Description
When nemoclaw {sandbox} snapshot create fails because a captured file is unreadable, the command exits non-zero with Snapshot failed. / Failed files: openclaw.json — but it does not clean up: the incomplete snapshot is left on disk AND registered as a listable snapshot (it appears in nemoclaw {sandbox} snapshot list as a normal versioned entry). Inconsistent fail-closed cleanup: the credential-sanitization-error path removes its incomplete backup, but the failed-files path leaves a listable, restorable, incomplete snapshot behind.
Impact: a later restore could pick up an incomplete snapshot that never completed successfully.
Platform scope: Reproduced on Ubuntu 24.04 x86_64 (A100), NemoClaw v0.0.101. Not believed platform-specific.
Regression: Unknown.
Environment
OS: Ubuntu 24.04.4 LTS Arch: x86_64 Docker: 29.6.0
OpenShell: 0.0.85 NemoClaw: v0.0.101 OpenClaw: 2026.7.1
Steps to Reproduce
- Onboard an OpenClaw sandbox
{sandbox}; confirm snapshot list is empty.
nemoclaw {sandbox} exec -- bash -lc 'chmod 000 /sandbox/.openclaw/openclaw.json'
nemoclaw {sandbox} snapshot create --name failtest (capture output + exit code)
nemoclaw {sandbox} snapshot list
Expected Result
The failed snapshot is cleaned up — incomplete staging dir removed, snapshot NOT registered/listed (consistent with the credential-sanitization-error path). snapshot list shows no new entry.
Actual Result
# Step 3 -> exit 1
Creating snapshot of '{sandbox}' (--name failtest)...
Snapshot failed.
Failed files: openclaw.json
# Step 4 -> the incomplete snapshot is listed as a valid versioned entry:
v1 failtest 2026-08-04T06-53-38-310Z /home/.../.nemoclaw/rebuild-ba...
The incomplete snapshot persists on disk and is listable (and restorable), with no cleanup or warning.
Description
When
nemoclaw {sandbox} snapshot createfails because a captured file is unreadable, the command exits non-zero withSnapshot failed. / Failed files: openclaw.json— but it does not clean up: the incomplete snapshot is left on disk AND registered as a listable snapshot (it appears innemoclaw {sandbox} snapshot listas a normal versioned entry). Inconsistent fail-closed cleanup: the credential-sanitization-error path removes its incomplete backup, but the failed-files path leaves a listable, restorable, incomplete snapshot behind.Impact: a later restore could pick up an incomplete snapshot that never completed successfully.
Platform scope: Reproduced on Ubuntu 24.04 x86_64 (A100), NemoClaw v0.0.101. Not believed platform-specific.
Regression: Unknown.
Environment
Steps to Reproduce
{sandbox}; confirmsnapshot listis empty.nemoclaw {sandbox} exec -- bash -lc 'chmod 000 /sandbox/.openclaw/openclaw.json'nemoclaw {sandbox} snapshot create --name failtest(capture output + exit code)nemoclaw {sandbox} snapshot listExpected Result
The failed snapshot is cleaned up — incomplete staging dir removed, snapshot NOT registered/listed (consistent with the credential-sanitization-error path).
snapshot listshows no new entry.Actual Result
The incomplete snapshot persists on disk and is listable (and restorable), with no cleanup or warning.