Skip to content

fix(connection): a cached wslrelay proof allows a token after the listener changes - #1510

Open
SebTardif wants to merge 3 commits into
openclaw:mainfrom
SebTardif:fix/f106-recheck-wslrelay-listener
Open

SebTardif wants to merge 3 commits into
openclaw:mainfrom
SebTardif:fix/f106-recheck-wslrelay-listener

Conversation

@SebTardif

@SebTardif SebTardif commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

What Problem This Solves

Fixes: a shared or bootstrap token can be sent to a new process that binds the gateway port while the wslrelay guest probe is running.

User Impact

User impact: a cached wslrelay proof is accepted only when the same Windows listener is still there after the guest probe.

Why This Change Was Made

The relayless path already calls ListenerSnapshotStillCurrent after the guest probe. The cached wslrelay path now does the same. If the listener changed, the strong credential is refused.

Evidence

October 1 current-head disposition: NEEDS_HUMAN_TEST for two narrow service/request observations. Published-head CI is GREEN, not CI-blocked. No blocking production or current-main integration defect was found. The new real canonical-relay traces below materially advance the proof: they report healthy acceptance through the changed cached production authority, unlike the older Connect observation. They remain authorization/stand-in evidence, not a demonstrated enabled-auth request receipt or a causal successful-probe/final-snapshot denial. No new screenshot, GUI/native click, protocol rewrite, or repeat local relayless fixture is requested.

Published author head: 74b1895a2571de9dccc2f22739317a4ab485dff4, tree 5015565e512d075a3fabdf32530e74dddf9865a8. The author normally merged main in 30f82803, then made the code-identical CI retrigger 74b1895a. Run 36892821510 passes required CI Gate, Core/CLI, Tray/setup/integration, and all three E2E lanes. No submitted reviews or inline threads were present. Earlier red checks do not apply to this head.

Current-main candidate: main 28df9c599b88889f70dee6640885e47cdaeafee8; unpublished local normal integration 811c900835897578a3543ddc55140ceffc95d94d, tree dd5705c8ad6ff1d991bbe76ea2f00566e62c582b. Earlier contributor d14be088 and unpublished 7757ae8e remain in history; no reset, stash, force-push, or supersession was used. Against current main the PR remains exactly two files, +39/-1. The Connection/provenance/verifier/authorizer/resolver and relevant App/dashboard sources are identical between published 74b1895a and this candidate. The seven main-only Local AI cache files from the independent cache work do not alter this authority seam.

ManagedLocalGatewayPortProvenanceService remains the WSL owner. InteractiveGatewayEndpointAuthorizer delegates non-native records to its cached gate, preserving native fail-closed checks; the interactive resolver withholds rejected credentials before downstream request construction. HTTP shared-token preference and WebSocket device-first preference are unchanged. The patch repeats the complete PID/start-time/path/address snapshot after a successful guest probe. It does not claim atomic socket binding or elimination of post-return TOCTOU.

October 1 identical frozen dual review and adjudication

One new bounded delta/integration review used actual claude-opus-5.5 (high) and gpt-6-astra (high, long_context), with an identical frozen prompt at candidate 811c9008. No nested, fallback, or duplicate panel ran. Both found no blocking production defect and credited the new healthy cached authority positive.

Both models agree: HIGH consensus

Issue Opus 5.5 GPT-6 Astra Fix Confidence
Swap trace does not report successful completion of the actual guest probe, so False could occur before the new final comparison MEDIUM, proof-only MEDIUM, proof-only 99% for observation-only evidence closure
Healthy cached authorization now deserves credit; old Connect-only gap is superseded Credit Credit N/A
Current published-head CI is green; old-head red checks are historical Cleared Cleared N/A

Only one model flagged: LOW consensus

Issue Opus 5.5 GPT-6 Astra Fix Confidence
Healthy and swapped runs need correlation to the same managed record/strong credential classification LOW, proof completeness Implicitly credited under stated path 95% for copied input/phase metadata

Both note that no actual healthy request receipt or armed denied-producer completion was shown. They differ on whether authenticated downstream effects are additionally required for this source seam. Maintainer adjudication follows the explicit current request: prove the same dummy-token producer's positive receipt and its denied completion, without demanding GUI/native proof. This is validation, not an accepted production bug. The declared temporary MainPID listener must remain classified as a stand-in; MainPID match alone is not real Gateway authentication.

Source ordering means a probe belonging to the cached gate starts after its initial snapshot. A correlated probe-start observation therefore advances timing evidence; an extra initial-capture timestamp is not intrinsically required if correlation is established. However, the actual guest method can return false on nonzero exit, timeout, startup failure, or exception; that old short circuit also denies without the added final capture. Current copied output does not exclude it. Retained harness/source/build identity or copied observer phase and producer-receipt data can establish causality. No fake verifier success, invented listener identity, or new trust contract is acceptable.

Earlier full original-head review used actual Opus 5/Codex; September 30 integration review used Opus 5.5/Astra. Their attribution and historical findings remain separate, not relabeled as new-head results. Optional architecture wording/dual-stack coverage suggestions remain nonblocking and were not converted into source changes to make reviewers green.

Change Type

  • Bug fix
  • Feature
  • Refactor
  • Docs or instructions
  • Tests or validation
  • Security hardening
  • Chore or infrastructure

Scope

  • Tray or WinUI UX
  • Windows node capability
  • Local MCP or winnode
  • Gateway, connection, or pairing
  • Setup or onboarding
  • Permissions, privacy, or security
  • Tests, CI, or docs

Required proof pools

  • windows-wsl-gateway-e2e: the credential boundary needs an owned real relay-backed Windows/WSL listener plus meaningful positive request receipt and precisely attributed late-swap rejection. Current traces advance authority evidence but are not a completed pool run.

The earlier windows-winui-interactive declaration accompanied the retained native dashboard claim. This PR changes no UI/app source; no new native/UI success is claimed. For the current source-owned authority boundary, correctly classified real service/request proof can suffice without a new GUI proof demand. Historical native observations are preserved below and are not promoted to current-head native verification. No new local/remote/cloud/browser/WSL reservation or host attempt was made on October 1.

Validation

Current October 1 evidence

Published-head CI Gate: SUCCESS on 74b1895a. Setup/connect, Revocation, and Network recovery are all SUCCESS on that same head. The previous 30f82803 run 36890455032 failed Revocation at E2ESetupFixture.WaitForMcpReady with a 90-second MCP startup timeout. That failure is superseded by the code-identical new-head successful run, not carried forward as a current gate or conflated with older restart-refusal signatures.

Local results below belong to unpublished candidate 811c9008, tree dd5705c8, not the published head or a final merge tree. $a is the private task artifacts directory. OPENCLAW_REPO_ROOT selected this worktree; SettingsManager/local-data roots and C: NTFS TEMP/TMP were process-local and task-owned, with the direct local-data override unset so Connection migration tests could set their own roots. UseSharedCompilation=false was process-local. No real credentials, user profiles, global ACL/env changes, or shared-process kills were used.

Exact command Result
.\build.ps1 Passed, exit 0, all five projects; ran initially and again before post-failure diagnostic
dotnet build .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --verbosity quiet Passed before default Shared test run
dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Shared.trx" --results-directory $a --verbosity quiet Failed 2, passed 4222, skipped 33, total 4257; retained default-mode failure
dotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Shared-collection-diagnostic.trx" --results-directory $a --verbosity quiet -- xUnit.MaxParallelThreads=1 xUnit.ParallelizeTestCollections=false Passed 4224, failed 0, skipped 33, total 4257; ONE distinct full collection-serialized diagnostic
dotnet build .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --verbosity quiet Passed before Tray tests
dotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Tray.trx" --results-directory $a --verbosity quiet Passed 3859, failed 0, skipped 0
dotnet build .\tests\OpenClaw.Connection.Tests\OpenClaw.Connection.Tests.csproj --verbosity quiet Passed before Connection tests
dotnet test .\tests\OpenClaw.Connection.Tests\OpenClaw.Connection.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Connection.trx" --results-directory $a --verbosity quiet Passed 1477, failed 0, skipped 1, total 1478
`dotnet test .\tests\OpenClaw.Connection.Tests\OpenClaw.Connection.Tests.csproj --no-build --no-restore --filter 'FullyQualifiedName~ManagedLocalGatewayPortProvenanceServiceTests FullyQualifiedName~InteractiveGatewayCredentialResolverTests' --logger "trx;LogFileName=oct1-ownership.trx" --results-directory $a --verbosity quiet`

Default Shared failures were PiperVoiceExtractionTests.ExtractTarBz2Async_CancellationIsBoundedAndKillsExtractor (fixture PID not published within its 3-second deadline) and McpHttpServerTests.Dispose_DuringInFlightHandler_DoesNotSurfaceObjectDisposedException:412 (process-wide unobserved-task capture saw two closed-FileStream ReadToEndAsync exceptions). Shared source/test files are identical published-author-to-candidate. The exact traces did not establish origin in this PR or the MCP handler limiter. One full collection-serialization diagnostic passed with unchanged assertions, no filters, no tool/source changes, and identical total count. Default failures remain reported; the diagnostic is not relabeled as a default pass or a blanket baseline-flake finding. No repeated default/full retry-until-green loop ran. TRX summaries were checked for nonzero counts.

Historical September 30 and original contributor validation, preserved separately

These results do not certify new head 74b1895a.

Original d14be08862505c401143ab23033fb8d711ceba56: .\build.ps1 passed. Shared 4107 passed/32 skipped/0 failed; Tray 3072 passed/0 failed; Connection 801 passed/1 skipped/0 failed; focused provenance 32 passed. Each test project was built before --no-restore.

Unpublished 7757ae8ed0aa780044672366932a5189e91e6756, tree fd7ea5071dde5e1eaafea6663524b4796f70337b, based on main 04a880fe: .\build.ps1 passed; Shared 4169 passed/33 skipped; Tray 3363 passed; Connection 1420 passed/1 skipped; focused provenance/native guard 33 passed. A filter also named a nonexistent separate authorizer test class; only the actual provenance class matched. Focused MXC cleanup timing repro passed 1, which did not clear hosted CI.

Exact historical test commands used the same project paths with --no-restore --logger "trx;LogFileName=head-<Shared/Tray/Connection>.trx" --results-directory $a --verbosity quiet for original-head results and integration-<Shared/Tray/Connection>.trx for integration results. Historical focused provenance used --no-build --no-restore --filter FullyQualifiedName~ManagedLocalGatewayPortProvenanceServiceTests --verbosity quiet. Historical MXC repro used --no-build --no-restore --filter FullyQualifiedName~RunAsync_CancellationCleanupIsBounded_WhenProcessTreeKillDoesNotStopLauncher --verbosity quiet.

The earlier scratch harness initially used nonexistent ConnectionStatus.PairingRequired, was corrected to real handshake/pairing events, and rebuilt with 0 warnings/errors before the one live attempt. No product source changed. First post-attempt build passed; Shared then failed 1 (4168 passed/33 skipped) when the process-wide MCP monitor caught closed-FileStream reads. An isolated Dispose_DuringInFlightHandler_DoesNotSurfaceObjectDisposedException repro passed 1; one diagnosed full build/Shared/Tray rerun passed (4169/33 skipped and 3363), plus focused provenance 33. The failed TRX was retained, not omitted or called a blanket flake.

Original-head run 36039166551 failed all three E2E lanes on live-serving-owner restart refusal, with derivative CI Gate red. Exact-base run 35991614068 had that same signature only in Network recovery; Setup and Revocation instead failed restart-intent/state-lifecycle contention. Old main 04a880fe run 36759009857 had E2E green but Core/CLI red on cleanup 3232 ms versus 2 seconds. These older distinct signatures are preserved as history, not new-head blockers. Cancelled ClawSweeper dispatch was separate from required CI.

Earlier contributor-reported commands/results on d14be088:

  • ./build.ps1: exit 0.
  • dotnet test ./tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj: Passed 4107, Failed 0, Skipped 32, Total 4139.
  • dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj: Passed 3067, Failed 5, Total 3072. The five failures are the LF source-contract mismatch tracked in fix(tests): tray source checks fail when the checkout is LF #1518.
  • Focused InteractiveCredentialGate_CachedWslRelayReplacedDuringGuestProbe_FailsClosed: Passed 1, Failed 0.

Real Behavior Proof

Current-head cached relay traces (author evidence retained verbatim)

Head 74b1895a2571de9dccc2f22739317a4ab485dff4. Windows 11, Ubuntu-24.04. The production ManagedLocalGatewayPortProvenanceService and InteractiveGatewayEndpointAuthorizer ran against canonical C:\Program Files\WSL\wslrelay.exe.

The installed openclaw-gateway node unit exits 78 because another lifecycle owner blocks maintenance, so it does not remain the systemd MainPID. For this trace the same user unit was pointed at a temporary loopback listener on port 18789, which the guest probe could match to MainPID. That listener was removed afterward and the unit is inactive again. No user Gateway token was used. The browser was not launched.

Healthy handoff, after Inspect cached the relay:

TRACE healthy inspect kind=ExpectedManagedGateway port=18789 pid=11900 name=wslrelay path=C:\Program Files\WSL\wslrelay.exe
TRACE healthy detail=Expected WSL relay owns loopback port 18789.
TRACE healthy handoff allowed=True browserLaunch=not-called
TRACE healthy target=http://127.0.0.1:18789/ tokenLength=27 tokenPrinted=false

Late swap. A new wsl.exe guest probe was observed, then the original relay process was replaced by a local listener on the same port before the gate returned:

TRACE swap allowed=False probeSeenUtc=2026-10-01T17:03:53.9659497Z swapUtc=2026-10-01T17:03:53.9861669Z note=replacement-bound decoyBytes=0 tokenSeen=False
TRACE swap originalRelayPid=11900

The replacement accepted no bytes and did not see the synthetic token. The credential handoff stayed denied.

Current maintainer classification: Credit the reported real canonical relay, production cached-service/authorizer healthy allowed=True, and timed replacement-denial observation. Do not conflate this with the old Connect path or discard it. The endpoint was a temporary unit-owned listener, not a running authenticated Gateway. URL/token-length construction with browserLaunch=not-called is authority evidence, not an actual healthy credential-bearing request receipt. Correlating the observed probe to this gate supports replacement after the initial capture; its successful result and final-capture execution are still absent. A failed real guest probe would also produce False before the new check. No source/hash or copied observer/producer data establishes those missing phases yet.

Remaining evidence request is exactly two items:

  1. Healthy cached gate permits the same dummy-token request producer through the current production authorizer/resolver path, and the owned expected listener receives that request with enabled, meaningful authentication as a positive control. Include the same managed record/credential classification and retained harness/source/build identity or copied phase/receipt data; do not print tokens or credential-bearing URLs. A stand-in remains explicitly classified as such, not claimed as real Gateway auth from MainPID matching alone.
  2. Replacement is tied to the real initial listener snapshot and an actual successful production guest probe, then the final real snapshot rejects changed ownership before any token-bearing producer/process/network dispatch. Include correlation/phase order, producer invoked and completed denied, zero downstream credential dispatch, and zero decoy credential receipt. An observation-only wrapper may pause after a genuinely successful real probe and before the final capture; it must not fabricate verifier success or listener data.

These can be real service/request observations on the contributor's owned relay-backed host. No generic screenshots, unrelated GUI pool, native click, new protocol, another model panel, or repeat fixture on this known relayless local host is requested. Native/app claims still need native proof if made, but they are not required for this source-only authority seam. Current disposition remains NEEDS_HUMAN_TEST until these two items are verifiable.

Retained original contributor evidence (d14be088, historical only)

Head d14be08862505c401143ab23033fb8d711ceba56. The guest user unit openclaw-gateway owned port 18789. Windows wslrelay.exe PID 7288 forwarded it. Connect sent the shared token. The gateway rejected it as a mismatch. The token is not shown.

Allowed relay: authentication failed after the token was sent

That Connect left a cached wslrelay proof. The next action was the dashboard deep link, which calls IsStrongCredentialAllowed before it opens a browser. During the guest probe the Windows listener was replaced: wslrelay.exe PID 7288 was stopped and python bound port 18789. The dashboard call returned 3.3 seconds later, after the probe and before the 5 second probe timeout, with "Gateway URL or credential is not configured". No browser started. The python log stayed connections=0, token_seen=false, bytes=0.

The focused unit test on this head still passes:

Passed!  - Failed: 0, Passed: 1, Skipped: 0, Total: 1, Duration: 20 ms
same wslrelay listener: IsStrongCredentialAllowed true
listener replaced during guest probe: IsStrongCredentialAllowed false

Original contributor proof details retained:

  • Behavior or issue addressed: A cached wslrelay proof must not send a shared token after another process binds the gateway port.
  • Real environment tested: Windows, isolated tray, head d14be08862505c401143ab23033fb8d711ceba56, Ubuntu-24.04, wslrelay.exe PID 7288.
  • Exact steps or command run after this patch: Connect while wslrelay.exe owned port 18789 and the guest user gateway owned that port. Then open the dashboard deep link. During its guest probe, stop wslrelay.exe and bind python on port 18789.
  • Evidence after fix: Connect sent the shared token and the gateway rejected the mismatch. The dashboard call returned 3.3 seconds later without starting a browser. The python log stayed connections=0, token_seen=false, bytes=0.
  • Observed result after fix: The real relay receives the token. A listener that appears during the guest probe does not.
  • Screenshot or artifact links verified? Yes. The capture in Evidence shows the allowed authentication failure and does not show a token. The dashboard refusal did not change that page.
  • Not verified / blocked: The product setup wizard was not run. The shared token was a fake value, so the allowed result is an authentication mismatch rather than a paired session. Chat waits for an operator handshake, so it did not call this gate.
  • What was not tested: A browser address bar. The dashboard URL was not recorded.

This retained image was downloaded/visibly inspected September 30; it shows Connect auth failure, not the new head's cached request receipt. It remains contributor evidence, not an independent current-head native capture.

Historical September 30 ONE authorized local attempt and cleanup

This was blocked, not a runtime proof pass. Candidate 7757ae8e, tree fd7ea507; WSL 2.9.13.0; fresh Ubuntu-24.04 OpenClawE2E-1510; real Gateway pinned/verified 2026.7.1, port 31351 (31353 also preflighted). Root D:\openclaw-proof-1510-f9047ec3, child data/local/process-local TEMP/TMP roots; install D:\openclaw-proof-1510-f9047ec3\local\wsl\OpenClawE2E-1510. Preflight checked absent target, existing registered default, bindable IPv4/IPv6 ports, sufficient disk and task-child ACL. No user distro/profile/export/global settings, paid/cloud or native launch was used.

Scratch dotnet build $proofProject --no-restore --verbosity quiet, then dotnet $proofAssembly once, invoked real product Create/Configure/InstallCLI/InstallService/Start steps and the actual provenance Inspect. Planned cached-authorizer/resolver/request/swap phases were not reached.

87217 ms: create succeeded
92930 ms: configure succeeded
116535 ms: pinned CLI installed, version 2026.7.1
118630 ms: install-service succeeded
125976 ms: start-gateway succeeded
128032 ms: real cache prime -> ExpectedManagedGateway, ProcessId=null, ProcessStartTimeUtc=null
128042 ms: BLOCKED: No real identity-bearing WSL relay proof; do not substitute relayless proof
131055 ms: ownership-gated cleanup succeeded, exact task distro unregistered
131055 ms: baseline default selection preserved=true

No healthy cached producer or replacement ran; no fabricated token/counter receipt, forced relay, changed networking, second fixture, scenario retry, or shared PID kill was used. CleanupStaleDistroStep with destructive consent disabled required durable OpenClaw evidence plus live HKCU Lxss BasePath matching the exact install. Only the task distro was terminated/unregistered. Registration/VHD/marker absence, preserved default, and released ports were verified; data/local roots and private bin/obj removed; WSL reservation released.

Initially 11 locked compiler analyzer DLL copies (2,233,832 bytes) were retained in named task TEMP rather than killing a possibly shared compiler. The parent confirmed this remaining cache was removed October 1; no 1510 host resource remains. The historical relayless topology cannot prove this PR's cached wslrelay branch, so no new local fixture was started. No old resource or reservation was inherited.

  • Environment tested: Published-author real relay traces as reported, plus isolated headless integration tests; no new independent runtime host.
  • PR head or commit tested: Published 74b1895a has green hosted CI and the reported new traces; local validation 811c9008/dd5705c8 is separate. Old d14be088/7757ae8e evidence remains historical. No final merge tree exists.
  • Exact steps or command run: Current and historical commands above, plus the 2026-10-06 stand-in receipt and probe-grep denial below.
  • Evidence after fix: Healthy production authority allowed the dummy shared token, and the stand-in accepted that bearer. The denial run returned false only after the guest ss grep had already succeeded.
  • Observed result: The allowed producer received an authenticated hello-ok from the stand-in. The replacement decoy received no bytes.
  • Screenshot or artifact links verified? (Yes/No/N/A): No new screenshot. The traces below are the current-head service output.
  • Not verified or blocked: No changed node/MCP command surface exists, so no tools/list or invocation claim is made. The stand-in is not the OpenClaw gateway process.

Current-head service observations (2026-10-06)

Head 74b1895a2571de9dccc2f22739317a4ab485dff4. A local executable built from this worktree called ManagedLocalGatewayPortProvenanceService.Inspect, InteractiveGatewayEndpointAuthorizer with that service's IsStrongCredentialAllowed, and InteractiveGatewayCredentialResolver.TryResolve. The dummy shared token is not printed.

The first October 6 pass used the real OpenClaw gateway. Its control UI returned HTTP 200 for a bearer GET, and a connect frame without a device signature returned INVALID_REQUEST. That did not show enabled authentication. The pass below replaces that receipt.

For this pass the user unit's ExecStart was temporarily a Python stand-in on port 18789. The stand-in requires the bearer: a GET without it is HTTP 401. It is not the OpenClaw gateway, and it was removed afterward. The Windows listener during the trace was canonical C:\Program Files\WSL\wslrelay.exe. After the trace the user unit was restored to node ... gateway --port 18789, and Windows could connect to 18789 again.

Healthy receipt, after Inspect cached the relay:

INSPECT kind=ExpectedManagedGateway port=18789 pid=41004 name=wslrelay path=C:\Program Files\WSL\wslrelay.exe
INSPECT detail=Expected WSL relay owns loopback port 18789.
GATE allowed=True
RESOLVER returned=True source=record.SharedGatewayToken bootstrap=False
HTTP status=200 authHeader=true tokenInBody=False bodyLen=10
WS challenge=True tokenInChallenge=False
WS authReceipt=true tokenEcho=False errorCode=ok bytes=90
PRODUCER completed=sent dispatch=1

Stand-in log, in order: HTTP authorized=False for the unauthenticated probe, then HTTP authorized=True and WS authorized=True for the producer. The websocket response was hello-ok. The token was not echoed.

Denial after the guest ownership check, before dispatch. A temporary /usr/local/bin/grep called /usr/bin/grep and wrote /tmp/ocwn-1510-probe-ok only after grep -F pid= succeeded. That is the last check in the product guest probe. It then slept 2.5 seconds, so the probe process had not exited yet. During that sleep the harness killed the snapshotted wslrelay pid and bound a decoy on 18789. The wrapper was removed afterward.

INSPECT kind=ExpectedManagedGateway port=18789 pid=41004 name=wslrelay path=C:\Program Files\WSL\wslrelay.exe
SWAP killedPid=41004 afterProbeGrep=true
DECOY listening=true
RESOLVER returned=False source=none bootstrap=none
PRODUCER completed=denied dispatch=0
FINAL kind=UnknownListener pid= samePid=False
DECOY bytes=0 marker=True

The marker exists only because the pid grep succeeded. The resolver then returned false, the producer opened no socket, and the decoy read 0 bytes. A later Inspect saw a different listener than pid 41004.

Current-head service observations (2026-10-06 real gateway)

Head 74b1895a2571de9dccc2f22739317a4ab485dff4. No new commit. This pass uses the real OpenClaw 2026.9.6 gateway, not the Python stand-in recorded above. The stand-in section stays as the earlier attempt. The user unit's MainPID owned port 18789 inside Ubuntu-24.04, and the Windows listener was canonical C:\Program Files\WSL\wslrelay.exe. The proof record's shared token was the explicit dummy. It is not printed.

Healthy receipt, after Inspect cached that relay. The producer sent one POST to /tools/invoke with the resolved bearer and an empty JSON object. A different bearer on the same route is the negative control.

INSPECT kind=ExpectedManagedGateway port=18789 pid=26572 name=wslrelay path=C:\Program Files\WSL\wslrelay.exe
GATE allowed=True elapsedMs=1138
RESOLVER returned=True source=record.SharedGatewayToken bootstrap=False tokenIsDummy=True
HTTP status=400 authHeader=true tokenInBody=False bodyLen=86 authPassed=True toolLayer=True
CONTROL status=401 authRejected=True tokenInBody=False
PRODUCER completed=sent dispatch=1

HTTP 400 is the gateway's own tools.invoke requires name after authentication. HTTP 401 is Unauthorized for the other bearer. The control UI GET is not this receipt.

Denial after a successful guest probe, before dispatch. A temporary /usr/local/bin/ss ran /usr/bin/ss and paused only when that output already satisfied the product probe: user MainPID greater than 0, and ss -ltnp showed that pid on port 18789 (ss_rc=0, probe_predicate=yes). The wrapper was not armed during Inspect. During the pause the harness killed the snapshotted wslrelay and bound its own listener, then released the probe. The gate returned in 914 ms, inside the 5 second probe budget, so this is not the timeout short circuit. The wrapper was removed afterward.

BEFORE 127.0.0.1:18789 pid=26572 name=wslrelay path=C:\Program Files\WSL\wslrelay.exe | ::1:18789 pid=26572 name=wslrelay path=C:\Program Files\WSL\wslrelay.exe
GATE allowed=False elapsedMs=914 swap=killed=True replacement=bound
ss_rc=0
pid_ok=yes
probe_predicate=yes
mainpid=881
continue_seen=yes waits=1
RESOLVER returned=False source=none bootstrap=none
AFTER 127.0.0.1:18789 pid=24988 name=ocw1510 path=C:\Users\sebta\AppData\Local\Temp\ocw-1510-harness\bin\Release\net10.0\ocw1510.exe
REPLACEMENT connections=0 authHeaderSeen=False tokenSeen=False
PRODUCER completed=denied dispatch=0

The final Windows listener was the harness, not pid 26572. The resolver returned false. The producer opened no socket. The replacement accepted 0 connections and saw no Authorization header and no token.

Security Impact

  • New permissions or capabilities? (Yes/No): No
  • Secrets or tokens handling changed? (Yes/No): Yes
  • New or changed network calls? (Yes/No): No
  • Command or tool execution surface changed? (Yes/No): No
  • Data access scope changed? (Yes/No): No
  • If any answer is Yes, explain the risk and mitigation: The same complete Windows listener identity is required after the successful guest probe before a strong credential is returned. Existing PID/start-time/path and address-family completeness checks remain. The preexisting post-return time-of-use window is not claimed to be eliminated. Only explicit dummy credentials such as test-auth-token may be used for proof; never publish actual tokens or token-bearing URLs.

Compatibility and Migration

  • Backward compatible? (Yes/No): Yes
  • Config or environment changes? (Yes/No): No
  • Migration needed? (Yes/No): No
  • If yes, list the exact upgrade steps: N/A. The author already normally updated the branch and obtained green exact-head CI. No further branch update is required merely for the independent current-main cache change. Any future code/head change needs its own exact-head evidence.

Review Conversations

  • I replied to or resolved every bot review conversation addressed by this PR.
  • I left unresolved only conversations that still need maintainer judgment.

All body/comments/new replies/commit history/current reviews and inline threads were read. No submitted reviews or inline threads were present. ClawSweeper durable revision 12 now credits the real relay traces and green CI while requesting final-effect proof; it is advisory, not merge authority. Its earlier omission of the appended trace was superseded by that fresh review. The maintainer independently narrows the current request to two service/request observations, not generic native screenshots. Contributor history/attribution and older evidence are preserved. No source rewrite, force-push, workflow/auth/admin bypass, superseding PR, merge, or archival was performed.

A cached wslrelay proof waited on the guest and then allowed a shared
token without reading the Windows listeners again. Accept the credential
only when that snapshot is still the same relay.

- Call ListenerSnapshotStillCurrent after IsExpectedWslGatewayListening
- Fail closed when the listener is replaced during the guest probe

Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 24, 2026
@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed October 6, 2026, 12:35 PM ET / 16:35 UTC (Revision 15).

ClawSweeper review

What this changes

The branch rechecks the Windows gateway listener after the WSL ownership probe before releasing cached shared or bootstrap credentials, and adds a listener-replacement regression test.

Merge readiness

✅ Ready for maintainer review

This PR remains necessary: current main and the latest release lack the guard. No blocking defect was found, and the appended real-gateway observations satisfy both outstanding proof requests.

Priority: P2
Reviewed head: 74b1895a2571de9dccc2f22739317a4ab485dff4

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused repair with useful regression coverage, green exact-head CI, and sufficient current-head allowed/forbidden request proof.
Proof confidence 🐚 platinum hermit (4/6) Sufficient (live_output): Exact-head Windows/Ubuntu observations exercise the production cached provenance service, authorizer, resolver, and request producer: the real gateway distinguishes the dummy bearer from a rejected control, while successful guest ownership observation followed by relay replacement yields denied resolution, zero dispatch, and zero replacement receipt. This satisfies the prior authority-chain requests; no stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (live_output): Exact-head Windows/Ubuntu observations exercise the production cached provenance service, authorizer, resolver, and request producer: the real gateway distinguishes the dummy bearer from a rejected control, while successful guest ownership observation followed by relay replacement yields denied resolution, zero dispatch, and zero replacement receipt. This satisfies the prior authority-chain requests; no stored-data contract changes.
Evidence reviewed 9 items Pinned introduced change: The exact merge-base-to-head delta adds the final listener comparison only after a successful guest probe; production changes are +4/-1 and tests +35/-0.
Current main still needs the repair: Current main returns the guest-probe result directly on the cached identity-bearing relay path. The two-file comparison confirms the proposed guard and regression test remain absent.
Latest release remains affected: GitHub identifies v2026.9.4 as the latest release. Its source also returns the guest-probe result directly at line 354 without the final cached-relay listener comparison. Release source was inspected through GitHub contents after local blob retrieval failed.
Findings None None.
Security None None.

How this fits together

The connection subsystem verifies that a managed local gateway owns its endpoint before giving interactive request producers a powerful credential. Its decision controls whether dashboard and chat consumers can construct credential-bearing requests.

flowchart TD
  A[Managed gateway record and credential] --> B[Cached endpoint proof]
  B --> C[Initial Windows listener snapshot]
  C --> D[WSL gateway ownership probe]
  D --> E[Final listener identity comparison]
  E --> F[Permit credential and request]
  E --> G[Deny credential before dispatch]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Production and test delta production +4/-1, tests +35/-0; 2 files The small production addition closes the cached-relay race using an existing comparison helper.

Technical review

Best possible solution:

Keep cached credential authorization in the existing provenance owner and reject listener changes before releasing a strong credential.

Do we have a high-confidence way to reproduce the issue?

Yes, source establishes the race: replace the cached Windows relay during a successful guest probe and current main can authorize without recapturing the listener. This review did not execute a failing current-main reproduction.

Is this the best way to solve the issue?

Yes. Reusing the existing complete snapshot comparison is a narrow repair, and the regression test plus current-head allowed and denied request observations cover its intended boundary.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 4895ed50e39e.

Labels

Label changes:

  • add proof: sufficient: Contributor real behavior proof is sufficient. Exact-head Windows/Ubuntu observations exercise the production cached provenance service, authorizer, resolver, and request producer: the real gateway distinguishes the dummy bearer from a rejected control, while successful guest ownership observation followed by relay replacement yields denied resolution, zero dispatch, and zero replacement receipt. This satisfies the prior authority-chain requests; no stored-data contract changes.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (live_output): Exact-head Windows/Ubuntu observations exercise the production cached provenance service, authorizer, resolver, and request producer: the real gateway distinguishes the dummy bearer from a rejected control, while successful guest ownership observation followed by relay replacement yields denied resolution, zero dispatch, and zero replacement receipt. This satisfies the prior authority-chain requests; no stored-data contract changes.
  • remove status: 📣 needs proof: Current PR status label is status: 👀 ready for maintainer look.
  • remove rating: 🦐 gold shrimp: Current PR rating is rating: 🐚 platinum hermit, so this older rating label is no longer current.
  • remove merge-risk: 🚨 security-boundary: Current PR review selected no merge-risk labels.

Label justifications:

  • P2: This is a focused credential-boundary repair for a local listener-replacement race, with no demonstrated widespread urgent failure.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🐚 platinum hermit and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (live_output): Exact-head Windows/Ubuntu observations exercise the production cached provenance service, authorizer, resolver, and request producer: the real gateway distinguishes the dummy bearer from a rejected control, while successful guest ownership observation followed by relay replacement yields denied resolution, zero dispatch, and zero replacement receipt. This satisfies the prior authority-chain requests; no stored-data contract changes.
  • proof: sufficient: Contributor real behavior proof is sufficient. Exact-head Windows/Ubuntu observations exercise the production cached provenance service, authorizer, resolver, and request producer: the real gateway distinguishes the dummy bearer from a rejected control, while successful guest ownership observation followed by relay replacement yields denied resolution, zero dispatch, and zero replacement receipt. This satisfies the prior authority-chain requests; no stored-data contract changes.

Evidence

What I checked:

  • Pinned introduced change: The exact merge-base-to-head delta adds the final listener comparison only after a successful guest probe; production changes are +4/-1 and tests +35/-0. (src/OpenClaw.Connection/ManagedLocalGatewayPortProvenanceService.cs:361, 74b1895a2571)
  • Current main still needs the repair: Current main returns the guest-probe result directly on the cached identity-bearing relay path. The two-file comparison confirms the proposed guard and regression test remain absent. (src/OpenClaw.Connection/ManagedLocalGatewayPortProvenanceService.cs:361, 4895ed50e39e)
  • Latest release remains affected: GitHub identifies v2026.9.4 as the latest release. Its source also returns the guest-probe result directly at line 354 without the final cached-relay listener comparison. Release source was inspected through GitHub contents after local blob retrieval failed. (src/OpenClaw.Connection/ManagedLocalGatewayPortProvenanceService.cs:354, 3c43751b2bac)
  • Credential rejection precedes request construction: The final comparison checks listener count, address, port, PID, start time, path, and capture completeness. The interactive resolver returns false with a null credential when authorization rejects; the app supplies the production authorizer to that resolver. (src/OpenClaw.Connection/InteractiveGatewayCredentialResolver.cs:84, 74b1895a2571)
  • Captured proof identity and authenticated positive control: The complete fetched body hashes to the captured SHA-256 506170600e00ad8e9a4ab53fc15ded0e26221ea6d4703068855444cf12d9da4f. Its appended October 6 real-gateway section reports exact-head production service/authorizer/resolver execution on Windows and Ubuntu-24.04 with canonical wslrelay and OpenClaw 2026.9.6. A resolved dummy shared bearer reaches /tools/invoke's authenticated validation response (400, requires name); a different bearer gets 401. The producer reports one dispatch. This supersedes the earlier public-control-UI and stand-in-only positive evidence. (74b1895a2571)
  • Late replacement denied before final effect: The same captured body records an observation wrapper running real ss and pausing only after MainPID and port ownership predicates succeed. It was unarmed during Inspect. After relay PID 26572 is replaced and the probe released, authorization finishes denied in 914 ms, below the five-second timeout; Windows ownership changes to harness PID 24988, resolution returns false, producer dispatch is zero, and replacement connections, Authorization receipt, and token receipt are zero. These copied phase and receipt observations address the prior successful-probe and forbidden-listener proof request without claiming an atomic socket binding. (74b1895a2571)

Likely related people:

  • shanselman: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • vincentkoc: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (14 earlier review cycles; latest 8 shown)
  • reviewed 2026-09-30T19:54:43.791Z sha d14be08 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-30T20:11:36.522Z sha d14be08 :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-01T16:21:03.505Z sha 30f8280 :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-01T16:39:03.522Z sha 74b1895 :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-01T17:10:41.359Z sha 74b1895 :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-01T19:15:27.715Z sha 74b1895 :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-01T19:33:07.867Z sha 74b1895 :: needs real behavior proof before merge. :: none
  • reviewed 2026-10-06T14:56:41.906Z sha 74b1895 :: needs real behavior proof before merge. :: none

@karkarl

karkarl commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

Global triage: NEEDS_HUMAN_TEST. Take confidence 86%; recommendation confidence 99%; effort medium; risk high.

No significant source defect was found. The provenance guard fails closed and the focused regression test covers the intended listener-replacement race through the platform seam.

This still needs current-head final-effect proof. Replace the none declaration with:

  • windows-wsl-gateway-e2e for the strong-credential boundary.
  • windows-winui-interactive for the changed visible chat/dashboard denial path.

The proof must demonstrate that a replacement listener receives no token-bearing request; screenshots alone cannot establish that. Also report the required build, Shared, and Tray closeout results.

The three failed E2E lanes have the same setup-fixture failure on the exact base, and CI Gate is derivative. No PR-caused check failure was verified.

@karkarl

karkarl commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator

Hey @SebTardif, thanks for the PR. Per claw sweeper review, please post screenshot / video proof for your change.

@karkarl karkarl added the status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. label Sep 25, 2026
@clawsweeper clawsweeper Bot added proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. labels Sep 25, 2026
@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Sep 30, 2026
@shanselman

Copy link
Copy Markdown
Collaborator

Source and local validation are clear, but this remains NEEDS_HUMAN_TEST and CI-blocked. @SebTardif, please update this branch normally to current main and obtain green CI on the resulting exact head. The original d14be08 head passed local build, Shared (4107 pass, 32 skip), Tray (3072 pass), Connection (801 pass, 1 skip), and focused provenance (32 pass). A normal unpublished integration with main 04a880f also passed build, Shared (4169 pass, 33 skip), Tray (3363 pass), Connection (1420 pass, 1 skip), and focused provenance (33 pass). Your original two-file patch and attribution are intact; no source rewrite or force-push is needed.

Please add the healthy positive outcome through the SAME cached dashboard gate used in your listener-swap run. Connect uses fresh Inspect and does not exercise IsStrongCredentialAllowed. Use only an owned isolated Gateway/relay and a dummy token such as test-auth-token; record that the healthy cached dashboard handoff reaches the intended listener, then timestamp the replacement after the initial Windows snapshot and during the guest probe, with zero token-bearing process/network I/O to the replacement. Do not capture a token-bearing URL or real credentials. Your negative counters and screenshot are retained in the body and correctly credited as contributor evidence, not discarded or presented as independent proof.

Required CI Gate is still red on d14be08. All three head E2E lanes report live-serving-owner restart refusal; exact base has that same signature only in Network recovery, while Setup and Revocation instead fail restart-intent contention. Current main has those E2E lanes green but an unrelated MXC cleanup timing failure; that focused timing test passed locally, which does not clear hosted CI. The body now separates original head, unpublished integration, contributor runtime proof, and missing current-head proof. Current required Opus 5.5/GPT-6 Astra review found no blocking production defect. No app/WSL fixture was launched or borrowed, and no required gate was bypassed. Optional architecture wording/dual-stack coverage suggestions are nonblocking; do not broaden the trust contract for this lane.

@shanselman shanselman added status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. and removed status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. proof: sufficient Contributor real behavior proof is sufficient. status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. labels Sep 30, 2026
@clawsweeper clawsweeper Bot added rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. and removed rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. labels Sep 30, 2026
@shanselman shanselman added status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. and removed status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. labels Sep 30, 2026
@shanselman

Copy link
Copy Markdown
Collaborator

The ONE authorized headless proof attempt provisioned the actual pinned Gateway 2026.7.1 on candidate 7757ae8e/tree fd7ea507, but the real verifier observed a relayless endpoint (ExpectedManagedGateway, null Windows PID/start). The changed cached wslrelay branch could not run, so we stopped before credential production or swapping. This is BLOCKED, not a service/transport or app proof pass. Ownership-marker plus live BasePath-gated cleanup removed only OpenClawE2E-1510; distro/VHD/marker absent, default unchanged, ports free, reservation released. No second fixture or networking workaround ran.

Final required build passed; Shared4169/33skip, Tray3363, focused provenance33 passed; prior full Connection1420/1skip is retained. An intermediate Shared failure captured closed-FileStream unobserved exceptions; the isolated repro and one diagnosed full required rerun passed. The failed TRX remains recorded, not omitted or called a blanket baseline flake. No product source changed.

The body now explicitly records one retained non-Gateway resource: 11 locked compiler analyzer DLL copies (2.23MB) under the named task TEMP cache. We did not kill a possibly shared compiler or run global shutdown. No Gateway/token store/VHD remains. Same cached-dashboard healthy-positive/timed-swap proof still needs an appropriate owned relay host, and exact published-head CI Gate is still red. Original contributor evidence and attribution remain intact; no force-push, workflow-bearing push, merge, or superseding PR.

@shanselman shanselman added the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Oct 1, 2026
@shanselman

Copy link
Copy Markdown
Collaborator

Thanks for the new 74b1895 relay traces. They materially advance the evidence: healthy acceptance now runs through the changed cached production service/authorizer on a real canonical relay, not just Connect. CI Gate and all three E2E lanes are green on this exact head. Current Opus 5.5/Astra review found no blocking production or main-integration defect. No new GUI screenshots, native clicks, protocol changes, or repeat local relayless fixture are requested.

Only two concrete proof items remain:

  1. After caching the real owned relay, use the same managed record and dummy strong credential through the current production authorizer/resolver to permit an armed request producer, and show the owned expected listener receives that request with enabled, meaningful auth as a positive control. Retained harness/source/build identity OR copied observer/producer receipt data is sufficient. The temporary MainPID listener must stay explicitly classified as a stand-in; matching MainPID is not a claim of actual Gateway authentication. Do not publish a token or token-bearing URL.

  2. Correlate the swap to this gate after its real initial snapshot and successful actual guest probe, then show changed ownership in the final real snapshot, authorization denied, and the same producer invocation completing denied before credential-bearing process/network dispatch, with zero downstream credential dispatch and zero decoy credential receipt. Observing wsl.exe start helps order the initial snapshot, but without its actual successful result False could still come from the earlier probe-failure short circuit. An observation-only wrapper may pause after a genuine successful probe before the final capture; do not fake success or listener identity.

The body preserves your new traces verbatim and separates old d14/7757 evidence from current results. Unpublished current-main candidate 811c9008/tree dd5705c8 passed full build, Tray3859, Connection1477/1skip and focused owners41. Default Shared failed2 (Piper fixture PID deadline and process-wide unobserved closed-file capture); the retained, single full collection-serialized diagnostic passed4224/33skip with no filters or assertion changes. These local diagnostic distinctions do not make the published green CI red. Parking only the narrow current proof request; no source rewrite, host attempt, push, supersession or merge.

@shanselman shanselman removed the status: 🚢 actively landing A maintainer or agent is actively driving this item through implementation, validation, or merge. label Oct 1, 2026
@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. labels Oct 6, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants