You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
On an accepted rootless Podman Linux host, fresh Portable OpenClaw onboarding must apply the accepted default policy set and reach authoritative finality.
When NEMOCLAW_POLICY_PRESETS is absent, empty, or whitespace-only, fresh onboarding must:
select exactly weather,public-reference,github;
preserve every mandatory baseline policy entry;
complete step 8/8;
confirm the applied policy through OpenShell readback; and
keep the sandbox and onboarding session resumable after a policy failure.
A nonblank NEMOCLAW_POLICY_PRESETS value remains authoritative. Resume must not inject the fresh default.
Scope authority
Epic #9200 records the accepted narrow-default decision and delivery order. Merged PR #9289 implements the fresh default. PR #9238 remains the separate status-preservation and temporary-cleanup slice.
This decision replaces the earlier requirement to compose personal-open-internet with the mandatory exact-host policies. The accepted default does not require an OpenShell host-exclusion capability.
Current gap
The previous personal-open-internet default overlapped mandatory exact-host policies with incompatible OpenShell metadata. Fresh onboarding then stopped before policy finality.
Merged PR #9289 excludes that broad preset from the implicit default. Explicit operator policy intent remains unchanged.
PR #9238 must still preserve an exact nonzero policy submission status through cleanup and resumable unwind.
Acceptance criteria
Default: Fresh absent, empty, or whitespace-only intent selects exactly weather,public-reference,github.
Stop before weakening a mandatory baseline policy, explicit operator authority, resume authority, or failure status.
Out of scope
Pairing settlement, host restart, general lifecycle recovery, uninstall preservation, Hermes, and production Podman-provider activation remain separate work.
Goal
On an accepted rootless Podman Linux host, fresh Portable OpenClaw onboarding must apply the accepted default policy set and reach authoritative finality.
When
NEMOCLAW_POLICY_PRESETSis absent, empty, or whitespace-only, fresh onboarding must:weather,public-reference,github;A nonblank
NEMOCLAW_POLICY_PRESETSvalue remains authoritative. Resume must not inject the fresh default.Scope authority
Epic #9200 records the accepted narrow-default decision and delivery order. Merged PR #9289 implements the fresh default. PR #9238 remains the separate status-preservation and temporary-cleanup slice.
This decision replaces the earlier requirement to compose
personal-open-internetwith the mandatory exact-host policies. The accepted default does not require an OpenShell host-exclusion capability.Current gap
The previous
personal-open-internetdefault overlapped mandatory exact-host policies with incompatible OpenShell metadata. Fresh onboarding then stopped before policy finality.Merged PR #9289 excludes that broad preset from the implicit default. Explicit operator policy intent remains unchanged.
PR #9238 must still preserve an exact nonzero policy submission status through cleanup and resumable unwind.
Acceptance criteria
weather,public-reference,github.Evidence
Exact PR #9289 commit
6df172770c11115b931f06390fdf417feedffa79completed these boundaries on a dedicated L40S Brev host:qwen3.6:35bmodel selection without fallback;Readyand direct CUDA proof;weather,public-reference,githubpolicy readback;example.comaccess;connect --probe-onlywith status 0;gateway connected | idle; andThe Epic keeps stop/start, product-installed host restart, uninstall, and the protected complete-journey lane open.
Blockers and stop conditions
Out of scope
Pairing settlement, host restart, general lifecycle recovery, uninstall preservation, Hermes, and production Podman-provider activation remain separate work.