fix: complete setup and recover interrupted session state - #51
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs real behavior proof before merge. Reviewed September 17, 2026, 4:01 PM ET / 20:01 UTC (Revision 27). ClawSweeper reviewWhat this changesThe Windows launcher adds diagnostic bundles and session-free setup, reconciles interrupted session state, and coordinates gateway recovery with teardown. Merge readiness⛔ Blocked before merge - 4 items remain This remains useful, unmerged work. Earlier cleanup and fixture defects are addressed in the current source; the remaining blocker is proof of rejection at the guest-to-host diagnostics boundary. Priority: P2 Review scores
Verification
How this fits togetherThe Windows launcher prepares and manages OpenClaw inside an isolated agent session. Its diagnostics path collects guest files through a shared workspace, then reads and removes those files using the signed-in user's authority. flowchart TD
A[Operator commands] --> B[Windows launcher]
B --> C[Recorded session and setup state]
C --> D[Isolated agent session]
D --> E[Shared diagnostics staging]
E --> F[Generation and file containment checks]
F --> G[Redacted ZIP and staging cleanup]
Before merge
Findings
Agent review detailsSecurityNeeds attention: The prior cleanup defect is repaired, but diagnostics boundary rejection still needs final-effect evidence. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Retain generation-bound, handle-validated diagnostics access and establish its rejection behavior through the production collection boundary before landing. Do we have a high-confidence way to reproduce the issue? Not applicable as a current-main bug reproduction: this extends an unmerged isolation stack. Source and regression tests establish the intended recovery cases, but no runtime reproduction was executed during this review. Is this the best way to solve the issue? Yes, the current handle-based cleanup and persisted reconciliation are a maintainable direction; final-effect boundary proof remains necessary to establish merge readiness. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 685ee93b7ebb. LabelsLabel justifications:
EvidenceSecurity concerns:
What I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (26 earlier review cycles; latest 8 shown)
|
b862f23 to
364ceec
Compare
364ceec to
cb1939e
Compare
cb1939e to
7ed8a25
Compare
7ed8a25 to
f03c305
Compare
f03c305 to
0fecd32
Compare
261464c to
166d399
Compare
166d399 to
4389d95
Compare
4389d95 to
22d31b2
Compare
22d31b2 to
3ba6c64
Compare
024730b to
e456f4f
Compare
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 97c31f3f-0c7b-43e8-b979-6418dcb7fedc
What Problem This Solves
Interrupted setup and lifecycle transitions need to recover accurately without binding gateway state to the wrong session or hiding the reason a gateway exited.
User Impact
Setup can reconcile its durable state, retry a launch whose outcome was not confirmed, and use a guest-visible working directory. Status and stop commands expose the gateway detail when it is available.
Why This Change Was Made
The lifecycle requires a durable completion marker and reconciles stale provisions rather than accepting a superficially completed setup. Gateway records are scoped to the current session, and teardown removes gateway recovery registration.
Review fixes addressed
NodeRuntimeInstaller.EnsureInstalled.--install-tools, and the default working directory is the guest-visible session workspace unless explicitly configured.clawctl gateway-service status.Current validation
Latest hosted follow-up: The lifecycle-recovery test fixture no longer references the later-layer
AliasCommandoption, restoring this PR's independent layer compile. Its static-analysis quality gate and 22 focusedProgramTestspass, and the replayed final tip passes the full 628-test suite.Handle-bound cleanup follow-up: diagnostics collection now retains a generation-aware workspace operation across guest collection, final bundle reads, and success/failure cleanup. Staged files are opened through that operation, and cleanup deletes relative to its validated workspace handle only while the recorded session generation remains current; the previous path-based recursive
Directory.Deleteflow is removed.Current layer head:
6b08ee1a23890cb39260a917c588fe4deccc46f2. This layer is included in the final integrated stack tipcce2b02f3acd5791654b7a6b1a5a9c27db5ff63brebased onto685ee93b7ebbec1e784205a3544c460bea740e11.Integrated local gates: exact .NET SDK 10.0.100;
Test-DotNetQuality.ps1with 0 warnings/errors; full solution tests 642/642; NativeAOT x64 and ARM64 publishes for both launcher and session host; NativeAOT CLI, deployment, MXC, signing, runtime-input, release-identity, bundle, isolation-plugin, and packaging-relevance policy suites.Live x64 MXC evidence: final-tip Developer Mode deployment registered
OpenClaw.Gateway_0.1.2451.40134_x64__kaa03rpbbqef6from workflow payload run 35191206689;openclaw --versionreturnedOpenClaw 2026.9.4 (3a9d69d);clawctl statusconfirmed the isolated session was running. Earlier final-tip validation also exercised setup, Node.js 24.20.0 reuse, package-qualified activation, detached gateway launch, and redacted diagnostics collection.Signed package evidence: local NativeAOT x64 and ARM64 packages and a multi-architecture bundle were composed and test-signed. Elevated upgrade validation passed all four proof-release transitions (
v0.0.0.0andv0.0.0.1, standalone and bundle), retained package-family LocalState in every transition, and accepted fresh standalone and bundle installs. The temporary certificate and test package were removed, then the Developer Mode registration was restored.Layer 9 of 12. Parent: #50 - feat/session-diagnostics. Child: #52 - feat/session-fresh-reset