惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
G
GRAHAM CLULEY
P
Privacy & Cybersecurity Law Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
宝玉的分享
宝玉的分享
P
Proofpoint News Feed
H
Help Net Security
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
C
Cisco Blogs
人人都是产品经理
人人都是产品经理
Know Your Adversary
Know Your Adversary
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Recorded Future
Recorded Future
I
Intezer
罗磊的独立博客
T
The Exploit Database - CXSecurity.com
Blog — PlanetScale
Blog — PlanetScale
Malwarebytes
Malwarebytes
Spread Privacy
Spread Privacy
T
Tor Project blog
V
Vulnerabilities – Threatpost
云风的 BLOG
云风的 BLOG
腾讯CDC
B
Blog RSS Feed
Stack Overflow Blog
Stack Overflow Blog
F
Future of Privacy Forum
MyScale Blog
MyScale Blog
Latest news
Latest news
IT之家
IT之家
MongoDB | Blog
MongoDB | Blog
The Hacker News
The Hacker News
S
Securelist
博客园 - 【当耐特】
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threat Research - Cisco Blogs
Jina AI
Jina AI
Cisco Talos Blog
Cisco Talos Blog
B
Blog
博客园 - 三生石上(FineUI控件)
Last Week in AI
Last Week in AI
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
M
MIT News - Artificial intelligence
V
V2EX
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Cloudflare Blog
The GitHub Blog
The GitHub Blog
博客园 - 聂微东
F
Full Disclosure
C
CERT Recently Published Vulnerability Notes

Recent Commits to openclaw:main

fix(agents): classify auth HTML provider responses (#79900) · openclaw/openclaw@7f4462e fix(gateway): allow bearer-auth session history reads (#81815) fix(installer): handle headless onboarding tty refactor(gateway): remove unused readLastMessagePreviewFromTranscript… · openclaw/openclaw@9b7e431 test: fix environment sensitivity in resolveNpmCommandInvocation test… · openclaw/openclaw@faf96ff fix(auth): load legacy Codex OAuth sidecars in embedded secrets-runti… Fix/codex deactivated workspace failover (#55893) fix(codex): demote plugin thread eligibility log · openclaw/openclaw@1d5b5db address review v2: workspace scope, warm generation guard, plugin rel… · openclaw/openclaw@c452a1e address review: scope short-circuit by caller auth context + rewarm o… · openclaw/openclaw@01087cb test(model-provider-auth): cover prepared-state short-circuit and clear · openclaw/openclaw@180cecd fix(models): reset warmed provider auth on hot reload · openclaw/openclaw@aef8d17 perf(models): pre-warm provider auth state at gateway startup · openclaw/openclaw@4f80cc1 address review v3: invalidate prepared map on auth-profile logout + d… · openclaw/openclaw@7ddcca6 fix(qa-lab): rename codex lifecycle fixtures to match knip ignore pat… · openclaw/openclaw@ebd8b00 test(gateway): relax e2e node status waits · openclaw/openclaw@b25a0d0 fix #84745: scope Google preview model normalization to Google provid… · openclaw/openclaw@7d5afcb test(qa-lab): cover codex plugin lifecycle fixtures · openclaw/openclaw@bbf3eec fix(tests): allow slower kitchen sink installs · openclaw/openclaw@ec0cf9a revert(qa-lab): remove scenario github traceability metadata · openclaw/openclaw@46c8864 fix(docker): prune omitted plugin runtime deps fix(auth): skip OAuth refresh adapter when credential has no refresh … test(qa-lab): cover update package sentinel · openclaw/openclaw@178e510 fix(json): retry on transient File changed during read race condition… fix(status): add gateway delivery health telemetry (#85016) · openclaw/openclaw@5955f35 test(qa-lab): trace scenario issue evidence · openclaw/openclaw@efb7e47 fix(sessions): preserve compatible auth overrides (#85014) · openclaw/openclaw@b33deb4 ci(qa): publish soak parity artifacts fix(qa): keep searchable tool coverage report-only test(e2e): isolate kitchen sink rpc gateway fix(ollama): allow Orb host local auth (#84999) · openclaw/openclaw@277a4b6 test(qa-lab): add personal failure recovery scenario · openclaw/openclaw@229323d ci: tune crabbox developer image config feat(qa-lab): add jsonl replay harness · openclaw/openclaw@cf06578 fix(codex): beta blocker - keep context engine on canonical session k… · openclaw/openclaw@66dcc4e chore(release): refresh generated baselines · openclaw/openclaw@1b1580c fix(openshell): use NVIDIA CLI contract · openclaw/openclaw@e72f601 docs(release): prefer 1Password provider preflight Policy: add model, network, and MCP conformance checks (#80783) · openclaw/openclaw@6dbd5bd fix(agents): fence embedded session writes refactor: remove sender owner tool gating · openclaw/openclaw@02182d5 docs: remove stale owner tool wording test: update command auth expectations · openclaw/openclaw@95eac52 fix(xai): keep OAuth URL clickable (#84927) · openclaw/openclaw@159b300 Fix stale WebChat typing indicator after terminal session patch (#84565) docs: document rejected autoreview findings · openclaw/openclaw@c49647e docs(changelog): note VAPID subject fix · openclaw/openclaw@db606a8 perf(plugins): reuse compatible gateway startup registry · openclaw/openclaw@d2ad7d6 test: cover dispatch registry reuse caller · openclaw/openclaw@b248b48 docs: add plugin registry reuse changelog · openclaw/openclaw@6ccca4a fix(tests): wrap kitchen sink pnpm runner fix(agents): cap heartbeat context hint fallback · openclaw/openclaw@04061bc chore(deadcode): dedupe repeated helpers · openclaw/openclaw@88c49f9 perf(cli): cache stable subcommand help (#84786) · openclaw/openclaw@f39f56a fix(ollama): preserve tool call ids [AI-assisted] (#84855) · openclaw/openclaw@2000227 fix: align remaining copyright notice · openclaw/openclaw@f43e83c fix(config): append numeric bound hints to ceiling/floor validation e… · openclaw/openclaw@8a8f9dc fix(qa): enable private self-check runtime · openclaw/openclaw@0fb1de5 fix(diffs): replace iconMarkup string with ToolbarIconName enum to el… · openclaw/openclaw@b7f9bf5 fix: update mac copyright owner fix(agents): normalize openapi tool schemas · openclaw/openclaw@ec67290 fix(memory): stop recall tracking when dreaming is disabled · openclaw/openclaw@c89632b fix(diagnostics-otel): suppress exporter rejection crashes (#84881) perf: speed up secrets and nodes help startup (#84818) · openclaw/openclaw@233765b docs: add PDF timeout changelog · openclaw/openclaw@e3b77d6 fix(pdf): bound remote body reads [Fix] Reject slow node event sends (#84387) fix(doctor): detect Codex bwrap namespace denials · openclaw/openclaw@43c6c26 fix(update): prune stale local bundled plugin shadows · openclaw/openclaw@4a360ac ci: add live Codex plugin release check · openclaw/openclaw@3eb2d64 fix(slack): suppress reasoning reply payloads (#84322) chore: update vite · openclaw/openclaw@ec7495c chore: update dependencies · openclaw/openclaw@ec10d12 fix(config): validate browser sandbox bind sources [AI] (#84799) · openclaw/openclaw@3cc8b2a doctor: constrain legacy plugin cleanup paths [AI] (#84801) Fix Telegram isolated polling stall watchdog (#84861) · openclaw/openclaw@40db92f ci(release): keep non-waiting clawhub publish best effort fix(docker): keep prune store warmup before offline stage · openclaw/openclaw@1e8d966 ci(release): require resolved target before child dispatch · openclaw/openclaw@2fd02c2 fix(docker): keep runtime prune offline · openclaw/openclaw@a329b9e ci(release): streamline beta publish verification · openclaw/openclaw@1c5fda1 ci(release): preserve direct repair publishes · openclaw/openclaw@0604d25 ci(release): keep focused validation reruns independent · openclaw/openclaw@624d920 [Fix] Keep node systemd tokens out of unit files (#84815) fix: reject symlinked whatsapp creds · openclaw/openclaw@194f078 fix(whatsapp): guard credential atomic writes refactor(whatsapp): use async fs-safe credential checks · openclaw/openclaw@9ec9fbf fix(doctor): clear stale runtime override pins (#84221) fix(agents): disable pi-coding-agent auto-retry to prevent tool call … fix(trajectory): tolerate partial skill snapshot entries in support c… · openclaw/openclaw@c9b6a8b fix(ui): widen settings personal card · openclaw/openclaw@3156d94 fix(agents): log pre-prompt compaction fits decisions (#84676) · openclaw/openclaw@79be940 fix(memory-core): allow bounded dreaming session cleanup (#84802) · openclaw/openclaw@0671a2a perf(cli): lazy-load agents actions for help (#84483) · openclaw/openclaw@168f8a7 Skip empty sherpa structured transcripts (#84667) · openclaw/openclaw@46030f5 feat: support git and local skill installs (#84793) · openclaw/openclaw@c031274 Policy: add tool metadata conformance (#80056) fix(doctor): warn when sandbox hides MCP tools (#84742) · openclaw/openclaw@6745fe8 perf(cli): speed up onboarding help startup (#84488) · openclaw/openclaw@2c0c9c9 perf: isolate doctor core check tests (#84493) · openclaw/openclaw@2585249
fix(exec): protect pathPrepend against posix login-shell RC overrides… · openclaw/openclaw@b77f36f
medns · 2026-05-22 · via Recent Commits to openclaw:main

@@ -104,7 +104,12 @@ vi.mock("../process/supervisor/index.js", () => {

104104

};

105105106106

const immediate = () => new Promise<void>((resolve) => setImmediate(resolve));

107-

const readEnvPath = (env?: NodeJS.ProcessEnv) => env?.PATH ?? env?.Path ?? "";

107+

const readPathKey = (env?: NodeJS.ProcessEnv) =>

108+

env && "Path" in env && !("PATH" in env) ? "Path" : "PATH";

109+

const readEnvPath = (env?: NodeJS.ProcessEnv) => env?.[readPathKey(env)] ?? "";

110+

const writeEnvPath = (env: NodeJS.ProcessEnv, value: string) => {

111+

env[readPathKey(env)] = value;

112+

};

108113

const extractCommand = (input: SpawnInput) => input.ptyCommand ?? input.argv?.at(-1) ?? "";

109114

const splitCommands = (command: string) => {

110115

const commands: string[] = [];

@@ -116,7 +121,18 @@ vi.mock("../process/supervisor/index.js", () => {

116121

}

117122

return commands;

118123

};

119-

const stdoutForSegment = (segment: string, env?: NodeJS.ProcessEnv) => {

124+

const applySegmentShellEffects = (segment: string, env: NodeJS.ProcessEnv) => {

125+

if (segment === 'export PATH="${OPENCLAW_PREPEND_PATH}${PATH:+:$PATH}"') {

126+

const prepend = env.OPENCLAW_PREPEND_PATH ?? "";

127+

const current = readEnvPath(env);

128+

writeEnvPath(env, `${prepend}${current ? `:${current}` : ""}`);

129+

return;

130+

}

131+

if (segment === "unset OPENCLAW_PREPEND_PATH") {

132+

delete env.OPENCLAW_PREPEND_PATH;

133+

}

134+

};

135+

const stdoutForSegment = (segment: string, env: NodeJS.ProcessEnv) => {

120136

if (segment === "echo $PATH" || segment === "Write-Output $env:PATH") {

121137

return `${readEnvPath(env)}\n`;

122138

}

@@ -129,10 +145,15 @@ vi.mock("../process/supervisor/index.js", () => {

129145

return "";

130146

};

131147132-

const commandOutput = (command: string, env?: NodeJS.ProcessEnv) =>

133-

splitCommands(command)

134-

.map((segment) => stdoutForSegment(segment, env))

148+

const commandOutput = (command: string, env?: NodeJS.ProcessEnv) => {

149+

const shellEnv = { ...env };

150+

return splitCommands(command)

151+

.map((segment) => {

152+

applySegmentShellEffects(segment, shellEnv);

153+

return stdoutForSegment(segment, shellEnv);

154+

})

135155

.join("");

156+

};

136157137158

return {

138159

getProcessSupervisor: () => ({

@@ -845,6 +866,23 @@ describe("exec PATH handling", () => {

845866

expect(index).toBeLessThan(baseIndex);

846867

}

847868

});

869+870+

it("protects POSIX prepended paths from shell startup overrides", async () => {

871+

if (isWin) {

872+

return;

873+

}

874+

process.env.PATH = "/evil/bin:/usr/bin";

875+

const tool = createTestExecTool({ pathPrepend: ["/custom/bin"] });

876+877+

const result = await executeExecCommand(tool, COMMAND_PRINT_PATH);

878+879+

const text = readNormalizedTextContent(result.content);

880+

const entries = text.split(path.delimiter);

881+882+

// Simulate a shell startup file prepending /evil/bin before the command runs.

883+

// The exec wrapper must still restore configured pathPrepend entries to the front.

884+

expect(entries).toEqual(["/custom/bin", "/evil/bin", "/usr/bin"]);

885+

});

848886

});

849887850888

describe("findPathKey", () => {