惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
S
Securelist
V
Vulnerabilities – Threatpost
C
Cyber Attacks, Cyber Crime and Cyber Security
Schneier on Security
Schneier on Security
Cyberwarzone
Cyberwarzone
Simon Willison's Weblog
Simon Willison's Weblog
Hacker News - Newest:
Hacker News - Newest: "LLM"
P
Palo Alto Networks Blog
T
Troy Hunt's Blog
SecWiki News
SecWiki News
Security Archives - TechRepublic
Security Archives - TechRepublic
T
The Blog of Author Tim Ferriss
Project Zero
Project Zero
Microsoft Security Blog
Microsoft Security Blog
The Register - Security
The Register - Security
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
J
Java Code Geeks
F
Full Disclosure
阮一峰的网络日志
阮一峰的网络日志
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Attack and Defense Labs
Attack and Defense Labs
Know Your Adversary
Know Your Adversary
WordPress大学
WordPress大学
PCI Perspectives
PCI Perspectives
N
News | PayPal Newsroom
The Last Watchdog
The Last Watchdog
酷 壳 – CoolShell
酷 壳 – CoolShell
P
Privacy & Cybersecurity Law Blog
P
Proofpoint News Feed
V
Visual Studio Blog
C
CERT Recently Published Vulnerability Notes
H
Help Net Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
云风的 BLOG
云风的 BLOG
月光博客
月光博客
T
The Exploit Database - CXSecurity.com
I
InfoQ
大猫的无限游戏
大猫的无限游戏
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
U
Unit 42
腾讯CDC
小众软件
小众软件
V2EX - 技术
V2EX - 技术
罗磊的独立博客
Cloudbric
Cloudbric
Recorded Future
Recorded Future
IT之家
IT之家
Google DeepMind News
Google DeepMind News
C
CXSECURITY Database RSS Feed - CXSecurity.com

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4 test: trim doctor command hotspots · openclaw/openclaw@c66f16a test: isolate agent auth and spawn hotspots · openclaw/openclaw@9285935 test: stabilize MCP startup disposal race · openclaw/openclaw@dd9d2eb test: merge browser contract server suites · openclaw/openclaw@5817a76 test: narrow ollama provider discovery setup · openclaw/openclaw@a0d9598 build: declare qa-lab aimock runtime dependency · openclaw/openclaw@24431e5 test: speed up safe-bins exec harness · openclaw/openclaw@ee856ab test: preserve tool helpers in embedded runner mocks · openclaw/openclaw@acd86a0 refactor: move memory embeddings into provider plugins · openclaw/openclaw@77e6e4c test: reuse system-run temp fixtures · openclaw/openclaw@7e9ff0f test: trim hotspot wait overhead · openclaw/openclaw@12a59b0 Check: avoid duplicate boundary prep · openclaw/openclaw@baf11b8 test: reduce hotspot fixture overhead · openclaw/openclaw@3a59edd feat(ui): overhaul settings and slash command UX (#67819) thanks @Bun… · openclaw/openclaw@2cfb660 QA Matrix: exit cleanly on failure · openclaw/openclaw@42805d2 QA Matrix: isolate scenario coverage · openclaw/openclaw@7e659e1 Matrix: refresh crypto bootstrap state · openclaw/openclaw@94081d8 QA Lab: add provider registry · openclaw/openclaw@bb7e982 Matrix: add plugin changelog · openclaw/openclaw@4acab55 test: trim more hotspot overhead · openclaw/openclaw@f485311 test: trim remaining hotspot tests · openclaw/openclaw@6ba8626 test: narrow hotspot mocks · openclaw/openclaw@dbc8179 test: isolate gemini embedding request helpers · openclaw/openclaw@cd330f5 test: trim memory and mcp hotspots · openclaw/openclaw@fd48dfa test: slim provider registry mocks · openclaw/openclaw@2e08c77 test: harden Parallels update smoke · openclaw/openclaw@1a98090 feat: default Anthropic to Opus 4.7 · openclaw/openclaw@628b454 fix: harden node-host shell payload mutability checks · openclaw/openclaw@75c551e fix: land node-host approval binding for native binaries (#66731) (th… · openclaw/openclaw@29919bb CI: add daily schedule to CodeQL workflow (#67645) · openclaw/openclaw@69d25f5 fix(gateway): capture config hash after plugin auto-enable to prevent… · openclaw/openclaw@8c11210 fix: repair sanitized replay tool results before send (#67620) (thank… · openclaw/openclaw@c3c7a99 fix: restrict HTML timeout short-circuit to transient statuses · openclaw/openclaw@de129a6 fix: keep TUI watchdog bound to active run (#67401) (thanks @xantorres) · openclaw/openclaw@3525273 Gateway/skills: dedupe skills prefix-match + drop dead fallback on log · openclaw/openclaw@d7f489f Extensions/lmstudio: back off inference preload after consecutive fai… · openclaw/openclaw@b555214 TUI/streaming: add watchdog that resets the activity indicator after … · openclaw/openclaw@f44ab20 Agents/tool-loop: enable unknown-tool stream guard by default · openclaw/openclaw@36ed367 Gateway/skills: invalidate session skills snapshot on config write · openclaw/openclaw@b23d59a fix: classify HTML provider error pages correctly (#67642) (thanks @s… · openclaw/openclaw@e588e90 fix(skills): remove unused model-usage import (#67641) · openclaw/openclaw@55f05df docs(changelog): credit codex fix superseded PRs · openclaw/openclaw@e485f24 fix(openai-codex): normalize stale transport metadata in resolution a… · openclaw/openclaw@90801ba CI: pin Docker-related GitHub Actions (#67632) · openclaw/openclaw@f697b01 Android: modernize WebView and discovery API usage (#67627) · openclaw/openclaw@44a6e50 fix(deps): bump hono to 4.12.14 and @hono/node-server to 1.19.14 (GHS… · openclaw/openclaw@fbccc18 fix(deps): bump dompurify to 3.4.0 (#67614) · openclaw/openclaw@2c2dc00 CI: add explicit permissions to all workflow jobs (fixes code-scannin… · openclaw/openclaw@01b7516 fix: register bundled TTS providers and route overrides correctly (#6… · openclaw/openclaw@6ea3cdd fix: align host tilde paths with OS home (#62804) (thanks @stainlu) · openclaw/openclaw@ecfaf64 fix: flush creds queue before reconnect socket open (#67464) (thanks … · openclaw/openclaw@405c63f fix: strip standalone <function> tool call tags from visible text (#6… · openclaw/openclaw@78df859 fix(agents): preserve cli session metadata before transcript persist … · openclaw/openclaw@898fd04 docs(changelog): move cli transcript entry · openclaw/openclaw@c1817c6 fix(agents): normalize cli transcript api field · openclaw/openclaw@3a3fae0 docs(changelog): note cli transcript persistence · openclaw/openclaw@6c343f1 fix(agents): persist cli transcript turns · openclaw/openclaw@b8ef507 fix(msteams): harden security-sensitive flows (#65841) · openclaw/openclaw@c56b56e [Dashboard] Fix exec approval modal overflow for long command content… · openclaw/openclaw@053c5b0 Docs: remove QA changelog entry · openclaw/openclaw@7fd5771 QA: fix private runtime source loading (#67428) · openclaw/openclaw@d5933af docs(gateway): correct protocol.md schema path, hello-ok example, aut… · openclaw/openclaw@489404d CI: pin Node 22 runners to 22.18.0 · openclaw/openclaw@4ffa621 models.authStatus: normalize provider ids + tighten env-backed escape… · openclaw/openclaw@f2fdb9d Update CHANGELOG.md · openclaw/openclaw@7694a92 test(parallels): clean up npm update guard jobs · openclaw/openclaw@045ea7b Plugins: prefer scanDir override paths · openclaw/openclaw@b2974da fix(dreaming): default storage.mode to "separate" so phase blocks sto… · openclaw/openclaw@8c392f0 fix(memory-core): skip dreaming transcript ingestion via session stor… · openclaw/openclaw@a1b01f0 fix: dedupe replayed exec.finished node events (#67281) · openclaw/openclaw@5dcf526
fix(security): kill timed out exec process trees · openclaw/openclaw@39dc92e
vincentkoc · 2026-06-18 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -0,0 +1,17 @@

1+

import type { ChildProcess } from "node:child_process";

2+

import { signalProcessTree } from "./kill-tree.js";

3+
4+

export function shouldDetachChildForProcessTree(): boolean {

5+

return process.platform !== "win32";

6+

}

7+
8+

export function forceKillChildProcessTree(child: Pick<ChildProcess, "kill" | "pid">): void {

9+

if (typeof child.pid === "number" && child.pid > 0) {

10+

signalProcessTree(child.pid, "SIGKILL", {

11+

detached: shouldDetachChildForProcessTree(),

12+

});

13+

return;

14+

}

15+
16+

child.kill("SIGKILL");

17+

}

Original file line numberDiff line numberDiff line change

@@ -5,6 +5,12 @@ import path from "node:path";

55

import { afterAll, beforeAll, describe, expect, it, vi } from "vitest";

66

import type { OpenClawConfig } from "../config/config.js";

77

import { MAX_TIMER_TIMEOUT_MS } from "../shared/number-coercion.js";

8+

import {

9+

killPidIfAlive,

10+

readPidFile,

11+

waitForPidToExit,

12+

writeForkingNoOutputScript,

13+

} from "../test-utils/process-tree.js";

814

import { INVALID_EXEC_SECRET_REF_IDS } from "../test-utils/secret-ref-test-vectors.js";

915

import { withMockedWindowsPlatform } from "../test-utils/vitest-spies.js";

1016

import {

@@ -55,6 +61,7 @@ describe("secret ref resolver", () => {

5561

jsonOnly?: boolean;

5662

allowSymlinkCommand?: boolean;

5763

trustedDirs?: string[];

64+

env?: Record<string, string>;

5865

args?: string[];

5966

timeoutMs?: number;

6067

noOutputTimeoutMs?: number;

@@ -255,6 +262,28 @@ describe("secret ref resolver", () => {

255262

expect(value).toBe("ok");

256263

});

257264
265+

itPosix("kills forked exec provider children on no-output timeout", async () => {

266+

const root = await createCaseDir("exec-fork-timeout");

267+

const scriptPath = await writeForkingNoOutputScript(root);

268+

const pidPath = path.join(root, "forked.pid");

269+

let childPid: number | undefined;

270+
271+

try {

272+

await expect(

273+

resolveExecSecret(scriptPath, {

274+

env: { NODE_BINARY: process.execPath, PID_FILE: pidPath },

275+

noOutputTimeoutMs: 150,

276+

timeoutMs: 2000,

277+

}),

278+

).rejects.toThrow('Exec provider "execmain" produced no output');

279+
280+

childPid = await readPidFile(pidPath);

281+

expect(await waitForPidToExit(childPid)).toBe(true);

282+

} finally {

283+

killPidIfAlive(childPid);

284+

}

285+

});

286+
258287

itPosix("supports non-JSON single-value exec output when jsonOnly is false", async () => {

259288

const value = await resolveExecSecret(execPlainScriptPath, { jsonOnly: false });

260289

expect(value).toBe("plain-secret");

Original file line numberDiff line numberDiff line change

@@ -18,6 +18,10 @@ import {

1818

loadPluginManifestRegistry,

1919

type PluginManifestRegistry,

2020

} from "../plugins/manifest-registry.js";

21+

import {

22+

forceKillChildProcessTree,

23+

shouldDetachChildForProcessTree,

24+

} from "../process/child-process-tree.js";

2125

import { inspectPathPermissions, safeStat } from "../security/audit-fs.js";

2226

import { isPathInside } from "../security/scan-paths.js";

2327

import { resolveUserPath } from "../utils.js";

@@ -497,6 +501,7 @@ async function runExecResolver(params: {

497501

stdio: ["pipe", "pipe", "pipe"],

498502

shell: false,

499503

windowsHide: true,

504+

detached: shouldDetachChildForProcessTree(),

500505

});

501506
502507

let settled = false;

@@ -508,7 +513,7 @@ async function runExecResolver(params: {

508513

let noOutputTimer: NodeJS.Timeout | null = null;

509514

const timeoutTimer = setTimeout(() => {

510515

timedOut = true;

511-

child.kill("SIGKILL");

516+

forceKillChildProcessTree(child);

512517

}, params.timeoutMs);

513518
514519

const clearTimers = () => {

@@ -525,15 +530,15 @@ async function runExecResolver(params: {

525530

}

526531

noOutputTimer = setTimeout(() => {

527532

noOutputTimedOut = true;

528-

child.kill("SIGKILL");

533+

forceKillChildProcessTree(child);

529534

}, params.noOutputTimeoutMs);

530535

};

531536
532537

const append = (chunk: Buffer | string, target: "stdout" | "stderr") => {

533538

const text = typeof chunk === "string" ? chunk : chunk.toString("utf8");

534539

outputBytes += Buffer.byteLength(text, "utf8");

535540

if (outputBytes > params.maxOutputBytes) {

536-

child.kill("SIGKILL");

541+

forceKillChildProcessTree(child);

537542

if (!settled) {

538543

settled = true;

539544

clearTimers();

Original file line numberDiff line numberDiff line change

@@ -4,6 +4,12 @@ import os from "node:os";

44

import path from "node:path";

55

import { afterEach, beforeEach, describe, expect, it } from "vitest";

66

import type { OpenClawConfig } from "../config/types.openclaw.js";

7+

import {

8+

killPidIfAlive,

9+

readPidFile,

10+

waitForPidToExit,

11+

writeForkingNoOutputScript,

12+

} from "../test-utils/process-tree.js";

713

import {

814

runInstallPolicy,

915

validateInstallPolicyStatic,

@@ -211,6 +217,42 @@ describe("runInstallPolicy", () => {

211217

expect(result).toEqual({});

212218

});

213219
220+

it.runIf(process.platform !== "win32")(

221+

"kills forked policy command children on no-output timeout",

222+

async () => {

223+

const forkScriptPath = await writeForkingNoOutputScript(sourceDir);

224+

const pidPath = path.join(sourceDir, "forked.pid");

225+

let childPid: number | undefined;

226+
227+

try {

228+

const result = await runInstallPolicy({

229+

config: {

230+

security: {

231+

installPolicy: {

232+

enabled: true,

233+

exec: {

234+

source: "exec",

235+

command: forkScriptPath,

236+

env: { NODE_BINARY: process.execPath, PID_FILE: pidPath },

237+

allowInsecurePath: true,

238+

noOutputTimeoutMs: 150,

239+

timeoutMs: 2000,

240+

},

241+

},

242+

},

243+

},

244+

request: baseRequest(sourceDir),

245+

});

246+
247+

expect(result?.blocked?.reason).toContain("policy command produced no output");

248+

childPid = await readPidFile(pidPath);

249+

expect(await waitForPidToExit(childPid)).toBe(true);

250+

} finally {

251+

killPidIfAlive(childPid);

252+

}

253+

},

254+

);

255+
214256

it("does not inherit PATH unless passEnv includes it", async () => {

215257

const envPath = path.join(sourceDir, "env.json");

216258

const response = JSON.stringify({ protocolVersion: 1, decision: "allow" });

Original file line numberDiff line numberDiff line change

@@ -4,6 +4,10 @@ import fs from "node:fs/promises";

44

import path from "node:path";

55

import type { OpenClawConfig, SecurityConfig } from "../config/types.openclaw.js";

66

import { formatErrorMessage } from "../infra/errors.js";

7+

import {

8+

forceKillChildProcessTree,

9+

shouldDetachChildForProcessTree,

10+

} from "../process/child-process-tree.js";

711

import { normalizePositiveInt, normalizePositiveTimerMs } from "../secrets/shared.js";

812

import { resolveUserPath } from "../utils.js";

913

import { resolveRuntimeServiceVersion } from "../version.js";

@@ -534,6 +538,7 @@ async function runPolicyCommand(params: {

534538

stdio: ["pipe", "pipe", "pipe"],

535539

shell: false,

536540

windowsHide: true,

541+

detached: shouldDetachChildForProcessTree(),

537542

});

538543
539544

let settled = false;

@@ -545,7 +550,7 @@ async function runPolicyCommand(params: {

545550

let noOutputTimer: NodeJS.Timeout | null = null;

546551

const timeoutTimer = setTimeout(() => {

547552

timedOut = true;

548-

child.kill("SIGKILL");

553+

forceKillChildProcessTree(child);

549554

}, params.timeoutMs);

550555
551556

const clearTimers = () => {

@@ -562,15 +567,15 @@ async function runPolicyCommand(params: {

562567

}

563568

noOutputTimer = setTimeout(() => {

564569

noOutputTimedOut = true;

565-

child.kill("SIGKILL");

570+

forceKillChildProcessTree(child);

566571

}, params.noOutputTimeoutMs);

567572

};

568573
569574

const append = (chunk: Buffer | string, target: "stdout" | "stderr") => {

570575

const text = typeof chunk === "string" ? chunk : chunk.toString("utf8");

571576

outputBytes += Buffer.byteLength(text, "utf8");

572577

if (outputBytes > params.maxOutputBytes) {

573-

child.kill("SIGKILL");

578+

forceKillChildProcessTree(child);

574579

if (!settled) {

575580

settled = true;

576581

clearTimers();

Original file line numberDiff line numberDiff line change

@@ -0,0 +1,51 @@

1+

import fs from "node:fs/promises";

2+

import path from "node:path";

3+
4+

export async function writeForkingNoOutputScript(dir: string): Promise<string> {

5+

const scriptPath = path.join(dir, "fork-no-output.sh");

6+

await fs.writeFile(

7+

scriptPath,

8+

[

9+

"#!/bin/sh",

10+

'"$NODE_BINARY" -e "setInterval(() => {}, 1000)" &',

11+

'printf "%s" "$!" > "$PID_FILE"',

12+

"sleep 30",

13+

].join("\n"),

14+

"utf8",

15+

);

16+

await fs.chmod(scriptPath, 0o700);

17+

return scriptPath;

18+

}

19+
20+

export function isPidAlive(pid: number): boolean {

21+

try {

22+

process.kill(pid, 0);

23+

return true;

24+

} catch {

25+

return false;

26+

}

27+

}

28+
29+

export async function waitForPidToExit(pid: number, timeoutMs = 2000): Promise<boolean> {

30+

const deadline = Date.now() + timeoutMs;

31+

while (Date.now() < deadline) {

32+

if (!isPidAlive(pid)) {

33+

return true;

34+

}

35+

await new Promise<void>((resolve) => {

36+

setTimeout(resolve, 25);

37+

});

38+

}

39+

return !isPidAlive(pid);

40+

}

41+
42+

export async function readPidFile(pidPath: string): Promise<number> {

43+

return Number((await fs.readFile(pidPath, "utf8")).trim());

44+

}

45+
46+

export function killPidIfAlive(pid: number | undefined): void {

47+

if (pid === undefined || !isPidAlive(pid)) {

48+

return;

49+

}

50+

process.kill(pid, "SIGKILL");

51+

}