Skip to content

fix: make Windows Launcher isolation status informational - #78

Merged
xlinush merged 15 commits into
openclaw:mainfrom
ChazGo:chazgo-informational-isolation-plugin
Sep 22, 2026
Merged

xlinush merged 15 commits into
openclaw:mainfrom
ChazGo:chazgo-informational-isolation-plugin

Conversation

@ChazGo

@ChazGo ChazGo commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Why is this change being made?

Windows Launcher should report the packaged Gateway's required isolation, not present isolation as a configurable mode. Its informational page should appear by default without overwriting an operator's explicit plugin decision.

What changed?

  • Removed isolation controls and enable/disable guidance. The captured launcher signal reports Gateway Isolation: Active; missing, malformed or unsupported reports produce neutral Invalid status.
  • Added seven accessible, copy-only command references with user-session and agent-session guidance. The page never executes commands.
  • Enabled the bundled plugin by default while preserving explicit disable, global disable, denylist and restrictive allowlist decisions.
  • Preserved authenticated read-only access, operator.read, hardened headers, the opaque iframe sandbox and validated live theme forwarding.
  • Adopted main's stable-source selection, immutable retry snapshots and signing validation. Official approval remains OpenClaw v2026.9.4 at 3a9d69db306cd7f081e06254cb89c4bcc14a7107, MSIX revision 3. Qualification of v2026.9.5 does not grant official runtime approval.
  • Combined Windows/native Node validation with main's install-architecture and cache-provenance checks. ARM64 payload jobs retain main's windows-11-arm runner; cross-composition remains available with a qualified payload.
  • Preserved main's PowerShell completion and automatic clean-install setup/eligible Gateway start behavior unchanged. Completion generation and reuse remain inside isolated payload validation alongside the plugin checks.
  • Fixed an expected-failure test leaking $LASTEXITCODE=1 into the Actions wrapper without suppressing unexpected native failures.

Head: dd3cfdb0b97d4cb66645591c270f0193a6a9ee47, incorporating main d99389ce873d474601c19c10d45d034afda69824. Plugin source, tests and manifest are unchanged from the previously qualified 872e72958c6cd1dedd1d15de48334d02ab7e0f96. Default activation still needs maintainer acceptance; official runtime approval remains separate.

How was the change tested?

Current-head local validation (dd3cfdb): Passed 52 plugin tests, 1,062 managed tests, zero-warning static analysis and 24 NativeAOT scenarios plus the expected wrong-alias negative. The Gateway isolation plugin and Node runtime input suites passed, including completion generation/reuse, native install architecture, default activation, explicit disable and isolated-cache cleanup. Documentation reported zero findings. The earlier 6a8f0c0 reconciliation passed all 11 focused PowerShell suites, including 45 source-selection cases and workflow/signing/package/cache/version checks; their unchanged source-selection and official-policy inputs were retained.

This head resolves the conflicts with main d99389ce. No new upstream build, MSIX composition, signing or installed VM/browser cycle was run for dd3cfdb, and no new-head CI success is claimed. Historical CI and installed evidence below do not substitute for validation of a newly composed package.

Historical installed x64 recovery and fresh-install proof (872e729): Tested the locally test-signed MSIX 2026.9.500.0 with OpenClaw 2026.9.5 and matching build/runtime Node 24.20.0. Package SHA-256: 917260192f2ce977badc745ab4512600a7b0b863ea5cabfb7b49f6ac3f27d47d. This evidence applies to the historical candidate, not the reconciled host.

  • Recovery preserved configuration, a workspace canary, session identity and Node bytes, then passed startup, readiness, native-command and browser checks.
  • Clean fresh installation passed setup, native-command, default-activation and browser checks.
  • Explicit false survived restart and supported setup. The plugin was not imported, registered no routes and exposed no tab or iframe; the unregistered route returned 404.
  • Both browser runs used the actual launcher signal, not an injected enabled fixture. Authenticated requests returned 200 inside an allow-scripts iframe without allow-same-origin. Four themes switched on the same frame with zero post-mount navigations, page errors or command-execution requests.
  • Final stop, collection, teardown, uninstall and owned test-certificate removal passed. Independent final inventory showed no product package, state records, scheduled tasks, listeners or processes; owned provider tasks/children and the SSH tunnel were removed. Official trust was unchanged.

Important limitation: Official baseline 2026.9.4.1001 installed and setup passed, but its Gateway exited with a native Koffi loading error before becoming ready. That failure remains recorded. The completed lane is failed-baseline recovery, not healthy-baseline upgrade proof. Fresh-install proof is separate. The tested 872e729 candidate predates main's native-preload, PowerShell-completion and automatic first-launch changes in #86, #88 and #91.

Historical source and CI checks (872e729): Local validation passed 52 plugin tests, 807 managed tests, zero-warning static analysis, 18 NativeAOT scenarios plus the expected wrong-alias negative, and the owning plugin, workflow/signing, release/version, Node runtime, payload/build-identity and documentation checks. Initial failures and successful recoveries remain separate records.

Historical PR integration CI used merge commit 20ce92b7aefae10954776573777cf1547bc59fe5, combining main 288521d5 with 872e729, not the current head. Host checks, upstream full build, x64/ARM64 MSIX jobs and multiarchitecture bundling passed. The native ARM64 job used ARM64 Node 24.20.0, built a fresh payload, validated Gateway/UI identity and completed NativeAOT composition. This is historical merge-ref integration evidence, not current-head or installed ARM64 proof.

The historical local candidate combines the 872e729 host with separately validated CI payload 10665831515; its producer contract and injected plugin bytes were verified against that head. Genuine CI metadata remains unchanged. The upstream tarball SHA-256 is 8b1a6569f24d0c3739bd62371b1e75c5d0fc8ff2f95c498bbe923d1825f9a991. Registry TLS failures were recovered through supported, integrity-checked payload and MXC archive reuse, without weakening verification.

Actual clipboard values and denial recovery

Independent checks of both hash-bound browser results verified 28 exact copy actions and 28 fallback calls. Mouse and keyboard actions produced each value below in both runs; keyboard focus stayed on Copy.

Expected and actual clipboard value Keyboard activation
clawctl pwsh Enter
clawctl gateway-service status Space
clawctl gateway-service stop && clawctl gateway-service start Enter
clawctl --help Space
openclaw tui Enter
openclaw dashboard --no-open Space
openclaw --help Enter

With deliberately injected denial, writeText threw and execCommand("copy") returned false. Both runs retained UI proof sentinel on the clipboard, selected exactly clawctl gateway-service status, and displayed:

Copy unavailable. Gateway status command selected; press Ctrl+C to copy.

Actual manual Ctrl+C then copied that exact command. This proves recovery from an injected denial, not a naturally observed permission failure.

Historical fresh-installed runtime (872e729): four themes

These captures were inspected visually and identify the exact tested source, runtime, package and local test signing. Earlier recovery images had a stale harness footer and are retained but excluded here; their separate behavioral results identify the correct candidate. These are unchanged 872e729 captures, not a new installed run of dd3cfdb.

Installed Windows Launcher with default dark theme

Installed Windows Launcher with default light theme

Installed Windows Launcher with imported custom light theme

Installed Windows Launcher with imported custom dark theme

Healthy-baseline upgrade and installed ARM64 remain unproven. Cleanup covers owned product/provider state, not a global MXC backend inventory. Local test signing and passing checks do not establish official release readiness or replace maintainer scope acceptance.

Chaz Gordish and others added 9 commits September 17, 2026 18:38
Remove unsupported isolation commands and copy controls. Show Running and Active only with the captured enabled report, and report all other isolation signals as invalid with HTTP 503.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep isolation reports informational, replace unsupported controls with verified general command references, and cover sandbox clipboard fallback and accessible feedback.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the agent shell and Gateway chat UI distinct, preserve copy-only behavior, and fit all seven references without clipping.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the stable signing policy separate and reject incompatible official workflow inputs before building.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use a native ARM64 runner, reject incompatible inspection hosts before staging, and isolate the plugin snapshot cache for every CLI probe.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@clawsweeper

clawsweeper Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 18, 2026
@clawsweeper

clawsweeper Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Codex review: blocked before merge. Reviewed September 22, 2026, 2:10 PM ET / 18:10 UTC (Revision 7).

ClawSweeper review

What this changes

Makes the Windows Launcher page informational, adds seven copyable command references, enables its bundled plugin by default, and updates Windows payload validation and regression coverage.

Merge readiness

⛔ Blocked before merge - 4 items remain

Keep open: the informational page and default activation remain distinct from main and the latest release. No blocking code defect was found; the outstanding product and upgrade decisions remain unresolved.

Priority: P2
Reviewed head: dd3cfdb0b97d4cb66645591c270f0193a6a9ee47
Owner decision: Required. See Decision needed.

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A sound, focused patch with strong installed plugin evidence, while package-upgrade coverage still needs resolution.
Proof confidence 🦞 diamond lobster (5/6) Sufficient (live_output): Installed x64 evidence exercises the unchanged plugin through the real Gateway and browser, recording default activation, explicit-disable rejection, exact clipboard values and theme changes. This supports plugin behavior, not a newly composed dd3cfdb package or healthy-baseline upgrade; that separate limitation remains open. No stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (live_output): Installed x64 evidence exercises the unchanged plugin through the real Gateway and browser, recording default activation, explicit-disable rejection, exact clipboard values and theme changes. This supports plugin behavior, not a newly composed dd3cfdb package or healthy-baseline upgrade; that separate limitation remains open. No stored-data contract changes.
Evidence reviewed 12 items Introduced change: Reviewed the pinned main-to-head delta across all 11 paths. The runtime change is confined to the existing plugin; the launcher source change adds synchronization comments.
Still necessary on main: Main still declares enabledByDefault=false and retains the previous isolation-command guidance; it does not implement this PR's central behavior.
Latest release remains default-disabled: GitHub identifies v2026.9.4-msix.3 as the latest release, targeting ee41ab7; its plugin manifest also declares enabledByDefault=false.
Findings None None.
Security None None.

How this fits together

The Windows package launches OpenClaw inside an isolated agent session. Its bundled Windows Launcher plugin turns a captured launcher report into an authenticated Control UI page, while payload validation checks plugin activation before packaging.

flowchart LR
  A[Windows launcher] --> B[Captured isolation report]
  C[Plugin preferences] --> D[Upstream plugin activation]
  B --> E[Windows Launcher plugin]
  D --> E
  E --> F[Authenticated status page]
  F --> G[Status and copyable commands]
Loading

Decision needed

Question Recommendation
Should Windows Launcher activate by default for existing undecided profiles, and must healthy-baseline upgrade evidence precede landing? Approve the default after upgrade proof: Accept default activation once a healthy existing installation upgrades to the reconciled candidate with preferences and session state preserved.

Why: The implementation preserves explicit preferences, but deciding to activate an existing optional surface and accepting incomplete upgrade coverage requires maintainer intent.

Before merge

  • Resolve merge risk (P1) - Existing profiles without a plugin preference will gain an active tab and authenticated route on their next Gateway start; maintainer acceptance of this default change is not recorded.
  • Resolve merge risk (P1) - Healthy-baseline upgrade behavior remains unproven for the reconciled package: the installed evidence covers fresh installation and recovery from a baseline that never reached Gateway readiness.
  • Complete next step (P2) - Record the maintainer's default-activation decision and resolve the healthy-upgrade coverage limitation before merge.
  • Resolve maintainer decision - Resolve the maintainer decision shown above before merge.
Agent review details

Security

None.

Review metrics

Metric Value Why it matters
Production and test LOC Production +29 net; tests and fixtures +245 net Production growth supports the command references and activation validation, with most net growth in regression coverage.

Merge-risk options

Maintainer options:

  1. Qualify the upgrade transition (recommended)
    Add healthy-baseline upgrade evidence for the reconciled candidate before landing the approved default change.
  2. Accept recovery-only coverage
    A maintainer can explicitly accept the documented upgrade limitation together with activation for undecided existing profiles.
  3. Preserve the existing default
    Retain opt-in activation while keeping the informational rendering and supported command references.

Technical review

Best possible solution:

Keep the existing read-only plugin owner, preserve explicit operator preferences, and qualify a maintainer-approved activation default across fresh installation and healthy upgrade.

Do we have a high-confidence way to reproduce the issue?

Not applicable as a single bug reproduction: this PR combines informational UI changes with a deliberate activation-default change, supported by installed plugin evidence.

Is this the best way to solve the issue?

Yes for the implementation approach: it extends the existing plugin and uses upstream activation policy without adding a configuration owner; default rollout remains a maintainer choice.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against d99389ce873d.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This is a bounded Windows status and discoverability improvement without evidence of an urgent runtime outage.
  • merge-risk: 🚨 compatibility: The manifest changes activation for existing undecided profiles, while healthy-baseline upgrade coverage and acceptance remain unresolved.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🦞 diamond lobster and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (live_output): Installed x64 evidence exercises the unchanged plugin through the real Gateway and browser, recording default activation, explicit-disable rejection, exact clipboard values and theme changes. This supports plugin behavior, not a newly composed dd3cfdb package or healthy-baseline upgrade; that separate limitation remains open. No stored-data contract changes.
  • proof: sufficient: Contributor real behavior proof is sufficient. Installed x64 evidence exercises the unchanged plugin through the real Gateway and browser, recording default activation, explicit-disable rejection, exact clipboard values and theme changes. This supports plugin behavior, not a newly composed dd3cfdb package or healthy-baseline upgrade; that separate limitation remains open. No stored-data contract changes.

Evidence

What I checked:

  • Introduced change: Reviewed the pinned main-to-head delta across all 11 paths. The runtime change is confined to the existing plugin; the launcher source change adds synchronization comments. (plugins/gateway-isolation/index.js:4, dd3cfdb0b97d)
  • Still necessary on main: Main still declares enabledByDefault=false and retains the previous isolation-command guidance; it does not implement this PR's central behavior. (plugins/gateway-isolation/openclaw.plugin.json:5, d99389ce873d)
  • Latest release remains default-disabled: GitHub identifies v2026.9.4-msix.3 as the latest release, targeting ee41ab7; its plugin manifest also declares enabledByDefault=false. (plugins/gateway-isolation/openclaw.plugin.json:5, ee41ab70e76c)
  • Existing isolation owner: The launcher supplies the constant enabled report to child processes; the plugin reads that diagnostic without changing session execution or creating an alternative isolation owner. (src/OpenClaw.Launcher/OpenClawRuntimeEnvironment.cs:52, dd3cfdb0b97d)
  • Default activation and dependency boundary: Build-Payload invokes the selected upstream OpenClaw CLI to inspect fresh, undecided-existing, and explicitly disabled profiles. It checks registration and configuration hashes, establishing a direct dependency on upstream plugin activation semantics. No persistent user-data format changes are introduced. (scripts/Build-Payload.ps1:228, dd3cfdb0b97d)
  • Upstream preference precedence: At the qualified runtime revision, resolvePluginActivationDecisionShared checks global disable, denylist, explicit disable and restrictive allowlist before bundled default enablement. The packaging change consumes this existing owner rather than rewriting operator preferences. (src/plugins/config-activation-shared.ts, ec9c1a13db89)

Likely related people:

  • paulcam206: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • ChazGo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rank-up moves

Optional improvements that raise the rating; they are not merge blockers.

  • Add healthy-baseline upgrade evidence for the reconciled candidate, or obtain explicit acceptance of that specific coverage limitation.

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (6 earlier review cycles)
  • reviewed 2026-09-18T18:44:35.810Z sha 1b2ea92 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-18T18:59:05.767Z sha 1b2ea92 :: needs real behavior proof before merge. :: [P2] Clear the expected native failure before returning from the test
  • reviewed 2026-09-21T21:17:36.718Z sha 872e729 :: needs real behavior proof before merge. :: none
  • reviewed 2026-09-22T00:29:49.390Z sha 872e729 :: blocked before merge. :: none
  • reviewed 2026-09-22T00:39:45.305Z sha 872e729 :: blocked before merge. :: none
  • reviewed 2026-09-22T17:41:02.407Z sha 6a8f0c0 :: blocked before merge. :: none

@clawsweeper clawsweeper Bot added merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. and removed rating: 🦪 silver shellfish Thin PR readiness signal; proof, validation, or implementation needs work. labels Sep 18, 2026
Validate fresh and existing default profiles without enablement overrides, preserve explicit disables, and share the real plugin registration fixture. Clear only the asserted expected native failure so the Actions PowerShell wrapper succeeds.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Chaz Gordish and others added 3 commits September 18, 2026 20:31
Resolve the instruction-file migration by retaining development-runtime and architecture-matched payload rules at their new owners.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Align workflow defaults and approved release identity with the stable runtime containing plugin theme forwarding. Retain unapproved-input signing coverage without a development override.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@clawsweeper clawsweeper Bot removed the merge-risk: 🚨 automation 🚨 Merging this PR could break CI, automerge, proof capture, label sync, or automation. label Sep 21, 2026
@ChazGo
ChazGo marked this pull request as ready for review September 21, 2026 23:04
@clawsweeper clawsweeper Bot added proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. and removed rating: 🦐 gold shrimp Decent PR readiness signal, but merge confidence is limited. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. labels Sep 22, 2026
@clawsweeper clawsweeper Bot added status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. labels Sep 22, 2026
Chaz Gordish and others added 2 commits September 22, 2026 08:43
Adopt main's source-selection and native payload architecture ownership while preserving default-on plugin inspection, explicit disables, and isolated cache handling. Keep the existing official runtime approval and remove the superseded workflow pin validator.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Merge the approved main baseline without changing its automatic setup or eligible gateway start behavior. Generate trusted PowerShell completion inside the isolated payload validation profile and extend the shared fixture while preserving default activation and explicit-disable checks.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@xlinush
xlinush merged commit bf4dec6 into openclaw:main Sep 22, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-risk: 🚨 compatibility 🚨 Merging this PR could break existing users, config, migrations, defaults, or upgrades. P2 Normal priority bug or improvement with limited blast radius. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants