OpenClaw merged PR #168889, a high-priority update fix for large agent databases and managed Gateway services with custom heap limits.
The bug showed up during updates. A managed Gateway could be running with a sufficient Node heap limit, but the update child processes used for candidate rehearsal, activation Doctor, recovery, and verification could lose those heap controls. In another edge case, an empty service NODE_OPTIONS could erase a caller-supplied heap override.
The result was a confusing failure mode: the service had enough memory, but the updater children could run out of heap while Doctor checked a large database.
What Changed
The update service-state reader now projects the effective command's heap flags into the captured environment used by update children. It uses the existing heap parser rather than inventing a new configuration surface.
Service command-line heap flags keep precedence over NODE_OPTIONS. If the service has an empty NODE_OPTIONS value, OpenClaw now preserves the caller's heap controls while still clearing inherited preload and debugger flags as intended.
The fix does not add a new option, dependency, database migration, or update marker. It improves how existing service facts are carried into existing update phases.
Why It Matters
Update reliability depends on matching the runtime conditions that operators already set for their Gateway. If a service needs a larger heap to manage a big agent database, the update path should not silently forget that constraint at the moment it runs Doctor or recovery.
The practical benefit is strongest for installations with:
- Large agent databases.
- Managed Gateway services using explicit heap flags.
- Update rehearsals that run Doctor before activation.
- Recovery or verification phases launched as child processes.
There is also an important limit: this protection must exist in the updater that is already installed before the update starts. An older updater cannot acquire this behavior from the candidate it has not safely activated yet.
Proof From The PR
The PR includes real child-process assertions that NODE_OPTIONS carries the expected heap control. All four targeted cases assert that the final old-space flag is --max-old-space-size=160, including service-argv precedence and clearing an inherited missing preload.
Focused tests passed under both Node 26.11.1 and Bun 1.4.2. The broader unchanged-production evidence also ran 1,258 selected tests across 54 files, plus changed-file checks, import-cycle checks, and relevant lint/typecheck work.
The PR is careful not to overclaim. It explicitly says no live 7 GB database or operator Gateway was used, and it does not speculate on unrelated database-maintenance causes. The implemented fix is the heap-control inheritance path.
Bottom Line
PR #168889 makes OpenClaw updates respect the service memory posture operators already chose. That should reduce update-time Doctor heap failures on larger installations without changing configuration or database behavior.