fix(security): update OpenClaw to 2026.7.1 - #7280
Conversation
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughOpenClaw is upgraded from 2026.6.10 to 2026.7.1 across builds, manifests, integrity metadata, compatibility patches, and tests. Selected plugin archives receive deterministic Axios remediation, while shared-state permissions, legacy cache handling, Node.js, and Docker image pins are refreshed. ChangesOpenClaw 2026.7.1 migration
Estimated code review effort: 5 (Critical) | ~120 minutes Sequence Diagram(s)sequenceDiagram
participant Build
participant ArchiveRemediation
participant OpenClawPlugin
participant RuntimeValidation
Build->>ArchiveRemediation: materialize reviewed plugin archive
ArchiveRemediation->>OpenClawPlugin: patch and repack selected dependency graph
OpenClawPlugin-->>Build: verified archive and integrity
Build->>RuntimeValidation: install and validate pinned runtime
RuntimeValidation-->>Build: runtime and contract results
Possibly related issues
Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit b6bf757 in the TypeScript / code-coverage/cliThe overall coverage in commit b6bf757 in the Show a code coverage summary of the most impacted files.
Updated |
|
🌿 Preview your docs: https://nvidia-preview-pr-7280.docs.buildwithfern.com/nemoclaw |
PR Review Advisor — InformationalAdvisor assessment: Informational / medium confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 1 optional E2E recommendation
This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/messaging/applier/build/messaging-build-applier.mts`:
- Around line 1300-1307: Update the remediation call in the archive handling
flow to pass exactPackage.packageSpec unchanged as packageSpec. Remove the
appended `@exactPackage.version` suffix so remediateReviewedOpenClawPluginArchive
uses the normalized lookup key and matches REMEDIATIONS.
In `@test/openclaw-integrity-pin-suite.ts`:
- Around line 43-46: Complete the version-sensitive fixtures in
test/openclaw-integrity-pin-suite.ts: update the “newer unreviewed base” fixture
at lines 43-46 from 2026.6.11 to a version newer than 2026.7.1, such as
2026.7.2, and update its expected diagnostic; at lines 627-642, change both
optional-plugin archive-name regexes from 2026\.6\.10\.tgz to 2026\.7\.1\.tgz.
- Around line 497-502: Update the total dependency count assertion in the
reviewNote expectations to require the documented current value of 822 instead
of 818, while leaving the other dependency and severity assertions unchanged.
In `@test/openclaw-npm-remediation.test.ts`:
- Around line 77-93: Extend the remediation test around the existing shrinkwrap
assertions to also load and validate package.json, confirming axios is declared
and bundled as required. Assert the patched axios, https-proxy-agent, and
agent-base entries include the reviewed resolved URLs and SRI integrity values,
preserving the existing version and dependency checks so broken or unpinned
archives fail.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 5564a444-e868-40c2-b23a-5cb0ba739aaf
📒 Files selected for processing (58)
.github/actions/ci-reviewed-npm-audit/action.yaml.github/workflows/candidate-compatibility.yaml.github/workflows/e2e.yamlDockerfileDockerfile.baseagents/hermes/Dockerfileagents/langchain-deepagents-code/Dockerfile.baseagents/openclaw/manifest.yamlci/reviewed-npm-audit.jsonci/reviewed-npm-lifecycle-allowlist.jsondocs/security/openclaw-2026.7.1-dependency-review.mdnemoclaw-blueprint/policies/presets/weather.yamlnemoclaw/package.jsonscripts/audit-reviewed-npm-graph.mtsscripts/check-messaging-plan-image-boundary.mtsscripts/lib/openclaw-npm-remediation.mtsscripts/nemoclaw-start.shscripts/patch-openclaw-chat-send.mtsscripts/patch-openclaw-device-self-approval.mtsscripts/patch-openclaw-issue-4434-diagnostics.mtsscripts/validate-openclaw-tool-search.mtssrc/lib/messaging/applier/build/messaging-build-applier.mtssrc/lib/messaging/channels/discord/manifest.tssrc/lib/messaging/channels/metadata.test.tssrc/lib/messaging/channels/slack/manifest.tssrc/lib/messaging/channels/teams/manifest.tssrc/lib/messaging/channels/whatsapp/hooks/status-health.tssrc/lib/messaging/channels/whatsapp/manifest.tssrc/lib/messaging/channels/whatsapp/runtime/whatsapp-qr-compact.test.tssrc/lib/messaging/channels/whatsapp/runtime/whatsapp-qr-compact.tssrc/lib/sandbox/build-context.tstest/e2e/live/messaging-providers.test.tstest/e2e/live/openclaw-tui-chat-correlation.test.tstest/e2e/live/openshell-gateway-auth-source-contract-helpers.tstest/e2e/live/snapshot-credential-scanner.tstest/e2e/support/messaging-providers-runtime-proofs.test.tstest/e2e/support/openclaw-plugin-runtime-exdev-workflow-boundary.test.tstest/e2e/support/openshell-gateway-auth-contract-workflow-boundary.test.tstest/effective-policy-contracts.test.tstest/fetch-guard-patch-regression.test.tstest/helpers/fetch-guard-patch-harness.tstest/helpers/openclaw-device-self-approval-patch-harness.tstest/helpers/openclaw-real-device-self-approval-proof.tstest/issue-4434-error-fields.test.tstest/messaging-build-applier-integrity.test.tstest/messaging-build-applier.test.tstest/openclaw-dependency-review.test.tstest/openclaw-device-self-approval-patch.test.tstest/openclaw-integrity-pin-suite.tstest/openclaw-lifecycle-policy.test.tstest/openclaw-npm-remediation.test.tstest/openclaw-optional-plugin-build.test.tstest/openclaw-real-patched-dist-harness.test.tstest/openclaw-tool-search-runtime-validator.test.tstest/package-contract/msteams-message-hints-preload.test.tstest/sandbox-build-context.test.tstools/e2e/openclaw-plugin-runtime-exdev-workflow-boundary.mtstools/e2e/openshell-gateway-auth-contract-workflow-boundary.mts
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29797209133
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
There was a problem hiding this comment.
Actionable comments posted: 2
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
test/openclaw-integrity-pin-suite.ts (1)
461-483: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick winBind each package to its matching integrity and tarball.
These independent
toContain()checks can pass even when the dependency-review note associates one package with another package’s integrity or tarball. Parse the package records, or assert each package/version/integrity/tarball tuple together, so this contract test actually validates package identity and SRI alignment.As per path instructions, review tests for behavioral confidence rather than implementation lock-in.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/openclaw-integrity-pin-suite.ts` around lines 461 - 483, Update the dependency-review assertions in the integrity-pin test around reviewNote so each package’s version, integrity, and tarball are validated as one associated record rather than through independent toContain checks. Parse the package records or use tuple-level assertions, covering all listed OpenClaw, NemoClaw, and Codex packages while preserving the existing pinned constants and avoiding implementation-specific assertions.Source: Path instructions
🧹 Nitpick comments (1)
Dockerfile (1)
587-602: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winAdd runtime assertions for Patch 4’s dispatcher branches.
The build check verifies only textual replacement. Add real-dist coverage proving that OpenShell plus an omitted
dispatcherPolicyuses the proxy, explicit dispatcher policies retain their existing behavior, and non-OpenShell behavior is unchanged.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@Dockerfile` around lines 587 - 602, Add runtime assertions alongside the Patch 4 validation for the real dist: verify OPENSHELL_SANDBOX=1 with an omitted dispatcherPolicy routes through the proxy, while explicit dispatcherPolicy values preserve their existing behavior. Also assert that non-OpenShell execution remains unchanged, using the relevant dispatcher/fetch entry point and existing test harness utilities.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@Dockerfile`:
- Around line 1320-1330: Update the Dockerfile state-file initialization around
the exec-approvals and SQLite paths to validate every pre-existing target before
any touch, chown, or chmod operation. Reject symlinks and hard-linked files,
using no-follow or equivalent metadata checks, and exit with the existing
unsafe-state error before modifying anything; only create or modify validated
regular files inside the intended state directory.
In `@test/openclaw-shared-state-permissions-patch.test.ts`:
- Around line 461-482: The new test conditionals violate the codebase-growth
guardrails. In test/openclaw-shared-state-permissions-patch.test.ts:461-482,
replace all manual environment save/restore if/else blocks around the test suite
with vi.stubEnv and a shared afterEach(() => vi.unstubAllEnvs()) cleanup. In
test/openclaw-2026-7-startup-compat.test.ts:125-143, replace the it.each
kind-based if/else branching with a keyed setup map, and use a nullish guard
instead of the if (!match) check near line 33.
---
Outside diff comments:
In `@test/openclaw-integrity-pin-suite.ts`:
- Around line 461-483: Update the dependency-review assertions in the
integrity-pin test around reviewNote so each package’s version, integrity, and
tarball are validated as one associated record rather than through independent
toContain checks. Parse the package records or use tuple-level assertions,
covering all listed OpenClaw, NemoClaw, and Codex packages while preserving the
existing pinned constants and avoiding implementation-specific assertions.
---
Nitpick comments:
In `@Dockerfile`:
- Around line 587-602: Add runtime assertions alongside the Patch 4 validation
for the real dist: verify OPENSHELL_SANDBOX=1 with an omitted dispatcherPolicy
routes through the proxy, while explicit dispatcherPolicy values preserve their
existing behavior. Also assert that non-OpenShell execution remains unchanged,
using the relevant dispatcher/fetch entry point and existing test harness
utilities.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: bdbd4e8e-8ddc-416c-b325-9001cfdae773
⛔ Files ignored due to path filters (1)
nemoclaw/package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (17)
DockerfileDockerfile.basedocs/security/openclaw-2026.7.1-dependency-review.mdnemoclaw/package.jsonscripts/lib/normalize_mutable_config_perms.pyscripts/nemoclaw-start.shscripts/patch-openclaw-shared-state-permissions.mtssrc/lib/onboard/dockerfile-remote-dashboard-bind-contract.tssrc/lib/sandbox/build-context.tstest/helpers/openclaw-real-device-self-approval-proof.tstest/openclaw-2026-7-startup-compat.test.tstest/openclaw-dependency-review.test.tstest/openclaw-integrity-pin-suite.tstest/openclaw-real-patched-dist-harness.test.tstest/openclaw-shared-state-permissions-patch.test.tstest/sandbox-build-context.test.tstest/sandbox-provisioning.test.ts
🚧 Files skipped from review as they are similar to previous changes (6)
- nemoclaw/package.json
- test/sandbox-build-context.test.ts
- test/openclaw-dependency-review.test.ts
- src/lib/sandbox/build-context.ts
- Dockerfile.base
- test/helpers/openclaw-real-device-self-approval-proof.ts
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
test/openclaw-2026-7-startup-compat.test.ts (1)
122-147: 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick winVerify rejected filesystem entries remain unchanged.
These cases currently assert only exit status
1. Also snapshot the symlink target/hardlink target and directory state, then verify they were not modified after rejection; otherwise a partial-write regression could still pass the test.As per path instructions, test observable safety outcomes rather than only the rejection status.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/openclaw-2026-7-startup-compat.test.ts` around lines 122 - 147, Extend the parameterized repairUpdateCheck rejection test to capture each entry’s observable state before calling repairUpdateCheck: the symlink target’s contents, hardlink target’s contents, or directory state as applicable. After asserting status 1, verify the corresponding target or directory remains unchanged, ensuring rejected symlink, hardlink, and directory paths are not partially modified.Source: Path instructions
🧹 Nitpick comments (2)
test/openclaw-2026-7-startup-compat.test.ts (2)
44-47: 🎯 Functional Correctness | 🔵 Trivial | ⚡ Quick winValidate the active Dockerfile contract, not a raw substring.
A
.includes("ENV ...")assertion can pass on a comment or unrelated text and does not prove the built image receives the variable. Parse the active instruction or inspect image metadata at the runtime boundary.As per path instructions, tests should prefer observable outcomes over source-text assertions.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/openclaw-2026-7-startup-compat.test.ts` around lines 44 - 47, Update the test case “marks direct NemoClaw containers for split-user shared state” to validate the active Dockerfile instruction or built-image runtime metadata instead of using a raw substring search. Ensure the assertion proves NEMOCLAW_OPENCLAW_SHARED_STATE is actually configured in the resulting image, while preserving the existing compatibility expectation.Source: Path instructions
32-36: 🎯 Functional Correctness | 🔵 Trivial | 🏗️ Heavy liftExercise the real startup boundary instead of a regex-extracted copy.
The test extracts
launch_openclaw_gatewayfromscripts/nemoclaw-start.shand runs the copy, so it can pass while the script’s sourcing, environment setup, or dispatch path is broken. Prefer invoking the actual script with a fixture gateway; keep extraction only as supplemental coverage.As per path instructions, tests should prefer observable public-boundary behavior over source-shape testing.
Also applies to: 149-191
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/openclaw-2026-7-startup-compat.test.ts` around lines 32 - 36, Update the startup compatibility test to invoke scripts/nemoclaw-start.sh directly with a fixture gateway and assert its observable behavior, including sourcing, environment setup, and dispatch. Keep extractShellFunction and its isolated launch_openclaw_gateway coverage only as supplemental testing rather than the primary path, preserving the existing expectations where applicable.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In `@test/openclaw-2026-7-startup-compat.test.ts`:
- Around line 122-147: Extend the parameterized repairUpdateCheck rejection test
to capture each entry’s observable state before calling repairUpdateCheck: the
symlink target’s contents, hardlink target’s contents, or directory state as
applicable. After asserting status 1, verify the corresponding target or
directory remains unchanged, ensuring rejected symlink, hardlink, and directory
paths are not partially modified.
---
Nitpick comments:
In `@test/openclaw-2026-7-startup-compat.test.ts`:
- Around line 44-47: Update the test case “marks direct NemoClaw containers for
split-user shared state” to validate the active Dockerfile instruction or
built-image runtime metadata instead of using a raw substring search. Ensure the
assertion proves NEMOCLAW_OPENCLAW_SHARED_STATE is actually configured in the
resulting image, while preserving the existing compatibility expectation.
- Around line 32-36: Update the startup compatibility test to invoke
scripts/nemoclaw-start.sh directly with a fixture gateway and assert its
observable behavior, including sourcing, environment setup, and dispatch. Keep
extractShellFunction and its isolated launch_openclaw_gateway coverage only as
supplemental testing rather than the primary path, preserving the existing
expectations where applicable.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: bf259856-0243-4c67-b633-48b46cb1bfea
📒 Files selected for processing (4)
scripts/patch-openclaw-shared-state-permissions.mtstest/openclaw-2026-7-startup-compat.test.tstest/openclaw-real-patched-dist-harness.test.tstest/openclaw-shared-state-permissions-patch.test.ts
🚧 Files skipped from review as they are similar to previous changes (3)
- scripts/patch-openclaw-shared-state-permissions.mts
- test/openclaw-real-patched-dist-harness.test.ts
- test/openclaw-shared-state-permissions-patch.test.ts
E2E Target Results — ❌ Some tests failedRun: 29803628074
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29888849758
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29895770951
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29897565324
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29893928454
|
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29898253764
|
|
Maintainer acceptance for exact head
I accept these non-success checks as maintainer for this exact head/base pair. They do not provide regression evidence against the narrow OpenClaw credential-boundary or installed-base migration fix. Proceeding with an exact-head guarded admin squash merge. |
## Summary - Keep the installer production contract unchanged: relative OpenShell overrides are resolved to an absolute physical path with `pwd -P`. - Make the focused test assert the actual contract: the watcher receives an absolute path resolving to the same executable. - Accept the standard macOS `/var` to `/private/var` canonicalization. ## Why The post-merge main platform watch failed only because the test compared path spellings lexically. The identical assertion failed on the immediately previous completed main-watch run and on the first completed run after the test was introduced, so this was not introduced by #7280. Evidence: https://github.com/NVIDIA/NemoClaw/actions/runs/29910675239/job/88892568917 and https://github.com/NVIDIA/NemoClaw/actions/runs/29897085188/job/88849484779 ## Verification - `CI=1 npx vitest run --project cli src/lib/actions/uninstall/hermes-forward-watcher-installer.test.ts --reporter=verbose` - `npx @biomejs/biome check src/lib/actions/uninstall/hermes-forward-watcher-installer.test.ts` - `npm run build:cli && npm run typecheck` - `git diff --check` Signed-off-by: Aaron Erickson <aerickson@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Updated coverage to verify that the Hermes forward watcher logs an absolute OpenShell path. * Confirmed the logged path resolves to the same filesystem target as the generated executable. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Adds the canonical `## v0.0.92` release entry to `docs/changelog/2026-07-22.mdx` before the release plan is generated. The entry summarizes all ten pull requests merged after v0.0.91, including the OpenClaw security update and Jaeger runtime regression coverage. ## Changes - Added the canonical v0.0.92 changelog entry. - Recorded the user-visible, security, documentation, CI, and test changes in the release range. - #7280 -> `docs/changelog/2026-07-22.mdx`: OpenClaw 2026.7.1 and Node.js 22.23.1 security/runtime update. - #7378 -> `docs/changelog/2026-07-22.mdx`: canonical macOS watcher path validation. - #7379 -> `docs/changelog/2026-07-22.mdx`: stabilized full WSL platform validation. - #7380 -> `docs/changelog/2026-07-22.mdx`: bounded swap for hosted Hermes image exports. - #7100 -> `docs/changelog/2026-07-22.mdx`: semantic progress phases for live E2E tests. - #7376 -> `docs/changelog/2026-07-22.mdx`: restored v0.0.91 changelog history and corrected tagged guidance. - #7374 -> `docs/changelog/2026-07-22.mdx`: reviewed Homebrew formula transition for installer integrity checks. - #7346 -> `docs/changelog/2026-07-22.mdx`: provider-neutral headless server deployment guidance. - #7381 -> `docs/changelog/2026-07-22.mdx`: stabilized Hermes guard timing and WSL ownership fixtures. - #7339 -> `docs/changelog/2026-07-22.mdx`: real-artifact Jaeger header remediation regression coverage. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates the canonical dated changelog and release heading contract. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts` passed 6/6 tests. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not applicable to a changelog-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — passed with 0 errors and 2 pre-existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added `v0.0.92` release notes covering sandboxing updates (OpenClaw/Node.js bumps, integrity pinning remediation, mcporter handling, and upgrade validation). * Updated deployment guidance for provider-neutral headless installs, and improved live E2E test reporting plus phase-plan validation. * Tightened installer integrity-check messaging during an OpenShell Homebrew transition and expanded platform/image validation (including macOS/WSL timing) and hosted image export behavior. * Restored the previously missed `v0.0.91` changelog entry and release validation guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Carlos Villela <cvillela@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary #7100 established semantic phase coverage for all live E2E cases. This follow-up closes the remaining contract gaps without reapplying that implementation: it covers workflow-selected credential-free integration tests, requires E2E child-process boundaries to expose content-free liveness, and blocks OpenShell gateway-auth artifact uploads unless a fail-closed safety scan approves the current run attempt. Together with #7100, this completes #7101 while preserving current `main` behavior in the audited overlap areas. ## Related Issue Fixes #7101 ## Changes - Strengthen the shared progress contract with a frozen canonical capability, target/scenario identity, total and phase elapsed time, validated content-free events and activities, timestamp-only child-output observations, and final-phase enforcement. - Add `spawnObservedChild` as the audited direct asynchronous process boundary used by E2E helpers. The semantic checker rejects unaudited direct process APIs and requires synchronous calls to use a bounded timeout plus `SIGKILL`. - Add the lightweight `workflow-e2e-test` fixture for credential-free integration tests selected by the authoritative E2E planner, so they publish and validate the same semantic timeline and progress artifact contract without the stateful live fixture. - Convert the remaining agent-turn, Bedrock, Ollama, inference-routing, runtime-override, fake-server, Docker, and cleanup process paths to progress-aware boundaries without forwarding child stdout or stderr contents. - Scan final OpenShell gateway-auth artifacts before upload in both main and candidate workflows. Unsafe files are quarantined or deleted, and upload requires a run-ID/run-attempt-specific approval marker so a stale or failed scan cannot authorize publication. - Expand semantic coverage tests, workflow-boundary tests, pre-commit routing, and contributor/E2E documentation for these additional enforcement boundaries. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [x] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates <!-- Check one tests line and one docs line. Check other lines when applicable. Add every requested justification or approval reference. --> - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [x] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: An independent clean-delta and rollback audit confirmed that #7100 behavior remains intact, all 13 previously identified #7280-sensitive paths preserve current `main`, the Hermes shard implementations are unchanged, and the gateway-auth scanner/upload path fails closed. Focused scanner and workflow-boundary tests pass on the rebased commit. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence <!-- Required only when scripts/prepare-dgx-station-host.sh changes. Maintainers must review the linked evidence before approving or merging. This is human-reviewed evidence, not authenticated hardware provenance. Exceptional bypasses use existing repository governance and must be documented on the PR. --> - [ ] Tested on DGX Station - Tested commit: - Station profile/scenario: - Result: - Supporting evidence: ## Verification <!-- Check each applicable item only when supported by the requested evidence. Run targeted tests once per relevant change set and rerun after later edits or hook autofixes that can affect the tested behavior. Do not rerun hook-covered checks. --> - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — rebased final-head E2E-support suite: 17 files and 150/150 tests passed; `npm run test:e2e-phases:check`: 123 tests across 82 files passed; selected integration suite: 6 files passed and 1 skipped, with 37 tests passed and 3 skipped; CLI and plugin type-checks, CLI build, and diff checks passed - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — local `npm run check` completed the full pre-commit stage, but its intentionally serial CLI/integration coverage lane reached the four-hour execution ceiling before producing a final summary; required sharded CI is authoritative - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — passed with 0 errors and 2 existing Fern warnings - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- <!-- DCO sign-off is required in this PR description, and every commit must appear as Verified in GitHub. Run: git config user.name && git config user.email --> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added structured, redacted progress reporting across E2E phases and workflow-selected credential-free integration tests. * Introduced an OpenShell gateway auth artifact safety scan that produces an approved payload and gates evidence/artifact uploads. * **Bug Fixes** * Prevented sensitive values from appearing in progress output and persisted artifacts; uploads now proceed only after safety approval succeeds. * Hardened E2E subprocess lifecycle handling with forced termination, bounded output capture, and safer shutdown behavior. * **Documentation** * Updated E2E phase-plan/progress and artifact-safety guidance, including the `test:e2e-phases:check` contract. * **Tests** * Expanded coverage for progress reporting, observed subprocess lifecycle, and workflow/semantic-phase boundary rules. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: `CONTRIBUTING.md`, `test/e2e/README.md`, `test/e2e/docs/README.md` - Agent: Codex Desktop - PR: #7397 <!-- docs-review-head-sha: bd75ae8 --> <!-- docs-review-agents-blob-sha: 560ff38 --> --------- Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> Signed-off-by: Carlos Villela <cvillela@nvidia.com> Co-authored-by: Carlos Villela <cvillela@nvidia.com>
Summary
Updates the reviewed OpenClaw distribution from 2026.6.10 to 2026.7.1 and the sandbox Node image to 22.23.1. The image build fails closed while applying integrity-pinned remediations for vulnerable Axios copies in the Slack and Teams archives and the affected OpenTelemetry Jaeger pair in diagnostics. The separately locked
mcporter@0.7.3graph now resolves exact@hono/node-server@2.0.11andfast-uri@3.1.4releases and passes the reviewed audit, signature, install, and CLI checks.The sandbox credential contract remains unchanged: generated
openclaw.jsoncontains the non-secretapiKey: "unused"sentinel, whileCOMPATIBLE_API_KEYremains an OpenShell provider-environment placeholder whose real value is resolved at the OpenShell boundary. No literal provider credential is persisted in OpenClaw configuration or state.OpenClaw 2026.7.1 changed loopback shared-token CLI calls to omit the signed CLI device identity. That prevented the paired-device scope comparison from reaching the canonical
scope-upgradepairing gate. The compatibility patch now retains the signed CLI identity only after a stored operator device credential exists. The shared token still authenticates the loopback call; the paired-device record remains authoritative for scopes, and anoperator.adminrequest must still create and receive canonical pairing approval.The installed-base contract is covered explicitly. A pinned E2E row installs NemoClaw v0.0.89 with OpenClaw 2026.6.10 from a registry-SRI-bound frozen source archive, materializes the legacy per-agent SQLite, Memory Core, and update-check state, then upgrades in place to 2026.7.1. The current installer is deliberately not given the provider credential, so the post-upgrade turn proves reuse of the credential already held by OpenShell. The shared frozen-installer adapter also keeps the historical v0.0.36, v0.0.55, v0.0.74, and v0.0.89 matrix deterministic without weakening the current candidate.
The merge from current
mainpreserves its Nodetar@7.5.20package fix and bundled-npm tar remediation, rebinding the affected-base guard to the upgraded Node 22.23.1 image digest. For the E2E-only OpenClaw 2026.3.11 stale-upgrade fixture, the exact reviewed source shape is verified, the replacementtar@7.5.19archive is registry-SRI-bound, and that reviewed package is bundled into the remediated OpenClaw archive before installation. There is no completed-image scanner exception: any remaining affected copy fails the strict scan, and both stale-upgrade E2Es require the rebuilt current image inventory to be completely clean.Changes
@hono/node-server@2.0.11andfast-uri@3.1.4; verify the script-disabled production install, registry signatures, ESM transport construction/close path, and installed CLI version.tar@7.5.11to a registry-SRI-bound, bundledtar@7.5.19, with the completed-image scan remaining strict and exception-free.Type of Change
Quality Gates
DGX Station Hardware Evidence
Verification
Signed-off-by:lines and all new commits are SSH-signed and DCO-clean.npm run checks,npm run typecheck,npm run typecheck:cli,npm run source-shape:check, andnpm run test-size:checkpassed on the current-main reconciliation.mainthrough fix(e2e): bundle reviewed tar in legacy OpenClaw archive #7360, the focused remediation/integrity/scanner suites passed 34/34 and the installed-base migration/workflow suites passed 19/19.mainthrough fix(e2e): seed historical Hermes API key #7364, the exact affected Hermes historical fixture passed 9/9, the focused OpenClaw contract set passed 81 tests with one expected skip, and repository/source-shape checks passed.Evidence:
operator.admincron path.Signed-off-by: Julie Yaunches jyaunches@nvidia.com
Signed-off-by: Aaron Erickson aerickson@nvidia.com