Problem
BenchFlow core owns a 973-line OpenClaw-specific ACP shim in src/benchflow/agents/openclaw_acp_shim.py, reads it during registry import, and embeds it into OpenClaw's sandbox installer.
benchflow-ai/agents separately carries same shim as an opaque base64 payload in acp/openclaw/manifest.toml. Every shim change therefore starts in framework core, needs a BenchFlow release, then needs a generated cross-repo payload sync. Human review sees a one-line encoded manifest change rather than readable adapter code.
This is wrong ownership boundary. Shim implements OpenClaw workspace layout, auth stores, provider config, model quirks, subprocess behavior, and private session-JSONL parsing. Those are agent-adapter concerns. BenchFlow core should own generic manifest discovery, ACP transport, sandbox lifecycle, provider-env contract, and trajectory capture.
Recent evidence
OpenClaw churn repeatedly changed BenchFlow core and then agents manifest:
Desired outcome
benchflow-ai/agents is sole owner of readable, tested OpenClaw shim source.
- BenchFlow resolves public OpenClaw forms through external manifest while retaining same installed bytes and behavior initially.
- Source failures for
openclaw, acp/openclaw, acpx/openclaw, and acp:openclaw fail before sandbox provisioning; none can degrade into raw/PATH command execution.
- Unrelated malformed manifests remain warnings. Bad, absent, duplicate, or incompatible OpenClaw manifest fails with typed resolution error.
- Core contains no OpenClaw shim or installer implementation after extraction.
Scope
- Copy current shim byte-for-byte into agents repo with focused tests and freshness CI.
- Preserve current inline manifest payload during ownership cutover.
- Add minimal fail-closed known-migrated-agent resolution plus non-poisoning CLI discovery.
- Remove core OpenClaw source/registry installer only after external path passes Docker and Daytona parity.
Removing inline base64 through a checksum-verified raw-Git artifact is a separate optional transport milestone. It changes sandbox egress requirements and is not required to complete ownership extraction.
Non-goals
- Native Gateway
openclaw acp promotion.
- Fixing current blocking cancel behavior.
- Changing global
benchflow-ai/agents@main policy or adding offline catalog snapshots.
- OpenClaw-only result provenance, manifest contract metadata, or broad agent-loader redesign.
- Generic MCP capability model.
Generic selected-agent source provenance and broader agent-system architecture belong in #1089, not this extraction.
Problem
BenchFlow core owns a 973-line OpenClaw-specific ACP shim in
src/benchflow/agents/openclaw_acp_shim.py, reads it during registry import, and embeds it into OpenClaw's sandbox installer.benchflow-ai/agentsseparately carries same shim as an opaque base64 payload inacp/openclaw/manifest.toml. Every shim change therefore starts in framework core, needs a BenchFlow release, then needs a generated cross-repo payload sync. Human review sees a one-line encoded manifest change rather than readable adapter code.This is wrong ownership boundary. Shim implements OpenClaw workspace layout, auth stores, provider config, model quirks, subprocess behavior, and private session-JSONL parsing. Those are agent-adapter concerns. BenchFlow core should own generic manifest discovery, ACP transport, sandbox lifecycle, provider-env contract, and trajectory capture.
Recent evidence
OpenClaw churn repeatedly changed BenchFlow core and then agents manifest:
openclaw@2026.6.9after floating runtime broke fresh runs.Desired outcome
benchflow-ai/agentsis sole owner of readable, tested OpenClaw shim source.openclaw,acp/openclaw,acpx/openclaw, andacp:openclawfail before sandbox provisioning; none can degrade into raw/PATH command execution.Scope
Removing inline base64 through a checksum-verified raw-Git artifact is a separate optional transport milestone. It changes sandbox egress requirements and is not required to complete ownership extraction.
Non-goals
openclaw acppromotion.benchflow-ai/agents@mainpolicy or adding offline catalog snapshots.Generic selected-agent source provenance and broader agent-system architecture belong in #1089, not this extraction.