惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
Engineering at Meta
Engineering at Meta
博客园 - 司徒正美
T
Tailwind CSS Blog
F
Full Disclosure
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
小众软件
小众软件
IT之家
IT之家
J
Java Code Geeks
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
B
Blog
V
V2EX
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
The Cloudflare Blog
Recent Announcements
Recent Announcements
博客园 - 【当耐特】
Google DeepMind News
Google DeepMind News
罗磊的独立博客
博客园 - 叶小钗
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog
云风的 BLOG
云风的 BLOG
aimingoo的专栏
aimingoo的专栏
大猫的无限游戏
大猫的无限游戏
酷 壳 – CoolShell
酷 壳 – CoolShell
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Security @ Cisco Blogs
MyScale Blog
MyScale Blog
MongoDB | Blog
MongoDB | Blog
U
Unit 42
H
Heimdal Security Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
V2EX - 技术
V2EX - 技术
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Google Online Security Blog
Google Online Security Blog
N
News and Events Feed by Topic
Hacker News - Newest:
Hacker News - Newest: "LLM"
PCI Perspectives
PCI Perspectives
博客园 - 三生石上(FineUI控件)
I
InfoQ
SecWiki News
SecWiki News
N
News and Events Feed by Topic
D
DataBreaches.Net
Schneier on Security
Schneier on Security
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4 test: trim doctor command hotspots · openclaw/openclaw@c66f16a test: isolate agent auth and spawn hotspots · openclaw/openclaw@9285935 test: stabilize MCP startup disposal race · openclaw/openclaw@dd9d2eb test: merge browser contract server suites · openclaw/openclaw@5817a76 test: narrow ollama provider discovery setup · openclaw/openclaw@a0d9598 build: declare qa-lab aimock runtime dependency · openclaw/openclaw@24431e5 test: speed up safe-bins exec harness · openclaw/openclaw@ee856ab test: preserve tool helpers in embedded runner mocks · openclaw/openclaw@acd86a0 refactor: move memory embeddings into provider plugins · openclaw/openclaw@77e6e4c test: reuse system-run temp fixtures · openclaw/openclaw@7e9ff0f test: trim hotspot wait overhead · openclaw/openclaw@12a59b0 Check: avoid duplicate boundary prep · openclaw/openclaw@baf11b8 test: reduce hotspot fixture overhead · openclaw/openclaw@3a59edd feat(ui): overhaul settings and slash command UX (#67819) thanks @Bun… · openclaw/openclaw@2cfb660 QA Matrix: exit cleanly on failure · openclaw/openclaw@42805d2 QA Matrix: isolate scenario coverage · openclaw/openclaw@7e659e1 Matrix: refresh crypto bootstrap state · openclaw/openclaw@94081d8 QA Lab: add provider registry · openclaw/openclaw@bb7e982 Matrix: add plugin changelog · openclaw/openclaw@4acab55 test: trim more hotspot overhead · openclaw/openclaw@f485311 test: trim remaining hotspot tests · openclaw/openclaw@6ba8626 test: narrow hotspot mocks · openclaw/openclaw@dbc8179 test: isolate gemini embedding request helpers · openclaw/openclaw@cd330f5 test: trim memory and mcp hotspots · openclaw/openclaw@fd48dfa test: slim provider registry mocks · openclaw/openclaw@2e08c77 test: harden Parallels update smoke · openclaw/openclaw@1a98090 feat: default Anthropic to Opus 4.7 · openclaw/openclaw@628b454 fix: harden node-host shell payload mutability checks · openclaw/openclaw@75c551e fix: land node-host approval binding for native binaries (#66731) (th… · openclaw/openclaw@29919bb CI: add daily schedule to CodeQL workflow (#67645) · openclaw/openclaw@69d25f5 fix(gateway): capture config hash after plugin auto-enable to prevent… · openclaw/openclaw@8c11210 fix: repair sanitized replay tool results before send (#67620) (thank… · openclaw/openclaw@c3c7a99 fix: restrict HTML timeout short-circuit to transient statuses · openclaw/openclaw@de129a6 fix: keep TUI watchdog bound to active run (#67401) (thanks @xantorres) · openclaw/openclaw@3525273 Gateway/skills: dedupe skills prefix-match + drop dead fallback on log · openclaw/openclaw@d7f489f Extensions/lmstudio: back off inference preload after consecutive fai… · openclaw/openclaw@b555214 TUI/streaming: add watchdog that resets the activity indicator after … · openclaw/openclaw@f44ab20 Agents/tool-loop: enable unknown-tool stream guard by default · openclaw/openclaw@36ed367 Gateway/skills: invalidate session skills snapshot on config write · openclaw/openclaw@b23d59a fix: classify HTML provider error pages correctly (#67642) (thanks @s… · openclaw/openclaw@e588e90 fix(skills): remove unused model-usage import (#67641) · openclaw/openclaw@55f05df docs(changelog): credit codex fix superseded PRs · openclaw/openclaw@e485f24 fix(openai-codex): normalize stale transport metadata in resolution a… · openclaw/openclaw@90801ba CI: pin Docker-related GitHub Actions (#67632) · openclaw/openclaw@f697b01 Android: modernize WebView and discovery API usage (#67627) · openclaw/openclaw@44a6e50 fix(deps): bump hono to 4.12.14 and @hono/node-server to 1.19.14 (GHS… · openclaw/openclaw@fbccc18 fix(deps): bump dompurify to 3.4.0 (#67614) · openclaw/openclaw@2c2dc00 CI: add explicit permissions to all workflow jobs (fixes code-scannin… · openclaw/openclaw@01b7516 fix: register bundled TTS providers and route overrides correctly (#6… · openclaw/openclaw@6ea3cdd fix: align host tilde paths with OS home (#62804) (thanks @stainlu) · openclaw/openclaw@ecfaf64 fix: flush creds queue before reconnect socket open (#67464) (thanks … · openclaw/openclaw@405c63f fix: strip standalone <function> tool call tags from visible text (#6… · openclaw/openclaw@78df859 fix(agents): preserve cli session metadata before transcript persist … · openclaw/openclaw@898fd04 docs(changelog): move cli transcript entry · openclaw/openclaw@c1817c6 fix(agents): normalize cli transcript api field · openclaw/openclaw@3a3fae0 docs(changelog): note cli transcript persistence · openclaw/openclaw@6c343f1 fix(agents): persist cli transcript turns · openclaw/openclaw@b8ef507 fix(msteams): harden security-sensitive flows (#65841) · openclaw/openclaw@c56b56e [Dashboard] Fix exec approval modal overflow for long command content… · openclaw/openclaw@053c5b0 Docs: remove QA changelog entry · openclaw/openclaw@7fd5771 QA: fix private runtime source loading (#67428) · openclaw/openclaw@d5933af docs(gateway): correct protocol.md schema path, hello-ok example, aut… · openclaw/openclaw@489404d CI: pin Node 22 runners to 22.18.0 · openclaw/openclaw@4ffa621 models.authStatus: normalize provider ids + tighten env-backed escape… · openclaw/openclaw@f2fdb9d Update CHANGELOG.md · openclaw/openclaw@7694a92 test(parallels): clean up npm update guard jobs · openclaw/openclaw@045ea7b Plugins: prefer scanDir override paths · openclaw/openclaw@b2974da fix(dreaming): default storage.mode to "separate" so phase blocks sto… · openclaw/openclaw@8c392f0 fix(memory-core): skip dreaming transcript ingestion via session stor… · openclaw/openclaw@a1b01f0 fix: dedupe replayed exec.finished node events (#67281) · openclaw/openclaw@5dcf526
Doctor: add health-check contract and --lint validation (#80055) · openclaw/openclaw@9a5f2f6
giodl73-repo · 2026-05-18 · via Recent Commits to openclaw:main

@@ -15,13 +15,34 @@ Related:

1515

- Troubleshooting: [Troubleshooting](/gateway/troubleshooting)

1616

- Security audit: [Security](/gateway/security)

171718+

## Why Use It

19+20+

`openclaw doctor` is the OpenClaw health surface. Use it when the gateway,

21+

channels, plugins, skills, model routing, local state, or config migrations are

22+

not behaving as expected and you want one command that can explain what is

23+

wrong.

24+25+

Doctor has three postures:

26+27+

| Posture | Command | Behavior |

28+

| ------- | ------------------------ | ------------------------------------------------------------------------------- |

29+

| Inspect | `openclaw doctor` | Human-oriented checks and guided prompts. |

30+

| Repair | `openclaw doctor --fix` | Applies supported repairs, using prompts unless non-interactive repair is safe. |

31+

| Lint | `openclaw doctor --lint` | Read-only structured findings for CI, preflight, and review gates. |

32+33+

Prefer `--lint` when automation needs a stable result. Prefer `--fix` when a

34+

human operator intentionally wants doctor to edit config or state.

35+1836

## Examples

19372038

```bash

2139

openclaw doctor

22-

openclaw doctor --repair

40+

openclaw doctor --lint

41+

openclaw doctor --lint --json

42+

openclaw doctor --lint --severity-min warning

2343

openclaw doctor --deep

24-

openclaw doctor --repair --non-interactive

44+

openclaw doctor --fix

45+

openclaw doctor --fix --non-interactive

2546

openclaw doctor --generate-gateway-token

2647

```

2748

@@ -44,13 +65,134 @@ The targeted Discord capabilities probe reports the bot's effective channel perm

4465

- `--non-interactive`: run without prompts; safe migrations and non-service repairs only

4566

- `--generate-gateway-token`: generate and configure a gateway token

4667

- `--deep`: scan system services for extra gateway installs and report recent Gateway supervisor restart handoffs

68+

- `--lint`: run modernized health checks in read-only mode and emit diagnostic findings

69+

- `--json`: with `--lint`, emit JSON findings instead of human output

70+

- `--severity-min <level>`: with `--lint`, drop findings below `info`, `warning`, or `error`

71+

- `--skip <id>`: with `--lint`, skip a check id; repeat to skip more than one

72+

- `--only <id>`: with `--lint`, run only a check id; repeat to run a small selected set

73+74+

## Lint mode

75+76+

`openclaw doctor --lint` is the read-only automation posture for doctor checks.

77+

It uses the structured health-check path, does not prompt, and does not repair

78+

or rewrite config/state. Use it in CI, preflight scripts, and review workflows

79+

when you want machine-readable findings instead of guided repair prompts.

80+

Lint-output options such as `--json`, `--severity-min`, `--only`, and `--skip`

81+

are only accepted with `--lint`.

82+83+

```bash

84+

openclaw doctor --lint

85+

openclaw doctor --lint --severity-min warning

86+

openclaw doctor --lint --json

87+

openclaw doctor --lint --only core/doctor/gateway-config --json

88+

```

89+90+

Human output is compact:

91+92+

```text

93+

doctor --lint: ran 5 check(s), 1 finding(s)

94+

[warning] core/doctor/gateway-config gateway.mode - gateway.mode is unset; gateway start will be blocked.

95+

fix: Run `openclaw configure` and set Gateway mode (local/remote), or `openclaw config set gateway.mode local`.

96+

```

97+98+

JSON output is the scripting surface for lint runs:

99+100+

```json

101+

{

102+

"ok": false,

103+

"checksRun": 5,

104+

"checksSkipped": 0,

105+

"findings": [

106+

{

107+

"checkId": "core/doctor/gateway-config",

108+

"severity": "warning",

109+

"message": "gateway.mode is unset; gateway start will be blocked.",

110+

"path": "gateway.mode",

111+

"fixHint": "Run `openclaw configure` and set Gateway mode (local/remote), or `openclaw config set gateway.mode local`."

112+

}

113+

]

114+

}

115+

```

116+117+

Exit behavior:

118+119+

- `0`: no findings at or above the selected severity threshold

120+

- `1`: at least one finding meets the selected threshold

121+

- `2`: command/runtime failure before lint findings can be produced

122+123+

`--severity-min` controls both visible findings and the exit threshold. For

124+

example, `openclaw doctor --lint --severity-min error` can print no findings and

125+

exit `0` even when lower-severity `info` or `warning` findings exist.

126+127+

## Structured Health Checks

128+129+

Modern doctor checks use a small structured contract:

130+131+

```ts

132+

detect(ctx, scope?) -> HealthFinding[]

133+

repair?(ctx, findings) -> HealthRepairResult

134+

```

135+136+

`detect()` powers `doctor --lint`. `repair()` is optional and is only considered

137+

by `doctor --fix` / `doctor --repair`. Checks that have not migrated to this

138+

shape continue to use the legacy doctor contribution flow.

139+140+

The split is intentional: `detect()` owns diagnosis, while `repair()` owns

141+

reporting what it changed or would change. Repair contexts can carry

142+

`dryRun`/`diff` requests, and repair results can return structured `diffs` for

143+

config/file edits plus `effects` for service, process, package, state, or other

144+

side effects. That lets converted checks grow toward `doctor --fix --dry-run`

145+

and diff reporting without moving mutation planning into `detect()`.

146+147+

`repair()` reports whether it attempted the requested repair with `status:

148+

"repaired" | "skipped" | "failed"`. Omitted status means `repaired`, so simple

149+

repair checks only need to return changes. When repair returns `skipped` or

150+

`failed`, doctor reports the reason and does not run validation for that check.

151+152+

After a successful structured repair, doctor re-runs `detect()` with the

153+

repaired findings as scope. Checks can use selected findings, paths, or `ocPath`

154+

values for focused validation. If the finding is still present, doctor reports a

155+

repair warning instead of treating the change as silently complete.

156+157+

A finding includes:

158+159+

| Field | Purpose |

160+

| ----------------- | ------------------------------------------------------ |

161+

| `checkId` | Stable id for skip/only filters and CI allowlists. |

162+

| `severity` | `info`, `warning`, or `error`. |

163+

| `message` | Human-readable problem statement. |

164+

| `path` | Config, file, or logical path when available. |

165+

| `line` / `column` | Source location when available. |

166+

| `ocPath` | Precise `oc://` address when a check can point to one. |

167+

| `fixHint` | Suggested operator action or repair summary. |

168+169+

This release registers the modernized core doctor checks on the structured

170+

health path. The `openclaw/plugin-sdk/health` subpath exposes the same

171+

contract for bundled follow-up consumers, but plugin-backed checks only run

172+

after their owning package registers them in the active command path.

173+174+

## Check Selection

175+176+

Use `--only` and `--skip` when a workflow wants a focused gate:

177+178+

```bash

179+

openclaw doctor --lint --only core/doctor/gateway-config --json

180+

openclaw doctor --lint --skip core/doctor/skills-readiness

181+

```

182+183+

`--only` and `--skip` accept full check ids and may be repeated. If an `--only`

184+

id is not registered, no check runs for that id; use the command's `checksRun`

185+

and `checksSkipped` fields to verify a focused gate is selecting the checks you

186+

expect.

4718748188

Notes:

4918950190

- In Nix mode (`OPENCLAW_NIX_MODE=1`), read-only doctor checks still work, but `doctor --fix`, `doctor --repair`, `doctor --yes`, and `doctor --generate-gateway-token` are disabled because `openclaw.json` is immutable. Edit the Nix source for this install instead; for nix-openclaw, use the agent-first [Quick Start](https://github.com/openclaw/nix-openclaw#quick-start).

51191

- Interactive prompts (like keychain/OAuth fixes) only run when stdin is a TTY and `--non-interactive` is **not** set. Headless runs (cron, Telegram, no terminal) will skip prompts.

52-

- Performance: non-interactive `doctor` runs skip eager plugin loading so headless health checks stay fast. Interactive sessions still fully load plugins when a check needs their contribution.

192+

- Performance: non-interactive `doctor` runs skip eager plugin loading so headless health checks stay fast. Interactive doctor sessions still load the plugin surfaces needed by the legacy health and repair flow.

193+

- `--lint` is stricter than `--non-interactive`: it is always read-only, never prompts, and never applies safe migrations. Run `doctor --fix` or `doctor --repair` when you want doctor to make changes.

53194

- `--fix` (alias for `--repair`) writes a backup to `~/.openclaw/openclaw.json.bak` and drops unknown config keys, listing each removal.

195+

- Modernized health checks can expose a `repair()` path for `doctor --fix`; checks that do not expose one continue through the existing doctor repair flow.

54196

- `doctor --fix --non-interactive` reports missing or stale gateway service definitions but does not install or rewrite them outside update repair mode. Run `openclaw gateway install` for a missing service, or `openclaw gateway install --force` when you intentionally want to replace the launcher.

55197

- State integrity checks now detect orphan transcript files in the sessions directory. Archiving them as `.deleted.<timestamp>` requires an interactive confirmation; `--fix`, `--yes`, and headless runs leave them in place.

56198

- Doctor also scans `~/.openclaw/cron/jobs.json` (or `cron.store`) for legacy cron job shapes and can rewrite them in place before the scheduler has to auto-normalize them at runtime.