Skip to content

feat(browser): install and pair Chrome with Windows Companion - #1446

Draft
roboclaw-bot wants to merge 78 commits into
mainfrom
openclaw/automatic-chrome-extension-pairing
Draft

roboclaw-bot wants to merge 78 commits into
mainfrom
openclaw/automatic-chrome-extension-pairing

Conversation

@roboclaw-bot

@roboclaw-bot roboclaw-bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Related: openclaw/openclaw#152004. Coordinated with openclaw/openclaw#152057 (feat(browser): unify local Chrome setup across desktop and terminal).

Implemented for Peter Steinberger (@steipete), incorporating canonical Windows transport/setup work contributed by Jason (@fuller-stack-dev).

Work sessions

What Problem This Solves

Windows Companion should offer Chrome setup and local pairing without copied secrets or competing native-host registration owners.

User Impact

One packaged OpenClaw.BrowserBootstrap.exe and one Windows registration service replace the old helper and duplicate registry writers. A fresh Companion uses its existing managed-local WSL intent. Explicit standalone native-Windows CLI setup uses its bound Windows context. Conflicting bindings, browser opt-outs and saved extension pairing remain untouched. Chrome approval is still required.

Draft: current-head Windows and production integration proof remain merge gates. No release or real-user installation is included.

Why This Change Was Made

The private management ABI uses bounded JSON plus EOF while Chrome native-messaging v1 remains unchanged. Windows owns immutable private generations, SID/DACL/reparse/hash admission, transactional native/Store registry mutation and ownership checks. The canonical TypeScript consumer retains config, credential and relay policy. Companion retains active-Gateway, connection-intent, generation and managed-WSL provenance checks.

Installer and uninstaller call the same owner through bounded pipes and a kill-on-close job. Startup repair does not replay Store enrollment. Chrome EOF cancels either explicit backend. There is no PATH, localhost or availability-based topology fallback.

Evidence

September 28 recovery checkpoint (corrected-consumer proof; no merge)

Candidate 88958a8; Windows base 3331b5e. Consumer 6cff547216bd3229446d7cc32a7dae667182ef51 (#160161), pre-merge. #152057 remains merged. Wait-bound correction and preserved 58f receipts: this update. Idempotence correction and a14 terminal failures: recorded here. Original native production and WSL owners are unchanged. Exact parent/image/arguments, positive guest settlement, UNKNOWN/BUSY retention and 15s/2s remain intact.

Verified on preceding source 6bf6ffd: production WSL36367399650 passed all6 actual owner cases, including canonical real CLI pairing, early EOF, detached-descendant cleanup, caller cancellation, deadline15059.9941ms and an actual forced client kill. Exact lookup completed2962ms with one match; missing acknowledgment retained BUSY with zero command/lease/activation/mutation completion. Settled cases preserve owner ordering. Gateway unchanged, original CLI restored and fixture disposed. Receipt10948307871, JSON SHA256146a97f0da3ac4350d965738977ff6c5d9441e3fa1ff3f3592673d881f10893d. This is WSL/source-linked ownership proof, not native helper/registry acceptance or current-head proof.

Native36367399725 FAILED before producer build: pnpm/action-setup looked for package.json at the empty workspace root. The reviewed correction selects consumer/package.json using the documented input, preserving the pinned packageManager as sole version owner. A red/green regression covers this; no native acceptance was reached. CI36367400545 failed Setup/connect E2E during Phase1 SetupEngine initialization (17pass/23fail/6skip, restart-preparation/StateDatabaseCoordinatorContentionError categories); UI was still nonterminal before the new head. No consumer causality, CI success or waiver is inferred. Core/CLI, Tray/setup/integration, x64 publish/installer and MSIX lanes passed; ARM64 publish was skipped, not passed.

Local secretless checks: Node27/27, C# diagnostics27/27, installer preservation11/11. Canonical autoreview helper d5cbe626989195044e97545b3acb7c99b06a6103, Codex gpt-6-sol/high P0-P2: full candidate and subsequent test/setup/guard deltas scoped-clean, inherited auth/proxy/isolation unchanged. Full Windows build/setup-dev explicitly refuse Linux. Initial Linux Shared140fail/4008pass/33skip and Tray15fail/3143pass/2skip remain failed attempts; the merge-exposed installer assertion was fixed while requiring both preservation guards. Final Linux Tray14fail/3146pass/2skip remains platform-blocked, not Windows proof.

Historical native35478208205 and WSL35478208163 remain failed; their expired artifacts and recovered bounded session diagnostics are not passing acceptance. Standard CI35478210437 remains historical success, not blindly rerun. No merge: corrected-consumer native proof and CI/WSL admission remain required. Terminal evidence and external dependency. No release/signing/Store publication/real-user installation. CI attribution and diagnostic correction. Corrected-consumer proof. All earlier failures and limitations below are preserved.

Historical fixture repair and diagnostic checkpoint (not final acceptance)

Reviewed source bfcccf8, fixture commit 4278029. Production source is unchanged by this batch. Saved-profile proof now checks Gateway18789/path/profile=work separately from relay19444 and uses another private directory with the required node.exe basename for runtime drift. Static failure stages and numeric coordinates exclude raw errors, pairing values and child output; primary and cleanup failures remain distinct.

Forced-WSL-client lookup now exposes a fixed script-entry marker plus bounded process/drain/stage/count evidence without changing exact parent/command/image selection or any deadline. The stale combined workflow guard is reconciled into the ORIGINAL edd93f4 native-production baseline and a SEPARATE reviewed42780299 fixture baseline, with additional fixture dependencies protected. Both positive checks passed; known older production/fixture revisions were rejected. No guard was disabled.

Actual canonical autoreview (immutable helper e18ab3b62f7716d6ba20329602baa2c1da0d4601, Codex gpt-5.6-sol/high, P0-P2) passed scoped-clean for the corrected fixture bundle and then for the separate guard diff. Its initial P2 finding was accepted and fixed: re-observing an already-faulted drain must not invent a new cleanup failure. Two regression tests cover this. The older vendored-helper proxy refusal remains recorded; inherited proxy/auth environment was unchanged, with no configuration, credential or security-policy workaround.

Not frozen or ready to merge: the next hosted runs are diagnostic, not final coupled acceptance. Native consumer57201e3e and WSL consumer63f5d867 are unchanged diagnostic pins; the main owner must supply the final reviewed consumer freeze. Preserve three distinct failures: native35472473290 passed the original14 cases then failed saved-profile execution; WSL forced_client_exit timed out before selecting/killing the exact client; CI35472475313 failed the immediate process.HasExited assertion in BoundedProcessWaitTests. Their causes are not conflated or waived. No new native success, release, signing or LAND completion is claimed. Earlier checkpoints below are historical, not current-head acceptance.

Production WSL owner repair published; forced-loss proof assertion unresolved

Current head 97e7aa7 (reviewed implementationc8738ea5). The prerequisite canonical prototype35467770110 passed19/19; receipt10592605207 was independently validated. Real canonical CLI settled3924ms, deadline15036ms, unknown acknowledgments never authorized result/retirement; Gateway and cleanup checks passed. Consumer63f packageSHA2d923fbb888cafd352f5b31c07eff82c91bff8bf36a8270dfef1275ad9b54eb6.

The production command now uses that private gate/supervisor protocol, EOF revocation, strict bounded framing and positive guest acknowledgment before Windows/drain settlement and owner completion. Missing acknowledgments deliberately retain UNKNOWN/BUSY beyond the existing soft cleanup budget. No public ABI, registration/generation schema, ACL, topology/selector, provenance, credential or deadline change. The early-EOF-before-READY review finding was fixed and has unit/hosted regressions. A later sole runtime-selection allegation was rejected after checking the already-first managed-runtime PATH and executing an isolated bundled-runtime selection check; do not interpret that reviewer exit1 as a clean exit0. No accepted actionable finding remains.

Focused connection tests34/34 passed; embedded broker framing/capacity checks and E2E graph build passed (0warnings/errors). Full local Windows build remains unavailable; Shared194fail3823pass33skip and Tray18fail2965pass2skip remain failed local attempts. Actual production-owner proof35469857614 executes6 cases including early EOF, real CLI, successful detached descendant, cancellation, deadline and missing-ack BUSY retention; fresh CI35469859761 is separately watched. Terminal actual-owner run35469857614 FAILED: receipt10592523499 passed early EOF, real CLI (4812ms), normal detached cleanup, caller cancellation and deadline (15064ms), with owner/lease/activation preceding management completion and empty postchecks. forced_client_exit failed EqualException; the old failure receipt omitted its exact assertion stage. Do NOT claim all6 or completed forced-loss retention. Gateway unchanged, original CLI restored and owned fixture disposed. A test-only correction restores the previously successful parent-PID-bound exact-client lookup and adds bounded concurrent query drains plus redacted stage/count/outcome/ownership counters; BUSY/no-ack assertions stay unchanged. Production code remains unchanged. StandardCI35469859761 is terminal SUCCESS, including the formerly failing unchanged core stdout test, but that does not substitute for the failed dedicated proof or owed final consumer pairing. PriorCI35467773484 failed an unchanged SystemRunTests orphan-stdout assertion (empty versus hello) and Gate; exact logs retained without a waiver. Final consumer saved-profile pairing remains owed, with all14 accepted native cases retained. SOURCE NOT FROZEN until required proofs and final consumer validation are complete. No merge/release/signing.

Current reviewed prototype head edd93f4. Canonical-fixture source657ea9a0 and setup correction16756d46 passed independent review. Package/prototype35467447621 failed before build because pnpm/action-setup rejected duplicate version owners (explicit action version versus integrity-qualified consumer packageManager); its Windows prototype was skipped. The correction retains the immutable packageManager and frozen lockfile as the sole authority. Current prototype35467770110 has passed package-manager setup and is building the actual canonical package; terminal proof is pending. Fresh standardCI35467773484 has its own watch. No production integration, old trace/native14 rerun, merge or release. Prepared production protocol reader has14 local checks, but remains unshipped until prototype verification; saved-profile acceptance code is prepared separately for the eventual final consumer pin.

Private WSL owner prototype checkpoint (18/19; canonical CLI fixture correction)

Published head 3ab6899, reviewed sourcee849d4510ba080857215b70b8316e67cf5a3e227. Prototype run35451710265 attempted the actual fixed-stdin broker and request-owned user-systemd primitive in the existing disposable hosted fixture BEFORE production wiring. No production source, native14 inputs, old trace inputs or public contracts changed. Standard CI is not this checkpoint's completion.

Terminal attempt: receipt10586807604 reports no READY in any case, 18errors, unchanged Gateway and successful owned-fixture disposal. The single reported collision pass is NOT counted as lifecycle proof because the original test did not require a broker-entry witness. No protocol/systemd checkpoint has passed. The driver omitted production-equivalent stdin newline normalization; a harmless CRLF shell reproduction returns exit2 while LF returns0. A scoped correction normalizes actual stdin, adds a portable transport regression (1/1executed/passed), and requires a bounded broker-start marker for every positive/negative case, plus exact collision InvocationID preservation. The scoped transport correction passed independent review and is published as2778c1d5 plus Gateway metadata. Current head 8c9dc44 executes corrected prototype35452501667. Its terminal receipt10587690990 passed18/19 cases: handoff, environment, capacity, normal detached-child cleanup, cancellation/deadline, forced-loss unknown retention and observed epoch refusal. Only real_cli failed: positive guest settlement, no successful CLI result. Gateway identity and owned-fixture disposal were preserved. Production remains untouched.

Recovered follow-up: the fixture installed the public release rather than the reviewed canonical consumer. The inspected official openclaw2026.9.5 package has no --local-gateway CLI option. The scoped correction builds immutable63f5d867fb67242ea6322f866b0e4f732d4e801c through its self-contained source-pack helper and uses the EXISTING fixture candidate-package/version interface BEFORE Gateway startup, verifying source/version/SHA and CLI capability. This is a prototype pin, NOT the final coupled-consumer pin. No shim, token substitution, live upgrade, config replacement or shutdown shortcut. StandardCI35452503191/UIjob105922181478 has a hosted-runner lost-communication annotation; no failed UI assertion/completed log was recovered. It remains failed, with no product-cause claim or gate waiver. Fresh exact-head CI follows publication, not a blind rerun.

Nineteen cases cover open-stdin bash handoff, clean service environment, READY/PERMIT binding, real canonical CLI output, full16384UTF16 capacity, normal successful detached-descendant cleanup, EOF/cancel/15sdeadline, forced client loss beforeREADY/partial/fullPERMIT/RESULT/SETTLED, delayed start job, collision and observed unit-epoch drift refusal, duplicate/oversized/out-of-order controls. Missing acknowledgments are explicitly UNKNOWN/BUSY with no retirement permission; the prototype does not claim a proved early-submission fence or actual production retirement.

Independent review found and fixed a real normal-result deadlock: stop the positively bound unit after capturing RESULT, then wait for cgroup/runner settlement, including successful detached children. Review also raised Show/StopUnit atomicity against same-UID replacement. The scope decision is explicit: request names are fresh, single-writer and never restarted/reused by the protocol; the existing trusted UID controls the CLI/config/user-manager. Observed drift is refused, but NO atomic conditional-stop protection against an uncooperative trusted-UID actor is claimed. The receipt carries atomicManagerReplacementFenceProven=false. Final scoped Codex review exited clean after this clarification and a strict BOM-control regression fix.

Local framing/capacity tests5/5 passed; E2E graph compilation0warnings/errors; workflow YAML and PowerShell parsing passed. Required Linux full build remains Windows-blocked; Shared194fail3823pass33skip and Tray18fail2965pass2skip remain failed local attempts. Only redacted prototype receipts will be retained. Existing causal post-command RED/unknown activation evidence below remains unchanged; no repeat trace-only/native14/full-matrix manual run. Final coupled consumer pin is still awaited before that separate proof. No production wrapper wiring, merge, release or signing yet.

Instrumentation-improved WSL trace: terminal evidence and bounded conclusions

Fresh trace35433978782 completed all six cases and owned cleanup on fe82006. The harness step passed; the settlement-evaluation step correctly FAILED for one causal post-command survivor and one unknown boundary ordering. Improved receipt10581142668 was downloaded and independently checked. The measurement loop ends here; no repeat or production fix was started.

The forced-wsl.exe-loss case proves a BRIEF POST-WslCommand-COMPLETION survival interval, not a persistent orphan and not a proven post-management survivor. On one Windows Stopwatch clock (10,000,000ticks/sec): command completion hook793.5088ms; challenge sent793.6278ms; response received794.5915ms reported matched owner2929/start26511(stateR),worker2932/start26519(stateS),leaf2933/start26522(stateS),group2929 still running. Thus a causal observation occurred after command completion, independent of exit-notification transport latency. No test cleanup preceded that challenge.

Source-linked activation release795.8504ms and management return795.8912ms came later. Challenge2 sent796.1031ms and received796.8882ms reported all three absent. Their exit notifications arrived796.4855-796.9067ms. Those later notifications do NOT prove either survival or precedence at activation/management release: that ordering remains UNKNOWN. The earlier7bd trace remains correctly classified as no observed survivor/unknown ordering, not retroactively recast as red orphan proof.

Case Last guest-exit notification received(ms) WslCommand completion hook(ms) Activation release begin(ms) Management return(ms) Conclusion
normal 3440.3154 3455.2058 3465.1396 3468.5536 Observed exit-notification precedence
IPC EOF 868.5061 874.9065 861.0376 861.1016 UNKNOWN at activation/management
client cancellation 838.4794 839.6711 839.9906 840.0253 Observed precedence
deadline 15026.1139 15027.5435 15028.5282 15028.5599 Observed precedence
forced client exit 796.9067 793.5088 795.8504 795.8912 Causal survivor after command; UNKNOWN at activation/management
pipe retirement 813.4588 813.5338 830.5700 830.6247 Observed precedence

IPC EOF is a raw local pipe-disconnection fixture, not confirmed server EOF. Its source-linked native inventory/mutex operation returns on that local error; no shipping-helper/Chrome-frame/registry conclusion is inferred. All other native ownership timestamps are also explicitly source-linked unchanged owners with synthetic platform facts, not live registered-helper proof. The actual WSL command, pipe client/server, selected distro/user/provenance and immutable source pins were retained.

Observer READY preceded every trigger; every pidfd exit and challenge identity matches its armed PID/start pair; every observer group differs from its request group. All12challenges are causally after their named boundaries. No post-management running response occurred in this run. CLI restoration and removal of exact owned distroOpenClawE2E-23d19299 succeeded; fixture GatewayMainPID2383 was checked unchanged before teardown. Receipt errors=[]; no raw logs/config/env/credentials were uploaded. Custompool/Chrome/upgrade/wholeCompanion/realcredential proof remains open.

Receipt file SHA256ff33c5841a86372a8b0aba43adecfbcf55e1cd1fc4a2ff0f62f3cd95473148bf; archive digestsha256:2acfc70d57b7cf311a9472b712d6207c5433e2cc6f2ce907c1c08be9ff9670aa. Concrete fallback design below is delivered for parent review only (SHA256c95097f33a2ab0f18b057fd5d3dd41636c2b1bbccca2df89901145fca03f39f4); it explicitly specifies READY/PERMIT/SETTLED framing, user-systemd ownership, loss-point recovery and the before-READY/missing-ack availability limit. No production wrapper, API switch, new channel, persistence, public contract, selector, permission or deadline change is implemented.

Current head fe82006 contains reviewed proof-only source db2fa48 plus Gateway publication metadata. Fresh trace35433978782 is the one authorized materially improved measurement, not a rerun of35432479861. Production783/d779 source and accepted native14/consumer57 pins remain unchanged.

An independent persistent guest observer binds pidfds/start identities while all three owned fixture processes are alive, outside their process groups, and reports READY before any trigger. A dedicated Windows reader stamps bounded exit notifications before parsing on the same Stopwatch clock as synchronous completion hooks. Two challenges sent after owner/retirement boundaries can prove a causal survivor; later notifications remain UNKNOWN, not evidence of an orphan. No owner callback waits for observation. Unchanged source-linked NativeRegistrationRuntime/RegistrationService execute through existing platform interfaces with synthetic inventory and a real Windows mutex. Runtime lease release, activation release and serialized management completion are separately recorded. This is explicitly not shipping-helper, actual registry/ACL or Chrome-frame proof.

All six cases and identity-scoped cleanup are retained. Scoped Codex review is clean; E2E graph compilation has zero errors/warnings and the local persistent-observer protocol test passed. Required Linux full build remains Windows-blocked; Shared194fail and Tray18fail remain failed local attempts, not proof. No manual old/native/full-matrix rerun, merge, signing or release.

Concrete fallback owner design for parent review only (not implemented)

Candidate private WSL owner protocol (design only, not production code)

Scope and non-goals

This is a candidate for BrowserBootstrapWslCommand after measurement, not an assertion that an orphan was observed. Keep Chrome native v1, management v1, generation metadata, selected distro, default openclaw user, default HOME/state/config, installed CLI allowlist, Gateway MainPID/provenance and browser/connection intent checks unchanged. Retain the existing 15-second request deadline, 2-second cleanup budget and fail-closed ownership retention after an unsettled cleanup budget. No Gateway/distro shutdown, new public selector, permissions, persistent JSON/PID store, new generation files or side listener.

The proposal would require an inline guest broker/gate and private framing changes inside the current wsl.exe invocation. Those changes are NOT implemented or authorized by this document. No WslLaunch migration is proposed.

Transport and exact framing

Keep argv: system wsl.exe --distribution D --exec /bin/bash --noprofile --norc -s. D remains the admitted pinned distro. The fixed bootstrap script performs the existing authority checks, selects the installed CLI and ends in an exec of a fixed inline guest broker using the already-installed managed runtime. It is not written to a guest file. Remove WSLENV as today. Explicitly pass only the already-pinned runtime environment into systemd's otherwise clean service environment; do not inherit manager profile/Node overrides.

Windows writes the complete fixed script and flushes but does NOT close stdin. It sends no further bytes until broker READY, so bash cannot read ahead and consume control frames before exec. This precise stdin handoff must be proven on WSL before implementation acceptance. Request ID R is random 128-bit lowercase hex, generated once in Windows memory, never a credential, never reused or derived from the Chrome nonce.

After script handoff, private frames are 4-byte unsigned little-endian length followed by strict UTF-8 JSON, duplicate/unknown keys rejected, no BOM/trailing data. Control frames max2048 bytes. Combined stdout (all frames/headers) remains within the existing16384-byte budget, stderr remains bounded and discarded. Reserve4096 bytes for READY/SETTLED overhead; RESULT has only the remaining budget and fails closed on overflow (no truncation, no buffer growth). Legitimate pairing values already have much smaller validated limits, but this internal framing budget change needs compatibility review. Nothing on this wire is logged.

Windows to broker:

  • PERMIT: {"v":1,"type":"permit","requestId":R,"invocationId":I,"challenge":C}
  • CANCEL: {"v":1,"type":"cancel","requestId":R,"invocationId":I}
    EOF is also cancellation, never submit-complete or successful settlement.

Broker to Windows:

  • READY: {"v":1,"type":"ready","requestId":R,"unit":U,"invocationId":I,"bootId":B,"challenge":C,"gatePid":P,"gateStartTicks":S}
  • RESULT: {"v":1,"type":"result","requestId":R,"invocationId":I,"payload":}
  • SETTLED: {"v":1,"type":"settled","requestId":R,"invocationId":I,"outcome":"completed|cancelled|failed","startSealed":true,"gateExited":true,"cgroupEmpty":true,"startJobSettled":true,"cliExitCode":integer-or-null}
    READY identifiers must match the exact created unit and trusted manager observation. C is a random per-gate challenge. Only one READY, PERMIT, RESULT and SETTLED is accepted, in order; failed/cancelled cases omit RESULT. A result alone is never delivery permission. Unknown schema or lost/partial acknowledgment becomes UNKNOWN, never settled.

Guest ownership and child creation

The broker creates exactly one transient user service U=openclaw-browser-bootstrap-R.service, using fail-on-existing semantics, not replacement or adoption. The service initially runs only an inert permission gate. No CLI/worker may start before a complete matching PERMIT. READY is sent only after creation/start job succeeded, the gate is running, and the broker verifies the exact unit invocation ID, user, gate PID/start identity and control-group ownership. Retain the one creation job handle in memory until its outcome is known.

Candidate properties: Type=exec, ExitType=cgroup, KillMode=control-group, Restart=no, no timers/sockets/activation triggers or restart path. The gate is already inside the unit BEFORE it forks the CLI, so the CLI and descendants inherit that cgroup, including ordinary detached process groups. Closing an empty pre-created scope after spawning outside it would be wrong. Keep existing user/systemd privileges; this is not containment against malicious same-user cgroup migration.

Use inherited anonymous stdin/stdout/stderr (systemd-run --user --quiet --pipe or the corresponding StartTransientUnit fd properties), not journald, guest files or a network channel. Capture CLI stdout in a bounded gate-to-broker pipe; the CLI gets /dev/null stdin, not the permission stream. No raw CLI bytes can impersonate broker control frames.

The concrete service retention candidate is RemainAfterExit=yes until the broker has captured gate exit, CLI result and an empty cgroup; then stop only U and wait for that stop job. Do NOT combine this with waiting for deactivation before issuing StopUnit, which would deadlock. In particular, do not assume systemd-run --wait itself can replace manager state/cgroup checks while RemainAfterExit is set. An implementation may use manager reference retention instead if that primitive is verified, but it must preserve the same explicit state machine; it cannot silently add persistent receipts.

Normal finish and cancellation

Gate state is single-use WAIT_PERMIT -> RUNNING -> SEALED. EOF, malformed input, CANCEL or child completion enters SEALED irreversibly. Only WAIT_PERMIT may consume a matching PERMIT and make exactly one synchronous child-creation decision. Gate sealing and child creation must be serialized; no queued callback may fork after SEALED. If cancellation races a committed permit, a child may already exist, but the native activation stays held until that exact unit is stopped and empty.

Normal: CLI exits, gate drains its bounded streams and returns its outcome, gate exits, and broker observes the exact unit/cgroup with no remaining processes. Broker seals its own start path, resolves the original creation job, stops the retained inactive-work unit, waits for stop completion and only then emits SETTLED. Windows may return parsed CLI output only after valid RESULT + completed SETTLED + Windows process/stdout/stderr settlement and the unchanged post-generation authority revalidation.

EOF/deadline: Windows atomically transitions its request to CANCELLING, never sends a new PERMIT, sends CANCEL if the stream is usable, then closes input. The broker/gate stops only U; the manager applies control-group termination and the broker waits for empty cgroup/gate exit. The existing cleanup budget is an error/reporting bound, NOT permission to release an unjoined activation. No larger timeout is introduced. A bounded stop grace, if configured, must fit the existing cleanup policy rather than silently extending it.

Forced Windows-client loss and recovery table

Loss point Safe behavior and remaining evidence
Before READY Windows has issued no PERMIT, so no CLI can be started by a conforming gate. But a pending WSL launch or transient-unit creation can still create an inert broker/gate later. Windows join or a negative GetUnit is NOT enough to retire. Enter UNKNOWN and retain activation until the actual submission/creation job and guest work are positively settled.
READY received, before PERMIT Exact unit/invocation binding is known in RAM. Recover through the same pinned WSL command transport with a fixed cancel-and-inspect script for that tuple; never send PERMIT in recovery. Stop and wait only the matched unit.
Partial PERMIT Length framing prevents gate start before the whole frame validates. Still stop/inspect the known unit because delivery outcome is uncertain; never retry PERMIT.
Complete PERMIT may have arrived Assume CLI could have started. Recover only the known unit, seal/stop it, resolve its jobs, verify gate exit and empty cgroup; no successful return on wsl.exe exit alone.
After RESULT, before SETTLED Discard the result until positive settlement; same recovery rule.
SETTLED received, client then lost The authenticated in-memory tuple and terminal proof are already known. Join Windows process/drains and perform unchanged final authority checks. Never regenerate credentials as recovery.

Recovery is another fixed operation over the SAME existing selected-distro WSL transport, not a listener, endpoint or public management operation. If the parent considers even this private recovery invocation an unacceptable channel expansion, that is a review blocker; it is not silently implemented. Bind unit name + invocation ID + manager/boot epoch + user + fixed gate identity before stop. A collision, changed invocation, manager epoch change, unknown properties or permission denial refuses recovery; do not terminate a foreign unit.

Availability limit, not hidden success: before READY, or after a lost acknowledgment when the known unit has already disappeared, an absent unit does not disprove a delayed submission. Without a persistent terminal receipt or an independently proven submission fence, this design cannot guarantee automatic bounded recovery. The state remains UNKNOWN/BUSY and retirement does not complete. A new timeout, negative lookup, wsl.exe HANDLE signal, distro shutdown or invented acknowledgment cannot resolve it. This explicit fail-closed limit needs parent acceptance or a separately reviewed stronger submission-fencing design. No persistent tombstone/store is smuggled into this proposal.

No late-start proof obligation

Retirement predicate T requires: start decision SEALED; creation job resolved; exact invocation's gate exited; owned cgroup empty; no restart/activation path; terminal tuple acknowledged; Windows/drains joined. The only CLI spawn site is in that already-owned gate and requires one complete matching PERMIT. At T, that gate is gone, no queued creation/restart job exists, and the broker cannot submit again. Therefore no request-owned CLI/descendant can appear after T under the trusted-CLI model. Unknown before-READY submissions fail T, so they cannot be mislabeled retired. This is an invariant to prove with barriers/forced-loss tests, not a property established by the current component trace.

Required acceptance cases include loss before READY, partial/full permit races, delayed manager start job, child forks during cancellation, child setsid(), gate/broker failures, lost RESULT/SETTLED, repeated recovery, unit-name collision and changed manager epoch. Measure guest exit and native activation/management boundaries independently. No positive result until these races and cleanup are proven on the existing disposable hosted fixture.

WslLaunch assessment and primary contracts

Microsoft WslLaunch documents an associated process HANDLE, stdio handles and caller CloseHandle responsibility. It does not document termination propagation or descendant settlement order. It is only a candidate transport API, not a cancellation proof and not a reason to switch APIs here.

Primary sources consulted (September19,2026):

No gateway credential, raw environment, user configuration, persistent PID record or new native generation metadata is part of this protocol or its proof receipts.

WSL guest component trace: terminal, settlement ordering remains unproven

Trace35432479861 completed all six cases and cleanup on head7bd45d9872b06d99f3aaff4ba01569baa4f8f85d. Receipt10582090139 is independently checked against run/head/productionPin783, all18guestPID/start identities and default-user/provenance booleans. No guest survivor was observed. This is NOT a guest-settlement-before-retirement pass. Every first independent absence observation completed after owner completion; the sample windows cannot establish ordering.

Times below are milliseconds from each case start, before test cleanup:

Case Command returned Client completed First all-absent observation window
normal 5495 5500 5490-5608
IPC EOF 743 731 (local disconnect, not server acknowledgment) 724-852
client cancellation 757 758 745-869
deadline 15012 15013 15052-15167
forced Windows-client exit 701 704 698-815
pipe retirement 753 (Dispose also753) 810 731-861

For retirement, request-owned guest PID/start-ticks were3233/30377,3240/30386,3241/30390 (group3233); all were absent in the postcheck861-992ms. Forced-client case identities3202/30251,3205/30259,3206/30263 were absent at815-929ms. These are observation bounds, not an exit acknowledgment. Receipt status explicitly remains trace_complete_not_a_settlement_pass. Original CLI restored, unchanged fixture gateway MainPID2389 checked before teardown, exact owned distroOpenClawE2E-f84bde62 removed. No unrelated gateway/distro was stopped. Only redacted receipt uploaded; no raw logs/config/env/credential output.

Receipt file SHA25681da21764206fba7abb5cf3edf89a32cf6020c89b817a63acfdb1fcf5e7761b3; artifact archive digestsha256:8452d2c6499a76826d901a0a8bb4e7d33b5b247aceffa15afa971a917516626b. Actual Windows wsl.exe imageSHA2568797ff87fb1ae27f6bbbff141434a404ec2f9f11021444fa0547fc48151d6702. Production src/native proof diff against783 remains empty.

Parent-review proposal only: retain the existing private invocation as the owner of submission, liveness and terminal acknowledgment; supervise a request-owned guest child scope using the already-required user systemd where appropriate; cancellation/EOF terminates and waits only that scope, with acknowledgment after guest-tree exit. Windows owner/pipe cannot report settlement before that acknowledgment plus process/drain settlement. Unknown completion stays busy/fail-closed. Exact private framing, forced-client-exit behavior and scope termination must be reviewed and proven before implementing any wrapper/channel/persistence/deadline change. No production fix has been made. Custom Windows11 proof pool, real credential/wholeCompanion behavior, Chrome consent/upgrade and final consumer lineage remain open.

This follow-up adds only a dedicated hosted workflow, an opt-in E2E test and controlled guest CLI/identity observer. Production src, existing native workflow and consumer57 pin are frozen at783f178c. No production cancellation fix, ABI/selector/permissions/deadline change, merge, signing or release is included.

Existing setup proof was checked from actual terminal TRX, not its job name: run35429580488 executed37/passed37; six separate MXC cases were NotExecuted. Named WSL configuration, service-owned gateway, default-user CLI and keepalive cases passed with nonzero durations. The new job reuses E2ESetupFixture unique distro/free ports, replaces only a fixture-owned CLI entrypoint with an explicitly synthetic barrier, invokes unchanged BrowserBootstrapWslCommand and PipeServer/PipeClient, and independently observes PID/start identity/descendants for normal, IPC EOF, client cancellation, deadline, forced Windows-client exit and pipe retirement. This is NOT real credential/whole-Companion/custom-Windows11-pool proof.

Only an allowlisted numeric/boolean terminal receipt is uploaded. Raw test output, fixture logs/config/env and credentials stay private. CLI restoration and owned-distro teardown are required; red/unknown observations are retained before test cleanup. Zombies, absent PIDs and running processes remain distinct; no pre-completion settlement claim is inferred from Windows join alone.

Local E2E graph compile passed with zero warnings/errors. Guest observer unit checks passed (PID reuse refusal/pidfd cleanup/case isolation). Required Linux full build/setup check remain Windows-blocked; Shared194fail and Tray18fail remain failed local attempts. Scoped review corrected the zombie/absence label. Final independent Codex review exited clean on the exact three-file follow-up f7659f7. The hosted component trace is now terminal as detailed above; pre-completion settlement ordering remains unproven. Existing native14/14 and Windows CI receipts remain accepted historical evidence, not rerun results for this trace.

Actual proof-only published head 57fd3b0, reviewed source f7659f7. Attempt35432386447 failed workflow validation before any job/fixture ran: runner.temp was not allowed in job-level env (line22). No trace artifact exists and this is not a WSL capability denial. The two-line workflow-only correction passed its own scoped Codex review and was published normally as c6fc223 plus Gateway metadata. Current head7bd45d9872b06d99f3aaff4ba01569baa4f8f85d runs trace35432479861. Production/test implementation and accepted native pins are unchanged; trace execution completed; not claimed as a pre-retirement guest-settlement pass. No native proof or full matrix was manually rerun.

Accepted native proof head: 783f178. Reviewed production source d7795a2 is unchanged. Reviewed fixture-only correction e3db53c adds full producer history for GitVersion and closes the settled synthetic IPC fixture before final delivery. The publisher added only metadata. This PR remains DRAFT and is not task-merge-ready. Consumer remains exact 57f78c49d47f445b85d4859f038e8447e08983ba for this proof.

Verified composed success: run35429579145, redacted receipt10580531991, NEW producer10580132336. Actual head783f178ca5579d057d4799fceb5cec5e8c4d69f8 and exact consumer57f78c49 were checked against run/artifact/receipt identities. Executable SHA256 1f4ea285a26fecc0d084c53bd764f177c819f2c3d2338641b410d8cfc3b5f6b8 matches both the uploaded source manifest and independently hashed downloaded executable. Old6dd was not reused.

All 14 cases passed, including the ten prior checks. The receipt reports syntheticPairing=false, six accepted role chains, actual pairing/nonce/version validation, unchanged prepublication state, typed manifest_invalid refusal after uninstall/replacement with no pairing or old-state change, missing/preserved registration postconditions, unchanged replacement state, in-flight inspection/retirement busy, response before completed retirement, real in-flight EOF kill/join without pairing/state effect, parser-variant refusal and owned_registration_removed cleanup. This is real new-producer/current-pinned-consumer red-to-green evidence, not a unit-only substitution.

Current Windows CI35429580488 is terminal SUCCESS on attempt2, including CI Gate, on the same published783f178c. Attempt1 had a stalled Tray UI startup: no case output for26minutes versus16seconds on preceding identical-production run. Its cancellation and job105861715837 logs are retained, not called success. Exactly one targeted UI retry105865442082 plus dependent gate was requested; successful job timestamps were retained, not rerun. No code/assertion/deadline change for that retry.

Verified native counts: Shared4049pass/1skip; Connection809pass/1skip; BrowserBootstrap171pass/0skip including actual probe descendants; WinNodeCLI127pass/0skip; Tray2985pass/0skip; Tray integration22pass/0skip; SetupEngine1192pass/1skip. UI retry: Functional19pass, TrayUI117pass, Accessibility22pass, DevBuild identity verified. Setup/connect, network and revocation E2E, proof-pool contracts, x64 package/installer and both MSIX lanes passed. Production release/ARM64 release jobs skipped. Standard MSIX validation used its existing disposable Dev certificates; no production signing/release was initiated.

CodeQL workflow35429580470 succeeded with its configured security-analysis gates skipped; not claimed as a completed code scan. WSL guest settlement, final moving-consumer lineage, Chrome consent and upgrade gates remain open; DRAFT/no merge/release/no overall LAND completion.

Preserved repair-stage failures on4e3ad46f: composed35428758314 failed before tests/artifact creation because GitVersion rejected shallow checkout. CI35428759743 is terminal failure: Shared4048pass/1fail/1skip (global unobserved SafeFileHandle/ReadToEnd exception captured by the MCP disposal test), and packaged x64 synthetic IPC smoke waited for final response while its settled server remained open. The two fixture corrections are independently reviewed, with no product/validator/deadline change. The separate Shared failure remains explicitly unresolved, not weakened or silently called baseline. Other standard gates passed, including Tray/setup/integration, UI, network/setup/revocation E2E and MSIX; release skipped. The normal PR CI tested merge-ref f3d1248; comparison confirms no production src changes relative to4e3ad46f. No actual composed binary/TS proof was produced by the failed first run.

The current C# owner admits only the complete active generation and holds the existing SID mutex on one owning thread through backend work, confirmed joins and final success/failure frame delivery. No Store gating was added to ordinary bootstrap. Only the exact existing keyless input/caller cases avoid reacquisition; both still execute canonical TS and require its actual expected failure. No TS activation/parent policy, new wire fields, changed generation format, ACL weakening, GC shortcut or pairing rotation.

Scoped source review completed clean (Codex gpt-5.6-sol, autoreview local, exit 0). Retained red-before/green-after regressions cover early IPC cleanup release, oversized discard, expired-budget process/task joins, failure-frame serialization and cancellation-raced partial delivery. Probe descendants use a job assigned before sending the existing frame, not a new probe flag. Proof instrumentation timestamps retirement settlement independently and awaits controller readiness before releasing input.

Remaining WSL gap: Windows process/drain exit is not Linux guest-command settlement. The current invocation closes stdin after script submission and has no guest cancellation/exit acknowledgment. No new guest wrapper/channel/persistence/deadline change is included. Unsettled work stays busy/fail-closed; no hard forced-cleanup or overall LAND-complete claim is made.

The current composed workflow builds and uploads a new GITHUB_SHA/image-hash-bound producer; exact run lineage and terminal failures are recorded above. Old6dd is retained only as historical evidence, never as repaired proof. The run must validate all ten prior checks, stale-launcher refusals with zero-state and registry postconditions, real in-flight inspect/retire/EOF, parser variants, probe descendants, receipt identities and cleanup. Current-head standard Windows CI is also required. No signing/release or real-user installation.

Historical producer, failed investigations and prior Windows validation (not current repair proof)

Producer source and reused binary: 6dddf3d. Proof-only harness head: 16117ce.

Terminal current-consumer result: authority_review_required, not merge-ready. Run 35422437058, redacted receipts 10577951928, producer 6dddf3d / consumer 57f78c49d47f445b85d4859f038e8447e08983ba. All six private role chains and real read-only config validation passed. Ten checks passed: management EOF rejection, real generation installation with canonical TS prepublication probes, actual C#→TS admission and real pairing, origin/profile/state-context rejection, Chrome EOF cancellation, and preservation of the active generation. No synthetic Companion response. Owner cleanup succeeded.

The separate fresh-state lifecycle investigations reproduced both requested behaviors:

  • After completed owner-mediated uninstall, the prior launcher returned success and pairing material and changed its isolated state. Registration remained missing; it was not silently restored. Keyless prepublication probes had not changed that fresh state.
  • After owner-mediated replacement installation, the previous launcher still returned success/pairing material and changed its old isolated state. Replacement state was unchanged and the replacement registration remained active.

This is exact observed lifecycle behavior requiring coordinated authority-contract repair/review, not a newly invented policy or a completed merge gate. C# Program/GenerationStore.RuntimeLease and TS admitWindowsNativeRuntime validate retained private generation integrity/context without current registration identity. RemoveNative deliberately retains generations because GC is not an ABI postcondition. Any agreed active-authority check must occur before successful key/relay side effects while preserving existing keyless prepublication invalid-request/origin probes. No generation tampering, new bypass/probe flag, second registry writer, product source edit, or main/ABI change was made. No merge.

Live ACL result: run 35421401544, redacted receipts 10577965011, diagnosed global-node ancestors 5..1: inherited allow ACE 0 (AceFlags=16), classified authenticated_users, mask 0x001301bf, forbidden-write intersection 0x00010110; leaf intersection 0x00010116. checkout-cli/ancestor-5 failed untrusted_owner (identity withheld). Private installation passed all 16 Node/CLI components, then all six producer/node/CLI/state/config/generation-root role audits passed. Exact current consumer built, actual producer installation and canonical TS rejection probes passed. Positive bootstrap failed afterward; owner cleanup succeeded.

The remaining fixture error is verified against the exact57 schema: profile color is doctor-only legacy input rejected by the strict canonical config schema. Current harness removes it, validates the fixture with actual built SDK readConfigFileSnapshot({observe:false,pluginValidation:"core-only"}), and captures only safe bootstrap response booleans/allowlisted code and harness coordinates. Raw child stderr is explicitly captured, not echoed. Both product pins, validators and global permissions remain unchanged. The corrected-fixture terminal result is recorded above.

Setup attempts 35421033735 and 35421233474 are preserved failures, not native proof. The latter precisely isolated CommandNotFoundException during Node resolution: all hosted-Windows booleans true and audit helper compilation passed. The reviewed correction discovers the actual executable through the installed node launcher, canonicalizes it and requires v24.16.0; production native execution still uses only an explicit admitted private path. No ACL observations or product defect were claimed from these preflight failures.

Scoped autoreview is clean after fixing snapshot/refusal/registry-postcondition evidence gaps. C# audit compile, PowerShell parse, JS syntax and focused proof-evidence checks passed. Required local baseline attempts are not Windows proof: build refused Linux; Shared 3815 passed / 194 failed / 33 skipped; Tray 2965 passed / 18 failed / 2 skipped. No claim of local full-suite success. Normal PR CI runs automatically; no completed matrices were manually rerun.

First composed run built canonical consumer 2048e9b7fa3edcf9993925f29defb17af2c52ebf successfully, then the real producer returned unsafe_path during management installation before TS probes. Missing-management-EOF rejection passed and owner cleanup removed no foreign data. Redacted terminal receipt.

Corrected bounded composed proof completed failure: the exact consumer built, all five producer/node/CLI/state/config path chains were canonical with no symbolic ancestors, but the real producer refused management installation with unsafe_acl before TS probes. Management missing-EOF rejection passed; owner-mediated registry cleanup succeeded. Redacted terminal receipt. Producer executable SHA-256: 950e00a348ee9c31077c36d274c81500b79ae3fb05f812987d6705d32cad01cb. This is not a successful composed native proof. The exact rejected path/ACE is not exposed by the public receipt; do not infer that TS TrustedInstaller handling is missing.

The 04:07 continuation performs that fixture/runtime investigation in this same Windows lane. The prior private-layout proposal is not completion or an external-owner blocker.

  • Full Windows matrix: success, including CI Gate; release skipped.
  • PR-required workflow: success on attempt 2, including CI Gate. Attempt 1 failed while creating its disposable WSL distro (wsl.exe list timed out before the revocation test ran); only failed jobs were rerun. The full exact-head matrix also independently passed revocation E2E. Both completed run conclusions were verified on September 19, 2026 at 03:06 UTC.
  • x64 native and installer proof: success.
  • ARM64 native executable proof: success.

The x64 log contains NATIVE_BOOTSTRAP_PROOF_OK and INNO_MANAGEMENT_TRANSPORT_PROOF_OK. The latter executes a disposable fixture installer/uninstaller using the actual shared Pascal pipe client and helper. It is not a signed release, production Chrome/WSL proof or real-user installation.

Accepted contract SHA-256: 1ad636e97e200ef34f3609d734bbfc2272ae5aba75cccc3df42952a3352f565a. Boundary fixtures SHA-256: b52e1acc48e74114311c32641bc807987c61adfdf4b584fe7b6305f0d6c122a3. Both were reverified after restart recovery.

Change Type

  • Feature
  • Refactor
  • Tests or validation
  • Security hardening
  • Docs or instructions

Scope

  • Gateway, connection, or pairing
  • Setup or onboarding
  • Permissions, privacy, or security
  • Tests, CI, or docs
  • New Windows node capability or local MCP command

Required proof pools

  • windows-clean-installer-upgrade: signed fresh/upgrade/repair/uninstall and remembered opt-out.
  • windows-wsl-gateway-e2e: actual allowed/denied/revoked production credential path with the matching core candidate.
  • windows-11-arm64: native executable, ACL/registry and architecture behavior.
  • windows-winui-interactive: actual Chrome approval and Companion connection/preference behavior.

Validation

Current diagnostic-source checks: node --test scripts/BrowserNativeSavedProfile.test.mjs scripts/BrowserNativeProofTiming.test.mjs: 7/7 passed. dotnet test tests/OpenClaw.E2ETests/OpenClaw.E2ETests.csproj --no-restore --filter FullyQualifiedName~BrowserWslLookupDiagnosticsTests: 6/6 passed, with successful E2E graph compilation. Exact lookup PowerShell parsed; git diff --check passed.

Required local attempts: ./build.ps1 through the installed PowerShell runtime failed because Windows is required; Shared --no-restore: 3823 passed / 194 failed / 33 skipped; Tray --no-restore with isolated data: 2965 passed / 18 failed / 2 skipped. These Linux attempts are not native acceptance and no failures are waived. Fresh Windows CI and dedicated proofs remain required.

Current repair local checks (d7795a2, Linux, isolated tray settings):

  • dotnet test tests/OpenClaw.BrowserBootstrap.Tests/OpenClaw.BrowserBootstrap.Tests.csproj --no-restore -c Release: 166 passed, 0 failed, 5 native-Windows tests skipped.
  • Shared pipe/process/protocol focused tests: 34 passed, 0 failed.
  • dotnet test tests/OpenClaw.Connection.Tests/OpenClaw.Connection.Tests.csproj --no-restore -c Release --filter FullyQualifiedName~BrowserBootstrap: 16 passed, 0 failed.
  • node --test scripts/BrowserNativeProofTiming.test.mjs: 3 passed. JS syntax, PowerShell parser and embedded proof-controller C# compile passed.
  • pwsh -File build.ps1 and pwsh -File scripts/setup-dev.ps1 -CheckOnly: Windows required; not a native build pass.
  • dotnet test tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: 3,823 passed, 194 failed, 33 skipped.
  • dotnet test tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: 2,965 passed, 18 failed, 2 skipped.

These local failures/skips are not accepted Windows validation. The new composed proof and current standard Windows CI are verified terminal success as detailed above, including the disclosed targeted UI retry. Local Linux failures remain historical failed attempts, not converted to passes. Fresh independent review used the exact local change bundle and adjacent ownership/protocol source, and completed with no accepted/actionable findings. No additional unchanged-bundle review is required.

Historical validation before the activation repair

Current-head Windows x64 and ARM64 packaged helper gates pass. Actual production installer compilation and disposable shared-client install/uninstall pass on x64. The early compiler-only gate prevents unsupported Pascal declarations from reaching slow builds.

Exact-head native core results: Shared 4,041 passed/1 skipped; Connection 809 passed/1 skipped; BrowserBootstrap 133 passed/0 skipped; WinNode CLI 127 passed/0 skipped. Tray 2,985 passed/0 skipped; Tray integration 22 passed/0 skipped; SetupEngine 1,192 passed/1 skipped. No failures. The original foreign-write race, uncontended create/update/delete, private/ancestor ACL and uncancellable-read regressions all execute on Windows.

Required local commands were rerun after code changes on this Linux host:

  • pwsh -File build.ps1 and pwsh -File scripts/setup-dev.ps1 -CheckOnly: refuse Linux; not native build proof.
  • dotnet test tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: 3,815 passed, 194 failed, 33 skipped.
  • dotnet test tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: 2,965 passed, 18 failed, 2 skipped.
  • dotnet test tests/OpenClaw.BrowserBootstrap.Tests --no-restore: 129 passed, 4 native-Windows cases skipped.
  • Focused package/cache tests: 6 passed. Installer integration contracts: 3 passed.
  • PowerShell parser, production framing helper, CI workflow contracts and git diff --check: passed.

Linux runtime/path/loopback failures are not represented as green gates. Native matrix results above are the platform evidence.

Independent review repaired registry concurrency, uncancellable stdin deadlines, protected Program Files ancestor admission, packaging and installer compiler defects. Each repair received fresh scoped review. The final producer review's request to migrate the alleged previous release was rejected: the retired helper existed only in this unmerged PR; the agreed ABI requires unknown/legacy bindings to be preserved and refused. No clean-review claim is made for that exit-1 pass. Subsequent scoped repair reviews exited 0 without actionable findings.

Real Behavior Proof

Current fixture changes have portable diagnostic tests only. New hosted native/WSL proof and exact final-consumer lineage are pending; no whole-Companion, Chrome consent or upgrade claim is added.

Current repair: published783f178c/source d7795a2 plus fixturee3db53c2; new producer artifact and all14 composed checks verified in run35429579145 as detailed above. Prior terminal red run 35422437058 remains preserved and is not relabeled green. WSL guest settlement, Chrome consent, final moving-consumer lineage and upgrade gates remain open.

Historical pre-repair packaged helper evidence follows, not current repaired runtime proof:

  • Environment: disposable hosted Windows x64 and native ARM64 runners.
  • Head: 6dddf3d.
  • Native command: ./scripts/Test-BrowserNativeHost.ps1 -ExecutablePath publish/tools/browser-bootstrap/OpenClaw.BrowserBootstrap.exe.
  • Installer command: ./scripts/Test-BrowserBootstrapInstaller.ps1 with that executable and the installed Inno Setup compiler.
  • Observed: exact packaged binaries execute; management requires EOF and rejects missing EOF within its deadline; private generations and ownership checks work; native framing/origin/current-user IPC, native-first Store request, cleanup and foreign preservation pass. Installer/uninstaller pipes accept bounded clean receipts and clean owned registry entries.
  • Evidence links: current-head job links and successful log markers verified. No Chrome screenshot claimed.
  • Not verified / blocked: composed canonical TypeScript native-Windows consumer; actual Companion/provenance/WSL production credential delivery and rejection after foreign destination/disconnect/switch; Chrome consent; signed fresh/upgrade/repair/uninstall and MSIX runtime upgrade behavior. These remain merge gates.

Security Impact

Optional user-approved Chrome enrollment adds native execution and owned current-user registry metadata. Pairing travels through authenticated same-user IPC or the explicitly bound canonical Windows CLI. No gateway-token fallback, Chrome profile edits, enterprise policy, elevation or arbitrary selector fields. Private ownership protections remain strict; TrustedInstaller is accepted only for existing non-private directory ancestors.

Compatibility and Migration

No external Chrome v1 bump, public user-config fields or native-Windows provisioning. Foreign/unknown/legacy registrations are preserved and refused, not adopted. Same-context new-format upgrades require renewed admission. Partial or uncertain operations are not falsely reported as rolled back. Uninstall retains generation directories rather than recursively deleting possibly referenced content.

Review Conversations

  • Accepted implementation and native-CI findings addressed and re-reviewed.
  • Production integration and upgrade proof complete before merge.

The fork-only collaboration toggle is inapplicable to this same-repository PR (GitHub 422); normal repository collaborator permissions apply.


View the OpenClaw team session

roboclaw-bot and others added 5 commits September 18, 2026 17:44
Add a bounded native-messaging executable, current-user tray IPC, managed-local WSL pairing admission, ownership-preserving registration, packaging, and architecture-specific proof hooks. Store installation and Windows runtime proof remain coordinated follow-up gates.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Register the native host before creating the owned HKCU external Store request, preserve foreign entries and persisted opt-outs, and remove only owned registrations. Match the coordinated remote:false CLI response and keep pre-setup bootstrap retryable.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@clawsweeper

clawsweeper Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

OpenClaw-Publication: ebec6cb8-5bb0-429e-9c98-7584d9f52b77

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@roboclaw-bot
roboclaw-bot force-pushed the openclaw/automatic-chrome-extension-pairing branch from 1004606 to 136a955 Compare September 18, 2026 18:16
@roboclaw-bot roboclaw-bot added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 18, 2026
@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 18, 2026
@clawsweeper

clawsweeper Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex review: needs real behavior proof before merge. Reviewed September 28, 2026, 5:28 AM ET / 09:28 UTC (Revision 43).

ClawSweeper review

What this changes

The branch packages a Windows Chrome native host, adds installer and tray registration, routes local pairing through the managed WSL Gateway, and adds validation and proof workflows.

Merge readiness

⛔ Blocked before merge - 8 items remain

Keep this PR open. Current main does not provide the Windows Chrome bootstrap flow, and two previously identified defects remain on the pinned head: pairing authority can lapse before the Chrome response, and enabling Browser control after startup does not register the host.

Priority: P2
Reviewed head: 88958a82fab7063eea3a44ffc92fa4868b325db3

Review scores

Measure Result What it means
Overall readiness 🦪 silver shellfish (2/6) The branch has substantial focused validation and prior-head real-path evidence, but current-head final-effect and upgrade proof remain incomplete alongside two actionable defects.
Proof confidence 🦪 silver shellfish (2/6) Needs stronger real behavior proof before merge: Authority-chain proof required: the production tray owner checks an allowed managed Gateway and returns pairing bytes, but the captured runs do not show an allowed request and a revoked request at the native host's final Chrome write. A preceding-head production WSL owner run exercises real transport recovery, and a later native run reached 23 of 24 checks before the foreign-Store refusal; the exact-head run remains in progress. The new persisted generation and registry contract also lacks signed existing-state upgrade proof. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Patch quality 🦐 gold shrimp (3/6) Security review found an item that needs attention.

Verification

Check Result Evidence
Real behavior Needs proof Needs stronger real behavior proof before merge: Authority-chain proof required: the production tray owner checks an allowed managed Gateway and returns pairing bytes, but the captured runs do not show an allowed request and a revoked request at the native host's final Chrome write. A preceding-head production WSL owner run exercises real transport recovery, and a later native run reached 23 of 24 checks before the foreign-Store refusal; the exact-head run remains in progress. The new persisted generation and registry contract also lacks signed existing-state upgrade proof. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
Evidence reviewed 12 items Pinned introduction: The merge-base-to-head patch adds the browser bootstrap implementation; the verified test merge has the pinned main and head as its two parents.
Final-response authority gap: The tray checks the active gateway and endpoint before returning pairing bytes, but the pipe server and native host subsequently write those bytes without another live gateway authorization check.
Registration only at startup: Start runs management registration only if Browser control is already enabled. The settings-saved handler invalidates pairing requests but does not register the host when the preference changes from off to on.
Findings 2 actionable findings [P1] Recheck pairing authority before the Chrome response
[P2] Register the host when Browser control is enabled later
Security Needs attention Pairing response may cross a revoked authority boundary: The tray returns a successful credential-bearing response after checking the gateway, while the pipe server and native host perform the final Chrome write later without revalidating that gateway's current authority.

How this fits together

Chrome sends a native-messaging request to the packaged Windows host. The host consults the tray and managed WSL browser CLI for pairing, while a Windows registration owner manages native-host and Chrome Store entries.

flowchart LR
 A[Installer and tray settings] --> B[Windows registration owner]
 B --> C[Chrome native host]
 C --> D[Tray pairing service]
 D --> E[Managed WSL browser CLI]
 E --> D
 D --> C
 C --> F[Chrome pairing response]
Loading

Before merge

  • Add real behavior proof - Needs stronger real behavior proof before merge: Authority-chain proof required: the production tray owner checks an allowed managed Gateway and returns pairing bytes, but the captured runs do not show an allowed request and a revoked request at the native host's final Chrome write. A preceding-head production WSL owner run exercises real transport recovery, and a later native run reached 23 of 24 checks before the foreign-Store refusal; the exact-head run remains in progress. The new persisted generation and registry contract also lacks signed existing-state upgrade proof. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.
  • Recheck pairing authority before the Chrome response (P1) - A gateway disconnect, switch, or Browser-control disable can occur after this method returns the pairing bytes but before the pipe and native host write them to Chrome. Carry a live revocation check or equivalent owner-held authority through that final write, and prove the nearest revoked case produces no pairing frame.
  • Register the host when Browser control is enabled later (P2) - Start registers the host only when the saved preference is already enabled. The settings-saved callback only invalidates requests, so turning Browser control on during a running session leaves Chrome without the native host until restart.
  • Resolve security concern: Pairing response may cross a revoked authority boundary - The tray returns a successful credential-bearing response after checking the gateway, while the pipe server and native host perform the final Chrome write later without revalidating that gateway's current authority.
  • Resolve merge risk (P1) - The current head lacks allowed-then-revoked proof at the final Chrome response boundary; earlier WSL and native receipts do not establish that a disconnected or switched gateway is refused before Chrome receives pairing material.
  • Resolve merge risk (P1) - Private generation files and current-user Chrome registrations change persisted setup state, but signed fresh-install, upgrade, repair, and uninstall compatibility with existing user state remains unverified.
  • Resolve merge risk (P1) - The pinned canonical consumer correction at fix(browser): Windows Chrome setup fails after saved-profile Store enrollment openclaw#160161 is still open, so the final combined behavior is not established by a merged consumer.
  • Complete next step (P2) - Repair final-response revocation and later Browser-control enablement; provide allowed and revoked final-Chrome-output proof, terminal current-head native and WSL results, and signed upgrade evidence against the merged canonical consumer.

Findings

  • [P1] Recheck pairing authority before the Chrome response — src/OpenClaw.Connection/BrowserBootstrapService.cs:37-40
  • [P2] Register the host when Browser control is enabled later — src/OpenClaw.Tray.WinUI/Services/BrowserBootstrapHost.cs:59
  • [high] Pairing response may cross a revoked authority boundary — src/OpenClaw.Connection/BrowserBootstrapService.cs:40
Agent review details

Security

Needs attention: The final Chrome response can outlive the tray authorization check, allowing pairing material to cross a revoked gateway boundary.

Review metrics

Metric Value Why it matters
Production and test code production +2323/−0 lines; tests +3133/−4 lines The PR attributes substantial production growth to consolidating Windows native registration and pairing ownership, which warrants focused boundary review.

Merge-risk options

Maintainer options:

  1. Complete the authority and upgrade path (recommended)
    Repair final-response revocation and later enablement, then capture allowed and revoked Chrome output plus signed existing-install upgrade results on the reviewed head.
  2. Keep the draft paused
    Leave the branch open while the canonical consumer lands and the native, WSL, Chrome, and upgrade acceptance runs reach terminal results.

Technical review

Best possible solution:

Keep one Windows registration owner, make live authorization govern the final Chrome write, register when Browser control is enabled later, and land only with current-head Chrome and signed upgrade evidence against the merged canonical consumer.

Do we have a high-confidence way to reproduce the issue?

No complete current-head runtime reproduction has been captured. Source establishes the off-to-on registration omission and a controlled scheduling point between the final tray check and Chrome write.

Is this the best way to solve the issue?

No. The single-owner design is appropriate, but the final response must remain tied to live authority and the registration lifecycle must handle a saved preference becoming enabled.

Full review comments:

  • [P1] Recheck pairing authority before the Chrome response — src/OpenClaw.Connection/BrowserBootstrapService.cs:37-40
    A gateway disconnect, switch, or Browser-control disable can occur after this method returns the pairing bytes but before the pipe and native host write them to Chrome. Carry a live revocation check or equivalent owner-held authority through that final write, and prove the nearest revoked case produces no pairing frame.
    Confidence: 0.92
  • [P2] Register the host when Browser control is enabled later — src/OpenClaw.Tray.WinUI/Services/BrowserBootstrapHost.cs:59
    Start registers the host only when the saved preference is already enabled. The settings-saved callback only invalidates requests, so turning Browser control on during a running session leaves Chrome without the native host until restart.
    Confidence: 0.96

Overall correctness: patch is incorrect
Overall confidence: 0.93

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 3331b5e38876.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This is a significant browser setup improvement with bounded current impact, while identified merge blockers require repair.
  • merge-risk: 🚨 security-boundary: Pairing material can be prepared under one gateway state and written to Chrome after that state has been revoked.
  • merge-risk: 🚨 compatibility: The new persisted generation and registry paths have no accepted signed existing-install upgrade result.
  • rating: 🦪 silver shellfish: Overall readiness is 🦪 silver shellfish; proof is 🦪 silver shellfish and patch quality is 🦐 gold shrimp.
  • status: 📣 needs proof: The PR needs real behavior proof before ClawSweeper can clear the contributor ask. Needs stronger real behavior proof before merge: Authority-chain proof required: the production tray owner checks an allowed managed Gateway and returns pairing bytes, but the captured runs do not show an allowed request and a revoked request at the native host's final Chrome write. A preceding-head production WSL owner run exercises real transport recovery, and a later native run reached 23 of 24 checks before the foreign-Store refusal; the exact-head run remains in progress. The new persisted generation and registry contract also lacks signed existing-state upgrade proof. After adding proof, update the PR body; ClawSweeper should re-review automatically. If it does not, the PR author or someone with repository write access can comment @clawsweeper re-review.

Evidence

Security concerns:

  • [high] Pairing response may cross a revoked authority boundary — src/OpenClaw.Connection/BrowserBootstrapService.cs:40
    The tray returns a successful credential-bearing response after checking the gateway, while the pipe server and native host perform the final Chrome write later without revalidating that gateway's current authority.
    Confidence: 0.91

What I checked:

Likely related people:

  • Barbara Kudiess: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Jeremy McKeehen: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • Natalie Aguinaldo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Repair final-response revocation and show allowed and revoked outcomes at Chrome's response boundary.
  • Cover a persisted Browser-control off-to-on transition without restarting the app.
  • Verify the merged consumer with current-head native, WSL, Chrome approval, and signed upgrade evidence.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (42 earlier review cycles; latest 8 shown)
  • reviewed 2026-09-28T01:54:47.424Z sha 6bf6ffd :: needs real behavior proof before merge. :: [P2] Expect reuse after an unchanged saved-profile install
  • reviewed 2026-09-28T03:04:31.549Z sha 58f0eb8 :: needs real behavior proof before merge. :: [P2] Expect reuse on an unchanged saved-profile install
  • reviewed 2026-09-28T03:48:18.379Z sha a14dc45 :: needs real behavior proof before merge. :: [P2] Expect reuse on an unchanged saved-profile install | [P2] Register the host when Browser control is enabled later | [P1] Bind revocation to the final Chrome response
  • reviewed 2026-09-28T04:42:42.666Z sha 92afaa4 :: needs real behavior proof before merge. :: [P1] Bind revocation to the final Chrome response | [P2] Register the host when Browser control is enabled later
  • reviewed 2026-09-28T05:28:20.241Z sha 92afaa4 :: needs real behavior proof before merge. :: [P1] Bind revocation to the final Chrome response | [P2] Register the host when Browser control is enabled later
  • reviewed 2026-09-28T06:05:12.738Z sha 37256b7 :: needs real behavior proof before merge. :: [P1] Recheck authorization before the final Chrome response | [P2] Register the host when Browser control is enabled later | [P1] Repin after the consumer can select an owned Store profile
  • reviewed 2026-09-28T06:18:29.096Z sha 9c604ea :: needs real behavior proof before merge. :: [P1] Revalidate authority before writing the Chrome response | [P2] Register the host when Browser control is enabled later
  • reviewed 2026-09-28T09:21:58.371Z sha 88958a8 :: needs real behavior proof before merge. :: [P1] Recheck pairing authority before the Chrome response | [P2] Register the host when Browser control is enabled later

roboclaw-bot and others added 3 commits September 18, 2026 18:27
Insert the helper payload after SDK publish conflict resolution so parent runtime assets do not remove its nested hostpolicy and framework files. Add executable MSBuild regression tests and a completeness gate. Independent autoreview passed with no actionable findings.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
…tion objects

Execute the production framing functions in a MemoryStream regression before touching the registry. Suppress VoidTaskResult pipeline output from ReadExactlyAsync. Independent autoreview passed with no actionable findings.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
…input

Address verified ClawSweeper findings: validate the canonical IPv4 destination with the same pinned gateway and distro before and after CLI execution, while retaining original-record lifecycle checks. Normalize CRLF/CR script input to LF before Bash stdin. Six regression cases added; 16 focused connection tests and independent autoreview pass.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Addressed the two code findings in f90b195174a9d58281c58bbc1b78d3a4e71fe18b:

  • Both provenance checks now receive an immutable record pinned to the exact 127.0.0.1 destination returned by the CLI, retaining the same gateway ID and managed distro. Lifecycle/switch checks still use the original active record. Regression cases reject separately owned IPv4 for IPv6/localhost records and verify both destination checks.
  • Bash stdin now normalizes CRLF and lone CR to LF, with Windows-checkout regression cases.

The focused connection suite now passes 16 tests. Independent autoreview of this correction exited 0 with no actionable findings.

Real Windows CI also exposed and led to fixes for nested self-contained runtime files being dropped during publish and async completion objects leaking from the PowerShell proof reader. Those fixes have dedicated regressions and clean independent reviews. The latest exact-head full Windows run is https://github.com/openclaw/openclaw-windows-node/actions/runs/35380918100 . It is still running, not claimed complete.

The draft remains blocked from merge pending the compatible coordinated core CLI, real production Windows/WSL authority-chain and Chrome approval proof, and installer/upgrade proof. Synthetic pipe tests are not presented as that authority-chain evidence. No forced enterprise policy, release publication, or merge is requested here.

Clear the stale native exit code only after all proof assertions and cleanup finish successfully. Real Windows x64 and ARM64 runs reached both success markers but GitHub inherited the last intentional rejection exit status. Independent autoreview passed without actionable findings.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. and removed rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. labels Sep 18, 2026
@roboclaw-bot roboclaw-bot added status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. and removed status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. labels Sep 18, 2026
roboclaw-bot and others added 6 commits September 19, 2026 01:43
Use the agreed bounded management ABI and sole generation-backed registry owner for explicit managed WSL and native Windows transports. Preserve private ACL, provenance, lifecycle, cancellation and foreign-entry protections; exercise packaged helpers and installer pipe management in Windows CI.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
OpenClaw-Publication: 419c1274-364c-4165-8c59-cb7f1f493677
Require the ninth non-E2E suite and derive the strict runner count from the explicit project inventory. Reproduced the exact Windows fast-validation failure locally; repaired contract passes and fresh scoped autoreview is clean.
OpenClaw-Publication: 44e3f8cf-ed9c-4ab9-b824-078556e512cb
Track the credential-free single-file profile previously omitted by the generic pubxml ignore rule, fail before nested publish when missing, and verify bundle settings. Update the core cache test inventory for the complete bootstrap graph and normalize MSBuild paths for portable validation. Focused packaging/cache tests and fresh scoped review pass.
OpenClaw-Publication: 925fbbfa-fb99-42c4-b323-2157e9967e18
roboclaw-bot and others added 7 commits September 20, 2026 00:13
OpenClaw-Publication: 4667b421-0ba1-42be-8c15-83136272b5be
Preserve both architecture ledger additions and current main integration changes. Recovery validation remains pending.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Pin native and WSL acceptance to the landed canonical consumer. Preserve the exact native registration assertion while reporting closed-schema CLI projection facts, and distinguish WSL lookup entry/query/completion without changing identity guards or deadlines. Node diagnostics and protocol regressions pass 14/14 in a secretless network-isolated sandbox. Windows build and hosted acceptance remain pending.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Align native initialization with the landed consumer and Node version and add a cross-file pin regression. Correct the bootstrap ownership documentation. Accept the concrete autoreview preflight mismatch; reject the claimed x64 ARM64 execution because build-arm64 runs on windows-11-arm. The historical observer readiness caller already has a five-second timeout; its EOF diagnostic refinement is not a production or current acceptance blocker.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Bind the WSL lane guard to a5d1625 after coherent consumer/preflight pins. Preserve the original edd93 native production baseline. Canonical autoreview d5cbe626 (Codex gpt-6-sol/high, P0-P2) completed both full-candidate passes scoped-clean with inherited authentication, proxy and isolation unchanged.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Reconcile the main migration contract with the existing browser-generation preservation branch. Keep the exact successful-cleanup gate and add negative cases for disabling the native-generation guard or removing its early exit. The merged source previously failed the positive assertion; all 11 focused cases now pass in a secretless network-none container. Canonical scoped P0-P2 autoreview is clean.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Native proof 36367399725 stopped before producer build because pnpm/action-setup looked for package.json at the empty workspace root. Select consumer/package.json through the documented action input and keep its immutable packageManager as the sole version owner. The new regression reproduces the missing-selector failure and all 16 Node checks pass in secretless network-none isolation. No product or acceptance assertion changed.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
@clawsweeper clawsweeper Bot added rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. and removed rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. labels Sep 28, 2026
roboclaw-bot and others added 3 commits September 28, 2026 01:55
Advance only the native proof fixture guard to c23905b after the packageManager path correction. Canonical scoped P0-P2 autoreview passed with no findings; production baseline and runtime guards remain unchanged. Existing 6bf6ffd WSL and CI runs are still being collected before the next publication.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
The saved-profile fixture passed --wait-ms 0, but the canonical CLI rejects values outside 1000-120000 before installation. Reproduce exact CLI error on the immutable bb2 consumer package in a secretless network-none Node24.19 sandbox; 1000 reaches registration-status output. Correct all 15 fixture invocations to the canonical minimum and add a red/green range regression. All 17 Node checks pass. Production 15s/2s bounds and all acceptance/ownership assertions are unchanged; actual Windows acceptance remains required.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Advance the native-fixture guard to 11827e2 after replacing all invalid zero discovery waits with the canonical 1000ms minimum. Canonical scoped P0-P2 review passed; the exact CLI red/green reproduction and 17 Node tests passed. Preserve edd93 production baseline and every native/WSL ownership, settlement, identity and acceptance guard.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Saved-profile seed cause fixed; exact-head acceptance remains required

Published candidate: a14dc45. The failed 58f native run remains 14/23, with all nine saved-profile checks unreached. Its receipt10949863589 reports seed exit1/error projection and successful owned cleanup, not acceptance.

The cause is the fixture input, not a registration-output schema change: every saved-profile invocation used --wait-ms 0, while the immutable canonical normalizer requires 1000-120000 ms, before installation. The historical572 consumer has the same minimum. The rejected CLI error was then obscured by the old registrations.some exception.

Using the actual source-bound bb2 package (SHA256 bdd915c075eaaf05055aad4067a4d01982d96ca9683f3f1ca8cc6145753cf3b2) in a secretless network-none Node24.19 sandbox: zero produces the exact wait-range refusal and no registrations; changing only the wait to1000 reaches normal registration-status JSON. Config validation passes and all four CLI flags are recognized. This is a parser/fixture reproduction on Linux, not Windows registry acceptance.

All15 invocations now use the canonical minimum. The regression was red before the correction; all17 Node checks pass afterward. Canonical autoreview d5cbe626 (Codex gpt-6-sol/high, P0-P2) is scoped-clean. The native fixture guard advances to11827e21, while the originaledd93 production guard remains unchanged. No C# product changes, ownership/refusal assertion relaxation, public ABI changes, or production15s/2s deadline changes.

58f production WSL36371812131 independently passed all6 cases againstbb2, including real CLI pairing, actual forced client kill with UNKNOWN/BUSY retention, ordered settlement, and complete owned cleanup. Receipt10950470629. This is not relabeled as a14 proof.

58f CI36371816804 remains unaccepted: Shared's unchanged audio cancellation test failed its immediate HasExited assertion atline54; Revocation failed during fixture Phase1 with restart-preparation/state-coordinator-contention categories, before its behavior assertion. Setup/connect passed. UI remained nonterminal before the necessary new-head publication. These are preserved failures, not waived or attributed to Chrome without evidence. No blind rerun or speculative unrelated production patch.

Draft stays open pending exact-a14 native23, WSL6 and all required CI gates. No merge, release or Store publication is claimed.

Recovery implementation and verification

roboclaw-bot and others added 3 commits September 28, 2026 04:24
The a14 native seed and saved-profile selection now pass, but the fixture incorrectly demanded a new generation for idempotent install. Require unchanged generation/directory state and seed retained history through explicit same-owner origin transitions, restoring canonical CLI origins before pairing. Preserve all 23 acceptance cases and immutable generation rules. The a14 WSL run failed before any owner case; add bounded closed-schema fixture-phase/setup JSONL diagnostics without exposing logs, paths, argv or credentials. Node18 and CSharp22 focused tests pass in secretless network-none isolation. No product, ABI, ownership or deadline change; actual Windows proof and CI remain gates.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Accept the scoped review finding that a record cap must retain the newest records, not discard the final failure. The new regression reproduces the prior loss and all 23 CSharp diagnostic/transport tests pass in secretless isolation. Clarify that native generation reuse sees only currently registered manifests, not retained directories; the proposed restore-reuse finding does not apply to this owner. No production or acceptance guard changes.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Bind the native fixture guard to b926e7a after the idempotent-generation history correction and bounded newest-record diagnostics. Canonical corrected P0-P2 autoreview completed scoped-clean; Node18 and CSharp23 focused checks pass. Original production source and ownership/deadline/ABI guards remain unchanged. All required exact-head Windows proofs and CI are still required before landing.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Idempotent-generation proof corrected; setup admission remains observable and fail-closed

Current candidate: 92afaa4. No production C# or TypeScript consumer changes, public ABI changes, identity relaxation or production 15s/2s deadline changes.

The a14 native run 36374656166 remains failed, 14/23. Its receipt 10950619450 confirms that the corrected CLI seed is owned Work, actual initial pairing succeeds, and selector-free inspect/verify/install retain Work/relay19444 and the missing Store request. The next failure was fixture line78 demanding one new generation for install. The existing C# owner deliberately reuses a matching binding and executable.

The corrected oracle requires zero added directories and the same active generation for same-input setup. To retain the mixed-generation and retired-profile checks, history is now prepared through explicit same-owner origin transitions using the one C# writer, followed by actual canonical CLI restoration before pairing. No generation files or producer bytes are forged. The original canonical generation is retained but unregistered; the owner's reuse inventory contains registered manifests only, not arbitrary retained directories. All 23 acceptance checks remain required.

The a14 WSL run 36374656149 remains failed before any owner case. Its receipt 10950014764 has cases=[], fixture:InvalidOperationException and ownedFixtureDisposed=true. This is not a post-kill owner failure or proof that a verified Gateway changed. New proof-only diagnostics distinguish initialization, tray stop, identity inspection and actual owner cases. Initialization failures project only closed setup stages/codes and numeric command facts from a bounded private JSONL tail; no raw messages, paths, argv, output or credentials are uploaded. Primary facts cannot be overwritten by rollback. A reviewed latest-record bug was reproduced and fixed: keep the newest 1024 records within 256KiB, not the oldest records in the tail.

Local secretless network-none checks: 18 Node tests and 23 C# diagnostic/transport tests passed, with the new tail regression red before repair. Canonical corrected autoreview d5cbe626, Codex gpt-6-sol/high P0-P2, completed scoped-clean. Native fixture guard b926e7a and original edd93 production guard are retained independently.

Required a14 CI 36374660003 is also failed. Its current blocker differs from 58f: Connection's unchanged MigrationRecordTests.CleanupScript_CompletedReceiptPreservesFilesWithoutCallingWsl exceeded its existing 30-second child-script limit; root cleanup was confirmed. No speculative deadline increase, unrelated production patch or waiver was made. The a14 UI/functional/accessibility job passed. Earlier audio, setup-admission and cancelled UI evidence remains preserved separately.

This is not merge acceptance. Fresh exact-92af native23, WSL6 and every required CI gate must pass. No release or Store publication is claimed.

Recovery implementation and verification

@clawsweeper clawsweeper Bot removed the merge-risk: 🚨 availability 🚨 Merging this PR could cause crashes, hangs, restart loops, stalls, or process outages. label Sep 28, 2026
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Blocked on the canonical consumer selection contract; no merge

Frozen Windows head 92afaa4, consumer bb2d479926adb23fb30737e2fd3e5af63969dc84. All current acceptance runs are terminal failures, not waived.

Native: 21/23. Run36378360927, receipt10952945221. All original14 plus7 saved-profile checks passed, including real Work pairing, relay19444/gateway18789, idempotence, opt-out and negative ownership cases. Explicit Store enrollment succeeded; selector-free repair then produced no target projection (fixture197:39). The two final checks remain unverified. Owned registration/Store cleanup succeeded.

A concrete consumer contract defect now blocks this configuration:

  1. The consumer initially inspects chrome when no profile is specified.
  2. With native and Store ownership bound to Work, the C# Store guard and profile-bound SameOwnership return a valid preliminary tuple: context_conflict, owned native-windows-cli, store=foreign, installation=null.
  3. The canonical classifier rejects store=foreign before its context-conflict recovery branch. It never performs the bounded read-only Work probe.

A secretless source-derived reproduction executes the exact immutable selection function with contract-shaped observations: missing Store selects Work (two probes); requested Work Store with the initial chrome conflict refuses with zero Work probes; an already matching Work/requested observation succeeds. Type erasure and dependency injection only; no policy patch. File Git blob35ca06eaaecdb65daa6dd7633d707d7035745b00 independently matches GitHub. This is not an additional Windows registry run, and the failed real run did not retain its raw CLI error text.

The canonical selection owner needs a follow-up correction/regression that permits safe preliminary read-only discovery while still requiring a fully validated final native/Store selection before any effects. Do not loosen C# Store ownership/removal or treat foreign/unknown observations as mutation permission. Main#152057 remains merged and was not reopened or edited by this Windows writer. A corrected reviewed immutable consumer pin is an external landing dependency.

Separate unwaived gates: WSL36378360966 reached 0/6, failing fixture initialization with closed restart-preparation/intent-refusal/state-coordinator-contention observations; these do not prove the lock-holder cause. CI36378364728 failed Core migration-cleanup's30s script timeout, Setup/connect and Revocation fixture initialization, and CI Gate. UI and other reported jobs passed; skips are not passes. No blind rerun, timeout increase, unrelated patch or force merge.

PR remains draft and unmerged. Historical failures, both contributor credits and all Work sessions remain intact. No release or Store publication.

Recovery implementation and verification

@roboclaw-bot roboclaw-bot added status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. and removed status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. labels Sep 28, 2026
Recover only allowlisted setup completion stages when the logger redacts
step identifiers. Correlate commands and exceptions by step-start boundaries
and cover the real logger path, unknown text, and cross-step isolation.

Capture pre-cleanup process and drain completion in migration timeout
diagnostics without changing deadlines, cleanup or preservation assertions.
These are diagnostic corrections, not a waiver or claimed runtime repair.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Independent required-CI diagnosis and bounded diagnostics

Source 37256b7 changes three test/diagnostic files only. This is not a production-runtime fix or merge acceptance. Canonical consumer remains bb2d479926adb23fb30737e2fd3e5af63969dc84 pending the separate Store-selection follow-up described above. No guard, deadline or ownership policy was relaxed.

Baseline evidence: main 3331b5e runs 36343820973 and 36350261697 fail the exact same 23 Setup/connect identities as 92af, during shared fixture initialization on Gateway 2026.9.6 (eb377ac). Wizard completion and reload restoration succeed; restart then encounters state-lifecycle admission contention and refuses intent recording. Prior occurrence is proven, but the coordinator holder/root cause is not.

The two migration timeouts are not proven pre-existing: all five target theory cases passed in the base dispatch (base push skipped Connection tests after an earlier Shared failure). Current Revocation also passed on both base runs; its startup-error family occurs in base Setup/Network, not that exact case. Coverage mode differs between base dispatch and PR, so this is not a controlled regression attribution. No blanket flaky/unrelated classification or waiver.

Corrections: the real SetupLogger redacts every step_id; the prior proof parser therefore lost the stage and preceding command facts. The parser now recovers only allowlisted completion prefixes and correlates by step-start boundaries, with actual-logger and cross-step regression tests. Migration timeout diagnostics now record whether the root and output tasks had already exited/completed before cleanup. The 30s oracle, tree kill, bounded joins and preservation assertions are unchanged. One current timeout had already logged the expected lock-sharing refusal before reaching the checker, so attributing both to checker compilation would be unsupported.

Validation: inspected network-none, proxy-forwarding-disabled isolated .NET 10.0.401 environment: actual logger red reproduced 2 failures; corrected focused suite 27/27; scratch-only execution of the exact migration timeout helper 1/1 (Linux process lifecycle, not Windows PowerShell proof). Full build/setup-dev reject Linux. Full Shared 140 failed / 4008 passed / 33 skipped and Tray 14 failed / 3146 passed / 2 skipped remain unsuccessful local attempts, not Windows acceptance. Current canonical autoreview helper d5cbe626989195044e97545b3acb7c99b06a6103, Codex gpt-6-sol/high, P0–P2, completed scoped-clean with unchanged review authentication/proxy/isolation.

New source-triggered CI/WSL runs collect the missing diagnostic facts; they are not blind reruns and do not substitute for final coupled native/WSL proof on the corrected immutable consumer. Historical 92af native 21/23, WSL 0/6, and required CI failures remain failed and unwaived. Draft remains open; no merge, release or real-user installation.

roboclaw-bot and others added 2 commits September 28, 2026 06:08
Pin native and WSL composition to reviewed OpenClaw consumer 6cff5472.
Retain every prior native case and verify saved Work Store preservation
for inspect, verify and install through the actual canonical CLI.

Construct a real foreign Chrome Store with a matching Work native host
through the sole C# owner. Require typed ownership refusal, failed CLI
verify/install, unchanged state hashes and native generations, and exact
owned cleanup. No product guard, timeout or ABI change.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Advance only the native fixture pin to reviewed source 9e650dd.
Keep the original native production baseline and all fail-closed guards.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Corrected immutable consumer now under native composition proof

Windows source 9c604ea freezes reviewed fixture 9e650dd and uses exact reviewed OpenClaw 6cff547216bd3229446d7cc32a7dae667182ef51 from #160161. This tests the consumer before its merge; it does not wait circularly for consumer landing. Original #152057 stays merged. This is pending acceptance, not a passing receipt.

The guarded native workflow retains all 23 prior checks and adds one actual foreign-Store check. Saved Work enrollment is now exercised through selector-free inspect, verify and install, requiring Work/relay19444, requested Store state and unchanged pairing for each action.

For the negative case, the same C# owner creates a legitimate Chrome Store request, removes its native registration while preserving that Store request, then installs a Work native host without modifying the Store. A matching Work inspection must return the typed foreign_registration / owned-native / foreign-Store response with its current descriptor. The real canonical CLI must refuse verify/install with no success projection, no native generation or Store mutation, and identical before/after initialized fixture-state hashes. Cleanup removes only those precisely bound fixture owners. No forged registry values, alternate production writer, consumer-source patch or relaxed guard is used.

The reviewed consumer orders selected-profile confirmation before relay access and installation. Live proof captures typed ownership observations, CLI outcomes, preserved state/generation hashes and cleanup; it does not claim an instrumented count of internal token-read calls.

Validation: 19/19 Node fixture/transport checks passed in an inspected credential-free, proxy-forwarding-disabled, network-none container. Canonical gpt-6-sol/high P0–P2 autoreview completed scoped-clean for the fixture/pin update and separately for the one-line freeze update. Original native production baseline and exact fixture guards were checked; the old fixture pin was correctly rejected. Required local build/setup-dev refuse Linux; Shared 140 failed / 4008 passed / 33 skipped and Tray 14 failed / 3146 passed / 2 skipped remain failed local attempts, not Windows proof.

Native evidence will be evaluated against all 24 named checks plus explicit Store recovery/refusal and cleanup fields. Final Windows landing still requires current-head CI and WSL acceptance. All prior failed receipts and diagnostics remain unwaived. No release, signing, real-user installation or main-tree edit.

roboclaw-bot and others added 2 commits September 28, 2026 09:09
Canonical 6cff CLI inspection initializes a 1454080-byte general state
database, reproducing the old whole-tree 1 MiB bound with just three entries.
Snapshot config and atomic siblings, credentials and browser installation
state instead, with 64 KiB streaming hashes and unchanged 1 MiB/256-entry
acceptance budgets. Detect absence, mutation, links and unsupported files.
Keep prior native whole-state checks and foreign Store/generation checks.

Record bounded role-only legacy size/count evidence before the browser
snapshot; never expose file names, contents, pairing material or raw errors.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
Bind WSL composition to reviewed snapshot source aa6cc7f.
Keep original native production baseline and all refusal/settlement guards.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
Co-authored-by: fuller-stack-dev <263060202+fuller-stack-dev@users.noreply.github.com>
@roboclaw-bot

Copy link
Copy Markdown
Contributor Author

Native snapshot fixture repaired; consumer pin unchanged

New Windows candidate 88958a8 freezes reviewed fixture aa6cc7f against the same immutable consumer 6cff547216bd3229446d7cc32a7dae667182ef51. Native composition 36402484091 is the new source-triggered acceptance run, not an accepted result yet.

Preserved failure: 9c6 native 36385074120 finished 23/24, with all three saved Work Store recovery actions passing. Its true-foreign test stopped at the before-state snapshot, before either rejection call. Receipt 10954994185, SHA-256 40989c1bde54ab38bcc03b5e4de9129c3faff36c2e0d470fd0f6142e5c6942cd, remains failed, not consumer-security evidence.

Reproduced fixture cause: the exact 6cff package (e719847e6fd543c4e441d7414e9577143e4a675a54a82c8318fdc05d9de01c7b) running ordinary CLI inspection in an inspected secretless Node24.19 container initialized a 1,454,080-byte general runtime database. The old snapshot reproduced fixture_state_bound: only 3 entries, so the 1,048,576-byte file bound, not the 256-entry limit, failed in this controlled reproduction. The historical Windows receipt did not identify its file; the new live receipt records closed size/count/role facts rather than guessing it retrospectively.

The foreign-Store snapshot now covers the immutable consumer’s actual mutation owners: the selected config and atomic/backup siblings, credentials/, and browser/ installation state. It hashes incrementally in 64 KiB chunks, retaining 1 MiB and 256-entry acceptance caps, absence detection, link/type/change refusal, and exact before/after comparisons. Generic CLI database/log/cache bookkeeping is explicitly outside this browser-state claim. The original native whole-state checks, Store/descriptor/generation guards, true refusal calls and cleanup remain intact. No production ownership or deadline change.

27/27 Node checks pass, including mutation/removal/creation, backup, streaming hash, byte/entry overflow, symlink, diagnostic-redaction and frozen-dependency regressions. Current canonical autoreview completed scoped-clean after the stale/index-only fixture-pin findings were fixed. Full build/setup-dev still refuse Linux; required local Shared 140 failed / 4008 passed / 33 skipped and Tray 14 failed / 3146 passed / 2 skipped are not Windows acceptance.

All 9c6 failures remain unwaived: WSL reached the first five cases but failed exact-client selection before a kill; required CI failed Connection migration cleanup and Setup initialization. The new native receipt will be returned first for consumer #160161, while final Windows landing still requires all current gates. No release, real-user installation or main-tree edit.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. P2 Normal priority bug or improvement with limited blast radius. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant