OpenClaw merged PR #168862, a Gateway reliability fix for shutdowns that intersect with retired worker inventories.
The issue was narrow but operationally annoying. A Gateway could be otherwise finished shutting down, yet still fail because the worker inventory had already retired before the tunnel cleanup path could ask it for the final state. A related reconciliation path could also reject after shutdown had already started.
What Changed
The fix adds a typed retirement error for worker inventories and handles it at two shutdown boundaries. Tunnel shutdown now treats an already retired inventory as acceptable only around the fallback inventory lookup, while still awaiting and reporting real remote cleanup failures. Reconciliation also treats retirement as expected only after its existing stop flag has been set.
That distinction matters. OpenClaw is not hiding every worker-environment failure during shutdown. It is recognizing the specific case where the inventory owner has already crossed the retirement boundary and the cleanup path should finish draining retained tunnels and workspace transfers instead of failing the whole shutdown.
The PR also simplifies nearby tunnel status and live-owner code, but the behavioral change stays focused. No database schema, configuration, lifecycle state, or memory limit is added.
Why It Matters
Gateway shutdown is a trust surface. When users stop a Gateway, they need retained worker tunnels and workspace transfers to be cleaned up predictably. A false shutdown failure can make an operator wonder whether cleanup actually happened, whether they need to restart, or whether a workspace transfer was left in an uncertain state.
This PR makes the shutdown path more tolerant of one expected race:
- Worker inventory retirement can happen before the last cleanup lookup.
- Retained tunnels and transfers still drain.
- Ordinary inventory, teardown, and remote cleanup failures remain visible.
- A running Gateway with a retired inventory still needs separate recovery.
That last point keeps the fix honest. It repairs the shutdown boundary, not every possible worker inventory failure.
Proof From The PR
The PR records red/green regression evidence before the handling fix. The two retirement regressions failed before the patch while their ordinary-error counterparts still passed, confirming that the repair targeted the expected edge rather than muting broad errors.
The final proof covered node-worker-tunnel and service-lifetime suites on isolated AWS. The PR reports 26 tunnel tests and 27 service-lifetime tests passing, along with type-aware lint, export collision checks, line-cap checks, formatting, core typecheck, and Knip scans.
There was also a follow-up after CI found a missing shared retirement-error module in the PR wrapper source inventory. The final integration preserved the worker-file behavior, resolved conflicts with landed byte-reader work, and kept the refreshed P0/P1 review clean.
Bottom Line
PR #168862 makes OpenClaw Gateway shutdowns less brittle around retired worker inventories. Operators should see fewer false shutdown failures while still getting signal when real worker cleanup fails.