Skip to content

Legacy upgrade leaves healthy patched container with sandbox stuck Deleting #9531

Description

@rsliter

Summary

The v0.0.89 x86-64 upgrade E2E rebuilt a healthy patched container, but the OpenShell sandbox remained in Deleting until the 900-second final handoff deadline expired. The installer then failed recovery and preserved the backup.

This is a product or integration regression with an intermittent trigger, not a flaky assertion. The same exact job passed in four recent full E2E runs.

Current evidence

The final handoff diagnostic reported:

OpenShell supervisor did not reach Ready (last phase: Deleting).
sandbox_phase=Deleting
patched_container_status=running
patched_container_running=true
patched_container_exit_code=0
patched_container_health=healthy

The installer waited the full 900-second handoff budget, failed recovery, retained the registry entry and backup, and exited 1. No retry ran.

Recurrence evidence

The same exact job passed recently:

Closed #4664 and #5662 cover earlier GPU-patch handoff failures where a healthy container and OpenShell phase diverged. This occurrence is distinct because the sandbox remained in Deleting during a legacy-upgrade recovery path.

Required behavior

  1. Determine whether NemoClaw's container handoff or the OpenShell state machine owns the persistent Deleting phase.
  2. If OpenShell owns it, attach sanitized upstream evidence and record the upstream issue here.
  3. A healthy patched container must not remain indefinitely detached from the sandbox lifecycle record.
  4. Recovery must either converge to the same ready sandbox identity or fail with the preserved backup and a stable ownership diagnostic.
  5. Add deterministic coverage at the smallest lifecycle-state boundary for a healthy container paired with a persistent Deleting sandbox phase.
  6. Keep the live E2E assertion on restored survivor state and lifecycle readiness.

Non-goals

  • Increasing the 900-second timeout without evidence.
  • Retrying the complete workflow or upgrade mutation.
  • Treating a healthy Docker container as success while OpenShell remains non-ready.
  • Adding another live E2E target.

Release signal

Classification: product or integration regression with an intermittent trigger. It is terminal for the candidate and recovered zero times.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

area: installInstall, setup, prerequisites, or uninstall flowarea: sandboxOpenShell sandbox lifecycle, runtime, config, or recoveryintegration: openclawOpenClaw integration behavior

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions