Skip to content

fix(android): block self-package notification forwarding in allowlist mode#99559

Closed
ly85206559 wants to merge 1 commit into
openclaw:mainfrom
ly85206559:fix/android-notification-allowlist-self-block
Closed

fix(android): block self-package notification forwarding in allowlist mode#99559
ly85206559 wants to merge 1 commit into
openclaw:mainfrom
ly85206559:fix/android-notification-allowlist-self-block

Conversation

@ly85206559

Copy link
Copy Markdown
Contributor

What Problem This Solves

Notification allowlist mode could forward OpenClaw's own notifications when the app package was allowlisted, risking gateway/node forwarding loops. Blocklist mode already blocked self by default.

Why This Change Was Made

Carry the app package through NotificationForwardingPolicy.selfPackageName and fail closed in allowsPackage regardless of filter mode.

User Impact

Allowlists cannot accidentally forward OpenClaw app notifications to the gateway.

Evidence

  • NotificationForwardingPolicyTest.allowsPackage_neverForwardsSelfPackageEvenInAllowlist
  • SecurePrefsNotificationForwardingTest.getNotificationForwardingPolicy_blocksSelfPackageInAllowlistMode
cd apps/android
./gradlew :app:testPlayDebugUnitTest --tests ai.openclaw.app.NotificationForwardingPolicyTest --tests ai.openclaw.app.SecurePrefsNotificationForwardingTest

… mode

Always reject the OpenClaw app package in allowsPackage, matching the
blocklist fail-closed behavior and preventing gateway/node forwarding loops.

Co-authored-by: Cursor <[email protected]>
@clawsweeper

clawsweeper Bot commented Jul 3, 2026

Copy link
Copy Markdown
Contributor

ClawSweeper status: review started.

I am starting a fresh review of this pull request: fix(android): block self-package notification forwarding in allowlist mode This is item 1/1 in the current shard. Shard 0/1.

This placeholder means the worker is alive and reading the current context. I will edit this same comment with the actual review when the claws are done clicking.

Crustacean status: shell secured, claws on keyboard, evidence pebbles being sorted.

@ly85206559

Copy link
Copy Markdown
Contributor Author

Queued behind #99557 and the talk-config PR. Will open after prior fixes land.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant