Conversation
Remove unsupported isolation commands and copy controls. Show Running and Active only with the captured enabled report, and report all other isolation signals as invalid with HTTP 503. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep isolation reports informational, replace unsupported controls with verified general command references, and cover sandbox clipboard fallback and accessible feedback. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the agent shell and Gateway chat UI distinct, preserve copy-only behavior, and fit all seven references without clipping. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Keep the stable signing policy separate and reject incompatible official workflow inputs before building. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Use a native ARM64 runner, reject incompatible inspection hosts before staging, and isolate the plugin snapshot cache for every CLI probe. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 21, 2026, 8:39 PM ET / September 22, 2026, 00:39 UTC (Revision 5). ClawSweeper reviewWhat this changesMakes Windows Launcher an informational page with seven copyable commands, enables its plugin by default, and updates runtime approval and architecture-specific packaging checks. Merge readiness⛔ Blocked before merge - 5 items remain Keep open: current main retains the old isolation-control guidance, so the informational page remains useful, distinct work. No blocking code defect was found in the pinned diff. Priority: P2 Review scores
Verification
How this fits togetherThe packaging-owned Windows Launcher plugin displays the isolated Gateway's launch report inside OpenClaw's Control UI. Packaging selects and validates the upstream runtime; upstream plugin policy controls activation and authenticated access. flowchart LR
A[Runtime and package inputs] --> B[Payload validation]
B --> C[Packaged Gateway]
D[Operator plugin settings] --> C
C --> E[Authenticated launcher tab]
F[Captured isolation report] --> E
E --> G[Status and copyable commands]
Decision needed
Why: The UI improvement is distinct from approving an upstream release for official signing, and the supplied evidence does not resolve healthy-upgrade compatibility. Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Keep one read-only launcher tab governed by upstream plugin settings, reuse main's source-selection owners, and separate official runtime approval unless maintainers accept it with upgrade evidence. Do we have a high-confidence way to reproduce the issue? Yes, source establishes the mismatch: current main displays planned isolation controls while the launcher always supplies an enabled isolation report. No current-main runtime reproduction was executed. Is this the best way to solve the issue? Yes for the informational page and preservation of upstream plugin policy; the broader packaging edits should be reconciled with main's existing source-selection owner rather than retained as parallel policy. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 207d19d0fd28. LabelsLabel justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (4 earlier review cycles)
|
Validate fresh and existing default profiles without enablement overrides, preserve explicit disables, and share the real plugin registration fixture. Clear only the asserted expected native failure so the Actions PowerShell wrapper succeeds. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Resolve the instruction-file migration by retaining development-runtime and architecture-matched payload rules at their new owners. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Align workflow defaults and approved release identity with the stable runtime containing plugin theme forwarding. Retain unapproved-input signing coverage without a development override. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
|
@copilot please fix the merge conflicts in this pull request. |
Why is this change being made?
Windows Launcher should report the packaged Gateway's required isolation, not present isolation as a configurable mode. Its informational page should appear by default without overwriting an operator's explicit plugin decision.
What changed?
operator.read, hardened headers, the opaque iframe sandbox and validated live theme forwarding.v2026.9.5atec9c1a13db8938e5a3eaa51fca2e981cde2395a9, aligned workflow defaults and release policy, and removed the development override.windows-11-vs2026-arm; cross-composition remains available with a qualified payload.$LASTEXITCODE=1into the Actions wrapper without suppressing unexpected native failures.Head:
872e72958c6cd1dedd1d15de48334d02ab7e0f96. The merged #75 native-staging fix is included. The coordinated runtime update, default activation and native payload-build requirement still need maintainer acceptance.How was the change tested?
Installed x64 recovery and fresh-install proof: Tested the exact-head, locally test-signed MSIX
2026.9.500.0with OpenClaw 2026.9.5 and matching build/runtime Node 24.20.0. Package SHA-256:917260192f2ce977badc745ab4512600a7b0b863ea5cabfb7b49f6ac3f27d47d.falsesurvived restart and supported setup. The plugin was not imported, registered no routes and exposed no tab or iframe; the unregistered route returned 404.allow-scriptsiframe withoutallow-same-origin. Four themes switched on the same frame with zero post-mount navigations, page errors or command-execution requests.Important limitation: Official baseline
2026.9.4.1001installed and setup passed, but its Gateway exited with a native Koffi loading error before becoming ready. That failure remains recorded. The completed lane is failed-baseline recovery, not healthy-baseline upgrade proof. Fresh-install proof is separate. No PR86 changes were incorporated.Source and CI checks: Exact-head local validation passed 52 plugin tests, 807 managed tests, zero-warning static analysis, 18 NativeAOT scenarios plus the expected wrong-alias negative, and the owning plugin, workflow/signing, release/version, Node runtime, payload/build-identity and documentation checks. Initial failures and successful recoveries remain separate records.
PR integration CI used merge commit
20ce92b7aefae10954776573777cf1547bc59fe5, combining main288521d5with this head. Host checks, upstream full build, x64/ARM64 MSIX jobs and multiarchitecture bundling passed. The native ARM64 job used ARM64 Node 24.20.0, built a fresh payload, validated Gateway/UI identity and completed NativeAOT composition. This is merge-ref integration evidence, not exact-head or installed ARM64 proof.The local candidate combines the exact-head host with separately validated CI payload
10665831515; its producer contract and injected plugin bytes match this head. Genuine CI metadata remains unchanged. The upstream tarball SHA-256 is8b1a6569f24d0c3739bd62371b1e75c5d0fc8ff2f95c498bbe923d1825f9a991. Registry TLS failures were recovered through supported, integrity-checked payload and MXC archive reuse, without weakening verification.Actual clipboard values and denial recovery
Independent checks of both hash-bound browser results verified 28 exact copy actions and 28 fallback calls. Mouse and keyboard actions produced each value below in both runs; keyboard focus stayed on Copy.
clawctl pwshclawctl gateway-service statusclawctl gateway-service stop && clawctl gateway-service startclawctl --helpopenclaw tuiopenclaw dashboard --no-openopenclaw --helpWith deliberately injected denial,
writeTextthrew andexecCommand("copy")returned false. Both runs retainedUI proof sentinelon the clipboard, selected exactlyclawctl gateway-service status, and displayed:Actual manual Ctrl+C then copied that exact command. This proves recovery from an injected denial, not a naturally observed permission failure.
Actual fresh-installed runtime: four themes
These captures were inspected visually and identify the exact tested source, runtime, package and local test signing. Earlier recovery images had a stale harness footer and are retained but excluded here; their separate behavioral results identify the correct candidate.
Healthy-baseline upgrade and installed ARM64 remain unproven. Cleanup covers owned product/provider state, not a global MXC backend inventory. Local test signing and passing checks do not establish official release readiness or replace maintainer scope acceptance.