## Release range
- Previous release: `v0.0.116` at `b12bede8bfa5bc7a8c083f54fc79a4f5663b81df`
- Candidate: `95ff29e5df737aa02e25df7eddee79d5da61896a`
- Candidate selection: current-main
- Commits: 37
- Risky files detected: 365
## QA context
### Risky areas
- Workflow / enforcement
- Sandbox / policy / SSRF
- Installer / bootstrap
- Credentials / inference
- Onboarding / host glue
### Suggested test focus
- Fresh install and upgrade paths
- Onboarding wizard and sandbox creation
- Policy enforcement, network egress, and SSRF protections
- CI checks, pre-commit hooks, and DCO declarations
- Credential storage and inference provider routing
## Canonical release entry
- Path: `docs/changelog/2026-08-31.mdx`
- Entry:
## v0.0.117
NemoClaw v0.0.117 makes OpenShell the sole durable network-policy authority.
It improves fail-closed recovery for sandboxes, Shields, the installer, Portable runtimes, and messaging channels.
It also removes the deprecated Brev deploy wrapper and adds contributor and maintainer analysis tools.
- OpenShell is now the sole durable source of sandbox policy state.
NemoClaw policy commands and Shields operate on the live OpenShell policy without storing a second desired-policy copy, while rebuild carries the current policy through one private, temporary handoff.
Legacy policy fields are removed from NemoClaw state without changing the live policy.
Related change: [PR #10515](https://github.com/NVIDIA/NemoClaw/pull/10515).
- Failed onboarding cleanup now retains immutable sandbox, gateway, policy, and create-attempt evidence.
While OpenShell still reports the sandbox live, `destroy` preserves recovery instead of deleting by mutable name.
After OpenShell confirms absence, NemoClaw removes only containers that match the retained immutable identity and verifies their absence before clearing recovery state.
Related change: [PR #10571](https://github.com/NVIDIA/NemoClaw/pull/10571).
- The OpenClaw memory secret scanner now covers writes under absolute named-workspace paths such as `/sandbox/.openclaw/workspace-main/`.
Project directories whose names start with `workspace-` remain outside the memory-path classification unless they are under the OpenClaw state directory.
Related change: [PR #10527](https://github.com/NVIDIA/NemoClaw/pull/10527).
- Hermes activation and Shields recovery now bind release acknowledgement, writer rescans, root-broker cleanup, and completed auto-restore lock retirement to exact process and transaction identities.
Transient replaced writers are reconsidered under fresh identity, while live, foreign, durable, or ambiguous identity remains denied.
Related changes: [PR #10272](https://github.com/NVIDIA/NemoClaw/pull/10272), [PR #10597](https://github.com/NVIDIA/NemoClaw/pull/10597), and [PR #10603](https://github.com/NVIDIA/NemoClaw/pull/10603).
- macOS upgrades can retire an identity-verified legacy OpenShell gateway or Homebrew service before selecting the checksum-verified replacement binaries.
Managed startup also transfers protected receipts through read-only Docker volumes, so VM-backed Docker daemons such as Colima do not need access to a client-only temporary path.
Failed verification retains the recovery receipts, and successful finalization reports any exact volume that cleanup cannot remove.
Related changes: [PR #10484](https://github.com/NVIDIA/NemoClaw/pull/10484) and [PR #10534](https://github.com/NVIDIA/NemoClaw/pull/10534).
- Hermes Portable `connect --probe-only` now recovers published Ollama only for the `ollama-local` provider.
Descriptor-backed compatible endpoints keep verification-only routing without requiring an Ollama receipt.
Routine recovery reuses a healthy published runtime or performs one lifecycle recovery for a stopped runtime before it proves published Ollama readiness.
Onboarding and explicit deep validation retain generated completion, tool-call, and model-placement qualification.
OpenClaw Portable recovery uses one bounded in-sandbox gateway observer and a shorter OpenShell registration poll while preserving the existing readiness statuses and outer lifecycle deadline.
Related changes: [PR #10556](https://github.com/NVIDIA/NemoClaw/pull/10556), [PR #10612](https://github.com/NVIDIA/NemoClaw/pull/10612), and [PR #10614](https://github.com/NVIDIA/NemoClaw/pull/10614).
- Experimental OpenClaw WeChat setup now writes the exact revision-scoped OpenShell placeholder to the Tencent plugin account file and binds both authorized iLink endpoints to the channel provider.
Channel removal clears durable account state before provider, policy, or registry teardown, and raw bot tokens remain outside sandbox files, process arguments, and diagnostics.
Related change: [PR #10601](https://github.com/NVIDIA/NemoClaw/pull/10601).
- The deprecated `nemoclaw deploy` Brev compatibility command has been removed.
Remote hosts use their provisioning workflow, the hosted installer, and `nemoclaw onboard`; `deploy` is now available as a sandbox name.
Related change: [PR #10576](https://github.com/NVIDIA/NemoClaw/pull/10576).
- `nemoclaw <name> logs` now labels OpenClaw gateway lines with `[gateway]` and keeps existing OpenShell source tags unchanged.
Follow mode bounds incomplete-line memory, honors output backpressure, waits for accepted writes, and reports source failures.
Related change: [PR #10342](https://github.com/NVIDIA/NemoClaw/pull/10342).
- Contributors with a prepared checkout can run the checked-in PR Review Advisor specialists on committed and working-tree changes with `npm run review:local` before PR publication.
The [local-run prerequisites](https://github.com/NVIDIA/NemoClaw/blob/main/tools/pr-review-advisor/README.md#local-run) name the required host tools, the `origin/main` trust base, and the credential boundary.
Hosted specialist jobs publish completed analyses in their GitHub job summaries.
Maintainer analysis now emits bounded slow-test evidence and Perfetto-compatible PR lifetime traces with revision, readiness, review-request, workflow, job, and step timelines.
Related changes: [PR #10581](https://github.com/NVIDIA/NemoClaw/pull/10581), [PR #10604](https://github.com/NVIDIA/NemoClaw/pull/10604), [PR #10608](https://github.com/NVIDIA/NemoClaw/pull/10608), [PR #10611](https://github.com/NVIDIA/NemoClaw/pull/10611), [PR #10616](https://github.com/NVIDIA/NemoClaw/pull/10616), [PR #10617](https://github.com/NVIDIA/NemoClaw/pull/10617), and [PR #10623](https://github.com/NVIDIA/NemoClaw/pull/10623).
- Development qualification now contains a provider-owned record and dormant executor for the OpenShell v0.0.24 and MXC v0.7.0-rc1 checkpoint on physical Windows.
NemoClaw does not register or select MXC, expose Windows onboarding, activate this executor, or treat the checkpoint as an accepted stable distribution.
Related changes: [PR #10591](https://github.com/NVIDIA/NemoClaw/pull/10591) and [PR #10596](https://github.com/NVIDIA/NemoClaw/pull/10596).
## Documentation coverage
- Latest included cumulative docs PR: [#10642](https://github.com/NVIDIA/NemoClaw/pull/10642), `docs: prepare v0.0.117 documentation`.
- Final PR commit and merge commit: `054133e6140f9951b278b8d2aff97d431b30a697`; merge `7291b44e0887ece716a9e567503eb6f7e88e67d5`.
- Final automated refresh coverage commit: `b6b593e7e868cf213858d8c3afa5c400e010b368`.
- Later commits and merged PRs:
- `7291b44e0887ece716a9e567503eb6f7e88e67d5` — [#10642](https://github.com/NVIDIA/NemoClaw/pull/10642), cumulative v0.0.117 documentation.
- `521032482ae177f52ac62920ebb5ff23604aaaf6` — [#10662](https://github.com/NVIDIA/NemoClaw/pull/10662), monitoring recovery guidance.
- `2cf1ecd69e81ce12a44b8bd60dca8f4b7d76a7b9` — [#10666](https://github.com/NVIDIA/NemoClaw/pull/10666), auth-proxy recovery distinction.
- `ce4bb354905e611371da1615ccb9cf3878fa8ffa` — [#10230](https://github.com/NVIDIA/NemoClaw/pull/10230), narrow doctor diagnostic fix with its owning `docs/reference/commands.mdx` update.
- `95ff29e5df737aa02e25df7eddee79d5da61896a` — [#10673](https://github.com/NVIDIA/NemoClaw/pull/10673), final WSL/auth-proxy documentation qualification.
- Changed paths: #10642 changed only allowed documentation paths: `docs/changelog/2026-08-31.mdx` and `docs/monitoring/monitor-sandbox-activity.mdx`.
- Review and checks: #10642 was `APPROVED`; its recorded head matches the final PR commit. All 40 checks completed: 29 successful (`ShellCheck`; release-target labeling; all PR Review Advisor discovery, publication, and nine specialists; CI changes, checks, and docs-only checks; three CodeQL analyses; docs preview; growth guardrails; title lint; maintainer-edits; DCO; JavaScript/TypeScript and Python security scanning; ShellCheck SARIF; OpenShell SDK packaging; installer-hash verification), 10 skipped (`request`, `build-typecheck`, `cli-test-shards`, `cli-tests`, `installer-integration`, `openshell-sdk-package`, `plugin-tests`, `reviewed-npm-audit`, `static-checks`, `wechat-runtime-audit`), and one neutral (`CodeQL`). No check failed or remained pending.
- Open managed docs PRs: None.
- Maintainer decision: Proceed with the candidate as shown.
## Base and managed image evidence
- Base-image candidate: `95ff29e5df737aa02e25df7eddee79d5da61896a`
- Evidence: [E2E run 33391782401, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/33391782401), event `push`, branch `main`, workflow `.github/workflows/e2e.yaml`; successful [base-image-publication job 99489600246](https://github.com/NVIDIA/NemoClaw/actions/runs/33391782401/job/99489600246), completed `2026-08-31T12:37:44Z` and bound to the candidate SHA.
## General E2E decision
- Exact-candidate push run: [33391782401, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/33391782401), candidate `95ff29e5df737aa02e25df7eddee79d5da61896a`, created and started `2026-08-31T12:26:40Z`, last updated `2026-08-31T12:44:53Z`, completed successfully. The required [base-image-publication](https://github.com/NVIDIA/NemoClaw/actions/runs/33391782401/job/99489600246), selected [jetson-nvmap-gpu](https://github.com/NVIDIA/NemoClaw/actions/runs/33391782401/job/99490279296), and aggregate [Relevant E2E](https://github.com/NVIDIA/NemoClaw/actions/runs/33391782401/job/99491667584) jobs succeeded. No job failed, was cancelled, or remained unresolved; unselected matrix jobs were skipped.
- Newest identifiable full manual run: [33350578179, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179), tested `0ac27fc96694c4bf97b2fd51c3d29642855cecd4`, which does not match the candidate. It was created and started `2026-08-31T02:24:33Z`, last updated `2026-08-31T03:55:08Z`, and was 10 hours, 15 minutes, 58 seconds old at the `2026-08-31T12:40:31Z` inspection. The workflow completed with failure. Failed jobs were [messaging-providers](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363408336), [openclaw-plugin-runtime-exdev](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363408483), [Exact staging Brev Launchable](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363408536), [Pi AMD64](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363409714), [Pi ARM64](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363409768), [OpenClaw channel preservation](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363410557), [Hermes channel preservation](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363410850), and [Release qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99376267845). Selector or aggregate skips were [package-openshell-sdk](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363021634), [Launchable identity](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363408697), [retired selector compatibility](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363408754), [Jetson](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363408907), [native-runtime producer plan](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363409083), [external gateway](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363409195), [DGX Spark plan](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363409247), [Podman toolchain](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363409990), [protected llama.cpp](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363411918), [matrix job](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363413031), [native-runtime aggregate](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99363415608), and [Relevant E2E](https://github.com/NVIDIA/NemoClaw/actions/runs/33350578179/job/99376268344). No job was queued, running, or cancelled at inspection.
- Maintainer-cited run: [33385261471, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/33385261471), tested `b6b593e7e868cf213858d8c3afa5c400e010b368`, which does not match the candidate. It was created and started `2026-08-31T11:04:29Z`, last updated `2026-08-31T12:36:43Z`, had nine failed messaging, Pi, and installation jobs, and was force-cancelled at the maintainer's request while its final protected GPU/local-inference job was running.
- Maintainer choice: Proceed with the status as shown.
Exceptions: Exact-candidate base-image publication passed. Changes after the last tested product commit are documentation plus PR #10230's narrow doctor diagnostic fix, which passed focused tests and complete CI. We accept the older mismatched full-run failures for this release decision.