openclaw/docs/cli
Peter Steinberger de0d340597
fix(plugins): verify ClawHub archive files by extracted names (#156322)
## What Problem This Solves

Legacy ClawHub ZIP archives can be rejected when the separate preflight parser and the extractor interpret their filenames differently.

## User Impact

ClawHub verifies the extractor's canonical filenames and SHA-256 hashes before installation. A native-backed CP437 archive that previously failed now installs when its files match the advertised metadata. Harmless backslash aliases may normalize to those exact paths, and root-only records that produce no output are ignored. Unsafe paths, collisions, missing or changed files, extra files, named unsupported records, and archive limits remain enforced.

## Why This Change Was Made

The released extractor's existing entry callback supplies the complete canonical inventory, including named records that extraction cannot materialize. Verification hashes the observed regular files in the fresh, unstripped extraction workspace and retains unsupported records without a digest so they cannot disappear from integrity checks.

This removes the second ZIP read/parser and the later directory walk, reducing production code by 48 lines without adding a library API or changing configuration or stored formats. Server-provided paths and generated `_meta.json` validation remain strict. The install documentation records the canonical-name behavior.

## Evidence

- The real native-backed installer CP437 case failed before this change and passes afterward. Synthetic archive proof also covers canonical aliases, inert root records, named unsupported entries, complete inventory/hash matching, unsafe paths, archive limits, cleanup, and installation authority.
- Focused proof passed 146 tests in 33.20 seconds wall time. The changed ClawHub suite measured 107 tests in 23.77 seconds wall time; the final CI repair rerun passed the same 107 tests in 38.04 seconds of wrapper time.
- All 14 affected checks passed in 181.69 seconds. The assertion-safety baseline shrinks exactly from 7 to 5; no boundary waiver or policy exception was added.
- CI identified a facade export retained only by a negative test spy after its production caller was deleted. Both are now removed; the real installer assertions for single extraction, lost authority, absent persistent installation, and cleanup remain. The exact full production and all-export dependency scans now pass, along with affected type, format, and lint checks.
- Fresh independent scoped reviews found no actionable findings. Lead review checked the released extractor's planning/publication guarantee and the final implementation.
- Proof uses synthetic archives and the actual installer on macOS. No live ClawHub service or Windows execution is claimed.
2026-09-23 07:42:46 -07:00
..
doctor fix(doctor): carry the recorded failure in session SQLite recovery reports (#156431) 2026-09-23 11:34:12 +00:00
gateway fix(daemon): preserve runtime paths during service reinstalls (#155265) 2026-09-22 00:42:06 +00:00
mcp refactor: retire pre-June import and verification compatibility (#156285) 2026-09-23 02:22:22 -07:00
plugins fix(plugins): verify ClawHub archive files by extracted names (#156322) 2026-09-23 07:42:46 -07:00
policy fix: skip official setup approvals and default to Astra (#145646) 2026-09-12 00:34:25 -07:00
update fix(update): preserve original update failure diagnostics (#156189) 2026-09-23 12:43:31 +00:00
acp.md fix: stop ACP client when terminal input closes (#148611) 2026-09-14 19:20:13 -07:00
agent.md fix(agents): session-ID lookup loses partition ownership (#155741) 2026-09-22 14:03:52 -07:00
agents.md fix: Ask OpenClaw drops requested agent display names (#151449) 2026-09-17 23:40:46 -07:00
approvals.md docs: fix 16 secops-owned audit findings across gateway, cli, and security pages (#144030) 2026-09-10 20:28:21 +08:00
attach.md
audit.md docs: correct verified accuracy defects in CLI, tools, and automation pages (#143179) 2026-09-09 23:57:06 +09:00
backup.md fix(backup): verification accepts archives missing captured databases (#156211) 2026-09-23 01:10:31 -06:00
browser.md feat(browser): unify local Chrome setup across desktop and terminal (#152057) 2026-09-22 06:28:29 -07:00
channels.md fix(channels): keep status reads available during state maintenance (#153445) 2026-09-20 05:40:20 -07:00
clawbot.md docs: correct verified accuracy defects in CLI, tools, and automation pages (#143179) 2026-09-09 23:57:06 +09:00
claws.md fix(claws): preserve user files when a workspace scan is incomplete (#154797) 2026-09-22 02:06:28 -07:00
completion.md fix(cli): stop Bash flag completion after the option terminator (#149678) 2026-09-16 22:00:11 +05:30
config.md fix(config): preserve session-store owners on unrelated writes (#151468) 2026-09-18 00:52:02 -07:00
configure.md docs: STE structural cleanup for gateway, cli and concepts (46 audit findings) (#143931) 2026-09-10 18:50:32 +08:00
connect.md feat: share selected sessions read-only with a paired team Gateway (#136253) 2026-09-12 13:35:17 -07:00
cron.md fix(cron): keep acknowledged manual runs durable across restart (#153360) 2026-09-19 23:00:58 -07:00
daemon.md fix(gateway): support pinned daemon runtime paths (#82290) 2026-09-16 21:20:21 -06:00
dashboard.md fix: preserve dashboard HTTP errors when diagnostics fail (#145227) 2026-09-11 13:46:03 -07:00
devices.md fix: reject agent Cron calls after caller revocation (#150921) 2026-09-17 16:21:59 +01:00
directory.md fix(directory): reject explicitly blank channel selectors (#153731) 2026-09-20 21:40:05 +05:30
dns.md docs: fix 20 link defects confirmed live in the verified backlog (#144133) 2026-09-11 03:48:10 +08:00
docs.md fix(docs): reject malformed search result collections (#145613) 2026-09-12 00:20:46 -07:00
doctor.md docs: close remaining one-way link findings in cli, plugins, tools, providers (#143855) 2026-09-10 16:15:08 +08:00
file-transfer.md docs: close the small audit categories (generated, governance, link, split) (#144029) 2026-09-10 21:52:03 +08:00
fleet.md feat(fleet): show the recorded container runtime in status (#144691) 2026-09-19 17:54:21 +01:00
gateway.md docs(gateway): warn that installation starts the service (#139562) 2026-09-10 17:23:20 +05:30
health.md fix: avoid local health timeouts for wildcard Gateways (#153984) 2026-09-20 16:04:33 -07:00
hooks.md docs: STE pass on terminology consistency and run-on sentences (#143770) 2026-09-10 15:51:49 +09:00
index.md docs: fix 20 link defects confirmed live in the verified backlog (#144133) 2026-09-11 03:48:10 +08:00
infer.md docs(providers): expand llmman guidance and add hybrid inference (#139606) 2026-09-19 10:07:03 -07:00
logs.md fix(cli): reject explicitly blank Gateway ports (#139613) 2026-09-06 06:47:43 -07:00
mcp.md docs: fix one-way and absolute links across cli, tools, gateway, and channels (#143157) 2026-09-10 07:40:16 +09:00
memory.md fix(memory): retain forget lineage through writer admission (#152902) 2026-09-19 07:43:49 -07:00
message.md fix(cli): retain every repeated message media attachment (#151043) 2026-09-20 15:54:37 +05:30
migrate.md fix: clarify Codex onboarding migration scope (#151383) 2026-09-21 00:57:52 -07:00
models.md fix: keep ACP harness models out of native calls (#153756) 2026-09-22 22:58:40 +01:00
node.md docs: fix node approval command examples (#153716) 2026-09-21 00:31:02 +05:30
nodes.md fix(cli): reject empty node invocation keys before lookup (#145032) 2026-09-20 15:50:30 +05:30
onboard.md feat(onboarding): add Apple on-device setup and utility model (#150376) 2026-09-16 20:53:06 -07:00
openclaw.md fix: guide model provider setup through protected Settings (#150800) 2026-09-17 17:03:18 +05:30
pairing.md docs: STE structural cleanup for gateway, cli and concepts (46 audit findings) (#143931) 2026-09-10 18:50:32 +08:00
path.md docs: fix checkable ux defects in docs/cli and docs/concepts (#143927) 2026-09-10 18:39:20 +08:00
plugins.md feat(plugins): manage multiple plugins in one CLI command (#149910) 2026-09-16 04:10:52 -07:00
policy.md docs: close remaining one-way link findings in cli, plugins, tools, providers (#143855) 2026-09-10 16:15:08 +08:00
promos.md docs: fix one-way and absolute links across cli, tools, gateway, and channels (#143157) 2026-09-10 07:40:16 +09:00
proxy.md docs: STE structural cleanup for gateway, cli and concepts (46 audit findings) (#143931) 2026-09-10 18:50:32 +08:00
qr.md fix(pairing): QR setup rejects trusted-proxy gateways without a shared secret (#147036) 2026-09-13 21:36:05 +08:00
reset.md docs: STE structural cleanup for gateway, cli and concepts (46 audit findings) (#143931) 2026-09-10 18:50:32 +08:00
resume.md
sandbox.md docs: fix 16 secops-owned audit findings across gateway, cli, and security pages (#144030) 2026-09-10 20:28:21 +08:00
secrets.md fix(doctor): agree with secrets audit on non-secret API-key markers (#156216) 2026-09-23 06:24:20 +00:00
security.md fix: bound filesystem reads and keep sandbox reads responsive (#146654) 2026-09-12 19:41:19 -07:00
sessions.md fix(sessions): reuse canonical token count formatting (#117517) 2026-09-16 20:10:52 -07:00
setup.md feat: select and manage installed agents from Models (#150224) 2026-09-20 18:00:12 +05:30
skills.md fix(skills): restore usage counts and current Workshop inventory (#151048) 2026-09-18 12:17:09 +05:30
status.md fix: report absent Gateways without waiting for startup (#154637) 2026-09-22 18:20:08 -07:00
system.md docs(cli): document system Gateway port and password options (#139071) 2026-09-10 16:01:11 +05:30
tasks.md docs: fix checkable ux defects in docs/cli and docs/concepts (#143927) 2026-09-10 18:39:20 +08:00
transcripts.md fix(gateway): apply settings without unnecessary restarts (#154792) 2026-09-21 11:50:57 -07:00
triage.md fix(triage): stop reporting failed updates as resolved (#153443) 2026-09-20 02:38:30 -07:00
tui.md docs: close remaining one-way link findings in cli, plugins, tools, providers (#143855) 2026-09-10 16:15:08 +08:00
uninstall.md docs: fix one-way and absolute links across cli, tools, gateway, and channels (#143157) 2026-09-10 07:40:16 +09:00
update.md fix(update): include npm errors in failure reports (#155337) 2026-09-22 03:37:42 +00:00
voicecall.md docs(plugins): remove obsolete Gateway restart guidance (#146516) 2026-09-12 16:48:13 -07:00
webhooks.md docs: STE pass on terminology consistency and run-on sentences (#143770) 2026-09-10 15:51:49 +09:00
wiki.md fix(memory-wiki): bound exact page reads (#129897) 2026-09-04 22:05:24 -07:00
workboard.md fix(workboard): preserve ready-card history on idle dispatch (#149160) 2026-09-15 20:46:50 +05:30
worker.md fix(nodes): finish worker cleanup when stopping environments (#152896) 2026-09-19 07:48:36 -07:00