release aidev SIG 4/5

OpenClaw 2026.6.33: security hardening across gateway auth, MCP authority, and channel delivery

A 169-PR release dominated by security and reliability repair. Gateway HTTP now rejects disallowed browser origins before unauthenticated handling, external MCP loopback clients get short-lived session-bound grants instead of inheriting mutable child-process authority, Codex app-server commands require a real human or plugin approval, and secrets are redacted from MCP status output and Telegram-adjacent logs. Operators running exposed gateways should treat this as an upgrade release.

PUBLISHED2026-08-08
OBSERVED2026-08-11
AGE3d
SOURCES1

Highlights

  • Response-size caps on provider streams, Discord REST responses, browser fetches, OAuth paths; Telegram credentials kept out of diagnostics
  • Run release, liveness checks, and watchdog semantics distinguish genuine stalls from active long model calls and wedged backends
  • Discord reconnects no longer silently drop queued messages or repeat ambiguous non-idempotent sends; Telegram bot-to-bot and reply-fence handling preserve thread and authorization result
  • Service restarts preserve SecretRef-backed Telegram credentials; OAuth repair no longer overwrites a valid destination profile
  • Package installs can select and update from the extended-stable channel without silently falling back to another release line

Authority changes

  • Codex app-server commands require an actual human/plugin approval
  • Exec auto-review bound to the exact resolved command
  • Narrow tool allowlists stay owned by the constructing factory
  • External MCP loopback clients use short-lived session-bound attach grants
  • Gateway message actions retain trusted requester provenance and reject untrusted callers

Fixes

  • Gateway HTTP rejects disallowed browser origins before unauthenticated handling; permission repair confined to its intended include; MCP status output redacts secrets
  • Bounded agent-run caches, no file-descriptor leak in lock probes, valid UTF-8 close reasons, heartbeat reads survive transient filesystem races
  • Anthropic-compatible partial streams no longer hang at their size bound; OpenAI Realtime uses correct auth and transcription secret flow; remote CDP credentials kept out of responses
  • Replayed Twilio requests rejected under sustained traffic; corrupt queued channel rows tombstoned without blocking later work; Telegram tokens redacted across split log chunks

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.