openclaw/qa
Peter Steinberger 2fffd4e8ba
feat(sessions): enable cross-agent session access by default (#136755)
* feat(sessions): enable cross-agent session access by default

`tools.sessions.visibility` now defaults to `all` and
`tools.agentToAgent.enabled` to `true`; both widen access.
Narrow access via `tools.sessions.visibility` (agent|tree|self),
`tools.agentToAgent.allow`, or `enabled: false`.

Document that an omitted/empty allow list permits every agent pair.
Denial copy for narrowed visibility no longer instructs enabling the
already-on policy. Regenerate prompt-snapshot fixtures for the visibility
hedge. Maintainer-directed.

* feat(security): audit default cross-agent session access

Add `security.trust_model.cross_agent_session_access_default`: `info`
for plain multi-agent defaults, `warn` with sandbox/tool-restriction/
multi-user ingress signals. No new config keys.

* test(gateway): drain detached a2a flow between agentId send rows

The announce/ping-pong flow outlives the sessions_send tool request; the second agentId row picked up the first row's follow-up agent call for agent:orion:main, so each row now waits for gateway active work to drain before releasing its test state.

* test(security): mock the cross-agent access collector in the non-deep facade

The readonly-setup-fallback test mocks audit.nondeep.runtime with an explicit factory; it now exports collectCrossAgentSessionAccessFindings so the registered collector resolves under the mock (CI run 33699015755, checks-node-compact-large-21).

* fix(security): scope the cross-agent audit to unsandboxed sessions

The audit finding now names which agents can reach other agents
(unsandboxed sessions, or any session when
agents.defaults.sandbox.sessionToolsVisibility is "all"), emits nothing
when every agent is fully sandboxed under the default clamp, and says
sandboxed transcripts stay readable by unsandboxed callers.

Docs qualify the agent-to-agent reference with the requester-owned
native/ACP child exception and correct the security overview's sandbox
wording. Addresses both ClawSweeper rank-up moves on #136755.

* docs(security): qualify the fully sandboxed audit exemption

State in the CLI reference and high-level security audit summary that
fully sandboxed rosters under the default spawn-tree clamp produce no
cross-agent access finding. Disabling that clamp removes the exemption.

Addresses the mechanical ClawSweeper rank-up on #136755 at 3208e19534e.

* fix(security): report per-agent session tool reach in the cross-agent audit

The finding now lists which agents can reach other agents (unclamped sessions that still have a session tool allowed) with their calling context and allowed tools, lists non-reaching agents with the reason, and emits nothing when nobody reaches; help text no longer claims enabled=false isolates agents because requester-owned native/ACP child sessions stay reachable under tree or all visibility; gateway final-effect proof that a disabled policy or restrictive allow list never dispatches to the target. Addresses the ClawSweeper re-review on #136755.

* test(gateway): drain detached a2a flow in an afterEach hook

The in-row drain shared the row's 10s budget and could time out under load, leaking the next row's mock calls; the hook has its own bounded timeout.

* docs: stop describing disabled agent-to-agent access as isolation

enabled: false blocks ordinary cross-agent access, but requester-owned native subagent and ACP child sessions stay reachable under tree or all visibility; every introduced claim now says so and points strict separation to tools.sessions.visibility or separate gateways. Addresses the ClawSweeper P2 on #136755.

* test(qa-lab): prove default cross-agent send and policy denials end to end

Three mock-openai flow scenarios run a two-agent QA Gateway: default config dispatches sessions_send to agent:orion:main (accepted, target run observed, target main session created); enabled=false and a restrictive allow list return forbidden before any target work. Addresses the ClawSweeper P1 merge risk on #136755.

* fix(config): stop listing tree visibility as strict separation

Strict separation is agent or self; tree still admits requester-owned native subagent and ACP child sessions across agents. Addresses a ClawSweeper rank-up move on #136755.
2026-09-02 22:39:03 -07:00
..
convex-credential-broker chore(deps): refresh seven-day eligible packages (#135177) 2026-09-02 18:43:03 -07:00
scenarios feat(sessions): enable cross-agent session access by default (#136755) 2026-09-02 22:39:03 -07:00
frontier-harness-plan.md chore: migrate active GPT-5.5 references to GPT-5.6 (#104452) 2026-07-11 06:30:57 -07:00
maturity-scores.yaml refactor(canvas): make the panel a widget presenter (#126030) 2026-08-19 08:21:07 -07:00
README.md Convert QA scenarios to YAML files (#92915) 2026-06-14 17:31:18 -07:00
scenarios.md Convert QA scenarios to YAML files (#92915) 2026-06-14 17:31:18 -07:00

QA Scenarios

Seed QA assets for the private qa-lab extension.

Files:

  • scenarios/index.yaml - canonical QA scenario pack, kickoff mission, and operator identity.
  • scenarios/<theme>/*.yaml - one runnable scenario per YAML file.
  • frontier-harness-plan.md - big-model bakeoff and tuning loop for harness work.
  • convex-credential-broker/ - standalone Convex v1 lease broker for pooled live credentials.

Key workflow:

  • qa suite is the executable frontier subset / regression loop.
  • qa manual is the scoped personality and style probe after the executable subset is green.
  • qa coverage prints the scenario coverage inventory from scenario YAML.

Operator workflows:

  • Use the openclaw-qa-testing skill for QA Lab live lanes, Convex credential pool operations, and WhatsApp live credential setup/replacement.

Keep this folder in git. Add new scenarios here before wiring them into automation.