Conversation
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: steipete <58493+steipete@users.noreply.github.com> OpenClaw-Publication: 6f22cf3b-82c5-4ca7-9d1c-c79f01c7dbd7
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 30, 2026, 1:29 AM ET / 05:29 UTC (Revision 9). ClawSweeper reviewWhat this changesThe branch adds a strictly validated update-outcome receiver, a capability check, separate analytics storage, collection disclosures, and HTTP coverage to the telemetry Worker. Merge readiness⛔ Blocked before merge - 3 items remain Current main does not accept update outcomes, and this PR remains useful. The earlier quota and disclosure findings are resolved; the remaining blocker is telemetry-owner approval of the staged rollout before the default-on companion client is released. Priority: P2 Review scores
Verification
How this fits togetherThe telemetry Worker receives OpenClaw update requests and returns the latest published version. The new path accepts a terminal update outcome and writes bounded labels to a separate analytics dataset when that dataset is bound. flowchart LR
A[OpenClaw update client] --> B[Capability check]
B --> C{Outcome dataset bound?}
C -->|No| D[Unavailable response]
C -->|Yes| E[Outcome upload]
E --> F[Quota and validation]
F --> G[Separate analytics dataset]
F --> H[Latest version response]
Decision needed
Why: The code deliberately leaves collection unavailable in production, and coordinating activation with the companion release requires an accountable telemetry-owner decision. Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Merge the receiver only after the telemetry owner approves the staged sequence; separately bind the outcome dataset and verify delivery and retention before the companion client release. Do we have a high-confidence way to reproduce the issue? Not applicable as a feature PR. Current main lacks this receiver, while the branch's local Worker HTTP harness exercises the new path. Is this the best way to solve the issue? Yes for the receiver implementation: strict validation and separate storage preserve the daily telemetry path. The staged production sequence still needs telemetry-owner approval. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 7388b9e26064. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (8 earlier review cycles)
|
Accept bounded extended-stable patch versions in all four outcome fields. Clarify update-policy controls and require receiver readiness before releasing the default-on client. Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Merge pinned upstream main 1d9ff5c, preserving its compiled vocabulary and refreshed Worker tooling. Check GET/POST recording quota once before reading an upload. Add the no-side-effect HEAD capability handshake and keep UPDATE_RESULTS out of automatic production deployment pending separately authorized rollout. Document default-on update policy, strict wire shape, and two-request attempts; verify bounded unfinished streams and real local workerd HTTP. Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: steipete <58493+steipete@users.noreply.github.com> Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Keep the custom-endpoint exception scoped to daily checks and schema-1 feature reports, matching the companion client implementation and tests. Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: steipete <58493+steipete@users.noreply.github.com> Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
Correct both privacy-page statements: CI always suppresses update outcomes, including with a replacement endpoint. Preserve the daily-check and optional-feature exception, and cover both disclosures in public-surface tests. Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: steipete <58493+steipete@users.noreply.github.com> Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
|
@steipete @vincentkoc — Json (@fuller-stack-dev) renewed the request to land both update-ping PRs. Please review exact receiver head Both rendered CI statements are corrected: truthy CI always suppresses outcomes, even with a replacement endpoint. Regression reproduced RED, then 4/4 focused and 492/492 full tests passed; standard pre-commit AutoReview P0–P2 (no custom prompt) is scoped-clean; exact-head CI is green.
|
Refresh Cloudflare Workers types to 5.20260930.1, Vitest to 5.0.2, and Wrangler to 4.144.0 with the matching workerd 1.20260926.1 install-script allowance and npm lockfile. Remote Linux validation with Node 24.19.0 and npm 11.17.0 passed npm ci, npm run check (406 tests in 12 files, vocabulary consistency, and TypeScript), the Wrangler dry-run build, npm audit (zero vulnerabilities), and npm outdated (no outdated direct dependencies). Independent Codex AutoReview found no actionable P0–P2 findings.
Integrate current main's Worker tooling, preserve the separately bound schema-2 receiver and capability handshake, and add the maintainer changelog entry with contributor credit. Production UPDATE_RESULTS remains unbound. Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com> Co-authored-by: steipete <58493+steipete@users.noreply.github.com> Co-authored-by: vincentkoc <25068+vincentkoc@users.noreply.github.com>
|
Landed as Fresh remote Linux proof on Node 24.19.0/npm 11.17.0: Exact-head PR CI passed. The resulting main check, deployment, and CodeQL checks are green: https://github.com/openclaw/telemetry/actions/runs/36673816182. The receiver is staged unbound: UPDATE_RESULTS remains absent from the production configuration, and this merge does not activate outcome collection. Production dataset activation and delivery/retention verification remain separate prerequisites before releasing or activating the paired default-on client. No production outcome submissions or dataset provisioning were performed here. |
Summary
Add a receiver for strictly validated, identifier-free terminal update outcomes on
POST /api/latest-version, with a side-effect-free HEAD capability check. Schema-2 outcomes use a separate optional dataset and never fall back to daily telemetry. The existing recording quota is checked once before reading uploads, preserving fast version answers for exhausted callers with unfinished bodies.The contract accepts 18 mandatory public-label fields, rejects unknown keys, malformed UTF-8, and uploads over 4096 bytes, and stores no identifiers, geography, raw User-Agent, logs, or free-form diagnostics. Documentation and the rendered disclosure explain the companion client's default-on outcome policy and unconditional CI suppression. Daily checks and optional schema-1 feature statistics retain their existing behavior.
Staged rollout
UPDATE_RESULTSis deliberately absent from production configuration. Merging deploys the unbound receiver through the existing main-push workflow; HEAD returns 503 without capability until a separately authorized rollout supplies the outcome binding. Dataset delivery and retention must be verified before releasing or activating the default-on companion client in openclaw/openclaw#154067. Capability is not production-readiness proof. No production outcome requests, dataset provisioning, credentials changes, or manual deployment are part of this PR.Validation
Current candidate:
00c6a4325f638284f178a0eb8c7ac7b577d55278, integrating main's refreshed tooling. The original contributor commits and all three human co-author trailers are preserved; the maintainer added the Unreleased entry.npm ci && npm run check && npx wrangler deploy --dry-run && npm auditpassed — deterministic vocabulary, TypeScript, 492 tests in 13 files including all 79 outcome tests and all nine workerd HTTP tests, Worker build, and zero vulnerabilities. The build lists only TELEMETRY and RATE_LIMIT; UPDATE_RESULTS remains absent. No production delivery is claimed.Rendered before/after
Actual
renderHomePage()output served over local HTTP in the existing Chrome profile, light theme, 1000 × 1600 viewport, full-page captures. Before is main7388b9e; after is this candidate. Both captures were inspected and contain only the synthetic public disclosure and example payload.Thanks @roboclaw-bot, @fuller-stack-dev, @steipete, and @vincentkoc.