fix: scope jiti transform cache by OpenClaw install#87745
Conversation
|
Codex review: needs maintainer review before merge. Reviewed May 28, 2026, 4:49 PM ET / 20:49 UTC. Summary PR surface: Source +161, Tests +142. Total +303 across 6 files. Reproducibility: Partially. Source inspection confirms current main uses jiti without OpenClaw-scoped fsCache on the two affected loader paths, and the PR body provides affected logs plus after-fix real jiti proof; I did not independently reproduce the packaged upgrade failure. Review metrics: 1 noteworthy metric.
Merge readiness Overall follows the weaker of proof and patch quality, so missing proof can cap an otherwise strong patch. Rank-up moves:
Risk before merge
Maintainer options:
Next step before merge
Security Review detailsBest possible solution: Merge after current-head CI is green and maintainers accept the focused jiti proof, or request one packaged upgrade smoke if they want end-to-end upgrade evidence before changing cache placement. Do we have a high-confidence way to reproduce the issue? Partially. Source inspection confirms current main uses jiti without OpenClaw-scoped fsCache on the two affected loader paths, and the PR body provides affected logs plus after-fix real jiti proof; I did not independently reproduce the packaged upgrade failure. Is this the best way to solve the issue? Yes, with maintainer acceptance of the proof level. The fix is narrow because it changes the two jiti loader creation points and preserves jiti's documented fsCache opt-outs instead of adding a new OpenClaw config surface. AGENTS.md: found and applied where relevant. Codex review notes: model gpt-5.5, reasoning high; reviewed against b5d90ae4ec39. Label changesLabel changes:
Label justifications:
Evidence reviewedPR surface: Source +161, Tests +142. Total +303 across 6 files. View PR surface stats
What I checked:
Likely related people:
What the crustacean ranks mean
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics. How this review workflow works
|
8aef277 to
fdc2a91
Compare
fdc2a91 to
a6d2da7
Compare
|
Pre-merge verification for PR 87745: Commands run locally before merge: Observed result: Relevant passing CI/proof runs: Known proof gaps: |
Scope jiti filesystem transform caches for OpenClaw plugin loaders by package version and package.json install metadata so stale transforms cannot survive upgrades or package reinstalls. Covers the central plugin module loader and the plugin SDK root alias CJS loader, while preserving jiti filesystem-cache env opt-outs and the TMPDIR cwd guard. Verification: CI run 26601117143 passed; Real behavior proof run 26601445285 passed; CodeQL selected checks passed in run 26601117126; CodeQL Critical Quality plugin-boundary and plugin-sdk-package-contract passed in run 26601117074; OpenGrep PR diff passed in run 26601117137. Refs: openclaw#87745 Thanks @fuller-stack-dev.
Scope jiti filesystem transform caches for OpenClaw plugin loaders by package version and package.json install metadata so stale transforms cannot survive upgrades or package reinstalls. Covers the central plugin module loader and the plugin SDK root alias CJS loader, while preserving jiti filesystem-cache env opt-outs and the TMPDIR cwd guard. Verification: CI run 26601117143 passed; Real behavior proof run 26601445285 passed; CodeQL selected checks passed in run 26601117126; CodeQL Critical Quality plugin-boundary and plugin-sdk-package-contract passed in run 26601117074; OpenGrep PR diff passed in run 26601117137. Refs: #87745 Thanks @fuller-stack-dev.
Scope jiti filesystem transform caches for OpenClaw plugin loaders by package version and package.json install metadata so stale transforms cannot survive upgrades or package reinstalls. Covers the central plugin module loader and the plugin SDK root alias CJS loader, while preserving jiti filesystem-cache env opt-outs and the TMPDIR cwd guard. Verification: CI run 26601117143 passed; Real behavior proof run 26601445285 passed; CodeQL selected checks passed in run 26601117126; CodeQL Critical Quality plugin-boundary and plugin-sdk-package-contract passed in run 26601117074; OpenGrep PR diff passed in run 26601117137. Refs: openclaw#87745 Thanks @fuller-stack-dev.
Scope jiti filesystem transform caches for OpenClaw plugin loaders by package version and package.json install metadata so stale transforms cannot survive upgrades or package reinstalls. Covers the central plugin module loader and the plugin SDK root alias CJS loader, while preserving jiti filesystem-cache env opt-outs and the TMPDIR cwd guard. Verification: CI run 26601117143 passed; Real behavior proof run 26601445285 passed; CodeQL selected checks passed in run 26601117126; CodeQL Critical Quality plugin-boundary and plugin-sdk-package-contract passed in run 26601117074; OpenGrep PR diff passed in run 26601117137. Refs: openclaw#87745 Thanks @fuller-stack-dev.
Summary
TMPDIR/jiti/openclaw/<package-version>/<package-json-mtime-size>so generated transforms cannot be reused across OpenClaw upgrades or package reinstall locations.TMPDIRresolves toprocess.cwd(), and preserve the documentedJITI_FS_CACHE=false/JITI_CACHE=falseopt-out.Evidence from affected logs
product-poller.log:113830dispatched the SeasonalFlush build.product-poller.log:113845recorded builder run29aa0d05failing forbuilder-pipeline-31ab1d36.product-poller.log:113846recorded:TypeError: (0 , _agentHarnessRuntime.projectRuntimeToolInputSchema) is not a function.session-registry.jsonl:32recorded the same failed builder session and error at2026-05-28T16:21:00Z.TMPDIR/jitiwhile the currently installed OpenClaw package exportedprojectRuntimeToolInputSchemacorrectly, which matches a stale transform-cache upgrade failure rather than project code failure.Verification
node scripts/run-vitest.mjs src/plugins/sdk-alias.test.ts src/plugins/plugin-module-loader-cache.test.ts src/plugins/contracts/plugin-sdk-root-alias.test.tsgit diff --checknode scripts/build-all.mjsnode scripts/run-tsgo.mjs -p test/tsconfig/tsconfig.core.test.json --incremental false --tsBuildInfoFile .artifacts/tsgo-cache/core-test-pr87745-fresh.tsbuildinfonode scripts/run-tsgo.mjs -p test/tsconfig/tsconfig.extensions.test.json --incremental --tsBuildInfoFile .artifacts/tsgo-cache/extensions-test.tsbuildinfoAUTOREVIEW_AUTO_TESTS=0 .agents/skills/autoreview/scripts/autoreview --mode branch --base upstream/mainautoreview clean: no accepted/actionable findings reported.Real behavior proof
Behavior addressed: stale unversioned
TMPDIR/jititransforms can survive upgrades and be reused by OpenClaw plugin/runtime jiti loaders; the repair must not regress jiti'sTMPDIR == process.cwd()guard or filesystem-cache env opt-outs.Real environment tested: local OpenClaw source checkout on macOS with Node 24.14.0 and real
jiti2.7.0. The proof usedcreateJiti()against a TypeScript fixture with a stale unversioned cache sentinel present underTMPDIR/jiti.Exact steps or command run after this patch: created a temporary
TMPDIR, wroteTMPDIR/jiti/stale-sentinel.cjs, loaded a TypeScript fixture through realjitiusingbuildPluginLoaderJitiOptions()from this patch, listed generated cache files, and separately checked theJITI_FS_CACHE=falseoption path.Evidence after fix:
{ "loaded": "versioned-cache", "fsCache": "/var/folders/04/4nmxfbmn44d21bwf7cqknhgc0000gn/T/openclaw-jiti-proof-ajI2Bi/jiti/openclaw/2026.5.28/1779995946163-105060", "staleUnversionedStillPresent": true, "generatedFileCount": 1, "generatedFileSample": [ "openclaw-jiti-proof-ajI2Bi-fixture.79ae0ab5.cjs" ], "disabledFsCache": false }Additional validation output:
Observed result after fix: real jiti transformed and loaded the fixture from the versioned OpenClaw cache directory while the stale unversioned sentinel stayed present and unused; the loader options also return
fsCache: falsewhenJITI_FS_CACHE=falsedisables jiti filesystem caching.What was not tested: no package-manager upgrade E2E was run; the focused proof covers the loader/root-alias cache behavior, the real jiti cache placement path, the env opt-out, and the full local build.