[codex] fix: allow trusted .openclaw symlink#72713
Conversation
|
Thanks for the context here. I swept through the related work, and this is now duplicate or superseded. Keep open: the underlying symlinked Root-cause cluster Members:
Proposal only: this assessment does not dispatch repair, suppress jobs, mutate sibling items, close, or merge anything. Canonical path: Close this stale PR. The latest review rated it F, the branch still lacks merge-ready proof, and there has been no human follow-up after the durable review. So I’m closing this here because the remaining work is already tracked in the canonical issue. Review detailsBest possible solution: Close this stale PR. The latest review rated it F, the branch still lacks merge-ready proof, and there has been no human follow-up after the durable review. Do we have a high-confidence way to reproduce the issue? Yes. Source inspection shows Is this the best way to solve the issue? No, not as submitted. The compatibility direction is valid, but the stale draft needs a rebase that preserves current state-dir behavior and hardening before it can be the best fix. Security review: Security review needs attention: The patch changes command-approval filesystem trust boundaries and currently misses current main's directory hardening on the Node path.
AGENTS.md: found and applied where relevant. What I checked:
Likely related people:
Codex review notes: model internal, reasoning high; reviewed against 36dd9ee3c3c1. |
|
ClawSweeper PR egg 🎁 Pass real behavior proof to wake the egg and unlock a hatchable treat. Where did the egg go?
|
|
This pull request has been automatically marked as stale due to inactivity. |
|
This pull request has been automatically marked as stale due to inactivity. |
|
ClawSweeper status: review started. I am starting a fresh review of this pull request: [codex] fix: allow trusted .openclaw symlink This is item 1/1 in the current shard. Shard 0/1. This placeholder means the worker is alive and reading the current context. I will edit this same comment with the actual review when the claws are done clicking. Crustacean status: shell secured, claws on keyboard, evidence pebbles being sorted. |
Summary
Closes #72572.
This restores support for dotfile-managed
~/.openclawdirectories while keeping exec approval paths hardened on both the Node and macOS node-host paths.~/.openclawsymlinks on POSIX after validating link ownership, link location, target ownership, target permissions, and stable resolved ancestors.openclawsymlink targets blocked until ACL validation existsexec-approvals.jsondestinationsOPENCLAW_STATE_DIRoverrides and system/tmp//varsymlink rootsValidation
pnpm docs:listpnpm exec oxfmt --check --threads=1 src/infra/exec-approvals.ts src/infra/exec-approvals-store.test.tspnpm test src/infra/exec-approvals-store.test.tsswiftc -parse apps/macos/Sources/OpenClaw/ExecApprovals.swift apps/macos/Sources/OpenClaw/ExecApprovalsSocket.swift apps/macos/Sources/OpenClaw/NodeMode/MacNodeRuntime.swift apps/macos/Tests/OpenClawIPCTests/ExecApprovalsSocketPathGuardTests.swift apps/macos/Tests/OpenClawIPCTests/ExecApprovalsStoreRefactorTests.swiftgit diff --checkpnpm check:changed(core lanes passed; apps lane stopped becauseswiftlintis not installed locally)swift test --filter ExecApprovalsSocketPathGuardTestsattempted; SwiftPM hung while downloading/building Sparkle artifact locallycodex review -c model="gpt-5.4" --base origin/mainAI-assisted: yes
lobster-biscuit