Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
119 lines
4.3 KiB
Markdown
119 lines
4.3 KiB
Markdown
---
|
|
summary: "Bot-to-bot loop protection defaults and channel overrides"
|
|
read_when:
|
|
- Configuring bot-authored channel messages
|
|
- Tuning bot-to-bot loop protection
|
|
title: "Bot loop protection"
|
|
sidebarTitle: "Bot loop protection"
|
|
---
|
|
|
|
OpenClaw can accept messages written by other bots on channels that support `allowBots`. When that path is enabled, pair loop protection prevents two bot identities from replying to each other indefinitely.
|
|
|
|
The guard is enforced by the core inbound reply runner. Each supporting channel maps its inbound event into generic facts: account or scope, conversation id, sender bot id, and receiver bot id. Core tracks the participant pair in both directions (A to B and B to A count as the same pair), applies a sliding-window budget, and suppresses the pair during a cooldown after the budget is exceeded.
|
|
|
|
## Defaults
|
|
|
|
Pair loop protection is active whenever a channel lets bot-authored messages reach dispatch. Built-in defaults:
|
|
|
|
| Key | Default | Meaning |
|
|
| -------------------- | ------- | --------------------------------------------------- |
|
|
| `enabled` | `true` | Guard active for channels that support it. |
|
|
| `maxEventsPerWindow` | `20` | Events a bot pair can exchange within the window. |
|
|
| `windowSeconds` | `60` | Sliding window length. |
|
|
| `cooldownSeconds` | `60` | Suppression time after the pair exceeds the budget. |
|
|
|
|
The guard does not affect human-authored messages, single-bot deployments, self-message filtering, or bot replies that stay under the budget.
|
|
|
|
## Configure shared defaults
|
|
|
|
Set `channels.defaults.botLoopProtection` once to give every supporting channel the same baseline. Channel, account, and room overrides can still tune individual surfaces.
|
|
|
|
```json5
|
|
{
|
|
channels: {
|
|
defaults: {
|
|
botLoopProtection: {
|
|
maxEventsPerWindow: 20,
|
|
windowSeconds: 60,
|
|
cooldownSeconds: 60,
|
|
},
|
|
},
|
|
},
|
|
}
|
|
```
|
|
|
|
Set `enabled: false` only when your channel policy intentionally allows bot-to-bot conversations without automatic suppression.
|
|
|
|
## Override per channel, account, or room
|
|
|
|
Supporting channels layer their own config over the shared default, key by key. Precedence, narrowest first:
|
|
|
|
1. `channels.<channel>.<room-or-space>.botLoopProtection`, when the channel supports per-conversation overrides
|
|
2. `channels.<channel>.accounts.<account>.botLoopProtection`, when the channel supports accounts
|
|
3. `channels.<channel>.botLoopProtection`, when the channel supports top-level defaults
|
|
4. `channels.defaults.botLoopProtection`
|
|
5. built-in defaults
|
|
|
|
```json5
|
|
{
|
|
channels: {
|
|
defaults: {
|
|
botLoopProtection: {
|
|
maxEventsPerWindow: 20,
|
|
},
|
|
},
|
|
discord: {
|
|
botLoopProtection: {
|
|
maxEventsPerWindow: 8,
|
|
},
|
|
accounts: {
|
|
secondary: {
|
|
allowBots: "mentions",
|
|
botLoopProtection: {
|
|
maxEventsPerWindow: 5,
|
|
cooldownSeconds: 90,
|
|
},
|
|
},
|
|
},
|
|
},
|
|
googlechat: {
|
|
allowBots: true,
|
|
groups: {
|
|
"spaces/AAAA": {
|
|
botLoopProtection: {
|
|
maxEventsPerWindow: 5,
|
|
},
|
|
},
|
|
},
|
|
},
|
|
matrix: {
|
|
allowBots: "mentions",
|
|
groups: {
|
|
"!roomid:example.org": {
|
|
botLoopProtection: {
|
|
maxEventsPerWindow: 5,
|
|
},
|
|
},
|
|
},
|
|
},
|
|
slack: {
|
|
allowBots: "mentions",
|
|
botLoopProtection: {
|
|
maxEventsPerWindow: 8,
|
|
},
|
|
},
|
|
},
|
|
}
|
|
```
|
|
|
|
## Channel support
|
|
|
|
- Discord: native `author.bot` facts, keyed by Discord account, channel, and bot pair.
|
|
- Google Chat: native `sender.type=BOT` facts for accepted bot-authored messages, keyed by account, space, and bot pair.
|
|
- Matrix: configured Matrix bot accounts, keyed by Matrix account, room, and configured bot pair.
|
|
- Slack: native `bot_id` facts for accepted bot-authored messages, keyed by Slack account, channel, and bot pair.
|
|
|
|
Channels that do not expose a reliable inbound bot identity keep using their normal self-message and access-policy filters. They should not opt into this guard until they can identify both participants in the bot pair.
|
|
|
|
See [SDK runtime](/plugins/sdk-runtime#reusable-runtime-utilities) for plugin implementation details.
|