Diagrams of where OpenClaw tool execution runs and what contains it, across the common sandbox configurations. Each figure fuses the machine / container / process boundaries with the tool-call containment. The configuration figures use two agents on one gateway paired with a generic node; per-platform node containment has its own section.
- Head:
9d79002fbacafe741b44416ca02773e2547467e5 - Static Windows host route:
ssh, leasestatic_172-26-197-87, targetwindows-normal - Command:
pr97086-gather-windows-runtime-proof.ps1 -ProofHead 9d79002fbacafe741b44416ca02773e2547467e5 -SkipInstall -SkipBuild -NoScreenshot - Runtime markers:
PROOF_MXC_RUNTIME_EXIT 0,PROOF_MXC_RUNTIME_OK,PROOF_RUNTIME_AND_SCREENSHOT_COLLECTION_OK - Note: screenshot was captured in the interactive desktop proof run from the same synced file content; this exact-head rerun verifies the final pushed commit id.