PPradeep Elankumaranfix: allow tab creation recovery to finish
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix: submit Amazon continuation before waiting | 20 天前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix(cookies): contain resolved cookie paths Co-authored-by: Sebastion <sebastion@sebastion.dev> | 1 个月前 | |
fix: recover mouse fallback actionability errors | 20 天前 | |
fix: stop faking direct session location Fixes #10667 | 16 天前 | |
fix: normalize uppercase enter key | 20 天前 | |
Stabilize browser e2e teardown | 3 个月前 | |
fix: restore CI startup dependencies | 4 个月前 | |
fix(click): bound boundingBox() in mouse-sequence fallback to prevent 30s handler timeout 500s When a normal click attempt fails because the element detached after a page change (SPA re-render between snapshot and click), the mouse-sequence fallback called locator.boundingBox() with no timeout. Playwright waited its default 30s for the element to resolve, blowing the entire HANDLER_TIMEOUT_MS budget and surfacing as: click failed: action timed out after 30000ms -> 500 internal error Worse, that generic 'timed out after' error is classified by isTimeoutError() as a navigation timeout, so handleRouteError() destroyed the whole user session (fresh proxy/context) over a stale ref. Fix: - boundingBox() is now bounded to min(3s, remaining handler budget), floored at 500ms. - On timeout it throws a 422 'Element not actionable' error whose message deliberately avoids the 'timed out after' phrase, so the session survives and the client gets an actionable hint (snapshot + retry) in ~3s instead of a 500 after 30s. Adds tests/unit/clickBoundingBoxTimeout.test.js covering the source contract (no bare boundingBox() calls), the budget math, and the error classification. | 3 个月前 | |
test: retry recoverable browser restarts | 11 天前 | |
feat: automate Windows cleanup and PDF retrieval Fixes #10042\nFixes #9333\nFixes #9334 | 16 天前 | |
fix: make consent dismissal explicit and scoped | 1 个月前 | |
Fix cookie test server teardown race | 3 个月前 | |
test: update tests for telemetry rename | 4 个月前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix: harden browser navigation and actions | 1 个月前 | |
fix(evaluate): route errors through handleRouteError | 1 个月前 | |
fix: support Node 24 and host dependency overrides | 1 个月前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
refactor: extract Fly helpers to lib/fly.js, rename metrics to camofox_* - Extract makeTabId/parseTabOwner/isLocalTab/replayMiddleware to lib/fly.js - server.js uses createFlyHelpers(CONFIG) — no-op when not on Fly - Rename all jo_browser_* Prometheus metrics to camofox_* (upstream-ready) - Update grafana dashboard to match new metric names - flyReplay tests now import from lib/fly.js instead of replicating logic - All 225 tests passing | 5 个月前 | |
Fall back from empty Google search results | 20 天前 | |
Health endpoint: return 503 for unexpected browser absence Tracks _lastBrowserStopReason to distinguish intentional idle/admin stops (200) from unexpected deaths like browser_disconnected, memory_pressure, browser_rss_pressure (503 + warm retry). Fly health checks will now detect and route around machines with unexpectedly dead browsers, while intentional idle shutdown still passes health checks as before. | 4 个月前 | |
test: cover disabled session and browser timeouts | 20 天前 | |
feat: add persistence helpers, inflight coalescing, bootstrap cookies Standalone library modules from PR #62: - lib/persistence.js: atomic storageState save/restore with SHA256-hashed user dirs - lib/inflight.js: coalesceInflight primitive for concurrent session creation dedup - lib/cookies.js: importBootstrapCookies helper for first-run cookie seeding - Unit tests for all three modules Co-authored-by: company8 <compan@post.com> | 5 个月前 | |
fix: guard inline PDF response size | 12 天前 | |
fix: expose combobox controls to agents | 20 天前 | |
fix: stop faking direct session location Fixes #10667 | 16 天前 | |
feat: convert to ESM, add version sync script - Convert all lib/, tests/, and config files from CJS (require/module.exports) to ESM (import/export) - Add "type": "module" to package.json - Rename jest.config.js → jest.config.cjs (Jest needs CJS config with ESM) - Add NODE_OPTIONS='--experimental-vm-modules' to test scripts - Add scripts/sync-version.js + npm version hook to keep openclaw.plugin.json in sync (fixes #26) - Sync openclaw.plugin.json version to 1.3.1 | 6 个月前 | |
fix(mcp): align adapter binary name | 1 个月前 | |
Fix jo-browser idle shutdown memory leak Prevent repeated idle cleanup ticks from resetting the browser shutdown timer, which left zero-session Camoufox processes running indefinitely. Add browser process-tree RSS checks so idle Firefox child processes trigger cleanup even when Node memory looks healthy. Also fix watchdog tab summaries to use tabGroups instead of stale session.tabs state. | 4 个月前 | |
fix: support Node 24 and host dependency overrides | 1 个月前 | |
fix: per-user nav health tracking, session-scoped recovery, single-flight race - Replace process-global healthState.consecutiveNavFailures with Map<userId, UserNavHealth> for per-user failure tracking (#9321) - Wire recordNavSuccess(userId)/recordNavFailure(userId) into all navigation routes: POST /tabs, POST /tabs/:tabId/navigate, POST /tabs/open, POST /navigate, and handleRouteError for /act (#9323) - Add recoverUserSession(userId) for session-scoped recovery instead of restartBrowser() killing all sessions on nav failures (#9322) - Remove manual browserLaunchPromise = null in restartBrowser() — ensureBrowser() owns the single-flight primitive (#8554) - Clean up per-user nav health on destroySession() - Aggregate per-user failures in /health endpoint - Add tests/unit/navHealthRecovery.test.js (8 tests) Fixes #9321, #9322, #9323 Relates to #8554 | 1 个月前 | |
feat: navigate abort on tab delete + snapshot size metrics - createTabState gets navigateAbort AbortController field - navigateCurrentPage races page.goto() with abort signal - DELETE /tabs/:tabId calls abort() before safePageClose, cancelling in-flight navigation immediately instead of waiting 30s timeout - Add camofox_snapshot_bytes histogram for snapshot size tracking - 6 new abort tests passing | 4 个月前 | |
fix: classify aborted navigation before generic network errors Signed-off-by: Bortlesboat <169967362+Bortlesboat@users.noreply.github.com> | 20 天前 | |
fix(cookies): map a session expiry onto -1 for addCookies() Netscape cookie files use `0` in the expiry field to mean "session cookie". That is the only convention the format has for it, and it is what browser exports actually contain. `parseNetscapeCookieFile()` read that field with a bare `Number(parts[4])` and handed it straight to Playwright's `context.addCookies()`, which does not read `0` as "session": it wants `-1`, and treats `0` as a Unix timestamp, so 1970-01-01. The cookie is expired the moment it is added and Playwright drops it. Nothing surfaces that. The import still reports every cookie as imported and the caller sees a success; the cookie is simply never attached to any later request. Because session cookies are the common case in exported files, this hits ordinary usage rather than an edge case. Anything that is not a positive finite number now maps to -1. That also covers an unparsable expiry, which used to yield NaN and be rejected by addCookies() outright. The tests no longer reimplement the parser. They carried a second copy of it with a comment asking that any change be mirrored by hand, which is exactly how a parser and its tests can agree perfectly while both being wrong: the old suite asserted `expires: 0` and a NaN, so it passed on the broken behaviour. They now import the shipped parser through `lib/cookies.js`, and three cases cover session, negative and unparsable expiries. | 20 天前 | |
test(sessions): assert page lease return | 1 个月前 | |
fix: update test to match telemetry deploy branch rename | 4 个月前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix(openclaw): use direct Camoufox downloader | 11 天前 | |
fix(openclaw): use current plugin API | 15 天前 | |
Normalize browser operational failures ref JO-2731 | 3 个月前 | |
Merge branch 'fix/session-page-leases' into master Fixes #8555 | 1 个月前 | |
fix(plugins): scope virtual display providers Thanks to @shauneccles for reporting #9527 and identifying the filesystem-order collision. | 20 天前 | |
fix: stop broadcasting typed text to plugins The tab:type plugin event carried req.body.text verbatim, and lib/plugins.js documented text as part of the public plugin contract. The text typed into a login form is a password, so any subscribing plugin received credentials it never asked for. No shipped plugin subscribes, so nothing in-tree relies on it. Emits textLength instead. The payload is built by a pure helper next to the contract it implements, so the shape is unit-testable without a server. This is a contract change: a plugin reading event.text now reads undefined. | 20 天前 | |
fix(vnc): honor ENABLE_VNC=1 over config enabled:false The plugin loader skipped plugins absent from camofox.config.json before their env override could run, and install-plugin-deps.sh dropped enabled:false plugins so the image shipped without noVNC deps. Plugins can now declare an enableEnvVar (plugins/vnc/plugin.json) that loads them when the env var is set; dependency installation no longer filters on enabled state. vnc-launcher now passes an explicit watcher env whitelist instead of spreading process.env, per CONTRIBUTING.md. Closes #4933, closes #4314 | 3 个月前 | |
fix: preserve live Firefox profiles during cleanup Fixes #9584. | 20 天前 | |
feat: automate Windows cleanup and PDF retrieval Fixes #10042\nFixes #9333\nFixes #9334 | 16 天前 | |
fix: retry Firefox proxy connection failures | 20 天前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix(reporter): avoid retained request response dispatchers | 20 天前 | |
Recycle wedged idle browsers sooner | 3 个月前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix: recover navigation after browser tab closes | 20 天前 | |
feat: SSL error handling, tabNotFoundResponse, memory admission + eviction Cherry-picked from jo-browser 816d961 with jo-specific refs removed. SSL error handling: - SEC_ERROR/SSL_ERROR/MOZILLA_PKIX_ERROR → clean 502 with code: 'ssl_error', recoverable: false (in POST /tabs and POST /tabs/:tabId/navigate) tabNotFoundResponse (smarter 404/410): - Track _lastBrowserRestartAt timestamp on browser launch - Tabs lost in a browser restart return 410 Gone ("create a new tab") instead of ambiguous 404, so clients can auto-recover - Random/invalid tab IDs still get 404 Memory admission control (Fly.io only, no-ops locally): - Reject new sessions at >90% RAM with 503 - Session overflow redirect when machine exceeds fair-share cap Memory pressure eviction (Fly.io only): - 30s interval evicts oldest session when RAM >80% - Prevents OOM by proactively freeing BrowserContexts Also: fly-replay uses CONFIG.flyAppName instead of hardcoded app name. Tests updated: recycled tabs now expect 410 (browser just launched = restart window). | 4 个月前 | |
fix: support native select controls | 20 天前 | |
Await server:shutdown listeners before closing sessions gracefulShutdown() fired the server:shutdown event with plain EventEmitter#emit, which does not wait for async listeners. It then called closeAllSessions() immediately after, racing the persistence plugin's in-flight context.storageState() checkpoint against context.close() for the same session -- intermittently failing with "Target page, context or browser has been closed" and silently dropping unsaved storage state on restart. closeSession() already gets this right for session:destroying via emitAsync(); server:shutdown just wasn't using the same helper. Fixes #7162 | 2 个月前 | |
test: cover disabled session and browser timeouts | 20 天前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
test(release): synchronize MCP package version | 1 个月前 | |
Fix tabNotFoundResponse to handle Fly-prefixed tab IDs Tab IDs on Fly are '{machineId}_{uuid}'. The UUID regex check was testing the full prefixed string, always failing, so stale tabs after browser restart got 404 instead of 410. Now extracts the UUID portion before validation. | 4 个月前 | |
fix(tabs): force-close on safePageClose timeout + orphan page reaper Three fixes for the Playwright Page reference leak that causes tab creation to fail with '500: tab create timed out' under sustained concurrency: 1. safePageClose: timeout branch now rejects instead of resolving silently. Catch block attempts force-close with runBeforeUnload:false and calls page.removeAllListeners() to drop GC roots. Early-return on null/closed. 2. getTotalTabCount: uses context.pages().length (real Playwright count) instead of tabGroups bookkeeping. Leaked pages now exert backpressure on MAX_TABS_GLOBAL, surfacing the problem before Firefox OOM. 3. Orphan page reaper: 60s interval walks each session's context.pages() and force-closes any page not present in tabGroups. Catches pages that survived a safePageClose timeout or were dropped from tracking. 22 unit tests added covering all three fixes. Closes #2234 Co-authored-by: cunninghambe <cunninghambe@users.noreply.github.com> | 4 个月前 | |
fix: recover navigation after browser tab closes | 20 天前 | |
Harden tab lifecycle: stale-tab errors, lastAccess refresh, popup tracking, tab locks - Remove navigate auto-create: return 404/410 for unknown tabs per contract - Refresh session.lastAccess on all tab ops (snapshot, click, type, press, scroll, links, back, forward, refresh, wait, downloads, images, screenshot, stats, viewport) so active tabs don't hit session timeout - Add withTabLock to scroll and links routes for serialization - Register popups (target=_blank, window.open) as managed tabs via page.on('popup') attached to each managed page (no orphaned pages) - Add tabLifecycleContract test suite covering stale-tab errors, lastAccess refresh, and popup registration - Update tabRecycling test to expect 404 on navigate with unknown tab ref JO-2452 JO-2456 JO-2457 | 4 个月前 | |
fix: allow tab creation recovery to finish | 7 天前 | |
fix: preserve live Firefox profiles during cleanup Fixes #9584. | 20 天前 | |
feat: opt-in session tracing via Playwright (#68) Opt-in per-session Playwright tracing — pass trace:true on first tab, get screenshots + DOM snapshots + network in a .zip for Trace Viewer. Three new endpoints (list/download/delete), auth-protected, async fs, TOCTOU-safe streaming. 38 tests. Co-authored-by: Matt Van Horn <455140+mvanhorn@users.noreply.github.com> Co-authored-by: Jo Inc <oss@askjo.ai> | 5 个月前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix: strip all non-ASCII from shipped files (scanner unicode-control-chars) Replace all Unicode characters (em-dash, arrows, bullets, box-drawing, curly quotes, checkmarks, emoji) with ASCII equivalents across all 49 files that ship in the npm package. The ClawHub scanner generates SKILL.md from package contents and flagged unicode control characters as a potential prompt-injection pattern. All shipped files are now pure ASCII. Note: path-depth markers in reporter.js JSDoc comments changed from the original bullet (U+2022) to [path] -- using * would create nested block comment syntax errors. | 4 个月前 | |
fix(upload): contain file paths within upload directory Resolve upload paths before attaching files. Reject paths outside CAMOFOX_UPLOADS_DIR, including symlink escapes, and require regular files. Co-authored-by: Leone Parise <1442927+leoneparise@users.noreply.github.com> | 1 个月前 | |
fix(upload): contain file paths within upload directory Resolve upload paths before attaching files. Reject paths outside CAMOFOX_UPLOADS_DIR, including symlink escapes, and require regular files. Co-authored-by: Leone Parise <1442927+leoneparise@users.noreply.github.com> | 1 个月前 | |
feat: POST /tabs/:tabId/viewport for responsive testing Adds endpoint wrapping Playwright's page.setViewportSize() to trigger real CSS layout reflows. window.resizeTo() is a no-op on non-popup windows in modern browsers — this is the correct headless primitive. - Input validation: width/height must be finite numbers in 100..4000 - 150ms settle delay for SPAs (media queries, ResizeObserver) - Emits tab:viewport plugin event - Returns { ok, width, height } with rounded values Tests: 17 unit (validation) + 4 e2e (mobile/desktop/invalid/reflow). Improved validation over original PR: uses Number.isFinite() to also reject NaN and Infinity (which bypass typeof+range checks). Co-authored-by: cunninghambe <cunninghambe@users.noreply.github.com> | 4 个月前 | |
fix: prefer visible selector matches for clicks | 20 天前 | |
fix(test): discover Playwright browser process on Windows | 16 天前 |