Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed October 5, 2026, 9:48 AM ET / 13:48 UTC (Revision 7). ClawSweeper reviewWhat this changesThe Tauri desktop companion gains Windows bundled-Bun staging, private Node-based CLI installation, and explicit Gateway runtime selection through the existing Windows service owner. Merge readiness⛔ Blocked before merge - 4 items remain Useful Windows desktop preparation remains absent from current main. The draft accurately records its native adoption limitation and outstanding signed-artifact qualification; neither merged prerequisite supersedes this work. Priority: P2 Review scores
Verification
How this fits togetherThe desktop companion installs or invokes the canonical CLI, which owns Windows Gateway service changes. Verified bundled runtime files supply the executable, while explicit user confirmation and captured service state control adoption. flowchart TD
A[Windows artifact pins] --> B[Verify and stage runtime]
B --> C[Immutable runtime files]
D[Desktop setup or confirmation] --> E[Canonical CLI]
C --> E
E --> F[Check current service authority]
F --> G[Preserve or replace Gateway]
Decision needed
Why: Native proof establishes an actual privilege boundary; choosing the supported user experience and elevation contract requires maintainer intent. Before merge
Agent review detailsSecurityNone. PR surfaceSource +146, Tests +498, Docs +116, Config +24, Other +777. Total +1561 across 31 files. View PR surface stats
Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Provide a consented one-shot canonical-CLI elevation handoff that retains the captured pin and revalidates service authority, while preserving ordinary desktop privileges and existing runtime selections. Do we have a high-confidence way to reproduce the issue? Not applicable as a feature proposal; supplied native Windows proof does establish fresh setup success and reproducible restricted-service adoption refusal. Is this the best way to solve the issue? Yes for the ownership structure: reuse the canonical installer and Windows service writer. Completion still depends on choosing the supported privilege handoff and qualifying signed native artifacts. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against 740ddaa458e3. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (6 earlier review cycles)
|
81a0ebc to
8dff06a
Compare
8dff06a to
d8916dc
Compare
What Problem This Solves
Prepares the Tauri desktop companion to run its local Gateway on the bundled fork Bun on Windows x64 and ARM64 through the canonical Windows service owner.
User Impact
DRAFT — do not merge or publish Windows builds. Windows runtime admission stays inert until a signed fork artifact exists for the matching architecture. The OpenClaw Foundation Azure Artifact Signing identity is approved. Production qualification requires the corrected signed fork prerelease, coordinator-generated x64/ARM64 pins, and matching release-profile proof. Native existing-install proof also confirmed a privilege-boundary blocker below. Work is stopped for the requested design decision; this draft is not ready for merge. The current real unsigned x64 pin is test preparation data; no ARM64 hash or artifact is fabricated.
Existing Gateways retain their runtime across startup, reconnect, quit and app updates. Adoption requires Use bundled runtime… and its native confirmation. Fresh Windows setup supports Stable and Beta packages.
Why This Change Was Made
The shared release-manifest projection supports both Windows targets while preserving all four Unix pin entries and their provenance. The stager verifies archive/executable hashes and matching PE architecture. The existing materializer publishes immutable
.exeslots under the Windows state root with native file locking, reparse rejection and closed write handles before rename. The build-only local-artifact option admits explicitly test-only debug proof; unsigned release-profile input is refused.The CLI stays on private Node; the Gateway uses bundled Bun. The explicit action carries the observed
--expected-runtime-pininto the existing Scheduled Task reconciliation owner. Prerequisites #165261 (stop old → publish definition → start new) and #165538 (authored runtime-pin identity versus effective native cwd) are merged. No new service owner, user configuration or automatic migration is introduced.Updates preserve the selected runtime and native task policy. Fresh setup needs Windows private CLI installation and command transport; these remain in the existing installer/CLI owners. PowerShell 5 transports npm policy and account aliases without dropping empty arguments or nesting arrays. The prerequisite's published 2026.9.8 → candidate update passed; its known same-account UserId warning was retained. This branch fixes that alias comparison with a native regression. Uninstall uses the independent canonical CLI contract: quit the app, then run from Node and a CLI package outside the state directory.
The native privilege boundary requires a design decision before continuing: an explicitly consented one-shot elevation handoff through the existing canonical CLI, retaining the captured pin across elevation, or manual elevated-CLI guidance for these installations. Neither option is implemented; the ordinary desktop app is not elevated and task permissions are unchanged.
Evidence
Exact-head native CI passed Windows x64, Windows ARM64, Linux and macOS. Each Windows job asserts its native OS architecture and explicit Rust target, then passes 10 materialization cases, 61 Windows-filtered cases (four overlap), one power test and one process-owner test. General CI is skipped for the draft. This proves app-side fixtures; real ARM64 Bun execution awaits the corrected fork artifact and signed prerelease.
The actual app executable was built before the final rebase; all production Rust/UI and embedded installer inputs are byte-identical to the final candidate. Only docs, a JS test and nine
cfg(test)lines changed. The final canonical CLI was rebuilt natively in 3m44.2s and its package validation passed in 146s.Measured file costs with the repository wrapper and
--maxWorkers=1:src/cli/daemon-cli/install.test.tssrc/daemon/service-audit-schtasks.windows.test.tssrc/daemon/service-definition-schtasks.test.tstest/scripts/install-ps1.release.test.tstest/scripts/stage-openclaw-bun.test.tsInitial native Windows installer/audit proof took 264.98s including cold transforms; the SID regression took 664ms. The refreshed 15-case native audit suite took 138.78s including cold transforms. Final CI wall times: Windows ARM64 358s, Windows x64 241s, Linux 326s, macOS 252s.
Before: Windows CLI installation was unavailable in the companion.
After: explicit Stable/Beta setup and the actual Gateway Control UI on the unsigned test-only build.
Existing Node Gateway: the native tray exposes the explicit runtime action. Its confirmation names the observed runtime and explains the service restart and future explicit-action requirement. Only the synthetic test path is redacted.
Current native refusal, before any service mutation: