fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix: add test env bypass to API validation functions - #1459

Closed
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability
Closed

fix: add test env bypass to API validation functions#1459
la14-1 wants to merge 6 commits into
mainfrom
fix/openclaw-reliability

Conversation

@la14-1

Copy link
Copy Markdown
Collaborator

Summary

Follow-up to #1456 (fix/openclaw-reliability) addressing remaining review feedback:

  • verify_openrouter_model() and verify_openrouter_key() in shared/common.sh now skip live network calls when BUN_ENV=test or NODE_ENV=test, in addition to the existing SPAWN_SKIP_API_VALIDATION check
  • This prevents test hangs from unexpected live API calls in CI/test environments
  • The other two review items (quoting escaped_cmd in install_agent() and json_escape() on model_id in _generate_openclaw_json) were already addressed in the prior commit ad425ba

Test plan

  • bash -n shared/common.sh passes
  • bun test confirms no new failures introduced (all failures are pre-existing on the branch)

-- refactor/pr-maintainer

🤖 Generated with Claude Code

AhmedTMMand others added 6 commits February 18, 2026 03:44
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…formance
Fixes multiple issues causing openclaw to break on most clouds:
Bugs fixed:
- Double-prefixed model ID (openrouter/openrouter/auto) in config generation
- AWS gateway starting without env vars (missing .zshrc source)
- DigitalOcean sourcing .spawnrc instead of .zshrc for gateway
- Destructive rm -rf ~/.openclaw on re-runs (now mkdir -p)
Validation added:
- API key checked against OpenRouter /auth/key endpoint with re-prompt on failure
- Model ID verified against OpenRouter model list with re-prompt loop
- openrouter/auto and openrouter/free bypass model check
Reliability improvements:
- Standardized gateway launch with </dev/null & disown across all 9 clouds
- Gateway log auto-displayed on startup timeout for diagnostics
- 2GB swap added to cloud-init to prevent OOM on small VMs
- Portable install timeout (10 min) with macOS gtimeout fallback
Performance:
- Reordered spawn_agent: OAuth runs while VM provisions (saves 30-60s)
- Fly.io: bumped to 2GB RAM + 2 shared CPUs for openclaw
- Fly.io: tries bun first (faster), falls back to npm
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Keep both: our swap + OAuth reorder, and upstream's Node.js v22 upgrade.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… cmd
- Add SPAWN_SKIP_API_VALIDATION=1 bypass to verify_openrouter_key/model
- Quote escaped_cmd in install_agent timeout wrapper
- Add json_escape() for model_id in openclaw JSON config
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
- Extend verify_openrouter_model() and verify_openrouter_key() to skip
live API calls when BUN_ENV=test or NODE_ENV=test (in addition to
existing SPAWN_SKIP_API_VALIDATION check)
- Prevents test hangs from network calls in CI/test environments
- Note: escaped_cmd quoting and json_escape(model_id) were already
addressed in prior commit ad425ba
Agent: pr-maintainer
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

The branch has merge conflicts with main (shared/common.sh diverged significantly due to recent security fixes merged to main). The rebase is non-trivial — manual resolution needed. The commits on this branch that need to land:

  • ad425ba fix: address security review feedback (quoting, json_escape, SPAWN_SKIP_API_VALIDATION)
  • 4d84526 fix: skip sudo in gh install when running as root (Fly.io containers)
  • 75bb623 fix: add BUN_ENV/NODE_ENV test bypass to API validation functions

The primary fixes from the security review are in place. A human reviewer should resolve the shared/common.sh conflict before merging.

-- refactor/team-lead

@la14-1

Copy link
Copy Markdown
CollaboratorAuthor

Closing this PR as it is superseded by #1460, which is on the same branch (fix/openclaw-reliability) and contains all commits from this PR plus additional reliability fixes (double-escaping fix, github-auth improvements, Gemini CLI routing, graceful error handling). PR #1460 is mergeable and awaiting review.

This PR has unresolvable merge conflicts with main (shared/common.sh diverged due to recent security fixes), and since #1460 already resolved those conflicts and built on top of this work, there is no value in rebasing this one separately.

-- refactor/pr-maintainer

@la14-1la14-1 closed this Feb 19, 2026
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@la14-1@AhmedTMM@louisgv