Skip to content

Enable Companion App to use session backed OpenClaw #1236

Description

@msft-yiyang

Enable Companion App to use session-backed OpenClaw

1. Detect MXC / Session containment capability

  • Detect Windows/OS capabilities and whether Session containment is available
  • Select the appropriate setup path based on capability detection

2. Native Windows + MXC installer and setup experience

  • Make the native Windows Gateway the primary local setup path
  • Update the PowerShell installer/setup engine for MXC (powershell -c "irm https://openclaw.ai/install.ps1 | iex")
  • Setup wizard UI changes for capability/prerequisite checks
  • Gateway acquisition flow
  • Session setup flow
  • Re-entrancy and recovery handling
  • Choose between creating a local Gateway or connecting to an existing one

3. Migrate existing WSL Gateway to local Windows Gateway

  • Supported migration path from existing WSL-based Gateway to native Windows/MXC Gateway
  • Migration UX and rollback support
  • Aligns with golden-path goal: new local Gateway setup, existing Gateway connection, and migration to local Windows Gateway

4. Gateway lifecycle + management UI

  • User-facing UI for managing a locally installed Gateway
  • Detect and apply Gateway updates
  • Recovery and removal flows
  • Entry point for migrating to a local Gateway
  • Successfully update Gateway through an Update button

5. Run local Gateway inside an MXC Session

  • Start and maintain the local Gateway as a long-running workload inside a Session
  • Lifecycle, restart, and recovery behavior
  • Gateway runs in a Session while tool calls receive additional process containment

6. MXC process containment for Gateway tool calls

  • Integrate the MXC sandbox/plugin with OpenClaw's tool-call path
  • Individual tool invocations receive process containment and applicable policy before execution
  • Wrap each tool call with MXC process and associated OpenClaw plugin toolhook

Activity

  1. added
    clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.
    clawsweeper:needs-product-decisionClawSweeper marked this issue as needing a product or behavior decision.
    clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.
    P3Low-risk cleanup, docs, polish, ergonomics, or speculative feature.
    on Aug 26, 2026
  2. clawsweeper commented on Aug 26, 2026

    @clawsweeper

    Codex review: this still needs some work. Reviewed October 3, 2026, 8:20 AM ET / 12:20 UTC.

    Summary
    Keep open: native onboarding and isolated-session integration now exist, but supported WSL migration and complete native Gateway management remain unfinished. No single related item covers the remaining umbrella scope.

    Likely related people: karkarl and Paul Campbell for native setup/runtime integration; samanthamsong for the requested product scope.

    Reproducibility: not applicable. this is a multi-capability feature request, and source inspection confirms both implemented native integration and unfinished management surfaces.

    Root-cause cluster
    Relationship: canonical
    Canonical: #1236
    Summary: This remains the umbrella for several explicitly linked capabilities; narrower issues and merged PRs cover only parts.

    Members:

    Proposal only: this assessment does not dispatch repair, suppress jobs, mutate sibling items, close, or merge anything.

    Maintainer decision needed

    Question Recommendation
    Should this umbrella remain open until WSL migration, native update/recovery controls, and Gateway-wide tool containment are delivered, or should its acceptance scope be narrowed to the implemented native onboarding? Retain explicit remaining acceptance criteria: Keep the umbrella open, mark implemented onboarding/session ownership complete, and assign migration, management, and containment deliverables to focused owners.

    Why: The central integration has landed, but the original checklist and collaborator expansion include distinct unfinished capabilities whose acceptance boundary cannot be chosen from source alone.

    Next step
    Refresh the umbrella checklist against merged work and settle the remaining cross-repository migration and containment scope before commissioning focused implementation.

    Review details

    Best possible solution:

    Finish guided migration and native management through package-owned lifecycle APIs, with visible repair controls and separately defined Gateway tool-containment guarantees.

    Do we have a high-confidence way to reproduce the issue?

    Not applicable: this is a multi-capability feature request, and source inspection confirms both implemented native integration and unfinished management surfaces.

    Is this the best way to solve the issue?

    Partly: the package-owned isolated runtime is the maintainable foundation, but treating new native setup as WSL migration or universal tool containment would overstate what it implements.

    AGENTS.md: found and applied where relevant.

    Remaining risk / open question:

    • WSL-to-native migration still needs explicit data-preservation, credential-transfer, rollback, and recovery acceptance criteria.
    • Per-node system.run containment does not establish the requested containment policy for every Gateway tool invocation.

    Codex review notes: model internal, reasoning medium; reviewed against a6c5fb276f9f.

    Label changes

    Label changes:

    No label changes.

    Label justifications:

    • P2: This is an unfinished native setup and migration program; the report itself establishes no current emergency or blocked first-run reproduction.
    • impact:other: The request affects local Gateway hosting, installation ownership, migration, and lifecycle management.
    Evidence reviewed

    What I checked:

    Likely related people:

    • Karen: Raw commit dba8121 adds src/OpenClaw.SetupEngine/NativeGatewaySetupEligibility.cs:16 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: dba81213371c; files: src/OpenClaw.SetupEngine/NativeGatewaySetupEligibility.cs)
    • Paul Campbell: Raw commit 5abfabb adds src/OpenClaw.Connection/NativeGateway/NativeGatewayPackageClient.cs:11 relative to its recorded parents. This identifies author metadata, not feature responsibility or a PR merger. (role: source-line author; confidence: high; commits: 5abfabb38e12; files: src/OpenClaw.Connection/NativeGateway/NativeGatewayPackageClient.cs)
    • samanthamsong: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
    How this review workflow works
    • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
    • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
    • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
    • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
    • Maintainers can also comment @clawsweeper review to request a fresh review only.
    • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
    • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
    • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.
  3. samanthamsong commented on Sep 2, 2026

    @samanthamsong
    Collaborator

    @msft-yiyang We also want a skill so that the node understands that its gateway is running in a session.

    • any UI thats for updating or migrating to the gateway
  4. added
    P0Emergency: data loss, security bypass, crash loop, or unusable core runtime.
    and removed
    P3Low-risk cleanup, docs, polish, ergonomics, or speculative feature.
    on Sep 4, 2026
  5. added this to the 9/30 MXC Release milestone on Sep 4, 2026
  6. added
    P2Normal priority bug or improvement with limited blast radius.
    impact:otherThis issue has meaningful maintainer-visible impact outside the owned taxonomy.
    and removed
    P0Emergency: data loss, security bypass, crash loop, or unusable core runtime.
    on Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

P2Normal priority bug or improvement with limited blast radius.clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.clawsweeper:needs-product-decisionClawSweeper marked this issue as needing a product or behavior decision.clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.impact:otherThis issue has meaningful maintainer-visible impact outside the owned taxonomy.issue-rating: 🌊 off-meta tidepoolIssue quality rating does not apply to this item.

Type

No type

Fields

Priority

None yet

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions