fix(security): remediate OpenClaw 2026.6.10 transitive dependencies#7286
Conversation
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughAdds a validated OpenClaw npm archive remediation helper, integrates it into archive packaging and Docker installation for version ChangesOpenClaw remediation flow
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant ReviewedArchivePacker
participant OpenClawRemediation
participant NpmInstall
ReviewedArchivePacker->>OpenClawRemediation: provide packed archive and package spec
OpenClawRemediation->>OpenClawRemediation: patch and validate dependency graph
OpenClawRemediation->>NpmInstall: return remediated archive path
NpmInstall->>NpmInstall: install resulting archive
Possibly related issues
Possibly related PRs
Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit b26cf68 in the TypeScript / code-coverage/cliThe overall coverage in commit b26cf68 in the Show a code coverage summary of the most impacted files.
Updated |
PR Review Advisor — InformationalAdvisor assessment: Informational / high confidence Model lanes
Nemotron output stays in workflow artifacts and does not change the assessment above. E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: 2 optional E2E recommendations
2 warnings · 0 suggestionsWarningsWarnings do not block.
|
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@scripts/lib/openclaw-npm-remediation.mts`:
- Around line 522-527: The CLI path around buildRemediatedOpenClawArchive must
pass the pinned remediation digest. Resolve the selected package’s metadata from
REMEDIATIONS using the packageSpec argument and provide its
expectedPatchedMetadataIntegrity value, matching
remediateReviewedOpenClawArchive’s guarded behavior.
In `@test/openclaw-integrity-pin-suite.ts`:
- Around line 228-240: The remediation helper writes remediated-openclaw.tgz,
but the installation assertions currently accept the original npm pack archive.
Update the success checks in the OpenClaw installation test to verify every
install command consumes remediated-openclaw.tgz and rejects the source archive,
using observable command/output data rather than broad mocks.
In `@test/openclaw-npm-remediation.test.ts`:
- Around line 139-166: Extend the remediation tests to inspect the patched
package.json through the existing public-boundary test flow, not only
npm-shrinkwrap.json. For both remediation paths, assert the expected plugin
axios and bundledDependencies metadata and the core tar metadata, ensuring
incomplete archive patches cannot pass.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 4265c642-5274-4729-994b-905ec5406fd6
📒 Files selected for processing (13)
DockerfileDockerfile.baseagents/hermes/Dockerfilescripts/audit-reviewed-npm-graph.mtsscripts/lib/openclaw-npm-remediation.mtssrc/lib/messaging/applier/build/messaging-build-applier.mtssrc/lib/sandbox/build-context.tstest/messaging-build-applier-integrity.test.tstest/messaging-build-applier.test.tstest/openclaw-dependency-review.test.tstest/openclaw-integrity-pin-suite.tstest/openclaw-npm-remediation.test.tstest/sandbox-build-context.test.ts
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
|
🌿 Preview your docs: https://nvidia-preview-pr-7286.docs.buildwithfern.com/nemoclaw |
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
E2E Target Results —
|
| Test | Result | Total wall clock time |
|---|---|---|
| agent-turn-latency | 1m 49s | |
| bedrock-runtime-compatible-anthropic | 1m 51s | |
| bootstrap-install-smoke | 1m 48s | |
| brave-search | ✅ success | 47s |
| channels-add-remove | 1m 47s | |
| channels-stop-start | 1m 50s | |
| cloud-inference | 1m 49s | |
| cloud-onboard | 1m 51s | |
| common-egress-agent | 1m 49s | |
| concurrent-gateway-ports | 1m 48s | |
| credential-migration | 1m 49s | |
| credential-sanitization | 1m 49s | |
| cron-preflight-inference-local | 1m 48s | |
| device-auth-health | 1m 50s | |
| diagnostics | 1m 48s | |
| docs-validation | 1m 47s | |
| double-onboard | 1m 49s | |
| full-e2e | 1m 50s | |
| gateway-drift-preflight | ✅ success | 45s |
| gateway-guard-recovery | 1m 48s | |
| gateway-health-honest | ✅ success | 55s |
| generate-matrix | ✅ success | 34s |
| gpu-double-onboard | 1m 35s | |
| gpu-e2e | 46s | |
| hermes-dashboard | 1m 48s | |
| hermes-discord | 1m 48s | |
| hermes-e2e | 1m 49s | |
| hermes-gpu-startup | ⏭️ skipped | — |
| hermes-inference-switch | 1m 49s | |
| hermes-shields-config | 1m 48s | |
| hermes-slack | 1m 25s | |
| inference-routing | 1m 49s | |
| issue-2478-crash-loop-recovery | 1m 49s | |
| issue-4434-tui-unreachable-inference | ✅ success | 1m 5s |
| issue-4462-scope-upgrade-approval | 1m 48s | |
| jetson-nvmap-gpu | ⏭️ skipped | — |
| kimi-inference-compat | 1m 50s | |
| live | 1m 53s | |
| mcp-bridge | 1m 51s | |
| mcp-bridge-dev | ⏭️ skipped | — |
| messaging-compatible-endpoint | 1m 50s | |
| messaging-providers | 1m 49s | |
| model-router-provider-routed-inference | 1m 50s | |
| network-policy | 1m 51s | |
| ollama-auth-proxy | 1m 48s | |
| onboard-negative-paths | ✅ success | 59s |
| onboard-repair | 1m 49s | |
| onboard-resume | 1m 49s | |
| openclaw-discord-pairing | 1m 47s | |
| openclaw-inference-switch | 1m 50s | |
| openclaw-plugin-runtime-exdev | 1m 48s | |
| openclaw-skill-cli | 1m 50s | |
| openclaw-slack-pairing | 1m 48s | |
| openclaw-tui-chat-correlation | 1m 48s | |
| openshell-gateway-auth-contract | ⏭️ skipped | — |
| openshell-gateway-upgrade | 1m 51s | |
| openshell-version-pin | ✅ success | 48s |
| overlayfs-autofix | ✅ success | 49s |
| rebuild-hermes | 1m 48s | |
| rebuild-hermes-stale-base | 1m 49s | |
| rebuild-openclaw | 1m 49s | |
| sandbox-operations | 1m 50s | |
| sandbox-rebuild | 1m 50s | |
| sandbox-rlimits-connect | ⏭️ skipped | — |
| sandbox-survival | 1m 50s | |
| security-posture | 1m 49s | |
| sessions-agents-cli | 1m 49s | |
| shields-config | 1m 48s | |
| skill-agent | 1m 50s | |
| snapshot-commands | 1m 49s | |
| spark-install | 1m 48s | |
| state-backup-restore | 1m 49s | |
| telegram-injection | 1m 48s | |
| token-rotation | 1m 50s | |
| tunnel-lifecycle | 1m 47s | |
| ubuntu-repo-cli-smoke | ✅ success | 36s |
| upgrade-stale-sandbox | 1m 50s | |
| vllm-docker-storage | ✅ success | 43s |
Explicit-only jobs skipped:
openshell-gateway-auth-contract(default dispatch excludes the resource-heavy OpenShell auth-contract probe unless selected; validate withjobs=openshell-gateway-auth-contractortargets=openshell-gateway-auth-contract),mcp-bridge-dev(default dispatch excludes moving OpenShell dev artifacts unless explicitly selected; validate withjobs=mcp-bridge-devortargets=mcp-bridge-dev),hermes-gpu-startup(default dispatch excludes this explicit-only job unless selected; validate withjobs=hermes-gpu-startuportargets=hermes-gpu-startup),sandbox-rlimits-connect(default dispatch excludes the destructive rlimit fork/connect probe unless selected; validate withjobs=sandbox-rlimits-connectortargets=sandbox-rlimits-connect),jetson-nvmap-gpu(default dispatch excludes Jetson; explicit dispatch requires allow_jetson_runner_queue=true after confirming an online Jetson runner because queued jobs do not honor timeout-minutes before assignment; validate withjobs=jetson-nvmap-gpuortargets=jetson-nvmap-gpu).
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/security/openclaw-2026.6.10-dependency-review.md`:
- Around line 49-54: Update the text immediately before the command in the
dependency review document to add a complete imperative sentence addressing the
reader directly in active voice and present tense. Ensure every sentence in that
section ends with a period, while preserving the command unchanged.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: bfbbb5d6-4961-4cad-a322-0c5ecce33b68
📒 Files selected for processing (8)
.github/workflows/base-image.yamlci/source-shape-test-budget.jsondocs/security/openclaw-2026.6.10-dependency-review.mdscripts/lib/openclaw-npm-remediation.mtstest/fetch-guard-patch-regression.test.tstest/openclaw-dependency-review.test.tstest/openclaw-integrity-pin-suite.tstest/openclaw-npm-remediation.test.ts
🚧 Files skipped from review as they are similar to previous changes (3)
- test/openclaw-integrity-pin-suite.ts
- test/openclaw-dependency-review.test.ts
- scripts/lib/openclaw-npm-remediation.mts
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
E2E Target Results —
|
| Test | Result | Total wall clock time |
|---|---|---|
| agent-turn-latency | 2m 46s | |
| bedrock-runtime-compatible-anthropic | 2m 50s | |
| bootstrap-install-smoke | 2m 47s | |
| brave-search | ✅ success | 43s |
| channels-add-remove | 2m 46s | |
| channels-stop-start | 2m 48s | |
| cloud-inference | 2m 46s | |
| cloud-onboard | 2m 46s | |
| common-egress-agent | 2m 47s | |
| concurrent-gateway-ports | 2m 47s | |
| credential-migration | 2m 47s | |
| credential-sanitization | 2m 48s | |
| cron-preflight-inference-local | 2m 46s | |
| device-auth-health | 2m 48s | |
| diagnostics | 2m 46s | |
| docs-validation | ✅ success | 1m 46s |
| double-onboard | 2m 46s | |
| full-e2e | 2m 45s | |
| gateway-drift-preflight | ✅ success | 50s |
| gateway-guard-recovery | 2m 47s | |
| gateway-health-honest | ✅ success | 47s |
| generate-matrix | ✅ success | 21s |
| gpu-double-onboard | 1m 44s | |
| gpu-e2e | 1m 46s | |
| hermes-dashboard | 2m 46s | |
| hermes-discord | 2m 46s | |
| hermes-e2e | 2m 45s | |
| hermes-gpu-startup | ⏭️ skipped | — |
| hermes-inference-switch | 2m 47s | |
| hermes-shields-config | 2m 47s | |
| hermes-slack | 2m 17s | |
| inference-routing | 2m 46s | |
| issue-2478-crash-loop-recovery | 2m 48s | |
| issue-4434-tui-unreachable-inference | ✅ success | 56s |
| issue-4462-scope-upgrade-approval | 2m 46s | |
| jetson-nvmap-gpu | ⏭️ skipped | — |
| kimi-inference-compat | 2m 46s | |
| live | 2m 48s | |
| mcp-bridge | 2m 49s | |
| mcp-bridge-dev | ⏭️ skipped | — |
| messaging-compatible-endpoint | 2m 46s | |
| messaging-providers | 2m 46s | |
| model-router-provider-routed-inference | 2m 47s | |
| network-policy | 2m 45s | |
| ollama-auth-proxy | ✅ success | 1m 29s |
| onboard-negative-paths | ✅ success | 56s |
| onboard-repair | 2m 46s | |
| onboard-resume | 2m 46s | |
| openclaw-discord-pairing | 2m 47s | |
| openclaw-inference-switch | 2m 48s | |
| openclaw-plugin-runtime-exdev | 2m 47s | |
| openclaw-skill-cli | 2m 45s | |
| openclaw-slack-pairing | 2m 47s | |
| openclaw-tui-chat-correlation | 2m 46s | |
| openshell-gateway-auth-contract | ⏭️ skipped | — |
| openshell-gateway-upgrade | 2m 47s | |
| openshell-version-pin | ✅ success | 39s |
| overlayfs-autofix | ✅ success | 42s |
| rebuild-hermes | 2m 47s | |
| rebuild-hermes-stale-base | 2m 46s | |
| rebuild-openclaw | 2m 46s | |
| sandbox-operations | 2m 46s | |
| sandbox-rebuild | 2m 46s | |
| sandbox-rlimits-connect | ⏭️ skipped | — |
| sandbox-survival | 2m 48s | |
| security-posture | 2m 47s | |
| sessions-agents-cli | 2m 47s | |
| shields-config | 2m 45s | |
| skill-agent | 2m 46s | |
| snapshot-commands | 2m 46s | |
| spark-install | 2m 48s | |
| state-backup-restore | 2m 47s | |
| telegram-injection | 2m 46s | |
| token-rotation | 2m 47s | |
| tunnel-lifecycle | 2m 47s | |
| ubuntu-repo-cli-smoke | ✅ success | 41s |
| upgrade-stale-sandbox | 2m 46s | |
| vllm-docker-storage | ✅ success | 40s |
Explicit-only jobs skipped:
openshell-gateway-auth-contract(default dispatch excludes the resource-heavy OpenShell auth-contract probe unless selected; validate withjobs=openshell-gateway-auth-contractortargets=openshell-gateway-auth-contract),mcp-bridge-dev(default dispatch excludes moving OpenShell dev artifacts unless explicitly selected; validate withjobs=mcp-bridge-devortargets=mcp-bridge-dev),hermes-gpu-startup(default dispatch excludes this explicit-only job unless selected; validate withjobs=hermes-gpu-startuportargets=hermes-gpu-startup),sandbox-rlimits-connect(default dispatch excludes the destructive rlimit fork/connect probe unless selected; validate withjobs=sandbox-rlimits-connectortargets=sandbox-rlimits-connect),jetson-nvmap-gpu(default dispatch excludes Jetson; explicit dispatch requires allow_jetson_runner_queue=true after confirming an online Jetson runner because queued jobs do not honor timeout-minutes before assignment; validate withjobs=jetson-nvmap-gpuortargets=jetson-nvmap-gpu).
There was a problem hiding this comment.
🧹 Nitpick comments (1)
test/openclaw-npm-remediation.test.ts (1)
419-421: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winDuplicated "extract observed integrity, then rebuild" scaffolding across the core and plugin tests.
The try/catch block that regex-extracts
got (sha512-\S+)from the deliberate-mismatch error and reuses it for a secondbuildRemediatedOpenClawArchivecall is copy-pasted between the core archive test (around line 419) and the plugin archive test (lines 460-469). Extracting a small shared helper, e.g.rebuildWithObservedIntegrity(request), would remove this duplication and reduce drift risk as more remediation package types are added.As per path instructions, prefer tests built on shared, reusable assertions over duplicated implementation-detail parsing where practical.
♻️ Suggested helper
function rebuildWithObservedIntegrity( request: Parameters<typeof buildRemediatedOpenClawArchive>[0], ): ReturnType<typeof buildRemediatedOpenClawArchive> { let metadataIntegrity = ""; try { buildRemediatedOpenClawArchive({ ...request, expectedPatchedMetadataIntegrity: "sha512-deliberate-mismatch", }); } catch (error) { const message = String(error); expect(message).toMatch(/got sha512-\S+/u); metadataIntegrity = message.match(/got (sha512-\S+)/u)?.[1] ?? ""; } expect(metadataIntegrity).toMatch(/^sha512-/u); return buildRemediatedOpenClawArchive({ ...request, expectedPatchedMetadataIntegrity: metadataIntegrity, }); }Also applies to: 460-469
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@test/openclaw-npm-remediation.test.ts` around lines 419 - 421, Extract the duplicated observed-integrity retry logic from the core and plugin archive tests into a shared rebuildWithObservedIntegrity helper near the test utilities. Have it perform the deliberate-mismatch build, validate and extract the observed sha512 integrity, then call buildRemediatedOpenClawArchive again with that integrity; replace both duplicated try/catch blocks with this helper.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@test/openclaw-npm-remediation.test.ts`:
- Around line 419-421: Extract the duplicated observed-integrity retry logic
from the core and plugin archive tests into a shared
rebuildWithObservedIntegrity helper near the test utilities. Have it perform the
deliberate-mismatch build, validate and extract the observed sha512 integrity,
then call buildRemediatedOpenClawArchive again with that integrity; replace both
duplicated try/catch blocks with this helper.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: bce2aa80-2e49-4719-a426-3b5735f6418b
📒 Files selected for processing (2)
ci/source-shape-test-budget.jsontest/openclaw-npm-remediation.test.ts
🚧 Files skipped from review as they are similar to previous changes (1)
- ci/source-shape-test-budget.json
apurvvkumaria
left a comment
There was a problem hiding this comment.
Requesting changes for one production-blocking issue at current head 223aea520.
Blocker: the Docker-style global install has no usable tar package
The earlier nested tar@7.5.13 problem is gone, but the replacement archive still does not produce a valid production dependency topology. I rebuilt the reviewed archive and installed it with the exact Dockerfile-style command under the pinned Node 22/npm 10 base. npm install -g --ignore-scripts succeeds and openclaw --version passes, but:
npm ls -g tar --all
npm error code ELSPROBLEMS
invalid: tar@ /usr/local/lib/node_modules/openclaw/node_modules/tar
That tar directory is empty, has no package.json, and resolving tar from OpenClaw throws MODULE_NOT_FOUND. OpenClaw runtime code imports tar, so this can fail at runtime despite the version smoke test passing.
The remediation rewrites both requirements to 7.5.19 and physically bundles the patched fs-safe package, but it does not fetch/copy/bundle tar@7.5.19 itself. Global npm deduplication across that bundled dependency boundary leaves an empty stub. The reviewed graph audit uses a local install, where tar hoists successfully, so its passing result does not exercise this production failure. Even auditing the broken global tree does not report the missing module.
Before merge, please:
- Materialize the SRI-pinned
tar@7.5.19package into a valid global-install topology. - Add a production-parity regression that runs
npm install -gwith the pinned Node/npm image, then requiresnpm ls -g tar --allto succeed, resolvestarfrom OpenClaw, and asserts every installed OpenClaw tar copy is7.5.19.
I am not blocking this emergency mitigation on the documented low/moderate advisories, generalized completed-image scanning, archive resource ceilings, or fuller base-input provenance binding; those can be handled in the planned fix-forward work.
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
|
The production-blocking global-install topology issue from review 4741268993 is fixed in c9aa63c. The remediation now removes @openclaw/fs-safe duplicate optional tar/jszip declarations so npm retains OpenClaw direct jszip@3.10.1 and remediated tar@7.5.19. A real Node 22.22.2 global install imports the clawhub module successfully, and both Docker image paths now fail closed on an invalid installed dependency tree. Focused tests, docs, source-shape, hooks/check:diff, and the exact reviewed dependency audit are green; final-head E2E run 29802319965 is in progress. |
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
|
Update: #7289 now validates this PR's current-image installed OpenClaw dependency graph only. #7289 is downstream and does not block #7286 from merging. After #7286 lands, #7289 will be updated or rebased onto that main revision and its opt-in container lane will be run against the exact final image digest. |
E2E Target Results — ❌ Some tests failedRun: 29828082831
|
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29830832493
|
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
E2E Target Results — ❌ Some tests failedRun: 29833691485
|
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
E2E Target Results — ✅ All requested tests passedRun: 29837105130
|
E2E Target Results — ❌ Some tests failedRun: 29841116860
|
E2E Target Results — ✅ All requested tests passedRun: 29841030448
|
E2E Target Results — ❌ Some tests failedRun: 29842118854
|
E2E Target Results — ✅ All requested tests passedRun: 29842321123
|
E2E Target Results — ❌ Some tests failedRun: 29842856969
|
E2E Target Results — ❌ Some tests failedRun: 29841990305
|
E2E Target Results — ❌ Some tests failedRun: 29843686345
|
E2E Target Results — ❌ Some tests failedRun: 29840145320
|
E2E Target Results — ❌ Some tests failedRun: 29844272101
|
E2E Target Results — ✅ All requested tests passedRun: 29844141664
|
E2E Target Results — ✅ All requested tests passedRun: 29844646319
|
E2E Target Results — ✅ All requested tests passedRun: 29844868678
|
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
## Summary Complete the planned v0.0.90 changelog after the security remediation in #7286 merged. The release entry now records the remediated OpenClaw dependency boundary and links to the detailed dependency review. ## Related Issue Related to #5591 and follows #7286. ## Changes - Add the OpenClaw core, Slack, and Microsoft Teams transitive dependency remediation to the v0.0.90 summary and release bullets. - Record fail-closed archive validation and the reviewed residual audit findings. - Link the detailed OpenClaw 2026.6.10 dependency review. - Source summary: #7286 -> `docs/changelog/2026-07-20.mdx`. - Reconciled #7316 as documentation-only coverage for existing Deep Agents behavior; its merged source page is already the canonical record and requires no separate release behavior entry. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `test/changelog-docs.test.ts` validates changelog structure and links, and the full docs build validates generated content and routes. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: not applicable - Station profile/scenario: not applicable - Result: not applicable - Supporting evidence: not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts`: 6/6 passed - [x] Applicable broad gate passed — `npm run docs`: 0 errors; the two repository-wide pre-existing Fern warnings remain - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [x] `npm run docs` builds without warnings (doc changes only) — 0 errors; the two repository-wide pre-existing Fern warnings remain - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Clarified inference provider routing and credential handling for managed agent images. * Added migration guidance ahead of the upcoming fallback removal. * Documented security updates for OpenClaw, Slack, and Microsoft Teams installations, including verified package remediation and archive validation. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Julie Yaunches <jyaunches@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Add a standalone container verifier for the current OpenClaw security remediation produced by #7286. The verifier inspects the installed OpenClaw package graph in an offline, read-only, unprivileged container and rejects vulnerable, stale, or internally inconsistent dependency state. ## Related Issue Related to #7272. The real-container lane validates the final image produced after #7286 lands; this PR remains independently based on `main` and has no dependency on #7276. ## Changes - Keep always-running contract coverage for explicit opt-in, evidence rejection, and the least-privilege Docker boundary. - Replace the historical runtime plugin-install matrix with one current-image probe of the globally installed `openclaw@2026.6.10` graph. - Require exact installed and shrinkwrap evidence for `tar@7.5.19`, `brace-expansion@5.0.7`, `@openclaw/fs-safe@0.3.0`, and `jszip@3.10.1`. - Require the `@openclaw/fs-safe` optional dependencies to be absent, reject nested vulnerable copies, validate `npm ls`, and verify the OpenClaw executable resolves to the reviewed installation. - Run the image probe with no network, a read-only root filesystem, the sandbox identity, no capabilities, no privilege escalation, bounded resources, and no host mounts. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [ ] Docs updated for user-facing behavior changes - [x] Docs not applicable — justification: this changes only an internal, explicitly opt-in image verifier and introduces no user-facing behavior, configuration, API, or documentation route. - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable - Station profile/scenario: Not applicable - Result: Not applicable - Supporting evidence: Not applicable ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — current exact-head contract run: 3 passed with the real-container lane intentionally skipped; current exact-head real-container lane: 4 passed against the exact merged-#7286 CI image; an older pre-final image was correctly rejected for its stale wrapper, `fs-safe`, and lock metadata. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) Additional checks passed: CLI typecheck, exact Vitest project membership, test-title style, source-shape budget, test-file-size budget, Biome, repository checks, and secret scanning. ## Merge Dependencies This is a downstream verifier and does not block #7286 from merging. Human review can proceed now, but this PR must not merge until all items below are complete: - [x] #7286 is merged into `main`. - [x] Update this PR on the resulting `main` and run the opt-in real-container lane against the exact final built image. - [x] Record the merged #7286 SHA, immutable image digest, and passing test evidence before merging this PR. Final image evidence: - Merged #7286 revision: `2ad613d6e9abc26859b59e5a876ddd0ee40c7ca1` - Exact #7289 head: `48459d489c929076b47b41550b035cc90093bee1` - CI-built image: `nemoclaw-production@sha256:a075375409e3c81d248beafe2b627c6bd2ee5ea95f8f36a7b1c0fdb02850bc4c` - OCI revision label: `acfa2613c7a645ae1bff21914f25d824e5fbcf62` - Hardened real-container verifier: 4/4 passed (offline, read-only root filesystem, unprivileged sandbox user, no capabilities, no privilege escalation, bounded resources, and no host mounts). --- Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Added a new end-to-end security validation for an OpenClaw container image, selected via target ID and/or explicit opt-in. * Enforces that the image is referenced by an immutable digest (rejects non-digest/invalid image values). * When enabled, executes verification in a hardened container boundary (offline, read-only, least-privilege, constrained resources) and confirms expected dependency/lockfile integrity, including absence of optional and nested dependencies. * Emits and strictly validates structured JSON security evidence, including negative contract checks for tampered results. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Apurv Kumaria <akumaria@nvidia.com> Signed-off-by: Charan Jagwani <cjagwani@nvidia.com> Co-authored-by: Charan Jagwani <cjagwani@nvidia.com>
## Summary Reopen follow-up for #6520: `nemoclaw uninstall --yes` followed by a curl reinstall hard-aborts at the installer strict pre-upgrade backup. The uninstall removes the gateway registration and the sandbox container but preserves `sandboxes.json`, so the stranded record can only ever be skipped — and the strict gate (`NEMOCLAW_REQUIRE_ALL_SANDBOX_BACKUPS=1`, #6114) exits 1 before the installer recovery phase (`recover_preexisting_sandboxes_before_onboard`), the phase that knows how to surface orphans, ever runs. The #6539 orphan classifier is wired only into `upgrade-sandboxes`, which is downstream of the aborting backup. ## What changed - `backupAll()` now classifies stranded records with the existing `classifyOrphanedRegistrySandboxes` (unobserved on the selected gateway AND persisted binding resolving to that same gateway), gated on the new `isSandboxContainerDefinitivelyAbsent()`. Stranded records are tracked separately from `skipped`, so the strict gate keeps failing closed for every genuine skip, and the run ends with `orphanedRegistrySummary` + `orphanedRegistryRemediation` (same destroy/onboard guidance as the recovery phase). End-to-end, the installer now proceeds to its recovery phase, which reports the orphans and yields "completed with warnings" instead of a hard abort. - The exemption is two-phase (PRA-1): after the backup loop, a confirming second pinned listing re-checks every stranded candidate — the same #6114 confirmation idiom as `upgrade-sandboxes` — and any candidate the gateway observes again reverts to a genuine strict skip. Container absence is itself checked per candidate at skip time. - `isSandboxContainerDefinitivelyAbsent()` fails closed everywhere absence cannot be proven: non-docker or unknown driver (including a throwing registry read), and a failed or timed-out labeled listing. The listing is status-checked (`docker ps -a` with the OpenShell labels) rather than reusing `findLabeledSandboxContainers`, which swallows docker errors — a dead daemon yields `null`, never "absent" — and passes `ignoreError` so the probe cannot `process.exit` the run. - `backup-all` now pins its sandbox listing to the selected gateway (same #6114 rationale and idiom as `upgrade-sandboxes`): an unpinned list taken from a sibling gateway selection must not feed a fail-open stranded decision. - The exemption carries an in-code source-of-truth review block (PRA-2): source boundary (`nemoclaw uninstall` preserves `sandboxes.json` by design), source-fix constraint (backup-all must not reconcile the registry; record removal is owned by the recovery phase destroy/onboard flow), and removal condition (install/uninstall registry reconciliation, or running the recovery phase before the strict backup). ## Constraints preserved (pinned by tests) - Strict gate still aborts on any genuine skip (#6114 cases untouched and green). - A sandbox bound to a sibling gateway is never claimed stranded, even when its container is absent on this host. - An unobserved sandbox whose container still exists keeps the strict abort (reconnect race). - A stranded candidate the confirming listing observes again reverts to a strict skip (lifecycle race). - Real backup failures (EACCES, non-manifest paths) still re-throw/abort. - A registry row with a null/unknown driver keeps the strict abort — fail closed, since absence cannot be proven for it. - `ORPHANED_SANDBOX_MARKER` / summary / remediation wording unchanged; install.sh greps the marker only from the recovery-phase log, which this change does not touch. ## Review responses - **PR Review Advisor PRA-1** (revalidate absence before exempting the gate): addressed by the confirming second pinned listing after the backup loop plus per-candidate absence checks at skip time; new test pins the reappeared-candidate revert. - **PR Review Advisor PRA-2** (bound the workaround to its source fix): addressed with the in-code source-of-truth review block (source boundary / fix constraint / removal condition). - `reviewed-npm-audit` failure is upstream-wide (also fails on #7289) and is being remediated by #7286; this PR adds no dependencies. ## Verification - `vitest`: `maintenance.test.ts` (32), `stopped-sandbox-backup.test.ts` (24), `orphan-detection.test.ts`, `upgrade-sandboxes-recovery.test.ts`, `openshell-sandbox-list.test.ts` — 108 tests green; installer lane `test/install-orphaned-sandbox-recovery.test.ts` (8, drives strict backup through recovery and the real install.sh orphan grep) green; `typecheck:cli`, `lint`, and `biome check` clean. The new maintenance tests pin `GATEWAY_PORT` so they stay green under an exported `NEMOCLAW_GATEWAY_PORT`. - Live end-to-end on a workstation (real docker daemon, real registry file, openshell CLI shimmed to a healthy empty gateway, real built CLI): stranded record → warning + `0 skipped` + exit 0 under strict mode (through both listings); same record bound to `gatewayPort: 9999` → strict abort exit 1 with no orphan claim; same record with a labeled container present → strict abort exit 1 with no orphan claim. Refs #6520 Signed-off-by: Dongni Yang <dongniy@nvidia.com> 🤖 Generated with [Claude Code](https://claude.com/claude-code) <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved backup-all orphan handling: potentially stranded sandboxes are skipped when their containers are definitively absent, then rechecked with the same selected gateway before remediation occurs. * Tightened strict-mode “fail closed” behavior for confirmed absent containers, including mismatched-gateway scenarios and reappearing candidates. * Reduced false “container absent” results by treating Docker/registry uncertainties as unknown rather than absent. * **Tests** * Expanded coverage for stranded-orphan detection and definitive container absence (including fail-closed, reappearance, and gateway-pinning scenarios) with improved Docker mock observability. <!-- end of auto-generated comment: release notes by coderabbit.ai --> ## Takeover review response - The PR Review Advisor handoff warning is addressed by an installer boundary regression that drives strict `backup-all`, orphan recovery, and the completed-with-warnings result in order. ## Documentation Writer Review - [x] Documentation writer subagent reviewed the completed changes - Result: `no-docs-needed` - Evidence: Reviewed the complete five-file diff at `71a02caebe9f`. No documentation paths changed; existing docs already cover strict backup and stranded-record recovery and remediation. - Agent: Codex Desktop - PR: #7290 <!-- docs-review-head-sha: 71a02ca --> <!-- docs-review-agents-blob-sha: 560ff38 --> Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> --------- Signed-off-by: Dongni Yang <dongniy@nvidia.com> Signed-off-by: Charan Jagwani <cjagwani@nvidia.com> Signed-off-by: Julie Yaunches <jyaunches@nvidia.com> Co-authored-by: Charan Jagwani <cjagwani@nvidia.com> Co-authored-by: Julie Yaunches <jyaunches@nvidia.com>
Summary
Keep OpenClaw core and official plugins pinned to
2026.6.10while replacing the reviewed vulnerable transitive packages before installation. The same fail-closed archive remediation feeds production images, messaging plugin installs, and the reviewed npm audit graph.Changes
tar@7.5.16and@openclaw/fs-safe@0.3.0'star@7.5.13resolution withtar@7.5.19.brace-expansion@5.0.6with5.0.7in the core graph.axios@1.16.0with1.18.0in the Slack and Teams plugin archives, including its reviewed proxy dependencies.Type of Change
Quality Gates
DGX Station Hardware Evidence
Verification
npm run check:diffpassed when hooks were skipped or unavailable223aea520; required CI is also runningnpm run docsbuilds without warnings (doc changes only) — 0 errors; 2 pre-existing warningsAdditional evidence:
22.22.2reviewed npm audit:info=0 low=1 moderate=1 high=0 critical=0; configuredhighthreshold passes.info=0 low=0 moderate=0 high=0 critical=0.openclaw@2026.6.10and@openclaw/fs-safe@0.3.0, with installedtar@7.5.19andbrace-expansion@5.0.7.Signed-off-by: Julie Yaunches jyaunches@nvidia.com
Summary by CodeRabbit
Bug Fixes
Documentation
Tests