Skip to content

improve: diagnostics bundles explain failed commands and name the build they ran on - #120

Merged
paulcam206 merged 4 commits into
mainfrom
paulcam206-coworker-diagnostics-investigation
Sep 24, 2026
Merged

paulcam206 merged 4 commits into
mainfrom
paulcam206-coworker-diagnostics-investigation

Conversation

@paulcam206

@paulcam206 paulcam206 commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

What Problem This Solves

Fixes: clawctl collect-logs bundles can't explain a failed setup, command, or gateway start. The openclaw.exe launcher's diagnostic log recorded only an exception type and never named the Windows build, the package version, or how the package was installed. Bundles also left out the gateway's own output, although a failed gateway start tells users to run clawctl collect-logs to capture it.

User Impact

User impact: a clawctl collect-logs bundle now shows why a command or gateway start failed and what it ran on, so a report can be diagnosed without follow-up questions. The command also names each source as it gathers it.

  • Diagnostic log and bundle: every host start records the Windows build and update revision, and how the package was installed:

    • Developer Mode loose-layout registration;
    • Store-signed install;
    • developer-signed MSIX.

    It also records the package, OpenClaw payload, MXC, Node.js, and .NET versions. Failures record their message, MXC error and failing operation, Windows error code, and inner causes. Every gateway start records its outcome and the message the user saw.

  • Gateway launch logs: gateway/ in the ZIP holds each gateway launch's own output and supervisor status, including earlier launches that a later start replaced. Only the newest 10 launches are kept, and each file is cut to its last 1 MiB.

  • Narration: collect-logs narrates each source on standard error. --json output is unchanged and narrates nothing.

  • Console output (failure paths only):

    • collect-logs notes about files it couldn't collect now include the underlying cause.
    • A failed gateway inspection or stop now adds The guest reported: <reason>.
    • An unreadable MXC executor response now includes its exit code and diagnostics.
  • Risk: bundles now carry full failure messages, gateway output, and the install path. For a local loose-layout deployment, that path is the developer's checkout. Redaction now also covers:

    • URL query or fragment credentials, such as a Control UI link's #token=;
    • environment-style assignments;
    • HTTP authorization header credentials.

    The bundle's "review before sharing" guidance still applies. Redaction applies to every collected file, to manifest.txt, and to the notes collect-logs prints, because a note can quote a failure's raw detail. Browser-launch failures still log only a Windows error code, because the message would contain the Control UI URL and its token.

Why This Change Was Made

A field bundle from a failed clawctl setup contained only Unhandled failure: MxcException. MXC had provisioned the isolated session and then refused to start it, but the backend's error, code, and failing operation were dropped. Several other failures reached only the console: status probes, gateway inspection and stop, readiness probes, and logon-task registration.

A second field bundle came from a gateway that failed twice with another OpenClaw process owns gateway-lifecycle, because an embedded TUI from onboarding was still running. That bundle had neither launch's output or supervisor status, and the first failure came from a launch the gateway record no longer named. Its host log showed each start beginning but never how it ended.

One failure formatter now owns what the log records. Each host start writes one Environment: line, and every bundle's manifest repeats it. The gateway controller logs each start's outcome in the one method every start path goes through. #109 added timing records that intentionally log only exception types. The failure records added here are separate, and docs/architecture.md describes both.

Implementation notes
  • DiagnosticFailure formats a failure as its type and message, then MXC code, backend code, and operation, then Win32 error or HRESULT, then every inner cause. Aggregated causes are numbered. The last-chance handler also records stack traces.
  • MxcException carries the error envelope's operation. When the executor produces no parsable envelope, the error keeps its exit code, its diagnostics, and up to 512 characters of its output.
  • Wrapping exceptions at result-read and protocol JSON boundaries now keep their inner exception. Attached openclaw and clawctl pwsh runs log their exit code, so a missing exit line shows that the host was killed.
  • HostEnvironment reads the package origin through GetStagedPackageOrigin (exported by kernelbase.dll) and development mode through GetCurrentPackageInfo. Any fact it can't read is described as unavailable, so the environment line never fails a command.
  • collect-logs progress uses fix: clawctl commands show nothing until long operations finish #108's NarrateOperationAsync, and the handler takes host paths from the session runtime, as its sibling handlers do.
  • The gateway launch files are read host-side from the shared workspace through SessionWorkspaceOperation/TrustedPath, so a session that can no longer start still yields them. Only gateway-<recorded generation>-*.log and .status.json are taken. Reparse points are refused, launches are grouped and the newest 10 kept, and each read is bounded to its last 1 MiB and cut at a line boundary.
  • Every DiagnosticsRedactor pattern now runs with RegexOptions.NonBacktracking. The redacted text is largely guest-written, and the backtracking engine took quadratic time on crafted input; one 360 KB line exceeded a 5 s cap, compared with 16 ms now. A NativeAOT scenario runs the redactor.
  • Bundle notes, and the manifest's environment line, pass through the same redactor before they are written or returned. A note can quote a failure's full detail, which for a malformed MXC response includes the executor's raw output.
  • Guest-written text logged by the host passes through DiagnosticFailure.SingleLine, so a line break or escape sequence cannot forge a host-log entry.
  • gateway-service status no longer prints a gateway log tail. The code that did, GatewayControlOutput, has had no production caller since Improve clawctl output readability and color #66. The troubleshooting guide now points to the collected launch logs instead; removing or rewiring that class is left for a follow-up.

Evidence

Head: ec45dcb9ef737889cba3097e62d6891cb0474b9a, rebased onto main 6191262. The automated lanes and the real run below come from this head on the author's Windows machine. The origin-mapping probe is a read-only OS check that doesn't depend on any code.

Automated lanes (at ec45dcb)

  • .\scripts\Test-DotNetQuality.ps1: passed with 0 warnings and 0 errors.
  • dotnet test .\OpenClaw.Gateway.MSIX.slnx --configuration Release --no-restore: 1202 passed, 0 failed. This includes:
    • end-to-end tests of the real collect-logs handler: the per-source narration appears in order on standard error and the result on standard output, and --json produces one parsable document with empty standard error;
    • a bundle test modeled on the second field bundle. An earlier failed launch and a later launch both land under gateway/ with their supervisor status. The Control UI #token= in the later log is redacted. A request file and another generation's log are left out;
    • bounds tests: 12 launches keep the newest 10 with a note, and a 2 MiB log keeps its last 1 MiB from a line boundary, ending with its final line;
    • a bundle test that drives malformed executor output carrying a bearer token and an OPENAI_API_KEY= assignment through the real MXC client. Neither credential reaches manifest.txt or the returned notes, while the failure detail does;
    • tests that a start logs its outcome for both an exit during startup and a listening gateway, and that guest text with CR/LF and an escape sequence stays on one log line;
    • redaction tests for URL, environment, and header credentials, including a 4-character Basic credential, prose that must survive, and crafted guest input under a 30 s timeout.
  • .\scripts\Test-NativeAotCli.Tests.ps1: 29 scenarios passed under the clawctl alias, including package-provenance binding and redaction under NativeAOT. The rerun under a wrong executable name fails only the alias check, as designed.
  • .\scripts\Test-DocReferences.ps1: 0 findings. git diff --check: clean.

Review findings addressed

  • An independent code review of the gateway-launch-log commit found three issues, all fixed: quadratic backtracking in redaction, authorization matching that altered prose and missed short credentials, and guest line breaks reaching the host log.
  • ClawSweeper's review of 8b80863 found that bundle notes quoting raw MXC executor output reached manifest.txt and the command's output without redaction. ec45dcb redacts every note and the manifest's environment line, and adds the regression test above.

Real run (at ec45dcb)

Environment:

  • Side-by-side Developer Mode deployment: Deploy-LocalPackage.ps1 -Patch diag-ec45dcb -Architecture x64, which also ran clawctl setup.
  • Windows build 26693.1000, main payload run 36059536555 (OpenClaw 2026.9.5, ec9c1a13).
  • clawctl-diag-ec45dcb --version reported commit ec45dcb9ef737889cba3097e62d6891cb0474b9a.
  • The Store-signed base install was left in place.

Gateway starts, in order:

  1. With no OpenClaw config yet, gateway-service start exited 1 with exited during startup … The supervisor reported: the application exited with code 78.
  2. After gateway.mode local and a free port (59363) were set through clawctl-diag-ec45dcb pwsh --command, the next start failed with The gateway's state could not be established, so a new one was not started: Access is denied.
    • This came from the in-session inspector's handle to the previous launch's recorded process, a pre-existing path this PR doesn't change. That PID was no longer running when checked from the host afterwards.
    • gateway-service status then reported the earlier launch as stopped with exit code 78.
    • This is tracked as a follow-up rather than fixed here.
  3. The retried start exited 0 and reported listening on 59363.

collect-logs --no-color with the two streams redirected to separate files exited 0 in 550 ms. Standard error (narration):

  Collecting redacted diagnostics.
  Starting the isolated session.
  Collecting OpenClaw logs and configuration from the isolated session.
  Collecting the host diagnostic log.
  Collecting the setup record.
  Collecting the session record.
  Collecting the gateway record.
  Collecting the gateway recovery launcher.
  Collecting the gateway launch logs.
  Adding the OpenClaw logs and configuration from the isolated session.

Standard output contained only the result: Included: host and session diagnostics, the review guidance, and the bundle path on its own line. collect-logs --json exited 0 in 486 ms, with 0 bytes on standard error and one document containing "ok": true, "included": "host-and-session", and "notes": [].

The bundle held 13 entries, including two launches under gateway/, newest first:

gateway/gateway-<generation>-<launch 3>.log          …[gateway] ready …
gateway/gateway-<generation>-<launch 3>.status.json  {"state":"running", … "detail":"supervising process …"}
gateway/gateway-<generation>-<launch 1>.log          Missing config. Run `openclaw setup` or set gateway.mode=local (or pass --allow-unconfigured).
gateway/gateway-<generation>-<launch 1>.status.json  {"state":"exited", … "detail":"the application exited with code 78"}

The earlier failed launch is collected even though the gateway record now names the later one. The bundled host log records each start's outcome and the transient inspection failure:

… Gateway start finished: Stopped. The gateway process exited during startup. The supervisor reported: the application exited with code 78 Run `clawctl collect-logs` to capture the gateway log.
… Gateway inspection failed in the session: Access is denied.
… Unhandled failure: SessionException: The gateway's state could not be established, so a new one was not started: Access is denied.
… Gateway start finished: Running. The gateway is running on port 59363.

manifest.txt, read inside the packaged process:

Environment: Windows 10.0.26693.1000 (X64 OS, X64 process); package OpenClawFoundation.OpenClawGateway-diag-ec45dcb_0.1.2458.54464_x64__rfcbke2p71se2 (Developer Mode loose-layout registration, origin DeveloperUnsigned) at <checkout>\artifacts\local-package\patches\diag-ec45dcb\x64\layout, build 0.1.2458.54464 (commit ec45dcb9ef737889cba3097e62d6891cb0474b9a); OpenClaw payload 2026.9.5 (commit ec9c1a13db8938e5a3eaa51fca2e981cde2395a9); MXC @microsoft/mxc-sdk 0.8.0 x64, wire 0.6.0-alpha; Node.js 24.20.0; .NET 10.0.12
  • The host log also has the setup-time support evidence (Supported from BackendProbe evidence; host build 26693.1000; … backend probe isolation sessions available, tier base-container, warnings none) and the pwsh exit (PowerShell 7 exited with code 0.).
  • A scan for credential-shaped values across all 13 bundle entries found no raw credentials.
  • Afterwards, the gateway was stopped, clawctl-diag-ec45dcb teardown --force removed the session, and Deploy-LocalPackage.ps1 -Unregister -Patch diag-ec45dcb unregistered the patch.

Origin mapping

A read-only GetStagedPackageOrigin probe of the machine's installed packages matched Get-AppxPackage (2026-09-23):

SignatureKind Origin Packages
Store Store 53
Developer DeveloperSigned 27
System Inbox 45
None (development mode) DeveloperUnsigned 1

This product's own Store install, OpenClawFoundation.OpenClawGateway_2026.9.404.0_x64__rfcbke2p71se2, reports origin Store (2026-09-24).

Local ClawSweeper range review at ec45dcb against main 6191262: the patch was reviewed as correct (confidence 0.86), security cleared, and real behavior proof sufficient, with no findings.

Not run

  • A Store-signed or developer-signed MSIX built from this change and reporting its own provenance. The real runs used a Developer Mode layout; the other origins rest on the read-only probe.
  • MSIX packaging lanes and the PowerShell script suites. This change touches no scripts or packaging inputs.

paulcam206 and others added 3 commits September 24, 2026 14:19
A field bundle recorded only "Unhandled failure: MxcException": setup had
provisioned a session and MXC refused to start it, but the host log dropped
the backend's error and the bundle named neither the build nor how it was
installed.

- Log every failure through one describer: type, message, MXC code, backend
  code and failing operation, Win32 error or HRESULT, and every inner cause.
  The last-chance handler also records stack traces.
- Carry the MXC error envelope's operation on MxcException, and keep exit
  code, diagnostics, and a bounded output excerpt when no envelope parses.
- Log failures that previously reached only the console: status probes,
  gateway inspection and stop, readiness probes, recovery registration,
  JSON setup, and open. Keep the guest's own error on a failed inspection.
- Preserve inner exceptions at result-read and protocol JSON wraps, and log
  how each attached run ended.
- Record an Environment line at every host start and in the collect-logs
  manifest: Windows build and UBR, architectures, package full name with
  origin (Developer Mode loose layout, Store-signed, developer-signed MSIX)
  and install path, package and payload versions, MXC runtime and wire
  schema, Node.js, and .NET. Log the support decision's evidence too.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
collect-logs narrated a single opening status while it started the
isolated session and collected guest files. It now reports each source as
it gathers it: the session start, the OpenClaw logs and configuration
collected inside it, each host record read into the bundle, and the staged
agent files. The progress flows through the shared NarrateOperationAsync
path, so narration stays on standard error, redirected standard error
keeps a line per source, and --json narrates nothing.

The handler now takes host paths from the session runtime, as its sibling
handlers do, so the narrated path is covered end to end.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
…tcome

A field bundle for a gateway that failed twice held neither launch's own
output nor supervisor status, although the failure message tells users that
collect-logs captures the gateway log. The host log also recorded only that
each start began, never how it ended.

- Collect each gateway launch's log and supervisor status from the shared
  workspace, including earlier launches the gateway record no longer names.
  Files must carry the recorded session generation, reparse points are
  refused, only the newest 10 launches are kept, and each file is cut to its
  last 1 MiB. Reading them needs no running session.
- Log every gateway start's outcome, covering gateway-service start and
  restart and the automatic start after openclaw.
- Redact URL query or fragment credentials, environment-style assignments,
  and HTTP authorization header credentials. Run every redaction pattern
  non-backtracking, so crafted guest text cannot stall collection.
- Keep guest-written text on its own host-log line.
- Point the troubleshooting guide at the collected launch logs instead of a
  status log tail that is no longer printed.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@paulcam206
paulcam206 force-pushed the paulcam206-coworker-diagnostics-investigation branch from 5aa83b9 to 8b80863 Compare September 24, 2026 21:38
@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. labels Sep 24, 2026
@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 24, 2026, 6:30 PM ET / 22:30 UTC (Revision 2).

ClawSweeper review

What this changes

The branch adds build and failure details to Windows host diagnostics, includes bounded gateway launch files in collected ZIPs, and narrates collection progress.

Merge readiness

✅ Ready for maintainer review

Keep open. Current main still lacks the requested diagnostic evidence. The latest head addresses the previous manifest-redaction finding, and an exact-head Windows run supports the repair.

Priority: P2
Reviewed head: ec45dcb9ef737889cba3097e62d6891cb0474b9a

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) The exact-head Windows run and focused tests support a broad but coherent diagnostic repair.
Proof confidence 🦞 diamond lobster (5/6) Sufficient (terminal): At the exact head, an x64 Windows Developer Mode clawctl run collected a prior failed gateway launch and a later running launch into one ZIP, showed build provenance and source narration, and kept JSON narration silent. Signed MSIX origins and ARM64 were not run; no stored-data contract changed.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (terminal): At the exact head, an x64 Windows Developer Mode clawctl run collected a prior failed gateway launch and a later running launch into one ZIP, showed build provenance and source narration, and kept JSON narration silent. Signed MSIX origins and ARM64 were not run; no stored-data contract changed.
Evidence reviewed 8 items Current main does not collect gateway launches: The main-branch collector gathers host and staged agent files; its collection path has no gateway launch file gathering or environment argument.
Introduced collection path: The proposed collector finds launch files for the recorded session generation and reads them through the workspace operation, with a ten-launch selection and bounded file tails.
Prior finding addressed: The manifest environment line and every returned or written failure note now pass through the redactor. A bundle test checks that credential-shaped MXC output is absent from both the manifest and returned notes.
Findings None None.
Security None None.

How this fits together

The Windows launcher manages the isolated session and gateway, and records host diagnostics. clawctl collect-logs gathers those records with agent and gateway files into a redacted ZIP for troubleshooting.

flowchart LR
  A[clawctl commands] --> B[Windows launcher]
  B --> C[Isolated session and gateway]
  B --> D[Host diagnostics]
  C --> E[Agent and gateway files]
  D --> F[Bundle collector]
  E --> F
  F --> G[Redacted ZIP and notes]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Code and test growth production +982/-104 lines; tests +1541/-20 lines The stated diagnostic and bundle gaps explain the production growth, with substantial focused regression coverage.

Technical review

Best possible solution:

Keep diagnostics in the existing launcher and bundle owners, with bounded gateway history, useful failure context, and redaction before ZIP or note output.

Do we have a high-confidence way to reproduce the issue?

Yes. On current main, a failed gateway start followed by clawctl collect-logs has a clear source path that omits gateway launch files; this review did not execute that baseline on Windows.

Is this the best way to solve the issue?

Yes. The branch extends the existing diagnostic bundle owner and uses the existing command narration path; the exact-head Windows run demonstrates the intended collected output.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning high; reviewed against b06135e97580.

Labels

Label changes:

  • add proof: sufficient: Contributor real behavior proof is sufficient. At the exact head, an x64 Windows Developer Mode clawctl run collected a prior failed gateway launch and a later running launch into one ZIP, showed build provenance and source narration, and kept JSON narration silent. Signed MSIX origins and ARM64 were not run; no stored-data contract changed.
  • add rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🦞 diamond lobster and patch quality is 🐚 platinum hermit.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (terminal): At the exact head, an x64 Windows Developer Mode clawctl run collected a prior failed gateway launch and a later running launch into one ZIP, showed build provenance and source narration, and kept JSON narration silent. Signed MSIX origins and ARM64 were not run; no stored-data contract changed.
  • remove rating: 🦐 gold shrimp: Current PR rating is rating: 🐚 platinum hermit, so this older rating label is no longer current.
  • remove status: ⏳ waiting on author: Current PR status label is status: 👀 ready for maintainer look.
  • remove merge-risk: 🚨 security-boundary: Current PR review selected no merge-risk labels.

Label justifications:

  • P2: This improves diagnosis of Windows setup and gateway failures with a limited user-facing blast radius.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🦞 diamond lobster and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (terminal): At the exact head, an x64 Windows Developer Mode clawctl run collected a prior failed gateway launch and a later running launch into one ZIP, showed build provenance and source narration, and kept JSON narration silent. Signed MSIX origins and ARM64 were not run; no stored-data contract changed.
  • proof: sufficient: Contributor real behavior proof is sufficient. At the exact head, an x64 Windows Developer Mode clawctl run collected a prior failed gateway launch and a later running launch into one ZIP, showed build provenance and source narration, and kept JSON narration silent. Signed MSIX origins and ARM64 were not run; no stored-data contract changed.

Evidence

What I checked:

  • Current main does not collect gateway launches: The main-branch collector gathers host and staged agent files; its collection path has no gateway launch file gathering or environment argument. (src/OpenClaw.Launcher/Gateway/DiagnosticsBundle.cs:100, b06135e97580)
  • Introduced collection path: The proposed collector finds launch files for the recorded session generation and reads them through the workspace operation, with a ten-launch selection and bounded file tails. (src/OpenClaw.Launcher/Gateway/DiagnosticsBundle.cs:205, ec45dcb9ef73)
  • Prior finding addressed: The manifest environment line and every returned or written failure note now pass through the redactor. A bundle test checks that credential-shaped MXC output is absent from both the manifest and returned notes. (src/OpenClaw.Launcher/Gateway/DiagnosticsBundle.cs:456, ec45dcb9ef73)
  • Redaction regression coverage: The test drives malformed output through the MXC client and asserts that bearer and API-key values do not appear in the generated ZIP manifest or returned notes. (tests/OpenClaw.Launcher.Tests/Gateway/DiagnosticsBundleTests.cs:340, ec45dcb9ef73)
  • Exact-head Windows behavior proof: The full PR body matches the captured body hash 9a7a33d3451855b0bd3ceeacf6790766b3849aa1a4e319ec569336c469ad2310. It records an x64 Developer Mode run at this head: a failed gateway launch and a later running launch both appeared in the collected ZIP, alongside build provenance; redirected narration and silent JSON output were observed. (ec45dcb9ef73)
  • MXC contract signal: The changed MXC client parses executor responses and incorporates a bounded excerpt when no failure envelope parses; this is the source of the failure detail exercised by the redaction test. (src/OpenClaw.Launcher/Mxc/MxcCliSessionClient.cs:243, ec45dcb9ef73)

Likely related people:

  • paulcam206: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-09-24T21:49:24.732Z sha 8b80863 :: blocked before merge. :: [P2] Redact expanded failure notes before writing the manifest

A failure note quotes the failure's full detail, which for a malformed MXC
response includes the executor's raw output and diagnostics. The notes were
written to manifest.txt and returned for console and JSON output without
the redaction applied to collected file text, so a credential-shaped value in
executor output could leave the machine in a shared bundle.

Every note, and the manifest's environment line, now passes through
DiagnosticsRedactor before it is written or returned. A bundle test drives
malformed executor output carrying a bearer token and an API key assignment
through the real MXC client and asserts neither reaches the manifest or the
returned notes, while the failure detail itself survives.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: ⏳ waiting on author ClawSweeper has contributor-facing work open and is waiting for author action. merge-risk: 🚨 security-boundary 🚨 Merging this PR could weaken sandboxing, authorization, credentials, or sensitive data. labels Sep 24, 2026
@paulcam206
paulcam206 marked this pull request as ready for review September 24, 2026 22:31
@clawsweeper

clawsweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper

clawsweeper Bot commented Sep 24, 2026

Copy link
Copy Markdown

ClawSweeper status: review started.

I am starting a fresh review of this pull request: improve: diagnostics bundles explain failed commands and name the build they ran on This is item 1/1 in the current shard. Shard 0/1.

This temporary status tracks the active review worker. The completed review will appear in the durable ClawSweeper review comment.

Crustacean status: shell secured, claws on keyboard, evidence pebbles being sorted.

@paulcam206
paulcam206 merged commit 524c789 into main Sep 24, 2026
20 checks passed
@paulcam206
paulcam206 deleted the paulcam206-coworker-diagnostics-investigation branch September 24, 2026 22:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant