chore(deps): update OpenShell to 0.0.106 - #9192
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughOpenShell support is upgraded from ChangesOpenShell 0.0.106 release integration
Estimated code review effort: 4 (Complex) | ~60 minutes Merge Risk: 🟡 Moderate · up to The dependency update changes installation and workflow validation behavior, but merge readiness is not yet clean because stable workflow checks may accept additional unreviewed installer commands and the release security documentation may attribute older-version evidence to the new version; explicit owner follow-up is needed before merge. Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
PR Review Advisor — InformationalAdvisor assessment: Informational / low confidence Model lanes
Second-opinion terminology and E2E selections are advisory. Live E2E does not run automatically for pull requests. E2E guidanceAdvisory only. A maintainer can dispatch the default E2E suite for the commit under review. Recommended E2E: Manual-only E2E: This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
prekshivyas
left a comment
There was a problem hiding this comment.
Reviewed exact head 26248e1 after merging current main. The conflict resolution retains the main 0.0.103 trust records and the candidate 0.0.105 manifest records, and focused dependency tests plus shell syntax checks pass locally. This draft cannot become green or approvable yet: the base-trusted installer parser on main has no reviewed 0.0.105 standalone-sandbox or supervisor identities, so candidate code cannot self-authorize them; check-hash fails closed as designed. The protected Podman proof also still dispatches OpenShell 0.0.101 while the candidate installer intentionally accepts only 0.0.105. Land the prerequisite trust identities on main and update the protected workflow pin through the authorized dependency process, then refresh this branch. GitHub also prohibits me from approving my own PR.
68c7ce4 to
53396de
Compare
Patch-Walker-Manifest: sha256:7d6533d0fb5cb297bffd415e1c07fb744cd770eb059258707bef1b617900787d Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
ac0274a to
30d2dcb
Compare
30d2dcb to
bc8f1d6
Compare
bc8f1d6 to
d107fba
Compare
Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
d107fba to
d204b66
Compare
Patch-Walker-Manifest: sha256:8fbcac736e876d15a8d2e9c6433aac3a616dbafa754933ca6a36c8a4730fe44d Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:8fbcac736e876d15a8d2e9c6433aac3a616dbafa754933ca6a36c8a4730fe44d Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:8fbcac736e876d15a8d2e9c6433aac3a616dbafa754933ca6a36c8a4730fe44d Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:6d6499fda9409244210dd3dac0afcb0962928c106f1a5ab08ef5a2530193e5af Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:24726c2eac18527fa6e37220662188b77f6e1284cf343c7d1197f11e5cf4e81b Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:6d6e27ca3454cc7cb9996326f35a4e203fedafb73e414f0c3b7b0fd645547736 Refs NVIDIA#6256 Refs NVIDIA#3136 Refs NVIDIA#6871 Refs NVIDIA#7367 Refs NVIDIA#7937 Refs NVIDIA#7957 Refs NVIDIA#8769 Refs NVIDIA#8887 Refs NVIDIA#8893 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Patch-Walker-Manifest: sha256:24444858ce8f9cfb285bc06375dd8e5cdabf62e68112086251b97bf6f027c0c4 Prerequisite-PR: NVIDIA#9224 Prerequisite-Commit: 080b144 Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
…l-0.0.105-31ee658967
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
…alker/openshell-0.0.105-31ee658967
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
…l-0.0.105-31ee658967
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
…l-0.0.105-31ee658967
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
senthilr-nv
left a comment
There was a problem hiding this comment.
Blocking: OpenShell 0.0.106 requires every static credential exposed as an environment placeholder to be classified by endpoint-binding metadata. This PR now requires 0.0.106, but src/lib/actions/sandbox/mcp-bridge-provider-mutation.ts:51 still creates a profile-less generic provider, and src/lib/actions/sandbox/mcp-bridge-policy-render.ts:104-111 emits the endpoint without credential_binding.provider. In v0.0.106 the gateway therefore supplies the credential with no binding and the supervisor rejects the snapshot as an unclassified credential key, so authenticated MCP bridges lose credential projection. The new docs at docs/deployment/set-up-mcp-bridge.mdx:95-99 also describe the old sandbox-scoped behavior instead of this fail-closed requirement. Import or use an endpointless provider profile, bind the generated endpoint to its concrete provider, update the status and docs, and add a v0.0.106 regression proving resolution only on the intended endpoint.
apurvvkumaria
left a comment
There was a problem hiding this comment.
Reviewed commit 24d5f55. I found no critical blocker. The OpenShell 0.0.106 dependency is pinned with immutable installer and supervisor provenance, feature gates and credential-boundary evidence match the new contract, and runtime identity now mints credentials after provider attachment with compensating cleanup on failure. Trusted exact-head E2E run 32320521878 completed successfully, including the runtime-identity scenario that previously blocked this migration.
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com>
senthilr-nv
left a comment
There was a problem hiding this comment.
Reviewed latest PR commit e3a53c9. Accepted scope is established by #8893. The OpenShell 0.0.106 MCP path now validates an endpointless nemoclaw-mcp-v1 profile, attaches under an unbound capability policy, applies credential_binding.provider before readiness, rejects legacy generic providers for active use while preserving exact cleanup, and removes bound policy before detach. Owning docs and status guidance match the contract. Security review found no blocker across credential handling, ownership, policy restriction, rollback, or dependency integrity. Focused validation passed: MCP/vLLM 147/147, selector 7/7, package contract 4/4, CLI typecheck/build, repository checks, docs, and normal commit/push hooks. Cross-issue sweep found no adjacent fix or contradiction above the confidence floor.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
senthilr-nv
left a comment
There was a problem hiding this comment.
Reviewed commit ab648f9. Accepted scope is established by #8893. The OpenShell 0.0.106 MCP contract now uses the reviewed provider profile and endpoint credential binding; the follow-up preserves legacy generic-provider cleanup while rejecting rebuild before managed state changes. Focused validation passed 75/75 tests plus CLI type-checking. No unresolved correctness, security, architecture, documentation, or automated-feedback blocker remains.
<!-- markdownlint-disable MD041 --> ## Summary Add the canonical dated changelog entry required before planning the v0.0.112 release. The entry summarizes the 75 merged PRs in `v0.0.111..af56158`, links user-facing themes to published documentation routes, and links every included source PR. ## Changes - Add `docs/changelog/2026-08-20.mdx` with the exact `## v0.0.112` release heading and parser-safe MDX SPDX comment. - Cover managed local inference, onboarding and sandbox lifecycle recovery, messaging continuity, review and release automation, E2E qualification, dependency updates, and cumulative documentation catch-up. - Preserve the documentation skip list and supported-agent matrix; the release entry contains none of the blocked terms or excluded experimental surfaces. ### Source-to-doc mapping - #8620 -> `docs/changelog/2026-08-20.mdx`: Record the LangChain Deep Agents Code 0.1.55 update. - #9192 -> `docs/changelog/2026-08-20.mdx`: Record the OpenShell 0.0.106 update. - #9240 -> `docs/changelog/2026-08-20.mdx`: Record the cold base-image pull heartbeat. - #9412 -> `docs/changelog/2026-08-20.mdx`: Record voice context preservation across sequential turns. - #9483 -> `docs/changelog/2026-08-20.mdx`: Record Ollama model verification through the sandbox endpoint. - #9493 -> `docs/changelog/2026-08-20.mdx`: Record E2E cloud-check wiring coverage. - #9495 -> `docs/changelog/2026-08-20.mdx`: Record Model Router endpoint health validation. - #9534 -> `docs/changelog/2026-08-20.mdx`: Record default-sandbox resolution for tunnel status. - #9537 -> `docs/changelog/2026-08-20.mdx`: Record Linux AMD64 Muse and Lightning profiles. - #9543 -> `docs/changelog/2026-08-20.mdx`: Record corrected network-policy preset examples. - #9545 -> `docs/changelog/2026-08-20.mdx`: Record shared runtime-adapter port validation. - #9578 -> `docs/changelog/2026-08-20.mdx`: Record Portable network creation before host aliases. - #9589 -> `docs/changelog/2026-08-20.mdx`: Record running vLLM profile validation. - #9590 -> `docs/changelog/2026-08-20.mdx`: Record the two-turn atomic advisor review. - #9597 -> `docs/changelog/2026-08-20.mdx`: Record Portable uninstall without host-owned lifecycle resources. - #9605 -> `docs/changelog/2026-08-20.mdx`: Record release automation for an initially empty tag history. - #9607 -> `docs/changelog/2026-08-20.mdx`: Record credential retry navigation. - #9626 -> `docs/changelog/2026-08-20.mdx`: Record retirement of DeepSeek V4 Pro from the featured menu. - #9631 -> `docs/changelog/2026-08-20.mdx`: Record reduction-directed advisor design blockers. - #9632 -> `docs/changelog/2026-08-20.mdx`: Record Portable Ollama under Podman. - #9633 -> `docs/changelog/2026-08-20.mdx`: Record llama.cpp attachment without `/props` model aliases. - #9636 -> `docs/changelog/2026-08-20.mdx`: Record Docker authority independent of terminal state. - #9641 -> `docs/changelog/2026-08-20.mdx`: Record the separate Portable host-gateway subnet. - #9642 -> `docs/changelog/2026-08-20.mdx`: Record cumulative command documentation catch-up. - #9645 -> `docs/changelog/2026-08-20.mdx`: Record removal of completed advisor rollout compatibility. - #9647 -> `docs/changelog/2026-08-20.mdx`: Record diagnostics for OpenShell deletion handoffs. - #9650 -> `docs/changelog/2026-08-20.mdx`: Record OpenClaw pairing settlement after route changes. - #9652 -> `docs/changelog/2026-08-20.mdx`: Record repaired same-turn advisor submissions. - #9653 -> `docs/changelog/2026-08-20.mdx`: Record llama.cpp authority preservation on resume. - #9654 -> `docs/changelog/2026-08-20.mdx`: Record the schema-owned Microsoft Teams webhook field. - #9655 -> `docs/changelog/2026-08-20.mdx`: Record configured managed vLLM ports. - #9656 -> `docs/changelog/2026-08-20.mdx`: Record interrupted managed vLLM installation recovery. - #9660 -> `docs/changelog/2026-08-20.mdx`: Record catalog-owned vLLM profiles and refreshed llama.cpp pins. - #9663 -> `docs/changelog/2026-08-20.mdx`: Record attested LKG production-image requests. - #9664 -> `docs/changelog/2026-08-20.mdx`: Record corrected documented environment-variable handling. - #9665 -> `docs/changelog/2026-08-20.mdx`: Record retired gateway evidence validation. - #9666 -> `docs/changelog/2026-08-20.mdx`: Record Docker authority across terminal sessions. - #9667 -> `docs/changelog/2026-08-20.mdx`: Record contribution intake and product-decision guidance. - #9669 -> `docs/changelog/2026-08-20.mdx`: Record bounded DGX Spark llama.cpp request bodies. - #9670 -> `docs/changelog/2026-08-20.mdx`: Record managed llama.cpp bridge authentication. - #9671 -> `docs/changelog/2026-08-20.mdx`: Record gateway recreation after Docker network loss. - #9672 -> `docs/changelog/2026-08-20.mdx`: Record bounded WSL Ollama host probes. - #9674 -> `docs/changelog/2026-08-20.mdx`: Record cumulative inference and command documentation catch-up. - #9675 -> `docs/changelog/2026-08-20.mdx`: Record Muse Glimmer vLLM image revision handling. - #9676 -> `docs/changelog/2026-08-20.mdx`: Record the grouped CodeQL Actions update. - #9677 -> `docs/changelog/2026-08-20.mdx`: Record the actions/setup-go 7.0.0 update. - #9678 -> `docs/changelog/2026-08-20.mdx`: Record resumable failed llama.cpp cleanup. - #9681 -> `docs/changelog/2026-08-20.mdx`: Record Docker executable injection in the state-mutation harness. - #9683 -> `docs/changelog/2026-08-20.mdx`: Record Windows Docker path fixtures. - #9684 -> `docs/changelog/2026-08-20.mdx`: Record isolated macOS status subprocess cleanup. - #9686 -> `docs/changelog/2026-08-20.mdx`: Record managed-inference catalog compilation for Portable E2E. - #9687 -> `docs/changelog/2026-08-20.mdx`: Record cumulative uninstall documentation catch-up. - #9688 -> `docs/changelog/2026-08-20.mdx`: Record DCode model-selector loading through tsx. - #9689 -> `docs/changelog/2026-08-20.mdx`: Record bounded docs-parity process starts. - #9690 -> `docs/changelog/2026-08-20.mdx`: Record reduced advisor review protocol failures. - #9691 -> `docs/changelog/2026-08-20.mdx`: Record managed llama.cpp bridge cleanup coverage. - #9692 -> `docs/changelog/2026-08-20.mdx`: Record upstream credential rejection diagnostics. - #9693 -> `docs/changelog/2026-08-20.mdx`: Record cumulative managed vLLM documentation catch-up. - #9694 -> `docs/changelog/2026-08-20.mdx`: Record the pinned Portable rootless Podman runtime. - #9695 -> `docs/changelog/2026-08-20.mdx`: Record owned llama.cpp image publication. - #9697 -> `docs/changelog/2026-08-20.mdx`: Record Windows-host Ollama resume behavior. - #9699 -> `docs/changelog/2026-08-20.mdx`: Record the separate trusted Windows path oracle. - #9702 -> `docs/changelog/2026-08-20.mdx`: Record sandbox bridge cleanup coverage. - #9703 -> `docs/changelog/2026-08-20.mdx`: Record hardened Ollama installer downloads. - #9704 -> `docs/changelog/2026-08-20.mdx`: Record supervised dashboard recovery evidence. - #9706 -> `docs/changelog/2026-08-20.mdx`: Record reused model and reasoning health validation. - #9708 -> `docs/changelog/2026-08-20.mdx`: Record fixed local vLLM profile preservation. - #9711 -> `docs/changelog/2026-08-20.mdx`: Record local registry authority in E2E runs. - #9712 -> `docs/changelog/2026-08-20.mdx`: Record Hermes dashboard migration before gateway health. - #9720 -> `docs/changelog/2026-08-20.mdx`: Record default OpenClaw session admission during uninstall. - #9721 -> `docs/changelog/2026-08-20.mdx`: Record MCP credential republishing after policy binding. - #9722 -> `docs/changelog/2026-08-20.mdx`: Record provider republishing after Docker recreation. - #9724 -> `docs/changelog/2026-08-20.mdx`: Record reclamation of dead Shields lifecycle owners. - #9725 -> `docs/changelog/2026-08-20.mdx`: Record fail-closed unscripted onboarding prompts. - #9729 -> `docs/changelog/2026-08-20.mdx`: Record aligned sandbox launch forward ports. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the dated release-entry contract. - [ ] Tests not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable; documentation-only change. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts` (7 passed). - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to one prose-only changelog page. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — passed with 0 errors and the 2 existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — the parser-safe MDX SPDX comment is present; native changelog pages intentionally do not use frontmatter. --- Signed-off-by: Charan Jagwani <cjagwani@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for v0.0.112. * Documented improvements to managed model runtimes, sandbox recovery, MCP and provider handling, messaging, Shields, and PR Review Advisor. * Added details on release provenance, end-to-end qualification, dependency updates, and documentation alignment. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
<!-- markdownlint-disable MD041 --> ## Summary Restore the PR exact OpenClaw MCP qualification path end to end. The job now onboards the exact managed image, preserves a classified MCP credential environment alongside gateway-only inference credentials, and performs authenticated discovery with the live revision-scoped OpenShell placeholder. ## Root cause The same two five-phase qualification jobs were genuinely green before the dependency upgrade. The last clean pre-upgrade pair, [run 32332905722](https://github.com/NVIDIA/NemoClaw/actions/runs/32332905722) at `ab5db717b`, installed OpenShell 0.0.101 and passed without a waiver. [NemoClaw PR #9192](#9192) then merged at 2026-08-19 22:29 PDT and upgraded OpenShell directly from 0.0.101 to 0.0.106. The first exact pair based on 0.0.106, [run 32338412376](https://github.com/NVIDIA/NemoClaw/actions/runs/32338412376), failed phase 3 in both passes with no successful MCP request. The causal OpenShell change is [OpenShell PR #2510](NVIDIA/OpenShell#2510), merged as `0120535ef`, which introduced endpoint-bound static credential snapshots. A profileless inference provider contributes a static environment key without binding or non-secret classification; the binding-capable supervisor rejects that snapshot as `provider environment contains an unclassified credential key` and revokes the otherwise correctly bound MCP credential too. The failures occurred at five successive boundaries: 1. The PR MCP child environment dropped the managed-image catalog and activation inputs. Onboarding therefore built a Dockerfile image instead of qualifying the candidate image. 2. With the exact image active, OpenShell 0.0.106 emitted the legacy `openai` provider credential without selected-profile binding metadata. The supervisor rejected the provider environment as containing an unclassified credential and atomically withheld the MCP static credential too. 3. After classifying the inference provider with an endpointless profile, the discovery runtime still synthesized `openshell:resolve:env:<KEY>`. OpenShell's bound resolver requires the current live revision-scoped value (`openshell:resolve:env:v<revision>_<KEY>`), so discovery received HTTP 500 before any request reached the fake MCP server. 4. Once diagnostic discovery used the live revision and successfully listed `fake_echo` and `fake_status`, the managed mcporter config still persisted the canonical unversioned placeholder. The direct agent-adapter proof therefore received HTTP 500 even though the diagnostic path was green. 5. After both diagnostic discovery and direct mcporter discovery passed, the test entered a separate trusted-private DNS-rebinding fixture. That fixture rewrote `/etc/hosts` on the runner and sandbox, but OpenShell resolves egress in the Docker supervisor namespace. The supervisor never observed the fake hostname mapping, rejected the connection before it reached the server, and the negative-only raw probe had previously passed for the same wrong reason. 6. Once both passes reached the rebuild lifecycle, the 0.0.106 migration's pre-delete `removeGeneratedPolicy()` correctly removed `mcp-bridge-fake`, but the captured policy selection still handed that generated name to inner onboarding and generic policy replay. The first correction normalized the rebuild session, but resumed sandbox creation then overwrote it from the intentionally preserved crash-recovery registry row. Recreate therefore still failed deterministically with `Preset not found: mcp-bridge-fake` before the dedicated MCP restore phase could reattach the provider, generated policy, and adapter. This is the normal host-gateway / one-container-per-sandbox topology. No custom MCP sidecar is involved. ## Changes - Preserve the workflow-owned managed-image catalog, candidate SHA, live qualification flag, and supervisor image across the MCP child-process boundary. - Activate onboarding through `--temp-managed-runtime` and `--temp-managed-runtime-catalog`, then require the sandbox receipt to identify the exact candidate revision. - Import an endpointless, inference-capable `openai` profile before the endpointless MCP profile so OpenShell can classify gateway-only inference credentials without injecting them into workloads. - When `openai` already exists, export it and require the exact gateway-only boundary: `id: openai`, empty credentials/endpoints/binaries, and `inference_capable: true`. Fail closed before MCP policy or provider mutation on export failure, malformed output, or a mismatch. - Make MCP discovery read the fresh process environment and accept only a canonical or revision-scoped OpenShell placeholder for the declared key. Raw, wrong-key, malformed, missing, and injected values fail closed and never enter argv, output, or a request. - Return the bounded live credential revision from the attachment-readiness proof and project that exact revision into managed mcporter configuration. Post-write registration inspection now requires the same readiness-proven revision (`v12` cannot verify as `v11`); canonical status/removal matching remains available only when readiness was canonical. - Qualify every `mcp-bridge-*.ts` change through the PR and main managed-image workflow boundaries so adapter projection changes cannot bypass this live proof. - Scope exact managed-image CI to the topology it actually owns: exact-image onboarding, authenticated public MCP discovery, direct adapter use, endpoint boundaries, credential rotation, restart, and removal. The evidence records `managed-image-discovery`; the job no longer claims trusted-private DNS-rebinding coverage from a runner/sandbox hosts fixture that cannot control the supervisor resolver. Full MCP E2E retains that proof for supervisor-authoritative DNS topologies. - Exclude only the generated policy names already preserved by the MCP rebuild transaction from inner-onboard and generic policy replay. The outer rebuild now carries that normalized selection through an explicit authoritative create intent, so sandbox recreation cannot replace it from the stale source registry row or ambient policy variables. Matching-journal recovery remains a fallback, a journal for another sandbox cannot supply policy state, the crash-recovery registry remains untouched, built-in and operator policy selections remain unchanged, and the dedicated post-rebuild MCP phase remains the sole owner of restoring the provider-bound generated policy and adapter. - Rebuild and pin the reviewed MCP discovery runtime bundle. The `openai` profile is a provisional compatibility path for the pinned 0.0.106 binary, not the intended ownership model. The ownership-free fix is [OpenShell PR #2862](NVIDIA/OpenShell#2862): at the gateway response boundary, remove each static key that lacks binding metadata before sending the snapshot to a binding-capable supervisor. Bound static credentials and valid dynamic credentials remain active, provider resolution stays unchanged, and legacy supervisors retain their existing strip-all behavior. The full 1,415-test server suite passes (1,408 passed, 7 ignored), as do formatting and warning-as-error clippy. After that fix is released and NemoClaw updates its pin, this PR should remove the provisional shared profile and its lifecycle code. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — Senthil explicitly accepted the provisional `openai` profile ownership boundary and approved at `52b2db132`; Ryan's rebuild and exact-revision findings on `75aefaf3b` are addressed by signed commits `a51adb149` and `6c05be2d9`, and the current head awaits re-review. OpenShell PR #2862 remains the ownership-free follow-up. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: - Station profile/scenario: - Result: - Supporting evidence: ## Verification - [x] PR description includes a `Signed-off-by:` line and every pushed commit is signed and DCO-compliant - [x] Normal pre-commit, commit-msg, and pre-push hooks passed - [x] Targeted behavior tests pass for the current change set — the 371-test MCP bridge suite, 217 publication/risk-boundary tests, the current 179-test affected workflow/scope suite, the earlier 149 focused provider, discovery, onboarding, image, build-context, and publication tests, the current 126-test policy/rebuild suite, and the current 98-test adapter/status/crash/restart suite pass; the isolated discovery runtime wire test and typecheck also pass - [x] `npm run typecheck:cli`, `npm run build:cli`, focused Oxlint, formatting, `npm run checks:repository`, and the 32-test growth guard pass - [ ] Applicable broad gate passed — current replacement managed-image run [32468003695](https://github.com/NVIDIA/NemoClaw/actions/runs/32468003695) is pending for signed commit `6c05be2d9`; run [32463784345](https://github.com/NVIDIA/NemoClaw/actions/runs/32463784345) passed the exact-image build and phases 1–3 in both discovery passes, including authenticated `fake_echo`/`fake_status` discovery with `credentialRewriteMatched: true`, then proved that inner sandbox creation still reloaded the stale generated-policy name from the preserved registry; attempt 3 of run [32457422244](https://github.com/NVIDIA/NemoClaw/actions/runs/32457422244) first reproduced that same phase-4 boundary in both passes, run [32454193518](https://github.com/NVIDIA/NemoClaw/actions/runs/32454193518) first exposed rebuild failure, and run [32452343170](https://github.com/NVIDIA/NemoClaw/actions/runs/32452343170) reached live discovery in both passes but was cancelled by a newer push - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> --------- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> Signed-off-by: Senthil Ravichandran <senthilr@nvidia.com> Signed-off-by: Charan Jagwani <cjagwani@nvidia.com> Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> Co-authored-by: Senthil Ravichandran <senthilr@nvidia.com> Co-authored-by: Charan Jagwani <cjagwani@nvidia.com> Co-authored-by: Julie Yaunches <jyaunches@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Hermes Discord reaches the native gateway with an OpenShell credential placeholder, but the current generic provider has no endpoint binding after the OpenShell 0.0.106 credential revision. This change attaches an endpointless Hermes Discord profile and binds only the Discord credential endpoints so REST and WebSocket rewrites can resolve the token without exposing it. ## Changes - Add deterministic coverage requiring the Hermes Discord provider to use an endpointless profile. - Require the Discord REST and gateway policy endpoints to bind the exact sandbox-scoped provider while leaving the CDN endpoint unbound. - Materialize the sandbox-scoped provider name in the Discord policy and require an exact provider type and credential name before reusing an existing provider. - Extend the live fake-gateway setup to bind its temporary endpoint while preserving the exact `UPGRADE`, `HELLO`, `IDENTIFY`, `READY`, acknowledgement, and raw-token assertions. Current requirement and consumer: OpenShell 0.0.106 requires endpoint authorization before resolving a static placeholder, and Hermes `discord.py` sends that placeholder in the Discord IDENTIFY payload. A policy-only direct change is insufficient because `credential_binding` requires an attached endpointless provider profile. `test/hermes-discord-credential-binding.test.ts` protects both sides of this contract. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [x] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: security self-review covered authentication, authorization, secrets, injection, transport, dependencies, cryptography, failure handling, and test coverage; all categories passed with no findings. Automated review remains required before this draft becomes ready. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable; this change does not modify `scripts/prepare-dgx-station-host.sh`. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — fail-first commit `ab595507a7e7d79689882c1eb4038fafbc9d9476` fails both new assertions on unchanged main. Corrective commit `e7796bbf83776262b1ef2cac240b473401386c36` passes 296 focused tests across the messaging provider, bridge, preparation, onboarding, policy, effective-policy, and schema suites. CLI type-checking, repository checks, package/config schema checks (128 tests), and the portable inventory check also pass. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: `npm run test:changed` completed with 24,028 passing, 76 skipped, and 58 failing tests across 32 files. The changed behavior suites pass; observed failures are shared process/Oclif timeouts, unrelated state leakage, and an existing ignored `nemoclaw-blueprint/router/llm-router/.env.example` portable-inventory entry. Required GitHub checks and the final exact live target remain pending. - [ ] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) ### Regression source - Root-cause key: `Hermes Discord / native gateway rewrite / ReconnectWebSocket returns None instead of websocket UPGRADE` - Ordinary main run: https://github.com/NVIDIA/NemoClaw/actions/runs/32460591192 (run `32460591192`, attempt `1`, `workflow_dispatch`) - Failed job: https://github.com/NVIDIA/NemoClaw/actions/runs/32460591192/job/96713099714 (`96713099714`, `Messaging: Hermes preserves Discord configuration across rebuild / NVIDIA inference API key`) - Tested main commit and workflow SHA: `fac4e6d6783e8909aabf4a9d94f5fa809fea3ec1` - Stable signature: `test/e2e/live/hermes-discord.test.ts:608` expected `UPGRADE`, received exactly `ERROR ReconnectWebSocket: None`. - Install, provider/health, configuration, and placeholder phases passed. Cleanup passed. - The same signature first appeared after `chore(deps): update OpenShell to 0.0.106 (#9192)`: the last passing exact target was https://github.com/NVIDIA/NemoClaw/actions/runs/32330051811/job/96309077343, and the first observed failing main target was in https://github.com/NVIDIA/NemoClaw/actions/runs/32335841665. Scope declaration: this PR owns only the Hermes Discord provider-to-endpoint credential-binding regression and its native gateway proof. It does not address the separate Hermes Slack HTTP 500 or Brave credential failure, add broad retries, or weaken the live assertion. The exact `hermes-discord` E2E target on the final candidate and responses to every actionable review finding remain required before this draft can become ready. ### Review and CI follow-up - Corrective head `e7796bbf83776262b1ef2cac240b473401386c36` exposed a duplicate `discord-bridge` cleanup suffix in CLI shard 1 (`test/sandbox-provider-cleanup.test.ts:34`, job `96726254168`). Commit `cd9f257804c756edff5ac85bd84fe17f5fefcb3c` deduplicates the combined manifest/profile inventory so cleanup issues exactly one detach per provider suffix. The exact failing test and adjacent destroy/Discord binding coverage pass (39 tests); the broader affected integration selection passes (54 tests), CLI type-checking passes, and normal commit/push hooks pass. - The GPT-5.6 Terra advisor lane on `e7796bbf83776262b1ef2cac240b473401386c36` failed its internal submit-review accounting contract. The published advisor assessment recorded zero blockers, zero warnings, zero required suggestions, and `No advisor follow-up needed`; Nemotron completed with high confidence. A fresh assessment on the final head remains pending. - Advisor blocker `PRA-1` on `cd9f257804c756edff5ac85bd84fe17f5fefcb3c` identified that an existing same-ID static profile was trusted without verifying its authority boundary. Commit `c03f880b24a0022f8242ae5d987ae54d8641a12a` now exports existing static profiles as JSON and compares their ID, full credential/header configuration, empty endpoint list, empty binary list, and non-inference capability with the checked-in YAML. It also verifies an import-race winner and fails closed before provider creation on any mismatch. Profile-registration tests pass (34), including matching, endpoint drift, binary drift, credential drift, and race cases; the broader affected CLI selection passes (143), affected integration tests pass (54), CLI type-checking passes, and normal commit/push hooks pass. --- Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **New Features** - Added support for Hermes Discord providers using static bot-token credentials. - Discord REST and WebSocket endpoints now use sandbox-specific providers. - Messaging setup selects provider profiles based on the configured agent and channel. - Sandbox-specific policies safely substitute valid sandbox names, including during snapshot restores. - Permissive runtime policies preserve sandbox-specific Discord credential bindings. - **Bug Fixes** - Improved credential reuse and validation for compatible provider configurations. - Prevented unsafe, incomplete, or incompatible provider configurations from being reused. - Preserved existing credentials when matching bindings are detected. - Enforced exact credential bindings and prevented updates when conflicts are detected. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Summary
Updates OpenShell from 0.0.101 to 0.0.106 using the sealed NemoPin migration evidence. Release-trust prerequisite #9224 is merged on
main, and the E2E-selector work from #9378 is included in this branch. The PR is reconciled with currentmainat latest PR commite3a53c96f.Related Issue
Changes
sha256:65355e5c4180f3716fd8e0d0431d432a876460a7005db6099fa18a8599c3037e.44c2636d85f788f81767fbb451717566e0a8d475across 5 adjacent release ranges.mainat base commit40dc27283, includes the reviewed E2E-selector work from ci(e2e): select OpenShell 0.0.106 #9378, adopts the upstream messaging-plan fixture fix from test(messaging): bind Dockerfile plan fixture to agent #9517, and hardens runtime-identity qualification for cold 0.0.106 onboarding while recording the attached-provider post-state..github/workflows/e2e.yaml,.github/workflows/podman-cpu-proof.yaml,agents/hermes/Dockerfile,agents/hermes/mcp-config-transaction.py,agents/hermes/runtime-config-guard.py,agents/hermes/start.sh,docs/deployment/set-up-mcp-bridge.mdx,docs/manage-sandboxes/add-mcp-server.mdx,docs/manage-sandboxes/update-sandboxes.mdx,docs/reference/commands.mdx,docs/reference/configure-runtime-identity.mdx,docs/reference/troubleshooting.mdx,docs/security/best-practices.mdx,docs/security/gateway-authentication-controls.mdx,internal/security-reviews/openshell-0.0.72-compatibility-review.mdx,nemoclaw-blueprint/blueprint.yaml,nemoclaw/src/shared/openshell-policy-boundary.cts,scripts/brev-launchable-ci-cpu.sh,scripts/checks/dependency-pins.mts,scripts/checks/managed-image-protected-runtime-contract.ts,scripts/install-openshell.sh,scripts/install.sh,scripts/update-hermes-agent.sh,src/lib/actions/sandbox/mcp-bridge-input-validation.test.ts,src/lib/actions/sandbox/mcp-bridge-url-validation.ts,src/lib/actions/sandbox/mcp-bridge-validation.ts,src/lib/actions/sandbox/openshell-child-visible-credentials.v0.0.106.json,src/lib/onboard/docker-driver-gateway-config-toml.test.ts,src/lib/onboard/docker-driver-gateway-runtime.test.ts,src/lib/onboard/docker-driver-gateway-runtime.ts,src/lib/onboard/experimental/portable-demo-lifecycle.ts,src/lib/onboard/forward-start.ts,src/lib/onboard/managed-bootstrap/podman-held-workload.test.ts,src/lib/onboard/managed-bootstrap/podman-held-workload.ts,src/lib/onboard/openshell-feature-gate.test.ts,src/lib/onboard/openshell-feature-gate.ts,src/lib/onboard/openshell-install.test.ts,src/lib/onboard/openshell-install.ts,src/lib/onboard/openshell-version.ts,src/lib/onboard/runtime-provider/podman-lifecycle.ts,src/lib/policy/index.ts,test/brev-launchable-ci-cpu-checksum.test.ts,test/deepagents-mcp-legacy-lifecycle.test.ts,test/dependency-pins-check.test.ts,test/e2e/fixtures/openshell-v0106-qualification.ts,test/e2e/fixtures/security-posture.ts,test/e2e/live/mcp-bridge-sandbox.ts,test/e2e/live/network-policy.test.ts,test/e2e/live/openclaw-plugin-runtime-exdev.test.ts,test/e2e/live/openshell-gateway-auth-source-contract-helpers.ts,test/e2e/live/openshell-gateway-auth-source-contract.test.ts,test/e2e/live/openshell-gateway-upgrade.test.ts,test/e2e/live/openshell-v0106-tls-server-name-source.ts,test/e2e/live/podman-cpu-lifecycle-helpers.ts,test/e2e/live/podman-cpu-lifecycle.test.ts,test/e2e/support/mcp-bridge-runtime-compatibility.test.ts,test/e2e/support/mcp-bridge-sandbox.test.ts,test/e2e/support/mcp-workflow-boundary.test.ts,test/e2e/support/openshell-gateway-auth-contract-workflow-boundary.test.ts,test/e2e/support/openshell-v0106-tls-server-name-source.test.ts,test/e2e/support/workflow-plan.test.ts,test/exit-code-user-error-surfaces.test.ts,test/fixtures/openshell-v0.0.106,test/gateway-state-reconcile-2276.test.ts,test/hermes-doctor-config-hash.test.ts,test/hermes-mcp-config-transaction.test.ts,test/hermes-mcp-credential-boundary-manifest.test.ts,test/install-openshell-version-check.test.ts,test/install-openshell-version-pin.test.ts,test/installer-hash-check.test.ts,test/installer-sandbox-build-trust.test.ts,test/installer-supervisor-manifest-trust.test.ts,test/mcp-add-crash-consistency.test.ts,test/mcp-destroy-lifecycle.test.ts,test/mcp-policy-key-ownership.test.ts,test/mcp-restart-policy-order.test.ts,test/onboard-gateway-port-conflict-fast-fail.test.ts,test/openshell-0.0.85-migration-review.test.ts,test/openshell-channel-workflow.test.ts,test/pr-risk-plan.test.ts,test/rebuild-credential-preflight.test.ts,test/runner.test.ts,test/sandbox-provisioning.test.ts,test/sandbox-rlimit-hooks.test.ts,test/update-hermes-agent-script.test.ts,tools/e2e/mcp-workflow-boundary.mts,tools/e2e/openshell-gateway-auth-contract-workflow-boundary.mts,tools/e2e/workflow-boundary.mtsRelease ranges
8ddd98c3dff6→f48b05e31228f48b05e31228→c825b1f8efacc825b1f8efac→dd2b4e3bc068dd2b4e3bc068→0f8fad23c4710f8fad23c471→c4b500a7de64Concern dispositions
openshell-0.0.101..v0.0.102-network-1openshell-0.0.101..v0.0.102-runtime-topology-2openshell-0.0.101..v0.0.102-security-identity-3openshell-v0.0.102..v0.0.103-network-1openshell-v0.0.102..v0.0.103-runtime-topology-2openshell-v0.0.103..v0.0.104-runtime-topology-1openshell-v0.0.104..v0.0.105-compatibility-change-1openshell-v0.0.104..v0.0.105-network-2openshell-v0.0.104..v0.0.105-runtime-topology-3openshell-v0.0.105..v0.0.106-lifecycle-state-1openshell-v0.0.105..v0.0.106-code-impact-configuration-1openshell-v0.0.105..v0.0.106-code-impact-contract-or-schema-2openshell-v0.0.105..v0.0.106-code-impact-security-3openshell-v0.0.105..v0.0.106-code-impact-test-4Immutable artifacts
969493205e3d3462…ce981904ae8febd9…7421aaf9d5550dc1…de8f90db9dd0d3b4…22b7781249e34870…26e4345449e02475…b7760cb752a4363c…e6cde8a54568aa19…5e5d758d53c6abc6…0031c6b257a23ecc…88bc98ffdc915fb7…559b8aaad3a8eeab…019301ec8618abbe…d1a885a91b3e5aaa…98ecf95113fea999…f0f86519e227b3b3…2583a04a0557f069…7e8e05efcb725807…b122b4a5af5a5823…722f44669722961b…Validation receipt
cc9167892. After the final main reconciliation, 32/32 conflict-sensitive gateway/TLS assertions andnpm run validate:prpassed on latest PR commitd1990537d.cc9167892with trusted base/workflowa9fc8045dpassed 5/7 cases. TC-INF-12 and TC-INF-13 both completed cold onboarding, plan/apply, provider attachment, token refresh, and post-attach inference; OpenShell 0.0.106 then failed to projectE2E_ACCESS_TOKEN/ENTRA_ACCESS_TOKENinto 19 fresh sandbox execs over 35 seconds. Protected managed-image runtime was not launched because inference is its prerequisite. This is a repeated upstream runtime-credential projection blocker, not a waived gate.Type of Change
Quality Gates
Documentation Writer Review
docs-updateddocs/deployment/set-up-mcp-bridge.mdx,docs/manage-sandboxes/add-mcp-server.mdx,docs/manage-sandboxes/manage-mcp-servers.mdx,docs/reference/commands.mdx, anddocs/reference/troubleshoot-mcp-servers.mdxDGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run validate:prpassed after refreshingorigin/mainwhen hooks were skipped or unavailablecc9167892; 32/32 conflict-sensitive gateway/TLS assertions andnpm run validate:prthen passed after the final main reconciliation on latest PR commitd1990537d.npm run docsbuilds without warnings (doc changes only)Signed-off-by: Prekshi Vyas prekshiv@nvidia.com
NemoPatch current-head status
Status: blocked
Latest PR commit:
d1990537d9b9c8579c3197cba33faddaeb9aa101Checked: 2026-08-19T02:46:48Z
Reconciled with
mainat base commitee6762b99; 32/32 conflict-sensitive gateway/TLS assertions, local PR validation, and all 45 applicable current-commit GitHub checks pass. The two advisor services failed analysis without findings. Exact inference oncc9167892with trusted base/workflowa9fc8045dpassed 5/7 and repeatedly isolated an OpenShell 0.0.106 runtime-credential projection failure after successful provider attachment and refresh. Protected managed-image E2E remains gated; maintainer/upstream resolution is required.Summary by CodeRabbit
New Features
0.0.106, including updated CLI, gateway, sandbox, supervisor, and credential-boundary assets.Bug Fixes
Documentation
0.0.106.