Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
57 commits
Select commit Hold shift + click to select a range
e8fa235
feat(agents): add Deep Agents Code harness
cv Jun 11, 2026
3a68260
fix(agents): harden Deep Agents Code harness
cv Jun 11, 2026
1371e39
fix(agents): address Deep Agents Code review feedback
cv Jun 11, 2026
41d174d
Merge remote-tracking branch 'origin/main' into codex/4861-langchain-…
cv Jun 11, 2026
7ad9d1d
fix(agents): address terminal runtime review gaps
cv Jun 11, 2026
16e73d3
test(agents): cover Deep Agents Code runtime acceptance
cv Jun 11, 2026
2e38503
fix(agents): close Deep Agents Code wrapper bypass
cv Jun 11, 2026
29df680
fix(agents): enforce Deep Agents managed launcher posture
cv Jun 11, 2026
5d6b3b1
fix(agents): harden Deep Agents managed module mode
cv Jun 11, 2026
eda9780
fix(agents): scope Deep Agents V1 web search posture
cv Jun 11, 2026
a0a1f12
fix(agents): avoid persisted credentialed Deep Agents proxies
cv Jun 11, 2026
ec9bf6e
Merge branch 'main' into codex/4861-langchain-deepagents-code
cv Jun 11, 2026
0c17809
fix(agents): catch scheme-less credentialed Deep Agents proxies
cv Jun 11, 2026
bbdc578
fix(onboard): skip dashboard setup for terminal agents
cv Jun 11, 2026
304efd5
fix(onboard): harden dashboard runtime planning
cv Jun 11, 2026
d327dd3
merge: main into Deep Agents Code harness
cv Jun 11, 2026
01ca6b5
fix(agent): use terminal runtime helper during setup
cv Jun 11, 2026
657271f
refactor(onboard): share terminal dashboard helpers
cv Jun 11, 2026
1d4cc87
Merge remote-tracking branch 'origin/main' into codex/4861-langchain-…
cv Jun 11, 2026
7a24c25
refactor(onboard): keep dashboard merge net neutral
cv Jun 11, 2026
65e6d1e
fix(agent): verify terminal smoke on resume
cv Jun 11, 2026
a97623a
fix(agents): remove dcode shell allow-list bypass
cv Jun 11, 2026
df0d883
fix(agents): clear credentialed proxy env
cv Jun 11, 2026
81d7306
Merge remote-tracking branch 'origin/main' into codex/4861-langchain-…
cv Jun 11, 2026
5d78005
fix(agents): tighten deepagents sandbox contracts
cv Jun 11, 2026
976381a
Merge branch 'main' into codex/4861-langchain-deepagents-code
cv Jun 11, 2026
e02d48d
merge: main into Deep Agents Code harness
cv Jun 12, 2026
ea96f09
fix: keep onboard entrypoint net neutral
cv Jun 12, 2026
6d43cf6
fix(agents): reject credentialed Deep Agents base URLs
cv Jun 12, 2026
36d4e37
fix(onboard): skip dashboard finalization for terminal agents
cv Jun 12, 2026
33227e8
Merge branch 'main' into codex/4861-langchain-deepagents-code
cv Jun 12, 2026
03f0c80
merge: main into deep agents code harness
cv Jun 18, 2026
5ca838d
refactor(sandbox): reduce recovery status reporting complexity
cv Jun 18, 2026
e018e8e
Merge remote-tracking branch 'origin/main' into codex/4861-langchain-…
cv Jun 19, 2026
de6d75f
test(e2e): relax workflow inventory timeout
cv Jun 19, 2026
ebe1a85
test(e2e): increase workflow inventory timeout
cv Jun 19, 2026
bd6a2bd
Merge remote-tracking branch 'origin/main' into codex/4861-langchain-…
cv Jun 20, 2026
dcf1c81
test(agent): move terminal helpers out of test file
cv Jun 20, 2026
2e33dc5
Merge branch 'main' into codex/4861-langchain-deepagents-code
cv Jun 22, 2026
b393840
fix(agents): address Deep Agents Code review findings
cv Jun 22, 2026
1d7136d
Merge branch 'main' into codex/4861-langchain-deepagents-code
cv Jun 22, 2026
603212f
merge: main into Deep Agents Code harness
cv Jun 22, 2026
34f9810
Merge branch 'main' into codex/4861-langchain-deepagents-code
cv Jun 22, 2026
2ed6c63
fix(agents): hash-lock Deep Agents Code install
cv Jun 22, 2026
96e8166
Merge remote-tracking branch 'origin/codex/4861-langchain-deepagents-…
cv Jun 22, 2026
50f9a9a
fix(agents): require Landlock for Deep Agents Code
cv Jun 22, 2026
e525517
fix(connect): show terminal agent launch command
cv Jun 22, 2026
64ae393
fix(sandbox): normalize base image input paths
cv Jun 22, 2026
0519019
fix(agents): audit Deep Agents Code lockfile
cv Jun 22, 2026
5526a7f
test(agents): cover Deep Agents Code runtime contracts
cv Jun 22, 2026
ac53500
test(agents): cover Deep Agents Code runtime contracts
cv Jun 22, 2026
e1275e3
merge: remote Deep Agents Code follow-up
cv Jun 22, 2026
0e58a81
fix(agents): align Deep Agents Code E2E contract
cv Jun 22, 2026
6a3efee
test(agents): document Deep Agents Code policy boundaries
cv Jun 22, 2026
107456a
test(agents): fix Deep Agents Python egress probe
cv Jun 22, 2026
4d5ca2f
fix(agents): drop credentialed proxy create env
cv Jun 22, 2026
0a30ab6
fix(agents): sanitize Deep Agents config metadata
cv Jun 23, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ It provides guided onboarding, a hardened blueprint, routed inference, network p

- [OpenClaw](https://openclaw.ai) (default)
- [Hermes](https://get-hermes.ai/)
- [LangChain Deep Agents Code](https://docs.langchain.com/oss/python/deepagents/code/overview)

For capabilities, architecture, security controls, and the full feature list, see the [NemoClaw documentation](https://docs.nvidia.com/nemoclaw/latest/).

Expand All @@ -28,6 +29,7 @@ For Hermes, set `NEMOCLAW_AGENT=hermes` before running the installer, or use the
|-------|-------|
| OpenClaw (default) | [Quickstart with OpenClaw](https://docs.nvidia.com/nemoclaw/latest/get-started/quickstart.html) |
| Hermes | [Quickstart with Hermes](https://docs.nvidia.com/nemoclaw/latest/get-started/quickstart-hermes.html) |
| LangChain Deep Agents Code | [Quickstart with LangChain Deep Agents Code](https://docs.nvidia.com/nemoclaw/latest/get-started/quickstart-langchain-deepagents-code.html) |

## Documentation

Expand Down
92 changes: 92 additions & 0 deletions agents/langchain-deepagents-code/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
#
# LangChain Deep Agents Code sandbox image.

# NemoClaw staging supplies a resolved base image reference. Direct Docker builds
# must pass --build-arg BASE_IMAGE=... rather than falling back to a mutable tag.
ARG BASE_IMAGE

# hadolint ignore=DL3006
FROM ${BASE_IMAGE}

RUN set -eu; \
dcode_path="$(command -v dcode 2>/dev/null || true)"; \
if [ "$dcode_path" != "/usr/local/bin/dcode" ]; then \
echo "ERROR: expected dcode at /usr/local/bin/dcode, got ${dcode_path:-missing}" >&2; \
exit 1; \
fi; \
test -x /usr/local/bin/dcode; \
/usr/local/bin/dcode --version

# Copy config generator, wrapper, startup script, and shared blueprint files.
COPY agents/langchain-deepagents-code/generate-config.ts /opt/nemoclaw-deepagents-code/generate-config.ts
COPY agents/langchain-deepagents-code/patch-managed-deepagents-code.py /opt/nemoclaw-deepagents-code/patch-managed-deepagents-code.py
COPY agents/langchain-deepagents-code/dcode-wrapper.sh /usr/local/lib/nemoclaw/dcode-wrapper.sh
COPY agents/langchain-deepagents-code/start.sh /usr/local/bin/nemoclaw-start
COPY nemoclaw-blueprint/ /opt/nemoclaw-blueprint/
RUN chmod 444 /opt/nemoclaw-deepagents-code/generate-config.ts /opt/nemoclaw-deepagents-code/patch-managed-deepagents-code.py \
&& chmod 755 /usr/local/bin/nemoclaw-start /usr/local/lib/nemoclaw/dcode-wrapper.sh \
&& chmod -R a+rX /opt/nemoclaw-blueprint \
&& python3 /opt/nemoclaw-deepagents-code/patch-managed-deepagents-code.py \
&& rm -f /usr/local/bin/dcode /usr/local/bin/deepagents-code \
&& install -m 0755 /usr/local/lib/nemoclaw/dcode-wrapper.sh /usr/local/bin/dcode \
&& install -m 0755 /usr/local/lib/nemoclaw/dcode-wrapper.sh /usr/local/bin/dcode.real \
&& install -m 0755 /usr/local/lib/nemoclaw/dcode-wrapper.sh /usr/local/bin/deepagents-code \
&& /usr/local/bin/dcode --version \
&& /usr/local/bin/dcode.real --version \
&& /usr/local/bin/deepagents-code --version

ARG NEMOCLAW_MODEL=nvidia/nemotron-3-super-120b-a12b
ARG NEMOCLAW_PROVIDER_KEY=inference
ARG NEMOCLAW_UPSTREAM_PROVIDER=nvidia
ARG NEMOCLAW_INFERENCE_BASE_URL=https://inference.local/v1
ARG NEMOCLAW_INFERENCE_API=openai-completions
ARG NEMOCLAW_BUILD_ID=default
ARG NEMOCLAW_DARWIN_VM_COMPAT=0

ENV HOME=/sandbox \
PATH="/usr/local/bin:${PATH}" \
NEMOCLAW_MODEL=${NEMOCLAW_MODEL} \
NEMOCLAW_PROVIDER_KEY=${NEMOCLAW_PROVIDER_KEY} \
NEMOCLAW_UPSTREAM_PROVIDER=${NEMOCLAW_UPSTREAM_PROVIDER} \
NEMOCLAW_INFERENCE_BASE_URL=${NEMOCLAW_INFERENCE_BASE_URL} \
NEMOCLAW_INFERENCE_API=${NEMOCLAW_INFERENCE_API} \
NEMOCLAW_BUILD_ID=${NEMOCLAW_BUILD_ID} \
DEEPAGENTS_CODE_NO_UPDATE_CHECK=1 \
DEEPAGENTS_CODE_AUTO_UPDATE=0 \
DEEPAGENTS_CODE_OPENAI_API_KEY=nemoclaw-managed-inference \
OPENAI_BASE_URL=${NEMOCLAW_INFERENCE_BASE_URL}

WORKDIR /sandbox
USER sandbox

RUN mkdir -p /sandbox/.nemoclaw/blueprints/0.1.0 \
&& cp -r /opt/nemoclaw-blueprint/* /sandbox/.nemoclaw/blueprints/0.1.0/ \
&& node --experimental-strip-types /opt/nemoclaw-deepagents-code/generate-config.ts \
&& chmod 660 /sandbox/.deepagents/config.toml

USER root
RUN chown root:root /sandbox/.nemoclaw \
&& chmod 1755 /sandbox/.nemoclaw \
&& chown -R root:root /sandbox/.nemoclaw/blueprints \
&& chmod -R 755 /sandbox/.nemoclaw/blueprints \
&& mkdir -p /sandbox/.nemoclaw/state /sandbox/.nemoclaw/migration /sandbox/.nemoclaw/snapshots /sandbox/.nemoclaw/staging \
&& chown sandbox:sandbox /sandbox/.nemoclaw/state /sandbox/.nemoclaw/migration /sandbox/.nemoclaw/snapshots /sandbox/.nemoclaw/staging \
&& printf '%s' '{}' > /sandbox/.nemoclaw/config.json \
&& chown sandbox:sandbox /sandbox/.nemoclaw/config.json

RUN if [ "$NEMOCLAW_DARWIN_VM_COMPAT" = "1" ]; then \
chmod -R a+rwX /sandbox/.deepagents; \
find /sandbox/.deepagents -type d -exec chmod a+rwx {} +; \
for p in /sandbox/.nemoclaw/state /sandbox/.nemoclaw/migration /sandbox/.nemoclaw/snapshots /sandbox/.nemoclaw/staging; do \
chmod -R a+rwX "$p"; \
find "$p" -type d -exec chmod a+rwx {} +; \
done; \
chmod a+rw /sandbox/.nemoclaw/config.json; \
chmod a+rw /sandbox/.bashrc /sandbox/.profile; \
fi

USER sandbox
ENTRYPOINT ["/usr/local/bin/nemoclaw-start"]
CMD ["/bin/bash"]
71 changes: 71 additions & 0 deletions agents/langchain-deepagents-code/Dockerfile.base
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
#
# LangChain Deep Agents Code sandbox base image.
#
# Contains the expensive, rarely-changing layers for the terminal harness:
# Node for NemoClaw build-time config generation, Python, shell tools, and a
# hash-locked deepagents-code install with the NVIDIA provider extra.

FROM node:22-trixie-slim@sha256:2d9f5c76c8f4dd36e8f253bee5d828a83a6c09f36188f0b0414325232e0b175d

ENV DEBIAN_FRONTEND=noninteractive

RUN apt-get update && apt-get install -y --no-install-recommends \
python3=3.13.5-1 \
python3-pip=25.1.1+dfsg-1 \
python3-venv=3.13.5-1 \
curl=8.14.1-2+deb13u3 \
git=1:2.47.3-0+deb13u1 \
ca-certificates=20250419 \
iproute2=6.15.0-1 \
iptables=1.8.11-2 \
libcap2-bin=1:2.75-10+deb13u1+b1 \
procps=2:4.0.4-9 \
e2fsprogs=1.47.2-3+b11 \
openssh-sftp-server=1:10.0p1-7+deb13u4 \
jq=1.7.1-6+deb13u2 \
vim-tiny=2:9.1.1230-2 \
&& rm -rf /var/lib/apt/lists/*

RUN groupadd -r sandbox \
&& useradd -r -g sandbox -d /sandbox -s /bin/bash sandbox \
&& usermod -a -G sandbox root \
&& mkdir -p /sandbox/.nemoclaw \
/sandbox/.deepagents/.state \
/sandbox/.deepagents/skills \
&& chown -R sandbox:sandbox /sandbox \
&& chmod 2770 /sandbox/.deepagents \
&& chmod 770 /sandbox/.deepagents/.state /sandbox/.deepagents/skills

# Pre-create shell init files for the sandbox user. OpenShell/NemoClaw writes
# /tmp/nemoclaw-proxy-env.sh at startup so interactive sessions and dcode share
# the same proxy, CA, inference, HOME, and update-check posture.
# hadolint ignore=SC2016
RUN printf '%s\n' \
'# Source runtime proxy + Deep Agents Code config' \
'[ -f /tmp/nemoclaw-proxy-env.sh ] && . /tmp/nemoclaw-proxy-env.sh' \
'export HOME=/sandbox' \
'export PATH="/usr/local/bin:${PATH}"' \
> /sandbox/.bashrc \
&& printf '%s\n' \
'# Source runtime proxy + Deep Agents Code config' \
'[ -f /tmp/nemoclaw-proxy-env.sh ] && . /tmp/nemoclaw-proxy-env.sh' \
'export HOME=/sandbox' \
'export PATH="/usr/local/bin:${PATH}"' \
> /sandbox/.profile \
&& chown root:root /sandbox/.bashrc /sandbox/.profile \
&& chmod 444 /sandbox/.bashrc /sandbox/.profile

COPY agents/langchain-deepagents-code/requirements.lock /tmp/deepagents-code-requirements.lock

RUN pip3 install --no-cache-dir --break-system-packages --ignore-installed --require-hashes \
-r /tmp/deepagents-code-requirements.lock \
&& rm -f /tmp/deepagents-code-requirements.lock \
&& /usr/local/bin/dcode --version

ENV HOME=/sandbox \
PATH="/usr/local/bin:${PATH}" \
DEEPAGENTS_CODE_NO_UPDATE_CHECK=1

WORKDIR /sandbox
64 changes: 64 additions & 0 deletions agents/langchain-deepagents-code/dcode-wrapper.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,64 @@
#!/usr/bin/env bash
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
#
# Managed Deep Agents Code launcher for NemoClaw/OpenShell sandboxes.

set -euo pipefail

export HOME=/sandbox
export PATH="/usr/local/bin:${PATH}"
export DEEPAGENTS_CODE_NO_UPDATE_CHECK=1
export DEEPAGENTS_CODE_AUTO_UPDATE=0
export DEEPAGENTS_CODE_OPENAI_API_KEY="${DEEPAGENTS_CODE_OPENAI_API_KEY:-nemoclaw-managed-inference}"
export OPENAI_BASE_URL="${OPENAI_BASE_URL:-https://inference.local/v1}"

run_dcode() {
exec python3 -m deepagents_code "$@"
}

case "${1:-}" in
--version | -v | -V | --help | -h)
run_dcode "$@"
;;
esac

unset DEEPAGENTS_CODE_SHELL_ALLOW_LIST

reject_managed_override() {
local posture="$1"
local arg="$2"
printf 'NemoClaw manages Deep Agents Code %s; remove %s and use NemoClaw policy/configuration instead.\n' "$posture" "$arg" >&2
exit 2
}

if [ "${1:-}" = "mcp" ]; then
reject_managed_override "MCP posture" "mcp"
fi

for arg in "$@"; do
case "$arg" in
--sandbox | --sandbox=*)
reject_managed_override "sandbox isolation" "$arg"
;;
--sandbox-id | --sandbox-id=*)
reject_managed_override "sandbox isolation" "$arg"
;;
--sandbox-snapshot-name | --sandbox-snapshot-name=*)
reject_managed_override "sandbox isolation" "$arg"
;;
--sandbox-setup | --sandbox-setup=*)
reject_managed_override "sandbox isolation" "$arg"
;;
--mcp-config | --mcp-config=* | --trust-project-mcp | --no-mcp=*)
reject_managed_override "MCP posture" "$arg"
;;
--shell-allow-list | --shell-allow-list=* | -S | -S?*)
reject_managed_override "shell allow-list posture" "$arg"
;;
esac
done

extra_args=(--sandbox none --no-mcp)

run_dcode "${extra_args[@]}" "$@"
15 changes: 15 additions & 0 deletions agents/langchain-deepagents-code/dependency-review.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->

# LangChain Deep Agents Code Dependency Review

This file records the reviewed dependency baseline for the Deep Agents Code sandbox base image.
Update it whenever `requirements.lock` changes.

- Lockfile: `agents/langchain-deepagents-code/requirements.lock`
- Lockfile SHA-256: `a0b986369ff564ed9105c4e95915541ccc161d6f1e8032cc496127ea3e7d2e45`
- Audit command: `pip-audit -r agents/langchain-deepagents-code/requirements.lock --progress-spinner off`
- Audit date: 2026-06-22
- Audit result: `No known vulnerabilities found`

The Dockerfile installs this lockfile with `pip3 install --require-hashes`, so this review covers the exact package versions selected for the managed image install.
Loading
Loading