Skip to content

S15.g.1: split OpenClaw runtime adapter into runtimes/openclaw/ package - #107

Merged
Pal Lakatos-Toth (pallakatos) merged 2 commits into
devfrom
phase2-runtime-package-split-g1
Apr 29, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 2 commits into
devfrom
phase2-runtime-package-split-g1

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Mechanical move. Lifts the AzureClaw runtime adapter for OpenClaw out of cli/src/ into its own top-level package runtimes/openclaw/, sibling to the future runtimes/openai-agents/ and runtimes/maf/ adapters (S10.A3 + S10.A4). No behaviour change.

Old path New path
cli/src/plugin.ts runtimes/openclaw/src/index.ts
cli/src/core/ runtimes/openclaw/src/core/
cli/src/plugin.test.ts runtimes/openclaw/src/index.test.ts
cli/src/redact.test.ts runtimes/openclaw/src/redact.test.ts
cli/src/router-url.test.ts runtimes/openclaw/src/router-url.test.ts
cli/openclaw.plugin.json runtimes/openclaw/openclaw.plugin.json

What changed besides the moves

  • New runtimes/openclaw/{package.json,tsconfig.json,.gitignore} — @azureclaw/runtime-openclaw. Deps narrowed to the actual surface (@agentmesh/sdk + commander); operator-CLI-only deps stay in cli/package.json.
  • sandbox-images/openclaw/Dockerfile cli-builder stage repointed to runtimes/openclaw/. The policy-engine/profiles/ copy was removed from this stage because it's only consumed by cli's own build script (host-side azureclaw dev seccomp staging) — the in-sandbox runtime adapter never reads those JSONs. cli's own build pipeline still produces them for the operator CLI tarball.
  • ci/loc-budget.yaml entry repointed: cli/src/plugin.ts → runtimes/openclaw/src/index.ts.
  • .github/workflows/ci.yml adds new Runtime OpenClaw Build & Test job at parity with cli-build and mesh-plugin-build.

Verification

  • cd runtimes/openclaw && tsc / lint (23 warn) / test (100 pass) / build — all clean.
  • cd cli && tsc / lint (16 warn) / test (354 pass / 2 skipped) / build — all clean. Test count is −100 vs pre-S15.g.1 because three test files followed the source.

Risk + rollback

  • Risk: medium. Sandbox Dockerfile path rewrite is the functional risk surface — Kind smoke + image rebuild covered by S16 chaos-tier.
  • Rollback: revert this PR.

Audit doc: docs/security-audits/2026-04-29-phase2-runtime-package-split-g1.md.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

Pal Lakatos-Toth and others added 2 commits April 29, 2026 23:06
Mechanical move. Lifts the AzureClaw runtime adapter for OpenClaw out
of cli/src/ into its own top-level package runtimes/openclaw/, sibling
to the future runtimes/openai-agents/ and runtimes/maf/ adapters
(S10.A3 + S10.A4). No behaviour change.

Moves (git mv preserves history):
  cli/src/plugin.ts            → runtimes/openclaw/src/index.ts
  cli/src/core/                → runtimes/openclaw/src/core/
  cli/src/plugin.test.ts       → runtimes/openclaw/src/index.test.ts
  cli/src/redact.test.ts       → runtimes/openclaw/src/redact.test.ts
  cli/src/router-url.test.ts   → runtimes/openclaw/src/router-url.test.ts
  cli/openclaw.plugin.json     → runtimes/openclaw/openclaw.plugin.json

New runtimes/openclaw/{package.json,tsconfig.json,.gitignore} —
@azureclaw/runtime-openclaw, narrowed deps (@agentmesh/sdk +
commander only; operator-CLI-only deps stay in cli/).

Sandbox Dockerfile cli-builder stage repointed to runtimes/openclaw/.
ci/loc-budget.yaml entry repointed. New 'Runtime OpenClaw Build &
Test' CI job at parity with cli-build and mesh-plugin-build.

Verification: cd runtimes/openclaw && tsc / lint / test (100 pass) /
build all clean. cd cli && tsc / lint / test (354 pass / 2 skipped) /
build all clean.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…s/ in CI gates

Folder rename. The top-level 'policy-engine/' directory contained one
seccomp JSON used only by host-side 'azureclaw dev' (cli/src/commands/
dev.ts:471). The name implied a runtime engine that doesn't exist, and
the deployed AKS seccomp profile actually lives at deploy/seccomp/ and
is loaded by the Helm seccomp-installer DaemonSet — this cli artifact
was misleadingly co-located at the repo root.

  policy-engine/profiles/  ->  cli/profiles/

Also: ci/security-audit-required.sh, ci/no-stubs.sh, ci/no-custom-crypto.sh,
docs/implementation-plan.md, docs/security-reviewers.md updated to add
'runtimes/openclaw/src/(core|index.ts)' and 'deploy/seccomp/' +
'deploy/helm/azureclaw/files/' (the actual deploy-time seccomp profile)
to the production-code regex/PROD_PATHS lists.

cli/package.json build script: 'cp -r ../policy-engine/profiles ...'
  ->  'cp -r profiles ...'.

Doc string updates across README.md, docs/security.md,
docs/blueprints/05-sovereign-airgapped.md, docs/security-audits/README.md,
docs/competitive.md, docs/internal/global-agentmesh-plan.md,
tests/conformance/{fixtures/README.md,specs/sandbox-isolation.spec.ts}.

Verification: cli build + tests (354 pass) clean; runtime build + tests
(100 pass) clean; CI gate scripts smoke-tested.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit cd59c01 into dev Apr 29, 2026
15 of 16 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the phase2-runtime-package-split-g1 branch April 29, 2026 21:23
Pal Lakatos-Toth (pallakatos) added a commit that referenced this pull request May 12, 2026
…ge (#107)

* S15.g.1: split runtime adapter into runtimes/openclaw/ package

Mechanical move. Lifts the AzureClaw runtime adapter for OpenClaw out
of cli/src/ into its own top-level package runtimes/openclaw/, sibling
to the future runtimes/openai-agents/ and runtimes/maf/ adapters
(S10.A3 + S10.A4). No behaviour change.

Moves (git mv preserves history):
  cli/src/plugin.ts            → runtimes/openclaw/src/index.ts
  cli/src/core/                → runtimes/openclaw/src/core/
  cli/src/plugin.test.ts       → runtimes/openclaw/src/index.test.ts
  cli/src/redact.test.ts       → runtimes/openclaw/src/redact.test.ts
  cli/src/router-url.test.ts   → runtimes/openclaw/src/router-url.test.ts
  cli/openclaw.plugin.json     → runtimes/openclaw/openclaw.plugin.json

New runtimes/openclaw/{package.json,tsconfig.json,.gitignore} —
@azureclaw/runtime-openclaw, narrowed deps (@agentmesh/sdk +
commander only; operator-CLI-only deps stay in cli/).

Sandbox Dockerfile cli-builder stage repointed to runtimes/openclaw/.
ci/loc-budget.yaml entry repointed. New 'Runtime OpenClaw Build &
Test' CI job at parity with cli-build and mesh-plugin-build.

Verification: cd runtimes/openclaw && tsc / lint / test (100 pass) /
build all clean. cd cli && tsc / lint / test (354 pass / 2 skipped) /
build all clean.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* S15.g.1 fixup: rename policy-engine/ -> cli/profiles/ + cover runtimes/ in CI gates

Folder rename. The top-level 'policy-engine/' directory contained one
seccomp JSON used only by host-side 'azureclaw dev' (cli/src/commands/
dev.ts:471). The name implied a runtime engine that doesn't exist, and
the deployed AKS seccomp profile actually lives at deploy/seccomp/ and
is loaded by the Helm seccomp-installer DaemonSet — this cli artifact
was misleadingly co-located at the repo root.

  policy-engine/profiles/  ->  cli/profiles/

Also: ci/security-audit-required.sh, ci/no-stubs.sh, ci/no-custom-crypto.sh,
docs/implementation-plan.md, docs/security-reviewers.md updated to add
'runtimes/openclaw/src/(core|index.ts)' and 'deploy/seccomp/' +
'deploy/helm/azureclaw/files/' (the actual deploy-time seccomp profile)
to the production-code regex/PROD_PATHS lists.

cli/package.json build script: 'cp -r ../policy-engine/profiles ...'
  ->  'cp -r profiles ...'.

Doc string updates across README.md, docs/security.md,
docs/blueprints/05-sovereign-airgapped.md, docs/security-audits/README.md,
docs/competitive.md, docs/internal/global-agentmesh-plan.md,
tests/conformance/{fixtures/README.md,specs/sandbox-isolation.spec.ts}.

Verification: cli build + tests (354 pass) clean; runtime build + tests
(100 pass) clean; CI gate scripts smoke-tested.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant