Documentation menu
On this page

Why the model can’t turn wardend off

The whole point of WardenClaw is that a compromised or malicious model must not be able to disable its own guard. This page states plainly what that guarantee rests on, what is proven by tests in redteam/, and where the honest limits are. No marketing.

The adversary

Assume the worst realistic case: the model fully controls the harness process (OpenClaw or any other agent) and every one of its descendants. It can issue any syscall that its user is allowed to. It cannot gain privileges its user does not have, and it cannot run execve/execveat around the gate (that is exactly what wardend notifies on).

Everything below turns on one question: does wardend run under the same user as the harness, or a different one?

The decisive premise: same user vs separate user

wardend gates execve/execveat through a seccomp user-notification filter. It does not gate kill, ptrace, process_vm_writev, or writes to files and /proc/<pid>/mem. Under Linux, whether those cross-process operations are allowed is decided by the kernel from the UID, not by seccomp.

So there are two very different deployments:

Vector table

Vector Same-user Hardened install
Run a command around the gate (execve/execveat) Closed (seccomp USER_NOTIF) Closed
Nested seccomp notify filter to answer “yes” itself Closed (filter denies a new listener) Closed
32-bit / compat exec to dodge the filter Closed (foreign arch -> ENOSYS) Closed
memfd_create + execveat, fexecve, calling ld.so directly Closed (still gated; unresolved path -> deny) Closed
TOCTOU: swap argv or the file after CONTINUE Closed (SIGSTOP post-check, default) Closed
Approve its own card over HTTP (127.0.0.1) Closed (needs a trusted device signature; pairing only off the filter) Closed
Forge or replay a ticket Closed (Ed25519, nonce, time window) Closed
Flood the card queue (DoS) Closed (bounded queue -> EAGAIN) Closed
kill / ptrace / process_vm_writev the supervisor Open (same UID) Closed by the kernel (different UID)
Write the binary / config / key / journal Open (owned by the agent’s UID) Closed (root-owned)
Write /proc/<supervisor>/mem Open Closed by the kernel
Rewrite the service unit and restart without the gate Open (user unit is writable) Closed (root-owned system unit)
OOM-kill the supervisor Open Reduced (OOMScoreAdjust in the unit)

Every “Closed” cell above is exercised by a test in redteam/ or the main suite (exec, memfd, ld.so, nested listener, pairing, forgery, queue). Every “Open” cell is demonstrated succeeding in same-user mode by redteam/run.sh, which is the proof that the hardened install is not optional for a real guarantee. The reverse check, redteam/hardened-check.sh, runs as the agent user on a hardened install and expects every one of those attacks to be refused (step 7).

What wardend does at startup

Honest premises and out of scope