Sync agent state from PC at 2026-05-21 16:55:03

This commit is contained in:
wangzhendong
2026-05-21 16:55:03 +08:00
parent 193bf821cb
commit dc7e5bb0da
2 changed files with 34 additions and 20 deletions

View File

@@ -4,9 +4,9 @@
## Current Stage
Stage 2A Authorized: foreground G2 may start under runbook.
Stage 2A In Progress: PC node connected; Gateway status check needed.
Fresh second G2 authorization was reconfirmed for ORCHESTRATOR in `D:\openclaw-control-plane`. CORRECTION recorded a fresh T13 PASS, so T9 may proceed under `docs/G2_RUNBOOK.md` using a user-run local PowerShell token/node flow; T10 must wait until T9 produces a matching non-secret pairing request ID or pending node ID.
T9 is done. PC_EXECUTOR recorded only non-secret evidence, and the user reported the PC node connected to `openclaw.smartmotor.cloud`. No pairing request ID or pending node ID was provided, so T10 remains blocked while VPS_EXECUTOR performs a read-only Gateway pending/online status check.
## Completed
@@ -19,13 +19,14 @@ Fresh second G2 authorization was reconfirmed for ORCHESTRATOR in `D:\openclaw-c
- The `smartmotor.cloud` filing-review website freeze is active as a hard rule.
- PC baseline was collected and independently accepted.
- VPS baseline was collected and independently accepted.
- T9 PC foreground node run completed with non-secret evidence: user reported connection to `openclaw.smartmotor.cloud`.
- Sync-health recovered and is currently healthy under CORRECTION monitoring.
- Current communication remains Git polling; future work should upgrade to async notification or a coordinator after the basic path is stable.
## Current Blockers
- No active sync-health blocker is recorded.
- VPS pairing approval is blocked until T9 produces a matching non-secret pairing request ID or pending node ID.
- VPS pairing approval is blocked until T10A finds one matching non-secret pairing request/node ID, or proves the intended PC node is already online/approved.
- G3 smoke test and G4 persistence remain closed.
## Allowed Actions
@@ -35,13 +36,13 @@ Fresh second G2 authorization was reconfirmed for ORCHESTRATOR in `D:\openclaw-c
- Agents may continue read-only monitoring for sync-health, drift, missing evidence, and freeze-policy risk.
- CORRECTION may monitor T13 for sync, secret, role, and freeze risks.
- PC_EXECUTOR may claim T9, confirm or refresh the required rollback note, give the user the dedicated local PowerShell command template, and collect only non-secret status from the user-run foreground PC node flow in `docs/G2_RUNBOOK.md`.
- VPS_EXECUTOR may not act yet; T10 waits for T9 evidence with a matching non-secret pairing request/node ID.
- VPS_EXECUTOR may perform only T10A read-only Gateway pending/online status check. T10 approval waits for ORCHESTRATOR to open it with a matching non-secret request/node ID.
## Forbidden Actions
- Do not start Gateway/node pairing or approval outside the T9/T10 sequence in `docs/G2_RUNBOOK.md`.
- Do not run any G2 command outside `docs/G2_RUNBOOK.md`.
- Do not run T10 until T9 produces a matching non-secret pairing request/node ID.
- Do not run T10 approval until T10A/T9 evidence provides a matching non-secret pairing request/node ID and ORCHESTRATOR opens T10.
- Do not record, print, commit, or chat-send `OPENCLAW_GATEWAY_TOKEN`; token may only be set by the user in a dedicated local PC PowerShell terminal during T9.
- PC_EXECUTOR must not receive the token, paste it into an Agent shell, or run the token-bearing foreground node flow directly.
- Do not install, start, restart, stop, or persist PC/VPS services.
@@ -52,7 +53,7 @@ Fresh second G2 authorization was reconfirmed for ORCHESTRATOR in `D:\openclaw-c
## Single Recommended Next Step
PC_EXECUTOR should claim T9, confirm or refresh `rollback/pc-g2-node-run-YYYYMMDD.md`, give the user the dedicated local PowerShell command template, and collect only non-secret status from the user-run foreground node flow in `docs/G2_RUNBOOK.md`.
VPS_EXECUTOR should claim `tasks/T10A-G2-VPS-pending-status-check.md` and perform only the read-only Gateway pending/online status check.
## User Decision Needed
@@ -77,14 +78,14 @@ No additional user decision is needed for T9 if PC_EXECUTOR stays within `docs/G
## Latest Health Snapshot
- Snapshot refreshed: 2026-05-19 16:31 UTC+8 from tracked control-plane files.
- PC sync heartbeat: clean at `2026-05-19T16:31:42+08:00`.
- VPS sync heartbeat: clean at `2026-05-19T16:31:06+0800`.
- Snapshot refreshed: 2026-05-21 16:53 UTC+8 from tracked control-plane files.
- PC sync heartbeat: clean at `2026-05-21T16:53:27+08:00`.
- VPS sync heartbeat: clean at `2026-05-21T16:52:34+0800`.
- Sync error files: none observed.
- G2 runbook: `docs/G2_RUNBOOK.md` complete.
- G2 authorization card: `docs/G2_AUTHORIZATION_CARD.md` prepared for user review.
- G2 authorization: fresh second authorization reconfirmed for foreground PC node run and corresponding VPS pairing approval only.
- Next work: T9 user-run foreground PC node flow guided by PC_EXECUTOR.
- Next work: T10A read-only VPS Gateway pending/online status check.
- Public website freeze: still active.
- Mutation/setup phase: limited G2 foreground pairing may start; service persistence and infrastructure changes remain forbidden.
@@ -93,7 +94,7 @@ No additional user decision is needed for T9 if PC_EXECUTOR stays within `docs/G
- Freeze time: 2026-05-19 14:46 UTC+8.
- Current phase: G2 limited foreground pairing is authorized under `docs/G2_RUNBOOK.md`.
- Completed: G0A, G0B, G1, G2 runbook, role-misdirection recovery, and second G2 authorization.
- Blocked: T10/VPS approval until T9 produces one matching non-secret pairing request/node ID. G3 and G4 remain closed.
- Blocked: T10/VPS approval until T10A finds one matching non-secret pairing request/node ID, or proves the intended PC node is already online/approved. G3 and G4 remain closed.
- Safety constraints: no secret recording, no `openclaw node install/start`, no service persistence, no Nginx/Docker/website/firewall/network changes.
- Next owner: PC_EXECUTOR for T9, with CORRECTION monitoring T13.
- Single next action: PC_EXECUTOR claims T9, confirms or refreshes `rollback/pc-g2-node-run-YYYYMMDD.md`, gives the user the dedicated local PowerShell command template, then records only non-secret status from the user-run foreground node flow in `docs/G2_RUNBOOK.md`.
- Next owner: VPS_EXECUTOR for T10A, with CORRECTION monitoring sync/secret/freeze guardrails.
- Single next action: VPS_EXECUTOR claims `tasks/T10A-G2-VPS-pending-status-check.md` and performs only the read-only Gateway pending/online status check.

View File

@@ -6,7 +6,7 @@ Own requirements alignment, task decomposition, dependency tracking, and final a
## Current Objective
Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: T13 has recorded a fresh PASS, T9 uses a user-run local PowerShell token/node model, and T10 remains blocked until T9 evidence provides one matching non-secret request/node ID.
Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`: T9 is done with non-secret PC connection evidence, T10A read-only Gateway status check is ready, and T10 approval remains blocked until a matching non-secret request/node ID exists or Gateway state proves approval is unnecessary.
## Must Read
@@ -29,7 +29,7 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`:
- `USER_STATUS.md` is the user-facing status entry; internal agent ledgers should not be required reading for the user.
- Fresh second G2 authorization was received and reconfirmed for ORCHESTRATOR in `D:\openclaw-control-plane` on 2026-05-19.
- `docs/G2_RUNBOOK.md` has been prepared as the G2 execution-before-action runbook. It does not authorize execution by itself.
- Sync-health is currently cleared for T9: latest tracked PC and VPS heartbeats are clean and within the 5-minute threshold, and no `sync-state/error-*.md` files are observed in the latest control-plane snapshot.
- Sync-health is currently healthy in the latest tracked snapshot: PC and VPS heartbeats are clean and no `sync-state/error-*.md` files are observed.
- T2.1 and T8 are now treated as complete control-plane setup work; G2 is In Progress under the limited runbook scope.
- The polling sync is intentionally temporary; design an async notification/coordinator layer when PC/VPS baseline work is stable.
- Filing-review freeze path wording has been corrected from the obsolete single `docker-composite.yml` reference to `/opt/services/docker-compose.openclaw.yml` plus any equivalent compose/service entries that could affect public website output.
@@ -38,9 +38,9 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`:
1. Keep `USER_STATUS.md` current when gate, blocker, heartbeat, or required user decision changes.
2. Keep T7/CORRECTION monitoring active for sync-health, drift, missing evidence, and freeze-policy risk.
3. Keep CORRECTION monitoring T13 for sync/secret/freeze guardrails during T9.
4. Let PC_EXECUTOR claim T9, confirm or refresh `rollback/pc-g2-node-run-YYYYMMDD.md`, give the user the dedicated local PowerShell command template, and collect only non-secret status from the user-run foreground node flow in `docs/G2_RUNBOOK.md`.
5. Keep T10 blocked until T9 evidence includes a matching non-secret pairing request ID or pending node ID.
3. Keep CORRECTION monitoring sync/secret/freeze guardrails during T10A/T10.
4. Let VPS_EXECUTOR claim T10A and perform only read-only Gateway pending/online status checks for `desktop-vuor0gs`.
5. Keep T10 blocked until T10A evidence includes a matching non-secret pairing request ID or pending node ID, or proves the intended PC node is already online/approved.
6. Continue forbidding service persistence, `openclaw node install/start`, Nginx/Docker/website changes, firewall/network changes, G3 smoke test, G4 setup, and recording any token or secret.
## Open Questions
@@ -50,6 +50,18 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`:
## Last Update
2026-05-21 16:53 UTC+8: ORCHESTRATOR reviewed T9 done evidence and kept T10 blocked, without executing VPS approval.
- `git pull` returned already up to date.
- T9 is done: `tasks/T9-G2-PC-node-run.md` and `evidence/pc-g2-node-run-20260521.md` report user-run foreground node flow completed.
- PC evidence contains only non-secret information. User reported connection to `openclaw.smartmotor.cloud`.
- No pairing request ID or pending node ID was provided in T9 evidence.
- Current tracked sync heartbeats are clean: PC `2026-05-21T16:53:27+08:00`, VPS `2026-05-21T16:52:34+0800`; no tracked `sync-state/error-*.md` files were observed.
- Decision: evidence is not sufficient to skip T10 because Gateway-side pending/online/approved state is not yet proven. T10 remains blocked.
- Opened `tasks/T10A-G2-VPS-pending-status-check.md` for VPS_EXECUTOR to collect read-only non-secret Gateway pending/online status for `desktop-vuor0gs`.
- If T10A finds a matching non-secret pending request/node ID, ORCHESTRATOR can open T10 for that specific approval. If T10A proves the intended PC node is already online/approved and no approval is required, ORCHESTRATOR can skip T10 and route to G2 verification.
- ORCHESTRATOR did not execute VPS commands, did not approve, did not handle a token, did not change services, and did not modify Gateway/Nginx/Docker state.
2026-05-19 17:05 UTC+8: ORCHESTRATOR corrected the T9 token execution model, without executing G2.
- Repeated T9 `blocked` states were caused by an invalid assumption that the Agent shell could safely receive `OPENCLAW_GATEWAY_TOKEN` from a separate user PowerShell session.
@@ -150,8 +162,9 @@ Coordinate freshly authorized G2 execution strictly under `docs/G2_RUNBOOK.md`:
## G2 Planning State
- T9: PC foreground node run, ready after fresh T13 PASS with healthy sync; user performs token setup and foreground node run in a dedicated local PC PowerShell terminal, while PC_EXECUTOR records only non-secret status.
- T10: VPS pairing approval, blocked until T9 evidence.
- T9: PC foreground node run, done with non-secret evidence and no pairing request/node ID.
- T10A: VPS Gateway pending status read-only check, ready.
- T10: VPS pairing approval, blocked until T10A finds one matching non-secret request/node ID or proves approval is unnecessary.
- T11: PC G2 verification, draft.
- T12: VPS G2 verification and freeze compliance, draft.
- T13: G2 correction guard, ready.