Skip to content

feat(telemetry): maintain public vocabulary from stable releases - #29

Merged
vincentkoc merged 2 commits into
mainfrom
fix/telemetry-automatic-release-vocabulary-20261001
Oct 1, 2026
Merged

vincentkoc merged 2 commits into
mainfrom
fix/telemetry-automatic-release-vocabulary-20261001

Conversation

@vincentkoc

@vincentkoc vincentkoc commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Problem and result

Public vocabulary drift previously required a maintainer to regenerate, commit, and deploy names for each OpenClaw release. Build on #27 and #28 by putting that recurring work in the existing Deploy workflow.

Fully paginate stable releases, retain immutable release/tag/commit identities, backfill missed snapshots, and keep historical public names. Generation runs read-only; a separate trusted check job validates the two generated files and runs the existing tests and build. A constrained publisher can fast-forward only those files. The existing deployment job then verifies one 100%-active Worker version tagged with the exact checked commit. Missing or failed deployment receipts remain retryable even when publication already succeeded.

Activation and trust boundary

Draft only. Merging this workflow would enable daily generation at 03:17 UTC, automatic data-only publication to main, and deployment. That operational activation needs separate review and discussion. Nothing has been scheduled, dispatched, deployed, or configured by this PR publication.

  • Reuse the existing GitHub token and Cloudflare repository secret. Scope contents-write to publication and statuses-write to deployment. All privileged jobs are skipped on pull requests.
  • Serialize production runs and reject stale main commits; deploy bot-created commits in the same run because their push does not trigger another workflow.
  • New-name membership trusts the canonical generator and immutable released OpenClaw packaging metadata. The publisher validates artifact structure, retained history, release provenance, and deterministic output; it does not independently re-execute upstream metadata code.
  • Preserve the compiled public-only allowlist. No client-derived names, ingestion-time catalog requests, collection changes, or rewriting of historical reports.
  • Automatic bundled-release backfill starts at v2026.9.7; earlier retained catalog history is broader but does not prove every transient older bundled name. Freshness can lag until the next daily run, plus GitHub scheduler and queue delays. Manual recovery remains available. Changed contracts, moved tags, byte-budget growth, and publication-policy failures still need maintainer review.

Evidence

  • 84 focused tests pass across maintenance, generator, and payload suites, including real fast-forward publication races, artifact path/symlink/code rejection, incomplete pagination, retained-history checks, deployment retry states, exact-version verification, historical source replay, and the full-vocabulary storage budget.
  • Actual read-only discovery processed all 249 published/draft release records across three pages and correctly produced no refresh against the current retained stable release.
  • Node syntax, actionlint, offline vocabulary consistency, and git diff checks pass. Both independent source reviews found no actionable findings.
  • Historical implementation CI passed for 3a2b7eeb3470f974dc0dfbe19da158fe4baef6a2: typecheck, all 14 test files, release coverage, and Wrangler dry-run. CodeQL also passed. Discovery, generation, publication, and deployment jobs were skipped. No live end-to-end automation or deployment test was run.

Production scripts: +262/-2 (net +260); workflow: +175/-3 (net +172); tests: +205/-1 (net +204). The growth implements release completeness/provenance, the data-only publication boundary, concurrency, and rollout recovery. Worker runtime code, dependencies, stored columns, and the current vocabulary are unchanged.

The daily-cadence update at 39440071640f06323b6f377f0eb2f1e2ac145166 changes only the scheduled cron and matching documentation (+6/-6 across three files). Actionlint, diff checks, and independent delta review pass. Fresh exact-head PR CI passes on this daily-cadence head, including the normal check, release coverage, and Wrangler dry-run. CodeQL passes; discovery, generation, publication, and deployment are skipped. Historical CI above remains attributed to its original head.

@clawsweeper

clawsweeper Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 1, 2026
@clawsweeper

clawsweeper Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed October 1, 2026, 3:21 AM ET / 07:21 UTC (Revision 2).

ClawSweeper review

What this changes

Add daily stable-release discovery, historical vocabulary backfill, validated data-only publication, and exact-commit deployment verification to telemetry’s existing workflow.

Merge readiness

⛔ Blocked before merge - 4 items remain

This remains distinct from the merged vocabulary repairs and has no identified blocking code defect. The daily schedule preserves the unresolved decision to authorize automatic publication and production deployment; the author’s MEMBER association also prevents automatic closure.

Priority: P2
Reviewed head: 39440071640f06323b6f377f0eb2f1e2ac145166
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) The implementation is coherent and well bounded, with no actionable findings; activation approval remains separate from patch quality.
Proof confidence 🌊 off-meta tidepool Not applicable: MEMBER-authored work is exempt from the ordinary contributor proof gate. Supplied discovery exercised real read-only release lookup with no refresh; publication and deployment were skipped. Additive provenance metadata preserves existing snapshots, rendering, and Worker storage contracts.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: MEMBER-authored work is exempt from the ordinary contributor proof gate. Supplied discovery exercised real read-only release lookup with no refresh; publication and deployment were skipped. Additive provenance metadata preserves existing snapshots, rendering, and Worker storage contracts.
Evidence reviewed 10 items Introduced implementation: The pinned main-to-head delta adds discovery, isolated generation, artifact validation, publication, and rollout receipts. Privileged production jobs exclude pull-request events.
Current main still requires manual refresh: Main checks release coverage and deploys checked source, but has no scheduled discovery or data publication. #28 is verified merged; it supplies release metadata support rather than this automation.
Publication and authority boundaries: The publisher revalidates bounded regular files, retained snapshots, release identities, and deterministic TypeScript; it installs no dependencies and publishes only the two vocabulary files using a guarded fast-forward. New-name membership deliberately trusts the canonical generator and released packaging metadata.
Findings None None.
Security None None.

How this fits together

Telemetry filters reported feature names through a compiled public vocabulary before recording analytics. This workflow derives that vocabulary from released OpenClaw metadata, publishes validated updates, and deploys the Worker.

flowchart LR
  A[Stable OpenClaw releases] --> B[Daily release discovery]
  B --> C[Isolated vocabulary generation]
  C --> D[Trusted artifact validation]
  D --> E[Data-only publication]
  E --> F[Worker deployment]
  F --> G[Exact-commit rollout receipt]
Loading

Decision needed

Question Recommendation
Should merging enable daily writes to main and production deployment under the documented upstream-generator trust boundary? Hold activation for operational approval: Keep the draft pending approval of publication permissions, generator trust, and a controlled rollout verification.

Why: This grants recurring operational authority, and the PR explicitly reserves activation for separate review; changing cadence does not establish approval.

Before merge

  • Resolve merge risk (P1) - Merging immediately authorizes daily vocabulary publication to main and production deployment, including trust in released upstream generator output for new-name membership; separate operational approval is still outstanding.
  • Resolve merge risk (P1) - The production publication and rollout-recovery path has not been exercised end to end; repository write permissions, deployment credentials, and live receipt handling remain operationally unverified.
  • Complete next step (P2) - Obtain explicit approval for daily publication and production deployment, including generator trust and acceptance or resolution of the unverified live rollout path.
  • Resolve maintainer decision - Resolve the maintainer decision shown above before merge.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Implementation growth Production scripts +262/-2; workflow +175/-3; tests +205/-1 The body justifies the growth through release provenance, constrained publication, serialization, and rollout recovery.

Merge-risk options

Maintainer options:

  1. Stage activation (recommended)
    Keep the workflow inactive until operational authority is approved and publication plus rollout recovery are validated.
  2. Accept the rollout uncertainty
    Explicitly approve immediate daily activation with ownership of permission failures and unverified live deployment recovery.

Technical review

Best possible solution:

Adopt automatic maintenance through an explicitly approved rollout that preserves manual recovery and verifies data-only publication and exact-commit deployment.

Do we have a high-confidence way to reproduce the issue?

Not applicable to a proposed automation capability. Source confirms that main still relies on manual refresh and lacks this scheduled publication path.

Is this the best way to solve the issue?

Yes, extending the existing generator and deployment workflow avoids a competing implementation; operational adoption still needs explicit approval.

AGENTS.md: not found in the target repository.

Codex review notes: model internal, reasoning medium; reviewed against 6a440445c2e2.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This is a bounded operational improvement without evidence of an urgent current user-facing outage.
  • merge-risk: 🚨 automation: The diff enables recurring writes and production deployments whose live permissions and recovery behavior have not been exercised.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: MEMBER-authored work is exempt from the ordinary contributor proof gate. Supplied discovery exercised real read-only release lookup with no refresh; publication and deployment were skipped. Additive provenance metadata preserves existing snapshots, rendering, and Worker storage contracts.

Evidence

What I checked:

  • Introduced implementation: The pinned main-to-head delta adds discovery, isolated generation, artifact validation, publication, and rollout receipts. Privileged production jobs exclude pull-request events. (.github/workflows/deploy.yml:22, 39440071640f)
  • Current main still requires manual refresh: Main checks release coverage and deploys checked source, but has no scheduled discovery or data publication. fix(telemetry): refresh public vocabulary from released metadata #28 is verified merged; it supplies release metadata support rather than this automation. (.github/workflows/deploy.yml:14, 6a440445c2e2)
  • Publication and authority boundaries: The publisher revalidates bounded regular files, retained snapshots, release identities, and deterministic TypeScript; it installs no dependencies and publishes only the two vocabulary files using a guarded fast-forward. New-name membership deliberately trusts the canonical generator and released packaging metadata. (scripts/vocabulary-maintenance.mjs:123, 39440071640f)
  • Explicit activation remains unapproved: The captured PR body explicitly requests separate operational review before activation. README documents that merging enables daily generation, writes to main, and deployment. No human reviews were returned by the review endpoint. (README.md:286, 39440071640f)
  • Re-review continuity: The previous completed review reported no findings and required activation approval. GitHub’s exact-head commit patch confirms that the follow-up changes only cron and matching documentation from hourly to daily; it does not change the publication boundary. (.github/workflows/deploy.yml:10, 39440071640f)
  • Compatibility and supplied validation: The committed metadata adds release provenance while preserving snapshots and generated names. The existing renderer ignores the additive release field, and Worker storage/configuration are unchanged. The body reports real read-only discovery with no refresh and passing focused tests, while expressly stating that publication and deployment were not exercised. (scripts/public-vocabulary.mjs:122, 39440071640f)

Likely related people:

  • Vincent Koc: Raw commit 6a44044 adds scripts/public-vocabulary.mjs:64 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: 6a440445c2e2; files: scripts/public-vocabulary.mjs)
  • unknown: The claimed source-line change could not be verified from bounded local history. (role: source history unknown; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Validate data-only publication, exact-commit rollout receipts, and recovery after a published commit’s failed deployment in a controlled environment.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-10-01T07:04:20.227Z sha 3a2b7ee :: blocked before merge. :: none

@vincentkoc

vincentkoc commented Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

Daily activation is approved and landed as 133ff8562f721cbe3cea3683523e058afae6e0ac: the 03:17 UTC release poll, validated data-only publication, and the existing production deployment path use the documented released-generator trust boundary.

Fresh Astra/high autoreview of the complete main-to-head diff at 39440071640f06323b6f377f0eb2f1e2ac145166 completed with no actionable P0–P2 findings. Exact-head checks and CodeQL passed; independent source and lifecycle reviews were clean.

Post-merge verification:

  • Normal main run passed discovery, checks, and deployment, including exact-commit Worker tag verification at 100% traffic.
  • One manual recovery run passed on the same unchanged main commit, verified its 100% rollout, and wrote a fresh successful telemetry/deploy receipt.
  • Neither run needed new vocabulary, so generation and publication were skipped. Read-only planner evaluation with live release and status inputs returned no refresh and no deployment for a scheduled poll; manual recovery intentionally redeploys.

ClawSweeper rank-up disposition: live generated-change publication awaits a real new stable release; we did not fabricate released source, ingestion traffic, or a production failure merely to exercise it. This operational uncertainty is accepted. Deterministic tests cover publication races and failed/missing receipt retries. The first real scheduled execution remains future; manual recovery is not evidence of the scheduled trigger itself.

@vincentkoc
vincentkoc marked this pull request as ready for review October 1, 2026 07:30
@vincentkoc
vincentkoc merged commit 133ff85 into main Oct 1, 2026
8 checks passed
@vincentkoc
vincentkoc deleted the fix/telemetry-automatic-release-vocabulary-20261001 branch October 1, 2026 07:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant