v0.0.109
NemoClaw v0.0.109 adds credential-free launch-readiness leases, an editable onboarding review, a distinct OpenAI-compatible API port for each Hermes sandbox, and selectable Hermes WhatsApp reply modes. It also adds a Deferred N1x Express preview for one-host managed vLLM while N1x remains outside the supported-platform set. It improves inference health reporting, local inference discovery, onboarding recovery, sandbox startup, messaging status, and uninstall behavior. It also strengthens managed images, Deep Agents Code login probes, Shields transitions, gateway lifecycle authority, and release qualification.
- On Linux,
nemoclaw launch <sandbox>can reuse a credential-free launch-readiness lease with a fixed 24-hour lifetime after it validates the sandbox, policy, inference route, forwards, and agent health. For missing, expired, changed, or unavailable evidence, NemoClaw fences any prior acceptable evidence before it runs the complete preflight. If prior authority might remain and NemoClaw cannot durably rotate it,launchstops before preflight or recovery. On macOS,launchruns the complete preflight every time and does not publish a launch-readiness lease. Sandbox startup now waits for OpenShell readiness before process recovery, probe-only recovery starts a stopped container, and status reports stopped sandboxes without implying that their gateways are serving. For more information, refer to the NemoClaw CLI Commands Reference, Run Sandboxes, and Recover and Rebuild Sandboxes. Related changes: PR #8951, PR #8990, PR #8977, PR #8848, and PR #8895. - Interactive onboarding now lets operators apply the configuration, edit the inference provider or model, edit the sandbox name, or exit before provider registration.
Fresh sandbox registration now binds one lifecycle generation to the final
Readyidentity, while incomplete onboarding exits nonzero and keeps resumable state. Resumed and recreated sandboxes use their recorded dashboard ports, wait up to 1 minute for OpenShell’s exactsandbox is not readyhandoff, and start forwarding only after readiness succeeds. Onboarding now reports the failed GPU trust-gate check, preserves actionable recovery for portable and legacy states, and records standalone gateway authority for a non-default gateway port. When NemoClaw resolves the complete listener set for a gateway-port conflict, the diagnostic lists each listener by PID and by process name when available. Stop guidance targets only unverified listener PIDs. A conflict with only verified managed listeners uses port-scoped uninstall guidance. When the host gateway is down, recovery guidance now directs operators tonemoclaw onboardfor a NemoClaw-owned gateway or to the owning deployment andopenshell gateway select <gateway>for an externally managed gateway. For more information, refer to the OpenClaw Quickstart, Hermes Quickstart, Deep Agents Quickstart, and System Readiness. Related changes: PR #9013, PR #9020, PR #8983, PR #8992, PR #9065, PR #9064, PR #9052, PR #9074, PR #9086, PR #9095, PR #9089, PR #9117, PR #9096, PR #9037, PR #9151, and PR #9149. - Sandbox status and
startnow send one bounded inference request after the route responds, so rejected credentials reportunauthorizedinstead of route reachability alone. Ollama model switching waits for the selected model to load before recording its served context window, and local Ollama validation bypasses ambient host proxy variables. GPU discovery now findsnvidia-smion WSL and requires bounded CUDA evidence before accepting a plausible ARM64 GPU name that lacks trusted host identity. DGX Spark cluster discovery recognizes dual-controller QSFP topology, Ollama proxy credentials remain consistent across gateway ports, and Model Router shutdown verifies process convergence. For more information, refer to Verify the Inference Route, Use Ollama, and Troubleshooting. Related changes: PR #8731, PR #8988, PR #9004, PR #9008, PR #8904, PR #8645, PR #8736, PR #8869, PR #8809, and PR #7663. - Model Router setup now requires 3 GiB of free or reclaimable storage before it creates the managed virtual environment.
The validated routed credential owns
OPENAI_API_KEYfor the shipped NVIDIA pool, and startup failures can include redacted diagnostics from~/.nemoclaw/state/model-router.log. Inference health now accepts a content reply with an emptytool_callslist, Local Ollama onboarding requires version 0.32.9 or newer, and stopping an Ollama-backed sandbox requests immediate model unload. For more information, refer to Set Up Model Router, Understand Provider Validation, and Use Ollama. Related changes: PR #8972, PR #9002, PR #9124, PR #9113, and PR #9157. - OpenClaw agent commands now suppress NemoClaw-owned
UNDICI-EHPAand empty plugin-allowlist warnings while preserving other warnings and agent standard error.Ctrl+CandSIGTERMnow stop in-sandbox work and return signal-derived status, and a timed-out turn returns failure instead of accepting an incomplete success envelope. Repeated launches can reuse a still-qualified pairing observation, while ambiguous--timeoutarguments leave the OpenShell wait unbounded instead of applying an inferred deadline. For more information, refer to the NemoClaw CLI Commands Reference and Configure Inference Timeouts. Related changes: PR #9021, PR #9036, PR #9034, PR #9056, and PR #9075. - On macOS, the official Homebrew formula remains the gateway lifecycle authority through a checksum-verified, formula-scoped temporary trust boundary.
Installation uses a standalone gateway only when Homebrew and its OpenShell formula or keg cannot retain authority, and a known unavailable
systemduser manager follows a similarly bounded fallback on Linux. Onboarding abort now stops and deletes a NemoClaw-managed gateway when no retained lifecycle authority owns it, reports incompatible gateway database recovery without discarding state, preserves a requested sandbox name during resume, and prints portable recovery commands instead of an unsupported--resumehint. Portable onboarding avoids overlapping Personal-tier presets and preserves an explicitNEMOCLAW_POLICY_PRESETSselection, whilenemoclaw host probedistinguishes remediable Docker storage from an unresolvable host failure. For more information, refer to Gateway Lifecycle Authority, System Readiness, and Network Policies Reference. Related changes: PR #7739, PR #8949, PR #8993, PR #8995, PR #8958, PR #8897, PR #8994, PR #9003, PR #8922, and PR #8867. - Each Hermes sandbox now receives its own recorded OpenAI-compatible API port, including forward recovery and snapshot-clone restoration.
Hermes WhatsApp setup lets the operator select
self-chatorbotreply behavior, and status checks use the configured durable session path.channels statusagain accepts documented calls without--wait, and the Hermes forward watcher now reports bounded redacted diagnostics without stopping a forward that it does not own. Hermes can also install its pinned Hindsight client into durable sandbox-owned state with the opt-inlocal-memorynetwork policy. Hermes preserves the exact bounded OpenShell credential placeholder generation when it refreshes the managed.envfile. Hindsight lazy installation now uses bundledpipin the Hermes virtual environment and validates the managed certificate-bundle link before sandbox permission checks. Managed MCP mutations recover the allocated API port from an exact managed relay and ignore unrelated service-manager children without weakening identity checks. Native Docker GPU onboarding now keeps the restart-safe Hermes startup command, while rebuild restores cron state for every generated drain-token value and preserves exact managed GPU fallback evidence while the rollback backup is retained. For more information, refer to the Hermes Quickstart, Set Up WhatsApp, and Install Hermes Plugins. Related changes: PR #8577, PR #8423, PR #8727, PR #8900, PR #8956, PR #8844, PR #8913, PR #9059, PR #9094, PR #9097, PR #9122, PR #9147, PR #9148, PR #9150, and PR #9162. - Fresh and resumed onboarding now removes a host-configured messaging channel’s stale network policy preset after the operator removes that channel’s configuration. NemoClaw preserves the policy presets for in-sandbox QR-paired channels because the host environment cannot determine their pairing state. For more information, refer to Network Policies. Related change: PR #9139.
- Backup credential scanning now excludes dependency trees while retaining scans of user and runtime state.
An equivalent repeated
shields downrequest succeeds only with matching live auto-restore authority, and an unsafe Hermes configuration path leaves Shields up or restores the restrictive policy. Seven policy presets now match the installed Python interpreter without retaining a nonexistentpython3.11path. Policy explanations now identify presets enforced by an agent base policy asagent-base, report them as active, and omit unnecessarypolicy addsuggestions. For more information, refer to Create and Restore Snapshots, Understand Runtime Changes, Create Custom Policy Presets, and Explain Network Policy to Agents. Related changes: PR #8807, PR #8821, PR #8830, PR #8960, and PR #9082. - Managed Deep Agents Code images now protect the root-owned login profile used by managed probes and reject a reusable base image without executable
dos2unix. Managed OpenClaw, Hermes, and Deep Agents Code images include checksum-pinned Vim fixes and the NemoClaw libssh2 revision containing two reviewed public-key fixes. For more information, refer to Run LangChain Deep Agents Code, Process Controls, and Trusted Computing Base. Related changes: PR #8670, PR #8937, PR #8940, PR #8941, PR #8959, and PR #9025. - A failed snapshot clone now reports that the destination remains unregistered and prints the owning gateway’s cleanup command.
destroynow refuses an ambiguous sandbox name before container deletion, and full uninstall removes an exactly labeled orphaned managed vLLM container. Uninstall preserves an unrecorded gateway process owned by another non-root user and continues the remaining cleanup instead of treating the permission denial as a failure. For more information, refer to Create and Restore Snapshots, Uninstall NemoClaw, and the NemoClaw CLI Commands Reference. Related changes: PR #9024, PR #9032, PR #9005, and PR #9042. nemoclaw uninstall --delete-modelsnow removes every model in the validated loopback Ollama inventory and non-credential Hugging Face cache data after managed runtimes stop. The operation preserves authentication files and model stores used by sibling gateways, returns nonzero when inventory or deletion fails, and limits broad Docker cleanup to parsed owned container and image fields. Selected-port uninstall also highlights retained sibling gateway environments and their cleanup commands. For more information, refer to Uninstall NemoClaw. Related changes: PR #8919, PR #8976, and PR #8876.- The hosted installer now preserves status
130when onboarding is interrupted, admits the explicit experimental portable profile without bypassing unrelated readiness failures, and can authorize NVIDIA CDI repair through passwordlesssudo. Portable execution uses the numeric user ID, and manual OpenShell upgrade recovery preserves the selected non-default gateway port. On qualified N1x FASTOS hosts, the Deferred preview offers one-host managed vLLM withnvidia/Qwen3.6-35B-A3B-NVFP4; N1x remains outside the supported-platform set until physical NemoClaw Express E2E validation passes. For more information, refer to Platform Support, System Readiness, and the NemoClaw CLI Commands Reference. Related changes: PR #9010, PR #9033, PR #9011, PR #9071, PR #8938, PR #9152, and PR #8903. - Contributor tooling now uses Oxlint and Oxfmt, enforces LF checkout for tracked text files, and reports the required Node.js heap limit when setup type checks exhaust memory. Issue-planning and implementation skills now support configured GitHub access, while stale-issue verification adds stricter reproduction, evidence, and cost controls. GitHub Actions dependencies also include the reviewed CodeQL Action and path-filter updates. Related changes: PR #8930, PR #8657, PR #8865, PR #8968, PR #8838, PR #8309, PR #8933, and PR #8934.
- Release engineering now derives relevant main-push and full release qualification jobs from one runner-aware end-to-end (E2E) target catalogue and renders the selected execution plan. The workflow keeps exact candidate and risk-signal identities, runs the Jetson GPU proof on main pushes, and adds coverage for interactive policy ordering, Hermes routing, image contracts, WSL connection behavior, and state-lock recovery. Full manual release qualification can use an administrator-authorized job waiver whose requested jobs, reason, actor identities, candidate commit, and completed outcomes remain bound in the workflow evidence. Trusted manual dispatches preserve profile credentials only after repository, event, ref, workflow, and checkout identity validation, while copied workflows and forks receive empty credentials. CI corrections restore the affected workflow, source-architecture, timeout, and abort-cleanup checks without changing the shipped runtime contracts. PR #7853 preserves contributor history through a no-diff merge after PR #8859 supplied the messaging credential-drift implementation, so it adds no separate release behavior. Related changes: PR #7853, PR #8618, PR #8896, PR #8902, PR #8912, PR #8915, PR #8946, PR #8948, PR #8950, PR #8954, PR #8957, PR #8961, PR #8963, PR #8966, PR #8984, PR #8986, PR #8989, PR #8997, PR #9001, PR #9016, PR #9027, PR #9040, PR #9063, PR #9078, PR #9080, and PR #9101.