$ the-wire · showcase
Access audit trails on delete, subagent wake-up fix
By RepoJournal · Filed · About OpenClaw · Composed from the cited sources · methodology
openclaw-enterprise closes the gap where deleted Secrets and torn-down Namespaces took their access grants with them silently, while openclaw fixes finished subagents that never woke their parents.
fix(iam): audit access removed with its target and drop a deleted Namespace's policy openclaw/openclaw-enterprise
Deleting a Secret, Configuration, Preset, credential source, ServiceAccount, or Agent now lists the AccessBindings it removed in the delete audit event, and Namespace teardown deletes the Namespace's AccessBindings and Roles in the same tombstoning transaction, so no grant outlives its Namespace. Enterprise docs now describe that audit behavior.
fix(agents): finished subagents fail to wake their parent when registry writes overlap openclaw/openclaw
Finished subagents could fail to wake or settle their parent when registry writes overlapped, leaving the parent waiting forever while the Gateway logged that a subagent publication lost its original preimage. The fix makes the terminal signal commit even when the registry row mutates concurrently.
refactor(cron): remove runtime legacy job identity repair openclaw/openclaw
Cron no longer repairs obsolete file-job identity aliases at runtime, since every supported SQLite writer persists canonical identities and readers install the authoritative job_id. An alias-only invalid save now fails before it replaces existing rows, while Doctor still recovers supported quarantine payloads.
fix(sessions): retain agent ownership for run operations (#161119) openclaw/openclaw
Run-based artifact lookup and terminal persistence could lose the original agent when a conversation used a raw key such as global, or when resolution fell back to a resident session row after run-context cleanup. Run operations now retain the original logical agent and unchanged stored key together, and gateway and cron admission record the owner they already selected.
Merge pull request #876: fix(runtime): drop the codex untrusted-workspace startup error openclaw/openclaw-enterprise
The runtime no longer emits the codex untrusted-workspace startup error.
Merge pull request #880: fix(kubernetes): drop kubelet's log-unavailable answer from runtime log reads openclaw/openclaw-enterprise
Runtime log reads stop surfacing kubelet's log-unavailable answer.
fix(ci): freeze lockfiles before pnpm bootstrap (#162862) openclaw/openclaw
Older selected-source installers could invoke pnpm before their install-only frozen-lockfile flag took effect, letting package-manager bootstrap rewrite the selected source lockfile. The source receiver now supplies frozen policy before starting the installer.
fix: keep docs design consistent across languages openclaw/docs
Non-English visitors saw an obsolete homepage hero and different composition, because English heading IDs controlled section placement. All 21 supported languages now share the same homepage design with localized copy, and the RTL language menu stays on screen. Footer social links were resynced with openclaw.ai and the decorative background now renders on every page and locale, articles included.