OpenClaw merged a P1 update reliability fix this morning: PR #164769, "fix(update): complete the package swap across devices instead of rolling back on EXDEV". The change is aimed at npm-global installations where Docker OverlayFS refuses a package directory rename with EXDEV.
That error is a classic filesystem boundary problem. A rename that works on one device can fail when the source directory lives in an image layer and the target operation crosses into a different device or overlay boundary.
What Changed
The PR teaches future npm-global update drivers to recover from the first EXDEV by copying the candidate into an operation-specific sibling, persisting that copy, and verifying it before publication continues.
The fallback does not blindly copy and hope. The PR says OpenClaw verifies the copied contents, inventory, links, permissions, and ownership, then records the copy's fingerprint before retiring the original package. Publication and rollback both consume that recorded fingerprint.
The existing journal format gains copy-custody intent data, but the PR explicitly says SQL tables, columns, and version are unchanged. There are no new configuration options, CLI flags, or dependencies.
Why It Matters
OpenClaw's updater has to work in environments that are messier than a developer laptop. Docker images, inherited layers, systemd services, npm global installs, and rollback expectations all collide in production.
Before this fix, an otherwise valid candidate could be forced into rollback because the underlying filesystem refused a rename that could never succeed. With the new fallback, future drivers can complete the swap through a verified copy path instead of retrying an impossible operation.
The user-facing impact is narrow but important:
- Image-layer npm installations can update in place when the fixed driver is already in control.
- Rollback keeps a verified copy instead of relying on a failed rename path.
- Copy-inventory mismatches leave the original package intact.
- The fallback warns instead of repeatedly attempting the same impossible rename.
The First-Hop Caveat
The PR includes a crucial operational note: the first hop from 2026.9.7 or 2026.9.8 still needs the manual path. Those installed drivers execute their own publication owner before a fixed candidate can take over.
That means operators on those versions should rebuild the Docker image with a release containing this fix, or follow the documented backup and service-stop precautions before running npm install -g openclaw@<version> inside the container.
Verification
The validation matrix is broader than a single happy-path test. The PR reports publication-boundary coverage for commit, rollback, corrupt-copy refusal, lost acknowledgments, partial source removal, and journal recovery. It also reports explicit E2E package override and installed-updater self-replay checks.
There is one honest limitation: the PR says a Linux Docker overlay2 image-layer npm-global update with a systemd user service remains unproven because the required remote infrastructure was unavailable. That candor is useful. The filesystem boundary is still directly tested through injected EXDEV, and the production Docker lane remains a follow-up proof point.
For OpenClaw operators maintaining containerized npm-global deployments, PR #164769 is a meaningful step toward safer updates across real filesystem boundaries.