NVIDIA / NVIDIA/NemoClaw

Qualify the accepted Windows OpenShell MXC profile

Open
#10,585 1 comment 0 reactions 1 assignee Claimed by @senthilr-nv View on GitHub
area: e2e area: sandbox integration: openclaw platform: windows security v0.0.127
Dominant language
TypeScript
Stars
22.5k
Forks
3.1k
Avg merge
1d 1h
Merged PRs (30d)
715

Description

Part of #8178.

This task qualifies the dormant native Windows/OpenShell MXC candidate. It does not establish support or production activation.

## Outcome

The checked-in Windows harness repeatedly validates the exact accepted Windows, NemoClaw, OpenShell, MXC/`wxc-exec.exe`, Node.js, and OpenClaw identities through the merged inactive onboarding composition.

## Delivery state

Accepted-package physical qualification.

## Dependencies

- Blocked by #10584.
- Requires an accepted host and privilege contract.
- Unblocks opt-in qualification onboarding, policy and inference work, and lifecycle completion.

## Deliverables

- Connect the checked-in Windows target to the trusted executor and inactive onboarding composition.
- Pin every component and configuration identity in the run manifest.
- Run repeated create, readiness, filesystem allow and deny, authenticated forwarding, exact mock-backed `CHAT_OK`, recovery, deletion, process termination, registry removal, forward shutdown, artifact cleanup, and recreation checks.
- Preserve a sanitized evidence bundle tied to exact commits and package identities.

## Acceptance evidence

- Allowed: at least two consecutive clean cycles pass with exact identity and no stale state.
- Denied: substituted binaries, unsupported host facts, policy mismatch, unauthorized forwarding, and stale sandbox identity fail closed.
- Ambiguous: create, readiness, or cleanup uncertainty triggers reconciliation and produces an inconclusive result rather than a pass.
- Failure or recovery: injected interruption proves exact recovery or reports the authority-bound retained resource.

## Security and authority boundaries

- Evidence must not contain credentials, tokens, private keys, or sensitive host data.
- Authenticated forwarding must be sandbox-scoped and removed with the sandbox.
- The shallow state path may remain a declared MXC-02 workload workaround but must not be represented as a general filesystem fix.

## Test plan

- Run the checked-in physical Windows target against the accepted pinned profile.
- Preserve deterministic E2E-support tests for manifest validation, redaction, retry policy, and evidence completeness.
- Record every attempt rather than hiding a failed cycle with an unbounded rerun.

## Deferred scope

- Public installer, normal runtime selection, production credentials, and activation.

## Stop conditions

- Stop if any identity cannot be resolved to an accepted source.
- Stop if the run needs untracked host changes, insecure credential handling, or a policy exception not accepted by #8178.

## Completion evidence

- Link the qualification PR if code changes are required, exact NemoClaw commit, host profile, package manifest, run attempts, and sanitized evidence bundle. One same-repository PR should own any repository change.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.