$ the-wire · showcase
OpenClaw's deslop sweep removes 1,000+ production lines
By RepoJournal · Filed · About OpenClaw · Composed from the cited sources · methodology
A coordinated refactor across core, gateway, plugins, and the control UI strips duplicate adapters and plumbing while holding public contracts fixed, and the enterprise and Peekaboo desks spend the day tightening test fixtures and identity checks.
refactor(core): deslop small core subsystems (#164708) openclaw/openclaw
Credential selection duplication, one-use forwarding layers, and fixed-option plumbing are gone across core subsystems, a net reduction of 1,000 production lines. Configuration, persisted data, protocol shapes, SDK contracts, security checks, and lifecycle fencing are all explicitly preserved, so the change should be invisible to callers.
refactor(plugins): deslop plugins (#164617) openclaw/openclaw
Private plugin activation, auth-receipt settlement, callback binding, and SDK forwarding are simplified for a net 565 production lines and 62 test lines removed. Windows startup checks, receiver-free recovery callbacks, and protected metadata/scan contracts survive, and the assertion ratchet drops from 3 to 2.
fix(channels): preserve lazy pairing reads for Doctor openclaw/openclaw
The dynamic import is restored at the default ingress allowlist reader, after a static import pulled memory-wiki's Doctor contract into Kysely through security-runtime and the shared-state reader. Doctor should load without that database graph until an actual store read.
fix(audit): redact and cap route denial explanations openclaw/openclaw-enterprise
The controller's denial() helper was spreading route explanations on top of the audit event, so decisionReason skipped the factory's redaction and its 120-character cap, and details reached the Postgres sink unredacted. The Agent service principal denial records a 220-character reason today; the route denial explanations are now redacted and capped.
fix(paste): fence exact-window clipboard delivery openclaw/Peekaboo
Temporary rich and binary paste is now fenced to an exact background window using the native clipboard generation retained by the write transaction, and the input host checks a content-free claim before every new key-down. A competing copy stops new paste input without suppressing releases owed to the original process generation.
test(auth): pin the shared ID-token verifier once openclaw/openclaw-enterprise
The generic ID-token cases that google-id-token.test.mjs re-ran against verifyIdToken are now pinned once in oidc-id-token.test.mjs, ending two copies that had drifted and killed different verifier mutants.