Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
78 commits
Select commit Hold shift + click to select a range
2178da6
feat(browser): pair Chrome with the managed Windows gateway
roboclaw-bot Sep 18, 2026
be2bfa2
feat(browser): request the Chrome Store extension during Windows setup
roboclaw-bot Sep 18, 2026
8d52bde
test(browser): label synthetic gateway credentials explicitly
roboclaw-bot Sep 18, 2026
1449549
chore: ignore local agent validation scratch
roboclaw-bot Sep 18, 2026
f156a25
test(browser): use a noncredential query rejection fixture
roboclaw-bot Sep 18, 2026
136a955
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 18, 2026
ccba823
fix(browser): preserve the native helper runtime in Windows packages
roboclaw-bot Sep 18, 2026
d2624da
test(browser): keep native frame proof responses free of async comple…
roboclaw-bot Sep 18, 2026
f90b195
fix(browser): verify the exact pairing destination and normalize WSL …
roboclaw-bot Sep 18, 2026
0468aae
test(browser): report successful native proof after expected rejections
roboclaw-bot Sep 18, 2026
c1d151d
feat(browser): consolidate Windows Chrome setup ownership
roboclaw-bot Sep 19, 2026
b39910c
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
65a117a
test(browser): include bootstrap suite in CI contract inventory
roboclaw-bot Sep 19, 2026
b47996d
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
6df9a6c
fix(browser): ship the standalone bootstrap publish profile
roboclaw-bot Sep 19, 2026
d9487e8
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
a1be75b
fix(browser): enforce native deadlines and preserve raced registry state
roboclaw-bot Sep 19, 2026
b59dcbe
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
a4e4db8
fix(browser): use Pascal comments in installer code include
roboclaw-bot Sep 19, 2026
63d6112
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
c3b20f7
fix(browser): use supported Inno pointer types and compile early
roboclaw-bot Sep 19, 2026
6dddf3d
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
b048618
test(browser): prove pinned Windows producer and canonical CLI together
roboclaw-bot Sep 19, 2026
d44aa75
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
6b7b56d
test(browser): canonicalize native composition fixture paths
roboclaw-bot Sep 19, 2026
b1cb4b9
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
1e4b9d6
test(browser): audit native ACLs and stage private composed runtime
roboclaw-bot Sep 19, 2026
1de6add
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
a96370d
test(browser): identify redacted private runtime preparation failures
roboclaw-bot Sep 19, 2026
18db5d7
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
e2f28a1
test(browser): resolve private runtime from installed Node launcher
roboclaw-bot Sep 19, 2026
909a5e0
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
a5a5d86
test(browser): validate native fixture against canonical current schema
roboclaw-bot Sep 19, 2026
16117ce
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
d7795a2
fix(browser): serialize native activation with registration retirement
roboclaw-bot Sep 19, 2026
4e3ad46
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
e3db53c
fix(ci): build and settle the native browser proof fixtures
roboclaw-bot Sep 19, 2026
783f178
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
f7659f7
test(browser): trace owned WSL guest settlement on hosted Windows
roboclaw-bot Sep 19, 2026
57fd3b0
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
c6fc223
fix(ci): resolve WSL trace receipt path at step runtime
roboclaw-bot Sep 19, 2026
7bd45d9
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
db2fa48
test(browser): observe WSL exit ordering with pre-armed pidfds
roboclaw-bot Sep 19, 2026
fe82006
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
e849d45
test(browser): prototype acknowledged request-owned WSL settlement
roboclaw-bot Sep 19, 2026
3ab6899
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
2778c1d
fix(test): normalize WSL prototype stdin before broker handoff
roboclaw-bot Sep 19, 2026
8c9dc44
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
657ea9a
fix(test): bind WSL owner proof to the canonical CLI package
roboclaw-bot Sep 19, 2026
f7dc5c5
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
16756d4
fix(ci): use the canonical consumer package-manager pin
roboclaw-bot Sep 19, 2026
edd93f4
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
c8738ea
fix(browser): retain WSL ownership until guest settlement
roboclaw-bot Sep 19, 2026
97e7aa7
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
b8aacce
fix(test): bind forced WSL loss to the exact owned client
roboclaw-bot Sep 19, 2026
2b3ca36
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
dd747b1
test(browser): verify saved Windows profile with the final consumer
roboclaw-bot Sep 19, 2026
0fc4058
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 19, 2026
4278029
test(browser): correct saved-profile fixtures and isolate proof failures
roboclaw-bot Sep 20, 2026
bfcccf8
test(browser): pin reviewed proof fixtures separately from native pro…
roboclaw-bot Sep 20, 2026
de28859
feat(browser): install and pair Chrome with Windows Companion
roboclaw-bot Sep 20, 2026
271a03c
Merge main into Windows Chrome pairing recovery
roboclaw-bot Sep 28, 2026
29772fc
test(browser): recover final consumer proof diagnostics
roboclaw-bot Sep 28, 2026
a5d1625
test(browser): keep final consumer preflight pins coherent
roboclaw-bot Sep 28, 2026
deff95a
test(browser): freeze recovered native proof fixture
roboclaw-bot Sep 28, 2026
6bf6ffd
test(installer): retain migration and browser preservation guards
roboclaw-bot Sep 28, 2026
c23905b
test(browser): resolve pnpm from the nested consumer checkout
roboclaw-bot Sep 28, 2026
58f0eb8
test(browser): bind nested-checkout fixture correction
roboclaw-bot Sep 28, 2026
11827e2
test(browser): use accepted canonical setup discovery waits
roboclaw-bot Sep 28, 2026
a14dc45
test(browser): freeze valid saved-profile CLI acceptance inputs
roboclaw-bot Sep 28, 2026
bef49fd
test(browser): respect generation reuse and diagnose setup admission
roboclaw-bot Sep 28, 2026
b926e7a
test(browser): retain latest setup failure records within bounds
roboclaw-bot Sep 28, 2026
92afaa4
test(browser): freeze idempotent saved-profile proof inputs
roboclaw-bot Sep 28, 2026
37256b7
test: retain setup and migration failure boundaries
roboclaw-bot Sep 28, 2026
9e650dd
test(browser): verify reviewed saved-profile Store recovery
roboclaw-bot Sep 28, 2026
9c604ea
test(browser): freeze reviewed corrected-consumer fixture
roboclaw-bot Sep 28, 2026
aa6cc7f
test(browser): snapshot named browser mutation state incrementally
roboclaw-bot Sep 28, 2026
88958a8
test(browser): freeze bounded native snapshot fixture
roboclaw-bot Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
106 changes: 106 additions & 0 deletions .github/workflows/browser-native-composed-proof.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
name: Browser native composed proof

on:
push:
branches: [openclaw/automatic-chrome-extension-pairing]
paths:
- .github/workflows/browser-native-composed-proof.yml
- scripts/Test-BrowserNativeComposition.mjs
- scripts/Test-BrowserNativeSavedProfile.mjs
- scripts/Initialize-BrowserNativeComposition.ps1
- scripts/BrowserNativePathAudit.cs
- scripts/Control-BrowserNativeProofChild.ps1
- scripts/BrowserNativeProofTiming.mjs
- scripts/BrowserNativeProofTiming.test.mjs
- scripts/BrowserNativeSavedProfile.test.mjs
- scripts/BrowserNativeStateSnapshot.mjs
- scripts/BrowserNativeStateSnapshot.test.mjs
- src/OpenClaw.BrowserBootstrap/**
- src/OpenClaw.BrowserBootstrap.Contracts/**
- src/OpenClaw.Shared/Browser/**
- tests/OpenClaw.BrowserBootstrap.Tests/**

permissions:
contents: read
actions: read

jobs:
composed-native:
runs-on: windows-latest
timeout-minutes: 40
steps:
- uses: actions/checkout@v7
with:
path: producer
fetch-depth: 0
persist-credentials: false
- uses: actions/checkout@v7
with:
repository: openclaw/openclaw
ref: 6cff547216bd3229446d7cc32a7dae667182ef51
path: consumer
persist-credentials: false
- uses: actions/setup-node@v4
with:
node-version: '24.19.0'
- uses: pnpm/action-setup@v4
with:
# The pinned consumer packageManager is the only version authority.
package_json_file: consumer/package.json
run_install: false
- uses: actions/setup-dotnet@v5
with:
dotnet-version: '10.0.x'
- name: Verify proof ordering instrumentation
shell: pwsh
run: node --test producer/scripts/BrowserNativeProofTiming.test.mjs producer/scripts/BrowserNativeSavedProfile.test.mjs producer/scripts/BrowserNativeStateSnapshot.test.mjs
- name: Build and identify the current reviewed producer
shell: pwsh
run: |
$ErrorActionPreference = 'Stop'
if ((git -C producer rev-parse HEAD).Trim() -cne $env:GITHUB_SHA) { throw 'Producer source identity mismatch.' }
dotnet test producer/tests/OpenClaw.BrowserBootstrap.Tests/OpenClaw.BrowserBootstrap.Tests.csproj -c Release
if ($LASTEXITCODE -ne 0) { throw 'Current producer tests failed.' }
dotnet publish producer/src/OpenClaw.BrowserBootstrap/OpenClaw.BrowserBootstrap.csproj -c Release -r win-x64 --self-contained true -p:PublishSingleFile=true -p:IncludeNativeLibrariesForSelfExtract=true -o artifact/tools/browser-bootstrap
if ($LASTEXITCODE -ne 0) { throw 'Current producer build failed.' }
$image = Get-FileHash artifact/tools/browser-bootstrap/OpenClaw.BrowserBootstrap.exe -Algorithm SHA256
@{producerSha=$env:GITHUB_SHA;executableSha256=$image.Hash.ToLowerInvariant()} | ConvertTo-Json -Compress | Set-Content artifact/producer-source.json -Encoding utf8NoBOM
- name: Retain the new producer artifact
uses: actions/upload-artifact@v7
with:
name: browser-native-producer-${{ github.sha }}
path: artifact/
retention-days: 7
- name: Audit original runtime ACLs and create private exact installation
shell: pwsh
run: |
if ((git -C producer rev-parse HEAD).Trim() -cne $env:GITHUB_SHA) { throw 'Producer checkout changed.' }
./producer/scripts/Initialize-BrowserNativeComposition.ps1 -Consumer "${{ github.workspace }}/consumer" -Receipt "${{ runner.temp }}/composed-path-audit.json"
if ($LASTEXITCODE -ne 0) { throw 'Private runtime preparation failed; see redacted path audit.' }
- name: Build exact canonical runtime without changing its source
working-directory: ${{ env.COMPOSED_PRIVATE_CORE }}
shell: pwsh
run: |
$ErrorActionPreference = 'Stop'
if ((git rev-parse HEAD).Trim() -cne '6cff547216bd3229446d7cc32a7dae667182ef51') { throw 'Consumer revision mismatch.' }
pnpm install --frozen-lockfile --store-dir "$env:COMPOSED_PRIVATE_ROOT/store" --package-import-method=copy
if ($LASTEXITCODE -ne 0) { throw 'Pinned consumer dependency install failed.' }
pnpm build:docker
if ($LASTEXITCODE -ne 0) { throw 'Pinned consumer runtime build failed.' }
git diff --exit-code
if ($LASTEXITCODE -ne 0) { throw 'Consumer tracked source changed during build.' }
- name: Execute real management generation admission pairing and rejection chain
shell: pwsh
run: |
& $env:COMPOSED_PRIVATE_NODE producer/scripts/Test-BrowserNativeComposition.mjs "${{ github.workspace }}/artifact" $env:COMPOSED_PRIVATE_CORE "${{ runner.temp }}/composed-native-receipt.json"
if ($LASTEXITCODE -ne 0) { throw 'Composed native proof failed; see redacted receipt.' }
- name: Retain redacted terminal receipt only
if: always()
uses: actions/upload-artifact@v7
with:
name: browser-native-composed-receipt
path: |
${{ runner.temp }}/composed-native-receipt.json
${{ runner.temp }}/composed-path-audit.json
if-no-files-found: warn
retention-days: 7
76 changes: 76 additions & 0 deletions .github/workflows/browser-wsl-guest-trace.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
name: Browser WSL guest component trace

on:
push:
branches: [openclaw/automatic-chrome-extension-pairing]
paths:
- .github/workflows/browser-wsl-guest-trace.yml
- scripts/BrowserWslGuestTrace.py
- tests/OpenClaw.E2ETests/Setup/BrowserWsl*.cs
- tests/OpenClaw.E2ETests/OpenClaw.E2ETests.csproj

permissions:
contents: read

jobs:
guest-trace:
runs-on: windows-latest
timeout-minutes: 40
env:
OPENCLAW_REPO_ROOT: ${{ github.workspace }}
OPENCLAW_RUN_E2E: '1'
OPENCLAW_BROWSER_WSL_TRACE: '1'
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
persist-credentials: false
- name: Verify frozen production and accepted native proof
shell: pwsh
run: |
git diff --exit-code 783f178ca5579d057d4799fceb5cec5e8c4d69f8 HEAD -- src .github/workflows/browser-native-composed-proof.yml scripts/Test-BrowserNativeComposition.mjs scripts/Initialize-BrowserNativeComposition.ps1
if ($LASTEXITCODE -ne 0) { throw 'Frozen production/native proof changed.' }
"OPENCLAW_WSL_TRACE_RECEIPT=$env:RUNNER_TEMP/browser-wsl-guest-receipt.json" >> $env:GITHUB_ENV
- uses: actions/setup-dotnet@v6
with:
dotnet-version: '10.0.x'
- name: Build existing managed WSL setup fixture
shell: pwsh
run: |
dotnet restore src/OpenClaw.Tray.WinUI -r win-x64
if ($LASTEXITCODE -ne 0) { throw 'Tray restore failed.' }
dotnet restore tests/OpenClaw.E2ETests -r win-x64
if ($LASTEXITCODE -ne 0) { throw 'Fixture restore failed.' }
dotnet build src/OpenClaw.Tray.WinUI -c Debug -r win-x64 --no-restore
if ($LASTEXITCODE -ne 0) { throw 'Tray build failed.' }
dotnet build tests/OpenClaw.E2ETests -c Debug -r win-x64 --no-restore
if ($LASTEXITCODE -ne 0) { throw 'Fixture build failed.' }
- name: Trace exact owner in disposable managed WSL fixture
shell: pwsh
run: |
# Existing setup diagnostics may include synthetic fixture credentials.
# Neither raw test output, TRX output sections nor fixture files are uploaded.
$privateLog = Join-Path $env:RUNNER_TEMP 'wsl-trace-private-test.log'
$privateResults = Join-Path $env:RUNNER_TEMP 'wsl-trace-private-results'
dotnet test tests/OpenClaw.E2ETests --no-build -c Debug -r win-x64 --filter FullyQualifiedName~BrowserWslGuestTraceTests --results-directory $privateResults --logger 'trx;LogFileName=trace.trx' *> $privateLog
$testExit = $LASTEXITCODE
if (!(Test-Path $env:OPENCLAW_WSL_TRACE_RECEIPT)) { throw 'No terminal component receipt. Setup/build capability must be diagnosed privately.' }
[xml]$trx = Get-Content (Join-Path $privateResults 'trace.trx')
$cases = @($trx.TestRun.Results.UnitTestResult)
if ($cases.Count -ne 1 -or $cases[0].outcome -ne 'Passed' -or $testExit -ne 0) { throw 'Component trace did not execute and finish all owned cleanup.' }
Write-Host 'Component trace collected; this is not a guest-settlement pass.'
- name: Retain only explicitly redacted component receipt
if: always()
uses: actions/upload-artifact@v7
with:
name: browser-wsl-guest-component-receipt
path: ${{ env.OPENCLAW_WSL_TRACE_RECEIPT }}
if-no-files-found: warn
retention-days: 7
- name: Evaluate guest settlement separately from trace execution
shell: pwsh
run: |
$r = Get-Content $env:OPENCLAW_WSL_TRACE_RECEIPT -Raw | ConvertFrom-Json
if ($r.status -ne 'trace_complete_not_a_settlement_pass' -or $r.cases.Count -ne 6) { throw 'Trace incomplete.' }
if (@($r.cases | Where-Object { $_.settlementVerdict -like 'RED_*' -or $_.settlementVerdict -like 'UNKNOWN_*' }).Count -gt 0) { throw 'RED or UNKNOWN: guest settlement is not established. Inspect redacted receipt.' }
Write-Host 'Persistent pidfd observer receipt is authoritative. Exit-notification precedence is not a reaping or whole-Companion claim.'
154 changes: 154 additions & 0 deletions .github/workflows/browser-wsl-owner-proof.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,154 @@
name: Browser WSL production owner proof

on:
push:
branches: [openclaw/automatic-chrome-extension-pairing]
paths:
- .github/workflows/browser-wsl-owner-proof.yml
- src/OpenClaw.Connection/BrowserBootstrapWsl*
- src/OpenClaw.Connection/OpenClaw.Connection.csproj
- tests/OpenClaw.Connection.Tests/BrowserBootstrap*
- tests/OpenClaw.E2ETests/Prototype/BrowserWslProductionOwnerTests.cs
- tests/OpenClaw.E2ETests/Prototype/BrowserWslLookupDiagnosticsTests.cs
- tests/OpenClaw.E2ETests/Prototype/BrowserWslSetupDiagnostics*.cs

permissions:
contents: read

jobs:
canonical-consumer:
runs-on: ubuntu-latest
timeout-minutes: 60
outputs:
version: ${{ steps.identity.outputs.version }}
sha256: ${{ steps.identity.outputs.sha256 }}
steps:
- uses: actions/checkout@v7
with:
repository: openclaw/openclaw
ref: 6cff547216bd3229446d7cc32a7dae667182ef51
persist-credentials: false
- uses: actions/setup-node@v4
with:
node-version: '24.19.0'
- uses: pnpm/action-setup@v4
with:
# The immutable consumer packageManager includes its integrity-qualified version.
# Do not provide a second, conflicting action version.
run_install: false
- name: Build the immutable canonical CLI, not the published release CLI
shell: bash
run: |
set -euo pipefail
test "$(git rev-parse HEAD)" = 6cff547216bd3229446d7cc32a7dae667182ef51
pnpm install --frozen-lockfile
node scripts/package-openclaw-for-docker.mjs --allow-unreleased-changelog --output-dir "$RUNNER_TEMP/canonical-consumer" --output-name openclaw-current.tgz
git diff --exit-code
- name: Bind the candidate package bytes to their immutable source
id: identity
shell: bash
run: |
set -euo pipefail
node - <<'JS'
const fs=require('fs'),crypto=require('crypto'),path=require('path');
const dir=path.join(process.env.RUNNER_TEMP,'canonical-consumer');
const version=require('./package.json').version;
const sha256=crypto.createHash('sha256').update(fs.readFileSync(path.join(dir,'openclaw-current.tgz'))).digest('hex');
fs.writeFileSync(path.join(dir,'package-candidate.json'),JSON.stringify({sourceSha:'6cff547216bd3229446d7cc32a7dae667182ef51',version,sha256}));
fs.appendFileSync(process.env.GITHUB_OUTPUT,'version='+version+'\nsha256='+sha256+'\n');
JS
- uses: actions/upload-artifact@v7
with:
name: wsl-owner-canonical-consumer
path: ${{ runner.temp }}/canonical-consumer/
retention-days: 7
owner-prototype:
needs: canonical-consumer
runs-on: windows-latest
timeout-minutes: 40
env:
OPENCLAW_REPO_ROOT: ${{ github.workspace }}
OPENCLAW_RUN_E2E: '1'
OPENCLAW_BROWSER_WSL_OWNER_PROOF: '1'
OPENCLAW_WSL_PROTOTYPE_CONSUMER_SHA: 6cff547216bd3229446d7cc32a7dae667182ef51
OPENCLAW_E2E_GATEWAY_VERSION: ${{ needs.canonical-consumer.outputs.version }}
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
persist-credentials: false
- uses: actions/download-artifact@v8
with:
name: wsl-owner-canonical-consumer
path: ${{ runner.temp }}/canonical-consumer
- name: Verify the candidate for the existing fixture package interface
shell: pwsh
env:
EXPECTED_SHA256: ${{ needs.canonical-consumer.outputs.sha256 }}
run: |
$ErrorActionPreference = 'Stop'
$package = Join-Path $env:RUNNER_TEMP 'canonical-consumer/openclaw-current.tgz'
$metadata = Get-Content (Join-Path $env:RUNNER_TEMP 'canonical-consumer/package-candidate.json') -Raw | ConvertFrom-Json
$actual = (Get-FileHash $package -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actual -cne $env:EXPECTED_SHA256 -or $metadata.sha256 -cne $actual -or $metadata.sourceSha -cne $env:OPENCLAW_WSL_PROTOTYPE_CONSUMER_SHA -or $metadata.version -cne $env:OPENCLAW_E2E_GATEWAY_VERSION) { throw 'Canonical package identity mismatch.' }
"OPENCLAW_E2E_GATEWAY_PACKAGE_TGZ=$package" >> $env:GITHUB_ENV
"OPENCLAW_WSL_PROTOTYPE_PACKAGE_SHA256=$actual" >> $env:GITHUB_ENV
- name: Verify frozen production and accepted native proof
shell: pwsh
run: |
# Production remains on its original reviewed baseline; fixture evolution has its own reviewed pin.
git diff --exit-code edd93f4998528cc0362443067db95a1c822e4cf1 HEAD -- src/OpenClaw.BrowserBootstrap src/OpenClaw.BrowserBootstrap.Contracts src/OpenClaw.Shared/Browser
if ($LASTEXITCODE -ne 0) { throw 'Frozen native production changed.' }
git diff --exit-code aa6cc7f828e778f95fa2eb745b80bce4993f362c HEAD -- .github/workflows/browser-native-composed-proof.yml scripts/Test-BrowserNativeComposition.mjs scripts/Initialize-BrowserNativeComposition.ps1 scripts/Test-BrowserNativeSavedProfile.mjs scripts/BrowserNativeSavedProfile.test.mjs scripts/BrowserNativeStateSnapshot.mjs scripts/BrowserNativeStateSnapshot.test.mjs scripts/BrowserNativeProofTiming.mjs scripts/BrowserNativeProofTiming.test.mjs scripts/Control-BrowserNativeProofChild.ps1 scripts/BrowserNativePathAudit.cs
if ($LASTEXITCODE -ne 0) { throw 'Reviewed native proof fixture changed.' }
"OPENCLAW_WSL_OWNER_RECEIPT=$env:RUNNER_TEMP/browser-wsl-production-owner.json" >> $env:GITHUB_ENV
- uses: actions/setup-dotnet@v6
with:
dotnet-version: '10.0.x'
- name: Check private protocol without running Linux service work
shell: pwsh
run: node --test scripts/BrowserWslOwnerPrototype.test.cjs
- name: Build existing managed WSL setup fixture
shell: pwsh
run: |
dotnet restore src/OpenClaw.Tray.WinUI -r win-x64
if ($LASTEXITCODE -ne 0) { throw 'Tray restore failed.' }
dotnet restore tests/OpenClaw.E2ETests -r win-x64
if ($LASTEXITCODE -ne 0) { throw 'Fixture restore failed.' }
dotnet build src/OpenClaw.Tray.WinUI -c Debug -r win-x64 --no-restore
if ($LASTEXITCODE -ne 0) { throw 'Tray build failed.' }
dotnet build tests/OpenClaw.E2ETests -c Debug -r win-x64 --no-restore
if ($LASTEXITCODE -ne 0) { throw 'Fixture build failed.' }
- name: Verify the actual stdin newline normalization
shell: pwsh
run: |
dotnet test tests/OpenClaw.E2ETests --no-build -c Debug -r win-x64 --filter 'FullyQualifiedName~BrowserPrototypeTransportTests|FullyQualifiedName~BrowserWslLookupDiagnosticsTests|FullyQualifiedName~BrowserWslSetupDiagnosticsTests'
if ($LASTEXITCODE -ne 0) { throw 'Prototype stdin transport regression failed.' }
- name: Exercise actual WSL owner and retirement retention in disposable WSL
shell: pwsh
run: |
# Existing setup diagnostics may include synthetic fixture credentials.
# Neither raw test output, TRX output sections nor fixture files are uploaded.
$privateLog = Join-Path $env:RUNNER_TEMP 'wsl-owner-private-test.log'
$privateResults = Join-Path $env:RUNNER_TEMP 'wsl-owner-private-results'
dotnet test tests/OpenClaw.E2ETests --no-build -c Debug -r win-x64 --filter FullyQualifiedName~BrowserWslProductionOwnerTests --results-directory $privateResults --logger 'trx;LogFileName=trace.trx' *> $privateLog
$testExit = $LASTEXITCODE
if (!(Test-Path $env:OPENCLAW_WSL_OWNER_RECEIPT)) { throw 'No terminal component receipt. Setup/build capability must be diagnosed privately.' }
[xml]$trx = Get-Content (Join-Path $privateResults 'trace.trx')
$cases = @($trx.TestRun.Results.UnitTestResult)
if ($cases.Count -ne 1 -or $cases[0].outcome -ne 'Passed' -or $testExit -ne 0) { throw 'Component trace did not execute and finish all owned cleanup.' }
Write-Host 'Actual production-owner receipt collected; full native/consumer pairing remains separately required.'
- name: Retain only explicitly redacted component receipt
if: always()
uses: actions/upload-artifact@v7
with:
name: browser-wsl-production-owner-receipt
path: ${{ env.OPENCLAW_WSL_OWNER_RECEIPT }}
if-no-files-found: warn
retention-days: 7
- name: Evaluate actual owner proof
shell: pwsh
run: |
$r = Get-Content $env:OPENCLAW_WSL_OWNER_RECEIPT -Raw | ConvertFrom-Json
if ($r.status -ne 'production_owner_proof_passed' -or $r.cases.Count -ne 6) { throw 'Actual production-owner proof incomplete.' }
Write-Host 'Actual owner requires guest acknowledgment; missing acknowledgment must keep activation and retirement blocked.'
Loading
Loading