OSS Inventory
OSS Inventory (Fabric Consumer Mode)
jhf-deployment consumes OSS upgrade/version truth from Fabric as canonical source of truth and does not define a competing platform-wide OSS upgrade authority.
Canonical Fabric contracts consumed by this repo:
contracts/platform/platform_version_truth.jsoncontracts/platform/platform_projection_catalog.jsoncontracts/platform/platform_oss_upgrade_governance_v1.jsoncontracts/platform/platform_oss_upgrade_compatibility_matrix_v1.jsoncontracts/platform/platform_oss_upgrade_evidence_contract_v1.jsoncontracts/platform/helpifyr_stack_module_identity_v1.jsoncontracts/platform/stack_tool_oss_inventory_directory.jsondocs/contracts/HELPIFYR_PLATFORM_OSS_UPGRADE_GOVERNANCE.mddocs/contracts/HELPIFYR_STACK_MODULE_IDENTITY.mddocs/contracts/HELPIFYR_STACK_TOOL_OSS_INVENTORY_DIRECTORY.md
Repo-local consumer bindings:
maintenance/fabric-oss-upgrade-consumption.jsonmaintenance/platform-oss-upgrade-rollout-governance.jsonmaintenance/oss-version-truth.jsonmaintenance/coordinated-upgrade-catalog.jsonmaintenance/stack-upgrade-owner-boundaries.jsonmaintenance/openclaw-2026.5.20-host172-upgrade-evaluation.jsonmaintenance/openclaw-2026.5.20-bounded-verify-lane.jsonmaintenance/openclaw-2026.5.22-host172-upgrade-evaluation.jsonmaintenance/openclaw-2026.5.22-bounded-verify-lane.jsonmaintenance/openclaw-2026.6.8-host172-upgrade-evaluation.jsonmaintenance/openclaw-2026.6.8-bounded-verify-lane.jsonmaintenance/spindle-erpnext-v16-host172-rollout-lane.json
Candidate Evaluation: OpenClaw 2026.5.20
Current deployment truth remains pinned to OpenClaw 2026.5.12 in the default
environments/test version path and the checked example pins. Host172 also
currently runs ghcr.io/openclaw/openclaw:2026.5.12 on openclaw-gateway.
The deployment-owned evaluation artifact
maintenance/openclaw-2026.5.20-host172-upgrade-evaluation.json records:
- current Host172 runtime truth (
2026.5.12, healthy) - current repo pin truth (
2026.5.12) - the official upstream release delta review for
2026.5.18,2026.5.19, and2026.5.20 - the non-mutating gate verdict from:
- Fabric stack contract compliance inventory
- stack OSS runtime materialization verification
- bounded Stage-2 candidate certification evidence
Current recommendation:
2026.5.20is a plausible bounded deployment candidate- Host172 rollout stays deferred in this slice
- next step is a bounded staging or branch verify path before any Host172 main rollout pin changes are made
Bounded Verify Lane: OpenClaw 2026.5.20
The deployment-owned bounded verify contract
maintenance/openclaw-2026.5.20-bounded-verify-lane.json materializes the next
step after the readiness evaluation:
- candidate image version proof is read directly from the OpenClaw image on
host73 via
/app/package.json - Stage-2 certification must consume that real candidate-version proof
- Host172 remains read-only and must stay on
2026.5.12 - the bounded lane reruns:
- Fabric stack contract compliance inventory
- strict Host172 stack OSS runtime materialization
- deployment-owned
jhf-beamlive SSH attachment gate
Candidate Re-Evaluation: OpenClaw 2026.5.22
OpenClaw 2026.5.22 is now the latest stable candidate and supersedes
2026.5.20 as the active rollout target. Host172 still remains pinned to
2026.5.12 in this slice.
The deployment-owned artifact
maintenance/openclaw-2026.5.22-host172-upgrade-evaluation.json records:
- current Host172 runtime truth (
2026.5.12, healthy) - current repo pin truth (
2026.5.12) - the upstream delta review for
2026.5.20,2026.5.22, and2026.5.24-beta.1 - the non-mutating gate verdict from:
- Fabric stack contract compliance inventory
- stack OSS runtime materialization verification
- bounded Stage-2 candidate certification evidence
- bounded practical verify lane
Current recommendation:
2026.5.22is the current latest stable candidate- the bounded practical verify lane is green
- the next step is now a dedicated controlled Host172 rollout slice with snapshot, rollback, pin update, and post-rollout live verify
Controlled Host172 Rollout: OpenClaw 2026.5.22
The deployment-owned artifact
maintenance/openclaw-2026.5.22-host172-rollout-evidence.json captures the
actual Host172 live rollout that followed the bounded candidate lane:
- pre-change snapshot under
/home/administrator/rollout-snapshots/ - runtime-owner rollout branch/worktree and compose path
- rollback trigger plus last-known-good
2026.5.12compose command - post-change Host172 runtime readback (
2026.5.22,running,healthy) - owner-side live verifies from
jhf-openclaw-env - deployment-owned end-to-end rerun against the now-upgraded Host172
Bounded Verify Lane: OpenClaw 2026.5.22
The deployment-owned bounded verify contract
maintenance/openclaw-2026.5.22-bounded-verify-lane.json keeps the same
non-mutating lane shape:
- candidate image version proof is read directly from the OpenClaw image on
host73 via
/app/package.json - Stage-2 certification must consume that real candidate-version proof
- Host172 remains read-only and must stay on
2026.5.12 - the bounded lane reruns:
- Fabric stack contract compliance inventory
- strict Host172 stack OSS runtime materialization
- deployment-owned
jhf-beamlive SSH attachment gate
Candidate Re-Evaluation: OpenClaw 2026.6.8
OpenClaw 2026.6.8 is now the current latest stable candidate and supersedes
the earlier 2026.5.22 rollout target for the next bounded upgrade slice.
Host172 remains pinned live to 2026.5.22 in this re-evaluation slice.
The deployment-owned artifact
maintenance/openclaw-2026.6.8-host172-upgrade-evaluation.json records:
- current Host172 runtime truth (
2026.5.22, healthy) - current repo-default pin truth (
2026.5.22) for the reusable Stage-2 test lane after the completed2026.5.22Host172 rollout - the upstream release delta review for
2026.6.8,2026.6.8-beta.2, and2026.6.8-beta.1 - the non-mutating gate verdict from:
- Fabric stack contract compliance inventory
- stack OSS runtime materialization verification
- bounded Stage-2 candidate certification evidence
- bounded practical verify lane
Current recommendation:
2026.6.8is the current latest stable candidate- the bounded practical verify lane is green without changing Host172
- the next step is a dedicated controlled Host172 rollout slice with snapshot, rollback, pin update, and post-rollout live verify
Planned Host172 Rollout Lane: Spindle ERPNext/Frappe 15 -> 16
The deployment-owned contract
maintenance/spindle-erpnext-v16-host172-rollout-lane.json defines the
bounded Host172 live rollout lane for the Spindle ERPNext/Frappe major upgrade
without executing the cutover in this slice.
The lane is intentionally fail-closed:
- Host172 rollout remains blocked until Host73 certification (
jhf-deployment#406) and Beam certification (jhf-beam#240/#241) are green. - rollout requires parity readback between Host73 and Host172 for commit, version vector, runtime identity, and critical parameters.
- freeze, scheduler/worker drain, fresh financial baseline capture, pre-change snapshot, rollback triggers, and post-live verify are declared before any live mutation is allowed.
- post-live unfreeze is blocked until auth, MCP/business smokes, financial reconciliation, payment sanity when present, PDF/print sanity, and the first five-minute monitoring window are green.
Verification
- fail-closed local truth alignment:
python3 scripts/validate-oss-version-truth.py
- fail-closed Fabric consumer contract verification (fixture mode for CI):
python3 scripts/verify-fabric-oss-upgrade-consumption.py --fixtures-dir tests/fixtures/fabric-platform-oss --output test-results/fabric-oss-upgrade-consumption.ci.json
- fail-closed deployment rollout governance verification (fixture mode + dry-run evidence):
python3 scripts/verify-platform-oss-upgrade-rollout-governance.py --fixtures-dir tests/fixtures/fabric-platform-oss --evidence tests/fixtures/platform-oss-upgrade-rollout/valid-rollout-evidence.json --output test-results/platform-oss-upgrade-rollout-governance.ci.json
- fail-closed Fabric consumer readback (live mode):
python3 scripts/verify-fabric-oss-upgrade-consumption.py --output test-results/fabric-oss-upgrade-consumption.live.json
- fail-closed deployment rollout governance readback (live mode):
python3 scripts/verify-platform-oss-upgrade-rollout-governance.py --evidence tests/fixtures/platform-oss-upgrade-rollout/valid-rollout-evidence.json --output test-results/platform-oss-upgrade-rollout-governance.live.json
- bounded candidate evaluation:
python3 scripts/run-stage2-openclaw-certification.py --target-version 2026.5.20 --json-command 'python -c "import json; print(json.dumps({\"ok\": True, \"target_version\": \"2026.5.20\"}))"' --output test-results/stage2-openclaw-certification.2026.5.20.eval.json --stack-contract-compliance-evidence-output test-results/fabric-stack-contract-compliance-inventory.stage2-2026.5.20.eval.json --json-clean-evidence-output test-results/stage2-openclaw-json-clean-evidence.2026.5.20.eval.json --promotion-payload-output test-results/stage2-openclaw-promotion-payload.2026.5.20.eval.json
- bounded practical verify lane:
python3 scripts/run-stage2-openclaw-2026-5-20-bounded-verify.py --output test-results/openclaw-2026.5.20-bounded-verify.local.json
- latest stable bounded practical verify lane:
python3 scripts/run-stage2-openclaw-2026-5-20-bounded-verify.py --target-version 2026.6.8 --candidate-image ghcr.io/openclaw/openclaw:2026.6.8 --source-issue 744 --expected-host172-image ghcr.io/openclaw/openclaw:2026.5.22 --output test-results/openclaw-2026.6.8-bounded-verify.local.json
- controlled Host172 rollout rerun:
python3 scripts/run-stage2-openclaw-2026-5-20-bounded-verify.py --target-version 2026.5.22 --candidate-image ghcr.io/openclaw/openclaw:2026.5.22 --source-issue 385 --expected-host172-image ghcr.io/openclaw/openclaw:2026.5.22 --output test-results/openclaw-2026.5.22-host172-rollout.live.json
- Spindle ERPNext/Frappe Host172 rollout lane contract:
python3 maintenance/verify-maintenance-contracts.py
- live Host172 non-mutating version/materialization readback:
python3 scripts/verify_stack_oss_runtime_materialization.py --live-via-ssh <internal-runtime-redacted><internal-runtime-redacted> --fail-on-non-env-floating --output test-results/stack-oss-runtime-materialization.2026-05-22.eval.json
- maintenance contract lane:
python3 maintenance/verify-maintenance-contracts.py
Fail-closed posture
- missing/unreadable Fabric SoT contracts fail
- missing required Fabric docs contracts fail
- local shadow copies of Fabric platform OSS contracts fail
- local
latestassumptions are forbidden in OSS version truth - deployment rollout evidence fails closed on missing
target_version, missing compatibility gate, missing postdeploy readback, missing rollback evidence, orlatest-only posture
License: AGPLv3 Source and governance: https://helpifyr.com