Files
Peter Steinberger 39373e69f8 chore(deps): refresh dependencies through September 19 cutoff (#159401)
Refresh application, plugin, native, build and container dependencies through the fixed 2026-09-19T16:27:11Z cutoff. Migrate native TypeScript snapshot/printer APIs while preserving compilation and filesystem contracts; retain existing patches and compatibility holds. Document offline container-image preparation.

Include the verified compiler process-census and loading-clock fixture repairs and deterministic warm-history regression. Adopt the canonical production history fixes from #159924 and #159955.

Land under the maintainer's explicit approval to treat proven pre-existing CI failures as non-blocking and repair main afterward. CI36365552098 failed an unchanged Android Compose fixture's asynchronous catalog projection assertion (3518 passed,1 failed); the Android/Gradle tree matches its main parent byte-for-byte. Security and dependency reviews passed. The final rebase preserves reviewed source changes and regenerates only the intentional Node-image documentation fingerprint. See PR159401 for complete validation and the follow-up repair obligation.
2026-09-27 19:33:08 -07:00
..

@openclaw/openshell-sandbox

Official NVIDIA OpenShell sandbox backend for OpenClaw.

This plugin lets OpenClaw use OpenShell-managed local or remote sandboxes with SSH command execution. Choose mirror mode for a synchronized local workspace or remote mode for a remote-canonical workspace.

Mirror operations sharing a workspace run sequentially so concurrent agent turns cannot overwrite one another. Outbound attachments resolve against the configured remote workspace, which defaults to /sandbox.

Configuring an OpenShell workspace requires OpenShell v0.0.88 or newer. The plugin supports OpenShell control-plane workspaces through plugins.entries.openshell.config.workspace; this is separate from OpenClaw's local/remote filesystem workspace mode. The setting applies to the whole plugin instance, not individual agents or sessions. When unset, the plugin preserves the OpenShell CLI's ambient OPENSHELL_WORKSPACE selection, or its default fallback when no ambient selection exists.

Install

openclaw plugins install @openclaw/openshell-sandbox

Restart the Gateway after installing or updating the plugin.

Configure

Install and configure the OpenShell CLI before enabling the backend. As the same operating system user that runs the OpenClaw Gateway, verify:

openshell --version
openshell gateway list
openshell sandbox list

Set agents.defaults.sandbox.backend to "openshell", enable plugins.entries.openshell, and restart the OpenClaw Gateway. OpenShell settings belong under plugins.entries.openshell.config.

The optional policy setting must be the path to a readable OpenShell policy YAML file on the Gateway host; it is not a policy name or ID. Use an absolute path to avoid resolving it relative to an agent workspace.

Use the OpenShell docs for credentials, workspace mirroring, runtime selection, and troubleshooting:

Package

  • Plugin id: openshell
  • Package: @openclaw/openshell-sandbox
  • Minimum OpenClaw host: 2026.5.12-beta.1