$ the-wire · showcase
OpenClaw 2026.8.35 ships critical security fixes, Bun patches NODE_OPTIONS and worker ports
By RepoJournal · Filed · About OpenClaw · Composed from the cited sources · methodology
The extended-stable gateway release lands with backported security fixes and GPT-6.1 Sol support, while Bun closes a cluster of Node-compatibility gaps that silently changed process and worker behavior.
openclaw 2026.8.35 openclaw/openclaw
The extended-stable (LTS-equivalent) gateway release is OpenClaw from the end of August 2026 plus critical security updates, reliability and performance fixes, and new model support including GPT-6.1 Sol across OpenAI routing and discovery. If you pin to extended-stable rather than the 2026.9.7 current release, this is the branch that now carries the security backports.
fix(cli): apply supported NODE_OPTIONS before command-line arguments openclaw/bun
Bun ignored NODE_OPTIONS entirely, so a child process launched with an environment --require preload ran without its startup hook even though the same preload passed on the command line worked. Bun now parses Node's quoting and escaping rules and applies the Node flags it implements before ordinary command-line arguments, which unblocks process-manager fixtures and tools that propagate startup ...
fix(worker_threads): preserve emitted MessagePort payloads openclaw/bun
MessagePort.emit("message", payload) treated payload as an event-init dictionary, so Node listeners received null instead of the original object; it now constructs the matching Web event and preserves the raw emitted value, including undefined, for the native parentPort transferred into Node workers. Any code emitting on a MessagePort with a Node-style listener has been getting null.
fix(process): enumerate newly assigned Windows environment variables (#81) openclaw/bun
Windows native environment accessors stayed non-enumerable when a variable was absent at launch, so environment copies silently dropped values such as TZ. Written properties are now enumerable while retaining their native accessors and SHARE_ENV behavior, with the regression proof matching Node 24.
fix(auth): classify only connection failures as unreachable for device login openclaw/openclaw-enterprise
The long tail: device-login auth now classifies only genuine connection failures as unreachable, names the cluster's egress policy in the API message, and surfaces a "Codex sign-in failed." console prefix; Codex connection and network proxy diagnostics are readable again in the Logs tab and occ agent logs; a namespace left behind by a failed Dedicated Agent create can now be deleted; gateway re...
Action items
- → Upgrade openclaw to 2026.8.35 to pick up the backported critical security updates on extended-stable openclaw/openclaw [plan]