 viettranxandClaude Opus 4.6
|
73b46c3634
|
feat(security): apply upstream TS OpenClaw security and core engine fixes
Port 8 fixes from upstream TypeScript OpenClaw (4 CRITICAL + 4 HIGH):
CRITICAL:
1. Tool call name trimming — add strings.TrimSpace() to all provider
response parsers (Anthropic 2 locations, OpenAI 3 locations) to
prevent registry lookup failures from LLM whitespace-padded names
2. Shell env injection deny patterns — block GIT_EXTERNAL_DIFF,
GIT_DIFF_OPTS, BASH_ENV, and ENV=.*sh to prevent code execution
via environment variable injection during git/shell operations
3. Broken symlink escape — recursive target resolution via
resolveThroughExistingAncestors() to catch chained symlinks
that escape workspace (e.g. link1→link2→/etc/passwd)
4. Mutable parent-symlink TOCTOU check — hasMutableSymlinkParent()
detects symlinks in writable parent dirs that could be rebound
between path validation and file operation
HIGH:
5. Model fallback thinking preservation — add ThinkingCapable interface
to providers/types.go, implement on Anthropic/OpenAI/DashScope,
check before injecting thinking_level in agent loop, warn on
fallback when thinking is configured
6. Cron session-key double-prefix guard — prevent agent:X:cron:agent:X
duplication in BuildCronSessionKey()
7. Webhook rate limiter — bounded WebhookRateLimiter (4096 keys max,
60s window, 30 hits/window) to prevent memory exhaustion DoS
8. DM policy allowlist validation — warn at startup when
dmPolicy=allowlist with empty allowFrom (silent message drop)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
2026-02-28 16:52:37 +07:00 |
|