v0.0.97
NemoClaw v0.0.97 adds read-only host readiness reporting, a Deferred automatic two-Station vLLM evaluation, compatible-endpoint reasoning effort controls, and an experimental runtime identity reference for direct OpenClaw blueprints. It also hardens compatible-provider switching, managed sandbox images, Jetson GPU access, lifecycle recovery, network policy guidance, MCP discovery, and release E2E evidence.
nemoclaw host probenow produces a schema-versioned readiness report without changing host, Docker, gateway, provider, policy, credential, or sandbox state. Human-readable and JSON output share the same redacted evidence, stable capability and finding IDs, deterministic exit codes, and fail-closed Linux, macOS, WSL, DGX Spark, and DGX Station qualification. For more information, refer to System Readiness and the NemoClaw CLI Commands Reference.- DGX Station Express can now select and prepare one pretrusted two-Station GB300 pair for distributed Nemotron Ultra when reciprocal Station identity, GPU, SSH, route, neighbor, rail, and jumbo-frame checks pass. The installer records durable controller and pair ownership, stops for manual reboots, resumes from owner-only receipts, and cleans up the recorded pair during full uninstall. If no trusted pair qualifies, automatic selection keeps the single-Station Ultra path, while an explicitly selected peer must qualify. The two-Station path remains a Deferred evaluation and does not change single-Station support status. For more information, refer to Prepare DGX Station to Install NemoClaw and Set Up vLLM.
- The direct OpenClaw blueprint runner now has an experimental, explicit opt-in provider-neutral runtime identity component with a bundled data-only Okta reference profile. The runner validates the complete profile and DNS destinations before mutation, keeps refresh material out of plans and command arguments, records resource ownership as it applies changes, and uses those receipts for compensation and rollback. The shipped blueprint and normal onboarding do not enable this component, custom Okta domains are outside the reviewed policy, and this release does not add Entra, OBO, OAuth bootstrap, production middleware, or real-tenant certification. For more information, refer to Architecture Details.
- OpenClaw-compatible endpoints can now set
NEMOCLAW_REASONING_EFFORTor passinference set --reasoning-effortwithlow,medium,high, ordefaultonopenai-completionsroutes. NemoClaw validates the value, provider, and API before mutation, records the effective state for diagnostics, preserves it through resume, rebuild, and restart, and clears it when the resulting route no longer supports the setting. For more information, refer to Configure Model Capabilities, Set Up an OpenAI-Compatible Endpoint, and the NemoClaw CLI Commands Reference. - Compatible-provider switching now creates and verifies an absent direct provider before route selection and removes that provider if selection fails.
An existing direct provider is reused only when its recorded endpoint and credential environment exactly match the request; NemoClaw refuses an endpoint replacement that OpenShell cannot expose safely enough to roll back.
Host-side
config setalso accepts the exacthttp://host.openshell.internal:<unprivileged-port>shape only for supported providerbaseUrlfields, while generic keys and other private URL shapes remain rejected. Retired NVIDIA Build MiniMax and Qwen model paths are no longer offered. For more information, refer to Switch Inference Providers, Meet Custom Endpoint Security Requirements, and Set Up Ollama. - Docker-driver post-reboot recovery now waits for the labeled container to reach Docker readiness.
It restores the in-sandbox gateway and host forwards before reporting success, refreshes stale stopped-container evidence, and fails closed when delivery cannot be proven.
Recovery also unpauses a paused original container before reporting success.
Resumed onboarding writes a secret-free same-name recreation journal before deletion so an interrupted run can continue or fail closed on ambiguous identity.
Uninstall checks for the
openshellcommand after confirmation and before cleanup mutation, while source-checkout installation preserves an absoluteNEMOCLAW_OPENSHELL_BINselection during user-local OpenShell discovery. For more information, refer to Recover and Rebuild Sandboxes and Uninstall NemoClaw. - Jetson setup now explains why host preparation was skipped when it encounters an unrecognized or unparseable release. GPU onboarding carries eligible numeric group IDs for real, non-symlink DRI render character devices into the recreated container while preserving the established Tegra device allowlist. The sandbox CUDA proof remains fail-closed, and physical IGX Orin validation of the reported configuration remains pending. For more information, refer to the NemoClaw CLI Commands Reference and Troubleshooting.
- Telegram channel status now returns
unreachablewith a nonzero exit when the Bot API startup probe receives a definitive HTTP error. Managed MCP tool discovery accepts compliant case-variant or parameterized SSE media types through the reviewed SDK runtime. Hermes image assembly normalizes executable modes before metadata validation, and locked restart integrity accepts the generated v1 managed MCP state record while retaining fail-closed hashing and failed-reload rollback. Hermes now keeps gateway PID, lock, and status records in the writable runtime directory. This lets a restart replace the tracked gateway while shields are up without weakening config locks or crash quarantine. For more information, refer to Choose Messaging Channels, Manage MCP Servers with OpenClaw, Manage MCP Servers with Hermes, and the NemoClaw CLI Commands Reference. - Deep Agents now publishes the bounded approval, baseline, preset, custom-preset, and live-policy tasks that apply to its maintained runtime.
The
claude-codepreset permits browser login only throughGETandPOSTonplatform.claude.com/v1/oauth/**, without widening unrelated Anthropic or telemetry access. For more information, refer to Approve or Deny Network Requests, Apply Policy Presets, and Security Best Practices. - Every managed OpenClaw, Hermes, and Deep Agents Code base image now installs checksum-bound backports for four libssh2 memory-safety fixes and the Python 3.13
HTMLParserincremental-input complexity fix. Image builds verify immutable source and package identities, libssh2 compatibility and upstream tests, Python file identity and behavior, final package inventories, and clean package-manager state on amd64 and arm64. For more information, refer to Architecture Details. - Pre-tag release validation now derives its exact candidate test ledger from the candidate commit’s E2E workflow, accumulates attempt-aware green evidence in parallel, and keeps every missing execution visible for an itemized maintainer decision. A one-off exact-SHA Launchable qualification can contribute evidence without replacing the default suite, while phase-specific E2E diagnostics, consolidated journeys, checksum-verified official Node.js 22.23.1 archives for WSL, and stricter workflow boundaries improve failure attribution.