Finding / openclaw
2026-09-21-openclaw-the-workspace-symlink-then-boundary-fix-is-in-stable-not-in-extended-stable
The workspace symlink-then-.. boundary fix is in stable, not in extended-stable. The profile’s standing “fixed in no release on any channel” is false as of 2026-08-31 for latest/beta. It stays true for extended-stable 2026.7.35. The maintainers’ own caveat (validation-time check, not race-safe) is unchanged. A related advisory, GHSA-5rx7-34fw-64qg (“Unicode fallback could escape workspaceOnly roots”, medium 5.3), is patched in 2026.8.1: on filesystems with canonically equivalent sibling directory names, a missing in-workspace path could be retried against a sibling outside the root. That escape needs no symlink.
Channel: tagged-release (not in extended-stable). Half: defect. Date: 2026-08-31 (first stable); merge 2026-07-27.
Operator consequence: On stable, the workspace root is a validation-time barrier, not a race-safe one. On extended-stable it is still hygiene only. Update the profile’s avoid_for line to name the channel rather than “every channel”.
Receipt
Finding metadata
Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0
Finding ID: 2026-09-21-openclaw-the-workspace-symlink-then-boundary-fix-is-in-stable-not-in-extended-stable
Profile citations
- OpenClaw / claim / workspace-boundary-fix-stable
Source links
Primary links, including exact changelog lines when available.
- tagged commit file2026-09-21-openclaw-the-workspace-symlink-then-boundary-fix-is-in-stable-not-in-extended-stableopenclaw/openclaw / src/agents/sandbox-paths.tsmerged pr2026-09-21-openclaw-the-workspace-symlink-then-boundary-fix-is-in-stable-not-in-extended-stablegithub.com/openclaw/openclaw/pull/113405