Skip to content

fix(onboard): reject incompatible OpenClaw base images - #7606

Merged
prekshivyas merged 6 commits into
mainfrom
fix/openclaw-base-security-inventory
Jul 27, 2026
Merged

prekshivyas merged 6 commits into
mainfrom
fix/openclaw-base-security-inventory

Conversation

@sandl99

@sandl99 sandl99 commented Jul 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

OpenClaw onboarding now rejects a release base image that lacks the immutable security package inventory. The resolver refreshes the selected release once, then builds the current base locally instead of failing in the completed image's final layer.

Related Issue

Fixes #7605

Changes

  • Validate the OpenClaw base image's security inventory before completed-image construction.
  • Run the validation probe without network access, Linux capabilities, writable filesystem access, or privilege escalation.
  • Use the existing release resolver to refresh the exact selected release and build the current local base when it remains incompatible.
  • Preserve the resolver contract that does not substitute mutable latest for a selected release.
  • Add tests for the inventory probe and the release-to-local fallback.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Quality Gates

  • Tests added or updated for changed behavior
  • Existing tests cover changed behavior — justification:
  • Tests not applicable — justification:
  • Docs updated for user-facing behavior changes
  • Docs not applicable — justification: The commands reference already documents refresh-once, local-build fallback, disabled-build failure, and no mutable latest substitution.
  • Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging)
  • Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification:
  • Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue:

Documentation Writer Review

  • Documentation writer subagent reviewed the completed changes
  • Result: no-docs-needed
  • Evidence: docs/reference/commands.mdx already documents the resolver behavior. The latest source-loader fixture fix changes no command, option, required user action, or output contract.
  • Agent: Codex Desktop

DGX Station Hardware Evidence

  • Tested on DGX Station
  • Tested commit:
  • Station profile/scenario:
  • Result:
  • Supporting evidence:

Verification

  • PR description includes a Signed-off-by: line and every commit appears as Verified in GitHub
  • Normal pre-commit, commit-msg, and pre-push hooks passed, or npm run check:diff passed when hooks were skipped or unavailable
  • Targeted behavior tests pass for the current change set, or tests are marked not applicable above — command/result or justification: npx vitest run --project cli src/lib/onboard/base-image.test.ts src/lib/sandbox-base-image-release-resolution.test.ts passed 12 tests.
  • Applicable broad gate passed — npm test for broad runtime/test-harness changes; npm run check for repo-wide validation/coverage changes — command/result: Not run; the change is scoped to OpenClaw base-image resolution and has focused coverage.
  • Quality Gates section completed with required justifications or waivers
  • No secrets, API keys, or credentials committed
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: San Dang sdang@nvidia.com

Summary by CodeRabbit

  • Bug Fixes

    • Improved sandbox base-image validation by adding a security-inventory probe that verifies the inventory file exists, is not a symlink, matches expected ownership/permissions, and contains exact expected contents.
    • Enhanced sandbox base-image release resolution to correctly handle cases where the selected release predates the security inventory.
  • Tests

    • Added/extended tests to cover the security-inventory probe behavior and the local-image fallback scenario.
    • Updated Docker/subprocess test stubs and added a sandbox-hardening test to ensure consistent probe detection and runner capture handling.

Signed-off-by: San Dang <sdang@nvidia.com>
@sandl99 sandl99 added integration: openclaw OpenClaw integration behavior area: onboarding Onboarding FSM, provider setup, sandbox launch, or first-run flow area: sandbox OpenShell sandbox lifecycle, runtime, config, or recovery area: security Security controls, permissions, secrets, or hardening bug-fix PR fixes a bug or regression platform: container Affects Docker, containerd, Podman, or images labels Jul 27, 2026
@sandl99 sandl99 self-assigned this Jul 27, 2026
@coderabbitai

coderabbitai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

The change adds security inventory validation for OpenClaw base images, integrates it into release resolution, and tests local-build fallback when a pulled release image lacks the required inventory.

Changes

Base image validation

Layer / File(s) Summary
Security inventory probe
src/lib/onboard/base-image.ts, src/lib/onboard/base-image.test.ts
Adds a restricted Docker probe validating the inventory file and tests successful and empty probe results.
Release resolution fallback
src/lib/onboard/base-image.ts, src/lib/sandbox-base-image-release-resolution.test.ts
Uses the probe during image resolution and verifies local-build fallback for an incompatible release image.
Integration test harness support
test/helpers/onboard-script-mocks.cjs, test/shellquote-sandbox.test.ts, test/gateway-state-reconcile-2276.test.ts, test/rebuild-*.test.ts, test/repro-2201.test.ts
Updates mocked Docker handlers to detect the security-inventory probe and emit its expected marker.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Suggested reviewers: cv, apurvvkumaria, prekshivyas

Sequence Diagram(s)

sequenceDiagram
  participant Onboarding
  participant BaseImageResolver
  participant Docker
  participant LocalBuilder
  Onboarding->>BaseImageResolver: resolve sandbox base image
  BaseImageResolver->>Docker: pull exact release reference
  BaseImageResolver->>Docker: run security inventory validation
  Docker-->>BaseImageResolver: validation result
  BaseImageResolver->>LocalBuilder: build current base image when invalid
  LocalBuilder-->>BaseImageResolver: local image result
  LocalBuilder-->>Onboarding: return resolved base image
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The changes validate the security inventory, retry the exact release once, and fall back to a local build when the release remains incompatible, matching #7605.
Out of Scope Changes check ✅ Passed The diff appears scoped to the onboarding validation change and its supporting tests and mocks.
Docstring Coverage ✅ Passed Docstring coverage is 80.00% which is sufficient. The required threshold is 80.00%.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly matches the main change: onboarding now rejects incompatible OpenClaw base images.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/openclaw-base-security-inventory

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in commit d22283e in the fix/openclaw-base-se... branch remains at 96%, unchanged from commit 87270de in the main branch.

TypeScript / code-coverage/cli

The overall coverage in commit d22283e in the fix/openclaw-base-se... branch is 81%. The coverage in commit 0b18549 in the main branch is 80%.

Show a code coverage summary of the most impacted files.
File main 0b18549 fix/openclaw-base-se... d22283e +/-
src/lib/domain/.../connect-env.ts 97% 89% -8%
src/lib/shields/index.ts 71% 72% +1%
src/lib/onboard...eway-service.ts 81% 82% +1%
src/lib/actions...dbox/destroy.ts 93% 95% +2%
src/lib/actions...e-validation.ts 81% 84% +3%
src/lib/onboard...shboard-port.ts 90% 93% +3%
src/lib/actions...x/mcp-bridge.ts 35% 41% +6%
src/lib/actions...lution-probe.ts 88% 95% +7%
src/lib/actions...-add-restart.ts 10% 19% +9%
src/lib/actions...time-command.ts 82% 100% +18%

Updated July 27, 2026 07:03 UTC

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/lib/onboard/base-image.test.ts`:
- Around line 22-40: Strengthen the test for
openClawBaseImageHasSecurityInventory by explicitly asserting every mandatory
probe safeguard in the dockerMocks.capture command: --cap-drop ALL,
no-new-privileges, the pinned shell entrypoint, and the symlink, ownership, and
content validation fragments, while retaining the existing network, read-only,
inventory-path, and timeout assertions.

In `@src/lib/sandbox-base-image-release-resolution.test.ts`:
- Around line 211-235: Update the test around resolveSandboxBaseImage to assert
dockerMocks.pull is called exactly once and state.validateImage receives
RELEASE_REF twice in order, proving both the initial and post-refresh
validations while retaining the existing local-build expectations.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 3c973110-57aa-4805-bad8-8b913c6c8890

📥 Commits

Reviewing files that changed from the base of the PR and between 0b18549 and 4eee7a0.

📒 Files selected for processing (3)
  • src/lib/onboard/base-image.test.ts
  • src/lib/onboard/base-image.ts
  • src/lib/sandbox-base-image-release-resolution.test.ts

Comment thread src/lib/onboard/base-image.test.ts
Comment thread src/lib/sandbox-base-image-release-resolution.test.ts
@github-actions

github-actions Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

PR Review Advisor — No blocking findings reported

Advisor assessment: No blocking advisor findings reported
Next action: No advisor follow-up needed.
Findings: 0 blockers · 0 warnings · 0 suggestions

Model lanes

  • GPT-5.6 Terra (primary): Completed · medium confidence · 0 blockers · 0 warnings · 0 suggestions
  • Nemotron 3 Ultra (second opinion): Completed · high confidence · 1 blocker · 2 warnings · 1 suggestion
  • Model comparison: normalized findings differ; normalized E2E selections differ; Nemotron reported 1 more blocker, 2 more warnings, 1 more suggestion.

Nemotron output stays in workflow artifacts and does not change the assessment above.

E2E guidance

Advisory only. E2E / PR Gate selects and runs jobs independently.

Recommended E2E: onboard-repair, onboard-resume, cloud-onboard

1 optional E2E recommendation
  • rebuild-openclaw

Workflow run details

This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@test/helpers/onboard-script-mocks.cjs`:
- Around line 71-77: Strengthen the inventory probe validation in
mockOnboardRunCapture and the embedded Docker stubs so success requires the
complete probe contract, including Docker isolation and the expected
inventory-check arguments, not merely the success marker. Reuse shared helper
logic where practical. Apply this in
test/helpers/onboard-script-mocks.cjs:71-77,
test/gateway-state-reconcile-2276.test.ts:275,
test/rebuild-credential-preflight.test.ts:305,
test/rebuild-shields-auto-unlock.test.ts:249,
test/rebuild-stale-recovery.test.ts:187, and test/repro-2201.test.ts:313-316;
preserve success only for valid probes and reject weakened commands.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: dcbc2c37-801e-4b8e-a597-b83ef1174d9e

📥 Commits

Reviewing files that changed from the base of the PR and between 4eee7a0 and 13586f8.

📒 Files selected for processing (8)
  • src/lib/onboard/base-image.test.ts
  • src/lib/sandbox-base-image-release-resolution.test.ts
  • test/gateway-state-reconcile-2276.test.ts
  • test/helpers/onboard-script-mocks.cjs
  • test/rebuild-credential-preflight.test.ts
  • test/rebuild-shields-auto-unlock.test.ts
  • test/rebuild-stale-recovery.test.ts
  • test/repro-2201.test.ts
🚧 Files skipped from review as they are similar to previous changes (2)
  • src/lib/onboard/base-image.test.ts
  • src/lib/sandbox-base-image-release-resolution.test.ts

Comment thread test/helpers/onboard-script-mocks.cjs Outdated
Signed-off-by: San Dang <sdang@nvidia.com>
@sandl99
sandl99 requested review from apurvvkumaria and cv July 27, 2026 06:05
@apurvvkumaria apurvvkumaria self-assigned this Jul 27, 2026
apurvvkumaria and others added 2 commits July 26, 2026 23:33
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: San Dang <sdang@nvidia.com>
@prekshivyas
prekshivyas merged commit b77e9e8 into main Jul 27, 2026
97 of 101 checks passed
@prekshivyas
prekshivyas deleted the fix/openclaw-base-security-inventory branch July 27, 2026 08:03
@cv cv mentioned this pull request Jul 27, 2026
10 of 23 tasks
cv added a commit that referenced this pull request Jul 27, 2026
<!-- markdownlint-disable MD041 -->
## Summary

`docs/changelog/2026-07-25.mdx` now includes the user-facing fixes that
merged after #7607 and before the v0.0.96 tag.
The follow-up covers safer bulk backup and clone restore behavior,
policy and inference repairs, cleaner onboarding diagnostics, and
OpenClaw base-image validation while leaving test-only and
maintainer-internal merges out of the release entry.

## Changes

- Document the Shields-safe `backup-all` flow from #7557 and the
clone-specific restore pairing publication from #7608.
- Record the Claude Code resolved-launcher policy repair from #7581,
Hermes namespaced-model handling from #7604, and persisted Ollama
proxy-token reuse from #7620.
- Record OpenClaw immutable base-inventory validation from #7606, hidden
route-only reservations from #7621, and clean invalid gateway-management
errors from #7630.
- Link the gateway lifecycle and snapshot authorities, retain #7622's
already-merged Docker Engine wording, and exclude internal or test-only
merges from the release entry.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates

- [ ] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [x] Tests not applicable — justification: This PR changes
release-entry prose only. The changelog contract test and Fern
validation cover the dated entry, published routes, and rendering
requirements.
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## Documentation Writer Review

- [x] Documentation writer subagent reviewed the completed changes
- Result: `docs-updated`
- Evidence: At exact PR head `29316da26`, a Codex Desktop documentation
writer reviewed `docs/changelog/2026-07-25.mdx` against `AGENTS.md`,
`WRITING.md`, and `docs/CONTRIBUTING.md`. The review confirmed that the
full entry accurately reflects the merged user-visible behavior, retains
#7622's existing wording, appropriately excludes internal and test-only
PRs, and uses conforming terminology, structure, links, and release
classification. It also confirmed that the review follow-ups use active
third-person release-entry voice, name the actor and recovery
requirement directly, and accurately preserve the trusted-backup,
cached-release refresh, and local-build fallback constraints. The
changelog test passed 6/6, and the docs build completed with 0 errors
and 2 pre-existing hidden warnings.
- Agent: Codex Desktop
<!-- docs-review-head-sha: 29316da -->
<!-- docs-review-agents-blob-sha: be20a09 -->

## DGX Station Hardware Evidence

- [ ] Tested on DGX Station
- Tested commit:
- Station profile/scenario:
- Result:
- Supporting evidence:

## Verification

- [x] PR description includes a `Signed-off-by:` line and every commit
appears as `Verified` in GitHub
- [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or
`npm run check:diff` passed when hooks were skipped or unavailable
- [x] Targeted behavior tests pass for the current change set, or tests
are marked not applicable above — command/result or justification: `npx
vitest run test/changelog-docs.test.ts` passed 6/6 tests after the final
review fix.
- [ ] Applicable broad gate passed — `npm test` for broad
runtime/test-harness changes; `npm run check` for repo-wide
validation/coverage changes — command/result: Not applicable to this
prose-only changelog change.
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only) — exited
0 with 0 errors and 2 pre-existing hidden warnings after the final
review fix.
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

---
Signed-off-by: Carlos Villela <cvillela@nvidia.com>


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Expanded the changelog to clarify persistent `policy exclude`/`policy
restore` behavior across rebuilds and snapshot restores, including
reporting on removed endpoints and exclusion consistency.
* Updated `claude-code` preset guidance to allow the npm-installed
OpenShell launcher path while maintaining endpoint/HTTP method scope.
* Documented hardened handling for invalid gateway-management
declarations, improved gateway/agent-version diagnostics scope, and
clarified onboarding/restore credential and reasoning precedence.
* Tightened bulk backup/restore guidance (safety windows, approval
limits, and failure recovery) and refined OpenClaw base selection to
avoid incompatible cached releases and `:latest` fallback.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: onboarding Onboarding FSM, provider setup, sandbox launch, or first-run flow area: sandbox OpenShell sandbox lifecycle, runtime, config, or recovery area: security Security controls, permissions, secrets, or hardening bug-fix PR fixes a bug or regression integration: openclaw OpenClaw integration behavior platform: container Affects Docker, containerd, Podman, or images

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OpenClaw onboarding accepts a release base without its required security inventory

3 participants