惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

O
OpenAI News
I
Intezer
C
CERT Recently Published Vulnerability Notes
V
Vulnerabilities – Threatpost
S
Securelist
C
Cyber Attacks, Cyber Crime and Cyber Security
G
GRAHAM CLULEY
P
Palo Alto Networks Blog
P
Privacy & Cybersecurity Law Blog
T
Tenable Blog
T
Threatpost
Latest news
Latest news
Cisco Talos Blog
Cisco Talos Blog
A
Arctic Wolf
罗磊的独立博客
云风的 BLOG
云风的 BLOG
L
LangChain Blog
博客园 - 【当耐特】
P
Privacy International News Feed
The GitHub Blog
The GitHub Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
www.infosecurity-magazine.com
www.infosecurity-magazine.com
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
T
Troy Hunt's Blog
量子位
Security Archives - TechRepublic
Security Archives - TechRepublic
爱范儿
爱范儿
S
Security @ Cisco Blogs
Martin Fowler
Martin Fowler
博客园_首页
SecWiki News
SecWiki News
Spread Privacy
Spread Privacy
I
InfoQ
博客园 - 司徒正美
T
Tor Project blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
H
Help Net Security
L
LINUX DO - 最新话题
H
Heimdal Security Blog
TaoSecurity Blog
TaoSecurity Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
Vercel News
Vercel News
Y
Y Combinator Blog
D
DataBreaches.Net
T
Threat Research - Cisco Blogs
Stack Overflow Blog
Stack Overflow Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
M
MIT News - Artificial intelligence
Recorded Future
Recorded Future
博客园 - 叶小钗

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4 test: trim doctor command hotspots · openclaw/openclaw@c66f16a test: isolate agent auth and spawn hotspots · openclaw/openclaw@9285935 test: stabilize MCP startup disposal race · openclaw/openclaw@dd9d2eb test: merge browser contract server suites · openclaw/openclaw@5817a76 test: narrow ollama provider discovery setup · openclaw/openclaw@a0d9598 build: declare qa-lab aimock runtime dependency · openclaw/openclaw@24431e5 test: speed up safe-bins exec harness · openclaw/openclaw@ee856ab test: preserve tool helpers in embedded runner mocks · openclaw/openclaw@acd86a0 refactor: move memory embeddings into provider plugins · openclaw/openclaw@77e6e4c test: reuse system-run temp fixtures · openclaw/openclaw@7e9ff0f test: trim hotspot wait overhead · openclaw/openclaw@12a59b0 Check: avoid duplicate boundary prep · openclaw/openclaw@baf11b8 test: reduce hotspot fixture overhead · openclaw/openclaw@3a59edd feat(ui): overhaul settings and slash command UX (#67819) thanks @Bun… · openclaw/openclaw@2cfb660 QA Matrix: exit cleanly on failure · openclaw/openclaw@42805d2 QA Matrix: isolate scenario coverage · openclaw/openclaw@7e659e1 Matrix: refresh crypto bootstrap state · openclaw/openclaw@94081d8 QA Lab: add provider registry · openclaw/openclaw@bb7e982 Matrix: add plugin changelog · openclaw/openclaw@4acab55 test: trim more hotspot overhead · openclaw/openclaw@f485311 test: trim remaining hotspot tests · openclaw/openclaw@6ba8626 test: narrow hotspot mocks · openclaw/openclaw@dbc8179 test: isolate gemini embedding request helpers · openclaw/openclaw@cd330f5 test: trim memory and mcp hotspots · openclaw/openclaw@fd48dfa test: slim provider registry mocks · openclaw/openclaw@2e08c77 test: harden Parallels update smoke · openclaw/openclaw@1a98090 feat: default Anthropic to Opus 4.7 · openclaw/openclaw@628b454 fix: harden node-host shell payload mutability checks · openclaw/openclaw@75c551e fix: land node-host approval binding for native binaries (#66731) (th… · openclaw/openclaw@29919bb CI: add daily schedule to CodeQL workflow (#67645) · openclaw/openclaw@69d25f5 fix(gateway): capture config hash after plugin auto-enable to prevent… · openclaw/openclaw@8c11210 fix: repair sanitized replay tool results before send (#67620) (thank… · openclaw/openclaw@c3c7a99 fix: restrict HTML timeout short-circuit to transient statuses · openclaw/openclaw@de129a6 fix: keep TUI watchdog bound to active run (#67401) (thanks @xantorres) · openclaw/openclaw@3525273 Gateway/skills: dedupe skills prefix-match + drop dead fallback on log · openclaw/openclaw@d7f489f Extensions/lmstudio: back off inference preload after consecutive fai… · openclaw/openclaw@b555214 TUI/streaming: add watchdog that resets the activity indicator after … · openclaw/openclaw@f44ab20 Agents/tool-loop: enable unknown-tool stream guard by default · openclaw/openclaw@36ed367 Gateway/skills: invalidate session skills snapshot on config write · openclaw/openclaw@b23d59a fix: classify HTML provider error pages correctly (#67642) (thanks @s… · openclaw/openclaw@e588e90 fix(skills): remove unused model-usage import (#67641) · openclaw/openclaw@55f05df docs(changelog): credit codex fix superseded PRs · openclaw/openclaw@e485f24 fix(openai-codex): normalize stale transport metadata in resolution a… · openclaw/openclaw@90801ba CI: pin Docker-related GitHub Actions (#67632) · openclaw/openclaw@f697b01 Android: modernize WebView and discovery API usage (#67627) · openclaw/openclaw@44a6e50 fix(deps): bump hono to 4.12.14 and @hono/node-server to 1.19.14 (GHS… · openclaw/openclaw@fbccc18 fix(deps): bump dompurify to 3.4.0 (#67614) · openclaw/openclaw@2c2dc00 CI: add explicit permissions to all workflow jobs (fixes code-scannin… · openclaw/openclaw@01b7516 fix: register bundled TTS providers and route overrides correctly (#6… · openclaw/openclaw@6ea3cdd fix: align host tilde paths with OS home (#62804) (thanks @stainlu) · openclaw/openclaw@ecfaf64 fix: flush creds queue before reconnect socket open (#67464) (thanks … · openclaw/openclaw@405c63f fix: strip standalone <function> tool call tags from visible text (#6… · openclaw/openclaw@78df859 fix(agents): preserve cli session metadata before transcript persist … · openclaw/openclaw@898fd04 docs(changelog): move cli transcript entry · openclaw/openclaw@c1817c6 fix(agents): normalize cli transcript api field · openclaw/openclaw@3a3fae0 docs(changelog): note cli transcript persistence · openclaw/openclaw@6c343f1 fix(agents): persist cli transcript turns · openclaw/openclaw@b8ef507 fix(msteams): harden security-sensitive flows (#65841) · openclaw/openclaw@c56b56e [Dashboard] Fix exec approval modal overflow for long command content… · openclaw/openclaw@053c5b0 Docs: remove QA changelog entry · openclaw/openclaw@7fd5771 QA: fix private runtime source loading (#67428) · openclaw/openclaw@d5933af docs(gateway): correct protocol.md schema path, hello-ok example, aut… · openclaw/openclaw@489404d CI: pin Node 22 runners to 22.18.0 · openclaw/openclaw@4ffa621 models.authStatus: normalize provider ids + tighten env-backed escape… · openclaw/openclaw@f2fdb9d Update CHANGELOG.md · openclaw/openclaw@7694a92 test(parallels): clean up npm update guard jobs · openclaw/openclaw@045ea7b Plugins: prefer scanDir override paths · openclaw/openclaw@b2974da fix(dreaming): default storage.mode to "separate" so phase blocks sto… · openclaw/openclaw@8c392f0 fix(memory-core): skip dreaming transcript ingestion via session stor… · openclaw/openclaw@a1b01f0 fix: dedupe replayed exec.finished node events (#67281) · openclaw/openclaw@5dcf526
fix(gateway): forward image-only input on /v1/responses (parity with … · openclaw/openclaw@b72634f
s554097550 · 2026-06-14 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -10,6 +10,12 @@ export type ConversationEntry = {

1010

internalStreamError?: boolean;

1111

};

1212
13+

// Placeholder user text for an image-only turn. The agent command requires a

14+

// non-empty message even when the real payload is the attached image, so both

15+

// the /v1/chat/completions and /v1/responses prompt builders substitute this

16+

// for the active user turn. Keep it shared so the two endpoints stay in sync.

17+

export const IMAGE_ONLY_USER_MESSAGE = "User sent image(s) with no text.";

18+
1319

/**

1420

* Coerce body to string. Handles cases where body is a content array

1521

* (e.g. [{type:"text", text:"hello"}]) that would serialize as

Original file line numberDiff line numberDiff line change

@@ -39,6 +39,7 @@ import { resolveAssistantStreamDeltaText } from "./agent-event-assistant-text.js

3939

import {

4040

buildAgentMessageFromConversationEntries,

4141

type ConversationEntry,

42+

IMAGE_ONLY_USER_MESSAGE,

4243

} from "./agent-prompt.js";

4344

import type { AuthRateLimiter } from "./auth-rate-limit.js";

4445

import type { ResolvedGatewayAuth } from "./auth.js";

@@ -105,7 +106,6 @@ type OpenAiChatCompletionRequest = {

105106

};

106107
107108

const DEFAULT_OPENAI_CHAT_COMPLETIONS_BODY_BYTES = 20 * 1024 * 1024;

108-

const IMAGE_ONLY_USER_MESSAGE = "User sent image(s) with no text.";

109109

const DEFAULT_OPENAI_MAX_IMAGE_PARTS = 8;

110110

const DEFAULT_OPENAI_MAX_TOTAL_IMAGE_BYTES = 20 * 1024 * 1024;

111111

const DEFAULT_OPENAI_IMAGE_LIMITS: InputImageLimits = {

Original file line numberDiff line numberDiff line change

@@ -10,6 +10,7 @@ import { HISTORY_CONTEXT_MARKER } from "../auto-reply/reply/history.js";

1010

import { CURRENT_MESSAGE_MARKER } from "../auto-reply/reply/mentions.js";

1111

import { resetConfigRuntimeState } from "../config/config.js";

1212

import { emitAgentEvent } from "../infra/agent-events.js";

13+

import { IMAGE_ONLY_USER_MESSAGE } from "./agent-prompt.js";

1314

import { buildAssistantDeltaResult } from "./test-helpers.agent-results.js";

1415

import {

1516

agentCommand,

@@ -1710,6 +1711,54 @@ describe("OpenResponses HTTP API (e2e)", () => {

17101711

expect(agentCommand).not.toHaveBeenCalled();

17111712

});

17121713
1714+

it("accepts image-only input without text, matching /v1/chat/completions", async () => {

1715+

const port = enabledPort;

1716+

// 1x1 PNG; same fixture used by the parity schema tests.

1717+

const pngBase64 =

1718+

"iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAYAAAAfFcSJAAAADUlEQVR42mNk+M9QDwADhgGAWjR9awAAAABJRU5ErkJggg==";

1719+
1720+

agentCommand.mockClear();

1721+

agentCommand.mockResolvedValueOnce({ payloads: [{ text: "ok" }] } as never);

1722+
1723+

const res = await postResponses(port, {

1724+

model: "openclaw",

1725+

input: [

1726+

{

1727+

type: "message",

1728+

role: "user",

1729+

content: [

1730+

{

1731+

type: "input_image",

1732+

source: { type: "base64", media_type: "image/png", data: pngBase64 },

1733+

},

1734+

],

1735+

},

1736+

],

1737+

});

1738+
1739+

expect(res.status).toBe(200);

1740+

expect(agentCommand).toHaveBeenCalledTimes(1);

1741+

const opts = firstAgentOpts();

1742+

// Image-only turn carries a non-empty placeholder so the agent command runs,

1743+

// with the real image attached via `images` (parity with /v1/chat/completions).

1744+

expect((opts as { message?: string }).message ?? "").toBe(IMAGE_ONLY_USER_MESSAGE);

1745+

expect((opts as { images?: unknown[] }).images?.length).toBe(1);

1746+

await ensureResponseConsumed(res);

1747+

});

1748+
1749+

it("still rejects input with neither text nor image", async () => {

1750+

const port = enabledPort;

1751+

agentCommand.mockClear();

1752+
1753+

const res = await postResponses(port, {

1754+

model: "openclaw",

1755+

input: [{ type: "message", role: "user", content: [] }],

1756+

});

1757+
1758+

await expectInvalidRequest(res, /Missing user message/i);

1759+

expect(agentCommand).not.toHaveBeenCalled();

1760+

});

1761+
17131762

it("enforces URL allowlist and URL part cap for responses inputs", async () => {

17141763

const allowlistConfig = buildResponsesUrlPolicyConfig(1);

17151764

await writeGatewayConfig(allowlistConfig);

Original file line numberDiff line numberDiff line change

@@ -6,6 +6,7 @@

66

*/

77
88

import { beforeAll, describe, it, expect } from "vitest";

9+

import { IMAGE_ONLY_USER_MESSAGE } from "./agent-prompt.js";

910

import { wrapUntrustedFileContent } from "./openresponses-file-content.js";

1011
1112

let InputImageContentPartSchema: typeof import("./open-responses.schema.js").InputImageContentPartSchema;

@@ -374,6 +375,31 @@ describe("OpenResponses Feature Parity", () => {

374375

expect(result.message).toContain("72°F");

375376

expect(result.message).toContain("Thanks");

376377

});

378+
379+

it("substitutes a placeholder for an image-only active user turn", () => {

380+

const result = buildAgentPrompt([

381+

{

382+

type: "message" as const,

383+

role: "user" as const,

384+

content: [

385+

{

386+

type: "input_image" as const,

387+

source: { type: "url" as const, url: "https://example.com/cat.png" },

388+

},

389+

],

390+

},

391+

]);

392+
393+

expect(result.message).toBe(IMAGE_ONLY_USER_MESSAGE);

394+

});

395+
396+

it("keeps an empty message when the active turn has neither text nor image", () => {

397+

const result = buildAgentPrompt([

398+

{ type: "message" as const, role: "user" as const, content: [] },

399+

]);

400+
401+

expect(result.message).toBe("");

402+

});

377403

});

378404
379405

describe("input_file hardening", () => {

Original file line numberDiff line numberDiff line change

@@ -2,6 +2,7 @@

22

import {

33

buildAgentMessageFromConversationEntries,

44

type ConversationEntry,

5+

IMAGE_ONLY_USER_MESSAGE,

56

} from "./agent-prompt.js";

67

import type { ContentPart, ItemParam } from "./open-responses.schema.js";

78

@@ -23,6 +24,21 @@ function extractTextContent(content: string | ContentPart[]): string {

2324

.join("\n");

2425

}

2526
27+

function hasImageContent(content: string | ContentPart[]): boolean {

28+

return typeof content !== "string" && content.some((part) => part.type === "input_image");

29+

}

30+
31+

/** Index of the last user message item, or -1 when there is none. */

32+

function findActiveUserMessageIndex(input: ItemParam[]): number {

33+

for (let i = input.length - 1; i >= 0; i -= 1) {

34+

const item = input[i];

35+

if (item?.type === "message" && item.role === "user") {

36+

return i;

37+

}

38+

}

39+

return -1;

40+

}

41+
2642

/** Build the user message and optional system prompt from Responses API input. */

2743

export function buildAgentPrompt(input: string | ItemParam[]): {

2844

message: string;

@@ -34,16 +50,26 @@ export function buildAgentPrompt(input: string | ItemParam[]): {

3450
3551

const systemParts: string[] = [];

3652

const conversationEntries: ConversationEntry[] = [];

53+

const activeUserMessageIndex = findActiveUserMessageIndex(input);

3754
38-

for (const item of input) {

55+

for (const [i, item] of input.entries()) {

3956

if (item.type === "message") {

4057

const content = extractTextContent(item.content).trim();

41-

if (!content) {

58+

// Substitute a placeholder for an image-only active user turn so the turn

59+

// is not dropped and the downstream agent command (which requires non-empty

60+

// message text) still runs with the attached image, matching /v1/chat/completions.

61+

// Historical image-only turns stay skipped because their bytes are not replayed.

62+

const body =

63+

content ||

64+

(item.role === "user" && i === activeUserMessageIndex && hasImageContent(item.content)

65+

? IMAGE_ONLY_USER_MESSAGE

66+

: "");

67+

if (!body) {

4268

continue;

4369

}

4470
4571

if (item.role === "system" || item.role === "developer") {

46-

systemParts.push(content);

72+

systemParts.push(body);

4773

continue;

4874

}

4975

@@ -52,7 +78,7 @@ export function buildAgentPrompt(input: string | ItemParam[]): {

5278
5379

conversationEntries.push({

5480

role: normalizedRole,

55-

entry: { sender, body: content },

81+

entry: { sender, body },

5682

});

5783

} else if (item.type === "function_call_output") {

5884

conversationEntries.push({