8225 Commits
Author SHA1 Message Date
Vincent Koc d024aa1d02 fix(tooling): split root test types into serial graphs (#160098)
Split root-test checking into four serial projects while preserving the canonical CI inventory, complete source coverage, ambient declarations, and separate incremental caches.

Validated with four cold compiler runs under a 7 GiB kernel cap, focused tests, exact-head required CI, and independent review.

Related: https://github.com/openclaw/openclaw/issues/160010
2026-09-28 12:46:46 +07:00
Peter Steinberger 1ca6a5d0a8 fix(pr): honor conditional code-owner review requirements 2026-09-27 22:39:21 -07:00
Peter Steinberger 45b00bdd13 fix(release): run scheduled main validation through the SHA-pinned helper (#160106)
* fix(release): run scheduled main validation through the SHA-pinned helper

The nightly dispatched full-release-validation.yml with ref main, so the parent
dispatched its children from mutable main and refused once main moved
("Child workflow ref main moved to ..., expected ...; refusing dispatch"), as in
runs 36293217885 and 36216720090. Check out the scheduled main SHA and run
pnpm ci:full-release --sha <sha> --workflow-sha <sha> with the existing stable,
soak, reuse, rerun_group=all and main-qualification inputs, so the helper
dispatches from an immutable release-ci/<sha12>-<id> transport ref, watches the
parent, verifies evidence, and cleans up its refs.

Run every 3 hours (7 */3 * * *) under one non-cancelling concurrency group so
readiness tracks landing commits without overlapping runs.

* fix(release): give the scheduled validation watcher the parent waiter's runner and 720-minute budget
2026-09-27 22:37:29 -07:00
Vincent Koc e07ec8c700 fix(tooling): admit semantic checks within host memory budgets (#160094)
Related: https://github.com/openclaw/openclaw/issues/160010

## What Problem This Solves

Independent lint and compiler processes can each fit their own heap target while collectively exhausting the host.

## User Impact

This adds the shared admission owner for subsequent compiler and lint activation; no existing command uses it yet. Callers receive one host/account slot, a kernel process-tree limit based on current memory headroom, and a 15-minute queue-plus-execution deadline.

The owner requires verified Linux containment. Unsupported platforms or insufficient/unknown memory headroom return an actionable refusal instead of starting an unbounded process. Compiler/lint command activation and platform routing are separate PRs.

## Why This Change Was Made

The kernel limit from https://github.com/openclaw/openclaw/pull/160024 bounds one process tree; this owner prevents simultaneous checks across worktrees from independently consuming the same budget. It uses the existing fs-safe lock contract and process-memory reader, with the OS account identity rather than task-specific HOME.

Admission follows artifact ownership, measures headroom after waiting, caps the aggregate tree at the smaller of 8 GiB or half of usable capacity/headroom, and refuses below 512 MiB. It records the kernel scope identity before launch and retains ownership when cleanup cannot prove tree extinction. Cancellation remains owned through asynchronous release; soft Go overrides remain intact.

## Evidence

- [Blacksmith Testbox proof](https://github.com/openclaw/openclaw/actions/runs/36373081283) exercised real filesystem lock contention, canceled/expired admission, late acquisition, command snapshotting, capacity/headroom refusal, non-Linux refusal, receipt ordering, and retention after uncertain cleanup. Kernel launches are mocked in this focused owner suite; actual kernel enforcement was qualified in the merged parent.
- Strict script/root test types, targeted typed lint, formatting, and whitespace passed for the helper and profiler candidate. An independent P0–P2 review found no actionable finding.
- This PR cherry-picks the tested helper unchanged onto the merged kernel/cancellation parents. The three dependency-owner modules are byte-identical to the proof base. Hosted CI will validate this exact head.
- Production/tooling: +166/-0; tests: +321/-0. The growth supplies the missing cross-worktree admission/lifecycle owner. There is no runtime/config migration or new dependency.

CI correction: exact-head check-lint identified nine missing control-flow braces in the new test file. Commit `e590faf299ddb75e36b1a8e503121807785bb1ba` adds those braces; conditions and async sequencing are unchanged. Targeted formatting, whitespace, and independent P0–P2 review pass. Fresh CI provides the updated lint proof.

Measured test cost at `e590faf299ddb75e36b1a8e503121807785bb1ba`: the exact helper and test bytes were run on [Testbox](https://github.com/openclaw/openclaw/actions/runs/36376377264) from the profiler child revision, with `--maxWorkers=1`. All 26 cases passed; file test time 1.331s, Vitest wall 1.84s, complete test command 2.69s. Dedicated test execution adds 2.69 CI wall seconds, excluding shared checkout/install/setup. This addresses the review's test-cost finding and Rank-up move; no source change or repeat review is needed.
2026-09-28 12:34:22 +07:00
Peter Steinberger 57dfbc3142 ci: bound PR test admission and retain canonical metadata 2026-09-27 22:30:48 -07:00
Peter Steinberger 6a50179657 ci: select protected owner coverage for pull requests
Use existing owner maps and runtime transitive imports instead of broad PR
fallbacks, with six fixed smoke files and protected regression coverage.
Keep audited zero-catch suites in the existing PR-exempt tier with direct-edit
and owner opt-in.

Select Windows, UI, build, Docker, and QA families through their owners.
Preserve all moved coverage hourly and in Full Release Verification through
the existing normal CI and Plugin Prerelease owners. Static correctness gates
remain blocking.

Supersedes the RV3 selection work in #158594. Linux owning-config, shared-helper,
selection, and static proof passed with focused corrections; P2 review completed.
2026-09-27 22:30:47 -07:00
Peter Steinberger 6bfe76fcd7 chore(deps): refresh dependencies through September 20 cutoff (#160085)
Refresh OpenAI 7.20.0, Pi TUI 0.86.1, tsx 4.23.15, native TypeScript 7.1.0-dev.20260920.1, Tauri 2.11.6, single-instance 2.4.5, rand 0.10.3, and SimSlim 0.10.0 under the fixed 2026-09-20T18:25:54Z cutoff. Align companion manifests, native locks, Docker tooling, and SimSlim qualification. Preserve existing patches, overrides, the updater fork, and compatibility holds.

Validation includes 303 npm consumer cases, 148 Rust core cases, 63 desktop cases, 86 SimSlim cases, actual Linux container and SDK transport proof, four typecheck lanes, 102 npm lock mirrors, and cutoff/integrity audits. Synthetic terminal comparisons are attached to the PR and verified rendered. Independent reviews are clean through P2.

Land under explicit maintainer approval for proven pre-existing CI failures. Run 36376168824 exposed three unchanged Windows checkout-fixture inventory failures already repaired on main by #160024 (b9cd492ac6). The dependency delta does not touch that workflow/helper/test closure. No green full-CI result is claimed. No third-party PR, release, or deployment.
2026-09-27 22:26:12 -07:00
Peter Steinberger 56376753f8 fix(pr): recognize the current CI failure monitor step 2026-09-27 22:06:03 -07:00
Peter Steinberger 02e1ac8391 perf(diagnostics): add guarded heap snapshots and retention diffs (#160040)
* perf(diagnostics): add guarded heap snapshots and retention diffs

* fix(protocol): regenerate heap snapshot method enum

* fix(tooling): register heap snapshot diff entrypoint
2026-09-28 05:02:58 +00:00
Josh Avant 13cc4e0d39 fix(ios): avoid repeated setup in release qualification (#160025)
* fix(ios): make release qualification lifecycle explicit

* fix(ios): normalize provider receipt timestamps

* fix(ios): align qualification checks with native input and viewport

* ci: refresh iOS qualification after main fixture repair

* fix(ios): prepare release Gateway before simulator boot
2026-09-28 00:01:02 -05:00
Peter Steinberger 54a0ea673b fix(pr): verify attributed merge trees before admission 2026-09-27 21:45:21 -07:00
Peter Steinberger 824982caa6 fix(ci): preserve security authority in baseline failure admission 2026-09-27 21:45:21 -07:00
Peter Steinberger 42c498353a fix(pr): support approved pre-existing CI failures 2026-09-27 21:45:20 -07:00
Peter Steinberger 6fdaf084f6 fix(ci): separate extension test time from runtime preparation 2026-09-27 21:19:56 -07:00
Kimi Yu 98782a01dd fix(codex): recover remote connections during harness replacement (#159466) 2026-09-27 21:11:17 -07:00
Vincent Koc f26303d702 fix(tooling): join canceled artifact ownership waits (#160057)
Join signal-aware artifact waits and release ownership won after cancellation. Preserve the published updater native wait contract.

Validated cancellation races, published updater lock handoff, and exact-head CI.
2026-09-28 12:08:42 +08:00
Vincent Koc b9cd492ac6 fix(tooling): enforce Linux process-tree memory limits (#160024)
Add opt-in aggregate Linux process-tree memory containment to the managed tooling runner. Own the invocation-specific scope through verified cleanup before releasing its resource claim; preserve uncapped caller behavior.

Validated real-kernel OOM, descendant cleanup, signals, cancellation and packaged launcher behavior; focused lifecycle/preload tests and exact-head CI/security gates passed. Related: #160010.
2026-09-28 11:58:07 +08:00
Peter Steinberger ab416e262c ci: route PR verification to hosted runners without adding jobs
Use hosted Linux and Windows capacity for PR verification and its waiting
failure monitor. Reuse the existing Node planner, static packing, Windows
shards, and 90/130/96 compact, total, and active Node caps. Preserve all test
inventory, blocking checks, worker policies, cancellation grace, and red-gate
handoff; keep main/release routing and the backend variable unchanged.

Use the hosted boundary-cache path when physical placement is hosted even if
the logical profile is Blacksmith. Retain existing cache trust restrictions.

Focused Linux proof covers routing, PR control, inventory, changed checks,
explicit boundary lint, workflow validation, and P2. Preserve intervening
main changes to extension-lint packing and known-main-failure classification.
Current wall/queue performance awaits ordinary CI; no proof dispatch needed.
2026-09-27 20:57:14 -07:00
Peter Steinberger 915567dc34 fix(build): allow retrying failed source builds (#160059) 2026-09-27 20:52:35 -07:00
Peter Steinberger 1a8f1d1472 fix(ci): preserve measured worker identity in selected rows
Keep precise file selections in their canonical worker timing policy, so
serial and overlapping command rows do not publish the same timing key.
Use compatible exact subset measurements as admission floors without the
stale full-owner price cap. Preserve execution, coverage and worker limits.

The regression reproduced the original key collision and rejected refit.
Commands 8/8, adjacent precise checks 8/8 and sparse-selection 1/1 passed;
script/root-test types, lint, changed gates and P2 review are clean. The new
case took 258ms; the full commands file took 15.21s locally.
2026-09-27 20:36:57 -07:00
Peter Steinberger 69232a161a ci: hardlink job-local Linux dependency installs
Use hard links for Linux's private workspace pnpm store, including hosted
store-only consumers. Keep external stores, macOS policy, frozen validation,
and lifecycle scripts unchanged.

On the same Linux Testbox, median store extraction plus install fell from
4.442s to 3.351s. The two new recipe cases add 75ms in the full tooling run.

Validation: 846 tooling files and 27,257 tests passed (existing skips only);
323 workflow guards passed on one worker in 62.83s; changed-scope checks,
types, lint, boundary lint, formatting, and P2 review passed.
2026-09-27 20:13:39 -07:00
joshavant 57f1abecc1 test(ci): fix static evidence fixture contracts 2026-09-27 22:08:43 -05:00
Peter Steinberger 6d8d77725f fix(test): retire checkout actors on denied lease reads
The checkout fixture's lease reader only recognized ENOENT as retirement. Windows can return EPERM when the supervisor deletes the lease while an actor reopens it, crashing the sentinel into workflow.log after the Git owner correctly returned 124. The token-reread assumption was introduced by da7d113b90af21b5cc6d355a6f7706ea3912a8e1; 8868f7ed8c later made those reads watcher-driven.

Treat the denied lease as unavailable authority and stop the actor. Preserve other errors, Git exit codes, ownership checks, and cleanup joins. Extend the existing git-exit-124 case to inject the Windows denial during lease-only sentinel shutdown and require an unsignaled zero exit with empty workflow output.

Proof on Blacksmith Testbox, Linux Node 24.19.0, CI=1, the tooling project and CI's four-worker/file-parallel route: unchanged pinned main ce73f2c8f2 passed the seven-file shard; the injected regression failed 3/3 against the baseline fixture. After the fix, 20/20 full-file runs passed (72 tests each), all 3 seven-file shard runs passed (187 passed, 4 existing platform skips each), and sibling coverage passed 614 tests (2 existing skips). Single-worker file cost: 52s wall; no added test cases, sleeps, or timeout changes. check-changed against the pinned base, formatting, and diff checks passed remotely. Native Windows execution was unavailable. Local hooks were disabled under the explicit no-local-checks constraint; review and push are delegated to the lead.
2026-09-27 19:58:18 -07:00
RoboClawandRomneyDa 43d73d77a0 fix(ci): preserve frozen-target managed restart coverage (#160043)
Preserve native-contained managed restart coverage for frozen targets whose committed runtime predates absent-membership recovery. Keep current targets on the strict absent-containment path with both warning receipts and run-ID matching.

The existing verified-source resolver owns selection and explicit sparse acquisition; Docker forwarding and preflight metadata carry the result. Updater, replacement, authentication, serving and survival assertions remain intact. Independent review is scoped-clean, with focused regression, sibling and acquisition proof documented in the PR. Installed-package release qualification remains separate.

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
2026-09-28 02:34:45 +00:00
Peter Steinberger 39373e69f8 chore(deps): refresh dependencies through September 19 cutoff (#159401)
Refresh application, plugin, native, build and container dependencies through the fixed 2026-09-19T16:27:11Z cutoff. Migrate native TypeScript snapshot/printer APIs while preserving compilation and filesystem contracts; retain existing patches and compatibility holds. Document offline container-image preparation.

Include the verified compiler process-census and loading-clock fixture repairs and deterministic warm-history regression. Adopt the canonical production history fixes from #159924 and #159955.

Land under the maintainer's explicit approval to treat proven pre-existing CI failures as non-blocking and repair main afterward. CI36365552098 failed an unchanged Android Compose fixture's asynchronous catalog projection assertion (3518 passed,1 failed); the Android/Gradle tree matches its main parent byte-for-byte. Security and dependency reviews passed. The final rebase preserves reviewed source changes and regenerates only the intentional Node-image documentation fingerprint. See PR159401 for complete validation and the follow-up repair obligation.
2026-09-27 19:33:08 -07:00
Peter Steinberger 83fb6a3aa8 ci: tolerate verified main failures in PR gates
Match complete Node assertions and supported static diagnostics against trusted
hourly main evidence. Require untouched failing files and direct subjects,
current evidence, complete selected work, and an attempt-bound monitor receipt.
Keep PR-owned, incomplete, and unknown failures blocking, and annotate inherited
failures as known main red, owned by main.

This only classifies existing CI attempts. It does not dispatch, rerun, or update
branches. Fork observation is read-only; auto-merge PRs are never cancelled.

Validation: focused local regressions and native Testbox evidence; changed lint,
boundary checks, workflow sanity, and all three Knip export scans passed. The
local full typecheck remains limited by an existing TypeScript version and
workspace-declaration mismatch; no task-file errors remain in its output.
2026-09-27 19:28:00 -07:00
Peter Steinberger decfd9abba ci: capture complete compiler and lint diagnostics
Reuse native compiler and lint process owners to record bounded diagnostic
output and joined leaf/group completion. Opt-in evidence mode finishes ordinary
diagnostic failures while missing, interrupted, or unknown output stays unproven.
2026-09-27 19:27:59 -07:00
Peter Steinberger eedec20b10 ci: record complete Node test shard execution
Finish ordinary failed packed configs when the existing continuation flag is
selected. Publish native completion counts only after selected plans, child
processes, and cleanup finish, so consumers can distinguish assertions from
partial or interrupted execution.
2026-09-27 19:27:58 -07:00
RoboClawandRomneyDa 8232c28ba9 fix(ci): honor loaded stop policy in upgrade fixtures (#160000)
Use the fixture's admitted loaded-unit stop budget for policy inspection and cleanup. Preserve loaded snapshots until reload, retain supervisor custody through failed policy reads, and report failed stops only after observed cleanup. Adapt supervisor test callers without weakening their behavior checks.

Independent and ClawSweeper reviews resolved the outer-stop failure; installed-shim regressions cover policy loss, process extinction and uncertain settlement. Focused policy/cgroup and caller proofs passed. Full local suite setup limitations and exact-head hosted evidence are recorded in the PR. No product runtime changes or completed release qualification are claimed.

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
2026-09-28 02:00:26 +00:00
Peter Steinberger ce73f2c8f2 fix(packaging): include required peers in fresh npm installs (#160015) 2026-09-27 18:44:04 -07:00
Peter Steinberger af17bf3be5 ci: pack full extension lint into three jobs
Keep the same bounded chunks, rules, and serial compiler processes while removing three repeated checkouts, dependency setups, and SDK preparations. Targeted and frozen layouts retain their existing ownership.
2026-09-27 18:35:19 -07:00
Vyctor H. Brzezowski 52fc8af5db fix(ci): keep reply-preview retention proof on Node (#159991)
* fix(ci): keep reply-preview retention proof on Node

Under the bun-compatible PR policy, chat-pane-retained-presentation.test.ts runs in a warm isolate:false Bun worker, where JSC GC timing can leave the released ReplyPreviewMessage reachable only through the test's own WeakRef. Route it to Node with the existing chat-thread and usage-page-details retention proofs.

* docs(ci): list Control UI retention proofs kept on Node
2026-09-27 22:32:12 -03:00
Peter Steinberger 96110f898a fix: recover managed Gateways after updates and repairs (#159577)
* fix: recover managed Gateways after updates and repairs

* refactor(update): simplify service inspection diagnostic

* fix(test): route Doctor live proofs into the infra shard

Include src/commands live tests alongside the CLI update proofs in the existing native-live-src-infra release shard. Extend the routing fixture while preserving full-inventory coverage and provider-filtered fanout assertions.

This is required live-shard inventory maintenance, not a baseline edit to silence a check.

Validation: reproduced the missing Doctor file before the fix; test-live-shard passed 36 tests on each of three local runs (1.03s, 1.06s, 0.89s test time). Full check-changed and 551 package-acceptance-workflow tests passed on Testbox tbx_01m3jmz9qh20mefc5tw4yhmvgr (run 36360539165). Fresh P1 autoreview was clean.
2026-09-28 01:20:31 +00:00
RoboClawandRomneyDa 7c2fd96062 fix(ci): keep upgrade recipes compatible with frozen targets (#159996)
Bind upgrade-survivor Tool Search recipe coverage to the verified frozen target and expose the existing default-off manual Package Acceptance opt-in. Preserve all applicable migration assertions, package/plugin admission and other recipe coverage.

Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
2026-09-27 18:14:01 -07:00
Peter Steinberger 84bf30fecf ci: honor the pinned Node version on hosted runners
Resolve hosted 24.x requests through the workflow's existing same-major
Node pin, preserving explicit compatibility inputs and self-hosted selection.
This keeps runner moves from silently changing the tested runtime patch.
No version value changes.

Linux owning-config and setup guards, changed checks, boundary lint, and P2
review passed. The repository pin remains 24.21.0.
2026-09-27 18:04:49 -07:00
RoboClawandIWhatsskill da6e11cf80 fix(android): align Play Store icon with the app (#159964)
* fix(android): align Play Store icon with the app

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>

* fix(test): cover Bun candidate versions through the smoke entrypoint

Replace the source-string assertion made stale by the candidate-helper extraction with a mismatched tarball case in the existing installation fixture.

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>

---------

Co-authored-by: IWhatsskill <284122573+IWhatsskill@users.noreply.github.com>
2026-09-27 17:54:30 -07:00
Peter Steinberger 1ea24b2dc3 ci: shorten pull request control jobs and completion
Preserve parallel Node and baseline-ratchet admission, with selected ratchets
still required by the final gate. Route eligible hybrid control jobs through
existing Blacksmith capacity and account for hosted fallback rows exactly.
Keep check-plan's cache input separate from the shared plain setup.

Retire the failure monitor when one workload remains while the aggregate
still waits for and validates it. Retain complete boundary checks on the
measured runner class.

Reuse completed Linux owner and worker proof. Focused routing, cache,
parallel-admission, PR-graph, and hosted-budget tests pass, along with lint,
root-test types, workflow validation, documentation links, and P2 review.
2026-09-27 17:49:46 -07:00
Peter Steinberger 018639af3b fix(update): complete already-current updates before service membership guards (#159193)
* fix(update): complete already-current updates before service membership guards

* refactor(update): prepare maintenance warnings in the no-op owner

* fix(update): manage updates when native containment is absent

Keep unreadable membership and genuine service descendants guarded while allowing verified external callers to use the existing managed stop/update/start lifecycle on hosts without native containment.

Record the lifecycle warning at terminal reporting, retain inspected service state for already-current maintenance, and exercise the managed Docker recovery and no-op paths.

* fix(update): bound readiness observation and backup cleanup

Reuse the restart deadline for native readiness reads and managed recovery. Restore the retained package and previous Gateway when startup never becomes ready, and retain obsolete backups with a warning when the cooperative cleanup budget expires.

* fix(plugins): retain source identities across native captures

* fix(update): preserve observed readiness timeout failures
2026-09-28 00:46:48 +00:00
Josh Avant cd7e0ee4ec fix(ios): stabilize native release qualification (#159890)
* fix(ios): use native element waits for composer readiness

* ci(ios): increase release qualification runner capacity
2026-09-27 19:44:26 -05:00
Dallin Romney 7e3745e41c fix(release): keep frozen onboarding validation compatible (#159973) 2026-09-27 17:31:22 -07:00
Peter Steinberger 8b07c92b2b fix(terminal): terminals fail on OpenClaw's Bun build when Node is not installed (#159447)
* fix(terminal): run PTYs on Bun's native terminal

Under Bun on macOS and Linux, spawnTerminalPty launched a Node worker
because Bun closes node-pty's nonblocking tty.ReadStream on EAGAIN, so
terminals failed on Bun-only installs without Node. Replace the bridge
with an adapter over Bun.spawn({ terminal }) behind TerminalPtyHandle and
delete the worker, its IPC protocol, their tests, and the terminalPty
runtime entrypoint. Node and Windows keep node-pty.

The adapter keeps node-pty's contract: TERM/PWD handling, UTF-8 string
output, exit after PTY EOF with a 200 ms fallback, signalled exits as
exit code 0 plus the signal number, and session-tree kills. One ordered
queue replays pre-subscription output and honors pause; the OpenClaw Bun
fork's Terminal.pause()/resume() (openclaw/bun#10) supplies real output
backpressure and is feature-detected. A terminating kill keeps reading to
EOF and drains output before exit so a paused consumer cannot hold up
teardown.

The CI process lane runs the new Bun suite on Bun and keeps its siblings
on Node.

* fix(terminal): use Bun’s native PTY on Windows

Route Bun terminal creation through the native adapter on every platform while preserving Windows batch command lines, environment inheritance, and direct kill behavior. Keep node-pty for Node and preserve existing output lifecycle handling.

Add Windows ConPTY coverage and portable spawn-contract regressions; document Windows flow-control availability. Validation: 546 Node tests passed, fork Bun passed 9 tests, stock Bun passed 6, typechecks/lint/format/assertion safety passed, and independent review found no actionable issues. Real Windows ConPTY tests remain unexecuted on this macOS host.

* revert(terminal): keep node-pty for Bun on Windows

Bun.Terminal on Windows does not deliver Ctrl-C to the foreground program; node-pty does on the same host. Restore node-pty for Bun on Windows while retaining Bun native PTYs on macOS and Linux and node-pty for Node on every platform.

* fix(terminal): keep the Node helper on Bun builds without Terminal.pause

Resolve ClawSweeper's P1s for supported stock Bun: preserve output
backpressure and avoid the macOS wait4 event-loop deadlock after fast PTY
child exit. Gate the native adapter on Terminal.prototype.pause, supplied
by the OpenClaw Bun fork carrying openclaw/bun#10 and #11. Other POSIX Bun
builds keep main's Node helper with raw parameters and launch-authority
checks; Node and Windows retain node-pty.

Restore the helper, worker, protocol, tests, and runtime entrypoint
byte-identically from origin/main. Require pause/resume in the gated
native adapter while preserving output replay, teardown drain, EOF grace,
and exit ordering. Update runtime and terminal docs without a changelog edit.

Resolve the P2 replay-test issue with controlled Bun.spawn callbacks,
without sleeps or a production test hook. Cover capability routing and a
real stock-Bun Node-helper terminal; retain CI routing with native PTY
cases skipped until its Bun pin gains the capability.

Validation: Node product suites 550 passed; fork Bun 16 passed; stock Bun
9 passed with all 8 native cases skipped. Typechecks, scoped lint,
formatting, assertion-safety ratchet, and docs syntax pass. The requested
combined Node command reports only the known lint-suppression mismatch
already fixed on main by b8fa8dc (#159553); leave that file untouched.

* fix(terminal): never deliver unsubscribed Bun PTY output after exit

Output queued with no data subscriber stayed in the adapter's queue when
exit was published, so a later onData subscription received it after
exit. Drop it at exit, as node-pty drops output nobody listens to, and
cover a late subscriber with a deterministic controlled-callback test.
2026-09-27 17:30:18 -07:00
Peter Steinberger e205c9d6fc fix(test): include manifest-only plugins in extension test plans (#159981) 2026-09-27 17:17:34 -07:00
Peter Steinberger 9491d5a5a3 refactor(scripts): deslop scripts/lib (#159362)
* refactor(scripts): deslop scripts/lib

Consolidate script lifecycle, scenario, planner, report, release and
packaging helpers while retaining CLI and publication contracts.

Keep config-boundary source caches within one scan so repeated in-process
checks observe edits. Carry extracted helpers through selective fixtures
and iOS scope routing. Leave PR tooling and its library import closure intact.

* fix(scripts): retain sanitizer fast path after helper cleanup

* fix(scripts): model watchdog shell consumer in dead-code checks
2026-09-27 17:13:58 -07:00
Peter Steinberger e337075dd7 ci: start Node tests alongside baseline ratchets 2026-09-27 17:06:56 -07:00
Peter Steinberger b3f4c0aa54 ci: balance native test rows from measured timing
Retain complete worker-qualified timing identities, split oversized families
by file, and enforce the ordered-slot 300-second wall budget across broad
and selected plans. Direct Blacksmith observations keep their native price.

Use the qualified four-worker Gateway policy with its memory admission and
two-worker fallback, preserve hosted hourly budgets, and expose test wall
separately from aggregate work. Coverage and exclusive-group policies remain
owned by the existing planner.
2026-09-27 16:50:28 -07:00
b7a0e00097 fix(ci): distinguish survivor recovery failure boundaries (#159751)
Refine the existing phase only during recovery and restore it on success. Preserve updater exits, assertion short-circuiting, signal capture and cleanup ordering.

Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com>
Co-authored-by: RomneyDa <6581799+RomneyDa@users.noreply.github.com>
2026-09-27 16:30:05 -07:00
Peter Steinberger 47d9700dcf chore(ci): catch Node spawns in Bun-only installs (#159439)
Add an advisory Bun-only runtime smoke to Install Smoke, run only by Release Checks (Full Release Validation). It
installs the verified candidate with the pinned Bun fork, hides every real Node inside a private mount namespace,
and exercises install, CLI, Gateway, node host pairing, a mocked agent turn, doctor, terminals, and the browser.
A PATH sentinel records every node/npm/pnpm/yarn/corepack execution with its exact path and process ancestry, a Bun
preload records the JS stack, and a classifier fails on any attempt missing from
scripts/e2e/lib/bun-only-runtime/expected-node-blockers.json or on a listed blocker that no longer reproduces.

Admin-merged with maintainer approval: the only failing required check was test/scripts/pr-wrappers.test.ts, a main
regression from b2e0e562 unrelated to this change. PR-owned tests (94), lint, workflow checks, check-dependencies,
docs, guards, and types passed at this head.
2026-09-27 16:28:36 -07:00
Vincent Koc d038d1dbbf fix(qa): keep Telegram round-trip checks on the exercised route (#159284)
Resolve the probe route from the selected scenario attempt's surviving
messages and use the provisioned primary participant. Keep the first
sample fresh and reject replies from a different topic.

Preserve explicit probes and native observer admission. Rework the
original repair without migrating the scenario catalog.

Related: https://github.com/openclaw/openclaw/pull/137139
2026-09-27 16:26:01 -07:00
Peter Steinberger ef681882ff ci: collect exact pull request timing samples
Use complete config, file, and worker identities when refitting compact
PR workloads. Preserve independent-run admission and partial-inventory
retention, and keep main-run tooling logs out of the PR timing cohort.
Publish the complete refit report as an artifact with bounded job outputs.

Linux Testbox proof: 508 owner cases, workflow validation, extracted-wrapper
inventory, types, boundary lint, three Knip scans, lint, and formatting.
The 174-case timing file took 45.452s with one worker. The mixed-source
regression failed before the fix and passed afterward. P2 review is clean.
Broad PR plans are byte-identical against the base before timing refreshes.
2026-09-27 16:25:06 -07:00
Peter Steinberger a1ba139b56 perf(ci): use measured budgets for bounded lint shards 2026-09-27 16:19:40 -07:00