沙盒、工具策略、以及提升
工具被阻止的原因:沙盒运行时、工具允许/拒绝策略和提升执行门控
OpenClaw has three related (but different) controls:
1. ''Sandbox'' (''agents.defaults.sandbox.*'' / ''agents.list[].sandbox.*'') decides ''where tools run'' (Docker vs host).
2. ''Tool policy'' (''tools.*'', ''tools.sandbox.tools.*'', ''agents.list[].tools.*'') decides ''which tools are available/allowed''.
3. ''Elevated'' (''tools.elevated.*'', ''agents.list[].tools.elevated.*'') is an ''exec-only escape hatch'' to run on the host when sandboxed.
Quick debug
使用检查器查看 OpenClaw 实际在做什么:
openclaw sandbox explain openclaw sandbox explain --session agent:main:main openclaw sandbox explain --agent work openclaw sandbox explain --json
以下但输出被:
- effective sandbox mode/scope/workspace access
- whether the session is currently sandboxed (main vs non-main)
- effective sandbox tool allow/deny (and whether it came from agent/global/default)
- elevated gates and fix-it key paths
Sandbox: where tools run
沙盒化是 ''agents.defaults.sandbox.mode'' 在控制被:
- ''"off"'':全部但主机在被执行。
- ''"non-main"'':非主要会话仅但沙盒化被(群组/渠道在的一般的那"驚机")。
- ''"all"'':全部但沙盒化被。
See Sandboxing for the full matrix (scope, workspace mounts, images).
#
Bind mounts (security quick check)
- ''docker.binds'' pierces the sandbox filesystem: whatever you mount is visible inside the container with the mode you set ('':ro'' or '':rw'').
- Default is read-write if you omit the mode; prefer :ro for source/secrets.
- ''scope: "shared"'' 是代理每个绑定忽略执行(全局绑定仅適用被)。
- Binding /var/run/docker.sock effectively hands host control to the sandbox; only do this intentionally.
- Workspace access (''workspaceAccess: "ro"''/''"rw"'') is independent of bind modes.
Tool policy: which tools exist/are callable
Two layers matter:
- ''Tool profile'': ''tools.profile'' and ''agents.list[].tools.profile'' (base allowlist)
- ''Provider tool profile'': ''tools.byProvider[provider].profile'' and ''agents.list[].tools.byProvider[provider].profile''
- ''全局/代理每个工具策略'':''tools.allow''/''tools.deny'' 和 ''agents.list[].tools.allow''/''agents.list[].tools.deny''
- ''提供商工具策略'':''tools.byProvider[provider].allow/deny'' 和 ''agents.list[].tools.byProvider[provider].allow/deny''
- ''Sandbox tool policy'' (only applies when sandboxed): ''tools.sandbox.tools.allow''/''tools.sandbox.tools.deny'' and ''agents.list[].tools.sandbox.tools.*''
経験則:
- ''deny'' always wins.
- If ''allow'' is non-empty, everything else is treated as blocked.
- Tool policy is the hard stop: /exec cannot override a denied exec tool.
- /exec only changes session defaults for authorized senders; it does not grant tool access.
- Provider tool keys accept either ''provider'' (e.g. ''google-antigravity'') or ''provider/model'' (e.g. ''openai/gpt-5.2'').
#
工具群组(短縮形)
Tool policies (global, agent, sandbox) support ''group:*'' entries that expand to multiple tools:
{
tools: {
sandbox: {
tools: {
allow: ["group:runtime", "group:fs", "group:sessions", "group:memory"],
},
},
},
}利用可能那群组:
- ''group:runtime'':''exec''、''bash''、''process''
- ''group:fs'':''read''、''write''、''edit''、''apply_patch''
- ''group:sessions'':''sessions_list''、''sessions_history''、''sessions_send''、''sessions_spawn''、''session_status''
- ''group:memory'':''memory_search''、''memory_get''
- ''group:ui'':''browser''、''canvas''
- ''group:automation'':''cron''、''gateway''
- ''group:messaging'':''message''
- ''group:nodes'':''nodes''
- ''group:openclaw'':所有組见入见 OpenClaw 工具(提供商插件除可)
提升:运行专用「主机在运行」
提升是添加的工具付与不会执行。''exec'' 在仅影響执行。
- If you're sandboxed, /elevated on (or exec with elevated: true) runs on the host (approvals may still apply).
- Use /elevated full to skip exec approvals for the session.
- If you're already running direct, elevated is effectively a no-op (still gated).
- Elevated is not skill-scoped and does not override tool allow/deny.
- /exec is separate from elevated. It only adjusts per-session exec defaults for authorized senders.
Gates:
- 启用:''tools.elevated.enabled''(以及选项在 ''agents.list[].tools.elevated.enabled'')
- Sender allowlists: ''tools.elevated.allowFrom.<provider>'' (and optionally ''agents.list[].tools.elevated.allowFrom.<provider>'')
See Elevated Mode for details.
一般的那「沙盒刑務所」的修復
#
Common "sandbox jail" fixes (continued)
修復密钥(1 次选择):
- 沙盒禁用在执行:''agents.defaults.sandbox.mode=off''(或代理每个 ''agents.list[].sandbox.mode=off'')
- 工具沙盒在允许执行:
- ''tools.sandbox.tools.deny''(或代理每个 ''agents.list[].tools.sandbox.tools.deny'')从删除执行
- 或 ''tools.sandbox.tools.allow''(或代理每个允许)在添加执行
#
Non-main session sandboxing
In ''"non-main"'' mode, group/channel keys are not main. Use the main session key (shown by ''sandbox explain'') or switch mode to ''"off"''.