Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
344 lines
12 KiB
TypeScript
344 lines
12 KiB
TypeScript
// Verify Plugin Npm Published Runtime tests cover verify plugin npm published runtime script behavior.
|
|
import { describe, expect, it } from "vitest";
|
|
import {
|
|
collectPluginNpmPublishedRuntimeErrors,
|
|
findPackedPackageReadmePath,
|
|
parseVerifyPublishedPluginRuntimeArgs,
|
|
parseNpmReadmeMetadata,
|
|
readPluginNpmCommandOptions,
|
|
readPositiveIntEnv,
|
|
resolveNpmPackFilename,
|
|
runPluginNpmCommand,
|
|
usage,
|
|
} from "../../scripts/verify-plugin-npm-published-runtime.mjs";
|
|
|
|
describe("plugin npm publish verifier args", () => {
|
|
it("parses help and package specs before npm calls", () => {
|
|
expect(parseVerifyPublishedPluginRuntimeArgs(["--help"])).toEqual({ help: true, spec: "" });
|
|
expect(parseVerifyPublishedPluginRuntimeArgs(["--", "@openclaw/discord@2026.5.2"])).toEqual({
|
|
help: false,
|
|
spec: "@openclaw/discord@2026.5.2",
|
|
});
|
|
});
|
|
|
|
it("rejects unknown and extra args before npm calls", () => {
|
|
expect(() => parseVerifyPublishedPluginRuntimeArgs([])).toThrow(usage());
|
|
expect(() => parseVerifyPublishedPluginRuntimeArgs(["--wat"])).toThrow(
|
|
"Unknown plugin npm verifier option: --wat",
|
|
);
|
|
expect(() =>
|
|
parseVerifyPublishedPluginRuntimeArgs(["@openclaw/discord@2026.5.2", "extra"]),
|
|
).toThrow("Unexpected plugin npm verifier argument: extra");
|
|
});
|
|
});
|
|
|
|
describe("plugin npm publish verifier retry limits", () => {
|
|
it("rejects loose numeric retry env values instead of parsing prefixes", () => {
|
|
expect(() =>
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS", 90, {
|
|
OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS: "2tries",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS: 2tries");
|
|
expect(() =>
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS", 10000, {
|
|
OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS: "1e3",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS: 1e3");
|
|
expect(() =>
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS", 6, {
|
|
OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS: "0",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS: 0");
|
|
});
|
|
|
|
it("accepts strict positive retry env values and defaults", () => {
|
|
expect(readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS", 90, {})).toBe(90);
|
|
expect(
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_README_VERIFY_DELAY_MS", 10000, {
|
|
OPENCLAW_PLUGIN_NPM_README_VERIFY_DELAY_MS: "2500",
|
|
}),
|
|
).toBe(2500);
|
|
});
|
|
});
|
|
|
|
describe("plugin npm publish verifier command limits", () => {
|
|
it("bounds npm command runtime and captured output by default", () => {
|
|
expect(readPluginNpmCommandOptions({})).toStrictEqual({
|
|
encoding: "utf8",
|
|
killSignal: "SIGKILL",
|
|
maxBuffer: 16 * 1024 * 1024,
|
|
stdio: ["ignore", "pipe", "pipe"],
|
|
timeout: 5 * 60 * 1000,
|
|
});
|
|
});
|
|
|
|
it("accepts strict npm command timeout and buffer overrides", () => {
|
|
expect(
|
|
readPluginNpmCommandOptions({
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "33554432",
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "120000",
|
|
}),
|
|
).toMatchObject({
|
|
maxBuffer: 32 * 1024 * 1024,
|
|
timeout: 120000,
|
|
});
|
|
});
|
|
|
|
it("rejects loose npm command timeout and buffer overrides", () => {
|
|
expect(() =>
|
|
readPluginNpmCommandOptions({
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "60s",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: 60s");
|
|
expect(() =>
|
|
readPluginNpmCommandOptions({
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "16mb",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: 16mb");
|
|
});
|
|
|
|
it("runs npm metadata commands with bounded exec options", () => {
|
|
const calls: unknown[] = [];
|
|
const output = runPluginNpmCommand(["view", "@openclaw/discord", "readme"], {
|
|
env: {
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "1024",
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "2500",
|
|
},
|
|
execFileSyncImpl(command: string, args: string[], options: unknown) {
|
|
calls.push({ args, command, options });
|
|
return JSON.stringify("# Discord");
|
|
},
|
|
});
|
|
|
|
expect(output).toBe(JSON.stringify("# Discord"));
|
|
expect(calls).toStrictEqual([
|
|
{
|
|
args: ["view", "@openclaw/discord", "readme"],
|
|
command: "npm",
|
|
options: {
|
|
encoding: "utf8",
|
|
killSignal: "SIGKILL",
|
|
maxBuffer: 1024,
|
|
stdio: ["ignore", "pipe", "pipe"],
|
|
timeout: 2500,
|
|
},
|
|
},
|
|
]);
|
|
});
|
|
});
|
|
|
|
describe("collectPluginNpmPublishedRuntimeErrors", () => {
|
|
it("flags published plugin packages with TypeScript entries and no compiled runtime output", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
spec: "@openclaw/discord@2026.5.2",
|
|
packageJson: {
|
|
name: "@openclaw/discord",
|
|
version: "2026.5.2",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
},
|
|
},
|
|
files: ["package.json", "index.ts"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/discord@2026.5.2 requires compiled runtime output for TypeScript entry ./index.ts: expected ./dist/index.js, ./dist/index.mjs, ./dist/index.cjs, ./index.js, ./index.mjs, ./index.cjs",
|
|
]);
|
|
});
|
|
|
|
it("accepts published plugin packages with explicit runtimeExtensions", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/zalo",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
},
|
|
},
|
|
files: ["package.json", "index.ts", "dist/index.js"],
|
|
}),
|
|
).toStrictEqual([]);
|
|
});
|
|
|
|
it("flags missing explicit runtimeExtensions outputs", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/line",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./src/index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
},
|
|
},
|
|
files: ["package.json", "src/index.ts"],
|
|
}),
|
|
).toEqual(["@openclaw/line@2026.5.3 runtime extension entry not found: ./dist/index.js"]);
|
|
});
|
|
|
|
it("flags runtimeExtensions length mismatches", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/acpx",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts", "./tools.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
},
|
|
},
|
|
files: ["package.json", "dist/index.js"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/acpx@2026.5.3 package.json openclaw.runtimeExtensions length (1) must match openclaw.extensions length (2)",
|
|
]);
|
|
});
|
|
|
|
it("flags blank runtimeExtensions entries instead of falling back to inferred outputs", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/whatsapp",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./src/index.ts"],
|
|
runtimeExtensions: [" "],
|
|
},
|
|
},
|
|
files: ["package.json", "src/index.ts", "dist/index.js"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/whatsapp@2026.5.3 package.json openclaw.runtimeExtensions[0] must be a non-empty string",
|
|
]);
|
|
});
|
|
|
|
it("flags published plugin packages with TypeScript setup entries and no compiled setup runtime", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/line",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
setupEntry: "./setup-entry.ts",
|
|
},
|
|
},
|
|
files: ["package.json", "index.ts", "dist/index.js", "setup-entry.ts"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/line@2026.5.3 requires compiled runtime output for TypeScript entry ./setup-entry.ts: expected ./dist/setup-entry.js, ./dist/setup-entry.mjs, ./dist/setup-entry.cjs, ./setup-entry.js, ./setup-entry.mjs, ./setup-entry.cjs",
|
|
]);
|
|
});
|
|
|
|
it("accepts published plugin packages with explicit runtimeSetupEntry", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/qqbot",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
setupEntry: "./setup-entry.ts",
|
|
runtimeSetupEntry: "./dist/setup-entry.js",
|
|
},
|
|
},
|
|
files: ["package.json", "dist/index.js", "dist/setup-entry.js"],
|
|
}),
|
|
).toStrictEqual([]);
|
|
});
|
|
|
|
it("flags missing explicit runtimeSetupEntry outputs", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/matrix",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
setupEntry: "./setup-entry.ts",
|
|
runtimeSetupEntry: "./dist/setup-entry.js",
|
|
},
|
|
},
|
|
files: ["package.json", "dist/index.js"],
|
|
}),
|
|
).toEqual(["@openclaw/matrix@2026.5.3 runtime setup entry not found: ./dist/setup-entry.js"]);
|
|
});
|
|
|
|
it("flags runtimeSetupEntry without setupEntry", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/twitch",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
runtimeSetupEntry: "./dist/setup-entry.js",
|
|
},
|
|
},
|
|
files: ["package.json", "dist/index.js", "dist/setup-entry.js"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/twitch@2026.5.3 package.json openclaw.runtimeSetupEntry requires openclaw.setupEntry",
|
|
]);
|
|
});
|
|
});
|
|
|
|
describe("resolveNpmPackFilename", () => {
|
|
it("uses the final tarball filename from plain npm pack output", () => {
|
|
const noisyOutput = [
|
|
"npm notice",
|
|
"npm notice package: @openclaw/msteams@2026.5.24-beta.1",
|
|
"openclaw-msteams-2026.5.24-beta.1.tgz",
|
|
"",
|
|
].join("\n");
|
|
|
|
expect(resolveNpmPackFilename(noisyOutput)).toBe("openclaw-msteams-2026.5.24-beta.1.tgz");
|
|
});
|
|
|
|
it("rejects path-like tarball output instead of reading outside the pack directory", () => {
|
|
const unsafeOutputs = [
|
|
"../openclaw-msteams.tgz",
|
|
"nested/openclaw-msteams.tgz",
|
|
"nested\\openclaw-msteams.tgz",
|
|
"/tmp/openclaw-msteams.tgz",
|
|
"C:\\temp\\openclaw-msteams.tgz",
|
|
"openclaw-msteams\u0000.tgz",
|
|
];
|
|
|
|
for (const output of unsafeOutputs) {
|
|
expect(() => resolveNpmPackFilename(output)).toThrow(
|
|
"npm pack did not report a tarball filename",
|
|
);
|
|
}
|
|
});
|
|
});
|
|
|
|
describe("findPackedPackageReadmePath", () => {
|
|
it("finds a root package README without accepting nested documentation files", () => {
|
|
expect(
|
|
findPackedPackageReadmePath(["package.json", "docs/README.md", "README.md", "dist/index.js"]),
|
|
).toBe("README.md");
|
|
expect(findPackedPackageReadmePath(["package.json", "docs/README.md"])).toBe("");
|
|
});
|
|
});
|
|
|
|
describe("parseNpmReadmeMetadata", () => {
|
|
it("accepts non-empty npm readme metadata", () => {
|
|
expect(parseNpmReadmeMetadata(JSON.stringify("# Plugin\n\nInstall it."))).toBe(
|
|
"# Plugin\n\nInstall it.",
|
|
);
|
|
});
|
|
|
|
it("rejects empty or unsupported npm readme metadata", () => {
|
|
expect(parseNpmReadmeMetadata(JSON.stringify(""))).toBe("");
|
|
expect(parseNpmReadmeMetadata(JSON.stringify(null))).toBe("");
|
|
expect(parseNpmReadmeMetadata("{")).toBe("");
|
|
});
|
|
});
|