Skip to content

v0.0.127

@cjagwani cjagwani tagged this 17 Sep 16:23
## Release range

- Previous release: `v0.0.126` at `ef7299010fa731d4075a29363aa60ee3c48f2eaf`
- Candidate: `37ca4cb4220265c2a12b9d9b8a120d0d23a338dd`
- Candidate selection: current-main
- Commits: 46
- Risky files detected: 145

## QA context

### Risky areas

- Workflow / enforcement
- Credentials / inference
- Installer / bootstrap
- Onboarding / host glue
- Sandbox / policy / SSRF

### Suggested test focus

- Fresh install and upgrade paths
- Onboarding wizard and sandbox creation
- Policy enforcement, network egress, and SSRF protections
- CI checks, pre-commit hooks, and DCO declarations
- Credential storage and inference provider routing

## Canonical release entry

- Path: `docs/changelog/2026-09-17.mdx`
- Entry:

## v0.0.127

NemoClaw v0.0.127 returns gateway, plugin, and package lifecycle ownership to OpenClaw and Hermes while preserving OpenShell sandbox controls.
It also improves sandbox startup and deletion convergence, configuration export, shared inference routing, installer readiness, MCP diagnostics, and messaging reuse.

- OpenClaw and Hermes now own their native gateway processes, plugins, packages, child processes, hooks, and background work after onboarding.
  NemoClaw continues to select the exact OpenShell sandbox, project credentials, observe health, repair host forwards, and preserve native agent state through rebuild and restore.
  Managed Docker bootstrap also retains recovery state until the replacement sandbox identity and reconnect path are verified.
  Related changes: [PR #11792](https://github.com/NVIDIA/NemoClaw/pull/11792), [PR #11906](https://github.com/NVIDIA/NemoClaw/pull/11906), and [PR #11698](https://github.com/NVIDIA/NemoClaw/pull/11698).
  For more information, refer to [Understand Gateway Lifecycle Control](/user-guide/openclaw/manage-sandboxes/configure-sandboxes/understand-gateway-lifecycle-control), [Install OpenClaw Plugins](/user-guide/openclaw/manage-sandboxes/install-openclaw-plugins), and [Install Hermes Plugins](/user-guide/hermes/manage-sandboxes/install-hermes-plugins).
- Starting a stopped OpenClaw or Hermes sandbox now waits for the native gateway to become observably ready before health checks and host-forward restoration.
  A failed OpenClaw startup retains its intentional-stop record so a retry repeats the bounded settlement path, while Hermes recovery rejects a persistently stopped gateway instead of reporting readiness early.
  Related changes: [PR #11914](https://github.com/NVIDIA/NemoClaw/pull/11914), [PR #11933](https://github.com/NVIDIA/NemoClaw/pull/11933), and [PR #11950](https://github.com/NVIDIA/NemoClaw/pull/11950).
  For more information, refer to [Recover and Rebuild Sandboxes](/user-guide/openclaw/manage-sandboxes/operate-sandboxes/recover-and-rebuild-sandboxes) and the [NemoClaw CLI Commands Reference](/user-guide/openclaw/reference/commands).
- Sandbox destroy, rebuild, forced snapshot restore, and final-gateway cleanup now wait for bounded OpenShell deletion convergence without retrying the delete mutation.
  Ambiguous or persistent state preserves local recovery ownership, and final-gateway cleanup explains why it kept the gateway when sandbox absence or the lack of other live sandboxes cannot be proved.
  Related changes: [PR #11838](https://github.com/NVIDIA/NemoClaw/pull/11838), [PR #11951](https://github.com/NVIDIA/NemoClaw/pull/11951), and [PR #11614](https://github.com/NVIDIA/NemoClaw/pull/11614).
  For more information, refer to the [NemoClaw CLI Commands Reference](/user-guide/openclaw/reference/commands), [Create and Restore Snapshots](/user-guide/openclaw/manage-sandboxes/state-and-backups/create-and-restore-snapshots), and [Troubleshooting](/user-guide/openclaw/reference/troubleshooting).
- Docker-backed rebuild now replays the exact provider-captured GPU selector and fails before deletion when the selected acceleration cannot be represented safely.
  Related change: [PR #11929](https://github.com/NVIDIA/NemoClaw/pull/11929).
  For more information, refer to the [NemoClaw CLI Commands Reference](/user-guide/openclaw/reference/commands).
- `nemoclaw config export` now accepts HTTP and HTTPS inference endpoints, retains supported managed vLLM execution and model settings, and exports the verified selected Ollama model with its SHA-256 digest.
  Hosted OpenClaw exports also preserve every supported read-only secondary agent in runtime order and reject the complete document when any roster member conflicts with the verified primary route.
  Related changes: [PR #11789](https://github.com/NVIDIA/NemoClaw/pull/11789), [PR #11889](https://github.com/NVIDIA/NemoClaw/pull/11889), [PR #11891](https://github.com/NVIDIA/NemoClaw/pull/11891), and [PR #11900](https://github.com/NVIDIA/NemoClaw/pull/11900).
  For more information, refer to the [NemoClaw CLI Commands Reference](/user-guide/openclaw/reference/commands) and [Set Up Ollama](/user-guide/openclaw/inference/local-inference/set-up-ollama).
- Pi rebuild now preserves recorded context-window, output-token, reasoning, and reasoning-effort settings, and its qualification path verifies context-free automation and interactive session persistence across onboarding, rebuild, and recovery.
  The Pi documentation now defines model limits, lifecycle commands, candidate-image authority, and the current support boundary.
  Related change: [PR #10355](https://github.com/NVIDIA/NemoClaw/pull/10355).
  For more information, refer to [Configure Pi Model Limits](/user-guide/pi/inference/configure-model-limits), [Run Pi](/user-guide/pi/manage-sandboxes/run-pi), and [Pi Support and Security](/user-guide/pi/reference/pi-support).
- `nemoclaw <sandbox> inference set` now permits provider-only or model-only changes on a shared OpenShell gateway and warns which registered sandboxes the route change affects.
  Endpoint, API-family, credential, incomplete-route, and invalid-gateway conflicts still stop before mutation.
  Related change: [PR #11947](https://github.com/NVIDIA/NemoClaw/pull/11947).
  For more information, refer to [Use Shared Gateway Routes](/user-guide/openclaw/inference/manage-inference/use-shared-gateway-routes) and the [NemoClaw CLI Commands Reference](/user-guide/openclaw/reference/commands).
- Docker readiness and onboarding now treat `DOCKER_CONTEXT` as the operator-selected authority instead of silently falling back to another local daemon.
  Installation now stages and verifies the required OpenShell SDK without GitHub credentials, and a trusted package upgrade writes the complete authenticated gateway environment before restarting the service.
  Related changes: [PR #11786](https://github.com/NVIDIA/NemoClaw/pull/11786), [PR #11921](https://github.com/NVIDIA/NemoClaw/pull/11921), and [PR #11843](https://github.com/NVIDIA/NemoClaw/pull/11843).
  For more information, refer to [System Readiness](/user-guide/openclaw/reference/system-readiness), [Troubleshooting](/user-guide/openclaw/reference/troubleshooting), and the [OpenClaw Quickstart](/user-guide/openclaw/get-started/quickstart).
- MCP status and credential probes now honor the recorded trusted private host when discovering tools, while entries without that recorded trust keep the strict public-address boundary.
  Managed MCP documentation now distinguishes adapter-scoped egress from interactive shell commands, and `nemoclaw credentials add` refuses an ambient untrusted gateway endpoint override before any host-side probe or provider mutation.
  Related changes: [PR #11405](https://github.com/NVIDIA/NemoClaw/pull/11405), [PR #11866](https://github.com/NVIDIA/NemoClaw/pull/11866), and [PR #11865](https://github.com/NVIDIA/NemoClaw/pull/11865).
  For more information, refer to [Add an MCP Server](/user-guide/openclaw/manage-sandboxes/mcp-servers/add-an-mcp-server), [Manage MCP Servers](/user-guide/openclaw/manage-sandboxes/mcp-servers/manage-mcp-servers), and [Troubleshoot MCP Servers](/user-guide/openclaw/reference/troubleshoot-mcp-servers).
- Reusing a sandbox through onboarding now preserves an active messaging channel and its matching network policy when durable gateway credential bindings still prove that configuration.
  Explicit channel removal or durable credential removal still disables the channel and removes its policy preset.
  Related change: [PR #10782](https://github.com/NVIDIA/NemoClaw/pull/10782).
  For more information, refer to [Enable Channels During Onboarding](/user-guide/openclaw/manage-sandboxes/messaging-channels/enable-channels-during-onboarding) and [Network Policies Reference](/user-guide/openclaw/reference/network-policies).
- Manual OpenClaw state transfer now includes every seeded workspace template, including `TOOLS.md` and `HEARTBEAT.md`, while keeping generated `POLICY.md` out of uploads.
  Related change: [PR #11524](https://github.com/NVIDIA/NemoClaw/pull/11524).
  For more information, refer to [Transfer State Manually](/user-guide/openclaw/manage-sandboxes/state-and-backups/transfer-state-manually).

## Documentation coverage

- Latest included cumulative docs PR: [#11788](https://github.com/NVIDIA/NemoClaw/pull/11788), `docs: prepare v0.0.126 documentation`.
- Final PR commit and merge commit: `46a4317c7cf00a406e475795a11910ce78b96b29`; `d3587e8495de6cfc1403aa66f20b3c4f06ce4286`.
- Final automated refresh coverage commit: `ff8ea373d7ffccdf7110f220871b1ec299518693`.
- Later commits and merged PRs: 85 first-parent commits follow that coverage point—39 through `v0.0.126`, then the 46-PR [`v0.0.126...v0.0.127` candidate range](https://github.com/NVIDIA/NemoClaw/compare/v0.0.126...37ca4cb4220265c2a12b9d9b8a120d0d23a338dd). Direct release-prep PR [#12003](https://github.com/NVIDIA/NemoClaw/pull/12003) was based on `58bc8b7f98be9955483eaddb508de16b04bfab1c`, has final PR commit `dcca2b58be765af515c2d98cd99ad0ea63422332`, and merged as the candidate.
- Changed paths: #11788 changed only `docs/changelog/2026-09-15.mdx` and `docs/reference/commands.mdx`; #12003 changed only `docs/changelog/2026-09-17.mdx`. All are allowed documentation paths.
- Review and checks: #11788 was approved with 51 terminal checks and no failures. #12003 was approved with all 57 checks terminal and no failures; neutral or intentionally skipped checks were non-blocking.
- Open managed docs PRs: draft [#11881](https://github.com/NVIDIA/NemoClaw/pull/11881), still titled for `v0.0.126`, review required, head `3cf73b4dd0dd518f7ef42a01db4e5d40d80f3e84`, with one added line in `docs/reference/commands.mdx`; its latest automated refresh parent is the previous release commit `ef7299010fa731d4075a29363aa60ee3c48f2eaf`.
- Maintainer decision: Proceed with the candidate as shown.

## Base and managed image evidence

- Base-image candidate: `37ca4cb4220265c2a12b9d9b8a120d0d23a338dd`
- Evidence: successful `base-image-publication` in [E2E run 35243233299, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/35243233299), [job 105276734407](https://github.com/NVIDIA/NemoClaw/actions/runs/35243233299/job/105276734407), completed at `2026-09-17T15:55:49Z`.

## General E2E decision

- Candidate push context: [run 35243233299, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/35243233299) tested `37ca4cb4220265c2a12b9d9b8a120d0d23a338dd` from `2026-09-17T15:54:14Z` through `2026-09-17T16:01:25Z`. The Jetson dispatch succeeded, but `jetson-nvmap-gpu` failed during OpenClaw onboarding because the created sandbox entered OpenShell phase `Error`; later GPU assertions were skipped and cleanup succeeded. The required `base-image-publication` job succeeded, while `Relevant E2E` reported failure from that selected Jetson result.
- Newest identifiable full manual main context: [run 35236217006, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/35236217006) tested `f3c50ad4c4c55507ed10c2ef8ad7a61d98ecf883`, not the candidate, from `2026-09-17T14:50:00Z` through last update `2026-09-17T15:41:09Z`. Its `base-image-publication` selection timed out after 50 minutes, and [Release qualification](https://github.com/NVIDIA/NemoClaw/actions/runs/35236217006/job/105271765540) failed after downstream jobs were skipped.
- Requested run: focused `jetson-nvmap-gpu` [run 35244589015, attempt 1](https://github.com/NVIDIA/NemoClaw/actions/runs/35244589015), [job 105282343716](https://github.com/NVIDIA/NemoClaw/actions/runs/35244589015/job/105282343716), tested the exact candidate `37ca4cb4220265c2a12b9d9b8a120d0d23a338dd` and completed successfully at `2026-09-17T16:13:27Z`.
- Maintainer choice: Proceed with the status as shown and waive a full candidate E2E rerun.

Exceptions: The full general E2E suite was not rerun on the candidate. The maintainer is proceeding because the mandatory candidate `base-image-publication` verifier and the requested exact-candidate `jetson-nvmap-gpu` scope both passed; the older full run tested a different commit and failed before its suite when image-publication selection timed out.
Assets 2
Loading