Conversation
|
Codex review: blocked before merge. Reviewed October 5, 2026, 2:38 PM ET / 18:38 UTC (Revision 2). ClawSweeper reviewWhat this changesThe branch makes ShellBench’s gateway client identify and sign as a CLI operator, adds bounded startup and agent-registration retries, cleans pending requests, and documents pairing with regression coverage. Regression provenancePossible regression — suspected (reviewed change). No predecessor PR is attributed. Merge readiness⛔ Blocked before merge - 4 items remain The repair remains necessary and has credible live gateway validation. An existing identity-disabled worker configuration loses its authentication compatibility path, so its upgrade handling needs resolution before merge. Priority: P1 Review scores
Verification
How this fits togetherShellBench’s benchmark harness creates agents and sessions through OpenClaw’s WebSocket gateway. Gateway admission and session setup must succeed before benchmark tasks can run. flowchart TD
A[Benchmark task] --> B[Gateway client]
C[Token and device identity] --> B
B --> D[Gateway admission]
D --> E[Agent creation]
E --> F[Bounded registration retry]
F --> G[Benchmark session]
Decision needed
Why: The worker explicitly supports this configuration today, while the branch changes the gateway policy it reaches; choosing its permanent support contract requires maintainer intent. Before merge
Findings
Agent review detailsSecurityNone. Review metrics
Root-cause clusterRelationship: Members:
Proposal only: this assessment does not dispatch repair, suppress jobs, mutate sibling items, close, or merge anything. Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Keep the signed CLI repair and bounded retries, with an approved, tested migration from identity-disabled workers to paired operator access and an actionable preflight diagnostic. Do we have a high-confidence way to reproduce the issue? Yes: current-main identity and immediate session setup match the reported failures, and the older gateway authentication policy establishes the identity-disabled upgrade failure. This review did not execute target code. Is this the best way to solve the issue? Unclear overall: signed CLI access and targeted retries fit the reported bugs, but the worker’s existing identity-disabled configuration needs an explicit migration or supported compatibility path. Full review comments:
Overall correctness: patch is incorrect AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against e3f8d25a01f4. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rank-up movesOptional improvements that raise the rating; they are not merge blockers.
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
What does this PR do?
Restore the gateway client’s compatibility with OpenClaw 2026.9.5: identify and sign as a CLI operator, tolerate a newly created agent’s registration delay, and retry the gateway’s explicit startup admission response within the existing connection budget.
Why?
Fixes #91. Thanks @FancyKat for the precise report and successful workaround.
The browser Control UI identity triggers the gateway’s build-ID admission check. Separately,
agents.createreturns before its configuration hot reload becomes visible tosessions.create. A live smoke also exposedUNAVAILABLE - gateway starting; retry shortlyafter the HTTP health endpoint was already serving.Changes
cliidentity and mode in both the connection metadata and device signature; retain gateway device approval and operator-scope enforcement.INVALID_REQUEST/Unknown agent idresponse for an agent this client just created. The window lasts at most five seconds from creation, capped by the request timeout; success and deletion end eligibility, and reconnect preserves the original deadline.RuntimeErrortext. Release pending RPC bookkeeping on cancellation and send failure as well as timeout.Tests
AWS Crabbox, Python 3.14, with
python -m pip install -e '.[dev]':python -m pytest -q: 548 passed, 5 skipped; one existing Gradio warning.python -m ruff check clawbench app.py scripts tests, changed-file pre-commit hooks,python -m pip check, wheel build and wheel runtime-data inspection passed.Real OpenClaw 2026.9.5 (
ec9c1a1), Node 24.18.1, with isolated synthetic gateway/harness state:NOT_PAIRED. Listing and explicitly approving that exact device throughopenclaw devicesenabled the connection.sessions.createcalls reproducedUnknown agent idfor 3/3 new agents. The patchedcreate_sessionrecovered for 3/3 and returned real session keys.agents.createforbidden for missingoperator.admin.Passing live gateway and final wheel proof. Synthetic local state only; no model/provider calls or benchmark score claim.
Independent Codex autoreview through P2: scoped clean.
Exact head
cc71bb4323dace43a62bb2a40494440f8ba9db21passes Python 3.11 and 3.12 CI.