Skip to content

build(deps): pin OpenShell v0.1.3-pre.4 - #12655

Closed
cv wants to merge 1 commit into
v1from
deps/openshell-0.1.3-pre.4
Closed

cv wants to merge 1 commit into
v1from
deps/openshell-0.1.3-pre.4

Conversation

@cv

@cv cv commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Summary

Moves the OpenShell pin from v0.1.2 to v0.1.3-pre.4 (e7fdd6beef98): the Rust crates, the vendored SDK, and the gateway, supervisor and sandbox images.

Why a prerelease

v0.1.2 is still OpenShell's newest stable release. v0.1.3-pre.4 is its newest tag with published images, 84 commits later. Two changes in that range affect us:

What a prerelease costs

  • No GitHub release page. The matching CLI comes from OpenShell's installer with OPENSHELL_VERSION=pre, which requires an authenticated GitHub CLI. docs/prerequisites.md now says this.
  • Its CLI artifacts expire. They are workflow artifacts kept for 90 days, so this pin should move to v0.1.3 when it's released.
  • Exact version match. The SDK refuses a gateway that reports any version other than the pin. The pinned gateway image reports 0.1.3-pre.4.

Changes

  • versions.json: version, revision and the three image digests.
  • Cargo.toml, Cargo.lock: the three OpenShell git dependencies.
  • crates/vendor/openshell-sdk: sources, tests and README replaced with upstream crates/openshell-sdk at the new revision; the manifest's resolved dependency values are unchanged upstream; NOTICE.md records the refresh.
  • The default gateway digest in the schema, configuration reference, 9 examples, 4 fixtures and the provider's managed reference file.
  • Docs that named v0.1.2 or the old revision. I re-checked each claim against the new source: TLS terminate/passthrough are still rejected, every linked upstream path still exists, and the SDK limits in design/architecture.md are unchanged.

Validation

  • cargo ci on Linux ARM64: every step passes (1042 tests, then 96 lifecycle tests).
  • cargo ci live-docker on Linux ARM64 with the pinned images: all 8 tests pass, including the three managed-gateway tests (plan/apply/no-op/recovery with real OpenTofu, sandbox readiness on a pinned Docker gateway, and profile revisions surviving repeated reads and a gateway restart).
  • Docs and schema checks pass, and every relative link resolves.
  • Not run: GPU, Podman, SSH placement and Brev live tests.

The pin was v0.1.2, still OpenShell's newest stable release.
v0.1.3-pre.4 is its newest tag with published images. Its gateway
computes profile revisions from sorted annotations (OpenShell #4122);
v0.1.2 hashed protobuf map order, which is why the provider packs
every profile field into one annotation (#12458). The SDK only adds
fields with defaults; no proto field or public SDK item was removed.

The Rust git dependencies, the vendored SDK, and the gateway,
supervisor and sandbox digests move together, because the SDK
refuses a gateway reporting any version other than the pin; the new
gateway image reports 0.1.3-pre.4. The vendored SDK takes upstream's
sources, tests and README at the new revision; its manifest's
resolved dependency values are unchanged upstream. The default
gateway digest also changes in the schema, configuration reference,
examples, fixtures and the managed reference file.

A prerelease has no GitHub release page: its CLI comes from
OpenShell's installer with OPENSHELL_VERSION=pre, and those artifacts
expire after 90 days. docs/prerequisites.md now says so. Docs naming
v0.1.2 were rechecked against the new source: TLS terminate and
passthrough are still rejected, linked upstream paths still exist,
and the SDK limits in the architecture page are unchanged. The
profile annotation encoding stays; its comment notes it is no longer
required.

Validation: `cargo ci` passes on Linux ARM64 (1042 tests, then 96
lifecycle tests); `cargo ci live-docker` passes all 8 tests with the
pinned images, including the three managed-gateway tests; docs and
schema checks pass.
@cv cv added the v1 NemoClaw v1 branch label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cv
cv enabled auto-merge (squash) October 6, 2026 02:55
@cv

cv commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator Author

Closing: we're staying on OpenShell's stable releases, and v0.1.2 is still the newest. I'm keeping the deps/openshell-0.1.3-pre.4 branch as a starting point for moving to v0.1.3 once it's released. That move will need new image digests and another cargo ci live-docker run.

@cv cv closed this Oct 6, 2026
auto-merge was automatically disabled October 6, 2026 02:57

Pull request was closed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

v1 NemoClaw v1 branch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant