Skip to content

release: ClawFix 0.12.0 - #26

Merged
arcabotai merged 24 commits into
mainfrom
release/next-20260727
Aug 2, 2026
Merged

arcabotai merged 24 commits into
mainfrom
release/next-20260727

Conversation

@arcabotai

@arcabotai arcabotai commented Jul 27, 2026 •

Copy link
Copy Markdown
Owner

Status: 0.12.0 published and ready to merge. Tag v0.12.0 and npm provenance resolve to exact reviewed source 5df94480b7b3a43eed4ac76e27471e7b73e28ca6. Final PR head 263274c8bcfcb12986ded6a4e8ae8755d870aefb adds only the post-publication capability receipt and has green exact-head CI.

Summary

Prepare ClawFix 0.12.0 and close the known gaps in published 0.11.2.

  • routes every catalog repair through preflight, apply, verify, and rollback semantics
  • rejects failed, malformed, timed-out, aborted, truncated, partial, or ambiguous process results before verification can create false success
  • preserves explicitly present invalid terminal metadata through catalog adapters for fail-closed engine validation
  • preserves executable modes in packaged TUI launchers and binaries
  • verifies downloaded/extracted glibc, baseline, and musl/Alpine artifacts in real explicitly sized PTYs
  • validates production SSE framing, ordering, completion identity, terminal-event uniqueness, and useful non-whitespace output
  • preserves synthetic-canary identity through database rehydration and excludes it from public and fallback statistics
  • adds bounded free production continuity verification; paid canaries remain opt-in only

PR #26 includes the repair work represented by #27 and now includes the continuity work represented by #30. Those PRs should be treated as superseded rather than merged separately.

Exact-head validation

Candidate head: 5df94480b7b3a43eed4ac76e27471e7b73e28ca6
Candidate tree: 014bb77c208523fdae7d61826d74061c374751e7

Local and GitHub gates:

  • combined Node suite: 519/519 passed
  • focused repair, continuity, and TUI contracts: 146/146 passed
  • remediation proof: 7/7 passed
  • repair validation: 50 scripts, 0 blockers
  • capability generation/check passed
  • runtime dependency audit: 0 vulnerabilities
  • Node 22, Node 24, Bun/OpenTUI, and production-container CI passed
  • exact-head CI: https://github.com/arcabotai/clawfix/actions/runs/30733600195

Disposable-host final-artifact proof:

  • embedded source marker resolves to exact head 5df94480b7b3a43eed4ac76e27471e7b73e28ca6
  • source archive SHA-256: b735b1a8b81b50e64dc7ba7b322c5028c68d2623360a20821e4b6a093ddf52ab
  • Node suite: 519/519 passed
  • focused suite: 120/120 passed
  • Bun/OpenTUI suite: 95/95 passed
  • glibc, baseline, and musl binaries built and passed artifact validation
  • all three final tarballs passed archive/extracted 0755 mode checks and checksum verification
  • all three extracted launchers rendered, accepted typed input, and exited cleanly under their native glibc or Alpine runtime
  • final marker: RELEASE_CANDIDATE_REMOTE_MATRIX=PASS
  • sandbox cleanup verified; remaining Blaxel inventory: []

Independent exact-head integration review: READY, no findings (deleg_75c89a9e)

Publication receipts:

Post-release production proof:

  • merged main commit: 16f655c13c171885883ad4b6335e8bd791c1495c
  • Railway deployment 5711147584: success
  • post-merge main CI: https://github.com/arcabotai/clawfix/actions/runs/30734219341
  • live root, health, stats, and installer checks passed at https://clawfix.dev
  • public installer installed clawfix@0.12.0 and verified npm integrity in a clean Node 22 container
  • fail-closed repair probe passed against the installed public package
  • all three public TUI archives passed checksums, 0755 archive/extracted modes, native-runtime render, real-PTY input, and clean exit
  • GitHub attestations verified for all three public TUI archives
  • final marker: POST_RELEASE_CLEANROOM=PASS
  • no paid production canary was run

Release ordering

The tag, npm package, GitHub release, checksums, attestations, and all three TUI assets were published before merge so Railway could not advertise unavailable artifacts. Capability evidence is published; the merged website, installer, npm package, and downloaded TUI artifacts subsequently passed clean-room verification.

@arcabotai
arcabotai requested a review from felirami as a code owner July 27, 2026 13:09
Cad from Arca and others added 23 commits July 27, 2026 13:10
Distinguish unreadable config from empty values, block repairs with unknown starting state, record partial mutations, and roll back every post-change failure.

Co-authored-by: Felirami <feli@arcabot.ai>
Signed-off-by: Felirami <feli@arcabot.ai>
Co-authored-by: Felirami <feli@arcabot.ai>
Signed-off-by: Felirami <feli@arcabot.ai>
Co-authored-by: Felirami <feli@arcabot.ai>
Signed-off-by: Felirami <feli@arcabot.ai>
Co-authored-by: Felirami <feli@arcabot.ai>
Signed-off-by: Felirami <feli@arcabot.ai>
…ase-continuity-20260801

Signed-off-by: Cad from Arca <cad@arcabot.ai>

# Conflicts:
#	cli/core/repair-catalog.js
…ase-continuity-20260801

Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
(cherry picked from commit 5de40b5)
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
(cherry picked from commit ee33e52)
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
Signed-off-by: Cad from Arca <cad@arcabot.ai>
@arcabotai
arcabotai merged commit 16f655c into main Aug 2, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant