Skip to content

feat(browser): install and pair Chrome with Windows Companion - #1446

Draft
roboclaw-bot wants to merge 61 commits into
mainfrom
openclaw/automatic-chrome-extension-pairing
Draft

roboclaw-bot wants to merge 61 commits into
mainfrom
openclaw/automatic-chrome-extension-pairing

Conversation

@roboclaw-bot

@roboclaw-bot roboclaw-bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Related: openclaw/openclaw#152004. Coordinated with openclaw/openclaw#152057 (feat(browser): unify local Chrome setup across desktop and terminal).

Implemented for Peter Steinberger (@steipete), incorporating canonical Windows transport/setup work contributed by Jason (@fuller-stack-dev).

Work sessions

What Problem This Solves

Windows Companion should offer Chrome setup and local pairing without copied secrets or competing native-host registration owners.

User Impact

One packaged OpenClaw.BrowserBootstrap.exe and one Windows registration service replace the old helper and duplicate registry writers. A fresh Companion uses its existing managed-local WSL intent. Explicit standalone native-Windows CLI setup uses its bound Windows context. Conflicting bindings, browser opt-outs and saved extension pairing remain untouched. Chrome approval is still required.

Draft: current-head Windows and production integration proof remain merge gates. No release or real-user installation is included.

Why This Change Was Made

The private management ABI uses bounded JSON plus EOF while Chrome native-messaging v1 remains unchanged. Windows owns immutable private generations, SID/DACL/reparse/hash admission, transactional native/Store registry mutation and ownership checks. The canonical TypeScript consumer retains config, credential and relay policy. Companion retains active-Gateway, connection-intent, generation and managed-WSL provenance checks.

Installer and uninstaller call the same owner through bounded pipes and a kill-on-close job. Startup repair does not replay Store enrollment. Chrome EOF cancels either explicit backend. There is no PATH, localhost or availability-based topology fallback.

Evidence

Current fixture repair and diagnostic checkpoint (not final acceptance)

Reviewed source bfcccf8, fixture commit 4278029. Production source is unchanged by this batch. Saved-profile proof now checks Gateway18789/path/profile=work separately from relay19444 and uses another private directory with the required node.exe basename for runtime drift. Static failure stages and numeric coordinates exclude raw errors, pairing values and child output; primary and cleanup failures remain distinct.

Forced-WSL-client lookup now exposes a fixed script-entry marker plus bounded process/drain/stage/count evidence without changing exact parent/command/image selection or any deadline. The stale combined workflow guard is reconciled into the ORIGINAL edd93f4 native-production baseline and a SEPARATE reviewed42780299 fixture baseline, with additional fixture dependencies protected. Both positive checks passed; known older production/fixture revisions were rejected. No guard was disabled.

Actual canonical autoreview (immutable helper e18ab3b62f7716d6ba20329602baa2c1da0d4601, Codex gpt-5.6-sol/high, P0-P2) passed scoped-clean for the corrected fixture bundle and then for the separate guard diff. Its initial P2 finding was accepted and fixed: re-observing an already-faulted drain must not invent a new cleanup failure. Two regression tests cover this. The older vendored-helper proxy refusal remains recorded; inherited proxy/auth environment was unchanged, with no configuration, credential or security-policy workaround.

Not frozen or ready to merge: the next hosted runs are diagnostic, not final coupled acceptance. Native consumer57201e3e and WSL consumer63f5d867 are unchanged diagnostic pins; the main owner must supply the final reviewed consumer freeze. Preserve three distinct failures: native35472473290 passed the original14 cases then failed saved-profile execution; WSL forced_client_exit timed out before selecting/killing the exact client; CI35472475313 failed the immediate process.HasExited assertion in BoundedProcessWaitTests. Their causes are not conflated or waived. No new native success, release, signing or LAND completion is claimed. Earlier checkpoints below are historical, not current-head acceptance.

Production WSL owner repair published; forced-loss proof assertion unresolved

Current head 97e7aa7 (reviewed implementationc8738ea5). The prerequisite canonical prototype35467770110 passed19/19; receipt10592605207 was independently validated. Real canonical CLI settled3924ms, deadline15036ms, unknown acknowledgments never authorized result/retirement; Gateway and cleanup checks passed. Consumer63f packageSHA2d923fbb888cafd352f5b31c07eff82c91bff8bf36a8270dfef1275ad9b54eb6.

The production command now uses that private gate/supervisor protocol, EOF revocation, strict bounded framing and positive guest acknowledgment before Windows/drain settlement and owner completion. Missing acknowledgments deliberately retain UNKNOWN/BUSY beyond the existing soft cleanup budget. No public ABI, registration/generation schema, ACL, topology/selector, provenance, credential or deadline change. The early-EOF-before-READY review finding was fixed and has unit/hosted regressions. A later sole runtime-selection allegation was rejected after checking the already-first managed-runtime PATH and executing an isolated bundled-runtime selection check; do not interpret that reviewer exit1 as a clean exit0. No accepted actionable finding remains.

Focused connection tests34/34 passed; embedded broker framing/capacity checks and E2E graph build passed (0warnings/errors). Full local Windows build remains unavailable; Shared194fail3823pass33skip and Tray18fail2965pass2skip remain failed local attempts. Actual production-owner proof35469857614 executes6 cases including early EOF, real CLI, successful detached descendant, cancellation, deadline and missing-ack BUSY retention; fresh CI35469859761 is separately watched. Terminal actual-owner run35469857614 FAILED: receipt10592523499 passed early EOF, real CLI (4812ms), normal detached cleanup, caller cancellation and deadline (15064ms), with owner/lease/activation preceding management completion and empty postchecks. forced_client_exit failed EqualException; the old failure receipt omitted its exact assertion stage. Do NOT claim all6 or completed forced-loss retention. Gateway unchanged, original CLI restored and owned fixture disposed. A test-only correction restores the previously successful parent-PID-bound exact-client lookup and adds bounded concurrent query drains plus redacted stage/count/outcome/ownership counters; BUSY/no-ack assertions stay unchanged. Production code remains unchanged. StandardCI35469859761 is terminal SUCCESS, including the formerly failing unchanged core stdout test, but that does not substitute for the failed dedicated proof or owed final consumer pairing. PriorCI35467773484 failed an unchanged SystemRunTests orphan-stdout assertion (empty versus hello) and Gate; exact logs retained without a waiver. Final consumer saved-profile pairing remains owed, with all14 accepted native cases retained. SOURCE NOT FROZEN until required proofs and final consumer validation are complete. No merge/release/signing.

Current reviewed prototype head edd93f4. Canonical-fixture source657ea9a0 and setup correction16756d46 passed independent review. Package/prototype35467447621 failed before build because pnpm/action-setup rejected duplicate version owners (explicit action version versus integrity-qualified consumer packageManager); its Windows prototype was skipped. The correction retains the immutable packageManager and frozen lockfile as the sole authority. Current prototype35467770110 has passed package-manager setup and is building the actual canonical package; terminal proof is pending. Fresh standardCI35467773484 has its own watch. No production integration, old trace/native14 rerun, merge or release. Prepared production protocol reader has14 local checks, but remains unshipped until prototype verification; saved-profile acceptance code is prepared separately for the eventual final consumer pin.

Private WSL owner prototype checkpoint (18/19; canonical CLI fixture correction)

Published head 3ab6899, reviewed sourcee849d4510ba080857215b70b8316e67cf5a3e227. Prototype run35451710265 attempted the actual fixed-stdin broker and request-owned user-systemd primitive in the existing disposable hosted fixture BEFORE production wiring. No production source, native14 inputs, old trace inputs or public contracts changed. Standard CI is not this checkpoint's completion.

Terminal attempt: receipt10586807604 reports no READY in any case, 18errors, unchanged Gateway and successful owned-fixture disposal. The single reported collision pass is NOT counted as lifecycle proof because the original test did not require a broker-entry witness. No protocol/systemd checkpoint has passed. The driver omitted production-equivalent stdin newline normalization; a harmless CRLF shell reproduction returns exit2 while LF returns0. A scoped correction normalizes actual stdin, adds a portable transport regression (1/1executed/passed), and requires a bounded broker-start marker for every positive/negative case, plus exact collision InvocationID preservation. The scoped transport correction passed independent review and is published as2778c1d5 plus Gateway metadata. Current head 8c9dc44 executes corrected prototype35452501667. Its terminal receipt10587690990 passed18/19 cases: handoff, environment, capacity, normal detached-child cleanup, cancellation/deadline, forced-loss unknown retention and observed epoch refusal. Only real_cli failed: positive guest settlement, no successful CLI result. Gateway identity and owned-fixture disposal were preserved. Production remains untouched.

Recovered follow-up: the fixture installed the public release rather than the reviewed canonical consumer. The inspected official openclaw2026.9.5 package has no --local-gateway CLI option. The scoped correction builds immutable63f5d867fb67242ea6322f866b0e4f732d4e801c through its self-contained source-pack helper and uses the EXISTING fixture candidate-package/version interface BEFORE Gateway startup, verifying source/version/SHA and CLI capability. This is a prototype pin, NOT the final coupled-consumer pin. No shim, token substitution, live upgrade, config replacement or shutdown shortcut. StandardCI35452503191/UIjob105922181478 has a hosted-runner lost-communication annotation; no failed UI assertion/completed log was recovered. It remains failed, with no product-cause claim or gate waiver. Fresh exact-head CI follows publication, not a blind rerun.

Nineteen cases cover open-stdin bash handoff, clean service environment, READY/PERMIT binding, real canonical CLI output, full16384UTF16 capacity, normal successful detached-descendant cleanup, EOF/cancel/15sdeadline, forced client loss beforeREADY/partial/fullPERMIT/RESULT/SETTLED, delayed start job, collision and observed unit-epoch drift refusal, duplicate/oversized/out-of-order controls. Missing acknowledgments are explicitly UNKNOWN/BUSY with no retirement permission; the prototype does not claim a proved early-submission fence or actual production retirement.

Independent review found and fixed a real normal-result deadlock: stop the positively bound unit after capturing RESULT, then wait for cgroup/runner settlement, including successful detached children. Review also raised Show/StopUnit atomicity against same-UID replacement. The scope decision is explicit: request names are fresh, single-writer and never restarted/reused by the protocol; the existing trusted UID controls the CLI/config/user-manager. Observed drift is refused, but NO atomic conditional-stop protection against an uncooperative trusted-UID actor is claimed. The receipt carries atomicManagerReplacementFenceProven=false. Final scoped Codex review exited clean after this clarification and a strict BOM-control regression fix.

Local framing/capacity tests5/5 passed; E2E graph compilation0warnings/errors; workflow YAML and PowerShell parsing passed. Required Linux full build remains Windows-blocked; Shared194fail3823pass33skip and Tray18fail2965pass2skip remain failed local attempts. Only redacted prototype receipts will be retained. Existing causal post-command RED/unknown activation evidence below remains unchanged; no repeat trace-only/native14/full-matrix manual run. Final coupled consumer pin is still awaited before that separate proof. No production wrapper wiring, merge, release or signing yet.

Instrumentation-improved WSL trace: terminal evidence and bounded conclusions

Fresh trace35433978782 completed all six cases and owned cleanup on fe82006. The harness step passed; the settlement-evaluation step correctly FAILED for one causal post-command survivor and one unknown boundary ordering. Improved receipt10581142668 was downloaded and independently checked. The measurement loop ends here; no repeat or production fix was started.

The forced-wsl.exe-loss case proves a BRIEF POST-WslCommand-COMPLETION survival interval, not a persistent orphan and not a proven post-management survivor. On one Windows Stopwatch clock (10,000,000ticks/sec): command completion hook793.5088ms; challenge sent793.6278ms; response received794.5915ms reported matched owner2929/start26511(stateR),worker2932/start26519(stateS),leaf2933/start26522(stateS),group2929 still running. Thus a causal observation occurred after command completion, independent of exit-notification transport latency. No test cleanup preceded that challenge.

Source-linked activation release795.8504ms and management return795.8912ms came later. Challenge2 sent796.1031ms and received796.8882ms reported all three absent. Their exit notifications arrived796.4855-796.9067ms. Those later notifications do NOT prove either survival or precedence at activation/management release: that ordering remains UNKNOWN. The earlier7bd trace remains correctly classified as no observed survivor/unknown ordering, not retroactively recast as red orphan proof.

Case Last guest-exit notification received(ms) WslCommand completion hook(ms) Activation release begin(ms) Management return(ms) Conclusion
normal 3440.3154 3455.2058 3465.1396 3468.5536 Observed exit-notification precedence
IPC EOF 868.5061 874.9065 861.0376 861.1016 UNKNOWN at activation/management
client cancellation 838.4794 839.6711 839.9906 840.0253 Observed precedence
deadline 15026.1139 15027.5435 15028.5282 15028.5599 Observed precedence
forced client exit 796.9067 793.5088 795.8504 795.8912 Causal survivor after command; UNKNOWN at activation/management
pipe retirement 813.4588 813.5338 830.5700 830.6247 Observed precedence

IPC EOF is a raw local pipe-disconnection fixture, not confirmed server EOF. Its source-linked native inventory/mutex operation returns on that local error; no shipping-helper/Chrome-frame/registry conclusion is inferred. All other native ownership timestamps are also explicitly source-linked unchanged owners with synthetic platform facts, not live registered-helper proof. The actual WSL command, pipe client/server, selected distro/user/provenance and immutable source pins were retained.

Observer READY preceded every trigger; every pidfd exit and challenge identity matches its armed PID/start pair; every observer group differs from its request group. All12challenges are causally after their named boundaries. No post-management running response occurred in this run. CLI restoration and removal of exact owned distroOpenClawE2E-23d19299 succeeded; fixture GatewayMainPID2383 was checked unchanged before teardown. Receipt errors=[]; no raw logs/config/env/credentials were uploaded. Custompool/Chrome/upgrade/wholeCompanion/realcredential proof remains open.

Receipt file SHA256ff33c5841a86372a8b0aba43adecfbcf55e1cd1fc4a2ff0f62f3cd95473148bf; archive digestsha256:2acfc70d57b7cf311a9472b712d6207c5433e2cc6f2ce907c1c08be9ff9670aa. Concrete fallback design below is delivered for parent review only (SHA256c95097f33a2ab0f18b057fd5d3dd41636c2b1bbccca2df89901145fca03f39f4); it explicitly specifies READY/PERMIT/SETTLED framing, user-systemd ownership, loss-point recovery and the before-READY/missing-ack availability limit. No production wrapper, API switch, new channel, persistence, public contract, selector, permission or deadline change is implemented.

Current head fe82006 contains reviewed proof-only source db2fa48 plus Gateway publication metadata. Fresh trace35433978782 is the one authorized materially improved measurement, not a rerun of35432479861. Production783/d779 source and accepted native14/consumer57 pins remain unchanged.

An independent persistent guest observer binds pidfds/start identities while all three owned fixture processes are alive, outside their process groups, and reports READY before any trigger. A dedicated Windows reader stamps bounded exit notifications before parsing on the same Stopwatch clock as synchronous completion hooks. Two challenges sent after owner/retirement boundaries can prove a causal survivor; later notifications remain UNKNOWN, not evidence of an orphan. No owner callback waits for observation. Unchanged source-linked NativeRegistrationRuntime/RegistrationService execute through existing platform interfaces with synthetic inventory and a real Windows mutex. Runtime lease release, activation release and serialized management completion are separately recorded. This is explicitly not shipping-helper, actual registry/ACL or Chrome-frame proof.

All six cases and identity-scoped cleanup are retained. Scoped Codex review is clean; E2E graph compilation has zero errors/warnings and the local persistent-observer protocol test passed. Required Linux full build remains Windows-blocked; Shared194fail and Tray18fail remain failed local attempts, not proof. No manual old/native/full-matrix rerun, merge, signing or release.

Concrete fallback owner design for parent review only (not implemented)

Candidate private WSL owner protocol (design only, not production code)

Scope and non-goals

This is a candidate for BrowserBootstrapWslCommand after measurement, not an assertion that an orphan was observed. Keep Chrome native v1, management v1, generation metadata, selected distro, default openclaw user, default HOME/state/config, installed CLI allowlist, Gateway MainPID/provenance and browser/connection intent checks unchanged. Retain the existing 15-second request deadline, 2-second cleanup budget and fail-closed ownership retention after an unsettled cleanup budget. No Gateway/distro shutdown, new public selector, permissions, persistent JSON/PID store, new generation files or side listener.

The proposal would require an inline guest broker/gate and private framing changes inside the current wsl.exe invocation. Those changes are NOT implemented or authorized by this document. No WslLaunch migration is proposed.

Transport and exact framing

Keep argv: system wsl.exe --distribution D --exec /bin/bash --noprofile --norc -s. D remains the admitted pinned distro. The fixed bootstrap script performs the existing authority checks, selects the installed CLI and ends in an exec of a fixed inline guest broker using the already-installed managed runtime. It is not written to a guest file. Remove WSLENV as today. Explicitly pass only the already-pinned runtime environment into systemd's otherwise clean service environment; do not inherit manager profile/Node overrides.

Windows writes the complete fixed script and flushes but does NOT close stdin. It sends no further bytes until broker READY, so bash cannot read ahead and consume control frames before exec. This precise stdin handoff must be proven on WSL before implementation acceptance. Request ID R is random 128-bit lowercase hex, generated once in Windows memory, never a credential, never reused or derived from the Chrome nonce.

After script handoff, private frames are 4-byte unsigned little-endian length followed by strict UTF-8 JSON, duplicate/unknown keys rejected, no BOM/trailing data. Control frames max2048 bytes. Combined stdout (all frames/headers) remains within the existing16384-byte budget, stderr remains bounded and discarded. Reserve4096 bytes for READY/SETTLED overhead; RESULT has only the remaining budget and fails closed on overflow (no truncation, no buffer growth). Legitimate pairing values already have much smaller validated limits, but this internal framing budget change needs compatibility review. Nothing on this wire is logged.

Windows to broker:

  • PERMIT: {"v":1,"type":"permit","requestId":R,"invocationId":I,"challenge":C}
  • CANCEL: {"v":1,"type":"cancel","requestId":R,"invocationId":I}
    EOF is also cancellation, never submit-complete or successful settlement.

Broker to Windows:

  • READY: {"v":1,"type":"ready","requestId":R,"unit":U,"invocationId":I,"bootId":B,"challenge":C,"gatePid":P,"gateStartTicks":S}
  • RESULT: {"v":1,"type":"result","requestId":R,"invocationId":I,"payload":}
  • SETTLED: {"v":1,"type":"settled","requestId":R,"invocationId":I,"outcome":"completed|cancelled|failed","startSealed":true,"gateExited":true,"cgroupEmpty":true,"startJobSettled":true,"cliExitCode":integer-or-null}
    READY identifiers must match the exact created unit and trusted manager observation. C is a random per-gate challenge. Only one READY, PERMIT, RESULT and SETTLED is accepted, in order; failed/cancelled cases omit RESULT. A result alone is never delivery permission. Unknown schema or lost/partial acknowledgment becomes UNKNOWN, never settled.

Guest ownership and child creation

The broker creates exactly one transient user service U=openclaw-browser-bootstrap-R.service, using fail-on-existing semantics, not replacement or adoption. The service initially runs only an inert permission gate. No CLI/worker may start before a complete matching PERMIT. READY is sent only after creation/start job succeeded, the gate is running, and the broker verifies the exact unit invocation ID, user, gate PID/start identity and control-group ownership. Retain the one creation job handle in memory until its outcome is known.

Candidate properties: Type=exec, ExitType=cgroup, KillMode=control-group, Restart=no, no timers/sockets/activation triggers or restart path. The gate is already inside the unit BEFORE it forks the CLI, so the CLI and descendants inherit that cgroup, including ordinary detached process groups. Closing an empty pre-created scope after spawning outside it would be wrong. Keep existing user/systemd privileges; this is not containment against malicious same-user cgroup migration.

Use inherited anonymous stdin/stdout/stderr (systemd-run --user --quiet --pipe or the corresponding StartTransientUnit fd properties), not journald, guest files or a network channel. Capture CLI stdout in a bounded gate-to-broker pipe; the CLI gets /dev/null stdin, not the permission stream. No raw CLI bytes can impersonate broker control frames.

The concrete service retention candidate is RemainAfterExit=yes until the broker has captured gate exit, CLI result and an empty cgroup; then stop only U and wait for that stop job. Do NOT combine this with waiting for deactivation before issuing StopUnit, which would deadlock. In particular, do not assume systemd-run --wait itself can replace manager state/cgroup checks while RemainAfterExit is set. An implementation may use manager reference retention instead if that primitive is verified, but it must preserve the same explicit state machine; it cannot silently add persistent receipts.

Normal finish and cancellation

Gate state is single-use WAIT_PERMIT -> RUNNING -> SEALED. EOF, malformed input, CANCEL or child completion enters SEALED irreversibly. Only WAIT_PERMIT may consume a matching PERMIT and make exactly one synchronous child-creation decision. Gate sealing and child creation must be serialized; no queued callback may fork after SEALED. If cancellation races a committed permit, a child may already exist, but the native activation stays held until that exact unit is stopped and empty.

Normal: CLI exits, gate drains its bounded streams and returns its outcome, gate exits, and broker observes the exact unit/cgroup with no remaining processes. Broker seals its own start path, resolves the original creation job, stops the retained inactive-work unit, waits for stop completion and only then emits SETTLED. Windows may return parsed CLI output only after valid RESULT + completed SETTLED + Windows process/stdout/stderr settlement and the unchanged post-generation authority revalidation.

EOF/deadline: Windows atomically transitions its request to CANCELLING, never sends a new PERMIT, sends CANCEL if the stream is usable, then closes input. The broker/gate stops only U; the manager applies control-group termination and the broker waits for empty cgroup/gate exit. The existing cleanup budget is an error/reporting bound, NOT permission to release an unjoined activation. No larger timeout is introduced. A bounded stop grace, if configured, must fit the existing cleanup policy rather than silently extending it.

Forced Windows-client loss and recovery table

Loss point Safe behavior and remaining evidence
Before READY Windows has issued no PERMIT, so no CLI can be started by a conforming gate. But a pending WSL launch or transient-unit creation can still create an inert broker/gate later. Windows join or a negative GetUnit is NOT enough to retire. Enter UNKNOWN and retain activation until the actual submission/creation job and guest work are positively settled.
READY received, before PERMIT Exact unit/invocation binding is known in RAM. Recover through the same pinned WSL command transport with a fixed cancel-and-inspect script for that tuple; never send PERMIT in recovery. Stop and wait only the matched unit.
Partial PERMIT Length framing prevents gate start before the whole frame validates. Still stop/inspect the known unit because delivery outcome is uncertain; never retry PERMIT.
Complete PERMIT may have arrived Assume CLI could have started. Recover only the known unit, seal/stop it, resolve its jobs, verify gate exit and empty cgroup; no successful return on wsl.exe exit alone.
After RESULT, before SETTLED Discard the result until positive settlement; same recovery rule.
SETTLED received, client then lost The authenticated in-memory tuple and terminal proof are already known. Join Windows process/drains and perform unchanged final authority checks. Never regenerate credentials as recovery.

Recovery is another fixed operation over the SAME existing selected-distro WSL transport, not a listener, endpoint or public management operation. If the parent considers even this private recovery invocation an unacceptable channel expansion, that is a review blocker; it is not silently implemented. Bind unit name + invocation ID + manager/boot epoch + user + fixed gate identity before stop. A collision, changed invocation, manager epoch change, unknown properties or permission denial refuses recovery; do not terminate a foreign unit.

Availability limit, not hidden success: before READY, or after a lost acknowledgment when the known unit has already disappeared, an absent unit does not disprove a delayed submission. Without a persistent terminal receipt or an independently proven submission fence, this design cannot guarantee automatic bounded recovery. The state remains UNKNOWN/BUSY and retirement does not complete. A new timeout, negative lookup, wsl.exe HANDLE signal, distro shutdown or invented acknowledgment cannot resolve it. This explicit fail-closed limit needs parent acceptance or a separately reviewed stronger submission-fencing design. No persistent tombstone/store is smuggled into this proposal.

No late-start proof obligation

Retirement predicate T requires: start decision SEALED; creation job resolved; exact invocation's gate exited; owned cgroup empty; no restart/activation path; terminal tuple acknowledged; Windows/drains joined. The only CLI spawn site is in that already-owned gate and requires one complete matching PERMIT. At T, that gate is gone, no queued creation/restart job exists, and the broker cannot submit again. Therefore no request-owned CLI/descendant can appear after T under the trusted-CLI model. Unknown before-READY submissions fail T, so they cannot be mislabeled retired. This is an invariant to prove with barriers/forced-loss tests, not a property established by the current component trace.

Required acceptance cases include loss before READY, partial/full permit races, delayed manager start job, child forks during cancellation, child setsid(), gate/broker failures, lost RESULT/SETTLED, repeated recovery, unit-name collision and changed manager epoch. Measure guest exit and native activation/management boundaries independently. No positive result until these races and cleanup are proven on the existing disposable hosted fixture.

WslLaunch assessment and primary contracts

Microsoft WslLaunch documents an associated process HANDLE, stdio handles and caller CloseHandle responsibility. It does not document termination propagation or descendant settlement order. It is only a candidate transport API, not a cancellation proof and not a reason to switch APIs here.

Primary sources consulted (September19,2026):

No gateway credential, raw environment, user configuration, persistent PID record or new native generation metadata is part of this protocol or its proof receipts.

WSL guest component trace: terminal, settlement ordering remains unproven

Trace35432479861 completed all six cases and cleanup on head7bd45d9872b06d99f3aaff4ba01569baa4f8f85d. Receipt10582090139 is independently checked against run/head/productionPin783, all18guestPID/start identities and default-user/provenance booleans. No guest survivor was observed. This is NOT a guest-settlement-before-retirement pass. Every first independent absence observation completed after owner completion; the sample windows cannot establish ordering.

Times below are milliseconds from each case start, before test cleanup:

Case Command returned Client completed First all-absent observation window
normal 5495 5500 5490-5608
IPC EOF 743 731 (local disconnect, not server acknowledgment) 724-852
client cancellation 757 758 745-869
deadline 15012 15013 15052-15167
forced Windows-client exit 701 704 698-815
pipe retirement 753 (Dispose also753) 810 731-861

For retirement, request-owned guest PID/start-ticks were3233/30377,3240/30386,3241/30390 (group3233); all were absent in the postcheck861-992ms. Forced-client case identities3202/30251,3205/30259,3206/30263 were absent at815-929ms. These are observation bounds, not an exit acknowledgment. Receipt status explicitly remains trace_complete_not_a_settlement_pass. Original CLI restored, unchanged fixture gateway MainPID2389 checked before teardown, exact owned distroOpenClawE2E-f84bde62 removed. No unrelated gateway/distro was stopped. Only redacted receipt uploaded; no raw logs/config/env/credential output.

Receipt file SHA25681da21764206fba7abb5cf3edf89a32cf6020c89b817a63acfdb1fcf5e7761b3; artifact archive digestsha256:8452d2c6499a76826d901a0a8bb4e7d33b5b247aceffa15afa971a917516626b. Actual Windows wsl.exe imageSHA2568797ff87fb1ae27f6bbbff141434a404ec2f9f11021444fa0547fc48151d6702. Production src/native proof diff against783 remains empty.

Parent-review proposal only: retain the existing private invocation as the owner of submission, liveness and terminal acknowledgment; supervise a request-owned guest child scope using the already-required user systemd where appropriate; cancellation/EOF terminates and waits only that scope, with acknowledgment after guest-tree exit. Windows owner/pipe cannot report settlement before that acknowledgment plus process/drain settlement. Unknown completion stays busy/fail-closed. Exact private framing, forced-client-exit behavior and scope termination must be reviewed and proven before implementing any wrapper/channel/persistence/deadline change. No production fix has been made. Custom Windows11 proof pool, real credential/wholeCompanion behavior, Chrome consent/upgrade and final consumer lineage remain open.

This follow-up adds only a dedicated hosted workflow, an opt-in E2E test and controlled guest CLI/identity observer. Production src, existing native workflow and consumer57 pin are frozen at783f178c. No production cancellation fix, ABI/selector/permissions/deadline change, merge, signing or release is included.

Existing setup proof was checked from actual terminal TRX, not its job name: run35429580488 executed37/passed37; six separate MXC cases were NotExecuted. Named WSL configuration, service-owned gateway, default-user CLI and keepalive cases passed with nonzero durations. The new job reuses E2ESetupFixture unique distro/free ports, replaces only a fixture-owned CLI entrypoint with an explicitly synthetic barrier, invokes unchanged BrowserBootstrapWslCommand and PipeServer/PipeClient, and independently observes PID/start identity/descendants for normal, IPC EOF, client cancellation, deadline, forced Windows-client exit and pipe retirement. This is NOT real credential/whole-Companion/custom-Windows11-pool proof.

Only an allowlisted numeric/boolean terminal receipt is uploaded. Raw test output, fixture logs/config/env and credentials stay private. CLI restoration and owned-distro teardown are required; red/unknown observations are retained before test cleanup. Zombies, absent PIDs and running processes remain distinct; no pre-completion settlement claim is inferred from Windows join alone.

Local E2E graph compile passed with zero warnings/errors. Guest observer unit checks passed (PID reuse refusal/pidfd cleanup/case isolation). Required Linux full build/setup check remain Windows-blocked; Shared194fail and Tray18fail remain failed local attempts. Scoped review corrected the zombie/absence label. Final independent Codex review exited clean on the exact three-file follow-up f7659f7. The hosted component trace is now terminal as detailed above; pre-completion settlement ordering remains unproven. Existing native14/14 and Windows CI receipts remain accepted historical evidence, not rerun results for this trace.

Actual proof-only published head 57fd3b0, reviewed source f7659f7. Attempt35432386447 failed workflow validation before any job/fixture ran: runner.temp was not allowed in job-level env (line22). No trace artifact exists and this is not a WSL capability denial. The two-line workflow-only correction passed its own scoped Codex review and was published normally as c6fc223 plus Gateway metadata. Current head7bd45d9872b06d99f3aaff4ba01569baa4f8f85d runs trace35432479861. Production/test implementation and accepted native pins are unchanged; trace execution completed; not claimed as a pre-retirement guest-settlement pass. No native proof or full matrix was manually rerun.

Accepted native proof head: 783f178. Reviewed production source d7795a2 is unchanged. Reviewed fixture-only correction e3db53c adds full producer history for GitVersion and closes the settled synthetic IPC fixture before final delivery. The publisher added only metadata. This PR remains DRAFT and is not task-merge-ready. Consumer remains exact 57f78c49d47f445b85d4859f038e8447e08983ba for this proof.

Verified composed success: run35429579145, redacted receipt10580531991, NEW producer10580132336. Actual head783f178ca5579d057d4799fceb5cec5e8c4d69f8 and exact consumer57f78c49 were checked against run/artifact/receipt identities. Executable SHA256 1f4ea285a26fecc0d084c53bd764f177c819f2c3d2338641b410d8cfc3b5f6b8 matches both the uploaded source manifest and independently hashed downloaded executable. Old6dd was not reused.

All 14 cases passed, including the ten prior checks. The receipt reports syntheticPairing=false, six accepted role chains, actual pairing/nonce/version validation, unchanged prepublication state, typed manifest_invalid refusal after uninstall/replacement with no pairing or old-state change, missing/preserved registration postconditions, unchanged replacement state, in-flight inspection/retirement busy, response before completed retirement, real in-flight EOF kill/join without pairing/state effect, parser-variant refusal and owned_registration_removed cleanup. This is real new-producer/current-pinned-consumer red-to-green evidence, not a unit-only substitution.

Current Windows CI35429580488 is terminal SUCCESS on attempt2, including CI Gate, on the same published783f178c. Attempt1 had a stalled Tray UI startup: no case output for26minutes versus16seconds on preceding identical-production run. Its cancellation and job105861715837 logs are retained, not called success. Exactly one targeted UI retry105865442082 plus dependent gate was requested; successful job timestamps were retained, not rerun. No code/assertion/deadline change for that retry.

Verified native counts: Shared4049pass/1skip; Connection809pass/1skip; BrowserBootstrap171pass/0skip including actual probe descendants; WinNodeCLI127pass/0skip; Tray2985pass/0skip; Tray integration22pass/0skip; SetupEngine1192pass/1skip. UI retry: Functional19pass, TrayUI117pass, Accessibility22pass, DevBuild identity verified. Setup/connect, network and revocation E2E, proof-pool contracts, x64 package/installer and both MSIX lanes passed. Production release/ARM64 release jobs skipped. Standard MSIX validation used its existing disposable Dev certificates; no production signing/release was initiated.

CodeQL workflow35429580470 succeeded with its configured security-analysis gates skipped; not claimed as a completed code scan. WSL guest settlement, final moving-consumer lineage, Chrome consent and upgrade gates remain open; DRAFT/no merge/release/no overall LAND completion.

Preserved repair-stage failures on4e3ad46f: composed35428758314 failed before tests/artifact creation because GitVersion rejected shallow checkout. CI35428759743 is terminal failure: Shared4048pass/1fail/1skip (global unobserved SafeFileHandle/ReadToEnd exception captured by the MCP disposal test), and packaged x64 synthetic IPC smoke waited for final response while its settled server remained open. The two fixture corrections are independently reviewed, with no product/validator/deadline change. The separate Shared failure remains explicitly unresolved, not weakened or silently called baseline. Other standard gates passed, including Tray/setup/integration, UI, network/setup/revocation E2E and MSIX; release skipped. The normal PR CI tested merge-ref f3d1248; comparison confirms no production src changes relative to4e3ad46f. No actual composed binary/TS proof was produced by the failed first run.

The current C# owner admits only the complete active generation and holds the existing SID mutex on one owning thread through backend work, confirmed joins and final success/failure frame delivery. No Store gating was added to ordinary bootstrap. Only the exact existing keyless input/caller cases avoid reacquisition; both still execute canonical TS and require its actual expected failure. No TS activation/parent policy, new wire fields, changed generation format, ACL weakening, GC shortcut or pairing rotation.

Scoped source review completed clean (Codex gpt-5.6-sol, autoreview local, exit 0). Retained red-before/green-after regressions cover early IPC cleanup release, oversized discard, expired-budget process/task joins, failure-frame serialization and cancellation-raced partial delivery. Probe descendants use a job assigned before sending the existing frame, not a new probe flag. Proof instrumentation timestamps retirement settlement independently and awaits controller readiness before releasing input.

Remaining WSL gap: Windows process/drain exit is not Linux guest-command settlement. The current invocation closes stdin after script submission and has no guest cancellation/exit acknowledgment. No new guest wrapper/channel/persistence/deadline change is included. Unsettled work stays busy/fail-closed; no hard forced-cleanup or overall LAND-complete claim is made.

The current composed workflow builds and uploads a new GITHUB_SHA/image-hash-bound producer; exact run lineage and terminal failures are recorded above. Old6dd is retained only as historical evidence, never as repaired proof. The run must validate all ten prior checks, stale-launcher refusals with zero-state and registry postconditions, real in-flight inspect/retire/EOF, parser variants, probe descendants, receipt identities and cleanup. Current-head standard Windows CI is also required. No signing/release or real-user installation.

Historical producer, failed investigations and prior Windows validation (not current repair proof)

Producer source and reused binary: 6dddf3d. Proof-only harness head: 16117ce.

Terminal current-consumer result: authority_review_required, not merge-ready. Run 35422437058, redacted receipts 10577951928, producer 6dddf3d / consumer 57f78c49d47f445b85d4859f038e8447e08983ba. All six private role chains and real read-only config validation passed. Ten checks passed: management EOF rejection, real generation installation with canonical TS prepublication probes, actual C#→TS admission and real pairing, origin/profile/state-context rejection, Chrome EOF cancellation, and preservation of the active generation. No synthetic Companion response. Owner cleanup succeeded.

The separate fresh-state lifecycle investigations reproduced both requested behaviors:

  • After completed owner-mediated uninstall, the prior launcher returned success and pairing material and changed its isolated state. Registration remained missing; it was not silently restored. Keyless prepublication probes had not changed that fresh state.
  • After owner-mediated replacement installation, the previous launcher still returned success/pairing material and changed its old isolated state. Replacement state was unchanged and the replacement registration remained active.

This is exact observed lifecycle behavior requiring coordinated authority-contract repair/review, not a newly invented policy or a completed merge gate. C# Program/GenerationStore.RuntimeLease and TS admitWindowsNativeRuntime validate retained private generation integrity/context without current registration identity. RemoveNative deliberately retains generations because GC is not an ABI postcondition. Any agreed active-authority check must occur before successful key/relay side effects while preserving existing keyless prepublication invalid-request/origin probes. No generation tampering, new bypass/probe flag, second registry writer, product source edit, or main/ABI change was made. No merge.

Live ACL result: run 35421401544, redacted receipts 10577965011, diagnosed global-node ancestors 5..1: inherited allow ACE 0 (AceFlags=16), classified authenticated_users, mask 0x001301bf, forbidden-write intersection 0x00010110; leaf intersection 0x00010116. checkout-cli/ancestor-5 failed untrusted_owner (identity withheld). Private installation passed all 16 Node/CLI components, then all six producer/node/CLI/state/config/generation-root role audits passed. Exact current consumer built, actual producer installation and canonical TS rejection probes passed. Positive bootstrap failed afterward; owner cleanup succeeded.

The remaining fixture error is verified against the exact57 schema: profile color is doctor-only legacy input rejected by the strict canonical config schema. Current harness removes it, validates the fixture with actual built SDK readConfigFileSnapshot({observe:false,pluginValidation:"core-only"}), and captures only safe bootstrap response booleans/allowlisted code and harness coordinates. Raw child stderr is explicitly captured, not echoed. Both product pins, validators and global permissions remain unchanged. The corrected-fixture terminal result is recorded above.

Setup attempts 35421033735 and 35421233474 are preserved failures, not native proof. The latter precisely isolated CommandNotFoundException during Node resolution: all hosted-Windows booleans true and audit helper compilation passed. The reviewed correction discovers the actual executable through the installed node launcher, canonicalizes it and requires v24.16.0; production native execution still uses only an explicit admitted private path. No ACL observations or product defect were claimed from these preflight failures.

Scoped autoreview is clean after fixing snapshot/refusal/registry-postcondition evidence gaps. C# audit compile, PowerShell parse, JS syntax and focused proof-evidence checks passed. Required local baseline attempts are not Windows proof: build refused Linux; Shared 3815 passed / 194 failed / 33 skipped; Tray 2965 passed / 18 failed / 2 skipped. No claim of local full-suite success. Normal PR CI runs automatically; no completed matrices were manually rerun.

First composed run built canonical consumer 2048e9b7fa3edcf9993925f29defb17af2c52ebf successfully, then the real producer returned unsafe_path during management installation before TS probes. Missing-management-EOF rejection passed and owner cleanup removed no foreign data. Redacted terminal receipt.

Corrected bounded composed proof completed failure: the exact consumer built, all five producer/node/CLI/state/config path chains were canonical with no symbolic ancestors, but the real producer refused management installation with unsafe_acl before TS probes. Management missing-EOF rejection passed; owner-mediated registry cleanup succeeded. Redacted terminal receipt. Producer executable SHA-256: 950e00a348ee9c31077c36d274c81500b79ae3fb05f812987d6705d32cad01cb. This is not a successful composed native proof. The exact rejected path/ACE is not exposed by the public receipt; do not infer that TS TrustedInstaller handling is missing.

The 04:07 continuation performs that fixture/runtime investigation in this same Windows lane. The prior private-layout proposal is not completion or an external-owner blocker.

  • Full Windows matrix: success, including CI Gate; release skipped.
  • PR-required workflow: success on attempt 2, including CI Gate. Attempt 1 failed while creating its disposable WSL distro (wsl.exe list timed out before the revocation test ran); only failed jobs were rerun. The full exact-head matrix also independently passed revocation E2E. Both completed run conclusions were verified on September 19, 2026 at 03:06 UTC.
  • x64 native and installer proof: success.
  • ARM64 native executable proof: success.

The x64 log contains NATIVE_BOOTSTRAP_PROOF_OK and INNO_MANAGEMENT_TRANSPORT_PROOF_OK. The latter executes a disposable fixture installer/uninstaller using the actual shared Pascal pipe client and helper. It is not a signed release, production Chrome/WSL proof or real-user installation.

Accepted contract SHA-256: 1ad636e97e200ef34f3609d734bbfc2272ae5aba75cccc3df42952a3352f565a. Boundary fixtures SHA-256: b52e1acc48e74114311c32641bc807987c61adfdf4b584fe7b6305f0d6c122a3. Both were reverified after restart recovery.

Change Type

  • Feature
  • Refactor
  • Tests or validation
  • Security hardening
  • Docs or instructions

Scope

  • Gateway, connection, or pairing
  • Setup or onboarding
  • Permissions, privacy, or security
  • Tests, CI, or docs
  • New Windows node capability or local MCP command

Required proof pools

  • windows-clean-installer-upgrade: signed fresh/upgrade/repair/uninstall and remembered opt-out.
  • windows-wsl-gateway-e2e: actual allowed/denied/revoked production credential path with the matching core candidate.
  • windows-11-arm64: native executable, ACL/registry and architecture behavior.
  • windows-winui-interactive: actual Chrome approval and Companion connection/preference behavior.

Validation

Current diagnostic-source checks: node --test scripts/BrowserNativeSavedProfile.test.mjs scripts/BrowserNativeProofTiming.test.mjs: 7/7 passed. dotnet test tests/OpenClaw.E2ETests/OpenClaw.E2ETests.csproj --no-restore --filter FullyQualifiedName~BrowserWslLookupDiagnosticsTests: 6/6 passed, with successful E2E graph compilation. Exact lookup PowerShell parsed; git diff --check passed.

Required local attempts: ./build.ps1 through the installed PowerShell runtime failed because Windows is required; Shared --no-restore: 3823 passed / 194 failed / 33 skipped; Tray --no-restore with isolated data: 2965 passed / 18 failed / 2 skipped. These Linux attempts are not native acceptance and no failures are waived. Fresh Windows CI and dedicated proofs remain required.

Current repair local checks (d7795a2, Linux, isolated tray settings):

  • dotnet test tests/OpenClaw.BrowserBootstrap.Tests/OpenClaw.BrowserBootstrap.Tests.csproj --no-restore -c Release: 166 passed, 0 failed, 5 native-Windows tests skipped.
  • Shared pipe/process/protocol focused tests: 34 passed, 0 failed.
  • dotnet test tests/OpenClaw.Connection.Tests/OpenClaw.Connection.Tests.csproj --no-restore -c Release --filter FullyQualifiedName~BrowserBootstrap: 16 passed, 0 failed.
  • node --test scripts/BrowserNativeProofTiming.test.mjs: 3 passed. JS syntax, PowerShell parser and embedded proof-controller C# compile passed.
  • pwsh -File build.ps1 and pwsh -File scripts/setup-dev.ps1 -CheckOnly: Windows required; not a native build pass.
  • dotnet test tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: 3,823 passed, 194 failed, 33 skipped.
  • dotnet test tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: 2,965 passed, 18 failed, 2 skipped.

These local failures/skips are not accepted Windows validation. The new composed proof and current standard Windows CI are verified terminal success as detailed above, including the disclosed targeted UI retry. Local Linux failures remain historical failed attempts, not converted to passes. Fresh independent review used the exact local change bundle and adjacent ownership/protocol source, and completed with no accepted/actionable findings. No additional unchanged-bundle review is required.

Historical validation before the activation repair

Current-head Windows x64 and ARM64 packaged helper gates pass. Actual production installer compilation and disposable shared-client install/uninstall pass on x64. The early compiler-only gate prevents unsupported Pascal declarations from reaching slow builds.

Exact-head native core results: Shared 4,041 passed/1 skipped; Connection 809 passed/1 skipped; BrowserBootstrap 133 passed/0 skipped; WinNode CLI 127 passed/0 skipped. Tray 2,985 passed/0 skipped; Tray integration 22 passed/0 skipped; SetupEngine 1,192 passed/1 skipped. No failures. The original foreign-write race, uncontended create/update/delete, private/ancestor ACL and uncancellable-read regressions all execute on Windows.

Required local commands were rerun after code changes on this Linux host:

  • pwsh -File build.ps1 and pwsh -File scripts/setup-dev.ps1 -CheckOnly: refuse Linux; not native build proof.
  • dotnet test tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: 3,815 passed, 194 failed, 33 skipped.
  • dotnet test tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: 2,965 passed, 18 failed, 2 skipped.
  • dotnet test tests/OpenClaw.BrowserBootstrap.Tests --no-restore: 129 passed, 4 native-Windows cases skipped.
  • Focused package/cache tests: 6 passed. Installer integration contracts: 3 passed.
  • PowerShell parser, production framing helper, CI workflow contracts and git diff --check: passed.

Linux runtime/path/loopback failures are not represented as green gates. Native matrix results above are the platform evidence.

Independent review repaired registry concurrency, uncancellable stdin deadlines, protected Program Files ancestor admission, packaging and installer compiler defects. Each repair received fresh scoped review. The final producer review's request to migrate the alleged previous release was rejected: the retired helper existed only in this unmerged PR; the agreed ABI requires unknown/legacy bindings to be preserved and refused. No clean-review claim is made for that exit-1 pass. Subsequent scoped repair reviews exited 0 without actionable findings.

Real Behavior Proof

Current fixture changes have portable diagnostic tests only. New hosted native/WSL proof and exact final-consumer lineage are pending; no whole-Companion, Chrome consent or upgrade claim is added.

Current repair: published783f178c/source d7795a2 plus fixturee3db53c2; new producer artifact and all14 composed checks verified in run35429579145 as detailed above. Prior terminal red run 35422437058 remains preserved and is not relabeled green. WSL guest settlement, Chrome consent, final moving-consumer lineage and upgrade gates remain open.

Historical pre-repair packaged helper evidence follows, not current repaired runtime proof:

  • Environment: disposable hosted Windows x64 and native ARM64 runners.
  • Head: 6dddf3d.
  • Native command: ./scripts/Test-BrowserNativeHost.ps1 -ExecutablePath publish/tools/browser-bootstrap/OpenClaw.BrowserBootstrap.exe.
  • Installer command: ./scripts/Test-BrowserBootstrapInstaller.ps1 with that executable and the installed Inno Setup compiler.
  • Observed: exact packaged binaries execute; management requires EOF and rejects missing EOF within its deadline; private generations and ownership checks work; native framing/origin/current-user IPC, native-first Store request, cleanup and foreign preservation pass. Installer/uninstaller pipes accept bounded clean receipts and clean owned registry entries.
  • Evidence links: current-head job links and successful log markers verified. No Chrome screenshot claimed.
  • Not verified / blocked: composed canonical TypeScript native-Windows consumer; actual Companion/provenance/WSL production credential delivery and rejection after foreign destination/disconnect/switch; Chrome consent; signed fresh/upgrade/repair/uninstall and MSIX runtime upgrade behavior. These remain merge gates.

Security Impact

Optional user-approved Chrome enrollment adds native execution and owned current-user registry metadata. Pairing travels through authenticated same-user IPC or the explicitly bound canonical Windows CLI. No gateway-token fallback, Chrome profile edits, enterprise policy, elevation or arbitrary selector fields. Private ownership protections remain strict; TrustedInstaller is accepted only for existing non-private directory ancestors.

Compatibility and Migration

No external Chrome v1 bump, public user-config fields or native-Windows provisioning. Foreign/unknown/legacy registrations are preserved and refused, not adopted. Same-context new-format upgrades require renewed admission. Partial or uncertain operations are not falsely reported as rolled back. Uninstall retains generation directories rather than recursively deleting possibly referenced content.

Review Conversations

  • Accepted implementation and native-CI findings addressed and re-reviewed.
  • Production integration and upgrade proof complete before merge.

The fork-only collaboration toggle is inapplicable to this same-repository PR (GitHub 422); normal repository collaborator permissions apply.


View the OpenClaw team session

roboclaw-bot and others added 5 commits September 18, 2026 17:44
Add a bounded native-messaging executable, current-user tray IPC, managed-local WSL pairing admission, ownership-preserving registration, packaging, and architecture-specific proof hooks. Store installation and Windows runtime proof remain coordinated follow-up gates.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Register the native host before creating the owned HKCU external Store request, preserve foreign entries and persisted opt-outs, and remove only owned registrations. Match the coordinated remote:false CLI response and keep pre-setup bootstrap retryable.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@clawsweeper

clawsweeper Bot commented Sep 18, 2026

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

OpenClaw-Publication: ebec6cb8-5bb0-429e-9c98-7584d9f52b77

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@roboclaw-bot
roboclaw-bot force-pushed the openclaw/automatic-chrome-extension-pairing branch from 1004606 to 136a955 Compare September 18, 2026 18:16
@roboclaw-bot roboclaw-bot added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 18, 2026
@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 18, 2026
@clawsweeper

clawsweeper Bot commented Sep 18, 2026

Copy link
Copy Markdown

Codex review: needs real behavior proof before merge. Reviewed September 19, 2026, 8:20 PM ET / September 20, 2026, 00:20 UTC (Revision 34).

ClawSweeper review

What this changes

Adds a packaged Windows helper, installer integration, and Companion-to-WSL pairing so Chrome can connect to an explicitly selected local OpenClaw runtime.

Merge readiness

Blocked before merge - 9 items remain

This remains useful, unmerged work. Both prior findings remain actionable, and the accepted native evidence does not yet satisfy the Companion authority, saved-profile, and upgrade acceptance gates.

Priority: P2
Reviewed head: de288593ab32f0f91ecd2abb4726a73deed56a43
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) Substantial implementation and valid native evidence remain useful, but two retained findings and incomplete authority and upgrade acceptance prevent merge readiness.
Proof confidence 🦐 gold shrimp (3/6) Needs stronger real behavior proof before merge: Authority-chain proof required: preserve the accepted 14 real native-helper/CLI cases on unchanged helper source. The complete Companion allowed/foreign/disconnected/switched-authority path, final-consumer saved-profile acceptance, Chrome consent, and signed upgrade evidence remain explicitly open. Current dedicated runs were still pending, and the saved-profile fixture retains its source-proven defect; these gaps are not inferred from omitted body text. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Patch quality 🦐 gold shrimp (3/6) Security review found an item that needs attention.

Verification

Check Result Evidence
Real behavior Needs proof Needs stronger real behavior proof before merge: Authority-chain proof required: preserve the accepted 14 real native-helper/CLI cases on unchanged helper source. The complete Companion allowed/foreign/disconnected/switched-authority path, final-consumer saved-profile acceptance, Chrome consent, and signed upgrade evidence remain explicitly open. Current dedicated runs were still pending, and the saved-profile fixture retains its source-proven defect; these gaps are not inferred from omitted body text. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Evidence reviewed 10 items Applicable repository policy: Read the complete root AGENTS.md and proof-validation skill. No applicable nested AGENTS.md or maintainer-notes directory was found. Applied ownership, native proof, and upgrade guidance; no builds, tests, or reviewer helpers were executed in this read-only review.
Verified introduced scope: The pinned merge-base-to-head comparison contains 88 files, 7,612 additions and 11 deletions. The checkout is the original PR head. No removal claim is inferred from the stale test-merge classification.
Current main owns a different browser path: Current main’s browser.proxy forwards HTTP requests to a browser-control endpoint; it does not implement this native Chrome enrollment and pairing path. Main and the supplied latest-release tree contain no BrowserBootstrap implementation.
Findings 2 actionable findings [P2] Expect generation reuse for an unchanged saved-profile install
[P3] Update the proof command to the packaged executable
Security Needs attention Complete Companion credential revocation proof: Source checks active gateway intent and endpoint provenance before and after CLI work, but available evidence explicitly leaves the full Companion path unverified for foreign listeners and authority revoked during pairing. Demonstrate rejection before credential delivery; this is an unresolved proof boundary, not an established exploit.

How this fits together

Chrome sends native messages through a registered Windows helper. The helper validates its installation and delegates pairing to either Companion’s managed WSL gateway or an explicitly bound Windows CLI, returning pairing material only through that selected path.

flowchart TD
  A[Installer or Companion startup] --> B[Owned native registration]
  C[Chrome extension request] --> D[Windows helper admission]
  B --> D
  D --> E{Selected runtime}
  E --> F[Companion and managed WSL]
  E --> G[Bound Windows CLI]
  F --> H[Pairing response or refusal]
  G --> H
Loading

Decision needed

Question Recommendation
May the managed-WSL pairing lane ship with indefinite UNKNOWN/BUSY retention after a lost settlement acknowledgment? Resolve recovery before landing: Keep the lane unlanded until safe recovery and shutdown behavior are defined and demonstrated without releasing unacknowledged work.

Why: The retention is deliberate and security-preserving, but tests cannot decide whether its pairing, retirement, and shutdown availability tradeoff is acceptable.

Before merge

  • Add real behavior proof - Needs stronger real behavior proof before merge: Authority-chain proof required: preserve the accepted 14 real native-helper/CLI cases on unchanged helper source. The complete Companion allowed/foreign/disconnected/switched-authority path, final-consumer saved-profile acceptance, Chrome consent, and signed upgrade evidence remain explicitly open. Current dedicated runs were still pending, and the saved-profile fixture retains its source-proven defect; these gaps are not inferred from omitted body text. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
  • Expect generation reuse for an unchanged saved-profile install (P2) - This prior finding remains: GenerationStore.Prepare returns the existing generation when the context and executable hash match, but this assertion expects a new directory for install. The real composed proof therefore fails on correct reuse. Assert unchanged generation/directory state and explicitly seed the retired generation needed by the later mixed-generation case, rather than relying on reinstall to create it.
  • Update the proof command to the packaged executable (P3) - This prior finding remains: packaging emits OpenClaw.BrowserBootstrap.exe, but the documented command passes OpenClaw.BrowserNativeHost.exe. Following these validation instructions fails before the native proof starts. Use the executable name already used by the CI publish jobs.
  • Resolve security concern: Complete Companion credential revocation proof - Source checks active gateway intent and endpoint provenance before and after CLI work, but available evidence explicitly leaves the full Companion path unverified for foreign listeners and authority revoked during pairing. Demonstrate rejection before credential delivery; this is an unresolved proof boundary, not an established exploit.
  • Resolve merge risk (P1) - The complete Companion path has not yet demonstrated that foreign listeners, disconnects, and gateway switches prevent credential delivery at the final effect.
  • Resolve merge risk (P1) - Lost WSL settlement acknowledgments deliberately leave pairing and registration retirement blocked indefinitely; safe user recovery and shutdown behavior remain unsettled.
  • Resolve merge risk (P1) - New persisted generation metadata and installer enrollment need signed fresh-install and upgrade acceptance showing preservation of saved pairing, opt-outs, and foreign registrations.
  • Complete next step (P2) - Repair both retained findings, complete coordinated native/Companion and upgrade acceptance against the final consumer, and obtain an explicit lost-acknowledgment recovery decision before merge.
  • Resolve maintainer decision - Resolve the maintainer decision shown above before merge.

Findings

  • [P2] Expect generation reuse for an unchanged saved-profile install — scripts/Test-BrowserNativeSavedProfile.mjs:61-62
  • [P3] Update the proof command to the packaged executable — docs/BROWSER_EXTENSION_BOOTSTRAP.md:114
  • [medium] Complete Companion credential revocation proof — src/OpenClaw.Connection/BrowserBootstrapService.cs:34
Agent review details

Security

Needs attention: No new supply-chain defect was established, but the Companion credential authority boundary still requires final-effect acceptance.

Review metrics

Metric Value Why it matters
Production and test tree growth src/: +2323/-0 lines; tests/: +2740/-3 lines The stated growth establishes one Windows registration and transport owner with contract and lifecycle coverage.

Merge-risk options

Maintainer options:

  1. Complete coordinated acceptance (recommended)
    Repair the proof fixture, bind the final consumer, and establish authority rejection plus fresh-install and upgrade preservation.
  2. Hold the WSL lane for recovery design
    Pause landing while acknowledgment-loss recovery and its availability tradeoff remain unresolved.

Technical review

Best possible solution:

Keep one Windows registration owner, preserve canonical CLI policy, and land only with demonstrated authority rejection, upgrade preservation, and an accepted lost-acknowledgment recovery contract.

Do we have a high-confidence way to reproduce the issue?

Yes for the retained fixture defect: an unchanged install reaches generation reuse, while the harness expects a new directory. This is source-proven; no runtime tests were executed during the read-only review.

Is this the best way to solve the issue?

The single registration owner is a sound direction, but the current patch is not ready: its acceptance fixture contradicts production behavior and the authority, upgrade, and recovery gates remain open.

Full review comments:

  • [P2] Expect generation reuse for an unchanged saved-profile install — scripts/Test-BrowserNativeSavedProfile.mjs:61-62
    This prior finding remains: GenerationStore.Prepare returns the existing generation when the context and executable hash match, but this assertion expects a new directory for install. The real composed proof therefore fails on correct reuse. Assert unchanged generation/directory state and explicitly seed the retired generation needed by the later mixed-generation case, rather than relying on reinstall to create it.
    Confidence: 0.99
  • [P3] Update the proof command to the packaged executable — docs/BROWSER_EXTENSION_BOOTSTRAP.md:114
    This prior finding remains: packaging emits OpenClaw.BrowserBootstrap.exe, but the documented command passes OpenClaw.BrowserNativeHost.exe. Following these validation instructions fails before the native proof starts. Use the executable name already used by the CI publish jobs.
    Confidence: 1

Overall correctness: patch is incorrect
Overall confidence: 0.97

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 8ed7c56dfd02.

Labels

Label justifications:

  • P2: This is a useful optional browser setup feature with bounded repair and acceptance work, not an established urgent shipped regression.
  • merge-risk: 🚨 compatibility: Installer enrollment and persisted native generations require proof that upgrades preserve existing pairing, preferences, and foreign ownership.
  • merge-risk: 🚨 security-boundary: The new credential handoff still lacks complete Companion final-effect proof for forbidden and revoked authority.
  • merge-risk: 🚨 availability: A lost guest acknowledgment can indefinitely retain the single-flight pairing operation and block registration retirement.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🦐 gold shrimp.
  • status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: Authority-chain proof required: preserve the accepted 14 real native-helper/CLI cases on unchanged helper source. The complete Companion allowed/foreign/disconnected/switched-authority path, final-consumer saved-profile acceptance, Chrome consent, and signed upgrade evidence remain explicitly open. Current dedicated runs were still pending, and the saved-profile fixture retains its source-proven defect; these gaps are not inferred from omitted body text. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.

Evidence

Security concerns:

  • [medium] Complete Companion credential revocation proof — src/OpenClaw.Connection/BrowserBootstrapService.cs:34
    Source checks active gateway intent and endpoint provenance before and after CLI work, but available evidence explicitly leaves the full Companion path unverified for foreign listeners and authority revoked during pairing. Demonstrate rejection before credential delivery; this is an unresolved proof boundary, not an established exploit.
    Confidence: 0.96

What I checked:

  • Applicable repository policy: Read the complete root AGENTS.md and proof-validation skill. No applicable nested AGENTS.md or maintainer-notes directory was found. Applied ownership, native proof, and upgrade guidance; no builds, tests, or reviewer helpers were executed in this read-only review. (AGENTS.md:85, de288593ab32)
  • Verified introduced scope: The pinned merge-base-to-head comparison contains 88 files, 7,612 additions and 11 deletions. The checkout is the original PR head. No removal claim is inferred from the stale test-merge classification. (de288593ab32)
  • Current main owns a different browser path: Current main’s browser.proxy forwards HTTP requests to a browser-control endpoint; it does not implement this native Chrome enrollment and pairing path. Main and the supplied latest-release tree contain no BrowserBootstrap implementation. (src/OpenClaw.Shared/Capabilities/BrowserProxyCapability.cs:56, 8ed7c56dfd02)
  • Production explicitly reuses unchanged generations: Prepare returns the existing generation when the binding and executable hash match. The saved-profile fixture still expects one new directory for selector-free install at line 62, then assumes a retained generation exists at lines 123–128. (src/OpenClaw.BrowserBootstrap/GenerationStore.cs:71, de288593ab32)
  • Affirmative canonical-consumer dependency: The target workflow pins this consumer, and the target documentation requires its browser extension CLI contract. runBrowserExtensionSetup recovers the saved Windows profile and delegates installation to the existing management owner; installWindowsNativeHost passes the selected context to that owner. This supports reuse rather than compulsory generation rotation. The coordinated feature PR remains open and unmerged: feat(browser): unify local Chrome setup across desktop and terminal openclaw#152057 (feat(browser): unify local Chrome setup across desktop and terminal). (extensions/browser/src/browser/extension-setup.ts, 57201e3e2696)
  • Earlier findings remain: The current saved-profile assertion remains unchanged in substance from the previously reviewed head; the subsequent commit changes URL expectations and diagnostic reporting. The documentation also still names OpenClaw.BrowserNativeHost.exe, while packaging emits OpenClaw.BrowserBootstrap.exe. (docs/BROWSER_EXTENSION_BOOTSTRAP.md:114, de288593ab32)

Likely related people:

  • shanselman: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • karkarl: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Correct generation-reuse expectations, explicitly seed the retained-generation fixture, and fix the documented executable name.
  • Prove allowed and nearest-forbidden Companion final effects, including disconnect or gateway reassignment before credential delivery, and resolve lost-ack recovery acceptance.
  • Complete final-consumer saved-profile, Chrome consent, and signed fresh/upgrade evidence. Redact private details from screenshots, recordings, terminal output, or logs; update the PR body for automatic re-review, or ask a maintainer to comment @clawsweeper re-review.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (33 earlier review cycles; latest 8 shown)
  • reviewed 2026-09-19T15:30:17.897Z sha 3ab6899 :: needs real behavior proof before merge. :: [P3] [P3] Update the documented proof command to the packaged executable
  • reviewed 2026-09-19T15:45:07.349Z sha 8c9dc44 :: needs real behavior proof before merge. :: [P3] [P3] Update the proof command to the packaged executable
  • reviewed 2026-09-19T20:32:41.635Z sha f7dc5c5 :: needs real behavior proof before merge. :: [P2] [P2] Let the pinned consumer select its pnpm version | [P3] [P3] Update the proof command to the packaged executable
  • reviewed 2026-09-19T20:41:57.022Z sha edd93f4 :: needs real behavior proof before merge. :: [P3] [P3] Update the proof command to the packaged executable
  • reviewed 2026-09-19T21:22:45.920Z sha 97e7aa7 :: needs real behavior proof before merge. :: [P3] [P3] Update the proof command to the packaged executable
  • reviewed 2026-09-19T21:50:46.063Z sha 97e7aa7 :: needs real behavior proof before merge. :: [P3] Update the proof command to the packaged executable
  • reviewed 2026-09-19T21:59:51.723Z sha 2b3ca36 :: needs real behavior proof before merge. :: [P3] Update the proof command to the packaged executable
  • reviewed 2026-09-19T22:14:42.076Z sha 0fc4058 :: needs real behavior proof before merge. :: [P2] Expect generation reuse for an unchanged saved-profile install | [P3] Update the proof command to the packaged executable

roboclaw-bot and others added 3 commits September 18, 2026 18:27
Insert the helper payload after SDK publish conflict resolution so parent runtime assets do not remove its nested hostpolicy and framework files. Add executable MSBuild regression tests and a completeness gate. Independent autoreview passed with no actionable findings.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
…tion objects

Execute the production framing functions in a MemoryStream regression before touching the registry. Suppress VoidTaskResult pipeline output from ReadExactlyAsync. Independent autoreview passed with no actionable findings.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
…input

Address verified ClawSweeper findings: validate the canonical IPv4 destination with the same pinned gateway and distro before and after CLI execution, while retaining original-record lifecycle checks. Normalize CRLF/CR script input to LF before Bash stdin. Six regression cases added; 16 focused connection tests and independent autoreview pass.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Addressed the two code findings in f90b195174a9d58281c58bbc1b78d3a4e71fe18b:

  • Both provenance checks now receive an immutable record pinned to the exact 127.0.0.1 destination returned by the CLI, retaining the same gateway ID and managed distro. Lifecycle/switch checks still use the original active record. Regression cases reject separately owned IPv4 for IPv6/localhost records and verify both destination checks.
  • Bash stdin now normalizes CRLF and lone CR to LF, with Windows-checkout regression cases.

The focused connection suite now passes 16 tests. Independent autoreview of this correction exited 0 with no actionable findings.

Real Windows CI also exposed and led to fixes for nested self-contained runtime files being dropped during publish and async completion objects leaking from the PowerShell proof reader. Those fixes have dedicated regressions and clean independent reviews. The latest exact-head full Windows run is https://github.com/openclaw/openclaw-windows-node/actions/runs/35380918100 . It is still running, not claimed complete.

The draft remains blocked from merge pending the compatible coordinated core CLI, real production Windows/WSL authority-chain and Chrome approval proof, and installer/upgrade proof. Synthetic pipe tests are not presented as that authority-chain evidence. No forced enterprise policy, release publication, or merge is requested here.

Clear the stale native exit code only after all proof assertions and cleanup finish successfully. Real Windows x64 and ARM64 runs reached both success markers but GitHub inherited the last intentional rejection exit status. Independent autoreview passed without actionable findings.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. and removed rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. labels Sep 18, 2026
@roboclaw-bot roboclaw-bot added status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. and removed status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. labels Sep 18, 2026
roboclaw-bot and others added 6 commits September 19, 2026 01:43
Use the agreed bounded management ABI and sole generation-backed registry owner for explicit managed WSL and native Windows transports. Preserve private ACL, provenance, lifecycle, cancellation and foreign-entry protections; exercise packaged helpers and installer pipe management in Windows CI.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 419c1274-364c-4165-8c59-cb7f1f493677
Require the ninth non-E2E suite and derive the strict runner count from the explicit project inventory. Reproduced the exact Windows fast-validation failure locally; repaired contract passes and fresh scoped autoreview is clean.
OpenClaw-Publication: 44e3f8cf-ed9c-4ab9-b824-078556e512cb
Track the credential-free single-file profile previously omitted by the generic pubxml ignore rule, fail before nested publish when missing, and verify bundle settings. Update the core cache test inventory for the complete bootstrap graph and normalize MSBuild paths for portable validation. Focused packaging/cache tests and fresh scoped review pass.
OpenClaw-Publication: 925fbbfa-fb99-42c4-b323-2157e9967e18
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. label Sep 19, 2026
roboclaw-bot and others added 2 commits September 19, 2026 07:22
Fetch full producer history for GitVersion, and close the synchronous
synthetic IPC handler before awaiting the native host final response.
Preserve all native validators, consumer pin, deadlines and assertions.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: afab64dc-d33f-40ce-bc86-39f2c5dc5241
@clawsweeper clawsweeper Bot removed the merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. label Sep 19, 2026
roboclaw-bot and others added 12 commits September 19, 2026 08:34
Keep production source and accepted native proof frozen at 783f178. Reuse the disposable managed WSL fixture and label controlled CLI component evidence, red/unknown retirement boundaries, and scoped cleanup explicitly.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 7b1b4687-7c3a-4fcc-82f1-13a9454b4a03
Move the unchanged receipt path out of job-level runner context. No trace, production, native proof pin, permission or deadline change.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: e4166975-f3e2-45bc-b96a-249bd4709204
Replace round-trip postchecks with a persistent independent observer and causal post-boundary challenges. Timestamp unchanged source-linked native activation and serialized retirement owners with explicit component scope. Preserve production source, native protocol, deadlines and accepted proof pins.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: cf71fe03-1dac-40bb-8dff-c18802a41653
Exercise fixed stdin handoff, strict private frames, single-use permit, transient user-systemd cgroup ownership, successful detached-child cleanup, cancellation/loss boundaries, and observed epoch refusal before production wiring. Preserve public contracts and 16384 UTF16 payload capacity. Missing acknowledgment remains an explicit UNKNOWN checkpoint, not permission to retire.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 847c6ecd-a165-4e81-93e2-6a3c023df253
Apply the production-equivalent CRLF/CR normalization to actual stdin. Require a bounded broker-entry witness before classifying any protocol case and preserve exact collision identity. Add and run the portable transport regression; retain the failed first hosted receipt.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: adeaf35e-c123-4c3e-befd-ea8bd1baadd0
Build the immutable reviewed consumer through its self-contained package helper and use the existing candidate-package setup interface. Verify source/version/hash and the required CLI option before testing real pairing. Preserve the failed release-CLI receipt and strengthen negative-case assertions.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: e6f61c00-e221-46e7-9e54-78b40467fbc6
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. label Sep 19, 2026
roboclaw-bot and others added 2 commits September 19, 2026 20:33
Remove the duplicate action version that rejected the consumer packageManager integrity-qualified pin before package build. Keep the immutable consumer and frozen install unchanged.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 4b0039c9-267b-4970-9b6d-8191f5840a43
@clawsweeper clawsweeper Bot removed the merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. label Sep 19, 2026
roboclaw-bot and others added 2 commits September 19, 2026 21:15
Use a single-use private READY/PERMIT/RESULT/SETTLED exchange with request-owned transient user-systemd supervision. Revoke via EOF, require positive guest acknowledgment and Windows/drain settlement, and retain UNKNOWN/BUSY when acknowledgment is missing. Preserve existing public ABI, authority selectors, request and cleanup budgets.

Add strict framing/cancellation regressions and a dedicated actual-owner hosted proof, including early EOF and missing-ack retirement retention.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: a44b98a1-def8-4950-9c4c-c9d028c41304
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 availability 🚨 Merging this PR could cause crashes, hangs, restart loops, stalls, or process outages. label Sep 19, 2026
roboclaw-bot and others added 7 commits September 19, 2026 21:53
Use the parent-bound full owner command line, single-match enforcement, a pinned process handle and executable-image verification. Bound both lookup drains and process waits, and retain redacted failure-stage and retirement counters without weakening missing-ack BUSY assertions.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 29ce3e8f-5acf-4f2a-9adf-29d6f3dd4956
Pin the published 57201e3e consumer, retain all fourteen native lifecycle cases, and exercise canonical CLI saved-work recovery, relay and pairing preservation, Store intent, fail-closed context and inventory cases, cancellation, retired selection, and verified owned cleanup.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 41652768-6ae2-4ff4-a411-44d8d77c0c4d
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
…duction

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 4667b421-0ba1-42be-8c15-83136272b5be
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 availability 🚨 Merging this PR could cause crashes, hangs, restart loops, stalls, or process outages. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant