Package OpenClaw 2026.9.1 as a local PKGBUILD based on the AUR one,
tracking the npm registry's latest dist-tag through the repository's
declarative npm upstream provider: upstream's release cadence outruns
the AUR maintainer, and the dist-tag is the stable channel where a plain
version-max would ship next cycle's betas. A 24h min_release_age
quarantines fresh releases, which matters more than usual here because
the npm tarball is not vendored: package() resolves ~330 transitive
dependencies from the live registry without integrity pins. The pinned
sha256 was verified against the registry by hand. The initial pin was
taken inside its quarantine window through the documented
BYPASS_MIN_RELEASE_AGE maintainer path, deliberately, and lands through
this reviewed change as that path intends.
The AUR post_upgrade restart attempt is replaced with printed guidance:
it targeted a nonexistent openclaw.service, and the real
openclaw-gateway.service is a systemd user unit a root pacman hook
cannot reach (voxtype-bin sets the precedent).
The builder ships npm 12, which refuses install-time lifecycle scripts unless
the package is allow-listed, and for a local tarball the allow-list key is the
tarball's own file: spec rather than the package name. Without it openclaw's
postinstall never runs, the .openclaw-lifecycle-pending marker ships in the
package, and every invocation dies trying to finish the lifecycle inside the
root-owned /usr/lib/node_modules/openclaw. package() now passes
--allow-scripts and fails the build if the marker survives.
That postinstall also runs upstream's legacy-state migration against whatever
home it sees, so the npm call gets a scratch HOME under $srcdir with the
OPENCLAW_* location overrides unset: a maintainer's own ~/.openclaw is not
the build's to prune.