Repository navigation
Conversation
A cached wslrelay proof waited on the guest and then allowed a shared token without reading the Windows listeners again. Accept the credential only when that snapshot is still the same relay. - Call ListenerSnapshotStillCurrent after IsExpectedWslGatewayListening - Fail closed when the listener is replaced during the guest probe Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 6, 2026, 12:35 PM ET / 16:35 UTC (Revision 15). ClawSweeper reviewWhat this changesThe branch rechecks the Windows gateway listener after the WSL ownership probe before releasing cached shared or bootstrap credentials, and adds a listener-replacement regression test. Merge readiness✅ Ready for maintainer review This PR remains necessary: current main and the latest release lack the guard. No blocking defect was found, and the appended real-gateway observations satisfy both outstanding proof requests. Priority: P2 Review scores
Verification
How this fits togetherThe connection subsystem verifies that a managed local gateway owns its endpoint before giving interactive request producers a powerful credential. Its decision controls whether dashboard and chat consumers can construct credential-bearing requests. flowchart TD
A[Managed gateway record and credential] --> B[Cached endpoint proof]
B --> C[Initial Windows listener snapshot]
C --> D[WSL gateway ownership probe]
D --> E[Final listener identity comparison]
E --> F[Permit credential and request]
E --> G[Deny credential before dispatch]
Before mergeNone. Agent review detailsSecurityNone. Review metrics
Technical reviewBest possible solution: Keep cached credential authorization in the existing provenance owner and reject listener changes before releasing a strong credential. Do we have a high-confidence way to reproduce the issue? Yes, source establishes the race: replace the cached Windows relay during a successful guest probe and current main can authorize without recapturing the listener. This review did not execute a failing current-main reproduction. Is this the best way to solve the issue? Yes. Reusing the existing complete snapshot comparison is a narrow repair, and the regression test plus current-head allowed and denied request observations cover its intended boundary. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 4895ed50e39e. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (14 earlier review cycles; latest 8 shown)
|
|
Global triage: NEEDS_HUMAN_TEST. Take confidence 86%; recommendation confidence 99%; effort medium; risk high. No significant source defect was found. The provenance guard fails closed and the focused regression test covers the intended listener-replacement race through the platform seam. This still needs current-head final-effect proof. Replace the
The proof must demonstrate that a replacement listener receives no token-bearing request; screenshots alone cannot establish that. Also report the required build, Shared, and Tray closeout results. The three failed E2E lanes have the same setup-fixture failure on the exact base, and CI Gate is derivative. No PR-caused check failure was verified. |
|
Hey @SebTardif, thanks for the PR. Per claw sweeper review, please post screenshot / video proof for your change. |
|
Source and local validation are clear, but this remains NEEDS_HUMAN_TEST and CI-blocked. @SebTardif, please update this branch normally to current main and obtain green CI on the resulting exact head. The original d14be08 head passed local build, Shared (4107 pass, 32 skip), Tray (3072 pass), Connection (801 pass, 1 skip), and focused provenance (32 pass). A normal unpublished integration with main 04a880f also passed build, Shared (4169 pass, 33 skip), Tray (3363 pass), Connection (1420 pass, 1 skip), and focused provenance (33 pass). Your original two-file patch and attribution are intact; no source rewrite or force-push is needed. Please add the healthy positive outcome through the SAME cached dashboard gate used in your listener-swap run. Connect uses fresh Inspect and does not exercise IsStrongCredentialAllowed. Use only an owned isolated Gateway/relay and a dummy token such as test-auth-token; record that the healthy cached dashboard handoff reaches the intended listener, then timestamp the replacement after the initial Windows snapshot and during the guest probe, with zero token-bearing process/network I/O to the replacement. Do not capture a token-bearing URL or real credentials. Your negative counters and screenshot are retained in the body and correctly credited as contributor evidence, not discarded or presented as independent proof. Required CI Gate is still red on d14be08. All three head E2E lanes report live-serving-owner restart refusal; exact base has that same signature only in Network recovery, while Setup and Revocation instead fail restart-intent contention. Current main has those E2E lanes green but an unrelated MXC cleanup timing failure; that focused timing test passed locally, which does not clear hosted CI. The body now separates original head, unpublished integration, contributor runtime proof, and missing current-head proof. Current required Opus 5.5/GPT-6 Astra review found no blocking production defect. No app/WSL fixture was launched or borrowed, and no required gate was bypassed. Optional architecture wording/dual-stack coverage suggestions are nonblocking; do not broaden the trust contract for this lane. |
|
The ONE authorized headless proof attempt provisioned the actual pinned Gateway 2026.7.1 on candidate 7757ae8e/tree fd7ea507, but the real verifier observed a relayless endpoint (ExpectedManagedGateway, null Windows PID/start). The changed cached wslrelay branch could not run, so we stopped before credential production or swapping. This is BLOCKED, not a service/transport or app proof pass. Ownership-marker plus live BasePath-gated cleanup removed only OpenClawE2E-1510; distro/VHD/marker absent, default unchanged, ports free, reservation released. No second fixture or networking workaround ran. Final required build passed; Shared4169/33skip, Tray3363, focused provenance33 passed; prior full Connection1420/1skip is retained. An intermediate Shared failure captured closed-FileStream unobserved exceptions; the isolated repro and one diagnosed full required rerun passed. The failed TRX remains recorded, not omitted or called a blanket baseline flake. No product source changed. The body now explicitly records one retained non-Gateway resource: 11 locked compiler analyzer DLL copies (2.23MB) under the named task TEMP cache. We did not kill a possibly shared compiler or run global shutdown. No Gateway/token store/VHD remains. Same cached-dashboard healthy-positive/timed-swap proof still needs an appropriate owned relay host, and exact published-head CI Gate is still red. Original contributor evidence and attribution remain intact; no force-push, workflow-bearing push, merge, or superseding PR. |
Signed-off-by: Sebastien Tardif <SebTardif@ncf.ca>
|
Thanks for the new 74b1895 relay traces. They materially advance the evidence: healthy acceptance now runs through the changed cached production service/authorizer on a real canonical relay, not just Connect. CI Gate and all three E2E lanes are green on this exact head. Current Opus 5.5/Astra review found no blocking production or main-integration defect. No new GUI screenshots, native clicks, protocol changes, or repeat local relayless fixture are requested. Only two concrete proof items remain:
The body preserves your new traces verbatim and separates old d14/7757 evidence from current results. Unpublished current-main candidate 811c9008/tree dd5705c8 passed full build, Tray3859, Connection1477/1skip and focused owners41. Default Shared failed2 (Piper fixture PID deadline and process-wide unobserved closed-file capture); the retained, single full collection-serialized diagnostic passed4224/33skip with no filters or assertion changes. These local diagnostic distinctions do not make the published green CI red. Parking only the narrow current proof request; no source rewrite, host attempt, push, supersession or merge. |
What Problem This Solves
Fixes: a shared or bootstrap token can be sent to a new process that binds the gateway port while the wslrelay guest probe is running.
User Impact
User impact: a cached wslrelay proof is accepted only when the same Windows listener is still there after the guest probe.
Why This Change Was Made
The relayless path already calls
ListenerSnapshotStillCurrentafter the guest probe. The cached wslrelay path now does the same. If the listener changed, the strong credential is refused.Evidence
October 1 current-head disposition: NEEDS_HUMAN_TEST for two narrow service/request observations. Published-head CI is GREEN, not CI-blocked. No blocking production or current-main integration defect was found. The new real canonical-relay traces below materially advance the proof: they report healthy acceptance through the changed cached production authority, unlike the older Connect observation. They remain authorization/stand-in evidence, not a demonstrated enabled-auth request receipt or a causal successful-probe/final-snapshot denial. No new screenshot, GUI/native click, protocol rewrite, or repeat local relayless fixture is requested.
Published author head:
74b1895a2571de9dccc2f22739317a4ab485dff4, tree5015565e512d075a3fabdf32530e74dddf9865a8. The author normally merged main in30f82803, then made the code-identical CI retrigger74b1895a. Run 36892821510 passes requiredCI Gate, Core/CLI, Tray/setup/integration, and all three E2E lanes. No submitted reviews or inline threads were present. Earlier red checks do not apply to this head.Current-main candidate: main
28df9c599b88889f70dee6640885e47cdaeafee8; unpublished local normal integration811c900835897578a3543ddc55140ceffc95d94d, treedd5705c8ad6ff1d991bbe76ea2f00566e62c582b. Earlier contributord14be088and unpublished7757ae8eremain in history; no reset, stash, force-push, or supersession was used. Against current main the PR remains exactly two files, +39/-1. The Connection/provenance/verifier/authorizer/resolver and relevant App/dashboard sources are identical between published74b1895aand this candidate. The seven main-only Local AI cache files from the independent cache work do not alter this authority seam.ManagedLocalGatewayPortProvenanceServiceremains the WSL owner.InteractiveGatewayEndpointAuthorizerdelegates non-native records to its cached gate, preserving native fail-closed checks; the interactive resolver withholds rejected credentials before downstream request construction. HTTP shared-token preference and WebSocket device-first preference are unchanged. The patch repeats the complete PID/start-time/path/address snapshot after a successful guest probe. It does not claim atomic socket binding or elimination of post-return TOCTOU.October 1 identical frozen dual review and adjudication
One new bounded delta/integration review used actual
claude-opus-5.5(high) andgpt-6-astra(high, long_context), with an identical frozen prompt at candidate811c9008. No nested, fallback, or duplicate panel ran. Both found no blocking production defect and credited the new healthy cached authority positive.Both models agree: HIGH consensus
Only one model flagged: LOW consensus
Both note that no actual healthy request receipt or armed denied-producer completion was shown. They differ on whether authenticated downstream effects are additionally required for this source seam. Maintainer adjudication follows the explicit current request: prove the same dummy-token producer's positive receipt and its denied completion, without demanding GUI/native proof. This is validation, not an accepted production bug. The declared temporary MainPID listener must remain classified as a stand-in; MainPID match alone is not real Gateway authentication.
Source ordering means a probe belonging to the cached gate starts after its initial snapshot. A correlated probe-start observation therefore advances timing evidence; an extra initial-capture timestamp is not intrinsically required if correlation is established. However, the actual guest method can return false on nonzero exit, timeout, startup failure, or exception; that old short circuit also denies without the added final capture. Current copied output does not exclude it. Retained harness/source/build identity or copied observer phase and producer-receipt data can establish causality. No fake verifier success, invented listener identity, or new trust contract is acceptable.
Earlier full original-head review used actual Opus 5/Codex; September 30 integration review used Opus 5.5/Astra. Their attribution and historical findings remain separate, not relabeled as new-head results. Optional architecture wording/dual-stack coverage suggestions remain nonblocking and were not converted into source changes to make reviewers green.
Change Type
Scope
winnodeRequired proof pools
windows-wsl-gateway-e2e: the credential boundary needs an owned real relay-backed Windows/WSL listener plus meaningful positive request receipt and precisely attributed late-swap rejection. Current traces advance authority evidence but are not a completed pool run.The earlier
windows-winui-interactivedeclaration accompanied the retained native dashboard claim. This PR changes no UI/app source; no new native/UI success is claimed. For the current source-owned authority boundary, correctly classified real service/request proof can suffice without a new GUI proof demand. Historical native observations are preserved below and are not promoted to current-head native verification. No new local/remote/cloud/browser/WSL reservation or host attempt was made on October 1.Validation
Current October 1 evidence
Published-head CI Gate: SUCCESS on
74b1895a. Setup/connect, Revocation, and Network recovery are all SUCCESS on that same head. The previous30f82803run 36890455032 failed Revocation atE2ESetupFixture.WaitForMcpReadywith a 90-second MCP startup timeout. That failure is superseded by the code-identical new-head successful run, not carried forward as a current gate or conflated with older restart-refusal signatures.Local results below belong to unpublished candidate
811c9008, treedd5705c8, not the published head or a final merge tree.$ais the private task artifacts directory.OPENCLAW_REPO_ROOTselected this worktree; SettingsManager/local-data roots and C: NTFS TEMP/TMP were process-local and task-owned, with the direct local-data override unset so Connection migration tests could set their own roots.UseSharedCompilation=falsewas process-local. No real credentials, user profiles, global ACL/env changes, or shared-process kills were used..\build.ps1dotnet build .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --verbosity quietdotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Shared.trx" --results-directory $a --verbosity quietdotnet test .\tests\OpenClaw.Shared.Tests\OpenClaw.Shared.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Shared-collection-diagnostic.trx" --results-directory $a --verbosity quiet -- xUnit.MaxParallelThreads=1 xUnit.ParallelizeTestCollections=falsedotnet build .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --verbosity quietdotnet test .\tests\OpenClaw.Tray.Tests\OpenClaw.Tray.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Tray.trx" --results-directory $a --verbosity quietdotnet build .\tests\OpenClaw.Connection.Tests\OpenClaw.Connection.Tests.csproj --verbosity quietdotnet test .\tests\OpenClaw.Connection.Tests\OpenClaw.Connection.Tests.csproj --no-restore --logger "trx;LogFileName=oct1-Connection.trx" --results-directory $a --verbosity quietDefault Shared failures were
PiperVoiceExtractionTests.ExtractTarBz2Async_CancellationIsBoundedAndKillsExtractor(fixture PID not published within its 3-second deadline) andMcpHttpServerTests.Dispose_DuringInFlightHandler_DoesNotSurfaceObjectDisposedException:412(process-wide unobserved-task capture saw two closed-FileStreamReadToEndAsyncexceptions). Shared source/test files are identical published-author-to-candidate. The exact traces did not establish origin in this PR or the MCP handler limiter. One full collection-serialization diagnostic passed with unchanged assertions, no filters, no tool/source changes, and identical total count. Default failures remain reported; the diagnostic is not relabeled as a default pass or a blanket baseline-flake finding. No repeated default/full retry-until-green loop ran. TRX summaries were checked for nonzero counts.Historical September 30 and original contributor validation, preserved separately
These results do not certify new head
74b1895a.Original
d14be08862505c401143ab23033fb8d711ceba56:.\build.ps1passed. Shared 4107 passed/32 skipped/0 failed; Tray 3072 passed/0 failed; Connection 801 passed/1 skipped/0 failed; focused provenance 32 passed. Each test project was built before--no-restore.Unpublished
7757ae8ed0aa780044672366932a5189e91e6756, treefd7ea5071dde5e1eaafea6663524b4796f70337b, based on main04a880fe:.\build.ps1passed; Shared 4169 passed/33 skipped; Tray 3363 passed; Connection 1420 passed/1 skipped; focused provenance/native guard 33 passed. A filter also named a nonexistent separate authorizer test class; only the actual provenance class matched. Focused MXC cleanup timing repro passed 1, which did not clear hosted CI.Exact historical test commands used the same project paths with
--no-restore --logger "trx;LogFileName=head-<Shared/Tray/Connection>.trx" --results-directory $a --verbosity quietfor original-head results andintegration-<Shared/Tray/Connection>.trxfor integration results. Historical focused provenance used--no-build --no-restore --filter FullyQualifiedName~ManagedLocalGatewayPortProvenanceServiceTests --verbosity quiet. Historical MXC repro used--no-build --no-restore --filter FullyQualifiedName~RunAsync_CancellationCleanupIsBounded_WhenProcessTreeKillDoesNotStopLauncher --verbosity quiet.The earlier scratch harness initially used nonexistent
ConnectionStatus.PairingRequired, was corrected to real handshake/pairing events, and rebuilt with 0 warnings/errors before the one live attempt. No product source changed. First post-attempt build passed; Shared then failed 1 (4168 passed/33 skipped) when the process-wide MCP monitor caught closed-FileStream reads. An isolatedDispose_DuringInFlightHandler_DoesNotSurfaceObjectDisposedExceptionrepro passed 1; one diagnosed full build/Shared/Tray rerun passed (4169/33 skipped and 3363), plus focused provenance 33. The failed TRX was retained, not omitted or called a blanket flake.Original-head run 36039166551 failed all three E2E lanes on live-serving-owner restart refusal, with derivative CI Gate red. Exact-base run 35991614068 had that same signature only in Network recovery; Setup and Revocation instead failed restart-intent/state-lifecycle contention. Old main
04a880ferun 36759009857 had E2E green but Core/CLI red on cleanup 3232 ms versus 2 seconds. These older distinct signatures are preserved as history, not new-head blockers. Cancelled ClawSweeper dispatch was separate from required CI.Earlier contributor-reported commands/results on
d14be088:./build.ps1: exit 0.dotnet test ./tests/OpenClaw.Shared.Tests/OpenClaw.Shared.Tests.csproj: Passed 4107, Failed 0, Skipped 32, Total 4139.dotnet test ./tests/OpenClaw.Tray.Tests/OpenClaw.Tray.Tests.csproj: Passed 3067, Failed 5, Total 3072. The five failures are the LF source-contract mismatch tracked in fix(tests): tray source checks fail when the checkout is LF #1518.InteractiveCredentialGate_CachedWslRelayReplacedDuringGuestProbe_FailsClosed: Passed 1, Failed 0.Real Behavior Proof
Current-head cached relay traces (author evidence retained verbatim)
Head
74b1895a2571de9dccc2f22739317a4ab485dff4. Windows 11, Ubuntu-24.04. The productionManagedLocalGatewayPortProvenanceServiceandInteractiveGatewayEndpointAuthorizerran against canonicalC:\Program Files\WSL\wslrelay.exe.The installed
openclaw-gatewaynode unit exits 78 because another lifecycle owner blocks maintenance, so it does not remain the systemd MainPID. For this trace the same user unit was pointed at a temporary loopback listener on port 18789, which the guest probe could match to MainPID. That listener was removed afterward and the unit is inactive again. No user Gateway token was used. The browser was not launched.Healthy handoff, after
Inspectcached the relay:Late swap. A new
wsl.exeguest probe was observed, then the original relay process was replaced by a local listener on the same port before the gate returned:The replacement accepted no bytes and did not see the synthetic token. The credential handoff stayed denied.
Current maintainer classification: Credit the reported real canonical relay, production cached-service/authorizer healthy
allowed=True, and timed replacement-denial observation. Do not conflate this with the old Connect path or discard it. The endpoint was a temporary unit-owned listener, not a running authenticated Gateway. URL/token-length construction withbrowserLaunch=not-calledis authority evidence, not an actual healthy credential-bearing request receipt. Correlating the observed probe to this gate supports replacement after the initial capture; its successful result and final-capture execution are still absent. A failed real guest probe would also produce False before the new check. No source/hash or copied observer/producer data establishes those missing phases yet.Remaining evidence request is exactly two items:
These can be real service/request observations on the contributor's owned relay-backed host. No generic screenshots, unrelated GUI pool, native click, new protocol, another model panel, or repeat fixture on this known relayless local host is requested. Native/app claims still need native proof if made, but they are not required for this source-only authority seam. Current disposition remains NEEDS_HUMAN_TEST until these two items are verifiable.
Retained original contributor evidence (
d14be088, historical only)Head
d14be08862505c401143ab23033fb8d711ceba56. The guest user unitopenclaw-gatewayowned port 18789. Windowswslrelay.exePID 7288 forwarded it. Connect sent the shared token. The gateway rejected it as a mismatch. The token is not shown.That Connect left a cached wslrelay proof. The next action was the dashboard deep link, which calls
IsStrongCredentialAllowedbefore it opens a browser. During the guest probe the Windows listener was replaced:wslrelay.exePID 7288 was stopped and python bound port 18789. The dashboard call returned 3.3 seconds later, after the probe and before the 5 second probe timeout, with "Gateway URL or credential is not configured". No browser started. The python log stayedconnections=0,token_seen=false,bytes=0.The focused unit test on this head still passes:
Original contributor proof details retained:
d14be08862505c401143ab23033fb8d711ceba56, Ubuntu-24.04,wslrelay.exePID 7288.wslrelay.exeowned port 18789 and the guest user gateway owned that port. Then open the dashboard deep link. During its guest probe, stopwslrelay.exeand bind python on port 18789.connections=0,token_seen=false,bytes=0.This retained image was downloaded/visibly inspected September 30; it shows Connect auth failure, not the new head's cached request receipt. It remains contributor evidence, not an independent current-head native capture.
Historical September 30 ONE authorized local attempt and cleanup
This was blocked, not a runtime proof pass. Candidate
7757ae8e, treefd7ea507; WSL 2.9.13.0; fresh Ubuntu-24.04OpenClawE2E-1510; real Gateway pinned/verified 2026.7.1, port 31351 (31353 also preflighted). RootD:\openclaw-proof-1510-f9047ec3, child data/local/process-local TEMP/TMP roots; installD:\openclaw-proof-1510-f9047ec3\local\wsl\OpenClawE2E-1510. Preflight checked absent target, existing registered default, bindable IPv4/IPv6 ports, sufficient disk and task-child ACL. No user distro/profile/export/global settings, paid/cloud or native launch was used.Scratch
dotnet build $proofProject --no-restore --verbosity quiet, thendotnet $proofAssemblyonce, invoked real product Create/Configure/InstallCLI/InstallService/Start steps and the actual provenance Inspect. Planned cached-authorizer/resolver/request/swap phases were not reached.No healthy cached producer or replacement ran; no fabricated token/counter receipt, forced relay, changed networking, second fixture, scenario retry, or shared PID kill was used. CleanupStaleDistroStep with destructive consent disabled required durable OpenClaw evidence plus live HKCU Lxss BasePath matching the exact install. Only the task distro was terminated/unregistered. Registration/VHD/marker absence, preserved default, and released ports were verified; data/local roots and private bin/obj removed; WSL reservation released.
Initially 11 locked compiler analyzer DLL copies (2,233,832 bytes) were retained in named task TEMP rather than killing a possibly shared compiler. The parent confirmed this remaining cache was removed October 1; no 1510 host resource remains. The historical relayless topology cannot prove this PR's cached wslrelay branch, so no new local fixture was started. No old resource or reservation was inherited.
74b1895ahas green hosted CI and the reported new traces; local validation811c9008/dd5705c8is separate. Oldd14be088/7757ae8eevidence remains historical. No final merge tree exists.ssgrep had already succeeded.Yes/No/N/A): No new screenshot. The traces below are the current-head service output.Current-head service observations (2026-10-06)
Head
74b1895a2571de9dccc2f22739317a4ab485dff4. A local executable built from this worktree calledManagedLocalGatewayPortProvenanceService.Inspect,InteractiveGatewayEndpointAuthorizerwith that service'sIsStrongCredentialAllowed, andInteractiveGatewayCredentialResolver.TryResolve. The dummy shared token is not printed.The first October 6 pass used the real OpenClaw gateway. Its control UI returned HTTP 200 for a bearer GET, and a connect frame without a device signature returned
INVALID_REQUEST. That did not show enabled authentication. The pass below replaces that receipt.For this pass the user unit's
ExecStartwas temporarily a Python stand-in on port 18789. The stand-in requires the bearer: a GET without it is HTTP 401. It is not the OpenClaw gateway, and it was removed afterward. The Windows listener during the trace was canonicalC:\Program Files\WSL\wslrelay.exe. After the trace the user unit was restored tonode ... gateway --port 18789, and Windows could connect to 18789 again.Healthy receipt, after Inspect cached the relay:
Stand-in log, in order:
HTTP authorized=Falsefor the unauthenticated probe, thenHTTP authorized=TrueandWS authorized=Truefor the producer. The websocket response was hello-ok. The token was not echoed.Denial after the guest ownership check, before dispatch. A temporary
/usr/local/bin/grepcalled/usr/bin/grepand wrote/tmp/ocwn-1510-probe-okonly aftergrep -F pid=succeeded. That is the last check in the product guest probe. It then slept 2.5 seconds, so the probe process had not exited yet. During that sleep the harness killed the snapshotted wslrelay pid and bound a decoy on 18789. The wrapper was removed afterward.The marker exists only because the pid grep succeeded. The resolver then returned false, the producer opened no socket, and the decoy read 0 bytes. A later Inspect saw a different listener than pid 41004.
Current-head service observations (2026-10-06 real gateway)
Head
74b1895a2571de9dccc2f22739317a4ab485dff4. No new commit. This pass uses the real OpenClaw 2026.9.6 gateway, not the Python stand-in recorded above. The stand-in section stays as the earlier attempt. The user unit's MainPID owned port 18789 inside Ubuntu-24.04, and the Windows listener was canonicalC:\Program Files\WSL\wslrelay.exe. The proof record's shared token was the explicit dummy. It is not printed.Healthy receipt, after Inspect cached that relay. The producer sent one POST to
/tools/invokewith the resolved bearer and an empty JSON object. A different bearer on the same route is the negative control.HTTP 400 is the gateway's own
tools.invoke requires nameafter authentication. HTTP 401 isUnauthorizedfor the other bearer. The control UI GET is not this receipt.Denial after a successful guest probe, before dispatch. A temporary
/usr/local/bin/ssran/usr/bin/ssand paused only when that output already satisfied the product probe: user MainPID greater than 0, andss -ltnpshowed that pid on port 18789 (ss_rc=0,probe_predicate=yes). The wrapper was not armed during Inspect. During the pause the harness killed the snapshotted wslrelay and bound its own listener, then released the probe. The gate returned in 914 ms, inside the 5 second probe budget, so this is not the timeout short circuit. The wrapper was removed afterward.The final Windows listener was the harness, not pid 26572. The resolver returned false. The producer opened no socket. The replacement accepted 0 connections and saw no Authorization header and no token.
Security Impact
Yes/No):NoYes/No):YesYes/No):NoYes/No):NoYes/No):NoYes, explain the risk and mitigation: The same complete Windows listener identity is required after the successful guest probe before a strong credential is returned. Existing PID/start-time/path and address-family completeness checks remain. The preexisting post-return time-of-use window is not claimed to be eliminated. Only explicit dummy credentials such astest-auth-tokenmay be used for proof; never publish actual tokens or token-bearing URLs.Compatibility and Migration
Yes/No):YesYes/No):NoYes/No):NoReview Conversations
All body/comments/new replies/commit history/current reviews and inline threads were read. No submitted reviews or inline threads were present. ClawSweeper durable revision 12 now credits the real relay traces and green CI while requesting final-effect proof; it is advisory, not merge authority. Its earlier omission of the appended trace was superseded by that fresh review. The maintainer independently narrows the current request to two service/request observations, not generic native screenshots. Contributor history/attribution and older evidence are preserved. No source rewrite, force-push, workflow/auth/admin bypass, superseding PR, merge, or archival was performed.