xingzhou
16c2bbb540
fix(mantis): bound Crabbox source checkout ( #108940 )
2026-07-16 07:49:07 -07:00
Peter Steinberger
06e3a09bd8
fix(ci): preserve advisory release checks
2026-07-16 11:56:01 +01:00
Alix-007
8a21f640e3
fix(ci): bound release resume tarball downloads ( #108766 )
2026-07-16 01:54:50 -07:00
Dallin Romney
401e7b003c
fix(release): support frozen pre-AI package targets ( #108479 )
2026-07-15 15:49:27 -07:00
Peter Steinberger
28d30e9dae
ci: stabilize release validation tests ( #108420 )
...
* test(codex): remove turn-watch timing race
* ci: pin workflow sanity shellcheck
* ci: run workflow sanity on blacksmith
* ci: serialize workflow sanity lint
* ci: bound workflow lint stalls
* ci: cap actionlint process fanout
* ci: report stalled workflow shellcheck
* ci: stabilize release validation checks
* ci: restore release workflow shellcheck
* test: preserve codex turn watch reset proof
2026-07-15 13:22:31 -07:00
Dallin Romney
8c77936e50
fix(release): propagate frozen-target guard and retry live timeouts ( #108418 )
...
* fix(release): preserve frozen package acceptance opt-in
* fix(release): retry transient live terminal timeouts
* fix(release): keep package dispatch input budget
* refactor(release): name frozen-target compatibility mode
* revert: keep frozen-target guard naming
2026-07-15 13:06:24 -07:00
Peter Steinberger
d8b3e1c093
fix(release): compare evidence archive contents
2026-07-15 20:38:57 +01:00
Peter Steinberger
23d2f664fb
fix(release): retain npm provenance evidence
2026-07-15 20:02:53 +01:00
Peter Steinberger
f4f5bb15d4
fix(release): verify resumed npm publisher identity
2026-07-15 19:29:37 +01:00
Dallin Romney
ee51b35616
fix(release): support frozen Codex validation ( #108343 )
...
* fix(release): support frozen Codex validation
* fix(release): support frozen Codex validation
* fix(release): support frozen Codex validation
* fix(release): support frozen Codex validation
2026-07-15 10:05:02 -07:00
Peter Steinberger
4c667aac88
fix(release): harden frozen target validation ( #108296 )
...
* fix(release): harden frozen scenario planning
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): omit unsupported scenario-only lanes
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): fail closed on malformed target scenarios
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): report unsupported frozen lanes
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): defer frozen survivor inspection
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): report partial survivor omissions
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(ci): fetch shard fallback from workflow commit
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(release): gate frozen scenario omissions
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* test(release): auto-clean frozen target temp dirs
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
* fix(ci): satisfy frozen validation workflow lint
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
---------
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
2026-07-15 06:31:07 -07:00
Dallin Romney
ed05dae2d8
fix(release): support frozen Matrix QA profiles ( #108279 )
2026-07-15 05:01:29 -07:00
Dallin Romney
043e4d1ec4
fix(release): validate frozen targets with current workflows ( #108189 )
...
* fix(release): support frozen validation targets
* fix(release): filter frozen-target upgrade scenarios
2026-07-15 04:28:17 -07:00
Peter Steinberger
54f70c5d8c
fix(release): unblock plugin bootstrap recovery ( #108243 )
2026-07-15 03:34:08 -07:00
Peter Steinberger
dfa246e6fd
fix(release): complete protected publish tooling
2026-07-15 10:43:00 +01:00
Peter Steinberger
bb1a7e5069
fix(release): pin publish workflows to protected tags
2026-07-15 09:52:01 +01:00
Dallin Romney
6c4e76ea8b
ci(qa): reuse Matrix live workflow for releases ( #103604 )
...
* ci(qa): reuse Matrix live workflow for releases
* docs(testing): restore Tailscale isolation flag
* fix(ci): make Matrix artifact names ref-safe
* test(ci): type Matrix workflow profiles
* style(testing): format Tailscale isolation guidance
2026-07-15 01:48:59 -07:00
Peter Steinberger
732fb5f9e6
fix(release): bind Telegram proof artifact identity
2026-07-15 08:02:17 +01:00
Peter Steinberger
504be0c255
fix(release): preserve closeout asset names ( #107047 )
2026-07-13 21:20:01 -07:00
Peter Steinberger
04fa6beed4
fix(release): make closeout recovery shell-safe ( #107015 )
2026-07-13 20:02:45 -07:00
Peter Steinberger
4fdb314d9a
fix(release): normalize Windows checksum manifests
2026-07-14 00:27:34 +01:00
Peter Steinberger
34c63c3c3a
fix(release): support evidence-backed late closeout
2026-07-14 00:27:34 +01:00
Vincent Koc
85cf09a3e1
docs(release): bound release recovery loops ( #106852 )
...
* docs(release): keep release work scoped
* style(release): format workflow test
2026-07-14 06:44:23 +08:00
Vincent Koc
6a0eecdb44
fix(release): separate code and release SHA validation ( #105948 )
2026-07-13 13:38:19 +08:00
Vincent Koc
37807242c9
fix(release): pin publish workflow refs ( #105773 )
2026-07-13 08:15:35 +08:00
Vincent Koc
55f438e295
fix(release): handle empty ClawHub bootstrap plan ( #105722 )
...
* fix(release): handle empty ClawHub bootstrap plan
* fix(release): handle empty ClawHub bootstrap plan
2026-07-13 06:55:23 +08:00
Peter Steinberger
d5fd7ad6ff
ci(release): parallelize runtime parity tiers ( #105545 )
2026-07-12 18:23:41 +01:00
Peter Steinberger
7c5b66a1e4
fix(ci): wait for Telegram credential capacity ( #105535 )
...
* fix(ci): wait for Telegram credential capacity
* test(ci): align Telegram credential wait contract
2026-07-12 18:19:13 +01:00
Peter Steinberger
9d042e252c
fix(release): keep source-ref packaging self-contained ( #105360 )
...
* fix(release): make ref packaging harness self-contained
* docs(agents): preserve cwd after PR merge
* test(release): track package harness temp dirs
* style(test): format package harness imports
2026-07-12 13:45:24 +01:00
Peter Steinberger
e0f45bfbf0
feat(tooling): enforce indexed access checks in root tests ( #105223 )
...
* feat(tooling): enforce indexed access checks in root tests
* style(tooling): clarify scoped package guard
2026-07-12 10:42:07 +01:00
Peter Steinberger
b683a0a5cf
fix(ci): prevent AWS Crabbox pnpm exit hang ( #104710 )
2026-07-11 14:25:19 -07:00
Peter Steinberger
fa77fe10d5
chore: migrate active GPT-5.5 references to GPT-5.6 ( #104452 )
...
* chore(models): migrate active GPT-5.5 references
* test(workboard): expect GPT-5.6 Sol default
* chore: keep release notes in PR body
* test(models): align picker fixtures with Sol default
* test: update PDF default model expectation
* test(qa): migrate thinking smoke to Luna
* test(gateway): align mock catalog with Sol default
* ci: retrigger exact-head PR checks
* test(gateway): document default catalog invariant
2026-07-11 06:30:57 -07:00
Peter Steinberger
fe261b0f59
chore(tooling): typecheck root test/** with a dedicated tsgo lane ( #104475 )
...
* chore(types): add declaration files for scripts/lib and scripts/e2e modules
* chore(types): add declaration files for top-level script modules (a-m)
* chore(types): add declaration files for top-level script modules (n-z)
* test: use a non-secret-shaped gateway token fixture
* test: type ci workflow guard helpers for the root test lane
* chore(tooling): typecheck root test/** with a dedicated tsgo lane
- test/tsconfig/tsconfig.test.root.json: root-test program (strict unused checks,
fixtures excluded; two Docker E2E clients that import built dist/** stay out,
same rationale as the scripts/e2e exclusion in tsconfig.scripts.json)
- tsgo:test:root wired into tsgo:test, check:test-types, scripts/check.mjs, and
the ci.yml test-types shard, mirroring the tsgo:scripts lane (#104348 )
- changed-lane routing: test/**/*.ts (excluding fixtures) and the lane tsconfig
now trigger 'typecheck test root' in check:changed; previously test/ paths ran
lint only, so harness type errors surfaced first in CI (#104287 envDir case)
- burn down all 1071 latent type errors in the program: precise param/local
types across test/scripts, test/vitest, test/e2e, and transitive scripts/e2e
program members; 205 sibling .d.mts declaration files for imported .mjs
modules (committed separately); zero any, zero ts-expect-error
- resolve the pre-existing testing star-export ambiguity in
scripts/e2e/parallels/common.ts with an explicit re-export
Closes #104388
* chore(types): correct declaration fidelity per structured review
- re-derive 51 .d.mts files from implementation data flow instead of
initializers: fix a wrong never return (runTestProjectsDelegation returns
the child), add encoding-sensitive exec/spawn overloads (plain-gh), restore
the full release profile union, make parsed paths string | null, add missing
parseArgs fields via help/non-help unions, add a missing sibling declaration
(budget-number-args), drop 15 unused lint directives
- precise install-record/tuple typing removes the type-aware oxlint
regressions the first declarations caused in scripts/e2e implementations
- route .mts declaration edits under test/ to the testRoot lane and reference
the test-root project from tsconfig.projects.json so tsgo:all covers it
(closes both review findings against the lane wiring)
* chore(scripts): keep telegram runner dist typing structural for the boundary guard
* chore(types): declare runtime pack and gateway readiness exports added on main
* test: pin the importTargetPlan form of the plugin-contract plan import
The guard expectation still referenced the raw await import( form that
7ae5996bb3 (#103975 ) replaced with the importTargetPlan fallback helper;
the assertion fails on current main.
2026-07-11 06:15:41 -07:00
Peter Steinberger
3f2e9184f6
ci(release): fail fast in Telegram validation ( #104324 )
...
* ci(release): bound Telegram validation time
* fix(release): preserve Telegram QA cleanup
* style(test): format Telegram workflow assertions
* test(release): encode Telegram lease timeout
2026-07-11 02:11:27 -07:00
Vincent Koc
c47ceb0f3d
improve(release): reuse exact-SHA validation evidence ( #104162 )
...
* perf(release): share changelog verification snapshots
* perf(release): reuse exact-SHA validation evidence
* feat(release): checkpoint candidate workflow state
* feat(release): watch CI transitions compactly
* fix(testbox): rotate stale reusable leases
* refactor(release): move CI verifier into scripts
* fix(release): preserve verifier executable mode
* fix(testbox): force noninteractive remote hydration
* perf(testbox): skip sync for proven clean heads
* fix(testbox): keep changed gates synchronized
* fix(testbox): isolate git state probes
* fix(testbox): isolate wrapper git commands
* fix(testbox): preserve git command contracts
* fix(release): validate reused SHA evidence
* fix(release): resume serialized plugin selections
* fix(testbox): sync source on every lease reuse
* fix(release): verify from trusted workflow checkout
* fix(release): gate evidence reuse on trusted lineage
* fix(release): support legacy verifier checkouts
* fix(testbox): export CI across shell snippets
* fix(release): revalidate reused evidence before publish
* fix(release): reject untrusted reuse before lookup
* fix(release): reuse SHA-pinned root evidence
* fix(ci): allow unreleased notes in QA packages
* fix(release): satisfy script lint contracts
* fix(release): handle Unicode workflow refs safely
2026-07-11 12:48:27 +08:00
Vincent Koc
ffc8051cac
test(release): align trusted SHA workflow guard
2026-07-11 11:09:58 +08:00
Peter Steinberger
7febbad017
fix(release): dispatch Telegram QA with environment access ( #104066 )
2026-07-10 19:19:04 -07:00
Peter Steinberger
49941fab6d
fix(ci): keep hydrate-github pnpm shims writable ( #103971 )
2026-07-10 23:36:10 +01:00
Vincent Koc
b0e3c85a61
fix(release): bind publish children to trusted SHAs ( #103913 )
...
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-10 23:25:26 +01:00
Vincent Koc
022dd9dc27
fix(release): unblock Meta npm bootstrap publication ( #103951 )
...
* fix(release): isolate Meta npm bootstrap
* test(release): assert OIDC npm version guard
2026-07-10 14:50:00 -07:00
Vincent Koc
54cc90b1b1
fix(release): publish ClawHub bootstrap artifacts immutably ( #103809 )
...
* fix(release): harden ClawHub bootstrap
* fix(release): centralize publication artifact verification
* fix(release): harden publication artifact verification
* fix(release): lock ClawHub bootstrap toolchain
* test(release): assert locked ClawHub binary
* fix(release): pack with trusted ClawHub harness
* fix(release): bound beta verifier artifact reads
* fix(release): bind target and tooling identities
* fix(release): stabilize signed package ordering
* fix(release): bind ClawHub pretag proof
* fix(release): bind ClawHub OIDC readback
* fix(release): bind ClawHub OIDC readback
2026-07-10 13:33:20 -07:00
Peter Steinberger
fece8c9f54
fix(release): keep validation evidence immutable across reruns ( #103906 )
...
* fix(release): bind validation evidence to exact attempts
* test(release): cover exact validation attempts
2026-07-10 20:16:19 +01:00
Vincent Koc
2a1d6e49d5
fix(ci): run Telegram release QA from trusted harness ( #103207 )
...
* fix(ci): use trusted Telegram QA harness
* fix(ci): restrict trusted Telegram QA candidate
* fix(ci): isolate trusted Telegram QA candidate
* fix(ci): harden Telegram QA process boundary
* fix(ci): pass Telegram QA release gates
* test(qa): stub Telegram env explicitly
* fix(ci): harden Telegram release QA boundary
* test(ci): harden trusted workflow and memory guards
2026-07-10 11:32:24 -07:00
Peter Steinberger
b597a8d364
fix(release): restore prerelease and release validation startup ( #103834 )
...
* fix(release): split image publication from validation
* fix(ci): honor install smoke caller input
* fix(ci): harden Docker rerun targeting
2026-07-10 18:46:08 +01:00
Vincent Koc
afd0c60f15
fix(ci): bind release status artifacts to run attempts ( #103772 )
...
* fix(ci): bind release status artifacts to run attempts
* test(ci): align release summary contract assertions
* fix(ci): preserve Tideclaw advisory status policy
2026-07-10 09:06:42 -07:00
Vincent Koc
cbe3731f77
fix(release): make validation proof no-write ( #103737 )
...
* fix(release): make validation proof no-write
* test(release): align no-write workflow contracts
2026-07-10 08:18:44 -07:00
JC
59e95fe3fd
feat: support GPT-5.6 Ultra across OpenClaw and Codex runtimes ( #98021 )
...
* feat: support GPT-5.6 Ultra across agent runtimes
Co-authored-by: J Cai <anyech@gmail.com >
* fix: keep harness projections discovery-free
* fix(codex): mirror V2 native subagent tasks
* chore: refresh plugin SDK surface budgets
* test: expose Ultra wire effort proof
* test(cron): avoid hoisted mock initialization race
---------
Co-authored-by: Peter Steinberger <steipete@gmail.com >
2026-07-10 15:23:24 +01:00
Peter Steinberger
8d66e47773
fix(release): prove registry tarball identity before resuming a publish
...
Codex review: version existence alone does not prove the npm registry
serves the tarball this tag's preflight built — the same version could
have been published from a different artifact and npm versions are
immutable. The resume resolver now downloads the preflight manifest,
requires its releaseSha to match the target, and compares the published
registry tarball's sha256 against the manifest before skipping the core
dispatch; mismatches abort with correction-tag guidance.
2026-07-10 03:09:10 -07:00
Peter Steinberger
ef22e77f0b
perf(release): make publish reruns resumable and promote assets concurrently
...
The 2026.7.1 retro measured ~13h tag-to-published for beta.2 and stable
2026.6.11; any post-npm failure previously hard-aborted retries because
the already-published guard refused the whole run.
- resolve_openclaw_npm_publish_state replaces the abort guard: an
already-published core version skips the core npm dispatch and resumes
the remaining stages; verify_published_release still proves the
registry state matches the tag before the page leaves draft.
- Windows and Android promotion runs concurrently with the core npm
publish (their only shared prerequisite is the draft release page,
which is now created before the dispatch) and each promotion
short-circuits when the release already carries its verified asset
contract, so retries only redo failed stages.
- The release proof cites the core npm run only when this run dispatched
one; resumed publishes rely on the registry package check.
2026-07-10 03:09:09 -07:00
Peter Steinberger
4bc300843d
fix(qa): keep runtime parity tiers flow-compatible ( #103609 )
...
* fix(qa): keep runtime parity tiers flow-compatible
Refs #103588
* test(qa): follow canonical frontier defaults
2026-07-10 10:51:13 +01:00