Skip to content

ci: refresh release tools and restore Crabbox capacity - #61

Merged
steipete merged 1 commit into
mainfrom
sweep3/ci-maintenance
Sep 22, 2026
Merged

steipete merged 1 commit into
mainfrom
sweep3/ci-maintenance

Conversation

@steipete

@steipete steipete commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Crabbox warmup failed because the configured 160 GB root disk is smaller than the current image snapshot. Raise it to the required 400 GB so the remote validation environment can start again.

Refresh GoReleaser to 2.18.2 and the reviewed GitHub CLI release-producer pin to 2.101.0. Use Node 26.10.0 for documentation CI and Homebrew’s currently available 26.9.0 for the canonical release producer. Update the matching release contract fixtures and checks without changing application behavior or the Go floor.

Validation: AWS Crabbox passed the documented build, lint, tests, coverage (92.4%), race tests, vet, Node 26.10.0 documentation tests and generated metadata check, and govulncheck (no vulnerabilities). The lease used explicit checksum-verified toolchain setup because the local Actions interpreter does not support setup-go’s cache option. A fresh checkout of the exact PR head also passed actionlint, deadcode, gosec, GoReleaser configuration and six-target snapshot builds, all six binary vulnerability scans, and isolated byte-for-byte reproducibility checks on Crabbox. macOS release-contract validation remains gated by exact-head CI. Independent Codex autoreview found no actionable P0–P2 findings.

@steipete
steipete requested a review from a team as a code owner September 22, 2026 12:11
@clawsweeper

clawsweeper Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 22, 2026
@clawsweeper

clawsweeper Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed September 22, 2026, 8:20 AM ET / 12:20 UTC (Revision 2).

ClawSweeper review

What this changes

The PR increases Crabbox’s root disk to 400 GB and updates release and documentation tools alongside their validation fixtures.

Merge readiness

✅ Ready for maintainer review

The PR remains useful: main still has the older pins and disk size. No actionable defect was found, and the exact-head macOS audit—including release contracts and snapshot reproducibility—passed.

Priority: P2
Reviewed head: 75fd1785a0ac6d51ab31ff12a852a8cb8046603e

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused maintenance patch with consistent fixtures, successful relevant CI, and no actionable findings.
Proof confidence 🌊 off-meta tidepool Not applicable: The collaborator-authored PR is exempt from ordinary contributor proof. Its body reports successful AWS validation; GitHub independently confirms the changed CI path passed snapshots, scans, reproducibility, and macOS release contracts. No stored-data contract or material authority change requires additional proof.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: The collaborator-authored PR is exempt from ordinary contributor proof. Its body reports successful AWS validation; GitHub independently confirms the changed CI path passed snapshots, scans, reproducibility, and macOS release contracts. No stored-data contract or material authority change requires additional proof.
Evidence reviewed 7 items Introduced scope: The pinned base-to-head diff contains seven files and only disk-size, tool-version, and corresponding fixture substitutions; no application logic or permissions change.
Still needed on main: The inspected main blob retains a 160 GB root disk. Main's release producer also retains GoReleaser 2.18.1, Node 26.8.2, and GitHub CLI 2.100.0.
Release boundary preserved: The producer retains canonical executable checks, frozen executable identities, version checks, and pre-execution rechecks. The documented release model already requires exact reviewed tools; the collaborator explicitly proposes refreshing those requirements. Older operator tool installations must use the new versions.
Findings None None.
Security None None.

How this fits together

Crabbox provides remote validation capacity, while CI and the local release producer turn repository source into checked release artifacts. These changes update their capacity and tool requirements without changing the CLI.

flowchart LR
  A[Repository source] --> B[Crabbox validation]
  C[400 GB root disk] --> B
  A --> D[CI checks]
  E[Pinned release tools] --> D
  E --> F[Local release producer]
  A --> F
  D --> G[Validated build artifacts]
  F --> G
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Validation disk capacity 160 GB → 400 GB The increase accommodates the image snapshot reported to prevent Crabbox startup.

Technical review

Best possible solution:

Keep the coordinated tool pins and validation fixtures aligned while retaining the existing credential-free CI and local release safeguards.

Do we have a high-confidence way to reproduce the issue?

Not applicable to the tool refresh; the reported Crabbox capacity failure was not independently reproduced during this read-only review.

Is this the best way to solve the issue?

Yes. Updating the existing pins and fixtures is a focused solution, and the exact-head audit verifies their integration without introducing a parallel release path.

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against 415ff611d515.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: Restoring remote validation capacity and refreshing release tools is bounded infrastructure maintenance.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: The collaborator-authored PR is exempt from ordinary contributor proof. Its body reports successful AWS validation; GitHub independently confirms the changed CI path passed snapshots, scans, reproducibility, and macOS release contracts. No stored-data contract or material authority change requires additional proof.

Evidence

What I checked:

  • Introduced scope: The pinned base-to-head diff contains seven files and only disk-size, tool-version, and corresponding fixture substitutions; no application logic or permissions change. (75fd1785a0ac)
  • Still needed on main: The inspected main blob retains a 160 GB root disk. Main's release producer also retains GoReleaser 2.18.1, Node 26.8.2, and GitHub CLI 2.100.0. (.crabbox.yaml:27, 415ff611d515)
  • Release boundary preserved: The producer retains canonical executable checks, frozen executable identities, version checks, and pre-execution rechecks. The documented release model already requires exact reviewed tools; the collaborator explicitly proposes refreshing those requirements. Older operator tool installations must use the new versions. (scripts/release-local:237, 75fd1785a0ac)
  • Exact-head macOS validation: GitHub reports successful release contract tests, reviewed GitHub CLI installation, GoReleaser snapshot building, binary vulnerability scanning, and reproducibility checks for the reviewed head. Job: https://github.com/openclaw/goplaces/actions/runs/35725729538/job/106738790776 . No repository tests were executed during this read-only review. (.github/workflows/ci.yml:105, 75fd1785a0ac)
  • Reported remote validation: The captured PR body reports successful AWS Crabbox validation, 92.4% coverage, six-target snapshots, vulnerability scans, and byte-for-byte reproducibility. This is contributor-reported evidence; no lease identifier or attached runtime transcript was supplied. The author is a COLLABORATOR, so ordinary external-contributor proof is not a merge gate. (75fd1785a0ac)
  • Prior area ownership: GitHub verifies steipete authored the merged prior toolchain refresh at chore(ci): refresh build pins and strengthen portable checks #52 . Local history also records repeated release-producer work. Some deeper blame and follow-history inspection failed because historical objects could not be retrieved; no source-line introduction claim is made. (scripts/release-local, d7a83610f74e)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-09-22T12:13:58.207Z sha 75fd178 :: needs maintainer review before merge. :: none

@steipete
steipete merged commit 531494a into main Sep 22, 2026
15 checks passed
@vincentkoc
vincentkoc deleted the sweep3/ci-maintenance branch September 25, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant