Files
openclaw-control-plane/USER_STATUS.md
2026-05-19 17:06:57 +08:00

100 lines
7.5 KiB
Markdown

# OpenClaw User Status
> This is the user-facing status page. Agent board, task files, handoffs, evidence, and sync-state files are internal agent ledgers.
## Current Stage
Stage 2A Authorized: foreground G2 may start under runbook.
Fresh second G2 authorization was reconfirmed for ORCHESTRATOR in `D:\openclaw-control-plane`. CORRECTION recorded a fresh T13 PASS, so T9 may proceed under `docs/G2_RUNBOOK.md` using a user-run local PowerShell token/node flow; T10 must wait until T9 produces a matching non-secret pairing request ID or pending node ID.
## Completed
- Collaboration mechanism was confirmed: agent roles, Git polling MVP, sync-health monitoring, and this user-facing status page.
- OpenClaw target design was confirmed: QQ and phone Control UI are control entries, VPS Gateway is the always-on hub, DeepSeek handles white-listed autonomous decisions, and Windows PC is the main execution node.
- G2 runbook and draft role tasks were prepared for review.
- `docs/G2_RUNBOOK.md` was completed as the G2 pre-execution plan.
- G2 runbook remains the binding procedure for this limited foreground pairing stage.
- Fresh second G2 authorization was recorded and later reconfirmed for ORCHESTRATOR after role-misdirection correction.
- The `smartmotor.cloud` filing-review website freeze is active as a hard rule.
- PC baseline was collected and independently accepted.
- VPS baseline was collected and independently accepted.
- Sync-health recovered and is currently healthy under CORRECTION monitoring.
- Current communication remains Git polling; future work should upgrade to async notification or a coordinator after the basic path is stable.
## Current Blockers
- No active sync-health blocker is recorded.
- VPS pairing approval is blocked until T9 produces a matching non-secret pairing request ID or pending node ID.
- G3 smoke test and G4 persistence remain closed.
## Allowed Actions
- Keep the sync scripts running.
- Agents may update user-facing status, handoffs, evidence, and internal ledgers.
- Agents may continue read-only monitoring for sync-health, drift, missing evidence, and freeze-policy risk.
- CORRECTION may monitor T13 for sync, secret, role, and freeze risks.
- PC_EXECUTOR may claim T9, confirm or refresh the required rollback note, give the user the dedicated local PowerShell command template, and collect only non-secret status from the user-run foreground PC node flow in `docs/G2_RUNBOOK.md`.
- VPS_EXECUTOR may not act yet; T10 waits for T9 evidence with a matching non-secret pairing request/node ID.
## Forbidden Actions
- Do not start Gateway/node pairing or approval outside the T9/T10 sequence in `docs/G2_RUNBOOK.md`.
- Do not run any G2 command outside `docs/G2_RUNBOOK.md`.
- Do not run T10 until T9 produces a matching non-secret pairing request/node ID.
- Do not record, print, commit, or chat-send `OPENCLAW_GATEWAY_TOKEN`; token may only be set by the user in a dedicated local PC PowerShell terminal during T9.
- PC_EXECUTOR must not receive the token, paste it into an Agent shell, or run the token-bearing foreground node flow directly.
- Do not install, start, restart, stop, or persist PC/VPS services.
- Do not run `openclaw node install`, `openclaw node start`, or any service persistence command.
- Do not change firewall, routing, Nginx, Docker compose, bind mounts, container images, environment variables, or service state.
- Do not change the `smartmotor.cloud` homepage, linked content, static assets, routing, or anything that could alter public website output during filing review.
- Do not write secrets, tokens, passwords, API keys, private keys, cookies, or `OPENCLAW_GATEWAY_TOKEN` into files, logs, evidence, commits, or chat.
## Single Recommended Next Step
PC_EXECUTOR should claim T9, confirm or refresh `rollback/pc-g2-node-run-YYYYMMDD.md`, give the user the dedicated local PowerShell command template, and collect only non-secret status from the user-run foreground node flow in `docs/G2_RUNBOOK.md`.
## User Decision Needed
No additional user decision is needed for T9 if PC_EXECUTOR stays within `docs/G2_RUNBOOK.md`. A new decision is required for G3 smoke test, G4 persistence, service changes, network/firewall changes, Nginx/Docker/website changes, or any action outside the runbook.
## Confirmed Target Design
- QQ is included in the current stage as a primary natural-language entry.
- Phone Control UI must be able to start basic tasks, show status/results, and approve high-risk actions.
- VPS OpenClaw Gateway is the always-on hub for device connection, routing, approval flow, state aggregation, and audit.
- DeepSeek may understand, split, and autonomously trigger white-listed actions. High-risk or non-white-listed actions require human approval.
- Windows PC is the main execution node and may perform broad user-level local execution.
- PC system-level changes, service installation, network/firewall changes, and large destructive file operations require human approval and rollback notes.
- Tailscale is optional for administration, troubleshooting, or private-path enhancement. It is not a G2 prerequisite; the main path uses the VPS Gateway.
- Future multiple PCs, phones, and endpoint model nodes should join through the same Gateway model.
## Frozen Acceptance Criteria
- G2 connection setup is accepted only when the PC node can connect to the VPS Gateway, the VPS can show pending/approved node state, approval does not leak secrets, and the frozen `smartmotor.cloud` website output remains unchanged.
- G3 smoke test is accepted only when a harmless task starts from QQ or phone Control UI, routes through the Gateway to the Windows PC, returns visible results, and verifier evidence proves execution came from the PC rather than the VPS.
- G4 persistence is accepted only when the PC node can run as a persistent service or startup item, service install/start/status and reboot survival evidence exist, rollback notes exist for system-level changes, and approval guardrails still work.
## Latest Health Snapshot
- Snapshot refreshed: 2026-05-19 16:31 UTC+8 from tracked control-plane files.
- PC sync heartbeat: clean at `2026-05-19T16:31:42+08:00`.
- VPS sync heartbeat: clean at `2026-05-19T16:31:06+0800`.
- Sync error files: none observed.
- G2 runbook: `docs/G2_RUNBOOK.md` complete.
- G2 authorization card: `docs/G2_AUTHORIZATION_CARD.md` prepared for user review.
- G2 authorization: fresh second authorization reconfirmed for foreground PC node run and corresponding VPS pairing approval only.
- Next work: T9 user-run foreground PC node flow guided by PC_EXECUTOR.
- Public website freeze: still active.
- Mutation/setup phase: limited G2 foreground pairing may start; service persistence and infrastructure changes remain forbidden.
## Session Freeze
- Freeze time: 2026-05-19 14:46 UTC+8.
- Current phase: G2 limited foreground pairing is authorized under `docs/G2_RUNBOOK.md`.
- Completed: G0A, G0B, G1, G2 runbook, role-misdirection recovery, and second G2 authorization.
- Blocked: T10/VPS approval until T9 produces one matching non-secret pairing request/node ID. G3 and G4 remain closed.
- Safety constraints: no secret recording, no `openclaw node install/start`, no service persistence, no Nginx/Docker/website/firewall/network changes.
- Next owner: PC_EXECUTOR for T9, with CORRECTION monitoring T13.
- Single next action: PC_EXECUTOR claims T9, confirms or refreshes `rollback/pc-g2-node-run-YYYYMMDD.md`, gives the user the dedicated local PowerShell command template, then records only non-secret status from the user-run foreground node flow in `docs/G2_RUNBOOK.md`.