Repository navigation
S15.g.1: split OpenClaw runtime adapter into runtimes/openclaw/ package - #107
Merged
Pal Lakatos-Toth (pallakatos) merged 2 commits intoApr 29, 2026
Merged
Conversation
Mechanical move. Lifts the AzureClaw runtime adapter for OpenClaw out
of cli/src/ into its own top-level package runtimes/openclaw/, sibling
to the future runtimes/openai-agents/ and runtimes/maf/ adapters
(S10.A3 + S10.A4). No behaviour change.
Moves (git mv preserves history):
cli/src/plugin.ts → runtimes/openclaw/src/index.ts
cli/src/core/ → runtimes/openclaw/src/core/
cli/src/plugin.test.ts → runtimes/openclaw/src/index.test.ts
cli/src/redact.test.ts → runtimes/openclaw/src/redact.test.ts
cli/src/router-url.test.ts → runtimes/openclaw/src/router-url.test.ts
cli/openclaw.plugin.json → runtimes/openclaw/openclaw.plugin.json
New runtimes/openclaw/{package.json,tsconfig.json,.gitignore} —
@azureclaw/runtime-openclaw, narrowed deps (@agentmesh/sdk +
commander only; operator-CLI-only deps stay in cli/).
Sandbox Dockerfile cli-builder stage repointed to runtimes/openclaw/.
ci/loc-budget.yaml entry repointed. New 'Runtime OpenClaw Build &
Test' CI job at parity with cli-build and mesh-plugin-build.
Verification: cd runtimes/openclaw && tsc / lint / test (100 pass) /
build all clean. cd cli && tsc / lint / test (354 pass / 2 skipped) /
build all clean.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…s/ in CI gates
Folder rename. The top-level 'policy-engine/' directory contained one
seccomp JSON used only by host-side 'azureclaw dev' (cli/src/commands/
dev.ts:471). The name implied a runtime engine that doesn't exist, and
the deployed AKS seccomp profile actually lives at deploy/seccomp/ and
is loaded by the Helm seccomp-installer DaemonSet — this cli artifact
was misleadingly co-located at the repo root.
policy-engine/profiles/ -> cli/profiles/
Also: ci/security-audit-required.sh, ci/no-stubs.sh, ci/no-custom-crypto.sh,
docs/implementation-plan.md, docs/security-reviewers.md updated to add
'runtimes/openclaw/src/(core|index.ts)' and 'deploy/seccomp/' +
'deploy/helm/azureclaw/files/' (the actual deploy-time seccomp profile)
to the production-code regex/PROD_PATHS lists.
cli/package.json build script: 'cp -r ../policy-engine/profiles ...'
-> 'cp -r profiles ...'.
Doc string updates across README.md, docs/security.md,
docs/blueprints/05-sovereign-airgapped.md, docs/security-audits/README.md,
docs/competitive.md, docs/internal/global-agentmesh-plan.md,
tests/conformance/{fixtures/README.md,specs/sandbox-isolation.spec.ts}.
Verification: cli build + tests (354 pass) clean; runtime build + tests
(100 pass) clean; CI gate scripts smoke-tested.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
phase2-runtime-package-split-g1
branch
April 29, 2026 21:23
This was referenced Apr 29, 2026
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
…ge (#107) * S15.g.1: split runtime adapter into runtimes/openclaw/ package Mechanical move. Lifts the AzureClaw runtime adapter for OpenClaw out of cli/src/ into its own top-level package runtimes/openclaw/, sibling to the future runtimes/openai-agents/ and runtimes/maf/ adapters (S10.A3 + S10.A4). No behaviour change. Moves (git mv preserves history): cli/src/plugin.ts → runtimes/openclaw/src/index.ts cli/src/core/ → runtimes/openclaw/src/core/ cli/src/plugin.test.ts → runtimes/openclaw/src/index.test.ts cli/src/redact.test.ts → runtimes/openclaw/src/redact.test.ts cli/src/router-url.test.ts → runtimes/openclaw/src/router-url.test.ts cli/openclaw.plugin.json → runtimes/openclaw/openclaw.plugin.json New runtimes/openclaw/{package.json,tsconfig.json,.gitignore} — @azureclaw/runtime-openclaw, narrowed deps (@agentmesh/sdk + commander only; operator-CLI-only deps stay in cli/). Sandbox Dockerfile cli-builder stage repointed to runtimes/openclaw/. ci/loc-budget.yaml entry repointed. New 'Runtime OpenClaw Build & Test' CI job at parity with cli-build and mesh-plugin-build. Verification: cd runtimes/openclaw && tsc / lint / test (100 pass) / build all clean. cd cli && tsc / lint / test (354 pass / 2 skipped) / build all clean. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * S15.g.1 fixup: rename policy-engine/ -> cli/profiles/ + cover runtimes/ in CI gates Folder rename. The top-level 'policy-engine/' directory contained one seccomp JSON used only by host-side 'azureclaw dev' (cli/src/commands/ dev.ts:471). The name implied a runtime engine that doesn't exist, and the deployed AKS seccomp profile actually lives at deploy/seccomp/ and is loaded by the Helm seccomp-installer DaemonSet — this cli artifact was misleadingly co-located at the repo root. policy-engine/profiles/ -> cli/profiles/ Also: ci/security-audit-required.sh, ci/no-stubs.sh, ci/no-custom-crypto.sh, docs/implementation-plan.md, docs/security-reviewers.md updated to add 'runtimes/openclaw/src/(core|index.ts)' and 'deploy/seccomp/' + 'deploy/helm/azureclaw/files/' (the actual deploy-time seccomp profile) to the production-code regex/PROD_PATHS lists. cli/package.json build script: 'cp -r ../policy-engine/profiles ...' -> 'cp -r profiles ...'. Doc string updates across README.md, docs/security.md, docs/blueprints/05-sovereign-airgapped.md, docs/security-audits/README.md, docs/competitive.md, docs/internal/global-agentmesh-plan.md, tests/conformance/{fixtures/README.md,specs/sandbox-isolation.spec.ts}. Verification: cli build + tests (354 pass) clean; runtime build + tests (100 pass) clean; CI gate scripts smoke-tested. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Pal Lakatos-Toth <pallakatos@microsoft.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Mechanical move. Lifts the AzureClaw runtime adapter for OpenClaw out of
cli/src/into its own top-level packageruntimes/openclaw/, sibling to the futureruntimes/openai-agents/andruntimes/maf/adapters (S10.A3 + S10.A4). No behaviour change.cli/src/plugin.tsruntimes/openclaw/src/index.tscli/src/core/runtimes/openclaw/src/core/cli/src/plugin.test.tsruntimes/openclaw/src/index.test.tscli/src/redact.test.tsruntimes/openclaw/src/redact.test.tscli/src/router-url.test.tsruntimes/openclaw/src/router-url.test.tscli/openclaw.plugin.jsonruntimes/openclaw/openclaw.plugin.jsonWhat changed besides the moves
runtimes/openclaw/{package.json,tsconfig.json,.gitignore}—@azureclaw/runtime-openclaw. Deps narrowed to the actual surface (@agentmesh/sdk+commander); operator-CLI-only deps stay incli/package.json.sandbox-images/openclaw/Dockerfilecli-builderstage repointed toruntimes/openclaw/. Thepolicy-engine/profiles/copy was removed from this stage because it's only consumed by cli's own build script (host-sideazureclaw devseccomp staging) — the in-sandbox runtime adapter never reads those JSONs. cli's own build pipeline still produces them for the operator CLI tarball.ci/loc-budget.yamlentry repointed:cli/src/plugin.ts→runtimes/openclaw/src/index.ts..github/workflows/ci.ymladds newRuntime OpenClaw Build & Testjob at parity withcli-buildandmesh-plugin-build.Verification
cd runtimes/openclaw && tsc / lint (23 warn) / test (100 pass) / build— all clean.cd cli && tsc / lint (16 warn) / test (354 pass / 2 skipped) / build— all clean. Test count is −100 vs pre-S15.g.1 because three test files followed the source.Risk + rollback
Audit doc:
docs/security-audits/2026-04-29-phase2-runtime-package-split-g1.md.Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com