Skip to content

docs: recover v0.0.101 changelog entry - #8160

Merged
senthilr-nv merged 13 commits into
mainfrom
codex/docs-v0.0.101-post-release-recovery
Aug 4, 2026
Merged

docs: recover v0.0.101 changelog entry#8160
senthilr-nv merged 13 commits into
mainfrom
codex/docs-v0.0.101-post-release-recovery

Conversation

@apurvvkumaria

@apurvvkumaria apurvvkumaria commented Aug 3, 2026

Copy link
Copy Markdown
Collaborator

Summary

Adds the canonical dated v0.0.101 changelog entry that was missing when the release tag was cut. This post-release recovery records the shipped behavior on current main without changing or replacing the existing tag.

Changes

  • Add docs/changelog/2026-08-03.mdx with the exact ## v0.0.101 heading, release summary, detailed behavior changes, support boundaries, and links to durable documentation.
  • #7317 -> docs/changelog/2026-08-03.mdx: Records experimental OpenClaw Google Chat support and its restricted credential and webhook boundary.
  • #7715 -> docs/changelog/2026-08-03.mdx: Records strict onboarding recovery state and authoritative resume identity.
  • #7749 -> docs/changelog/2026-08-03.mdx: Records the provider-neutral policy seam and unchanged runtime support boundary.
  • #7817 -> docs/changelog/2026-08-03.mdx: Records preserved Hermes home-channel assignments across rebuilds.
  • #7820 -> docs/changelog/2026-08-03.mdx: Records the SSH-session status field correction.
  • #7847 -> docs/changelog/2026-08-03.mdx: Records fail-closed credential filtering for migration and rebuild backups.
  • #7870 -> docs/changelog/2026-08-03.mdx: Records sandbox-qualified in-sandbox host command hints.
  • #7875 -> docs/changelog/2026-08-03.mdx: Records Microsoft Teams stop and start E2E coverage.
  • #7885 -> docs/changelog/2026-08-03.mdx: Records Hermes managed gateway detection in status.
  • #7889 -> docs/changelog/2026-08-03.mdx: Records policy-authenticated HTTPS Pin Runtime route revocation.
  • #7891 -> docs/changelog/2026-08-03.mdx: Records default fallback for negative timeout and polling overrides.
  • #7993 -> docs/changelog/2026-08-03.mdx: Records correct sibling detection during uninstall.
  • #7995 -> docs/changelog/2026-08-03.mdx: Records absent configuration-hash handling before shields lock.
  • #8001 -> docs/changelog/2026-08-03.mdx: Records the dormant atomic managed workload replacement foundation.
  • #8029 -> docs/changelog/2026-08-03.mdx: Records repository terminology review in PR Review Advisor.
  • #8031 -> docs/changelog/2026-08-03.mdx: Records provider-neutral managed snapshot authority.
  • #8032 -> docs/changelog/2026-08-03.mdx: Records immutable managed clone handoff contracts.
  • #8034 -> docs/changelog/2026-08-03.mdx: Records the dormant provider-owned clone transaction surface.
  • #8035 -> docs/changelog/2026-08-03.mdx: Records the dormant Hermes managed clone broker boundary.
  • #8036 -> docs/changelog/2026-08-03.mdx: Records the dormant transactional managed bootstrap boundary.
  • #8037 -> docs/changelog/2026-08-03.mdx: Records dormant Docker bootstrap primitives and the unchanged provider support boundary.
  • #8070 -> docs/changelog/2026-08-03.mdx: Records consolidated sandbox resource-limit E2E coverage.
  • #8071 -> docs/changelog/2026-08-03.mdx: Records escaped and bounded CLI validation diagnostics.
  • #8081 -> docs/changelog/2026-08-03.mdx: Records bounded linear snapshot Base64 validation.
  • #8085 -> docs/changelog/2026-08-03.mdx: Records commit-bound workflow approval for eligible same-repository maintainers.
  • #8088 -> docs/changelog/2026-08-03.mdx: Records Hermes managed-policy E2E selection.
  • #8090 -> docs/changelog/2026-08-03.mdx: Records pinned CI search-tool provisioning.
  • #8106 -> docs/changelog/2026-08-03.mdx: Records fallback from failed managed OpenShell gateway startup.
  • #8107 -> docs/changelog/2026-08-03.mdx: Records Hermes adapter lifecycle E2E selection.
  • #8128 -> docs/changelog/2026-08-03.mdx: Records the dormant transactional Docker bootstrap adapter and rollback authority.
  • #8140 -> docs/changelog/2026-08-03.mdx: Records Slack conflict scope across independent OpenShell gateways.
  • #8147 -> docs/changelog/2026-08-03.mdx: Records completion of durable v0.0.100 documentation audit follow-ups.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification: This documentation-only recovery does not change executable behavior.
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification:
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification:
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: docs-updated
  • Evidence: Independently reviewed docs/changelog/2026-08-03.mdx at commit 0bebe1f568e3dc85cf410aac1dfb8f8830070b85. Its blob is 82887920f9720eafd75db6b2271c35f7477edb9b. The entry follows the writing guide, controlled terminology, changelog structure, MDX SPDX format, literal CLI-name rule, and root-absolute route requirements. It accurately records the v0.0.100...v0.0.101 release range, Announcement NemoClaw v0.0.101 is out! #8162, accepted scope boundaries, and shipped security behavior. There are no code samples. Focused changelog tests and the documentation build pass for this commit.
  • Agent: Codex Desktop independent documentation writer

Security Review

  • Result: PASS
  • Reviewed commit: 0bebe1f568e3dc85cf410aac1dfb8f8830070b85
  • Base commit: 643a4ab8b5f583d8555192a37927268b26022c51
  • Findings: None.
  • Secrets and credentials: PASS. No credential values or secret files are present.
  • Input validation and data sanitization: PASS. No executable input path changes.
  • Authentication and authorization: PASS. No identity or permission logic changes.
  • Dependencies and third-party libraries: PASS. No dependency changes.
  • Error handling and logging: PASS. No runtime path changes; diagnostic-security claims are precise.
  • Cryptography and data protection: PASS. No implementation changes.
  • Configuration and security controls: PASS. No configuration, container, port, or HTTP changes.
  • Security testing: PASS. No coverage is removed; the entry records shipped test and security behavior.
  • System security: PASS. No runtime control changes; dormant and non-activation boundaries are explicit.
  • Agent: Codex Desktop independent security reviewer

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub — verification is pending after commit 0bebe1f568e3dc85cf410aac1dfb8f8830070b85 is pushed.
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run validate:pr passed after refreshing origin/main when hooks were skipped or unavailable — commit hooks passed; pre-push is pending.
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — tests are not applicable to this documentation-only recovery.
  • Applicable broad gate passed — not applicable to this documentation-only recovery.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, credentials, or private keys are added by this diff.
  • npm run docs builds without warnings (doc changes only) — GitHub documentation checks are pending.
  • Doc pages follow the style guide (doc changes only) — independent documentation review passed.
  • New doc pages include SPDX header and frontmatter (new pages only) — the native changelog entry uses the required parser-safe MDX SPDX comment and intentionally has no frontmatter.

GitHub CI is authoritative.
Focused changelog tests and npm run docs passed after the merge refresh.


Signed-off-by: Apurv Kumaria akumaria@nvidia.com

Summary by CodeRabbit

  • New Features

    • Added experimental Google Chat support.
    • Improved runtime and session status visibility.
    • Added onboarding recovery and persistence safeguards.
    • Added snapshot validation and dormant managed-workload support.
  • Bug Fixes

    • Improved backup sanitization, route handling, and gateway reliability.
  • Documentation

    • Added the v0.0.101 changelog and related updates.
  • Tests

    • Expanded end-to-end coverage and strengthened trusted CI validation.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
@apurvvkumaria apurvvkumaria added area: docs Documentation, examples, guides, or docs build v0.0.102 labels Aug 3, 2026
@apurvvkumaria apurvvkumaria self-assigned this Aug 3, 2026
@coderabbitai

coderabbitai Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The PR adds the v0.0.101 changelog. It records changes to integrations, runtime behavior, recovery, persistence, validation, CI, E2E coverage, and documentation.

Changes

Release documentation

Layer / File(s) Summary
v0.0.101 release entry
docs/changelog/2026-08-03.mdx
Adds release notes for Google Chat support, runtime and session handling, recovery safeguards, persistence, sanitization, workload contracts, CI, E2E coverage, and documentation.

Estimated code review effort: 1 (Trivial) | ~5 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the recovery of the missing v0.0.101 changelog entry.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch codex/docs-v0.0.101-post-release-recovery

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

PR Review Advisor — No blocking findings reported

Advisor assessment: No blocking advisor findings reported
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions

Model lanes

  • GPT-5.6 Terra (primary): Completed · high confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Failed after a partial review · low confidence · 0 blockers · 0 warnings · 0 suggestions

Second-opinion terminology and E2E selections are advisory. They do not change the primary assessment or E2E / PR Gate.

4 semantic terminology decisions

Terminology decisions are advisory. They affect the assessment only when a separate finding identifies concrete semantic impact.

  • define — restricted webhook endpoint at docs/changelog/2026-08-03.mdx:11: If this term recurs outside this changelog, define the restriction and the traffic it permits at first use.
  • define — authoritative sandbox identity at docs/changelog/2026-08-03.mdx:22: If this term recurs outside this changelog, identify the record that supplies the authoritative identity at first use.
  • define — provider-neutral policy seam at docs/changelog/2026-08-03.mdx:34: If this term recurs outside this changelog, define the seam and its provider-neutral boundary at first use.
  • define — managed workload replacement at docs/changelog/2026-08-03.mdx:36: If this term recurs outside this changelog, state the current consumer and support boundary at first use.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: None

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
@apurvvkumaria
apurvvkumaria enabled auto-merge (squash) August 3, 2026 19:57

@cv cv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Documentation writer review: changes requested for commit 529c299a8.

I reviewed the entry against the signed v0.0.100...v0.0.101 range, Announcement #8162, merged PR metadata, checked-in source and behavior tests, the writing rules, documentation style, the skip list, and published routes. The current entry has blocking release-meaning and link-applicability errors. Do not merge this commit.

Required corrections:

  1. Line 14 overstates text output. nemoclaw status reports the local SSH-session count; nemoclaw list --json includes activeSessionCount; text nemoclaw list marks an active session without printing the count. Use: “nemoclaw status now reports the number of local SSH sessions instead of presenting that count as a general connection signal. nemoclaw list --json reports each sandbox's activeSessionCount, while text output marks sandboxes that have an active session.” Keep the Hermes and command-hint sentence. Add the Hermes commands and Troubleshooting routes alongside the OpenClaw commands route. Evidence: src/lib/inventory/index.ts:347-355 and docs/reference/commands.mdx:840-844 at the release commit.

  2. Line 19 should link negative timeout fallback to /user-guide/openclaw/inference/manage-inference/configure-inference-timeouts, which owns that behavior, instead of the generic Troubleshooting page.

  3. Lines 24-25 describe an image lock, but Shields Up repairs an absent configuration-hash record and then locks Deep Agents Code configuration. Use: “NemoClaw can lock Deep Agents Code configuration when the sandbox image did not ship a configuration hash.” Put uninstall behavior in a separate sentence. Link the lock behavior to /user-guide/deepagents/reference/commands and uninstall to /user-guide/openclaw/manage-sandboxes/operate-sandboxes/uninstall-nemoclaw. Evidence: src/lib/shields/index.ts:1597-1604.

  4. Lines 26-27 promise that unsafe input cannot leave an incomplete backup. Cleanup failure can leave incomplete output, and NemoClaw must report that state. Keep the fail-closed statement and use: “NemoClaw deletes incomplete output when cleanup succeeds and reports when an incomplete backup remains.” Evidence: src/lib/state/sandbox-backup-sanitization.test.ts:101-115 and docs/manage-sandboxes/backup-restore.mdx:41-47.

  5. Lines 32-34 call all provider-neutral foundations dormant, but immutable managed snapshot authority already protects existing Docker snapshot and restore paths. Use: “Runtime orchestration now uses a provider-neutral policy seam. Provider-neutral authority now binds existing Docker snapshot and restore behavior to immutable runtime snapshots. Managed workload replacement, clone handoff, transactional bootstrap, and Docker rollback contracts remain dormant. These changes do not register Podman, activate buildless onboarding, or add a new supported runtime provider.” Remove the Architecture Details link because that page does not own these subjects. Evidence: src/lib/actions/sandbox/snapshot.ts:691-697,1055-1090.

  6. Add /user-guide/openclaw/reference/troubleshooting to lines 29-31 for the validation-diagnostic change from #8071.

  7. Preserve line 35's current commit-matching vocabulary. Split the bullet so each sentence has one subject: “Trusted CI approves a workflow run only when its recorded commit matches the current PR head for an eligible same-repository maintainer. It provisions pinned search tools before untrusted CLI tests run and reviews changed repository terminology. Live E2E selection now covers ...”

  8. Split the Slack clarification from #8147's durable documentation follow-up. Keep the Slack links with the first sentence. Link the follow-up to /user-guide/openclaw/inference/validate-inference/understand-provider-validation, /user-guide/openclaw/inference/validate-inference/verify-inference-route, and /user-guide/openclaw/manage-sandboxes/operate-sandboxes/recover-and-rebuild-sandboxes.

For clarity, replace “sandbox lifecycle safety” with a concrete behavior and use “recorded Hermes home-channel assignments.”

The existing passing documentation receipt is invalid because these blockers remain and it predates Announcement #8162. After correcting the entry, let GitHub CI rerun, repeat the independent documentation review for the new commit, and update both hidden receipt values. The current required aggregate check also fails because the docs workflow cannot resolve the pull-request merge base; that repository CI defect is being handled separately and must not be bypassed.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>

@cv cv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Documentation writer review: changes requested for commit be97cf2.\n\nThe prior review findings 1 through 7 are corrected. Three blocking writing and link issues remain.\n\n1. In the opening summary, replace “backup safety” with “backup handling.” Replace “Hermes messaging persistence” with “preservation of Hermes home-channel assignments during rebuilds.” These forms state the conditions behind each claim.\n2. For the Hermes home-channel rebuild behavior, replace the Manage Messaging Channels link with /user-guide/hermes/manage-sandboxes/messaging-channels/choose-messaging-channels. That page owns the behavior.\n3. Split the durable documentation follow-up from the Slack bullet. Make it a separate bullet, for example: “Documentation also adds durable guidance for inference-route timing, validation reuse boundaries, replacement-image cleanup, and recovery.” Keep the three existing follow-up links with that new bullet.\n\nThe hidden receipt values match this commit and the current AGENTS.md blob, but the visible docs-updated receipt is not valid while these findings remain. After the correction changes the commit, repeat the independent documentation review and refresh both hidden values.\n\nThe substantive GitHub CI and Fern validation passed for this commit.

Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
auto-merge was automatically disabled August 3, 2026 20:51

Pull Request is not mergeable

cv
cv previously requested changes Aug 3, 2026

@cv cv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Documentation review for commit SHA 5578d6b found one remaining blocking factual error in docs/changelog/2026-08-03.mdx. The validation-diagnostics bullet says rejected “sandbox and agent names,” but PR #8071 covers sandbox names, MCP server names, and persisted credential environment names; it does not add an agent-name callsite.

Please use: “CLI validation diagnostics now escape and bound rejected sandbox, MCP server, and credential environment names before writing them to terminals or CI logs.”

After the edit, refresh the documentation-writer receipt for the new commit SHA. The failed docs-only repository check and the pending E2E gate remain separate merge blockers.

apurvvkumaria and others added 6 commits August 3, 2026 14:12
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Signed-off-by: Carlos Villela <cvillela@nvidia.com>

@senthilr-nv senthilr-nv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed b697ff3. Product scope is established, recent review findings are addressed, and focused changelog and documentation checks pass. No blocking findings.

@senthilr-nv
senthilr-nv dismissed cv’s stale review August 4, 2026 06:28

Addressed in subsequent commits; refreshed documentation review and focused checks pass.

@senthilr-nv
senthilr-nv merged commit bc9501f into main Aug 4, 2026
68 of 70 checks passed
@senthilr-nv
senthilr-nv deleted the codex/docs-v0.0.101-post-release-recovery branch August 4, 2026 06:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: docs Documentation, examples, guides, or docs build

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants