fix: unblock development reports after QQbot externalization - #300
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 8, 2026, 9:17 AM ET / 13:17 UTC. ClawSweeper reviewWhat this changesRemoves the retired bundled QQbot fixture, adopts the inspector’s registration-capture repair, and refreshes fixture expectations, documentation, and reports. Merge readiness⛔ Blocked before merge - 3 items remain This remains useful work: current main retains the failing development selection, and the related alternative is unmerged. No concrete blocking defect was found in the introduced patch. Priority: P2 Review scores
Verification
How this fits togetherCrabpot checks plugin fixtures against OpenClaw host contracts and publishes compatibility dashboards. Its fixture manifest selects packages, while the separate plugin-inspector dependency supplies inspection and registration capture. flowchart LR
A[Fixture manifest] --> B[Selected plugin packages]
C[OpenClaw host checkout] --> B
B --> D[Plugin inspector]
D --> E[Registration capture and probes]
E --> F[Compatibility reports]
F --> G[Dashboard]
Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Keep the seven supported development fixtures and existing Tencent Git coverage, with the upstream capture repair adopted through the normal resolver and source/package provenance kept explicit. Do we have a high-confidence way to reproduce the issue? Yes: the development selection reaches the source materializer’s missing-package failure, and the discussion records the failing runs. This review inspected that path without executing target code. Is this the best way to solve the issue? Yes: removing the retired duplicate mapping and adopting the repair from its existing dependency owner is a narrow solution that preserves Tencent coverage and avoids vendoring inspector logic. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 6b9357f69452. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
|
|
Landing-gate disposition for Pinned-cache acquisition/use: both review items and the sole Rank-up move are addressed. Required Check https://github.com/openclaw/crabpot/actions/runs/34230280555 passed, including aggregate job The three hosted report artifacts are Ubuntu This is bounded hosted module-location plus resolver-contract proof. No separate cache archive, standalone checkout attestation, npm release or package/source parity is claimed. Ordinary npm CLI evidence remains the older published 0.3.24 artifact. Scheduled development publication: staged post-merge verification is the accepted mitigation. The natural scheduled workflow must run after landing to observe the repaired main checkout. Publication is not yet demonstrated by the local preview or PR checks. After merge, we will observe the existing schedule without manual dispatch, verify its actual checkout SHA and source/fixture inputs, inspect report artifacts and failures, then verify the published A green workflow alone will not establish publication recovery: report failures or fallback outcomes remain visible. Any new owner failure stops completion with its exact evidence preserved. No workflow, pin, threshold, timeout or fallback change is included in this disposition. |
Related: #287
Additional instructions
Maintainer edits use repository write permissions on this same-repository branch; GitHub's fork-only Allow edits from maintainers toggle does not apply. This is a draft; required CI, the latest ClawSweeper findings/Rank-up dispositions, and final maintainer approval remain landing gates.
What Problem This Solves
Resolves a problem where development dashboard runs stop on the retired bundled QQ Bot source package, then encounter registration-capture failures in surviving source-packed plugins.
Why This Change Was Made
Remove the obsolete
openclaw-qqbotfixture and its owned selection, exception, npm shim/lock, inventory, tests, and generated projections. Preserve the separate TencentqqbotGit fixture at7ceb7f0913d15417c5a74d82442a672ef0382c64, including its valid upstream plugin IDopenclaw-qqbot.Adopt the already-landed inspector source repair from openclaw/plugin-inspector#70 through the existing source resolver. Ordinary CLI smoke stays on the older published
@openclaw/plugin-inspector@0.3.24; that registry artifact contains source92db8c57, not the adopted repair.Thanks to @steipete for investigating the externalized QQ Bot fixture in #287. This separately reviewed replacement preserves existing Tencent Git coverage instead of adding that PR's different Tencent npm fixture and diagnostic helper. Its branch is untouched; it remains open until replacement landing and equivalence are confirmed. This does not adopt the unrelated refresh in #295 or Tencent pin update in #216.
User Impact
The supported development selection becomes seven source-packed fixtures; the full/default inventory becomes 59. Existing generators produce the tracked full/default README and reports, with development output kept separate. No new executable path, dependency, option, host pin, timeout, policy threshold, fallback, workflow, or release is introduced.
Evidence
All local fixture execution ran in disposable credential-free containers with networking disabled during capture, synthetic, and native execution. Public dependency preparation was separate, with install scripts disabled.
92db8c57and passes on adopted84ede904. Existing source-routing test file passes 5/5, including a real missing-registration nonzero exit.no-register-export.fullandfull:register, measured captured count six/lifecycle count three, zero failures and no fallback. This is the native probe, not all fixture lifecycles or native tool-contract acceptance.395e1e756e69ff501483b44befaf0af8d9cdf860, tree4d0693f5ae4599ed101ca913ac6c23f6d712e0d6. Final base merge below preserves that entire tree.Development suite command:
Exact inputs and output binding
c60398861b74da037dc3399c8efb8b7f384e0cc7; generated commit395e1e756e69ff501483b44befaf0af8d9cdf860.c99c600a8b32fe31a6f2dca09edf4ffee384700b. Mechanical merge of output-only main6b9357f694521aaa4f9feaada516145f49b1acf7, using--no-log; full message contains no CI-skip directive. Entire tree remains4d0693f5ae4599ed101ca913ac6c23f6d712e0d6. Tests are attributed to their actual source input, not relabeled as new runs.84ede904fd6e766a9fc4de002f39af87d90c1916, tree10168a46665e659a4efafc86f1f640d255b7ad92, explicitly bound throughCRABPOT_PLUGIN_INSPECTOR_DIR.89fcceb655c193604bfef0f73e5c23871ea0c3dd, tree4f382d75663aa4ecb55394ea0f298b3d47a48c2d; Node 24.20.0, npm 11.19.0, pnpm 12.3.4. Accepted frozen registration/native scope, not a latest-whole-host behavior claim.5570c5ffac86acb74979c7314da6f3364781985a, tree5db1e058954c3776e4f91f341394c0efbad8ad03; Node 22.23.2/npm 10.9.8, inherited exact-lock dependencies.local:default, 59,2026-09-08T12:52:00.642Z. Separate development metadata:local:development, seven,2026-09-08T12:41:59.767Z. Both have empty current run URLs. The separately labeled baseline remainsmain at b326861d5c1ewith its own historical run.2dbd428472296ccb0dec43544256ff3cad52721f11bf9021b396e0d629269868; remote readback matches committed/exported bytes. All 28 generated changes match their default archive.90c31206506a9d99f5475676c69e632b58cc2403. Actual cached executable/package bytes match it, with zero local npm matches; capture hash matches old source92db and differs from adopted A. No same-version source package shadowing is claimed as registry proof.Fixture Impact
Fixture Verification
npm testcommand's Node test suite, through the single combined runner: 203/203; no separate duplicate runnode scripts/sync-fixtures.mjs --checkthrough the combined runnernode scripts/run-contract-smoke.mjsthrough the combined runnerNotes