Add gated Claw hosted feed and lifecycle proof - #3092
Conversation
|
@giodl73-repo is attempting to deploy a commit to the OpenClaw Foundation Team on Vercel. A member of the Team first needs to authorize it. |
|
CI follow-up on head
Classifying this as baseline CI noise and leaving the Claws patch unchanged. |
|
Codex review: needs maintainer review before merge. Reviewed July 22, 2026, 1:33 AM ET / 05:33 UTC. Summary Reproducibility: not applicable. This PR adds an experimental capability rather than correcting established broken behavior. Its stated real-run proof provides a concrete validation path for the proposed feature. Review metrics: 3 noteworthy metrics.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Next step before merge
Maintainer decision needed
Security Review detailsBest possible solution: Have a maintainer sponsor or decline the staged experimental Claw contract, then land the prerequisite schema, publication, discovery, and hosted-feed slices in order with the deployment gate retained until compatibility and rollout policy are approved. Do we have a high-confidence way to reproduce the issue? Not applicable: this PR adds an experimental capability rather than correcting established broken behavior. Its stated real-run proof provides a concrete validation path for the proposed feature. Is this the best way to solve the issue? Unclear: the gated, separately versioned feed is a coherent implementation approach, but maintainers must first confirm that this registry and public-contract direction is the intended product boundary. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning high; reviewed against a9775fc39b10. Label changesLabel changes:
Label justifications:
Evidence reviewedWhat I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
Review history (3 earlier review cycles)
|
|
Restacked the hosted-feed slice onto refreshed #3091 at |
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
927bd80 to
cf7e473
Compare
|
Restacked and consolidated the hosted-feed slice at cf7e4733. The feed uses the exact artifact digest, safe summary only, disabled 404/no-store behavior, archive link/special-file rejection, and the current OpenClaw CLI contract. The real WSL cross-repo proof passes all 3 tests against OpenClaw #106888 head 3df96efbd320; transcript and exact command are now in the PR body. |
|
@clawsweeper re-review |
cf7e473 to
66fed8f
Compare
|
Final hosted-feed slice is restacked at 66fed8fdd109. Feed entries project exact artifact metadata/digest plus the bounded safe summary, and the lifecycle harness now selects safe extraction by artifact kind for both npm tarballs and legacy ZIP releases. Windows feed/API/unit tests pass (38 passed, 2 expected Linux-only skips), schema/type/lint/format/diff checks pass, and WSL Ubuntu live proof passes 4/4 against OpenClaw #106888 head 3df96efbd320, including real claws add --dry-run --json. The final cumulative Codex review is clean. |
|
@clawsweeper re-review |
11f6dd3 to
8f25cdd
Compare
|
Independent three-agent review fixes are applied at |
7490a7f to
cba388a
Compare
|
Restacked onto #3091 exact head and refreshed the cross-repository proof. The obsolete #106888 reference is gone: the hosted artifact now passes the real OpenClaw dry-run path against #112773 head b5c2836155b8, which includes current #111391 CLAW.md support and the portable agent-settings slice. Exact head: cba388a. The focused feed/API/archive suite passes 36/36, including 7/7 bridge cases and a real claws add --dry-run --json invocation; schema build, root typecheck, type-aware lint, format, and diff checks pass. The commit is signed and the PR is mergeable. @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
cba388a to
9e3e5be
Compare
|
Restacked cleanly on corrected #3091. Exact signed head: @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
9e3e5be to
a7e0b2d
Compare
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
|
ClawSweeper status: review started. I am starting a fresh review of this pull request: Add gated Claw hosted feed and lifecycle proof This is item 1/1 in the current shard. Shard 7/22. This placeholder means the worker is alive and reading the current context. I will edit this same comment with the actual review when the claws are done clicking. Crustacean status: shell secured, claws on keyboard, evidence pebbles being sorted. |
a7e0b2d to
86c9f77
Compare
|
Restacked and upgraded the real bridge fixture to include @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
86c9f77 to
5eb3295
Compare
|
Restacked onto current ClawHub |
5eb3295 to
0c495a6
Compare
|
Restacked and revalidated at signed head @clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. |
0c495a6 to
544c781
Compare
Summary
/v1/feeds/clawsonly whenCLAWHUB_EXPERIMENTAL_CLAWS=1.CLAW.mdplusprofiles/openclaw.ymlreaches real OpenClawclaws add --dry-run --json.This is ClawHub PR 4 of 4 for RFC #27, RFC #48, and OpenClaw #112773.
Stack
Real behavior proof
The exact hosted fixture includes portable identity in
CLAW.mdand restrictive OpenClaw settings in the package-local profile. The bridge downloads exact artifact bytes, verifies feed/artifact integrity, performs safe extraction, resolves scoped package names through the canonical artifact route, and invokes OpenClaw headd255a128a23. OpenClaw validates and loads the sidecar and returns a non-mutating add plan with zero blocked actions.Validation
git diff --checkpass.0c495a6c968d.No public ClawHub deployment or production signing key was used.