Skip to content

v0.0.125

@cjagwani cjagwani tagged this 15 Sep 08:32
## Release range

- Previous release: `v0.0.124` at `6f3cced4230ae9660c049cc11804daf37797c595`
- Candidate: `db2e3eefc2372cc1f4641eaee4621f4955f11004`
- Candidate selection: current-main
- Commits: 28
- Risky files detected: 71

## QA context

### Risky areas

- Workflow / enforcement
- Sandbox / policy / SSRF
- Installer / bootstrap
- Credentials / inference
- Onboarding / host glue

### Suggested test focus

- Fresh install and upgrade paths
- Onboarding wizard and sandbox creation
- Policy enforcement, network egress, and SSRF protections
- CI checks, pre-commit hooks, and DCO declarations
- Credential storage and inference provider routing

## Canonical release entry

- Path: `docs/changelog/2026-09-14.mdx`
- Entry:

## v0.0.125

NemoClaw v0.0.125 strengthens Hermes Portable recovery, OpenShell gateway authority, and onboarding finalization.
It also improves sandbox transfers, native Podman and OpenClaw networking, and the release validation pipeline.

- Hermes Portable interactive `connect` and `launch` can recover the exact stopped managed Ollama runtime after the recorded route becomes unavailable.
  Forward recovery now allows 30 seconds for verification and 60 seconds for the complete transaction, while retaining the original structured failure when cleanup cannot be proved.
  Related changes: [PR #11759](https://github.com/NVIDIA/NemoClaw/pull/11759) and [PR #11735](https://github.com/NVIDIA/NemoClaw/pull/11735).
  For more information, refer to [Recover and Rebuild Sandboxes](/user-guide/hermes/manage-sandboxes/operate-sandboxes/recover-and-rebuild-sandboxes), [Set Up Ollama](/user-guide/hermes/inference/local-inference/set-up-ollama), and the [Hermes CLI Commands Reference](/user-guide/hermes/reference/commands).
- The Hermes `nemoclaw-acp` adapter can select and, when required, start only its exact recorded OpenShell gateway when it is missing, unhealthy, or unreachable, or when a different gateway is connected.
  Conflicting or ambiguous gateway identities, authentication errors, schema failures, timeouts, and other observation failures stop recovery before gateway startup or ACP session creation.
  Related changes: [PR #11691](https://github.com/NVIDIA/NemoClaw/pull/11691) and [PR #11681](https://github.com/NVIDIA/NemoClaw/pull/11681).
  For more information, refer to the [Hermes CLI Commands Reference](/user-guide/hermes/reference/commands) and [Recover and Rebuild Sandboxes](/user-guide/hermes/manage-sandboxes/operate-sandboxes/recover-and-rebuild-sandboxes).
- Onboarding preserves process-inspection and secret-boundary refusals as incomplete, resumable state instead of reporting a ready sandbox.
  Experimental version 2 external-component activation evidence now accepts the same namespaced component IDs as registration while continuing to reject the reserved `openshell/` prefix and malformed evidence.
  Related changes: [PR #11760](https://github.com/NVIDIA/NemoClaw/pull/11760) and [PR #11745](https://github.com/NVIDIA/NemoClaw/pull/11745).
  For more information, refer to the [NemoClaw CLI Commands Reference](/user-guide/openclaw/reference/commands), [Troubleshooting](/user-guide/openclaw/reference/troubleshooting), and [Register an External Component During Onboarding](/user-guide/openclaw/deployment/register-external-component).
- Legacy OpenShell upgrade recovery preserves the recorded gateway, sandbox identity, workspace, and digest-verified pre-upgrade policy when live provider inspection is unavailable.
  Portable Hermes lifecycle and onboarding operations now await live policy reads and revalidate authority before startup, publication, restoration, or uninstall effects.
  Related changes: [PR #11612](https://github.com/NVIDIA/NemoClaw/pull/11612) and [PR #11585](https://github.com/NVIDIA/NemoClaw/pull/11585).
  For more information, refer to [Recover and Rebuild Sandboxes](/user-guide/openclaw/manage-sandboxes/operate-sandboxes/recover-and-rebuild-sandboxes) and [Recover and Rebuild Sandboxes for Hermes](/user-guide/hermes/manage-sandboxes/operate-sandboxes/recover-and-rebuild-sandboxes).
- Sandbox upload and download commands now await typed OpenShell transfers on the sandbox's recorded gateway.
  The lifecycle lock and owned staging remain active until transfer, verification, publication, and cleanup settle, while existing terminal output and exit behavior remain unchanged.
  Related change: [PR #11496](https://github.com/NVIDIA/NemoClaw/pull/11496).
  For more information, refer to the [NemoClaw CLI Commands Reference](/user-guide/openclaw/reference/commands).
- Managed OpenClaw now uses its native sandbox-local loopback endpoint by default and no longer depends on private-interface discovery, insecure private WebSockets, or a dedicated gateway dialback policy.
  Native Podman onboarding accepts the standard rootless socket layout when a private current-user directory prevents access by other users, while unsafe reachable sockets remain blocked.
  Related changes: [PR #11695](https://github.com/NVIDIA/NemoClaw/pull/11695) and [PR #11730](https://github.com/NVIDIA/NemoClaw/pull/11730).
  For more information, refer to [Network Policies](/user-guide/openclaw/reference/network-policies), [System Readiness](/user-guide/openclaw/reference/system-readiness), and [Troubleshooting](/user-guide/openclaw/reference/troubleshooting).
- Protected managed-image qualification now retains bounded, redacted failure evidence and completes rollback in OpenShell-before-Docker order.
  Lifecycle changes trigger the corresponding activation and publication gates, platform runs retain per-commit evidence, isolated jobs initialize their gateway before owned cleanup, transient tool downloads retry, and obsolete or overly broad E2E fixtures have been removed or narrowed.
  Agent-alias and onboarding probes also run independent cases concurrently without reducing assertions.
  Related changes: [PR #11713](https://github.com/NVIDIA/NemoClaw/pull/11713), [PR #11663](https://github.com/NVIDIA/NemoClaw/pull/11663), [PR #11607](https://github.com/NVIDIA/NemoClaw/pull/11607), [PR #11769](https://github.com/NVIDIA/NemoClaw/pull/11769), [PR #11742](https://github.com/NVIDIA/NemoClaw/pull/11742), [PR #11743](https://github.com/NVIDIA/NemoClaw/pull/11743), [PR #11588](https://github.com/NVIDIA/NemoClaw/pull/11588), [PR #11708](https://github.com/NVIDIA/NemoClaw/pull/11708), and [PR #11704](https://github.com/NVIDIA/NemoClaw/pull/11704).
- PR Review Advisor accepts unresolved required E2E coverage when no runnable selector exists, requires a nonempty read of each declared evidence file, and records bounded tool-flow metadata for failed turns without exposing arguments, paths, or untrusted names.
  Related changes: [PR #11773](https://github.com/NVIDIA/NemoClaw/pull/11773), [PR #11762](https://github.com/NVIDIA/NemoClaw/pull/11762), and [PR #11728](https://github.com/NVIDIA/NemoClaw/pull/11728).
- Internal messaging declarations with no active consumer have been removed without changing channel manifests or runtime behavior.
  The source scan configuration also recognizes the checksum-pinned Hermes documentation search key through one exact, read-only allowlist entry.
  Related changes: [PR #11705](https://github.com/NVIDIA/NemoClaw/pull/11705) and [PR #11740](https://github.com/NVIDIA/NemoClaw/pull/11740).

## Documentation coverage

- Latest included cumulative docs PR: [#11734](https://github.com/NVIDIA/NemoClaw/pull/11734), `docs: prepare v0.0.125 documentation`.
- Final PR commit and merge commit: `2851ee22b8a15103f10afce3812e505137a2cd29`; `db2e3eefc2372cc1f4641eaee4621f4955f11004`.
- Final automated refresh coverage commit: `a05d1f238f84e59e6d4fbdc30e547ec7281772c4`, derived from the last verified `docs: catch up after main` automation commit `d2fc945ba4dbfef7cdfe28eab45c4e435eb2e9dd`.
- Later commits and merged PRs: `e42eb870f5439714df4a2c583f311a5030c323e0` ([#11775](https://github.com/NVIDIA/NemoClaw/pull/11775), capability enforcement ownership), `a43a27af07da0ee92fb81fffbc851e6001abeebd` ([#11739](https://github.com/NVIDIA/NemoClaw/pull/11739), session exports through the transfer adapter), and candidate `db2e3eefc2372cc1f4641eaee4621f4955f11004` ([#11734](https://github.com/NVIDIA/NemoClaw/pull/11734)). The canonical entry does not name #11775 or #11739.
- Changed paths: #11734 changed only allowed `docs/**` paths. #11775 later changed runtime, tests, and security/platform documentation; #11739 later changed session-export runtime and tests without documentation.
- Review and checks: `APPROVED`; all 32 checks completed, with 21 successes and 11 intentional skips, and no failed, cancelled, or pending checks.
- Open managed docs PRs: None.
- Maintainer decision: Proceed with the candidate as shown.

## Base and managed image evidence

- Base-image candidate: `db2e3eefc2372cc1f4641eaee4621f4955f11004`
- Evidence: [E2E / Main and Manual Suite run 34932272712, attempt 2](https://github.com/NVIDIA/NemoClaw/actions/runs/34932272712), `main` push using `.github/workflows/e2e.yaml`; [`base-image-publication` job 104272726200](https://github.com/NVIDIA/NemoClaw/actions/runs/34932272712/job/104272726200) completed successfully at `2026-09-15T06:09:29Z` for the exact candidate SHA.

## General E2E decision

- Newest identifiable full manual `main` run: [run 34842707308, attempt 2](https://github.com/NVIDIA/NemoClaw/actions/runs/34842707308), created `2026-09-14T12:18:27Z`, started `2026-09-14T13:11:01Z`, last updated `2026-09-14T14:22:49Z`; inspected at `2026-09-15T06:12:04Z`, age 17h 53m. It tested `49765a4305ef1f61575f73cf7cb504dbc48d45db`, which does not match the candidate, and completed with `failure`. [Release qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/34842707308/job/104012671601) failed; [Exact staging Brev Launchable](https://github.com/NVIDIA/NemoClaw/actions/runs/34842707308/job/103988233163) succeeded. Fifteen test jobs plus release qualification failed, and ten non-selected jobs were skipped.
- Candidate-bound recovery run: [run 34932272712, attempt 2](https://github.com/NVIDIA/NemoClaw/actions/runs/34932272712), created `2026-09-15T05:30:33Z`, started `2026-09-15T05:30:31Z`, last updated `2026-09-15T06:14:43Z`; exact candidate `db2e3eefc2372cc1f4641eaee4621f4955f11004`, completed with `success` and no failed jobs. [`base-image-publication`](https://github.com/NVIDIA/NemoClaw/actions/runs/34932272712/job/104272726200), [`jetson-nvmap-gpu`](https://github.com/NVIDIA/NemoClaw/actions/runs/34932272712/job/104273351982), and [`Relevant E2E`](https://github.com/NVIDIA/NemoClaw/actions/runs/34932272712/job/104274032543) succeeded. This main-push run was not the full manual suite.
- Maintainer choice: Proceed with the status as shown.

Exceptions: Proceed because the exact candidate push rerun succeeded with no failed jobs—including required base-image publication, Jetson, and Relevant E2E—and the failed full run tested an older noncandidate SHA while its Launchable job succeeded.
Assets 2
Loading