Conversation
Enable the analyzers that ship with the pinned .NET SDK and add a root .editorconfig that defines formatting, naming, and IDE style explicitly. Every rule reports as a warning at this layer so the diagnostic backlog is visible without blocking the build. Add scripts/Test-DotNetQuality.ps1 as the single quality entry point shared by local development, CI, and the future pre-push hook, and invoke it from the Windows test job. Add CONTRIBUTING.md and a pull request template, which the repository previously lacked. GenerateDocumentationFile is required for build-time IDE0005, so CS1591 is suppressed rather than satisfied with low-value XML comments. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11
Apply the outstanding whitespace and style fixes, then promote the IDE style and naming rules from warning to error so CI rejects future drift. The code changes are behavior preserving: indentation in ProgramTests, two collection expressions, and the diagnostic log's lock object moving from `object` to `System.Threading.Lock`. The lock field is only ever used in `lock` statements, so the new type introduces no Monitor-based behavior change. Also refine the style policy so it only enforces rules that add value. `var` versus explicit type, throw expressions, conditional expressions over guard clauses, and IDE0058 discards are left to the author, because forcing them produced worse code in this codebase rather than better. Test-DotNetQuality.ps1 now also verifies whitespace and style. It remains check-only and never rewrites source, including in CI. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11
* improve: harden native library loading All ten P/Invokes in the launcher target kernel32.dll. Without an explicit search path the loader also probes the application and current directories, so a planted kernel32.dll next to openclaw.exe could be loaded instead of the system one. Restrict DLL resolution to System32 for the whole assembly. Also stop marshalling the CreateProcessW command line through a StringBuilder. CreateProcessW may write to that buffer, so it now receives an explicitly null-terminated char array sized from the built command line. The buffer is never read back. Promote CA5392 and CA1838 to errors now that both are clear, and add a regression test that launches a real child process with an argument containing spaces and embedded quotes to prove the command line still arrives intact. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11 * fix: keep child command text free of fixture paths The real-child argument test interpolated the fixture output path into a single-quoted PowerShell literal. A temporary root containing an apostrophe (for example C:\Users\O'Connor) terminated that literal early and turned the remaining path into PowerShell syntax, so the test failed for a reason unrelated to argument marshalling. Pass the output path to the child as environment data and keep the command text fixed. The spaced and embedded-quote payload still travels on the command line, so the marshalling assertion is unchanged, and the case is now covered for both a plain fixture subdirectory and one containing spaces and an apostrophe. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11 --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11
Narrow the launcher's implementation types to internal and make every string comparison in the test suite explicit and culture-independent, then promote the contract and globalization analyzer families to errors. Internalizing the seven implementation-only types removes the ambiguity about what this executable's supported surface is. Because these types are no longer externally visible, the six CA1062 public-argument-validation findings disappear without adding guard clauses that would have become dead weight. The test project keeps full access through the existing InternalsVisibleTo entry. The CA1307 findings were all Assert.Contains calls matching literal English fragments of diagnostic and exception messages. StringComparison.Ordinal is the semantically correct choice: these assertions want exact, invariant substring matching, not culture-sensitive collation. CA1062, CA1307, CA1308, and CA1515 are now errors. CA1308 and CA1062 have zero findings and act as forward guards. CA1515 is disabled for the test project because xUnit 2.x only discovers public test classes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11
Make every await in the launcher explicit about continuation scheduling and replace the remaining synchronous calls inside async methods, then promote the async analyzer family to errors. The launcher is a console executable with no SynchronizationContext, so ConfigureAwait(false) is a no-op at runtime today. It is applied anyway because the rule protects future code: if this assembly is ever consumed from a context-capturing host, or a UI-hosted setup surface is added, the absence of an explicit choice becomes a deadlock risk rather than a style question. Making the intent explicit at every await costs nothing now and removes an entire defect class later. CA1849 flagged two genuine synchronous calls on async paths: the clawctl --version write to the output TextWriter, and File.ReadAllText in the interop argument-delivery test. Both now use their asynchronous overloads, and the test threads its existing timeout token through the read so a hung file operation fails the test rather than hanging the run. CA2007 does not apply to the test project; the SDK excludes it automatically for projects that reference a test framework, so no ConfigureAwait noise is added to test code. Validated on this branch: static analysis gate clean, 53 tests pass, and win-x64 NativeAOT publish succeeds with no IL, trim, or AOT warnings. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11
Give every disposable in the test suite an explicit scope, document the one deliberate broad catch, sharpen a private return type, and promote the remaining lifetime and design analyzer families to errors. After this change the branch builds with zero warnings. The three CA2000 findings were StringWriter instances in tests that were never disposed. They are now scoped with using declarations. This is small but real: undisposed writers accumulate across a run and mask genuine ownership mistakes in the same files later. CA1031 flagged the last-chance catch in Main. That catch is correct and deliberate. Every other catch in this assembly already uses an exception filter to name the failures it expects; Main is the process boundary, and narrowing it would trade a logged diagnostic, a readable error message, and a deterministic exit code 1 for an unhandled-exception crash. The rule is suppressed at that single method with that rationale rather than repository wide, so any new broad catch elsewhere still fails the build. CA1859 flagged FindPathCandidates returning IReadOnlyList<string> from a private helper that always produces a List<string>. The interface added no contract value across a private call and cost an interface dispatch on the PATH scan; the concrete type is now returned directly. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11
* chore: enforce the complete .NET quality gate Turn on TreatWarningsAsErrors now that the branch builds warning-free, and add an opt-in pre-push hook so contributors can get the CI answer before pushing. The per-rule error entries the earlier layers added only cover diagnostics somebody has already looked at. The gap they leave is everything nobody has classified yet: a new compiler warning, a new analyzer from an SDK bump, a rule that changes default severity. Those arrive as warnings and get scrolled past. TreatWarningsAsErrors turns each one into a decision at the moment it appears. The explicit .editorconfig severities stay as readable policy history. NuGet audit advisories are excluded from the gate. NU1901 through NU1904 report published vulnerabilities, so one can appear against a dependency graph nobody touched and break main with no committed change and no fix available inside the failing build. They remain visible as warnings and are triaged as security work rather than treated as build breaks. The hook is deliberately small and deliberately opt in. hooks/pre-push is tracked, carries a marker identifying it as repository-owned, and runs only Test-DotNetQuality.ps1, so it cannot drift from what CI does. Install-GitHooks.ps1 copies it into the current clone and -Remove deletes it. Neither direction touches global Git configuration or core.hooksPath; installation stops if core.hooksPath is set rather than writing a hook Git would silently ignore, refuses to overwrite a pre-push hook it did not write, and removal only deletes a hook carrying the marker. Both are idempotent. The hook is a latency shortcut, not a policy boundary. It is local to one clone and `git push --no-verify` skips it; required CI checks remain authoritative. That is stated in the hook, the installer, and CONTRIBUTING so nobody mistakes it for enforcement. Test-GitHooks.Tests.ps1 covers install, repeated install, removal, repeated removal, unmanaged-hook conflict in both directions, and the core.hooksPath refusal. The pass and fail cases are end to end: they build a throwaway repository with a local bare remote and a stub quality script, then perform a real git push, proving Git invokes the hook and that its exit code decides whether the push lands. Nothing runs against this clone. CI runs the suite alongside the existing policy suites. Validated on this branch: quality gate clean, 53 tests pass, all three PowerShell suites pass, win-x64 NativeAOT publish succeeds with no IL, trim, or AOT warnings, and an injected #warning fails the build as CS1030. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11 * fix: install the pre-push hook where Git looks for it The installer composed its destination from git rev-parse --absolute-git-dir plus 'hooks'. In a linked worktree that is the worktree's private directory, which Git never consults for hooks, so installation reported success and no push ever ran the quality gate. Ask Git for the hooks directory instead, with rev-parse --git-path hooks, and use that answer for both installation and removal. A clone has one hooks directory shared by all of its worktrees, so say so in the installer output and in CONTRIBUTING. The hook suite now runs every existing case against both an ordinary clone and a linked worktree. In the worktree layout the two work trees carry opposite stub exit codes, so the real pushes prove Git ran the pushing worktree's quality script. Two further cases cover the shared destination and clone-wide removal. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11 --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 331d9f1d-2f78-491c-8347-19969cb5ce11
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7cb16ef4-e347-4342-a67e-385a8721db1c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7cb16ef4-e347-4342-a67e-385a8721db1c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a35bc4fd-e612-4be2-8166-7c100e8cf3ef
The signing script previously skipped both architecture directories when the artifact root was not CI-shaped, then reported success after creating and discarding a certificate. Validate the expected architecture directories before creating signing material so a no-op cannot look like a signed result. Add a regression test that runs the script against an empty artifact root and verifies the failure message, non-zero exit, absence of output, and absence of a newly created publisher certificate. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
…openclaw#29) * Parse clawctl arguments with System.CommandLine Replace the hand-written clawctl parser and help renderer with a declarative System.CommandLine tree. The `openclaw` entrypoint is unchanged and still forwards its argument vector to the OpenClaw CLI without parsing it. - Add ClawCtlCommandLine: a root command plus a `setup` subcommand, with Node prerequisite and install guidance in the command descriptions so help is generated from one source instead of hand-formatted. - Delete ClawCtlCommand and its enum/parse-result/exact-token matcher rather than leaving a second dispatch model beside the library. - Rewrite Program.RunControlAsync around the tree. Disable the library's default exception handler so operational failures keep reaching the host's diagnostic boundary, and leave ProcessTerminationTimeout null so it does not compete with the Node job object for process lifetime. The setup action's cancellation token now flows into the Node resolver. - Replace the `Action<string> writeError` seam with an injected TextWriter and drop the direct Console.Error write from the control dispatcher. - Report the launcher assembly version through a custom version action. The built-in one reports the entry assembly, which under a test or scenario host is not the launcher. - Disable response-file expansion. A leading `@` is an unrecognized argument for clawctl and stays uninterpreted through `openclaw`. Completion is kept. Invalid management input now exits 1, the library's parse-error code, instead of the previous 2. Add Test-NativeAotCli.Tests.ps1 and run it in CI. The xUnit suite runs under a JIT test host, so it cannot observe the root command name that System.CommandLine derives from native argv[0], and a successful AOT publish is not execution evidence. The script publishes win-x64 NativeAOT into a temporary directory it owns, runs the binary as clawctl.exe, and removes it afterwards. Node-dependent scenarios stay in xUnit with an injected runtime so the gate does not depend on the agent's installed Node version. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 79e90679-15f4-4fd5-a669-d70d363a9c34 * Cover the completion directive and version precedence The only completion test used the in-process GetCompletions API, which no shell can reach. Cover the `[suggest]` directive through the real control dispatcher instead, since that is the path a completion client actually calls. Also record that `--version` now wins over trailing arguments. The old parser rejected the combination; the library's version action clears parse errors, so `clawctl --version bogus` prints the version and exits 0. That is stock System.CommandLine behavior, not a local choice, but it is a visible change to this CLI's contract and was previously untested. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 79e90679-15f4-4fd5-a669-d70d363a9c34 * fix: exit the NativeAOT clawctl gate with its own status The gate's final assertion runs clawctl with an argument that must be rejected, so $LASTEXITCODE is 1 when the script ends. GitHub Actions exits a pwsh step with that value, so the step failed even though every assertion passed. The job printed "NativeAOT clawctl checks completed successfully." immediately before reporting exit code 1. Exit 0 explicitly after cleanup. Assertion failures throw and never reach that line, so the gate still fails when it should: verified by injecting a pattern that cannot match, which exits 1 with the offending output. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 79e90679-15f4-4fd5-a669-d70d363a9c34 * Isolate the NativeAOT command-line gate from the user profile The native gate published the production launcher and ran its `Main`. `Main` creates the diagnostic log through `HostDiagnosticLog.Create()`, which resolves `%LOCALAPPDATA%\OpenClawGatewayMSIX` rather than anything relative to the publish directory, so every gate run appended startup and exit records to the developer's real log. Publishing into a temporary directory did not redirect that, and green CI never revealed it. Extract the startup path into `Program.RunAsync(args, HostStartup)` and leave `Main` as the production adapter that supplies the real collaborators. `HostStartup` carries the entrypoint, the diagnostic factory, the base directory, the writers, and the existing Node and launch seams, so startup can be driven with fixture-owned storage. Replace the gate's subject with a NativeAOT scenario driver in `tests/OpenClaw.Launcher.AotSmoke`. It runs the same `RunAsync` under the `clawctl.exe` name with an explicit temporary log path, in-memory writers, and delegates that cannot start a real process, so native coverage still includes startup logging and the error boundary. The script now also runs the driver under a wrong executable name and requires a nonzero exit, so the alias check cannot pass vacuously. Add JIT regressions for the same seam: diagnostics routed to a test path, a handled operational failure reporting that path and exiting 1, a failed diagnostic factory warning once and continuing, and `openclaw` forwarding arguments verbatim while returning the child's exit code. A read-only before/after observation of the normal unpackaged log across a full gate run showed an unchanged length, timestamp, and SHA-256. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 79e90679-15f4-4fd5-a669-d70d363a9c34 * Keep the NativeAOT scenario fixtures out of %TEMP% CodeQL treats `Path.GetTempPath()` as a user-controlled source, because `TMP` is an environment variable a caller controls. The scenario driver is a plain console executable rather than a test-framework project, so it is not classified as test code, and its fixture roots flowed into `HostOptions.Parse` and the driver's own file writes as eight new high-severity `cs/path-injection` alerts on the pull request. Build the fixture roots under `AppContext.BaseDirectory` instead. The gate script already publishes into a directory it owns and deletes, so the scenarios stay isolated without reading an environment variable, and the alerts have no source. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 79e90679-15f4-4fd5-a669-d70d363a9c34 --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 79e90679-15f4-4fd5-a669-d70d363a9c34
Carry the upstream toolchain version through payload metadata and MSIX composition. Validate bundled executables without launching staged images, repair invalid caches under a cross-session installation lock, reclaim interrupted staging, and expose bundled tools only to the child PATH. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Preserve the System.CommandLine startup and NativeAOT gates while routing setup to bundled-runtime preparation and keeping openclaw arguments transparent. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
* chore(ci): finalize Artifact Signing setup * docs: name the dedicated packaging signer * docs: use the MSIX signing identity name * fix(ci): recurse into signing artifact folders
* feat(ci): publish durable signed MSIX releases * feat(ci): publish multi-architecture MSIX bundle * fix(ci): authorize exact MSIX bundle contents * fix(ci): use explicit zero-version signing proof
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: roboclaw-bot <309084314+roboclaw-bot@users.noreply.github.com> Co-authored-by: hannesrudolph <49103247+hannesrudolph@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
feat: bundle Node.js runtime in the Gateway MSIX
…-identity fix: release dashboard rejects matching packaged gateway
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Attach runtime and payload matrices, clipboard checks, regression results, and authenticated Control UI screenshots. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Consume the host's semantic widget theme in the sandboxed Gateway Isolation tab while retaining system-theme fallbacks for older Control UI builds. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a3d515fe-cd93-465c-8bae-6686c73c1320
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: a3d515fe-cd93-465c-8bae-6686c73c1320
Preserve reusable payload caches while provisioning the Windows Launcher plugin only in the output copy. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…cher-plugin Add themed Windows Launcher status plugin
* feat(ci): derive Store-safe MSIX release versions * fix(ci): use readable MSIX release versions * fix(ci): accept full MSIX patch range * fix(ci): reserve MSIX rebuild slots per gateway correction * fix(ci): reserve thousand-wide MSIX release slots * docs: explain Gateway MSIX versioning policy * test: prove proof-release upgrade compatibility * test(ci): prove proof-release bundle upgrades * fix(ci): normalize empty package queries * fix(ci): trust test signing cert machine-wide * chore(release): advance Gateway baseline to 2026.9.4 * test(signing): keep payload mismatch fixture invalid * fix(payload): allow disabled plugin migration entries
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
* Define MXC lifecycle contracts and wire serialization Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Consume MXC contracts through the CLI transport and readiness probe Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Add the pinned MXC runtime acquisition and trust inputs Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Fix deterministic MXC executor cancellation test Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
) * Define attached session launch protocol Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Build attached session guest helper Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
* Add durable session ownership and setup state Add synchronization and package-derived writable paths for owned sessions. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Add session coordination and routing policy Provision or reuse owned sessions through the MXC abstraction and route required executions safely. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Add staged session helper execution Dispatch correlated argument vectors through the packaged guest helper with safe cleanup and runtime composition. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Install the agent runtime through the guest Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Activate public session setup and transparent routing Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Fix isolated session lifecycle boundaries Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Persist the agent Node runtime directory Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Reject a sandbox issued to another application Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Refuse invalid isolated session state Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Update lifecycle launch test seam Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
…enclaw#47) * Add the isolated agent PowerShell shell Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Install agent command tools inside the session Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Include session host job support Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Avoid duplicating launcher job support Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Scope shared job support to the session host Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
…aw#48) * Add detached session supervision Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Observe and stop owned guest processes Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Define gateway lifecycle contracts Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Add gateway session adapter and controller Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Add manual gateway-service controls Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Harden gateway session launch behavior Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Fix confirmed teardown regression Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Point gateway startup guidance to its status command Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Restore the unconfirmed teardown regression Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Preserve gateway session exit diagnostics Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
* Define gateway recovery task scheduling Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Add gateway recovery reconciliation Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Activate gateway sign-in recovery after setup Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Bind gateway recovery to the package executable Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Preserve unowned gateway recovery scripts Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Clean up cancelled gateway scheduler processes Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Detect missing scheduled tasks without localized text Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Inject recovery into the successful-setup fixture Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Fix gateway logon recovery Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
* Add guest diagnostic collection plumbing Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Handle deferred guest diagnostic enumeration failures Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Constrain guest diagnostics staging paths Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
* Add redacted diagnostics bundle command Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Complete setup and recover stale sessions Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Reconcile gateway lifecycle after session replacement Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Use the agent runtime across the session lifecycle Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Validate session support before session-free setup Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Allow teardown after an unconfirmed gateway launch Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Bind agent diagnostic reads to opened files Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Avoid an unnecessary gateway request state machine Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Persist superseded session reconciliation Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Preserve configured gateway working directories Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * fix: recover session lifecycle safely Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Use the interactive user for gateway recovery Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Stabilize collection reparse test paths Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Update startup launch test seam Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
* Add fresh setup reset Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Add forced fresh setup recovery Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Resolve lifecycle stack integration Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Gate setup on session support Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Keep ordinary setup cancellation guidance non-destructive Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Document session-free setup requirements Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Reject redirected installation state ancestors Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Install agent command tools inside the session Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Persist superseded session reconciliation Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Detect missing scheduled tasks without localized text Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Fix session reset and gateway failure output Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Harden installation state cleanup Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Keep session fixtures isolated Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Resolve session lifecycle integration Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Preserve host runtime startup Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Read the gateway log from the session workspace Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Update fresh reset launch test seams Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
* Document isolated session runtime Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * docs: correct session runtime behavior Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Clarify host and session runtime operations Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc * Separate host and session setup guidance Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc --------- Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Remove the setup and environment opt-outs for session containment, delete the direct host launch path, and require both clawctl setup and openclaw to fail loudly when isolated sessions are unsupported. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 7e811db2-bbae-462e-a61f-ee0373b945c5
clawctl described the machine rather than the person using it: passive wording, package paths and sandbox identifiers in ordinary output, and inconsistent severity words. Each command also built its own presentation strings, so alignment came from per-command width constants and severity vocabulary drifted between commands. Commands now return semantic results and a single renderer owns presentation. - Add ClawCtlResults, so operations describe what happened and the renderer decides how it reads. - Compose output from Spectre.Console renderables. A Grid derives the label column from the widest label, which removes the per-command widths, and a Panel renders the note callout for an unexpected fault. - Colour is an event, not a wash: labels stay in the terminal's own foreground and only the leading state word carries a hue. This follows openclaw's styleHealthChannelLine, which colours the state word of a "label: detail" row and leaves the label alone. - Add ClawCtlColorPolicy for --no-color, NO_COLOR, FORCE_COLOR, CI, and redirected output, and enable virtual terminal processing only when the selected stream is really an interactive console, so FORCE_COLOR still produces ANSI when output is redirected. - Report gateway and sign-in recovery state in clawctl status, alongside the Node.js version recorded at setup. - Keep a successful clawctl pwsh silent so the user reaches the shell prompt. - Persist the pre-reset report and include it in collect-logs, instead of printing a log path the user has to find. Values are built with Paragraph.Append rather than interpolated into markup, because package paths and error messages contain characters Spectre would otherwise parse as markup. Verified with the managed suite, static analysis, and the NativeAOT scenario driver, which now renders through Spectre ahead of time. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: f472f437-3ee7-41f3-a501-81ae01590103
Remove unsupported isolation commands and copy controls. Show Running and Active only with the captured enabled report, and report all other isolation signals as invalid with HTTP 503. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep isolation reports informational, replace unsupported controls with verified general command references, and cover sandbox clipboard fallback and accessible feedback. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the agent shell and Gateway chat UI distinct, preserve copy-only behavior, and fit all seven references without clipping. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the stable signing policy separate and reject incompatible official workflow inputs before building. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use a native ARM64 runner, reject incompatible inspection hosts before staging, and isolate the plugin snapshot cache for every CLI probe. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Problem This Solves
Windows Launcher presents isolation as a configurable mode even though the packaged Gateway requires an isolated session.
User Impact
Operators get one truthful Gateway Isolation: Active report and a copy-only command reference, not isolation controls. Missing, malformed, and unsupported reports show neutral Invalid status. The plugin remains opt-in.
Why This Change Was Made
44e9347d3342cd8b5e27fec78df40b8dff0dca34for development theme support without changing the official stable approval. Added early signing-policy checks, architecture-matched Windows/Node validation, a native ARM64 workflow runner, and isolated inspection caches.Dependency: Installed native-addon execution uses the separate, still-draft/unmerged openclaw#75 at
a6a849b970be1d3f2a16f1514dfc08dc845b4db5. Its implementation is not included in this PR.Evidence
1b2ea924f7789b9578b59d0dea129b9ec2dc7f1a:node --test .\plugins\gateway-isolation\index.test.jspassed all 52 tests;Test-GatewayIsolationPlugin.Tests.ps1passed. Exact final heading/text browser fixtures passed four themes, missing/malformed/unsupported reports, authentication, no-reload behavior, and mouse/keyboard/manual-copy checks.9b67a25770f1945698e83e0decfcfdd6d8356772: combined authored99597e7, canonical maina99bb66, the pinned PR75 fix, and the same development runtime. Passed 714 managed tests, 17 NativeAOT scenarios, payload qualification, MSIX composition, and test signing. The precursor integration61df2bdalso passed the static-analysis quality gate and 13 packaging/policy PowerShell suites.clawctl pwshopened PowerShell 7.6.6. Authenticated Control UI passed four live themes without iframe reload, 14 exact mouse/keyboard copies, and an explicitly simulated clipboard-denial/manual-copy case. Supported cleanup was verified.The reviewed screenshots are native 2880 × 2240 captures. Final-heading component previews and genuine installed integration evidence are kept distinct.