mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 01:29:56 +00:00
## What Problem This Solves Legacy ClawHub ZIP archives can be rejected when the separate preflight parser and the extractor interpret their filenames differently. ## User Impact ClawHub verifies the extractor's canonical filenames and SHA-256 hashes before installation. A native-backed CP437 archive that previously failed now installs when its files match the advertised metadata. Harmless backslash aliases may normalize to those exact paths, and root-only records that produce no output are ignored. Unsafe paths, collisions, missing or changed files, extra files, named unsupported records, and archive limits remain enforced. ## Why This Change Was Made The released extractor's existing entry callback supplies the complete canonical inventory, including named records that extraction cannot materialize. Verification hashes the observed regular files in the fresh, unstripped extraction workspace and retains unsupported records without a digest so they cannot disappear from integrity checks. This removes the second ZIP read/parser and the later directory walk, reducing production code by 48 lines without adding a library API or changing configuration or stored formats. Server-provided paths and generated `_meta.json` validation remain strict. The install documentation records the canonical-name behavior. ## Evidence - The real native-backed installer CP437 case failed before this change and passes afterward. Synthetic archive proof also covers canonical aliases, inert root records, named unsupported entries, complete inventory/hash matching, unsafe paths, archive limits, cleanup, and installation authority. - Focused proof passed 146 tests in 33.20 seconds wall time. The changed ClawHub suite measured 107 tests in 23.77 seconds wall time; the final CI repair rerun passed the same 107 tests in 38.04 seconds of wrapper time. - All 14 affected checks passed in 181.69 seconds. The assertion-safety baseline shrinks exactly from 7 to 5; no boundary waiver or policy exception was added. - CI identified a facade export retained only by a negative test spy after its production caller was deleted. Both are now removed; the real installer assertions for single extraction, lost authority, absent persistent installation, and cleanup remain. The exact full production and all-export dependency scans now pass, along with affected type, format, and lint checks. - Fresh independent scoped reviews found no actionable findings. Lead review checked the released extractor's planning/publication guarantee and the final implementation. - Proof uses synthetic archives and the actual installer on macOS. No live ClawHub service or Windows execution is claimed. |
||
|---|---|---|
| .. | ||
| oxlint | ||
| tsconfig | ||
| assertion-safety-baseline.txt | ||
| ci-test-timings.json | ||
| control-ui-startup-budget-baseline.json | ||
| env-var-count-budget.txt | ||
| knip.all-exports.config.ts | ||
| knip.config.ts | ||
| knip.scripts-exports.config.ts | ||
| markdownlint-cli2.jsonc | ||
| markdownlint-templates.jsonc | ||
| max-lines-baseline.txt | ||
| shellcheckrc | ||
| stylelint.config.mjs | ||
| swiftformat | ||
| swiftlint.yml | ||