fix(sandbox): compare hermes agent version in its runtime scheme - #6089
Conversation
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughHermes now pins to ChangesHermes version comparison fix
Estimated code review effort: 3 (Moderate) | ~25 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in the Show a code coverage summary of the most covered files.
TypeScript / code-coverage/cliThe overall coverage in the Show a code coverage summary of the most covered files.
Updated |
PR Review Advisor — Changes requestedMerge posture: Do not merge yet Action checklist
Findings index
Review findings by urgency: 0 required fixes, 6 items to resolve/justify, 1 in-scope improvement
|
PR Review Advisor (Nemotron Ultra) — InformationalMerge posture: Informational / low confidence Action checklist
Findings index
Review findings by urgency: 0 required fixes, 1 item to resolve/justify, 0 in-scope improvements
|
There was a problem hiding this comment.
🧹 Nitpick comments (2)
src/lib/agent/defs.test.ts (1)
92-98: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winTest hardcodes the same magic threshold used in production code.
This test re-derives the major version and asserts
major < 1000, duplicating theCALENDAR_VERSION_MIN_MAJORconstant defined insrc/lib/sandbox/version.ts. If that threshold ever changes, this test won't track it and could silently diverge from the real staleness logic it's meant to protect.Consider exporting
CALENDAR_VERSION_MIN_MAJORfromversion.tsand importing it here instead of re-declaring1000.As per path instructions for
**/*.test.{ts,js,mts,mjs,cts,cjs}, tests should "Flag copied production algorithms... and conditionals that make a test pass without exercising its claim."♻️ Proposed fix
- const major = Number.parseInt(String(hermes.expectedVersion).split(".")[0] ?? "", 10); - expect(major).toBeLessThan(1000); + const major = Number.parseInt(String(hermes.expectedVersion).split(".")[0] ?? "", 10); + expect(major).toBeLessThan(CALENDAR_VERSION_MIN_MAJOR);(requires exporting
CALENDAR_VERSION_MIN_MAJORfromsrc/lib/sandbox/version.tsand importing it in this test file)🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/lib/agent/defs.test.ts` around lines 92 - 98, The Hermes version test is duplicating the production calendar-version threshold with a hardcoded major version check, so it can drift from the real staleness rule. Export CALENDAR_VERSION_MIN_MAJOR from version.ts and import that constant into defs.test.ts, then use it in the hermes.expectedVersion assertion instead of re-deriving or hardcoding 1000.Source: Path instructions
src/lib/sandbox/version.ts (1)
95-108: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick winDocument the scheme-mismatch tradeoff.
versionsComparablecorrectly suppresses false positives when schemes differ (the bug this PR fixes), but it also means a genuine update will not be flagged once an agent's version scheme changes again (e.g., a future switch back to calendar versioning) until both sides use the same scheme. That's a reasonable tradeoff, but it's worth a short comment explaining the assumption so a future reader doesn't mistakeisAgentStalereturningfalsefor "definitely up to date."📝 Suggested comment
+// Cross-scheme versions (e.g. calendar "2026.6.19" vs semver "0.17.0") cannot be +// meaningfully ordered by versionGte. Treat them as "not stale" rather than risk a +// false-positive update notice; a real update will only be detected once both the +// installed runtime and the manifest pin use the same scheme again. function versionsComparable(left: string, right: string): boolean {🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/lib/sandbox/version.ts` around lines 95 - 108, Add a short comment near versionsComparable/isAgentStale explaining the scheme-mismatch assumption: when sandboxVersion and expectedVersion use different versioning schemes, isAgentStale intentionally returns false to avoid false positives, but that also means a real update may be missed until both sides share the same scheme again. Reference versionsComparable, isAgentStale, and CALENDAR_VERSION_MIN_MAJOR in the comment so future readers don’t read false as “definitely up to date.”
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@src/lib/agent/defs.test.ts`:
- Around line 92-98: The Hermes version test is duplicating the production
calendar-version threshold with a hardcoded major version check, so it can drift
from the real staleness rule. Export CALENDAR_VERSION_MIN_MAJOR from version.ts
and import that constant into defs.test.ts, then use it in the
hermes.expectedVersion assertion instead of re-deriving or hardcoding 1000.
In `@src/lib/sandbox/version.ts`:
- Around line 95-108: Add a short comment near versionsComparable/isAgentStale
explaining the scheme-mismatch assumption: when sandboxVersion and
expectedVersion use different versioning schemes, isAgentStale intentionally
returns false to avoid false positives, but that also means a real update may be
missed until both sides share the same scheme again. Reference
versionsComparable, isAgentStale, and CALENDAR_VERSION_MIN_MAJOR in the comment
so future readers don’t read false as “definitely up to date.”
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: 0c9b8e86-3f5c-4f52-8cd2-861e40837376
📒 Files selected for processing (4)
agents/hermes/manifest.yamlsrc/lib/agent/defs.test.tssrc/lib/sandbox/version.test.tssrc/lib/sandbox/version.ts
E2E Advisor RecommendationRequired E2E: Dispatch hint: Full advisor summaryE2E Recommendation AdvisorBase: Required E2E
Optional E2E
New E2E recommendations
Dispatch hint
|
E2E Target RecommendationRequired E2E targets: Dispatch required E2E targets:
Full E2E target advisor summaryE2E Target AdvisorBase: Required E2E targets
Optional E2E targets
Relevant changed files
|
…ersion Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…smatch Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🧹 Nitpick comments (1)
src/lib/sandbox/version.ts (1)
114-120: 📐 Maintainability & Code Quality | 🔵 Trivial | 🏗️ Heavy liftKeep the staleness helper pure; move stderr output to the boundary.
isAgentStalenow writes toprocess.stderrthroughwarnSchemeMismatch, which makes version comparison depend on host I/O. Return a skip/reason from the helper and let the action/CLI formatting layer decide whether to print it. As per path instructions, “helpers for version comparison/staleness detection withinsrc/lib/sandbox/**” should be “small pure helpers” with “no direct host calls.”Also applies to: 131-134
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@src/lib/sandbox/version.ts` around lines 114 - 120, The staleness/version comparison path is doing host I/O inside the helper, specifically `warnSchemeMismatch` is writing directly to `process.stderr` from within `isAgentStale` flow. Refactor the sandbox version helpers in `src/lib/sandbox/version.ts` so `isAgentStale` and `warnSchemeMismatch` stay pure and only return a skip/reason or warning signal, then move the actual stderr printing to the action/CLI formatting boundary that consumes the result. Keep the deduping logic in the helper, but remove any direct process calls from these version comparison helpers.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/lib/sandbox/version.ts`:
- Around line 102-105: The calendar version check in isCalendarVersion currently
only matches bare numeric tags, so v-prefixed calendar releases still fall
through as non-calendar. Update CALENDAR_VERSION_PATTERN in version.ts to accept
an optional leading v while keeping the existing numeric calendar format, and
keep the logic in isCalendarVersion using that pattern so v2026.6.19 is
classified correctly. Verify the change still excludes non-calendar semver tags
like v0.17.0.
---
Nitpick comments:
In `@src/lib/sandbox/version.ts`:
- Around line 114-120: The staleness/version comparison path is doing host I/O
inside the helper, specifically `warnSchemeMismatch` is writing directly to
`process.stderr` from within `isAgentStale` flow. Refactor the sandbox version
helpers in `src/lib/sandbox/version.ts` so `isAgentStale` and
`warnSchemeMismatch` stay pure and only return a skip/reason or warning signal,
then move the actual stderr printing to the action/CLI formatting boundary that
consumes the result. Keep the deduping logic in the helper, but remove any
direct process calls from these version comparison helpers.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: a101e8d0-1282-4044-87f4-9afb61d4a6ce
📒 Files selected for processing (1)
src/lib/sandbox/version.ts
…smatch log Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…bucket Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…fixtures Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…endar vs semver Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…re-read Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…ime and manifest Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
… year range Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…ismatch line Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…d structured warn payload Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
prekshivyas
left a comment
There was a problem hiding this comment.
Reviewed the core logic in the new version-scheme.ts: shape classifier (calendar 2020–2099/3000–9999 vs semver), and evaluateStaleness fails closed on a cross-scheme pair (marks stale + one-shot structured warning) rather than comparing blindly; otherwise defers to versionGte. Root cause is fixed by pinning the manifest expected_version to the runtime's semver. Sound and well-tested (semver match/behind, cross-scheme, ssh-probe). Note: this is the heaviest change in the batch and modifies the sensitive src/lib/sandbox/version.ts path — the author-requested maintainer review of that orchestration should still be recorded per the template. Approving on the scheme-comparator logic + green advisors/CodeRabbit/E2E/CI.
## Summary After #6089 merged (re-pinning the Hermes manifest to semver `0.17.0`), the `rebuild-hermes` live test started failing on main. The regex at line 696 was extracting a calver version in parentheses — `(2026.6.19)` — but the version output now uses a semver tag format — `v0.17.0`. The two never match. ## Related Issue Regression introduced by #6089 (merged as `2ab9e525`). The live `rebuild-hermes` test doesn't run on PRs so it merged green. ## Changes - `test/e2e/live/rebuild-hermes.test.ts:696` — change `/\((\d+\.\d+\.\d+)\)/` to `/v(\d+\.\d+\.\d+)/` ## Type of Change - [x] Code change (feature, bug fix, or refactor) ## Quality Gates - [x] Tests added or updated for changed behavior - [x] Docs not applicable — justification: live test fix, no user-facing change - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) — no ## Verification - [x] Git hooks passed during commit and push - [x] No secrets, API keys, or credentials committed --- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Updated end-to-end Hermes version parsing to match the latest CLI output format. * Added new test coverage for `nemoclaw-start` gateway preload selection and persistent gateway log mirroring, including refusal on unsafe symlinked log directories. * Removed overlapping preload/log hardening suites from the existing `nemoclaw-start` test file. * Introduced a helper to extract shell functions from script sources for more reliable testing. * **Chores** * Adjusted the `nemoclaw-start` test file size budget to reflect the new suite layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
## Summary - Add the `v0.0.72` release-note section with links to the deeper docs pages for installer recovery, command diagnostics, inference, policy, and sandbox repair changes. - Document the custom preset `allowed_ips` guard for user-authored policy files. ## Related Issue None. ## Source summary - #6132 -> `docs/about/release-notes.mdx`: Summarizes installer and upgrade recovery before generic onboarding, with links to quickstart and lifecycle docs. - #6087 -> `docs/network-policy/customize-network-policy.mdx`: Documents that user-authored custom presets reject `allowed_ips` for ordinary endpoints; also summarized in release notes. - #5975 -> `docs/about/release-notes.mdx`: Summarizes safer curl-based inference probes that keep API keys out of process arguments. - #6044 -> `docs/about/release-notes.mdx`: Summarizes compact `channels status` configuration reporting. - #6096 -> `docs/about/release-notes.mdx`: Summarizes OpenClaw EC2 metadata discovery disablement and links to security guidance. - #5980 and #5991 -> `docs/about/release-notes.mdx`: Summarizes `exec` multiline argument rejection and recovery guidance. - #6023 -> `docs/about/release-notes.mdx`: Summarizes registered-provider diagnostics for `inference set` failures. - #6074 -> `docs/about/release-notes.mdx`: Summarizes the refreshed NVIDIA Endpoints featured-model selection behavior. - #5969 -> `docs/about/release-notes.mdx`: Summarizes `credentials add` provider credential registration. - #6060 -> `docs/about/release-notes.mdx`: Summarizes mutable OpenClaw config permission restoration after `exec`. - #6134 -> `docs/about/release-notes.mdx`: Summarizes restored Tavily access for managed Python workflows. - #6089 -> `docs/about/release-notes.mdx`: Summarizes Hermes runtime version-scheme comparison during upgrade checks. - #6131 -> `docs/about/release-notes.mdx`: Summarizes OpenClaw gateway watchdog recovery behavior. - #5976 and #5990 -> `docs/about/release-notes.mdx`: Summarizes prompt stdin EOF cancellation behavior during onboarding. - #5540 -> `docs/about/release-notes.mdx`: Summarizes clarified host-level and per-sandbox status command scope. - #5978 and #6018 -> `docs/about/release-notes.mdx`: Summarizes policy-denial log breadcrumbs in connect shells. ## Testing - `npm run docs:sync-agent-variants` - `npm run docs` - Commit hooks passed during `git commit`, including commitlint and gitleaks. - Pre-push hook passed during `git push`, including TypeScript CLI and package/tag version sync. ## Checklist - [x] Documentation updated. - [x] `npm run docs` completed with 0 errors and 1 existing Fern warning. - [x] No source code or generated build artifacts committed. Signed-off-by: Miyoung Choi <miyoungc@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for v0.0.72 covering improved installer recovery, clearer CLI diagnostics, safer inference setup and provider switching, better credential handling, stronger policy boundaries, and more robust runtime repair behavior. * Updated network policy guidance to clarify when `allowed_ips` can be used, including a specific exception for the sandbox-to-host bridge endpoint. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
…DIA#6089) <!-- markdownlint-disable MD041 --> ## Summary `nemoclaw <name> status` on a Hermes sandbox always reported `Update: v2026.6.19 available` because the staleness check compared the runtime semver against the manifest calver with a scheme-blind comparator. ## Related Issue Fixes NVIDIA#6049 ## Changes - `agents/hermes/manifest.yaml`: pin `expected_version` to the semver the runtime reports. - `src/lib/sandbox/version.ts`: skip the comparison when runtime and expected versions are in different schemes. - `scripts/update-hermes-agent.sh`: align drift check and manifest pin with `HERMES_SEMVER`. - Tests: cover semver-match, behind, cross-scheme, and ssh-probe paths. ## Type of Change - [x] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [ ] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [x] Tests added or updated for changed behavior - [ ] Existing tests cover changed behavior — justification: - [ ] Tests not applicable — justification: - [ ] Docs updated for user-facing behavior changes - [x] Docs not applicable — justification: corrects an existing `status` line; no new command or flag. - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: requesting maintainer review of `src/lib/sandbox/version.ts`. - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Verification - [x] PR description includes the DCO sign-off declaration and every commit appears as `Verified` in GitHub - [x] Git hooks passed during commit and push, or `npx prek run --from-ref main --to-ref HEAD` passes - [x] Targeted tests pass for changed behavior - [ ] Full `npm test` passes (broad runtime changes only) - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) - [ ] Doc pages follow the style guide (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) --- Signed-off-by: Tinson Lai <tinsonl@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved Hermes runtime compatibility checks with scheme-aware version handling (semver-like vs calendar-style), including accurate stale detection for both registry and SSH-probed paths. * Added clearer one-time warnings when sandbox/expected versions use different version schemes. * **Tests** * Expanded Hermes version parsing/validation and runtime detection coverage, including exact-match, staleness, and non-update scenarios. * **Chores** * Updated the Hermes agent update/check script to treat the manifest’s expected version as semver. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
…IA#6138) ## Summary After NVIDIA#6089 merged (re-pinning the Hermes manifest to semver `0.17.0`), the `rebuild-hermes` live test started failing on main. The regex at line 696 was extracting a calver version in parentheses — `(2026.6.19)` — but the version output now uses a semver tag format — `v0.17.0`. The two never match. ## Related Issue Regression introduced by NVIDIA#6089 (merged as `2ab9e525`). The live `rebuild-hermes` test doesn't run on PRs so it merged green. ## Changes - `test/e2e/live/rebuild-hermes.test.ts:696` — change `/\((\d+\.\d+\.\d+)\)/` to `/v(\d+\.\d+\.\d+)/` ## Type of Change - [x] Code change (feature, bug fix, or refactor) ## Quality Gates - [x] Tests added or updated for changed behavior - [x] Docs not applicable — justification: live test fix, no user-facing change - [x] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) — no ## Verification - [x] Git hooks passed during commit and push - [x] No secrets, API keys, or credentials committed --- Signed-off-by: Prekshi Vyas <prekshiv@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Tests** * Updated end-to-end Hermes version parsing to match the latest CLI output format. * Added new test coverage for `nemoclaw-start` gateway preload selection and persistent gateway log mirroring, including refusal on unsafe symlinked log directories. * Removed overlapping preload/log hardening suites from the existing `nemoclaw-start` test file. * Introduced a helper to extract shell functions from script sources for more reliable testing. * **Chores** * Adjusted the `nemoclaw-start` test file size budget to reflect the new suite layout. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
## Summary - Add the `v0.0.72` release-note section with links to the deeper docs pages for installer recovery, command diagnostics, inference, policy, and sandbox repair changes. - Document the custom preset `allowed_ips` guard for user-authored policy files. ## Related Issue None. ## Source summary - NVIDIA#6132 -> `docs/about/release-notes.mdx`: Summarizes installer and upgrade recovery before generic onboarding, with links to quickstart and lifecycle docs. - NVIDIA#6087 -> `docs/network-policy/customize-network-policy.mdx`: Documents that user-authored custom presets reject `allowed_ips` for ordinary endpoints; also summarized in release notes. - NVIDIA#5975 -> `docs/about/release-notes.mdx`: Summarizes safer curl-based inference probes that keep API keys out of process arguments. - NVIDIA#6044 -> `docs/about/release-notes.mdx`: Summarizes compact `channels status` configuration reporting. - NVIDIA#6096 -> `docs/about/release-notes.mdx`: Summarizes OpenClaw EC2 metadata discovery disablement and links to security guidance. - NVIDIA#5980 and NVIDIA#5991 -> `docs/about/release-notes.mdx`: Summarizes `exec` multiline argument rejection and recovery guidance. - NVIDIA#6023 -> `docs/about/release-notes.mdx`: Summarizes registered-provider diagnostics for `inference set` failures. - NVIDIA#6074 -> `docs/about/release-notes.mdx`: Summarizes the refreshed NVIDIA Endpoints featured-model selection behavior. - NVIDIA#5969 -> `docs/about/release-notes.mdx`: Summarizes `credentials add` provider credential registration. - NVIDIA#6060 -> `docs/about/release-notes.mdx`: Summarizes mutable OpenClaw config permission restoration after `exec`. - NVIDIA#6134 -> `docs/about/release-notes.mdx`: Summarizes restored Tavily access for managed Python workflows. - NVIDIA#6089 -> `docs/about/release-notes.mdx`: Summarizes Hermes runtime version-scheme comparison during upgrade checks. - NVIDIA#6131 -> `docs/about/release-notes.mdx`: Summarizes OpenClaw gateway watchdog recovery behavior. - NVIDIA#5976 and NVIDIA#5990 -> `docs/about/release-notes.mdx`: Summarizes prompt stdin EOF cancellation behavior during onboarding. - NVIDIA#5540 -> `docs/about/release-notes.mdx`: Summarizes clarified host-level and per-sandbox status command scope. - NVIDIA#5978 and NVIDIA#6018 -> `docs/about/release-notes.mdx`: Summarizes policy-denial log breadcrumbs in connect shells. ## Testing - `npm run docs:sync-agent-variants` - `npm run docs` - Commit hooks passed during `git commit`, including commitlint and gitleaks. - Pre-push hook passed during `git push`, including TypeScript CLI and package/tag version sync. ## Checklist - [x] Documentation updated. - [x] `npm run docs` completed with 0 errors and 1 existing Fern warning. - [x] No source code or generated build artifacts committed. Signed-off-by: Miyoung Choi <miyoungc@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for v0.0.72 covering improved installer recovery, clearer CLI diagnostics, safer inference setup and provider switching, better credential handling, stronger policy boundaries, and more robust runtime repair behavior. * Updated network policy guidance to clarify when `allowed_ips` can be used, including a specific exception for the sandbox-to-host bridge endpoint. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Summary
nemoclaw <name> statuson a Hermes sandbox always reportedUpdate: v2026.6.19 availablebecause the staleness check compared the runtime semver against the manifest calver with a scheme-blind comparator.Related Issue
Fixes #6049
Changes
agents/hermes/manifest.yaml: pinexpected_versionto the semver the runtime reports.src/lib/sandbox/version.ts: skip the comparison when runtime and expected versions are in different schemes.scripts/update-hermes-agent.sh: align drift check and manifest pin withHERMES_SEMVER.Type of Change
Quality Gates
statusline; no new command or flag.src/lib/sandbox/version.ts.Verification
Verifiedin GitHubnpx prek run --from-ref main --to-ref HEADpassesnpm testpasses (broad runtime changes only)npm run docsbuilds without warnings (doc changes only)Signed-off-by: Tinson Lai tinsonl@nvidia.com
Summary by CodeRabbit