惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
C
Check Point Blog
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
有赞技术团队
有赞技术团队
P
Proofpoint News Feed
IT之家
IT之家
B
Blog
博客园_首页
量子位
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
J
Java Code Geeks
H
Help Net Security
A
About on SuperTechFans
Apple Machine Learning Research
Apple Machine Learning Research
Jina AI
Jina AI
D
DataBreaches.Net
Y
Y Combinator Blog
大猫的无限游戏
大猫的无限游戏
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix(docker): precreate owned named volume targets (#85454...
steipete · 2026-05-23 · via Recent Commits to openclaw:main
Original file line numberDiff line numberDiff line change

@@ -48,6 +48,7 @@ Docs: https://docs.openclaw.ai

4848

- Memory: expand `~` in configured extra memory paths before resolving them, so home-relative folders are not treated as workspace-relative. Fixes #58026. Thanks @stadman.

4949

- Skills: treat `openclaw.os: macos` as Darwin when checking skill requirements, so macOS-only skills no longer report as missing on macOS hosts. Fixes #61338. Thanks @Jessecq1995.

5050

- Control UI/logs: strip ANSI escape sequences from displayed Gateway log messages so color codes no longer appear as raw text. Fixes #64399. Thanks @guguangxin-eng.

51+

- Docker: pre-create the workspace and auth-profile config mount points with `node` ownership so first-run named volumes do not start root-owned. Fixes #85076. Thanks @Noerr.

5152

- CLI/update: preserve managed Gateway service environment during package cutovers so macOS LaunchAgent repair/restart reads the pre-update service state instead of caller shell state. (#83026)

5253

- Agents/providers: honor per-model `api` and `baseUrl` overrides in custom provider auth hooks and transport selection. Fixes #80487. (#80488) Thanks @huveewomg.

5354

- Gateway/restart: eager-load the lifecycle runtime before in-place upgrade signal handling so package replacement does not deadlock restart imports. (#84890) Thanks @myps6415.

Original file line numberDiff line numberDiff line change

@@ -285,10 +285,15 @@ RUN --mount=type=cache,id=openclaw-bookworm-apt-cache,target=/var/cache/apt,shar

285285

RUN ln -sf /app/openclaw.mjs /usr/local/bin/openclaw \

286286

&& chmod 755 /app/openclaw.mjs

287287
288-

# Pre-create the default state dir so first-run Docker named volumes mounted

289-

# here inherit node ownership instead of root-owned state.

290-

RUN install -d -m 0700 -o node -g node /home/node/.openclaw && \

291-

stat -c '%U:%G %a' /home/node/.openclaw | grep -qx 'node:node 700'

288+

# Pre-create default named-volume mount points so first-run Docker volumes copy

289+

# node ownership from the image instead of starting as root-owned directories.

290+

RUN install -d -m 0700 -o node -g node \

291+

/home/node/.openclaw \

292+

/home/node/.openclaw/workspace \

293+

/home/node/.config/openclaw && \

294+

stat -c '%U:%G %a' /home/node/.openclaw | grep -qx 'node:node 700' && \

295+

stat -c '%U:%G %a' /home/node/.openclaw/workspace | grep -qx 'node:node 700' && \

296+

stat -c '%U:%G %a' /home/node/.config/openclaw | grep -qx 'node:node 700'

292297
293298

ENV NODE_ENV=production

294299
Original file line numberDiff line numberDiff line change

@@ -291,11 +291,11 @@ describe("Dockerfile", () => {

291291

);

292292

});

293293
294-

it("pre-creates the OpenClaw home before switching to the node user", async () => {

294+

it("pre-creates named-volume mount points before switching to the node user", async () => {

295295

const dockerfile = await readFile(dockerfilePath, "utf8");

296296

const runtimeStageIndex = dockerfile.lastIndexOf("FROM base-runtime");

297297

const stateDirIndex = dockerfile.indexOf(

298-

"RUN install -d -m 0700 -o node -g node /home/node/.openclaw && \\",

298+

"RUN install -d -m 0700 -o node -g node \\",

299299

runtimeStageIndex,

300300

);

301301

const userIndex = dockerfile.indexOf("USER node", runtimeStageIndex);

@@ -306,8 +306,16 @@ describe("Dockerfile", () => {

306306

expect(stateDirIndex).toBeGreaterThan(runtimeStageIndex);

307307

expect(stateDirIndex).toBeLessThan(userIndex);

308308

expect(dockerfile).not.toContain("mkdir -p /home/node/.openclaw");

309+

expect(dockerfile).toContain("/home/node/.openclaw/workspace");

310+

expect(dockerfile).toContain("/home/node/.config/openclaw");

309311

expect(dockerfile).toContain(

310312

"stat -c '%U:%G %a' /home/node/.openclaw | grep -qx 'node:node 700'",

311313

);

314+

expect(dockerfile).toContain(

315+

"stat -c '%U:%G %a' /home/node/.openclaw/workspace | grep -qx 'node:node 700'",

316+

);

317+

expect(dockerfile).toContain(

318+

"stat -c '%U:%G %a' /home/node/.config/openclaw | grep -qx 'node:node 700'",

319+

);

312320

});

313321

});