ShadowClaw 1.3.1¶
Three commits landed on main after the v1.3.0 tag and none of them moved
the version, so a build from main called itself 1.3.0 while behaving
differently from the thing that tag points at. packaging/build.sh reads
VERSION straight out of shadowclaw/authorship.py, which means the
mislabelling reached the artifact filenames too. This release corrects
that.
A way to take the tool off the machine¶
What a 1.3.1 user has that a 1.3.0 user did not, first, is scripts/uninstall.sh
— it removes ShadowClaw from a host including the changes it made inside
other people's products. The destination it added to DefenseClaw's config
comes out through defenseclaw setup observability remove rather than by
editing config.yaml, and a dashboard installed into a Grafana that was
already running is deleted by UID, with the folder removed only when
nothing else has been filed in it. Every process match is anchored to a
path ShadowClaw owns, because Loki, Grafana, and eslogger are all things
another product may be running, and a bare pkill would take a colleague's
copy with it. The ledger survives by default. packaging/uninstall.sh
still owns the pkg payload and is delegated to rather than reimplemented.
See Uninstall.
Installing costs 418 MB less¶
Second, install.sh fetched the OpenTelemetry Collector by default, from
when every export path went through one, and install-otelcol.sh left its
89 MB archive in dist/ afterwards and never cleaned up. Neither is needed
on the documented path: Loki 3.x accepts OTLP directly, so the sensor posts
to :3100 and no collector is started. The download is now
--with-otelcol, the archive is deleted once its checksum verifies, and
make validate reports what to fetch instead of failing on a missing
binary. --skip-otelcol is still accepted, so anything written against
the old default keeps working.
The dashboard survives real data volume¶
Third, Loki aborts a query whose result exceeds its 4 MB default gRPC ceiling, and Grafana renders that failure exactly like an empty result, so a panel reads "No data" with the reason only in Loki's log. The trigger is how many findings fall in the window rather than anything about the query, which is why panels that had worked for weeks went dark together without being edited.
An unwrapped range aggregation keeps every label of every matching line as
its own series unless it names a grouping, and a finding carries about
fifty-five labels, so by () is the difference between shipping tens of
thousands of series and shipping one number. All sixteen unwrapping targets
carried the same latent bug, not just the panel that was noticed. See
Raise the gRPC message limits
and
Writing queries that scale.
Patch rather than minor¶
Nothing here touches detection. No signal, threshold, or score changed; no event was added, renamed, or reshaped; no telemetry attribute moved. Anything parsing ShadowClaw's output against 1.3.0 needs no change to read 1.3.1. This is tooling, packaging, and dashboards — which is also why it is worth releasing on its own rather than waiting to ride along with a detection change.
One caveat outlives the release¶
The findings-log panel is a logs panel, and showing every field when a line
is expanded is its entire purpose, so there is nothing to aggregate away —
it needs Loki's ceiling raised instead. Both halves of the failing hop have
to move, since the querier's client to the query frontend carries a
separate 4 MB default that the server setting does not cover. That
configuration lives outside this repository — loki.yaml is written by the
operator, and scripts/ShadowclawAI errors if it is absent — so upgrading
to 1.3.1 does not fix that panel on a host that has not applied it. The
requirement is documented in the
DefenseClaw integration.
Verification¶
The attribution digest is unchanged, and that is correct rather than an
oversight: it covers the product and author constants and deliberately not
VERSION, so cutting a release cannot disturb the tamper evidence. Verified
through the documented path, python3 -m shadowclaw --about, which reports
the computed and expected digests as equal. 807 tests pass.