Skip to content

test(e2e): add inactive Windows MXC OpenClaw qualification - #8300

Merged
senthilr-nv merged 8 commits into
mainfrom
codex/windows-mxc-process-container-e2e
Aug 5, 2026
Merged

test(e2e): add inactive Windows MXC OpenClaw qualification#8300
senthilr-nv merged 8 commits into
mainfrom
codex/windows-mxc-process-container-e2e

Conversation

@senthilr-nv

@senthilr-nv senthilr-nv commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

Adds an opt-in live E2E target for the inactive Windows MXC OpenClaw process_container candidate. NemoClaw previously had no revision-bound qualification path for this candidate; the target now checks exact package and artifact identities, workload readiness, filesystem allow and deny behavior, sandbox deletion, registry removal, and exact OpenClaw process cleanup without registering or activating MXC.

Related Issue

Refs #8178

Changes

  • Validate the exact NemoClaw revision, OpenShell package binaries, wxc-exec, and OpenClaw artifact tree before execution, then revalidate each pinned runtime artifact immediately before its security-relevant use.
  • Generate a temporary least-privilege gateway configuration, filesystem policy, and OpenClaw probe, then exercise sandbox create and delete only through OpenShell.
  • Restrict host child environments, fail closed on command/query errors, validate process identities before emergency cleanup, and record a secret-free qualification receipt.
  • Add support tests, mock-parity coverage, and semantic checks for progress and the OpenShell-only MXC control boundary.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification:
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Exact-head security review passed all nine categories on 99e54157678400cfda425bdc9a1f0e531749e6ea; the target is opt-in, loopback-bound, argument-array based, least-privilege, identity-pinned and revalidated before security-relevant use, host-environment restricted, token-redacting, resource-bounded, and fail-closed on create, query, or cleanup fallback.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: pass
  • Evidence: Exact-head review confirmed the inactive/no-support boundary, artifact revalidation, least-privilege receipt, environment allowlist, process-identity checks, and failure-containment cleanup behavior. The writer corrected the receipt claim so operators are told that, after preflight and local setup succeed, the target writes a secret-free receipt for either verdict; earlier failures may occur before receipt creation. No user docs, changelog, navigation, or routing change is required.
  • Agent: Codex Desktop documentation-writer subagent

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and all 8 commits appear as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run validate:pr passed after refreshing origin/main when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — npx vitest run --project e2e-support test/e2e/support/windows-mxc-openclaw-process-container.test.ts test/e2e/support/e2e-semantic-phase-check.test.ts passed 35 tests in 2 files; npm run test:e2e-phases:check passed 118 tests in 75 files; mock parity, repository checks, CLI build, and CLI type-check passed. The receipt-boundary follow-up passed normal Markdown lint and the repository test-file budget.
  • Applicable broad gate passed — npm test for broad runtime/test-harness changes; npm run check for repo-wide validation/coverage changes — command/result: npm test was attempted outside the sandbox, including a four-worker retry, but unchanged local tests failed or timed out; an isolated failure was caused by the host Python lacking yaml.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only) — the build passed with two existing Fern warnings.
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

GitHub Actions

Fresh exact-head CI and protected E2E evidence for 99e54157678400cfda425bdc9a1f0e531749e6ea are required. No prior-head result is carried forward and no check is waived.


Signed-off-by: Senthil Ravichandran senthilr@nvidia.com

Summary by CodeRabbit

  • New Features

    • Added qualification coverage for Windows x64 OpenClaw process containers, including sandbox lifecycle, process identity, artifact integrity, readiness, and cleanup validation.
    • Added deterministic artifact-tree integrity verification for qualification assets.
  • Tests

    • Added gated end-to-end validation with progress reporting and pass/fail receipts.
    • Added contract and semantic checks for configuration, security boundaries, token handling, process validation, cleanup, and failure scenarios.
  • Documentation

    • Documented prerequisites, environment setup, execution steps, artifact verification, token handling, cleanup safeguards, and expected failure behavior.

Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
@senthilr-nv senthilr-nv self-assigned this Aug 5, 2026
@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR adds an inactive Windows x64 MXC OpenClaw process_container qualification flow. It validates artifacts and identities, runs a probe agent, checks sandbox and process lifecycles, performs cleanup, writes receipts, and adds contract and E2E coverage.

Changes

Windows MXC OpenClaw qualification

Layer / File(s) Summary
Artifact and identity validation
test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts, tools/e2e/windows-mxc-openclaw-artifact-tree.mts, test/e2e/support/windows-mxc-openclaw-process-container.test.ts
Validates environment inputs, artifact containment, source revisions, process identities, supported artifact types, and deterministic SHA-256 artifact-tree digests.
Runtime configuration and observation
test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts, test/e2e/support/windows-mxc-openclaw-process-container.test.ts
Renders gateway and filesystem policies, generates the probe agent, runs bounded commands, and checks readiness, health, process identities, environment variables, and token handling.
Qualification lifecycle and cleanup
test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts, test/e2e/live/windows-mxc-openclaw-process-container.test.ts, test/e2e/README.md
Runs the gated qualification, validates sandbox and registry lifecycle behavior, performs layered cleanup, writes receipts, and documents execution requirements and checks.
Semantic boundary validation
tools/e2e/check-semantic-phases.mts, test/e2e/support/e2e-semantic-phase-check.test.ts, test/e2e/mock-parity.json
Validates approved OpenShell control calls, sandbox operation ordering, reviewed progress capabilities, required helper presence, and mock-parity registration.

Estimated code review effort: 5 (Critical) | ~120 minutes

Possibly related issues

Possibly related PRs

  • NVIDIA/NemoClaw#8234: Adds related gated OpenClaw qualification infrastructure with protected control paths.
  • NVIDIA/NemoClaw#8266: Adds a related dormant hardware-specific qualification lane with artifact, lifecycle, cleanup, and contract validation.

Suggested labels: area: security

Suggested reviewers: apurvvkumaria

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the added inactive Windows MXC OpenClaw E2E qualification target.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/windows-mxc-process-container-e2e

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit 99e5415 in the codex/windows-mxc-pr... branch remains at 96%, unchanged from commit c81f7fc in the main branch.

TypeScript / code-coverage/cli

The overall coverage in commit 99e5415 in the codex/windows-mxc-pr... branch remains at 82%, unchanged from commit cbabb66 in the main branch.

Show a code coverage summary of the most impacted files.
File main cbabb66 codex/windows-mxc-pr... 99e5415 +/-
src/lib/sandbox...rce-identity.ts 87% 87% 0%
src/lib/adapter...shell/client.ts 88% 90% +2%

Updated August 05, 2026 17:01 UTC

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — No blocking findings reported

Advisor assessment: No blocking advisor findings reported
Next action: Review the warnings below.
Findings: 0 blockers · 1 warning · 0 suggestions

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 1 warning · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Model comparison: normalized findings differ; normalized terminology decisions differ; normalized E2E selections match; Nemotron reported the same number of blockers, 1 fewer warning, the same number of suggestions.
5 terminology differences from the second opinion

Advisory only. These are normalized differences from the primary terminology receipt.

  • control boundary at test/e2e/support/e2e-semantic-phase-check.test.ts:59: selected only by the second-opinion lane as justified.
  • qualification at test/e2e/README.md:190: selected only by the second-opinion lane as justified.
  • probe-agent at test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts:446: selected only by the second-opinion lane as justified.
  • inactive-candidate at test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts:122: selected only by the second-opinion lane as define.
  • artifact-tree at test/e2e/README.md:203: selected only by the second-opinion lane as define.

Second-opinion terminology and E2E selections are advisory. They do not change the primary assessment or E2E / PR Gate.

2 semantic terminology decisions

Terminology decisions are advisory. They affect the assessment only when a separate finding identifies concrete semantic impact.

  • established — secret-free receipt at test/e2e/README.md:268: Keep the established term and state the receipt's verdict and sensitive-artifact boundary.
  • justified — failure containment at test/e2e/README.md:251: Keep the modifier because the adjacent text defines the failure result and distinguishes it from passing compatibility behavior.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: cloud-inference, cloud-onboard, security-posture

1 warning · 0 suggestions

Warnings

Warnings do not block.

PRA-1 Warning — Prove that emergency cleanup makes the qualification fail

  • Location: test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts:1374
  • Category: correctness
  • Problem: The cleanup path records emergency process or gateway termination and makes the final receipt fail, but checked-in tests cover only helper predicates and rendering. They do not exercise a still-running identity-validated process through cleanup and verify the failed receipt outcome.
  • Impact: A later cleanup refactor can invoke host-side forced termination yet still produce a passing receipt, weakening the qualification's lifecycle evidence.
  • Recommendation: Add a seam that simulates a trusted OpenClaw or gateway process remaining alive during cleanup, then assert that the receipt records the emergency flag and has verdict fail.
  • Verification: Inspect the cleanup branch and pass predicate in the helper, then inspect the support test for a simulated still-live trusted process.
  • Test coverage: A support test that drives each emergency-termination cleanup branch and asserts a fail receipt with the corresponding emergency flag set.
  • Simplification (shrink): Remove Untested implicit cleanup-state coupling between emergency flags and the final receipt.; use Expose a narrow cleanup dependency seam used only by support tests to simulate process liveness and termination.. Net: 0 lines.
  • Keep: Keep production process-identity checks and the fail-on-fallback pass predicate unchanged.
  • Evidence: test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts:1374-1449 sets the emergency flags after liveness checks. test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts:1459-1470 requires both flags to be false before a pass. test/e2e/README.md:250-253 states that fallback use fails the qualification. test/e2e/support/windows-mxc-openclaw-process-container.test.ts:1-348 does not exercise qualification cleanup with a live trusted process.

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts Fixed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 11

🧹 Nitpick comments (7)
test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts (6)

680-702: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Derive the timeout text from the constant.

The deadline uses COMMAND_TIMEOUT_MS, but the error message on line 701 hardcodes "30 seconds". If COMMAND_TIMEOUT_MS changes, the message becomes wrong.

♻️ Proposed change
-  throw new Error("OpenShell gateway did not listen within 30 seconds");
+  throw new Error(`OpenShell gateway did not listen within ${COMMAND_TIMEOUT_MS} ms`);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
680 - 702, Update the timeout error in waitForPort to derive its reported
duration from COMMAND_TIMEOUT_MS instead of hardcoding “30 seconds,” ensuring
the message remains accurate if the constant changes.

564-577: 🩺 Stability & Availability | 🔵 Trivial | 💤 Low value

Clear the timeout on the output-bound rejection path.

The overflow branch calls child.kill() and reject(...) but leaves timer scheduled. The close handler normally clears it. If the killed child never closes, the timer fires later and calls child.kill() a second time. The promise is already settled, so the second reject is a no-op, and the impact is limited to a stray timer.

Call clearTimeout(timer) in the overflow branch.

♻️ Proposed change
       if (outputBytes > MAX_COMMAND_OUTPUT_BYTES) {
+        clearTimeout(timer);
         child.kill();
         reject(new Error(`${path.basename(file)} output exceeded its bound`));
         return;
       }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
564 - 577, Update the output overflow branch in append to call
clearTimeout(timer) before killing the child and rejecting, ensuring the timeout
cannot fire after output-bound rejection.

493-510: 🚀 Performance & Scalability | 🔵 Trivial | 💤 Low value

Consider ending the host wait when the agent gives up.

The agent stops polling health after 120000 ms and then never writes readyPath. The host waitForFile(readyPath, READY_TIMEOUT_MS) at line 1043 keeps waiting for the full 180000 ms. Every health failure therefore adds about 60 seconds of dead wait.

Have the agent write a terminal marker (or write readyPath with a failure body that the host inspects) so the host stops as soon as the outcome is known. Deriving both deadlines from one value would also keep them consistent.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
493 - 510, Update the health-polling flow around the gateway wait loop so that
exhausting its deadline writes a terminal failure marker or failure body to
readyPath, and ensure the host wait logic inspects that result and exits
promptly instead of waiting for READY_TIMEOUT_MS. Keep successful health
detection unchanged, and derive the agent and host deadlines from a shared
timeout where appropriate.

269-271: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Consider streaming and sharing one sha256File implementation.

sha256File reads the whole file into memory. The staged tree includes node.exe and can include up to 100,000 files hashed through the identical private copy in tools/e2e/windows-mxc-openclaw-artifact-tree.mts (lines 11-13). Export the tools-module implementation and import it here, so both digests come from one definition.

Streaming with createReadStream would also bound peak memory. This is optional for a local qualification target.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
269 - 271, Replace the local sha256File implementation with the exported shared
implementation from tools/e2e/windows-mxc-openclaw-artifact-tree.mts, and import
that symbol here so both callers use one definition. Do not add the optional
streaming change unless required by the existing API.

356-359: 🔒 Security & Privacy | 🔵 Trivial | 💤 Low value

Security Misconfiguration (CWE-1284): Improper Validation of Specified Quantity in Input

Reachability: Internal · Exploitability: Theoretical

Reachability path
● Entry
  test/e2e/support/windows-mxc-openclaw-process-container.test.ts
│
▼
● Hop
  tools/e2e/windows-mxc-openclaw-artifact-tree.mts:11
  sha256File
│
▼
● Sink
  test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts

Anchor the port value to its --port flag.

assertExpectedOpenClawProcessIdentity accepts the expected port as any command-line token. Match the ordered --port and value pair so the port check is explicit. This remains defense in depth.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
356 - 359, Update assertExpectedOpenClawProcessIdentity so the expected port is
validated as the ordered "--port" flag followed by String(expected.port), rather
than as an unconstrained command-line token. Preserve the existing checks for
the entry path, "gateway", and probe agent path.

768-790: 🔒 Security & Privacy | 🔵 Trivial | 💤 Low value

Security Misconfiguration (CWE-426): Untrusted Search Path

Reachability: Internal · Exploitability: Theoretical

Reachability path
● Entry
  test/e2e/support/windows-mxc-openclaw-process-container.test.ts
│
▼
● Hop
  tools/e2e/windows-mxc-openclaw-artifact-tree.mts:11
  sha256File
│
▼
● Sink
  test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts

Make checkout identity checks independent of the caller context.

If exact identity checks must remain independent of host state, resolve git through the same trusted executable policy and pass the checkout root through cwd (or use git -C). The current calls depend on PATH and the process working directory.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
768 - 790, Update assertCurrentCheckoutIdentity to resolve git using the
established trusted executable policy and execute both rev-parse and status
checks against the intended checkout root via cwd or git -C. Keep the existing
revision and clean-status validation behavior unchanged while removing
dependence on PATH and the caller’s working directory.
test/e2e/support/windows-mxc-openclaw-process-container.test.ts (1)

130-196: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

Consider splitting this test by concern.

The test covers registry name matching, the delete-retry predicate, host process identity equality, and three cases of assertExpectedOpenClawProcessIdentity. The title names two of them. A failure in any one of the seven assertions reports the same test name, so the cause is not visible from the report.

Splitting into one test per exported function would localize failures.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/support/windows-mxc-openclaw-process-container.test.ts` around lines
130 - 196, Split the combined test into separate tests for each exported
function: sandboxListContainsExactName, shouldRetrySandboxDelete,
sameWindowsProcessIdentity, and assertExpectedOpenClawProcessIdentity. Keep the
existing assertions and scenarios unchanged, grouping the three process-identity
validation cases under the latter function so failures identify their specific
concern.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts`:
- Around line 1086-1095: Update the sandboxCreateAccepted logic to document why
a non-zero create.exitCode is tolerated and replace the command-detail error
denylist with a positive success signal from the pinned OpenShell revision.
Preserve the existing health and registry prerequisites, and ensure acceptance
requires that explicit signal rather than merely the absence of known error
phrases.
- Around line 1249-1260: Add an identity-validated gateway termination fallback
to the cleanup block around gateway.kill() and gatewayStopped: after the
existing five-second wait, verify the gateway is still the expected process,
invoke the established taskkill/escalation mechanism, and wait for termination
before finalizing gatewayStopped. Reuse the same PID-validation approach used
for the OpenClaw process cleanup rather than leaving a surviving gateway
unhandled.
- Around line 472-489: Update the gateway spawn flow around spawn and
writeFileSync to capture the ChildProcess "error" event, prevent an unhandled
exception, and record the spawn failure for the probe result. Only write
openClawPidPath when gateway.pid is defined, and include the captured spawnError
in the result object written by the probe agent so the receipt reports the
actual cause.
- Around line 899-902: Update the setup around gatewayPort, openClawPort,
sandboxName, and gatewayName to allocate openClawPort with freeLoopbackPort()
instead of deriving it from runId, ensuring the host-side probe validates the
port. Derive one name from the other if they must remain equal; otherwise use
distinct prefixes so sandbox and gateway entries are distinguishable.
- Around line 1262-1283: Update the cleanup block around
sensitiveRuntimeArtifactsRemoved so each sensitive path in the cleanup list is
removed within its own try/catch, allowing subsequent paths to be attempted
after EBUSY or EPERM errors. Continue collecting removal errors in
cleanupFailures, then recompute sensitiveRuntimeArtifactsRemoved after all paths
have been processed so runRoot cleanup can follow the existing flow.
- Around line 927-949: The gatewayEnvironment construction currently forwards
the entire host environment through the environment spread. Replace that spread
with an explicit allowlist containing only the variables required by the gateway
and the existing NemoClaw/OpenShell configuration, while preserving the values
already assigned in gatewayEnvironment. Keep controlEnvironment based on the
restricted gatewayEnvironment and continue removing NEMOCLAW_MXC_E2E_TOKEN
there.
- Around line 390-391: Update the qualification receipt generation near the
pc_least_privilege configuration to record that least privilege is disabled, and
add documentation explaining why the qualification requires this relaxed
privilege posture. Keep the existing filesystem-check receipt entries and
capability configuration unchanged.
- Around line 605-615: Update the process-query result handling in the helper
that invokes Get-CimInstance so any non-zero exit code is checked and raised
before evaluating empty stdout. Preserve the explicit exit code 3 path as the
genuine no-process case returning null, while only treating empty stdout as
absent after a successful query.

In `@test/e2e/live/windows-mxc-openclaw-process-container.test.ts`:
- Around line 18-33: The declared phase timeline does not match the work
performed by runWindowsMxcOpenClawProcessContainerQualification. Align the
phases with the actual boundaries by moving sandbox deletion, registry
verification, process termination, and cleanup into a distinct third
phase—either by splitting the qualification flow or having that function call
progress.phase for the cleanup phase through its existing progress parameter—so
the receipt assertion phase is not misleadingly used for completed work.

In `@test/e2e/support/windows-mxc-openclaw-process-container.test.ts`:
- Around line 232-249: Replace the source-text assertions in the test “uses
OpenShell as the sole MXC control boundary and never pre-deletes by name
(`#8178`)” with behavior-focused assertions on the exported helpers. Add AST rules
to tools/e2e/check-semantic-phases.mts that reject direct wxc-exec invocation
and sandbox-name deletion before creation, without relying on formatting,
literal counts, or source ordering; keep this test limited to observable
public-helper outcomes.
- Line 126: Update the assertion for normalizeReportedVersion("2026.7.10\n") to
use an exact expected normalized version value rather than a negative
comparison, preserving the test’s intended verification that the full version
does not get truncated to the prefix.

---

Nitpick comments:
In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts`:
- Around line 680-702: Update the timeout error in waitForPort to derive its
reported duration from COMMAND_TIMEOUT_MS instead of hardcoding “30 seconds,”
ensuring the message remains accurate if the constant changes.
- Around line 564-577: Update the output overflow branch in append to call
clearTimeout(timer) before killing the child and rejecting, ensuring the timeout
cannot fire after output-bound rejection.
- Around line 493-510: Update the health-polling flow around the gateway wait
loop so that exhausting its deadline writes a terminal failure marker or failure
body to readyPath, and ensure the host wait logic inspects that result and exits
promptly instead of waiting for READY_TIMEOUT_MS. Keep successful health
detection unchanged, and derive the agent and host deadlines from a shared
timeout where appropriate.
- Around line 269-271: Replace the local sha256File implementation with the
exported shared implementation from
tools/e2e/windows-mxc-openclaw-artifact-tree.mts, and import that symbol here so
both callers use one definition. Do not add the optional streaming change unless
required by the existing API.
- Around line 356-359: Update assertExpectedOpenClawProcessIdentity so the
expected port is validated as the ordered "--port" flag followed by
String(expected.port), rather than as an unconstrained command-line token.
Preserve the existing checks for the entry path, "gateway", and probe agent
path.
- Around line 768-790: Update assertCurrentCheckoutIdentity to resolve git using
the established trusted executable policy and execute both rev-parse and status
checks against the intended checkout root via cwd or git -C. Keep the existing
revision and clean-status validation behavior unchanged while removing
dependence on PATH and the caller’s working directory.

In `@test/e2e/support/windows-mxc-openclaw-process-container.test.ts`:
- Around line 130-196: Split the combined test into separate tests for each
exported function: sandboxListContainsExactName, shouldRetrySandboxDelete,
sameWindowsProcessIdentity, and assertExpectedOpenClawProcessIdentity. Keep the
existing assertions and scenarios unchanged, grouping the three process-identity
validation cases under the latter function so failures identify their specific
concern.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 978c9180-ee62-4eb0-9e8b-02f1d41f65be

📥 Commits

Reviewing files that changed from the base of the PR and between fdd6828 and adb7d84.

📒 Files selected for processing (6)
  • test/e2e/README.md
  • test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts
  • test/e2e/live/windows-mxc-openclaw-process-container.test.ts
  • test/e2e/support/windows-mxc-openclaw-process-container.test.ts
  • tools/e2e/check-semantic-phases.mts
  • tools/e2e/windows-mxc-openclaw-artifact-tree.mts

Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts Outdated
Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts Outdated
Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts Outdated
Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts Outdated
Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts
Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts
Comment thread test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts Outdated
Comment thread test/e2e/live/windows-mxc-openclaw-process-container.test.ts
Comment thread test/e2e/support/windows-mxc-openclaw-process-container.test.ts Outdated
Comment thread test/e2e/support/windows-mxc-openclaw-process-container.test.ts Outdated
@senthilr-nv senthilr-nv added chore Build, CI, dependency, or tooling maintenance area: e2e End-to-end tests, nightly failures, or validation infrastructure platform: windows Affects native Windows environments integration: openclaw OpenClaw integration behavior v0.0.103 Release target labels Aug 5, 2026
@cv

cv commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Maintainer train classification for adb7d8485a32071ad7bf1524a3330d6f63b7b204:

This PR is within #8178 delivery step 5 because it adds an inactive, opt-in qualification harness and does not register, activate, or document Windows/MXC support. It is not merge-ready yet:

  • Required CI fails because the new live target has no entry in test/e2e/mock-parity.json.
  • Fail closed on an unrelated nonzero sandbox create result; accept an exception only for an exact documented OpenShell outcome protected by a regression test.
  • Keep pc_least_privilege enabled, or document an exact version-bound upstream constraint and test the compensating privilege boundary.
  • Add direct artifact-digest tests for content and relative-path changes plus symlink and unsupported-entry rejection.

These are technical and security validation gaps, not approval to broaden the product surface. No check waiver or activation is proposed.

Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🧹 Nitpick comments (4)
test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts (1)

1143-1146: 🩺 Stability & Availability | 🔵 Trivial | ⚡ Quick win

Short-circuit the outcome wait when sandbox create fails.

create already runs with READY_TIMEOUT_MS. If create exits non-zero, no probe agent runs, so waitForFile(outcomePath, READY_TIMEOUT_MS) waits another 180000 ms and then throws a timeout error. The recorded primaryFailure then reports a missing outcome file instead of the create failure.

Fail fast on a non-zero create exit code and record the command detail.

♻️ Proposed short-circuit
+    if (create.exitCode !== 0) {
+      throw new Error(`OpenShell sandbox create failed: ${commandDetail(create)}`);
+    }
     await waitForFile(outcomePath, READY_TIMEOUT_MS);
     const ready = fs.existsSync(readyPath);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
1143 - 1146, Update the sandbox creation flow around the `create` result and
`waitForFile(outcomePath, READY_TIMEOUT_MS)` to check for a non-zero create exit
code first; skip waiting for the outcome file, fail immediately, and record the
create command detail in `primaryFailure` while preserving the existing outcome
handling for successful creates.
test/e2e/support/e2e-semantic-phase-check.test.ts (1)

52-65: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

Add coverage for the missing create and missing delete failures.

Both test sources contain a sandbox create call and a sandbox delete call. The branches at check-semantic-phases.mts lines 189-190 that emit "OpenShell sandbox create command is missing" and "OpenShell sandbox delete command is missing" are never exercised. A source that drops the sandbox lifecycle entirely is the case the guard exists to catch.

💚 Proposed additional case
+  test("rejects a Windows MXC control flow without sandbox create or delete", () => {
+    const source = `
+      async function qualify(cli, env, progress) {
+        await runCommand(cli, ["gateway", "select", "name"], env, progress, "select");
+      }
+    `;
+
+    expect(validateWindowsMxcControlBoundarySource(source)).toEqual([
+      "OpenShell sandbox create command is missing",
+      "OpenShell sandbox delete command is missing",
+    ]);
+  });
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/support/e2e-semantic-phase-check.test.ts` around lines 52 - 65, Add
test coverage in the semantic phase validation tests around
validateWindowsMxcControlBoundarySource for a source that omits both sandbox
lifecycle commands, and assert the expected “OpenShell sandbox create command is
missing” and “OpenShell sandbox delete command is missing” diagnostics. Keep the
existing direct wxc-exec and delete-before-create coverage unchanged.
tools/e2e/check-semantic-phases.mts (2)

2630-2637: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win

The Windows MXC validation is bound to one exact path string.

validateWindowsMxcControlBoundarySource runs only when relativeFile equals WINDOWS_MXC_OPENCLAW_HELPER. If the helper is renamed or moved, the traversal no longer matches, and the control-boundary guard stops running without any failure. The graph scan still succeeds, so no test reports the gap.

Assert that the constant resolves to an existing file, or record a failure when the live target graph contains no matching source.

♻️ Proposed existence assertion
     const relativeFile = path.relative(REPO_ROOT, file).split(path.sep).join("/");
     if (relativeFile === WINDOWS_MXC_OPENCLAW_HELPER) {
+      // The guard is path-bound; a rename must fail loudly instead of skipping validation.
       childProcessAuditFailures.push(
         ...validateWindowsMxcControlBoundarySource(sourceFile.text).map(
           (failure) => `${relativeFile}: ${failure}`,
         ),
       );
     }

Add a repository check that WINDOWS_MXC_OPENCLAW_HELPER exists on disk.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tools/e2e/check-semantic-phases.mts` around lines 2630 - 2637, Ensure the
repository scan validates that WINDOWS_MXC_OPENCLAW_HELPER resolves to an
existing file, recording a childProcessAuditFailures entry when it does not. Add
this check near the traversal logic so validateWindowsMxcControlBoundarySource
cannot silently stop running after the helper is moved or renamed.

156-197: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value

The ordering check proves source position, not execution order.

commandKind records node.getStart(sourceFile), so deletePositions.some((position) => position < observedCreatePosition) compares text offsets. A delete call placed in a helper function declared above the create call fails the check even when it runs after create. A delete that runs first at runtime but appears later in the file passes.

containsWxcExecPath is also broad. It matches any wxcExecPath identifier inside an argument subtree, including a non-executing use such as path.dirname(inputs.openShell.wxcExecPath) in a spawn options object.

Both behaviors are acceptable for a source-level guard. Record the intent in a comment so a later reader does not treat the check as a control-flow proof.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tools/e2e/check-semantic-phases.mts` around lines 156 - 197, Add a concise
comment near the source-position tracking and ordering logic in `inspect`
explaining that the check is a source-level guard based on textual offsets, not
runtime control-flow or execution order, and that `containsWxcExecPath`
intentionally performs broad subtree matching. Do not change `commandKind`,
`getStart(sourceFile)`, or the existing validation behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@test/e2e/support/windows-mxc-openclaw-process-container.test.ts`:
- Around line 210-230: Update the negative case in the test “requires the
OpenShell gateway path and ordered port argument pair (`#8178`)” to keep the
expected port at 17670 while constructing a command line where --port and 17670
are not adjacent or correctly ordered, then assert that
assertExpectedOpenShellGatewayProcessIdentity throws. Remove the unrelated
--other 9999 variation so the test specifically validates ordered port-argument
matching.

---

Nitpick comments:
In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts`:
- Around line 1143-1146: Update the sandbox creation flow around the `create`
result and `waitForFile(outcomePath, READY_TIMEOUT_MS)` to check for a non-zero
create exit code first; skip waiting for the outcome file, fail immediately, and
record the create command detail in `primaryFailure` while preserving the
existing outcome handling for successful creates.

In `@test/e2e/support/e2e-semantic-phase-check.test.ts`:
- Around line 52-65: Add test coverage in the semantic phase validation tests
around validateWindowsMxcControlBoundarySource for a source that omits both
sandbox lifecycle commands, and assert the expected “OpenShell sandbox create
command is missing” and “OpenShell sandbox delete command is missing”
diagnostics. Keep the existing direct wxc-exec and delete-before-create coverage
unchanged.

In `@tools/e2e/check-semantic-phases.mts`:
- Around line 2630-2637: Ensure the repository scan validates that
WINDOWS_MXC_OPENCLAW_HELPER resolves to an existing file, recording a
childProcessAuditFailures entry when it does not. Add this check near the
traversal logic so validateWindowsMxcControlBoundarySource cannot silently stop
running after the helper is moved or renamed.
- Around line 156-197: Add a concise comment near the source-position tracking
and ordering logic in `inspect` explaining that the check is a source-level
guard based on textual offsets, not runtime control-flow or execution order, and
that `containsWxcExecPath` intentionally performs broad subtree matching. Do not
change `commandKind`, `getStart(sourceFile)`, or the existing validation
behavior.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 59d64e4d-d38e-45e0-b154-5b565a06db8e

📥 Commits

Reviewing files that changed from the base of the PR and between adb7d84 and 64a7ea2.

📒 Files selected for processing (8)
  • test/e2e/README.md
  • test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts
  • test/e2e/live/windows-mxc-openclaw-process-container.test.ts
  • test/e2e/mock-parity.json
  • test/e2e/support/e2e-semantic-phase-check.test.ts
  • test/e2e/support/windows-mxc-openclaw-process-container.test.ts
  • tools/e2e/check-semantic-phases.mts
  • tools/e2e/windows-mxc-openclaw-artifact-tree.mts
🚧 Files skipped from review as they are similar to previous changes (2)
  • test/e2e/live/windows-mxc-openclaw-process-container.test.ts
  • test/e2e/README.md

Comment thread test/e2e/support/windows-mxc-openclaw-process-container.test.ts
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
@senthilr-nv

Copy link
Copy Markdown
Collaborator Author

Addressed the latest review feedback in 7b1f42b2:

  • fail immediately on a nonzero sandbox create result and preserve its command detail;
  • revalidate pinned OpenShell, wxc-exec, Node.js, and OpenClaw artifacts immediately before security-relevant use, with a replacement regression test;
  • fail loudly if the path-bound MXC semantic guard disappears, and cover missing lifecycle commands;
  • clarify that delete retry and process termination are failure containment and cannot produce a passing qualification.

Focused E2E support tests pass (35/35), semantic phase coverage passes (118 tests across 75 files), repository checks and docs validation pass, and the exact-head security and documentation reviews pass.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (2)
test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts (2)

930-944: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Register the live target in mock parity.

Add this Windows MXC OpenClaw target to test/e2e/mock-parity.json. Without registration, the live qualification flow can diverge from its required mock coverage.

As per path instructions, add the target to mock-parity.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
930 - 944, Register the Windows MXC OpenClaw qualification target in
test/e2e/mock-parity.json, using the target identity associated with
runWindowsMxcOpenClawProcessContainerQualification. Preserve the existing
mock-parity structure and entries while adding this live target so it has
corresponding mock coverage.

Source: Path instructions


905-918: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Add direct artifact-tree boundary tests.

Add direct tests for content changes, relative-path changes, symlink rejection, unsupported entries, deterministic ordering, and traversal or file-count limits. The current qualification depends on these properties to validate the staged artifact identity.

As per path instructions, preserve direct artifact-tree tests for digest sensitivity, relative-path changes, symlink rejection, unsupported entries, deterministic ordering, and traversal/file-count limits.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts` around lines
905 - 918, Add direct tests for the artifact-tree hashing helper used by
assertExactArtifactIdentities, covering content and relative-path changes,
symlink and unsupported-entry rejection, deterministic ordering, and
traversal/file-count limits. Keep these as focused unit tests of the
artifact-tree behavior so qualification continues validating staged artifact
identity.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts`:
- Around line 930-944: Register the Windows MXC OpenClaw qualification target in
test/e2e/mock-parity.json, using the target identity associated with
runWindowsMxcOpenClawProcessContainerQualification. Preserve the existing
mock-parity structure and entries while adding this live target so it has
corresponding mock coverage.
- Around line 905-918: Add direct tests for the artifact-tree hashing helper
used by assertExactArtifactIdentities, covering content and relative-path
changes, symlink and unsupported-entry rejection, deterministic ordering, and
traversal/file-count limits. Keep these as focused unit tests of the
artifact-tree behavior so qualification continues validating staged artifact
identity.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 94fdd7af-f942-443e-b794-ee8f8afab617

📥 Commits

Reviewing files that changed from the base of the PR and between 0bce964 and 7b1f42b.

📒 Files selected for processing (5)
  • test/e2e/README.md
  • test/e2e/live/windows-mxc-openclaw-process-container-helpers.ts
  • test/e2e/support/e2e-semantic-phase-check.test.ts
  • test/e2e/support/windows-mxc-openclaw-process-container.test.ts
  • tools/e2e/check-semantic-phases.mts
🚧 Files skipped from review as they are similar to previous changes (2)
  • test/e2e/README.md
  • test/e2e/support/e2e-semantic-phase-check.test.ts

Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
@senthilr-nv
senthilr-nv enabled auto-merge (squash) August 5, 2026 15:08
@senthilr-nv
senthilr-nv requested a review from cv August 5, 2026 15:16

@cjagwani cjagwani left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review — exact head afcd6266ce6af736a9018bcd19c68b6afabe08af against base cbabb66bfc985f3474714f95bfbc6ec1992441f9: PASS with no findings.

  1. Secrets and credentials — PASS. The opt-in target creates an ephemeral random readiness token, keeps it out of arguments and receipts, redacts command output, and passes host children only an explicit Windows runtime-variable allowlist. No repository secret or reusable credential is added.
  2. Input validation and injection resistance — PASS. Required inputs are validated as exact revisions, versions, paths, hashes, ports, and process identities. Runtime commands use argument arrays rather than shell interpolation. Files and artifact trees are resolved, type-checked, bounded, and rejected when they contain links or unsupported entries.
  3. Authentication and authorization — PASS. The temporary gateway is loopback-bound and token-protected. The target neither registers nor activates MXC as a supported runtime and does not widen repository or host permissions.
  4. Dependencies and supply chain — PASS. No dependency or lockfile changes. NemoClaw, OpenShell, wxc-exec, Node, OpenClaw entry, and the complete OpenClaw artifact tree are identity-pinned and revalidated immediately before security-relevant use.
  5. Error handling and information exposure — PASS. Create, query, identity, policy, and cleanup failures are fail-closed. Child output is size-bounded, diagnostics omit the token, and the qualification receipt contains only non-secret evidence.
  6. Cryptography and data protection — PASS. randomBytes(32) supplies the ephemeral token. SHA-256 is used for deterministic artifact identity, not as an authentication substitute. Sensitive temporary state is removed during terminal cleanup.
  7. Configuration and infrastructure — PASS. The generated gateway and filesystem policy are temporary and least-privilege; network access is limited to loopback. The qualification is inactive and opt-in, with bounded processes, timeouts, output, artifact traversal, and cleanup scope.
  8. Security testing — PASS. Support contracts cover identity drift and replacement, dirty-source and version-prefix rejection, complete process identity, token exclusion, environment filtering, tree-content/path/link/device cases, semantic phases, policy allow/deny behavior, and cleanup fallbacks. Exact GitHub Actions and protected qualification evidence remain mandatory.
  9. System security — PASS. Emergency process termination occurs only after re-querying and matching the recorded executable, arguments, parent/child relationship, and port identity. Cleanup targets exact generated names and run directories and reports any residual sandbox, process, registry, or sensitive path.

The current head is a signed mechanical merge of current main. Its effective eight-file patch is byte-for-byte unchanged from reviewed head 98adf64d2b1c7d5275c801dadc30c9c44ff34911 (raw patch SHA-256 285c9a4cd764c51605f45f8a8bdaa9e557ff6db3d91980bd62cf80268b779734; stable patch ID d6bf3bd8aef510d5f59dc5c5d803216d62c0d3df). No product-scope waiver or gate waiver is used.

Signed-off-by: Charan Jagwani <cjagwani@nvidia.com>

@cjagwani cjagwani left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review — exact head 99e54157678400cfda425bdc9a1f0e531749e6ea against base cbabb66bfc985f3474714f95bfbc6ec1992441f9: PASS with no findings.

The nine-category review at parent afcd6266ce6af736a9018bcd19c68b6afabe08af is carried forward without expansion. The only new change is a documentation correction in test/e2e/README.md: it now says a secret-free receipt is written for either verdict only after preflight and local setup succeed. That matches the implementation and removes an unsafe expectation that early identity or host-validation failures would always leave a receipt.

  1. Secrets and credentials — PASS: no secret-bearing behavior or example changes.
  2. Input validation and injection resistance — PASS: no executable path changes; exact identity and argument-array controls remain intact.
  3. Authentication and authorization — PASS: the loopback token boundary and inactive/no-support scope are unchanged.
  4. Dependencies and supply chain — PASS: no dependency or artifact source changes.
  5. Error handling and information exposure — PASS: the documentation now accurately distinguishes pre-receipt failures from verdict-bearing runs.
  6. Cryptography and data protection — PASS: token generation, SHA-256 identity checks, and sensitive-state cleanup are unchanged.
  7. Configuration and infrastructure — PASS: no policy, privilege, host, network, or workflow change.
  8. Security testing — PASS: the previous exact eight-file security contracts remain unchanged; Markdown lint and the repository test-file budget passed for the follow-up.
  9. System security — PASS: no process, cleanup, filesystem, or trusted-boundary behavior changes.

Commit 99e54157678400cfda425bdc9a1f0e531749e6ea is signed and Signed-off-by. Fresh CI, independent exact-head approval, and protected E2E remain mandatory; no prior-head result is accepted.

@cjagwani
cjagwani requested a review from apurvvkumaria August 5, 2026 16:49
@cjagwani

cjagwani commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

The required documentation-writer review found and fixed one exact operator-contract issue in signed, GitHub-Verified commit 99e54157678400cfda425bdc9a1f0e531749e6ea: receipts are written for either verdict only after preflight and local setup succeed; earlier validation failures may occur before receipt creation. Normal Markdown lint and the repository test-file budget passed. The exact-head nine-category security review passed, and fresh CI plus protected E2E are required. Please review the current head so the post-push approval rule can be satisfied.

@senthilr-nv
senthilr-nv merged commit 30f6554 into main Aug 5, 2026
76 checks passed
@senthilr-nv
senthilr-nv deleted the codex/windows-mxc-process-container-e2e branch August 5, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: e2e End-to-end tests, nightly failures, or validation infrastructure chore Build, CI, dependency, or tooling maintenance integration: openclaw OpenClaw integration behavior platform: windows Affects native Windows environments v0.0.103 Release target

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants