Skip to content

Phase 1 slice 4: Route exec, interactive sessions, and SSH through the OpenShell adapter #9804

Description

@rsliter

Parent Epic: #9802

Outcome

Route buffered exec, interactive command transport, and SSH-session behavior through the typed OpenShell interface.

Draft scope

  • Define typed command, stream, interactive-session, and SSH transport results required by current consumers.
  • Keep CLI exec flags, SSH-config parsing, subprocess wiring, terminal details, and gateway arguments inside the CLI implementation.
  • Migrate production exec, connect, command-transport, health-probe, agent setup, and version-probe consumers.
  • Preserve cancellation, signal, timeout, TTY, stdout, stderr, and exit-code behavior.

Acceptance evidence

  • Commands preserve arguments, working directory, environment, input, output streams, and exit status.
  • Timeout, cancellation, missing executable, transport failure, and remote nonzero exit remain distinguishable.
  • Interactive and SSH paths do not widen credential or terminal access.
  • Consumers do not parse CLI SSH configuration or process-shaped results.

Test plan

  • Action tests against typed exec and session fakes.
  • CLI implementation tests for exact argv, input, streams, timeout, signals, and SSH-config parsing.
  • Existing command-transport, connect, session, agent, and sandbox-version tests.
  • Focused runtime evidence for interactive terminal behavior where mocks are insufficient.

Dependencies and sequencing

Blocked by Slice 1. File transfer, port forwarding, and log fallback work should reuse the transport boundaries established here.

Deferred scope

  • SDK exec and SSH implementation.
  • Redesign of the user-facing terminal experience.
  • File transfer and persistent forwarding.

Activity

  1. self-assigned this
    on Aug 20, 2026
  2. added theissue type on Aug 20, 2026
  3. added
    area: cliCommand line interface, flags, terminal UX, or output
    on Aug 24, 2026
  4. cv commented on Aug 28, 2026

    @cv
    Collaborator
    • .agents/skills/nemoclaw-maintainer-verify-stale/reference/brev-provisioning.md:764 — Sandbox execution or interactive-access call or contract.
    • .agents/skills/nemoclaw-maintainer-verify-stale/reference/brev-provisioning.md:768 — Sandbox execution or interactive-access call or contract.
    • .agents/skills/nemoclaw-maintainer-verify-stale/reference/brev-provisioning.md:773 — Sandbox execution or interactive-access call or contract.
    • agents/hermes/Dockerfile.base:394 — Sandbox execution or interactive-access call or contract.
    • agents/langchain-deepagents-code/Dockerfile.base:313 — Sandbox execution or interactive-access call or contract.
    • agents/langchain-deepagents-code/start.sh:442 — Sandbox execution or interactive-access call or contract.
    • agents/pi/Dockerfile.base:320 — Sandbox execution or interactive-access call or contract.
    • agents/pi/start.sh:382 — Sandbox execution or interactive-access call or contract.
    • docs/monitoring/monitor-sandbox-activity.mdx:91 — Sandbox execution or interactive-access call or contract.
    • docs/monitoring/monitor-sandbox-activity.mdx:94 — Sandbox execution or interactive-access call or contract.
    • docs/network-policy/apply-policy-presets.mdx:160 — Sandbox execution or interactive-access call or contract.
    • docs/network-policy/approve-network-requests.mdx:33 — Sandbox execution or interactive-access call or contract.
    • docs/network-policy/approve-network-requests.mdx:50 — Sandbox execution or interactive-access call or contract.
    • docs/network-policy/create-custom-policy-presets.mdx:221 — Sandbox execution or interactive-access call or contract.
    • docs/network-policy/create-custom-policy-presets.mdx:44 — Sandbox execution or interactive-access call or contract.
    • docs/reference/cli-selection-guide.mdx:201 — Sandbox execution or interactive-access call or contract.
    • docs/reference/commands.mdx:1331 — Sandbox execution or interactive-access call or contract.
    • docs/reference/commands.mdx:4203 — Sandbox execution or interactive-access call or contract.
    • docs/reference/commands.mdx:4209 — Sandbox execution or interactive-access call or contract.
    • docs/reference/commands.mdx:4212 — Sandbox execution or interactive-access call or contract.
    • docs/reference/troubleshooting.mdx:2455 — Sandbox execution or interactive-access call or contract.
    • docs/security/best-practices.mdx:370 — Sandbox execution or interactive-access call or contract.
    • nemoclaw/src/blueprint/snapshot.ts:152 — Sandbox execution or interactive-access call or contract.
    • nemoclaw/src/blueprint/snapshot.ts:154 — Sandbox execution or interactive-access call or contract.
    • scripts/backup-workspace.sh:66 — Sandbox execution or interactive-access call or contract.
    • scripts/checks/run-managed-image-openshell-e2e.ts:1126 — Sandbox execution or interactive-access call or contract.
    • scripts/lib/sandbox-rlimits.sh:6 — Sandbox execution or interactive-access call or contract.
    • scripts/lib/sandbox-rlimits.sh:82 — Sandbox execution or interactive-access call or contract.
    • scripts/nemoclaw-start.sh:212 — Sandbox execution or interactive-access call or contract.
    • scripts/nemoclaw-start.sh:230 — Sandbox execution or interactive-access call or contract.
    • scripts/nemoclaw-start.sh:3563 — Sandbox execution or interactive-access call or contract.
    • scripts/nemoclaw-start.sh:4245 — Sandbox execution or interactive-access call or contract.
    • scripts/walkthrough.sh:71 — Sandbox execution or interactive-access call or contract.
    • scripts/walkthrough.sh:74 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/agent/passthrough-dispatch.ts:13 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/agent/passthrough-dispatch.ts:20 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/agent/passthrough-dispatch.ts:372 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/connect-autopair-budget.ts:32 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/download.ts:29 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:102 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:125 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:135 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:136 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:17 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:20 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:61 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.multiline-argv.test.ts:82 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:107 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:123 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:125 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:138 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:139 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:143 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:146 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:166 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:167 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/exec.test.ts:176 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/process-recovery.ts:1070 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/sandbox-exec-output.ts:50 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/sessions/export.ts:180 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/sessions/export.ts:371 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/sessions/export.ts:504 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/sessions/export.ts:640 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/snapshot.test.ts:38 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/snapshot.test.ts:668 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/wipe-state.ts:51 — Sandbox execution or interactive-access call or contract.
    • src/lib/actions/sandbox/wipe-state.ts:52 — Sandbox execution or interactive-access call or contract.
    • src/lib/adapters/openshell/client.test.ts:291 — Sandbox execution or interactive-access call or contract.
    • src/lib/adapters/openshell/restore-gateway-pairing.ts:96 — Sandbox execution or interactive-access call or contract.
    • src/lib/adapters/openshell/restore-gateway-pairing.ts:98 — Sandbox execution or interactive-access call or contract.
    • src/lib/adapters/sandbox/command-transport.test.ts:200 — Sandbox execution or interactive-access call or contract.
    • src/lib/adapters/sandbox/command-transport.test.ts:281 — Sandbox execution or interactive-access call or contract.
    • src/lib/agent/binary-availability.ts:45 — Sandbox execution or interactive-access call or contract.
    • src/lib/agent/binary-availability.ts:46 — Sandbox execution or interactive-access call or contract.
    • src/lib/agent/onboard.ts:225 — Sandbox execution or interactive-access call or contract.
    • src/lib/agent/onboard.ts:226 — Sandbox execution or interactive-access call or contract.
    • src/lib/agent/onboard.ts:387 — Sandbox execution or interactive-access call or contract.
    • src/lib/agent/onboard.ts:472 — Sandbox execution or interactive-access call or contract.
    • src/lib/diagnostics/debug.ts:383 — Sandbox execution or interactive-access call or contract.
    • src/lib/diagnostics/debug.ts:398 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/compatible-endpoint-smoke.ts:213 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/compatible-endpoint-smoke.ts:214 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/dcode-selection-drift.ts:130 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/docker-gpu-supervisor-reconnect.ts:163 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/docker-gpu-supervisor-reconnect.ts:235 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/sandbox-create-launch.test.ts:527 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/sandbox-gpu-create-run-attempt.ts:301 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/sandbox-gpu-create-run-attempt.ts:538 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/sandbox-readiness-tracing.ts:457 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/web-search-verify.ts:245 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/web-search-verify.ts:246 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/web-search-verify.ts:274 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/web-search-verify.ts:275 — Sandbox execution or interactive-access call or contract.
    • src/lib/onboard/web-search-verify.ts:277 — Sandbox execution or interactive-access call or contract.
    • src/lib/share-command-deps.ts:55 — Sandbox execution or interactive-access call or contract.
    • src/lib/share-command-deps.ts:56 — Sandbox execution or interactive-access call or contract.
    • src/lib/shields/index.ts:1068 — Sandbox execution or interactive-access call or contract.
    • src/lib/shields/inference-convergence.test.ts:46 — Sandbox execution or interactive-access call or contract.
    • src/lib/state/sandbox.ts:1498 — Sandbox execution or interactive-access call or contract.
    • src/lib/tunnel/services.ts:686 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:104 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:113 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:119 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:125 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:134 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:140 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:35 — Sandbox execution or interactive-access call or contract.
    • test/agents/deepagents/langchain-deepagents-code-headless-runtime.test.ts:98 — Sandbox execution or interactive-access call or contract.
    • test/e2e-runtime/repro-7795-connect-shell-sandbox-label.test.ts:115 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/02-inference-local-http.sh:20 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/03-deepagents-code-nemotron-ultra-profile.sh:35 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/04-deepagents-code-fresh-reonboard.sh:267 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/04-deepagents-code-fresh-reonboard.sh:35 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/04-deepagents-code-fresh-reonboard.sh:395 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/04-deepagents-code-fresh-reonboard.sh:56 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/04-landlock-readonly.sh:44 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/05-deepagents-code-landlock-readonly.sh:28 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/06-deepagents-code-python-egress.sh:35 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/06-deepagents-code-python-egress.sh:39 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/07-deepagents-code-headless-inference.sh:47 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/07-deepagents-code-headless-inference.sh:54 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/07-deepagents-code-headless-inference.sh:62 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/07-deepagents-code-headless-inference.sh:70 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/07-deepagents-code-headless-inference.sh:75 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/08-deepagents-code-secret-boundary.sh:34 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/09-deepagents-code-tavily-opt-in.sh:28 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/09-deepagents-code-tavily-opt-in.sh:32 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/09-deepagents-code-tavily-opt-in.sh:38 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/10-deepagents-code-tui-startup.sh:225 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/10-deepagents-code-tui-startup.sh:50 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/11-deepagents-code-observability.sh:117 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/11-deepagents-code-observability.sh:259 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/11-deepagents-code-observability.sh:281 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/11-deepagents-code-observability.sh:291 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/11-deepagents-code-observability.sh:62 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/12-deepagents-code-thread-auto-approval.sh:201 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/checks/12-deepagents-code-thread-auto-approval.sh:80 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/features/skill/add-sandbox-skill.sh:97 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/features/skill/lib/validate_sandbox_openclaw_skills.sh:27 — Sandbox execution or interactive-access call or contract.
    • test/e2e/e2e-cloud-experimental/features/skill/verify-sandbox-skill-via-agent.sh:65 — Sandbox execution or interactive-access call or contract.
    • test/e2e/fixtures/clients/sandbox.ts:111 — Sandbox execution or interactive-access call or contract.
    • test/e2e/fixtures/clients/sandbox.ts:120 — Sandbox execution or interactive-access call or contract.
    • test/e2e/fixtures/clients/sandbox.ts:132 — Sandbox execution or interactive-access call or contract.
    • test/e2e/lib/security-posture-assertions.sh:12 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/issue-4434-tui-unreachable-inference.test.ts:123 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/issue-6194-tui-expect.ts:200 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/issue-6194-tui-expect.ts:91 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/openclaw-agent-assertion.ts:67 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/openclaw-inference-switch.test.ts:821 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/openshell-gateway-upgrade.test.ts:250 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/openshell-gateway-upgrade.test.ts:633 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/telegram-injection.test.ts:124 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/telegram-injection.test.ts:32 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/telegram-injection.test.ts:41 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/telegram-injection.test.ts:64 — Sandbox execution or interactive-access call or contract.
    • test/e2e/live/telegram-injection.test.ts:80 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:499 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:501 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:506 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:507 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:605 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:610 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:623 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:636 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:637 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:647 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:660 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/e2e-clients.test.ts:684 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/issue-6194-tui-post-idle-contract.test.ts:181 — Sandbox execution or interactive-access call or contract.
    • test/e2e/support/issue-6194-tui-post-idle-contract.test.ts:63 — Sandbox execution or interactive-access call or contract.
    • test/installer-integration/install-preflight.test.ts:1411 — Sandbox execution or interactive-access call or contract.
    • test/installer-integration/install-preflight.test.ts:1490 — Sandbox execution or interactive-access call or contract.
    • test/installer-integration/install-preflight.test.ts:925 — Sandbox execution or interactive-access call or contract.
    • test/onboarding/onboard-inference-reconciliation.test.ts:441 — Sandbox execution or interactive-access call or contract.
    • test/package-contract/cli/debug-cli-command.test.ts:75 — Sandbox execution or interactive-access call or contract.
    • test/process-recovery/process-recovery-custom-agent.test.ts:120 — Sandbox execution or interactive-access call or contract.
    • test/process-recovery/process-recovery-custom-agent.test.ts:126 — Sandbox execution or interactive-access call or contract.
    • test/process-recovery/process-recovery-custom-agent.test.ts:193 — Sandbox execution or interactive-access call or contract.
    • tools/openshell-agent/runtime.mts:322 — Sandbox execution or interactive-access call or contract.
    • tools/openshell-agent/runtime.mts:324 — Sandbox execution or interactive-access call or contract.
  5. rsliter commented on Sep 3, 2026

    @rsliter
    ContributorAuthor

    Issue #9804: Phase 1 slice 4: Route exec, interactive sessions, and SSH through the OpenShell adapter

    Requested outcome, confirmed scope, and current owner

    • Requested outcome: Route buffered exec, streamed commands, interactive sessions, and SSH behavior through typed OpenShell interfaces while preserving current behavior.
    • Confirmed scope authority: Accepted Phase 1 architecture issue Isolate the OpenShell integration and migrate eligible CLI operations to the SDK or gRPC #9802.
    • Current behavior owner: src/lib/actions/sandbox/exec.ts, src/lib/adapters/sandbox/command-transport.ts, connect and pass-through actions, agent setup, health probes, and src/lib/sandbox/version.ts.
    • Assigned implementation owner: @rsliter.

    Related work and delivery constraints

    Current state and decisions

    • Existing structure to extend: Transport-neutral OpenShell contracts under src/lib/adapters/openshell/, with CLI-specific implementations beside them.
    • Unresolved product decisions: None for Phase 1. SDK-backed command and SSH implementations remain deferred.
    • Operation and failure class: Remote sandbox command execution, streamed terminal execution, SSH configuration, SSH execution, and interactive session handoff. Failures include invalid input, unavailable executable, timeout, cancellation, transport failure, remote nonzero exit, and cleanup failure.
    • Sibling paths checked: Public exec, launch, agent and session pass-through, buffered command transport, onboarding verification, channel health probes, agent setup, version probes, file transfer, forwarding, and log fallback.
    • Sensitive-workflow states: Success preserves arguments, streams, and status. Remote nonzero returns the remote status without retry. Missing executables and timeouts return typed failures. Cancellation preserves the terminating signal. Transport ambiguity does not authorize a broader fallback. Cleanup runs after success, failure, or cancellation. Temporary SSH configuration is removed after use. Credentials remain in their current process or temporary-file boundary and are not returned in typed results.
    • Security boundaries: Validate sandbox and gateway identity before process creation. Keep CLI argv, subprocess environment, SSH configuration, temporary files, and terminal ownership inside CLI implementations. Do not widen credential, process, or terminal access.

    Observable acceptance examples

    • Allowed: A multiline command with a working directory, stdin choice, and TTY choice -> the CLI implementation preserves each argument and stream -> adapter argv and action tests.
    • Denied: An invalid sandbox or gateway name, endpoint override, NUL command argument, or multiline working directory -> fail before process creation -> validation and no-spawn tests.
    • Ambiguous: A failed directory probe or SSH-config read -> report an unobservable or transport failure, not a missing sandbox or successful command -> typed failure tests.
    • Failure or recovery: Timeout, cancellation, missing executable, transport failure, remote nonzero exit, and post-command cleanup failure -> distinct typed outcomes and unchanged exit behavior -> adapter, action, command-transport, connect, and version tests.

    Capability slices

    Slice 1: Route streamed command execution through a typed adapter

    • Outcome: Public exec and current execSandbox callers no longer construct OpenShell CLI commands or consume process-shaped results.
    • Acceptance evidence: Preserve argv bytes, gateway targeting, working directory, TTY, stdin, timeout flags, signals, remote exit status, and post-command cleanup.
    • Dependencies and decisions: Reuse the target type from Phase 1 slice 1: Route sandbox inventory and readiness through the OpenShell adapter #9803. Keep compatibility delegates for consumers assigned to later slices.
    • Test plan: CLI adapter tests, exec action tests with a typed fake, CLI build, CLI typecheck, affected tests, and repository architecture checks.
    • Deferred scope: Buffered output, remote environment, SSH, and interactive-session ownership.

    Slice 2: Route buffered execution and probes through typed results

    • Outcome: Captured command transport, onboarding verification, health probes, agent setup, binary checks, and compatible-endpoint smoke checks stop consuming CLI and process details.
    • Acceptance evidence: Preserve environment, input, stdout, stderr, timeout, remote status, and current fallback decisions.
    • Dependencies and decisions: Builds on Slice 1. Local Docker fallback remains fail-closed and does not gain new eligibility.
    • Test plan: Buffered adapter tests, consumer tests with typed fakes, affected Vitest projects, and architecture checks.
    • Deferred scope: SSH and interactive sessions.
    • Follow-on issue: Phase 1 slice 4b: Route buffered sandbox exec consumers through the OpenShell adapter #10991.

    Slice 3: Route SSH command transport and version probes through typed results

    • Outcome: Consumers stop parsing OpenShell SSH configuration and constructing SSH processes.
    • Acceptance evidence: Preserve named-gateway targeting, temporary-config access and cleanup, timeout, output, status, and version parsing.
    • Dependencies and decisions: Builds on Slice 1. Preserve the current host-verification policy.
    • Test plan: SSH adapter tests, command-transport and version tests with typed fakes, and runtime evidence only when local tests cannot prove behavior.
    • Deferred scope: Interactive sessions, SDK SSH, file transfer, and forwarding.
    • Follow-on issue: Phase 1 slice 4c: Route SSH command transport and version probes through the OpenShell adapter #10992.

    Slice 4: Route interactive connect and session handoff through typed results

    • Outcome: Connect, launch, and pass-through consumers stop owning OpenShell process and terminal details.
    • Acceptance evidence: Preserve TTY, stdin, stdout, stderr, concurrent-session detection, signals, cancellation, terminal restoration, and remote exit behavior.
    • Dependencies and decisions: Builds on Slice 1 and may reuse Slice 3. Do not redesign the terminal experience.
    • Test plan: Interactive adapter tests, action tests with typed fakes, existing terminal tests, and focused runtime evidence where mocks are insufficient.
    • Deferred scope: Terminal redesign, SDK sessions, file transfer, forwarding, and log fallback.
    • Follow-on issue: Phase 1 slice 4d: Route interactive connect and session handoff through the OpenShell adapter #10994.

    Delivery order

    GitHub writes

  6. rsliter commented on Sep 10, 2026

    @rsliter
    ContributorAuthor

    Remaining implementation plan

    The streamed execution PR #10995 and buffered execution PR #11089 have merged. The remaining work will use three lean PRs:

    1. Phase 1 slice 4c: Route SSH command transport and version probes through the OpenShell adapter #10992: SSH adapter and version probes. Introduce the typed asynchronous SSH boundary and migrate sandbox version probes and their direct callers. Preserve gateway targeting, host verification, temporary configuration access and cleanup, timeouts, output, and version-cache decisions.
    2. Phase 1 slice 4c: Route SSH command transport and version probes through the OpenShell adapter #10992: SSH command-transport consumers. Migrate command transport and its synchronous MCP registration, recovery, and rebuild call chains. Keep the first PR's deferred consumers assigned to @rsliter under Phase 1 slice 4c: Route SSH command transport and version probes through the OpenShell adapter #10992 until this PR lands. Preserve mutation ordering, lock lifetime, credential checks, and fallback eligibility.
    3. Phase 1 slice 4d: Route interactive connect and session handoff through the OpenShell adapter #10994: Interactive sessions. Migrate connect, launch, and pass-through consumers, preserve terminal and signal behavior, and retire compatibility helpers after their final consumers migrate.

    Both SSH PRs reference #10992; only the second closes it. #9804 remains open until all remaining acceptance evidence is satisfied. #9813 owns the final consumer audit.

    This split is approved by @rsliter. Surface any need to change fallback rules, host-verification policy, terminal behavior, credential authority, or MCP lifecycle semantics before extending scope. SDK work, file transfer, forwarding, log fallback, and terminal redesign remain deferred.

  7. rsliter commented on Sep 10, 2026

    @rsliter
    ContributorAuthor

    Remaining slice progress: #11358 is ready for review; #11459 remains draft while its async-consumer test repairs complete. The interactive-session slice (#10994) is implemented and passed PR validation at 8260ae0 against canonical main 9166f90. Rebecca approved a narrowly scoped validation-configuration exception: runtime fan-in 48 to 47 and connect fan-out 43 to 41 in ci/source-architecture-budget.json, with all other validation code/settings unchanged. Publication is queued behind the contributor open-PR limit (10/10).

    Scope remains unchanged. Converting existing Hermes OpenShell exec paths to SSH is excluded from #10992 and belongs in the separate consumer audit (#9813).

  8. rsliter commented on Sep 10, 2026

    @rsliter
    ContributorAuthor

    The interactive-session slice is now published as draft #11462, stacked on #11358. Its latest PR validation passed against canonical main, and all new commits are Verified. CodeRabbit review has been requested. The two lower architecture limits retain the previously recorded approval; no additional scope or validation exception was introduced.

  9. rsliter commented on Sep 10, 2026

    @rsliter
    ContributorAuthor

    All three remaining slices are now open for review: #11358 (typed SSH and version probes), #11459 (SSH command consumers), and #11462 (interactive sessions). The approved single rerun for #11459 passed on its unchanged commit, and both dependent PRs have passing CI and live E2E evidence. They remain stacked on #11358 and will be retargeted after it merges. No broader Hermes transport or SDK installation policy changes were added.

  10. rsliter commented on Sep 10, 2026

    @rsliter
    ContributorAuthor

    Closing as completed with Rebecca's approval. Streamed execution merged in #10995, buffered execution in #11089, and SSH and interactive sessions in #11358, which incorporated #11459 and #11462. Follow-on issues #10991, #10992, and #10994 are closed.

    The final production-consumer audit remains tracked separately in #9813.

    The managed-runtime activation failure in run 34532634016 remains unclassified; no causal link to this migration has been established. A separate 48-hour monitor is watching for recurrence in PR activation jobs and main E2E runs. This closure does not classify that failure as resolved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: cliCommand line interface, flags, terminal UX, or outputintegration: openclawOpenClaw integration behavior

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions