mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 01:29:56 +00:00
Related: #154370 ## What Problem This Solves Fixes memory reads returning contents outside an authorized directory when that directory is replaced between path admission and the actual read. ## User Impact Memory reads and transient retries stay bound to the admitted filesystem root. Existing contained workspace aliases, strict extra-directory rules, hardlinks, literal filenames, Markdown/glob restrictions, file-size behavior, and missing-file versus I/O-error results remain supported. ## Why This Change Was Made The memory reader now retains the existing fs-safe Root through the content read and retry, replacing separate path checks followed by an unrelated absolute-path read. This removes duplicate containment helpers without changing configuration, stored formats, or public memory APIs. The existing `memory_get` and remote-worker routes continue to call the same reader. ## Evidence - Two real directory-substitution cases returned outside contents on the original implementation and now refuse the substituted data. Existing compatibility controls also passed on the original source. - Final focused proof passed 40 cases in 73.022 seconds. The changed reader suite passed all 15 cases with `node scripts/run-vitest.mjs packages/memory-host-sdk/src/host/read-file.test.ts --maxWorkers=1 --reporter=verbose` in 59.985 seconds wall time. Cold preparation differs between runs; no speed comparison is claimed. - Coverage includes contained workspace aliases, rejected extra-root aliases, hardlinks, literal `~`, Markdown/glob admission, transient `EAGAIN` retries, propagated `EIO`, and missing/error distinctions. - All selected check components passed across the initial runs and targeted lint corrections, including core and all 25 test type graphs, dead exports, formatting, and the remaining guards. The final ten-command recovery run passed in 583.501 seconds; the original failing check command is not represented as a pass. - Earlier review findings about retry and I/O propagation were fixed. The final review's Markdown-widening claim was rejected after source inspection: `matchesDirectory` still requires `.md`, its directory branch requires that predicate, and the retained `note.txt` rejection case passes. Raw review findings were preserved; there are no accepted actionable findings. The final lint edit only omitted an identical default `void` type argument. - Proof used synthetic local files on macOS. No Windows or live-Gateway execution is claimed. |
||
|---|---|---|
| .. | ||
| acp-core | ||
| agent-core | ||
| ai | ||
| gateway-client | ||
| gateway-protocol | ||
| llm-core | ||
| markdown-core | ||
| media-core | ||
| media-generation-core | ||
| media-understanding-common | ||
| memory-host-sdk | ||
| mermaid-renderer | ||
| model-catalog-core | ||
| net-policy | ||
| normalization-core | ||
| plugin-package-contract | ||
| plugin-sdk | ||
| retry | ||
| sdk | ||
| session-url-contract | ||
| terminal-core | ||
| tool-call-repair | ||
| workboard-contract | ||