RepoJournal

$ cat openclaw/month/2026-09-01.log

OpenClaw

OpenClaw

the month in review · September 2026

OpenClaw 2026.9.7 backs up state before migrations

By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology

♥

September also fixed three Slack and attachment authorization gaps, and openclaw 2026.9.3 to 2026.9.4 added update rehearsals and rollback recovery.

2930 commits 1589 PRs merged 30 releases 10 security advisories 30 briefings covered

all openclaw reviews →

Slack file downloads could miss conversation authorization openclaw/openclaw

A Slack file download could be served without checking that the requester was authorized for the conversation it came from. If your workspace runs OpenClaw against Slack, treat this as a data-exposure fix and move to a build that includes it.

OpenAI-compatible transport could send provider credentials to the wrong endpoint openclaw/openclaw

The OpenAI-compatible transport could send provider credentials to the wrong endpoint. Anyone pointing OpenClaw at a self-hosted or third-party OpenAI-compatible provider should rotate the credentials that transport carried.

Outbound attachments could ignore requester read denials openclaw/openclaw

Outbound attachments could be sent despite a read denial from the requester. The fix matters most where you rely on read permissions to gate what leaves an agent session.

openclaw 2026.9.7 openclaw/openclaw

by github-actions[bot]

Updates now back up every state and agent database before migrations, restore them on rollback, and take consistent snapshots while the Gateway keeps writing. The update stops before schema changes if snapshot cleanup fails, so a failed run leaves the old schema intact rather than half-migrated.

openclaw 2026.9.4 openclaw/openclaw

by github-actions[bot]

The release retains the previous package and restores it with the previous configuration and service when schema and configuration checks prove rollback is safe. Database migrations are the exception: they still require a verified pre-update backup, so budget for that in automation that upgrades unattended.

openclaw 2026.9.3 openclaw/openclaw

by github-actions[bot]

Core and plugin changes are now rehearsed in isolated candidate state before activation, eligible 2026.9.2 migrations are supported, and abandoned update records recover without stopping a healthy matching Gateway. It is the release that makes the later rollback work reachable in practice.

fs-safe 0.21.1 openclaw/fs-safe

by github-actions[bot]

On Linux without openat2, native opens now follow in-root relative symlinks exactly as RESOLVE_BENEATH does, rejecting absolute links, `..` escapes, procfs and nosymfollow links, and chains longer than 40. Denial and symlink policies report the same errors as the openat2 path, so behavior no longer diverges by kernel.

acpx 0.18.0 openclaw/acpx

by steipete

Sessions can change modes, models, and configuration through the shared runtime and inspect capabilities without shelling out to the CLI, and final output, usage, and accepted settings survive cancellation, timeouts, and reconnects. Callers wrapping acpx get a stable result across those paths instead of reconstructing state themselves.

$ ls openclaw/month/ # the briefings behind this review

Tue Sep 1 ocm upgrade simulations survive cleanup failures, legacy config migration unblocked Wed Sep 2 Managed Gateway upgrades survive shutdown, QA uploads reject cleanly Thu Sep 3 Cross-agent session access is now the default in OpenClaw Fri Sep 4 OpenClaw and OCM harden upgrades: atomic commits, macOS signing, deduplicated doc builds Sat Sep 5 Gateway fixes bind cancellations to exact live runs; hot reload keeps webhook retries Sun Sep 6 Catalog refreshes stop hiding failures; APFS checkpoints survive live logs Mon Sep 7 Gesture update rollback guard fixed; Slack slackens redundant work Tue Sep 8 Selective evidence collection and truthful reviewer prompts land in ClawSweeper Wed Sep 9 openclaw 2026.9.3 rehearses updates; discrawl guards publication compatibility Thu Sep 10 Codex history replay fixed, Moonshot China auth loops stopped Fri Sep 11 OpenClaw 2026.9.4 ships rollback recovery as Slack, OpenAI transport, and attachment auth bugs land Sat Sep 12 Codex route migration keeps subscription billing, cron script paths stop silently landing on neighbors Sun Sep 13 Crabbox collapses 2,771 lines of provider forwarding, Gateway task cleanup fixed Mon Sep 14 Faster settings startup, deferred plugin scope fix Tue Sep 15 Clawrouter withdraws OpenAI subscription onboarding, Fusion fixes leaked adviser accounting Wed Sep 16 fs-safe tightens identity checks, TAR reads get buffered Thu Sep 17 Matrix encryption recovery, faster session writes, stalled dashboard polls Fri Sep 18 fs-safe 0.14.0 ships safer guest listings, Code Mode stops dropping tool calls Sat Sep 19 Home-linked chat headers regain Pin session and Move to group Sun Sep 20 Cold-start Gateway diagnostics stop crying wolf, doctor repairs plugin drift Mon Sep 21 acpx 0.18.0 ships shared-session controls and permission hardening Tue Sep 22 Clawsweeper isolates Git overrides, OpenClaw hardens restart recovery Wed Sep 23 Astra becomes the default reviewer, ClawRouter learns to price service tiers Thu Sep 24 History eviction recovers, i18n stops retranslating Fri Sep 25 fs-safe 0.19.0 hardens atomic secret writes, nightly release validation lands Sat Sep 26 Telegram delivery after bot swaps, async ocm upgrades, docs go full width Sun Sep 27 fs-safe watcher survives sustained churn, Rust hub replaces Node workers Mon Sep 28 fs-safe 0.21.1 hardens Linux symlink resolution and denies case-insensitive bypasses Tue Sep 29 SQLite WAL checkpointing moves off the commit path Wed Sep 30 openclaw 2026.9.7 hardens update rollback, and Peekaboo ships GPT-6.1 Sol

Keep up with OpenClaw in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

all openclaw reviews →