Skip to content

fix: refresh Windows Launcher command references - #96

Merged
xlinush merged 2 commits into
openclaw:mainfrom
ChazGo:chazgo-refresh-launcher-command-references
Sep 22, 2026
Merged

xlinush merged 2 commits into
openclaw:mainfrom
ChazGo:chazgo-refresh-launcher-command-references

Conversation

@ChazGo

@ChazGo ChazGo commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

What Problem This Solves

The Windows Launcher command reference still shows a stop/start chain and a
dashboard URL-display recipe instead of the supported ClawCtl commands.

User Impact

Users can copy clawctl gateway-service restart and clawctl open from the
ClawCtl group. Open dashboard now opens the default browser when the copied
command is run. It requires completed setup and a running gateway, and does not
print authenticated URLs or tokens.

ClawCtl lists Gateway status, Restart Gateway, and Open dashboard first, followed
by Agent session PowerShell and Launcher help. The advanced shell no longer
precedes the common gateway commands. OpenClaw still lists Gateway chat TUI,
then OpenClaw help.

The page remains informational and copy-only. Unaffected commands, activation,
isolation reporting, authentication, themes, and clipboard fallback are unchanged.

Why This Change Was Made

We already have a dedicated restart operation and a verified, authenticated
browser handoff. This follow-up updates the command text, dashboard grouping and
order, descriptions, README, and exact clipboard regressions without changing
CLI or runtime behavior.

Evidence

Head: 8ced9ef59e327919425141186084c1d373260e14.
Base: 54e718d6d96720741147493d4c95c8da605c5c12 from canonical main.

  • .\scripts\Test-GatewayIsolationPlugin.Tests.ps1: 52/52 Node tests passed,
    plus disposable payload success/failure fixtures.
  • .\scripts\Test-DocReferences.ps1: zero findings. git diff --check: passed.

Browser behavior, not just the screenshot

Fresh terminal diagnostics captured at 2026-09-22 22:09:47 UTC from the
committed plugin in Edge 153.0.4234.48, Playwright 1.63.0, Node v24.18.0.
The loopback component fixture calls the actual plugin route handler with a
synthetic enabled report and embeds it in an allow-scripts iframe.
The wrapper does not implement Gateway authentication.

All seven commands matched DOM and visual order. The primary copy path called
the browser's real document.execCommand("copy"); each result below was read
back through the actual clipboard, not a mocked return value. Terminal excerpt:

head=8ced9ef59e327919425141186084c1d373260e14
GET /plugins/gateway-isolation/status -> 200; CSP=default-src 'none'; style-src 'unsafe-inline'; script-src 'unsafe-inline'; frame-ancestors 'self'
headers=no-store, no-referrer, nosniff; iframe=allow-scripts; parentDOM=SecurityError
clipboard mouse    "clawctl gateway-service restart" PASS
clipboard keyboard "clawctl gateway-service restart" PASS
clipboard mouse    "clawctl open" PASS
clipboard keyboard "clawctl open" PASS
native document.execCommand(copy): 14/14 successful; clipboard readbacks: 14/14 exact
fallback [fault-injected clipboard denial] Ctrl+C "clawctl gateway-service restart" PASS; no false success
fallback [fault-injected clipboard denial] Ctrl+C "clawctl open" PASS; no false success
interaction requests=0; navigations=0; popups=0; failedRequests=0; pageErrors=0; consoleErrors=0
PASS: real browser copy behavior; command execution not attempted

For the explicitly fault-injected fallback cases, both programmatic copy APIs
were denied. The UI selected the exact command and announced manual-copy
guidance without changing the clipboard sentinel; real Ctrl+C then copied the
selected command. No command-triggered network requests, navigation, or browser
opening occurred during the interaction window.

Existing command-owner and native CLI checks

The completed Test Gateway MSIX host job
provides public terminal logs for this revision:

Passed! - Failed: 0, Passed: 1062, Skipped: 0, Total: 1062
ok    gateway-service help includes restart
24 NativeAOT scenarios passed.
NativeAOT clawctl checks completed successfully.

CI checked out merge 611bcf8ba358f5998e62a172ed662f99e5cb35ee
(base 54e718d6d967 plus head 8ced9ef59e32). GitHub's commit API confirms
its tree is identical to the PR head: 04e18c1cae6a8b8e11df1759c733b4eb0adc27b0.
No duplicate local build was needed.

The unfiltered .NET suite includes the existing
restart owner regressions
and open-command regressions:
single-lock stop/start, refusal after unverified stop, setup/running-gateway
requirements, handoff binding, and authenticated-URL non-disclosure. These use
fixture-owned collaborators, not a live installed Gateway. The NativeAOT driver
executes the real startup/CLI path with injected collaborators; its intentional
wrong-executable-name negative check fails as expected.

Rendered reference

The screenshot below is fresh local component/browser fixture proof, with a
synthetic isolation report, captured at native 2400 x 2240 resolution. It shows
the gateway-first order, exact commands, and ClawCtl/OpenClaw grouping. It is not
installed-package, Gateway authentication, restart execution, or authenticated
browser-handoff proof. No historical screenshots are reused.

Local browser fixture: gateway commands before Agent session PowerShell in the ClawCtl group

The browser diagnostics and CI checks above cover the changed copy-only
presentation and existing owner contracts. They do not prove installed Gateway
authentication, a real gateway restart, or a real authenticated browser handoff.
No new local build, VM, installed-package, signing, healthy-upgrade, or broad
browser/runtime matrix was run to gather this evidence. Existing automatic CI
is linked above; no manual workflow or review run was dispatched.

Use the supported gateway restart and authenticated dashboard browser commands in the copy-only reference. Update command grouping, descriptions, clipboard regressions, and README guidance.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@clawsweeper

clawsweeper Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@clawsweeper clawsweeper Bot added P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. proof: sufficient Contributor real behavior proof is sufficient. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Sep 22, 2026
@clawsweeper

clawsweeper Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Codex review: needs maintainer review before merge. Reviewed September 22, 2026, 6:38 PM ET / 22:38 UTC (Revision 3).

ClawSweeper review

What this changes

Updates the Windows Launcher’s copyable command reference and README to use supported restart and dashboard commands, puts gateway actions first, and adjusts regression tests.

Merge readiness

✅ Ready for maintainer review

This PR remains useful because current main still displays the older command recipes. The updated browser diagnostics resolve the previous proof blocker, and no blocking correctness or security findings remain.

Priority: P3
Reviewed head: 8ced9ef59e327919425141186084c1d373260e14

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, maintainable patch with convincing browser proof and no actionable findings.
Proof confidence 🦞 diamond lobster (5/6) Sufficient (terminal): The actual plugin route was exercised in Edge at the reviewed head: terminal diagnostics show exact real clipboard results, keyboard interaction, and manual-copy recovery, while the inspected screenshot confirms ordering. This resolves the prior screenshot-only gap for the changed presentation; installed Gateway authentication and lifecycle execution remain outside this diff. No stored-data contract changes.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Verified Sufficient (terminal): The actual plugin route was exercised in Edge at the reviewed head: terminal diagnostics show exact real clipboard results, keyboard interaction, and manual-copy recovery, while the inspected screenshot confirms ordering. This resolves the prior screenshot-only gap for the changed presentation; installed Gateway authentication and lifecycle execution remain outside this diff. No stored-data contract changes.
Evidence reviewed 7 items Introduced change is limited to command presentation: The pinned introduction delta changes README guidance, static command definitions, and corresponding tests. Clipboard implementation, route authentication, CSP, plugin registration, dependencies, and persisted state are unchanged.
Current main still needs the reference refresh: Main retains the stop/start chain, dashboard --no-open recipe, and shell-first ordering. The live main API returned the supplied base SHA. Related merged command implementations do not supersede this presentation change.
References match existing command owners: GatewayController.RestartAsync holds one lifecycle lock and aborts replacement after an unsuccessful stop. Program's open handler requires setup and a running gateway, validates the handoff and current session, and opens the browser without including the URL in its result. These existing capabilities came through #90 and #84.
Findings None None.
Security None None.

How this fits together

The Windows Launcher tab renders isolation status and copyable commands inside OpenClaw’s Control UI. Users copy those commands into their Windows terminal; the page itself does not execute them.

flowchart LR
  A[Launcher isolation report] --> B[Windows Launcher page]
  C[Supported command references] --> B
  B --> D[Copy button]
  D --> E[Clipboard or manual selection]
  E --> F[User runs command in terminal]
  F --> G[Existing launcher command owners]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Keep the launcher reference aligned with the existing command owners while preserving its copy-only interaction.

Do we have a high-confidence way to reproduce the issue?

Not applicable as a runtime defect: source inspection confirms the old reference text on current main, and the supplied browser evidence demonstrates the updated presentation and copying.

Is this the best way to solve the issue?

Yes. Updating the existing reference data and its tests is the narrowest solution; the patch reuses supported commands without introducing another execution path.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against 54e718d6d967.

Labels

Label changes:

  • add proof: sufficient: Contributor real behavior proof is sufficient. The actual plugin route was exercised in Edge at the reviewed head: terminal diagnostics show exact real clipboard results, keyboard interaction, and manual-copy recovery, while the inspected screenshot confirms ordering. This resolves the prior screenshot-only gap for the changed presentation; installed Gateway authentication and lifecycle execution remain outside this diff. No stored-data contract changes.
  • add status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (terminal): The actual plugin route was exercised in Edge at the reviewed head: terminal diagnostics show exact real clipboard results, keyboard interaction, and manual-copy recovery, while the inspected screenshot confirms ordering. This resolves the prior screenshot-only gap for the changed presentation; installed Gateway authentication and lifecycle execution remain outside this diff. No stored-data contract changes.
  • remove status: 📣 needs proof: Current PR status label is status: 👀 ready for maintainer look.
  • remove proof: 📸 screenshot: Current real behavior proof evidence kind is terminal.

Label justifications:

  • P3: This is a bounded command-reference and ordering improvement with no runtime lifecycle change.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🦞 diamond lobster and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Sufficient (terminal): The actual plugin route was exercised in Edge at the reviewed head: terminal diagnostics show exact real clipboard results, keyboard interaction, and manual-copy recovery, while the inspected screenshot confirms ordering. This resolves the prior screenshot-only gap for the changed presentation; installed Gateway authentication and lifecycle execution remain outside this diff. No stored-data contract changes.
  • proof: sufficient: Contributor real behavior proof is sufficient. The actual plugin route was exercised in Edge at the reviewed head: terminal diagnostics show exact real clipboard results, keyboard interaction, and manual-copy recovery, while the inspected screenshot confirms ordering. This resolves the prior screenshot-only gap for the changed presentation; installed Gateway authentication and lifecycle execution remain outside this diff. No stored-data contract changes.

Evidence

What I checked:

  • Introduced change is limited to command presentation: The pinned introduction delta changes README guidance, static command definitions, and corresponding tests. Clipboard implementation, route authentication, CSP, plugin registration, dependencies, and persisted state are unchanged. (plugins/gateway-isolation/index.js:4, 8ced9ef59e32)
  • Current main still needs the reference refresh: Main retains the stop/start chain, dashboard --no-open recipe, and shell-first ordering. The live main API returned the supplied base SHA. Related merged command implementations do not supersede this presentation change. (plugins/gateway-isolation/index.js:24, 54e718d6d967)
  • References match existing command owners: GatewayController.RestartAsync holds one lifecycle lock and aborts replacement after an unsuccessful stop. Program's open handler requires setup and a running gateway, validates the handoff and current session, and opens the browser without including the URL in its result. These existing capabilities came through feat: restart the managed gateway with one command #90 and feat: add clawctl open command #84. (src/OpenClaw.Launcher/Program.cs:697, 8ced9ef59e32)
  • After-fix browser proof addresses the previous review: The supplied complete body, captured under sourceRevision 4a81ebef21b78a6361f097588e134e7fd82846315008c7102c323cf4b3c5dc59, records Edge execution of the actual plugin route in an allow-scripts iframe at this head. It reports 14 exact real clipboard readbacks, mouse and keyboard coverage, fault-injected denial followed by successful manual Ctrl+C, and zero interaction requests, navigations, popups, or browser errors. The downloaded screenshot was inspected and confirms all seven commands and their grouping. The synthetic isolation report does not establish installed Gateway authentication or command execution, neither of which this patch changes. (plugins/gateway-isolation/index.js:4, 8ced9ef59e32)
  • Validation and reviewer execution limits: The contributor reports 52 Node tests, disposable payload fixtures, and documentation checks passing; supplied checks show successful host and packaging jobs. Reviewer git diff --check passed and the checkout remained clean. No tests, builds, browser runs, NativeAOT execution, deployment, upgrade harness, or signing were run by this review. PowerShell startup failed because /home/runner/.cache/powershell could not be created on the read-only filesystem; source inspection continued with read-only shell commands. (plugins/gateway-isolation/index.test.js:161, 8ced9ef59e32)
  • Release context: The latest release API returns v2026.9.4-msix.3, published September 19, targeting ee41ab7. No implemented-on-main or shipped-fix claim is made: current main still contains the old references. Historical release-blob inspection was unavailable locally. (ee41ab70e76c)

Likely related people:

  • ChazGo: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)
  • paulcam206: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (2 earlier review cycles)
  • reviewed 2026-09-22T21:48:21.167Z sha 55c2995 :: needs maintainer review before merge. :: none
  • reviewed 2026-09-22T22:01:33.321Z sha 8ced9ef :: needs real behavior proof before merge. :: none

Move the advanced agent PowerShell row below status, restart, and dashboard. Align order regressions and README without changing command behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@ChazGo
ChazGo marked this pull request as ready for review September 22, 2026 21:57
@clawsweeper clawsweeper Bot added status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. proof: sufficient Contributor real behavior proof is sufficient. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. and removed status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. proof: sufficient Contributor real behavior proof is sufficient. status: 📣 needs proof The PR needs real behavior proof before ClawSweeper can clear the contributor ask. proof: 📸 screenshot Contributor real behavior proof includes screenshot evidence. labels Sep 22, 2026
@xlinush
xlinush merged commit 32a8e88 into openclaw:main Sep 22, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low-risk cleanup, docs, polish, ergonomics, or speculative feature. proof: sufficient Contributor real behavior proof is sufficient. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants