Closes #137665
Related: #131475
## What Problem This Solves
Fixes an issue where an accepted IPv4-mapped CIDR such as `::ffff:10.0.0.0/104` rejected proxy addresses that belong to the equivalent `10.0.0.0/8` range. Proxied requests returned HTTP 403 `proxy_attribution_required`. The same matcher left eligible node pairing requests pending for mapped `autoApproveCidrs` and `sshVerify.cidrs` entries.
## Why This Change Was Made
Normalize the prefix into IPv4's bit space before the existing IPv4 match. The shared matcher now handles plain and mapped ranges in one path, without a second mapped-address matcher. Exact addresses, native IPv6, parsing, and downstream authorization keep their existing paths.
## User Impact
Mapped `/104`, `/120`, and `/128` ranges behave like IPv4 `/8`, `/24`, and exact addresses. Prefixes at or below `/96` cover all IPv4, including loopback; the wizard keeps its explicit loopback-consent prompt. Native IPv6 peers do not match mapped ranges. Keep proxy allowlists narrow: a catch-all still consumes every IPv4 forwarded hop and cannot attribute a client through that chain.
Automatic pairing still requires a fresh, signed, scopeless node request. Roles, scopes, browser requests, manual approval, and SSH host/device identity checks retain their own gates. No configuration field, schema, dependency, or permission policy is added.
## Evidence
Real source Gateway and CLI runs use isolated documentation-address peers, a real overwriting loopback reverse proxy, TLS, and actual SSH reading `openclaw node identity --json`.
| Caller | Pinned main | Repair |
| --- | --- | --- |
| Matching mapped proxy range | HTTP 403 | HTTP 200 from protected `/v1/models` |
| Plain equivalent proxy range | HTTP 200 | HTTP 200 |
| Nearby nonmatching proxy range | HTTP 403 | HTTP 403 |
| Matching mapped node auto-approval range | Manual pending | Approved via trusted CIDR and connected |
| Matching mapped SSH-verification range | Manual pending | SSH verified and connected |
Additional real controls cover `/64`, `/95`, `/96`, `/104`, `/128`, exact nonmatches, native IPv6, loopback consent, missing/disallowed identities, missing headers, invalid/loopback forwarded clients, origin allow/deny, scope caps, and SSH identity/key failures. Signed WebSocket checks retain manual role upgrades, scoped/browser requests, signature rejection, and manual read-only enrollment. The enrolled operator can read after restart and cannot invoke an administrative write. CIDR device pairing retains separate capability approval.
The three focused regression files show nine intended failures on main and 123 passes with the repair. Another 232 focused network/pairing/SSH tests pass. The exact installed ipaddr.js 2.5.0 source was inspected: IPv4 matching consumes 32 bits, so mapped prefixes must subtract 96.
Paired runtime proof uses main `
|
||
|---|---|---|
| .agents | ||
| .claude | ||
| .github | ||
| .vscode | ||
| apps | ||
| config | ||
| custodian-skills | ||
| deploy | ||
| docs | ||
| examples/ai-chat | ||
| extensions | ||
| git-hooks | ||
| packages | ||
| patches | ||
| qa | ||
| scripts | ||
| security | ||
| skills | ||
| src | ||
| test | ||
| ui | ||
| .crabbox.yaml | ||
| .dockerignore | ||
| .env.example | ||
| .gitattributes | ||
| .gitignore | ||
| .npmrc | ||
| .oxfmtrc.jsonc | ||
| .oxlintrc.json | ||
| .pre-commit-config.yaml | ||
| .semgrepignore | ||
| AGENTS.md | ||
| appcast.xml | ||
| CHANGELOG.md | ||
| CLAUDE.md | ||
| CONTRIBUTING.md | ||
| docker-compose.yml | ||
| Dockerfile | ||
| fly.toml | ||
| LICENSE | ||
| node-version.d.mts | ||
| node-version.mjs | ||
| openclaw.mjs | ||
| package.json | ||
| pnpm-lock.yaml | ||
| pnpm-workspace.yaml | ||
| README.md | ||
| render.yaml | ||
| SECURITY.md | ||
| taxonomy.yaml | ||
| THIRD_PARTY_NOTICES.md | ||
| tsconfig.core.json | ||
| tsconfig.extensions.json | ||
| tsconfig.extensions.projects.json | ||
| tsconfig.json | ||
| tsconfig.scripts.json | ||
| tsconfig.ui.json | ||
| tsdown.ai.config.ts | ||
| tsdown.config.ts | ||
| VISION.md | ||
| vitest.config.ts | ||
OpenClaw 🦞 — Your assistant, on your devices, in your chats
OpenClaw is an open-source AI assistant that runs on your own computer and meets you in the channels you already use: Discord, iMessage, Slack, Teams, Telegram, WhatsApp, and 20+ more, plus native apps for macOS, iOS, Android, Windows, and Linux. One Gateway runs it as a personal assistant on a laptop or as a shared team deployment; configuration is the only difference.
Yours, with no catch. State, memory, and credentials live on your hardware. Models and agent harnesses (Claude, Codex, local models) are plugins you can swap without changing anything else. Your prompts go to the model provider and chat platforms you configure, plus any diagnostics export you enable yourself; by default OpenClaw itself phones home for nothing but a daily version check, anonymous feature statistics are opt-in, and update.checkOnStart: false disables both (what OpenClaw sends). OpenClaw is stewarded by the OpenClaw Foundation, an independent 501(c)(3), and has no paid tier, hosted service, or token. The architecture case — trusted gateway, untrusted execution, deterministic policy — is in Why OpenClaw.
Website · Docs · Getting started · Why OpenClaw · Showcase · FAQ · Vision · DeepWiki
Install
The installer supports macOS, Linux, and Windows. It provisions a supported Node.js runtime when needed.
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash
# Windows PowerShell
iwr -useb https://openclaw.ai/install.ps1 | iex
Already manage Node.js? Install the published package instead (Node 24.16+ or 26.1+):
npm install -g openclaw@latest --allow-scripts=openclaw
That command is for npm 12 or npm 11.16+. On npm 11.15 and earlier, omit
--allow-scripts=openclaw. See the
installation guide for the lifecycle script
contract, Docker, Nix, and other deployment paths.
Quick start
On a fresh install, the installer scripts start onboarding automatically. Complete the wizard they open. If you installed the package directly with npm, pnpm, or Bun, run:
openclaw onboard --install-daemon
After onboarding:
openclaw gateway status
openclaw dashboard
Onboarding verifies model access, creates the workspace, and configures the Gateway. The last command opens the Control UI; send a message there to confirm the assistant is working. See the getting started guide for channel setup and troubleshooting.
How it fits together
- The Gateway is the local control plane for sessions, tools, events, and channel connections.
- The Control UI, CLI, and TUI connect to the Gateway.
- Channels bring the assistant to WhatsApp, Telegram, Slack, Discord, Google Chat, Signal, iMessage, and other messaging services.
- Companion apps and nodes add voice, Canvas, camera, screen, and device-local actions on supported platforms.
OpenClaw works with hosted and local model providers. Its tools, skills, and plugins extend what an assistant can do.
Security
Treat inbound messages as untrusted input. DM-capable channels pair unknown senders by default; approve a pairing request with openclaw pairing approve <channel> <code>.
Tools run on the host for the main session unless you configure sandboxing. Read the security guide, exposure runbook, and sandboxing guide before connecting other users or exposing the Gateway remotely.
Documentation
| Goal | Start here |
|---|---|
| Configure models and auth | Models · Model providers |
| Connect a messaging service | Channels |
| Add tools, skills, and plugins | Tools · Skills · Plugins · ClawHub |
| Run apps and device nodes | Platforms · Nodes |
| Use the CLI and chat commands | CLI reference · Slash commands |
| Configure or operate the Gateway | Configuration · Architecture · Updating · Release channels |
Development
The repository is a pnpm workspace. Plain npm install at the repository root is not supported.
git clone https://github.com/openclaw/openclaw.git
cd openclaw
pnpm install
pnpm build
pnpm ui:build
See CONTRIBUTING.md for the contribution workflow and the source setup guide for the development loop.
Governance
OpenClaw is developed in the open by the OpenClaw Foundation, an independent 501(c)(3). The Foundation employs the core team and signs releases. Donors and infrastructure sponsors support the Foundation; none of them own or direct the project. OpenAI is a donor, not an owner.
Community
See CONTRIBUTING.md for maintainers and contribution guidelines; AI-assisted PRs are welcome.
Use the issue chooser for bugs and feature requests, ask setup questions in Discord, and report vulnerabilities through SECURITY.md. New capabilities usually belong in plugins built on the plugin SDK and shared through ClawHub.
OpenClaw was built for Molty, a space lobster AI assistant, by Peter Steinberger and the community. Explore the project lore, soul.md, Peter's site, Star History, and @openclaw.
Special thanks to Mario Zechner for his support and for pi, and to Adam Doppelt for the lobster.bot domain.
Donors and sponsors
The Foundation is funded by donors including the University of Michigan, OpenAI, Amazon, Red Hat, Offline Holdings, and Lobster Computer Company, with infrastructure support from GitHub, NVIDIA, Vercel, Blacksmith, and Convex.
Contributors
Thanks to all clawtributors:
License
MIT © OpenClaw Foundation. See THIRD_PARTY_NOTICES.md for incorporated or adapted code.