Repository navigation
[P0][Bug]: Native Store Gateway onboarding requires manual clawctl setup before the wizard can continue #1672
Description
Activity
- addedP0Emergency: data loss, security bypass, crash loop, or unusable core runtime.Emergency: data loss, security bypass, crash loop, or unusable core runtime.clawsweeper:needs-live-reproClawSweeper needs live local, crabbox, or manual validation to confirm this issue.ClawSweeper needs live local, crabbox, or manual validation to confirm this issue.clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.ClawSweeper marked this issue as needing maintainer review before automation.clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.ClawSweeper does not recommend queueing a new automated fix PR for this issue.impact:ux-release-blockerA non-technical user is blocked without terminal, logs, config, or support.A non-technical user is blocked without terminal, logs, config, or support.issue-rating: 🐚 platinum hermitGood issue quality with a plausible reproduction path needing some confirmation.Good issue quality with a plausible reproduction path needing some confirmation.
on Oct 7, 2026 Codex review: this still needs some work. Reviewed October 7, 2026, 10:01 PM ET / October 8, 2026, 02:01 UTC.
Summary
Keep open: the Store onboarding failure is documented, and the related merged packaging repair explicitly leaves this original incident unresolved.Reproducibility: no. the original failure occurred once, its failing JSON was lost, and the reporter’s clean same-version and missing-helper retests passed. A related controlled contention case was reproduced and repaired, but current-main reproduction of the original incident is not established.
Next step
Continue the retained-state investigation with redacted pre-repair package JSON; the accepted bounded repair leaves no confirmed, narrow Companion defect for automatic implementation.Review details
Best possible solution:
Preserve contract and credential checks, verify the original retained-state case with the packaging repair, and provide an inline Retry or Fix action for any remaining supported-package readiness failure.
Do we have a high-confidence way to reproduce the issue?
No: the original failure occurred once, its failing JSON was lost, and the reporter’s clean same-version and missing-helper retests passed. A related controlled contention case was reproduced and repaired, but current-main reproduction of the original incident is not established.
Is this the best way to solve the issue?
Unclear for the original incident: the package-owned error-envelope repair is appropriate for the demonstrated contention case, while changing Companion’s admission ordering without the original response would risk weakening established checks.
AGENTS.md: found and applied where relevant.
Remaining risk / open question:
- The original pre-repair status JSON and retained-session trigger remain unknown; the merged contention repair does not establish resolution on the reported Store versions.
Codex review notes: model internal, reasoning medium; reviewed against 037c17dcb581.
Label changes
Label changes:
- add
clawsweeper:no-new-fix-pr: Current issue advisory state selects this label. - add
clawsweeper:needs-maintainer-review: Current issue advisory state selects this label.
Label justifications:
P0: The documented Store onboarding block required an external terminal command before a first useful run.impact:ux-release-blocker: Retry setup did not provide recovery until the user manually ran clawctl setup outside the wizard.
Evidence reviewed
What I checked:
- Current onboarding ordering: CreateDraftAsync detects the package contract before creating a draft; PrepareAsync repeats detection before automatic package preparation. This confirms the reported investigation boundary, but does not establish what the original status response contained. (
src/OpenClaw.SetupEngine/NativeGatewaySetupService.cs:79, 037c17dcb581) - Capability and readiness remain separate: DetectAsync accepts the versioned integration metadata independently of command success. SetupAsync subsequently requires success and a ready isolated session; configuration reads independently validate returned credentials. Removing contract admission is therefore not a justified repair. (
src/OpenClaw.Connection/NativeGateway/NativeGatewayPackageClient.cs:55, 037c17dcb581) - Automatic setup already exists: The production setup host invokes the package client’s setup command for the isolated integration; the client runs package-qualified setup --json. (
src/OpenClaw.SetupEngine.UI/NativeGatewaySetupHost.cs:85, 037c17dcb581) - Observed failure and successful retest: Inspected all four prepared screenshots: the original wizard shows profile preparation blocked by the unsupported-contract message; later images show Your AI is ready and connected Chat returning 56. The reporter’s clean same-version retest and controlled missing-helper test both completed automatically, so missing helper staging alone is not a confirmed explanation. The original failing JSON was not retained.
- Merged bounded repair and explicit incident disposition: fix: preserve isolated capability in clawctl error responses openclaw-windows-packaging#164 (fix: preserve isolated capability in clawctl error responses) merged at 2026-10-08T01:52:45Z as cadb7e860d24d8398892e8255119bdbeb6c2a813. Its full body records real before/after lifecycle-contention onboarding evidence, but expressly distinguishes that case from the original Store incident. The MEMBER-authored comment fix: preserve isolated capability in clawctl error responses openclaw-windows-packaging#164 (comment) records the accepted decision: accept the bounded reproduction and keep the original incident open. Dependency relevance is affirmative: Companion consumes this package’s status JSON before setup. (cadb7e860d24)
- Area history and inspection limitation: File history connects isolated onboarding to merged fix: Companion cannot onboard with an isolated Gateway #1553 and subsequent runtime recovery to fix: Companion fails to reconnect after isolated session replacement #1649. The exact-string history hunt and blame could not complete because historical blob 1742f23a36ea9ff3a49ab8e875c81941c56b4b2e is unavailable in the partial checkout; attempted retrieval returned HTTP 403. Current files and commit metadata were readable, but source-line introduction is unverified. (
src/OpenClaw.Connection/NativeGateway/NativeGatewayPackageClient.cs, 5abfabb38e12)
Likely related people:
- paulcam206: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
- RomneyDa: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
How this review workflow works
- ClawSweeper keeps one durable marker-backed review comment per issue or PR.
- Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
- A fresh review can be triggered by eligible
@clawsweeper re-reviewcomments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch. - PR/issue authors and users with repository write access can comment
@clawsweeper re-reviewor@clawsweeper re-runon an open PR or issue to request a fresh review only. - Maintainers can also comment
@clawsweeper reviewto request a fresh review only. - Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
- Maintainer-only repair and merge flows require explicit commands such as
@clawsweeper autofix,@clawsweeper automerge,@clawsweeper fix ci, or@clawsweeper address review. - Maintainers can comment
@clawsweeper explainto ask for more context, or@clawsweeper stopto stop active automation.
Clean Store retest
Could not reproduce the original failure with a clean Store install. This is a diagnostic data point; it does not establish the original cause or a fix.
Retested on Windows 11 Enterprise Insider Preview ARM64, build 28120.3151, using the same Store versions: Companion 2026.9.520.0 and Gateway 2026.9.701.0. This was native Gateway mode, not WSL.
- Used supported Gateway teardown, backed up the prior Companion profile and managed Local AI files, removed both packages, and verified zero OpenClaw Appx registrations. Reinstalled Companion from Store and let its wizard install Gateway from Store. Existing WSL distributions were preserved; this was clean app/Gateway state on an existing OS.
- Native support, package verification, profile preparation and Gateway startup all passed automatically. No external
clawctl setupcommand was needed. - Separately stopped the new test Gateway, renamed its helper directory to preserve it, and restarted onboarding with another fresh Companion profile. The resulting helper-not-staged status already included
integration.kind = isolated-sessionandversion = 1. The unmodified Store wizard automatically restaged the helper and continued. This controlled case did not reproduce the contract error and does not support missing helper staging alone as its explanation. - Local AI setup passed. After the app restarted, Qwen 3.6 correctly answered 56 for 7 × 8, together with a new test nonce. Chat showed Owner Connected. The app, native Gateway and Local AI are running.
No fix PR is being submitted because a same-issue fix is not yet confirmed. The original failure and successful manual workaround remain recorded above. Its first failing JSON response was not retained, so the actual root cause remains unconfirmed.
Clean Local AI wizard completion:
Working Chat after restart:
I will leave this issue open for now since I am not sure if it has been fixed or if it is just not reproducible
- addedstatus: 🚢 actively landingA maintainer or agent is actively driving this item through implementation, validation, or merge.A maintainer or agent is actively driving this item through implementation, validation, or merge.
on Oct 7, 2026 - addedissue-rating: 🦪 silver shellfishThin issue quality; more reproduction proof or environment detail is needed.Thin issue quality; more reproduction proof or environment detail is needed.and removedissue-rating: 🐚 platinum hermitGood issue quality with a plausible reproduction path needing some confirmation.Good issue quality with a plausible reproduction path needing some confirmation.clawsweeper:needs-live-reproClawSweeper needs live local, crabbox, or manual validation to confirm this issue.ClawSweeper needs live local, crabbox, or manual validation to confirm this issue.
on Oct 7, 2026 - removedstatus: 🚢 actively landingA maintainer or agent is actively driving this item through implementation, validation, or merge.A maintainer or agent is actively driving this item through implementation, validation, or merge.
on Oct 7, 2026 - removedclawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.ClawSweeper does not recommend queueing a new automated fix PR for this issue.clawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.ClawSweeper marked this issue as needing maintainer review before automation.
on Oct 7, 2026 - addedstatus: 🚢 actively landingA maintainer or agent is actively driving this item through implementation, validation, or merge.A maintainer or agent is actively driving this item through implementation, validation, or merge.and removedstatus: 🚢 actively landingA maintainer or agent is actively driving this item through implementation, validation, or merge.A maintainer or agent is actively driving this item through implementation, validation, or merge.
on Oct 7, 2026 🦞
⚠️
Automatic implementation stopped before completion.
Reason: The automatic implementation worker stopped before all deterministic gates completed. Open the workflow run for the exact blocker.
Worker: https://github.com/openclaw/clawsweeper/actions/runs/37714655762- removedstatus: 🚢 actively landingA maintainer or agent is actively driving this item through implementation, validation, or merge.A maintainer or agent is actively driving this item through implementation, validation, or merge.
on Oct 8, 2026 - addedclawsweeper:needs-maintainer-reviewClawSweeper marked this issue as needing maintainer review before automation.ClawSweeper marked this issue as needing maintainer review before automation.clawsweeper:no-new-fix-prClawSweeper does not recommend queueing a new automated fix PR for this issue.ClawSweeper does not recommend queueing a new automated fix PR for this issue.
on Oct 8, 2026
Metadata
Metadata
Assignees
Labels
Type
Fields
Priority
Projects
- StatusShow more project fieldsBacklog


Bug
Requested priority: P0. Native Store onboarding blocks users until they run an external repair command.
Microsoft Store Companion native Gateway onboarding stops at Prepare your Gateway profile with an unsupported isolated-session contract error. Running the installed Store Gateway's
clawctl setup --jsonmanually, then clicking Retry setup, allows the wizard to continue using the same installed package versions.The wizard should prepare the supported Gateway automatically. A user should not need to leave onboarding and run a terminal command.
Reproduction
Observed once on October 7, 2026:
9NFPR3BGDRR5, and launch with a fresh Companion profile.9NV70LV3D6XC.This was an existing development machine with a fresh Companion profile. Gateway/session state was not deliberately reset before the test. A factory-clean machine and a current-main build have not been tested for this failure.
Expected behavior
The wizard initializes or safely repairs the supported native Gateway and continues without a manual
clawctl setupinvocation. If preparation cannot proceed, it surfaces the actual readiness problem with an actionable recovery path.Actual behavior
The wizard displays:
The installed Gateway CLI, invoked in the signed-in Windows user's interactive session, reported that the isolated-session helper had not been staged for this package version and directed the user to run
clawctl setupagain.Environment
OpenClawFoundation.OpenClaw,2026.9.520.0, ARM64OpenClawFoundation.OpenClawGateway,2026.9.701.0, ARM64SignatureKind=Store,Status=Ok616.00Companion package family:
OpenClawFoundation.OpenClaw_rfcbke2p71se2.Gateway package family:
OpenClawFoundation.OpenClawGateway_rfcbke2p71se2.The wizard's native device-support check passed on this Windows build. The observed failure occurred later during Gateway profile preparation, and the workaround succeeded without a Windows update.
No source build, developer MSIX replacement, or WSL fallback was used for the successful run.
Workaround and observed recovery
Ran the installed Store Gateway's package-qualified alias with
setup --jsonin the signed-in user's interactive Windows session. Equivalent PowerShell:The command reported success, a ready isolated session, and integration
isolated-sessionversion 1. Clicking Retry setup then allowed native onboarding to continue. Neither MSIX was updated between failure and recovery.Completed Local AI installation through the wizard. It reached Your AI is ready with verified model
llamacpp/qwen3.6-35b-a3b-mtp-ud-iq4-xs. After the setup-driven app restart, Chat showed Owner Connected, and Qwen 3.6 correctly answered 56 for 7 × 8. The app, native Gateway, and Local AI were left running.Evidence
Original wizard failure:
Wizard success after the manual command and retry:
Working local Chat after setup and restart:
These are original screenshots from the observed run. A terminal screenshot of the repair command was not captured; the workaround above records the command that was invoked. The first failing package JSON response was not retained.
Investigation lead
The inspected source checks the package contract before preparing the package:
NativeGatewaySetupService.CreateDraftAsynccalls contract detection before a draft is created.NativeGatewaySetupService.PrepareAsyncalso detects the contract beforePreparePackageAsync.NativeGatewaySetupHost.PreparePackageAsynccontains the automaticclawctl setup --jsoncall.This ordering is consistent with an initialization/readiness failure stopping onboarding before automatic setup can repair it. It is an investigation lead, not a confirmed root cause. Regression coverage should include an installed supported package whose helper needs staging, and should preserve the existing credential-handoff checks.
Related merged work: #1553 (fix: Companion cannot onboard with an isolated Gateway), openclaw/openclaw-windows-packaging#134 (fix: Companion cannot configure an isolated Gateway), and #1649 (fix: Companion fails to reconnect after isolated session replacement). None was confirmed as an exact duplicate of this first-run failure.