Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
32 commits
Select commit Hold shift + click to select a range
d84f839
fix(onboard): continue onboarding when Homebrew cannot confirm the Op…
harjothkhara Jul 28, 2026
8350421
docs(reference): document the standalone fallback for unconfirmed Hom…
harjothkhara Jul 28, 2026
cb9d771
fix(onboard): limit the Homebrew fallback to the pinned-tap load refusal
harjothkhara Jul 28, 2026
d37a028
fix(onboard): name the pinned-tap refusal precisely in the fallback w…
harjothkhara Jul 28, 2026
3b75153
fix(onboard): keep a loaded Homebrew launchd service fatal during tap…
harjothkhara Jul 28, 2026
ab87091
fix(onboard): fail closed when the launchd probe cannot answer
harjothkhara Jul 28, 2026
48d2974
fix(onboard): treat an unrecognized launchctl failure as an unknown u…
harjothkhara Jul 28, 2026
b832b25
merge(main): sync current main
apurvvkumaria Jul 28, 2026
9fe39c1
fix(onboard): recognize only missing launchd unit
apurvvkumaria Jul 28, 2026
d7b474c
merge(onboard): preserve launchd probe hardening
apurvvkumaria Jul 28, 2026
b7f5338
merge(main): sync current main
apurvvkumaria Jul 28, 2026
c182d79
merge(main): sync current main
apurvvkumaria Jul 28, 2026
717ecb2
merge(main): sync current main
apurvvkumaria Jul 29, 2026
249b9f7
merge(main): sync current main
apurvvkumaria Jul 29, 2026
bf489d7
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani Jul 29, 2026
cdbac77
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani Jul 29, 2026
26b3b0f
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani Jul 30, 2026
eb958ff
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cjagwani Jul 30, 2026
fcc6702
merge: sync Homebrew fallback with main
cjagwani Jul 30, 2026
46debbf
merge(main): refresh #7739 against current main
cv Aug 2, 2026
3f8825b
fix(onboard): harden Homebrew fallback diagnostics
cv Aug 2, 2026
1ced5be
merge(main): refresh #7739 against current main
cjagwani Aug 3, 2026
4c1c55b
merge(main): update #7739 to latest main
cjagwani Aug 3, 2026
829b9a3
test(onboard): convert complete CRLF fixtures
cjagwani Aug 3, 2026
7920f2a
docs(onboard): record Homebrew fallback retirement
cjagwani Aug 3, 2026
5307aa8
fix(onboard): fail closed on unknown brew list errors
apurvvkumaria Aug 3, 2026
76cb83c
merge(main): update #7739 to latest main
harjothkhara Aug 4, 2026
b4b590f
merge(main): refresh Homebrew fallback
apurvvkumaria Aug 4, 2026
181e1bf
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
cv Aug 4, 2026
7d258a6
Merge branch 'main' into fix/7707-homebrew-untrusted-tap
apurvvkumaria Aug 4, 2026
47218c5
merge(main): refresh #7739 against current main
harjothkhara Aug 6, 2026
f68e951
merge(main): refresh Homebrew fallback
apurvvkumaria Aug 6, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion ci/platform-matrix.json
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@
"status": "caveated",
"prd_priority": "P0",
"ci_tested": true,
"notes": "Start the container runtime (Colima or Docker Desktop) before running the installer. When Homebrew is available, OpenShell uses its official formula and the gateway appears in `brew services list` as `openshell`; without Homebrew, NemoClaw uses the standalone OpenShell install and detached gateway fallback. Homebrew Colima users must install both Colima and the Docker CLI (`brew install colima docker`) before `docker info` can work. Xcode Command Line Tools (`xcode-select --install`) are typically required for Node native modules during install. NemoClaw recommends them but does not enforce them during preflight."
"notes": "Start the container runtime (Colima or Docker Desktop) before running the installer. When Homebrew can load the pinned official OpenShell formula, the gateway appears in `brew services list` as `openshell`. When Homebrew 6.x returns the exact pinned-formula untrusted-tap refusal from `brew list` or `brew info`, NemoClaw checks the matching launchd unit with `launchctl print`. NemoClaw uses the detached standalone gateway fallback only when that command returns the exact missing-service result for `homebrew.mxcl.openshell`. Without Homebrew, NemoClaw uses the standalone OpenShell install and the same fallback. Homebrew Colima users must install both Colima and the Docker CLI (`brew install colima docker`) before `docker info` can work. Xcode Command Line Tools (`xcode-select --install`) are typically required for Node native modules during install. NemoClaw recommends but does not require them during preflight."
},
{
"name": "DGX OS (Spark)",
Expand Down
2 changes: 1 addition & 1 deletion docs/get-started/prerequisites.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -104,7 +104,7 @@ The table comes from [`ci/platform-matrix.json`](https://github.com/NVIDIA/NemoC
| DGX OS (Spark) | Docker | Tested | Use the standard installer and `$$nemoclaw onboard`. The automatic two-DGX Spark managed-vLLM profile is Experimental, and physical two-node end-to-end validation is pending. For the profile requirements and controls, see [Set Up vLLM on Two DGX Sparks](../inference/local-inference/set-up-vllm-on-two-dgx-sparks). For the validated single-DGX Spark walkthrough with local inference, see the [NVIDIA Spark playbook](https://build.nvidia.com/spark/nemoclaw). |
| DGX OS (Station) | Docker | Tested with limitations | Tested with limitations across qualified profiles on one physical DGX Station GB300; see [Additional Setup for DGX Station](additional-setup/dgx-station-preparation) for accepted profiles, the pending no-OTA DGX OS `7.6.x` end-to-end qualification, runtime gates, and current dual-Station and dedicated CI limitations. |
| Linux | Docker | Tested | Primary tested path. Ubuntu 24.04 has host-level onboarding validation. A digest-pinned Ubuntu 26.04 userspace lane builds the CLI and runs preflight, installer, and platform contracts on eligible main pushes; Docker-host, AppArmor, Landlock, and live onboarding validation on 26.04 remain pending. Other distros (Ubuntu 22.04, Fedora, Rocky, Alma, NixOS, Arch) may work but are not validated. |
| macOS (Apple Silicon) | Colima, Docker Desktop | Tested with limitations | Start the container runtime (Colima or Docker Desktop) before running the installer. When Homebrew is available, OpenShell uses its official formula and the gateway appears in `brew services list` as `openshell`; without Homebrew, NemoClaw uses the standalone OpenShell install and detached gateway fallback. Homebrew Colima users must install both Colima and the Docker CLI (`brew install colima docker`) before `docker info` can work. Xcode Command Line Tools (`xcode-select --install`) are typically required for Node native modules during install. NemoClaw recommends them but does not enforce them during preflight. |
| macOS (Apple Silicon) | Colima, Docker Desktop | Tested with limitations | Start the container runtime (Colima or Docker Desktop) before running the installer. When Homebrew can load the pinned official OpenShell formula, the gateway appears in `brew services list` as `openshell`. When Homebrew 6.x returns the exact pinned-formula untrusted-tap refusal from `brew list` or `brew info`, NemoClaw checks the matching launchd unit with `launchctl print`. NemoClaw uses the detached standalone gateway fallback only when that command returns the exact missing-service result for `homebrew.mxcl.openshell`. Without Homebrew, NemoClaw uses the standalone OpenShell install and the same fallback. Homebrew Colima users must install both Colima and the Docker CLI (`brew install colima docker`) before `docker info` can work. Xcode Command Line Tools (`xcode-select --install`) are typically required for Node native modules during install. NemoClaw recommends but does not require them during preflight. |
| Windows WSL2 | Docker Desktop (WSL backend) | Tested with limitations | Requires WSL2 with Docker Desktop backend. See [Additional Setup for Windows Machines](additional-setup/windows-preparation) before the Quickstart. |

For the complete platform support matrix, including all deferred platforms and CI coverage, refer to [Platform Support](../reference/platform-support).
Expand Down
6 changes: 6 additions & 0 deletions docs/reference/architecture.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,12 @@ On Apple Silicon macOS, Homebrew makes the official OpenShell formula authoritat
The installer stages the formula and onboarding starts its `openshell` service.
If the service fails inspection, startup, or its health check, NemoClaw prints the formula log command and attempts the standalone fallback.
A host without Homebrew, or with no installed OpenShell formula, also uses the standalone macOS gateway.
Homebrew 6.x can return a pinned-formula untrusted-tap refusal from `brew list --formula openshell` or `brew info --json=v2 openshell`.
Only the complete refusal for `nvidia/openshell/openshell` from `nvidia/openshell` can select the standalone macOS gateway fallback.
Before the fallback, `launchctl print` must return the exact missing-service result for `homebrew.mxcl.openshell`.
Onboarding prints the recognized diagnostic one time without repeating raw Homebrew output when both conditions match.
Every other `brew info` identity failure or unrecognized `launchctl` result stops onboarding.
Comment thread
apurvvkumaria marked this conversation as resolved.
A loaded `homebrew.mxcl.openshell` service remains under launchd lifecycle authority, so onboarding does not stop, replace, or adopt its process.
On both platforms, standalone startup requires exclusive ownership of the gateway port.
A positively untrusted upstream package service is declined as described above.
Trust failures in a marked NemoClaw service or Homebrew formula, and unsafe environment configuration, remain hard failures.
Expand Down
2 changes: 1 addition & 1 deletion docs/reference/platform-support.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ For install requirements and the shorter setup-oriented platform view, refer to
| DGX OS (Spark) | Docker | Tested | P1 | Yes | Use the standard installer and `$$nemoclaw onboard`. The automatic two-DGX Spark managed-vLLM profile is Experimental, and physical two-node end-to-end validation is pending. For the profile requirements and controls, see [Set Up vLLM on Two DGX Sparks](../inference/local-inference/set-up-vllm-on-two-dgx-sparks). For the validated single-DGX Spark walkthrough with local inference, see the [NVIDIA Spark playbook](https://build.nvidia.com/spark/nemoclaw). |
| DGX OS (Station) | Docker | Tested with limitations | P1 | No | The PRD marks this platform as P1. Physical validation on one DGX Station GB300 covers generic Ubuntu 24.04 ARM64, stock DGX OS `7.5.0`, the April 2026 NVIDIA Colossus BaseOS profile, and the June 2026 NVIDIA AI Developer Tools profile. A physical no-OTA DGX OS `7.6.0` host provided the release and hardware profile used for its stable workstation-family classifier and passed read-only eligibility and runtime-command preflight. Full Station Express end-to-end qualification for the accepted no-OTA DGX OS `7.6.x` profile is pending. The profile remains subject to the same physical GB300, driver, ECC, Docker, CDI, and container GPU validation. Clean-host end-to-end validation passed on generic Ubuntu and Colossus BaseOS; stock DGX OS and AI Developer Tools completed Station Express validation. The DGX OS `7.5.0` run used released OpenShell `0.0.85`, local Nemotron Ultra serving, sandbox `cuInit(0)`, and a Hermes write/read file-tool task. A dual-Station configuration has not been validated, and dedicated CI coverage is not available. Direct-GPU policies expose only the exact read-only BDF directory for each discovered display-class PCI device with NVIDIA vendor ID (`0x10de`) and GB300 device ID (`0x31c2` or `0x31c3`) plus required existing topology and module paths; they do not expose `/sys`, the PCI parent subtree, or sysfs write access. During physical validation, reads of `/sys/fs/cgroup/cgroup.controllers` and `/sys/class/net/lo/address` remained denied. For canonical hardware qualification, image requirements, preparation, repair limits, reboot handoff, and the explicit temporary metadata override, see [Prepare DGX Station to Install NemoClaw](../get-started/additional-setup/dgx-station-preparation). |
| Linux | Docker | Tested | P0 | Yes | Primary tested path. Ubuntu 24.04 has host-level onboarding validation. A digest-pinned Ubuntu 26.04 userspace lane builds the CLI and runs preflight, installer, and platform contracts on eligible main pushes; Docker-host, AppArmor, Landlock, and live onboarding validation on 26.04 remain pending. Other distros (Ubuntu 22.04, Fedora, Rocky, Alma, NixOS, Arch) may work but are not validated. |
| macOS (Apple Silicon) | Colima, Docker Desktop | Tested with limitations | P0 | Yes | Start the container runtime (Colima or Docker Desktop) before running the installer. When Homebrew is available, OpenShell uses its official formula and the gateway appears in `brew services list` as `openshell`; without Homebrew, NemoClaw uses the standalone OpenShell install and detached gateway fallback. Homebrew Colima users must install both Colima and the Docker CLI (`brew install colima docker`) before `docker info` can work. Xcode Command Line Tools (`xcode-select --install`) are typically required for Node native modules during install. NemoClaw recommends them but does not enforce them during preflight. |
| macOS (Apple Silicon) | Colima, Docker Desktop | Tested with limitations | P0 | Yes | Start the container runtime (Colima or Docker Desktop) before running the installer. When Homebrew can load the pinned official OpenShell formula, the gateway appears in `brew services list` as `openshell`. When Homebrew 6.x returns the exact pinned-formula untrusted-tap refusal from `brew list` or `brew info`, NemoClaw checks the matching launchd unit with `launchctl print`. NemoClaw uses the detached standalone gateway fallback only when that command returns the exact missing-service result for `homebrew.mxcl.openshell`. Without Homebrew, NemoClaw uses the standalone OpenShell install and the same fallback. Homebrew Colima users must install both Colima and the Docker CLI (`brew install colima docker`) before `docker info` can work. Xcode Command Line Tools (`xcode-select --install`) are typically required for Node native modules during install. NemoClaw recommends but does not require them during preflight. |
| NVIDIA RTX (consumer and Pro workstation GPUs) | Docker | Deferred | P1 | No | The PRD marks this platform as P1. Covers RTX consumer cards and RTX Pro workstation cards on Linux hosts that meet the generic-Linux-GPU requirements (NVIDIA Container Toolkit + CDI present). The provider menu emits managed vLLM behind `NEMOCLAW_EXPERIMENTAL=1` or `NEMOCLAW_PROVIDER=install-vllm` for this host class today; the end-to-end onboard path on this hardware is not yet validated in CI. |
| Windows WSL2 | Docker Desktop (WSL backend) | Tested with limitations | P1 | No | Requires WSL2 with Docker Desktop backend. |
{/* platform-matrix-full:end */}
Expand Down
5 changes: 5 additions & 0 deletions docs/reference/troubleshooting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -1055,6 +1055,11 @@ Follow these steps to reconnect.
```

During onboarding, NemoClaw uses the standalone fallback when the `openshell` formula is missing.
If `brew list --formula openshell` or `brew info --json=v2 openshell` returns the exact pinned-formula untrusted-tap refusal, onboarding prints the recognized diagnostic once without repeating raw Homebrew output.
It selects the standalone fallback only when `launchctl print` also returns the exact missing-service result for `homebrew.mxcl.openshell`.
Every other `brew info` identity failure or unrecognized `launchctl` result stops onboarding.
A loaded `homebrew.mxcl.openshell` service remains under launchd lifecycle authority.
NemoClaw does not stop, replace, or adopt that process, and the error provides the `launchctl bootout` remediation command.
If the installed service fails inspection, startup, or its health check, NemoClaw prints this log command:

```bash
Expand Down
2 changes: 1 addition & 1 deletion nemoclaw/src/security/credential-filter.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@ describe("plugin credential-filter", () => {
expect(isSafeCredentialPlaceholder("xoxb-OPENSHELL-RESOLVE-ENV-SLACK_TOKEN")).toBe(true);
expect(isSafeCredentialPlaceholder(null)).toBe(false);
expect(valueLooksLikeSecret("sk-abcdefghijklmnopqrstuvwxyz")).toBe(true);
expect(valueLooksLikeSecret("glpat-abcdefghijklmnopqrst")).toBe(true);
expect(valueLooksLikeSecret("glpat-abcdefghijklmnopqrst")).toBe(true); // gitleaks:allow -- credential-detector fixture
expect(valueLooksLikeSecret("nvcf-abcdefghij")).toBe(true);
expect(valueLooksLikeSecret("GITHUB_TOKEN=opaque-secret-value-123")).toBe(true);
expect(valueLooksLikeSecret("apiKey=opaque-secret-value-123")).toBe(true);
Expand Down
Loading