Skip to content

[Ubuntu 24.04][Sandbox] Failed snapshot (unreadable file) exits 1 'Snapshot failed' but still registers and lists the incomplete snapshot #8201

Description

@wangericnv

Description

When nemoclaw {sandbox} snapshot create fails because a captured file is unreadable, the command exits non-zero with Snapshot failed. / Failed files: openclaw.json — but it does not clean up: the incomplete snapshot is left on disk AND registered as a listable snapshot (it appears in nemoclaw {sandbox} snapshot list as a normal versioned entry). Inconsistent fail-closed cleanup: the credential-sanitization-error path removes its incomplete backup, but the failed-files path leaves a listable, restorable, incomplete snapshot behind.

Impact: a later restore could pick up an incomplete snapshot that never completed successfully.

Platform scope: Reproduced on Ubuntu 24.04 x86_64 (A100), NemoClaw v0.0.101. Not believed platform-specific.
Regression: Unknown.

Environment

OS: Ubuntu 24.04.4 LTS   Arch: x86_64   Docker: 29.6.0
OpenShell: 0.0.85   NemoClaw: v0.0.101   OpenClaw: 2026.7.1

Steps to Reproduce

  1. Onboard an OpenClaw sandbox {sandbox}; confirm snapshot list is empty.
  2. nemoclaw {sandbox} exec -- bash -lc 'chmod 000 /sandbox/.openclaw/openclaw.json'
  3. nemoclaw {sandbox} snapshot create --name failtest (capture output + exit code)
  4. nemoclaw {sandbox} snapshot list

Expected Result

The failed snapshot is cleaned up — incomplete staging dir removed, snapshot NOT registered/listed (consistent with the credential-sanitization-error path). snapshot list shows no new entry.

Actual Result

# Step 3 -> exit 1
Creating snapshot of '{sandbox}' (--name failtest)...
Snapshot failed.
Failed files: openclaw.json

# Step 4 -> the incomplete snapshot is listed as a valid versioned entry:
v1   failtest   2026-08-04T06-53-38-310Z   /home/.../.nemoclaw/rebuild-ba...

The incomplete snapshot persists on disk and is listable (and restorable), with no cleanup or warning.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

area: sandboxOpenShell sandbox lifecycle, runtime, config, or recovery

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions