Repository navigation
Conversation
The pin was v0.1.2, still OpenShell's newest stable release. v0.1.3-pre.4 is its newest tag with published images. Its gateway computes profile revisions from sorted annotations (OpenShell #4122); v0.1.2 hashed protobuf map order, which is why the provider packs every profile field into one annotation (#12458). The SDK only adds fields with defaults; no proto field or public SDK item was removed. The Rust git dependencies, the vendored SDK, and the gateway, supervisor and sandbox digests move together, because the SDK refuses a gateway reporting any version other than the pin; the new gateway image reports 0.1.3-pre.4. The vendored SDK takes upstream's sources, tests and README at the new revision; its manifest's resolved dependency values are unchanged upstream. The default gateway digest also changes in the schema, configuration reference, examples, fixtures and the managed reference file. A prerelease has no GitHub release page: its CLI comes from OpenShell's installer with OPENSHELL_VERSION=pre, and those artifacts expire after 90 days. docs/prerequisites.md now says so. Docs naming v0.1.2 were rechecked against the new source: TLS terminate and passthrough are still rejected, linked upstream paths still exist, and the SDK limits in the architecture page are unchanged. The profile annotation encoding stays; its comment notes it is no longer required. Validation: `cargo ci` passes on Linux ARM64 (1042 tests, then 96 lifecycle tests); `cargo ci live-docker` passes all 8 tests with the pinned images, including the three managed-gateway tests; docs and schema checks pass.
Contributor
|
v1 documentation preview: https://nvidia-preview-nemoclaw-v1-pr-12655.docs.buildwithfern.com/nemoclaw |
cv
enabled auto-merge (squash)
October 6, 2026 02:55
Collaborator
Author
|
Closing: we're staying on OpenShell's stable releases, and v0.1.2 is still the newest. I'm keeping the |
auto-merge was automatically disabled
October 6, 2026 02:57
Pull request was closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Moves the OpenShell pin from v0.1.2 to v0.1.3-pre.4 (
e7fdd6beef98): the Rust crates, the vendored SDK, and the gateway, supervisor and sandbox images.Why a prerelease
v0.1.2 is still OpenShell's newest stable release. v0.1.3-pre.4 is its newest tag with published images, 84 commits later. Two changes in that range affect us:
SandboxSpec.restart_policyandServiceExposure.authorization_modeare added with defaults. No proto field or public SDK item was removed.What a prerelease costs
OPENSHELL_VERSION=pre, which requires an authenticated GitHub CLI.docs/prerequisites.mdnow says this.0.1.3-pre.4.Changes
versions.json: version, revision and the three image digests.Cargo.toml,Cargo.lock: the three OpenShell git dependencies.crates/vendor/openshell-sdk: sources, tests and README replaced with upstreamcrates/openshell-sdkat the new revision; the manifest's resolved dependency values are unchanged upstream;NOTICE.mdrecords the refresh.terminate/passthroughare still rejected, every linked upstream path still exists, and the SDK limits indesign/architecture.mdare unchanged.Validation
cargo cion Linux ARM64: every step passes (1042 tests, then 96 lifecycle tests).cargo ci live-dockeron Linux ARM64 with the pinned images: all 8 tests pass, including the three managed-gateway tests (plan/apply/no-op/recovery with real OpenTofu, sandbox readiness on a pinned Docker gateway, and profile revisions surviving repeated reads and a gateway restart).