Skip to content

[NemoClaw][All Platform][Policy&Network] Git clone works inside sandbox though user did not set policy #6502

Description

@zNeill

Description

Summary: NemoClaw appears to inject a github network policy+binary into the effective sandbox policy even when the user did not select any GitHub-related preset. The visible policy presets list also confirms github preset is not set.

Steps to reproduce:

  1. nemoclaw install
    1. Run: git clone https://github.com/NVIDIA/NemoClaw.git
    2. Run: cd NemoClaw
    3. Run: npm install
    4. Run: cd nemoclaw && npm install && npm run build && cd ..
    5. git checkout v0.0.75
    6. aerial@spark-6087:~/NemoClaw$ git status
      HEAD detached at v0.0.75
      nothing to commit, working tree clean
  2. nemoclaw onboard (do not select github preset)
  3. nemoclaw policy-list (verify github preset is not set)
  4. nemoclaw connect
  5. Inside Sandbox - git clone https://github.com/NVIDIA/NemoClaw.git
Expected behavior:
  • GitHub access should not be added unless explicitly selected by the user, or
  • git clone must fail - git reports "fatal: unable to access: 403"
Actual output:
aerial@spark-6087:~/NemoClaw$ nemoclaw test connect
  ✓ Connecting to sandbox 'test'
  Inside the sandbox, run `openclaw tui` to start chatting with the agent.
  Type `/exit` to leave the chat, then `exit` to return to the host shell.
  Note: this sandbox restricts outbound network access by policy.
  Blocked requests fail with 'CONNECT tunnel failed, response 403'.
  See which rule denied a request:  nemoclaw  logs --tail 50
sandbox@50fa59173c28:~$ git clone https://github.com/NVIDIA/NemoClaw.git
Cloning into 'NemoClaw'...
remote: Enumerating objects: 101853, done.
remote: Counting objects: 100% (1796/1796), done.
remote: Compressing objects: 100% (559/559), done.

sandbox@50fa59173c28:~$ exit
exit
aerial@spark-6087:~/NemoClaw$ nemoclaw test policy-list
  Policy presets for sandbox 'test':
    ● brave [from balanced tier] — Brave Search API access
    ● brew [from balanced tier] — Homebrew (Linuxbrew) package manager access (brew binary preinstalled in base image)
    ○ claude-code — Claude Code API, telemetry, and crash-report access
    ○ github — GitHub.com and GitHub API access (git)
    ● huggingface [from balanced tier] — Hugging Face Hub, LFS, and Inference API access
    ○ jira — Jira and Atlassian Cloud access
    ○ local-inference — Local inference access (Ollama, vLLM) via host gateway
    ○ nous-audio — Nous Portal managed audio generation and transcription gateway
    ○ nous-browser — Nous Portal managed browser automation gateway
    ○ nous-code — Nous Portal managed sandboxed code execution gateway
    ○ nous-image — Nous Portal managed image generation gateway
    ○ nous-web — Nous Portal managed web search and crawl gateway
    ● npm [from balanced tier] — npm and Yarn registry access
    ○ openclaw-diagnostics-otel-local — OpenClaw diagnostics OTLP/HTTP export to local host collector
    ● openclaw-pricing [user-added] — OpenClaw model-pricing reference fetch (LiteLLM + OpenRouter)
    ○ outlook — Microsoft Outlook and Graph API access
    ○ public-reference — Read-only structured public reference APIs
    ● pypi [from balanced tier] — Python Package Index (PyPI) access
    ○ tavily — Tavily web search API access (opt-in)
    ○ weather — Read-only public weather, geocoding, and alert APIs
    ○ telegram — Telegram Bot API access
    ○ discord — Discord API, gateway, and CDN access
    ○ wechat — WeChat (personal) iLink API access (OpenClaw + Hermes)
    ○ slack — Slack API, Socket Mode, and webhooks access
    ○ whatsapp — WhatsApp Web WebSocket and media access
    ○ teams — Microsoft Teams Bot Framework and Graph API access

Environment

  • NemoClaw v0.0.75
  • OpenShell 0.0.72
  • OpenClaw 2026.4.23
  • Node.js 22.22.2

Bug Details

Field Value
Priority Unprioritized
Action Dev - Open - To fix
Disposition Open issue
Module Machine Learning - NemoClaw
Keyword NemoClaw, NEMOCLAW_GH_SYNC_APPROVAL, NemoClaw_Policy&Network

[NVB#6425654]

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions