viettranx
bdb60de7ae
chore: upgrade Go 1.25 → 1.26 and apply go fix modernizations
...
- Update go.mod and Dockerfile to Go 1.26
- Apply `go fix ./...` stdlib modernizations across 170+ files
- Add `go fix` to post-implementation checklist in CLAUDE.md
- Fix go fix misapplied rewrite in loop_history.go
2026-03-10 00:09:15 +07:00
viettranx
d839e034af
feat(tools): add exec path exemptions and tool arguments in events
...
- Add AllowPathExemptions to ExecTool for fine-grained deny bypass (skills-store)
- Include tool call arguments in tool.result event payloads
2026-03-08 22:40:09 +07:00
viettranx
b62d46e50e
refactor(lint): apply Go best practices across codebase
...
- Use errors.Is() instead of direct sentinel comparison (13 instances)
- Convert if/else-if chains to switch/case for same-variable comparisons
- Remove redundant bitwise OR with zero
- Add post-implementation checklist to CLAUDE.md
2026-03-07 20:51:39 +07:00
Viet Tran and GitHub
6895e369f6
refactor: remove standalone mode, consolidate to managed-only (PostgreSQL) ( #70 )
...
- Remove standalone mode code: file-based stores, standalone gateway,
heartbeat service, SQLite memory, standalone docker-compose
- Rename docker-compose.managed.yml → docker-compose.postgres.yml
- Clean up ~130 Go comments referencing "managed mode" qualifier
- Simplify docker-compose.yml env vars (providers/channels via web UI)
- Update .env.example to essential vars only (token + encryption key)
- Add setup wizard UI (provider → agent → channel bootstrap flow)
- Add logs.tail WebSocket handler for live log streaming
- Add cursor-pointer to interactive UI components
- Clean up config page (remove standalone-only sections)
- Update README and docs for managed-only architecture
2026-03-06 18:51:11 +07:00
viettranx and Claude Opus 4.6
74d85c8dd5
feat(security): enforce group file writer restrictions + harden exec against env/config leaks
...
Group writer enforcement (managed mode):
- GroupWriterCache with 5min TTL wrapping AgentStore.ListGroupFileWriters
- Tool-level blocking: write_file, edit, read_file (SOUL.md/AGENTS.md), cron mutations
- System prompt injection: non-writers get refusal instructions + filtered context files
- Cache invalidation via bus events on add/remove writer
- Wired through resolver, loop, gateway_managed, gateway_callbacks
Exec security hardening:
- Block /proc/PID/environ and /proc/self/environ reads (env var exfiltration)
- Block strings on /proc files (binary env dump)
- DenyPaths() on ExecTool: block data dir, .goclaw/, config file from exec commands
- Scrub VIRTUAL_* env vars from tool output
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-03-02 19:22:21 +07:00
viettranx and Claude Opus 4.6
73b46c3634
feat(security): apply upstream TS OpenClaw security and core engine fixes
...
Port 8 fixes from upstream TypeScript OpenClaw (4 CRITICAL + 4 HIGH):
CRITICAL:
1. Tool call name trimming — add strings.TrimSpace() to all provider
response parsers (Anthropic 2 locations, OpenAI 3 locations) to
prevent registry lookup failures from LLM whitespace-padded names
2. Shell env injection deny patterns — block GIT_EXTERNAL_DIFF,
GIT_DIFF_OPTS, BASH_ENV, and ENV=.*sh to prevent code execution
via environment variable injection during git/shell operations
3. Broken symlink escape — recursive target resolution via
resolveThroughExistingAncestors() to catch chained symlinks
that escape workspace (e.g. link1→link2→/etc/passwd)
4. Mutable parent-symlink TOCTOU check — hasMutableSymlinkParent()
detects symlinks in writable parent dirs that could be rebound
between path validation and file operation
HIGH:
5. Model fallback thinking preservation — add ThinkingCapable interface
to providers/types.go, implement on Anthropic/OpenAI/DashScope,
check before injecting thinking_level in agent loop, warn on
fallback when thinking is configured
6. Cron session-key double-prefix guard — prevent agent:X:cron:agent:X
duplication in BuildCronSessionKey()
7. Webhook rate limiter — bounded WebhookRateLimiter (4096 keys max,
60s window, 30 hits/window) to prevent memory exhaustion DoS
8. DM policy allowlist validation — warn at startup when
dmPolicy=allowlist with empty allowFrom (silent message drop)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-28 16:52:37 +07:00
viettranx
08ced252b2
feat: Introduce agent summoning flow with a dedicated modal and updated bootstrap process for predefined agents.
2026-02-24 10:19:49 +07:00
Viet Tran
2991283901
Add environment variable dumping protections and expand credential scrubbing patterns
...
Remove env/printenv from safe bins list and add deny patterns for bare env/printenv/set/export commands that dump all environment variables including secrets. Expand credential scrubbing to detect connection strings (PostgreSQL, MySQL, MongoDB, Redis, AMQP), generic KEY=/SECRET=/CREDENTIAL= environment variables, DSN/DATABASE_URL patterns, and long hex strings (64+ chars) that may be encryption keys or hashes.
2026-02-22 22:00:35 +07:00
Viet Tran
765bec2287
Add Docker-based sandbox support with comprehensive security hardening and graceful fallback
...
Introduce optional Docker sandbox for agent code execution with defense-in-depth security patterns. Add ENABLE_SANDBOX build arg to conditionally install docker-cli in runtime image. Create docker-compose.sandbox.yml overlay with sandbox configuration (512MB memory, 1 CPU, no network, session-scoped containers). Expand shell command deny patterns to cover data exfiltration (DNS tunneling, curl POST), reverse
2026-02-22 19:18:10 +07:00
Viet Tran
172216e73d
Add edit tool, cron tool, session tools, and message tool with full wiring and exec approval hardening
...
Register edit tool (sandboxed + non-sandboxed variants) with context file and memory interceptors in managed mode. Add cron tool for agent-facing job management. Register session tools (list, status, history, send) and message tool with proper SessionStoreAware, BusAware, and ChannelSenderAware wiring. Harden exec approval system to always be active with deny patterns + safe bins, defaulting to full
2026-02-22 18:34:05 +07:00
Viet Tran and Claude Opus 4.6
f3f4c67b36
Initial commit: GoClaw AI agent gateway
...
Multi-agent AI gateway with WebSocket RPC, HTTP API, and messaging channel integrations.
Go port of OpenClaw with multi-tenant PostgreSQL, per-user isolation, security hardening,
and production observability.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-22 14:58:07 +07:00