open-source.log — 27 contributions · /open-source

OPEN SOURCE · ISSUES · REPRODUCTIONS · PRS

OPEN SOURCE.

Bugs I reported, traced, or fixed in public projects. Each row links to the issue, comment, or PR on GitHub.

2 merged PRs4 done issues2 open issues19 reproductions

Ordered by impact: reach, outcome, severity, and evidence, scored 0–9.

Upstream: OpenClaw, Codex, Claude Code, OpenCode 19

OpenClaw 1

MERGEDopenclaw/openclaw.ai #85 PR · squash-merged as bfc0bd9fix(installer): consolidate windows install reliabilityRewrote the Windows install checks in OpenClaw's official installer; Get-OpenClawCommandPath, Get-NpmGlobalBinCandidates and Invoke-OpenClawCommand still run in openclaw.ai/install.ps1.Impact: Every Windows user who installs OpenClaw with the official command runs this code. The openclaw npm package it installs was downloaded 70.3 million times between the merge (2026-03-02) and 2026-09-27, on all platforms.Merged commit (Software Heritage) ↗Source commit 5c47d98 ↗Live install.ps1 ↗Install docs ↗

Why this row links to archives: github.com/openclaw/openclaw.ai returns 404 since mid-2026, and GitHub hid its PRs with it. Four independent records show the merge:

GH Archive (public log of all GitHub events)th3nolo opens PR #85 on openclaw/openclaw.ai from branch fix/windows-install-minimal-v3
Software Heritage (permanent source-code archive)main gets commit bfc0bd9 "fix(installer): consolidate windows install reliability (#85)", author th3nolo, committer GitHub (squash merge). Its install.ps1 is byte-identical to my commit 5c47d98; the commit before it has none of the three functions.
Wayback Machinesnapshot of openclaw/openclaw.ai PR #84, the round before #85
openclaw.ai/install.ps1 (live)the three functions still run, compared line by line below
Compare my commit with the live installer

Left: public/install.ps1 in merge commit bfc0bd9 (2026-03-02), from the Software Heritage copy; it is the same file as my commit 5c47d98. Right: the file served at openclaw.ai/install.ps1, fetched 2026-09-28 04:18 UTC. = marks a line that is the same in both files. + marks a line OpenClaw added later.

Get-NpmGlobalBinCandidates16/16 of my lines · identical
PR #85 as merged (bfc0bd9) · lines 182–197MatchLive openclaw.ai/install.ps1 · lines 1209–1224
182function Get-NpmGlobalBinCandidates {same line1209function Get-NpmGlobalBinCandidates {
183 param(same line1210 param(
184 [string]$NpmPrefixsame line1211 [string]$NpmPrefix
185 )same line1212 )
186same line1213
187 $candidates = @()same line1214 $candidates = @()
188 if (-not [string]::IsNullOrWhiteSpace($NpmPrefix)) {same line1215 if (-not [string]::IsNullOrWhiteSpace($NpmPrefix)) {
189 $candidates += $NpmPrefixsame line1216 $candidates += $NpmPrefix
190 $candidates += (Join-Path $NpmPrefix "bin")same line1217 $candidates += (Join-Path $NpmPrefix "bin")
191 }same line1218 }
192 if (-not [string]::IsNullOrWhiteSpace($env:APPDATA)) {same line1219 if (-not [string]::IsNullOrWhiteSpace($env:APPDATA)) {
193 $candidates += (Join-Path $env:APPDATA "npm")same line1220 $candidates += (Join-Path $env:APPDATA "npm")
194 }same line1221 }
195same line1222
196 return $candidates | Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -Uniquesame line1223 return $candidates | Where-Object { -not [string]::IsNullOrWhiteSpace($_) } | Select-Object -Unique
197}same line1224}
Get-OpenClawCommandPath13/13 of my lines · identical
PR #85 as merged (bfc0bd9) · lines 154–166MatchLive openclaw.ai/install.ps1 · lines 1082–1094
154function Get-OpenClawCommandPath {same line1082function Get-OpenClawCommandPath {
155 $openclawCmd = Get-Command openclaw.cmd -ErrorAction SilentlyContinuesame line1083 $openclawCmd = Get-Command openclaw.cmd -ErrorAction SilentlyContinue
156 if ($openclawCmd -and $openclawCmd.Source) {same line1084 if ($openclawCmd -and $openclawCmd.Source) {
157 return $openclawCmd.Sourcesame line1085 return $openclawCmd.Source
158 }same line1086 }
159same line1087
160 $openclaw = Get-Command openclaw -ErrorAction SilentlyContinuesame line1088 $openclaw = Get-Command openclaw -ErrorAction SilentlyContinue
161 if ($openclaw -and $openclaw.Source) {same line1089 if ($openclaw -and $openclaw.Source) {
162 return $openclaw.Sourcesame line1090 return $openclaw.Source
163 }same line1091 }
164same line1092
165 return $nullsame line1093 return $null
166}same line1094}
Invoke-OpenClawCommand13/13 of my lines · same code + 4 lines added later
PR #85 as merged (bfc0bd9) · lines 168–180MatchLive openclaw.ai/install.ps1 · lines 1096–1112
168function Invoke-OpenClawCommand {same line1096function Invoke-OpenClawCommand {
169 param(same line1097 param(
170 [Parameter(ValueFromRemainingArguments = $true)]same line1098 [Parameter(ValueFromRemainingArguments = $true)]
171 [string[]]$Argumentssame line1099 [string[]]$Arguments
172 )same line1100 )
173same line1101
174 $commandPath = Get-OpenClawCommandPathsame line1102 $commandPath = Get-OpenClawCommandPath
175 if (-not $commandPath) {same line1103 if (-not $commandPath) {
176 throw "openclaw command not found on PATH."same line1104 throw "openclaw command not found on PATH."
177 }same line1105 }
178same line1106
179 & $commandPath @Argumentssame line1107 & $commandPath @Arguments
added later1108 $exitCode = $LASTEXITCODE
added later1109 if ($exitCode -ne 0) {
added later1110 throw "openclaw $($Arguments -join ' ') failed with exit code $exitCode."
added later1111 }
180}same line1112}

Check it yourself:

curl -s https://openclaw.ai/install.ps1 | grep -n "^function Get-NpmGlobalBinCandidates\|^function Get-OpenClawCommandPath\|^function Invoke-OpenClawCommand"

Codex 13

REPROopenai/codex #40357 comment on[Windows] Chrome plugin clean reinstall leaves stale chrome-native-hosts-v2 entries and fails with missing codexCliPathShowed that all 23 manifest entries contain nodePath but point to deleted runtimes, so "missing required path" means a stale target, not a missing field.Impact: Showed the error text is misleading: the path is there, but it points to a runtime that was deleted.OPENopenai/codex #34801 issueCodex Desktop: image thumbnails fail with "File stream access denied" — estuary download URL is fetched without AuthorizationReplayed the image download requests and showed that the desktop app fetches the signed download URL without the Bearer token, which the endpoint requires.Impact: Gave OpenAI the exact cause of broken image thumbnails in Codex Desktop: the app skips the login token on one download.REPROopenai/codex #30435 comment onWSL agent: bad cwd and Chrome/Computer Use unavailableReproduced the WSL browser failure on Codex Desktop 26.623 with the log line that disables browser use and the malformed Windows plugin path.Impact: Gave the exact log line that turns off browser use for WSL agents.REPROopenai/codex #30270 comment onBundled Browser/Chrome/Computer Use plugins disappear after Windows app updates due to stale bundled marketplace pathConfirmed on Codex AppX 26.825.6671.0 that the bundled marketplace is hidden by a WSL-style path and appears at once with the Windows path.Impact: Showed the fix: the plugins come back at once when the path uses the Windows form.REPROopenai/codex #35705 comment onChatGPT Chrome extension had a nodePath bug and cannot be openedReproduced the nodePath error on Codex AppX 26.825.6671.0 and linked it to the stale manifest and plugin cache issues, not to the Chrome extension.Impact: Linked the extension error to the stale-manifest bug, so one fix covers both.REPROopenai/codex #41592 comment on[Windows] Chrome extension fails to start: app-server manifest missing required nodePath after Codex data-directory migrationReproduced the nodePath error on Codex AppX 26.825.6671.0 without a data-directory migration and traced it to stale runtime entries in the app-server manifest.Impact: Showed the bug happens without moving the data folder, so the Codex team can rule that cause out.REPROopenai/codex #33738 comment onManaged bundled marketplace snapshot remains stale after app update, causing Browser reinstall to select the old plugin versionReported a variant where the bundled plugin source is current but registered with a WSL-style path, so a reinstall keeps the old cached version.Impact: Found a new form of the bug: a WSL-style path hides the current plugin after an update.REPROopenai/codex #21116 comment onBug Report — Codex runtime bundle not provisioned (bundleVersion=null)Downloaded and checked the runtime archive by hand (checksum matched, extraction worked), which points the failure at the app's provisioning step.Impact: Proved the download itself is fine (checksum matched), so the bug is in the app's setup step.REPROopenai/codex #26792 comment onBundled plugins (browser/computer-use) silently break after every MS Store auto-update — incomplete marketplace sync + stale config cascadeAdded a Codex AppX 26.825.6671.0 data point: the source advertises one plugin version, the cache holds older ones, and a reinstall does not fix it.Impact: Showed that a reinstall does not fix it, so users need a real patch.REPROopenai/codex #39562 comment onCodex receives in-app browser ambient state but browser control tools are not exposed to the agentTested the Browser Plugin bootstrap on Codex AppX 26.825.4187.0 and reported that in-app browser control works; only the direct Playwright import fails.Impact: Corrected the report: browser control works, and only one import path fails.REPROopenai/codex #40311 comment on[Windows] node_repl lacks CommonJS default interoperability: import("playwright") failsReproduced the Playwright import error on Codex AppX 26.825.4187.0 and confirmed that the Browser Plugin still works through its own entry point.Impact: Showed that the Browser Plugin still works, so only direct Playwright imports need a fix.REPROopenai/codex #25301 comment onComputer Use is unavailable in Windows Desktop when app-server runs in WSL (`reason=wsl-disabled`)Reproduced the wsl-disabled browser gate on Codex Desktop 26.623 and showed that the WSL agent gets no browser backend while the browser pane is open.Impact: Confirmed on a newer build that WSL agents still get no browser.REPROopenai/codex #26011 comment onconfig.toml MCP paths stale after auto-update — node_repl fails with 'os error 3'Showed the same stale versioned-path bug in a second generated file, the Chrome app-server registry, on Codex AppX 26.825.6671.0.Impact: Found the same stale-path bug in a second generated file.

Blockchain 4

DONEhiero-ledger/hiero-sdk-js #3951 issuePublish 2.83.0-beta.3 to npm: contains GHSA-xq3m-2v4x-88gg (protobufjs RCE) fixVerified that the published @hashgraph/sdk package still resolved the vulnerable protobufjs 8.0.0 release after the upstream fix had already been merged, and documented the affected npm dist-tags plus a safe downstream override.Impact: Identified a release-distribution gap where downstream users could still install a dependency affected by a critical arbitrary-code-execution advisory, and gave maintainers a reproducible npm-level report showing exactly which published package remained affected.REPROhiero-ledger/hiero-sdk-js #3947 comment onchore(release): v2.83.0 beta.3Pointed out on the release PR that the npm dist-tags still resolved the vulnerable protobufjs 8.0.0 for every install.Impact: Showed that npm still installed the vulnerable version, so the fix had not reached users yet.
MERGEDOsCordero/hackathon #2 PRauth dapper wallet, ledger walletEnabled Dapper and Ledger wallet sign-in by opting in to both services in the Flow FCL discovery configuration.Impact: Users of the hackathon app could sign in with Dapper and Ledger wallets.PR #2 ↗Line 7 today ↗
Compare my PR with the repo today
PR #2 diff · flow/config.jsMatchmain today · flow/config.js
7+ "discovery.authn.include": ["0x9d2e44203cb13051", "0x82ec283f88a62e65"],same line7 "discovery.authn.include": ["0x9d2e44203cb13051", "0x82ec283f88a62e65"],

This line turns on Dapper and Ledger sign-in in Flow's wallet picker. My commit d087e08 is still the last change to this file.

DONEMetaMask/eth-phishing-detect #156384 issue[Legitimate Site Blocked] arbitrum.stackit.aiAsked MetaMask to review a phishing flag on arbitrum.stackit.ai; the site was unblocked the same day.Impact: A legitimate site was no longer blocked as phishing for MetaMask users.

Other open source 4