78 Commits
Author SHA1 Message Date
Peter Steinberger 6652f7eac8 refactor: remove Tasks and TaskFlow runtime (#159179)
Remove Tasks and TaskFlow runtime, APIs, CLI, SDK surfaces and panels after the Cron, session, native execution and media completion ownership cutovers. Preserve stored rows and import provable legacy native assignments through Doctor; ambiguous ownership stays untouched with a warning.

Follows #158221, #158217, #158225, #158222, #158702 and #158776. Related: #156532. Task-specific public APIs retire immediately; retained responsibilities use their existing owners.

Maintainer-authorized administrative landing after full CI run 36312986498 attempt 2 passed on 274595e2, with subsequent actual conflicts reviewed and focused checks passing. Current PR CI preflight hits the 64 KiB changed-path metadata limit before tests (run 36335042695); its duplicate security-review status mirrors that planning failure. Review and scoped proof are recorded in the PR. Published 9.4 native import is proven; remaining native completion and 9.4 rollback witnesses are explicitly unproven.
2026-09-27 10:40:29 -07:00
Peter Steinberger 8b16e5328e fix: prevent temporary-file exhaustion from SQLite coordination (#157413)
Use transactions on the actual SQLite state and device databases for ordinary writes. Remove redundant coordination databases, transport, and exclusion layers while preserving bounded process ownership for startup, schema work, and offline maintenance.

Tie test and QA scratch retirement to settled workers and native resources, preserve active plugin captures, and join SDK declaration compiler processes before synchronous semantic rendering.

Validation: main-tier CI on 5e731c1f64 had 144 successful jobs and one Windows ACP initialization timeout. Qualified unchanged replay 36314027585 passed all 896 tests with the original 48-file order, six projects, toolchain, and deadlines. The original timeout remains unexplained and recorded in the PR. Reviewed main-conflict integration through 39caa592ef passes focused SQLite, Doctor, image, and Cron proof plus affected typechecks and lint. No accepted actionable independent-review findings remain.

Squash landing of #157413 under explicit maintainer authority to resolve logical main drift and admin-merge using the completed CI evidence. No PR-specific schema or public configuration migration.
2026-09-27 05:30:41 -07:00
Peter Steinberger 1e6f1ea508 fix(browser): existing-session Chrome MCP needs Node when OpenClaw runs on Bun (#159422)
* fix(browser): run managed Chrome MCP on the current runtime

Existing-session profiles launched the packaged Chrome DevTools MCP server
through a real Node, so a Gateway on Bun either spawned Node or failed the
attach when none was installed. Start the pinned server with process.execPath;
Node installs keep the same executable, and custom mcpCommand values are
unchanged.

Keep Bun's transpiler cache out of the native-host e2e HOME snapshot and
document the browser subprocess runtimes, including the Windows node.exe
requirement for native messaging registration.

* chore(browser): drop stale Chrome MCP Node resolver trigger and 1.8 note

* ci(browser): run the Chrome MCP contract on the pinned Bun fork

The macOS and Linux desktop apps run the Browser plugin only on the
OpenClaw Bun fork, and the managed Chrome MCP server now follows the host
runtime. Add a contract-bun job that runs the real-Chromium contract files
and the launch-option test under OPENCLAW_VITEST_RUNTIME=bun on the
checksum-pinned setup-test-bun build, and rerun it when that pin changes.
The Node contract job is unchanged.

Also correct the patch maintenance note, which still said Browser starts
the packaged CLI with Node, and describe the Bun job in the CI docs.
2026-09-27 06:59:15 +00:00
Peter Steinberger c5b5d5ac95 perf(crabbox): shrink source-mirror allocation critical section and wait briefly instead of cold fallback (#159195) 2026-09-26 22:19:21 +00:00
Peter Steinberger 12bc123ec9 test: stabilize flaky fixtures (batch f036) (#159046)
* test(gateway): stabilize CLI question authority fixtures

Align the webchat fixture's runtime registry with its disabled-plugin config.
Shared channel stubs otherwise load bundled message adapters during tool
resolution, delaying the test deadline and letting stale teardown interrupt
the following case.

Proof: both reported cases passed 10 isolated runs; the complete 13-case file
passed twice. Formatting, typechecking, targeted lint, and P2 autoreview
passed. check-changed hit only Knip ETIMEDOUT on both permitted attempts.

* test(slack): stabilize auth monitor fixtures

Align supplied and ambient fixture config to avoid cold bundled-plugin discovery. Own and join dispatch work before resetting shared state, and wait on Bolt readiness events. Control the stalled-auth deadline through real request and socket-close events, with cancellation-aware cleanup and fixture-owned database setup.

* test(gateway): stabilize mock provider readiness

Wait for the existing bound-port announcement on an OS-assigned port instead of racing the implicit one-second startup poll. Preserve the real health check, cancellation, cleanup, and stream assertions. The final full-shard run passes both streams and global run observation.

* test(commands): stabilize doctor preflight fixtures

Scope real plugin discovery to each fixture and prepare the compiled Discord package needed by config migration coverage. Keep cold unrelated plugin imports outside the existing test deadlines.

* test(cli): stabilize startup and broadcast fixtures

* test(scripts): stabilize Android qualification fixture

* test(auto-reply): stabilize SCP cancellation fixture

* test: preserve existing CLI runtime shard budget

Keep the broadcast fixture stabilization but drop the startup-only build prerequisite that pushes the retained CLI runtime cohort beyond its existing prediction bound. Preserve main startup behavior and all bounds. Include Doctor preflight in its exact runtime ownership expectations.
2026-09-26 18:33:26 +00:00
Peter Steinberger 614aa3acff perf(build): avoid duplicate native declaration transforms
Native SDK preparation transformed declarations separately for diagnostics,
then repeated preflight and transformation during in-memory emission. Keep
configuration and requested semantic validation, collect declaration errors
from EmitResult, and reject errors or skipped emission before publication.
Remove the unused includeDeclaration diagnostic option.

Measured cold Node 24 preparation fell from 156.294s to 89.817s; sampled
process-group memory fell from 8.845 to 6.961 GiB. The existing 300-second
limit and Go memory settings are unchanged. This removes proven duplicate
work; it does not conclusively reproduce the historical CI timeout.

Proof: real native tests reject TS4094 and lazy-global TS2318 in both
modes, reject TS2322 in all mode, and accept valid declarations. Focused
suite: 14 passed/3 platform skips, 6.176s wall. Sibling preparation and
tsdown integration: 52 passed/7 platform skips. Changed-file checks,
types/lint, and final independent review through P2 pass.

The native API global-diagnostics handler already forces semantic checking
before collecting fileless diagnostics; source inspection and real API
probes resolve the apparent late-global diagnostic gap. Declaration member
order and synthesized readonly modifiers vary across unchanged original
compiler runs, so generated byte equivalence is not claimed.
2026-09-26 10:07:01 -07:00
Peter Steinberger 813169e282 fix: allow builds and lint in nested checkouts (#158674)
* fix: allow builds and lint in nested checkouts

Use the pinned native TypeScript 7.1 API to bound declaration resolution before ancestor installations can influence build and lint inputs. Keep portable input receipts, mutation fences, cache validation, and child cleanup, while preserving the SDK revision renderer dependency contract.

* fix: admit pinned prerelease native compilers

Accept the exact TypeScript prerelease version used by bounded declaration emission before trusted frozen-client parsing. Preserve lock, package, native executable, ownership, and integrity validation, with explicit range and tag rejection coverage.

* test: include compiler worker in artifact ownership fixture
2026-09-26 11:19:13 +00:00
Peter Steinberger ae25401879 perf(crabbox): reuse per-worktree source mirrors for capsules (#158681)
* perf(crabbox): reuse per-worktree source mirrors for capsules

* perf(crabbox): retain 32 source mirrors
2026-09-26 07:57:17 +00:00
Peter Steinberger 430ea3c671 perf(gateway): prewarm first Control UI requests while idle (#158555)
* perf(gateway): prewarm first-use chat paths while idle

* fix(gateway): validate idle prewarm handler lookup

* test(gateway): normalize idle prewarm fixture paths

* test(gateway): narrow prewarm call order assertion
2026-09-25 22:04:51 -07:00
Peter Steinberger 23ebaf9ced fix: keep native PR checks on the captured main base (#158368)
* fix: keep native PR checks on the captured main base

* test: align native gate fixtures with the captured base

* test: include native gate regression in planner expectations

* test: verify captured gate and publication snapshots
2026-09-25 17:11:36 -07:00
Peter Steinberger e8378618c9 fix(test): batch infrastructure tests in local full runs (#158197)
* fix(test): batch infrastructure tests in local full runs

Distribute the isolated infrastructure and host SQLite test inventory through bounded batches in the existing full-suite scheduler. Preserve exclusions, deduplication, worker limits, and focused and watch routing.

* test(install): isolate global npm configuration in version fixtures

Use a controlled absent global config inside the fixture home so the
release helper does not query the deliberately narrow npm stub. Keep
predecessor selection, fresh-install behavior, and expected exits intact.
2026-09-25 12:55:43 -07:00
Vincent Koc 2d94121bb0 feat(perf): separate session and first tool resource costs (#157744) 2026-09-25 16:04:46 +08:00
Peter Steinberger 510d72b2ef perf(test): reduce Bun UI test time and memory growth (#156220)
Pin the reviewed Bun fork with the corrected WebKit string bounds checks, remove the CSS tokenizer workaround, and reduce native worker, fallback, browser and fixture overhead while preserving all assertions and Node GC coverage.

The complete matched Linux comparison preserves 1,494 files, 25,127 passing cases and four skips. Bun reduces summed shard command time by 3.60% and the slowest shard by 1.18%. The unsharded run passes within the unchanged 10 GiB sampled-PSS guard. Full release verification retains both runtimes.
2026-09-24 19:51:28 +00:00
Vincent Koc 08707779a2 feat(perf): qualify plugin cold-import resource measurements (#157071)
* feat(perf): qualify plugin cold-import resource measurements

Record importing-process CPU and peak RSS with signed baseline deltas, source/build/runtime identity, awaited completion, and terminal cleanup qualification. Document the cold-import scope and retain explicit gaps when screening evidence is unavailable.

* fix(perf): preserve report paths alongside portable screening entries
2026-09-25 01:31:51 +08:00
Peter Steinberger 53068e7f5c fix(bench): retain failed gateway concurrency attempts (#138016) 2026-09-24 06:01:25 -07:00
Peter Steinberger c8eab36020 refactor: run plugins and tooling without TypeScript 6 (#156829)
* refactor: remove TypeScript 6 from plugin runtime and tooling

Keep source plugin loading on Jiti and native module transforms, move development analysis and declaration builds to TypeScript 7, and preserve captured loader and input ownership contracts. Scaffolds compile to the same entry path without shipping a compiler in production.

* refactor: use native checker for restart preflight detection

* fix: keep test-directory docs out of native helper scans

* fix: preserve native compiler tooling across CI runtimes

Keep compiler-backed tests on the supported Node transport, preserve declared Windows aliases and partial-source analysis, and bind relocated SDK reports to their installed compiler. Retain strict package input admission and the existing fixture assertions.

* test: compare messaging guard diagnostics without sorting

* fix: bound native tooling memory and preserve bootstrap loading

* fix: bound native declaration builds with tsdown scheduling

* fix: retire compiler-only helpers from installed packages

* test: migrate routing import scan to native parser

* test(ui): wait for recovered model catalog receipt
2026-09-23 22:34:20 -07:00
Peter Steinberger 01b253c681 refactor: retire pre-June config and upgrade test support (#156859)
* refactor: retire pre-June config and upgrade test support

Retire obsolete Doctor keys and their runtime fallbacks. Older configurations use the documented 2026.9.5 Doctor bridge; current upgrade verification starts at June 2026 while historical receipts remain readable.

* fix: preserve retired config when the upgrade bridge is skipped

* test: align upgrade fixtures with retained migration contracts
2026-09-23 19:26:23 -07:00
Peter Steinberger c93c3e0b55 fix(ci): preserve first failures through release validation
Live, Docker, channel and release wrappers could repeat failed validation
or downgrade failed jobs automatically. Run each test invocation once,
remove known-flake redispatch, and require an explicit recorded waiver
when the release policy permits one.

Wait for the original plugin publisher to settle before reporting failure.
Keep bounded artifact-download recovery before tests. Read published
v2026.9.6 empty retry metadata without restoring executable allowances or
automatic waivers, preserving the sealed plan digest. Use the existing
fresh-read owner for release-priority cleanup.

Testbox owner/sibling proof and three CI-config replays passed. The two
freshness regressions passed 20 repetitions. Published evidence retained
its original digest; nonempty retry metadata remained rejected. The stale
Testbox assertion now matches its already-landed four-hour lease; this
change raises no runtime, test, hook or watchdog budget.
2026-09-23 18:27:19 -07:00
Peter Steinberger 36baa2cd98 fix(test): preserve the first Vitest timeout
The project runner replaced timed-out configurations with another attempt
and could turn their failed hooks into a green job. CI run 35928401414,
job 107409413294, masked seven settlement-hook failures this way.

Remove replacement dispatch and its expanded retry deadline. Keep the first
watchdog failure even when a child exits zero, retain incomplete reports,
and preserve process/cache cleanup.

Proof: the temporary fail-first test failed the real CI shard entry point
with exit 143 and one attempt. The runner owner passed 20 standalone runs
and three CI-config replays on Testbox; shared-helper importers passed.
2026-09-23 18:27:19 -07:00
Peter Steinberger 37887f2e6c fix: prepare native worker code before selected tests start (#156489)
* fix(test): prepare native workers before selected test cases

* test: normalize expected absolute selection paths

* fix(test): preserve Windows selection and controlled worker admission
2026-09-23 15:53:29 -07:00
Peter Steinberger a4fbf649cd fix: preserve live Control UI timeout diagnostics (#156659) 2026-09-23 10:35:51 -07:00
Peter Steinberger 7dbfab8c2c chore(deps): refresh dependencies with a seven-day cutoff (#156363)
* chore(deps): refresh dependencies with a seven-day cutoff

* fix(deps): preserve runtime and tooling contracts after upgrades

* fix(deps): align fixture lifetimes and preserve Unicode contracts

* fix(ui): publish goal rejections and align integration fixtures

Publish rejected goal actions through the existing renderer lifecycle. Start the Session Share service in integration fixtures, preserve same-job workflow authority, and distinguish pnpm launcher escalation from detached cleanup ownership.

* test: follow Corepack ownership and await navigation handoff
2026-09-23 17:35:48 +00:00
Vincent Koc 59a734b735 feat: export committed plugin inventory for resource coverage (#155775) 2026-09-23 09:14:59 +08:00
Vincent Koc 4bc30cabb7 feat(test): share the measured Gateway host across plugin workloads (#155830) 2026-09-23 03:13:10 +08:00
Peter Steinberger 533d301e21 fix(test): prevent Gateway server suite heap exhaustion (#155871)
* fix(test): bound Gateway server process lifetimes

* fix(pr): include workspace Git helper in wrapper sources

* chore: incorporate upstream wrapper inventory repair

* fix(pr): include config write finalization in wrapper sources

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-22 11:26:37 -07:00
Vincent Koc 96cb48b10e feat: calibrate Gateway plugin resources through retirement (#155792)
* feat: calibrate Gateway plugin resources through retirement

* fix(test): reject forced descendant cleanup in resource proof
2026-09-23 00:08:15 +08:00
Vincent Koc 50ea1795fc feat: compare Kitchen Sink Gateway resource costs (#155734)
* feat: compare Kitchen Sink Gateway resource costs

* fix(test): keep resource delta helper private

* fix(test): isolate resource cases and retain failure receipts

* test: rebalance Gateway worker typecheck roots
2026-09-22 14:40:32 +00:00
Peter Steinberger 9dc3d48e78 improve(ci): speed up compatible Control UI tests with Bun (#154585)
* ci: run compatible UI tests on Bun with isolated transform caches

* perf(ui): narrow Bun tokenizer workaround and skip zero-width styles

Keep all JIT tiers enabled while preventing the ordered CSS-tokenizer runaway at its end-of-file predicate. Avoid redundant style resolution for zero-width marquee labels while preserving resize recovery and reveal cleanup.

Keep PR runtime partitions, native shards, worker budgets, assertions, and release Node/Bun coverage intact. Repair the fixture dependency URL and make the marquee regression establish keyboard focus modality explicitly.

* perf(test): split sidebar cases across UI workers

Keep the existing 484 sidebar cases in four topic entrypoints so native UI sharding and worker scheduling can share their cost. Move mock and global cleanup into the common sidebar fixture, scope footer cleanup to its cases, and preserve the complete cache-warmer collection.

* perf(ci): warm Bun UI caches and defer costly FTL compilation
2026-09-22 02:28:49 -07:00
Peter Steinberger 4aa466c3da fix(ui): run build validators without compiler subprocesses (#154675)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-21 21:04:26 -07:00
Peter Steinberger c69b8b9868 fix: recognize verified team admins as channel owners (#153508)
* fix: recognize verified team admins as channel owners

Resolve channel owner authority from SQLite profile identity links and current login grants, with immediate revocation across deferred work. Keep Gateway and bundled plugins on one native SDK graph and replace the related process-global authority registries with instance-owned capabilities.

* fix: preserve channel owner authority through deferred work

Authorize Discord commands before ACP preparation and retain the original live owner through backend effects and updater handoffs. Normalize direct notice recipients through channel contracts. Complete native test-loader and instance-runtime fixture coverage, including final-effect and revocation regressions.

* fix(plugins): retain host SDK access in captured workers

Link captured plugins to the selected host package for worker isolates, preserving native SDK identity through retained generations and recovery. Align CI fixtures with instance-owned runtimes and join owned asynchronous work in teardown and Telegram buffering tests.

Validation: native worker regression fails before the fix and passes across native/legacy and source/dist hosts; 325 core tests, the full 3121-test Slack suite, targeted channel tests, protocol generation, Android lint, changed checks, and independent review pass.

* fix(runtime): keep snapshot cleanup inside owned directories

Treat captured SDK host-package links as removable leaves, preserving ownership records until snapshot data is gone. Preserve sanitized readiness subprocess failures and exercise Doctor through its complete isolated runtime on clean installations.

* fix(plugins): keep lazy runtime ownership metadata local

Preserve deferred Gateway facets with instance-owned proxy metadata and retain redacted readiness failure diagnostics on the current subprocess result owner.

* fix(auth): retain live owner authority through command effects

Carry the admitted administrator assertion through command dispatch, ACP controls and metadata commits, config and allowlist writes, plugin consent and installation, MCP mutation, and restart preparation. Preserve accepted-operation settlement and condition restart acknowledgement cleanup on its owned revision. Prove allowed administrators, forbidden senders, revocation and reassignment through real handler and persistence boundaries.

* refactor(restart): require owned revisions for sentinel cleanup

Remove the unused unconditional clear facade and storage branch. Keep revision-floor migration, durable failure reporting, and updater consumption proof on the canonical conditional-clear operation.

* test(auth): align owner regressions with fixture lint contracts

* refactor(auth): simplify channel owner and runtime authority

Resolve linked channel administration from the current Team role policy, retaining identity-grant fallback only for roleless installations. Consolidate Gateway generation state into its lifecycle owner, simplify Discord native routing and remove redundant loader and ingress state. Preserve current-authority checks before writes and required cleanup after accepted operations.

* test(auth): compare public generation state values

* refactor(auth): keep authority fixtures and handoff types with their owners

Extract coherent fixture builders and internal updater types to keep large files from growing. Correct the task-identifier test import to its codec owner and remove the unused internal route-policy export. Preserve all runtime behavior, assertions, deadlines and revision-owned sentinel cleanup.

* fix(channels): preserve native conversation scope in ingress authority

* fix(imessage): bind ingress after reply ID mapping

* fix(test): preserve scoped filesystem and channel admission contracts

* test(fleet): share stopped container state fixture

* test(fleet): type stop mock against the container contract

* fix(auth): retain current owner authority through deferred effects

* refactor(auth): keep authority fixtures and helpers with their owners

* fix(ci): remove duplicate database worker test entry

Retain the existing worker.runtime test entry so compact CI planning includes every storage-state test once. The duplicate introduced in d2c8c34af2 made preflight reject all split timing generations for this owner.

Reproduced the exact preflight error before the repair. Hybrid, GitHub, and Blacksmith planning now preserve all 660 unique storage-state files. The 217 planner/config tests, selected changed-file checks, formatting, and diff checks pass.

* refactor(auth): prepare profile authority in SQLite workers

Move channel identity and affected profile writes onto the existing worker owners, with current authority at commit and explicit rollback recovery. Bind native Telegram commands to verified ingress and retain shared-owner administration.

* fix(auth): preserve owner checks and released ingress callers

Forward Telegram authority through configured backend preparation and retain released ingress helper provenance through the existing plugin instance owner. Keep identity result types in the leaf contract and repair worker-aware test routing and fixtures without weakening policy assertions.

* fix: correct ingress names and database test ownership

Keep supported SDK ingress adapters while distinguishing internal policy operations. Assign broker-dependent HTTP suites only to the Gateway fork owner, preserve sorted test discovery, reuse chat registration fixtures, and declare the dynamically loaded Telegram test entry.

* test(cli): use prepared runtime for MCP probe exit

Exercise the real CLI entrypoint instead of compiling source-backed SQLite workers inside the command deadline. Keep the 30-second deadline and the exit, JSON, and named diagnostic checks.

* test(codex): check native worker termination at teardown

Observe native Worker thread IDs after fixture cleanup instead of equating
thread exit with asynchronous resource-destroy notification. Keep the
allocation assertion and existing cleanup; do not wait for idle retirement.

The three-case file passes in 48.495s. Omitting only its harness disk-worker
drain fails immediately on a live thread in 30.715s. A Node 24.19 control
observes threadId -1 while the async destroy notification is still pending.
Managed review is clean through P2. The earlier CI worker identity remains
unproven; this is a test-contract repair, not a production leak claim.

* test: settle identity fixtures and route database cleanup

Wait for actual GitHub metadata entry and settle both identity requests on failure. Run the session-store consumer in the existing database fork owner so native retirement can use the host broker.

* test: settle admin fixtures at their owning boundaries

Await canonical asynchronous MCP OAuth reads and the existing Gateway attachment completion. Keep avatar work independently gated and preserve all permission assertions. Move ingress and callback fixture helpers into the existing support owner to keep the health suite within its line-growth limit.

* test(worker): share the compiled SDK graph in crash fixtures
2026-09-21 19:56:45 -07:00
Peter Steinberger bf9611abc4 fix(test): reuse caches across serial project runs (#155052)
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-21 17:23:30 -07:00
Peter Steinberger 3a632e1dd0 test(update): cover multi-provider published upgrade turns (#155158)
* test(update): cover multiple providers in upgrade survivor

* test(update): use supported live survivor model configuration

* test(update): include command helper in isolated assertion fixture

* test(update): align survivor credential fixture assertion

* test(update): refuse live selections for frozen survivor runners
2026-09-21 14:02:12 -07:00
Peter Steinberger ed5937fbd9 improve: profile concurrent Gateway sessions with live OpenAI (#154845)
* improve: profile live Gateway concurrency

* fix: align Gateway benchmark with CI contracts
2026-09-21 13:33:16 +00:00
Peter Steinberger 65485f6ade fix(browser): preserve references across waits and renderer changes (#154215)
* fix(browser): preserve references across waits and renderer changes

Pin and bundle the patched Chrome DevTools MCP 1.8.0 runtime so source and npm installs receive the same identity repair. Verify packaged bytes and exercise real browser waits, cross-origin frames, stale-reference rejection, and recovery.

* fix(browser): declare bundled MCP dependency ownership

* test(browser): remove unused tarball fixture imports

* ci(browser): remove retired MCP download prewarming

* test(browser): pack MCP bundles with portable npm runner
2026-09-20 22:05:49 -07:00
Peter Steinberger a94962e9ca chore(ci): run compatible PR tests on the pinned Bun fork (#154340)
* ci: run compatible PR tests on the pinned Bun fork

* fix(ci): include Bun runtime helper in PR wrapper extraction
2026-09-21 04:08:42 +00:00
Peter Steinberger a4e3a5d5f8 fix(ci): restore Vitest cache reuse (#154121)
* fix(ci): restore Vitest cache reuse

* test(ci): keep cache fingerprint fixtures strictly typed

* fix(test): preserve UI dependency identities with optimization
2026-09-20 18:12:59 -07:00
Peter Steinberger aed59efc4b refactor(code-mode): execute JavaScript with typed API discovery (#154001)
* refactor(code-mode): execute JavaScript with typed API discovery

Keep schema-derived tool declarations available to agents while removing TypeScript compilation, optional preflight, and language selection from Code Mode. Retire the saved languages setting through shared Doctor/startup migration, preserving activation and limits. Existing TypeScript cells must be rewritten as JavaScript.

Related: #153889

* fix(code-mode): complete JavaScript cutover checks

* docs(config): regenerate JavaScript-only Code Mode baseline

* test(code-mode): match public names in live validation errors

* test(code-mode): avoid shadowing the selected call

* test(code-mode): allow fixture rereads in live evidence
2026-09-20 15:57:08 -07:00
Peter Steinberger 7fc68b8a87 fix: prevent sibling installs from breaking test runs (#154096)
* fix(test): isolate dependency files across source checkouts

* test: preserve Corepack cache in install isolation fixture
2026-09-20 15:19:47 -07:00
Peter Steinberger 8846e9e61d fix: preserve restart cleanup and initial chat positioning (#153267)
* fix: preserve restart ownership and chat position during startup

Keep foreground and update-owned restarts within their existing capped cleanup deadline instead of assuming an enclosing service will replace them. Anchor the chat position rail after its first visible-message measurement. Stabilize Doctor and memory SQLite fixtures and assert the actual Codex process-notification ordering contract.

* test: exercise doctor state isolation on Windows

* fix(ci): wait for exiting Darwin process groups

* fix(tasks): keep superseded progress from failing readers

* fix(tasks): preserve publication ownership through supersession

* test: acknowledge delivery fixtures with their claim owner

* test(qa): join parent acknowledgement before terminal assertions

* test(tasks): arm scan barrier after starting mutation

* test: retire task event owners at fixture boundaries

* test: share port claims and await hover recovery
2026-09-20 02:52:09 -07:00
Peter Steinberger fe318b3530 fix: preserve Node debugger attachment on SIGUSR1 (#153462)
* fix: preserve Node debugger attachment on SIGUSR1

Use SIGUSR2 for Gateway restarts and reserve SIGUSR1 for Node's inspector.
Update internal callers, diagnostics, QA harnesses, and operator docs.

Route current unmanaged Gateways through owner-targeted restart RPC while
retaining SIGUSR1 only for verified legacy Gateway locks during upgrades.
Refuse self-signaling embedded Unix hosts without a restart handler.

Manual restart scripts must switch to SIGUSR2; prefer openclaw gateway restart.

* test: follow prepared runtime replacement owner
2026-09-20 00:34:04 -07:00
286487d234 fix(ui): keep attached context out of message text (#152539)
* fix(ui): keep attached context out of message text

Preserve bounded send-time reference snapshots separately from authored text through queued sends, retries, transcript display, and edit actions. Keep raw context inspectable behind a disclosure without changing its authority.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): complete context attachment CI coverage

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(state): align custody proof with worker acquisition

Apply the already-landed test correction from bfec65a2a0. Release the late competing host owner before awaiting the worker, while preserving authority checks, operation outcomes, and persisted-state assertions. Reproduces and repairs both failures in CI job 105859785996 without production changes or longer timeouts.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(ui): keep simulated history fling events contiguous

Drive the final contact movement, release, and initial inertia in one browser task so RPC latency cannot split the intended continuous gesture. Preserve total movement, stationary-touch coverage, omitted scrollend, and every-frame anchoring assertions.

* test(ui): avoid shadowing the momentum fixture parameter

* test: fix native shutdown and session fixture races

Keep Sparkplug compilation synchronous in test Node processes and propagate the shared argv policy to Vitest fork workers. This avoids a proven compiler/GC deadlock during process.exit without changing production shutdown, assertions, or deadlines. Join background session disk measurements before closing and handing off SQLite fixtures.

* test: fix compiler policy assertion and rebalance UI typechecks

Retain the independent Sparkplug shutdown policy when opting into Maglev. Split chat test roots into an appended shard without changing coverage or root limits.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-09-19 19:19:31 -07:00
Peter Steinberger c53eaf5509 improve(ui): load older chat history with less rendering work (#153245)
* perf(ui): reduce work when loading older chat history

* fix(ui): settle history anchors at scroll boundaries

* fix(ui): keep focused transcript rendering stable

* test(state): isolate retired cleanup at its store boundary
2026-09-19 18:31:56 -07:00
Peter Steinberger b183809e02 fix(ui): reduce layout work when loading chat history (#153137)
* fix(ui): reduce layout work when loading chat history

* style(ui): make optional measurement result explicit
2026-09-19 13:41:11 -07:00
6f36619571 fix(imessage): keep queued answers attached to their questions (#150626)
* fix(imessage): keep queued answers attached to their questions

* fix(imessage): keep queued reply targets with correct provenance

* test(agents): isolate CLI image capability discovery

* test: await asynchronous owner completion

* test(cron): await deferred session cleanup

* test: await lifecycle settlement in CI fixtures

* test(codex): compile catalog workers before fixture requests

* test(codex): keep worker declarations out of root builds

* test: use Git transport for wrapper fixture clones

---------

Co-authored-by: gennadyclaw <275141878+gennadyclaw@users.noreply.github.com>
Co-authored-by: Jason (Json) <263060202+fuller-stack-dev@users.noreply.github.com>
2026-09-19 13:50:15 -06:00
Shakker d5b46dfea5 feat: recover abandoned Crabbox source staging (#152006)
Add local inspection and recovery of abandoned Crabbox source capsules after verifying writer settlement, native claims, retained source, and diagnostics.
2026-09-18 22:11:31 +01:00
Shakker 9930cf44a7 fix: finish Crabbox wrapper cancellation cleanup (#151862)
Finish supported Crabbox wrapper cancellation before restoring retained lease ownership, preserving diagnostics, and removing disposable source.

Fixes https://github.com/openclaw/openclaw/issues/151804.
2026-09-18 17:38:42 +01:00
Peter Steinberger 5e0fba7b86 fix(test): retain Node for Node-owned tooling under Bun (#151772)
* fix(test): keep script erasability checks on Node

* test(tooling): preserve workflow Node heredoc ownership
2026-09-18 07:53:41 -07:00
Peter Steinberger efe55d7162 fix: preserve browser test failures when diagnostics stall (#151555) 2026-09-18 01:01:38 -07:00
Vincent Koc eb32f229ef improve(bench): verify Gateway work across CPU affinity (#149702)
* improve(bench): verify warmed Gateway work across CPU affinity

Punchcard-Session: brisk-summit-brook-mr

* fix(bench): bind inference markers through runtime context

Punchcard-Session: brisk-summit-brook-mr

* fix(bench): clean up failed Gateway launches

Punchcard-Session: brisk-summit-brook-mr

* test(perf): separate warmup lifecycle evidence from measured turns

Punchcard-Session: clear-workshop-brook-w2

* docs(perf): describe agent warmup checkpoints

Punchcard-Session: clear-workshop-brook-w2
2026-09-18 12:45:36 +08:00
Peter Steinberger db98ebc771 fix(test): drain Codex fixture workers and diagnose teardown stalls (#151225)
Join canonical agent and shared-state SQLite cleanup in Codex fixtures and drain reusable disk-budget workers at file teardown. Concurrent drains share one completion so accepted scans finish and later worker reuse stays intact. Runtime lifecycle cleanup uses the same owner.

Add bounded, redacted native-worker diagnostics for extension-fork teardown stalls while preserving the existing failure deadline and Vitest termination and exit-joining ownership. No dependency patch, retry, schema, or public configuration change.

Exact-head CI run 35289664323 passed with zero pending checks. Native-resource regression, real-process shutdown scenarios, and 20 Linux pressure runs verify cleanup and unchanged failure outcomes. The original intermittent timeout was not reproduced verbatim.

Related: #150819. The voice-call fixture repair remains in #151187.
2026-09-17 17:45:52 -07:00