Summary
The v0.0.89 x86-64 upgrade E2E rebuilt a healthy patched container, but the OpenShell sandbox remained in Deleting until the 900-second final handoff deadline expired. The installer then failed recovery and preserved the backup.
This is a product or integration regression with an intermittent trigger, not a flaky assertion. The same exact job passed in four recent full E2E runs.
Current evidence
The final handoff diagnostic reported:
OpenShell supervisor did not reach Ready (last phase: Deleting).
sandbox_phase=Deleting
patched_container_status=running
patched_container_running=true
patched_container_exit_code=0
patched_container_health=healthy
The installer waited the full 900-second handoff budget, failed recovery, retained the registry entry and backup, and exited 1. No retry ran.
Recurrence evidence
The same exact job passed recently:
Closed #4664 and #5662 cover earlier GPU-patch handoff failures where a healthy container and OpenShell phase diverged. This occurrence is distinct because the sandbox remained in Deleting during a legacy-upgrade recovery path.
Required behavior
- Determine whether NemoClaw's container handoff or the OpenShell state machine owns the persistent
Deleting phase.
- If OpenShell owns it, attach sanitized upstream evidence and record the upstream issue here.
- A healthy patched container must not remain indefinitely detached from the sandbox lifecycle record.
- Recovery must either converge to the same ready sandbox identity or fail with the preserved backup and a stable ownership diagnostic.
- Add deterministic coverage at the smallest lifecycle-state boundary for a healthy container paired with a persistent
Deleting sandbox phase.
- Keep the live E2E assertion on restored survivor state and lifecycle readiness.
Non-goals
- Increasing the 900-second timeout without evidence.
- Retrying the complete workflow or upgrade mutation.
- Treating a healthy Docker container as success while OpenShell remains non-ready.
- Adding another live E2E target.
Release signal
Classification: product or integration regression with an intermittent trigger. It is terminal for the candidate and recovered zero times.
Summary
The v0.0.89 x86-64 upgrade E2E rebuilt a healthy patched container, but the OpenShell sandbox remained in
Deletinguntil the 900-second final handoff deadline expired. The installer then failed recovery and preserved the backup.This is a product or integration regression with an intermittent trigger, not a flaky assertion. The same exact job passed in four recent full E2E runs.
Current evidence
b2d1ce52a716444b083f6e3b8ed8bace1cba3240Upgrade: migrates v0.0.89 state on x86-64 / GitHub read tokenThe final handoff diagnostic reported:
The installer waited the full 900-second handoff budget, failed recovery, retained the registry entry and backup, and exited 1. No retry ran.
Recurrence evidence
The same exact job passed recently:
Closed #4664 and #5662 cover earlier GPU-patch handoff failures where a healthy container and OpenShell phase diverged. This occurrence is distinct because the sandbox remained in
Deletingduring a legacy-upgrade recovery path.Required behavior
Deletingphase.Deletingsandbox phase.Non-goals
Release signal
Classification: product or integration regression with an intermittent trigger. It is terminal for the candidate and recovered zero times.