$ the-wire · showcase
fs-safe 0.21.1 hardens Linux symlink resolution and denies case-insensitive bypasses
By RepoJournal · Filed · About OpenClaw · Composed from the cited sources · methodology
The day's highest-stakes work is defensive: a fs-safe patch release closes symlink and deny-policy gaps on Linux and case-insensitive filesystems, while openclaw's fourth-pass deslop sweeps and a batch of acpx test-harness fixes land behind it.
fs-safe 0.21.1 openclaw/fs-safe
by github-actions[bot]
On Linux builds without openat2, native opens now follow in-root relative symlinks exactly as RESOLVE_BENEATH does: absolute links, `..` escapes, procfs and nosymfollow links, and chains longer than 40 are rejected, links inside sticky world-writable directories are refused, and deny/symlink policies report the same errors as the openat2 path. `denyMutations` also now denies creations that case...
fix(acpx): recover adapter launches after plugin capture cleanup (#160156) openclaw/openclaw
Codex and Claude ACP launches were failing with `MODULE_NOT_FOUND` when cleanup reclaimed the plugin capture referenced by their durable wrappers. Generated wrappers now fall back to the existing pinned adapter package when the captured entry file disappears, with installed adapters still preferred; restart the Gateway after updating to regenerate wrappers.
fix(viewer): retain live state during atomic replacement openclaw/acpx
The viewer's optional-read fallbacks were swallowing the `path-mismatch` error raised when polling overlapped an atomic replacement, and republished an older saved projection instead of the live one. The error now propagates through summary loading, the listing batch and selected-run loading so the existing live-resource recovery keeps the last readable state.
refactor(channels): deslop Telegram, Matrix and Feishu fourth pass (#160032) openclaw/openclaw
The fourth deslop pass over the Telegram, Matrix and Feishu channels shares canonical types and parameter/result owners, removes unused forwarding layers and callback projections, and cuts 629 net production lines while preserving wire formats and policy contracts. It also fixes Telegram membership audits leaking owned transports and Mini App bootstrap issuance retaining stale configuration acr...
refactor(commands): deslop commands fourth pass (#158940) openclaw/openclaw
The commands fourth pass keeps transcript reads available during registry refresh by preparing auxiliary store discovery only for history views that consume cross-store lineage, while preserving primary authority and cleanup checks on every request and disposing Talk test resources even when publication rejects.
perf(copy): reuse the admitted clone filesystem (#732) openclaw/fs-safe
Copy operations reuse the filesystem name returned by native clone admission rather than re-querying the same retained parent descriptor. Installed XFS/Btrfs syscall traces show destination probes dropping from 3 to 2 with source probes unchanged across a 64-leg, 28,800-call study.
improve(ui): show active collaborators below typing previews (#159263) openclaw/openclaw
Two inline collaborator preview bubbles now sit below typing previews with independent draft and expiry deadlines; extra active collaborators share one bounded, named overflow row that clears on stop or idle without discarding retained preview drafts.
ci: execute every shipped platform and add nightly watch stress openclaw/fs-safe
CI now runs all seven shipped native bindings, adds Windows Server 2022 and Node 26, exercises the Linux no-openat2 descriptor walk, and loads glibc 2.28 bindings on Rocky Linux 8 for both GNU architectures, with a nightly watch stress workflow across Linux, macOS and Windows and unchanged required check names. The four remaining acpx items bound test-harness cleanup and argument validation: fl...
Action items