$ the-wire · showcase
fs-safe 0.19.0 hardens atomic secret writes, nightly release validation lands
By RepoJournal · Filed · About OpenClaw · Composed from the cited sources · methodology
fs-safe shipped 0.19.0 with stricter secret-file durability and literal tilde handling, while openclaw.io restructured its usage-cost and release-validation internals to make future catalog and packaging changes safe.
fs-safe 0.19.0 openclaw/fs-safe
by github-actions[bot]
createSecretFileAtomic() now accepts durable: "file" to require every file flush to succeed, including on EPERM, with parent-directory synchronization remaining best effort. FileStore keys, absolute Root reads, discovered walk entries, and ZIP/TAR entries named ~ are now treated literally rather than as home-directory shorthand across reads, writes, removal, pruning, and extraction.
fix(cron): announce runs miss the channel's formatting rules openclaw/openclaw
Scheduled cron runs that announce to a channel were getting none of that channel's formatting rules, so a job posting to a Telegram chat with richMessages: true never saw the rich-message contract and the model guessed its markup. A fix follows the earlier move of the Telegram rich contract out of the core system prompt and into the channel's inbound formatting hints, so the same job stops flip...
ci(release): schedule a nightly Full Release Validation of main openclaw/openclaw
A nightly Full Release Validation of main now runs unattended, reusing the openclaw-live-updater skill's 12-hour pnpm ci:full-release cadence. That work previously began only when an operator took over a stable cut, and the 2026.9.6 stable spent 21 hours from takeover to core npm.
fix(release): serialize plugin SDK install and render phases openclaw/openclaw
Plugin SDK API rendering could start while a sibling package install was still mutating the shared prepared workspace, so the renderer read a partially installed dependency tree and failed nondeterministically. Package preparation now has two explicit phases: all isolated installs complete first, then all API renders run, keeping parallelism within each phase.
refactor(usage): capture hosted pricing once per operation openclaw/openclaw
Each usage-cost operation now retains a single hosted pricing context, preparing accounting for catalog updates that can occur mid-operation. Nothing changes for existing recorded costs, configured overrides, or local model prices, and catalog downloads still require a Gateway restart to activate.
fix(native): reject negative Unix descriptor sentinels openclaw/fs-safe
The rest of the day was the long tail: a shared nonnegative-descriptor check across fs-safe's query, hashing, staging, cleanup, and clone/copy admission paths (macOS opens beneath roots now reject negatives with EBADF before openat), a rollback retry for ReFS clones that reject the ignore-readonly deletion flag, and thirteen duplicated slash-command failure builders collapsed into one private c...
Action items
- → Upgrade fs-safe to 0.19.0 to get the durable: "file" secret-write guarantee and literal ~ path handling openclaw/fs-safe [plan]