Qualify the accepted Windows OpenShell MXC profile
- Dominant language
- TypeScript
- Stars
- 22.5k
- Forks
- 3.1k
- Avg merge
- 1d 1h
- Merged PRs (30d)
- 715
Description
Part of #8178.
This task qualifies the dormant native Windows/OpenShell MXC candidate. It does not establish support or production activation.
## Outcome
The checked-in Windows harness repeatedly validates the exact accepted Windows, NemoClaw, OpenShell, MXC/`wxc-exec.exe`, Node.js, and OpenClaw identities through the merged inactive onboarding composition.
## Delivery state
Accepted-package physical qualification.
## Dependencies
- Blocked by #10584.
- Requires an accepted host and privilege contract.
- Unblocks opt-in qualification onboarding, policy and inference work, and lifecycle completion.
## Deliverables
- Connect the checked-in Windows target to the trusted executor and inactive onboarding composition.
- Pin every component and configuration identity in the run manifest.
- Run repeated create, readiness, filesystem allow and deny, authenticated forwarding, exact mock-backed `CHAT_OK`, recovery, deletion, process termination, registry removal, forward shutdown, artifact cleanup, and recreation checks.
- Preserve a sanitized evidence bundle tied to exact commits and package identities.
## Acceptance evidence
- Allowed: at least two consecutive clean cycles pass with exact identity and no stale state.
- Denied: substituted binaries, unsupported host facts, policy mismatch, unauthorized forwarding, and stale sandbox identity fail closed.
- Ambiguous: create, readiness, or cleanup uncertainty triggers reconciliation and produces an inconclusive result rather than a pass.
- Failure or recovery: injected interruption proves exact recovery or reports the authority-bound retained resource.
## Security and authority boundaries
- Evidence must not contain credentials, tokens, private keys, or sensitive host data.
- Authenticated forwarding must be sandbox-scoped and removed with the sandbox.
- The shallow state path may remain a declared MXC-02 workload workaround but must not be represented as a general filesystem fix.
## Test plan
- Run the checked-in physical Windows target against the accepted pinned profile.
- Preserve deterministic E2E-support tests for manifest validation, redaction, retry policy, and evidence completeness.
- Record every attempt rather than hiding a failed cycle with an unbounded rerun.
## Deferred scope
- Public installer, normal runtime selection, production credentials, and activation.
## Stop conditions
- Stop if any identity cannot be resolved to an accepted source.
- Stop if the run needs untracked host changes, insecure credential handling, or a policy exception not accepted by #8178.
## Completion evidence
- Link the qualification PR if code changes are required, exact NemoClaw commit, host profile, package manifest, run attempts, and sanitized evidence bundle. One same-repository PR should own any repository change.
Contributor guide
Assessment
This issue has not been assessed yet.