# Versioned state, guarded upgrades

> Database-first state, schema version contracts, guarded updates, release channels, and the maturity scorecard

- 网址：https://funcoding.ai/agents/openclaw/start/why-openclaw/versioned-state-guarded-upgrades/
- 来源：OpenClaw 官方文档原文（英文），MIT 许可，同步于 2026-10-11
- 官方原文：https://docs.openclaw.ai/zh-CN/start/why-openclaw/versioned-state-guarded-upgrades

---
Runtime state is database-first: one global SQLite store, one per agent, with a written contract that runtime code never reads or writes JSON sidecars as active state. The contract is machine-checked in CI ([database schemas](https://funcoding.ai/agents/openclaw/reference/database-schemas/)). Schemas carry a two-place version contract; a build refuses to open a database newer than itself. [`openclaw update`](https://funcoding.ai/agents/openclaw/cli/update/) refuses targets whose declared schema support is older than your on-disk databases; legacy target packages without schema metadata cannot be preflighted. [`openclaw doctor --fix`](https://funcoding.ai/agents/openclaw/cli/doctor/) is the single owner of file-to-SQLite migrations and records a receipt for each one. SQLite snapshots in [backups](https://funcoding.ai/agents/openclaw/cli/backup/) use SQLite's online-backup API and are integrity- and hash-checked during creation and publication. Whole-archive verification does not bind ordinary file payloads to content hashes; restore never happens in place. [Restart recovery](https://funcoding.ai/agents/openclaw/gateway/restart-recovery/) resumes interrupted turns under a bounded attempt budget, and a crash-loop breaker keeps the control plane reachable while suppressing channel autostart.

Releases come through four channels (stable, extended-stable, beta, dev) on calendar versions with immutable npm publishes ([development channels](https://funcoding.ai/agents/openclaw/install/development-channels/), [release process](https://docs.openclaw.ai/reference/RELEASING)). Extended-stable is the conservative track and it fails closed: the updater re-fetches and verifies the exact selected package, and missing or inconsistent registry data is an error, never a fallback to `latest`. The [Full Release Validation](https://docs.openclaw.ai/reference/full-release-validation) workflow seals an immutable execution-plan artifact covering cross-OS installs and upgrades, package acceptance, live channel lanes, and performance gates. Publishing is serialized and provenance-verified (Sigstore attestations, npm provenance) under the OpenClaw Foundation identity.

Per-surface readiness is published. The [maturity scorecard](https://docs.openclaw.ai/maturity/scorecard) grades 50 surfaces across [280 capability areas](https://docs.openclaw.ai/maturity/taxonomy) from deterministic QA evidence plus reviewed quality scores, with long-term-support status on every row. Extended-stable answers how long a surface is supported; the scorecard answers how proven it is.
