$ cat openclaw/week/2026-09-21.log
the week in review · Sep 21 – Sep 27, 2026
acpx 0.18.0 breaks config and permission behavior
By RepoJournal · composed from the cited sources · human-reviewed weekly · methodology
Three acpx fixes land alongside the release, and fs-safe 0.19.0 adds strict secret-file durability.
acpx 0.18.0 openclaw/acpx
Shared-session controls let you change modes, models, and configuration through the shared runtime and inspect capabilities without shelling out to the CLI; sessions now preserve final output, usage, and accepted settings across cancellation, timeouts, and reconnects. This is the breaking item of the period, so pin and test before upgrading.
fix: serialize interactive permission questions openclaw/acpx
Concurrent permission requests opened separate readline interfaces over the same stdin, so a single y approved multiple pending requests at once. Tool, file-write, and terminal questions now serialize through the shared prompt helper, keeping each question's header and details with its input.
fix: align bootstrap config selection and error output openclaw/acpx
Repeating top-level --cwd loaded config from the first directory while Commander executed in the last, so an approve-all first project could authorize writes inside a final deny-all project. Repeated --mcp-config had the same first-value mismatch, and configuration errors now go to the right output.
fs-safe 0.19.0 openclaw/fs-safe
by github-actions[bot]
createSecretFileAtomic() takes durable: "file" to require every file flush to succeed, including on EPERM, with parent-directory synchronization still best effort. Literal ~ file names are also handled correctly, which matters if any secret path is built from user-supplied text.
fix: preserve explicit agent names across registry and config openclaw/acpx
Agent names colliding with JavaScript prototype properties broke resolution: constructor could return the inherited Object function, and JSON __proto__ entries vanished during normalization. Registry entries are now treated as explicit own properties, which fixes CLI and embedding lookups for those names.
fix: isolate model subprocesses from inherited Git overrides (#1645) openclaw/clawsweeper
Model subprocesses no longer inherit indexed or parameter Git configuration, stripped via the existing denylist loops, while explicit command-line config and scoped settings are preserved. If your models run in a repo with inherited Git overrides, their environment changes with this fix.
fix(recovery): preserve restart-safe tool ownership openclaw/openclaw
An older run could clear a newer recovery owner's restart-safe tool restriction, and a related terminal-result race captured restart-status text as the interrupted turn's final answer. Both paths now preserve restart-safe tool ownership, so interrupted runs stop misreporting their outcome.
feat(proxy): add accounted Responses WebSocket sessions openclaw/clawrouter
Responses WebSocket upgrades get one Worker session owner covering routing, queue limits, grant pinning, per-create authorization, retention, and accounting. Each create receives a distinct usage ID and settles once through the same accounting owner as HTTP, with no request replay or grant rotation after upgrade.
$ ls openclaw/week/ # the briefings behind this review
Keep up with OpenClaw in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.
fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.
Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.