Inspection times out but screenshots work
Snapshots and page-text reads use a browser automation connection that can become stale even while tab listing and screenshots still work. OpenClaw reconnects once when that connection can no longer resolve the requested tab. Unresponsive sibling tabs share one target-inspection wait instead of adding a separate wait per tab. Retry the inspection once with the same profile and target ID. If it still fails, runopenclaw browser doctor and inspect a screenshot before restarting the
Gateway. A browser-rendered HTTP error, such as 403 Forbidden, is evidence that
the website denied access; it does not establish whether a profile or resource
exists.
Output directory errors
If an output fails withInvalid path: must stay within output directory, set
the output directory to its real, canonical path. Browser outputs reject
user-created symlinks anywhere in the directory path, including when the final
directory already exists. The macOS /tmp and /var system aliases remain
supported.
CDP startup failure vs navigation SSRF block
These are different failure classes and they point to different code paths.- CDP startup or readiness failure means OpenClaw cannot confirm that the browser control plane is healthy.
- Navigation SSRF block means the browser control plane is healthy, but a page navigation target is rejected by policy.
- CDP startup or readiness failure:
Chrome CDP websocket for profile "openclaw" is not reachable after startRemote CDP for profile "<name>" is not reachable at <cdpUrl>Port <port> is in use for profile "<name>" but not by openclawwhen a loopback external CDP service is configured withoutattachOnly: true
- Navigation SSRF block:
open,navigate, snapshot, or tab-opening flows fail with a browser/network policy error whilestartandtabsstill work
- If
startfails withnot reachable after start, troubleshoot CDP readiness first. - If
startsucceeds buttabsfails, the control plane is still unhealthy. Treat this as a CDP reachability problem, not a page-navigation problem. - If
startandtabssucceed butopenornavigatefails, the browser control plane is up and the failure is in navigation policy or the target page. - If
start,tabs, andopenall succeed, the basic managed-browser control path is healthy.
- Browser config defaults to a fail-closed SSRF policy object even when you do not configure
browser.ssrfPolicy. - For the local loopback
openclawmanaged profile, CDP health checks intentionally skip browser SSRF reachability enforcement for OpenClaw’s own local control plane. - After launching a local managed browser, readiness probes allow up to 1.5 seconds per HTTP request and 2 seconds per WebSocket stage to tolerate Gateway scheduling delays. The readiness retry window is eight seconds; probes near its end use shorter timeouts.
- Later operations use the same readiness allowance for an owned managed browser before deciding it needs a restart. Stopping a profile aborts its pending discovery and readiness probes; canceling one caller waiting for a shared start does not stop that shared launch.
- Navigation protection is separate. A successful
startortabsresult does not mean a lateropenornavigatetarget is allowed.
- Do not relax browser SSRF policy by default.
- Prefer narrow exact-hostname
allowedHostnamesexceptions over broad private-network access. - Use
dangerouslyAllowPrivateNetwork: trueonly in intentionally trusted environments where private-network browser access is required and reviewed.