$ cat openclaw/month/2026-09-01.log
the month in review · September 2026
OpenClaw 2026.9.7 backs up state before migrations
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
September also fixed three Slack and attachment authorization gaps, and openclaw 2026.9.3 to 2026.9.4 added update rehearsals and rollback recovery.
Slack file downloads could miss conversation authorization openclaw/openclaw
A Slack file download could be served without checking that the requester was authorized for the conversation it came from. If your workspace runs OpenClaw against Slack, treat this as a data-exposure fix and move to a build that includes it.
OpenAI-compatible transport could send provider credentials to the wrong endpoint openclaw/openclaw
The OpenAI-compatible transport could send provider credentials to the wrong endpoint. Anyone pointing OpenClaw at a self-hosted or third-party OpenAI-compatible provider should rotate the credentials that transport carried.
Outbound attachments could ignore requester read denials openclaw/openclaw
Outbound attachments could be sent despite a read denial from the requester. The fix matters most where you rely on read permissions to gate what leaves an agent session.
openclaw 2026.9.7 openclaw/openclaw
by github-actions[bot]
Updates now back up every state and agent database before migrations, restore them on rollback, and take consistent snapshots while the Gateway keeps writing. The update stops before schema changes if snapshot cleanup fails, so a failed run leaves the old schema intact rather than half-migrated.
openclaw 2026.9.4 openclaw/openclaw
by github-actions[bot]
The release retains the previous package and restores it with the previous configuration and service when schema and configuration checks prove rollback is safe. Database migrations are the exception: they still require a verified pre-update backup, so budget for that in automation that upgrades unattended.
openclaw 2026.9.3 openclaw/openclaw
by github-actions[bot]
Core and plugin changes are now rehearsed in isolated candidate state before activation, eligible 2026.9.2 migrations are supported, and abandoned update records recover without stopping a healthy matching Gateway. It is the release that makes the later rollback work reachable in practice.
fs-safe 0.21.1 openclaw/fs-safe
by github-actions[bot]
On Linux without openat2, native opens now follow in-root relative symlinks exactly as RESOLVE_BENEATH does, rejecting absolute links, `..` escapes, procfs and nosymfollow links, and chains longer than 40. Denial and symlink policies report the same errors as the openat2 path, so behavior no longer diverges by kernel.
acpx 0.18.0 openclaw/acpx
Sessions can change modes, models, and configuration through the shared runtime and inspect capabilities without shelling out to the CLI, and final output, usage, and accepted settings survive cancellation, timeouts, and reconnects. Callers wrapping acpx get a stable result across those paths instead of reconstructing state themselves.
$ ls openclaw/month/ # the briefings behind this review
Keep up with OpenClaw in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.