Skip to content

fix(openclaw): pin @openclaw/codex plugin to the core version (#152) - #153

Merged
yalexx merged 2 commits into
mainfrom
beta
May 28, 2026
Merged

yalexx merged 2 commits into
mainfrom
beta

Conversation

@yalexx

@yalexx yalexx commented May 28, 2026 •

Copy link
Copy Markdown
Collaborator

We pin the OpenClaw core (config/openclaw-target.txt) but installed the codex plugin unpinned — openclaw plugins install codex resolves @latest. So the plugin drifts ahead of the pinned core and every Codex chat crashes with "_diagnosticRuntime.createDiagnosticTraceContextFrom ActiveScope is not a function" (the newer plugin calls a runtime API the pinned core doesn't expose). Two customers on the latest ClawBox hit this; "You're up to date" boxes can't self-heal via the updater.

  • gateway-pre-start.sh: read the openclaw-target pin; reinstall codex when its version != the core target (not just when missing/broken); install the scoped pinned spec @openclaw/codex@ instead of the bare @latest alias. Drifted boxes now self-heal on next gateway start.
  • install.sh: the plugin-refresh loop derives each plugin's npm package from rootDir and pins @openclaw/* plugins to $TARGET instead of reinstalling by bare id (which also resolved @latest).
  • bump version 3.0.5 -> 3.0.6 so already-current devices receive the fix.

Validated on a Jetson: forced codex to 2026.5.27 against core 2026.5.22, ran the heal path, confirmed it detected the mismatch and realigned to 2026.5.22.

Summary

Type of change

  • Bug fix (non-breaking)
  • New feature (non-breaking)
  • Breaking change
  • Documentation / tooling
  • Other: ___

How was this tested?

  • bun run lint passes
  • bun run test passes
  • bun run build succeeds
  • Manually verified on device / dev install

Checklist

  • Branch is up to date with the target branch
  • Follows the conventions in CLAUDE.md and CONTRIBUTING.md
  • No secrets, tokens, or credentials committed
  • Added/updated tests where it makes sense
  • Updated docs where user-facing behavior changed

Screenshots / logs (if UI or runtime change)

Summary by CodeRabbit

  • Bug Fixes

    • Improved plugin refresh/install behavior to better preserve compatibility and avoid disruptive reinstalls; non-fatal refresh failures are retained and reported.
    • Enhanced detection and repair for runtime version skew, reinstalling when pinned versions diverge and warning when installs fail.
  • Chores

    • Package version bumped to 3.0.6
  • Tests

    • Updated browser test to verify launch against the production URL.

Review Change Stack

We pin the OpenClaw core (config/openclaw-target.txt) but installed the
codex plugin unpinned — `openclaw plugins install codex` resolves
@latest. So the plugin drifts ahead of the pinned core and every Codex
chat crashes with "_diagnosticRuntime.createDiagnosticTraceContextFrom
ActiveScope is not a function" (the newer plugin calls a runtime API the
pinned core doesn't expose). Two customers on the latest ClawBox hit
this; "You're up to date" boxes can't self-heal via the updater.

- gateway-pre-start.sh: read the openclaw-target pin; reinstall codex
  when its version != the core target (not just when missing/broken);
  install the scoped pinned spec @openclaw/codex@<target> instead of the
  bare @latest alias. Drifted boxes now self-heal on next gateway start.
- install.sh: the plugin-refresh loop derives each plugin's npm package
  from rootDir and pins @openclaw/* plugins to $TARGET instead of
  reinstalling by bare id (which also resolved @latest).
- bump version 3.0.5 -> 3.0.6 so already-current devices receive the fix.

Validated on a Jetson: forced codex to 2026.5.27 against core 2026.5.22,
ran the heal path, confirmed it detected the mismatch and realigned to
2026.5.22.
@yalexx
yalexx requested a review from a team as a code owner May 28, 2026 15:17
@coderabbitai

coderabbitai Bot commented May 28, 2026 •

Copy link
Copy Markdown

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 43b0c8d7-22b5-4f32-a45e-aa37b64343a4

📥 Commits

Reviewing files that changed from the base of the PR and between 941e71d and 90cbbed.

📒 Files selected for processing (1)
  • e2e-install/70-browser.spec.ts

📝 Walkthrough

Walkthrough

Add optional OpenClaw target pin handling; install script refreshes external plugins by deriving npm package names and pins @openclaw/* plugins to the target; gateway startup detects Codex version skew against the pin and reinstalls when needed. E2E test URL updated; package version bumped to 3.0.6.

Changes

OpenClaw Plugin Version Pinning and Alignment

Layer / File(s) Summary
Initialize pinned OpenClaw target version
scripts/gateway-pre-start.sh, package.json
Gateway startup loads OPENCLAW_TARGET from OPENCLAW_PIN_VERSION or clawbox/config/openclaw-target.txt, defaulting to empty; package.json version bumped to 3.0.6.
Refresh external plugins during install with version pinning
install.sh
Install script skips bundled plugins, derives npm package names from node_modules paths, and reinstalls plugins using those package identifiers—pinning @openclaw/* plugins to the core $TARGET while allowing other plugins to resolve independently. Inline docs updated.
Detect and repair Codex version skew at gateway startup
scripts/gateway-pre-start.sh
Gateway startup checks Codex package and peer-dep symlink, compares installed Codex runtime version to OPENCLAW_TARGET when pinned, and reinstalls @openclaw/codex@<target> (or unpinned codex) with --force when needed; failures emit warnings.
E2E browser launch target update
e2e-install/70-browser.spec.ts
Browser-launch test now navigates to https://clawbox.tech/ and asserts the launched URL contains clawbox.tech (previously openclawhardware.dev).

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~22 minutes

Possibly related PRs

  • ID-Robots/clawbox#152: Both PRs modify install.sh and scripts/gateway-pre-start.sh to pin and refresh external OpenClaw plugins to match the core target version.
  • ID-Robots/clawbox#142: Related changes to install.sh's post-core-install plugin refresh flow and handling of bundled vs external plugins.
  • ID-Robots/clawbox#138: Related edits to scripts/gateway-pre-start.sh Codex install/repair behavior.

Suggested reviewers

  • GeorgiK77

Poem

🐰 I hopped through install, sniffed each plugin line,

Pinned the claws to a target, kept versions in line.
Codex was mended at startup with care,
Tests now visit clawbox.tech fair and square.
A small rabbit cheer for builds that align!

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately summarizes the main change: pinning the @openclaw/codex plugin to the core version to prevent version drift and crashes.
Description check ✅ Passed The description is comprehensive and mostly complete, covering the problem statement, solution details, version bump rationale, and validation. Most template sections are addressed with substantive content.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch beta

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions

github-actions Bot commented May 28, 2026 •

Copy link
Copy Markdown

CI Summary

✅ Tests

  • Result: passed
  • View run
  • Coverage: statements 70.94%, branches 60.32%, functions 66.78%, lines 73.12%

✅ E2E

✅ E2E Install

@coderabbitai

coderabbitai Bot commented May 28, 2026

Copy link
Copy Markdown

Actionable comments posted: 0

KrasimirKralev
KrasimirKralev previously approved these changes May 28, 2026

@KrasimirKralev KrasimirKralev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I approve

The browser install test navigated to openclawhardware.dev, but the
main domain is now clawbox.tech. Update the navigation target, title,
assertion, and comment accordingly.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 28, 2026

Copy link
Copy Markdown

Actionable comments posted: 0

@yalexx
yalexx merged commit e2e3b1a into main May 28, 2026
9 of 13 checks passed
@yalexx
yalexx deleted the beta branch May 28, 2026 19:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants