Add experimental portable Claw package schema - #3089
Patrick-Erichsen merged 7 commits into
Conversation
|
@giodl73-repo is attempting to deploy a commit to the OpenClaw Foundation Team on Vercel. A member of the Team first needs to authorize it. |
5a65897 to
0087aea
Compare
|
Codex review: needs maintainer review before merge. Reviewed July 22, 2026, 1:32 AM ET / 05:32 UTC. Summary Reproducibility: not applicable. This PR introduces a new experimental package-family capability rather than fixing a currently broken behavior. Its submitted terminal proof provides a credible after-fix validator and schema-load path. Review metrics: 2 noteworthy metrics.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Copy recommended automerge instructionNext step before merge
Maintainer decision needed
Security Review detailsBest possible solution: Obtain explicit sponsorship for the staged experimental registry contract, including its compatibility/versioning and future gate-removal policy; then rebase this foundation and land the stack in its declared order while generic publication remains closed. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR introduces a new experimental package-family capability rather than fixing a currently broken behavior. Its submitted terminal proof provides a credible after-fix validator and schema-load path. Is this the best way to solve the issue? Unclear pending sponsorship: the staged boundary is technically narrow and keeps generic publication closed, but maintainers must first accept the durable storage and compatibility contract that the later stack will build on. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against a9775fc39b10. Label changesLabel justifications:
Evidence reviewedWhat I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
Review history (4 earlier review cycles)
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Updated at 821c1f4 after merging current main. The shared schema now matches the RFC sidecars for managed avatars, normalized workspace collisions, exact package-kind identity, Claw heartbeat/delay fields, portable MCP declarations, and five-field timezone-bound cron jobs without current-session leakage. The review-found multi---package bypass is fixed by validating every -p/--package selector. Proof: 23 focused tests, full ci:static and ci:types-build, built-schema plus Convex-schema positive/negative consumer runs, and a clean final Codex branch review. The PR body explicitly notes that no reusable local Convex backend was available rather than overstating that proof. |
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
821c1f4 to
a23ebf6
Compare
|
Refreshed this first slice onto current ClawHub main at �23ebf61. It now matches the final RFC/OpenClaw contract for strict strings, package-manager selection, blocked process env keys, tool-filter syntax, generic bounded image data URLs, and package uniqueness by kind. Focused schema tests/build/type/lint pass; the PR body now includes an inspectable built-schema/Convex load transcript. |
|
@clawsweeper re-review |
|
Final current-main refresh is at �23ebf6113d5. This foundation now enforces the RFC's strict Claw schema, bounded safe-summary contract, exact package-kind identity, full spawned-process environment-key policy, safe workspace/avatar limits, and experimental package-family storage. Focused schema tests (22), schema build/type/lint/format/diff checks, and built consumer plus Convex-schema load proof pass. The cumulative four-PR Codex review is clean. |
|
@clawsweeper re-review |
aea66c0 to
34f3cbe
Compare
|
Independent three-agent review fixes are applied at |
34f3cbe to
dd5fef7
Compare
|
Final exact-head correction: |
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
dd5fef7 to
58b53c7
Compare
|
Rebased onto current ClawHub main and synchronized the manifest contract with the current OpenClaw stack plus portable agent-settings addendum RFC #48. ClawHub validates portable profile/modifier structure without freezing OpenClaw's built-in profile registry; the applying OpenClaw version resolves the selected profile before planning mutation. Exact head: 58b53c7. Focused schema tests pass 25/25; schema build, root typecheck, type-aware lint, format, and diff checks pass. The commit is signed and the PR is mergeable. @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
|
ClawSweeper status: review started. I am starting a fresh review of this pull request: Add experimental Claw package schema This is item 1/1 in the current shard. Shard 15/22. This placeholder means the worker is alive and reading the current context. I will edit this same comment with the actual review when the claws are done clicking. Crustacean status: shell secured, claws on keyboard, evidence pebbles being sorted. |
|
Synced to the portable-core boundary from RFC #48: @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
680cc6b to
6b9a1d0
Compare
|
Rebased the full stack onto current ClawHub |
|
Portable pointer follow-up is fixed at signed head @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
Summary
agentlimited to identity and purpose.metadataand validatesopenclaw.configas a forward-slash package-relative YAML pointer.family: "claw"to storage while keeping publication closed until Add gated Claw publication and profile validation #3090.This is ClawHub PR 1 of 4 for merged OpenClaw RFC #27, updated for the portable-core boundary in RFC #48 and OpenClaw #112773.
The manifest does not embed OpenClaw policy.
metadata.openclaw.configpoints to a package-local profile; unknown metadata remains opaque. This slice validates pointer syntax only. #3090 owns validation of the referenced artifact.Experimental boundary
This PR exposes no publication, discovery, feed, or UI surface. Later surfaces require
CLAWHUB_EXPERIMENTAL_CLAWS=1. The gate is not user consent and does not replace OpenClaw plan-integrity confirmation.Stack
Validation
git diff --checkpass.61bc0f49759c.No live Convex deployment was modified.