-
Notifications
You must be signed in to change notification settings - Fork 3k
Expand file tree
/
Copy pathinstall.sh
More file actions
executable file
·195 lines (174 loc) · 7.75 KB
/
Copy pathinstall.sh
File metadata and controls
executable file
·195 lines (174 loc) · 7.75 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
#!/usr/bin/env bash
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
#
# Thin bootstrap for the NemoClaw installer.
# Public curl|bash installs should select a ref once, clone that ref, then
# execute installer logic from that same clone. Historical tags that predate
# the extracted payload fall back to their own root install.sh.
set -euo pipefail
if [[ -n "${BASH_SOURCE[0]:-}" ]]; then
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
else
SCRIPT_DIR=""
fi
LOCAL_PAYLOAD="${SCRIPT_DIR:+${SCRIPT_DIR}/scripts/install.sh}"
BOOTSTRAP_TMPDIR=""
PAYLOAD_MARKER="NEMOCLAW_VERSIONED_INSTALLER_PAYLOAD=1"
DEFAULT_INSTALL_REF="lkg"
INSTALL_TAG_EXAMPLE="vX.Y.Z"
resolve_release_tag() {
if [[ -n "${NEMOCLAW_INSTALL_REF:-}" ]]; then
printf "%s" "${NEMOCLAW_INSTALL_REF}"
return
fi
printf "%s" "${NEMOCLAW_INSTALL_TAG:-$DEFAULT_INSTALL_REF}"
}
verify_downloaded_script() {
local file="$1" label="${2:-installer}" expected_hash="${3:-}"
if [[ ! -s "$file" ]]; then
printf "[ERROR] %s download is empty or missing\n" "$label" >&2
exit 1
fi
if ! head -1 "$file" | grep -qE '^#!.*(sh|bash)'; then
printf "[ERROR] %s does not start with a shell shebang\n" "$label" >&2
exit 1
fi
if [[ -n "$expected_hash" ]]; then
local actual_hash=""
if command -v sha256sum >/dev/null 2>&1; then
actual_hash="$(sha256sum "$file" | awk '{print $1}')"
elif command -v shasum >/dev/null 2>&1; then
actual_hash="$(shasum -a 256 "$file" | awk '{print $1}')"
fi
if [[ -z "$actual_hash" ]]; then
printf "[ERROR] No SHA-256 tool available — cannot verify %s integrity\n" "$label" >&2
exit 1
fi
if [[ "$actual_hash" != "$expected_hash" ]]; then
rm -f "$file"
printf "[ERROR] %s integrity check failed\n Expected: %s\n Actual: %s\n" "$label" "$expected_hash" "$actual_hash" >&2
exit 1
fi
fi
}
has_payload_marker() {
local file="$1"
[[ -f "$file" ]] && grep -q "$PAYLOAD_MARKER" "$file"
}
clone_nemoclaw_ref() {
local ref="$1" dest="$2"
git init --quiet "$dest"
git -C "$dest" remote add origin https://github.com/NVIDIA/NemoClaw.git
if ! git -C "$dest" fetch --quiet --depth 1 origin "+${ref}:refs/nemoclaw-install/target"; then
printf "[ERROR] Requested install ref '%s' is not available from https://github.com/NVIDIA/NemoClaw.git.\n" "$ref" >&2
printf " Check NEMOCLAW_INSTALL_TAG/NEMOCLAW_INSTALL_REF and try again.\n" >&2
exit 1
fi
git -C "$dest" -c advice.detachedHead=false checkout --quiet --detach refs/nemoclaw-install/target
}
exec_installer_from_ref() {
local ref="$1"
shift
local tmpdir source_root payload_script legacy_script
tmpdir="$(mktemp -d)"
BOOTSTRAP_TMPDIR="$tmpdir"
trap 'rm -rf "${BOOTSTRAP_TMPDIR:-}"' EXIT
source_root="${tmpdir}/source"
clone_nemoclaw_ref "$ref" "$source_root"
payload_script="${source_root}/scripts/install.sh"
legacy_script="${source_root}/install.sh"
if has_payload_marker "$payload_script"; then
# The public curl|bash boundary deliberately executes from the complete
# selected-ref checkout, not from a standalone payload file. Installer
# helpers beside scripts/install.sh (including DGX Station preparation)
# are therefore staged from the same ref before payload execution.
verify_downloaded_script "$payload_script" "versioned installer"
NEMOCLAW_INSTALL_REF="$ref" NEMOCLAW_INSTALL_TAG="$ref" NEMOCLAW_BOOTSTRAP_PAYLOAD=1 \
bash "$payload_script" "$@"
return
fi
verify_downloaded_script "$legacy_script" "legacy installer"
NEMOCLAW_INSTALL_TAG="$ref" bash "$legacy_script" "$@"
}
require_supported_platform() {
# macOS ships only an Apple Silicon (aarch64) OpenShell gateway build, so an
# Intel Mac (x86_64 Darwin) install always fails once that binary is fetched.
# Reject it here, before any ref resolution or clone, so the user gets an
# actionable message instead of a mid-install failure and needless downloads.
if [[ "$(uname -s)" == "Darwin" && "$(uname -m)" == "x86_64" ]]; then
printf "[ERROR] Apple Silicon (aarch64) is required on macOS. Intel Mac (x86_64) is not supported.\n" >&2
exit 1
fi
}
bootstrap_version() {
printf "nemoclaw-installer\n"
}
bootstrap_usage() {
printf "\n"
printf " NemoClaw Installer\n\n"
printf " Usage:\n"
printf " curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash\n"
printf " curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash -s -- [options]\n\n"
printf " Options:\n"
printf " --non-interactive Skip prompts (uses env vars / defaults)\n"
printf " --station-deepseek Use DeepSeek V4 Flash for DGX Station express install\n"
printf " --yes-i-accept-third-party-software Accept the third-party software notice without prompting\n"
printf " --fresh Discard any failed/interrupted onboarding session and start over\n"
printf " --version, -v Print installer version and exit\n"
printf " --help, -h Show this help message and exit\n\n"
printf " Environment:\n"
printf " NEMOCLAW_INSTALL_REF Exact Git ref/SHA to install\n"
printf " NEMOCLAW_INSTALL_TAG Git ref to install (default: %s)\n" "$DEFAULT_INSTALL_REF"
printf " In curl pipes, set this on bash or export it first.\n"
printf " Example: curl -fsSL https://www.nvidia.com/nemoclaw.sh | NEMOCLAW_INSTALL_TAG=%s bash\n" "$INSTALL_TAG_EXAMPLE"
printf " NEMOCLAW_NON_INTERACTIVE=1 Same as --non-interactive\n"
printf " NEMOCLAW_FRESH=1 Same as --fresh\n"
printf " NEMOCLAW_ACCEPT_THIRD_PARTY_SOFTWARE=1 Same as --yes-i-accept-third-party-software\n"
printf " NEMOCLAW_NO_EXPRESS=1 Skip express install prompt on supported platforms\n"
printf " NEMOCLAW_SANDBOX_NAME Sandbox name to create/use\n"
printf " HF_TOKEN Optional Hugging Face read token for managed-vLLM downloads\n"
printf " Create one at https://huggingface.co/settings/tokens and export it before curl | bash.\n"
printf " HUGGING_FACE_HUB_TOKEN Compatibility alias for HF_TOKEN\n"
printf " NEMOCLAW_ACCEPT_EXPERIMENTAL_OPENSHELL_UPGRADE=1\n"
printf " Allow automatic pre-0.0.37 OpenShell gateway upgrade\n"
printf " NEMOCLAW_OPENSHELL_UPGRADE_PREPARED=1\n"
printf " Continue after manually backing up and retiring old gateway\n"
printf " NEMOCLAW_CONFIRM_LEGACY_MANAGED_RECREATE\n"
printf " Exact JSON array of pre-fingerprint managed sandbox names\n"
printf " NEMOCLAW_PROVIDER build | openrouter | openai | anthropic | anthropicCompatible\n"
printf " | gemini | ollama | custom | nim-local | vllm | routed\n"
printf " | hermes-provider\n"
printf " (aliases: cloud -> build, nim -> nim-local)\n"
printf " NEMOCLAW_POLICY_MODE suggested | custom | skip\n"
printf "\n"
}
bootstrap_main() {
for arg in "$@"; do
case "$arg" in
--help | -h)
bootstrap_usage
return 0
;;
--version | -v)
bootstrap_version
return 0
;;
esac
done
require_supported_platform
local ref
ref="$(resolve_release_tag)"
exec_installer_from_ref "$ref" "$@"
}
if has_payload_marker "$LOCAL_PAYLOAD"; then
# shellcheck source=/dev/null
. "$LOCAL_PAYLOAD"
fi
if [[ "${BASH_SOURCE[0]:-}" == "$0" ]] || { [[ -z "${BASH_SOURCE[0]:-}" ]] && { [[ "$0" == "bash" ]] || [[ "$0" == "-bash" ]]; }; }; then
if has_payload_marker "$LOCAL_PAYLOAD"; then
main "$@"
else
bootstrap_main "$@"
fi
fi