跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

Policy findings, repair, and exit codes

Every policy check id, what doctor --fix will and will not repair, and command exit codes

Interpreting a policy finding, repairing it, and the exit codes. Part of the openclaw policy reference.

Findings

Check idFinding
policy/policy-jsonc-missingPolicy is enabled but policy.jsonc is missing.
policy/policy-jsonc-invalidPolicy cannot be parsed or contains malformed rule entries.
policy/policy-hash-mismatchPolicy does not match configured expectedHash.
policy/attestation-hash-mismatchCurrent policy evidence no longer matches the accepted attestation.
policy/policy-conformance-invalidA baseline or checked policy file has invalid comparison syntax.
policy/policy-conformance-missingA checked policy file is missing a rule required by the baseline policy file.
policy/policy-conformance-weakerA checked policy file has a weaker value than the baseline policy file.
policy/channels-denied-providerAn enabled channel matches a channel deny rule.
policy/mcp-denied-serverA configured MCP server is denied by policy.
policy/mcp-unapproved-serverA configured MCP server is outside the allowlist.
policy/models-denied-providerA configured model provider or model ref uses a denied provider.
policy/models-unapproved-providerA configured model provider or model ref is outside the allowlist.
policy/network-private-access-enabledA private-network SSRF escape hatch is enabled when policy denies it.
policy/routing-bindings-requiredPolicy requires a channel route binding, but none is configured.
policy/routing-binding-channel-unconfiguredA route binding names a channel absent from channels.*.
policy/routing-agent-mismatchAn authored route resolves to a different agent.
policy/routing-match-kind-mismatchAn authored route matches at an unexpected binding specificity.
policy/ingress-dm-policy-unapprovedA channel DM policy is outside the policy allowlist.
policy/ingress-dm-scope-unapprovedsession.dmScope does not match the policy-required DM isolation scope.
policy/ingress-open-groups-deniedA channel group policy is open while policy denies open group ingress.
policy/ingress-group-mention-requiredA channel or group entry disables mention gates while policy requires them.
policy/gateway-non-loopback-bindGateway bind posture permits non-loopback exposure when policy denies it.
policy/gateway-auth-disabledGateway authentication is disabled when policy requires auth.
policy/gateway-rate-limit-missingGateway auth rate-limit posture is not explicit when policy requires it.
policy/gateway-control-ui-insecureGateway Control UI insecure exposure toggles are enabled.
policy/gateway-tailscale-funnelGateway Tailscale Funnel exposure is enabled when policy denies it.
policy/gateway-remote-enabledGateway remote mode is active when policy denies it.
policy/gateway-http-endpoint-enabledA Gateway HTTP API endpoint is enabled while denied by policy.
policy/gateway-http-url-fetch-unrestrictedGateway HTTP URL-fetch input lacks a required URL allowlist.
policy/gateway-node-command-deniedA node command denied by policy is not denied by OpenClaw config.
policy/agents-workspace-access-deniedAgent sandbox mode or workspace access is outside the policy allowlist.
policy/agents-tool-not-deniedAn agent or default config does not deny a tool required by policy.
policy/tools-profile-unapprovedA configured global or per-agent tool profile is outside the allowlist.
policy/tools-fs-workspace-only-requiredFilesystem tools are not configured with workspace-only path posture.
policy/tools-exec-security-unapprovedExec security mode is outside the policy allowlist.
policy/tools-exec-ask-unapprovedExec ask mode is outside the policy allowlist.
policy/tools-exec-host-unapprovedExec host routing is outside the policy allowlist.
policy/tools-elevated-enabledElevated tool mode is enabled when policy denies it.
policy/tools-also-allow-missingA configured alsoAllow list is missing an entry required by policy.
policy/tools-also-allow-unexpectedA configured alsoAllow list includes an entry not expected by policy.
policy/tools-required-deny-missingA global or per-agent tool deny list does not include a required denied tool.
policy/sandbox-mode-unapprovedSandbox mode is outside the policy allowlist.
policy/sandbox-backend-unapprovedSandbox backend is outside the policy allowlist.
policy/sandbox-container-posture-unobservableA container posture rule is enabled for a backend that cannot observe it.
policy/sandbox-container-host-network-deniedA container-backed sandbox or browser uses host network mode.
policy/sandbox-container-namespace-join-deniedA container-backed sandbox or browser joins another container namespace.
policy/sandbox-container-mount-mode-requiredA container-backed sandbox or browser mount is not read-only.
policy/sandbox-container-runtime-socket-mountA container-backed sandbox or browser mount exposes the container runtime socket.
policy/sandbox-container-unconfined-profileContainer sandbox profile is unconfined when policy denies it.
policy/sandbox-browser-cdp-source-range-missingSandbox browser CDP source range is missing when policy requires one.
policy/data-handling-telemetry-content-captureTelemetry content capture is enabled when policy denies it.
policy/data-handling-session-retention-not-enforcedSession retention maintenance is not enforced when policy requires it.
policy/data-handling-session-transcript-memory-enabledSession transcript memory indexing is enabled when policy denies it.
policy/secrets-unmanaged-providerA config SecretRef references a provider not declared under secrets.providers.
policy/secrets-denied-provider-sourceA config secret provider or SecretRef uses a source denied by policy.
policy/secrets-insecure-providerA secret provider opts into insecure posture when policy denies it.
policy/auth-profile-invalid-metadataA config auth profile is missing valid provider or mode metadata.
policy/auth-profile-unapproved-modeA config auth profile mode is outside the policy allowlist.
policy/exec-approvals-missingPolicy requires the SQLite exec approvals document, but its row is missing.
policy/exec-approvals-invalidThe configured SQLite exec approvals document cannot be parsed.
policy/exec-approvals-default-security-unapprovedExec approval defaults use a security mode outside the policy allowlist.
policy/exec-approvals-agent-security-unapprovedA per-agent effective exec approval security mode is outside the allowlist.
policy/exec-approvals-auto-allow-skills-enabledAn exec approval agent implicitly auto-allows skill CLIs when policy denies it.
policy/exec-approvals-allowlist-missingThe approvals allowlist is missing a pattern required by policy.
policy/exec-approvals-allowlist-unexpectedThe approvals allowlist includes a pattern not expected by policy.
policy/tools-missing-risk-levelA governed tool declaration is missing risk metadata.
policy/tools-unknown-risk-levelA governed tool declaration uses an unknown risk value.
policy/tools-missing-sensitivity-tokenA governed tool declaration is missing sensitivity metadata.
policy/tools-missing-ownerA governed tool declaration is missing owner metadata.
policy/tools-unknown-sensitivity-tokenA governed tool declaration uses an unknown sensitivity value.

A finding can include both target (the observed workspace thing that does not conform) and requirement (the authored rule that made it a finding). Both are oc:// address strings, but the field names describe policy role rather than address format.

Example findings:

{
  "checkId": "policy/channels-denied-provider",
  "severity": "error",
  "message": "Channel 'telegram' uses denied provider 'telegram'.",
  "source": "policy",
  "path": "openclaw config",
  "ocPath": "oc://openclaw.config/channels/telegram",
  "target": "oc://openclaw.config/channels/telegram",
  "requirement": "oc://policy.jsonc/channels/denyRules/#0",
  "fixHint": "Telegram is not approved for this workspace."
}
{
  "checkId": "policy/tools-missing-risk-level",
  "severity": "error",
  "message": "AGENTS.md tool 'deploy' has no explicit risk classification.",
  "source": "policy",
  "path": "AGENTS.md",
  "line": 12,
  "ocPath": "oc://AGENTS.md/tools/deploy",
  "target": "oc://AGENTS.md/tools/deploy",
  "requirement": "oc://policy.jsonc/tools/requireMetadata"
}
{
  "checkId": "policy/mcp-unapproved-server",
  "severity": "error",
  "message": "MCP server 'remote' is not in the policy allowlist.",
  "source": "policy",
  "path": "openclaw config",
  "ocPath": "oc://openclaw.config/mcp/servers/remote",
  "target": "oc://openclaw.config/mcp/servers/remote",
  "requirement": "oc://policy.jsonc/mcp/servers/allow"
}
{
  "checkId": "policy/models-unapproved-provider",
  "severity": "error",
  "message": "Model ref 'anthropic/claude-sonnet-4.7' uses unapproved provider 'anthropic'.",
  "source": "policy",
  "path": "openclaw config",
  "ocPath": "oc://openclaw.config/agents/defaults/model/fallbacks/#0",
  "target": "oc://openclaw.config/agents/defaults/model/fallbacks/#0",
  "requirement": "oc://policy.jsonc/models/providers/allow"
}
{
  "checkId": "policy/network-private-access-enabled",
  "severity": "error",
  "message": "Network setting 'browser-private-network' allows private-network access.",
  "source": "policy",
  "path": "openclaw config",
  "ocPath": "oc://openclaw.config/browser/ssrfPolicy/dangerouslyAllowPrivateNetwork",
  "target": "oc://openclaw.config/browser/ssrfPolicy/dangerouslyAllowPrivateNetwork",
  "requirement": "oc://policy.jsonc/network/privateNetwork/allow"
}
{
  "checkId": "policy/gateway-non-loopback-bind",
  "severity": "error",
  "message": "Gateway bind setting 'gateway-bind' permits non-loopback exposure.",
  "source": "policy",
  "path": "openclaw config",
  "ocPath": "oc://openclaw.config/gateway/bind",
  "target": "oc://openclaw.config/gateway/bind",
  "requirement": "oc://policy.jsonc/gateway/exposure/allowNonLoopbackBind"
}
{
  "checkId": "policy/gateway-node-command-denied",
  "severity": "error",
  "message": "Gateway node command 'system.run' is denied by policy but not denied by OpenClaw config.",
  "source": "policy",
  "path": "openclaw config",
  "ocPath": "oc://openclaw.config/gateway/nodes/commands/deny",
  "target": "oc://openclaw.config/gateway/nodes/commands/deny",
  "requirement": "oc://policy.jsonc/gateway/nodes/denyCommands",
  "fixHint": "Add 'system.run' to gateway.nodes.commands.deny or update policy after review."
}
{
  "checkId": "policy/agents-workspace-access-denied",
  "severity": "error",
  "message": "agents.defaults sandbox workspaceAccess 'rw' is not allowed by policy.",
  "source": "policy",
  "path": "openclaw config",
  "ocPath": "oc://openclaw.config/agents/defaults/sandbox/workspaceAccess",
  "target": "oc://openclaw.config/agents/defaults/sandbox/workspaceAccess",
  "requirement": "oc://policy.jsonc/agents/workspace/allowedAccess"
}

Repair

doctor --lint and policy check are read-only.

doctor --fix only edits policy-managed workspace settings when workspaceRepairs is explicitly enabled; otherwise checks report what they would repair and leave settings unchanged.

Repair can disable channels denied by channels.denyRules and apply the automatic narrowing repairs listed below. Enable workspaceRepairs only after the policy file has been reviewed, because a valid rule can change workspace config:

  • set tools.elevated.enabled=false when a global policy forbids elevated tools
  • add missing required-deny tool ids to tools.deny or agents.entries.*.tools.deny when policy requires those tools to be denied
  • set insecure gateway.controlUi.* toggles to false
  • set gateway.mode=local when policy denies remote gateway mode
  • set reported gateway.http.endpoints.*.enabled paths to false when policy denies Gateway HTTP API endpoints
  • set reported channel ingress groupPolicy paths to allowlist when policy denies open group ingress
  • set reported channel ingress requireMention paths to true when policy requires group mentions
  • set diagnostics.otel.captureContent=false, or diagnostics.otel.captureContent.enabled=false for object-form telemetry capture settings, when policy denies telemetry content capture

Scoped elevated-tools repairs are detect-only. Scoped data-handling repairs are also skipped when the finding reports shared telemetry config, because changing the shared setting would affect more than the scoped policy target.

dataHandling.sensitiveLogging.requireRedaction has no check and no repair. Sensitive log redaction is unconditional in OpenClaw, so nothing can report it as disabled. The key stays a supported policy rule: openclaw policy validates its shape, openclaw policy compare still requires a candidate policy to be at least as strict as the baseline for it, and openclaw policy check records the runtime invariant oc://openclaw.invariant/logging/redaction in the dataHandling evidence and attestation as proof the requirement is satisfied.

Scoped required-deny repairs are skipped when the finding reports inherited root tools.deny, because adding the required tool to root config would affect more than the scoped policy target. Agent-local required-deny repairs can update the reported agents.entries.*.tools.deny path.

Scoped channel ingress repairs are skipped when the finding reports inherited channels.defaults.*, because changing the shared channel default would affect more than the scoped policy target. Gateway HTTP URL-fetch allowlist findings remain manual because automatic repair cannot choose the correct endpoint URL allowlist values.

Gateway bind and node-command findings stay review-required. When policy/gateway-non-loopback-bind or policy/gateway-node-command-denied can be mapped to a config path, doctor --fix reports the proposed gateway.bind or gateway.nodes.commands.deny change as skipped preview guidance. It does not apply the change, and the finding does not count as repaired until an operator reviews and updates config or policy.

{
  "plugins": {
    "entries": {
      "policy": {
        "config": {
          "workspaceRepairs": true,
        },
      },
    },
  },
}

Exit codes

Command012
policy checkNo findings at the threshold.One or more findings met the threshold.Argument or runtime failure.
policy compareThe policy file is at least as strict as the baseline.The policy file is invalid, missing, or weaker than baseline rules.Argument or runtime failure.
policy watchNo findings and accepted hash is current.Findings exist or accepted attestation is stale.Argument or runtime failure.