2.1 KiB
2.1 KiB
G2 Authorization Card
Confirmation
- Current target window: ORCHESTRATOR.
- Current workspace:
D:\openclaw-control-plane. - G2 current state: paused/pending.
- Old G2 authorization: not valid after the role-misdirection correction.
- Sync-health: healthy by tracked files.
- PC heartbeat:
cleanat2026-05-19T12:35:06+08:00. - VPS heartbeat:
cleanat2026-05-19T12:34:45+0800. - Sync error files: none observed.
What This Card Does
This card gives the user one exact second authorization statement to copy when ready.
It does not execute G2 by itself. It does not authorize any agent to proceed unless the statement is sent by the user to the ORCHESTRATOR window after reviewing this card.
Copyable Second Authorization Statement
目标窗口:ORCHESTRATOR
当前工作区:D:\openclaw-control-plane
我确认这是 role-misdirection 修正后的第二段 G2 授权。
授权范围:仅 G2。
允许动作:按 docs/G2_RUNBOOK.md 打开 T9/T10;允许 PC_EXECUTOR 执行前台 PC node run;允许 VPS_EXECUTOR 在 T9 产生匹配的非 secret pairing request/node ID 后执行对应 VPS pairing approval。
禁止动作:不得执行 openclaw node install/start/persistence;不得进行服务重启;不得修改 Nginx/Docker/网站/防火墙/网络;不得记录、打印、提交、写入或聊天发送任何 secret、token、password、API key、private key、cookie 或 OPENCLAW_GATEWAY_TOKEN。
授权失效条件:sync blocked;目标角色不匹配;当前工作区不匹配;出现或可能记录 secret;出现多个或不明确的 pairing request;任何步骤偏离 docs/G2_RUNBOOK.md;任何动作可能影响 smartmotor.cloud 备案冻结网站输出。
ORCHESTRATOR Handling Rules After Copy
If the user sends the authorization statement above:
- Confirm target role and workspace again before changing task status.
- Move only the eligible G2 guard/task statuses needed to begin the runbook.
- Keep service persistence, G3 smoke test, and G4 service installation closed.
- Require rollback notes before token use, foreground node run, and approval actions.
- Stop immediately if any invalidation condition appears.