惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
T
The Exploit Database - CXSecurity.com
V
Vulnerabilities – Threatpost
Know Your Adversary
Know Your Adversary
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
N
News and Events Feed by Topic
Spread Privacy
Spread Privacy
Application and Cybersecurity Blog
Application and Cybersecurity Blog
S
Secure Thoughts
G
GRAHAM CLULEY
Google Online Security Blog
Google Online Security Blog
Help Net Security
Help Net Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
O
OpenAI News
Google DeepMind News
Google DeepMind News
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Security Archives - TechRepublic
Security Archives - TechRepublic
L
LINUX DO - 最新话题
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Stack Overflow Blog
Stack Overflow Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
Lohrmann on Cybersecurity
H
Hacker News: Front Page
W
WeLiveSecurity
P
Privacy International News Feed
Forbes - Security
Forbes - Security
月光博客
月光博客
PCI Perspectives
PCI Perspectives
T
Tailwind CSS Blog
N
News and Events Feed by Topic
T
Threat Research - Cisco Blogs
Engineering at Meta
Engineering at Meta
F
Full Disclosure
AI
AI
Hacker News - Newest:
Hacker News - Newest: "LLM"
Schneier on Security
Schneier on Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
D
Darknet – Hacking Tools, Hacker News & Cyber Security
V
Visual Studio Blog
The Hacker News
The Hacker News
博客园 - 叶小钗
G
Google Developers Blog
Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
T
The Blog of Author Tim Ferriss

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4 test: trim doctor command hotspots · openclaw/openclaw@c66f16a test: isolate agent auth and spawn hotspots · openclaw/openclaw@9285935 test: stabilize MCP startup disposal race · openclaw/openclaw@dd9d2eb test: merge browser contract server suites · openclaw/openclaw@5817a76 test: narrow ollama provider discovery setup · openclaw/openclaw@a0d9598 build: declare qa-lab aimock runtime dependency · openclaw/openclaw@24431e5 test: speed up safe-bins exec harness · openclaw/openclaw@ee856ab test: preserve tool helpers in embedded runner mocks · openclaw/openclaw@acd86a0 refactor: move memory embeddings into provider plugins · openclaw/openclaw@77e6e4c test: reuse system-run temp fixtures · openclaw/openclaw@7e9ff0f test: trim hotspot wait overhead · openclaw/openclaw@12a59b0 Check: avoid duplicate boundary prep · openclaw/openclaw@baf11b8 test: reduce hotspot fixture overhead · openclaw/openclaw@3a59edd feat(ui): overhaul settings and slash command UX (#67819) thanks @Bun… · openclaw/openclaw@2cfb660 QA Matrix: exit cleanly on failure · openclaw/openclaw@42805d2 QA Matrix: isolate scenario coverage · openclaw/openclaw@7e659e1 Matrix: refresh crypto bootstrap state · openclaw/openclaw@94081d8 QA Lab: add provider registry · openclaw/openclaw@bb7e982 Matrix: add plugin changelog · openclaw/openclaw@4acab55 test: trim more hotspot overhead · openclaw/openclaw@f485311 test: trim remaining hotspot tests · openclaw/openclaw@6ba8626 test: narrow hotspot mocks · openclaw/openclaw@dbc8179 test: isolate gemini embedding request helpers · openclaw/openclaw@cd330f5 test: trim memory and mcp hotspots · openclaw/openclaw@fd48dfa test: slim provider registry mocks · openclaw/openclaw@2e08c77 test: harden Parallels update smoke · openclaw/openclaw@1a98090 feat: default Anthropic to Opus 4.7 · openclaw/openclaw@628b454 fix: harden node-host shell payload mutability checks · openclaw/openclaw@75c551e fix: land node-host approval binding for native binaries (#66731) (th… · openclaw/openclaw@29919bb CI: add daily schedule to CodeQL workflow (#67645) · openclaw/openclaw@69d25f5 fix(gateway): capture config hash after plugin auto-enable to prevent… · openclaw/openclaw@8c11210 fix: repair sanitized replay tool results before send (#67620) (thank… · openclaw/openclaw@c3c7a99 fix: restrict HTML timeout short-circuit to transient statuses · openclaw/openclaw@de129a6 fix: keep TUI watchdog bound to active run (#67401) (thanks @xantorres) · openclaw/openclaw@3525273 Gateway/skills: dedupe skills prefix-match + drop dead fallback on log · openclaw/openclaw@d7f489f Extensions/lmstudio: back off inference preload after consecutive fai… · openclaw/openclaw@b555214 TUI/streaming: add watchdog that resets the activity indicator after … · openclaw/openclaw@f44ab20 Agents/tool-loop: enable unknown-tool stream guard by default · openclaw/openclaw@36ed367 Gateway/skills: invalidate session skills snapshot on config write · openclaw/openclaw@b23d59a fix: classify HTML provider error pages correctly (#67642) (thanks @s… · openclaw/openclaw@e588e90 fix(skills): remove unused model-usage import (#67641) · openclaw/openclaw@55f05df docs(changelog): credit codex fix superseded PRs · openclaw/openclaw@e485f24 fix(openai-codex): normalize stale transport metadata in resolution a… · openclaw/openclaw@90801ba CI: pin Docker-related GitHub Actions (#67632) · openclaw/openclaw@f697b01 Android: modernize WebView and discovery API usage (#67627) · openclaw/openclaw@44a6e50 fix(deps): bump hono to 4.12.14 and @hono/node-server to 1.19.14 (GHS… · openclaw/openclaw@fbccc18 fix(deps): bump dompurify to 3.4.0 (#67614) · openclaw/openclaw@2c2dc00 CI: add explicit permissions to all workflow jobs (fixes code-scannin… · openclaw/openclaw@01b7516 fix: register bundled TTS providers and route overrides correctly (#6… · openclaw/openclaw@6ea3cdd fix: align host tilde paths with OS home (#62804) (thanks @stainlu) · openclaw/openclaw@ecfaf64 fix: flush creds queue before reconnect socket open (#67464) (thanks … · openclaw/openclaw@405c63f fix: strip standalone <function> tool call tags from visible text (#6… · openclaw/openclaw@78df859 fix(agents): preserve cli session metadata before transcript persist … · openclaw/openclaw@898fd04 docs(changelog): move cli transcript entry · openclaw/openclaw@c1817c6 fix(agents): normalize cli transcript api field · openclaw/openclaw@3a3fae0 docs(changelog): note cli transcript persistence · openclaw/openclaw@6c343f1 fix(agents): persist cli transcript turns · openclaw/openclaw@b8ef507 fix(msteams): harden security-sensitive flows (#65841) · openclaw/openclaw@c56b56e [Dashboard] Fix exec approval modal overflow for long command content… · openclaw/openclaw@053c5b0 Docs: remove QA changelog entry · openclaw/openclaw@7fd5771 QA: fix private runtime source loading (#67428) · openclaw/openclaw@d5933af docs(gateway): correct protocol.md schema path, hello-ok example, aut… · openclaw/openclaw@489404d CI: pin Node 22 runners to 22.18.0 · openclaw/openclaw@4ffa621 models.authStatus: normalize provider ids + tighten env-backed escape… · openclaw/openclaw@f2fdb9d Update CHANGELOG.md · openclaw/openclaw@7694a92 test(parallels): clean up npm update guard jobs · openclaw/openclaw@045ea7b Plugins: prefer scanDir override paths · openclaw/openclaw@b2974da fix(dreaming): default storage.mode to "separate" so phase blocks sto… · openclaw/openclaw@8c392f0 fix(memory-core): skip dreaming transcript ingestion via session stor… · openclaw/openclaw@a1b01f0 fix: dedupe replayed exec.finished node events (#67281) · openclaw/openclaw@5dcf526
fix: harden clawpatch-reported edge cases · openclaw/openclaw@48f7db2
steipete · 2026-05-18 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -29,6 +29,7 @@ Docs: https://docs.openclaw.ai

2929
3030

### Fixes

3131
32+

- Core/plugins: harden clawpatch-reported edge cases across gateway auth cleanup, Claude session id paths, plugin activation policy, apply-patch hunk handling, diagnostic redaction, and plugin metadata validation.

3233

- Mac app: keep app-level menu commands and Dashboard failure states reachable when the remote Gateway is disconnected, and keep the Settings sidebar toggle in the leading titlebar area.

3334

- Gateway/webchat: hide internal runtime-context and other `display: false` transcript messages from Chat history and live message events. Fixes #83216. Thanks @EmpireCreator.

3435

- CLI/help: keep `gateway`, `doctor`, `status`, and `health` help registration out of action/runtime imports so subcommand `--help` stays lightweight in constrained terminals. Fixes #83228. Thanks @dfguerrerom.

Original file line numberDiff line numberDiff line change

@@ -206,9 +206,15 @@ function collectReferenceEvents(

206206

if (!clause?.namedBindings) {

207207

continue;

208208

}

209+

if (clause.isTypeOnly) {

210+

continue;

211+

}

209212
210213

if (ts.isNamedImports(clause.namedBindings)) {

211214

for (const element of clause.namedBindings.elements) {

215+

if (element.isTypeOnly) {

216+

continue;

217+

}

212218

const importedName = element.propertyName?.text ?? element.name.text;

213219

const record = recordMap.get(importedName);

214220

if (!record) {

Original file line numberDiff line numberDiff line change

@@ -110,5 +110,9 @@ const reportModules: Record<ReportModule["name"], ReportModule> = {

110110

};

111111
112112

export function renderTextReport(envelope: TopologyEnvelope, limit: number): string {

113-

return reportModules[envelope.report].describe(envelope, limit);

113+

const reportModule = reportModules[envelope.report];

114+

if (!reportModule) {

115+

throw new Error(`Unsupported topology report: ${envelope.report}`);

116+

}

117+

return reportModule.describe(envelope, limit);

114118

}

Original file line numberDiff line numberDiff line change

@@ -64,4 +64,34 @@ describe("createAnthropicPayloadLogger", () => {

6464

expect(source.sha256).toBe(crypto.createHash("sha256").update("QUJDRA==").digest("hex"));

6565

expect(event.payloadDigest).toMatch(/^[a-f0-9]{64}$/u);

6666

});

67+
68+

it("sanitizes usage and error fields before writing logs", () => {

69+

const lines: string[] = [];

70+

const logger = createAnthropicPayloadLogger({

71+

env: { OPENCLAW_ANTHROPIC_PAYLOAD_LOG: "1" },

72+

writer: {

73+

filePath: "memory",

74+

write: (line) => lines.push(line),

75+

flush: async () => undefined,

76+

},

77+

});

78+
79+

logger?.recordUsage(

80+

[

81+

{

82+

role: "assistant",

83+

content: "",

84+

usage: {

85+

input: 1,

86+

authorization: "Bearer sk-secret", // pragma: allowlist secret

87+

},

88+

} as never,

89+

],

90+

new Error("failed with Bearer sk-secret"), // pragma: allowlist secret

91+

);

92+
93+

const event = JSON.parse(lines[0]?.trim() ?? "{}") as Record<string, unknown>;

94+

expect(event.error).toBe("failed with Bearer <redacted>");

95+

expect(event.usage).toEqual({ input: 1 });

96+

});

6797

});

Original file line numberDiff line numberDiff line change

@@ -53,16 +53,18 @@ function getWriter(filePath: string): PayloadLogWriter {

5353
5454

function formatError(error: unknown): string | undefined {

5555

if (error instanceof Error) {

56-

return error.message;

56+

const redacted = sanitizeDiagnosticPayload(error.message);

57+

return typeof redacted === "string" ? redacted : error.message;

5758

}

5859

if (typeof error === "string") {

59-

return error;

60+

const redacted = sanitizeDiagnosticPayload(error);

61+

return typeof redacted === "string" ? redacted : error;

6062

}

6163

if (typeof error === "number" || typeof error === "boolean" || typeof error === "bigint") {

6264

return String(error);

6365

}

6466

if (error && typeof error === "object") {

65-

return safeJsonStringify(error) ?? "unknown error";

67+

return safeJsonStringify(sanitizeDiagnosticPayload(error)) ?? "unknown error";

6668

}

6769

return undefined;

6870

}

@@ -173,7 +175,7 @@ export function createAnthropicPayloadLogger(params: {

173175

...base,

174176

ts: new Date().toISOString(),

175177

stage: "usage",

176-

usage,

178+

usage: sanitizeDiagnosticPayload(usage) as Record<string, unknown>,

177179

error: errorMessage,

178180

});

179181

log.info("anthropic usage", {

Original file line numberDiff line numberDiff line change

@@ -53,10 +53,13 @@ function computeReplacements(

5353
5454

if (chunk.oldLines.length === 0) {

5555

const insertionIndex =

56-

originalLines.length > 0 && originalLines[originalLines.length - 1] === ""

57-

? originalLines.length - 1

58-

: originalLines.length;

56+

chunk.changeContext && !chunk.isEndOfFile

57+

? lineIndex

58+

: originalLines.length > 0 && originalLines[originalLines.length - 1] === ""

59+

? originalLines.length - 1

60+

: originalLines.length;

5961

replacements.push([insertionIndex, 0, chunk.newLines]);

62+

lineIndex = insertionIndex;

6063

continue;

6164

}

6265
Original file line numberDiff line numberDiff line change

@@ -131,6 +131,57 @@ describe("applyPatch", () => {

131131

expect(result.summary.modified).toEqual(["dest.txt"]);

132132

});

133133
134+

it("updates in place when move target resolves to the source file", async () => {

135+

const memory = createMemoryPatchSandbox({

136+

"source.txt": "foo\nbar\n",

137+

});

138+

const patch = `*** Begin Patch

139+

*** Update File: source.txt

140+

*** Move to: ./source.txt

141+

@@

142+

foo

143+

-bar

144+

+baz

145+

*** End Patch`;

146+
147+

const result = await applyPatch(patch, memory.options);

148+
149+

expect(memory.files.get("/sandbox/source.txt")).toBe("foo\nbaz\n");

150+

expect(result.summary.modified).toEqual(["source.txt"]);

151+

});

152+
153+

it("applies context-only insertions at the requested context", async () => {

154+

const memory = createMemoryPatchSandbox({

155+

"source.txt": "alpha\nanchor\nomega\n",

156+

});

157+

const patch = `*** Begin Patch

158+

*** Update File: source.txt

159+

@@ anchor

160+

+inserted

161+

*** End Patch`;

162+
163+

await applyPatch(patch, memory.options);

164+
165+

expect(memory.files.get("/sandbox/source.txt")).toBe("alpha\nanchor\ninserted\nomega\n");

166+

});

167+
168+

it("keeps later insertion contexts in original file coordinates", async () => {

169+

const memory = createMemoryPatchSandbox({

170+

"source.txt": "a\nb\nc\n",

171+

});

172+

const patch = `*** Begin Patch

173+

*** Update File: source.txt

174+

@@ a

175+

+after-a

176+

@@ b

177+

+after-b

178+

*** End Patch`;

179+
180+

await applyPatch(patch, memory.options);

181+
182+

expect(memory.files.get("/sandbox/source.txt")).toBe("a\nafter-a\nb\nafter-b\nc\n");

183+

});

184+
134185

it("supports end-of-file inserts", async () => {

135186

const memory = createMemoryPatchSandbox({

136187

"end.txt": "line1\n",

Original file line numberDiff line numberDiff line change

@@ -175,9 +175,21 @@ export async function applyPatch(

175175

const moveTarget = await resolvePatchPath(hunk.movePath, options);

176176

await assertPatchParentPath(hunk.movePath, options);

177177

await ensureDir(moveTarget.resolved, fileOps);

178-

await fileOps.writeFile(moveTarget.resolved, applied);

179-

await fileOps.remove(target.resolved);

180-

recordSummary(summary, seen, "modified", moveTarget.display);

178+

const moveResolvesToSource =

179+

path.resolve(moveTarget.resolved) === path.resolve(target.resolved);

180+

await fileOps.writeFile(

181+

moveResolvesToSource ? target.resolved : moveTarget.resolved,

182+

applied,

183+

);

184+

if (!moveResolvesToSource) {

185+

await fileOps.remove(target.resolved);

186+

}

187+

recordSummary(

188+

summary,

189+

seen,

190+

"modified",

191+

moveResolvesToSource ? target.display : moveTarget.display,

192+

);

181193

} else {

182194

await fileOps.writeFile(target.resolved, applied);

183195

recordSummary(summary, seen, "modified", target.display);

Original file line numberDiff line numberDiff line change

@@ -172,12 +172,17 @@ const transport = new StdioClientTransport({

172172

});

173173

const client = new Client({ name: "fake-claude", version: "1.0.0" });

174174

await client.connect(transport);

175-

const tools = await client.listTools();

176-

if (!tools.tools.some((tool) => tool.name === "bundle_probe")) {

177-

throw new Error("bundle_probe tool not exposed");

178-

}

179-

const result = await client.callTool({ name: "bundle_probe", arguments: {} });

180-

await transport.close();

175+

const result = await (async () => {

176+

try {

177+

const tools = await client.listTools();

178+

if (!tools.tools.some((tool) => tool.name === "bundle_probe")) {

179+

throw new Error("bundle_probe tool not exposed");

180+

}

181+

return await client.callTool({ name: "bundle_probe", arguments: {} });

182+

} finally {

183+

await transport.close();

184+

}

185+

})();

181186
182187

const text = Array.isArray(result.content)

183188

? result.content

Original file line numberDiff line numberDiff line change

@@ -157,6 +157,18 @@ describe("channel-health-monitor", () => {

157157

vi.useRealTimers();

158158

});

159159
160+

it("removes abort listener when stopped manually", () => {

161+

const signal = new AbortController().signal;

162+

const addEventListener = vi.spyOn(signal, "addEventListener");

163+

const removeEventListener = vi.spyOn(signal, "removeEventListener");

164+

const monitor = startDefaultMonitor(createMockChannelManager(), { abortSignal: signal });

165+
166+

monitor.stop();

167+
168+

expect(addEventListener).toHaveBeenCalledWith("abort", expect.any(Function), { once: true });

169+

expect(removeEventListener).toHaveBeenCalledWith("abort", addEventListener.mock.calls[0]?.[1]);

170+

});

171+
160172

it("does not run before the grace period", async () => {

161173

const manager = createMockChannelManager();

162174

const monitor = startDefaultMonitor(manager, { startupGraceMs: 60_000 });