feat(blueprint): add snapshot prune/delete commands for retention management - #5453
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughAdds strict snapshot validation, anchored symlink-safe deletion, retention pruning, and a ChangesSnapshot Retention Management
Estimated code review effort: 4 (Complex) | ~45 minutes Suggested labels: Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@nemoclaw/src/blueprint/snapshot.ts`:
- Around line 329-346: The pruneSnapshots function silently excludes snapshot
paths when deleteSnapshot returns false, leaving them out of both the deleted
and kept arrays, which hides failures from users. Add a failed array to track
snapshot paths where deleteSnapshot returns false, and include it in the
returned object alongside deleted and kept. This gives users visibility into
which specific snapshots failed to delete and why the counts might not add up to
the total.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: c471987d-87b6-4b91-bb33-a58a59186f72
📒 Files selected for processing (5)
ci/test-file-size-budget.jsonnemoclaw/src/blueprint/runner.test.tsnemoclaw/src/blueprint/runner.tsnemoclaw/src/blueprint/snapshot.test.tsnemoclaw/src/blueprint/snapshot.ts
66dc1d2 to
337c93b
Compare
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
nemoclaw/src/blueprint/snapshot.ts (1)
319-327: ⚡ Quick winConsider validating that
snapshotPathis withinSNAPSHOTS_DIR.
rejectSymlinksOnPathguards against symlink attacks under HOME but doesn't restrict deletion to the snapshots directory. A user could inadvertently (or maliciously via a compromised script) runsnapshots delete --path ~/.sshand delete unrelated directories.Adding a prefix check provides defense-in-depth:
🛡️ Suggested validation
export function deleteSnapshot(snapshotPath: string): boolean { try { + const resolved = resolve(snapshotPath); + if (!resolved.startsWith(SNAPSHOTS_DIR + '/') && resolved !== SNAPSHOTS_DIR) { + return false; + } rejectSymlinksOnPath(snapshotPath); rmSync(snapshotPath, { recursive: true, force: true }); return true; } catch { return false; } }🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@nemoclaw/src/blueprint/snapshot.ts` around lines 319 - 327, The deleteSnapshot function currently only guards against symlinks but doesn't restrict path deletion to the SNAPSHOTS_DIR directory, allowing arbitrary directory deletion. Add a validation check in deleteSnapshot that ensures snapshotPath is within SNAPSHOTS_DIR before proceeding with rejectSymlinksOnPath and rmSync calls. If the path is outside SNAPSHOTS_DIR, return false to prevent the deletion.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@nemoclaw/src/blueprint/snapshot.ts`:
- Around line 329-333: The pruneSnapshots function does not validate the keep
parameter for negative values, and when keep is negative, the slice(keep)
operation will behave unexpectedly by returning elements from the end of the
array. Add a defensive guard at the beginning of the pruneSnapshots function to
either throw an error for invalid negative values or clamp the keep value to a
minimum of 0 to ensure predictable behavior.
---
Nitpick comments:
In `@nemoclaw/src/blueprint/snapshot.ts`:
- Around line 319-327: The deleteSnapshot function currently only guards against
symlinks but doesn't restrict path deletion to the SNAPSHOTS_DIR directory,
allowing arbitrary directory deletion. Add a validation check in deleteSnapshot
that ensures snapshotPath is within SNAPSHOTS_DIR before proceeding with
rejectSymlinksOnPath and rmSync calls. If the path is outside SNAPSHOTS_DIR,
return false to prevent the deletion.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 4406e8b8-b940-40ca-bc6a-54f757bce558
📒 Files selected for processing (5)
ci/test-file-size-budget.jsonnemoclaw/src/blueprint/runner.test.tsnemoclaw/src/blueprint/runner.tsnemoclaw/src/blueprint/snapshot.test.tsnemoclaw/src/blueprint/snapshot.ts
🚧 Files skipped from review as they are similar to previous changes (4)
- ci/test-file-size-budget.json
- nemoclaw/src/blueprint/snapshot.test.ts
- nemoclaw/src/blueprint/runner.test.ts
- nemoclaw/src/blueprint/runner.ts
337c93b to
5e76755
Compare
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@nemoclaw/src/blueprint/runner.ts`:
- Around line 1092-1104: The delete command accepts a user-provided --path
argument that is passed directly to deleteSnapshot without validation, allowing
deletion of arbitrary directories outside the snapshots directory. After
extracting snapshotPath from argv (around line 1095), add validation to ensure
the path is constrained to the snapshots directory by resolving it to an
absolute path and verifying it starts with the expected snapshots directory path
(typically ~/.nemoclaw/snapshots). Reject the command with an appropriate error
message if the resolved path attempts to escape the snapshots directory. This
validation must occur before the deleteSnapshot function is called to prevent
unauthorized recursive deletion of directories outside the snapshots location.
- Around line 1065-1067: The `Number.parseInt` function at the keep variable
assignment performs lenient parsing and will accept malformed inputs like "3abc"
or "1.5" by silently truncating them to 3 and 1 respectively. To enforce the
"non-negative integer" requirement strictly, validate that the entire input
string represents a pure integer with no trailing characters or decimal points.
You can do this by checking that the parsed keep value, when converted back to a
string, matches the original trimmed input value, or by validating the input
format using a regex pattern that matches only optional whitespace and
non-negative integer digits before attempting to parse.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: bd9bfb48-d9d7-47f7-8974-9fc2e082f74f
📒 Files selected for processing (3)
nemoclaw/src/blueprint/runner.tsnemoclaw/src/blueprint/snapshot.test.tsnemoclaw/src/blueprint/snapshot.ts
🚧 Files skipped from review as they are similar to previous changes (2)
- nemoclaw/src/blueprint/snapshot.ts
- nemoclaw/src/blueprint/snapshot.test.ts
|
✨ Thanks for adding the Related open issues: |
1 similar comment
|
✨ Thanks for adding the Related open issues: |
|
Contributor compliance is still blocking review: the PR body lacks a valid |
Add snapshot list, prune, and delete commands for blueprint-managed OpenClaw migration snapshots. Report failed prune deletions explicitly and strictly validate prune counts. Constrain delete paths to child entries under the snapshots directory before recursive removal. Co-authored-by: vasanth53 <vasanth@peak42.in> Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
2beb2fb to
be3b7be
Compare
|
Exact-head rewrite at |
|
@coderabbitai review |
✅ Action performedReview finished.
|
E2E Target Results — ✅ All selected jobs passedRun: 29104926968
|
|
Follow-up validation is now green at exact head |
There was a problem hiding this comment.
Exact-head security review at be3b7be2e19c7c79e79e03483696b0be1231481d: changes required before approval.
nemoclaw/src/blueprint/snapshot.ts:319-325validates the snapshot path and its symlink components, then calls path-based recursivermSync. A concurrent replacement of the snapshots ancestor after validation can redirect deletion outside the snapshot tree. Please close this ancestor-swap TOCTOU boundary with a no-follow/beneath deletion design, or narrow the feature to a deletion primitive whose containment can be guaranteed.snapshot.ts:345-351,379-394trusts mutable manifest timestamps for prune ordering. Require identity/timestamp agreement with a strictly validated direct-child snapshot directory name and sort from that trusted identity.nemoclaw/src/blueprint/runner.ts:1048-1051prints mutable manifest/path fields without stripping control characters or bounding them.
The current shard-4 timeout is unrelated to this diff (the failing MCP test blob is unchanged from the parent), but it has repeated and remains a separate red required check.
cv
left a comment
There was a problem hiding this comment.
Exact-head maintainer sweep at be3b7be2e1: the current shard-4 red is the unrelated known 5-second timeout in mcp-bridge-status-resolution.test.ts, so that check can be rerun after the source fix below.
One command-contract blocker remains in this PR. pruneSnapshots() correctly returns a failed list, and the snapshots prune handler prints each failed path, but then falls through successfully. The runner protocol explicitly defines exit code 0 as success, so a partial or total prune failure is currently reported to callers and automation as success even though requested retention was not achieved.
Please preserve the per-path summary but make any non-empty failed result exit nonzero, and add a command-level regression that injects a deletion failure, asserts the failed path is reported, and asserts the command rejects or exits nonzero. After that, rerun ordinary CI, obtain trusted fork-context advisor review, and run the snapshot-focused live target recommended for the exact head.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
@coderabbitai review |
✅ Action performedReview finished.
|
E2E Advisor RecommendationRequired E2E: Dispatch hint: Full advisor summaryE2E Recommendation AdvisorBase: Required E2E
Optional E2E
New E2E recommendations
Dispatch hint
|
E2E Target RecommendationRequired E2E targets: Dispatch required E2E targets:
Full E2E target advisor summaryE2E Target AdvisorBase: Required E2E targets
Optional E2E targets
Relevant changed files
|
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
E2E Target Results — ✅ All requested jobs passedRun: 29125993228
|
cjagwani
left a comment
There was a problem hiding this comment.
Exact-head re-review of 977dabde0cc24f595ee3c4a19c26ef7a3a08b74f: the prior Python startup vulnerability is fixed. python3 -I, buildSubprocessEnv(), the hostile real-process sitecustomize regression, fd-relative no-follow deletion, all ordinary CI, and all three required live jobs now pass.
One merge-gate item remains: both trusted exact-head advisors independently return merge_after_fixes for the same architecture concern. This PR adds 225 production lines to security-sensitive snapshot.ts, 128 to the already-central runner.ts, and 465 to snapshot.test.ts (977 changed lines total). The new retention/deletion boundary and the snapshots CLI parser are cohesive surfaces and should not remain embedded in those existing modules.
Please perform a behavior-neutral extraction of the new retention/delete helper into a focused snapshot-retention module and the new CLI parsing/dispatch into a focused command module, with the corresponding new tests split alongside those surfaces. Preserve the now-verified subprocess and fd-relative security contracts unchanged. I am not treating the advisors' native-Windows, manifest-order, real-FS prune, or negative-keep notes as blockers; those are already handled, outside supported native-Windows scope, or explicitly tested.
After the mechanical split, rerun the focused snapshot suites, package checks, exact-head ordinary CI, the three live jobs, and trusted advisors. That should leave this otherwise-correct PR ready for approval.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
There was a problem hiding this comment.
follow-up at f159b21aaf81b23889a7117a73d8792ee7a6ac8e: the requested extraction is structurally good. runner.ts and snapshot.ts are substantially smaller, and the command, retention, and fd-relative deletion boundaries now live in focused modules. Two current-head issues remain before approval.
- The split made the snapshot tests materially nondeterministic. Repeating the exact focused plugin command below produced 6 passes and 4 failures in the latest 10-run sample (with 10/17 passes in an earlier sample):
npm test -- --run src/blueprint/snapshot.test.ts src/blueprint/snapshot-management.test.ts src/blueprint/snapshot-command.test.ts src/blueprint/snapshot-realfs.test.ts src/blueprint/runner.test.ts --silent
Failures vary between snapshot-command.test.ts:102 (the expected partial-failure throw disappears), snapshot-management.test.ts:76 (the trusted snapshot list is empty), snapshot-realfs.test.ts:82 (nothing is deleted), snapshot-command.test.ts:91 (No snapshots found), and snapshot-realfs.test.ts:193 (deleteSnapshot returns false). The prior 977dabde suites showed one related home-mock failure in 24 observed runs, but f159 adds two more files that repeatedly reset modules and dynamically mock node:os, alongside process-global PATH/platform stubs, and makes the race dramatically reproducible. Please give the extracted modules/tests a stable snapshot-root/platform/helper seam or otherwise scope the mocks deterministically, then demonstrate repeated normal-run stability. A one-off 553/553 pass is not sufficient for a 40% focused failure rate.
- The exact GPT advisor correctly found that the new destructive user-facing commands are undocumented. Please document
~/.nemoclaw/snapshots/,snapshots list,snapshots prune --keep <N>, andsnapshots delete --path <path>, including retention/data-loss guidance and the native-Windows/WSL limitation, then run the docs build.
The direct pruneSnapshots(-1) and native-Windows command-level behavior changed during the nominally behavior-neutral split. Those are not independent blockers because the CLI validates keep values and Windows deletion was already unsupported, but please either preserve the old behavior or make the intentional change explicit in tests/docs.
After the deterministic test repair and docs update, refresh ordinary CI, both advisors, and the three required snapshot/state live jobs. The stronger fd-relative deletion boundary itself remains accepted.
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
|
follow-up at The deterministic-test blocker from review #4675321850 remains because this commit does not change the dynamic HOME/PATH/platform seams. The exact five-file focused command passed 9/10 in the first current-head sample, then failed again on a later attempt at |
E2E Target Results — ✅ All requested jobs passedRun: 29126852665
|
Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com>
E2E Target Results —
|
| Job | Result |
|---|---|
| snapshot-commands | |
| state-backup-restore | |
| upgrade-stale-sandbox |
E2E Target Results — ✅ All requested jobs passedRun: 29127831946
|
cv
left a comment
There was a problem hiding this comment.
Current-head re-review passed at fade941. The extracted snapshot modules now use deterministic injected seams instead of process-global/module-reset mocks, the destructive snapshot commands and retention/data-loss/platform limits are documented, all current CI and commits are green/Verified, both exact-head trusted advisors returned merge_as_is, and snapshot-commands/state-backup-restore/upgrade-stale-sandbox all passed live. No unresolved review threads remain.
Dismissed after current-commit re-review: the requested module extraction, deterministic injected seams, and host-state documentation are present. The focused suites passed repeated stress runs, the full plugin suite and build passed, current CI is green, both trusted advisors reported merge_as_is, all three required live jobs passed, and all review threads are resolved. Earlier security and correctness requests remain covered by fd-relative no-follow deletion and isolated Python/environment regression tests.
<!-- markdownlint-disable MD041 --> ## Summary Release-prep documentation for v0.0.81 now summarizes user-facing changes merged since v0.0.80. It also closes the Hermes dashboard-profile backup gap and distinguishes direct blueprint-runner actions from public host CLI commands. ## Changes - Add the `v0.0.81` section to `docs/about/release-notes.mdx` with links to the detailed user guides. - Document that Hermes rebuilds preserve `.hermes/dashboard-home/`, including Dashboard `MEMORY.md` and `USER.md`. - Update Hermes manual backup and restore examples to transfer those two profile files without copying generated configuration or the secret-bearing dashboard `.env`. - Explain the new per-item backup failure causes. - Clarify that migration snapshot retention fragments are direct-runner arguments and are not exposed by the host `nemoclaw` CLI. ### Source summary - #6445 -> `docs/about/release-notes.mdx`, `docs/manage-sandboxes/backup-restore.mdx`, and `docs/manage-sandboxes/workspace-files.mdx`: Summarize manifest-owned key-level restore and current-config authority. - #6617 -> `docs/about/release-notes.mdx` and `docs/manage-sandboxes/backup-restore.mdx`: Record the fail-closed `/proc` fallback used to verify an idle Deep Agents runtime before snapshot creation. - #6685 -> `docs/about/release-notes.mdx`, `docs/manage-sandboxes/backup-restore.mdx`, and `docs/manage-sandboxes/workspace-files.mdx`: Document Hermes Web Dashboard profile persistence and safe manual transfer. - #6649 -> `docs/about/release-notes.mdx`: Summarize host-validated loopback compatible-endpoint routing through the sandbox gateway. - #6643 -> `docs/about/release-notes.mdx`: Summarize automatic `max_completion_tokens` handling for GPT-5 and o-series models. - #6661 -> `docs/about/release-notes.mdx`: Summarize bounded connection reuse for eligible provider-validation probes. - #6704 -> `docs/about/release-notes.mdx`: Record that direct blueprint apply stops instead of persisting incomplete state after provider or inference setup fails. - #6677 -> `docs/about/release-notes.mdx`: Summarize transactional recovery for legacy Docker containers whose managed supervisor disappeared after restart. - #6625 -> `docs/about/release-notes.mdx`: Record Hermes managed-startup persistence across direct Docker restarts. - #6597 -> `docs/about/release-notes.mdx`: Record final-sandbox gateway cleanup on macOS. - #6680 -> `docs/about/release-notes.mdx`: Summarize managed Deep Agents first-run and process-tree cleanup improvements. - #6647 -> `docs/about/release-notes.mdx`: Record fail-closed validation for the managed Deep Agents fetch CA bundle. - #6645 -> `docs/about/release-notes.mdx`: Summarize WhatsApp loopback pairing and trusted npm plugin provenance. - #6673 -> `docs/about/release-notes.mdx` and `docs/manage-sandboxes/backup-restore.mdx`: Document stopped-sandbox backup remediation. - #6631 -> `docs/about/release-notes.mdx` and `docs/manage-sandboxes/backup-restore.mdx`: Document per-item backup failure causes. - #6620 -> `docs/about/release-notes.mdx`: Record the created-but-not-ready sandbox lifecycle receipt. - #6664 -> `docs/about/release-notes.mdx`: Record prompt-aware onboarding progress output. - #6598 -> `docs/about/release-notes.mdx`: Summarize stale replay-result invalidation during resumed onboarding. - #6593 -> `docs/about/release-notes.mdx`: Summarize contextual OpenClaw audit findings for managed dashboard compatibility settings. - #6650 -> `docs/about/release-notes.mdx`: Record redaction of token-shaped URL query values. - #6638 -> `docs/about/release-notes.mdx`: Record the exact-path MCP `DELETE` policy recipe for session termination. - #5453 -> `docs/reference/host-files-and-state.mdx`: Clarify that snapshot retention actions belong to direct runner integrations and are not standalone host CLI commands. ### Skipped from docs-skip - #6633 matched the `openclaw-sandbox-permissive.yaml` path in `docs/.docs-skip` and produced no documentation in this update. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [x] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [x] Tests not applicable — justification: This is a documentation-only release-prep update; behavior is protected by the merged source PRs, and the documentation build validates the changed examples and routes. - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Verification - [x] PR description includes the DCO sign-off declaration and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — tests are not applicable for this documentation-only change; `npm run docs` completed successfully. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: not run for this documentation-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — 0 errors; two existing Fern warnings remain. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — no new pages. --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added release notes for v0.0.81 covering state preservation, inference setup, sandbox recovery, session setup, pairing, diagnostics, and security policy updates. - Expanded backup and restore guidance to include dashboard profile files and clarify files that must not be copied. - Added dashboard profile persistence details to workspace and rebuild documentation. - Clarified snapshot retention guidance and the distinction between host CLI capabilities and direct runner actions. - Added more detailed backup failure reporting information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Carlos Villela <cvillela@nvidia.com>
…agement (NVIDIA#5453) ## Summary Adds `snapshots list`, `snapshots prune --keep <N>`, and `snapshots delete --path <path>` subcommands to the blueprint runner, letting users manage disk space consumed by accumulated migration snapshots under `~/.nemoclaw/snapshots/`. ## Changes | File | Change | |------|--------| | `nemoclaw/src/blueprint/snapshot.ts` | Added `deleteSnapshot()`, `pruneSnapshots()` with symlink-attack rejection | | `nemoclaw/src/blueprint/snapshot.test.ts` | 8 tests covering deletion, symlink rejection, prune with keep count, empty state | | `nemoclaw/src/blueprint/runner.ts` | Added `snapshots` action with `list`, `prune`, `delete` subcommands and usage text | | `nemoclaw/src/blueprint/runner.test.ts` | 12 tests for CLI routing, list/prune/delete flows; extended fs mock with `lstatSync`, `readlinkSync`, `rmSync` | | `ci/test-file-size-budget.json` | Ratcheted runner.test.ts size budget to 1622 lines | ## Usage ```bash nemoclaw blueprint snapshots list nemoclaw blueprint snapshots prune --keep 5 nemoclaw blueprint snapshots delete --path ~/.nemoclaw/snapshots/20260101T000000Z ``` ## Testing All 503 plugin tests pass. All hooks pass (pre-commit, commitlint). New code adds 20 tests across two test files. ## Checklist - [x] Conventional Commit (`feat(blueprint):`) - [x] DCO sign-off - [x] Tests added/updated - [x] All tests pass - [x] Hooks pass (pre-commit, commitlint) - [x] Feature branch from `main` Closes NVIDIA#5452 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added a top-level `snapshots` CLI action with `list`, `prune --keep <N>`, and `delete --path <path>`. * `list` shows snapshot metadata (or “No snapshots found.”); `prune` validates `--keep` and reports kept/deleted/failed; `delete` safely removes snapshots and prints `Deleted snapshot:` (including for non-existent targets). * **Bug Fixes** * Tightened snapshot selection so only directories whose manifest timestamp exactly matches are considered. * Improved safety checks to prevent deleting outside the snapshots root and to reject symlink targets. * **Tests** * Expanded unit and CLI tests for retention, validation, error messaging, and failure reporting; added real-filesystem safety coverage (skipped on Windows). <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> --------- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> Co-authored-by: Prekshi Vyas <prekshiv@nvidia.com> Co-authored-by: Carlos Villela <cvillela@nvidia.com>
<!-- markdownlint-disable MD041 --> ## Summary Release-prep documentation for v0.0.81 now summarizes user-facing changes merged since v0.0.80. It also closes the Hermes dashboard-profile backup gap and distinguishes direct blueprint-runner actions from public host CLI commands. ## Changes - Add the `v0.0.81` section to `docs/about/release-notes.mdx` with links to the detailed user guides. - Document that Hermes rebuilds preserve `.hermes/dashboard-home/`, including Dashboard `MEMORY.md` and `USER.md`. - Update Hermes manual backup and restore examples to transfer those two profile files without copying generated configuration or the secret-bearing dashboard `.env`. - Explain the new per-item backup failure causes. - Clarify that migration snapshot retention fragments are direct-runner arguments and are not exposed by the host `nemoclaw` CLI. ### Source summary - NVIDIA#6445 -> `docs/about/release-notes.mdx`, `docs/manage-sandboxes/backup-restore.mdx`, and `docs/manage-sandboxes/workspace-files.mdx`: Summarize manifest-owned key-level restore and current-config authority. - NVIDIA#6617 -> `docs/about/release-notes.mdx` and `docs/manage-sandboxes/backup-restore.mdx`: Record the fail-closed `/proc` fallback used to verify an idle Deep Agents runtime before snapshot creation. - NVIDIA#6685 -> `docs/about/release-notes.mdx`, `docs/manage-sandboxes/backup-restore.mdx`, and `docs/manage-sandboxes/workspace-files.mdx`: Document Hermes Web Dashboard profile persistence and safe manual transfer. - NVIDIA#6649 -> `docs/about/release-notes.mdx`: Summarize host-validated loopback compatible-endpoint routing through the sandbox gateway. - NVIDIA#6643 -> `docs/about/release-notes.mdx`: Summarize automatic `max_completion_tokens` handling for GPT-5 and o-series models. - NVIDIA#6661 -> `docs/about/release-notes.mdx`: Summarize bounded connection reuse for eligible provider-validation probes. - NVIDIA#6704 -> `docs/about/release-notes.mdx`: Record that direct blueprint apply stops instead of persisting incomplete state after provider or inference setup fails. - NVIDIA#6677 -> `docs/about/release-notes.mdx`: Summarize transactional recovery for legacy Docker containers whose managed supervisor disappeared after restart. - NVIDIA#6625 -> `docs/about/release-notes.mdx`: Record Hermes managed-startup persistence across direct Docker restarts. - NVIDIA#6597 -> `docs/about/release-notes.mdx`: Record final-sandbox gateway cleanup on macOS. - NVIDIA#6680 -> `docs/about/release-notes.mdx`: Summarize managed Deep Agents first-run and process-tree cleanup improvements. - NVIDIA#6647 -> `docs/about/release-notes.mdx`: Record fail-closed validation for the managed Deep Agents fetch CA bundle. - NVIDIA#6645 -> `docs/about/release-notes.mdx`: Summarize WhatsApp loopback pairing and trusted npm plugin provenance. - NVIDIA#6673 -> `docs/about/release-notes.mdx` and `docs/manage-sandboxes/backup-restore.mdx`: Document stopped-sandbox backup remediation. - NVIDIA#6631 -> `docs/about/release-notes.mdx` and `docs/manage-sandboxes/backup-restore.mdx`: Document per-item backup failure causes. - NVIDIA#6620 -> `docs/about/release-notes.mdx`: Record the created-but-not-ready sandbox lifecycle receipt. - NVIDIA#6664 -> `docs/about/release-notes.mdx`: Record prompt-aware onboarding progress output. - NVIDIA#6598 -> `docs/about/release-notes.mdx`: Summarize stale replay-result invalidation during resumed onboarding. - NVIDIA#6593 -> `docs/about/release-notes.mdx`: Summarize contextual OpenClaw audit findings for managed dashboard compatibility settings. - NVIDIA#6650 -> `docs/about/release-notes.mdx`: Record redaction of token-shaped URL query values. - NVIDIA#6638 -> `docs/about/release-notes.mdx`: Record the exact-path MCP `DELETE` policy recipe for session termination. - NVIDIA#5453 -> `docs/reference/host-files-and-state.mdx`: Clarify that snapshot retention actions belong to direct runner integrations and are not standalone host CLI commands. ### Skipped from docs-skip - NVIDIA#6633 matched the `openclaw-sandbox-permissive.yaml` path in `docs/.docs-skip` and produced no documentation in this update. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [x] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [x] Tests not applicable — justification: This is a documentation-only release-prep update; behavior is protected by the merged source PRs, and the documentation build validates the changed examples and routes. - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Verification - [x] PR description includes the DCO sign-off declaration and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run check:diff` passed when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — tests are not applicable for this documentation-only change; `npm run docs` completed successfully. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: not run for this documentation-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — 0 errors; two existing Fern warnings remain. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — no new pages. --- Signed-off-by: Carlos Villela <cvillela@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit - **Documentation** - Added release notes for v0.0.81 covering state preservation, inference setup, sandbox recovery, session setup, pairing, diagnostics, and security policy updates. - Expanded backup and restore guidance to include dashboard profile files and clarify files that must not be copied. - Added dashboard profile persistence details to workspace and rebuild documentation. - Clarified snapshot retention guidance and the distinction between host CLI capabilities and direct runner actions. - Added more detailed backup failure reporting information. <!-- end of auto-generated comment: release notes by coderabbit.ai --> Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Summary
Adds
snapshots list,snapshots prune --keep <N>, andsnapshots delete --path <path>subcommands to the blueprint runner, letting users manage disk space consumed by accumulated migration snapshots under~/.nemoclaw/snapshots/.Changes
nemoclaw/src/blueprint/snapshot.tsdeleteSnapshot(),pruneSnapshots()with symlink-attack rejectionnemoclaw/src/blueprint/snapshot.test.tsnemoclaw/src/blueprint/runner.tssnapshotsaction withlist,prune,deletesubcommands and usage textnemoclaw/src/blueprint/runner.test.tslstatSync,readlinkSync,rmSyncci/test-file-size-budget.jsonUsage
nemoclaw blueprint snapshots list nemoclaw blueprint snapshots prune --keep 5 nemoclaw blueprint snapshots delete --path ~/.nemoclaw/snapshots/20260101T000000ZTesting
All 503 plugin tests pass. All hooks pass (pre-commit, commitlint). New code adds 20 tests across two test files.
Checklist
feat(blueprint):)mainCloses #5452
Summary by CodeRabbit
snapshotsCLI action withlist,prune --keep <N>, anddelete --path <path>.listshows snapshot metadata (or “No snapshots found.”);prunevalidates--keepand reports kept/deleted/failed;deletesafely removes snapshots and printsDeleted snapshot:(including for non-existent targets).Signed-off-by: Prekshi Vyas prekshiv@nvidia.com