Patrick Erichsen
105038e658
ci: mirror Docker release images to Vercel registry ( #120058 )
...
* ci: publish release images to Vercel registry
* ci: publish beta images to Vercel registry
* fix(ci): allow beta Vercel dispatch
* fix(ci): publish VCR-compatible image indexes
* fix(ci): allow VCR readiness propagation
* fix(ci): use Sandbox as VCR readiness proof
* fix(ci): promote clean VCR channel indexes
* fix(release): harden VCR publication
* fix(release): bind VCR publishing to verified inputs
* fix(test): follow script declaration migration
* fix(release): isolate VCR mirroring
* test(release): align VCR secret ownership
2026-08-10 14:45:05 -07:00
Peter Steinberger
25a9a2e020
fix(ci): guard empty QA-live filter token join in release checks
...
An all-QA live_suite_filter leaves repo_filter_tokens empty; joining the
empty array under set -u aborts the scheduling script on bash <4.4.
Default the expansion and update the workflow-content assertion.
2026-08-10 09:35:51 -07:00
Vincent Koc
1f591bba56
fix(release): bound validation retries and soak
2026-08-10 22:31:32 +08:00
Vincent Koc
a994d2ad5f
fix(qa): provide protocol base to evidence runs ( #120710 )
...
Co-authored-by: Dallin Romney <6581799+RomneyDa@users.noreply.github.com >
Punchcard-Session: amber-workshop-workshop-36
2026-08-10 16:59:58 +08:00
Vincent Koc
f4987deb94
fix(ci): support frozen validation scripts ( #121458 )
2026-08-10 14:49:51 +08:00
Peter Steinberger
eb9cac065f
fix(security): unify secret-redaction and SSRF policy ownership ( #121335 )
...
* fix(security): unify secret-redaction and SSRF policy ownership
Memory-host errors now redact through the canonical redactor (payment/card/CVV
coverage included) via the existing core facade instead of a stale local
pattern table; ACP error redaction is wired through a single barrel so the
injected canonical redactor no longer depends on module load order, and the
acp-core fallback table shrinks to the minimal standalone set (structured
auth-header patterns proven load-bearing stay). The memory-host SsrFPolicy
structural copy is deleted in favor of the canonical src/infra/net/ssrf.ts
type re-exported through the network facade.
* fix(build): keep memory-core doctor closure execa-free
Import the canonical redactor directly from src/logging/redact.js instead of
the openclaw-runtime-io facade (which reaches execa through the full runtime
graph), and regenerate the plugin SDK API baseline for the intentional
canonical-SsrFPolicy surface change.
* fix(security): merge operator redact patterns with defaults in injected redactors
ClawSweeper found that ACP injected the general redactor, where nonempty logging.redactPatterns replace the built-in provider-token patterns. Use the tool-payload redactor for ACP and memory-host error formatting so operator patterns extend defaults and redaction remains forced for these security boundaries.
2026-08-09 22:40:58 -07:00
Peter Steinberger
3156b67708
ci(labeler): fix dead rules, cover all plugin dirs, drop vendored artifacts ( #121348 )
...
* ci(labeler): fix dead rules and cover unlabeled plugin dirs
* chore: drop vendored swabble workflow and empty ActivityWidget asset catalog
2026-08-09 22:28:02 -07:00
Peter Steinberger
ff10db092b
ci(mantis): extract shared request-resolution, ref-trust, and reaction workflows ( #121339 )
...
* ci(mantis): extract shared request, trust, and reaction workflows
* ci(mantis): drop caller-less params from shared resolve workflow
* test(mantis): read candidate-override parsing from shared resolve workflow
2026-08-09 22:04:27 -07:00
Peter Steinberger
f44c5e2e5e
fix(plugins): surface manifest-only bundled capabilities ( #121354 )
...
Use a manifest-first inventory with independent coverage for manifest-only bundled capabilities.
Retire the undocumented thread-ownership plugin while Doctor removes stale references.
Document Talk voice and persist only provider-scoped voice selection.
Closes #121353
2026-08-09 19:43:49 -07:00
Peter Steinberger
88fc335323
fix(ci): support frozen script entrypoints ( #121208 )
...
* fix(ci): support frozen script entrypoints
* fix(ci): route frozen plugin tests through package script
* fix(release): support compiled candidate test helpers
* fix(release): support compiled upgrade helpers
* fix(release): mount trusted upgrade runtime
* fix(release): preserve trusted tsx resolution
2026-08-10 10:31:21 +08:00
Peter Steinberger
64695e5024
chore: detect export name collisions ( #121300 )
...
* chore(scripts): add export-name-collision check with debt baseline
* chore(scripts): allowlist per-module test-hook export idiom
* chore(scripts): recognize const forwarders, harness files, and JS sources in collision check
2026-08-09 18:58:28 -07:00
Peter Steinberger
0ef798d28d
fix(gateway): keep hello authorization aligned with RPC access ( #120888 )
...
* fix(gateway): separate socket and device token scopes
* chore(i18n): refresh native source baseline
* style(ios): keep gateway channel within lint limit
* refactor(gateway): simplify scope metadata decoding
* ci(ui): isolate real-gateway e2e suites
* docs(ci): align runner table formatting
* chore(plugin-sdk): refresh api baseline
* ci(ui): route real-gateway retries to hosted runners
* chore(plugin-sdk): repair generated api baseline
* test(ui): select Labs toggles by title
* fix(gateway): preserve stored scopes without wire metadata
2026-08-09 14:50:07 -07:00
Peter Steinberger
a828bfe04e
fix(release): bootstrap typed Docker planner ( #121088 )
...
* fix(release): bootstrap typed Docker planner
* test(release): handle optional workflow steps
* fix(release): isolate trusted planner dependencies
Punchcard-Session: amber-workshop-workshop-36
* test(release): update trusted harness contract
Punchcard-Session: amber-workshop-workshop-36
* fix(release): bootstrap every trusted Docker planner
Punchcard-Session: amber-workshop-workshop-36
* fix(release): centralize trusted harness bootstrap
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-09 11:14:23 -07:00
Vincent Koc
106cdd18a9
fix(ci): shard release merge-tree lint ( #120421 )
...
* fix(ci): shard release merge-tree lint
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): resolve branch-creation push base
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): follow Oxlint shard runner rename
Punchcard-Session: amber-workshop-workshop-36
2026-08-10 00:48:44 +08:00
Peter Steinberger
4b85d834ed
fix(ci): sparse-checkout the renamed local-heavy-check-runtime.mts on the frozen shard lane ( #121097 )
2026-08-09 08:59:30 -07:00
Peter Steinberger
623866a30e
fix(release): preserve SHA evidence identity ( #121080 )
2026-08-09 07:51:57 -07:00
Peter Steinberger
c70aee247e
refactor(scripts): migrate JavaScript tools to TypeScript ( #121005 )
...
* refactor(scripts): migrate JavaScript tools to TypeScript
* fix(ci): keep changed-scope preflight zero-install
* fix(ci): preserve zero-install script owners
* fix(ci): complete script migration follow-through
* fix(release): keep stable closeout zero-install
* fix(scripts): preserve standalone execution boundaries
* fix(scripts): repair standalone loader boundaries
* fix(scripts): normalize gateway observation ids
* fix(scripts): keep Docker packager standalone
* test(scripts): preserve rebase cleanup helpers
* test(sessions): use tracked temp directory
2026-08-09 07:21:35 -07:00
Vincent Koc
f83ba2b326
fix(ci): route UI E2E PR retries to hosted runners ( #120997 )
...
* fix(ci): route UI E2E PR retries to hosted runners
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): align UI E2E retry cache routing
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): clarify UI E2E retry routing
Punchcard-Session: amber-workshop-workshop-36
* fix(ci): validate workflow expression capture
Punchcard-Session: amber-workshop-workshop-36
2026-08-09 19:50:24 +08:00
Peter Steinberger
b869d5e73f
fix(workers): skip shared-host quiescence sweeps ( #120969 )
...
* fix(workers): skip shared-host quiescence sweeps
Refs #120952 .
* test(workers): update shared-host fixtures
Refs #120952 .
* fix(workers): reconcile shared-host lease metadata
* fix(workers): fence unknown lease isolation
* chore(plugin-sdk): refresh API baseline
* fix(workers): fence tunnel isolation updates
* docs(workers): clarify shared-host final fences
* ci: invalidate Vitest cache for state schemas
* refactor(workers): import stableWorkerPathComponent from its defining module
workspace-sync.ts crossed the 700-line lint budget by one; drop its
re-export and point consumers at workspace-sync-helpers directly.
2026-08-09 04:34:39 -07:00
Peter Steinberger
8b0735e89f
refactor(memory)!: remove the QMD backend; builtin is the only memory engine ( #120936 )
...
* refactor(memory): remove qmd backend
Make builtin the sole memory-core engine, rename the retained session helper barrel, retire QMD config with doctor migrations, and remove QMD runtime/UI/policy surfaces.
* docs(memory): remove qmd backend guidance
Delete the QMD concept page, rewrite memory documentation for builtin retrieval, and remove QMD from navigation and taxonomy source.
* refactor(memory): remove qmd-only leftovers
* refactor(memory): finish qmd integration cleanup
* build(deps): align root string-width types
* build(deps): model root string-width tooling
* refactor(memory): align qmd removal ui and docs
* fix(memory): preserve qmd external paths in doctor
* test(memory): remove obsolete backend probe case
* test(plugin-sdk): refresh private type baseline
2026-08-09 03:05:47 -07:00
Peter Steinberger
0df1a89e3a
fix(telegram): preserve visible draft recovery ( #120626 )
...
* fix(telegram): preserve visible draft recovery
* fix(telegram): await visible draft send
* test(telegram): use const in draft recovery test
* test(telegram): add live partial failure proof
* test(telegram): register live recovery coverage
* ci(qa): support mock Telegram proof scenarios
* test(telegram): isolate live recovery fallback
* test(telegram): assert live recovery behavior
* fix(agents): join partial reply delivery
* test(telegram): keep settlement proof at core boundary
2026-08-09 02:54:38 -07:00
Peter Steinberger
29c442d483
fix(ci): recheck ClawSweeper PR ack marker before posting ( #120990 )
...
Propagates the canonical dispatcher step from openclaw/clawsweeper#1083
byte-identically: the acknowledgement step waits 15s after a clean
marker check and rechecks immediately before posting, so near-simultaneous
opened and ready_for_review runs (draft PR marked ready within seconds,
as on #120974 ) post exactly one receipt ack.
2026-08-09 01:37:34 -07:00
Peter Steinberger
adcf5bd93a
ci: acknowledge pull request receipts in clawsweeper dispatch ( #120934 )
...
Propagate the receipt-acknowledgment steps from the canonical
ClawSweeper dispatch template (openclaw/clawsweeper#1080 ): mint a
minimal issues:write App token and post an idempotent
clawsweeper-pr-ack marker comment for non-draft opened and
ready_for_review pull requests, before review dispatch.
2026-08-09 00:15:08 -07:00
Peter Steinberger
26ee1b4935
fix(doctor): enforce deprecation registry deadlines ( #120868 )
2026-08-08 21:19:04 -07:00
Peter Steinberger
5cf9c9cda6
ci: extend watchdog for cold migration proofs ( #120700 )
2026-08-08 18:03:16 -07:00
Peter Steinberger
c5085b9152
fix(ci): isolate performance cron fixture ( #120648 )
...
Keep cron suppression local to the direct source-performance gateway child and remove the unrelated memory dreaming override.
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-08 15:54:29 -07:00
Vincent Koc
0d45efd5da
fix(ci): retry transient artifact API reads ( #120654 )
2026-08-09 02:05:04 +08:00
Vincent Koc
49161dee60
fix(release): unblock deferred Telegram beta validation ( #120630 )
...
* fix(release): allow deferring package Telegram validation
* fix(qa): mount taxonomy in package Telegram harness
* fix(release): restrict Telegram deferral to beta
2026-08-09 01:03:02 +08:00
Vincent Koc
0fd3ee6929
fix(ci): isolate performance gateway fixture ( #120620 )
2026-08-09 00:56:01 +08:00
Vincent Koc
13322b2adc
fix(ci): run every changed-scope routing suite ( #120625 )
2026-08-09 00:50:17 +08:00
Peter Steinberger
9a2f91a79a
fix(release): keep prerelease companions exact in cross-OS checks ( #120556 )
...
* fix(release): install exact cross-os companion artifacts
* fix(release): derive companion package type from resolver
* fix(release): produce provider-owned companion registries
* fix(release): preserve companions for npm candidates
* refactor(release): simplify companion registry flow
* test(release): align package acceptance contracts
* fix(release): guard optional registry JSON parsing
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-08-08 21:45:16 +08:00
Vincent Koc
4eec51a276
merge: align Fish Audio extension directory ( #120084 )
2026-08-08 20:46:55 +08:00
Peter Steinberger
caa50686ea
fix(ci): clear Mantis reactions with app identity ( #120523 )
2026-08-08 05:00:08 -07:00
Peter Steinberger
95ea82b1e5
fix(ci): restore deterministic main checks ( #120501 )
...
* fix(plugin-sdk): stabilize session catalog baseline
* test(doctor): isolate bind persistence inventory
* fix(ci): prepare max-lines base during checkout
* test(sessions): align freshness regression fixtures
* style(tests): format context usage fixture
* fix(ci): preserve token provenance and isolate fork credentials
Finish the canonical token-provenance fixtures while preserving the
latest maintainer-owned unavailable-usage ordering. Limit the diff-base
GitHub token to manual non-release comparisons and guard that fork
isolation invariant in the existing workflow regression test.
Co-authored-by: Sarah Fortune <sarah.fortune@gmail.com >
* test(ui): identify actual managed image eviction
* fix(ci): reuse the validated protocol comparison base
Consume the immutable diff base already resolved and validated by
preflight for every CI event. Remove the dead duplicate manual
GitHub lookup and unreachable fallbacks, and guard the single
authoritative path without changing fork credential isolation.
* test(sessions): preserve stale total expectation
* test(ui): arm reconnect deferral before disconnect
---------
Co-authored-by: Sarah Fortune <sarah.fortune@gmail.com >
2026-08-08 03:36:35 -07:00
Vincent Koc
e5f5030570
fix(plugins): align Fish Audio extension directory
2026-08-08 02:21:33 -07:00
Peter Steinberger
c98bd2287b
ci(release): retry child-run adoption through read-after-write lag ( #120477 )
2026-08-07 22:00:25 -07:00
Peter Steinberger
8b8058a68b
fix(release): supply exact Codex companions to cross-OS checks and repair legacy node-host metadata ( #120442 )
...
* fix(release): supply exact Codex companions to cross-OS checks and repair legacy node-host metadata
* test(release): align async run title rejection
2026-08-07 20:06:53 -07:00
Peter Steinberger
53ae576464
ci(release): tolerate async run-name evaluation when adopting validation children ( #120427 )
2026-08-07 19:10:49 -07:00
Peter Steinberger
7016b9c81d
fix(ci): adopt dispatched release validation runs ( #120342 )
...
* fix(ci): adopt dispatched release validation runs
* test(ci): update release child validation guard
* fix(ci): cancel mismatched release children
2026-08-07 16:44:12 -07:00
Vincent Koc
9195bd55c2
fix(ci): retire dead ClawSweeper commit dispatch ( #120281 )
...
* fix(ci): retire dead ClawSweeper commit dispatch
* docs(ci): preserve offline ClawSweeper review path
2026-08-08 05:39:08 +08:00
Vincent Koc
8c68f74ef9
fix(ci): align hosted gates with workflow applicability ( #120313 )
2026-08-08 03:59:27 +08:00
Dallin Romney
1f1333dfec
fix(ci): allow frozen target scenario omissions in candidate prep ( #120166 )
2026-08-07 14:56:42 +08:00
Vincent Koc
a0deb8edae
fix(release): provide prerelease plugin companions to package QA ( #120107 )
2026-08-07 13:31:41 +08:00
Vincent Koc
1823be79ce
fix(ci): provision native Android resources for frozen current-contract targets ( #120081 )
2026-08-07 11:37:04 +08:00
Vincent Koc
2013123472
fix(release): isolate private Telegram QA harness ( #120088 )
2026-08-07 10:03:14 +08:00
Peter Steinberger
00a5db443a
refactor: remove obsolete commit helper
2026-08-06 18:10:10 -07:00
Dallin Romney
8c64ca24b1
fix(qa): include pinned gateway restart in core runtime proof ( #118009 )
...
* fix(qa): run pinned gateway restart runtime pair
* fix(qa): run pinned pair before advisory report
2026-08-06 18:52:20 +08:00
Vincent Koc
01ae9d40fc
chore(release): add protected npm placeholder publishing ( #119875 )
...
Adds a protected, dry-run-by-default workflow for reserving release-enabled external plugin package names with verified npm 0.0.0 placeholders.
2026-08-06 17:37:09 +08:00
Vincent Koc
7dcb1ad5ce
fix(qa): attest realized profile executions ( #119761 )
...
* fix(qa): attest profile execution plans
Persist the canonical profile membership partition and scheduler-owned expected and observed execution cells in QA evidence. Validate successful evidence completeness and bind the canonical plan digest into workflow manifests.
Punchcard-Session: silver-meadow-lantern-vx
* test(ci): exercise QA evidence artifact round trips
Punchcard-Session: silver-meadow-lantern-vx
* fix(qa): record only realized profile executions
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
Co-authored-by: ruel225 <ruel225@users.noreply.github.com >
Punchcard-Session: silver-meadow-lantern-vx
* test(qa): type realized channel evidence
Punchcard-Session: silver-meadow-lantern-vx
---------
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
Co-authored-by: ruel225 <ruel225@users.noreply.github.com >
2026-08-06 08:33:02 +08:00
Peter Steinberger
e7b7d1c8cd
fix(ci): stop label-driven automation churn ( #119610 )
2026-08-05 06:53:23 -07:00