Description
When upgrading NemoClaw in place from v0.0.55 to v0.0.81 (curl|bash), a pre-existing (legacy) sandbox is now recovered to Ready via the new legacy-recreate guard + pre-upgrade backup + restore. The earlier "stuck in Provisioning/Error" break is fixed (the sandbox comes up Ready and the agent runs). However the recovery is incomplete — it silently drops two kinds of pre-upgrade state:
-
The configured Slack messaging channel is LOST. After the upgrade, openclaw channels list reports "no configured chat channels" (before the upgrade it was "Slack default: enabled, configured, running, connected, health:healthy"). The sandbox's /sandbox/.openclaw/credentials directory is empty. Only the slack egress policy preset survives — the channel itself is gone, so messaging is broken until the user re-adds it.
-
Any user data stored OUTSIDE /sandbox/.openclaw is LOST. A file tree seeded at /sandbox/user-data (a marker plus a random blob) is absent from the recreated sandbox and is not present in the pre-upgrade backup (the backup captures only the .openclaw state: ~13 directories). So this data is unrecoverable — not even via a manual snapshot restore.
Net: the primary GH#6114 symptom (sandbox stuck / all data unreachable until manual rebuild) is fixed, but the legacy-recreate restore does not preserve messaging-channel config or non-.openclaw workspace files. A user upgrading in place silently loses their Slack channel and any files kept outside .openclaw.
Platform scope: Reproduced on Ubuntu 26.04 x86_64 (RTX PRO 6000). Root cause (the upgrade backup/restore scope only covers .openclaw state + egress policy presets) is platform-independent; other platforms (e.g. DGX Spark aarch64) are expected to be affected.
Regression: Not a classic regression — this is a residual gap of the v0.0.81 legacy-recreate recovery that fixed the GH#6114 stuck-Provisioning break; the recovery is incomplete on channel + non-.openclaw data.
Environment
Device: RTX PRO 6000 test host (x86_64)
OS: Ubuntu 26.04 LTS
Architecture: x86_64
NemoClaw: v0.0.55 -> v0.0.81 (curl|bash in-place upgrade)
OpenShell: 0.0.44 -> 0.0.72 (auto-upgrade during install)
OpenClaw: 2026.5.22 (v0.0.55 sandbox), recovered on v0.0.81
Docker: 29.5.3
GPU: NVIDIA RTX PRO 6000 Blackwell Server Edition, driver 595.71.05
Steps to Reproduce
- Install NemoClaw v0.0.55 clean (installer tag v0.0.55, non-interactive, third-party accepted, express skipped), then onboard an OpenClaw sandbox named
my-assistant on the nvidia-prod (build) provider. The provider credential is supplied via the standard NVIDIA API key env var; the provider is selected with the standard provider env var.
- Add a Slack messaging channel to the sandbox and rebuild. Export the Slack app token, bot token, and allowed-user id in the standard channel env vars, then run:
nemoclaw my-assistant channels add slack
nemoclaw my-assistant rebuild # NVIDIA API key exported in the env
Confirm: nemoclaw my-assistant exec -- openclaw channels status → "Slack default: enabled, configured, running, connected, health:healthy".
- Seed user data OUTSIDE
.openclaw and record integrity — write a marker file plus a random blob under /sandbox/user-data/ and note the blob's sha256:
nemoclaw my-assistant exec -- bash -lc 'mkdir -p /sandbox/user-data/notes;
echo MARKER > /sandbox/user-data/marker.txt;
head -c 20000 /dev/urandom | base64 > /sandbox/user-data/notes/blob.b64;
sha256sum /sandbox/user-data/notes/blob.b64'
- Upgrade in place to v0.0.81 with the real user command (installer tag v0.0.81, third-party accepted, non-interactive, experimental OpenShell upgrade accepted). The upgrade halts requiring explicit legacy-recreate confirmation, so re-run it with the confirmation env var
NEMOCLAW_CONFIRM_LEGACY_MANAGED_RECREATE set to ["my-assistant"] and the NVIDIA API key exported. The recovery then recreates and restores the sandbox.
- After the upgrade completes and the sandbox is Ready, check preservation:
nemoclaw my-assistant exec -- openclaw channels list
nemoclaw my-assistant exec -- find /sandbox/user-data -type f
ls ~/.nemoclaw/rebuild-backups/my-assistant/<timestamp>/
Expected Result
The legacy-recreate recovery restores the full pre-upgrade sandbox state — including any configured messaging channels (Slack) and all workspace/user files — so that after the in-place upgrade the Slack channel is still connected and the user's files are intact. An in-place upgrade must not silently drop a configured channel or user data; if some paths are intentionally not preserved, the CLI should warn and require confirmation before discarding them.
Actual Result
Sandbox recovers to Ready (stuck-Provisioning symptom fixed), .openclaw agent state is restored, and the agent runs (inference OK). But:
- openclaw channels list -> "no configured chat channels"
(pre-upgrade it was: "Slack default: enabled, configured, running, connected, healthy")
/sandbox/.openclaw/credentials is empty. Only the slack egress policy preset survived.
=> Slack messaging is broken after the upgrade; the channel must be re-added.
- find /sandbox/user-data -> (nothing; the directory is gone)
The seeded marker + blob (sha256 f1a75863...a16938) are absent from the recreated
sandbox AND absent from the pre-upgrade backup (backup contains only .openclaw state
dirs: agents, canvas, credentials, cron, ...).
=> non-.openclaw user data is silently lost and unrecoverable.
Logs
# Upgrade recovery (restore) log:
Found pre-upgrade backup for 'my-assistant'; it will be restored after recreation.
Restoring workspace state from pre-upgrade backup...
State restored (13 directories, 1 files)
Policy presets restored: slack, npm, pypi, huggingface, brew, openclaw-pricing
Deployment verified — gateway and dashboard are healthy.
OpenClaw is ready
Existing sandboxes were recovered and upgraded.
# Post-upgrade — Slack channel gone:
$ openclaw channels list
- no configured chat channels (run `openclaw channels list --all` to see installable channels)
$ ls /sandbox/.openclaw/credentials/ # -> empty
# Post-upgrade — non-.openclaw user data gone (live sandbox AND backup):
$ find /sandbox/user-data -type f # -> (nothing)
$ grep -rl UPGRADE-DATA-MARKER ~/.nemoclaw/rebuild-backups # -> (no match)
# backup dir top-level: agents canvas credentials cron devices extensions hooks identity ...
# Agent still works after upgrade:
$ openclaw agent --agent main -m "reply with exactly UPGRADE-SMOKE-OK" --json
UPGRADE-SMOKE-OK
# Fix direction: the legacy-recreate restore should also re-apply messaging-channel
# credentials/config (so channels survive the upgrade) and should back up + restore the
# full /sandbox workspace, not only .openclaw — or explicitly warn + confirm before
# discarding non-preserved paths.
Description
When upgrading NemoClaw in place from v0.0.55 to v0.0.81 (
curl|bash), a pre-existing (legacy) sandbox is now recovered to Ready via the new legacy-recreate guard + pre-upgrade backup + restore. The earlier "stuck in Provisioning/Error" break is fixed (the sandbox comes up Ready and the agent runs). However the recovery is incomplete — it silently drops two kinds of pre-upgrade state:The configured Slack messaging channel is LOST. After the upgrade,
openclaw channels listreports "no configured chat channels" (before the upgrade it was "Slack default: enabled, configured, running, connected, health:healthy"). The sandbox's/sandbox/.openclaw/credentialsdirectory is empty. Only the slack egress policy preset survives — the channel itself is gone, so messaging is broken until the user re-adds it.Any user data stored OUTSIDE
/sandbox/.openclawis LOST. A file tree seeded at/sandbox/user-data(a marker plus a random blob) is absent from the recreated sandbox and is not present in the pre-upgrade backup (the backup captures only the.openclawstate: ~13 directories). So this data is unrecoverable — not even via a manual snapshot restore.Net: the primary GH#6114 symptom (sandbox stuck / all data unreachable until manual rebuild) is fixed, but the legacy-recreate restore does not preserve messaging-channel config or non-
.openclawworkspace files. A user upgrading in place silently loses their Slack channel and any files kept outside.openclaw.Platform scope: Reproduced on Ubuntu 26.04 x86_64 (RTX PRO 6000). Root cause (the upgrade backup/restore scope only covers
.openclawstate + egress policy presets) is platform-independent; other platforms (e.g. DGX Spark aarch64) are expected to be affected.Regression: Not a classic regression — this is a residual gap of the v0.0.81 legacy-recreate recovery that fixed the GH#6114 stuck-Provisioning break; the recovery is incomplete on channel + non-
.openclawdata.Environment
Steps to Reproduce
my-assistanton the nvidia-prod (build) provider. The provider credential is supplied via the standard NVIDIA API key env var; the provider is selected with the standard provider env var.nemoclaw my-assistant channels add slack nemoclaw my-assistant rebuild # NVIDIA API key exported in the envnemoclaw my-assistant exec -- openclaw channels status→ "Slack default: enabled, configured, running, connected, health:healthy"..openclawand record integrity — write a marker file plus a random blob under/sandbox/user-data/and note the blob's sha256:NEMOCLAW_CONFIRM_LEGACY_MANAGED_RECREATEset to["my-assistant"]and the NVIDIA API key exported. The recovery then recreates and restores the sandbox.Expected Result
The legacy-recreate recovery restores the full pre-upgrade sandbox state — including any configured messaging channels (Slack) and all workspace/user files — so that after the in-place upgrade the Slack channel is still connected and the user's files are intact. An in-place upgrade must not silently drop a configured channel or user data; if some paths are intentionally not preserved, the CLI should warn and require confirmation before discarding them.
Actual Result
Sandbox recovers to Ready (stuck-Provisioning symptom fixed),
.openclawagent state is restored, and the agent runs (inference OK). But:Logs