T06 · System Persistence
- Location
references/troubleshooting.md:321- Finding
Boot-Persistent OpenClaw Service Exceeds the Docker Deployment Scope
- Content
View full analysis
/dev/null << EOF [Unit] Description=OpenClaw Gateway After=network.target [Service] Type=simple User=$USER ExecStart=/usr/bin/node $(npm prefix -g)/bin/openclaw gateway --bind lan --port 18789 Restart=on-failure RestartSec=5 [Install] WantedBy=multi-user.target EOF sudo systemctl daemon-reload sudo systemctl enable openclaw sudo systemctl start openclaw sudo systemctl status openclaw ``` ``` ### Technical Analysis The instructions globally install OpenClaw, use root privileges to write a systemd unit under `/etc/systemd/system`, configure automatic restart, and enable the service at boot. Although the service process is configured to run as the invoking user rather than root, creating and enabling the unit requires administrative privileges and gives the installed package a durable host execution path. This behavior exceeds the minimum privileges necessary for the Skill's declared purpose, which is running OpenClaw inside Docker. A host-level global installation and boot-enabled service bypass the intended container boundary and persist across terminal sessions and system restarts. The service also starts the gateway with `--bind lan`, increasing its network exposure relative to a localhost-only deployment. The globally installed npm package is not pinned to a reviewed version, so the persistent executable may change depending on the package version available when the user follows the instructions. ### Attack Path 1. A user follows the Docker-to-global migration instructions. 2. `npm install -g openclaw` installs the currently published, unpinned package. 3. Root privileges are used to create a sys ...[truncated 1027 chars]- Remediation
View remediation
