Skip to content

fix(permissions): the Permissions page hides wildcard exec rules - #1506

Merged
shanselman merged 9 commits into
openclaw:mainfrom
SebTardif:fix/f078-wildcard-exec-policy
Sep 27, 2026
Merged

shanselman merged 9 commits into
openclaw:mainfrom
SebTardif:fix/f078-wildcard-exec-policy

Conversation

@SebTardif

@SebTardif SebTardif commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

What Problem This Solves

The Permissions page could hide wildcard exec-approval rules and could activate previously dormant main or wildcard grants when a user added a rule under inherited Deny/Off or Deny/OnMiss.

User Impact

The page now:

  • shows both main and wildcard rules with localized this agent / all agents scope labels;
  • removes a rule from its original policy bucket;
  • keeps inherited Deny authoritative when older dormant rules exist;
  • labels stored rules inactive while Deny remains effective;
  • uses the same Allowlist/OnMiss fallback as the runtime executor when no security value is stored.

Why This Change Was Made

system.run resolves agents["main"], then agents["*"], then defaults, and merges both allowlists. The previous page projected only main rules and its Add transition could change main to Allowlist in a way that activated older merged entries.

The repair preserves the existing storage schema and execution engine. It changes only the editor projection and mutation policy, with source-aware removal and fail-closed Add behavior.

Change Type

  • Bug fix
  • Feature
  • Refactor
  • Docs or instructions
  • Tests or validation
  • Security hardening
  • Chore or infrastructure

Scope

  • Tray or WinUI UX
  • Windows node capability
  • Local MCP or winnode proof
  • Gateway, connection, or pairing
  • Permissions, privacy, or security
  • Tests, CI, or docs

Required proof pools

  • windows-winui-interactive: PASS on current head. The native Permissions page showed Default action: Deny, scoped all agents / this agent rows, distinct accessible Remove names, and inactive status for both stored rules.
  • windows-wsl-mxc: PASS on current head. Strict non-skipping Gateway-to-node MXC validation completed 17/17.

Validation

Current head: 40cc5e61be4c945e63784a72639eebaa50bcad24

  • ./build.ps1: PASS.
  • dotnet test ./tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: 4,107 passed, 32 skipped, 0 failed.
  • dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: 3,141 passed, 0 failed.
  • ./scripts/validate-mxc-e2e.ps1 -NoBuild without -AllowSkip: 17/17 passed.
  • Focused policy/resolver cases cover pre-existing main and wildcard rules under both Deny/Off and Deny/OnMiss, plus the runtime Allowlist/OnMiss fallback.
  • Security-focused rubber-duck review findings were addressed.

Real behavior proof

Native UI

An isolated current-head profile represented the post-Add state under wildcard security=Deny, ask=OnMiss with an older wildcard rule and a newly stored main rule.

The native Permissions page showed:

  • Default action: Deny;
  • **/other.exe (all agents) with status inactive;
  • **/git.exe (this agent) with status inactive;
  • distinct accessible Remove controls for all agents and this agent.

The page was opened through local MCP app.navigate, proving the built current-head app and actual WinUI projection.

Final command I/O

A separate isolated MCP-only profile contained:

  • wildcard: security=Deny, ask=OnMiss, older **/cmd.exe rule;
  • main: no security/ask override, newly stored **/powershell.exe rule.

Two real winnode system.run calls attempted separate marker writes:

  • newly stored main rule: exec-approvals-v2: SecurityDeny (security=deny), exit 1;
  • previously dormant wildcard rule: exec-approvals-v2: SecurityDeny (security=deny), exit 1.

Neither marker file was created. This proves both commands were rejected before command execution while inherited Deny remained authoritative.

Persisted authorization semantics

  • Removing a wildcard entry deletes only that wildcard entry and preserves equivalent main and unrelated-agent entries.
  • Adding under inherited Deny/Off or Deny/OnMiss with any older dormant rule stores the new pattern but leaves main security/ask unset, so resolved policy remains Deny and every row is shown inactive.
  • Adding under inherited Deny/Always retains the existing safe behavior: main becomes Allowlist/Always, so every match still requires a prompt.
  • With no stored security value, the page projects the runtime fallback Allowlist/OnMiss rather than incorrectly showing inactive Deny.

Security Impact

  • New permissions or capabilities? No.
  • Secrets or tokens handling changed? No.
  • Network calls changed? No.
  • Storage schema changed? No.
  • Persisted authorization behavior changed? Yes, intentionally fail-closed for dormant-rule Add transitions and source-aware wildcard removal.

Compatibility and Migration

  • Existing exec-approvals.json files remain compatible.
  • No migration or environment change is required.

Review Conversations

  • Current review findings are addressed.
  • Required proof pools and validation describe the current head.

- Resolve the Permissions default action through main, then *, then defaults
- List wildcard allowlist entries as well as main

Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P1 Urgent regression or broken agent/channel workflow affecting real users now. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 24, 2026
@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 27, 2026, 2:49 PM ET / 18:49 UTC (Revision 15).

ClawSweeper review

What this changes

The Windows tray Permissions page now shows main and wildcard execution rules with their scopes, removes rules from their original scope, and keeps inherited Deny effective when adding a rule could activate older grants.

Merge readiness

✅ Ready for maintainer review

The current head addresses the earlier review findings and has current-head native UI and command-effect proof. The requested behavior is absent from current main, so this PR remains a useful landing candidate.

Priority: P1
Reviewed head: 40cc5e61be4c945e63784a72639eebaa50bcad24

Review scores

Measure Result What it means
Overall readiness 🦞 diamond lobster (5/6) The focused policy repair has strong current-head native and final-command evidence, with no remaining actionable finding.
Proof confidence 🦞 diamond lobster (5/6) Sufficient (terminal): At head 40cc5e6, isolated native WinUI output showed scoped inactive rules, and real local MCP system.run calls for an old wildcard rule and a newly stored main rule both returned SecurityDeny with no marker writes. Real-store regressions verify existing-file behavior; no stored-file schema migration is required.
Patch quality 🦞 diamond lobster (5/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (terminal): At head 40cc5e6, isolated native WinUI output showed scoped inactive rules, and real local MCP system.run calls for an old wildcard rule and a newly stored main rule both returned SecurityDeny with no marker writes. Real-store regressions verify existing-file behavior; no stored-file schema migration is required.
Evidence reviewed 7 items Introduced policy edit: The introduced Add guard leaves main security and ask unset when inherited Deny has older dormant rules; removal selects the rule's original main or wildcard bucket.
Runtime policy contract: The runtime resolves main, wildcard, defaults, then system fallback; it combines wildcard and agent allowlists. Deny is an absolute execution override.
Existing-state regression coverage: Real-store tests reopen a pre-existing policy after Add and verify that Deny remains effective with old and new entries under both Off and OnMiss.
Findings None None.
Security None None.

How this fits together

The Permissions page reads the Windows node's stored execution-approval policy and lets users edit its rules. The execution path resolves that policy before deciding whether a requested command may run.

flowchart LR
  A[Stored exec policy] --> B[Permissions page]
  B --> C[Scoped rule display]
  B --> D[Add or remove rule]
  D --> A
  A --> E[Runtime policy resolver]
  E --> F[Allow, prompt, or deny]
  F --> G[Command execution]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Code growth production +131 lines, tests +367 lines The production growth is tied to scoped policy edits and display, with substantially more regression coverage for persisted authorization behavior.

Technical review

Best possible solution:

Land the scoped editor behavior with its persisted-file regressions and retain the verified rule that inherited Deny prevents command execution before the final side effect.

Do we have a high-confidence way to reproduce the issue?

Yes, from source: current main projects only main rules, while the runtime merges main and wildcard rules. The earlier Add transition also differs from the runtime's inherited policy cascade.

Is this the best way to solve the issue?

Yes. The patch repairs the existing editor projection and mutations without changing the runtime executor or stored-file schema.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against ed0c045cfe60.

Labels

Label changes:

No label changes.

Label justifications:

  • P1: The PR addresses a permissions editor path that could conceal effective rules or activate older execution grants.
  • merge-risk: 🚨 security-boundary: The changed editor writes authorization policy; current-head real-store and command-effect evidence covers the identified grant-escalation cases.
  • rating: 🦞 diamond lobster: Overall readiness is 🦞 diamond lobster; proof is 🦞 diamond lobster and patch quality is 🦞 diamond lobster.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (terminal): At head 40cc5e6, isolated native WinUI output showed scoped inactive rules, and real local MCP system.run calls for an old wildcard rule and a newly stored main rule both returned SecurityDeny with no marker writes. Real-store regressions verify existing-file behavior; no stored-file schema migration is required.
  • proof: sufficient: Contributor real behavior proof is sufficient. At head 40cc5e6, isolated native WinUI output showed scoped inactive rules, and real local MCP system.run calls for an old wildcard rule and a newly stored main rule both returned SecurityDeny with no marker writes. Real-store regressions verify existing-file behavior; no stored-file schema migration is required.

Evidence

What I checked:

Likely related people:

  • karkarl: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • shanselman: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • AlexAlves87: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (14 earlier review cycles; latest 8 shown)
  • reviewed 2026-09-27T16:32:58.839Z sha aae72e4 :: needs real behavior proof before merge. :: [P1] Identify each rule's main or wildcard scope before removal | [P1] Prevent Add from silently activating other wildcard grants
  • reviewed 2026-09-27T16:39:20.269Z sha d7776a1 :: needs real behavior proof before merge. :: [P1] Show each rule's main or wildcard scope before removal | [P1] Keep inherited Deny/Off from activating wildcard grants
  • reviewed 2026-09-27T17:10:29.471Z sha e046a2c :: needs real behavior proof before merge. :: [P1] Keep inherited Deny/OnMiss from activating wildcard grants | [P2] Explain when Add saves an inactive rule
  • reviewed 2026-09-27T17:31:06.213Z sha d00350c :: needs real behavior proof before merge. :: [P1] Keep Deny/OnMiss from activating older wildcard grants | [P2] Explain when a newly saved rule remains inactive
  • reviewed 2026-09-27T17:35:32.334Z sha d00350c :: needs real behavior proof before merge. :: [P1] Keep inherited Deny/OnMiss from activating wildcard grants | [P2] Explain when Add saves an inactive rule
  • reviewed 2026-09-27T18:09:10.852Z sha 5c4bb63 :: needs real behavior proof before merge. :: [P1] Keep older main rules dormant during Add | [P2] Use the executor fallback for inactive labels
  • reviewed 2026-09-27T18:27:27.669Z sha 40cc5e6 :: blocked before merge. :: none
  • reviewed 2026-09-27T18:36:36.282Z sha 40cc5e6 :: needs maintainer review before merge. :: none

@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 24, 2026
Preserve wildcard/main rule provenance through CAS removal and use the displayed policy cascade when adding a main rule. Cover cross-bucket duplicate IDs, ID-less argument variants, concurrent replacement, inherited policy, and fresh-store persistence.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 4e7c9166-338e-44fb-828a-577c05de49b7
@clawsweeper clawsweeper Bot added rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. and removed rating: 🧂 unranked krab Not merge-ready due to missing proof or serious correctness/safety concerns. labels Sep 24, 2026
@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 24, 2026
@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. and removed status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. labels Sep 24, 2026
@karkarl

karkarl commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Global triage: HOLD_FOR_AUTHOR. Take confidence 35%; recommendation confidence 93%; effort medium; risk high.

Reviewed exact head cba7b9b0c9dc. Display and bucket-scoped removal are largely correct, but adding a rule while inheriting wildcard Deny/Always writes main as Allowlist/Off. Because wildcard allowlist entries merge into every agent, this can silently activate dormant wildcard grants and remove prompting. The new wildcard rows also lack visible and accessible source labels, so identical main/wildcard rows can revoke different scopes without distinction.

Owner: SebTardif. Add main/wildcard source cues, cover a non-empty inherited wildcard allowlist, and obtain explicit maintainer approval or preserve prompting for the escalation. Align or document the page-versus-engine fallback difference, make native proof reproducible from the PR, then run strict windows-wsl-mxc; the focused WinUI evidence alone is insufficient.

@shanselman

Copy link
Copy Markdown
Collaborator

Hi @karkarl, Copilot here helping Scott close the native proof gap. Scott confirms this machine does not support BaseContainer (the strict probe selects appcontainer-dacl). If your Windows 11 + WSL2 machine has BaseContainer, could you please run ./scripts/validate-mxc-e2e.ps1 without -AllowSkip in isolated exact-head checkouts, starting with #1506 (fix(permissions): the Permissions page hides wildcard exec rules) at cba7b9b0c9dc and #1499 (fix(chat): in-chat approval card can show a different command than Allow runs) at de0164bfef42? #1477 (fix(mxc): treat cmd /R as a command-mode switch) at a4a9c9398fa1 is next; if time allows, #1476 (fix(setup): keep WSL PATH scripts off the wsl.exe argv path) at 7fa601b4ad9d and #1482 (fix(setup): quote gateway bind, auth mode, and reload mode) at 47e860bb02ea also need native transport/metacharacter proof. No pressure to take all five at once.

For each result, please include the exact SHA, whether BaseContainer was actually selected, non-skipped MXC test counts, and the real WSL Gateway -> Windows node system.run outcome, with credentials, user settings and command content redacted. A skip or DACL fallback should stay a blocker, not a pass. #1506 already has local source/UI/CI proof; #1499 separately still needs approval-card UI/Gateway proof, and #1482 has a red required CI gate, so this request does not authorize a merge or waive those other gates. A quick note if your host cannot run a lane would be useful too. Thanks for helping us keep the boundary fail-closed.

@shanselman

Copy link
Copy Markdown
Collaborator

Maintainer product decision for this original PR, following Karen's exact-head review at cba7b9b0c9dc: when adding a main exec rule under inherited wildcard Deny/Always, retain Ask=Always. Do not silently write main Allowlist/Off. The current transition can activate merged wildcard grants without a prompt, so the repaired display/UI tests and a passing CI Gate are not enough for a >=90% landing. Please add a regression with a non-empty inherited wildcard allowlist, keep main/wildcard source visibly and accessibly distinguishable, and document/reconcile the page versus engine fallback. If source fix is small I can help on this branch. Strict current-head validate-mxc-e2e.ps1 without -AllowSkip on a Windows 11 + WSL2 + BaseContainer host remains mandatory; I have requested help from Karen because this machine selects DACL fallback. Do not merge based on the diagnostic PR #1507 or label proof: sufficient alone: #1507 records Gateway restart state but does not change execution policy or establish MXC containment.

Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
@SebTardif

Copy link
Copy Markdown
Contributor Author

aae72e4 keeps the displayed ask when a main rule is added under inherited Deny. For wildcard Deny/Always that writes main Allowlist with Ask=Always, not Allowlist/Off. The wildcard bucket is unchanged.

Local filter AddRule_FromInheritedWildcardDeny: 1 passed. This does not merge diagnostic #1507.

@clawsweeper clawsweeper Bot added rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. and removed proof: sufficient Contributor real behavior proof is sufficient. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. labels Sep 24, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9ba54a2d-477b-4b8e-994c-5fb3755d8b01
@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 27, 2026
A wildcard row and a main row with the same pattern now show wildcard or main in the list and in the Remove name. Adding a rule while wildcard security is Deny and Ask is Off, and main security is unset, stores the new pattern without switching main to Allowlist. Inherited Deny/Always still enables only the main allowlist and keeps Ask Always.

./build.ps1 exit 0. Shared tests: 4107 passed, 32 skipped. Tray tests: 3133 passed, 0 failed.

Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
@shanselman

Copy link
Copy Markdown
Collaborator

I saw and preserved the concurrent author update e046a2c0 rather than overwriting it. Its inherited Deny/Off behavior is the safer policy requested by review: the added main rule is stored but remains dormant while inherited Deny stays authoritative. I am validating that exact implementation and will only add a small localization/accessibility cleanup if needed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9ba54a2d-477b-4b8e-994c-5fb3755d8b01
@shanselman

Copy link
Copy Markdown
Collaborator

Current head is now d00350c6dfa715e043979037133fbeb9ecbeadf7.

This preserves Seb's concurrent e046a2c0 policy fix: under inherited wildcard Deny/Off, the new main rule is stored but remains dormant because main security/ask stay unset and the resolved policy remains absolute Deny. The follow-up localizes the visible scope labels (this agent / all agents) and accessible Remove names across all supported locales, and adds a real-store regression proving the resolved main policy remains Deny/Off with both dormant entries present.

Validation

  • ./build.ps1: PASS.
  • dotnet test ./tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj --no-restore: PASS, 4,107 passed, 32 skipped, 0 failed.
  • dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj --no-restore: PASS, 3,134 passed, 0 failed.
  • ./scripts/validate-mxc-e2e.ps1 -NoBuild without -AllowSkip: PASS, 17/17 tests, including canonical Gateway-to-node MXC execution and blocked tray-data writes.
  • Focused policy/accessibility/localization tests: PASS.

Current-head visible UI proof is being captured separately now.

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

@shanselman

Copy link
Copy Markdown
Collaborator

Current-head visible UI proof

Validated d00350c6dfa715e043979037133fbeb9ecbeadf7 in an isolated tray profile seeded with identical main and wildcard patterns under inherited wildcard Deny/Off.

  • Local MCP discovery advertised app.navigate.
  • winnode --command app.navigate --params '{"page":"permissions"}' returned { "navigated": true, "page": "permissions" }.
  • The native Permissions page visibly showed Default action: Deny and 2 entries.
  • The identical patterns were distinguishable as:
    • **/git.exe (all agents)
    • **/git.exe (this agent)
  • The accessibility tree exposed distinct controls:
    • Remove all agents allowlist entry **/git.exe
    • Remove this agent allowlist entry **/git.exe

This is current-head native WinUI evidence of the changed state. The real-store regression additionally proves both entries remain present while resolved main policy stays security=Deny, ask=Off, so the new main entry does not activate the dormant wildcard grant.

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9ba54a2d-477b-4b8e-994c-5fb3755d8b01
@shanselman

Copy link
Copy Markdown
Collaborator

Current head 5c4bb63e06315905ad4ef0f59e3c0d0de0620d0c closes the inherited Deny/OnMiss path as well as Deny/Off.

Current-head native UI proof

In an isolated profile representing the post-Add state under wildcard security=Deny, ask=on-miss, with an existing wildcard **/other.exe entry and a newly stored main **/git.exe entry:

  • The native Permissions page visibly showed Default action: Deny.
  • The wildcard row rendered **/other.exe (all agents) with status inactive.
  • The main row rendered **/git.exe (this agent) with status inactive.
  • Accessibility exposed distinct Remove controls for all agents and this agent.
  • Local MCP app.navigate opened the exact current-head Permissions page.

The real-store theory covers both inherited Deny/Off and Deny/OnMiss: main security/ask remain unset, resolved main policy remains security=Deny, both patterns remain stored, and ExecApprovalRulesActive stays false. Inherited Deny/Always remains the explicit safe exception: it becomes main Allowlist/Always, so every match still requires a prompt.

Validation

  • ./build.ps1: PASS.
  • Shared: 4,107 passed, 32 skipped, 0 failed.
  • Tray: 3,136 passed, 0 failed.
  • Strict validate-mxc-e2e.ps1 without -AllowSkip: 17/17 passed.
  • Focused Deny/Off + Deny/OnMiss policy, real-store, UI contract, accessibility, and localization tests: PASS.

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. and removed rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. labels Sep 27, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9ba54a2d-477b-4b8e-994c-5fb3755d8b01
@shanselman

Copy link
Copy Markdown
Collaborator

Current head 40cc5e61be4c945e63784a72639eebaa50bcad24 now includes older main entries in the dormant-grant guard and uses the executor's actual fallback (Allowlist/OnMiss) for UI active/inactive projection.

Final command-I/O proof

Ran the exact head in an isolated MCP-only profile with:

  • wildcard: security=Deny, ask=OnMiss, older rule **/cmd.exe
  • main: no security/ask override, newly stored rule **/powershell.exe

system.execApprovals.get confirmed that persisted policy. Then two real local MCP system.run calls attempted to create separate marker files:

  • Newly stored main rule (powershell.exe): exec-approvals-v2: SecurityDeny (security=deny), exit 1.
  • Previously dormant wildcard rule (cmd.exe): exec-approvals-v2: SecurityDeny (security=deny), exit 1.
  • New-rule marker file: absent.
  • Old-rule marker file: absent.

This proves both commands are rejected before command execution while inherited Deny remains authoritative. The native Permissions UI shows both rows as inactive. Separate tests cover existing dormant entries in either the main or wildcard bucket under both Deny/Off and Deny/OnMiss. A no-security snapshot now displays active Allowlist/OnMiss behavior, matching the runtime resolver rather than assuming Deny.

Validation

  • ./build.ps1: PASS.
  • Shared: 4,107 passed, 32 skipped, 0 failed.
  • Tray: 3,137 passed, 0 failed.
  • Strict validate-mxc-e2e.ps1 without -AllowSkip: 17/17 passed.
  • Final local MCP command-effect proof: PASS, both intended marker writes absent.

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

@shanselman

Copy link
Copy Markdown
Collaborator

Validation count correction for the preceding proof comment: the exact full Tray result is 3,141 passed, 0 failed. All other reported results are unchanged.

@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. labels Sep 27, 2026
@shanselman

Copy link
Copy Markdown
Collaborator

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

@clawsweeper clawsweeper Bot added rating: 🦞 diamond lobster Very strong PR readiness with only minor maintainer review expected. and removed rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. labels Sep 27, 2026
@shanselman

Copy link
Copy Markdown
Collaborator

@clawsweeper re-review

@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

@shanselman
shanselman merged commit cf3626a into openclaw:main Sep 27, 2026
29 checks passed
@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 27, 2026
@SebTardif
SebTardif deleted the fix/f078-wildcard-exec-policy branch September 28, 2026 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. P1 Urgent regression or broken agent/channel workflow affecting real users now. proof: sufficient Contributor real behavior proof is sufficient. rating: 🦞 diamond lobster Very strong PR readiness with only minor maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants