## Release range
- Previous release: `v0.0.118` at `c3f309f2f344a4b25e58d204e0b423e54a4cb379`
- Candidate: `f427b07d0e01b309983239dd97c989234b18c3c1`
- Candidate selection: current-main
- Commits: 54
- Risky files detected: 343
## QA context
### Risky areas
- Workflow / enforcement
- Credentials / inference
- Onboarding / host glue
- Sandbox / policy / SSRF
- Installer / bootstrap
### Suggested test focus
- Fresh install and upgrade paths
- Onboarding wizard and sandbox creation
- Policy enforcement, network egress, and SSRF protections
- CI checks, pre-commit hooks, and DCO declarations
- Credential storage and inference provider routing
## Canonical release entry
- Path: `docs/changelog/2026-09-02.mdx`
- Entry:
## v0.0.119
NemoClaw v0.0.119 adds an explicitly selected native rootless Podman runtime path and an experimental managed llama.cpp path for qualifying Windows WSL N1x hosts.
It hardens custom network policy, WeChat redirect, Langfuse, MCP credential, and messaging-rebuild boundaries.
It also improves local inference selection, Hermes recovery, interrupted-install guidance, and sandbox command behavior, and updates reviewed production dependency graphs to remove four high-severity `fast-uri` advisories.
- Native rootless Podman can now run standard managed-image onboarding on qualified Linux hosts when you set `NEMOCLAW_GATEWAY_RUNTIME=podman`.
The provider verifies the current-user socket, rootless service, cgroups v2, bridge networking, DNS, platform, and exact managed-image receipt before admission.
Qualifying Windows WSL N1x hosts can use an explicit Experimental managed llama.cpp recipe for Qwen 3.6 35B-A3B after Docker Desktop, GPU passthrough, memory, driver, and product-identity checks pass.
Related changes: [PR #9923](https://github.com/NVIDIA/NemoClaw/pull/9923) and [PR #10742](https://github.com/NVIDIA/NemoClaw/pull/10742).
- Windows-host Ollama requests now stay inside Docker Desktop across inventory, pull, validation, health, recovery, and cleanup instead of switching to a WSL-inaccessible route.
Automatic Ollama selection chooses the largest fitting registered installed model before unregistered inventory entries, and managed vLLM preserves explicit GPU intent when an existing server occupies the selected port while reporting safe reuse or reconfiguration steps.
Failed Ollama proof processes are also cleaned up as a process tree.
Related changes: [PR #10741](https://github.com/NVIDIA/NemoClaw/pull/10741), [PR #10326](https://github.com/NVIDIA/NemoClaw/pull/10326), [PR #10308](https://github.com/NVIDIA/NemoClaw/pull/10308), and [PR #10767](https://github.com/NVIDIA/NemoClaw/pull/10767).
- Custom policy presets now reject untrusted private, local, metadata, and other special-use destinations before preview or mutation, while preserving exact explicit trust for supported private destinations.
Dry-run and apply share the same reserved-key ownership checks, and successful custom-preset lookup and removal no longer print a contradictory missing-preset warning.
Related changes: [PR #10659](https://github.com/NVIDIA/NemoClaw/pull/10659), [PR #10834](https://github.com/NVIDIA/NemoClaw/pull/10834), and [PR #10809](https://github.com/NVIDIA/NemoClaw/pull/10809).
- OpenShell policy reads and rebuild handoffs now use typed policy boundaries, separate provider-composed entries from the round-trippable base policy, and refuse to carry literal credentials into a replacement sandbox.
Credential commands route through the shared OpenShell provider adapter, including endpoint-bound non-secret provider configuration and managed MCP key ownership checks.
Related changes: [PR #10150](https://github.com/NVIDIA/NemoClaw/pull/10150) and [PR #10149](https://github.com/NVIDIA/NemoClaw/pull/10149).
- Experimental WeChat QR login now rejects untrusted redirect hosts before contact and authorizes only the exact validated Tencent iLink IDC origin captured for the account.
Rebuild preserves channels whose complete required credentials remain available through matching gateway providers; it disables a channel only after confirmed absence and stops without staging changes when inspection is uncertain or conflicting.
Related changes: [PR #10692](https://github.com/NVIDIA/NemoClaw/pull/10692) and [PR #10707](https://github.com/NVIDIA/NemoClaw/pull/10707).
- Managed MCP restart now verifies every selected server's stored credential before changing policy, providers, or agent adapters when no replacement host value is exported.
Hermes Langfuse Cloud credentials use an endpoint-bound OpenShell profile for the exact public and secret key names instead of relying on destination-independent placeholder rewriting.
Related changes: [PR #10759](https://github.com/NVIDIA/NemoClaw/pull/10759) and [PR #10844](https://github.com/NVIDIA/NemoClaw/pull/10844).
- An interrupted install or upgrade now reports that the compiled CLI is incomplete and directs you to rerun the installer, which attempts sandbox recovery.
Ordinary onboarding ignores an abandoned Portable configuration directory when no lifecycle authority exists, while protected Portable state remains fail-closed with corrective guidance.
Related changes: [PR #10444](https://github.com/NVIDIA/NemoClaw/pull/10444) and [PR #10743](https://github.com/NVIDIA/NemoClaw/pull/10743).
- A bare sandbox action now reports the required `nemoclaw <name> <action>` grammar without exposing arbitrary input.
`nemoclaw <sandbox> exec` runs without a pseudo-terminal by default so formatted output and stderr redirection behave predictably; pass `--tty` for an interactive terminal.
Uninstall previews now name the gateway and Docker volume selected by `NEMOCLAW_GATEWAY_PORT`.
Related changes: [PR #10335](https://github.com/NVIDIA/NemoClaw/pull/10335), [PR #10760](https://github.com/NVIDIA/NemoClaw/pull/10760), and [PR #10803](https://github.com/NVIDIA/NemoClaw/pull/10803).
- Hermes onboarding now requires its tracked base image, or a repository-built local base that passes the same controls, instead of falling through to an image that final provenance checks must reject.
Stopped-container recovery omits one known-futile prelaunch health request, keeps final authenticated health required, and reports credential-safe timing for its qualification, startup, polling, rollback, and total phases.
Related changes: [PR #10831](https://github.com/NVIDIA/NemoClaw/pull/10831), [PR #10805](https://github.com/NVIDIA/NemoClaw/pull/10805), and [PR #10811](https://github.com/NVIDIA/NemoClaw/pull/10811).
- NemoClaw now pins `fast-uri` 3.1.6 across its production dependency graphs and managed-image build inputs.
Reviewed locks, integrity metadata, runtime bundles, and image fixtures now exclude the four high-severity advisories that affect earlier 3.x releases while preserving the fail-closed audit threshold.
Related changes: [PR #10894](https://github.com/NVIDIA/NemoClaw/pull/10894) and [PR #10892](https://github.com/NVIDIA/NemoClaw/pull/10892).
## Documentation coverage
- Latest included cumulative docs PR: [#10832, `docs: prepare v0.0.119 documentation`](https://github.com/NVIDIA/NemoClaw/pull/10832).
- Final PR commit and merge commit: `16f5760bc5e0041faff710477c62018d3777d77e`; `e01658ed85745a46aa7892582cac307ad594ac01`.
- Final automated refresh coverage commit: `e76756027d7d561045cfbcf0c03d292ab05f6988`.
- Later commits and merged PRs, in first-parent order from the coverage point through the candidate:
- `fbf1ecfce663de167a01dfeb7f2f2622c5687914` — [#10692, `fix(messaging): authorize validated WeChat IDC origins`](https://github.com/NVIDIA/NemoClaw/pull/10692)
- `156bddd20e7e50ca129e1b86a7e218e8e3a762a2` — [#10834, `fix(policy): validate reserved keys during dry-run`](https://github.com/NVIDIA/NemoClaw/pull/10834)
- `63bc39d14c0889c6e77bc5fd8671ae284e2e7276` — [#10858, `test(review): align conflict fixer inference expectation`](https://github.com/NVIDIA/NemoClaw/pull/10858)
- `0e1b7d150b6079563256330baf1043dca998040f` — [#10859, `fix(ci): stabilize Docker boundary tests`](https://github.com/NVIDIA/NemoClaw/pull/10859)
- `16c21afdc858f5ca549b73d5e1fa6624bfc23c8b` — [#10844, `fix(hermes): bind Langfuse credentials to endpoint`](https://github.com/NVIDIA/NemoClaw/pull/10844)
- `5c8f991d2d7273ad512946dc701b230b3b338d5a` — [#9923, `feat(runtime): activate qualified native Podman`](https://github.com/NVIDIA/NemoClaw/pull/9923)
- `dcb7b7d2fe89da539df21977ad40d2aa8328e32b` — [#10150, `refactor(cli): add typed OpenShell policy boundaries`](https://github.com/NVIDIA/NemoClaw/pull/10150)
- `19bb9860a662e25418f1afbc7e0589d7f22f2497` — [#10707, `fix(messaging): stop rebuild from disabling gateway-backed channels`](https://github.com/NVIDIA/NemoClaw/pull/10707)
- `e01658ed85745a46aa7892582cac307ad594ac01` — [#10832, `docs: prepare v0.0.119 documentation`](https://github.com/NVIDIA/NemoClaw/pull/10832)
- `dfe7d3c70d8d72a749470185e7c0d45f05458fab` — [#10856, `refactor(automation): classify CI failures with a skill`](https://github.com/NVIDIA/NemoClaw/pull/10856)
- `2c9e2e9cb02313db0c8e1002e2df70d656b134c3` — [#10896, `docs(skills): remove volatile skill counts`](https://github.com/NVIDIA/NemoClaw/pull/10896)
- `80e15df42a712c656fa51df2815464db47fe0876` — [#10894, `ci(security): authorize fast-uri lock transition`](https://github.com/NVIDIA/NemoClaw/pull/10894)
- `8c974afaa6e92b6480a4bc8b11eb918616851b44` — [#10892, `fix(security): update vulnerable fast-uri graphs`](https://github.com/NVIDIA/NemoClaw/pull/10892)
- `4e581d8b42f56790b068cfbf5839d72a531c00de` — [#10901, `docs: finalize v0.0.119 release notes`](https://github.com/NVIDIA/NemoClaw/pull/10901)
- `788cfa1a4a888d1a33bfcdcf19360add9e9b328e` — [#10839, `perf(cli): detail Hermes currentness inspection timing`](https://github.com/NVIDIA/NemoClaw/pull/10839)
- `0673b122147433e8025222a135c7b8a3ebdbd27a` — [#10491, `fix(rebuild): recover from a void sandbox replacement journal`](https://github.com/NVIDIA/NemoClaw/pull/10491)
- `f427b07d0e01b309983239dd97c989234b18c3c1` — [#10902, `fix(ci): accept validated artifact data descriptors`](https://github.com/NVIDIA/NemoClaw/pull/10902)
- Changed paths: #10832 changed only allowed documentation paths: `docs/changelog/2026-09-02.mdx`, `docs/manage-sandboxes/set-up-wechat.mdx`, `docs/network-policy/create-custom-policy-presets.mdx`, and `docs/reference/troubleshooting.mdx`.
- Review and checks: #10832 was approved; all 63 checks completed (37 success, 26 skipped; no failed or pending checks). The later final release-docs PR #10901 was approved and merged; its rollup had 45 successes, 28 skips, one neutral result, and one failed self-hosted `test-e2e-sandbox` result.
- Open managed docs PRs: None at the final snapshot.
- Maintainer decision: Proceed with the candidate as shown.
## Base and managed image evidence
- Base-image candidate: `f427b07d0e01b309983239dd97c989234b18c3c1`
- Evidence: candidate E2E workflow [run 33690532582, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/33690532582); successful [`base-image-publication` job 100448017037](https://github.com/NVIDIA/NemoClaw/actions/runs/33690532582/job/100448017037), completed `2026-09-02T23:05:02Z`. The job successfully selected the applicable publication, downloaded and validated the immutable Deep Agents Code base contract, and downloaded and validated the immutable managed-image cohort contract.
## General E2E decision
- Displayed full run: no identifiable full manual `main` run was present among the newest 100 `workflow_dispatch` runs matching the `E2E full main` naming contract when inspected at `2026-09-02T23:06:54Z`. Candidate SHA: `f427b07d0e01b309983239dd97c989234b18c3c1`; full-run SHA, workflow attempt, created, started, last-updated, age, status, conclusion, workflow URL, and `Release qualification` job URL: not available.
- Non-successful or unresolved results: no identifiable full run was available to classify. No focused or full rerun was requested.
- Maintainer choice: Proceed with the status as shown.
Exceptions: No recent identifiable full manual-main run was found; proceeding because the exact candidate's required image-publication gate passed and the release-blocker regression has focused test coverage.