Peter Steinberger
99cf5836dd
fix(ci): pin calibrated Kova performance budgets
2026-07-14 13:54:29 +01:00
Peter Steinberger
9de11f098e
fix(release): forward-port July guards and restore main validation ( #107462 )
...
* fix(installer): validate upgraded Windows SQLite runtime
* fix(release): lock packed AI runtime dependency
* test(mattermost): tolerate additional fallback diagnostics
* test(live): make Claude resume proof explicit
* test(plugins): repair exact-main prerelease coverage
* test(release): restore root test type coverage
---------
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
Co-authored-by: Vincent Koc <25068+vincentkoc@users.noreply.github.com >
2026-07-14 05:41:24 -07:00
Peter Steinberger
c8bc82817c
fix(ci): accept normalized admin release permission
2026-07-14 12:52:37 +01:00
Peter Steinberger
92cca9343e
feat(linux): headless node device capabilities (camera, location, notifications) ( #107193 )
...
* feat(linux): add node device capabilities
* fix(linux-node): actionable pending-approval error + node-host advertise integration test
* fix(linux-node): map geoclue access-denied to LOCATION_DISABLED; floor camera maxWidth to avoid zero-height scale
* fix(linux-node): clamp small camera maxWidth to 2 instead of default
* docs(linux-node): clarify where-am-i -t is a process timeout, not update throttle
* refactor(gateway): extract legacy-node filter + rejection hint to fit LOC ratchet; docs-map + deadcode baseline
* fix(gateway): drop now-unused DEFAULT_DANGEROUS_NODE_COMMANDS import after hint extraction
* test(node-host): drop imports orphaned by removed error-code test
2026-07-14 02:30:36 -07:00
Peter Steinberger
47d37804a8
improve(ui): catch i18n catalog drift locally ( #107253 )
...
* ci(ui): verify i18n catalogs locally
* fix(ui): preserve scoped i18n sync errors
* refactor(ui): share i18n raw-copy verifier
* test(ui): cover i18n lint gate
* fix(ui): route lint threads to oxlint
2026-07-14 01:12:36 -07:00
Peter Steinberger
f4b7a19624
fix: avoid remote boxes for focused validation ( #107166 )
...
* fix: avoid remote boxes for focused validation
* fix: preserve explicit remote proof routing
* fix: delegate when local diff refs are unavailable
2026-07-14 00:53:17 -07:00
Peter Steinberger
606e2f5dba
fix(ci): stop unrelated main updates from forcing PR rebases ( #107050 )
...
* fix(ci): stop unrelated main updates from forcing PR rebases
* docs(ci): document reusable aggregate proof
* docs(ci): clarify immutable gate success
* chore(ci): refresh stalled PR head
2026-07-14 00:01:01 -07:00
Peter Steinberger
df5097b6e7
fix(native): keep platform validation warning-free ( #107101 )
...
* build(android): keep Gradle warning-free
* ci(native): pin XcodeGen tooling
* test(macos): avoid concurrency warnings
2026-07-13 22:33:12 -07:00
Peter Steinberger
504be0c255
fix(release): preserve closeout asset names ( #107047 )
2026-07-13 21:20:01 -07:00
Peter Steinberger
04fa6beed4
fix(release): make closeout recovery shell-safe ( #107015 )
2026-07-13 20:02:45 -07:00
Vincent Koc
f7ea3c776c
fix(ci): pin corrected Kova scenario calibration ( #106992 )
2026-07-14 10:23:58 +08:00
Vincent Koc
e5722a6726
fix(ci): pin calibrated Kova release budgets
2026-07-13 17:54:41 -07:00
Peter Steinberger
ad8107e136
feat(linux): ship deb/AppImage bundles on stable main-based releases ( #106891 )
...
* feat(linux): attach deb/AppImage bundles to main-based releases
* fix(linux): stamp release version into bundles and verify deb metadata
* fix(linux): stable-only release tags and ubuntu-22.04 glibc build floor
* docs(linux): document AppImage FUSE prerequisite
* fix(linux): allow numeric stable revision tags in release workflow
2026-07-13 16:31:09 -07:00
Peter Steinberger
4fdb314d9a
fix(release): normalize Windows checksum manifests
2026-07-14 00:27:34 +01:00
Peter Steinberger
34c63c3c3a
fix(release): support evidence-backed late closeout
2026-07-14 00:27:34 +01:00
Vincent Koc
85cf09a3e1
docs(release): bound release recovery loops ( #106852 )
...
* docs(release): keep release work scoped
* style(release): format workflow test
2026-07-14 06:44:23 +08:00
Peter Steinberger
70833dab7f
ci: scope PR Node tests to changed targets ( #106633 )
...
* ci: scope PR Node tests to changed targets
* ci: bound targeted Node test plans
* test: cover changed path manifest input
* fix(ui): preserve model providers lazy boundary
* ci: cover public SDK re-export consumers
* ci: reject unresolved changed test targets
* ci: cover public SDK wrapper imports
* ci: preserve global checks in targeted plans
* docs(ci): clarify targeted boundary coverage
* test(plugins): declare computed runtime dependencies
2026-07-13 15:26:02 -07:00
Peter Steinberger
856e1ab8d9
fix(ci): bind release target context ( #106836 )
2026-07-13 15:00:03 -07:00
Peter Steinberger
d1bb38345e
ci: preserve release target context ( #106783 )
2026-07-13 14:32:59 -07:00
Peter Steinberger
e30cc79b81
ci: remove redundant extension oxlint lanes
2026-07-13 11:02:51 -07:00
Peter Steinberger
80bcfa1796
feat(linux): deb/AppImage packaging, claw-mark brand icons, gateway auth guidance ( #106533 )
...
* feat(linux): package deb/AppImage bundles, claw-mark icons, foreign-gateway guidance
* fix(linux): pin pnpm dlx release-age for tauri-cli in packaging paths
* fix(linux): pin exact tauri-cli version under the release-age gate
* fix(linux): conditional wording for gateway auth-rejection guidance
* docs(linux): executable square-pad step in tray icon recipe
2026-07-13 09:22:12 -07:00
Peter Steinberger
458746e1c2
chore(ci): enforce changed-file TypeScript LOC ratchet ( #106387 )
...
* ci: enforce changed-file TypeScript LOC ratchet
* ci: derive release-gate LOC base from PR
* test(ci): exclude repository test helpers from LOC ratchet
* ci: validate LOC ratchet on PR merge tree
* style: format release maintainer skill
* ci: run LOC ratchet for fast-only changes
* fix(ci): harden LOC ratchet comparisons
* fix(ci): cover native TypeScript in LOC ratchet
* fix(ci): compare LOC against tested merge tree
* test(ci): cover LOC manifest routing
2026-07-13 07:20:32 -07:00
Peter Steinberger
882b2fe900
feat(channels): bundle Reef guarded claw-to-claw channel ( #106232 )
...
* feat(channels): bundle Reef guarded claw-to-claw channel
Moves the Reef channel extension from openclaw/reef into the bundled extensions tree with the wire protocol vendored under extensions/reef/protocol. Includes channelConfigs manifest metadata, runtime status reporting via setStatus/buildAccountSnapshot, abort-aware inbox shutdown, monotonic device-auth timestamps, and immutable-model guard admission (dated snapshots plus documented gpt-5.6 ids).
* fix(reef): pin zod exactly per dependency pin guard
* style(reef): satisfy extension lint gates
Curly braces in vendored protocol, explicit type re-exports, typed catch callbacks, Object.assign over map-spread, abort-aware loop restructure.
* fix(reef): CI gates — knip workspace, boundary tsconfig, facade imports, cycle break, contract baselines
- knip: reef workspace project includes vendored protocol/ (owns noble deps)
- tsconfig: conform to canonical extension package-boundary include/exclude; add @openclaw/plugin-sdk devDependency
- imports: channel-inbound/channel-outbound facades instead of deprecated subpaths
- protocol: home ReplayStore contract in envelope.ts to break the envelope<->replay type cycle
- baselines: reef in unguarded runtime-api list; regenerate bundled channel config metadata
* feat(reef): plugin catalog cover art, channel label, changelog revert
* fix(reef): drop unused error-class exports, register lint suppression
* fix(reef): knip entry surface for vendored protocol, explicit WebSocketLike export
2026-07-13 05:17:44 -07:00
Peter Steinberger
0bab08510e
feat: Linux desktop companion app with auto-install, Gateway lifecycle, and Control UI window ( #106352 )
...
* feat(linux): add Tauri desktop companion app and openclaw dashboard --json
* test(dashboard): assemble fake token fixture to satisfy secret scanners
* test(dashboard): avoid secret-scanner-shaped mock factory line
* fix(linux): actionable error when installed CLI predates dashboard --json
* docs: regenerate docs map for linux platform heading change
2026-07-13 05:17:27 -07:00
Peter Steinberger
4b6575636f
fix(ci): finalize control UI locale artifacts
2026-07-13 12:12:51 +01:00
Peter Steinberger
e2ed58efec
fix(ci): publish native generated locales
2026-07-13 11:41:15 +01:00
Peter Steinberger
6bb85f177f
feat(onepassword): optional 1Password secrets broker plugin ( #106133 )
...
* feat(onepassword): add optional 1Password secrets broker plugin
Curated slug registry with per-item auto/approve/deny policy, plugin-approval
gating with expiring allow-always grants, SQLite audit history, onepassword
status/audit CLI, and a single-attempt op client (--cache=false, minimal env).
Closes #105924
* docs(plugins): refresh generated inventory count after rebase
* fix(onepassword): scope grants and field reads
* fix(onepassword): bound grant retention
* fix(onepassword): satisfy deadcode ratchet and hook allowlist contract
* fix(onepassword): honor live policy reloads
* refactor(onepassword): trim private exports
* test(onepassword): satisfy plugin boundaries
* test(onepassword): document temp directory boundary
2026-07-13 03:12:47 -07:00
Peter Steinberger
d38fc3e2f0
fix(ci): keep Periphery scope checks off shared API quota ( #106090 )
...
* fix(ci): avoid API quota in Periphery scope checks
* fix(ci): preserve Periphery scope contracts
2026-07-13 01:47:43 -07:00
Peter Steinberger
b1ce84b079
ci: reduce Blacksmith registrations for pull requests ( #106146 )
2026-07-13 01:32:25 -07:00
Peter Steinberger
0ab7e2569b
fix(ci): preserve pinned manual checkout
2026-07-13 03:42:26 -04:00
Peter Steinberger
afdc29c3dd
fix(ci): reduce release validation polling load ( #106139 )
...
Co-authored-by: Vincent Koc <vincentkoc@ieee.org >
2026-07-13 15:32:27 +08:00
Jason (Json)
3375e30d9c
chore(ci): remove TypeScript LOC ratchet ( #106096 )
...
Remove the hard 500-line TypeScript LOC ratchet from CI and local check planning, along with its package commands, implementation, baseline, and dedicated tests. Keep the remaining pull-request temp-creation report on its own pr-base fetch.\n\nVerification: 99 focused tooling tests; actionlint; zizmor; workflow guards; exact-head autoreview.
2026-07-13 00:15:00 -06:00
Paul Campbell
008f04a656
feat(mxc): add Windows MXC sandbox backend ( #97086 )
...
* feat(mxc): add Windows MXC sandbox backend
Add the official MXC sandbox plugin package with Windows ProcessContainer execution, plugin-owned MXC SDK dependency packaging, host-backed filesystem bridge support, and configured MXC policy file loading via mxcPolicyPaths.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
* fix(mxc): preserve Windows binary override paths
* fix: remove stray sandbox barrel export
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Copilot-Session: 9ea19539-b8ca-44fb-93bd-b8496e3deb2c
* fix(mxc): address sandbox review feedback
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): satisfy test type checks
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): clarify protected skill enforcement
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* test(mxc): align fail-closed expectations
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): satisfy extension lint
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(plugin-sdk): narrow fs-safe remove surface
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com >
* fix(mxc): repair rebased CI failures
* fix(scripts): declare shrinkwrap override normalizer
---------
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
Co-authored-by: Gio Della-Libera <235387111+giodl73-repo@users.noreply.github.com >
Co-authored-by: Dallin Romney <dallinromney@gmail.com >
2026-07-12 23:07:25 -07:00
Peter Steinberger
aa04722c5c
fix(ci): make TypeScript LOC growth reviewable ( #105952 )
2026-07-12 23:06:30 -07:00
Vincent Koc
f33ab243cf
fix(sqlite): reject runtimes vulnerable to WAL corruption ( #106065 )
...
* fix(sqlite): require WAL-reset-safe Node runtime
* docs(sqlite): document safe Node runtime floor
* fix(sqlite): defer runtime library validation until use
* fix(ci): align startup memory with Node 24.15
2026-07-13 13:59:00 +08:00
Vincent Koc
6a0eecdb44
fix(release): separate code and release SHA validation ( #105948 )
2026-07-13 13:38:19 +08:00
Peter Steinberger
dce8eed0b9
ci(deadcode): restore enforced unused-export ratchet ( #105826 )
...
* ci(deadcode): restore export ratchet
* chore(deadcode): refresh export baseline
* refactor(sessions): remove obsolete patch writer
* refactor(deadcode): classify current export residue
* fix(deadcode): preserve exported signature types
* chore(deadcode): sync export baseline after rebase
* chore(deadcode): classify pairing test exports
* fix(ci): refresh plugin SDK declaration budget
2026-07-12 19:58:38 -07:00
Peter Steinberger
c3dbaf4375
refactor: split hot TypeScript modules and add LOC ratchet ( #105894 )
...
* refactor: split high-churn agent and chat modules
* ci: enforce TypeScript LOC ratchet
* ci: anchor LOC baseline updates to merge base
* test: cover LOC ratchet check plans
* chore: refresh TypeScript LOC baseline
2026-07-12 19:57:42 -07:00
Peter Steinberger
e01d1e85f3
ci(swift): enforce shared OpenClawKit dead-code coverage ( #105770 )
...
* ci(swift): enforce shared kit dead-code coverage
* chore(i18n): sync native source inventory
* ci(swift): install pinned iOS scan tools
2026-07-12 17:35:47 -07:00
Vincent Koc
37807242c9
fix(release): pin publish workflow refs ( #105773 )
2026-07-13 08:15:35 +08:00
Vincent Koc
13212f1a4d
fix(release): accept canonical plugin package identities ( #105746 )
2026-07-13 07:45:31 +08:00
Peter Steinberger
2264816f1d
ci(macos): add enforced periphery dead-code lane and delete the 12 current findings ( #105743 )
...
* refactor(macos): delete dead code flagged by periphery
* ci(macos): add enforced periphery dead-code lane
* fix(ci): scope-label the periphery skip message
* chore(i18n): sync native inventory line coordinates
2026-07-12 16:39:15 -07:00
Vincent Koc
55f438e295
fix(release): handle empty ClawHub bootstrap plan ( #105722 )
...
* fix(release): handle empty ClawHub bootstrap plan
* fix(release): handle empty ClawHub bootstrap plan
2026-07-13 06:55:23 +08:00
Vincent Koc
2c06dfdd2f
fix(ci): keep unused exports advisory ( #105704 )
...
* fix(ci): preserve frozen deadcode contracts
* fix(ci): keep unused exports advisory
2026-07-13 05:47:05 +08:00
Vincent Koc
bf81e589ac
fix(ci): bound Telegram gateway diagnostics ( #105645 )
2026-07-12 22:02:22 +02:00
Peter Steinberger
67d7bf1037
ci(release): deduplicate Telegram routing proofs ( #105613 )
2026-07-12 21:07:24 +02:00
Peter Steinberger
a425807c31
ci(deadcode): replace broken export report lanes with enforced knip exports ratchet ( #105595 )
...
* chore(deadcode): add generated knip unused-export baseline
* ci(deadcode): replace broken export report lanes with enforced knip exports ratchet
* chore(deadcode): regenerate unused-export baseline on current main
* chore(deadcode): regenerate unused-export baseline on current main
2026-07-12 11:36:42 -07:00
Peter Steinberger
1634d849c7
fix(ci): allow empty success diagnostics ( #105569 )
...
* fix(ci): allow empty success diagnostics
* docs(agents): guard non-main PR landing
2026-07-12 18:57:42 +01:00
Peter Steinberger
d5fd7ad6ff
ci(release): parallelize runtime parity tiers ( #105545 )
2026-07-12 18:23:41 +01:00
Peter Steinberger
7c5b66a1e4
fix(ci): wait for Telegram credential capacity ( #105535 )
...
* fix(ci): wait for Telegram credential capacity
* test(ci): align Telegram credential wait contract
2026-07-12 18:19:13 +01:00