Skip to content

chore(deps): update OpenShell to 0.0.106 - #9192

Merged
prekshivyas merged 70 commits into
NVIDIA:mainfrom
prekshivyas:patch-walker/openshell-0.0.105-31ee658967
Aug 20, 2026
Merged

chore(deps): update OpenShell to 0.0.106#9192
prekshivyas merged 70 commits into
NVIDIA:mainfrom
prekshivyas:patch-walker/openshell-0.0.105-31ee658967

Conversation

@prekshivyas

@prekshivyas prekshivyas commented Aug 15, 2026

Copy link
Copy Markdown
Collaborator

Summary

Updates OpenShell from 0.0.101 to 0.0.106 using the sealed NemoPin migration evidence. Release-trust prerequisite #9224 is merged on main, and the E2E-selector work from #9378 is included in this branch. The PR is reconciled with current main at latest PR commit e3a53c96f.

Related Issue

Changes

  • Applies only paths authorized by sha256:65355e5c4180f3716fd8e0d0431d432a876460a7005db6099fa18a8599c3037e.
  • Migrates the exact base 44c2636d85f788f81767fbb451717566e0a8d475 across 5 adjacent release ranges.
  • Reconciles the migration with current main at base commit 40dc27283, includes the reviewed E2E-selector work from ci(e2e): select OpenShell 0.0.106 #9378, adopts the upstream messaging-plan fixture fix from test(messaging): bind Dockerfile plan fixture to agent #9517, and hardens runtime-identity qualification for cold 0.0.106 onboarding while recording the attached-provider post-state.
  • Changed paths: .github/workflows/e2e.yaml, .github/workflows/podman-cpu-proof.yaml, agents/hermes/Dockerfile, agents/hermes/mcp-config-transaction.py, agents/hermes/runtime-config-guard.py, agents/hermes/start.sh, docs/deployment/set-up-mcp-bridge.mdx, docs/manage-sandboxes/add-mcp-server.mdx, docs/manage-sandboxes/update-sandboxes.mdx, docs/reference/commands.mdx, docs/reference/configure-runtime-identity.mdx, docs/reference/troubleshooting.mdx, docs/security/best-practices.mdx, docs/security/gateway-authentication-controls.mdx, internal/security-reviews/openshell-0.0.72-compatibility-review.mdx, nemoclaw-blueprint/blueprint.yaml, nemoclaw/src/shared/openshell-policy-boundary.cts, scripts/brev-launchable-ci-cpu.sh, scripts/checks/dependency-pins.mts, scripts/checks/managed-image-protected-runtime-contract.ts, scripts/install-openshell.sh, scripts/install.sh, scripts/update-hermes-agent.sh, src/lib/actions/sandbox/mcp-bridge-input-validation.test.ts, src/lib/actions/sandbox/mcp-bridge-url-validation.ts, src/lib/actions/sandbox/mcp-bridge-validation.ts, src/lib/actions/sandbox/openshell-child-visible-credentials.v0.0.106.json, src/lib/onboard/docker-driver-gateway-config-toml.test.ts, src/lib/onboard/docker-driver-gateway-runtime.test.ts, src/lib/onboard/docker-driver-gateway-runtime.ts, src/lib/onboard/experimental/portable-demo-lifecycle.ts, src/lib/onboard/forward-start.ts, src/lib/onboard/managed-bootstrap/podman-held-workload.test.ts, src/lib/onboard/managed-bootstrap/podman-held-workload.ts, src/lib/onboard/openshell-feature-gate.test.ts, src/lib/onboard/openshell-feature-gate.ts, src/lib/onboard/openshell-install.test.ts, src/lib/onboard/openshell-install.ts, src/lib/onboard/openshell-version.ts, src/lib/onboard/runtime-provider/podman-lifecycle.ts, src/lib/policy/index.ts, test/brev-launchable-ci-cpu-checksum.test.ts, test/deepagents-mcp-legacy-lifecycle.test.ts, test/dependency-pins-check.test.ts, test/e2e/fixtures/openshell-v0106-qualification.ts, test/e2e/fixtures/security-posture.ts, test/e2e/live/mcp-bridge-sandbox.ts, test/e2e/live/network-policy.test.ts, test/e2e/live/openclaw-plugin-runtime-exdev.test.ts, test/e2e/live/openshell-gateway-auth-source-contract-helpers.ts, test/e2e/live/openshell-gateway-auth-source-contract.test.ts, test/e2e/live/openshell-gateway-upgrade.test.ts, test/e2e/live/openshell-v0106-tls-server-name-source.ts, test/e2e/live/podman-cpu-lifecycle-helpers.ts, test/e2e/live/podman-cpu-lifecycle.test.ts, test/e2e/support/mcp-bridge-runtime-compatibility.test.ts, test/e2e/support/mcp-bridge-sandbox.test.ts, test/e2e/support/mcp-workflow-boundary.test.ts, test/e2e/support/openshell-gateway-auth-contract-workflow-boundary.test.ts, test/e2e/support/openshell-v0106-tls-server-name-source.test.ts, test/e2e/support/workflow-plan.test.ts, test/exit-code-user-error-surfaces.test.ts, test/fixtures/openshell-v0.0.106, test/gateway-state-reconcile-2276.test.ts, test/hermes-doctor-config-hash.test.ts, test/hermes-mcp-config-transaction.test.ts, test/hermes-mcp-credential-boundary-manifest.test.ts, test/install-openshell-version-check.test.ts, test/install-openshell-version-pin.test.ts, test/installer-hash-check.test.ts, test/installer-sandbox-build-trust.test.ts, test/installer-supervisor-manifest-trust.test.ts, test/mcp-add-crash-consistency.test.ts, test/mcp-destroy-lifecycle.test.ts, test/mcp-policy-key-ownership.test.ts, test/mcp-restart-policy-order.test.ts, test/onboard-gateway-port-conflict-fast-fail.test.ts, test/openshell-0.0.85-migration-review.test.ts, test/openshell-channel-workflow.test.ts, test/pr-risk-plan.test.ts, test/rebuild-credential-preflight.test.ts, test/runner.test.ts, test/sandbox-provisioning.test.ts, test/sandbox-rlimit-hooks.test.ts, test/update-hermes-agent-script.test.ts, tools/e2e/mcp-workflow-boundary.mts, tools/e2e/openshell-gateway-auth-contract-workflow-boundary.mts, tools/e2e/workflow-boundary.mts

Release ranges

Range Commits State Concerns
0.0.101 → v0.0.102 8ddd98c3dff6f48b05e31228 published 3
v0.0.102 → v0.0.103 f48b05e31228c825b1f8efac published 2
v0.0.103 → v0.0.104 c825b1f8efacdd2b4e3bc068 published 1
v0.0.104 → v0.0.105 dd2b4e3bc0680f8fad23c471 published 3
v0.0.105 → v0.0.106 0f8fad23c471c4b500a7de64 published 5

Concern dispositions

Concern Surface Planned disposition Failure prevented Remaining gate
openshell-0.0.101..v0.0.102-network-1 network test v0.0.102 reports network: ### Quick install * fix(e2e): separate Podman Machine loopback listeners by @matthewgrossman in NVIDIA/OpenShell#2622 * fix(pol... none
openshell-0.0.101..v0.0.102-runtime-topology-2 runtime topology test v0.0.102 reports runtime topology: ### Quick install * fix(e2e): separate Podman Machine loopback listeners by @matthewgrossman in NVIDIA/OpenShell#2622 ... runtime-proof
openshell-0.0.101..v0.0.102-security-identity-3 security identity guard v0.0.102 reports security identity: ### Quick install * fix(e2e): separate Podman Machine loopback listeners by @matthewgrossman in NVIDIA/OpenShell#2622... none
openshell-v0.0.102..v0.0.103-network-1 network test v0.0.103 reports network: ### Quick install * fix(sandbox): acknowledge unchanged policy revisions by @NaveCohenMonday in NVIDIA/OpenShell#2557 * fix(gat... none
openshell-v0.0.102..v0.0.103-runtime-topology-2 runtime topology test v0.0.103 reports runtime topology: ### Quick install * fix(sandbox): acknowledge unchanged policy revisions by @NaveCohenMonday in NVIDIA/OpenShell#2557 ... runtime-proof
openshell-v0.0.103..v0.0.104-runtime-topology-1 runtime topology test v0.0.104 reports runtime topology: ### Quick install * feat(build): add glibc-static supervisor libc variant by @EmilienM in NVIDIA/OpenShell#2682 * fix(... runtime-proof
openshell-v0.0.104..v0.0.105-compatibility-change-1 compatibility change test v0.0.105 reports compatibility change: ### Quick install * fix(gator): separate review budget from approval gate by @johntmyers in NVIDIA/OpenShell#2704 ... none
openshell-v0.0.104..v0.0.105-network-2 network test v0.0.105 reports network: ### Quick install * fix(gator): separate review budget from approval gate by @johntmyers in NVIDIA/OpenShell#2704 * perf(superv... none
openshell-v0.0.104..v0.0.105-runtime-topology-3 runtime topology test v0.0.105 reports runtime topology: ### Quick install * fix(gator): separate review budget from approval gate by @johntmyers in NVIDIA/OpenShell#2704 * pe... runtime-proof
openshell-v0.0.105..v0.0.106-lifecycle-state-1 lifecycle state test v0.0.106 reports lifecycle state: ### Quick install * ci(cargo-deny): add dependency audit with cargo-deny by @Ygnas in NVIDIA/OpenShell#2677 * feat(sdk/... runtime-proof
openshell-v0.0.105..v0.0.106-code-impact-configuration-1 mapped configuration test The exact-ref diff reports configuration changes in crates/openshell-cli/src/commands/common.rs, crates/openshell-cli/src/main.rs, crates/openshell-cli/src/run.rs. Mapped NemoCl... runtime-proof
openshell-v0.0.105..v0.0.106-code-impact-contract-or-schema-2 mapped contract or schema test The exact-ref diff reports contract or schema changes in crates/openshell-core/src/middleware.rs, crates/openshell-core/src/provider_credentials.rs, crates/openshell-driver-kube... runtime-proof
openshell-v0.0.105..v0.0.106-code-impact-security-3 mapped security test The exact-ref diff reports security changes in crates/openshell-bootstrap/src/build_windows.rs, crates/openshell-cli/src/commands/common.rs, crates/openshell-cli/src/main.rs. Ma... runtime-proof
openshell-v0.0.105..v0.0.106-code-impact-test-4 mapped test test The exact-ref diff reports test changes in crates/openshell-cli/tests/ensure_providers_integration.rs, crates/openshell-cli/tests/mtls_integration.rs, crates/openshell-cli/tests... runtime-proof

Immutable artifacts

Artifact SHA-256
openshell-aarch64-apple-darwin.tar.gz 969493205e3d3462…
openshell-aarch64-unknown-linux-musl.tar.gz ce981904ae8febd9…
openshell-checksums-sha256.txt 7421aaf9d5550dc1…
openshell-gateway-aarch64-apple-darwin.tar.gz de8f90db9dd0d3b4…
openshell-gateway-aarch64-unknown-linux-gnu.tar.gz 22b7781249e34870…
openshell-gateway-checksums-sha256.txt 26e4345449e02475…
openshell-gateway-x86_64-unknown-linux-gnu.tar.gz b7760cb752a4363c…
openshell-gateway-x86_64-unknown-linux-gnu.tar.gz::executable:openshell-gateway e6cde8a54568aa19…
openshell-sandbox-aarch64-unknown-linux-gnu.tar.gz 5e5d758d53c6abc6…
openshell-sandbox-aarch64-unknown-linux-gnu.tar.gz::executable:openshell-sandbox 0031c6b257a23ecc…
openshell-sandbox-checksums-sha256.txt 88bc98ffdc915fb7…
openshell-sandbox-x86_64-unknown-linux-gnu.tar.gz 559b8aaad3a8eeab…
openshell-sandbox-x86_64-unknown-linux-gnu.tar.gz::executable:openshell-sandbox 019301ec8618abbe…
openshell-x86_64-unknown-linux-musl.tar.gz d1a885a91b3e5aaa…
openshell-x86_64-unknown-linux-musl.tar.gz::executable:openshell 98ecf95113fea999…
openshell.rb f0f86519e227b3b3…
openshell-source:crates/openshell-core/src/google_cloud.rs 2583a04a0557f069…
openshell-source:crates/openshell-core/src/provider_credentials.rs 7e8e05efcb725807…
openshell-source:crates/openshell-core/src/secrets.rs b122b4a5af5a5823…
ghcr.io/nvidia/openshell/supervisor:index 722f44669722961b…

Validation receipt

Gate Current result
targeted Passed: 609 assertions with 1 intentional skip across the migration/runtime suites, 290/290 E2E registry/workflow overlap assertions, and 73/73 onboarding-preflight overlap assertions on cc9167892. After the final main reconciliation, 32/32 conflict-sensitive gateway/TLS assertions and npm run validate:pr passed on latest PR commit d1990537d.
brev-integration-fresh-onboarding Passed on Brev before reconciliation; latest PR commit GitHub CI passed
brev-integration-existing-upgrade Passed on Brev before reconciliation; latest PR commit GitHub CI passed
brev-integration-recovery-rollback Passed on Brev before reconciliation; latest PR commit GitHub CI passed
full-e2e Exact inference run 32199961381 on PR commit cc9167892 with trusted base/workflow a9fc8045d passed 5/7 cases. TC-INF-12 and TC-INF-13 both completed cold onboarding, plan/apply, provider attachment, token refresh, and post-attach inference; OpenShell 0.0.106 then failed to project E2E_ACCESS_TOKEN / ENTRA_ACCESS_TOKEN into 19 fresh sandbox execs over 35 seconds. Protected managed-image runtime was not launched because inference is its prerequisite. This is a repeated upstream runtime-credential projection blocker, not a waived gate.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification:
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: Independent exact-commit review passed for the OpenShell 0.0.106 migration and stacked E2E selector.
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: docs-updated
  • Evidence: docs/deployment/set-up-mcp-bridge.mdx, docs/manage-sandboxes/add-mcp-server.mdx, docs/manage-sandboxes/manage-mcp-servers.mdx, docs/reference/commands.mdx, and docs/reference/troubleshoot-mcp-servers.mdx
  • Agent: Codex Desktop

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run validate:pr passed after refreshing origin/main when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — 609 assertions passed with 1 intentional skip across the migration/runtime suites, followed by 290/290 E2E registry/workflow overlap assertions and 73/73 onboarding-preflight overlap assertions on cc9167892; 32/32 conflict-sensitive gateway/TLS assertions and npm run validate:pr then passed after the final main reconciliation on latest PR commit d1990537d.
  • Applicable broad gate passed — GitHub reports no required checks for this branch. Optional checks do not gate review unless they expose a PR defect.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Prekshi Vyas prekshiv@nvidia.com

NemoPatch current-head status

  • Status: blocked

  • Latest PR commit: d1990537d9b9c8579c3197cba33faddaeb9aa101

  • Checked: 2026-08-19T02:46:48Z

  • Reconciled with main at base commit ee6762b99; 32/32 conflict-sensitive gateway/TLS assertions, local PR validation, and all 45 applicable current-commit GitHub checks pass. The two advisor services failed analysis without findings. Exact inference on cc9167892 with trusted base/workflow a9fc8045d passed 5/7 and repeatedly isolated an OpenShell 0.0.106 runtime-credential projection failure after successful provider attachment and refresh. Protected managed-image E2E remains gated; maintainer/upstream resolution is required.

Summary by CodeRabbit

  • New Features

    • Added support for OpenShell 0.0.106, including updated CLI, gateway, sandbox, supervisor, and credential-boundary assets.
    • Added stronger installation integrity checks for reviewed binaries and release artifacts.
    • Added TLS server-name verification across Docker, Podman, and VM environments.
  • Bug Fixes

    • Improved MCP bridge destination validation before connections are established.
    • Added supervisor TLS-name sanitization protections.
  • Documentation

    • Updated setup, compatibility, security, installation, and troubleshooting guidance for OpenShell 0.0.106.
    • Added guidance for resolving Docker credential-store failures in headless environments.

@copy-pr-bot

copy-pr-bot Bot commented Aug 15, 2026

Copy link
Copy Markdown

Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually.

Contributors can view more details about this message here.

@coderabbitai

coderabbitai Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

OpenShell support is upgraded from 0.0.101 to 0.0.106 across release pins, credential manifests, installers, runtime checks, E2E qualification workflows, tests, and documentation. New validation covers reviewed binary identities and TLS server-name source boundaries.

Changes

OpenShell 0.0.106 release integration

Layer / File(s) Summary
Release pins and installation validation
.github/workflows/*, nemoclaw-blueprint/blueprint.yaml, scripts/install-openshell.sh, src/lib/onboard/openshell-feature-gate.ts, test/installer-*.test.ts
Version constraints, release digests, sandbox identities, supervisor manifest trust, and installer validation now target OpenShell 0.0.106.
Runtime compatibility and credential contracts
agents/hermes/*, src/lib/actions/sandbox/*, src/lib/onboard/*, test/*
Credential manifests, Hermes checks, onboarding compatibility, runtime fixtures, and related tests now use the 0.0.106 contracts.
E2E qualification and TLS source verification
test/e2e/*, tools/e2e/*, .github/workflows/e2e.yaml
Qualification metadata, release provenance, credential-free installer checks, and Docker, Podman, and VM TLS server-name source checks now validate the release.
Compatibility documentation and supporting checks
docs/*, internal/security-reviews/*, nemoclaw/src/*, test/e2e/support/*
Compatibility guidance, security references, policy markers, lifecycle comments, troubleshooting guidance, and supporting assertions now identify the updated release.

Estimated code review effort: 4 (Complex) | ~60 minutes

Merge Risk: 🟡 Moderate · up to cc916

The dependency update changes installation and workflow validation behavior, but merge readiness is not yet clean because stable workflow checks may accept additional unreviewed installer commands and the release security documentation may attribute older-version evidence to the new version; explicit owner follow-up is needed before merge.

Possibly related PRs

  • NVIDIA/NemoClaw#9224: Adds related OpenShell 0.0.106 trust data and manifest validation tests.
  • NVIDIA/NemoClaw#9514: Continues the E2E workflow changes for matrix labels and colon-suffixed target selection.
  • NVIDIA/NemoClaw#9459: Adds the Docker Desktop credential-store troubleshooting guidance included here.

Suggested labels: area: ci, area: e2e

Suggested reviewers: cv, apurvvkumaria

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 16.22% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely summarizes the primary change: updating OpenShell from version 0.0.101 to 0.0.106.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 15, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — Informational

Advisor assessment: Informational / low confidence
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions
Status: PR review advisor failed: PR review advisor SDK execution failed: session: investigate omitted required analysis; turn: investigate: investigate omitted required analysis

Model lanes

  • GPT-5.6 Terra (primary): Failed
  • Nemotron 3 Ultra (second opinion): Failed

Second-opinion terminology and E2E selections are advisory. Live E2E does not run automatically for pull requests.

E2E guidance

Advisory only. A maintainer can dispatch the default E2E suite for the commit under review.

Recommended E2E: managed-image-protected-runtime, inference-routing

Manual-only E2E: cloud-onboard, hermes-e2e, hermes-inference-switch, managed-image-multiarch-startup, security-posture, bedrock-runtime-compatible-anthropic, channels-stop-start, hermes-shields-config, mcp-bridge, mcp-bridge-dev, onboard-repair, onboard-resume, openclaw-plugin-runtime-exdev, openclaw-plugin-runtime-exdev-release, openshell-gateway-auth-contract, vllm-docker-storage, cloud-inference, full-e2e, dashboard-remote-bind, network-policy (+2 more)
The manual PR workflow does not run these selectors for the commit under review. Run them from reviewed code on main.

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@prekshivyas prekshivyas self-assigned this Aug 15, 2026

@prekshivyas prekshivyas left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head 26248e1 after merging current main. The conflict resolution retains the main 0.0.103 trust records and the candidate 0.0.105 manifest records, and focused dependency tests plus shell syntax checks pass locally. This draft cannot become green or approvable yet: the base-trusted installer parser on main has no reviewed 0.0.105 standalone-sandbox or supervisor identities, so candidate code cannot self-authorize them; check-hash fails closed as designed. The protected Podman proof also still dispatches OpenShell 0.0.101 while the candidate installer intentionally accepts only 0.0.105. Land the prerequisite trust identities on main and update the protected workflow pin through the authorized dependency process, then refresh this branch. GitHub also prohibits me from approving my own PR.

@prekshivyas prekshivyas changed the title chore(deps): update OpenShell to 0.0.105 chore(deps): update OpenShell to 0.0.106 Aug 16, 2026
@prekshivyas
prekshivyas force-pushed the patch-walker/openshell-0.0.105-31ee658967 branch from 68c7ce4 to 53396de Compare August 16, 2026 00:00
Patch-Walker-Manifest: sha256:7d6533d0fb5cb297bffd415e1c07fb744cd770eb059258707bef1b617900787d
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas
prekshivyas force-pushed the patch-walker/openshell-0.0.105-31ee658967 branch from ac0274a to 30d2dcb Compare August 16, 2026 16:04
@prekshivyas
prekshivyas force-pushed the patch-walker/openshell-0.0.105-31ee658967 branch from 30d2dcb to bc8f1d6 Compare August 16, 2026 16:16
@cv cv added chore Build, CI, dependency, or tooling maintenance area: install Install, setup, prerequisites, or uninstall flow area: sandbox OpenShell sandbox lifecycle, runtime, config, or recovery security labels Aug 16, 2026
@prekshivyas
prekshivyas changed the base branch from main to nemopatch-stack/openshell-0.0.106-trust-9224 August 16, 2026 20:02
@prekshivyas
prekshivyas changed the base branch from nemopatch-stack/openshell-0.0.106-trust-9224 to nemopatch-stack/openshell-0.0.106-pr-9224-0a87920416ae August 16, 2026 20:12
@prekshivyas
prekshivyas force-pushed the patch-walker/openshell-0.0.105-31ee658967 branch from bc8f1d6 to d107fba Compare August 16, 2026 20:38
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
@prekshivyas
prekshivyas force-pushed the patch-walker/openshell-0.0.105-31ee658967 branch from d107fba to d204b66 Compare August 16, 2026 20:43
Patch-Walker-Manifest: sha256:8fbcac736e876d15a8d2e9c6433aac3a616dbafa754933ca6a36c8a4730fe44d
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:8fbcac736e876d15a8d2e9c6433aac3a616dbafa754933ca6a36c8a4730fe44d
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:8fbcac736e876d15a8d2e9c6433aac3a616dbafa754933ca6a36c8a4730fe44d
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:6d6499fda9409244210dd3dac0afcb0962928c106f1a5ab08ef5a2530193e5af
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:24726c2eac18527fa6e37220662188b77f6e1284cf343c7d1197f11e5cf4e81b
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:6d6e27ca3454cc7cb9996326f35a4e203fedafb73e414f0c3b7b0fd645547736
Refs NVIDIA#6256
Refs NVIDIA#3136
Refs NVIDIA#6871
Refs NVIDIA#7367
Refs NVIDIA#7937
Refs NVIDIA#7957
Refs NVIDIA#8769
Refs NVIDIA#8887
Refs NVIDIA#8893

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:24444858ce8f9cfb285bc06375dd8e5cdabf62e68112086251b97bf6f027c0c4
Prerequisite-PR: NVIDIA#9224
Prerequisite-Commit: 080b144

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

@senthilr-nv senthilr-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: OpenShell 0.0.106 requires every static credential exposed as an environment placeholder to be classified by endpoint-binding metadata. This PR now requires 0.0.106, but src/lib/actions/sandbox/mcp-bridge-provider-mutation.ts:51 still creates a profile-less generic provider, and src/lib/actions/sandbox/mcp-bridge-policy-render.ts:104-111 emits the endpoint without credential_binding.provider. In v0.0.106 the gateway therefore supplies the credential with no binding and the supervisor rejects the snapshot as an unclassified credential key, so authenticated MCP bridges lose credential projection. The new docs at docs/deployment/set-up-mcp-bridge.mdx:95-99 also describe the old sandbox-scoped behavior instead of this fail-closed requirement. Import or use an endpointless provider profile, bind the generated endpoint to its concrete provider, update the status and docs, and add a v0.0.106 regression proving resolution only on the intended endpoint.

@apurvvkumaria apurvvkumaria left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed commit 24d5f55. I found no critical blocker. The OpenShell 0.0.106 dependency is pinned with immutable installer and supervisor provenance, feature gates and credential-boundary evidence match the new contract, and runtime identity now mints credentials after provider attachment with compensating cleanup on failure. Trusted exact-head E2E run 32320521878 completed successfully, including the runtime-identity scenario that previously blocked this migration.

Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>

@senthilr-nv senthilr-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed latest PR commit e3a53c9. Accepted scope is established by #8893. The OpenShell 0.0.106 MCP path now validates an endpointless nemoclaw-mcp-v1 profile, attaches under an unbound capability policy, applies credential_binding.provider before readiness, rejects legacy generic providers for active use while preserving exact cleanup, and removes bound policy before detach. Owning docs and status guidance match the contract. Security review found no blocker across credential handling, ownership, policy restriction, rollback, or dependency integrity. Focused validation passed: MCP/vLLM 147/147, selector 7/7, package contract 4/4, CLI typecheck/build, repository checks, docs, and normal commit/push hooks. Cross-issue sweep found no adjacent fix or contradiction above the confidence floor.

prekshivyas and others added 4 commits August 19, 2026 21:35
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

@senthilr-nv senthilr-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed commit ab648f9. Accepted scope is established by #8893. The OpenShell 0.0.106 MCP contract now uses the reviewed provider profile and endpoint credential binding; the follow-up preserves legacy generic-provider cleanup while rejecting rebuild before managed state changes. Focused validation passed 75/75 tests plus CLI type-checking. No unresolved correctness, security, architecture, documentation, or automated-feedback blocker remains.

@prekshivyas
prekshivyas merged commit 8cddcee into NVIDIA:main Aug 20, 2026
81 of 88 checks passed
cjagwani added a commit that referenced this pull request Aug 20, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Add the canonical dated changelog entry required before planning the
v0.0.112 release.
The entry summarizes the 75 merged PRs in
`v0.0.111..af56158`, links user-facing
themes to published documentation routes, and links every included
source PR.

## Changes

- Add `docs/changelog/2026-08-20.mdx` with the exact `## v0.0.112`
release heading and parser-safe MDX SPDX comment.
- Cover managed local inference, onboarding and sandbox lifecycle
recovery, messaging continuity, review and release automation, E2E
qualification, dependency updates, and cumulative documentation
catch-up.
- Preserve the documentation skip list and supported-agent matrix; the
release entry contains none of the blocked terms or excluded
experimental surfaces.

### Source-to-doc mapping

- #8620 -> `docs/changelog/2026-08-20.mdx`: Record the LangChain Deep
Agents Code 0.1.55 update.
- #9192 -> `docs/changelog/2026-08-20.mdx`: Record the OpenShell 0.0.106
update.
- #9240 -> `docs/changelog/2026-08-20.mdx`: Record the cold base-image
pull heartbeat.
- #9412 -> `docs/changelog/2026-08-20.mdx`: Record voice context
preservation across sequential turns.
- #9483 -> `docs/changelog/2026-08-20.mdx`: Record Ollama model
verification through the sandbox endpoint.
- #9493 -> `docs/changelog/2026-08-20.mdx`: Record E2E cloud-check
wiring coverage.
- #9495 -> `docs/changelog/2026-08-20.mdx`: Record Model Router endpoint
health validation.
- #9534 -> `docs/changelog/2026-08-20.mdx`: Record default-sandbox
resolution for tunnel status.
- #9537 -> `docs/changelog/2026-08-20.mdx`: Record Linux AMD64 Muse and
Lightning profiles.
- #9543 -> `docs/changelog/2026-08-20.mdx`: Record corrected
network-policy preset examples.
- #9545 -> `docs/changelog/2026-08-20.mdx`: Record shared
runtime-adapter port validation.
- #9578 -> `docs/changelog/2026-08-20.mdx`: Record Portable network
creation before host aliases.
- #9589 -> `docs/changelog/2026-08-20.mdx`: Record running vLLM profile
validation.
- #9590 -> `docs/changelog/2026-08-20.mdx`: Record the two-turn atomic
advisor review.
- #9597 -> `docs/changelog/2026-08-20.mdx`: Record Portable uninstall
without host-owned lifecycle resources.
- #9605 -> `docs/changelog/2026-08-20.mdx`: Record release automation
for an initially empty tag history.
- #9607 -> `docs/changelog/2026-08-20.mdx`: Record credential retry
navigation.
- #9626 -> `docs/changelog/2026-08-20.mdx`: Record retirement of
DeepSeek V4 Pro from the featured menu.
- #9631 -> `docs/changelog/2026-08-20.mdx`: Record reduction-directed
advisor design blockers.
- #9632 -> `docs/changelog/2026-08-20.mdx`: Record Portable Ollama under
Podman.
- #9633 -> `docs/changelog/2026-08-20.mdx`: Record llama.cpp attachment
without `/props` model aliases.
- #9636 -> `docs/changelog/2026-08-20.mdx`: Record Docker authority
independent of terminal state.
- #9641 -> `docs/changelog/2026-08-20.mdx`: Record the separate Portable
host-gateway subnet.
- #9642 -> `docs/changelog/2026-08-20.mdx`: Record cumulative command
documentation catch-up.
- #9645 -> `docs/changelog/2026-08-20.mdx`: Record removal of completed
advisor rollout compatibility.
- #9647 -> `docs/changelog/2026-08-20.mdx`: Record diagnostics for
OpenShell deletion handoffs.
- #9650 -> `docs/changelog/2026-08-20.mdx`: Record OpenClaw pairing
settlement after route changes.
- #9652 -> `docs/changelog/2026-08-20.mdx`: Record repaired same-turn
advisor submissions.
- #9653 -> `docs/changelog/2026-08-20.mdx`: Record llama.cpp authority
preservation on resume.
- #9654 -> `docs/changelog/2026-08-20.mdx`: Record the schema-owned
Microsoft Teams webhook field.
- #9655 -> `docs/changelog/2026-08-20.mdx`: Record configured managed
vLLM ports.
- #9656 -> `docs/changelog/2026-08-20.mdx`: Record interrupted managed
vLLM installation recovery.
- #9660 -> `docs/changelog/2026-08-20.mdx`: Record catalog-owned vLLM
profiles and refreshed llama.cpp pins.
- #9663 -> `docs/changelog/2026-08-20.mdx`: Record attested LKG
production-image requests.
- #9664 -> `docs/changelog/2026-08-20.mdx`: Record corrected documented
environment-variable handling.
- #9665 -> `docs/changelog/2026-08-20.mdx`: Record retired gateway
evidence validation.
- #9666 -> `docs/changelog/2026-08-20.mdx`: Record Docker authority
across terminal sessions.
- #9667 -> `docs/changelog/2026-08-20.mdx`: Record contribution intake
and product-decision guidance.
- #9669 -> `docs/changelog/2026-08-20.mdx`: Record bounded DGX Spark
llama.cpp request bodies.
- #9670 -> `docs/changelog/2026-08-20.mdx`: Record managed llama.cpp
bridge authentication.
- #9671 -> `docs/changelog/2026-08-20.mdx`: Record gateway recreation
after Docker network loss.
- #9672 -> `docs/changelog/2026-08-20.mdx`: Record bounded WSL Ollama
host probes.
- #9674 -> `docs/changelog/2026-08-20.mdx`: Record cumulative inference
and command documentation catch-up.
- #9675 -> `docs/changelog/2026-08-20.mdx`: Record Muse Glimmer vLLM
image revision handling.
- #9676 -> `docs/changelog/2026-08-20.mdx`: Record the grouped CodeQL
Actions update.
- #9677 -> `docs/changelog/2026-08-20.mdx`: Record the actions/setup-go
7.0.0 update.
- #9678 -> `docs/changelog/2026-08-20.mdx`: Record resumable failed
llama.cpp cleanup.
- #9681 -> `docs/changelog/2026-08-20.mdx`: Record Docker executable
injection in the state-mutation harness.
- #9683 -> `docs/changelog/2026-08-20.mdx`: Record Windows Docker path
fixtures.
- #9684 -> `docs/changelog/2026-08-20.mdx`: Record isolated macOS status
subprocess cleanup.
- #9686 -> `docs/changelog/2026-08-20.mdx`: Record managed-inference
catalog compilation for Portable E2E.
- #9687 -> `docs/changelog/2026-08-20.mdx`: Record cumulative uninstall
documentation catch-up.
- #9688 -> `docs/changelog/2026-08-20.mdx`: Record DCode model-selector
loading through tsx.
- #9689 -> `docs/changelog/2026-08-20.mdx`: Record bounded docs-parity
process starts.
- #9690 -> `docs/changelog/2026-08-20.mdx`: Record reduced advisor
review protocol failures.
- #9691 -> `docs/changelog/2026-08-20.mdx`: Record managed llama.cpp
bridge cleanup coverage.
- #9692 -> `docs/changelog/2026-08-20.mdx`: Record upstream credential
rejection diagnostics.
- #9693 -> `docs/changelog/2026-08-20.mdx`: Record cumulative managed
vLLM documentation catch-up.
- #9694 -> `docs/changelog/2026-08-20.mdx`: Record the pinned Portable
rootless Podman runtime.
- #9695 -> `docs/changelog/2026-08-20.mdx`: Record owned llama.cpp image
publication.
- #9697 -> `docs/changelog/2026-08-20.mdx`: Record Windows-host Ollama
resume behavior.
- #9699 -> `docs/changelog/2026-08-20.mdx`: Record the separate trusted
Windows path oracle.
- #9702 -> `docs/changelog/2026-08-20.mdx`: Record sandbox bridge
cleanup coverage.
- #9703 -> `docs/changelog/2026-08-20.mdx`: Record hardened Ollama
installer downloads.
- #9704 -> `docs/changelog/2026-08-20.mdx`: Record supervised dashboard
recovery evidence.
- #9706 -> `docs/changelog/2026-08-20.mdx`: Record reused model and
reasoning health validation.
- #9708 -> `docs/changelog/2026-08-20.mdx`: Record fixed local vLLM
profile preservation.
- #9711 -> `docs/changelog/2026-08-20.mdx`: Record local registry
authority in E2E runs.
- #9712 -> `docs/changelog/2026-08-20.mdx`: Record Hermes dashboard
migration before gateway health.
- #9720 -> `docs/changelog/2026-08-20.mdx`: Record default OpenClaw
session admission during uninstall.
- #9721 -> `docs/changelog/2026-08-20.mdx`: Record MCP credential
republishing after policy binding.
- #9722 -> `docs/changelog/2026-08-20.mdx`: Record provider republishing
after Docker recreation.
- #9724 -> `docs/changelog/2026-08-20.mdx`: Record reclamation of dead
Shields lifecycle owners.
- #9725 -> `docs/changelog/2026-08-20.mdx`: Record fail-closed
unscripted onboarding prompts.
- #9729 -> `docs/changelog/2026-08-20.mdx`: Record aligned sandbox
launch forward ports.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [ ] Tests added or updated for changed behavior
- [x] Existing tests cover changed behavior — justification:
`test/changelog-docs.test.ts` validates the dated release-entry
contract.
- [ ] Tests not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit: Not applicable; documentation-only change.
- Station profile/scenario: Not applicable.
- Result: Not applicable.
- Supporting evidence: Not applicable.

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run validate:pr` passed after refreshing `origin/main` when hooks
were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — `npx vitest run
test/changelog-docs.test.ts` (7 passed).
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — command/result: Not applicable to one
prose-only changelog page.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) — passed
with 0 errors and the 2 existing Fern warnings.
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)
— the parser-safe MDX SPDX comment is present; native changelog pages
intentionally do not use frontmatter.

---
Signed-off-by: Charan Jagwani <cjagwani@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
  * Added release notes for v0.0.112.
* Documented improvements to managed model runtimes, sandbox recovery,
MCP and provider handling, messaging, Shields, and PR Review Advisor.
* Added details on release provenance, end-to-end qualification,
dependency updates, and documentation alignment.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
cjagwani added a commit that referenced this pull request Aug 21, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Restore the PR exact OpenClaw MCP qualification path end to end. The job
now onboards the exact managed image, preserves a classified MCP
credential environment alongside gateway-only inference credentials, and
performs authenticated discovery with the live revision-scoped OpenShell
placeholder.

## Root cause

The same two five-phase qualification jobs were genuinely green before
the dependency upgrade. The last clean pre-upgrade pair, [run
32332905722](https://github.com/NVIDIA/NemoClaw/actions/runs/32332905722)
at `ab5db717b`, installed OpenShell 0.0.101 and passed without a waiver.
[NemoClaw PR #9192](#9192) then
merged at 2026-08-19 22:29 PDT and upgraded OpenShell directly from
0.0.101 to 0.0.106. The first exact pair based on 0.0.106, [run
32338412376](https://github.com/NVIDIA/NemoClaw/actions/runs/32338412376),
failed phase 3 in both passes with no successful MCP request.

The causal OpenShell change is [OpenShell PR
#2510](NVIDIA/OpenShell#2510), merged as
`0120535ef`, which introduced endpoint-bound static credential
snapshots. A profileless inference provider contributes a static
environment key without binding or non-secret classification; the
binding-capable supervisor rejects that snapshot as `provider
environment contains an unclassified credential key` and revokes the
otherwise correctly bound MCP credential too.

The failures occurred at five successive boundaries:

1. The PR MCP child environment dropped the managed-image catalog and
activation inputs. Onboarding therefore built a Dockerfile image instead
of qualifying the candidate image.
2. With the exact image active, OpenShell 0.0.106 emitted the legacy
`openai` provider credential without selected-profile binding metadata.
The supervisor rejected the provider environment as containing an
unclassified credential and atomically withheld the MCP static
credential too.
3. After classifying the inference provider with an endpointless
profile, the discovery runtime still synthesized
`openshell:resolve:env:<KEY>`. OpenShell's bound resolver requires the
current live revision-scoped value
(`openshell:resolve:env:v<revision>_<KEY>`), so discovery received HTTP
500 before any request reached the fake MCP server.
4. Once diagnostic discovery used the live revision and successfully
listed `fake_echo` and `fake_status`, the managed mcporter config still
persisted the canonical unversioned placeholder. The direct
agent-adapter proof therefore received HTTP 500 even though the
diagnostic path was green.
5. After both diagnostic discovery and direct mcporter discovery passed,
the test entered a separate trusted-private DNS-rebinding fixture. That
fixture rewrote `/etc/hosts` on the runner and sandbox, but OpenShell
resolves egress in the Docker supervisor namespace. The supervisor never
observed the fake hostname mapping, rejected the connection before it
reached the server, and the negative-only raw probe had previously
passed for the same wrong reason.
6. Once both passes reached the rebuild lifecycle, the 0.0.106
migration's pre-delete `removeGeneratedPolicy()` correctly removed
`mcp-bridge-fake`, but the captured policy selection still handed that
generated name to inner onboarding and generic policy replay. The first
correction normalized the rebuild session, but resumed sandbox creation
then overwrote it from the intentionally preserved crash-recovery
registry row. Recreate therefore still failed deterministically with
`Preset not found: mcp-bridge-fake` before the dedicated MCP restore
phase could reattach the provider, generated policy, and adapter.

This is the normal host-gateway / one-container-per-sandbox topology. No
custom MCP sidecar is involved.

## Changes

- Preserve the workflow-owned managed-image catalog, candidate SHA, live
qualification flag, and supervisor image across the MCP child-process
boundary.
- Activate onboarding through `--temp-managed-runtime` and
`--temp-managed-runtime-catalog`, then require the sandbox receipt to
identify the exact candidate revision.
- Import an endpointless, inference-capable `openai` profile before the
endpointless MCP profile so OpenShell can classify gateway-only
inference credentials without injecting them into workloads.
- When `openai` already exists, export it and require the exact
gateway-only boundary: `id: openai`, empty
credentials/endpoints/binaries, and `inference_capable: true`. Fail
closed before MCP policy or provider mutation on export failure,
malformed output, or a mismatch.
- Make MCP discovery read the fresh process environment and accept only
a canonical or revision-scoped OpenShell placeholder for the declared
key. Raw, wrong-key, malformed, missing, and injected values fail closed
and never enter argv, output, or a request.
- Return the bounded live credential revision from the
attachment-readiness proof and project that exact revision into managed
mcporter configuration. Post-write registration inspection now requires
the same readiness-proven revision (`v12` cannot verify as `v11`);
canonical status/removal matching remains available only when readiness
was canonical.
- Qualify every `mcp-bridge-*.ts` change through the PR and main
managed-image workflow boundaries so adapter projection changes cannot
bypass this live proof.
- Scope exact managed-image CI to the topology it actually owns:
exact-image onboarding, authenticated public MCP discovery, direct
adapter use, endpoint boundaries, credential rotation, restart, and
removal. The evidence records `managed-image-discovery`; the job no
longer claims trusted-private DNS-rebinding coverage from a
runner/sandbox hosts fixture that cannot control the supervisor
resolver. Full MCP E2E retains that proof for supervisor-authoritative
DNS topologies.
- Exclude only the generated policy names already preserved by the MCP
rebuild transaction from inner-onboard and generic policy replay. The
outer rebuild now carries that normalized selection through an explicit
authoritative create intent, so sandbox recreation cannot replace it
from the stale source registry row or ambient policy variables.
Matching-journal recovery remains a fallback, a journal for another
sandbox cannot supply policy state, the crash-recovery registry remains
untouched, built-in and operator policy selections remain unchanged, and
the dedicated post-rebuild MCP phase remains the sole owner of restoring
the provider-bound generated policy and adapter.
- Rebuild and pin the reviewed MCP discovery runtime bundle.

The `openai` profile is a provisional compatibility path for the pinned
0.0.106 binary, not the intended ownership model. The ownership-free fix
is [OpenShell PR #2862](NVIDIA/OpenShell#2862):
at the gateway response boundary, remove each static key that lacks
binding metadata before sending the snapshot to a binding-capable
supervisor. Bound static credentials and valid dynamic credentials
remain active, provider resolution stays unchanged, and legacy
supervisors retain their existing strip-all behavior. The full
1,415-test server suite passes (1,408 passed, 7 ignored), as do
formatting and warning-as-error clippy. After that fix is released and
NemoClaw updates its pin, this PR should remove the provisional shared
profile and its lifecycle code.

## Type of Change

- [x] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [ ] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [x] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [ ] Tests not applicable — justification:
- [x] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — Senthil explicitly accepted the provisional `openai` profile
ownership boundary and approved at `52b2db132`; Ryan's rebuild and
exact-revision findings on `75aefaf3b` are addressed by signed commits
`a51adb149` and `6c05be2d9`, and the current head awaits re-review.
OpenShell PR #2862 remains the ownership-free follow-up.
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit:
- Station profile/scenario:
- Result:
- Supporting evidence:

## Verification

- [x] PR description includes a `Signed-off-by:` line and every pushed
commit is signed and DCO-compliant
- [x] Normal pre-commit, commit-msg, and pre-push hooks passed
- [x] Targeted behavior tests pass for the current change set — the
371-test MCP bridge suite, 217 publication/risk-boundary tests, the
current 179-test affected workflow/scope suite, the earlier 149 focused
provider, discovery, onboarding, image, build-context, and publication
tests, the current 126-test policy/rebuild suite, and the current
98-test adapter/status/crash/restart suite pass; the isolated discovery
runtime wire test and typecheck also pass
- [x] `npm run typecheck:cli`, `npm run build:cli`, focused Oxlint,
formatting, `npm run checks:repository`, and the 32-test growth guard
pass
- [ ] Applicable broad gate passed — current replacement managed-image
run
[32468003695](https://github.com/NVIDIA/NemoClaw/actions/runs/32468003695)
is pending for signed commit `6c05be2d9`; run
[32463784345](https://github.com/NVIDIA/NemoClaw/actions/runs/32463784345)
passed the exact-image build and phases 1–3 in both discovery passes,
including authenticated `fake_echo`/`fake_status` discovery with
`credentialRewriteMatched: true`, then proved that inner sandbox
creation still reloaded the stale generated-policy name from the
preserved registry; attempt 3 of run
[32457422244](https://github.com/NVIDIA/NemoClaw/actions/runs/32457422244)
first reproduced that same phase-4 boundary in both passes, run
[32454193518](https://github.com/NVIDIA/NemoClaw/actions/runs/32454193518)
first exposed rebuild failure, and run
[32452343170](https://github.com/NVIDIA/NemoClaw/actions/runs/32452343170)
reached live discovery in both passes but was cancelled by a newer push
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only)
- [ ] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

---
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>

---------

Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Charan Jagwani <cjagwani@nvidia.com>
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Co-authored-by: Senthil Ravichandran <senthilr@nvidia.com>
Co-authored-by: Charan Jagwani <cjagwani@nvidia.com>
Co-authored-by: Julie Yaunches <jyaunches@nvidia.com>
cv pushed a commit that referenced this pull request Aug 22, 2026
<!-- markdownlint-disable MD041 -->
## Summary

Hermes Discord reaches the native gateway with an OpenShell credential
placeholder, but the current generic provider has no endpoint binding
after the OpenShell 0.0.106 credential revision. This change attaches an
endpointless Hermes Discord profile and binds only the Discord
credential endpoints so REST and WebSocket rewrites can resolve the
token without exposing it.

## Changes

- Add deterministic coverage requiring the Hermes Discord provider to
use an endpointless profile.
- Require the Discord REST and gateway policy endpoints to bind the
exact sandbox-scoped provider while leaving the CDN endpoint unbound.
- Materialize the sandbox-scoped provider name in the Discord policy and
require an exact provider type and credential name before reusing an
existing provider.
- Extend the live fake-gateway setup to bind its temporary endpoint
while preserving the exact `UPGRADE`, `HELLO`, `IDENTIFY`, `READY`,
acknowledgement, and raw-token assertions.

Current requirement and consumer: OpenShell 0.0.106 requires endpoint
authorization before resolving a static placeholder, and Hermes
`discord.py` sends that placeholder in the Discord IDENTIFY payload. A
policy-only direct change is insufficient because `credential_binding`
requires an attached endpointless provider profile.
`test/hermes-discord-credential-binding.test.ts` protects both sides of
this contract.

## Type of Change

- [x] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [ ] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [x] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [ ] Tests not applicable — justification:
- [x] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [x] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification: security self-review
covered authentication, authorization, secrets, injection, transport,
dependencies, cryptography, failure handling, and test coverage; all
categories passed with no findings. Automated review remains required
before this draft becomes ready.
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit: Not applicable; this change does not modify
`scripts/prepare-dgx-station-host.sh`.
- Station profile/scenario: Not applicable.
- Result: Not applicable.
- Supporting evidence: Not applicable.

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run validate:pr` passed after refreshing `origin/main` when hooks
were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — fail-first commit
`ab595507a7e7d79689882c1eb4038fafbc9d9476` fails both new assertions on
unchanged main. Corrective commit
`e7796bbf83776262b1ef2cac240b473401386c36` passes 296 focused tests
across the messaging provider, bridge, preparation, onboarding, policy,
effective-policy, and schema suites. CLI type-checking, repository
checks, package/config schema checks (128 tests), and the portable
inventory check also pass.
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — command/result: `npm run test:changed`
completed with 24,028 passing, 76 skipped, and 58 failing tests across
32 files. The changed behavior suites pass; observed failures are shared
process/Oclif timeouts, unrelated state leakage, and an existing ignored
`nemoclaw-blueprint/router/llm-router/.env.example` portable-inventory
entry. Required GitHub checks and the final exact live target remain
pending.
- [ ] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only)
- [ ] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

### Regression source

- Root-cause key: `Hermes Discord / native gateway rewrite /
ReconnectWebSocket returns None instead of websocket UPGRADE`
- Ordinary main run:
https://github.com/NVIDIA/NemoClaw/actions/runs/32460591192 (run
`32460591192`, attempt `1`, `workflow_dispatch`)
- Failed job:
https://github.com/NVIDIA/NemoClaw/actions/runs/32460591192/job/96713099714
(`96713099714`, `Messaging: Hermes preserves Discord configuration
across rebuild / NVIDIA inference API key`)
- Tested main commit and workflow SHA:
`fac4e6d6783e8909aabf4a9d94f5fa809fea3ec1`
- Stable signature: `test/e2e/live/hermes-discord.test.ts:608` expected
`UPGRADE`, received exactly `ERROR ReconnectWebSocket: None`.
- Install, provider/health, configuration, and placeholder phases
passed. Cleanup passed.
- The same signature first appeared after `chore(deps): update OpenShell
to 0.0.106 (#9192)`: the last passing exact target was
https://github.com/NVIDIA/NemoClaw/actions/runs/32330051811/job/96309077343,
and the first observed failing main target was in
https://github.com/NVIDIA/NemoClaw/actions/runs/32335841665.

Scope declaration: this PR owns only the Hermes Discord
provider-to-endpoint credential-binding regression and its native
gateway proof. It does not address the separate Hermes Slack HTTP 500 or
Brave credential failure, add broad retries, or weaken the live
assertion.

The exact `hermes-discord` E2E target on the final candidate and
responses to every actionable review finding remain required before this
draft can become ready.

### Review and CI follow-up

- Corrective head `e7796bbf83776262b1ef2cac240b473401386c36` exposed a
duplicate `discord-bridge` cleanup suffix in CLI shard 1
(`test/sandbox-provider-cleanup.test.ts:34`, job `96726254168`). Commit
`cd9f257804c756edff5ac85bd84fe17f5fefcb3c` deduplicates the combined
manifest/profile inventory so cleanup issues exactly one detach per
provider suffix. The exact failing test and adjacent destroy/Discord
binding coverage pass (39 tests); the broader affected integration
selection passes (54 tests), CLI type-checking passes, and normal
commit/push hooks pass.
- The GPT-5.6 Terra advisor lane on
`e7796bbf83776262b1ef2cac240b473401386c36` failed its internal
submit-review accounting contract. The published advisor assessment
recorded zero blockers, zero warnings, zero required suggestions, and
`No advisor follow-up needed`; Nemotron completed with high confidence.
A fresh assessment on the final head remains pending.
- Advisor blocker `PRA-1` on `cd9f257804c756edff5ac85bd84fe17f5fefcb3c`
identified that an existing same-ID static profile was trusted without
verifying its authority boundary. Commit
`c03f880b24a0022f8242ae5d987ae54d8641a12a` now exports existing static
profiles as JSON and compares their ID, full credential/header
configuration, empty endpoint list, empty binary list, and non-inference
capability with the checked-in YAML. It also verifies an import-race
winner and fails closed before provider creation on any mismatch.
Profile-registration tests pass (34), including matching, endpoint
drift, binary drift, credential drift, and race cases; the broader
affected CLI selection passes (143), affected integration tests pass
(54), CLI type-checking passes, and normal commit/push hooks pass.

---
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

- **New Features**
- Added support for Hermes Discord providers using static bot-token
credentials.
- Discord REST and WebSocket endpoints now use sandbox-specific
providers.
- Messaging setup selects provider profiles based on the configured
agent and channel.
- Sandbox-specific policies safely substitute valid sandbox names,
including during snapshot restores.
- Permissive runtime policies preserve sandbox-specific Discord
credential bindings.

- **Bug Fixes**
- Improved credential reuse and validation for compatible provider
configurations.
- Prevented unsafe, incomplete, or incompatible provider configurations
from being reused.
  - Preserved existing credentials when matching bindings are detected.
- Enforced exact credential bindings and prevented updates when
conflicts are detected.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: install Install, setup, prerequisites, or uninstall flow area: sandbox OpenShell sandbox lifecycle, runtime, config, or recovery chore Build, CI, dependency, or tooling maintenance security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants