Skip to content
Merged
Show file tree
Hide file tree
Changes from 250 commits
Commits
Show all changes
428 commits
Select commit Hold shift + click to select a range
cd65972
merge(stack): refresh managed bootstrap provider create
ericksoa Aug 1, 2026
f72b165
merge(stack): refresh durable bootstrap transactions
ericksoa Aug 1, 2026
84c849b
test(mcp): bound subprocess status checks
ericksoa Aug 1, 2026
0be111d
merge(stack): refresh managed bootstrap recovery
ericksoa Aug 1, 2026
d892b4c
test(runtime): keep watcher lease fixture linear
ericksoa Aug 1, 2026
16ba43b
merge(stack): refresh managed bootstrap image runtime
ericksoa Aug 1, 2026
32e0259
chore(stack): refresh managed image publication parent
ericksoa Aug 1, 2026
26683aa
feat(runtime): add durable Podman bootstrap journal
ericksoa Aug 1, 2026
9ec4f8d
merge(stack): refresh Podman bootstrap authority
ericksoa Aug 1, 2026
26eeb21
merge(stack): refresh Podman command adapter
ericksoa Aug 1, 2026
ffab808
merge(stack): refresh Podman bootstrap authority
ericksoa Aug 1, 2026
77166bc
test(runtime): bind held workload engine authority
ericksoa Aug 1, 2026
f33a363
feat(runtime): persist container engine authority
ericksoa Aug 1, 2026
907b42b
merge(stack): refresh persisted engine authority
ericksoa Aug 1, 2026
86e5e99
merge(stack): retain Podman bootstrap authority
ericksoa Aug 1, 2026
a602f82
merge(stack): refresh persisted engine authority on journal
ericksoa Aug 1, 2026
90ac8f1
feat(runtime): prepare exact Podman bootstrap replacement
ericksoa Aug 1, 2026
39c89b5
feat(runtime): stage Podman image bootstrap
ericksoa Aug 1, 2026
1c1cd2a
test(runtime): inventory Podman bootstrap sources
ericksoa Aug 1, 2026
2a0ff40
test(runtime): include Podman providers in source guard
ericksoa Aug 1, 2026
f89f61b
merge(stack): refresh Podman command adapter
ericksoa Aug 1, 2026
54dad99
test(runtime): verify exact Podman bootstrap rollback
ericksoa Aug 1, 2026
0ca37a2
merge(stack): refresh Podman bootstrap authority
ericksoa Aug 1, 2026
ea52d25
style(runtime): format Podman bootstrap rollback tests
ericksoa Aug 1, 2026
99c4ef2
test(runtime): normalize copied receipt modes
ericksoa Aug 1, 2026
55eb8bb
docs(runtime): record Podman bootstrap rollback contract
ericksoa Aug 1, 2026
3231d9f
merge(stack): refresh managed image publication
ericksoa Aug 1, 2026
d7eb1f5
merge(stack): refresh Podman command adapter
ericksoa Aug 1, 2026
2250c7f
feat(runtime): own Podman bootstrap state volume
ericksoa Aug 1, 2026
b600cb8
merge(stack): refresh repaired Podman bootstrap authority
ericksoa Aug 1, 2026
ca6bd6f
docs(runtime): record Podman bootstrap state ownership
ericksoa Aug 1, 2026
3d2efa1
fix(runtime): retain exact state-volume expectation
ericksoa Aug 1, 2026
9231122
feat(runtime): persist lifecycle engine recovery
ericksoa Aug 1, 2026
4e56aa3
merge(stack): refresh Podman bootstrap journal
ericksoa Aug 1, 2026
e7558bc
fix(runtime): harden lifecycle ledger recovery
ericksoa Aug 1, 2026
c004920
test(runtime): keep Podman harness branches explicit
ericksoa Aug 1, 2026
289287c
test(runtime): keep Podman image transaction fixture linear
ericksoa Aug 1, 2026
a46396a
test(runtime): inventory Podman bootstrap transactions
ericksoa Aug 1, 2026
2550531
fix(runtime): revalidate lifecycle completion
ericksoa Aug 1, 2026
ab65196
merge(stack): refresh Podman bootstrap journal checks
ericksoa Aug 1, 2026
4e18b65
test(runtime): inventory Podman image transaction
ericksoa Aug 1, 2026
c992dd3
fix(runtime): harden Podman bootstrap reconciliation
ericksoa Aug 1, 2026
fd82f60
fix(runtime): bind Podman image bootstrap authority
ericksoa Aug 1, 2026
256e687
fix(runtime): type persisted lifecycle callbacks
ericksoa Aug 1, 2026
377a9ea
test(runtime): discriminate Podman mount parsing
ericksoa Aug 1, 2026
094cea4
fix(runtime): accept omitted Podman shared mount mode
ericksoa Aug 1, 2026
8b5299d
fix(runtime): type lifecycle test capture
ericksoa Aug 1, 2026
dc3a484
docs(runtime): align Podman mount evidence
ericksoa Aug 1, 2026
6ae135a
merge(stack): refresh Podman bootstrap review fixes
ericksoa Aug 1, 2026
005ce53
fix(images): set root before DCode handoff
ericksoa Aug 1, 2026
9283304
merge(stack): append Podman image bootstrap transaction
ericksoa Aug 1, 2026
913c724
docs(runtime): record Podman image transaction boundary
ericksoa Aug 1, 2026
b403f7a
merge(stack): refresh Podman image bootstrap docs
ericksoa Aug 1, 2026
362a70c
chore(stack): refresh managed workload rebuild parity on current main
ericksoa Aug 1, 2026
b2374ee
chore(stack): refresh managed snapshot parity parent
ericksoa Aug 1, 2026
e09ce8a
chore(stack): refresh managed clone handoff parent
ericksoa Aug 1, 2026
aeeb6dd
chore(stack): refresh managed clone provider parent
ericksoa Aug 1, 2026
968c795
chore(stack): refresh Hermes clone broker parent
ericksoa Aug 1, 2026
fb0d7aa
chore(stack): refresh managed bootstrap protocol parent
ericksoa Aug 1, 2026
976771e
chore(stack): refresh Docker bootstrap adapter parent
ericksoa Aug 1, 2026
1978cfa
docs(runtime): clarify persisted engine authority
ericksoa Aug 1, 2026
ff5b16b
chore(stack): refresh managed bootstrap create parent
ericksoa Aug 1, 2026
300338c
merge(stack): restack persisted engine lifecycle
ericksoa Aug 1, 2026
998296e
chore(stack): refresh durable bootstrap transaction parent
ericksoa Aug 1, 2026
3be9d84
chore(stack): refresh managed bootstrap recovery parent
ericksoa Aug 1, 2026
ff7a040
chore(stack): refresh managed bootstrap image runtime parent
ericksoa Aug 1, 2026
e1d380e
chore(stack): refresh managed image publication parent
ericksoa Aug 1, 2026
269de66
test(runtime): avoid persisted authority check-use race
ericksoa Aug 1, 2026
606a482
merge(stack): refresh persisted engine lifecycle base
ericksoa Aug 1, 2026
cfa7cbb
feat(runtime): qualify Podman inference GPUs
ericksoa Aug 1, 2026
8bfea3a
chore(stack): refresh Podman command adapter parent
ericksoa Aug 1, 2026
d6f1cd6
chore(stack): refresh Podman bootstrap authority parent
ericksoa Aug 1, 2026
4b4fcef
chore(stack): refresh Podman bootstrap journal parent
ericksoa Aug 1, 2026
5250328
chore(stack): refresh Podman image transaction parent
ericksoa Aug 1, 2026
ae30b06
chore(stack): refresh persisted engine authority parent
ericksoa Aug 1, 2026
02b7389
merge(stack): refresh persisted engine lifecycle
ericksoa Aug 1, 2026
db3637a
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
d11f708
feat(runtime): translate Podman inference commands
ericksoa Aug 1, 2026
1d2a111
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
b12db1c
test(runtime): linearize lifecycle harness setup
ericksoa Aug 1, 2026
9d8fee1
feat(runtime): define host-local inference receipts
ericksoa Aug 1, 2026
bff34f9
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
ca85ca7
fix(hermes): preserve broker write ownership
ericksoa Aug 1, 2026
8db756d
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
3e25313
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
08060dd
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
eb88cce
merge(stack): refresh Podman inference parent
ericksoa Aug 1, 2026
bcf2ae9
chore(stack): incorporate Hermes broker review repairs
ericksoa Aug 1, 2026
642ff9d
fix(runtime): serialize persisted lifecycle execution
ericksoa Aug 1, 2026
f2a5806
test(onboard): linearize transaction recovery cases
ericksoa Aug 1, 2026
743a2f3
chore(stack): incorporate transaction test repairs
ericksoa Aug 1, 2026
6c23ebd
feat(runtime): bind host-local inference specifications
ericksoa Aug 1, 2026
2c11802
chore(stack): incorporate transaction test repairs
ericksoa Aug 1, 2026
2d55f98
chore(stack): incorporate transaction test repairs
ericksoa Aug 1, 2026
beb5731
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
de70077
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
9cb9e34
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
0f125e0
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
0fde3f9
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
52ecd0b
chore(stack): incorporate prior-slice repairs
ericksoa Aug 1, 2026
54cc06f
feat(runtime): manage Podman host-local inference
ericksoa Aug 1, 2026
32751f3
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
ee6ad30
merge(stack): refresh Podman inference parent
ericksoa Aug 1, 2026
333aab6
merge(stack): refresh host-local inference receipt parent
ericksoa Aug 1, 2026
4c66a17
feat(runtime): expose host-local inference providers
ericksoa Aug 1, 2026
ec453b7
test(runtime): complete provider surface fixture
ericksoa Aug 1, 2026
1add3cc
chore(runtime): format host-local inference slice
ericksoa Aug 1, 2026
d4622df
fix(runtime): reject duplicate Podman CDI inventory
ericksoa Aug 1, 2026
5aaf988
chore(stack): refresh E2E qualification
ericksoa Aug 1, 2026
5472c30
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
faa8610
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
1f4683f
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
fda94da
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
fb1e210
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
e724196
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
03f5a3d
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
a2ae17e
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
baa495a
chore(stack): incorporate prior-slice qualification refresh
ericksoa Aug 1, 2026
e74e262
merge(stack): refresh persisted engine lifecycle parent
ericksoa Aug 1, 2026
3ef4794
test(runtime): linearize Podman inference harness
ericksoa Aug 1, 2026
f4628d3
merge(stack): refresh Podman GPU translation parent
ericksoa Aug 1, 2026
3485901
merge(stack): refresh host-local inference receipt parent
ericksoa Aug 1, 2026
4b75eb4
refactor(runtime): keep receipt slice domain-only
ericksoa Aug 1, 2026
e2c5a19
merge(stack): narrow host-local inference receipt parent
ericksoa Aug 1, 2026
4b73583
fix(runtime): bind host inference authority exactly
ericksoa Aug 1, 2026
91eec72
feat(runtime): route host-local inference
ericksoa Aug 1, 2026
2f38f47
fix(runtime): bind inference receipt authority
ericksoa Aug 1, 2026
0410dbe
merge(stack): bind host inference parent
ericksoa Aug 1, 2026
3961da6
test(runtime): inventory host-local routing boundary
ericksoa Aug 1, 2026
c2cc2ce
fix(runtime): probe managed inference readiness
ericksoa Aug 2, 2026
c176e0d
merge(stack): restack routing on inference readiness
ericksoa Aug 2, 2026
81672c7
test(runtime): isolate Podman inference harness
ericksoa Aug 2, 2026
895d0e5
docs(runtime): align inference route terminology
ericksoa Aug 2, 2026
d62c13b
merge(stack): restack routing on test-only harness
ericksoa Aug 2, 2026
303387b
fix(runtime): reprove managed inference readiness
ericksoa Aug 2, 2026
38f670e
merge(stack): restack routing on managed readiness
ericksoa Aug 2, 2026
68991cc
test(runtime): carry managed readiness authority
ericksoa Aug 2, 2026
b588f8b
test(runtime): cover managed route retry
ericksoa Aug 2, 2026
14d8f52
fix(runtime): bind held workload namespace
apurvvkumaria Aug 3, 2026
a672a3f
feat(runtime): qualify Podman inference commands (#8059)
ericksoa Aug 3, 2026
9209d31
feat(runtime): define host-local inference receipts (#8060)
ericksoa Aug 3, 2026
8672699
feat(onboard): activate buildless managed workloads
ericksoa Aug 4, 2026
f83d8db
test(onboard): cover managed activation regressions
ericksoa Aug 4, 2026
18de09f
fix(onboard): harden managed activation qualification
ericksoa Aug 4, 2026
b433fc6
fix(ci): refresh live E2E parity mapping
ericksoa Aug 4, 2026
08ab3ff
fix(e2e): isolate legacy lanes from managed activation
ericksoa Aug 4, 2026
0040c91
merge: resolve conflicts with main
github-actions[bot] Aug 5, 2026
01c4a0a
fix(e2e): preserve legacy Dockerfile lanes
ericksoa Aug 5, 2026
3971674
test(e2e): refresh workflow compatibility digest
ericksoa Aug 5, 2026
07bd38c
test(e2e): activate protected managed runtime qualification
ericksoa Aug 5, 2026
15771f8
feat(runtime): add dormant Podman CPU lifecycle
ericksoa Aug 1, 2026
c791fdf
test(runtime): keep Podman fixtures branch-free
ericksoa Aug 1, 2026
6a28014
fix(runtime): harden Podman endpoint authority
ericksoa Aug 1, 2026
ca24013
test(runtime): cover Podman lifecycle retries
ericksoa Aug 1, 2026
aa2909c
test(runtime): include Podman providers in source guard
ericksoa Aug 1, 2026
c3beceb
fix(runtime): adapt Podman boundary to current architecture
ericksoa Aug 5, 2026
b269b4f
test(e2e): prove rootless Podman CPU lifecycle
ericksoa Aug 5, 2026
3d5f58e
fix(e2e): harden Docker shutdown for Podman proof
ericksoa Aug 5, 2026
9d865f8
fix(e2e): remove stale Docker socket after shutdown
ericksoa Aug 5, 2026
b27446e
fix(e2e): preserve legacy workload source coverage
ericksoa Aug 5, 2026
102055c
chore(stack): restack Podman proof on buildless activation
ericksoa Aug 5, 2026
1579e1d
test(e2e): register Podman live proof parity
ericksoa Aug 5, 2026
ca517d1
feat(onboard): gate managed runtime activation
ericksoa Aug 5, 2026
10b3589
merge(stack): refresh Podman proof on gated buildless activation
ericksoa Aug 5, 2026
da4fce1
merge(main): integrate CLI test isolation fixes
ericksoa Aug 5, 2026
e25e216
merge(stack): refresh Podman proof on current buildless base
ericksoa Aug 5, 2026
a254cf1
fix(runtime): bind Podman proof evidence
ericksoa Aug 5, 2026
1d816ab
merge(stack): rebuild Podman bootstrap batch on CPU proof
ericksoa Aug 5, 2026
8af8166
merge(stack): carry exact Podman proof head
ericksoa Aug 5, 2026
b6c404a
merge(stack): rebuild persisted runtime recovery on bootstrap
ericksoa Aug 5, 2026
0fa67eb
feat(runtime): define state mutation contract
jyaunches Aug 4, 2026
f40b6da
fix(runtime): harden state mutation plan validation
jyaunches Aug 4, 2026
085adae
fix(runtime): protect live Podman bootstrap leases
ericksoa Aug 5, 2026
25b2155
test(runtime): keep state mutation guards linear
ericksoa Aug 5, 2026
2247488
merge(stack): carry hardened Podman bootstrap head
ericksoa Aug 5, 2026
a84e56c
merge(stack): rebuild Podman GPU and inference runtime
ericksoa Aug 5, 2026
1539456
merge(stack): integrate host-local inference routing
ericksoa Aug 5, 2026
ee60626
feat(runtime): add dormant Podman managed bootstrap transaction (#8052)
ericksoa Aug 5, 2026
310c988
feat(runtime): add dormant Podman CPU lifecycle proof (#8276)
ericksoa Aug 5, 2026
9e60ef6
merge(stack): absorb qualified bootstrap batch
ericksoa Aug 5, 2026
d5159f4
merge(stack): absorb persisted lifecycle batch
ericksoa Aug 5, 2026
ed6b7e8
merge: resolve conflicts with main
github-actions[bot] Aug 5, 2026
5042e1e
merge: resolve conflicts with main
github-actions[bot] Aug 5, 2026
7490de2
fix(onboard): align composed inference dependencies
ericksoa Aug 5, 2026
7953081
merge(stack): preserve inference dependency fix
ericksoa Aug 5, 2026
ee460c4
merge(stack): reconcile persisted lifecycle with MXC
ericksoa Aug 5, 2026
d46c539
merge(stack): absorb repaired buildless base
ericksoa Aug 5, 2026
f046d6e
merge(stack): reconcile host inference with MXC
ericksoa Aug 5, 2026
c1d6087
docs(runtime): clarify dormant Podman contracts
ericksoa Aug 5, 2026
5d55661
test(runtime): align Podman CDI diagnostic
ericksoa Aug 5, 2026
44eac47
merge(runtime): reconstruct B4-D on current main
ericksoa Aug 11, 2026
0be7ad1
feat(runtime): bind Podman inference authority
ericksoa Aug 11, 2026
a0b85a1
feat(inference): bind canonical local receipts
ericksoa Aug 11, 2026
170db57
feat(runtime): manage Podman local inference
ericksoa Aug 11, 2026
9aade2f
feat(inference): transact host-local startup
ericksoa Aug 11, 2026
7b7a3bf
feat(onboard): route local inference across agents
ericksoa Aug 11, 2026
b59d01e
merge(runtime): refresh B4-D onto current main
ericksoa Aug 11, 2026
ce74746
test(runtime): satisfy strict B4-D fixtures
ericksoa Aug 11, 2026
9ed553d
test(runtime): satisfy conditional growth guard
ericksoa Aug 11, 2026
d8a2031
fix(onboard): remove dead rollback assignments
ericksoa Aug 11, 2026
456a337
fix(inference): harden B4-D proof contracts
ericksoa Aug 11, 2026
73454c0
fix(inference): report canonical provider lookup
ericksoa Aug 11, 2026
375b084
merge: refresh B4-D on current main
ericksoa Aug 11, 2026
4f98107
fix(e2e): accept authenticated OpenClaw readiness
ericksoa Aug 11, 2026
0b92ce0
test(e2e): keep health probe regression linear
ericksoa Aug 11, 2026
77d9f45
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
6151e7b
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
fa452d1
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
7221e54
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
deae142
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
caf1bd7
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
f5a5f67
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
b1e53b7
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
70c43e0
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
6b0f7ab
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
428136b
test(e2e): isolate OpenClaw health case
ericksoa Aug 11, 2026
2de7f1e
merge: refresh B4-D reconstruction base
ericksoa Aug 11, 2026
6e1e4ce
Merge remote-tracking branch 'origin/main' into reconstruct/pr8061-b4…
ericksoa Aug 11, 2026
dea3199
fix(openclaw): preserve config continuity metadata
ericksoa Aug 12, 2026
4a51cfd
merge: resolve conflicts with main
github-actions[bot] Aug 12, 2026
103e99f
merge: refresh B4-D reconstruction base
ericksoa Aug 12, 2026
ddabfdb
merge: preserve concurrent PR ancestry
ericksoa Aug 12, 2026
a3cf954
test(onboard): harden review recovery assertions
ericksoa Aug 12, 2026
d97c169
test(onboard): type review recovery mocks
ericksoa Aug 12, 2026
a4fbaf8
Merge current main into B4-D reconstruction
ericksoa Aug 12, 2026
1513291
Merge current main into B4-D reconstruction
ericksoa Aug 12, 2026
146c58f
fix(e2e): bind rollback journal authority
ericksoa Aug 12, 2026
198e3d7
Merge current main into B4-D reconstruction
ericksoa Aug 13, 2026
2da3997
test(e2e): harden protected inference evidence
ericksoa Aug 13, 2026
d427012
fix(inference): bind Ollama acceleration authority
ericksoa Aug 13, 2026
4608ea4
fix(inference): close B4-D review findings
ericksoa Aug 13, 2026
13f98b7
fix(onboard): keep provider seam net-neutral
ericksoa Aug 13, 2026
e17fe24
Merge remote-tracking branch 'origin/main' into reconstruct/pr8061-un…
ericksoa Aug 13, 2026
35d12f4
refactor(inference): satisfy static route guardrails
ericksoa Aug 13, 2026
3697126
chore(onboard): keep entrypoint growth neutral
ericksoa Aug 13, 2026
a5cf5cc
fix(onboard): roll back restart-loop replacements
ericksoa Aug 13, 2026
8c5e750
fix(hermes): allow assigned API port at startup
ericksoa Aug 13, 2026
d4316d6
Merge origin/main into feat/podman-host-local-inference-runtime
ericksoa Aug 13, 2026
d850315
Merge origin/main into feat/podman-host-local-inference-runtime
ericksoa Aug 13, 2026
9675591
fix(hermes): refresh validator integrity pin
ericksoa Aug 13, 2026
a2e7cb8
Merge origin/main into feat/podman-host-local-inference-runtime
ericksoa Aug 13, 2026
655443a
Merge origin/main into feat/podman-host-local-inference-runtime
ericksoa Aug 13, 2026
8988522
fix(podman): revalidate executable authority during dispatch
ericksoa Aug 13, 2026
3f9f3d3
fix(inference): fail closed on recovery authority drift
ericksoa Aug 13, 2026
5f1b450
fix(inference): require semantic tool proof
ericksoa Aug 13, 2026
ad4adef
fix(inference): fail closed on runtime cleanup proof
ericksoa Aug 13, 2026
69f41cd
test(podman): keep authority regression linear
ericksoa Aug 13, 2026
8792dce
merge: resolve conflicts with main
github-actions[bot] Aug 13, 2026
a9552e6
fix(openclaw): restore managed plugin allowlist
ericksoa Aug 13, 2026
5c2268f
merge(main): resolve PR #8061 conflict
ericksoa Aug 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/base-image.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,14 @@ on:
- "nemoclaw-blueprint/**"
- "scripts/**"
- "src/lib/actions/sandbox/openshell-child-visible-credentials.v*.json"
- "src/lib/core/json-types.ts"
- "src/lib/core/ports.ts"
- "src/lib/messaging/**"
- "src/lib/onboard/managed-bootstrap/envelope.ts"
- "src/lib/onboard/managed-startup/**"
- "src/lib/security/credential-hash.ts"
- "src/lib/state/paths.ts"
- "src/lib/state/state-root.ts"
- "src/lib/tool-disclosure.ts"
- "tools/mcp-tool-discovery-runtime/**"
- "tsconfig.runtime-preloads.json"
Expand Down
368 changes: 358 additions & 10 deletions .github/workflows/managed-images.yaml

Large diffs are not rendered by default.

85 changes: 79 additions & 6 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,22 @@ COPY tools/mcp-tool-discovery-runtime/package.json tools/mcp-tool-discovery-runt
RUN ./install-reviewed-runtime.sh \
&& rm -f ./install-reviewed-runtime.sh

# Bundle the driver-neutral startup-profile applicator into one CommonJS file.
# The final image needs no TypeScript loader or repository dependency tree.
FROM mcp-tool-discovery-runtime AS managed-startup-runtime-builder
WORKDIR /opt/nemoclaw-managed-startup-build
COPY src/lib/core/json-types.ts src/lib/core/ports.ts ./src/lib/core/
COPY src/lib/messaging/ ./src/lib/messaging/
COPY src/lib/onboard/managed-bootstrap/envelope.ts ./src/lib/onboard/managed-bootstrap/
COPY src/lib/onboard/managed-startup/ ./src/lib/onboard/managed-startup/
COPY src/lib/security/credential-hash.ts ./src/lib/security/
COPY src/lib/state/paths.ts src/lib/state/state-root.ts ./src/lib/state/
RUN /opt/mcp-tool-discovery-runtime/node_modules/.bin/esbuild \
src/lib/onboard/managed-startup/image-runtime.ts \
--bundle --platform=node --format=cjs --target=node22 \
--outfile=/out/managed-startup-image-runtime.cjs \
&& chmod 0444 /out/managed-startup-image-runtime.cjs

# Group repository-owned files outside the final image so both Docker builders
# can collapse related payloads without invalidating earlier final-image work.
FROM scratch AS openclaw-dependency-payload
Expand Down Expand Up @@ -90,6 +106,7 @@ COPY scripts/verify-wechat-runtime-lock.mts /usr/local/lib/nemoclaw/verify-wecha
FROM scratch AS openclaw-runtime-payload

COPY scripts/lib/sandbox-init.sh /usr/local/lib/nemoclaw/sandbox-init.sh
COPY scripts/lib/entrypoint-env-wrapper.sh /usr/local/lib/nemoclaw/entrypoint-env-wrapper.sh
COPY scripts/lib/gateway-supervisor.sh /usr/local/lib/nemoclaw/gateway-supervisor.sh
COPY scripts/lib/sandbox-rlimits.sh /usr/local/lib/nemoclaw/sandbox-rlimits.sh
COPY scripts/lib/openclaw_device_approval_policy.py /usr/local/lib/nemoclaw/openclaw_device_approval_policy.py
Expand All @@ -99,12 +116,15 @@ COPY scripts/state-dir-guard.py /usr/local/lib/nemoclaw/state-dir-guard.py
COPY scripts/openclaw-config-guard.py /usr/local/lib/nemoclaw/openclaw-config-guard.py
COPY scripts/managed-gateway-control.py /usr/local/lib/nemoclaw/managed-gateway-control.py
COPY scripts/nemoclaw-start.sh /usr/local/bin/nemoclaw-start
COPY scripts/managed-startup-hold.sh /usr/local/bin/nemoclaw-managed-startup-hold
COPY scripts/managed-bootstrap-trampoline.sh /usr/local/bin/nemoclaw-managed-bootstrap
COPY scripts/gateway-control.sh /usr/local/bin/nemoclaw-gateway-control
COPY nemoclaw-blueprint/scripts/*.js /usr/local/lib/nemoclaw/preloads/
COPY --from=runtime-preload-builder /opt/nemoclaw-root/dist/lib/messaging/channels/ /usr/local/lib/nemoclaw/preloads-compiled-channels/
COPY scripts/codex-acp-wrapper.sh /usr/local/bin/nemoclaw-codex-acp
COPY scripts/generate-openclaw-config.mts /scripts/generate-openclaw-config.mts
COPY scripts/validate-openclaw-tool-search.mts /scripts/validate-openclaw-tool-search.mts
COPY --from=managed-startup-runtime-builder /out/managed-startup-image-runtime.cjs /usr/local/lib/nemoclaw/managed-startup-image-runtime.cjs
COPY src/lib/tool-disclosure.ts /src/lib/tool-disclosure.ts
COPY src/lib/messaging/ /src/lib/messaging/
COPY nemoclaw-blueprint/openclaw-plugins/ /usr/local/share/nemoclaw/openclaw-plugins/
Expand Down Expand Up @@ -961,18 +981,24 @@ RUN mkdir -p /sandbox/.nemoclaw/blueprints/0.1.0 \
# runtime-preload-builder stage before being flattened by filename for --require.
COPY --from=openclaw-runtime-payload / /

# Keep the root-owned managed-startup handoff in this image-only layer. The
# following permissions block is replayed on the host by regression tests.
RUN discovery_contract="$(node /usr/local/lib/nemoclaw/mcp-tool-discovery-runtime/mcp-tool-discovery.mjs)" \
&& node -e "const result = JSON.parse(process.argv[1]); if (result.protocol !== 1 || result.ok !== false || result.detail !== \"tool discovery received invalid runtime arguments\") process.exit(1);" "$discovery_contract" \
&& discovery_unsafe="$(find -L /usr/local/lib/nemoclaw/mcp-tool-discovery-runtime \( ! -user root -o -perm /022 \) -print -quit)" \
&& test -z "$discovery_unsafe"
&& test -z "$discovery_unsafe" \
&& install -d -o root -g root -m 0755 /run/nemoclaw

# Copy startup script and shared sandbox initialisation library
# Copy startup script and shared sandbox initialisation library.
RUN chmod 755 /usr/local/bin/nemoclaw-start /usr/local/bin/nemoclaw-codex-acp \
/usr/local/bin/nemoclaw-managed-bootstrap \
/usr/local/bin/nemoclaw-managed-startup-hold \
/usr/local/lib/nemoclaw/sandbox-init.sh \
/scripts/generate-openclaw-config.mts \
/scripts/validate-openclaw-tool-search.mts \
/src/lib/messaging/applier/build/messaging-build-applier.mts \
&& chmod 444 /src/lib/tool-disclosure.ts \
/usr/local/lib/nemoclaw/entrypoint-env-wrapper.sh \
&& chmod -R a+rX /src/lib/messaging \
&& chown root:root /usr/local/bin/nemoclaw-gateway-control \
/usr/local/lib/nemoclaw/gateway-supervisor.sh \
Expand All @@ -984,6 +1010,7 @@ RUN chmod 755 /usr/local/bin/nemoclaw-start /usr/local/bin/nemoclaw-codex-acp \
/usr/local/lib/nemoclaw/openclaw-config-guard.py \
/usr/local/lib/nemoclaw/managed-gateway-control.py \
&& chmod 444 /usr/local/lib/nemoclaw/gateway-supervisor.sh \
/usr/local/lib/nemoclaw/entrypoint-env-wrapper.sh \
/usr/local/lib/nemoclaw/sandbox-rlimits.sh \
&& chmod 644 /usr/local/lib/nemoclaw/openclaw_device_approval_policy.py \
/usr/local/lib/nemoclaw/clean_runtime_shell_env_shim.py \
Expand Down Expand Up @@ -1044,6 +1071,13 @@ ARG NEMOCLAW_INFERENCE_COMPAT_B64=e30=
# rendering. The plan contains placeholders only; secrets are resolved at
# runtime via OpenShell providers.
ARG NEMOCLAW_MESSAGING_PLAN_B64=
# Release-image mode preinstalls the complete reviewed optional dependency
# union. It is inert by default and must never be enabled for a deployment-
# specific Dockerfile build carrying an active messaging plan.
ARG NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=0
# OpenClaw already uses a root supervisor; the explicit value keeps the managed
# image entry-user contract uniform with Hermes and DCode publication.
ARG NEMOCLAW_MANAGED_IMAGE_RUNTIME_USER=root
# Base64-encoded JSON array of secondary OpenClaw agent config entries
# (e.g. [{"id":"research","workspace":"/sandbox/.openclaw/workspace-research",
# "agentDir":"/sandbox/.openclaw/agents/research", ...}]).
Expand Down Expand Up @@ -1109,6 +1143,7 @@ ENV NEMOCLAW_MODEL=${NEMOCLAW_MODEL} \
NEMOCLAW_AGENT_HEARTBEAT_EVERY=${NEMOCLAW_AGENT_HEARTBEAT_EVERY} \
NEMOCLAW_INFERENCE_COMPAT_B64=${NEMOCLAW_INFERENCE_COMPAT_B64} \
NEMOCLAW_EXTRA_AGENTS_JSON_B64=${NEMOCLAW_EXTRA_AGENTS_JSON_B64} \
NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=${NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION} \
NEMOCLAW_OPENCLAW_WECHAT_PLUGIN_PREINSTALLED=1 \
NEMOCLAW_DASHBOARD_BIND=${NEMOCLAW_DASHBOARD_BIND} \
NEMOCLAW_WSL_DASHBOARD_EXPOSURE=${NEMOCLAW_WSL_DASHBOARD_EXPOSURE} \
Expand All @@ -1123,6 +1158,20 @@ ENV NEMOCLAW_MODEL=${NEMOCLAW_MODEL} \
NEMOCLAW_OPENCLAW_OTEL_SERVICE_NAME=${NEMOCLAW_OPENCLAW_OTEL_SERVICE_NAME} \
NEMOCLAW_OPENCLAW_OTEL_SAMPLE_RATE=${NEMOCLAW_OPENCLAW_OTEL_SAMPLE_RATE}

RUN case "$NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION" in \
0) ;; \
1) \
test -z "$NEMOCLAW_MESSAGING_PLAN_B64" \
|| { echo "ERROR: managed-image capability union requires an empty messaging plan" >&2; exit 1; }; \
test "$NEMOCLAW_WEB_SEARCH_ENABLED" = "0" \
|| { echo "ERROR: managed-image capability union requires web search disabled in the neutral image" >&2; exit 1; }; \
test "$NEMOCLAW_OPENCLAW_OTEL" = "0" \
|| { echo "ERROR: managed-image capability union requires OTEL disabled in the neutral image" >&2; exit 1; } \
;; \
*) echo "ERROR: NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION must be 0 or 1" >&2; exit 1 ;; \
esac \
&& test "$NEMOCLAW_MANAGED_IMAGE_RUNTIME_USER" = "root"

# Bake reduced messaging runtime metadata for the entrypoint. The full
# NEMOCLAW_MESSAGING_PLAN_B64 is a build input; OpenShell sandbox create only
# forwards explicit runtime env, so nemoclaw-start reads this generic artifact
Expand Down Expand Up @@ -1152,7 +1201,9 @@ USER sandbox
# for child npm processes. During image build the OpenShell gateway is not
# available at the runtime sandbox proxy address yet, so defer the final proxy
# block until after build-time OpenClaw doctor/plugin commands complete.
RUN NEMOCLAW_OPENCLAW_MANAGED_PROXY=0 node --experimental-strip-types /scripts/generate-openclaw-config.mts
RUN NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=0 \
NEMOCLAW_OPENCLAW_MANAGED_PROXY=0 \
node --experimental-strip-types /scripts/generate-openclaw-config.mts

# Validate the patched OpenClaw tool-search contract against real generated
# configs for both supported disclosure modes. This runs at image build time so
Expand All @@ -1168,6 +1219,7 @@ RUN set -eu; \
NEMOCLAW_MODEL=test-model \
NEMOCLAW_PRIMARY_MODEL_REF=inference/test-model \
NEMOCLAW_TOOL_DISCLOSURE="$mode" \
NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=0 \
NEMOCLAW_OPENCLAW_MANAGED_PROXY=0 \
node --experimental-strip-types /scripts/generate-openclaw-config.mts; \
node --experimental-strip-types /scripts/validate-openclaw-tool-search.mts \
Expand All @@ -1188,6 +1240,7 @@ RUN set -eu; \
# openKeyedStore on OpenClaw >= 2026.6.10.
# hadolint ignore=DL3059,DL4006
RUN set -eu; \
managed_image_union="${NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION:-0}"; \
verify_openclaw_plugin_integrity() { \
plugin_spec="$1"; \
expected_integrity=""; \
Expand Down Expand Up @@ -1220,13 +1273,16 @@ RUN set -eu; \
openclaw plugins install "npm-pack:${plugin_install_archive}"; \
rm -rf "$plugin_root"; \
}; \
if [ "$NEMOCLAW_OPENCLAW_OTEL" = "1" ] || [ "$NEMOCLAW_WEB_SEARCH_ENABLED" = "1" ]; then \
if [ "$managed_image_union" = "1" ] || [ "$NEMOCLAW_OPENCLAW_OTEL" = "1" ] || [ "$NEMOCLAW_WEB_SEARCH_ENABLED" = "1" ]; then \
test -n "$OPENCLAW_VERSION"; \
fi; \
if [ "$NEMOCLAW_OPENCLAW_OTEL" = "1" ]; then \
if [ "$managed_image_union" = "1" ]; then \
install_reviewed_openclaw_plugin "@openclaw/diagnostics-otel"; \
install_reviewed_openclaw_plugin "@openclaw/brave-plugin"; \
elif [ "$NEMOCLAW_OPENCLAW_OTEL" = "1" ]; then \
install_reviewed_openclaw_plugin "@openclaw/diagnostics-otel"; \
fi; \
if [ "$NEMOCLAW_WEB_SEARCH_ENABLED" = "1" ]; then \
if [ "$managed_image_union" != "1" ] && [ "$NEMOCLAW_WEB_SEARCH_ENABLED" = "1" ]; then \
case "${NEMOCLAW_WEB_SEARCH_PROVIDER:-brave}" in \
brave) \
install_reviewed_openclaw_plugin "@openclaw/brave-plugin"; \
Expand Down Expand Up @@ -1262,6 +1318,12 @@ RUN set -eu; \
NEMOCLAW_WECHAT_NPM_INSTALL_CACHE="$install_cache" \
OPENCLAW_VERSION="${OPENCLAW_VERSION}" \
node --experimental-strip-types /src/lib/messaging/applier/build/messaging-build-applier.mts --agent openclaw --phase agent-install; \
if [ "$NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION" = "1" ]; then \
NEMOCLAW_WECHAT_NPM_INSTALL_CACHE="$install_cache" \
OPENCLAW_VERSION="${OPENCLAW_VERSION}" \
node --experimental-strip-types /src/lib/messaging/applier/build/messaging-build-applier.mts \
--agent openclaw --phase managed-image-capability-union; \
fi; \
rm -rf "$install_cache"; \
trap - EXIT; \
test ! -e "$install_cache"; \
Expand Down Expand Up @@ -1305,6 +1367,17 @@ RUN NPM_CONFIG_IGNORE_SCRIPTS=true npm_config_ignore_scripts=true \
# hadolint ignore=DL3059,DL4006
RUN OPENCLAW_VERSION="${OPENCLAW_VERSION}" node --experimental-strip-types /src/lib/messaging/applier/build/messaging-build-applier.mts --agent openclaw --phase post-agent-install

# A managed image is a neutral capability carrier, not an all-channels-enabled
# deployment. Regenerate after every optional plugin is installed so OpenClaw's
# install registry survives while every optional plugin/channel remains inert.
# Validate the exact generated file through the pinned OpenClaw CLI.
# hadolint ignore=DL3059,DL4006
RUN if [ "$NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION" = "1" ]; then \
node --experimental-strip-types /scripts/generate-openclaw-config.mts; \
validation="$(openclaw config validate --json)"; \
node -e 'const result=JSON.parse(process.argv[1]); if (result.valid !== true) process.exit(1)' "$validation"; \
fi

# Release the offline lock so the runtime sandbox can install MCP servers,
# skills, and ad-hoc packages via the OpenShell L7 proxy.
ENV NPM_CONFIG_OFFLINE=false
Expand Down
Loading
Loading