Skip to content

feat(openshell): upgrade managed runtime to v0.0.99 - #8523

Merged
apurvvkumaria merged 40 commits into
mainfrom
codex/8497-openshell-v099-upgrade
Aug 7, 2026
Merged

feat(openshell): upgrade managed runtime to v0.0.99#8523
apurvvkumaria merged 40 commits into
mainfrom
codex/8497-openshell-v099-upgrade

Conversation

@apurvvkumaria

@apurvvkumaria apurvvkumaria commented Aug 7, 2026

Copy link
Copy Markdown
Collaborator

Summary

Upgrade NemoClaw's consumed OpenShell runtime from v0.0.85 to v0.0.99 after #8499 pinned the exact v0.0.99 release manifests. This PR pins the corresponding CLI, gateway, sandbox, supervisor, and child-visible credential identities across install, blueprint, managed-agent, Brev, and E2E paths. It also resolves v0.0.99 policy-activation incompatibilities for OpenClaw npm, Homebrew's GitHub endpoints, and Outlook's shared Microsoft endpoints.

Related Issue

Part of #8497.

Changes

  • Move OpenShell selectors and exact CLI, gateway, sandbox, and supervisor artifact identities to v0.0.99 across installer, blueprint, Hermes, Brev, and CI consumers.
  • Add the v0.0.99 child-visible credential manifest and migration review covering supported platforms, onboarding, managed MCP lifecycle, credential exposure, network policy, backup/recovery, and uninstall behavior.
  • Enforce OpenShell v0.0.99's routable sandbox-name contract (1–19 lowercase characters, no consecutive hyphens) across schema, CLI, policy/MCP boundaries, managed activation, installer upgrade preflight, and live workflows; legacy incompatible names now stop before backup, gateway retirement, OpenShell installation, or sandbox recreation and require manual state migration.
  • Reconcile OpenShell v0.0.99 policy activation: keep the Restricted OpenClaw npm baseline GET-only until npm is active, preserve approved exclusions, fail closed on drift, use automatic TLS for Homebrew's overlapping GitHub routes, and align Outlook's request-body credential rewrite with Microsoft Teams.
  • Update user documentation for v0.0.99 MCP commands, runtime identity, network-policy behavior, troubleshooting, and security behavior.
  • Add and update focused fixtures and tests that protect version selection, exact artifact verification, all-agent runtime contracts, MCP lifecycle boundaries, policy compatibility, and migration evidence.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification:
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Contributor migration and credential-boundary review is recorded in docs/security/openshell-0.0.99-migration-review.md and src/lib/actions/sandbox/openshell-child-visible-credentials.v0.0.99.json; repository-owned maintainer review routing remains authoritative.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: docs-updated
  • Evidence: docs/deployment/set-up-mcp-bridge.mdx, docs/manage-sandboxes/add-mcp-server.mdx, docs/manage-sandboxes/update-sandboxes.mdx, docs/network-policy/create-custom-policy-presets.mdx, docs/reference/architecture.mdx, docs/reference/commands.mdx, docs/reference/configure-runtime-identity.mdx, docs/reference/network-policies.mdx, docs/reference/troubleshoot-mcp-servers.mdx, docs/reference/troubleshooting.mdx, docs/security/best-practices.mdx, docs/security/openshell-0.0.72-compatibility-review.mdx, and docs/security/openshell-0.0.99-migration-review.md
  • Agent: Codex Desktop

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run validate:pr passed after refreshing origin/main when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: Focused installer, CLI, plugin, integration, and E2E-support suites passed for the legacy-name preflight, canonical validation, generated/runtime names, workflow contracts, policy/MCP boundaries, and Brev instance-name separation. The canonical-name repair passed 100 E2E-support tests and 13 MCP-policy tests. The release-evidence repair passed 17 focused tests. Revision 18ac71c45 passed 35 release/maintainer tests and 144 workflow-boundary tests. On final revision 6d5e9568a, 114 upstream GPU tests, 23 OpenShell migration/release-evidence tests, and 62 llama.cpp lifecycle tests passed; npm run typecheck:cli and npm run docs passed, normal merge hooks passed, and pre-push type/version gates passed. npm run validate:pr passed on parent revision 509a5bc60.
  • Applicable broad gate passed — npm test for broad runtime/test-harness changes; npm run check for repo-wide validation/coverage changes — command/result: npm test was attempted locally but the heavily loaded host produced widespread unrelated loopback/timing failures across untouched suites; changed-area suites pass in isolation and fresh PR CI is required.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only) — the final revision build passed with 0 errors and 2 existing Fern warnings, so this remains unchecked.
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Apurv Kumaria akumaria@nvidia.com

Summary by CodeRabbit

  • New Features

    • Added support for OpenShell 0.0.99 with updated sandbox credentials, runtime compatibility, and verified release artifacts.
    • Improved gateway inference detection across supported output formats.
    • Enforced a 19-character maximum for sandbox names.
  • Bug Fixes

    • Gateway configurations using JWT authentication now reject unsupported wildcard bindings.
    • Direct IPv6-literal MCP URLs are rejected as unqualified.
  • Documentation

    • Updated setup, migration, troubleshooting, security, and compatibility guidance for OpenShell 0.0.99.
    • Clarified gateway binding, glibc, TLS, DNS, and provider-operation limitations.
  • Tests

    • Refreshed installation, gateway, sandbox, MCP, and end-to-end coverage.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
@apurvvkumaria apurvvkumaria self-assigned this Aug 7, 2026
@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The PR upgrades NemoClaw’s OpenShell integration from 0.0.85 to 0.0.99. It updates pinned artifacts, credential manifests, compatibility rules, inference parsing, sandbox-name limits, E2E provenance, fixtures, and migration evidence.

Changes

OpenShell release identity and artifact pins

Layer / File(s) Summary
Release identity and artifact pins
.github/workflows/e2e.yaml, nemoclaw-blueprint/blueprint.yaml, scripts/*, src/lib/onboard/*, tools/e2e/*, test/*
Version defaults, artifact digests, supervisor images, sandbox allowlists, provenance values, fixtures, and version assertions now reference OpenShell 0.0.99.

Credential boundary manifest

Layer / File(s) Summary
Credential boundary manifest
agents/hermes/*, src/lib/actions/sandbox/*, test/hermes-*, test/mcp-*, test/sandbox-*, test/update-hermes-agent-script.test.ts
Hermes and sandbox integration now uses the 0.0.99 child-visible-credentials manifest and validates its declared OpenShell version.

Gateway and MCP compatibility contracts

Layer / File(s) Summary
Gateway, MCP, and runtime compatibility contracts
docs/deployment/*, docs/manage-sandboxes/*, docs/reference/*, docs/security/*, nemoclaw/src/shared/*, src/lib/actions/sandbox/*, src/lib/inference/*, src/lib/onboard/docker-gpu-patch-types.ts, test/*
Documentation and runtime contracts describe updated DNS, gateway binding, IPv6, glibc, MCP policy, inference, Docker inspect, and 19-character sandbox-name behavior.

Migration review and acceptance evidence

Layer / File(s) Summary
Migration review and acceptance evidence
docs/security/openshell-0.0.99-migration-review.md, test/openshell-0.0.99-migration-review.test.ts, ci/source-shape-test-budget.json
The migration review records release ranges, artifact provenance, boundary findings, activation details, and acceptance gates. Tests validate the documented evidence.

Estimated code review effort: 3 (Moderate) | ~30 minutes

Possibly related issues

Possibly related PRs

  • NVIDIA/NemoClaw#8499: Shares the OpenShell 0.0.99 artifact trust and manifest pinning changes.
  • NVIDIA/NemoClaw#8494: Shares changes to the Hermes MCP configuration transaction and host validation flow.
  • NVIDIA/NemoClaw#8524: Shares the installer hash-check test and OpenShell 0.0.99 manifest allowlisting.

Suggested labels: area: packaging, area: docs, area: security, area: sandbox, integration: openclaw, integration: hermes

Suggested reviewers: senthilr-nv, cv

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 10.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the primary change: upgrading the managed OpenShell runtime to v0.0.99.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/8497-openshell-v099-upgrade

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit 6d5e956 in the codex/8497-openshell... branch remains at 96%, unchanged from commit 41e7f23 in the main branch.


Updated August 07, 2026 16:31 UTC

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / low confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: PR review advisor failed: PR review advisor SDK execution failed: session: scope-risk-map-analysis omitted required analysis; turn: scope-risk-map-analysis: scope-risk-map-analysis omitted required analysis

Model lanes

  • GPT-5.6 Terra (primary): Failed
  • Nemotron 3 Ultra (second opinion): Failed

Second-opinion terminology and E2E selections are advisory. Live E2E does not run automatically for pull requests.

E2E guidance

Advisory only. A maintainer can dispatch the default E2E suite against this exact revision.

Recommended E2E: cloud-inference, cloud-onboard, full-e2e, hermes-e2e, hermes-inference-switch, llama-cpp-dgx-spark-qualification, managed-image-multiarch-startup, managed-image-protected-runtime, security-posture, bedrock-runtime-compatible-anthropic, channels-add-remove, channels-stop-start, common-egress-agent, dashboard-remote-bind, gpu-double-onboard, hermes-gpu-startup, inference-routing, issue-4434-tui-unreachable-inference, network-policy, onboard-repair (+19 more)

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@test/openshell-0.0.99-migration-review.test.ts`:
- Around line 38-41: The migration review test currently counts commit-like
tokens and checks string presence instead of validating evidence structure.
Replace the commitLedger token-count assertion with parsing of each range row,
asserting declared counts and unique commit IDs, and validate every archive,
extracted-binary, supervisor, source-commit, and manifest identity against
independent expected values tied to the 0.0.99 manifest. Update the runtime-gate
checks to assert observable behavior and artifact associations rather than
source-text occurrence.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 1c11c0a1-b81b-4f83-8022-93cd63bfa75d

📥 Commits

Reviewing files that changed from the base of the PR and between c11f455 and 89f469b.

📒 Files selected for processing (51)
  • .github/workflows/e2e.yaml
  • agents/hermes/Dockerfile
  • agents/hermes/mcp-config-transaction.py
  • docs/deployment/set-up-mcp-bridge.mdx
  • docs/manage-sandboxes/add-mcp-server.mdx
  • docs/reference/commands.mdx
  • docs/reference/configure-runtime-identity.mdx
  • docs/reference/troubleshoot-mcp-servers.mdx
  • docs/reference/troubleshooting.mdx
  • docs/security/best-practices.mdx
  • docs/security/openshell-0.0.99-migration-review.md
  • nemoclaw-blueprint/blueprint.yaml
  • scripts/brev-launchable-ci-cpu.sh
  • scripts/install-openshell.sh
  • scripts/update-hermes-agent.sh
  • src/lib/actions/sandbox/mcp-bridge-input-validation.test.ts
  • src/lib/actions/sandbox/mcp-bridge-validation.ts
  • src/lib/actions/sandbox/openshell-child-visible-credentials.v0.0.99.json
  • src/lib/onboard/docker-driver-gateway-runtime.test.ts
  • src/lib/onboard/docker-driver-gateway-runtime.ts
  • src/lib/onboard/docker-gpu-patch-types.ts
  • src/lib/onboard/openshell-feature-gate.test.ts
  • src/lib/onboard/openshell-feature-gate.ts
  • src/lib/onboard/openshell-install.test.ts
  • src/lib/onboard/openshell-install.ts
  • src/lib/onboard/openshell-version.ts
  • test/brev-launchable-ci-cpu-checksum.test.ts
  • test/candidate-compat.test.ts
  • test/deepagents-mcp-legacy-lifecycle.test.ts
  • test/e2e/live/network-policy.test.ts
  • test/e2e/live/openclaw-plugin-runtime-exdev.test.ts
  • test/e2e/live/openshell-gateway-auth-source-contract-helpers.ts
  • test/e2e/live/openshell-gateway-auth-source-contract.test.ts
  • test/e2e/live/openshell-gateway-upgrade.test.ts
  • test/fixtures/openshell-v0.0.99
  • test/hermes-doctor-config-hash.test.ts
  • test/hermes-final-image-layout.test.ts
  • test/hermes-mcp-credential-boundary-manifest.test.ts
  • test/install-openshell-version-check.test.ts
  • test/mcp-add-crash-consistency.test.ts
  • test/mcp-destroy-lifecycle.test.ts
  • test/mcp-openshell-workflow.test.ts
  • test/mcp-policy-key-ownership.test.ts
  • test/mcp-restart-policy-order.test.ts
  • test/openshell-0.0.99-migration-review.test.ts
  • test/openshell-channel-workflow.test.ts
  • test/pr-workflow-contract.test.ts
  • test/sandbox-provisioning.test.ts
  • test/sandbox-rlimit-hooks.test.ts
  • test/update-hermes-agent-script.test.ts
  • tools/e2e/mcp-workflow-boundary.mts

Comment thread test/openshell-0.0.99-migration-review.test.ts Outdated
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
@senthilr-nv

Copy link
Copy Markdown
Collaborator

@apurvvkumaria — I revalidated this review at head 58f4167c009286424096d7a2fbc3521c24059e06 against current main dd09a9ff141c621e6a04ffcd7c4c2125c0bd8f5d.

Product scope: PASS — #8497 authorizes the OpenShell v0.0.99 qualification and pin update.

GitHub merge state: BLOCKED — GitHub reports the PR mergeable, but it is behind the current base and required checks is failing. DCO and commit verification pass.

Blocking checklist

  • [P1] Handle OpenShell v0.0.99's 19-character sandbox-name limit. The exact all-agent managed activation now gets through provider creation and inference verification, confirming the new Inference: parser fix, but sandbox creation fails with name exceeds maximum length (27 > 19) for managed-activation-openclaw. Align NemoClaw validation/generated names with the supported upstream limit, add focused regression coverage, and rerun the exact activation lane.

  • [P1] Correct the DNS-pinning security claim in docs/deployment/set-up-mcp-bridge.mdx. The statement that neither path performs a second hostname resolution is not true when OpenShell's operator opt-in proxy_connect_by_hostname is enabled; v0.0.99 explicitly sends the hostname and reopens proxy-side resolution. Also, the cited proxy.rs:4697-4705 range is error handling, while the connection occurs immediately afterward. Either prove NemoClaw prohibits that option, or document the exception/residual risk and cite the actual connection path.

  • [P1] Finish the v0.0.99 fixture migration and restore required CI. Current exact-head failures include:

    • test/update-hermes-agent-script.test.ts: the pre-MCP mutation still removes the v0.0.85 manifest from a v0.0.99 fixture, so the expected missing-marker diagnostic is not produced.
    • test/installer-hash-check.test.ts: installer-sandbox-build-pin-change still searches for the v0.0.85 function text and does not mutate the v0.0.99 source.
    • test/openshell-0.0.85-migration-review.test.ts: still asserts the live blueprint min/max are v0.0.85.
    • test/e2e/support/mcp-bridge-sandbox.test.ts: still requires the v0.0.85 commit and source citations in the current MCP docs.
    • The base refresh also leaves CLI artifact workflow-boundary assertions failing across multiple E2E consumers; reconcile those contracts with current main before rerunning the gate.
  • [P2] Make the v0.0.99 migration-evidence test semantic. test/openshell-0.0.99-migration-review.test.ts currently counts 117 eight-character tokens and checks fixed strings. Parse the adjacent ranges, require unique/exact commit-ledger membership, and validate each source/archive/extracted-binary/supervisor/manifest identity against independent expectations. This also addresses the unresolved CodeRabbit finding: feat(openshell): upgrade managed runtime to v0.0.99 #8523 (comment)

  • [P2] Complete the downstream v0.0.85 compatibility audit. Revalidate and update or make version-neutral the explicit stale boundaries and user diagnostics in nemoclaw/src/shared/openshell-policy-boundary.cts, src/lib/onboard/forward-start.ts, src/lib/actions/sandbox/mcp-bridge-url-validation.ts, and agents/hermes/mcp-config-transaction.py. The migration concern ledger should also record the inference-heading and sandbox-name contract changes that the live lane exposed.

  • Refresh from current main without force-pushing, update the documentation-writer receipt for the resulting exact head, and rerun required current-head/current-base gates plus repository-produced automated review. Please resolve each checkbox as it is addressed so the follow-up review stays trackable.

I am holding approval until these items and the required GitHub gate are clear.

@apurvvkumaria

Copy link
Copy Markdown
Collaborator Author

Addressed all blockers from the maintainer review in verified commit 984d7c612 (current verified PR head 1f7ed6efc):

  • aligned canonical sandbox-name validation and generated activation fixtures with the OpenShell 0.0.99 19-character limit, with 19/20-character boundary coverage;
  • corrected the MCP DNS-pinning contract to document the proxy_connect_by_hostname exception and cite the actual default and forward connection paths;
  • refreshed the Hermes updater, installer hash, migration-review, MCP bridge, and CLI artifact fixtures/contracts to 0.0.99;
  • replaced token/string-presence evidence checks with semantic range membership, unique commit, complete artifact digest, supervisor, source commit, manifest association, parser-behavior, and sandbox-name behavior assertions;
  • updated the remaining stale 0.0.85 compatibility references and added OS99-13/OS99-14 to the migration concern ledger;
  • refreshed from current main, completed documentation-writer review, and passed npm run validate:pr, focused integration/E2E-support tests, the migration evidence test, and npm run docs locally.

Fresh GitHub CI and exact all-agent managed startup are running on 1f7ed6efc; those remain the final acceptance gates.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/lib/actions/sandbox/mcp-bridge-url-validation.ts`:
- Around line 224-227: Update the DNS-pinning validation and its explanatory
comment near the OpenShell connection flow to require
proxy_connect_by_hostname=false; reject or fail validation when the setting is
enabled, so the allowed_ips guarantee only applies when OpenShell connects using
its pinned SocketAddr list.

In `@test/runner.test.ts`:
- Around line 368-370: Extend the validateName boundary tests around the
existing 19-character case to assert that the first invalid length, 20
characters, throws the same “sandbox name too long (max 19 chars)” error. Keep
the existing valid 19-character and oversized-input assertions unchanged.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 319fa606-10d0-4b11-a7cc-d8a16414b59e

📥 Commits

Reviewing files that changed from the base of the PR and between 1cc8e3d and 1f7ed6e.

📒 Files selected for processing (20)
  • agents/hermes/mcp-config-transaction.py
  • ci/source-shape-test-budget.json
  • docs/deployment/set-up-mcp-bridge.mdx
  • docs/reference/commands.mdx
  • docs/reference/troubleshooting.mdx
  • docs/security/openshell-0.0.99-migration-review.md
  • nemoclaw/src/shared/openshell-policy-boundary.cts
  • nemoclaw/src/shared/sandbox-name.cts
  • src/lib/actions/sandbox/mcp-bridge-url-validation.ts
  • src/lib/deploy/index.test.ts
  • src/lib/onboard/forward-start.ts
  • test/e2e/support/mcp-bridge-sandbox.test.ts
  • test/installer-hash-check.test.ts
  • test/onboard-sandbox-name.test.ts
  • test/openshell-0.0.85-migration-review.test.ts
  • test/openshell-0.0.99-migration-review.test.ts
  • test/repro-5978-policy-denial-hint.test.ts
  • test/runner.test.ts
  • test/update-hermes-agent-script.test.ts
  • tools/e2e/cli-artifact-workflow-boundary.mts
🚧 Files skipped from review as they are similar to previous changes (5)
  • docs/security/openshell-0.0.99-migration-review.md
  • agents/hermes/mcp-config-transaction.py
  • docs/reference/commands.mdx
  • test/update-hermes-agent-script.test.ts
  • docs/reference/troubleshooting.mdx

Comment thread src/lib/actions/sandbox/mcp-bridge-url-validation.ts Outdated
Comment thread test/runner.test.ts
@apurvvkumaria

Copy link
Copy Markdown
Collaborator Author

Follow-up exact-activation blocker addressed in verified commits 12b4bca11 and a920fc38e (current head): OpenShell 0.0.99 creates the Docker sandbox from the inspected immutable image content ID, so Docker records that ID in Config.Image. Managed bootstrap now accepts only the exact reviewed repository@manifestDigest or that exact runtime content ID, while retaining the separate Docker image-inspect proof that links the reviewed manifest digest to the same content ID. An unrelated ID is explicitly rejected. Focused adapter coverage (26/26), npm run validate:pr, and npm run docs pass locally; the branch is refreshed from current main. Fresh required CI and exact all-agent activation are running.

@apurvvkumaria
apurvvkumaria enabled auto-merge (squash) August 7, 2026 14:05
@senthilr-nv

Copy link
Copy Markdown
Collaborator

@apurvvkumaria — one current-head blocker remains on 509a5bc60:

  • Update the release E2E evidence fixture IDs for the refreshed Hermes GPU matrix. Required CLI shard 6 and the exact local focused test both fail at test/release-e2e-evidence.test.ts:195 because the fixture still targets hermes-gpu-startup[scenario="fallback"]. The refreshed workflow matrix adds sandbox_name, so the planner now identifies that row as hermes-gpu-startup[scenario="fallback",sandbox_name="e2e-hgpu-fallback"]; the compatibility-only sibling assertion needs the corresponding sandbox_name="e2e-hgpu-compat" dimension. Revalidate with npx vitest run --project integration test/release-e2e-evidence.test.ts, then rerun the failed required job.

The exact all-agent activation, documentation receipt, CodeRabbit, and published PR Review Advisor result are otherwise clear on this head.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
@senthilr-nv

Copy link
Copy Markdown
Collaborator

Additional #8497 activation evidence from unrelated PR #8560: Managed Images run 31186757641, job 92896129767, used OpenShell v0.0.85. OpenClaw activation/recovery/cleanup passed, then Hermes sandbox creation ended after 77 seconds with terminal_failure_phase before runtime exercise. #8523's current v0.0.99 all-agent activation passed in run 31186050945, job 92893723945. This maps to #8497's accepted v0.0.85 managed-image activation workstream and remains owned here; no duplicate E2E run was dispatched.

senthilr-nv added a commit that referenced this pull request Aug 7, 2026
## Summary

Base-image publication can fail immediately after pushing a candidate
manifest when GHCR's token endpoint transiently returns `403 Forbidden`
to the first manifest read. This change gives registry reads five
bounded attempts while preserving the existing digest, platform, and
provenance verification.

The failure was observed in main E2E run 31184501275, job 92888376997,
propagated from Base Images run 31184501811, job 92886728421 (`Build and
push Hermes base image`).

## Changes

- Route base-image manifest reads through one fixed-policy retry helper.
- Preserve the final Docker exit status after five unsuccessful
attempts.
- Keep all existing source-digest, platform, candidate-manifest, and
publication checks unchanged.
- Add focused helper, workflow-shape, and opaque-input trigger coverage.

## Type of Change

- [x] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [ ] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [x] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [ ] Tests not applicable — justification:
- [ ] Docs updated for user-facing behavior changes
- [x] Docs not applicable — justification: This changes only internal
GitHub Actions registry-read reliability; no user-facing command,
configuration, default, or supported product behavior changes.
- [x] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [x] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification: Maintainer
nine-category review passed. The retry is bounded, arguments remain
quoted, terminal failures propagate, temporary stderr is removed,
credential handling is unchanged, and digest/platform/provenance
verification remains fail-closed.
- [x] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue: `PR exact all-agent
managed runtime activation` failed in [run 31186757641, job
92896129767](https://github.com/NVIDIA/NemoClaw/actions/runs/31186757641/job/92896129767)
on the existing OpenShell v0.0.85 Hermes sandbox-creation path. Accepted
issue #8497 owns that v0.0.85 activation failure, and PR #8523's v0.0.99
activation passed in [run 31186050945, job
92893723945](https://github.com/NVIDIA/NemoClaw/actions/runs/31186050945/job/92893723945).
The classification is recorded in
[#8560](#8560 (comment))
and routed to
[#8523](#8523 (comment)).

## Documentation Writer Review

- [x] Documentation writer subagent reviewed the completed changes
- Result: `no-docs-needed`
- Evidence: The change only adds bounded retries to internal GitHub
Actions base-image registry reads. It does not change a user-facing
command, configuration, default, or supported product behavior.
- Agent: Codex Desktop
<!-- docs-review-head-sha: 069dbd4 -->
<!-- docs-review-agents-blob-sha: 12ad395 -->

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit: Not applicable.
- Station profile/scenario: Not applicable.
- Result: Not applicable.
- Supporting evidence: `scripts/prepare-dgx-station-host.sh` is
unchanged.

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run validate:pr` passed after refreshing `origin/main` when hooks
were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — `npx vitest run --project integration
test/retry-docker-imagetools-inspect.test.ts
test/dcode-base-image-workflow.test.ts
test/managed-image-publication-workflow.test.ts
test/vitest-watch-triggers.test.ts` (4 files, 30 tests passed)
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — command/result: Not applicable to this
narrow internal workflow retry. Normal repository checks passed.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only)
- [ ] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

The existing `validate-managed-base-index` suite requires Bash
associative arrays. This macOS host has only Bash 3.2, so that suite
could not execute locally; required Linux CI remains authoritative for
that integration path.

---

Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>

Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
@apurvvkumaria

Copy link
Copy Markdown
Collaborator Author

Addressed in signed, GitHub-verified commit e91128b05. The fallback and compatibility-only release-evidence identities now include their sandbox_name dimensions, so the regression continues to prove that one failed matrix row remains missing while its sibling stays successful. The focused suite passes 17/17, scoped hooks pass, and the independent documentation/security review found no documentation change or security issue. The documentation receipt is refreshed, and required CI for the updated branch is running.

# Conflicts:
#	tools/e2e/cli-artifact-workflow-boundary.mts
@apurvvkumaria

apurvvkumaria commented Aug 7, 2026

Copy link
Copy Markdown
Collaborator Author

The release-evidence blocker remains addressed in signed, GitHub-verified commit e91128b05. The branch is now merged forward without force-pushing to current main 41e7f23f2 at signed, GitHub-verified revision 6d5e9568a.

The two newly merged upstream changes have no source/test overlap with the OpenShell upgrade; their shared documentation edits combined cleanly. On the final tree, 114 upstream GPU tests, 23 OpenShell migration/release-evidence tests, and 62 llama.cpp lifecycle tests pass. npm run typecheck:cli, npm run docs, merge hooks, and pre-push type/version gates pass. The exact-head documentation receipt is refreshed for revision 6d5e9568a and AGENTS.md blob 12ad395bb, with no additional documentation needed.

Fresh required CI, automated review, and exact all-agent managed activation are now running on the updated revision.

@senthilr-nv senthilr-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed 18ac71c45 against current base aae23eb4f.

Required checks and exact all-agent managed activation pass. The corrected release-evidence contract passes 19/19 locally; the exact-head documentation-writer receipt is current. CodeRabbit has no unresolved finding, and the informational PR Review Advisor result reports zero findings.

Product scope is approved under #8497.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
@apurvvkumaria
apurvvkumaria merged commit ea39b25 into main Aug 7, 2026
61 of 67 checks passed
@apurvvkumaria
apurvvkumaria deleted the codex/8497-openshell-v099-upgrade branch August 7, 2026 16:48
prekshivyas added a commit that referenced this pull request Aug 8, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Completes the remaining OpenShell `0.0.99` compatibility work after
#8499 and #8523. Existing `0.0.85` sandboxes can now survive the gateway
upgrade without losing the required supervisor workdir argument, and
Docker/Podman lifecycle authority matches the exact `0.0.99` identity
and status contracts.

## Related Issue

Closes #8497

## Changes

- Preserve only the reviewed OpenShell supervisor command (`--workdir
/sandbox`) when cloning a managed workload, while retaining the
empty-command form needed by `0.0.85` migration and rejecting other
supervisor arguments before mutation. Focused clone/startup tests
protect both accepted forms and the fail-closed path.
- Bind Docker and Podman lifecycle mutations to the exact `0.0.99`
default-workspace identity: workspace-qualified names, exact labels, and
full immutable container IDs. Ownership and lifecycle tests reject
foreign workspaces, ambiguous containers, and legacy Podman identities.
- Pin the portable Podman gateway to the prepared rootless socket and
add a credential-free live proof using OpenShell `0.0.99` and Podman
`5.7`. The lane disables Docker, checks authenticated gateway health,
activates all registered agent identities, and exercises the production
portable lifecycle binding.
- Scope gateway status probes to the requested gateway and recognize the
`0.0.99` connection-error form that omits the gateway name. OpenShell
does not yet provide a structured status error kind, so the fallback
remains limited to an explicitly scoped gateway and is covered by
exact-output fixtures.
- Update the migration/security review and pinned-version references
with the completed compatibility contracts and remaining live-CI
qualification gate.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [x] Code change with doc updates
- [ ] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [x] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [ ] Tests not applicable — justification:
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [x] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [x] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification: Independent Codex
Desktop review found no blockers after checking the exact OpenShell
`0.0.99` source contracts, ownership boundaries, rootless socket
binding, fail-closed behavior, and live-workflow cleanup.
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## Documentation Writer Review

- [x] Documentation writer subagent reviewed the completed changes
- Result: `docs-updated`
- Evidence: `docs/security/openshell-0.0.99-migration-review.md`,
`docs/security/openclaw-2026.7.1-dependency-review.md`, and
`tools/pr-review-advisor/README.md`
- Agent: Codex Desktop
<!-- docs-review-head-sha: 3b3f3e2 -->
<!-- docs-review-agents-blob-sha: 12ad395 -->

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit: Not applicable; DGX Station preparation did not change.
- Station profile/scenario:
- Result:
- Supporting evidence:

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run validate:pr` passed after refreshing `origin/main` when hooks
were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — 308 focused compatibility tests passed
before the final E2E correction; post-merge ownership/session coverage
passed 81/81, Podman support coverage passed 9/9, the affected destroy
integration coverage passed 4/4, semantic E2E coverage passed for 122
tests across 79 files, and CLI type-check plus architecture checks
passed.
- [ ] Applicable broad gate passed — GitHub CI will run the complete
matrix. A local repository-wide fast run was not claimed because
unrelated timing-sensitive tests flaked under local load; all
affected-area suites pass.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) —
completed with 0 errors and 2 pre-existing Fern warnings.
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

---
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added rootless Podman socket support for portable profiles.
* Improved workspace-aware sandbox discovery, container ownership, and
SSH host routing.
* Added gateway-specific status checks and deletion-convergence
validation.
* **Bug Fixes**
* Prevented ambiguous, malformed, or mismatched containers from being
reused or modified.
* Preserved container commands during Docker-based cloning while
rejecting unsupported configurations.
* Improved handling of interrupted command results and inference route
detection.
* **Testing**
* Expanded end-to-end coverage for Podman lifecycle, networking,
cleanup, diagnostics, and gateway startup.
* **Documentation**
  * Updated compatibility and migration guidance for OpenShell 0.0.99.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Co-authored-by: Carlos Villela <cvillela@nvidia.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Prekshi Vyas <prekshiv@nvidia.com>
@github-actions github-actions Bot added the v0.0.106 Release target label Aug 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants