Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
144 commits
Select commit Hold shift + click to select a range
7d449f8
feat(install): add native Windows candidate installer
ericksoa Sep 1, 2026
2d52feb
fix(install): enforce native qualification boundary
ericksoa Sep 1, 2026
c8eacb9
Merge remote-tracking branch 'origin/main' into feat/windows-native-i…
ericksoa Sep 1, 2026
1fa7e17
ci(windows): cache the pinned OpenShell build
ericksoa Sep 1, 2026
94ad38a
ci(windows): build only the qualified payload
ericksoa Sep 1, 2026
b833363
fix(install): own candidate recovery and drift
ericksoa Sep 1, 2026
a8e4fe2
fix(install): serialize native candidate recovery
ericksoa Sep 1, 2026
ce5d958
fix(install): tighten native candidate ownership
ericksoa Sep 1, 2026
d402736
test(windows): prove native candidate execution
ericksoa Sep 1, 2026
9df5c56
ci(windows): isolate native installer dispatch
ericksoa Sep 1, 2026
4c89232
test(windows): audit installer process starts
ericksoa Sep 1, 2026
5e808e2
fix(windows): release process audit subscription
ericksoa Sep 1, 2026
b14b3c5
test(windows): baseline hosted runner processes
ericksoa Sep 1, 2026
21b8c69
fix(windows): create exclusive installer lock
ericksoa Sep 1, 2026
ef0edd2
fix(windows): atomically replace installer receipts
ericksoa Sep 1, 2026
e4d90f8
test(windows): accept empty process audit
ericksoa Sep 1, 2026
b803b65
test(windows): harden native qualification evidence
ericksoa Sep 1, 2026
d185049
feat(install): package native Windows ARM64 candidate
ericksoa Sep 1, 2026
3b8ded5
fix(ci): select pinned Windows packaging SDK
ericksoa Sep 1, 2026
ee8dba7
fix(install): restrict native package upgrades
ericksoa Sep 1, 2026
d168651
fix(install): load pinned Burn UI extension
ericksoa Sep 1, 2026
3432028
fix(install): resolve pinned Burn extension path
ericksoa Sep 1, 2026
be5d5ed
fix(install): restore Burn extension deterministically
ericksoa Sep 2, 2026
3dd80ef
fix(install): explicitly restore pinned WiX packages
ericksoa Sep 2, 2026
c1b9e1a
fix(test): attribute native package process starts
ericksoa Sep 2, 2026
9594a7b
fix(install): build MSI and Burn bundle in phases
ericksoa Sep 2, 2026
9f32046
test(windows): record native installer proof video
ericksoa Sep 2, 2026
2eda6ed
fix(test): attribute remaining Windows processes
ericksoa Sep 2, 2026
b079406
fix(test): select versioned Windows metadata
ericksoa Sep 2, 2026
c5eb5e7
fix(test): compile Windows proof encoder with csc
ericksoa Sep 2, 2026
acbfdac
fix(test): reference Windows encoder facade
ericksoa Sep 2, 2026
f332eec
fix(test): await proof image clips
ericksoa Sep 2, 2026
e7e7109
fix(test): release proof encoder assembly file
ericksoa Sep 2, 2026
3ff04f5
test(windows): screen-record native install console
ericksoa Sep 2, 2026
8d63654
test(windows): record GitHub download and install
ericksoa Sep 2, 2026
1042a54
fix(test): allow initial live console frame
ericksoa Sep 2, 2026
3645738
test(windows): capture real installer windows
ericksoa Sep 2, 2026
fd29c69
fix(test): tolerate closing installer windows
ericksoa Sep 2, 2026
eb79a93
feat(install): package the native NemoClaw runtime
ericksoa Sep 2, 2026
5b965df
test(windows): require an installed NemoClaw turn
ericksoa Sep 2, 2026
2a248fc
fix(install): package versionless runtime payloads
ericksoa Sep 2, 2026
d4471ab
fix(test): isolate console execution to NemoClaw
ericksoa Sep 2, 2026
479b36e
fix(test): launch installed CLI on PowerShell 5
ericksoa Sep 2, 2026
c209640
fix(test): keep MXC host preparation external
ericksoa Sep 2, 2026
5475f6a
fix(windows): bound the native sandbox name
ericksoa Sep 2, 2026
6f44a32
fix(windows): stage the native artifact shallowly
ericksoa Sep 2, 2026
4fb8cd7
test(windows): retain sanitized MXC diagnostics
ericksoa Sep 2, 2026
8dd76a4
fix(windows): provide the sandbox process environment
ericksoa Sep 2, 2026
2b72dc9
fix(install): prepare MXC null device in setup
ericksoa Sep 2, 2026
ac48721
fix(install): keep null preparation boot-scoped
ericksoa Sep 2, 2026
428957b
fix(install): model boot-ephemeral MXC preparation
ericksoa Sep 2, 2026
eb5ddee
fix(install): prepare the MXC system drive
ericksoa Sep 2, 2026
bffb031
fix(install): separate MXC prerequisite cache ids
ericksoa Sep 2, 2026
07878a2
fix(install): separate MXC prerequisite payloads
ericksoa Sep 2, 2026
4306e7e
fix(test): bound full package operations realistically
ericksoa Sep 2, 2026
4aae7e0
fix(windows): enable Node UI compatibility in OpenShell
ericksoa Sep 2, 2026
8b55f32
test(windows): report failed sandbox probe results
ericksoa Sep 2, 2026
33d01a5
fix(windows): allow the OpenClaw process tree
ericksoa Sep 2, 2026
995d98a
test(windows): record the installed NemoClaw turn
ericksoa Sep 2, 2026
df42e2f
test(windows): bind proof to the full runtime
ericksoa Sep 2, 2026
32297ad
fix(windows): normalize the OpenClaw version receipt
ericksoa Sep 2, 2026
2c7c2a7
fix(ci): bind the runtime cache to the OpenShell patch
ericksoa Sep 2, 2026
2253765
fix(ci): forbid stale native runtime cache fallback
ericksoa Sep 2, 2026
7fa8f9e
fix(windows): run OpenClaw inside the MXC process
ericksoa Sep 2, 2026
c032a7f
chore(windows): remove an unused runtime import
ericksoa Sep 2, 2026
2f63b60
fix(windows): grant the staged runtime root read-only
ericksoa Sep 2, 2026
c6d8a32
fix(windows): detach the completed OpenShell watcher
ericksoa Sep 2, 2026
27745da
test(windows): keep the video focused on proof of life
ericksoa Sep 2, 2026
ef83c08
fix(install): exclude unused MXC backends
ericksoa Sep 2, 2026
2b68f38
fix(test): make process lineage lifecycle-aware
ericksoa Sep 2, 2026
91a447c
fix(windows): bind exact payload and cleanup evidence
ericksoa Sep 3, 2026
d97041e
fix(windows): remove dead cleanup assignment
ericksoa Sep 3, 2026
d6d2e8a
feat(windows): add branded three-turn web proof
ericksoa Sep 3, 2026
5862b73
feat(windows): add graphical agent onboarding
ericksoa Sep 3, 2026
f3fe553
fix(windows): select pinned launcher toolchain
ericksoa Sep 3, 2026
5033c7d
fix(windows): retain launcher install path
ericksoa Sep 3, 2026
da3436f
fix(windows): keep shortcuts out of user profile
ericksoa Sep 3, 2026
d5b0234
fix(windows): isolate bundle localization
ericksoa Sep 3, 2026
704fd79
fix(windows): await and diagnose web ui launch
ericksoa Sep 3, 2026
6795d13
fix(windows): connect and expose native onboarding
ericksoa Sep 3, 2026
971bd4f
fix(windows): disable unqualified agent choices
ericksoa Sep 3, 2026
396a048
feat(windows): package and qualify native Pi
ericksoa Sep 3, 2026
2f2df9e
feat(windows): replace stock setup with native experience
ericksoa Sep 3, 2026
3a51db1
feat(windows): package native Hermes candidate
ericksoa Sep 3, 2026
fbce77a
feat(windows): package native Deep Agents candidate
ericksoa Sep 3, 2026
921a991
feat(windows): add native experimental NemoCUA
ericksoa Sep 3, 2026
f2464e0
fix(windows): use MXC fallback loopback contract
ericksoa Sep 3, 2026
9947945
feat(windows): qualify every graphical agent choice
ericksoa Sep 3, 2026
63a9619
feat(windows): emit per-agent raw proof videos
ericksoa Sep 3, 2026
4815184
fix(windows): group payload below MSI component limit
ericksoa Sep 3, 2026
4849749
feat(windows): launch every configured native agent
ericksoa Sep 3, 2026
0aac82d
docs(windows): cover every executable signing gate
ericksoa Sep 3, 2026
c81dc8c
test(windows): bind agent receipts to installed payloads
ericksoa Sep 3, 2026
590888d
fix(windows): authenticate graphical onboarding session
ericksoa Sep 3, 2026
40d0f9e
fix(windows): keep complete onboarding window visible
ericksoa Sep 3, 2026
8697371
fix(windows): frame proof windows at full aspect
ericksoa Sep 3, 2026
d421215
docs(windows): describe credential handling accurately
ericksoa Sep 3, 2026
7b9d781
fix(windows): assign stable grouped component GUIDs
ericksoa Sep 3, 2026
5b39c78
fix(windows): bind credential probe arguments exactly
ericksoa Sep 3, 2026
16e5154
fix(security): update vulnerable fast-uri graphs (#10892)
jyaunches Sep 2, 2026
210ad84
fix(windows): embed complete managed BA payload
ericksoa Sep 3, 2026
1835073
fix(windows): attach managed BA payload group
ericksoa Sep 3, 2026
fd64ef6
merge: resolve conflicts with main
github-actions[bot] Sep 3, 2026
6d47532
fix(windows): author WiX 5 BA payloads explicitly
ericksoa Sep 3, 2026
e3447f4
merge: preserve concurrent branch update
ericksoa Sep 3, 2026
86bbc95
Revert "merge: resolve conflicts with main"
ericksoa Sep 3, 2026
50f4679
fix(windows): ship loadable single-file bootstrapper
ericksoa Sep 3, 2026
68debc9
fix(windows): isolate bootstrapper UI apartment
ericksoa Sep 3, 2026
2400d18
fix(windows): pump the Burn engine dispatcher
ericksoa Sep 3, 2026
9c0aeb5
ci(windows): add package startup diagnostic
ericksoa Sep 4, 2026
3b55fdf
fix(windows): provide Burn apply owner window
ericksoa Sep 4, 2026
d09750f
fix(windows): run OpenClaw Control UI inside MXC
ericksoa Sep 4, 2026
d557373
fix(windows): isolate Edge qualification profile
ericksoa Sep 4, 2026
dffc854
fix(windows): relay MXC Control UI to host Edge
ericksoa Sep 4, 2026
0f4e352
fix(windows): reach host UI relay from MXC
ericksoa Sep 4, 2026
e542aa8
fix(windows): bridge MXC UI over shared files
ericksoa Sep 4, 2026
18464f4
fix(windows): advance deterministic UI turns
ericksoa Sep 4, 2026
5c32ad6
ci(windows): diagnose every installed agent
ericksoa Sep 4, 2026
8c1b7fc
fix(windows): gate agent diagnostics on receipt
ericksoa Sep 4, 2026
f4eef71
fix(windows): unblock remaining native agents
ericksoa Sep 4, 2026
d4cf05b
ci(windows): stage complete native diagnostic runtime
ericksoa Sep 4, 2026
3b54151
fix(windows): complete native agent runtimes
ericksoa Sep 4, 2026
d5a3d23
fix(windows): recognize tagged tiktoken extension
ericksoa Sep 4, 2026
b8f7f15
fix(windows): inherit MXC temp directory access
ericksoa Sep 4, 2026
8c74606
fix(windows): expose Deep runtime to subprocesses
ericksoa Sep 4, 2026
ff256cb
fix(windows): support LangGraph on Python 3.13
ericksoa Sep 4, 2026
485ade9
fix(windows): preserve LangGraph patch bytes
ericksoa Sep 4, 2026
826621a
ci(windows): preserve Deep server diagnostics
ericksoa Sep 4, 2026
5eb1be9
fix(windows): include Deep console runtime
ericksoa Sep 4, 2026
32fb244
fix(windows): complete Deep server native runtime
ericksoa Sep 4, 2026
3060eeb
fix(windows): keep Deep in-memory runtime grpc-free
ericksoa Sep 4, 2026
99557b7
fix(windows): complete Deep QuickJS runtime
ericksoa Sep 4, 2026
d1899c2
fix(windows): preserve Deep runtime DACLs
ericksoa Sep 4, 2026
b806274
fix(windows): inherit DACLs for Deep temp files
ericksoa Sep 4, 2026
3f0a919
fix(windows): capture full qualification video
ericksoa Sep 4, 2026
6766c18
fix(windows): validate recorded agent summaries
ericksoa Sep 5, 2026
b285014
Merge remote-tracking branch 'origin/main' into feat/windows-native-i…
ericksoa Sep 5, 2026
e0bc9e1
fix(windows): align native env allowlist with main
ericksoa Sep 5, 2026
84d4169
fix(windows): restrict Deep temporary file mode
ericksoa Sep 5, 2026
349ab13
refactor(windows): isolate native preview from mainline
ericksoa Sep 5, 2026
b0c3874
ci(windows): qualify additive preview workflow
ericksoa Sep 5, 2026
5026563
fix(windows): wait for native launcher qualification
ericksoa Sep 5, 2026
ede9f59
fix(windows): replay validated agent turn in proof
ericksoa Sep 5, 2026
9d2daca
fix(windows): fence process audit PID generations
ericksoa Sep 5, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
620 changes: 620 additions & 0 deletions .github/workflows/windows-native-installer.yaml

Large diffs are not rendered by default.

39 changes: 39 additions & 0 deletions packaging/windows/Bundle.wxs
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<Wix xmlns="http://wixtoolset.org/schemas/v4/wxs">
<Bundle
Name="NemoClaw"
Manufacturer="NVIDIA Corporation"
Version="$(var.ProductVersion)"
UpgradeCode="1BA739B8-B632-4A8C-BB02-95058CC3A960"
IconSourceFile="$(var.SourceRoot)\packaging\windows\assets\NemoClaw.ico"
AboutUrl="https://github.com/NVIDIA/NemoClaw"
Copyright="Copyright (c) 2026 NVIDIA Corporation and affiliates">
<BootstrapperApplication SourceFile="$(var.BootstrapperPath)">
<PayloadGroupRef Id="NemoClawBootstrapperPayloads" />
</BootstrapperApplication>
<Chain>
<ExePackage
Id="MxcSystemDrivePreparation"
CacheId="MxcSystemDrivePreparation-0.8.0-arm64"
Name="mxc\wxc-host-prep-system-drive.exe"
SourceFile="$(var.WxcHostPrepPath)"
InstallArguments="prepare-system-drive"
PerMachine="yes"
Permanent="yes"
Compressed="yes"
Vital="yes" />
<ExePackage
Id="MxcNullDevicePreparation"
CacheId="MxcNullDevicePreparation-0.8.0-arm64"
Name="mxc\wxc-host-prep-null-device.exe"
SourceFile="$(var.WxcHostPrepPath)"
InstallArguments="prepare-null-device"
PerMachine="yes"
Permanent="yes"
Compressed="yes"
Vital="yes" />
<MsiPackage Id="NemoClawArm64Msi" SourceFile="$(var.MsiPath)" Compressed="yes" Vital="yes" />
</Chain>
</Bundle>
</Wix>
14 changes: 14 additions & 0 deletions packaging/windows/License.rtf
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{\rtf1\ansi\deff0
{\fonttbl{\f0 Segoe UI;}}
\fs20
NemoClaw Native Windows Candidate Preview\par
\par
Copyright (c) 2026 NVIDIA Corporation and affiliates.\par
\par
NemoClaw is licensed under the Apache License, Version 2.0. The complete
license is installed with the product as LICENSE.txt and is available in the
NemoClaw source repository.\par
\par
This package is a qualification candidate. It does not establish production
support for native Windows, Microsoft MXC, or any agent runtime.\par
}
21 changes: 21 additions & 0 deletions packaging/windows/MXC-LICENSE.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
MIT License

Copyright (c) Microsoft Corporation.

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.
54 changes: 54 additions & 0 deletions packaging/windows/NATIVE-PREVIEW.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
NemoClaw Native Windows Candidate Preview

This package contains the NemoClaw CLI, Node.js 22.22.3, OpenClaw 2026.7.1,
native Windows ARM64 builds of openshell.exe and openshell-gateway.exe from
NVIDIA/OpenShell#2721 merge commit bcd517bbe08cc80860c9be57699390cd32e8445f,
and the pinned Microsoft MXC 0.8.0 ARM64 wxc-exec.exe and wxc-host-prep.exe
ProcessContainer tools. WSLC and other unused backend sidecars are excluded.

The packaged OpenShell gateway is a source-built NVIDIA/OpenShell#2721
derivative with the checked-in OPENSHELL-NODE-UI-COMPATIBILITY.patch applied.
That compatibility change emits ui.disable=false so the contained Node.js
process can initialize. The qualification turn runs OpenClaw in a worker inside
that same process; MXC filesystem containment remains active.

The pinned OpenShell create watcher does not return after the one-shot workload
completes. NemoClaw stops that client-side watcher after receiving the exact
workload result, then deletes the sandbox through OpenShell.

The NVIDIA-branded setup installs a native ARM64 NemoClaw GUI launcher and a
graphical first-run experience. The interface names OpenClaw, Hermes Agent,
LangChain Deep Agents Code, Pi, and NemoCUA, with Pi and NemoCUA explicitly
marked experimental. Every enabled choice has an agent-specific executable
adapter: OpenClaw opens its authentic Control UI, Hermes Agent, Deep Agents
Code, and Pi open their native terminal surfaces, and NemoCUA runs its bounded
experimental visible-browser implementation. A choice is not a production
support claim until its exact package qualification passes.

CI separately drives three deterministic turns through each real agent runtime
inside native MXC. OpenClaw uses its Control UI; terminal agents use their
genuine non-interactive CLI modes; NemoCUA observes and acts on real Edge
pixels. The deterministic loopback model proves transport and runtime wiring
without a pull-request secret; it is not production inference quality.

Graphical onboarding collects the selected provider endpoint and model.
Provider API keys are written by the native ARM64 launcher to Windows
Credential Manager and are not stored in MSI-owned files or JSON. Agent state
and secret-free configuration live below the current user's Local AppData.
Runtime processes receive only an authenticated, ephemeral loopback broker
route; the provider credential remains on the Windows host.

The setup executable applies Microsoft MXC's elevated prepare-system-drive and
prepare-null-device host prerequisites before installing the MSI. Windows
resets the null-device prerequisite at reboot; persistent production lifecycle
ownership remains deferred.

This is a qualification candidate, not a production support claim. Native MXC
execution remains limited by the Windows host build and capabilities. Gateway
service registration, messaging, web-search integration, managed local-model
lifecycle, and production activation remain incomplete. Mutable runtime state
stays outside this MSI-owned installation directory.

PR qualification artifacts are unsigned. Production use remains gated on
Authenticode signing of the NemoClaw, OpenClaw, OpenShell, MXC, MSI, and setup
payloads as applicable.
35 changes: 35 additions & 0 deletions packaging/windows/NemoClaw.Bundle.wixproj
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<Project Sdk="WixToolset.Sdk/5.0.2">
<PropertyGroup>
<OutputType>Bundle</OutputType>
<InstallerPlatform>arm64</InstallerPlatform>
<OutputName>NemoClawSetup-$(ProductVersion)-windows-arm64</OutputName>
<OutputPath>$(PackageOutputRoot)</OutputPath>
<IntermediateOutputPath>$(PackageIntermediateRoot)\bundle\</IntermediateOutputPath>
<EnableDefaultCompileItems>false</EnableDefaultCompileItems>
<EnableDefaultEmbeddedResourceItems>false</EnableDefaultEmbeddedResourceItems>
<DefineConstants>$(DefineConstants);ProductVersion=$(ProductVersion);SourceRoot=$(SourceRoot);MsiPath=$(MsiPath);WxcHostPrepPath=$(PayloadRoot)\mxc\wxc-host-prep.exe;BootstrapperPath=$(BootstrapperPath);BootstrapperRoot=$(BootstrapperRoot)</DefineConstants>
<TreatWarningsAsErrors>true</TreatWarningsAsErrors>
<!-- The null-device prerequisite is boot-ephemeral by Windows design, so a
durable DetectCondition would incorrectly skip it after reboot. -->
<SuppressSpecificWarnings>1161</SuppressSpecificWarnings>
<DebugType>none</DebugType>
</PropertyGroup>
<ItemGroup>
<Compile Include="Bundle.wxs" />
<Compile Include="$(GeneratedBootstrapperPayloadAuthoring)" />
</ItemGroup>
<Target Name="ValidateNemoClawBundleInputs" BeforeTargets="ResolveWixExtensionReferences">
<Error Condition="'$(MsiPath)' == ''" Text="MsiPath is required." />
<Error Condition="!Exists('$(MsiPath)')" Text="The ARM64 MSI input is missing." />
<Error Condition="!Exists('$(PayloadRoot)\mxc\wxc-host-prep.exe')" Text="The pinned ARM64 MXC host-preparation input is missing." />
<Error Condition="!Exists('$(PayloadRoot)\bin\NemoClaw.exe')" Text="The NemoClaw UI launcher is missing." />
<Error Condition="'$(BootstrapperPath)' == ''" Text="BootstrapperPath is required." />
<Error Condition="!Exists('$(BootstrapperPath)')" Text="The native ARM64 NemoClaw bootstrapper application is missing." />
<Error Condition="'$(BootstrapperRoot)' == ''" Text="BootstrapperRoot is required." />
<Error Condition="!Exists('$(BootstrapperRoot)\mbanative.dll')" Text="The native WiX managed-bootstrapper bridge is missing." />
<Error Condition="'$(GeneratedBootstrapperPayloadAuthoring)' == ''" Text="GeneratedBootstrapperPayloadAuthoring is required." />
<Error Condition="!Exists('$(GeneratedBootstrapperPayloadAuthoring)')" Text="The generated bootstrapper payload authoring is missing." />
</Target>
</Project>
54 changes: 54 additions & 0 deletions packaging/windows/NemoClaw.wixproj
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<Project Sdk="WixToolset.Sdk/5.0.2">
<PropertyGroup>
<OutputType>Package</OutputType>
<InstallerPlatform>arm64</InstallerPlatform>
<OutputName>NemoClaw-$(ProductVersion)-windows-arm64</OutputName>
<OutputPath>$(PackageOutputRoot)</OutputPath>
<IntermediateOutputPath>$(PackageIntermediateRoot)\msi\</IntermediateOutputPath>
<EnableDefaultCompileItems>false</EnableDefaultCompileItems>
<EnableDefaultEmbeddedResourceItems>false</EnableDefaultEmbeddedResourceItems>
<DefineConstants>$(DefineConstants);ProductVersion=$(ProductVersion);PayloadRoot=$(PayloadRoot);SourceRoot=$(SourceRoot)</DefineConstants>
<TreatWarningsAsErrors>true</TreatWarningsAsErrors>
<!-- Locked npm graphs contain three versionless native payloads. They remain
MSI-hashed, exact-manifest-qualified, repairable files; suppress only
ICE60's optional PE version/language metadata rule. -->
<SuppressIces>ICE60</SuppressIces>
<DebugType>none</DebugType>
</PropertyGroup>
<ItemGroup>
<Compile Include="Product.wxs" />
<Compile Include="$(GeneratedPayloadAuthoring)" />
</ItemGroup>
<Target Name="ValidateNemoClawPackageInputs" BeforeTargets="Build">
<Error Condition="'$(ProductVersion)' == ''" Text="ProductVersion is required." />
<Error Condition="'$(PayloadRoot)' == ''" Text="PayloadRoot is required." />
<Error Condition="'$(SourceRoot)' == ''" Text="SourceRoot is required." />
<Error Condition="'$(GeneratedPayloadAuthoring)' == ''" Text="GeneratedPayloadAuthoring is required." />
<Error Condition="!Exists('$(GeneratedPayloadAuthoring)')" Text="The grouped payload authoring is missing." />
<Error Condition="!Exists('$(PayloadRoot)\bin\openshell.exe')" Text="The ARM64 openshell.exe payload is missing." />
<Error Condition="!Exists('$(PayloadRoot)\bin\openshell-gateway.exe')" Text="The ARM64 openshell-gateway.exe payload is missing." />
<Error Condition="!Exists('$(PayloadRoot)\bin\node.exe')" Text="The ARM64 Node.js runtime is missing." />
<Error Condition="!Exists('$(PayloadRoot)\bin\NemoClaw.exe')" Text="The ARM64 NemoClaw launcher is missing." />
<Error Condition="!Exists('$(PayloadRoot)\bin\nemoclaw.cmd')" Text="The NemoClaw launcher is missing." />
<Error Condition="!Exists('$(PayloadRoot)\nemoclaw\app\bin\nemoclaw.js')" Text="The NemoClaw CLI package is missing." />
<Error Condition="!Exists('$(PayloadRoot)\openclaw\node_modules\openclaw\openclaw.mjs')" Text="The OpenClaw runtime package is missing." />
<Error Condition="!Exists('$(PayloadRoot)\pi\node_modules\@earendil-works\pi-coding-agent\dist\cli.js')" Text="The Pi runtime package is missing." />
<Error Condition="!Exists('$(PayloadRoot)\python\python.exe')" Text="The native ARM64 Python runtime is missing." />
<Error Condition="!Exists('$(PayloadRoot)\hermes\site-packages\hermes_cli\main.py')" Text="The Hermes Agent runtime is missing." />
<Error Condition="!Exists('$(PayloadRoot)\deepagents\site-packages\deepagents_code\main.py')" Text="The Deep Agents Code runtime is missing." />
<Error Condition="!Exists('$(PayloadRoot)\nemocua\run_with_harness.py')" Text="The experimental NemoCUA runtime is missing." />
<Error Condition="!Exists('$(PayloadRoot)\onboarding\index.html')" Text="The NemoClaw graphical onboarder is missing." />
<Error Condition="!Exists('$(PayloadRoot)\mxc\wxc-exec.exe')" Text="The MXC executor is missing." />
<Error Condition="!Exists('$(PayloadRoot)\mxc\wxc-host-prep.exe')" Text="The MXC host preparation utility is missing." />
<Error Condition="!Exists('$(PayloadRoot)\config\mxc-gateway.toml')" Text="The OpenShell MXC gateway configuration is missing." />
<Error Condition="!Exists('$(PayloadRoot)\qualification\run-installed-native-turn.mts')" Text="The installed native turn qualification entrypoint is missing." />
<Error Condition="!Exists('$(PayloadRoot)\qualification\run-installed-native-web-ui.mts')" Text="The installed native web UI entrypoint is missing." />
<Error Condition="!Exists('$(PayloadRoot)\qualification\run-installed-native-console-agent.mts')" Text="The configured native terminal-agent entrypoint is missing." />
<Error Condition="!Exists('$(PayloadRoot)\qualification\run-installed-native-pi.mts')" Text="The installed native Pi entrypoint is missing." />
<Error Condition="!Exists('$(PayloadRoot)\qualification\run-installed-native-nemocua.mts')" Text="The installed native NemoCUA entrypoint is missing." />
<Error Condition="!Exists('$(PayloadRoot)\agent-support.json')" Text="The native Windows agent support catalog is missing." />
<Error Condition="!Exists('$(SourceRoot)\packaging\windows\assets\NemoClaw.ico')" Text="The NemoClaw product icon is missing." />
</Target>
</Project>
59 changes: 59 additions & 0 deletions packaging/windows/Product.wxs
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
<Wix xmlns="http://wixtoolset.org/schemas/v4/wxs">
<Package
Name="NemoClaw Runtime"
Manufacturer="NVIDIA Corporation"
Version="$(var.ProductVersion)"
UpgradeCode="52718EC2-AD6D-4A84-9FBF-3D73C9B11864"
Language="1033"
Scope="perMachine"
InstallerVersion="500"
Compressed="yes">

<SummaryInformation
Description="NemoClaw native Windows ARM64 preview"
Manufacturer="NVIDIA Corporation" />
<MajorUpgrade

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Keep the previous MSI inside rollback protection

A bare MajorUpgrade uses WiX's afterInstallValidate default, which removes the related product before the new install transaction is initialized. If the replacement then fails (for example while publishing files or PATH/ARP state), rollback cannot restore the removed version and the host is left with neither installation. This contradicts the advertised upgrade/rollback contract. Schedule removal at afterInstallInitialize or a later component-rule-safe point, and qualify a forced upgrade failure after removal has begun.

Schedule="afterInstallInitialize"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Qualify rollback after the old product is removed

afterInstallInitialize fixes the authoring half of the prior finding, but the only new guard regex-matches this XML. The Windows package qualification still does not install a lower version, begin a major upgrade, force the replacement to fail after related-product removal, and prove that the old files, ARP entry, and PATH registration are restored. Because this PR advertises repair/upgrade/rollback behavior for a per-machine installer, add that forced-failure qualification before treating the P1 as closed.

DowngradeErrorMessage="A newer NemoClaw native Windows candidate is already installed." />
<MediaTemplate EmbedCab="yes" CompressionLevel="high" />

<Property Id="ARPCOMMENTS" Value="NemoClaw native Windows ARM64 preview with pinned OpenShell, MXC, Node.js, and OpenClaw runtime. Host qualification and production activation remain required." />
<Property Id="ARPCONTACT" Value="NVIDIA Corporation" />
<Property Id="ARPURLINFOABOUT" Value="https://github.com/NVIDIA/NemoClaw" />
<Property Id="ARPPRODUCTICON" Value="NemoClawIcon" />
<Icon Id="NemoClawIcon" SourceFile="$(var.SourceRoot)\packaging\windows\assets\NemoClaw.ico" />

<StandardDirectory Id="ProgramFiles6432Folder">
<Directory Id="NvidiaFolder" Name="NVIDIA">
<Directory Id="INSTALLFOLDER" Name="NemoClaw">
<Directory Id="BinFolder" Name="bin">
<Component Id="MachinePathComponent" Guid="4A428913-FB6B-4710-9573-5CCF0E3E4686" Bitness="always64">
<RegistryValue
Root="HKLM"
Key="Software\NVIDIA Corporation\NemoClaw Native Windows Candidate"
Name="InstallBin"
Type="string"
Value="[BinFolder]"
KeyPath="yes" />
<Environment
Id="NemoClawMachinePath"
Name="PATH"
Action="set"
Part="last"
System="yes"
Permanent="no"
Value="[BinFolder]" />
</Component>
</Directory>
</Directory>
</Directory>
</StandardDirectory>

<Feature Id="Complete" Title="NemoClaw" Level="1">
<ComponentGroupRef Id="PayloadComponents" />
<ComponentRef Id="MachinePathComponent" />
</Feature>
</Package>
</Wix>
Loading
Loading