Independent OpenClaw reporting, releases, guides, and community coverage
OpenClaw News

OpenClaw Fixes Windows Update Lease Rollbacks

OpenClaw PR #162245 fixes a Windows updater rollback path caused by rounded NTFS lease identities during 2026.9.6 to 2026.9.7 upgrades.

Filed under Posts 3 min read Updated Oct 1, 2026
OpenClaw Fixes Windows Update Lease Rollbacks

OpenClaw merged a P0 update-path fix early Thursday for Windows users moving from 2026.9.6 to 2026.9.7. PR #162245, titled "fix(update): accept legacy numeric lease identities once, then pin exact bigint identities," targets a rollback failure in the managed update handoff.

The bug was narrow, but high impact. A Windows 2026.9.6 updater could pass all candidate checks, publish 2026.9.7, and then roll back when the first delegated live Doctor reported that the candidate executor binding did not match its parent. The underlying cause was an identity-format mismatch: the older updater passed a numeric NTFS lease identity, while newer candidate code compared against bigint-based identity strings.

What Changed

The fix accepts the legacy numeric lease identity at one specific point: initial admission from the older driver. That acceptance is not an ongoing loosening of the update boundary. After the candidate admits the legacy handoff, OpenClaw pins exact bigint identities for subsequent file and parent-directory checks.

That matters because update leases protect the handoff between an installed updater, the candidate package, Doctor checks, and the final replacement steps. If the boundary is too strict, a legitimate older driver can fail the upgrade. If it is too loose, the updater could lose confidence that it is acting on the expected executor and package directory.

The PR also improves diagnostics. Lease read failures now surface their underlying errors instead of being flattened into a generic unreadable-lease classification.

Why Operators Should Care

Update reliability is one of OpenClaw's most sensitive operational surfaces. A rollback after publication is confusing even when it preserves state, because the operator sees the candidate almost succeed and then unwind at the live Doctor stage.

For Windows installations, this fix is about making the 2026.9.6 to 2026.9.7 path respect the reality of the shipped older driver. It accepts the old identity spelling once, only when it rounds to the candidate's bigint identity through the same serialization path, then resumes exact checks.

The result should be fewer false rollbacks during otherwise valid updates without weakening the custody model for the rest of the update.

Security Boundary

The PR carried both compatibility and security-boundary risk labels, which is appropriate for this part of the system. Lease identity is not just bookkeeping. It is part of how OpenClaw decides whether a live updater and a candidate package are still bound to the same installation context.

The important line is that legacy tolerance happens at admission, not everywhere. Once the bridge from 2026.9.6 is crossed, the candidate uses exact bigint identities for follow-up operations.

Evidence

The pull request documents the observed failure mode from a Windows 2026.9.6 to 2026.9.7 update and ties it to the managed-update lease-directory identity change introduced in earlier update work. The patch keeps the update owner responsible for comparing identities, records the one-hop compatibility tradeoff at that comparer, and preserves later exact matching.

This is the kind of P0 repair that may not change the daily interface, but it directly affects whether users can safely get onto the current release line. For Windows operators who hit the rollback path, the update should now recognize the legitimate older-driver handoff and continue with stricter candidate-owned identity checks.

Daily Briefing

Get the Open-Source Briefing

The stories that matter, delivered to your inbox every morning. Free, no spam, unsubscribe anytime.

Join 45,000+ developers. No spam. Unsubscribe anytime.