Commit Graph

613 Commits

Author SHA1 Message Date
Dallin Romney 53fbe2eb33 fix(release): preserve validation plan across reruns (#127343)
* fix(release): preserve validation plan across reruns

* test(release): align rerun plan assertions

* refactor(release): use canonical plan cache action

* style(test): format release plan cache assertion
2026-08-21 19:08:32 -07:00
Jason (Json) a4ae339903 docs: prefer gh attach for PR media (#127417) 2026-08-21 13:55:28 -06:00
Vincent Koc a2f0b84e8a fix(release): report blockers before diagnostics finish (#127014)
* fix(release): separate decisions from diagnostic drain

* test(release): align decision drain fixtures

* fix(release): pin artifact downloads to valid v8 SHA

* fix(release): default empty evidence paths in plans

* fix(release): bind complete evidence reuse selection

* fix(release): harden retry artifact integrity

* fix(release): canonicalize reused validation evidence

* fix(release): bind manifest children to execution plan

* test(release): fix validation fixture types

* fix(release): retry transient decision artifact reads
2026-08-21 09:14:39 -07:00
Vincent Koc fa86caf94f fix(release): keep protected tooling trusted after main moves (#126881)
* fix(release): keep protected tooling trusted after main moves

* fix(release): cover protected tooling recovery paths

* fix(release): honor live tooling contracts

* fix(release): revalidate tooling at npm publish

* fix(release): bind npm publishers to live tooling

* fix(release): preserve trusted dispatch identity

* fix(release): revalidate parent authorization

* fix(release): bind ClawHub to release parent

* docs(release): define frozen tooling identity

* test(release): align ClawHub protected dispatch ref

* fix(release): trust protected plugin npm preflight tooling

* docs(release): scope protected writer guarantees

* fix(release): keep protected tooling foundation npm-only

* test(release): cover trusted npm preflight tooling
2026-08-21 07:24:31 +00:00
Vincent Koc 73ff2d2f45 fix(agents): distinguish review routing from enforcement (#126216) 2026-08-20 23:47:14 -07:00
Vincent Koc 750f2f3762 fix(release): require concrete validation retry groups (#127012)
* fix(release): require concrete validation retry groups

* fix(release): reject mismatched retry filters

* fix(release): align retry controller vocabulary

* fix(release): preserve historical validation evidence

* fix(release): validate retry filters before scheduling

* test(release): follow shared filter validator

* docs(testing): clarify release QA retry groups
2026-08-20 23:35:16 -07:00
Dallin Romney 1c40eee82e fix(ci): route recurring validation through SHA helper (#126766) 2026-08-20 19:11:27 -07:00
Peter Steinberger a6a58d827c chore: prepare fresh Amp orb lifecycle (#126933)
* chore: prepare Amp orb lifecycle

Amp-Thread-ID: https://ampcode.com/threads/T-01a01dec-e5b8-75b8-be47-c1a67e993602

* fix: harden orb toolchain bootstrap

Amp-Thread-ID: https://ampcode.com/threads/T-01a01dec-e5b8-75b8-be47-c1a67e993602

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-20 19:03:46 -07:00
Vincent Koc c28c279afa fix(release): keep frozen validation independent of main (#126622)
* fix(release): freeze validation tooling identity

* fix(release): enforce frozen validation contract

* fix(release): validate candidate identity in parent

* fix(ci): close release isolation gate findings
2026-08-20 04:32:38 -07:00
Peter Steinberger b740c68bb5 fix(pr): distinguish owner review from independent approval (#126475) 2026-08-19 16:37:34 -07:00
Patrick Erichsen 1762f43a34 docs: preflight release validation imports (#126471) 2026-08-19 16:25:50 -07:00
Patrick Erichsen 7d3471f129 docs: add release validation handoff (#126456)
* docs: add release validation handoff

* docs: label release validation campaigns

* fix: match release validation label exactly

* docs: structure release validation reports
2026-08-19 16:25:38 -07:00
Peter Steinberger 341551937e fix(agents): preserve empty CLI subagent completions (#126379)
* fix(agents): preserve empty CLI subagent completions

* chore(qa): remove retired Matrix coverage leaf

* refactor: consolidate shared runtime ownership

* fix(scripts): keep runtime build coercion dependency-light

* chore: remove release-owned changelog entry
2026-08-19 11:30:43 -07:00
Josh Lehman a91f1202d9 fix(ui): keep Plugins hub navigation stable (#126061)
* fix(ui): keep Plugins hub navigation stable

* chore: format release validation skill
2026-08-18 16:08:41 -07:00
Patrick Erichsen ed7317eeb9 fix(release): streamline validation setup (#126055)
* fix(release): streamline validation setup

* docs(release): add guided testing prompt

* docs(release): orient validation testers

* docs(release): introduce validation workflow
2026-08-18 15:35:04 -07:00
Patrick Erichsen 695b25386d fix(release): offer OCM installation (#126019) 2026-08-18 14:08:14 -07:00
Patrick Erichsen 3e2a82bc0b feat(release): add interactive release validation skill (#125642)
* feat(release): model interactive validation campaigns

* feat(release): add validation skill workflow

* fix(release): select validation scope before missions

* fix(release): harden copied validation setup

* fix(release): require manual validation skill invocation

* fix(release): harden copied validation finalization

* fix(release): narrow validation issue feedback

* fix(release): surface upgrade results before testing

* fix(release): select validation missions one at a time

* refactor(release): simplify validation to markdown worksheet

* feat(release): prioritize validation from release notes

* refactor(release): tighten validation worksheet hierarchy

* refactor(release): summarize validation priorities by theme

* refactor(release): integrate priorities into subsystem notes

* refactor(release): align subsystem note hierarchy

* refactor(release): remove cherry-picked examples

* refactor(release): derive validation from maturity scorecard

* fix(release): publish absolute scorecard links

* docs(release): preserve scorecard generation step

* docs(release): clarify generated surface headings

* refactor(release): present validation guidance in tables

* docs(release): normalize surface table example

* refactor(release): embed notes in surface tables

* refactor(release): sequence validation campaign setup

* fix(release): trust explicit validation issue

* fix(release): preserve campaign worksheet

* fix(release): clarify validation worksheet
2026-08-18 13:48:11 -07:00
Josh Lehman c5c8a1e4c0 fix(skills): resolve GitHub identity from auth (#125481) 2026-08-17 22:21:33 -07:00
ClawSweeper 1d65e7b449 test: default trusted checks to local execution (#125120)
Co-authored-by: RoboClaw <309084314+roboclaw-bot@users.noreply.github.com>
2026-08-16 23:45:50 -07:00
Peter Steinberger 1ce67d541f docs(ci): record artifact checkout experiment 2026-08-16 15:30:04 -07:00
Peter Steinberger 8f23e68a10 docs(skills): note hosted state-dir and envelope media in session fetching
Two traps hit while reading a team-host session with images: hosted/systemd
installs keep state under the service user's home (root can carry a stray
install), and user-attached images live in message.__openclaw.media[] rather
than image content parts, so parts-only extractors find nothing.
2026-08-16 11:13:47 -07:00
Peter Steinberger cae9ecaba4 fix(pr): substitute anchor-matching canonical wrapper for stale worktrees (#124710)
A linked worktree whose base predates (or carries) wrapper changes relative
to origin/main previously hit a hard refusal, even though the canonical
checkout held exactly the trusted origin/main wrapper the refusal message
told the operator to go run by hand. When the canonical checkout is clean
and byte-identical to fetched refs/remotes/origin/main, exec it with a loud
stderr notice instead; advisory dev-wrapper opt-in keeps precedence, and
the refusal remains when no anchor-matching wrapper exists on disk.

Also records the squash-merged stacked-branch rebase gotcha
(git rebase --onto origin/main <landed-branch>) in the PR maintainer skill.
2026-08-16 10:48:26 -07:00
Peter Steinberger 55240929f5 fix: avoid nesting dedicated Linux workers (#124636)
* fix: avoid nesting dedicated Linux workers

* fix: preserve worker routing prerequisites

---------

Co-authored-by: Amp <amp@ampcode.com>
2026-08-16 08:25:04 -07:00
Peter Steinberger 0c546979b2 fix(release): exclude RoboClaw from contributor credit (#124526) 2026-08-16 03:19:26 -07:00
Peter Steinberger 203aafc415 feat(lint): SAFETY-comment assertion ratchet + repo deslop skill (#124359)
* feat(lint): add SAFETY-comment assertion ratchet

* feat(skills): add repo deslop skill

* fix(lint): refresh initial assertion baseline

* chore(lint): align assertion baseline with main

* chore(lint): sync baseline with current assertion ledger

* test(ui): stabilize Control UI E2E waits

* chore(lint): sync narrowed assertion ledger

* chore(lint): sync fully drained assertion ledger

* fix(lint): close assertion ratchet bypasses
2026-08-15 22:03:48 -07:00
Peter Steinberger c9da900a96 docs(agents): third cleanup pass — sentence-level dedup, CI-guard citations, deployed-agent bullet relocation (#124078)
Three audit lanes over the remaining sections:

- Repair Doctrine/Code/Tests/Start: merge bullets that restate the same
  obligation (read-broadly pair, LOC+closeout, verification pair, helper-rent
  pair, narrow-API pair, over-engineering pair, test-value trio); relocate the
  consolidate-duplicated-setup clause into the test-audit skill's authoring
  gate; split the Codex hard gate into its own bullet.
- Architecture: cite CI enforcement instead of restating it (coercion-helper
  guard owns isRecord carve-outs); defer additive-SQLite criteria to
  docs/reference/database-schemas.md (verbatim coverage); merge the channel
  transport-only trio, hot-path pair, and process-stable/freshness trio;
  every approval gate untouched.
- Platform/Ops: delete the three deployed-agent bullets (generated-media wake,
  message_tool_only, memory wiki) — deployed agents read runtime prompts and
  docs, not this repo's AGENTS.md, and docs/tools/media-overview.md,
  docs/gateway/config-channels.md, and the memory-wiki plugin surfaces cover
  every clause (wiki-maintainer skill gains the verify-contact-data line);
  move SwiftUI Observation + provider-schema bullets to Code; compress Mac
  signing to its doc pointer.
- ClawSweeper: 13 wording compressions; every schema field name and gate kept.

Adversarial no-loss audit ran over the diff; its four findings (external-API
live-test weakened by a feasibility qualifier, dropped orchestration-only
clause, existing-vs-obsolete abstraction flip, oversold channel-doc pointer)
are all restored/fixed.
2026-08-15 02:43:38 -07:00
Peter Steinberger f6ed40d649 docs(agents): fact-check, disambiguate, and further slim root AGENTS.md (#124053)
* docs(agents): fact-check, disambiguate, and further slim root AGENTS.md

Second cleanup pass over root AGENTS.md driven by three audit lanes
(fact-check vs repo, confusion/contradiction hunt, cut candidates):

- Fact fixes: delete the @buape/carbon pin rule (dependency no longer exists
  in any manifest or pnpm-lock.yaml); fix the reply-format example to a real
  file (extensions/telegram/src/bot-access.ts).
- Confusion fixes: define checkout classes once in Commands and merge the
  three conflicting test/check bullets onto them; state that the mock-gateway
  harness verdict satisfies channel-visible proof as an explicit exception to
  mandatory UI screenshots; complete the Map scoped-guide list (src/tui, test)
  and note deeper subtree guides; inline the dangling 'Start-section evidence
  bar' reference; gate issue-closing and public-comment posting on explicit
  authority; scope the NO_REPLY rule to ClawSweeper hook sessions; clarify
  auto-provisioning vs Architecture's compat-fallback deletion rules.
- Cuts/moves: scripts/pr gotchas, throttle-lock recovery, non-main merge
  procedure, media-upload mechanics, and merge-ref-race recognition into
  $openclaw-pr-maintainer; QA private build flag into $openclaw-qa-testing;
  release-branch CI dispatch refs and release-ci-summary limits into
  $release-openclaw-ci; Vitest ENOTEMPTY race into $openclaw-testing;
  WebVNC screenshot etiquette into $crabbox; delete bullets duplicated by
  those skills (prompt snapshots, QA YAML) and the obsolete rebrand-doctor
  bullet; compress the preflight, Codex gate, SQLite-additive, ClawSweeper,
  and Execution Identity wording without dropping any invariant.

* docs(agents): exempt extended-stable canonical dispatch from the target_context_ref rule
2026-08-14 23:40:48 -07:00
Peter Steinberger 83319bad60 docs(agents): dedupe root AGENTS.md and move workflow detail into owning skills (#124027)
* docs(agents): dedupe root AGENTS.md and move workflow detail into owning skills

Root AGENTS.md loads into every session; ~9.5KB of it duplicated content
already owned by skills (crabbox, openclaw-testing, release-openclaw-*,
openclaw-pr-maintainer, openclaw-changelog-update) or restated the same
invariant in multiple sections. Skills absorb the root-only operational
details first (Testbox/Crabbox mechanics, backport default target, fork-code
landing variant), then root keeps hard policy and routing only.

Also fixes skill drift found during the audit: positional testbox status id,
missing remote-unavailable local-fallback policy, delegated-flag reject list,
and aligns the early performance dispatch fail_on_regression flag with the
Full Release Validation profile gate (true stable / false beta).

* docs(agents): derive fail_on_regression from release profile in dispatch example
2026-08-14 22:34:27 -07:00
Peter Steinberger bd4b972794 ci: lower hybrid compact shard height (#123595) 2026-08-14 06:55:17 -07:00
Peter Steinberger 3a49aa1ac6 improve: split hosted Windows CI into three lanes (#123577)
* ci: split Windows tests into three lanes

* test: cover three-way Windows CI partition
2026-08-14 02:40:02 -07:00
Peter Steinberger 257eb21235 improve(ci): shorten GitHub-hosted Node matrix (#123406)
* improve(ci): shorten GitHub-hosted matrix wall time

* fix(ci): keep hosted dependency setup store-only

* fix(ci): split the hosted tooling tail
2026-08-13 19:32:50 -07:00
Peter Steinberger fb82d87cad fix: keep CI running during Blacksmith outages (#123263)
* ci: add runner-backend circuit breaker with GitHub-hosted fallback

* fix(ci): extend hosted timeouts to circuit-breaker runs
2026-08-13 10:18:35 -07:00
Peter Steinberger fa18d8d273 ci: pipeline canonical main runs across two concurrency slots (#123135)
Measured canonical-main first-start delay: median 180s, average 209s; 10 of the last 30 runs waited more than 300s.

Approved tradeoff: up to ~+30 concurrent Blacksmith VMs during merge storms. Scope is canonical main pushes only; pull requests, manual runs, non-main refs, and forks keep their existing semantics.

Bump the canonical-main concurrency group from v7 to v8 so in-flight old-group runs cannot mix with the two-slot pipeline.
2026-08-13 04:04:51 -07:00
Ayaan Zaidi d2afbd05ad refactor(plugin-sdk): replace API baselines with diffs (#123036)
* refactor(plugin-sdk): replace API baselines with diffs

* perf(plugin-sdk): bound API diff resources

* fix(plugin-sdk): isolate API diff dependencies

* fix(release): forward Plugin SDK acknowledgement

* fix(release): enforce SDK acknowledgement on publish

* chore: preserve generated-doc ignore policy

* fix(release): freeze SDK API evidence before publish

* fix(ci): satisfy SDK evidence guards

* fix(release): bind complete SDK evidence

* fix(release): authenticate plugin SDK evidence

* fix(plugin-sdk): abort interrupted API diffs

* test(ui): freeze page clock in background-tasks rail e2e

The rail transcript is compared byte-for-byte across the detail-panel
round-trip while it renders live relative ages; on slow CI runners the
second boundary ticks between the two reads (11s -> 12s) and fails the
equality assertion. Fix the page Date with Playwright setFixedTime while
keeping timers running so the tasks.list polling assertions still hold.

Repro: a 1.5s stall between the reads fails pre-fix with the exact CI
diff and passes post-fix.

* fix(scripts): drop unused export on dependency-evidence CLI main

Knip's workflow scan re-roots script references after an actions/checkout
step that sets path:, so the new trusted-tooling checkout in
openclaw-npm-release.yml stops marking this CLI as a workflow entry and
its exported main() surfaces as an unused export in check-dependencies.
Nothing imports main; the module invokes it through its own entry guard,
so the export keyword was dead surface either way.

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-13 03:45:36 -07:00
Peter Steinberger 3b6e54041f ci: replace dependency sticky disk with exact cache (#123040)
Amp-Thread-ID: https://ampcode.com/threads/T-019ff3db-c467-70ad-8ed3-81f2ba94b0c0

Co-authored-by: Amp <amp@ampcode.com>
2026-08-13 01:13:25 -07:00
Peter Steinberger 86bf768de0 docs(skills): document session and transcript fetching in openclaw-debugging (#122904)
Adds a Fetching Sessions and Transcripts section: sessions CLI first, then
the per-agent SQLite data plane (session_nodes lookup from chat URL
fragments, transcript_events shape, __openclaw sender provenance,
session_transcript_fts, media://inbound mapping) and a dependency-free
node:sqlite read-only recipe for hosts without sqlite3. Read-only-against-
live-gateway rule stated inline.
2026-08-12 18:41:54 -07:00
Josh Lehman 542ac9ac68 fix: make live updater checkout portable (oc-237) (#122873) 2026-08-12 17:17:18 -07:00
Peter Steinberger 6792921dea refactor: finish commitments retirement bookkeeping (#122143)
* refactor(commitments): remove remaining retired references

* refactor(state): track schema retirements
2026-08-11 09:59:11 -07:00
Peter Steinberger 1dcac5b15f fix: open terminals no longer delay gateway updates (#121601)
* fix(gateway): allow updates with open terminals

* fix(updater): support terminal policy upgrades

* chore(plugin-sdk): refresh API baseline
2026-08-11 09:37:58 -07:00
Jason (Json) 94ae370bcc fix(updater): verify launchd bootstrap postcondition (#121747)
* fix(updater): verify launchd bootstrap postcondition

* test(commands): align learn prompt invariants

* test(approvals): align plugin runtime event kinds

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-08-11 09:02:15 -07:00
Vincent Koc 1f591bba56 fix(release): bound validation retries and soak 2026-08-10 22:31:32 +08:00
Peter Steinberger e37614c83f refactor(plugin-sdk): replace hash manifest with JSONL contract (#121473)
* refactor(plugin-sdk): use JSONL API baseline contract

* chore(plugin-sdk): add generated JSONL API baseline
2026-08-10 03:49:17 -07:00
Dallin Romney a808b0d96a docs(release): reconcile stable maturity issue signals (#120515)
* docs(release): reconcile stable maturity issue signals

* docs(release): preserve stable label audit context

* docs(release): reconcile open labelled fixes
2026-08-10 16:13:34 +08:00
Peter Steinberger a8714eea9a docs(agents): add test-audit authoring gate and net-neutral bug-fix doctrine
- Rename openclaw-test-audit skill to test-audit; add an authoring-gate mode
  invoked whenever tests are written, not only during sweeps.
- Repair Doctrine: capture the failing repro before editing; regression tests
  must fail on pre-fix code. Bug fixes default to net <=0 production LOC via
  the refactor that absorbs the fix, not a bolted-on guard.
- ClawSweeper policy: production-vs-test LOC reviewMetrics entry is now
  unconditional for code PRs, counted with judgment; net-positive bug-fix
  deltas become risks findings with bestSolution naming the absorbing refactor.
2026-08-09 19:24:36 -07:00
Shakker cd5ec0027c docs: keep maintainer leads hands-on (#121225) 2026-08-09 21:25:34 +01:00
Peter Steinberger a39c24463e docs: add OpenClaw test-audit skill (#121110) 2026-08-09 09:07:23 -07:00
Vincent Koc 41423753e0 fix(release): normalize appended PR suffixes (#120971) 2026-08-09 23:21:32 +08:00
Peter Steinberger c70aee247e refactor(scripts): migrate JavaScript tools to TypeScript (#121005)
* refactor(scripts): migrate JavaScript tools to TypeScript

* fix(ci): keep changed-scope preflight zero-install

* fix(ci): preserve zero-install script owners

* fix(ci): complete script migration follow-through

* fix(release): keep stable closeout zero-install

* fix(scripts): preserve standalone execution boundaries

* fix(scripts): repair standalone loader boundaries

* fix(scripts): normalize gateway observation ids

* fix(scripts): keep Docker packager standalone

* test(scripts): preserve rebase cleanup helpers

* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00
Vincent Koc 1b404a1755 fix(release): accept repeated PR title suffixes (#120948) 2026-08-09 14:49:39 +08:00
Peter Steinberger 26ee1b4935 fix(doctor): enforce deprecation registry deadlines (#120868) 2026-08-08 21:19:04 -07:00