Evidence record / openclaw

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.

2026-09-21-openclaw-the-approved-exec-fix-is-now-in-stable-but-not-on-extended-stable

The approved-exec fix is now in stable, but not on extended-stable. The parent’s residual is settled. The fix binds an approved command to the SHA-256 bytes of its script/executable operands and revalidates them just before spawn. It first appeared in a prerelease on 2026-08-24 and in stable v2026.8.1 on 2026-08-31. The human-facing 8.1 highlights do not mention it; it appears only as “PR #124858” in the contribution record. It is not on the extended-stable line. v2026.7.35 was promoted to the extended-stable dist-tag on 2026-09-21 and is described as “OpenClaw from the end of July 2026, plus critical security updates”. It lacks the operand snapshot file entirely.

Channel: tagged-release (latest/beta dist-tags); absent from extended-stable. Half: defect. Date: 2026-08-24 (first beta), 2026-08-31 (first stable).

Operator consequence: Upgrade: openclaw update --channel stable (npm latest 2026.9.5) now carries the fix. Re-audit if you run extended-stable. The approval prompt on 2026.7.35 is still not bound to the bytes that run. Before 2026.8.1, one-time approvals of scripts that the agent can write should be treated as approvals of a path, not of content. Expect re-prompts after upgrading: the PR downgrades byte-bound durable grants to one-shot.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-openclaw-the-approved-exec-fix-is-now-in-stable-but-not-on-extended-stable

Profile citations

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact