fix: make Windows Launcher isolation status informational - #78
Conversation
Remove unsupported isolation commands and copy controls. Show Running and Active only with the captured enabled report, and report all other isolation signals as invalid with HTTP 503. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep isolation reports informational, replace unsupported controls with verified general command references, and cover sandbox clipboard fallback and accessible feedback. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the agent shell and Gateway chat UI distinct, preserve copy-only behavior, and fit all seven references without clipping. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the stable signing policy separate and reject incompatible official workflow inputs before building. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use a native ARM64 runner, reject incompatible inspection hosts before staging, and isolate the plugin snapshot cache for every CLI probe. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 22, 2026, 2:10 PM ET / 18:10 UTC (Revision 7). ClawSweeper reviewWhat this changesMakes the Windows Launcher page informational, adds seven copyable command references, enables its bundled plugin by default, and updates Windows payload validation and regression coverage. Merge readiness⛔ Blocked before merge - 4 items remain Keep open: the informational page and default activation remain distinct from main and the latest release. No blocking code defect was found; the outstanding product and upgrade decisions remain unresolved. Priority: P2 Review scores
Verification
How this fits togetherThe Windows package launches OpenClaw inside an isolated agent session. Its bundled Windows Launcher plugin turns a captured launcher report into an authenticated Control UI page, while payload validation checks plugin activation before packaging. flowchart LR
A[Windows launcher] --> B[Captured isolation report]
C[Plugin preferences] --> D[Upstream plugin activation]
B --> E[Windows Launcher plugin]
D --> E
E --> F[Authenticated status page]
F --> G[Status and copyable commands]
Decision needed
Why: The implementation preserves explicit preferences, but deciding to activate an existing optional surface and accepting incomplete upgrade coverage requires maintainer intent. Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Keep the existing read-only plugin owner, preserve explicit operator preferences, and qualify a maintainer-approved activation default across fresh installation and healthy upgrade. Do we have a high-confidence way to reproduce the issue? Not applicable as a single bug reproduction: this PR combines informational UI changes with a deliberate activation-default change, supported by installed plugin evidence. Is this the best way to solve the issue? Yes for the implementation approach: it extends the existing plugin and uses upstream activation policy without adding a configuration owner; default rollout remains a maintainer choice. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against d99389ce873d. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (6 earlier review cycles)
|
Validate fresh and existing default profiles without enablement overrides, preserve explicit disables, and share the real plugin registration fixture. Clear only the asserted expected native failure so the Actions PowerShell wrapper succeeds. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve the instruction-file migration by retaining development-runtime and architecture-matched payload rules at their new owners. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Align workflow defaults and approved release identity with the stable runtime containing plugin theme forwarding. Retain unapproved-input signing coverage without a development override. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Adopt main's source-selection and native payload architecture ownership while preserving default-on plugin inspection, explicit disables, and isolated cache handling. Keep the existing official runtime approval and remove the superseded workflow pin validator. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Merge the approved main baseline without changing its automatic setup or eligible gateway start behavior. Generate trusted PowerShell completion inside the isolated payload validation profile and extend the shared fixture while preserving default activation and explicit-disable checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Why is this change being made?
Windows Launcher should report the packaged Gateway's required isolation, not present isolation as a configurable mode. Its informational page should appear by default without overwriting an operator's explicit plugin decision.
What changed?
operator.read, hardened headers, the opaque iframe sandbox and validated live theme forwarding.v2026.9.4at3a9d69db306cd7f081e06254cb89c4bcc14a7107, MSIX revision 3. Qualification ofv2026.9.5does not grant official runtime approval.windows-11-armrunner; cross-composition remains available with a qualified payload.$LASTEXITCODE=1into the Actions wrapper without suppressing unexpected native failures.Head:
dd3cfdb0b97d4cb66645591c270f0193a6a9ee47, incorporating maind99389ce873d474601c19c10d45d034afda69824. Plugin source, tests and manifest are unchanged from the previously qualified872e72958c6cd1dedd1d15de48334d02ab7e0f96. Default activation still needs maintainer acceptance; official runtime approval remains separate.How was the change tested?
Current-head local validation (
dd3cfdb): Passed 52 plugin tests, 1,062 managed tests, zero-warning static analysis and 24 NativeAOT scenarios plus the expected wrong-alias negative. The Gateway isolation plugin and Node runtime input suites passed, including completion generation/reuse, native install architecture, default activation, explicit disable and isolated-cache cleanup. Documentation reported zero findings. The earlier6a8f0c0reconciliation passed all 11 focused PowerShell suites, including 45 source-selection cases and workflow/signing/package/cache/version checks; their unchanged source-selection and official-policy inputs were retained.This head resolves the conflicts with main
d99389ce. No new upstream build, MSIX composition, signing or installed VM/browser cycle was run fordd3cfdb, and no new-head CI success is claimed. Historical CI and installed evidence below do not substitute for validation of a newly composed package.Historical installed x64 recovery and fresh-install proof (
872e729): Tested the locally test-signed MSIX2026.9.500.0with OpenClaw 2026.9.5 and matching build/runtime Node 24.20.0. Package SHA-256:917260192f2ce977badc745ab4512600a7b0b863ea5cabfb7b49f6ac3f27d47d. This evidence applies to the historical candidate, not the reconciled host.falsesurvived restart and supported setup. The plugin was not imported, registered no routes and exposed no tab or iframe; the unregistered route returned 404.allow-scriptsiframe withoutallow-same-origin. Four themes switched on the same frame with zero post-mount navigations, page errors or command-execution requests.Important limitation: Official baseline
2026.9.4.1001installed and setup passed, but its Gateway exited with a native Koffi loading error before becoming ready. That failure remains recorded. The completed lane is failed-baseline recovery, not healthy-baseline upgrade proof. Fresh-install proof is separate. The tested872e729candidate predates main's native-preload, PowerShell-completion and automatic first-launch changes in #86, #88 and #91.Historical source and CI checks (
872e729): Local validation passed 52 plugin tests, 807 managed tests, zero-warning static analysis, 18 NativeAOT scenarios plus the expected wrong-alias negative, and the owning plugin, workflow/signing, release/version, Node runtime, payload/build-identity and documentation checks. Initial failures and successful recoveries remain separate records.Historical PR integration CI used merge commit
20ce92b7aefae10954776573777cf1547bc59fe5, combining main288521d5with872e729, not the current head. Host checks, upstream full build, x64/ARM64 MSIX jobs and multiarchitecture bundling passed. The native ARM64 job used ARM64 Node 24.20.0, built a fresh payload, validated Gateway/UI identity and completed NativeAOT composition. This is historical merge-ref integration evidence, not current-head or installed ARM64 proof.The historical local candidate combines the
872e729host with separately validated CI payload10665831515; its producer contract and injected plugin bytes were verified against that head. Genuine CI metadata remains unchanged. The upstream tarball SHA-256 is8b1a6569f24d0c3739bd62371b1e75c5d0fc8ff2f95c498bbe923d1825f9a991. Registry TLS failures were recovered through supported, integrity-checked payload and MXC archive reuse, without weakening verification.Actual clipboard values and denial recovery
Independent checks of both hash-bound browser results verified 28 exact copy actions and 28 fallback calls. Mouse and keyboard actions produced each value below in both runs; keyboard focus stayed on Copy.
clawctl pwshclawctl gateway-service statusclawctl gateway-service stop && clawctl gateway-service startclawctl --helpopenclaw tuiopenclaw dashboard --no-openopenclaw --helpWith deliberately injected denial,
writeTextthrew andexecCommand("copy")returned false. Both runs retainedUI proof sentinelon the clipboard, selected exactlyclawctl gateway-service status, and displayed:Actual manual Ctrl+C then copied that exact command. This proves recovery from an injected denial, not a naturally observed permission failure.
Historical fresh-installed runtime (872e729): four themes
These captures were inspected visually and identify the exact tested source, runtime, package and local test signing. Earlier recovery images had a stale harness footer and are retained but excluded here; their separate behavioral results identify the correct candidate. These are unchanged
872e729captures, not a new installed run ofdd3cfdb.Healthy-baseline upgrade and installed ARM64 remain unproven. Cleanup covers owned product/provider state, not a global MXC backend inventory. Local test signing and passing checks do not establish official release readiness or replace maintainer scope acceptance.