Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
58 commits
Select commit Hold shift + click to select a range
420f96b
fix(messaging): bind OpenClaw WeChat credentials
prekshivyas Aug 29, 2026
2294f33
fix(messaging): refresh sealed WeChat credentials
prekshivyas Aug 29, 2026
57a6c47
Merge branch 'main' into codex/fix-10079-openclaw-wechat-binding
prekshivyas Aug 29, 2026
c6bcc2a
fix(messaging): detect active WeChat accounts
prekshivyas Aug 29, 2026
1f9b57c
fix(messaging): preflight WeChat placeholder refresh
prekshivyas Aug 29, 2026
d0d8334
refactor(messaging): simplify WeChat refresh dispatch
prekshivyas Aug 29, 2026
66429a7
fix(messaging): order WeChat refresh before config writes
prekshivyas Aug 29, 2026
9ac6b97
test(messaging): prove WeChat runtime credential binding
prekshivyas Aug 29, 2026
ece29d1
merge(main): refresh PR validation base
prekshivyas Aug 29, 2026
89d5814
docs(messaging): clarify WeChat placeholder invariant
prekshivyas Aug 29, 2026
c827152
test(e2e): register WeChat runtime proof helpers
prekshivyas Aug 29, 2026
f9918d3
fix(messaging): clear OpenClaw WeChat account state
prekshivyas Aug 29, 2026
0b63a1d
fix(messaging): fail closed on WeChat removal
prekshivyas Aug 29, 2026
a6804dc
test(messaging): execute WeChat refresh boundary
prekshivyas Aug 29, 2026
043dd5a
test(e2e): remove WeChat source-shape assertion
prekshivyas Aug 29, 2026
0756a17
fix(messaging): recover failed WeChat removal
prekshivyas Aug 29, 2026
0f3bf90
fix(messaging): verify offline WeChat state mount
prekshivyas Aug 29, 2026
c95da08
fix(messaging): isolate offline WeChat volume
prekshivyas Aug 29, 2026
4a8b1d9
merge(main): refresh PR validation base
prekshivyas Aug 29, 2026
38efd25
test(messaging): stage WeChat refresh helper
prekshivyas Aug 30, 2026
633f3a1
merge(main): refresh PR validation base
prekshivyas Aug 30, 2026
66bfee3
fix(messaging): tighten WeChat lifecycle boundaries
prekshivyas Aug 30, 2026
11aeecf
test(messaging): pin WeChat cleanup paths
prekshivyas Aug 30, 2026
6c03dc3
refactor(messaging): centralize WeChat cleanup paths
prekshivyas Aug 30, 2026
60307cd
fix(messaging): diagnose stopped WeChat cleanup
prekshivyas Aug 30, 2026
57a2131
refactor(sandbox): invert channel cleanup dependency
prekshivyas Aug 30, 2026
46ffead
test(e2e): route WeChat fixture changes
prekshivyas Aug 30, 2026
38899ef
refactor(messaging): own WeChat cleanup state in manifest
prekshivyas Aug 30, 2026
9f88d07
merge(main): refresh PR validation base
prekshivyas Aug 30, 2026
cfaa17c
chore(runtime): refresh managed startup bundle
prekshivyas Aug 30, 2026
66d8c0f
fix(messaging): gate channel state cleanup by agent
prekshivyas Aug 30, 2026
4412ad9
test(messaging): remove source-shape import assertion
prekshivyas Aug 30, 2026
8595b03
fix(messaging): harden runtime credential refresh
prekshivyas Aug 30, 2026
377778f
merge(main): refresh PR validation base
prekshivyas Aug 30, 2026
0f02e4f
test(runtime): refresh reviewed bundle digest
prekshivyas Aug 30, 2026
fd43fdd
test(messaging): use Hermes credential boundary
prekshivyas Aug 30, 2026
398168b
docs(messaging): clarify stopped cleanup condition
prekshivyas Aug 30, 2026
425c003
test(e2e): bind Google Chat fixture at channel boundary
prekshivyas Aug 30, 2026
6adf351
test(e2e): cover Google Chat rebuild provider boundary
prekshivyas Aug 30, 2026
8dfe6f1
test(e2e): bind Google Chat fixture to startup registration
prekshivyas Aug 30, 2026
a3da32d
test(e2e): unify Google Chat startup boundary
prekshivyas Aug 30, 2026
c41151e
test(e2e): use named Google Chat fixture imports
prekshivyas Aug 30, 2026
6db670e
test(e2e): bind rebuild to Google Chat fixture
prekshivyas Aug 30, 2026
c66efc5
test(e2e): keep messaging fixtures behavior-focused
prekshivyas Aug 30, 2026
d49ed2a
test(cli): move onboarding import outside timeout
prekshivyas Aug 30, 2026
55f9bd7
merge(main): refresh PR validation base
prekshivyas Aug 30, 2026
aeeae73
docs(onboard): clarify policy sync fallback
prekshivyas Aug 30, 2026
47488fa
merge: resolve conflicts with main
github-actions[bot] Aug 30, 2026
07a5b9e
fix(wechat): harden runtime credential cleanup
senthilr-nv Aug 31, 2026
65cbc28
chore(runtime): refresh reviewed startup bundle
senthilr-nv Aug 31, 2026
6dd9805
fix(wechat): clarify cleanup recovery
senthilr-nv Aug 31, 2026
86a7a80
test(runtime): use explicit cleanup image oracle
senthilr-nv Aug 31, 2026
2825fbb
fix(wechat): improve cleanup recovery guidance
senthilr-nv Aug 31, 2026
d26ac5e
docs(wechat): explain stopped cleanup recovery
senthilr-nv Aug 31, 2026
653f269
fix(installer): admit wechat preload files
senthilr-nv Aug 31, 2026
9f6cc4c
fix(wechat): roll back partial account refresh
senthilr-nv Aug 31, 2026
58d904d
docs(wechat): qualify stopped cleanup fallback
senthilr-nv Aug 31, 2026
c3b5f1c
fix(wechat): narrow refresh abort handling
senthilr-nv Aug 31, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -580,6 +580,7 @@
COPY scripts/lib/openclaw_device_approval_policy.py /usr/local/lib/nemoclaw/openclaw_device_approval_policy.py
COPY scripts/lib/clean_runtime_shell_env_shim.py /usr/local/lib/nemoclaw/clean_runtime_shell_env_shim.py
COPY scripts/lib/normalize_mutable_config_perms.py /usr/local/lib/nemoclaw/normalize_mutable_config_perms.py
COPY scripts/lib/refresh-openclaw-wechat-placeholder.py /usr/local/lib/nemoclaw/refresh-openclaw-wechat-placeholder.py
COPY scripts/state-dir-guard.py /usr/local/lib/nemoclaw/state-dir-guard.py
COPY agents/openclaw/state-lock-plan.json /usr/local/share/nemoclaw/state-lock-plan.json
COPY scripts/openclaw-config-guard.py /usr/local/lib/nemoclaw/openclaw-config-guard.py
Expand Down Expand Up @@ -1584,10 +1585,10 @@
# CHAT_UI_URL is a non-loopback address (Brev Launchable, remote deployments)
# since terminal-based pairing is impossible in those contexts.
# Default: "0" (device auth enabled for local deployments — secure by default).
ARG NEMOCLAW_DISABLE_DEVICE_AUTH=0

Check warning on line 1588 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NEMOCLAW_DISABLE_DEVICE_AUTH") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 1588 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NEMOCLAW_DISABLE_DEVICE_AUTH") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
# Internal audit provenance for the opt-out above. Standard onboarding rewrites
# this to managed-onboard; direct image builders retain operator provenance.
ARG NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE=operator

Check warning on line 1591 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 1591 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ARG "NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
# Compatibility build arg for older custom Dockerfiles and rebuild tooling.
# NemoClaw-managed images intentionally do not consume it; gateway auth tokens
# are generated at container startup and are never baked into image layers.
Expand Down Expand Up @@ -1621,7 +1622,7 @@
# NEMOCLAW_MESSAGING_PLAN_B64 intentionally remains ARG-only: Docker exposes it
# to build RUN processes without retaining the full plan in the final image env.
# Direct ARG interpolation into inline source is a code injection vector (C-2).
ENV NEMOCLAW_MODEL=${NEMOCLAW_MODEL} \

Check warning on line 1625 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 1625 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "NEMOCLAW_DISABLE_DEVICE_AUTH") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 1625 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "NEMOCLAW_DISABLE_DEVICE_AUTH") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/

Check warning on line 1625 in Dockerfile

View workflow job for this annotation

GitHub Actions / PR build and direct managed startup (OpenClaw)

Sensitive data should not be used in the ARG or ENV commands

SecretsUsedInArgOrEnv: Do not use ARG or ENV instructions for sensitive data (ENV "NEMOCLAW_DEVICE_AUTH_OPT_OUT_SOURCE") More info: https://docs.docker.com/go/dockerfile/rule/secrets-used-in-arg-or-env/
NEMOCLAW_INFERENCE_PROVIDER_ID=${NEMOCLAW_INFERENCE_PROVIDER_ID} \
NEMOCLAW_UPSTREAM_PROVIDER=${NEMOCLAW_UPSTREAM_PROVIDER} \
NEMOCLAW_PRIMARY_MODEL_REF=${NEMOCLAW_PRIMARY_MODEL_REF} \
Expand Down
12 changes: 10 additions & 2 deletions docs/manage-sandboxes/manage-messaging-channels.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -69,9 +69,17 @@ The cleanup targets `/sandbox/.openclaw/<channel>/`.
The cleanup targets `/sandbox/.hermes/platforms/<channel>/`.
</AgentOnly>

It tries `openshell sandbox exec` and falls back to SSH if the first transport does not produce the success sentinel. If neither transport can reach a running sandbox, the command exits nonzero and asks you to start the sandbox and rerun it.
It tries `openshell sandbox exec` and falls back to SSH if the first transport does not produce the success sentinel.

NemoClaw leaves the registry and current OpenShell policy unchanged on that failure path so a later retry can complete cleanly.
<AgentOnly variant="openclaw">
For OpenClaw WeChat only, if neither transport succeeds, NemoClaw tries the stopped Docker fallback.
It confirms that the container belongs to the registered sandbox and has one writable Docker volume at `/sandbox`.
The helper removes only the WeChat state paths declared by the channel manifest.
Only when WeChat appears in neither the messaging plan nor the current OpenShell policy does NemoClaw treat state cleanup as complete without inspecting a volume if the registry entry is missing, the driver is not Docker, or no eligible stopped container exists.
</AgentOnly>

If the messaging plan or current OpenShell policy still records the channel and NemoClaw cannot confirm cleanup, the command exits nonzero with recovery guidance.
It leaves the bridge provider, credentials, registry, and current OpenShell policy unchanged so you can fix the reported condition and retry removal.

`channels remove whatsapp` clears the client-side Baileys session but cannot deregister the linked device with WhatsApp's servers after the local connection is gone. The phone continues to list the sandbox as a Linked Device until you remove it manually or WhatsApp's 14-day inactivity timeout expires.

Expand Down
Loading
Loading