diff --git a/AGENT_BOARD.md b/AGENT_BOARD.md index d663623..a2791b6 100644 --- a/AGENT_BOARD.md +++ b/AGENT_BOARD.md @@ -64,7 +64,7 @@ Bring the Windows 11 always-on PC, Tencent Cloud VPS OpenClaw Gateway, phone Con | T6 | Verify VPS baseline before any VPS change | VPS_VERIFIER | T4 | Accepted | | T7 | Monitor drift, sync-health failures, conflicts, unsafe changes, and missing evidence | CORRECTION | G0A | Claimed | | T8 | Solidify COACH role, session freeze, and knowledge capture | COACH | T2.1 | Done | -| T9 | G2 PC foreground node run | PC_EXECUTOR | Fresh user G2 authorization, fresh T13 PASS, T7 healthy | Blocked | +| T9 | G2 PC foreground node run | PC_EXECUTOR | Fresh user G2 authorization, fresh T13 PASS, T7 healthy | Ready | | T10 | G2 VPS pairing approval | VPS_EXECUTOR | T9, explicit approval authorization | Blocked | | T11 | Verify G2 PC evidence | PC_VERIFIER | T9 | Draft | | T12 | Verify G2 VPS evidence and freeze compliance | VPS_VERIFIER | T10 | Draft | @@ -100,7 +100,7 @@ Bring the Windows 11 always-on PC, Tencent Cloud VPS OpenClaw Gateway, phone Con ## G2 Authorization Boundary -- Fresh second G2 authorization was received on 2026-05-19 for ORCHESTRATOR in `D:\openclaw-control-plane`; T13 may proceed under `docs/G2_RUNBOOK.md`, but T9 is blocked until CORRECTION records a fresh T13 PASS with healthy sync. +- Fresh second G2 authorization was received on 2026-05-19 for ORCHESTRATOR in `D:\openclaw-control-plane`; T13 has recorded a fresh PASS with healthy sync, so T9 may proceed under `docs/G2_RUNBOOK.md`. - `docs/G2_RUNBOOK.md` remains the planned G2 procedure, but it does not authorize token injection, `openclaw node run`, VPS approval, or any mutation by itself. - T10 remains blocked until T9 evidence contains a matching non-secret pairing request ID or pending node ID. - G2 must remain foreground-only for the PC node; service persistence belongs to G4. diff --git a/USER_STATUS.md b/USER_STATUS.md index ad99a25..4d1ca2e 100644 --- a/USER_STATUS.md +++ b/USER_STATUS.md @@ -6,7 +6,7 @@ Stage 2A Authorized: foreground G2 may start under runbook. -Fresh second G2 authorization was reconfirmed for ORCHESTRATOR in `D:\openclaw-control-plane`. T13 and T9 may proceed under `docs/G2_RUNBOOK.md`; T10 must wait until T9 produces a matching non-secret pairing request ID or pending node ID. +Fresh second G2 authorization was reconfirmed for ORCHESTRATOR in `D:\openclaw-control-plane`. CORRECTION recorded a fresh T13 PASS, so T9 may proceed under `docs/G2_RUNBOOK.md`; T10 must wait until T9 produces a matching non-secret pairing request ID or pending node ID. ## Completed @@ -76,14 +76,14 @@ No additional user decision is needed for T9 if PC_EXECUTOR stays within `docs/G ## Latest Health Snapshot -- Snapshot refreshed: 2026-05-19 14:44 UTC+8 from tracked control-plane files. -- PC sync heartbeat: clean at `2026-05-19T14:43:58+08:00`. -- VPS sync heartbeat: clean at `2026-05-19T14:43:58+0800`. +- Snapshot refreshed: 2026-05-19 16:31 UTC+8 from tracked control-plane files. +- PC sync heartbeat: clean at `2026-05-19T16:31:42+08:00`. +- VPS sync heartbeat: clean at `2026-05-19T16:31:06+0800`. - Sync error files: none observed. - G2 runbook: `docs/G2_RUNBOOK.md` complete. - G2 authorization card: `docs/G2_AUTHORIZATION_CARD.md` prepared for user review. - G2 authorization: fresh second authorization reconfirmed for foreground PC node run and corresponding VPS pairing approval only. -- Next work: T13 guard and T9 foreground PC node run. +- Next work: T9 foreground PC node run by PC_EXECUTOR. - Public website freeze: still active. - Mutation/setup phase: limited G2 foreground pairing may start; service persistence and infrastructure changes remain forbidden. @@ -95,4 +95,4 @@ No additional user decision is needed for T9 if PC_EXECUTOR stays within `docs/G - Blocked: T10/VPS approval until T9 produces one matching non-secret pairing request/node ID. G3 and G4 remain closed. - Safety constraints: no secret recording, no `openclaw node install/start`, no service persistence, no Nginx/Docker/website/firewall/network changes. - Next owner: PC_EXECUTOR for T9, with CORRECTION monitoring T13. -- Single next action: PC_EXECUTOR claims T9, writes `rollback/pc-g2-node-run-YYYYMMDD.md`, then follows only the foreground node flow in `docs/G2_RUNBOOK.md`. +- Single next action: PC_EXECUTOR claims T9, confirms or refreshes `rollback/pc-g2-node-run-YYYYMMDD.md`, then follows only the foreground node flow in `docs/G2_RUNBOOK.md`. diff --git a/handoff/ORCHESTRATOR.md b/handoff/ORCHESTRATOR.md index fef6add..9ccb3b6 100644 --- a/handoff/ORCHESTRATOR.md +++ b/handoff/ORCHESTRATOR.md @@ -6,7 +6,7 @@ Own requirements alignment, task decomposition, dependency tracking, and final a ## Current Objective -Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: T13 guard must record a fresh PASS before T9 can resume; T10 remains blocked until T9 evidence provides one matching non-secret request/node ID. +Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: T13 has recorded a fresh PASS, T9 is released for PC_EXECUTOR, and T10 remains blocked until T9 evidence provides one matching non-secret request/node ID. ## Must Read @@ -29,7 +29,7 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: - `USER_STATUS.md` is the user-facing status entry; internal agent ledgers should not be required reading for the user. - Fresh second G2 authorization was received and reconfirmed for ORCHESTRATOR in `D:\openclaw-control-plane` on 2026-05-19. - `docs/G2_RUNBOOK.md` has been prepared as the G2 execution-before-action runbook. It does not authorize execution by itself. -- Sync-health is not currently cleared for T9: latest tracked PC and VPS heartbeats are clean but stale relative to the 5-minute blocked threshold, and no `sync-state/error-*.md` files are observed in the latest control-plane snapshot. +- Sync-health is currently cleared for T9: latest tracked PC and VPS heartbeats are clean and within the 5-minute threshold, and no `sync-state/error-*.md` files are observed in the latest control-plane snapshot. - T2.1 and T8 are now treated as complete control-plane setup work; G2 is In Progress under the limited runbook scope. - The polling sync is intentionally temporary; design an async notification/coordinator layer when PC/VPS baseline work is stable. - Filing-review freeze path wording has been corrected from the obsolete single `docker-composite.yml` reference to `/opt/services/docker-compose.openclaw.yml` plus any equivalent compose/service entries that could affect public website output. @@ -38,8 +38,8 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: 1. Keep `USER_STATUS.md` current when gate, blocker, heartbeat, or required user decision changes. 2. Keep T7/CORRECTION monitoring active for sync-health, drift, missing evidence, and freeze-policy risk. -3. Require CORRECTION to rerun T13 and record a fresh PASS with healthy sync/secret/freeze guardrails before T9 resumes. -4. Keep PC_EXECUTOR blocked on T9 until that fresh T13 PASS exists; after unblock, PC_EXECUTOR may write `rollback/pc-g2-node-run-YYYYMMDD.md`, set token only in the local shell/session without recording it, and run only the foreground node command in `docs/G2_RUNBOOK.md`. +3. Keep CORRECTION monitoring T13 for sync/secret/freeze guardrails during T9. +4. Let PC_EXECUTOR claim T9, confirm or refresh `rollback/pc-g2-node-run-YYYYMMDD.md`, set token only in the same local shell/session without recording it, and run only the foreground node command in `docs/G2_RUNBOOK.md`. 5. Keep T10 blocked until T9 evidence includes a matching non-secret pairing request ID or pending node ID. 6. Continue forbidding service persistence, `openclaw node install/start`, Nginx/Docker/website changes, firewall/network changes, G3 smoke test, G4 setup, and recording any token or secret. @@ -50,6 +50,17 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: ## Last Update +2026-05-19 16:31 UTC+8: ORCHESTRATOR released T9 based on CORRECTION fresh T13 PASS, without executing G2. + +- `git pull` returned already up to date. +- G2 remains authorized and `AGENT_BOARD.md` shows G2 `In Progress`. +- CORRECTION recorded fresh T13 PASS at 2026-05-19 16:29 UTC+8 for sync/secret/role/freeze/config risks. +- Current tracked sync heartbeats are clean and within the 5-minute threshold: PC `2026-05-19T16:31:42+08:00`, VPS `2026-05-19T16:31:06+0800`. +- `sync-state/` contains `README.md`, `heartbeat-pc.json`, and `heartbeat-vps.json`; no tracked `error-*.md` files were observed. +- `AGENT_BOARD.md` and `tasks/T9-G2-PC-node-run.md` were updated so T9 is Ready. +- T10 remains Blocked until T9 produces one matching non-secret pairing request ID or pending node ID. +- ORCHESTRATOR did not execute PC/VPS commands, did not handle a token, did not start a node, and did not approve pairing. + 2026-05-19 16:24 UTC+8: ORCHESTRATOR reconciled G2 execution state without executing G2. - `git pull` returned already up to date. @@ -119,7 +130,7 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: ## G2 Planning State -- T9: PC foreground node run, blocked pending fresh T13 PASS with healthy sync and same-session token availability. +- T9: PC foreground node run, ready after fresh T13 PASS with healthy sync; PC_EXECUTOR must still ensure same-session token availability without disclosure. - T10: VPS pairing approval, blocked until T9 evidence. - T11: PC G2 verification, draft. - T12: VPS G2 verification and freeze compliance, draft. @@ -156,6 +167,6 @@ Resume prompt: ```text You are ORCHESTRATOR resuming OpenClaw G2. Read USER_STATUS.md, AGENT_BOARD.md, handoff/ORCHESTRATOR.md, tasks/T9-G2-PC-node-run.md, tasks/T10-G2-VPS-pairing-approve.md, tasks/T13-G2-correction-guard.md, docs/G2_RUNBOOK.md, and sync-state/README.md. -Current state: G2 is In Progress under limited runbook scope; T13 is Ready for a fresh guard check; T9 is Blocked until fresh T13 PASS with healthy sync; T10 is Blocked until T9 produces one matching non-secret pairing request/node ID. +Current state: G2 is In Progress under limited runbook scope; T13 has fresh PASS; T9 is Ready for PC_EXECUTOR under docs/G2_RUNBOOK.md; T10 is Blocked until T9 produces one matching non-secret pairing request/node ID. Do not execute PC/VPS commands from ORCHESTRATOR. Do not handle or record secrets. Keep G3/G4 closed. ``` diff --git a/sync-state/heartbeat-pc.json b/sync-state/heartbeat-pc.json index f0f49ce..087940b 100644 --- a/sync-state/heartbeat-pc.json +++ b/sync-state/heartbeat-pc.json @@ -1,9 +1,9 @@ { "host": "pc", - "time": "2026-05-19T16:31:42+08:00", + "time": "2026-05-19T16:32:44+08:00", "branch": "main", - "head": "e3d1946", - "status": "clean", + "head": "babc0b9", + "status": "dirty", "intervalSeconds": 30, "heartbeatEverySeconds": 60 } diff --git a/tasks/T9-G2-PC-node-run.md b/tasks/T9-G2-PC-node-run.md index 742c0ea..8ee8f3b 100644 --- a/tasks/T9-G2-PC-node-run.md +++ b/tasks/T9-G2-PC-node-run.md @@ -2,7 +2,7 @@ ## Status -blocked +ready ## Owner @@ -38,7 +38,16 @@ This task is not ready until ORCHESTRATOR records explicit user authorization fo - No token value was read, printed, recorded, committed, or chat-sent. - No service, scheduled task, firewall, network, environment persistence, or public-port exposure change was performed. - Evidence: `evidence/pc-g2-node-run-20260519.md`. -- T9 is blocked until the token is available in the same non-persistent local shell session that will run the foreground node, without printing or recording the token value. +- This prior attempt remained stopped because the token was not available in the same non-persistent local shell session that would run the foreground node. + +## Release - 2026-05-19 16:31 UTC+8 + +- ORCHESTRATOR reviewed CORRECTION's fresh T13 PASS from 2026-05-19 16:29 UTC+8. +- G2 remains authorized and `In Progress`. +- PC and VPS heartbeats are clean and within the 5-minute sync-health threshold. +- No `sync-state/error-*.md` files were observed. +- T9 is released back to `ready` for PC_EXECUTOR under `docs/G2_RUNBOOK.md`. +- PC_EXECUTOR must still set `OPENCLAW_GATEWAY_TOKEN` only in the same non-persistent local shell session that will run the foreground node, without printing or recording the token value. ## Required Evidence