run the exhaustive
|
||||
live/Docker soak. Pass `run_release_soak=true` to include the same soak lanes
|
||||
with the `beta` profile. Stable publication rejects a validation manifest
|
||||
without this soak and blocking product-performance evidence.
|
||||
The conceptual phases map to current inputs:
|
||||
|
||||
- `beta-publish`: `release_profile=beta`, `run_release_soak=false`
|
||||
- `postpublish-confidence`: exact published package plus
|
||||
`run_release_soak=true` or explicit focused groups
|
||||
- `stable-publish`: `release_profile=stable`
|
||||
|
||||
Beta-publish `all` excludes broad live/E2E soak and QA-live lanes. Stable and
|
||||
full always run the soak. Stable publication rejects a validation manifest
|
||||
without soak and blocking product-performance evidence.
|
||||
|
||||
Package Acceptance normally builds the candidate tarball from the resolved
|
||||
`ref`, including full-SHA runs dispatched with `pnpm ci:full-release`. After a
|
||||
@@ -122,17 +136,17 @@ the `runtime-assets` Docker target with
|
||||
other stages and is enforced by the umbrella verifier; lanes no longer wait for
|
||||
it before dispatching. A narrower `rerun_group` skips this preflight.
|
||||
|
||||
| Stage | Details |
|
||||
| ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| Target resolution | **Job:** `Resolve target ref`<br />**Child workflow:** none<br />**Proves:** resolves the release branch, tag, or full commit SHA and records selected inputs.<br />**Rerun:** rerun the umbrella if this fails. |
|
||||
| Shared candidate | **Job:** `Prepare shared release candidate`<br />**Child workflow:** `OpenClaw Live And E2E Checks (Reusable)`<br />**Proves:** packs and validates one exact-SHA package, builds one functional Docker image, and records immutable package and image artifact tuples for both package-facing child workflows.<br />**Rerun:** rerun the affected package, plugin-prerelease, cross-OS, or live/E2E group. |
|
||||
| Docker assets preflight | **Job:** `Verify Docker runtime image assets`<br />**Child workflow:** none<br />**Proves:** the `runtime-assets` Docker build target still succeeds before any other stage dispatches. Runs only for `rerun_group=all`.<br />**Rerun:** rerun the umbrella with `rerun_group=all`. |
|
||||
| Vitest and normal CI | **Job:** `Run normal full CI`<br />**Child workflow:** `CI`<br />**Proves:** manual full CI graph against the target ref, including Linux Node lanes, bundled plugin shards, plugin and channel contract shards, Node 22 compatibility, `check-*`, `check-additional-*`, built-artifact smoke checks, docs checks, Python skills, Windows, macOS, Control UI i18n, and Android via the umbrella.<br />**Rerun:** `rerun_group=ci`. |
|
||||
| Plugin prerelease | **Job:** `Run plugin prerelease validation`<br />**Child workflow:** `Plugin Prerelease`<br />**Proves:** release-only plugin static checks, agentic plugin coverage, full plugin batch shards, plugin prerelease Docker lanes, and a non-blocking `plugin-inspector-advisory` artifact for compatibility triage.<br />**Rerun:** `rerun_group=plugin-prerelease`. |
|
||||
| Release checks | **Job:** `Run release/live/Docker/QA validation`<br />**Child workflow:** `OpenClaw Release Checks`<br />**Proves:** install smoke, cross-OS package checks, Package Acceptance, QA Lab parity, live Matrix, Buzz, and Telegram, plus gated advisory Discord, WhatsApp, and Slack lanes. Stable and full profiles also run exhaustive live/E2E suites and Docker release-path chunks; beta can opt in with `run_release_soak=true`.<br />**Rerun:** `rerun_group=release-checks` or a narrower release-checks handle. |
|
||||
| Package Telegram | **Job:** `Run package Telegram E2E`<br />**Child workflow:** `NPM Telegram Beta E2E`<br />**Proves:** a focused published-package Telegram E2E when `release_package_spec` or `npm_telegram_package_spec` is set. Full candidate validation uses the canonical Package Acceptance Telegram E2E instead.<br />**Rerun:** `rerun_group=npm-telegram` with `release_package_spec` or `npm_telegram_package_spec`. |
|
||||
| Product performance | **Job:** `Run product performance evidence`<br />**Child workflow:** `OpenClaw Performance`<br />**Proves:** release-profile performance run (`profile=release`, `repeat=3`, `fail_on_regression=true`, `publish_reports=false`) against the target SHA. Kova output stays in workflow artifacts and the child must prove its report publisher was skipped. Required (blocking) only for `rerun_group=all` or `rerun_group=performance`; not required for narrower rerun groups.<br />**Rerun:** `rerun_group=performance`. |
|
||||
| Umbrella verifier | **Job:** `Verify full validation`<br />**Child workflow:** none<br />**Proves:** re-checks recorded child run conclusions and appends slowest-job tables from child workflows.<br />**Rerun:** rerun only this job after rerunning a failed child to green. |
|
||||
| Stage | Details |
|
||||
| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| Target resolution | **Job:** `Resolve target ref`<br />**Child workflow:** none<br />**Proves:** resolves the release branch, tag, or full commit SHA and records selected inputs.<br />**Rerun:** rerun the umbrella if this fails. |
|
||||
| Shared candidate | **Job:** `Prepare shared release candidate`<br />**Child workflow:** `OpenClaw Live And E2E Checks (Reusable)`<br />**Proves:** packs and validates one exact-SHA package, builds one functional Docker image, and records immutable package and image artifact tuples for both package-facing child workflows.<br />**Rerun:** rerun the affected package, plugin-prerelease, cross-OS, or live/E2E group. |
|
||||
| Docker assets preflight | **Job:** `Verify Docker runtime image assets`<br />**Child workflow:** none<br />**Proves:** the `runtime-assets` Docker build target still succeeds before any other stage dispatches. Runs only for `rerun_group=all`.<br />**Rerun:** rerun the umbrella with `rerun_group=all`. |
|
||||
| Vitest and normal CI | **Job:** `Run normal full CI`<br />**Child workflow:** `CI`<br />**Proves:** manual full CI graph against the target ref, including Linux Node lanes, bundled plugin shards, plugin and channel contract shards, Node 22 compatibility, `check-*`, `check-additional-*`, built-artifact smoke checks, docs checks, Python skills, Windows, macOS, Control UI i18n, and Android via the umbrella.<br />**Rerun:** `rerun_group=ci`. |
|
||||
| Plugin prerelease | **Job:** `Run plugin prerelease validation`<br />**Child workflow:** `Plugin Prerelease`<br />**Proves:** release-only plugin static checks, agentic plugin coverage, full plugin batch shards, plugin prerelease Docker lanes, and a non-blocking `plugin-inspector-advisory` artifact for compatibility triage.<br />**Rerun:** `rerun_group=plugin-prerelease`. |
|
||||
| Release checks | **Job:** `Run release/live/Docker/QA validation`<br />**Child workflow:** `OpenClaw Release Checks`<br />**Proves:** install smoke, cross-OS package checks, Package Acceptance, and QA Lab parity. QA-live Matrix, Buzz, and Telegram plus gated advisory Discord, WhatsApp, and Slack run for stable/full, beta with `run_release_soak=true`, or explicit `qa`/`qa-live` groups. Stable and full profiles also run exhaustive live/E2E suites and Docker release-path chunks.<br />**Rerun:** `rerun_group=release-checks` or a narrower release-checks handle. |
|
||||
| Package Telegram | **Job:** `Run package Telegram E2E`<br />**Child workflow:** `NPM Telegram Beta E2E`<br />**Proves:** a focused published-package Telegram E2E when `release_package_spec` or `npm_telegram_package_spec` is set. Full candidate validation uses the canonical Package Acceptance Telegram E2E instead.<br />**Rerun:** `rerun_group=npm-telegram` with `release_package_spec` or `npm_telegram_package_spec`. |
|
||||
| Product performance | **Job:** `Run product performance evidence`<br />**Child workflow:** `OpenClaw Performance`<br />**Proves:** release-profile performance run (`profile=release`, `repeat=3`, `fail_on_regression=true`, `publish_reports=false`) against the target SHA. Kova output stays in workflow artifacts and the child must prove its report publisher was skipped. Required (blocking) only for `rerun_group=all` or `rerun_group=performance`; not required for narrower rerun groups.<br />**Rerun:** `rerun_group=performance`. |
|
||||
| Umbrella verifier | **Job:** `Verify full validation`<br />**Child workflow:** none<br />**Proves:** re-checks recorded child run conclusions and appends slowest-job tables from child workflows.<br />**Rerun:** rerun only this job after rerunning a failed child to green. |
|
||||
|
||||
The umbrella always dispatches product performance in artifact-only mode.
|
||||
`OpenClaw Performance` permits report publication only for scheduled runs or a
|
||||
@@ -153,11 +167,10 @@ publish consumers. The verifier always prefers the attempt-qualified artifact;
|
||||
as a transition, it accepts the stable name only for an attempt-1 manifest v2
|
||||
producer. It rejects that legacy name for later attempts and manifest v3.
|
||||
|
||||
For `ref=main` with `rerun_group=all`, for `release/*` refs, and for Tideclaw
|
||||
alpha refs, a newer umbrella run supersedes an older one with the same ref and
|
||||
rerun group. When the parent is cancelled, its monitor cancels any child
|
||||
workflow it already dispatched. Tag and pinned-SHA validation runs do not
|
||||
cancel each other.
|
||||
Concurrency is keyed by Validation SHA, Tooling SHA, and rerun group and does
|
||||
not cancel an older run. Parent cancellation or timeout leaves an adopted
|
||||
identity-checked child running. Cancel that exact child explicitly when it is
|
||||
no longer useful.
|
||||
|
||||
## Release checks stages
|
||||
|
||||
@@ -168,7 +181,7 @@ artifact when package or Docker-facing stages need it.
|
||||
|
||||
| Stage | Details |
|
||||
| ------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| Release target | **Job:** `Resolve target ref`<br />**Backing workflow:** none<br />**Tests:** selected ref, optional expected SHA, profile, rerun group, and focused live suite filter.<br />**Rerun:** `rerun_group=release-checks`. |
|
||||
| Release target | **Job:** `Resolve target ref`<br />**Backing workflow:** none<br />**Tests:** selected ref, optional expected Validation SHA, profile, rerun group, and focused live suite filter.<br />**Rerun:** `rerun_group=release-checks`. |
|
||||
| Package artifact | **Job:** `Prepare release package artifact`<br />**Backing workflow:** none<br />**Tests:** validates the umbrella's immutable package tuple, or packs one candidate tarball for a direct/focused Release Checks dispatch, then exposes it to downstream package-facing checks.<br />**Rerun:** the affected package, cross-OS, or live/E2E group. |
|
||||
| Install smoke | **Job:** `Run install smoke`<br />**Backing workflow:** `Install Smoke`<br />**Tests:** full install path with root Dockerfile smoke image reuse, QR package install, root and gateway Docker smokes, installer Docker tests, and Bun global install image-provider smoke.<br />**Rerun:** `rerun_group=install-smoke`. |
|
||||
| Cross-OS | **Job:** `cross_os_release_checks`<br />**Backing workflow:** `OpenClaw Cross-OS Release Checks (Reusable)`<br />**Tests:** fresh and upgrade lanes on Linux, Windows, and macOS for the selected provider and mode, using the candidate tarball plus a baseline package.<br />**Rerun:** `rerun_group=cross-os`. |
|
||||
@@ -211,11 +224,11 @@ commands with package artifact and image reuse inputs when available.
|
||||
|
||||
`release_profile` mostly controls live/provider breadth inside release checks.
|
||||
It does not remove normal full CI, Plugin Prerelease, install smoke, package
|
||||
acceptance, or QA Lab. Stable and full profiles always run exhaustive repo/live
|
||||
E2E and Docker release-path soak coverage. The beta profile can opt in with
|
||||
`run_release_soak=true`. Package Acceptance supplies the canonical package
|
||||
Telegram E2E for every full candidate, so the umbrella does not duplicate that
|
||||
live poller.
|
||||
acceptance, or QA parity. Stable and full profiles always run exhaustive
|
||||
repo/live E2E, Docker release-path, and QA-live soak coverage. The beta profile
|
||||
adds those lanes only with `run_release_soak=true` or an explicit `qa` or
|
||||
`qa-live` rerun. Package Acceptance supplies the canonical package Telegram
|
||||
E2E for every candidate, so the umbrella does not duplicate that live poller.
|
||||
|
||||
| Profile | Intended use | Included live/provider coverage |
|
||||
| -------- | --------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
@@ -247,7 +260,7 @@ Use `rerun_group` to avoid repeating unrelated release boxes:
|
||||
|
||||
| Handle | Scope |
|
||||
| ------------------- | ----------------------------------------------------------------------------------------------- |
|
||||
| `all` | All Full Release Validation stages. |
|
||||
| `all` | Phase-default stages; beta without soak excludes broad live/E2E and QA-live. |
|
||||
| `ci` | Manual full CI child only. |
|
||||
| `plugin-prerelease` | Plugin Prerelease child only. |
|
||||
| `release-checks` | All OpenClaw Release Checks stages. |
|
||||
@@ -301,8 +314,11 @@ need fresh QA evidence.
|
||||
## Evidence to keep
|
||||
|
||||
Keep the `Full Release Validation` summary as the release-level index. It links
|
||||
child run ids and includes slowest-job tables. For failures, inspect the child
|
||||
workflow first, then rerun the smallest matching handle above.
|
||||
child run ids and includes slowest-job tables. Classify failures as product,
|
||||
harness/tooling/provenance, infrastructure/credential, or wrapper. Only a
|
||||
confirmed product failure changes the Code SHA. Use one diagnosis, one fix when
|
||||
needed, and one narrow retry, then reassess; do not automatically rerun `all`.
|
||||
Narrow evidence is not publish authorization by itself.
|
||||
|
||||
For a regular release, record both Code SHA and Release SHA, the reuse policy
|
||||
and changed-path set, the green Code SHA parent run, and the lightweight Release
|
||||
|
||||
Reference in New Issue
Block a user