openclaw/docs/help
Jason O'Neal 7fffbf60b0
fix: harden package URL downloads (#85578)
* fix: harden package URL downloads

Guard package acceptance URL downloads with HTTPS-only validation, no embedded credentials, private/special-use DNS and IP rejection, manual redirect checks, bounded timeout/size limits, pinned lookup, and atomic temp-file writes. Add tooling tests for unsafe URLs, redirect validation, size limits, and successful writes.

* fix: cancel redirect response bodies before closing dispatcher

ClawSweeper P2: the redirect branch in openPackageDownloadResponse cleared
the timeout and awaited dispatcher.close() without first cancelling
response.body. Undici's close() is graceful — it waits for in-flight
requests to complete — so a malicious redirect with a slow/never-ending
body could hang the hardened downloader.

Fix: call response.body?.cancel() before dispatcher.close() to abort the
redirect body immediately.

Test: add a regression test that uses a ReadableStream with an indefinite
interval to simulate a hanging body, and asserts cancel() was called.

Refs: clawsweeper review on PR #85512

* test: harden redirect body cancellation race in regression test

Guard the ReadableStream controller.enqueue() call with a cancelled
flag and try/catch to prevent ERR_INVALID_STATE when the interval
fires after cancel() closes the controller.

* fix: cancel final response body before closing dispatcher in downloadUrl

ClawSweeper P2: the HTTP-error and declared-oversize early-exit paths
in downloadUrl threw before consuming or canceling response.body. The
finally block then cleared the timeout and awaited graceful
dispatcher.close() with the body still open, allowing a slow/never-ending
response to hang release tooling.

Fix: add response.body?.cancel() in the finally block before
dispatcher.close().

Tests: add two regressions:
- HTTP 500 with slow body: asserts cancel() called before dispatcher close
- Declared content-length oversize with slow body: same assertion

* fix: add trusted package URL source policy

* fix: keep package URL resolver dependency-free

* test: cover encoded IPv6 package URL bypasses

* docs: sync package acceptance source overview

* docs: restore release doc formatting

* docs: sync package acceptance trusted-url source

* test: cover dotted IPv4 embedded IPv6 package URLs

* fix: parse dotted IPv4 embedded in IPv6 package URLs

* test: isolate anthropic pruning defaults

* test: move anthropic dated model coverage

---------

Co-authored-by: Peter Steinberger <steipete@gmail.com>
2026-05-23 17:28:29 +01:00
..
debugging.md Revert "refactor: move runtime state to SQLite" 2026-05-13 13:33:38 +01:00
environment.md docs: absorb documentation PR sweep 2026-05-23 10:23:34 +01:00
faq-first-run.md fix(anthropic): migrate 1M context to GA handling 2026-05-23 12:29:31 +01:00
faq-models.md fix: prune retired model catalog entries 2026-05-23 16:46:59 +01:00
faq.md fix(agents): simplify subagent completion handoff 2026-05-23 13:50:08 +01:00
gpt55-codex-agentic-parity-maintainers.md fix(qa-lab): refresh parity model targets 2026-05-17 23:12:26 +08:00
gpt55-codex-agentic-parity.md fix(qa-lab): refresh parity model targets 2026-05-17 23:12:26 +08:00
index.md docs: typography hygiene across 5 pages 2026-05-05 20:04:12 -07:00
scripts.md docs: audit and fix 3 pages (typography across help/channels) 2026-05-05 21:28:47 -07:00
testing-live.md fix: route openai video edits to edits endpoint 2026-05-23 01:27:06 +01:00
testing-updates-plugins.md fix: harden package URL downloads (#85578) 2026-05-23 17:28:29 +01:00
testing.md fix: harden package URL downloads (#85578) 2026-05-23 17:28:29 +01:00
troubleshooting.md docs: refresh contributor docs 2026-05-22 22:58:27 +01:00