Skip to content

fix(setup): retry guarded restart intent contention - #1507

Merged
shanselman merged 6 commits into
mainfrom
shanselman-gateway-restart-fixture-diagnostics
Sep 28, 2026
Merged

shanselman merged 6 commits into
mainfrom
shanselman-gateway-restart-fixture-diagnostics

Conversation

@shanselman

@shanselman shanselman commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

For #1498, this PR adds a fixture-only, pre-rollback diagnostic for guarded post-wizard Gateway restart failures. The allowlisted artifact records coarse selected user-service state, PID liveness/equality, restart count, and bounded service result/exit facts without writing raw PIDs, paths, process arguments, config, environment, credentials, or raw command output.

The diagnostic identified a distinct hosted failure: the Gateway CLI refused restart-intent recording because another OpenClaw process owned state-lifecycle. The setup engine recognizes only the combination of the typed coordinator-contention marker and the exact restart-intent refusal. It waits 500 ms, re-verifies expected managed endpoint provenance, and retries the same guarded openclaw gateway restart command exactly once.

The #1515 serving-owner recovery remains intact. Persistent contention, unrelated restart failures, and unknown or conflicting listeners still fail closed. There is no direct systemctl restart, ownership bypass, lock deletion, or relaxed Gateway CLI admission.

The remaining ClawSweeper security finding is fixed. The fixture now redirects Bash stderr before opening the racy /proc/<pid>/stat input, so a disappearing process cannot leak a raw proc path into setup command logs or uploaded artifacts.

Required proof pools

  • windows-wsl-gateway-e2e: setup, pairing, post-wizard restart, revocation recovery, and network recovery cross the real WSL Gateway boundary.
  • windows-wsl-mxc: strict real Gateway to Windows node system.run containment proof is required by repository policy for setup/connect changes.

Validation

Current head: f6fab60a5cc7049981b7df1cbe99348fa162179b.

  • $env:OPENCLAW_REPO_ROOT=(Get-Location).Path; .\build.ps1: passed. All five projects and documentation validation succeeded.
  • dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore: 4,115 passed, 32 skipped, 0 failed.
  • dotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --no-restore: 3,154 passed, 0 failed.
  • dotnet test .\tests\OpenClaw.SetupEngine.Tests\OpenClaw.SetupEngine.Tests.csproj --no-restore: 1,206 passed, 1 skipped, 0 failed. Coverage includes exact two-marker classification, one successful guarded retry, repeated-failure boundedness, and rejection of unknown/conflicting listeners.
  • dotnet test .\tests\OpenClaw.E2ETests\OpenClaw.E2ETests.csproj --no-restore --filter FullyQualifiedName~GatewayRestartFailureDiagnosticTests: 12 passed, 0 failed.
  • .\scripts\validate-mxc-e2e.ps1 with process-only TEMP/TMP set to a task-owned D:\ directory: 17 passed, 0 failed. Strict proof did not use -AllowSkip.
  • .\scripts\Invoke-CiE2e.ps1 -Name revocation-recovery -Filter FullyQualifiedName~OpenClaw.E2ETests.Setup.RevocationAndRecoveryTests: 1 passed, 0 failed.
  • .\scripts\Invoke-CiE2e.ps1 -Name network-recovery -Filter FullyQualifiedName~OpenClaw.E2ETests.Setup.NetworkRecoveryTests: 2 passed, 0 failed.
  • Canonical setup/connect test FullSetup_TrayConnects_OperatorAndNode: 1 passed, 0 failed. The narrowed wrapper then intentionally returned nonzero because its filter omitted the separate required MXC sentinel; strict MXC passed independently above.
  • Full local setup-connect shard: Not verified / blocked as a complete shard. Its setup pipeline completed and exercised the serving-owner refusal, managed provenance recheck, one guarded retry, and successful Gateway health. Later tests lost the disposable fixture distro and cascaded connection failures on this workstation.
  • Current-head hosted CI run 36469295686: passed, including Setup and connect E2E, Revocation recovery E2E, Network recovery E2E, Tray/setup/integration, security checks, and CI Gate.
  • Rubber-duck review: accepted the Bash redirection-order finding and fixed it. Other comments were non-blocking scope suggestions.
  • python .agents\skills\autoreview\scripts\autoreview --mode branch --base origin/main ...: clean, no accepted/actionable findings, overall confidence 0.96.

Real behavior proof

  • Security boundary: an empirical WSL Bash probe against a nonexistent proc path using read -r stat 2>/dev/null < /proc/999999999/stat returned stdout suppressed, empty stderr, and exit code 0. The regression test requires this redirection order and rejects the prior unsafe order.
  • Guarded Gateway boundary: local and hosted real setup received the serving-owner restart refusal, rechecked managed endpoint provenance, invoked the original guarded Gateway CLI restart once, received Restarted systemd service: openclaw-gateway.service, reached HTTP 200, and completed the wizard step successfully. No direct systemd fallback was used by setup.
  • Exact typed-contention policy: the exact two-marker typed contention is timing-dependent and did not recur in the current-head hosted artifacts. Deterministic focused coverage proves that only both exact markers admit the 500 ms delay and one guarded retry; either marker alone, persistent failure, unrelated errors, and unknown/conflicting listeners remain terminal. Earlier hosted failure traces established the real Gateway 2026.9.6 message shape that this classifier matches.
  • Strict MXC: real Gateway system.run executed through the Windows node MXC sandbox, tray-data writes were blocked, and the mirrored WSL-safe Gateway port was listening and recorded. All 17 strict tests passed.
  • Recovery lanes: current-head hosted Setup and connect E2E, Revocation recovery E2E, and Network recovery E2E all passed. Local real WSL revocation recovery passed 1/1 and network recovery passed 2/2.

The task-owned D:\ validation temp directory was removed after all disposable distros were unregistered. No secret-bearing settings or gateway artifacts are attached.

@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 24, 2026
@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 24, 2026
@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed September 28, 2026, 3:06 PM ET / 19:06 UTC (Revision 9).

ClawSweeper review

What this changes

The setup engine adds one guarded Gateway CLI restart retry after exact coordinator contention, while the disposable WSL test fixture records bounded service diagnostics before rollback.

Regression provenance

Possible regression — suspected (failure trace). No predecessor PR is attributed.

Merge readiness

⛔ Blocked before merge - 5 items remain

Current main still lacks recovery for the typed restart-intent contention that blocks WSL setup. The earlier proc-path logging finding is fixed, but the prior approval of a guarded retry explicitly excluded typed contention. This branch still needs approval for that expanded boundary and a real setup result showing the new retry path.

Priority: P0
Reviewed head: f6fab60a5cc7049981b7df1cbe99348fa162179b
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🦐 gold shrimp (3/6) The bounded implementation and validation have useful signal, while exact-path runtime proof and approval of the expanded restart boundary remain open.
Proof confidence 🦐 gold shrimp (3/6) Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.
Patch quality 🦐 gold shrimp (3/6) Security review found an item that needs attention.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.
Evidence reviewed 10 items Introduced production retry: The pinned merge-base-to-head diff adds the typed contention classifier, a 500 ms delay, managed-endpoint recheck, and one repeat of the existing guarded CLI restart.
Current main remains distinct: Fetched main retries the serving-owner refusal but has no typed coordinator-contention classifier or retry.
Prior merged recovery: Merged #1515 added the serving-owner recovery and identified coordinator contention as separate remaining work.
Findings None None.
Security Needs attention Approve the expanded guarded-retry boundary: Typed coordinator contention previously remained terminal under the accepted retry policy. This PR permits a second guarded attempt for that case; the CLI guard remains in place, but acceptance of this additional attempt is unresolved.

How this fits together

Windows setup completes the Gateway wizard inside an app-owned WSL distro, restores its reload setting, and asks the Gateway CLI to restart the service. Endpoint checks and Gateway health determine whether setup continues or rolls back.

flowchart LR
  A[Wizard completes] --> B[Restore reload setting]
  B --> C[Gateway CLI restart]
  C --> D{Classified refusal?}
  D -->|Yes| E[Check managed endpoint]
  E --> F[One guarded CLI retry]
  D -->|No| G[Health or rollback]
  F --> G
Loading

Decision needed

Question Recommendation
Should setup make one additional guarded Gateway CLI restart attempt after the exact typed coordinator-contention and restart-intent refusal, given that approval of the earlier retry excluded this case? Approve the bounded retry after proof: Accept this exact classifier and one guarded retry after a current-head real setup trace shows the typed failure, recheck, retry, and outcome.

Why: The new attempt stays behind the CLI guard, but accepting an additional restart after admission contention is a security-boundary policy choice that the earlier decision did not cover.

Before merge

  • Resolve security concern: Approve the expanded guarded-retry boundary - Typed coordinator contention previously remained terminal under the accepted retry policy. This PR permits a second guarded attempt for that case; the CLI guard remains in place, but acceptance of this additional attempt is unresolved.
  • Resolve merge risk (P1) - The earlier approval of a guarded restart retry expressly excluded typed coordinator contention. This expanded retry boundary needs an explicit maintainer decision.
  • Resolve merge risk (P1) - Current-head real setup evidence exercises the existing serving-owner retry, while the new typed-contention recovery is demonstrated only by focused tests. A real Gateway setup result for that exact path remains unverified.
  • Complete next step (P2) - Obtain explicit approval for retrying typed contention and current-head real Gateway setup evidence for that exact retry path before merge.
  • Resolve maintainer decision - Resolve the maintainer decision shown above before merge.

Findings

  • [medium] Approve the expanded guarded-retry boundary — src/OpenClaw.SetupEngine/SetupWizardRunner.cs:624
Agent review details

Security

Needs attention: The retry still uses the guarded CLI and the proc-path logging fix is present, but the newly retried admission case needs an explicit boundary decision.

Review metrics

Metric Value Why it matters
Production and test LOC production +67, tests +473, docs +20 Most growth is disposable fixture diagnostics and focused coverage; production growth adds the bounded retry and observer.

Root-cause cluster

Relationship: fixed_by_candidate
Canonical: #1498
Summary: This PR targets the remaining typed contention in the canonical setup failure; the merged serving-owner retry addressed a distinct refusal.

Members:

Proposal only: this assessment does not dispatch repair, suppress jobs, mutate sibling items, close, or merge anything.

Merge-risk options

Maintainer options:

  1. Prove and approve this refusal case (recommended)
    Capture the typed-contention path through the real guarded CLI on this head, then record explicit approval of the expanded retry boundary.
  2. Pause the retry change
    Retain fail-closed contention behavior until an upstream Gateway recovery contract is available.

Technical review

Best possible solution:

Keep the Gateway CLI as the final restart authority and provide an in-product Fix or retry path with redacted diagnostics when contention persists.

Do we have a high-confidence way to reproduce the issue?

Yes. Hosted setup on main with Gateway 2026.9.6 recorded the exact typed contention and restart-intent refusal, and current main still lacks this recovery branch.

Is this the best way to solve the issue?

Unclear. Repeating the same guarded CLI once is a narrow local repair, but its exact real-world recovery and expanded boundary have not yet been established.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against 5e0b31ab830a.

Labels

Label changes:

  • add status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.

Label justifications:

  • P0: Gateway 2026.9.6 can halt first-run WSL setup after the wizard, leaving local onboarding incomplete.
  • merge-risk: 🚨 security-boundary: The PR permits one more service-restart attempt after an admission failure, a boundary the earlier acceptance did not cover.
  • rating: 🦐 gold shrimp: Overall readiness is 🦐 gold shrimp; proof is 🦐 gold shrimp and patch quality is 🦐 gold shrimp.
  • status: ⏳ waiting on author: ClawSweeper has contributor-facing work open and is waiting for author action. Not applicable: Real behavior proof is not required for maintainer- or bot-authored pull requests.

Evidence

Security concerns:

  • [medium] Approve the expanded guarded-retry boundary — src/OpenClaw.SetupEngine/SetupWizardRunner.cs:624
    Typed coordinator contention previously remained terminal under the accepted retry policy. This PR permits a second guarded attempt for that case; the CLI guard remains in place, but acceptance of this additional attempt is unresolved.
    Confidence: 0.9

What I checked:

Likely related people:

  • karkarl: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • shanselman: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • SebTardif: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Add a redacted current-head Gateway 2026.9.6 setup trace showing the typed refusal, managed-endpoint recheck, one guarded retry, and observed setup outcome.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (8 earlier review cycles)
  • reviewed 2026-09-24T11:32:16.329Z sha 9c74443 :: blocked before merge. :: none
  • reviewed 2026-09-24T11:54:37.169Z sha 9c74443 :: blocked before merge. :: none
  • reviewed 2026-09-25T06:08:11.444Z sha 60bc21e :: blocked before merge. :: none
  • reviewed 2026-09-25T23:01:22.755Z sha a2ce88e :: blocked before merge. :: [P2] Suppress proc-read errors before logging diagnostics
  • reviewed 2026-09-25T23:23:20.615Z sha a2ce88e :: blocked before merge. :: [P2] Suppress proc-read errors before logging diagnostics
  • reviewed 2026-09-25T23:49:33.318Z sha c99d2d0 :: blocked before merge. :: [P2] Suppress failed proc reads before logging diagnostics
  • reviewed 2026-09-26T01:11:02.036Z sha c99d2d0 :: blocked before merge. :: [P2] Suppress failed proc reads before logging diagnostics
  • reviewed 2026-09-28T17:58:52.991Z sha c99d2d0 :: blocked before merge. :: [P2] Suppress failed proc reads before logging diagnostics

@shanselman

Copy link
Copy Markdown
Collaborator Author

CI run 35993290413 on official Gateway 2026.9.6 produced three pre-rollback allowlisted diagnostics. Setup/connect job 107612506610 recorded typed coordinator_contention; revocation 107612506607 and network 107612506669 recorded distinct generic serving_owner_unverified without typed contention. All three recorded ownerPredicate=not_exposed_by_gateway_cli, probe=ok, scope=user, unitEqual=true, active=active, sub=running, pidPresent=true, pidLive=true, pidEqual=true (systemd MainPID vs ExecMainPID), processStartAvailable=true, serviceStartAvailable=true, restartCount=1. These coarse facts do not establish Gateway's owner-lease predicate or a common root cause.

Every fixture retained fail-closed cleanup: setup journal pipeline_failed=1, rollback_ok=19; subsequent uninstall journal rollback_ok=34, uninstall_completed=1. No retry, ownership bypass, or fixture preservation. New diagnostic JSON contained only expected allowlisted keys; existing raw artifact contents are not linked here. Tray/setup/integration CI passed, but all three setup-dependent E2E jobs and the CI gate are red as expected. Do not merge this diagnostic PR as a compatibility fix.

Review: rubber-duck found no blocking issues. Structured python .agents\skills\autoreview\scripts\autoreview --mode branch --base origin/main --codex-bin <isolated CLI> exited 0 with no accepted/actionable findings. Local full build and required Shared/Tray tests passed (4104 passed/35 skipped; 3072 passed); full SetupEngine tests passed (1195 passed/1 skipped); focused E2E diagnostic tests passed 8. Local read-only WSL probe smoke exited 0, but is not an owned-fixture reproduction.

@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 24, 2026
@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. and removed rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. labels Sep 24, 2026
@karkarl

karkarl commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Global triage: NEEDS_HUMAN_TEST. Take confidence 80%; recommendation confidence 92%; effort small; risk low.

Reviewed exact head 9c7444328615. The diagnostic hook is fixture-only, runs immediately before rollback, preserves the original failure when it throws, uses stdin for the WSL script, and emits only allowlisted coarse fields. Current-head CI logs show the diagnostic firing against the pre-existing #1498 Gateway restart failure, so the feature itself is proven. The remaining gates are artifact inspection and targeted MXC disposition, not source defects.

Owner: maintainer. Inspect the three gateway-restart-diagnostic.json artifacts and cleanup journals from run 35993290413, record strict validate-mxc-e2e.ps1 results or a named host blocker, and explicitly decide whether diagnostic-only work may land while #1498 keeps setup E2E red. Do not treat this PR as the fix for #1498.

@shanselman

Copy link
Copy Markdown
Collaborator Author

Current-head local behavior proof (reviewed head 9c744432): on Windows 11 ARM64 with a newly installed task-owned WSL2 distro and official Gateway 2026.9.6, the unchanged setup path finished the wizard then reproduced the generic guarded restart refusal. The fixture-only observer fired before rollback and emitted only its expected allowlist: serving_owner_unverified, owner predicate not_exposed_by_gateway_cli, selected user unit equal, service activating/auto-restart, no MainPID/liveness, process start unavailable, service start available, restart count 0. This shows the selected service was not live in this local run. It does not expose the actual Gateway owner lease or explain the different hosted generic refusals with active/running service/PID, and does not fix #1498.

Setup and uninstall completed their owned cleanup (19 and 34 rollback_ok entries respectively); no task distro remains registered and its isolated profile was removed. The one filtered E2E failed, as expected for the existing Gateway 2026.9.6 restart behavior. CI Gate remains red; this PR should not be merged by treating its useful diagnostic output as a passing setup check. No raw fixture artifact is posted.

@shanselman

Copy link
Copy Markdown
Collaborator Author

Exact-head hosted closeout for #1507 at 60bc21e5, CI run 36101139179, official Gateway 2026.9.6. I inspected only the fixed pre-rollback diagnostic line in each completed job, validated 17 expected keys, zero missing/unexpected in every result, and checked the job logs for owned uninstall and teardown:

Job Refusal Selected service at capture Bounded exit fields Cleanup
Setup/connect serving_owner_unverified user unit equal, active/running, live/equal PID, restart count 1 Result=success, ExecMainCode=0, ExecMainStatus=0 uninstall and teardown observed
Revocation serving_owner_unverified same coarse active/running live-PID state success / 0 / 0 uninstall and teardown observed
Network recovery typed coordinator_contention same coarse active/running live-PID state success / 0 / 0 uninstall and teardown observed

This contrasts with the separate task-owned local generic refusal where the selected unit was activating/auto-restart, had no live PID, and its previous process exited 0. Neither observation reveals the upstream owner-lease predicate or a common cause. The hosted Tray/setup/integration job passed; all three Gateway E2E jobs and required CI Gate failed on the pre-existing restart issue. The diagnostic runs and its fixed allowlist are validated; Gateway compatibility and strict current-head MXC proof are not claimed. This host selects DACL fallback rather than BaseContainer. No raw CI artifact, credentials, PID or process command line is attached, and I am not requesting a CI waiver or merge of this diagnostic-only PR.

@shanselman

Copy link
Copy Markdown
Collaborator Author

Public main 7d92747, Build and Test run 36162008650, verifies #1515 (fix(setup): retry guarded restart after reload owner handoff) as a partial Gateway 2026.9.6 fix: Revocation recovery passed 1/1 and Network recovery passed 2/2, each after exactly one classified guarded serving-owner retry. Setup/connect still failed (17 passed, 23 failed, 6 skipped) with separate typed StateDatabaseCoordinatorContentionError / restart-intent-recording refusal and zero guarded-owner retry warnings. Its setup rollback and owned uninstall completed. No single root cause is inferred.

#1498 (Gateway 2026.9.6 blocks WSL setup at guarded post-wizard restart) and this diagnostic PR remain open; this diagnostic is not a compatibility fix and should not be merged to claim closure. The exact-main run already covered all three lanes. No rerun or raw artifact disclosure is needed.

@karkarl karkarl added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 25, 2026
shanselman and others added 2 commits September 25, 2026 15:49
…back

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1533edb3-7b37-405a-9829-959466a93b54
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. label Sep 25, 2026
@karkarl
karkarl force-pushed the shanselman-gateway-restart-fixture-diagnostics branch from 60bc21e to a2ce88e Compare September 25, 2026 22:56
@karkarl karkarl removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 25, 2026
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. and removed rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 25, 2026
@karkarl karkarl added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 25, 2026
@clawsweeper clawsweeper Bot added the merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. label Sep 25, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 504f71d1-79b6-4d69-abd3-cbb098ca9e0b
@karkarl karkarl changed the title test(setup): capture guarded restart state before fixture rollback fix(setup): retry guarded restart intent contention Sep 25, 2026
@clawsweeper clawsweeper Bot added P0 Emergency: data loss, security bypass, crash loop, or unusable core runtime. and removed P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. proof: sufficient Contributor real behavior proof is sufficient. labels Sep 25, 2026
@karkarl karkarl removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 26, 2026
@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 28, 2026
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1cae2b28-e7ec-42b3-96d8-cddf8565243e
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 1cae2b28-e7ec-42b3-96d8-cddf8565243e
@shanselman shanselman removed the status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. label Sep 28, 2026
@shanselman

Copy link
Copy Markdown
Collaborator Author

@clawsweeper re-reviewnnThe P2 proc-path log leak is fixed at f6fab60: stderr is redirected before the racy proc input open. Regression tests, empirical WSL stderr proof, full required suites, strict MXC 17/17, revocation 1/1, network 2/2, canonical setup/connect 1/1, rubber-duck, and clean autoreview are recorded in the PR body.

@clawsweeper

clawsweeper Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper assist is taking a look at your question.

I queued a lightweight read-only assist pass. It will post a separate answer comment and will not edit the durable ClawSweeper review comment or trigger close, merge, repair, label, or branch changes.

Request: re-reviewnnThe P2 proc-path log leak is fixed at f6fab60: stderr is redirected before the racy proc input open. Regression tests, empirical WSL stderr proof, full required suites, strict MXC 17/17, revocation 1/1, network 2/2, canonical setup/connect 1/1, rubber-duck, and clean autoreview are recorded in the PR body.

@clawsweeper clawsweeper Bot added the status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. label Sep 28, 2026
@shanselman

Copy link
Copy Markdown
Collaborator Author

@clawsweeper re-review

Maintainer decision: approve the expanded bounded retry for the exact typed coordinator-contention plus restart-intent refusal.

The accepted boundary is narrow: both exact markers are required, setup waits 500 ms, managed endpoint provenance must pass, and the same guarded Gateway CLI restart is attempted once. Persistent contention, either marker alone, unrelated failures, and unknown/conflicting listeners remain terminal. There is no direct systemd fallback, ownership bypass, or lock deletion.

The timing-dependent typed contention did not recur in current-head hosted artifacts, so I am explicitly accepting deterministic exact-path tests plus current-head real Gateway boundary proof, strict MXC 17/17, all three hosted WSL lanes, security checks, clean autoreview, and the resolved proc-path finding as sufficient release evidence. ClawSweeper is advisory rather than final merge authority; no actionable code finding remains.

@clawsweeper

clawsweeper Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

🦞👀
Exact review queued.

Re-review progress:

@shanselman
shanselman merged commit 60e978c into main Sep 28, 2026
27 checks passed
@shanselman
shanselman deleted the shanselman-gateway-restart-fixture-diagnostics branch September 28, 2026 19:18
@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. P0 Emergency: data loss, security bypass, crash loop, or unusable core runtime. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants